# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=324

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 325

---

## [Expected log for successful FileBeats =\> Logstash integration](https://discuss.elastic.co/t/expected-log-for-successful-filebeats-logstash-integration/196544)

<div class="topic-metadata">

**Author:** [@payneb25827](https://discuss.elastic.co/u/payneb25827)\
**Replies:** 1\
**Last updated:** [August 23, 2019, 11:29pm UTC](https://discuss.elastic.co/t/expected-log-for-successful-filebeats-logstash-integration/196544 "2019-08-23T23:29:29Z")

</div>

Hello! Can anyone confirm that this is the expected output of filebeats when it successfully harvests and ships the associated data to logstash? filebeats.yml: filebeat.inputs: - type: log paths: - c:\\elk\\logs\\t…

---

## [Change auditd modules index name](https://discuss.elastic.co/t/change-auditd-modules-index-name/196054)

<div class="topic-metadata">

**Author:** [@Mohammad.ali](https://discuss.elastic.co/u/Mohammad.ali)\
**Replies:** 2\
**Last updated:** [August 23, 2019, 6:26pm UTC](https://discuss.elastic.co/t/change-auditd-modules-index-name/196054 "2019-08-23T18:26:34Z")

</div>

Hello everyone i enable filebeat audit modules but the question is how can i change the default index name which is filebeat\*?

---

## [Filebeat custom log files / how to disable default module field mappings](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195)

<div class="topic-metadata">

**Author:** [@tishma](https://discuss.elastic.co/u/tishma)\
**Replies:** 4\
**Last updated:** [August 23, 2019, 4:18pm UTC](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195 "2019-08-23T16:18:55Z")

</div>

I'm using filebeat to read log files that are not supported out of the box, for elasticsearch indexing. The thing is that I get 1000+ field mappings that appear to be coming from default filebeat modules (apache, nginx,…

---

## [Metricbeat redis error while retrieving INFO and KEYSPACE stats](https://discuss.elastic.co/t/metricbeat-redis-error-while-retrieving-info-and-keyspace-stats/196555)

<div class="topic-metadata">

**Author:** [@vishwanathh](https://discuss.elastic.co/u/vishwanathh)\
**Replies:** 1\
**Last updated:** [August 23, 2019, 3:32pm UTC](https://discuss.elastic.co/t/metricbeat-redis-error-while-retrieving-info-and-keyspace-stats/196555 "2019-08-23T15:32:16Z")

</div>

Hello, I had enabled the metricbeat redis module and below is my YML configuration: module: redis metricsets: \["info","keyspace"\] period: 10s module: redis metricsets: \["key"\] key.patterns: pattern: '\*' lim…

---

## [Configure Filebeat not to rotate file on restart](https://discuss.elastic.co/t/configure-filebeat-not-to-rotate-file-on-restart/195525)

<div class="topic-metadata">

**Author:** [@Romano](https://discuss.elastic.co/u/Romano)\
**Replies:** 5\
**Last updated:** [August 23, 2019, 9:31am UTC](https://discuss.elastic.co/t/configure-filebeat-not-to-rotate-file-on-restart/195525 "2019-08-23T09:31:20Z")

</div>

I am using filebeat to parse some logs and collect data for a month. System uses logrotate to rotate file when needed. Filebeat system fits perfectly for me, because It starts up on server restart, and easy to setup the …

---

## [Out of memory issues with single log file](https://discuss.elastic.co/t/out-of-memory-issues-with-single-log-file/196323)

<div class="topic-metadata">

**Author:** [@flavioarieta](https://discuss.elastic.co/u/flavioarieta)\
**Replies:** 2\
**Last updated:** [August 23, 2019, 1:23pm UTC](https://discuss.elastic.co/t/out-of-memory-issues-with-single-log-file/196323 "2019-08-23T13:23:32Z")

</div>

Hi, I'm experiencing the following error some seconds after starting filebeat and I can't understand the reason. ... 2019-08-22T12:08:13.494Z INFO instance/beat.go:280 Setup Beat: filebeat; Version: 6.8.1 2019-08-22T12…

