# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=329

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 330

---

## [Getting json data into Elasticsearch](https://discuss.elastic.co/t/getting-json-data-into-elasticsearch/194457)

<div class="topic-metadata">

**Author:** [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Replies:** 0\
**Last updated:** [August 8, 2019, 2:57pm UTC](https://discuss.elastic.co/t/getting-json-data-into-elasticsearch/194457 "2019-08-08T14:57:45Z")

</div>

Hi all, I have a simple json (key/single value per key) file I need to get into Elasticsearch via Filebeat. I've been able to do this, but it's using the standard filebeat index, therefore the datatypes are off and I c…

---

## [Filebeat: field "log.file" - is empty](https://discuss.elastic.co/t/filebeat-field-log-file-is-empty/194295)

<div class="topic-metadata">

**Author:** [@maxozerov](https://discuss.elastic.co/u/maxozerov)\
**Replies:** 3\
**Last updated:** [August 8, 2019, 2:29pm UTC](https://discuss.elastic.co/t/filebeat-field-log-file-is-empty/194295 "2019-08-08T14:29:54Z")

</div>

Hi There, Hope you are good. Help to understand what is the reason # Custom filebeat-module - module: my-service ## Requests logs requests: enabled: true var.paths: \["/var/lib/lxd/containers/ZZ/rootfs/var/…

---

## [Do I only need to run metricbeat setup once?](https://discuss.elastic.co/t/do-i-only-need-to-run-metricbeat-setup-once/194089)

<div class="topic-metadata">

**Author:** [@carson](https://discuss.elastic.co/u/carson)\
**Replies:** 3\
**Last updated:** [August 8, 2019, 2:23pm UTC](https://discuss.elastic.co/t/do-i-only-need-to-run-metricbeat-setup-once/194089 "2019-08-08T14:23:34Z")

</div>

Hi, this may be a dumb question, but important to my work. I was encountering a huge problem that I fixed by doing a metricbeat setup before running. I had previously thought I could get away without doing it, which is …

---

## [Error 1053 the service did not respond to the start or control request in a timely fashion](https://discuss.elastic.co/t/error-1053-the-service-did-not-respond-to-the-start-or-control-request-in-a-timely-fashion/194388)

<div class="topic-metadata">

**Author:** [@marcohald](https://discuss.elastic.co/u/marcohald)\
**Replies:** 0\
**Last updated:** [August 8, 2019, 9:37am UTC](https://discuss.elastic.co/t/error-1053-the-service-did-not-respond-to-the-start-or-control-request-in-a-timely-fashion/194388 "2019-08-08T09:37:09Z")

</div>

Hi, i have had installed the winlogbeat server on a 2019 Server and it worked without a Problem. Then I uninstalled it and tested a few things and tweaked the config. Now when i reinstall it i cannot start it. I get t…

---

## [Error running input: error receiving slowlog data: dial tcp 127.0.0.1:6379: connect: connection refused](https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-dial-tcp-127-0-0-1-connect-connection-refused/193157)

<div class="topic-metadata">

**Author:** [@loas](https://discuss.elastic.co/u/loas)\
**Replies:** 2\
**Last updated:** [August 8, 2019, 1:00pm UTC](https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-dial-tcp-127-0-0-1-connect-connection-refused/193157 "2019-08-08T13:00:47Z")

</div>

Hey gang, I am trying the Filebeat Redis module on Kubernetes but can't seem to get past the following errors. Error running input: error receiving slowlog data: dial tcp 127.0.0.1:6379: connect: connection refused Er…

---

## [I updated metricbeat from 7.2 to 7.3 and now metrics dashboard don't show network or cpu, just load and memory](https://discuss.elastic.co/t/i-updated-metricbeat-from-7-2-to-7-3-and-now-metrics-dashboard-dont-show-network-or-cpu-just-load-and-memory/194265)

<div class="topic-metadata">

**Author:** [@amcneill3](https://discuss.elastic.co/u/amcneill3)\
**Replies:** 2\
**Last updated:** [August 8, 2019, 10:57am UTC](https://discuss.elastic.co/t/i-updated-metricbeat-from-7-2-to-7-3-and-now-metrics-dashboard-dont-show-network-or-cpu-just-load-and-memory/194265 "2019-08-08T10:57:22Z")

