# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=318

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 319

---

## [Load balancing filebeat](https://discuss.elastic.co/t/load-balancing-filebeat/198963)

<div class="topic-metadata">

**Author:** [@an0nemus](https://discuss.elastic.co/u/an0nemus)\
**Replies:** 2\
**Last updated:** [September 11, 2019, 10:03pm UTC](https://discuss.elastic.co/t/load-balancing-filebeat/198963 "2019-09-11T22:03:06Z")

</div>

I'm trying to set up filebeat sending to mulitple logstash hosts: filebeat version 6.4.0 (amd64), libbeat 6.4.0 \[34b4e2cc75fbbee5e7149f3916de72fb8892d070 built 2018-08-17 22:19:27 +0000 UTC\] OS: windows 2016 I have a…

---

## [Unable to create package for new beat based on metribeat](https://discuss.elastic.co/t/unable-to-create-package-for-new-beat-based-on-metribeat/198688)

<div class="topic-metadata">

**Author:** [@kenrowland](https://discuss.elastic.co/u/kenrowland)\
**Replies:** 11\
**Last updated:** [September 11, 2019, 8:51pm UTC](https://discuss.elastic.co/t/unable-to-create-package-for-new-beat-based-on-metribeat/198688 "2019-09-11T20:51:26Z")

</div>

Hello, I am trying to create a new beat based on metricbeat. I have followed the instructions and am able to build and debug my new beat. All works as expected. However, when I try to create a package using "make pack…

---

## [Memory usage is at extreme high level](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 9\
**Last updated:** [September 11, 2019, 8:25pm UTC](https://discuss.elastic.co/t/memory-usage-is-at-extreme-high-level/198085 "2019-09-11T20:25:13Z")

</div>

Hello World! Memory usage seems a bit excessive for metricbeat, is it not? I # systemctl status metricbeat.service ● metricbeat.service - Metricbeat is a lightweight shipper for metrics. Loaded: loaded (/lib/system…

---

## [System Module for Auditbeat-oss](https://discuss.elastic.co/t/system-module-for-auditbeat-oss/198971)

<div class="topic-metadata">

**Author:** [@jvicente](https://discuss.elastic.co/u/jvicente)\
**Replies:** 1\
**Last updated:** [September 11, 2019, 7:56pm UTC](https://discuss.elastic.co/t/system-module-for-auditbeat-oss/198971 "2019-09-11T19:56:22Z")

</div>

I am trying to get system login logs to an AWS Elastic Search run on a VPC. However when I tried using the regular Auditbeat docker it gave xpack issues. After searching online, it was suggested that I use the oss versio…

---

## [Metricbeat OSS connects for Windows servers not for Linux](https://discuss.elastic.co/t/metricbeat-oss-connects-for-windows-servers-not-for-linux/198946)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 3\
**Last updated:** [September 11, 2019, 5:17pm UTC](https://discuss.elastic.co/t/metricbeat-oss-connects-for-windows-servers-not-for-linux/198946 "2019-09-11T17:17:43Z")

</div>

ECE 2.3 Deployment - Elastic 7.2 & Kibana 7.2 Metricbeat-OSS-7.0.0 I'm running into an issue with metricbeat-oss-7.0.0 where beats that are installed on our Windows servers report to both an Elastic-oss version as wel…

---

## [What happens if output (redis, kafka, logstash, ...) is not available?](https://discuss.elastic.co/t/what-happens-if-output-redis-kafka-logstash-is-not-available/198716)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 3\
**Last updated:** [September 11, 2019, 3:27pm UTC](https://discuss.elastic.co/t/what-happens-if-output-redis-kafka-logstash-is-not-available/198716 "2019-09-11T15:27:34Z")

</div>

Hi, currently I am using metricbeat with file output. Then filebeat is fetching the log and delivering to redis. I know that metricbeat has redis output capability like filebeat. So I would like to understand what hap…

---

## [Packetbeat.service stop-sigterm timed out. Killing](https://discuss.elastic.co/t/packetbeat-service-stop-sigterm-timed-out-killing/199084)

