# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=349

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 350

---

## [Custom indexname not triggered](https://discuss.elastic.co/t/custom-indexname-not-triggered/184605)

<div class="topic-metadata">

**Author:** [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Replies:** 1\
**Last updated:** [June 6, 2019, 2:58pm UTC](https://discuss.elastic.co/t/custom-indexname-not-triggered/184605 "2019-06-06T14:58:12Z")

</div>

Hi, this is the config I am using: filebeat.inputs: - type: log paths: - /Users/peter/es-stack/datasets/nyc\_collision\_data.csv output.elasticsearch: hosts: \["localhost:9200"\] index: "nyc\_visionzero" pipeli…

---

## [Specifying SSL settings for managed Metricbeat](https://discuss.elastic.co/t/specifying-ssl-settings-for-managed-metricbeat/184601)

<div class="topic-metadata">

**Author:** [@bobes](https://discuss.elastic.co/u/bobes)\
**Replies:** 2\
**Last updated:** [June 6, 2019, 2:43pm UTC](https://discuss.elastic.co/t/specifying-ssl-settings-for-managed-metricbeat/184601 "2019-06-06T14:43:02Z")

</div>

I've enabled a Metricbeat to use CM, before I had configurations to deal with SSL in the YAML of the Beat. Now that its managed where do I define these settings? I attempted to define then in the metricbeat.yml file, but…

---

## [Filebeat stops collecting docker logs after sometime](https://discuss.elastic.co/t/filebeat-stops-collecting-docker-logs-after-sometime/184567)

<div class="topic-metadata">

**Author:** [@gauravsachan07](https://discuss.elastic.co/u/gauravsachan07)\
**Replies:** 1\
**Last updated:** [June 6, 2019, 11:08am UTC](https://discuss.elastic.co/t/filebeat-stops-collecting-docker-logs-after-sometime/184567 "2019-06-06T11:08:05Z")

</div>

I have configured filebeat v7.1.0 to autodiscover a particular docker container and send the docker logs to logstash which inturn sends them to elastic search. We are using docker images. When we start the containers it …

---

## [Load packetbeat Dashboard into Kibana with localhost access only](https://discuss.elastic.co/t/load-packetbeat-dashboard-into-kibana-with-localhost-access-only/184476)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 2\
**Last updated:** [June 6, 2019, 10:07am UTC](https://discuss.elastic.co/t/load-packetbeat-dashboard-into-kibana-with-localhost-access-only/184476 "2019-06-06T10:07:39Z")

</div>

I can't seem to get this right. If I have the ELK stack running in Linux and I want to load the packetbeat dashboard from a remote Windows host The issue however is that elasticsearch and kibana are only accessible loc…

---

## [Drop beginning of JSON log](https://discuss.elastic.co/t/drop-beginning-of-json-log/184202)

<div class="topic-metadata">

**Author:** [@SantZP](https://discuss.elastic.co/u/SantZP)\
**Replies:** 3\
**Last updated:** [June 6, 2019, 8:18am UTC](https://discuss.elastic.co/t/drop-beginning-of-json-log/184202 "2019-06-06T08:18:16Z")

</div>

Hi! Im trying to parse the following JSON log in FileBeat but i keep getting error.message: "Error decoding JSON: invalid character 'J' looking for beginning of value: " JSON Authentication: {"timestamp": "2019-06-04T1…

---

## [Filebeat 5.3 sends to elasticsearch 7.0.1](https://discuss.elastic.co/t/filebeat-5-3-sends-to-elasticsearch-7-0-1/184482)

<div class="topic-metadata">

**Author:** [@OcanGo](https://discuss.elastic.co/u/OcanGo)\
**Replies:** 2\
**Last updated:** [June 6, 2019, 7:09am UTC](https://discuss.elastic.co/t/filebeat-5-3-sends-to-elasticsearch-7-0-1/184482 "2019-06-06T07:09:50Z")

</div>

I send to elasticsearch 5.3 by using filebeat 5.3 before.Now, a new elasticsearch(7.0.1) is installed into a new server.When I want to sends to elasticsearch(7.0.1) by filebeat 5.3.It seems that because elasticsearch(7.…

