# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=341

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 342

---

## [Connection error for metricbeat with mssql server](https://discuss.elastic.co/t/connection-error-for-metricbeat-with-mssql-server/188443)

<div class="topic-metadata">

**Author:** [@Suraj\_Customer\_Exp\_L](https://discuss.elastic.co/u/Suraj_Customer_Exp_L)\
**Replies:** 0\
**Last updated:** [July 2, 2019, 6:56am UTC](https://discuss.elastic.co/t/connection-error-for-metricbeat-with-mssql-server/188443 "2019-07-02T06:56:09Z")

</div>

i can't able to connect mssql server with metricbeat and fetch data into kibana. i have configured mssql.yml file as module: mssql metricsets: "transaction\_log" "performance" hosts: \["sqlserver://user:password@192.…

---

## [Getting windows module to work in docker](https://discuss.elastic.co/t/getting-windows-module-to-work-in-docker/188416)

<div class="topic-metadata">

**Author:** [@LukeBourne2009](https://discuss.elastic.co/u/LukeBourne2009)\
**Replies:** 0\
**Last updated:** [July 1, 2019, 10:19pm UTC](https://discuss.elastic.co/t/getting-windows-module-to-work-in-docker/188416 "2019-07-01T22:19:35Z")

</div>

Hey, I'm new to the elastic stack and still learning but i've got kibana, elastic search and metricbeat all up and running in individual docker containers. They are communicating fine and I can get results from the defa…

---

## [Filebeats IIS Grok](https://discuss.elastic.co/t/filebeats-iis-grok/188160)

<div class="topic-metadata">

**Author:** [@anon15412260](https://discuss.elastic.co/u/anon15412260)\
**Replies:** 1\
**Last updated:** [July 1, 2019, 7:38pm UTC](https://discuss.elastic.co/t/filebeats-iis-grok/188160 "2019-07-01T19:38:43Z")

</div>

We ran into an issue where we were using filebeats iis module to inject iis logs from a directory. We found that the grok parsers were not properly parsing the logs sent to elasticsearch. We used the grok UI in kibana to…

---

## [Winlogbeat - PowerShell arguments](https://discuss.elastic.co/t/winlogbeat-powershell-arguments/188372)

<div class="topic-metadata">

**Author:** [@mually](https://discuss.elastic.co/u/mually)\
**Replies:** 0\
**Last updated:** [July 1, 2019, 4:21pm UTC](https://discuss.elastic.co/t/winlogbeat-powershell-arguments/188372 "2019-07-01T16:21:01Z")

</div>

Hi, Using Winlogbeat on a windows host, I can see logs when the PowerShell process is started/running/stopped. Is there a way for me get Elastic to report the arguments executed in a PowerShell channel? For example, if…

---

## [Dynamic date files input to Filebeat](https://discuss.elastic.co/t/dynamic-date-files-input-to-filebeat/188127)

<div class="topic-metadata">

**Author:** [@Dibyakanta](https://discuss.elastic.co/u/Dibyakanta)\
**Replies:** 7\
**Last updated:** [July 1, 2019, 4:20pm UTC](https://discuss.elastic.co/t/dynamic-date-files-input-to-filebeat/188127 "2019-07-01T16:20:07Z")

</div>

Hi, I need to exlude some log files which were created a day ago. Or else in simple words, I need to include only today's log file in Filebeat. In my path, I have log files named as user\_log.2019.06.29 and in that folde…

---

## [Duplicate Events in Kibana](https://discuss.elastic.co/t/duplicate-events-in-kibana/188362)

<div class="topic-metadata">

**Author:** [@cob](https://discuss.elastic.co/u/cob)\
**Replies:** 0\
**Last updated:** [July 1, 2019, 3:48pm UTC](https://discuss.elastic.co/t/duplicate-events-in-kibana/188362 "2019-07-01T15:48:08Z")

</div>

Hello All, I'm having an issue where it seems the same events keeps getting pushed to Logstash (or kibana/es?). When I look for an Event ID in Discovery, I see a lot of the same event occurrences, with the same timestam…

---

## [Nginx module - No event published for error log entry](https://discuss.elastic.co/t/nginx-module-no-event-published-for-error-log-entry/188342)

