# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=355

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 356

---

## [Network Traffic Per Interface - Metricbeat & Kibana](https://discuss.elastic.co/t/network-traffic-per-interface-metricbeat-kibana/180612)

<div class="topic-metadata">

**Author:** [@Todd\_Sayers](https://discuss.elastic.co/u/Todd_Sayers)\
**Replies:** 1\
**Last updated:** [May 16, 2019, 1:45pm UTC](https://discuss.elastic.co/t/network-traffic-per-interface-metricbeat-kibana/180612 "2019-05-16T13:45:28Z")

</div>

We'd like to see per-interface graphs \[in Kibana\] of the network stats sent by Metricbeat. The response to a previous/similar query was not especially helpful: Network Traffic per interface I'm struggling to see \[in th…

---

## [After upgrade to 7.0.1 filebeat is complaining about a license](https://discuss.elastic.co/t/after-upgrade-to-7-0-1-filebeat-is-complaining-about-a-license/181233)

<div class="topic-metadata">

**Author:** [@werowe](https://discuss.elastic.co/u/werowe)\
**Replies:** 2\
**Last updated:** [May 16, 2019, 1:43pm UTC](https://discuss.elastic.co/t/after-upgrade-to-7-0-1-filebeat-is-complaining-about-a-license/181233 "2019-05-16T13:43:32Z")

</div>

After apt-get remove elasticsearch to remove version 6.x and then downloading version 7.0.1 ES and installing it with dpkg ES starts fine. In other words I kept my cluster config files the same. But filebeat is complai…

---

## [Filebeat registry](https://discuss.elastic.co/t/filebeat-registry/181141)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 1\
**Last updated:** [May 15, 2019, 11:32pm UTC](https://discuss.elastic.co/t/filebeat-registry/181141 "2019-05-15T23:32:11Z")

</div>

Dear All, we processed some files with 7d old timestamp.Parsing not done properly in logstash and corrected now. How do i reprocess the same files?

---

## [Filebeat export template doesnt have custom module fields on the generated file](https://discuss.elastic.co/t/filebeat-export-template-doesnt-have-custom-module-fields-on-the-generated-file/181246)

<div class="topic-metadata">

**Author:** [@Daniel\_Diogo](https://discuss.elastic.co/u/Daniel_Diogo)\
**Replies:** 1\
**Last updated:** [May 15, 2019, 6:07pm UTC](https://discuss.elastic.co/t/filebeat-export-template-doesnt-have-custom-module-fields-on-the-generated-file/181246 "2019-05-15T18:07:48Z")

</div>

Hey, I developed a custom filebeat module to deal with my logs, that is working correctly, the data are being sent to elastic well splitted. On the fields.yml file I added the custom fields for the module and when gene…

---

## [AutoDiscovery & Kubernetes & Promteheus within single namespace](https://discuss.elastic.co/t/autodiscovery-kubernetes-promteheus-within-single-namespace/181237)

<div class="topic-metadata">

**Author:** [@remmeier](https://discuss.elastic.co/u/remmeier)\
**Replies:** 0\
**Last updated:** [May 15, 2019, 4:02pm UTC](https://discuss.elastic.co/t/autodiscovery-kubernetes-promteheus-within-single-namespace/181237 "2019-05-15T16:02:27Z")

</div>

Hi I'm trying to setup autodiscovery within Kubernetes to collect metrics from Prometheus endpoints. My configuration looks like: metricbeat.config: modules: path: ${path.config}/modules.d/\*.yml reload.enable…

---

## [Certificate signed by unknown authority filebeat](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority-filebeat/181219)

<div class="topic-metadata">

**Author:** [@rnkhouse](https://discuss.elastic.co/u/rnkhouse)\
**Replies:** 0\
**Last updated:** [May 15, 2019, 2:33pm UTC](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority-filebeat/181219 "2019-05-15T14:33:10Z")

</div>

I am getting this error from filebeat: Failed to connect to backoff(elasticsearch(https://elk.example.com:9200)): Get https://elk.example.com:9200: x509: certificate signed by unknown authority INFO pipeline/output…

