# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=332

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 333

---

## [Cannot start service winlogbeat in Docker Windows Container](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092)

<div class="topic-metadata">

**Author:** [@HippyCraig](https://discuss.elastic.co/u/HippyCraig)\
**Replies:** 6\
**Last updated:** [July 30, 2019, 12:43pm UTC](https://discuss.elastic.co/t/cannot-start-service-winlogbeat-in-docker-windows-container/190092 "2019-07-30T12:43:50Z")

</div>

I have looked through all the existing posts on this but I am still struggling with getting the service to run. I am using Chocolaty to install winlogbeat inside my windows container, (1809). Everything install fine, I…

---

## [Unable to customize the beats log storage location](https://discuss.elastic.co/t/unable-to-customize-the-beats-log-storage-location/192890)

<div class="topic-metadata">

**Author:** [@subhash.parise](https://discuss.elastic.co/u/subhash.parise)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 12:12pm UTC](https://discuss.elastic.co/t/unable-to-customize-the-beats-log-storage-location/192890 "2019-07-30T12:12:07Z")

</div>

Hello Team, I have installed elasticsearch 7.2 ,filebeat,metricbeat are configured to push the metrics & logs. By default all beat logs are writing to /var/log/messages or /var/log/syslog. i have modified -path.logs =…

---

## [Filebeat dies on startup with 32-bit Ubuntu](https://discuss.elastic.co/t/filebeat-dies-on-startup-with-32-bit-ubuntu/192585)

<div class="topic-metadata">

**Author:** [@aaronr](https://discuss.elastic.co/u/aaronr)\
**Replies:** 2\
**Last updated:** [July 30, 2019, 12:26pm UTC](https://discuss.elastic.co/t/filebeat-dies-on-startup-with-32-bit-ubuntu/192585 "2019-07-30T12:26:29Z")

</div>

Trying to start Filebeat crashes because it can't create the registry directory. 2019-07-29T00:32:18.905+0100 INFO registrar/migrate.go:104 No registry home found. Create: /var/lib/filebeat/registry/filebeat 2019-07-29T…

---

## [Metricbeat monitoring drops after exactly 1 hour & mbeats randomly stop reporting from Windows Servers](https://discuss.elastic.co/t/metricbeat-monitoring-drops-after-exactly-1-hour-mbeats-randomly-stop-reporting-from-windows-servers/192098)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 4\
**Last updated:** [July 30, 2019, 11:58am UTC](https://discuss.elastic.co/t/metricbeat-monitoring-drops-after-exactly-1-hour-mbeats-randomly-stop-reporting-from-windows-servers/192098 "2019-07-30T11:58:41Z")

</div>

ECE 2.2 Elastic 7.2 (RHEL) Mbeat 7.2 (On windows servers) I'm having two issues with metricbeats deployed on our windows servers. The first and primary issue is that some of these beats, setup as a service, will just…

---

## [Sending Logs to both Elasticsearch & Logstash](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755)

<div class="topic-metadata">

**Author:** [@w0lfxpunk](https://discuss.elastic.co/u/w0lfxpunk)\
**Replies:** 7\
**Last updated:** [July 30, 2019, 10:45am UTC](https://discuss.elastic.co/t/sending-logs-to-both-elasticsearch-logstash/191755 "2019-07-30T10:45:46Z")

</div>

Dear All, Is it possible to send logs to Elasticsearch & Logstash both from a server ? For example I want to send some logs to Elasticsearch only say Apache access logs howwever I want o send and parse apache error l…

---

## [I am trying to receive logs from FileBeat on Ubuntu on ElasticCloud](https://discuss.elastic.co/t/i-am-trying-to-receive-logs-from-filebeat-on-ubuntu-on-elasticcloud/192853)

<div class="topic-metadata">

**Author:** [@ode.raita](https://discuss.elastic.co/u/ode.raita)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 9:02am UTC](https://discuss.elastic.co/t/i-am-trying-to-receive-logs-from-filebeat-on-ubuntu-on-elasticcloud/192853 "2019-07-30T09:02:47Z")

