# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=351

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 352

---

## [Unable to connect to AWS Elasticsearch Service Domain from Metricbeat](https://discuss.elastic.co/t/unable-to-connect-to-aws-elasticsearch-service-domain-from-metricbeat/183677)

<div class="topic-metadata">

**Author:** [@Sukrity\_Chakraborty](https://discuss.elastic.co/u/Sukrity_Chakraborty)\
**Replies:** 2\
**Last updated:** [May 31, 2019, 10:57am UTC](https://discuss.elastic.co/t/unable-to-connect-to-aws-elasticsearch-service-domain-from-metricbeat/183677 "2019-05-31T10:57:18Z")

</div>

Hi All, I have configured a new Elasticsearch Service domain in AWS following the steps mentioned in the tutorial. I have set open access to the domain as of now. I installed and configured Metricbeat on one of my EC2 …

---

## [Metricbeat used or create mysql connections](https://discuss.elastic.co/t/metricbeat-used-or-create-mysql-connections/182853)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 4\
**Last updated:** [May 31, 2019, 6:07am UTC](https://discuss.elastic.co/t/metricbeat-used-or-create-mysql-connections/182853 "2019-05-31T06:07:33Z")

</div>

Dear Elastic Team, Would like to know how many that metricbeats us or create connection for our mysql for example, based on what? With regards, Yasin D

---

## [Will filebeat create non default index if i need one?](https://discuss.elastic.co/t/will-filebeat-create-non-default-index-if-i-need-one/183355)

<div class="topic-metadata">

**Author:** [@Jonny](https://discuss.elastic.co/u/Jonny)\
**Replies:** 2\
**Last updated:** [May 31, 2019, 5:14am UTC](https://discuss.elastic.co/t/will-filebeat-create-non-default-index-if-i-need-one/183355 "2019-05-31T05:14:30Z")

</div>

Hi all ! Did not get an idea of output.elasticsearch: worker: 3 hosts: \["127.0.0.1:9200"\] index: "acc-%{\[agent.version\]}-%{+yyyy.MM.dd}" Am i right that new index will be created instead of using default f…

---

## [Check filebeat status using API on local host](https://discuss.elastic.co/t/check-filebeat-status-using-api-on-local-host/183594)

<div class="topic-metadata">

**Author:** [@rahulnathan](https://discuss.elastic.co/u/rahulnathan)\
**Replies:** 3\
**Last updated:** [May 30, 2019, 10:38pm UTC](https://discuss.elastic.co/t/check-filebeat-status-using-api-on-local-host/183594 "2019-05-30T22:38:14Z")

</div>

Hello, Is it possible to check filebeat status locally on the host using API/CLI where it is running ? We are trying to build monitoring around filebeat to check whether it is up, connected to remote ElasticSearch end…

---

## [Lag in filebeat tailing the logs from local disk and send to Kafka](https://discuss.elastic.co/t/lag-in-filebeat-tailing-the-logs-from-local-disk-and-send-to-kafka/182723)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 6\
**Last updated:** [May 30, 2019, 8:51pm UTC](https://discuss.elastic.co/t/lag-in-filebeat-tailing-the-logs-from-local-disk-and-send-to-kafka/182723 "2019-05-30T20:51:23Z")

</div>

filebeat timestamp in the log message is 2019-05-24T17:16:10.063Z; Log timestamp is: I0524 16:32:40.761113. therefore, it takes filebeat more than 30 mins to tail a production C++ logs and send them to kafka, I looke…

---

## [Winlogbeat delayed data shipping](https://discuss.elastic.co/t/winlogbeat-delayed-data-shipping/183176)

<div class="topic-metadata">

**Author:** [@Alessio\_Creo](https://discuss.elastic.co/u/Alessio_Creo)\
**Replies:** 4\
**Last updated:** [May 30, 2019, 7:54pm UTC](https://discuss.elastic.co/t/winlogbeat-delayed-data-shipping/183176 "2019-05-30T19:54:33Z")

</div>

Hi there, I'm collecting security register data from Active Directory dedicated Windows Server 2012 host, that pass via Logstash and finally land in ES. After the week-end I've a found an huge delay of 15 hours between …

