# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=313

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 314

---

## [The request for this panel failed all shards failed metrixbeat 7.3.1](https://discuss.elastic.co/t/the-request-for-this-panel-failed-all-shards-failed-metrixbeat-7-3-1/200269)

<div class="topic-metadata">

**Author:** [@mheinle](https://discuss.elastic.co/u/mheinle)\
**Replies:** 2\
**Last updated:** [September 30, 2019, 3:07pm UTC](https://discuss.elastic.co/t/the-request-for-this-panel-failed-all-shards-failed-metrixbeat-7-3-1/200269 "2019-09-30T15:07:09Z")

</div>

Hello, I am am hoping someone can point me in the right direction. I rebooted my ELK stack the other day and upon trying to start Logstash I received an error about all shards failed. I was able to delete my indices t…

---

## [Setup.template.name with space when using setup.ilm.enabled: auto](https://discuss.elastic.co/t/setup-template-name-with-space-when-using-setup-ilm-enabled-auto/201657)

<div class="topic-metadata">

**Author:** [@McQueen2063](https://discuss.elastic.co/u/McQueen2063)\
**Replies:** 0\
**Last updated:** [September 30, 2019, 2:22pm UTC](https://discuss.elastic.co/t/setup-template-name-with-space-when-using-setup-ilm-enabled-auto/201657 "2019-09-30T14:22:53Z")

</div>

Hello everyone, I wonder whether I tripped over a bug or whether I might misunderstand the documentation. I'm using filebeat 7.3.2 and want to use ilm, but also create indices based on my environments. config settings…

---

## [Filter winlogbeat](https://discuss.elastic.co/t/filter-winlogbeat/201647)

<div class="topic-metadata">

**Author:** [@DorianL](https://discuss.elastic.co/u/DorianL)\
**Replies:** 2\
**Last updated:** [September 30, 2019, 2:06pm UTC](https://discuss.elastic.co/t/filter-winlogbeat/201647 "2019-09-30T14:06:48Z")

</div>

Hello, As part of the implementation of a centralized logging system in my company I am configuring winlogbeat to visualize my logs of login and logoff. I send the data directly to the elasticsearch cloud. But I am po…

---

## [ELK workflow with Filebeat - could you explain in detail?](https://discuss.elastic.co/t/elk-workflow-with-filebeat-could-you-explain-in-detail/201538)

<div class="topic-metadata">

**Author:** [@Nguy\_n\_T\_t\_Dung](https://discuss.elastic.co/u/Nguy_n_T_t_Dung)\
**Replies:** 5\
**Last updated:** [September 30, 2019, 12:09pm UTC](https://discuss.elastic.co/t/elk-workflow-with-filebeat-could-you-explain-in-detail/201538 "2019-09-30T12:09:56Z")

</div>

Hi buddy, I'm very very confused and try to clear the flow of Elasticsearch - Logstash - Kibana . Now , this is my situation : I wanna monitoring my Kafka server by ELK and i found the way ; use ELK . And this is my t…

---

## [Help index packetbeat not appear in kibana](https://discuss.elastic.co/t/help-index-packetbeat-not-appear-in-kibana/201526)

<div class="topic-metadata">

**Author:** [@fajar\_3t3](https://discuss.elastic.co/u/fajar_3t3)\
**Replies:** 1\
**Last updated:** [September 30, 2019, 11:29am UTC](https://discuss.elastic.co/t/help-index-packetbeat-not-appear-in-kibana/201526 "2019-09-30T11:29:08Z")

</div>

hi all, i already install packet beat on my client server. and also kibana already installed but i didnt found index packet beat on my kibana. indent preformatted text by 4 spaces GET /packetbeat-\*/\_search?pretty { …

---

## [Creating a new custom index for haproxy metricbeat](https://discuss.elastic.co/t/creating-a-new-custom-index-for-haproxy-metricbeat/199246)

<div class="topic-metadata">

**Author:** [@L33T](https://discuss.elastic.co/u/L33T)\
**Replies:** 2\
**Last updated:** [September 30, 2019, 9:20am UTC](https://discuss.elastic.co/t/creating-a-new-custom-index-for-haproxy-metricbeat/199246 "2019-09-30T09:20:33Z")

