# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=347

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 348

---

## [Filebeat not ingesting JSON](https://discuss.elastic.co/t/filebeat-not-ingesting-json/185634)

<div class="topic-metadata">

**Author:** [@Astarandel](https://discuss.elastic.co/u/Astarandel)\
**Replies:** 2\
**Last updated:** [June 13, 2019, 12:30pm UTC](https://discuss.elastic.co/t/filebeat-not-ingesting-json/185634 "2019-06-13T12:30:22Z")

</div>

Hi folks, I've been using Filebeat for ingesting regular log files to Logstash without a problem. I've tried to ingest some JSON files which I get from memory tracking logs but nothing seems to happen. Here is what I …

---

## [Metricbeat docker module container labels are missing for Docker API](https://discuss.elastic.co/t/metricbeat-docker-module-container-labels-are-missing-for-docker-api/185123)

<div class="topic-metadata">

**Author:** [@aviratna](https://discuss.elastic.co/u/aviratna)\
**Replies:** 2\
**Last updated:** [June 13, 2019, 11:16am UTC](https://discuss.elastic.co/t/metricbeat-docker-module-container-labels-are-missing-for-docker-api/185123 "2019-06-13T11:16:20Z")

</div>

Metricbeat version: 7.1.1 We have configured Metricbeat with Docker API instead of Unix Socket in metricbeat.yml We are able to get container, cpu, emory, stats etc. Each Metrics consist of cpu stats, container id, c…

---

## [\[solved\] Kubernetes – autodiscover and add\_kubermetes\_metadata only working partially](https://discuss.elastic.co/t/solved-kubernetes-autodiscover-and-add-kubermetes-metadata-only-working-partially/185438)

<div class="topic-metadata">

**Author:** [@c\_g](https://discuss.elastic.co/u/c_g)\
**Replies:** 3\
**Last updated:** [June 13, 2019, 10:46am UTC](https://discuss.elastic.co/t/solved-kubernetes-autodiscover-and-add-kubermetes-metadata-only-working-partially/185438 "2019-06-13T10:46:11Z")

</div>

Hi! Basically I'm trying to ship all logs from my k8s cluster, while adding kubernetes metadata to all containers and joining some multiline output on some of them. I only get the kubernetes: {}-data on some log lines,…

---

## [Hi,all.....Filebeat collection nginx log error,what？](https://discuss.elastic.co/t/hi-all-filebeat-collection-nginx-log-error-what/185603)

<div class="topic-metadata">

**Author:** [@yycm](https://discuss.elastic.co/u/yycm)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 10:18am UTC](https://discuss.elastic.co/t/hi-all-filebeat-collection-nginx-log-error-what/185603 "2019-06-13T10:18:40Z")

</div>

---

## [Overlap between Metricbeat and zabbix-agent?](https://discuss.elastic.co/t/overlap-between-metricbeat-and-zabbix-agent/185220)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 9:21am UTC](https://discuss.elastic.co/t/overlap-between-metricbeat-and-zabbix-agent/185220 "2019-06-13T09:21:35Z")

</div>

I've been looking into replacing our nagios installation with something more versatile and have been testing zabbix. I've metered-up a few hosts but have been wondering about whether the data that the zabbix 'agent' coll…

---

## [Missing fields - Postgresql Module](https://discuss.elastic.co/t/missing-fields-postgresql-module/184666)

<div class="topic-metadata">

**Author:** [@zolthar-z](https://discuss.elastic.co/u/zolthar-z)\
**Replies:** 2\
**Last updated:** [June 13, 2019, 9:15am UTC](https://discuss.elastic.co/t/missing-fields-postgresql-module/184666 "2019-06-13T09:15:15Z")

</div>

Hi I'm using filebeat 7.1.0 - PostgreSQL module to send logs from the DB to Elasticsearch, from the logs I want to extract event.duration and log.postgresql.query but filebeat only send this information in some logs and…

---

## [Get Distinct Values with More than 50000](https://discuss.elastic.co/t/get-distinct-values-with-more-than-50000/185162)

