# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=325

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 326

---

## [Delete a custom created module in metricbeat](https://discuss.elastic.co/t/delete-a-custom-created-module-in-metricbeat/196330)

<div class="topic-metadata">

**Author:** [@Venkat\_Raj](https://discuss.elastic.co/u/Venkat_Raj)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 1:29pm UTC](https://discuss.elastic.co/t/delete-a-custom-created-module-in-metricbeat/196330 "2019-08-22T13:29:05Z")

</div>

Need help on deleting a custom module created inside metricbeat. I have created a new metricset inside metricbeat using "make create-metricset" command and have some logics inside it. Now I don't need that particular mo…

---

## [High CPU usage on Filebeat](https://discuss.elastic.co/t/high-cpu-usage-on-filebeat/195958)

<div class="topic-metadata">

**Author:** [@ViniciusArnhold](https://discuss.elastic.co/u/ViniciusArnhold)\
**Replies:** 1\
**Last updated:** [August 22, 2019, 12:37pm UTC](https://discuss.elastic.co/t/high-cpu-usage-on-filebeat/195958 "2019-08-22T12:37:02Z")

</div>

Hi, We are experiencing high CPU usage on our filebeat instances on Windows machines, we're seeing between 15%-50% usage on the affected instances but there are active nodes in which there is no CPU usage even though th…

---

## [deviceId changes of the drive where filebeat reads log, produces a lot of duplicate log messages](https://discuss.elastic.co/t/deviceid-changes-of-the-drive-where-filebeat-reads-log-produces-a-lot-of-duplicate-log-messages/196310)

<div class="topic-metadata">

**Author:** [@frueht68](https://discuss.elastic.co/u/frueht68)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 11:48am UTC](https://discuss.elastic.co/t/deviceid-changes-of-the-drive-where-filebeat-reads-log-produces-a-lot-of-duplicate-log-messages/196310 "2019-08-22T11:48:37Z")

</div>

We observed the following behavior in our private cloud, managed by an external provider: In some occasions we observe changes of the deviceId of the drive, where filebeat reads the log files from. Those occasions alway…

---

## [Read from pcap file VS Not read from pcap file](https://discuss.elastic.co/t/read-from-pcap-file-vs-not-read-from-pcap-file/196280)

<div class="topic-metadata">

**Author:** [@hyhong](https://discuss.elastic.co/u/hyhong)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 9:13am UTC](https://discuss.elastic.co/t/read-from-pcap-file-vs-not-read-from-pcap-file/196280 "2019-08-22T09:13:22Z")

</div>

First,I use follow command read data to es: ./packetbeat -e -c packetbeat-redis.yml Second,I use follow command generate a trace.pcap file,and read from trace.pcap to es. ./packetbeat -c packetbeat-redis.yml -dump tra…

---

## [Add body to a request while checking for status of the url in heartbeat](https://discuss.elastic.co/t/add-body-to-a-request-while-checking-for-status-of-the-url-in-heartbeat/194990)

<div class="topic-metadata">

**Author:** [@Tinkerbell](https://discuss.elastic.co/u/Tinkerbell)\
**Replies:** 2\
**Last updated:** [August 22, 2019, 8:56am UTC](https://discuss.elastic.co/t/add-body-to-a-request-while-checking-for-status-of-the-url-in-heartbeat/194990 "2019-08-22T08:56:13Z")

</div>

How to add body to a request while checking for status of the url in heartbeat. Here is my sample from heartbeat.yml type: http enabled: true name: "vtrack" urls: \[""\] check.request: method: GET headers: \[ 'Con…

---

## [Creating count beat and end up with below error, please suggest](https://discuss.elastic.co/t/creating-count-beat-and-end-up-with-below-error-please-suggest/196232)

<div class="topic-metadata">

**Author:** [@shali93](https://discuss.elastic.co/u/shali93)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 4:37am UTC](https://discuss.elastic.co/t/creating-count-beat-and-end-up-with-below-error-please-suggest/196232 "2019-08-22T04:37:50Z")

</div>

C:\\Users\\Admin\\go\\src\\github.com\\shali93\\countbeat\>make setup C:\\Users\\Admin\\go\\bin\\mage.exe panic: failed determine libbeat dir location: failed to determine root import path (Did you git init?, Is the project in the …

