# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=319

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 320

---

## [Manually uploading the template and shard number](https://discuss.elastic.co/t/manually-uploading-the-template-and-shard-number/198712)

<div class="topic-metadata">

**Author:** [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 2:38pm UTC](https://discuss.elastic.co/t/manually-uploading-the-template-and-shard-number/198712 "2019-09-09T14:38:08Z")

</div>

Hello, when we use the manual method to upload the index template it creates the index with one shard - is there a way to change this so I can choose the shard number? Thanks.

---

## [Close\_eof data loss?](https://discuss.elastic.co/t/close-eof-data-loss/198710)

<div class="topic-metadata">

**Author:** [@lobando](https://discuss.elastic.co/u/lobando)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 2:34pm UTC](https://discuss.elastic.co/t/close-eof-data-loss/198710 "2019-09-09T14:34:57Z")

</div>

Filebeat documentation for close\_eof says that there can be data loss, can someone explain this a bit better, an example of how data loss can happen ? I understand the harverster will be close on EOF, and maybe later da…

---

## [Can one filebeat run against multiple redis instances based on fields?](https://discuss.elastic.co/t/can-one-filebeat-run-against-multiple-redis-instances-based-on-fields/198704)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 2:10pm UTC](https://discuss.elastic.co/t/can-one-filebeat-run-against-multiple-redis-instances-based-on-fields/198704 "2019-09-09T14:10:48Z")

</div>

Hi, currently metricbeat outputting its probes to file system. Same procedure as for all logs, filebeat is tailing application logs and metricbeat probes and ships them to redis. Key is set depending by a key. No I wo…

---

## [File harvested but not sent](https://discuss.elastic.co/t/file-harvested-but-not-sent/197624)

<div class="topic-metadata">

**Author:** [@lobando](https://discuss.elastic.co/u/lobando)\
**Replies:** 1\
**Last updated:** [September 9, 2019, 2:08pm UTC](https://discuss.elastic.co/t/file-harvested-but-not-sent/197624 "2019-09-09T14:08:19Z")

</div>

Hello, This is my current setup. Filebeat running in a docker container reading json files from a mounted docker volume. These files are only read once and then close. close\_eof = true Files are written to the …

---

## [Filebeat failing](https://discuss.elastic.co/t/filebeat-failing/198473)

<div class="topic-metadata">

**Author:** [@NewmazN24](https://discuss.elastic.co/u/NewmazN24)\
**Replies:** 1\
**Last updated:** [September 9, 2019, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-failing/198473 "2019-09-09T13:39:40Z")

</div>

Hey guys, My environment - Dev Master nodes (Elasticsearch & Logstash are installed) x 2 Kibana node (Only Kibana) x 1 All m servers are on CentOS7 Before you ask I can reach my master nodes Both nodes see eachother …

---

## [Metricbeat -\> redis -\> logstash -\> elasticsearch: failed to parse field \[kubernetes.labels.app\]](https://discuss.elastic.co/t/metricbeat-redis-logstash-elasticsearch-failed-to-parse-field-kubernetes-labels-app/194992)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 5\
**Last updated:** [September 9, 2019, 12:01pm UTC](https://discuss.elastic.co/t/metricbeat-redis-logstash-elasticsearch-failed-to-parse-field-kubernetes-labels-app/194992 "2019-09-09T12:01:00Z")

</div>

Hi, not sure if this issue is better be posted here or in metricbeat section. I have deployed metricbeat in kubernetes using this manual: https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-kubernetes.…

---

## [Reading TLS packets from a capture file](https://discuss.elastic.co/t/reading-tls-packets-from-a-capture-file/198664)

<div class="topic-metadata">

**Author:** [@stackoverflow](https://discuss.elastic.co/u/stackoverflow)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 10:58am UTC](https://discuss.elastic.co/t/reading-tls-packets-from-a-capture-file/198664 "2019-09-09T10:58:12Z")

</div>

Hello, I am interested in running packet beat with a -I option to parse TLS metadata stored in a file. I am only interested in Client Hello, Server Hello TLS messages. I would like to know if the capture file should h…

