# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=348

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 349

---

## [No matching indices found: No indices match pattern "packetbeat-\*"](https://discuss.elastic.co/t/no-matching-indices-found-no-indices-match-pattern-packetbeat/184760)

<div class="topic-metadata">

**Author:** [@Richard\_Phillips\_Roy](https://discuss.elastic.co/u/Richard_Phillips_Roy)\
**Replies:** 1\
**Last updated:** [June 10, 2019, 3:56pm UTC](https://discuss.elastic.co/t/no-matching-indices-found-no-indices-match-pattern-packetbeat/184760 "2019-06-10T15:56:44Z")

</div>

I'm running elasticsearch & kibana on machine with ip 7.7.7.4 and packetbeat is running on ip 7.7.7.1, I configured kibana on port 5601 and server host 0.0.0.0 and also configured packetbeat elasticsearch output to 7.7.7…

---

## [Winlogbeat installation error](https://discuss.elastic.co/t/winlogbeat-installation-error/184853)

<div class="topic-metadata">

**Author:** [@sathishpalanu](https://discuss.elastic.co/u/sathishpalanu)\
**Replies:** 3\
**Last updated:** [June 10, 2019, 3:49pm UTC](https://discuss.elastic.co/t/winlogbeat-installation-error/184853 "2019-06-10T15:49:23Z")

</div>

I am getting the error while starting the service post installation. Error Message: "error 1053 the service did not respond to the start or control request in a timely fashion" Window 2016 Server Winlogbeat version: …

---

## [Increasing ignore\_older value fails to ship additional events](https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898)

<div class="topic-metadata">

**Author:** [@bharrisonit](https://discuss.elastic.co/u/bharrisonit)\
**Replies:** 3\
**Last updated:** [June 10, 2019, 3:47pm UTC](https://discuss.elastic.co/t/increasing-ignore-older-value-fails-to-ship-additional-events/184898 "2019-06-10T15:47:28Z")

</div>

Hello! I assume I'm missing something relatively basic here, but my search has yielded little. I'm using OSS agent version 7.0.1 on WIndows 7. Following a successful install of winlogbeat which respects the "ignore\_old…

---

## [Filebeat read same file again](https://discuss.elastic.co/t/filebeat-read-same-file-again/184990)

<div class="topic-metadata">

**Author:** [@OlegInishev](https://discuss.elastic.co/u/OlegInishev)\
**Replies:** 0\
**Last updated:** [June 10, 2019, 12:57pm UTC](https://discuss.elastic.co/t/filebeat-read-same-file-again/184990 "2019-06-10T12:57:48Z")

</div>

Hi everyone I have very extraordinary task. I want read /proc/self/mounts every 1 min (maybe every 5min) and read all lines from file all time. I have next config - type: log paths: - /proc/self/mounts close\_…

---

## [Modules showing up after disabled](https://discuss.elastic.co/t/modules-showing-up-after-disabled/183201)

<div class="topic-metadata">

**Author:** [@Leif](https://discuss.elastic.co/u/Leif)\
**Replies:** 4\
**Last updated:** [June 10, 2019, 4:15am UTC](https://discuss.elastic.co/t/modules-showing-up-after-disabled/183201 "2019-06-10T04:15:15Z")

</div>

We had enabled modules in filebeat by accident and have since disabled them. I cannot figure out how to remove the module fields from the index. I tried creating a new index from the days after the modules in filebeat we…

---

## [How to load audit rules from seperate files](https://discuss.elastic.co/t/how-to-load-audit-rules-from-seperate-files/184692)

<div class="topic-metadata">

**Author:** [@Richard\_Phillips\_Roy](https://discuss.elastic.co/u/Richard_Phillips_Roy)\
**Replies:** 1\
**Last updated:** [June 9, 2019, 2:05am UTC](https://discuss.elastic.co/t/how-to-load-audit-rules-from-seperate-files/184692 "2019-06-09T02:05:24Z")

</div>

How do I start writing rules in audit.rules.d folder do I need to create a file rules.d file and write in it. I'm not seeing any rules when i run auditbeat show auditd-rules

---

## [\[7.0.1\] Journalbeat not processing Elasticsearch Log4j ESJsonLayout logs properly?](https://discuss.elastic.co/t/7-0-1-journalbeat-not-processing-elasticsearch-log4j-esjsonlayout-logs-properly/184673)