---

## [Create new beat fails at make set up](https://discuss.elastic.co/t/create-new-beat-fails-at-make-set-up/196206)

<div class="topic-metadata">

**Author:** [@Anjana](https://discuss.elastic.co/u/Anjana)\
**Replies:** 1\
**Last updated:** [August 22, 2019, 4:37am UTC](https://discuss.elastic.co/t/create-new-beat-fails-at-make-set-up/196206 "2019-08-22T04:37:26Z")

</div>

Hi, I am trying to create a new beat in Windows and it fails when I run the make command. I get the below error C:\\Users\\anjana\\go\\src\\github.com\\Anjana\\xstorebeat\>make setup C:\\Users\\anjana\\go\\bin\\mage.exe panic: fa…

---

## [Redis packet data is loss](https://discuss.elastic.co/t/redis-packet-data-is-loss/196218)

<div class="topic-metadata">

**Author:** [@hyhong](https://discuss.elastic.co/u/hyhong)\
**Replies:** 0\
**Last updated:** [August 22, 2019, 2:24am UTC](https://discuss.elastic.co/t/redis-packet-data-is-loss/196218 "2019-08-22T02:24:49Z")

</div>

When I use redis-cli to test,there are packet data loss.Is there some solutions?

---

## [Ghost index unable to populate itself under '\_docs' | functionbeat](https://discuss.elastic.co/t/ghost-index-unable-to-populate-itself-under-docs-functionbeat/195873)

<div class="topic-metadata">

**Author:** [@asad\_ali](https://discuss.elastic.co/u/asad_ali)\
**Replies:** 1\
**Last updated:** [August 21, 2019, 3:32pm UTC](https://discuss.elastic.co/t/ghost-index-unable-to-populate-itself-under-docs-functionbeat/195873 "2019-08-21T15:32:54Z")

</div>

I'm using functionbeat 7.1, and after great pain and countless night i was able to deploy 'function'. The inbuilt tutorial is very insufficient for development setups, as it lacks 'in-between' setups/details and configur…

---

## [Metricbeat cannot get metrics from kafka running in k8](https://discuss.elastic.co/t/metricbeat-cannot-get-metrics-from-kafka-running-in-k8/196014)

<div class="topic-metadata">

**Author:** [@memelet](https://discuss.elastic.co/u/memelet)\
**Replies:** 1\
**Last updated:** [August 21, 2019, 2:28pm UTC](https://discuss.elastic.co/t/metricbeat-cannot-get-metrics-from-kafka-running-in-k8/196014 "2019-08-21T14:28:09Z")

</div>

My configuration contains: - condition: equals: kubernetes.labels: strimzi\_io/name: vikafka-kafka …

---

## [Is it possible to make a new http request with the data in the responsebody?](https://discuss.elastic.co/t/is-it-possible-to-make-a-new-http-request-with-the-data-in-the-responsebody/196105)

<div class="topic-metadata">

**Author:** [@ISKU](https://discuss.elastic.co/u/ISKU)\
**Replies:** 1\
**Last updated:** [August 21, 2019, 2:15pm UTC](https://discuss.elastic.co/t/is-it-possible-to-make-a-new-http-request-with-the-data-in-the-responsebody/196105 "2019-08-21T14:15:31Z")

</div>

Hi. I want to make two http requests. Get the json data of the response body from the first request, I want to use that json data as the value of the header of the second request. For example: name: http schedule: '…

---

## [Filebeat 7.3 Timezone Issues with System Module](https://discuss.elastic.co/t/filebeat-7-3-timezone-issues-with-system-module/195971)

<div class="topic-metadata">

**Author:** [@DavidJohnson](https://discuss.elastic.co/u/DavidJohnson)\
**Replies:** 5\
**Last updated:** [August 21, 2019, 1:40pm UTC](https://discuss.elastic.co/t/filebeat-7-3-timezone-issues-with-system-module/195971 "2019-08-21T13:40:25Z")

</div>

I have installed a new instance of Elasticsearch 7.3 and configured one host to send Filebeat data with Auditd and System modules. The auditd logs look correct. The System module collected data will not stop converting t…

