# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=331

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 332

---

## [How to format/filter events from syslog to send to auditbeat index](https://discuss.elastic.co/t/how-to-format-filter-events-from-syslog-to-send-to-auditbeat-index/193287)

<div class="topic-metadata">

**Author:** [@MalfuncEddie](https://discuss.elastic.co/u/MalfuncEddie)\
**Replies:** 1\
**Last updated:** [August 1, 2019, 12:56pm UTC](https://discuss.elastic.co/t/how-to-format-filter-events-from-syslog-to-send-to-auditbeat-index/193287 "2019-08-01T12:56:13Z")

</div>

Hi, Audit beat is not supported on AIX. But I can send auth information to an syslog server. I would like to write a filter that can send the syslog file to the audit beat index. Is there any guide how to do this? kin…

---

## [Metricbeat 7.3 windows module sevice metricset filter error](https://discuss.elastic.co/t/metricbeat-7-3-windows-module-sevice-metricset-filter-error/193320)

<div class="topic-metadata">

**Author:** [@nitzan.karni](https://discuss.elastic.co/u/nitzan.karni)\
**Replies:** 0\
**Last updated:** [August 1, 2019, 12:40pm UTC](https://discuss.elastic.co/t/metricbeat-7-3-windows-module-sevice-metricset-filter-error/193320 "2019-08-01T12:40:48Z")

</div>

\- module: windows metricsets: \["service"\] period: 60s processors: - drop\_event.when.not.equals: windows.service.display\_name: Windows Firewall this example is taken straight out of the documentation. need…

---

## [Vsphere \_metricbeat](https://discuss.elastic.co/t/vsphere-metricbeat/190918)

<div class="topic-metadata">

**Author:** [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Replies:** 3\
**Last updated:** [August 1, 2019, 12:12pm UTC](https://discuss.elastic.co/t/vsphere-metricbeat/190918 "2019-08-01T12:12:42Z")

</div>

Hi There, I was looking at the vphere metribeat module, Iam bit confused , should we install the metribeat on vphere itself with vphere module enabled or should we install in another server where we install the metricb…

---

## [Default value escaping](https://discuss.elastic.co/t/default-value-escaping/189362)

<div class="topic-metadata">

**Author:** [@Alex\_Zeleznikov1](https://discuss.elastic.co/u/Alex_Zeleznikov1)\
**Replies:** 2\
**Last updated:** [August 1, 2019, 10:50am UTC](https://discuss.elastic.co/t/default-value-escaping/189362 "2019-08-01T10:50:14Z")

</div>

How can I escape default values when doing variable substitution? for example multiline.pattern: '${kubernetes.annotations.multiline\_pattern:^(0\[1-9\]|\[1-2\]\[0-9\]|3\[0-1\])-(0\[1-9\]|1\[0-2\])-\[0-9\]{4}}' I need to change the re…

---

## [How to fix "rm: cannot remove '/usr/share/filebeat/bin/data/registry/filebeat': Directory not empty"?](https://discuss.elastic.co/t/how-to-fix-rm-cannot-remove-usr-share-filebeat-bin-data-registry-filebeat-directory-not-empty/192821)

<div class="topic-metadata">

**Author:** [@kensaku-okada](https://discuss.elastic.co/u/kensaku-okada)\
**Replies:** 2\
**Last updated:** [August 1, 2019, 9:14am UTC](https://discuss.elastic.co/t/how-to-fix-rm-cannot-remove-usr-share-filebeat-bin-data-registry-filebeat-directory-not-empty/192821 "2019-08-01T09:14:13Z")

</div>

I made a docker which 1) let a shellscript repetitively run Filebeat to read a file and transmit its data to the local Logstash and 2) run a logstash to transfer the received data to a web server. Since I wanted to do a…

---

## [Winlogbeat ships translated events](https://discuss.elastic.co/t/winlogbeat-ships-translated-events/193281)

<div class="topic-metadata">

**Author:** [@DennisH](https://discuss.elastic.co/u/DennisH)\
**Replies:** 0\
**Last updated:** [August 1, 2019, 8:57am UTC](https://discuss.elastic.co/t/winlogbeat-ships-translated-events/193281 "2019-08-01T08:57:46Z")

