# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=361

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 362

---

## [How to Consolidate filebeat.prospector properties](https://discuss.elastic.co/t/how-to-consolidate-filebeat-prospector-properties/178689)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 0\
**Last updated:** [April 26, 2019, 4:19pm UTC](https://discuss.elastic.co/t/how-to-consolidate-filebeat-prospector-properties/178689 "2019-04-26T16:19:35Z")

</div>

Hello, below is a hypothetical prospector setup. Many parameters are unique to a given prospector but some are identical (for instance, the multiline params). Is there a way to configure the filebeat.yml to extract the s…

---

## [Configure filebeat to control how often logs are read and to ignore old logs](https://discuss.elastic.co/t/configure-filebeat-to-control-how-often-logs-are-read-and-to-ignore-old-logs/178332)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 1\
**Last updated:** [April 26, 2019, 3:55pm UTC](https://discuss.elastic.co/t/configure-filebeat-to-control-how-often-logs-are-read-and-to-ignore-old-logs/178332 "2019-04-26T15:55:58Z")

</div>

Hi, I have a setup in my filebeat.yml roughly as follows: filebeat.propectors: - type: log paths: - /tmp/log/typeA\*.log pipeline: "pipelineA" fields\_under\_root: true fields: logtype: TYPEA - type: log paths: …

---

## [Unable to create index based of message body key](https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420)

<div class="topic-metadata">

**Author:** [@ishu52](https://discuss.elastic.co/u/ishu52)\
**Replies:** 3\
**Last updated:** [April 26, 2019, 3:28pm UTC](https://discuss.elastic.co/t/unable-to-create-index-based-of-message-body-key/178420 "2019-04-26T15:28:47Z")

</div>

I wanted to create index based on the key 'request-id' which inside json body of the log message. I am trying to put filter on filebeat.config to get the logs based on request-id. I wanted to know how can i parse jso…

---

## [ELK 7 The request for this panel failed](https://discuss.elastic.co/t/elk-7-the-request-for-this-panel-failed/177136)

<div class="topic-metadata">

**Author:** [@teamg](https://discuss.elastic.co/u/teamg)\
**Replies:** 8\
**Last updated:** [April 26, 2019, 2:36pm UTC](https://discuss.elastic.co/t/elk-7-the-request-for-this-panel-failed/177136 "2019-04-26T14:36:59Z")

</div>

I have an ELK 6.7 and an ELK 7 both on single nodes. They're configured the same with metricbeat installed to monitor the nodes. When I look at the Host Overview Dashboard on ELK 7 I see: This does not occur on th…

---

## [Metricbeat 6.7.1 - can't import dashboards](https://discuss.elastic.co/t/metricbeat-6-7-1-cant-import-dashboards/178644)

<div class="topic-metadata">

**Author:** [@AndyT](https://discuss.elastic.co/u/AndyT)\
**Replies:** 0\
**Last updated:** [April 26, 2019, 12:29pm UTC](https://discuss.elastic.co/t/metricbeat-6-7-1-cant-import-dashboards/178644 "2019-04-26T12:29:57Z")

</div>

Fresh install of metricbeat on a box also running ES/Kibana, all at 6.7.1. When I run "metricbeat setup --dashboards" I get the following error; \> 2019-04-26T12:10:58.184Z INFO elasticsearch/client.go:164 …

---

## [FileBeat log rotation problem with Log4j](https://discuss.elastic.co/t/filebeat-log-rotation-problem-with-log4j/178445)

<div class="topic-metadata">

**Author:** [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Replies:** 1\
**Last updated:** [April 26, 2019, 12:00pm UTC](https://discuss.elastic.co/t/filebeat-log-rotation-problem-with-log4j/178445 "2019-04-26T12:00:48Z")

</div>

We are using 6.4.2 version of Elastic Stack. How we tested? We created a java class to generate log. LoggerMain.java package com.jcg.examples; import org.apache.log4j.Logger; public class LoggerMain { public stat…

---

## [There is no log in discover part of kibana](https://discuss.elastic.co/t/there-is-no-log-in-discover-part-of-kibana/177839)

