# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=354

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 355

---

## [Regex doesn't work - metricbeat system module](https://discuss.elastic.co/t/regex-doesnt-work-metricbeat-system-module/182177)

<div class="topic-metadata">

**Author:** [@jasony](https://discuss.elastic.co/u/jasony)\
**Replies:** 0\
**Last updated:** [May 22, 2019, 8:55am UTC](https://discuss.elastic.co/t/regex-doesnt-work-metricbeat-system-module/182177 "2019-05-22T08:55:01Z")

</div>

metricbeat.modules: - module: system metricsets: \["process"\] enabled: true period: 60s processes: \['^.\*logstash.\*$'\] fields: dc: doj-dev host: "doj-dev-elk-col-01" cluster\_type: "collector" ... $ p…

---

## [No data in uptime dashboard](https://discuss.elastic.co/t/no-data-in-uptime-dashboard/179651)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 7\
**Last updated:** [May 22, 2019, 7:49am UTC](https://discuss.elastic.co/t/no-data-in-uptime-dashboard/179651 "2019-05-22T07:49:48Z")

</div>

My uptime dashboard is empty. I am able to see data flowing in the discover tab for the urls I have configured in the heartbeat.yml file. I am able to see data in the Heartbeat default dashboard but the uptime is empty. …

---

## [DNS tunneling](https://discuss.elastic.co/t/dns-tunneling/181919)

<div class="topic-metadata">

**Author:** [@pathri](https://discuss.elastic.co/u/pathri)\
**Replies:** 5\
**Last updated:** [May 22, 2019, 3:57am UTC](https://discuss.elastic.co/t/dns-tunneling/181919 "2019-05-22T03:57:11Z")

</div>

i can see pre build dashboards for DNS while using packetbeat at below location /usr/share/packetbeat/kibana/7/dashboard/Packetbeat-dns-tunneling.json. What i am supposed to do so that this dashboard will be visible in…

---

## [Filebeat JSON string](https://discuss.elastic.co/t/filebeat-json-string/182052)

<div class="topic-metadata">

**Author:** [@NFhbar](https://discuss.elastic.co/u/NFhbar)\
**Replies:** 0\
**Last updated:** [May 21, 2019, 3:33pm UTC](https://discuss.elastic.co/t/filebeat-json-string/182052 "2019-05-21T15:33:00Z")

</div>

I have a filebeat configuration as follows: filebeat.yml: |- filebeat.autodiscover: providers: - type: kubernetes hints.enabled: true templates: - condition: …

---

## [Events being not published to logstash when using drop\_event.when.not.or processor](https://discuss.elastic.co/t/events-being-not-published-to-logstash-when-using-drop-event-when-not-or-processor/181857)

<div class="topic-metadata">

**Author:** [@nhscyberguy](https://discuss.elastic.co/u/nhscyberguy)\
**Replies:** 8\
**Last updated:** [May 21, 2019, 2:32pm UTC](https://discuss.elastic.co/t/events-being-not-published-to-logstash-when-using-drop-event-when-not-or-processor/181857 "2019-05-21T14:32:07Z")

</div>

Hi I'm having a problem with winlogbeat not publishing events to logstash when I configure the processors for Security events so that I can specify more than the 22 limit: - name: Security ignore\_older: 72h p…

---

## [Cannon simple change index name in filebeat](https://discuss.elastic.co/t/cannon-simple-change-index-name-in-filebeat/181973)

<div class="topic-metadata">

**Author:** [@patsevanton](https://discuss.elastic.co/u/patsevanton)\
**Replies:** 2\
**Last updated:** [May 21, 2019, 10:51am UTC](https://discuss.elastic.co/t/cannon-simple-change-index-name-in-filebeat/181973 "2019-05-21T10:51:58Z")

</div>

ELK - 7.0.1 Filebeat - 7.0.1 cat /etc/filebeat/filebeat.yml filebeat.inputs: - type: log enabled: true paths: - '/var/lib/docker/containers/\*/\*.log' json.keys\_under\_root: true json.message\_key: log encod…

---

## [Filebeat on docker/kubernetes - delay termination to attempt to clear queue?](https://discuss.elastic.co/t/filebeat-on-docker-kubernetes-delay-termination-to-attempt-to-clear-queue/181944)

