# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=305

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 306

---

## [Filebeat on Kubernetes EKS "file info is not identical with opened file. Aborting harvesting "](https://discuss.elastic.co/t/filebeat-on-kubernetes-eks-file-info-is-not-identical-with-opened-file-aborting-harvesting/204449)

<div class="topic-metadata">

**Author:** [@Babadofar](https://discuss.elastic.co/u/Babadofar)\
**Replies:** 4\
**Last updated:** [October 28, 2019, 11:47am UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-eks-file-info-is-not-identical-with-opened-file-aborting-harvesting/204449 "2019-10-28T11:47:16Z")

</div>

In a kubernetes cluster on Amazon EKS with heavy logging we find that there is some missing data from elasticsearch. Log rotation is set up on a 10MB schedule, which means log rotation sometimes happens every minute. No…

---

## [Unable to load beat dashboard with Beats](https://discuss.elastic.co/t/unable-to-load-beat-dashboard-with-beats/205317)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [October 28, 2019, 9:17am UTC](https://discuss.elastic.co/t/unable-to-load-beat-dashboard-with-beats/205317 "2019-10-28T09:17:43Z")

</div>

Hi all, using full stack on version 7.4 I'm not able to load the dashboard on Kibana using Winlogbeat. I have specified this section in my winlogbeat.yml ============================== Dashboards =====================…

---

## [Exiting: resource 'metricbeat-7.4.0' exists, but it is not an alias](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-4-0-exists-but-it-is-not-an-alias/204425)

<div class="topic-metadata">

**Author:** [@LiuGangR](https://discuss.elastic.co/u/LiuGangR)\
**Replies:** 6\
**Last updated:** [October 28, 2019, 6:17am UTC](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-4-0-exists-but-it-is-not-an-alias/204425 "2019-10-28T06:17:53Z")

</div>

I update my metricbeat from 7.1.0. It is ok. But today it didn't work. When I input this -'sudo metricbeat setup -e'; 2019-10-21T17:30:15.706+0800 INFO template/load.go:169 Existing template will be overwritten, as ov…

---

## [Change index name and policy name to use](https://discuss.elastic.co/t/change-index-name-and-policy-name-to-use/205406)

<div class="topic-metadata">

**Author:** [@elasticnubie](https://discuss.elastic.co/u/elasticnubie)\
**Replies:** 0\
**Last updated:** [October 28, 2019, 5:47am UTC](https://discuss.elastic.co/t/change-index-name-and-policy-name-to-use/205406 "2019-10-28T05:47:57Z")

</div>

I wanna change the index name and the lifecycle policy name to use of packetbeat to my own. index name: packetbeat-7.4.1-2019.10.28 to dns-2019.10.28 ILM Policy: packetbeat-7.4.1 to ilm-dns (I created) I first creat…

---

## [Dynamic log file](https://discuss.elastic.co/t/dynamic-log-file/205091)

<div class="topic-metadata">

**Author:** [@theo1991](https://discuss.elastic.co/u/theo1991)\
**Replies:** 2\
**Last updated:** [October 27, 2019, 2:01pm UTC](https://discuss.elastic.co/t/dynamic-log-file/205091 "2019-10-27T14:01:12Z")

</div>

Hi there, Is there any way to send dynamic log file (which are always changing, adding new lines, modyfing old ones etc ...) into elasticsearch to work on with kibana (visualize, dashboard etc ...) ? My problem is that…

---

## [Pfsense suricata fails to process alerts in elasticsearch via filebeat module](https://discuss.elastic.co/t/pfsense-suricata-fails-to-process-alerts-in-elasticsearch-via-filebeat-module/205349)

<div class="topic-metadata">

**Author:** [@Pedestrian](https://discuss.elastic.co/u/Pedestrian)\
**Replies:** 1\
**Last updated:** [October 27, 2019, 8:00am UTC](https://discuss.elastic.co/t/pfsense-suricata-fails-to-process-alerts-in-elasticsearch-via-filebeat-module/205349 "2019-10-27T08:00:48Z")