<div class="topic-metadata">

**Author:** [@Mohammad\_hossein\_Taj](https://discuss.elastic.co/u/Mohammad_hossein_Taj)\
**Replies:** 5\
**Last updated:** [April 26, 2019, 11:19am UTC](https://discuss.elastic.co/t/there-is-no-log-in-discover-part-of-kibana/177839 "2019-04-26T11:19:18Z")

</div>

I'm trying to send logs from filebeat to logstash but after running logstash and filebeat I can't see any log . it's my steps: run elasticsearch and kibana add a .conf file named "beatsToElasticSearchPipeline.conf" to …

---

## [Filebeat starting error](https://discuss.elastic.co/t/filebeat-starting-error/178570)

<div class="topic-metadata">

**Author:** [@Amit\_Yadav](https://discuss.elastic.co/u/Amit_Yadav)\
**Replies:** 6\
**Last updated:** [April 26, 2019, 10:43am UTC](https://discuss.elastic.co/t/filebeat-starting-error/178570 "2019-04-26T10:43:07Z")

</div>

Hi please suggest me when i starting the filebeat i m getting the below error . filebeat.service - filebeat Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; vendor preset: disabled) Active: failed (R…

---

## [\[http-module\] Collecting Data from Webserver: Problem with JSON-Array](https://discuss.elastic.co/t/http-module-collecting-data-from-webserver-problem-with-json-array/178031)

<div class="topic-metadata">

**Author:** [@PeterPain](https://discuss.elastic.co/u/PeterPain)\
**Replies:** 2\
**Last updated:** [April 26, 2019, 10:01am UTC](https://discuss.elastic.co/t/http-module-collecting-data-from-webserver-problem-with-json-array/178031 "2019-04-26T10:01:33Z")

</div>

Hey there, so i want to collect live Data from a webservice. The webservice is for compressor-monitoring and offers an interface in JSON-Format. Demo: http://www.airleader.biz/demo/index.jsp Interface: http://www.ai…

---

## [System mount points data via metricbeat](https://discuss.elastic.co/t/system-mount-points-data-via-metricbeat/177808)

<div class="topic-metadata">

**Author:** [@cppatel](https://discuss.elastic.co/u/cppatel)\
**Replies:** 4\
**Last updated:** [April 26, 2019, 9:45am UTC](https://discuss.elastic.co/t/system-mount-points-data-via-metricbeat/177808 "2019-04-26T09:45:33Z")

</div>

I am unable to find /dev/shm data of my hosts on which I have installed metricbeat and enabled a below metricset: metricsets: - filesystem - fsstat processors: drop\_event.when.regexp: system.filesystem.mount\_point…

---

## [Docker swap usage](https://discuss.elastic.co/t/docker-swap-usage/178287)

<div class="topic-metadata">

**Author:** [@Masdi](https://discuss.elastic.co/u/Masdi)\
**Replies:** 2\
**Last updated:** [April 26, 2019, 9:35am UTC](https://discuss.elastic.co/t/docker-swap-usage/178287 "2019-04-26T09:35:29Z")

</div>

Hi, I can't found out the swap usage for the Docker module in the memory metricset, it seems that it is only supported for the System module, am I right? By the way, the memory metrics refer to the RAM of the container,…

---

## [Kafka output ERROR](https://discuss.elastic.co/t/kafka-output-error/178271)

<div class="topic-metadata">

**Author:** [@Masdi](https://discuss.elastic.co/u/Masdi)\
**Replies:** 2\
**Last updated:** [April 26, 2019, 9:30am UTC](https://discuss.elastic.co/t/kafka-output-error/178271 "2019-04-26T09:30:17Z")

</div>

Hello, I'm monitoring my docker containers and I'm sending the output to my kafka topic. It seems to work but I have the following log when I'm running it: metricbeat | 2019-04-24T14:15:48.555Z ERROR kafka/…

---

## [Correct output config via Central Management for Elastic Cloud](https://discuss.elastic.co/t/correct-output-config-via-central-management-for-elastic-cloud/178591)

