# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=368

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 369

---

## [Unable to get the multiline log using the multilie.pattern in filebeat.yml which is running on windows 2012 server](https://discuss.elastic.co/t/unable-to-get-the-multiline-log-using-the-multilie-pattern-in-filebeat-yml-which-is-running-on-windows-2012-server/175747)

<div class="topic-metadata">

**Author:** [@shub8050](https://discuss.elastic.co/u/shub8050)\
**Replies:** 0\
**Last updated:** [April 8, 2019, 3:37am UTC](https://discuss.elastic.co/t/unable-to-get-the-multiline-log-using-the-multilie-pattern-in-filebeat-yml-which-is-running-on-windows-2012-server/175747 "2019-04-08T03:37:28Z")

</div>

I have an ELK stack running on ubuntu server. I want to get the logs from one of my windows server where the filebeat is running. I have tried everything but Iam unable to get the log which is of multiple lines. Also not…

---

## [How to transfer one elasticsearch data to another elasticsearch by using filebeat as a middleware?](https://discuss.elastic.co/t/how-to-transfer-one-elasticsearch-data-to-another-elasticsearch-by-using-filebeat-as-a-middleware/175664)

<div class="topic-metadata">

**Author:** [@Mohan\_Selvam](https://discuss.elastic.co/u/Mohan_Selvam)\
**Replies:** 4\
**Last updated:** [April 7, 2019, 10:36am UTC](https://discuss.elastic.co/t/how-to-transfer-one-elasticsearch-data-to-another-elasticsearch-by-using-filebeat-as-a-middleware/175664 "2019-04-07T10:36:21Z")

</div>

I am having two elasticsearch with different versions, one is development and another one is production, so now i need to transfer the live data of production to development elasticsearch, so is anyway to achieve this by…

---

## [Elasticsearch not receiving ForwardedEvents](https://discuss.elastic.co/t/elasticsearch-not-receiving-forwardedevents/175507)

<div class="topic-metadata">

**Author:** [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Replies:** 1\
**Last updated:** [April 6, 2019, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-not-receiving-forwardedevents/175507 "2019-04-06T18:48:44Z")

</div>

Collector on Server 2016 and ElasticStack 6.7 All events appear to be coming into the ForwardedEvents on the Collector, all that seems to work OK. And I know it's coming through the logstash pipe because it set up my i…

---

## [Tls verification\_mode, custom validation options?](https://discuss.elastic.co/t/tls-verification-mode-custom-validation-options/171532)

<div class="topic-metadata">

**Author:** [@matp](https://discuss.elastic.co/u/matp)\
**Replies:** 3\
**Last updated:** [April 5, 2019, 5:20pm UTC](https://discuss.elastic.co/t/tls-verification-mode-custom-validation-options/171532 "2019-04-05T17:20:24Z")

</div>

https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#\_literal\_verification\_mode\_literal As I understand it, if verification\_mode is set to full, then the beats client will error if the hostname …

---

## [Filebeat 6.7.1 high CPU usage](https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493)

<div class="topic-metadata">

**Author:** [@mlaterman](https://discuss.elastic.co/u/mlaterman)\
**Replies:** 3\
**Last updated:** [April 5, 2019, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-6-7-1-high-cpu-usage/175493 "2019-04-05T15:58:45Z")

</div>

I'm observing high CPU utilization with filebeat in trivial cases when running on Amazon Linux Given a fresh install of filebeat with the config: filebeat.inputs: - paths: \[/var/log/testlog\] type: log logging.level: …

---

## [How to change the content of message field](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510)

<div class="topic-metadata">

**Author:** [@savitaashture](https://discuss.elastic.co/u/savitaashture)\
**Replies:** 6\
**Last updated:** [April 5, 2019, 2:00pm UTC](https://discuss.elastic.co/t/how-to-change-the-content-of-message-field/175510 "2019-04-05T14:00:08Z")

</div>

Hi All, Input log content: {"time": "2019-04-03T23:35:17.751Z","stream":"stdout","log":"message content information\\n"} console output: { "@timestamp": "2019-04-05T04:21:57.239Z", "@metadata": { "beat": "filebeat"…