</div>

I am trying to receive logs from FileBeat on Ubuntu on ElasticCloud. It has been confirmed that FileBeat is operating normally. Enrollment of FileBeat has been executed from ElasticCloud / Kibana integrated console. H…

---

## [Filebeat PostgreSQL Module](https://discuss.elastic.co/t/filebeat-postgresql-module/192827)

<div class="topic-metadata">

**Author:** [@ts-kazuob](https://discuss.elastic.co/u/ts-kazuob)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 6:05am UTC](https://discuss.elastic.co/t/filebeat-postgresql-module/192827 "2019-07-30T06:05:52Z")

</div>

I would like to know how to see PostgreSQL fields in Kibana. https://www.elastic.co/guide/en/beats/filebeat/6.5/exported-fields-postgresql.html Below is a part of the PostgreSQL log which can be seen in kibana and it s…

---

## [Overriding Var.Path variable in Filebeat Module](https://discuss.elastic.co/t/overriding-var-path-variable-in-filebeat-module/192819)

<div class="topic-metadata">

**Author:** [@michaelberg](https://discuss.elastic.co/u/michaelberg)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 4:36am UTC](https://discuss.elastic.co/t/overriding-var-path-variable-in-filebeat-module/192819 "2019-07-30T04:36:38Z")

</div>

Good evening everyone! I am trying to use the Zeek module with Filebeat ... no matter what I do Filebeat is insisting on looking in /var/log/zeek/current for it's file source ... I compiled Zeek from source and it's run…

---

## [Parsing non-live windows event logs into winlogbeat](https://discuss.elastic.co/t/parsing-non-live-windows-event-logs-into-winlogbeat/192810)

<div class="topic-metadata">

**Author:** [@gracia](https://discuss.elastic.co/u/gracia)\
**Replies:** 1\
**Last updated:** [July 30, 2019, 3:19am UTC](https://discuss.elastic.co/t/parsing-non-live-windows-event-logs-into-winlogbeat/192810 "2019-07-30T03:19:42Z")

</div>

I have old windows event logs in the computer where I installed winlogbeat. How do I get winlogbeat to parse them instead of live windows event logs?

---

## [Beats on OPNsense](https://discuss.elastic.co/t/beats-on-opnsense/192803)

<div class="topic-metadata">

**Author:** [@SteveP](https://discuss.elastic.co/u/SteveP)\
**Replies:** 0\
**Last updated:** [July 30, 2019, 1:52am UTC](https://discuss.elastic.co/t/beats-on-opnsense/192803 "2019-07-30T01:52:01Z")

</div>

Has anyone been able to configure OPNsense for Beats? I see alot of work on pfsense, but nothing on OPNsense.

---

## [Question about Security Module + ECS + Sparcity Question](https://discuss.elastic.co/t/question-about-security-module-ecs-sparcity-question/190957)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 7\
**Last updated:** [July 30, 2019, 1:47am UTC](https://discuss.elastic.co/t/question-about-security-module-ecs-sparcity-question/190957 "2019-07-30T01:47:16Z")

</div>

Hi, I have some questions regarding the security module. Using the processor.Convert() the mapping between windows event data into ECS is done by renaming fields. I have some doubts regarding to the behavior When th…

---

## [Show Selenium test results In ES](https://discuss.elastic.co/t/show-selenium-test-results-in-es/192757)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 6:18pm UTC](https://discuss.elastic.co/t/show-selenium-test-results-in-es/192757 "2019-07-29T18:18:09Z")

</div>

Hi A team runs selenium tests and stores results in xml file. I want to pull this data in to elastic search and plot kibana. Any idea how I can do this? I need to send below values from the xml file. testSuiteId= Ad…