---

## [\[Solved\] Filebeat 7.0.1 has no data on \[Filebeat System\] Syslog dashboard ECS](https://discuss.elastic.co/t/solved-filebeat-7-0-1-has-no-data-on-filebeat-system-syslog-dashboard-ecs/182575)

<div class="topic-metadata">

**Author:** [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Replies:** 2\
**Last updated:** [May 30, 2019, 5:04pm UTC](https://discuss.elastic.co/t/solved-filebeat-7-0-1-has-no-data-on-filebeat-system-syslog-dashboard-ecs/182575 "2019-05-30T17:04:41Z")

</div>

Hello team, I have an ELK stack running on 7.0.1 and i have trouble displaying data on the \[Filebeat System\] Syslog dashboard ECS but i can see logs on the discover panel. I have configured a linuxclient to send system…

---

## [Required Object but found string](https://discuss.elastic.co/t/required-object-but-found-string/183543)

<div class="topic-metadata">

**Author:** [@KWBrandenWagner](https://discuss.elastic.co/u/KWBrandenWagner)\
**Replies:** 2\
**Last updated:** [May 30, 2019, 3:56pm UTC](https://discuss.elastic.co/t/required-object-but-found-string/183543 "2019-05-30T15:56:37Z")

</div>

I know this has to be something simple, but im staring at it and cant figure it out, so im posting here for some extra eyes to tell me what i did wrong. ERROR Exiting: Error while initializing input: required 'object',…

---

## [Send both filebeats and heartbeat to logstash did not work](https://discuss.elastic.co/t/send-both-filebeats-and-heartbeat-to-logstash-did-not-work/179717)

<div class="topic-metadata">

**Author:** [@Joe\_Joedan](https://discuss.elastic.co/u/Joe_Joedan)\
**Replies:** 2\
**Last updated:** [May 30, 2019, 3:05am UTC](https://discuss.elastic.co/t/send-both-filebeats-and-heartbeat-to-logstash-did-not-work/179717 "2019-05-30T03:05:42Z")

</div>

Hi All, Currently I run both filebeat and heartbeat in docker and would pass data to Logstash to filter before those data will be forwarded again to elasticsearch. Also I would separate data from filebeat and heartbeat…

---

## [Processor event variable interpolation](https://discuss.elastic.co/t/processor-event-variable-interpolation/183434)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 2\
**Last updated:** [May 30, 2019, 1:56am UTC](https://discuss.elastic.co/t/processor-event-variable-interpolation/183434 "2019-05-30T01:56:22Z")

</div>

Hi, Hopefully a quick one. I want to add document metadata via processors, however the value depends on event values. How would I get something like this to work? I tried the following formats with no luck. processors…

---

## [Access json objects with dot in key using string output codec](https://discuss.elastic.co/t/access-json-objects-with-dot-in-key-using-string-output-codec/182047)

<div class="topic-metadata">

**Author:** [@logankimmel](https://discuss.elastic.co/u/logankimmel)\
**Replies:** 2\
**Last updated:** [May 29, 2019, 10:17pm UTC](https://discuss.elastic.co/t/access-json-objects-with-dot-in-key-using-string-output-codec/182047 "2019-05-29T22:17:18Z")

</div>

I'm trying to access a nested json object when using the string codec format but the key I'm trying to access has a "." in it. What is the correct syntax to do so? An example of the json is: { "json": { "time": "201…

---

## [Heartbeat scheduled jobs already active](https://discuss.elastic.co/t/heartbeat-scheduled-jobs-already-active/181230)

<div class="topic-metadata">

**Author:** [@packland](https://discuss.elastic.co/u/packland)\
**Replies:** 1\
**Last updated:** [May 29, 2019, 9:56pm UTC](https://discuss.elastic.co/t/heartbeat-scheduled-jobs-already-active/181230 "2019-05-29T21:56:26Z")

</div>

Hi, I'm running Beats version 5.4.2 and running into a constant issue which persists through restart of both heartbeat and the host system. Heartbeat will work for a period (there doesn't seem to be a pattern as to how…

