# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=36

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 37

---

## [How to create API key with built-in role ? Filebeat to Elastic configuration](https://discuss.elastic.co/t/how-to-create-api-key-with-built-in-role-filebeat-to-elastic-configuration/344884)

<div class="topic-metadata">

**Author:** [@Gaetan\_Verdin-Pol](https://discuss.elastic.co/u/Gaetan_Verdin-Pol)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/how-to-create-api-key-with-built-in-role-filebeat-to-elastic-configuration/344884 "2023-10-12T08:29:29Z")

</div>

Hello all ! I am currently following the nginx filebeat integration from Filebeat to Elastic and I want to use api\_key instead of username/password to authenticate to my Elastic instance and setup the filebeat module. B…

---

## [ELK8.10 filebeat input combine modules and filestream and can not show dashboard current](https://discuss.elastic.co/t/elk8-10-filebeat-input-combine-modules-and-filestream-and-can-not-show-dashboard-current/344876)

<div class="topic-metadata">

**Author:** [@p81061473525](https://discuss.elastic.co/u/p81061473525)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 6:55am UTC](https://discuss.elastic.co/t/elk8-10-filebeat-input-combine-modules-and-filestream-and-can-not-show-dashboard-current/344876 "2023-10-12T06:55:00Z")

</div>

Hello, I'm currently installing version ELK8.10. my system diagram like this one filebeat -\> es cluster my problem is my server has mutiple log need to collect . such as. nginx, php log, rsyslog ... and I know file…

---

## [Duplicate content when using azure-blob-storage input](https://discuss.elastic.co/t/duplicate-content-when-using-azure-blob-storage-input/344046)

<div class="topic-metadata">

**Author:** [@djesus](https://discuss.elastic.co/u/djesus)\
**Replies:** 4\
**Last updated:** [October 11, 2023, 7:00am UTC](https://discuss.elastic.co/t/duplicate-content-when-using-azure-blob-storage-input/344046 "2023-10-11T07:00:34Z")

</div>

Hello everyone, I'm encountering an issue while using the azure-blob-storage input in Filebeat, where I'm consistently getting duplicate entries each time I poll for data. Here's the setup: We have a container in Azure…

---

## [Documentation on pkg.go.dev (godoc) not working](https://discuss.elastic.co/t/documentation-on-pkg-go-dev-godoc-not-working/344783)

<div class="topic-metadata">

**Author:** [@tlinker13](https://discuss.elastic.co/u/tlinker13)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 5:38am UTC](https://discuss.elastic.co/t/documentation-on-pkg-go-dev-godoc-not-working/344783 "2023-10-11T05:38:46Z")

</div>

Hey all, I try to write a first metricbeat module/metricset and need to dive into the MapStrAPI, but there is no content displayed at libbeat's godoc page saying: "Documentation not displayed due to license restriction…

---

## [\[HELP winlogbeat.yml\] How to send Removable storage logs to Elasticsearch](https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 4:00pm UTC](https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738 "2023-10-10T16:00:39Z")

</div>

Hello from Japan I have a question for you respected engineers. I am an inexperienced Japanese engineer with Elastic search. I have installed winlogbeat on my Windows PC and have built an environment to send Windows l…

---

## [I want to create a pipeline like Log files -\> FileBeat -\> Kafka -\> Logstash -\> Elastic -\> Kibana](https://discuss.elastic.co/t/i-want-to-create-a-pipeline-like-log-files-filebeat-kafka-logstash-elastic-kibana/344744)

<div class="topic-metadata">

**Author:** [@Pritam\_Bhirud](https://discuss.elastic.co/u/Pritam_Bhirud)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 2:20pm UTC](https://discuss.elastic.co/t/i-want-to-create-a-pipeline-like-log-files-filebeat-kafka-logstash-elastic-kibana/344744 "2023-10-10T14:20:24Z")

</div>

While sending data from Filebeat to Kafka, the server crashes continuously. While sending data from Kafka to Logstash, the server also crashes continuously. I have installed kafka in one VM (Ubuntu 22.04, 4GB RAM, 4 Co…