<div class="topic-metadata">

**Author:** [@naisanza](https://discuss.elastic.co/u/naisanza)\
**Replies:** 2\
**Last updated:** [June 7, 2019, 9:05pm UTC](https://discuss.elastic.co/t/7-0-1-journalbeat-not-processing-elasticsearch-log4j-esjsonlayout-logs-properly/184673 "2019-06-07T21:05:20Z")

</div>

This entire code block is from the "message" field that journalbeat has shipped from an elasticsearch node, and it ends with a comma { "type": "server", "timestamp": "2019-06-06T22:50:40,854+0000", "level": "DEBUG", "co…

---

## [Cannot specify index name on elastic cloud](https://discuss.elastic.co/t/cannot-specify-index-name-on-elastic-cloud/184674)

<div class="topic-metadata">

**Author:** [@bitcoin](https://discuss.elastic.co/u/bitcoin)\
**Replies:** 2\
**Last updated:** [June 7, 2019, 6:24pm UTC](https://discuss.elastic.co/t/cannot-specify-index-name-on-elastic-cloud/184674 "2019-06-07T18:24:54Z")

</div>

Hello wonderful people! I would like to create different indexes for each environment that I have (test / staging / production) I am using elastic cloud setup with filebeat 7.1.x but I cannot specify custom index name …

---

## [How can filebeat queue.mem send more than queue.mem.events to output?](https://discuss.elastic.co/t/how-can-filebeat-queue-mem-send-more-than-queue-mem-events-to-output/184639)

<div class="topic-metadata">

**Author:** [@bschaeffer](https://discuss.elastic.co/u/bschaeffer)\
**Replies:** 3\
**Last updated:** [June 7, 2019, 4:13pm UTC](https://discuss.elastic.co/t/how-can-filebeat-queue-mem-send-more-than-queue-mem-events-to-output/184639 "2019-06-07T16:13:47Z")

</div>

I am just trying to understand how, after a log load test has stopped producing logs and files have been rotated and deleted, filebeat continues to send 100s of thousands of log messages (in my case 1MM) to my output ove…

---

## [Filebeat on Centos7 not properly starting or logging](https://discuss.elastic.co/t/filebeat-on-centos7-not-properly-starting-or-logging/184646)

<div class="topic-metadata">

**Author:** [@bdobsonbcm](https://discuss.elastic.co/u/bdobsonbcm)\
**Replies:** 2\
**Last updated:** [June 7, 2019, 3:46pm UTC](https://discuss.elastic.co/t/filebeat-on-centos7-not-properly-starting-or-logging/184646 "2019-06-07T15:46:59Z")

</div>

Filebeat Version 7.1.1 I have been using Filebeat, without issue on our CentOS6 machines and have started to roll it out to our CentOS7 machines. I have installed via the following repository: \[elasticsearch-7.x\] name…

---

## [Undocumented changes from Filebeat 6.7 to 7.0/7.1?](https://discuss.elastic.co/t/undocumented-changes-from-filebeat-6-7-to-7-0-7-1/184233)

<div class="topic-metadata">

**Author:** [@LollerAgent](https://discuss.elastic.co/u/LollerAgent)\
**Replies:** 4\
**Last updated:** [June 7, 2019, 1:08pm UTC](https://discuss.elastic.co/t/undocumented-changes-from-filebeat-6-7-to-7-0-7-1/184233 "2019-06-07T13:08:00Z")

</div>

We're working on upgrading from 6.6/6/7 to 7.1 and have noticed the following changes which we can't find mentions of in the release notes and/or documentation: When using add\_docker\_metadata, \[container\] used to be n…

---

## [Kafka Module Metricbeat on Kerberized cluster - jaas file](https://discuss.elastic.co/t/kafka-module-metricbeat-on-kerberized-cluster-jaas-file/184724)

<div class="topic-metadata">

**Author:** [@phgolard](https://discuss.elastic.co/u/phgolard)\
**Replies:** 4\
**Last updated:** [June 7, 2019, 12:06pm UTC](https://discuss.elastic.co/t/kafka-module-metricbeat-on-kerberized-cluster-jaas-file/184724 "2019-06-07T12:06:22Z")