---

## [Specify multiline prospector and pipeline for elasticsearch output](https://discuss.elastic.co/t/specify-multiline-prospector-and-pipeline-for-elasticsearch-output/175445)

<div class="topic-metadata">

**Author:** [@thola](https://discuss.elastic.co/u/thola)\
**Replies:** 2\
**Last updated:** [April 5, 2019, 12:26pm UTC](https://discuss.elastic.co/t/specify-multiline-prospector-and-pipeline-for-elasticsearch-output/175445 "2019-04-05T12:26:27Z")

</div>

I am new to filebeat and would like to set up a prospector reading a log file in which one entry is of the following form of a http request and response. It is multiline and i am not sure how to specify, that the \[RESPON…

---

## [Why does the decode\_json\_fields processor not have a keys\_under\_root option?](https://discuss.elastic.co/t/why-does-the-decode-json-fields-processor-not-have-a-keys-under-root-option/175542)

<div class="topic-metadata">

**Author:** [@thola](https://discuss.elastic.co/u/thola)\
**Replies:** 2\
**Last updated:** [April 5, 2019, 12:07pm UTC](https://discuss.elastic.co/t/why-does-the-decode-json-fields-processor-not-have-a-keys-under-root-option/175542 "2019-04-05T12:07:46Z")

</div>

I want to parse logs in the following format. But what confuses me is that i have to specify fields for the decode\_json\_fields processor under which to find json strings. But what if there is no outer field for the json?…

---

## [New \`add\_lxc\_metadata\` processor for adding LXC container ID](https://discuss.elastic.co/t/new-add-lxc-metadata-processor-for-adding-lxc-container-id/175166)

<div class="topic-metadata">

**Author:** [@907th](https://discuss.elastic.co/u/907th)\
**Replies:** 1\
**Last updated:** [April 5, 2019, 11:14am UTC](https://discuss.elastic.co/t/new-add-lxc-metadata-processor-for-adding-lxc-container-id/175166 "2019-04-05T11:14:34Z")

</div>

Hello! I want to audit system events which happen inside LXC containers. Is it able to do with Auditbeat?

---

## [Filebeat hints-based autodiscover for JSON encoded logs](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-for-json-encoded-logs/175571)

<div class="topic-metadata">

**Author:** [@rmetzler](https://discuss.elastic.co/u/rmetzler)\
**Replies:** 0\
**Last updated:** [April 5, 2019, 10:36am UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-for-json-encoded-logs/175571 "2019-04-05T10:36:24Z")

</div>

Hi, I'm trying to set up autodiscovery in Kubernetes for Filebeat. There is a DaemonSet running Filebeat on each node, logging into ElasticSearch. Hints based autodiscovery works well for HAProxy and nginx Containers/P…

---

## [Error while installing filebeat](https://discuss.elastic.co/t/error-while-installing-filebeat/175174)

<div class="topic-metadata">

**Author:** [@Neha\_Jain](https://discuss.elastic.co/u/Neha_Jain)\
**Replies:** 1\
**Last updated:** [April 5, 2019, 10:01am UTC](https://discuss.elastic.co/t/error-while-installing-filebeat/175174 "2019-04-05T10:01:00Z")

</div>

I am getting following error while running command .\\filebeat -e ERROR fileset/factory.go:105 Error creating input: No paths were defined for input ac cessing config Elasticsearch - 6.5.4 searchguard - search-guar…

---

## [Sync data between MongoDB Atlas and Elastic search using logstash module](https://discuss.elastic.co/t/sync-data-between-mongodb-atlas-and-elastic-search-using-logstash-module/174253)

<div class="topic-metadata">

**Author:** [@vishal.k](https://discuss.elastic.co/u/vishal.k)\
**Replies:** 1\
**Last updated:** [April 5, 2019, 9:22am UTC](https://discuss.elastic.co/t/sync-data-between-mongodb-atlas-and-elastic-search-using-logstash-module/174253 "2019-04-05T09:22:58Z")

