# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=309

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 310

---

## [Couldnt start filebeat-Please HELP!](https://discuss.elastic.co/t/couldnt-start-filebeat-please-help/203623)

<div class="topic-metadata">

**Author:** [@anusree\_arun](https://discuss.elastic.co/u/anusree_arun)\
**Replies:** 2\
**Last updated:** [October 16, 2019, 4:08am UTC](https://discuss.elastic.co/t/couldnt-start-filebeat-please-help/203623 "2019-10-16T04:08:00Z")

</div>

systemctl status filebeat â filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; vendor preset: disabled) Active: fa…

---

## [Collect sequence when there are a lot of files?](https://discuss.elastic.co/t/collect-sequence-when-there-are-a-lot-of-files/203736)

<div class="topic-metadata">

**Author:** [@dumbdonkey](https://discuss.elastic.co/u/dumbdonkey)\
**Replies:** 0\
**Last updated:** [October 16, 2019, 3:46am UTC](https://discuss.elastic.co/t/collect-sequence-when-there-are-a-lot-of-files/203736 "2019-10-16T03:46:33Z")

</div>

will Filebeat collect file from the oldest one to the newest one? I cannot find any documentation about this. thanks

---

## [Problem compiling filebeat from source](https://discuss.elastic.co/t/problem-compiling-filebeat-from-source/203704)

<div class="topic-metadata">

**Author:** [@thurston](https://discuss.elastic.co/u/thurston)\
**Replies:** 5\
**Last updated:** [October 15, 2019, 7:48pm UTC](https://discuss.elastic.co/t/problem-compiling-filebeat-from-source/203704 "2019-10-15T19:48:30Z")

</div>

Working on compiling Filebeat from source to run on arm architecture. This worked for 7.3 without any issues. A new message came up with 7.4 here is a snip of my script that i am using. go get github.com/elastic/beat…

---

## [Weblogicbeat](https://discuss.elastic.co/t/weblogicbeat/203649)

<div class="topic-metadata">

**Author:** [@shali93](https://discuss.elastic.co/u/shali93)\
**Replies:** 0\
**Last updated:** [October 15, 2019, 12:44pm UTC](https://discuss.elastic.co/t/weblogicbeat/203649 "2019-10-15T12:44:36Z")

</div>

I have created custom weblogicbeat using below reference. I am tying to fetch thread status details from weblogicbeat. Is this required Docker? We tried Jolokia and (https://github.com/golang/mobile/tree/master/inte…

---

## [Problem with Filebeat and Kibana](https://discuss.elastic.co/t/problem-with-filebeat-and-kibana/202806)

<div class="topic-metadata">

**Author:** [@Jonathan\_Sieger](https://discuss.elastic.co/u/Jonathan_Sieger)\
**Replies:** 9\
**Last updated:** [October 15, 2019, 11:41am UTC](https://discuss.elastic.co/t/problem-with-filebeat-and-kibana/202806 "2019-10-15T11:41:06Z")

</div>

Hi, I use Filebeat 7.4 and Kibana 7.3.2 . Filebeat receive cleanly the log. But he don't forwad to Kibana. When I do : filebeat setup I have this result : Index setup finished. Loading dashboards (Kibana must be run…

---

## [\[Filebeat System\] New users and groups ECS Dashboard](https://discuss.elastic.co/t/filebeat-system-new-users-and-groups-ecs-dashboard/203619)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 0\
**Last updated:** [October 15, 2019, 10:27am UTC](https://discuss.elastic.co/t/filebeat-system-new-users-and-groups-ecs-dashboard/203619 "2019-10-15T10:27:32Z")

</div>

Hello Team, We are in testing phase of ELK 7.4.0. Our architecture is Filebeat-\>Logstash-\>Elasticserach-\>Kibana. We have used system module of filebeat with logstash pipeline for parsingand getting the logs on kibana d…

