# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=310

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 311

---

## [Problem with Filebeat and Kafka](https://discuss.elastic.co/t/problem-with-filebeat-and-kafka/202988)

<div class="topic-metadata">

**Author:** [@saisimo02](https://discuss.elastic.co/u/saisimo02)\
**Replies:** 3\
**Last updated:** [October 11, 2019, 9:02pm UTC](https://discuss.elastic.co/t/problem-with-filebeat-and-kafka/202988 "2019-10-11T21:02:54Z")

</div>

Hello, I have a problem with my configuration filebeat+kafka+logstash. I have a lot of files every minute and I am using kafka between filebeat and logstash to deal with that. Filebeat send an error message: 2019-10-…

---

## [Filebeat haproxy module messages](https://discuss.elastic.co/t/filebeat-haproxy-module-messages/202628)

<div class="topic-metadata">

**Author:** [@froot](https://discuss.elastic.co/u/froot)\
**Replies:** 3\
**Last updated:** [October 11, 2019, 2:30pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-messages/202628 "2019-10-11T14:30:03Z")

</div>

Hello, i would like to use the haproxy module of filebeat. The logs also arrive on my ELK stack, unfortunately messages are not converted into keyvalues. The Informations are still in message. How can I customize this…

---

## [Split and access to array elements](https://discuss.elastic.co/t/split-and-access-to-array-elements/199689)

<div class="topic-metadata">

**Author:** [@matapo](https://discuss.elastic.co/u/matapo)\
**Replies:** 1\
**Last updated:** [October 11, 2019, 2:02pm UTC](https://discuss.elastic.co/t/split-and-access-to-array-elements/199689 "2019-10-11T14:02:56Z")

</div>

Hi, I am trying to split a field and to register each element of the given array in new fields (filebeat 7.3.1). url.array is well created as an array and contains my 2 elements. That's ok for that. I've tried : …

---

## [FIlebeat failed to connect to backoff(elasticsearch(http://elasticsearch:9200)](https://discuss.elastic.co/t/filebeat-failed-to-connect-to-backoff-elasticsearch-http-elasticsearch-9200/203241)

<div class="topic-metadata">

**Author:** [@xwiz](https://discuss.elastic.co/u/xwiz)\
**Replies:** 0\
**Last updated:** [October 11, 2019, 1:23pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-connect-to-backoff-elasticsearch-http-elasticsearch-9200/203241 "2019-10-11T13:23:16Z")

</div>

Hello! I try to configure sending logs from my cluster Kubernetes with filebeats. I installed filebeat 7.1.1 oss in my cluster via filebeat-kubernetes.yaml: --- apiVersion: v1 kind: ConfigMap metadata: name: filebeat…

---

## [Alert on new windows update available](https://discuss.elastic.co/t/alert-on-new-windows-update-available/201632)

<div class="topic-metadata">

**Author:** [@INML](https://discuss.elastic.co/u/INML)\
**Replies:** 2\
**Last updated:** [October 11, 2019, 12:57pm UTC](https://discuss.elastic.co/t/alert-on-new-windows-update-available/201632 "2019-10-11T12:57:09Z")

</div>

Hello there, I have an idea of creating a watcher that sends me a mail when a new windows update is detected by the windows update service on a specific server. I already tried to find something with winlogbeat but i di…

---

## [How to collect nginx request duration using filebeat](https://discuss.elastic.co/t/how-to-collect-nginx-request-duration-using-filebeat/201684)

<div class="topic-metadata">

**Author:** [@p.anas](https://discuss.elastic.co/u/p.anas)\
**Replies:** 1\
**Last updated:** [October 11, 2019, 9:39am UTC](https://discuss.elastic.co/t/how-to-collect-nginx-request-duration-using-filebeat/201684 "2019-10-11T09:39:07Z")

</div>

Goal: I would like to collect request duration using filebeat (with version 6.8.1). The existing nginx module does not support it. I have seen that existing nginx module is using ingest pipeline to parse the essential …

