# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=326

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 327

---

## [Metricbeat system overview dashboard is throwing a fieldata disabled error](https://discuss.elastic.co/t/metricbeat-system-overview-dashboard-is-throwing-a-fieldata-disabled-error/195805)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 0\
**Last updated:** [August 19, 2019, 8:28pm UTC](https://discuss.elastic.co/t/metricbeat-system-overview-dashboard-is-throwing-a-fieldata-disabled-error/195805 "2019-08-19T20:28:24Z")

</div>

Hello, When I am browsing system overview dashboard I am getting the following error message: \[esaggs\] \> Request to Elasticsearch failed: {"error":{"root\_cause":\[{"type":"illegal\_argument\_exception","reason":"Fielddata…

---

## [Is it possible to alter the name of the cfn stack being created?](https://discuss.elastic.co/t/is-it-possible-to-alter-the-name-of-the-cfn-stack-being-created/195787)

<div class="topic-metadata">

**Author:** [@furqank123](https://discuss.elastic.co/u/furqank123)\
**Replies:** 0\
**Last updated:** [August 19, 2019, 5:19pm UTC](https://discuss.elastic.co/t/is-it-possible-to-alter-the-name-of-the-cfn-stack-being-created/195787 "2019-08-19T17:19:16Z")

</div>

Hi, Is it possible to specify the aws cfn stack before attempting to deploy a function(either through functionbeat.yml or CLI)? We strictly follow specific naming patterns for our AWS resources, which ends up rendering …

---

## [Filebeat service failing after upgrading to 7.3.0](https://discuss.elastic.co/t/filebeat-service-failing-after-upgrading-to-7-3-0/195778)

<div class="topic-metadata">

**Author:** [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Replies:** 1\
**Last updated:** [August 19, 2019, 4:55pm UTC](https://discuss.elastic.co/t/filebeat-service-failing-after-upgrading-to-7-3-0/195778 "2019-08-19T16:55:17Z")

</div>

Elasticsearch version: 7.3.0 Filebeat version: 7.3.0 Logstash version: 7.3.0 Filebeat configuration: filebeat.prospectors: - input\_type: log paths: - /var/log/nginx/\*.log exclude\_files: \['\\.gz$'\] output.logs…

---

## [Filebeat - Apache module - Access - URI detail / SEO](https://discuss.elastic.co/t/filebeat-apache-module-access-uri-detail-seo/189495)

<div class="topic-metadata">

**Author:** [@willouuu](https://discuss.elastic.co/u/willouuu)\
**Replies:** 6\
**Last updated:** [August 19, 2019, 2:29pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-access-uri-detail-seo/189495 "2019-08-19T14:29:37Z")

</div>

Hello I am modifying the apache access processor to cut the url There is a lot of useful information on a URI to get the correct SEO data Imagine the following cases and their associated data https://www.domain.com/p…

---

## [Winlogbeat "event\_id" filter does not seem to be working](https://discuss.elastic.co/t/winlogbeat-event-id-filter-does-not-seem-to-be-working/195312)

<div class="topic-metadata">

**Author:** [@olaf1](https://discuss.elastic.co/u/olaf1)\
**Replies:** 1\
**Last updated:** [August 19, 2019, 1:48pm UTC](https://discuss.elastic.co/t/winlogbeat-event-id-filter-does-not-seem-to-be-working/195312 "2019-08-19T13:48:12Z")

</div>

Hello, it seems the event\_id filtering is not working for me. Instead, Winlogbeat just sends all events available in the evtx files to the elastic stack. The buildhash of winlogbeat is "6f0ec01a0e57fe7d4fd703b017fb5a2f6…

---

## [\[filebeat\] not generating logs when logging set to debug](https://discuss.elastic.co/t/filebeat-not-generating-logs-when-logging-set-to-debug/195389)

<div class="topic-metadata">

**Author:** [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Replies:** 4\
**Last updated:** [August 19, 2019, 12:36pm UTC](https://discuss.elastic.co/t/filebeat-not-generating-logs-when-logging-set-to-debug/195389 "2019-08-19T12:36:58Z")

