# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=338

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 339

---

## [Filebeat Error while initializing input](https://discuss.elastic.co/t/filebeat-error-while-initializing-input/188791)

<div class="topic-metadata">

**Author:** [@bizomb](https://discuss.elastic.co/u/bizomb)\
**Replies:** 2\
**Last updated:** [July 10, 2019, 4:23pm UTC](https://discuss.elastic.co/t/filebeat-error-while-initializing-input/188791 "2019-07-10T16:23:43Z")

</div>

I am trying to get data to send logs to kibana and when try to run filebeat -e -c filebeat.yml -d "publish" or filebeat -e I get error Exiting: Error interpreting the template of the input: template: text:3:22: executing…

---

## [Filebeat Processing /var/log/secure](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758)

<div class="topic-metadata">

**Author:** [@aviator](https://discuss.elastic.co/u/aviator)\
**Replies:** 5\
**Last updated:** [July 10, 2019, 3:33pm UTC](https://discuss.elastic.co/t/filebeat-processing-var-log-secure/189758 "2019-07-10T15:33:58Z")

</div>

Hi ES 7.0.2 Am trying to view the Filebeat System New user and groups dashboard but the results are sporadic at best. Filebeat 7.2.0 installed locally on ES instance and on remote machine to confirm. Configured to har…

---

## [Syslog messages not displayed for kibana interface](https://discuss.elastic.co/t/syslog-messages-not-displayed-for-kibana-interface/189813)

<div class="topic-metadata">

**Author:** [@Mohamed\_Afzal](https://discuss.elastic.co/u/Mohamed_Afzal)\
**Replies:** 0\
**Last updated:** [July 10, 2019, 3:28pm UTC](https://discuss.elastic.co/t/syslog-messages-not-displayed-for-kibana-interface/189813 "2019-07-10T15:28:44Z")

</div>

Hi, I have setup an ELK and run winlogbeat and filebeat. Winlogbeat logs displayed in the kibana interface but the syslog from the devices not showing up. when i do a tcpdump port 5544(the port i have setup to listen fo…

---

## [Add\_cloud\_metadata wrong provider](https://discuss.elastic.co/t/add-cloud-metadata-wrong-provider/189780)

<div class="topic-metadata">

**Author:** [@dannyverbeek](https://discuss.elastic.co/u/dannyverbeek)\
**Replies:** 0\
**Last updated:** [July 10, 2019, 1:40pm UTC](https://discuss.elastic.co/t/add-cloud-metadata-wrong-provider/189780 "2019-07-10T13:40:39Z")

</div>

I all, we have seen some issues with beats. Both filebeat and metricbeat. When adding add\_cloud\_metadata is sometimes add openstack as provider, but we run on AWS. anyone have this issue? add\_cloud\_metadata.go:351 add…

---

## [Get Host Ip displayed on my kibana](https://discuss.elastic.co/t/get-host-ip-displayed-on-my-kibana/189794)

<div class="topic-metadata">

**Author:** [@monica2](https://discuss.elastic.co/u/monica2)\
**Replies:** 0\
**Last updated:** [July 10, 2019, 2:24pm UTC](https://discuss.elastic.co/t/get-host-ip-displayed-on-my-kibana/189794 "2019-07-10T14:24:45Z")

</div>

I am using fiilebeat version 7.1.1. I am trying to get Host ip address displayed on kibana UI. I tried many ways but seems not working. I used beat.ip\_address and fields.beat.hostname and used host metadata but seems not…

---

## [What happens when the ouput of Auditbeat is down](https://discuss.elastic.co/t/what-happens-when-the-ouput-of-auditbeat-is-down/189568)

<div class="topic-metadata">

**Author:** [@vishnug](https://discuss.elastic.co/u/vishnug)\
**Replies:** 2\
**Last updated:** [July 10, 2019, 2:16pm UTC](https://discuss.elastic.co/t/what-happens-when-the-ouput-of-auditbeat-is-down/189568 "2019-07-10T14:16:02Z")

