# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=340

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 341

---

## [Host, observer, monitor confusion](https://discuss.elastic.co/t/host-observer-monitor-confusion/188641)

<div class="topic-metadata">

**Author:** [@BasG](https://discuss.elastic.co/u/BasG)\
**Replies:** 2\
**Last updated:** [July 4, 2019, 5:49am UTC](https://discuss.elastic.co/t/host-observer-monitor-confusion/188641 "2019-07-04T05:49:57Z")

</div>

The docs state that the "observer" is the one doing the monitoring and the host is the thing being monitored. However the "host" fields are being populated with data about the node running the heartbeat process (aka obs…

---

## [Capture fields from log message in Filebeats](https://discuss.elastic.co/t/capture-fields-from-log-message-in-filebeats/188831)

<div class="topic-metadata">

**Author:** [@Amit3](https://discuss.elastic.co/u/Amit3)\
**Replies:** 0\
**Last updated:** [July 4, 2019, 5:32am UTC](https://discuss.elastic.co/t/capture-fields-from-log-message-in-filebeats/188831 "2019-07-04T05:32:40Z")

</div>

Hi, I have log file with following format (including hyphens): Domain: www.example.com Timestamp: 7/4/2019 12:13:18 AM Severity: Warning ActivityId: 40592004-057f-4621-acef-b3585b845094 Message: HandlingInstanceID…

---

## [Filebeat with Suricata in Windows can't parse log file](https://discuss.elastic.co/t/filebeat-with-suricata-in-windows-cant-parse-log-file/188118)

<div class="topic-metadata">

**Author:** [@jkana](https://discuss.elastic.co/u/jkana)\
**Replies:** 2\
**Last updated:** [July 4, 2019, 1:16am UTC](https://discuss.elastic.co/t/filebeat-with-suricata-in-windows-cant-parse-log-file/188118 "2019-07-04T01:16:23Z")

</div>

Hello, I have issue with filebeat while parsing Suricata log to ELK. My Filebeat 7.0.2 on Windows can't parse Suricata logs to ELK. It seem a bug in Filebeat on Windows since Filebeat on my Linux work correctly Here is…

---

## [How to add the swarm cluster metadata?](https://discuss.elastic.co/t/how-to-add-the-swarm-cluster-metadata/188789)

<div class="topic-metadata">

**Author:** [@alex16](https://discuss.elastic.co/u/alex16)\
**Replies:** 1\
**Last updated:** [July 3, 2019, 7:14pm UTC](https://discuss.elastic.co/t/how-to-add-the-swarm-cluster-metadata/188789 "2019-07-03T19:14:27Z")

</div>

Hello, I want to collect logs from services with swarm cluster? But I can't add a label com.docker.swarm.service.name . Maybe there is a workaround? Thank you!

---

## [FIlebeat SSL Issue](https://discuss.elastic.co/t/filebeat-ssl-issue/188577)

<div class="topic-metadata">

**Author:** [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Replies:** 6\
**Last updated:** [July 3, 2019, 6:39pm UTC](https://discuss.elastic.co/t/filebeat-ssl-issue/188577 "2019-07-03T18:39:52Z")

</div>

I am using SSL for Kibana and have the following config values set in the filebeat.yml file ssl.enabled: true ssl.certificate: "cert.pem" ssl.key: "key.pem" ssl.key\_passphrase: "XXXXXXXX" when I try to run filebeat …

---

## [Auditbeat login dataset generates xxxx indices](https://discuss.elastic.co/t/auditbeat-login-dataset-generates-xxxx-indices/188790)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [July 3, 2019, 6:00pm UTC](https://discuss.elastic.co/t/auditbeat-login-dataset-generates-xxxx-indices/188790 "2019-07-03T18:00:50Z")

</div>

Hello, Just activated the login dataset on a few 100 hosts and noticed some time thereafter that all of a sudden I have 100+ extra indices, one for each day ranging from 2018 untill today.. There should be a way to lim…