</div>

I updated metricbeat from 7.2 to 7.3 and some of my beas clients, after updating elasticsearch, logstash and kibana from 7.2 to 7.3. and now metrics dashboard don't show network or cpu, just load and memory. I can dis…

---

## [Multi port output configuration](https://discuss.elastic.co/t/multi-port-output-configuration/194395)

<div class="topic-metadata">

**Author:** [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Replies:** 0\
**Last updated:** [August 8, 2019, 10:10am UTC](https://discuss.elastic.co/t/multi-port-output-configuration/194395 "2019-08-08T10:10:57Z")

</div>

Hi Team, I have multiple filebeat instances running in different machines to pull the logs from the instace. We have one single file beat file in all instance to pull the logs and send the data to logstash. We tried us…

---

## [Filebeat won't read log files](https://discuss.elastic.co/t/filebeat-wont-read-log-files/190821)

<div class="topic-metadata">

**Author:** [@tsc036](https://discuss.elastic.co/u/tsc036)\
**Replies:** 9\
**Last updated:** [August 8, 2019, 10:04am UTC](https://discuss.elastic.co/t/filebeat-wont-read-log-files/190821 "2019-08-08T10:04:03Z")

</div>

My filebeat doesn't read log files to send to logstash on a remote server. Here is my config file: filebeat.inputs: type: log enabled: true paths: -/var/log/demisto/\*.log logging.level: debug logging.to\_files: t…

---

## [Filebeat multiline setting not working](https://discuss.elastic.co/t/filebeat-multiline-setting-not-working/194263)

<div class="topic-metadata">

**Author:** [@rituzy](https://discuss.elastic.co/u/rituzy)\
**Replies:** 2\
**Last updated:** [August 8, 2019, 8:19am UTC](https://discuss.elastic.co/t/filebeat-multiline-setting-not-working/194263 "2019-08-08T08:19:01Z")

</div>

Hi, I was trying to consolidate stack trace by filebeat as per instruction here This is my filebeat.yml settings filebeat.inputs: - type: log enabled: true paths: - /home/myHomeFolder/log\_example.log fie…

---

## [Missing column kubernetes.container.memory.limit.bytes using Kubernetes](https://discuss.elastic.co/t/missing-column-kubernetes-container-memory-limit-bytes-using-kubernetes/193549)

<div class="topic-metadata">

**Author:** [@warnerrj79](https://discuss.elastic.co/u/warnerrj79)\
**Replies:** 1\
**Last updated:** [August 8, 2019, 3:59am UTC](https://discuss.elastic.co/t/missing-column-kubernetes-container-memory-limit-bytes-using-kubernetes/193549 "2019-08-08T03:59:44Z")

</div>

Hi Using Kubernetes 1.12.7, I am attempting to bring through the kubernetes.container.memory.limit.bytes column, but there is no information being yielded. I am trying to use this column as the basis of a memory calcul…

---

## [Metricbeat: How to enable geo ip processor](https://discuss.elastic.co/t/metricbeat-how-to-enable-geo-ip-processor/194196)

<div class="topic-metadata">

**Author:** [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Replies:** 1\
**Last updated:** [August 8, 2019, 12:37am UTC](https://discuss.elastic.co/t/metricbeat-how-to-enable-geo-ip-processor/194196 "2019-08-08T00:37:46Z")

</div>

Hello Team I've installed packetbeat and running it on Ubuntu. Everything is fine but I see that geo ip data is missing on maps ? Any suggestions on how to enable the the geo ip?

---

## [TTY Auditing User Keystrokes](https://discuss.elastic.co/t/tty-auditing-user-keystrokes/194000)

<div class="topic-metadata">

**Author:** [@SCL\_ADMIN](https://discuss.elastic.co/u/SCL_ADMIN)\
**Replies:** 3\
**Last updated:** [August 8, 2019, 12:25am UTC](https://discuss.elastic.co/t/tty-auditing-user-keystrokes/194000 "2019-08-08T00:25:00Z")

</div>

Hello I've managed to get Auditbeats working a remote server and I have enabled user keystrokes But I'm a bit lost in finding the entries showing the keystrokes when using the server as a user. Do i need to need to p…

---

## [Filebeat netflow events per second - losing data?](https://discuss.elastic.co/t/filebeat-netflow-events-per-second-losing-data/194279)

