# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=315

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 316

---

## [Weird etdl+1](https://discuss.elastic.co/t/weird-etdl-1/200528)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [September 23, 2019, 5:07pm UTC](https://discuss.elastic.co/t/weird-etdl-1/200528 "2019-09-23T17:07:43Z")

</div>

Found a weird etdl+1 value in Packetbeat dns data: Seems not normal to create this field for an ip? "question": { "name": "127.0.0.1:5432", "type": "A", "class": "IN", "etld\_plus\_one": "0.1:5432" },

---

## [Defining "if - elseif - else" when setting up processors?](https://discuss.elastic.co/t/defining-if-elseif-else-when-setting-up-processors/200725)

<div class="topic-metadata">

**Author:** [@TheSwede86](https://discuss.elastic.co/u/TheSwede86)\
**Replies:** 0\
**Last updated:** [September 23, 2019, 3:54pm UTC](https://discuss.elastic.co/t/defining-if-elseif-else-when-setting-up-processors/200725 "2019-09-23T15:54:56Z")

</div>

Hi, Some context: AWS Log Group: MyLogGroupForEC2s Log Streams: myhost1-System #EventViewer myhost1-Application #EventViewer myhost1-CloudWatchAgent #CustomLogTxt and many more for the fictious "myhost1" and A LO…

---

## [Winlog with SSL - Errors](https://discuss.elastic.co/t/winlog-with-ssl-errors/200454)

<div class="topic-metadata">

**Author:** [@NewmazN24](https://discuss.elastic.co/u/NewmazN24)\
**Replies:** 3\
**Last updated:** [September 23, 2019, 1:20pm UTC](https://discuss.elastic.co/t/winlog-with-ssl-errors/200454 "2019-09-23T13:20:55Z")

</div>

Hello folks, I have configured Kibana, Elasticsearch with TLS/SSL. It works. When I am trying to do the same for my Winlogbeat, I can't make it work. Command: .\\winlogbeat.exe -c winlogbeat.yml -e -d "\*" Outpout 201…

---

## [Unable to load the sample dashboard for auditbeat7.2.0](https://discuss.elastic.co/t/unable-to-load-the-sample-dashboard-for-auditbeat7-2-0/200405)

<div class="topic-metadata">

**Author:** [@Abdur\_Raqeeb2](https://discuss.elastic.co/u/Abdur_Raqeeb2)\
**Replies:** 1\
**Last updated:** [September 23, 2019, 5:38am UTC](https://discuss.elastic.co/t/unable-to-load-the-sample-dashboard-for-auditbeat7-2-0/200405 "2019-09-23T05:38:09Z")

</div>

HI, Im unable to load the auditbeat 7.2.0 dashboard from the server.Please find the error below # auditbeat setup --dashboards Loading dashboards (Kibana must be running and reachable) Exiting: Failed to import dashboa…

---

## [Filebeat Autodiscover Docker ES7](https://discuss.elastic.co/t/filebeat-autodiscover-docker-es7/200102)

<div class="topic-metadata">

**Author:** [@cbille0](https://discuss.elastic.co/u/cbille0)\
**Replies:** 2\
**Last updated:** [September 23, 2019, 1:29am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-docker-es7/200102 "2019-09-23T01:29:02Z")

</div>

Hello, Have a quick question in regards to Filebeat autodiscover for Docker. Traditionally we have deployed Filebeat on every node in our cluster to retrieve logs from Docker containers and send them to Logstash. This…

---

## [Question about Heartbeat not being able to communicate with Elastic/Kibana server](https://discuss.elastic.co/t/question-about-heartbeat-not-being-able-to-communicate-with-elastic-kibana-server/200589)

<div class="topic-metadata">

**Author:** [@hacbobross](https://discuss.elastic.co/u/hacbobross)\
**Replies:** 8\
**Last updated:** [September 22, 2019, 3:29pm UTC](https://discuss.elastic.co/t/question-about-heartbeat-not-being-able-to-communicate-with-elastic-kibana-server/200589 "2019-09-22T15:29:55Z")

