# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=312

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 313

---

## [Filebeat + cloud.id defaulting to port 443 rather than 9243](https://discuss.elastic.co/t/filebeat-cloud-id-defaulting-to-port-443-rather-than-9243/202194)

<div class="topic-metadata">

**Author:** [@CloudIO](https://discuss.elastic.co/u/CloudIO)\
**Replies:** 0\
**Last updated:** [October 3, 2019, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-cloud-id-defaulting-to-port-443-rather-than-9243/202194 "2019-10-03T14:40:39Z")

</div>

I'm trying to setup ELK and running into problem. As an aside, I'm finding the documentation and steps very, very confusing - they tend to switch between setting filebeat \> logstash, filebeat \> elasticsearch and also di…

---

## [Filebeat Parsing error](https://discuss.elastic.co/t/filebeat-parsing-error/198860)

<div class="topic-metadata">

**Author:** [@bernaldo.penas](https://discuss.elastic.co/u/bernaldo.penas)\
**Replies:** 1\
**Last updated:** [October 3, 2019, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-parsing-error/198860 "2019-10-03T13:50:04Z")

</div>

Hi: I'm getting this error with filebeats and maybe someone can help me to try to figure out what's going on in my test lab: WARN elasticsearch/client.go:535 Cannot index event publisher.Event{Content:bea…

---

## [Mass deployment](https://discuss.elastic.co/t/mass-deployment/201668)

<div class="topic-metadata">

**Author:** [@Yatesss](https://discuss.elastic.co/u/Yatesss)\
**Replies:** 4\
**Last updated:** [October 3, 2019, 1:05pm UTC](https://discuss.elastic.co/t/mass-deployment/201668 "2019-10-03T13:05:31Z")

</div>

Hi all, Has anyone managed to automate the deployment of packetbeat to Windows 10 machines? I can't figure out how to define the monitoring interfaces in packetbeat.yml on mass while keeping it relatively simple. Thank…

---

## ["Failed to publish events...i/o timeout" (but telnet is OK)](https://discuss.elastic.co/t/failed-to-publish-events-i-o-timeout-but-telnet-is-ok/201802)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 1\
**Last updated:** [October 3, 2019, 9:32am UTC](https://discuss.elastic.co/t/failed-to-publish-events-i-o-timeout-but-telnet-is-ok/201802 "2019-10-03T09:32:29Z")

</div>

Hello, I try to push some log files from filebeat to logstash. Everything is working from the server A (filebeat) to Logstash Then I tried to push same logs from server B (filebeat) to Logstash and I have these errors…

---

## [What is the best practice to convert my custom logs to ECS(Or not)](https://discuss.elastic.co/t/what-is-the-best-practice-to-convert-my-custom-logs-to-ecs-or-not/200576)

<div class="topic-metadata">

**Author:** [@Aviad\_Hadida](https://discuss.elastic.co/u/Aviad_Hadida)\
**Replies:** 2\
**Last updated:** [October 3, 2019, 8:16am UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-convert-my-custom-logs-to-ecs-or-not/200576 "2019-10-03T08:16:05Z")

</div>

Hi. I am newbie on the ELK and i have done simple intergation with the cloud product(Very easy to use) The problem started when i try to ship the logs with the new ECS(Elastic common schema) and i was lost.. I have cu…

---

## [Possible to use filebeat\>logstash\>Eleastic in this manner](https://discuss.elastic.co/t/possible-to-use-filebeat-logstash-eleastic-in-this-manner/202008)

<div class="topic-metadata">

**Author:** [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Replies:** 2\
**Last updated:** [October 3, 2019, 7:46am UTC](https://discuss.elastic.co/t/possible-to-use-filebeat-logstash-eleastic-in-this-manner/202008 "2019-10-03T07:46:35Z")

</div>

is it possible to use filebeat\>logstash\>eleasticsearch in this way. Logstash is running three ports, 5045, 5046, 5047. I have a filebeats config that is picking up logs from 3 different locations and redirecting each l…

---

## [ILM is not being disabled in Metricbeat 7.2.1 and 7.3.1](https://discuss.elastic.co/t/ilm-is-not-being-disabled-in-metricbeat-7-2-1-and-7-3-1/202034)

