# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=323

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 324

---

## [Graylog-sidecar and auditbeats - ERRO\[0040\] \[auditbeat\] Unable to validate configuration, timeout reached](https://discuss.elastic.co/t/graylog-sidecar-and-auditbeats-erro-0040-auditbeat-unable-to-validate-configuration-timeout-reached/197075)

<div class="topic-metadata">

**Author:** [@pandzioo](https://discuss.elastic.co/u/pandzioo)\
**Replies:** 0\
**Last updated:** [August 28, 2019, 9:34am UTC](https://discuss.elastic.co/t/graylog-sidecar-and-auditbeats-erro-0040-auditbeat-unable-to-validate-configuration-timeout-reached/197075 "2019-08-28T09:34:11Z")

</div>

First of all I would like to say Hello :slight\_smile: I would like to say that I'm new in Elastic topics - I need help. I installed elastic search and graylog for collecting logs from linux environment. I have many li…

---

## [Filebeat: Split message field in kibana into several fields](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 5\
**Last updated:** [August 28, 2019, 9:19am UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676 "2019-08-28T09:19:36Z")

</div>

Do I need logstash to transform below log message received in Kibana from filebeat \[2019-08-25T19:23:07.489Z\] "GET /health HTTP/1.1" 200 - "-" "-" 0 15 22 22 "-" "kube-probe/1.13" "68e1cfbd-345f-45cd-9b86-2b4b17ab3ade"…

---

## [Add IP Address field using winlogbeat](https://discuss.elastic.co/t/add-ip-address-field-using-winlogbeat/196647)

<div class="topic-metadata">

**Author:** [@JustinJ](https://discuss.elastic.co/u/JustinJ)\
**Replies:** 2\
**Last updated:** [August 28, 2019, 4:48am UTC](https://discuss.elastic.co/t/add-ip-address-field-using-winlogbeat/196647 "2019-08-28T04:48:46Z")

</div>

Is there any way we can add the ip address field in the forwarded logs. In windows events, ip address field is empty. It is only having hostname. Is there any way we can parse the ip address using the hostname and add it…

---

## [Timestamp data is missing from winlog beat to logstash](https://discuss.elastic.co/t/timestamp-data-is-missing-from-winlog-beat-to-logstash/196918)

<div class="topic-metadata">

**Author:** [@Harish\_Babu\_B](https://discuss.elastic.co/u/Harish_Babu_B)\
**Replies:** 2\
**Last updated:** [August 28, 2019, 4:22am UTC](https://discuss.elastic.co/t/timestamp-data-is-missing-from-winlog-beat-to-logstash/196918 "2019-08-28T04:22:02Z")

</div>

Hii friends I am trying to collect the data sent from the winlog beat to the logstash. while i'm doing it i'm unable to get the timestamp of the event generated. I'm getting only the message but I also need timestamp to…

---

## [Filebeat not picking up all log messages from container](https://discuss.elastic.co/t/filebeat-not-picking-up-all-log-messages-from-container/197010)

<div class="topic-metadata">

**Author:** [@dgarson](https://discuss.elastic.co/u/dgarson)\
**Replies:** 0\
**Last updated:** [August 27, 2019, 10:06pm UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-all-log-messages-from-container/197010 "2019-08-27T22:06:18Z")

</div>

Hi everyone. I'm trying to get filebeat working in kubernetes to ship logs from containers running on the same node over to Logstash. I am encountering a bit of a bizarre problem. Some log messages appear to make it from…

---

## [Kafka, Zstandard Compression, 2.3.0](https://discuss.elastic.co/t/kafka-zstandard-compression-2-3-0/197008)

<div class="topic-metadata">

**Author:** [@landonix](https://discuss.elastic.co/u/landonix)\
**Replies:** 0\
**Last updated:** [August 27, 2019, 9:45pm UTC](https://discuss.elastic.co/t/kafka-zstandard-compression-2-3-0/197008 "2019-08-27T21:45:49Z")

</div>

Are there any plans to continue adding features available in the latest versions of Kafka? As an example, ZStandard support for compression is one such feature that provides considerable cpu/network savings for beats cli…

