# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=356

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 357

---

## [Osquery Module issue](https://discuss.elastic.co/t/osquery-module-issue/180454)

<div class="topic-metadata">

**Author:** [@netpacket](https://discuss.elastic.co/u/netpacket)\
**Replies:** 2\
**Last updated:** [May 13, 2019, 9:46pm UTC](https://discuss.elastic.co/t/osquery-module-issue/180454 "2019-05-13T21:46:48Z")

</div>

I am running filebeat 7.0 using osquery module. I am trying to override the the module's input by filtering for multiline. I am not sure why access command and placing multiline filter into the module is not working. Fi…

---

## [Json logfiles from Elastic Engineer I course not loaded into elasticsearch 7.0](https://discuss.elastic.co/t/json-logfiles-from-elastic-engineer-i-course-not-loaded-into-elasticsearch-7-0/180888)

<div class="topic-metadata">

**Author:** [@Mark\_Busenhart](https://discuss.elastic.co/u/Mark_Busenhart)\
**Replies:** 0\
**Last updated:** [May 13, 2019, 8:57pm UTC](https://discuss.elastic.co/t/json-logfiles-from-elastic-engineer-i-course-not-loaded-into-elasticsearch-7-0/180888 "2019-05-13T20:57:32Z")

</div>

Didn't succeed to migrate my data from the elastic engineer I course to elasticsearch 7.0. Input log: {"geoip":{"city\_name":"Holly Springs","country\_name":"United States","country\_code2":"US","continent\_code":"NA","cou…

---

## [Monitoring the publisher](https://discuss.elastic.co/t/monitoring-the-publisher/180119)

<div class="topic-metadata">

**Author:** [@Sierra4x4](https://discuss.elastic.co/u/Sierra4x4)\
**Replies:** 1\
**Last updated:** [May 13, 2019, 7:06pm UTC](https://discuss.elastic.co/t/monitoring-the-publisher/180119 "2019-05-13T19:06:11Z")

</div>

Good morning all, I am new to all of this and been thrown in the deep end to understanding an existing setup. Currently we have a go script which monitors folders for files and upon identifying the files processes thes…

---

## [Single event for all the metrics](https://discuss.elastic.co/t/single-event-for-all-the-metrics/180406)

<div class="topic-metadata">

**Author:** [@whiletruelearn](https://discuss.elastic.co/u/whiletruelearn)\
**Replies:** 1\
**Last updated:** [May 13, 2019, 4:56pm UTC](https://discuss.elastic.co/t/single-event-for-all-the-metrics/180406 "2019-05-13T16:56:58Z")

</div>

Hi , I could see in this post\[1\] that it will be possible to have multiple events from various metricssets such as cpu, load, memory etc written as a single event. As mentioned in the post Having all the related metr…

---

## [Filebeat Service Timeout on Linux Server](https://discuss.elastic.co/t/filebeat-service-timeout-on-linux-server/180600)

<div class="topic-metadata">

**Author:** [@danielmoon](https://discuss.elastic.co/u/danielmoon)\
**Replies:** 1\
**Last updated:** [May 13, 2019, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-service-timeout-on-linux-server/180600 "2019-05-13T16:15:10Z")

</div>

Hi, I'm running into as issue with starting the filebeat service. Whenever I start the service sudo systemctl start filebeat Filebeat begins working, but the command never finishes executing. After about a 20 minute p…

---

## [Why are multiple events created for \`network \` in system module](https://discuss.elastic.co/t/why-are-multiple-events-created-for-network-in-system-module/180810)

<div class="topic-metadata">

**Author:** [@whiletruelearn](https://discuss.elastic.co/u/whiletruelearn)\
**Replies:** 1\
**Last updated:** [May 13, 2019, 1:45pm UTC](https://discuss.elastic.co/t/why-are-multiple-events-created-for-network-in-system-module/180810 "2019-05-13T13:45:08Z")

</div>

Despite giving period as 1m , i was able to see about 8 events created for the same timestamp for the metricset containing network

---

## [Filebeat : harvester setup failed: unexpected file opening error](https://discuss.elastic.co/t/filebeat-harvester-setup-failed-unexpected-file-opening-error/180783)

