# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=374

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 375

---

## [Metricbeat generating disabled modules dashboards](https://discuss.elastic.co/t/metricbeat-generating-disabled-modules-dashboards/172554)

<div class="topic-metadata">

**Author:** [@groverjatin17](https://discuss.elastic.co/u/groverjatin17)\
**Replies:** 2\
**Last updated:** [March 16, 2019, 4:21am UTC](https://discuss.elastic.co/t/metricbeat-generating-disabled-modules-dashboards/172554 "2019-03-16T04:21:19Z")

</div>

Hi All, I was trying Metricbeat demo from this link. I ran this command(although it said already enabled) ./metricbeat modules enable system I edited ES host name and Kibana Hostname. Started MetricBeat ./metric…

---

## [FileBeat 1.3.1 sends logs containing json to logstash 2.4](https://discuss.elastic.co/t/filebeat-1-3-1-sends-logs-containing-json-to-logstash-2-4/172622)

<div class="topic-metadata">

**Author:** [@Jerry\_Wang1](https://discuss.elastic.co/u/Jerry_Wang1)\
**Replies:** 0\
**Last updated:** [March 16, 2019, 2:52am UTC](https://discuss.elastic.co/t/filebeat-1-3-1-sends-logs-containing-json-to-logstash-2-4/172622 "2019-03-16T02:52:01Z")

</div>

My log format is a json string per each line as below. {"level":"INFO","message":"Loading database shards","source":"UBS.Bootstrap","details":"","type":"ubs-log4net","@version":1,"host":"JERRYWANG01","@timestamp":"2019-…

---

## [Help on: Can't get text on a START\_OBJECT](https://discuss.elastic.co/t/help-on-cant-get-text-on-a-start-object/172193)

<div class="topic-metadata">

**Author:** [@mobidyc](https://discuss.elastic.co/u/mobidyc)\
**Replies:** 7\
**Last updated:** [March 15, 2019, 8:39pm UTC](https://discuss.elastic.co/t/help-on-cant-get-text-on-a-start-object/172193 "2019-03-15T20:39:56Z")

</div>

Hello, I know it is a widely discussed subject but I don't know understand how to solve it. from what I understood, it is a conflict between the filebeat mapping and my template, but I just can't rename the conflictin…

---

## [Resend old logs from filebeat to logstash](https://discuss.elastic.co/t/resend-old-logs-from-filebeat-to-logstash/172402)

<div class="topic-metadata">

**Author:** [@Arthur19](https://discuss.elastic.co/u/Arthur19)\
**Replies:** 2\
**Last updated:** [March 15, 2019, 5:45pm UTC](https://discuss.elastic.co/t/resend-old-logs-from-filebeat-to-logstash/172402 "2019-03-15T17:45:15Z")

</div>

Hi, Thanks in advance for your help. I would like to reload some logs to customize additional fields. I have noticed that registry file in filebeat configuration keeps track of the files already picked. However, if I re…

---

## [Metricbeat apache module - error.message:HTTP error 404 in status: 404 Not Found](https://discuss.elastic.co/t/metricbeat-apache-module-error-message-http-error-404-in-status-404-not-found/169911)

<div class="topic-metadata">

**Author:** [@bradfordaemorton](https://discuss.elastic.co/u/bradfordaemorton)\
**Replies:** 9\
**Last updated:** [March 15, 2019, 3:40pm UTC](https://discuss.elastic.co/t/metricbeat-apache-module-error-message-http-error-404-in-status-404-not-found/169911 "2019-03-15T15:40:18Z")

</div>

Hi All, I have enabled the merticbeat module for apache. When reviewing the logs in Kibana I notice that I get an error -HTTP error 404 in status: 404 Not Found. I guess there is something wrong in my configure? Wha…

---

## [Compiled Filebeat for rpi successfully but spool doesn't work](https://discuss.elastic.co/t/compiled-filebeat-for-rpi-successfully-but-spool-doesnt-work/172374)

