# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=358

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 359

---

## [Apply Filter Query to Visualization](https://discuss.elastic.co/t/apply-filter-query-to-visualization/178211)

<div class="topic-metadata">

**Author:** [@philipp\_s](https://discuss.elastic.co/u/philipp_s)\
**Replies:** 4\
**Last updated:** [May 6, 2019, 2:26pm UTC](https://discuss.elastic.co/t/apply-filter-query-to-visualization/178211 "2019-05-06T14:26:00Z")

</div>

Hi, I'm currently facing the problem that I cant filter my Disk used \[Metricbeat System\] ECS visualization for a specific system.filesystem.device\_name. When I Group By Term I can see all devices -\> But now I want to …

---

## [Filebeat Nginx Module with Dockerized Nginx](https://discuss.elastic.co/t/filebeat-nginx-module-with-dockerized-nginx/179589)

<div class="topic-metadata">

**Author:** [@tpurcell](https://discuss.elastic.co/u/tpurcell)\
**Replies:** 1\
**Last updated:** [May 6, 2019, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-with-dockerized-nginx/179589 "2019-05-06T13:39:41Z")

</div>

Hello I'm running the ELK stack with all components at version 7.0.1 in an Ubuntu 18.04 environment. I want to process logs from an nginx docker container that is setup to send access logs to stdout and error logs to s…

---

## [Beats management questions](https://discuss.elastic.co/t/beats-management-questions/179617)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 3\
**Last updated:** [May 6, 2019, 1:26pm UTC](https://discuss.elastic.co/t/beats-management-questions/179617 "2019-05-06T13:26:40Z")

</div>

Trying to get started in beats central management. How can I specify a port in logstash output hosts? How to add fields in the general section via management? Thanks

---

## [How to monitor docker services using metricbeat](https://discuss.elastic.co/t/how-to-monitor-docker-services-using-metricbeat/179753)

<div class="topic-metadata">

**Author:** [@matanper](https://discuss.elastic.co/u/matanper)\
**Replies:** 0\
**Last updated:** [May 6, 2019, 11:24am UTC](https://discuss.elastic.co/t/how-to-monitor-docker-services-using-metricbeat/179753 "2019-05-06T11:24:19Z")

</div>

I have a docker swarm running a number of services. I'm using the elastic stack (kibana, elastic, filebeat, etc) for monitoring. For the business logic I'm writing logs and using filebeat to move them to logstash and an…

---

## [Filebeat module ignore\_older](https://discuss.elastic.co/t/filebeat-module-ignore-older/179616)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 1\
**Last updated:** [May 6, 2019, 9:09am UTC](https://discuss.elastic.co/t/filebeat-module-ignore-older/179616 "2019-05-06T09:09:35Z")

</div>

How can I add the ignore\_older option to filebeat modules?

---

## [Ошибка в Filebeat](https://discuss.elastic.co/t/filebeat/179632)

<div class="topic-metadata">

**Author:** [@ssolomin](https://discuss.elastic.co/u/ssolomin)\
**Replies:** 1\
**Last updated:** [May 6, 2019, 9:03am UTC](https://discuss.elastic.co/t/filebeat/179632 "2019-05-06T09:03:48Z")

</div>

Здравствуйте. Использую filebeat 6.3.2, отправляю данные через logstash. На этой же машине стоит metricbeat 6.3.2. В логах filebeat ошибка 2019-05-04T21:05:59.390+0300 ERROR registrar/registrar.go:346 Writin…

---

## [Beat to index HTTP output](https://discuss.elastic.co/t/beat-to-index-http-output/179375)

<div class="topic-metadata">

**Author:** [@coudenysj](https://discuss.elastic.co/u/coudenysj)\
**Replies:** 5\
**Last updated:** [May 6, 2019, 8:09am UTC](https://discuss.elastic.co/t/beat-to-index-http-output/179375 "2019-05-06T08:09:01Z")

