# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=372

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 373

---

## [Truncate command causes filebeat misbehave](https://discuss.elastic.co/t/truncate-command-causes-filebeat-misbehave/173713)

<div class="topic-metadata">

**Author:** [@Jehutywong](https://discuss.elastic.co/u/Jehutywong)\
**Replies:** 2\
**Last updated:** [March 25, 2019, 4:20pm UTC](https://discuss.elastic.co/t/truncate-command-causes-filebeat-misbehave/173713 "2019-03-25T16:20:04Z")

</div>

OS: Centos7 Filebeat: 6.6.2 We have a cronjob to reduce log size in case disk full. the command used is truncate. like: truncate -s 15G /path/to/file We found that filebeat will quickly eat up all memory in the syste…

---

## [Metricbeat breaks with Mapping Exception Error](https://discuss.elastic.co/t/metricbeat-breaks-with-mapping-exception-error/173118)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 3\
**Last updated:** [March 25, 2019, 3:28pm UTC](https://discuss.elastic.co/t/metricbeat-breaks-with-mapping-exception-error/173118 "2019-03-25T15:28:28Z")

</div>

Hi- I hit the below error, when I run the windows metricset: Failed to connect to backoff(elasticsearch(http://172.20.23.100:9200)): Connection marked as failed because the onConnect callback failed: Error loading Elas…

---

## [Filebeat 6 on Redhat (RHEL/CentOS 5) not supported!](https://discuss.elastic.co/t/filebeat-6-on-redhat-rhel-centos-5-not-supported/172049)

<div class="topic-metadata">

**Author:** [@knight](https://discuss.elastic.co/u/knight)\
**Replies:** 11\
**Last updated:** [March 25, 2019, 1:53pm UTC](https://discuss.elastic.co/t/filebeat-6-on-redhat-rhel-centos-5-not-supported/172049 "2019-03-25T13:53:48Z")

</div>

OS ENV： cat /etc/redhat-release Red Hat Enterprise Linux Server release 5.4 (Tikanga) uname -r 2.6.18-164.el5 Filebeat version： 6.6.2 when i run cmd：./filebeat -e -c ./filebeat.yml , i got those info： runtime: ep…

---

## [Filebeat startup fail](https://discuss.elastic.co/t/filebeat-startup-fail/173677)

<div class="topic-metadata">

**Author:** [@thps](https://discuss.elastic.co/u/thps)\
**Replies:** 3\
**Last updated:** [March 25, 2019, 12:43pm UTC](https://discuss.elastic.co/t/filebeat-startup-fail/173677 "2019-03-25T12:43:07Z")

</div>

Hello everyone, i´m trying to setup elastic-stack as a logserver with elastic search, logstash and filebeat. I´ve tested it on poc-machines with root-acces. Everything works fine. On our productive enviroment i got in …

---

## [Eror : No indices match pattern "filebeat-\*"](https://discuss.elastic.co/t/eror-no-indices-match-pattern-filebeat/173510)

<div class="topic-metadata">

**Author:** [@allfreed](https://discuss.elastic.co/u/allfreed)\
**Replies:** 5\
**Last updated:** [March 25, 2019, 12:40pm UTC](https://discuss.elastic.co/t/eror-no-indices-match-pattern-filebeat/173510 "2019-03-25T12:40:01Z")

</div>

No matching indices found: No indices match pattern "filebeat-\*" Hi , I want to get apache access.log but while adding filebeat index pattern show this error. filebeat.yml file tried other beats(metricbeat,packetb…

---

## [New AWS module](https://discuss.elastic.co/t/new-aws-module/173129)

<div class="topic-metadata">

**Author:** [@proudboffin](https://discuss.elastic.co/u/proudboffin)\
**Replies:** 2\
**Last updated:** [March 25, 2019, 11:37am UTC](https://discuss.elastic.co/t/new-aws-module/173129 "2019-03-25T11:37:51Z")

</div>

Hi there, trying out the new AWS module in Metricbeat that was announced yesterday, encountering some difficulties. Two questions: Is it possible to pass the AWS credentials directly in the module config and not as en…