<div class="topic-metadata">

**Author:** [@gruselglatz](https://discuss.elastic.co/u/gruselglatz)\
**Replies:** 2\
**Last updated:** [April 26, 2019, 9:14am UTC](https://discuss.elastic.co/t/correct-output-config-via-central-management-for-elastic-cloud/178591 "2019-04-26T09:14:57Z")

</div>

Hi, I try to use Central Management for my metricbeat to push messages into the Elastic Cloud. How can i Configure Metricbeat via Central Management to use the cloud.id and cloud.auth for the output. So I dont have to …

---

## [Drop\_event does NOT work](https://discuss.elastic.co/t/drop-event-does-not-work/178342)

<div class="topic-metadata">

**Author:** [@jasony](https://discuss.elastic.co/u/jasony)\
**Replies:** 1\
**Last updated:** [April 26, 2019, 9:11am UTC](https://discuss.elastic.co/t/drop-event-does-not-work/178342 "2019-04-26T09:11:40Z")

</div>

Hello I am trying to drop event when a specific kv is received. I executed metricbeat with using below yaml lines, but the drop\_event never worked as what i expected. can you please advise what i wrongly configured in …

---

## [Nats module error](https://discuss.elastic.co/t/nats-module-error/178230)

<div class="topic-metadata">

**Author:** [@Costi](https://discuss.elastic.co/u/Costi)\
**Replies:** 1\
**Last updated:** [April 26, 2019, 9:07am UTC](https://discuss.elastic.co/t/nats-module-error/178230 "2019-04-26T09:07:16Z")

</div>

Hi, I tried to use the new module, Nats but i encounter the following error: failure parsing Nats stats API response: invalid character '\<' looking for beginning of value. Does anyone encounter this error? Thanks!

---

## [After adding metricbeat to central management, windows service wont start](https://discuss.elastic.co/t/after-adding-metricbeat-to-central-management-windows-service-wont-start/178588)

<div class="topic-metadata">

**Author:** [@gruselglatz](https://discuss.elastic.co/u/gruselglatz)\
**Replies:** 1\
**Last updated:** [April 26, 2019, 9:04am UTC](https://discuss.elastic.co/t/after-adding-metricbeat-to-central-management-windows-service-wont-start/178588 "2019-04-26T09:04:11Z")

</div>

Hi! After I've added Metricbeat (7.0.0) to central management (elastic cloud 7.0), the windows service won't start anymore. I get this messages in Powershell with Admin rights: start-service metricbeat start-service :…

---

## [Full Stack](https://discuss.elastic.co/t/full-stack/178052)

<div class="topic-metadata">

**Author:** [@Masdi](https://discuss.elastic.co/u/Masdi)\
**Replies:** 1\
**Last updated:** [April 26, 2019, 9:03am UTC](https://discuss.elastic.co/t/full-stack/178052 "2019-04-26T09:03:20Z")

</div>

Hi, I was wondering why this full stack is not appropriate in production: https://www.elastic.co/fr/blog/a-full-stack-in-one-command I'd like to setup a K8s/Kafka/ELK cluster and monitor it with Metricbeat.

---

## [Kafka log errors](https://discuss.elastic.co/t/kafka-log-errors/178030)

<div class="topic-metadata">

**Author:** [@brucejiang2](https://discuss.elastic.co/u/brucejiang2)\
**Replies:** 1\
**Last updated:** [April 26, 2019, 8:58am UTC](https://discuss.elastic.co/t/kafka-log-errors/178030 "2019-04-26T08:58:48Z")

</div>

hosts: \["GZTXY-BIGDATA-PRD-REPT003:9092","GZTXY-BIGDATA-PRD-REPT004:9092","GZTXY-BIGDATA-PRD-REPT005:9092"\] log errors : 2019-04-23T19:31:20.179+0800 INFO kafka/log.go:53 Connected to broker at GZTXY-BIGDATA-PRD-REPT00…

