# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=370

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 371

---

## [Metricbeat and mongo db replication](https://discuss.elastic.co/t/metricbeat-and-mongo-db-replication/173866)

<div class="topic-metadata">

**Author:** [@LeeK](https://discuss.elastic.co/u/LeeK)\
**Replies:** 1\
**Last updated:** [April 1, 2019, 12:14pm UTC](https://discuss.elastic.co/t/metricbeat-and-mongo-db-replication/173866 "2019-04-01T12:14:41Z")

</div>

I have a mongodb replication on 3 servers. I'm configuring the metricbeat on the Central Beat Management, and I'm not sure what's the best practice- writing the three servers on the host section, or writing localhost:27…

---

## [Duplicate messages created by FileBeat](https://discuss.elastic.co/t/duplicate-messages-created-by-filebeat/174741)

<div class="topic-metadata">

**Author:** [@Denis\_Murashov](https://discuss.elastic.co/u/Denis_Murashov)\
**Replies:** 0\
**Last updated:** [April 1, 2019, 9:14am UTC](https://discuss.elastic.co/t/duplicate-messages-created-by-filebeat/174741 "2019-04-01T09:14:00Z")

</div>

'm using FileBeat to load log messages into ElasticSearch through LogStash. The log files are located on Windows network share. The FileBeat runs on Windows machine. The problem is that some log file records are duplicat…

---

## [Filebeat : Send different logs from filebeat to different logstash Pipeline](https://discuss.elastic.co/t/filebeat-send-different-logs-from-filebeat-to-different-logstash-pipeline/174732)

<div class="topic-metadata">

**Author:** [@lakshykar](https://discuss.elastic.co/u/lakshykar)\
**Replies:** 0\
**Last updated:** [April 1, 2019, 8:12am UTC](https://discuss.elastic.co/t/filebeat-send-different-logs-from-filebeat-to-different-logstash-pipeline/174732 "2019-04-01T08:12:30Z")

</div>

Hi, I have configured one logstash service having two pipelines, both pipelines separate ports are given. Let's say Pipeline1 (Port 5044) , Pipeline2 (Port 5045) Now i want to send data to the logstash using filebeat.…

---

## [Cannot create new beat - make setup failed](https://discuss.elastic.co/t/cannot-create-new-beat-make-setup-failed/174681)

<div class="topic-metadata">

**Author:** [@Shani\_Berrebi](https://discuss.elastic.co/u/Shani_Berrebi)\
**Replies:** 1\
**Last updated:** [April 1, 2019, 8:08am UTC](https://discuss.elastic.co/t/cannot-create-new-beat-make-setup-failed/174681 "2019-04-01T08:08:24Z")

</div>

hi, I am using this guide in order to create my own beat. https://www.elastic.co/guide/en/beats/devguide/current/setting-up-beat.html when i tried to run: make setup i get this error: C:\\go-work\\src\\github.com\\git…

---

## [Is there a way to see what data has been sent to amqp in packetbeat?](https://discuss.elastic.co/t/is-there-a-way-to-see-what-data-has-been-sent-to-amqp-in-packetbeat/174104)

<div class="topic-metadata">

**Author:** [@rajeshk150](https://discuss.elastic.co/u/rajeshk150)\
**Replies:** 1\
**Last updated:** [April 1, 2019, 7:51am UTC](https://discuss.elastic.co/t/is-there-a-way-to-see-what-data-has-been-sent-to-amqp-in-packetbeat/174104 "2019-04-01T07:51:28Z")

</div>

We are capturing the amqp traffic in packetbeat. Is there a way to fetch the data present in this packetbeat to verify that it is the amqp message itself. Below is the data getting captured. { "\_index": "packetbeat-6.…

---

## [How to get internal ip address from filebeat?](https://discuss.elastic.co/t/how-to-get-internal-ip-address-from-filebeat/169769)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 23\
**Last updated:** [April 1, 2019, 7:20am UTC](https://discuss.elastic.co/t/how-to-get-internal-ip-address-from-filebeat/169769 "2019-04-01T07:20:27Z")

</div>

I want to get internal ip address in as a field value in filebeat. currently only global ips indexed into elastic. why is that ? indexed json i got from elastic as below { "\_index": "filebeat-6.4.3-2019.02.25", "\_t…