---

## [Auditbeat host dataset throwing occasional errors](https://discuss.elastic.co/t/auditbeat-host-dataset-throwing-occasional-errors/188783)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [July 3, 2019, 5:21pm UTC](https://discuss.elastic.co/t/auditbeat-host-dataset-throwing-occasional-errors/188783 "2019-07-03T17:21:29Z")

</div>

Hello, Auditbeat 7.2.0 Got a Red Hat 7 host which sometimes throws: error encoding host information: gob: type host.Host has no exported fields Grtz Willem

---

## [Processor \[drop\_event\] not dropping events Beats Winlogbeat](https://discuss.elastic.co/t/processor-drop-event-not-dropping-events-beats-winlogbeat/188732)

<div class="topic-metadata">

**Author:** [@EFr](https://discuss.elastic.co/u/EFr)\
**Replies:** 2\
**Last updated:** [July 3, 2019, 3:09pm UTC](https://discuss.elastic.co/t/processor-drop-event-not-dropping-events-beats-winlogbeat/188732 "2019-07-03T15:09:49Z")

</div>

ver 7.2.0 I'm unable to filter the unwanted LogonType .\\winlogbeat.exe test config -c .\\winlogbeat.yml -e says the cfg is ok I've tried - equals.event\_data.LogonType: 0 or - equals.event\_data.LogonType: '0' as i'v…

---

## [Metricbeat problem on Infrstructure tab](https://discuss.elastic.co/t/metricbeat-problem-on-infrstructure-tab/188741)

<div class="topic-metadata">

**Author:** [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Replies:** 0\
**Last updated:** [July 3, 2019, 2:23pm UTC](https://discuss.elastic.co/t/metricbeat-problem-on-infrstructure-tab/188741 "2019-07-03T14:23:40Z")

</div>

Hi, I can get metricbeat indices but the data don't display on the Infrastructure tab. Do you have any idea? Best Regards, Thanos

---

## [Metricbeat problem on elasticsearch](https://discuss.elastic.co/t/metricbeat-problem-on-elasticsearch/188656)

<div class="topic-metadata">

**Author:** [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Replies:** 1\
**Last updated:** [July 3, 2019, 2:20pm UTC](https://discuss.elastic.co/t/metricbeat-problem-on-elasticsearch/188656 "2019-07-03T14:20:53Z")

</div>

Hi, I have recently updated all my metricbeat agents from all the hosts from 6.\* to 7.\* version and since then i cannot get data on the infrastructure tab. I checked on the index management that then new indices of the…

---

## [Metricbeat problem with Ingest Node](https://discuss.elastic.co/t/metricbeat-problem-with-ingest-node/188694)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 1\
**Last updated:** [July 3, 2019, 1:50pm UTC](https://discuss.elastic.co/t/metricbeat-problem-with-ingest-node/188694 "2019-07-03T13:50:41Z")

</div>

Hi, I would like to add ingest node for data from metricbeat. Unfortunately i have errors like that: metricbeat logs2019-07-03T10:58:40.182Z INFO elasticsearch/client.go:721 Connected to Elasticsearch ver…

---

## [Monitoring Entire Weblogic](https://discuss.elastic.co/t/monitoring-entire-weblogic/188723)

<div class="topic-metadata">

**Author:** [@anil\_kumar\_Samantula](https://discuss.elastic.co/u/anil_kumar_Samantula)\
**Replies:** 0\
**Last updated:** [July 3, 2019, 1:31pm UTC](https://discuss.elastic.co/t/monitoring-entire-weblogic/188723 "2019-07-03T13:31:00Z")

</div>

Hi Team , Requirement : Monitor Entire Weblogic . Tried Solution : enabled the REST API's in Weblogic but not able to find any api which fetches metrics of all the Queues /topics. Is there any other way ...similar to …

---

## [Auditbeat - Running as non-root user, will likely not report all processes](https://discuss.elastic.co/t/auditbeat-running-as-non-root-user-will-likely-not-report-all-processes/188310)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 4\
**Last updated:** [July 3, 2019, 11:14am UTC](https://discuss.elastic.co/t/auditbeat-running-as-non-root-user-will-likely-not-report-all-processes/188310 "2019-07-03T11:14:21Z")

