# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=317

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 318

---

## [Filebeat reads file too fast](https://discuss.elastic.co/t/filebeat-reads-file-too-fast/199574)

<div class="topic-metadata">

**Author:** [@msk\_76](https://discuss.elastic.co/u/msk_76)\
**Replies:** 0\
**Last updated:** [September 16, 2019, 5:21am UTC](https://discuss.elastic.co/t/filebeat-reads-file-too-fast/199574 "2019-09-16T05:21:30Z")

</div>

I have a problem with filebeat that it reads the file while the file is being overwritten by another process. This problem result in loading/reading some junk entries by Filebeat. My current configuration is : filebeat…

---

## [Enrich application log massage](https://discuss.elastic.co/t/enrich-application-log-massage/199513)

<div class="topic-metadata">

**Author:** [@sparmar](https://discuss.elastic.co/u/sparmar)\
**Replies:** 6\
**Last updated:** [September 16, 2019, 4:43am UTC](https://discuss.elastic.co/t/enrich-application-log-massage/199513 "2019-09-16T04:43:54Z")

</div>

I have a java application that is writing out message as follows for example: 00:00:13,950 INFO \[com.companyurl.application\] (bq-thread-pool-threads - 881) ABC response by ApplicationManager - received \<?xml version="1…

---

## [Filebeat multiline not working with autodiscover](https://discuss.elastic.co/t/filebeat-multiline-not-working-with-autodiscover/198103)

<div class="topic-metadata">

**Author:** [@zaratustra689](https://discuss.elastic.co/u/zaratustra689)\
**Replies:** 7\
**Last updated:** [September 16, 2019, 3:45am UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working-with-autodiscover/198103 "2019-09-16T03:45:13Z")

</div>

Hello, I have the following configuration in filebeat.yml and the multiline feature is NOT working as expected. I have read previous posts with this issue, but the difference is that i'm NOT using prospectors or inputs.…

---

## [Need advice: ensure filebeat streaming is working across multiple hosts](https://discuss.elastic.co/t/need-advice-ensure-filebeat-streaming-is-working-across-multiple-hosts/199533)

<div class="topic-metadata">

**Author:** [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Replies:** 0\
**Last updated:** [September 15, 2019, 12:30pm UTC](https://discuss.elastic.co/t/need-advice-ensure-filebeat-streaming-is-working-across-multiple-hosts/199533 "2019-09-15T12:30:08Z")

</div>

Hello, My project has multiple hosts, each streaming different files to different locations. I am looking for a way to get notified if any of the streams stops for any reason. I'd appreciate any ideas on how to achieve…

---

## [Swap files are created on auditbeat FIM](https://discuss.elastic.co/t/swap-files-are-created-on-auditbeat-fim/199242)

<div class="topic-metadata">

**Author:** [@zeno](https://discuss.elastic.co/u/zeno)\
**Replies:** 2\
**Last updated:** [September 14, 2019, 9:57pm UTC](https://discuss.elastic.co/t/swap-files-are-created-on-auditbeat-fim/199242 "2019-09-14T21:57:48Z")

</div>

I have created this topic on swap files creation but not getting the response on this. all the questions and answers are on this link attached below. Please check & respond Looking Forward

---

## [Filebeat as a log parser for random text log](https://discuss.elastic.co/t/filebeat-as-a-log-parser-for-random-text-log/199255)

<div class="topic-metadata">

**Author:** [@csrohit](https://discuss.elastic.co/u/csrohit)\
**Replies:** 1\
**Last updated:** [September 14, 2019, 10:27am UTC](https://discuss.elastic.co/t/filebeat-as-a-log-parser-for-random-text-log/199255 "2019-09-14T10:27:38Z")

</div>

Hi Guys, My application generates txt file logs. I am thinking of parsing them in Filebeat, sending them to Elasticsearch and analyzing using Kibana. I am quite sure that should be possible but I am not sure and also …

