# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=359

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 360

---

## [Auditbeat "drop\_event" regex performance?](https://discuss.elastic.co/t/auditbeat-drop-event-regex-performance/178258)

<div class="topic-metadata">

**Author:** [@ec4n6](https://discuss.elastic.co/u/ec4n6)\
**Replies:** 4\
**Last updated:** [May 2, 2019, 9:48am UTC](https://discuss.elastic.co/t/auditbeat-drop-event-regex-performance/178258 "2019-05-02T09:48:00Z")

</div>

I'm wondering which of these drop\_event formats will give the best run time? Thanks! \> - drop\_event: \> when.regexp.auditd.summary.actor.secondary: "root|daemon|bin" vs. - drop\_event: when.or: - equals.…

---

## [Metricbeat | Does metricbeat store hardware utilization data?](https://discuss.elastic.co/t/metricbeat-does-metricbeat-store-hardware-utilization-data/179100)

<div class="topic-metadata">

**Author:** [@Aftab\_Ali](https://discuss.elastic.co/u/Aftab_Ali)\
**Replies:** 1\
**Last updated:** [May 2, 2019, 9:44am UTC](https://discuss.elastic.co/t/metricbeat-does-metricbeat-store-hardware-utilization-data/179100 "2019-05-02T09:44:52Z")

</div>

Dear Team, I want to know, Does metricbeart store hardware utilization data and after that, if elasticsearch come online , So then its sync again that stored data to elasticsearch?

---

## [Regarding Filebeat Modules and Docker Logs](https://discuss.elastic.co/t/regarding-filebeat-modules-and-docker-logs/178276)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 2\
**Last updated:** [May 2, 2019, 8:55am UTC](https://discuss.elastic.co/t/regarding-filebeat-modules-and-docker-logs/178276 "2019-05-02T08:55:18Z")

</div>

Hi, We will be running filebeat in kubernetes where apps will be logging to stdout and filebeat will be scanning for container logs output by docker. Does this mean that filebeat modules cannot be used? Regards, D

---

## [Filebeat Module For Tomcat?](https://discuss.elastic.co/t/filebeat-module-for-tomcat/179222)

<div class="topic-metadata">

**Author:** [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Replies:** 1\
**Last updated:** [May 2, 2019, 8:20am UTC](https://discuss.elastic.co/t/filebeat-module-for-tomcat/179222 "2019-05-02T08:20:43Z")

</div>

I have found there is a Filebeat module to parse Apache logs, but is there a module that will parse Apache Tomcat logs? -Tony

---

## [Filebeat drop\_event has\_fields condition](https://discuss.elastic.co/t/filebeat-drop-event-has-fields-condition/179139)

<div class="topic-metadata">

**Author:** [@arianmotamedi](https://discuss.elastic.co/u/arianmotamedi)\
**Replies:** 1\
**Last updated:** [May 2, 2019, 6:47am UTC](https://discuss.elastic.co/t/filebeat-drop-event-has-fields-condition/179139 "2019-05-02T06:47:21Z")

</div>

I have defined two drop\_event conditions to exclude a subset of logs from making it to elastic: processors: - add\_kubernetes\_metadata: in\_cluster: true namespace: ${POD\_NAMESPACE} - drop\_event: whe…

---

## [Filebeats to correctly propagate Docker container information into Elasticsearc](https://discuss.elastic.co/t/filebeats-to-correctly-propagate-docker-container-information-into-elasticsearc/179186)

<div class="topic-metadata">

**Author:** [@tpnbrown](https://discuss.elastic.co/u/tpnbrown)\
**Replies:** 1\
**Last updated:** [May 2, 2019, 5:40am UTC](https://discuss.elastic.co/t/filebeats-to-correctly-propagate-docker-container-information-into-elasticsearc/179186 "2019-05-02T05:40:29Z")

</div>

Hi all, I'm struggling to get Filebeats to correctly propagate Docker container information into Elasticsearch. It includes 'docker.container.id'. However, the id is postfixed with '-json.log' as shown in the example b…

---

## [Processor not working in filebeat](https://discuss.elastic.co/t/processor-not-working-in-filebeat/178929)

<div class="topic-metadata">

**Author:** [@aarthinim](https://discuss.elastic.co/u/aarthinim)\
**Replies:** 4\
**Last updated:** [May 2, 2019, 5:21am UTC](https://discuss.elastic.co/t/processor-not-working-in-filebeat/178929 "2019-05-02T05:21:53Z")

</div>

HI, Need to get the ERROR message only from the log file using processors.

