# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=357

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 358

---

## [Filebeats Getting Logs from Container in K8s](https://discuss.elastic.co/t/filebeats-getting-logs-from-container-in-k8s/180255)

<div class="topic-metadata">

**Author:** [@NFhbar](https://discuss.elastic.co/u/NFhbar)\
**Replies:** 2\
**Last updated:** [May 9, 2019, 3:09pm UTC](https://discuss.elastic.co/t/filebeats-getting-logs-from-container-in-k8s/180255 "2019-05-09T15:09:08Z")

</div>

I have an express server running in k8s which writes its logs to a file: '/var/lib/docker/containers/analytics-error.log' I cannot get Filebeat to pick up this file, here is my conf --- apiVersion: v1 kind: ConfigMap …

---

## [Ssl.verification\_mode is broken in 6.7.2](https://discuss.elastic.co/t/ssl-verification-mode-is-broken-in-6-7-2/180385)

<div class="topic-metadata">

**Author:** [@jwlogemann](https://discuss.elastic.co/u/jwlogemann)\
**Replies:** 0\
**Last updated:** [May 9, 2019, 2:26pm UTC](https://discuss.elastic.co/t/ssl-verification-mode-is-broken-in-6-7-2/180385 "2019-05-09T14:26:32Z")

</div>

Hi, I'm trying to connect Filebeat 6.7.2 on Windows server 2019 to ES 6.6 which has a company issued certificate. I've set verification\_mode to none in the yml, but I get the following error when I try to start the ser…

---

## [Need advice for ELK](https://discuss.elastic.co/t/need-advice-for-elk/179846)

<div class="topic-metadata">

**Author:** [@zenimagine](https://discuss.elastic.co/u/zenimagine)\
**Replies:** 2\
**Last updated:** [May 9, 2019, 12:38pm UTC](https://discuss.elastic.co/t/need-advice-for-elk/179846 "2019-05-09T12:38:50Z")

</div>

Hello, I just installed ELK on my server by following the tutorial https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-18-04 and I have some questions…

---

## [Winlogbeat can't ingest archived .evtx files](https://discuss.elastic.co/t/winlogbeat-cant-ingest-archived-evtx-files/179851)

<div class="topic-metadata">

**Author:** [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Replies:** 8\
**Last updated:** [May 9, 2019, 11:08am UTC](https://discuss.elastic.co/t/winlogbeat-cant-ingest-archived-evtx-files/179851 "2019-05-09T11:08:18Z")

</div>

Hi I tried to ingest an archived evtx files. I set my configuration file like this guide https://www.elastic.co/guide/en/beats/winlogbeat/master/faq.html#reading-from-evtx I create the file winlogbeat-evtx.yml like t…

---

## [Cannot retrieve the elasticsearch cloud license, expiry time out of range](https://discuss.elastic.co/t/cannot-retrieve-the-elasticsearch-cloud-license-expiry-time-out-of-range/174361)

<div class="topic-metadata">

**Author:** [@Ben\_Touss](https://discuss.elastic.co/u/Ben_Touss)\
**Replies:** 17\
**Last updated:** [May 9, 2019, 9:49am UTC](https://discuss.elastic.co/t/cannot-retrieve-the-elasticsearch-cloud-license-expiry-time-out-of-range/174361 "2019-05-09T09:49:20Z")

</div>

Hello there, I'm discovering Elastic and I'm trying to setup a filebeat client to read log files and push these log to an Elastic instance. I'm guided by the tutorial from kibana to add a filebeat data source. As expl…

---

## [How to configure Filebeat.yml to listen logs via TCP](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475)

<div class="topic-metadata">

**Author:** [@maran2karan](https://discuss.elastic.co/u/maran2karan)\
**Replies:** 17\
**Last updated:** [May 9, 2019, 6:46am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-yml-to-listen-logs-via-tcp/179475 "2019-05-09T06:46:22Z")

</div>

Hello, I have configured the Logstash to listen logs from application via TCP using logback. the Same i have to do for filebeat where filebeat should listen the logs via TCP and send to logstash. Could anyone help on…

---

## [Kubernetes watch connection never close when inputreload create runner failed](https://discuss.elastic.co/t/kubernetes-watch-connection-never-close-when-inputreload-create-runner-failed/180112)