</div>

Hello everyone, I am trying to get familiar with the ELK stack and right now I am encountering a problem. I am using VMare Workstation 15 Pro and have set up an Elastic VM that contains Elasticsearch, Kibana, and Logsta…

---

## [Filebeat send to ES ingest pipeline but can't create index](https://discuss.elastic.co/t/filebeat-send-to-es-ingest-pipeline-but-cant-create-index/200586)

<div class="topic-metadata">

**Author:** [@Jib\_Suwanachote](https://discuss.elastic.co/u/Jib_Suwanachote)\
**Replies:** 0\
**Last updated:** [September 22, 2019, 1:31pm UTC](https://discuss.elastic.co/t/filebeat-send-to-es-ingest-pipeline-but-cant-create-index/200586 "2019-09-22T13:31:48Z")

</div>

I would like to send log to to ingest node pipeline this is my config before I send the log via filebeat I was created pipeline on ES and see filebeat log send the log to ES. I have question Why I can't see index nam…

---

## [Windows User managment events - problem](https://discuss.elastic.co/t/windows-user-managment-events-problem/200580)

<div class="topic-metadata">

**Author:** [@abu.sayeed](https://discuss.elastic.co/u/abu.sayeed)\
**Replies:** 0\
**Last updated:** [September 22, 2019, 12:53pm UTC](https://discuss.elastic.co/t/windows-user-managment-events-problem/200580 "2019-09-22T12:53:01Z")

</div>

I change winlogbeat-security.js file like below: // Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one // or more contributor license agreements. Licensed under the Elastic License; // you ma…

---

## [Full packet inspection with beats?](https://discuss.elastic.co/t/full-packet-inspection-with-beats/200555)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 0\
**Last updated:** [September 22, 2019, 1:53am UTC](https://discuss.elastic.co/t/full-packet-inspection-with-beats/200555 "2019-09-22T01:53:07Z")

</div>

How can the beat(s) system be used to listen/ingest full packets, ie i don't just want the headers, but the data also. Scenario: Can one or more beats be used to listen for SMB TCP traffic and identify the SMBv1 dialect…

---

## [Filebeat output connection to Kafka only working on the first execution](https://discuss.elastic.co/t/filebeat-output-connection-to-kafka-only-working-on-the-first-execution/200523)

<div class="topic-metadata">

**Author:** [@nemoon](https://discuss.elastic.co/u/nemoon)\
**Replies:** 0\
**Last updated:** [September 21, 2019, 11:19am UTC](https://discuss.elastic.co/t/filebeat-output-connection-to-kafka-only-working-on-the-first-execution/200523 "2019-09-21T11:19:57Z")

</div>

Hello! I am using Filebeat to stream a log file (PVSS\_II.log) to Kafka, but I am having troubles when I execute Filebeat after the first time (it works fine on the first launch). The first thing that I do is starting m…

---

## [Beats to Logstash?](https://discuss.elastic.co/t/beats-to-logstash/200503)

<div class="topic-metadata">

**Author:** [@SteveP](https://discuss.elastic.co/u/SteveP)\
**Replies:** 2\
**Last updated:** [September 21, 2019, 1:34am UTC](https://discuss.elastic.co/t/beats-to-logstash/200503 "2019-09-21T01:34:13Z")

</div>

If I am taking in data from Beats do I need to go through Logstash to Elasticsearch or can I go directly to Elasticsearch and then visualize it in Kibana? I am bit confused as to how Logstash fits into Beats.