---

## [Filebeat: Error on FD](https://discuss.elastic.co/t/filebeat-error-on-fd/173616)

<div class="topic-metadata">

**Author:** [@chitraj8](https://discuss.elastic.co/u/chitraj8)\
**Replies:** 2\
**Last updated:** [March 25, 2019, 11:12am UTC](https://discuss.elastic.co/t/filebeat-error-on-fd/173616 "2019-03-25T11:12:19Z")

</div>

We recently started using filebeat and its on latest version 6.6 After initiating filebeat daemon process, we are able to push messages to kafka topics Also we started seeing some errors around the metric data in the l…

---

## [Unnesting user\_agent fields](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704)

<div class="topic-metadata">

**Author:** [@opfreehere](https://discuss.elastic.co/u/opfreehere)\
**Replies:** 11\
**Last updated:** [March 25, 2019, 11:00am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704 "2019-03-25T11:00:06Z")

</div>

After using user\_agent processor, I am getting the results somewhat like this: "user\_agent" : { "patch" : "1", "major" : "5", "minor" : "1", "os" : "Android 5.1.1", "os\_minor" : "1", "os\_major" : "5", "name" : "A…

---

## [Docker autodiscover with default template harvests logs multiple times](https://discuss.elastic.co/t/docker-autodiscover-with-default-template-harvests-logs-multiple-times/173490)

<div class="topic-metadata">

**Author:** [@FSeidinger](https://discuss.elastic.co/u/FSeidinger)\
**Replies:** 1\
**Last updated:** [March 25, 2019, 10:25am UTC](https://discuss.elastic.co/t/docker-autodiscover-with-default-template-harvests-logs-multiple-times/173490 "2019-03-25T10:25:09Z")

</div>

I tried the autodiscover with docker containers only, like described in https://github.com/elastic/beats/issues/6084 and it fails with parsing docker log files multiple times. Consider the following config: filebeat.au…

---

## [Configure many outputs for filebeat](https://discuss.elastic.co/t/configure-many-outputs-for-filebeat/173693)

<div class="topic-metadata">

**Author:** [@wolecharles\_job](https://discuss.elastic.co/u/wolecharles_job)\
**Replies:** 2\
**Last updated:** [March 25, 2019, 9:54am UTC](https://discuss.elastic.co/t/configure-many-outputs-for-filebeat/173693 "2019-03-25T09:54:14Z")

</div>

I want to be able to configure multiple outputs for the filebeat. FIlebeat sends appropriate file to a configured output. What i mean is Filebeat sends the content of File A to the configured elastic search output on I…

---

## [Timezone issue](https://discuss.elastic.co/t/timezone-issue/171630)

<div class="topic-metadata">

**Author:** [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Replies:** 2\
**Last updated:** [March 25, 2019, 9:52am UTC](https://discuss.elastic.co/t/timezone-issue/171630 "2019-03-25T09:52:21Z")

</div>

I have metricbeat and filebeat enabled for both system and kafka. MetricBeat seems to be sending the right data and the time is shown correct EDT. However FileBeat seems to be sending a time 4 hours behind EDT. I have co…

---

## [Valid certificate from filebeat to logstash](https://discuss.elastic.co/t/valid-certificate-from-filebeat-to-logstash/173690)

<div class="topic-metadata">

**Author:** [@triguer](https://discuss.elastic.co/u/triguer)\
**Replies:** 0\
**Last updated:** [March 25, 2019, 8:53am UTC](https://discuss.elastic.co/t/valid-certificate-from-filebeat-to-logstash/173690 "2019-03-25T08:53:41Z")

</div>

Hello, I am trying to configure a tls comunication between all ELK stack. I am already configured tls between logstash - elasticsearch and elasticsearch - kibana. But when I try to configure the secure comunication betw…

---

## [Custom haproxy module grok pattern failing](https://discuss.elastic.co/t/custom-haproxy-module-grok-pattern-failing/172613)

<div class="topic-metadata">

**Author:** [@10acc](https://discuss.elastic.co/u/10acc)\
**Replies:** 1\
**Last updated:** [March 25, 2019, 8:29am UTC](https://discuss.elastic.co/t/custom-haproxy-module-grok-pattern-failing/172613 "2019-03-25T08:29:47Z")