---

## [Logstash pipeline for parsing with filebeat module](https://discuss.elastic.co/t/logstash-pipeline-for-parsing-with-filebeat-module/203424)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 1\
**Last updated:** [October 15, 2019, 6:19am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-parsing-with-filebeat-module/203424 "2019-10-15T06:19:28Z")

</div>

Hello Team, Currently we are using ELK 6.4.0 but now we want to upgrade on ELK 7.4.0 to use SIEM feature. So we are setting up our testing environment first before making change in prod environment. In ELK version 6.4.…

---

## [Status and listing does not match number of records](https://discuss.elastic.co/t/status-and-listing-does-not-match-number-of-records/202502)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 4\
**Last updated:** [October 15, 2019, 6:51am UTC](https://discuss.elastic.co/t/status-and-listing-does-not-match-number-of-records/202502 "2019-10-15T06:51:34Z")

</div>

Hi all, did you all experience this? the summary and the listing of sites went down does not tally ?

---

## [Metric beat is not pushing data to elastic search - I am using metric beat to monitor host and dockers](https://discuss.elastic.co/t/metric-beat-is-not-pushing-data-to-elastic-search-i-am-using-metric-beat-to-monitor-host-and-dockers/203468)

<div class="topic-metadata">

**Author:** [@ashish\_kumar1490](https://discuss.elastic.co/u/ashish_kumar1490)\
**Replies:** 8\
**Last updated:** [October 15, 2019, 3:54am UTC](https://discuss.elastic.co/t/metric-beat-is-not-pushing-data-to-elastic-search-i-am-using-metric-beat-to-monitor-host-and-dockers/203468 "2019-10-15T03:54:12Z")

</div>

This is for Host metricbeat.modules: …

---

## [Why does filebeat input path not support regex？](https://discuss.elastic.co/t/why-does-filebeat-input-path-not-support-regex/203549)

<div class="topic-metadata">

**Author:** [@mmaxiaolei](https://discuss.elastic.co/u/mmaxiaolei)\
**Replies:** 0\
**Last updated:** [October 15, 2019, 2:39am UTC](https://discuss.elastic.co/t/why-does-filebeat-input-path-not-support-regex/203549 "2019-10-15T02:39:34Z")

</div>

glob is too simple. my logback file pattern：biz.log.yyyy-MM-dd it match：biz.log、biz.log.2019-10-15 but glob should be：biz.log and biz.log.20\[0-9\]\[0-9\]-\[01\]\[0-9\]-\[0123\]\[0-9\]

---

## [Deployment improvement - MSI package](https://discuss.elastic.co/t/deployment-improvement-msi-package/203541)

<div class="topic-metadata">

**Author:** [@danielsnelling](https://discuss.elastic.co/u/danielsnelling)\
**Replies:** 0\
**Last updated:** [October 15, 2019, 12:45am UTC](https://discuss.elastic.co/t/deployment-improvement-msi-package/203541 "2019-10-15T00:45:38Z")

</div>

Hi, I'm in the process of adding Filebeat (and Metricbeat) to hundreds of servers that we want to retrieve logs from. These servers are not all config managed using tools like ansible or puppet, so manual deployment is …

---

## [Auditbeat 7.4 crashing - too many open files](https://discuss.elastic.co/t/auditbeat-7-4-crashing-too-many-open-files/202653)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 4\
**Last updated:** [October 14, 2019, 10:48pm UTC](https://discuss.elastic.co/t/auditbeat-7-4-crashing-too-many-open-files/202653 "2019-10-14T22:48:43Z")

</div>

Seeing errors like these in journal: Oct 02 18:26:50 hostname auditbeat\[30239\]: 2019-10-02T18:26:50.004Z ERROR instance/beat.go:878 Exiting: 1 error: 1 error: system/socket dataset setup failed: …

---

## [Alerting in Filebeat?](https://discuss.elastic.co/t/alerting-in-filebeat/203291)

<div class="topic-metadata">

**Author:** [@neilp](https://discuss.elastic.co/u/neilp)\
**Replies:** 2\
**Last updated:** [October 14, 2019, 6:24pm UTC](https://discuss.elastic.co/t/alerting-in-filebeat/203291 "2019-10-14T18:24:48Z")