---

## [Heartbeat sighup received](https://discuss.elastic.co/t/heartbeat-sighup-received/201267)

<div class="topic-metadata">

**Author:** [@ea1987](https://discuss.elastic.co/u/ea1987)\
**Replies:** 3\
**Last updated:** [October 11, 2019, 10:20am UTC](https://discuss.elastic.co/t/heartbeat-sighup-received/201267 "2019-10-11T10:20:49Z")

</div>

Hi all, I usually start Heartbeat (and other beats) with the following command: nohup ./beatname \>/dev/null 2\>&1 & but heartbeat stops after a while (random period). I checked on debug logs and this is the message I…

---

## [Filebeat wont post log messages to Elastic](https://discuss.elastic.co/t/filebeat-wont-post-log-messages-to-elastic/201872)

<div class="topic-metadata">

**Author:** [@Wanderer](https://discuss.elastic.co/u/Wanderer)\
**Replies:** 1\
**Last updated:** [October 11, 2019, 9:28am UTC](https://discuss.elastic.co/t/filebeat-wont-post-log-messages-to-elastic/201872 "2019-10-11T09:28:44Z")

</div>

This is the error we get. Any thoughts? filebeat: 2019-10-01T17:19:04.468-0400#011ERROR#011pipeline/output.go:100#011Failed to connect to backoff(elasticsearch(https://server.name.com:1234)): Connection marked as failed…

---

## [Edditing The Filebeat Default Mappings](https://discuss.elastic.co/t/edditing-the-filebeat-default-mappings/202439)

<div class="topic-metadata">

**Author:** [@Jacob\_Amar](https://discuss.elastic.co/u/Jacob_Amar)\
**Replies:** 1\
**Last updated:** [October 11, 2019, 8:22am UTC](https://discuss.elastic.co/t/edditing-the-filebeat-default-mappings/202439 "2019-10-11T08:22:36Z")

</div>

Hey guys, My name is Jacob and im using filebeat for our log collections with ELK stack. ELK is amazing but we have a problem we have a lot of fields like "host.os.name" or "host.os.platform" that we don't need, How can…

---

## [Kibana Index Patterns not shown and cannot create a new one](https://discuss.elastic.co/t/kibana-index-patterns-not-shown-and-cannot-create-a-new-one/201474)

<div class="topic-metadata">

**Author:** [@Hung\_M\_Le](https://discuss.elastic.co/u/Hung_M_Le)\
**Replies:** 2\
**Last updated:** [October 10, 2019, 10:51pm UTC](https://discuss.elastic.co/t/kibana-index-patterns-not-shown-and-cannot-create-a-new-one/201474 "2019-10-10T22:51:57Z")

</div>

Hi i am configuring in the filebeat.tml file the following setting. I can see that the new template was created and shown inside Kibana -\> elasticsearch -\> Index Management (I uploaded the picture for your reference) af…

---

## [Filebeat output indices behavior](https://discuss.elastic.co/t/filebeat-output-indices-behavior/202934)

<div class="topic-metadata">

**Author:** [@ninjasloth](https://discuss.elastic.co/u/ninjasloth)\
**Replies:** 1\
**Last updated:** [October 10, 2019, 6:25pm UTC](https://discuss.elastic.co/t/filebeat-output-indices-behavior/202934 "2019-10-10T18:25:16Z")

</div>

Currently I am using a custom index pattern via indices when filters. This works as expected. However anything not matching the rule ends up being sent to the default filebeat- index. As per the docs this makes sense: …

---

## [FileBeat Log Message combine](https://discuss.elastic.co/t/filebeat-log-message-combine/203062)

<div class="topic-metadata">

**Author:** [@warnerrj79](https://discuss.elastic.co/u/warnerrj79)\
**Replies:** 1\
**Last updated:** [October 10, 2019, 4:03pm UTC](https://discuss.elastic.co/t/filebeat-log-message-combine/203062 "2019-10-10T16:03:05Z")

</div>

Hi. I am looking for a way (in FileBeat if possible) to combine log messages that are timestamped at the same time. For example, I have an error log message with 9 lines. If I search for a certain word in the log via K…

---

## [Beats setup fails with custom kibana\_index](https://discuss.elastic.co/t/beats-setup-fails-with-custom-kibana-index/202984)

