# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=321

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 322

---

## [Processor not working](https://discuss.elastic.co/t/processor-not-working/197955)

<div class="topic-metadata">

**Author:** [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Replies:** 1\
**Last updated:** [September 3, 2019, 10:19pm UTC](https://discuss.elastic.co/t/processor-not-working/197955 "2019-09-03T22:19:08Z")

</div>

I am trying to use processors in filebeat, but the testing was not working as I expected. Here is the config: #=========================== Filebeat inputs ============================= processors: - drop\_event: whe…

---

## [Filebeat - Automatic log message TIMESTAMP recognition](https://discuss.elastic.co/t/filebeat-automatic-log-message-timestamp-recognition/197482)

<div class="topic-metadata">

**Author:** [@Arthur\_Gordon\_Pym](https://discuss.elastic.co/u/Arthur_Gordon_Pym)\
**Replies:** 1\
**Last updated:** [September 3, 2019, 10:01pm UTC](https://discuss.elastic.co/t/filebeat-automatic-log-message-timestamp-recognition/197482 "2019-09-03T22:01:45Z")

</div>

Hi guys. I started playing with ELK (7.3.1 all components), on my CentOS7 test machine. First problem, i also uso Splunk as bigdata Analyzer/Monitoring System... the first gift Splunk did, is to recognize almost every …

---

## [No log data found](https://discuss.elastic.co/t/no-log-data-found/197936)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 0\
**Last updated:** [September 3, 2019, 7:56pm UTC](https://discuss.elastic.co/t/no-log-data-found/197936 "2019-09-03T19:56:38Z")

</div>

Hello World! I followed Running Filebeat on Kubernetes | Filebeat Reference \[7.3\] | Elastic to deploy Filebeat to Kubernetes, yet Kibana' Monitoring app (elasticsearch/logs) says: No log data found $ kubectl --na…

---

## [Add\_kubernetes\_metadata without access to docker mountPaths?](https://discuss.elastic.co/t/add-kubernetes-metadata-without-access-to-docker-mountpaths/197932)

<div class="topic-metadata">

**Author:** [@dtanner](https://discuss.elastic.co/u/dtanner)\
**Replies:** 0\
**Last updated:** [September 3, 2019, 7:32pm UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-without-access-to-docker-mountpaths/197932 "2019-09-03T19:32:29Z")

</div>

It's my first time trying to use the add\_kubernetes\_metadata processor to include pod labels. Based on some examples I've seen, it looks like it's a requirement to mount e.g. /var/lib/docker/containers via the mountPath …

---

## [Filebeat Does Not Start](https://discuss.elastic.co/t/filebeat-does-not-start/197599)

<div class="topic-metadata">

**Author:** [@ljacobs7211](https://discuss.elastic.co/u/ljacobs7211)\
**Replies:** 1\
**Last updated:** [September 3, 2019, 7:30pm UTC](https://discuss.elastic.co/t/filebeat-does-not-start/197599 "2019-09-03T19:30:16Z")

</div>

I followed the instructions to install Filebeats to ingest Suricata eve.json data into Elasticsearch. Filebeat fails on start on Ubuntu Error Screenshot The setup created the dashboards and the Elasticsearch filebea…

---

## [Filebeat Input Config Error](https://discuss.elastic.co/t/filebeat-input-config-error/197912)

<div class="topic-metadata">

**Author:** [@whitecoffee](https://discuss.elastic.co/u/whitecoffee)\
**Replies:** 1\
**Last updated:** [September 3, 2019, 7:07pm UTC](https://discuss.elastic.co/t/filebeat-input-config-error/197912 "2019-09-03T19:07:40Z")

</div>

I am new to all of this so bear with me. I have set up an instance on elastic cloud and am attempting to import logs from my windows VM machine. I have the config file setup for the most part but cant find where to imp…

---

## [Filebeat modules with Logstash](https://discuss.elastic.co/t/filebeat-modules-with-logstash/197851)

<div class="topic-metadata">

**Author:** [@gerard1](https://discuss.elastic.co/u/gerard1)\
**Replies:** 3\
**Last updated:** [September 3, 2019, 6:19pm UTC](https://discuss.elastic.co/t/filebeat-modules-with-logstash/197851 "2019-09-03T18:19:25Z")