</div>

I am sending my haproxy logs with filebeat straight to my elasticsearch server. My haproxy logs are standard HTTP format , just have additional %fp (frontend\_port) at the very end. Mar 16 03:28:45 proksikas haproxy\[276…

---

## [IIS Module for Filebeats Not parsing Correct](https://discuss.elastic.co/t/iis-module-for-filebeats-not-parsing-correct/173266)

<div class="topic-metadata">

**Author:** [@erdo](https://discuss.elastic.co/u/erdo)\
**Replies:** 1\
**Last updated:** [March 25, 2019, 8:27am UTC](https://discuss.elastic.co/t/iis-module-for-filebeats-not-parsing-correct/173266 "2019-03-25T08:27:16Z")

</div>

I am trying to send my logs to filebeat with using filebeat with iis module and I have managed to send it following the documentation of iis module. Unfortunately, Its not parsing several things. Kibana: Filebeat: f…

---

## [Having troubles with XML Filtering](https://discuss.elastic.co/t/having-troubles-with-xml-filtering/173450)

<div class="topic-metadata">

**Author:** [@julsss](https://discuss.elastic.co/u/julsss)\
**Replies:** 4\
**Last updated:** [March 25, 2019, 2:21am UTC](https://discuss.elastic.co/t/having-troubles-with-xml-filtering/173450 "2019-03-25T02:21:55Z")

</div>

Good day everyone, I am new to this technology and I am trying to filter an xml file with the following elements. Now, when I checked kibana. The first event that I parsed always include the parent tag Due to thi…

---

## [Need advice on creating and collaborating on a new filebeat module](https://discuss.elastic.co/t/need-advice-on-creating-and-collaborating-on-a-new-filebeat-module/173448)

<div class="topic-metadata">

**Author:** [@JussiV](https://discuss.elastic.co/u/JussiV)\
**Replies:** 2\
**Last updated:** [March 23, 2019, 12:42pm UTC](https://discuss.elastic.co/t/need-advice-on-creating-and-collaborating-on-a-new-filebeat-module/173448 "2019-03-23T12:42:34Z")

</div>

Hello, I'm administering a rather old application with multiple servers and we're trying to centralise the the application logs. As the vendor doesn't really provide any support for log centralisation I had the grand id…

---

## [Package a beat built from source for deploying to other servers running on same platform](https://discuss.elastic.co/t/package-a-beat-built-from-source-for-deploying-to-other-servers-running-on-same-platform/170351)

<div class="topic-metadata">

**Author:** [@tabalchi](https://discuss.elastic.co/u/tabalchi)\
**Replies:** 8\
**Last updated:** [March 23, 2019, 3:39am UTC](https://discuss.elastic.co/t/package-a-beat-built-from-source-for-deploying-to-other-servers-running-on-same-platform/170351 "2019-03-23T03:39:29Z")

</div>

I built MetricBeat from source on an ARMv7 device running Debian Stretch. To do this, I installed Go, then downloaded the Beats source code from GitHub, switched to the matching version for my ElasticSearch and Kibana in…

---

## [Beat Index Created As "%{\[@metadata\]\[beat\]}-%{\[@metadata\]\[version\]}-2019.MM.DD"](https://discuss.elastic.co/t/beat-index-created-as-metadata-beat-metadata-version-2019-mm-dd/173558)

<div class="topic-metadata">

**Author:** [@bcisse](https://discuss.elastic.co/u/bcisse)\
**Replies:** 0\
**Last updated:** [March 22, 2019, 8:03pm UTC](https://discuss.elastic.co/t/beat-index-created-as-metadata-beat-metadata-version-2019-mm-dd/173558 "2019-03-22T20:03:52Z")

</div>

Hi all! I'm having trouble setting up Filebeat to send its data to Elasticsearch via Logstash. ELK stack is properly setup and is running without issues. After configuration, I can see the indices being created in the f…

---

## [How to estimate Filebeat bandwidth usage based on log size?](https://discuss.elastic.co/t/how-to-estimate-filebeat-bandwidth-usage-based-on-log-size/173001)

