# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=333

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 334

---

## [Filebeat custom index](https://discuss.elastic.co/t/filebeat-custom-index/192442)

<div class="topic-metadata">

**Author:** [@richard\_N](https://discuss.elastic.co/u/richard_N)\
**Replies:** 1\
**Last updated:** [July 26, 2019, 3:41pm UTC](https://discuss.elastic.co/t/filebeat-custom-index/192442 "2019-07-26T15:41:37Z")

</div>

I'm running filebeat 7.2 and trying to capture some exchange logs and put them in their own custom index but they always seem to end up in the default filebeat index. Below is my filebeat.yml. I've tried setting the setu…

---

## [Running Filebeat on a weekly basis](https://discuss.elastic.co/t/running-filebeat-on-a-weekly-basis/191797)

<div class="topic-metadata">

**Author:** [@Senthil\_Kumaran](https://discuss.elastic.co/u/Senthil_Kumaran)\
**Replies:** 3\
**Last updated:** [July 26, 2019, 12:47pm UTC](https://discuss.elastic.co/t/running-filebeat-on-a-weekly-basis/191797 "2019-07-26T12:47:25Z")

</div>

I have a requirement , where i have to run filebeat on a weekly basis , once a harvesting is done on a specified time frame i want the particular file to be harvested after a week , so any changes to be done in filebeat…

---

## [Combining processors for Graylog](https://discuss.elastic.co/t/combining-processors-for-graylog/192437)

<div class="topic-metadata">

**Author:** [@mdobson90](https://discuss.elastic.co/u/mdobson90)\
**Replies:** 0\
**Last updated:** [July 26, 2019, 12:35pm UTC](https://discuss.elastic.co/t/combining-processors-for-graylog/192437 "2019-07-26T12:35:06Z")

</div>

Hi all, Total noob here with Elastic, so hopefully you can help. I'm running a Graylog server which uses elastic backend, and have winlogbeat installed on all PCs via the Graylog Collector Sidecar. My current config i…

---

## [Cannot start Metricbeat as Windows Service ( 7.2.0 )](https://discuss.elastic.co/t/cannot-start-metricbeat-as-windows-service-7-2-0/192420)

<div class="topic-metadata">

**Author:** [@Nimothy](https://discuss.elastic.co/u/Nimothy)\
**Replies:** 0\
**Last updated:** [July 26, 2019, 11:16am UTC](https://discuss.elastic.co/t/cannot-start-metricbeat-as-windows-service-7-2-0/192420 "2019-07-26T11:16:56Z")

</div>

Hi All, I'm trying to start Metricbeat as a windows service but it is refusing to start. I'm getting an error 1067: The process terminated unexpectedly OS: Windows 2016 DataCenter Metricbeat Service AppPath "C:\\Prog…

---

## [Metricbeat on docker dashboard](https://discuss.elastic.co/t/metricbeat-on-docker-dashboard/192004)

<div class="topic-metadata">

**Author:** [@Jay-R\_Manguba](https://discuss.elastic.co/u/Jay-R_Manguba)\
**Replies:** 5\
**Last updated:** [July 26, 2019, 10:50am UTC](https://discuss.elastic.co/t/metricbeat-on-docker-dashboard/192004 "2019-07-26T10:50:41Z")

</div>

Hi, I install metric beat on docker to another server to check the CPU Usage, Memory Utilization and Network. I try the default metricbeat docker dashboard but the output seems wrong. Can anyone can help me how to creat…

---

## [Filebeat regexp](https://discuss.elastic.co/t/filebeat-regexp/191792)

<div class="topic-metadata">

**Author:** [@O.Shulha](https://discuss.elastic.co/u/O.Shulha)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 6:23pm UTC](https://discuss.elastic.co/t/filebeat-regexp/191792 "2019-07-25T18:23:24Z")

</div>

I have some log files in folder. I tried to send files to the logstash. filebeat.yml filebeat.inputs: - input\_type: log enabled: true paths: - /opt/nso/ncs-run/logs/rollback\* multiline.pattern: 'ncs:\*' mult…