</div>

Hi all, I was wondering if there is a beat which can periodically call a HTTP endpoint which outputs JSON, and index that data straight into Elasticsearch? This is useful for PHP opcache information, for instance (whic…

---

## [Where Clause for WMIbeat is not working](https://discuss.elastic.co/t/where-clause-for-wmibeat-is-not-working/179724)

<div class="topic-metadata">

**Author:** [@swapnali](https://discuss.elastic.co/u/swapnali)\
**Replies:** 0\
**Last updated:** [May 6, 2019, 7:58am UTC](https://discuss.elastic.co/t/where-clause-for-wmibeat-is-not-working/179724 "2019-05-06T07:58:13Z")

</div>

hello, I want to check non empty field of ip address in wmibeat, so i used whereclause for empty checking of IP adress as below in my wmibeat.yml. class: Win32\_NetworkAdapterConfiguration fields: IPAddress wherecla…

---

## [Configuring Functionbeat with AWS VPC information for self-hosted ELK](https://discuss.elastic.co/t/configuring-functionbeat-with-aws-vpc-information-for-self-hosted-elk/178508)

<div class="topic-metadata">

**Author:** [@andrewjkrull](https://discuss.elastic.co/u/andrewjkrull)\
**Replies:** 8\
**Last updated:** [May 6, 2019, 7:19am UTC](https://discuss.elastic.co/t/configuring-functionbeat-with-aws-vpc-information-for-self-hosted-elk/178508 "2019-05-06T07:19:23Z")

</div>

Good day. I have been working with Functionbeat for the past couple weeks. I was finally able to get logs to my self hosted ELK but I had to modify the IAM role Functionbeat created by adding the following policies: AW…

---

## [Read JSON fields with filebeat](https://discuss.elastic.co/t/read-json-fields-with-filebeat/179666)

<div class="topic-metadata">

**Author:** [@Leon\_Voerman](https://discuss.elastic.co/u/Leon_Voerman)\
**Replies:** 2\
**Last updated:** [May 5, 2019, 11:07pm UTC](https://discuss.elastic.co/t/read-json-fields-with-filebeat/179666 "2019-05-05T23:07:02Z")

</div>

Hi all, I'm trying to read the data fields of a JSON message from my anti virus with filebeat, but somehow it keeps showing up as a full message. It doesn't filter/detect the process.name and hostname and PID either. H…

---

## [Filebeat for Emails](https://discuss.elastic.co/t/filebeat-for-emails/179659)

<div class="topic-metadata">

**Author:** [@Kostas\_Gush](https://discuss.elastic.co/u/Kostas_Gush)\
**Replies:** 1\
**Last updated:** [May 5, 2019, 9:12am UTC](https://discuss.elastic.co/t/filebeat-for-emails/179659 "2019-05-05T09:12:05Z")

</div>

Hello, I am trying to develop something like the Hunting ELK, or HELK, which can be found in github. The final project should handle in some way phishing emails. For the first step I need to somehow get the emails to s…

---

## [Functionbeat JSON logs](https://discuss.elastic.co/t/functionbeat-json-logs/178301)

<div class="topic-metadata">

**Author:** [@Marc\_Fielding](https://discuss.elastic.co/u/Marc_Fielding)\
**Replies:** 0\
**Last updated:** [April 24, 2019, 5:02pm UTC](https://discuss.elastic.co/t/functionbeat-json-logs/178301 "2019-04-24T17:02:40Z")

</div>

Hey Everyone, So I have Functionbeat working nicely with cloudwatch logs, we use Bunyan to do out logging in JSON format so, for example, some log messages look like this: { "name": "the\_log", "hostname": "ip-1-2-3-4…

---

## [Overriding output from command line](https://discuss.elastic.co/t/overriding-output-from-command-line/178868)

<div class="topic-metadata">

**Author:** [@Maciej\_Krasuski](https://discuss.elastic.co/u/Maciej_Krasuski)\
**Replies:** 3\
**Last updated:** [May 3, 2019, 7:26pm UTC](https://discuss.elastic.co/t/overriding-output-from-command-line/178868 "2019-05-03T19:26:28Z")