---

## [Postgresql Dashboard for metricbeat6.4.0](https://discuss.elastic.co/t/postgresql-dashboard-for-metricbeat6-4-0/196884)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 2\
**Last updated:** [August 27, 2019, 5:51pm UTC](https://discuss.elastic.co/t/postgresql-dashboard-for-metricbeat6-4-0/196884 "2019-08-27T17:51:13Z")

</div>

Hello Team, We are using metricbeat6.4.0 and want to monitor postgresql database using metricbeat. We have postgresql.yml module in modules.d directory but postgresql dashboard is not available. For mongodb and mysql d…

---

## [ERR Connecting error publishing events (retrying): dial tcp 127.0.0.1:5044: getsockopt: connection refused](https://discuss.elastic.co/t/err-connecting-error-publishing-events-retrying-dial-tcp-127-0-0-1-getsockopt-connection-refused/196933)

<div class="topic-metadata">

**Author:** [@subhasmita\_mishra](https://discuss.elastic.co/u/subhasmita_mishra)\
**Replies:** 1\
**Last updated:** [August 27, 2019, 5:38pm UTC](https://discuss.elastic.co/t/err-connecting-error-publishing-events-retrying-dial-tcp-127-0-0-1-getsockopt-connection-refused/196933 "2019-08-27T17:38:37Z")

</div>

ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp localhost:5044: connect: connection refused/etc filebeat.yml file: ilebeat.prospectors: - paths: - /var/log/\*.log inp…

---

## [Creating file system visualization as per component wise?](https://discuss.elastic.co/t/creating-file-system-visualization-as-per-component-wise/196976)

<div class="topic-metadata">

**Author:** [@Bob94](https://discuss.elastic.co/u/Bob94)\
**Replies:** 1\
**Last updated:** [August 27, 2019, 4:47pm UTC](https://discuss.elastic.co/t/creating-file-system-visualization-as-per-component-wise/196976 "2019-08-27T16:47:53Z")

</div>

Hi guys, Lets just assume i have 3 components that is used to perform write and read operation in file system. Currently im using metricbeat to load and catch the visualization of the read and writes data on specific d…

---

## [Filebeat timestamp Ubuntu and CentOS](https://discuss.elastic.co/t/filebeat-timestamp-ubuntu-and-centos/196501)

<div class="topic-metadata">

**Author:** [@MrSnaKe](https://discuss.elastic.co/u/MrSnaKe)\
**Replies:** 3\
**Last updated:** [August 27, 2019, 9:56am UTC](https://discuss.elastic.co/t/filebeat-timestamp-ubuntu-and-centos/196501 "2019-08-27T09:56:31Z")

</div>

Hello, I have a problem with local time during send logs via filebeat and module system. In ubuntu uname -a Linux ub 4.15.0-58-generic #64-Ubuntu SMP Tue Aug 6 11:12:41 UTC 2019 x86\_64 x86\_64 x86\_64 GNU/Linux I add …

---

## [Why filebeat is SOOO slow in reading files (from SSD): only got 27MBPs when output to /dev/null console?](https://discuss.elastic.co/t/why-filebeat-is-sooo-slow-in-reading-files-from-ssd-only-got-27mbps-when-output-to-dev-null-console/196401)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 2\
**Last updated:** [August 26, 2019, 6:02pm UTC](https://discuss.elastic.co/t/why-filebeat-is-sooo-slow-in-reading-files-from-ssd-only-got-27mbps-when-output-to-dev-null-console/196401 "2019-08-26T18:02:12Z")

</div>

Hello, As comparison, a simple single threaded program can read at 3GBps+ on the same machine. However, when we allocate 7 cores to filebeat, the maximum throughput i got from filebeat is only about 27MBps. allocating…

---

## [Using Filebeat with Logstash breaks Metricbeat](https://discuss.elastic.co/t/using-filebeat-with-logstash-breaks-metricbeat/195363)

<div class="topic-metadata">

**Author:** [@carson](https://discuss.elastic.co/u/carson)\
**Replies:** 10\
**Last updated:** [August 26, 2019, 7:24pm UTC](https://discuss.elastic.co/t/using-filebeat-with-logstash-breaks-metricbeat/195363 "2019-08-26T19:24:38Z")

</div>

I'm using a default configuration for Filebeat, and a standard configuration for logstash to input from beats and output to elasticsearch. Metricbeat works fine, but once I start an instance of Filebeat, the metricbeat …