<div class="topic-metadata">

**Author:** [@Zen\_Spartan1](https://discuss.elastic.co/u/Zen_Spartan1)\
**Replies:** 4\
**Last updated:** [March 15, 2019, 3:33pm UTC](https://discuss.elastic.co/t/compiled-filebeat-for-rpi-successfully-but-spool-doesnt-work/172374 "2019-03-15T15:33:59Z")

</div>

I have successfully compiled Filebeat 6.6.2 for the RPI, filebeat works as expected but completely ignores settings spool settings to write to a file. The log shows filebeat working normally but contains no reference to …

---

## [Ecs, metricbeat, docker, apache, stdout where am I going wrong?](https://discuss.elastic.co/t/ecs-metricbeat-docker-apache-stdout-where-am-i-going-wrong/172440)

<div class="topic-metadata">

**Author:** [@ppafford](https://discuss.elastic.co/u/ppafford)\
**Replies:** 3\
**Last updated:** [March 15, 2019, 3:30pm UTC](https://discuss.elastic.co/t/ecs-metricbeat-docker-apache-stdout-where-am-i-going-wrong/172440 "2019-03-15T15:30:48Z")

</div>

Running metricbeat on ECS cluster in it's own docker container. running my application (including apache with the application) on another container. Both my app and apache log to STDOUT. have metricbeats setup for auto d…

---

## [Auditbeat issue - custom audit rule not working](https://discuss.elastic.co/t/auditbeat-issue-custom-audit-rule-not-working/172133)

<div class="topic-metadata">

**Author:** [@frankytamil](https://discuss.elastic.co/u/frankytamil)\
**Replies:** 1\
**Last updated:** [March 15, 2019, 2:44pm UTC](https://discuss.elastic.co/t/auditbeat-issue-custom-audit-rule-not-working/172133 "2019-03-15T14:44:54Z")

</div>

I am new to ELK... I have installed single node... Elasticsearch.. auditbeat and Kibana.... i can see documents in elasticsearch/kibana on default audits enabled bu auditbeat; not the one i enabled. \[root@elk-testing…

---

## [Winlogbeat Can create diiferent indices](https://discuss.elastic.co/t/winlogbeat-can-create-diiferent-indices/171895)

<div class="topic-metadata">

**Author:** [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Replies:** 7\
**Last updated:** [March 15, 2019, 2:10pm UTC](https://discuss.elastic.co/t/winlogbeat-can-create-diiferent-indices/171895 "2019-03-15T14:10:45Z")

</div>

instead of having Winlogbeat create daily indices We can create separate index for logs from different client(Different machine) to one elasticsearch server

---

## [Cannot drop\_event by system.syslog.program field](https://discuss.elastic.co/t/cannot-drop-event-by-system-syslog-program-field/172371)

<div class="topic-metadata">

**Author:** [@arustleund](https://discuss.elastic.co/u/arustleund)\
**Replies:** 1\
**Last updated:** [March 15, 2019, 2:07pm UTC](https://discuss.elastic.co/t/cannot-drop-event-by-system-syslog-program-field/172371 "2019-03-15T14:07:56Z")

</div>

Version: filebeat-6.6.2-darwin-x86\_64 I am attempting to drop events from Filebeat using a processor. I have the system module enabled and I would like to drop events using conditions matching fields from the system mod…

---

## [Performance Filebeat in a webhosting environment](https://discuss.elastic.co/t/performance-filebeat-in-a-webhosting-environment/172355)

<div class="topic-metadata">

**Author:** [@michali](https://discuss.elastic.co/u/michali)\
**Replies:** 1\
**Last updated:** [March 15, 2019, 2:05pm UTC](https://discuss.elastic.co/t/performance-filebeat-in-a-webhosting-environment/172355 "2019-03-15T14:05:08Z")

</div>

Hey I'm doing an internship at a hosting company and I got a question about what gives us the best performance. The endgoal is to pipe all apache and php logfiles into Logstash. The options are: Push all apache files…

---

## [Metricbeat elasticsearch module not showing index fields](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780)

<div class="topic-metadata">

**Author:** [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Replies:** 14\
**Last updated:** [March 15, 2019, 1:26pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780 "2019-03-15T13:26:46Z")