</div>

I am using the following pipeline to forward data Auditbeat ---\> logstash ---\> ES Suppose if the logstash machine goes down, I want to know how the Auditbeat handles the situation. I would like to know the specifics l…

---

## [Unusually high Metricbeat memory usage](https://discuss.elastic.co/t/unusually-high-metricbeat-memory-usage/184621)

<div class="topic-metadata">

**Author:** [@apang](https://discuss.elastic.co/u/apang)\
**Replies:** 13\
**Last updated:** [July 10, 2019, 1:41pm UTC](https://discuss.elastic.co/t/unusually-high-metricbeat-memory-usage/184621 "2019-07-10T13:41:39Z")

</div>

I have metricbeat installed on a Windows Server 2016 Datacenter server that also has an Elasticsearch node. I also have metricbeat installed on a Windows Server 2012 Standard server with an Elasticsearch node as well in…

---

## [Custom module from default](https://discuss.elastic.co/t/custom-module-from-default/189726)

<div class="topic-metadata">

**Author:** [@izual512](https://discuss.elastic.co/u/izual512)\
**Replies:** 0\
**Last updated:** [July 10, 2019, 10:55am UTC](https://discuss.elastic.co/t/custom-module-from-default/189726 "2019-07-10T10:55:08Z")

</div>

Hi, I have IHS in my env, so I have 3 types of logs: error, access and ncsa. I am currently using modules: apache2/error for error logs and apache2/access for ncsa logs, but access logs are different. I tried to duplic…

---

## [Decreasing total](https://discuss.elastic.co/t/decreasing-total/189575)

<div class="topic-metadata">

**Author:** [@lasselj](https://discuss.elastic.co/u/lasselj)\
**Replies:** 2\
**Last updated:** [July 10, 2019, 1:32pm UTC](https://discuss.elastic.co/t/decreasing-total/189575 "2019-07-10T13:32:25Z")

</div>

How does it happen that the packetbeat metric dest.stats.net\_bytes\_total (or in some cases source.stats.net\_bytes\_total) is not monotonic within a particular flow over time? I.e. this looks weird:

---

## [Filebeat cannot send output to logstash](https://discuss.elastic.co/t/filebeat-cannot-send-output-to-logstash/188034)

<div class="topic-metadata">

**Author:** [@Dave\_Hafid](https://discuss.elastic.co/u/Dave_Hafid)\
**Replies:** 7\
**Last updated:** [July 10, 2019, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-cannot-send-output-to-logstash/188034 "2019-07-10T13:25:04Z")

</div>

Dear ALL, iam trying to configure filebeat to send output to logstash, after running command filebeat setup i found this error message Exiting: Index management requested but the Elasticsearch output is not configured/…

---

## [Filebeat logstash output other than 5044 is not working](https://discuss.elastic.co/t/filebeat-logstash-output-other-than-5044-is-not-working/189534)

<div class="topic-metadata">

**Author:** [@gorkii](https://discuss.elastic.co/u/gorkii)\
**Replies:** 1\
**Last updated:** [July 10, 2019, 1:19pm UTC](https://discuss.elastic.co/t/filebeat-logstash-output-other-than-5044-is-not-working/189534 "2019-07-10T13:19:54Z")

</div>

Hello, I have a problem that if filebeat output is configured to use any ports except 5044 is not working. Filebeat does not send ACK after receiving SYN, ACK from the logstash. When I change the port to 5044, it is wor…

---

## [Filebeat for apache log](https://discuss.elastic.co/t/filebeat-for-apache-log/189378)

<div class="topic-metadata">

**Author:** [@zmira\_meriem](https://discuss.elastic.co/u/zmira_meriem)\
**Replies:** 1\
**Last updated:** [July 10, 2019, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-for-apache-log/189378 "2019-07-10T13:12:53Z")

</div>

Hi plz help me i install filebeat to collect acces and error apache http but i cant get a correct dashboard journalctl show the following: \[monitoring\] log/log.go:145 Non-zero metrics in the last 30s …

---

## [Filebeat using accessive amount of memory on server](https://discuss.elastic.co/t/filebeat-using-accessive-amount-of-memory-on-server/189374)