---

## [Changing timezone in pipeline does not show correct in Kibana](https://discuss.elastic.co/t/changing-timezone-in-pipeline-does-not-show-correct-in-kibana/192391)

<div class="topic-metadata">

**Author:** [@B.Brey](https://discuss.elastic.co/u/B.Brey)\
**Replies:** 0\
**Last updated:** [July 26, 2019, 8:50am UTC](https://discuss.elastic.co/t/changing-timezone-in-pipeline-does-not-show-correct-in-kibana/192391 "2019-07-26T08:50:48Z")

</div>

We are having problems with a server running in CET timezone and apache 2 error logs. The apache error logs do not have timezone information unlike the access logs. When I check the page https://www.elastic.co/guide/en…

---

## [INFO \[publish\] pipeline/retry.go:155 Drop batch](https://discuss.elastic.co/t/info-publish-pipeline-retry-go-155-drop-batch/191597)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 2\
**Last updated:** [July 26, 2019, 6:39am UTC](https://discuss.elastic.co/t/info-publish-pipeline-retry-go-155-drop-batch/191597 "2019-07-26T06:39:26Z")

</div>

Hi, what is the meaning of this line in filebeat logs? 2019-07-22T09:41:10.690+0200 INFO \[publish\] pipeline/retry.go:155 Drop batch I have this line very regularly, but as I see it data is shipped to redi…

---

## [Filebeat is sending data from a Different Location](https://discuss.elastic.co/t/filebeat-is-sending-data-from-a-different-location/192236)

<div class="topic-metadata">

**Author:** [@mostafa\_kamal](https://discuss.elastic.co/u/mostafa_kamal)\
**Replies:** 2\
**Last updated:** [July 26, 2019, 5:43am UTC](https://discuss.elastic.co/t/filebeat-is-sending-data-from-a-different-location/192236 "2019-07-26T05:43:28Z")

</div>

Hi, I am trying to send log from one server to logstash server. But, I found that, log is being sent from other location. What did I miss? filebeat.yml ######################Filebeat Configuration Example #############…

---

## [Help needed Apache Access log grok pattern](https://discuss.elastic.co/t/help-needed-apache-access-log-grok-pattern/192357)

<div class="topic-metadata">

**Author:** [@narrasudhakar](https://discuss.elastic.co/u/narrasudhakar)\
**Replies:** 0\
**Last updated:** [July 26, 2019, 5:24am UTC](https://discuss.elastic.co/t/help-needed-apache-access-log-grok-pattern/192357 "2019-07-26T05:24:59Z")

</div>

Hi, I am using filebeat to send the access logs to elastic search, not able to write grok patten for below log format, any help will be appreciated. "2019-07-25 21:21:43" user POST "/api/details" "" text/html 500 606 7…

---

## [How to authorize heartbeat http urls](https://discuss.elastic.co/t/how-to-authorize-heartbeat-http-urls/192237)

<div class="topic-metadata">

**Author:** [@Priya2](https://discuss.elastic.co/u/Priya2)\
**Replies:** 2\
**Last updated:** [July 26, 2019, 4:55am UTC](https://discuss.elastic.co/t/how-to-authorize-heartbeat-http-urls/192237 "2019-07-26T04:55:05Z")

</div>

Hi, I have installed and configured http url on my heartbeat.yml (Heartbeat version6.3.2). My urls are working fine. Getting the login page. But heartbeat is trying to authorize those urls. I am not getting why? Below i…

---

## [MAX TPS Achieved by file beat to Azure Event Hub : 600, anything more than that ends up in broken pipe](https://discuss.elastic.co/t/max-tps-achieved-by-file-beat-to-azure-event-hub-600-anything-more-than-that-ends-up-in-broken-pipe/192119)

<div class="topic-metadata">

**Author:** [@Pragna\_Mohapatra](https://discuss.elastic.co/u/Pragna_Mohapatra)\
**Replies:** 2\
**Last updated:** [July 26, 2019, 3:33am UTC](https://discuss.elastic.co/t/max-tps-achieved-by-file-beat-to-azure-event-hub-600-anything-more-than-that-ends-up-in-broken-pipe/192119 "2019-07-26T03:33:40Z")

