# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=369

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 370

---

## [Multiline Filebeat](https://discuss.elastic.co/t/multiline-filebeat/174817)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 4\
**Last updated:** [April 3, 2019, 11:39am UTC](https://discuss.elastic.co/t/multiline-filebeat/174817 "2019-04-03T11:39:48Z")

</div>

Hi all! HELP PLEASE! :slight\_smile: I have a log file, each "log" consists of 4 lines and is separated by \*\* Alert. \[Simple enough\] Can somebody try to explain why this is not working?? Example Log: \*\* Alert 1554131…

---

## [Low disk watermark exceeded](https://discuss.elastic.co/t/low-disk-watermark-exceeded/170663)

<div class="topic-metadata">

**Author:** [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Replies:** 8\
**Last updated:** [April 3, 2019, 4:29am UTC](https://discuss.elastic.co/t/low-disk-watermark-exceeded/170663 "2019-04-03T04:29:37Z")

</div>

Hello, I have installed Elasticsearch, Kibana and filebeat 6.5.4. I am planning to fetch Windows logs and logs from a custom directory. I have been successful in doing this but with some issues. Issue 1: \[2019-03-04T…

---

## [How can I create Unique IP map from user defined log file(Wildify,Redhat jboss)?](https://discuss.elastic.co/t/how-can-i-create-unique-ip-map-from-user-defined-log-file-wildify-redhat-jboss/175061)

<div class="topic-metadata">

**Author:** [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Replies:** 0\
**Last updated:** [April 2, 2019, 7:40pm UTC](https://discuss.elastic.co/t/how-can-i-create-unique-ip-map-from-user-defined-log-file-wildify-redhat-jboss/175061 "2019-04-02T19:40:33Z")

</div>

Hi I am very new to Elasticsearh and kibana, however started to like this product. I am using Wildify (Redhat Jboss) , so it has bellow type log where source IP is listed "\[45.30.200.104\]" , i want to create a Uniqu…

---

## [How to constrain Filebeat to only ship logs if they contain a specific field?](https://discuss.elastic.co/t/how-to-constrain-filebeat-to-only-ship-logs-if-they-contain-a-specific-field/174883)

<div class="topic-metadata">

**Author:** [@zimmertr](https://discuss.elastic.co/u/zimmertr)\
**Replies:** 3\
**Last updated:** [April 2, 2019, 11:41pm UTC](https://discuss.elastic.co/t/how-to-constrain-filebeat-to-only-ship-logs-if-they-contain-a-specific-field/174883 "2019-04-02T23:41:37Z")

</div>

I’m trying to collect logs from Kubernetes nodes using Filebeat and ONLY ship them to ELK IF the logs originate from a specific Kubernetes Namespace. So far I’ve discovered that you can define Processors which I think a…

---

## [Heartbeat Monitor for Oracle DB Connection?](https://discuss.elastic.co/t/heartbeat-monitor-for-oracle-db-connection/174847)

<div class="topic-metadata">

**Author:** [@Matt\_Vasquez](https://discuss.elastic.co/u/Matt_Vasquez)\
**Replies:** 1\
**Last updated:** [April 2, 2019, 6:44pm UTC](https://discuss.elastic.co/t/heartbeat-monitor-for-oracle-db-connection/174847 "2019-04-02T18:44:46Z")

</div>

Does anyone know how to setup a Heartbeat monitor for a Oracle Database Connection? This is what I have setup which is not working: heartbeat.monitors: - type: tcp schedule: "@Every 10 sec" hosts: \["192.168.1.101:…

---

## [Filebeat checking for x-pack despite monitoring disabled](https://discuss.elastic.co/t/filebeat-checking-for-x-pack-despite-monitoring-disabled/174836)

<div class="topic-metadata">

**Author:** [@elizajanus](https://discuss.elastic.co/u/elizajanus)\
**Replies:** 6\
**Last updated:** [April 2, 2019, 5:06pm UTC](https://discuss.elastic.co/t/filebeat-checking-for-x-pack-despite-monitoring-disabled/174836 "2019-04-02T17:06:36Z")

</div>

Filebeat is failing to connect to Elasticsearch only in dev, despite having the same config as prod. The ping to the ES host returns a 200, but Filebeat is then attempting to connect to an x-pack endpoint, even though AW…