---

## [Close\_inactive placement in the configuration](https://discuss.elastic.co/t/close-inactive-placement-in-the-configuration/196532)

<div class="topic-metadata">

**Author:** [@Shashank\_Dhyani](https://discuss.elastic.co/u/Shashank_Dhyani)\
**Replies:** 0\
**Last updated:** [August 23, 2019, 1:14pm UTC](https://discuss.elastic.co/t/close-inactive-placement-in-the-configuration/196532 "2019-08-23T13:14:33Z")

</div>

Hello, My filebeat.yml looks like this: Here I am giving path of external configurations. filebeat.config.inputs: enabled: true path: C:\\\\Users\\\\\<user-id\>\\\\Documents\\\\Shashank\\\\Filebeat\\\\filebeat1\\\\configs\\\\test…

---

## [Filebeat multiple index output to elastic cloud](https://discuss.elastic.co/t/filebeat-multiple-index-output-to-elastic-cloud/196511)

<div class="topic-metadata">

**Author:** [@fadil030889](https://discuss.elastic.co/u/fadil030889)\
**Replies:** 0\
**Last updated:** [August 23, 2019, 11:42am UTC](https://discuss.elastic.co/t/filebeat-multiple-index-output-to-elastic-cloud/196511 "2019-08-23T11:42:32Z")

</div>

Hi, I wanted to know if it was possible to use only filebeat to sending logs two or more different indices. Say for example, two different log paths with two different log formats. Thanks, Fadil

---

## [Install filebeat and application in the same POD](https://discuss.elastic.co/t/install-filebeat-and-application-in-the-same-pod/196171)

<div class="topic-metadata">

**Author:** [@prabhat\_ranjan](https://discuss.elastic.co/u/prabhat_ranjan)\
**Replies:** 2\
**Last updated:** [August 23, 2019, 10:49am UTC](https://discuss.elastic.co/t/install-filebeat-and-application-in-the-same-pod/196171 "2019-08-23T10:49:30Z")

</div>

Team, I am working with kubernetes/docker and hosting a application on cloud. My application is having multi pod .I am creating image using docker . I want to ship filebeat along with my application in the same dock…

---

## [No value received in system.cpu.total.norm.pct in 7.3.0 and 7.3.1](https://discuss.elastic.co/t/no-value-received-in-system-cpu-total-norm-pct-in-7-3-0-and-7-3-1/196422)

<div class="topic-metadata">

**Author:** [@kagoadvs](https://discuss.elastic.co/u/kagoadvs)\
**Replies:** 1\
**Last updated:** [August 23, 2019, 10:28am UTC](https://discuss.elastic.co/t/no-value-received-in-system-cpu-total-norm-pct-in-7-3-0-and-7-3-1/196422 "2019-08-23T10:28:28Z")

</div>

Does anyone know, why no value is received in system.cpu.total.norm.pct from Metricbeat 7.3.0 and 7.3.1 on Windows 2016/2019 servers. It was working fine in previous versions. It seems like it is still a valid field: ht…

---

## [Can I only reserve fields parsed from log when output?](https://discuss.elastic.co/t/can-i-only-reserve-fields-parsed-from-log-when-output/196461)

<div class="topic-metadata">

**Author:** [@Vvv](https://discuss.elastic.co/u/Vvv)\
**Replies:** 0\
**Last updated:** [August 23, 2019, 7:39am UTC](https://discuss.elastic.co/t/can-i-only-reserve-fields-parsed-from-log-when-output/196461 "2019-08-23T07:39:31Z")

</div>

Hi, I want harvest Nginx access log using Filebeat. Instead of output to Logstash / Elasticsearch, I just want to send log content to Kafka topic. The content may like: {"foo":"xxx","bar":"yyy"} Then I config filebeat…

---

## [Creatiing multiple index in elasticsearch using filebeat and sending logs](https://discuss.elastic.co/t/creatiing-multiple-index-in-elasticsearch-using-filebeat-and-sending-logs/196460)

