# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=342

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 343

---

## [Table for successful icmp counts](https://discuss.elastic.co/t/table-for-successful-icmp-counts/186794)

<div class="topic-metadata">

**Author:** [@noairbag](https://discuss.elastic.co/u/noairbag)\
**Replies:** 5\
**Last updated:** [June 28, 2019, 11:34am UTC](https://discuss.elastic.co/t/table-for-successful-icmp-counts/186794 "2019-06-28T11:34:57Z")

</div>

How can I create a table that shows the number of successful ICMP pings to each server (10 in total)? Context: this is for a game; as long as teams keep their networks up, the pings to their servers will be successful. …

---

## [Heartbeat configure host metadata](https://discuss.elastic.co/t/heartbeat-configure-host-metadata/187634)

<div class="topic-metadata">

**Author:** [@Luis\_Pereira1](https://discuss.elastic.co/u/Luis_Pereira1)\
**Replies:** 1\
**Last updated:** [June 28, 2019, 11:34am UTC](https://discuss.elastic.co/t/heartbeat-configure-host-metadata/187634 "2019-06-28T11:34:28Z")

</div>

Hi everyone, Anyone tried to configure the processor add-observer\_metadata, i'm trying to configure this for specific hosts but i dont know how i can archieve this and how can i remove the icmp:// from the url field

---

## [Sending Heartbeat Data to Logstash: Empty Uptime Overview in Kibana UI](https://discuss.elastic.co/t/sending-heartbeat-data-to-logstash-empty-uptime-overview-in-kibana-ui/186810)

<div class="topic-metadata">

**Author:** [@J143](https://discuss.elastic.co/u/J143)\
**Replies:** 1\
**Last updated:** [June 28, 2019, 11:28am UTC](https://discuss.elastic.co/t/sending-heartbeat-data-to-logstash-empty-uptime-overview-in-kibana-ui/186810 "2019-06-28T11:28:00Z")

</div>

Hello, I installed heartbeat on the same host like elasticsearch, logstash and kibana. I configured the output in yaml-file for logstash. output.logstash: hosts: \["localhost:5044"\] In UI I see the beats under "Discov…

---

## [Enable 2 different filebeat modules & send to different index name](https://discuss.elastic.co/t/enable-2-different-filebeat-modules-send-to-different-index-name/187733)

<div class="topic-metadata">

**Author:** [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Replies:** 4\
**Last updated:** [June 28, 2019, 11:04am UTC](https://discuss.elastic.co/t/enable-2-different-filebeat-modules-send-to-different-index-name/187733 "2019-06-28T11:04:49Z")

</div>

Hello, I am trying to use a single filebeat, enabled with system & apache module to send to elasticsearch. I would want to have a system index and a apache index. How can i do this? ILM is enabled for me and for a sin…

---

## [Hey, filebeat.inputs reads two log files. I am sending it to elasticsearch How can I show them in two different index names in kibana?](https://discuss.elastic.co/t/hey-filebeat-inputs-reads-two-log-files-i-am-sending-it-to-elasticsearch-how-can-i-show-them-in-two-different-index-names-in-kibana/187841)

<div class="topic-metadata">

**Author:** [@Jitendra\_Kumhar](https://discuss.elastic.co/u/Jitendra_Kumhar)\
**Replies:** 3\
**Last updated:** [June 28, 2019, 8:57am UTC](https://discuss.elastic.co/t/hey-filebeat-inputs-reads-two-log-files-i-am-sending-it-to-elasticsearch-how-can-i-show-them-in-two-different-index-names-in-kibana/187841 "2019-06-28T08:57:06Z")

</div>

Hello , My filebeat.inputs reads two log files. I am sending it to elasticsearch How can I show them in two different index names in kibana?

---

## [ESXI, beats](https://discuss.elastic.co/t/esxi-beats/185419)

<div class="topic-metadata">

**Author:** [@Ahmed1](https://discuss.elastic.co/u/Ahmed1)\
**Replies:** 2\
**Last updated:** [June 28, 2019, 8:42am UTC](https://discuss.elastic.co/t/esxi-beats/185419 "2019-06-28T08:42:57Z")

</div>

Hey all, how can i install beats on ESXI. thanks.