<div class="topic-metadata">

**Author:** [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Replies:** 1\
**Last updated:** [August 8, 2019, 12:16am UTC](https://discuss.elastic.co/t/filebeat-netflow-events-per-second-losing-data/194279 "2019-08-08T00:16:45Z")

</div>

Hi there, we are currently trying to use Logstash and Filebeat to process a large netflow stream. We are running filebeat and logstash in docker containers using the official elastic search container images. The server r…

---

## [Cisco ASA Netflow](https://discuss.elastic.co/t/cisco-asa-netflow/194107)

<div class="topic-metadata">

**Author:** [@dmitriy.y](https://discuss.elastic.co/u/dmitriy.y)\
**Replies:** 1\
**Last updated:** [August 7, 2019, 4:42pm UTC](https://discuss.elastic.co/t/cisco-asa-netflow/194107 "2019-08-07T16:42:35Z")

</div>

I am using latest 7.3 ELK stack with filebeat. Configured netflow with the filebeat netflow plugin to monitor my ASA. For network.direction i am getting "unknown" For network.bytes i am getting just "-" Any tips woul…

---

## [Using Winlogbeat 7.2.0 with ILM enabled - Winlogbeat does not synchronize old logs. just todays logs](https://discuss.elastic.co/t/using-winlogbeat-7-2-0-with-ilm-enabled-winlogbeat-does-not-synchronize-old-logs-just-todays-logs/194291)

<div class="topic-metadata">

**Author:** [@jeetthakkar](https://discuss.elastic.co/u/jeetthakkar)\
**Replies:** 3\
**Last updated:** [August 7, 2019, 7:53pm UTC](https://discuss.elastic.co/t/using-winlogbeat-7-2-0-with-ilm-enabled-winlogbeat-does-not-synchronize-old-logs-just-todays-logs/194291 "2019-08-07T19:53:28Z")

</div>

Hello, I can't import the older logs into elasticsearch even though the following options have been specified into winlogbeat.yml. winlogbeat.event\_logs: - name: Application ignore\_older: 720h - name: System …

---

## [Audit logs are not rotated correctly when the elasticsearch module is enabled](https://discuss.elastic.co/t/audit-logs-are-not-rotated-correctly-when-the-elasticsearch-module-is-enabled/193526)

<div class="topic-metadata">

**Author:** [@gerarddp](https://discuss.elastic.co/u/gerarddp)\
**Replies:** 4\
**Last updated:** [August 7, 2019, 1:56pm UTC](https://discuss.elastic.co/t/audit-logs-are-not-rotated-correctly-when-the-elasticsearch-module-is-enabled/193526 "2019-08-07T13:56:46Z")

</div>

When enabling the audit log parsing with the elasticsearch module for filbeat, the audit logs are not rotate correctly because filebeat keeps the files open. That also causes the disk to get full quickly because of the a…

---

## [Metricbeat Kubernetes module - all events have failures but no ERROR message in logs](https://discuss.elastic.co/t/metricbeat-kubernetes-module-all-events-have-failures-but-no-error-message-in-logs/194237)

<div class="topic-metadata">

**Author:** [@Majus\_Misiak](https://discuss.elastic.co/u/Majus_Misiak)\
**Replies:** 2\
**Last updated:** [August 7, 2019, 12:27pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module-all-events-have-failures-but-no-error-message-in-logs/194237 "2019-08-07T12:27:56Z")

</div>

I am using stable/metricbeat Helm Chart for installing metricbeat on Kubernetes cluster NAME CHART VERSION APP VERSION DESCRIPTION stable/metricbeat 1.7.0 6.7.0 A Helm …

---

## [Functionbeat license error](https://discuss.elastic.co/t/functionbeat-license-error/194129)

<div class="topic-metadata">

**Author:** [@smahmud](https://discuss.elastic.co/u/smahmud)\
**Replies:** 1\
**Last updated:** [August 7, 2019, 12:12pm UTC](https://discuss.elastic.co/t/functionbeat-license-error/194129 "2019-08-07T12:12:23Z")

</div>

I have successfully setup functionbeat on aws, but I am getting following license error, license manager stops and function stops: 2019-08-07T03:11:55.435Z INFO \[functionbeat\] beater/functionbeat.go:74 Functionbeat is r…