</div>

Hi everyone, I was wondering if there is a configuration option in Filebeat to do alerting when it is about to send a log over to logstash? Thanks, Neil

---

## [Does Filebeat support output to S3?](https://discuss.elastic.co/t/does-filebeat-support-output-to-s3/203499)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 1\
**Last updated:** [October 14, 2019, 5:51pm UTC](https://discuss.elastic.co/t/does-filebeat-support-output-to-s3/203499 "2019-10-14T17:51:43Z")

</div>

Is there an output plugging for AWS S3 ? Need to send container logs to S3. Thanks John

---

## [Can't collect data from other namespaces?](https://discuss.elastic.co/t/cant-collect-data-from-other-namespaces/203170)

<div class="topic-metadata">

**Author:** [@ZMMWMY](https://discuss.elastic.co/u/ZMMWMY)\
**Replies:** 1\
**Last updated:** [October 14, 2019, 4:28pm UTC](https://discuss.elastic.co/t/cant-collect-data-from-other-namespaces/203170 "2019-10-14T16:28:35Z")

</div>

For example, I have two namespaces A and B. I deploy it in namespace A, which does not collect data from namespace B. But if I use filebeat , it won't be the problem ,filebeat can collect data from all namespaces.

---

## [In TCP, what happens if I use strange hosts?](https://discuss.elastic.co/t/in-tcp-what-happens-if-i-use-strange-hosts/203200)

<div class="topic-metadata">

**Author:** [@111219](https://discuss.elastic.co/u/111219)\
**Replies:** 1\
**Last updated:** [October 14, 2019, 4:26pm UTC](https://discuss.elastic.co/t/in-tcp-what-happens-if-i-use-strange-hosts/203200 "2019-10-14T16:26:41Z")

</div>

I am registering a host according to the form. My question is as follows: What happens if I register a non-existent host such as 'aaaaabbbbbccc.com'? How long is the timeout while connecting to an unresponsive host…

---

## [Does this check the host in parallel?](https://discuss.elastic.co/t/does-this-check-the-host-in-parallel/203365)

<div class="topic-metadata">

**Author:** [@111219](https://discuss.elastic.co/u/111219)\
**Replies:** 1\
**Last updated:** [October 14, 2019, 4:22pm UTC](https://discuss.elastic.co/t/does-this-check-the-host-in-parallel/203365 "2019-10-14T16:22:44Z")

</div>

I am wondering whether it is serial or parallel. If it's parallel, I want to know how many things are processed at the same time.

---

## [Beats - fatal error: concurrent map iteration and map write](https://discuss.elastic.co/t/beats-fatal-error-concurrent-map-iteration-and-map-write/203489)

<div class="topic-metadata">

**Author:** [@vishnug](https://discuss.elastic.co/u/vishnug)\
**Replies:** 0\
**Last updated:** [October 14, 2019, 4:12pm UTC](https://discuss.elastic.co/t/beats-fatal-error-concurrent-map-iteration-and-map-write/203489 "2019-10-14T16:12:54Z")

</div>

Hi I was following this doc to create a custom beat. I was able to build and run the beat.I encountered an error while running it fatal error: concurrent map iteration and map write goroutine 1 \[running\]: runtime.thr…

---

## [Metricbeat Failing to connect to Elasticsearch version 7.1.1 on aws](https://discuss.elastic.co/t/metricbeat-failing-to-connect-to-elasticsearch-version-7-1-1-on-aws/202039)

<div class="topic-metadata">

**Author:** [@Sanjanar](https://discuss.elastic.co/u/Sanjanar)\
**Replies:** 1\
**Last updated:** [October 14, 2019, 3:29pm UTC](https://discuss.elastic.co/t/metricbeat-failing-to-connect-to-elasticsearch-version-7-1-1-on-aws/202039 "2019-10-14T15:29:39Z")

