# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=344

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 345

---

## [Filebeat read a log repeatly](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609)

<div class="topic-metadata">

**Author:** [@SimonK](https://discuss.elastic.co/u/SimonK)\
**Replies:** 5\
**Last updated:** [June 25, 2019, 3:03am UTC](https://discuss.elastic.co/t/filebeat-read-a-log-repeatly/186609 "2019-06-25T03:03:42Z")

</div>

Hi, I need to collect the automatic test log to analysis. The log content like this: Total Pass Fail 5 2 0 The automation program will update the number of case. It does't add a new line or change the siz…

---

## [Beats-7.1.1 does not create index for custom pattern](https://discuss.elastic.co/t/beats-7-1-1-does-not-create-index-for-custom-pattern/187092)

<div class="topic-metadata">

**Author:** [@rebirther](https://discuss.elastic.co/u/rebirther)\
**Replies:** 1\
**Last updated:** [June 24, 2019, 9:58pm UTC](https://discuss.elastic.co/t/beats-7-1-1-does-not-create-index-for-custom-pattern/187092 "2019-06-24T21:58:39Z")

</div>

Beats does not create an index from output.elasticsearch.index. I have this configuration for metricbeat: metricbeat.config.modules: path: ${path.config}/modules.d/\*.yml reload.enabled: false setup.template.enabled:…

---

## [Unable to change the elasticsearch indexname in herbeat 6.5 version](https://discuss.elastic.co/t/unable-to-change-the-elasticsearch-indexname-in-herbeat-6-5-version/187104)

<div class="topic-metadata">

**Author:** [@iamyogesh](https://discuss.elastic.co/u/iamyogesh)\
**Replies:** 1\
**Last updated:** [June 24, 2019, 9:57pm UTC](https://discuss.elastic.co/t/unable-to-change-the-elasticsearch-indexname-in-herbeat-6-5-version/187104 "2019-06-24T21:57:45Z")

</div>

from heartbeat am monitoring ip address is up or down using icmp configuration and writing data to elasticsearch by default it write the index to heartbeat-6.5.4-\*\* i need to change the default index name giving followin…

---

## [Error with Enroll Beat for Beats Management](https://discuss.elastic.co/t/error-with-enroll-beat-for-beats-management/187180)

<div class="topic-metadata">

**Author:** [@rebirther](https://discuss.elastic.co/u/rebirther)\
**Replies:** 1\
**Last updated:** [June 24, 2019, 9:55pm UTC](https://discuss.elastic.co/t/error-with-enroll-beat-for-beats-management/187180 "2019-06-24T21:55:56Z")

</div>

Error: Error while enrolling: fail to execute the HTTP POST request: Post https://kibana:5601/api/beats/agent/c6ffda0c-c395-421b-ac8b-41eb3e97fb81: dial tcp 127.0.0.1:5601: connect: connection refused When I want to do…

---

## [Filebeat not sending after update add\_cloud\_metadata: hosting provider type not detected](https://discuss.elastic.co/t/filebeat-not-sending-after-update-add-cloud-metadata-hosting-provider-type-not-detected/187164)

<div class="topic-metadata">

**Author:** [@markov](https://discuss.elastic.co/u/markov)\
**Replies:** 3\
**Last updated:** [June 24, 2019, 7:23pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-after-update-add-cloud-metadata-hosting-provider-type-not-detected/187164 "2019-06-24T19:23:09Z")

</div>

i'm getting this error while starting filebeat after an update from 6.x to 7.x : i have logstash filters but it's sending the machine informations any ideas !! 2019-06-24T12:48:48.741+0100 DEBUG \[beat\] instance/…

---

## [Metricbeats Configuration Issue: Loading index template in Elasticsearch doesn't work](https://discuss.elastic.co/t/metricbeats-configuration-issue-loading-index-template-in-elasticsearch-doesnt-work/184815)

<div class="topic-metadata">

**Author:** [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Replies:** 1\
**Last updated:** [June 24, 2019, 5:22pm UTC](https://discuss.elastic.co/t/metricbeats-configuration-issue-loading-index-template-in-elasticsearch-doesnt-work/184815 "2019-06-24T17:22:03Z")

