# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=335

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 336

---

## [Metricbeat won't connect to Logstash over network](https://discuss.elastic.co/t/metricbeat-wont-connect-to-logstash-over-network/191239)

<div class="topic-metadata">

**Author:** [@johnbchron](https://discuss.elastic.co/u/johnbchron)\
**Replies:** 2\
**Last updated:** [July 19, 2019, 5:38pm UTC](https://discuss.elastic.co/t/metricbeat-wont-connect-to-logstash-over-network/191239 "2019-07-19T17:38:42Z")

</div>

Hello all, I have set up a full installation of the elastic stack (full for me, filebeat-logstash-elasticsearch-kibana) on ubuntu 18.04, and it was working perfectly but I need metricbeat to send logs from a local windo…

---

## [Zeek Module - Custom Zeek Install Location](https://discuss.elastic.co/t/zeek-module-custom-zeek-install-location/191253)

<div class="topic-metadata">

**Author:** [@MrTrav](https://discuss.elastic.co/u/MrTrav)\
**Replies:** 2\
**Last updated:** [July 19, 2019, 4:27pm UTC](https://discuss.elastic.co/t/zeek-module-custom-zeek-install-location/191253 "2019-07-19T16:27:57Z")

</div>

I have installed Zeek at a custom location, how can I configure the Zeek module in FileBeats to collect the logs from the proper log location?

---

## [ECE Xpack Monitoring Connected but not displaying in Kibana](https://discuss.elastic.co/t/ece-xpack-monitoring-connected-but-not-displaying-in-kibana/191400)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 11\
**Last updated:** [July 19, 2019, 4:27pm UTC](https://discuss.elastic.co/t/ece-xpack-monitoring-connected-but-not-displaying-in-kibana/191400 "2019-07-19T16:27:37Z")

</div>

I'm currently trying to setup xpack monitoring on a Metricbeat thats pointing to an ECE cluster. I have been able to get a metricbeat on my desktop with xpack monitoring to connect to an ECE cluster named DevOps. Those…

---

## [Auth.log format via syslog?](https://discuss.elastic.co/t/auth-log-format-via-syslog/191420)

<div class="topic-metadata">

**Author:** [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Replies:** 0\
**Last updated:** [July 19, 2019, 3:10pm UTC](https://discuss.elastic.co/t/auth-log-format-via-syslog/191420 "2019-07-19T15:10:25Z")

</div>

Hi there, we are using filebeat to automatically pick up the /var/log/syslog and /var/log/auth.log on our Ubuntu servers and it is working great to populate the authlog dashboard in Kibana. We are starting to develop mo…

---

## [Filebeat doesn't send the message field to logstash](https://discuss.elastic.co/t/filebeat-doesnt-send-the-message-field-to-logstash/191398)

<div class="topic-metadata">

**Author:** [@daniele.saccon](https://discuss.elastic.co/u/daniele.saccon)\
**Replies:** 3\
**Last updated:** [July 19, 2019, 3:05pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-send-the-message-field-to-logstash/191398 "2019-07-19T15:05:10Z")

</div>

Hello, I have deployed Filebeat 6.8.1 in docker container, filebeat sends all the corrected data but the MESSAGE field is missing. The input configuration is: type: log paths: '/var/lib/docker/containers//.log' js…

---

## [Filebeat on Kubernetes, host.name got the pod names (and not the Kubernetes host name ?)](https://discuss.elastic.co/t/filebeat-on-kubernetes-host-name-got-the-pod-names-and-not-the-kubernetes-host-name/189951)

<div class="topic-metadata">

**Author:** [@twiggy](https://discuss.elastic.co/u/twiggy)\
**Replies:** 2\
**Last updated:** [July 19, 2019, 12:25pm UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-host-name-got-the-pod-names-and-not-the-kubernetes-host-name/189951 "2019-07-19T12:25:24Z")

</div>

Hello, Environment : Kibana, metricbeat, filebeat (all 7.2) I've deployed Filebeat on my Kubernetes cluster using this yaml. It's the one from the official website, but with namespaces (elastic) and elasticsearch host …

