# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=350

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 351

---

## [Monitoring remote container processes](https://discuss.elastic.co/t/monitoring-remote-container-processes/183600)

<div class="topic-metadata">

**Author:** [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Replies:** 3\
**Last updated:** [June 4, 2019, 7:21pm UTC](https://discuss.elastic.co/t/monitoring-remote-container-processes/183600 "2019-06-04T19:21:50Z")

</div>

Hello, I have Metricbeat deployed in a dedicated Docker container monitoring CPU, Memory and I/O on numerous other containers running on the same VM. Data is collected from the other containers via /var/run/docker.sock…

---

## [Mysql database used connection](https://discuss.elastic.co/t/mysql-database-used-connection/182642)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 3\
**Last updated:** [June 4, 2019, 1:01pm UTC](https://discuss.elastic.co/t/mysql-database-used-connection/182642 "2019-06-04T13:01:55Z")

</div>

Dear Elastic Team, We were wondering how many connection that metricbeat will USE from our mysql available open connection?

---

## [Iptables Filebeat](https://discuss.elastic.co/t/iptables-filebeat/183856)

<div class="topic-metadata">

**Author:** [@TheSun](https://discuss.elastic.co/u/TheSun)\
**Replies:** 2\
**Last updated:** [June 4, 2019, 12:08pm UTC](https://discuss.elastic.co/t/iptables-filebeat/183856 "2019-06-04T12:08:49Z")

</div>

Hi, I run the ELK service on ubuntu. I use Filebeat, Elasticsearch and Kibana. I have a problem about dashboard. Filebeat Iptables dashboard displays a bit of data when I PING, but Ubiquiti Firewall logs does not show …

---

## [Filebeat Kubernetes autodiscover provider is getting failed with "/var/run/secrets/kubernetes.io/serviceaccount/namespace: no such file or directory" Error](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-provider-is-getting-failed-with-var-run-secrets-kubernetes-io-serviceaccount-namespace-no-such-file-or-directory-error/183953)

<div class="topic-metadata">

**Author:** [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Replies:** 3\
**Last updated:** [June 4, 2019, 11:53am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-provider-is-getting-failed-with-var-run-secrets-kubernetes-io-serviceaccount-namespace-no-such-file-or-directory-error/183953 "2019-06-04T11:53:31Z")

</div>

Hi - I am using following configuration to autodiscover filebeat pods filebeat.autodiscover: providers: - type: kubernetes templates: - condition: equals: kubernetes.namespace: default config: - type: docker containers.…

---

## [Filebeat Issue - all log entries are merged in a single message instead of multiple messages](https://discuss.elastic.co/t/filebeat-issue-all-log-entries-are-merged-in-a-single-message-instead-of-multiple-messages/184055)

<div class="topic-metadata">

**Author:** [@sukanta007](https://discuss.elastic.co/u/sukanta007)\
**Replies:** 4\
**Last updated:** [June 4, 2019, 11:39am UTC](https://discuss.elastic.co/t/filebeat-issue-all-log-entries-are-merged-in-a-single-message-instead-of-multiple-messages/184055 "2019-06-04T11:39:35Z")

</div>

Hello team, Hope I will get a resolution for this issue ASAP. I am using filebeat v5.6.2 to send log file to ELK where log entries will be displayed in Kibana for visualization & analysis purpose. I have noticed that l…

---

## [Functionbeat not using timestamp from CloudWatch logEvent](https://discuss.elastic.co/t/functionbeat-not-using-timestamp-from-cloudwatch-logevent/183551)

<div class="topic-metadata">

**Author:** [@sparrowt](https://discuss.elastic.co/u/sparrowt)\
**Replies:** 2\
**Last updated:** [June 4, 2019, 10:12am UTC](https://discuss.elastic.co/t/functionbeat-not-using-timestamp-from-cloudwatch-logevent/183551 "2019-06-04T10:12:19Z")

</div>

The CloudwatchLogs transformer in functionbeat (see here) is using time.Now() for the Timestamp field (ends up as @timestamp in Elasticsearch) rather than extracting the 'timestamp' field from the CloudWatch event, which…

---

## [Website down when it's public IP why?](https://discuss.elastic.co/t/website-down-when-its-public-ip-why/184082)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 5\
**Last updated:** [June 4, 2019, 7:08am UTC](https://discuss.elastic.co/t/website-down-when-its-public-ip-why/184082 "2019-06-04T07:08:31Z")

