# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=327

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 328

---

## [Filebeat docker container is not connecting to logstash docker container](https://discuss.elastic.co/t/filebeat-docker-container-is-not-connecting-to-logstash-docker-container/195192)

<div class="topic-metadata">

**Author:** [@douy](https://discuss.elastic.co/u/douy)\
**Replies:** 1\
**Last updated:** [August 15, 2019, 10:31am UTC](https://discuss.elastic.co/t/filebeat-docker-container-is-not-connecting-to-logstash-docker-container/195192 "2019-08-15T10:31:41Z")

</div>

Hi, I've created custom docker images based on ubuntu for elasticsearch, kibana, logstash and filebeat and I'm trying to connect them to each other. I've started out with elasticsearch, which runs perfectly well and is …

---

## [Windows Dhcp Server logs with Filebeat](https://discuss.elastic.co/t/windows-dhcp-server-logs-with-filebeat/194750)

<div class="topic-metadata">

**Author:** [@psyapathy](https://discuss.elastic.co/u/psyapathy)\
**Replies:** 2\
**Last updated:** [August 15, 2019, 5:21am UTC](https://discuss.elastic.co/t/windows-dhcp-server-logs-with-filebeat/194750 "2019-08-15T05:21:41Z")

</div>

Hello! Can i get logs from Windows Dhcp Server with Filebeat into Elasticsearch? Is it possible?

---

## [2019-08-14T21:00:48Z ERR State for READER-006.log should have been dropped, but couldn't as state is not finished](https://discuss.elastic.co/t/2019-08-14t2148z-err-state-for-reader-006-log-should-have-been-dropped-but-couldnt-as-state-is-not-finished/195273)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 0\
**Last updated:** [August 14, 2019, 10:01pm UTC](https://discuss.elastic.co/t/2019-08-14t2148z-err-state-for-reader-006-log-should-have-been-dropped-but-couldnt-as-state-is-not-finished/195273 "2019-08-14T22:01:30Z")

</div>

HI, Filebeat team, we have lots of error lines in the filebeat log, i am wondering is this serious? what might have caused this? thanks! 2019-08-14T21:00:48Z ERR State for READER-006.log should have been dropped, but …

---

## [Cant't change index name in metricbeat](https://discuss.elastic.co/t/cantt-change-index-name-in-metricbeat/195182)

<div class="topic-metadata">

**Author:** [@simple\_commentateur](https://discuss.elastic.co/u/simple_commentateur)\
**Replies:** 1\
**Last updated:** [August 14, 2019, 5:52pm UTC](https://discuss.elastic.co/t/cantt-change-index-name-in-metricbeat/195182 "2019-08-14T17:52:36Z")

</div>

Hello, I want to change the index name for the metricbeat. For that I try to change index name in Outputs of metricbeat.yml and metricbeat.reference.yml file as shown below : setup.template.name: "test-" setup.templat…

---

## [Winlogbeat lost logs](https://discuss.elastic.co/t/winlogbeat-lost-logs/195127)

<div class="topic-metadata">

**Author:** [@cmz729268499](https://discuss.elastic.co/u/cmz729268499)\
**Replies:** 1\
**Last updated:** [August 14, 2019, 5:41pm UTC](https://discuss.elastic.co/t/winlogbeat-lost-logs/195127 "2019-08-14T17:41:37Z")

</div>

I installed winlogbeat6.4 on windows server 2008R2 and sent the log to logstash. When I set ignore\_older to 5S, I found that some logs were lost. What is the reason?

