# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=334

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 335

---

## [Resolved](https://discuss.elastic.co/t/resolved/187907)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 0\
**Last updated:** [June 27, 2019, 7:15pm UTC](https://discuss.elastic.co/t/resolved/187907 "2019-06-27T19:15:27Z")

</div>

resolved....

---

## [Metricbeat Docker Module seems to break when used whithin Autodiscover context](https://discuss.elastic.co/t/metricbeat-docker-module-seems-to-break-when-used-whithin-autodiscover-context/192144)

<div class="topic-metadata">

**Author:** [@rmdm](https://discuss.elastic.co/u/rmdm)\
**Replies:** 0\
**Last updated:** [July 24, 2019, 9:46pm UTC](https://discuss.elastic.co/t/metricbeat-docker-module-seems-to-break-when-used-whithin-autodiscover-context/192144 "2019-07-24T21:46:00Z")

</div>

I'm trying to restrict the set of the containers to collect metrics from, by using autodiscover, exactly like this: metricbeat.autodiscover: providers: - type: docker templates: - condition: …

---

## [Packetbeat dropping transactions when attempting to split http requests and responses into seperate transactions](https://discuss.elastic.co/t/packetbeat-dropping-transactions-when-attempting-to-split-http-requests-and-responses-into-seperate-transactions/192092)

<div class="topic-metadata">

**Author:** [@Mark\_Ryder](https://discuss.elastic.co/u/Mark_Ryder)\
**Replies:** 0\
**Last updated:** [July 24, 2019, 4:27pm UTC](https://discuss.elastic.co/t/packetbeat-dropping-transactions-when-attempting-to-split-http-requests-and-responses-into-seperate-transactions/192092 "2019-07-24T16:27:07Z")

</div>

Hi, We are currently trying to do a full trace of all request and response XML payloads across an application. Packetbeat is able to get all transactions across the port specified when the transaction timeout is greater…

---

## [\[ filebeat -\> logstash \] vs \[ flume -\> kafka -\> logstash \]](https://discuss.elastic.co/t/filebeat-logstash-vs-flume-kafka-logstash/192018)

<div class="topic-metadata">

**Author:** [@sunil\_patel](https://discuss.elastic.co/u/sunil_patel)\
**Replies:** 0\
**Last updated:** [July 24, 2019, 11:48am UTC](https://discuss.elastic.co/t/filebeat-logstash-vs-flume-kafka-logstash/192018 "2019-07-24T11:48:41Z")

</div>

Hello Team, I needs feedback/comparison while deciding stack, anyone can help to provide idea that, \[flume -\> kafka -\>logstash\] flow could be replaced by \[filebeat-\>logstash\] efficiently without compromising data-los…

---

## [Filebeat shipping incomplete logs](https://discuss.elastic.co/t/filebeat-shipping-incomplete-logs/187296)

<div class="topic-metadata">

**Author:** [@svanschooten](https://discuss.elastic.co/u/svanschooten)\
**Replies:** 2\
**Last updated:** [July 23, 2019, 2:58pm UTC](https://discuss.elastic.co/t/filebeat-shipping-incomplete-logs/187296 "2019-07-23T14:58:49Z")

</div>

We want to improve our logging (filebeat -\> logstash -\> elasticsearch -\> kibana) and so far I have filebeat running on our docker host in its own container (I map all log files manually, since we do not manage the docker…

---

## [How to monitor kubernetes node filesystem from a container](https://discuss.elastic.co/t/how-to-monitor-kubernetes-node-filesystem-from-a-container/191919)

<div class="topic-metadata">

**Author:** [@Nicolas\_Labrot](https://discuss.elastic.co/u/Nicolas_Labrot)\
**Replies:** 1\
**Last updated:** [July 24, 2019, 5:42am UTC](https://discuss.elastic.co/t/how-to-monitor-kubernetes-node-filesystem-from-a-container/191919 "2019-07-24T05:42:44Z")

</div>

Hi, I'm trying to monitor the k8s node filesystem by using the metricbeat 7.2 deployment: I have adapted a little bit the drop event to drop the container filesystem: processors: - drop\_event.when.regexp: …