</div>

Hi, i have configured logging in filebeat.yml #================================ Logging ===================================== # Sets log level. The default log level is info. # Available log levels are: error, warning…

---

## [How to configure heartbeat for cpu\_memory usage](https://discuss.elastic.co/t/how-to-configure-heartbeat-for-cpu-memory-usage/195707)

<div class="topic-metadata">

**Author:** [@fajar\_3t3](https://discuss.elastic.co/u/fajar_3t3)\
**Replies:** 1\
**Last updated:** [August 19, 2019, 12:21pm UTC](https://discuss.elastic.co/t/how-to-configure-heartbeat-for-cpu-memory-usage/195707 "2019-08-19T12:21:00Z")

</div>

hi all, need your help, how to configure heartbeat.yml for monitoring memory\_cpu usage server. Thanks

---

## [ELK STACK CONFIGURATION STEP BY STEP](https://discuss.elastic.co/t/elk-stack-configuration-step-by-step/195738)

<div class="topic-metadata">

**Author:** [@Dimuthu](https://discuss.elastic.co/u/Dimuthu)\
**Replies:** 0\
**Last updated:** [August 19, 2019, 12:11pm UTC](https://discuss.elastic.co/t/elk-stack-configuration-step-by-step/195738 "2019-08-19T12:11:34Z")

</div>

Hi Elastic Geek Lovers, I have made a tutorial to configure elastic elk stack log server and collect audit events using auditbeat module. I think this will guide you how to configure ELK Stack with Auditbeat step by st…

---

## [Can filebeat specify which ip to send data](https://discuss.elastic.co/t/can-filebeat-specify-which-ip-to-send-data/195165)

<div class="topic-metadata">

**Author:** [@Yanchun](https://discuss.elastic.co/u/Yanchun)\
**Replies:** 2\
**Last updated:** [August 19, 2019, 10:37am UTC](https://discuss.elastic.co/t/can-filebeat-specify-which-ip-to-send-data/195165 "2019-08-19T10:37:44Z")

</div>

My host has two IPs( i.e two network cards), can I configure filebeat to send data to the output(such as kafka) with one of the IP?

---

## [Packetbeat drop packets as internet speed increase above 3.5 MB/s](https://discuss.elastic.co/t/packetbeat-drop-packets-as-internet-speed-increase-above-3-5-mb-s/195691)

<div class="topic-metadata">

**Author:** [@Umar\_Hayat](https://discuss.elastic.co/u/Umar_Hayat)\
**Replies:** 0\
**Last updated:** [August 19, 2019, 7:45am UTC](https://discuss.elastic.co/t/packetbeat-drop-packets-as-internet-speed-increase-above-3-5-mb-s/195691 "2019-08-19T07:45:46Z")

</div>

We are using Packetbeat to capture traffic comming on a network interface card that is 1 GBPS and stack it on the Elasticsearch database. The problem we are currently trouble shouting is that as the speed of the network …

---

## [Beats and index naming](https://discuss.elastic.co/t/beats-and-index-naming/195073)

<div class="topic-metadata">

**Author:** [@Marcell0e](https://discuss.elastic.co/u/Marcell0e)\
**Replies:** 21\
**Last updated:** [August 19, 2019, 1:40am UTC](https://discuss.elastic.co/t/beats-and-index-naming/195073 "2019-08-19T01:40:56Z")

</div>

Here is an overview of what I am trying to do. I have my Logstash config file set up to index like this index =\> "%{\[@metadata\]\[beat\]}-%{+yyyy.ww}". When I try to load the winlogbeat beat template manually following th…

---

## [Filebeat skipping files](https://discuss.elastic.co/t/filebeat-skipping-files/195187)

<div class="topic-metadata">

**Author:** [@rsumit](https://discuss.elastic.co/u/rsumit)\
**Replies:** 6\
**Last updated:** [August 18, 2019, 11:55pm UTC](https://discuss.elastic.co/t/filebeat-skipping-files/195187 "2019-08-18T23:55:22Z")