<div class="topic-metadata">

**Author:** [@Ihjaz](https://discuss.elastic.co/u/Ihjaz)\
**Replies:** 0\
**Last updated:** [September 11, 2019, 1:53pm UTC](https://discuss.elastic.co/t/packetbeat-service-stop-sigterm-timed-out-killing/199084 "2019-09-11T13:53:20Z")

</div>

Hi, I'm using packetbeat v6.2.2 and at times I see packetbeat service not getting stopped when the stop command is run. Nov 15 15:18:49 systemd\[1\]: Stopping packetbeat... Nov 15 15:20:19 systemd\[1\]: packetbeat.service …

---

## [Filebeat on central Syslog Server for loadbalancing](https://discuss.elastic.co/t/filebeat-on-central-syslog-server-for-loadbalancing/199054)

<div class="topic-metadata">

**Author:** [@Mugen](https://discuss.elastic.co/u/Mugen)\
**Replies:** 4\
**Last updated:** [September 11, 2019, 12:38pm UTC](https://discuss.elastic.co/t/filebeat-on-central-syslog-server-for-loadbalancing/199054 "2019-09-11T12:38:22Z")

</div>

I'm planning to get rid of our kafka messaging queue since we just set it up it because it was part of a hdfs, wich will be removed. I now want to scale up from one to two logstash with persisted queue and setup load ba…

---

## [Install Metricbeat](https://discuss.elastic.co/t/install-metricbeat/196502)

<div class="topic-metadata">

**Author:** [@cristianaxion](https://discuss.elastic.co/u/cristianaxion)\
**Replies:** 3\
**Last updated:** [September 11, 2019, 11:48am UTC](https://discuss.elastic.co/t/install-metricbeat/196502 "2019-09-11T11:48:32Z")

</div>

Hello, when I try to install Metricbeat I get an error in the curl request What can be?

---

## [Packetbeat \>= 7.0.0: Root mapping definition has unsupported parameters](https://discuss.elastic.co/t/packetbeat-7-0-0-root-mapping-definition-has-unsupported-parameters/199053)

<div class="topic-metadata">

**Author:** [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Replies:** 0\
**Last updated:** [September 11, 2019, 9:36am UTC](https://discuss.elastic.co/t/packetbeat-7-0-0-root-mapping-definition-has-unsupported-parameters/199053 "2019-09-11T09:36:48Z")

</div>

Hi, packetbeat in version \>= 7.0.0 gives: \[2019-09-11T11:28:41,165\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"packetbeat-2019…

---

## [Error Filebeats in kubernetes](https://discuss.elastic.co/t/error-filebeats-in-kubernetes/198853)

<div class="topic-metadata">

**Author:** [@florenzo](https://discuss.elastic.co/u/florenzo)\
**Replies:** 1\
**Last updated:** [September 11, 2019, 6:37am UTC](https://discuss.elastic.co/t/error-filebeats-in-kubernetes/198853 "2019-09-11T06:37:44Z")

</div>

im trying to install filebat over kubernetes in a Openshift environment . the idea is use it instead openshift fluentd my environment is Openshift 3.6 with kubernetes 1.6 . ok i followed this guide https://www.elastic.…

---

## [Specifying Multiple Success Status Codes for Heartbeat Monitor](https://discuss.elastic.co/t/specifying-multiple-success-status-codes-for-heartbeat-monitor/198074)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 11\
**Last updated:** [September 11, 2019, 3:12am UTC](https://discuss.elastic.co/t/specifying-multiple-success-status-codes-for-heartbeat-monitor/198074 "2019-09-11T03:12:16Z")

</div>

TL;DR How do I specify multiple success response codes for an Elastic Heartbeat monitor? Details We have an application for which http.response.code: 200 and http.response.code: 403 are both considered successful. Howe…

---

## [Throughput priority / balance / QoS behaviour of multiple inputs](https://discuss.elastic.co/t/throughput-priority-balance-qos-behaviour-of-multiple-inputs/198990)

<div class="topic-metadata">

**Author:** [@gwilym](https://discuss.elastic.co/u/gwilym)\
**Replies:** 0\
**Last updated:** [September 11, 2019, 12:42am UTC](https://discuss.elastic.co/t/throughput-priority-balance-qos-behaviour-of-multiple-inputs/198990 "2019-09-11T00:42:26Z")