</div>

I've set up a Filebeat -\> Logstash -\> Kibana workflow that it's been working for the last 2 years. In the most recent Elastic package versions, new features are available, such as Filebeat modules, Kibana SIEM etc. Som…

---

## [Unable to parse log via filebeat](https://discuss.elastic.co/t/unable-to-parse-log-via-filebeat/197833)

<div class="topic-metadata">

**Author:** [@Nithani25](https://discuss.elastic.co/u/Nithani25)\
**Replies:** 1\
**Last updated:** [September 3, 2019, 2:37pm UTC](https://discuss.elastic.co/t/unable-to-parse-log-via-filebeat/197833 "2019-09-03T14:37:26Z")

</div>

Hi Team, My setup has been working perfectly fine for quite some time now, however, i am working on injecting new set of logs into logstash via filebeat which is not happening. I dont see any visible errors with filebea…

---

## [To produce beat that will ingest ECS logs and metrics into elasticsearch](https://discuss.elastic.co/t/to-produce-beat-that-will-ingest-ecs-logs-and-metrics-into-elasticsearch/197827)

<div class="topic-metadata">

**Author:** [@vanshika\_agrawal](https://discuss.elastic.co/u/vanshika_agrawal)\
**Replies:** 2\
**Last updated:** [September 3, 2019, 1:44pm UTC](https://discuss.elastic.co/t/to-produce-beat-that-will-ingest-ecs-logs-and-metrics-into-elasticsearch/197827 "2019-09-03T13:44:00Z")

</div>

I am trying to produce beat that will ingest ECS logs and metrics into ElasticSearch? How can I ingest logs and metrics into ElasticSearch

---

## [Support additional fields in "activity" metricset for PostgreSQL 10](https://discuss.elastic.co/t/support-additional-fields-in-activity-metricset-for-postgresql-10/197725)

<div class="topic-metadata">

**Author:** [@kjsh](https://discuss.elastic.co/u/kjsh)\
**Replies:** 2\
**Last updated:** [September 3, 2019, 1:36pm UTC](https://discuss.elastic.co/t/support-additional-fields-in-activity-metricset-for-postgresql-10/197725 "2019-09-03T13:36:49Z")

</div>

Postgres 10 added few more columns to the pg\_stat\_activity which can be exported by the metricbeats module. I noticed that we use 9.2 at the moment. I would be happy to send in a patch for the "activity" metricset. Howe…

---

## [Issue to setting up Metricbeat on Linux](https://discuss.elastic.co/t/issue-to-setting-up-metricbeat-on-linux/197692)

<div class="topic-metadata">

**Author:** [@Aw4xs](https://discuss.elastic.co/u/Aw4xs)\
**Replies:** 2\
**Last updated:** [September 3, 2019, 1:25pm UTC](https://discuss.elastic.co/t/issue-to-setting-up-metricbeat-on-linux/197692 "2019-09-03T13:25:05Z")

</div>

Hello guys, I'm currently trying to use my ELK install on WIN2016 and all access seems to be ok with the good tutorial from : http://robwillis.info/2019/05/installing-elk-7-elasticsearch-logstash-and-kibana-windows-serv…

---

## [Aws module](https://discuss.elastic.co/t/aws-module/197618)

<div class="topic-metadata">

**Author:** [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Replies:** 3\
**Last updated:** [September 3, 2019, 1:24pm UTC](https://discuss.elastic.co/t/aws-module/197618 "2019-09-03T13:24:48Z")

</div>

There was no error in the debug log, and there was no events pulled from AWS (in metricbeat-\* index there was no message). Please help, thanks in advance! Here is the config: # Module: aws # Docs: https://www.elastic.…

---

## [Metricbeat - Haproxy stats delta for (IN bytes and OUT bytes)](https://discuss.elastic.co/t/metricbeat-haproxy-stats-delta-for-in-bytes-and-out-bytes/197679)

