# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=363

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 364

---

## [Field named "agent", introduced in 7.0.0 is in conflict with our fields](https://discuss.elastic.co/t/field-named-agent-introduced-in-7-0-0-is-in-conflict-with-our-fields/177862)

<div class="topic-metadata">

**Author:** [@jesusgn90](https://discuss.elastic.co/u/jesusgn90)\
**Replies:** 2\
**Last updated:** [April 23, 2019, 10:30am UTC](https://discuss.elastic.co/t/field-named-agent-introduced-in-7-0-0-is-in-conflict-with-our-fields/177862 "2019-04-23T10:30:16Z")

</div>

Hi guys, adapting our integration (Wazuh) for Elastic 7.0 I've noticed that Filebeat is using a field named "agent" which is in conflict with our field "agent". Our events have agent.id, agent.name along other agent.\* fi…

---

## [No data displaying in dashboard - \[Filebeat System\] SSH login attempts ECS](https://discuss.elastic.co/t/no-data-displaying-in-dashboard-filebeat-system-ssh-login-attempts-ecs/177947)

<div class="topic-metadata">

**Author:** [@bradfordaemorton](https://discuss.elastic.co/u/bradfordaemorton)\
**Replies:** 1\
**Last updated:** [April 23, 2019, 9:51am UTC](https://discuss.elastic.co/t/no-data-displaying-in-dashboard-filebeat-system-ssh-login-attempts-ecs/177947 "2019-04-23T09:51:50Z")

</div>

I have recently rebuilt my elasticsearch and kibana infrastructure to 7.0 and reinstalled filebeat and metricbeat collectors to 7.0. I currently collect access and error logs for apache2 (I have the module enabled) as w…

---

## [I get the error during setup of the filebeat](https://discuss.elastic.co/t/i-get-the-error-during-setup-of-the-filebeat/177871)

<div class="topic-metadata">

**Author:** [@Burak\_Cayir](https://discuss.elastic.co/u/Burak_Cayir)\
**Replies:** 3\
**Last updated:** [April 23, 2019, 9:36am UTC](https://discuss.elastic.co/t/i-get-the-error-during-setup-of-the-filebeat/177871 "2019-04-23T09:36:22Z")

</div>

Hello , I installed filebeat 7.0.0 in my ubuntu vm. I did all necessary config. But , when I enter "sudo filebeat setup" command in terminal I get this output : Index setup complete. Loading dashboards (Kibana must be …

---

## [Can't see the output on Kibana webpage](https://discuss.elastic.co/t/cant-see-the-output-on-kibana-webpage/177485)

<div class="topic-metadata">

**Author:** [@Ayushi47](https://discuss.elastic.co/u/Ayushi47)\
**Replies:** 2\
**Last updated:** [April 23, 2019, 8:51am UTC](https://discuss.elastic.co/t/cant-see-the-output-on-kibana-webpage/177485 "2019-04-23T08:51:08Z")

</div>

I have installed filebeat on X server and logstash on Y server. I am trying to send data from X to Y. How do I verify why I can't see on the webpage.

---

## [How can Filebeat send match rules to Logstash](https://discuss.elastic.co/t/how-can-filebeat-send-match-rules-to-logstash/176814)

<div class="topic-metadata">

**Author:** [@Gary.Pan](https://discuss.elastic.co/u/Gary.Pan)\
**Replies:** 2\
**Last updated:** [April 23, 2019, 7:45am UTC](https://discuss.elastic.co/t/how-can-filebeat-send-match-rules-to-logstash/176814 "2019-04-23T07:45:33Z")

</div>

I want to let Logstash'gork filter use the match rules which Filebeat give Here is my Filebeat config: filebeat.inputs: - type: log enabled: true paths: - /root/Log-test/test.log fields: "@metadata": …

---

## [Heartbeat check.response.code multiple values](https://discuss.elastic.co/t/heartbeat-check-response-code-multiple-values/177267)

<div class="topic-metadata">

**Author:** [@Jugsofbeer](https://discuss.elastic.co/u/Jugsofbeer)\
**Replies:** 2\
**Last updated:** [April 22, 2019, 10:39pm UTC](https://discuss.elastic.co/t/heartbeat-check-response-code-multiple-values/177267 "2019-04-22T22:39:26Z")

