# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=352

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 353

---

## [ELK no read logs from docker containers](https://discuss.elastic.co/t/elk-no-read-logs-from-docker-containers/182612)

<div class="topic-metadata">

**Author:** [@angie](https://discuss.elastic.co/u/angie)\
**Replies:** 1\
**Last updated:** [May 28, 2019, 7:18pm UTC](https://discuss.elastic.co/t/elk-no-read-logs-from-docker-containers/182612 "2019-05-28T19:18:53Z")

</div>

hello, Filebeat is not reading docker logs, of course, because of permission: Exiting: error initializing publisher: error initializing processors: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is…

---

## [Metricbeat Jolokia GC Young space](https://discuss.elastic.co/t/metricbeat-jolokia-gc-young-space/182600)

<div class="topic-metadata">

**Author:** [@rubbercable](https://discuss.elastic.co/u/rubbercable)\
**Replies:** 1\
**Last updated:** [May 28, 2019, 6:19pm UTC](https://discuss.elastic.co/t/metricbeat-jolokia-gc-young-space/182600 "2019-05-28T18:19:35Z")

</div>

Metric beat doesn't handle spaces in mbeans well. curl localhost:8778/jolokia/read/java.lang:name=G1%20Young%20Generation,type=GarbageCollector I can curl this to get statistics, but Metricbeat reports: { "error": "…

---

## [Getting log INFO File is inactive: /logs/analytics/xyz6.log. Closing because close\_inactive of 5m0s reached](https://discuss.elastic.co/t/getting-log-info-file-is-inactive-logs-analytics-xyz6-log-closing-because-close-inactive-of-5m0s-reached/183160)

<div class="topic-metadata">

**Author:** [@Swaroop\_Chand](https://discuss.elastic.co/u/Swaroop_Chand)\
**Replies:** 0\
**Last updated:** [May 28, 2019, 5:43pm UTC](https://discuss.elastic.co/t/getting-log-info-file-is-inactive-logs-analytics-xyz6-log-closing-because-close-inactive-of-5m0s-reached/183160 "2019-05-28T17:43:40Z")

</div>

Getting log INFO File is inactive: /logs/analytics/xyz6.log. Closing because close\_inactive of 5m0s reached. Data is not reaching to logstash. output { if \[type\] =~ "syslog" { elasticsearch { hosts =\> \["http://127.0…

---

## [vSphere Module Snapshots](https://discuss.elastic.co/t/vsphere-module-snapshots/182391)

<div class="topic-metadata">

**Author:** [@Michael\_Fischer](https://discuss.elastic.co/u/Michael_Fischer)\
**Replies:** 1\
**Last updated:** [May 28, 2019, 4:38pm UTC](https://discuss.elastic.co/t/vsphere-module-snapshots/182391 "2019-05-28T16:38:53Z")

</div>

Hey, is it possible to look for existing Snapshots of VMs using the vsphere module or in any other way? Thanks for your help! Michael

---

## [Customize fields.yml according to a specific module](https://discuss.elastic.co/t/customize-fields-yml-according-to-a-specific-module/181705)

<div class="topic-metadata">

**Author:** [@testik](https://discuss.elastic.co/u/testik)\
**Replies:** 1\
**Last updated:** [May 28, 2019, 3:36pm UTC](https://discuss.elastic.co/t/customize-fields-yml-according-to-a-specific-module/181705 "2019-05-28T15:36:10Z")

</div>

Hello all, Currently I\`m trying configuring the metricbeat only for system basic data - such as: cpu, memory, disk usage etc.... I run the command: ./metricbeat modules list and saw only the system module is enabled a…

---

## [Permissions for postgres / metricbeat account?](https://discuss.elastic.co/t/permissions-for-postgres-metricbeat-account/182764)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [May 28, 2019, 3:17pm UTC](https://discuss.elastic.co/t/permissions-for-postgres-metricbeat-account/182764 "2019-05-28T15:17:40Z")

</div>

I'd like to monitor postgresql using the metricbeat module. To this end I want to use a separate psql account from any other logins. What permissions does this account need?