---

## [TShark and Rotating JSON Files](https://discuss.elastic.co/t/tshark-and-rotating-json-files/195124)

<div class="topic-metadata">

**Author:** [@michaelberg](https://discuss.elastic.co/u/michaelberg)\
**Replies:** 2\
**Last updated:** [August 14, 2019, 4:24pm UTC](https://discuss.elastic.co/t/tshark-and-rotating-json-files/195124 "2019-08-14T16:24:44Z")

</div>

Greetings ... I am searching and searching and cannot seem to find a way to have TShark capture packets live to ElasticSearch JSON format and rotate them so I create a new JSON file, say, every hour or every 6 hours or …

---

## [ICMP error](https://discuss.elastic.co/t/icmp-error/195227)

<div class="topic-metadata">

**Author:** [@Felipe\_Cabral\_Jeroni](https://discuss.elastic.co/u/Felipe_Cabral_Jeroni)\
**Replies:** 0\
**Last updated:** [August 14, 2019, 3:22pm UTC](https://discuss.elastic.co/t/icmp-error/195227 "2019-08-14T15:22:28Z")

</div>

Hi guys, I've configured the packetbeat to send information to logstash. The beats are arriving in logstash and elasticsearch but there is an error in its status for ICMP "DestinationUnreachable(Host)", as you can see b…

---

## [IIS logs and timezone](https://discuss.elastic.co/t/iis-logs-and-timezone/194948)

<div class="topic-metadata">

**Author:** [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Replies:** 1\
**Last updated:** [August 14, 2019, 2:28pm UTC](https://discuss.elastic.co/t/iis-logs-and-timezone/194948 "2019-08-14T14:28:47Z")

</div>

Guys really sorry if this is a repeat Question. I have searched and read almost all the posts on timezone and iis. but i m not able to fix my issue. I guess i m overthinking :slight\_smile: so here is my setup. windows f…

---

## [Dependencies for kubernetes module? capacity=0](https://discuss.elastic.co/t/dependencies-for-kubernetes-module-capacity-0/195209)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [August 14, 2019, 1:10pm UTC](https://discuss.elastic.co/t/dependencies-for-kubernetes-module-capacity-0/195209 "2019-08-14T13:10:44Z")

</div>

Hi, I installed metricbeat for kubernetes. On one host the capacity has values, on other nodes, like shown value is always zero. Where does metricbeat get this data from? What may be the issue that it does not show v…

---

## [ERR Harvester logs : Connection reset by peer](https://discuss.elastic.co/t/err-harvester-logs-connection-reset-by-peer/194550)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 2\
**Last updated:** [August 14, 2019, 10:34am UTC](https://discuss.elastic.co/t/err-harvester-logs-connection-reset-by-peer/194550 "2019-08-14T10:34:11Z")

</div>

Hi, I am getting the following error harvester logs in kibana from filebeat and followed by info logs so , is it fine is my filebeat sending the logs after showing connection reset by peer or not ? This is happening ev…

---

## [Missing container fields](https://discuss.elastic.co/t/missing-container-fields/195179)

<div class="topic-metadata">

**Author:** [@shalvah.deimos](https://discuss.elastic.co/u/shalvah.deimos)\
**Replies:** 0\
**Last updated:** [August 14, 2019, 9:53am UTC](https://discuss.elastic.co/t/missing-container-fields/195179 "2019-08-14T09:53:20Z")

</div>

I'm running Filebeat 7.3 on Kubernetes with this configuration: processors: - add\_cloud\_metadata: - add\_kubernetes\_metadata: in\_cluster: true filebeat.autodiscover: providers: - type:…

---

## [System module not logging severity & facility](https://discuss.elastic.co/t/system-module-not-logging-severity-facility/195171)

<div class="topic-metadata">

**Author:** [@hrak](https://discuss.elastic.co/u/hrak)\
**Replies:** 0\
**Last updated:** [August 14, 2019, 9:41am UTC](https://discuss.elastic.co/t/system-module-not-logging-severity-facility/195171 "2019-08-14T09:41:13Z")

</div>

Judging from the ingest pipeline definition of the Filebeat system module, it currently does not support logging of the severity and facility of an event, even if you adapt your syslog daemon configuration to log these i…

