# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=301

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 302

---

## [Elastic 7.4.2 metricbeat host.name is set to metricbeat agent.name on Centos 7.4](https://discuss.elastic.co/t/elastic-7-4-2-metricbeat-host-name-is-set-to-metricbeat-agent-name-on-centos-7-4/206579)

<div class="topic-metadata">

**Author:** [@ionescu77](https://discuss.elastic.co/u/ionescu77)\
**Replies:** 2\
**Last updated:** [November 12, 2019, 9:12am UTC](https://discuss.elastic.co/t/elastic-7-4-2-metricbeat-host-name-is-set-to-metricbeat-agent-name-on-centos-7-4/206579 "2019-11-12T09:12:09Z")

</div>

In the Kibana Metricbeat Dashboard, I see the agent name instead of the hostname. The metricbeat.yml is: This behaviour is annoying, because if I click in the dashboard on "System Overview" it will use the query: …

---

## [Not parsing event fields from Zeek log](https://discuss.elastic.co/t/not-parsing-event-fields-from-zeek-log/207434)

<div class="topic-metadata">

**Author:** [@ganchu](https://discuss.elastic.co/u/ganchu)\
**Replies:** 0\
**Last updated:** [November 12, 2019, 3:44am UTC](https://discuss.elastic.co/t/not-parsing-event-fields-from-zeek-log/207434 "2019-11-12T03:44:06Z")

</div>

Filebeat zeek module not parsing Zeek event fields to ES event field. I need add some mapping on logstash? or make some config? Zeek version is 3.0.0.

---

## [Converting Cisco Module](https://discuss.elastic.co/t/converting-cisco-module/206916)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 6\
**Last updated:** [November 11, 2019, 11:59pm UTC](https://discuss.elastic.co/t/converting-cisco-module/206916 "2019-11-11T23:59:46Z")

</div>

I'm learning to use filebeat, I was wondering if there is a way to convert the ingest pipeline from elasticsearch to logstash config I've had a look here https://www.elastic.co/guide/en/logstash/current/ingest-converte…

---

## [Old index getting new log data](https://discuss.elastic.co/t/old-index-getting-new-log-data/207180)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 1\
**Last updated:** [November 11, 2019, 3:46pm UTC](https://discuss.elastic.co/t/old-index-getting-new-log-data/207180 "2019-11-11T15:46:48Z")

</div>

After running this command, ./filebeat -e --modules system,nginx,mysql This Index was created yellow filebeat-7.4.0-2019.11.08-000001 open lMcCHhWuT9ecTfsI4OyGEA 1 1 3982 0 676kb 2019-11-08T20:06:41.949Z But …

---

## [Excessive Disk usage - Filebeat](https://discuss.elastic.co/t/excessive-disk-usage-filebeat/207325)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 0\
**Last updated:** [November 11, 2019, 10:11am UTC](https://discuss.elastic.co/t/excessive-disk-usage-filebeat/207325 "2019-11-11T10:11:56Z")

</div>

Hi, i'm using elk stack of version 5.5 without x-pack. My disk is getting filled even though my file is deleted , filebeat still has the file handler open, the file disappears but still takes up space on my disk. so i…

---

## [Kibana output port not accepted in filebeat.yml](https://discuss.elastic.co/t/kibana-output-port-not-accepted-in-filebeat-yml/206865)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 14\
**Last updated:** [November 11, 2019, 8:45am UTC](https://discuss.elastic.co/t/kibana-output-port-not-accepted-in-filebeat-yml/206865 "2019-11-11T08:45:11Z")

</div>

I am trying to use filebeats to ingest logs and send them to Kibana. Here is my filebeat.yml file filebeat: inputs: - paths: - /home/mehak/Downloads/Dispatcher-ExtTicketId-24748775/Dispstcher-ExtTicketId-24748775/lo…