---

## [Date format increasing doesn't work](https://discuss.elastic.co/t/date-format-increasing-doesnt-work/343818)

<div class="topic-metadata">

**Author:** [@20wjsdudtj](https://discuss.elastic.co/u/20wjsdudtj)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 12:48am UTC](https://discuss.elastic.co/t/date-format-increasing-doesnt-work/343818 "2023-10-10T00:48:03Z")

</div>

After assigning my ILM policy as follows: PUT /\_ilm/policy/my\_policy { "policy": { "phases": { "hot": { "actions": { "rollover": { "max\_size": "50gb", "max\_age": "30…

---

## [Fleet "CreateIndexRequest" constantly rollover indicies](https://discuss.elastic.co/t/fleet-createindexrequest-constantly-rollover-indicies/342604)

<div class="topic-metadata">

**Author:** [@Anabel](https://discuss.elastic.co/u/Anabel)\
**Replies:** 2\
**Last updated:** [October 9, 2023, 1:59pm UTC](https://discuss.elastic.co/t/fleet-createindexrequest-constantly-rollover-indicies/342604 "2023-10-09T13:59:27Z")

</div>

Hi everyone Elasticsearch was complaining that we've reached max amount of shards -- we've increased max\_shards\_per\_node from default 1000 to 2000 and later to 5000. and then we noticed hundreds of empty indices with …

---

## [Files crawling count issue in filebeat \[8.6.2\]](https://discuss.elastic.co/t/files-crawling-count-issue-in-filebeat-8-6-2/344620)

<div class="topic-metadata">

**Author:** [@rapetr2](https://discuss.elastic.co/u/rapetr2)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 6:02am UTC](https://discuss.elastic.co/t/files-crawling-count-issue-in-filebeat-8-6-2/344620 "2023-10-09T06:02:42Z")

</div>

We were previously using the filebeat version 7.17.3 and we keep on monitoring the filebeat daily to prepare the reports. Recently, we have upgraded the filebeat to version 8.6.2 and we have observed two things: We obs…

---

## [【filebeat】Did Filebeat consider adding a Grok processor in the processors module?](https://discuss.elastic.co/t/filebeat-did-filebeat-consider-adding-a-grok-processor-in-the-processors-module/344610)

<div class="topic-metadata">

**Author:** [@Enha](https://discuss.elastic.co/u/Enha)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 2:43am UTC](https://discuss.elastic.co/t/filebeat-did-filebeat-consider-adding-a-grok-processor-in-the-processors-module/344610 "2023-10-09T02:43:01Z")

</div>

Did Filebeat consider adding a Grok processor in the processing module? It would be very smooth to use Filebeat to format multiline data when the destination is not Elasticsearch, without the need for an additional layer…

---

## [\[filebeat\] In Filebeat, when using the move\_fields processor with the ignore\_missing: true setting to ignore missing keys, it doesn't work as expected](https://discuss.elastic.co/t/filebeat-in-filebeat-when-using-the-move-fields-processor-with-the-ignore-missing-true-setting-to-ignore-missing-keys-it-doesnt-work-as-expected/344591)

<div class="topic-metadata">

**Author:** [@Enha](https://discuss.elastic.co/u/Enha)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 8:11am UTC](https://discuss.elastic.co/t/filebeat-in-filebeat-when-using-the-move-fields-processor-with-the-ignore-missing-true-setting-to-ignore-missing-keys-it-doesnt-work-as-expected/344591 "2023-10-08T08:11:23Z")

</div>

In Filebeat 8.10.2, when using the move\_fields processor with the ignore\_missing: true setting to ignore missing keys, it doesn't work as expected. Instead of ignoring the missing field and continuing the processing, an …

---

## [\[filebeat\]Suspect Redis connection pool configuration issue causing discrepancy between maximum connection settings and actual results](https://discuss.elastic.co/t/filebeat-suspect-redis-connection-pool-configuration-issue-causing-discrepancy-between-maximum-connection-settings-and-actual-results/344578)