</div>

I'd like to debug processing of events by production filebeat.yml trying to redirect input and output for filebeat to console. Input can be redefined by -E with no problems but output redirection is fairly impossible. A…

---

## [Custom Beat Panic "Index Out of Error"](https://discuss.elastic.co/t/custom-beat-panic-index-out-of-error/179574)

<div class="topic-metadata">

**Author:** [@FracKen](https://discuss.elastic.co/u/FracKen)\
**Replies:** 0\
**Last updated:** [May 3, 2019, 6:38pm UTC](https://discuss.elastic.co/t/custom-beat-panic-index-out-of-error/179574 "2019-05-03T18:38:16Z")

</div>

I am getting an "index out of range" error for a beat I am building. I am about to pull my hair out over this. I am NOT a developer and the developers I have access to are not knowledgeable enough about beats or elastics…

---

## [Logstash doesn't receive packetbeat logs](https://discuss.elastic.co/t/logstash-doesnt-receive-packetbeat-logs/179548)

<div class="topic-metadata">

**Author:** [@Robin020](https://discuss.elastic.co/u/Robin020)\
**Replies:** 2\
**Last updated:** [May 3, 2019, 3:47pm UTC](https://discuss.elastic.co/t/logstash-doesnt-receive-packetbeat-logs/179548 "2019-05-03T15:47:38Z")

</div>

Hello, I have the following set up: server1 is running packetbeat. In packetbeat.yml i have configure output to my logstash node. server2 is running logstash and elasticsearch. There is were I want to send all my dat…

---

## [Reinstall vs upgrade beats](https://discuss.elastic.co/t/reinstall-vs-upgrade-beats/179468)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 2\
**Last updated:** [May 3, 2019, 2:38pm UTC](https://discuss.elastic.co/t/reinstall-vs-upgrade-beats/179468 "2019-05-03T14:38:05Z")

</div>

Hi I have a question. I have recently upgraded Elastic search and kibana to 7 from 6.7. On few of the servers I have prior to 6.7 beats version running. What happens if I uninstall 6.x version and resinstall filebeat7 …

---

## [Identify syslog message and filter it](https://discuss.elastic.co/t/identify-syslog-message-and-filter-it/179550)

<div class="topic-metadata">

**Author:** [@raxawageme](https://discuss.elastic.co/u/raxawageme)\
**Replies:** 2\
**Last updated:** [May 3, 2019, 2:33pm UTC](https://discuss.elastic.co/t/identify-syslog-message-and-filter-it/179550 "2019-05-03T14:33:02Z")

</div>

Greetings. I want identify log messages received from syslog based on a regex pattern to tipify them and send to my logstash. For e.g.: logs with 'SECURITY' will be send with\[type\] = 'security' while logs with 'SYSTEM'…

---

## [Getting deeper into NFS with Packetbeat](https://discuss.elastic.co/t/getting-deeper-into-nfs-with-packetbeat/179124)

<div class="topic-metadata">

**Author:** [@databloom](https://discuss.elastic.co/u/databloom)\
**Replies:** 1\
**Last updated:** [May 3, 2019, 1:32pm UTC](https://discuss.elastic.co/t/getting-deeper-into-nfs-with-packetbeat/179124 "2019-05-03T13:32:23Z")

</div>

Hi ! Love packetbeat, I'm using it to replace home-grown sed and awk templates with tshark. I looked through fields.yml and ran packetbeat -d and realized you were constraining your output event schema predump. Is it …

---

## [Gz rollover support in Filebeat](https://discuss.elastic.co/t/gz-rollover-support-in-filebeat/179542)

<div class="topic-metadata">

**Author:** [@Neerav\_Vadodaria](https://discuss.elastic.co/u/Neerav_Vadodaria)\
**Replies:** 0\
**Last updated:** [May 3, 2019, 1:26pm UTC](https://discuss.elastic.co/t/gz-rollover-support-in-filebeat/179542 "2019-05-03T13:26:16Z")