---

## [Filebeat works as executable but not windows service](https://discuss.elastic.co/t/filebeat-works-as-executable-but-not-windows-service/174686)

<div class="topic-metadata">

**Author:** [@bernhard\_feldmann](https://discuss.elastic.co/u/bernhard_feldmann)\
**Replies:** 0\
**Last updated:** [March 31, 2019, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-works-as-executable-but-not-windows-service/174686 "2019-03-31T15:45:44Z")

</div>

HI, i installed filebeat as windows service, even though it's running, it doesn't work! no log folder created and nothing shipped. But when i ran the executable from command line then it works stright away, i can't fin…

---

## [Custom Access Log to JSON Format By Grok Pattern in Filebeat](https://discuss.elastic.co/t/custom-access-log-to-json-format-by-grok-pattern-in-filebeat/174584)

<div class="topic-metadata">

**Author:** [@mortezaipo](https://discuss.elastic.co/u/mortezaipo)\
**Replies:** 0\
**Last updated:** [March 29, 2019, 5:26pm UTC](https://discuss.elastic.co/t/custom-access-log-to-json-format-by-grok-pattern-in-filebeat/174584 "2019-03-29T17:26:05Z")

</div>

I have a custom Access log and I want to send it ('output') by Gork pattern. I don't have any access to the Logstash server, and I just can config my Filebeat to send Access log messages in a Grok pattern. I have a Gray…

---

## [Unable to Send Windows Events to Logstash-WinlogBeats S0LVED](https://discuss.elastic.co/t/unable-to-send-windows-events-to-logstash-winlogbeats-s0lved/174551)

<div class="topic-metadata">

**Author:** [@dragan979](https://discuss.elastic.co/u/dragan979)\
**Replies:** 1\
**Last updated:** [March 30, 2019, 1:22pm UTC](https://discuss.elastic.co/t/unable-to-send-windows-events-to-logstash-winlogbeats-s0lved/174551 "2019-03-30T13:22:51Z")

</div>

I installed windowsbeats winlogbeat.event\_logs: - name: Application ignore\_older: 72h - name: Security - name: System winlogbeat.registry\_file: C:/ProgramData/winlogbeat/.winlogbeat.yml output.logstash: # Th…

---

## [Filebeat "Provided Grok expressions do not match field value:" for /var/log/messages on RHEL7 with system module](https://discuss.elastic.co/t/filebeat-provided-grok-expressions-do-not-match-field-value-for-var-log-messages-on-rhel7-with-system-module/174616)

<div class="topic-metadata">

**Author:** [@Ian\_Bishop](https://discuss.elastic.co/u/Ian_Bishop)\
**Replies:** 0\
**Last updated:** [March 29, 2019, 11:10pm UTC](https://discuss.elastic.co/t/filebeat-provided-grok-expressions-do-not-match-field-value-for-var-log-messages-on-rhel7-with-system-module/174616 "2019-03-29T23:10:20Z")

</div>

Hi, sorry for the massive title. I think that encapsulates what we're seeing. We have a completely new ELK install, with filebeat forwarding directly into elasticsearch. All /var/log/messages entries are failing to pa…

---

## [Help with Docker prospector and dissect processor on filebeat](https://discuss.elastic.co/t/help-with-docker-prospector-and-dissect-processor-on-filebeat/174569)

<div class="topic-metadata">

**Author:** [@bbgobie](https://discuss.elastic.co/u/bbgobie)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 7:02pm UTC](https://discuss.elastic.co/t/help-with-docker-prospector-and-dissect-processor-on-filebeat/174569 "2019-03-29T19:02:08Z")

</div>

Hi, I'm trying to use filebeat to parse my docker logs, and dissect them to send to Elasticsearch. My filebeat.yml looks like this filebeat.prospectors: - type: docker document\_type: docker containers: ids: "\*" p…

---

## [Recommendations for parsing 1000's ~10MB files to backfill elasticsearch](https://discuss.elastic.co/t/recommendations-for-parsing-1000s-10mb-files-to-backfill-elasticsearch/174114)

