# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=365

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 366

---

## [\[autodiscover\] Error creating runner from config: Can only start an input when all related states are finished](https://discuss.elastic.co/t/autodiscover-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/177056)

<div class="topic-metadata">

**Author:** [@Sush\_Sampath](https://discuss.elastic.co/u/Sush_Sampath)\
**Replies:** 0\
**Last updated:** [April 16, 2019, 10:16am UTC](https://discuss.elastic.co/t/autodiscover-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/177056 "2019-04-16T10:16:12Z")

</div>

Hi, I am using filebeat 6.6.2 version with autodiscover for kubernetes provider type. After version upgrade from 6.2.4 to 6.6.2, I am facing this error for multiple docker containers. ERROR \[autodiscover\] cfgfile/list…

---

## [Mapping conflict for system.process.cpu.system+user when using metricbeat-6.3.0 and 6.6.0](https://discuss.elastic.co/t/mapping-conflict-for-system-process-cpu-system-user-when-using-metricbeat-6-3-0-and-6-6-0/174999)

<div class="topic-metadata">

**Author:** [@kaem2111](https://discuss.elastic.co/u/kaem2111)\
**Replies:** 2\
**Last updated:** [April 16, 2019, 8:56am UTC](https://discuss.elastic.co/t/mapping-conflict-for-system-process-cpu-system-user-when-using-metricbeat-6-3-0-and-6-6-0/174999 "2019-04-16T08:56:23Z")

</div>

I got a mapping conflict in Kibana index patterns due to different templates definitions for same field provided during beat installation. How can I fix that? How will you handle this with ECS?

---

## [Wildfly monitoring with apache module](https://discuss.elastic.co/t/wildfly-monitoring-with-apache-module/176926)

<div class="topic-metadata">

**Author:** [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Replies:** 1\
**Last updated:** [April 16, 2019, 8:41am UTC](https://discuss.elastic.co/t/wildfly-monitoring-with-apache-module/176926 "2019-04-16T08:41:52Z")

</div>

Is it possible to monitor a Wildfly server with the apache module in filebeat 6.5.2?

---

## [Error in filebeat when sending logs to kibana](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314)

<div class="topic-metadata">

**Author:** [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Replies:** 14\
**Last updated:** [April 16, 2019, 7:52am UTC](https://discuss.elastic.co/t/error-in-filebeat-when-sending-logs-to-kibana/176314 "2019-04-16T07:52:40Z")

</div>

Hello, I have set up Elasticsearch (6.7.1) and kibana on my local machine. Have installed Filebeat and logstash on a VM for testing and for shipping logs from VM to my local machine. Filebeat config: #===============…

---

## [\[Filebeat IIS\] lumberjack protocol error](https://discuss.elastic.co/t/filebeat-iis-lumberjack-protocol-error/175210)

<div class="topic-metadata">

**Author:** [@nyarlath](https://discuss.elastic.co/u/nyarlath)\
**Replies:** 2\
**Last updated:** [April 16, 2019, 7:28am UTC](https://discuss.elastic.co/t/filebeat-iis-lumberjack-protocol-error/175210 "2019-04-16T07:28:19Z")

</div>

Hello all, I have filebeat installed on two windows 2008R2 servers with IIS 7.5. My filebeat log file is polluted by this kind of entries: |INFO|log/input.go:138|Configured paths: \[C:\\inetpub\\logs\\LogFiles\\\*\\\*.log\]| …

---

## [Capturing http.response/sequest.body.content of elasticsearch traffic](https://discuss.elastic.co/t/capturing-http-response-sequest-body-content-of-elasticsearch-traffic/177005)

<div class="topic-metadata">

**Author:** [@Arcefi](https://discuss.elastic.co/u/Arcefi)\
**Replies:** 0\
**Last updated:** [April 16, 2019, 6:20am UTC](https://discuss.elastic.co/t/capturing-http-response-sequest-body-content-of-elasticsearch-traffic/177005 "2019-04-16T06:20:35Z")

</div>

What do I have to Configure to enable packetbeat to capture the full body of an elasticsearch request or response? I know I have to set include\_body\_for: but I don´t know what kind of config I need. Can anybody hel…

---

## [Loading Beats dashboard to Kibana in an openstack cloud](https://discuss.elastic.co/t/loading-beats-dashboard-to-kibana-in-an-openstack-cloud/176936)