---

## [Full body response to elasticsearch](https://discuss.elastic.co/t/full-body-response-to-elasticsearch/199973)

<div class="topic-metadata">

**Author:** [@coachbjork](https://discuss.elastic.co/u/coachbjork)\
**Replies:** 7\
**Last updated:** [November 10, 2019, 9:00pm UTC](https://discuss.elastic.co/t/full-body-response-to-elasticsearch/199973 "2019-11-10T21:00:10Z")

</div>

I am trying to figure out how to index the full body response into elastics using Heartbeat. I found this: https://discuss.elastic.co/t/send-body-response-to-elastic/188516 And it is now solved, but seems to only be du…

---

## [Configuring envoyproxy module for collecting stats](https://discuss.elastic.co/t/configuring-envoyproxy-module-for-collecting-stats/198881)

<div class="topic-metadata">

**Author:** [@somi](https://discuss.elastic.co/u/somi)\
**Replies:** 9\
**Last updated:** [November 10, 2019, 1:30am UTC](https://discuss.elastic.co/t/configuring-envoyproxy-module-for-collecting-stats/198881 "2019-11-10T01:30:34Z")

</div>

Hi, I have an envoy, metricbeat and elasticsearch container in my kubernetes cluster. I want to use the envoyproxy module of metricbeat to collect stats and send it to elasticsearch. Configured the module according this…

---

## [Using index name in rollover alias](https://discuss.elastic.co/t/using-index-name-in-rollover-alias/207184)

<div class="topic-metadata">

**Author:** [@bunjiboys](https://discuss.elastic.co/u/bunjiboys)\
**Replies:** 0\
**Last updated:** [November 8, 2019, 10:57pm UTC](https://discuss.elastic.co/t/using-index-name-in-rollover-alias/207184 "2019-11-08T22:57:04Z")

</div>

We're trying to set up filebeat to use ILM with "automatic" index naming from our Kubernetes cluster. Output configuration: output: elasticsearch: bulk\_max\_size: 1000 enable: true host…

---

## [Filebeat.autodiscover on Kubernetes not honoring multiline message config](https://discuss.elastic.co/t/filebeat-autodiscover-on-kubernetes-not-honoring-multiline-message-config/207167)

<div class="topic-metadata">

**Author:** [@Michael\_Davis](https://discuss.elastic.co/u/Michael_Davis)\
**Replies:** 1\
**Last updated:** [November 8, 2019, 8:42pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-on-kubernetes-not-honoring-multiline-message-config/207167 "2019-11-08T20:42:56Z")

</div>

Hi all, I'm using Filebeat as a DaemonSet in Kubernetes to capture logs from containers across the cluster. These logs are being pushed into an Elastic Cloud deployment by Filebeat. We're primarily a Java shop, so I'm t…

---

## [How to i get specific process name by metricbeat?](https://discuss.elastic.co/t/how-to-i-get-specific-process-name-by-metricbeat/206768)

<div class="topic-metadata">

**Author:** [@Yungyoung\_Ok](https://discuss.elastic.co/u/Yungyoung_Ok)\
**Replies:** 2\
**Last updated:** [November 8, 2019, 6:43am UTC](https://discuss.elastic.co/t/how-to-i-get-specific-process-name-by-metricbeat/206768 "2019-11-08T06:43:17Z")

</div>

In general, the metric bits come from the process name java, python, etc. But, i want to get specific process name. is it possible?

---

## [Filebeat S3 Input - Output Garbled](https://discuss.elastic.co/t/filebeat-s3-input-output-garbled/206924)

<div class="topic-metadata">

**Author:** [@jbws](https://discuss.elastic.co/u/jbws)\
**Replies:** 4\
**Last updated:** [November 7, 2019, 4:49pm UTC](https://discuss.elastic.co/t/filebeat-s3-input-output-garbled/206924 "2019-11-07T16:49:40Z")

</div>

I have configured VPC Flow logs to ship to S3 and then an SQS message queue to notify Filebeat. This creates records in ES but they appear like this! Any ideas?

