# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=330

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 331

---

## [Configuring Input Type for Filebeat Module](https://discuss.elastic.co/t/configuring-input-type-for-filebeat-module/193819)

<div class="topic-metadata">

**Author:** [@learnitall](https://discuss.elastic.co/u/learnitall)\
**Replies:** 2\
**Last updated:** [August 6, 2019, 4:14pm UTC](https://discuss.elastic.co/t/configuring-input-type-for-filebeat-module/193819 "2019-08-06T16:14:50Z")

</div>

Hello! Is there a way to add configuration options to the lower-level input type that a filebeat module uses? For instance, if I am using the zeek filebeat module and I want to change some of the default settings for the…

---

## [Filebeat Amazon ECS log rotation issue](https://discuss.elastic.co/t/filebeat-amazon-ecs-log-rotation-issue/191872)

<div class="topic-metadata">

**Author:** [@justkind](https://discuss.elastic.co/u/justkind)\
**Replies:** 4\
**Last updated:** [August 6, 2019, 2:59pm UTC](https://discuss.elastic.co/t/filebeat-amazon-ecs-log-rotation-issue/191872 "2019-08-06T14:59:20Z")

</div>

Hi Elastic Team, Sorry to bother y'all, but I've been running into an issue using Filebeat on Amazon ECS and would appreciate any help. Summary: Filebeat 6.8.1 deployed on each individual ECS host instance and forward…

---

## [Log file displaying as a string message](https://discuss.elastic.co/t/log-file-displaying-as-a-string-message/193883)

<div class="topic-metadata">

**Author:** [@cjb312](https://discuss.elastic.co/u/cjb312)\
**Replies:** 1\
**Last updated:** [August 6, 2019, 12:23pm UTC](https://discuss.elastic.co/t/log-file-displaying-as-a-string-message/193883 "2019-08-06T12:23:55Z")

</div>

I am using filebeat to ingest a log file so I can view it on Kibana but on Kibana the log file comes up as this: \`"#fields\\tts\\tid\\tcertificate.version\\tcertificate.serial\\tcertificate.subject\\tcertificate.issuer\\tcerti…

---

## [Winlogbeat 7.2.0 index name not changing despite specifying setup.template.name, setup.template.pattern](https://discuss.elastic.co/t/winlogbeat-7-2-0-index-name-not-changing-despite-specifying-setup-template-name-setup-template-pattern/193613)

<div class="topic-metadata">

**Author:** [@jeetthakkar](https://discuss.elastic.co/u/jeetthakkar)\
**Replies:** 4\
**Last updated:** [August 6, 2019, 12:12pm UTC](https://discuss.elastic.co/t/winlogbeat-7-2-0-index-name-not-changing-despite-specifying-setup-template-name-setup-template-pattern/193613 "2019-08-06T12:12:35Z")

</div>

Hello, Everyone jhas asked this multiple times and I've tried the solutions but it doesn't seem to work. I have tried to specify the template.name and template.pattern to change the name of the index to which wingbeat i…

---

## [Filebeat shows merged single error lines despite Multiline](https://discuss.elastic.co/t/filebeat-shows-merged-single-error-lines-despite-multiline/190701)

<div class="topic-metadata">

**Author:** [@elk51211](https://discuss.elastic.co/u/elk51211)\
**Replies:** 4\
**Last updated:** [August 6, 2019, 12:00pm UTC](https://discuss.elastic.co/t/filebeat-shows-merged-single-error-lines-despite-multiline/190701 "2019-08-06T12:00:10Z")

</div>

Hello, I managed to merge my stacktrace in a mulitline. Unfortunately my kibana still shows me the logs for single error threads. How do I avoid these single logs and get solely multilines? Multiline settings: multili…

---

## [CPU usage 100% when Elasticsearch is down (Act 2)](https://discuss.elastic.co/t/cpu-usage-100-when-elasticsearch-is-down-act-2/193997)

<div class="topic-metadata">

**Author:** [@fredrik.jonsson](https://discuss.elastic.co/u/fredrik.jonsson)\
**Replies:** 1\
**Last updated:** [August 6, 2019, 11:51am UTC](https://discuss.elastic.co/t/cpu-usage-100-when-elasticsearch-is-down-act-2/193997 "2019-08-06T11:51:20Z")