---

## [Auditbeat system module fails to start](https://discuss.elastic.co/t/auditbeat-system-module-fails-to-start/173582)

<div class="topic-metadata">

**Author:** [@Owdaan](https://discuss.elastic.co/u/Owdaan)\
**Replies:** 5\
**Last updated:** [April 2, 2019, 3:22pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-fails-to-start/173582 "2019-04-02T15:22:24Z")

</div>

I'm trying to get system module of Auditbeat to work with no success. When I start Auditbeat it throws an error: 2019-03-23T09:05:16.523+0100 ERROR instance/beat.go:911 Exiting: 1 error: no metricsets configured for mod…

---

## [Filebeat 6.7.0 not pushing logs to Elasticsearch 6.7.0 after upgrade](https://discuss.elastic.co/t/filebeat-6-7-0-not-pushing-logs-to-elasticsearch-6-7-0-after-upgrade/174365)

<div class="topic-metadata">

**Author:** [@a14b6b031b49e3a61207](https://discuss.elastic.co/u/a14b6b031b49e3a61207)\
**Replies:** 5\
**Last updated:** [April 2, 2019, 3:13pm UTC](https://discuss.elastic.co/t/filebeat-6-7-0-not-pushing-logs-to-elasticsearch-6-7-0-after-upgrade/174365 "2019-04-02T15:13:37Z")

</div>

Filebeat stopped working after upgrading from 6.6.2 to 6.7.0 My Filebeat configuration is: filebeat.inputs: - type: log enabled: true paths: - /var/www/current/log/production.log - /var/www/current/log/api\_…

---

## [Using Logstash output for data and Elasticsearch output for x-pack monitoring](https://discuss.elastic.co/t/using-logstash-output-for-data-and-elasticsearch-output-for-x-pack-monitoring/174992)

<div class="topic-metadata">

**Author:** [@matthenning](https://discuss.elastic.co/u/matthenning)\
**Replies:** 0\
**Last updated:** [April 2, 2019, 12:56pm UTC](https://discuss.elastic.co/t/using-logstash-output-for-data-and-elasticsearch-output-for-x-pack-monitoring/174992 "2019-04-02T12:56:14Z")

</div>

Is there a way to use the Logstash output to transmit data collected by the beat and still configure x-pack monitoring? Currently x-pack monitoring only supports sending data to Elasticsearch directly which means I have…

---

## [IIS Filebeat module exclude\_lines not working](https://discuss.elastic.co/t/iis-filebeat-module-exclude-lines-not-working/174961)

<div class="topic-metadata">

**Author:** [@Darren\_Mansell](https://discuss.elastic.co/u/Darren_Mansell)\
**Replies:** 3\
**Last updated:** [April 2, 2019, 12:16pm UTC](https://discuss.elastic.co/t/iis-filebeat-module-exclude-lines-not-working/174961 "2019-04-02T12:16:49Z")

</div>

Hi. This is a simple install of filebeat 6.6.1 on windows. I've enabled the IIS module and set the location so it doesn't pick up the FTP logs and have grok failures. I also need it to ignore certain lines which contain…

---

## [Specific Message Format Creation](https://discuss.elastic.co/t/specific-message-format-creation/174930)

<div class="topic-metadata">

**Author:** [@osamaikhlas](https://discuss.elastic.co/u/osamaikhlas)\
**Replies:** 1\
**Last updated:** [April 2, 2019, 11:57am UTC](https://discuss.elastic.co/t/specific-message-format-creation/174930 "2019-04-02T11:57:09Z")

</div>

I have logs in which I want specific chunks of log but there is no specific string with which it starts or end so i'm having trouble to create pattern in filebeat. so is there any way to store those specific chunks will…

---

## [Filebeat modules timestamp issue at elasticsearch end](https://discuss.elastic.co/t/filebeat-modules-timestamp-issue-at-elasticsearch-end/174925)

<div class="topic-metadata">

**Author:** [@vsalunkhe](https://discuss.elastic.co/u/vsalunkhe)\
**Replies:** 1\
**Last updated:** [April 2, 2019, 11:53am UTC](https://discuss.elastic.co/t/filebeat-modules-timestamp-issue-at-elasticsearch-end/174925 "2019-04-02T11:53:28Z")

