# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=314

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 315

---

## [Beats reference.yml is missing documentation for json.ignore\_decoding\_error](https://discuss.elastic.co/t/beats-reference-yml-is-missing-documentation-for-json-ignore-decoding-error/200892)

<div class="topic-metadata">

**Author:** [@m13u](https://discuss.elastic.co/u/m13u)\
**Replies:** 1\
**Last updated:** [September 26, 2019, 1:52am UTC](https://discuss.elastic.co/t/beats-reference-yml-is-missing-documentation-for-json-ignore-decoding-error/200892 "2019-09-26T01:52:38Z")

</div>

PR 6547 added a new option json.ignore\_decoding\_error but documentation for this option is missing in the Beats reference.yml.

---

## [Filebeat for Fail2Ban via Logstash?](https://discuss.elastic.co/t/filebeat-for-fail2ban-via-logstash/201115)

<div class="topic-metadata">

**Author:** [@Dan\_Kennedy](https://discuss.elastic.co/u/Dan_Kennedy)\
**Replies:** 0\
**Last updated:** [September 25, 2019, 11:07pm UTC](https://discuss.elastic.co/t/filebeat-for-fail2ban-via-logstash/201115 "2019-09-25T23:07:28Z")

</div>

Hi All, need a bit of advice. I'm using Elasticsearch to collect and categorise logs from network devices. These are being sent to Logstash before being forwarded to Elasticsearch. I want to forward some Linux server F…

---

## [Metricbeat 7.2 : Kubernetes module - Gathers only host metrics but not that of node,container etc](https://discuss.elastic.co/t/metricbeat-7-2-kubernetes-module-gathers-only-host-metrics-but-not-that-of-node-container-etc/200266)

<div class="topic-metadata">

**Author:** [@sam101](https://discuss.elastic.co/u/sam101)\
**Replies:** 1\
**Last updated:** [September 25, 2019, 10:26pm UTC](https://discuss.elastic.co/t/metricbeat-7-2-kubernetes-module-gathers-only-host-metrics-but-not-that-of-node-container-etc/200266 "2019-09-25T22:26:21Z")

</div>

As a brief overview on installation, Deployed metricbeat as a daemonset and it gathers the metrics every 30secs and has the Metricbeat for Kubernetes with Kubernetes module enabled. But metricbeat seems to be gatherin…

---

## [Filebeat v7.3.2 - Failed to publish events caused by: EOF](https://discuss.elastic.co/t/filebeat-v7-3-2-failed-to-publish-events-caused-by-eof/200335)

<div class="topic-metadata">

**Author:** [@profiler](https://discuss.elastic.co/u/profiler)\
**Replies:** 5\
**Last updated:** [September 25, 2019, 8:24pm UTC](https://discuss.elastic.co/t/filebeat-v7-3-2-failed-to-publish-events-caused-by-eof/200335 "2019-09-25T20:24:16Z")

</div>

Getting these about 20-30 minutes after starting filebeat and ongoing from then on: Sep 20 15:42:39 silver.smartabase.com filebeat\[7615\]: WARN beater/filebeat.go:368 Filebeat is unable to load the Ingest N…

---

## [Capturing missed logs after Elasticsearch read-only reset](https://discuss.elastic.co/t/capturing-missed-logs-after-elasticsearch-read-only-reset/201096)

<div class="topic-metadata">

**Author:** [@MinnMoto](https://discuss.elastic.co/u/MinnMoto)\
**Replies:** 0\
**Last updated:** [September 25, 2019, 7:44pm UTC](https://discuss.elastic.co/t/capturing-missed-logs-after-elasticsearch-read-only-reset/201096 "2019-09-25T19:44:18Z")

</div>

I ran into the situation 2 days ago where Elasticsearch kicked in to a "FORBIDDEN/12/index read-only" episode. I freed up space, reset the read\_only\_allow\_delete and got logs capturing again. However, I had about 12 hour…

---

## [Filter the content of "message" as independent fields](https://discuss.elastic.co/t/filter-the-content-of-message-as-independent-fields/200260)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 3\
**Last updated:** [September 25, 2019, 7:21pm UTC](https://discuss.elastic.co/t/filter-the-content-of-message-as-independent-fields/200260 "2019-09-25T19:21:06Z")