<div class="topic-metadata">

**Author:** [@waraiotoko](https://discuss.elastic.co/u/waraiotoko)\
**Replies:** 0\
**Last updated:** [October 10, 2019, 9:01am UTC](https://discuss.elastic.co/t/beats-setup-fails-with-custom-kibana-index/202984 "2019-10-10T09:01:31Z")

</div>

When setting up a new secure stack I noticed that beat setup fails when all of these are true: xpack.security.enabled: true using setup user as described in Grant users access to secured resources | Metricbeat Referenc…

---

## [Can we use S3 bucket as input in function beat and send data to some ingest pipeline](https://discuss.elastic.co/t/can-we-use-s3-bucket-as-input-in-function-beat-and-send-data-to-some-ingest-pipeline/201560)

<div class="topic-metadata">

**Author:** [@akki2208](https://discuss.elastic.co/u/akki2208)\
**Replies:** 2\
**Last updated:** [October 10, 2019, 8:34am UTC](https://discuss.elastic.co/t/can-we-use-s3-bucket-as-input-in-function-beat-and-send-data-to-some-ingest-pipeline/201560 "2019-10-10T08:34:57Z")

</div>

Can we use S3 bucket as input in function beat and send data to some ingest pipeline.

---

## [Deduplication in beats while sending logs to Logstash or Elasticsearch](https://discuss.elastic.co/t/deduplication-in-beats-while-sending-logs-to-logstash-or-elasticsearch/202942)

<div class="topic-metadata">

**Author:** [@nindate](https://discuss.elastic.co/u/nindate)\
**Replies:** 0\
**Last updated:** [October 10, 2019, 4:51am UTC](https://discuss.elastic.co/t/deduplication-in-beats-while-sending-logs-to-logstash-or-elasticsearch/202942 "2019-10-10T04:51:51Z")

</div>

Hi, I am sure this point would have been considered already, but since I could not find any reference to this, asking it here. When various beats send log data to Logstash/Elasticsearch data for most of the fields from…

---

## [Packetbeat not capturing anything when \`packetbeat.flows: enabled: false\`](https://discuss.elastic.co/t/packetbeat-not-capturing-anything-when-packetbeat-flows-enabled-false/202909)

<div class="topic-metadata">

**Author:** [@shreyapatel](https://discuss.elastic.co/u/shreyapatel)\
**Replies:** 0\
**Last updated:** [October 9, 2019, 8:54pm UTC](https://discuss.elastic.co/t/packetbeat-not-capturing-anything-when-packetbeat-flows-enabled-false/202909 "2019-10-09T20:54:05Z")

</div>

I am using Packetbeat v5.6.16 and want to monitor the data in P4 packets captured. Enabling packetbeat.flows does not capture the individual packet data; only header information in bulk is captured. Disabling packetbea…

---

## [Can't complete filebeat setup due to failed ML setup](https://discuss.elastic.co/t/cant-complete-filebeat-setup-due-to-failed-ml-setup/202893)

<div class="topic-metadata">

**Author:** [@DigitalMachinist](https://discuss.elastic.co/u/DigitalMachinist)\
**Replies:** 1\
**Last updated:** [October 9, 2019, 7:21pm UTC](https://discuss.elastic.co/t/cant-complete-filebeat-setup-due-to-failed-ml-setup/202893 "2019-10-09T19:21:34Z")

</div>

I'm getting an error whenever I run filebeat setup caused by filebeat being unable to setup ML jobs (that I don't even use). Here's the terminal output: \> sudo filebeat setup Loaded index template Loading dashboards (Ki…

---

## [Multiple indexes output and ilm coliision](https://discuss.elastic.co/t/multiple-indexes-output-and-ilm-coliision/202481)

<div class="topic-metadata">

**Author:** [@Aviad\_Hadida](https://discuss.elastic.co/u/Aviad_Hadida)\
**Replies:** 1\
**Last updated:** [October 9, 2019, 6:30pm UTC](https://discuss.elastic.co/t/multiple-indexes-output-and-ilm-coliision/202481 "2019-10-09T18:30:01Z")

</div>

Hi. I have a use case where i have several index i would like to use. But it seems that index name are not affected when using ilm. Look on the linked discussion: Is there a way to achieve this behavior with ilm? How…

