# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=307

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 308

---

## [Replace rsyslog with Filebeat?](https://discuss.elastic.co/t/replace-rsyslog-with-filebeat/204540)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 1\
**Last updated:** [October 22, 2019, 11:29am UTC](https://discuss.elastic.co/t/replace-rsyslog-with-filebeat/204540 "2019-10-22T11:29:13Z")

</div>

Can Filebeat be used as a simple rsyslog replacement? Can i have 3 udp inputs on 10514, 10515 and 10516, and each of them outputting to ES to 3 different indices?

---

## [Setup Beats with Zeek](https://discuss.elastic.co/t/setup-beats-with-zeek/204478)

<div class="topic-metadata">

**Author:** [@tmans1991](https://discuss.elastic.co/u/tmans1991)\
**Replies:** 1\
**Last updated:** [October 22, 2019, 9:23am UTC](https://discuss.elastic.co/t/setup-beats-with-zeek/204478 "2019-10-22T09:23:05Z")

</div>

Hello, I am new to ELK and this is my first project with it. I currently have the following setup: 1 server (CentOS 7) that has zeek installed and logs all trafic it logs the current current day in /op/zeek/spool/log…

---

## ["Successully published" but it didn't](https://discuss.elastic.co/t/successully-published-but-it-didnt/204432)

<div class="topic-metadata">

**Author:** [@ajawm](https://discuss.elastic.co/u/ajawm)\
**Replies:** 2\
**Last updated:** [October 22, 2019, 7:00am UTC](https://discuss.elastic.co/t/successully-published-but-it-didnt/204432 "2019-10-22T07:00:02Z")

</div>

I have setup winlogbeat according to instructions, however logs do not show up in Kibana, despite log stating "successfully published". 2019-10-21T11:37:59.647+0200 WARN elasticsearch/client.go:535 Cannot index even…

---

## [Metricbeat connecting to AWS reporting Failed DescribeRegions](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100)

<div class="topic-metadata">

**Author:** [@alesanchez](https://discuss.elastic.co/u/alesanchez)\
**Replies:** 5\
**Last updated:** [October 22, 2019, 6:41am UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100 "2019-10-22T06:41:40Z")

</div>

Hi again everyone, I installed the aws module for metricbeat with the following configuration: # Module: aws # Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.4/metricbeat-module-aws.html - module: aws perio…

---

## [How to enable metric beat](https://discuss.elastic.co/t/how-to-enable-metric-beat/204299)

<div class="topic-metadata">

**Author:** [@anusree\_arun](https://discuss.elastic.co/u/anusree_arun)\
**Replies:** 7\
**Last updated:** [October 22, 2019, 4:53am UTC](https://discuss.elastic.co/t/how-to-enable-metric-beat/204299 "2019-10-22T04:53:44Z")

</div>

I have configured Metricbeat on kibana.When i take the kibana UI -Management\_central Management below page is shown.how to enable it

---

## [Filebeat 7.4.0 does not recover when it fails to connect with k8s API](https://discuss.elastic.co/t/filebeat-7-4-0-does-not-recover-when-it-fails-to-connect-with-k8s-api/204327)

<div class="topic-metadata">

**Author:** [@GreenKnight15](https://discuss.elastic.co/u/GreenKnight15)\
**Replies:** 3\
**Last updated:** [October 21, 2019, 3:31pm UTC](https://discuss.elastic.co/t/filebeat-7-4-0-does-not-recover-when-it-fails-to-connect-with-k8s-api/204327 "2019-10-21T15:31:02Z")

</div>

I am using the filebeat elastic helm chart https://github.com/elastic/helm-charts/tree/master/filebeat under an Istio service mesh. As of filebeat 7.4.0 with the new k8s client Update kubernetes watcher to use official…

---

## [Uptime not loading Heartbeat logs](https://discuss.elastic.co/t/uptime-not-loading-heartbeat-logs/201992)

<div class="topic-metadata">

**Author:** [@dorg](https://discuss.elastic.co/u/dorg)\
**Replies:** 6\
**Last updated:** [October 21, 2019, 1:59pm UTC](https://discuss.elastic.co/t/uptime-not-loading-heartbeat-logs/201992 "2019-10-21T13:59:23Z")

