# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=353

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 354

---

## [Is it ok to leave all my metricbeats with the default index name?](https://discuss.elastic.co/t/is-it-ok-to-leave-all-my-metricbeats-with-the-default-index-name/182113)

<div class="topic-metadata">

**Author:** [@TsuWeiQuan](https://discuss.elastic.co/u/TsuWeiQuan)\
**Replies:** 5\
**Last updated:** [May 24, 2019, 10:31am UTC](https://discuss.elastic.co/t/is-it-ok-to-leave-all-my-metricbeats-with-the-default-index-name/182113 "2019-05-24T10:31:57Z")

</div>

Is it ok to leave all my metricbeats with the default index name as long as i am able to display live data? Or Isit actually recommended to separate each instance's metric beat with a unique name? I am setting up the …

---

## [Input docker stuck when bad offset is saved in registry file - bug?](https://discuss.elastic.co/t/input-docker-stuck-when-bad-offset-is-saved-in-registry-file-bug/181828)

<div class="topic-metadata">

**Author:** [@marqc](https://discuss.elastic.co/u/marqc)\
**Replies:** 2\
**Last updated:** [May 24, 2019, 10:28am UTC](https://discuss.elastic.co/t/input-docker-stuck-when-bad-offset-is-saved-in-registry-file-bug/181828 "2019-05-24T10:28:08Z")

</div>

I'm using filebeat with docker input. In offset registry offset saved for specified docker file was incorect (probably some unclean shutdown or docker output file rotated when filebeat was down). When filebeat started a…

---

## [Output.elasticsearch.indices matching not working in 7.0.1](https://discuss.elastic.co/t/output-elasticsearch-indices-matching-not-working-in-7-0-1/182396)

<div class="topic-metadata">

**Author:** [@pa-jberanek](https://discuss.elastic.co/u/pa-jberanek)\
**Replies:** 11\
**Last updated:** [May 24, 2019, 7:59am UTC](https://discuss.elastic.co/t/output-elasticsearch-indices-matching-not-working-in-7-0-1/182396 "2019-05-24T07:59:31Z")

</div>

Just upgraded from Elastic Stack 6.7.1 to 7.0.1 and filebeat configuration I had to dynamically change the index name appears to have stopped working. My simple config: filebeat.inputs: - type: log paths: - /sysl…

---

## [Custom beats not writing logs in file when starting as service](https://discuss.elastic.co/t/custom-beats-not-writing-logs-in-file-when-starting-as-service/180958)

<div class="topic-metadata">

**Author:** [@debasish283](https://discuss.elastic.co/u/debasish283)\
**Replies:** 2\
**Last updated:** [May 24, 2019, 3:57am UTC](https://discuss.elastic.co/t/custom-beats-not-writing-logs-in-file-when-starting-as-service/180958 "2019-05-24T03:57:17Z")

</div>

Hi All, We have build custom beats for our use case and able to start the service successfully but logs are not writing to the specified log path (var/log/beats) Below is the config of beat.yml, beat: # Defines how …

---

## [Disable fileintegrity and dataset module in auditbeat](https://discuss.elastic.co/t/disable-fileintegrity-and-dataset-module-in-auditbeat/177063)

<div class="topic-metadata">

**Author:** [@nandha\_88](https://discuss.elastic.co/u/nandha_88)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 10:22pm UTC](https://discuss.elastic.co/t/disable-fileintegrity-and-dataset-module-in-auditbeat/177063 "2019-05-23T22:22:35Z")

</div>

Hi All, I just need to record the commands run by users. I dont like to have file integrity and system module in the auditbeat because my syslog server diskspace getting filed weekly once and auditbeat module consist of…

---

## [Auditbeat crashes few seconds after start](https://discuss.elastic.co/t/auditbeat-crashes-few-seconds-after-start/182444)

<div class="topic-metadata">

**Author:** [@Olivier\_JUDITH](https://discuss.elastic.co/u/Olivier_JUDITH)\
**Replies:** 3\
**Last updated:** [May 23, 2019, 8:35pm UTC](https://discuss.elastic.co/t/auditbeat-crashes-few-seconds-after-start/182444 "2019-05-23T20:35:36Z")

