# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=316

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 317

---

## [FileBeat cant connect to Logstash](https://discuss.elastic.co/t/filebeat-cant-connect-to-logstash/199879)

<div class="topic-metadata">

**Author:** [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Replies:** 4\
**Last updated:** [September 19, 2019, 4:05am UTC](https://discuss.elastic.co/t/filebeat-cant-connect-to-logstash/199879 "2019-09-19T04:05:38Z")

</div>

Hello everyone, so i installed ELK on a server and filebeat on a client and it was working fine. now that im going to prod env i did the same thing but filebeat cant for some reason reach logstash. Im using aws instance…

---

## [Zeek Import - Timestamp & Geo Failing](https://discuss.elastic.co/t/zeek-import-timestamp-geo-failing/198536)

<div class="topic-metadata">

**Author:** [@0x00](https://discuss.elastic.co/u/0x00)\
**Replies:** 3\
**Last updated:** [September 19, 2019, 2:37am UTC](https://discuss.elastic.co/t/zeek-import-timestamp-geo-failing/198536 "2019-09-19T02:37:52Z")

</div>

I am attempting to use Filebeat on Ubuntu Linux to import a JSON formatted conn.log as the obfuscated sample is shown below: {"\_path":"conn","\_system\_name":"sensor","\_write\_ts":"2019-07-02T15:53:03.511364Z","ts":"2019-0…

---

## [How to merge log events as a single log event, when frequent updates happens to a file](https://discuss.elastic.co/t/how-to-merge-log-events-as-a-single-log-event-when-frequent-updates-happens-to-a-file/200054)

<div class="topic-metadata">

**Author:** [@Mahesh\_Guntumadugu](https://discuss.elastic.co/u/Mahesh_Guntumadugu)\
**Replies:** 0\
**Last updated:** [September 18, 2019, 4:30pm UTC](https://discuss.elastic.co/t/how-to-merge-log-events-as-a-single-log-event-when-frequent-updates-happens-to-a-file/200054 "2019-09-18T16:30:53Z")

</div>

Data will be written in log file while installing product at random time interval.Overall it will take 10 minutes time to finish the whole installation process. with multiline settings , I was able to send whole file as…

---

## [Script processor seems to be not working](https://discuss.elastic.co/t/script-processor-seems-to-be-not-working/199500)

<div class="topic-metadata">

**Author:** [@Andrii](https://discuss.elastic.co/u/Andrii)\
**Replies:** 1\
**Last updated:** [September 18, 2019, 4:11pm UTC](https://discuss.elastic.co/t/script-processor-seems-to-be-not-working/199500 "2019-09-18T16:11:56Z")

</div>

I need to lowercase the value for one of the fields. And seems like a script processor is the only option to do this. But even with an example config beat is not able to start. Filebeat version is 7.3.2 the config is: …

---

## [Filebeat and fields with dots in name](https://discuss.elastic.co/t/filebeat-and-fields-with-dots-in-name/198620)

<div class="topic-metadata">

**Author:** [@marcomusso](https://discuss.elastic.co/u/marcomusso)\
**Replies:** 5\
**Last updated:** [September 18, 2019, 2:26pm UTC](https://discuss.elastic.co/t/filebeat-and-fields-with-dots-in-name/198620 "2019-09-18T14:26:15Z")

</div>

Hi all, I found that the issue discussed in: is still relevant in 2019 using the default audit output in JSON (ref: log4j2.properties for Elasticsearch 7.x) which is: appender.audit\_rolling.layout.pattern = {\\ …

---

## [Security\_exception: action \[indices:admin/open\] is unauthorized for user](https://discuss.elastic.co/t/security-exception-action-indices-admin-open-is-unauthorized-for-user/200002)

<div class="topic-metadata">

**Author:** [@RafnexJr](https://discuss.elastic.co/u/RafnexJr)\
**Replies:** 0\
**Last updated:** [September 18, 2019, 12:14pm UTC](https://discuss.elastic.co/t/security-exception-action-indices-admin-open-is-unauthorized-for-user/200002 "2019-09-18T12:14:07Z")

</div>

Hi, I try to set the permissions for a Winlogbeat for my Elastic Cloud. I set the permissions like specified in this guide: "https://www.elastic.co/guide/en/beats/winlogbeat/current/feature-roles.html#privileges-to-set…