---

## [Metricbeat 7.3.1 not delete](https://discuss.elastic.co/t/metricbeat-7-3-1-not-delete/202829)

<div class="topic-metadata">

**Author:** [@mirketto82](https://discuss.elastic.co/u/mirketto82)\
**Replies:** 1\
**Last updated:** [October 9, 2019, 6:01pm UTC](https://discuss.elastic.co/t/metricbeat-7-3-1-not-delete/202829 "2019-10-09T18:01:27Z")

</div>

hello guys i just installed the new metricbeat 7.4.0,but when i opend the metric i have this error: shards failed and the name for the old version metricbeat infact i see in the index managemente the old version 7.3.1…

---

## [Beats Central Management in ECE error creating a new enrollment token unexpected number of tokens got 0 only one expected](https://discuss.elastic.co/t/beats-central-management-in-ece-error-creating-a-new-enrollment-token-unexpected-number-of-tokens-got-0-only-one-expected/202717)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 3\
**Last updated:** [October 9, 2019, 5:13pm UTC](https://discuss.elastic.co/t/beats-central-management-in-ece-error-creating-a-new-enrollment-token-unexpected-number-of-tokens-got-0-only-one-expected/202717 "2019-10-09T17:13:17Z")

</div>

Were trying to use Beats Central Management in ECE 2.3 by using a username and password so that we can script this when we deploy to numerous servers. The metricbeat is not set as a service on one of our testing comput…

---

## [Filebeat cisco module not parsing ASA logs](https://discuss.elastic.co/t/filebeat-cisco-module-not-parsing-asa-logs/202871)

<div class="topic-metadata">

**Author:** [@JayK](https://discuss.elastic.co/u/JayK)\
**Replies:** 0\
**Last updated:** [October 9, 2019, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-not-parsing-asa-logs/202871 "2019-10-09T15:45:35Z")

</div>

Our ASA sends its logs to a server where they handled by rsyslog and placed in the necessary directories. FIlebeat, running on the same server, then sends them to Elasticsearch using the cisco module. It looks like every…

---

## [System/socket module stops auditbeat 7.4 from starting (ipv6 detection)](https://discuss.elastic.co/t/system-socket-module-stops-auditbeat-7-4-from-starting-ipv6-detection/201852)

<div class="topic-metadata">

**Author:** [@stephan13360](https://discuss.elastic.co/u/stephan13360)\
**Replies:** 9\
**Last updated:** [October 9, 2019, 3:01pm UTC](https://discuss.elastic.co/t/system-socket-module-stops-auditbeat-7-4-from-starting-ipv6-detection/201852 "2019-10-09T15:01:51Z")

</div>

With the update to 7.4 some of my auditbeats now longer start. (for me the ones running on digitalocean). The error is: ERROR instance/beat.go:878 Exiting: 1 error: 1 error: system/socket dataset setup failed: unable t…

---

## [Mssql module on metricbeat oss](https://discuss.elastic.co/t/mssql-module-on-metricbeat-oss/202837)

<div class="topic-metadata">

**Author:** [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Replies:** 0\
**Last updated:** [October 9, 2019, 1:31pm UTC](https://discuss.elastic.co/t/mssql-module-on-metricbeat-oss/202837 "2019-10-09T13:31:04Z")

</div>

hi, Can I use mssql module on metricbeat oss(7.3.2 and 7.4) version? # metricbeat modules list|grep mssql mssql It's on the list, but when I enable it, metricbeat failed to start. Thanks for aswer.