<div class="topic-metadata">

**Author:** [@urvi](https://discuss.elastic.co/u/urvi)\
**Replies:** 4\
**Last updated:** [July 10, 2019, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-using-accessive-amount-of-memory-on-server/189374 "2019-07-10T13:09:38Z")

</div>

Hello Team, I am using fileebat 6.5.1. We have server that produce large volume of data per day(75 gb). I am facing memory issue on this server for filebeat. Filebeat is keep on increasing memory usage every day almos…

---

## [Exiting: 1 error: setting 'filebeat.prospectors' has been removed](https://discuss.elastic.co/t/exiting-1-error-setting-filebeat-prospectors-has-been-removed/189486)

<div class="topic-metadata">

**Author:** [@Dea\_Agra](https://discuss.elastic.co/u/Dea_Agra)\
**Replies:** 1\
**Last updated:** [July 10, 2019, 1:00pm UTC](https://discuss.elastic.co/t/exiting-1-error-setting-filebeat-prospectors-has-been-removed/189486 "2019-07-10T13:00:15Z")

</div>

I got an error when running the filebeat. here my configuration

---

## [Send body response to Elastic](https://discuss.elastic.co/t/send-body-response-to-elastic/188516)

<div class="topic-metadata">

**Author:** [@Necroarcano](https://discuss.elastic.co/u/Necroarcano)\
**Replies:** 1\
**Last updated:** [July 10, 2019, 10:17am UTC](https://discuss.elastic.co/t/send-body-response-to-elastic/188516 "2019-07-10T10:17:55Z")

</div>

I can send body response to Elastic? I need this to show results (my healthcheck is a JSON) in canvas Thks

---

## [Filebeat 7.2 wont start - Ubuntu 16.04](https://discuss.elastic.co/t/filebeat-7-2-wont-start-ubuntu-16-04/189068)

<div class="topic-metadata">

**Author:** [@u3432](https://discuss.elastic.co/u/u3432)\
**Replies:** 6\
**Last updated:** [July 10, 2019, 7:59am UTC](https://discuss.elastic.co/t/filebeat-7-2-wont-start-ubuntu-16-04/189068 "2019-07-10T07:59:50Z")

</div>

Hi all, Filebeat wont start on one server running file on the other 5+. Even import config files from working machine but it still wont start. Thank You.

---

## [Troubshooting mapping conflicts after 7.2 upgrade, event id's](https://discuss.elastic.co/t/troubshooting-mapping-conflicts-after-7-2-upgrade-event-ids/189383)

<div class="topic-metadata">

**Author:** [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Replies:** 5\
**Last updated:** [July 10, 2019, 1:54am UTC](https://discuss.elastic.co/t/troubshooting-mapping-conflicts-after-7-2-upgrade-event-ids/189383 "2019-07-10T01:54:49Z")

</div>

Upgraded to elasticstack/Winlogbeats 7.2 and it's great! But I seem to have some conflicts in mapping somewhere and I'm not sure how to troubleshoot. In the past I could simply got to 'Index Patterns' hit the 'refresh …

---

## [Fields not populated](https://discuss.elastic.co/t/fields-not-populated/189390)

<div class="topic-metadata">

**Author:** [@GregL](https://discuss.elastic.co/u/GregL)\
**Replies:** 3\
**Last updated:** [July 10, 2019, 1:11am UTC](https://discuss.elastic.co/t/fields-not-populated/189390 "2019-07-10T01:11:06Z")

</div>

I have installed the 7.2 versions of elasticsearch, logstash and kibana. Trying to follow this blog: However when filtering down to event\_id 4624 the TargetUserName and targetDomainName fields don't seem to be popula…

---

## [Winlogbeat for windows 10](https://discuss.elastic.co/t/winlogbeat-for-windows-10/189179)

<div class="topic-metadata">

**Author:** [@syllamiran](https://discuss.elastic.co/u/syllamiran)\
**Replies:** 2\
**Last updated:** [July 9, 2019, 10:14pm UTC](https://discuss.elastic.co/t/winlogbeat-for-windows-10/189179 "2019-07-09T22:14:51Z")