<div class="topic-metadata">

**Author:** [@mikesource\_com](https://discuss.elastic.co/u/mikesource_com)\
**Replies:** 2\
**Last updated:** [March 22, 2019, 7:41pm UTC](https://discuss.elastic.co/t/how-to-estimate-filebeat-bandwidth-usage-based-on-log-size/173001 "2019-03-22T19:41:57Z")

</div>

With the pricing models used in cloud for ingress and egress it has become relevant to understand how much traffic will occur over the course of a year before actually implementing elastic. With this in mind, if I have …

---

## [Enabling postgresql module in Metricbeat causes crash](https://discuss.elastic.co/t/enabling-postgresql-module-in-metricbeat-causes-crash/173467)

<div class="topic-metadata">

**Author:** [@aswinm](https://discuss.elastic.co/u/aswinm)\
**Replies:** 5\
**Last updated:** [March 22, 2019, 6:22pm UTC](https://discuss.elastic.co/t/enabling-postgresql-module-in-metricbeat-causes-crash/173467 "2019-03-22T18:22:12Z")

</div>

I recently installed Metricbeat on a windows server 2016 and enabled apache and Postgresql modules. After almost a day after this my Postgres crashed with an error no buffer space available. I had to reboot the system to…

---

## [Can't pull Docker image](https://discuss.elastic.co/t/cant-pull-docker-image/173535)

<div class="topic-metadata">

**Author:** [@AndresPineros](https://discuss.elastic.co/u/AndresPineros)\
**Replies:** 2\
**Last updated:** [March 22, 2019, 5:57pm UTC](https://discuss.elastic.co/t/cant-pull-docker-image/173535 "2019-03-22T17:57:03Z")

</div>

From my machine: docker pull docker.elastic.co/beats/filebeat:6.6.2 Returns: Error response from daemon: unauthorized: authentication required My cluster says: filebeat-bp9cv …

---

## [Truncate cmdline to save bandwith](https://discuss.elastic.co/t/truncate-cmdline-to-save-bandwith/172920)

<div class="topic-metadata">

**Author:** [@kaem2111](https://discuss.elastic.co/u/kaem2111)\
**Replies:** 1\
**Last updated:** [March 22, 2019, 9:40am UTC](https://discuss.elastic.co/t/truncate-cmdline-to-save-bandwith/172920 "2019-03-22T09:40:32Z")

</div>

Hello, I am using Version 6.6.0 and have some very long system.process.cmdline fieldvalues that I want to truncate within the (metric)beat agent. The only working possibility I know today is to drop the field: processo…

---

## [Setting close\_timeout for all inputs in filebeat](https://discuss.elastic.co/t/setting-close-timeout-for-all-inputs-in-filebeat/173269)

<div class="topic-metadata">

**Author:** [@burandobata](https://discuss.elastic.co/u/burandobata)\
**Replies:** 1\
**Last updated:** [March 22, 2019, 9:33am UTC](https://discuss.elastic.co/t/setting-close-timeout-for-all-inputs-in-filebeat/173269 "2019-03-22T09:33:05Z")

</div>

Hey, is there a way to set close\_timeout for all filebeat inputs in one place (or change the default)? I have a lot of inputs and setting it for every single one is just redundant. I'm on version 6.6 and tried differe…

---

## [How filebeat calculate metrics returned by HTTP endpoint](https://discuss.elastic.co/t/how-filebeat-calculate-metrics-returned-by-http-endpoint/172715)

<div class="topic-metadata">

**Author:** [@bbking](https://discuss.elastic.co/u/bbking)\
**Replies:** 1\
**Last updated:** [March 22, 2019, 9:30am UTC](https://discuss.elastic.co/t/how-filebeat-calculate-metrics-returned-by-http-endpoint/172715 "2019-03-22T09:30:42Z")

</div>

Hi, it is unclear to me if the data is accumulated since the start of filebeat or it is a real-time view. Will the metrics be cleared if filebeat is restarted? Could you point to me the script that generates the metric…

---

## [Need help to convert fielddata to doc\_values](https://discuss.elastic.co/t/need-help-to-convert-fielddata-to-doc-values/172169)

