# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=300

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 301

---

## [Docker module is not publishing all metrics for CPU and memory](https://discuss.elastic.co/t/docker-module-is-not-publishing-all-metrics-for-cpu-and-memory/207910)

<div class="topic-metadata">

**Author:** [@Ivers07](https://discuss.elastic.co/u/Ivers07)\
**Replies:** 0\
**Last updated:** [November 14, 2019, 2:14pm UTC](https://discuss.elastic.co/t/docker-module-is-not-publishing-all-metrics-for-cpu-and-memory/207910 "2019-11-14T14:14:08Z")

</div>

Hi, I've installed Metricbeat V7.4.1 on a Windows Server 2019 host that is running docker 19.0.3 with the system, windows and docker modules enabled. The system and windows modules are working correctly with kibana dash…

---

## [How can I create aliases (readable names) for urls in heartbeat monitor yml file for Kibana visualization](https://discuss.elastic.co/t/how-can-i-create-aliases-readable-names-for-urls-in-heartbeat-monitor-yml-file-for-kibana-visualization/207587)

<div class="topic-metadata">

**Author:** [@Abhimanyu\_Sharma](https://discuss.elastic.co/u/Abhimanyu_Sharma)\
**Replies:** 2\
**Last updated:** [November 14, 2019, 2:13pm UTC](https://discuss.elastic.co/t/how-can-i-create-aliases-readable-names-for-urls-in-heartbeat-monitor-yml-file-for-kibana-visualization/207587 "2019-11-14T14:13:59Z")

</div>

Hi I have a yml file for heartbeat monitor configuration containing urls for various services in the following format : type: http schedule: '@every 180s' urls: http://service1/getStatus http://service2/getStatus …

---

## [2 different udp sources in filebeat](https://discuss.elastic.co/t/2-different-udp-sources-in-filebeat/207871)

<div class="topic-metadata">

**Author:** [@Dimitris\_S](https://discuss.elastic.co/u/Dimitris_S)\
**Replies:** 0\
**Last updated:** [November 14, 2019, 11:17am UTC](https://discuss.elastic.co/t/2-different-udp-sources-in-filebeat/207871 "2019-11-14T11:17:30Z")

</div>

Hi there, I have data coming from 2 different Raspis and I would like to physically separate the traffic in 2 different UDP ports. I've configured filebeat.yml like so: filebeat.inputs: type: udp enabled: true ma…

---

## [Filebeat merging two logs](https://discuss.elastic.co/t/filebeat-merging-two-logs/207843)

<div class="topic-metadata">

**Author:** [@sur1029](https://discuss.elastic.co/u/sur1029)\
**Replies:** 0\
**Last updated:** [November 14, 2019, 9:12am UTC](https://discuss.elastic.co/t/filebeat-merging-two-logs/207843 "2019-11-14T09:12:57Z")

</div>

Hi, I am using filebeat to push logs to elastic search. The logs is mainly a json which is being pushed by different celery workers all in one single file. However I am noticing that these logs are getting merged for fe…

---

## [Filebeat error on dashboard & elasticsearch server](https://discuss.elastic.co/t/filebeat-error-on-dashboard-elasticsearch-server/204820)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 4\
**Last updated:** [November 14, 2019, 8:29am UTC](https://discuss.elastic.co/t/filebeat-error-on-dashboard-elasticsearch-server/204820 "2019-11-14T08:29:49Z")

</div>

After I downgraded from Filebeat 7.3.2 to 7.1.1. and my elasticsearch remains 7.3.2. Then I encounter that filebeat cannot load the dashboards, and I followed by reloading the index and also the dashboards, but still ha…

---

## [Filebeat \> Nginx Module](https://discuss.elastic.co/t/filebeat-nginx-module/196026)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 34\
**Last updated:** [November 14, 2019, 3:22am UTC](https://discuss.elastic.co/t/filebeat-nginx-module/196026 "2019-11-14T03:22:30Z")

</div>

Hi all, i found that this Nginx Module's visualization does not provides the full template. How can I get it and steps to install it? As when I view the dashboard, some are appeared "Could not locate that index-pattern …