---

## [Filebeat Cannot Parse Syslog File from Aerohive](https://discuss.elastic.co/t/filebeat-cannot-parse-syslog-file-from-aerohive/195773)

<div class="topic-metadata">

**Author:** [@jmorris](https://discuss.elastic.co/u/jmorris)\
**Replies:** 2\
**Last updated:** [August 21, 2019, 11:30am UTC](https://discuss.elastic.co/t/filebeat-cannot-parse-syslog-file-from-aerohive/195773 "2019-08-21T11:30:49Z")

</div>

Hello, I am fairly new to elastic stack. I have the stack up and running, and the syslogs from my host server show up in Kibana. I've configured the syslogs from my Aerohive wireless access points to point to filebeat …

---

## [Failed to publish events caused by: EOF,Failed to publish events caused by: client is not connected,Failed to publish events: client is not connected](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-eof-failed-to-publish-events-caused-by-client-is-not-connected-failed-to-publish-events-client-is-not-connected/195042)

<div class="topic-metadata">

**Author:** [@Mohammad.ali](https://discuss.elastic.co/u/Mohammad.ali)\
**Replies:** 2\
**Last updated:** [August 21, 2019, 8:20am UTC](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-eof-failed-to-publish-events-caused-by-client-is-not-connected-failed-to-publish-events-client-is-not-connected/195042 "2019-08-21T08:20:52Z")

</div>

Hello everyone, i have a very simple filebeat which send some simple log file to logstash which is running on another server,,after i start filebeat and logstash the log which i see from filebeat shows me the connection…

---

## [Multiple Filebeat instances with separate configuration files to different Logstash containers](https://discuss.elastic.co/t/multiple-filebeat-instances-with-separate-configuration-files-to-different-logstash-containers/195984)

<div class="topic-metadata">

**Author:** [@kmiklas](https://discuss.elastic.co/u/kmiklas)\
**Replies:** 1\
**Last updated:** [August 21, 2019, 7:36am UTC](https://discuss.elastic.co/t/multiple-filebeat-instances-with-separate-configuration-files-to-different-logstash-containers/195984 "2019-08-21T07:36:13Z")

</div>

Is it possible to run multiple instances of Filebeat with different filebeat.yml config files? I need to send log lines to different servers running Logstash. Thx, Keith :^)

---

## [Can index creation be cancelled daily](https://discuss.elastic.co/t/can-index-creation-be-cancelled-daily/196023)

<div class="topic-metadata">

**Author:** [@longfu.zhu](https://discuss.elastic.co/u/longfu.zhu)\
**Replies:** 4\
**Last updated:** [August 21, 2019, 7:10am UTC](https://discuss.elastic.co/t/can-index-creation-be-cancelled-daily/196023 "2019-08-21T07:10:59Z")

</div>

Can index creation be cancelled daily Metricbeat6.7.1 elasticSearch 6.7.1 kibana 6.7.1

---

## [Enable netflow module in filebeat on Rasberry PI](https://discuss.elastic.co/t/enable-netflow-module-in-filebeat-on-rasberry-pi/195629)

<div class="topic-metadata">

**Author:** [@wimdebruyn](https://discuss.elastic.co/u/wimdebruyn)\
**Replies:** 2\
**Last updated:** [August 21, 2019, 3:46am UTC](https://discuss.elastic.co/t/enable-netflow-module-in-filebeat-on-rasberry-pi/195629 "2019-08-21T03:46:05Z")

</div>

I am running filebeat 7.3 on a Raspberry PI (running buster) shipping to Elastic cloud 7.3. I compiled filebeat from source following instructions from @andig. It is already successfuly shipping syslog and nginx logs…

---

## [Filebeat skipping log lines in windows](https://discuss.elastic.co/t/filebeat-skipping-log-lines-in-windows/195783)

<div class="topic-metadata">

**Author:** [@Skyy](https://discuss.elastic.co/u/Skyy)\
**Replies:** 1\
**Last updated:** [August 20, 2019, 8:29pm UTC](https://discuss.elastic.co/t/filebeat-skipping-log-lines-in-windows/195783 "2019-08-20T20:29:37Z")