---

## [Create a custom index in winlogbeat using cloud.id](https://discuss.elastic.co/t/create-a-custom-index-in-winlogbeat-using-cloud-id/179256)

<div class="topic-metadata">

**Author:** [@mdhw3uxhwh](https://discuss.elastic.co/u/mdhw3uxhwh)\
**Replies:** 2\
**Last updated:** [May 2, 2019, 3:02am UTC](https://discuss.elastic.co/t/create-a-custom-index-in-winlogbeat-using-cloud-id/179256 "2019-05-02T03:02:45Z")

</div>

Hello, I have reviewed a post that contains information on how to accomplish changing the default winlogbeat index name, but it does not seem to work for me. I have tried exactly what the post provided and it didn't wo…

---

## [ILM setting in beats configuration](https://discuss.elastic.co/t/ilm-setting-in-beats-configuration/179257)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 4\
**Last updated:** [May 1, 2019, 9:56pm UTC](https://discuss.elastic.co/t/ilm-setting-in-beats-configuration/179257 "2019-05-01T21:56:43Z")

</div>

Hi I am seeing ilm errors in my Elastic search. I am currently using beats 6.7 version. I am planning to install version 7 now. I got to know that filebeat has to create an alias while creating an index. I see the bel…

---

## [Beats (filebeat/metricbeat etc.) log to syslog with "logging.to\_syslog: false"](https://discuss.elastic.co/t/beats-filebeat-metricbeat-etc-log-to-syslog-with-logging-to-syslog-false/179085)

<div class="topic-metadata">

**Author:** [@bcsmith](https://discuss.elastic.co/u/bcsmith)\
**Replies:** 5\
**Last updated:** [May 1, 2019, 8:08pm UTC](https://discuss.elastic.co/t/beats-filebeat-metricbeat-etc-log-to-syslog-with-logging-to-syslog-false/179085 "2019-05-01T20:08:37Z")

</div>

Hello I am looking at a host running Ubuntu Xenial, Logging goes to the /var/log/filebeat/filebeat fine, until an index it is writing to goes read only. Then filebeat spams /var/log/syslog with messages like the followi…

---

## [Getting a 400 Bad Request when hitting the min.io browser login](https://discuss.elastic.co/t/getting-a-400-bad-request-when-hitting-the-min-io-browser-login/179229)

<div class="topic-metadata">

**Author:** [@Joseph\_Gange](https://discuss.elastic.co/u/Joseph_Gange)\
**Replies:** 2\
**Last updated:** [May 1, 2019, 7:05pm UTC](https://discuss.elastic.co/t/getting-a-400-bad-request-when-hitting-the-min-io-browser-login/179229 "2019-05-01T19:05:02Z")

</div>

I've configured a monitor to check out Minio instance. The section of the heartbeat.yml is below (address and credentials replaced with "x"s). type: http schedule: '@every 5s' urls: \["http://xxx.xxx.xxx.xxx:9000/min…

---

## [Filebeat + kubernetes + ingress-nginx](https://discuss.elastic.co/t/filebeat-kubernetes-ingress-nginx/177504)

<div class="topic-metadata">

**Author:** [@concretefairy](https://discuss.elastic.co/u/concretefairy)\
**Replies:** 1\
**Last updated:** [May 1, 2019, 3:12pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-ingress-nginx/177504 "2019-05-01T15:12:00Z")

</div>

Versions: Filebeat 6.6.1 ELK 6.6.1 kubernetes 1.11.1 ingress 0.23.1 Greetings! I am new to filebeat, and k8s. My goal is - harvest nginx-igress access + error logs and pass it to logstash with filebeat. Here is a p…