</div>

Using suricata 4.1.5 (eve json) from pfsense to redis -\> file -\> filebeat -\> logstash -\> elasticsearch The alerts and some other event types are not showing up in the filebeat index. logstash is also 7.3.2 in this case…

---

## [Doubt on Filebeat tcp input concept](https://discuss.elastic.co/t/doubt-on-filebeat-tcp-input-concept/202004)

<div class="topic-metadata">

**Author:** [@NicoForce](https://discuss.elastic.co/u/NicoForce)\
**Replies:** 1\
**Last updated:** [October 26, 2019, 8:33pm UTC](https://discuss.elastic.co/t/doubt-on-filebeat-tcp-input-concept/202004 "2019-10-26T20:33:09Z")

</div>

It's not quite clear to me from the docs how the tcp input works for filebeat, so I wanted to ask here. I have the following filebeat.yaml. filebeat.inputs: - type: tcp host: "localhost:5044" multiline.pattern: '^\[\[…

---

## [Filebeat Output to Heartbeat Index?](https://discuss.elastic.co/t/filebeat-output-to-heartbeat-index/205334)

<div class="topic-metadata">

**Author:** [@sdf301](https://discuss.elastic.co/u/sdf301)\
**Replies:** 0\
**Last updated:** [October 25, 2019, 11:12pm UTC](https://discuss.elastic.co/t/filebeat-output-to-heartbeat-index/205334 "2019-10-25T23:12:08Z")

</div>

I have a Hearbeat that checks system status around my network (as expected). I also have some shell scripts that check the status of various components around my network. Unfortunately, those components don't fit nicely …

---

## [Missing setup.kibana.space.id in documentation](https://discuss.elastic.co/t/missing-setup-kibana-space-id-in-documentation/205233)

<div class="topic-metadata">

**Author:** [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Replies:** 1\
**Last updated:** [October 25, 2019, 9:03pm UTC](https://discuss.elastic.co/t/missing-setup-kibana-space-id-in-documentation/205233 "2019-10-25T21:03:30Z")

</div>

Hi, I know the setting setup.kibana.space.id in beats configuration, but when I today copied a filebeat.reference.yml I noticed, that this setting is not in there (version 7.4.1). I checked with the reference files of o…

---

## [Filebeat pushs syslog logs to elasticsearch through Logstash](https://discuss.elastic.co/t/filebeat-pushs-syslog-logs-to-elasticsearch-through-logstash/205149)

<div class="topic-metadata">

**Author:** [@Vladpov](https://discuss.elastic.co/u/Vladpov)\
**Replies:** 3\
**Last updated:** [October 25, 2019, 8:53pm UTC](https://discuss.elastic.co/t/filebeat-pushs-syslog-logs-to-elasticsearch-through-logstash/205149 "2019-10-25T20:53:29Z")

</div>

Hi everyone! I'm trying to push syslog logs to elasticsearch by using Filebeat and Logstash. How should my configuration files look like? #=========================== Filebeat inputs ============================= file…

---

## [Heartbeat | Problem installing on Windows](https://discuss.elastic.co/t/heartbeat-problem-installing-on-windows/204686)

<div class="topic-metadata">

**Author:** [@andrezenun](https://discuss.elastic.co/u/andrezenun)\
**Replies:** 3\
**Last updated:** [October 25, 2019, 6:55pm UTC](https://discuss.elastic.co/t/heartbeat-problem-installing-on-windows/204686 "2019-10-25T18:55:36Z")

</div>

Hi, I'm trying to install heartbeat on a Windows 2012 Server and I got this error: The install script seams to be the same as the other beats. I have installed metricbeat and packetbeat on this same server! Any one g…

---

## [Cisco module, ES error too many dynamic script compilations within, max](https://discuss.elastic.co/t/cisco-module-es-error-too-many-dynamic-script-compilations-within-max/205139)

<div class="topic-metadata">

**Author:** [@JSkier](https://discuss.elastic.co/u/JSkier)\
**Replies:** 2\
**Last updated:** [October 25, 2019, 5:29pm UTC](https://discuss.elastic.co/t/cisco-module-es-error-too-many-dynamic-script-compilations-within-max/205139 "2019-10-25T17:29:56Z")