</div>

Hi everyone, I am trying to change the default Metricbeat index name given to elasticsearch from metricbeat-7.1.1-2019.06.07-000001 to beatsindex-7.1.1-2019.06.07-000001 However my Elasticsearch index name doesn…

---

## [How to configure metric beat to collect OS & Ports Metric](https://discuss.elastic.co/t/how-to-configure-metric-beat-to-collect-os-ports-metric/185768)

<div class="topic-metadata">

**Author:** [@ganesh2](https://discuss.elastic.co/u/ganesh2)\
**Replies:** 5\
**Last updated:** [June 24, 2019, 2:40pm UTC](https://discuss.elastic.co/t/how-to-configure-metric-beat-to-collect-os-ports-metric/185768 "2019-06-24T14:40:51Z")

</div>

Hi, I would like to collect OS type (Windows/Linux) from my VM's and also the list of ports/protocols its listening to. I tried adding the below in the system.yml under 'processors' add\_host\_metadata: netinfo.enabled…

---

## [Arrays of JSON Log File Too Long](https://discuss.elastic.co/t/arrays-of-json-log-file-too-long/186486)

<div class="topic-metadata">

**Author:** [@hosey123](https://discuss.elastic.co/u/hosey123)\
**Replies:** 2\
**Last updated:** [June 24, 2019, 1:26pm UTC](https://discuss.elastic.co/t/arrays-of-json-log-file-too-long/186486 "2019-06-24T13:26:16Z")

</div>

Hi there, I'm currently using Filebeat to listen for JSON files being sent over TCP and send them to Logstash, which then sends them to Elasticsearch. The JSON files I'm attempting to index contain fields with some long …

---

## [Getting Error when i start metric beat service](https://discuss.elastic.co/t/getting-error-when-i-start-metric-beat-service/186393)

<div class="topic-metadata">

**Author:** [@stalinbritto](https://discuss.elastic.co/u/stalinbritto)\
**Replies:** 6\
**Last updated:** [June 24, 2019, 9:44am UTC](https://discuss.elastic.co/t/getting-error-when-i-start-metric-beat-service/186393 "2019-06-24T09:44:14Z")

</div>

// metricbeat.service - Metricbeat is a lightweight shipper for metrics. Loaded: loaded (/lib/systemd/system/metricbeat.service; enabled; vendor preset: enabled) Active: active (running) since Wed 2019-06-19 06…

---

## [Filebeat 7.1.1 cannot send bulk log](https://discuss.elastic.co/t/filebeat-7-1-1-cannot-send-bulk-log/186469)

<div class="topic-metadata">

**Author:** [@rizkan\_abadi](https://discuss.elastic.co/u/rizkan_abadi)\
**Replies:** 5\
**Last updated:** [June 24, 2019, 9:30am UTC](https://discuss.elastic.co/t/filebeat-7-1-1-cannot-send-bulk-log/186469 "2019-06-24T09:30:01Z")

</div>

please help, my filebeat cannot send bulk log laravel to elasticsearch. help

---

## [Template configuration not working with ilm enabled](https://discuss.elastic.co/t/template-configuration-not-working-with-ilm-enabled/186717)

<div class="topic-metadata">

**Author:** [@4rakasi](https://discuss.elastic.co/u/4rakasi)\
**Replies:** 1\
**Last updated:** [June 24, 2019, 9:26am UTC](https://discuss.elastic.co/t/template-configuration-not-working-with-ilm-enabled/186717 "2019-06-24T09:26:42Z")

</div>

Hello, When I modify the "Elasticsearch template setting" part in the filebeat.yml file with the ilm enabled (by default), I can't manage to modify the index pattern of the template and it's name. The only thing that ca…

---

## [Filebeat Parsing for Multiline including previous lines from the log](https://discuss.elastic.co/t/filebeat-parsing-for-multiline-including-previous-lines-from-the-log/186645)

<div class="topic-metadata">

**Author:** [@abinashkd](https://discuss.elastic.co/u/abinashkd)\
**Replies:** 1\
**Last updated:** [June 24, 2019, 8:55am UTC](https://discuss.elastic.co/t/filebeat-parsing-for-multiline-including-previous-lines-from-the-log/186645 "2019-06-24T08:55:40Z")

