# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=371

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 372

---

## [Categorize the servers on Kibana](https://discuss.elastic.co/t/categorize-the-servers-on-kibana/174187)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 1\
**Last updated:** [March 28, 2019, 8:12am UTC](https://discuss.elastic.co/t/categorize-the-servers-on-kibana/174187 "2019-03-28T08:12:15Z")

</div>

Hi I have multiple Linux servers from which I am sending metric beats data to elastic search. I can see a default dashboard created and under \[System Overview\] I can see a list of servers and when I click i get in to m…

---

## [Flows dashboard unexpected behaviour](https://discuss.elastic.co/t/flows-dashboard-unexpected-behaviour/174260)

<div class="topic-metadata">

**Author:** [@DustyMeg](https://discuss.elastic.co/u/DustyMeg)\
**Replies:** 0\
**Last updated:** [March 28, 2019, 7:58am UTC](https://discuss.elastic.co/t/flows-dashboard-unexpected-behaviour/174260 "2019-03-28T07:58:20Z")

</div>

I have recently installed Packetbeat 6.6.2 on 2 of our internal servers. They do not have access to Elasticsearch and go through Logstash. Packetbeat was unzipped locally on the Elasticsearch machine (1 Node) and ran w…

---

## [How to get logs from remote server to elk](https://discuss.elastic.co/t/how-to-get-logs-from-remote-server-to-elk/174230)

<div class="topic-metadata">

**Author:** [@gomathiganesan995](https://discuss.elastic.co/u/gomathiganesan995)\
**Replies:** 4\
**Last updated:** [March 28, 2019, 4:16am UTC](https://discuss.elastic.co/t/how-to-get-logs-from-remote-server-to-elk/174230 "2019-03-28T04:16:48Z")

</div>

How to get logs from remote server to elk

---

## [Dont have Query count and cumulated duration \[Filebeat PostgreSQL\]](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799)

<div class="topic-metadata">

**Author:** [@patsevanton](https://discuss.elastic.co/u/patsevanton)\
**Replies:** 4\
**Last updated:** [March 27, 2019, 11:05pm UTC](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799 "2019-03-27T23:05:20Z")

</div>

Hi. ELK stack version 6.6.2. I deployed a new server with PostgreSQL and I use Filebeat to send PostgreSQL logs the the elasticsearch cluster. I added the pluggin PostgreSQL and imported the dashboard (filebeat setup -e)…

---

## [Elastic CLA issue](https://discuss.elastic.co/t/elastic-cla-issue/174168)

<div class="topic-metadata">

**Author:** [@pohzipohzi](https://discuss.elastic.co/u/pohzipohzi)\
**Replies:** 1\
**Last updated:** [March 27, 2019, 9:46pm UTC](https://discuss.elastic.co/t/elastic-cla-issue/174168 "2019-03-27T21:46:56Z")

</div>

I seem to have some issue with the elastic CLA here https://github.com/elastic/beats/pull/8594. It used to work last time until recently. I have not changed my email or username and have signed and resigned the license a…

---

## ["message" field format not correct?](https://discuss.elastic.co/t/message-field-format-not-correct/174200)

<div class="topic-metadata">

**Author:** [@CraigS](https://discuss.elastic.co/u/CraigS)\
**Replies:** 2\
**Last updated:** [March 27, 2019, 8:54pm UTC](https://discuss.elastic.co/t/message-field-format-not-correct/174200 "2019-03-27T20:54:37Z")

</div>

Just starting with Winlogbeat 6.6.2 on Server 2012 and ELK (on Ubuntu) and I think the message section of the Event is being sent in binary and not text. The sample of the section below is from the Winlogbeat log file in…

---

## [Non-zero metrics in the last 30s: meaning](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-meaning/173970)

<div class="topic-metadata">

**Author:** [@ptemmer](https://discuss.elastic.co/u/ptemmer)\
**Replies:** 2\
**Last updated:** [March 27, 2019, 3:53pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s-meaning/173970 "2019-03-27T15:53:16Z")

</div>

Hi, Apparently logs are transferred from Filebeat to Elasticsearch, however the filebeat logs continiously show this message: 2019-03-26T16:16:02.557Z INFO \[monitoring\] log/log.go:144 Non-zero metrics in the last 30s {…