---

## [Convert\_timezone alternative in Filebeat 7.3.0](https://discuss.elastic.co/t/convert-timezone-alternative-in-filebeat-7-3-0/194160)

<div class="topic-metadata">

**Author:** [@gmolina](https://discuss.elastic.co/u/gmolina)\
**Replies:** 1\
**Last updated:** [August 7, 2019, 11:27am UTC](https://discuss.elastic.co/t/convert-timezone-alternative-in-filebeat-7-3-0/194160 "2019-08-07T11:27:20Z")

</div>

In Filebeat 7.3.0 the way timezone conversion is applied is different. Now, you have to use processors to add, remove or change the "event.timezone" variable. Now, I can't get it to work, at least with the panw module. I…

---

## [Filebeat is running but not sending logs/data to logstash](https://discuss.elastic.co/t/filebeat-is-running-but-not-sending-logs-data-to-logstash/193802)

<div class="topic-metadata">

**Author:** [@hitesh\_kumar](https://discuss.elastic.co/u/hitesh_kumar)\
**Replies:** 1\
**Last updated:** [August 7, 2019, 11:25am UTC](https://discuss.elastic.co/t/filebeat-is-running-but-not-sending-logs-data-to-logstash/193802 "2019-08-07T11:25:13Z")

</div>

Hi Team, I am trying to setup filebeat on my centos 7 machine. filebeat is working fine but still not able to send logstash. Filebeat.yml file ###################### Filebeat Configuration Example ####################…

---

## [Silent installation and configuration steps for Windows FileBeat agent](https://discuss.elastic.co/t/silent-installation-and-configuration-steps-for-windows-filebeat-agent/194190)

<div class="topic-metadata">

**Author:** [@pkosuru](https://discuss.elastic.co/u/pkosuru)\
**Replies:** 0\
**Last updated:** [August 7, 2019, 9:10am UTC](https://discuss.elastic.co/t/silent-installation-and-configuration-steps-for-windows-filebeat-agent/194190 "2019-08-07T09:10:41Z")

</div>

Hi Team, We are planning to go for Silent installation and configuration of Windows FileBeat agent on windows machine Can you suggest the steps required to follow Thanks

---

## [Error: Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/error-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/192106)

<div class="topic-metadata">

**Author:** [@Saber.Tala](https://discuss.elastic.co/u/Saber.Tala)\
**Replies:** 5\
**Last updated:** [August 7, 2019, 4:28am UTC](https://discuss.elastic.co/t/error-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/192106 "2019-08-07T04:28:00Z")

</div>

Got following error when tried to start Filebeat service: \[root@VM1 filebeat\]# systemctl start filebeat Exiting: no modules or inputs enabled and configuration reloading disabled. What files do you want me to watch? \*\*F…

---

## [Encounter an error while startup winlogbeat](https://discuss.elastic.co/t/encounter-an-error-while-startup-winlogbeat/193740)

<div class="topic-metadata">

**Author:** [@ravipemmasani](https://discuss.elastic.co/u/ravipemmasani)\
**Replies:** 8\
**Last updated:** [August 7, 2019, 12:17am UTC](https://discuss.elastic.co/t/encounter-an-error-while-startup-winlogbeat/193740 "2019-08-07T00:17:03Z")

</div>

Hello Team, While we are doing POC,i am getting following error when starting up WinlogBeat on remote Host.Following is my ELK stack version info.Would really appreciate your help. Syslog-ng-3.21 ElasticSearch-7.2 Lo…

---

## [Plans to support UDP Logstash output](https://discuss.elastic.co/t/plans-to-support-udp-logstash-output/194102)

<div class="topic-metadata">

**Author:** [@ssiws](https://discuss.elastic.co/u/ssiws)\
**Replies:** 1\
**Last updated:** [August 6, 2019, 9:54pm UTC](https://discuss.elastic.co/t/plans-to-support-udp-logstash-output/194102 "2019-08-06T21:54:32Z")

</div>

Hello, are you planning to support UDP output ? It would be very helpful to achieve true load balancing when using a 3rd party load balancer. Typically, we have a load-balancer (hardware appliance) with backend servers…