<div class="topic-metadata">

**Author:** [@ORich](https://discuss.elastic.co/u/ORich)\
**Replies:** 1\
**Last updated:** [July 1, 2019, 2:53pm UTC](https://discuss.elastic.co/t/nginx-module-no-event-published-for-error-log-entry/188342 "2019-07-01T14:53:40Z")

</div>

Dear all, as you can notice in here enclosed filebeat log file in debug mode, filebeat does actually monitor nginx error log file but there is neither event published to elasticsearch nor data available in kibana dashbo…

---

## [Set version for custom beat?](https://discuss.elastic.co/t/set-version-for-custom-beat/188106)

<div class="topic-metadata">

**Author:** [@hmschreck](https://discuss.elastic.co/u/hmschreck)\
**Replies:** 2\
**Last updated:** [July 1, 2019, 2:51pm UTC](https://discuss.elastic.co/t/set-version-for-custom-beat/188106 "2019-07-01T14:51:11Z")

</div>

I'm trying to set the version for the custom beats I'm writing, and I must be completely overlooking something. Guidance?

---

## [Is it possible to detect when filebeat is finished harvesting a file](https://discuss.elastic.co/t/is-it-possible-to-detect-when-filebeat-is-finished-harvesting-a-file/187932)

<div class="topic-metadata">

**Author:** [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Replies:** 5\
**Last updated:** [July 1, 2019, 1:10pm UTC](https://discuss.elastic.co/t/is-it-possible-to-detect-when-filebeat-is-finished-harvesting-a-file/187932 "2019-07-01T13:10:58Z")

</div>

We are in the process of designing a system in AWS that automatically creates and stands up a new instance of an application server and after a configured amount of time tear it down and rebuild a new one. We're doing th…

---

## [Issue after upgrade from metricbeat 7.1.1 to 7.2.0](https://discuss.elastic.co/t/issue-after-upgrade-from-metricbeat-7-1-1-to-7-2-0/187878)

<div class="topic-metadata">

**Author:** [@ohardy](https://discuss.elastic.co/u/ohardy)\
**Replies:** 1\
**Last updated:** [July 1, 2019, 9:07am UTC](https://discuss.elastic.co/t/issue-after-upgrade-from-metricbeat-7-1-1-to-7-2-0/187878 "2019-07-01T09:07:25Z")

</div>

Hi, Before upgrade, I got records of type event.dataset='kubernetes.container' with kubernetes meta data added like labels, pod id, etc. After the upgrade, I lost kubernetes meta data. I change nothing, just upgraded …

---

## [Notify when windows service does not exist](https://discuss.elastic.co/t/notify-when-windows-service-does-not-exist/188254)

<div class="topic-metadata">

**Author:** [@Wismat](https://discuss.elastic.co/u/Wismat)\
**Replies:** 0\
**Last updated:** [July 1, 2019, 7:42am UTC](https://discuss.elastic.co/t/notify-when-windows-service-does-not-exist/188254 "2019-07-01T07:42:23Z")

</div>

Hi! As for today my windows module configuration looks like: - module: windows metricsets: \["service"\] period: 10s processors: - drop\_event.when.not.regexp: windows.service.display\_name: '^(MyService1|MyS…

---

## [Start process Winlogbeat](https://discuss.elastic.co/t/start-process-winlogbeat/188177)

<div class="topic-metadata">

**Author:** [@mually](https://discuss.elastic.co/u/mually)\
**Replies:** 2\
**Last updated:** [July 1, 2019, 7:25am UTC](https://discuss.elastic.co/t/start-process-winlogbeat/188177 "2019-07-01T07:25:34Z")

</div>

Hi, I recently installed Winlogbeat 7.2.0 and Auditbeat 7.2.0. The README.md file included with the application download contains the instruction below. " To get started with Winlogbeat, you need to set up Elasticsea…

---

## [Unexpected error error="invalid stored block lengths"](https://discuss.elastic.co/t/unexpected-error-error-invalid-stored-block-lengths/188204)