<div class="topic-metadata">

**Author:** [@drwg](https://discuss.elastic.co/u/drwg)\
**Replies:** 2\
**Last updated:** [March 29, 2019, 3:53pm UTC](https://discuss.elastic.co/t/recommendations-for-parsing-1000s-10mb-files-to-backfill-elasticsearch/174114 "2019-03-29T15:53:53Z")

</div>

I'm currently using filebeat -\> logstash -\> elastic to back fill elastic search with exit codes from several thousand text output files each 10's MB in size and \>10k lines. ~200GB in total. The server can push 5GB/s read…

---

## [Compiling filebeat on ARM64 : go1.12.1/pkg/tool/linux\_arm64/link: running gcc failed: exit status 1](https://discuss.elastic.co/t/compiling-filebeat-on-arm64-go1-12-1-pkg-tool-linux-arm64-link-running-gcc-failed-exit-status-1/174296)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 3:49pm UTC](https://discuss.elastic.co/t/compiling-filebeat-on-arm64-go1-12-1-pkg-tool-linux-arm64-link-running-gcc-failed-exit-status-1/174296 "2019-03-29T15:49:05Z")

</div>

Dear Community, I tried to compile and install filebeat on aarch64 GNU/Linux ( ARM 64bit ) manually as it is not available as package on this platform. I upgrade language GO from version 1.7 to the latest available "go…

---

## [Recover operation resultats of jolokia](https://discuss.elastic.co/t/recover-operation-resultats-of-jolokia/174068)

<div class="topic-metadata">

**Author:** [@Mustapha\_HAJ\_ROMDHA1](https://discuss.elastic.co/u/Mustapha_HAJ_ROMDHA1)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 3:44pm UTC](https://discuss.elastic.co/t/recover-operation-resultats-of-jolokia/174068 "2019-03-29T15:44:28Z")

</div>

Hello, I am working with the module jolokia of metricbeat, I need to recover the result of the operation dumpAllThread and send the data in elasticsearch. Any idea ? Thank you

---

## [Metricsbeat -6.6.2 - CPU Usage missing| Ubuntu 18.04](https://discuss.elastic.co/t/metricsbeat-6-6-2-cpu-usage-missing-ubuntu-18-04/173860)

<div class="topic-metadata">

**Author:** [@Sunil\_Jacob](https://discuss.elastic.co/u/Sunil_Jacob)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 3:43pm UTC](https://discuss.elastic.co/t/metricsbeat-6-6-2-cpu-usage-missing-ubuntu-18-04/173860 "2019-03-29T15:43:11Z")

</div>

Hi Team, I have ELK stack on Ubuntu machine and also installed metric beat on the same machine. I access the Kibana URL from a remote Windows machine, by giving the IP: of the machine where Kibana is installed. But am…

---

## [System tests of metricbeat modules](https://discuss.elastic.co/t/system-tests-of-metricbeat-modules/173834)

<div class="topic-metadata">

**Author:** [@berfinsari](https://discuss.elastic.co/u/berfinsari)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 3:41pm UTC](https://discuss.elastic.co/t/system-tests-of-metricbeat-modules/173834 "2019-03-29T15:41:40Z")

</div>

I wonder something about system tests of metricbeat modules. Some system tests are in the metricbeat/module/{module} directory instead of metricbeat/test/system directory. Because of this, MODULE={module} make test-mod…

---

## [Metricbeat kafka output problem](https://discuss.elastic.co/t/metricbeat-kafka-output-problem/173287)

<div class="topic-metadata">

**Author:** [@khergner](https://discuss.elastic.co/u/khergner)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 3:40pm UTC](https://discuss.elastic.co/t/metricbeat-kafka-output-problem/173287 "2019-03-29T15:40:09Z")

</div>

Hi, I want to use message que for any beat. I search how to implemente message que in elastic system, I think we should use Kafka . I use metricbeat 6.6.1v so metricbeat data is send to kafka but Kafka can not log vers…

---

## [Winlogbeat not all events are parsed](https://discuss.elastic.co/t/winlogbeat-not-all-events-are-parsed/173707)

<div class="topic-metadata">

**Author:** [@kalinichenk](https://discuss.elastic.co/u/kalinichenk)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 2:50pm UTC](https://discuss.elastic.co/t/winlogbeat-not-all-events-are-parsed/173707 "2019-03-29T14:50:21Z")