---

## [Run Filebeats as Non-Root User](https://discuss.elastic.co/t/run-filebeats-as-non-root-user/198374)

<div class="topic-metadata">

**Author:** [@thps](https://discuss.elastic.co/u/thps)\
**Replies:** 2\
**Last updated:** [September 9, 2019, 9:40am UTC](https://discuss.elastic.co/t/run-filebeats-as-non-root-user/198374 "2019-09-09T09:40:44Z")

</div>

Hi folks, i´m trying to run Filebeat as a non root user on RHEL 7.5. What have i done: chown for /etc/filebeat , /var/log/filebeat ,/usr/share/filebeat and /var/lib/filebeat. The user is now owner of this directo…

---

## [ILM config for beats](https://discuss.elastic.co/t/ilm-config-for-beats/198629)

<div class="topic-metadata">

**Author:** [@coudenysj](https://discuss.elastic.co/u/coudenysj)\
**Replies:** 1\
**Last updated:** [September 9, 2019, 9:39am UTC](https://discuss.elastic.co/t/ilm-config-for-beats/198629 "2019-09-09T09:39:27Z")

</div>

Hi, I was wondering if the index logic for beats was changed due to ILM settings. In the logs of filebeat, I see Set output.elasticsearch.index to 'filebeat-7.3.1' as ILM is enabled.. This is different from the base co…

---

## [Fork/exec /var/task/functionbeat: exec format error: PathError null](https://discuss.elastic.co/t/fork-exec-var-task-functionbeat-exec-format-error-patherror-null/198630)

<div class="topic-metadata">

**Author:** [@Gavin\_Hardy](https://discuss.elastic.co/u/Gavin_Hardy)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 8:19am UTC](https://discuss.elastic.co/t/fork-exec-var-task-functionbeat-exec-format-error-patherror-null/198630 "2019-09-09T08:19:59Z")

</div>

Hi, When deploying functionbeat, I can get it to successfully deploy to Lambda. However, when looking at logs I get the following error- fork/exec /var/task/functionbeat: exec format error: PathError null functionbeat.…

---

## [Can I put the logLine in a different field as message on log basis?](https://discuss.elastic.co/t/can-i-put-the-logline-in-a-different-field-as-message-on-log-basis/198622)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [September 9, 2019, 7:45am UTC](https://discuss.elastic.co/t/can-i-put-the-logline-in-a-different-field-as-message-on-log-basis/198622 "2019-09-09T07:45:09Z")

</div>

Hi, my pipeline looks like this: log -\> filebeat -\> redis -\> logstash -\> elasticsearch My logfile is a simple json file which should be ready to index at elasticsearch directly, so logstash doesn't really need to much …

---

## [Winlogbeat default paths](https://discuss.elastic.co/t/winlogbeat-default-paths/198581)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 1\
**Last updated:** [September 8, 2019, 9:18pm UTC](https://discuss.elastic.co/t/winlogbeat-default-paths/198581 "2019-09-08T21:18:32Z")

</div>

The default Winlogbeat path.data is ${path.home}/data, documented here https://www.elastic.co/guide/en/beats/winlogbeat/current/directory-layout.html. However, the default service installer install-service-winlogbeat.ps…

---

## [Squid proxy logs directly to ELasticSearch via filebeat!](https://discuss.elastic.co/t/squid-proxy-logs-directly-to-elasticsearch-via-filebeat/197949)

<div class="topic-metadata">

**Author:** [@sk545](https://discuss.elastic.co/u/sk545)\
**Replies:** 5\
**Last updated:** [September 6, 2019, 9:04pm UTC](https://discuss.elastic.co/t/squid-proxy-logs-directly-to-elasticsearch-via-filebeat/197949 "2019-09-06T21:04:31Z")

</div>

I am wondering does any one already configured the shipping of Squid Proxy logs directly to Elastic search via file beat ?if yes, can some one provide me the information to achieve this ! Thank you

---

## [Send logs from one EC2 instance to another](https://discuss.elastic.co/t/send-logs-from-one-ec2-instance-to-another/198462)