</div>

Hello, On our kerberized cloudera hadoop cluster I tried to set up metricbeat kafka module to collect metricsets consumergroup and partitions. I set up the following kafka.yml - module: kafka period: 10s metricset…

---

## [GitHub Issue #11975 (kubernetes cores field types)](https://discuss.elastic.co/t/github-issue-11975-kubernetes-cores-field-types/184709)

<div class="topic-metadata">

**Author:** [@easkay](https://discuss.elastic.co/u/easkay)\
**Replies:** 2\
**Last updated:** [June 7, 2019, 10:21am UTC](https://discuss.elastic.co/t/github-issue-11975-kubernetes-cores-field-types/184709 "2019-06-07T10:21:40Z")

</div>

Hi folks, I was thinking of picking up this issue as it's a problem that we ran into and will likely need to fix soon. Is anyone already working on it or is there anything I should bear in mind when altering the fields? …

---

## [Filebeat stoped to write logs after K8S upgrade to 1.14.1 ver](https://discuss.elastic.co/t/filebeat-stoped-to-write-logs-after-k8s-upgrade-to-1-14-1-ver/183870)

<div class="topic-metadata">

**Author:** [@aleksei.saiko](https://discuss.elastic.co/u/aleksei.saiko)\
**Replies:** 4\
**Last updated:** [June 7, 2019, 8:11am UTC](https://discuss.elastic.co/t/filebeat-stoped-to-write-logs-after-k8s-upgrade-to-1-14-1-ver/183870 "2019-06-07T08:11:15Z")

</div>

Hi there! After upgrading the K8S ver from 1.10 to 1.14.1 ver, our filebeat stoped to write logs. I did found something in k8s doc - The container log directory changed from /var/lib/docker/ to /var/log/pods/ . If y…

---

## [Upgrade winlogbeat 7.0 to 7.1](https://discuss.elastic.co/t/upgrade-winlogbeat-7-0-to-7-1/184641)

<div class="topic-metadata">

**Author:** [@greyfire](https://discuss.elastic.co/u/greyfire)\
**Replies:** 1\
**Last updated:** [June 7, 2019, 7:46am UTC](https://discuss.elastic.co/t/upgrade-winlogbeat-7-0-to-7-1/184641 "2019-06-07T07:46:26Z")

</div>

How exactly does one upgrade the winlogbeat agent on a windows host as the docs are really quite lacking. I am running the beat as a service. I tried copying all of the new files and running the uninstall and install pow…

---

## [Error connecting to Kibana](https://discuss.elastic.co/t/error-connecting-to-kibana/184294)

<div class="topic-metadata">

**Author:** [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Replies:** 5\
**Last updated:** [June 7, 2019, 7:17am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294 "2019-06-07T07:17:03Z")

</div>

Hi, when i was typing metricbeat setup then this error appear \[root@localhost share\]# metricbeat setup Index setup complete. Loading dashboards (Kibana must be running and reachable) Exiting: error connecting t…

---

## [\[Solved\] Indexes does not automatically created based on new date](https://discuss.elastic.co/t/solved-indexes-does-not-automatically-created-based-on-new-date/183640)

<div class="topic-metadata">

**Author:** [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Replies:** 3\
**Last updated:** [June 7, 2019, 6:44am UTC](https://discuss.elastic.co/t/solved-indexes-does-not-automatically-created-based-on-new-date/183640 "2019-06-07T06:44:17Z")

</div>

Hello, I have this small problem where I realized my beats are not creating new indexes as the day goes by. All data are stored in a single index which doesn't look good and can be a problem it was deleted. This proble…

---

## [Filebeat - Multiline: Ingest XML’s log file without end of last XML tag](https://discuss.elastic.co/t/filebeat-multiline-ingest-xml-s-log-file-without-end-of-last-xml-tag/184019)

<div class="topic-metadata">

**Author:** [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Replies:** 2\
**Last updated:** [June 7, 2019, 6:43am UTC](https://discuss.elastic.co/t/filebeat-multiline-ingest-xml-s-log-file-without-end-of-last-xml-tag/184019 "2019-06-07T06:43:05Z")

</div>

I have logs file in XML format and I'm using Filebeat to collect these file and push it to Kafka topic. These XML files end without line feed, this filebeat multiline codec never forwards the last line of the XML to Kafk…

---

## [Filebeat read log slow when registry file is too large](https://discuss.elastic.co/t/filebeat-read-log-slow-when-registry-file-is-too-large/184184)

<div class="topic-metadata">

**Author:** [@jasper-zhang](https://discuss.elastic.co/u/jasper-zhang)\
**Replies:** 8\
**Last updated:** [June 6, 2019, 11:24am UTC](https://discuss.elastic.co/t/filebeat-read-log-slow-when-registry-file-is-too-large/184184 "2019-06-06T11:24:51Z")

</div>

Hello, When the registry file is about 13M, read log is about 1w/s. But when I remove the registry file then restart filebeat, read log grow up to 7w/s. can the size of registry file affect reading speed ?