</div>

Just installed winlogbeat 7.3 and it ships my logs in Norwegian instead of English. When looking at the logs in say Eventviewer, the logs are in English. Is there a setting for winlogbeat that will allow me to get the …

---

## [Error log filebeat](https://discuss.elastic.co/t/error-log-filebeat/193279)

<div class="topic-metadata">

**Author:** [@sarahmech](https://discuss.elastic.co/u/sarahmech)\
**Replies:** 0\
**Last updated:** [August 1, 2019, 8:54am UTC](https://discuss.elastic.co/t/error-log-filebeat/193279 "2019-08-01T08:54:04Z")

</div>

my problem it's i can't send nothing since filebeat to kibana. i don't see where is the error thanks!

---

## [404 error when downloading windows binaries](https://discuss.elastic.co/t/404-error-when-downloading-windows-binaries/193100)

<div class="topic-metadata">

**Author:** [@filipes](https://discuss.elastic.co/u/filipes)\
**Replies:** 2\
**Last updated:** [August 1, 2019, 8:33am UTC](https://discuss.elastic.co/t/404-error-when-downloading-windows-binaries/193100 "2019-08-01T08:33:03Z")

</div>

Keep getting a 404 error when trying to download windows binaries for filebeat.

---

## [Call Custom-Beats functions from another language than go](https://discuss.elastic.co/t/call-custom-beats-functions-from-another-language-than-go/193260)

<div class="topic-metadata">

**Author:** [@Dev-Flo](https://discuss.elastic.co/u/Dev-Flo)\
**Replies:** 0\
**Last updated:** [August 1, 2019, 6:50am UTC](https://discuss.elastic.co/t/call-custom-beats-functions-from-another-language-than-go/193260 "2019-08-01T06:50:36Z")

</div>

Hey, I'm currently writing a custom Beat. However, the data I want to push with the Beat, I receive via a C# program. I dont want to store the data and then read it via filebeat because the beat is running on something …

---

## [Metricbeat mssql support](https://discuss.elastic.co/t/metricbeat-mssql-support/193219)

<div class="topic-metadata">

**Author:** [@dnwobu](https://discuss.elastic.co/u/dnwobu)\
**Replies:** 0\
**Last updated:** [July 31, 2019, 9:22pm UTC](https://discuss.elastic.co/t/metricbeat-mssql-support/193219 "2019-07-31T21:22:00Z")

</div>

Is there a timeline of when the mssql metricset for Metricbeat will be GA and not in beta? I see that it has errorlog support in Filebeat 7.3

---

## [Fails when running filebeat -e](https://discuss.elastic.co/t/fails-when-running-filebeat-e/193182)

<div class="topic-metadata">

**Author:** [@RayKishev](https://discuss.elastic.co/u/RayKishev)\
**Replies:** 2\
**Last updated:** [July 31, 2019, 6:36pm UTC](https://discuss.elastic.co/t/fails-when-running-filebeat-e/193182 "2019-07-31T18:36:43Z")

</div>

Hello guys, I have a small error when running Filebeat -e. I was successfully able to install and run Metricbeats, however there is an issue running filebeats. this is the error i'm getting: 2019-07-31T09:31:42.916-07…

---

## [Filebeat syslog parse error](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643)

<div class="topic-metadata">

**Author:** [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Replies:** 9\
**Last updated:** [July 31, 2019, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643 "2019-07-31T15:16:08Z")

</div>

Filebeat is giving errors while parsing syslog messages from ASA. ERROR \[syslog\] syslog/input.go:132 can't parse event as syslog rfc3164 {"message": "\<165\>:Jul 10 07:10:12 IST: %ASA-config-5-111010: User 'XXXXX', runnin…

---

## [Selective dashboard creation with setup command](https://discuss.elastic.co/t/selective-dashboard-creation-with-setup-command/193151)