<div class="topic-metadata">

**Author:** [@praveenkumar.2608](https://discuss.elastic.co/u/praveenkumar.2608)\
**Replies:** 1\
**Last updated:** [September 3, 2019, 1:23pm UTC](https://discuss.elastic.co/t/metricbeat-haproxy-stats-delta-for-in-bytes-and-out-bytes/197679 "2019-09-03T13:23:57Z")

</div>

Hi, I am using metricbeat to collect haproxy stats. It seems metricbeat does not calculate delta for cumulative fields like (haproxy.stats.in.bytes and haproxy.stats.out.bytes). Is there any way to calculate the delta v…

---

## [Pattern filter in filebeat or ingest node?](https://discuss.elastic.co/t/pattern-filter-in-filebeat-or-ingest-node/197374)

<div class="topic-metadata">

**Author:** [@rverchere](https://discuss.elastic.co/u/rverchere)\
**Replies:** 2\
**Last updated:** [September 2, 2019, 8:53pm UTC](https://discuss.elastic.co/t/pattern-filter-in-filebeat-or-ingest-node/197374 "2019-09-02T20:53:30Z")

</div>

Hello, I have a setup with a filebeat agent that sends messages to an elastic cluster. I need to filter messages that goes to the cluster, and I have 2 options: Using pattern filters on filebeat Using filtering pipel…

---

## [Decode\_json\_fields.fields: \["message"\] decodes JSON logs with "logs"](https://discuss.elastic.co/t/decode-json-fields-fields-message-decodes-json-logs-with-logs/197712)

<div class="topic-metadata">

**Author:** [@olivierwa](https://discuss.elastic.co/u/olivierwa)\
**Replies:** 0\
**Last updated:** [September 2, 2019, 3:25pm UTC](https://discuss.elastic.co/t/decode-json-fields-fields-message-decodes-json-logs-with-logs/197712 "2019-09-02T15:25:04Z")

</div>

Hello, I am running an Elastic+Kibana+Filebeat docker stack to monitor containers. Everything is working fine but there is something that I do not understand and wasted many hours on it to debug. The log files under /v…

---

## [Failed to connect to backoff - Forbidden](https://discuss.elastic.co/t/failed-to-connect-to-backoff-forbidden/197704)

<div class="topic-metadata">

**Author:** [@pmatula](https://discuss.elastic.co/u/pmatula)\
**Replies:** 0\
**Last updated:** [September 2, 2019, 2:20pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-forbidden/197704 "2019-09-02T14:20:52Z")

</div>

Hi, I installed winlogbeat and used an existing and working winlogbeat.yml - but on this client, I get the error: Failed to connect to backoff(elasticsearch(https://elasticserver:9200)): Get https://elasticserver:9200:…

---

## [Need help in dropping DNS event with packetbeat](https://discuss.elastic.co/t/need-help-in-dropping-dns-event-with-packetbeat/197395)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 8\
**Last updated:** [September 2, 2019, 4:09am UTC](https://discuss.elastic.co/t/need-help-in-dropping-dns-event-with-packetbeat/197395 "2019-09-02T04:09:41Z")

</div>

Hi team, I am trying to drop certain events on my AD server since I have packet beat installed and listening for DNS ports. I somehow unable to get it working, and I really appreciate if someone can help me on this? H…

---

## [Help understanding cpu values returned by docker module](https://discuss.elastic.co/t/help-understanding-cpu-values-returned-by-docker-module/197617)

<div class="topic-metadata">

**Author:** [@marcoregueira](https://discuss.elastic.co/u/marcoregueira)\
**Replies:** 0\
**Last updated:** [September 1, 2019, 9:48am UTC](https://discuss.elastic.co/t/help-understanding-cpu-values-returned-by-docker-module/197617 "2019-09-01T09:48:56Z")

</div>

Hi I have a test system for ELK using VirtualBox and Docker with 4 virtual cpu cores. I've managed to enable metricbeat in a container with the docker module enabled (only this module) and I am receiving readings from …