</div>

I had Cisco ASA logs coming in fine awhile ago (7.4.0). Then they just stopped, no parsing happens, and this error is everywhere: \[script\] Too many dynamic script compilations within, max: \[75/5m\]; please use indexed, …

---

## [Metricbeat 6.8.3 service on CentOS 7 failing to start automatically on reboot](https://discuss.elastic.co/t/metricbeat-6-8-3-service-on-centos-7-failing-to-start-automatically-on-reboot/205232)

<div class="topic-metadata">

**Author:** [@Mohit\_Kunjir](https://discuss.elastic.co/u/Mohit_Kunjir)\
**Replies:** 2\
**Last updated:** [October 25, 2019, 5:15pm UTC](https://discuss.elastic.co/t/metricbeat-6-8-3-service-on-centos-7-failing-to-start-automatically-on-reboot/205232 "2019-10-25T17:15:12Z")

</div>

This is my metricbeat.yml file name: Metricbeat-Monitor #================================= Paths ============================ path.home: /usr/share/metricbeat path.config: /etc/metricbeat path.data: /var/lib/metric…

---

## [Single line JSON file not being processed](https://discuss.elastic.co/t/single-line-json-file-not-being-processed/205287)

<div class="topic-metadata">

**Author:** [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Replies:** 1\
**Last updated:** [October 25, 2019, 4:00pm UTC](https://discuss.elastic.co/t/single-line-json-file-not-being-processed/205287 "2019-10-25T16:00:54Z")

</div>

Hi Team, I have Filebeat version 6.7.1 configured to read numerous JSON files as they come/go from a single directory. Some of the JSON files contain a single line with no newline character at the end. My problem is t…

---

## [Is it possible to mix json and plain text?](https://discuss.elastic.co/t/is-it-possible-to-mix-json-and-plain-text/205141)

<div class="topic-metadata">

**Author:** [@Mikael\_Elkiaer](https://discuss.elastic.co/u/Mikael_Elkiaer)\
**Replies:** 2\
**Last updated:** [October 25, 2019, 2:30pm UTC](https://discuss.elastic.co/t/is-it-possible-to-mix-json-and-plain-text/205141 "2019-10-25T14:30:44Z")

</div>

I use filebeat to grab my Docker logs. Most of these are plain text. However, for self-created services I like to use Serilog for structured logging and it therefore formats the logs in elasticsearch format. Is it possi…

---

## [Parsing custom date with Filebeat (or Logstash)](https://discuss.elastic.co/t/parsing-custom-date-with-filebeat-or-logstash/205201)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 2\
**Last updated:** [October 25, 2019, 1:51pm UTC](https://discuss.elastic.co/t/parsing-custom-date-with-filebeat-or-logstash/205201 "2019-10-25T13:51:27Z")

</div>

Hello, I have some logs that I want to sent into an Elastic index. Log lines examples : "1","O","I","190312 135108","E","165","1024000","FTP","GREENTRF","TST02","/home/gateway/","test054","TSTTST01","GREENTRF","TST02"…

---

## [Filebeat temp location when it cant send logs](https://discuss.elastic.co/t/filebeat-temp-location-when-it-cant-send-logs/205195)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 1\
**Last updated:** [October 25, 2019, 1:41pm UTC](https://discuss.elastic.co/t/filebeat-temp-location-when-it-cant-send-logs/205195 "2019-10-25T13:41:11Z")

</div>

hi , I am using elk stack of version 7.1.1 and i read logs from the console that my docker driver prints . Through filebeat I push them to the logstash and then to elastic but for the past 2 days due to some logstash e…

---

## [Zeek module](https://discuss.elastic.co/t/zeek-module/205264)

<div class="topic-metadata">

**Author:** [@tmans1991](https://discuss.elastic.co/u/tmans1991)\
**Replies:** 0\
**Last updated:** [October 25, 2019, 1:22pm UTC](https://discuss.elastic.co/t/zeek-module/205264 "2019-10-25T13:22:05Z")