</div>

Hi! I'm using filebeat in my GKE cluster. All my logs messages are in json format. My surprise is that the message field is treated as a single field, and what I would like is for it to be treated as separate fields in…

---

## [Send kubernetes pod IP address data from filebeat](https://discuss.elastic.co/t/send-kubernetes-pod-ip-address-data-from-filebeat/200028)

<div class="topic-metadata">

**Author:** [@chakragod](https://discuss.elastic.co/u/chakragod)\
**Replies:** 1\
**Last updated:** [September 25, 2019, 1:56pm UTC](https://discuss.elastic.co/t/send-kubernetes-pod-ip-address-data-from-filebeat/200028 "2019-09-25T13:56:22Z")

</div>

Hello, We have our filebeat set up as a daemon set in our Kubernetes Cluster. We have enabled the Kubernetes metadata configuration, but do not get the pod ip data. Tried the following configs without any luck: proce…

---

## [Grok filter fails when met with new line in multiline log](https://discuss.elastic.co/t/grok-filter-fails-when-met-with-new-line-in-multiline-log/200837)

<div class="topic-metadata">

**Author:** [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Replies:** 2\
**Last updated:** [September 25, 2019, 12:28pm UTC](https://discuss.elastic.co/t/grok-filter-fails-when-met-with-new-line-in-multiline-log/200837 "2019-09-25T12:28:54Z")

</div>

Hi, I'm trying to parse some logs into Ealsticsearch from Filebeat. The logs has a new line in them and their format is as follows: # error 123 failed attempt because blah blah I am changing the filter in the ingest…

---

## [Docker hints based autodiscover custom label](https://discuss.elastic.co/t/docker-hints-based-autodiscover-custom-label/200999)

<div class="topic-metadata">

**Author:** [@jbws](https://discuss.elastic.co/u/jbws)\
**Replies:** 1\
**Last updated:** [September 25, 2019, 1:12pm UTC](https://discuss.elastic.co/t/docker-hints-based-autodiscover-custom-label/200999 "2019-09-25T13:12:37Z")

</div>

Can I create a custom label in my container and then choose an index based on that? For example co.elastic.logs/environment=staging I have test and staging applications running in the same cluster that need to log to d…

---

## [Elasticsearch doesn't create Metricbeat index](https://discuss.elastic.co/t/elasticsearch-doesnt-create-metricbeat-index/200444)

<div class="topic-metadata">

**Author:** [@ndg](https://discuss.elastic.co/u/ndg)\
**Replies:** 2\
**Last updated:** [September 25, 2019, 12:49pm UTC](https://discuss.elastic.co/t/elasticsearch-doesnt-create-metricbeat-index/200444 "2019-09-25T12:49:57Z")

</div>

So, i am making a POC Swarm with 1 manager and 2 workers and both workers are in Drain state so i am only deploying services in the manager. I am trying to build a ELK stack from the ground up fully with docker container…

---

## [Filebeat data publish completion status](https://discuss.elastic.co/t/filebeat-data-publish-completion-status/200989)

<div class="topic-metadata">

**Author:** [@sonukumarsah](https://discuss.elastic.co/u/sonukumarsah)\
**Replies:** 0\
**Last updated:** [September 25, 2019, 7:54am UTC](https://discuss.elastic.co/t/filebeat-data-publish-completion-status/200989 "2019-09-25T07:54:11Z")

</div>

How can I ensure the filebeat published all the logs data successfully to ES. example: in kibana, there is an option in index management 'Docs count'. once we start filebeat, the logs will be loading and the 'Docs cou…

---

## [Filebat - Create a custom index on elasticsearch](https://discuss.elastic.co/t/filebat-create-a-custom-index-on-elasticsearch/197741)

<div class="topic-metadata">

**Author:** [@jaderolyver](https://discuss.elastic.co/u/jaderolyver)\
**Replies:** 13\
**Last updated:** [September 25, 2019, 7:10am UTC](https://discuss.elastic.co/t/filebat-create-a-custom-index-on-elasticsearch/197741 "2019-09-25T07:10:20Z")