</div>

This is a continue of, https://discuss.elastic.co/t/cpu-usage-100-when-elasticsearch-is-down/185850, which was automatically closed during vacation. The issue was this, "I noticed that when Elasticsearch can't retrieve…

---

## [How can I parser json log with uncertain fields?](https://discuss.elastic.co/t/how-can-i-parser-json-log-with-uncertain-fields/190680)

<div class="topic-metadata">

**Author:** [@Martin\_Ma11](https://discuss.elastic.co/u/Martin_Ma11)\
**Replies:** 6\
**Last updated:** [August 6, 2019, 11:41am UTC](https://discuss.elastic.co/t/how-can-i-parser-json-log-with-uncertain-fields/190680 "2019-08-06T11:41:39Z")

</div>

I am new to filebeat and I trying to find a way to parser json without predefined fields. For example I have a log file like this: {"key1":"value1","key2":"value2"} {"key1":"value1","key3":"value3"} Some of the keys a…

---

## [Tuning filebeat performance, why i can not drive CPU usage close to 100%](https://discuss.elastic.co/t/tuning-filebeat-performance-why-i-can-not-drive-cpu-usage-close-to-100/189891)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 20\
**Last updated:** [August 6, 2019, 11:05am UTC](https://discuss.elastic.co/t/tuning-filebeat-performance-why-i-can-not-drive-cpu-usage-close-to-100/189891 "2019-08-06T11:05:36Z")

</div>

Hello, I tried to tune filebeat performance, as @steffens suggested in one post, i changed the output to console, one thing I find strange is: I allocated 3 cores to filebeat, however, i can only drive the CPU usage to …

---

## [Winlogbeat user.name is missing in event 4634 (Logoff Event) - ECS Missing Correlation](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 10\
**Last updated:** [August 6, 2019, 7:27am UTC](https://discuss.elastic.co/t/winlogbeat-user-name-is-missing-in-event-4634-logoff-event-ecs-missing-correlation/189363 "2019-08-06T07:27:33Z")

</div>

Hi, I'm analizing windows event logs comming from a winlogbeat 7.2. When looking in the logoff event (id 4634) I see that the field user.name does not exists The field winlog.event\_data.TargetUserName has the proper u…

---

## [How to read same file multiple times in Filebeat?](https://discuss.elastic.co/t/how-to-read-same-file-multiple-times-in-filebeat/193706)

<div class="topic-metadata">

**Author:** [@Daniel6](https://discuss.elastic.co/u/Daniel6)\
**Replies:** 2\
**Last updated:** [August 5, 2019, 7:45am UTC](https://discuss.elastic.co/t/how-to-read-same-file-multiple-times-in-filebeat/193706 "2019-08-05T07:45:07Z")

</div>

Hi, I run ELK on Linux(CentOS7). I know in Logstash we could add sincedb\_path =\> "/dev/null" in config/logstash.conf, so we could read same file again and again. How to do this in filebeat?

---

## [The metricbeat service terminated unexpectedly](https://discuss.elastic.co/t/the-metricbeat-service-terminated-unexpectedly/193849)

<div class="topic-metadata">

**Author:** [@johnbchron](https://discuss.elastic.co/u/johnbchron)\
**Replies:** 1\
**Last updated:** [August 5, 2019, 6:47pm UTC](https://discuss.elastic.co/t/the-metricbeat-service-terminated-unexpectedly/193849 "2019-08-05T18:47:33Z")

</div>

Hello All, So I've been running the full stack (metricbeat, logstash, elasticsearch, kibana) on 7.2, all on Linux except that most of the metricbeat clients are on windows machines. I have beat-logstash connections encr…

---

## [Docker Images for Beats 7.3.0 - not available on hub.docker.com](https://discuss.elastic.co/t/docker-images-for-beats-7-3-0-not-available-on-hub-docker-com/193838)

<div class="topic-metadata">

**Author:** [@Chris\_Samo](https://discuss.elastic.co/u/Chris_Samo)\
**Replies:** 2\
**Last updated:** [August 5, 2019, 5:54pm UTC](https://discuss.elastic.co/t/docker-images-for-beats-7-3-0-not-available-on-hub-docker-com/193838 "2019-08-05T17:54:15Z")