---

## [Loading Index Template](https://discuss.elastic.co/t/loading-index-template/207793)

<div class="topic-metadata">

**Author:** [@msauter](https://discuss.elastic.co/u/msauter)\
**Replies:** 1\
**Last updated:** [November 14, 2019, 3:15am UTC](https://discuss.elastic.co/t/loading-index-template/207793 "2019-11-14T03:15:03Z")

</div>

Hello. Completely new to Elastic as well as this form. Initially working with auditbeat. Using 7.4. I am planning to send all of the captured audit information directly to Logstash first. Since I’ll use Logstash to …

---

## [Filebeats 7.4.2/nomad OOM error](https://discuss.elastic.co/t/filebeats-7-4-2-nomad-oom-error/207407)

<div class="topic-metadata">

**Author:** [@djesrani](https://discuss.elastic.co/u/djesrani)\
**Replies:** 2\
**Last updated:** [November 13, 2019, 5:15pm UTC](https://discuss.elastic.co/t/filebeats-7-4-2-nomad-oom-error/207407 "2019-11-13T17:15:13Z")

</div>

Hello all, I've been running into Out Of Memory/"task killed" issues deploying Filebeats and docker-gen into our production cluster. Nomad version is 0.9.4, Filebeats version is 7.4.2. Memory allocation to Filebeats b…

---

## [Filebeat - Module Elasticsearch - Parsing date](https://discuss.elastic.co/t/filebeat-module-elasticsearch-parsing-date/207641)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 1\
**Last updated:** [November 13, 2019, 5:57pm UTC](https://discuss.elastic.co/t/filebeat-module-elasticsearch-parsing-date/207641 "2019-11-13T17:57:34Z")

</div>

Hello, I am using Filebeat Elasticsearch Module, but timestamp is not parsed from elasticsearch logs. Can Filebeat Elasticsearch Module parse timestamp from elasticsearch logs? From some reason I see all collected docum…

---

## [Winlogbeat Connection Refused](https://discuss.elastic.co/t/winlogbeat-connection-refused/207399)

<div class="topic-metadata">

**Author:** [@michael.whittaker](https://discuss.elastic.co/u/michael.whittaker)\
**Replies:** 2\
**Last updated:** [November 13, 2019, 4:09pm UTC](https://discuss.elastic.co/t/winlogbeat-connection-refused/207399 "2019-11-13T16:09:20Z")

</div>

Running 7.4, trying to push WIN10 events to Ubuntu Elasticsearch. Seeing the following when debugging on the Win10 box: "2019-11-11T12:08:14.383-0500 ERROR pipeline/output.go:100 Failed to connect to backoff(elast…

---

## [How to debug filebeat issues](https://discuss.elastic.co/t/how-to-debug-filebeat-issues/207062)

<div class="topic-metadata">

**Author:** [@Jeremy\_Gachet](https://discuss.elastic.co/u/Jeremy_Gachet)\
**Replies:** 3\
**Last updated:** [November 13, 2019, 3:43pm UTC](https://discuss.elastic.co/t/how-to-debug-filebeat-issues/207062 "2019-11-13T15:43:09Z")

</div>

Hello, I installed filebeat, used with apache module a few month ago. Everything was ok since I try to add the response time to my apache logs using this tutorial : https://www.partiallydisassembled.net/posts/filebeat-…

---

## [Kubernetes autodiscovery: pod with multiple log files](https://discuss.elastic.co/t/kubernetes-autodiscovery-pod-with-multiple-log-files/207405)

<div class="topic-metadata">

**Author:** [@DominicWatson](https://discuss.elastic.co/u/DominicWatson)\
**Replies:** 2\
**Last updated:** [November 13, 2019, 3:29pm UTC](https://discuss.elastic.co/t/kubernetes-autodiscovery-pod-with-multiple-log-files/207405 "2019-11-13T15:29:57Z")

</div>

Hi there, I'm struggling to get filebeats to pick up log files in my pods using autodiscovery annotations. My filebeat daemonset config looks like this: --- apiVersion: v1 kind: ConfigMap metadata: name: filebeat-conf…