</div>

Hi all, I am trying to install https://github.com/elastic/helm-charts/tree/master/metricbeat helmchart on kubernetes with the following configurations: prometheus.yml: | metricbeat.modules: - module: promet…

---

## [How to cache metric data?](https://discuss.elastic.co/t/how-to-cache-metric-data/202895)

<div class="topic-metadata">

**Author:** [@pixelrebel](https://discuss.elastic.co/u/pixelrebel)\
**Replies:** 1\
**Last updated:** [October 14, 2019, 2:04pm UTC](https://discuss.elastic.co/t/how-to-cache-metric-data/202895 "2019-10-14T14:04:23Z")

</div>

I ran a test and disconnected the network from a system with metricbeat running. When network came back, metricbeat never sent the data that was collected during the outage. There is a gap in my data. How do I enable …

---

## [Output to different kafka topic](https://discuss.elastic.co/t/output-to-different-kafka-topic/203465)

<div class="topic-metadata">

**Author:** [@Fabien\_Morel](https://discuss.elastic.co/u/Fabien_Morel)\
**Replies:** 0\
**Last updated:** [October 14, 2019, 1:26pm UTC](https://discuss.elastic.co/t/output-to-different-kafka-topic/203465 "2019-10-14T13:26:34Z")

</div>

Hi ! I'm using filebeat 7.4.0 to send linux logs to kafka. I want to split the data from one file into 2 topics. For example data from /var/log/secure should go to topic1 if it contains "sudo" and topic2 if not. My pr…

---

## [Multiple config file](https://discuss.elastic.co/t/multiple-config-file/203448)

<div class="topic-metadata">

**Author:** [@Mohammad.ali](https://discuss.elastic.co/u/Mohammad.ali)\
**Replies:** 3\
**Last updated:** [October 14, 2019, 12:40pm UTC](https://discuss.elastic.co/t/multiple-config-file/203448 "2019-10-14T12:40:35Z")

</div>

Hello everyone i have a simple filebeat.yml which send some log from specific path to logstash my problem is how can i activate some filebeat modules such as system on this host while the output of filebeat.yml is logs…

---

## [Parse Log file using Filebeat, filter the data and save it to elasticsearch database](https://discuss.elastic.co/t/parse-log-file-using-filebeat-filter-the-data-and-save-it-to-elasticsearch-database/203447)

<div class="topic-metadata">

**Author:** [@Nehajain](https://discuss.elastic.co/u/Nehajain)\
**Replies:** 1\
**Last updated:** [October 14, 2019, 12:35pm UTC](https://discuss.elastic.co/t/parse-log-file-using-filebeat-filter-the-data-and-save-it-to-elasticsearch-database/203447 "2019-10-14T12:35:25Z")

</div>

Hi, I have to read a log file using File Beat, apply few filters and then save this filtered data to Elastic Search database using PUT and POST queries. I could read log file, get the data in elastic search. I could s…

---

## [Increasing throughput from Filebeat to Logstash](https://discuss.elastic.co/t/increasing-throughput-from-filebeat-to-logstash/199450)

<div class="topic-metadata">

**Author:** [@nathansegers](https://discuss.elastic.co/u/nathansegers)\
**Replies:** 0\
**Last updated:** [September 13, 2019, 2:44pm UTC](https://discuss.elastic.co/t/increasing-throughput-from-filebeat-to-logstash/199450 "2019-09-13T14:44:39Z")

</div>

I am using latest versions of Filebeat, Logstash and Elasticsearch on Ubuntu 18.04 machines I have: 2 filebeat VM's, configured with 8 CPU cores and 16 GB Memory 3 logstash VM's with 24 CPU cores and 64 Gb Memory (31G…

---

## [Issue : Error decoding JSON: json: cannot unmarshal string into Go value of type map\[string\]interface {}](https://discuss.elastic.co/t/issue-error-decoding-json-json-cannot-unmarshal-string-into-go-value-of-type-map-string-interface/202293)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 2\
**Last updated:** [October 14, 2019, 6:50am UTC](https://discuss.elastic.co/t/issue-error-decoding-json-json-cannot-unmarshal-string-into-go-value-of-type-map-string-interface/202293 "2019-10-14T06:50:05Z")