---

## [URL monitoring in Kibana](https://discuss.elastic.co/t/url-monitoring-in-kibana/179314)

<div class="topic-metadata">

**Author:** [@ksunil](https://discuss.elastic.co/u/ksunil)\
**Replies:** 2\
**Last updated:** [May 15, 2019, 3:34pm UTC](https://discuss.elastic.co/t/url-monitoring-in-kibana/179314 "2019-05-15T15:34:05Z")

</div>

Hi, I got a requirement to monitor URL for example http://testabc.com:8080/dcf . In general the url requires username and password to go through. But is there any way to get status code=200 without passing username an…

---

## [Boolean Env vars](https://discuss.elastic.co/t/boolean-env-vars/180995)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 4\
**Last updated:** [May 15, 2019, 1:13pm UTC](https://discuss.elastic.co/t/boolean-env-vars/180995 "2019-05-15T13:13:10Z")

</div>

Dear Elastic Team, Would like the know if it's possible to put a env variable as shown below: - module: mysql enabled: ${MYSQL\_ENABLE} metricsets: https://www.elastic.co/guide/en/beats/heartbeat/current/using-enviro…

---

## [Message.keyword does not exists](https://discuss.elastic.co/t/message-keyword-does-not-exists/181028)

<div class="topic-metadata">

**Author:** [@qsadmin](https://discuss.elastic.co/u/qsadmin)\
**Replies:** 4\
**Last updated:** [May 15, 2019, 1:01pm UTC](https://discuss.elastic.co/t/message-keyword-does-not-exists/181028 "2019-05-15T13:01:24Z")

</div>

Hi, i have the same problem as in this thread: .keyword doesn't exist Background: I have updated the elk-stack from version 6.7 to 7. After the update i can not see message.keyword in my index "filebeat-". But at my in…

---

## [Need help - Windows Filebeat x509: certificate](https://discuss.elastic.co/t/need-help-windows-filebeat-x509-certificate/181144)

<div class="topic-metadata">

**Author:** [@retroisbest](https://discuss.elastic.co/u/retroisbest)\
**Replies:** 2\
**Last updated:** [May 15, 2019, 11:52am UTC](https://discuss.elastic.co/t/need-help-windows-filebeat-x509-certificate/181144 "2019-05-15T11:52:26Z")

</div>

Hi there, I currently have winlogbeat logstash and elasticsearch (with kibana, all on version 7.01) working correctly, I have now installed filebeat (64bit windows client to try and parse some DHCP log files) and really…

---

## [\[Filebeat\] Newly added lines don't send to a server](https://discuss.elastic.co/t/filebeat-newly-added-lines-dont-send-to-a-server/180716)

<div class="topic-metadata">

**Author:** [@0x00dec0de](https://discuss.elastic.co/u/0x00dec0de)\
**Replies:** 2\
**Last updated:** [May 15, 2019, 7:53am UTC](https://discuss.elastic.co/t/filebeat-newly-added-lines-dont-send-to-a-server/180716 "2019-05-15T07:53:02Z")

</div>

Hi there, newly added lines to a log don't send to a server. If I add a new log file to the Filebeat config and restart then. A Filebeat sends to a server all content of log file, but if then a new line added to this …

---

## [Filebeat on AIX7.1](https://discuss.elastic.co/t/filebeat-on-aix7-1/179656)

<div class="topic-metadata">

**Author:** [@Faysal](https://discuss.elastic.co/u/Faysal)\
**Replies:** 4\
**Last updated:** [May 15, 2019, 6:07am UTC](https://discuss.elastic.co/t/filebeat-on-aix7-1/179656 "2019-05-15T06:07:04Z")

</div>

Hi, I am not able to find a compatible version of filebeat for AIX7.1. I have multiple AIX servers and needs to ship logs into elasticsearch. your help will be highly appreciated. thanks, Faysal