---

## [Filebeat + zeekmodule to elastic + kibana](https://discuss.elastic.co/t/filebeat-zeekmodule-to-elastic-kibana/205482)

<div class="topic-metadata">

**Author:** [@tmans1991](https://discuss.elastic.co/u/tmans1991)\
**Replies:** 6\
**Last updated:** [November 7, 2019, 4:21pm UTC](https://discuss.elastic.co/t/filebeat-zeekmodule-to-elastic-kibana/205482 "2019-11-07T16:21:45Z")

</div>

hi im using a filebeat + zeekmodule machine to send .log files (written in JSON) to an elastic + kibana machine i am sending conn.logg dns.log http.log files.log ssl.log and notice.log but i am not sending : capture…

---

## [Winlogbeat and Windows Event Log Service dependency](https://discuss.elastic.co/t/winlogbeat-and-windows-event-log-service-dependency/206978)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 0\
**Last updated:** [November 7, 2019, 2:56pm UTC](https://discuss.elastic.co/t/winlogbeat-and-windows-event-log-service-dependency/206978 "2019-11-07T14:56:48Z")

</div>

Hi, I have installed winlogbeat 7.4 in a windows server 2016. I noticed that if I stop the Windows Event Log service winlogbeat is stopped automatically. I read in the documentation about the event\_logs.no\_more\_events…

---

## [Winlogbeat dont use custom template](https://discuss.elastic.co/t/winlogbeat-dont-use-custom-template/206958)

<div class="topic-metadata">

**Author:** [@j.frenker](https://discuss.elastic.co/u/j.frenker)\
**Replies:** 0\
**Last updated:** [November 7, 2019, 12:49pm UTC](https://discuss.elastic.co/t/winlogbeat-dont-use-custom-template/206958 "2019-11-07T12:49:25Z")

</div>

Hi we want to use Winlogbeat (7.4.2) for sending the eventlogs of a Windows Server to an Elasticsearch cluster, but it use always the default settings and not the custom one of the Template Section: setup.template: n…

---

## [Docker Metricbeat not getting the System Metrics from host](https://discuss.elastic.co/t/docker-metricbeat-not-getting-the-system-metrics-from-host/206567)

<div class="topic-metadata">

**Author:** [@Simon\_Becker](https://discuss.elastic.co/u/Simon_Becker)\
**Replies:** 1\
**Last updated:** [November 7, 2019, 11:46am UTC](https://discuss.elastic.co/t/docker-metricbeat-not-getting-the-system-metrics-from-host/206567 "2019-11-07T11:46:01Z")

</div>

Hello there, i am trying to get my host metrics forwarded through my metricbeat in a docker container. I mounted all the neccecary directories, as shown in the docs here: https://www.elastic.co/guide/en/beats/metricbea…

---

## [Conditionals and processor Chains](https://discuss.elastic.co/t/conditionals-and-processor-chains/206938)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 0\
**Last updated:** [November 7, 2019, 9:43am UTC](https://discuss.elastic.co/t/conditionals-and-processor-chains/206938 "2019-11-07T09:43:06Z")

</div>

Hi, Is it possible to use conditionals inside a processor Chain? I use a copySubjectUser processor chain in order to copy the SubjectUser information in windows events. For most of the events Subject user information …

---

## [High CPU usage in BEATS](https://discuss.elastic.co/t/high-cpu-usage-in-beats/205239)

<div class="topic-metadata">

**Author:** [@Tinkerbell](https://discuss.elastic.co/u/Tinkerbell)\
**Replies:** 4\
**Last updated:** [November 7, 2019, 8:09am UTC](https://discuss.elastic.co/t/high-cpu-usage-in-beats/205239 "2019-11-07T08:09:15Z")

</div>

I am using Filebeat to ship logs from the server to Elastic. We use ingestNode pipelines to parse the files using Grok processor. Please find my filebeat.yml file. I see the memory consumed by a single process is around…