</div>

Hello, my setup: in one server i log (with zeek) all data from the office network on the same server i filebeat this data from the /opt/zeek/spool/logger/\* to an other server with elastic and kibana i also use the z…

---

## [Exiting: error loading config file: stat filebeat.yml: no such file or directory](https://discuss.elastic.co/t/exiting-error-loading-config-file-stat-filebeat-yml-no-such-file-or-directory/205154)

<div class="topic-metadata">

**Author:** [@thurston](https://discuss.elastic.co/u/thurston)\
**Replies:** 2\
**Last updated:** [October 25, 2019, 12:58pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-stat-filebeat-yml-no-such-file-or-directory/205154 "2019-10-25T12:58:59Z")

</div>

Hello, I compiled filebeat from source to run on arm architecture. I successfully have filebeat running, but I have noticed that I can't just run filebeat command. ex. filebeat setup -e Contrary to normal filebeat ins…

---

## [Filebeat pipeline not being used 500 internal server error](https://discuss.elastic.co/t/filebeat-pipeline-not-being-used-500-internal-server-error/205258)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [October 25, 2019, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-pipeline-not-being-used-500-internal-server-error/205258 "2019-10-25T12:46:35Z")

</div>

ECE 2.3 v7.3.0 Filebeat 7.3 Were having trouble getting our Filebeat pipeline to work. We are currently able to establish a connection from Filebeat to our Elastic Cloud Enterprise cluster and send data when the pipe…

---

## [Kubernetes dashboard not showing some metrics when using 15 min interval](https://discuss.elastic.co/t/kubernetes-dashboard-not-showing-some-metrics-when-using-15-min-interval/205254)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 0\
**Last updated:** [October 25, 2019, 12:28pm UTC](https://discuss.elastic.co/t/kubernetes-dashboard-not-showing-some-metrics-when-using-15-min-interval/205254 "2019-10-25T12:28:44Z")

</div>

We have metricbeats reporting Kubernetes kube state metrics every 30s and have verified this when looking through the indexes. The dashboard that metricbeats creates that shows the number of deployments and pods, when se…

---

## [Filebeat 7.1 UDP + JSON](https://discuss.elastic.co/t/filebeat-7-1-udp-json/205115)

<div class="topic-metadata">

**Author:** [@Serg](https://discuss.elastic.co/u/Serg)\
**Replies:** 1\
**Last updated:** [October 25, 2019, 11:47am UTC](https://discuss.elastic.co/t/filebeat-7-1-udp-json/205115 "2019-10-25T11:47:27Z")

</div>

Hi I try to use such config to get data from my app. on UDP socket in JSON format. I hope it will help to mark all fields automatically (like in GELF driver) filebeat.inputs: - type: udp host: "localhost:9099" m…

---

## [Filebeat on windows not reading log file](https://discuss.elastic.co/t/filebeat-on-windows-not-reading-log-file/204663)

<div class="topic-metadata">

**Author:** [@computer\_engineer](https://discuss.elastic.co/u/computer_engineer)\
**Replies:** 1\
**Last updated:** [October 25, 2019, 11:38am UTC](https://discuss.elastic.co/t/filebeat-on-windows-not-reading-log-file/204663 "2019-10-25T11:38:31Z")

</div>

I am attempting to have filebeat read json packets from log files in a specific directory and send to elasticsearch directly, without using logstash. I got the filebeat service to start up but keeping the following messa…

---

## [Filebeat not logging to elasticsearch](https://discuss.elastic.co/t/filebeat-not-logging-to-elasticsearch/204037)

<div class="topic-metadata">

**Author:** [@whoatemyjam](https://discuss.elastic.co/u/whoatemyjam)\
**Replies:** 4\
**Last updated:** [October 25, 2019, 11:27am UTC](https://discuss.elastic.co/t/filebeat-not-logging-to-elasticsearch/204037 "2019-10-25T11:27:29Z")

</div>

Hi Please if someone can help with the issue will be highly appreciated we have openshift cluster 3.11 and trying to replace fluentd with filebeat. we have deployed filebeat 6.0 which is compatible with current es …

