# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=308

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 309

---

## [Anyone got auditbeat woring in azure with OMS Agent working](https://discuss.elastic.co/t/anyone-got-auditbeat-woring-in-azure-with-oms-agent-working/204097)

<div class="topic-metadata">

**Author:** [@stwilliams](https://discuss.elastic.co/u/stwilliams)\
**Replies:** 1\
**Last updated:** [October 17, 2019, 11:27pm UTC](https://discuss.elastic.co/t/anyone-got-auditbeat-woring-in-azure-with-oms-agent-working/204097 "2019-10-17T23:27:46Z")

</div>

Hi We are having trouble with our azure servers. We are using the Azure Security Centre and Update Manager to keep our servers up to 'snuff'. We use the OMSagent for Linux to keep an eye on what is going on. OMSagent…

---

## [Case sensitivity with import of github.com/Sirupsen/logrus](https://discuss.elastic.co/t/case-sensitivity-with-import-of-github-com-sirupsen-logrus/204130)

<div class="topic-metadata">

**Author:** [@bealesh](https://discuss.elastic.co/u/bealesh)\
**Replies:** 0\
**Last updated:** [October 17, 2019, 8:57pm UTC](https://discuss.elastic.co/t/case-sensitivity-with-import-of-github-com-sirupsen-logrus/204130 "2019-10-17T20:57:50Z")

</div>

Hi all - My company imports beats for a few mission critical apps, and in trying to update some dependencies we converted our Go monorepo to modules. Now, when trying to build, I'm getting the following error: github.c…

---

## [Specify pipeline on Elastic Cloud using Cloud.id/auth](https://discuss.elastic.co/t/specify-pipeline-on-elastic-cloud-using-cloud-id-auth/203906)

<div class="topic-metadata">

**Author:** [@andrezenun](https://discuss.elastic.co/u/andrezenun)\
**Replies:** 3\
**Last updated:** [October 17, 2019, 5:45pm UTC](https://discuss.elastic.co/t/specify-pipeline-on-elastic-cloud-using-cloud-id-auth/203906 "2019-10-17T17:45:34Z")

</div>

Hello every one! I would like to know if is possible to specify a pipeline on the beat when I only use the cloud.id and cloud.auth configs. I know that with output.elasticsearch I have this option, but for some reason o…

---

## [Filebeat reports config is invalid but it all passes YAML Linting (with solution)](https://discuss.elastic.co/t/filebeat-reports-config-is-invalid-but-it-all-passes-yaml-linting-with-solution/204071)

<div class="topic-metadata">

**Author:** [@dnorth98](https://discuss.elastic.co/u/dnorth98)\
**Replies:** 0\
**Last updated:** [October 17, 2019, 1:57pm UTC](https://discuss.elastic.co/t/filebeat-reports-config-is-invalid-but-it-all-passes-yaml-linting-with-solution/204071 "2019-10-17T13:57:52Z")

</div>

I've just spent the last 30 minutes figuring this out and finally found the problem and figure it may help someone else so posting here. Starting filebeat, it starts ok but then exits right away. In the log the last li…

---

## [Import large PCAP with Packetbeat](https://discuss.elastic.co/t/import-large-pcap-with-packetbeat/203578)

<div class="topic-metadata">

**Author:** [@sutello](https://discuss.elastic.co/u/sutello)\
**Replies:** 3\
**Last updated:** [October 17, 2019, 1:52pm UTC](https://discuss.elastic.co/t/import-large-pcap-with-packetbeat/203578 "2019-10-17T13:52:51Z")

</div>

Hey, we sitting here in a Study-Project in Germany and want to work with packetbeat and ELK to find security issues in network-traffic. The live-capturing works fine. Now, we want to import our old PCAP-files from the …

---

## [Cisco FTD Intrusion events logs are not parsed properly?](https://discuss.elastic.co/t/cisco-ftd-intrusion-events-logs-are-not-parsed-properly/202716)