<div class="topic-metadata">

**Author:** [@rudraram](https://discuss.elastic.co/u/rudraram)\
**Replies:** 0\
**Last updated:** [July 31, 2019, 3:10pm UTC](https://discuss.elastic.co/t/selective-dashboard-creation-with-setup-command/193151 "2019-07-31T15:10:13Z")

</div>

running commands like filebeat setup or filebeat setup --dashboards creates whole shebang of dashboards which wont use. is there a way to restrict and create dashboard selectively example like filebeat setup --dashbo…

---

## [Can't make Metricbeat to use passed env variable](https://discuss.elastic.co/t/cant-make-metricbeat-to-use-passed-env-variable/193148)

<div class="topic-metadata">

**Author:** [@pavlovdog](https://discuss.elastic.co/u/pavlovdog)\
**Replies:** 0\
**Last updated:** [July 31, 2019, 2:56pm UTC](https://discuss.elastic.co/t/cant-make-metricbeat-to-use-passed-env-variable/193148 "2019-07-31T14:56:17Z")

</div>

I'm trying to run metricbeat service in docker, according to the official documentation (version 7.2.0). Here's my bash command for setup: docker run -d --name=metricbeat docker.elastic.co/beats/metricbeat:7.2.0 setup\\ …

---

## [Filebeat for redis slowlog](https://discuss.elastic.co/t/filebeat-for-redis-slowlog/192914)

<div class="topic-metadata">

**Author:** [@rudraram](https://discuss.elastic.co/u/rudraram)\
**Replies:** 3\
**Last updated:** [July 31, 2019, 2:51pm UTC](https://discuss.elastic.co/t/filebeat-for-redis-slowlog/192914 "2019-07-31T14:51:38Z")

</div>

Hi Friends, Need help with my configuration. I am trying to see if i can configure filebeat to ingest redis slow logs into my elasticsearch cluster. before that want to see if i get the events listed to console here is…

---

## [Filebeat crash each day](https://discuss.elastic.co/t/filebeat-crash-each-day/193139)

<div class="topic-metadata">

**Author:** [@j0nathan33](https://discuss.elastic.co/u/j0nathan33)\
**Replies:** 1\
**Last updated:** [July 31, 2019, 2:28pm UTC](https://discuss.elastic.co/t/filebeat-crash-each-day/193139 "2019-07-31T14:28:25Z")

</div>

Hi, I use last version on filebeat (7.2.1) and my filebeat crash every day on this error : "invalid memory address or nil pointer dereference" (same error on 7.2.0). Only way to restart filebeat, it's to remove some "fi…

---

## [Filebeat TimeZone Issue](https://discuss.elastic.co/t/filebeat-timezone-issue/192999)

<div class="topic-metadata">

**Author:** [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Replies:** 3\
**Last updated:** [July 31, 2019, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-timezone-issue/192999 "2019-07-31T13:14:52Z")

</div>

I am using version 7.2.0 and have system module enabled. What I am seeing is that when an event occures lets say at 6PM. When this event is sent to elasticsearch it assumes this is UTC and when opened in browser adjusts …

---

## [Filebeat ignoring json created by ruby](https://discuss.elastic.co/t/filebeat-ignoring-json-created-by-ruby/191073)

<div class="topic-metadata">

**Author:** [@DevopsNewb](https://discuss.elastic.co/u/DevopsNewb)\
**Replies:** 4\
**Last updated:** [July 31, 2019, 1:13pm UTC](https://discuss.elastic.co/t/filebeat-ignoring-json-created-by-ruby/191073 "2019-07-31T13:13:58Z")

</div>

Thanks in advance for any help - I've been fighting with this thing all day and I don't feel like I've made much progress. Here's the situation. Using Ansible facts, we are pulling out a list of all installed packages,…

---

## [Files aren't automatically sent to logstash](https://discuss.elastic.co/t/files-arent-automatically-sent-to-logstash/193088)

