# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=366

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 367

---

## [Filebeat compilation using gcc-go compiler in AIX 7.1](https://discuss.elastic.co/t/filebeat-compilation-using-gcc-go-compiler-in-aix-7-1/176550)

<div class="topic-metadata">

**Author:** [@rsumit](https://discuss.elastic.co/u/rsumit)\
**Replies:** 0\
**Last updated:** [April 12, 2019, 7:10am UTC](https://discuss.elastic.co/t/filebeat-compilation-using-gcc-go-compiler-in-aix-7-1/176550 "2019-04-12T07:10:40Z")

</div>

Hi Team I need to install Filebeat on AIX 7.1 . As filebeat is not compatible with AIX, I found multiple post to use gcc-go compiler to create binary. However, I could not find any relative steps or document for the sam…

---

## [Error while enrolling: empty access\_token](https://discuss.elastic.co/t/error-while-enrolling-empty-access-token/175626)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 2\
**Last updated:** [April 12, 2019, 4:31am UTC](https://discuss.elastic.co/t/error-while-enrolling-empty-access-token/175626 "2019-04-12T04:31:59Z")

</div>

Hello World! I'm using Elastic stack 6.7.1 and trying to follow Enroll Beats in central management, yet running into following issue: # filebeat enroll --force https://X.X.X:443 --username elastic --password stdin Ente…

---

## [I want to run two filebeat instance in the same directory](https://discuss.elastic.co/t/i-want-to-run-two-filebeat-instance-in-the-same-directory/176370)

<div class="topic-metadata">

**Author:** [@wolfman](https://discuss.elastic.co/u/wolfman)\
**Replies:** 2\
**Last updated:** [April 12, 2019, 2:22am UTC](https://discuss.elastic.co/t/i-want-to-run-two-filebeat-instance-in-the-same-directory/176370 "2019-04-12T02:22:46Z")

</div>

i want to run two filebeat instance in the same directory,one using a.yml and the other using b.yml, and i use the different register data directories.Other than this,what else should i pay attention to ?

---

## [Can Filebeat detect when a log file it's configured to read, is being updated?](https://discuss.elastic.co/t/can-filebeat-detect-when-a-log-file-its-configured-to-read-is-being-updated/176485)

<div class="topic-metadata">

**Author:** [@enwillia](https://discuss.elastic.co/u/enwillia)\
**Replies:** 0\
**Last updated:** [April 11, 2019, 7:38pm UTC](https://discuss.elastic.co/t/can-filebeat-detect-when-a-log-file-its-configured-to-read-is-being-updated/176485 "2019-04-11T19:38:05Z")

</div>

I am using Filebeat to read in logs. I could not find any information about how Filebeat handles log file collisions. I want to know if Filebeat can detect when a log file it's configured to read, is being updated or add…

---

## [How to delete specific filebeat indices](https://discuss.elastic.co/t/how-to-delete-specific-filebeat-indices/176446)

<div class="topic-metadata">

**Author:** [@daniel.gutierrez](https://discuss.elastic.co/u/daniel.gutierrez)\
**Replies:** 1\
**Last updated:** [April 11, 2019, 6:55pm UTC](https://discuss.elastic.co/t/how-to-delete-specific-filebeat-indices/176446 "2019-04-11T18:55:16Z")

</div>

Hello everyone I want to delete specific indices on filebeat I have 2 questions What is the command to delete specific indices How can i see my indices thanks

---

## [How does the autodiscover feature in \*Beat work?](https://discuss.elastic.co/t/how-does-the-autodiscover-feature-in-beat-work/172603)

<div class="topic-metadata">

**Author:** [@Jeeppler](https://discuss.elastic.co/u/Jeeppler)\
**Replies:** 2\
**Last updated:** [April 11, 2019, 6:57pm UTC](https://discuss.elastic.co/t/how-does-the-autodiscover-feature-in-beat-work/172603 "2019-04-11T18:57:46Z")

</div>

How does the autodiscover feature in \*Beat (MetricBeat, FileBeat etc.) work from a technical perspective? I am especially interested in how it works on Kubernetes? As far as I understood it the \*Beat, for example Metri…

