# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=304

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 305

---

## [Filebeat too many open files using Docker autodiscover](https://discuss.elastic.co/t/filebeat-too-many-open-files-using-docker-autodiscover/205596)

<div class="topic-metadata">

**Author:** [@CpuID](https://discuss.elastic.co/u/CpuID)\
**Replies:** 1\
**Last updated:** [October 29, 2019, 11:01pm UTC](https://discuss.elastic.co/t/filebeat-too-many-open-files-using-docker-autodiscover/205596 "2019-10-29T23:01:27Z")

</div>

Seeing this on a machine that runs short lived containers every few minutes, seems to run out of file descriptors due to filebeat hanging onto connections to the Docker daemon socket? File descriptor leak? Takes a day o…

---

## [Need suggestions which is the best setup for our server landscape](https://discuss.elastic.co/t/need-suggestions-which-is-the-best-setup-for-our-server-landscape/205441)

<div class="topic-metadata">

**Author:** [@Christian\_Lorenz](https://discuss.elastic.co/u/Christian_Lorenz)\
**Replies:** 2\
**Last updated:** [October 29, 2019, 9:16pm UTC](https://discuss.elastic.co/t/need-suggestions-which-is-the-best-setup-for-our-server-landscape/205441 "2019-10-29T21:16:37Z")

</div>

Hi, our server setup looks like this: We've got an independent Ubuntu PC in our IT mainroom where I'm displaying the data (latest errors and so on...) and where logstash, elasticsearch and kibana are running on. I'm ca…

---

## [Filebeat "decode\_json\_fields" and nested fields](https://discuss.elastic.co/t/filebeat-decode-json-fields-and-nested-fields/205316)

<div class="topic-metadata">

**Author:** [@delphi](https://discuss.elastic.co/u/delphi)\
**Replies:** 4\
**Last updated:** [October 29, 2019, 8:38pm UTC](https://discuss.elastic.co/t/filebeat-decode-json-fields-and-nested-fields/205316 "2019-10-29T20:38:05Z")

</div>

Hi. I'm using Filebeat 7.4.0 and Google Pub/Sub as an input for reading Google App Engine exported logs. Although the processor "decode\_json\_fields" is working fine, I'm getting an issue with nested fields not mapped c…

---

## [Using filebeat syslog input for PANW. Logs not publishing to Kibana](https://discuss.elastic.co/t/using-filebeat-syslog-input-for-panw-logs-not-publishing-to-kibana/204565)

<div class="topic-metadata">

**Author:** [@ablanco722](https://discuss.elastic.co/u/ablanco722)\
**Replies:** 4\
**Last updated:** [October 29, 2019, 6:13pm UTC](https://discuss.elastic.co/t/using-filebeat-syslog-input-for-panw-logs-not-publishing-to-kibana/204565 "2019-10-29T18:13:00Z")

</div>

So I am trying to get the PANW module for filebeats running. Currently its configured to receive palo alto logs via UDP. When I set filebeat to run in debug I am seeing logs being parsed but yet its not showing up in kib…

---

## [Difficulty in enabling Netflow in Filebeat](https://discuss.elastic.co/t/difficulty-in-enabling-netflow-in-filebeat/205723)

<div class="topic-metadata">

**Author:** [@thebeaoliveira](https://discuss.elastic.co/u/thebeaoliveira)\
**Replies:** 0\
**Last updated:** [October 29, 2019, 4:53pm UTC](https://discuss.elastic.co/t/difficulty-in-enabling-netflow-in-filebeat/205723 "2019-10-29T16:53:06Z")

</div>

Hello! I am starting to test SIEM (v7.4.1) and have come across a bit of trouble enabling Netflow in Filebeat. I need to do a configuration in Linux (CentOS 7) and Windows Server environments. I can get the Filebeat s…

---

## [Not getting system.diskio.iostat.queue.avg\_size information](https://discuss.elastic.co/t/not-getting-system-diskio-iostat-queue-avg-size-information/205597)