</div>

My conf Redhat EL7 x64 auditbeat 7.1 (tar.gz) Any idea ? / 2019-05-23T14:51:03.739+0200 INFO \[monitoring\] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"auditd":{"received\_msgs":12},"be…

---

## [AES Encryption at rest for winlogbeat.yml](https://discuss.elastic.co/t/aes-encryption-at-rest-for-winlogbeat-yml/179387)

<div class="topic-metadata">

**Author:** [@magneton](https://discuss.elastic.co/u/magneton)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 7:26pm UTC](https://discuss.elastic.co/t/aes-encryption-at-rest-for-winlogbeat-yml/179387 "2019-05-23T19:26:51Z")

</div>

Hi All, Is there a way to encrypt the winlogbeat.yml file for winlogbeat so that if an attacker lands on a windows box they cant just read the logging configuration? The idea would be to have it encrypted at rest and d…

---

## [Possible to use Beats processors instead of logstash for adding transforms / fields?](https://discuss.elastic.co/t/possible-to-use-beats-processors-instead-of-logstash-for-adding-transforms-fields/182507)

<div class="topic-metadata">

**Author:** [@mzmuda](https://discuss.elastic.co/u/mzmuda)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 7:20pm UTC](https://discuss.elastic.co/t/possible-to-use-beats-processors-instead-of-logstash-for-adding-transforms-fields/182507 "2019-05-23T19:20:56Z")

</div>

Hi all, I'm wondering if it's possible to use the processors in beats / filebeats instead of logstash filters to add fields for data / visualization? Right now I have filebeats configured to send data directly to elast…

---

## [Metricbeat MSSQL module How to configure SQL server connection on other TCP listening ports](https://discuss.elastic.co/t/metricbeat-mssql-module-how-to-configure-sql-server-connection-on-other-tcp-listening-ports/179936)

<div class="topic-metadata">

**Author:** [@Jerome\_Cabaret](https://discuss.elastic.co/u/Jerome_Cabaret)\
**Replies:** 4\
**Last updated:** [May 23, 2019, 6:13pm UTC](https://discuss.elastic.co/t/metricbeat-mssql-module-how-to-configure-sql-server-connection-on-other-tcp-listening-ports/179936 "2019-05-23T18:13:34Z")

</div>

How to configure the hosts with a different tcp listen port ========================================================= module: mssql metricsets: "transaction\_log" "performance" hosts: \["sqlserver:user:password@tcp…

---

## [Filebeat consumes a large amount of disk io reads on a Kubernetes node](https://discuss.elastic.co/t/filebeat-consumes-a-large-amount-of-disk-io-reads-on-a-kubernetes-node/180022)

<div class="topic-metadata">

**Author:** [@Max\_Brain](https://discuss.elastic.co/u/Max_Brain)\
**Replies:** 6\
**Last updated:** [May 23, 2019, 6:11pm UTC](https://discuss.elastic.co/t/filebeat-consumes-a-large-amount-of-disk-io-reads-on-a-kubernetes-node/180022 "2019-05-23T18:11:42Z")

</div>

When running Filebeat on a Kubernetes node, the system is spending a large amount of cpu cycles on iowait. According to according to iotop, the system during this time is writing 10 MB/S. Reads account for upwards of 150…

---

## [Settings from keystore doesnot load](https://discuss.elastic.co/t/settings-from-keystore-doesnot-load/182321)

<div class="topic-metadata">

**Author:** [@Thanura\_Kannangara](https://discuss.elastic.co/u/Thanura_Kannangara)\
**Replies:** 4\
**Last updated:** [May 23, 2019, 5:19pm UTC](https://discuss.elastic.co/t/settings-from-keystore-doesnot-load/182321 "2019-05-23T17:19:47Z")

</div>

I'm running OSS version of winlogbeat winlogbeat-oss-6.7.1-windows-x86\_64 I created winlogbeat keystore and stored ES\_PWD using instructions available here and I'm using refering to the key as mentioned in the above m…

---

## [Runtime: out of memory](https://discuss.elastic.co/t/runtime-out-of-memory/182460)

<div class="topic-metadata">

**Author:** [@Nishar\_shaik](https://discuss.elastic.co/u/Nishar_shaik)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 4:05pm UTC](https://discuss.elastic.co/t/runtime-out-of-memory/182460 "2019-05-23T16:05:36Z")