---

## [Filebeat Multiline.Pattern error parsing regexp](https://discuss.elastic.co/t/filebeat-multiline-pattern-error-parsing-regexp/199988)

<div class="topic-metadata">

**Author:** [@kollp](https://discuss.elastic.co/u/kollp)\
**Replies:** 0\
**Last updated:** [September 18, 2019, 11:25am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-error-parsing-regexp/199988 "2019-09-18T11:25:08Z")

</div>

Hello, Can someone give me a hint why the following Regex is not working within filebeat? ^\[\\d{4}\[\\S\\s\]+?\]\]?$ Errormessage is: 2019-09-18T13:14:38.496+0200 ERROR instance/beat.go:877 Exiting: Error while init…

---

## [Filebeat custom module to subscribe to events?](https://discuss.elastic.co/t/filebeat-custom-module-to-subscribe-to-events/199918)

<div class="topic-metadata">

**Author:** [@granier](https://discuss.elastic.co/u/granier)\
**Replies:** 3\
**Last updated:** [September 18, 2019, 11:17am UTC](https://discuss.elastic.co/t/filebeat-custom-module-to-subscribe-to-events/199918 "2019-09-18T11:17:25Z")

</div>

Hi, Is it possible to develop a custom filebeat module that subscribe to event such as clear\_renamed or clean\_removed or clean\_inactive ? My goal is to develop a module that delete the log files when filebeat stops to …

---

## [Create custom Docker image for metricbeat](https://discuss.elastic.co/t/create-custom-docker-image-for-metricbeat/199966)

<div class="topic-metadata">

**Author:** [@kjsh](https://discuss.elastic.co/u/kjsh)\
**Replies:** 0\
**Last updated:** [September 18, 2019, 10:00am UTC](https://discuss.elastic.co/t/create-custom-docker-image-for-metricbeat/199966 "2019-09-18T10:00:56Z")

</div>

Hi, I want to add a new metricset to Metricbeat v7.3.2 and build the corresponding Docker image with my changes. After reading the documentation about "Creating a new metricset", I was able to generate the new "metricbe…

---

## [Adding Filebeat to Production Environment](https://discuss.elastic.co/t/adding-filebeat-to-production-environment/199381)

<div class="topic-metadata">

**Author:** [@StevenO](https://discuss.elastic.co/u/StevenO)\
**Replies:** 1\
**Last updated:** [September 13, 2019, 8:14am UTC](https://discuss.elastic.co/t/adding-filebeat-to-production-environment/199381 "2019-09-13T08:14:19Z")

</div>

It is quite urgent that I add consolidating logging to a rather brittle system that includes wildfly 10.10 and tomcat servers(5). How does one add filebeats to a production environment? What is the maximum amount of m…

---

## [Heartbeat - Unnamed auto-tcp-0X3C15C657CDFFA0C3](https://discuss.elastic.co/t/heartbeat-unnamed-auto-tcp-0x3c15c657cdffa0c3/199674)

<div class="topic-metadata">

**Author:** [@Maekee](https://discuss.elastic.co/u/Maekee)\
**Replies:** 2\
**Last updated:** [September 18, 2019, 8:15am UTC](https://discuss.elastic.co/t/heartbeat-unnamed-auto-tcp-0x3c15c657cdffa0c3/199674 "2019-09-18T08:15:49Z")

</div>

Hello, I have configured the heartbeat.yml with these configs: heartbeat.monitors: type: tcp hosts: \["mylogstashserver1"\] schedule: '@every 10s' ports: \[5044\] name: "mylogstashserver1" output.logstash: hosts: …

---

## [Metricbeat dashboard not displaying accurate avg metrics for every host](https://discuss.elastic.co/t/metricbeat-dashboard-not-displaying-accurate-avg-metrics-for-every-host/199921)

<div class="topic-metadata">

**Author:** [@skdasari](https://discuss.elastic.co/u/skdasari)\
**Replies:** 0\
**Last updated:** [September 18, 2019, 7:04am UTC](https://discuss.elastic.co/t/metricbeat-dashboard-not-displaying-accurate-avg-metrics-for-every-host/199921 "2019-09-18T07:04:01Z")

