# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=346

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 347

---

## [How to log auditbeat/metricbeat output not to syslog?](https://discuss.elastic.co/t/how-to-log-auditbeat-metricbeat-output-not-to-syslog/186015)

<div class="topic-metadata">

**Author:** [@indreek](https://discuss.elastic.co/u/indreek)\
**Replies:** 1\
**Last updated:** [June 17, 2019, 8:56am UTC](https://discuss.elastic.co/t/how-to-log-auditbeat-metricbeat-output-not-to-syslog/186015 "2019-06-17T08:56:21Z")

</div>

I have example config. And i still don't see any files in /tmp/ folder. All auditbeat log goes to syslog? Is it possible to log it into file instead of syslog? My current config: logging.level: warning logging.to\_syslo…

---

## [Filebeat+csv - to many fields indexed](https://discuss.elastic.co/t/filebeat-csv-to-many-fields-indexed/185594)

<div class="topic-metadata">

**Author:** [@urosz](https://discuss.elastic.co/u/urosz)\
**Replies:** 3\
**Last updated:** [June 17, 2019, 8:01am UTC](https://discuss.elastic.co/t/filebeat-csv-to-many-fields-indexed/185594 "2019-06-17T08:01:57Z")

</div>

Hi, I've created a flow filebeat (\*.csv) -\> elasticseach cloud -\> kibana Ingest pipe: PUT \_ingest/pipeline/stat\_csv\_parser { "description" : "CSV Parser", "processors" : \[ { "gro…

---

## [Filebeat High CPU consumption on two of four hosts](https://discuss.elastic.co/t/filebeat-high-cpu-consumption-on-two-of-four-hosts/183399)

<div class="topic-metadata">

**Author:** [@Aross](https://discuss.elastic.co/u/Aross)\
**Replies:** 2\
**Last updated:** [June 17, 2019, 7:48am UTC](https://discuss.elastic.co/t/filebeat-high-cpu-consumption-on-two-of-four-hosts/183399 "2019-06-17T07:48:36Z")

</div>

Hi, I am using filebeat version 6.2.4 on a RHEL host to ship log data from applications to a log stash instance. On two of our four hosts that are configured to send data to the same log stash hosts, we are seeing signi…

---

## [Flow of packetbeat through logstash](https://discuss.elastic.co/t/flow-of-packetbeat-through-logstash/185989)

<div class="topic-metadata">

**Author:** [@s23deepak](https://discuss.elastic.co/u/s23deepak)\
**Replies:** 2\
**Last updated:** [June 17, 2019, 5:52am UTC](https://discuss.elastic.co/t/flow-of-packetbeat-through-logstash/185989 "2019-06-17T05:52:23Z")

</div>

I need help in clarifying the flow of packets through the following files: i) packetbeat.yml ii) logstash.yml iii) logstash configuration file ( logstash.conf ) iv) pipelines.yml Could someone tell in which order th…

---

## [Errors ingesting elasticsearch audit due to mapping of request.method](https://discuss.elastic.co/t/errors-ingesting-elasticsearch-audit-due-to-mapping-of-request-method/185967)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 0\
**Last updated:** [June 16, 2019, 3:43pm UTC](https://discuss.elastic.co/t/errors-ingesting-elasticsearch-audit-due-to-mapping-of-request-method/185967 "2019-06-16T15:43:36Z")

</div>

We're getting errors like this: "Could not dynamically add mapping for field \[request.method\]. Existing mapping for \[elasticsearch.audit.request\] must be of type object but found \[keyword\]." It look like it's attempt…

---

## [Winlogbeat speeding the clock](https://discuss.elastic.co/t/winlogbeat-speeding-the-clock/185641)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 3\
**Last updated:** [June 16, 2019, 10:14am UTC](https://discuss.elastic.co/t/winlogbeat-speeding-the-clock/185641 "2019-06-16T10:14:51Z")

</div>

Dear all, In our environment we installed winlogbeat 6.3.2 version . Found in only windows 2008 R2 servers clock speeding up. Is it a known issue? From which version this issue resolved? Regards, Vijay