</div>

Hi Team I am using filebeat agent to monitor logs which are rotated after certain size. The system was working fine earlier however as the load increased and the frequency of rotation had increased filebeat seems to mis…

---

## [Kibana spaces and index customization](https://discuss.elastic.co/t/kibana-spaces-and-index-customization/195499)

<div class="topic-metadata">

**Author:** [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Replies:** 1\
**Last updated:** [August 18, 2019, 9:48am UTC](https://discuss.elastic.co/t/kibana-spaces-and-index-customization/195499 "2019-08-18T09:48:59Z")

</div>

Hi I created few spaces in one elasticsearch. I had one big log file and one index which differed only by field calles app\_name. So I decided to stick with one, but also shard them for different spaces. My filebeat lo…

---

## [Winlogbeat & Metricbeat 7.3 ignore yml Kibana host settings unless debug logging enabled](https://discuss.elastic.co/t/winlogbeat-metricbeat-7-3-ignore-yml-kibana-host-settings-unless-debug-logging-enabled/195612)

<div class="topic-metadata">

**Author:** [@Mr.Shaky](https://discuss.elastic.co/u/Mr.Shaky)\
**Replies:** 0\
**Last updated:** [August 17, 2019, 6:22pm UTC](https://discuss.elastic.co/t/winlogbeat-metricbeat-7-3-ignore-yml-kibana-host-settings-unless-debug-logging-enabled/195612 "2019-08-17T18:22:20Z")

</div>

Background info: new Ubuntu18 vm, ip addr: 192.168.1.42 hostname: Aramaki (patches up-to-date. static host entered in local dns service) \[ESXi 6.7u2 host ip addr: 192.168.1.40 \] Win10 1903 workstation, ip addr: 192.16…

---

## [New sysmon event\_id 22, DNS Query](https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635)

<div class="topic-metadata">

**Author:** [@Ian\_Boje](https://discuss.elastic.co/u/Ian_Boje)\
**Replies:** 3\
**Last updated:** [August 17, 2019, 4:24pm UTC](https://discuss.elastic.co/t/new-sysmon-event-id-22-dns-query/194635 "2019-08-17T16:24:52Z")

</div>

Hi Everybody I'm not much of a programmer, but I'm tempted to try to learn to submit some changes to winlogbeat, but would be interested in finding out if I'm doing this right. Newer versions of sysmon added event\_id 2…

---

## [FreeBSD - Updated Beats Pkg](https://discuss.elastic.co/t/freebsd-updated-beats-pkg/195605)

<div class="topic-metadata">

**Author:** [@SteveP](https://discuss.elastic.co/u/SteveP)\
**Replies:** 0\
**Last updated:** [August 17, 2019, 3:59pm UTC](https://discuss.elastic.co/t/freebsd-updated-beats-pkg/195605 "2019-08-17T15:59:41Z")

</div>

Hello all, On the FreeBSD Ports section the most current install pkg for Beats is 6.7.1. Is there a 7.3 pkg available and will it be updated on the Ports page? Thanks, Steve

---

## [Schema Bug in Filebeat panw Module](https://discuss.elastic.co/t/schema-bug-in-filebeat-panw-module/193569)

<div class="topic-metadata">

**Author:** [@learnitall](https://discuss.elastic.co/u/learnitall)\
**Replies:** 3\
**Last updated:** [August 17, 2019, 11:35am UTC](https://discuss.elastic.co/t/schema-bug-in-filebeat-panw-module/193569 "2019-08-17T11:35:20Z")

</div>

Greetings! Hope all is well. I've been testing out the Palo Alto module on Filebeat version 7.2.1 with some of our internal PAN-OS Traffic and Threat syslogs. I believe I found a bug in the Threat schema. In the Filebe…

---

## [Metricbeat - Central Management - error retrieving new configurations](https://discuss.elastic.co/t/metricbeat-central-management-error-retrieving-new-configurations/195548)

<div class="topic-metadata">

**Author:** [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Replies:** 0\
**Last updated:** [August 16, 2019, 7:02pm UTC](https://discuss.elastic.co/t/metricbeat-central-management-error-retrieving-new-configurations/195548 "2019-08-16T19:02:01Z")

