# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=376

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 377

---

## [Ayuda para cambiar en \_index de filebeat por la ruta](https://discuss.elastic.co/t/ayuda-para-cambiar-en-index-de-filebeat-por-la-ruta/171541)

<div class="topic-metadata">

**Author:** [@joseantoniotg26](https://discuss.elastic.co/u/joseantoniotg26)\
**Replies:** 0\
**Last updated:** [March 8, 2019, 6:04pm UTC](https://discuss.elastic.co/t/ayuda-para-cambiar-en-index-de-filebeat-por-la-ruta/171541 "2019-03-08T18:04:36Z")

</div>

Tengo configurado el Kibana en un server funcionando y 3 maquinas con filebeat enviando logs. Todo funciona bien pero necesito cambiar los nombres que salen en los campos \_index del Kibana para que me salgan los nombres…

---

## [Add a timestamp from the log line in filebeat](https://discuss.elastic.co/t/add-a-timestamp-from-the-log-line-in-filebeat/171511)

<div class="topic-metadata">

**Author:** [@Janjko](https://discuss.elastic.co/u/Janjko)\
**Replies:** 2\
**Last updated:** [March 9, 2019, 4:56pm UTC](https://discuss.elastic.co/t/add-a-timestamp-from-the-log-line-in-filebeat/171511 "2019-03-09T16:56:13Z")

</div>

I made an app that uses Nlog to log into a file. Then I added the functionality within the app to download Filebeat and ship the logs to a central Elastic Stack. I thought about Nlog.Target.Elasticsearch, but I like the …

---

## [I can't see logs when I upgrade kubernetes filebeat 6.0 to 6.6.1](https://discuss.elastic.co/t/i-cant-see-logs-when-i-upgrade-kubernetes-filebeat-6-0-to-6-6-1/171480)

<div class="topic-metadata">

**Author:** [@irraz](https://discuss.elastic.co/u/irraz)\
**Replies:** 3\
**Last updated:** [March 9, 2019, 4:04pm UTC](https://discuss.elastic.co/t/i-cant-see-logs-when-i-upgrade-kubernetes-filebeat-6-0-to-6-6-1/171480 "2019-03-09T16:04:11Z")

</div>

Hi there, I tried upgrade filebeat 6.0 to 6.6.1 in kubernetes: https://raw.githubusercontent.com/elastic/beats/6.0/deploy/kubernetes/filebeat-kubernetes.yaml to https://raw.githubusercontent.com/elastic/beats/6.6/dep…

---

## [Problem while importing logs](https://discuss.elastic.co/t/problem-while-importing-logs/171463)

<div class="topic-metadata">

**Author:** [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Replies:** 2\
**Last updated:** [March 9, 2019, 6:43am UTC](https://discuss.elastic.co/t/problem-while-importing-logs/171463 "2019-03-09T06:43:54Z")

</div>

What does it actually means? 2019-03-08T14:50:07.716+0530 INFO \[monitoring\] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":70,"time":{"ms":7…

---

## [Filebeat log ERR State for READER-034.log should have been dropped, but couldn't as state is not finished](https://discuss.elastic.co/t/filebeat-log-err-state-for-reader-034-log-should-have-been-dropped-but-couldnt-as-state-is-not-finished/171559)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 0\
**Last updated:** [March 8, 2019, 9:38pm UTC](https://discuss.elastic.co/t/filebeat-log-err-state-for-reader-034-log-should-have-been-dropped-but-couldnt-as-state-is-not-finished/171559 "2019-03-08T21:38:49Z")

</div>

Dear Filebeat experts, my filebeat log is full of the following error messages. I am wondering what goes wrong? Thanks! 2019-03-08T21:21:26Z ERR State for READER-034.log should have been dropped, but couldn't as stat…

---

## [Response Time, Flows and New Transaction Protocol](https://discuss.elastic.co/t/response-time-flows-and-new-transaction-protocol/170671)