</div>

Please can the Beats Docker Images be released to hub.docker.com for 7.3.0? This has been done for Elasticsearch, Kibana, Logstash and APM Server but it appears the Beats all remain at 7.2.0. Due to environment restrict…

---

## [Beats fields.yml Mapping, How to configure beats to store fields values?](https://discuss.elastic.co/t/beats-fields-yml-mapping-how-to-configure-beats-to-store-fields-values/193831)

<div class="topic-metadata">

**Author:** [@\_Barak\_Harari](https://discuss.elastic.co/u/_Barak_Harari)\
**Replies:** 0\
**Last updated:** [August 5, 2019, 3:20pm UTC](https://discuss.elastic.co/t/beats-fields-yml-mapping-how-to-configure-beats-to-store-fields-values/193831 "2019-08-05T15:20:58Z")

</div>

Hi I'm trying to store event values on fields as explain here: https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-store.html setup.template.settings: \_source: enabled: false key: beats\_name t…

---

## [Harvest + Analyze customers application logs](https://discuss.elastic.co/t/harvest-analyze-customers-application-logs/193678)

<div class="topic-metadata">

**Author:** [@mnaveh](https://discuss.elastic.co/u/mnaveh)\
**Replies:** 4\
**Last updated:** [August 5, 2019, 2:18pm UTC](https://discuss.elastic.co/t/harvest-analyze-customers-application-logs/193678 "2019-08-05T14:18:29Z")

</div>

Hi I am new with Elastic and Filebeat. Decided to test harvesting and analyze customers application logs. Installed (Windows) Elastic + Filebeat + Kibana. Configured Filebeat fields.yml to the customized logs fields …

---

## [Filebeat 7.3 logging output](https://discuss.elastic.co/t/filebeat-7-3-logging-output/193788)

<div class="topic-metadata">

**Author:** [@Mesmer](https://discuss.elastic.co/u/Mesmer)\
**Replies:** 0\
**Last updated:** [August 5, 2019, 12:10pm UTC](https://discuss.elastic.co/t/filebeat-7-3-logging-output/193788 "2019-08-05T12:10:22Z")

</div>

I just upgraded from Filebeat 7.0 to Filebeat 7.3 and i notice that it's defaulting back to /var/log/messages output error logs, even though it was configured to have separate logs. The filebeat process is running the -…

---

## [Data Accuracy with Filebeat/IIS Aggregation](https://discuss.elastic.co/t/data-accuracy-with-filebeat-iis-aggregation/193409)

<div class="topic-metadata">

**Author:** [@subhashpant](https://discuss.elastic.co/u/subhashpant)\
**Replies:** 0\
**Last updated:** [August 1, 2019, 9:31pm UTC](https://discuss.elastic.co/t/data-accuracy-with-filebeat-iis-aggregation/193409 "2019-08-01T21:31:08Z")

</div>

I was previously parsing the IIS Log data (to get aggregate) using Log Parser 2.2. Generic command as follows: .\\logparser -rtp:-1 -i:iisw3c "SELECT TO\_LOCALTIME(QUANTIZE(TO\_TIMESTAMP(date, time), 3600)) AS \[DateTime\], …

---

## [Fortianalyzer and Filebeat](https://discuss.elastic.co/t/fortianalyzer-and-filebeat/193610)

<div class="topic-metadata">

**Author:** [@aculha](https://discuss.elastic.co/u/aculha)\
**Replies:** 1\
**Last updated:** [August 5, 2019, 10:42am UTC](https://discuss.elastic.co/t/fortianalyzer-and-filebeat/193610 "2019-08-05T10:42:21Z")

</div>

I've been researching for the past few days on how to get my fortigate logs forwarded to filebeat so that I can view them through the SIEM. Currently I have yet to find a solution and have hit a wall, but was wondering i…

---

## [Basic Architecture Question](https://discuss.elastic.co/t/basic-architecture-question/193400)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 3\
**Last updated:** [August 3, 2019, 3:31am UTC](https://discuss.elastic.co/t/basic-architecture-question/193400 "2019-08-03T03:31:26Z")

</div>

New to ElasticSearch so hoping someone can clear this up. I have a need to use WinLogBeat and FileBeat to collect logs from servers. I plan on having an ElasticSearch instance in Amazon. For various reasons, I cannot ha…