</div>

Hi, I cannot seem to get a new custom index created in elastic when trying output from metricbeat using the haproxy module. I have a 3 node cluster in operation. I can see the kibana dashboards install into kibana and t…

---

## [How to run Metricbeat as a service on SUSE enterprise 11](https://discuss.elastic.co/t/how-to-run-metricbeat-as-a-service-on-suse-enterprise-11/201144)

<div class="topic-metadata">

**Author:** [@arun1](https://discuss.elastic.co/u/arun1)\
**Replies:** 7\
**Last updated:** [September 30, 2019, 7:13am UTC](https://discuss.elastic.co/t/how-to-run-metricbeat-as-a-service-on-suse-enterprise-11/201144 "2019-09-30T07:13:30Z")

</div>

Hi, I have installed Meticbeat on SUSE Linux Enterprise 11 using the .rpm package. I am also able to start metricbeat from the command line using the command 'sudo ./metricbeat -e'. However when I try to start it as a …

---

## [Custom Index Name for FileBeat](https://discuss.elastic.co/t/custom-index-name-for-filebeat/200073)

<div class="topic-metadata">

**Author:** [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Replies:** 2\
**Last updated:** [September 30, 2019, 3:52am UTC](https://discuss.elastic.co/t/custom-index-name-for-filebeat/200073 "2019-09-30T03:52:53Z")

</div>

Hello everyone, So i have ELK configured on a server and filebeat configured on a bunch of other servers which will be sending their log files to the ELK server. Now i need to be able to differentiate each servers' logs…

---

## [Error in index or visualisations for "\[Metricbeat System\] Overview ECS"](https://discuss.elastic.co/t/error-in-index-or-visualisations-for-metricbeat-system-overview-ecs/201490)

<div class="topic-metadata">

**Author:** [@bodo.te](https://discuss.elastic.co/u/bodo.te)\
**Replies:** 3\
**Last updated:** [September 28, 2019, 9:28pm UTC](https://discuss.elastic.co/t/error-in-index-or-visualisations-for-metricbeat-system-overview-ecs/201490 "2019-09-28T21:28:45Z")

</div>

After setting up ELK 7.3.1 according to ELK Tutorial : https://www.elastic.co/guide/en/elastic-stack-get-started/current/get-started-elastic-stack.html and looking in to this dashboard: "\[Metricbeat System\] Overview E…

---

## [Can filebeat monitoring send data to Kafka?](https://discuss.elastic.co/t/can-filebeat-monitoring-send-data-to-kafka/200006)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 7\
**Last updated:** [September 28, 2019, 3:43pm UTC](https://discuss.elastic.co/t/can-filebeat-monitoring-send-data-to-kafka/200006 "2019-09-28T15:43:06Z")

</div>

As per the monitoring options for Filebeat given here, the monitoring stats can be send to Elasticsearch. But I would like the data to be sent to Kafka. Is this possible?.

---

## [Filebeat replacement for Solaris 11](https://discuss.elastic.co/t/filebeat-replacement-for-solaris-11/201350)

<div class="topic-metadata">

**Author:** [@Ankit\_Jindal](https://discuss.elastic.co/u/Ankit_Jindal)\
**Replies:** 2\
**Last updated:** [September 28, 2019, 3:44am UTC](https://discuss.elastic.co/t/filebeat-replacement-for-solaris-11/201350 "2019-09-28T03:44:31Z")

</div>

We have a requirement for one of our customer where we need to read Oracle DB alert logs. Oracle DB is placed.on Solaris server. As far as we know filebeat does not have support for Solaris. Can you please provide the so…

---

## [Doc bug for system.cpu.user.pct (and other pct)?](https://discuss.elastic.co/t/doc-bug-for-system-cpu-user-pct-and-other-pct/201301)

<div class="topic-metadata">

**Author:** [@suryaj](https://discuss.elastic.co/u/suryaj)\
**Replies:** 5\
**Last updated:** [September 28, 2019, 12:28am UTC](https://discuss.elastic.co/t/doc-bug-for-system-cpu-user-pct-and-other-pct/201301 "2019-09-28T00:28:18Z")