<div class="topic-metadata">

**Author:** [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Replies:** 1\
**Last updated:** [May 21, 2019, 8:50am UTC](https://discuss.elastic.co/t/filebeat-on-docker-kubernetes-delay-termination-to-attempt-to-clear-queue/181944 "2019-05-21T08:50:14Z")

</div>

I have Filebeat running in a sidecar container, alongside my app container, in a Kubernetes pod. They share an attached volume: the app is writing JSON logs and Filebeat is shipping them. I have a daemonset Filebeat ru…

---

## [Filebeat - stalls and effectively hangs when max request size exceeded](https://discuss.elastic.co/t/filebeat-stalls-and-effectively-hangs-when-max-request-size-exceeded/178437)

<div class="topic-metadata">

**Author:** [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Replies:** 4\
**Last updated:** [May 21, 2019, 8:04am UTC](https://discuss.elastic.co/t/filebeat-stalls-and-effectively-hangs-when-max-request-size-exceeded/178437 "2019-05-21T08:04:12Z")

</div>

I'm using filebeat to send raw JSON documents (one per line) to a hosted (cloud.elastic.co) ES cluster. The max request size is not configurable server-side, and despite tweaking the batch size in the elasticsearch conf…

---

## [Filebeat refuses to log to file (7.0.1)](https://discuss.elastic.co/t/filebeat-refuses-to-log-to-file-7-0-1/181846)

<div class="topic-metadata">

**Author:** [@buzzlightyear](https://discuss.elastic.co/u/buzzlightyear)\
**Replies:** 2\
**Last updated:** [May 21, 2019, 7:41am UTC](https://discuss.elastic.co/t/filebeat-refuses-to-log-to-file-7-0-1/181846 "2019-05-21T07:41:22Z")

</div>

Filebeat is configured to log to /var/log/filebeat, but it only logs to syslog. /var/log/filebeat directory does exist, and filebeat logs no error or warning to syslog to indicate any issues with logging to files. I've …

---

## [Dynamic fields in request body](https://discuss.elastic.co/t/dynamic-fields-in-request-body/180777)

<div class="topic-metadata">

**Author:** [@Mattias\_Arbin](https://discuss.elastic.co/u/Mattias_Arbin)\
**Replies:** 2\
**Last updated:** [May 20, 2019, 2:39pm UTC](https://discuss.elastic.co/t/dynamic-fields-in-request-body/180777 "2019-05-20T14:39:17Z")

</div>

I have a need to generate dynamic content in the request body of http-based heartbeat requests. I need to generate a unique UUID for each call and also a timstamp based on current time in ISO 8601 format. e.g.: check.…

---

## [Redis output and missing fields](https://discuss.elastic.co/t/redis-output-and-missing-fields/181785)

<div class="topic-metadata">

**Author:** [@faisanroses](https://discuss.elastic.co/u/faisanroses)\
**Replies:** 0\
**Last updated:** [May 20, 2019, 10:13am UTC](https://discuss.elastic.co/t/redis-output-and-missing-fields/181785 "2019-05-20T10:13:40Z")

</div>

Hello! I've been stuck with the Beats / Redis / Logstash configuration for several weeks and maybe someone of you could help me. Currently I have implemented Elasticsearch Stack with Docker so that the output of the Bea…

---

## [Using metricbeat to monitor infrastructure](https://discuss.elastic.co/t/using-metricbeat-to-monitor-infrastructure/181153)

<div class="topic-metadata">

**Author:** [@omardawed](https://discuss.elastic.co/u/omardawed)\
**Replies:** 2\
**Last updated:** [May 20, 2019, 9:47am UTC](https://discuss.elastic.co/t/using-metricbeat-to-monitor-infrastructure/181153 "2019-05-20T09:47:06Z")

</div>

hello, i have configured metricbeat i can visualise logs but i want to monitor the host using the infrastructure tab. how to do this , what is the right configuration ?