---

## [Filebeat and Duplicate entries](https://discuss.elastic.co/t/filebeat-and-duplicate-entries/193505)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 2\
**Last updated:** [August 2, 2019, 8:47pm UTC](https://discuss.elastic.co/t/filebeat-and-duplicate-entries/193505 "2019-08-02T20:47:31Z")

</div>

I need my Filebeat process to identify duplicate entries and update, not recreate, based on this. This would be similar to the document id in logstash. Is this available using Filebeat? My filebeat process passes the …

---

## [Auditbeat doesn't embed kubernetes metadata in the events](https://discuss.elastic.co/t/auditbeat-doesnt-embed-kubernetes-metadata-in-the-events/192281)

<div class="topic-metadata">

**Author:** [@nickbabkin](https://discuss.elastic.co/u/nickbabkin)\
**Replies:** 1\
**Last updated:** [August 2, 2019, 1:32pm UTC](https://discuss.elastic.co/t/auditbeat-doesnt-embed-kubernetes-metadata-in-the-events/192281 "2019-08-02T13:32:50Z")

</div>

Hello! We have installed auditbeat v.7.2 as daemonset on our kubernetes cluster and enabled kubernetes metadata as instructed here: https://www.elastic.co/guide/en/beats/auditbeat/6.7/add-kubernetes-metadata.html And …

---

## [More crypto problems with Elasticsearch](https://discuss.elastic.co/t/more-crypto-problems-with-elasticsearch/192967)

<div class="topic-metadata">

**Author:** [@jbrowe](https://discuss.elastic.co/u/jbrowe)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 6:38pm UTC](https://discuss.elastic.co/t/more-crypto-problems-with-elasticsearch/192967 "2019-07-30T18:38:23Z")

</div>

I am trying to upgrade a winlogbeat agent on Windows from version 6.6.1 to version 7.2. According to the documentation,, I must first upgrade from 6.6 to 6.7, load the new template and then upgrade to 7. Upgrade from 6…

---

## [Shipping logs from multiple log files from single instance of filebeat to logstash](https://discuss.elastic.co/t/shipping-logs-from-multiple-log-files-from-single-instance-of-filebeat-to-logstash/192400)

<div class="topic-metadata">

**Author:** [@Eva](https://discuss.elastic.co/u/Eva)\
**Replies:** 7\
**Last updated:** [August 2, 2019, 12:18pm UTC](https://discuss.elastic.co/t/shipping-logs-from-multiple-log-files-from-single-instance-of-filebeat-to-logstash/192400 "2019-08-02T12:18:12Z")

</div>

Hello I have a setup where i send only one log file like /abc/example.log to logstash instance like below: filebeat.prospectors: paths: /abc/example.log fields: app\_suite: cba application: abc name: "xyz" outp…

---

## [Alert when detecting a specific number of shards on index](https://discuss.elastic.co/t/alert-when-detecting-a-specific-number-of-shards-on-index/193472)

<div class="topic-metadata">

**Author:** [@nepes](https://discuss.elastic.co/u/nepes)\
**Replies:** 0\
**Last updated:** [August 2, 2019, 7:49am UTC](https://discuss.elastic.co/t/alert-when-detecting-a-specific-number-of-shards-on-index/193472 "2019-08-02T07:49:34Z")

</div>

I would like to detect when a number of shards per index passes some threshold. I use Metricbeat with Elasticsearch module to retrieve metrics data from indices and ElastAlert to send alerts when some number of shards p…

---

## [How to use the original indicator of Monitoring in the log file of filebeat](https://discuss.elastic.co/t/how-to-use-the-original-indicator-of-monitoring-in-the-log-file-of-filebeat/193434)

<div class="topic-metadata">

**Author:** [@ADiiana](https://discuss.elastic.co/u/ADiiana)\
**Replies:** 0\
**Last updated:** [August 2, 2019, 2:08am UTC](https://discuss.elastic.co/t/how-to-use-the-original-indicator-of-monitoring-in-the-log-file-of-filebeat/193434 "2019-08-02T02:08:41Z")

</div>

Just like these data，I want to use cpu time (system, total, user) to calculate the CPU utilization, so I must know the meaning of the three options, thank you very much. { "monitoring":{ "metrics":{ "beat":…