---

## [Beats - custom index issue](https://discuss.elastic.co/t/beats-custom-index-issue/176467)

<div class="topic-metadata">

**Author:** [@S\_Chase](https://discuss.elastic.co/u/S_Chase)\
**Replies:** 0\
**Last updated:** [April 11, 2019, 5:28pm UTC](https://discuss.elastic.co/t/beats-custom-index-issue/176467 "2019-04-11T17:28:29Z")

</div>

With Heartbeat, Filebeat, and Metricbeat I tried to set a custom index - same name just removing the date. So instead of heartbeat-%{\[agent.version\]}-%{+yyyy.MM.dd} I was trying to make it: heartbeat-%{\[agent.version\]}…

---

## [Cluster upgrade](https://discuss.elastic.co/t/cluster-upgrade/176244)

<div class="topic-metadata">

**Author:** [@Alessio\_Creo](https://discuss.elastic.co/u/Alessio_Creo)\
**Replies:** 2\
**Last updated:** [April 11, 2019, 2:32pm UTC](https://discuss.elastic.co/t/cluster-upgrade/176244 "2019-04-11T14:32:50Z")

</div>

Hi there, I'm receiving data shipped by Filebeat from 59 hosts. Now I have to proceed a full cluster restart to change the SSL certificate while upgrading to the last version. Is it recommended to stop the agents while…

---

## [Testing filebeat](https://discuss.elastic.co/t/testing-filebeat/176145)

<div class="topic-metadata">

**Author:** [@furstenheim-geoblink](https://discuss.elastic.co/u/furstenheim-geoblink)\
**Replies:** 1\
**Last updated:** [April 11, 2019, 2:18pm UTC](https://discuss.elastic.co/t/testing-filebeat/176145 "2019-04-11T14:18:53Z")

</div>

Hi, I'd like to know how to test a filebeat configuration. I have filebeat installed locally, so I can do filebeat test config -c $MY\_FILE. That is good to test if the configuration is semantically correct. However, I'…

---

## [Load one dashboard instead of all Filebeat default dashboards](https://discuss.elastic.co/t/load-one-dashboard-instead-of-all-filebeat-default-dashboards/176281)

<div class="topic-metadata">

**Author:** [@Reedler](https://discuss.elastic.co/u/Reedler)\
**Replies:** 2\
**Last updated:** [April 11, 2019, 2:11pm UTC](https://discuss.elastic.co/t/load-one-dashboard-instead-of-all-filebeat-default-dashboards/176281 "2019-04-11T14:11:19Z")

</div>

Hopefully I'm just going about this all wrong. I've tried to use set.dashboards.file in the dashboards section of the filebeat.yml to load just the IIS dashboard. First I tried to export the Filebeat-iis.json in kibana a…

---

## [Filebeat Issue - Connection Closed forcibly](https://discuss.elastic.co/t/filebeat-issue-connection-closed-forcibly/175589)

<div class="topic-metadata">

**Author:** [@Ganesh999](https://discuss.elastic.co/u/Ganesh999)\
**Replies:** 2\
**Last updated:** [April 11, 2019, 1:43pm UTC](https://discuss.elastic.co/t/filebeat-issue-connection-closed-forcibly/175589 "2019-04-11T13:43:32Z")

</div>

Hi All, I have been receiving error while publishing data from filebeat to logstash. Below is the error 2019-04-05T03:55:19.382+0530 ERROR logstash/async.go:256 Failed to publish events caused by: write tcp XX.XX.XX.X…

---

## [Filebeat is partially collecting logs](https://discuss.elastic.co/t/filebeat-is-partially-collecting-logs/176256)

<div class="topic-metadata">

**Author:** [@y3046308](https://discuss.elastic.co/u/y3046308)\
**Replies:** 2\
**Last updated:** [April 11, 2019, 1:08pm UTC](https://discuss.elastic.co/t/filebeat-is-partially-collecting-logs/176256 "2019-04-11T13:08:48Z")

</div>

Hi I'm having a funny issue with filebeat in kubernetes cluster. Filebeat collects logs for some pods but it doesn't collect logs for all the other pods. I don't see any noticeable error messages from filebeat log. Co…

