# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=373

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 374

---

## [Different index name for different filebeat instances](https://discuss.elastic.co/t/different-index-name-for-different-filebeat-instances/172874)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 2\
**Last updated:** [March 21, 2019, 1:27am UTC](https://discuss.elastic.co/t/different-index-name-for-different-filebeat-instances/172874 "2019-03-21T01:27:33Z")

</div>

Hi Elastic stack version 6.6.1 Setup: filebeat -- Elastic Search -- Kibana I have different environments windows and Linux. I want to forward logs from multiple servers to elastic search . EX:- server1, 2, 3 to elast…

---

## [Conditional statements in filebeat.yml](https://discuss.elastic.co/t/conditional-statements-in-filebeat-yml/173211)

<div class="topic-metadata">

**Author:** [@mikemadden42](https://discuss.elastic.co/u/mikemadden42)\
**Replies:** 1\
**Last updated:** [March 20, 2019, 10:46pm UTC](https://discuss.elastic.co/t/conditional-statements-in-filebeat-yml/173211 "2019-03-20T22:46:37Z")

</div>

We currently have filebeat setup on a Windows node that is hosting several web apps. The filebeat.yml is very similar to this. I've sanitized host and application names. filebeat.inputs: - type: log enabled: true …

---

## [EventStore Beat](https://discuss.elastic.co/t/eventstore-beat/172991)

<div class="topic-metadata">

**Author:** [@aloulo47](https://discuss.elastic.co/u/aloulo47)\
**Replies:** 0\
**Last updated:** [March 19, 2019, 2:03pm UTC](https://discuss.elastic.co/t/eventstore-beat/172991 "2019-03-19T14:03:04Z")

</div>

Hey Guys am working on a beat that catches events from eventstore and send it to logstash you can check it and help me to improve it take a look !

---

## [File beat throwing warning for custom index pattern](https://discuss.elastic.co/t/file-beat-throwing-warning-for-custom-index-pattern/173201)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 1\
**Last updated:** [March 20, 2019, 8:28pm UTC](https://discuss.elastic.co/t/file-beat-throwing-warning-for-custom-index-pattern/173201 "2019-03-20T20:28:54Z")

</div>

Hi I am seeing this weird issue on my file beat module 6.6.2 . When I have default configuration in the filebeat.yml and iis module enabled. The file beat sends logs fine but when I try to add an index pattern it is t…

---

## [Windows perfmon metricset](https://discuss.elastic.co/t/windows-perfmon-metricset/172938)

<div class="topic-metadata">

**Author:** [@yaharin\_ben\_ayon](https://discuss.elastic.co/u/yaharin_ben_ayon)\
**Replies:** 1\
**Last updated:** [March 20, 2019, 4:13pm UTC](https://discuss.elastic.co/t/windows-perfmon-metricset/172938 "2019-03-20T16:13:00Z")

</div>

https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-metricset-windows-perfmon.html#metricbeat-metricset-windows-perfmon I'm looking for a more detailed guide on how to write there queries. How can i find…

---

## [Preferred k8s metricbeat install: helm or link in documentation?](https://discuss.elastic.co/t/preferred-k8s-metricbeat-install-helm-or-link-in-documentation/173184)

<div class="topic-metadata">

**Author:** [@krainboltgreene](https://discuss.elastic.co/u/krainboltgreene)\
**Replies:** 0\
**Last updated:** [March 20, 2019, 3:46pm UTC](https://discuss.elastic.co/t/preferred-k8s-metricbeat-install-helm-or-link-in-documentation/173184 "2019-03-20T15:46:08Z")

</div>

I can install metricbeat with either a helm chart or via the link to a configuration from the official documentation, but they're pretty different. Which one should I pick?