</div>

Hey all ! I am working on Kibana ,which i included Packet beat file to get the Network Data.I installed the packet data into my system and configured packetbeat.yml file too but when i run packetbeat setup --dashboards …

---

## [Filebeat error on processing log file](https://discuss.elastic.co/t/filebeat-error-on-processing-log-file/181252)

<div class="topic-metadata">

**Author:** [@ankitachow](https://discuss.elastic.co/u/ankitachow)\
**Replies:** 3\
**Last updated:** [May 23, 2019, 3:51pm UTC](https://discuss.elastic.co/t/filebeat-error-on-processing-log-file/181252 "2019-05-23T15:51:12Z")

</div>

I'm trying to ingest log from filebeat, parsed through logstash and ingest in Elasticsearch. To make the pipeline work, I didnt add the grok yet but the log file is not moving forward with below error I'm using 6.x ver…

---

## [System\_api\_version \[7\] is not supported by system\_id beats](https://discuss.elastic.co/t/system-api-version-7-is-not-supported-by-system-id-beats/182406)

<div class="topic-metadata">

**Author:** [@Urs\_Bronk](https://discuss.elastic.co/u/Urs_Bronk)\
**Replies:** 5\
**Last updated:** [May 23, 2019, 2:03pm UTC](https://discuss.elastic.co/t/system-api-version-7-is-not-supported-by-system-id-beats/182406 "2019-05-23T14:03:27Z")

</div>

Hi, I'm trying to monitor my filebeats on Kibana through elasticsearch. I get the following error: system\_api\_version \[7\] is not supported by system\_id ERROR pipeline/output.go:121 Failed to publish events: 400 Ba…

---

## [Packetbeat - external API response](https://discuss.elastic.co/t/packetbeat-external-api-response/182308)

<div class="topic-metadata">

**Author:** [@Paula](https://discuss.elastic.co/u/Paula)\
**Replies:** 2\
**Last updated:** [May 23, 2019, 12:52pm UTC](https://discuss.elastic.co/t/packetbeat-external-api-response/182308 "2019-05-23T12:52:35Z")

</div>

Quick configuration question... new to beats Viewing json status code and bytes output for each request however not the actual response. Is there a yml flag to set in order to display? Please advise, Thanks!

---

## [Failing to capture oracle alert logs (kubernetes)](https://discuss.elastic.co/t/failing-to-capture-oracle-alert-logs-kubernetes/181963)

<div class="topic-metadata">

**Author:** [@Maurya\_M](https://discuss.elastic.co/u/Maurya_M)\
**Replies:** 7\
**Last updated:** [May 23, 2019, 12:17pm UTC](https://discuss.elastic.co/t/failing-to-capture-oracle-alert-logs-kubernetes/181963 "2019-05-23T12:17:11Z")

</div>

Hi, Having a setup wherein my oracle is deployed on kubernetes as statefulset, i need to monitor some logs other than the container logs, so from documentation and examples online was able create a filebeat config such …

---

## [When using heartbeat it is showing portal is down even when my portal is not down](https://discuss.elastic.co/t/when-using-heartbeat-it-is-showing-portal-is-down-even-when-my-portal-is-not-down/182418)

<div class="topic-metadata">

**Author:** [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Replies:** 0\
**Last updated:** [May 23, 2019, 11:50am UTC](https://discuss.elastic.co/t/when-using-heartbeat-it-is-showing-portal-is-down-even-when-my-portal-is-not-down/182418 "2019-05-23T11:50:50Z")

</div>

I am getting this message in error.message field dial tcp 103.253.70.90:443: connect: connection refused

---

## [Differentiate between logs based on log.file.path](https://discuss.elastic.co/t/differentiate-between-logs-based-on-log-file-path/180496)

<div class="topic-metadata">

**Author:** [@rplus](https://discuss.elastic.co/u/rplus)\
**Replies:** 8\
**Last updated:** [May 23, 2019, 5:27am UTC](https://discuss.elastic.co/t/differentiate-between-logs-based-on-log-file-path/180496 "2019-05-23T05:27:59Z")

