# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=302

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 303

---

## [Functionbeat unable to start on lambda due to beats.keystore permissions](https://discuss.elastic.co/t/functionbeat-unable-to-start-on-lambda-due-to-beats-keystore-permissions/206704)

<div class="topic-metadata">

**Author:** [@josh.bowers](https://discuss.elastic.co/u/josh.bowers)\
**Replies:** 0\
**Last updated:** [November 6, 2019, 2:33am UTC](https://discuss.elastic.co/t/functionbeat-unable-to-start-on-lambda-due-to-beats-keystore-permissions/206704 "2019-11-06T02:33:44Z")

</div>

Installing functionbeat on AWS Lambda I'm getting this error: Exiting: could not initialize the keystore: open beats.keystore: permission denied beats.keystore has the correct permissions (in fact anything else will fa…

---

## [Filebeat CEF Module](https://discuss.elastic.co/t/filebeat-cef-module/206094)

<div class="topic-metadata">

**Author:** [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Replies:** 8\
**Last updated:** [November 5, 2019, 10:45pm UTC](https://discuss.elastic.co/t/filebeat-cef-module/206094 "2019-11-05T22:45:26Z")

</div>

We've been trying to create a pipeline for logs from a security tool using the recently released CEF module, but we've been getting an error about the log format and its parsing. The tool would pull its logs via an API …

---

## [Kubernetes With Filebeat parsing nginx container](https://discuss.elastic.co/t/kubernetes-with-filebeat-parsing-nginx-container/206677)

<div class="topic-metadata">

**Author:** [@miszterx](https://discuss.elastic.co/u/miszterx)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 9:13pm UTC](https://discuss.elastic.co/t/kubernetes-with-filebeat-parsing-nginx-container/206677 "2019-11-05T21:13:52Z")

</div>

I have a nginx based container in kubernetes. It is running and create standard nginx logs to stdout and stderr. These logs needs to be grabbed and send to elasticsearch with nginx module parser. I used as referrence th…

---

## [Filebeat Error: "Write: connection reset by peer"](https://discuss.elastic.co/t/filebeat-error-write-connection-reset-by-peer/206667)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 8:09pm UTC](https://discuss.elastic.co/t/filebeat-error-write-connection-reset-by-peer/206667 "2019-11-05T20:09:55Z")

</div>

TL;DR Filebeat 7.4.2 fails write to logstash multiple times per day with write: connection reset by peer Longer version Filebeat version is 7.4.2 for Linux. I see this issue periodically across our environment. Ordinar…

---

## [Output Configuration Block Host Question](https://discuss.elastic.co/t/output-configuration-block-host-question/206674)

<div class="topic-metadata">

**Author:** [@whitecoffee](https://discuss.elastic.co/u/whitecoffee)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 8:47pm UTC](https://discuss.elastic.co/t/output-configuration-block-host-question/206674 "2019-11-05T20:47:48Z")

</div>

I have an instance setup in Beats central management that has a filebeat input from a specific filepath, i need to know how to output this data. I am assuming you need to create a output configuration block so i've done…

---

## [Metricbeat Deployment: decoding of metric family failed](https://discuss.elastic.co/t/metricbeat-deployment-decoding-of-metric-family-failed/206625)

<div class="topic-metadata">

**Author:** [@JonasDeGendt](https://discuss.elastic.co/u/JonasDeGendt)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 2:25pm UTC](https://discuss.elastic.co/t/metricbeat-deployment-decoding-of-metric-family-failed/206625 "2019-11-05T14:25:20Z")

</div>

Trying to run Metricbeat 7.4 on Kubernetes, my Daemonset metricbeat is running fine, but the singleton Deployment type returns the following error message: 2019-11-05T14:20:31.748Z ERROR \[kubernetes.state\_state…

---

## [Filebeat Processor regex case insensitive](https://discuss.elastic.co/t/filebeat-processor-regex-case-insensitive/206462)

