# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=364

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 365

---

## [Metricbeat kubernetes module error](https://discuss.elastic.co/t/metricbeat-kubernetes-module-error/177236)

<div class="topic-metadata">

**Author:** [@Ji\_Ho\_Choi](https://discuss.elastic.co/u/Ji_Ho_Choi)\
**Replies:** 1\
**Last updated:** [April 18, 2019, 1:26am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module-error/177236 "2019-04-18T01:26:36Z")

</div>

My beats is sending logs ok right now but elasticsearch is keep complaining about same error over and over. Pasted below. I have metricbeat and filebeat applied as daemonset. What is elasticsearch complaining about?

---

## [Database Monitoring Available in ELK](https://discuss.elastic.co/t/database-monitoring-available-in-elk/177306)

<div class="topic-metadata">

**Author:** [@nagr](https://discuss.elastic.co/u/nagr)\
**Replies:** 0\
**Last updated:** [April 17, 2019, 1:49pm UTC](https://discuss.elastic.co/t/database-monitoring-available-in-elk/177306 "2019-04-17T13:49:54Z")

</div>

Hi Team, I want to monitor the IBM DB2 application, so is the any beat support for this (or) is this feature can archive over ELK ? Please suggest me some idea, Thanks, Nagarajan,

---

## [Multiple filebeat instances in single docker container?](https://discuss.elastic.co/t/multiple-filebeat-instances-in-single-docker-container/177335)

<div class="topic-metadata">

**Author:** [@JJB](https://discuss.elastic.co/u/JJB)\
**Replies:** 3\
**Last updated:** [April 17, 2019, 9:10pm UTC](https://discuss.elastic.co/t/multiple-filebeat-instances-in-single-docker-container/177335 "2019-04-17T21:10:05Z")

</div>

I am running 4 docker containers for ELKB. I have a Filebeat set up to bring in log files from a volume folder and a logstash filter to process the log files (they're of the same format). I now have another set of log f…

---

## [Regarding Ingest Pipeline Upload](https://discuss.elastic.co/t/regarding-ingest-pipeline-upload/177330)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 3\
**Last updated:** [April 17, 2019, 9:04pm UTC](https://discuss.elastic.co/t/regarding-ingest-pipeline-upload/177330 "2019-04-17T21:04:52Z")

</div>

Hi, I'm not seeing expected behaviour when uploading logstash ingest pipelines: $ filebeat setup --pipelines --modules logstash Loaded Ingest pipelines However, when I look at the pipelines in elasticsearch I see that…

---

## [Unable to stop filebeat](https://discuss.elastic.co/t/unable-to-stop-filebeat/177210)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 5\
**Last updated:** [April 17, 2019, 5:38pm UTC](https://discuss.elastic.co/t/unable-to-stop-filebeat/177210 "2019-04-17T17:38:23Z")

</div>

Hello, I am unable to stop filebeat from sending the logs My filebeat config is filebeat.prospectors: input\_type: log paths: /var/www/html/hfurpublic\_html/urllog/\*\*/\* fields: service\_id: 347rfnkr multiline: pa…

---

## [Filebeat suspension](https://discuss.elastic.co/t/filebeat-suspension/177322)

<div class="topic-metadata">

**Author:** [@pravinab](https://discuss.elastic.co/u/pravinab)\
**Replies:** 1\
**Last updated:** [April 17, 2019, 5:37pm UTC](https://discuss.elastic.co/t/filebeat-suspension/177322 "2019-04-17T17:37:32Z")

</div>

Is there a way to suspend Filebeat from sending logs during a particular day of the week, between two timestamps (like during maintenance period)

---

## [Filebeat "make update" fails on 7.0](https://discuss.elastic.co/t/filebeat-make-update-fails-on-7-0/177304)

<div class="topic-metadata">

**Author:** [@muryoh](https://discuss.elastic.co/u/muryoh)\
**Replies:** 1\
**Last updated:** [April 17, 2019, 4:51pm UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-on-7-0/177304 "2019-04-17T16:51:34Z")