<div class="topic-metadata">

**Author:** [@alokkumar](https://discuss.elastic.co/u/alokkumar)\
**Replies:** 1\
**Last updated:** [October 29, 2019, 3:26pm UTC](https://discuss.elastic.co/t/not-getting-system-diskio-iostat-queue-avg-size-information/205597 "2019-10-29T15:26:33Z")

</div>

I am trying to find average queue length of the requests that were issued to the device. But system.diskio.iostat.queue.avg\_size information is not showing in window os. I am also using Grafana to show them graphically. …

---

## [What is the difference between processor add\_fields and regular "fields:"](https://discuss.elastic.co/t/what-is-the-difference-between-processor-add-fields-and-regular-fields/205662)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 2\
**Last updated:** [October 29, 2019, 3:19pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-processor-add-fields-and-regular-fields/205662 "2019-10-29T15:19:58Z")

</div>

I am using filebeat (docker 7.4.1). 1)What is the difference between processor add\_fields and regular "fields:" Also, I am using autodiscover for nginx/mongo containers AND regular filebeat.input of type container fo…

---

## [Reading data from multiple namespaces in filebeat](https://discuss.elastic.co/t/reading-data-from-multiple-namespaces-in-filebeat/205655)

<div class="topic-metadata">

**Author:** [@whoatemyjam](https://discuss.elastic.co/u/whoatemyjam)\
**Replies:** 0\
**Last updated:** [October 29, 2019, 11:42am UTC](https://discuss.elastic.co/t/reading-data-from-multiple-namespaces-in-filebeat/205655 "2019-10-29T11:42:13Z")

</div>

hi How to add multiple namespaces in input kind: ConfigMap metadata: name: filebeat-inputs namespace: "{{ namespace }}" labels: k8s-app: filebeat data: kubernetes.yml: |- - type: docker containers…

---

## [How to add an event created time in Winlogbeat.yml for version 6.3](https://discuss.elastic.co/t/how-to-add-an-event-created-time-in-winlogbeat-yml-for-version-6-3/205674)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [October 29, 2019, 1:18pm UTC](https://discuss.elastic.co/t/how-to-add-an-event-created-time-in-winlogbeat-yml-for-version-6-3/205674 "2019-10-29T13:18:17Z")

</div>

Hi all, The goal is to have the event that the raw log from event viewer was first generated inside the windows event log. That way I will have two time stamps one from the pipeline @timestamp and a event\_created timest…

---

## [Filebeat not pushing to elastic - docker compose](https://discuss.elastic.co/t/filebeat-not-pushing-to-elastic-docker-compose/205427)

<div class="topic-metadata">

**Author:** [@Neal\_Derman](https://discuss.elastic.co/u/Neal_Derman)\
**Replies:** 5\
**Last updated:** [October 29, 2019, 1:06pm UTC](https://discuss.elastic.co/t/filebeat-not-pushing-to-elastic-docker-compose/205427 "2019-10-29T13:06:20Z")

</div>

I'm trying to get filebeat data to elastic. I've followed the instructions and I have filebeat running in a container. I'd ultimately like it to grab stdout from my other containers and push that to elastic.co but first …

---

## [Filebeat V7.4.1 output.elasticsearch not writing to defined index "logstash"](https://discuss.elastic.co/t/filebeat-v7-4-1-output-elasticsearch-not-writing-to-defined-index-logstash/205444)

<div class="topic-metadata">

**Author:** [@Ritzo](https://discuss.elastic.co/u/Ritzo)\
**Replies:** 5\
**Last updated:** [October 29, 2019, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-v7-4-1-output-elasticsearch-not-writing-to-defined-index-logstash/205444 "2019-10-29T12:46:55Z")

</div>

Hello The goal is to write the filebeat-Logs via the output.elasticsearch into the logstash index. We have done the following entry in the filebeat.yml setup.template: name: "logstash" pattern: "logstash-\*" output.e…

---

## [Should filebeat be installed on all the clients](https://discuss.elastic.co/t/should-filebeat-be-installed-on-all-the-clients/205635)

<div class="topic-metadata">

**Author:** [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Replies:** 1\
**Last updated:** [October 29, 2019, 12:28pm UTC](https://discuss.elastic.co/t/should-filebeat-be-installed-on-all-the-clients/205635 "2019-10-29T12:28:27Z")