<div class="topic-metadata">

**Author:** [@Mayurbiw](https://discuss.elastic.co/u/Mayurbiw)\
**Replies:** 1\
**Last updated:** [May 13, 2019, 10:35am UTC](https://discuss.elastic.co/t/filebeat-harvester-setup-failed-unexpected-file-opening-error/180783 "2019-05-13T10:35:50Z")

</div>

I am sending a data from file beat to Logstash. File beat is throwing an error - harvester setup failed: unexcepted file opening error? I am reading files from a directory like this example - filebeat.inputs: type: l…

---

## [Filebeat Apache Module Change Index Name](https://discuss.elastic.co/t/filebeat-apache-module-change-index-name/176955)

<div class="topic-metadata">

**Author:** [@Ryne\_Keel](https://discuss.elastic.co/u/Ryne_Keel)\
**Replies:** 5\
**Last updated:** [May 13, 2019, 9:05am UTC](https://discuss.elastic.co/t/filebeat-apache-module-change-index-name/176955 "2019-05-13T09:05:21Z")

</div>

Been having trouble getting the index to be created as a different index name than filebeat. #============================= Filebeat modules =============================== filebeat.config.modules: path: ${path.confi…

---

## [Does filebeat support http/https for log shipping?](https://discuss.elastic.co/t/does-filebeat-support-http-https-for-log-shipping/180720)

<div class="topic-metadata">

**Author:** [@Satyakam\_mohapatra](https://discuss.elastic.co/u/Satyakam_mohapatra)\
**Replies:** 1\
**Last updated:** [May 12, 2019, 9:34pm UTC](https://discuss.elastic.co/t/does-filebeat-support-http-https-for-log-shipping/180720 "2019-05-12T21:34:04Z")

</div>

Hi, I need a information regarding filebeats What is the protocol filebeats use to transfer log file to logstash? Is it http! and If it is not then is there anyway we can do it via http ? 2.Currently I have logstash …

---

## [Metricbeat on Kubernetes - issues connecting to port 10255/10250](https://discuss.elastic.co/t/metricbeat-on-kubernetes-issues-connecting-to-port-10255-10250/180660)

<div class="topic-metadata">

**Author:** [@bogd](https://discuss.elastic.co/u/bogd)\
**Replies:** 0\
**Last updated:** [May 11, 2019, 4:03pm UTC](https://discuss.elastic.co/t/metricbeat-on-kubernetes-issues-connecting-to-port-10255-10250/180660 "2019-05-11T16:03:43Z")

</div>

I am trying to deploy Metricbeat on a K8s cluster set up using kubeadm (v1.14), and I have encountered several issues. The documentation lists a manifest file that tries to collect metrics from the kubelet read-only po…

---

## [Read From Top of File](https://discuss.elastic.co/t/read-from-top-of-file/180407)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 4\
**Last updated:** [May 10, 2019, 4:09pm UTC](https://discuss.elastic.co/t/read-from-top-of-file/180407 "2019-05-10T16:09:29Z")

</div>

Is there a way to configure FileBeat to read a log file bottom to top? I have a log that is inverted, where the most recent records appear at the top and the oldest records are at the bottom.

---

## [How to send two different log file types from the same source directory to logstash](https://discuss.elastic.co/t/how-to-send-two-different-log-file-types-from-the-same-source-directory-to-logstash/180366)

<div class="topic-metadata">

**Author:** [@mgolubov55](https://discuss.elastic.co/u/mgolubov55)\
**Replies:** 5\
**Last updated:** [May 10, 2019, 2:11pm UTC](https://discuss.elastic.co/t/how-to-send-two-different-log-file-types-from-the-same-source-directory-to-logstash/180366 "2019-05-10T14:11:05Z")

</div>

I have been sending two different log files to logstash from two different source directories. One type is an "Index log" that is always named "IndexService\*.log", for example: IndexService-sv\_Toolkit-GBWLLSLO015-310120…

---

## [Auditbeat randomly shuts down](https://discuss.elastic.co/t/auditbeat-randomly-shuts-down/135335)

<div class="topic-metadata">

**Author:** [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Replies:** 23\
**Last updated:** [May 10, 2019, 1:47pm UTC](https://discuss.elastic.co/t/auditbeat-randomly-shuts-down/135335 "2019-05-10T13:47:38Z")