</div>

Dear all, I just configured the heartbeat to monitor our websites， and we notice when the site is using static public IP will be reflected as "down" while the site is working fine and accessible. IP with 202.x.x.x are …

---

## [Unable to start Packbeat 7.1.1 on ELK 7.1.1](https://discuss.elastic.co/t/unable-to-start-packbeat-7-1-1-on-elk-7-1-1/183915)

<div class="topic-metadata">

**Author:** [@Pradeep\_Kumar1](https://discuss.elastic.co/u/Pradeep_Kumar1)\
**Replies:** 2\
**Last updated:** [June 4, 2019, 3:25am UTC](https://discuss.elastic.co/t/unable-to-start-packbeat-7-1-1-on-elk-7-1-1/183915 "2019-06-04T03:25:48Z")

</div>

Hi Team, Tried running below line - C:\\elkbeats\\packetbeat\>docker run -d e5a311b3b005 --name packetbeat --cap-add=NET\_ADMIN --network=host ================================================================ C:\\elkbeats\\…

---

## [Create new module for filebeat 7.1.1](https://discuss.elastic.co/t/create-new-module-for-filebeat-7-1-1/183969)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 2\
**Last updated:** [June 3, 2019, 1:46pm UTC](https://discuss.elastic.co/t/create-new-module-for-filebeat-7-1-1/183969 "2019-06-03T13:46:51Z")

</div>

Hello, I am about to set up log injesting for some java application and I decided that it would be easier if I would create a filebeat module for each of them. Is there an easy way to create a new module on filebeat? I …

---

## [Kibana cant find Filebeat index Pattern](https://discuss.elastic.co/t/kibana-cant-find-filebeat-index-pattern/179719)

<div class="topic-metadata">

**Author:** [@Nils98](https://discuss.elastic.co/u/Nils98)\
**Replies:** 19\
**Last updated:** [June 3, 2019, 7:38pm UTC](https://discuss.elastic.co/t/kibana-cant-find-filebeat-index-pattern/179719 "2019-06-03T19:38:21Z")

</div>

Hello There, i installed ELK, the Beats etc. with follow Guide: But Kibana dont see the Filebeat to create an index pattern. I tryed my best, but i still cant find a way to fix this. Can you please help me, guys?…

---

## [Community\_ID](https://discuss.elastic.co/t/community-id/183636)

<div class="topic-metadata">

**Author:** [@james007](https://discuss.elastic.co/u/james007)\
**Replies:** 7\
**Last updated:** [June 3, 2019, 6:43pm UTC](https://discuss.elastic.co/t/community-id/183636 "2019-06-03T18:43:34Z")

</div>

Hello, I have audit beat v8.0.0 running on CentOS 7.6.1810. I am able to run auditbeat, and I added - community\_id: fields: source\_ip: my\_source\_ip source\_port: my\_source\_port destination…

---

## [Metricbeat in Kubernetes - 404 error for Kubernetes module events](https://discuss.elastic.co/t/metricbeat-in-kubernetes-404-error-for-kubernetes-module-events/181653)

<div class="topic-metadata">

**Author:** [@chandra2037](https://discuss.elastic.co/u/chandra2037)\
**Replies:** 3\
**Last updated:** [June 3, 2019, 4:17pm UTC](https://discuss.elastic.co/t/metricbeat-in-kubernetes-404-error-for-kubernetes-module-events/181653 "2019-06-03T16:17:59Z")

</div>

Hello, I am running Metricbeat 7.0.1 on Kubernetes cluster (Server V1.14), followed the official instructions, and enabled System, Docker, Kubernetes modules. System and Docker modules working where I can see the data i…

---

## [Import Heartbeat Dashboard is trying to connect Elasticsearch client on http://127.0.0.1:9200](https://discuss.elastic.co/t/import-heartbeat-dashboard-is-trying-to-connect-elasticsearch-client-on-http-127-0-0-1-9200/183518)

<div class="topic-metadata">

**Author:** [@Priya2](https://discuss.elastic.co/u/Priya2)\
**Replies:** 1\
**Last updated:** [June 3, 2019, 2:47pm UTC](https://discuss.elastic.co/t/import-heartbeat-dashboard-is-trying-to-connect-elasticsearch-client-on-http-127-0-0-1-9200/183518 "2019-06-03T14:47:43Z")