---

## [Log files are missing/deleted during log rotation](https://discuss.elastic.co/t/log-files-are-missing-deleted-during-log-rotation/184493)

<div class="topic-metadata">

**Author:** [@Sharath\_Thrishuleshw](https://discuss.elastic.co/u/Sharath_Thrishuleshw)\
**Replies:** 0\
**Last updated:** [June 6, 2019, 4:59am UTC](https://discuss.elastic.co/t/log-files-are-missing-deleted-during-log-rotation/184493 "2019-06-06T04:59:43Z")

</div>

When using filebeat version 7.0.0, the latest log files are missing after rotation. I am using logback + slf4j for logging, log rotation in tomcat This does not happen always, but randomly When not running filebeat I …

---

## [Set Index pattern name in Kibana by auditbeat setup](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242)

<div class="topic-metadata">

**Author:** [@thekm1](https://discuss.elastic.co/u/thekm1)\
**Replies:** 4\
**Last updated:** [June 6, 2019, 5:02am UTC](https://discuss.elastic.co/t/set-index-pattern-name-in-kibana-by-auditbeat-setup/184242 "2019-06-06T05:02:48Z")

</div>

For kibana setup from audit beat: (In the both verision I am discribing below, I am using the parameter setup.dashboard.index from "./auditbeat setup" command to set the index-pattern title ) in Version 6.7, I was able…

---

## [Heartbeat-elastic site monitoring error (Web down)](https://discuss.elastic.co/t/heartbeat-elastic-site-monitoring-error-web-down/184112)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 2\
**Last updated:** [June 6, 2019, 3:07am UTC](https://discuss.elastic.co/t/heartbeat-elastic-site-monitoring-error-web-down/184112 "2019-06-06T03:07:18Z")

</div>

Error Msg: Head https://xx.org/: dial tcp 202.xx.xx.xx:443: i/o timeout (Client.Timeout exceeded while awaiting headers) May I know does anyone faced this before? Which part has caused this issue? Is it Uptime service …

---

## [Wildcard in provider(Source) name not working](https://discuss.elastic.co/t/wildcard-in-provider-source-name-not-working/184228)

<div class="topic-metadata">

**Author:** [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Replies:** 2\
**Last updated:** [June 6, 2019, 1:19am UTC](https://discuss.elastic.co/t/wildcard-in-provider-source-name-not-working/184228 "2019-06-06T01:19:18Z")

</div>

hi, im using winlogbeat 6.7.1 version for collecting event logs. I have a lot of application witch all starts with the same name on the beginning and it will be very useful to filter application by using application name…

---

## [File/Packet/Metric beat on Raspi Centos 7 (armhf/armv7l)](https://discuss.elastic.co/t/file-packet-metric-beat-on-raspi-centos-7-armhf-armv7l/184048)

<div class="topic-metadata">

**Author:** [@m.pers](https://discuss.elastic.co/u/m.pers)\
**Replies:** 5\
**Last updated:** [June 6, 2019, 1:02am UTC](https://discuss.elastic.co/t/file-packet-metric-beat-on-raspi-centos-7-armhf-armv7l/184048 "2019-06-06T01:02:18Z")

</div>

Is there a build of packetbeat and filebeat for centos 7(armhf/armv7l arch) on the raspberry pi 3B+? I know raspbian has one but I am looking specifically for a build on Centos 7 with armv7l architecture or one close eno…

---

## [File beat does not post the data to elk stack](https://discuss.elastic.co/t/file-beat-does-not-post-the-data-to-elk-stack/184396)

<div class="topic-metadata">

**Author:** [@atul.bhingarde](https://discuss.elastic.co/u/atul.bhingarde)\
**Replies:** 3\
**Last updated:** [June 5, 2019, 8:32pm UTC](https://discuss.elastic.co/t/file-beat-does-not-post-the-data-to-elk-stack/184396 "2019-06-05T20:32:56Z")

</div>

I have setup the file beat on one of the server and am trying to post the data from apache access log to the elk stack. I am unable to see the logs in logstash Thanks Atul