---

## [System requirements for Metricbeat](https://discuss.elastic.co/t/system-requirements-for-metricbeat/171135)

<div class="topic-metadata">

**Author:** [@zolthar-z](https://discuss.elastic.co/u/zolthar-z)\
**Replies:** 2\
**Last updated:** [March 20, 2019, 1:36pm UTC](https://discuss.elastic.co/t/system-requirements-for-metricbeat/171135 "2019-03-20T13:36:57Z")

</div>

HI I had installed metricbeat and it is working fine but we saw in all clients that the Average CPU use for Metricbeat client is between 1% or 2%, I was wondering if this behavior is normal or maybe if Elastic has a fo…

---

## [Filebeat multiline directly to elasticsearch](https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794)

<div class="topic-metadata">

**Author:** [@Matus\_Gajdos](https://discuss.elastic.co/u/Matus_Gajdos)\
**Replies:** 3\
**Last updated:** [March 20, 2019, 11:54am UTC](https://discuss.elastic.co/t/filebeat-multiline-directly-to-elasticsearch/172794 "2019-03-20T11:54:20Z")

</div>

Hello, I would like to send application logs from filebeat directly to elasticsearch index. I'm trying send multiline message but in index I see it as single line. EmbargoServiceLogger Error: 92 : 3/12/2019 1:46:29 PM…

---

## [Couldn't Make the Package of metricbeats in Windows-7 32 bit](https://discuss.elastic.co/t/couldnt-make-the-package-of-metricbeats-in-windows-7-32-bit/172462)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 7\
**Last updated:** [March 20, 2019, 9:18am UTC](https://discuss.elastic.co/t/couldnt-make-the-package-of-metricbeats-in-windows-7-32-bit/172462 "2019-03-20T09:18:38Z")

</div>

Hi- I have to Make Package of metricbeats (got to test couple of bugs in Windows module which has been fixed, which is still in a pull request, but not yet into the master), but its failing with an error message as belo…

---

## [Any plan for HTTP input support?](https://discuss.elastic.co/t/any-plan-for-http-input-support/173088)

<div class="topic-metadata">

**Author:** [@Garlandal](https://discuss.elastic.co/u/Garlandal)\
**Replies:** 0\
**Last updated:** [March 20, 2019, 7:23am UTC](https://discuss.elastic.co/t/any-plan-for-http-input-support/173088 "2019-03-20T07:23:33Z")

</div>

hey, i'm using filebeat building my log server, but on the filebeat input support list, there is not HTTP input support, since logstash and fluentd both have http input plugin, so is there any plan for HTTP input suppor…

---

## [Filebeat harvests files but doesn't send them anywhere](https://discuss.elastic.co/t/filebeat-harvests-files-but-doesnt-send-them-anywhere/173025)

<div class="topic-metadata">

**Author:** [@vladiulianbogdan](https://discuss.elastic.co/u/vladiulianbogdan)\
**Replies:** 1\
**Last updated:** [March 19, 2019, 6:01pm UTC](https://discuss.elastic.co/t/filebeat-harvests-files-but-doesnt-send-them-anywhere/173025 "2019-03-19T18:01:14Z")

</div>

Hi, I am using Filebeat version 6.6.2 on macOS. The configuration files is: filebeat.prospectors: - type: log enabled: true paths: - /tmp/\*.json json.keys\_under\_root: true json.overwrite\_keys: true output.…

---

## [Does filebeat.yml setup.template.append\_fields support multi-fields for elasticsearch index template?](https://discuss.elastic.co/t/does-filebeat-yml-setup-template-append-fields-support-multi-fields-for-elasticsearch-index-template/172207)

<div class="topic-metadata">

**Author:** [@PSM](https://discuss.elastic.co/u/PSM)\
**Replies:** 2\
**Last updated:** [March 19, 2019, 5:44pm UTC](https://discuss.elastic.co/t/does-filebeat-yml-setup-template-append-fields-support-multi-fields-for-elasticsearch-index-template/172207 "2019-03-19T17:44:59Z")

</div>

I'm configuring the filebeat filebeat.yml to load elasticsearch index templates. I have a few fields that I'd like to index as both type keyword and type text so I can use them for sorting and aggregation as well as for…

---

## [Filebeat events not sending to Logstash](https://discuss.elastic.co/t/filebeat-events-not-sending-to-logstash/171392)