</div>

Hi all, I am trying to import Heartbeat Dashboard. Steps performed: -Installed Elasticsearch and Kibana on Host1. This is working Fine -Installed Heartbeat5.6 on Host2 . Heartbeat monitoring is working fine Edited h…

---

## [Help needed for setup.template.append\_fields usage](https://discuss.elastic.co/t/help-needed-for-setup-template-append-fields-usage/183701)

<div class="topic-metadata">

**Author:** [@Georgios\_Gkinis](https://discuss.elastic.co/u/Georgios_Gkinis)\
**Replies:** 7\
**Last updated:** [June 3, 2019, 2:02pm UTC](https://discuss.elastic.co/t/help-needed-for-setup-template-append-fields-usage/183701 "2019-06-03T14:02:08Z")

</div>

I am trying to add fields to filebeat but cannot get it working. When my logs are indexed i cannot find the 'resource' field within my access or error logs from nginx. I have deleted all filebeat indexes and templates f…

---

## [Auditbeat vs Filebeat with auditd module](https://discuss.elastic.co/t/auditbeat-vs-filebeat-with-auditd-module/183633)

<div class="topic-metadata">

**Author:** [@bobes](https://discuss.elastic.co/u/bobes)\
**Replies:** 2\
**Last updated:** [June 3, 2019, 1:57pm UTC](https://discuss.elastic.co/t/auditbeat-vs-filebeat-with-auditd-module/183633 "2019-06-03T13:57:29Z")

</div>

Hi - I'm trying to understand the different uses of the Beats agents and have hit a bit of a wall with this one. Functionally what is the difference between the Auditbeat agent watching Linux audit logs and a Filebeat ag…

---

## [Configure winlogbeat to send logs to cluster](https://discuss.elastic.co/t/configure-winlogbeat-to-send-logs-to-cluster/183945)

<div class="topic-metadata">

**Author:** [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Replies:** 2\
**Last updated:** [June 3, 2019, 1:56pm UTC](https://discuss.elastic.co/t/configure-winlogbeat-to-send-logs-to-cluster/183945 "2019-06-03T13:56:52Z")

</div>

Hello, recently I have installed in my lab cluster ELK 7. Now I'd like to send events from Windows to ELK. How properly should I configure winlogbeat? output.elasticsearch: # Array of hosts to connect to. hosts: \["…

---

## [Nginx module. upstream\_addr not available in nginx fields](https://discuss.elastic.co/t/nginx-module-upstream-addr-not-available-in-nginx-fields/183975)

<div class="topic-metadata">

**Author:** [@ORich](https://discuss.elastic.co/u/ORich)\
**Replies:** 0\
**Last updated:** [June 3, 2019, 1:31pm UTC](https://discuss.elastic.co/t/nginx-module-upstream-addr-not-available-in-nginx-fields/183975 "2019-06-03T13:31:58Z")

</div>

Hi everyone, I cannot find any upstream\_addr related key in nginx fields https://www.elastic.co/guide/en/beats/filebeat/7.1/exported-fields-nginx.html The upstream\_addr does contain the IP address and port, or the path…

---

## [Configuration file: setup.template.pattern usage?](https://discuss.elastic.co/t/configuration-file-setup-template-pattern-usage/183322)

<div class="topic-metadata">

**Author:** [@ORich](https://discuss.elastic.co/u/ORich)\
**Replies:** 3\
**Last updated:** [June 3, 2019, 12:27pm UTC](https://discuss.elastic.co/t/configuration-file-setup-template-pattern-usage/183322 "2019-06-03T12:27:06Z")

</div>

I am not clear in my mind regarding the option setup.template.pattern in FileBeat configuration file. From a general standpoint, I do not understand why we should tell Filebeat which index template to load ? According t…

---

## [Harvester.go infinitely loops on decoding JSON, fails to provide error context](https://discuss.elastic.co/t/harvester-go-infinitely-loops-on-decoding-json-fails-to-provide-error-context/183628)

<div class="topic-metadata">

**Author:** [@mdaniel](https://discuss.elastic.co/u/mdaniel)\
**Replies:** 3\
**Last updated:** [June 3, 2019, 9:02am UTC](https://discuss.elastic.co/t/harvester-go-infinitely-loops-on-decoding-json-fails-to-provide-error-context/183628 "2019-06-03T09:02:16Z")