---

## [What is the difference between environment and roles](https://discuss.elastic.co/t/what-is-the-difference-between-environment-and-roles/176343)

<div class="topic-metadata">

**Author:** [@Mohan\_Selvam](https://discuss.elastic.co/u/Mohan_Selvam)\
**Replies:** 2\
**Last updated:** [April 11, 2019, 1:00pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-environment-and-roles/176343 "2019-04-11T13:00:00Z")

</div>

Can anyone please tell me the difference between roles and environments, if i apply the roles i need to run the chef-client same as environment , chef client runs both env and role and it makes the environment attributes…

---

## [Filebeat monitoring not working](https://discuss.elastic.co/t/filebeat-monitoring-not-working/176247)

<div class="topic-metadata">

**Author:** [@wiliamauc85](https://discuss.elastic.co/u/wiliamauc85)\
**Replies:** 2\
**Last updated:** [April 10, 2019, 4:08pm UTC](https://discuss.elastic.co/t/filebeat-monitoring-not-working/176247 "2019-04-10T16:08:01Z")

</div>

Hi, I've been trying to set up filebeat monitoring and going through the docs, my filebeats.yml looks like this - type: log enabled: true paths: - /var/log/secure output.logstash: hosts: \["logstash:5044"\] s…

---

## [Heartbeat 6.7 regression bug. mode:all always logs a false UP](https://discuss.elastic.co/t/heartbeat-6-7-regression-bug-mode-all-always-logs-a-false-up/174892)

<div class="topic-metadata">

**Author:** [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Replies:** 3\
**Last updated:** [April 11, 2019, 7:57am UTC](https://discuss.elastic.co/t/heartbeat-6-7-regression-bug-mode-all-always-logs-a-false-up/174892 "2019-04-11T07:57:19Z")

</div>

Hi, Monitor config: - type: http name: test urls: - http://elastic.co:8888/v1 ipv6: false mode: all schedule: '@every 5s' timeout: 2s In the case of 6.6.2 and 6.7 heartbeat logs all the right DOWN even…

---

## [Monitor health check of the website](https://discuss.elastic.co/t/monitor-health-check-of-the-website/175690)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 2\
**Last updated:** [April 11, 2019, 3:50am UTC](https://discuss.elastic.co/t/monitor-health-check-of-the-website/175690 "2019-04-11T03:50:37Z")

</div>

Hi I have installed metric and filebeats on my website. I am getting system and access logs. from IIS module and apache module. I want to know the health check of the site "https://testwebsite.com" to see if its acc…

---

## [Duplicate messages created by Journalbeat 6.7.1-1](https://discuss.elastic.co/t/duplicate-messages-created-by-journalbeat-6-7-1-1/175930)

<div class="topic-metadata">

**Author:** [@ddiguru](https://discuss.elastic.co/u/ddiguru)\
**Replies:** 6\
**Last updated:** [April 10, 2019, 7:45pm UTC](https://discuss.elastic.co/t/duplicate-messages-created-by-journalbeat-6-7-1-1/175930 "2019-04-10T19:45:42Z")

</div>

I'm running journalbeat-6.7.1-1 on CentOS 7.6 and Fedora 28, and i'm noticing that journal beat is duplicating some but NOT all messages. The only thing that appears different between the messages is the journalbeat\_read…

---

## [Filebeat crashing on JSON decoder and multiline together specifying a message\_key value error](https://discuss.elastic.co/t/filebeat-crashing-on-json-decoder-and-multiline-together-specifying-a-message-key-value-error/176132)

<div class="topic-metadata">

**Author:** [@Tharun](https://discuss.elastic.co/u/Tharun)\
**Replies:** 0\
**Last updated:** [April 10, 2019, 4:07am UTC](https://discuss.elastic.co/t/filebeat-crashing-on-json-decoder-and-multiline-together-specifying-a-message-key-value-error/176132 "2019-04-10T04:07:02Z")

</div>

Filebeat Version: 6.5.4 and Logstash Version: 6.5.4 Hello, here is the Filebeat configuration I'm using - type: log paths: - /var/lib/docker/containers/\*/\*.log symlinks: true multiline: pattern: ^\[\[:spac…