</div>

Hello All, I have setup metricbeat in 4 servers A,B,C,D. A and B are windows servers where C and D are linux servers. In server C I have my ELasticsearch and Kibana setup installaed. When I installed metricbeat in all 4…

---

## [Filebeat to Logstash via reverse proxy](https://discuss.elastic.co/t/filebeat-to-logstash-via-reverse-proxy/199760)

<div class="topic-metadata">

**Author:** [@jaiganesh06](https://discuss.elastic.co/u/jaiganesh06)\
**Replies:** 1\
**Last updated:** [September 18, 2019, 5:17am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-via-reverse-proxy/199760 "2019-09-18T05:17:42Z")

</div>

Hi All, I am new here. We have configured filebeat to logstash via SSL in our test environment. In our production environment, we are planning for an architecture similar to below: Filebeat \> Secure Apache based revers…

---

## [ELK integration with vcenter](https://discuss.elastic.co/t/elk-integration-with-vcenter/199839)

<div class="topic-metadata">

**Author:** [@lvendluru](https://discuss.elastic.co/u/lvendluru)\
**Replies:** 0\
**Last updated:** [September 17, 2019, 2:22pm UTC](https://discuss.elastic.co/t/elk-integration-with-vcenter/199839 "2019-09-17T14:22:28Z")

</div>

Hi , can you please suggest best method , how to integrate vcenter with ELK.? i tried using metric-beats by enabling module "vsphere"...But, i am not able to get relevant data from vcenter. PFB config file which i was…

---

## [File beats is not sending logs to elastic search](https://discuss.elastic.co/t/file-beats-is-not-sending-logs-to-elastic-search/196524)

<div class="topic-metadata">

**Author:** [@Seetharaman\_K](https://discuss.elastic.co/u/Seetharaman_K)\
**Replies:** 2\
**Last updated:** [September 17, 2019, 12:55pm UTC](https://discuss.elastic.co/t/file-beats-is-not-sending-logs-to-elastic-search/196524 "2019-09-17T12:55:54Z")

</div>

Hi , i have installed file beats in my system. https://justpaste.it/3dvoz --\> configration . this is supposed to send logs to elastic search . but its not doing. elastic instance is up and running fine and even receiv…

---

## [Filebeat processor add\_kubernetes\_metadata is not working with input type log](https://discuss.elastic.co/t/filebeat-processor-add-kubernetes-metadata-is-not-working-with-input-type-log/199588)

<div class="topic-metadata">

**Author:** [@Himanshu\_Rajput](https://discuss.elastic.co/u/Himanshu_Rajput)\
**Replies:** 2\
**Last updated:** [September 17, 2019, 11:44am UTC](https://discuss.elastic.co/t/filebeat-processor-add-kubernetes-metadata-is-not-working-with-input-type-log/199588 "2019-09-17T11:44:03Z")

</div>

We are using filebeat v 7.3 over Kubernetes. Along with pod's logs, we also want to push host logs to elasticsearch. We have mounted "/var/log/messages" of host towards the filebeat pod. The logs are successfully being p…

---

## [Parent process sometimes missing](https://discuss.elastic.co/t/parent-process-sometimes-missing/199652)

<div class="topic-metadata">

**Author:** [@vaclav](https://discuss.elastic.co/u/vaclav)\
**Replies:** 1\
**Last updated:** [September 17, 2019, 11:08am UTC](https://discuss.elastic.co/t/parent-process-sometimes-missing/199652 "2019-09-17T11:08:41Z")

</div>

Hello, I am using this processor to get information about process parent: add\_process\_metadata: match\_pids: \[ process.ppid \] target: process.parent but sometimes is parent process missing in auditbeat messages I f…

---

## [Auditbeat and events from secure log](https://discuss.elastic.co/t/auditbeat-and-events-from-secure-log/199670)

<div class="topic-metadata">

**Author:** [@sruthycs](https://discuss.elastic.co/u/sruthycs)\
**Replies:** 4\
**Last updated:** [September 17, 2019, 10:53am UTC](https://discuss.elastic.co/t/auditbeat-and-events-from-secure-log/199670 "2019-09-17T10:53:08Z")