<div class="topic-metadata">

**Author:** [@nandrik](https://discuss.elastic.co/u/nandrik)\
**Replies:** 2\
**Last updated:** [March 8, 2019, 8:55pm UTC](https://discuss.elastic.co/t/response-time-flows-and-new-transaction-protocol/170671 "2019-03-08T20:55:06Z")

</div>

I've read the post: Finding total latency(round trip time or response time) per flow? I want to be able for a new transaction protocol, call it elastic which transacts on port: 2019 to be able to calculate response time…

---

## [Metricbeat dashboard with negative values](https://discuss.elastic.co/t/metricbeat-dashboard-with-negative-values/170843)

<div class="topic-metadata">

**Author:** [@1862347ba9566e72a47d](https://discuss.elastic.co/u/1862347ba9566e72a47d)\
**Replies:** 1\
**Last updated:** [March 8, 2019, 8:43pm UTC](https://discuss.elastic.co/t/metricbeat-dashboard-with-negative-values/170843 "2019-03-08T20:43:51Z")

</div>

Help me please deal with the graphs on the dashboard - \[Metricbeat System\] Host overview Why are there negative values on the graphs? And what do they mean? And how can there be more than 100 percent CPU Usage?

---

## [Mapper parsing exception from autodiscover docker logs](https://discuss.elastic.co/t/mapper-parsing-exception-from-autodiscover-docker-logs/171551)

<div class="topic-metadata">

**Author:** [@Cova](https://discuss.elastic.co/u/Cova)\
**Replies:** 0\
**Last updated:** [March 8, 2019, 8:06pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-from-autodiscover-docker-logs/171551 "2019-03-08T20:06:37Z")

</div>

There seems to be a type conflict with the way the fields get created by filebeat with auto-discovered docker logs, which is causing me to get mapper parsing exceptions from my nginx logs. I've got a bunch of different …

---

## [Elastic not following their own advice to prevent sparsity?](https://discuss.elastic.co/t/elastic-not-following-their-own-advice-to-prevent-sparsity/170760)

<div class="topic-metadata">

**Author:** [@agx](https://discuss.elastic.co/u/agx)\
**Replies:** 2\
**Last updated:** [March 8, 2019, 7:09pm UTC](https://discuss.elastic.co/t/elastic-not-following-their-own-advice-to-prevent-sparsity/170760 "2019-03-08T19:09:08Z")

</div>

With the deprecation and eventual removal of "document types" from indices in ES 6 and 7 respectively, I am confused about filebeat's behaviour. For instance, if I am running filebeat to collect nginx and postgresql logs…

---

## [Kibana could not monitoring filebeat](https://discuss.elastic.co/t/kibana-could-not-monitoring-filebeat/171296)

<div class="topic-metadata">

**Author:** [@ly217](https://discuss.elastic.co/u/ly217)\
**Replies:** 3\
**Last updated:** [March 8, 2019, 3:50pm UTC](https://discuss.elastic.co/t/kibana-could-not-monitoring-filebeat/171296 "2019-03-08T15:50:38Z")

</div>

my filebeat verion is 6.2.3 .the elasticsearch version is 6.6.1.kibana version is also 6.6.1.I have enabled filebeat x-pack monitoring . but the kibana could not monitoring filebeat.

---

## [Https - 443 - response time - Packetbeat](https://discuss.elastic.co/t/https-443-response-time-packetbeat/170914)

<div class="topic-metadata">

**Author:** [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Replies:** 1\
**Last updated:** [March 8, 2019, 3:30pm UTC](https://discuss.elastic.co/t/https-443-response-time-packetbeat/170914 "2019-03-08T15:30:08Z")

</div>

Hi There, I would like to know if there is anyway to find out the https (443 )response time in packetbeat, i could see the http (80) response time . Is there any field available or how to find out ? Please do let…

---

## [Is there support for selecting containers other than by container id?](https://discuss.elastic.co/t/is-there-support-for-selecting-containers-other-than-by-container-id/168125)

<div class="topic-metadata">

**Author:** [@username1234](https://discuss.elastic.co/u/username1234)\
**Replies:** 3\
**Last updated:** [March 8, 2019, 2:51pm UTC](https://discuss.elastic.co/t/is-there-support-for-selecting-containers-other-than-by-container-id/168125 "2019-03-08T14:51:18Z")