<div class="topic-metadata">

**Author:** [@Jitendra\_Kumhar](https://discuss.elastic.co/u/Jitendra_Kumhar)\
**Replies:** 2\
**Last updated:** [July 1, 2019, 7:09am UTC](https://discuss.elastic.co/t/unexpected-error-error-invalid-stored-block-lengths/188204 "2019-07-01T07:09:17Z")

</div>

Hello, I am sending logs from Windows machine to fluentd using filebeat and then finally to elastic search. Though the logs are sent on elastic search I am getting some errors on fluentd machine. my fluentd conf file …

---

## [Dynamic date log file input to Filebeat](https://discuss.elastic.co/t/dynamic-date-log-file-input-to-filebeat/188124)

<div class="topic-metadata">

**Author:** [@Dibyakanta](https://discuss.elastic.co/u/Dibyakanta)\
**Replies:** 2\
**Last updated:** [July 1, 2019, 5:49am UTC](https://discuss.elastic.co/t/dynamic-date-log-file-input-to-filebeat/188124 "2019-07-01T05:49:22Z")

</div>

Hi, I have a requirement to add log files to my filebeat server which will create an index in Elasticsearch. The location from where Filebeat would be taking the log file contains log file of different dates. Suppose f…

---

## [Beats error: POST \_bulk EOF after upgrade from 6.5.4 to 7.2.0](https://discuss.elastic.co/t/beats-error-post-bulk-eof-after-upgrade-from-6-5-4-to-7-2-0/188185)

<div class="topic-metadata">

**Author:** [@Dmitry\_Baskakov](https://discuss.elastic.co/u/Dmitry_Baskakov)\
**Replies:** 0\
**Last updated:** [June 30, 2019, 10:12am UTC](https://discuss.elastic.co/t/beats-error-post-bulk-eof-after-upgrade-from-6-5-4-to-7-2-0/188185 "2019-06-30T10:12:50Z")

</div>

I have 4 networks (Client-Network-A, Client-Network-B, Client-Network-C, and Server-Network-ELK) In Server-Network-ELK I have ES cluster with 6 master nodes, 1 ingest node, kibana and logstash I run everything on 6.5.4…

---

## [Filebeat index pattern's hostname is missing](https://discuss.elastic.co/t/filebeat-index-patterns-hostname-is-missing/187943)

<div class="topic-metadata">

**Author:** [@Amine\_Abed](https://discuss.elastic.co/u/Amine_Abed)\
**Replies:** 2\
**Last updated:** [June 30, 2019, 4:17am UTC](https://discuss.elastic.co/t/filebeat-index-patterns-hostname-is-missing/187943 "2019-06-30T04:17:06Z")

</div>

Hi , i have an issue that i have two machine that ship iptables log with filebeat , when creating index pattern i found only one filebeat index pattern i want to have index patterns by hostname can you help me please

---

## [Filebeat Date/Time Parsers](https://discuss.elastic.co/t/filebeat-date-time-parsers/188161)

<div class="topic-metadata">

**Author:** [@anon15412260](https://discuss.elastic.co/u/anon15412260)\
**Replies:** 0\
**Last updated:** [June 30, 2019, 1:29am UTC](https://discuss.elastic.co/t/filebeat-date-time-parsers/188161 "2019-06-30T01:29:14Z")

</div>

We have had the need to inject various logs into elastic for searching/reporting, but struggling to get the parsing right away. Is there a way to natively have several patterns that search the logs for standard date/time…

---

## [Is there a complete, working example of a filebeats config on kubernetes?](https://discuss.elastic.co/t/is-there-a-complete-working-example-of-a-filebeats-config-on-kubernetes/187813)

<div class="topic-metadata">

**Author:** [@Rainer\_Alfoldi](https://discuss.elastic.co/u/Rainer_Alfoldi)\
**Replies:** 5\
**Last updated:** [June 29, 2019, 6:57pm UTC](https://discuss.elastic.co/t/is-there-a-complete-working-example-of-a-filebeats-config-on-kubernetes/187813 "2019-06-29T18:57:16Z")

</div>

Hi all, is there a complete(!) working example of a filebeat configuration on kubernetes where I only want the logs of a specific set of containers. Just dumping everything to es is trivial, but not what I want or need. …