<div class="topic-metadata">

**Author:** [@danielQ](https://discuss.elastic.co/u/danielQ)\
**Replies:** 2\
**Last updated:** [May 9, 2019, 1:44am UTC](https://discuss.elastic.co/t/kubernetes-watch-connection-never-close-when-inputreload-create-runner-failed/180112 "2019-05-09T01:44:49Z")

</div>

Hi, guys: filebeat run as daemonset in kubernetes cluster and set reload true, when config has changed and if reload create runner failed, it won't close kubernetes watch connection with kube-apiserver, and it will…

---

## [Multiple events from system module login dataset](https://discuss.elastic.co/t/multiple-events-from-system-module-login-dataset/180242)

<div class="topic-metadata">

**Author:** [@olatunde.tokun](https://discuss.elastic.co/u/olatunde.tokun)\
**Replies:** 1\
**Last updated:** [May 8, 2019, 11:23pm UTC](https://discuss.elastic.co/t/multiple-events-from-system-module-login-dataset/180242 "2019-05-08T23:23:52Z")

</div>

Been running auditbeat in my test environment for a while. I notice that auditbeat indexes the same login event more than once (between 5 to 10times) for every logon or logout. Auditbeat Version: auditbeat version 6.7…

---

## [Uptime dashboard is not showing any data after upgrade to 7](https://discuss.elastic.co/t/uptime-dashboard-is-not-showing-any-data-after-upgrade-to-7/176798)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 3\
**Last updated:** [May 8, 2019, 6:26pm UTC](https://discuss.elastic.co/t/uptime-dashboard-is-not-showing-any-data-after-upgrade-to-7/176798 "2019-05-08T18:26:37Z")

</div>

Uptime is not showing any data after upgrade. I am able to see logs in discover from heartbeat.

---

## [The best way to collect custom data?](https://discuss.elastic.co/t/the-best-way-to-collect-custom-data/180230)

<div class="topic-metadata">

**Author:** [@Todd\_Sayers](https://discuss.elastic.co/u/Todd_Sayers)\
**Replies:** 0\
**Last updated:** [May 8, 2019, 6:14pm UTC](https://discuss.elastic.co/t/the-best-way-to-collect-custom-data/180230 "2019-05-08T18:14:15Z")

</div>

I'd like to know the "correct" or "best" way to get custom metrics (e.g., Lustre performance, OPA topology, etc) into ES using the Beats "system." My first thought was to create a Metricbeat module. I've also seen Execb…

---

## [Beats not rolling in 7.0.0](https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207)

<div class="topic-metadata">

**Author:** [@saif3r](https://discuss.elastic.co/u/saif3r)\
**Replies:** 3\
**Last updated:** [May 8, 2019, 5:05pm UTC](https://discuss.elastic.co/t/beats-not-rolling-in-7-0-0/180207 "2019-05-08T17:05:05Z")

</div>

Hi Guys, I recently launched server monitoring using Winlogbeat, Packetbeat and Metricbeat. All three agents are running with default settings (except for Elasticsearch/Kibana hosts and winlog narrowed to security). Tem…

---

## [Is it possible to send Windows Registry Keys/Subkeys and file catalog structure along with accesses?](https://discuss.elastic.co/t/is-it-possible-to-send-windows-registry-keys-subkeys-and-file-catalog-structure-along-with-accesses/179837)

<div class="topic-metadata">

**Author:** [@saif3r](https://discuss.elastic.co/u/saif3r)\
**Replies:** 1\
**Last updated:** [May 8, 2019, 3:08pm UTC](https://discuss.elastic.co/t/is-it-possible-to-send-windows-registry-keys-subkeys-and-file-catalog-structure-along-with-accesses/179837 "2019-05-08T15:08:36Z")

</div>

Hi Guys, I'm looking into some use cases for which i might use Beats for in our company. Two that has been identified so far are: Ability to send Windows Registry Keys and Subkeys to Elasticsearch to review each user'…

---

## [Filebeat find error Dropping event: no topic could be selected](https://discuss.elastic.co/t/filebeat-find-error-dropping-event-no-topic-could-be-selected/179876)