</div>

Hi, I am using kafka sink more to write the logs using file beat to as azure event hub. The maximum throughput I ever achieved is 700, anything beyond that just ends up broken pipes and my throughput drops drastically.…

---

## [Metricbeat fail with the error: failed to process cluster event (put-lifecycle-metricbeat-7.2.0) within 30s](https://discuss.elastic.co/t/metricbeat-fail-with-the-error-failed-to-process-cluster-event-put-lifecycle-metricbeat-7-2-0-within-30s/192340)

<div class="topic-metadata">

**Author:** [@Flaviu](https://discuss.elastic.co/u/Flaviu)\
**Replies:** 0\
**Last updated:** [July 26, 2019, 12:47am UTC](https://discuss.elastic.co/t/metricbeat-fail-with-the-error-failed-to-process-cluster-event-put-lifecycle-metricbeat-7-2-0-within-30s/192340 "2019-07-26T00:47:34Z")

</div>

I am getting the following error, and after a few hours of reasearch and configuration changes I could not find a solution. Jul 26 00:31:05 am01 metricbeat: {"level":"error","timestamp":"2019-07-26T00:31:05.712Z","calle…

---

## [Configuring filebeat for parsing JSON formatted messages](https://discuss.elastic.co/t/configuring-filebeat-for-parsing-json-formatted-messages/192324)

<div class="topic-metadata">

**Author:** [@Karthik2411](https://discuss.elastic.co/u/Karthik2411)\
**Replies:** 0\
**Last updated:** [July 25, 2019, 9:16pm UTC](https://discuss.elastic.co/t/configuring-filebeat-for-parsing-json-formatted-messages/192324 "2019-07-25T21:16:01Z")

</div>

Hello @Brandon\_Kobel. We are using filebeat on windows. We are forwarding messages using filebeat to ELK. The messages are coming in as is from the JSON Index. I am wondering If we need to change anything in the filebeat…

---

## [Filebeat logging data from disabled modules](https://discuss.elastic.co/t/filebeat-logging-data-from-disabled-modules/192312)

<div class="topic-metadata">

**Author:** [@johnc1231](https://discuss.elastic.co/u/johnc1231)\
**Replies:** 0\
**Last updated:** [July 25, 2019, 7:44pm UTC](https://discuss.elastic.co/t/filebeat-logging-data-from-disabled-modules/192312 "2019-07-25T19:44:50Z")

</div>

I am running filebeat as a DaemonSet on my Kubernetes cluster. The following is my configuration file: filebeat.modules: filebeat.inputs: - type: container paths: - /var/log/containers/\*.log processors: - ad…

---

## [Filebeat not able to ship logs for multiple paths](https://discuss.elastic.co/t/filebeat-not-able-to-ship-logs-for-multiple-paths/191428)

<div class="topic-metadata">

**Author:** [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 6:44pm UTC](https://discuss.elastic.co/t/filebeat-not-able-to-ship-logs-for-multiple-paths/191428 "2019-07-25T18:44:46Z")

</div>

I have the below configuration for filebeat : --- filebeat.config.modules: path: "${path.config}/modules.d/\*.yml" reload.enabled: false filebeat.inputs: - enabled: true paths: - '/builds/v2018/jenkins/jobs/…

---

## [Filebeat 7.2's osquery module not respecting var.use\_namespace: false](https://discuss.elastic.co/t/filebeat-7-2s-osquery-module-not-respecting-var-use-namespace-false/191465)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-7-2s-osquery-module-not-respecting-var-use-namespace-false/191465 "2019-07-25T18:41:17Z")

</div>

The documentation at Osquery module | Filebeat Reference \[8.11\] | Elastic says: var.use\_namespace If true, all fields exported by this module are prefixed with osquery.result . Set to false to copy the fields in the …

---

## [How to get beat.name(filebeat) as Docker HostIP](https://discuss.elastic.co/t/how-to-get-beat-name-filebeat-as-docker-hostip/191549)

<div class="topic-metadata">

**Author:** [@monica2](https://discuss.elastic.co/u/monica2)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 6:37pm UTC](https://discuss.elastic.co/t/how-to-get-beat-name-filebeat-as-docker-hostip/191549 "2019-07-25T18:37:27Z")