</div>

Hi All, I have a doubt. For getting information from the client machines ( 5 separate different machines) Should I install filebeat on all this 5 machines or I install filebeat on the elasticserver and enable the mod…

---

## [Metricbeat in Virtual machine gives huge network traffic](https://discuss.elastic.co/t/metricbeat-in-virtual-machine-gives-huge-network-traffic/205647)

<div class="topic-metadata">

**Author:** [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Replies:** 1\
**Last updated:** [October 29, 2019, 11:03am UTC](https://discuss.elastic.co/t/metricbeat-in-virtual-machine-gives-huge-network-traffic/205647 "2019-10-29T11:03:09Z")

</div>

Hi, Recently I installed metricbeat on my servers and use a grafana multy metrics dashboard to show stats. Quite catchy, however the results were shocking. The network out traffic appeared to be near 2 TB/s . Quite a lo…

---

## ["Filebeat.prospectors has been removed"](https://discuss.elastic.co/t/filebeat-prospectors-has-been-removed/205563)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 1\
**Last updated:** [October 29, 2019, 11:01am UTC](https://discuss.elastic.co/t/filebeat-prospectors-has-been-removed/205563 "2019-10-29T11:01:07Z")

</div>

This is my filebeat.yml file content filebeat: prospectors: - paths: - C:/elk/\*.log input\_type: log multiline.pattern: '^\[0-9\]{4}-\[0-9\]{2}-\[0-9\]{2}' multiline.negate: true multiline.match: after output: logsta…

---

## [Filebeat6.2.1 logs are not collected intermittently](https://discuss.elastic.co/t/filebeat6-2-1-logs-are-not-collected-intermittently/205607)

<div class="topic-metadata">

**Author:** [@Tom\_Chen1](https://discuss.elastic.co/u/Tom_Chen1)\
**Replies:** 5\
**Last updated:** [October 29, 2019, 10:51am UTC](https://discuss.elastic.co/t/filebeat6-2-1-logs-are-not-collected-intermittently/205607 "2019-10-29T10:51:06Z")

</div>

I don't see any changes in the log for a long time 2019-10-29T07:25:38.891Z INFO \[monitoring\] log/log.go:124 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"tic…

---

## [Auditbeat - how to exclude outbound socket data](https://discuss.elastic.co/t/auditbeat-how-to-exclude-outbound-socket-data/205457)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 2\
**Last updated:** [October 29, 2019, 10:46am UTC](https://discuss.elastic.co/t/auditbeat-how-to-exclude-outbound-socket-data/205457 "2019-10-29T10:46:04Z")

</div>

Im hoping to reduce the amount of data that auditbeat is sending me for a specific host. Host in question is producing 5-10x more than any others. Is running zabbix-server so there are lots of outbound sockets. From the …

---

## [Moving from ELK to EFK](https://discuss.elastic.co/t/moving-from-elk-to-efk/204073)

<div class="topic-metadata">

**Author:** [@yavidor](https://discuss.elastic.co/u/yavidor)\
**Replies:** 2\
**Last updated:** [October 29, 2019, 9:21am UTC](https://discuss.elastic.co/t/moving-from-elk-to-efk/204073 "2019-10-29T09:21:23Z")

</div>

Hi! were moving our infra to containers and we wold like to use filebeat to send the logs directly to Elasticsearch from Filebeat, instead of going trough Logstash. In this process we might lose our logstash filtering a…

---

## [How to ingest logs if they differ from the default filebeat module](https://discuss.elastic.co/t/how-to-ingest-logs-if-they-differ-from-the-default-filebeat-module/205610)

<div class="topic-metadata">

**Author:** [@Muckis](https://discuss.elastic.co/u/Muckis)\
**Replies:** 0\
**Last updated:** [October 29, 2019, 8:05am UTC](https://discuss.elastic.co/t/how-to-ingest-logs-if-they-differ-from-the-default-filebeat-module/205610 "2019-10-29T08:05:45Z")

</div>

Hi, I'm importing postgreSql logs where the log format is different to what the filebeat-\>postgresql module is set to ingest, so elasticsearch contains none of the postgresql specific fields just the message and the def…

