# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=303

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 304

---

## [Is it possible to use enviromant variable in config for user](https://discuss.elastic.co/t/is-it-possible-to-use-enviromant-variable-in-config-for-user/205964)

<div class="topic-metadata">

**Author:** [@chersko](https://discuss.elastic.co/u/chersko)\
**Replies:** 4\
**Last updated:** [November 1, 2019, 1:40am UTC](https://discuss.elastic.co/t/is-it-possible-to-use-enviromant-variable-in-config-for-user/205964 "2019-11-01T01:40:21Z")

</div>

is possible to use a enviroment variable in the config for the user for example // cloud.auth: '{metrics\_uname}:{MW\_PWD}'

---

## [Issue reading from multiple config inputs](https://discuss.elastic.co/t/issue-reading-from-multiple-config-inputs/205854)

<div class="topic-metadata">

**Author:** [@Scott\_Strain](https://discuss.elastic.co/u/Scott_Strain)\
**Replies:** 2\
**Last updated:** [October 31, 2019, 7:54pm UTC](https://discuss.elastic.co/t/issue-reading-from-multiple-config-inputs/205854 "2019-10-31T19:54:32Z")

</div>

We are trying to use multiple filebeat.inputs using type log so we can write different topics to kafka hosts. Below are the configs and the logs #Main Config output.kafka: hosts: \["sitkafka342w88m7:9092","sitkafka343w…

---

## [ILM and using one index per Filebeat module](https://discuss.elastic.co/t/ilm-and-using-one-index-per-filebeat-module/205752)

<div class="topic-metadata">

**Author:** [@philraj](https://discuss.elastic.co/u/philraj)\
**Replies:** 2\
**Last updated:** [October 31, 2019, 7:42pm UTC](https://discuss.elastic.co/t/ilm-and-using-one-index-per-filebeat-module/205752 "2019-10-31T19:42:29Z")

</div>

Hi, Is there any way (without disabling ILM) to have Filebeat use a different index for each enabled module? This was easy before ILM by adding conditions to the output.elasticsearch.indices: setup.template.name: "logs…

---

## [Filebeat with AWS ES IAM Role authentication ...?](https://discuss.elastic.co/t/filebeat-with-aws-es-iam-role-authentication/206061)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 1\
**Last updated:** [October 31, 2019, 6:36pm UTC](https://discuss.elastic.co/t/filebeat-with-aws-es-iam-role-authentication/206061 "2019-10-31T18:36:44Z")

</div>

I am using filebeat-7.4.1 docker on AWS with AWS ES. It is my understanding that Filebeat doesn't support IAM authentication when used with AWS Elasticsearch service ? Is there any plan to support this in near future o…

---

## [Journalbeat and packetbeat config separation](https://discuss.elastic.co/t/journalbeat-and-packetbeat-config-separation/206057)

<div class="topic-metadata">

**Author:** [@micas](https://discuss.elastic.co/u/micas)\
**Replies:** 3\
**Last updated:** [October 31, 2019, 4:54pm UTC](https://discuss.elastic.co/t/journalbeat-and-packetbeat-config-separation/206057 "2019-10-31T16:54:15Z")

</div>

All the other beats support some sort of "conf.d/\*.yml" way of separating the configs. I cannot find documentation of journalbeat and packetbeat supporting a similar feature. Is it possible? how can it be done?

---

## [Winlogbeat Evt 4741 4742 4743 - Computer Management Events](https://discuss.elastic.co/t/winlogbeat-evt-4741-4742-4743-computer-management-events/206069)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 0\
**Last updated:** [October 31, 2019, 3:23pm UTC](https://discuss.elastic.co/t/winlogbeat-evt-4741-4742-4743-computer-management-events/206069 "2019-10-31T15:23:32Z")

</div>

Hi, I'm working now with Events related to creation, changing and deletion of computers in windows Active directory. In these events the fields TargetUserSID, TargetUserName and TargetDomainName represents the SID,Name…