---

## [Issue sending logs with FileBeat Getting parsed at Logstash](https://discuss.elastic.co/t/issue-sending-logs-with-filebeat-getting-parsed-at-logstash/182821)

<div class="topic-metadata">

**Author:** [@iukea](https://discuss.elastic.co/u/iukea)\
**Replies:** 1\
**Last updated:** [May 29, 2019, 8:19pm UTC](https://discuss.elastic.co/t/issue-sending-logs-with-filebeat-getting-parsed-at-logstash/182821 "2019-05-29T20:19:24Z")

</div>

I am able to get some of my logs sent from FileBeat to Logstash, but I seem to be having an issue with a 2 of them. Do you guys have any words of wisdom? I see logs in the folders that FileBeat is supposed to read from…

---

## [FileBeat Sending to logstash Need help parsing a CSV](https://discuss.elastic.co/t/filebeat-sending-to-logstash-need-help-parsing-a-csv/182530)

<div class="topic-metadata">

**Author:** [@iukea](https://discuss.elastic.co/u/iukea)\
**Replies:** 4\
**Last updated:** [May 29, 2019, 7:35pm UTC](https://discuss.elastic.co/t/filebeat-sending-to-logstash-need-help-parsing-a-csv/182530 "2019-05-29T19:35:56Z")

</div>

Hey, guys, I am having an issue with my Filebeat yml config and was curious if any of you could spot anything obvious that I missing? Logstash conf # Heralding if \[type\] == "Heralding" { csv { c…

---

## [Monitoring Beats if it's not running](https://discuss.elastic.co/t/monitoring-beats-if-its-not-running/182625)

<div class="topic-metadata">

**Author:** [@Thibaut\_M](https://discuss.elastic.co/u/Thibaut_M)\
**Replies:** 1\
**Last updated:** [May 29, 2019, 7:17pm UTC](https://discuss.elastic.co/t/monitoring-beats-if-its-not-running/182625 "2019-05-29T19:17:35Z")

</div>

Hi everyone, I was wondering, is there a way to monitor if a beats service is up and running? I saw on the monitoring part that we can see the up time but when the service is stopped i guess that the beats just disappe…

---

## [Issues analysing elastic traffic](https://discuss.elastic.co/t/issues-analysing-elastic-traffic/182963)

<div class="topic-metadata">

**Author:** [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Replies:** 3\
**Last updated:** [May 29, 2019, 2:20pm UTC](https://discuss.elastic.co/t/issues-analysing-elastic-traffic/182963 "2019-05-29T14:20:01Z")

</div>

Hi, Im trying to analyze the queries that came to my ES cluster, I manage to install packetbeat to analyze the http traffic that cames to the port 9200, and Im getting the request (and responses) but Im also having a lo…

---

## [Sent Logs from Cisco ASA to ELK (OS Ubuntu 18.04)](https://discuss.elastic.co/t/sent-logs-from-cisco-asa-to-elk-os-ubuntu-18-04/183181)

<div class="topic-metadata">

**Author:** [@Gustavo\_Oliveira](https://discuss.elastic.co/u/Gustavo_Oliveira)\
**Replies:** 2\
**Last updated:** [May 29, 2019, 1:33pm UTC](https://discuss.elastic.co/t/sent-logs-from-cisco-asa-to-elk-os-ubuntu-18-04/183181 "2019-05-29T13:33:54Z")

</div>

Good afternoon, I have a server ELK (OS Ubuntu 18.04), the network gateway (CISCO ASA) store all logs and send to Gray LOG, but i want that these logs been sents to ELK (filebeat\>logstash\>elasticsearch\>kibana). How can …

---

## [Packet beat Reverse DNS lookup not working properly](https://discuss.elastic.co/t/packet-beat-reverse-dns-lookup-not-working-properly/183285)

<div class="topic-metadata">

**Author:** [@swapnali](https://discuss.elastic.co/u/swapnali)\
**Replies:** 1\
**Last updated:** [May 29, 2019, 12:34pm UTC](https://discuss.elastic.co/t/packet-beat-reverse-dns-lookup-not-working-properly/183285 "2019-05-29T12:34:07Z")