---

## [Output.elasticsearch ， hosts: \["localhost:9200"\] Which go file is calling this address?](https://discuss.elastic.co/t/output-elasticsearch-hosts-localhost-9200-which-go-file-is-calling-this-address/176607)

<div class="topic-metadata">

**Author:** [@brucejiang2](https://discuss.elastic.co/u/brucejiang2)\
**Replies:** 3\
**Last updated:** [April 26, 2019, 8:58am UTC](https://discuss.elastic.co/t/output-elasticsearch-hosts-localhost-9200-which-go-file-is-calling-this-address/176607 "2019-04-26T08:58:31Z")

</div>

output.elasticsearch ， hosts: \["localhost:9200"\] Which go file is calling this address?

---

## [Kubernetes autodiscover hints annotations](https://discuss.elastic.co/t/kubernetes-autodiscover-hints-annotations/178501)

<div class="topic-metadata">

**Author:** [@Tousnick](https://discuss.elastic.co/u/Tousnick)\
**Replies:** 0\
**Last updated:** [April 25, 2019, 4:14pm UTC](https://discuss.elastic.co/t/kubernetes-autodiscover-hints-annotations/178501 "2019-04-25T16:14:07Z")

</div>

Hi, I'm using filebeat version 6.6.1 and I'm currently struggling to understand how https://www.elastic.co/guide/en/beats/filebeat/master/configuration-autodiscover-hints.html#\_mc is working. I have a pods with 3 conta…

---

## [K8s limited access scenario](https://discuss.elastic.co/t/k8s-limited-access-scenario/178385)

<div class="topic-metadata">

**Author:** [@Aitor\_Carrera\_Hernan](https://discuss.elastic.co/u/Aitor_Carrera_Hernan)\
**Replies:** 1\
**Last updated:** [April 25, 2019, 3:11pm UTC](https://discuss.elastic.co/t/k8s-limited-access-scenario/178385 "2019-04-25T15:11:07Z")

</div>

Hi Guys! i have an scenario that I have limited access to k8s, I only can act in a namespace so i think i cant install kube metrics or consume it. There is any documentatioin about this scenario because i want to beat th…

---

## [Can't get journal beat docker image working on CoreOS](https://discuss.elastic.co/t/cant-get-journal-beat-docker-image-working-on-coreos/177533)

<div class="topic-metadata">

**Author:** [@arlen](https://discuss.elastic.co/u/arlen)\
**Replies:** 1\
**Last updated:** [April 25, 2019, 10:21am UTC](https://discuss.elastic.co/t/cant-get-journal-beat-docker-image-working-on-coreos/177533 "2019-04-25T10:21:23Z")

</div>

We can start from the top, the doc page is inoperable. Example: Download this example configuration file as a starting point: curl -L -O https://raw.githubusercontent.com/elastic/beats/6.7/deploy/docker/journalbeat.do…

---

## [Heartbeat Alerting Question](https://discuss.elastic.co/t/heartbeat-alerting-question/178119)

<div class="topic-metadata">

**Author:** [@Kyle123](https://discuss.elastic.co/u/Kyle123)\
**Replies:** 4\
**Last updated:** [April 25, 2019, 1:17pm UTC](https://discuss.elastic.co/t/heartbeat-alerting-question/178119 "2019-04-25T13:17:21Z")

</div>

Hello, I am trying to find out a way to do alerting on downed hosts with watcher though I am running into an issue trying to figure out how to handle throttling the alerts. Once a given host is down I only want it to se…

---

## [Check open harvesters](https://discuss.elastic.co/t/check-open-harvesters/178462)

<div class="topic-metadata">

**Author:** [@Emanuel9](https://discuss.elastic.co/u/Emanuel9)\
**Replies:** 0\
**Last updated:** [April 25, 2019, 1:08pm UTC](https://discuss.elastic.co/t/check-open-harvesters/178462 "2019-04-25T13:08:18Z")

</div>

Hello, quick question: is there a way to see which log files are currently harvested by Filebeat? I am using Filebeat version 6.4.3 Thanks in advance! Manuel