</div>

We have logback configuration with FixedWindowRollingPOlicy with rolls over the logs after every 500MB file size to a gz format. I have read several topics and didn't find how can I achieve this is filebeat if the file g…

---

## [Add tag for only one beat](https://discuss.elastic.co/t/add-tag-for-only-one-beat/179512)

<div class="topic-metadata">

**Author:** [@Robin020](https://discuss.elastic.co/u/Robin020)\
**Replies:** 2\
**Last updated:** [May 3, 2019, 1:09pm UTC](https://discuss.elastic.co/t/add-tag-for-only-one-beat/179512 "2019-05-03T13:09:18Z")

</div>

I am trying to add an tag for the logs of packetbeat before it sends to elasticsearch. Packetbeat send his logs to logstash. In the logstash pipiline file i want to try to add an tag only for logs of packetbeat but I do…

---

## [Failed to connect to backoff](https://discuss.elastic.co/t/failed-to-connect-to-backoff/179398)

<div class="topic-metadata">

**Author:** [@sblancocr](https://discuss.elastic.co/u/sblancocr)\
**Replies:** 2\
**Last updated:** [May 3, 2019, 10:14am UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff/179398 "2019-05-03T10:14:23Z")

</div>

Hi I installed a metricbeat in the server... and it have next configuration. metricbeat.config.modules: path: ${path.config}/modules.d/.yml\* reload.enabled: false setup.template.settings: index.number\_of\_shards: 1 …

---

## [Filebeat 7.0.0](https://discuss.elastic.co/t/filebeat-7-0-0/179478)

<div class="topic-metadata">

**Author:** [@Pascal72](https://discuss.elastic.co/u/Pascal72)\
**Replies:** 0\
**Last updated:** [May 3, 2019, 6:32am UTC](https://discuss.elastic.co/t/filebeat-7-0-0/179478 "2019-05-03T06:32:18Z")

</div>

Hi, I have recently upgraded my ELK infrastructure to version 7.0.0. On my elasticsearch nodes, I have also upgraded the filebeat component. The configuration is quite simple, I have only activated the elasticsearch mod…

---

## [Filebeat SSH dashboard failing to show events (Kibana 7.0)](https://discuss.elastic.co/t/filebeat-ssh-dashboard-failing-to-show-events-kibana-7-0/177792)

<div class="topic-metadata">

**Author:** [@bradfordaemorton](https://discuss.elastic.co/u/bradfordaemorton)\
**Replies:** 16\
**Last updated:** [May 3, 2019, 5:49am UTC](https://discuss.elastic.co/t/filebeat-ssh-dashboard-failing-to-show-events-kibana-7-0/177792 "2019-05-03T05:49:18Z")

</div>

Hi All, I have recently rebuilt my elasticsearch and kibana infrastructure to 7.0 and reinstalled my filebeat and metricbeat collectors to 7.0. I currently collect access and error logs for apache2 (I have the module …

---

## [Beats and ELK cluster version](https://discuss.elastic.co/t/beats-and-elk-cluster-version/179419)

<div class="topic-metadata">

**Author:** [@rohitg](https://discuss.elastic.co/u/rohitg)\
**Replies:** 1\
**Last updated:** [May 3, 2019, 2:17am UTC](https://discuss.elastic.co/t/beats-and-elk-cluster-version/179419 "2019-05-03T02:17:23Z")

</div>

I am planning to upgrade my ELK cluster to 7.0 and don't want to upgrade my beats which are on the older version. I just want to confirm there will be no issue after only upgrading my cluster. Or do i need to upgrade my…