---

## [Filebeat multiline enquiry](https://discuss.elastic.co/t/filebeat-multiline-enquiry/181089)

<div class="topic-metadata">

**Author:** [@peterch](https://discuss.elastic.co/u/peterch)\
**Replies:** 0\
**Last updated:** [May 15, 2019, 2:57am UTC](https://discuss.elastic.co/t/filebeat-multiline-enquiry/181089 "2019-05-15T02:57:39Z")

</div>

Dear all, I tried Combining both lines but fail. May I know anything wrong? Thanks Log 09:07:25,589 ERROR \[RepositoryImpl\] (default task-27) ex\[Ljava.lang.StackTraceElement;@56e05a91: HttpClientErrorException: 404 Not…

---

## [Enable mssql module](https://discuss.elastic.co/t/enable-mssql-module/180900)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 7\
**Last updated:** [May 14, 2019, 9:13pm UTC](https://discuss.elastic.co/t/enable-mssql-module/180900 "2019-05-14T21:13:20Z")

</div>

Using metricbeat 7.0.1 Why is mssql module not part of this list? metricbeat modules list Enabled: system Disabled: aerospike apache ceph couchbase couchdb docker dropwizard elasticsearch envoyproxy etcd golang graphi…

---

## [Kubernetes metrics: CronJobs](https://discuss.elastic.co/t/kubernetes-metrics-cronjobs/180377)

<div class="topic-metadata">

**Author:** [@mdibaiee](https://discuss.elastic.co/u/mdibaiee)\
**Replies:** 3\
**Last updated:** [May 14, 2019, 8:59pm UTC](https://discuss.elastic.co/t/kubernetes-metrics-cronjobs/180377 "2019-05-14T20:59:39Z")

</div>

Hi, We are using Metricbeat in our Kubernetes cluster, but it seems Metricbeat doesn't collect any metrics for our CronJob pods when they run. I tried searching for any data in the Discover tab, but no results. Can any…

---

## [Filebeat config error (YAML error)](https://discuss.elastic.co/t/filebeat-config-error-yaml-error/179580)

<div class="topic-metadata">

**Author:** [@basitmohammad](https://discuss.elastic.co/u/basitmohammad)\
**Replies:** 6\
**Last updated:** [May 14, 2019, 8:37pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-error/179580 "2019-05-14T20:37:33Z")

</div>

I keep on getting this error when I try to configure Filebeat and/or Metricbeat. ERROR instance/beat.go:802 Exiting: 1 error: error loading config file: invalid config: yaml: line 9: could not find expected ':' E…

---

## [Can't start filebeat](https://discuss.elastic.co/t/cant-start-filebeat/181050)

<div class="topic-metadata">

**Author:** [@hHelen](https://discuss.elastic.co/u/hHelen)\
**Replies:** 9\
**Last updated:** [May 14, 2019, 7:56pm UTC](https://discuss.elastic.co/t/cant-start-filebeat/181050 "2019-05-14T19:56:57Z")

</div>

Could someone please help me, I have just configured filebeat and tried starting the service, but got the following error. Here is the log file: Is there something I'm doing wrong?

---

## [Two different drop\_events not dropping events](https://discuss.elastic.co/t/two-different-drop-events-not-dropping-events/181057)

<div class="topic-metadata">

**Author:** [@Manish\_Pandey](https://discuss.elastic.co/u/Manish_Pandey)\
**Replies:** 0\
**Last updated:** [May 14, 2019, 6:54pm UTC](https://discuss.elastic.co/t/two-different-drop-events-not-dropping-events/181057 "2019-05-14T18:54:47Z")

</div>

I have more than 22 event IDs in 'Application' and 'Antivirus Security'. 28 in Application and more than 100 in Antivirus Security. below is the winlogbeat.yml configuration winlogbeat.event\_logs: name: Security ig…

---

## [Custom Beat - spool disk queue](https://discuss.elastic.co/t/custom-beat-spool-disk-queue/180622)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 2\
**Last updated:** [May 14, 2019, 5:46pm UTC](https://discuss.elastic.co/t/custom-beat-spool-disk-queue/180622 "2019-05-14T17:46:07Z")