</div>

Hi All, I have an auditbeat instance running on RHEL 6, just the file integrity module. At certain times, it just stops running with the following error: panic: runtime error: invalid memory address or nil pointer dere…

---

## [Unable to setup HAproxy monitoring using Filebeat module](https://discuss.elastic.co/t/unable-to-setup-haproxy-monitoring-using-filebeat-module/180241)

<div class="topic-metadata">

**Author:** [@ssardana08](https://discuss.elastic.co/u/ssardana08)\
**Replies:** 4\
**Last updated:** [May 10, 2019, 1:23pm UTC](https://discuss.elastic.co/t/unable-to-setup-haproxy-monitoring-using-filebeat-module/180241 "2019-05-10T13:23:07Z")

</div>

Hi all, I'm trying to setup a good alarming and visualization on Kibana for my haproxy setup using ELK and Filebeat. But everytime I use Filebeat in-built module for haproxy and goes to the step of setting up environme…

---

## [Unable to view or read logs in Kibana](https://discuss.elastic.co/t/unable-to-view-or-read-logs-in-kibana/180564)

<div class="topic-metadata">

**Author:** [@krajapraveen](https://discuss.elastic.co/u/krajapraveen)\
**Replies:** 0\
**Last updated:** [May 10, 2019, 1:17pm UTC](https://discuss.elastic.co/t/unable-to-view-or-read-logs-in-kibana/180564 "2019-05-10T13:17:34Z")

</div>

Hi I want to display logs in Kibana on Red Hat Enterprise Linux 7. I have elasticsearch-6.4.0.rpm, kibana-6.4.0-x86\_64.rpm, logstash-6.4.1 and filebeat-5.6.4-x86\_64.rpm installed on Red Hat Enterprise Linux 7. In /usr…

---

## [Parsing Redis log message field using Redis module but shipping to Logstash](https://discuss.elastic.co/t/parsing-redis-log-message-field-using-redis-module-but-shipping-to-logstash/180563)

<div class="topic-metadata">

**Author:** [@A\_B](https://discuss.elastic.co/u/A_B)\
**Replies:** 0\
**Last updated:** [May 10, 2019, 1:10pm UTC](https://discuss.elastic.co/t/parsing-redis-log-message-field-using-redis-module-but-shipping-to-logstash/180563 "2019-05-10T13:10:21Z")

</div>

Hello all, I am testing the Redis module for Filebeat. Filebeat uses Logstash as the output. The log messages are not parsed as I had expected. Based on this from the documentation Uses ingest node to parse and proces…

---

## [Multiple multiline filter in one yml file](https://discuss.elastic.co/t/multiple-multiline-filter-in-one-yml-file/180560)

<div class="topic-metadata">

**Author:** [@sonukumarsah](https://discuss.elastic.co/u/sonukumarsah)\
**Replies:** 0\
**Last updated:** [May 10, 2019, 1:02pm UTC](https://discuss.elastic.co/t/multiple-multiline-filter-in-one-yml-file/180560 "2019-05-10T13:02:20Z")

</div>

i am trying to use multiple date filter format in one yml, but its showing error. filebeat.inputs: type: log enabled: true paths: - /devspace/Sonu/data/input/\*.log multiline.pattern: '^((\\b(Jan?|Feb?|Mar?|Apr?|May…

---

## [Sync data from MongoDB to elasticsearch](https://discuss.elastic.co/t/sync-data-from-mongodb-to-elasticsearch/180501)

<div class="topic-metadata">

**Author:** [@vishal.k](https://discuss.elastic.co/u/vishal.k)\
**Replies:** 0\
**Last updated:** [May 10, 2019, 6:59am UTC](https://discuss.elastic.co/t/sync-data-from-mongodb-to-elasticsearch/180501 "2019-05-10T06:59:59Z")

</div>

Hello, I wanted sync data between MongoDB Atlas and Elasticsearch (cloud) using anything, however I'm not able to find any good way to do so. I tried using mongodb-connector however there are some SSL handshake issues …

---

## [Metricbeat Error : x509 Certificate is valid for x, not Y](https://discuss.elastic.co/t/metricbeat-error-x509-certificate-is-valid-for-x-not-y/180495)