<div class="topic-metadata">

**Author:** [@OffColour](https://discuss.elastic.co/u/OffColour)\
**Replies:** 0\
**Last updated:** [November 4, 2019, 7:01pm UTC](https://discuss.elastic.co/t/filebeat-processor-regex-case-insensitive/206462 "2019-11-04T19:01:37Z")

</div>

I think I'm being an idiot here, but my filebeat 6.3.2 drop\_event processor regex condition drops the correct events with '^\\/health$' but when I try to make it case insensitive with the following, it doesn't drop anyt…

---

## [Monitoring SaaS application, browser beat?](https://discuss.elastic.co/t/monitoring-saas-application-browser-beat/206616)

<div class="topic-metadata">

**Author:** [@Ron.Janssen](https://discuss.elastic.co/u/Ron.Janssen)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 1:10pm UTC](https://discuss.elastic.co/t/monitoring-saas-application-browser-beat/206616 "2019-11-05T13:10:46Z")

</div>

Do we have a solution to monitor the performance of a SaaS application? I have tried using Heartbeat, but there is an annoying IAM (Identity and Access Management) system in the flow. Using Heartbeat I monitor the IAM i…

---

## [Filebeat 6.8.2 logs are 600](https://discuss.elastic.co/t/filebeat-6-8-2-logs-are-600/206613)

<div class="topic-metadata">

**Author:** [@Fay\_Sray](https://discuss.elastic.co/u/Fay_Sray)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 12:48pm UTC](https://discuss.elastic.co/t/filebeat-6-8-2-logs-are-600/206613 "2019-11-05T12:48:42Z")

</div>

Hello, I deployed filebeat 6.8.2 and the logs are stored with 600, is there any way to turn them into 644 ? anything might be done in filebeat.yml ? thanks

---

## [Autodiscover with k8s labels](https://discuss.elastic.co/t/autodiscover-with-k8s-labels/206596)

<div class="topic-metadata">

**Author:** [@whoatemyjam](https://discuss.elastic.co/u/whoatemyjam)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 11:21am UTC](https://discuss.elastic.co/t/autodiscover-with-k8s-labels/206596 "2019-11-05T11:21:32Z")

</div>

Hi I am trying to use condition in filebeat autodiscover for kubernates labels and i get yaml error. There is no error in yaml when checked in yamlint. filbeat version : 6.8.3 es version : 6.8.3 apiVersion: v1 da…

---

## [Filebeat is sending multiple messages to elasticsearch](https://discuss.elastic.co/t/filebeat-is-sending-multiple-messages-to-elasticsearch/206578)

<div class="topic-metadata">

**Author:** [@manish97](https://discuss.elastic.co/u/manish97)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 9:48am UTC](https://discuss.elastic.co/t/filebeat-is-sending-multiple-messages-to-elasticsearch/206578 "2019-11-05T09:48:58Z")

</div>

I wrote a multiline pattern to read multiple lines of a log .Now when i start the filebeat I see the same line twice on my kibana dashboard. filebeat multiline pattern multiline.pattern: '^\[\[:space:\]\]Event:\[\[:space:\]\]…

---

## [Filebeat container exiting with "Exiting: No monitoring reporter configured" on using output.logstash](https://discuss.elastic.co/t/filebeat-container-exiting-with-exiting-no-monitoring-reporter-configured-on-using-output-logstash/206559)

<div class="topic-metadata">

**Author:** [@Sandeep\_K](https://discuss.elastic.co/u/Sandeep_K)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 9:18am UTC](https://discuss.elastic.co/t/filebeat-container-exiting-with-exiting-no-monitoring-reporter-configured-on-using-output-logstash/206559 "2019-11-05T09:18:31Z")

</div>

Hi, I am using docker-compose file to bring up Filebeat, Logstash, Elasticsearch & Kibana containers. I want Filebeat to read logs and export them to Logstash. Need to apply Grok patterns in Logstash. Getting this err…

---

## [Connection drops for certain log inputs on secure beats to logstash beats input](https://discuss.elastic.co/t/connection-drops-for-certain-log-inputs-on-secure-beats-to-logstash-beats-input/200835)