<div class="topic-metadata">

**Author:** [@stevetso](https://discuss.elastic.co/u/stevetso)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 9:12am UTC](https://discuss.elastic.co/t/get-distinct-values-with-more-than-50000/185162 "2019-06-13T09:12:53Z")

</div>

Hi, I found an error if the unique count of a field over 50000. Request to Elasticsearch failed: {"error":{"root\_cause":,"type":"search\_phase\_execution\_exception","reason":"","phase":"fetch","grouped":true,"failed\_shar…

---

## [Filebit does not see some of the containers on the host in the kubernetes](https://discuss.elastic.co/t/filebit-does-not-see-some-of-the-containers-on-the-host-in-the-kubernetes/185151)

<div class="topic-metadata">

**Author:** [@pastukhov](https://discuss.elastic.co/u/pastukhov)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 8:38am UTC](https://discuss.elastic.co/t/filebit-does-not-see-some-of-the-containers-on-the-host-in-the-kubernetes/185151 "2019-06-13T08:38:17Z")

</div>

Good day! Today I found that filebit does not collect logs from a part of the containers in my cluster My config: filebeat.config: modules: path: ${path.config}/modules.d/\*.yml reload.enabled…

---

## [Metricbeat metricset in kubernetes module](https://discuss.elastic.co/t/metricbeat-metricset-in-kubernetes-module/184783)

<div class="topic-metadata">

**Author:** [@bhblair](https://discuss.elastic.co/u/bhblair)\
**Replies:** 1\
**Last updated:** [June 13, 2019, 7:32am UTC](https://discuss.elastic.co/t/metricbeat-metricset-in-kubernetes-module/184783 "2019-06-13T07:32:35Z")

</div>

Hi, all. I'm newby to ES and kibana. This is the very first time to use ES with k8s-module, but I don't have any clue. I need any help, please. :frowning: I'd like to bring the same value as the example below, "resour…

---

## [How to configure Accurate metrics projection for CPU/RAM usage](https://discuss.elastic.co/t/how-to-configure-accurate-metrics-projection-for-cpu-ram-usage/184912)

<div class="topic-metadata">

**Author:** [@Ritzy](https://discuss.elastic.co/u/Ritzy)\
**Replies:** 3\
**Last updated:** [June 13, 2019, 5:13am UTC](https://discuss.elastic.co/t/how-to-configure-accurate-metrics-projection-for-cpu-ram-usage/184912 "2019-06-13T05:13:02Z")

</div>

kibana dashboard seems to show cpu usage changes on increments(i'm using metricbeat to ship system metrics). How do I configure the dashboard to project cpu usage on a real time basis.

---

## [Converting logstash to filebeat module strangeness](https://discuss.elastic.co/t/converting-logstash-to-filebeat-module-strangeness/185306)

<div class="topic-metadata">

**Author:** [@SnakeByte](https://discuss.elastic.co/u/SnakeByte)\
**Replies:** 8\
**Last updated:** [June 13, 2019, 12:00am UTC](https://discuss.elastic.co/t/converting-logstash-to-filebeat-module-strangeness/185306 "2019-06-13T00:00:46Z")

</div>

I've created a pipeline in elasticsearch to process some jetty output: PUT \_ingest/pipeline/filebeat-6.7.2-jetty-log-pipeline { "description" : "Ingest pipeline for jetty stderror", "processors": \[ { "grok": { "f…

---

## [Kibana Uptime having an issue (unknown type for collapse field \`monitor.id\`)](https://discuss.elastic.co/t/kibana-uptime-having-an-issue-unknown-type-for-collapse-field-monitor-id/185511)

<div class="topic-metadata">

**Author:** [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Replies:** 3\
**Last updated:** [June 12, 2019, 9:01pm UTC](https://discuss.elastic.co/t/kibana-uptime-having-an-issue-unknown-type-for-collapse-field-monitor-id/185511 "2019-06-12T21:01:57Z")

</div>

Hi, i am having an issue while configure Heartbeat to setup uptime in kibana, it says "Error GraphQL error: \[search\_context\_exception\] unknown type for collapse field monitor.id,", can someone please help me with it, th…