</div>

I'm trying to get an understanding for how Filebeat treats multiple inputs with dissimilar volumes. For example: if I am using Filebeat to transport logs from two files—one high volume and one low volume—will the inputs…

---

## [His Beat requires the default distribution of Elasticsearch. Please install the default distribution of Elasticsearch from elastic.co, or install the oss-only distribution of beats\]](https://discuss.elastic.co/t/his-beat-requires-the-default-distribution-of-elasticsearch-please-install-the-default-distribution-of-elasticsearch-from-elastic-co-or-install-the-oss-only-distribution-of-beats/196614)

<div class="topic-metadata">

**Author:** [@Arman\_Ajdani](https://discuss.elastic.co/u/Arman_Ajdani)\
**Replies:** 2\
**Last updated:** [September 10, 2019, 9:42pm UTC](https://discuss.elastic.co/t/his-beat-requires-the-default-distribution-of-elasticsearch-please-install-the-default-distribution-of-elasticsearch-from-elastic-co-or-install-the-oss-only-distribution-of-beats/196614 "2019-09-10T21:42:41Z")

</div>

Hi, I have installed metricbeat 6.8.2 and I have elasticsearch 6.2.4 , when try to setup metricbeat I get this: Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: \[Error connection to Elast…

---

## [Filebeat syslog with wrong @timestamp](https://discuss.elastic.co/t/filebeat-syslog-with-wrong-timestamp/195454)

<div class="topic-metadata">

**Author:** [@ntlong](https://discuss.elastic.co/u/ntlong)\
**Replies:** 4\
**Last updated:** [September 10, 2019, 9:28pm UTC](https://discuss.elastic.co/t/filebeat-syslog-with-wrong-timestamp/195454 "2019-09-10T21:28:40Z")

</div>

Hi everyone, I am very new with all of elastic stack, so i hope that you guy can help in details. I am trying to configure filebeat to send syslog directly to elasticsearch, however, the @timestamp of each entry seem t…

---

## [Mean Time Between Failure Heartbeat documents](https://discuss.elastic.co/t/mean-time-between-failure-heartbeat-documents/198945)

<div class="topic-metadata">

**Author:** [@mando\_mat](https://discuss.elastic.co/u/mando_mat)\
**Replies:** 3\
**Last updated:** [September 10, 2019, 8:08pm UTC](https://discuss.elastic.co/t/mean-time-between-failure-heartbeat-documents/198945 "2019-09-10T20:08:37Z")

</div>

Hi, I'm trying to calculate the mean time between recovery and the mean time between failure of some services monitored by heartbeat. For example, for MTBR, for each service I would like to get the time elapsed between …

---

## [Help with multiline log from Windows 2016 Server to Kibana](https://discuss.elastic.co/t/help-with-multiline-log-from-windows-2016-server-to-kibana/198081)

<div class="topic-metadata">

**Author:** [@Peter\_C](https://discuss.elastic.co/u/Peter_C)\
**Replies:** 1\
**Last updated:** [September 10, 2019, 5:39pm UTC](https://discuss.elastic.co/t/help-with-multiline-log-from-windows-2016-server-to-kibana/198081 "2019-09-10T17:39:41Z")

</div>

HI, I am having trouble with getting the multiline logs to show up right in Kibana using filebeats 6.8.2. I've tried using the following: multiline.pattern: '^\\d{1,2}\\/\\d{1,2}\\/\\d{4} \\d{1,2}:\\d{2}:\\d{2} (AM|PM) :' mul…

---

## [X-Pack check on oss Docker image?](https://discuss.elastic.co/t/x-pack-check-on-oss-docker-image/198521)

<div class="topic-metadata">

**Author:** [@josephk](https://discuss.elastic.co/u/josephk)\
**Replies:** 1\
**Last updated:** [September 10, 2019, 4:28pm UTC](https://discuss.elastic.co/t/x-pack-check-on-oss-docker-image/198521 "2019-09-10T16:28:15Z")

</div>

We're running a managed AWS Elasticsearch cluster — not ideal, but that's life — and run most the rest of our stuff with Kubernetes. We recently upgraded our cluster to Elasticsearch 7, so I wanted to upgrade the Filebea…