---

## [Filebeat is not cleaning old kubernetes log files that were autodiscovered from the registry](https://discuss.elastic.co/t/filebeat-is-not-cleaning-old-kubernetes-log-files-that-were-autodiscovered-from-the-registry/200494)

<div class="topic-metadata">

**Author:** [@carlsoane](https://discuss.elastic.co/u/carlsoane)\
**Replies:** 0\
**Last updated:** [September 20, 2019, 8:46pm UTC](https://discuss.elastic.co/t/filebeat-is-not-cleaning-old-kubernetes-log-files-that-were-autodiscovered-from-the-registry/200494 "2019-09-20T20:46:23Z")

</div>

I have found that filebeat is not cleaning kubernetes autodiscovered log entries from the registry. I verified this by running an ls against each source listed in my filebeat registry file. I found that the vast majority…

---

## [Filebeat Apache Module Ingest Pipeline](https://discuss.elastic.co/t/filebeat-apache-module-ingest-pipeline/200493)

<div class="topic-metadata">

**Author:** [@jvicente](https://discuss.elastic.co/u/jvicente)\
**Replies:** 0\
**Last updated:** [September 20, 2019, 8:45pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-ingest-pipeline/200493 "2019-09-20T20:45:41Z")

</div>

I am currently working on formatting the @timestamp in access logs for the apache2 module in Filebeat. Currently getting the following error message on kibana: "Provided Grok expressions do not match field value:" My cu…

---

## [Filebeat autodiscovery hints](https://discuss.elastic.co/t/filebeat-autodiscovery-hints/200415)

<div class="topic-metadata">

**Author:** [@Andrii](https://discuss.elastic.co/u/Andrii)\
**Replies:** 0\
**Last updated:** [September 20, 2019, 12:38pm UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-hints/200415 "2019-09-20T12:38:43Z")

</div>

I'm trying to use Kubernetes annotations to instruct filebeat how my logs should be processed. But so far I was lucky with the dissect and timestamp processors only. Nor rename, neither drop\_fileds are not working for …

---

## [Could not locate that index-pattern-field](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field/200147)

<div class="topic-metadata">

**Author:** [@Ludovic9](https://discuss.elastic.co/u/Ludovic9)\
**Replies:** 2\
**Last updated:** [September 20, 2019, 11:33am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-field/200147 "2019-09-20T11:33:54Z")

</div>

Hello, I have some questions about this error I have when I run a visualization "Unique IPs map \[Filebeat Apache2\]". I'm using filbeat to send logs of filezilla to logstash then to elasticsearch. The index name is "fil…

---

## [How fast is the Filebeat autodiscover?](https://discuss.elastic.co/t/how-fast-is-the-filebeat-autodiscover/200382)

<div class="topic-metadata">

**Author:** [@jiangpengcheng](https://discuss.elastic.co/u/jiangpengcheng)\
**Replies:** 0\
**Last updated:** [September 20, 2019, 8:53am UTC](https://discuss.elastic.co/t/how-fast-is-the-filebeat-autodiscover/200382 "2019-09-20T08:53:51Z")

</div>

Hello all, I have a situation where containers may be created and terminated frequently, so I wonder whether the Filebeat able to realize a container and collect its logs if that container is terminated just a few second…

---

## [\[ES7.3\] Double input not working](https://discuss.elastic.co/t/es7-3-double-input-not-working/200372)

<div class="topic-metadata">

**Author:** [@ericv](https://discuss.elastic.co/u/ericv)\
**Replies:** 0\
**Last updated:** [September 20, 2019, 8:06am UTC](https://discuss.elastic.co/t/es7-3-double-input-not-working/200372 "2019-09-20T08:06:11Z")

</div>

Hi, I've setup ES 7.3 and it's been working great for us so far. From our servers I'm sending logs to it using Filebeat without issues. The problem I'm facing is because of our storage devices, HP Nimble. The can only s…

---

## [Filebeat on windows problem Failed to publish events](https://discuss.elastic.co/t/filebeat-on-windows-problem-failed-to-publish-events/200348)

<div class="topic-metadata">

**Author:** [@111202](https://discuss.elastic.co/u/111202)\
**Replies:** 0\
**Last updated:** [September 20, 2019, 6:15am UTC](https://discuss.elastic.co/t/filebeat-on-windows-problem-failed-to-publish-events/200348 "2019-09-20T06:15:58Z")

</div>

Hello, I wanna collect IIS service log to my logstash then services was running on windows but I can't send logs to my logstash , following this picture is error log from filebeat here are my setting config windo…