---

## [HTTP Metricset data in Windows metricset documents](https://discuss.elastic.co/t/http-metricset-data-in-windows-metricset-documents/181737)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 6\
**Last updated:** [May 20, 2019, 9:40am UTC](https://discuss.elastic.co/t/http-metricset-data-in-windows-metricset-documents/181737 "2019-05-20T09:40:19Z")

</div>

Hi- I just noticed the HTTP metricset added to the metricbeats modules, Is there a way to make a http get call and add the response to the all Windows metricset documents. Would it be possible? Please let me know. Thank…

---

## [Is there a way to edit grok filters in existing filebeat module?](https://discuss.elastic.co/t/is-there-a-way-to-edit-grok-filters-in-existing-filebeat-module/180528)

<div class="topic-metadata">

**Author:** [@ssardana08](https://discuss.elastic.co/u/ssardana08)\
**Replies:** 1\
**Last updated:** [May 20, 2019, 8:45am UTC](https://discuss.elastic.co/t/is-there-a-way-to-edit-grok-filters-in-existing-filebeat-module/180528 "2019-05-20T08:45:42Z")

</div>

I want to add some more fields in the filters of Haproxy module as it is not fetching all the data. Is it possible to do so?

---

## [Metricbeat 7.0.1 causes parse errors on elasticsearch](https://discuss.elastic.co/t/metricbeat-7-0-1-causes-parse-errors-on-elasticsearch/180788)

<div class="topic-metadata">

**Author:** [@s.pawluk.krd](https://discuss.elastic.co/u/s.pawluk.krd)\
**Replies:** 2\
**Last updated:** [May 20, 2019, 7:27am UTC](https://discuss.elastic.co/t/metricbeat-7-0-1-causes-parse-errors-on-elasticsearch/180788 "2019-05-20T07:27:44Z")

</div>

\[2019-05-13T12:44:04,931\]\[DEBUG\]\[o.e.a.b.TransportShardBulkAction\] \[ELK-DATA03\] \[metricbeat-7.0.1-2019.05.13-000001\]\[0\] failed to execute bulk item (index) index {\[metricbeat-7.0.1\]\[\_doc\]\[HwrKsGoB-qY06G5b1mox\], source\[{"…

---

## [Heartbeat is crashing due to High Availability Cluster Communication](https://discuss.elastic.co/t/heartbeat-is-crashing-due-to-high-availability-cluster-communication/181588)

<div class="topic-metadata">

**Author:** [@iamyogesh](https://discuss.elastic.co/u/iamyogesh)\
**Replies:** 3\
**Last updated:** [May 20, 2019, 7:33am UTC](https://discuss.elastic.co/t/heartbeat-is-crashing-due-to-high-availability-cluster-communication/181588 "2019-05-20T07:33:40Z")

</div>

For confirmed bugs, please report: Version: heartbeat 5.4.3, elasticsearch 4 node cluster with version 6.3.2 Operating System: heartbeat installed on ubuntu 18.04, elasticsearch cluster centos 7 Discuss Forum URL: hea…

---

## [Functionbeat with AWS Elasticsearch Service](https://discuss.elastic.co/t/functionbeat-with-aws-elasticsearch-service/181712)

<div class="topic-metadata">

**Author:** [@fbidu](https://discuss.elastic.co/u/fbidu)\
**Replies:** 1\
**Last updated:** [May 19, 2019, 1:15pm UTC](https://discuss.elastic.co/t/functionbeat-with-aws-elasticsearch-service/181712 "2019-05-19T13:15:24Z")

</div>

Hello, After searching around for a while and deploying some test functions, I haven't been able to make Functionbeat output logs to AWS's Elasticsearch service. Has anybody here been able to achieve this successfully?…

---

## [Filebeat Module Custom Index](https://discuss.elastic.co/t/filebeat-module-custom-index/181350)

<div class="topic-metadata">

**Author:** [@jbws](https://discuss.elastic.co/u/jbws)\
**Replies:** 1\
**Last updated:** [May 17, 2019, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-module-custom-index/181350 "2019-05-17T22:26:14Z")

</div>

I currently have application logs going in to an index through Filebeat, but would like to use the NGINX module to send access and error logs to a seperate instance through the same Filebeat. I can see how to set the lo…

---

## [Metricbeat-6.6.0 "MySQL module" ("MySQL status metricset" can't connect to MySQL 8)](https://discuss.elastic.co/t/metricbeat-6-6-0-mysql-module-mysql-status-metricset-cant-connect-to-mysql-8/181599)