</div>

I want to apply a prospector to only some of the docker containers I am running. However, it appears that the only way to select the containers in the prospector yml config is to specify container.ids which only matches …

---

## [Winlogbeat To Send All Windows Events](https://discuss.elastic.co/t/winlogbeat-to-send-all-windows-events/170805)

<div class="topic-metadata">

**Author:** [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Replies:** 1\
**Last updated:** [March 8, 2019, 2:26pm UTC](https://discuss.elastic.co/t/winlogbeat-to-send-all-windows-events/170805 "2019-03-08T14:26:25Z")

</div>

How or what is the best way to configure the Winlogbeat.yml file to send all Windows events? Thoughts?

---

## [Track VPN activity](https://discuss.elastic.co/t/track-vpn-activity/171041)

<div class="topic-metadata">

**Author:** [@fedwe](https://discuss.elastic.co/u/fedwe)\
**Replies:** 1\
**Last updated:** [March 8, 2019, 2:24pm UTC](https://discuss.elastic.co/t/track-vpn-activity/171041 "2019-03-08T14:24:14Z")

</div>

Is it possible to track someone's activity when he uses a VPN using packet beat. Like detect that he opened a VPN and see his browsing activity for example.

---

## [Trying to get a filebeat running in docker-compose](https://discuss.elastic.co/t/trying-to-get-a-filebeat-running-in-docker-compose/169958)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 4\
**Last updated:** [March 8, 2019, 11:42am UTC](https://discuss.elastic.co/t/trying-to-get-a-filebeat-running-in-docker-compose/169958 "2019-03-08T11:42:50Z")

</div>

Hi All I'm a bit unsure what I've done wrong. I have a docker-compose that places dmarc logs in a folder. I then want to have another docker image running with a filebeat, that pushes it into logstash. But for some r…

---

## [Filebeat6.6启动报错](https://discuss.elastic.co/t/filebeat6-6/170108)

<div class="topic-metadata">

**Author:** [@ctinm](https://discuss.elastic.co/u/ctinm)\
**Replies:** 6\
**Last updated:** [March 6, 2019, 9:01am UTC](https://discuss.elastic.co/t/filebeat6-6/170108 "2019-03-06T09:01:12Z")

</div>

Exiting: error unpacking config data: can not convert 'string' into 'object' accessing 'output.logstash' (source:'filebeat.yml') accessing 'output' (source:'filebeat.yml')

---

## [Winlogbeat desplay version number in the display name](https://discuss.elastic.co/t/winlogbeat-desplay-version-number-in-the-display-name/171312)

<div class="topic-metadata">

**Author:** [@tv-itops](https://discuss.elastic.co/u/tv-itops)\
**Replies:** 1\
**Last updated:** [March 7, 2019, 11:49pm UTC](https://discuss.elastic.co/t/winlogbeat-desplay-version-number-in-the-display-name/171312 "2019-03-07T23:49:41Z")

</div>

We use saltstack for the configuration management und deployment. winlogbeat have found one difference between the other windows compatible beat agents. If we get the display name and version via saltstack, then in con…

---

## [Creating new beat throws an error](https://discuss.elastic.co/t/creating-new-beat-throws-an-error/171386)

<div class="topic-metadata">

**Author:** [@ash\_coder](https://discuss.elastic.co/u/ash_coder)\
**Replies:** 0\
**Last updated:** [March 7, 2019, 9:32pm UTC](https://discuss.elastic.co/t/creating-new-beat-throws-an-error/171386 "2019-03-07T21:32:34Z")

</div>

Hi, I am creating a new beat and following the documentation https://www.elastic.co/guide/en/beats/libbeat/5.4/setting-up-beat.html I hit this error. Could some one please help. I am on the master branch /vendor/githu…

---

## [Question on filebeat multiline pattern](https://discuss.elastic.co/t/question-on-filebeat-multiline-pattern/171134)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 5\
**Last updated:** [March 7, 2019, 9:12pm UTC](https://discuss.elastic.co/t/question-on-filebeat-multiline-pattern/171134 "2019-03-07T21:12:04Z")

