# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=377

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 378

---

## [Need to use Multiline with Filebeat Configuration on Specific Tags](https://discuss.elastic.co/t/need-to-use-multiline-with-filebeat-configuration-on-specific-tags/171110)

<div class="topic-metadata">

**Author:** [@manya12](https://discuss.elastic.co/u/manya12)\
**Replies:** 2\
**Last updated:** [March 7, 2019, 10:26am UTC](https://discuss.elastic.co/t/need-to-use-multiline-with-filebeat-configuration-on-specific-tags/171110 "2019-03-07T10:26:12Z")

</div>

Hi Team, We are using filebeat and have set up multiple prospectors in its configuration. We are also using multiline in it, now we want to add one more prospector but do not want it to use multiline configuration. Her…

---

## [Filebeat6.6.1 start up failed](https://discuss.elastic.co/t/filebeat6-6-1-start-up-failed/171236)

<div class="topic-metadata">

**Author:** [@ly217](https://discuss.elastic.co/u/ly217)\
**Replies:** 4\
**Last updated:** [March 7, 2019, 6:55am UTC](https://discuss.elastic.co/t/filebeat6-6-1-start-up-failed/171236 "2019-03-07T06:55:38Z")

</div>

the filebeat version is 6.6.1,the os version Red Hat Enterprise Linux Server release 5.7,when start up filebeat ,it failed.the log showed: runtime: epollwait on fd 4 failed with 38 fatal error: runtime: netpoll failed …

---

## [Filebeat multiline regexp patterns help](https://discuss.elastic.co/t/filebeat-multiline-regexp-patterns-help/170648)

<div class="topic-metadata">

**Author:** [@pup\_seba](https://discuss.elastic.co/u/pup_seba)\
**Replies:** 4\
**Last updated:** [March 7, 2019, 6:26am UTC](https://discuss.elastic.co/t/filebeat-multiline-regexp-patterns-help/170648 "2019-03-07T06:26:02Z")

</div>

Hi, I'm trying to use multline in filebeat to ship this application log entry as 1 document to logstash. 2019-02-12 00:01:57,302 WARN \[ScheduledTask-1\] \[name=account@domain.com;mid=1513;ds=CAL-11170;\] datasource - Sc…

---

## [\[AWS\] No functions are enabled for selected provider](https://discuss.elastic.co/t/aws-no-functions-are-enabled-for-selected-provider/171184)

<div class="topic-metadata">

**Author:** [@tyler\_hilsabeck](https://discuss.elastic.co/u/tyler_hilsabeck)\
**Replies:** 2\
**Last updated:** [March 6, 2019, 8:28pm UTC](https://discuss.elastic.co/t/aws-no-functions-are-enabled-for-selected-provider/171184 "2019-03-06T20:28:04Z")

</div>

Hello! I am trying to collect VPC flowlogs in Cloudwatch Logs using the functionbeat. The deploy command works as expected. I am running Functionbeat 6.6.1 on a RHEL 7 machine. Environment variables are correctly set. …

---

## [\[AWS\] Functionbeat to logstash config problem](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842)

<div class="topic-metadata">

**Author:** [@Marcin\_Druzgala](https://discuss.elastic.co/u/Marcin_Druzgala)\
**Replies:** 4\
**Last updated:** [March 6, 2019, 8:07pm UTC](https://discuss.elastic.co/t/aws-functionbeat-to-logstash-config-problem/168842 "2019-03-06T20:07:05Z")

</div>

Hi so I have prepared following config for my functionbeat: functionbeat.provider.aws.deploy\_bucket: "functionbeat-deploy" functionbeat.provider.aws.functions: - name: cloudwatch enabled: true type: cloudwatc…

---

## [Filebeat does not send logs](https://discuss.elastic.co/t/filebeat-does-not-send-logs/170562)

<div class="topic-metadata">

**Author:** [@jonathanhher](https://discuss.elastic.co/u/jonathanhher)\
**Replies:** 1\
**Last updated:** [March 6, 2019, 4:23pm UTC](https://discuss.elastic.co/t/filebeat-does-not-send-logs/170562 "2019-03-06T16:23:24Z")