</div>

I've been trying to get this to work with the metricbeat and managed to create a problem. Recieving this error: ERROR \[centralmgmt\] management/manager.go:224 error retrieving new configurations, wi…

---

## [New field names in 7.x](https://discuss.elastic.co/t/new-field-names-in-7-x/193822)

<div class="topic-metadata">

**Author:** [@Duggina](https://discuss.elastic.co/u/Duggina)\
**Replies:** 2\
**Last updated:** [August 16, 2019, 6:12pm UTC](https://discuss.elastic.co/t/new-field-names-in-7-x/193822 "2019-08-16T18:12:49Z")

</div>

Hi , I upgraded my elastic cluster from 6.8.1 to 7.2 and also updated beats to 7.3. What are the fields i suppose to update in visualization and dashboards to consume the new 7 field names.

---

## ["filter\_pattern" parsing AWS ALB-logs | "Invalid subscription filter pattern" in CF](https://discuss.elastic.co/t/filter-pattern-parsing-aws-alb-logs-invalid-subscription-filter-pattern-in-cf/195513)

<div class="topic-metadata">

**Author:** [@TheSwede86](https://discuss.elastic.co/u/TheSwede86)\
**Replies:** 0\
**Last updated:** [August 16, 2019, 2:29pm UTC](https://discuss.elastic.co/t/filter-pattern-parsing-aws-alb-logs-invalid-subscription-filter-pattern-in-cf/195513 "2019-08-16T14:29:14Z")

</div>

Hi, Running a Lambda created by AWS to fetch ALB-access logs from S3 and import them to CloudWatch; However when viewing the log-group there are only the fields "Timestamp" and "Message" where "Message" actually is al…

---

## [Send full syslog unparsed message](https://discuss.elastic.co/t/send-full-syslog-unparsed-message/195468)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 1\
**Last updated:** [August 16, 2019, 12:08pm UTC](https://discuss.elastic.co/t/send-full-syslog-unparsed-message/195468 "2019-08-16T12:08:00Z")

</div>

Hi, I am using filebeat to collect syslogs from a cisco firepower IPS straight to logstash. Filebeat is able to parse the time, the issue is that firepower sends the time in RFC3164 in UTC. Filebeat is parsing the sys…

---

## [Kubernetes.statefulset.generation.\* what are these fields meaning?](https://discuss.elastic.co/t/kubernetes-statefulset-generation-what-are-these-fields-meaning/195362)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [August 16, 2019, 9:59am UTC](https://discuss.elastic.co/t/kubernetes-statefulset-generation-what-are-these-fields-meaning/195362 "2019-08-16T09:59:24Z")

</div>

Hi, the two exported fields: kubernetes.statefulset.generation.desired kubernetes.statefulset.generation.observed What do they mean in detail? I understand the replicas.desired and observed, but what is generation? …

---

## [Where can I find the Windows PerfMon dashboard?](https://discuss.elastic.co/t/where-can-i-find-the-windows-perfmon-dashboard/195155)

<div class="topic-metadata">

**Author:** [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Replies:** 2\
**Last updated:** [August 16, 2019, 3:20am UTC](https://discuss.elastic.co/t/where-can-i-find-the-windows-perfmon-dashboard/195155 "2019-08-16T03:20:08Z")

</div>

I can find this ./kibana/7/dashboard/metricbeat-windows-service.json and service dashboard was created in Kibana by using metricbeat.exe setup --dashboards, but I can't find the corresponding json file for PerfMon, any i…

---

## [Extract timestamp from the logline](https://discuss.elastic.co/t/extract-timestamp-from-the-logline/195277)

<div class="topic-metadata">

**Author:** [@justin1](https://discuss.elastic.co/u/justin1)\
**Replies:** 6\
**Last updated:** [August 15, 2019, 11:52pm UTC](https://discuss.elastic.co/t/extract-timestamp-from-the-logline/195277 "2019-08-15T23:52:37Z")