<div class="topic-metadata">

**Author:** [@Andrew\_West](https://discuss.elastic.co/u/Andrew_West)\
**Replies:** 1\
**Last updated:** [April 16, 2019, 4:36am UTC](https://discuss.elastic.co/t/loading-beats-dashboard-to-kibana-in-an-openstack-cloud/176936 "2019-04-16T04:36:34Z")

</div>

Hi Running an openstack cloud with Filebeat5.6 on all the Compute nodes and ELK stack on the controllers. If I want to upload the Filebeat (or metricbeat,if it was installed) dashboard to Kibana , do I have to enable …

---

## [Upgrade Filebeat from 6.7 to 7.0](https://discuss.elastic.co/t/upgrade-filebeat-from-6-7-to-7-0/176603)

<div class="topic-metadata">

**Author:** [@PWIT](https://discuss.elastic.co/u/PWIT)\
**Replies:** 5\
**Last updated:** [April 15, 2019, 4:19pm UTC](https://discuss.elastic.co/t/upgrade-filebeat-from-6-7-to-7-0/176603 "2019-04-15T16:19:03Z")

</div>

I have upgraded my filebeat version from 6.7 to 7.0, here is my filebeat.yml #=========================== Filebeat inputs ============================= filebeat.inputs: - type: log enabled: true paths: - /usr/lo…

---

## [Prospector ticker stopped](https://discuss.elastic.co/t/prospector-ticker-stopped/176309)

<div class="topic-metadata">

**Author:** [@Kalyan\_MB](https://discuss.elastic.co/u/Kalyan_MB)\
**Replies:** 4\
**Last updated:** [April 15, 2019, 1:58pm UTC](https://discuss.elastic.co/t/prospector-ticker-stopped/176309 "2019-04-15T13:58:47Z")

</div>

Hi, facing this problem.. 2019-04-03T20:42:54.626+0530 INFO log/harvester.go:216 Harvester started for file: /home/vankata/190\_APS\_QUALIFICATION/kalyan\_elk\_logs/free\_data\_11\_09\_02\_30.txt 2019-04-03T20:42:54.626+0530 I…

---

## [Nothing is being logged to the log file](https://discuss.elastic.co/t/nothing-is-being-logged-to-the-log-file/176790)

<div class="topic-metadata">

**Author:** [@James\_Woods](https://discuss.elastic.co/u/James_Woods)\
**Replies:** 1\
**Last updated:** [April 15, 2019, 12:42pm UTC](https://discuss.elastic.co/t/nothing-is-being-logged-to-the-log-file/176790 "2019-04-15T12:42:23Z")

</div>

So filebeat is running my apache log, located in /var/log/httpd and the path I'm using is /var/log/httpd/\* in the filebeats.yml file but from what I can tell it's doing nothing. I thought I should check the log file, cha…

---

## [After enabling multiline.pattern, filebeat service not starting](https://discuss.elastic.co/t/after-enabling-multiline-pattern-filebeat-service-not-starting/176669)

<div class="topic-metadata">

**Author:** [@Bhaskar\_Balapuram](https://discuss.elastic.co/u/Bhaskar_Balapuram)\
**Replies:** 1\
**Last updated:** [April 15, 2019, 12:35pm UTC](https://discuss.elastic.co/t/after-enabling-multiline-pattern-filebeat-service-not-starting/176669 "2019-04-15T12:35:16Z")

</div>

Hi Team, There is requirement of shipping multiple lines of logs to elasticsearch. Here is the configuration which i placed in filebeat.yml file. ============= type: docker combine\_partial: true containers: path…

---

## [SIGSEGV: segmentation violation code=0x2](https://discuss.elastic.co/t/sigsegv-segmentation-violation-code-0x2/176888)

<div class="topic-metadata">

**Author:** [@mrspring](https://discuss.elastic.co/u/mrspring)\
**Replies:** 0\
**Last updated:** [April 15, 2019, 11:00am UTC](https://discuss.elastic.co/t/sigsegv-segmentation-violation-code-0x2/176888 "2019-04-15T11:00:17Z")

</div>

I'm using packetbeat to record data on a linux server. It randomly fails with the following error 2019-04-15T09:21:39.726931776Z goroutine 26 \[running\]: 2019-04-15T09:21:39.925593735Z runtime.throw(0x17de829, 0x5) 2…