---

## [Filebeat install E: Unable to locate package filebeat](https://discuss.elastic.co/t/filebeat-install-e-unable-to-locate-package-filebeat/203921)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 9\
**Last updated:** [October 28, 2019, 11:43pm UTC](https://discuss.elastic.co/t/filebeat-install-e-unable-to-locate-package-filebeat/203921 "2019-10-28T23:43:43Z")

</div>

Following Install Filebeat 7.x, I typed these commands in this order- apt-get install apt-transport-https apt update apt install filebeat But the last command gave me the error shown in picture. I tried sudo rm /va…

---

## [New to this: Looking for Consulting Type Folks](https://discuss.elastic.co/t/new-to-this-looking-for-consulting-type-folks/205326)

<div class="topic-metadata">

**Author:** [@ELKNub](https://discuss.elastic.co/u/ELKNub)\
**Replies:** 4\
**Last updated:** [October 28, 2019, 8:12pm UTC](https://discuss.elastic.co/t/new-to-this-looking-for-consulting-type-folks/205326 "2019-10-28T20:12:09Z")

</div>

Hello Everyone! So I (through much effort and a kind soul on Reddit) finally got a full ELKStack setup up and running where by the ELKStack lives on a Windows Machine. (Microsoft house) The Logs/Data I care about is fro…

---

## [Create New Tag in Beats Central Management](https://discuss.elastic.co/t/create-new-tag-in-beats-central-management/201809)

<div class="topic-metadata">

**Author:** [@Himanshu\_Bhati](https://discuss.elastic.co/u/Himanshu_Bhati)\
**Replies:** 0\
**Last updated:** [October 1, 2019, 1:26pm UTC](https://discuss.elastic.co/t/create-new-tag-in-beats-central-management/201809 "2019-10-01T13:26:24Z")

</div>

Hi Team , i have a spacific filebeat.yml file, I want the new tag in Beats central management shoud be the same as the file . can you suggest. I am sharing the file details here. filebeat.inputs: - type: log paths:…

---

## [Adding docker swarm node name to events](https://discuss.elastic.co/t/adding-docker-swarm-node-name-to-events/205540)

<div class="topic-metadata">

**Author:** [@ndg](https://discuss.elastic.co/u/ndg)\
**Replies:** 0\
**Last updated:** [October 28, 2019, 7:15pm UTC](https://discuss.elastic.co/t/adding-docker-swarm-node-name-to-events/205540 "2019-10-28T19:15:16Z")

</div>

Hi! After a lot of work i managed to receive data from a Docker Swarm cluster from a apache-php microservice that i created and i can visualize it with Kibana but i have one extra thing to improve, which is the node name…

---

## [How to use/have just one address field in Netflow module regardless of IP version?](https://discuss.elastic.co/t/how-to-use-have-just-one-address-field-in-netflow-module-regardless-of-ip-version/205519)

<div class="topic-metadata">

**Author:** [@Jorge\_Correa](https://discuss.elastic.co/u/Jorge_Correa)\
**Replies:** 0\
**Last updated:** [October 28, 2019, 4:59pm UTC](https://discuss.elastic.co/t/how-to-use-have-just-one-address-field-in-netflow-module-regardless-of-ip-version/205519 "2019-10-28T16:59:44Z")

</div>

Hi! I was using the Logstash netflow module for a while. With ELK 7.4 I started to get some errors with UDP input and realized that Logstash Netflow Module was being deprecated. So, I installed Filebeat Netflow Module. H…

---

## [FIlebeat IPtables Module timezone wrong](https://discuss.elastic.co/t/filebeat-iptables-module-timezone-wrong/205467)

<div class="topic-metadata">

**Author:** [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Replies:** 0\
**Last updated:** [October 28, 2019, 1:04pm UTC](https://discuss.elastic.co/t/filebeat-iptables-module-timezone-wrong/205467 "2019-10-28T13:04:38Z")

</div>

I found that the pipeline in the iptables log ingest have some glitch in the timezone, with version 7.4.0, I have the document 7 hours next from my timezone. Since I check the date compare to syslog, I put the pipeline …