---

## [How to update filebeat grok filter](https://discuss.elastic.co/t/how-to-update-filebeat-grok-filter/185725)

<div class="topic-metadata">

**Author:** [@marcandre](https://discuss.elastic.co/u/marcandre)\
**Replies:** 3\
**Last updated:** [June 15, 2019, 6:40pm UTC](https://discuss.elastic.co/t/how-to-update-filebeat-grok-filter/185725 "2019-06-15T18:40:24Z")

</div>

Hello, I would like to know if you have a link or a step by step guide on how to add more format for filebeat? Looking to add more format for filebeat apache module. Latest version. Provided Grok expressions do not ma…

---

## [Index Default Name](https://discuss.elastic.co/t/index-default-name/185943)

<div class="topic-metadata">

**Author:** [@stevetso](https://discuss.elastic.co/u/stevetso)\
**Replies:** 1\
**Last updated:** [June 15, 2019, 4:05pm UTC](https://discuss.elastic.co/t/index-default-name/185943 "2019-06-15T16:05:39Z")

</div>

According to doc, the default name of index name would be: The default is "filebeat-%{\[agent.version\]}-%{+yyyy.MM.dd}" but I found the index name of auto created index is simply "filebeat-7.0.1". I tried to add this …

---

## [Email data using packetbeat](https://discuss.elastic.co/t/email-data-using-packetbeat/185627)

<div class="topic-metadata">

**Author:** [@pathri](https://discuss.elastic.co/u/pathri)\
**Replies:** 1\
**Last updated:** [June 15, 2019, 11:11am UTC](https://discuss.elastic.co/t/email-data-using-packetbeat/185627 "2019-06-15T11:11:56Z")

</div>

Hi, i am getting the data for port 25 after configuring SMTP server. It is showing source and destinations IP as per my requirement but not able to see the mail body. How to achieve this? Thanks in advance

---

## [Using tshark -e \<field\> with -T ek switch, parsing json, filebeat](https://discuss.elastic.co/t/using-tshark-e-field-with-t-ek-switch-parsing-json-filebeat/183625)

<div class="topic-metadata">

**Author:** [@dataGuy](https://discuss.elastic.co/u/dataGuy)\
**Replies:** 3\
**Last updated:** [June 11, 2019, 2:50am UTC](https://discuss.elastic.co/t/using-tshark-e-field-with-t-ek-switch-parsing-json-filebeat/183625 "2019-06-11T02:50:54Z")

</div>

Thanks for allowing me in the forums I'm new to Elasticstack and this is my first post so please be gentle. Tools: Windows 10.1804 (Admin)PowerShell Elastic Version 7.0.1 Problem: When harvesting a json file genera…

---

## [Some of filebeats crashed when receiving new configuration from central management](https://discuss.elastic.co/t/some-of-filebeats-crashed-when-receiving-new-configuration-from-central-management/185670)

<div class="topic-metadata">

**Author:** [@leonJ](https://discuss.elastic.co/u/leonJ)\
**Replies:** 1\
**Last updated:** [June 14, 2019, 7:03pm UTC](https://discuss.elastic.co/t/some-of-filebeats-crashed-when-receiving-new-configuration-from-central-management/185670 "2019-06-14T19:03:11Z")

</div>

Version: filebeat: 6.5.4 elasticsearch: 6.5.4 kibana: 6.5.4 logstash: 6.5.4 Operating System: os: rhel 6.6 go version: 1.10.6 kernel version: 2.6.32-504.el6.x86\_64 panic: send on closed channel

---

## [Failed to publish events caused by: lumberjack protocol error](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-lumberjack-protocol-error/185574)

<div class="topic-metadata">

**Author:** [@lauea](https://discuss.elastic.co/u/lauea)\
**Replies:** 1\
**Last updated:** [June 14, 2019, 6:46pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-lumberjack-protocol-error/185574 "2019-06-14T18:46:32Z")

</div>

Hi All, Here is the error. transport\] transport/client.go:131 closing 2019-06-13T08:07:06.252Z DEBUG \[logstash\] logstash/async.go:159 69 events out of 69 events sent to logstash host xxx.xxx..xxx:15044. Continue sendin…