</div>

Hi, We are using heartbeat v6.7.1 on a windows server. We have a heartbeat request to a login page; which will depending on its cluster state provide a different response code. if the cluster state for the url is prim…

---

## [Heartbeat error DEBUG \[tcp\] tcp/task.go:58 check failed with: EOF](https://discuss.elastic.co/t/heartbeat-error-debug-tcp-tcp-task-go-58-check-failed-with-eof/174469)

<div class="topic-metadata">

**Author:** [@tarj](https://discuss.elastic.co/u/tarj)\
**Replies:** 3\
**Last updated:** [April 22, 2019, 5:35pm UTC](https://discuss.elastic.co/t/heartbeat-error-debug-tcp-tcp-task-go-58-check-failed-with-eof/174469 "2019-04-22T17:35:36Z")

</div>

Hello, I am trying to do heartbeat TCP check to my oracle database port. The database is up, but heartbeat is reporting is as down. Debug log is showing the below error: 2019-03-29T12:46:07.748+0800 DEBUG \[tcp\] …

---

## [Monitor.id duplicated on service restart](https://discuss.elastic.co/t/monitor-id-duplicated-on-service-restart/176974)

<div class="topic-metadata">

**Author:** [@RayS](https://discuss.elastic.co/u/RayS)\
**Replies:** 1\
**Last updated:** [April 22, 2019, 5:10pm UTC](https://discuss.elastic.co/t/monitor-id-duplicated-on-service-restart/176974 "2019-04-22T17:10:32Z")

</div>

Running version 7 of heartbeat. If I restart the heartbeat-elastic server I end up with duplicate monitor.id entries on the Heartbeat HTTP Monitoring Dashboard. Two questions: Is this normal and if so what's the logi…

---

## [Multiline Java stack trace...yes another one](https://discuss.elastic.co/t/multiline-java-stack-trace-yes-another-one/177115)

<div class="topic-metadata">

**Author:** [@hueyg](https://discuss.elastic.co/u/hueyg)\
**Replies:** 8\
**Last updated:** [April 22, 2019, 3:36pm UTC](https://discuss.elastic.co/t/multiline-java-stack-trace-yes-another-one/177115 "2019-04-22T15:36:17Z")

</div>

I have combed through the similar questions but the few with solutions have not applied to my case. This log file contains both single line and multiple lines. All lines start with the same label. My grok expression o…

---

## [Filebeat Empty Monitoring Metrics](https://discuss.elastic.co/t/filebeat-empty-monitoring-metrics/176766)

<div class="topic-metadata">

**Author:** [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Replies:** 4\
**Last updated:** [April 22, 2019, 11:36am UTC](https://discuss.elastic.co/t/filebeat-empty-monitoring-metrics/176766 "2019-04-22T11:36:03Z")

</div>

Hi, When monitoring Filebeat 6.7.1, we see some empty metrics: Throughput (/s), Fail Rates (/s), Output Errors (/s) All of these are at 0. Our output is Kafka

---

## [Filebeat to send application logs to elastic search](https://discuss.elastic.co/t/filebeat-to-send-application-logs-to-elastic-search/176894)

<div class="topic-metadata">

**Author:** [@Neeraj\_Jain](https://discuss.elastic.co/u/Neeraj_Jain)\
**Replies:** 5\
**Last updated:** [April 22, 2019, 6:58am UTC](https://discuss.elastic.co/t/filebeat-to-send-application-logs-to-elastic-search/176894 "2019-04-22T06:58:56Z")

</div>

Hi, I want to use filebeat to ship my application logs to elastic search running in a log server. My application generates a log file in a particular folder. whenever the log file reaches a configured size, then a new l…

---

## [Filebeat and Metricbeats setup fails with Elasticsearch and Kibana 7.0 -Failed to import dashboard: Failed to load directory](https://discuss.elastic.co/t/filebeat-and-metricbeats-setup-fails-with-elasticsearch-and-kibana-7-0-failed-to-import-dashboard-failed-to-load-directory/177068)