---

## [Ecs version 1.1.0 on latest winlogbeats](https://discuss.elastic.co/t/ecs-version-1-1-0-on-latest-winlogbeats/207589)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 1\
**Last updated:** [November 13, 2019, 3:25pm UTC](https://discuss.elastic.co/t/ecs-version-1-1-0-on-latest-winlogbeats/207589 "2019-11-13T15:25:29Z")

</div>

Has ecs 1.2 not been integrated yet into beats? This is a fresh install of the elastic stack and winlogbeats. Thanks Phil

---

## [Beats in docker: logging so filebeat picks up logs via "docker logs" API](https://discuss.elastic.co/t/beats-in-docker-logging-so-filebeat-picks-up-logs-via-docker-logs-api/205869)

<div class="topic-metadata">

**Author:** [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Replies:** 3\
**Last updated:** [November 13, 2019, 3:07pm UTC](https://discuss.elastic.co/t/beats-in-docker-logging-so-filebeat-picks-up-logs-via-docker-logs-api/205869 "2019-11-13T15:07:57Z")

</div>

I'm running several containers in docker and using filebeat and metricbeat to poll the Docker APIs to get metrics and logfiles. However I can't see any of the filebeat or metricbeat logs (also running in containers) usi…

---

## [Moving from Logstash to Filebeat](https://discuss.elastic.co/t/moving-from-logstash-to-filebeat/207460)

<div class="topic-metadata">

**Author:** [@yavidor](https://discuss.elastic.co/u/yavidor)\
**Replies:** 1\
**Last updated:** [November 13, 2019, 2:59pm UTC](https://discuss.elastic.co/t/moving-from-logstash-to-filebeat/207460 "2019-11-13T14:59:48Z")

</div>

Hi. were Moving from logstash to filebeat as a part of our transition to containers. our old logstash configuration was: input { file { path =\> "/servicename/\_logs/servicename.log" codec =\> multiline { …

---

## [Metricbeat process\_summary on windows](https://discuss.elastic.co/t/metricbeat-process-summary-on-windows/206879)

<div class="topic-metadata">

**Author:** [@tomr](https://discuss.elastic.co/u/tomr)\
**Replies:** 2\
**Last updated:** [November 13, 2019, 2:44pm UTC](https://discuss.elastic.co/t/metricbeat-process-summary-on-windows/206879 "2019-11-13T14:44:02Z")

</div>

I'm using metricbeat (7.3.2) on Windows, and trying to figure out what the various process\_summary metrics mean. t metricset.name process\_summary t service.type system # system.process.summary.dead 0 # syst…

---

## [Parse rancher text logs using filebeat](https://discuss.elastic.co/t/parse-rancher-text-logs-using-filebeat/207243)

<div class="topic-metadata">

**Author:** [@tru64gurus](https://discuss.elastic.co/u/tru64gurus)\
**Replies:** 1\
**Last updated:** [November 13, 2019, 2:06pm UTC](https://discuss.elastic.co/t/parse-rancher-text-logs-using-filebeat/207243 "2019-11-13T14:06:18Z")

</div>

Hi, I have serveral k8s clusters running on rancher 2.3.1 sending several GB of logs per second and causing disk pressure on source side . To solve source bottleneck , logs are being sent to syslog server and get writt…

---

## [Beats writing logs to messages](https://discuss.elastic.co/t/beats-writing-logs-to-messages/205144)

<div class="topic-metadata">

**Author:** [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Replies:** 6\
**Last updated:** [November 13, 2019, 1:59pm UTC](https://discuss.elastic.co/t/beats-writing-logs-to-messages/205144 "2019-11-13T13:59:16Z")

</div>

Hi Team, Even though I've setting for writing beat logs to file its still writing the logs to messages only. Below is the config for metricbeat i have the same for filebeat too. But both writing ton of logs to /var/logs…

---

## [How to send Cisco devices logs to Logstash?](https://discuss.elastic.co/t/how-to-send-cisco-devices-logs-to-logstash/207132)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 2\
**Last updated:** [November 13, 2019, 11:56am UTC](https://discuss.elastic.co/t/how-to-send-cisco-devices-logs-to-logstash/207132 "2019-11-13T11:56:32Z")