---

## [How to check Filebeat is running properly](https://discuss.elastic.co/t/how-to-check-filebeat-is-running-properly/199024)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 3\
**Last updated:** [September 13, 2019, 9:22pm UTC](https://discuss.elastic.co/t/how-to-check-filebeat-is-running-properly/199024 "2019-09-13T21:22:22Z")

</div>

Hi I notice that after I ran the service for logstash the run time will restart some times after a few second. And there are no logs recorded on the /var/log/logstash. If is properly running, will it produce log files a…

---

## [Rename json array field names](https://discuss.elastic.co/t/rename-json-array-field-names/197903)

<div class="topic-metadata">

**Author:** [@vinshas1](https://discuss.elastic.co/u/vinshas1)\
**Replies:** 2\
**Last updated:** [September 10, 2019, 4:51pm UTC](https://discuss.elastic.co/t/rename-json-array-field-names/197903 "2019-09-10T16:51:42Z")

</div>

{ "Network IP Gateway": "165.10.2.3", "network details": \[ { "Adapter Name": "Intel(R) Network Connection", "Manufacturer": "Intel Corporation", "Adapter Type": "Ethernet 802.3", "MAC Address": "00:50:56:A3:2F:36…

---

## [How to increase filebeat speed](https://discuss.elastic.co/t/how-to-increase-filebeat-speed/199254)

<div class="topic-metadata">

**Author:** [@kmacew](https://discuss.elastic.co/u/kmacew)\
**Replies:** 3\
**Last updated:** [September 13, 2019, 7:06pm UTC](https://discuss.elastic.co/t/how-to-increase-filebeat-speed/199254 "2019-09-13T19:06:05Z")

</div>

Dear elastic team, In my environment i got around 6-7 applications. These applications logs around 30-40 lines per second, it's few GB per day. Filebeat can't keep up with parsing logs to send them to elasticsearch (via…

---

## [Connect FileBeat to Logstash and ES](https://discuss.elastic.co/t/connect-filebeat-to-logstash-and-es/199091)

<div class="topic-metadata">

**Author:** [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Replies:** 5\
**Last updated:** [September 13, 2019, 5:59pm UTC](https://discuss.elastic.co/t/connect-filebeat-to-logstash-and-es/199091 "2019-09-13T17:59:40Z")

</div>

Hello everyone, So i have filebeat configured in an apache server AWS EC2 instance and another EC2 instance which has logstash and elasticsearch. i can send log files to the ec2 instance to logstash but i can only displ…

---

## [Logstash output amazon es plugin version support](https://discuss.elastic.co/t/logstash-output-amazon-es-plugin-version-support/199463)

<div class="topic-metadata">

**Author:** [@Brian\_DiCola](https://discuss.elastic.co/u/Brian_DiCola)\
**Replies:** 0\
**Last updated:** [September 13, 2019, 5:07pm UTC](https://discuss.elastic.co/t/logstash-output-amazon-es-plugin-version-support/199463 "2019-09-13T17:07:31Z")

</div>

I see that filebeat 6.4 does not support adding tags and fields. I believe I am limited to 6.4 because the plugin logstash-output-amazon\_es is only up to version 6. So my stack is: filebeat 6.4.3 logstash 1:6.4.3-1 …

---

## [Offline monitoring or Spooling into a disk](https://discuss.elastic.co/t/offline-monitoring-or-spooling-into-a-disk/199110)

<div class="topic-metadata">

**Author:** [@RayKishev](https://discuss.elastic.co/u/RayKishev)\
**Replies:** 9\
**Last updated:** [September 13, 2019, 4:05pm UTC](https://discuss.elastic.co/t/offline-monitoring-or-spooling-into-a-disk/199110 "2019-09-13T16:05:47Z")

</div>

Hello Elastic team, I really need your help on this. I am trying to setup the internal Queue, so when my system is offline for some time and after connecting it back to the network, i could still receive a metricbeat da…

---

## [Configure TCP input via Central Management](https://discuss.elastic.co/t/configure-tcp-input-via-central-management/186152)

<div class="topic-metadata">

**Author:** [@jderose](https://discuss.elastic.co/u/jderose)\
**Replies:** 4\
**Last updated:** [September 13, 2019, 2:49pm UTC](https://discuss.elastic.co/t/configure-tcp-input-via-central-management/186152 "2019-09-13T14:49:07Z")