</div>

Hi, I have a server which serves two purposes: Mail server Normal Linux Server I need to monitor the syslog messages for Mail Server and also need to enable the filebeat System modules to monitor System and Auth Mess…

---

## [Multiple Thread for ingesting a single file filebeat](https://discuss.elastic.co/t/multiple-thread-for-ingesting-a-single-file-filebeat/174915)

<div class="topic-metadata">

**Author:** [@osamaikhlas](https://discuss.elastic.co/u/osamaikhlas)\
**Replies:** 1\
**Last updated:** [April 2, 2019, 11:49am UTC](https://discuss.elastic.co/t/multiple-thread-for-ingesting-a-single-file-filebeat/174915 "2019-04-02T11:49:09Z")

</div>

File size which i am ingesting through filebeat to Elasticsearch is about 70 GB per day but it takes whole day to upload data to elasticsearch is there is any possibility to increase the threads to read a single file or…

---

## [\[AWS\] Functionbeat: no function are enabled for selected provider: 'aws'](https://discuss.elastic.co/t/aws-functionbeat-no-function-are-enabled-for-selected-provider-aws/174388)

<div class="topic-metadata">

**Author:** [@stazio](https://discuss.elastic.co/u/stazio)\
**Replies:** 7\
**Last updated:** [April 2, 2019, 11:43am UTC](https://discuss.elastic.co/t/aws-functionbeat-no-function-are-enabled-for-selected-provider-aws/174388 "2019-04-02T11:43:37Z")

</div>

Hi All, I'm in the process of trying to configure Functionbeat (following the release of ELK 6.7) to ship RDS alert logs, via cloudwatch logs, to my ELK stack. I have successfully created the S3 bucket and deployed the…

---

## [How to get logs of company in one system?](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904)

<div class="topic-metadata">

**Author:** [@Kajol\_Nimesh](https://discuss.elastic.co/u/Kajol_Nimesh)\
**Replies:** 4\
**Last updated:** [April 2, 2019, 10:18am UTC](https://discuss.elastic.co/t/how-to-get-logs-of-company-in-one-system/172904 "2019-04-02T10:18:00Z")

</div>

Hi, I'm new to ELK Stack and I want to know that how can I get logs of multiple systems of company on my system. Do I need to install filebeat or Winlogbeat on each system or is there any other way to do it? I'm unable …

---

## [Setup index template only for the fields of the enabled modules](https://discuss.elastic.co/t/setup-index-template-only-for-the-fields-of-the-enabled-modules/174565)

<div class="topic-metadata">

**Author:** [@kostja79](https://discuss.elastic.co/u/kostja79)\
**Replies:** 0\
**Last updated:** [March 29, 2019, 4:01pm UTC](https://discuss.elastic.co/t/setup-index-template-only-for-the-fields-of-the-enabled-modules/174565 "2019-03-29T16:01:05Z")

</div>

Hi, the setup of the index template for the Beats generates a lot of fields (e.g. 1860 for Metricbeat). Many fields are designed only for specific modules that I am not planning to use, so I'd like to avoid to load the…

---

## [Beats Management - SSL Configuration in Logstash Output](https://discuss.elastic.co/t/beats-management-ssl-configuration-in-logstash-output/174552)

<div class="topic-metadata">

**Author:** [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Replies:** 3\
**Last updated:** [April 2, 2019, 3:45am UTC](https://discuss.elastic.co/t/beats-management-ssl-configuration-in-logstash-output/174552 "2019-04-02T03:45:38Z")

</div>

Hi, I have 2 questions about Beat Central Management in Kibana UI. Brief explanation: I have 5 Logstash servers, all using SSL config, and I am exploring capability on Beat Central Management. Questions: Would you…

---

## [Multipleline pattern not working](https://discuss.elastic.co/t/multipleline-pattern-not-working/174451)

<div class="topic-metadata">

**Author:** [@yagami23](https://discuss.elastic.co/u/yagami23)\
**Replies:** 3\
**Last updated:** [April 2, 2019, 12:26am UTC](https://discuss.elastic.co/t/multipleline-pattern-not-working/174451 "2019-04-02T00:26:19Z")