</div>

I got thrown off by the documentation here for system.cpu.user.pct. The percentage of CPU time spent in user space. On multi-core systems, you can have percentages that are greater than 100%. For example, if 3 cores a…

---

## [Config filebeat only to read last 5 minutes of log file](https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669)

<div class="topic-metadata">

**Author:** [@Ingram\_Gultom](https://discuss.elastic.co/u/Ingram_Gultom)\
**Replies:** 3\
**Last updated:** [September 27, 2019, 4:39pm UTC](https://discuss.elastic.co/t/config-filebeat-only-to-read-last-5-minutes-of-log-file/200669 "2019-09-27T16:39:43Z")

</div>

Can filebeat read only last 5 minutes of log file? From the doc only found tail\_files but its for read latest line of log

---

## [How to audit mysql's log using auditbeat and display the log content on the elastic search page](https://discuss.elastic.co/t/how-to-audit-mysqls-log-using-auditbeat-and-display-the-log-content-on-the-elastic-search-page/201126)

<div class="topic-metadata">

**Author:** [@goodboy](https://discuss.elastic.co/u/goodboy)\
**Replies:** 3\
**Last updated:** [September 27, 2019, 2:45pm UTC](https://discuss.elastic.co/t/how-to-audit-mysqls-log-using-auditbeat-and-display-the-log-content-on-the-elastic-search-page/201126 "2019-09-27T14:45:49Z")

</div>

Now I'm thinking of replacing filebeat with auditbeat, but I don't know how to use auditbeat to audit mysql's log and display it on the elastic search page. I hope to get help. Thank you.

---

## [What privileges mongodb user should have for fetching the mongodb status through metricbeat mongodb module](https://discuss.elastic.co/t/what-privileges-mongodb-user-should-have-for-fetching-the-mongodb-status-through-metricbeat-mongodb-module/201197)

<div class="topic-metadata">

**Author:** [@GRV](https://discuss.elastic.co/u/GRV)\
**Replies:** 1\
**Last updated:** [September 27, 2019, 1:44pm UTC](https://discuss.elastic.co/t/what-privileges-mongodb-user-should-have-for-fetching-the-mongodb-status-through-metricbeat-mongodb-module/201197 "2019-09-27T13:44:41Z")

</div>

In mongodb.yml file inside metricbeat modules, i am using user which is assign readWrite permission for admin db. I am getting these errors Error 1 : Error fetching data for metricset mongodb.dbstats: Error retrievin…

---

## [Metricbeats vsphere](https://discuss.elastic.co/t/metricbeats-vsphere/200891)

<div class="topic-metadata">

**Author:** [@jlim0930](https://discuss.elastic.co/u/jlim0930)\
**Replies:** 2\
**Last updated:** [September 27, 2019, 1:36pm UTC](https://discuss.elastic.co/t/metricbeats-vsphere/200891 "2019-09-27T13:36:26Z")

</div>

can we list multiple vsphere hosts in the hosts field? currently I have hosts: \[ "https://host1/sdk", "https://host2/sdk"\] but it is only collecting information from host1 and nothing from host2 if we are wanting to co…

---

## [Failed to encode event: unsupported float value](https://discuss.elastic.co/t/failed-to-encode-event-unsupported-float-value/199270)

<div class="topic-metadata">

**Author:** [@drew.flint](https://discuss.elastic.co/u/drew.flint)\
**Replies:** 8\
**Last updated:** [September 27, 2019, 1:32pm UTC](https://discuss.elastic.co/t/failed-to-encode-event-unsupported-float-value/199270 "2019-09-27T13:32:13Z")

</div>

I'm doing a POC to use a metricbeat pod to scrape all metrics from a prometheus pod in the same namespace of a kubernetes cluster. The metricbeat pod is able to connect to the prometheus pod's /federate end point and gat…

---

## [Filebeat multiline regular expression](https://discuss.elastic.co/t/filebeat-multiline-regular-expression/201371)

<div class="topic-metadata">

**Author:** [@Mahipavan](https://discuss.elastic.co/u/Mahipavan)\
**Replies:** 0\
**Last updated:** [September 27, 2019, 9:38am UTC](https://discuss.elastic.co/t/filebeat-multiline-regular-expression/201371 "2019-09-27T09:38:36Z")