<div class="topic-metadata">

**Author:** [@arnold79](https://discuss.elastic.co/u/arnold79)\
**Replies:** 2\
**Last updated:** [November 5, 2019, 8:45am UTC](https://discuss.elastic.co/t/connection-drops-for-certain-log-inputs-on-secure-beats-to-logstash-beats-input/200835 "2019-11-05T08:45:24Z")

</div>

Hi there, Currently we have an issue that occurs once a week, which seems to drop connections and certain log input aren't received anymore. First log input (/var/log/messages) are still received. The logs are still ava…

---

## [Machinebeat MQTT module: SSL connection to broker fails](https://discuss.elastic.co/t/machinebeat-mqtt-module-ssl-connection-to-broker-fails/206369)

<div class="topic-metadata">

**Author:** [@gmackers](https://discuss.elastic.co/u/gmackers)\
**Replies:** 1\
**Last updated:** [November 5, 2019, 8:16am UTC](https://discuss.elastic.co/t/machinebeat-mqtt-module-ssl-connection-to-broker-fails/206369 "2019-11-05T08:16:19Z")

</div>

Hi, I'm trying out the MQTT module of the machinebeat beta after reading about it here: \[https://www.elastic.co/blog/industrial-internet-of-things-iiot-with-the-elastic-stack\] and I'm having a problem connecting to an M…

---

## [Filebeat write: connection reset by peer](https://discuss.elastic.co/t/filebeat-write-connection-reset-by-peer/206511)

<div class="topic-metadata">

**Author:** [@CainGao](https://discuss.elastic.co/u/CainGao)\
**Replies:** 0\
**Last updated:** [November 5, 2019, 2:55am UTC](https://discuss.elastic.co/t/filebeat-write-connection-reset-by-peer/206511 "2019-11-05T02:55:01Z")

</div>

Hello, I use filebeat 5.5.2 send data to logstash , Sometimes, I get it; write tcp Filebeat:32890-\>LOGSTASH\_IP:6044: write: connection reset by peer But other filebet is working...

---

## [Filebeat do not send data to logstash](https://discuss.elastic.co/t/filebeat-do-not-send-data-to-logstash/206257)

<div class="topic-metadata">

**Author:** [@Vladimir\_Martyshin](https://discuss.elastic.co/u/Vladimir_Martyshin)\
**Replies:** 5\
**Last updated:** [November 4, 2019, 6:14pm UTC](https://discuss.elastic.co/t/filebeat-do-not-send-data-to-logstash/206257 "2019-11-04T18:14:40Z")

</div>

2019-11-03T00:54:09.479+0300 INFO crawler/crawler.go:106 Loading and starting Inputs completed. Enabled inputs: 1 2019-11-03T00:54:09.480+0300 INFO log/harvester.go:251 Harvester started for file: /home/cowrie/cowrie/var…

---

## [Kubernetes json log parsing with filebeat](https://discuss.elastic.co/t/kubernetes-json-log-parsing-with-filebeat/206457)

<div class="topic-metadata">

**Author:** [@Mohammad.ali](https://discuss.elastic.co/u/Mohammad.ali)\
**Replies:** 0\
**Last updated:** [November 4, 2019, 5:56pm UTC](https://discuss.elastic.co/t/kubernetes-json-log-parsing-with-filebeat/206457 "2019-11-04T17:56:00Z")

</div>

Hello everyone We have project to ship some application log from Kubernetes cluster to elasticsearch..the problem is we have right now is the logs that kubernetes produce is json based which is located on /var/log/con…

---

## [Monitor NTP Drift](https://discuss.elastic.co/t/monitor-ntp-drift/206448)

<div class="topic-metadata">

**Author:** [@ccutmt](https://discuss.elastic.co/u/ccutmt)\
**Replies:** 0\
**Last updated:** [November 4, 2019, 5:10pm UTC](https://discuss.elastic.co/t/monitor-ntp-drift/206448 "2019-11-04T17:10:17Z")

</div>

Hello Elastic Community, Some time ago the following topic was opened Monitor NTP in Linux and in conjunction to this, there is a feature request on GitHub. My current approach is to have a small script executing ntpq …