---

## [Can the "\_source" fields be dropped from events published by filebeat to ES](https://discuss.elastic.co/t/can-the-source-fields-be-dropped-from-events-published-by-filebeat-to-es/205476)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 3\
**Last updated:** [October 28, 2019, 4:32pm UTC](https://discuss.elastic.co/t/can-the-source-fields-be-dropped-from-events-published-by-filebeat-to-es/205476 "2019-10-28T16:32:13Z")

</div>

Hi I am using "add\_docker\_metadata" processor. And when I looked at events published to ES, I see most of the docker metadata common or duplicate under "\_source" as well as "docker" fields. Is there a way to eliminat…

---

## [Not the best first impression of new beats development](https://discuss.elastic.co/t/not-the-best-first-impression-of-new-beats-development/205272)

<div class="topic-metadata">

**Author:** [@rmauri](https://discuss.elastic.co/u/rmauri)\
**Replies:** 2\
**Last updated:** [October 28, 2019, 4:15pm UTC](https://discuss.elastic.co/t/not-the-best-first-impression-of-new-beats-development/205272 "2019-10-28T16:15:03Z")

</div>

Greetings, I am just gettings started with Elastic beats development. I have been developing with Golang for a few years and was excited to try to develop my first Helloworldbeat. I allocated a couple hours to the task. …

---

## [Heart beat 7.4 https post request](https://discuss.elastic.co/t/heart-beat-7-4-https-post-request/205150)

<div class="topic-metadata">

**Author:** [@sparashara](https://discuss.elastic.co/u/sparashara)\
**Replies:** 1\
**Last updated:** [October 28, 2019, 3:18pm UTC](https://discuss.elastic.co/t/heart-beat-7-4-https-post-request/205150 "2019-10-28T15:18:05Z")

</div>

Hi Everyone, I am trying to configure https POST URL in metric beat. Goal is to monitor api via uptime. When i test the url from post man it works perfectly but i configure same in yaml files in heartbeat it always says…

---

## [Packetbeat 7.2.0 and mongodb 4.0.12 - no "resource" and no "mongodb.fullCollectionName"](https://discuss.elastic.co/t/packetbeat-7-2-0-and-mongodb-4-0-12-no-resource-and-no-mongodb-fullcollectionname/205454)

<div class="topic-metadata">

**Author:** [@Maria\_Dorohin](https://discuss.elastic.co/u/Maria_Dorohin)\
**Replies:** 0\
**Last updated:** [October 28, 2019, 12:16pm UTC](https://discuss.elastic.co/t/packetbeat-7-2-0-and-mongodb-4-0-12-no-resource-and-no-mongodb-fullcollectionname/205454 "2019-10-28T12:16:04Z")

</div>

I am monitoring mongodb with packetbeat. I want to build dashboard in kibana with "Visualize" per collection name, but I don't see relevant values in "resource" or in "mongodb.fullCollectionName" in ellastic. The val…

---

## [Decode\_json\_fields and array](https://discuss.elastic.co/t/decode-json-fields-and-array/205218)

<div class="topic-metadata">

**Author:** [@granier](https://discuss.elastic.co/u/granier)\
**Replies:** 2\
**Last updated:** [October 28, 2019, 11:49am UTC](https://discuss.elastic.co/t/decode-json-fields-and-array/205218 "2019-10-28T11:49:13Z")

</div>

Hy, We use filbeat to store lgo messages in Json format and we use the processor decode\_json\_fields. We read this post Condition with decode\_json\_fields processor and this documentation Decode JSON fields. We get a pr…

---

## [Logging now working](https://discuss.elastic.co/t/logging-now-working/205463)

<div class="topic-metadata">

**Author:** [@whoatemyjam](https://discuss.elastic.co/u/whoatemyjam)\
**Replies:** 0\
**Last updated:** [October 28, 2019, 12:46pm UTC](https://discuss.elastic.co/t/logging-now-working/205463 "2019-10-28T12:46:47Z")

</div>

I am trying to enable logging in a filebeat pod and the filebeat setings are as below apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: "{{ namespace }}" labels: k8s-app: filebeat dat…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=303)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=305)