---

## [Metricbeat set index pattern](https://discuss.elastic.co/t/metricbeat-set-index-pattern/182799)

<div class="topic-metadata">

**Author:** [@Gidi\_Kalef](https://discuss.elastic.co/u/Gidi_Kalef)\
**Replies:** 2\
**Last updated:** [May 28, 2019, 3:02pm UTC](https://discuss.elastic.co/t/metricbeat-set-index-pattern/182799 "2019-05-28T15:02:00Z")

</div>

Hi Guys , i have the following configuration under my metricbeat.yml configuration file: output.elasticsearch: hosts: '${ELASTICSEARCH\_HOSTS:elasticsearch:9200}' index: "alerts-kafka-%{+yyyy.MM.dd}" #===============…

---

## [Netflows not showing protocol types in Dashboards](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288)

<div class="topic-metadata">

**Author:** [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Replies:** 5\
**Last updated:** [May 28, 2019, 1:48pm UTC](https://discuss.elastic.co/t/netflows-not-showing-protocol-types-in-dashboards/182288 "2019-05-28T13:48:03Z")

</div>

Newbie here.. I am curious as to why my netflows are only giving the traffic but not the protocol type in the dashboards. Also are you really able to inspect packets from a cloud implementation?

---

## [AuditBeat And Oracle Linux](https://discuss.elastic.co/t/auditbeat-and-oracle-linux/181572)

<div class="topic-metadata">

**Author:** [@Murat\_Celebi](https://discuss.elastic.co/u/Murat_Celebi)\
**Replies:** 4\
**Last updated:** [May 28, 2019, 10:32am UTC](https://discuss.elastic.co/t/auditbeat-and-oracle-linux/181572 "2019-05-28T10:32:41Z")

</div>

Hi, Is there any plan to make Auditbeat work Oracle Linux ? As far as I have seen it is not certified right now. Thank you.

---

## [Sending Windows security logs to a different LogStash endpoint - multiple logstash endpoints](https://discuss.elastic.co/t/sending-windows-security-logs-to-a-different-logstash-endpoint-multiple-logstash-endpoints/182392)

<div class="topic-metadata">

**Author:** [@jjjwils](https://discuss.elastic.co/u/jjjwils)\
**Replies:** 2\
**Last updated:** [May 28, 2019, 8:35am UTC](https://discuss.elastic.co/t/sending-windows-security-logs-to-a-different-logstash-endpoint-multiple-logstash-endpoints/182392 "2019-05-28T08:35:16Z")

</div>

Hi, We have a requirement to send our security logs to a different LogStash endpoint - I've tried various configs in the WinLogBeat.yml file - but Im not sure if its possible. I know on LogStash this is fairly easy to …

---

## [Central Management with searchguard](https://discuss.elastic.co/t/central-management-with-searchguard/182900)

<div class="topic-metadata">

**Author:** [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Replies:** 6\
**Last updated:** [May 28, 2019, 8:15am UTC](https://discuss.elastic.co/t/central-management-with-searchguard/182900 "2019-05-28T08:15:34Z")

</div>

Hi I need to know if I have a cluster secured by search guard could use Central Managment beats and how could I configure it. Thank you Franco

---

## [Filebeat http end point support](https://discuss.elastic.co/t/filebeat-http-end-point-support/182837)

<div class="topic-metadata">

**Author:** [@spadhi](https://discuss.elastic.co/u/spadhi)\
**Replies:** 4\
**Last updated:** [May 28, 2019, 7:08am UTC](https://discuss.elastic.co/t/filebeat-http-end-point-support/182837 "2019-05-28T07:08:42Z")

</div>

Does filebeat support sending logs to an http endpoint?