</div>

The GitHub new bug report template said I should come here first, so I'm following the process. There are two bad things happening with filebeat-oss:7.1.0: it appears to be ignoring json.ignore\_decoding\_error: true an…

---

## [How to configure ingest node pipeline in filebeats when using elastic cloud?](https://discuss.elastic.co/t/how-to-configure-ingest-node-pipeline-in-filebeats-when-using-elastic-cloud/183774)

<div class="topic-metadata">

**Author:** [@mzmuda](https://discuss.elastic.co/u/mzmuda)\
**Replies:** 1\
**Last updated:** [June 3, 2019, 8:49am UTC](https://discuss.elastic.co/t/how-to-configure-ingest-node-pipeline-in-filebeats-when-using-elastic-cloud/183774 "2019-06-03T08:49:33Z")

</div>

Hi all, We're looking to configure ingest node processing on a deployment hosted in the elastic cloud, and had a question on how to configure the ingest pipeline, ie since this is a e.co cloud deployment our config for …

---

## [Json fields are now being added to message field instead of mapped fields](https://discuss.elastic.co/t/json-fields-are-now-being-added-to-message-field-instead-of-mapped-fields/183785)

<div class="topic-metadata">

**Author:** [@dataGuy](https://discuss.elastic.co/u/dataGuy)\
**Replies:** 1\
**Last updated:** [June 3, 2019, 7:48am UTC](https://discuss.elastic.co/t/json-fields-are-now-being-added-to-message-field-instead-of-mapped-fields/183785 "2019-06-03T07:48:49Z")

</div>

filebeat is mapping my json fields to a "message" field that I have not created and do not allow dynamic fields. Is this because I'm using decode json feature in filebeat.yml? Is there an attribute related to this behavi…

---

## [Postgres module and altered log\_line\_prefix](https://discuss.elastic.co/t/postgres-module-and-altered-log-line-prefix/182586)

<div class="topic-metadata">

**Author:** [@MalfuncEddie](https://discuss.elastic.co/u/MalfuncEddie)\
**Replies:** 2\
**Last updated:** [June 3, 2019, 7:35am UTC](https://discuss.elastic.co/t/postgres-module-and-altered-log-line-prefix/182586 "2019-06-03T07:35:37Z")

</div>

Hi, Does filebeat take into account when the log\_line\_prefix is altered and the postgres module is loaded? i'm getting: Provided Grok expressions do not match field value: Do I need to change the grok patern and how …

---

## [Sending logs from OpenShift using Filebeat to external Elastic Stack](https://discuss.elastic.co/t/sending-logs-from-openshift-using-filebeat-to-external-elastic-stack/183459)

<div class="topic-metadata">

**Author:** [@vivek14](https://discuss.elastic.co/u/vivek14)\
**Replies:** 2\
**Last updated:** [June 3, 2019, 3:46am UTC](https://discuss.elastic.co/t/sending-logs-from-openshift-using-filebeat-to-external-elastic-stack/183459 "2019-06-03T03:46:28Z")

</div>

Hi, I want to install Beats (Filebeat for time being) on OpenShift in order to ship data to Logstash. This Logstash instance is part of external Elastic Stack environment outside of OpenShift. Is this currently possibl…

---

## [【filebeat output.file】when the output filebeat has been deleted，it wont be created agian automatically](https://discuss.elastic.co/t/filebeat-output-file-when-the-output-filebeat-has-been-deleted-it-wont-be-created-agian-automatically/183675)

<div class="topic-metadata">

**Author:** [@liyihan093730](https://discuss.elastic.co/u/liyihan093730)\
**Replies:** 2\
**Last updated:** [June 3, 2019, 2:50am UTC](https://discuss.elastic.co/t/filebeat-output-file-when-the-output-filebeat-has-been-deleted-it-wont-be-created-agian-automatically/183675 "2019-06-03T02:50:02Z")

</div>

when I using filebeat to filter log files and output the contents to a new file(all function is carried by filebeat souce code), I found when I delete the output file, it wont be created again, even I touch a file in t…

---

## [Filebeat 6.4.3 suddenly starts giving Error decoding JSON: json: cannot unmarshal number into Go value of type map\[string\]interface {}](https://discuss.elastic.co/t/filebeat-6-4-3-suddenly-starts-giving-error-decoding-json-json-cannot-unmarshal-number-into-go-value-of-type-map-string-interface/183839)

