# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=322

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 323

---

## [Delete explanation in message field](https://discuss.elastic.co/t/delete-explanation-in-message-field/196554)

<div class="topic-metadata">

**Author:** [@herrBez](https://discuss.elastic.co/u/herrBez)\
**Replies:** 1\
**Last updated:** [August 30, 2019, 6:54am UTC](https://discuss.elastic.co/t/delete-explanation-in-message-field/196554 "2019-08-30T06:54:07Z")

</div>

Hi There, I am importing logs with winlogbeat 7.3.0. All works fine :slight\_smile: However, some of the events I am collecting contains sometimes an explanation inside a message, e.g., 4679 https://www.ultimatewindow…

---

## [Filebeat: anything to know about rotating logfiles?](https://discuss.elastic.co/t/filebeat-anything-to-know-about-rotating-logfiles/197331)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 2\
**Last updated:** [August 30, 2019, 6:26am UTC](https://discuss.elastic.co/t/filebeat-anything-to-know-about-rotating-logfiles/197331 "2019-08-30T06:26:05Z")

</div>

Hi, I am monitoring a jboss application with a lot of logfiles. Log4j is taking care of log rotating. Files are rotated when a given size is reached and a suffix is added. In the past I always told filebeat to use \*.lo…

---

## [Uptime showing No Data available](https://discuss.elastic.co/t/uptime-showing-no-data-available/197046)

<div class="topic-metadata">

**Author:** [@vishal.k](https://discuss.elastic.co/u/vishal.k)\
**Replies:** 1\
**Last updated:** [August 30, 2019, 1:42am UTC](https://discuss.elastic.co/t/uptime-showing-no-data-available/197046 "2019-08-30T01:42:26Z")

</div>

Hi Team, Need Urgent Help. By mistakly I have deleted heartbeat index from elastic search so now Uptime is showing as No Data available. So, I reinstalled heartbeart rpm and started service back. Now I can see new ind…

---

## [Create two index with winlogbeat 7.3](https://discuss.elastic.co/t/create-two-index-with-winlogbeat-7-3/197427)

<div class="topic-metadata">

**Author:** [@maria1](https://discuss.elastic.co/u/maria1)\
**Replies:** 0\
**Last updated:** [August 30, 2019, 12:53am UTC](https://discuss.elastic.co/t/create-two-index-with-winlogbeat-7-3/197427 "2019-08-30T00:53:43Z")

</div>

Hello, I'm trying to configure winlogbeat to create 2 index, one for each user. I Know I can configure this using this command: setup.template.name: 'new-index' setup.template.pattern: 'new-index-\*' output.elasticse…

---

## [Filebeat-multiline not working](https://discuss.elastic.co/t/filebeat-multiline-not-working/197378)

<div class="topic-metadata">

**Author:** [@deemanu](https://discuss.elastic.co/u/deemanu)\
**Replies:** 1\
**Last updated:** [August 29, 2019, 10:49pm UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working/197378 "2019-08-29T22:49:44Z")

</div>

Hello , I have below logs to parse .No idea if timestamp in grok is the one which is failing or multiline conf in filebeat .please help Timestamp: 8/19/2019 4:17:15 PM Message: affd Response | 130313 | GetUsageDetails…

---

## [Panic in Redis module](https://discuss.elastic.co/t/panic-in-redis-module/197253)

<div class="topic-metadata">

**Author:** [@jwarren116](https://discuss.elastic.co/u/jwarren116)\
**Replies:** 2\
**Last updated:** [August 29, 2019, 9:07pm UTC](https://discuss.elastic.co/t/panic-in-redis-module/197253 "2019-08-29T21:07:19Z")

</div>

Version: Metricbeat 6.8.2 Operating System: Ubuntu 16.04 I'm regularly seeing this panic in the Redis module. Metricbeat seems to recover and continue running based on logs, but no further metrics are shipped to my out…

---

## [Filebeat on Kubernetes not collecting logs from master nodes](https://discuss.elastic.co/t/filebeat-on-kubernetes-not-collecting-logs-from-master-nodes/197229)

