# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=336

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 337

---

## [Simply push json -\> elasticsearch](https://discuss.elastic.co/t/simply-push-json-elasticsearch/190981)

<div class="topic-metadata">

**Author:** [@AaronNBrock](https://discuss.elastic.co/u/AaronNBrock)\
**Replies:** 1\
**Last updated:** [July 17, 2019, 12:33pm UTC](https://discuss.elastic.co/t/simply-push-json-elasticsearch/190981 "2019-07-17T12:33:48Z")

</div>

I have a simple application that logs to a file in single complete json strings. Example /tmp/my.log { "user": "bob", "event":"speak", "message":"Hello, world!" } { "user": "bill", "event":"sleep", "duration":8 } I'd…

---

## [Filebeat have harvested logs and got a connection to logstash, yet they don't show up on kibana](https://discuss.elastic.co/t/filebeat-have-harvested-logs-and-got-a-connection-to-logstash-yet-they-dont-show-up-on-kibana/189805)

<div class="topic-metadata">

**Author:** [@s133996](https://discuss.elastic.co/u/s133996)\
**Replies:** 2\
**Last updated:** [July 17, 2019, 12:32pm UTC](https://discuss.elastic.co/t/filebeat-have-harvested-logs-and-got-a-connection-to-logstash-yet-they-dont-show-up-on-kibana/189805 "2019-07-17T12:32:04Z")

</div>

Hello, as can be seen on my error below I've established a connection and have harvested a log file (the log file isn't empty) Yet when I'm looking at kibana I cannot see the log from filebeat (the name serviceportal…

---

## [Filebeat for both system|service logs and application logs](https://discuss.elastic.co/t/filebeat-for-both-system-service-logs-and-application-logs/189742)

<div class="topic-metadata">

**Author:** [@coudenysj](https://discuss.elastic.co/u/coudenysj)\
**Replies:** 7\
**Last updated:** [July 17, 2019, 12:00pm UTC](https://discuss.elastic.co/t/filebeat-for-both-system-service-logs-and-application-logs/189742 "2019-07-17T12:00:13Z")

</div>

Hi, I'm having trouble to pick a solution to use filebeat for both the default system|service log files and application log files. I'm logging my application logs in json, so not much processing must be done, but I wou…

---

## [Filebeat configuration for multi line option (regex required)](https://discuss.elastic.co/t/filebeat-configuration-for-multi-line-option-regex-required/189798)

<div class="topic-metadata">

**Author:** [@amr.abdelfattah](https://discuss.elastic.co/u/amr.abdelfattah)\
**Replies:** 7\
**Last updated:** [July 17, 2019, 11:32am UTC](https://discuss.elastic.co/t/filebeat-configuration-for-multi-line-option-regex-required/189798 "2019-07-17T11:32:02Z")

</div>

Kindly i need your urgent advise to configure filebeat to process below log: 2019-07-02 16:00:00.037 \[SUBSCRIBER\_PROFILE-1157917705-d73442b7-8d07-4aee-a850-09aa51ff37e2\] Inquiry Item \[com.etisalat.oms.inquiry.actions.Vo…

---

## [How to get the new rotated log file name for source field in Kibana?](https://discuss.elastic.co/t/how-to-get-the-new-rotated-log-file-name-for-source-field-in-kibana/190893)

<div class="topic-metadata">

**Author:** [@ashwin\_s](https://discuss.elastic.co/u/ashwin_s)\
**Replies:** 1\
**Last updated:** [July 17, 2019, 11:27am UTC](https://discuss.elastic.co/t/how-to-get-the-new-rotated-log-file-name-for-source-field-in-kibana/190893 "2019-07-17T11:27:39Z")

</div>

We have Nlogs getting dumped to a folder, which is being monitored by Filebeat. And logs are getting rotated in two cases : 1. If the log file has reached 25MB or time has crossed an hour. In Kibana, we are using source …

---

## [Filebeat not scanning after input of ignore\_older](https://discuss.elastic.co/t/filebeat-not-scanning-after-input-of-ignore-older/190905)

