# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=345

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 346

---

## [Facing connection refused issue while starting metricbeat](https://discuss.elastic.co/t/facing-connection-refused-issue-while-starting-metricbeat/186716)

<div class="topic-metadata">

**Author:** [@krish2](https://discuss.elastic.co/u/krish2)\
**Replies:** 0\
**Last updated:** [June 20, 2019, 2:52pm UTC](https://discuss.elastic.co/t/facing-connection-refused-issue-while-starting-metricbeat/186716 "2019-06-20T14:52:38Z")

</div>

Hi , I have installed elk stack on some server A with IP: x.x.x.x. I have installed metricbeat on another server B with IP: y.y.y.y I have configured metricbeat.yml as below ####### Metricbeat Configuration Example …

---

## [Trouble Collecting Kubernetes apiserver Metricset](https://discuss.elastic.co/t/trouble-collecting-kubernetes-apiserver-metricset/186529)

<div class="topic-metadata">

**Author:** [@rudolphk](https://discuss.elastic.co/u/rudolphk)\
**Replies:** 1\
**Last updated:** [June 20, 2019, 1:23pm UTC](https://discuss.elastic.co/t/trouble-collecting-kubernetes-apiserver-metricset/186529 "2019-06-20T13:23:27Z")

</div>

I've been trying to setup metricbeat to monitor my k8s cluster. I've got my daemonset and pods working, but I'm having difficulty getting apiserver metrics. Originally I was getting ssl cert errors from metricbeat unti…

---

## [Filebeat mapping bug with json enabled?](https://discuss.elastic.co/t/filebeat-mapping-bug-with-json-enabled/186642)

<div class="topic-metadata">

**Author:** [@daniell](https://discuss.elastic.co/u/daniell)\
**Replies:** 4\
**Last updated:** [June 20, 2019, 10:08am UTC](https://discuss.elastic.co/t/filebeat-mapping-bug-with-json-enabled/186642 "2019-06-20T10:08:23Z")

</div>

Hi All, Let's say I have app with such output line: "{'message':'example output from my app'}", when I use filebeat without json parsing giving "my app" in kibana is enough to find it ... but with json parsing enabled…

---

## [Incorrect mapping of fields by Kibanna send from logstash](https://discuss.elastic.co/t/incorrect-mapping-of-fields-by-kibanna-send-from-logstash/186336)

<div class="topic-metadata">

**Author:** [@asad\_ali](https://discuss.elastic.co/u/asad_ali)\
**Replies:** 3\
**Last updated:** [June 20, 2019, 9:58am UTC](https://discuss.elastic.co/t/incorrect-mapping-of-fields-by-kibanna-send-from-logstash/186336 "2019-06-20T09:58:28Z")

</div>

Problem I have very simple log file for testing purposes. Below as:- 2008-09-15T11:30:00Z sarah 2008-09-15T12:18:00Z jessica 2008-09-15T13:20:00Z parker lee On testing stdout of logstash is { "type" =\> "log", …

---

## [Add tag with specific word contained in log](https://discuss.elastic.co/t/add-tag-with-specific-word-contained-in-log/182387)

<div class="topic-metadata">

**Author:** [@nyarlath](https://discuss.elastic.co/u/nyarlath)\
**Replies:** 0\
**Last updated:** [May 23, 2019, 9:27am UTC](https://discuss.elastic.co/t/add-tag-with-specific-word-contained-in-log/182387 "2019-05-23T09:27:47Z")

</div>

(topic withdrawn by author, will be automatically deleted in 24 hours unless flagged)

---

## [Different files to same index](https://discuss.elastic.co/t/different-files-to-same-index/186553)

<div class="topic-metadata">

**Author:** [@robymemo](https://discuss.elastic.co/u/robymemo)\
**Replies:** 5\
**Last updated:** [June 20, 2019, 8:45am UTC](https://discuss.elastic.co/t/different-files-to-same-index/186553 "2019-06-20T08:45:28Z")

</div>

Hi, I have this simply configuration on filebeat.inputs filebeat.inputs: type: log paths: /var/log/test.log /var/log/temp\_tst/\*.log the beats are loaded on a single index . I'm not understanding why is considere…