---

## [Error "build constraints exclude all Go files" while building beats from source for Solaris 11.3 x86](https://discuss.elastic.co/t/error-build-constraints-exclude-all-go-files-while-building-beats-from-source-for-solaris-11-3-x86/198482)

<div class="topic-metadata">

**Author:** [@ConnorRies](https://discuss.elastic.co/u/ConnorRies)\
**Replies:** 1\
**Last updated:** [September 10, 2019, 2:40pm UTC](https://discuss.elastic.co/t/error-build-constraints-exclude-all-go-files-while-building-beats-from-source-for-solaris-11-3-x86/198482 "2019-09-10T14:40:26Z")

</div>

My goal is to run Filebeat on a Solaris 11.3 system. Running uname -a shows me: SunOS solaris 5.11 11.3 i86pc i386 i86pc To build Filebeat, I also need to build go because the version found in package manager is too l…

---

## [Max depth in decode\_json\_fields not working](https://discuss.elastic.co/t/max-depth-in-decode-json-fields-not-working/198874)

<div class="topic-metadata">

**Author:** [@w00f](https://discuss.elastic.co/u/w00f)\
**Replies:** 0\
**Last updated:** [September 10, 2019, 10:28am UTC](https://discuss.elastic.co/t/max-depth-in-decode-json-fields-not-working/198874 "2019-09-10T10:28:46Z")

</div>

I am trying to decode a json fields and try to limit the depth to 1. My config as below: - decode\_json\_fields: fields: \["message"\] process\_array: true max\_depth: 1 …

---

## [Syslog harvesting: Exiting: Error while initializing input: No paths were defined for input accessing config](https://discuss.elastic.co/t/syslog-harvesting-exiting-error-while-initializing-input-no-paths-were-defined-for-input-accessing-config/198846)

<div class="topic-metadata">

**Author:** [@stozik](https://discuss.elastic.co/u/stozik)\
**Replies:** 0\
**Last updated:** [September 10, 2019, 8:27am UTC](https://discuss.elastic.co/t/syslog-harvesting-exiting-error-while-initializing-input-no-paths-were-defined-for-input-accessing-config/198846 "2019-09-10T08:27:07Z")

</div>

Hi, I am configuring syslog harvesting for the first time and I get this error and the filebeat exits: 2019-09-10T11:12:17.635+0300 ERROR instance/beat.go:877 Exiting: Error while initializing input: No paths w…

---

## [Filebeat different log paths to different indexes to elastic cloud](https://discuss.elastic.co/t/filebeat-different-log-paths-to-different-indexes-to-elastic-cloud/198843)

<div class="topic-metadata">

**Author:** [@fadil030889](https://discuss.elastic.co/u/fadil030889)\
**Replies:** 0\
**Last updated:** [September 10, 2019, 7:56am UTC](https://discuss.elastic.co/t/filebeat-different-log-paths-to-different-indexes-to-elastic-cloud/198843 "2019-09-10T07:56:47Z")

</div>

Hi, So i wanted to send logs from different paths directly to elastic cloud, from filebeat. Usually the output to customise the index would be in the filebeat.yml: setup.ilm.enabled: true setup.ilm.rollover\_alias: "i…

---

## [Filbert get the timestamp from the filename](https://discuss.elastic.co/t/filbert-get-the-timestamp-from-the-filename/198819)

<div class="topic-metadata">

**Author:** [@LiuHao](https://discuss.elastic.co/u/LiuHao)\
**Replies:** 0\
**Last updated:** [September 10, 2019, 3:47am UTC](https://discuss.elastic.co/t/filbert-get-the-timestamp-from-the-filename/198819 "2019-09-10T03:47:09Z")

</div>

Hello,I'am new in Filebeat and now I get a problem. My log file's name like 11073101\_20190811.txt :school number\_yyyymmdd.txt and the content like 00:15:34,109.75.53.176 :hh:mm…

---

## [Filebeat service terminated unexpectedly - Windows server 2016](https://discuss.elastic.co/t/filebeat-service-terminated-unexpectedly-windows-server-2016/198797)

<div class="topic-metadata">

**Author:** [@scottk](https://discuss.elastic.co/u/scottk)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 10:03pm UTC](https://discuss.elastic.co/t/filebeat-service-terminated-unexpectedly-windows-server-2016/198797 "2019-09-09T22:03:38Z")