<div class="topic-metadata">

**Author:** [@Ghaith\_Haddad](https://discuss.elastic.co/u/Ghaith_Haddad)\
**Replies:** 0\
**Last updated:** [September 6, 2019, 5:55pm UTC](https://discuss.elastic.co/t/send-logs-from-one-ec2-instance-to-another/198462 "2019-09-06T17:55:52Z")

</div>

Hello everyone, So i have one EC2 instance with logstash, elastichsearch and kibana installed on it. and i have another EC2 instance thats running a dummy apache server. Now i know that i should install filebeat on the …

---

## [Filebeat 7.x compatible with ES 6.x?](https://discuss.elastic.co/t/filebeat-7-x-compatible-with-es-6-x/198458)

<div class="topic-metadata">

**Author:** [@spuder](https://discuss.elastic.co/u/spuder)\
**Replies:** 0\
**Last updated:** [September 6, 2019, 5:32pm UTC](https://discuss.elastic.co/t/filebeat-7-x-compatible-with-es-6-x/198458 "2019-09-06T17:32:09Z")

</div>

I'm doing a proof of concept with filebeats writing to an existing Elasticsearch 6.4.0 cluster. I find that I'm unable to write any filebeat data due to the error "Failed to parse mapping \[doc\]: Mapping definition for \[…

---

## [Filebeat conditional multiline on container metadata](https://discuss.elastic.co/t/filebeat-conditional-multiline-on-container-metadata/198449)

<div class="topic-metadata">

**Author:** [@cdalexndr](https://discuss.elastic.co/u/cdalexndr)\
**Replies:** 0\
**Last updated:** [September 6, 2019, 4:28pm UTC](https://discuss.elastic.co/t/filebeat-conditional-multiline-on-container-metadata/198449 "2019-09-06T16:28:49Z")

</div>

Using a filebeat configuration: filebeat.inputs: - type: container paths: - '/var/lib/docker/containers/\*/\*.log' processors: - add\_docker\_metadata: host: "unix:///var/run/docker.sock" How can I appl…

---

## [RPM names do not match their contents](https://discuss.elastic.co/t/rpm-names-do-not-match-their-contents/193782)

<div class="topic-metadata">

**Author:** [@akshatsharma](https://discuss.elastic.co/u/akshatsharma)\
**Replies:** 11\
**Last updated:** [September 6, 2019, 3:06pm UTC](https://discuss.elastic.co/t/rpm-names-do-not-match-their-contents/193782 "2019-09-06T15:06:12Z")

</div>

filebeat RPM file names do not match their contents. Specifically, filebeat-1.2.3-x86\_64.rpm should be filebeat-1.2.3-1.x86\_64.rpm (is missing the release and the dot before the arch) and filebeat-5.2.1.rpm should be fi…

---

## [Windows User managment events - Events 4720-4722-4723-4724-4725-4726-4738-4740-4767](https://discuss.elastic.co/t/windows-user-managment-events-events-4720-4722-4723-4724-4725-4726-4738-4740-4767/194865)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 5\
**Last updated:** [September 6, 2019, 2:51pm UTC](https://discuss.elastic.co/t/windows-user-managment-events-events-4720-4722-4723-4724-4725-4726-4738-4740-4767/194865 "2019-09-06T14:51:18Z")

</div>

Hi, @andrewkroh I've been working with user management-related events In order to identify all the operations related to user creation/deletion and other user-account changes, I've made some modification to the winlog…

---

## [Winlogbeat New ECS Fields and security module questions](https://discuss.elastic.co/t/winlogbeat-new-ecs-fields-and-security-module-questions/190479)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 15\
**Last updated:** [September 6, 2019, 2:50pm UTC](https://discuss.elastic.co/t/winlogbeat-new-ecs-fields-and-security-module-questions/190479 "2019-09-06T14:50:14Z")

</div>

Hi, I've been working on events 4624 (An account was successfully logged on), 4634 (An account was logged off), 4672 (Special privileges assigned to new logon) in order to correlate logon information about Administrato…