</div>

Hi, i'm using the elk stack 7.1.1 with x-pack installed and i trying to parse json log into logstash and apply grok filter to it then im getting the following error Error decoding JSON: json: cannot unmarshal string i…

---

## [Configuring decode\_json\_fields using docker labels](https://discuss.elastic.co/t/configuring-decode-json-fields-using-docker-labels/203378)

<div class="topic-metadata">

**Author:** [@trajano](https://discuss.elastic.co/u/trajano)\
**Replies:** 1\
**Last updated:** [October 14, 2019, 6:31am UTC](https://discuss.elastic.co/t/configuring-decode-json-fields-using-docker-labels/203378 "2019-10-14T06:31:43Z")

</div>

I have a service which I am deploying to the swarm. Specifically for the Kibana logs It has the following labels defined: deploy: labels: co.elastic.logs/processors.1.decode\_json\_fields.overwrite\_keys: "true" …

---

## [Nginx module | Processor drop\_event HTTP 200 not working](https://discuss.elastic.co/t/nginx-module-processor-drop-event-http-200-not-working/203352)

<div class="topic-metadata">

**Author:** [@lfraga](https://discuss.elastic.co/u/lfraga)\
**Replies:** 2\
**Last updated:** [October 14, 2019, 1:41am UTC](https://discuss.elastic.co/t/nginx-module-processor-drop-event-http-200-not-working/203352 "2019-10-14T01:41:26Z")

</div>

I'm trying to exclude HTTP 200 events from Nginx module using processors My config file nginx.yml is # Module: nginx # Docs: https://www.elastic.co/guide/en/beats/filebeat/7.4/filebeat-module-nginx.html - module: ngin…

---

## [How many log files can filebeat following at the same time?](https://discuss.elastic.co/t/how-many-log-files-can-filebeat-following-at-the-same-time/203362)

<div class="topic-metadata">

**Author:** [@ted\_ye](https://discuss.elastic.co/u/ted_ye)\
**Replies:** 0\
**Last updated:** [October 14, 2019, 12:44am UTC](https://discuss.elastic.co/t/how-many-log-files-can-filebeat-following-at-the-same-time/203362 "2019-10-14T00:44:54Z")

</div>

Hi , I have a question about using filebeat to collect logs. My logs is special , the log path is using strftime ,e.g. now is 2019/10/14 8:39:00, and the log path is /app/logs/19/10/14/08/39/00/a.log, it meas every sec…

---

## [Filebeat - drop fields processor doesn't remove agent.\* and ecs fields. (Without Logstash)](https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985)

<div class="topic-metadata">

**Author:** [@turgayozgur](https://discuss.elastic.co/u/turgayozgur)\
**Replies:** 3\
**Last updated:** [October 13, 2019, 11:44am UTC](https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985 "2019-10-13T11:44:49Z")

</div>

The drop fields section is working for the other fields like kubernetes.pod.id but it is not working for agent.\* and ecs fields. Any workaround here? Version: 7.3.2 Operating System: Linux Steps to Reproduce: Apply th…

---

## [How do you enable modules via the command line](https://discuss.elastic.co/t/how-do-you-enable-modules-via-the-command-line/202915)

<div class="topic-metadata">

**Author:** [@trajano](https://discuss.elastic.co/u/trajano)\
**Replies:** 3\
**Last updated:** [October 13, 2019, 4:54am UTC](https://discuss.elastic.co/t/how-do-you-enable-modules-via-the-command-line/202915 "2019-10-13T04:54:14Z")

</div>

I'm trying to run metric beats without having a configuration file. I was wondering how do you enable modules? I tried -E modules.docker.enable=true -E module.docker.enable=true -E metricbeat.modules=\[module.docker.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=308)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=310)