<div class="topic-metadata">

**Author:** [@bradfordaemorton](https://discuss.elastic.co/u/bradfordaemorton)\
**Replies:** 2\
**Last updated:** [April 22, 2019, 2:44am UTC](https://discuss.elastic.co/t/filebeat-and-metricbeats-setup-fails-with-elasticsearch-and-kibana-7-0-failed-to-import-dashboard-failed-to-load-directory/177068 "2019-04-22T02:44:11Z")

</div>

Running sudo metricbeat setup and sudo filebeat setup and get the following error belows. root@ubuntu-s-1vcpu-2gb-sfo2-01:/etc/metricbeat/modules.d# sudo metricbeat setup Index setup complete. Loading dashboards (Kiba…

---

## [Discovery problem](https://discuss.elastic.co/t/discovery-problem/174958)

<div class="topic-metadata">

**Author:** [@jof300](https://discuss.elastic.co/u/jof300)\
**Replies:** 3\
**Last updated:** [April 21, 2019, 8:42pm UTC](https://discuss.elastic.co/t/discovery-problem/174958 "2019-04-21T20:42:36Z")

</div>

Hi, I am trying to implement a sample example with autodiscover and modules I created 2 docker : nginx filebeat I want filebeat container to get logs from nginx container with autodiscover and use nginx module to pa…

---

## [Filebeat pipelines](https://discuss.elastic.co/t/filebeat-pipelines/177238)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 6\
**Last updated:** [April 21, 2019, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238 "2019-04-21T15:56:33Z")

</div>

Hi, Is it possible to customise the naming of pipelines used by filebeat. Is there any example config? Regards, D

---

## [Filebeat Modules And Kubernetes](https://discuss.elastic.co/t/filebeat-modules-and-kubernetes/177731)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 0\
**Last updated:** [April 20, 2019, 8:42pm UTC](https://discuss.elastic.co/t/filebeat-modules-and-kubernetes/177731 "2019-04-20T20:42:12Z")

</div>

Hi, In the situation where kubernetes pods are logging to stdout (container logs on the node) is it still possible to make use of modules and associated pipelines/dashboards? If not, how should users work around it? R…

---

## [How to enable dashboards for metricbeat in kubernetes daemonset environment](https://discuss.elastic.co/t/how-to-enable-dashboards-for-metricbeat-in-kubernetes-daemonset-environment/177216)

<div class="topic-metadata">

**Author:** [@Ji\_Ho\_Choi](https://discuss.elastic.co/u/Ji_Ho_Choi)\
**Replies:** 1\
**Last updated:** [April 19, 2019, 9:43pm UTC](https://discuss.elastic.co/t/how-to-enable-dashboards-for-metricbeat-in-kubernetes-daemonset-environment/177216 "2019-04-19T21:43:58Z")

</div>

I currently have a default daemonset settings from elastic stack like below It's what I have copied off from https://github.com/elastic/beats/tree/master/deploy/kubernetes/metricbeat I would like to import default dash…

---

## [Metricbeat / windows - perfmon counter](https://discuss.elastic.co/t/metricbeat-windows-perfmon-counter/175251)

<div class="topic-metadata">

**Author:** [@Reb](https://discuss.elastic.co/u/Reb)\
**Replies:** 1\
**Last updated:** [April 19, 2019, 8:47pm UTC](https://discuss.elastic.co/t/metricbeat-windows-perfmon-counter/175251 "2019-04-19T20:47:31Z")

</div>

hi , for my windows module (metricset: perfmon), do I have to fill in the counter in the metricbeat.yml Because I would like to do that in the configuration of the windows module, but not in the metricbeat.yml. m…

---

## [REST APIs for Beats](https://discuss.elastic.co/t/rest-apis-for-beats/177618)

<div class="topic-metadata">

**Author:** [@alexcarrega](https://discuss.elastic.co/u/alexcarrega)\
**Replies:** 1\
**Last updated:** [April 19, 2019, 2:27pm UTC](https://discuss.elastic.co/t/rest-apis-for-beats/177618 "2019-04-19T14:27:30Z")