---

## [Exiting: Registry file path must be a file. /usr/share/filebeat/data/registry is a directory](https://discuss.elastic.co/t/exiting-registry-file-path-must-be-a-file-usr-share-filebeat-data-registry-is-a-directory/182894)

<div class="topic-metadata">

**Author:** [@Maurya\_M](https://discuss.elastic.co/u/Maurya_M)\
**Replies:** 3\
**Last updated:** [May 28, 2019, 4:54am UTC](https://discuss.elastic.co/t/exiting-registry-file-path-must-be-a-file-usr-share-filebeat-data-registry-is-a-directory/182894 "2019-05-28T04:54:31Z")

</div>

Hi, I am try to match the various compatible version listed here : https://www.elastic.co/support/matrix#matrix\_compatibility, but when i use 6.8.0, i am getting this error in my filebeat daemonset, any idea how to fix …

---

## [Custom index using ES 7.1.0](https://discuss.elastic.co/t/custom-index-using-es-7-1-0/182950)

<div class="topic-metadata">

**Author:** [@Maurya\_M](https://discuss.elastic.co/u/Maurya_M)\
**Replies:** 1\
**Last updated:** [May 27, 2019, 11:53pm UTC](https://discuss.elastic.co/t/custom-index-using-es-7-1-0/182950 "2019-05-27T23:53:45Z")

</div>

Hi, I am trying to generate custom index into elastic search from filebeat with the following config: (using both 7.1.0 versions) , but unable to see this index - oraclesidecar-%{\[agent.version\]}-%{+yyyy.MM.dd} on the e…

---

## [Metricbeat System process permissions needed on windows](https://discuss.elastic.co/t/metricbeat-system-process-permissions-needed-on-windows/181977)

<div class="topic-metadata">

**Author:** [@Inbloo](https://discuss.elastic.co/u/Inbloo)\
**Replies:** 3\
**Last updated:** [May 27, 2019, 2:46pm UTC](https://discuss.elastic.co/t/metricbeat-system-process-permissions-needed-on-windows/181977 "2019-05-27T14:46:29Z")

</div>

Hi We are using metricbeat system process module to monitor all processes running on windows platforms. Metricbeat is only able to get himself process information. We want to get all processes information. What permiss…

---

## [Logstash starts with an error and does not receive filebeat data](https://discuss.elastic.co/t/logstash-starts-with-an-error-and-does-not-receive-filebeat-data/182929)

<div class="topic-metadata">

**Author:** [@PHImD](https://discuss.elastic.co/u/PHImD)\
**Replies:** 1\
**Last updated:** [May 27, 2019, 2:15pm UTC](https://discuss.elastic.co/t/logstash-starts-with-an-error-and-does-not-receive-filebeat-data/182929 "2019-05-27T14:15:02Z")

</div>

Hello! I am new to the ELK Stack. I configure ELK in docker for collecting logs of containers. I ran into some problems. When I run the filebeat container, I get a warning: "It is not configured / enabled. If you’ve a…

---

## [Cannot provide a name](https://discuss.elastic.co/t/cannot-provide-a-name/182027)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 9\
**Last updated:** [May 27, 2019, 11:27am UTC](https://discuss.elastic.co/t/cannot-provide-a-name/182027 "2019-05-27T11:27:47Z")

</div>

Dear Elastic Team, Seems like when giving a "name:" in heartbeat.yml file it doesn't work?

---

## [Add fields to winlogbeat events](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 7\
**Last updated:** [May 27, 2019, 10:30am UTC](https://discuss.elastic.co/t/add-fields-to-winlogbeat-events/182639 "2019-05-27T10:30:56Z")

</div>

Hello using winlogbeat and elasticsearch as the output (not logstash) can i create a key-value pari lookup database? use case: For event\_id: 4625 i would like to include fields or do a lookup for the Status and Substa…

---

## [Exiting: Error while initializing input: can not convert 'string' into 'bool' accessing 'filebeat.inputs.0.enabled' (source:'/etc/filebeat/filebeat.yml')](https://discuss.elastic.co/t/exiting-error-while-initializing-input-can-not-convert-string-into-bool-accessing-filebeat-inputs-0-enabled-source-etc-filebeat-filebeat-yml/182841)

