# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=367

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 368

---

## [Heartbeat 6.7.0 isnt updating kibana uptime endpoint count](https://discuss.elastic.co/t/heartbeat-6-7-0-isnt-updating-kibana-uptime-endpoint-count/175182)

<div class="topic-metadata">

**Author:** [@Luis\_Pereira1](https://discuss.elastic.co/u/Luis_Pereira1)\
**Replies:** 2\
**Last updated:** [April 9, 2019, 3:55pm UTC](https://discuss.elastic.co/t/heartbeat-6-7-0-isnt-updating-kibana-uptime-endpoint-count/175182 "2019-04-09T15:55:19Z")

</div>

Hello, Im trying to deploy a elastic stack on docker and im having some trouble with the heartbeat plugin. ls I have my heartbeat.yml like this: eartbeat.config.monitors: Directory + glob pattern to search for confi…

---

## [Metricbeat autodiscover's doc minor bug](https://discuss.elastic.co/t/metricbeat-autodiscovers-doc-minor-bug/174947)

<div class="topic-metadata">

**Author:** [@bce5f98666119dc29b31](https://discuss.elastic.co/u/bce5f98666119dc29b31)\
**Replies:** 3\
**Last updated:** [April 9, 2019, 2:26pm UTC](https://discuss.elastic.co/t/metricbeat-autodiscovers-doc-minor-bug/174947 "2019-04-09T14:26:06Z")

</div>

i found some error at config iterms : hosts: "{data.host}:{data.port}" , this config need to change : hosts: "{data.host}:${data.port}", if not metricbeat won't work correctly.

---

## [Error 1053: “The service did not respond in a timely fashion” when attempting to start winlogbeat service](https://discuss.elastic.co/t/error-1053-the-service-did-not-respond-in-a-timely-fashion-when-attempting-to-start-winlogbeat-service/176032)

<div class="topic-metadata">

**Author:** [@aaa111aaa](https://discuss.elastic.co/u/aaa111aaa)\
**Replies:** 0\
**Last updated:** [April 9, 2019, 1:20pm UTC](https://discuss.elastic.co/t/error-1053-the-service-did-not-respond-in-a-timely-fashion-when-attempting-to-start-winlogbeat-service/176032 "2019-04-09T13:20:47Z")

</div>

Hello all, When attempting to start the winlogbeat service in Windows I receive the following: Error 1053: "The service did not respond in a timely fashion" when attempting to start, stop or pause a service." I've suc…

---

## [Multiple Multiline pattern based on a condition](https://discuss.elastic.co/t/multiple-multiline-pattern-based-on-a-condition/176015)

<div class="topic-metadata">

**Author:** [@Abhilash\_B](https://discuss.elastic.co/u/Abhilash_B)\
**Replies:** 0\
**Last updated:** [April 9, 2019, 11:49am UTC](https://discuss.elastic.co/t/multiple-multiline-pattern-based-on-a-condition/176015 "2019-04-09T11:49:54Z")

</div>

I have two files have the same extension(.evt), but one is xml and other is a composite format mixed with key-value pairs and csv. To process xml file in logstash, I must send the whole file content as part of the messag…

---

## [Help on Cassandrabeat](https://discuss.elastic.co/t/help-on-cassandrabeat/175788)

<div class="topic-metadata">

**Author:** [@Arunlal\_A](https://discuss.elastic.co/u/Arunlal_A)\
**Replies:** 3\
**Last updated:** [April 9, 2019, 11:42am UTC](https://discuss.elastic.co/t/help-on-cassandrabeat/175788 "2019-04-09T11:42:03Z")

</div>

Hi, I am trying to configure beats for Cassandra application. I tried to configure it with Jolokia and it's not working. Also read about Cassandrabeat (This announcement) however, this also not working. Can someone help…

---

## [File beat reading logs twice based on scan frequency](https://discuss.elastic.co/t/file-beat-reading-logs-twice-based-on-scan-frequency/175840)

<div class="topic-metadata">

**Author:** [@amolp](https://discuss.elastic.co/u/amolp)\
**Replies:** 0\
**Last updated:** [April 8, 2019, 12:44pm UTC](https://discuss.elastic.co/t/file-beat-reading-logs-twice-based-on-scan-frequency/175840 "2019-04-08T12:44:19Z")