</div>

I can setup an input in Filebeat as a TCP listener in the config file, but when I enroll it with Beats Central Management, my configuration is erased in favor of the UI configuration. However, I can't see any way to conf…

---

## [Filebeat error setting up modules on windows](https://discuss.elastic.co/t/filebeat-error-setting-up-modules-on-windows/199154)

<div class="topic-metadata">

**Author:** [@Marcell0e](https://discuss.elastic.co/u/Marcell0e)\
**Replies:** 1\
**Last updated:** [September 13, 2019, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-error-setting-up-modules-on-windows/199154 "2019-09-13T14:06:50Z")

</div>

I am getting the following error setting up filebeat on windows. I am trying to setup the following modules (elasticsearch, kibana, logstash, system). I have followed the instructions, but I think I am missing somethin…

---

## [How fix “Failed to import index-pattern”](https://discuss.elastic.co/t/how-fix-failed-to-import-index-pattern/199020)

<div class="topic-metadata">

**Author:** [@111209](https://discuss.elastic.co/u/111209)\
**Replies:** 7\
**Last updated:** [September 13, 2019, 12:50pm UTC](https://discuss.elastic.co/t/how-fix-failed-to-import-index-pattern/199020 "2019-09-13T12:50:25Z")

</div>

When i\`m try setup metricbeat dashboard i get error. i run this command: // metricbeat setup --dashboards and got this error: metricbeat setup --dashboards Loading dashboards (Kibana must be running and reachable) Ex…

---

## [Provided Grok expressions do not match field value when using postgres log](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-when-using-postgres-log/199404)

<div class="topic-metadata">

**Author:** [@oobi89](https://discuss.elastic.co/u/oobi89)\
**Replies:** 0\
**Last updated:** [September 13, 2019, 9:50am UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-when-using-postgres-log/199404 "2019-09-13T09:50:47Z")

</div>

Hello, I've configured Filebeats to get logs from postgres, send it to elasticsearch and then display them in kibana. Logs are send successfully to Elasticsearch, when I go to Kibana\>Discovery I receive error: # \[Inde…

---

## [Index alias is broken every night by auto(bulk api)](https://discuss.elastic.co/t/index-alias-is-broken-every-night-by-auto-bulk-api/199185)

<div class="topic-metadata">

**Author:** [@Jesus\_Munoz](https://discuss.elastic.co/u/Jesus_Munoz)\
**Replies:** 2\
**Last updated:** [September 13, 2019, 6:43am UTC](https://discuss.elastic.co/t/index-alias-is-broken-every-night-by-auto-bulk-api/199185 "2019-09-13T06:43:09Z")

</div>

I use heartbeat 7.3.0 to send data to a 7.3.0 ES hosted in elastic cloud. I have one docker heartbeat deployed in EKS 1.13, with default values. Everything runs fine until every night at 1:00AM UTC, in which auto(bulk …

---

## [Private ip map from dictionary used in processor-dns](https://discuss.elastic.co/t/private-ip-map-from-dictionary-used-in-processor-dns/199342)

<div class="topic-metadata">

**Author:** [@ppafford](https://discuss.elastic.co/u/ppafford)\
**Replies:** 0\
**Last updated:** [September 13, 2019, 2:30am UTC](https://discuss.elastic.co/t/private-ip-map-from-dictionary-used-in-processor-dns/199342 "2019-09-13T02:30:08Z")

</div>

the two links above are what I'd like to combine and basically take LogStash out of my pipeline, just have filebeat custom defined processor for dns use the dictionary instead of the name-servers. is this possible ye…

---

## [Squid proxy module for file beat](https://discuss.elastic.co/t/squid-proxy-module-for-file-beat/199327)

<div class="topic-metadata">

**Author:** [@sk545](https://discuss.elastic.co/u/sk545)\
**Replies:** 0\
**Last updated:** [September 12, 2019, 9:48pm UTC](https://discuss.elastic.co/t/squid-proxy-module-for-file-beat/199327 "2019-09-12T21:48:48Z")