</div>

Hey there :slight\_smile: I just had a cool presentation of the Beats ecosystem, and more particularly of FileBeats I think it's very cool and would like to write a component for an application of my company. Having f…

---

## [Filebeat multi output](https://discuss.elastic.co/t/filebeat-multi-output/177307)

<div class="topic-metadata">

**Author:** [@Momo](https://discuss.elastic.co/u/Momo)\
**Replies:** 1\
**Last updated:** [April 17, 2019, 4:48pm UTC](https://discuss.elastic.co/t/filebeat-multi-output/177307 "2019-04-17T16:48:23Z")

</div>

Hello, I have a filebeat that sends logs to logstash and elasticsearch. I would like to enable the haproxy module of filebeat to send the haproxy logs to elasticsearch but when I run the command: filebeat setup -e I h…

---

## [Export only custom JSON to elasticsearch](https://discuss.elastic.co/t/export-only-custom-json-to-elasticsearch/177229)

<div class="topic-metadata">

**Author:** [@Yonatan\_Omer](https://discuss.elastic.co/u/Yonatan_Omer)\
**Replies:** 1\
**Last updated:** [April 17, 2019, 4:35pm UTC](https://discuss.elastic.co/t/export-only-custom-json-to-elasticsearch/177229 "2019-04-17T16:35:27Z")

</div>

When providing Filebeat with text file containing rows with JSON , Filebeat export to Elasticsearch server meta info such as log.offset , log.file.path ect. Even commenting these lines in filebeat.yaml did not help: #- …

---

## [Filebeat: Template Creation Error](https://discuss.elastic.co/t/filebeat-template-creation-error/177222)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [April 17, 2019, 4:33pm UTC](https://discuss.elastic.co/t/filebeat-template-creation-error/177222 "2019-04-17T16:33:24Z")

</div>

Hi, I'm testing filebeat 6.7.1 and am testing creation of custom template and index names. My config looks like this: setup.template: enabled: true name: "beats-logs-%{\[agent.version\]}" pattern: "beats-logs-\*" …

---

## [Is it possible to give a pipeline.json file path in filebeat.yml file?](https://discuss.elastic.co/t/is-it-possible-to-give-a-pipeline-json-file-path-in-filebeat-yml-file/177184)

<div class="topic-metadata">

**Author:** [@Mohan\_Selvam](https://discuss.elastic.co/u/Mohan_Selvam)\
**Replies:** 1\
**Last updated:** [April 17, 2019, 3:52pm UTC](https://discuss.elastic.co/t/is-it-possible-to-give-a-pipeline-json-file-path-in-filebeat-yml-file/177184 "2019-04-17T15:52:32Z")

</div>

I need to add the path of json file instead of pipeline name , so that i can change the pipeline data doing by role apply in chef. is it anyway to do this? and i am getting this error : pipeline with id \[/etc/filebeat…

---

## [Filebeat error Debian 6](https://discuss.elastic.co/t/filebeat-error-debian-6/176619)

<div class="topic-metadata">

**Author:** [@Felipe\_Aguiar\_Liota](https://discuss.elastic.co/u/Felipe_Aguiar_Liota)\
**Replies:** 1\
**Last updated:** [April 17, 2019, 2:54pm UTC](https://discuss.elastic.co/t/filebeat-error-debian-6/176619 "2019-04-17T14:54:20Z")

</div>

I installed Filebeat version 6.5.4 on Debian 6. The default configuration, when I try to start the service, returns error: Exiting: Error initializing the publisher: Error initializing processors: 1 Error: No / etc / -…

---

## [Filebeat not harvesting anything in Kubernetes](https://discuss.elastic.co/t/filebeat-not-harvesting-anything-in-kubernetes/177150)