---

## [Filebeat Logstash Multiple Index error](https://discuss.elastic.co/t/filebeat-logstash-multiple-index-error/184845)

<div class="topic-metadata">

**Author:** [@rvjagadheesh](https://discuss.elastic.co/u/rvjagadheesh)\
**Replies:** 1\
**Last updated:** [June 12, 2019, 8:44pm UTC](https://discuss.elastic.co/t/filebeat-logstash-multiple-index-error/184845 "2019-06-12T20:44:15Z")

</div>

Why this config is not creating indexes in Kibana for Filebeat Logstash Multiple Indexes. Using 7.1.1 version filebeat.yml #=========================== Filebeat inputs ============================= filebeat.inputs: …

---

## [Filebeat close\_\* clean\_\* params are confusing. Just want to wait 90s after rotation and then give up](https://discuss.elastic.co/t/filebeat-close-clean-params-are-confusing-just-want-to-wait-90s-after-rotation-and-then-give-up/185485)

<div class="topic-metadata">

**Author:** [@bschaeffer](https://discuss.elastic.co/u/bschaeffer)\
**Replies:** 0\
**Last updated:** [June 12, 2019, 5:31pm UTC](https://discuss.elastic.co/t/filebeat-close-clean-params-are-confusing-just-want-to-wait-90s-after-rotation-and-then-give-up/185485 "2019-06-12T17:31:06Z")

</div>

Howdy. I really don't understand what configuration I need for the docker input to just have filebeat do the following: tail new files (read from head) wait 90s after eof stop tailing file, remove from registry, preten…

---

## [Metricbeat unable to import dashboards](https://discuss.elastic.co/t/metricbeat-unable-to-import-dashboards/184939)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 4\
**Last updated:** [June 12, 2019, 3:50pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-import-dashboards/184939 "2019-06-12T15:50:30Z")

</div>

Hello, I have just installed 7.1.1 with security enabled. I have reconfigured the metricbeat with the credentials but when I am starting it would fail with the following errors: https://pastebin.com/GhD3hH5a The metri…

---

## [Help with Setting up new Index/ dashboards Filebeat 7.1.1 and logstash indexes](https://discuss.elastic.co/t/help-with-setting-up-new-index-dashboards-filebeat-7-1-1-and-logstash-indexes/185405)

<div class="topic-metadata">

**Author:** [@Lee\_Lilleorg-Meilleu](https://discuss.elastic.co/u/Lee_Lilleorg-Meilleu)\
**Replies:** 6\
**Last updated:** [June 12, 2019, 1:46pm UTC](https://discuss.elastic.co/t/help-with-setting-up-new-index-dashboards-filebeat-7-1-1-and-logstash-indexes/185405 "2019-06-12T13:46:55Z")

</div>

Dear Support forum, I have upgraded my ELK to 7.1.1 and wanted to use the plugins and dashboards that filbeat ships with natively however I am unable to get the index to stay consistant. When using file beat and the se…

---

## [Loading list of config parameters into custom beat](https://discuss.elastic.co/t/loading-list-of-config-parameters-into-custom-beat/185238)

<div class="topic-metadata">

**Author:** [@Dede\_Pessu](https://discuss.elastic.co/u/Dede_Pessu)\
**Replies:** 1\
**Last updated:** [June 12, 2019, 1:17pm UTC](https://discuss.elastic.co/t/loading-list-of-config-parameters-into-custom-beat/185238 "2019-06-12T13:17:39Z")

</div>

Is there a way to load a multiple parameters into array/list type structure from your custom beat.yml file? all the custom beat tutorials only show loading one parameter into a singular variable for example... if you h…

---

## [Filebeat path glob support](https://discuss.elastic.co/t/filebeat-path-glob-support/185288)

<div class="topic-metadata">

**Author:** [@SnakeByte](https://discuss.elastic.co/u/SnakeByte)\
**Replies:** 4\
**Last updated:** [June 12, 2019, 2:25am UTC](https://discuss.elastic.co/t/filebeat-path-glob-support/185288 "2019-06-12T02:25:42Z")