<div class="topic-metadata">

**Author:** [@icoolchn](https://discuss.elastic.co/u/icoolchn)\
**Replies:** 2\
**Last updated:** [May 8, 2019, 10:57am UTC](https://discuss.elastic.co/t/filebeat-find-error-dropping-event-no-topic-could-be-selected/179876 "2019-05-08T10:57:05Z")

</div>

filebeat Helm chart deploy ，autodiscover kubernetes log . find ERROR: kafka/client.go:131 Dropping event: no topic could be selected. cause CPU 300% /var/lib/docker/containers/ dir path of filebeat docker log Disk …

---

## [\[filebeat-7.0.x\] Group multiple when/regexp condition for renaming](https://discuss.elastic.co/t/filebeat-7-0-x-group-multiple-when-regexp-condition-for-renaming/180153)

<div class="topic-metadata">

**Author:** [@jesusgn90](https://discuss.elastic.co/u/jesusgn90)\
**Replies:** 0\
**Last updated:** [May 8, 2019, 10:36am UTC](https://discuss.elastic.co/t/filebeat-7-0-x-group-multiple-when-regexp-condition-for-renaming/180153 "2019-05-08T10:36:45Z")

</div>

Hi guys :slight\_smile: Given the next rename blocks for Filebeat: - rename: fields: - from: "data.aws.sourceIPAddress" to: "@src\_ip" ignore\_missing: true fail\_on\_error: false …

---

## [Regarding Deduplication](https://discuss.elastic.co/t/regarding-deduplication/180121)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 2\
**Last updated:** [May 8, 2019, 9:22am UTC](https://discuss.elastic.co/t/regarding-deduplication/180121 "2019-05-08T09:22:38Z")

</div>

Hi, I'm looking at avoiding duplicated entries when indexing logs indexed to elasticsearch from filebeat via logstash. To do that I'll be using the logstash fingerprint module... I'd like to use more than the message f…

---

## [License error with Filebeat 6.7.1 Docker image and AWS ElasticSearch](https://discuss.elastic.co/t/license-error-with-filebeat-6-7-1-docker-image-and-aws-elasticsearch/180003)

<div class="topic-metadata">

**Author:** [@spiffytech](https://discuss.elastic.co/u/spiffytech)\
**Replies:** 1\
**Last updated:** [May 8, 2019, 7:16am UTC](https://discuss.elastic.co/t/license-error-with-filebeat-6-7-1-docker-image-and-aws-elasticsearch/180003 "2019-05-08T07:16:07Z")

</div>

I'm trying to upgrade my Kubernetes cluster to use the 6.7.1 Docker image and I'm getting the following error when the container starts: Failed to connect to backoff(myserver.es.amazonaws.com:443)): Connection marked as…

---

## [How to monitor two servers with Metricbeat?](https://discuss.elastic.co/t/how-to-monitor-two-servers-with-metricbeat/180052)

<div class="topic-metadata">

**Author:** [@zenimagine](https://discuss.elastic.co/u/zenimagine)\
**Replies:** 9\
**Last updated:** [May 8, 2019, 3:52am UTC](https://discuss.elastic.co/t/how-to-monitor-two-servers-with-metricbeat/180052 "2019-05-08T03:52:27Z")

</div>

I have a two servers : SERVER\_1 with ELK (https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-18-04) ELK is accessible from a subdomain and protect…

---

## [Filebeat multiline pattern with negate works for all logs even without pattern](https://discuss.elastic.co/t/filebeat-multiline-pattern-with-negate-works-for-all-logs-even-without-pattern/179942)

<div class="topic-metadata">

**Author:** [@andrvin](https://discuss.elastic.co/u/andrvin)\
**Replies:** 0\
**Last updated:** [May 7, 2019, 11:06am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-with-negate-works-for-all-logs-even-without-pattern/179942 "2019-05-07T11:06:23Z")

</div>

Hi! I want to use multiline for Java stacktraces. I use following configuration: - type: docker multiline: pattern: '^\[0-9\]{4}-\[0-9\]{2}-\[0-9\]{2}' negate: true match: after It works fine for java logs, but…

---

## [How do I separate nginx logs for different sites on the same server with Filebeat 7.0.1](https://discuss.elastic.co/t/how-do-i-separate-nginx-logs-for-different-sites-on-the-same-server-with-filebeat-7-0-1/180078)