</div>

Hello, Trying out the process module for auditbeat on Windows. Seeinq the following message: |2019-07-01T14:02:55.289+0200|WARN|\[cfgwarn\]|process/process.go:131|BETA: The system/process dataset is beta| |---|---|---|--…

---

## [Problem with Prometheus Module](https://discuss.elastic.co/t/problem-with-prometheus-module/188332)

<div class="topic-metadata">

**Author:** [@D.B](https://discuss.elastic.co/u/D.B)\
**Replies:** 1\
**Last updated:** [July 3, 2019, 9:30am UTC](https://discuss.elastic.co/t/problem-with-prometheus-module/188332 "2019-07-03T09:30:19Z")

</div>

Hey all, I am currently making a POC with Metricbeat. My goal is to scrape Pormetheus metrics and send them over to the ELK Stack. Currently I am running into an Error, which I can not solve, namely "Unable to decode r…

---

## [Wavefront proxy LogsIngester not establish response to Filebeat after 1 hour idle](https://discuss.elastic.co/t/wavefront-proxy-logsingester-not-establish-response-to-filebeat-after-1-hour-idle/187036)

<div class="topic-metadata">

**Author:** [@ravi\_Wavefront](https://discuss.elastic.co/u/ravi_Wavefront)\
**Replies:** 0\
**Last updated:** [June 24, 2019, 3:35am UTC](https://discuss.elastic.co/t/wavefront-proxy-logsingester-not-establish-response-to-filebeat-after-1-hour-idle/187036 "2019-06-24T03:35:30Z")

</div>

We found that log metric cannot send wavefront if the log file has been idle for ~1 hour. Filebeat version 6.3.2 (amd64), libbeat 6.3.2 Attached filebeat.yml and logsIngestion.yaml Steps to reproduce: Write log to …

---

## [Winlogbeat/logstash change/rename JSON path schema](https://discuss.elastic.co/t/winlogbeat-logstash-change-rename-json-path-schema/188661)

<div class="topic-metadata">

**Author:** [@matejrycek](https://discuss.elastic.co/u/matejrycek)\
**Replies:** 0\
**Last updated:** [July 3, 2019, 9:06am UTC](https://discuss.elastic.co/t/winlogbeat-logstash-change-rename-json-path-schema/188661 "2019-07-03T09:06:09Z")

</div>

Hi, maybe this will be stupid question, but i would like to rename build in JSON fields and little change structure of JSON path schema. If will be possibilities to do that on winlogbeat instead of logstash it would be…

---

## [Heartbeat startup error](https://discuss.elastic.co/t/heartbeat-startup-error/184973)

<div class="topic-metadata">

**Author:** [@andre\_b](https://discuss.elastic.co/u/andre_b)\
**Replies:** 3\
**Last updated:** [July 3, 2019, 7:53am UTC](https://discuss.elastic.co/t/heartbeat-startup-error/184973 "2019-07-03T07:53:10Z")

</div>

Hi all, I'm trying to configure heartbeat-elastic without success. When I try to start the service I get this error: ● heartbeat-elastic.service - Ping remote services for availability and log results to Elasticsearch …

---

## [WinLogBeat Setup](https://discuss.elastic.co/t/winlogbeat-setup/184131)

<div class="topic-metadata">

**Author:** [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Replies:** 4\
**Last updated:** [July 3, 2019, 5:21am UTC](https://discuss.elastic.co/t/winlogbeat-setup/184131 "2019-07-03T05:21:41Z")

</div>

Hi, I'm new to WinLogBeat and trying to setup in my work machine and ofcourse due to lack of Admin privileges I'm not able to start WinLogBeat as a service as mentioned in the setup docs. I have couple of questions on h…

---

## [Filebeat Apache module add timezone due to UTC conversion](https://discuss.elastic.co/t/filebeat-apache-module-add-timezone-due-to-utc-conversion/188591)