<div class="topic-metadata">

**Author:** [@wang-qijia](https://discuss.elastic.co/u/wang-qijia)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 2:17am UTC](https://discuss.elastic.co/t/filebeat-suspect-redis-connection-pool-configuration-issue-causing-discrepancy-between-maximum-connection-settings-and-actual-results/344578 "2023-10-08T02:17:56Z")

</div>

Description: I am experiencing an issue with the maximum connection settings in Redis not matching the expected behavior. I suspect that there might be a problem with the Redis connection pool configuration. Specifical…

---

## [Filebeat 7.17.6 does not overwrite agent.type and agent.version if they are already present](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 7:18am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521 "2023-10-06T07:18:02Z")

</div>

Hi. We're writing application logs to the files using Elastic.CommonSchema.Serilog package and then ship them with Filebeat to Elastic. Here is how agent field looks like in log files: "agent": { "type": "Elastic.Co…

---

## [Getting error after adding filebeat](https://discuss.elastic.co/t/getting-error-after-adding-filebeat/344481)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 12:56pm UTC](https://discuss.elastic.co/t/getting-error-after-adding-filebeat/344481 "2023-10-05T12:56:24Z")

</div>

Dear Team, We are getting error as below after adding new log files through filebeat ,we have increased our heap size up to 30 g ,and total memory is 62 gb present now on server , \[ERROR\]\[o.e.x.c.a.AsyncTaskIndexServic…

---

## [Filebeat 7.17.6 automatically populates event.module and service.type fields?](https://discuss.elastic.co/t/filebeat-7-17-6-automatically-populates-event-module-and-service-type-fields/344474)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 11:34am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-automatically-populates-event-module-and-service-type-fields/344474 "2023-10-05T11:34:33Z")

</div>

Hi, I'm facing weird behaviour of Filebeat for which I couldn't find any explanation in the docs. So we write application logs into files in ECS format using Elastic.CommonSchema.Serilog package. All log entries have po…

---

## [503 error from Kibana while running Filebeat setup](https://discuss.elastic.co/t/503-error-from-kibana-while-running-filebeat-setup/344435)

<div class="topic-metadata">

**Author:** [@nspeaks](https://discuss.elastic.co/u/nspeaks)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 9:54am UTC](https://discuss.elastic.co/t/503-error-from-kibana-while-running-filebeat-setup/344435 "2023-10-05T09:54:52Z")

</div>

I am trying to run the command filebeat setup -e and this is the error I get {"log.level":"info","@timestamp":"2023-10-05T02:55:42.666Z","log.origin":{"file.name":"instance/beat.go","file.line":783},"message":"Home pa…

---

## [Filebeat cisco ios Parsing delimeter error](https://discuss.elastic.co/t/filebeat-cisco-ios-parsing-delimeter-error/344432)

<div class="topic-metadata">

**Author:** [@lee.clemens](https://discuss.elastic.co/u/lee.clemens)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 10:00pm UTC](https://discuss.elastic.co/t/filebeat-cisco-ios-parsing-delimeter-error/344432 "2023-10-04T22:00:10Z")

</div>

Hello, I'm seeing this runtime error being logged parsing deny logs from IOS: GoError: could not find beginning delimiter: list in remaining: F0/0: fman\_fp\_image: list ACL\_Inbound denied udp 127.0.0.1(51052) -\> 127.0.…

---

## [Filebeat auth.oauth2 error appeared on Google workspace config](https://discuss.elastic.co/t/filebeat-auth-oauth2-error-appeared-on-google-workspace-config/344421)

<div class="topic-metadata">

**Author:** [@Umor](https://discuss.elastic.co/u/Umor)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 6:25pm UTC](https://discuss.elastic.co/t/filebeat-auth-oauth2-error-appeared-on-google-workspace-config/344421 "2023-10-04T18:25:50Z")

</div>

Greetings, I am using the Google Workspace module, and while running Filebeat the Google logs show and after a couple of minutes this error appeared {"log.level":"error","@timestamp":"2023-10-04T23:21:34.745+0500","log…