</div>

Please someone here understand what is happen with my config, my filebeat doenst create index with my custom name. When i run the command filebeat setup the filebeat communicate with my elastic and create a index default…

---

## [How to configure the Auditbeat, Metricbeat, ....etc on Server and clients side? For example I have one server and I would like to manage others client](https://discuss.elastic.co/t/how-to-configure-the-auditbeat-metricbeat-etc-on-server-and-clients-side-for-example-i-have-one-server-and-i-would-like-to-manage-others-client/200951)

<div class="topic-metadata">

**Author:** [@pbona](https://discuss.elastic.co/u/pbona)\
**Replies:** 0\
**Last updated:** [September 25, 2019, 3:24am UTC](https://discuss.elastic.co/t/how-to-configure-the-auditbeat-metricbeat-etc-on-server-and-clients-side-for-example-i-have-one-server-and-i-would-like-to-manage-others-client/200951 "2019-09-25T03:24:02Z")

</div>

How to configure the Auditbeat, Metricbeat, ....etc on Server and clients side? For example I have one server and I would like to manage others client.

---

## [Filebeat CPU usage too high](https://discuss.elastic.co/t/filebeat-cpu-usage-too-high/200782)

<div class="topic-metadata">

**Author:** [@sugimoccos](https://discuss.elastic.co/u/sugimoccos)\
**Replies:** 2\
**Last updated:** [September 25, 2019, 1:30am UTC](https://discuss.elastic.co/t/filebeat-cpu-usage-too-high/200782 "2019-09-25T01:30:58Z")

</div>

Hi, My filebeats' CPU usage is too high. I couldn't find solution in this forum. I'm suspecting multiple wildcard inclusion such as \*-\*\_\*.log causes CPU consumption. Please tell me how to reduce CPU usage. Version o…

---

## [Heartbeat configuration path not picking up when started](https://discuss.elastic.co/t/heartbeat-configuration-path-not-picking-up-when-started/200883)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 1\
**Last updated:** [September 24, 2019, 10:02pm UTC](https://discuss.elastic.co/t/heartbeat-configuration-path-not-picking-up-when-started/200883 "2019-09-24T22:02:03Z")

</div>

Platform: Windows Heartbeat 7.0.0 As we expand the amount of servers that were monitoring I've been trying to setup heartbeat to read from the monitors.d folder. ############################# Heartbeat ###############…

---

## [Metricbeat for Solaris x86](https://discuss.elastic.co/t/metricbeat-for-solaris-x86/199881)

<div class="topic-metadata">

**Author:** [@ConnorRies](https://discuss.elastic.co/u/ConnorRies)\
**Replies:** 3\
**Last updated:** [September 24, 2019, 9:30pm UTC](https://discuss.elastic.co/t/metricbeat-for-solaris-x86/199881 "2019-09-24T21:30:58Z")

</div>

Hey guys, Was just curious if it was possible to successfully run Metricbeat on Solaris x86 or if that was going to be a significant effort. I was able to build Filebeat from source for Solaris 11.3 (x86) just fine, bu…

---

## [Unable to integrate new beat metrics with Kibana](https://discuss.elastic.co/t/unable-to-integrate-new-beat-metrics-with-kibana/200893)

<div class="topic-metadata">

**Author:** [@kenrowland](https://discuss.elastic.co/u/kenrowland)\
**Replies:** 3\
**Last updated:** [September 24, 2019, 9:00pm UTC](https://discuss.elastic.co/t/unable-to-integrate-new-beat-metrics-with-kibana/200893 "2019-09-24T21:00:45Z")

</div>

I am having trouble finding documentation on the process of getting the metrics reported by my new beat into Kibana. The beat was created based on metric beat as described here. The process created a starting module and…

---

## [Prometheus module stop working with new metrics format](https://discuss.elastic.co/t/prometheus-module-stop-working-with-new-metrics-format/199069)

<div class="topic-metadata">

**Author:** [@Angel\_Luis\_Gonzalez](https://discuss.elastic.co/u/Angel_Luis_Gonzalez)\
**Replies:** 1\
**Last updated:** [September 24, 2019, 5:20pm UTC](https://discuss.elastic.co/t/prometheus-module-stop-working-with-new-metrics-format/199069 "2019-09-24T17:20:28Z")