---

## [Module system doesn't exist!...but it does](https://discuss.elastic.co/t/module-system-doesnt-exist-but-it-does/178702)

<div class="topic-metadata">

**Author:** [@teamg](https://discuss.elastic.co/u/teamg)\
**Replies:** 2\
**Last updated:** [May 1, 2019, 1:54pm UTC](https://discuss.elastic.co/t/module-system-doesnt-exist-but-it-does/178702 "2019-05-01T13:54:46Z")

</div>

Been troubleshooting metricbeat and found something interesting in version 7 of ELK and Metricbeat: \[root@elk modules.d\]# metricbeat modules list Enabled: Disabled: \[root@elk modules.d\]# metricbeat modules enable …

---

## [Filebeats not pulling logs](https://discuss.elastic.co/t/filebeats-not-pulling-logs/179196)

<div class="topic-metadata">

**Author:** [@vbrundavanam](https://discuss.elastic.co/u/vbrundavanam)\
**Replies:** 0\
**Last updated:** [May 1, 2019, 11:09am UTC](https://discuss.elastic.co/t/filebeats-not-pulling-logs/179196 "2019-05-01T11:09:17Z")

</div>

Hi, I am using ELK 6.3.2 on windows server. i am able to configure audit beat and logbeat but unable to configure filebeat. Below is my filebeat configuration. # This file is an example configuration file highlighting …

---

## [Possible Memory Leak?](https://discuss.elastic.co/t/possible-memory-leak/179126)

<div class="topic-metadata">

**Author:** [@AddChickpeas](https://discuss.elastic.co/u/AddChickpeas)\
**Replies:** 2\
**Last updated:** [April 30, 2019, 8:35pm UTC](https://discuss.elastic.co/t/possible-memory-leak/179126 "2019-04-30T20:35:56Z")

</div>

Hi All, We deployed filebeat to a handful of Windows Server 2012 VMs over the weekend and are seeing very high memory usage on all of the servers. I dug around and found a bunch of other mem leak issues, but none seemed…

---

## [Filebeat 6.6 to ES 7.0](https://discuss.elastic.co/t/filebeat-6-6-to-es-7-0/179133)

<div class="topic-metadata">

**Author:** [@robscott27](https://discuss.elastic.co/u/robscott27)\
**Replies:** 1\
**Last updated:** [April 30, 2019, 8:12pm UTC](https://discuss.elastic.co/t/filebeat-6-6-to-es-7-0/179133 "2019-04-30T20:12:41Z")

</div>

Looking to send logs from Filebeat 6.6 into Elasticsearch 7.0. The connection is established but then I get the following error message: 2019-04-30T14:08:17.472-0400 ERROR pipeline/output.go:100 Failed to connect to bac…

---

## [Log forwarding using filebeat to Elastic Search](https://discuss.elastic.co/t/log-forwarding-using-filebeat-to-elastic-search/179136)

<div class="topic-metadata">

**Author:** [@Tejesh](https://discuss.elastic.co/u/Tejesh)\
**Replies:** 0\
**Last updated:** [April 30, 2019, 6:52pm UTC](https://discuss.elastic.co/t/log-forwarding-using-filebeat-to-elastic-search/179136 "2019-04-30T18:52:36Z")

</div>

Hello , Can you share a sample filebeat.yml to ship logs directly to elastic search . Thank you

---

## [Gather metrics with lower resolution](https://discuss.elastic.co/t/gather-metrics-with-lower-resolution/178897)

<div class="topic-metadata">

**Author:** [@A\_B](https://discuss.elastic.co/u/A_B)\
**Replies:** 2\
**Last updated:** [April 30, 2019, 2:53pm UTC](https://discuss.elastic.co/t/gather-metrics-with-lower-resolution/178897 "2019-04-30T14:53:31Z")

</div>

Hello, I'm a longtime Elastic Stack user but new to Metricbeat. I installed it on a few machines last week to test it out and have a few questions :slight\_smile: Is there a way to down sample or adjust the resolution o…