---

## [Categorization of logs in windows](https://discuss.elastic.co/t/categorization-of-logs-in-windows/194491)

<div class="topic-metadata">

**Author:** [@Camilo\_Franco](https://discuss.elastic.co/u/Camilo_Franco)\
**Replies:** 2\
**Last updated:** [August 26, 2019, 7:13pm UTC](https://discuss.elastic.co/t/categorization-of-logs-in-windows/194491 "2019-08-26T19:13:48Z")

</div>

I am trying to take the records to create user account, delete user account and modify user account. I have also been asked to take audit events on files and folders, this send it to logstash. I have already installed …

---

## [Filebeat Couldn't Send Logs to Logstash](https://discuss.elastic.co/t/filebeat-couldnt-send-logs-to-logstash/196334)

<div class="topic-metadata">

**Author:** [@kolten](https://discuss.elastic.co/u/kolten)\
**Replies:** 6\
**Last updated:** [August 26, 2019, 5:20pm UTC](https://discuss.elastic.co/t/filebeat-couldnt-send-logs-to-logstash/196334 "2019-08-26T17:20:54Z")

</div>

Hi, I get this error everytime. 2019-08-22T16:41:22.957+0300 ERROR logstash/async.go:256 Failed to publish events caused by: write tcp 172.30.10.5:49924-\>172.30.10.112:5046: wsasend: An existing connection was forcibly…

---

## [File beats not sending logs to logshatsh](https://discuss.elastic.co/t/file-beats-not-sending-logs-to-logshatsh/196659)

<div class="topic-metadata">

**Author:** [@Seetharaman\_K](https://discuss.elastic.co/u/Seetharaman_K)\
**Replies:** 4\
**Last updated:** [August 26, 2019, 5:11pm UTC](https://discuss.elastic.co/t/file-beats-not-sending-logs-to-logshatsh/196659 "2019-08-26T17:11:00Z")

</div>

file beats log i know this might be upteenth time a similar kind of question is asked here , but even after refering all similar threads am not able to conclude what is the problem why my file beat is not harvesting th…

---

## [Winlogbeat Support for Windows Server 2019 and Semi-Annual Channel](https://discuss.elastic.co/t/winlogbeat-support-for-windows-server-2019-and-semi-annual-channel/196670)

<div class="topic-metadata">

**Author:** [@pcgeek86](https://discuss.elastic.co/u/pcgeek86)\
**Replies:** 1\
**Last updated:** [August 26, 2019, 3:52pm UTC](https://discuss.elastic.co/t/winlogbeat-support-for-windows-server-2019-and-semi-annual-channel/196670 "2019-08-26T15:52:00Z")

</div>

Hello, I was taking a look at the Elastic Support Matrix and noticed that Windows Server 2019 and Semi-Annual Channel weren't listed under the winlogbeat project. Are these platforms supported by winlogbeat, or did supp…

---

## [Issue installing metricbeat](https://discuss.elastic.co/t/issue-installing-metricbeat/196598)

<div class="topic-metadata">

**Author:** [@Mezoloth](https://discuss.elastic.co/u/Mezoloth)\
**Replies:** 15\
**Last updated:** [August 26, 2019, 3:12pm UTC](https://discuss.elastic.co/t/issue-installing-metricbeat/196598 "2019-08-26T15:12:01Z")

</div>

I am following the setup guide from elastic for metric beat, and get the following when I run " metricbeat setup -e" 019-08-23T20:48:31.017Z INFO kibana/client.go:117 Kibana url: http://localhost:5601 201…

---

## [Winlogbeat not working](https://discuss.elastic.co/t/winlogbeat-not-working/196789)

<div class="topic-metadata">

**Author:** [@NewmazN24](https://discuss.elastic.co/u/NewmazN24)\
**Replies:** 4\
**Last updated:** [August 26, 2019, 2:52pm UTC](https://discuss.elastic.co/t/winlogbeat-not-working/196789 "2019-08-26T14:52:01Z")

</div>

Hey Guys, Elasticsearch + Kibana are on the same server - CentOS7. I can reach my server without issue and curl ports. From a Windows 10 test machine, Winlogbeat is installed correctly according to the doc. I copied th…

---

## [Journalbeat 7.2 repeating last log in an infinite loop](https://discuss.elastic.co/t/journalbeat-7-2-repeating-last-log-in-an-infinite-loop/196512)