<div class="topic-metadata">

**Author:** [@HelpComputer](https://discuss.elastic.co/u/HelpComputer)\
**Replies:** 8\
**Last updated:** [March 19, 2019, 4:50pm UTC](https://discuss.elastic.co/t/filebeat-events-not-sending-to-logstash/171392 "2019-03-19T16:50:24Z")

</div>

Hello, I've been working on an issue all morning and can't quite figure it out. Hoping someone might be able to point me in the right direction. Issue Filebeat data not making it to Logstash or at least it doesn't app…

---

## [Enable SSO for data ingestion](https://discuss.elastic.co/t/enable-sso-for-data-ingestion/172834)

<div class="topic-metadata">

**Author:** [@sirababu](https://discuss.elastic.co/u/sirababu)\
**Replies:** 0\
**Last updated:** [March 18, 2019, 4:54pm UTC](https://discuss.elastic.co/t/enable-sso-for-data-ingestion/172834 "2019-03-18T16:54:00Z")

</div>

Hello All, I see i can setup user name & password for ingestion but is there anyway i can do more than that like integrating LDAP or SSO for data ingestion to ES cluster. If i create a key store, any one who has file l…

---

## [\[Solved\] Decoding multiline JSON log file in v.6.6](https://discuss.elastic.co/t/solved-decoding-multiline-json-log-file-in-v-6-6/172922)

<div class="topic-metadata">

**Author:** [@osscombat](https://discuss.elastic.co/u/osscombat)\
**Replies:** 1\
**Last updated:** [March 19, 2019, 2:55pm UTC](https://discuss.elastic.co/t/solved-decoding-multiline-json-log-file-in-v-6-6/172922 "2019-03-19T14:55:36Z")

</div>

Hi! I'm trying to decode a plain JSON text log file (this is a nextcloud audit.log actually) via filebeat 6.6. Did tried the solutions from the manual, but I finished with the following crash in the processing: ... Fil…

---

## [Error key populated even when explicitly disabled](https://discuss.elastic.co/t/error-key-populated-even-when-explicitly-disabled/172602)

<div class="topic-metadata">

**Author:** [@mobidyc](https://discuss.elastic.co/u/mobidyc)\
**Replies:** 6\
**Last updated:** [March 19, 2019, 8:29am UTC](https://discuss.elastic.co/t/error-key-populated-even-when-explicitly-disabled/172602 "2019-03-19T08:29:02Z")

</div>

Hello, Using filebeat 6.6 I have a "error" field used in my template, it has to come from the log file. so, in the configuration file, I disabled the error key with the following parameter: json.add\_error\_key: false …

---

## [Filebeat on Azure AKS](https://discuss.elastic.co/t/filebeat-on-azure-aks/172912)

<div class="topic-metadata">

**Author:** [@Vincehood](https://discuss.elastic.co/u/Vincehood)\
**Replies:** 0\
**Last updated:** [March 19, 2019, 8:15am UTC](https://discuss.elastic.co/t/filebeat-on-azure-aks/172912 "2019-03-19T08:15:18Z")

</div>

Hello, I am wondering whether it is possible to deploy and use filebeat as daemonset on top of Azure AKS Kubernetes to retrieve my application container logs. Is AKS actually allowing log file access to filebeat? Br /…

---

## [\[BUG\] Filebeat is unable to parse the syslog message when priority value is given as \<0\> in syslog message of format RFC 3164](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447)

<div class="topic-metadata">

**Author:** [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Replies:** 5\
**Last updated:** [March 19, 2019, 6:08am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447 "2019-03-19T06:08:34Z")

</div>

Observation: It is observed that filebeat is unable to parse the syslog message of format RFC-3164 properly when priority value is given as \<0\> in syslog message. For other priorities filebeat is working as expected. F…