</div>

Hi, I am trying to parse a log which have the context as below: \[2019-06-20 08:51:10\] Build ID: XXXXX Build time: XXXXX Application version: XXXXX Category: XXXXX Message: Nested Exception StackTrace: java.sql.…

---

## [Need Help Configuring Filebeat](https://discuss.elastic.co/t/need-help-configuring-filebeat/186726)

<div class="topic-metadata">

**Author:** [@ShadowMole](https://discuss.elastic.co/u/ShadowMole)\
**Replies:** 1\
**Last updated:** [June 24, 2019, 8:53am UTC](https://discuss.elastic.co/t/need-help-configuring-filebeat/186726 "2019-06-24T08:53:02Z")

</div>

I have never used the Elastic Stack before so I am trying to learn as a I go. I am on a Windows machine and do not have access to curl. I am using 7.1.1 for Filebeat, Elasticsearch, and Kibana. I am trying to send CSVs t…

---

## [Test execution stuck for beats v6.4.1](https://discuss.elastic.co/t/test-execution-stuck-for-beats-v6-4-1/184502)

<div class="topic-metadata">

**Author:** [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Replies:** 3\
**Last updated:** [June 24, 2019, 6:56am UTC](https://discuss.elastic.co/t/test-execution-stuck-for-beats-v6-4-1/184502 "2019-06-24T06:56:27Z")

</div>

Hello guys, We are working on 6.4.1 version of ELK stack and there is a requirement for testing. While executing the test suite for beat v6.4.1, it gets stuck after "test\_fileset\_file\_0\_auditd (test\_modules.Test)" witho…

---

## [Create new custom Beats, generate.py doesn't generate files/dir](https://discuss.elastic.co/t/create-new-custom-beats-generate-py-doesnt-generate-files-dir/187011)

<div class="topic-metadata">

**Author:** [@\_Barak\_Harari](https://discuss.elastic.co/u/_Barak_Harari)\
**Replies:** 1\
**Last updated:** [June 23, 2019, 4:02pm UTC](https://discuss.elastic.co/t/create-new-custom-beats-generate-py-doesnt-generate-files-dir/187011 "2019-06-23T16:02:18Z")

</div>

Hi i'm using this guide: https://www.elastic.co/guide/en/beats/devguide/current/newbeat-generate.html after this step python $GOPATH/src/github.com/elastic/beats/script/generate.py Beat Name \[Examplebeat\]: Countbeat …

---

## [Multiline.pattern does not search for start with when the pattern has a string](https://discuss.elastic.co/t/multiline-pattern-does-not-search-for-start-with-when-the-pattern-has-a-string/186971)

<div class="topic-metadata">

**Author:** [@KRISHNA\_SINHA](https://discuss.elastic.co/u/KRISHNA_SINHA)\
**Replies:** 0\
**Last updated:** [June 22, 2019, 8:15pm UTC](https://discuss.elastic.co/t/multiline-pattern-does-not-search-for-start-with-when-the-pattern-has-a-string/186971 "2019-06-22T20:15:01Z")

</div>

I have a log file. From this log file I need to separate the entries based on following pattern multiline.pattern: '^{"EntryDate' multiline.negate: false multiline.match: after The output I am expecting is that Filebe…

---

## [Parsing winlogbeat message field](https://discuss.elastic.co/t/parsing-winlogbeat-message-field/186879)

<div class="topic-metadata">

**Author:** [@lwilliams](https://discuss.elastic.co/u/lwilliams)\
**Replies:** 2\
**Last updated:** [June 22, 2019, 2:26pm UTC](https://discuss.elastic.co/t/parsing-winlogbeat-message-field/186879 "2019-06-22T14:26:56Z")

</div>

I am struggling a little bit with the learning curve of Elasticsearch; in the first instance I’d just like to index some specific Windows logs for our privilege management solution and graph out a few metrics. I’ve got …

---

## [Is there a MacOS pkg installer?](https://discuss.elastic.co/t/is-there-a-macos-pkg-installer/186931)

<div class="topic-metadata">

**Author:** [@opoplawski](https://discuss.elastic.co/u/opoplawski)\
**Replies:** 1\
**Last updated:** [June 21, 2019, 9:09pm UTC](https://discuss.elastic.co/t/is-there-a-macos-pkg-installer/186931 "2019-06-21T21:09:23Z")

</div>

https://github.com/elastic/beats/issues/6053 seems to indicate that there was work done on a beats installer for MacOS, but I cannot find any evidence of it available for download. Does such a beast exist?