<div class="topic-metadata">

**Author:** [@luc1](https://discuss.elastic.co/u/luc1)\
**Replies:** 0\
**Last updated:** [July 31, 2019, 10:04am UTC](https://discuss.elastic.co/t/files-arent-automatically-sent-to-logstash/193088 "2019-07-31T10:04:07Z")

</div>

Hello, I have a strange issue. I'm extracting json file from a server and my filebeat is meant to send them to logstash and then Kibana. Here is the thing: The files sent aren't being taken into account by logstash whe…

---

## [How do I transfer data across networks?](https://discuss.elastic.co/t/how-do-i-transfer-data-across-networks/191577)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 6\
**Last updated:** [July 31, 2019, 9:43am UTC](https://discuss.elastic.co/t/how-do-i-transfer-data-across-networks/191577 "2019-07-31T09:43:04Z")

</div>

I want to transfer the data to different networks How should I set the url of logstash/filebeat? filebeat conf output.redis: hosts: \["redis.xxx.net:7887"\] key: data db: 0 timeout: 30 Failed to connect to redis(t…

---

## [Unable to see incoming ping in packetbeat,kibana?](https://discuss.elastic.co/t/unable-to-see-incoming-ping-in-packetbeat-kibana/192923)

<div class="topic-metadata">

**Author:** [@Embedded\_Projects](https://discuss.elastic.co/u/Embedded_Projects)\
**Replies:** 1\
**Last updated:** [July 31, 2019, 7:47am UTC](https://discuss.elastic.co/t/unable-to-see-incoming-ping-in-packetbeat-kibana/192923 "2019-07-31T07:47:54Z")

</div>

I have just started using packetbeats, I am using kibana gui to check data. I have 2 systems lets say A and B, I have installed packetbeats, kibana, elasticsearch on A. IP A: 172.16.8.73 IP B: 192.168.1.45 When I ping…

---

## [\[Still Not Solved!\] Filebeat cannot recognize timezone in syslog](https://discuss.elastic.co/t/still-not-solved-filebeat-cannot-recognize-timezone-in-syslog/192661)

<div class="topic-metadata">

**Author:** [@cosloli](https://discuss.elastic.co/u/cosloli)\
**Replies:** 24\
**Last updated:** [July 31, 2019, 6:02am UTC](https://discuss.elastic.co/t/still-not-solved-filebeat-cannot-recognize-timezone-in-syslog/192661 "2019-07-31T06:02:04Z")

</div>

I THOUGHT THE PROBLEM HAS BEEN SOLVED, BUT IS'T NOT! ########### Original Question: I'm using filebeat to harvest logs directly to ES. The timezone on my server is UTC +08:00 (Asia/Shanghai). I used filebeat modules …

---

## [Filebeat7.2 cpu over 100% all time](https://discuss.elastic.co/t/filebeat7-2-cpu-over-100-all-time/193029)

<div class="topic-metadata">

**Author:** [@liangf](https://discuss.elastic.co/u/liangf)\
**Replies:** 0\
**Last updated:** [July 31, 2019, 4:16am UTC](https://discuss.elastic.co/t/filebeat7-2-cpu-over-100-all-time/193029 "2019-07-31T04:16:23Z")

</div>

Hi: i use filebeat7.2 for log collect,have a strange situation,when i'm not output more info to terminal,run like this:./filebeat -e -c filebeat.yml,filebeat cost the CPU above 100%,if i run filebeat like this:./filebea…

---

## [\[Metricbeat\]About the configuration of mongodb module to connet a mongodb server with SCRAM-SHA-256](https://discuss.elastic.co/t/metricbeat-about-the-configuration-of-mongodb-module-to-connet-a-mongodb-server-with-scram-sha-256/193015)

<div class="topic-metadata">

**Author:** [@yuewu](https://discuss.elastic.co/u/yuewu)\
**Replies:** 0\
**Last updated:** [July 31, 2019, 2:09am UTC](https://discuss.elastic.co/t/metricbeat-about-the-configuration-of-mongodb-module-to-connet-a-mongodb-server-with-scram-sha-256/193015 "2019-07-31T02:09:37Z")