<div class="topic-metadata">

**Author:** [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Replies:** 1\
**Last updated:** [July 3, 2019, 2:21am UTC](https://discuss.elastic.co/t/filebeat-apache-module-add-timezone-due-to-utc-conversion/188591 "2019-07-03T02:21:35Z")

</div>

Hello, I realised that with logs like this \[Tue Jul 02 17:40:34.827535 2019\] \[weblogic:error\] \[pid 11619:tid 140101724120832\] \[client 10.10.130.151:50833\] \<1161915620604214988\> Write to the client failed: calling URL:…

---

## [Issue with JSON logs and field 'log.level'](https://discuss.elastic.co/t/issue-with-json-logs-and-field-log-level/188012)

<div class="topic-metadata">

**Author:** [@ohardy](https://discuss.elastic.co/u/ohardy)\
**Replies:** 2\
**Last updated:** [July 2, 2019, 10:17pm UTC](https://discuss.elastic.co/t/issue-with-json-logs-and-field-log-level/188012 "2019-07-02T22:17:20Z")

</div>

Hi, I decide to upgrade our logs format to respect elastic ECS. So a sample of my log application looks like: { "@timestamp": "2019-06-28T09:40:16.551Z", "service": { "runtime": { "name": "node", "…

---

## [Winlogbeat unable to connect to ES after enabling x-pack](https://discuss.elastic.co/t/winlogbeat-unable-to-connect-to-es-after-enabling-x-pack/188334)

<div class="topic-metadata">

**Author:** [@K\_B1](https://discuss.elastic.co/u/K_B1)\
**Replies:** 4\
**Last updated:** [July 2, 2019, 2:10pm UTC](https://discuss.elastic.co/t/winlogbeat-unable-to-connect-to-es-after-enabling-x-pack/188334 "2019-07-02T14:10:25Z")

</div>

My winlogbeat is on windows server and ELK is on Ubuntu server. After upgrading to 7.1.1 and enabling X-pack , winlogbeat is unable to connect to ES and giving me error: connectex: No connection could be made because th…

---

## [Load one dashboard instead of all Filebeat default dashboards (follow up)](https://discuss.elastic.co/t/load-one-dashboard-instead-of-all-filebeat-default-dashboards-follow-up/188455)

<div class="topic-metadata">

**Author:** [@coudenysj](https://discuss.elastic.co/u/coudenysj)\
**Replies:** 1\
**Last updated:** [July 2, 2019, 12:17pm UTC](https://discuss.elastic.co/t/load-one-dashboard-instead-of-all-filebeat-default-dashboards-follow-up/188455 "2019-07-02T12:17:24Z")

</div>

This is basically the same question as in https://discuss.elastic.co/t/load-one-dashboard-instead-of-all-filebeat-default-dashboards/176281. When I run filebeat setup --modules apache2, it still provisions all the dashb…

---

## [Filebeat is not sending the data to logstash](https://discuss.elastic.co/t/filebeat-is-not-sending-the-data-to-logstash/188274)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 2\
**Last updated:** [July 2, 2019, 10:12am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-the-data-to-logstash/188274 "2019-07-02T10:12:17Z")

</div>

HI, i am using filebeat to get the logs from a file for filebeat ouput is logstash and using logstash to filter the logs for logstash output is elasticsearch while trying to print logs on a console the logstash is j…

---

## [Metricbeat knowing that a machine is turned on](https://discuss.elastic.co/t/metricbeat-knowing-that-a-machine-is-turned-on/188472)

<div class="topic-metadata">

**Author:** [@Mouloud\_CHIKHOUNE](https://discuss.elastic.co/u/Mouloud_CHIKHOUNE)\
**Replies:** 0\
**Last updated:** [July 2, 2019, 10:06am UTC](https://discuss.elastic.co/t/metricbeat-knowing-that-a-machine-is-turned-on/188472 "2019-07-02T10:06:26Z")

</div>

Hi, how can I configure metricbeat to know if a given machine is turned on? Because when a machine "A" is turned off it doesn't return any data. Is there a mean to know from a machine "B" if machine "A" is turned off? I …