---

## [Filter out events by JSON content](https://discuss.elastic.co/t/filter-out-events-by-json-content/177037)

<div class="topic-metadata">

**Author:** [@smoking81](https://discuss.elastic.co/u/smoking81)\
**Replies:** 3\
**Last updated:** [April 30, 2019, 1:53pm UTC](https://discuss.elastic.co/t/filter-out-events-by-json-content/177037 "2019-04-30T13:53:20Z")

</div>

Hello there, I am running Filebeat on K8S and want to index just application files encoded in JSON which contain a field "classtype" with value "application". It seems a quite easy requirement, after trying all the poss…

---

## [Filebeat with multiple different index type](https://discuss.elastic.co/t/filebeat-with-multiple-different-index-type/178847)

<div class="topic-metadata">

**Author:** [@sahinguler](https://discuss.elastic.co/u/sahinguler)\
**Replies:** 4\
**Last updated:** [April 30, 2019, 1:27pm UTC](https://discuss.elastic.co/t/filebeat-with-multiple-different-index-type/178847 "2019-04-30T13:27:14Z")

</div>

Hi all. I want to use filebeat with different input in a single yml file. Such as input type docker and input type log in same file. Does anybody help? My config yml for filebeat as following: Autodiscover allows you …

---

## [Filebeat, nginx module dashboards are broken after migrate to 6.7](https://discuss.elastic.co/t/filebeat-nginx-module-dashboards-are-broken-after-migrate-to-6-7/178268)

<div class="topic-metadata">

**Author:** [@jonviously](https://discuss.elastic.co/u/jonviously)\
**Replies:** 4\
**Last updated:** [April 30, 2019, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-dashboards-are-broken-after-migrate-to-6-7/178268 "2019-04-30T13:00:16Z")

</div>

Hi everyone ! I'm using the nginx module of filebeat with logstash. After migrate from 6.6.1 to 6.7.1, the differents dashboards of the module were broken. For Example the dashboard "\[Filebeat Nginx\] Overview" was lik…

---

## [Unable to get files from filebeat to kafka](https://discuss.elastic.co/t/unable-to-get-files-from-filebeat-to-kafka/178963)

<div class="topic-metadata">

**Author:** [@massiveashok](https://discuss.elastic.co/u/massiveashok)\
**Replies:** 7\
**Last updated:** [April 30, 2019, 12:51pm UTC](https://discuss.elastic.co/t/unable-to-get-files-from-filebeat-to-kafka/178963 "2019-04-30T12:51:36Z")

</div>

Am new in using filebeat 7.0.0 and populate log files to kafka 2.10. ###################### Filebeat Configuration Example #=========================== Filebeat inputs ============================= filebeat.inputs: E…

---

## [How to change the index name of beats logs in kubernetes](https://discuss.elastic.co/t/how-to-change-the-index-name-of-beats-logs-in-kubernetes/177684)

<div class="topic-metadata">

**Author:** [@Ji\_Ho\_Choi](https://discuss.elastic.co/u/Ji_Ho_Choi)\
**Replies:** 1\
**Last updated:** [April 30, 2019, 12:29pm UTC](https://discuss.elastic.co/t/how-to-change-the-index-name-of-beats-logs-in-kubernetes/177684 "2019-04-30T12:29:41Z")

</div>

I have beats linked to elastic cloud elasticsearch 7.0.0. We have filebeats and metricbeats successfully sending logs to elasticsearch as both deployment and daemonset in kubernetes environment. However, I am unable to c…

---

## [Filebeat for shipping the entire logfile as it is](https://discuss.elastic.co/t/filebeat-for-shipping-the-entire-logfile-as-it-is/178565)

<div class="topic-metadata">

**Author:** [@shub8050](https://discuss.elastic.co/u/shub8050)\
**Replies:** 10\
**Last updated:** [April 30, 2019, 10:58am UTC](https://discuss.elastic.co/t/filebeat-for-shipping-the-entire-logfile-as-it-is/178565 "2019-04-30T10:58:59Z")

</div>

I need to get the entire log file as it is in the elk stack. Consider I have this log: \<line1\> \<line2\> \<line3\>| If my pointer is placed on the line 3 i will get the entire log file except \<line3\> . If the cursor is in…