</div>

Hello. Why the results of logs with winlogbeat 7.2 is differents between Windows 10 1803 (not have an Windows event ID) and windows 1903 (have an windows event ID like 4624, 4800)? The configuration has the same in both …

---

## [Does Filebeat logs fills up the disk?](https://discuss.elastic.co/t/does-filebeat-logs-fills-up-the-disk/189602)

<div class="topic-metadata">

**Author:** [@ridhima](https://discuss.elastic.co/u/ridhima)\
**Replies:** 1\
**Last updated:** [July 9, 2019, 6:27pm UTC](https://discuss.elastic.co/t/does-filebeat-logs-fills-up-the-disk/189602 "2019-07-09T18:27:06Z")

</div>

why the filebeat is generating the logs like filebeat , filbeat.1 , filebeat.2 ? "filebeat " log file created by filebeat as it runs showing what is doing.That kind of continuing content will eventually create a …

---

## [Beats refuse to start if Kibana is not ready, even if retry is enabled](https://discuss.elastic.co/t/beats-refuse-to-start-if-kibana-is-not-ready-even-if-retry-is-enabled/189598)

<div class="topic-metadata">

**Author:** [@tomj](https://discuss.elastic.co/u/tomj)\
**Replies:** 0\
**Last updated:** [July 9, 2019, 4:32pm UTC](https://discuss.elastic.co/t/beats-refuse-to-start-if-kibana-is-not-ready-even-if-retry-is-enabled/189598 "2019-07-09T16:32:38Z")

</div>

Works in 6.8.1. Doesn't work in 7.2.0. I'm using docker-compose to bring up Elasticsearch, Kibana, Logstash, Metricbeat, and Packetbeat. Both Metricbeat and Packetbeat are set up to depend on Logstash and Kibana. Usi…

---

## [Importing beats dashboards from file system fails](https://discuss.elastic.co/t/importing-beats-dashboards-from-file-system-fails/188348)

<div class="topic-metadata">

**Author:** [@tomj](https://discuss.elastic.co/u/tomj)\
**Replies:** 2\
**Last updated:** [July 9, 2019, 3:46pm UTC](https://discuss.elastic.co/t/importing-beats-dashboards-from-file-system-fails/188348 "2019-07-09T15:46:00Z")

</div>

Using Metricbeat 6.7.2, Elasticsearch 6.7.0, Kibana 6.7.0 I'd like to be able to "pre-load" selected Beats dashboards into a Kibana/Elasticsearch instance before setting up any client Beats instances or modules. When I…

---

## [Metricbeat index don't increment](https://discuss.elastic.co/t/metricbeat-index-dont-increment/185895)

<div class="topic-metadata">

**Author:** [@bigster](https://discuss.elastic.co/u/bigster)\
**Replies:** 3\
**Last updated:** [July 9, 2019, 1:48pm UTC](https://discuss.elastic.co/t/metricbeat-index-dont-increment/185895 "2019-07-09T13:48:38Z")

</div>

Hi all, I've configured by metricbeat with ilm.enabled: true but i've got only a single index created. The default should be "{now/d}-000001" but only an index was created. The problem with this is that the policy fre…

---

## [Filebeat 7.2 netflow module and adding custom fields](https://discuss.elastic.co/t/filebeat-7-2-netflow-module-and-adding-custom-fields/189546)

<div class="topic-metadata">

**Author:** [@involuntary-pretzel](https://discuss.elastic.co/u/involuntary-pretzel)\
**Replies:** 0\
**Last updated:** [July 9, 2019, 12:31pm UTC](https://discuss.elastic.co/t/filebeat-7-2-netflow-module-and-adding-custom-fields/189546 "2019-07-09T12:31:29Z")

</div>

Hi there I recently switched from using the logstash.netflow module to the filebeat.netflow module (so the data shows in SIEM). In the logstash.netflow configuration I had the following field \[netflow\]\[sampling\_bytes\] …