</div>

Hello, I wanted sync data between MongoDB Atlas and Elasticsearch (cloud) using logstash module, however I'm not finding any good way to do so. I tried using mongodb-connector however there are some SSL handshake issue…

---

## [Filebeat Input docker on stopped containers](https://discuss.elastic.co/t/filebeat-input-docker-on-stopped-containers/175371)

<div class="topic-metadata">

**Author:** [@Anatoliy](https://discuss.elastic.co/u/Anatoliy)\
**Replies:** 1\
**Last updated:** [April 5, 2019, 9:00am UTC](https://discuss.elastic.co/t/filebeat-input-docker-on-stopped-containers/175371 "2019-04-05T09:00:18Z")

</div>

I configured filebeat with type docker and everything workes well on runnig containers and new started. Also i got in logstash.conf Output to file and elasticsearch. filebeat.autodiscover: providers: - type: docke…

---

## [Parsing message with filebeat](https://discuss.elastic.co/t/parsing-message-with-filebeat/175367)

<div class="topic-metadata">

**Author:** [@Christophe](https://discuss.elastic.co/u/Christophe)\
**Replies:** 1\
**Last updated:** [April 5, 2019, 7:10am UTC](https://discuss.elastic.co/t/parsing-message-with-filebeat/175367 "2019-04-05T07:10:37Z")

</div>

Dear all, I installed filebeat on my server, and it's configured to read the auth.log file. The information in the auth.log file is sending to ELK. In Kibana I have a JSON message with a label message. This label is a…

---

## [Issue with the fileds.env value](https://discuss.elastic.co/t/issue-with-the-fileds-env-value/175216)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 4\
**Last updated:** [April 5, 2019, 5:07am UTC](https://discuss.elastic.co/t/issue-with-the-fileds-env-value/175216 "2019-04-05T05:07:08Z")

</div>

Hi I have been installing beats by categorizing then with a field value. I used integer value on all my beats. Now when I am trying to use a string value I see errors. fields: env: 10.6 Can I not use multiple data t…

---

## [Filebeat not closing the handler when a file is rolled over](https://discuss.elastic.co/t/filebeat-not-closing-the-handler-when-a-file-is-rolled-over/175505)

<div class="topic-metadata">

**Author:** [@DebG](https://discuss.elastic.co/u/DebG)\
**Replies:** 0\
**Last updated:** [April 5, 2019, 4:14am UTC](https://discuss.elastic.co/t/filebeat-not-closing-the-handler-when-a-file-is-rolled-over/175505 "2019-04-05T04:14:41Z")

</div>

Hi, In my environment, I have installed Filebeat 6.6. I have a huge volume of log files written and with log roll over policy on, I see the files are being created as serviceaudit.log.0, serviceaudit.log.1, and so on (h…

---

## [Unable to build packetbeat on macOS](https://discuss.elastic.co/t/unable-to-build-packetbeat-on-macos/175271)

<div class="topic-metadata">

**Author:** [@mikemadden42](https://discuss.elastic.co/u/mikemadden42)\
**Replies:** 3\
**Last updated:** [April 4, 2019, 5:23pm UTC](https://discuss.elastic.co/t/unable-to-build-packetbeat-on-macos/175271 "2019-04-04T17:23:20Z")

</div>

Is anyone else running into issues building packetbeat on macOS? I'm running into the following issue on the master & 7.0 branch. packetbeat(master): go version go version go1.12.1 darwin/amd64 packetbeat(master): mage…

---

## [\[AWS\] CloudFormation Stack Resource Limits](https://discuss.elastic.co/t/aws-cloudformation-stack-resource-limits/175453)

<div class="topic-metadata">

**Author:** [@mtrspringer](https://discuss.elastic.co/u/mtrspringer)\
**Replies:** 0\
**Last updated:** [April 4, 2019, 4:58pm UTC](https://discuss.elastic.co/t/aws-cloudformation-stack-resource-limits/175453 "2019-04-04T16:58:59Z")

</div>

I am currently testing out Functionbeat for forwarding CloudWatch logs to my Logstash service. From what I have gathered, under the hood Functionbeat is generating a CloudFormation stack template for all necessary resou…