</div>

Hi, I want to send the Cisco switch logs to ELK stack? Is below procedure correct ? step-1 Sentd logs from Cisco switch to Rsyslog server Step-2 Install filebeat on Rsyslog server Step-3: enable Filbeat Cisco mo…

---

## [Filebeat merge several lines from mysql-slow.log into one line](https://discuss.elastic.co/t/filebeat-merge-several-lines-from-mysql-slow-log-into-one-line/207166)

<div class="topic-metadata">

**Author:** [@Vladpov](https://discuss.elastic.co/u/Vladpov)\
**Replies:** 1\
**Last updated:** [November 13, 2019, 11:32am UTC](https://discuss.elastic.co/t/filebeat-merge-several-lines-from-mysql-slow-log-into-one-line/207166 "2019-11-13T11:32:36Z")

</div>

Hello everyone, I'm trying to analyze mysql-slow.log by using Filebeat Logstash and Elasticsearch. I have messages in mysql-slow.log file that look like this: # Time: 2019-11-08T20:02:05.474508Z # User@Host: user\[user\]…

---

## [Unable to monitor the host machine via Auditbeat Docker](https://discuss.elastic.co/t/unable-to-monitor-the-host-machine-via-auditbeat-docker/206941)

<div class="topic-metadata">

**Author:** [@jdouk](https://discuss.elastic.co/u/jdouk)\
**Replies:** 0\
**Last updated:** [November 7, 2019, 9:55am UTC](https://discuss.elastic.co/t/unable-to-monitor-the-host-machine-via-auditbeat-docker/206941 "2019-11-07T09:55:24Z")

</div>

I have been trying to monitor my host using Auditbeat docker but so far I am unable to see any login attemps to my ELK stack (SIEM). The container runs without any problems. Here is the command used to bring up the cont…

---

## [ILM and output.elasticsearch.indices](https://discuss.elastic.co/t/ilm-and-output-elasticsearch-indices/207634)

<div class="topic-metadata">

**Author:** [@andye](https://discuss.elastic.co/u/andye)\
**Replies:** 0\
**Last updated:** [November 13, 2019, 6:39am UTC](https://discuss.elastic.co/t/ilm-and-output-elasticsearch-indices/207634 "2019-11-13T06:39:45Z")

</div>

Currently using fluentbit to read in docker log files and forward on to elasticsearch and thinking about moving over to Filebeats to try to take advantage of the new ILM features. We currently have some application spec…

---

## [FileBeats consuming unnecessary disk](https://discuss.elastic.co/t/filebeats-consuming-unnecessary-disk/207615)

<div class="topic-metadata">

**Author:** [@rwat090](https://discuss.elastic.co/u/rwat090)\
**Replies:** 0\
**Last updated:** [November 13, 2019, 2:56am UTC](https://discuss.elastic.co/t/filebeats-consuming-unnecessary-disk/207615 "2019-11-13T02:56:37Z")

</div>

This seems to be a common issue but I would just like some input, we have an issue where filebeats is not removing openFiles filebeat 54442 root 8r REG 253,2 104857631 51401225 /var/log/grouper/grou…

---

## [I cannot see information when create index filebeat in "Time filter field name: @timestamp"](https://discuss.elastic.co/t/i-cannot-see-information-when-create-index-filebeat-in-time-filter-field-name-timestamp/207593)

<div class="topic-metadata">

**Author:** [@mguel](https://discuss.elastic.co/u/mguel)\
**Replies:** 0\
**Last updated:** [November 12, 2019, 9:57pm UTC](https://discuss.elastic.co/t/i-cannot-see-information-when-create-index-filebeat-in-time-filter-field-name-timestamp/207593 "2019-11-12T21:57:20Z")

</div>

I am new to ELK and configure filebat with modules, the cisco module is enable and I am not receiving information when I create the index pattern with filter "@timestap", if I create the index in kibana without time filt…

---

## [High number of log files leads to high filebeat RAM and CPU usage](https://discuss.elastic.co/t/high-number-of-log-files-leads-to-high-filebeat-ram-and-cpu-usage/207575)