</div>

Hi, I've a server hosting several sites containing multiple IIS logs from each site in structure like this: D:\\IISLogs\\Customer1\\logs D:\\IISLogs\\Customer2\\logs D:\\IISLogs\\Customer3\\logs I'm using filebeat with IIS m…

---

## [Filebeat Failed to connect to backoff(async(tcp:logstash:5044](https://discuss.elastic.co/t/filebeat-failed-to-connect-to-backoff-async-tcp5044/182147)

<div class="topic-metadata">

**Author:** [@hari.v](https://discuss.elastic.co/u/hari.v)\
**Replies:** 2\
**Last updated:** [May 23, 2019, 2:37am UTC](https://discuss.elastic.co/t/filebeat-failed-to-connect-to-backoff-async-tcp5044/182147 "2019-05-23T02:37:21Z")

</div>

Hi i tried to setup filebeat 7 in my client server.. log message shows: May 22 22:50:06 beat filebeat: 2019-05-22T22:50:06.108+0800#011ERROR#011pipeline/output.go:100#011Failed to connect to backoff(async(tcp://192.16…

---

## [Filebeat fails to send logs to Elasticsearch](https://discuss.elastic.co/t/filebeat-fails-to-send-logs-to-elasticsearch/181250)

<div class="topic-metadata">

**Author:** [@surya2](https://discuss.elastic.co/u/surya2)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 1:05am UTC](https://discuss.elastic.co/t/filebeat-fails-to-send-logs-to-elasticsearch/181250 "2019-05-23T01:05:54Z")

</div>

Hello, I have filebeat (5.6.3) when i am trying to ship logs to Elasticsearch i get below error. 2019-05-15T14:01:19.553-0400 ERROR pipeline/output.go:92 Failed to publish events: Post http://demo.com:9200/\_bulk: n…

---

## [How do we know if the filebeat processed log successfully](https://discuss.elastic.co/t/how-do-we-know-if-the-filebeat-processed-log-successfully/181454)

<div class="topic-metadata">

**Author:** [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 1:03am UTC](https://discuss.elastic.co/t/how-do-we-know-if-the-filebeat-processed-log-successfully/181454 "2019-05-23T01:03:44Z")

</div>

Hello Experts, how do we know if filebeat successfully sent log entry to logstash? Here is my filebeat logs prints: ":387}},"total":{"ticks":1270,"time":{"ms":1281},"value":1270},"user":{"ticks":890,"time":{"ms":894}}…

---

## [Multiple IIS logs - Add field (?)](https://discuss.elastic.co/t/multiple-iis-logs-add-field/181319)

<div class="topic-metadata">

**Author:** [@shortcommand](https://discuss.elastic.co/u/shortcommand)\
**Replies:** 2\
**Last updated:** [May 23, 2019, 1:00am UTC](https://discuss.elastic.co/t/multiple-iis-logs-add-field/181319 "2019-05-23T01:00:05Z")

</div>

Hi, I don't know if this goes into filebeat category, logstash or both. I've around 50 websites on a single server. Running one instance of filebeat with IIS module enabled. My problem is that In Kibana I would like to …

---

## [Message of length too large or too small](https://discuss.elastic.co/t/message-of-length-too-large-or-too-small/181563)

<div class="topic-metadata">

**Author:** [@joongwan\_koo](https://discuss.elastic.co/u/joongwan_koo)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 12:54am UTC](https://discuss.elastic.co/t/message-of-length-too-large-or-too-small/181563 "2019-05-23T00:54:03Z")

</div>

Hi i makeing a log anslysis system using elastic It worked well in the test environment, but the following error occurred int the live environment. the target log file size is 140M , and error message is more 1g syste…

---

## [Filebeat for apache logs on Windows](https://discuss.elastic.co/t/filebeat-for-apache-logs-on-windows/181797)

<div class="topic-metadata">

**Author:** [@pup\_seba](https://discuss.elastic.co/u/pup_seba)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 12:48am UTC](https://discuss.elastic.co/t/filebeat-for-apache-logs-on-windows/181797 "2019-05-23T00:48:52Z")