---

## [Filebeat unable to read stdout from Container via Autodiscover initiation](https://discuss.elastic.co/t/filebeat-unable-to-read-stdout-from-container-via-autodiscover-initiation/206797)

<div class="topic-metadata">

**Author:** [@miri](https://discuss.elastic.co/u/miri)\
**Replies:** 0\
**Last updated:** [November 6, 2019, 1:30pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-read-stdout-from-container-via-autodiscover-initiation/206797 "2019-11-06T13:30:03Z")

</div>

I m running an pod with one container writing into files and one sidecar. The sidecars simply tail'ing the mounted file from the main container to stdout. Have tested nearly the whole day to get the lines into filebeat…

---

## [Mysql select method event's duration is lost](https://discuss.elastic.co/t/mysql-select-method-events-duration-is-lost/206904)

<div class="topic-metadata">

**Author:** [@meng\_liu](https://discuss.elastic.co/u/meng_liu)\
**Replies:** 0\
**Last updated:** [November 7, 2019, 6:29am UTC](https://discuss.elastic.co/t/mysql-select-method-events-duration-is-lost/206904 "2019-11-07T06:29:54Z")

</div>

I use beats to minitor mysql, when the method is select, we found the event not have the duration, and that the start and end is reverse. { "@timestamp":"2019-11-06T04:40:21.168Z", "@metadata":{ "beat":…

---

## [MISP module for Filebeat 7.2](https://discuss.elastic.co/t/misp-module-for-filebeat-7-2/206894)

<div class="topic-metadata">

**Author:** [@vishnug](https://discuss.elastic.co/u/vishnug)\
**Replies:** 0\
**Last updated:** [November 7, 2019, 5:43am UTC](https://discuss.elastic.co/t/misp-module-for-filebeat-7-2/206894 "2019-11-07T05:43:48Z")

</div>

Hi Everyone I was trying out the MISP module for filebeat. I know it's in beta. Is the MISP module available for Filbeat 7.2?

---

## [Set version of custom beat](https://discuss.elastic.co/t/set-version-of-custom-beat/206864)

<div class="topic-metadata">

**Author:** [@MelonSmasher](https://discuss.elastic.co/u/MelonSmasher)\
**Replies:** 0\
**Last updated:** [November 6, 2019, 9:39pm UTC](https://discuss.elastic.co/t/set-version-of-custom-beat/206864 "2019-11-06T21:39:57Z")

</div>

Hi all, I've made a new beat and I'm ready to upload a packaged release to my Github releases. I'd like the version to match my git tags. I've searched around and tried on my own to override the version provided by libb…

---

## [Is there a Heartbeat service](https://discuss.elastic.co/t/is-there-a-heartbeat-service/205912)

<div class="topic-metadata">

**Author:** [@darking360](https://discuss.elastic.co/u/darking360)\
**Replies:** 1\
**Last updated:** [November 6, 2019, 9:05pm UTC](https://discuss.elastic.co/t/is-there-a-heartbeat-service/205912 "2019-11-06T21:05:55Z")

</div>

Greetings. Reading the documentation it says to download either Heartbeat or Metricbeat to send this data to an Elastic Search instance, for example, the problem is where to deploy this? Is there like a Heartbeat as a se…

---

## [Loading Kibana dashboard for filebeat](https://discuss.elastic.co/t/loading-kibana-dashboard-for-filebeat/206480)

<div class="topic-metadata">

**Author:** [@sarahvo](https://discuss.elastic.co/u/sarahvo)\
**Replies:** 1\
**Last updated:** [November 6, 2019, 8:11pm UTC](https://discuss.elastic.co/t/loading-kibana-dashboard-for-filebeat/206480 "2019-11-06T20:11:04Z")

</div>

Hi, I'm using Elasticsearch and Kibana services in Azure and I have logstash on-prem. I want to have filebeat push logs to logstash. I'm trying to load the Kibana dashboard for filebeat using the endpoint URLs for Elasti…