</div>

Hello We are using Elasticsearch 7.3 with kibana 7.2 versions. I set up Heartbeat (using docker) and configured the heartbeat.yml properly. After that I saw all of our services are exists under "Uptime" tab and saw tha…

---

## [EVTX Import failure when EVTX contains a deleted entry](https://discuss.elastic.co/t/evtx-import-failure-when-evtx-contains-a-deleted-entry/203269)

<div class="topic-metadata">

**Author:** [@dlebrun](https://discuss.elastic.co/u/dlebrun)\
**Replies:** 1\
**Last updated:** [October 21, 2019, 8:31am UTC](https://discuss.elastic.co/t/evtx-import-failure-when-evtx-contains-a-deleted-entry/203269 "2019-10-21T08:31:10Z")

</div>

When running Winlogbeat 7.4 from a PowerShell script to process EVTX files I am running into a problem specific to the number of records imported into Kibana. If the EVTX file contains no deleted entries, the script impo…

---

## [Getting error for mongodb module in metricbeat](https://discuss.elastic.co/t/getting-error-for-mongodb-module-in-metricbeat/200538)

<div class="topic-metadata">

**Author:** [@GRV](https://discuss.elastic.co/u/GRV)\
**Replies:** 3\
**Last updated:** [October 20, 2019, 6:41pm UTC](https://discuss.elastic.co/t/getting-error-for-mongodb-module-in-metricbeat/200538 "2019-10-20T18:41:34Z")

</div>

My mongodb server running on local (127.0.0.1:27017). I have 2 user in mongodb database. 1 for application and 2nd user with read only permission. (Eg. user/password). I configure the 2nd user in mondodb.yml module, whic…

---

## [Sending log from filebeat to logstash error: Failed to publish events caused by: lumberjack protocol error](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332)

<div class="topic-metadata">

**Author:** [@Sam](https://discuss.elastic.co/u/Sam)\
**Replies:** 5\
**Last updated:** [October 20, 2019, 2:35pm UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332 "2019-10-20T14:35:15Z")

</div>

Halo guys I'm new with ELK Stack I try to send IIS log from FileBeat to Logstash and further but it doesn't work. I get an error Failed to publish events caused by: lumberjack protocol error when start FileBeat (Logsta…

---

## [Is there a way to apply a lifecycle management policy only to metricbeat-\* pattern index?](https://discuss.elastic.co/t/is-there-a-way-to-apply-a-lifecycle-management-policy-only-to-metricbeat-pattern-index/204337)

<div class="topic-metadata">

**Author:** [@Mai\_Waly](https://discuss.elastic.co/u/Mai_Waly)\
**Replies:** 2\
**Last updated:** [October 20, 2019, 11:39am UTC](https://discuss.elastic.co/t/is-there-a-way-to-apply-a-lifecycle-management-policy-only-to-metricbeat-pattern-index/204337 "2019-10-20T11:39:55Z")

</div>

Is there a way to apply a life cycle management policy only to metricbeat-\* pattern index in 7.4 logstash/Elasticsearch/kibana cluster to delete any index older than 30 days?

---

## [How to clean metricbeat index every 30 days without x-pack?](https://discuss.elastic.co/t/how-to-clean-metricbeat-index-every-30-days-without-x-pack/204313)

<div class="topic-metadata">

**Author:** [@Mai\_Waly](https://discuss.elastic.co/u/Mai_Waly)\
**Replies:** 3\
**Last updated:** [October 19, 2019, 5:32pm UTC](https://discuss.elastic.co/t/how-to-clean-metricbeat-index-every-30-days-without-x-pack/204313 "2019-10-19T17:32:32Z")

</div>

Please help How to clean metricbeat index every 30 days without x-pack?