---

## [Filebeat 7.2 on pfsense](https://discuss.elastic.co/t/filebeat-7-2-on-pfsense/188733)

<div class="topic-metadata">

**Author:** [@aztag](https://discuss.elastic.co/u/aztag)\
**Replies:** 2\
**Last updated:** [July 9, 2019, 9:30am UTC](https://discuss.elastic.co/t/filebeat-7-2-on-pfsense/188733 "2019-07-09T09:30:30Z")

</div>

Hi, I am new to ELK, and currently implementing a SIEM using the ELK stack alongside a pfsense firewall with suricata. The ELK stack is set up, pfsense with suricata also. I can send and visualize the firewall logs on …

---

## [Windows Roles & Services](https://discuss.elastic.co/t/windows-roles-services/189262)

<div class="topic-metadata">

**Author:** [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Replies:** 1\
**Last updated:** [July 9, 2019, 3:44am UTC](https://discuss.elastic.co/t/windows-roles-services/189262 "2019-07-09T03:44:53Z")

</div>

Hi, it would be nice to have list of installed roles and features from servers. Can it be implemented? It could be to metricbeat i guess. Jan

---

## [CPU usage 100% when Elasticsearch is down](https://discuss.elastic.co/t/cpu-usage-100-when-elasticsearch-is-down/185850)

<div class="topic-metadata">

**Author:** [@fredrik.jonsson](https://discuss.elastic.co/u/fredrik.jonsson)\
**Replies:** 5\
**Last updated:** [July 8, 2019, 11:51pm UTC](https://discuss.elastic.co/t/cpu-usage-100-when-elasticsearch-is-down/185850 "2019-07-08T23:51:22Z")

</div>

I noticed that when Elasticsearch can't retrieve any more data the beats sending data went up to 100% CPU usage. E.g. if the disc is full on the Elasticsearch server. After clear up some space and "reset" Elasticsearch…

---

## [Output logstash problem in filebeat 7.2](https://discuss.elastic.co/t/output-logstash-problem-in-filebeat-7-2/189281)

<div class="topic-metadata">

**Author:** [@abu.sayeed](https://discuss.elastic.co/u/abu.sayeed)\
**Replies:** 1\
**Last updated:** [July 8, 2019, 11:38pm UTC](https://discuss.elastic.co/t/output-logstash-problem-in-filebeat-7-2/189281 "2019-07-08T23:38:13Z")

</div>

filebeat.yml: filebeat.inputs: type: log enabled: false paths: /var/log/\*.log #- c:\\programdata\\elasticsearch\\logs\* filebeat.registry.path: /var/lib/filebeat/registry filebeat.registry.file\_permissions: 0600 …

---

## [Using Beats to return Windows Registry Keys - Windows Storage Replica](https://discuss.elastic.co/t/using-beats-to-return-windows-registry-keys-windows-storage-replica/189412)

<div class="topic-metadata">

**Author:** [@enoc](https://discuss.elastic.co/u/enoc)\
**Replies:** 0\
**Last updated:** [July 8, 2019, 7:08pm UTC](https://discuss.elastic.co/t/using-beats-to-return-windows-registry-keys-windows-storage-replica/189412 "2019-07-08T19:08:53Z")

</div>

Hey everyone, I am trying to setup monitoring of the Windows Storage Replica service, to enable reporting of what server(s) and drive(s) are being replicated and where to. The information is located at hklm/software/m…

---

## [Filebeat not Harvesting with nre 'Container' type](https://discuss.elastic.co/t/filebeat-not-harvesting-with-nre-container-type/188906)

<div class="topic-metadata">

**Author:** [@aleksei.saiko](https://discuss.elastic.co/u/aleksei.saiko)\
**Replies:** 3\
**Last updated:** [July 8, 2019, 1:32pm UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-with-nre-container-type/188906 "2019-07-08T13:32:25Z")

</div>

Hi there! I upgraded ELK from 6.6.2 to 7.2.0, changed the filebeat type from docker to container, and filbeat can't harvest. Though when changing the type to log, is starts to Harvest, why? Here's my DaemonSet yml fil…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=337)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=339)