<div class="topic-metadata">

**Author:** [@Min](https://discuss.elastic.co/u/Min)\
**Replies:** 0\
**Last updated:** [May 10, 2019, 6:33am UTC](https://discuss.elastic.co/t/metricbeat-error-x509-certificate-is-valid-for-x-not-y/180495 "2019-05-10T06:33:27Z")

</div>

i have an error when i setup metricbeat Step4 : ./metricbeat setup this is my metricbeat.yml Setup kibana setup.kibana: host: \["http://192.168.137.88:5601"\] OutPut elasticsearch output.elasticsearch: hosts…

---

## [How to change memory usage unit](https://discuss.elastic.co/t/how-to-change-memory-usage-unit/180158)

<div class="topic-metadata">

**Author:** [@Kalyan\_MB](https://discuss.elastic.co/u/Kalyan_MB)\
**Replies:** 5\
**Last updated:** [May 10, 2019, 5:09am UTC](https://discuss.elastic.co/t/how-to-change-memory-usage-unit/180158 "2019-05-10T05:09:08Z")

</div>

Hi, i have installed metric beat in few clients where i am running some load and integrated it to ELK stack, i can see the dashboard in kibana for the same. can any one help with how to change the unit of "Processes B…

---

## [Filebeat publishes events only few hours after log rotator creates a new file](https://discuss.elastic.co/t/filebeat-publishes-events-only-few-hours-after-log-rotator-creates-a-new-file/180466)

<div class="topic-metadata">

**Author:** [@Jaepyoung\_Kim](https://discuss.elastic.co/u/Jaepyoung_Kim)\
**Replies:** 0\
**Last updated:** [May 10, 2019, 1:22am UTC](https://discuss.elastic.co/t/filebeat-publishes-events-only-few-hours-after-log-rotator-creates-a-new-file/180466 "2019-05-10T01:22:33Z")

</div>

I have several Elastic Searches clusters in several Kubernetes Clusters. Several VMs are sending the logs through filebeat to Logstash. Some logs show very wired pattern. The following graph shows that the number of t…

---

## [Filebeat 7.0.1 system module setup (with logstash) no system fields in document](https://discuss.elastic.co/t/filebeat-7-0-1-system-module-setup-with-logstash-no-system-fields-in-document/180465)

<div class="topic-metadata">

**Author:** [@pdizz](https://discuss.elastic.co/u/pdizz)\
**Replies:** 0\
**Last updated:** [May 10, 2019, 1:19am UTC](https://discuss.elastic.co/t/filebeat-7-0-1-system-module-setup-with-logstash-no-system-fields-in-document/180465 "2019-05-10T01:19:27Z")

</div>

I'm trying to set up the filebeat system module on a centos 7 host with elastic, logstash, kibana, and filebeat all on the same host. Using the steps from the module quickstart (https://www.elastic.co/guide/en/beats/file…

---

## [Mix beats and es versions?](https://discuss.elastic.co/t/mix-beats-and-es-versions/180453)

<div class="topic-metadata">

**Author:** [@nt-josh](https://discuss.elastic.co/u/nt-josh)\
**Replies:** 1\
**Last updated:** [May 10, 2019, 12:58am UTC](https://discuss.elastic.co/t/mix-beats-and-es-versions/180453 "2019-05-10T00:58:09Z")

</div>

Can i use a newer beat like auditbeat 7.0.1 on an elastic 6.7.1 cluster?

---

## [How to use dlv to debug beats with version 6.7.0+](https://discuss.elastic.co/t/how-to-use-dlv-to-debug-beats-with-version-6-7-0/180449)

<div class="topic-metadata">

**Author:** [@rugang](https://discuss.elastic.co/u/rugang)\
**Replies:** 0\
**Last updated:** [May 9, 2019, 10:39pm UTC](https://discuss.elastic.co/t/how-to-use-dlv-to-debug-beats-with-version-6-7-0/180449 "2019-05-09T22:39:25Z")

</div>

I'm using beats version 6.7.0, it has 1.10.8 in .go-version, so I use go 1.10.8 to build it. Building is fine and binaries run well. But when I try to use dlv to debug a beat binary (auditbeat), it shows to me: could …

