# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=311

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 312

---

## [Winlogbeat - Cannot start](https://discuss.elastic.co/t/winlogbeat-cannot-start/202692)

<div class="topic-metadata">

**Author:** [@NewmazN24](https://discuss.elastic.co/u/NewmazN24)\
**Replies:** 3\
**Last updated:** [October 8, 2019, 3:29pm UTC](https://discuss.elastic.co/t/winlogbeat-cannot-start/202692 "2019-10-08T15:29:06Z")

</div>

Hello Folks, I use SSL/TLS encryption, it works fine. I use keystore to access my password. When I launch winlogbeat from powershell, it fails, see error below. However, if I make it run manually from PowerShell, I hav…

---

## [Index template not working from Filebeat to ES](https://discuss.elastic.co/t/index-template-not-working-from-filebeat-to-es/202684)

<div class="topic-metadata">

**Author:** [@ISR\_FY](https://discuss.elastic.co/u/ISR_FY)\
**Replies:** 2\
**Last updated:** [October 8, 2019, 2:55pm UTC](https://discuss.elastic.co/t/index-template-not-working-from-filebeat-to-es/202684 "2019-10-08T14:55:14Z")

</div>

Hi, team: I´ve found an issue in my config about the creation of index. In logs I can see this error: But I have got configured this in filebeat.yml: Now I´ve updated to 7.4 the ELK but in 6.8 version the index wa…

---

## [Filebeat-panw Module timezone issues](https://discuss.elastic.co/t/filebeat-panw-module-timezone-issues/202193)

<div class="topic-metadata">

**Author:** [@jbenner](https://discuss.elastic.co/u/jbenner)\
**Replies:** 7\
**Last updated:** [October 8, 2019, 12:38pm UTC](https://discuss.elastic.co/t/filebeat-panw-module-timezone-issues/202193 "2019-10-08T12:38:22Z")

</div>

Hello, I am sorry to re-hash the same issue others have had but I can't seem to get the fixes they have done to work for my environment and it has driven me crazy trying to figure it out. So right now, when I setup File…

---

## [Monitoring a secure elasticsearch cluster with heartbeat](https://discuss.elastic.co/t/monitoring-a-secure-elasticsearch-cluster-with-heartbeat/202323)

<div class="topic-metadata">

**Author:** [@Maekee](https://discuss.elastic.co/u/Maekee)\
**Replies:** 4\
**Last updated:** [October 8, 2019, 12:13pm UTC](https://discuss.elastic.co/t/monitoring-a-secure-elasticsearch-cluster-with-heartbeat/202323 "2019-10-08T12:13:16Z")

</div>

Hello, I have a monitor on all my cluster nodes that monitors on port 9200. But after enabling security, the heartbeat cannot of course access ES. What is the syntax for the monitor to login securely This is my curre…

---

## [Won't start runner: monitor ID user-center is configured for multiple monitors! IDs must be unique values](https://discuss.elastic.co/t/wont-start-runner-monitor-id-user-center-is-configured-for-multiple-monitors-ids-must-be-unique-values/200961)

<div class="topic-metadata">

**Author:** [@ZMMWMY](https://discuss.elastic.co/u/ZMMWMY)\
**Replies:** 9\
**Last updated:** [October 8, 2019, 3:20am UTC](https://discuss.elastic.co/t/wont-start-runner-monitor-id-user-center-is-configured-for-multiple-monitors-ids-must-be-unique-values/200961 "2019-10-08T03:20:08Z")

</div>

i have changed my question when i restart my application in k8s , i found error message in heartbeat log won't start runner: monitor ID user-center is configured for multiple monitors! IDs must be unique values. What…

---

## [Index lifecycle error security\_exception, permission issue](https://discuss.elastic.co/t/index-lifecycle-error-security-exception-permission-issue/202572)

<div class="topic-metadata">

**Author:** [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Replies:** 0\
**Last updated:** [October 7, 2019, 4:59pm UTC](https://discuss.elastic.co/t/index-lifecycle-error-security-exception-permission-issue/202572 "2019-10-07T16:59:17Z")

</div>

We just installed beats with recommenced permissions, but now we'll getting the same permission issues from all beats. 5 indices have lifecycle errors in Kibana under Management / Index management security\_exception: a…

