# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=306

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 307

---

## [Filebeat 7.3.2 Cisco Module Parsing issue for ASA Syslog rfc3164](https://discuss.elastic.co/t/filebeat-7-3-2-cisco-module-parsing-issue-for-asa-syslog-rfc3164/204554)

<div class="topic-metadata">

**Author:** [@thurston](https://discuss.elastic.co/u/thurston)\
**Replies:** 2\
**Last updated:** [October 24, 2019, 8:46pm UTC](https://discuss.elastic.co/t/filebeat-7-3-2-cisco-module-parsing-issue-for-asa-syslog-rfc3164/204554 "2019-10-24T20:46:53Z")

</div>

Getting Error from Filebeat 7.3.2 related to CISCO module. Sending Cisco ASA logs to Filebeat / Cisco module. I have read several threads here on elastic, stackoverflow, and other random sites. Not finding a clear sol…

---

## [Include name of downed monitor in XPack alert](https://discuss.elastic.co/t/include-name-of-downed-monitor-in-xpack-alert/204573)

<div class="topic-metadata">

**Author:** [@jmadkins](https://discuss.elastic.co/u/jmadkins)\
**Replies:** 1\
**Last updated:** [October 24, 2019, 8:37pm UTC](https://discuss.elastic.co/t/include-name-of-downed-monitor-in-xpack-alert/204573 "2019-10-24T20:37:59Z")

</div>

Following this guide, I have a work alert to OpsGenie when a monitor goes down. However, the alert the is generated is so unhelpful and requires logging into Kibana. Is there a way to customize the title of the alert th…

---

## [Is it possible to define the shared properties between different filebeat inputs just once?](https://discuss.elastic.co/t/is-it-possible-to-define-the-shared-properties-between-different-filebeat-inputs-just-once/204758)

<div class="topic-metadata">

**Author:** [@SeaUser](https://discuss.elastic.co/u/SeaUser)\
**Replies:** 2\
**Last updated:** [October 24, 2019, 7:08pm UTC](https://discuss.elastic.co/t/is-it-possible-to-define-the-shared-properties-between-different-filebeat-inputs-just-once/204758 "2019-10-24T19:08:37Z")

</div>

I have a filebeat.yml file, in which I want to define multiple filebeat inputs. I understand each input needs to be configured separately, but that would be sub-optimal in my opinion, since I could re-use a lot of proper…

---

## [How do I delete the registry on a Windows Service?](https://discuss.elastic.co/t/how-do-i-delete-the-registry-on-a-windows-service/205120)

<div class="topic-metadata">

**Author:** [@mhare](https://discuss.elastic.co/u/mhare)\
**Replies:** 1\
**Last updated:** [October 24, 2019, 5:09pm UTC](https://discuss.elastic.co/t/how-do-i-delete-the-registry-on-a-windows-service/205120 "2019-10-24T17:09:37Z")

</div>

While developing my Filebeat fed pipelines, I find a need to delete the Filebeat registry from time to time to force a re-read of all the data. When I was running Filebeat from the command line it was easy, there is a '…

---

## [Retrofitting Filebeat into my ELK stack](https://discuss.elastic.co/t/retrofitting-filebeat-into-my-elk-stack/203282)

<div class="topic-metadata">

**Author:** [@mhare](https://discuss.elastic.co/u/mhare)\
**Replies:** 8\
**Last updated:** [October 24, 2019, 4:47pm UTC](https://discuss.elastic.co/t/retrofitting-filebeat-into-my-elk-stack/203282 "2019-10-24T16:47:22Z")

</div>

I am ingesting 8 different CSV file schemas using 8 logstash pipelines and reading from a Windows file share. IT has been recommending to not read across the file share but use Filebeat. Not finding just a whole bunch o…

---

## [Heartbeat Monitoring for Windows Servers](https://discuss.elastic.co/t/heartbeat-monitoring-for-windows-servers/202227)