---

## [Kafka/log.go:53 Connected to broker at 10.0.7.65:9092 (unregistered)](https://discuss.elastic.co/t/kafka-log-go-53-connected-to-broker-at-10-0-7-65-9092-unregistered/188135)

<div class="topic-metadata">

**Author:** [@wentao](https://discuss.elastic.co/u/wentao)\
**Replies:** 0\
**Last updated:** [June 29, 2019, 10:41am UTC](https://discuss.elastic.co/t/kafka-log-go-53-connected-to-broker-at-10-0-7-65-9092-unregistered/188135 "2019-06-29T10:41:48Z")

</div>

My metricbeat's version is 7.0.0.When i used Kafka module,i met a problem.Questions are as follows： 2019-06-29T18:28:14.028+0800 INFO pipeline/output.go:105 Connection to backoff(elasticsearch(http://10.130.20.55:9200))…

---

## [ILM setup dynamic alias in filebeat](https://discuss.elastic.co/t/ilm-setup-dynamic-alias-in-filebeat/187298)

<div class="topic-metadata">

**Author:** [@TanguyB](https://discuss.elastic.co/u/TanguyB)\
**Replies:** 1\
**Last updated:** [June 28, 2019, 9:07pm UTC](https://discuss.elastic.co/t/ilm-setup-dynamic-alias-in-filebeat/187298 "2019-06-28T21:07:51Z")

</div>

Hello, I'm trying to setup ILM in my filebeat.yml and I want to use dynamic index My index is set to: index: "filebeat-%{\[agent.version\]}-%{\[fileset.module\]}-%{+yyyy.MM.dd}" which mean I'll have different index per f…

---

## [Functionbeat with logstash](https://discuss.elastic.co/t/functionbeat-with-logstash/188105)

<div class="topic-metadata">

**Author:** [@rhader](https://discuss.elastic.co/u/rhader)\
**Replies:** 0\
**Last updated:** [June 28, 2019, 8:56pm UTC](https://discuss.elastic.co/t/functionbeat-with-logstash/188105 "2019-06-28T20:56:47Z")

</div>

can functionbeat installed on aws cloudwatch/lambda send logs from a specific log group to logstash? Within the functionbeat.yml file I see a logstash output section. Currently I am sending logs directly to my elastic c…

---

## [New custom beat is not sending a template mapping](https://discuss.elastic.co/t/new-custom-beat-is-not-sending-a-template-mapping/186310)

<div class="topic-metadata">

**Author:** [@hmschreck](https://discuss.elastic.co/u/hmschreck)\
**Replies:** 4\
**Last updated:** [June 28, 2019, 6:42pm UTC](https://discuss.elastic.co/t/new-custom-beat-is-not-sending-a-template-mapping/186310 "2019-06-28T18:42:00Z")

</div>

I am creating a custom beat, and I have things such as the follow in \_meta/fields.yml - name: port\_22\_out type: integer When I run the built beat, it is not sending a mapping, as evidenced by the following ma…

---

## [Filebeat WARN 400 please help to decipher](https://discuss.elastic.co/t/filebeat-warn-400-please-help-to-decipher/187898)

<div class="topic-metadata">

**Author:** [@jkrivocheia](https://discuss.elastic.co/u/jkrivocheia)\
**Replies:** 12\
**Last updated:** [June 28, 2019, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-warn-400-please-help-to-decipher/187898 "2019-06-28T16:42:25Z")

</div>

Can Somoene please help me understand the message below? What I did is convert the puppetlogs go json format, in hope to avoid parsing and send it directly to elastic search instead of sending to logstash. I do see th…

---

## [Enable apache2 module in filebeat](https://discuss.elastic.co/t/enable-apache2-module-in-filebeat/188079)

<div class="topic-metadata">

**Author:** [@rnkhouse](https://discuss.elastic.co/u/rnkhouse)\
**Replies:** 0\
**Last updated:** [June 28, 2019, 3:33pm UTC](https://discuss.elastic.co/t/enable-apache2-module-in-filebeat/188079 "2019-06-28T15:33:46Z")

</div>

I want to capture apache error logs and access logs in kibana. I am using this filebeat configuration in kubernetes: https://raw.githubusercontent.com/elastic/beats/7.0/deploy/kubernetes/filebeat-kubernetes.yaml I upda…