</div>

I am trying to get the logs from a legacy system into Elastic via Filebeat. Needless to say it is the so called "Log from Hell". Since it is a csv I am using grok to great relief. There is one thing which is bothering m…

---

## [Filebeat - Sends all the messages on every new message written to log file](https://discuss.elastic.co/t/filebeat-sends-all-the-messages-on-every-new-message-written-to-log-file/171223)

<div class="topic-metadata">

**Author:** [@ash\_coder](https://discuss.elastic.co/u/ash_coder)\
**Replies:** 2\
**Last updated:** [March 7, 2019, 6:46pm UTC](https://discuss.elastic.co/t/filebeat-sends-all-the-messages-on-every-new-message-written-to-log-file/171223 "2019-03-07T18:46:25Z")

</div>

Hi, I am running the filebeat with below configuration. Filebeat always publishes all the messages from the log file whenever there is a new message written into it instead of reading the messages after the offset value…

---

## [Unable to deploy functionbeat to s3 bucket](https://discuss.elastic.co/t/unable-to-deploy-functionbeat-to-s3-bucket/171371)

<div class="topic-metadata">

**Author:** [@Bhavani\_Ananth](https://discuss.elastic.co/u/Bhavani_Ananth)\
**Replies:** 0\
**Last updated:** [March 7, 2019, 6:35pm UTC](https://discuss.elastic.co/t/unable-to-deploy-functionbeat-to-s3-bucket/171371 "2019-03-07T18:35:07Z")

</div>

Hello Team, I was experimenting with /functionbeat-7.0.0-beta1-linux-x86\_64. When I try to deploy I always get the error, 2019-03-07T18:20:44.997Z DEBUG \[aws.executor\] aws/executor.go:46 The executor is…

---

## [Filebeat not sending specific Log Files](https://discuss.elastic.co/t/filebeat-not-sending-specific-log-files/170776)

<div class="topic-metadata">

**Author:** [@shiva\_jawanjal](https://discuss.elastic.co/u/shiva_jawanjal)\
**Replies:** 4\
**Last updated:** [March 7, 2019, 6:28pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-specific-log-files/170776 "2019-03-07T18:28:38Z")

</div>

I have configured filebeat 6.6 on a Windows instance. Weird thing is, it is sending logs for IIS but not for file I have specified even though the filebeat can detect it. Filebeat.yml --\> filebeat.inputs: - type: log …

---

## [LIst of URLS in heartbeat.yml doesn't show in Heartbeat dashboard](https://discuss.elastic.co/t/list-of-urls-in-heartbeat-yml-doesnt-show-in-heartbeat-dashboard/167320)

<div class="topic-metadata">

**Author:** [@Iraida07](https://discuss.elastic.co/u/Iraida07)\
**Replies:** 8\
**Last updated:** [March 7, 2019, 5:24pm UTC](https://discuss.elastic.co/t/list-of-urls-in-heartbeat-yml-doesnt-show-in-heartbeat-dashboard/167320 "2019-03-07T17:24:10Z")

</div>

Hi guys. I recently configure 18 Urls to query in the heartbeat.yml file, heartbeat worked fine but since a few days when I open the heartbeat dashboard, I just have five urls listed. I checked the configuration file (h…

---

## [Problems getting pipeline to run in filebeat module](https://discuss.elastic.co/t/problems-getting-pipeline-to-run-in-filebeat-module/171156)

<div class="topic-metadata">

**Author:** [@John\_Swift](https://discuss.elastic.co/u/John_Swift)\
**Replies:** 2\
**Last updated:** [March 7, 2019, 4:07pm UTC](https://discuss.elastic.co/t/problems-getting-pipeline-to-run-in-filebeat-module/171156 "2019-03-07T16:07:07Z")

</div>

hi folks I'm having some trouble with GROK within a custom filebeat module Runing filebeat 6.5 on windows The mudule is ingesting & sending the logs to elasticserach without any issues so i dont know if the module is…

---

## [Listen request from using port](https://discuss.elastic.co/t/listen-request-from-using-port/171158)

<div class="topic-metadata">

**Author:** [@Welton\_Leao\_Machado](https://discuss.elastic.co/u/Welton_Leao_Machado)\
**Replies:** 1\
**Last updated:** [March 7, 2019, 3:14pm UTC](https://discuss.elastic.co/t/listen-request-from-using-port/171158 "2019-03-07T15:14:42Z")

</div>

i want catch every request in a specific port where a application server is running. Example my jboss is running in 8080 and i want catch the request all requests received in port 8080. Is possible this with Filbeat?