<div class="topic-metadata">

**Author:** [@Marcell0e](https://discuss.elastic.co/u/Marcell0e)\
**Replies:** 2\
**Last updated:** [October 24, 2019, 12:45pm UTC](https://discuss.elastic.co/t/heartbeat-monitoring-for-windows-servers/202227 "2019-10-24T12:45:12Z")

</div>

I have tried to setup heartbeat monitoring for windows servers. I have setup IMCP through the Module.d folder. The heartbeat service starts and shows the server as up. I can power down the server and the monitor still…

---

## [Elasticsearch index creation](https://discuss.elastic.co/t/elasticsearch-index-creation/204632)

<div class="topic-metadata">

**Author:** [@france](https://discuss.elastic.co/u/france)\
**Replies:** 2\
**Last updated:** [October 24, 2019, 8:58am UTC](https://discuss.elastic.co/t/elasticsearch-index-creation/204632 "2019-10-24T08:58:14Z")

</div>

I have problems with elasticsearch index creation with filebeat. I installed all the other beats on ubuntu 19.04 server and all theese beats created the index in elasticsearch. I installed in the same way filebeat and t…

---

## [Documentation Error for Metricbeat system.diskio.iostat.request.avg\_size](https://discuss.elastic.co/t/documentation-error-for-metricbeat-system-diskio-iostat-request-avg-size/204945)

<div class="topic-metadata">

**Author:** [@dnwobu](https://discuss.elastic.co/u/dnwobu)\
**Replies:** 1\
**Last updated:** [October 24, 2019, 7:47am UTC](https://discuss.elastic.co/t/documentation-error-for-metricbeat-system-diskio-iostat-request-avg-size/204945 "2019-10-24T07:47:43Z")

</div>

The value calculated in https://github.com/elastic/beats/blob/master/metricbeat/module/system/diskio/diskstat\_linux\_test.go line 88 does not align with the documentation: https://www.elastic.co/guide/en/beats/metricbeat…

---

## [Metricbeat ElasticSearch Module problem](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-problem/204652)

<div class="topic-metadata">

**Author:** [@rajuleo](https://discuss.elastic.co/u/rajuleo)\
**Replies:** 1\
**Last updated:** [October 24, 2019, 7:40am UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-problem/204652 "2019-10-24T07:40:29Z")

</div>

Hi Team, We are running metricbeat on kubernetes and we enabled the elasticsearch module with below metrics: - node - node\_stats - index - index\_recovery - index\_summary - shard - ml\_job But we are receiving metrics o…

---

## [What is the difference between "-oss" and regular docker images](https://discuss.elastic.co/t/what-is-the-difference-between-oss-and-regular-docker-images/205000)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 1\
**Last updated:** [October 24, 2019, 6:01am UTC](https://discuss.elastic.co/t/what-is-the-difference-between-oss-and-regular-docker-images/205000 "2019-10-24T06:01:45Z")

</div>

What are the differences in terms of features and more importantly, are there different validations/ checks etc with one over the other ?. I am using filebeat with kibana and elasticsearch. ( all docker containers with…

---

## [Anyone experienced with this issue?](https://discuss.elastic.co/t/anyone-experienced-with-this-issue/204980)

<div class="topic-metadata">

**Author:** [@pbona](https://discuss.elastic.co/u/pbona)\
**Replies:** 1\
**Last updated:** [October 24, 2019, 2:58am UTC](https://discuss.elastic.co/t/anyone-experienced-with-this-issue/204980 "2019-10-24T02:58:54Z")

</div>

\[root@elastic ~\]# auditbeat setup --dashboards Loading dashboards (Kibana must be running and reachable) Exiting: Failed to import dashboard: Failed to load directory /usr/share/auditbeat/kibana/7/dashboard: error loa…

---

## [Filebeat sends duplicate log](https://discuss.elastic.co/t/filebeat-sends-duplicate-log/204926)

<div class="topic-metadata">

**Author:** [@Pepper\_Pam](https://discuss.elastic.co/u/Pepper_Pam)\
**Replies:** 3\
**Last updated:** [October 23, 2019, 11:44pm UTC](https://discuss.elastic.co/t/filebeat-sends-duplicate-log/204926 "2019-10-23T23:44:08Z")

</div>

I used filebeat to connect Kafka, and I noticed that everytime I updated the log file, the filebeat will send duplicate content to the Kafka. Any help to change that?