---

## [Integrate with log4j2 with logstack](https://discuss.elastic.co/t/integrate-with-log4j2-with-logstack/206194)

<div class="topic-metadata">

**Author:** [@ravikishore](https://discuss.elastic.co/u/ravikishore)\
**Replies:** 1\
**Last updated:** [November 4, 2019, 4:10pm UTC](https://discuss.elastic.co/t/integrate-with-log4j2-with-logstack/206194 "2019-11-04T16:10:17Z")

</div>

I want read the log file and display the logs into the Kibana UI. Can any one help me on this

---

## [Incorrect default index pattern for metricbeats?](https://discuss.elastic.co/t/incorrect-default-index-pattern-for-metricbeats/206298)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 2\
**Last updated:** [November 4, 2019, 2:29pm UTC](https://discuss.elastic.co/t/incorrect-default-index-pattern-for-metricbeats/206298 "2019-11-04T14:29:18Z")

</div>

We are using metricbeats 7.4.2 (also seen on 7.4.0) and with an elastic cluster that support index lifecycle management. According to metricbeats documentation, because ilm is enabled, the created index name is metricbe…

---

## [Create table aggregation with multiple server metrics](https://discuss.elastic.co/t/create-table-aggregation-with-multiple-server-metrics/206414)

<div class="topic-metadata">

**Author:** [@skdasari](https://discuss.elastic.co/u/skdasari)\
**Replies:** 0\
**Last updated:** [November 4, 2019, 1:45pm UTC](https://discuss.elastic.co/t/create-table-aggregation-with-multiple-server-metrics/206414 "2019-11-04T13:45:21Z")

</div>

Hello All, I am trying to generate report to know the top 5 processes for each server in a day, when CPU is max. utilized with time at which spike happened. I am sending metrics from various servers to store in Elastic…

---

## [Central Management and Default ILM](https://discuss.elastic.co/t/central-management-and-default-ilm/206386)

<div class="topic-metadata">

**Author:** [@rverchere](https://discuss.elastic.co/u/rverchere)\
**Replies:** 0\
**Last updated:** [November 4, 2019, 11:25am UTC](https://discuss.elastic.co/t/central-management-and-default-ilm/206386 "2019-11-04T11:25:30Z")

</div>

Hello, I have a filebeat that uses the default ILM, creating indices like 'filebeat-7.4.1-2019.11.01-000001'. After enroll the filebeat to the Central Management, the default ILM is not taken in account, and filebeat c…

---

## [Metricbeat missing kubernetes pods metrics](https://discuss.elastic.co/t/metricbeat-missing-kubernetes-pods-metrics/205417)

<div class="topic-metadata">

**Author:** [@Ivan\_Martos](https://discuss.elastic.co/u/Ivan_Martos)\
**Replies:** 6\
**Last updated:** [November 4, 2019, 8:29am UTC](https://discuss.elastic.co/t/metricbeat-missing-kubernetes-pods-metrics/205417 "2019-11-04T08:29:15Z")

</div>

Hey guys I need a bit of help with Metricbeat. I have Kubernetes (1.14) running in AWS EKS. Inside Kibana I can see metrics of Hosts, but when I switch to Kubernetes view, I can see all the pods, but no metrics for the…

---

## [Custom Beat with Multiple Event Field Structures](https://discuss.elastic.co/t/custom-beat-with-multiple-event-field-structures/206350)

<div class="topic-metadata">

**Author:** [@0xThiebaut](https://discuss.elastic.co/u/0xThiebaut)\
**Replies:** 0\
**Last updated:** [November 4, 2019, 7:56am UTC](https://discuss.elastic.co/t/custom-beat-with-multiple-event-field-structures/206350 "2019-11-04T07:56:46Z")

</div>

I am writing a custom network-related Beat following the "Creating a New Beat" dev-guide. As part of this Beat, I would like multiple type of events to be produced which would have different field mappings. The above El…