---

## [Issue building auditbeat](https://discuss.elastic.co/t/issue-building-auditbeat/172830)

<div class="topic-metadata">

**Author:** [@mikemadden42](https://discuss.elastic.co/u/mikemadden42)\
**Replies:** 4\
**Last updated:** [March 19, 2019, 2:00am UTC](https://discuss.elastic.co/t/issue-building-auditbeat/172830 "2019-03-19T02:00:41Z")

</div>

Is anyone else having issues building auditbeat in the 6.6 or 6.7 branch? Here is an example of building auditbeat in the 6.6 branch. I do not see this issue in the 7.0 branch. # git branch \* 6.6 6.7 7.0 master …

---

## [Error when using autodiscovery](https://discuss.elastic.co/t/error-when-using-autodiscovery/172875)

<div class="topic-metadata">

**Author:** [@tomriley](https://discuss.elastic.co/u/tomriley)\
**Replies:** 0\
**Last updated:** [March 18, 2019, 11:50pm UTC](https://discuss.elastic.co/t/error-when-using-autodiscovery/172875 "2019-03-18T23:50:51Z")

</div>

We are looking to use autodiscovery with Filebeat in Kubernetes to make it possible to configure Filebeat on a pod by pod basis, as it is intended. However, when enabling we are swamped with Error creating runner from c…

---

## [Using Environment variable in ES index name](https://discuss.elastic.co/t/using-environment-variable-in-es-index-name/172862)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 2\
**Last updated:** [March 18, 2019, 11:28pm UTC](https://discuss.elastic.co/t/using-environment-variable-in-es-index-name/172862 "2019-03-18T23:28:16Z")

</div>

I was hopping to use an env variable as part of the index name: ... output.elasticsearch: ... index: 'auditbeat-${ENVIRONMENT\_NAME}-%{\[host\]\[name\]}-%{+yyyy.MM.dd}' ... But when setting up the Kibana dashboard manuall…

---

## [Cannot change date format on @timestamp](https://discuss.elastic.co/t/cannot-change-date-format-on-timestamp/172638)

<div class="topic-metadata">

**Author:** [@mobidyc](https://discuss.elastic.co/u/mobidyc)\
**Replies:** 2\
**Last updated:** [March 18, 2019, 8:29pm UTC](https://discuss.elastic.co/t/cannot-change-date-format-on-timestamp/172638 "2019-03-18T20:29:57Z")

</div>

Hello, filebeat does not recognize the date format I have in my logs (issue opened on github): "2019-03-16T12:15:58.420454+0000" so I tried to specify the format using a template.json file: { "mappings": { "doc…

---

## [Supported config](https://discuss.elastic.co/t/supported-config/172790)

<div class="topic-metadata">

**Author:** [@bering](https://discuss.elastic.co/u/bering)\
**Replies:** 1\
**Last updated:** [March 18, 2019, 7:16pm UTC](https://discuss.elastic.co/t/supported-config/172790 "2019-03-18T19:16:13Z")

</div>

I am running ES,Kibana, MetricBeat version 6.6.2 I have been able to add tags to my metricbeat configuration by adding the following in the Other Config: tags: - Computer1 - Server1 But I can't add the following: s…

---

## [6.5.4 Filebeat w enabled postgresql module doesn't create proper index - no postgresql.\*.\* fields](https://discuss.elastic.co/t/6-5-4-filebeat-w-enabled-postgresql-module-doesnt-create-proper-index-no-postgresql-fields/172575)

<div class="topic-metadata">

**Author:** [@yurim](https://discuss.elastic.co/u/yurim)\
**Replies:** 4\
**Last updated:** [March 18, 2019, 7:09pm UTC](https://discuss.elastic.co/t/6-5-4-filebeat-w-enabled-postgresql-module-doesnt-create-proper-index-no-postgresql-fields/172575 "2019-03-18T19:09:15Z")

</div>

Hi guys, running ELK stack 6.5.4 on rhat 7.3 and postgresql 11.2, though had the same issue with pgsql 9.6. Postgresql has been configured to write into syslog and csvlog, so filebeat with postgresql module enabled sho…