<div class="topic-metadata">

**Author:** [@Kwiskas](https://discuss.elastic.co/u/Kwiskas)\
**Replies:** 1\
**Last updated:** [July 17, 2019, 11:21am UTC](https://discuss.elastic.co/t/filebeat-not-scanning-after-input-of-ignore-older/190905 "2019-07-17T11:21:25Z")

</div>

Hi there On my company we have a server that has a huge amount of logs because of a lot of scheduled jobs and a few memory. So when filebeat turns up to collect em it takes all RAM to do so. So the idea i had is to sca…

---

## [Exported fields for log content which module exports them?](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717)

<div class="topic-metadata">

**Author:** [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Replies:** 4\
**Last updated:** [July 17, 2019, 9:07am UTC](https://discuss.elastic.co/t/exported-fields-for-log-content-which-module-exports-them/190717 "2019-07-17T09:07:20Z")

</div>

Hello, i am actually using Filebeat in version 7.2.1 In the description for the exported fields are fields for log content described: https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-log.html#expo…

---

## [Can't load filebeat Index Template in Elasticsearch](https://discuss.elastic.co/t/cant-load-filebeat-index-template-in-elasticsearch/190836)

<div class="topic-metadata">

**Author:** [@Saber.Tala](https://discuss.elastic.co/u/Saber.Tala)\
**Replies:** 1\
**Last updated:** [July 17, 2019, 9:01am UTC](https://discuss.elastic.co/t/cant-load-filebeat-index-template-in-elasticsearch/190836 "2019-07-17T09:01:53Z")

</div>

Hello, Using Filebeat version 7.2.0, Logstash version 7.1.1 and ElasticSearch version 7.1.1, when I try to load Filebeat Index Template in Elasticsearch, I get the following error: \[root@VM1 ~\]# curl -XPUT 'http://loc…

---

## [Can filebeats to read lxc container logs?](https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625)

<div class="topic-metadata">

**Author:** [@yuecong](https://discuss.elastic.co/u/yuecong)\
**Replies:** 3\
**Last updated:** [July 17, 2019, 5:48am UTC](https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625 "2019-07-17T05:48:23Z")

</div>

from the host, I can read the lxc contianers logs using root like /var/lib/lxc//test//logs/\*.log but when I put the above path into filebeats as one path for log type of inputs , it can not find it.( A harvester on the…

---

## [Errors in Kibana with Metricbeat 6.7.1+](https://discuss.elastic.co/t/errors-in-kibana-with-metricbeat-6-7-1/186301)

<div class="topic-metadata">

**Author:** [@alexz00](https://discuss.elastic.co/u/alexz00)\
**Replies:** 8\
**Last updated:** [July 16, 2019, 9:06pm UTC](https://discuss.elastic.co/t/errors-in-kibana-with-metricbeat-6-7-1/186301 "2019-07-16T21:06:40Z")

</div>

Running Kibana (I tried different versions, from 6.5.x to 7.1.1) with Metricbeat 6.7.1 and 7.1.1 I see several errors in Kibana: Unable to see metricbeat-\* index pattern in Kibana: Request Timeout error Unable to open …

---

## [Keystore wrong location in version 7.2.0](https://discuss.elastic.co/t/keystore-wrong-location-in-version-7-2-0/190603)

<div class="topic-metadata">

**Author:** [@zpraxis](https://discuss.elastic.co/u/zpraxis)\
**Replies:** 2\
**Last updated:** [July 16, 2019, 4:40pm UTC](https://discuss.elastic.co/t/keystore-wrong-location-in-version-7-2-0/190603 "2019-07-16T16:40:56Z")

</div>

Documentation says: Filebeat creates the keystore in the directory defined by the path.config configuration setting. However, keystore is created in /path\_where\_tar\_was\_extracted/filebeat-7.2.0-linux-x86\_64/data/ . …

---

## [Filebeat adds a host.name field to JSON messages even when already set](https://discuss.elastic.co/t/filebeat-adds-a-host-name-field-to-json-messages-even-when-already-set/190780)

<div class="topic-metadata">

**Author:** [@fgabolde](https://discuss.elastic.co/u/fgabolde)\
**Replies:** 0\
**Last updated:** [July 16, 2019, 3:43pm UTC](https://discuss.elastic.co/t/filebeat-adds-a-host-name-field-to-json-messages-even-when-already-set/190780 "2019-07-16T15:43:30Z")