---

## [Filebeat on Kubernetes setup pipelines](https://discuss.elastic.co/t/filebeat-on-kubernetes-setup-pipelines/184430)

<div class="topic-metadata">

**Author:** [@zx10r](https://discuss.elastic.co/u/zx10r)\
**Replies:** 0\
**Last updated:** [June 5, 2019, 5:35pm UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-setup-pipelines/184430 "2019-06-05T17:35:55Z")

</div>

We are using filebeat in kubernetes to output to logstash. In order for the modules we use to be correctly parsed via pipelines and ingest nodes this needs to be enabled somehow but currently i see no way to pass it or e…

---

## [Metricbeat performance](https://discuss.elastic.co/t/metricbeat-performance/183763)

<div class="topic-metadata">

**Author:** [@fdmsantos](https://discuss.elastic.co/u/fdmsantos)\
**Replies:** 4\
**Last updated:** [June 5, 2019, 3:29pm UTC](https://discuss.elastic.co/t/metricbeat-performance/183763 "2019-06-05T15:29:16Z")

</div>

Hello, I'm developing a beat based on metricbeat. I use the report.Event to send an event. There is any way to improve the performance of this method? Exists any way to send an array of Events to the buffer instead o…

---

## [\[ERROR\] - Kubernetes Module - reading bearer token file](https://discuss.elastic.co/t/error-kubernetes-module-reading-bearer-token-file/183408)

<div class="topic-metadata">

**Author:** [@grfneto](https://discuss.elastic.co/u/grfneto)\
**Replies:** 6\
**Last updated:** [June 5, 2019, 2:52pm UTC](https://discuss.elastic.co/t/error-kubernetes-module-reading-bearer-token-file/183408 "2019-06-05T14:52:19Z")

</div>

Hi everyone. I have Kubernetes 1.14.1, tried monitoring my cluster with Metricbeat 6.6.1 and Elasticsearch/Kibana. I used the follow configuration in kubernetes.yml: - module: kubernetes metricsets: - node -…

---

## [Filebeat 7.1.1 default template do not have a geoip coordinate](https://discuss.elastic.co/t/filebeat-7-1-1-default-template-do-not-have-a-geoip-coordinate/184392)

<div class="topic-metadata">

**Author:** [@Ronan\_Robineau](https://discuss.elastic.co/u/Ronan_Robineau)\
**Replies:** 0\
**Last updated:** [June 5, 2019, 2:45pm UTC](https://discuss.elastic.co/t/filebeat-7-1-1-default-template-do-not-have-a-geoip-coordinate/184392 "2019-06-05T14:45:10Z")

</div>

Hi! I'm configuring an ELK with filebeat and Suricata (IDS). By default, I setup my template like this: filebeat setup -e -E output.logstash.enabled=false -E "output.elasticsearch.hosts=\['localhost:9200'\]" -E setup.k…

---

## [Filebeat apache module unable to parse certain logs](https://discuss.elastic.co/t/filebeat-apache-module-unable-to-parse-certain-logs/184279)

<div class="topic-metadata">

**Author:** [@alloystory](https://discuss.elastic.co/u/alloystory)\
**Replies:** 6\
**Last updated:** [June 5, 2019, 2:10pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-unable-to-parse-certain-logs/184279 "2019-06-05T14:10:55Z")

</div>

Hi all, I have a couple of lines in my apache access logs that cannot be parsed by the default apache module. After some testing, I found that: Does not work: 123.123.123.123 - - \[04/Jun/2019:12:25:00 +0000\] "-" 400 …

---

## [Filebeat failing way way behind when shipping output](https://discuss.elastic.co/t/filebeat-failing-way-way-behind-when-shipping-output/184368)

<div class="topic-metadata">

**Author:** [@bschaeffer](https://discuss.elastic.co/u/bschaeffer)\
**Replies:** 0\
**Last updated:** [June 5, 2019, 1:32pm UTC](https://discuss.elastic.co/t/filebeat-failing-way-way-behind-when-shipping-output/184368 "2019-06-05T13:32:42Z")