---

## [How to get Disk Latency data in Metricbeat?](https://discuss.elastic.co/t/how-to-get-disk-latency-data-in-metricbeat/203858)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 2\
**Last updated:** [October 19, 2019, 10:55am UTC](https://discuss.elastic.co/t/how-to-get-disk-latency-data-in-metricbeat/203858 "2019-10-19T10:55:23Z")

</div>

How to get Disk Latency data in Metricbeat? If yes what is the field name ?

---

## [Mysql filebeat module \[mysql.error\] no result found](https://discuss.elastic.co/t/mysql-filebeat-module-mysql-error-no-result-found/203433)

<div class="topic-metadata">

**Author:** [@Admiraludon](https://discuss.elastic.co/u/Admiraludon)\
**Replies:** 10\
**Last updated:** [October 19, 2019, 4:07am UTC](https://discuss.elastic.co/t/mysql-filebeat-module-mysql-error-no-result-found/203433 "2019-10-19T04:07:38Z")

</div>

Hi , I using filebeat to send mysql data to elasticsearch, but i notice there are no result for mysql.error data in elasticsearch even though mysql.slowlog data are coming correctly. I check the data using kibana discov…

---

## [Metricbeat AWS RDS Module for Aurora Serverless](https://discuss.elastic.co/t/metricbeat-aws-rds-module-for-aurora-serverless/203077)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 5\
**Last updated:** [October 18, 2019, 11:26pm UTC](https://discuss.elastic.co/t/metricbeat-aws-rds-module-for-aurora-serverless/203077 "2019-10-18T23:26:10Z")

</div>

Hi, Are there plans to scrape metrics for aurora serverless databases? Best, Justin

---

## [Module haproxy : error getting IdlePct: strconv.ParseFloat: parsing \\"\\": invalid syntax](https://discuss.elastic.co/t/module-haproxy-error-getting-idlepct-strconv-parsefloat-parsing-invalid-syntax/202647)

<div class="topic-metadata">

**Author:** [@bodo.te](https://discuss.elastic.co/u/bodo.te)\
**Replies:** 7\
**Last updated:** [October 18, 2019, 6:49pm UTC](https://discuss.elastic.co/t/module-haproxy-error-getting-idlepct-strconv-parsefloat-parsing-invalid-syntax/202647 "2019-10-18T18:49:28Z")

</div>

Version: metricbeat 7.4.0 haproxy 1.9.8 Operating System: Ubuntu 16.04.6 LTS Discuss Forum URL: https://discuss.elastic.co/t/haproxy-strconv-parsefloat-parsing-invalid-syntax/181403 Steps to Reproduce: install meso…

---

## [Metricbeat-oss missing aws module](https://discuss.elastic.co/t/metricbeat-oss-missing-aws-module/204258)

<div class="topic-metadata">

**Author:** [@gearoto](https://discuss.elastic.co/u/gearoto)\
**Replies:** 1\
**Last updated:** [October 18, 2019, 5:22pm UTC](https://discuss.elastic.co/t/metricbeat-oss-missing-aws-module/204258 "2019-10-18T17:22:06Z")

</div>

I can't seem to find any answers on this. looking at the docker images for: docker.elastic.co/beats/metricbeat:7.4.0 and docker.elastic.co/beats/metricbeat-oss :7.4.0 The metricbeat-oss does not include the aws modul…

---

## [Provided Grok expressions do not match field value on Filebeat 7.4.0](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-on-filebeat-7-4-0/203917)

<div class="topic-metadata">

**Author:** [@andrezenun](https://discuss.elastic.co/u/andrezenun)\
**Replies:** 1\
**Last updated:** [October 18, 2019, 4:49pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-on-filebeat-7-4-0/203917 "2019-10-18T16:49:07Z")

</div>

Hi I have seen that this was a problem on older versions of filbeat, but I just installed filebeat 7.4.0 and the server is running httpd-2.4.6-88.el7.centos.x86\_64. I have pointed the log files on the apache module confi…