---

## [How can use exported fields by plugin in kibana](https://discuss.elastic.co/t/how-can-use-exported-fields-by-plugin-in-kibana/197327)

<div class="topic-metadata">

**Author:** [@Saeed\_MH](https://discuss.elastic.co/u/Saeed_MH)\
**Replies:** 2\
**Last updated:** [September 1, 2019, 9:30am UTC](https://discuss.elastic.co/t/how-can-use-exported-fields-by-plugin-in-kibana/197327 "2019-09-01T09:30:34Z")

</div>

I am using following elk components: kibana 6.8.0 logstash 6.8.1 filebeat 7.3 I enabled mongodb modules for filebeat and now i can see mongo logs in kibana but i don't see any exported fields of mongodb module like "…

---

## [Filebeat throwing mapper\_parsing\_exception](https://discuss.elastic.co/t/filebeat-throwing-mapper-parsing-exception/197513)

<div class="topic-metadata">

**Author:** [@Ulka](https://discuss.elastic.co/u/Ulka)\
**Replies:** 1\
**Last updated:** [September 1, 2019, 7:48am UTC](https://discuss.elastic.co/t/filebeat-throwing-mapper-parsing-exception/197513 "2019-09-01T07:48:21Z")

</div>

I am sending filebeat output to elastic search. In filebeat logs, can see mapper parser error. trying to load dynamic template manually (through postman) but still getting error. filebeat is on K8S cluster and ES is hos…

---

## [Metricbeat on VM can't connect to Elasticsearch in another VM](https://discuss.elastic.co/t/metricbeat-on-vm-cant-connect-to-elasticsearch-in-another-vm/197555)

<div class="topic-metadata">

**Author:** [@ajaque](https://discuss.elastic.co/u/ajaque)\
**Replies:** 4\
**Last updated:** [August 30, 2019, 8:51pm UTC](https://discuss.elastic.co/t/metricbeat-on-vm-cant-connect-to-elasticsearch-in-another-vm/197555 "2019-08-30T20:51:37Z")

</div>

Hi all. I am new to Elastic and I have been reading many of the possible solutions to the problem I am experiencing without any success. May be I could help some more direct help here. Scenario: Lenovo machine runnin…

---

## [S3 bucket logs forwarding to Elastic Search through filebeat](https://discuss.elastic.co/t/s3-bucket-logs-forwarding-to-elastic-search-through-filebeat/197403)

<div class="topic-metadata">

**Author:** [@sk545](https://discuss.elastic.co/u/sk545)\
**Replies:** 4\
**Last updated:** [August 30, 2019, 7:17pm UTC](https://discuss.elastic.co/t/s3-bucket-logs-forwarding-to-elastic-search-through-filebeat/197403 "2019-08-30T19:17:02Z")

</div>

I have my application logs present in AWS S3 bucket , Now i am wondering is there any way to forward those logs to elastic search through file beat ?

---

## [Syslog Input -\> Cisco ASA not fully parsing](https://discuss.elastic.co/t/syslog-input-cisco-asa-not-fully-parsing/197559)

<div class="topic-metadata">

**Author:** [@ztune](https://discuss.elastic.co/u/ztune)\
**Replies:** 0\
**Last updated:** [August 30, 2019, 5:02pm UTC](https://discuss.elastic.co/t/syslog-input-cisco-asa-not-fully-parsing/197559 "2019-08-30T17:02:27Z")

</div>

Hi Everyone, I've got an issue I'm hoping someone can help with. I have a Win2016 server as my log collection server, with Filebeat running Syslog input and it outputs directly to Elasticsearch. The problem I'm having i…

---

## [Kubernetes labels are missing in pod and container metricsets](https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 3\
**Last updated:** [August 30, 2019, 1:41pm UTC](https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505 "2019-08-30T13:41:36Z")

</div>

Hi, I am currently evaluating different approaches to filter filter for deployments / statefulsets and show the child pods and containers including their metrics. I noticed that in all metricsets having the prefix sta…

---

## [Issue with systemd startup and keystore values](https://discuss.elastic.co/t/issue-with-systemd-startup-and-keystore-values/197520)