---

## [Send syslog to Filebeat server](https://discuss.elastic.co/t/send-syslog-to-filebeat-server/343987)

<div class="topic-metadata">

**Author:** [@msylvestre](https://discuss.elastic.co/u/msylvestre)\
**Replies:** 27\
**Last updated:** [October 4, 2023, 7:06pm UTC](https://discuss.elastic.co/t/send-syslog-to-filebeat-server/343987 "2023-10-04T19:06:22Z")

</div>

Greetings, I'm trying to send my Cisco Switches logs to my Filebeat server but for some reason it's not working. I can see that the Filebeat receives the logs, but it doesn't ship them to elastic afterwards. I tried usi…

---

## [ECK Filebeat processor add\_kubernetes\_metadata does not add fields with kube metadata](https://discuss.elastic.co/t/eck-filebeat-processor-add-kubernetes-metadata-does-not-add-fields-with-kube-metadata/344322)

<div class="topic-metadata">

**Author:** [@AlekseyD](https://discuss.elastic.co/u/AlekseyD)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 3:30pm UTC](https://discuss.elastic.co/t/eck-filebeat-processor-add-kubernetes-metadata-does-not-add-fields-with-kube-metadata/344322 "2023-10-04T15:30:30Z")

</div>

Kubernetes: 1.24.3 Kibana: 8.10.2 Elastic: 8.10.2 Filebeat: 8.10.2 Fresh install via ECK 2.9.0 The processor "add\_kubernetesmetadata" does not add kubernetes metadata fields to elasticsearch, the filebeat log does n…

---

## [It is not possible exclude specific mount point from metricbeat measurement](https://discuss.elastic.co/t/it-is-not-possible-exclude-specific-mount-point-from-metricbeat-measurement/344378)

<div class="topic-metadata">

**Author:** [@LadaDvorak](https://discuss.elastic.co/u/LadaDvorak)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 10:33am UTC](https://discuss.elastic.co/t/it-is-not-possible-exclude-specific-mount-point-from-metricbeat-measurement/344378 "2023-10-04T10:33:22Z")

</div>

I use metricbeat on linux server to detect free disk space on disk. My metricbeat.yml is set like this: processors: -drop\_event.when.regexp: system.filesystem.mount\_point: ‘^ / (sys | cgroup | proc | run | n…

---

## [Duplicated Google Workspace log entries by Filebeat](https://discuss.elastic.co/t/duplicated-google-workspace-log-entries-by-filebeat/344374)

<div class="topic-metadata">

**Author:** [@rlevitsky](https://discuss.elastic.co/u/rlevitsky)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 10:06am UTC](https://discuss.elastic.co/t/duplicated-google-workspace-log-entries-by-filebeat/344374 "2023-10-04T10:06:34Z")

</div>

Couple weeks ago, we’ve noticed that some Google Workspace logs received by Filebeat got duplicated. I’ve searched the internet for possible cause and find one similar issue here at Elastic Discuss, Google Workspace mod…

---

## [Customize filebeat connections](https://discuss.elastic.co/t/customize-filebeat-connections/344239)

<div class="topic-metadata">

**Author:** [@yvangarc](https://discuss.elastic.co/u/yvangarc)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 3:28pm UTC](https://discuss.elastic.co/t/customize-filebeat-connections/344239 "2023-10-03T15:28:51Z")

</div>

Hello, We have been given a logstash endpoint, which goes against 2 replicas running on an infra of k8s. What we see is that there is no control of the logstash pod to which we connect, and that many times our clients e…

---

## [No modules or inputs enabled - GCP vpcflow](https://discuss.elastic.co/t/no-modules-or-inputs-enabled-gcp-vpcflow/344246)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 7\
**Last updated:** [October 2, 2023, 9:21pm UTC](https://discuss.elastic.co/t/no-modules-or-inputs-enabled-gcp-vpcflow/344246 "2023-10-02T21:21:54Z")