</div>

I'm using an UDP input to gather logs from Java applications with Filebeat. The Java apps send JSON objects over UDP through https://github.com/logstash/logstash-logback-encoder. I had some issues since it seems that th…

---

## [Performance of hearbeat](https://discuss.elastic.co/t/performance-of-hearbeat/190215)

<div class="topic-metadata">

**Author:** [@ciment](https://discuss.elastic.co/u/ciment)\
**Replies:** 1\
**Last updated:** [July 16, 2019, 3:38pm UTC](https://discuss.elastic.co/t/performance-of-hearbeat/190215 "2019-07-16T15:38:54Z")

</div>

Hello, How many hearbeat instances should I have running to monitoring 40-60 services? All services running in one network. How to setup hearbeats in failover mode? Does exist something? Thanks.

---

## [Monitor array of objects in JSON response](https://discuss.elastic.co/t/monitor-array-of-objects-in-json-response/190145)

<div class="topic-metadata">

**Author:** [@wu3rstle](https://discuss.elastic.co/u/wu3rstle)\
**Replies:** 2\
**Last updated:** [July 16, 2019, 3:37pm UTC](https://discuss.elastic.co/t/monitor-array-of-objects-in-json-response/190145 "2019-07-16T15:37:13Z")

</div>

I've tried monitoring a service with nested JSON using Heartbeat 7.2.0. Several variants for the check.response.json are not working. I've tried the following keys for the array check: data\[0\].state: data\[0\]\[state\]: d…

---

## [Format of system.uptime.duration.ms in Metricbeat 7.2 (WIndows)](https://discuss.elastic.co/t/format-of-system-uptime-duration-ms-in-metricbeat-7-2-windows/187614)

<div class="topic-metadata">

**Author:** [@kagoadvs](https://discuss.elastic.co/u/kagoadvs)\
**Replies:** 3\
**Last updated:** [July 16, 2019, 2:52pm UTC](https://discuss.elastic.co/t/format-of-system-uptime-duration-ms-in-metricbeat-7-2-windows/187614 "2019-07-16T14:52:03Z")

</div>

Does anyone know the format of system.uptime.duration.ms send by Metricbeat 7.2 (Windows). The number jumped a lot when I upgraded to Metricbeat 7.2 on my Windows Servers (2016).

---

## [Filebeat package for AIX 7.1 and AIX 7.2 b versions](https://discuss.elastic.co/t/filebeat-package-for-aix-7-1-and-aix-7-2-b-versions/190577)

<div class="topic-metadata">

**Author:** [@ridhima](https://discuss.elastic.co/u/ridhima)\
**Replies:** 1\
**Last updated:** [July 16, 2019, 2:11pm UTC](https://discuss.elastic.co/t/filebeat-package-for-aix-7-1-and-aix-7-2-b-versions/190577 "2019-07-16T14:11:51Z")

</div>

We have filebeat package builded "filebeat-5.5.1-1.aix6.1.ppc.rpm" and it is working on AIX 6.1 . Can we use the same package on AIX 7.1 and AIX 7.2 versions ? if not what changes we have to do in filebeat-…

---

## [Automaticaly set tags](https://discuss.elastic.co/t/automaticaly-set-tags/190751)

<div class="topic-metadata">

**Author:** [@nitzan.karni](https://discuss.elastic.co/u/nitzan.karni)\
**Replies:** 0\
**Last updated:** [July 16, 2019, 2:05pm UTC](https://discuss.elastic.co/t/automaticaly-set-tags/190751 "2019-07-16T14:05:27Z")

</div>

Hi, Is there a way to set automatically tags to beats in central management? case scenario: new beat is enrolled to the central management -\> tags A B and C are set to the specific beat by beat type, name, os and more…

---

## [Auditbeat 7.2 compatibility with an older kibana version](https://discuss.elastic.co/t/auditbeat-7-2-compatibility-with-an-older-kibana-version/190735)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 2\
**Last updated:** [July 16, 2019, 2:04pm UTC](https://discuss.elastic.co/t/auditbeat-7-2-compatibility-with-an-older-kibana-version/190735 "2019-07-16T14:04:46Z")