</div>

good day, everyone, thank you in advance for the collaboration. I have installed a filebeat agent on a Linux Debian server and it does not send data through the network. I have verified the configuration and did not id…

---

## [How to configure FileBeat and LogStash to read multiple input files and process them separately?](https://discuss.elastic.co/t/how-to-configure-filebeat-and-logstash-to-read-multiple-input-files-and-process-them-separately/170568)

<div class="topic-metadata">

**Author:** [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Replies:** 1\
**Last updated:** [March 6, 2019, 4:21pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-and-logstash-to-read-multiple-input-files-and-process-them-separately/170568 "2019-03-06T16:21:40Z")

</div>

Hello, I have tried to look into similar threads, but I am not sure I got to a conclusive solution. Here is my situation: I have a number N of log files, with same type of content I have already a LogStash config…

---

## [Problems with values from paths other than the specified path](https://discuss.elastic.co/t/problems-with-values-from-paths-other-than-the-specified-path/170668)

<div class="topic-metadata">

**Author:** [@a86236df74eecab0f8a3](https://discuss.elastic.co/u/a86236df74eecab0f8a3)\
**Replies:** 1\
**Last updated:** [March 6, 2019, 4:12pm UTC](https://discuss.elastic.co/t/problems-with-values-from-paths-other-than-the-specified-path/170668 "2019-03-06T16:12:23Z")

</div>

hello. I wanted to analyze log informatins in real time by receiving them from the Wi-Fi terminal. so I used rsyslog to get logs and saved them as /var/log/remote.log. filebeat.yml filebeat.inputs: type: log enable…

---

## [Filebeat not capturing all events in syslog](https://discuss.elastic.co/t/filebeat-not-capturing-all-events-in-syslog/170876)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 1\
**Last updated:** [March 6, 2019, 3:39pm UTC](https://discuss.elastic.co/t/filebeat-not-capturing-all-events-in-syslog/170876 "2019-03-06T15:39:26Z")

</div>

I am currently using the following pipeline to get my data to Elasticsearch syslog----\>filebeat----\>kafka----\>logstash----\>elasticsearch I am trying to capture shutdown and restart events from the syslog. The syslog en…

---

## [Set "Time Filter field" name from filebeat](https://discuss.elastic.co/t/set-time-filter-field-name-from-filebeat/170614)

<div class="topic-metadata">

**Author:** [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Replies:** 2\
**Last updated:** [March 6, 2019, 3:34pm UTC](https://discuss.elastic.co/t/set-time-filter-field-name-from-filebeat/170614 "2019-03-06T15:34:48Z")

</div>

From filebeat, If I create default template name, by default takes @timestamp but what I want is I need to pass logtimestamp as default time filter field. setup.template.name: "org-n4-apex" setup.template.pattern: "org-…

---

## [Filebeat shows i/o timeout when pushing file](https://discuss.elastic.co/t/filebeat-shows-i-o-timeout-when-pushing-file/170976)

<div class="topic-metadata">

**Author:** [@vladiulianbogdan](https://discuss.elastic.co/u/vladiulianbogdan)\
**Replies:** 1\
**Last updated:** [March 6, 2019, 3:22pm UTC](https://discuss.elastic.co/t/filebeat-shows-i-o-timeout-when-pushing-file/170976 "2019-03-06T15:22:49Z")

</div>

Hi, I have a very simple setup. I have the ELK stack in a docker container. I am using the latest image from here https://hub.docker.com/r/sebp/elk/. I've installed Filebeat (6.6.1) on the machine. The configuration fi…

---

## [Filebeat Error...what am I doing wrong?](https://discuss.elastic.co/t/filebeat-error-what-am-i-doing-wrong/171021)

<div class="topic-metadata">

**Author:** [@Evan\_Skinner](https://discuss.elastic.co/u/Evan_Skinner)\
**Replies:** 1\
**Last updated:** [March 6, 2019, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-error-what-am-i-doing-wrong/171021 "2019-03-06T15:18:31Z")