<div class="topic-metadata">

**Author:** [@koventhan](https://discuss.elastic.co/u/koventhan)\
**Replies:** 0\
**Last updated:** [August 23, 2019, 7:29am UTC](https://discuss.elastic.co/t/creatiing-multiple-index-in-elasticsearch-using-filebeat-and-sending-logs/196460 "2019-08-23T07:29:01Z")

</div>

Hello Team, I'm trying to create two index in filebeat and sending the logs to elasticsearch as separate index's in them.im not able to get the right configuration for filebeat on sending the logs to two index's in elas…

---

## [Filebeats isn't logging and will send old events after reboots](https://discuss.elastic.co/t/filebeats-isnt-logging-and-will-send-old-events-after-reboots/196451)

<div class="topic-metadata">

**Author:** [@hobby](https://discuss.elastic.co/u/hobby)\
**Replies:** 0\
**Last updated:** [August 23, 2019, 6:14am UTC](https://discuss.elastic.co/t/filebeats-isnt-logging-and-will-send-old-events-after-reboots/196451 "2019-08-23T06:14:10Z")

</div>

Installed Filebeat 7.3.0 on my windows machine to ship logs to ELK. After running "Start-Service filebeat" for the first time everything worked as expected. I can see all the events in kibana. However, after I made some …

---

## [Filebeat for kubernetes containers. How include / exclude logs by kubernetes labes?](https://discuss.elastic.co/t/filebeat-for-kubernetes-containers-how-include-exclude-logs-by-kubernetes-labes/195946)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 2\
**Last updated:** [August 23, 2019, 6:22am UTC](https://discuss.elastic.co/t/filebeat-for-kubernetes-containers-how-include-exclude-logs-by-kubernetes-labes/195946 "2019-08-23T06:22:43Z")

</div>

Hi, I have a kubernetes cluster (currently in dev status) where following is running: elastic stack different project specific apps. I want to use the same elastic stack for monitoring my kubernetes instance and my p…

---

## [Run Auditbeat with non-root user](https://discuss.elastic.co/t/run-auditbeat-with-non-root-user/193707)

<div class="topic-metadata">

**Author:** [@Daniel6](https://discuss.elastic.co/u/Daniel6)\
**Replies:** 1\
**Last updated:** [August 23, 2019, 2:30am UTC](https://discuss.elastic.co/t/run-auditbeat-with-non-root-user/193707 "2019-08-23T02:30:06Z")

</div>

Hi Elastic Team, I run ELK on Linux(CentOS7). Because of security issue, I need to run Auditbeat with non-root user. When runing Auditbeat with non-root user, it shows: 2019-08 WARN \[cfgwarn\] host/host.go…

---

## [Filebeat 7.3 syslog / auth log timezone parsing error](https://discuss.elastic.co/t/filebeat-7-3-syslog-auth-log-timezone-parsing-error/196031)

<div class="topic-metadata">

**Author:** [@Kent\_Wang](https://discuss.elastic.co/u/Kent_Wang)\
**Replies:** 2\
**Last updated:** [August 23, 2019, 12:13am UTC](https://discuss.elastic.co/t/filebeat-7-3-syslog-auth-log-timezone-parsing-error/196031 "2019-08-23T00:13:15Z")

</div>

Hi Guys, I think there is something wrong in the system module ingest pipeline related to timezone processing. Here is an excerpt of date processors from pipipeline.json: { "date": { "field": "system.auth.…

---

## [How to debug multiline in filebeat?](https://discuss.elastic.co/t/how-to-debug-multiline-in-filebeat/195918)

<div class="topic-metadata">

**Author:** [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Replies:** 2\
**Last updated:** [August 22, 2019, 10:10pm UTC](https://discuss.elastic.co/t/how-to-debug-multiline-in-filebeat/195918 "2019-08-22T22:10:10Z")

</div>

Here is my filebeat.yml: filebeat.inputs: - type: log enabled: true paths: - /home/xyz/nohup.txt multiline.pattern: '^\\\[\[0-9\]{4}-\[0-9\]{2}-\[0-9\]{2}' multiline.negate: true multiline.match: after Here …