---

## ["producer/broker maximum request accumulated, waiting for space" indication of need to increase channel\_buffer\_size?](https://discuss.elastic.co/t/producer-broker-maximum-request-accumulated-waiting-for-space-indication-of-need-to-increase-channel-buffer-size/192792)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 1\
**Last updated:** [July 30, 2019, 12:14am UTC](https://discuss.elastic.co/t/producer-broker-maximum-request-accumulated-waiting-for-space-indication-of-need-to-increase-channel-buffer-size/192792 "2019-07-30T00:14:43Z")

</div>

I have many "producer/broker/\[\[1521\]\] maximum request accumulated, waiting for space" in my filebeat logs, does this mean i need to increase channel\_buffer\_size? the default value seems very small? "Per Kafka broker nu…

---

## [Drop Event Logs - By "Content"](https://discuss.elastic.co/t/drop-event-logs-by-content/192761)

<div class="topic-metadata">

**Author:** [@Hotdog453](https://discuss.elastic.co/u/Hotdog453)\
**Replies:** 4\
**Last updated:** [July 29, 2019, 11:08pm UTC](https://discuss.elastic.co/t/drop-event-logs-by-content/192761 "2019-07-29T23:08:47Z")

</div>

Hello! So, we're looking to forward windows Firewall logs via WinLogBeat, into LogStash, for review/security. My desire is, however, to 'drop' 'known blocks'; that is, for example, we're going to block TCP 137. This is e…

---

## [I want to establish connectivity between filebeat running on a linux based VM and logstash running in kubernetes(logstash exposed through ingress)](https://discuss.elastic.co/t/i-want-to-establish-connectivity-between-filebeat-running-on-a-linux-based-vm-and-logstash-running-in-kubernetes-logstash-exposed-through-ingress/192781)

<div class="topic-metadata">

**Author:** [@ntsh999](https://discuss.elastic.co/u/ntsh999)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 9:49pm UTC](https://discuss.elastic.co/t/i-want-to-establish-connectivity-between-filebeat-running-on-a-linux-based-vm-and-logstash-running-in-kubernetes-logstash-exposed-through-ingress/192781 "2019-07-29T21:49:54Z")

</div>

I have specified logstash output in the filebeat.yml file host: \["https://example.com/logstash"\]. I have multiple services exposed through ingress and hence I want the logstash also to be exposed through the same ingress…

---

## [Beats protocol input option](https://discuss.elastic.co/t/beats-protocol-input-option/192771)

<div class="topic-metadata">

**Author:** [@Will\_Weber](https://discuss.elastic.co/u/Will_Weber)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 8:14pm UTC](https://discuss.elastic.co/t/beats-protocol-input-option/192771 "2019-07-29T20:14:49Z")

</div>

Any chance you all would be open to a beats server as a filebeat input option? My team currently run a series of beats servers at my edge to push into a larger aggregator infrastructure(over tcp and udp), and would love…

---

## [How to interpret memory stats in filebeat log](https://discuss.elastic.co/t/how-to-interpret-memory-stats-in-filebeat-log/191110)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 2\
**Last updated:** [July 29, 2019, 7:48pm UTC](https://discuss.elastic.co/t/how-to-interpret-memory-stats-in-filebeat-log/191110 "2019-07-29T19:48:08Z")

</div>

Hello, I am wondering what is the following 3 memstats means? beat.memstats.gc\_next=32389200 beat.memstats.memory\_alloc=32504416 beat.memstats.memory\_total=51506747192 For example, i would like to know what is maxim…

---

## [Filebeat 6.4 not sorting the keys in ascending for json formatted log lines](https://discuss.elastic.co/t/filebeat-6-4-not-sorting-the-keys-in-ascending-for-json-formatted-log-lines/192701)

<div class="topic-metadata">

**Author:** [@er.navalgupta](https://discuss.elastic.co/u/er.navalgupta)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 1:21pm UTC](https://discuss.elastic.co/t/filebeat-6-4-not-sorting-the-keys-in-ascending-for-json-formatted-log-lines/192701 "2019-07-29T13:21:38Z")

</div>

we were having filebeat running on 5.6 and it was working perfectly fine reading JSON formatted logs and this 5.6 version was sorting keys in each and every log line by default. But 6.4 is not doing this, its not sortin…