---

## [Need help with configuring cisco module in filebeat](https://discuss.elastic.co/t/need-help-with-configuring-cisco-module-in-filebeat/189596)

<div class="topic-metadata">

**Author:** [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Replies:** 3\
**Last updated:** [July 19, 2019, 7:52am UTC](https://discuss.elastic.co/t/need-help-with-configuring-cisco-module-in-filebeat/189596 "2019-07-19T07:52:32Z")

</div>

I am planning to use cisco module in filebeat to ship syslog messages from cisco ASA Firewall to Elasticsearch through Logstash. So far, I installed Filebeat on a windows 7 machine and enabled cisco module. I enabled se…

---

## [Adding a field while parsing for kibana](https://discuss.elastic.co/t/adding-a-field-while-parsing-for-kibana/190787)

<div class="topic-metadata">

**Author:** [@Soumitra\_Ghosh](https://discuss.elastic.co/u/Soumitra_Ghosh)\
**Replies:** 1\
**Last updated:** [July 19, 2019, 7:42am UTC](https://discuss.elastic.co/t/adding-a-field-while-parsing-for-kibana/190787 "2019-07-19T07:42:49Z")

</div>

Here is something i do to get java exceptions in fluentd is this possible in filebeat? thanks \<filter raw.kubernetes.\*\*\> @type record\_transformer enable\_ruby exception ${record\["log"\]\[/(java.\[a-zA-Z\]+.\[a-zA-Z\]+Exc…

---

## [Kafka byte rate](https://discuss.elastic.co/t/kafka-byte-rate/190753)

<div class="topic-metadata">

**Author:** [@amitavmohanty01](https://discuss.elastic.co/u/amitavmohanty01)\
**Replies:** 1\
**Last updated:** [July 19, 2019, 7:35am UTC](https://discuss.elastic.co/t/kafka-byte-rate/190753 "2019-07-19T07:35:01Z")

</div>

Kafka provides input and output byte rate. Does metricbeat capture that?

---

## [Getting error while making custom beat - panic: failed determine libbeat dir location](https://discuss.elastic.co/t/getting-error-while-making-custom-beat-panic-failed-determine-libbeat-dir-location/191327)

<div class="topic-metadata">

**Author:** [@tameshwar.sahu](https://discuss.elastic.co/u/tameshwar.sahu)\
**Replies:** 0\
**Last updated:** [July 19, 2019, 6:48am UTC](https://discuss.elastic.co/t/getting-error-while-making-custom-beat-panic-failed-determine-libbeat-dir-location/191327 "2019-07-19T06:48:42Z")

</div>

Hi, Getting error while ruining 'make setup' command. panic: failed determine libbeat dir location: failed to find github.com/elastic/beats/dev-tools/mage in the project's vendor Please suggest what could be wrong. T…

---

## [How to process JBoss access log with FileBeat](https://discuss.elastic.co/t/how-to-process-jboss-access-log-with-filebeat/191234)

<div class="topic-metadata">

**Author:** [@Arioule](https://discuss.elastic.co/u/Arioule)\
**Replies:** 1\
**Last updated:** [July 19, 2019, 5:51am UTC](https://discuss.elastic.co/t/how-to-process-jboss-access-log-with-filebeat/191234 "2019-07-19T05:51:09Z")

</div>

I install FileBeat on my local computer to send data to my Kibana application hosted in AWS. However there is no Out Of Box JBOSS Access Log module for FileBeat. Is there any way for FileBeat to process JBoss Access lo…

---

## [Jolokia module not displaying threadcount in kibana](https://discuss.elastic.co/t/jolokia-module-not-displaying-threadcount-in-kibana/191041)

<div class="topic-metadata">

**Author:** [@cjb312](https://discuss.elastic.co/u/cjb312)\
**Replies:** 15\
**Last updated:** [July 19, 2019, 5:42am UTC](https://discuss.elastic.co/t/jolokia-module-not-displaying-threadcount-in-kibana/191041 "2019-07-19T05:42:35Z")