</div>

Hey all! We are attempting to load test filebeat for shipping our kubernetes logs. Our current max log line rate on any given node is 5000/s, so we are load testing 7500 lines/s. We do this by spinning up a single pod w…

---

## [Event stopped process](https://discuss.elastic.co/t/event-stopped-process/182891)

<div class="topic-metadata">

**Author:** [@holiveira](https://discuss.elastic.co/u/holiveira)\
**Replies:** 4\
**Last updated:** [June 5, 2019, 12:32pm UTC](https://discuss.elastic.co/t/event-stopped-process/182891 "2019-06-05T12:32:11Z")

</div>

how to capture the status of the process when it is interrupted? I only have the status when it is running and sometimes I get a process status that has stopped. Auditbeat 7.1.0 (Windows Server 2008 R2) Elasticsearch 7…

---

## [Winlogbeat not creating daily indexes](https://discuss.elastic.co/t/winlogbeat-not-creating-daily-indexes/184322)

<div class="topic-metadata">

**Author:** [@srdegeus](https://discuss.elastic.co/u/srdegeus)\
**Replies:** 2\
**Last updated:** [June 5, 2019, 10:30am UTC](https://discuss.elastic.co/t/winlogbeat-not-creating-daily-indexes/184322 "2019-06-05T10:30:54Z")

</div>

I have taken over an elasticsearch 6.6.2 environment which was a proof of concept to centralize event\_logs monitoring. I have upgraded the servers to Windows 2019 and elasticsearch to 7.1.0 (and now 7.1.1) and added a d…

---

## [Auditbeat 7.x on CentOS 7 logging to /var/log/messages](https://discuss.elastic.co/t/auditbeat-7-x-on-centos-7-logging-to-var-log-messages/183421)

<div class="topic-metadata">

**Author:** [@mbakkes](https://discuss.elastic.co/u/mbakkes)\
**Replies:** 2\
**Last updated:** [June 5, 2019, 10:10am UTC](https://discuss.elastic.co/t/auditbeat-7-x-on-centos-7-logging-to-var-log-messages/183421 "2019-06-05T10:10:45Z")

</div>

It will ignore any settings in the service or the auditbeat.yml and always log straight to var log messages. This issue doesn't occur in RHEL 7.

---

## [Filebeat start too long when registry is too large](https://discuss.elastic.co/t/filebeat-start-too-long-when-registry-is-too-large/184177)

<div class="topic-metadata">

**Author:** [@jasper-zhang](https://discuss.elastic.co/u/jasper-zhang)\
**Replies:** 2\
**Last updated:** [June 5, 2019, 8:34am UTC](https://discuss.elastic.co/t/filebeat-start-too-long-when-registry-is-too-large/184177 "2019-06-05T08:34:07Z")

</div>

My registry is about 13M. When I restart Filebeat, It spends about 2 hours before start Harvester.

---

## [Filebeats not sendind any logs (Already enable)](https://discuss.elastic.co/t/filebeats-not-sendind-any-logs-already-enable/184298)

<div class="topic-metadata">

**Author:** [@this](https://discuss.elastic.co/u/this)\
**Replies:** 1\
**Last updated:** [June 5, 2019, 8:33am UTC](https://discuss.elastic.co/t/filebeats-not-sendind-any-logs-already-enable/184298 "2019-06-05T08:33:49Z")

</div>

My config looks like filebeat.prospectors: - type: log enabled: true paths: - /opt/app/logs/info.log output.file: path: "/tmp/filebeat" filename: filebeat logging.level: debug logging.to\_files: true logging…

---

## [\[TCP Input\] Token too long](https://discuss.elastic.co/t/tcp-input-token-too-long/184290)

<div class="topic-metadata">

**Author:** [@Valker](https://discuss.elastic.co/u/Valker)\
**Replies:** 1\
**Last updated:** [June 5, 2019, 7:50am UTC](https://discuss.elastic.co/t/tcp-input-token-too-long/184290 "2019-06-05T07:50:40Z")

</div>

Hello, I think I have found an issue with the TCP input module of the Filebeat. When I tried to send multiple long json messages as a batch, while some of them are really long (like 7.5K characters), I got an error in …