---

## [How to get LDAP metrics](https://discuss.elastic.co/t/how-to-get-ldap-metrics/202516)

<div class="topic-metadata">

**Author:** [@Hamad\_Almogbl](https://discuss.elastic.co/u/Hamad_Almogbl)\
**Replies:** 0\
**Last updated:** [October 7, 2019, 11:05am UTC](https://discuss.elastic.co/t/how-to-get-ldap-metrics/202516 "2019-10-07T11:05:42Z")

</div>

Hello everyone, I would like to know how to get the metrics of LDAP. Thank you

---

## [Json.error and Logs are getting broken in elastic search](https://discuss.elastic.co/t/json-error-and-logs-are-getting-broken-in-elastic-search/202322)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 1\
**Last updated:** [October 7, 2019, 5:32am UTC](https://discuss.elastic.co/t/json-error-and-logs-are-getting-broken-in-elastic-search/202322 "2019-10-07T05:32:19Z")

</div>

Hi, i'm using elk stack 5.5 version without x-pack i'm getting json.errors very frequent and those logs are not reading or writting properly into elasticsearch ? and this is happening for every 5 to 10 mins. please he…

---

## [Filebeat 7.4, decode\_cef getting error malformed value](https://discuss.elastic.co/t/filebeat-7-4-decode-cef-getting-error-malformed-value/202469)

<div class="topic-metadata">

**Author:** [@cling1988](https://discuss.elastic.co/u/cling1988)\
**Replies:** 0\
**Last updated:** [October 7, 2019, 3:11am UTC](https://discuss.elastic.co/t/filebeat-7-4-decode-cef-getting-error-malformed-value/202469 "2019-10-07T03:11:08Z")

</div>

I using Filebeat 7.4 and using the decode\_cef processors. And I getting error "malformed value for eventAnnotationAuditTrail at pos 2165" After checking the raw source, the position 2165 is the "\\n" eventAnnotationMod…

---

## [Metricbeat is not working out-of-the-box](https://discuss.elastic.co/t/metricbeat-is-not-working-out-of-the-box/199333)

<div class="topic-metadata">

**Author:** [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Replies:** 5\
**Last updated:** [October 6, 2019, 2:04pm UTC](https://discuss.elastic.co/t/metricbeat-is-not-working-out-of-the-box/199333 "2019-10-06T14:04:14Z")

</div>

I followed the instructions and setup the metricbeat and Kibana dashboard, all default configurations. But it doesn't show a lot of metrics, please see the screenshot. Environment: Ubuntu 18.04, installed using deb appr…

---

## [K8s autodiscovery doesn't accept metrics\_path](https://discuss.elastic.co/t/k8s-autodiscovery-doesnt-accept-metrics-path/202446)

<div class="topic-metadata">

**Author:** [@michaelh](https://discuss.elastic.co/u/michaelh)\
**Replies:** 0\
**Last updated:** [October 6, 2019, 1:41pm UTC](https://discuss.elastic.co/t/k8s-autodiscovery-doesnt-accept-metrics-path/202446 "2019-10-06T13:41:33Z")

</div>

I am running metricbeat 7.4.0 as DaemonSet and another Spring boot 2 application deployment annotated as following; spec: replicas: 1 selector: matchLabels: app: petclinic template: metadata: l…

---

## [Cannot see data on Kiabana](https://discuss.elastic.co/t/cannot-see-data-on-kiabana/201274)

<div class="topic-metadata">

**Author:** [@Kernel\_Panic](https://discuss.elastic.co/u/Kernel_Panic)\
**Replies:** 4\
**Last updated:** [October 5, 2019, 5:42pm UTC](https://discuss.elastic.co/t/cannot-see-data-on-kiabana/201274 "2019-10-05T17:42:12Z")

</div>

Hello there Server info: CentOS Linux release 7.7.1908 (Core) packetbeat-6.8.3-1.x86\_64 kibana-6.8.3-1.x86\_64 elasticsearch-6.8.3-1.noarch I cannot see the data on kibana when performing searches like this: beat.ho…