---

## [Logstash grok pattern working fine in grok debugger, but fails in logstash conf file to parse](https://discuss.elastic.co/t/logstash-grok-pattern-working-fine-in-grok-debugger-but-fails-in-logstash-conf-file-to-parse/198420)

<div class="topic-metadata">

**Author:** [@sonammarda](https://discuss.elastic.co/u/sonammarda)\
**Replies:** 3\
**Last updated:** [September 6, 2019, 2:22pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-working-fine-in-grok-debugger-but-fails-in-logstash-conf-file-to-parse/198420 "2019-09-06T14:22:07Z")

</div>

Logstash version - 7.3 Filebeat version - 7.3 OS - Windows Below is my exception format in application log file- \<log4j:event logger="ESM.EasyPurchaseMarketplace.Infrastructure.Logging.Logger" timestamp="156696497168…

---

## [Metricbeat docker dashboard table sort irrelevant](https://discuss.elastic.co/t/metricbeat-docker-dashboard-table-sort-irrelevant/197876)

<div class="topic-metadata">

**Author:** [@cdalexndr](https://discuss.elastic.co/u/cdalexndr)\
**Replies:** 0\
**Last updated:** [September 3, 2019, 1:44pm UTC](https://discuss.elastic.co/t/metricbeat-docker-dashboard-table-sort-irrelevant/197876 "2019-09-03T13:44:41Z")

</div>

The docker dashboard table ("Docker containers" top left) shows only top 5 containers (sorted by some unknown metric), but if I want to sort by some top header column, only the displayed data is sorted, missing some cont…

---

## [fileBeats failing](https://discuss.elastic.co/t/filebeats-failing/198311)

<div class="topic-metadata">

**Author:** [@NewmazN24](https://discuss.elastic.co/u/NewmazN24)\
**Replies:** 1\
**Last updated:** [September 6, 2019, 1:28pm UTC](https://discuss.elastic.co/t/filebeats-failing/198311 "2019-09-06T13:28:30Z")

</div>

Hey guys, My environment - Dev Master nodes (Elasticsearch & Logstash are installed) x 2 Kibana node (Only Kibana) x 1 All m servers are on CentOS7 Before you ask I can reach my master nodes Both nodes see eachother …

---

## [Filebeat (installation steps for Redhat) task is send jenkins logs through filebeatto KIBANA Dashboard if anybody knows help me](https://discuss.elastic.co/t/filebeat-installation-steps-for-redhat-task-is-send-jenkins-logs-through-filebeatto-kibana-dashboard-if-anybody-knows-help-me/198422)

<div class="topic-metadata">

**Author:** [@Hari\_Reddy](https://discuss.elastic.co/u/Hari_Reddy)\
**Replies:** 0\
**Last updated:** [September 6, 2019, 12:19pm UTC](https://discuss.elastic.co/t/filebeat-installation-steps-for-redhat-task-is-send-jenkins-logs-through-filebeatto-kibana-dashboard-if-anybody-knows-help-me/198422 "2019-09-06T12:19:40Z")

</div>

\[root@ip- ~\]# sudo systemctl enable filebeat \[root@ip- ~\]# sudo systemctl status filebeat ● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/usr/lib/systemd/sy…

---

## [Metricbeat index gets deleted loosing data](https://discuss.elastic.co/t/metricbeat-index-gets-deleted-loosing-data/198386)

<div class="topic-metadata">

**Author:** [@piotr.pawlak3](https://discuss.elastic.co/u/piotr.pawlak3)\
**Replies:** 0\
**Last updated:** [September 6, 2019, 9:34am UTC](https://discuss.elastic.co/t/metricbeat-index-gets-deleted-loosing-data/198386 "2019-09-06T09:34:24Z")

</div>

Hi, from time to time but re-occuring we loosing data in metricbeat-\* index. We noticed this happen at 2am when index snapshot is taken. The lost data causing dashboards to fail. Err: Fielddata is disabled on text fiel…