---

## [Filebeat modules es index names](https://discuss.elastic.co/t/filebeat-modules-es-index-names/186539)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 1\
**Last updated:** [June 20, 2019, 7:06am UTC](https://discuss.elastic.co/t/filebeat-modules-es-index-names/186539 "2019-06-20T07:06:37Z")

</div>

i'm using filebeat's suricata and zeek modules, everything works great as long as i dont mess with the index names.. my issue is i have multiple sources sending in data from multiple locations.. right now everything is…

---

## [Many Apache servers on one machine?](https://discuss.elastic.co/t/many-apache-servers-on-one-machine/186386)

<div class="topic-metadata">

**Author:** [@baerrach](https://discuss.elastic.co/u/baerrach)\
**Replies:** 3\
**Last updated:** [June 20, 2019, 7:02am UTC](https://discuss.elastic.co/t/many-apache-servers-on-one-machine/186386 "2019-06-20T07:02:15Z")

</div>

I've got a machine with many Apache servers on it. The Apache logs got into different directories, /srv/host1.com/logs /srv/host2.com/logs etc If I enable modules this will use the default paths, which obviously wont…

---

## [Heartbeat showing application as down even when its up](https://discuss.elastic.co/t/heartbeat-showing-application-as-down-even-when-its-up/185402)

<div class="topic-metadata">

**Author:** [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Replies:** 9\
**Last updated:** [June 20, 2019, 6:45am UTC](https://discuss.elastic.co/t/heartbeat-showing-application-as-down-even-when-its-up/185402 "2019-06-20T06:45:14Z")

</div>

Hi, I have an application URL 1 that redirects to a different URL 2. From browser when I hit URL 1 , it redirects me to URL 2 and in network I can see that URL 1 returns response code as 302 as its redirecting to URL 2.…

---

## [Filebeat / Kafka bug?](https://discuss.elastic.co/t/filebeat-kafka-bug/185843)

<div class="topic-metadata">

**Author:** [@Rob3](https://discuss.elastic.co/u/Rob3)\
**Replies:** 2\
**Last updated:** [June 19, 2019, 6:57pm UTC](https://discuss.elastic.co/t/filebeat-kafka-bug/185843 "2019-06-19T18:57:26Z")

</div>

Filebeat Version: 7.x (testing on 7.1.1 and 7.1.2) Kafka Version: Azure Event Hubs Kafka surface Logstash and Fluentd both work with Event Hubs Kafka interface, Filebeat not so much. For some reason it appears the Eve…

---

## [EXISTS WEBLOGIC FILEBEAT MODULE?](https://discuss.elastic.co/t/exists-weblogic-filebeat-module/185818)

<div class="topic-metadata">

**Author:** [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Replies:** 1\
**Last updated:** [June 19, 2019, 7:00pm UTC](https://discuss.elastic.co/t/exists-weblogic-filebeat-module/185818 "2019-06-19T19:00:32Z")

</div>

Is there a filebeat module for the weblogic application?

---

## [Filebeat haproxy module not using geoip](https://discuss.elastic.co/t/filebeat-haproxy-module-not-using-geoip/186350)

<div class="topic-metadata">

**Author:** [@stevesimpson](https://discuss.elastic.co/u/stevesimpson)\
**Replies:** 1\
**Last updated:** [June 19, 2019, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-not-using-geoip/186350 "2019-06-19T14:06:22Z")

</div>

Hi, I've been following the guides below to try and get haproxy logs into elasticsearch using filebeat and logstash. https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-haproxy.html https://www.elast…

---

## [Metricbeat output to logstash then no data in dashboards](https://discuss.elastic.co/t/metricbeat-output-to-logstash-then-no-data-in-dashboards/185415)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 4\
**Last updated:** [June 19, 2019, 1:07pm UTC](https://discuss.elastic.co/t/metricbeat-output-to-logstash-then-no-data-in-dashboards/185415 "2019-06-19T13:07:55Z")