</div>

Hi, i would like to separate the log below in to 2 event , but the multiple line pattern fails to do that, any help appreciated \[2019-03-28T20:16:55.092-05:00\] \[soa\_server2\] \[NOTIFICATION\] \[oracle.integration.platform…

---

## [Error connecting to Elasticsearch after upgrading to Heartbeat v6.7.0](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-after-upgrading-to-heartbeat-v6-7-0/174623)

<div class="topic-metadata">

**Author:** [@aburck](https://discuss.elastic.co/u/aburck)\
**Replies:** 2\
**Last updated:** [April 2, 2019, 12:05am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-after-upgrading-to-heartbeat-v6-7-0/174623 "2019-04-02T00:05:30Z")

</div>

I recently attempted to update one of my servers running Heartbeat v6.6.2 to v6.7.0 and started receiving the following error message: INFO pipeline/output.go:95 Connecting to backoff(elasticsearch(https://elastic…

---

## [Can I install multiple agents (Metricbeat, Packetbeat or Filebeat) on one node?](https://discuss.elastic.co/t/can-i-install-multiple-agents-metricbeat-packetbeat-or-filebeat-on-one-node/172218)

<div class="topic-metadata">

**Author:** [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)\
**Replies:** 2\
**Last updated:** [April 1, 2019, 11:56pm UTC](https://discuss.elastic.co/t/can-i-install-multiple-agents-metricbeat-packetbeat-or-filebeat-on-one-node/172218 "2019-04-01T23:56:17Z")

</div>

Hi, Just a quick question, i'm wondering, if i have a Kibana server, is it possible to install few agents and point them to different server? Thanks! Lee Weng Sheng

---

## [Custom Fields with Module Config](https://discuss.elastic.co/t/custom-fields-with-module-config/174601)

<div class="topic-metadata">

**Author:** [@mattz](https://discuss.elastic.co/u/mattz)\
**Replies:** 2\
**Last updated:** [April 1, 2019, 6:02pm UTC](https://discuss.elastic.co/t/custom-fields-with-module-config/174601 "2019-04-01T18:02:29Z")

</div>

Is it possible to use custom fields within module config file? What is the appropriate hierarchy? For example in apache2 module - module: apache2 access: enabled: true var.paths: \["/var/log/apache2/access.log…

---

## [Failure with package dataset](https://discuss.elastic.co/t/failure-with-package-dataset/174816)

<div class="topic-metadata">

**Author:** [@olatunde.tokun](https://discuss.elastic.co/u/olatunde.tokun)\
**Replies:** 1\
**Last updated:** [April 1, 2019, 5:55pm UTC](https://discuss.elastic.co/t/failure-with-package-dataset/174816 "2019-04-01T17:55:32Z")

</div>

I recently upgraded to auditbeat version 6.7.0 on our fleet of linux servers to test functionality of the newly added system datasets. Every other dataset works pretty well except for package I get an error for failures…

---

## [Auid value not set properly](https://discuss.elastic.co/t/auid-value-not-set-properly/174553)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 1\
**Last updated:** [April 1, 2019, 3:19pm UTC](https://discuss.elastic.co/t/auid-value-not-set-properly/174553 "2019-04-01T15:19:59Z")

</div>

The auid field is set to "unset" in many documents. A sample document is here. Here in the "message" field there is value for auid. but in the parsed section, the auid is set as "unset". { "process": { …

---

## [Event id processor fails to start service](https://discuss.elastic.co/t/event-id-processor-fails-to-start-service/174545)

<div class="topic-metadata">

**Author:** [@Eric\_Bonjour](https://discuss.elastic.co/u/Eric_Bonjour)\
**Replies:** 2\
**Last updated:** [April 1, 2019, 3:14pm UTC](https://discuss.elastic.co/t/event-id-processor-fails-to-start-service/174545 "2019-04-01T15:14:58Z")

</div>

I'm trying to follow the configuration that is detailed on this page - https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html. I am running winlogbeat version 6.2.3 I have the fo…