<div class="topic-metadata">

**Author:** [@bbgobie](https://discuss.elastic.co/u/bbgobie)\
**Replies:** 4\
**Last updated:** [April 17, 2019, 2:03pm UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-anything-in-kubernetes/177150 "2019-04-17T14:03:36Z")

</div>

New to filebeats. I had a working configuration on docker, trying to get a simple config working in Kubernetes. Using the deploy sample from 6.6 branch I don't seem to be able to get Filebeats to parse logs or do anyth…

---

## [Several Functionbeat Questions](https://discuss.elastic.co/t/several-functionbeat-questions/177298)

<div class="topic-metadata">

**Author:** [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Replies:** 0\
**Last updated:** [April 17, 2019, 1:27pm UTC](https://discuss.elastic.co/t/several-functionbeat-questions/177298 "2019-04-17T13:27:06Z")

</div>

Dear Beats Team, you are awesome and love to see the new project go GA. This is timely as we're in our transition to Elastic. Several questions if I may: Is it unclear in the documentation that role that is needed for …

---

## [How to index the data of file beat automatically](https://discuss.elastic.co/t/how-to-index-the-data-of-file-beat-automatically/176913)

<div class="topic-metadata">

**Author:** [@Nabil\_Mohamed](https://discuss.elastic.co/u/Nabil_Mohamed)\
**Replies:** 2\
**Last updated:** [April 17, 2019, 12:20pm UTC](https://discuss.elastic.co/t/how-to-index-the-data-of-file-beat-automatically/176913 "2019-04-17T12:20:21Z")

</div>

Dears , -please check the below configuration for the filebeat as below --\> \[root@nabilmohamed2c filebeat\]# cat filebeat.yml filebeat.prospectors: type: log paths: /var/log/logstash-tutorial.log output.logstash: …

---

## [Filebeat is not showing up container name, namespace details with latest version 7.0.0](https://discuss.elastic.co/t/filebeat-is-not-showing-up-container-name-namespace-details-with-latest-version-7-0-0/177284)

<div class="topic-metadata">

**Author:** [@ishu52](https://discuss.elastic.co/u/ishu52)\
**Replies:** 0\
**Last updated:** [April 17, 2019, 11:40am UTC](https://discuss.elastic.co/t/filebeat-is-not-showing-up-container-name-namespace-details-with-latest-version-7-0-0/177284 "2019-04-17T11:40:46Z")

</div>

Hi, I am not able to see data for all the fields. Could only see below fields. Note: with filebeat 6.0.1 it was working fine Thanks,

---

## [Unable to configure packetbeat dashboards](https://discuss.elastic.co/t/unable-to-configure-packetbeat-dashboards/177250)

<div class="topic-metadata">

**Author:** [@BoffinPanda](https://discuss.elastic.co/u/BoffinPanda)\
**Replies:** 0\
**Last updated:** [April 17, 2019, 9:17am UTC](https://discuss.elastic.co/t/unable-to-configure-packetbeat-dashboards/177250 "2019-04-17T09:17:58Z")

</div>

./packetbeat setup --dashboards -c /etc/packetbeat/packetbeat.yml --path.data "/usr/share/packetbeat/kibana/6" Loading dashboards (Kibana must be running and reachable) Skipping loading dashboards, No directory /usr/sh…

---

## [How to add or change the fields to custom fields in filebeat?](https://discuss.elastic.co/t/how-to-add-or-change-the-fields-to-custom-fields-in-filebeat/176847)

<div class="topic-metadata">

**Author:** [@Mohan\_Selvam](https://discuss.elastic.co/u/Mohan_Selvam)\
**Replies:** 2\
**Last updated:** [April 17, 2019, 4:50am UTC](https://discuss.elastic.co/t/how-to-add-or-change-the-fields-to-custom-fields-in-filebeat/176847 "2019-04-17T04:50:21Z")