</div>

So i have a similar issue outlined here and im pretty sure the problem is the same: Our log writing process is custom and replaces the old log file entirely on update. The issue is when filebeat reads logs realtime an…

---

## [Index issues](https://discuss.elastic.co/t/index-issues/195585)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 1\
**Last updated:** [August 20, 2019, 7:45pm UTC](https://discuss.elastic.co/t/index-issues/195585 "2019-08-20T19:45:58Z")

</div>

Hello I have setup a template PUT /\_template/active-directory I have setup an index PUT active-directory When i confirm my mappings, they are as expected. They just include the mappings i have specifically set. GE…

---

## [How to read monitoring lines in filebeat logs](https://discuss.elastic.co/t/how-to-read-monitoring-lines-in-filebeat-logs/195501)

<div class="topic-metadata">

**Author:** [@rsumit](https://discuss.elastic.co/u/rsumit)\
**Replies:** 1\
**Last updated:** [August 20, 2019, 7:25pm UTC](https://discuss.elastic.co/t/how-to-read-monitoring-lines-in-filebeat-logs/195501 "2019-08-20T19:25:05Z")

</div>

Hi Team I need to understand how to read filebeat logs, specifically the lines which has monitoring in it. For e.g. 2019-08-16T18:56:05.320+0530 INFO \[monitoring\] log/log.go:144 Non-zero metrics in the last …

---

## [Auditbeat is devouring the CPU](https://discuss.elastic.co/t/auditbeat-is-devouring-the-cpu/195815)

<div class="topic-metadata">

**Author:** [@craig.merchant](https://discuss.elastic.co/u/craig.merchant)\
**Replies:** 2\
**Last updated:** [August 20, 2019, 6:31pm UTC](https://discuss.elastic.co/t/auditbeat-is-devouring-the-cpu/195815 "2019-08-20T18:31:25Z")

</div>

I have installed auditbeat on an Ubuntu Linux 18.04 VM. I am using the recommended audit.rules config from the CIS benchmarks. When auditbeat is running, it consistently consumes 40-60% of a core. The native Linux aud…

---

## [Heartbeat with protected API's](https://discuss.elastic.co/t/heartbeat-with-protected-apis/195977)

<div class="topic-metadata">

**Author:** [@Johnnie843](https://discuss.elastic.co/u/Johnnie843)\
**Replies:** 0\
**Last updated:** [August 20, 2019, 5:01pm UTC](https://discuss.elastic.co/t/heartbeat-with-protected-apis/195977 "2019-08-20T17:01:15Z")

</div>

Hello Everyone, We have an application deployed with a bunch of API's exposed. They are protected via Keycloak(OAuth2). Is there a way to authenticate to test the Uptime of the API Url? If not I will always get the for…

---

## [Question regarding specifying "localhost" and deploying to Lambda](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332)

<div class="topic-metadata">

**Author:** [@TheSwede86](https://discuss.elastic.co/u/TheSwede86)\
**Replies:** 5\
**Last updated:** [August 20, 2019, 4:20pm UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332 "2019-08-20T16:20:23Z")

</div>

Running on my localhost (i.e. my laptop): ES 7.3 w. Basic-license (port 9200 is verified and returns info) Kibana 7.3 w. Basic-license (port 5601 is verified and returns the Kibana interface) Functionbeat 7.3 from the…

---

## [Filebeat/kibana upgrade issues from 6.x to 7.x](https://discuss.elastic.co/t/filebeat-kibana-upgrade-issues-from-6-x-to-7-x/195961)

<div class="topic-metadata">

**Author:** [@tenney](https://discuss.elastic.co/u/tenney)\
**Replies:** 0\
**Last updated:** [August 20, 2019, 2:54pm UTC](https://discuss.elastic.co/t/filebeat-kibana-upgrade-issues-from-6-x-to-7-x/195961 "2019-08-20T14:54:18Z")

</div>

Upgraded to 7.x and having some issues with our nginx data. One example is response times the fields were moved from nginx.access.response\_code to http.response.status\_code. I thought enabling the compatibility later w…

---

## [Journalbeat creates registry file with root:root ownership instead of journalbeat user](https://discuss.elastic.co/t/journalbeat-creates-registry-file-with-root-root-ownership-instead-of-journalbeat-user/182649)