</div>

I want to use metricbeat to monitor a mongodb(4.0) server with SCRAM-SHA-256 But the metricbeat service shows: Jul 31 09:45:55 Perf-7151 metricbeat\[19520\]: 2019-07-31T09:45:55.724+0800 ERROR mongodb/mong…

---

## [Can't enable apache on filebeats on windows 10](https://discuss.elastic.co/t/cant-enable-apache-on-filebeats-on-windows-10/191924)

<div class="topic-metadata">

**Author:** [@AbuBakar2101](https://discuss.elastic.co/u/AbuBakar2101)\
**Replies:** 3\
**Last updated:** [July 30, 2019, 11:56pm UTC](https://discuss.elastic.co/t/cant-enable-apache-on-filebeats-on-windows-10/191924 "2019-07-30T23:56:14Z")

</div>

I have been trying to run apache module but I get stuck on the command which enables the module .\\filebeat.exe modules enable apache when I try to insert this command on command prompt, there is a pop up on my pc that…

---

## [Monitoring winlogbeat service](https://discuss.elastic.co/t/monitoring-winlogbeat-service/192981)

<div class="topic-metadata">

**Author:** [@jwwags92](https://discuss.elastic.co/u/jwwags92)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 7:44pm UTC](https://discuss.elastic.co/t/monitoring-winlogbeat-service/192981 "2019-07-30T19:44:49Z")

</div>

I'm extremely new to all of this. I have about 25 Windows event logs forwarding to an ELK stash server and I very much like the results. Going forward, i wonder if there is a way to monitor the winlogbeat service using …

---

## [How to use "exported fields"?](https://discuss.elastic.co/t/how-to-use-exported-fields/192973)

<div class="topic-metadata">

**Author:** [@Dmitry1](https://discuss.elastic.co/u/Dmitry1)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 7:00pm UTC](https://discuss.elastic.co/t/how-to-use-exported-fields/192973 "2019-07-30T19:00:11Z")

</div>

Helo, please help. From documentation and googling i can't understand what "Exported fields" in filebeat is and how to use them. For example i want to add information about logfile's mtime when i send events to logstash. …

---

## [Metricbeat Kubernetes - limiting information being retrieved](https://discuss.elastic.co/t/metricbeat-kubernetes-limiting-information-being-retrieved/192948)

<div class="topic-metadata">

**Author:** [@warnerrj79](https://discuss.elastic.co/u/warnerrj79)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 4:35pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-limiting-information-being-retrieved/192948 "2019-07-30T16:35:51Z")

</div>

Hi all. First post here so go easy on me :wink: I am in the middle of setting up Minikube Kubernetes with ElasticSearch, Kibana and MetricBeat. I have been successful in setting up all three (with a lot of effort) but …

---

## [Error Filebeat](https://discuss.elastic.co/t/error-filebeat/191825)

<div class="topic-metadata">

**Author:** [@sarahmech](https://discuss.elastic.co/u/sarahmech)\
**Replies:** 4\
**Last updated:** [July 30, 2019, 3:10pm UTC](https://discuss.elastic.co/t/error-filebeat/191825 "2019-07-30T15:10:08Z")

</div>

Hi this is my config, ###################### Filebeat Configuration Example ######################### # This file is an example configuration file highlighting only the most common # options. The filebeat.referenc…

---

## [Filebeat is not able to parse json from files where \\n separated json lines (events) are written](https://discuss.elastic.co/t/filebeat-is-not-able-to-parse-json-from-files-where-n-separated-json-lines-events-are-written/192927)

<div class="topic-metadata">

**Author:** [@nyet](https://discuss.elastic.co/u/nyet)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 2:54pm UTC](https://discuss.elastic.co/t/filebeat-is-not-able-to-parse-json-from-files-where-n-separated-json-lines-events-are-written/192927 "2019-07-30T14:54:22Z")

</div>

I have a log source that generates json log files with excess line feeds. I can get around this (partially) by adding exclude\_lines: \['^$'\] as suggested here: This solves the problem on the logstash/ES side, but sysl…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=330)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=332)