---

## [Filebeat Autodiscovery for coredns in docker, what labels to use?](https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530)

<div class="topic-metadata">

**Author:** [@Masta\_Boombastic](https://discuss.elastic.co/u/Masta_Boombastic)\
**Replies:** 3\
**Last updated:** [October 5, 2019, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530 "2019-10-05T12:56:02Z")

</div>

I'm running elk and coredns in docker. I am having difficulty getting any log data from coredns docker container using the autodiscovery. The sample apache auto discovery works a treat for me, I get data in ES and nice…

---

## [Filebeat coredns module doesn't work with default coredns/docker logging](https://discuss.elastic.co/t/filebeat-coredns-module-doesnt-work-with-default-coredns-docker-logging/202392)

<div class="topic-metadata">

**Author:** [@MangledDeutz](https://discuss.elastic.co/u/MangledDeutz)\
**Replies:** 0\
**Last updated:** [October 4, 2019, 9:25pm UTC](https://discuss.elastic.co/t/filebeat-coredns-module-doesnt-work-with-default-coredns-docker-logging/202392 "2019-10-04T21:25:03Z")

</div>

See https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530 When using docker + hints, the filebeat coredns module silently fail sending any data. Turns out the ingester trie…

---

## [Keep elastic cloud credentials separately & securly](https://discuss.elastic.co/t/keep-elastic-cloud-credentials-separately-securly/202413)

<div class="topic-metadata">

**Author:** [@elikesha](https://discuss.elastic.co/u/elikesha)\
**Replies:** 1\
**Last updated:** [October 5, 2019, 4:54am UTC](https://discuss.elastic.co/t/keep-elastic-cloud-credentials-separately-securly/202413 "2019-10-05T04:54:19Z")

</div>

I am using metricbeat to monitor the K8s cluster. I was using the following config, https://raw.githubusercontent.com/elastic/beats/7.4/deploy/kubernetes/metricbeat-kubernetes.yaml Here elastic cloud creds are referred…

---

## ["child "meta\_fields" fails because \["meta\_fields" must be an array\]" after configuring Kafka logs and metrics](https://discuss.elastic.co/t/child-meta-fields-fails-because-meta-fields-must-be-an-array-after-configuring-kafka-logs-and-metrics/202395)

<div class="topic-metadata">

**Author:** [@mrubin](https://discuss.elastic.co/u/mrubin)\
**Replies:** 0\
**Last updated:** [October 4, 2019, 9:54pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails-because-meta-fields-must-be-an-array-after-configuring-kafka-logs-and-metrics/202395 "2019-10-04T21:54:29Z")

</div>

I am running ES/Kibana 7.4.0 on Elastic Cloud and wanted to try out the "Kafka logs" and "Kafka metrics". I followed the instructions to install filebeat-7.4.0 and metricbeat-7.4.0 on my Kafka nodes (running on AWS EC2 l…

---

## [Install Filebeat on rhel with ppc64le architecture](https://discuss.elastic.co/t/install-filebeat-on-rhel-with-ppc64le-architecture/202365)

<div class="topic-metadata">

**Author:** [@alesabat](https://discuss.elastic.co/u/alesabat)\
**Replies:** 1\
**Last updated:** [October 4, 2019, 5:03pm UTC](https://discuss.elastic.co/t/install-filebeat-on-rhel-with-ppc64le-architecture/202365 "2019-10-04T17:03:34Z")

</div>

Hi everyone, is it possibble to install Filebeat on a RHEL server running over ppc64el architecture? I couldn't find anything conclusive. I'll very appreciate any help. Regards!

---

## [Heartbeat - Setting a custom ILM policy](https://discuss.elastic.co/t/heartbeat-setting-a-custom-ilm-policy/202346)

<div class="topic-metadata">

**Author:** [@AlessandroKP](https://discuss.elastic.co/u/AlessandroKP)\
**Replies:** 0\
**Last updated:** [October 4, 2019, 1:13pm UTC](https://discuss.elastic.co/t/heartbeat-setting-a-custom-ilm-policy/202346 "2019-10-04T13:13:25Z")