<div class="topic-metadata">

**Author:** [@pvi](https://discuss.elastic.co/u/pvi)\
**Replies:** 0\
**Last updated:** [June 1, 2019, 9:26pm UTC](https://discuss.elastic.co/t/filebeat-6-4-3-suddenly-starts-giving-error-decoding-json-json-cannot-unmarshal-number-into-go-value-of-type-map-string-interface/183839 "2019-06-01T21:26:58Z")

</div>

After rebooting filebeat docker on one of our servers it started giving this error for every log line: Error decoding JSON: json: cannot unmarshal number into Go value of type map\[string\]interface {} I can't really f…

---

## [Fail to get kibana version: HTTP GET request to http:/localhost:5600/api](https://discuss.elastic.co/t/fail-to-get-kibana-version-http-get-request-to-http-localhost-5600-api/182887)

<div class="topic-metadata">

**Author:** [@faad021](https://discuss.elastic.co/u/faad021)\
**Replies:** 2\
**Last updated:** [June 1, 2019, 8:49am UTC](https://discuss.elastic.co/t/fail-to-get-kibana-version-http-get-request-to-http-localhost-5600-api/182887 "2019-06-01T08:49:25Z")

</div>

Hi all, I am running elasticsearch and kibana in a container and i am trying to link filebeat to kibana but I am having an error. I am still a noob in this.However, I succesfully had results when i installed them locall…

---

## [Doubled time zone in Logs](https://discuss.elastic.co/t/doubled-time-zone-in-logs/183474)

<div class="topic-metadata">

**Author:** [@fetch](https://discuss.elastic.co/u/fetch)\
**Replies:** 4\
**Last updated:** [May 31, 2019, 8:42pm UTC](https://discuss.elastic.co/t/doubled-time-zone-in-logs/183474 "2019-05-31T20:42:11Z")

</div>

Hello, ELK versions: 6.8.0 I've just enabled "Logs" feature in Kibana and came across issue when timezone value is doubled. I'm using filebeat to send Elasticsearch's own logs. filebeat's config: - module: elasticsea…

---

## [Custom module pipeline is not working on Kibana](https://discuss.elastic.co/t/custom-module-pipeline-is-not-working-on-kibana/183450)

<div class="topic-metadata">

**Author:** [@bivaswap](https://discuss.elastic.co/u/bivaswap)\
**Replies:** 1\
**Last updated:** [May 31, 2019, 8:08pm UTC](https://discuss.elastic.co/t/custom-module-pipeline-is-not-working-on-kibana/183450 "2019-05-31T20:08:37Z")

</div>

I was trying to generate a custom module, named 'unixhops' fileset 'access' Steps I followed: Downloaded github repo make create-module MODULE={module} Test pipeline: go run main.go -elasticsearch http://10.0.50.100:9…

---

## [Multiline pattern setting for multiple loglines in XML file](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618)

<div class="topic-metadata">

**Author:** [@kishorerv93](https://discuss.elastic.co/u/kishorerv93)\
**Replies:** 1\
**Last updated:** [May 31, 2019, 2:56pm UTC](https://discuss.elastic.co/t/multiline-pattern-setting-for-multiple-loglines-in-xml-file/183618 "2019-05-31T14:56:02Z")

</div>

Hi, Below is my xml file. Now my question is, I was able get every line in the above xml in a each message, but i'm unable to get all the log lines in a single message. Anyone can assist ? Thanks \<?xml-stylesheet al…

---

## [I am not geeting logs on kibana file beat showing below logs](https://discuss.elastic.co/t/i-am-not-geeting-logs-on-kibana-file-beat-showing-below-logs/183227)

<div class="topic-metadata">

**Author:** [@hemantkhokhar](https://discuss.elastic.co/u/hemantkhokhar)\
**Replies:** 3\
**Last updated:** [May 31, 2019, 2:41pm UTC](https://discuss.elastic.co/t/i-am-not-geeting-logs-on-kibana-file-beat-showing-below-logs/183227 "2019-05-31T14:41:08Z")

</div>

i am using two logstash and enable load balance true. need help 2019-05-29T05:53:58.797Z ERROR logstash/async.go:235 Failed to publish events caused by: write tcp 172.30.1.19:55834-\>172.30.6.147:5044: write: connection…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=349)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=351)