</div>

I am trying to index log files to Elastic search. All the log entries are being indexed into a field named message. @timestamp field shows the time the entry was indexed and not the timestamp from log entry. I created a…

---

## [Kibana is showing only one record on the discover dash board](https://discuss.elastic.co/t/kibana-is-showing-only-one-record-on-the-discover-dash-board/195109)

<div class="topic-metadata">

**Author:** [@Arun\_Soman](https://discuss.elastic.co/u/Arun_Soman)\
**Replies:** 6\
**Last updated:** [August 15, 2019, 7:32pm UTC](https://discuss.elastic.co/t/kibana-is-showing-only-one-record-on-the-discover-dash-board/195109 "2019-08-15T19:32:36Z")

</div>

In my kibana discover dash board it is only showing one record. And the record is updating every time when I have data from file beat. also my \_id value is %{logstash\_checksum} I am using bitnami filebeat -logstash- …

---

## [Filebeat Grok Error - IIS](https://discuss.elastic.co/t/filebeat-grok-error-iis/195100)

<div class="topic-metadata">

**Author:** [@bsanderRMG](https://discuss.elastic.co/u/bsanderRMG)\
**Replies:** 3\
**Last updated:** [August 15, 2019, 7:20pm UTC](https://discuss.elastic.co/t/filebeat-grok-error-iis/195100 "2019-08-15T19:20:32Z")

</div>

ES-7.1.1 Kibana-7.1.1 Filebeat 7.0.1 Hey all, I'm trying to ingest the logs from an IIS 7.5 instance directly to ES, and the logs are being sent through successfully. However, every log is giving an error of "Provided…

---

## [Layer7 API Gateway - parsing logs](https://discuss.elastic.co/t/layer7-api-gateway-parsing-logs/195385)

<div class="topic-metadata">

**Author:** [@Randy-312](https://discuss.elastic.co/u/Randy-312)\
**Replies:** 0\
**Last updated:** [August 15, 2019, 7:19pm UTC](https://discuss.elastic.co/t/layer7-api-gateway-parsing-logs/195385 "2019-08-15T19:19:28Z")

</div>

Anyone boarded Layer7 API Gateway logs, and parsed them? We used to do this with regex, but have moved to FileBeat...albeit in an uparsed mode. We now want to get field level details,like CA has documented. Here are t…

---

## [Add 'exists' filter to rollup](https://discuss.elastic.co/t/add-exists-filter-to-rollup/195367)

<div class="topic-metadata">

**Author:** [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Replies:** 0\
**Last updated:** [August 15, 2019, 3:59pm UTC](https://discuss.elastic.co/t/add-exists-filter-to-rollup/195367 "2019-08-15T15:59:17Z")

</div>

Greetings, I'm working with rollups of metricbeat data. In rollups we want to see only documents that contain a certain field such as system.cpu.total.pct. Can I add the filter directly to the rollup definition? I'd …

---

## [Libbeat common.Match not work with case insensitive](https://discuss.elastic.co/t/libbeat-common-match-not-work-with-case-insensitive/195315)

<div class="topic-metadata">

**Author:** [@111193](https://discuss.elastic.co/u/111193)\
**Replies:** 1\
**Last updated:** [August 15, 2019, 11:57am UTC](https://discuss.elastic.co/t/libbeat-common-match-not-work-with-case-insensitive/195315 "2019-08-15T11:57:46Z")

</div>

beats document said filebeat suppport "(?i)" regexp I read the beats code,found it depend on beats/libbeat/common/match, but I found beats/libbeat/common/match does not work with "(?i)" option version: GitHub - elast…

---

## [How to use Filebeat with a custom index and pattern](https://discuss.elastic.co/t/how-to-use-filebeat-with-a-custom-index-and-pattern/194730)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 3\
**Last updated:** [August 15, 2019, 10:37am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-with-a-custom-index-and-pattern/194730 "2019-08-15T10:37:41Z")

</div>

I am using Filebeat for supported log formats and using the default index settings and mappings etc.. This is great.. Now i also want to send a custom JSON log file, also using Filebeat, but want to send it into it's o…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=325)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=327)