---

## [Collecting Logs from Window Server 2008 R2](https://discuss.elastic.co/t/collecting-logs-from-window-server-2008-r2/176332)

<div class="topic-metadata">

**Author:** [@Kajol\_Nimesh](https://discuss.elastic.co/u/Kajol_Nimesh)\
**Replies:** 2\
**Last updated:** [April 15, 2019, 8:39am UTC](https://discuss.elastic.co/t/collecting-logs-from-window-server-2008-r2/176332 "2019-04-15T08:39:21Z")

</div>

Hi, Is there any possible way that I can get logs of window server 2008 R1 & R2 on my local client machine without installing elk stack and Winbeatlog on server? Please suggest me some possible way.

---

## [Filebeat for Raspberry Pi](https://discuss.elastic.co/t/filebeat-for-raspberry-pi/176749)

<div class="topic-metadata">

**Author:** [@johndowe](https://discuss.elastic.co/u/johndowe)\
**Replies:** 6\
**Last updated:** [April 14, 2019, 11:24pm UTC](https://discuss.elastic.co/t/filebeat-for-raspberry-pi/176749 "2019-04-14T23:24:17Z")

</div>

Hi Guys, just checking i am trying to setup a system where the logstash server is hosted locally on prem and the elasticsearch + kibana are in the cloud. Anyone has any suggestions/tips around this? I tried to do some …

---

## [Timestamp field not populating correctly](https://discuss.elastic.co/t/timestamp-field-not-populating-correctly/176792)

<div class="topic-metadata">

**Author:** [@richwillars](https://discuss.elastic.co/u/richwillars)\
**Replies:** 1\
**Last updated:** [April 14, 2019, 8:43pm UTC](https://discuss.elastic.co/t/timestamp-field-not-populating-correctly/176792 "2019-04-14T20:43:04Z")

</div>

Hi all. I've got functionbeat working on a AWS lambda, and it's populating all fields correctly apart from the timestamp. { "@timestamp": event.ts, labels: { env: process.env.NODE\_CONFIG\_…

---

## [JSON Parsing Errors](https://discuss.elastic.co/t/json-parsing-errors/176765)

<div class="topic-metadata">

**Author:** [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Replies:** 0\
**Last updated:** [April 14, 2019, 8:25am UTC](https://discuss.elastic.co/t/json-parsing-errors/176765 "2019-04-14T08:25:03Z")

</div>

Hi Did anyone encounter these in Filebeat? json/json.go:51 Error decoding JSON: invalid character 'C' looking for beginning of value

---

## [Filebeat setup error message](https://discuss.elastic.co/t/filebeat-setup-error-message/176750)

<div class="topic-metadata">

**Author:** [@KK23](https://discuss.elastic.co/u/KK23)\
**Replies:** 2\
**Last updated:** [April 14, 2019, 5:39am UTC](https://discuss.elastic.co/t/filebeat-setup-error-message/176750 "2019-04-14T05:39:58Z")

</div>

Hi, I am getting below error with file beat setup sudo filebeat setup gives "Exiting: 1 error: Error checking if xpack is available: 500 Internal Server Error: {"error":{"root\_cause":\[{"type":"security\_exception","rea…

---

## [Fielddata is disabled on text fields by default. Set fielddata=true on \[host.name\] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead](https://discuss.elastic.co/t/fielddata-is-disabled-on-text-fields-by-default-set-fielddata-true-on-host-name-in-order-to-load-fielddata-in-memory-by-uninverting-the-inverted-index-note-that-this-can-however-use-significant-memory-alternatively-use-a-keyword-field-instead/176727)

<div class="topic-metadata">

**Author:** [@Zyuxing](https://discuss.elastic.co/u/Zyuxing)\
**Replies:** 3\
**Last updated:** [April 13, 2019, 10:44am UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-text-fields-by-default-set-fielddata-true-on-host-name-in-order-to-load-fielddata-in-memory-by-uninverting-the-inverted-index-note-that-this-can-however-use-significant-memory-alternatively-use-a-keyword-field-instead/176727 "2019-04-13T10:44:34Z")

</div>

I had this problem visiting kibana Infrastructure. I followed the document example: PUT metricbeat - \* / \_mapping { "Properties" : { "Host name" : { "Type" : "text", "Fielddata" : true } } } It happened: Mapp…