</div>

Hi, following are configuration of packetbeat for Reverse DNS lookup processors: dns: type: reverse action: append fields: server.ip: server.hostname client.ip: client.hostname success\_cache: capacity.initial…

---

## [DNS Reverse lookup](https://discuss.elastic.co/t/dns-reverse-lookup/183329)

<div class="topic-metadata">

**Author:** [@swapnali](https://discuss.elastic.co/u/swapnali)\
**Replies:** 0\
**Last updated:** [May 29, 2019, 12:26pm UTC](https://discuss.elastic.co/t/dns-reverse-lookup/183329 "2019-05-29T12:26:53Z")

</div>

Hi, I am trying to get the logs of windows via winlogbeat but i am not able to capture DNS Reverse lookup failure using winlogbeat. can you please help me how and i what way i can capture it.

---

## [Filebeat 7.1.0 Elasticsearch module audit pipeline incorrectly references @timestamp instead of timestamp](https://discuss.elastic.co/t/filebeat-7-1-0-elasticsearch-module-audit-pipeline-incorrectly-references-timestamp-instead-of-timestamp/182721)

<div class="topic-metadata">

**Author:** [@Chris\_Samo](https://discuss.elastic.co/u/Chris_Samo)\
**Replies:** 3\
**Last updated:** [May 29, 2019, 11:01am UTC](https://discuss.elastic.co/t/filebeat-7-1-0-elasticsearch-module-audit-pipeline-incorrectly-references-timestamp-instead-of-timestamp/182721 "2019-05-29T11:01:16Z")

</div>

I'm using Filebeat and Elasticsearch 7.1.0 to capture logs through the Docker input and parsing with the elasticsearch module with config such as: filebeat.autodiscover: providers: # elasticsearch - type: dock…

---

## [Error creating runner in Kubernetes autodiscover](https://discuss.elastic.co/t/error-creating-runner-in-kubernetes-autodiscover/183295)

<div class="topic-metadata">

**Author:** [@cypherfox](https://discuss.elastic.co/u/cypherfox)\
**Replies:** 0\
**Last updated:** [May 29, 2019, 10:02am UTC](https://discuss.elastic.co/t/error-creating-runner-in-kubernetes-autodiscover/183295 "2019-05-29T10:02:35Z")

</div>

Hi there, I am trying to gather logs from kubernetes, using filebeat and forwarding to Elasticsearch. I have configured autoconfigure and added -d autodiscover to the arguments to activate more autodiscover logging. M…

---

## [Filebeat's elasticsearch module output wrong timestamp on Kibana Logs](https://discuss.elastic.co/t/filebeats-elasticsearch-module-output-wrong-timestamp-on-kibana-logs/182986)

<div class="topic-metadata">

**Author:** [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Replies:** 0\
**Last updated:** [May 28, 2019, 5:31am UTC](https://discuss.elastic.co/t/filebeats-elasticsearch-module-output-wrong-timestamp-on-kibana-logs/182986 "2019-05-28T05:31:02Z")

</div>

Hello, I am running 3 elasticsearch nodes and trying to output their logs using filebeat elasticsearch modules. I was setting up filebeat logging for elasticsearch module and the logs for system.yml modules is in the c…

---

## [Harvesting a moved file in filebeat](https://discuss.elastic.co/t/harvesting-a-moved-file-in-filebeat/183279)

<div class="topic-metadata">

**Author:** [@Krrish\_Raj](https://discuss.elastic.co/u/Krrish_Raj)\
**Replies:** 0\
**Last updated:** [May 29, 2019, 8:43am UTC](https://discuss.elastic.co/t/harvesting-a-moved-file-in-filebeat/183279 "2019-05-29T08:43:24Z")

</div>

In the documentation of filebeat under harvesters section, it says that a file won't be harvested again if a file is moved/deleted while harvester is closed. Also it says that filebeat internally maintains inode number…

---

## [Test failure error:beats](https://discuss.elastic.co/t/test-failure-error-beats/182638)

<div class="topic-metadata">

**Author:** [@john5](https://discuss.elastic.co/u/john5)\
**Replies:** 6\
**Last updated:** [May 29, 2019, 7:40am UTC](https://discuss.elastic.co/t/test-failure-error-beats/182638 "2019-05-29T07:40:36Z")