<div class="topic-metadata">

**Author:** [@George\_Wainwright](https://discuss.elastic.co/u/George_Wainwright)\
**Replies:** 6\
**Last updated:** [October 3, 2019, 6:41am UTC](https://discuss.elastic.co/t/ilm-is-not-being-disabled-in-metricbeat-7-2-1-and-7-3-1/202034 "2019-10-03T06:41:58Z")

</div>

I am trying to disable ILM in metricbeat 7.2.1 and 7.3.1 in output elasticsearch section but it doesn't work. metricbeat.config.modules: path: ${path.config}/modules.d/\*.yml output: elasticsearch: hosts:…

---

## [Auditbeat custom index name not working](https://discuss.elastic.co/t/auditbeat-custom-index-name-not-working/201483)

<div class="topic-metadata">

**Author:** [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Replies:** 1\
**Last updated:** [October 3, 2019, 5:35am UTC](https://discuss.elastic.co/t/auditbeat-custom-index-name-not-working/201483 "2019-10-03T05:35:06Z")

</div>

Hi All, I am planning to add my own custom index name (auditlogs instead of default auditbeat) of index for auditbeat but somehow its not working. Below are the configs that I have related to ES & Kibana, am I doing som…

---

## [Beats processors: else if?](https://discuss.elastic.co/t/beats-processors-else-if/197608)

<div class="topic-metadata">

**Author:** [@danielmotaleite](https://discuss.elastic.co/u/danielmotaleite)\
**Replies:** 2\
**Last updated:** [September 7, 2019, 12:39am UTC](https://discuss.elastic.co/t/beats-processors-else-if/197608 "2019-09-07T00:39:39Z")

</div>

In https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html we can see that processors have "if then else", but no word if it supports the "if then else if then else" I need to do multiple checks …

---

## [If i use apache module do i need to ship the logs separately?](https://discuss.elastic.co/t/if-i-use-apache-module-do-i-need-to-ship-the-logs-separately/198088)

<div class="topic-metadata">

**Author:** [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Replies:** 1\
**Last updated:** [October 2, 2019, 1:59pm UTC](https://discuss.elastic.co/t/if-i-use-apache-module-do-i-need-to-ship-the-logs-separately/198088 "2019-10-02T13:59:11Z")

</div>

I am shipping the logs from apache to elastic search through logstash as I need to ship to different elastic search cluster. My question is if i use the apache module in the filebeat modules, do i need to ship the logs s…

---

## [Two filebeats with almost same data to send to Elastic](https://discuss.elastic.co/t/two-filebeats-with-almost-same-data-to-send-to-elastic/201079)

<div class="topic-metadata">

**Author:** [@rverchere](https://discuss.elastic.co/u/rverchere)\
**Replies:** 2\
**Last updated:** [October 2, 2019, 1:57pm UTC](https://discuss.elastic.co/t/two-filebeats-with-almost-same-data-to-send-to-elastic/201079 "2019-10-02T13:57:08Z")

</div>

Hello, I have a setup with 2 syslog servers that get all logs from devices. Devices send to these 2 servers in parallel, but there is no sync between them. So the syslog servers have "almost" the same data, but I witho…

---

## [Where I install filebeat, if I want Cisco ASA log](https://discuss.elastic.co/t/where-i-install-filebeat-if-i-want-cisco-asa-log/201942)

<div class="topic-metadata">

**Author:** [@lokmanopt](https://discuss.elastic.co/u/lokmanopt)\
**Replies:** 1\
**Last updated:** [October 2, 2019, 12:40pm UTC](https://discuss.elastic.co/t/where-i-install-filebeat-if-i-want-cisco-asa-log/201942 "2019-10-02T12:40:09Z")

</div>

Dear Experts, I can't understand where I can install filebeat if I want to Cisco ASA log or Cisco router log. Please need help filebeat experts. Regards Lokman Hakim

---

## [Packetbeat does accurately measure tls/https traffic on local machine but not server](https://discuss.elastic.co/t/packetbeat-does-accurately-measure-tls-https-traffic-on-local-machine-but-not-server/201945)