<div class="topic-metadata">

**Author:** [@colincoghill](https://discuss.elastic.co/u/colincoghill)\
**Replies:** 1\
**Last updated:** [August 29, 2019, 8:56pm UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-not-collecting-logs-from-master-nodes/197229 "2019-08-29T20:56:17Z")

</div>

Hi, While trying to investigate a problem with our kubernetes cluster I discovered that our filebeat install was not collecting logs from anything running on the "master" nodes. It did when I initially installed filebea…

---

## [Cannot access /metrics path, does in\_cluster and kubeconfig work for apiserver in kubernetes modules?](https://discuss.elastic.co/t/cannot-access-metrics-path-does-in-cluster-and-kubeconfig-work-for-apiserver-in-kubernetes-modules/197281)

<div class="topic-metadata">

**Author:** [@KielChan](https://discuss.elastic.co/u/KielChan)\
**Replies:** 1\
**Last updated:** [August 29, 2019, 8:23pm UTC](https://discuss.elastic.co/t/cannot-access-metrics-path-does-in-cluster-and-kubeconfig-work-for-apiserver-in-kubernetes-modules/197281 "2019-08-29T20:23:26Z")

</div>

my metric beat cannot access apiserver:8443/metrics, even though it has privileges to access apiserver

---

## [Check Docker Filebeat in VM is sending to Docker logstash in another VM](https://discuss.elastic.co/t/check-docker-filebeat-in-vm-is-sending-to-docker-logstash-in-another-vm/197411)

<div class="topic-metadata">

**Author:** [@jeffery](https://discuss.elastic.co/u/jeffery)\
**Replies:** 1\
**Last updated:** [August 29, 2019, 7:57pm UTC](https://discuss.elastic.co/t/check-docker-filebeat-in-vm-is-sending-to-docker-logstash-in-another-vm/197411 "2019-08-29T19:57:49Z")

</div>

LIke the title says, I have two VM's one has filebeat reading at a location, and the other has Logstash (and the rest of the ElasticSearch stack) on the other VM. I've configured my filebeat to be: filebeat.inputs: t…

---

## [How can we read log files with size greater than zero](https://discuss.elastic.co/t/how-can-we-read-log-files-with-size-greater-than-zero/196271)

<div class="topic-metadata">

**Author:** [@Jeetu19](https://discuss.elastic.co/u/Jeetu19)\
**Replies:** 2\
**Last updated:** [August 29, 2019, 6:51pm UTC](https://discuss.elastic.co/t/how-can-we-read-log-files-with-size-greater-than-zero/196271 "2019-08-29T18:51:51Z")

</div>

Hi we have situation where abinitio jobs creating .err files every day. but if there is "no error" file size of zero byte. If there is error then file size is greater than zero. Almost more than 20000 thousand error…

---

## [Wrong filebeat hostname in logs](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080)

<div class="topic-metadata">

**Author:** [@sjorda20](https://discuss.elastic.co/u/sjorda20)\
**Replies:** 4\
**Last updated:** [August 29, 2019, 6:44pm UTC](https://discuss.elastic.co/t/wrong-filebeat-hostname-in-logs/195080 "2019-08-29T18:44:12Z")

</div>

I have 100 systems that are sending rsyslog messages to a syslog server. I have installed the ELK stack and filebeats on that server. Filebeats is configured to monitor the logs that are being populated by syslog and s…

---

## [Is config reload logged?](https://discuss.elastic.co/t/is-config-reload-logged/197067)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [August 29, 2019, 6:18pm UTC](https://discuss.elastic.co/t/is-config-reload-logged/197067 "2019-08-29T18:18:31Z")

</div>

Hi, I am using config reload on logs like described here: https://www.elastic.co/guide/en/beats/filebeat/current/\_live\_reloading.html #=========================== Filebeat inputs ============================= # Enable …

---

## [Filebeat 7.2.0 autodiscover configuration issues](https://discuss.elastic.co/t/filebeat-7-2-0-autodiscover-configuration-issues/188168)

<div class="topic-metadata">

**Author:** [@dnmahendra](https://discuss.elastic.co/u/dnmahendra)\
**Replies:** 3\
**Last updated:** [August 29, 2019, 4:39pm UTC](https://discuss.elastic.co/t/filebeat-7-2-0-autodiscover-configuration-issues/188168 "2019-08-29T16:39:55Z")