</div>

node and node\_stats are working but not seeing index fileds coming into metricbeat. module: elasticsearch metricsets: node - node\_stats index index\_summary - shard period: 10s hosts: \["http://...:9200"\]

---

## [How to collect a custom metric using metricbeat](https://discuss.elastic.co/t/how-to-collect-a-custom-metric-using-metricbeat/172250)

<div class="topic-metadata">

**Author:** [@msk\_76](https://discuss.elastic.co/u/msk_76)\
**Replies:** 4\
**Last updated:** [March 15, 2019, 12:15pm UTC](https://discuss.elastic.co/t/how-to-collect-a-custom-metric-using-metricbeat/172250 "2019-03-15T12:15:55Z")

</div>

I have to create a sampled time series data by running a command( by application on RH 7 Linux) at interval of 5minutes that will generate a output. Now i want to tag this time ( of fixed interval of 5 mins) to the data…

---

## [Cannot select host on System Overview after upgrade to 6.6.0](https://discuss.elastic.co/t/cannot-select-host-on-system-overview-after-upgrade-to-6-6-0/166642)

<div class="topic-metadata">

**Author:** [@carrion](https://discuss.elastic.co/u/carrion)\
**Replies:** 7\
**Last updated:** [March 15, 2019, 8:16am UTC](https://discuss.elastic.co/t/cannot-select-host-on-system-overview-after-upgrade-to-6-6-0/166642 "2019-03-15T08:16:23Z")

</div>

Hello, After upgrade from 6.5.0 to 6.6.0 I cannot select host on System Overview page by double click to view Host Overview data. Filter field is empty. Anyway, I can apply filter manually, but how I can fix this? Than…

---

## [Can Filebeat Handle Load to Push Around 200Mil events per hour to kafka](https://discuss.elastic.co/t/can-filebeat-handle-load-to-push-around-200mil-events-per-hour-to-kafka/172043)

<div class="topic-metadata">

**Author:** [@userguy](https://discuss.elastic.co/u/userguy)\
**Replies:** 2\
**Last updated:** [March 14, 2019, 7:16am UTC](https://discuss.elastic.co/t/can-filebeat-handle-load-to-push-around-200mil-events-per-hour-to-kafka/172043 "2019-03-14T07:16:02Z")

</div>

Hello , Has any one optimized Filebeat to send more than 200Mil events per hour to kafka to various topics . Because what i am seeing in my setup is it is way too slow to handle or carter that request - It is only able…

---

## [Error connection from filebeat to Logstash](https://discuss.elastic.co/t/error-connection-from-filebeat-to-logstash/172145)

<div class="topic-metadata">

**Author:** [@Zachary](https://discuss.elastic.co/u/Zachary)\
**Replies:** 5\
**Last updated:** [March 15, 2019, 6:56am UTC](https://discuss.elastic.co/t/error-connection-from-filebeat-to-logstash/172145 "2019-03-15T06:56:43Z")

</div>

I set up the filebeat to ingest logs and pass to Logstash using SSL however when I try to test the connection to between filebeat and logstash using curl the following error shows: \* SSL read: errno -5961 (PR\_CONNECT\_R…

---

## [Beats documentation for yum repo has an error](https://discuss.elastic.co/t/beats-documentation-for-yum-repo-has-an-error/172370)

<div class="topic-metadata">

**Author:** [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Replies:** 1\
**Last updated:** [March 14, 2019, 7:52pm UTC](https://discuss.elastic.co/t/beats-documentation-for-yum-repo-has-an-error/172370 "2019-03-14T19:52:09Z")

</div>

Hi, Filebeat doc for 7.0.0-beta1: https://www.elastic.co/guide/en/beats/filebeat/7.0/setup-repositories.html Shows a .repo file with: https://artifacts.elastic.co/packages/6.x-prerelease/yum That is for 6.x pre-rele…

---

## [Heartbeat bug with fix in 7.x, if no backport... doc fix in 6.x?](https://discuss.elastic.co/t/heartbeat-bug-with-fix-in-7-x-if-no-backport-doc-fix-in-6-x/172377)