</div>

Hello, I pointed the output to logstash from Metricbeat & i am able to see the data in discovery. But no data in Metricbeat dashboards. IN Metricbeat: ym file output.logstash: hosts: \['X.x.X.x:5044'\] loadbalance:…

---

## [Is there any way to send to logs to s3 to overcome the space issue in elk server?](https://discuss.elastic.co/t/is-there-any-way-to-send-to-logs-to-s3-to-overcome-the-space-issue-in-elk-server/186069)

<div class="topic-metadata">

**Author:** [@krish2](https://discuss.elastic.co/u/krish2)\
**Replies:** 3\
**Last updated:** [June 19, 2019, 12:49pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-send-to-logs-to-s3-to-overcome-the-space-issue-in-elk-server/186069 "2019-06-19T12:49:03Z")

</div>

Hi , I'm facing a problem with my elk server. I have installed filebeat and metricbeat in my server . The root mount is getting filled with the logs and having space issue. Due to that the new logs are not getting loade…

---

## [Using Packetbeat and named pipes on Linux](https://discuss.elastic.co/t/using-packetbeat-and-named-pipes-on-linux/184587)

<div class="topic-metadata">

**Author:** [@wsales](https://discuss.elastic.co/u/wsales)\
**Replies:** 1\
**Last updated:** [June 19, 2019, 12:03pm UTC](https://discuss.elastic.co/t/using-packetbeat-and-named-pipes-on-linux/184587 "2019-06-19T12:03:46Z")

</div>

Hi all, I have some old linux servers on my network that's will not run packetbeat, and I want do capture the trafic and put on a elasticsearch instance. One of the ways I've been found to remote capture is by using tcp…

---

## [Getting unauthorized access error in metricbeat](https://discuss.elastic.co/t/getting-unauthorized-access-error-in-metricbeat/186435)

<div class="topic-metadata">

**Author:** [@emnioj](https://discuss.elastic.co/u/emnioj)\
**Replies:** 3\
**Last updated:** [June 19, 2019, 11:43am UTC](https://discuss.elastic.co/t/getting-unauthorized-access-error-in-metricbeat/186435 "2019-06-19T11:43:06Z")

</div>

hi team, i am getting below error in metricbeat: 2019-06-19T11:39:50.528+0100 INFO \[monitoring\] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"tic…

---

## [SSL settings for Kibana](https://discuss.elastic.co/t/ssl-settings-for-kibana/186453)

<div class="topic-metadata">

**Author:** [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Replies:** 0\
**Last updated:** [June 19, 2019, 11:32am UTC](https://discuss.elastic.co/t/ssl-settings-for-kibana/186453 "2019-06-19T11:32:50Z")

</div>

I am using the latest stable releases (7.1.x). Reading the documentation for Auditbeat and how to setup the Kibana dashboards that come with it, it says that you can enable ssl for the connection to Kibana. The example c…

---

## [Not able to re-install filebeat on a linux server](https://discuss.elastic.co/t/not-able-to-re-install-filebeat-on-a-linux-server/185380)

<div class="topic-metadata">

**Author:** [@sak6070](https://discuss.elastic.co/u/sak6070)\
**Replies:** 2\
**Last updated:** [June 19, 2019, 7:07am UTC](https://discuss.elastic.co/t/not-able-to-re-install-filebeat-on-a-linux-server/185380 "2019-06-19T07:07:18Z")

</div>

Hello, I have accidentally deleted filebeat folder. now, while reinstalling I am getting below error. How can I reinstall filebeat on my linux server. \[root@LX01435L etc\]# sudo rpm -vi filebeat-7.1.1-x86\_64.rpm warnin…

---

## [Sending syslog to FileBeat from Cisco Asa](https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147)

<div class="topic-metadata">

**Author:** [@jsandri](https://discuss.elastic.co/u/jsandri)\
**Replies:** 3\
**Last updated:** [June 19, 2019, 2:52am UTC](https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147 "2019-06-19T02:52:43Z")

</div>

Hi everyone! I am a new user of elk and beats and I am trying to send logs from a Cisco Asa to a virtual machine with filebeat 7.1.1 using UDP. Logs are received but I encountered the following error message: 2019-06-…