</div>

Hi! I'm trying to configure this module for filebeat, but I keep geting errors like "No paths were defined for input accessing config". I've tried configuring the apache.yml module (which we enabled) by modifying its v…

---

## [Filebeat not able to find logs on microk8](https://discuss.elastic.co/t/filebeat-not-able-to-find-logs-on-microk8/182023)

<div class="topic-metadata">

**Author:** [@srilumpa](https://discuss.elastic.co/u/srilumpa)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 12:39am UTC](https://discuss.elastic.co/t/filebeat-not-able-to-find-logs-on-microk8/182023 "2019-05-23T00:39:39Z")

</div>

Hi, I'm struggling to configure a filebeat container to be able to read logs from containers running on a kubernetes microK8 instance. On microk8, logs are stored directly in /var/log/containers: # ls /var/log/contain…

---

## [Filebeat running but not sending logs to logstash](https://discuss.elastic.co/t/filebeat-running-but-not-sending-logs-to-logstash/182036)

<div class="topic-metadata">

**Author:** [@govk222](https://discuss.elastic.co/u/govk222)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 12:38am UTC](https://discuss.elastic.co/t/filebeat-running-but-not-sending-logs-to-logstash/182036 "2019-05-23T00:38:27Z")

</div>

Hi, I see: 2019-05-21T14:42:36.988Z INFO \[monitoring\] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":50,"time":{"ms":1}},"total":{"tick…

---

## [Filebeat 5.x install and file migration](https://discuss.elastic.co/t/filebeat-5-x-install-and-file-migration/182307)

<div class="topic-metadata">

**Author:** [@EtienneDemers](https://discuss.elastic.co/u/EtienneDemers)\
**Replies:** 1\
**Last updated:** [May 23, 2019, 12:35am UTC](https://discuss.elastic.co/t/filebeat-5-x-install-and-file-migration/182307 "2019-05-23T00:35:40Z")

</div>

I have a filebeat on a web server forwarding a logfile to a logstash instance. I'm planning to migrate said web server and i'll migrate the whole logfile and install the same filebeat version (5.6.4) and migrate it's ru…

---

## [Apache HTTPD logs with (comma-delimited) X-Forwarded-For IPs](https://discuss.elastic.co/t/apache-httpd-logs-with-comma-delimited-x-forwarded-for-ips/181917)

<div class="topic-metadata">

**Author:** [@jamiejackson](https://discuss.elastic.co/u/jamiejackson)\
**Replies:** 4\
**Last updated:** [May 22, 2019, 5:17pm UTC](https://discuss.elastic.co/t/apache-httpd-logs-with-comma-delimited-x-forwarded-for-ips/181917 "2019-05-22T17:17:33Z")

</div>

Hi Folks, I thought I'd be able to use the filebeat apache module out of the box, but then I noticed the handling of X-Forwarded-For. It only seems to get the inner-most IP from it (which is a proxy, and not the end-use…

---

## [Index Naming issues](https://discuss.elastic.co/t/index-naming-issues/180557)

<div class="topic-metadata">

**Author:** [@itguy\_chris](https://discuss.elastic.co/u/itguy_chris)\
**Replies:** 4\
**Last updated:** [May 22, 2019, 12:36pm UTC](https://discuss.elastic.co/t/index-naming-issues/180557 "2019-05-22T12:36:41Z")

</div>

I've been doing some searching and tried a few things already, even tried to create a new template (but failed) ... not even sure that is what is required. Outline: 5 production servers using IIS 3 dev servers using I…

---

## [Process Logs line after the line](https://discuss.elastic.co/t/process-logs-line-after-the-line/181992)

<div class="topic-metadata">

**Author:** [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Replies:** 2\
**Last updated:** [May 22, 2019, 9:57am UTC](https://discuss.elastic.co/t/process-logs-line-after-the-line/181992 "2019-05-22T09:57:01Z")

</div>

I have a log file in below format and I'm using filebeats to push to Logstash Currenttime="5/21/19 1:42 AM" Job="MyJob" Status="WAITING" START\_TIME="" END\_TIME="" AVG\_TIME=146 Currenttime="5/21/19 3:00 AM" Job="MyJob" S…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=352)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=354)