<div class="topic-metadata">

**Author:** [@iiqq8888](https://discuss.elastic.co/u/iiqq8888)\
**Replies:** 3\
**Last updated:** [May 27, 2019, 9:47am UTC](https://discuss.elastic.co/t/exiting-error-while-initializing-input-can-not-convert-string-into-bool-accessing-filebeat-inputs-0-enabled-source-etc-filebeat-filebeat-yml/182841 "2019-05-27T09:47:47Z")

</div>

Hi All I am new ELK user, and I install Elasticsearch 7.1,Kibana 7.1,Filebeat 7.1 in Redhat 6.8 by vmware. I use default config of elasticsearch.yml ,kibana. filebeat.yml below configuration file. #==================…

---

## [This Beat requires the default distribution of Elasticsearch](https://discuss.elastic.co/t/this-beat-requires-the-default-distribution-of-elasticsearch/182490)

<div class="topic-metadata">

**Author:** [@Maurya\_M](https://discuss.elastic.co/u/Maurya_M)\
**Replies:** 6\
**Last updated:** [May 27, 2019, 5:50am UTC](https://discuss.elastic.co/t/this-beat-requires-the-default-distribution-of-elasticsearch/182490 "2019-05-27T05:50:41Z")

</div>

Using Filebeat image : docker.elastic.co/beats/filebeat:7.0.0 Elastic Search image : k8s.gcr.io/elasticsearch:v6.2.5 EDIT: Now have changed to docker.elastic.co/elasticsearch/elasticsearch-oss:6.4.0, but in the fileb…

---

## [Failed to send logs to elasticsearch output because failed to create ILM alias](https://discuss.elastic.co/t/failed-to-send-logs-to-elasticsearch-output-because-failed-to-create-ilm-alias/179116)

<div class="topic-metadata">

**Author:** [@razafinr](https://discuss.elastic.co/u/razafinr)\
**Replies:** 5\
**Last updated:** [May 26, 2019, 4:44pm UTC](https://discuss.elastic.co/t/failed-to-send-logs-to-elasticsearch-output-because-failed-to-create-ilm-alias/179116 "2019-05-26T16:44:10Z")

</div>

Hello, I am using metricbeat 7.0.0 and sending data to the elasticsearch output. My elasticsearch version is also 7.0.0 I have a very basic configuration: metricbeat.config.modules: # Glob pattern for configuration …

---

## [Filebeat Iptables Overview / No results found](https://discuss.elastic.co/t/filebeat-iptables-overview-no-results-found/181881)

<div class="topic-metadata">

**Author:** [@TheSun](https://discuss.elastic.co/u/TheSun)\
**Replies:** 12\
**Last updated:** [May 26, 2019, 9:39am UTC](https://discuss.elastic.co/t/filebeat-iptables-overview-no-results-found/181881 "2019-05-26T09:39:30Z")

</div>

20/5000 I'm new in this area. I am trying to handle the event created by iptables with ELK. It encountered an error that I could not fix. My Discover have data but Filebeat Iptables Overview report No results found. H…

---

## [Auditbeat system metric error](https://discuss.elastic.co/t/auditbeat-system-metric-error/180629)

<div class="topic-metadata">

**Author:** [@nt-josh](https://discuss.elastic.co/u/nt-josh)\
**Replies:** 2\
**Last updated:** [May 25, 2019, 12:03am UTC](https://discuss.elastic.co/t/auditbeat-system-metric-error/180629 "2019-05-25T00:03:26Z")

</div>

so we have a 6.7.1 es cluster. using auditbeat 6.7.1 i was able to run the kibana dashboard install with ./auditbeat setup. however it refuses to start because of no metricsets configured for system. Someone else had th…

---

## [Packetbeat network traffic issue](https://discuss.elastic.co/t/packetbeat-network-traffic-issue/181494)

<div class="topic-metadata">

**Author:** [@Gerardo\_Heredia](https://discuss.elastic.co/u/Gerardo_Heredia)\
**Replies:** 1\
**Last updated:** [May 24, 2019, 9:29pm UTC](https://discuss.elastic.co/t/packetbeat-network-traffic-issue/181494 "2019-05-24T21:29:33Z")