</div>

I have a simple community beat that sends messages received on a udp channel to elasticsearch. bt.client, err = b.Publisher.ConnectWith(beat.ClientConfig{ PublishMode: beat.GuaranteedSend, WaitClose: 10 \* time.Se…

---

## [Beats RPMS for Manual Download & Installation](https://discuss.elastic.co/t/beats-rpms-for-manual-download-installation/181032)

<div class="topic-metadata">

**Author:** [@PravinDwiwedi](https://discuss.elastic.co/u/PravinDwiwedi)\
**Replies:** 1\
**Last updated:** [May 14, 2019, 4:54pm UTC](https://discuss.elastic.co/t/beats-rpms-for-manual-download-installation/181032 "2019-05-14T16:54:04Z")

</div>

Hi, I want to create our own yum repository to install latest Beats(filebeat/metricbeat) on offline prod servers. Could some please guide me where can I find the RPMS file to download manually for my Yum Repo? I can s…

---

## [Controls widget for metricbeat use](https://discuss.elastic.co/t/controls-widget-for-metricbeat-use/180987)

<div class="topic-metadata">

**Author:** [@1862347ba9566e72a47d](https://discuss.elastic.co/u/1862347ba9566e72a47d)\
**Replies:** 0\
**Last updated:** [May 14, 2019, 11:11am UTC](https://discuss.elastic.co/t/controls-widget-for-metricbeat-use/180987 "2019-05-14T11:11:32Z")

</div>

Hello! I use metrics to monitor servers. Installed the latest version. Indexes are stored weekly. When I install the metricbit on a new server, data begins to be collected. But there is a problem with the widget Control…

---

## [Filter the Error content from Server Log (WildFly Application server log)](https://discuss.elastic.co/t/filter-the-error-content-from-server-log-wildfly-application-server-log/180486)

<div class="topic-metadata">

**Author:** [@Madhan\_Kumar1](https://discuss.elastic.co/u/Madhan_Kumar1)\
**Replies:** 2\
**Last updated:** [May 14, 2019, 2:05pm UTC](https://discuss.elastic.co/t/filter-the-error-content-from-server-log-wildfly-application-server-log/180486 "2019-05-14T14:05:01Z")

</div>

Hi Team, I've installed File Beat/Elasticsearch/Kibana to get server log from WildFly server and below is my configuration on File Beat We are using processor to filter the log content in File Beat ###################…

---

## [Packetbeat missing some data](https://discuss.elastic.co/t/packetbeat-missing-some-data/180090)

<div class="topic-metadata">

**Author:** [@shantanuo](https://discuss.elastic.co/u/shantanuo)\
**Replies:** 1\
**Last updated:** [May 14, 2019, 2:04pm UTC](https://discuss.elastic.co/t/packetbeat-missing-some-data/180090 "2019-05-14T14:04:21Z")

</div>

Is there a limit of 10 seconds for logging queries using packetbeat? For e.g. The first query in the following example got logged correctly as expected. But the second query does not show up in elastic. MySQL \[test\]\> se…

---

## [Error connection between filebeat and logstash](https://discuss.elastic.co/t/error-connection-between-filebeat-and-logstash/180782)

<div class="topic-metadata">

**Author:** [@Gionata\_Donati](https://discuss.elastic.co/u/Gionata_Donati)\
**Replies:** 2\
**Last updated:** [May 14, 2019, 1:57pm UTC](https://discuss.elastic.co/t/error-connection-between-filebeat-and-logstash/180782 "2019-05-14T13:57:06Z")

</div>

Hello, everyone, I have a problem with the communication of filebeat and elasticsearch. I have recently configured SSL for communication between filebeat and logstash. As from the site the certificates have been set c…

---

## [Unable to push the logs from the local machine using Filebeat to local elastic search instance](https://discuss.elastic.co/t/unable-to-push-the-logs-from-the-local-machine-using-filebeat-to-local-elastic-search-instance/180806)

<div class="topic-metadata">

**Author:** [@krishnagurramvenkata](https://discuss.elastic.co/u/krishnagurramvenkata)\
**Replies:** 2\
**Last updated:** [May 14, 2019, 1:52pm UTC](https://discuss.elastic.co/t/unable-to-push-the-logs-from-the-local-machine-using-filebeat-to-local-elastic-search-instance/180806 "2019-05-14T13:52:42Z")