---

## [After upgrading from FB 5.6.5 to FB 6.5.4, events stopped indexing](https://discuss.elastic.co/t/after-upgrading-from-fb-5-6-5-to-fb-6-5-4-events-stopped-indexing/172854)

<div class="topic-metadata">

**Author:** [@Frederico\_Ferreira](https://discuss.elastic.co/u/Frederico_Ferreira)\
**Replies:** 3\
**Last updated:** [March 27, 2019, 3:33pm UTC](https://discuss.elastic.co/t/after-upgrading-from-fb-5-6-5-to-fb-6-5-4-events-stopped-indexing/172854 "2019-03-27T15:33:16Z")

</div>

Hello there. Before someone comes posting that this is a duplicate, the threads that I found here does not solve my issue. Here it goes: My stask works like this: Filebeat -\> Logstash -\> Elasticsearch I have lots and l…

---

## [Winlogbeat timestamp format](https://discuss.elastic.co/t/winlogbeat-timestamp-format/173116)

<div class="topic-metadata">

**Author:** [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Replies:** 8\
**Last updated:** [March 27, 2019, 3:14pm UTC](https://discuss.elastic.co/t/winlogbeat-timestamp-format/173116 "2019-03-27T15:14:37Z")

</div>

when i get log from machine using Winlogbeat it shows @timestamp as like this: in kibana it shows like this in table format it shows as |@timestamp || |---|---| ||March 18th 2019, 12:30:04.874| and same date and ti…

---

## [Add tags via kibana - best practice](https://discuss.elastic.co/t/add-tags-via-kibana-best-practice/173808)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 4\
**Last updated:** [March 27, 2019, 3:08pm UTC](https://discuss.elastic.co/t/add-tags-via-kibana-best-practice/173808 "2019-03-27T15:08:58Z")

</div>

Hi, maybe this topic may be better placed in elasticsearch, but I want to enable the kibana user to do that, so I start this topic here. I have a loadtest environment set up. Multiple servers are included. Metricbeat …

---

## [Timeout on metricbeat setup](https://discuss.elastic.co/t/timeout-on-metricbeat-setup/174018)

<div class="topic-metadata">

**Author:** [@ricwhitney](https://discuss.elastic.co/u/ricwhitney)\
**Replies:** 2\
**Last updated:** [March 27, 2019, 2:58pm UTC](https://discuss.elastic.co/t/timeout-on-metricbeat-setup/174018 "2019-03-27T14:58:58Z")

</div>

I know I'm missing some setup of elasticsearch or something like that but can't find it in Kibana pages Here is the output of :# metricbeat setup Exiting: Couldn't connect to any of the configured Elasticsearch hosts.…

---

## [Metricbeat docker fail to start under not a root user](https://discuss.elastic.co/t/metricbeat-docker-fail-to-start-under-not-a-root-user/174022)

<div class="topic-metadata">

**Author:** [@scripnichenko](https://discuss.elastic.co/u/scripnichenko)\
**Replies:** 1\
**Last updated:** [March 27, 2019, 2:56pm UTC](https://discuss.elastic.co/t/metricbeat-docker-fail-to-start-under-not-a-root-user/174022 "2019-03-27T14:56:16Z")

</div>

Hi Team, Task is set-up Docker containers monitoring using Metricbeat container. I am following YAML file as mentioned in this article and trying to use my metricbeat.docker.yml but not able to use --user=root as I am …

---

## [Filebeat autodicover with docker doesn't see any logs from the containers](https://discuss.elastic.co/t/filebeat-autodicover-with-docker-doesnt-see-any-logs-from-the-containers/174086)

<div class="topic-metadata">

**Author:** [@iredko](https://discuss.elastic.co/u/iredko)\
**Replies:** 1\
**Last updated:** [March 27, 2019, 2:49pm UTC](https://discuss.elastic.co/t/filebeat-autodicover-with-docker-doesnt-see-any-logs-from-the-containers/174086 "2019-03-27T14:49:27Z")