</div>

Greetings: Below is the output when I try to start filebeats. What is going wrong and how can I fix this? I will provide more info as needed. Thank you! 2019-03-05T19:14:42.582-0800 INFO instance/beat.go:616 Home path:…

---

## [Does filebeat support fetching logfiles from defined kubernetes pods?](https://discuss.elastic.co/t/does-filebeat-support-fetching-logfiles-from-defined-kubernetes-pods/171076)

<div class="topic-metadata">

**Author:** [@Crusader](https://discuss.elastic.co/u/Crusader)\
**Replies:** 1\
**Last updated:** [March 6, 2019, 3:02pm UTC](https://discuss.elastic.co/t/does-filebeat-support-fetching-logfiles-from-defined-kubernetes-pods/171076 "2019-03-06T15:02:19Z")

</div>

Out of the box filebeat fetches each container in k8s environment. However i have some pods which belong to plugins or controllers which i dont want to process. I already had a look into: https://www.elastic.co/guide/…

---

## [MSMQ data -\> Elastic Search](https://discuss.elastic.co/t/msmq-data-elastic-search/171131)

<div class="topic-metadata">

**Author:** [@Daniel\_Mirz](https://discuss.elastic.co/u/Daniel_Mirz)\
**Replies:** 0\
**Last updated:** [March 6, 2019, 2:19pm UTC](https://discuss.elastic.co/t/msmq-data-elastic-search/171131 "2019-03-06T14:19:06Z")

</div>

Hi, i am trying to ship messages from MSMQ in one of our servers. is there a way to do it? i succeeded to get System data (network,CPU...) with MetricBeat but no data on Queues

---

## [Problem with Dashboard - \[Metricbeat Apache\] Overview Full](https://discuss.elastic.co/t/problem-with-dashboard-metricbeat-apache-overview-full/169921)

<div class="topic-metadata">

**Author:** [@bradfordaemorton](https://discuss.elastic.co/u/bradfordaemorton)\
**Replies:** 2\
**Last updated:** [March 6, 2019, 8:52am UTC](https://discuss.elastic.co/t/problem-with-dashboard-metricbeat-apache-overview-full/169921 "2019-03-06T08:52:10Z")

</div>

Hi All, When I try and use the Apache Metricbeat dashboard I get the error could not locate that index-pattern however when I look in Management \> Kibana \> Index I can see the index and index pattern defined. Screensho…

---

## [Audibeat access auditd time](https://discuss.elastic.co/t/audibeat-access-auditd-time/170929)

<div class="topic-metadata">

**Author:** [@Lukass](https://discuss.elastic.co/u/Lukass)\
**Replies:** 0\
**Last updated:** [March 5, 2019, 2:23pm UTC](https://discuss.elastic.co/t/audibeat-access-auditd-time/170929 "2019-03-05T14:23:08Z")

</div>

Hi, Does someone know what is time sequence that auditbeat is getting events from auditd? Is it possible to reduce this time? I made some testing if auditbeat is logging reboot commands for server - unsuccessfully. W…

---

## [Conexion metricbeat](https://discuss.elastic.co/t/conexion-metricbeat/170996)

<div class="topic-metadata">

**Author:** [@edwin](https://discuss.elastic.co/u/edwin)\
**Replies:** 0\
**Last updated:** [March 5, 2019, 10:02pm UTC](https://discuss.elastic.co/t/conexion-metricbeat/170996 "2019-03-05T22:02:48Z")

</div>

Regards I have been trying to send the metrics of a linux server by means of metricbeat to the server where I have installed the elasticsearch and the kibana but I am getting the following error which I can not find sol…

---

## [Can we change Java heap memory in Filebeat? If yes, how and where do we change?](https://discuss.elastic.co/t/can-we-change-java-heap-memory-in-filebeat-if-yes-how-and-where-do-we-change/168933)

<div class="topic-metadata">

**Author:** [@Chandana](https://discuss.elastic.co/u/Chandana)\
**Replies:** 9\
**Last updated:** [March 5, 2019, 8:13pm UTC](https://discuss.elastic.co/t/can-we-change-java-heap-memory-in-filebeat-if-yes-how-and-where-do-we-change/168933 "2019-03-05T20:13:52Z")