</div>

Dear Elastic Team, Is it possible to use auditbeat 7.2 with Kibana 6.71? Based on the matrix it's not possible can we confirm? https://www.elastic.co/support/matrix#matrix\_compatibility

---

## [Get Beat config status](https://discuss.elastic.co/t/get-beat-config-status/190748)

<div class="topic-metadata">

**Author:** [@nitzan.karni](https://discuss.elastic.co/u/nitzan.karni)\
**Replies:** 0\
**Last updated:** [July 16, 2019, 1:56pm UTC](https://discuss.elastic.co/t/get-beat-config-status/190748 "2019-07-16T13:56:44Z")

</div>

Hi, I want to retrieve the beats that are not running / not communicating / not configuered well. Basically get all the beats that are not Running in the config status in central management page. I tried to do this by…

---

## [Add\_kubernetes\_metadata does not provide K8S namespace or pod uid](https://discuss.elastic.co/t/add-kubernetes-metadata-does-not-provide-k8s-namespace-or-pod-uid/189360)

<div class="topic-metadata">

**Author:** [@aleksei.saiko](https://discuss.elastic.co/u/aleksei.saiko)\
**Replies:** 2\
**Last updated:** [July 16, 2019, 11:41am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-does-not-provide-k8s-namespace-or-pod-uid/189360 "2019-07-16T11:41:28Z")

</div>

Hi there! I upgraded from ELK 6.6.2 to 7.2.0. Before the upgrade, everything worked fine, after the upgrade, I can't receive k8s logs anymore. I configured and updated everything according to documentation. The yaml …

---

## [Automatically delete old indices](https://discuss.elastic.co/t/automatically-delete-old-indices/190276)

<div class="topic-metadata">

**Author:** [@ngg971](https://discuss.elastic.co/u/ngg971)\
**Replies:** 8\
**Last updated:** [July 16, 2019, 10:33am UTC](https://discuss.elastic.co/t/automatically-delete-old-indices/190276 "2019-07-16T10:33:56Z")

</div>

Hi, I know this has been asked a lot, but I wanted to check if there were any updates since most threads on this date back to 2017. I have integrated Filebeat into my Kubernetes cluster and it is ingesting around 3GB a …

---

## [\[metricbeat\]\[filebeat\]\[7.2\] host.name wrong value. Bug or wrong set?](https://discuss.elastic.co/t/metricbeat-filebeat-7-2-host-name-wrong-value-bug-or-wrong-set/190007)

<div class="topic-metadata">

**Author:** [@ea1987](https://discuss.elastic.co/u/ea1987)\
**Replies:** 2\
**Last updated:** [July 16, 2019, 8:52am UTC](https://discuss.elastic.co/t/metricbeat-filebeat-7-2-host-name-wrong-value-bug-or-wrong-set/190007 "2019-07-16T08:52:41Z")

</div>

Hi guys, I'm currently working on filebeat (system module enabled) and metricbeat, 7.2v. I noticed that field host.name which, as Elastic ecs documentation reports, refers to the name of the host, has the same value of…

---

## [Filebeat 7.2 shipping to elastic cloud .yml - Error Decoding Json logs](https://discuss.elastic.co/t/filebeat-7-2-shipping-to-elastic-cloud-yml-error-decoding-json-logs/189533)

<div class="topic-metadata">

**Author:** [@fadil030889](https://discuss.elastic.co/u/fadil030889)\
**Replies:** 4\
**Last updated:** [July 16, 2019, 8:10am UTC](https://discuss.elastic.co/t/filebeat-7-2-shipping-to-elastic-cloud-yml-error-decoding-json-logs/189533 "2019-07-16T08:10:44Z")

</div>

Hi, we have moved to elastic from our on prem 6.2 version elk cluster. We are currently having some problems into decoding json docker logs and renaming indices. My filebeat.yml test file is as follows: filebeat.inputs: …