---

## [ERROR: input state for file was not removed, CreateFile: Access is denied](https://discuss.elastic.co/t/error-input-state-for-file-was-not-removed-createfile-access-is-denied/187560)

<div class="topic-metadata">

**Author:** [@Astarandel](https://discuss.elastic.co/u/Astarandel)\
**Replies:** 1\
**Last updated:** [June 28, 2019, 8:41am UTC](https://discuss.elastic.co/t/error-input-state-for-file-was-not-removed-createfile-access-is-denied/187560 "2019-06-28T08:41:40Z")

</div>

Hello, a FileBeat on one of our machines started giving this error: ERROR log/input.go:222 input state for C:\\tmp\\InstalledPrograms.log was not removed: CreateFile C:\\tmp\\InstalledPrograms.log: Access is denied. INFO l…

---

## [Dmarc2logstash fails to log in to outlook365 mail account](https://discuss.elastic.co/t/dmarc2logstash-fails-to-log-in-to-outlook365-mail-account/187990)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 0\
**Last updated:** [June 28, 2019, 8:27am UTC](https://discuss.elastic.co/t/dmarc2logstash-fails-to-log-in-to-outlook365-mail-account/187990 "2019-06-28T08:27:04Z")

</div>

I've had this running nicely, the dmarc2logstash runs, and pulls all the reports, unzips, and places them ready for filebeat to grab, and send to logstash. I've used the code from jertel: https://github.com/jertel/dmarc…

---

## [Seeing error in IIS module](https://discuss.elastic.co/t/seeing-error-in-iis-module/187901)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 6\
**Last updated:** [June 28, 2019, 4:03am UTC](https://discuss.elastic.co/t/seeing-error-in-iis-module/187901 "2019-06-28T04:03:17Z")

</div>

Hi @pierhugues @Kaiyan\_Sheng I am using ELK 7.2. I am using iis module to ship iis access logs to es. I am seeing this error. error.message Provided Grok expressions do not match field value: \[2019-02-09 09:40:50 10…

---

## [System\_api\_version \[7\] is not supported by system\_id](https://discuss.elastic.co/t/system-api-version-7-is-not-supported-by-system-id/187905)

<div class="topic-metadata">

**Author:** [@Duggina](https://discuss.elastic.co/u/Duggina)\
**Replies:** 1\
**Last updated:** [June 27, 2019, 9:23pm UTC](https://discuss.elastic.co/t/system-api-version-7-is-not-supported-by-system-id/187905 "2019-06-27T21:23:27Z")

</div>

Hi, i get the following error when i am trying to send monitoring data from metricbeat to elasticsearch. ERROR pipeline/output.go:121 Failed to publish events: 400 Bad Request: {"error":{"root\_ …

---

## [Type:mapper\_parsing\_exception , reason:object mapping for \[os\] tried to parse field \[os\] as object, but found a concrete value](https://discuss.elastic.co/t/type-mapper-parsing-exception-reason-object-mapping-for-os-tried-to-parse-field-os-as-object-but-found-a-concrete-value/187320)

<div class="topic-metadata">

**Author:** [@Jitendra\_Kumhar](https://discuss.elastic.co/u/Jitendra_Kumhar)\
**Replies:** 6\
**Last updated:** [June 27, 2019, 9:13pm UTC](https://discuss.elastic.co/t/type-mapper-parsing-exception-reason-object-mapping-for-os-tried-to-parse-field-os-as-object-but-found-a-concrete-value/187320 "2019-06-27T21:13:21Z")

</div>

Hello, I am passing log file with each line as JSON and my JSON has a field "os": "mac" That JSON lines are not passed to elastic search and throwing this error in debug mode. {"type":"mapper\_parsing\_exception","reas…

---

## [Functinobeat.yml config file & cloudwatch](https://discuss.elastic.co/t/functinobeat-yml-config-file-cloudwatch/187921)

<div class="topic-metadata">

**Author:** [@rhader](https://discuss.elastic.co/u/rhader)\
**Replies:** 0\
**Last updated:** [June 27, 2019, 8:33pm UTC](https://discuss.elastic.co/t/functinobeat-yml-config-file-cloudwatch/187921 "2019-06-27T20:33:15Z")

</div>

I have deployed functionbeat to aws -\> type: cloudwatch\_logs Is there a way to have more than one trigger tho? I am trying to get functionbeat to trigger on multiple cloudwatch log groups but I keep getting errors. Ive …