<div class="topic-metadata">

**Author:** [@yiy](https://discuss.elastic.co/u/yiy)\
**Replies:** 3\
**Last updated:** [October 17, 2019, 1:48pm UTC](https://discuss.elastic.co/t/cisco-ftd-intrusion-events-logs-are-not-parsed-properly/202716 "2019-10-17T13:48:31Z")

</div>

It seems that some intrusion events from Cisco FTD is not parse. Filebeat version: 7.4.0 (amd64), libbeat 7.4.0 \[f940c36884d3749901a9c99bea5463a6030cdd9c built 2019-09-27 07:45:44 +0000 UTC\] For example, this is a p…

---

## [X-pack bricking metricbeat after enabling Central Management](https://discuss.elastic.co/t/x-pack-bricking-metricbeat-after-enabling-central-management/203683)

<div class="topic-metadata">

**Author:** [@mangeloco](https://discuss.elastic.co/u/mangeloco)\
**Replies:** 1\
**Last updated:** [October 17, 2019, 1:21pm UTC](https://discuss.elastic.co/t/x-pack-bricking-metricbeat-after-enabling-central-management/203683 "2019-10-17T13:21:14Z")

</div>

Before i enroll my metricbeat (either windows or linux), i have monitoring.enabled : true under X-pack monitoring, which will allow the beat to show up under Stack Monitoring in Kibana. But after I enroll that Metricbea…

---

## [How to redirect s3 data to multiple pipelines](https://discuss.elastic.co/t/how-to-redirect-s3-data-to-multiple-pipelines/203974)

<div class="topic-metadata">

**Author:** [@akki2208](https://discuss.elastic.co/u/akki2208)\
**Replies:** 1\
**Last updated:** [October 17, 2019, 12:08pm UTC](https://discuss.elastic.co/t/how-to-redirect-s3-data-to-multiple-pipelines/203974 "2019-10-17T12:08:48Z")

</div>

Hello Team, I need to send data of s3 input data to multiple pipelines based on some regex in the log path. can anyone here me here. @andrewkroh

---

## [Index can be found in Kibana Discover, but not in editing Dashboard](https://discuss.elastic.co/t/index-can-be-found-in-kibana-discover-but-not-in-editing-dashboard/203977)

<div class="topic-metadata">

**Author:** [@totalz](https://discuss.elastic.co/u/totalz)\
**Replies:** 0\
**Last updated:** [October 17, 2019, 6:22am UTC](https://discuss.elastic.co/t/index-can-be-found-in-kibana-discover-but-not-in-editing-dashboard/203977 "2019-10-17T06:22:21Z")

</div>

Using filebeat to fetch kibana log. On kibana discover, I can find related index and doc, but the same query does not work in editing new dashboard. Any tip on troubleshooting? Is there predefined \[filebeat kibana\] da…

---

## [Multiple filebeat output to ES and Logstash](https://discuss.elastic.co/t/multiple-filebeat-output-to-es-and-logstash/203824)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 2\
**Last updated:** [October 17, 2019, 4:00am UTC](https://discuss.elastic.co/t/multiple-filebeat-output-to-es-and-logstash/203824 "2019-10-17T04:00:30Z")

</div>

Team, i have a requirement where i need to send audit, auth and syslog from servers to elasticsearch directly and application's log to logstash. here are the changes and steps i performed. I am using ubuntu 16 in our set…

---

## [Absolutely nothing shows in any \[Filebeat\] Kibana Dashboards (“No results found”)](https://discuss.elastic.co/t/absolutely-nothing-shows-in-any-filebeat-kibana-dashboards-no-results-found/202139)

<div class="topic-metadata">

**Author:** [@totalz](https://discuss.elastic.co/u/totalz)\
**Replies:** 2\
**Last updated:** [October 17, 2019, 3:53am UTC](https://discuss.elastic.co/t/absolutely-nothing-shows-in-any-filebeat-kibana-dashboards-no-results-found/202139 "2019-10-17T03:53:46Z")

</div>

On Windows 10, I enabled Kibana and System in filebeat. I'm not sure if System would work, but Kibana should. health status index uuid pri rep docs.count docs.deleted stor…