</div>

I used to have an thirdparty prometheus exporter (Microprofile metrics) and the prometheus metricbeat module worked fine. Here an example of the working format: # HELP base:thread\_max\_count Displays the peak live thread…

---

## [System.cpu.total.norm.pct missing](https://discuss.elastic.co/t/system-cpu-total-norm-pct-missing/199840)

<div class="topic-metadata">

**Author:** [@Ron.Janssen](https://discuss.elastic.co/u/Ron.Janssen)\
**Replies:** 1\
**Last updated:** [September 24, 2019, 2:44pm UTC](https://discuss.elastic.co/t/system-cpu-total-norm-pct-missing/199840 "2019-09-24T14:44:11Z")

</div>

I'm creating my first dashboard to report on resource utilization of some VM's. One of the VMs has multiple cores, and system.cpu.total.pct is reporting percentages \> 100%. According to the documentation I can use the no…

---

## [Trouble integrating new beat, based on metricbeat, with Kibana](https://discuss.elastic.co/t/trouble-integrating-new-beat-based-on-metricbeat-with-kibana/200264)

<div class="topic-metadata">

**Author:** [@kenrowland](https://discuss.elastic.co/u/kenrowland)\
**Replies:** 1\
**Last updated:** [September 24, 2019, 1:49pm UTC](https://discuss.elastic.co/t/trouble-integrating-new-beat-based-on-metricbeat-with-kibana/200264 "2019-09-24T13:49:19Z")

</div>

I am having trouble finding documentation on the process of getting the metrics reported by my new beat into Kibana. The beat was created based on metric beat as described here. The process created a starting module and…

---

## [Help needed: Filebeat Container input \> Elasticsearch \>Kibana](https://discuss.elastic.co/t/help-needed-filebeat-container-input-elasticsearch-kibana/197059)

<div class="topic-metadata">

**Author:** [@Iosif\_Zamfirescu](https://discuss.elastic.co/u/Iosif_Zamfirescu)\
**Replies:** 11\
**Last updated:** [September 24, 2019, 11:54am UTC](https://discuss.elastic.co/t/help-needed-filebeat-container-input-elasticsearch-kibana/197059 "2019-09-24T11:54:21Z")

</div>

Hi all, Docker home user here who needs some help. Architecture: Host OS: Windows 10 Pro Docker for Windows latest version. I use docker compose managed through dockstation.io In the attached picture you can see wh…

---

## [Json data logging has strange behaviour](https://discuss.elastic.co/t/json-data-logging-has-strange-behaviour/200852)

<div class="topic-metadata">

**Author:** [@Monu\_Kumar](https://discuss.elastic.co/u/Monu_Kumar)\
**Replies:** 0\
**Last updated:** [September 24, 2019, 11:21am UTC](https://discuss.elastic.co/t/json-data-logging-has-strange-behaviour/200852 "2019-09-24T11:21:50Z")

</div>

I'm using filebeat to send JSON logs to elasticsearch-\>kibana. Here is my filebeat.inputs config params: filebeat.inputs: - type: log enabled: true paths: - /home/ubuntu/testlog.\* jso…

---

## [Multiline problem - need help](https://discuss.elastic.co/t/multiline-problem-need-help/200851)

<div class="topic-metadata">

**Author:** [@mkaruza](https://discuss.elastic.co/u/mkaruza)\
**Replies:** 0\
**Last updated:** [September 24, 2019, 11:20am UTC](https://discuss.elastic.co/t/multiline-problem-need-help/200851 "2019-09-24T11:20:06Z")

</div>

I'm trying to assign entries without timestamp to the previous ones that DO have timestamps, so they stick together when I perform search in Elasticsearch. However, I haven't been successful at it. This is my filebeat …

---

## [Can i run heartbeat in k8s and how to config](https://discuss.elastic.co/t/can-i-run-heartbeat-in-k8s-and-how-to-config/200784)

<div class="topic-metadata">

**Author:** [@ZMMWMY](https://discuss.elastic.co/u/ZMMWMY)\
**Replies:** 1\
**Last updated:** [September 24, 2019, 10:09am UTC](https://discuss.elastic.co/t/can-i-run-heartbeat-in-k8s-and-how-to-config/200784 "2019-09-24T10:09:39Z")