---

## [Index name for modules](https://discuss.elastic.co/t/index-name-for-modules/194893)

<div class="topic-metadata">

**Author:** [@tenney](https://discuss.elastic.co/u/tenney)\
**Replies:** 3\
**Last updated:** [August 14, 2019, 9:37am UTC](https://discuss.elastic.co/t/index-name-for-modules/194893 "2019-08-14T09:37:56Z")

</div>

Using filebeat 7.3.0 on ubuntu and can't seem to change the index name for any modules that get enabled. All I want to do is make the indexes that get created be done so monthly names instead of daily. I would expect t…

---

## [How to create custom fields like apache for Tomcat logs?](https://discuss.elastic.co/t/how-to-create-custom-fields-like-apache-for-tomcat-logs/193628)

<div class="topic-metadata">

**Author:** [@Aftab\_Ali](https://discuss.elastic.co/u/Aftab_Ali)\
**Replies:** 2\
**Last updated:** [August 14, 2019, 8:57am UTC](https://discuss.elastic.co/t/how-to-create-custom-fields-like-apache-for-tomcat-logs/193628 "2019-08-14T08:57:00Z")

</div>

Dear Team, I am happy to use your services but I want to create custom fields like apache module response code, error and I want to create same to same fields for tomcat access logs, how it is possible, Please share th…

---

## [Filebeat stops sending logs when load balancing is enabled and second node unavailable](https://discuss.elastic.co/t/filebeat-stops-sending-logs-when-load-balancing-is-enabled-and-second-node-unavailable/195163)

<div class="topic-metadata">

**Author:** [@Hawchik\_Pupkur](https://discuss.elastic.co/u/Hawchik_Pupkur)\
**Replies:** 0\
**Last updated:** [August 14, 2019, 8:39am UTC](https://discuss.elastic.co/t/filebeat-stops-sending-logs-when-load-balancing-is-enabled-and-second-node-unavailable/195163 "2019-08-14T08:39:46Z")

</div>

Hello I have two nodes. If one of them becomes unavailable the filebeat stops sending logs to both nodes. This looks like a bug https://github.com/elastic/beats/issues/1829 but it\`s already fixed(in which version?) My…

---

## [Nginx Module (Filebeat) getting data from another server](https://discuss.elastic.co/t/nginx-module-filebeat-getting-data-from-another-server/195130)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 1\
**Last updated:** [August 14, 2019, 6:20am UTC](https://discuss.elastic.co/t/nginx-module-filebeat-getting-data-from-another-server/195130 "2019-08-14T06:20:45Z")

</div>

I am trying to resolve the following case. I have my ES, filebeat, logstash, and kibana installed and setup on Server A. But now I am trying to activate this "Nginx module" to monitor activities and logs from Server B. …

---

## [Normalized fields are not acting like numerical fields?](https://discuss.elastic.co/t/normalized-fields-are-not-acting-like-numerical-fields/195113)

<div class="topic-metadata">

**Author:** [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Replies:** 0\
**Last updated:** [August 13, 2019, 9:54pm UTC](https://discuss.elastic.co/t/normalized-fields-are-not-acting-like-numerical-fields/195113 "2019-08-13T21:54:32Z")

</div>

Hello out there. If I work with utilization data from Metricbeat, fields like system.cpu.total.pct are easy to create graphs with, can be used for statistical analysis, etc. However the normalized values like system.cp…

---

## [Custom dashboard for kubernets monitoring](https://discuss.elastic.co/t/custom-dashboard-for-kubernets-monitoring/195046)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [August 13, 2019, 2:34pm UTC](https://discuss.elastic.co/t/custom-dashboard-for-kubernets-monitoring/195046 "2019-08-13T14:34:19Z")

</div>

Hi, Ive setup metricbeat with kubernetes module to ship data to elasticsearch. I want to create dashboards to monitor deployments or statefulsets including used resources like volumes, etc. I had a first look on the sam…