</div>

hey there, I am really confused about the correct configuration of Filebeat v8.8.1 GCP module. I need to enable the vpcflow module, so I configured the gcp.yml file in this way: - module: gcp vpcflow: enabled: t…

---

## [Cannot parse "message" in pipeline with Grok -- illegal\_argument\_exception](https://discuss.elastic.co/t/cannot-parse-message-in-pipeline-with-grok-illegal-argument-exception/344188)

<div class="topic-metadata">

**Author:** [@bbarshaw](https://discuss.elastic.co/u/bbarshaw)\
**Replies:** 8\
**Last updated:** [October 1, 2023, 4:37pm UTC](https://discuss.elastic.co/t/cannot-parse-message-in-pipeline-with-grok-illegal-argument-exception/344188 "2023-10-01T16:37:00Z")

</div>

When attempting to Grok the "message" field in a filebeat pipeline from Kibana I am getting the following error: { "docs": \[ { "error": { "root\_cause": \[ { "type": "illegal\_argu…

---

## [Execbeats unable to run powershell](https://discuss.elastic.co/t/execbeats-unable-to-run-powershell/344160)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [September 30, 2023, 12:20pm UTC](https://discuss.elastic.co/t/execbeats-unable-to-run-powershell/344160 "2023-09-30T12:20:50Z")

</div>

I'm a bit stuck trying to get execbeat run a powershell and send the outcome to my elastic cluster. I'm afraid that the problem is the space that exist in windows paths (linux users must be laughing at me now) So my con…

---

## [Packetbeat's tls report has not bytes\_out field](https://discuss.elastic.co/t/packetbeats-tls-report-has-not-bytes-out-field/344145)

<div class="topic-metadata">

**Author:** [@hansc](https://discuss.elastic.co/u/hansc)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 3:28pm UTC](https://discuss.elastic.co/t/packetbeats-tls-report-has-not-bytes-out-field/344145 "2023-09-29T15:28:56Z")

</div>

I have packetbeat 8.10.2 installed in Debian 11. The protocols configurations are - type: http ports: \[80, 8080, 8000, 18083\] - type: tls ports: - 443 # HTTPS I am successfully see the bytes\_in and bytes\_o…

---

## [Metricbeat non-positive interval for NewTicker](https://discuss.elastic.co/t/metricbeat-non-positive-interval-for-newticker/344122)

<div class="topic-metadata">

**Author:** [@gergelyzsamboki-seon](https://discuss.elastic.co/u/gergelyzsamboki-seon)\
**Replies:** 1\
**Last updated:** [September 29, 2023, 10:28am UTC](https://discuss.elastic.co/t/metricbeat-non-positive-interval-for-newticker/344122 "2023-09-29T10:28:26Z")

</div>

hi. i'm trying to monitor a logstash cluster with metricbeat and logstash-xpack module. However after starting metricbeat, one datapoint is logged into elasticsearch, then an error is logged saying non-negative interval …

---

## [Winlogbeat stop and start services](https://discuss.elastic.co/t/winlogbeat-stop-and-start-services/343282)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 9:43pm UTC](https://discuss.elastic.co/t/winlogbeat-stop-and-start-services/343282 "2023-09-28T21:43:37Z")

</div>

Hi, We are having issues stoping and starting winlogbeat agent. It eventually timeouts . Process kill seems ok.Is there any known issue around this? We are just using Powershell scrip to stop and start the service. Sec…

---

## [Exiting: resource ‘metricbeat-7.17.12’ exists, but it is not an alias](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-17-12-exists-but-it-is-not-an-alias/344059)

<div class="topic-metadata">

**Author:** [@lliadan](https://discuss.elastic.co/u/lliadan)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 11:48am UTC](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-17-12-exists-but-it-is-not-an-alias/344059 "2023-09-28T11:48:13Z")

</div>

hello, i'm installing ELK in my company and i have some issues. My elk server is ready and i try to appare 4 linux with filebeat . I copy past the same folder for my 4 machines. 2 of them work but i have this error on…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=35)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=37)