</div>

According to the docs: https://www.elastic.co/guide/en/logstash/6.7/glob-support.html It looks like there's some glob support for paths. However, a glob pattern I've written doesn't seem to be getting used by filebeat…

---

## [Using keystore for filebeat user password](https://discuss.elastic.co/t/using-keystore-for-filebeat-user-password/185277)

<div class="topic-metadata">

**Author:** [@marcandre](https://discuss.elastic.co/u/marcandre)\
**Replies:** 0\
**Last updated:** [June 11, 2019, 8:25pm UTC](https://discuss.elastic.co/t/using-keystore-for-filebeat-user-password/185277 "2019-06-11T20:25:54Z")

</div>

Hello, I am trying to follow this: https://www.elastic.co/guide/en/cloud-enterprise/current/ece-configuring-keystore.html#ece-configuring-keystore I want to use the keystore for the filbeat user password. I am using e…

---

## [Backpressure behavior and logging with cgroups](https://discuss.elastic.co/t/backpressure-behavior-and-logging-with-cgroups/185272)

<div class="topic-metadata">

**Author:** [@theterribletrivium](https://discuss.elastic.co/u/theterribletrivium)\
**Replies:** 0\
**Last updated:** [June 11, 2019, 7:40pm UTC](https://discuss.elastic.co/t/backpressure-behavior-and-logging-with-cgroups/185272 "2019-06-11T19:40:59Z")

</div>

I noticed when testing cgroups throttling with auditbeat, the "default" backpressure\_strategy was enabled for auditbeat, if I were to perform a spammy call (i.e. touch /etc/passwd) it would grind to a halt and take over…

---

## [Multiple Heartbeat with one Kibana](https://discuss.elastic.co/t/multiple-heartbeat-with-one-kibana/185260)

<div class="topic-metadata">

**Author:** [@knowvista](https://discuss.elastic.co/u/knowvista)\
**Replies:** 1\
**Last updated:** [June 11, 2019, 7:00pm UTC](https://discuss.elastic.co/t/multiple-heartbeat-with-one-kibana/185260 "2019-06-11T19:00:37Z")

</div>

Hi, Can I install multiple Heartbeats to connect to one Kibana? I just run the checks from multiple geographies.

---

## [Hearbeat](https://discuss.elastic.co/t/hearbeat/185254)

<div class="topic-metadata">

**Author:** [@knowvista](https://discuss.elastic.co/u/knowvista)\
**Replies:** 1\
**Last updated:** [June 11, 2019, 5:49pm UTC](https://discuss.elastic.co/t/hearbeat/185254 "2019-06-11T17:49:02Z")

</div>

Hi, will heartbeat support following features? http monitor - Keyword checking in webpage Reading configurations from database

---

## [Why Filebeat returns Unicode character code instead of XML tag symbol under message, it is showing like \\u003c and \\u003e](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916)

<div class="topic-metadata">

**Author:** [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Replies:** 14\
**Last updated:** [June 11, 2019, 4:54pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916 "2019-06-11T16:54:40Z")

</div>

I'm new here even for ELK. Just trying to use Filebeat to collect XML log and push it to Kafka but Filebeat returns Unicode character code instead of XML tag symbol under message, it is showing like \\u003c and \\u003e. I…

---

## [Issue setting up Filebeat for initial use](https://discuss.elastic.co/t/issue-setting-up-filebeat-for-initial-use/185054)

<div class="topic-metadata">

**Author:** [@RFX](https://discuss.elastic.co/u/RFX)\
**Replies:** 2\
**Last updated:** [June 11, 2019, 4:16pm UTC](https://discuss.elastic.co/t/issue-setting-up-filebeat-for-initial-use/185054 "2019-06-11T16:16:36Z")

</div>

Hi! I am trying to install filebeat to start scanning some logs, and I am trying to get it to work, and I cannot see why it is not. Service starts. It monitors every 30 seconds. The path is correct... but it does not se…