---

## [Metricbeat stops sending metrics when there is no consumer/publisher on a RabbitMQ queue](https://discuss.elastic.co/t/metricbeat-stops-sending-metrics-when-there-is-no-consumer-publisher-on-a-rabbitmq-queue/184766)

<div class="topic-metadata">

**Author:** [@wouter.vandenheede](https://discuss.elastic.co/u/wouter.vandenheede)\
**Replies:** 4\
**Last updated:** [June 14, 2019, 3:58pm UTC](https://discuss.elastic.co/t/metricbeat-stops-sending-metrics-when-there-is-no-consumer-publisher-on-a-rabbitmq-queue/184766 "2019-06-14T15:58:15Z")

</div>

Hello, I have an issue with the metricset Queue for RabbitMQ. If there are 1 or more consumers on a queue, there is no problem. Then metrics from this queue comes in Elasticsearch. As soon as the consumer disappears, n…

---

## [Monitor Google URL](https://discuss.elastic.co/t/monitor-google-url/185600)

<div class="topic-metadata">

**Author:** [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Replies:** 4\
**Last updated:** [June 14, 2019, 3:42pm UTC](https://discuss.elastic.co/t/monitor-google-url/185600 "2019-06-14T15:42:54Z")

</div>

Hi, I was trying to monitor Google page (www.google.com) using HeartBeat. This is how my output is. It says that google is down :frowning: . Output : "error" : { "message" : "lookup www.google.com: getaddrinfo…

---

## [Write errors after upgrade to 7.0](https://discuss.elastic.co/t/write-errors-after-upgrade-to-7-0/183119)

<div class="topic-metadata">

**Author:** [@rhizoet](https://discuss.elastic.co/u/rhizoet)\
**Replies:** 2\
**Last updated:** [June 14, 2019, 3:10pm UTC](https://discuss.elastic.co/t/write-errors-after-upgrade-to-7-0/183119 "2019-06-14T15:10:16Z")

</div>

Hello, We are currently using a rather large stack, which we upgraded to version 7.0 two weeks ago. After we patched everything and updated the file- and metricbeat, we get the following error message in Elasticsearch: …

---

## [Filebeat won't collect syslogs over network](https://discuss.elastic.co/t/filebeat-wont-collect-syslogs-over-network/185261)

<div class="topic-metadata">

**Author:** [@johnbchron](https://discuss.elastic.co/u/johnbchron)\
**Replies:** 1\
**Last updated:** [June 14, 2019, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-wont-collect-syslogs-over-network/185261 "2019-06-14T14:33:04Z")

</div>

So I (for various reasons) would like to collect logs using Filebeat that are sent in from multiple locations on the local network. If possible I would like to access the actual logs being sent in, the actual contents of…

---

## [Some questions about Filebeat that are not clear in the docs](https://discuss.elastic.co/t/some-questions-about-filebeat-that-are-not-clear-in-the-docs/185172)

<div class="topic-metadata">

**Author:** [@jesusgn90](https://discuss.elastic.co/u/jesusgn90)\
**Replies:** 5\
**Last updated:** [June 14, 2019, 9:29am UTC](https://discuss.elastic.co/t/some-questions-about-filebeat-that-are-not-clear-in-the-docs/185172 "2019-06-14T09:29:11Z")

</div>

Hi team, just some quick questions: Can Filebeat setup a pipeline in Elasticsearch like it does with the template? What I meant is that I can send a JSON index template from FIlebeat to Elasticsearch using setup.templa…

---

## [Filebeat loops while corrupted logs processing](https://discuss.elastic.co/t/filebeat-loops-while-corrupted-logs-processing/183091)

<div class="topic-metadata">

**Author:** [@yverbin](https://discuss.elastic.co/u/yverbin)\
**Replies:** 4\
**Last updated:** [June 14, 2019, 8:44am UTC](https://discuss.elastic.co/t/filebeat-loops-while-corrupted-logs-processing/183091 "2019-06-14T08:44:02Z")