---

## [Filebeat in kubernetes with json problem](https://discuss.elastic.co/t/filebeat-in-kubernetes-with-json-problem/176716)

<div class="topic-metadata">

**Author:** [@qiyongxiao](https://discuss.elastic.co/u/qiyongxiao)\
**Replies:** 0\
**Last updated:** [April 13, 2019, 4:15am UTC](https://discuss.elastic.co/t/filebeat-in-kubernetes-with-json-problem/176716 "2019-04-13T04:15:35Z")

</div>

Hello, I deployed filebeat on kubernetes. I meet an proble with json on kibana message key. The configmap is filebeat.yml: |- setup.kibana: host: "kibana.kube-system.svc.cluster.local:5601" filebeat.inputs: - type: …

---

## [Metricbeat-god core dump running as non-root user on RHEL 6.0](https://discuss.elastic.co/t/metricbeat-god-core-dump-running-as-non-root-user-on-rhel-6-0/174362)

<div class="topic-metadata">

**Author:** [@arunachala](https://discuss.elastic.co/u/arunachala)\
**Replies:** 4\
**Last updated:** [April 12, 2019, 4:40pm UTC](https://discuss.elastic.co/t/metricbeat-god-core-dump-running-as-non-root-user-on-rhel-6-0/174362 "2019-04-12T16:40:06Z")

</div>

Hi, I am trying to run metricbeat (version 6.2.3) as a non-root user, but the metricbeat-god is throwing an exception and core dumping. \[root@RHEL ~\]# /home/test/metricbeat/bin/metricbeat-god -u test -r / -n -p /home/…

---

## [Upload and parse exported .evtx files to Elasticsearch](https://discuss.elastic.co/t/upload-and-parse-exported-evtx-files-to-elasticsearch/175014)

<div class="topic-metadata">

**Author:** [@jwahlgren](https://discuss.elastic.co/u/jwahlgren)\
**Replies:** 8\
**Last updated:** [April 12, 2019, 4:36pm UTC](https://discuss.elastic.co/t/upload-and-parse-exported-evtx-files-to-elasticsearch/175014 "2019-04-12T16:36:55Z")

</div>

I have a use case scenario where I have to manually upload and parse Windows logs to Elasticsearch by using exported .evtx files. Splunk handles this fine with the "oneshot" command and I was wondering if anyone in this …

---

## [Running filebeat as non-root in Kubernetes?](https://discuss.elastic.co/t/running-filebeat-as-non-root-in-kubernetes/176652)

<div class="topic-metadata">

**Author:** [@Vincehood](https://discuss.elastic.co/u/Vincehood)\
**Replies:** 0\
**Last updated:** [April 12, 2019, 3:01pm UTC](https://discuss.elastic.co/t/running-filebeat-as-non-root-in-kubernetes/176652 "2019-04-12T15:01:25Z")

</div>

Hi, the filebeat Helm chart (https://raw.githubusercontent.com/elastic/beats/7.0/deploy/kubernetes/filebeat-kubernetes.yaml) specifies that the user shall be root (runAsUser: 0). Is there any other way to achieve appli…

---

## [Docker Json Logs to haproxy module](https://discuss.elastic.co/t/docker-json-logs-to-haproxy-module/176432)

<div class="topic-metadata">

**Author:** [@usuar.niam](https://discuss.elastic.co/u/usuar.niam)\
**Replies:** 1\
**Last updated:** [April 12, 2019, 2:33pm UTC](https://discuss.elastic.co/t/docker-json-logs-to-haproxy-module/176432 "2019-04-12T14:33:41Z")

</div>

Hi, My docker logging driver is set to output JSON log files. Changing this setting is out of my control, and means all of the logs in /var/lib/docker/containers/${data.docker.container.id} are in json format. i.e., a l…

---

## [Filebeat Windows not shipping logs after restart](https://discuss.elastic.co/t/filebeat-windows-not-shipping-logs-after-restart/175233)

<div class="topic-metadata">

**Author:** [@jimmyvalmer19](https://discuss.elastic.co/u/jimmyvalmer19)\
**Replies:** 1\
**Last updated:** [April 12, 2019, 2:17pm UTC](https://discuss.elastic.co/t/filebeat-windows-not-shipping-logs-after-restart/175233 "2019-04-12T14:17:41Z")