<div class="topic-metadata">

**Author:** [@rajatrj16](https://discuss.elastic.co/u/rajatrj16)\
**Replies:** 1\
**Last updated:** [August 26, 2019, 2:03pm UTC](https://discuss.elastic.co/t/journalbeat-7-2-repeating-last-log-in-an-infinite-loop/196512 "2019-08-26T14:03:39Z")

</div>

Hello, I am taking logs from journalctl and giving input in logstash, then logstash sent it to kibana. The main concern is the last log is repeating in an infinite loop and journalbeat-7.2 is publishing event in about …

---

## [Journalbeat 6.7 repeats old log records after rotation](https://discuss.elastic.co/t/journalbeat-6-7-repeats-old-log-records-after-rotation/174940)

<div class="topic-metadata">

**Author:** [@John\_Lemsky](https://discuss.elastic.co/u/John_Lemsky)\
**Replies:** 4\
**Last updated:** [August 26, 2019, 2:02pm UTC](https://discuss.elastic.co/t/journalbeat-6-7-repeats-old-log-records-after-rotation/174940 "2019-08-26T14:02:15Z")

</div>

Hello, Currently, I have the following setup. One machine with installed systemd-journal-upload and another one with systemd-journal-remote. systemd-journal-remote write all received logs into the dedicated directory. J…

---

## [Filebeat to Logstash --\> DBG \[transport\] handle error: EOF](https://discuss.elastic.co/t/filebeat-to-logstash-dbg-transport-handle-error-eof/196735)

<div class="topic-metadata">

**Author:** [@andreatera](https://discuss.elastic.co/u/andreatera)\
**Replies:** 0\
**Last updated:** [August 26, 2019, 9:17am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-dbg-transport-handle-error-eof/196735 "2019-08-26T09:17:16Z")

</div>

We have the following Filebeat 6.1.3 conf: filebeat.prospectors: - type: log paths: - /usr/share/filebeat/taifunlogs/server.log output.logstash: hosts: \["xxxxxx.com:443"\] bulk\_max\_size: 999999999 logg…

---

## [It seems like memory leaks](https://discuss.elastic.co/t/it-seems-like-memory-leaks/196718)

<div class="topic-metadata">

**Author:** [@judy1](https://discuss.elastic.co/u/judy1)\
**Replies:** 0\
**Last updated:** [August 26, 2019, 7:02am UTC](https://discuss.elastic.co/t/it-seems-like-memory-leaks/196718 "2019-08-26T07:02:11Z")

</div>

Hi I've set up a filebeat service (Two 6.2.1 & One 5.5.1) running on ubuntu. Memory is used always near 100%. The memory not released all the time. It seems like memory leaks. filebeat.yml - 6.2.1 filebeat.prospec…

---

## [Packet is loss](https://discuss.elastic.co/t/packet-is-loss/196715)

<div class="topic-metadata">

**Author:** [@hyhong](https://discuss.elastic.co/u/hyhong)\
**Replies:** 0\
**Last updated:** [August 26, 2019, 6:19am UTC](https://discuss.elastic.co/t/packet-is-loss/196715 "2019-08-26T06:19:35Z")

</div>

The packet is loss and debug log as follow: 2019-08-26T14:06:32.611+0800 INFO \[monitoring\] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":490,"time":{"ms…

---

## [While shipping the server logs through filebeat to elasticsearch via logstash , most of the entries are missing](https://discuss.elastic.co/t/while-shipping-the-server-logs-through-filebeat-to-elasticsearch-via-logstash-most-of-the-entries-are-missing/195848)

<div class="topic-metadata">

**Author:** [@Alok](https://discuss.elastic.co/u/Alok)\
**Replies:** 2\
**Last updated:** [August 26, 2019, 5:14am UTC](https://discuss.elastic.co/t/while-shipping-the-server-logs-through-filebeat-to-elasticsearch-via-logstash-most-of-the-entries-are-missing/195848 "2019-08-26T05:14:35Z")

</div>

We are trying to ship logs through filebeat to elasticsearch but unfortunately all the logs are getting ingested to Elasticsearch. We have tried both ways - (a)Filebeat to Elastic search directly and (b) From Filebeat to…