</div>

Hello, I'm trying to set up the Filebeat with the autodiscovey for my docker containers. So the filebeat starts finds some containers. And that's all. No files harvesting, no metrics sending. I've already wasted so mu…

---

## [\[BUG\] When "log" field is missing in docker container's log line, filebeat immediately exited with Go routine panic](https://discuss.elastic.co/t/bug-when-log-field-is-missing-in-docker-containers-log-line-filebeat-immediately-exited-with-go-routine-panic/173880)

<div class="topic-metadata">

**Author:** [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Replies:** 5\
**Last updated:** [March 27, 2019, 5:49am UTC](https://discuss.elastic.co/t/bug-when-log-field-is-missing-in-docker-containers-log-line-filebeat-immediately-exited-with-go-routine-panic/173880 "2019-03-27T05:49:53Z")

</div>

Objective: Verifying the filebeat behavior when json field "log" is missing from container's log line but "stream" and "time" fields are present. Version: 6.4, 6.7 Execution Steps: Create a docker container …

---

## [Filebeat module for jboss logs](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521)

<div class="topic-metadata">

**Author:** [@Saloni\_Vithalani](https://discuss.elastic.co/u/Saloni_Vithalani)\
**Replies:** 4\
**Last updated:** [March 27, 2019, 5:17am UTC](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521 "2019-03-27T05:17:29Z")

</div>

We are using keycloak 5.0.0 and it gets started on JBOSS wildfly 7.0.0. What will be the recommended way of getting and parsig jboss logs in ELK. We are using filebeat, logstash, elasticsearch and kibana flow.

---

## [Analysing arbitrary log files (newbie)](https://discuss.elastic.co/t/analysing-arbitrary-log-files-newbie/173903)

<div class="topic-metadata">

**Author:** [@Nathan\_Sowatskey](https://discuss.elastic.co/u/Nathan_Sowatskey)\
**Replies:** 2\
**Last updated:** [March 27, 2019, 5:12am UTC](https://discuss.elastic.co/t/analysing-arbitrary-log-files-newbie/173903 "2019-03-27T05:12:58Z")

</div>

Hi I would like to ingest and correlate messages from a number of log files that I have on disk. I have installed Elasticsearch, Kibana and Filebeat. I have configured Filebeat to read the log files from a directory, an…

---

## [Docker.container.name is always empty](https://discuss.elastic.co/t/docker-container-name-is-always-empty/171022)

<div class="topic-metadata">

**Author:** [@tonyskulk](https://discuss.elastic.co/u/tonyskulk)\
**Replies:** 4\
**Last updated:** [March 27, 2019, 3:09am UTC](https://discuss.elastic.co/t/docker-container-name-is-always-empty/171022 "2019-03-27T03:09:33Z")

</div>

Hi, I have a docker setup with filebeat and other containers producing logs that are fetched by the filebeat container. That works well so far, everything gets imported to elasticsearch indices and I can discover them in…

---

## [Filebeat doesn't send data to logstash (?) OR logstash isn't receiving it (?)](https://discuss.elastic.co/t/filebeat-doesnt-send-data-to-logstash-or-logstash-isnt-receiving-it/173544)

<div class="topic-metadata">

**Author:** [@boxclever38](https://discuss.elastic.co/u/boxclever38)\
**Replies:** 6\
**Last updated:** [March 26, 2019, 9:32pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-send-data-to-logstash-or-logstash-isnt-receiving-it/173544 "2019-03-26T21:32:55Z")

</div>

I have an Elastic stack working A-OK (afaik). Filebeat runs great on the local machine, sending to logstash, and everything looks good in Kibana. I am now trying to send logs from a remote machine and it does not appear…

---

## [Export "Differentiated Services" (TOS) IPv4/IPv6 header field](https://discuss.elastic.co/t/export-differentiated-services-tos-ipv4-ipv6-header-field/172556)

<div class="topic-metadata">

**Author:** [@guido.lamoto](https://discuss.elastic.co/u/guido.lamoto)\
**Replies:** 2\
**Last updated:** [March 26, 2019, 8:51pm UTC](https://discuss.elastic.co/t/export-differentiated-services-tos-ipv4-ipv6-header-field/172556 "2019-03-26T20:51:06Z")