</div>

Hi, some time filebeat reading the number of logs properly and some time reading same logs twice, when I am changing scan\_frequency attribute value this is happing that's what I found but maybe I am wrong please any one…

---

## [Filebeat: unrecognized service](https://discuss.elastic.co/t/filebeat-unrecognized-service/175992)

<div class="topic-metadata">

**Author:** [@Sandip\_Giri](https://discuss.elastic.co/u/Sandip_Giri)\
**Replies:** 1\
**Last updated:** [April 9, 2019, 9:44am UTC](https://discuss.elastic.co/t/filebeat-unrecognized-service/175992 "2019-04-09T09:44:44Z")

</div>

Hi, I have installed filebeat from source using below steps : apt-get install -y golang make git && mkdir HOME/go \\ && mkdir -p {GOPATH}/src/github.com/elastic && cd ${GOPATH}/src/github.com/elastic && git clone ht…

---

## [No CPU/Mem metrics on docker module for windows](https://discuss.elastic.co/t/no-cpu-mem-metrics-on-docker-module-for-windows/175196)

<div class="topic-metadata">

**Author:** [@fpoulin09](https://discuss.elastic.co/u/fpoulin09)\
**Replies:** 1\
**Last updated:** [April 9, 2019, 9:40am UTC](https://discuss.elastic.co/t/no-cpu-mem-metrics-on-docker-module-for-windows/175196 "2019-04-09T09:40:22Z")

</div>

Hi, I'm trying to configure metric beat on windows to retrieve docker container's metrics. However, it looks like Kibana is always showing 0% for the CPU and the Memory for my Containers. I'm talking about the Infrastru…

---

## [Filebeat can't send logs after Elasticsearch cluster failure](https://discuss.elastic.co/t/filebeat-cant-send-logs-after-elasticsearch-cluster-failure/175982)

<div class="topic-metadata">

**Author:** [@gchermennov](https://discuss.elastic.co/u/gchermennov)\
**Replies:** 0\
**Last updated:** [April 9, 2019, 8:40am UTC](https://discuss.elastic.co/t/filebeat-cant-send-logs-after-elasticsearch-cluster-failure/175982 "2019-04-09T08:40:40Z")

</div>

We recently had a problem when ES cluster failed. The problem was resolved, but filebeat failed to send new data after the failure. Here's a portion of the logs - it seems to retry forever but can't send the data: …

---

## [Metricbeat Prometheus and cAdvisor](https://discuss.elastic.co/t/metricbeat-prometheus-and-cadvisor/174786)

<div class="topic-metadata">

**Author:** [@McElroy](https://discuss.elastic.co/u/McElroy)\
**Replies:** 3\
**Last updated:** [April 9, 2019, 8:33am UTC](https://discuss.elastic.co/t/metricbeat-prometheus-and-cadvisor/174786 "2019-04-09T08:33:02Z")

</div>

Hi, I let prometheus grab the data from cAdvisor and then I try to export the data to elasticsearch with metricbeat. I see some data but not everything, for example I am interested in the value container\_fs\_reads\_total …

---

## [Filebeat input rotation file](https://discuss.elastic.co/t/filebeat-input-rotation-file/175947)

<div class="topic-metadata">

**Author:** [@Yungyoung\_Ok](https://discuss.elastic.co/u/Yungyoung_Ok)\
**Replies:** 0\
**Last updated:** [April 9, 2019, 4:46am UTC](https://discuss.elastic.co/t/filebeat-input-rotation-file/175947 "2019-04-09T04:46:43Z")

</div>

Can a filebeat read a rotating file without missing or duplicate data ? example... file list log\_file1 log\_file2 When log\_file1 is full, it writes data to log\_file2. When log\_file2 is full, it writes data to log\_fi…

---

## [Include\_lines and exclude\_lines not working as expected](https://discuss.elastic.co/t/include-lines-and-exclude-lines-not-working-as-expected/175815)

