# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=362

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 363

---

## [Filebeat can not get enviroment variable in docker](https://discuss.elastic.co/t/filebeat-can-not-get-enviroment-variable-in-docker/177829)

<div class="topic-metadata">

**Author:** [@ducminhle](https://discuss.elastic.co/u/ducminhle)\
**Replies:** 5\
**Last updated:** [April 25, 2019, 10:32am UTC](https://discuss.elastic.co/t/filebeat-can-not-get-enviroment-variable-in-docker/177829 "2019-04-25T10:32:35Z")

</div>

Hi All, Here is my config in filebeat.yml: fields: env: '${SPRING\_PROFILES\_ACTIVE}' Result in the container is: root@07acb280f9e5:/# echo ${SPRING\_PROFILES\_ACTIVE} perf15 But I got issue went container start fil…

---

## [File beat stop harvesting logs from few files suddenly , works fine after restart](https://discuss.elastic.co/t/file-beat-stop-harvesting-logs-from-few-files-suddenly-works-fine-after-restart/178286)

<div class="topic-metadata">

**Author:** [@praveen.gunupati](https://discuss.elastic.co/u/praveen.gunupati)\
**Replies:** 1\
**Last updated:** [April 25, 2019, 10:28am UTC](https://discuss.elastic.co/t/file-beat-stop-harvesting-logs-from-few-files-suddenly-works-fine-after-restart/178286 "2019-04-25T10:28:02Z")

</div>

We are using file beat version 5.6 to tail logs from all the docker containers of a machine and sending them to logstash. Here is the config we have for file beat. ''' filebeat.prospectors: input\_type: log paths: /…

---

## [Build issue with beats in project using go.mod](https://discuss.elastic.co/t/build-issue-with-beats-in-project-using-go-mod/178249)

<div class="topic-metadata">

**Author:** [@danielw93](https://discuss.elastic.co/u/danielw93)\
**Replies:** 1\
**Last updated:** [April 25, 2019, 10:09am UTC](https://discuss.elastic.co/t/build-issue-with-beats-in-project-using-go-mod/178249 "2019-04-25T10:09:31Z")

</div>

Hey all! I have a project depending on beats/libbeat and after changing my dependency management to go modules I can no longer build the project. It fails with the following message: unknown import path "github.com/el…

---

## [Metricbeat caching old IPs after DNS change](https://discuss.elastic.co/t/metricbeat-caching-old-ips-after-dns-change/178278)

<div class="topic-metadata">

**Author:** [@mcguacon](https://discuss.elastic.co/u/mcguacon)\
**Replies:** 1\
**Last updated:** [April 25, 2019, 10:02am UTC](https://discuss.elastic.co/t/metricbeat-caching-old-ips-after-dns-change/178278 "2019-04-25T10:02:13Z")

</div>

We are using Metricbeat to collect info on our RabbitMQ cluster. With a DNS change we cutover our cluster, but the monitoring itself kept reporting on the cluster with the old IP address. A restart of the monitoring up…

---

## [Heartbeat Docker field monitor](https://discuss.elastic.co/t/heartbeat-docker-field-monitor/174990)

<div class="topic-metadata">

**Author:** [@Pradnya](https://discuss.elastic.co/u/Pradnya)\
**Replies:** 2\
**Last updated:** [April 25, 2019, 8:05am UTC](https://discuss.elastic.co/t/heartbeat-docker-field-monitor/174990 "2019-04-25T08:05:25Z")

</div>

Can you provide any heartbeat docker field monitor yml file template or example.

---

## [How to see system host missing value on kibana dashboard](https://discuss.elastic.co/t/how-to-see-system-host-missing-value-on-kibana-dashboard/174474)

<div class="topic-metadata">

**Author:** [@Pradnya](https://discuss.elastic.co/u/Pradnya)\
**Replies:** 4\
**Last updated:** [April 25, 2019, 8:03am UTC](https://discuss.elastic.co/t/how-to-see-system-host-missing-value-on-kibana-dashboard/174474 "2019-04-25T08:03:07Z")

</div>

I am using metricbeat to get system metrics, currently having 20-30 system on kibana dashborad, but if my metribeat.service goes down on client machine obviously i wont get that system data on kibana. But how to identif…