---

## [Metricbeats system disk usage not showing when using 15 min interval](https://discuss.elastic.co/t/metricbeats-system-disk-usage-not-showing-when-using-15-min-interval/205267)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 2\
**Last updated:** [October 31, 2019, 3:22pm UTC](https://discuss.elastic.co/t/metricbeats-system-disk-usage-not-showing-when-using-15-min-interval/205267 "2019-10-31T15:22:26Z")

</div>

Looking at the dashboard created by metricbeats for system metrics, the gauge for disk usage does not display any value when using last 15 mins. When switching to an the last hour the gauge does display correctly. We hav…

---

## [Filebeat deleted indecies are getting recreated due to no log rotation policy](https://discuss.elastic.co/t/filebeat-deleted-indecies-are-getting-recreated-due-to-no-log-rotation-policy/206064)

<div class="topic-metadata">

**Author:** [@ankamraok](https://discuss.elastic.co/u/ankamraok)\
**Replies:** 0\
**Last updated:** [October 31, 2019, 2:51pm UTC](https://discuss.elastic.co/t/filebeat-deleted-indecies-are-getting-recreated-due-to-no-log-rotation-policy/206064 "2019-10-31T14:51:48Z")

</div>

Hi All, I have a log which can only rotate after reaching 100 MB,and this log is pretty slow and it might reaches 100 MB by 6 months,though it generates log messages every hour.it has 3 months data. I have a curator w…

---

## [FileBeat to logstash via IPv6 - cannot assign requested address](https://discuss.elastic.co/t/filebeat-to-logstash-via-ipv6-cannot-assign-requested-address/206039)

<div class="topic-metadata">

**Author:** [@dmdean](https://discuss.elastic.co/u/dmdean)\
**Replies:** 2\
**Last updated:** [October 31, 2019, 1:08pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-via-ipv6-cannot-assign-requested-address/206039 "2019-10-31T13:08:50Z")

</div>

Hi Folks An ELK/Beats noob here I'm trying to send audit log entries from the app server to an ELK server using filebeats (docker) These are the errors i'm seeing 2019-10-31T12:16:57.109Z INFO log/harvester.go:2…

---

## [Make one filebeat send data to elasticsearch and to logstash](https://discuss.elastic.co/t/make-one-filebeat-send-data-to-elasticsearch-and-to-logstash/206006)

<div class="topic-metadata">

**Author:** [@tmans1991](https://discuss.elastic.co/u/tmans1991)\
**Replies:** 2\
**Last updated:** [October 31, 2019, 12:01pm UTC](https://discuss.elastic.co/t/make-one-filebeat-send-data-to-elasticsearch-and-to-logstash/206006 "2019-10-31T12:01:06Z")

</div>

hello, i am currently sending some logfiles to elasticsearch using filebeat, filebeat is on one machine, and elastich on an other (elk) machine thats all working fine, but i want to send -using the same filebeat- dat…

---

## [Axis cameras and server Monitoring](https://discuss.elastic.co/t/axis-cameras-and-server-monitoring/205632)

<div class="topic-metadata">

**Author:** [@walid.z](https://discuss.elastic.co/u/walid.z)\
**Replies:** 2\
**Last updated:** [October 31, 2019, 11:18am UTC](https://discuss.elastic.co/t/axis-cameras-and-server-monitoring/205632 "2019-10-31T11:18:31Z")

</div>

Hello all, I'm new in elastic, and i would like to monitor and visualize logs from AXIS server ( camera server). there is any way to track the status of the Axis service if it's up or down.( windows service). Thank yo…

---

## [Fsusedsize in dbstats of mongodb](https://discuss.elastic.co/t/fsusedsize-in-dbstats-of-mongodb/205984)

<div class="topic-metadata">

**Author:** [@chandu5565](https://discuss.elastic.co/u/chandu5565)\
**Replies:** 1\
**Last updated:** [October 31, 2019, 10:14am UTC](https://discuss.elastic.co/t/fsusedsize-in-dbstats-of-mongodb/205984 "2019-10-31T10:14:51Z")

</div>

Hi, I am trying to show the fs size of mongodb. Which i can get by using statement in mongodb as db.stats(). But when I fetch the data using metricbeat mongodb module it is not fetching the fsusedsize, fstotal size. I …