---

## [Filebeat 7.4.0 issue](https://discuss.elastic.co/t/filebeat-7-4-0-issue/202680)

<div class="topic-metadata">

**Author:** [@mirketto82](https://discuss.elastic.co/u/mirketto82)\
**Replies:** 2\
**Last updated:** [October 9, 2019, 12:27pm UTC](https://discuss.elastic.co/t/filebeat-7-4-0-issue/202680 "2019-10-09T12:27:14Z")

</div>

hello today i updated the new filebeat with new version release 7.4.0. i configured the yml file but when i try this two commands: ./filebeat setup ./filebeat -e i received this error: bash: ./filebeat: cannot exec…

---

## [In filebeat, what is the difference between json.keys\_under\_root and decode\_json\_fields](https://discuss.elastic.co/t/in-filebeat-what-is-the-difference-between-json-keys-under-root-and-decode-json-fields/202732)

<div class="topic-metadata">

**Author:** [@john\_eapen](https://discuss.elastic.co/u/john_eapen)\
**Replies:** 1\
**Last updated:** [October 9, 2019, 10:49am UTC](https://discuss.elastic.co/t/in-filebeat-what-is-the-difference-between-json-keys-under-root-and-decode-json-fields/202732 "2019-10-09T10:49:06Z")

</div>

I am confused about the difference between json.keys\_under\_root and decode\_json\_fields. Are these overlapping options ? I need the fields to be under root. I am getting these error and was wondering if decode\_json\_fie…

---

## [Incorrect request response mapping for a few requests in a Kubernetes environment](https://discuss.elastic.co/t/incorrect-request-response-mapping-for-a-few-requests-in-a-kubernetes-environment/202814)

<div class="topic-metadata">

**Author:** [@kumud.t](https://discuss.elastic.co/u/kumud.t)\
**Replies:** 0\
**Last updated:** [October 9, 2019, 10:43am UTC](https://discuss.elastic.co/t/incorrect-request-response-mapping-for-a-few-requests-in-a-kubernetes-environment/202814 "2019-10-09T10:43:37Z")

</div>

I have installed packetbeat OSS (v6.8.3) using this YAML reference on a K8s cluster (v 1.10.13) with Docker (v 17.9.0) running on Debian GNU/Linux 9 (stretch) (4.9.0-7-amd64). The traffic ingress to our applications w…

---

## [New Needing in Filebeat (Protobuf Codec In Output Configuration)](https://discuss.elastic.co/t/new-needing-in-filebeat-protobuf-codec-in-output-configuration/202804)

<div class="topic-metadata">

**Author:** [@kiss001](https://discuss.elastic.co/u/kiss001)\
**Replies:** 1\
**Last updated:** [October 9, 2019, 10:37am UTC](https://discuss.elastic.co/t/new-needing-in-filebeat-protobuf-codec-in-output-configuration/202804 "2019-10-09T10:37:06Z")

</div>

I found there only hava two codec method in https://www.elastic.co/guide/en/beats/filebeat/current/configuration-output-codec.html website, Now I hava a new requirement that It use protocol buffer to codec the data. Whet…

---

## [Watcher repository by metricbeat module (kubernetes, system)](https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 3\
**Last updated:** [October 8, 2019, 10:03pm UTC](https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736 "2019-10-08T22:03:22Z")

</div>

Hi, What do people here think of creating a repository to store default (or example) Watcher alerts for the kubernetes and/or system module? (I'm also in favor of other modules but we should pick somewhere to start). M…

---

## [Undefined: publisher.Client missing from go imports](https://discuss.elastic.co/t/undefined-publisher-client-missing-from-go-imports/202731)

<div class="topic-metadata">

**Author:** [@dakoller](https://discuss.elastic.co/u/dakoller)\
**Replies:** 0\
**Last updated:** [October 8, 2019, 9:15pm UTC](https://discuss.elastic.co/t/undefined-publisher-client-missing-from-go-imports/202731 "2019-10-08T21:15:52Z")

</div>

I followed the beats tutorial at https://www.elastic.co/guide/en/beats/devguide/current/beater-interface.html and my go file gives an error at publisher.Client() ... obviously the import is missing. my imports: import …

---

## [Why event.code has string type?](https://discuss.elastic.co/t/why-event-code-has-string-type/199678)

<div class="topic-metadata">

**Author:** [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Replies:** 2\
**Last updated:** [October 8, 2019, 5:27pm UTC](https://discuss.elastic.co/t/why-event-code-has-string-type/199678 "2019-10-08T17:27:18Z")

</div>

Hello. Why event.code has string type and not number by default?Thats why i can't properly filter. If you filter by 7 - you find a lot of - 4557, 4755, 4575 and so on. Also, you cant use ranges.

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=309)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=311)