---

## [ERR Failed to connect: Connection marked as failed because the onConnect callback failed: Error loading Elasticsearch template: could not load template: couldn't load template: couldn't load json. Error: 400 Bad Request](https://discuss.elastic.co/t/err-failed-to-connect-connection-marked-as-failed-because-the-onconnect-callback-failed-error-loading-elasticsearch-template-could-not-load-template-couldnt-load-template-couldnt-load-json-error-400-bad-request/177071)

<div class="topic-metadata">

**Author:** [@ishu52](https://discuss.elastic.co/u/ishu52)\
**Replies:** 11\
**Last updated:** [April 25, 2019, 7:01am UTC](https://discuss.elastic.co/t/err-failed-to-connect-connection-marked-as-failed-because-the-onconnect-callback-failed-error-loading-elasticsearch-template-could-not-load-template-couldnt-load-template-couldnt-load-json-error-400-bad-request/177071 "2019-04-25T07:01:26Z")

</div>

I get this error when I deploy filebeat. it was tested before with 6.6.1 version and was working fine but now the same yaml is giving this error.

---

## [Help to setup Metricbeat to push system/application metrics to ES cluster](https://discuss.elastic.co/t/help-to-setup-metricbeat-to-push-system-application-metrics-to-es-cluster/177194)

<div class="topic-metadata">

**Author:** [@Arunlal\_A](https://discuss.elastic.co/u/Arunlal_A)\
**Replies:** 2\
**Last updated:** [April 25, 2019, 5:49am UTC](https://discuss.elastic.co/t/help-to-setup-metricbeat-to-push-system-application-metrics-to-es-cluster/177194 "2019-04-25T05:49:48Z")

</div>

Hey guys, Need some help on implementing Metricbeat on Production environment. I have tested the working locally (ELK stack on Laptop) and it good for collecting System level and Application level metrics. Now we're pla…

---

## [Not able to set shard allocation filtering in metricbeat template](https://discuss.elastic.co/t/not-able-to-set-shard-allocation-filtering-in-metricbeat-template/177405)

<div class="topic-metadata">

**Author:** [@shshnk28](https://discuss.elastic.co/u/shshnk28)\
**Replies:** 5\
**Last updated:** [April 25, 2019, 4:05am UTC](https://discuss.elastic.co/t/not-able-to-set-shard-allocation-filtering-in-metricbeat-template/177405 "2019-04-25T04:05:33Z")

</div>

I am running a 8 node cluster (ES 6.7.0) of which one node I am using solely for the purpose of monitoring other 7 nodes. The node name for this lets say is monitoring. Now I am trying to monitor other nodes using x-pack…

---

## [Heartbeat 7.X no dashboards](https://discuss.elastic.co/t/heartbeat-7-x-no-dashboards/178296)

<div class="topic-metadata">

**Author:** [@HowardtheDuck](https://discuss.elastic.co/u/HowardtheDuck)\
**Replies:** 0\
**Last updated:** [April 24, 2019, 4:36pm UTC](https://discuss.elastic.co/t/heartbeat-7-x-no-dashboards/178296 "2019-04-24T16:36:53Z")

</div>

When installing the latest Heartbeat from the Elastic 7.0 repository and running heartbeat setup, dashboards do not load. When uninstalled, and pulled from the Elastic 6.0 repository dashboards do load. \[root@Email he…

---

## [Filebeat dies after trying to harvest 3 times (max\_retries)](https://discuss.elastic.co/t/filebeat-dies-after-trying-to-harvest-3-times-max-retries/178086)

<div class="topic-metadata">

**Author:** [@Arthur19](https://discuss.elastic.co/u/Arthur19)\
**Replies:** 5\
**Last updated:** [April 24, 2019, 3:05pm UTC](https://discuss.elastic.co/t/filebeat-dies-after-trying-to-harvest-3-times-max-retries/178086 "2019-04-24T15:05:58Z")

</div>

Hi, I have some problems when getting logs after log file haven't changed after 3 retries of harvesting, filebeat dies after this retries and I have to start manually to start harvesting. This is the log in Filebeat be…

---

## [Rename field with filebeat](https://discuss.elastic.co/t/rename-field-with-filebeat/178064)

<div class="topic-metadata">

**Author:** [@Raju\_Gupta](https://discuss.elastic.co/u/Raju_Gupta)\
**Replies:** 6\
**Last updated:** [April 24, 2019, 12:57pm UTC](https://discuss.elastic.co/t/rename-field-with-filebeat/178064 "2019-04-24T12:57:00Z")