---

## [Shipping to Logstash vs Elasticsearch, and pipelines. Also modules?](https://discuss.elastic.co/t/shipping-to-logstash-vs-elasticsearch-and-pipelines-also-modules/203089)

<div class="topic-metadata">

**Author:** [@hueyg](https://discuss.elastic.co/u/hueyg)\
**Replies:** 3\
**Last updated:** [October 17, 2019, 3:53am UTC](https://discuss.elastic.co/t/shipping-to-logstash-vs-elasticsearch-and-pipelines-also-modules/203089 "2019-10-17T03:53:27Z")

</div>

Sorry for the rambling topic, but I am falling down a rabbit hole. Once I feel like a get a handle on ELK terminology and infrastructure the floor drops. I have never completely understood why you would ship a beat dir…

---

## [How to configure multiple indexes inside filebeat for one log type?](https://discuss.elastic.co/t/how-to-configure-multiple-indexes-inside-filebeat-for-one-log-type/203943)

<div class="topic-metadata">

**Author:** [@Hung\_M\_Le](https://discuss.elastic.co/u/Hung_M_Le)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 10:58pm UTC](https://discuss.elastic.co/t/how-to-configure-multiple-indexes-inside-filebeat-for-one-log-type/203943 "2019-10-16T22:58:28Z")

</div>

Hi I am trying to configure the filebeat to output to Elasticsearch cloud using the following index templates definition inside filebeat.yml. The issue that I encountered is that I do not see the new indexe template (ta…

---

## [Large scale deployment of beats through Central Management](https://discuss.elastic.co/t/large-scale-deployment-of-beats-through-central-management/165822)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 2\
**Last updated:** [October 16, 2019, 9:43pm UTC](https://discuss.elastic.co/t/large-scale-deployment-of-beats-through-central-management/165822 "2019-10-16T21:43:07Z")

</div>

After testing out beats central management for a few days I wondering how you scale this feature. From my understanding when you enroll a beat its on a one to one ratio. A user clicks on Enroll Beats, gets a link/token…

---

## [Filebeat 'iptables' module missing](https://discuss.elastic.co/t/filebeat-iptables-module-missing/203933)

<div class="topic-metadata">

**Author:** [@danielsnelling](https://discuss.elastic.co/u/danielsnelling)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 9:35pm UTC](https://discuss.elastic.co/t/filebeat-iptables-module-missing/203933 "2019-10-16T21:35:23Z")

</div>

In Kibana 7.4, the Filebeat 'iptables' module is missing from the Central Management Config tag options. Is there a reason for this?

---

## [Beats transport mechanisms](https://discuss.elastic.co/t/beats-transport-mechanisms/203924)

<div class="topic-metadata">

**Author:** [@arxo](https://discuss.elastic.co/u/arxo)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 8:11pm UTC](https://discuss.elastic.co/t/beats-transport-mechanisms/203924 "2019-10-16T20:11:20Z")

</div>

I was wondering about deploying beats in a segregated network. Is there a way to send beats via HTTP or a simpler protocol than lumberjack (to allow it to pass via an inspection firewall/ASA) . On a side note is there a…

---

## [Decode\_json on partial field](https://discuss.elastic.co/t/decode-json-on-partial-field/203904)

<div class="topic-metadata">

**Author:** [@dnorth98](https://discuss.elastic.co/u/dnorth98)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 5:56pm UTC](https://discuss.elastic.co/t/decode-json-on-partial-field/203904 "2019-10-16T17:56:54Z")

</div>

Hi there, I'm pulling in a log with filebeat with lines that look like this: I, \[2019-10-16T17:44:37.242758 #17339\] INFO -- : \[ac4878f8-b88b-406f-8271-f7efb873e200\] {"method":"GET","path":"/healthcheck","format":"text"…

---

## [Filebeat 7.3.2 logstash module timezone bug - Time in the future](https://discuss.elastic.co/t/filebeat-7-3-2-logstash-module-timezone-bug-time-in-the-future/203900)

<div class="topic-metadata">

**Author:** [@Khatarian](https://discuss.elastic.co/u/Khatarian)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 5:34pm UTC](https://discuss.elastic.co/t/filebeat-7-3-2-logstash-module-timezone-bug-time-in-the-future/203900 "2019-10-16T17:34:41Z")