---

## [Filebeat Hints Using Incorrect Fileset/Dataset](https://discuss.elastic.co/t/filebeat-hints-using-incorrect-fileset-dataset/187909)

<div class="topic-metadata">

**Author:** [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Replies:** 0\
**Last updated:** [June 27, 2019, 7:25pm UTC](https://discuss.elastic.co/t/filebeat-hints-using-incorrect-fileset-dataset/187909 "2019-06-27T19:25:30Z")

</div>

Hi there, I'm currently testing out upgrading Filebeat from 6.x to 7.2. I've taken our existing 6.x config and changed a couple of fields: filebeat.registry\_flush \> filebeat.registry.flush filebeat.config.prospectors \>…

---

## [SSL between Filebeat and Logstash which is on SAME SERVER](https://discuss.elastic.co/t/ssl-between-filebeat-and-logstash-which-is-on-same-server/185457)

<div class="topic-metadata">

**Author:** [@Sundaramoorthy\_Anand](https://discuss.elastic.co/u/Sundaramoorthy_Anand)\
**Replies:** 1\
**Last updated:** [June 27, 2019, 7:17pm UTC](https://discuss.elastic.co/t/ssl-between-filebeat-and-logstash-which-is-on-same-server/185457 "2019-06-27T19:17:00Z")

</div>

All my B-ELK stack is running on same servers, say Filebeat on port 5044 ,ES on 9200, LS on 9600 which config-ed to listen Filebeat on port 5044 and finally KIB on 5601. My doubt is, since I'm developing ELK Log analysi…

---

## [Loading remote configs](https://discuss.elastic.co/t/loading-remote-configs/185231)

<div class="topic-metadata">

**Author:** [@amclaughlin](https://discuss.elastic.co/u/amclaughlin)\
**Replies:** 1\
**Last updated:** [June 27, 2019, 7:11pm UTC](https://discuss.elastic.co/t/loading-remote-configs/185231 "2019-06-27T19:11:33Z")

</div>

We are in the early stages of an installation of the ELK stack, and we are going to be using Winlogbeat as part of a SIEM platform that uses the ELK stack as the backbone. We would very much like to not have to maintain…

---

## [Filebeat neither sending updated logs to AWS elastic search nor updating it's own logs](https://discuss.elastic.co/t/filebeat-neither-sending-updated-logs-to-aws-elastic-search-nor-updating-its-own-logs/184808)

<div class="topic-metadata">

**Author:** [@shilpa0209](https://discuss.elastic.co/u/shilpa0209)\
**Replies:** 1\
**Last updated:** [June 27, 2019, 6:56pm UTC](https://discuss.elastic.co/t/filebeat-neither-sending-updated-logs-to-aws-elastic-search-nor-updating-its-own-logs/184808 "2019-06-27T18:56:21Z")

</div>

I have configured filebeat(version 7.1.1) on my system to send logs to AWS Elastic Search but it is not doing following two things appropriately: Updating it's own log file at /var/log/filebeat, and Sending the updated…

---

## [Filebeat - On-Demand Loading Compressed (.gz) Files from Stdin](https://discuss.elastic.co/t/filebeat-on-demand-loading-compressed-gz-files-from-stdin/184159)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 1\
**Last updated:** [June 27, 2019, 6:42pm UTC](https://discuss.elastic.co/t/filebeat-on-demand-loading-compressed-gz-files-from-stdin/184159 "2019-06-27T18:42:09Z")

</div>

If you want to load compressed files like .gz .zip etc. you can use Filebeat with input stdin. vasek ~ $ filebeat version filebeat version 7.0.1 (amd64), libbeat 7.0.1 \[cbffb4dcc8d1d2b0ef2078cb7d7546092ee86e57 built 201…

---

## [On ElasticCloud hosted ElasticSearch, 'bucket \<xxx\> already exist and you don't have permission to access it'](https://discuss.elastic.co/t/on-elasticcloud-hosted-elasticsearch-bucket-xxx-already-exist-and-you-dont-have-permission-to-access-it/187899)

<div class="topic-metadata">

**Author:** [@Mike\_Zmuda](https://discuss.elastic.co/u/Mike_Zmuda)\
**Replies:** 0\
**Last updated:** [June 27, 2019, 6:17pm UTC](https://discuss.elastic.co/t/on-elasticcloud-hosted-elasticsearch-bucket-xxx-already-exist-and-you-dont-have-permission-to-access-it/187899 "2019-06-27T18:17:42Z")