---

## [Default Filebeat index pattern](https://discuss.elastic.co/t/default-filebeat-index-pattern/200314)

<div class="topic-metadata">

**Author:** [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Replies:** 1\
**Last updated:** [September 20, 2019, 5:45am UTC](https://discuss.elastic.co/t/default-filebeat-index-pattern/200314 "2019-09-20T05:45:05Z")

</div>

Filebeat creates a huge index pattern when with over a 1K fields in it when its connected the first time to ES/Kibana. WIth all the field for all the modules. Is there a way to disable it and to create an index pattern o…

---

## [Apache module add field](https://discuss.elastic.co/t/apache-module-add-field/200300)

<div class="topic-metadata">

**Author:** [@ppafford](https://discuss.elastic.co/u/ppafford)\
**Replies:** 0\
**Last updated:** [September 19, 2019, 7:38pm UTC](https://discuss.elastic.co/t/apache-module-add-field/200300 "2019-09-19T19:38:00Z")

</div>

The documentation is not straight forward but it does lead me to believe that this might be possible https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache.html#apache-settings https://www.elasti…

---

## [Syslog and filebeat assistance request](https://discuss.elastic.co/t/syslog-and-filebeat-assistance-request/192993)

<div class="topic-metadata">

**Author:** [@Brian\_Tima](https://discuss.elastic.co/u/Brian_Tima)\
**Replies:** 24\
**Last updated:** [September 19, 2019, 7:27pm UTC](https://discuss.elastic.co/t/syslog-and-filebeat-assistance-request/192993 "2019-09-19T19:27:40Z")

</div>

We have been running ELK v. 6.2.x We have a central syslog server on EL5 pushing log files with filebeat to logstash I have been tasked with setting up a new central syslog server on EL7 (replace EL5 instance). Filebe…

---

## [How does the filebeat elasticsearch module know where the elasticsearch server is?](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066)

<div class="topic-metadata">

**Author:** [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Replies:** 13\
**Last updated:** [September 19, 2019, 4:58pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066 "2019-09-19T16:58:15Z")

</div>

How do I tell the filebeat elasticsearch module where my elasticsearch cluster is? I am running in kubernetes and elasticsearch is installed in a different namespace.

---

## [Error in visualization "field" is a required parameter](https://discuss.elastic.co/t/error-in-visualization-field-is-a-required-parameter/198122)

<div class="topic-metadata">

**Author:** [@mheinle](https://discuss.elastic.co/u/mheinle)\
**Replies:** 1\
**Last updated:** [September 19, 2019, 4:24pm UTC](https://discuss.elastic.co/t/error-in-visualization-field-is-a-required-parameter/198122 "2019-09-19T16:24:07Z")

</div>

Hello, I am super new to ELK and having trouble with Kibana after running through Getting Started with Winlogbeats 7.0 I had Winlogbeats working fine and was trying to output to Logstash so I went through the guide. O…

---

## [Filebeat with json logs, using template](https://discuss.elastic.co/t/filebeat-with-json-logs-using-template/200230)

<div class="topic-metadata">

**Author:** [@Frank\_Wang](https://discuss.elastic.co/u/Frank_Wang)\
**Replies:** 0\
**Last updated:** [September 19, 2019, 2:26pm UTC](https://discuss.elastic.co/t/filebeat-with-json-logs-using-template/200230 "2019-09-19T14:26:52Z")

</div>

Assume I have Logs like: {"CFSItemName":"mds list user fs","CFSCluster":"clu01","Item":\[{"TotalBytes":9223372036854775808,"FreeBytes":9223372036854763507,"Fsname":"fs-z0gzns5267"},{"TotalBytes":1233372036854775808,"Free…

---

## [Extract kubernetes cluster name from logs to visualize in kibana dashboard](https://discuss.elastic.co/t/extract-kubernetes-cluster-name-from-logs-to-visualize-in-kibana-dashboard/200050)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 3\
**Last updated:** [September 19, 2019, 1:33pm UTC](https://discuss.elastic.co/t/extract-kubernetes-cluster-name-from-logs-to-visualize-in-kibana-dashboard/200050 "2019-09-19T13:33:23Z")