---

## [Filebeats not dropping agent.\* fields](https://discuss.elastic.co/t/filebeats-not-dropping-agent-fields/204907)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 3\
**Last updated:** [October 23, 2019, 8:47pm UTC](https://discuss.elastic.co/t/filebeats-not-dropping-agent-fields/204907 "2019-10-23T20:47:24Z")

</div>

We are using filebeats 7.4.0 in a k8s cluster to ship logs to ES, however when specifying a processor to drop the agent.\* fields they are still sent to ES. Config is as follows: filebeat.inputs: - type: docker …

---

## [Index from Central Management ES-Cloud](https://discuss.elastic.co/t/index-from-central-management-es-cloud/197886)

<div class="topic-metadata">

**Author:** [@meyerf99](https://discuss.elastic.co/u/meyerf99)\
**Replies:** 1\
**Last updated:** [October 23, 2019, 6:59pm UTC](https://discuss.elastic.co/t/index-from-central-management-es-cloud/197886 "2019-10-23T18:59:48Z")

</div>

Hello Community First of all I want to say that I'm new with ELK stack and full log mgmt. Hope someone can help me. We use the full Elastic Stack from the ES-Cloud (AWS). Now I want to bring some application logs fro…

---

## [Filebeat sending the whole log again](https://discuss.elastic.co/t/filebeat-sending-the-whole-log-again/204886)

<div class="topic-metadata">

**Author:** [@jeto.abialinti](https://discuss.elastic.co/u/jeto.abialinti)\
**Replies:** 3\
**Last updated:** [October 23, 2019, 6:03pm UTC](https://discuss.elastic.co/t/filebeat-sending-the-whole-log-again/204886 "2019-10-23T18:03:14Z")

</div>

I encounter a bug on filebeat, Filebeat sending the whole log again Is there a way for filebeat not to read log history so far, but rather for the last 60 to 100 lines?

---

## [Can't configure filebeat to only send new added log content](https://discuss.elastic.co/t/cant-configure-filebeat-to-only-send-new-added-log-content/204927)

<div class="topic-metadata">

**Author:** [@Pepper\_Pam](https://discuss.elastic.co/u/Pepper_Pam)\
**Replies:** 1\
**Last updated:** [October 23, 2019, 5:43pm UTC](https://discuss.elastic.co/t/cant-configure-filebeat-to-only-send-new-added-log-content/204927 "2019-10-23T17:43:51Z")

</div>

I used filebeat to connect to Kafka. Everytime I add some new lines to the log file, I want filebeat only output this contents to Kafka. My Input of filebeat.yml as below: filebeat.inputs: type: log enabled: true …

---

## [Filebeat is harvesting the wrong files](https://discuss.elastic.co/t/filebeat-is-harvesting-the-wrong-files/204453)

<div class="topic-metadata">

**Author:** [@Tompson](https://discuss.elastic.co/u/Tompson)\
**Replies:** 3\
**Last updated:** [October 23, 2019, 5:14pm UTC](https://discuss.elastic.co/t/filebeat-is-harvesting-the-wrong-files/204453 "2019-10-23T17:14:59Z")

</div>

I'm using filebeat on a debian 10 to ship logfiles directly to elasticsearch und use kibana as the GUI to display an filter those files, as it's supposed to be. The problem is, that the configurations i make doesnt have …

---

## [Importing data files into already created index](https://discuss.elastic.co/t/importing-data-files-into-already-created-index/204675)

<div class="topic-metadata">

**Author:** [@computer\_engineer](https://discuss.elastic.co/u/computer_engineer)\
**Replies:** 1\
**Last updated:** [October 23, 2019, 4:06pm UTC](https://discuss.elastic.co/t/importing-data-files-into-already-created-index/204675 "2019-10-23T16:06:56Z")