</div>

I am trying to setup filebeat for the kubernetes cluster. I am trying to use autodiscover for my containers. I have istio envoy proxy running on each pod. I am trying to ship those logs to my elastic stack. But, I am get…

---

## [How to configure metricbeat for monitoring system processes](https://discuss.elastic.co/t/how-to-configure-metricbeat-for-monitoring-system-processes/197342)

<div class="topic-metadata">

**Author:** [@evalufran](https://discuss.elastic.co/u/evalufran)\
**Replies:** 3\
**Last updated:** [August 29, 2019, 3:46pm UTC](https://discuss.elastic.co/t/how-to-configure-metricbeat-for-monitoring-system-processes/197342 "2019-08-29T15:46:24Z")

</div>

Hi everyone!!! I'm trying to use metricbeat in order to check system processes status, but i can't understand how to configure metricbeat.yml. I'm working on a linux system. This is my actual config: metricbeat.modul…

---

## [Metricbeat Kafka Module "error in connect: EOF"](https://discuss.elastic.co/t/metricbeat-kafka-module-error-in-connect-eof/193392)

<div class="topic-metadata">

**Author:** [@broccoli](https://discuss.elastic.co/u/broccoli)\
**Replies:** 4\
**Last updated:** [August 29, 2019, 2:07pm UTC](https://discuss.elastic.co/t/metricbeat-kafka-module-error-in-connect-eof/193392 "2019-08-29T14:07:31Z")

</div>

Using the Metricbeat Kafka module, I get the following errors: 2019-08-01T20:31:02.479+0200 INFO kafka/log.go:53 Connected to broker at localhost:9093 (unregistered) 2019-08-01T20:31:02.731+0200 INFO kafka/…

---

## [Errors attemping to compile filebeat 6.3 in AIX with bullfreeware gccgo](https://discuss.elastic.co/t/errors-attemping-to-compile-filebeat-6-3-in-aix-with-bullfreeware-gccgo/197268)

<div class="topic-metadata">

**Author:** [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Replies:** 2\
**Last updated:** [August 29, 2019, 12:14pm UTC](https://discuss.elastic.co/t/errors-attemping-to-compile-filebeat-6-3-in-aix-with-bullfreeware-gccgo/197268 "2019-08-29T12:14:02Z")

</div>

Hello! I'm trying to compile filebeat 6.3 on AIX. I have faced a few error which I have been able to solve searching over the net but I got a few ones about I cannot find anything. The environment: I'm running AIX 7.…

---

## [Combining multiline from Laravel Horizon app](https://discuss.elastic.co/t/combining-multiline-from-laravel-horizon-app/197142)

<div class="topic-metadata">

**Author:** [@Martin\_Ostlund](https://discuss.elastic.co/u/Martin_Ostlund)\
**Replies:** 1\
**Last updated:** [August 29, 2019, 11:47am UTC](https://discuss.elastic.co/t/combining-multiline-from-laravel-horizon-app/197142 "2019-08-29T11:47:42Z")

</div>

Hello, I'm looking for a way to parse and combine a log of this format: \[2019-08-26 13:53:53\]\[83304\] Processing: App\\Jobs\\PublishListingUpdate \[2019-08-26 13:53:53\]\[83303\] Processing: App\\Jobs\\PublishListingUpdate \[2…

---

## [Filebeat Netflow pipeline in 7.3.1 does not load, 7.3.0 does](https://discuss.elastic.co/t/filebeat-netflow-pipeline-in-7-3-1-does-not-load-7-3-0-does/197324)

<div class="topic-metadata">

**Author:** [@HowardtheDuck](https://discuss.elastic.co/u/HowardtheDuck)\
**Replies:** 0\
**Last updated:** [August 29, 2019, 11:26am UTC](https://discuss.elastic.co/t/filebeat-netflow-pipeline-in-7-3-1-does-not-load-7-3-0-does/197324 "2019-08-29T11:26:23Z")

</div>

The Filebeat netflow module for 7.3.1 does not load the pipeline, even when specifically called (e.g. filebeat setup --pipelines --modules netflow). Downgraded to 7.3.0 and all worked as advertised.