---

## [Kafka/log.go:53 producer/broker/38402 maximum request accumulated, waiting for space? when I set output.kafka.required\_acks: 0?](https://discuss.elastic.co/t/kafka-log-go-53-producer-broker-38402-maximum-request-accumulated-waiting-for-space-when-i-set-output-kafka-required-acks-0/195982)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 2\
**Last updated:** [August 22, 2019, 8:00pm UTC](https://discuss.elastic.co/t/kafka-log-go-53-producer-broker-38402-maximum-request-accumulated-waiting-for-space-when-i-set-output-kafka-required-acks-0/195982 "2019-08-22T20:00:45Z")

</div>

Hello, I see lots of "INFO kafka/log.go:53 producer/broker/38322 maximum request accumulated, waiting for space" even when I set output.kafka.required\_acks: 0, i am using filebeat 7.2. I thought when I set required\_…

---

## [Filebeat close\_inactive while file is still active](https://discuss.elastic.co/t/filebeat-close-inactive-while-file-is-still-active/196305)

<div class="topic-metadata">

**Author:** [@hlamsc](https://discuss.elastic.co/u/hlamsc)\
**Replies:** 1\
**Last updated:** [August 22, 2019, 7:59pm UTC](https://discuss.elastic.co/t/filebeat-close-inactive-while-file-is-still-active/196305 "2019-08-22T19:59:09Z")

</div>

Hey there, currently we have a problem with our filebeat version 6.3.2 on windows server 2016. We have an application that logs massivly in one logfile. After the logfile size reached 20MB it gets rotated. The problem…

---

## [Wazuh configuration file](https://discuss.elastic.co/t/wazuh-configuration-file/196140)

<div class="topic-metadata">

**Author:** [@Thibault](https://discuss.elastic.co/u/Thibault)\
**Replies:** 1\
**Last updated:** [August 22, 2019, 7:36pm UTC](https://discuss.elastic.co/t/wazuh-configuration-file/196140 "2019-08-22T19:36:20Z")

</div>

Hi ! :slight\_smile: I set up Wazuh but the problem is that in the tutorial (https://documentation.wazuh.com/3.x/installation-guide/installing-wazuh-server/wazuh\_server\_rpm\_centos.html) they replace filebeat.yml with thi…

---

## [Using Filebeat like sincedb\_path](https://discuss.elastic.co/t/using-filebeat-like-sincedb-path/196116)

<div class="topic-metadata">

**Author:** [@zbawio](https://discuss.elastic.co/u/zbawio)\
**Replies:** 1\
**Last updated:** [August 22, 2019, 7:32pm UTC](https://discuss.elastic.co/t/using-filebeat-like-sincedb-path/196116 "2019-08-22T19:32:40Z")

</div>

Hi guys, i have an easy question for you but i could not find my answer :slightly\_smiling\_face: i was using logstash without filebeat and when i insert log it could load with sincedb\_path when logstash is not working bu…

---

## [Filebeat on kubernetes as non root?](https://discuss.elastic.co/t/filebeat-on-kubernetes-as-non-root/195949)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [August 22, 2019, 6:49pm UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-as-non-root/195949 "2019-08-22T18:49:14Z")

</div>

Hi, What possibilities do I have to run filebeat in kubernetes as non-root user and access the docker container logs? Our datacenter team don't really like privileged root processes :wink: So I want to avoid if possibl…

---

## [Filebeat Registry Issue](https://discuss.elastic.co/t/filebeat-registry-issue/195268)

<div class="topic-metadata">

**Author:** [@monica2](https://discuss.elastic.co/u/monica2)\
**Replies:** 9\
**Last updated:** [August 22, 2019, 6:44pm UTC](https://discuss.elastic.co/t/filebeat-registry-issue/195268 "2019-08-22T18:44:57Z")

</div>

I am using filbeat version 7.2.0. Using Docker . I am succesfully creating image and running iamge without any issues. But I am having issues on registry file. I specified the registry file to be /etc/filebeat/data/regi…