<div class="topic-metadata">

**Author:** [@avj1986](https://discuss.elastic.co/u/avj1986)\
**Replies:** 1\
**Last updated:** [April 9, 2019, 3:22am UTC](https://discuss.elastic.co/t/include-lines-and-exclude-lines-not-working-as-expected/175815 "2019-04-09T03:22:00Z")

</div>

Hi, I want to exclude a few lines from logs before sending it to logstash (6.6) from Filebeat. Here is my filebeat.conf: filebeat.inputs: - type: log paths: - /Users/amit\_joshi5/ElasticData/spool/FileReader…

---

## [FileBeat log rollover](https://discuss.elastic.co/t/filebeat-log-rollover/173315)

<div class="topic-metadata">

**Author:** [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Replies:** 4\
**Last updated:** [April 9, 2019, 1:50am UTC](https://discuss.elastic.co/t/filebeat-log-rollover/173315 "2019-04-09T01:50:31Z")

</div>

We are using filebeat to get log. I recently faced an issue which is annoying me. I have the filebeat configuration as log\*.log because every time when log size reaches 10mb my application creates new log and renames th…

---

## [Problme in x-pack machine learning (how can i solve it )](https://discuss.elastic.co/t/problme-in-x-pack-machine-learning-how-can-i-solve-it/175849)

<div class="topic-metadata">

**Author:** [@Oussama\_Drioui](https://discuss.elastic.co/u/Oussama_Drioui)\
**Replies:** 1\
**Last updated:** [April 9, 2019, 1:03am UTC](https://discuss.elastic.co/t/problme-in-x-pack-machine-learning-how-can-i-solve-it/175849 "2019-04-09T01:03:35Z")

</div>

2019-04-08T15:40:23.545+0200 INFO \[publisher\] pipeline/module.go:110 Beat name: drioui-SATELLITE-L850-1VQ 2019-04-08T15:40:23.557+0200 INFO beater/filebeat.go:101 Enabled modules/filesets: suricata (eve) 2019-04-08T15:…

---

## [Logstash output: Multi-entry A record discovery](https://discuss.elastic.co/t/logstash-output-multi-entry-a-record-discovery/175907)

<div class="topic-metadata">

**Author:** [@Will\_Weber](https://discuss.elastic.co/u/Will_Weber)\
**Replies:** 0\
**Last updated:** [April 8, 2019, 7:09pm UTC](https://discuss.elastic.co/t/logstash-output-multi-entry-a-record-discovery/175907 "2019-04-08T19:09:07Z")

</div>

Apologies for the word salad of a topic name -- I'm mostly trying to figure out how to configure a set of beats systems to discover downstream Logstash servers. Unfortunately in this scenario, the beats systems are not …

---

## [Metric Beat String Monitoring](https://discuss.elastic.co/t/metric-beat-string-monitoring/173115)

<div class="topic-metadata">

**Author:** [@Duella](https://discuss.elastic.co/u/Duella)\
**Replies:** 1\
**Last updated:** [April 8, 2019, 9:14pm UTC](https://discuss.elastic.co/t/metric-beat-string-monitoring/173115 "2019-04-08T21:14:13Z")

</div>

What field in Metricbeat will be able to tell me the thread count per server or will be able to use to calculate this?

---

## [Log message truncated at 32k](https://discuss.elastic.co/t/log-message-truncated-at-32k/175604)

<div class="topic-metadata">

**Author:** [@sud7](https://discuss.elastic.co/u/sud7)\
**Replies:** 1\
**Last updated:** [April 8, 2019, 3:53pm UTC](https://discuss.elastic.co/t/log-message-truncated-at-32k/175604 "2019-04-08T15:53:07Z")

</div>

Hello Experts, We have been using filebeat on our K8s1 as a daemonset. One of our containers spits our huge amount of log and it seems only a fraction of it makes it to logstash. Upon more debugging we have seen the co…

---

## [Filebeat Stops Consuming](https://discuss.elastic.co/t/filebeat-stops-consuming/175871)

<div class="topic-metadata">

**Author:** [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Replies:** 0\
**Last updated:** [April 8, 2019, 3:21pm UTC](https://discuss.elastic.co/t/filebeat-stops-consuming/175871 "2019-04-08T15:21:23Z")