---

## [One prospector per configuration file in logstash](https://discuss.elastic.co/t/one-prospector-per-configuration-file-in-logstash/176241)

<div class="topic-metadata">

**Author:** [@roblopes](https://discuss.elastic.co/u/roblopes)\
**Replies:** 2\
**Last updated:** [April 10, 2019, 2:49pm UTC](https://discuss.elastic.co/t/one-prospector-per-configuration-file-in-logstash/176241 "2019-04-10T14:49:44Z")

</div>

Hi, We have a filebeat instance with multiple prospectors, sending logs to logstash for parsing and ingesting into elasticsearch. Is it possible to break the configuration file in multiple files, one for each prospecto…

---

## [Help on: Error creating runner from config: Can only start an input when all related states are finished](https://discuss.elastic.co/t/help-on-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/176240)

<div class="topic-metadata">

**Author:** [@bikoumba](https://discuss.elastic.co/u/bikoumba)\
**Replies:** 0\
**Last updated:** [April 10, 2019, 2:28pm UTC](https://discuss.elastic.co/t/help-on-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/176240 "2019-04-10T14:28:14Z")

</div>

Hello, I have an issue with my filebeat configuration. I have an api running on k8s, logs are written to stdout and requests-logs to stderr in order to get them both in my ES Cluster. I m using filebeat 6.7.1 OSS with …

---

## [Pipeline/output.go:121 Failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/pipeline-output-go-121-failed-to-publish-events-temporary-bulk-send-failure/176223)

<div class="topic-metadata">

**Author:** [@setiseta](https://discuss.elastic.co/u/setiseta)\
**Replies:** 0\
**Last updated:** [April 10, 2019, 1:07pm UTC](https://discuss.elastic.co/t/pipeline-output-go-121-failed-to-publish-events-temporary-bulk-send-failure/176223 "2019-04-10T13:07:50Z")

</div>

Hi, im stuck at getting the obove error. don't know what went wrong. maybe someone here has some hints? Here is a log snippet: DEBUG \[elasticsearch\] elasticsearch/client.go:338 PublishEvents: 2 events have been…

---

## [Could not locate that index-pattern (id: winlogbeat-\*), \[click here to re-create it\](#/management/kibana/index)](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-id-winlogbeat-click-here-to-re-create-it-management-kibana-index/176201)

<div class="topic-metadata">

**Author:** [@Farhad\_Kocharli](https://discuss.elastic.co/u/Farhad_Kocharli)\
**Replies:** 0\
**Last updated:** [April 10, 2019, 11:26am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-id-winlogbeat-click-here-to-re-create-it-management-kibana-index/176201 "2019-04-10T11:26:55Z")

</div>

Hello everyone. I'm new for Elastic. Following documentation I have installed Elasticsearch, Kibana, Logstash (without any filters for now.) on CentOS 7 (all of them in one node). Then I've installed Winlogbeat in Win…

---

## [Performance Guide Needed](https://discuss.elastic.co/t/performance-guide-needed/175867)

<div class="topic-metadata">

**Author:** [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Replies:** 2\
**Last updated:** [April 10, 2019, 8:32am UTC](https://discuss.elastic.co/t/performance-guide-needed/175867 "2019-04-10T08:32:31Z")

</div>

Hi, We're in the process of optimizing our Filebeat processes and we're looking for a general guideline of how to do so. We have multiple HAproxy servers which write logs via rsyslog. Each event is written in JSON and …

---

## [Metricbeat - PostgreSQL modlue](https://discuss.elastic.co/t/metricbeat-postgresql-modlue/174599)

<div class="topic-metadata">

**Author:** [@stevemw](https://discuss.elastic.co/u/stevemw)\
**Replies:** 4\
**Last updated:** [April 10, 2019, 8:29am UTC](https://discuss.elastic.co/t/metricbeat-postgresql-modlue/174599 "2019-04-10T08:29:58Z")

</div>

We are trying to use the PostgreSQL module for metricbeat (v6.6.2), and we are having a problem with authentication. My Postgres module is configured as below: module: postgresql enabled: true metricsets: database b…