---

## [Environment variable syntax problems for beats monitoring](https://discuss.elastic.co/t/environment-variable-syntax-problems-for-beats-monitoring/205867)

<div class="topic-metadata">

**Author:** [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Replies:** 1\
**Last updated:** [October 31, 2019, 8:34am UTC](https://discuss.elastic.co/t/environment-variable-syntax-problems-for-beats-monitoring/205867 "2019-10-31T08:34:57Z")

</div>

I'm trying to pass through the monitoring elasticsearch cluster hostname as an enterprise variable and set in the metricbeat.yml and filebeat.yml. The variable is: MONITORING\_ELASTICSEARCH=elk-001 Hardcoding the name …

---

## [PostgreSQL Module: What is the "EXPECTED" format (I.E. postgresql.conf settings)](https://discuss.elastic.co/t/postgresql-module-what-is-the-expected-format-i-e-postgresql-conf-settings/205916)

<div class="topic-metadata">

**Author:** [@Larry\_Rosenman](https://discuss.elastic.co/u/Larry_Rosenman)\
**Replies:** 2\
**Last updated:** [October 31, 2019, 7:50am UTC](https://discuss.elastic.co/t/postgresql-module-what-is-the-expected-format-i-e-postgresql-conf-settings/205916 "2019-10-31T07:50:11Z")

</div>

for the filebeat PostgreSQL module, what are the expected settings in postgresql.conf (for the PostgreSQL server) on the logging related parameters, Prefix, etc. I've searched and searched and would love to have this do…

---

## [Upgrade the Beats:Filebeat without Downtime](https://discuss.elastic.co/t/upgrade-the-beats-filebeat-without-downtime/204764)

<div class="topic-metadata">

**Author:** [@viratag261](https://discuss.elastic.co/u/viratag261)\
**Replies:** 2\
**Last updated:** [October 31, 2019, 7:07am UTC](https://discuss.elastic.co/t/upgrade-the-beats-filebeat-without-downtime/204764 "2019-10-31T07:07:24Z")

</div>

Hi, I need to upgrade my Filebeat from6.4.1 to 7.4.0. But the upgrade process requires to shut down the beats process. Is there any way that the logs for the time beats is down be served to Logstash.? I mean no loss of …

---

## [Logstash index created but no data in pipeline](https://discuss.elastic.co/t/logstash-index-created-but-no-data-in-pipeline/205955)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 1\
**Last updated:** [October 31, 2019, 3:47am UTC](https://discuss.elastic.co/t/logstash-index-created-but-no-data-in-pipeline/205955 "2019-10-31T03:47:01Z")

</div>

Logstash is creating index in elasticsearch but no data is sent. I think its because the logs file from Filebeat to Logstash isn't being sent. So my question is- how to check pipeline is created and data is being sent fr…

---

## [Exiting: Error in initing input: No paths were defined for input accessing 'filebeat.inputs.0' (source:'filebeat.yml')](https://discuss.elastic.co/t/exiting-error-in-initing-input-no-paths-were-defined-for-input-accessing-filebeat-inputs-0-source-filebeat-yml/205550)

<div class="topic-metadata">

**Author:** [@mridula\_guuds](https://discuss.elastic.co/u/mridula_guuds)\
**Replies:** 2\
**Last updated:** [October 30, 2019, 10:16pm UTC](https://discuss.elastic.co/t/exiting-error-in-initing-input-no-paths-were-defined-for-input-accessing-filebeat-inputs-0-source-filebeat-yml/205550 "2019-10-30T22:16:19Z")

</div>

\[d3p@d3papp-po-a1p filebeat\]$ ./filebeat -e -d "\*" 2019-10-28T21:06:20.221Z INFO instance/beat.go:492 Home path: \[/home/d3p/filebeat\] Config path: \[/home/d3p/filebeat\] Data path: \[/home/d3p/filebeat/data\] L…

---

## [Standalone cluster using new parameter beat-xpack in metricbeat](https://discuss.elastic.co/t/standalone-cluster-using-new-parameter-beat-xpack-in-metricbeat/205820)