---

## [ILM settings not working](https://discuss.elastic.co/t/ilm-settings-not-working/190060)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 7\
**Last updated:** [July 24, 2019, 5:19am UTC](https://discuss.elastic.co/t/ilm-settings-not-working/190060 "2019-07-24T05:19:44Z")

</div>

Hi I am using filebeat and metric beat 7.2 and installing them on different windows and linux server. I want my beat agent to use existing ILM setting on elasticsearch but its overwriting it every time it is installed o…

---

## [Kibana logs shows HTTP 403 (Forbidden)](https://discuss.elastic.co/t/kibana-logs-shows-http-403-forbidden/183216)

<div class="topic-metadata">

**Author:** [@ksunil](https://discuss.elastic.co/u/ksunil)\
**Replies:** 6\
**Last updated:** [July 24, 2019, 2:51am UTC](https://discuss.elastic.co/t/kibana-logs-shows-http-403-forbidden/183216 "2019-07-24T02:51:10Z")

</div>

Hi, We are using kibana for monitoring where we defined the a custom files for url and TCP monitoring in heartbeat with all details a month back.Since last week URL and TCP monitoring data shows "No results found" in …

---

## [Monthly Indices with ILM not working?](https://discuss.elastic.co/t/monthly-indices-with-ilm-not-working/191847)

<div class="topic-metadata">

**Author:** [@arlen](https://discuss.elastic.co/u/arlen)\
**Replies:** 0\
**Last updated:** [July 23, 2019, 3:00pm UTC](https://discuss.elastic.co/t/monthly-indices-with-ilm-not-working/191847 "2019-07-23T15:00:15Z")

</div>

Using version 6.8.1 at the moment, trying to wrap my head around indices and ILM and I'm completely corn-fusled. Example: Packetbeat.yml contains: setup.template.name: "packetbeat-%{\[beat.version\]}" setup.template.pa…

---

## [Not getting TTY translations in Auditbeat 6.7](https://discuss.elastic.co/t/not-getting-tty-translations-in-auditbeat-6-7/191684)

<div class="topic-metadata">

**Author:** [@hobapolis](https://discuss.elastic.co/u/hobapolis)\
**Replies:** 2\
**Last updated:** [July 23, 2019, 12:09pm UTC](https://discuss.elastic.co/t/not-getting-tty-translations-in-auditbeat-6-7/191684 "2019-07-23T12:09:25Z")

</div>

Hello! I'm trying to get auditbeat to translate my TTY. I have the basics set up properly and I'm, for now, using the default rules that come out of the box with auditbeat. My /etc/pam.d/common-session file ends with s…

---

## [Dropped\_because\_of\_gaps](https://discuss.elastic.co/t/dropped-because-of-gaps/191786)

<div class="topic-metadata">

**Author:** [@Umar\_Hayat](https://discuss.elastic.co/u/Umar_Hayat)\
**Replies:** 0\
**Last updated:** [July 23, 2019, 10:44am UTC](https://discuss.elastic.co/t/dropped-because-of-gaps/191786 "2019-07-23T10:44:47Z")

</div>

I am trying to capture my network interface card traffic on my local machine. But Packetbeat is not capturing all packets. This is the error I am getting. {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":59…

---

## [PANW module timezone offset](https://discuss.elastic.co/t/panw-module-timezone-offset/191360)

<div class="topic-metadata">

**Author:** [@seatsea](https://discuss.elastic.co/u/seatsea)\
**Replies:** 4\
**Last updated:** [July 23, 2019, 10:33am UTC](https://discuss.elastic.co/t/panw-module-timezone-offset/191360 "2019-07-23T10:33:33Z")

</div>

I have a Paloalto firewall configured with the local timezone Europe/Paris sending syslog to a Filebeat Docker container using the default timezone of UTC using the PANW module. Setting var.convert\_timezone: true does n…

---

## [Respect the Filebeat template when using "setup.template", X-Pack monitoring failing](https://discuss.elastic.co/t/respect-the-filebeat-template-when-using-setup-template-x-pack-monitoring-failing/191771)