<div class="topic-metadata">

**Author:** [@stwilliams](https://discuss.elastic.co/u/stwilliams)\
**Replies:** 1\
**Last updated:** [August 30, 2019, 1:23pm UTC](https://discuss.elastic.co/t/issue-with-systemd-startup-and-keystore-values/197520 "2019-08-30T13:23:16Z")

</div>

We are rolling out a cluster with security high on the list of targets - so using SSL, authentication etc In our filebeat.yml, we have output.elasticsearch.username = "${ES\_USER}" output.elasticsearch.password = "${ES…

---

## [Filebeat stops parsing the data after service update and swich to another instance](https://discuss.elastic.co/t/filebeat-stops-parsing-the-data-after-service-update-and-swich-to-another-instance/197504)

<div class="topic-metadata">

**Author:** [@Suresh\_Pal](https://discuss.elastic.co/u/Suresh_Pal)\
**Replies:** 0\
**Last updated:** [August 30, 2019, 11:11am UTC](https://discuss.elastic.co/t/filebeat-stops-parsing-the-data-after-service-update-and-swich-to-another-instance/197504 "2019-08-30T11:11:40Z")

</div>

Hi Team, Hope you all are doing great. I'm using filebeat 6.3.2 for parsing microservices logs running on ECS . Whenever my service is updated a new container is launched in another EC2 instance and filebeat stops par…

---

## [Metricbeat exception from mongodb module](https://discuss.elastic.co/t/metricbeat-exception-from-mongodb-module/197503)

<div class="topic-metadata">

**Author:** [@Debashish\_Sen](https://discuss.elastic.co/u/Debashish_Sen)\
**Replies:** 0\
**Last updated:** [August 30, 2019, 11:05am UTC](https://discuss.elastic.co/t/metricbeat-exception-from-mongodb-module/197503 "2019-08-30T11:05:14Z")

</div>

Unable to fetch metrics from mongos router using Metricbeat mongodb module Getting following response from metricbeat in kibana discover tab. { "\_index":"metricbeat-6.6.1-2019.08.30", "\_type":"doc", "\_id":"TPR…

---

## [Filebeat Stats API shows negative active event count](https://discuss.elastic.co/t/filebeat-stats-api-shows-negative-active-event-count/197019)

<div class="topic-metadata">

**Author:** [@Chuan\_Li](https://discuss.elastic.co/u/Chuan_Li)\
**Replies:** 0\
**Last updated:** [August 28, 2019, 1:47am UTC](https://discuss.elastic.co/t/filebeat-stats-api-shows-negative-active-event-count/197019 "2019-08-28T01:47:39Z")

</div>

Filebeat version: 6.7.2 Background: Filebeat deployed as DaemonSet on Kubernetes with about a hundred nodes, sending logs to logstash via proxy; the workload is about 20-40 k messages/minutes. I noticed that the Stats …

---

## [Filebeat docker help](https://discuss.elastic.co/t/filebeat-docker-help/197161)

<div class="topic-metadata">

**Author:** [@Phil\_Brady](https://discuss.elastic.co/u/Phil_Brady)\
**Replies:** 3\
**Last updated:** [August 30, 2019, 9:10am UTC](https://discuss.elastic.co/t/filebeat-docker-help/197161 "2019-08-30T09:10:17Z")

</div>

Sorry if these questions have been answered before, I am new to elastic and cannot find the answers I have an entry in my docker logs that looks like this Wed, 28 Aug 2019 15:40:23 GMT - info: Prematch events sync pro…

---

## [Filebeat memory issues](https://discuss.elastic.co/t/filebeat-memory-issues/197297)

<div class="topic-metadata">

**Author:** [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Replies:** 4\
**Last updated:** [August 30, 2019, 8:01am UTC](https://discuss.elastic.co/t/filebeat-memory-issues/197297 "2019-08-30T08:01:06Z")

</div>

Here's a (not very) pretty picture - the filebeats in our K8s cluster appear to start up, then over not-very-long increase their memory consumption until they crash with out of memory, then restart. This is version 6.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=320)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=322)