---

## [\[IIS 7.5\] \[Filebeat 6.6.1\] Provided Grok expressions do not match field value](https://discuss.elastic.co/t/iis-7-5-filebeat-6-6-1-provided-grok-expressions-do-not-match-field-value/171730)

<div class="topic-metadata">

**Author:** [@nyarlath](https://discuss.elastic.co/u/nyarlath)\
**Replies:** 10\
**Last updated:** [April 1, 2019, 3:02pm UTC](https://discuss.elastic.co/t/iis-7-5-filebeat-6-6-1-provided-grok-expressions-do-not-match-field-value/171730 "2019-04-01T15:02:49Z")

</div>

Hello all, This is giving me headaches. I know there is a lot of posts regarding this issue, but I did not find any real solution. I'll try to be as comprehensive as possible. I want to send logs directly to Elastic f…

---

## [File integrity module not capturing user data](https://discuss.elastic.co/t/file-integrity-module-not-capturing-user-data/174099)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 1\
**Last updated:** [April 1, 2019, 2:49pm UTC](https://discuss.elastic.co/t/file-integrity-module-not-capturing-user-data/174099 "2019-04-01T14:49:31Z")

</div>

Iam using Auditbeat's file integrity module to listen to a few folders. Now, following is the sample of the file\_integrity module's output file { "osName": "ubuntu", "osCategory": "linux", …

---

## [No matching indices found: No indices match pattern "winlogbeat-\*"](https://discuss.elastic.co/t/no-matching-indices-found-no-indices-match-pattern-winlogbeat/174750)

<div class="topic-metadata">

**Author:** [@WarriorHarb](https://discuss.elastic.co/u/WarriorHarb)\
**Replies:** 3\
**Last updated:** [April 1, 2019, 1:48pm UTC](https://discuss.elastic.co/t/no-matching-indices-found-no-indices-match-pattern-winlogbeat/174750 "2019-04-01T13:48:05Z")

</div>

Hello , So i installed winlogbeat as a service and it is running fine, when i check in Kibana i get that error: No matching indices found: No indices match pattern "winlogbeat-\*" -Logsash was configured to receive da…

---

## [Renaming top level field only](https://discuss.elastic.co/t/renaming-top-level-field-only/174609)

<div class="topic-metadata">

**Author:** [@Ga\_Mer](https://discuss.elastic.co/u/Ga_Mer)\
**Replies:** 1\
**Last updated:** [April 1, 2019, 1:39pm UTC](https://discuss.elastic.co/t/renaming-top-level-field-only/174609 "2019-04-01T13:39:48Z")

</div>

I have an conflict on the ES side with a field called data (a string) conflicting with other fields that start with data (such as data.v1.chartSettingsInput.mountainColor. Is there anyway in filebeat to do a rename only …

---

## [Beats issue with keystore and Nginx basic auth](https://discuss.elastic.co/t/beats-issue-with-keystore-and-nginx-basic-auth/174774)

<div class="topic-metadata">

**Author:** [@bigor44](https://discuss.elastic.co/u/bigor44)\
**Replies:** 2\
**Last updated:** [April 1, 2019, 12:39pm UTC](https://discuss.elastic.co/t/beats-issue-with-keystore-and-nginx-basic-auth/174774 "2019-04-01T12:39:01Z")

</div>

Hi, I have an issue since cluster and beats has bee updated to 6.7 i have a Nginx front-end that handle basic-auth to access ES. Steps done: Old keystore seems to not be recognized since update. ( filebeat keystore l…

---

## [Create field value based on parsed logs](https://discuss.elastic.co/t/create-field-value-based-on-parsed-logs/174782)

<div class="topic-metadata">

**Author:** [@Andrew\_Striletskyi](https://discuss.elastic.co/u/Andrew_Striletskyi)\
**Replies:** 0\
**Last updated:** [April 1, 2019, 12:36pm UTC](https://discuss.elastic.co/t/create-field-value-based-on-parsed-logs/174782 "2019-04-01T12:36:26Z")

</div>

Hi guys! We have SNMP trap logs. We send this logs using filebeat. Our filebeat configuration: - input\_type: log paths: \["/var/log/snmptrapd.log"\] fields: tagtype: linux tagapps: traps logtype: traps-di…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=368)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=370)