</div>

Hi, is it possible to dynamic configure the Beats with, for example, a REST Interface (or something similar)? Thanks

---

## [Multiple Outputs in FileBeat](https://discuss.elastic.co/t/multiple-outputs-in-filebeat/177595)

<div class="topic-metadata">

**Author:** [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Replies:** 1\
**Last updated:** [April 19, 2019, 2:26pm UTC](https://discuss.elastic.co/t/multiple-outputs-in-filebeat/177595 "2019-04-19T14:26:09Z")

</div>

Hello, I have windows server and there are FileBeat and WinLogBeat installed. Both are pointed to Logstash. Everything works as expected. But now iu would like to use IIS module for filebeat. Then my problem is that IIS…

---

## [Filebeat not reading the already processed log file again](https://discuss.elastic.co/t/filebeat-not-reading-the-already-processed-log-file-again/177171)

<div class="topic-metadata">

**Author:** [@SManorathna](https://discuss.elastic.co/u/SManorathna)\
**Replies:** 2\
**Last updated:** [April 19, 2019, 4:47am UTC](https://discuss.elastic.co/t/filebeat-not-reading-the-already-processed-log-file-again/177171 "2019-04-19T04:47:28Z")

</div>

Hi, I am reading a .log file using filebeat and I need the data to be output to the elasticsearch. This is my filebeat configuration #=========================== Filebeat inputs ============================= filebeat.…

---

## [How to change elasticsearch output index with default template](https://discuss.elastic.co/t/how-to-change-elasticsearch-output-index-with-default-template/177518)

<div class="topic-metadata">

**Author:** [@geforcesong](https://discuss.elastic.co/u/geforcesong)\
**Replies:** 2\
**Last updated:** [April 18, 2019, 8:57pm UTC](https://discuss.elastic.co/t/how-to-change-elasticsearch-output-index-with-default-template/177518 "2019-04-18T20:57:19Z")

</div>

Hello, checked the documents, i am still not able to update elasticsearch output index. i want to add a log type on it. But it keeps giving me the default one. Here is my conf, filebeat.inputs: - type: log # ch…

---

## [InitPaths is not threadsafe](https://discuss.elastic.co/t/initpaths-is-not-threadsafe/177519)

<div class="topic-metadata">

**Author:** [@asanderson15](https://discuss.elastic.co/u/asanderson15)\
**Replies:** 2\
**Last updated:** [April 18, 2019, 6:12pm UTC](https://discuss.elastic.co/t/initpaths-is-not-threadsafe/177519 "2019-04-18T18:12:58Z")

</div>

There is a race when using InitPaths during initial beat configuration if you initialize more than a single beat in parallel. Calling InitPaths calls Path.InitPaths (code), where Path is a shared global pointer. That me…

---

## [Filebeat syslog input on windows](https://discuss.elastic.co/t/filebeat-syslog-input-on-windows/177523)

<div class="topic-metadata">

**Author:** [@jmcgee](https://discuss.elastic.co/u/jmcgee)\
**Replies:** 0\
**Last updated:** [April 18, 2019, 6:01pm UTC](https://discuss.elastic.co/t/filebeat-syslog-input-on-windows/177523 "2019-04-18T18:01:47Z")

</div>

Has anyone successfully used the syslog input on windows? I have tried several incantations of configuration so far, and I get no results. Historically we have used nxlog to take syslog input and spool to a file on a wi…

---

## [Metricbeat 7.0.0 on Windows x64 Elasticsearch template setup error](https://discuss.elastic.co/t/metricbeat-7-0-0-on-windows-x64-elasticsearch-template-setup-error/177313)

<div class="topic-metadata">

**Author:** [@Chernomazov](https://discuss.elastic.co/u/Chernomazov)\
**Replies:** 3\
**Last updated:** [April 18, 2019, 5:31pm UTC](https://discuss.elastic.co/t/metricbeat-7-0-0-on-windows-x64-elasticsearch-template-setup-error/177313 "2019-04-18T17:31:50Z")

</div>

Metricbeat: 7.0.0 ELK: 7.0.0 OS: MS Windows Server 2016 Core I call on the Elasticsearch host metricbeat setup --template -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=\["localhost:9200"\]' and I g…