</div>

Hi, I can see Filebeat stopped consuming some log files that are not done yet. When using debug level, I can see 4 files being read (2 old ones and 2 new ones): |-08T15:23:40.795Z|DEBUG|\[input\]|log/input.go:404|Check …

---

## [Auditbeat System module: Add parent process entity\_id field to process and socket events](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610)

<div class="topic-metadata">

**Author:** [@Aaron\_Jewitt](https://discuss.elastic.co/u/Aaron_Jewitt)\
**Replies:** 7\
**Last updated:** [April 8, 2019, 3:33pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610 "2019-04-08T15:33:44Z")

</div>

Recommend adding the parent processes event\_id field to all System module process events as well as socket events. Having the parent processes event\_id in a process and socket event would be extremely useful when conduc…

---

## [Log filebeat i wana solde the problem i have this when i change the link of the log file in fileveay.yml](https://discuss.elastic.co/t/log-filebeat-i-wana-solde-the-problem-i-have-this-when-i-change-the-link-of-the-log-file-in-fileveay-yml/175869)

<div class="topic-metadata">

**Author:** [@Oussama\_Drioui](https://discuss.elastic.co/u/Oussama_Drioui)\
**Replies:** 0\
**Last updated:** [April 8, 2019, 3:18pm UTC](https://discuss.elastic.co/t/log-filebeat-i-wana-solde-the-problem-i-have-this-when-i-change-the-link-of-the-log-file-in-fileveay-yml/175869 "2019-04-08T15:18:52Z")

</div>

pipeline/output.go:100 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp 127.0.0.1:5044: connect: connection refused

---

## [Set system to maintenance in Hearbeat](https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526)

<div class="topic-metadata">

**Author:** [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Replies:** 3\
**Last updated:** [April 8, 2019, 12:38pm UTC](https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526 "2019-04-08T12:38:34Z")

</div>

Before Heartbeat was GA, I already set up a Logstash pipeline to monitor our application's HTTP endpoint for uptime/downtime/errors/... I would like to switch to Hearbeat now, so I can also easily monitor the system on …

---

## [Filebeat low performance with multiple input files](https://discuss.elastic.co/t/filebeat-low-performance-with-multiple-input-files/173933)

<div class="topic-metadata">

**Author:** [@Naxo](https://discuss.elastic.co/u/Naxo)\
**Replies:** 6\
**Last updated:** [April 8, 2019, 11:21am UTC](https://discuss.elastic.co/t/filebeat-low-performance-with-multiple-input-files/173933 "2019-04-08T11:21:48Z")

</div>

Hi everyone, I have tried several configurations in the filebeat service but I cannot see a good performance. When I use a single input file we can see a high network throutput and logstash and elasticsearch do a good d…

---

## [Assorted Filebeat problems since upgrade to 6.6.2](https://discuss.elastic.co/t/assorted-filebeat-problems-since-upgrade-to-6-6-2/175819)

<div class="topic-metadata">

**Author:** [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Replies:** 1\
**Last updated:** [April 8, 2019, 11:06am UTC](https://discuss.elastic.co/t/assorted-filebeat-problems-since-upgrade-to-6-6-2/175819 "2019-04-08T11:06:18Z")

</div>

I upgraded to 6.6.2, to get the multiline flag. Running on K8s as a daemonset, using autodiscover. Previously running, I think, 6.2.something. Since then a new problem - the one I think I care most about - is that logs …

---

## [Filebeat Log Formats](https://discuss.elastic.co/t/filebeat-log-formats/175795)

<div class="topic-metadata">

**Author:** [@johncam](https://discuss.elastic.co/u/johncam)\
**Replies:** 0\
**Last updated:** [April 8, 2019, 8:40am UTC](https://discuss.elastic.co/t/filebeat-log-formats/175795 "2019-04-08T08:40:49Z")

</div>

I am looking to ship a number of logs in non-JSON format to Logstash for parsing and transforming prior to being indexed. Is this the best approach for indexing custom log files? Would changing our existing log format …