---

## [Filebeat not uploading lastest ingest grok pattern to elasticsearch](https://discuss.elastic.co/t/filebeat-not-uploading-lastest-ingest-grok-pattern-to-elasticsearch/179174)

<div class="topic-metadata">

**Author:** [@Dylan\_Nicholson](https://discuss.elastic.co/u/Dylan_Nicholson)\
**Replies:** 5\
**Last updated:** [May 3, 2019, 1:43am UTC](https://discuss.elastic.co/t/filebeat-not-uploading-lastest-ingest-grok-pattern-to-elasticsearch/179174 "2019-05-03T01:43:16Z")

</div>

I'm trying to test out an issue with my grok pattern (specifically, it seems to be ending parsing of the field on a space, despite the pattern requiring that a } be at the end), but it seems no matter what I put in the j…

---

## [Alerting on Filebeat](https://discuss.elastic.co/t/alerting-on-filebeat/179235)

<div class="topic-metadata">

**Author:** [@surya2](https://discuss.elastic.co/u/surya2)\
**Replies:** 3\
**Last updated:** [May 2, 2019, 2:40pm UTC](https://discuss.elastic.co/t/alerting-on-filebeat/179235 "2019-05-02T14:40:41Z")

</div>

Hello, I want to enable alerting on Filebeat. I want to send a email or message whenever filebeat service stops. How can i achieve it without curator. Thanks, Surya

---

## [Separate Monitoring Cluster with Basic License](https://discuss.elastic.co/t/separate-monitoring-cluster-with-basic-license/178101)

<div class="topic-metadata">

**Author:** [@snorris](https://discuss.elastic.co/u/snorris)\
**Replies:** 9\
**Last updated:** [May 2, 2019, 2:24pm UTC](https://discuss.elastic.co/t/separate-monitoring-cluster-with-basic-license/178101 "2019-05-02T14:24:48Z")

</div>

I have established a separate monitoring cluster based on recommended best practices (current ES version 6.5.3). Initially, I followed the instructions listed at https://www.elastic.co/guide/en/kibana/7.0/monitoring-metr…

---

## [Filebeat errors after update to version 7](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607)

<div class="topic-metadata">

**Author:** [@cawa](https://discuss.elastic.co/u/cawa)\
**Replies:** 9\
**Last updated:** [May 2, 2019, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-errors-after-update-to-version-7/178607 "2019-05-02T14:08:25Z")

</div>

I get a flood of errors since updating the cluster and filebeat to version 7. My setup consists of a 2 node elasticsearch cluster and a bunch of servers running filebeat with modules (system, auditd and nginx) shipping …

---

## [Filebeat not working when Logstash enabling](https://discuss.elastic.co/t/filebeat-not-working-when-logstash-enabling/179345)

<div class="topic-metadata">

**Author:** [@vbrundavanam](https://discuss.elastic.co/u/vbrundavanam)\
**Replies:** 1\
**Last updated:** [May 2, 2019, 11:06am UTC](https://discuss.elastic.co/t/filebeat-not-working-when-logstash-enabling/179345 "2019-05-02T11:06:26Z")

</div>

Hi Team, When i am trying to enable logstash configuration in filebeat.conf file, filebeat is not restarting. please find the below configurations. indent preformatted text by 4 spaces ###################### Filebeat …

---

## [Manually import Heartbeat dashboards](https://discuss.elastic.co/t/manually-import-heartbeat-dashboards/179129)

<div class="topic-metadata">

**Author:** [@Dhulem](https://discuss.elastic.co/u/Dhulem)\
**Replies:** 2\
**Last updated:** [May 2, 2019, 10:02am UTC](https://discuss.elastic.co/t/manually-import-heartbeat-dashboards/179129 "2019-05-02T10:02:38Z")

</div>

I am new to the Elk-Stack and found that when I try to import the dashboards with the following command. .\\heartbeat setup --dashboards No Directory (c:\\elk-stack\\heatbeat7.0.0\\kibana/7) I found https://github.com/ela…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=357)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=359)