---

## [Filebeat 6.8 stdin ssh logs](https://discuss.elastic.co/t/filebeat-6-8-stdin-ssh-logs/197314)

<div class="topic-metadata">

**Author:** [@Serg](https://discuss.elastic.co/u/Serg)\
**Replies:** 1\
**Last updated:** [August 29, 2019, 10:49am UTC](https://discuss.elastic.co/t/filebeat-6-8-stdin-ssh-logs/197314 "2019-08-29T10:49:07Z")

</div>

Hi I want to log ssh user commands (not attempts in auth.log ). I suggested that "stdin" log type could give me that chance. But I don't see any data in filebeat index Where am I wrong? type: stdin enabled: true …

---

## [Script for install and configure file beat on Linux](https://discuss.elastic.co/t/script-for-install-and-configure-file-beat-on-linux/197163)

<div class="topic-metadata">

**Author:** [@sk545](https://discuss.elastic.co/u/sk545)\
**Replies:** 3\
**Last updated:** [August 29, 2019, 7:26am UTC](https://discuss.elastic.co/t/script-for-install-and-configure-file-beat-on-linux/197163 "2019-08-29T07:26:37Z")

</div>

I have several servers those need to be installed with file beat .is there any shell /Ansible/some other way to install file beat on all Linux servers at once instead of manual intervention? TIA

---

## [Need help on Multiline Pattern](https://discuss.elastic.co/t/need-help-on-multiline-pattern/195857)

<div class="topic-metadata">

**Author:** [@lsanbu](https://discuss.elastic.co/u/lsanbu)\
**Replies:** 2\
**Last updated:** [August 29, 2019, 6:15am UTC](https://discuss.elastic.co/t/need-help-on-multiline-pattern/195857 "2019-08-29T06:15:32Z")

</div>

Dear Team, Greetings. I'm new to Elastic/File beat. I'm trying to read a log in the following pattern: \[2019-08-18 19:g19:50,787\]-\[NhdQWhb\_Z3arvCz4zWh3hEo:1353000:10.142.125.44\]- POST /ncs/anc/ANC2250S.do METHOD=next …

---

## [Why packetbeat events failed](https://discuss.elastic.co/t/why-packetbeat-events-failed/197262)

<div class="topic-metadata">

**Author:** [@hyhong](https://discuss.elastic.co/u/hyhong)\
**Replies:** 0\
**Last updated:** [August 29, 2019, 5:46am UTC](https://discuss.elastic.co/t/why-packetbeat-events-failed/197262 "2019-08-29T05:46:51Z")

</div>

In the packetbeat log,only failed number,but I don't know why. I want to know what's meaning whit the field：active/failed/published/retry/total/acked in the log {"active":0,"failed":5219,"published":44789,"retry":14336,"…

---

## [Using Filebeat with Zeek (issue with configuration)](https://discuss.elastic.co/t/using-filebeat-with-zeek-issue-with-configuration/192540)

<div class="topic-metadata">

**Author:** [@michaelberg](https://discuss.elastic.co/u/michaelberg)\
**Replies:** 5\
**Last updated:** [August 29, 2019, 3:39am UTC](https://discuss.elastic.co/t/using-filebeat-with-zeek-issue-with-configuration/192540 "2019-08-29T03:39:44Z")

</div>

Good afternoon everyone! Having a bit of an issue here with configuration and I hoping someone can kick me in the right direction ... Software Running: Latest compiled version of Zeek on a Fedora 30 Server Filebeat 7…

---

## [Problem with "host" field when parsing linux system logs with Filebeat pipeline](https://discuss.elastic.co/t/problem-with-host-field-when-parsing-linux-system-logs-with-filebeat-pipeline/195931)

<div class="topic-metadata">

**Author:** [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Replies:** 2\
**Last updated:** [August 28, 2019, 5:07pm UTC](https://discuss.elastic.co/t/problem-with-host-field-when-parsing-linux-system-logs-with-filebeat-pipeline/195931 "2019-08-28T17:07:21Z")