---

## [Heartbeat Autodiscover documentation uses \`hosts\` instead of \`urls\` for HTTP](https://discuss.elastic.co/t/heartbeat-autodiscover-documentation-uses-hosts-instead-of-urls-for-http/175398)

<div class="topic-metadata">

**Author:** [@mdibaiee](https://discuss.elastic.co/u/mdibaiee)\
**Replies:** 1\
**Last updated:** [April 8, 2019, 5:42am UTC](https://discuss.elastic.co/t/heartbeat-autodiscover-documentation-uses-hosts-instead-of-urls-for-http/175398 "2019-04-08T05:42:37Z")

</div>

Hi, In the Autodiscover documentation page of Heartbeat, the example for Kubernetes uses hosts under the HTTP configuration, whereas it should be urls. I spent an hour or so digging into this. https://www.elastic.co/gu…

---

## [Results from remote systems?](https://discuss.elastic.co/t/results-from-remote-systems/174965)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [April 8, 2019, 8:36am UTC](https://discuss.elastic.co/t/results-from-remote-systems/174965 "2019-04-08T08:36:28Z")

</div>

Trying out heartbeat v6.7. Ive configured 2 files in 'modules.d' and one inline. Where should I be expecting to see results? { "monitoring": { "metrics": { "beat": { "cpu": { "system": { "ticks": 240, "time": { …

---

## [Elastic, Kibana, filebeat failed sending data to elastic](https://discuss.elastic.co/t/elastic-kibana-filebeat-failed-sending-data-to-elastic/174278)

<div class="topic-metadata">

**Author:** [@kjk](https://discuss.elastic.co/u/kjk)\
**Replies:** 5\
**Last updated:** [April 8, 2019, 8:16am UTC](https://discuss.elastic.co/t/elastic-kibana-filebeat-failed-sending-data-to-elastic/174278 "2019-04-08T08:16:30Z")

</div>

I have a problem with sending data from filebeat to elasticsearch filebeat ver. filebeat-6.6.2-linux-x86\_64 ./filebeat setup Loaded index template Loading dashboards (Kibana must be running and reachable) Loaded da…

---

## [Journalbeat and Java exceptions](https://discuss.elastic.co/t/journalbeat-and-java-exceptions/172464)

<div class="topic-metadata">

**Author:** [@igorc](https://discuss.elastic.co/u/igorc)\
**Replies:** 3\
**Last updated:** [April 8, 2019, 7:22am UTC](https://discuss.elastic.co/t/journalbeat-and-java-exceptions/172464 "2019-04-08T07:22:08Z")

</div>

Hi all, I'm trying to catch java exceptions using multiline processor as follows: journalbeat.inputs: - paths: \[\] seek: cursor include\_matches: - "syslog.identifier=tomcat" multiline: pattern: '^\\d+\\serro…

---

## [How to create multiple index from file beat log input in log-stash config](https://discuss.elastic.co/t/how-to-create-multiple-index-from-file-beat-log-input-in-log-stash-config/175144)

<div class="topic-metadata">

**Author:** [@Sharma3007](https://discuss.elastic.co/u/Sharma3007)\
**Replies:** 8\
**Last updated:** [April 8, 2019, 5:32am UTC](https://discuss.elastic.co/t/how-to-create-multiple-index-from-file-beat-log-input-in-log-stash-config/175144 "2019-04-08T05:32:44Z")

</div>

How to configure multiple log files with different name in one logstash.conf instance. I am using below configuration , with single files it is working fine ,but multiple file with different index name doesn't work. Fi…

---

## [FB-5.4 with ES-6.6 and above?](https://discuss.elastic.co/t/fb-5-4-with-es-6-6-and-above/175758)

<div class="topic-metadata">

**Author:** [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Replies:** 0\
**Last updated:** [April 8, 2019, 5:29am UTC](https://discuss.elastic.co/t/fb-5-4-with-es-6-6-and-above/175758 "2019-04-08T05:29:26Z")

</div>

Hi, Currently we are using below stack in our application monitoring. FB-5.4 ES-LS-6.3. If we want to use ES-6.6 and above. Do we need to upgrade our Filebeat too? We have around 100+ clients sending data to LS-6.3.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=366)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=368)