</div>

Like the title says I cannot see the amount of threads in kibana here is my current jolokia.yml file: # Module: jolokia # Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.1/metricbeat-module-jolokia.html - modu…

---

## [Parse error for cisco asa logs in filebeat module](https://discuss.elastic.co/t/parse-error-for-cisco-asa-logs-in-filebeat-module/191264)

<div class="topic-metadata">

**Author:** [@alexb145](https://discuss.elastic.co/u/alexb145)\
**Replies:** 1\
**Last updated:** [July 18, 2019, 8:02pm UTC](https://discuss.elastic.co/t/parse-error-for-cisco-asa-logs-in-filebeat-module/191264 "2019-07-18T20:02:27Z")

</div>

I'm trying to send and parse data using the filebeat cisco module. We're getting the data to filebeat via syslog on an UDP port/ The data gets to elasticsearch, but the message field isn't parsed into the cisco module da…

---

## [OSQuery field types](https://discuss.elastic.co/t/osquery-field-types/190875)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 5\
**Last updated:** [July 18, 2019, 6:09pm UTC](https://discuss.elastic.co/t/osquery-field-types/190875 "2019-07-18T18:09:31Z")

</div>

I just realized all osquery fields get set to type 'string'. In osquery fields have appropriate types (for example for a temperature sensor it will have a string name and a double celsius temperature) But the json osqu…

---

## [Elastic heartbeat is not able to send the status to elastic servers](https://discuss.elastic.co/t/elastic-heartbeat-is-not-able-to-send-the-status-to-elastic-servers/191016)

<div class="topic-metadata">

**Author:** [@Nithani25](https://discuss.elastic.co/u/Nithani25)\
**Replies:** 1\
**Last updated:** [July 18, 2019, 5:54pm UTC](https://discuss.elastic.co/t/elastic-heartbeat-is-not-able-to-send-the-status-to-elastic-servers/191016 "2019-07-18T17:54:48Z")

</div>

HI Team, my heartbeat collectors have stopped working in production environment since last few days, i am unable to understand what is the problem here. Here is the log output: 2019-07-16T03:53:43.712-0700 INFO …

---

## [Filebeat 7.2.0 Container Input: Error Reading Docker Output](https://discuss.elastic.co/t/filebeat-7-2-0-container-input-error-reading-docker-output/191063)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [July 18, 2019, 5:33pm UTC](https://discuss.elastic.co/t/filebeat-7-2-0-container-input-error-reading-docker-output/191063 "2019-07-18T17:33:57Z")

</div>

I have installed Filebeat 7.2.0 on a host in our Docker cluster to test the container input. This is the container input segment of my filebeat.yml for that host: filebeat: inputs: - type: container paths: …

---

## [Enrich Beats data with Windows registry values](https://discuss.elastic.co/t/enrich-beats-data-with-windows-registry-values/191259)

<div class="topic-metadata">

**Author:** [@Micah\_Hunsberger](https://discuss.elastic.co/u/Micah_Hunsberger)\
**Replies:** 0\
**Last updated:** [July 18, 2019, 5:25pm UTC](https://discuss.elastic.co/t/enrich-beats-data-with-windows-registry-values/191259 "2019-07-18T17:25:08Z")

</div>

Is there any way to have metricbeat or some other beat add a registry entry value to their fields and/or tags? I know you can reference environment variables using ${VAR}, and so you could add an environment variable as …

---

## [Metricbeat return all filesystems](https://discuss.elastic.co/t/metricbeat-return-all-filesystems/187883)

<div class="topic-metadata">

**Author:** [@james.haynie](https://discuss.elastic.co/u/james.haynie)\
**Replies:** 2\
**Last updated:** [July 18, 2019, 3:25pm UTC](https://discuss.elastic.co/t/metricbeat-return-all-filesystems/187883 "2019-07-18T15:25:27Z")

</div>

For some reason, metricbeat 7.1 refuses to send all devices to elasticsearch 7.1. I have disabled the filtering, below is my /elasticsearch/modules.d/system.yml file: # Module: system # Docs: https://www.elastic.co/gui…