<div class="topic-metadata">

**Author:** [@jbrown](https://discuss.elastic.co/u/jbrown)\
**Replies:** 0\
**Last updated:** [November 12, 2019, 7:13pm UTC](https://discuss.elastic.co/t/high-number-of-log-files-leads-to-high-filebeat-ram-and-cpu-usage/207575 "2019-11-12T19:13:43Z")

</div>

I have a filebeat client watching a log folder that receives up to 120,000 log files per day. Early in the day, when there are only a few files in the folder, filebeat works fine. However, later in the day filebeat CPU…

---

## [Filebeat no releasing deleted files](https://discuss.elastic.co/t/filebeat-no-releasing-deleted-files/206171)

<div class="topic-metadata">

**Author:** [@A\_B](https://discuss.elastic.co/u/A_B)\
**Replies:** 7\
**Last updated:** [November 12, 2019, 1:18pm UTC](https://discuss.elastic.co/t/filebeat-no-releasing-deleted-files/206171 "2019-11-12T13:18:49Z")

</div>

Hello, I could not find a post with my current specific problem so creating a new one :slight\_smile: I use Filebeat version 6.8.2 running on Debian 9 I have problems with Filebeat on some machines where Filebeat keeps…

---

## [Can't run MetricBeat on Openshift](https://discuss.elastic.co/t/cant-run-metricbeat-on-openshift/206076)

<div class="topic-metadata">

**Author:** [@agiorgi](https://discuss.elastic.co/u/agiorgi)\
**Replies:** 6\
**Last updated:** [November 12, 2019, 12:15pm UTC](https://discuss.elastic.co/t/cant-run-metricbeat-on-openshift/206076 "2019-11-12T12:15:37Z")

</div>

Hi guys :slight\_smile: I'm having issues while trying to setup metricbeat on our Openshift cluster. Here are some details: Elasticsearch Version: 7.4 MetricBeat version: 7.4 OpenShift & Kubernetes: (OCP) Client Ver…

---

## [Functionbeat cloudwatch logging too much information](https://discuss.elastic.co/t/functionbeat-cloudwatch-logging-too-much-information/206187)

<div class="topic-metadata">

**Author:** [@Gavin\_Hardy](https://discuss.elastic.co/u/Gavin_Hardy)\
**Replies:** 3\
**Last updated:** [November 12, 2019, 12:14pm UTC](https://discuss.elastic.co/t/functionbeat-cloudwatch-logging-too-much-information/206187 "2019-11-12T12:14:01Z")

</div>

Hello, We have noticed that functionbeat is pushing way to many logs to cloudwatch, and is resulting in our bill being high, as we are getting charged for PutLogEvents. I have set the logging level to be error, but can …

---

## [MetricBeat v7.3.1 memory leak](https://discuss.elastic.co/t/metricbeat-v7-3-1-memory-leak/205650)

<div class="topic-metadata">

**Author:** [@Milan\_Todorovic](https://discuss.elastic.co/u/Milan_Todorovic)\
**Replies:** 8\
**Last updated:** [November 12, 2019, 11:42am UTC](https://discuss.elastic.co/t/metricbeat-v7-3-1-memory-leak/205650 "2019-11-12T11:42:44Z")

</div>

Hi, We are using ELK 7.3.1 installed on Kubernetes cluster. We are using official Docker image for Metricbeat in this case that is: docker.elastic.co/beats/metricbeat-oss:7.3.1 Ever since migration to this new version…

---

## [Filebeat is not harvesting Mysql error logs](https://discuss.elastic.co/t/filebeat-is-not-harvesting-mysql-error-logs/206133)

<div class="topic-metadata">

**Author:** [@Ashima83](https://discuss.elastic.co/u/Ashima83)\
**Replies:** 4\
**Last updated:** [November 12, 2019, 11:41am UTC](https://discuss.elastic.co/t/filebeat-is-not-harvesting-mysql-error-logs/206133 "2019-11-12T11:41:56Z")

</div>

Filebeat is harvesting mysql slow logs and that can be seen on Kibana dashboard but it isnt harvesting the mysql error log files. Below is the mysql.yml: # Module: mysql # Docs: https://www.elastic.co/guide/en/beats/fi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=299)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=301)