</div>

When i parse linux auth.log, i get error (in Kibana): error.message: cannot set \[hostname\] with parent object of type \[java.lang.String\] as part of path \[host.hostname\] It looks like I ingest logs in Elastic from ex…

---

## [Beat Service Name Change](https://discuss.elastic.co/t/beat-service-name-change/197125)

<div class="topic-metadata">

**Author:** [@tyler\_hilsabeck](https://discuss.elastic.co/u/tyler_hilsabeck)\
**Replies:** 0\
**Last updated:** [August 28, 2019, 1:34pm UTC](https://discuss.elastic.co/t/beat-service-name-change/197125 "2019-08-28T13:34:18Z")

</div>

Is there any reason why the service install script on Windows doesn't use a service name that can be set in the \*beat.yml file? To change the install name you have to manually edit the powershell script. Would this be a …

---

## [Filebeat not picking up logs from additional files specified for system module](https://discuss.elastic.co/t/filebeat-not-picking-up-logs-from-additional-files-specified-for-system-module/197143)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [August 28, 2019, 2:58pm UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-logs-from-additional-files-specified-for-system-module/197143 "2019-08-28T14:58:07Z")

</div>

TL;DR We are using the filebeat system module to monitor our Docker logs. It worked correctly until our Docker team moved the log location from /var/log/messages. Now it no longer picks up the logs, even though we've add…

---

## [Filebeat can't load template due to circuitbreaker](https://discuss.elastic.co/t/filebeat-cant-load-template-due-to-circuitbreaker/197004)

<div class="topic-metadata">

**Author:** [@rectalogic](https://discuss.elastic.co/u/rectalogic)\
**Replies:** 1\
**Last updated:** [August 28, 2019, 3:01pm UTC](https://discuss.elastic.co/t/filebeat-cant-load-template-due-to-circuitbreaker/197004 "2019-08-28T15:01:09Z")

</div>

I'm upgrading elasticsearch/filebeat from 6.5.2 to 7.3.0 filebeat is failing to start with this error: Error loading Elasticsearch template: could not load template. Elasticsearch returned: couldn't load template: coul…

---

## [Filebeat, Mapper Plugin & Adding \_size to all new logs](https://discuss.elastic.co/t/filebeat-mapper-plugin-adding-size-to-all-new-logs/197102)

<div class="topic-metadata">

**Author:** [@Ivan\_Artemov](https://discuss.elastic.co/u/Ivan_Artemov)\
**Replies:** 0\
**Last updated:** [August 28, 2019, 11:43am UTC](https://discuss.elastic.co/t/filebeat-mapper-plugin-adding-size-to-all-new-logs/197102 "2019-08-28T11:43:14Z")

</div>

Elasticsearch 6.8.2 Filebeat 6.8.2 I try to add \_size field to all our documents to analyze statistics I deploy elk-stack in docker with mapper pluging and want to write to-do list for steps, required for migrate our …

---

## [Filebeat - json imports](https://discuss.elastic.co/t/filebeat-json-imports/196568)

<div class="topic-metadata">

**Author:** [@VinceTempera](https://discuss.elastic.co/u/VinceTempera)\
**Replies:** 1\
**Last updated:** [August 28, 2019, 12:11pm UTC](https://discuss.elastic.co/t/filebeat-json-imports/196568 "2019-08-28T12:11:34Z")

</div>

Need some help and hopefully its something simple I have overlooked. I am trying to import a JSON file, single line records and when I go into Kibana, to view the data in discover, I dont see any of the fields if I use a…

---

## [Can I change default port of Filebeat "5044" to someother port](https://discuss.elastic.co/t/can-i-change-default-port-of-filebeat-5044-to-someother-port/197039)

<div class="topic-metadata">

**Author:** [@priya94](https://discuss.elastic.co/u/priya94)\
**Replies:** 4\
**Last updated:** [August 28, 2019, 9:35am UTC](https://discuss.elastic.co/t/can-i-change-default-port-of-filebeat-5044-to-someother-port/197039 "2019-08-28T09:35:32Z")

</div>

Hi All, I am new to ELK I am trying to run multiple filebeat instances on same machine to send different logs to logstash,then i am sending the logs to elasticserach with different index name. But Logstash is not reco…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=321)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=323)