---

## [Setting up Winlogbeats with Logstash issues](https://discuss.elastic.co/t/setting-up-winlogbeats-with-logstash-issues/164185)

<div class="topic-metadata">

**Author:** [@ciphee](https://discuss.elastic.co/u/ciphee)\
**Replies:** 2\
**Last updated:** [June 7, 2019, 1:16am UTC](https://discuss.elastic.co/t/setting-up-winlogbeats-with-logstash-issues/164185 "2019-06-07T01:16:13Z")

</div>

Hi there, I am trying to test out setting up 1 windows host and sending winlogbeat data to logstash. So far I have opened up a pipeline in logstash for beats, then configured the winlogbeat.yml file to point to logstash…

---

## [APP, Filebeat, and ELK - Local build works but when using Ansible, things go astray](https://discuss.elastic.co/t/app-filebeat-and-elk-local-build-works-but-when-using-ansible-things-go-astray/184670)

<div class="topic-metadata">

**Author:** [@ryh](https://discuss.elastic.co/u/ryh)\
**Replies:** 3\
**Last updated:** [June 6, 2019, 10:54pm UTC](https://discuss.elastic.co/t/app-filebeat-and-elk-local-build-works-but-when-using-ansible-things-go-astray/184670 "2019-06-06T22:54:19Z")

</div>

Hi All, I need your help. When I'm building my ELK stack with Filebeat and an app locally, I'm able to see my fields and messages are clear. But when I use Ansible, things go completely wrong. Below are my configs for …

---

## [Filebeat running on remote serverand sending logs to elasticsearch but not visible on kibana](https://discuss.elastic.co/t/filebeat-running-on-remote-serverand-sending-logs-to-elasticsearch-but-not-visible-on-kibana/184265)

<div class="topic-metadata">

**Author:** [@sandra1234](https://discuss.elastic.co/u/sandra1234)\
**Replies:** 14\
**Last updated:** [June 6, 2019, 9:56pm UTC](https://discuss.elastic.co/t/filebeat-running-on-remote-serverand-sending-logs-to-elasticsearch-but-not-visible-on-kibana/184265 "2019-06-06T21:56:07Z")

</div>

Hi, i have my elastic search configured as master and data node on same machine. The filebeats installed on that machine ships logs to kibana and its indexed but when i install filebeat on the remote server , and point i…

---

## [Packetbeat 7.1 and Geoip setup](https://discuss.elastic.co/t/packetbeat-7-1-and-geoip-setup/182510)

<div class="topic-metadata">

**Author:** [@Marcell0e](https://discuss.elastic.co/u/Marcell0e)\
**Replies:** 31\
**Last updated:** [June 3, 2019, 5:32pm UTC](https://discuss.elastic.co/t/packetbeat-7-1-and-geoip-setup/182510 "2019-06-03T17:32:25Z")

</div>

I am really new to Elasticsearch and all the components. I am trying to use the GeoIp with Packetbeat 7.1 and I can't figure out how to make it work. I am trying to use the following documentation. None of the Geo fie…

---

## [Correct formatting for using OR and WHEN condition in a processor](https://discuss.elastic.co/t/correct-formatting-for-using-or-and-when-condition-in-a-processor/184640)

<div class="topic-metadata">

**Author:** [@Joseph\_Gange](https://discuss.elastic.co/u/Joseph_Gange)\
**Replies:** 1\
**Last updated:** [June 6, 2019, 7:28pm UTC](https://discuss.elastic.co/t/correct-formatting-for-using-or-and-when-condition-in-a-processor/184640 "2019-06-06T19:28:28Z")

</div>

My filebeat config consists of the following relevant snippet- Blockquote decode\_json\_fields: when: contains: docker.container.labels.com.docker.swarm.service.name: "name" fields: \["message"\] process\_array: fal…