---

## [Trying to set a POST in heartbeat](https://discuss.elastic.co/t/trying-to-set-a-post-in-heartbeat/192961)

<div class="topic-metadata">

**Author:** [@Carlos\_Bodini](https://discuss.elastic.co/u/Carlos_Bodini)\
**Replies:** 1\
**Last updated:** [August 6, 2019, 7:55pm UTC](https://discuss.elastic.co/t/trying-to-set-a-post-in-heartbeat/192961 "2019-08-06T19:55:34Z")

</div>

hey guys, i'm trying to set a POST monitor in heartbeat but i'm failing, maybe i'm missing something really obvious.... Here my .yml so, maybe one of you could help me to set it up? heartbeat.monitors: - type: http …

---

## [Filebeat creates a "Standalone Cluster" in Kibana Monitoring](https://discuss.elastic.co/t/filebeat-creates-a-standalone-cluster-in-kibana-monitoring/188663)

<div class="topic-metadata">

**Author:** [@Christophe\_Journel](https://discuss.elastic.co/u/Christophe_Journel)\
**Replies:** 8\
**Last updated:** [August 6, 2019, 7:20pm UTC](https://discuss.elastic.co/t/filebeat-creates-a-standalone-cluster-in-kibana-monitoring/188663 "2019-08-06T19:20:41Z")

</div>

Hello, I have a whole ELK stack which is perfectly functionnal on production. However, i'm trying (with 7.2.0) to get metrics from filebeat. The problem is: It creates a new "cluster" in Kibana Monitoring page : "Stan…

---

## [AWS Log parsing - Are there any Field extraction 'templates' available](https://discuss.elastic.co/t/aws-log-parsing-are-there-any-field-extraction-templates-available/193636)

<div class="topic-metadata">

**Author:** [@Randy-312](https://discuss.elastic.co/u/Randy-312)\
**Replies:** 1\
**Last updated:** [August 6, 2019, 6:59pm UTC](https://discuss.elastic.co/t/aws-log-parsing-are-there-any-field-extraction-templates-available/193636 "2019-08-06T18:59:12Z")

</div>

I'm a fan of how the beats/logstash modules work, and can help provide logstash an easier way to break messages up so that we have explicit fields that are not originally in the metadata (ie apache logs). I'm looking to…

---

## [Tuning for harvesting a large number of files](https://discuss.elastic.co/t/tuning-for-harvesting-a-large-number-of-files/194076)

<div class="topic-metadata">

**Author:** [@btrowbri](https://discuss.elastic.co/u/btrowbri)\
**Replies:** 0\
**Last updated:** [August 6, 2019, 6:03pm UTC](https://discuss.elastic.co/t/tuning-for-harvesting-a-large-number-of-files/194076 "2019-08-06T18:03:07Z")

</div>

Hello, We are having some difficulty configuring our Filebeat to forward a large number of log files to our System. Since we are deploying on another tenant's machine we are required to keep the resource consumption to…

---

## [Compile packetbeat on Centos6.8](https://discuss.elastic.co/t/compile-packetbeat-on-centos6-8/190639)

<div class="topic-metadata">

**Author:** [@meng\_liu](https://discuss.elastic.co/u/meng_liu)\
**Replies:** 7\
**Last updated:** [August 6, 2019, 5:39pm UTC](https://discuss.elastic.co/t/compile-packetbeat-on-centos6-8/190639 "2019-08-06T17:39:49Z")

</div>

I have installed libpcap in Centos6.8, but when i compile packetbeat, it occurs a error, as flows: go build -i -ldflags "-X github.com/elastic/beats/libbeat/version.buildTime=2019-07-16T03:40:29Z -X github.com/elastic/b…

---

## [How to use packetbeat to monitor mysql of docker container?](https://discuss.elastic.co/t/how-to-use-packetbeat-to-monitor-mysql-of-docker-container/187968)

<div class="topic-metadata">

**Author:** [@meng\_liu](https://discuss.elastic.co/u/meng_liu)\
**Replies:** 4\
**Last updated:** [August 6, 2019, 5:37pm UTC](https://discuss.elastic.co/t/how-to-use-packetbeat-to-monitor-mysql-of-docker-container/187968 "2019-08-06T17:37:24Z")

</div>

Mysql and packetbeat be installed on the same machine! Mysql is started in docker container, and the packetbeat is installed on local machine. Local machine's 3306 is mapping mysql of container's 3306, i use packetbe…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=328)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=330)