---

## [Filebeat 6.7.0 not working with AWS Elasticsearch](https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407)

<div class="topic-metadata">

**Author:** [@MarekObu](https://discuss.elastic.co/u/MarekObu)\
**Replies:** 3\
**Last updated:** [April 4, 2019, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407 "2019-04-04T14:06:51Z")

</div>

After upgrading filebeat to 6.7.0, I've noticed that it doesn't ship logs anymore. I'm using AWS managed Elasticsearch, which does not provide license information. Related to: https://github.com/elastic/beats/pull/11296 …

---

## [SELinux policy for auditbeat](https://discuss.elastic.co/t/selinux-policy-for-auditbeat/175377)

<div class="topic-metadata">

**Author:** [@elm.mehdi](https://discuss.elastic.co/u/elm.mehdi)\
**Replies:** 0\
**Last updated:** [April 4, 2019, 10:09am UTC](https://discuss.elastic.co/t/selinux-policy-for-auditbeat/175377 "2019-04-04T10:09:40Z")

</div>

Hi, I'm working with auditbeat in our SELinux prod environment. I noticed that we are missing à selinux policy for auditbeat. Is Auditbeat support selinux ? Is there a developed policy for ? Kind regards, El Mehdi C…

---

## [Working with filebeat and Winlogbeat at the same time](https://discuss.elastic.co/t/working-with-filebeat-and-winlogbeat-at-the-same-time/175209)

<div class="topic-metadata">

**Author:** [@WarriorHarb](https://discuss.elastic.co/u/WarriorHarb)\
**Replies:** 1\
**Last updated:** [April 4, 2019, 9:20am UTC](https://discuss.elastic.co/t/working-with-filebeat-and-winlogbeat-at-the-same-time/175209 "2019-04-04T09:20:30Z")

</div>

Hello, So i had configured Filebeat to forward data to Logstash via port 5044 and data has to go through Grok filter (that contains a drop condition ) if "\_grokparsefailure" in \[tags\] { drop {} } it is working fine …

---

## [Unable exclude files](https://discuss.elastic.co/t/unable-exclude-files/174704)

<div class="topic-metadata">

**Author:** [@yagami23](https://discuss.elastic.co/u/yagami23)\
**Replies:** 4\
**Last updated:** [April 4, 2019, 8:08am UTC](https://discuss.elastic.co/t/unable-exclude-files/174704 "2019-04-04T08:08:36Z")

</div>

Hi, i using Filebeat 6.5.4, below is my filebeat content, the problem is those path stated in the "exclude files" are not being ignore, the filebeat still pick up the files under those path, any advise ? /opt/apps/logs/…

---

## [Filebeat-6.7.0 on windows IIS module](https://discuss.elastic.co/t/filebeat-6-7-0-on-windows-iis-module/175338)

<div class="topic-metadata">

**Author:** [@Michalis\_Kyprianou](https://discuss.elastic.co/u/Michalis_Kyprianou)\
**Replies:** 0\
**Last updated:** [April 4, 2019, 7:33am UTC](https://discuss.elastic.co/t/filebeat-6-7-0-on-windows-iis-module/175338 "2019-04-04T07:33:14Z")

</div>

Hi all we have installed filebeat 6.7.0 on windows server running iis which we need to monitoring logs. filebeat settings filebeat.inputs: type: log enabled: false paths: #- /var/log/\*.log #- c:\\programdata\\el…

---

## [Changing index template settings from default](https://discuss.elastic.co/t/changing-index-template-settings-from-default/175273)

<div class="topic-metadata">

**Author:** [@jkaoiadjmdna](https://discuss.elastic.co/u/jkaoiadjmdna)\
**Replies:** 0\
**Last updated:** [April 3, 2019, 8:53pm UTC](https://discuss.elastic.co/t/changing-index-template-settings-from-default/175273 "2019-04-03T20:53:06Z")

</div>

I'd like to adjust the defaults on the generally default configuration of filebeat to reduce shards from the default of 5 to 1. Do I need to configure filebeats for this change to apply going forward, or can I do this u…