---

## [Decode json logs filebeat docker hints-based autodiscover](https://discuss.elastic.co/t/decode-json-logs-filebeat-docker-hints-based-autodiscover/185953)

<div class="topic-metadata">

**Author:** [@goekboet](https://discuss.elastic.co/u/goekboet)\
**Replies:** 3\
**Last updated:** [June 21, 2019, 8:09pm UTC](https://discuss.elastic.co/t/decode-json-logs-filebeat-docker-hints-based-autodiscover/185953 "2019-06-21T20:09:31Z")

</div>

TL;DR; Can I have filebeat via hint-based autodiscover ship my json-formatted logs like: { "@timestamp": "2019-06-15T19:48:04.963Z", "foo": "bar" } instead of: { "@timestamp": "2019-…

---

## [Kubernetes Filebeat Manifest not connecting to elasticsearch](https://discuss.elastic.co/t/kubernetes-filebeat-manifest-not-connecting-to-elasticsearch/186896)

<div class="topic-metadata">

**Author:** [@mruge](https://discuss.elastic.co/u/mruge)\
**Replies:** 1\
**Last updated:** [June 21, 2019, 3:52pm UTC](https://discuss.elastic.co/t/kubernetes-filebeat-manifest-not-connecting-to-elasticsearch/186896 "2019-06-21T15:52:23Z")

</div>

I followed the instructions on: https://www.elastic.co/guide/en/beats/filebeat/current/running-on-kubernetes.html What's happening The daemonset deploys successfully, the logs all seem fine. It successfully parses th…

---

## [Monitor a database table with Metricbeat](https://discuss.elastic.co/t/monitor-a-database-table-with-metricbeat/186458)

<div class="topic-metadata">

**Author:** [@Azore](https://discuss.elastic.co/u/Azore)\
**Replies:** 3\
**Last updated:** [June 21, 2019, 2:20pm UTC](https://discuss.elastic.co/t/monitor-a-database-table-with-metricbeat/186458 "2019-06-21T14:20:57Z")

</div>

Hello all, I intend to monitor a special table from my SQL Server or MySQL database in graph. I have seen that metricbeat does the whole database monitoring not living one to write queries or to choose what else to mon…

---

## [Metricbeat: "system.filesystem.used.pct" is not correct](https://discuss.elastic.co/t/metricbeat-system-filesystem-used-pct-is-not-correct/186891)

<div class="topic-metadata">

**Author:** [@sderungs](https://discuss.elastic.co/u/sderungs)\
**Replies:** 1\
**Last updated:** [June 21, 2019, 2:15pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-used-pct-is-not-correct/186891 "2019-06-21T14:15:50Z")

</div>

Hi, I have the issue mentioned in the title. I am using the following stack: Version: 6.8.1 (same behavior in 6.7.1) Operating System: \> cat /proc/version\` Linux version 4.4.0-142-generic (buildd@lgw01-amd64-033) (g…

---

## [\[packetbeat\] memory usage is growing continuously when capturing redis traffic](https://discuss.elastic.co/t/packetbeat-memory-usage-is-growing-continuously-when-capturing-redis-traffic/186865)

<div class="topic-metadata">

**Author:** [@Romber\_Li](https://discuss.elastic.co/u/Romber_Li)\
**Replies:** 1\
**Last updated:** [June 21, 2019, 10:59am UTC](https://discuss.elastic.co/t/packetbeat-memory-usage-is-growing-continuously-when-capturing-redis-traffic/186865 "2019-06-21T10:59:57Z")

</div>

server: virtual machine cpu: 4 logic cpu/8 logic cpu ram: 32GB os: centos 7.2 x86\_64 packetbeat: 7.1.1(i used binary release not rpm package) redis: 4.0.8 kafka: 2.9.2-0.8.2.2 we have a redis cluster which has 8 d…

---

## [Lifecycle policy](https://discuss.elastic.co/t/lifecycle-policy/186795)

<div class="topic-metadata">

**Author:** [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Replies:** 19\
**Last updated:** [June 21, 2019, 9:16am UTC](https://discuss.elastic.co/t/lifecycle-policy/186795 "2019-06-21T09:16:33Z")