---

## [Unable to find any unassigned shards](https://discuss.elastic.co/t/unable-to-find-any-unassigned-shards/190294)

<div class="topic-metadata">

**Author:** [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Replies:** 6\
**Last updated:** [July 15, 2019, 6:48pm UTC](https://discuss.elastic.co/t/unable-to-find-any-unassigned-shards/190294 "2019-07-15T18:48:33Z")

</div>

Hi, I am getting below error while accessing the cluster allocation through dev console with below command GET \_cluster/allocation/explain?pretty I tried many forum solutions but still i am getting the same. Elk versi…

---

## [Metricbeat Error in Docker Module](https://discuss.elastic.co/t/metricbeat-error-in-docker-module/190564)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [July 15, 2019, 2:57pm UTC](https://discuss.elastic.co/t/metricbeat-error-in-docker-module/190564 "2019-07-15T14:57:56Z")

</div>

We have installed Metricbeat 7.1.1 on the servers in our Docker cluster and enabled the docker module with the following configuration: - module: docker metricsets: - container - cpu - diskio - event …

---

## [Search Filter not working](https://discuss.elastic.co/t/search-filter-not-working/190556)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 0\
**Last updated:** [July 15, 2019, 2:06pm UTC](https://discuss.elastic.co/t/search-filter-not-working/190556 "2019-07-15T14:06:09Z")

</div>

Dear Elastic Team, Want only to show all docker.container.status with status --\> unhealthy but it seems like not working. I've tried with the knowledge(basic) i have and didn't succeed. can you please help me out with …

---

## [Metricbeats failed to connect Elasticsearch with X-Pack enabled](https://discuss.elastic.co/t/metricbeats-failed-to-connect-elasticsearch-with-x-pack-enabled/190498)

<div class="topic-metadata">

**Author:** [@alza](https://discuss.elastic.co/u/alza)\
**Replies:** 8\
**Last updated:** [July 15, 2019, 1:12pm UTC](https://discuss.elastic.co/t/metricbeats-failed-to-connect-elasticsearch-with-x-pack-enabled/190498 "2019-07-15T13:12:44Z")

</div>

I setup an Elasticsearch 7.2.0 with the following elasticsearch.yml config file, , using docker, cluster.name: "docker-cluster" network.host: 0.0.0.0 discovery.type: single-node xpack.license.self\_generated.type: basic …

---

## [Journalbeat experimental?](https://discuss.elastic.co/t/journalbeat-experimental/190397)

<div class="topic-metadata">

**Author:** [@i333](https://discuss.elastic.co/u/i333)\
**Replies:** 1\
**Last updated:** [July 15, 2019, 12:13pm UTC](https://discuss.elastic.co/t/journalbeat-experimental/190397 "2019-07-15T12:13:38Z")

</div>

What does it mean that journalbeat is experimental? Should it not be used in production? Is there a roadmap or timeline of what needs to happen before it is no longer experimental, just like all the other types of beats…

---

## [Invalid character 'A' looking for beginning of value](https://discuss.elastic.co/t/invalid-character-a-looking-for-beginning-of-value/190446)

<div class="topic-metadata">

**Author:** [@jasony](https://discuss.elastic.co/u/jasony)\
**Replies:** 2\
**Last updated:** [July 15, 2019, 11:03am UTC](https://discuss.elastic.co/t/invalid-character-a-looking-for-beginning-of-value/190446 "2019-07-15T11:03:14Z")

</div>

hello, i am trying to replicate below 'curl' query with metricbeat http module. as you see below, 127.0.0.1:8088 opens and responds well as below. $ curl -XGET http://127.0.0.1:8088 Active connections: 5 server accepts…

---

## [Multiple beats to one logstash](https://discuss.elastic.co/t/multiple-beats-to-one-logstash/189969)

<div class="topic-metadata">

**Author:** [@markov](https://discuss.elastic.co/u/markov)\
**Replies:** 3\
**Last updated:** [July 15, 2019, 9:53am UTC](https://discuss.elastic.co/t/multiple-beats-to-one-logstash/189969 "2019-07-15T09:53:06Z")

</div>

Hi guys, i have one filebeat instance shipping logs to logstash and i after added another filebeat instance in another machine, they won't show up in kibana, the log file shows that the connection is established and it …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=335)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=337)