---

## [Which Beats are experimental](https://discuss.elastic.co/t/which-beats-are-experimental/175247)

<div class="topic-metadata">

**Author:** [@Phillip\_Groven](https://discuss.elastic.co/u/Phillip_Groven)\
**Replies:** 1\
**Last updated:** [April 3, 2019, 8:46pm UTC](https://discuss.elastic.co/t/which-beats-are-experimental/175247 "2019-04-03T20:46:06Z")

</div>

elastic.co has the following beats on their page Filebeat Metric Packetbeat Winlogbeat Auditbeat Hearbeat FunctionBeat I assume any other beats are experimental . Is that correct? I installed journalbeats and it…

---

## [Filebeat on AWS EKS worker node](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347)

<div class="topic-metadata">

**Author:** [@reenrik](https://discuss.elastic.co/u/reenrik)\
**Replies:** 4\
**Last updated:** [April 3, 2019, 7:45pm UTC](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347 "2019-04-03T19:45:50Z")

</div>

I'm an Elastic Cloud subscriber. We are standing up an EKS cluster on AWS, but would like to have filebeat exist outside of Kubernetes, directly on the worker node. I'm having some trouble understanding what to put in t…

---

## [Filebeat is not shipping all pod logs for deployment on kubernetes](https://discuss.elastic.co/t/filebeat-is-not-shipping-all-pod-logs-for-deployment-on-kubernetes/175187)

<div class="topic-metadata">

**Author:** [@venkat\_rebaca](https://discuss.elastic.co/u/venkat_rebaca)\
**Replies:** 0\
**Last updated:** [April 3, 2019, 12:04pm UTC](https://discuss.elastic.co/t/filebeat-is-not-shipping-all-pod-logs-for-deployment-on-kubernetes/175187 "2019-04-03T12:04:00Z")

</div>

Hi All, I was trying to ship all application logs inside all pods for a deployment on kubernetes setup using filebeat daemonset. Configuration: apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config names…

---

## [Autodiscover questions](https://discuss.elastic.co/t/autodiscover-questions/175154)

<div class="topic-metadata">

**Author:** [@jof300](https://discuss.elastic.co/u/jof300)\
**Replies:** 1\
**Last updated:** [April 3, 2019, 4:04pm UTC](https://discuss.elastic.co/t/autodiscover-questions/175154 "2019-04-03T16:04:44Z")

</div>

Hi, I was wondering how filebeat collects containers logs when filebeat is also a container? Are logs read from a path ? Are logs pulled from container (ex : nginx) and sent to filebeat? Should volumes (/var/run/dock…

---

## [Multiline patter not working for filebeat](https://discuss.elastic.co/t/multiline-patter-not-working-for-filebeat/175165)

<div class="topic-metadata">

**Author:** [@kumarvivek633](https://discuss.elastic.co/u/kumarvivek633)\
**Replies:** 1\
**Last updated:** [April 3, 2019, 3:56pm UTC](https://discuss.elastic.co/t/multiline-patter-not-working-for-filebeat/175165 "2019-04-03T15:56:34Z")

</div>

I am using filebeat to ship data to logstash but my multiline pattern i s not working as expected. paths: - D:/talent\_log.log fields: application: log-tc-local tags: \["tc"\] include\_lines: \['.ERROR.'\] multiline.pa…

---

## [Starting Beats on bootup with SystemD](https://discuss.elastic.co/t/starting-beats-on-bootup-with-systemd/175195)

<div class="topic-metadata">

**Author:** [@cgfrost](https://discuss.elastic.co/u/cgfrost)\
**Replies:** 0\
**Last updated:** [April 3, 2019, 12:40pm UTC](https://discuss.elastic.co/t/starting-beats-on-bootup-with-systemd/175195 "2019-04-03T12:40:35Z")

</div>

I believe I've found a problem where the default install of a Beat on a Linux system that uses Systemd, it won't register itself properly to be enabled at startup. I'm not super familiar with Systemd please forgive me if…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=367)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=369)