</div>

Hello everyone, data flow: Squid+file beat --\>logstash --\>Elastic search --\>Kibana I have set up connection to ship Squid proxy logs through file beat , i can able to see logs and some default fields in Kibana but th…

---

## [Module doesn't exist (but it does)](https://discuss.elastic.co/t/module-doesnt-exist-but-it-does/199116)

<div class="topic-metadata">

**Author:** [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Replies:** 3\
**Last updated:** [September 12, 2019, 7:14pm UTC](https://discuss.elastic.co/t/module-doesnt-exist-but-it-does/199116 "2019-09-12T19:14:21Z")

</div>

Hi, While trying to configure filebeat modules, I keep getting "module doesn't exist". It doesn't matter which module I try. Also the "filebeat modules list" command doesn't any modules. The service does run without …

---

## [I can't redirect output to a custom index](https://discuss.elastic.co/t/i-cant-redirect-output-to-a-custom-index/199153)

<div class="topic-metadata">

**Author:** [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Replies:** 3\
**Last updated:** [September 12, 2019, 6:22pm UTC](https://discuss.elastic.co/t/i-cant-redirect-output-to-a-custom-index/199153 "2019-09-12T18:22:01Z")

</div>

I can't redirect output to a custom index from a filebeat. It constantly loads the default filebeat template 7.3.1. Any idea where should I look? Logs are getting send to the filebeat-\* index. #==================== Elas…

---

## [Filebeat panic and exit?](https://discuss.elastic.co/t/filebeat-panic-and-exit/197578)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 7\
**Last updated:** [September 12, 2019, 4:59pm UTC](https://discuss.elastic.co/t/filebeat-panic-and-exit/197578 "2019-09-12T16:59:36Z")

</div>

Hello, I got the following from stderr while running filebeat, and filebeat just exited. any idea on why filebeat just dies? thanks! yan goroutine 74 \[select, 1 minutes\]: github.com/elastic/beats/filebeat/channel.(\*…

---

## [Timestamp conversion pattern on ingest\_node](https://discuss.elastic.co/t/timestamp-conversion-pattern-on-ingest-node/199231)

<div class="topic-metadata">

**Author:** [@AndresL](https://discuss.elastic.co/u/AndresL)\
**Replies:** 1\
**Last updated:** [September 12, 2019, 2:14pm UTC](https://discuss.elastic.co/t/timestamp-conversion-pattern-on-ingest-node/199231 "2019-09-12T14:14:22Z")

</div>

Hi, In an ingest node pipeline, im converting the log event into a timestamp. The log event is in this format: 2019-09-11 10:12:11,145 and the conversion via ingest\_node is removing the TIME: 2019-09-11T00:00:00.000Z …

---

## [Error in initing input: No paths were defined for input accessing 'filebeat.inputs.0'](https://discuss.elastic.co/t/error-in-initing-input-no-paths-were-defined-for-input-accessing-filebeat-inputs-0/199260)

<div class="topic-metadata">

**Author:** [@Naga\_Kodali](https://discuss.elastic.co/u/Naga_Kodali)\
**Replies:** 0\
**Last updated:** [September 12, 2019, 1:37pm UTC](https://discuss.elastic.co/t/error-in-initing-input-no-paths-were-defined-for-input-accessing-filebeat-inputs-0/199260 "2019-09-12T13:37:53Z")

</div>

I am trying to ship my server logs via filebeat v 6.8.3 and the ELK stack version is 6.6 .. I am facing difficulty in validating the config file. Below is my config file filebeat.inputs: type: log enabled: true path…

---

## [Issue in Creat Index Pattren in Kibana 7.3 "Error:: Forbidden"](https://discuss.elastic.co/t/issue-in-creat-index-pattren-in-kibana-7-3-error-forbidden/197496)