---

## [How to build auditbeat for freebsd](https://discuss.elastic.co/t/how-to-build-auditbeat-for-freebsd/206322)

<div class="topic-metadata">

**Author:** [@hadwin918](https://discuss.elastic.co/u/hadwin918)\
**Replies:** 0\
**Last updated:** [November 4, 2019, 3:27am UTC](https://discuss.elastic.co/t/how-to-build-auditbeat-for-freebsd/206322 "2019-11-04T03:27:50Z")

</div>

Hi All, I can not find any available auditbeat package for freebsd, can we support it? if yes, how to build a package Thanks

---

## [Module in filebeat for glassfish](https://discuss.elastic.co/t/module-in-filebeat-for-glassfish/206216)

<div class="topic-metadata">

**Author:** [@Zuleyma\_Espinoza](https://discuss.elastic.co/u/Zuleyma_Espinoza)\
**Replies:** 2\
**Last updated:** [November 1, 2019, 10:04pm UTC](https://discuss.elastic.co/t/module-in-filebeat-for-glassfish/206216 "2019-11-01T22:04:06Z")

</div>

Hi, I'm trying to make a module in filebeat for glassfish, this is because I want to work with logs from glassfish. I can see that in the list of modules It isn't any related with glassfish. Someone can help me please?

---

## [How to get only the information we want from the metricsbeat cloudwatch set?](https://discuss.elastic.co/t/how-to-get-only-the-information-we-want-from-the-metricsbeat-cloudwatch-set/206075)

<div class="topic-metadata">

**Author:** [@Ryan\_Waldron](https://discuss.elastic.co/u/Ryan_Waldron)\
**Replies:** 6\
**Last updated:** [November 1, 2019, 7:36pm UTC](https://discuss.elastic.co/t/how-to-get-only-the-information-we-want-from-the-metricsbeat-cloudwatch-set/206075 "2019-11-01T19:36:53Z")

</div>

We are trying to get only a few specific metrics from cloudwatch about our RDS instances (CPU, Memory, Etc). I have followed the documentation to try and come up with a configuration for metricbeats that works, and nothi…

---

## [Filebeat nginx include custom log field](https://discuss.elastic.co/t/filebeat-nginx-include-custom-log-field/206172)

<div class="topic-metadata">

**Author:** [@George\_Jetson](https://discuss.elastic.co/u/George_Jetson)\
**Replies:** 2\
**Last updated:** [November 1, 2019, 4:21pm UTC](https://discuss.elastic.co/t/filebeat-nginx-include-custom-log-field/206172 "2019-11-01T16:21:51Z")

</div>

Nginx: Running latest nginx on Ubuntu. We have added some custom fields to the access log (e.g. server\_name). Filebeat: Just setup 7.4.1 and trying to use the filebeat nginx module to send the log files to our version …

---

## [Drop\_event processor doesn't work](https://discuss.elastic.co/t/drop-event-processor-doesnt-work/206130)

<div class="topic-metadata">

**Author:** [@hlamsc](https://discuss.elastic.co/u/hlamsc)\
**Replies:** 1\
**Last updated:** [November 1, 2019, 1:50pm UTC](https://discuss.elastic.co/t/drop-event-processor-doesnt-work/206130 "2019-11-01T13:50:53Z")

</div>

Hello, I've a problem with my journalbeat config. I want to drop all events that have a syslog priority greater than 5 but nothing that has a process name with "nginx". The config looks like this: processors: …

---

## [That is an error from the auditbeat client. Any solutions to fix this problem?](https://discuss.elastic.co/t/that-is-an-error-from-the-auditbeat-client-any-solutions-to-fix-this-problem/204571)

<div class="topic-metadata">

**Author:** [@pbona](https://discuss.elastic.co/u/pbona)\
**Replies:** 3\
**Last updated:** [November 1, 2019, 2:16am UTC](https://discuss.elastic.co/t/that-is-an-error-from-the-auditbeat-client-any-solutions-to-fix-this-problem/204571 "2019-11-01T02:16:34Z")

</div>

root@dcim:~# auditbeat setup Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: \[Error connection to Elasticsearch https://172.16.5.199:9200: 401 Unauthorized: {"error":{"root\_cause":\[{"type…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=301)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=303)