</div>

Hi, I am trying to get all the network traffic of a building, I already install elasticsearch, kibana, logastash and packetbeat. I only get the traffic of the computer where the stack is installed. I am connected to the …

---

## [Metricbeat \> Logstash errors: client is not connected](https://discuss.elastic.co/t/metricbeat-logstash-errors-client-is-not-connected/182271)

<div class="topic-metadata">

**Author:** [@Jacko-ski](https://discuss.elastic.co/u/Jacko-ski)\
**Replies:** 4\
**Last updated:** [May 24, 2019, 5:41pm UTC](https://discuss.elastic.co/t/metricbeat-logstash-errors-client-is-not-connected/182271 "2019-05-24T17:41:54Z")

</div>

I'm observing these errors in Metricbeat logs on the sender machine. Looks like every Publish event fails initially, then reconnects after a re-try. Why is that happening? The Logstash consumer targets are deployed…

---

## [Make Release Not working](https://discuss.elastic.co/t/make-release-not-working/181044)

<div class="topic-metadata">

**Author:** [@Dede\_Pessu](https://discuss.elastic.co/u/Dede_Pessu)\
**Replies:** 1\
**Last updated:** [May 24, 2019, 4:23pm UTC](https://discuss.elastic.co/t/make-release-not-working/181044 "2019-05-24T16:23:06Z")

</div>

when i run make release command to generate rpm package i get the following message ➜ jmsbeat git:(master) ✗ make release DEPRECATION: Python 2.7 will reach the end of its life on January 1st, 2020. Please upgrade your…

---

## [Monitor multiple hosts with infrastructure](https://discuss.elastic.co/t/monitor-multiple-hosts-with-infrastructure/182195)

<div class="topic-metadata">

**Author:** [@omardawed](https://discuss.elastic.co/u/omardawed)\
**Replies:** 3\
**Last updated:** [May 24, 2019, 3:43pm UTC](https://discuss.elastic.co/t/monitor-multiple-hosts-with-infrastructure/182195 "2019-05-24T15:43:08Z")

</div>

hello, i installed elastic stack 7 , i can montor only one server with infrastructure; is it possible to monitor more than one server on infrastructure ? if yes how to do this ?

---

## [Haproxy strconv.ParseFloat: parsing "": invalid syntax](https://discuss.elastic.co/t/haproxy-strconv-parsefloat-parsing-invalid-syntax/181403)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 7\
**Last updated:** [May 24, 2019, 1:54pm UTC](https://discuss.elastic.co/t/haproxy-strconv-parsefloat-parsing-invalid-syntax/181403 "2019-05-24T13:54:44Z")

</div>

Dear Elastic Team, I've configured the haproxy but still receiving the following error message: "strconv.ParseFloat: parsing "": invalid syntax" as shown below. I'm wondering what i'm doing wrong. i also do not get the…

---

## [Unable to start FileBeat Due to Restrictions](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-restrictions/182650)

<div class="topic-metadata">

**Author:** [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Replies:** 1\
**Last updated:** [May 24, 2019, 1:04pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-restrictions/182650 "2019-05-24T13:04:30Z")

</div>

Hi Team, I have been trying to start the file beat but getting the following error while starting. Exiting: error loading config file: config file ("filebeat.yml") can only be writable by the owner but the permissions …

---

## [Testsuite failed: make testsuite: package github.com/docker/libcompose: cannot download](https://discuss.elastic.co/t/testsuite-failed-make-testsuite-package-github-com-docker-libcompose-cannot-download/182220)

<div class="topic-metadata">

**Author:** [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Replies:** 7\
**Last updated:** [May 24, 2019, 11:00am UTC](https://discuss.elastic.co/t/testsuite-failed-make-testsuite-package-github-com-docker-libcompose-cannot-download/182220 "2019-05-24T11:00:22Z")

</div>

Hi Team, I'm trying to perform testing for filebeat, but getting below problem with libcompose. package github.com/docker/libcompose: cannot download, $GOPATH must not be set to $GOROOT. For more details see: 'go help …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=351)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=353)