</div>

Hi, I am trying to implement filebeat multiline pattern on our custom application logs which contains entries of different formats as shown below. \[2019-09-27T10:35:44.257+02:00\] \[osb\_server1\] \[NOTIFICATION\] \[oracle.o…

---

## [Grok filter for email address alteration](https://discuss.elastic.co/t/grok-filter-for-email-address-alteration/201270)

<div class="topic-metadata">

**Author:** [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Replies:** 2\
**Last updated:** [September 27, 2019, 9:19am UTC](https://discuss.elastic.co/t/grok-filter-for-email-address-alteration/201270 "2019-09-27T09:19:02Z")

</div>

Hi, Am trying to pre-filter some data in Filebeat, i have a issue i cannot resolve from picking up some weird logs. I'm trying to pickup an email address from the file as well as an ip and date time etc... whilst it al…

---

## [Beats Monitoring through Logstash](https://discuss.elastic.co/t/beats-monitoring-through-logstash/201362)

<div class="topic-metadata">

**Author:** [@rog\_NB](https://discuss.elastic.co/u/rog_NB)\
**Replies:** 0\
**Last updated:** [September 27, 2019, 8:37am UTC](https://discuss.elastic.co/t/beats-monitoring-through-logstash/201362 "2019-09-27T08:37:27Z")

</div>

Hello We have a setup of few Logstashes behind a load balancer. Hosts are only allowed to talk to the load balancer for any elasticsearch data. I would like to know how to setup any beats.yml, that all beats are able …

---

## [\[metricbeat\] kafka metric show in discovery but not show in dashboard (detail in description )](https://discuss.elastic.co/t/metricbeat-kafka-metric-show-in-discovery-but-not-show-in-dashboard-detail-in-description/201226)

<div class="topic-metadata">

**Author:** [@Nguy\_n\_T\_t\_Dung](https://discuss.elastic.co/u/Nguy_n_T_t_Dung)\
**Replies:** 4\
**Last updated:** [September 27, 2019, 2:37am UTC](https://discuss.elastic.co/t/metricbeat-kafka-metric-show-in-discovery-but-not-show-in-dashboard-detail-in-description/201226 "2019-09-27T02:37:49Z")

</div>

HI there, i'm stucking in detect problem. Here is my situation : in client vm: metricbeat modules enable kafka output to Elasticsearch . Kibana : create index with : metricbeat-\* successfully with full log and kafka …

---

## [Name in place of IP](https://discuss.elastic.co/t/name-in-place-of-ip/200937)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 5\
**Last updated:** [September 26, 2019, 8:28pm UTC](https://discuss.elastic.co/t/name-in-place-of-ip/200937 "2019-09-26T20:28:36Z")

</div>

is there a way I can convert all IP that are getting register in to elasticsearch as name? I am just using regular packetbeat configuration and outputting straight to elasticsearch output.elasticsearch: # Array of ho…

---

## [Kubernetes + Auto-discovery + dedot](https://discuss.elastic.co/t/kubernetes-auto-discovery-dedot/201304)

<div class="topic-metadata">

**Author:** [@larslevie](https://discuss.elastic.co/u/larslevie)\
**Replies:** 0\
**Last updated:** [September 26, 2019, 7:18pm UTC](https://discuss.elastic.co/t/kubernetes-auto-discovery-dedot/201304 "2019-09-26T19:18:36Z")

</div>

With Filebeat 6.8.0, where exactly do the labels.dedot and annotations.dedot options go in the Filebeat config when using autodiscovery? Lack of dedotting is responsible for errors like: failed to parse field \[kubernet…

---

## [Filebeat on windows server not connecting with SSL](https://discuss.elastic.co/t/filebeat-on-windows-server-not-connecting-with-ssl/201284)

<div class="topic-metadata">

**Author:** [@hursto75](https://discuss.elastic.co/u/hursto75)\
**Replies:** 2\
**Last updated:** [September 26, 2019, 6:33pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-server-not-connecting-with-ssl/201284 "2019-09-26T18:33:31Z")