<div class="topic-metadata">

**Author:** [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Replies:** 3\
**Last updated:** [March 14, 2019, 4:52pm UTC](https://discuss.elastic.co/t/heartbeat-bug-with-fix-in-7-x-if-no-backport-doc-fix-in-6-x/172377 "2019-03-14T16:52:45Z")

</div>

Hi, I lost some time investigating why Heartbeat 6.6.2 (lastest stable) was not respecting the "Host" http header I was configuring in an HTTP monitor. I was using exactly what the doc was saying, etc. Turns out when …

---

## [ELK clustering](https://discuss.elastic.co/t/elk-clustering/172064)

<div class="topic-metadata">

**Author:** [@cppatel](https://discuss.elastic.co/u/cppatel)\
**Replies:** 4\
**Last updated:** [March 14, 2019, 2:24pm UTC](https://discuss.elastic.co/t/elk-clustering/172064 "2019-03-14T14:24:13Z")

</div>

We are going to do clustering of ELK nodes. So the idea is to run whole ELK on 1 node as well as on the second node too with same configuration of ELK. But we want to make a second node as a standby node ( file beat shou…

---

## [AWS Network and IAM Roles configuration](https://discuss.elastic.co/t/aws-network-and-iam-roles-configuration/172195)

<div class="topic-metadata">

**Author:** [@nielsoncr](https://discuss.elastic.co/u/nielsoncr)\
**Replies:** 2\
**Last updated:** [March 14, 2019, 2:15pm UTC](https://discuss.elastic.co/t/aws-network-and-iam-roles-configuration/172195 "2019-03-14T14:15:32Z")

</div>

I would like to be able to deploy a FunctionBeat in AWS that will ship CloudWatch Logs to an Elastic cluster deployed in a private VPC. This would require the FunctionBeat installer to support VPC and subnet configurati…

---

## [Filebeat NOT sending all matched log entries](https://discuss.elastic.co/t/filebeat-not-sending-all-matched-log-entries/169103)

<div class="topic-metadata">

**Author:** [@sundiv](https://discuss.elastic.co/u/sundiv)\
**Replies:** 11\
**Last updated:** [March 14, 2019, 1:41pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-all-matched-log-entries/169103 "2019-03-14T13:41:01Z")

</div>

Hello I'm using FileBeats version 6.6.0 on both Windows and RHEL 7 (also tried on previous versions) and having some issues parsing a log file greater than 12MB (our application log file sizes are 65MB and 150MB). We ar…

---

## [Filebeat is SLOW?](https://discuss.elastic.co/t/filebeat-is-slow/171564)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 3\
**Last updated:** [March 14, 2019, 1:25pm UTC](https://discuss.elastic.co/t/filebeat-is-slow/171564 "2019-03-14T13:25:20Z")

</div>

Hello, Filebeat developers and users, I am wondering what is your experience with filebeat output throughput? If I interpret the following filebeat log correctly, filebeat throughput to kafka is only 53KBps. we pin fil…

---

## [Unable to process joblogs coming from filebeat](https://discuss.elastic.co/t/unable-to-process-joblogs-coming-from-filebeat/172309)

<div class="topic-metadata">

**Author:** [@Sapna](https://discuss.elastic.co/u/Sapna)\
**Replies:** 0\
**Last updated:** [March 14, 2019, 10:36am UTC](https://discuss.elastic.co/t/unable-to-process-joblogs-coming-from-filebeat/172309 "2019-03-14T10:36:43Z")

</div>

Hello, I have a job logs for DB2 and they are coming from filebeat. I want to extract message, error code , table name, DB instance from logs to visualize them in kibana. Logs are for DB instance : EXXXX 2019/03/08 2…

---

## [Filebeat fields.yml](https://discuss.elastic.co/t/filebeat-fields-yml/171605)

<div class="topic-metadata">

**Author:** [@2ps](https://discuss.elastic.co/u/2ps)\
**Replies:** 3\
**Last updated:** [March 14, 2019, 11:46am UTC](https://discuss.elastic.co/t/filebeat-fields-yml/171605 "2019-03-14T11:46:26Z")

</div>

When specifying our fields.yml, I had several questions: How do we specify what should be the default time field for kibana? Is there any way to specify the moment.js format for the date field for kibana? What, if any,…