</div>

when first start metricbeat system the lifecycle policy is made automatically i want to know how to make lifecycle policy in my setting not just automatically

---

## [Metricbeat ILM Custom Index Name](https://discuss.elastic.co/t/metricbeat-ilm-custom-index-name/186099)

<div class="topic-metadata">

**Author:** [@wmcleod](https://discuss.elastic.co/u/wmcleod)\
**Replies:** 2\
**Last updated:** [June 21, 2019, 8:56am UTC](https://discuss.elastic.co/t/metricbeat-ilm-custom-index-name/186099 "2019-06-21T08:56:10Z")

</div>

Hi, I am trying to choose a custom index name whilst using ILM in Metricbeat. I'd like to have the indexes that Metricbeat writes to called metricbeat-department-7.1.1.... My metricbeat.yml contains the following: se…

---

## [Set index name when first start metricbeat](https://discuss.elastic.co/t/set-index-name-when-first-start-metricbeat/186798)

<div class="topic-metadata">

**Author:** [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Replies:** 1\
**Last updated:** [June 21, 2019, 8:55am UTC](https://discuss.elastic.co/t/set-index-name-when-first-start-metricbeat/186798 "2019-06-21T08:55:10Z")

</div>

When start metricbeat first time. it automatically make index name and lifecycle policy settings i want to be modify like this index name : SystemInfo-7.1.0-000001 lifecycle policy name: SystemInfo lifecycle policy o…

---

## [Exclude gc.log in filebeat config file](https://discuss.elastic.co/t/exclude-gc-log-in-filebeat-config-file/186595)

<div class="topic-metadata">

**Author:** [@jadaun\_kx1](https://discuss.elastic.co/u/jadaun_kx1)\
**Replies:** 2\
**Last updated:** [June 21, 2019, 5:32am UTC](https://discuss.elastic.co/t/exclude-gc-log-in-filebeat-config-file/186595 "2019-06-21T05:32:25Z")

</div>

Hi, Exclude gc.log in filebeat config file ￼ jadaun\_kx1 kaushal 5m while going on kibana i'm seeing it's showing localhost logs from /var/log/elasticsearch/gc.log but i dont want to see them, can anyone help me a…

---

## [Google Compute Engine systemd-resolved errors](https://discuss.elastic.co/t/google-compute-engine-systemd-resolved-errors/185757)

<div class="topic-metadata">

**Author:** [@baerrach](https://discuss.elastic.co/u/baerrach)\
**Replies:** 7\
**Last updated:** [June 21, 2019, 2:03am UTC](https://discuss.elastic.co/t/google-compute-engine-systemd-resolved-errors/185757 "2019-06-21T02:03:10Z")

</div>

I've just installed packetbeats on our Google Compute Engine, and I have been watching a days worth of visualizations. The visualization for "Errors vs successful transactions \[Packetbeat\] ECS" has a much higher error r…

---

## [Wrong parsed field](https://discuss.elastic.co/t/wrong-parsed-field/186751)

<div class="topic-metadata">

**Author:** [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Replies:** 1\
**Last updated:** [June 20, 2019, 8:28pm UTC](https://discuss.elastic.co/t/wrong-parsed-field/186751 "2019-06-20T20:28:24Z")

</div>

Hello, i am using WinLogBeat 7.1.1 (but it do not work in previous version too) and there is wrong parsed field winlog.event\_data.FailureReason t winlog.computer\_name SomeServer1 t winlog.event\_data.Authentic…

---

## [Understanding dashboards field in beat modules](https://discuss.elastic.co/t/understanding-dashboards-field-in-beat-modules/186739)

<div class="topic-metadata">

**Author:** [@skbly7](https://discuss.elastic.co/u/skbly7)\
**Replies:** 0\
**Last updated:** [June 20, 2019, 5:31pm UTC](https://discuss.elastic.co/t/understanding-dashboards-field-in-beat-modules/186739 "2019-06-20T17:31:56Z")

</div>

I see there are dashboards which are referred in module.yml: But where are they actually defined and from where can I download them as json?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=343)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=345)