---

## [Configuration using filebeat with static index name](https://discuss.elastic.co/t/configuration-using-filebeat-with-static-index-name/203842)

<div class="topic-metadata">

**Author:** [@ptrigo](https://discuss.elastic.co/u/ptrigo)\
**Replies:** 9\
**Last updated:** [October 17, 2019, 7:12pm UTC](https://discuss.elastic.co/t/configuration-using-filebeat-with-static-index-name/203842 "2019-10-17T19:12:04Z")

</div>

Hi, I would like to know how I need to configure filebeat to use an existing index(it's empty). What's the configuration to do so? So far I tried in a helm chart: output.elasticsearch: hosts: 'https://XXXXXX.com…

---

## [Running filebeat as a container to collect container logs](https://discuss.elastic.co/t/running-filebeat-as-a-container-to-collect-container-logs/203316)

<div class="topic-metadata">

**Author:** [@Mai\_Waly](https://discuss.elastic.co/u/Mai_Waly)\
**Replies:** 1\
**Last updated:** [October 18, 2019, 1:17pm UTC](https://discuss.elastic.co/t/running-filebeat-as-a-container-to-collect-container-logs/203316 "2019-10-18T13:17:55Z")

</div>

Hi All, I have installed filebeat as a docker container with the below file: filebeat.config: modules: path: ${path.config}/modules.d/\*.yml reload.enabled: false filebeat.autodiscover: providers: - type: docker …

---

## [When to use filebeat as a container?](https://discuss.elastic.co/t/when-to-use-filebeat-as-a-container/203023)

<div class="topic-metadata">

**Author:** [@Mai\_Waly](https://discuss.elastic.co/u/Mai_Waly)\
**Replies:** 1\
**Last updated:** [October 18, 2019, 1:14pm UTC](https://discuss.elastic.co/t/when-to-use-filebeat-as-a-container/203023 "2019-10-18T13:14:41Z")

</div>

Hi All, Please advise we have been asked to use filebeats as a container to monitor application that write the logs to the host itself is that logic, as I understand filebeat as a container is used to monitor other runn…

---

## [Autodiscover Kubernetes configuration](https://discuss.elastic.co/t/autodiscover-kubernetes-configuration/203138)

<div class="topic-metadata">

**Author:** [@ZMMWMY](https://discuss.elastic.co/u/ZMMWMY)\
**Replies:** 1\
**Last updated:** [October 18, 2019, 1:04pm UTC](https://discuss.elastic.co/t/autodiscover-kubernetes-configuration/203138 "2019-10-18T13:04:14Z")

</div>

I have multiple namespaces, but I don't want to choose all of them Can I configure multiple namespaces? document

---

## [Filebeat input setting has no effect on input](https://discuss.elastic.co/t/filebeat-input-setting-has-no-effect-on-input/204227)

<div class="topic-metadata">

**Author:** [@Tompson](https://discuss.elastic.co/u/Tompson)\
**Replies:** 0\
**Last updated:** [October 18, 2019, 12:44pm UTC](https://discuss.elastic.co/t/filebeat-input-setting-has-no-effect-on-input/204227 "2019-10-18T12:44:08Z")

</div>

As a test, i set a single logfile as a inputpath like in the example yml. But in kibana, i get everything from /var/log/\* . What did i configure wrong or haven't configured yet? input setting in filebeat.yml: #========…

---

## [Filebeat processor add tags to log files from different folders](https://discuss.elastic.co/t/filebeat-processor-add-tags-to-log-files-from-different-folders/204226)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [October 18, 2019, 12:39pm UTC](https://discuss.elastic.co/t/filebeat-processor-add-tags-to-log-files-from-different-folders/204226 "2019-10-18T12:39:34Z")

</div>

Filebeat 7.4.0 I've been trying to work off of the link below to add tags to logs that are coming from different folders. We have multiple different log folders like vdi001, vdimgmt001 and flx001 and we'd like to use f…