</div>

Hello! I have ELK stack 6.6.2 and some beats installed. The problem is that some fields from Winlogbeat are not parsed. For example event\_id 4663 "Message" field contains: Access Request Information: Accesses: Read…

---

## [Does filebeat's logstash output support IPv6?](https://discuss.elastic.co/t/does-filebeats-logstash-output-support-ipv6/174540)

<div class="topic-metadata">

**Author:** [@yongtao](https://discuss.elastic.co/u/yongtao)\
**Replies:** 2\
**Last updated:** [March 29, 2019, 1:50pm UTC](https://discuss.elastic.co/t/does-filebeats-logstash-output-support-ipv6/174540 "2019-03-29T13:50:29Z")

</div>

In the filebeat configuration, can I put IPv6 address as logstash.output destination? Like this? output.logstash: hosts: \["\<ipv6-address\>:5044"\] Thanks! Yongtao

---

## [How to compile filebeat source code?](https://discuss.elastic.co/t/how-to-compile-filebeat-source-code/174158)

<div class="topic-metadata">

**Author:** [@mortezaipo](https://discuss.elastic.co/u/mortezaipo)\
**Replies:** 7\
**Last updated:** [March 29, 2019, 1:10pm UTC](https://discuss.elastic.co/t/how-to-compile-filebeat-source-code/174158 "2019-03-29T13:10:37Z")

</div>

Hi, I've developed my own 'output' and I've introduced it to the publisher. Now I have a problem that I want to compile it and use it in a production mode. I've checked the 'developer' doc and I didn't find anything f…

---

## [Filebeat with graylog collector sidecar - java.lang.NullPointerException](https://discuss.elastic.co/t/filebeat-with-graylog-collector-sidecar-java-lang-nullpointerexception/174424)

<div class="topic-metadata">

**Author:** [@delsdam](https://discuss.elastic.co/u/delsdam)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 11:57am UTC](https://discuss.elastic.co/t/filebeat-with-graylog-collector-sidecar-java-lang-nullpointerexception/174424 "2019-03-29T11:57:41Z")

</div>

Hello, I installed graylog collector sidecar with filebeat (6.4.1). In the file catalina.out, I have the message below: java.lang.NullPointerException: null at org.zkoss.zk.ui.AbstractComponent.getAttachedUiEngine (A…

---

## [How to set ILM with Central Management](https://discuss.elastic.co/t/how-to-set-ilm-with-central-management/173435)

<div class="topic-metadata">

**Author:** [@hadesy](https://discuss.elastic.co/u/hadesy)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 11:56am UTC](https://discuss.elastic.co/t/how-to-set-ilm-with-central-management/173435 "2019-03-29T11:56:11Z")

</div>

I can't find "other settings“ in the output configuration block.

---

## [Filebeat Multiline not working-sundar](https://discuss.elastic.co/t/filebeat-multiline-not-working-sundar/173429)

<div class="topic-metadata">

**Author:** [@sundarm](https://discuss.elastic.co/u/sundarm)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 11:55am UTC](https://discuss.elastic.co/t/filebeat-multiline-not-working-sundar/173429 "2019-03-29T11:55:08Z")

</div>

Team, I am using following filebeat configuration to push magento logs to logstash and from there to kibana. But still its not working as expected . Earlier i used the below logstash configuration without using filebeat…

---

## [Enroll missing](https://discuss.elastic.co/t/enroll-missing/158419)

<div class="topic-metadata">

**Author:** [@bering](https://discuss.elastic.co/u/bering)\
**Replies:** 3\
**Last updated:** [March 29, 2019, 11:49am UTC](https://discuss.elastic.co/t/enroll-missing/158419 "2019-03-29T11:49:42Z")

</div>

I am trying to create a new metricset with the Metricbeat 6.5.1 i have downloaded the sourcecode from here: https://github.com/elastic/beats/releases I can easily compile the metricbeat but running metricbeat --help show…

---

## [Filebeat windows: add\_docker\_metadata from npipe](https://discuss.elastic.co/t/filebeat-windows-add-docker-metadata-from-npipe/173333)