---

## [Trying to setup Filebeat to send IIS logs to logstash](https://discuss.elastic.co/t/trying-to-setup-filebeat-to-send-iis-logs-to-logstash/198086)

<div class="topic-metadata">

**Author:** [@sonammarda](https://discuss.elastic.co/u/sonammarda)\
**Replies:** 1\
**Last updated:** [September 6, 2019, 11:08am UTC](https://discuss.elastic.co/t/trying-to-setup-filebeat-to-send-iis-logs-to-logstash/198086 "2019-09-06T11:08:38Z")

</div>

Filebeat version- 7.3 Logstash version- 7.3 OS- Windows Filebeat.yml file- filebeat.inputs: type: log enabled: true #Paths that should be crawled and fetched. Glob based paths. paths: c:\\Program Files\\filebea…

---

## [7.x Log Input config directory?](https://discuss.elastic.co/t/7-x-log-input-config-directory/198146)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 1\
**Last updated:** [September 6, 2019, 10:24am UTC](https://discuss.elastic.co/t/7-x-log-input-config-directory/198146 "2019-09-06T10:24:00Z")

</div>

Is it possible to provide a directory of log input config fragments in 7.x? We were doing this in 6.x with filebeat.prospectors.path and dropping in config fragments based on Puppet roles for each machine. This way we c…

---

## [Winlogbeat Windows config to see logs on Kibana Dashboard](https://discuss.elastic.co/t/winlogbeat-windows-config-to-see-logs-on-kibana-dashboard/198261)

<div class="topic-metadata">

**Author:** [@Luuckyx](https://discuss.elastic.co/u/Luuckyx)\
**Replies:** 6\
**Last updated:** [September 6, 2019, 9:47am UTC](https://discuss.elastic.co/t/winlogbeat-windows-config-to-see-logs-on-kibana-dashboard/198261 "2019-09-06T09:47:57Z")

</div>

Hello everyone,i need help in Winlogbeat config to see logs on Kibana Dashboard. I have install a ELK server on a ubuntu 18.04 virtualisation and it's work ! no problem here. I need add logs of a Virtual Windows Serve…

---

## [Filebeat: Extending Module Config](https://discuss.elastic.co/t/filebeat-extending-module-config/198368)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 0\
**Last updated:** [September 6, 2019, 8:15am UTC](https://discuss.elastic.co/t/filebeat-extending-module-config/198368 "2019-09-06T08:15:29Z")

</div>

Hi, I have a need to extend the config of a bundled filebeat module to exclude some files. Is this easily done? Regards, D

---

## [FIleBeat 7.3.1 and panw module](https://discuss.elastic.co/t/filebeat-7-3-1-and-panw-module/198366)

<div class="topic-metadata">

**Author:** [@mbritton](https://discuss.elastic.co/u/mbritton)\
**Replies:** 0\
**Last updated:** [September 6, 2019, 8:08am UTC](https://discuss.elastic.co/t/filebeat-7-3-1-and-panw-module/198366 "2019-09-06T08:08:22Z")

</div>

Hello, we are testing filebeat 7.3.1 and the panw module for palo alto firewall logs. Logs are send directly to filebeat module but are not ingested in elasticsearch and we have this error in filebeat logs: Failed to …

---

## [Function: \<functionbeat\>, could not deploy, error: incompatible type received, expecting: 'functionManager'](https://discuss.elastic.co/t/function-functionbeat-could-not-deploy-error-incompatible-type-received-expecting-functionmanager/198280)

<div class="topic-metadata">

**Author:** [@Gavin\_Hardy](https://discuss.elastic.co/u/Gavin_Hardy)\
**Replies:** 1\
**Last updated:** [September 6, 2019, 7:00am UTC](https://discuss.elastic.co/t/function-functionbeat-could-not-deploy-error-incompatible-type-received-expecting-functionmanager/198280 "2019-09-06T07:00:59Z")

</div>

Hi there, I have setup functionbeat to pull data from my kinesis data stream, and push to ES. However, when setting up the function beat I get the following error. Function: eventlogsfunctionbeat, could not deploy, err…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=318)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=320)