</div>

i have this format but what i need is is it anyway to do this by using filebeat

---

## [Winlogbeat 7.0 not dropping events](https://discuss.elastic.co/t/winlogbeat-7-0-not-dropping-events/176816)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 1\
**Last updated:** [April 15, 2019, 10:53am UTC](https://discuss.elastic.co/t/winlogbeat-7-0-not-dropping-events/176816 "2019-04-15T10:53:23Z")

</div>

Since the upgrade I have noticed winlogbeat is ingesting event ids other than specified in the config file. I also see some new fields are created like event.code and winlog.event\_id, while the event\_id is not showing af…

---

## [SOLVED - Index Template for filebeat - fails on fields](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745)

<div class="topic-metadata">

**Author:** [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Replies:** 4\
**Last updated:** [April 16, 2019, 10:52pm UTC](https://discuss.elastic.co/t/solved-index-template-for-filebeat-fails-on-fields/176745 "2019-04-16T22:52:15Z")

</div>

Hi, Recently we switched from beats -\> ES Cloud to beats -\> logstash -\> ES cloud. In our new cluster we found that the index mappings were not done (per previous post). I am trying to run the commands per documentation…

---

## [Unable to setup File Beats using go](https://discuss.elastic.co/t/unable-to-setup-file-beats-using-go/176980)

<div class="topic-metadata">

**Author:** [@johndowe](https://discuss.elastic.co/u/johndowe)\
**Replies:** 4\
**Last updated:** [April 16, 2019, 10:30pm UTC](https://discuss.elastic.co/t/unable-to-setup-file-beats-using-go/176980 "2019-04-16T22:30:01Z")

</div>

Similar to this : https://discuss.elastic.co/t/error-on-make-setup/147473/5 root@raspberrypi:~/go/src/github.com/elastic/beats/filebeat# GOPATH=~/go make Installing mage v1.8.0 from vendor dir. bash: mage: command not…

---

## [Filebeat system and iptables module timezone offset issue](https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732)

<div class="topic-metadata">

**Author:** [@mback2k](https://discuss.elastic.co/u/mback2k)\
**Replies:** 3\
**Last updated:** [April 16, 2019, 7:35pm UTC](https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732 "2019-04-16T19:35:54Z")

</div>

Hello everyone, I am using filebeat 6.7.1 with the system, iptables, traefik and apache2 modules. For some reason I am having issues with @timestamp being incorrect for system (from /var/log/syslog\* and /var/log/auth.lo…

---

## [Read JSON objects from JSON file with Filebeat](https://discuss.elastic.co/t/read-json-objects-from-json-file-with-filebeat/177139)

<div class="topic-metadata">

**Author:** [@strike](https://discuss.elastic.co/u/strike)\
**Replies:** 0\
**Last updated:** [April 16, 2019, 6:37pm UTC](https://discuss.elastic.co/t/read-json-objects-from-json-file-with-filebeat/177139 "2019-04-16T18:37:43Z")

</div>

I have .json file that has json object on each line, example content: {"method":"GET","path":"/-/metrics","format":"html","controller":"MetricsController","action":"index","status":200,"duration":4.53,"view":1.06,"db":0…

---

## [Filebeat Unexpected file opening error: File info is not identical with opened file](https://discuss.elastic.co/t/filebeat-unexpected-file-opening-error-file-info-is-not-identical-with-opened-file/177135)

<div class="topic-metadata">

**Author:** [@fionamacd](https://discuss.elastic.co/u/fionamacd)\
**Replies:** 0\
**Last updated:** [April 16, 2019, 5:56pm UTC](https://discuss.elastic.co/t/filebeat-unexpected-file-opening-error-file-info-is-not-identical-with-opened-file/177135 "2019-04-16T17:56:39Z")

</div>

I am running into the same problem logged previously: https://discuss.elastic.co/t/unexpected-file-opening-error-file-info-is-not-identical-with-opened-file/84026 I don't see any resolution to it though. I am also tryi…

---

## [Filebeat output to multiple ElasticSearch](https://discuss.elastic.co/t/filebeat-output-to-multiple-elasticsearch/177131)