</div>

Hi! I'm using filebeat in my GKE clusters to retrieve all logs for all my kubernetes clusters. I would like to do a filter / dashboard or visualization (I don't how to say it hehe) that I can filter logs by kubernetes…

---

## [Filbeat.yml file configuration to send to the cloud to different indexes](https://discuss.elastic.co/t/filbeat-yml-file-configuration-to-send-to-the-cloud-to-different-indexes/200183)

<div class="topic-metadata">

**Author:** [@fadil030889](https://discuss.elastic.co/u/fadil030889)\
**Replies:** 0\
**Last updated:** [September 19, 2019, 10:52am UTC](https://discuss.elastic.co/t/filbeat-yml-file-configuration-to-send-to-the-cloud-to-different-indexes/200183 "2019-09-19T10:52:21Z")

</div>

Hi so I have the following yaml file for filebeat, sending logs file from an on prem server to the elastic cloud. I wanted to have the config to send each log path to the defined indexes, but its not working. Anyone know…

---

## [Filebeat config.hosts using url](https://discuss.elastic.co/t/filebeat-config-hosts-using-url/198911)

<div class="topic-metadata">

**Author:** [@Frank\_Wang](https://discuss.elastic.co/u/Frank_Wang)\
**Replies:** 2\
**Last updated:** [September 19, 2019, 10:16am UTC](https://discuss.elastic.co/t/filebeat-config-hosts-using-url/198911 "2019-09-19T10:16:14Z")

</div>

I have a elasticSearch deployed on url "hd-yfcs-es6.xxx.com". I can curl it and get result like following \[root@A04-R08-I198-70-1WLFTP2 conf\]# curl CfsEs:CfsEs-es@hd-yfcs-es6.xxx.com:80 -v \* About to connect() to hd-yfc…

---

## [‼ Why is metricbeat contacting metadata.tencentyun.com?](https://discuss.elastic.co/t/why-is-metricbeat-contacting-metadata-tencentyun-com/200059)

<div class="topic-metadata">

**Author:** [@alastairs](https://discuss.elastic.co/u/alastairs)\
**Replies:** 2\
**Last updated:** [September 19, 2019, 9:01am UTC](https://discuss.elastic.co/t/why-is-metricbeat-contacting-metadata-tencentyun-com/200059 "2019-09-19T09:01:48Z")

</div>

Following some issues with our 6.x Elastic stack deployment, I deployed a new cluster to Google Cloud Platform in Belgium running Elasticsearch 7.3.2. I also updated our Filebeat deployment on our Kubernetes cluster to v…

---

## [When the processor-decode-cef would be available?](https://discuss.elastic.co/t/when-the-processor-decode-cef-would-be-available/200097)

<div class="topic-metadata">

**Author:** [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Replies:** 1\
**Last updated:** [September 19, 2019, 7:27am UTC](https://discuss.elastic.co/t/when-the-processor-decode-cef-would-be-available/200097 "2019-09-19T07:27:47Z")

</div>

Any idea when the processor-decode-cef would be available? https://www.elastic.co/guide/en/beats/filebeat/master/processor-decode-cef.html

---

## [Filebeat to logstash - connectivity issue](https://discuss.elastic.co/t/filebeat-to-logstash-connectivity-issue/196686)

<div class="topic-metadata">

**Author:** [@Arun\_Annamalai](https://discuss.elastic.co/u/Arun_Annamalai)\
**Replies:** 3\
**Last updated:** [September 19, 2019, 5:12am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-connectivity-issue/196686 "2019-09-19T05:12:01Z")

</div>

Versions used: logstash - 7.3.1 filebeat - 7.3.1 the entire elastic stack is running in on same server. I am facing issue while trying to send data from filebeat to logstash. 2019-08-25T21:34:21.900-0300 INFO l…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=314)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=316)