<div class="topic-metadata">

**Author:** [@Umar\_Hayat](https://discuss.elastic.co/u/Umar_Hayat)\
**Replies:** 0\
**Last updated:** [October 2, 2019, 11:53am UTC](https://discuss.elastic.co/t/packetbeat-does-accurately-measure-tls-https-traffic-on-local-machine-but-not-server/201945 "2019-10-02T11:53:15Z")

</div>

I am trying to capture TLS and https traffic using Packetbeat. The problem I am currently facing is when I try Packetbeat with elasticsearch on the local machine it reports the exact amount of traffic data while on a ser…

---

## [Auditbeat failed loading rules](https://discuss.elastic.co/t/auditbeat-failed-loading-rules/201786)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [October 2, 2019, 8:20am UTC](https://discuss.elastic.co/t/auditbeat-failed-loading-rules/201786 "2019-10-02T08:20:25Z")

</div>

Hello, When I try to load the following rules I got from https://github.com/bfuzzy1/auditd-attack -a always,exit -F arch=b32 -S touch -k T1099\_Timestomp -a always,exit -F arch=b64 -S touch -k T1099\_Timestomp I get err…

---

## [Elastic ML Node violating seccomp dac-decision](https://discuss.elastic.co/t/elastic-ml-node-violating-seccomp-dac-decision/201905)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [October 2, 2019, 8:19am UTC](https://discuss.elastic.co/t/elastic-ml-node-violating-seccomp-dac-decision/201905 "2019-10-02T08:19:27Z")

</div>

Hello, Not sure what to think of the following auditbeat events originating from our ml node: { "\_index": "auditbeat-7.3.2-2019.10.02", "\_type": "\_doc", "\_id": "7H-Di20Bk8gLhUqu1B6e", "\_version": 1, "\_score":…

---

## [How long to TCP's hosts max length?](https://discuss.elastic.co/t/how-long-to-tcps-hosts-max-length/201881)

<div class="topic-metadata">

**Author:** [@111219](https://discuss.elastic.co/u/111219)\
**Replies:** 1\
**Last updated:** [October 2, 2019, 2:49am UTC](https://discuss.elastic.co/t/how-long-to-tcps-hosts-max-length/201881 "2019-10-02T02:49:08Z")

</div>

What is the maximum length of hosts with an attribute of type tcp?

---

## [Filebeat Kubernetes metadata - Add namespace labels to kubernetes metadata](https://discuss.elastic.co/t/filebeat-kubernetes-metadata-add-namespace-labels-to-kubernetes-metadata/201715)

<div class="topic-metadata">

**Author:** [@jeffspahr](https://discuss.elastic.co/u/jeffspahr)\
**Replies:** 2\
**Last updated:** [October 2, 2019, 2:20am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-metadata-add-namespace-labels-to-kubernetes-metadata/201715 "2019-10-02T02:20:20Z")

</div>

As operators of a multi tenant Kubernetes cluster and operators of the Elastic Stack we want to be able to drop logs by namespace when log rates exceed a certain number. We'd like to control this by adding labels to a n…

---

## [Is AuditBeat dependent on Auditd daemon?](https://discuss.elastic.co/t/is-auditbeat-dependent-on-auditd-daemon/201503)

<div class="topic-metadata">

**Author:** [@Suat\_Bey](https://discuss.elastic.co/u/Suat_Bey)\
**Replies:** 1\
**Last updated:** [October 1, 2019, 8:33pm UTC](https://discuss.elastic.co/t/is-auditbeat-dependent-on-auditd-daemon/201503 "2019-10-01T20:33:45Z")

</div>

Do we need to install and start auditd in order to user AuditBeat? Or just installation AuditBeat will do the auditing , logging without auditd daemon? On last question is there any functşon that auditd can do but, Audit…

---

## [Filebeat Index Pattern Creation](https://discuss.elastic.co/t/filebeat-index-pattern-creation/200309)

<div class="topic-metadata">

**Author:** [@Eric\_Orcutt](https://discuss.elastic.co/u/Eric_Orcutt)\
**Replies:** 4\
**Last updated:** [October 1, 2019, 8:20pm UTC](https://discuss.elastic.co/t/filebeat-index-pattern-creation/200309 "2019-10-01T20:20:02Z")