</div>

Hi All I am using filebeat Docker. we have AWS Infrastructure this filebeat container is running on our 20 ec2 machines. The problem is when something goes wron on any machines it's being hard to debug which machine wen…

---

## [Filebeat yml configuration](https://discuss.elastic.co/t/filebeat-yml-configuration/191708)

<div class="topic-metadata">

**Author:** [@Rovaldy\_Applyrs](https://discuss.elastic.co/u/Rovaldy_Applyrs)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 6:28pm UTC](https://discuss.elastic.co/t/filebeat-yml-configuration/191708 "2019-07-25T18:28:15Z")

</div>

In regards to the Filebeat input configuration in the yml file, is it possible to read in a folder that contains multiple files as a possible path? Or only files could be used as a path?

---

## [The padding isn't handled correctly](https://discuss.elastic.co/t/the-padding-isnt-handled-correctly/191768)

<div class="topic-metadata">

**Author:** [@alexott](https://discuss.elastic.co/u/alexott)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 6:25pm UTC](https://discuss.elastic.co/t/the-padding-isnt-handled-correctly/191768 "2019-07-25T18:25:51Z")

</div>

It almost the same question as in https://discuss.elastic.co/t/dissect-filter-not-removing-whitespace-padding-via-suffix/161233 Per documentation we should handle padding on the right by adding -\> to the field name. I …

---

## [Filebeat Index Variables](https://discuss.elastic.co/t/filebeat-index-variables/191843)

<div class="topic-metadata">

**Author:** [@KWBrandenWagner](https://discuss.elastic.co/u/KWBrandenWagner)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 6:11pm UTC](https://discuss.elastic.co/t/filebeat-index-variables/191843 "2019-07-25T18:11:17Z")

</div>

I'm sure this is already written somewhere, but I am obviously looking for the wrong words. I just started using the SIEM in 7.2 and its working pretty good I am using Filebeat modules for Zeek and Suricata. I want eac…

---

## [Filebeat - ERROR registrar/registrar.go:374](https://discuss.elastic.co/t/filebeat-error-registrar-registrar-go-374/191878)

<div class="topic-metadata">

**Author:** [@bizomb](https://discuss.elastic.co/u/bizomb)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 5:37pm UTC](https://discuss.elastic.co/t/filebeat-error-registrar-registrar-go-374/191878 "2019-07-25T17:37:04Z")

</div>

When I run filebeat setup when processing the files I get error about the registry. Please assist on why and how to fix the error in the log file. ERROR registrar/registrar.go:374 2019-07-23T10:26:55.875-0700 ERR…

---

## [Filebeat for zLinux (IBM mainframe zOS Linux)](https://discuss.elastic.co/t/filebeat-for-zlinux-ibm-mainframe-zos-linux/191662)

<div class="topic-metadata">

**Author:** [@jiawang](https://discuss.elastic.co/u/jiawang)\
**Replies:** 2\
**Last updated:** [July 25, 2019, 5:25pm UTC](https://discuss.elastic.co/t/filebeat-for-zlinux-ibm-mainframe-zos-linux/191662 "2019-07-25T17:25:34Z")

</div>

We want to use filebeat to get some app logs on zLinux which is linux mainframe version provided by IBM zOS. It is not intel based system, it is IBM S/390 machine. what we did was the follow two steps (which worked with…

---

## [Drop Events By ID](https://discuss.elastic.co/t/drop-events-by-id/192145)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 4:28pm UTC](https://discuss.elastic.co/t/drop-events-by-id/192145 "2019-07-25T16:28:09Z")

</div>

Trying to drop events by their event\_id number but what I am using doesn't seem to be working. Where am I wrong at? winlogbeat.event\_logs: - name: System ignore\_older: 72h - name: Application ignore\_older: …

---

## [Multiline configuration for golang panic stacktraces](https://discuss.elastic.co/t/multiline-configuration-for-golang-panic-stacktraces/192071)

<div class="topic-metadata">

**Author:** [@bschaeffer](https://discuss.elastic.co/u/bschaeffer)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 4:00pm UTC](https://discuss.elastic.co/t/multiline-configuration-for-golang-panic-stacktraces/192071 "2019-07-25T16:00:30Z")