---

## [6.7.1: Regarding Custom Fields](https://discuss.elastic.co/t/6-7-1-regarding-custom-fields/177473)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 2\
**Last updated:** [April 18, 2019, 3:47pm UTC](https://discuss.elastic.co/t/6-7-1-regarding-custom-fields/177473 "2019-04-18T15:47:53Z")

</div>

Hi, I am using filebeat as follows: inputs disabled modules enabled output to logstash In that situation how can I add custom fields under root to all outgoing traffic? i see a processor for it in 7.0 but it is uncle…

---

## [Filebeat failed to start after adding add\_host\_metadata](https://discuss.elastic.co/t/filebeat-failed-to-start-after-adding-add-host-metadata/177467)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 1\
**Last updated:** [April 18, 2019, 3:43pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-start-after-adding-add-host-metadata/177467 "2019-04-18T15:43:14Z")

</div>

Hi All, We are trying to send logs using filebeat and we added the add\_host\_metadata processor to our beats yml files. But it not working on Windows Server 2016 64-bit servers and below is the system details, Any i…

---

## [Filebeat 7 Apache Module Error Events Broken](https://discuss.elastic.co/t/filebeat-7-apache-module-error-events-broken/177489)

<div class="topic-metadata">

**Author:** [@Ryne\_Keel](https://discuss.elastic.co/u/Ryne_Keel)\
**Replies:** 1\
**Last updated:** [April 18, 2019, 2:38pm UTC](https://discuss.elastic.co/t/filebeat-7-apache-module-error-events-broken/177489 "2019-04-18T14:38:52Z")

</div>

I finally got the filebeat error module for apache to parse my error logs. It was a combination of looking through the GET \_ingest/processor/grok In dev tools, and fairly heavily modifying the apache error module confi…

---

## [Why filebeat create so many fields in the index of elasticsearch](https://discuss.elastic.co/t/why-filebeat-create-so-many-fields-in-the-index-of-elasticsearch/177429)

<div class="topic-metadata">

**Author:** [@99da02c8d5a5a0c0474d](https://discuss.elastic.co/u/99da02c8d5a5a0c0474d)\
**Replies:** 1\
**Last updated:** [April 18, 2019, 12:16pm UTC](https://discuss.elastic.co/t/why-filebeat-create-so-many-fields-in-the-index-of-elasticsearch/177429 "2019-04-18T12:16:59Z")

</div>

Hi,all.I'm a newbie for ELK. We use filebeat to collect nginx logs and output to elasticsearch with the default template,but when I checking the kibana's index on the dashboard,I saw the index contains 1148 fields,why fi…

---

## [Filebeat-unable-to-send-logs-to-kafka](https://discuss.elastic.co/t/filebeat-unable-to-send-logs-to-kafka/177272)

<div class="topic-metadata">

**Author:** [@bomba](https://discuss.elastic.co/u/bomba)\
**Replies:** 2\
**Last updated:** [April 18, 2019, 7:40am UTC](https://discuss.elastic.co/t/filebeat-unable-to-send-logs-to-kafka/177272 "2019-04-18T07:40:08Z")

</div>

File Beat is unable to send logs from a particular folder, This is the application logs folder. Things that have been tried : Created a new topic in kafka to retest the settings. Checked for file permission for the fo…

---

## [Change the index name used in elasticsearch module](https://discuss.elastic.co/t/change-the-index-name-used-in-elasticsearch-module/176700)

<div class="topic-metadata">

**Author:** [@mtoumi](https://discuss.elastic.co/u/mtoumi)\
**Replies:** 4\
**Last updated:** [April 18, 2019, 3:58am UTC](https://discuss.elastic.co/t/change-the-index-name-used-in-elasticsearch-module/176700 "2019-04-18T03:58:05Z")

</div>

Hi I am trying to monitor an es cluster using metricbeat elasticsearch module for some reason I can't change the index name sent to my monitoring cluster from .monitor-es-6-mb. 2019-04-12T19:31:55.671Z DEBUG …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=362)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=364)