<div class="topic-metadata">

**Author:** [@Christophe\_Journel](https://discuss.elastic.co/u/Christophe_Journel)\
**Replies:** 7\
**Last updated:** [October 30, 2019, 9:23pm UTC](https://discuss.elastic.co/t/standalone-cluster-using-new-parameter-beat-xpack-in-metricbeat/205820 "2019-10-30T21:23:16Z")

</div>

Hello, I have multiple filebeat on several cluster. The monitoring is done by using beat-xpack feature from metricbeat on another server, using the HTTP entry point on each filebeat. However, Metricbeat ( with a correc…

---

## [Kubernetes Hints-based Autodiscover: Excluding a namespace](https://discuss.elastic.co/t/kubernetes-hints-based-autodiscover-excluding-a-namespace/205948)

<div class="topic-metadata">

**Author:** [@doug\_shareablee](https://discuss.elastic.co/u/doug_shareablee)\
**Replies:** 0\
**Last updated:** [October 30, 2019, 9:03pm UTC](https://discuss.elastic.co/t/kubernetes-hints-based-autodiscover-excluding-a-namespace/205948 "2019-10-30T21:03:43Z")

</div>

I'm using the hints-based autodiscover, and I'm wondering if there is a way to automatically exclude all pods in a given namespace. I'd prefer not to have to go annotate all of the pods in the namespace, if possible. I t…

---

## [Install-service-auditbeat -\> Status: Stopped](https://discuss.elastic.co/t/install-service-auditbeat-status-stopped/204901)

<div class="topic-metadata">

**Author:** [@akuninja](https://discuss.elastic.co/u/akuninja)\
**Replies:** 1\
**Last updated:** [October 30, 2019, 4:40pm UTC](https://discuss.elastic.co/t/install-service-auditbeat-status-stopped/204901 "2019-10-30T16:40:00Z")

</div>

My installation is always stopped. I have already enabled running unsigned scripts by entering this to PS: set-executionpolicy remotesigned The prtsc of the PS output attached.

---

## [Filebeat decode\_json\_fields isn't parssing arrays](https://discuss.elastic.co/t/filebeat-decode-json-fields-isnt-parssing-arrays/205677)

<div class="topic-metadata">

**Author:** [@B.M](https://discuss.elastic.co/u/B.M)\
**Replies:** 2\
**Last updated:** [October 29, 2019, 4:12pm UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-isnt-parssing-arrays/205677 "2019-10-29T16:12:28Z")

</div>

Hi, We are using filbeat processor decode\_json-fields to process log messages in Json. The problem we're having is that some of our logs are multi-layered with quite a few arrays and some nested objects. We tried using…

---

## [Why kafka event key must be unique?](https://discuss.elastic.co/t/why-kafka-event-key-must-be-unique/205330)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 2\
**Last updated:** [October 30, 2019, 4:05pm UTC](https://discuss.elastic.co/t/why-kafka-event-key-must-be-unique/205330 "2019-10-30T16:05:34Z")

</div>

I read the following from the manual. However, i could not seem to find this requirement from apache kafka documentation? We would like to use hostname + source filename to be kafka event key, which is definitely not u…

---

## [Node hostname on filebeat events](https://discuss.elastic.co/t/node-hostname-on-filebeat-events/205673)

<div class="topic-metadata">

**Author:** [@ndg](https://discuss.elastic.co/u/ndg)\
**Replies:** 5\
**Last updated:** [October 30, 2019, 3:53pm UTC](https://discuss.elastic.co/t/node-hostname-on-filebeat-events/205673 "2019-10-30T15:53:11Z")

</div>

I created a post yesterday and i can't find it, so i hope this isn't flag as repost. I wanted to know if there was a way for filebeat to send specific metada from the node because right now i am getting a nod id for each…

---

## [Index for NETFLOW Filebeat module](https://discuss.elastic.co/t/index-for-netflow-filebeat-module/205885)

<div class="topic-metadata">

**Author:** [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Replies:** 0\
**Last updated:** [October 30, 2019, 2:49pm UTC](https://discuss.elastic.co/t/index-for-netflow-filebeat-module/205885 "2019-10-30T14:49:02Z")