<div class="topic-metadata">

**Author:** [@dmitryzykov](https://discuss.elastic.co/u/dmitryzykov)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 11:43am UTC](https://discuss.elastic.co/t/filebeat-windows-add-docker-metadata-from-npipe/173333 "2019-03-29T11:43:24Z")

</div>

When using filebeat 6.6.2 inside windows container I can't add docker metadata from npipe: filebeat.yaml filebeat.inputs: - type: docker containers: path: "C:\\\\ContainerLogs" ids: "\*" processors: - add…

---

## [Filebeat.yml not parsing the env variables](https://discuss.elastic.co/t/filebeat-yml-not-parsing-the-env-variables/173324)

<div class="topic-metadata">

**Author:** [@elkuserbsm](https://discuss.elastic.co/u/elkuserbsm)\
**Replies:** 1\
**Last updated:** [March 29, 2019, 11:39am UTC](https://discuss.elastic.co/t/filebeat-yml-not-parsing-the-env-variables/173324 "2019-03-29T11:39:05Z")

</div>

Hi, I am using env variables in filebeat.yml, it is failing to parse the variables. filebeat.yml output.elasticsearch: hosts: \[$ELASTICSEARCH\_HOST\] template: name: "filebeat" path: "fields.yml" overwrite: false pro…

---

## [Filebeat Always Failing to Connect to Elasticsearch](https://discuss.elastic.co/t/filebeat-always-failing-to-connect-to-elasticsearch/173951)

<div class="topic-metadata">

**Author:** [@rmanning](https://discuss.elastic.co/u/rmanning)\
**Replies:** 3\
**Last updated:** [March 28, 2019, 7:19pm UTC](https://discuss.elastic.co/t/filebeat-always-failing-to-connect-to-elasticsearch/173951 "2019-03-28T19:19:38Z")

</div>

I am trying to run a simple elastic stack configuration (Filebeat + Elasticsearch + Kibana) on my local machine. Filebeat should take all the docker logs and output them to elasticsearch. I am running everything in docke…

---

## [Filebeat not capable to ingest all logs](https://discuss.elastic.co/t/filebeat-not-capable-to-ingest-all-logs/174206)

<div class="topic-metadata">

**Author:** [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Replies:** 5\
**Last updated:** [March 28, 2019, 2:02pm UTC](https://discuss.elastic.co/t/filebeat-not-capable-to-ingest-all-logs/174206 "2019-03-28T14:02:53Z")

</div>

Hi, My Filebeat (ver 5.6.9) is currently monitoring 6 files, each file generating ~11,500 new logs per minute. Apparently filebeat is not capable to catch up with the logging rate. Below is my configuration: filebea…

---

## [Is there an instruction for installing and configuring osquery in Elasticsearch/Kibana?](https://discuss.elastic.co/t/is-there-an-instruction-for-installing-and-configuring-osquery-in-elasticsearch-kibana/174055)

<div class="topic-metadata">

**Author:** [@patsevanton](https://discuss.elastic.co/u/patsevanton)\
**Replies:** 2\
**Last updated:** [March 28, 2019, 9:49am UTC](https://discuss.elastic.co/t/is-there-an-instruction-for-installing-and-configuring-osquery-in-elasticsearch-kibana/174055 "2019-03-28T09:49:15Z")

</div>

I installed Filebeat, Elasticsearch, Kibana 6.6.2 filebeat modules enable osquery sudo rpm -ivh https://osquery-packages.s3.amazonaws.com/centos7/noarch/osquery-s3-centos7-repo-1-0.0.noarch.rpm sudo yum install osquery …

---

## [How can I monitor MSSQL database server using Elastic search](https://discuss.elastic.co/t/how-can-i-monitor-mssql-database-server-using-elastic-search/174111)

<div class="topic-metadata">

**Author:** [@Mith](https://discuss.elastic.co/u/Mith)\
**Replies:** 3\
**Last updated:** [March 28, 2019, 8:13am UTC](https://discuss.elastic.co/t/how-can-i-monitor-mssql-database-server-using-elastic-search/174111 "2019-03-28T08:13:33Z")

</div>

Hi All, I'm new to ELK. I've installed Elasticsearch and Kibana. It's running fine. I want to monitor MSSQL database using Elastichsearch. Please help me understand how this can be achieved. Can this be done using fil…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=369)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=371)