---

## [Harvesting logs from many docker containers](https://discuss.elastic.co/t/harvesting-logs-from-many-docker-containers/178456)

<div class="topic-metadata">

**Author:** [@JJB](https://discuss.elastic.co/u/JJB)\
**Replies:** 0\
**Last updated:** [April 25, 2019, 12:36pm UTC](https://discuss.elastic.co/t/harvesting-logs-from-many-docker-containers/178456 "2019-04-25T12:36:40Z")

</div>

I think I might have gone down the wrong path here so just need a little guidance and some pros/cons to what I've done vs other ways of solving this problem. I have multiple docker containers each with a microservice in…

---

## [Fields in newly created filebeat module](https://discuss.elastic.co/t/fields-in-newly-created-filebeat-module/178447)

<div class="topic-metadata">

**Author:** [@Rolf\_Anderegg](https://discuss.elastic.co/u/Rolf_Anderegg)\
**Replies:** 0\
**Last updated:** [April 25, 2019, 11:57am UTC](https://discuss.elastic.co/t/fields-in-newly-created-filebeat-module/178447 "2019-04-25T11:57:08Z")

</div>

Im trying to create my own filebeat. I want to work with the direct elasticbeat ingest Pipeline (no Logstash in between). I downloaded the filebeat development package from github and programmed my filebeat module. I ma…

---

## [Netflow Cisco Switch](https://discuss.elastic.co/t/netflow-cisco-switch/178164)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 2\
**Last updated:** [April 24, 2019, 10:17pm UTC](https://discuss.elastic.co/t/netflow-cisco-switch/178164 "2019-04-24T22:17:33Z")

</div>

I'm trying to visualize netflow traffic in a table I set the metric to Sum of netflow.in\_bytes and the value for today is 181,130,876,462 I set the bucket to the following to show top 10 usage and it's fairly low comp…

---

## [Error and access logs are merged: Filebeat + Elasticsearch + php-fpm on Docker](https://discuss.elastic.co/t/error-and-access-logs-are-merged-filebeat-elasticsearch-php-fpm-on-docker/178163)

<div class="topic-metadata">

**Author:** [@remimikalsen](https://discuss.elastic.co/u/remimikalsen)\
**Replies:** 7\
**Last updated:** [April 25, 2019, 11:06am UTC](https://discuss.elastic.co/t/error-and-access-logs-are-merged-filebeat-elasticsearch-php-fpm-on-docker/178163 "2019-04-25T11:06:48Z")

</div>

I'm having an annoying problem with the way php-fpm behaves on Docker; it writes both error and access logs to stderr! This is done because php-fpm closes the stdout stream when it starts up, so it's impossible to write …

---

## [Can I add fields to json format data? (at filebeat)](https://discuss.elastic.co/t/can-i-add-fields-to-json-format-data-at-filebeat/178386)

<div class="topic-metadata">

**Author:** [@xodn0812](https://discuss.elastic.co/u/xodn0812)\
**Replies:** 1\
**Last updated:** [April 25, 2019, 11:02am UTC](https://discuss.elastic.co/t/can-i-add-fields-to-json-format-data-at-filebeat/178386 "2019-04-25T11:02:02Z")

</div>

I take json format data and send it to logstash from filebeat. {"key1":"val1","key2":"val2"} At this time, I want to set index information in filebeat and send it to logstash. How can I do it ??

---

## [Assigning Filebeat Logs To Different Pipelines and Appending a Log Type Field](https://discuss.elastic.co/t/assigning-filebeat-logs-to-different-pipelines-and-appending-a-log-type-field/177882)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 3\
**Last updated:** [April 25, 2019, 10:41am UTC](https://discuss.elastic.co/t/assigning-filebeat-logs-to-different-pipelines-and-appending-a-log-type-field/177882 "2019-04-25T10:41:24Z")

</div>

Hello, I have a use case where I would like to assign a different type of log input from filebeat to its own pipeline. The hope is that I can use filebeat to 1) assign the log message to the appropriate pipeline and 2) …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=360)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=362)