<div class="topic-metadata">

**Author:** [@algilber](https://discuss.elastic.co/u/algilber)\
**Replies:** 1\
**Last updated:** [April 16, 2019, 5:49pm UTC](https://discuss.elastic.co/t/filebeat-output-to-multiple-elasticsearch/177131 "2019-04-16T17:49:38Z")

</div>

Hi, I have a server RHEL7 with filebeat client installed. I want to send the syslog to a cluster of ElasticSearch (elk01) and the logs of Nginx to another one (elk02). What's the config for that. The first one wotk grea…

---

## [Status of stopped process](https://discuss.elastic.co/t/status-of-stopped-process/177084)

<div class="topic-metadata">

**Author:** [@holiveira](https://discuss.elastic.co/u/holiveira)\
**Replies:** 2\
**Last updated:** [April 16, 2019, 5:40pm UTC](https://discuss.elastic.co/t/status-of-stopped-process/177084 "2019-04-16T17:40:17Z")

</div>

how to capture the status of the process when it is stopped? I only have the status when it is running. Metricbeat 7.0.0 (Windows Server 2008 R2) Elasticsearch 7.0.0 (Ubuntu Server 18.04 LTS)

---

## [Beats logs going to syslog and not defined file path](https://discuss.elastic.co/t/beats-logs-going-to-syslog-and-not-defined-file-path/176938)

<div class="topic-metadata">

**Author:** [@ocabj](https://discuss.elastic.co/u/ocabj)\
**Replies:** 2\
**Last updated:** [April 16, 2019, 4:03pm UTC](https://discuss.elastic.co/t/beats-logs-going-to-syslog-and-not-defined-file-path/176938 "2019-04-16T16:03:20Z")

</div>

I have always used /var/log/\[name\]beats as the path for the beats logs. But ever since 6.7 to 7.0, the beats logs are going to local syslog. I even hard set logging.to\_syslog: false but beats still writes out to /var/log…

---

## [Filebeat doesn't read file after rotation](https://discuss.elastic.co/t/filebeat-doesnt-read-file-after-rotation/177116)

<div class="topic-metadata">

**Author:** [@jbm](https://discuss.elastic.co/u/jbm)\
**Replies:** 0\
**Last updated:** [April 16, 2019, 3:44pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-read-file-after-rotation/177116 "2019-04-16T15:44:59Z")

</div>

I am running Filebeat 7.0.0, and when trying to read a log, the file stops getting read after it rotates. The file rotates by copying the contents of "errorlog.log" to "errorlog.1.log" and then emptying "errorlog.log". …

---

## [SOLVED - Multi Line Help](https://discuss.elastic.co/t/solved-multi-line-help/175741)

<div class="topic-metadata">

**Author:** [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Replies:** 1\
**Last updated:** [April 16, 2019, 2:39pm UTC](https://discuss.elastic.co/t/solved-multi-line-help/175741 "2019-04-16T14:39:24Z")

</div>

Team, I have made good progress using the following pattern on a java log for filebeat as the configuration: multiline.pattern: '^\[0-9\]{4}-\[0-9\]{2}-\[0-9\]{2}' multiline.negate: true multiline.match: after Most of the…

---

## [Kafka Output Recurring I/O Timeout](https://discuss.elastic.co/t/kafka-output-recurring-i-o-timeout/176764)

<div class="topic-metadata">

**Author:** [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Replies:** 3\
**Last updated:** [April 16, 2019, 12:26pm UTC](https://discuss.elastic.co/t/kafka-output-recurring-i-o-timeout/176764 "2019-04-16T12:26:50Z")

</div>

Hi, We're seeing Filebeat getting: kafka/log.go:53 producer/broker/1036 state change to \[closing\] because write tcp 10.200.1.158:49334-\>10.200.3.121:9092: i/o timeout This causes Filebeat to re-connect to Kafka broke…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=363)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=365)