</div>

When attempting to deploy a SQS function with functionbeat, I get the following error: 'Function: sqs, could not deploy, error: bucket 'mybucket' already exist and you don't have permission to access it' Using the AWS …

---

## [AWS module credentials configuration: support default credentials provider](https://discuss.elastic.co/t/aws-module-credentials-configuration-support-default-credentials-provider/187440)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 2\
**Last updated:** [June 27, 2019, 5:53pm UTC](https://discuss.elastic.co/t/aws-module-credentials-configuration-support-default-credentials-provider/187440 "2019-06-27T17:53:18Z")

</div>

Hi, We'd prefer to mount an AWS credentials file into our docker containers at /root/.aws/credentials versus specifing AWS\_ACCESS\_KEY\_ID and AWS\_SECRET\_ACCESS\_KEY as env variables. I'd assume that the sdk would still p…

---

## [Getting -000001 at the end of daily index name](https://discuss.elastic.co/t/getting-000001-at-the-end-of-daily-index-name/187490)

<div class="topic-metadata">

**Author:** [@Karthik\_Vennalaganti](https://discuss.elastic.co/u/Karthik_Vennalaganti)\
**Replies:** 1\
**Last updated:** [June 27, 2019, 1:11pm UTC](https://discuss.elastic.co/t/getting-000001-at-the-end-of-daily-index-name/187490 "2019-06-27T13:11:24Z")

</div>

Hi all, I am using Filebeat -\> Elasticsearch -\> Kibana setup (version 7.1.1) for viewing our application level logs. One index is created per day and logs shipped by filebeat from our file logs are stored. The expected …

---

## [Should the Beat modules only be installed on client?](https://discuss.elastic.co/t/should-the-beat-modules-only-be-installed-on-client/187483)

<div class="topic-metadata">

**Author:** [@Mhn](https://discuss.elastic.co/u/Mhn)\
**Replies:** 9\
**Last updated:** [June 27, 2019, 10:54am UTC](https://discuss.elastic.co/t/should-the-beat-modules-only-be-installed-on-client/187483 "2019-06-27T10:54:36Z")

</div>

Hi everyone, i'm newbi and i am using elasticsearch , logstash, kibana. I want to send logs from an client to my elastic server (logstash) via FileBeat. Should i install FileBeat modules and activate it only on client o…

---

## [Connecting remote windows metrics (beats) to linux elasticsearch](https://discuss.elastic.co/t/connecting-remote-windows-metrics-beats-to-linux-elasticsearch/187800)

<div class="topic-metadata">

**Author:** [@SteMan](https://discuss.elastic.co/u/SteMan)\
**Replies:** 0\
**Last updated:** [June 27, 2019, 9:51am UTC](https://discuss.elastic.co/t/connecting-remote-windows-metrics-beats-to-linux-elasticsearch/187800 "2019-06-27T09:51:58Z")

</div>

I have tried all kinds of settings from all the docs and discussions here and I am sure that I am missing something obvious but I need some assistance :slight\_smile: So I have a linux sytem (lets call this linuxserver) …

---

## [Handling multiples modules output to multiples indexes, good practice?](https://discuss.elastic.co/t/handling-multiples-modules-output-to-multiples-indexes-good-practice/184085)

<div class="topic-metadata">

**Author:** [@TanguyB](https://discuss.elastic.co/u/TanguyB)\
**Replies:** 3\
**Last updated:** [June 27, 2019, 7:34am UTC](https://discuss.elastic.co/t/handling-multiples-modules-output-to-multiples-indexes-good-practice/184085 "2019-06-27T07:34:28Z")

</div>

Hello, In my current deployment, I've many filebeats shipping logs from many sources ( system / audit / mysql modules / docker processor ...). I'd like filebeat to send them in different indexes to ES instead of everyt…

---

## [Want to parse a nested json form filebeat to elasticsearch](https://discuss.elastic.co/t/want-to-parse-a-nested-json-form-filebeat-to-elasticsearch/187771)

<div class="topic-metadata">

**Author:** [@yuvaram\_mohan](https://discuss.elastic.co/u/yuvaram_mohan)\
**Replies:** 0\
**Last updated:** [June 27, 2019, 7:17am UTC](https://discuss.elastic.co/t/want-to-parse-a-nested-json-form-filebeat-to-elasticsearch/187771 "2019-06-27T07:17:34Z")