---

## [Vendor directory and VCS question](https://discuss.elastic.co/t/vendor-directory-and-vcs-question/206672)

<div class="topic-metadata">

**Author:** [@MelonSmasher](https://discuss.elastic.co/u/MelonSmasher)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 8:35pm UTC](https://discuss.elastic.co/t/vendor-directory-and-vcs-question/206672 "2019-11-05T20:35:29Z")

</div>

Hi all, I'm making my first Beat! I had a quick question that I struggled to find an answer to. When creating a new Beat should the vendor directory be checked into git?

---

## [Filebeat deleted indecies are getting recreated due to log rotation policy](https://discuss.elastic.co/t/filebeat-deleted-indecies-are-getting-recreated-due-to-log-rotation-policy/206837)

<div class="topic-metadata">

**Author:** [@ankamraok](https://discuss.elastic.co/u/ankamraok)\
**Replies:** 0\
**Last updated:** [November 6, 2019, 4:41pm UTC](https://discuss.elastic.co/t/filebeat-deleted-indecies-are-getting-recreated-due-to-log-rotation-policy/206837 "2019-11-06T16:41:33Z")

</div>

Continuing the discussion from Filebeat deleted indecies are getting recreated due to no log rotation policy:

---

## [Each log file from MS SQL error log indexing as a single data in elastic](https://discuss.elastic.co/t/each-log-file-from-ms-sql-error-log-indexing-as-a-single-data-in-elastic/203829)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 1\
**Last updated:** [November 6, 2019, 3:43pm UTC](https://discuss.elastic.co/t/each-log-file-from-ms-sql-error-log-indexing-as-a-single-data-in-elastic/203829 "2019-11-06T15:43:17Z")

</div>

I am using filebeat MSSQL module to index SQL error log for indexing to elastic all the log file index into log.original field as shown in picture

---

## [It is possible to use if statement in filebeat?](https://discuss.elastic.co/t/it-is-possible-to-use-if-statement-in-filebeat/206643)

<div class="topic-metadata">

**Author:** [@vpolizki](https://discuss.elastic.co/u/vpolizki)\
**Replies:** 1\
**Last updated:** [November 6, 2019, 3:31pm UTC](https://discuss.elastic.co/t/it-is-possible-to-use-if-statement-in-filebeat/206643 "2019-11-06T15:31:17Z")

</div>

Hi, i want to collect 2 different files with filebeat , only in first one use "Multiline options". Can i use if for this situation ? thanks

---

## [File beat not generating logs](https://discuss.elastic.co/t/file-beat-not-generating-logs/206729)

<div class="topic-metadata">

**Author:** [@Seetharaman\_K](https://discuss.elastic.co/u/Seetharaman_K)\
**Replies:** 0\
**Last updated:** [November 6, 2019, 5:50am UTC](https://discuss.elastic.co/t/file-beat-not-generating-logs/206729 "2019-11-06T05:50:35Z")

</div>

My file beat is not generating logs . below is the screen shot of the logs folder but i wonder how it is sending logs to ELK server , because i am seeing logs in kibana for today. but there is no evidence that file b…

---

## [Packebeat 7.1 mysql select duration](https://discuss.elastic.co/t/packebeat-7-1-mysql-select-duration/206728)

<div class="topic-metadata">

**Author:** [@meng\_liu](https://discuss.elastic.co/u/meng_liu)\
**Replies:** 0\
**Last updated:** [November 6, 2019, 5:43am UTC](https://discuss.elastic.co/t/packebeat-7-1-mysql-select-duration/206728 "2019-11-06T05:43:33Z")

</div>

I use beats 7.1 to minitor mysql, when the method is select, we found the event not have the duration, and that the start and end is reverse. "@timestamp":"2019-11-06T04:40:21.168Z", "@metadata":{ "beat"…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=300)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=302)