</div>

I'm attempting to create a custom index using ILM policy through Filebeat and everything appears to be fine except that the Index Pattern created in Kibana by Filebeat is not using the custom pattern that I'm providing i…

---

## [Is there a Beat that can read from a Kafka Topic (e.g. one that contains status from the Microservices)?](https://discuss.elastic.co/t/is-there-a-beat-that-can-read-from-a-kafka-topic-e-g-one-that-contains-status-from-the-microservices/200239)

<div class="topic-metadata">

**Author:** [@bkleynbok](https://discuss.elastic.co/u/bkleynbok)\
**Replies:** 7\
**Last updated:** [October 1, 2019, 7:16pm UTC](https://discuss.elastic.co/t/is-there-a-beat-that-can-read-from-a-kafka-topic-e-g-one-that-contains-status-from-the-microservices/200239 "2019-10-01T19:16:12Z")

</div>

The topology of our project is 3 Kafka nodes and 2 Cassandra nodes. Right now I have configured the ELK Stack to output to Elastic Search. For now we not going to use Logstash. I have able to configure a heartbeat to …

---

## [ERROR runtime/panic.go:44 ParseMemcache(UDP) exception. Recovering, but please report this](https://discuss.elastic.co/t/error-runtime-panic-go-44-parsememcache-udp-exception-recovering-but-please-report-this/198978)

<div class="topic-metadata">

**Author:** [@sstover](https://discuss.elastic.co/u/sstover)\
**Replies:** 4\
**Last updated:** [October 1, 2019, 2:59pm UTC](https://discuss.elastic.co/t/error-runtime-panic-go-44-parsememcache-udp-exception-recovering-but-please-report-this/198978 "2019-10-01T14:59:24Z")

</div>

Version 7.2.0 Packetbeat on an Ubuntu 14.0.4 host monitoring traffic on a dedicated SPAN port. Crashed on this error: 2019-08-29T18:37:54.446Z ERROR runtime/panic.go:44 ParseMemcache(UDP) exception. Recovering, b…

---

## [How to Parse url.query into Different Fields?](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920)

<div class="topic-metadata">

**Author:** [@antonio84](https://discuss.elastic.co/u/antonio84)\
**Replies:** 3\
**Last updated:** [October 1, 2019, 2:36pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920 "2019-10-01T14:36:16Z")

</div>

ELK 7.3 and Filebeat 7.3 I'm using the IIS module currently, and everything is parsing great. I would like to further parse the url.query section of this line, indicated in bold: 2019-09-24 17:14:04 10.202.225.10 GET …

---

## [/usr/share/metricbeat/bin/metricbeat exceeds max file size](https://discuss.elastic.co/t/usr-share-metricbeat-bin-metricbeat-exceeds-max-file-size/201783)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [October 1, 2019, 1:33pm UTC](https://discuss.elastic.co/t/usr-share-metricbeat-bin-metricbeat-exceeds-max-file-size/201783 "2019-10-01T13:33:15Z")

</div>

Hello I'm seeing the following warning when starting auditbeat: Oct 01 13:10:26 myserver auditbeat\[22218\]: 2019-10-01T13:10:26.828+0200 WARN \[process\] process/process.go:234 failed to hash executable /usr/share/metricb…

---

## [Filebeat no collecting apache logs from containers in swarm](https://discuss.elastic.co/t/filebeat-no-collecting-apache-logs-from-containers-in-swarm/201460)

<div class="topic-metadata">

**Author:** [@ndg](https://discuss.elastic.co/u/ndg)\
**Replies:** 1\
**Last updated:** [October 1, 2019, 1:01pm UTC](https://discuss.elastic.co/t/filebeat-no-collecting-apache-logs-from-containers-in-swarm/201460 "2019-10-01T13:01:59Z")

</div>

Hi everyone! After a lot of work i managed to create the ELK in my system with everything (Kibana, Elasticsearch, Logstash, Metricbeat) and i am moving to the next step which is monitoring the apache logs from a Apache/P…