---

## [Auditbeat getsockopt: connection refused](https://discuss.elastic.co/t/auditbeat-getsockopt-connection-refused/183118)

<div class="topic-metadata">

**Author:** [@Richard\_Phillips\_Roy](https://discuss.elastic.co/u/Richard_Phillips_Roy)\
**Replies:** 4\
**Last updated:** [June 5, 2019, 2:56am UTC](https://discuss.elastic.co/t/auditbeat-getsockopt-connection-refused/183118 "2019-06-05T02:56:37Z")

</div>

I'm running elasticsearch and kibana on the host machine and i want to send the auditbeat data from ubuntu running on virtual box to the host machine please help me with it.

---

## [Filebeat - IIS Module Questions (search, pipeline, grok)](https://discuss.elastic.co/t/filebeat-iis-module-questions-search-pipeline-grok/183333)

<div class="topic-metadata">

**Author:** [@itguy\_chris](https://discuss.elastic.co/u/itguy_chris)\
**Replies:** 0\
**Last updated:** [May 29, 2019, 12:48pm UTC](https://discuss.elastic.co/t/filebeat-iis-module-questions-search-pipeline-grok/183333 "2019-05-29T12:48:56Z")

</div>

Hi All, Using ES 7.0, FB 7.0 using just the IIS Module for now... I have a few questions: The field iis.access.cookie; I am trying to figure out in Kibana how to search (under discovery) for the context of the ASP.…

---

## [X509: cannot validate certificate for 192.168.0.85 because it doesn't contain any IP SANs](https://discuss.elastic.co/t/x509-cannot-validate-certificate-for-192-168-0-85-because-it-doesnt-contain-any-ip-sans/183691)

<div class="topic-metadata">

**Author:** [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Replies:** 2\
**Last updated:** [June 5, 2019, 5:02am UTC](https://discuss.elastic.co/t/x509-cannot-validate-certificate-for-192-168-0-85-because-it-doesnt-contain-any-ip-sans/183691 "2019-06-05T05:02:42Z")

</div>

Hello I'm just start 7.1 ES & KB & Metricbeat I have an error my metricbeat.yml #============================== Kibana ===================================== setup.kibana: host: "https://192.168.0.85:5601" #------…

---

## [Metricbeat 7.0.1 Windows Module Services](https://discuss.elastic.co/t/metricbeat-7-0-1-windows-module-services/181565)

<div class="topic-metadata">

**Author:** [@Michi](https://discuss.elastic.co/u/Michi)\
**Replies:** 6\
**Last updated:** [June 5, 2019, 4:23am UTC](https://discuss.elastic.co/t/metricbeat-7-0-1-windows-module-services/181565 "2019-06-05T04:23:14Z")

</div>

I have a problem with the Metricbeat Windows module, I only want to monitor 5 specific services in the service monitoring. But it always transfers all events to Elasticsearch. I've tried filtering like this in the examp…

---

## [\[SOLVED\]How to remove agent.\* and ecs.version?](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643)

<div class="topic-metadata">

**Author:** [@Duked](https://discuss.elastic.co/u/Duked)\
**Replies:** 7\
**Last updated:** [June 5, 2019, 12:51am UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643 "2019-06-05T00:51:05Z")

</div>

Hi, I've tried disabling all the processor metadata and somehow narrowed it down but I still can't get rid of agent.ephemeral\_id, agent.hostname, agent.id, agent.type, agent.version and ecs.version and log.offset. Is …

---

## [Multiple processors with same name - add\_tags](https://discuss.elastic.co/t/multiple-processors-with-same-name-add-tags/184060)

<div class="topic-metadata">

**Author:** [@jepe](https://discuss.elastic.co/u/jepe)\
**Replies:** 2\
**Last updated:** [June 4, 2019, 8:16pm UTC](https://discuss.elastic.co/t/multiple-processors-with-same-name-add-tags/184060 "2019-06-04T20:16:27Z")

</div>

Hello, is it possible to create configuration with multiple processors, using same processor name, but different conditions? I\`d like to add tags for specific log files, like all \*.log files must be tagged as "log" but…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=348)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=350)