---

## [Error retrieving collection totals from Mongo instance](https://discuss.elastic.co/t/error-retrieving-collection-totals-from-mongo-instance/183007)

<div class="topic-metadata">

**Author:** [@madurad](https://discuss.elastic.co/u/madurad)\
**Replies:** 10\
**Last updated:** [June 11, 2019, 1:42pm UTC](https://discuss.elastic.co/t/error-retrieving-collection-totals-from-mongo-instance/183007 "2019-06-11T13:42:29Z")

</div>

Hello, I'm using metricbeat v6.3 & kibana v6.7.1, recently I'm trying to add my mongoDB stats to metricbeat dashboard and enabled module on mongodb under /etc/metricbeat/module.d/mongodb.yaml using following command. s…

---

## [Syslog input decode json](https://discuss.elastic.co/t/syslog-input-decode-json/182645)

<div class="topic-metadata">

**Author:** [@soerenfrisk](https://discuss.elastic.co/u/soerenfrisk)\
**Replies:** 3\
**Last updated:** [June 11, 2019, 10:40am UTC](https://discuss.elastic.co/t/syslog-input-decode-json/182645 "2019-06-11T10:40:47Z")

</div>

I have a tcp syslog input in filebeat, the incoming data is json. i would want to decode json to top level keys in elastic search. To do this has been quite the challenge for me, and i hope someone is able to help. as t…

---

## [ILM Policy name without beat version number in it](https://discuss.elastic.co/t/ilm-policy-name-without-beat-version-number-in-it/183353)

<div class="topic-metadata">

**Author:** [@msproact](https://discuss.elastic.co/u/msproact)\
**Replies:** 1\
**Last updated:** [June 11, 2019, 9:00am UTC](https://discuss.elastic.co/t/ilm-policy-name-without-beat-version-number-in-it/183353 "2019-06-11T09:00:06Z")

</div>

I do logfile analysis trainings which include the Elastic Stack. I set setup.ilm.policy\_name: metricbeat in /etc/metricbeat/metricbeat.yml in order to have a single ILM policy for different Metricbeat versions. Otherwis…

---

## [Can i use .pfx file instead of .key & ,pem](https://discuss.elastic.co/t/can-i-use-pfx-file-instead-of-key-pem/184880)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 2\
**Last updated:** [June 10, 2019, 5:32pm UTC](https://discuss.elastic.co/t/can-i-use-pfx-file-instead-of-key-pem/184880 "2019-06-10T17:32:54Z")

</div>

To secure the communication between winlogbeat and elk stack i am using .pem, key & ca certificate. Can i use single .pfx instead of .key, .pem & CA files ?

---

## [Tags from dates](https://discuss.elastic.co/t/tags-from-dates/184371)

<div class="topic-metadata">

**Author:** [@thdesy](https://discuss.elastic.co/u/thdesy)\
**Replies:** 1\
**Last updated:** [June 10, 2019, 4:36pm UTC](https://discuss.elastic.co/t/tags-from-dates/184371 "2019-06-10T16:36:55Z")

</div>

Hi all, I would like to tag on a shipper transactions with additional dates, so I tried to run the beat with tags: \["foo", "baz", "%{+yyyy}","%{yyyy.MM}","%{yyyy.MM.dd}",\] assuming that the variables are evaluated. Ho…

---

## [Can Packetbeat just be used to show traffic going from a server?](https://discuss.elastic.co/t/can-packetbeat-just-be-used-to-show-traffic-going-from-a-server/184420)

<div class="topic-metadata">

**Author:** [@nlh](https://discuss.elastic.co/u/nlh)\
**Replies:** 2\
**Last updated:** [June 10, 2019, 4:14pm UTC](https://discuss.elastic.co/t/can-packetbeat-just-be-used-to-show-traffic-going-from-a-server/184420 "2019-06-10T16:14:15Z")

</div>

Not a network expert at all, but have some monitoring set up using Auditbeat and the Elastic Stack. We are interest in identifying files that are being transferred of a server, what the file is called, who requested it …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=346)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=348)