<div class="topic-metadata">

**Author:** [@jesusgn90](https://discuss.elastic.co/u/jesusgn90)\
**Replies:** 1\
**Last updated:** [July 23, 2019, 10:24am UTC](https://discuss.elastic.co/t/respect-the-filebeat-template-when-using-setup-template-x-pack-monitoring-failing/191771 "2019-07-23T10:24:32Z")

</div>

Hi team, Elastic stack 7.2.0 Filebeat -\> Elasticsearch -\> Kibana I'm struggling with a weird scenario where I need to load the index template for my integration through Filebeat but I don't want to override the Filebea…

---

## [Filebeat not sending ModSecurity log files](https://discuss.elastic.co/t/filebeat-not-sending-modsecurity-log-files/191224)

<div class="topic-metadata">

**Author:** [@maxxer](https://discuss.elastic.co/u/maxxer)\
**Replies:** 4\
**Last updated:** [July 23, 2019, 8:53am UTC](https://discuss.elastic.co/t/filebeat-not-sending-modsecurity-log-files/191224 "2019-07-23T08:53:56Z")

</div>

Hi. I've configured ModSecurity to generate JSON files this way: SecAuditEngine On SecAuditLogType Concurrent SecAuditLogFormat JSON SecAuditLogStorageDir /data/nginx/log/modsecurity This means ModSec will generate a …

---

## [Filebeat @metadata object, can we remove this object before publishing?](https://discuss.elastic.co/t/filebeat-metadata-object-can-we-remove-this-object-before-publishing/189847)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 5\
**Last updated:** [July 23, 2019, 7:03am UTC](https://discuss.elastic.co/t/filebeat-metadata-object-can-we-remove-this-object-before-publishing/189847 "2019-07-23T07:03:32Z")

</div>

I'm using filebeat 7.1.1 with a simple log file input filebeat.inputs: - type: log When the events are published, there is a "@metadata" object inserted in the event. { "@timestamp": "2019-07-10T18:24:56.312Z", …

---

## [Using a processor in a filebeat module may or may not actually find fields](https://discuss.elastic.co/t/using-a-processor-in-a-filebeat-module-may-or-may-not-actually-find-fields/191461)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 2\
**Last updated:** [July 22, 2019, 8:49pm UTC](https://discuss.elastic.co/t/using-a-processor-in-a-filebeat-module-may-or-may-not-actually-find-fields/191461 "2019-07-22T20:49:03Z")

</div>

(Elasticsearch and filebeat are both v7.2) I was encountering a lot of difficulty using the convert processor to change types, so I simplified things down to using rename. The results of my tests are confusing. Given t…

---

## [Minimum Permissions for Heartbeat](https://discuss.elastic.co/t/minimum-permissions-for-heartbeat/191246)

<div class="topic-metadata">

**Author:** [@tadgh](https://discuss.elastic.co/u/tadgh)\
**Replies:** 4\
**Last updated:** [July 22, 2019, 4:48pm UTC](https://discuss.elastic.co/t/minimum-permissions-for-heartbeat/191246 "2019-07-22T16:48:29Z")

</div>

Hey there What are the minimum permissions to get heartbeat up and running? I don't really want to provide superuser credentials to heartbeat, so I'd like to know what the very minimum I can get away with is, including …

---

## [Using packetbeat with macos/ios remote virutal interface](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604)

<div class="topic-metadata">

**Author:** [@stru](https://discuss.elastic.co/u/stru)\
**Replies:** 5\
**Last updated:** [July 22, 2019, 4:37pm UTC](https://discuss.elastic.co/t/using-packetbeat-with-macos-ios-remote-virutal-interface/183604 "2019-07-22T16:37:02Z")

</div>

Does packetbeat support use of the remote virtual interface on macOS? If so, what needs to be done to get it to work correctly. I am getting this error when trying to run packetbeat with rvi0 as an interface in packetbe…

---

## [Heartbeat 7.2.0 Error: unknown flag: --index-management](https://discuss.elastic.co/t/heartbeat-7-2-0-error-unknown-flag-index-management/191670)