---

## [Bytes to kbytes](https://discuss.elastic.co/t/bytes-to-kbytes/195094)

<div class="topic-metadata">

**Author:** [@SirJune](https://discuss.elastic.co/u/SirJune)\
**Replies:** 0\
**Last updated:** [August 13, 2019, 8:04pm UTC](https://discuss.elastic.co/t/bytes-to-kbytes/195094 "2019-08-13T20:04:55Z")

</div>

So i have metricbeats running. I am trying to create a visualization for the reads & writes but in kbytes unit. is scripted field the correct way to achieve it? i tried one but it's giving me this error. "script"…

---

## [Connection reset by peer with loadbalance: true filebeat =\> logstash](https://discuss.elastic.co/t/connection-reset-by-peer-with-loadbalance-true-filebeat-logstash/194604)

<div class="topic-metadata">

**Author:** [@a.gavric](https://discuss.elastic.co/u/a.gavric)\
**Replies:** 2\
**Last updated:** [August 13, 2019, 11:08am UTC](https://discuss.elastic.co/t/connection-reset-by-peer-with-loadbalance-true-filebeat-logstash/194604 "2019-08-13T11:08:09Z")

</div>

Hello, i have been looking into the issue between filebeat and logstash for days now and have unfortunately gotten nowhere. Namely the configuration we have is as following: Test Environment (firewall and SELinux disab…

---

## [Incorrect CPU usage and core count reading in metricbeat](https://discuss.elastic.co/t/incorrect-cpu-usage-and-core-count-reading-in-metricbeat/193722)

<div class="topic-metadata">

**Author:** [@mafshin](https://discuss.elastic.co/u/mafshin)\
**Replies:** 2\
**Last updated:** [August 13, 2019, 10:47am UTC](https://discuss.elastic.co/t/incorrect-cpu-usage-and-core-count-reading-in-metricbeat/193722 "2019-08-13T10:47:44Z")

</div>

I'm using system.cpu.total.norm.pct for average CPU usage but in some of the servers the reading is incorrect, which I guess is probably related to incorrect reading of system.cpu.cores CPU usage reported by system.cpu.…

---

## [Kubernetes metricbeat module - how to setup?](https://discuss.elastic.co/t/kubernetes-metricbeat-module-how-to-setup/194999)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [August 13, 2019, 10:40am UTC](https://discuss.elastic.co/t/kubernetes-metricbeat-module-how-to-setup/194999 "2019-08-13T10:40:52Z")

</div>

Hi, I am quite new to kubernetes and want to run metricbeat in kubernetes, so that I can see whats going on in kubernetes in my elastic stack. Kubernetes is running on bare metal, so there is no cloud provider involved…

---

## [Starting Filebeat issue](https://discuss.elastic.co/t/starting-filebeat-issue/194977)

<div class="topic-metadata">

**Author:** [@manickalai](https://discuss.elastic.co/u/manickalai)\
**Replies:** 2\
**Last updated:** [August 13, 2019, 10:15am UTC](https://discuss.elastic.co/t/starting-filebeat-issue/194977 "2019-08-13T10:15:57Z")

</div>

While starting Filebeat getting below error Error: Starting filebeat: Exiting: error unpacking config data: can not convert 'string' into 'object' accessing 'output.logstash' (source:'/etc/filebeat/filebeat.yml') acces…

---

## [Create new Fields to Filter by](https://discuss.elastic.co/t/create-new-fields-to-filter-by/194798)

<div class="topic-metadata">

**Author:** [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Replies:** 2\
**Last updated:** [August 13, 2019, 9:57am UTC](https://discuss.elastic.co/t/create-new-fields-to-filter-by/194798 "2019-08-13T09:57:44Z")

</div>

Hello Community, i'm still pretty new to Elastic-Stack. I got a Cluster of 1 Master and 2 Nodes set up, and already got all my Beat-Agents deployed on the servers. Now i set up beat nodes on my Cluster aswell, to monit…