---

## [How set reload config file by custom user's owner](https://discuss.elastic.co/t/how-set-reload-config-file-by-custom-users-owner/201731)

<div class="topic-metadata">

**Author:** [@111219](https://discuss.elastic.co/u/111219)\
**Replies:** 1\
**Last updated:** [October 1, 2019, 12:03pm UTC](https://discuss.elastic.co/t/how-set-reload-config-file-by-custom-users-owner/201731 "2019-10-01T12:03:41Z")

</div>

Error loading config from file '/tmp/jmuser/healthService/monitor/Test-Jmsight-id\_Test-Health-Name.yml', error invalid config: config file ("/tmp/jmuser/healthService/monitor/Test-Jmsight-id\_Test-Health-Name.yml") must b…

---

## [How do you remove (or not send) metadata from filebeat to logstash?](https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090)

<div class="topic-metadata">

**Author:** [@meatwad](https://discuss.elastic.co/u/meatwad)\
**Replies:** 3\
**Last updated:** [September 30, 2019, 8:19pm UTC](https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090 "2019-09-30T20:19:30Z")

</div>

Hi there. I am testing out filebeat on my Mac and it's successfully sending logs to logstash. Is there a way to only send the raw log message and not include any of the metadata? For example, here's what I get once it…

---

## [Syslog harvester does not start. Running Filebeat 7.3.1 on Docker](https://discuss.elastic.co/t/syslog-harvester-does-not-start-running-filebeat-7-3-1-on-docker/201398)

<div class="topic-metadata">

**Author:** [@glauber.ferreira](https://discuss.elastic.co/u/glauber.ferreira)\
**Replies:** 2\
**Last updated:** [September 30, 2019, 7:58pm UTC](https://discuss.elastic.co/t/syslog-harvester-does-not-start-running-filebeat-7-3-1-on-docker/201398 "2019-09-30T19:58:38Z")

</div>

I am running Elastic Stack 7.3.1 on Docker (Elastic, Kibana, Metricbeat, Filebeat). Filebeat harvesting are being started successfully for Docker container files. But, harvesting for Syslog module are not being started. …

---

## [Filebeat not sending fileset meta data to logstash](https://discuss.elastic.co/t/filebeat-not-sending-fileset-meta-data-to-logstash/201466)

<div class="topic-metadata">

**Author:** [@562uned](https://discuss.elastic.co/u/562uned)\
**Replies:** 2\
**Last updated:** [September 30, 2019, 4:34pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-fileset-meta-data-to-logstash/201466 "2019-09-30T16:34:44Z")

</div>

Hey guys, New to ELK and trying to get this working. I have successfully installed 6.8.3, and it worked i was getting the correct fields from filebeat including the fileset.module information. but i ended up upgrading t…

---

## [Winlogbeat v7 to NiFi partial messages](https://discuss.elastic.co/t/winlogbeat-v7-to-nifi-partial-messages/201436)

<div class="topic-metadata">

**Author:** [@Pavel201909](https://discuss.elastic.co/u/Pavel201909)\
**Replies:** 2\
**Last updated:** [September 30, 2019, 4:07pm UTC](https://discuss.elastic.co/t/winlogbeat-v7-to-nifi-partial-messages/201436 "2019-09-30T16:07:10Z")

</div>

Hi All, I ship windows events using ListenBeats in NiFi, however some messages arrive truncated. So far I can't identify a pattern why this happens. what I get on NiFi is this mess: I can see some non-printable char…

---

## [Delivered dashboards](https://discuss.elastic.co/t/delivered-dashboards/201675)

<div class="topic-metadata">

**Author:** [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Replies:** 0\
**Last updated:** [September 30, 2019, 4:03pm UTC](https://discuss.elastic.co/t/delivered-dashboards/201675 "2019-09-30T16:03:30Z")

</div>

Hi there, I have a question about defauilt dashboards delivered by filebeat agent to ELK. Few month ago, I tryed ELK 6.x on CentOs 6. It tryed to use dashboards delivered by agent, but still I had to find logstash con…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=311)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=313)