</div>

Hi, Our filebeat installed server gives Swap Usage CRITICAL most of the time. Initially we used to restart the server, but we are trying for a solution for this. We have a 20GB RAM for that server. Do we have any opt…

---

## [Heartbeat to Monitor FTP Server Status](https://discuss.elastic.co/t/heartbeat-to-monitor-ftp-server-status/170073)

<div class="topic-metadata">

**Author:** [@Micah\_Hunsberger](https://discuss.elastic.co/u/Micah_Hunsberger)\
**Replies:** 2\
**Last updated:** [March 5, 2019, 5:51pm UTC](https://discuss.elastic.co/t/heartbeat-to-monitor-ftp-server-status/170073 "2019-03-05T17:51:43Z")

</div>

Is there a way to monitor the status of an FTP server using heartbeat? There isn't an ftp monitor type like there is for http

---

## [Beat for server directory logging number of files and other metadata](https://discuss.elastic.co/t/beat-for-server-directory-logging-number-of-files-and-other-metadata/170948)

<div class="topic-metadata">

**Author:** [@blaskowitz](https://discuss.elastic.co/u/blaskowitz)\
**Replies:** 0\
**Last updated:** [March 5, 2019, 4:24pm UTC](https://discuss.elastic.co/t/beat-for-server-directory-logging-number-of-files-and-other-metadata/170948 "2019-03-05T16:24:32Z")

</div>

Hello, I'm looking for a beat that logs a server's directory metadata, like the current count of files in a directory for a period of time, but I can't find anything similar. Is there a beat like this, or execbeat with …

---

## [Filebeats Pattern now working as expected?](https://discuss.elastic.co/t/filebeats-pattern-now-working-as-expected/170931)

<div class="topic-metadata">

**Author:** [@justx](https://discuss.elastic.co/u/justx)\
**Replies:** 1\
**Last updated:** [March 5, 2019, 3:39pm UTC](https://discuss.elastic.co/t/filebeats-pattern-now-working-as-expected/170931 "2019-03-05T15:39:52Z")

</div>

I am attempting to use a filebeats 5.1. One of the multi line patterns i am using is causing me alot of trouble and I am not seeing why, I was hoping yall could point me in the right direction. What I am trying to use, …

---

## [Window size never grow up](https://discuss.elastic.co/t/window-size-never-grow-up/169517)

<div class="topic-metadata">

**Author:** [@keyolk](https://discuss.elastic.co/u/keyolk)\
**Replies:** 5\
**Last updated:** [March 5, 2019, 3:19pm UTC](https://discuss.elastic.co/t/window-size-never-grow-up/169517 "2019-03-05T15:19:48Z")

</div>

In our service environment, some of filebeats consume almost 100% of cpu core. After checking lumberjack protocol link and its tcpdump, I found that it always sends window size 1 And from below seems that if windowSi…

---

## [Monitoring files changes](https://discuss.elastic.co/t/monitoring-files-changes/170552)

<div class="topic-metadata">

**Author:** [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Replies:** 4\
**Last updated:** [March 5, 2019, 12:29pm UTC](https://discuss.elastic.co/t/monitoring-files-changes/170552 "2019-03-05T12:29:25Z")

</div>

I use auditbeat for monitoring files and directories and works fine when access to file from "vim, nano, etc" . But if modify from script or cat (redirection) not capture the event. Example: vim /tmp/foo (edit and save…

---

## [Heartbeat Indices not getting cleaned up](https://discuss.elastic.co/t/heartbeat-indices-not-getting-cleaned-up/170527)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 3\
**Last updated:** [March 5, 2019, 9:07am UTC](https://discuss.elastic.co/t/heartbeat-indices-not-getting-cleaned-up/170527 "2019-03-05T09:07:43Z")

</div>

Heartbeat seems to be creating endless heartbeat-6.5.4-yyyy.MM.dd indices and not cleaning them up. How can we define when such indices can be deleted? Metricbeat, APM and other modules seem to do this How exactly can …