</div>

Hello ! This issue can be related to: Filebeat 6.4.2 and 6.5.1: Read line error: "parsing CRI timestamp" and "invalid CRI log format" and many more situations when container log files are corrupted. There is a known iss…

---

## [Running Metricbeat for a long time everyday at the same time](https://discuss.elastic.co/t/running-metricbeat-for-a-long-time-everyday-at-the-same-time/184800)

<div class="topic-metadata">

**Author:** [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Replies:** 1\
**Last updated:** [June 14, 2019, 8:41am UTC](https://discuss.elastic.co/t/running-metricbeat-for-a-long-time-everyday-at-the-same-time/184800 "2019-06-14T08:41:50Z")

</div>

Hi everyone, Brief background about my problem: I need to run Metricbeat on my machine that is located in a different region (I don't live there), and that region does not have a reliable wifi connection. I need to rec…

---

## [Filebeat Binary Cannot Be Executed](https://discuss.elastic.co/t/filebeat-binary-cannot-be-executed/185749)

<div class="topic-metadata">

**Author:** [@Dominic\_Evert](https://discuss.elastic.co/u/Dominic_Evert)\
**Replies:** 5\
**Last updated:** [June 14, 2019, 8:30am UTC](https://discuss.elastic.co/t/filebeat-binary-cannot-be-executed/185749 "2019-06-14T08:30:14Z")

</div>

Running filebeat 6.2.0 on a ubuntu 16.04 VM, however, on starting the service, filebeat crashed, saying that the file /usr/share/filebeat/bin/filebeat cannot be found. Within /usr/share/filebeat/bin/ both filebeat and f…

---

## [Connection marked as failed because the onConnect callback failed: cannot retrieve the elasticsearch license: error from server, response code: 500](https://discuss.elastic.co/t/connection-marked-as-failed-because-the-onconnect-callback-failed-cannot-retrieve-the-elasticsearch-license-error-from-server-response-code-500/185704)

<div class="topic-metadata">

**Author:** [@ishu52](https://discuss.elastic.co/u/ishu52)\
**Replies:** 5\
**Last updated:** [June 14, 2019, 7:32am UTC](https://discuss.elastic.co/t/connection-marked-as-failed-because-the-onconnect-callback-failed-cannot-retrieve-the-elasticsearch-license-error-from-server-response-code-500/185704 "2019-06-14T07:32:01Z")

</div>

I am trying to connect to IBM Database for ES service from filebeat. Since ES is SSL connection for which I can get hosts,username,password and base64 encoded certificate. I have converted base64 in .pem format and passe…

---

## [AWS Module in Metricbeat](https://discuss.elastic.co/t/aws-module-in-metricbeat/185733)

<div class="topic-metadata">

**Author:** [@maneo99](https://discuss.elastic.co/u/maneo99)\
**Replies:** 1\
**Last updated:** [June 14, 2019, 1:42am UTC](https://discuss.elastic.co/t/aws-module-in-metricbeat/185733 "2019-06-14T01:42:35Z")

</div>

I am currently in the process of implementing the aws module in Metricbeat. I have followed the documentation for setup and everything looks ok. However, I am getting the following error: beat: Exiting: 1 error: 1 err…

---

## [Are these the only supported modules for Metricbeat?](https://discuss.elastic.co/t/are-these-the-only-supported-modules-for-metricbeat/185728)

<div class="topic-metadata">

**Author:** [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 11:51pm UTC](https://discuss.elastic.co/t/are-these-the-only-supported-modules-for-metricbeat/185728 "2019-06-13T23:51:55Z")

</div>

My colleagues use different softwares and they have asked me whether I can monitor their software performance by receiving metrics. My question is if the name of the software is not included in the module list of Metricb…

---

## [Filebeat Logging: Include filenames in the log](https://discuss.elastic.co/t/filebeat-logging-include-filenames-in-the-log/185285)

<div class="topic-metadata">

**Author:** [@seth.yes](https://discuss.elastic.co/u/seth.yes)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 10:52pm UTC](https://discuss.elastic.co/t/filebeat-logging-include-filenames-in-the-log/185285 "2019-06-13T22:52:08Z")