</div>

Hello! I am having a hard time finding the right configuration for Filebeat to be able to correctly parse nested JSON log lines. filbeat.yml file \</ filebeat.inputs: type: log enabled: true paths: D:/Development…

---

## [Skip SSL verify when enroll metricbeat](https://discuss.elastic.co/t/skip-ssl-verify-when-enroll-metricbeat/184113)

<div class="topic-metadata">

**Author:** [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Replies:** 1\
**Last updated:** [June 27, 2019, 2:44am UTC](https://discuss.elastic.co/t/skip-ssl-verify-when-enroll-metricbeat/184113 "2019-06-27T02:44:06Z")

</div>

I'm using ELK 7.1.1 and i current testing metricbeat erroll management center. But my kibana is using self cert so when i enroll beat i got error : Error while enrolling: fail to execute the HTTP POST request: Post ht…

---

## [Filebeat Logging on Centos 7](https://discuss.elastic.co/t/filebeat-logging-on-centos-7/187629)

<div class="topic-metadata">

**Author:** [@kjenney](https://discuss.elastic.co/u/kjenney)\
**Replies:** 3\
**Last updated:** [June 27, 2019, 2:06am UTC](https://discuss.elastic.co/t/filebeat-logging-on-centos-7/187629 "2019-06-27T02:06:17Z")

</div>

I'm trying to get the Filebeat service to log to /var/log/filebeat.log on Centos 7. I added the following to the config: logging.level: debug logging.to\_files: true logging.files: path: /var/log/filebeat name: fileb…

---

## [How to prevent filebeat exiting when Elasticsearch server is offline](https://discuss.elastic.co/t/how-to-prevent-filebeat-exiting-when-elasticsearch-server-is-offline/187694)

<div class="topic-metadata">

**Author:** [@Dylan\_Nicholson](https://discuss.elastic.co/u/Dylan_Nicholson)\
**Replies:** 0\
**Last updated:** [June 27, 2019, 1:22am UTC](https://discuss.elastic.co/t/how-to-prevent-filebeat-exiting-when-elasticsearch-server-is-offline/187694 "2019-06-27T01:22:18Z")

</div>

I've noticed quite a few times recently that the filebeat service just shuts down due to Elasticsearch server downtime. Basically the last line in the filebeat.log is "Exiting: couldn't connect to any of the configured …

---

## [Manually do what a module does? For example apache](https://discuss.elastic.co/t/manually-do-what-a-module-does-for-example-apache/187689)

<div class="topic-metadata">

**Author:** [@baerrach](https://discuss.elastic.co/u/baerrach)\
**Replies:** 0\
**Last updated:** [June 26, 2019, 11:29pm UTC](https://discuss.elastic.co/t/manually-do-what-a-module-does-for-example-apache/187689 "2019-06-26T23:29:42Z")

</div>

As noted in Many Apache servers on one machine?, the https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-modules.html documentation says using modules is optional and that I can configure these …

---

## [Has anyone built an end to end process on log forwarding to log pruning?](https://discuss.elastic.co/t/has-anyone-built-an-end-to-end-process-on-log-forwarding-to-log-pruning/187673)

<div class="topic-metadata">

**Author:** [@bryan\_stuhlsatz](https://discuss.elastic.co/u/bryan_stuhlsatz)\
**Replies:** 0\
**Last updated:** [June 26, 2019, 8:32pm UTC](https://discuss.elastic.co/t/has-anyone-built-an-end-to-end-process-on-log-forwarding-to-log-pruning/187673 "2019-06-26T20:32:58Z")

</div>

Has anyone built an end to end process on log forwarding to log pruning? Or, does everyone keep several x days of logs on the source, just in case something happens and you have to re-forward. Then implement watcher ru…

---

## [Zeek module - other logs](https://discuss.elastic.co/t/zeek-module-other-logs/187669)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 0\
**Last updated:** [June 26, 2019, 8:01pm UTC](https://discuss.elastic.co/t/zeek-module-other-logs/187669 "2019-06-26T20:01:29Z")

</div>

hi, i'm using filebeat with the zeek module to transfer logs to logstash then on to ES. as of now it looks like the zeek module only handles about 5 of the zeek logs (the common ones: conn, dns, http, files, ssl, notic…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=341)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=343)