<div class="topic-metadata">

**Author:** [@ald](https://discuss.elastic.co/u/ald)\
**Replies:** 0\
**Last updated:** [May 7, 2019, 9:57pm UTC](https://discuss.elastic.co/t/how-do-i-separate-nginx-logs-for-different-sites-on-the-same-server-with-filebeat-7-0-1/180078 "2019-05-07T21:57:42Z")

</div>

Sorry in advance if this is covered already elsewhere. I have a nginx server that hosts multiple sites and want to set a custom field/unique identifier for the access/error logs from each site that go to separate files.…

---

## [Install metricbeat agent on all ES nodes in my cluster](https://discuss.elastic.co/t/install-metricbeat-agent-on-all-es-nodes-in-my-cluster/180029)

<div class="topic-metadata">

**Author:** [@bkasrai](https://discuss.elastic.co/u/bkasrai)\
**Replies:** 4\
**Last updated:** [May 7, 2019, 4:56pm UTC](https://discuss.elastic.co/t/install-metricbeat-agent-on-all-es-nodes-in-my-cluster/180029 "2019-05-07T16:56:02Z")

</div>

Good afternoon, I have installed Metricbeat on an individual node within my ES cluster and was able to get the ES module enabled along with the metrics\\dashboards sent to Kibana. I am looking to expand this into the clu…

---

## [Beats' output, logstash or elasticsearh](https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894)

<div class="topic-metadata">

**Author:** [@gray380](https://discuss.elastic.co/u/gray380)\
**Replies:** 3\
**Last updated:** [May 7, 2019, 1:38pm UTC](https://discuss.elastic.co/t/beats-output-logstash-or-elasticsearh/179894 "2019-05-07T13:38:55Z")

</div>

Hi there, What is the best or recommended way to collect "auth" data within Beats, directly send it to elasticsearch or via logstash? For now beats are configured to use "output.logstash" and module "system" is enabled…

---

## [How do I send logs from glassfish 4.1 to logstash to analyze them with kibana? Any example that works?](https://discuss.elastic.co/t/how-do-i-send-logs-from-glassfish-4-1-to-logstash-to-analyze-them-with-kibana-any-example-that-works/179946)

<div class="topic-metadata">

**Author:** [@Martin\_Murciego](https://discuss.elastic.co/u/Martin_Murciego)\
**Replies:** 0\
**Last updated:** [May 7, 2019, 11:17am UTC](https://discuss.elastic.co/t/how-do-i-send-logs-from-glassfish-4-1-to-logstash-to-analyze-them-with-kibana-any-example-that-works/179946 "2019-05-07T11:17:24Z")

</div>

I have installed ELK Stack but I can not find examples of capturing glassfish logs and less version 4.1. Could you explain me in detail? I have installed ELK, configured the three tools and from a VPS. Then install file…

---

## [OS Support Matrix](https://discuss.elastic.co/t/os-support-matrix/179701)

<div class="topic-metadata">

**Author:** [@hanso](https://discuss.elastic.co/u/hanso)\
**Replies:** 4\
**Last updated:** [May 7, 2019, 10:19am UTC](https://discuss.elastic.co/t/os-support-matrix/179701 "2019-05-07T10:19:52Z")

</div>

Hi there. Could someone point me to a OS support matrix? I cannot find it anywhere. I have looked at elastic.co, the forums as well as the GitHub site. I am looking for confirmation that there is a version of Winlogbea…

---

## [Filebeat on Windows Server R2 2008 Issue](https://discuss.elastic.co/t/filebeat-on-windows-server-r2-2008-issue/179821)

<div class="topic-metadata">

**Author:** [@Ganesh999](https://discuss.elastic.co/u/Ganesh999)\
**Replies:** 2\
**Last updated:** [May 7, 2019, 9:19am UTC](https://discuss.elastic.co/t/filebeat-on-windows-server-r2-2008-issue/179821 "2019-05-07T09:19:50Z")

</div>

Hi All, Have been setting filebeat on Windows Server 2008 . The filebeat is installed as service but the problem here is using the multiline . While parsing the same file through logstash it is parsing properly with th…