</div>

It would be nice to track "Differentiated Services" field (see RFC2474) and have it available as exported field in Packetbeat. It is the second bytes in the IPv4 header (the old TOS field) and bits 4 to 11 in the IPv6 h…

---

## [Converting Heartbeat's tls.certificate\_not\_valid\_after field to a "days\_til\_expiration" integer using Logstash](https://discuss.elastic.co/t/converting-heartbeats-tls-certificate-not-valid-after-field-to-a-days-til-expiration-integer-using-logstash/171834)

<div class="topic-metadata">

**Author:** [@joedissmeyer](https://discuss.elastic.co/u/joedissmeyer)\
**Replies:** 2\
**Last updated:** [March 25, 2019, 1:49pm UTC](https://discuss.elastic.co/t/converting-heartbeats-tls-certificate-not-valid-after-field-to-a-days-til-expiration-integer-using-logstash/171834 "2019-03-25T13:49:22Z")

</div>

First off, thanks to the Heartbeat team for adding in TLS certificate metadata with Heartbeat HTTP pings! This is a big win for everyone. I've seen some others looking to achieve the same result in their own environment…

---

## [Unable to capture the activemq traffic in packetbeat](https://discuss.elastic.co/t/unable-to-capture-the-activemq-traffic-in-packetbeat/173913)

<div class="topic-metadata">

**Author:** [@rajeshk150](https://discuss.elastic.co/u/rajeshk150)\
**Replies:** 1\
**Last updated:** [March 26, 2019, 11:44am UTC](https://discuss.elastic.co/t/unable-to-capture-the-activemq-traffic-in-packetbeat/173913 "2019-03-26T11:44:30Z")

</div>

Hi Team, I am unable to capture the activemq traffic in packetbeat. PFB for more details. ActiveMq version: 5.15.8 PacketBeat version: 6.6.2 OS: Windows 10 64 bit Elastic search, logstash and kibana version: 6.6.2 …

---

## [No connections between logstash and filebeats](https://discuss.elastic.co/t/no-connections-between-logstash-and-filebeats/173895)

<div class="topic-metadata">

**Author:** [@dragan979](https://discuss.elastic.co/u/dragan979)\
**Replies:** 1\
**Last updated:** [March 26, 2019, 10:09am UTC](https://discuss.elastic.co/t/no-connections-between-logstash-and-filebeats/173895 "2019-03-26T10:09:25Z")

</div>

Today is second day i'm spending on ELK stack and have no any experience with this. My goal: Create "parent" index (client01) and for all machines related to client01 collect logs so i can filter data based on that "pa…

---

## [Filebeat Keystore broken](https://discuss.elastic.co/t/filebeat-keystore-broken/173802)

<div class="topic-metadata">

**Author:** [@Alive](https://discuss.elastic.co/u/Alive)\
**Replies:** 3\
**Last updated:** [March 26, 2019, 9:34am UTC](https://discuss.elastic.co/t/filebeat-keystore-broken/173802 "2019-03-26T09:34:00Z")

</div>

Hi All, seems that if I add a keystore and the password used has a comma (example: HDiwmdei,dd\*d ), the keystore doesn't work. The error at the startup is: filebeat test config Exiting: error initializing publisher: …

---

## [Mixingup of data in one index](https://discuss.elastic.co/t/mixingup-of-data-in-one-index/173892)

<div class="topic-metadata">

**Author:** [@swapnali](https://discuss.elastic.co/u/swapnali)\
**Replies:** 0\
**Last updated:** [March 26, 2019, 9:20am UTC](https://discuss.elastic.co/t/mixingup-of-data-in-one-index/173892 "2019-03-26T09:20:49Z")

</div>

I have two configuration file winlog-event.yml and iis.yml for winlog-event.yml - input is winlogbeat, inside of beat configuration file i have add tag as winlog,event log Topic name for winlog-event.yml is winlog and…