---

## [Problem with JSON date types](https://discuss.elastic.co/t/problem-with-json-date-types/194780)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 2\
**Last updated:** [August 13, 2019, 9:40am UTC](https://discuss.elastic.co/t/problem-with-json-date-types/194780 "2019-08-13T09:40:35Z")

</div>

I am generating custom logs formatted as single line JSON with Date fields and sending them to ES with Filebeat, however when the index and pattern is created, the date fields are Strings and numbers instead of Dates. d…

---

## [Many many processors, how many is too many?](https://discuss.elastic.co/t/many-many-processors-how-many-is-too-many/194729)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 1\
**Last updated:** [August 13, 2019, 9:15am UTC](https://discuss.elastic.co/t/many-many-processors-how-many-is-too-many/194729 "2019-08-13T09:15:54Z")

</div>

I have a very long winlogbeat processor list that does a heap of security related stuff like; Add failure code descriptions - add\_fields: when.equals.winlog.event\_data.Status: "0xc000006a" fields: …

---

## [ILM reports error illegal\_argument\_exception](https://discuss.elastic.co/t/ilm-reports-error-illegal-argument-exception/194968)

<div class="topic-metadata">

**Author:** [@swieczor](https://discuss.elastic.co/u/swieczor)\
**Replies:** 0\
**Last updated:** [August 13, 2019, 6:53am UTC](https://discuss.elastic.co/t/ilm-reports-error-illegal-argument-exception/194968 "2019-08-13T06:53:42Z")

</div>

Elasticsearch version : 7.2.0 Installed by eck-operator: 0.9.0-rc7 Plugins installed : as installed by eck-operator version 0.9.0-rc7 docker.elastic.co/elasticsearch/elasticsearch:7.2.0 JVM version ( java -version ):…

---

## [Problems with metricbeat 7.3.0 using filebeat to ship metricbeat probe logs](https://discuss.elastic.co/t/problems-with-metricbeat-7-3-0-using-filebeat-to-ship-metricbeat-probe-logs/194845)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 2\
**Last updated:** [August 13, 2019, 6:36am UTC](https://discuss.elastic.co/t/problems-with-metricbeat-7-3-0-using-filebeat-to-ship-metricbeat-probe-logs/194845 "2019-08-13T06:36:33Z")

</div>

Hi, I was using metricbeat 6.5.4 in my dev system before I upgraded to 7.3.0. Metricbeat is not pushing directly elasticsearch, but is the probes it takes to filesystem. So filesystem is my first buffer layer for metri…

---

## [Uwsgi statistics parsing failed with error: unexpected end of JSON input](https://discuss.elastic.co/t/uwsgi-statistics-parsing-failed-with-error-unexpected-end-of-json-input/192624)

<div class="topic-metadata">

**Author:** [@Angelo\_Deng](https://discuss.elastic.co/u/Angelo_Deng)\
**Replies:** 1\
**Last updated:** [August 12, 2019, 6:22pm UTC](https://discuss.elastic.co/t/uwsgi-statistics-parsing-failed-with-error-unexpected-end-of-json-input/192624 "2019-08-12T18:22:04Z")

</div>

Did anyone meet the problem? I add the uwsgi module on metricbeat My config is : metricbeat.modules: module: docker metricsets: "container" "cpu" "diskio" "healthcheck" "info" #- "image" "memory" "network" hosts…

---

## [Filebeat not filtering for separate index](https://discuss.elastic.co/t/filebeat-not-filtering-for-separate-index/193742)

<div class="topic-metadata">

**Author:** [@lucabes](https://discuss.elastic.co/u/lucabes)\
**Replies:** 9\
**Last updated:** [August 12, 2019, 7:30am UTC](https://discuss.elastic.co/t/filebeat-not-filtering-for-separate-index/193742 "2019-08-12T07:30:55Z")

</div>

I have problem with my filebeat configuration, it doesnt filter logs to separate index in elasticsearch. My configuration looks like: logging: level: error metrics: enabled: false filebeat.modules: - module…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=326)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=328)