</div>

Hi, my filebeat service will not run all of a sudden. Whenever I try to start the service, I get an error that "Error 1067: The process terminated unexpectedly". The event log provides no more details than that, besides …

---

## [Process unable to write to log file monitored by filebeat](https://discuss.elastic.co/t/process-unable-to-write-to-log-file-monitored-by-filebeat/198784)

<div class="topic-metadata">

**Author:** [@\_finack](https://discuss.elastic.co/u/_finack)\
**Replies:** 1\
**Last updated:** [September 9, 2019, 8:51pm UTC](https://discuss.elastic.co/t/process-unable-to-write-to-log-file-monitored-by-filebeat/198784 "2019-09-09T20:51:10Z")

</div>

I'm trying to use filebeat 7.3.0 on Windows Server 2016 to monitor two log files stored a local disk and I'm having trouble with the logging service having trouble writing to the log files while filebeat is monitoring th…

---

## [Multiline Pattern not Working](https://discuss.elastic.co/t/multiline-pattern-not-working/198763)

<div class="topic-metadata">

**Author:** [@mugil1988](https://discuss.elastic.co/u/mugil1988)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 6:20pm UTC](https://discuss.elastic.co/t/multiline-pattern-not-working/198763 "2019-09-09T18:20:53Z")

</div>

Hi Team , I am trying to configure filebeat to ship logs to logstash from one server. Filebeat is harvesting all the lines together irrespective of MultilineConfiguration. Sample Logs: 2019-09-09T23:40:59,919 | INFO …

---

## [Cumulative Values - X-PACK monitoring](https://discuss.elastic.co/t/cumulative-values-x-pack-monitoring/196578)

<div class="topic-metadata">

**Author:** [@leandro.borges](https://discuss.elastic.co/u/leandro.borges)\
**Replies:** 1\
**Last updated:** [September 9, 2019, 5:10pm UTC](https://discuss.elastic.co/t/cumulative-values-x-pack-monitoring/196578 "2019-09-09T17:10:31Z")

</div>

Hello I activated the monitoring on a Filebeat to send monitoring information to Elasticsearch. Now, in my dashboard inside Kibana I have: It shows the behaviour when filebeat is sending data. When I try to create …

---

## [Filebeat is not able to send logs to elastic](https://discuss.elastic.co/t/filebeat-is-not-able-to-send-logs-to-elastic/198566)

<div class="topic-metadata">

**Author:** [@Pankaj\_Kaushik](https://discuss.elastic.co/u/Pankaj_Kaushik)\
**Replies:** 8\
**Last updated:** [September 9, 2019, 5:00pm UTC](https://discuss.elastic.co/t/filebeat-is-not-able-to-send-logs-to-elastic/198566 "2019-09-09T17:00:33Z")

</div>

\#=========================== Filebeat inputs ============================= filebeat.prospectors: Each - is an input. Most options can be set at the input level, so you can use different inputs for various configuration…

---

## [K8S metadata is missing](https://discuss.elastic.co/t/k8s-metadata-is-missing/198647)

<div class="topic-metadata">

**Author:** [@aleksei.saiko](https://discuss.elastic.co/u/aleksei.saiko)\
**Replies:** 1\
**Last updated:** [September 9, 2019, 3:59pm UTC](https://discuss.elastic.co/t/k8s-metadata-is-missing/198647 "2019-09-09T15:59:11Z")

</div>

Hi there! I'm using ELK 7.3.1 And when Filebeat collects logs from Kubernetes, I don't see any Kubernetes metadata (namespace is missing, container, name and etc.). What am I doing wrong here? Attaching screen of appe…

---

## [Metric Beats not changing indexName](https://discuss.elastic.co/t/metric-beats-not-changing-indexname/198722)

<div class="topic-metadata">

**Author:** [@Sergioc](https://discuss.elastic.co/u/Sergioc)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 3:12pm UTC](https://discuss.elastic.co/t/metric-beats-not-changing-indexname/198722 "2019-09-09T15:12:30Z")

</div>

Hello, I have configured MetricBeats in one server but the index name is the same. I have tried to change the config but the indexname is the same always and in the logs, I can see this message. \[index-management\] idx…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=317)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=319)