---

## [Error metricbeat sending json data to elastic search](https://discuss.elastic.co/t/error-metricbeat-sending-json-data-to-elastic-search/192582)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 18\
**Last updated:** [August 1, 2019, 8:21pm UTC](https://discuss.elastic.co/t/error-metricbeat-sending-json-data-to-elastic-search/192582 "2019-08-01T20:21:06Z")

</div>

Hi I haven't tried this before. I am trying to send jenkins build data to elastic search. I am seeing some error. Elastic stack : 7.2 My jenkins url response is like this. http://master.example.com//job/Federated\_In…

---

## [Filesystem metricset not reporting nfs and some host filesystems](https://discuss.elastic.co/t/filesystem-metricset-not-reporting-nfs-and-some-host-filesystems/191866)

<div class="topic-metadata">

**Author:** [@Mario\_Fimiani](https://discuss.elastic.co/u/Mario_Fimiani)\
**Replies:** 6\
**Last updated:** [August 1, 2019, 2:36pm UTC](https://discuss.elastic.co/t/filesystem-metricset-not-reporting-nfs-and-some-host-filesystems/191866 "2019-08-01T14:36:16Z")

</div>

Continuing the discussion from Filesystem metricset not reporting nfs and other host filesystems: we have the same problem on our environment (7.1 elk and stack). Some info regarding this issue ?

---

## [Filebeat stopped harvesting logs after a while](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs-after-a-while/193298)

<div class="topic-metadata">

**Author:** [@codersofthedark](https://discuss.elastic.co/u/codersofthedark)\
**Replies:** 1\
**Last updated:** [August 1, 2019, 4:19pm UTC](https://discuss.elastic.co/t/filebeat-stopped-harvesting-logs-after-a-while/193298 "2019-08-01T16:19:38Z")

</div>

We have filebeat 6.7.1 running as a daemonset on our kubernetes cluster. Everything was working fine till suddenly logs stopped popping up in ES. When we checked filebeat logs, there was no ERROR but as filebeat there w…

---

## [Filebeat multiline pattern with linefeed](https://discuss.elastic.co/t/filebeat-multiline-pattern-with-linefeed/193266)

<div class="topic-metadata">

**Author:** [@thps](https://discuss.elastic.co/u/thps)\
**Replies:** 1\
**Last updated:** [August 1, 2019, 4:14pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-with-linefeed/193266 "2019-08-01T16:14:01Z")

</div>

Dear all, i try to match a multiline java - event in Filebeat via multiline pattern. In general, this is still working, but i´m not able to parse empty lines in this event. The String looks like this: BMC:SR:2019-08-0…

---

## [Couldn't connect to AWS ES](https://discuss.elastic.co/t/couldnt-connect-to-aws-es/193294)

<div class="topic-metadata">

**Author:** [@sv\_bcvt92](https://discuss.elastic.co/u/sv_bcvt92)\
**Replies:** 6\
**Last updated:** [August 1, 2019, 3:19pm UTC](https://discuss.elastic.co/t/couldnt-connect-to-aws-es/193294 "2019-08-01T15:19:39Z")

</div>

Hi Gurus, I'm setting Filebeat to send nginx logs to AWS Elasticsearch service. I do follow exactly this guide But in step 4, I got this error Exiting: Couldn't connect to any of the configured Elasticsearch hosts…

---

## [Can't load metricbeat data: Fielddata is disabled on text fields by default](https://discuss.elastic.co/t/cant-load-metricbeat-data-fielddata-is-disabled-on-text-fields-by-default/193178)

<div class="topic-metadata">

**Author:** [@carson](https://discuss.elastic.co/u/carson)\
**Replies:** 2\
**Last updated:** [August 1, 2019, 1:58pm UTC](https://discuss.elastic.co/t/cant-load-metricbeat-data-fielddata-is-disabled-on-text-fields-by-default/193178 "2019-08-01T13:58:15Z")

</div>

I'm not sure what caused this, possibly my previous attempt to use logstash, or an index I once tried on metricbeat. I now send beats directly to elasticsearch. I'm using 7.1 for all parts of the ELK stack. From the Inf…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=329)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=331)