---

## [Auditbeat windows service consistently fails](https://discuss.elastic.co/t/auditbeat-windows-service-consistently-fails/196369)

<div class="topic-metadata">

**Author:** [@doug.cain](https://discuss.elastic.co/u/doug.cain)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 4:45pm UTC](https://discuss.elastic.co/t/auditbeat-windows-service-consistently-fails/196369 "2019-08-22T16:45:41Z")

</div>

Hi, I've been using audit beats on my centos servers without issue so far but getting the service to run on windows is eluding me. I can run audit beat in a console with the -e flag and it runs fine. If I use the "inst…

---

## [Wrong timezone using haproxy module](https://discuss.elastic.co/t/wrong-timezone-using-haproxy-module/196368)

<div class="topic-metadata">

**Author:** [@pcantea](https://discuss.elastic.co/u/pcantea)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 4:43pm UTC](https://discuss.elastic.co/t/wrong-timezone-using-haproxy-module/196368 "2019-08-22T16:43:52Z")

</div>

I have the same issue as https://discuss.elastic.co/t/still-not-solved-filebeat-cannot-recognize-timezone-in-syslog/192661 HAProxy logs have the correct date on the server, the server timezone is set to UTC-8 (Pacific),…

---

## [IAM Policy to use the CloudWatch Logs feature](https://discuss.elastic.co/t/iam-policy-to-use-the-cloudwatch-logs-feature/196362)

<div class="topic-metadata">

**Author:** [@jbuenostein89](https://discuss.elastic.co/u/jbuenostein89)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 4:00pm UTC](https://discuss.elastic.co/t/iam-policy-to-use-the-cloudwatch-logs-feature/196362 "2019-08-22T16:00:59Z")

</div>

So I have followed the getting started guide and the instructions on the '/app/kibana#/home/tutorial/cloudwatchLogs?\_g=()' page, but when deploying the CloudFormation stack, I keep getting permission errors that are not …

---

## [Filebeat NAS access](https://discuss.elastic.co/t/filebeat-nas-access/196363)

<div class="topic-metadata">

**Author:** [@sakthiganesht](https://discuss.elastic.co/u/sakthiganesht)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 4:01pm UTC](https://discuss.elastic.co/t/filebeat-nas-access/196363 "2019-08-22T16:01:34Z")

</div>

Hello, I am trying to read log files from NAS drive but it couldn't read. The same file when copied locally where the filebeat is installed it is able to read. Does filebeat support NAS ? If yes is there a specific con…

---

## [System Module for Windows Hosts](https://discuss.elastic.co/t/system-module-for-windows-hosts/196339)

<div class="topic-metadata">

**Author:** [@j.backs](https://discuss.elastic.co/u/j.backs)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 1:58pm UTC](https://discuss.elastic.co/t/system-module-for-windows-hosts/196339 "2019-08-22T13:58:29Z")

</div>

Hi there, will Windows Hosts fully be supported by the Auditbeat System Module in the future? I guess that the System Socket datasets, User datasets, System login datasets, System package datasets and the System User d…

---

## [Filebeat vs logstash for syslog](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123)

<div class="topic-metadata">

**Author:** [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Replies:** 2\
**Last updated:** [August 22, 2019, 1:49pm UTC](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123 "2019-08-22T13:49:34Z")

</div>

I've been using logstash to test ingesting logs from various network devices (mostly Cisco). It works well. I see that filebeat has support for syslog ingestion and specifically includes a Cisco module. I can't seem t…

---

## [All syslogs appear to come from the same host](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119)

<div class="topic-metadata">

**Author:** [@jmorris](https://discuss.elastic.co/u/jmorris)\
**Replies:** 3\
**Last updated:** [August 22, 2019, 1:46pm UTC](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119 "2019-08-22T13:46:26Z")

</div>

I have several devices sending syslogs to my server, but in Kibana, all of them have the exact same host/agent name, so its impossible to visualize groups. For example, if I wanted to see all alerts from my core switch,…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=323)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=325)