---

## [One line JSON parsing into separate events/logs](https://discuss.elastic.co/t/one-line-json-parsing-into-separate-events-logs/191074)

<div class="topic-metadata">

**Author:** [@probson](https://discuss.elastic.co/u/probson)\
**Replies:** 1\
**Last updated:** [July 18, 2019, 3:14pm UTC](https://discuss.elastic.co/t/one-line-json-parsing-into-separate-events-logs/191074 "2019-07-18T15:14:46Z")

</div>

Hi, I am trying to ingest some logs via filebeats, the logs get to logstash but only one event is created, the logs are all on one line as per the example below, I have trimmed it down. {"requests": \[{"originId": 28301…

---

## [Metricbeat as non root user?](https://discuss.elastic.co/t/metricbeat-as-non-root-user/191184)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [July 18, 2019, 12:33pm UTC](https://discuss.elastic.co/t/metricbeat-as-non-root-user/191184 "2019-07-18T12:33:03Z")

</div>

Hi, is it possible to run metricbeat as non root user? What am I loosing if running as non-root? Thanks, Andreas

---

## [Using custom fields in ILM setup index names](https://discuss.elastic.co/t/using-custom-fields-in-ilm-setup-index-names/191174)

<div class="topic-metadata">

**Author:** [@JamesNotJamez](https://discuss.elastic.co/u/JamesNotJamez)\
**Replies:** 0\
**Last updated:** [July 18, 2019, 10:14am UTC](https://discuss.elastic.co/t/using-custom-fields-in-ilm-setup-index-names/191174 "2019-07-18T10:14:14Z")

</div>

Hi, I'm creating a custom field, service.name, based on the name of the log file and determined by a processor in the filebeat inputs filebeat.inputs: - type: log enabled: true paths: - /local/0/seal\_logs/\*.jso…

---

## [Use Heartbeat to read process status from a file](https://discuss.elastic.co/t/use-heartbeat-to-read-process-status-from-a-file/191139)

<div class="topic-metadata">

**Author:** [@abhishek13](https://discuss.elastic.co/u/abhishek13)\
**Replies:** 1\
**Last updated:** [July 18, 2019, 8:50am UTC](https://discuss.elastic.co/t/use-heartbeat-to-read-process-status-from-a-file/191139 "2019-07-18T08:50:50Z")

</div>

I have a process that writes it status in a file, single line stating "RUNNING/STOPPED". I can do a curl file:///mylocation/status.txt and in output i get RUNNING if process is running and stopped otherwise. Is there a…

---

## [Index name confusion with ILM enabled](https://discuss.elastic.co/t/index-name-confusion-with-ilm-enabled/190867)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 2\
**Last updated:** [July 18, 2019, 1:12am UTC](https://discuss.elastic.co/t/index-name-confusion-with-ilm-enabled/190867 "2019-07-18T01:12:45Z")

</div>

Previously I used daily indexes defined like: output.elasticsearch: index: "filebeat-%{\[agent.version\]}-%{+yyyy.MM}" Now I'm trying to use ILM so my daily indexes are managed more rationally. I have this config now: s…

---

## [Auditbeat "reassembler\_seq\_gaps":8589934603](https://discuss.elastic.co/t/auditbeat-reassembler-seq-gaps-8589934603/190970)

<div class="topic-metadata">

**Author:** [@vaclav](https://discuss.elastic.co/u/vaclav)\
**Replies:** 1\
**Last updated:** [July 17, 2019, 11:02pm UTC](https://discuss.elastic.co/t/auditbeat-reassembler-seq-gaps-8589934603/190970 "2019-07-17T23:02:44Z")

</div>

Hello, I have in auditbeat info messages very high value for reassembler\_seq\_gaps here is one example: auditbeat\[560\]: 2019-07-17T09:30:18.707Z INFO \[monitoring\] log/log.go:145 Non-zero metrics in the last 30s {"monit…

---

## [Auditbeat starts losing events couple minutes after restart](https://discuss.elastic.co/t/auditbeat-starts-losing-events-couple-minutes-after-restart/191032)