</div>

Is there a way to configure the logging to include the filename when reporting an error? I'm using an instance of Filebeat (v6.2) which tails somewhere around 80 different file paths. Currently when errors are reported…

---

## [Adding support for kerberos authentication for kafka output](https://discuss.elastic.co/t/adding-support-for-kerberos-authentication-for-kafka-output/185020)

<div class="topic-metadata">

**Author:** [@file\_descriptor](https://discuss.elastic.co/u/file_descriptor)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 8:59pm UTC](https://discuss.elastic.co/t/adding-support-for-kerberos-authentication-for-kafka-output/185020 "2019-06-13T20:59:57Z")

</div>

Hello, I'm a junior dev willing to start looking into implementing kerberos authentication for the kafka output of the \*Beats products. I've seen issues mentioning it, but to my knowledge nobody is working actively on i…

---

## [2 questions about multiline patterns](https://discuss.elastic.co/t/2-questions-about-multiline-patterns/184810)

<div class="topic-metadata">

**Author:** [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 8:27pm UTC](https://discuss.elastic.co/t/2-questions-about-multiline-patterns/184810 "2019-06-13T20:27:26Z")

</div>

hello, using Filebeat 6.7.1 I have a couple of questions about the usage of multiline options for the "log" input. Question 1: is there a way to apply include\_lines before multiline? The log file I am reading has a …

---

## [Writing Filebeat Multiline Pattern for Unusual Log Format](https://discuss.elastic.co/t/writing-filebeat-multiline-pattern-for-unusual-log-format/185695)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 3:59pm UTC](https://discuss.elastic.co/t/writing-filebeat-multiline-pattern-for-unusual-log-format/185695 "2019-06-13T15:59:11Z")

</div>

As I'm instrumenting a new application for log monitoring via filebeat, I came across a log format I've never seen before. It's a multiline log format, but instead of just continuing, each continuing line contains a cop…

---

## [Multiline JSON not importing to fields in ElasticSearch - do I need Logstash?](https://discuss.elastic.co/t/multiline-json-not-importing-to-fields-in-elasticsearch-do-i-need-logstash/183695)

<div class="topic-metadata">

**Author:** [@warburtron](https://discuss.elastic.co/u/warburtron)\
**Replies:** 3\
**Last updated:** [June 13, 2019, 5:11pm UTC](https://discuss.elastic.co/t/multiline-json-not-importing-to-fields-in-elasticsearch-do-i-need-logstash/183695 "2019-06-13T17:11:18Z")

</div>

I've tried really (really) hard to sort this before asking for help here, so I'm desperately hoping someone can help as it's driving me crazy! :slight\_smile: Fair warning... I'm still pretty new to ELK so there's a good …

---

## [Some documented fields (e.g. kubernetes.container.image) missing from events](https://discuss.elastic.co/t/some-documented-fields-e-g-kubernetes-container-image-missing-from-events/185217)

<div class="topic-metadata">

**Author:** [@bagratte](https://discuss.elastic.co/u/bagratte)\
**Replies:** 2\
**Last updated:** [June 13, 2019, 4:21pm UTC](https://discuss.elastic.co/t/some-documented-fields-e-g-kubernetes-container-image-missing-from-events/185217 "2019-06-13T16:21:13Z")

</div>

As per https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html#\_kubernetes, kubernetes.container.image is available in filebeat events. Consider a deployment of filebeat on a Kubernetes cl…

---

## [Auditbeat index pattern](https://discuss.elastic.co/t/auditbeat-index-pattern/185579)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 7\
**Last updated:** [June 13, 2019, 1:21pm UTC](https://discuss.elastic.co/t/auditbeat-index-pattern/185579 "2019-06-13T13:21:45Z")

</div>

I'm not able to create the index pattern and tried the following steps. what am i doing wrong? Tried 1: auditbeat setup --template -E output.logstash.enabled=false -E output.elasticsearch.hosts= -E setup.kibana.userna…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=345)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=347)