<div class="topic-metadata">

**Author:** [@SachinRaj](https://discuss.elastic.co/u/SachinRaj)\
**Replies:** 2\
**Last updated:** [September 12, 2019, 1:12pm UTC](https://discuss.elastic.co/t/issue-in-creat-index-pattren-in-kibana-7-3-error-forbidden/197496 "2019-09-12T13:12:44Z")

</div>

Hi, concept i am trying :: Filebeat--\> ELasticsearch--\> Kibana all 3 are running fine in console no error but in kibana while creating the index i am facing "Error:: Forbidden" server :: redhat 7.6 installation :: t…

---

## [Metricbeat Failed to parse JSON response: invalid character '\<' looking for beginning of value error](https://discuss.elastic.co/t/metricbeat-failed-to-parse-json-response-invalid-character-looking-for-beginning-of-value-error/199248)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [September 12, 2019, 12:23pm UTC](https://discuss.elastic.co/t/metricbeat-failed-to-parse-json-response-invalid-character-looking-for-beginning-of-value-error/199248 "2019-09-12T12:23:23Z")

</div>

ECE 2.3 Metricbeat-oss-7.0 Started getting a "Failed to parse JSON response: invalid character '\<' looking for beginning of value" error in the metricbeat logs when sending data to a regular Elastic cluster and an ECE …

---

## [Beats apache module. Multiline to join PHP Stack trace](https://discuss.elastic.co/t/beats-apache-module-multiline-to-join-php-stack-trace/199190)

<div class="topic-metadata">

**Author:** [@Martin\_Ostlund](https://discuss.elastic.co/u/Martin_Ostlund)\
**Replies:** 0\
**Last updated:** [September 12, 2019, 7:46am UTC](https://discuss.elastic.co/t/beats-apache-module-multiline-to-join-php-stack-trace/199190 "2019-09-12T07:46:49Z")

</div>

Filebeat version: 7.3.1 OS: Ubuntu 18.04 LTS Filebeat module: Apache Filebeat Output: Elastichost:9200 Problem description: Our Apache error log contains PHP Stacktraces that spans many lines. Question 1: Is it poss…

---

## [Create custom filebeat module issue](https://discuss.elastic.co/t/create-custom-filebeat-module-issue/198912)

<div class="topic-metadata">

**Author:** [@Marek\_Siwiec](https://discuss.elastic.co/u/Marek_Siwiec)\
**Replies:** 2\
**Last updated:** [September 12, 2019, 7:39am UTC](https://discuss.elastic.co/t/create-custom-filebeat-module-issue/198912 "2019-09-12T07:39:15Z")

</div>

Hi I have problem with creating custom module, when I try to create module by comman make create-module MODULE=nameofModule, then I got Unknown targets specified: create-module, MODULE=name. I folllowing by instruction…

---

## [Filebeat-processor-parse data- save in another column](https://discuss.elastic.co/t/filebeat-processor-parse-data-save-in-another-column/199184)

<div class="topic-metadata">

**Author:** [@abhishek\_kumar3](https://discuss.elastic.co/u/abhishek_kumar3)\
**Replies:** 0\
**Last updated:** [September 12, 2019, 6:55am UTC](https://discuss.elastic.co/t/filebeat-processor-parse-data-save-in-another-column/199184 "2019-09-12T06:55:17Z")

</div>

Hi, I have tried all the processors but I am unable to get my use case which is as below: -\>write a PROCESSOR and filter the message field with a regular expression and store it in another "target".

---

## [Unable to read modules. Modules is looking at different path](https://discuss.elastic.co/t/unable-to-read-modules-modules-is-looking-at-different-path/198118)

<div class="topic-metadata">

**Author:** [@Srisamardh](https://discuss.elastic.co/u/Srisamardh)\
**Replies:** 2\
**Last updated:** [September 12, 2019, 3:21am UTC](https://discuss.elastic.co/t/unable-to-read-modules-modules-is-looking-at-different-path/198118 "2019-09-12T03:21:23Z")

</div>

I am new to filebeat. I am trying to setup the apache module using kubernetes to get the logs from container. I am seeing the following error: "ERROR fileset/modules.go:125 Not loading modules. Module directory not fou…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=316)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=318)