<div class="topic-metadata">

**Author:** [@nickbabkin](https://discuss.elastic.co/u/nickbabkin)\
**Replies:** 0\
**Last updated:** [July 17, 2019, 2:40pm UTC](https://discuss.elastic.co/t/auditbeat-starts-losing-events-couple-minutes-after-restart/191032 "2019-07-17T14:40:51Z")

</div>

Hi everyone! We have an incredibly high amount of events lost shown as "auditbeat show auditd-status" command output on some hosts. Example: auditbeat show auditd-status enabled 1 failure 0 pid 1893 rate\_limit 0 b…

---

## [Problem connecting packetbeat to logstash](https://discuss.elastic.co/t/problem-connecting-packetbeat-to-logstash/188426)

<div class="topic-metadata">

**Author:** [@El\_Mahdi\_El\_Korri](https://discuss.elastic.co/u/El_Mahdi_El_Korri)\
**Replies:** 1\
**Last updated:** [July 17, 2019, 1:14pm UTC](https://discuss.elastic.co/t/problem-connecting-packetbeat-to-logstash/188426 "2019-07-17T13:14:59Z")

</div>

Hi Everyone, My packetbeat agent won't ship packets to logstash. Could someone give me hint to solve this issue ? Packetbeat log : 2019-07-02T02:18:24.403Z INFO \[monitoring\] log/log.go:144 Non-zero metri…

---

## [Filebeat as Docker](https://discuss.elastic.co/t/filebeat-as-docker/190627)

<div class="topic-metadata">

**Author:** [@monica2](https://discuss.elastic.co/u/monica2)\
**Replies:** 2\
**Last updated:** [July 17, 2019, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-as-docker/190627 "2019-07-17T13:12:37Z")

</div>

I am using filebeat in a docker. I am getting logs sending to kibana working good. I want to my Docker Host Ip(EC2-instance) address rather than my container ip. I used fileds called beat.name. beat.ip adrress seems my g…

---

## [Cannot index event publisher.Event ... Root mapping definition has unsupported parameters: \[\_all : {norms=false}\]"}}](https://discuss.elastic.co/t/cannot-index-event-publisher-event-root-mapping-definition-has-unsupported-parameters-all-norms-false/190921)

<div class="topic-metadata">

**Author:** [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Replies:** 1\
**Last updated:** [July 17, 2019, 12:00pm UTC](https://discuss.elastic.co/t/cannot-index-event-publisher-event-root-mapping-definition-has-unsupported-parameters-all-norms-false/190921 "2019-07-17T12:00:19Z")

</div>

Hi, I try to use packetbeat, but receive the following error and no indices are created. What is the problem there? 2019-07-17T10:27:51.246+0200 WARN elasticsearch/client.go:527 Cannot index event publisher.…

---

## [Minimum user rights for pushing from remote user](https://discuss.elastic.co/t/minimum-user-rights-for-pushing-from-remote-user/190994)

<div class="topic-metadata">

**Author:** [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Replies:** 0\
**Last updated:** [July 17, 2019, 1:08pm UTC](https://discuss.elastic.co/t/minimum-user-rights-for-pushing-from-remote-user/190994 "2019-07-17T13:08:01Z")

</div>

Hi, What are the minimum rights needed for letting users add their own metricbeat instance connected to a central elasticsearch cluster? For instance: user X installs metricbeat as a service with a given username and…

---

## [Error conecting to kibana](https://discuss.elastic.co/t/error-conecting-to-kibana/189521)

<div class="topic-metadata">

**Author:** [@sarahmech](https://discuss.elastic.co/u/sarahmech)\
**Replies:** 6\
**Last updated:** [July 17, 2019, 1:02pm UTC](https://discuss.elastic.co/t/error-conecting-to-kibana/189521 "2019-07-17T13:02:46Z")

</div>

Hi ! i can't cnnecting to kibana, can you help me thank you my winlogbeat.yml winlogbeat.event\_logs: name: Application name: Security name: System output.elasticsearch: hosts: - localhost:9200 output…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=334)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=336)