---

## [Failed to connect to backoff(elasticsearch(http://10.80.1.220:5044)): read: connection reset by peer](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-10-80-1-220-5044-read-connection-reset-by-peer/186342)

<div class="topic-metadata">

**Author:** [@Ahana\_Ambshri](https://discuss.elastic.co/u/Ahana_Ambshri)\
**Replies:** 3\
**Last updated:** [June 18, 2019, 8:53pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-10-80-1-220-5044-read-connection-reset-by-peer/186342 "2019-06-18T20:53:05Z")

</div>

Hi, I am getting "Connection reset by peer" error while starting the heartbeat. I have tried almost all the solutions given online but none of them worked. Please find the details below: Elastic Search running on Secur…

---

## [Variables substitution doesn't work from keystore in username/password fields of metricbeat.yml in autodiscover.providers.templates.config section](https://discuss.elastic.co/t/variables-substitution-doesnt-work-from-keystore-in-username-password-fields-of-metricbeat-yml-in-autodiscover-providers-templates-config-section/186125)

<div class="topic-metadata">

**Author:** [@nevmerzhitsky](https://discuss.elastic.co/u/nevmerzhitsky)\
**Replies:** 2\
**Last updated:** [June 18, 2019, 1:02pm UTC](https://discuss.elastic.co/t/variables-substitution-doesnt-work-from-keystore-in-username-password-fields-of-metricbeat-yml-in-autodiscover-providers-templates-config-section/186125 "2019-06-18T13:02:40Z")

</div>

Hi there! How can I use keystore variables in autodiscover.providers.templates.config section of metricbeat.yml? It looks like broken. Version 7.1.0. How to reproduce: Setup Docker for running next services Setup Ela…

---

## [Filebeat reliably dropping lines from head of first new files it sees during load testing](https://discuss.elastic.co/t/filebeat-reliably-dropping-lines-from-head-of-first-new-files-it-sees-during-load-testing/185508)

<div class="topic-metadata">

**Author:** [@bschaeffer](https://discuss.elastic.co/u/bschaeffer)\
**Replies:** 2\
**Last updated:** [June 18, 2019, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-reliably-dropping-lines-from-head-of-first-new-files-it-sees-during-load-testing/185508 "2019-06-18T13:14:15Z")

</div>

We are running a logging load test on our filebeat configuration and have observed that it is reliably dropping a small percentage of lines from the head of the first files it is seeing. Our Setup Filebeat is deployed …

---

## [Enrich information with the administrator flag](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062)

<div class="topic-metadata">

**Author:** [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Replies:** 12\
**Last updated:** [June 17, 2019, 10:10pm UTC](https://discuss.elastic.co/t/enrich-information-with-the-administrator-flag/186062 "2019-06-17T22:10:36Z")

</div>

Hi all I try to enrich the information that I send to Logstash. I'd like to add a field in the winlogbeat index with a label like administrator and in this field I'd like to set YES for the user that is admin of the pc…

---

## [Auditbeat triggers seccomp violations?](https://discuss.elastic.co/t/auditbeat-triggers-seccomp-violations/185700)

<div class="topic-metadata">

**Author:** [@arlen](https://discuss.elastic.co/u/arlen)\
**Replies:** 5\
**Last updated:** [June 17, 2019, 7:10pm UTC](https://discuss.elastic.co/t/auditbeat-triggers-seccomp-violations/185700 "2019-06-17T19:10:03Z")

</div>

So I fired up auditbeat (6.8) as a test on one of my servers to see how it does at collecting audit events. Imagine my surprise when I find over 1/3 of the audit events (runs to about 1400/hour) have auditbeat itself lis…

---

## [Documentation is no longer aligned with the code?](https://discuss.elastic.co/t/documentation-is-no-longer-aligned-with-the-code/185918)

<div class="topic-metadata">

**Author:** [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Replies:** 1\
**Last updated:** [June 17, 2019, 5:50pm UTC](https://discuss.elastic.co/t/documentation-is-no-longer-aligned-with-the-code/185918 "2019-06-17T17:50:26Z")