</div>

I have the keys specified. In the filebeats yml and it starts and runs but I get :slight\_smile: 2019/09/26 14:58:46.919313 async.go:235: ERR Failed to publish events caused by: lumberjack protocol error 2019/09/26 14:5…

---

## [Multiple Filebeat output](https://discuss.elastic.co/t/multiple-filebeat-output/201273)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 1\
**Last updated:** [September 26, 2019, 6:18pm UTC](https://discuss.elastic.co/t/multiple-filebeat-output/201273 "2019-09-26T18:18:15Z")

</div>

Hi All, is there a way to send logs from filebeat to 2 different outputs. Currently, we have Kafka in our ELK cluster. for logs like syslog, auditlog on the server, we want to push it to Kafka and application logs we w…

---

## [Filebeat Zeek Convert IP Address from "string" to "ip"](https://discuss.elastic.co/t/filebeat-zeek-convert-ip-address-from-string-to-ip/200902)

<div class="topic-metadata">

**Author:** [@0x00](https://discuss.elastic.co/u/0x00)\
**Replies:** 3\
**Last updated:** [September 26, 2019, 5:44pm UTC](https://discuss.elastic.co/t/filebeat-zeek-convert-ip-address-from-string-to-ip/200902 "2019-09-26T17:44:00Z")

</div>

The rename function in /usr/share/filebeat/module/zeek/connection/config/connection.yml processors: - drop\_fields: fields: \["json.orig\_bytes","json.resp\_bytes","json.tunnel\_parents"\] - rename: fields: …

---

## [Postgres module for filebeat is not matching the logs](https://discuss.elastic.co/t/postgres-module-for-filebeat-is-not-matching-the-logs/200680)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 4\
**Last updated:** [September 26, 2019, 2:29pm UTC](https://discuss.elastic.co/t/postgres-module-for-filebeat-is-not-matching-the-logs/200680 "2019-09-26T14:29:23Z")

</div>

Hello, I have set up filebeat postgres module to get the logs and send it to the dashboard but I have observed that the patterns are not matching the logs coming from postgresq. Therefore I am wondering what versions of…

---

## [Running beats on Kubernetes](https://discuss.elastic.co/t/running-beats-on-kubernetes/201251)

<div class="topic-metadata">

**Author:** [@earl\_potter](https://discuss.elastic.co/u/earl_potter)\
**Replies:** 0\
**Last updated:** [September 26, 2019, 2:11pm UTC](https://discuss.elastic.co/t/running-beats-on-kubernetes/201251 "2019-09-26T14:11:49Z")

</div>

I was running Minikube 1.4 on my Mac w/ Kubectl 1.16 and couldn't get the default manifest to run from https://raw.githubusercontent.com/elastic/beats/7.3/deploy/kubernetes/filebeat-kubernetes.yaml using these docs. htt…

---

## [Cannot rename sub-fields of cloud metadata added via add\_cloud\_metadata](https://discuss.elastic.co/t/cannot-rename-sub-fields-of-cloud-metadata-added-via-add-cloud-metadata/201157)

<div class="topic-metadata">

**Author:** [@jalaziz](https://discuss.elastic.co/u/jalaziz)\
**Replies:** 1\
**Last updated:** [September 26, 2019, 7:47am UTC](https://discuss.elastic.co/t/cannot-rename-sub-fields-of-cloud-metadata-added-via-add-cloud-metadata/201157 "2019-09-26T07:47:34Z")

</div>

I'm unable to rename sub-fields of the cloud field added via add\_cloud\_metadata. In particular, this configuration results in missing fields for serverId.id, serverId.datacenter.zone, etc: - add\_cloud\_metadata: ~ -…

---

## [Output to file](https://discuss.elastic.co/t/output-to-file/199720)

<div class="topic-metadata">

**Author:** [@DrProfSagi](https://discuss.elastic.co/u/DrProfSagi)\
**Replies:** 1\
**Last updated:** [September 26, 2019, 7:36am UTC](https://discuss.elastic.co/t/output-to-file/199720 "2019-09-26T07:36:32Z")

</div>

I am working on monitoring and debugging a closed up secured system, that can only output files to my main network (also not connected to the internet...). I have decided to output the metricbeat logs into a file with t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=312)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=314)