<div class="topic-metadata">

**Author:** [@Sergey\_Ambaryan](https://discuss.elastic.co/u/Sergey_Ambaryan)\
**Replies:** 3\
**Last updated:** [May 17, 2019, 9:02pm UTC](https://discuss.elastic.co/t/metricbeat-6-6-0-mysql-module-mysql-status-metricset-cant-connect-to-mysql-8/181599 "2019-05-17T21:02:14Z")

</div>

Hi! I have MySQL Ver 8.0.13 for Linux and i have installed and configured Metricbeat-6.6.0 with enabled module "mysql" (enabled metricsets "- status"). But, when i run metricbeat - in debug log i see next part of messa…

---

## [Filebeat exclude and include lines](https://discuss.elastic.co/t/filebeat-exclude-and-include-lines/181458)

<div class="topic-metadata">

**Author:** [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Replies:** 5\
**Last updated:** [May 17, 2019, 3:00pm UTC](https://discuss.elastic.co/t/filebeat-exclude-and-include-lines/181458 "2019-05-17T15:00:44Z")

</div>

Hello Experts, Before sending my logs to logstash I would like remove some lines which is not needed, and I also know which exact lines I need to send to my logstash to further process my logs using groks. Which option…

---

## [Multiple hosts feeding into 1 node](https://discuss.elastic.co/t/multiple-hosts-feeding-into-1-node/181569)

<div class="topic-metadata">

**Author:** [@cowensel](https://discuss.elastic.co/u/cowensel)\
**Replies:** 0\
**Last updated:** [May 17, 2019, 10:44am UTC](https://discuss.elastic.co/t/multiple-hosts-feeding-into-1-node/181569 "2019-05-17T10:44:20Z")

</div>

We are looking into the possibility of using metricbeat to monitor our Windows hosts. We would have about 15 servers going into elasticsearch directly. What do you recommend? is this the best way to do it or is it bette…

---

## [Metricbeat on AWS ECS using Fargate](https://discuss.elastic.co/t/metricbeat-on-aws-ecs-using-fargate/175277)

<div class="topic-metadata">

**Author:** [@monster](https://discuss.elastic.co/u/monster)\
**Replies:** 7\
**Last updated:** [May 17, 2019, 9:27am UTC](https://discuss.elastic.co/t/metricbeat-on-aws-ecs-using-fargate/175277 "2019-05-17T09:27:31Z")

</div>

I am trying to run Metricbeat using docker as a "sidecar" container in an ECS Fargate Task. Unfortunately when running inside Fargate containers cannot mount volumes on the host such as the /var/run/docker.sock required …

---

## [Can't push filebeat 6.5.3 index template to Elasticsearch](https://discuss.elastic.co/t/cant-push-filebeat-6-5-3-index-template-to-elasticsearch/181512)

<div class="topic-metadata">

**Author:** [@ganchu](https://discuss.elastic.co/u/ganchu)\
**Replies:** 0\
**Last updated:** [May 17, 2019, 5:24am UTC](https://discuss.elastic.co/t/cant-push-filebeat-6-5-3-index-template-to-elasticsearch/181512 "2019-05-17T05:24:18Z")

</div>

I trying Bro logs to logstash using filebeat-6.5.3. So I configured using \[https://github.com/mellow-hype/bro-stash\](http://this config) and pushing template to elasticsearch curl -XPUT 'http://localhost:9200/\_templat…

---

## [Nginx Module Dashboards "No data to display"](https://discuss.elastic.co/t/nginx-module-dashboards-no-data-to-display/180402)

<div class="topic-metadata">

**Author:** [@tpurcell](https://discuss.elastic.co/u/tpurcell)\
**Replies:** 4\
**Last updated:** [May 17, 2019, 4:18am UTC](https://discuss.elastic.co/t/nginx-module-dashboards-no-data-to-display/180402 "2019-05-17T04:18:31Z")

</div>

Hello Newbie here. I'm running the ELK stack with all components at version 7.0.1 in an Ubuntu 18.04 environment. My environment has nginx running in a docker container. my filebeat process is running on the docker hos…