</div>

Hey there! For awhile I noticed that logs from the Logstash module are in the future so I went digging in this bug. I'm using logstash to receive the logs and forward them to the ingress pipeline of elasticsearch. To f…

---

## [OS metrics](https://discuss.elastic.co/t/os-metrics/199876)

<div class="topic-metadata">

**Author:** [@Pierrelaurent](https://discuss.elastic.co/u/Pierrelaurent)\
**Replies:** 11\
**Last updated:** [October 16, 2019, 2:01pm UTC](https://discuss.elastic.co/t/os-metrics/199876 "2019-10-16T14:01:27Z")

</div>

Hi There, I managed to get data into elasticsearch via logstash. The data contains OS metrics. Now that we have the data I am trying to make sense of it. We are getting raw data in but we want to see everything in perce…

---

## [Autodiscover hints.enabled logs all pods](https://discuss.elastic.co/t/autodiscover-hints-enabled-logs-all-pods/203669)

<div class="topic-metadata">

**Author:** [@symjar](https://discuss.elastic.co/u/symjar)\
**Replies:** 1\
**Last updated:** [October 16, 2019, 12:27pm UTC](https://discuss.elastic.co/t/autodiscover-hints-enabled-logs-all-pods/203669 "2019-10-16T12:27:53Z")

</div>

Hey! I've attempted to implement kubernetes logging to elasticsearch. What I want to achieve: Ship all the logs from pods in the default namespace. Configure templates per pod type That was my first attempt and it w…

---

## [Filebeat Cisco ASA Parsing only Firewall deny messages](https://discuss.elastic.co/t/filebeat-cisco-asa-parsing-only-firewall-deny-messages/203789)

<div class="topic-metadata">

**Author:** [@qiratnahraf](https://discuss.elastic.co/u/qiratnahraf)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 9:01am UTC](https://discuss.elastic.co/t/filebeat-cisco-asa-parsing-only-firewall-deny-messages/203789 "2019-10-16T09:01:12Z")

</div>

Hello, We are collecting Cisco ASA logs on filebeat using cisco module through syslog. What we are facing is that some events are parse correctly whereas others or not. As per our troubleshooting, We are collecting log…

---

## [Adding more ASA syslog message patterns](https://discuss.elastic.co/t/adding-more-asa-syslog-message-patterns/203780)

<div class="topic-metadata">

**Author:** [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 8:31am UTC](https://discuss.elastic.co/t/adding-more-asa-syslog-message-patterns/203780 "2019-10-16T08:31:25Z")

</div>

How do i add more patterns in filebeat 7.4 to parse more asa syslog messages?

---

## [Heartbeat dynamic config reloader stopped](https://discuss.elastic.co/t/heartbeat-dynamic-config-reloader-stopped/203229)

<div class="topic-metadata">

**Author:** [@alexandru.toader](https://discuss.elastic.co/u/alexandru.toader)\
**Replies:** 3\
**Last updated:** [October 16, 2019, 8:29am UTC](https://discuss.elastic.co/t/heartbeat-dynamic-config-reloader-stopped/203229 "2019-10-16T08:29:22Z")

</div>

at a random time the heartbeat is shutting down with INFO messages : INFO cfgfile/reload.go:229 Dynamic config reloader stopped INFO \[reload\] cfgfile/list.go:118 Stopping 9 runners ... INFO \[moni…

---

## [Listen for different protocols over different interface](https://discuss.elastic.co/t/listen-for-different-protocols-over-different-interface/202459)

<div class="topic-metadata">

**Author:** [@Marko\_Todoric](https://discuss.elastic.co/u/Marko_Todoric)\
**Replies:** 2\
**Last updated:** [October 16, 2019, 8:23am UTC](https://discuss.elastic.co/t/listen-for-different-protocols-over-different-interface/202459 "2019-10-16T08:23:16Z")

</div>

Hello everyone, I've been using packetbeat for a while to monitor DHCP traffic on our network and to analyze the work of DHCP Servers. Now, i would like to know if there is something i could do here. The server that i…