</div>

i try to monitor services which running in k8s

---

## [\[Metricbeat\] Some Visualizations have no data to display in Dashboard](https://discuss.elastic.co/t/metricbeat-some-visualizations-have-no-data-to-display-in-dashboard/200196)

<div class="topic-metadata">

**Author:** [@sailershen](https://discuss.elastic.co/u/sailershen)\
**Replies:** 1\
**Last updated:** [September 24, 2019, 12:33am UTC](https://discuss.elastic.co/t/metricbeat-some-visualizations-have-no-data-to-display-in-dashboard/200196 "2019-09-24T00:33:51Z")

</div>

In master of k8s, /etc/metricbeat/modules.d/kubernetes.yml # Node metrics, from kubelet: - module: kubernetes metricsets: - node - system - pod - container - volume period: 10s hosts: \["127.0.0…

---

## [Message "failed to load host information: 1 error: no /etc/\<distrib\>-release file found"](https://discuss.elastic.co/t/message-failed-to-load-host-information-1-error-no-etc-distrib-release-file-found/200556)

<div class="topic-metadata">

**Author:** [@michaelberg](https://discuss.elastic.co/u/michaelberg)\
**Replies:** 5\
**Last updated:** [September 23, 2019, 10:15pm UTC](https://discuss.elastic.co/t/message-failed-to-load-host-information-1-error-no-etc-distrib-release-file-found/200556 "2019-09-23T22:15:03Z")

</div>

Good evening! I am getting "failed to load host information: 1 error: no /etc/-release file found" popping up all over my Auditbeat output and it's making it's way into Kibana/Elasticsearch as well .. Running Fedora 30…

---

## [Start FileBeat using publish](https://discuss.elastic.co/t/start-filebeat-using-publish/200710)

<div class="topic-metadata">

**Author:** [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Replies:** 20\
**Last updated:** [September 23, 2019, 7:55pm UTC](https://discuss.elastic.co/t/start-filebeat-using-publish/200710 "2019-09-23T19:55:19Z")

</div>

Hello everyone, Im not sure what the difference is between starting filebeat using: service start filebeat AND ./filebeat -e -c /etc/filebeat/filebeat.yml -d "publish" the latter seems to work better than the first one…

---

## [Attempting to add backward compatible field metricset.module](https://discuss.elastic.co/t/attempting-to-add-backward-compatible-field-metricset-module/200317)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 1\
**Last updated:** [September 23, 2019, 6:27pm UTC](https://discuss.elastic.co/t/attempting-to-add-backward-compatible-field-metricset-module/200317 "2019-09-23T18:27:28Z")

</div>

Hi, I am using metricbeat 7.3.2, with migration.6\_to\_7.enabled: true set to get backward compatible fields. One field that still isn't showing up is metricset.module. Many of our dashboards and alerts depend on this fi…

---

## [Limit number of bytes read from a file](https://discuss.elastic.co/t/limit-number-of-bytes-read-from-a-file/200497)

<div class="topic-metadata">

**Author:** [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Replies:** 2\
**Last updated:** [September 23, 2019, 5:45pm UTC](https://discuss.elastic.co/t/limit-number-of-bytes-read-from-a-file/200497 "2019-09-23T17:45:24Z")

</div>

Is there an option which can limit the number of bytes to be read from a file ? Some of the users are creating jobs that has very large log files and in that case i do not want to index all data but limit to a specific…

---

## [Filebeat UDP input problem setting up on Windows](https://discuss.elastic.co/t/filebeat-udp-input-problem-setting-up-on-windows/200605)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [September 23, 2019, 5:10pm UTC](https://discuss.elastic.co/t/filebeat-udp-input-problem-setting-up-on-windows/200605 "2019-09-23T17:10:46Z")

</div>

Hello, Trying to send some syslog to a Filebeat running on my Windows 10 device. Filebeat configuration: - type: udp max\_message\_size: 10KiB host: "localhost:10514" pipeline: filebeat-pfsense Now although I can …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=313)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=315)