---

## [Logstash grok pattern COMBINEDAPACHELOG field name collision with latest filebeat 7.2.0 client and logstash useragent plugin](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584)

<div class="topic-metadata">

**Author:** [@iuuuuan](https://discuss.elastic.co/u/iuuuuan)\
**Replies:** 4\
**Last updated:** [July 29, 2019, 8:53am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584 "2019-07-29T08:53:34Z")

</div>

Hi, there seems to be issues with logstash grok pattern COMBINEDAPACHELOG with latest filebeat 7.2.0 client and logstash useragent plugin. I am using grok pattern COMBINEDAPACHELOG which translates to %{COMMONAPACHELO…

---

## [Is Filebeat support planed for AIX?](https://discuss.elastic.co/t/is-filebeat-support-planed-for-aix/192651)

<div class="topic-metadata">

**Author:** [@Mickael\_Humphreys](https://discuss.elastic.co/u/Mickael_Humphreys)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 8:56am UTC](https://discuss.elastic.co/t/is-filebeat-support-planed-for-aix/192651 "2019-07-29T08:56:20Z")

</div>

Hello, We have seen a lot of discussions on how to install Filebeat on AIX systems. Since we are in 2019, do you have planed to have AIX support for Filebeat ? Cheers, Mickael HUMPHREYS.

---

## [Add multiple tags with Postgresql module](https://discuss.elastic.co/t/add-multiple-tags-with-postgresql-module/192646)

<div class="topic-metadata">

**Author:** [@ts-kazuob](https://discuss.elastic.co/u/ts-kazuob)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 8:36am UTC](https://discuss.elastic.co/t/add-multiple-tags-with-postgresql-module/192646 "2019-07-29T08:36:42Z")

</div>

Hi, I would like to know if multiple tags can be added with Postgresql module. In my environment there are two postgresql containers and it shoud have different Elasticsearch indexes. Below is the current setting of fil…

---

## [\[Feature\] Logstash Module with JVM & Pipelines](https://discuss.elastic.co/t/feature-logstash-module-with-jvm-pipelines/192645)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 8:28am UTC](https://discuss.elastic.co/t/feature-logstash-module-with-jvm-pipelines/192645 "2019-07-29T08:28:18Z")

</div>

Hi, everyone I would like to know if it is planned that Metricbeat's Logstash module (Link) can provide information about pipelines and JVM (heap, gc). Currently, it is possible to get Logstash’s metrics by using Joloki…

---

## [Metricbeat and Filebeat 7.2 enrollment problem](https://discuss.elastic.co/t/metricbeat-and-filebeat-7-2-enrollment-problem/192643)

<div class="topic-metadata">

**Author:** [@nitzan.karni](https://discuss.elastic.co/u/nitzan.karni)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 8:25am UTC](https://discuss.elastic.co/t/metricbeat-and-filebeat-7-2-enrollment-problem/192643 "2019-07-29T08:25:12Z")

</div>

Firstly the main problem caused me to try and upgrade my beats: Recently upgraded the elastic stack to 7.2, this caused the metricbeat and filebeat (Windows version 7.0.0) to stop sending data to the elastic. I decied…

---

## [Prioritize a logstash node over the others](https://discuss.elastic.co/t/prioritize-a-logstash-node-over-the-others/192625)

<div class="topic-metadata">

**Author:** [@Nonow53](https://discuss.elastic.co/u/Nonow53)\
**Replies:** 0\
**Last updated:** [July 29, 2019, 7:34am UTC](https://discuss.elastic.co/t/prioritize-a-logstash-node-over-the-others/192625 "2019-07-29T07:34:31Z")

</div>

Hello, When I define a multiple hosts list in logstash output configuration, is it possible to prioritize one host over the others ? Can I affect a weight in order to redistribute essentially to one specific node and s…

---

## [HEARTBEAT: most of HTTP monitors fail from time to time](https://discuss.elastic.co/t/heartbeat-most-of-http-monitors-fail-from-time-to-time/192557)