---

## [MySQL error logs not found](https://discuss.elastic.co/t/mysql-error-logs-not-found/204221)

<div class="topic-metadata">

**Author:** [@linuxwiz](https://discuss.elastic.co/u/linuxwiz)\
**Replies:** 0\
**Last updated:** [October 18, 2019, 12:12pm UTC](https://discuss.elastic.co/t/mysql-error-logs-not-found/204221 "2019-10-18T12:12:34Z")

</div>

Hello Folks, I am trying to send MariaDB error logs to Elastic. There are no errors seen in Filebeat logs but can't see them on Kibana. Only occasional one line of error appears that makes me confused. Just that erro…

---

## [Request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)](https://discuss.elastic.co/t/request-canceled-while-waiting-for-connection-client-timeout-exceeded-while-awaiting-headers/204217)

<div class="topic-metadata">

**Author:** [@vrathore18](https://discuss.elastic.co/u/vrathore18)\
**Replies:** 0\
**Last updated:** [October 18, 2019, 11:41am UTC](https://discuss.elastic.co/t/request-canceled-while-waiting-for-connection-client-timeout-exceeded-while-awaiting-headers/204217 "2019-10-18T11:41:19Z")

</div>

I am using below code snippet apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: kube-system labels: k8s-app: filebeat data: filebeat.yml: |- filebeat.config: inputs: …

---

## [Massive filtering in modules? Or in Logstash](https://discuss.elastic.co/t/massive-filtering-in-modules-or-in-logstash/204210)

<div class="topic-metadata">

**Author:** [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Replies:** 0\
**Last updated:** [October 18, 2019, 11:10am UTC](https://discuss.elastic.co/t/massive-filtering-in-modules-or-in-logstash/204210 "2019-10-18T11:10:50Z")

</div>

Hi, I followed the discussion around Convert Filebeat icinga.\* to ECS by webmat · Pull Request #9294 · elastic/beats · GitHub - a pull request to get the icinga module of Filebeat compatible to ECS. There were some chan…

---

## [Apply module config to redis input](https://discuss.elastic.co/t/apply-module-config-to-redis-input/204196)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 0\
**Last updated:** [October 18, 2019, 9:44am UTC](https://discuss.elastic.co/t/apply-module-config-to-redis-input/204196 "2019-10-18T09:44:13Z")

</div>

Hello I'm trying to find out if it is possible to apply filebeat module config/parsers to redis input. We ship suricata logs from firewalls to redis and then we pull them from redis with logstash. Now I'd like to use f…

---

## [Does it imply successful connection to Logstash DEBUG \[logstash\] logstash/sync.go:74 connect](https://discuss.elastic.co/t/does-it-imply-successful-connection-to-logstash-debug-logstash-logstash-sync-go-74-connect/204182)

<div class="topic-metadata">

**Author:** [@t3di](https://discuss.elastic.co/u/t3di)\
**Replies:** 0\
**Last updated:** [October 18, 2019, 7:38am UTC](https://discuss.elastic.co/t/does-it-imply-successful-connection-to-logstash-debug-logstash-logstash-sync-go-74-connect/204182 "2019-10-18T07:38:43Z")

</div>

so FunctionBeat throws INFO pipeline/output.go:95 Connecting to backoff(tcp://155.22.33.44:5044) DEBUG \[logstash\] logstash/sync.go:74 connect yet I cannot get anything in my Logstash instance .. what could possibly g…

---

## [Forwarding windows event logs in another language](https://discuss.elastic.co/t/forwarding-windows-event-logs-in-another-language/204067)

<div class="topic-metadata">

**Author:** [@username11](https://discuss.elastic.co/u/username11)\
**Replies:** 2\
**Last updated:** [October 18, 2019, 6:43am UTC](https://discuss.elastic.co/t/forwarding-windows-event-logs-in-another-language/204067 "2019-10-18T06:43:10Z")

</div>

Greetings. We are currently trying to ingest logs from a Windows server with a system language other than English. Because of that, the logs retrieved by Winlogbeat are not in English, and we need to get them in line wit…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=306)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=308)