<div class="topic-metadata">

**Author:** [@Geo-S](https://discuss.elastic.co/u/Geo-S)\
**Replies:** 1\
**Last updated:** [July 22, 2019, 4:21pm UTC](https://discuss.elastic.co/t/heartbeat-7-2-0-error-unknown-flag-index-management/191670 "2019-07-22T16:21:13Z")

</div>

Trying to upgrade to ELK 7.2.0. and have some ansible that gets beats up and running. Ran into an issue with Heartbeat 7.2.0 where the new --index-management flag is unknown and the --template flag still works despite t…

---

## [CPU utilisation visulaization showing 0 % always](https://discuss.elastic.co/t/cpu-utilisation-visulaization-showing-0-always/191612)

<div class="topic-metadata">

**Author:** [@sudeepvd](https://discuss.elastic.co/u/sudeepvd)\
**Replies:** 0\
**Last updated:** [July 22, 2019, 10:00am UTC](https://discuss.elastic.co/t/cpu-utilisation-visulaization-showing-0-always/191612 "2019-07-22T10:00:54Z")

</div>

Hi, I am trying to derive cpu utilisation visualization using system.cpu.total.pct field from metricbeat. I can see from discover tab that the field system.cpu.total.pct is being set as part of system module(cpu). Howev…

---

## [Icmp fields not populating](https://discuss.elastic.co/t/icmp-fields-not-populating/191357)

<div class="topic-metadata">

**Author:** [@AaronNBrock](https://discuss.elastic.co/u/AaronNBrock)\
**Replies:** 2\
**Last updated:** [July 22, 2019, 1:36pm UTC](https://discuss.elastic.co/t/icmp-fields-not-populating/191357 "2019-07-22T13:36:04Z")

</div>

Hello, I've got a instance of heartbeat running inside a docker container with the following configuration: heartbeat.monitors: - type: icmp schedule: '@every 10s' hosts: - 192.168.98.114 output.elasti…

---

## [\[metricbeat\]kubernetes job through kube-state-metrics](https://discuss.elastic.co/t/metricbeat-kubernetes-job-through-kube-state-metrics/191641)

<div class="topic-metadata">

**Author:** [@dague](https://discuss.elastic.co/u/dague)\
**Replies:** 0\
**Last updated:** [July 22, 2019, 1:00pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-job-through-kube-state-metrics/191641 "2019-07-22T13:00:33Z")

</div>

Hi, Following this thread, is there anyone working on job through kube-state-metrics? If not, i can work on it.

---

## [Filebeat Failed to publish events](https://discuss.elastic.co/t/filebeat-failed-to-publish-events/191010)

<div class="topic-metadata">

**Author:** [@jayshi1985](https://discuss.elastic.co/u/jayshi1985)\
**Replies:** 6\
**Last updated:** [July 22, 2019, 11:25am UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events/191010 "2019-07-22T11:25:20Z")

</div>

CentOS release 6.6 (Final) filebeat-6.6.1-linux-x86\_64.tar.gz filebeat config: type: log # Change to true to enable this input configuration. enabled: true # Paths that should be crawled and fetched. Glob bas…

---

## [Running Filebeat in docker with persistent registry file?](https://discuss.elastic.co/t/running-filebeat-in-docker-with-persistent-registry-file/191595)

<div class="topic-metadata">

**Author:** [@sLuvpreet33](https://discuss.elastic.co/u/sLuvpreet33)\
**Replies:** 4\
**Last updated:** [July 22, 2019, 9:24am UTC](https://discuss.elastic.co/t/running-filebeat-in-docker-with-persistent-registry-file/191595 "2019-07-22T09:24:08Z")

</div>

Hi, My question is this, If a container running filebeat is lost and we launch a new container, the registry file of the old container will be lost too and the new container wouldn't know from where the harvester should…

---

## [Metric beat kubernetes example not showing pod metrics](https://discuss.elastic.co/t/metric-beat-kubernetes-example-not-showing-pod-metrics/189257)