---

## [Get only new lines from file log](https://discuss.elastic.co/t/get-only-new-lines-from-file-log/171205)

<div class="topic-metadata">

**Author:** [@Welton\_Leao\_Machado](https://discuss.elastic.co/u/Welton_Leao_Machado)\
**Replies:** 1\
**Last updated:** [March 7, 2019, 3:12pm UTC](https://discuss.elastic.co/t/get-only-new-lines-from-file-log/171205 "2019-03-07T15:12:13Z")

</div>

Hi guys. I'll catch a new log to monitor but i want get only new lines from file log because the log file is not rotary and i can ignore the past this file.

---

## [Ensuring order for syslog events](https://discuss.elastic.co/t/ensuring-order-for-syslog-events/171117)

<div class="topic-metadata">

**Author:** [@thro](https://discuss.elastic.co/u/thro)\
**Replies:** 5\
**Last updated:** [March 7, 2019, 2:50pm UTC](https://discuss.elastic.co/t/ensuring-order-for-syslog-events/171117 "2019-03-07T14:50:00Z")

</div>

Hello, I have a problem trying with ordering of syslog events once they enter ElasticSearch. The problem is that the syslog daemon only has a resolution to the second, so the file itself is in correct order but there i…

---

## [Unable to load kibana dashboards](https://discuss.elastic.co/t/unable-to-load-kibana-dashboards/171214)

<div class="topic-metadata">

**Author:** [@James\_Kiarie](https://discuss.elastic.co/u/James_Kiarie)\
**Replies:** 1\
**Last updated:** [March 7, 2019, 2:06pm UTC](https://discuss.elastic.co/t/unable-to-load-kibana-dashboards/171214 "2019-03-07T14:06:39Z")

</div>

Hey guys! I'm trying to loads kibana dashboards by following instructions in the link https://www.elastic.co/guide/en/beats/libbeat/1.1/load-kibana-dashboards.html However, I'm getting this error! {"error":"Content-Ty…

---

## [Unable to access filebeat stats over HTTP](https://discuss.elastic.co/t/unable-to-access-filebeat-stats-over-http/171273)

<div class="topic-metadata">

**Author:** [@Nitish\_Raj](https://discuss.elastic.co/u/Nitish_Raj)\
**Replies:** 1\
**Last updated:** [March 7, 2019, 10:50am UTC](https://discuss.elastic.co/t/unable-to-access-filebeat-stats-over-http/171273 "2019-03-07T10:50:55Z")

</div>

Hi I am trying to access http://localhost:5066/stats URL to see statistics of filebeat events but it is not reachable. I am using windows machine. This is my configuration in filebeat.yml file : =======================…

---

## [No error or warning logs regarding Harvesting and connection failure to elasticsearch](https://discuss.elastic.co/t/no-error-or-warning-logs-regarding-harvesting-and-connection-failure-to-elasticsearch/171260)

<div class="topic-metadata">

**Author:** [@sintension](https://discuss.elastic.co/u/sintension)\
**Replies:** 1\
**Last updated:** [March 7, 2019, 10:31am UTC](https://discuss.elastic.co/t/no-error-or-warning-logs-regarding-harvesting-and-connection-failure-to-elasticsearch/171260 "2019-03-07T10:31:22Z")

</div>

Hi Filebeat Community, I'm stuck in a problem in which I couldn't make further progress because of the lack of error or warning logs. Let me express my situation clearly. \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* START of Working Case \*\*\*\*\*\*…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=375)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=377)