---

## [Filebeat not able to send logs to Elastic](https://discuss.elastic.co/t/filebeat-not-able-to-send-logs-to-elastic/178627)

<div class="topic-metadata">

**Author:** [@parsu](https://discuss.elastic.co/u/parsu)\
**Replies:** 5\
**Last updated:** [April 30, 2019, 10:52am UTC](https://discuss.elastic.co/t/filebeat-not-able-to-send-logs-to-elastic/178627 "2019-04-30T10:52:52Z")

</div>

Hi, I am trying to send data to elastic search using filebeat. I started my elastic search and then filebeat. I am getting the bellow message OS: Ubuntu 16.04 Filebeat version: filebeat-7.0.0 ElasticSearch version: …

---

## [How to make beats send data to multiple instances](https://discuss.elastic.co/t/how-to-make-beats-send-data-to-multiple-instances/179010)

<div class="topic-metadata">

**Author:** [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Replies:** 4\
**Last updated:** [April 30, 2019, 10:02am UTC](https://discuss.elastic.co/t/how-to-make-beats-send-data-to-multiple-instances/179010 "2019-04-30T10:02:17Z")

</div>

Dear ElasticSearch Team, Here I take logs use case as an example, Basically, we'll collect these system logs, application logs, business logs for each application on our production, and ship them to different logstash c…

---

## [It is possible to create an alert when an event 4652 appears?](https://discuss.elastic.co/t/it-is-possible-to-create-an-alert-when-an-event-4652-appears/178915)

<div class="topic-metadata">

**Author:** [@JoseLuis](https://discuss.elastic.co/u/JoseLuis)\
**Replies:** 2\
**Last updated:** [April 30, 2019, 7:56am UTC](https://discuss.elastic.co/t/it-is-possible-to-create-an-alert-when-an-event-4652-appears/178915 "2019-04-30T07:56:48Z")

</div>

Hello, I'm trying to configure a watcher in my elastic stack to show me alerts about windows events, however, I can only do general alerts and not specific events. Is it possible in some way to make the alerts more spec…

---

## [Is everyone know how to apply the close\_timeout in filebeat modules](https://discuss.elastic.co/t/is-everyone-know-how-to-apply-the-close-timeout-in-filebeat-modules/179015)

<div class="topic-metadata">

**Author:** [@Mohan\_Selvam](https://discuss.elastic.co/u/Mohan_Selvam)\
**Replies:** 2\
**Last updated:** [April 30, 2019, 7:26am UTC](https://discuss.elastic.co/t/is-everyone-know-how-to-apply-the-close-timeout-in-filebeat-modules/179015 "2019-04-30T07:26:12Z")

</div>

i am having this one in filebeat.yml file , but its not working. can anyone please tell me how to achieve this one?

---

## [Journalbeat for armv7l GNU/Linux](https://discuss.elastic.co/t/journalbeat-for-armv7l-gnu-linux/178911)

<div class="topic-metadata">

**Author:** [@lecndav](https://discuss.elastic.co/u/lecndav)\
**Replies:** 4\
**Last updated:** [April 30, 2019, 7:15am UTC](https://discuss.elastic.co/t/journalbeat-for-armv7l-gnu-linux/178911 "2019-04-30T07:15:55Z")

</div>

Hi, I want to compile and run Journalbeat for an armv7l architecture. Therefore my go build arguments are "GOOS=linux" and "GOARCH=arm". When I run journalbeat on my target machine it exits with "ERROR instance/beat…

---

## [Custom fields.yml](https://discuss.elastic.co/t/custom-fields-yml/178879)

<div class="topic-metadata">

**Author:** [@aksadvance](https://discuss.elastic.co/u/aksadvance)\
**Replies:** 2\
**Last updated:** [April 30, 2019, 6:48am UTC](https://discuss.elastic.co/t/custom-fields-yml/178879 "2019-04-30T06:48:06Z")

</div>

Hi, I have defined template in ES via \_template api. Created index also , having mapping as per above template. Now i want to feed data hence i have setup filebeat -\> Logstash -\> ES. I have created dummy data as per …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=358)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=360)