<div class="topic-metadata">

**Author:** [@csinc](https://discuss.elastic.co/u/csinc)\
**Replies:** 1\
**Last updated:** [July 19, 2019, 10:12pm UTC](https://discuss.elastic.co/t/metric-beat-kubernetes-example-not-showing-pod-metrics/189257 "2019-07-19T22:12:49Z")

</div>

Hi, I am just trying out metricbeat on kubernetes. I am using the provided example located at https://raw.githubusercontent.com/elastic/beats/7.2/deploy/kubernetes/metricbeat-kubernetes.yaml by only changing creds and c…

---

## [Metric beat kubernetes example not showing k8s pod metrics](https://discuss.elastic.co/t/metric-beat-kubernetes-example-not-showing-k8s-pod-metrics/191486)

<div class="topic-metadata">

**Author:** [@Soumitra\_Ghosh](https://discuss.elastic.co/u/Soumitra_Ghosh)\
**Replies:** 0\
**Last updated:** [July 20, 2019, 4:35pm UTC](https://discuss.elastic.co/t/metric-beat-kubernetes-example-not-showing-k8s-pod-metrics/191486 "2019-07-20T16:35:00Z")

</div>

Hi i can get data from metricsbeat in every env but from EKS i get the following error is there a workaround? localhost or hostip does not work either Error making http request: Get http://localhost:10255/stats/summary: …

---

## [Exclude Files with YYYY-MM-DD RegEx](https://discuss.elastic.co/t/exclude-files-with-yyyy-mm-dd-regex/191203)

<div class="topic-metadata">

**Author:** [@bgeveritt](https://discuss.elastic.co/u/bgeveritt)\
**Replies:** 2\
**Last updated:** [July 20, 2019, 3:52pm UTC](https://discuss.elastic.co/t/exclude-files-with-yyyy-mm-dd-regex/191203 "2019-07-20T15:52:12Z")

</div>

I have the following file structure: my-file1.2019-07-16.log my-file2.2019-07-16.log my-file.log Is there a way to apply a RegEx in the exclude\_files so that any of the files that have the YYYY-MM-DD pattern are excl…

---

## [No indices - but winlogbeat thinks it's working](https://discuss.elastic.co/t/no-indices-but-winlogbeat-thinks-its-working/191422)

<div class="topic-metadata">

**Author:** [@B\_Frap](https://discuss.elastic.co/u/B_Frap)\
**Replies:** 8\
**Last updated:** [July 19, 2019, 10:23pm UTC](https://discuss.elastic.co/t/no-indices-but-winlogbeat-thinks-its-working/191422 "2019-07-19T22:23:19Z")

</div>

Winlogbeat is pretty happy, but I'm not able to see anything in Kibana. I have some other beats reporting data. Here's a snip from winlogbeat: 2019-07-19T11:13:25.816-0400 INFO beater/eventlogger.go:76 EventLog\[Forward…

---

## [Filebeat not reading JSON Array](https://discuss.elastic.co/t/filebeat-not-reading-json-array/191451)

<div class="topic-metadata">

**Author:** [@subodhp](https://discuss.elastic.co/u/subodhp)\
**Replies:** 0\
**Last updated:** [July 19, 2019, 8:05pm UTC](https://discuss.elastic.co/t/filebeat-not-reading-json-array/191451 "2019-07-19T20:05:01Z")

</div>

I have "sourceIPs":\["127.0.0.1"\] in my JSON Logs, I am using drop\_events processor conditions like "equals" and "contains" to filter out events having 127.0.0.1 as sourceIP but none of the obvious filters seems to work. …

---

## [Filebeat is not sending logs due to ignore\_older](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-due-to-ignore-older/190567)

<div class="topic-metadata">

**Author:** [@Jaepyoung\_Kim](https://discuss.elastic.co/u/Jaepyoung_Kim)\
**Replies:** 6\
**Last updated:** [July 19, 2019, 8:02pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-due-to-ignore-older/190567 "2019-07-19T20:02:23Z")

</div>

The filebeat stop sending few hours after log files are rotated. I found out that ignore\_older is the reason of not sending data from some files. I haven't set config ignore\_older. So I disabled by ignore\_older: 0 exp…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=333)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=335)