---

## [Postgresql tcp check is not working](https://discuss.elastic.co/t/postgresql-tcp-check-is-not-working/174767)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 3\
**Last updated:** [April 10, 2019, 8:10am UTC](https://discuss.elastic.co/t/postgresql-tcp-check-is-not-working/174767 "2019-04-10T08:10:24Z")

</div>

Hello, I have setup in heartbeat a tcp check for postgresql but I don't seam to manage to have it working. The config looks like the following: - type: tcp schedule: '@every 5s' hosts: \["172.168.17.2"\] ports: \[5…

---

## [Creating custom beat, "make package" fails with "make: \*\*\* No rule to make target 'package'. Stop."](https://discuss.elastic.co/t/creating-custom-beat-make-package-fails-with-make-no-rule-to-make-target-package-stop/175766)

<div class="topic-metadata">

**Author:** [@akankshajpr](https://discuss.elastic.co/u/akankshajpr)\
**Replies:** 4\
**Last updated:** [April 10, 2019, 6:38am UTC](https://discuss.elastic.co/t/creating-custom-beat-make-package-fails-with-make-no-rule-to-make-target-package-stop/175766 "2019-04-10T06:38:33Z")

</div>

I am trying to create a custom beat using the guide https://www.elastic.co/guide/en/beats/devguide/current/new-beat.html and am unable to package it. Ideally the command "make package" should do the job but it is failing…

---

## [Haproxy.source not being logged](https://discuss.elastic.co/t/haproxy-source-not-being-logged/175670)

<div class="topic-metadata">

**Author:** [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Replies:** 1\
**Last updated:** [April 10, 2019, 6:16am UTC](https://discuss.elastic.co/t/haproxy-source-not-being-logged/175670 "2019-04-10T06:16:33Z")

</div>

I am using latest (6.7) ES, Kibana, and Filebeat. The grok patterns in pipeline.json for http log format contain %{IPORHOST:haproxy.source} and my log files seem to match OK, but this field is not being logged into m…

---

## [Heartbeat http monitor is not sending headers](https://discuss.elastic.co/t/heartbeat-http-monitor-is-not-sending-headers/175761)

<div class="topic-metadata">

**Author:** [@marvnz](https://discuss.elastic.co/u/marvnz)\
**Replies:** 3\
**Last updated:** [April 10, 2019, 3:19am UTC](https://discuss.elastic.co/t/heartbeat-http-monitor-is-not-sending-headers/175761 "2019-04-10T03:19:26Z")

</div>

I have configured the following http monitor: heartbeat.monitors: - type: "http" urls: \["http://elasticsearch-dev-master.dev-common-cache.svc.cluster.local:9200","https://dev-common-cache.gubbins.bobbins","http://10.1…

---

## [Metricbeat unable to find its own yml config](https://discuss.elastic.co/t/metricbeat-unable-to-find-its-own-yml-config/174846)

<div class="topic-metadata">

**Author:** [@teamg](https://discuss.elastic.co/u/teamg)\
**Replies:** 2\
**Last updated:** [April 9, 2019, 11:03pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-find-its-own-yml-config/174846 "2019-04-09T23:03:38Z")

</div>

Installed metricbeat-6.7.0-x86\_64.rpm on my single node ELK 6.7 server. When I go to load dashboards I get the following error: \[root@elk ~\]# /usr/share/metricbeat/bin/metricbeat -e setup --dashboards Exiting: error …

---

## [Filebeat =\> Logstash in Elastic Cloud](https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064)

<div class="topic-metadata">

**Author:** [@carlduevel](https://discuss.elastic.co/u/carlduevel)\
**Replies:** 3\
**Last updated:** [April 9, 2019, 4:49pm UTC](https://discuss.elastic.co/t/filebeat-logstash-in-elastic-cloud/176064 "2019-04-09T16:49:36Z")

</div>

I am evaluating Elastic Cloud and the preferred usage pattern would be to send log data with Filebeat to Logstash in the Cloud so we would just need to worry about Filebeat being configured the right way. In the documen…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=365)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=367)