---

## [Delay in metrics leaving logstash](https://discuss.elastic.co/t/delay-in-metrics-leaving-logstash/188286)

<div class="topic-metadata">

**Author:** [@madCow](https://discuss.elastic.co/u/madCow)\
**Replies:** 1\
**Last updated:** [July 2, 2019, 10:00am UTC](https://discuss.elastic.co/t/delay-in-metrics-leaving-logstash/188286 "2019-07-02T10:00:27Z")

</div>

Hi, I'm running Filebeats 5.6.1 and logstash 2.2 on Windows server 2012. (This was all setup by somebody who has left the company) We use filebeats to collect the IIS http request log files on a 4 webservers. which go…

---

## [Custom Metricbeat - Failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/custom-metricbeat-failed-to-publish-events-temporary-bulk-send-failure/186421)

<div class="topic-metadata">

**Author:** [@fdmsantos](https://discuss.elastic.co/u/fdmsantos)\
**Replies:** 3\
**Last updated:** [July 2, 2019, 10:00am UTC](https://discuss.elastic.co/t/custom-metricbeat-failed-to-publish-events-temporary-bulk-send-failure/186421 "2019-07-02T10:00:45Z")

</div>

Hello, I'm developing a beat based on metricbeat (https://github.com/CCSGroupInternational/vspherebeat) The goal is to retrieve all performance metrics from Vcenter. We have four Vcenters , and we have one beat instanc…

---

## [Receiving OS logs](https://discuss.elastic.co/t/receiving-os-logs/188036)

<div class="topic-metadata">

**Author:** [@markov](https://discuss.elastic.co/u/markov)\
**Replies:** 7\
**Last updated:** [July 2, 2019, 9:41am UTC](https://discuss.elastic.co/t/receiving-os-logs/188036 "2019-07-02T09:41:40Z")

</div>

i'm sending logs withe filebeat from a defined path to elastic but i'm getting the OS logs logstash and xpack enabled

---

## [Winlogbeat error when enabling Xpack](https://discuss.elastic.co/t/winlogbeat-error-when-enabling-xpack/187335)

<div class="topic-metadata">

**Author:** [@Marcell0e](https://discuss.elastic.co/u/Marcell0e)\
**Replies:** 2\
**Last updated:** [July 2, 2019, 9:26am UTC](https://discuss.elastic.co/t/winlogbeat-error-when-enabling-xpack/187335 "2019-07-02T09:26:26Z")

</div>

I get the following error when I uncommitted the Xpack monitoring reporter. I have also, uncommitted and entered the Elasticsearch host, but nothing seems to work. I also use Logstash as my output source. What am I mi…

---

## [Docker logs being written to file](https://discuss.elastic.co/t/docker-logs-being-written-to-file/188088)

<div class="topic-metadata">

**Author:** [@tdeprez](https://discuss.elastic.co/u/tdeprez)\
**Replies:** 2\
**Last updated:** [July 2, 2019, 9:18am UTC](https://discuss.elastic.co/t/docker-logs-being-written-to-file/188088 "2019-07-02T09:18:26Z")

</div>

I'm testing the auditbeat docker image using the kubernetes manifest linked from here: https://www.elastic.co/guide/en/beats/auditbeat/7.2/running-on-kubernetes.html It appears the auditbeat logs are being written to a…

---

## [Functionbeat error on Alpine Linux](https://discuss.elastic.co/t/functionbeat-error-on-alpine-linux/188444)

<div class="topic-metadata">

**Author:** [@teokeecheng](https://discuss.elastic.co/u/teokeecheng)\
**Replies:** 1\
**Last updated:** [July 2, 2019, 8:43am UTC](https://discuss.elastic.co/t/functionbeat-error-on-alpine-linux/188444 "2019-07-02T08:43:10Z")

</div>

Hi, I encounter the following error on Alpine Linux when executing functionbeat command. May I know if there are anyone experiencing similar issue? ./functionbeat: No such file or directory Thank you Regards, Kee Ch…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=339)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=341)