</div>

I am trying to rename non json field with filebeat but json field also getting renamed. Not sure what i am missing. Can some budy help me? Here is my config. setup.template.settings: index.number\_of\_shards: 1 index…

---

## [Duplicated Kubernetes Events](https://discuss.elastic.co/t/duplicated-kubernetes-events/174166)

<div class="topic-metadata">

**Author:** [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Replies:** 3\
**Last updated:** [April 24, 2019, 9:51am UTC](https://discuss.elastic.co/t/duplicated-kubernetes-events/174166 "2019-04-24T09:51:07Z")

</div>

Hi, We're using the Kubernetes event metricset to ingest Kubernetes events into Elasticsearch, however, we've observed occurrences where the exact same event is being emitted to Elasticsearch multiple times, which can c…

---

## [Metricbeat with namespace secrets in Kubernetes](https://discuss.elastic.co/t/metricbeat-with-namespace-secrets-in-kubernetes/177159)

<div class="topic-metadata">

**Author:** [@soandosnc](https://discuss.elastic.co/u/soandosnc)\
**Replies:** 3\
**Last updated:** [April 24, 2019, 8:14am UTC](https://discuss.elastic.co/t/metricbeat-with-namespace-secrets-in-kubernetes/177159 "2019-04-24T08:14:38Z")

</div>

I have metricbeat up and running on kubernetes collecting k8s metrics, as well as node metrics, forwarding to ES, deployed as a deamonset via helm chart. I want to use some of the other modules (rabbitmq, redis, etc), b…

---

## [Metricbeat Prometheus module not support match query](https://discuss.elastic.co/t/metricbeat-prometheus-module-not-support-match-query/177571)

<div class="topic-metadata">

**Author:** [@Jehutywong](https://discuss.elastic.co/u/Jehutywong)\
**Replies:** 4\
**Last updated:** [April 24, 2019, 1:43am UTC](https://discuss.elastic.co/t/metricbeat-prometheus-module-not-support-match-query/177571 "2019-04-24T01:43:02Z")

</div>

Metricbeat: 7.0.0 config: metricbeat.modules: module: prometheus period: 10s hosts: \["\<prometheus\_url\>"\] metrics\_path: '/federate' query: 'match\[\]': '{name!=""}' namespace: example This will result in: "error…

---

## [Send json message from filebeat to logstash (multi-line)](https://discuss.elastic.co/t/send-json-message-from-filebeat-to-logstash-multi-line/178042)

<div class="topic-metadata">

**Author:** [@xodn0812](https://discuss.elastic.co/u/xodn0812)\
**Replies:** 1\
**Last updated:** [April 23, 2019, 9:45pm UTC](https://discuss.elastic.co/t/send-json-message-from-filebeat-to-logstash-multi-line/178042 "2019-04-23T21:45:03Z")

</div>

I would like to send json-formatted messages to logstash via filebeat. i can filter each key value in json by writing the following in filebeat: json.keys\_under\_root: true json.add\_error\_key: true json.message\_ke…

---

## [Does central beat management support API to enroll the beats?](https://discuss.elastic.co/t/does-central-beat-management-support-api-to-enroll-the-beats/178017)

<div class="topic-metadata">

**Author:** [@subhash.parise](https://discuss.elastic.co/u/subhash.parise)\
**Replies:** 1\
**Last updated:** [April 23, 2019, 9:36pm UTC](https://discuss.elastic.co/t/does-central-beat-management-support-api-to-enroll-the-beats/178017 "2019-04-23T21:36:03Z")

</div>

Dear community members, we are using central beats management in kibana-ui to enroll the beats. the same thing we need to achieve by ansibleplay book. do we have api support to enroll the beats ? i haven't found much…

---

## [Use Metricbeat to monitor single node ELK?](https://discuss.elastic.co/t/use-metricbeat-to-monitor-single-node-elk/173994)

<div class="topic-metadata">

**Author:** [@teamg](https://discuss.elastic.co/u/teamg)\
**Replies:** 5\
**Last updated:** [April 23, 2019, 6:54pm UTC](https://discuss.elastic.co/t/use-metricbeat-to-monitor-single-node-elk/173994 "2019-04-23T18:54:55Z")

</div>

I have a single node ELK and would like to use Metricbeat to monitor resource utilization (memory, cput, etc). Are there any drawbacks to installing Metricbeat on my single ELK node?