</div>

Heloo, i am running test suit on beat version 6.4.1 and getting some error. Steps: Clone beats source code from git Download and set GO lang and GOPATH. Run make testsuite command. o/p: command \[go test -cover -co…

---

## [Central Management from ES-Cloud via Logstash](https://discuss.elastic.co/t/central-management-from-es-cloud-via-logstash/183252)

<div class="topic-metadata">

**Author:** [@gruselglatz](https://discuss.elastic.co/u/gruselglatz)\
**Replies:** 0\
**Last updated:** [May 29, 2019, 7:25am UTC](https://discuss.elastic.co/t/central-management-from-es-cloud-via-logstash/183252 "2019-05-29T07:25:31Z")

</div>

Hi, is it possible to Manage and update Beats from my Cloud instance via local Logstashes. The Problem I have is that my local beats arent allowed to communicate with the internet, only one logstash aggregator is allow…

---

## [Potential memory leak found by DrMemory](https://discuss.elastic.co/t/potential-memory-leak-found-by-drmemory/183172)

<div class="topic-metadata">

**Author:** [@chipitsine](https://discuss.elastic.co/u/chipitsine)\
**Replies:** 1\
**Last updated:** [May 29, 2019, 7:22am UTC](https://discuss.elastic.co/t/potential-memory-leak-found-by-drmemory/183172 "2019-05-29T07:22:03Z")

</div>

hello when I run windows filebeat together with DrMemory (http://drmemory.org/) it shows the following errors (and stops): filebeat is 7.1.1

---

## [Version Missmatch](https://discuss.elastic.co/t/version-missmatch/182736)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 2\
**Last updated:** [May 29, 2019, 12:13am UTC](https://discuss.elastic.co/t/version-missmatch/182736 "2019-05-29T00:13:32Z")

</div>

Is there any way to use Winlogbeat v7 with Elasticsearch v6.4? In a working 6.4 Winlogbeat, ES, Kibana environment, i tried to upgrade just winlogbeat to v7 to make use of the new add\_fields processor, however i now get…

---

## [Use google/gopacket instead of tsg/gopacket in Packetbeat](https://discuss.elastic.co/t/use-google-gopacket-instead-of-tsg-gopacket-in-packetbeat/183075)

<div class="topic-metadata">

**Author:** [@eloyekunle](https://discuss.elastic.co/u/eloyekunle)\
**Replies:** 2\
**Last updated:** [May 28, 2019, 11:26pm UTC](https://discuss.elastic.co/t/use-google-gopacket-instead-of-tsg-gopacket-in-packetbeat/183075 "2019-05-28T23:26:44Z")

</div>

Both packages seem to be forked from the gopcap project written by Andreas Krennmair. Benefits: Wider community support Updated more often I'll be interested in working on it if it sounds like a good idea.

---

## [Filebeat Log rotation support](https://discuss.elastic.co/t/filebeat-log-rotation-support/183182)

<div class="topic-metadata">

**Author:** [@ankitachow](https://discuss.elastic.co/u/ankitachow)\
**Replies:** 0\
**Last updated:** [May 28, 2019, 8:02pm UTC](https://discuss.elastic.co/t/filebeat-log-rotation-support/183182 "2019-05-28T20:02:19Z")

</div>

Hello, I have an application which does log rotation. The files are written in EventLogFile.0 which gets rolled over to EventLogFile.1, once new logs starts getting written to EventLogFile.0. The rollover happens till 4…

---

## [Regarding hint based autodiscover docker provider](https://discuss.elastic.co/t/regarding-hint-based-autodiscover-docker-provider/182895)

<div class="topic-metadata">

**Author:** [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Replies:** 1\
**Last updated:** [May 28, 2019, 8:01pm UTC](https://discuss.elastic.co/t/regarding-hint-based-autodiscover-docker-provider/182895 "2019-05-28T20:01:37Z")

</div>

Can anyone explain how hint based autodiscover is configured with different docker level. I am little bit confused with its working. Kindly help me out. Thanks

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=350)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=352)