---

## [Log level warning doesn't work](https://discuss.elastic.co/t/log-level-warning-doesnt-work/172709)

<div class="topic-metadata">

**Author:** [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Replies:** 1\
**Last updated:** [March 18, 2019, 6:45pm UTC](https://discuss.elastic.co/t/log-level-warning-doesnt-work/172709 "2019-03-18T18:45:22Z")

</div>

I have this config file: filebeat.prospectors: - type: log enabled: true paths: - /var/log/messages - /var/log/secure - /var/log/audit/audit.log - /var/log/yum.log - /root/.bash\_history - /va…

---

## [Packet Beat Crash](https://discuss.elastic.co/t/packet-beat-crash/172115)

<div class="topic-metadata">

**Author:** [@kamesh\_siva](https://discuss.elastic.co/u/kamesh_siva)\
**Replies:** 3\
**Last updated:** [March 18, 2019, 11:13am UTC](https://discuss.elastic.co/t/packet-beat-crash/172115 "2019-03-18T11:13:40Z")

</div>

The moment i use packetbeat.exe on windows 64 bit machine.. it is crashing.. Here is teh information Version of Packetbeat - 6.6.1 Problem signature: Problem Event Name: APPCRASH Application Name: packetbeat.exe Ap…

---

## [Failed to publish events: unsupported float value: NaN](https://discuss.elastic.co/t/failed-to-publish-events-unsupported-float-value-nan/169771)

<div class="topic-metadata">

**Author:** [@sgerlach](https://discuss.elastic.co/u/sgerlach)\
**Replies:** 15\
**Last updated:** [March 18, 2019, 10:22am UTC](https://discuss.elastic.co/t/failed-to-publish-events-unsupported-float-value-nan/169771 "2019-03-18T10:22:45Z")

</div>

Hello, We have some issues with metricbeat to logstash transport. After some time (can be days after startup), metricbeat starts logging "Failed to publish events: unsupported float value: NaN" every report cycle and re…

---

## [Docker network metrics not available](https://discuss.elastic.co/t/docker-network-metrics-not-available/172742)

<div class="topic-metadata">

**Author:** [@stevizik](https://discuss.elastic.co/u/stevizik)\
**Replies:** 0\
**Last updated:** [March 18, 2019, 10:13am UTC](https://discuss.elastic.co/t/docker-network-metrics-not-available/172742 "2019-03-18T10:13:38Z")

</div>

Hi all, i am using a kubernetes daemonset to create metricbeat instances in a K8s cluster. This seems to work pretty fine and i am able to send system, k8s and docker metrics to elasticsearch . The only thing i am miss…

---

## [Autodiscovery hints in docker swarm](https://discuss.elastic.co/t/autodiscovery-hints-in-docker-swarm/172664)

<div class="topic-metadata">

**Author:** [@atmosx](https://discuss.elastic.co/u/atmosx)\
**Replies:** 1\
**Last updated:** [March 17, 2019, 2:18pm UTC](https://discuss.elastic.co/t/autodiscovery-hints-in-docker-swarm/172664 "2019-03-17T14:18:32Z")

</div>

Hello, I have setup a docker swarm network. I have setup a metricbeat per host, at node level. Now I need to fetch data from prometheus exporters accessible through swarm overlay networks and I'm planning to use the hint…

---

## [How to add the timezone information for Postgresql module in Filebeat?](https://discuss.elastic.co/t/how-to-add-the-timezone-information-for-postgresql-module-in-filebeat/172244)

<div class="topic-metadata">

**Author:** [@Puneet\_Patwari](https://discuss.elastic.co/u/Puneet_Patwari)\
**Replies:** 4\
**Last updated:** [March 16, 2019, 12:24pm UTC](https://discuss.elastic.co/t/how-to-add-the-timezone-information-for-postgresql-module-in-filebeat/172244 "2019-03-16T12:24:09Z")

</div>

I am using filebeat modules for syslog and postgresql. For System module, var.convert\_timezone preserves the the timezone info in the ingest pipeline. However, this is not possible for postgresql module. I tried adding a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=372)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=374)