</div>

I have configured auditbeat as below: ########################## Auditbeat Configuration ############################# #================================ General ====================================== queue: # Queue…

---

## [Autodiscover Kubernetes + annotations on pods not working as excepted](https://discuss.elastic.co/t/autodiscover-kubernetes-annotations-on-pods-not-working-as-excepted/199743)

<div class="topic-metadata">

**Author:** [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Replies:** 1\
**Last updated:** [September 17, 2019, 8:08am UTC](https://discuss.elastic.co/t/autodiscover-kubernetes-annotations-on-pods-not-working-as-excepted/199743 "2019-09-17T08:08:02Z")

</div>

I am trying to make filebeat work with the official elastic helm chart. I would like to parse only the pods that have the "logging" : "json\_log" annotation. As soon as i deploy pods that have that annotation for some re…

---

## [JMX error fetching data](https://discuss.elastic.co/t/jmx-error-fetching-data/197486)

<div class="topic-metadata">

**Author:** [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Replies:** 1\
**Last updated:** [September 17, 2019, 5:32am UTC](https://discuss.elastic.co/t/jmx-error-fetching-data/197486 "2019-09-17T05:32:15Z")

</div>

I'm trying to send JMX data using a Dockerized Metricbeat to the cloud, but I get the following error: 2019-08-30T09:30:45.033Z INFO module/wrapper.go:247 Error fetching data for metricset jolokia.jmx: error making http…

---

## [Predefining arbitrary CloudFormation resource names](https://discuss.elastic.co/t/predefining-arbitrary-cloudformation-resource-names/199707)

<div class="topic-metadata">

**Author:** [@t3di](https://discuss.elastic.co/u/t3di)\
**Replies:** 0\
**Last updated:** [September 16, 2019, 5:39pm UTC](https://discuss.elastic.co/t/predefining-arbitrary-cloudformation-resource-names/199707 "2019-09-16T17:39:53Z")

</div>

is it possible to get rid of fnb- prefixes for aws deployment, by predefining them in functionbeat.yml ? I m concerned with these 3: AWS::IAM::Role AWS::Logs::LogGroup AWS::CloudFormation::Stack cheers!

---

## [I couldn't enter custome id for heartbeat services](https://discuss.elastic.co/t/i-couldnt-enter-custome-id-for-heartbeat-services/199214)

<div class="topic-metadata">

**Author:** [@Hamed\_khosravi](https://discuss.elastic.co/u/Hamed_khosravi)\
**Replies:** 1\
**Last updated:** [September 16, 2019, 2:43pm UTC](https://discuss.elastic.co/t/i-couldnt-enter-custome-id-for-heartbeat-services/199214 "2019-09-16T14:43:12Z")

</div>

when I configured heartbeat for myserrvices, i wasn't able to enter custom id for that, and in kibana in Uptime section is sowing " \[auto-http-0X63FF1979E2D8AEA9\] for ID, is the way can i configure a nice ID for that? i'…

---

## [Autodiscover name](https://discuss.elastic.co/t/autodiscover-name/198582)

<div class="topic-metadata">

**Author:** [@cdalexndr](https://discuss.elastic.co/u/cdalexndr)\
**Replies:** 2\
**Last updated:** [September 16, 2019, 2:42pm UTC](https://discuss.elastic.co/t/autodiscover-name/198582 "2019-09-16T14:42:15Z")

</div>

Currently, using the autodiscover feature, in kibana heartbeat dashboard all services have name "Unnamed-auto-tcp...". How to provide a name using some docker label? Tried using the following configuration with no resu…

---

## [How to change beat output timestamp include timezone info](https://discuss.elastic.co/t/how-to-change-beat-output-timestamp-include-timezone-info/199645)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 3\
**Last updated:** [September 16, 2019, 2:20pm UTC](https://discuss.elastic.co/t/how-to-change-beat-output-timestamp-include-timezone-info/199645 "2019-09-16T14:20:02Z")

</div>

I think by default beat timestamp output is UTC time. Is there a way to change time to local time in all the beats ? I tried add\_locale, but it didn't work

---

## [Cannot see ECS fields from Filebeat 7.3.2 -\> Logstash 6.8](https://discuss.elastic.co/t/cannot-see-ecs-fields-from-filebeat-7-3-2-logstash-6-8/199643)