---

## [Heartbeat to monitor AWS Elastic Beanstalk](https://discuss.elastic.co/t/heartbeat-to-monitor-aws-elastic-beanstalk/186166)

<div class="topic-metadata">

**Author:** [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Replies:** 5\
**Last updated:** [June 28, 2019, 2:52pm UTC](https://discuss.elastic.co/t/heartbeat-to-monitor-aws-elastic-beanstalk/186166 "2019-06-28T14:52:52Z")

</div>

Hi everyone, Background Info: I am working on a project that requires me to monitor the health of AWS Elastic Beanstalk (EB) applications, but when I use the URL provided for my applications by AWS EB, I keep seeing th…

---

## [Load index template from Filebeat module](https://discuss.elastic.co/t/load-index-template-from-filebeat-module/187780)

<div class="topic-metadata">

**Author:** [@jesusgn90](https://discuss.elastic.co/u/jesusgn90)\
**Replies:** 1\
**Last updated:** [June 28, 2019, 12:44pm UTC](https://discuss.elastic.co/t/load-index-template-from-filebeat-module/187780 "2019-06-28T12:44:12Z")

</div>

Hi guys! I've made a Filebeat module and I have no problem with it, it's working. My question is about index templates for Elasticsearch, right now I have the next block in /etc/filebeat/filebeat.yml which is the main c…

---

## [Adding Kubernetes node name to output](https://discuss.elastic.co/t/adding-kubernetes-node-name-to-output/187536)

<div class="topic-metadata">

**Author:** [@fredsted](https://discuss.elastic.co/u/fredsted)\
**Replies:** 2\
**Last updated:** [June 28, 2019, 11:44am UTC](https://discuss.elastic.co/t/adding-kubernetes-node-name-to-output/187536 "2019-06-28T11:44:17Z")

</div>

Hi, I've installed Heartbeat on my Kubernetes cluster (using Elasticsearch as output) on via the Helm chart. I can't seem to figure out how to add the Kubernetes node name to the output since I want to see how the netw…

---

## [Heartbeat Error](https://discuss.elastic.co/t/heartbeat-error/184013)

<div class="topic-metadata">

**Author:** [@Imad\_Bouchakour](https://discuss.elastic.co/u/Imad_Bouchakour)\
**Replies:** 5\
**Last updated:** [June 28, 2019, 11:38am UTC](https://discuss.elastic.co/t/heartbeat-error/184013 "2019-06-28T11:38:55Z")

</div>

Hi I just installed Heartbeat to monitor our server using ICMP, even if my server is UP heartbeat detecte it as down giving me this message write ip4 0.0.0.0-\>192.168.XX.XX: sendto: operation not permitted PS: the pin…

---

## [How to schedule Heartbeat for every 30th second of minute](https://discuss.elastic.co/t/how-to-schedule-heartbeat-for-every-30th-second-of-minute/185860)

<div class="topic-metadata">

**Author:** [@sukku77](https://discuss.elastic.co/u/sukku77)\
**Replies:** 5\
**Last updated:** [June 28, 2019, 11:38am UTC](https://discuss.elastic.co/t/how-to-schedule-heartbeat-for-every-30th-second-of-minute/185860 "2019-06-28T11:38:03Z")

</div>

Hi Guys, Can someone help me with configuration of heartbeat for below one: I need to schedule heartbeat run using cron expression for every 30th second but not @every 30secs. (like 10:14:30 ,10:15:30 , 10:16:30 an…

---

## [Filebeat fails to connect because template](https://discuss.elastic.co/t/filebeat-fails-to-connect-because-template/188038)

<div class="topic-metadata">

**Author:** [@acematrix](https://discuss.elastic.co/u/acematrix)\
**Replies:** 1\
**Last updated:** [June 28, 2019, 11:36am UTC](https://discuss.elastic.co/t/filebeat-fails-to-connect-because-template/188038 "2019-06-28T11:36:34Z")

</div>

Hi elastic community, I have a elasticsearch cluster running version "number": "7.1.1" I have followed the instructions to install filebeat found here: https://www.elastic.co/docker-kubernetes-container-monitoring ^ t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=340)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=342)