</div>

I have been having issues getting filebeat to work and opted to import the data using files into elasticsearch. However it looks like it is not possible to import into an existing created index. Is this true or is there …

---

## [Metricbeat on Kubernetes not reporting correct hostname](https://discuss.elastic.co/t/metricbeat-on-kubernetes-not-reporting-correct-hostname/204870)

<div class="topic-metadata">

**Author:** [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Replies:** 2\
**Last updated:** [October 23, 2019, 4:03pm UTC](https://discuss.elastic.co/t/metricbeat-on-kubernetes-not-reporting-correct-hostname/204870 "2019-10-23T16:03:57Z")

</div>

I have deployed metricbeat into a k8s cluster using the elastic helm chart however in kibana inventory the hostname is showing as the pod name and not the actual hostname for the node. The only change to the default conf…

---

## [Elapsed filter with filebeat](https://discuss.elastic.co/t/elapsed-filter-with-filebeat/204633)

<div class="topic-metadata">

**Author:** [@Alisa\_Faingold](https://discuss.elastic.co/u/Alisa_Faingold)\
**Replies:** 1\
**Last updated:** [October 23, 2019, 3:56pm UTC](https://discuss.elastic.co/t/elapsed-filter-with-filebeat/204633 "2019-10-23T15:56:37Z")

</div>

Hi, I used to work with elasticsearch, locally on my computer (using 'file' as input) and now we moved to work with filebeat and with 'S3' as input. Until now everything worked just fine with the elapsed filter, but no…

---

## [Can't specify custom index name in Filebeat](https://discuss.elastic.co/t/cant-specify-custom-index-name-in-filebeat/204643)

<div class="topic-metadata">

**Author:** [@Devopsio](https://discuss.elastic.co/u/Devopsio)\
**Replies:** 3\
**Last updated:** [October 23, 2019, 3:47pm UTC](https://discuss.elastic.co/t/cant-specify-custom-index-name-in-filebeat/204643 "2019-10-23T15:47:30Z")

</div>

Hi. I'm struggling to separate log inputs by using indices in Filebeat, which sends its data to elasticsearch from docker containers. It creates an index with a default name. I tried to use setup.ilm.enabed: false to dis…

---

## [Add\_field per instance of permon metricset](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 4\
**Last updated:** [October 23, 2019, 2:03pm UTC](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670 "2019-10-23T14:03:05Z")

</div>

Hello, The following does not seem to work? - module: windows metricsets: \[perfmon\] period: 10s perfmon.ignore\_non\_existent\_counters: true perfmon.group\_measurements\_by\_instance: true perfmon.counters: - …

---

## [Filebeat Error Failed to publish events write tcp](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events-write-tcp/204651)

<div class="topic-metadata">

**Author:** [@Neropointer](https://discuss.elastic.co/u/Neropointer)\
**Replies:** 1\
**Last updated:** [October 23, 2019, 1:54pm UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events-write-tcp/204651 "2019-10-23T13:54:38Z")

</div>

I am new to the whole Elasticsearch Topic and having some starter problems. I tried to search and find a solution on this topic in the Forum but couldnt find anything that could help me with it. I hope somebody can help …

---

## [Beats Mass installation](https://discuss.elastic.co/t/beats-mass-installation/204620)

<div class="topic-metadata">

**Author:** [@a.gavric](https://discuss.elastic.co/u/a.gavric)\
**Replies:** 2\
**Last updated:** [October 23, 2019, 10:47am UTC](https://discuss.elastic.co/t/beats-mass-installation/204620 "2019-10-23T10:47:03Z")

</div>

Hello Everyone, i am preparing for a Production deployment for elasticstack that will be used for Centralized Log-management. Now the question i have is one i was unable to find an answer for and is as follows: Is there …

---

## [Filebeat stop collecting the container logs while the service keeps running!](https://discuss.elastic.co/t/filebeat-stop-collecting-the-container-logs-while-the-service-keeps-running/203596)