---

## [Issue With reading file containing \\r or ^M as line terminator](https://discuss.elastic.co/t/issue-with-reading-file-containing-r-or-m-as-line-terminator/181155)

<div class="topic-metadata">

**Author:** [@Linoj\_Wilson](https://discuss.elastic.co/u/Linoj_Wilson)\
**Replies:** 5\
**Last updated:** [May 17, 2019, 2:35am UTC](https://discuss.elastic.co/t/issue-with-reading-file-containing-r-or-m-as-line-terminator/181155 "2019-05-17T02:35:11Z")

</div>

Dear All, I am trying to read some custom logs. I am using multi pattern as well. The file is containing only \\r or ^M as line terminator. I tried with line terminator configuration auto and carriage\_return as well. But…

---

## [Configure filebeat to send only required fields](https://discuss.elastic.co/t/configure-filebeat-to-send-only-required-fields/181479)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 2\
**Last updated:** [May 16, 2019, 9:43pm UTC](https://discuss.elastic.co/t/configure-filebeat-to-send-only-required-fields/181479 "2019-05-16T21:43:07Z")

</div>

Hi My filebeat send the following data to ES. I don't need all the fields Is there a way I can configure filebeat to send only required fields. Supporse I only need few fileds from the below data to be sent to ES. { …

---

## [Filebeat pipeline setup for system module ignores var.convert\_timezone: true?](https://discuss.elastic.co/t/filebeat-pipeline-setup-for-system-module-ignores-var-convert-timezone-true/181456)

<div class="topic-metadata">

**Author:** [@pdizz](https://discuss.elastic.co/u/pdizz)\
**Replies:** 2\
**Last updated:** [May 16, 2019, 9:29pm UTC](https://discuss.elastic.co/t/filebeat-pipeline-setup-for-system-module-ignores-var-convert-timezone-true/181456 "2019-05-16T21:29:46Z")

</div>

I'm trying to set up the filebeat system module to send logs to elastic through logstash. I'm following the filebeat "getting started" docs but the ingest pipeline that is created by the filebeat setup command is missing…

---

## [Filebeat always logging at least at DEBUG level](https://discuss.elastic.co/t/filebeat-always-logging-at-least-at-debug-level/181470)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 1\
**Last updated:** [May 16, 2019, 7:30pm UTC](https://discuss.elastic.co/t/filebeat-always-logging-at-least-at-debug-level/181470 "2019-05-16T19:30:05Z")

</div>

Hi, in my filebeat.yml file I have: logging.level: error , in spite of the filebeat is writing all messages (DEBUG, INFO, ERROR). Thinking it might be needing the -v option at the command line, I start filebeat this w…

---

## [Custom Input within Filebeat?](https://discuss.elastic.co/t/custom-input-within-filebeat/181453)

<div class="topic-metadata">

**Author:** [@thebenwaters](https://discuss.elastic.co/u/thebenwaters)\
**Replies:** 1\
**Last updated:** [May 16, 2019, 7:27pm UTC](https://discuss.elastic.co/t/custom-input-within-filebeat/181453 "2019-05-16T19:27:05Z")

</div>

I'm trying to create a beat for Okta. https://github.com/forter/oktabeat The only issue is it has to be pull and there's no way to track state. I wanted to try and hijack off of Filebeat's registar to be able to track…

---

## [No metric kubernetes.pod.cpu.usage.limit.pct in event output](https://discuss.elastic.co/t/no-metric-kubernetes-pod-cpu-usage-limit-pct-in-event-output/181216)

<div class="topic-metadata">

**Author:** [@Ethan\_Lebioda](https://discuss.elastic.co/u/Ethan_Lebioda)\
**Replies:** 3\
**Last updated:** [May 16, 2019, 2:46pm UTC](https://discuss.elastic.co/t/no-metric-kubernetes-pod-cpu-usage-limit-pct-in-event-output/181216 "2019-05-16T14:46:37Z")

</div>

Metricbeat documentation shows that pod level metrics should show kubernetes.pod.cpu.usage.limit.pct. I am using the github reference for setting up metricbeat, but cant see any pod percentages. Only thing showing up for…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=353)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=355)