<div class="topic-metadata">

**Author:** [@999chris](https://discuss.elastic.co/u/999chris)\
**Replies:** 0\
**Last updated:** [September 16, 2019, 11:15am UTC](https://discuss.elastic.co/t/cannot-see-ecs-fields-from-filebeat-7-3-2-logstash-6-8/199643 "2019-09-16T11:15:31Z")

</div>

I'd like to get the ctime and mtime fields from my log file and have them parsed later in Logstash, but I dont see them. https://www.elastic.co/guide/en/beats/filebeat/7.3/exported-fields-ecs.html Is there a parameter …

---

## [Multiline Pattern - Filebeat](https://discuss.elastic.co/t/multiline-pattern-filebeat/199409)

<div class="topic-metadata">

**Author:** [@gerard.ramos](https://discuss.elastic.co/u/gerard.ramos)\
**Replies:** 9\
**Last updated:** [September 16, 2019, 11:05am UTC](https://discuss.elastic.co/t/multiline-pattern-filebeat/199409 "2019-09-16T11:05:52Z")

</div>

Hello, I am having problems making a multiline match. The logs come from a file saved on the client machine. I send to the logstash server with filebeat. In the filebeat configuration I have the following: multiline.pat…

---

## [When send logs with filebeat input with pipeline, only sent logs to one partiton of kafka](https://discuss.elastic.co/t/when-send-logs-with-filebeat-input-with-pipeline-only-sent-logs-to-one-partiton-of-kafka/199635)

<div class="topic-metadata">

**Author:** [@Jinyoung\_Yeom](https://discuss.elastic.co/u/Jinyoung_Yeom)\
**Replies:** 0\
**Last updated:** [September 16, 2019, 10:44am UTC](https://discuss.elastic.co/t/when-send-logs-with-filebeat-input-with-pipeline-only-sent-logs-to-one-partiton-of-kafka/199635 "2019-09-16T10:44:39Z")

</div>

I set logging system with filebeat, kafka and elasticsearch Configs : filebeat #================================ General ===================================== fields: log\_kafka\_topic: es-log-stream #================…

---

## [Filebeat Install Documentation Not Clear](https://discuss.elastic.co/t/filebeat-install-documentation-not-clear/199358)

<div class="topic-metadata">

**Author:** [@StevenO](https://discuss.elastic.co/u/StevenO)\
**Replies:** 1\
**Last updated:** [September 16, 2019, 8:58am UTC](https://discuss.elastic.co/t/filebeat-install-documentation-not-clear/199358 "2019-09-16T08:58:30Z")

</div>

Guys I hope to increase the installs and usage of Filebeat by 100 fold on Mac if you will listen. Apt is often not available on Mac. 90% of us WILL use brew to install Filebeat. When we install Filebeat using brew we r…

---

## [Reset Filebeat harversters](https://discuss.elastic.co/t/reset-filebeat-harversters/198848)

<div class="topic-metadata">

**Author:** [@tunigas](https://discuss.elastic.co/u/tunigas)\
**Replies:** 2\
**Last updated:** [September 11, 2019, 5:47pm UTC](https://discuss.elastic.co/t/reset-filebeat-harversters/198848 "2019-09-11T17:47:30Z")

</div>

Hello, After a lot of testing with logstash and filebeat, I need to reset filebeat to be able to ship all the log data again in a clean way. First, I deleted all the data from elasticsearch. Then, I went to /var/lib/fi…

---

## [This Forum is NOT responsive enough](https://discuss.elastic.co/t/this-forum-is-not-responsive-enough/199565)

<div class="topic-metadata">

**Author:** [@StevenO](https://discuss.elastic.co/u/StevenO)\
**Replies:** 5\
**Last updated:** [September 16, 2019, 6:57am UTC](https://discuss.elastic.co/t/this-forum-is-not-responsive-enough/199565 "2019-09-16T06:57:29Z")

</div>

I have pointed out several days ago an issue with documentation about filebeat. Now I have yet another issue.https://discuss.elastic.co/t/filebeat-install-documentation-not-clear/199358 with Mac install. Its not connect…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=315)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=317)