</div>

Hi all, I'm having some problems trying to set the ILM policy of heartbeat indices. I'm running heartbeat with the following configuration (heartbeat.yml): heartbeat.config.monitors: path: ${path.config}/monitors.d/…

---

## [Filebeat parsing log containing structured JSON](https://discuss.elastic.co/t/filebeat-parsing-log-containing-structured-json/202238)

<div class="topic-metadata">

**Author:** [@bkleynbok](https://discuss.elastic.co/u/bkleynbok)\
**Replies:** 2\
**Last updated:** [October 4, 2019, 12:49pm UTC](https://discuss.elastic.co/t/filebeat-parsing-log-containing-structured-json/202238 "2019-10-04T12:49:37Z")

</div>

Running ELK Stack 7.3.2 on Linux I am trying to parse JSON via FIilebeat then output to Elasticsearch and show individual objects of the structured JSON in Kibana. Here is test.json \[ { "employee": { "firstName": "…

---

## [Number of file handles spikes up temporarily](https://discuss.elastic.co/t/number-of-file-handles-spikes-up-temporarily/202340)

<div class="topic-metadata">

**Author:** [@amitavmohanty01](https://discuss.elastic.co/u/amitavmohanty01)\
**Replies:** 0\
**Last updated:** [October 4, 2019, 12:34pm UTC](https://discuss.elastic.co/t/number-of-file-handles-spikes-up-temporarily/202340 "2019-10-04T12:34:56Z")

</div>

Looking at over a week of running Filebeat, I am finding sudden spikes in the number of file handles in Filebeat. The number of handles nearly doubles instantaneously. The number remains the same over some time and come…

---

## [Filebeat to ship bro logs - notice logs to kibana](https://discuss.elastic.co/t/filebeat-to-ship-bro-logs-notice-logs-to-kibana/201752)

<div class="topic-metadata">

**Author:** [@Ikenahim](https://discuss.elastic.co/u/Ikenahim)\
**Replies:** 2\
**Last updated:** [October 4, 2019, 12:34pm UTC](https://discuss.elastic.co/t/filebeat-to-ship-bro-logs-notice-logs-to-kibana/201752 "2019-10-04T12:34:33Z")

</div>

I set up Bro and ELK I managed to ship logs of Bro/Zeek to ELK server where ELK is configured to receive logs using Filebeat Zeek modul without going via Logstash. works perfectly. Now I want to ship notice log of Zeek…

---

## [Funtionbeat output.logstash](https://discuss.elastic.co/t/funtionbeat-output-logstash/201205)

<div class="topic-metadata">

**Author:** [@t3di](https://discuss.elastic.co/u/t3di)\
**Replies:** 1\
**Last updated:** [October 4, 2019, 11:38am UTC](https://discuss.elastic.co/t/funtionbeat-output-logstash/201205 "2019-10-04T11:38:09Z")

</div>

hi, I can see that the Logstash output has been added to Functionbeat as per https://github.com/elastic/beats/pull/13345 and merged to master branch, however when I install Functionbeat 7.3.2 the output isnt mentioned…

---

## [Winlogbeat XPACK Subscription](https://discuss.elastic.co/t/winlogbeat-xpack-subscription/201551)

<div class="topic-metadata">

**Author:** [@gromit](https://discuss.elastic.co/u/gromit)\
**Replies:** 1\
**Last updated:** [October 4, 2019, 11:34am UTC](https://discuss.elastic.co/t/winlogbeat-xpack-subscription/201551 "2019-10-04T11:34:25Z")

</div>

Hi, Would like some clarification on the XPACK Security modules packaged with Winlogbeat in the form of Modules. Which subscription do these come under, e.g Basic or Gold/Platinum?