---

## [Append Field Value to Each Log Message processed by Filebeat](https://discuss.elastic.co/t/append-field-value-to-each-log-message-processed-by-filebeat/177895)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 1\
**Last updated:** [April 23, 2019, 4:25pm UTC](https://discuss.elastic.co/t/append-field-value-to-each-log-message-processed-by-filebeat/177895 "2019-04-23T16:25:15Z")

</div>

Hello, I have a use case where I would like to append a field to each log message that is processed by filebeat. The value would be based upon the type of log read by filebeat. For instance, lets say I have 3 log types…

---

## [\[Metricbeat System\] Overview ECS Dashboard version 7](https://discuss.elastic.co/t/metricbeat-system-overview-ecs-dashboard-version-7/177527)

<div class="topic-metadata">

**Author:** [@Reedler](https://discuss.elastic.co/u/Reedler)\
**Replies:** 4\
**Last updated:** [April 23, 2019, 4:21pm UTC](https://discuss.elastic.co/t/metricbeat-system-overview-ecs-dashboard-version-7/177527 "2019-04-23T16:21:31Z")

</div>

Newly upgraded cluster to v7 as of today. All metricbeat agents are upgraded to 7. I've cleared out all metricbeat indices as this is a dev cluster. I've deleted all dashboard and and visualizations for metricbeat in th…

---

## [How to install metricbeat on multiple servers once](https://discuss.elastic.co/t/how-to-install-metricbeat-on-multiple-servers-once/177937)

<div class="topic-metadata">

**Author:** [@kamal1](https://discuss.elastic.co/u/kamal1)\
**Replies:** 2\
**Last updated:** [April 23, 2019, 3:25pm UTC](https://discuss.elastic.co/t/how-to-install-metricbeat-on-multiple-servers-once/177937 "2019-04-23T15:25:15Z")

</div>

I have installed beat agents on single machine and I want to get them installed (winlogbeat, metricbeat and filebeat) on 5 more machines in my environment. I don't want to login to each and every machine and install them…

---

## [Metricbeat kubernetes module error in elasticsearch](https://discuss.elastic.co/t/metricbeat-kubernetes-module-error-in-elasticsearch/177237)

<div class="topic-metadata">

**Author:** [@Ji\_Ho\_Choi](https://discuss.elastic.co/u/Ji_Ho_Choi)\
**Replies:** 2\
**Last updated:** [April 23, 2019, 1:32pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module-error-in-elasticsearch/177237 "2019-04-23T13:32:12Z")

</div>

My beats is sending logs ok right now but elasticsearch is keep complaining about same error over and over. Pasted below. I have metricbeat and filebeat applied as daemonset. What is elasticsearch complaining about? th…

---

## [Filebeat 7.0.0 rename index](https://discuss.elastic.co/t/filebeat-7-0-0-rename-index/177435)

<div class="topic-metadata">

**Author:** [@nimda](https://discuss.elastic.co/u/nimda)\
**Replies:** 2\
**Last updated:** [April 23, 2019, 12:41pm UTC](https://discuss.elastic.co/t/filebeat-7-0-0-rename-index/177435 "2019-04-23T12:41:08Z")

</div>

Hello everyone, I've tested lately filebeat 7.0.0. but coudn't get it to work with my elasticsearch-cluster (also version 7.0.0). Whenever I used the appropiate way to change the index name: https://www.elastic.co/guid…

---

## [Errors while using audit module of filebeat](https://discuss.elastic.co/t/errors-while-using-audit-module-of-filebeat/178010)

<div class="topic-metadata">

**Author:** [@sakharovb2b](https://discuss.elastic.co/u/sakharovb2b)\
**Replies:** 0\
**Last updated:** [April 23, 2019, 10:51am UTC](https://discuss.elastic.co/t/errors-while-using-audit-module-of-filebeat/178010 "2019-04-23T10:51:15Z")