---

## [Load Balancing and Roaming with Winlogbeat](https://discuss.elastic.co/t/load-balancing-and-roaming-with-winlogbeat/205071)

<div class="topic-metadata">

**Author:** [@bosand](https://discuss.elastic.co/u/bosand)\
**Replies:** 1\
**Last updated:** [October 25, 2019, 11:17am UTC](https://discuss.elastic.co/t/load-balancing-and-roaming-with-winlogbeat/205071 "2019-10-25T11:17:21Z")

</div>

Hi, I would like to know whether Winlogbeat supports the following use case: Suppose I have 1000 machines that are configured with 2 Logstash output hosts A and B. I would like all traffic to be sent to A. When A beco…

---

## [Using Winlogbeat with Docker-Compose under Linux](https://discuss.elastic.co/t/using-winlogbeat-with-docker-compose-under-linux/205105)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 2\
**Last updated:** [October 25, 2019, 10:11am UTC](https://discuss.elastic.co/t/using-winlogbeat-with-docker-compose-under-linux/205105 "2019-10-25T10:11:26Z")

</div>

Hello, I'm currently trying to integrate Winlogbeat to my Docker-Compose-Stack, but I'm not really successful with it. The problem is, that I normally download the current Logstash or Filebeat version (referenced in my …

---

## [Way to send RDS mysql logs to Elastic](https://discuss.elastic.co/t/way-to-send-rds-mysql-logs-to-elastic/204987)

<div class="topic-metadata">

**Author:** [@akki2208](https://discuss.elastic.co/u/akki2208)\
**Replies:** 1\
**Last updated:** [October 25, 2019, 9:03am UTC](https://discuss.elastic.co/t/way-to-send-rds-mysql-logs-to-elastic/204987 "2019-10-25T09:03:04Z")

</div>

Hello Elastic Team, I am working with filebeat's MySQL module for a long time. but I can see that similar logs are generated at AWS rds also. So after the 7.4 beat release(s3 as input), I want to ingest those rds logs…

---

## [Estrange results in metricbeat docker dashboard](https://discuss.elastic.co/t/estrange-results-in-metricbeat-docker-dashboard/204628)

<div class="topic-metadata">

**Author:** [@juanarmentia](https://discuss.elastic.co/u/juanarmentia)\
**Replies:** 5\
**Last updated:** [October 25, 2019, 8:51am UTC](https://discuss.elastic.co/t/estrange-results-in-metricbeat-docker-dashboard/204628 "2019-10-25T08:51:25Z")

</div>

Hi, I have enabled the docker module of metricbeat and the dashboard shows estrange results. In the table of docker containers (left) shows 1 container, while in the number of containers element (right) shows 4 running.…

---

## [Heartbeat Won't Ignore SSL Verification](https://discuss.elastic.co/t/heartbeat-wont-ignore-ssl-verification/204472)

<div class="topic-metadata">

**Author:** [@sdf301](https://discuss.elastic.co/u/sdf301)\
**Replies:** 2\
**Last updated:** [October 25, 2019, 12:47am UTC](https://discuss.elastic.co/t/heartbeat-wont-ignore-ssl-verification/204472 "2019-10-25T00:47:58Z")

</div>

Hello all. Long time lurker, first time poster. Using Elastic Stack 7.4. I have spent the better part of the past 2 weeks setting up Heartbeats to monitor all of my internal systems and services. It was a ton of work b…

---

## [No indices match pattern "winlogbeat-\*"](https://discuss.elastic.co/t/no-indices-match-pattern-winlogbeat/205001)

<div class="topic-metadata">

**Author:** [@Rmodi](https://discuss.elastic.co/u/Rmodi)\
**Replies:** 3\
**Last updated:** [October 24, 2019, 9:48pm UTC](https://discuss.elastic.co/t/no-indices-match-pattern-winlogbeat/205001 "2019-10-24T21:48:12Z")

</div>

Hi, I have configured elasticsearch, logstash and kibana in Server Cent OS which IP is (10.200.14.36) and both working perfectly. Also, with filebeat in another Client Cent OS machine, I can able to get index and logs …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=304)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=306)