---

## [Invalid Config](https://discuss.elastic.co/t/invalid-config/202112)

<div class="topic-metadata">

**Author:** [@Pierrelaurent](https://discuss.elastic.co/u/Pierrelaurent)\
**Replies:** 2\
**Last updated:** [October 4, 2019, 7:11am UTC](https://discuss.elastic.co/t/invalid-config/202112 "2019-10-04T07:11:18Z")

</div>

Can someone tell me what I am doing wrong? I am getting the following error

---

## [Loadbalnce setting in Filebeat output kafka?](https://discuss.elastic.co/t/loadbalnce-setting-in-filebeat-output-kafka/202281)

<div class="topic-metadata">

**Author:** [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Replies:** 0\
**Last updated:** [October 4, 2019, 5:31am UTC](https://discuss.elastic.co/t/loadbalnce-setting-in-filebeat-output-kafka/202281 "2019-10-04T05:31:04Z")

</div>

Hi, we have loab balance setting in filebeat output.logstash https://www.elastic.co/guide/en/beats/filebeat/master/load-balancing.html Why dont we have loadbalnace setting for output.kafka? https://www.elastic.co/gui…

---

## [Filebeat 7.4.0 Envoyproxy configuration issues](https://discuss.elastic.co/t/filebeat-7-4-0-envoyproxy-configuration-issues/202267)

<div class="topic-metadata">

**Author:** [@dnmahendra](https://discuss.elastic.co/u/dnmahendra)\
**Replies:** 0\
**Last updated:** [October 4, 2019, 2:28am UTC](https://discuss.elastic.co/t/filebeat-7-4-0-envoyproxy-configuration-issues/202267 "2019-10-04T02:28:52Z")

</div>

This is in continuation to the following issue I raised a while ago - https://discuss.elastic.co/t/filebeat-7-2-0-autodiscover-configuration-issues/188168 I migrated to elk stack 7.4.0 and trying to ship logs from the K…

---

## [Issues with Filebeat and Cisco ASA Parsing](https://discuss.elastic.co/t/issues-with-filebeat-and-cisco-asa-parsing/202254)

<div class="topic-metadata">

**Author:** [@mrvoids](https://discuss.elastic.co/u/mrvoids)\
**Replies:** 0\
**Last updated:** [October 3, 2019, 11:41pm UTC](https://discuss.elastic.co/t/issues-with-filebeat-and-cisco-asa-parsing/202254 "2019-10-03T23:41:19Z")

</div>

The module is working well but I am getting a couple of errors causing some messages not to parse. First is that an icmp code is to large for the short is stored in. The bigger issue is with message id 106023 I am receiv…

---

## [Metricbeat 7.4.0 and Kubernetes API - Issue](https://discuss.elastic.co/t/metricbeat-7-4-0-and-kubernetes-api-issue/202167)

<div class="topic-metadata">

**Author:** [@delphi](https://discuss.elastic.co/u/delphi)\
**Replies:** 3\
**Last updated:** [October 3, 2019, 7:22pm UTC](https://discuss.elastic.co/t/metricbeat-7-4-0-and-kubernetes-api-issue/202167 "2019-10-03T19:22:28Z")

</div>

Hi, there. Based on GitHub Beats Issue, I'm getting an problem related with k8s API, even using 1.13 clusters. After downgraded Metricbeat to 7.3.2, it was solved. My config is: metricbeat.config: modules: …

---

## [IIS module timestamp incorrect](https://discuss.elastic.co/t/iis-module-timestamp-incorrect/201388)

<div class="topic-metadata">

**Author:** [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Replies:** 6\
**Last updated:** [October 3, 2019, 5:19pm UTC](https://discuss.elastic.co/t/iis-module-timestamp-incorrect/201388 "2019-10-03T17:19:09Z")

</div>

I'm testing out Filebeat's IIS module. I noticed that it doesn't seem to use the time from the log as the timestamp. It's using the time it was sent to Logstash. According to the \\module\\iis\\access\\ingest\\default.js…

---

## [Metricbeat unable to load dashboards to kibana cloud due to Client.timeout](https://discuss.elastic.co/t/metricbeat-unable-to-load-dashboards-to-kibana-cloud-due-to-client-timeout/202209)

<div class="topic-metadata">

**Author:** [@eswo](https://discuss.elastic.co/u/eswo)\
**Replies:** 0\
**Last updated:** [October 3, 2019, 3:48pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-load-dashboards-to-kibana-cloud-due-to-client-timeout/202209 "2019-10-03T15:48:05Z")

</div>

Hello Guys, It is been a full day since i'm on this problem I searched everywhere but nothing helps. I'm trying to install metricbeat, and send some data about apache status. The installation goes well, i edited the …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=310)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=312)