<div class="topic-metadata">

**Author:** [@Suresh\_Pal](https://discuss.elastic.co/u/Suresh_Pal)\
**Replies:** 4\
**Last updated:** [October 23, 2019, 8:52am UTC](https://discuss.elastic.co/t/filebeat-stop-collecting-the-container-logs-while-the-service-keeps-running/203596 "2019-10-23T08:52:19Z")

</div>

Hi team, Filebeat stop collecting the container logs while the service keeps running !! When i restart the service it again start collecting . PFA filebeat.yml filebeat.prospectors: Each - is a prospector. Most optio…

---

## [Send Metricbeat measurements to another server (not Kibana/Logstash)](https://discuss.elastic.co/t/send-metricbeat-measurements-to-another-server-not-kibana-logstash/204660)

<div class="topic-metadata">

**Author:** [@Dimitris\_S](https://discuss.elastic.co/u/Dimitris_S)\
**Replies:** 1\
**Last updated:** [October 22, 2019, 2:42pm UTC](https://discuss.elastic.co/t/send-metricbeat-measurements-to-another-server-not-kibana-logstash/204660 "2019-10-22T14:42:31Z")

</div>

Hi there, I'm using Metricbeat on a Raspi but I would like to forward the measurements not in Kibana but to a different server. Output should be preferably in JSON format or other well-structured formats. Is there a way…

---

## [Index management : change index name in filebeat](https://discuss.elastic.co/t/index-management-change-index-name-in-filebeat/202876)

<div class="topic-metadata">

**Author:** [@icirco](https://discuss.elastic.co/u/icirco)\
**Replies:** 5\
**Last updated:** [October 22, 2019, 2:17pm UTC](https://discuss.elastic.co/t/index-management-change-index-name-in-filebeat/202876 "2019-10-22T14:17:28Z")

</div>

hello, I try to change the index name in filebeat.yml but when I start the filebeat, it still running on the oldest conf : filebeat.yml : output.elasticsearch: hosts: \["xx.xx.xx.xx:9200"\] #index: "filebeat-%{\[agent.…

---

## [Filebeats with postgresql module, custom log\_line\_prefix](https://discuss.elastic.co/t/filebeats-with-postgresql-module-custom-log-line-prefix/204457)

<div class="topic-metadata">

**Author:** [@mashuma](https://discuss.elastic.co/u/mashuma)\
**Replies:** 3\
**Last updated:** [October 22, 2019, 1:59pm UTC](https://discuss.elastic.co/t/filebeats-with-postgresql-module-custom-log-line-prefix/204457 "2019-10-22T13:59:13Z")

</div>

Hello, I'm struggling to set up filebeats with postrgesql module in order to ship postgresql logs to Elastic. The logs can be seen in Kibana, however they are not parsed and present following error message Provided Gr…

---

## [Filebeat json decode dynamic target uses kubernetes pod name](https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996)

<div class="topic-metadata">

**Author:** [@juka](https://discuss.elastic.co/u/juka)\
**Replies:** 3\
**Last updated:** [October 22, 2019, 12:59pm UTC](https://discuss.elastic.co/t/filebeat-json-decode-dynamic-target-uses-kubernetes-pod-name/202996 "2019-10-22T12:59:49Z")

</div>

Hello, is it possible to use a dynamic target in the decode\_json\_fields processor? https://www.elastic.co/guide/en/beats/filebeat/current/decode-json-fields.html I would like to have a target as follows: processors: …

---

## [Filebeat - Multiline events](https://discuss.elastic.co/t/filebeat-multiline-events/204505)

<div class="topic-metadata">

**Author:** [@jmilot](https://discuss.elastic.co/u/jmilot)\
**Replies:** 2\
**Last updated:** [October 22, 2019, 11:55am UTC](https://discuss.elastic.co/t/filebeat-multiline-events/204505 "2019-10-22T11:55:33Z")

</div>

Hello, In my case : logs are generated by Ruby On Rails. I would like to generate a message by request using multiline patterns : multiline.pattern: 'Started' multiline.negate: true multiline.match: after multiline.fl…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=305)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=307)