---

## [Capturing DNS @ Packetbeat](https://discuss.elastic.co/t/capturing-dns-packetbeat/196692)

<div class="topic-metadata">

**Author:** [@kaipeng.tan](https://discuss.elastic.co/u/kaipeng.tan)\
**Replies:** 0\
**Last updated:** [August 26, 2019, 3:25am UTC](https://discuss.elastic.co/t/capturing-dns-packetbeat/196692 "2019-08-26T03:25:47Z")

</div>

Hi, I am currently doing research with Packetbeat for some project. I did realize the DNS was captured in a JSON, msg with Query and Answer. Just wonder is there any configuration that I could have get the result in both…

---

## [How to monitor CPU, and other device, temps?](https://discuss.elastic.co/t/how-to-monitor-cpu-and-other-device-temps/196679)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 1\
**Last updated:** [August 26, 2019, 2:50am UTC](https://discuss.elastic.co/t/how-to-monitor-cpu-and-other-device-temps/196679 "2019-08-26T02:50:10Z")

</div>

Is there an up to date means that would allow me to monitor my local system temperatures? CPU, GPU, HDD's, etc. This is on a Linux based machine, so I did try lmsensorsbeat. But it seems to be pretty out of date. I'm ru…

---

## [How do we install and configure file beat on RHEL Linux](https://discuss.elastic.co/t/how-do-we-install-and-configure-file-beat-on-rhel-linux/196675)

<div class="topic-metadata">

**Author:** [@sk545](https://discuss.elastic.co/u/sk545)\
**Replies:** 1\
**Last updated:** [August 26, 2019, 2:45am UTC](https://discuss.elastic.co/t/how-do-we-install-and-configure-file-beat-on-rhel-linux/196675 "2019-08-26T02:45:42Z")

</div>

can anyone please provide me the documentation for installation and configuring file beat on RHEL Linux.

---

## [Metricbeat service error : Stopped Metricbeat is a lightweight shipper for metrics](https://discuss.elastic.co/t/metricbeat-service-error-stopped-metricbeat-is-a-lightweight-shipper-for-metrics/193315)

<div class="topic-metadata">

**Author:** [@abhijalan87](https://discuss.elastic.co/u/abhijalan87)\
**Replies:** 2\
**Last updated:** [August 24, 2019, 4:45pm UTC](https://discuss.elastic.co/t/metricbeat-service-error-stopped-metricbeat-is-a-lightweight-shipper-for-metrics/193315 "2019-08-24T16:45:59Z")

</div>

Hello Everyone, any idea about the below error? when I try to start metricbeat service, I am getting below error. systemctl status metricbeat ● metricbeat.service - Metricbeat is a lightweight shipper for metrics. …

---

## [Filebeat 7.3.0 with kubernetes autodiscover and nginx module creating duplicate log entries](https://discuss.elastic.co/t/filebeat-7-3-0-with-kubernetes-autodiscover-and-nginx-module-creating-duplicate-log-entries/196623)

<div class="topic-metadata">

**Author:** [@chrisferry](https://discuss.elastic.co/u/chrisferry)\
**Replies:** 0\
**Last updated:** [August 24, 2019, 2:35pm UTC](https://discuss.elastic.co/t/filebeat-7-3-0-with-kubernetes-autodiscover-and-nginx-module-creating-duplicate-log-entries/196623 "2019-08-24T14:35:44Z")

</div>

Running filebeat 7.3.0 and receiving duplicate log entries with two differences. Specifically fileset.name: access|error event.dataset nginx.access|nginx.error The log is identical otherwise. Watching the docker log…

---

## [Can't send logs from filebeats to logstash](https://discuss.elastic.co/t/cant-send-logs-from-filebeats-to-logstash/196492)

<div class="topic-metadata">

**Author:** [@rajdeep101](https://discuss.elastic.co/u/rajdeep101)\
**Replies:** 4\
**Last updated:** [August 24, 2019, 6:41am UTC](https://discuss.elastic.co/t/cant-send-logs-from-filebeats-to-logstash/196492 "2019-08-24T06:41:37Z")

</div>

Filebeats wont let me exclude output.elasticsearch from filebeat.yml and would give and error "Exiting: Index management requested but the Elasticsearch output is not configured/enabled". The setup runs without error wh…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=322)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=324)