<div class="topic-metadata">

**Author:** [@matp](https://discuss.elastic.co/u/matp)\
**Replies:** 1\
**Last updated:** [August 20, 2019, 1:00pm UTC](https://discuss.elastic.co/t/journalbeat-creates-registry-file-with-root-root-ownership-instead-of-journalbeat-user/182649 "2019-08-20T13:00:42Z")

</div>

journalbeat 6.7.1 tarball journalbeat is run via systemd unit with user/group journalbeat/journalbeat Ubuntu 16.04 # ps -C journalbeat o lstart,pid,user:14,group:14,cmd STARTED PID USER GR…

---

## [No kubernetes labels for volumes exported?](https://discuss.elastic.co/t/no-kubernetes-labels-for-volumes-exported/195894)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [August 20, 2019, 10:51am UTC](https://discuss.elastic.co/t/no-kubernetes-labels-for-volumes-exported/195894 "2019-08-20T10:51:04Z")

</div>

Hi, I am fetching volume information from kubernetes cluster. The labels are missing in the metricbeat event: { "@timestamp": "2019-08-20T10:39:59.823Z", "@metadata": { "beat": "metricbeat", "type": "\_doc"…

---

## [Filebeat not picking up CSV properly](https://discuss.elastic.co/t/filebeat-not-picking-up-csv-properly/194931)

<div class="topic-metadata">

**Author:** [@yungnvn](https://discuss.elastic.co/u/yungnvn)\
**Replies:** 6\
**Last updated:** [August 20, 2019, 10:49am UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-csv-properly/194931 "2019-08-20T10:49:33Z")

</div>

I have a filebeat config to pick up a CSV file shown below: paths: - /path/to/CSV multiline.pattern: '^\\d' multiline.negate: true multiline.match: after Here is a sample from the CSV: RTime,Concept,Time,Yest…

---

## [EvtSeek used by winlogbeats go wrong when arch is 386](https://discuss.elastic.co/t/evtseek-used-by-winlogbeats-go-wrong-when-arch-is-386/195825)

<div class="topic-metadata">

**Author:** [@tianlin](https://discuss.elastic.co/u/tianlin)\
**Replies:** 0\
**Last updated:** [August 20, 2019, 12:50am UTC](https://discuss.elastic.co/t/evtseek-used-by-winlogbeats-go-wrong-when-arch-is-386/195825 "2019-08-20T00:50:44Z")

</div>

Hi, I found there is a bug in \_EvtSeek. position is int64, but in 386, it must call syscall.Syscall6(procEvtSeek.Addr(), 6, uintptr(resultSet), uintptr(position), uintptr(position\>\>32), uintptr(bookmark), uintptr(timeou…

---

## [Filebeat handler open rotated log files](https://discuss.elastic.co/t/filebeat-handler-open-rotated-log-files/195694)

<div class="topic-metadata">

**Author:** [@nomis](https://discuss.elastic.co/u/nomis)\
**Replies:** 2\
**Last updated:** [August 19, 2019, 9:24pm UTC](https://discuss.elastic.co/t/filebeat-handler-open-rotated-log-files/195694 "2019-08-19T21:24:02Z")

</div>

On our kuberntes cluster we rotate the logs using the dockerd option "--log-opt max-size and --log-opt max-file". When the log are rotated filebeat still hold the rotated log file. We keep only 3 rotated log files, this …

---

## [Filebeat Setup Fails with Wildcard Certificate](https://discuss.elastic.co/t/filebeat-setup-fails-with-wildcard-certificate/193847)

<div class="topic-metadata">

**Author:** [@Zamiell](https://discuss.elastic.co/u/Zamiell)\
**Replies:** 4\
**Last updated:** [August 19, 2019, 7:56pm UTC](https://discuss.elastic.co/t/filebeat-setup-fails-with-wildcard-certificate/193847 "2019-08-19T19:56:35Z")

</div>

Greetings. I found a bug in beats, but I went to open a bug issue on GitHub but the prompts directed me here to confirm that it was a bug first. Steps to reproduce: Vanilla CentOS 7 Download and install filebeat-6.8.0…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=324)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=326)