<div class="topic-metadata">

**Author:** [@pastorsx](https://discuss.elastic.co/u/pastorsx)\
**Replies:** 2\
**Last updated:** [March 22, 2019, 5:52am UTC](https://discuss.elastic.co/t/need-help-to-convert-fielddata-to-doc-values/172169 "2019-03-22T05:52:17Z")

</div>

Hi all, I have a cluster and we use ES to index our data. We then use Kibana to display those all in different dashboards, but we think the memory usage by ES is just way too much and we cannot fix the issue. I read ab…

---

## [Does winlogbeat support windows xp sp3 embedded?](https://discuss.elastic.co/t/does-winlogbeat-support-windows-xp-sp3-embedded/173399)

<div class="topic-metadata">

**Author:** [@akumo](https://discuss.elastic.co/u/akumo)\
**Replies:** 2\
**Last updated:** [March 22, 2019, 12:00am UTC](https://discuss.elastic.co/t/does-winlogbeat-support-windows-xp-sp3-embedded/173399 "2019-03-22T00:00:11Z")

</div>

Hi, I tried to install winlogbeat on Windows XP SP3 Embedded but fail. Does winlogbeat support Windows XP Embedded ? Rgds.

---

## [Packetbeat is not sniffing the packets from amqp protocol running on 8161 port](https://discuss.elastic.co/t/packetbeat-is-not-sniffing-the-packets-from-amqp-protocol-running-on-8161-port/172776)

<div class="topic-metadata">

**Author:** [@Subrat](https://discuss.elastic.co/u/Subrat)\
**Replies:** 1\
**Last updated:** [March 21, 2019, 4:30pm UTC](https://discuss.elastic.co/t/packetbeat-is-not-sniffing-the-packets-from-amqp-protocol-running-on-8161-port/172776 "2019-03-21T16:30:39Z")

</div>

Packetbeat does not capture packets on amqp protocol running on 8161 port on Windows 10. packets e.g. amqp running on port 8161. Has anyone successfully installed and captured amqp packets on windows? I tried enabled …

---

## [How to configure Elasticsearch output](https://discuss.elastic.co/t/how-to-configure-elasticsearch-output/173291)

<div class="topic-metadata">

**Author:** [@nagr](https://discuss.elastic.co/u/nagr)\
**Replies:** 9\
**Last updated:** [March 21, 2019, 3:03pm UTC](https://discuss.elastic.co/t/how-to-configure-elasticsearch-output/173291 "2019-03-21T15:03:11Z")

</div>

Hi All, I am trying to load the log data over logstash to elasticsearch, so i have done the below steps, installed filebeat and configured "filebeat.yml" --\> like below #----------------------------- Logstash output …

---

## [Repeatedly read log file which shows current system status in one line](https://discuss.elastic.co/t/repeatedly-read-log-file-which-shows-current-system-status-in-one-line/172993)

<div class="topic-metadata">

**Author:** [@BKG](https://discuss.elastic.co/u/BKG)\
**Replies:** 0\
**Last updated:** [March 19, 2019, 2:23pm UTC](https://discuss.elastic.co/t/repeatedly-read-log-file-which-shows-current-system-status-in-one-line/172993 "2019-03-19T14:23:12Z")

</div>

We have a status.json file which shows the current "status" of our application which is updated every 5s. I would prefer not to log repeated outputs, but instead have filebeat re-read the file somehow. Is this possible? …

---

## [How to see the filebeat dashboard after enabling the filebeat through central beat management?](https://discuss.elastic.co/t/how-to-see-the-filebeat-dashboard-after-enabling-the-filebeat-through-central-beat-management/173093)

<div class="topic-metadata">

**Author:** [@subhash.parise](https://discuss.elastic.co/u/subhash.parise)\
**Replies:** 2\
**Last updated:** [March 21, 2019, 3:41am UTC](https://discuss.elastic.co/t/how-to-see-the-filebeat-dashboard-after-enabling-the-filebeat-through-central-beat-management/173093 "2019-03-21T03:41:54Z")

</div>

Dear Members, i have successfully enrolled the filebeat through kibana ui by using central beat management. After enrolling the beat filebeat.yml is like below : management: enabled: true period: 1m0s access\_token:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=371)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=373)