---

## [High DiskIO with Proxmox + Ceph](https://discuss.elastic.co/t/high-diskio-with-proxmox-ceph/173851)

<div class="topic-metadata">

**Author:** [@Esity](https://discuss.elastic.co/u/Esity)\
**Replies:** 1\
**Last updated:** [March 26, 2019, 8:38am UTC](https://discuss.elastic.co/t/high-diskio-with-proxmox-ceph/173851 "2019-03-26T08:38:38Z")

</div>

Hello, I am currently running a Proxmox + Ceph cluster. It is backed by 17 256gb SSDs. I have noticed that my iowait times for CPU were terrible. a 2 core VM was spending 50-75% of it's cpu on IOWait. The only thing run…

---

## [Filebeat not processing all configured files if we run as service](https://discuss.elastic.co/t/filebeat-not-processing-all-configured-files-if-we-run-as-service/173575)

<div class="topic-metadata">

**Author:** [@subramani.k1990](https://discuss.elastic.co/u/subramani.k1990)\
**Replies:** 2\
**Last updated:** [March 26, 2019, 7:04am UTC](https://discuss.elastic.co/t/filebeat-not-processing-all-configured-files-if-we-run-as-service/173575 "2019-03-26T07:04:48Z")

</div>

Hi all, I have configured 4 input files in filebeat.yml. If i start the filebeat via Command prompt then all the 4 files were processed and logs sent to Logstash. But If i start file beat as a Service then only two f…

---

## [Metricbeat not able to collect metrics from Kerberised Kafka](https://discuss.elastic.co/t/metricbeat-not-able-to-collect-metrics-from-kerberised-kafka/173725)

<div class="topic-metadata">

**Author:** [@mmahaja](https://discuss.elastic.co/u/mmahaja)\
**Replies:** 3\
**Last updated:** [March 26, 2019, 5:17am UTC](https://discuss.elastic.co/t/metricbeat-not-able-to-collect-metrics-from-kerberised-kafka/173725 "2019-03-26T05:17:53Z")

</div>

Issue: Metric beat is not to collect metrics from Kerberized Kafka. It works well with non-kerberized Kafka MetricBeat Version: 6.6.2 Operating System: CentOs 7.4.x logs snapshot: Blockquote Logs when metric beat …

---

## [Heartbeat configuration file syntax](https://discuss.elastic.co/t/heartbeat-configuration-file-syntax/173591)

<div class="topic-metadata">

**Author:** [@George\_Wainwright](https://discuss.elastic.co/u/George_Wainwright)\
**Replies:** 1\
**Last updated:** [March 25, 2019, 11:03pm UTC](https://discuss.elastic.co/t/heartbeat-configuration-file-syntax/173591 "2019-03-25T23:03:43Z")

</div>

Can heartbeat recognize such line in configuration yaml file? - {type: http, urls: \['https://google.com'\], schedule: '@every 1m'} I checked yaml syntax of this file by running python -c 'import yaml, sys; print(ya…

---

## [Setting up Logstash and Beats for VM communication](https://discuss.elastic.co/t/setting-up-logstash-and-beats-for-vm-communication/173828)

<div class="topic-metadata">

**Author:** [@LuJA](https://discuss.elastic.co/u/LuJA)\
**Replies:** 0\
**Last updated:** [March 25, 2019, 8:56pm UTC](https://discuss.elastic.co/t/setting-up-logstash-and-beats-for-vm-communication/173828 "2019-03-25T20:56:20Z")

</div>

Newbie question: Is there a good guide available on how to pass the logs from a VM running an IPS, using filebeat, to ELK running on the host? Most of the guidance seems to be focussed on everything happening on the host…

---

## [Beats 6.5 error while setting up](https://discuss.elastic.co/t/beats-6-5-error-while-setting-up/173607)

<div class="topic-metadata">

**Author:** [@sharon92](https://discuss.elastic.co/u/sharon92)\
**Replies:** 3\
**Last updated:** [March 25, 2019, 5:37pm UTC](https://discuss.elastic.co/t/beats-6-5-error-while-setting-up/173607 "2019-03-25T17:37:57Z")

</div>

my filebeat version is 6.5.4 and setting up I tried to execute below command, sudo filebeat setup and got below error Exiting: 2 errors: Error checking if xpack is available: 500 Internal Server Error: {"error":{"root…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=370)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=372)