</div>

Hi, i have two filebeat modules (kafka and netflow) enable. How to configure netflow module to write data to a different index? Thanks

---

## [Incorrect multiline flag detected](https://discuss.elastic.co/t/incorrect-multiline-flag-detected/205529)

<div class="topic-metadata">

**Author:** [@madjohnw](https://discuss.elastic.co/u/madjohnw)\
**Replies:** 5\
**Last updated:** [October 30, 2019, 2:35pm UTC](https://discuss.elastic.co/t/incorrect-multiline-flag-detected/205529 "2019-10-30T14:35:19Z")

</div>

I am adding SQL Server error log files to logstash using filebeat. Some of the log entries are getting combined into a single event, even though they are on separate lines on the log file. The only difference I can see…

---

## [Error connecting to Elasticsearch messages while starting filebeat](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806)

<div class="topic-metadata">

**Author:** [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Replies:** 4\
**Last updated:** [October 30, 2019, 11:12am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806 "2019-10-30T11:12:21Z")

</div>

Dear All, my instance details are Kibana version: 7.4.1 Elasticsearch version: 7.4.1 \*\*filebeat version \*\* 7.4.1 APM Agent language and version: NA Logstash version 7.4.1-1 From my clients, I can telnet to…

---

## [Filebeat - "Cannot index event publisher"](https://discuss.elastic.co/t/filebeat-cannot-index-event-publisher/205793)

<div class="topic-metadata">

**Author:** [@IwanHSKY](https://discuss.elastic.co/u/IwanHSKY)\
**Replies:** 0\
**Last updated:** [October 30, 2019, 5:31am UTC](https://discuss.elastic.co/t/filebeat-cannot-index-event-publisher/205793 "2019-10-30T05:31:40Z")

</div>

Hello everyone, I use ELK Stack in Docker. I try send logs from Java app in Docker. I Tested 7.4.0, and 7.4.1 versions. Send logs with filebeat to ES; Config Filebeat for ES Filebeat.yml# Modules configuration == …

---

## [Metricbeat 7.4 Kubernetes crash on startup](https://discuss.elastic.co/t/metricbeat-7-4-kubernetes-crash-on-startup/205479)

<div class="topic-metadata">

**Author:** [@David\_Jones](https://discuss.elastic.co/u/David_Jones)\
**Replies:** 2\
**Last updated:** [October 30, 2019, 9:53am UTC](https://discuss.elastic.co/t/metricbeat-7-4-kubernetes-crash-on-startup/205479 "2019-10-30T09:53:17Z")

</div>

I've been trying to run metricbeat on kubernetes according to the docs but the singleton instance is crashing on startup. Instance Logs Deployment The deployment is identical to the one given in the documentation, exc…

---

## [Filebeat syslog input to filebeat system](https://discuss.elastic.co/t/filebeat-syslog-input-to-filebeat-system/204515)

<div class="topic-metadata">

**Author:** [@gborg](https://discuss.elastic.co/u/gborg)\
**Replies:** 2\
**Last updated:** [October 30, 2019, 8:35am UTC](https://discuss.elastic.co/t/filebeat-syslog-input-to-filebeat-system/204515 "2019-10-30T08:35:23Z")

</div>

Hello. I have some servers running filebeat and I really like the system module, especially the ssh/auth parts of it. if I have a filebeat syslog UDP reciever running and send syslog event's to it, I would like them to…

---

## [Select template for different types of logs in Filebeat](https://discuss.elastic.co/t/select-template-for-different-types-of-logs-in-filebeat/205207)

<div class="topic-metadata">

**Author:** [@flowsys](https://discuss.elastic.co/u/flowsys)\
**Replies:** 2\
**Last updated:** [October 30, 2019, 7:45am UTC](https://discuss.elastic.co/t/select-template-for-different-types-of-logs-in-filebeat/205207 "2019-10-30T07:45:53Z")

</div>

How do I configure in filebeat.yml to select different index template based on different type of filebeat inputs configured? I was trying as below, didnt work: filebeat.inputs: - type: log enabled: true paths: - /…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=302)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=304)