<div class="topic-metadata">

**Author:** [@George\_Wainwright](https://discuss.elastic.co/u/George_Wainwright)\
**Replies:** 0\
**Last updated:** [July 28, 2019, 10:13am UTC](https://discuss.elastic.co/t/heartbeat-most-of-http-monitors-fail-from-time-to-time/192557 "2019-07-28T10:13:51Z")

</div>

From time to time most of my configured HTTP monitors fail with next errors: read: connection reset by peer or http: request timed out while waiting for response (Client.Timeout exceeded while awaiting headers) or E…

---

## [How to visualise unique counts in a data table](https://discuss.elastic.co/t/how-to-visualise-unique-counts-in-a-data-table/192553)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 0\
**Last updated:** [July 28, 2019, 8:32am UTC](https://discuss.elastic.co/t/how-to-visualise-unique-counts-in-a-data-table/192553 "2019-07-28T08:32:16Z")

</div>

Hi @andrewkroh and others. Andrew this blog article points to your repo, which is why i have mentioned you specifically. I have tried to configure the user logins table, but so far have not succeeded. I am specificall…

---

## [Heartbeat hostname](https://discuss.elastic.co/t/heartbeat-hostname/190754)

<div class="topic-metadata">

**Author:** [@temuccio](https://discuss.elastic.co/u/temuccio)\
**Replies:** 4\
**Last updated:** [July 27, 2019, 6:44am UTC](https://discuss.elastic.co/t/heartbeat-hostname/190754 "2019-07-27T06:44:13Z")

</div>

Hi all... On my networks I have enable heartbeat to monitor all networks devices via ICMP (ping). It's works fine but it is possible to associate at one host one human readable name on kibana for each hosts? Thanks

---

## [Can filebeat pick up log entries based on keywords?](https://discuss.elastic.co/t/can-filebeat-pick-up-log-entries-based-on-keywords/191565)

<div class="topic-metadata">

**Author:** [@yungnvn](https://discuss.elastic.co/u/yungnvn)\
**Replies:** 2\
**Last updated:** [July 26, 2019, 6:46pm UTC](https://discuss.elastic.co/t/can-filebeat-pick-up-log-entries-based-on-keywords/191565 "2019-07-26T18:46:24Z")

</div>

Is it possible for filebeat to pick up only certain log entries? For ex, if my log entry contains the following: \[2019-07-21:00:00:00\] \[INFO\] \[log message\] \[2019-07-21:00:00:01\] \[ERROR\] \[log message\] Can I tell fileb…

---

## [Is it possible to have multiple inputs with different type](https://discuss.elastic.co/t/is-it-possible-to-have-multiple-inputs-with-different-type/192486)

<div class="topic-metadata">

**Author:** [@tanjok](https://discuss.elastic.co/u/tanjok)\
**Replies:** 0\
**Last updated:** [July 26, 2019, 6:01pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-multiple-inputs-with-different-type/192486 "2019-07-26T18:01:15Z")

</div>

Hello. Is it possible to have multiple inputs with different type? Something like this. filebeat.inputs: - type: docker containers: path: "/usr/share/filebeat/dockerlogs/data" stream: "stdout" i…

---

## [IIS W3C format logs not being mapped by filebeat iis module](https://discuss.elastic.co/t/iis-w3c-format-logs-not-being-mapped-by-filebeat-iis-module/191332)

<div class="topic-metadata">

**Author:** [@fadil030889](https://discuss.elastic.co/u/fadil030889)\
**Replies:** 1\
**Last updated:** [July 26, 2019, 4:08pm UTC](https://discuss.elastic.co/t/iis-w3c-format-logs-not-being-mapped-by-filebeat-iis-module/191332 "2019-07-26T16:08:35Z")

</div>

Hi, So we have filebeat on prem, sending iis logs onto an elastic cloud stack, with the iis modules enabled, we are having this error: " Provided Grok expressions do not match field value ". I've checked the raw iis log…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=331)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=333)