</div>

Hello. I use filebeat-6-6.0-windows\_x86\_64 and when I restart filebeat, it would not continue harvest files. It only start harvesting files when I delete registry file during restart. I turned the verbose loglevel on, an…

---

## [AWS Module future support](https://discuss.elastic.co/t/aws-module-future-support/176303)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 4\
**Last updated:** [April 12, 2019, 1:51pm UTC](https://discuss.elastic.co/t/aws-module-future-support/176303 "2019-04-12T13:51:39Z")

</div>

Hi, The new AWS Metricbeat module looks great. We have similar ad hoc solutions internally for things like RDS and ALB metrics, so this will be a welcome way to have a more "official" way to ingest metrics from Cloudwat…

---

## [Logstash or Metricbeat best for Cloudwatch?](https://discuss.elastic.co/t/logstash-or-metricbeat-best-for-cloudwatch/175748)

<div class="topic-metadata">

**Author:** [@nick-george](https://discuss.elastic.co/u/nick-george)\
**Replies:** 4\
**Last updated:** [April 12, 2019, 1:51pm UTC](https://discuss.elastic.co/t/logstash-or-metricbeat-best-for-cloudwatch/175748 "2019-04-12T13:51:05Z")

</div>

Hi There, It appears that Elastic now has two supported methods of getting Cloudwatch Metrics into ES, Metricbeat and Logstash. Does the new v7 Metricbeat implementation now supersede the Logstash one? I'm about to im…

---

## [Multiline not capturing data in swirly brackets](https://discuss.elastic.co/t/multiline-not-capturing-data-in-swirly-brackets/176593)

<div class="topic-metadata">

**Author:** [@ukgaz](https://discuss.elastic.co/u/ukgaz)\
**Replies:** 0\
**Last updated:** [April 12, 2019, 9:29am UTC](https://discuss.elastic.co/t/multiline-not-capturing-data-in-swirly-brackets/176593 "2019-04-12T09:29:39Z")

</div>

I'm struggling to get multiple lines, including data inside swirly brackets to be captured, only the first line gets captured. Filebeat 5.6 multiline.pattern: '^\[0-9\]{2}:\[0-9\]{2}:\[0-9\]{2},\[0-9\]{3}' multiline.negate: tr…

---

## [Hi, Filebeat multiple input](https://discuss.elastic.co/t/hi-filebeat-multiple-input/176591)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Lubis](https://discuss.elastic.co/u/Ibrahim_Lubis)\
**Replies:** 0\
**Last updated:** [April 12, 2019, 9:26am UTC](https://discuss.elastic.co/t/hi-filebeat-multiple-input/176591 "2019-04-12T09:26:44Z")

</div>

Hi, I have filebeat with multiple input and tag, apache\_access, apache\_error, and modsec. This have one logstash input input { beats { port =\> "5044" EDIT SSL COMM ssl =\> true ssl\_certificate =\> "/etc/ssl/logstash/…

---

## [Autodiscovery with modules in Docker](https://discuss.elastic.co/t/autodiscovery-with-modules-in-docker/176390)

<div class="topic-metadata">

**Author:** [@ftec](https://discuss.elastic.co/u/ftec)\
**Replies:** 2\
**Last updated:** [April 12, 2019, 8:19am UTC](https://discuss.elastic.co/t/autodiscovery-with-modules-in-docker/176390 "2019-04-12T08:19:57Z")

</div>

Hi, I have the deployed ES stack (ES + Kibana + Metricbeat + Filebeat) to a Docker Swarm stack. That stack contains also some services like MySQL (mariadb), Kafka+Zookeeper, Traefik gateways, etc. I want to read Docke…

---

## [Add custom info in add\_kubernetes\_metadata](https://discuss.elastic.co/t/add-custom-info-in-add-kubernetes-metadata/176400)

<div class="topic-metadata">

**Author:** [@himani\_chawla](https://discuss.elastic.co/u/himani_chawla)\
**Replies:** 1\
**Last updated:** [April 12, 2019, 8:00am UTC](https://discuss.elastic.co/t/add-custom-info-in-add-kubernetes-metadata/176400 "2019-04-12T08:00:58Z")

</div>

How to add custom info such as pod's container's environment variable in add\_kubernetes\_metadata?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=364)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=366)