</div>

There are several problems in audit pipeline that made this module unusable for our filebeat instance. Our audit log line looks like this (we're using ubuntu 16.04 with it's reposiory auditd) node=test-01 type=EOE ms…

---

## [\[Beginner\] Collecting Live-Data from Webserver](https://discuss.elastic.co/t/beginner-collecting-live-data-from-webserver/176918)

<div class="topic-metadata">

**Author:** [@PeterPain](https://discuss.elastic.co/u/PeterPain)\
**Replies:** 3\
**Last updated:** [April 23, 2019, 11:46am UTC](https://discuss.elastic.co/t/beginner-collecting-live-data-from-webserver/176918 "2019-04-23T11:46:38Z")

</div>

Hey there, im just getting started with Elasticsearch and want to get data from a Webserver The Webserver offeres an interface to get the data in JSON format. Here are links for the website: http://www.airleader.biz/a…

---

## [Metricbeat bulk item insert failed and elasticsearch has lots of adding template \* for index patterns \* logs](https://discuss.elastic.co/t/metricbeat-bulk-item-insert-failed-and-elasticsearch-has-lots-of-adding-template-for-index-patterns-logs/177076)

<div class="topic-metadata">

**Author:** [@Jun\_Zhang](https://discuss.elastic.co/u/Jun_Zhang)\
**Replies:** 1\
**Last updated:** [April 23, 2019, 11:26am UTC](https://discuss.elastic.co/t/metricbeat-bulk-item-insert-failed-and-elasticsearch-has-lots-of-adding-template-for-index-patterns-logs/177076 "2019-04-23T11:26:34Z")

</div>

metricbeat v7.0 logs: 2019-04-16T19:11:48.356+0800 DEBUG \[elasticsearch\] elasticsearch/client.go:338 PublishEvents: 51 events have been published to elasticsearch in 6.695631ms. 2019-04-16T19:11:48.356+0800 …

---

## [Beats, Kafka output, Azure Event Hubs](https://discuss.elastic.co/t/beats-kafka-output-azure-event-hubs/178020)

<div class="topic-metadata">

**Author:** [@Rob3](https://discuss.elastic.co/u/Rob3)\
**Replies:** 0\
**Last updated:** [April 23, 2019, 11:24am UTC](https://discuss.elastic.co/t/beats-kafka-output-azure-event-hubs/178020 "2019-04-23T11:24:59Z")

</div>

Auditbeat and Filebeat seems to be unable to create new topics ("Event Hubs") in an Azure Event Hub Namespace. Using versions 7.0.0. Azure Event Hub Namespace Standard SKU created, with the Kafka interface enabled. Us…

---

## [How to install metricbeat on inside vmware esxi server](https://discuss.elastic.co/t/how-to-install-metricbeat-on-inside-vmware-esxi-server/177940)

<div class="topic-metadata">

**Author:** [@kamal1](https://discuss.elastic.co/u/kamal1)\
**Replies:** 1\
**Last updated:** [April 23, 2019, 11:20am UTC](https://discuss.elastic.co/t/how-to-install-metricbeat-on-inside-vmware-esxi-server/177940 "2019-04-23T11:20:53Z")

</div>

how to install metricbeat on inside vmware esxi server.

---

## [How to get only cpu specific data only from metricbeat](https://discuss.elastic.co/t/how-to-get-only-cpu-specific-data-only-from-metricbeat/177939)

<div class="topic-metadata">

**Author:** [@kamal1](https://discuss.elastic.co/u/kamal1)\
**Replies:** 1\
**Last updated:** [April 23, 2019, 11:19am UTC](https://discuss.elastic.co/t/how-to-get-only-cpu-specific-data-only-from-metricbeat/177939 "2019-04-23T11:19:41Z")

</div>

how to get only cpu specific data only from metricbeat

---

## [Metrics beat and fluentd](https://discuss.elastic.co/t/metrics-beat-and-fluentd/177659)

<div class="topic-metadata">

**Author:** [@Phillip\_Groven](https://discuss.elastic.co/u/Phillip_Groven)\
**Replies:** 1\
**Last updated:** [April 23, 2019, 11:03am UTC](https://discuss.elastic.co/t/metrics-beat-and-fluentd/177659 "2019-04-23T11:03:34Z")

</div>

Can Metricbeat be send into fluentd? If it can how would you configure it?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=361)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=363)