---

## [Filebeat (6.5.4) modules how to remove unused fields](https://discuss.elastic.co/t/filebeat-6-5-4-modules-how-to-remove-unused-fields/171943)

<div class="topic-metadata">

**Author:** [@Stancho](https://discuss.elastic.co/u/Stancho)\
**Replies:** 2\
**Last updated:** [March 14, 2019, 11:12am UTC](https://discuss.elastic.co/t/filebeat-6-5-4-modules-how-to-remove-unused-fields/171943 "2019-03-14T11:12:32Z")

</div>

Hi, i am using some filebeat modules (nginx, logstash, elasticsearch, kibana, redis), but some of the produced fields are not important for me and I don't want to save them in elasticsearch. Is there a possibility to re…

---

## [Another value for system.auth.ssh.event in the system module?](https://discuss.elastic.co/t/another-value-for-system-auth-ssh-event-in-the-system-module/172118)

<div class="topic-metadata">

**Author:** [@swedishmike](https://discuss.elastic.co/u/swedishmike)\
**Replies:** 3\
**Last updated:** [March 14, 2019, 11:11am UTC](https://discuss.elastic.co/t/another-value-for-system-auth-ssh-event-in-the-system-module/172118 "2019-03-14T11:11:26Z")

</div>

After hardening my ssh server I am now seeing quite a lot of the following messages: Mar 13 10:16:41 XXXXXXX sshd\[8349\]: Unable to negotiate with X.X.X.X port 58623: no matching key exchange method found. Their offer: d…

---

## [Metricbeats-6.6.1 on kubernetes](https://discuss.elastic.co/t/metricbeats-6-6-1-on-kubernetes/171453)

<div class="topic-metadata">

**Author:** [@Jitendra\_Gupta](https://discuss.elastic.co/u/Jitendra_Gupta)\
**Replies:** 3\
**Last updated:** [March 14, 2019, 7:44am UTC](https://discuss.elastic.co/t/metricbeats-6-6-1-on-kubernetes/171453 "2019-03-14T07:44:14Z")

</div>

As per the attached screenshot1 - looks like our metricbeat is configured correctly but the kubernetes dashboard does not load and fails with the attached error.We are using elastic6.6.1 stack. Any help on this will be h…

---

## [Add custom metadata to events](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 6\
**Last updated:** [March 14, 2019, 7:30am UTC](https://discuss.elastic.co/t/add-custom-metadata-to-events/166695 "2019-03-14T07:30:30Z")

</div>

Hi, Is it possible to add custom metadata to events? I like the concept of meta.cloud.\* and would like to add something like ec2 tags to that, nested under meta.cloud.tags.\* for everything on that instance. Alternativ…

---

## [Problem with Dashboard on system module (URGENT)](https://discuss.elastic.co/t/problem-with-dashboard-on-system-module-urgent/171777)

<div class="topic-metadata">

**Author:** [@khergner](https://discuss.elastic.co/u/khergner)\
**Replies:** 8\
**Last updated:** [March 14, 2019, 7:28am UTC](https://discuss.elastic.co/t/problem-with-dashboard-on-system-module-urgent/171777 "2019-03-14T07:28:21Z")

</div>

Hi, I get the following error, I don't understand why this is happening. Why not load values? Logstash input { beats { port =\> 5044 } } output { elasticsearch { hosts =\> \["http://172.28.26.152:9200"\] m…

---

## [Filebeat re-indexes old logs that have previously harvested](https://discuss.elastic.co/t/filebeat-re-indexes-old-logs-that-have-previously-harvested/170400)

<div class="topic-metadata">

**Author:** [@hubertn](https://discuss.elastic.co/u/hubertn)\
**Replies:** 2\
**Last updated:** [March 13, 2019, 5:30pm UTC](https://discuss.elastic.co/t/filebeat-re-indexes-old-logs-that-have-previously-harvested/170400 "2019-03-13T17:30:10Z")

</div>

We have a set logs file that roll over when it gets to a certain size; we keep 50 old files. We are using Log4Net to perform the log and roll over. On average, we may have 2 to 10 files per day. We create daily index …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=373)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=375)