---

## [Service Timing out when starting (RHEL)](https://discuss.elastic.co/t/service-timing-out-when-starting-rhel/180442)

<div class="topic-metadata">

**Author:** [@danielmoon](https://discuss.elastic.co/u/danielmoon)\
**Replies:** 1\
**Last updated:** [May 9, 2019, 9:19pm UTC](https://discuss.elastic.co/t/service-timing-out-when-starting-rhel/180442 "2019-05-09T21:19:50Z")

</div>

I'm going through a heck of a learning process here. I'm trying to setup filebeat on a RHEL server. We've got filebeat installed and I believe we have all the permissions setup correctly but when I try to start the ser…

---

## [Winlogbeat not sending to remote computers elasticsearch](https://discuss.elastic.co/t/winlogbeat-not-sending-to-remote-computers-elasticsearch/180441)

<div class="topic-metadata">

**Author:** [@limeabeen](https://discuss.elastic.co/u/limeabeen)\
**Replies:** 0\
**Last updated:** [May 9, 2019, 9:08pm UTC](https://discuss.elastic.co/t/winlogbeat-not-sending-to-remote-computers-elasticsearch/180441 "2019-05-09T21:08:42Z")

</div>

Hello, I am having trouble sending my logs from one machine (pc A) to another (pc B). As a preface I want to say that I am very new to the ELK stuff, so hopefully I provide all the needed info. PC A has Kibana, Elastic…

---

## [Duplicate audit logs for successful logins in auditbeat](https://discuss.elastic.co/t/duplicate-audit-logs-for-successful-logins-in-auditbeat/178067)

<div class="topic-metadata">

**Author:** [@Ritesh\_Kuchukulla](https://discuss.elastic.co/u/Ritesh_Kuchukulla)\
**Replies:** 6\
**Last updated:** [May 9, 2019, 5:17pm UTC](https://discuss.elastic.co/t/duplicate-audit-logs-for-successful-logins-in-auditbeat/178067 "2019-05-09T17:17:36Z")

</div>

When an auditbeat logs a successful login on ubuntu, it logs a success and a failed event. Example - I tried logging into my ubuntu instance and it was successful, so here I get a success log and a failure log. The fail…

---

## [Filter out Windows proccesses](https://discuss.elastic.co/t/filter-out-windows-proccesses/180392)

<div class="topic-metadata">

**Author:** [@Thomas\_Kucirek](https://discuss.elastic.co/u/Thomas_Kucirek)\
**Replies:** 1\
**Last updated:** [May 9, 2019, 4:24pm UTC](https://discuss.elastic.co/t/filter-out-windows-proccesses/180392 "2019-05-09T16:24:53Z")

</div>

Hi, i want to filter the events collected by the winlogbeat. Because it is a lot of unwanted noise, i want to drop all events that come from the System32 processes like svchost, backGroundTaskhost etc. I've tried using …

---

## [What is the storage layer for the metricsbeat agent?](https://discuss.elastic.co/t/what-is-the-storage-layer-for-the-metricsbeat-agent/175048)

<div class="topic-metadata">

**Author:** [@whiletruelearn](https://discuss.elastic.co/u/whiletruelearn)\
**Replies:** 4\
**Last updated:** [May 9, 2019, 4:18pm UTC](https://discuss.elastic.co/t/what-is-the-storage-layer-for-the-metricsbeat-agent/175048 "2019-05-09T16:18:51Z")

</div>

Hey all, Trying to understand the working of metrics beat for measuring System metrics. I could infer from the code that gopsutil is being used for measuring it, i wanted to know more about the storage layer used for pu…

---

## [Filebeat Windows Service won't start](https://discuss.elastic.co/t/filebeat-windows-service-wont-start/180085)

<div class="topic-metadata">

**Author:** [@Matt\_Richards](https://discuss.elastic.co/u/Matt_Richards)\
**Replies:** 5\
**Last updated:** [May 9, 2019, 3:32pm UTC](https://discuss.elastic.co/t/filebeat-windows-service-wont-start/180085 "2019-05-09T15:32:03Z")

</div>

Hi there, I've recently installed Filebeat 6.7.2 on a new windows server. I'm able to install the service using the included PowerShell scripts but I can't start it. I've tried running it under Local System USer and m…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=355)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=357)