---

## [Default Dashboard "\[Metricbeat Kubernetes\] Overview ECS" doesn't work](https://discuss.elastic.co/t/default-dashboard-metricbeat-kubernetes-overview-ecs-doesnt-work/203101)

<div class="topic-metadata">

**Author:** [@xwiz](https://discuss.elastic.co/u/xwiz)\
**Replies:** 9\
**Last updated:** [October 16, 2019, 8:08am UTC](https://discuss.elastic.co/t/default-dashboard-metricbeat-kubernetes-overview-ecs-doesnt-work/203101 "2019-10-16T08:08:46Z")

</div>

Hello! I am trying to configure monitoring of my Kubernetes cluster. For this, I did: Elasticsearch server and kibana version 7.1.1 Installed filebeat and metricbeat 7.1.1 on my Kubernetes cluster via yaml files. Inst…

---

## [How to upgrade to a specific version](https://discuss.elastic.co/t/how-to-upgrade-to-a-specific-version/203575)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 3\
**Last updated:** [October 16, 2019, 7:09am UTC](https://discuss.elastic.co/t/how-to-upgrade-to-a-specific-version/203575 "2019-10-16T07:09:55Z")

</div>

Hi all, I am currently on version 7.1.1, but I wish to upgrade it to 7.3.2. Instead of upgrading to the latest version 7.4.0, how can I upgrade using the repository to this 7.3.2 ?

---

## [Metricbeat - high network utilisation](https://discuss.elastic.co/t/metricbeat-high-network-utilisation/203474)

<div class="topic-metadata">

**Author:** [@RichardH](https://discuss.elastic.co/u/RichardH)\
**Replies:** 4\
**Last updated:** [October 16, 2019, 6:42am UTC](https://discuss.elastic.co/t/metricbeat-high-network-utilisation/203474 "2019-10-16T06:42:40Z")

</div>

Hello, We would like to use Metricbeat to monitor systems stats for a number of servers across slow WAN links. If I do a default install of Metric beat my outbound network throughput is around 7KB/s, however I want to s…

---

## [Kubernetes autodiscover indices](https://discuss.elastic.co/t/kubernetes-autodiscover-indices/203752)

<div class="topic-metadata">

**Author:** [@bstavenuiter](https://discuss.elastic.co/u/bstavenuiter)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 6:15am UTC](https://discuss.elastic.co/t/kubernetes-autodiscover-indices/203752 "2019-10-16T06:15:26Z")

</div>

Hi I am trying to setup filebeat with kubernetes so all the logs of the pods in all the different namespaces get sent to elasticsearch. But I would like different indexes for every app. That is why I use the %{\[kuberne…

---

## [Adding type in filebeat.yml](https://discuss.elastic.co/t/adding-type-in-filebeat-yml/203750)

<div class="topic-metadata">

**Author:** [@souravatta](https://discuss.elastic.co/u/souravatta)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 6:11am UTC](https://discuss.elastic.co/t/adding-type-in-filebeat-yml/203750 "2019-10-16T06:11:17Z")

</div>

I am stashing jenkins logs from filbeat to ELK stack. I have taken the reference of this logstash.conf file. I need to add the type =\> jenkins-server (highlighted in red) to my filebeat.yml for better filtering. I have…

---

## [Filebeat Configuration: Adding fields in filebeat.yml](https://discuss.elastic.co/t/filebeat-configuration-adding-fields-in-filebeat-yml/203617)

<div class="topic-metadata">

**Author:** [@souravatta](https://discuss.elastic.co/u/souravatta)\
**Replies:** 2\
**Last updated:** [October 16, 2019, 5:08am UTC](https://discuss.elastic.co/t/filebeat-configuration-adding-fields-in-filebeat-yml/203617 "2019-10-16T05:08:49Z")

</div>

I need to write a filebeat.yml for reading jenkins logs and then stashing the same in ELK. I have come across this filter and want to implement the same in filebeat.yml. I have made changes accordingly but stuck here in…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=307)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=309)