---

## [Packetbeat Conundrum](https://discuss.elastic.co/t/packetbeat-conundrum/183781)

<div class="topic-metadata">

**Author:** [@thev0yager](https://discuss.elastic.co/u/thev0yager)\
**Replies:** 24\
**Last updated:** [June 6, 2019, 7:21pm UTC](https://discuss.elastic.co/t/packetbeat-conundrum/183781 "2019-06-06T19:21:33Z")

</div>

Hi All, right now I just talked with some wonderful engineers at Elastic about a little problem I have been having with my deployment. I have a very bear bones setup of the Elastic Stack, and I am having an issue with my…

---

## [Unable to start HeartBeat](https://discuss.elastic.co/t/unable-to-start-heartbeat/181129)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 45\
**Last updated:** [June 6, 2019, 6:00pm UTC](https://discuss.elastic.co/t/unable-to-start-heartbeat/181129 "2019-06-06T18:00:21Z")

</div>

Hi I am new on this and starting to configure this feature. Unfortunately I am facing some difficulties getting the module to work. When executing : systemctl start heartbeat Results: Failed to start heartbeat.service:…

---

## [Hitting error getting heartbeat from Elasticsearch with SSL](https://discuss.elastic.co/t/hitting-error-getting-heartbeat-from-elasticsearch-with-ssl/184245)

<div class="topic-metadata">

**Author:** [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Replies:** 2\
**Last updated:** [June 6, 2019, 5:55pm UTC](https://discuss.elastic.co/t/hitting-error-getting-heartbeat-from-elasticsearch-with-ssl/184245 "2019-06-06T17:55:05Z")

</div>

This as working fine vefore converting to https. I have tried a number of modifications but still stuck on getting this to work. Below is my error and heartbeat configuration \[2019-06-04T19:21:17,067\]\[WARN \]\[o.e.h.Abs…

---

## [Auditbeat disable login log](https://discuss.elastic.co/t/auditbeat-disable-login-log/182856)

<div class="topic-metadata">

**Author:** [@nopma](https://discuss.elastic.co/u/nopma)\
**Replies:** 1\
**Last updated:** [June 6, 2019, 5:50pm UTC](https://discuss.elastic.co/t/auditbeat-disable-login-log/182856 "2019-06-06T17:50:08Z")

</div>

Hello all, I run auditbeat 7.1.0 and i can't disable the ssh log for auditbeat. On the graylog i get this: auditbeat\_auditd\_data\_op PAM:session\_open auditbeat\_auditd\_data\_terminal ssh On the auditbeat config fil…

---

## [Function could not deploy, error: bucket 'abc' already exist and you don't have permission to access it](https://discuss.elastic.co/t/function-could-not-deploy-error-bucket-abc-already-exist-and-you-dont-have-permission-to-access-it/184467)

<div class="topic-metadata">

**Author:** [@mac65](https://discuss.elastic.co/u/mac65)\
**Replies:** 5\
**Last updated:** [June 6, 2019, 4:28pm UTC](https://discuss.elastic.co/t/function-could-not-deploy-error-bucket-abc-already-exist-and-you-dont-have-permission-to-access-it/184467 "2019-06-06T16:28:24Z")

</div>

Hi, I'm having the same issue as https://discuss.elastic.co/t/unable-to-deploy-functionbeat-to-s3-bucket/171371/3, using Function Beat 7.1.1 Linux x86\_64. I do have full access to the bucket, and it does exist: aws s3 …

---

## [How to configure Beat to log to a specific Syslog facility](https://discuss.elastic.co/t/how-to-configure-beat-to-log-to-a-specific-syslog-facility/184458)

<div class="topic-metadata">

**Author:** [@stoth](https://discuss.elastic.co/u/stoth)\
**Replies:** 2\
**Last updated:** [June 6, 2019, 3:16pm UTC](https://discuss.elastic.co/t/how-to-configure-beat-to-log-to-a-specific-syslog-facility/184458 "2019-06-06T15:16:39Z")

</div>

Hello, I've written a custom beat that I want to log to a specific Syslog facility. I'm aware of the configuration to enable logging to Syslog, but I can't figure out how to log to a specific Syslog facility (ex. LOCAL6…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=347)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=349)