</div>

Hi, The goal is to follow proper procedure since I believe this is a doc bug and I would like to open an issue. Heartbeat exported fields doc contain 3 notes saying the timers might not be what they seem to be: Thi…

---

## [Beats logging into custom path prevented by -e global flag in systemd unit](https://discuss.elastic.co/t/beats-logging-into-custom-path-prevented-by-e-global-flag-in-systemd-unit/186118)

<div class="topic-metadata">

**Author:** [@thekm1](https://discuss.elastic.co/u/thekm1)\
**Replies:** 0\
**Last updated:** [June 17, 2019, 5:00pm UTC](https://discuss.elastic.co/t/beats-logging-into-custom-path-prevented-by-e-global-flag-in-systemd-unit/186118 "2019-06-17T17:00:41Z")

</div>

In the filebeat version 7.x there is an entry created in the systemd unit of filebeat Environment="BEAT\_LOG\_OPTS=-e". This entry overwrites the settings inside the .yml file for logging.to\_files: true If you are updatin…

---

## [Filebeat - How set always retry publish events?!](https://discuss.elastic.co/t/filebeat-how-set-always-retry-publish-events/185202)

<div class="topic-metadata">

**Author:** [@maxozerov](https://discuss.elastic.co/u/maxozerov)\
**Replies:** 7\
**Last updated:** [June 17, 2019, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-how-set-always-retry-publish-events/185202 "2019-06-17T13:37:59Z")

</div>

Please help... Trying to change the configuration (filebeat.yml), but not successfully - is it possible - always retry publish events? 2019-06-11T16:31:43+03:00 DBG \[publish\] Publish event: { "@timestamp": "2019-06-…

---

## [Loading filebeat default dashboard while using different index name](https://discuss.elastic.co/t/loading-filebeat-default-dashboard-while-using-different-index-name/185244)

<div class="topic-metadata">

**Author:** [@gazolle](https://discuss.elastic.co/u/gazolle)\
**Replies:** 2\
**Last updated:** [June 17, 2019, 12:42pm UTC](https://discuss.elastic.co/t/loading-filebeat-default-dashboard-while-using-different-index-name/185244 "2019-06-17T12:42:03Z")

</div>

Good day, I am seeking assistance on configuring Kibana to use Filebeats default (pre-made) dashboard, running on version 7.1.1. From the documentation I came across (Steps 4-5) it should be feasible. I modified the fi…

---

## [Filebeat 6.3.1 segmentation violation with go 1.11.1](https://discuss.elastic.co/t/filebeat-6-3-1-segmentation-violation-with-go-1-11-1/184780)

<div class="topic-metadata">

**Author:** [@abdulmoiz](https://discuss.elastic.co/u/abdulmoiz)\
**Replies:** 2\
**Last updated:** [June 17, 2019, 12:23pm UTC](https://discuss.elastic.co/t/filebeat-6-3-1-segmentation-violation-with-go-1-11-1/184780 "2019-06-17T12:23:30Z")

</div>

Hi, We are using filebeat version 6.3.1 and go language version 1.11.1 crosscompiled for ARM freescal IMx6 Board. When we run the filebeat application, we are getting segmentation violation issue with go language 1.11.…

---

## [How to calculate packebeat's Events Rate (/s) AND CPU Utilization (%)](https://discuss.elastic.co/t/how-to-calculate-packebeats-events-rate-s-and-cpu-utilization/186022)

<div class="topic-metadata">

**Author:** [@lion00](https://discuss.elastic.co/u/lion00)\
**Replies:** 0\
**Last updated:** [June 17, 2019, 8:59am UTC](https://discuss.elastic.co/t/how-to-calculate-packebeats-events-rate-s-and-cpu-utilization/186022 "2019-06-17T08:59:45Z")

</div>

How to calculate packebeat's Events Rate (/s) AND CPU Utilization (%), I get data from monitoring-beats-\* . like this cpu":{"total":{"ticks":245888430,"time":{"ms":245888438},"value":2.4588843e+08},"user":{"ticks":19761…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=344)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=346)