</div>

Hi, I have installed filebeat and elastic search successfully. I configured the local log file path in the filebeats.yml and output to elastic search. I am not seeing any error in filebeat log but the logs are not pushe…

---

## [Send logs and events from container logs to logstash](https://discuss.elastic.co/t/send-logs-and-events-from-container-logs-to-logstash/180750)

<div class="topic-metadata">

**Author:** [@bopedibop](https://discuss.elastic.co/u/bopedibop)\
**Replies:** 1\
**Last updated:** [May 14, 2019, 1:51pm UTC](https://discuss.elastic.co/t/send-logs-and-events-from-container-logs-to-logstash/180750 "2019-05-14T13:51:03Z")

</div>

Hi, I dont understand why Iam not getting the hole log into logstash. {this is not sent to logstash} But this is sent. What´s the thing with the curly brackets? I am missing a filter? {"log":"1:M 10 May 2019 14:58:50…

---

## [Symlinks with Filebeat](https://discuss.elastic.co/t/symlinks-with-filebeat/180679)

<div class="topic-metadata">

**Author:** [@Exocomp](https://discuss.elastic.co/u/Exocomp)\
**Replies:** 1\
**Last updated:** [May 14, 2019, 1:49pm UTC](https://discuss.elastic.co/t/symlinks-with-filebeat/180679 "2019-05-14T13:49:26Z")

</div>

How does filebeat handle the case where the underlying file changes when using Symlinks. I understand that you have to enable "symlinks: true" for it to process symlinks where it reads the actual file. But when the und…

---

## [Filebeat: Error while retrieving FD information: error getting number of open FD: key not found](https://discuss.elastic.co/t/filebeat-error-while-retrieving-fd-information-error-getting-number-of-open-fd-key-not-found/178378)

<div class="topic-metadata">

**Author:** [@kutomi](https://discuss.elastic.co/u/kutomi)\
**Replies:** 7\
**Last updated:** [May 14, 2019, 12:42pm UTC](https://discuss.elastic.co/t/filebeat-error-while-retrieving-fd-information-error-getting-number-of-open-fd-key-not-found/178378 "2019-05-14T12:42:23Z")

</div>

I also got the same error as this post. ERROR instance/metrics\_file\_descriptors.go:39 Error while retrieving FD information: error getting number of open FD: key not found I wonder what is the cause of this error? …

---

## [Journalbeat didn't see messages](https://discuss.elastic.co/t/journalbeat-didnt-see-messages/180824)

<div class="topic-metadata">

**Author:** [@John\_Lemsky](https://discuss.elastic.co/u/John_Lemsky)\
**Replies:** 1\
**Last updated:** [May 14, 2019, 11:41am UTC](https://discuss.elastic.co/t/journalbeat-didnt-see-messages/180824 "2019-05-14T11:41:11Z")

</div>

Journalbeat doesn't send messages from journald into Logstash. In debug logs, only error I see: Error while reading event: failed to get realtime timestamp: 99 According to https://github.com/elastic/beats/issues/11933,…

---

## [Nginx errors logs prase doesnt complete](https://discuss.elastic.co/t/nginx-errors-logs-prase-doesnt-complete/180975)

<div class="topic-metadata">

**Author:** [@Vlad\_Bubnov](https://discuss.elastic.co/u/Vlad_Bubnov)\
**Replies:** 0\
**Last updated:** [May 14, 2019, 10:12am UTC](https://discuss.elastic.co/t/nginx-errors-logs-prase-doesnt-complete/180975 "2019-05-14T10:12:09Z")

</div>

Hi there. I had a toruble. When i receve error.log from Filebeat, it is doesnt parse "message" field. Here is example: { "\_index": "filebeat-7.0.0-2019.05.08-000001", "\_type": "\_doc", "\_id": "JoZKtWoBYMWq00tgC4a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=354)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=356)