</div>

Has anyone come up with a multiline configuration for matching golang panic stacktraces? FWIW, an example: fatal error: runtime: out of memory runtime stack: runtime.throw(0x10daffb, 0x16) /tools/go/src/runtim…

---

## [Log Parsing in filebeat](https://discuss.elastic.co/t/log-parsing-in-filebeat/190075)

<div class="topic-metadata">

**Author:** [@Eowin](https://discuss.elastic.co/u/Eowin)\
**Replies:** 4\
**Last updated:** [July 25, 2019, 2:46pm UTC](https://discuss.elastic.co/t/log-parsing-in-filebeat/190075 "2019-07-25T14:46:02Z")

</div>

Hi, I need some help to setup different configuration on filebeat. I would like add a new grok pattern in /usr/share/filebeat/module/system/syslog/ingest/pipeline.json for this pattern of log : \[test0\]\[pression\]\[3.10.…

---

## [Metricbeat not able to connect with x-pack enabled elastic](https://discuss.elastic.co/t/metricbeat-not-able-to-connect-with-x-pack-enabled-elastic/191753)

<div class="topic-metadata">

**Author:** [@abhishek13](https://discuss.elastic.co/u/abhishek13)\
**Replies:** 3\
**Last updated:** [July 25, 2019, 12:33pm UTC](https://discuss.elastic.co/t/metricbeat-not-able-to-connect-with-x-pack-enabled-elastic/191753 "2019-07-25T12:33:02Z")

</div>

Hi While connecting metricbeat with x-pack enabled elastic cluster , i am getting below error. 2019-07-23T12:45:21.103+0530 INFO instance/beat.go:292 Setup Beat: metricbeat; Version: 7.2.0 2019-07-23T12:45:21.103+0530 …

---

## [FreeBSD metricbeat error cannot find matching process for pid](https://discuss.elastic.co/t/freebsd-metricbeat-error-cannot-find-matching-process-for-pid/191487)

<div class="topic-metadata">

**Author:** [@Mikedm](https://discuss.elastic.co/u/Mikedm)\
**Replies:** 1\
**Last updated:** [July 25, 2019, 10:39am UTC](https://discuss.elastic.co/t/freebsd-metricbeat-error-cannot-find-matching-process-for-pid/191487 "2019-07-25T10:39:21Z")

</div>

I'm trying to run the version of metricbeat from the FreeBSD packages. It's currently version 6.7.1. I've had a few issues with it due to files being in different places (modules.d, modules). I've now got it recognizin…

---

## [Filebeats to Elasticsearch](https://discuss.elastic.co/t/filebeats-to-elasticsearch/192211)

<div class="topic-metadata">

**Author:** [@sarban.kumar](https://discuss.elastic.co/u/sarban.kumar)\
**Replies:** 0\
**Last updated:** [July 25, 2019, 9:36am UTC](https://discuss.elastic.co/t/filebeats-to-elasticsearch/192211 "2019-07-25T09:36:46Z")

</div>

Hi All - I'm new on elasticsearch. We do have got requirment for log analysis for networks devices log , we are getting all the logs in one syslog server and installed filebeat on same server sending logs to elastic , b…

---

## [Filebeat errors while connecting to kubernetes API on start filebeat POD](https://discuss.elastic.co/t/filebeat-errors-while-connecting-to-kubernetes-api-on-start-filebeat-pod/192158)

<div class="topic-metadata">

**Author:** [@alexMX](https://discuss.elastic.co/u/alexMX)\
**Replies:** 0\
**Last updated:** [July 25, 2019, 3:43am UTC](https://discuss.elastic.co/t/filebeat-errors-while-connecting-to-kubernetes-api-on-start-filebeat-pod/192158 "2019-07-25T03:43:27Z")

</div>

Hello! On our k8s infrastructure, we are face to the connection issue while starting the filebeat POD. Affected filebeat versions are 6.4.0, 7.0. Log record is: ERROR kubernetes/kubernetes.go:127 Error starting kube…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=332)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=334)