---

## [\[HTTP-Module\] json: cannot unmarshal object into Go value of type \[\]common.MapStr](https://discuss.elastic.co/t/http-module-json-cannot-unmarshal-object-into-go-value-of-type-common-mapstr/179757)

<div class="topic-metadata">

**Author:** [@PeterPain](https://discuss.elastic.co/u/PeterPain)\
**Replies:** 3\
**Last updated:** [May 7, 2019, 8:43am UTC](https://discuss.elastic.co/t/http-module-json-cannot-unmarshal-object-into-go-value-of-type-common-mapstr/179757 "2019-05-07T08:43:07Z")

</div>

Hey there. Trying to pull data from a device which supports http protocol and has the option to query for different parameters in JSON-Format. Because the device puts the data in an array i have json.is\_array enabled. …

---

## [Filebeat log sending failed](https://discuss.elastic.co/t/filebeat-log-sending-failed/179041)

<div class="topic-metadata">

**Author:** [@brunoju](https://discuss.elastic.co/u/brunoju)\
**Replies:** 2\
**Last updated:** [May 7, 2019, 1:12am UTC](https://discuss.elastic.co/t/filebeat-log-sending-failed/179041 "2019-05-07T01:12:06Z")

</div>

EK + Filebeat But filebeat log sending to Kibana failed with unknown reason Here is the conf ================================== filebeat.inputs: - type: log enabled: true paths: - /var/log/\*.log filebeat.con…

---

## [Auditbeat compression on output data](https://discuss.elastic.co/t/auditbeat-compression-on-output-data/179845)

<div class="topic-metadata">

**Author:** [@kanapuliAthavan](https://discuss.elastic.co/u/kanapuliAthavan)\
**Replies:** 1\
**Last updated:** [May 6, 2019, 9:53pm UTC](https://discuss.elastic.co/t/auditbeat-compression-on-output-data/179845 "2019-05-06T21:53:54Z")

</div>

Say, There is a server with high audit events and when auditbeat reads this events and pushes it as output, does it compresses the data to save network? The output data compression is a feature which rsyslog provides wel…

---

## [Affichage des logs windows sur Kibana](https://discuss.elastic.co/t/affichage-des-logs-windows-sur-kibana/179800)

<div class="topic-metadata">

**Author:** [@elkinani](https://discuss.elastic.co/u/elkinani)\
**Replies:** 1\
**Last updated:** [May 6, 2019, 4:05pm UTC](https://discuss.elastic.co/t/affichage-des-logs-windows-sur-kibana/179800 "2019-05-06T16:05:52Z")

</div>

Bonjour, J'ai installée winlogbeat sur une machine windows cliente, j'ai modifiée le fichier winlogbeat.yml pour rédiriger les logs vers Logstash et j'ai crée le fichier de configuration windows.conf pour envoyer les lo…

---

## [Using Winlogbeats for Windows File Auditing](https://discuss.elastic.co/t/using-winlogbeats-for-windows-file-auditing/179808)

<div class="topic-metadata">

**Author:** [@Shauncpt](https://discuss.elastic.co/u/Shauncpt)\
**Replies:** 0\
**Last updated:** [May 6, 2019, 3:47pm UTC](https://discuss.elastic.co/t/using-winlogbeats-for-windows-file-auditing/179808 "2019-05-06T15:47:31Z")

</div>

Hi Folks, I'm pretty new to Elasticsearch and was wondering if anyone could assist or point me in the right direction with trying to get Windows File Auditing Logs and then shipping to Kibana. Is this something that is p…

---

## [Filebeat 7.0.0 on docker with Autodiscover and deploy mode: global](https://discuss.elastic.co/t/filebeat-7-0-0-on-docker-with-autodiscover-and-deploy-mode-global/179747)

<div class="topic-metadata">

**Author:** [@DieMal](https://discuss.elastic.co/u/DieMal)\
**Replies:** 0\
**Last updated:** [May 6, 2019, 10:59am UTC](https://discuss.elastic.co/t/filebeat-7-0-0-on-docker-with-autodiscover-and-deploy-mode-global/179747 "2019-05-06T10:59:51Z")

</div>

Hi guys, I'm trying to deploy a stack to a swarm using autodiscover configuration for Filebeat service 7.0.0 (https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html) , this is my filebeat…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=356)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=358)