---

## [Failed to parse field "tls.certificate\_not\_valid\_before" from heartbeat](https://discuss.elastic.co/t/failed-to-parse-field-tls-certificate-not-valid-before-from-heartbeat/165707)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 13\
**Last updated:** [March 5, 2019, 8:32am UTC](https://discuss.elastic.co/t/failed-to-parse-field-tls-certificate-not-valid-before-from-heartbeat/165707 "2019-03-05T08:32:28Z")

</div>

Hello, I have installed a clean installation of Elasticsearch 6.5.4 and heartbeat 6.5.4(Elasticsearch uses HTTPS). My heartbeat config is as follows: heartbeat.monitors: - type: http # List or urls to query urls…

---

## [Is MetricBeat available for Windows platform as open source w/out licensing?](https://discuss.elastic.co/t/is-metricbeat-available-for-windows-platform-as-open-source-w-out-licensing/170783)

<div class="topic-metadata">

**Author:** [@nybeat](https://discuss.elastic.co/u/nybeat)\
**Replies:** 1\
**Last updated:** [March 5, 2019, 5:28am UTC](https://discuss.elastic.co/t/is-metricbeat-available-for-windows-platform-as-open-source-w-out-licensing/170783 "2019-03-05T05:28:58Z")

</div>

I was led to believe that x-pack is the licensed extensions of the open source Elastic stack and that MetricBeat is something that is not open source. Can someone provide me with evidence that the Windows versions of Me…

---

## [Filebeat to Logstash (in Elastic Stack) over LAN](https://discuss.elastic.co/t/filebeat-to-logstash-in-elastic-stack-over-lan/168294)

<div class="topic-metadata">

**Author:** [@chadmando](https://discuss.elastic.co/u/chadmando)\
**Replies:** 8\
**Last updated:** [March 5, 2019, 12:22am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-in-elastic-stack-over-lan/168294 "2019-03-05T00:22:44Z")

</div>

Hello, looking for some help pushing logs from Ubuntu 18 to an elastic static installation running on the same subnet. Filebeat on Ubuntu is version 6.6.0 doesn't show publishing errors or other errors. When I run with…

---

## [MSI / EXE installer for beat agents](https://discuss.elastic.co/t/msi-exe-installer-for-beat-agents/170739)

<div class="topic-metadata">

**Author:** [@tv-itops](https://discuss.elastic.co/u/tv-itops)\
**Replies:** 0\
**Last updated:** [March 4, 2019, 2:23pm UTC](https://discuss.elastic.co/t/msi-exe-installer-for-beat-agents/170739 "2019-03-04T14:23:58Z")

</div>

Is it planned to offer an official MSI / Exe installer for the beat agents? The current ZIP package contains only 2 PowerShell scripts, which only cover the basics. Anyone using Beat Agents on Windows will usually need …

---

## [Processors syntax](https://discuss.elastic.co/t/processors-syntax/170491)

<div class="topic-metadata">

**Author:** [@Lukass](https://discuss.elastic.co/u/Lukass)\
**Replies:** 2\
**Last updated:** [March 4, 2019, 8:57am UTC](https://discuss.elastic.co/t/processors-syntax/170491 "2019-03-04T08:57:39Z")

</div>

Hi, I'm having problems with syntax on creating processor for dropping message in auditbeat. My field process.args has value \["-bash"\] if I configure processor: processors: - drop\_event: when: …

---

## [Filebeat 6.6 system module fields not being exported(or parsed)](https://discuss.elastic.co/t/filebeat-6-6-system-module-fields-not-being-exported-or-parsed/169476)

<div class="topic-metadata">

**Author:** [@ChrisOdney](https://discuss.elastic.co/u/ChrisOdney)\
**Replies:** 7\
**Last updated:** [March 4, 2019, 5:40am UTC](https://discuss.elastic.co/t/filebeat-6-6-system-module-fields-not-being-exported-or-parsed/169476 "2019-03-04T05:40:52Z")

</div>

Hi, I have installed filebeat and enabled the system module, I have also loaded the ingest pipelines manually as the filebeat output is being sent to logstash and to ES from there. The system dashboards were working ear…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=376)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=378)
