# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=378

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 379

---

## [Metricbeat pushing the whole template and the induced sparsity](https://discuss.elastic.co/t/metricbeat-pushing-the-whole-template-and-the-induced-sparsity/168545)

<div class="topic-metadata">

**Author:** [@wokmichel](https://discuss.elastic.co/u/wokmichel)\
**Replies:** 3\
**Last updated:** [March 3, 2019, 10:49pm UTC](https://discuss.elastic.co/t/metricbeat-pushing-the-whole-template-and-the-induced-sparsity/168545 "2019-03-03T22:49:27Z")

</div>

Hello, a question about metricbeat template and sparsity : My understanding is that when setting up the metricbeat template in ElasticSearch via the following command : metricbeat setup --template The whole template …

---

## [Index per beat type](https://discuss.elastic.co/t/index-per-beat-type/170571)

<div class="topic-metadata">

**Author:** [@Mike\_Frank](https://discuss.elastic.co/u/Mike_Frank)\
**Replies:** 0\
**Last updated:** [March 1, 2019, 11:14pm UTC](https://discuss.elastic.co/t/index-per-beat-type/170571 "2019-03-01T23:14:28Z")

</div>

With 7.0 and elastic common schema is there any reason to not combine all beats into a single index pattern?

---

## [Kubernetes Module - Kubelet -unauthorized error](https://discuss.elastic.co/t/kubernetes-module-kubelet-unauthorized-error/170436)

<div class="topic-metadata">

**Author:** [@pbedadham](https://discuss.elastic.co/u/pbedadham)\
**Replies:** 2\
**Last updated:** [March 1, 2019, 9:49pm UTC](https://discuss.elastic.co/t/kubernetes-module-kubelet-unauthorized-error/170436 "2019-03-01T21:49:22Z")

</div>

Hi I have Kubernetes 1.13.1 and Metricbeat 6.6.1 with Elasticsearch and Kibana. Not getting metrics of Kubelet though Kube-state-metric is working as expected. --Not working-- kubernetes.yml: |- - module: kubernetes …

---

## [How to log failure of start/stop of a service?](https://discuss.elastic.co/t/how-to-log-failure-of-start-stop-of-a-service/170502)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 0\
**Last updated:** [March 1, 2019, 1:13pm UTC](https://discuss.elastic.co/t/how-to-log-failure-of-start-stop-of-a-service/170502 "2019-03-01T13:13:59Z")

</div>

I want to track whether a normal user attempted to run a service. The command for starting/stopping service is given as below: service filebeat start I wrote an auditd rule like below in Auditbeat's auditd rules sectio…

---

## [Can I use co.elastic.logs/processors.dissect.tokenizer label without slash?](https://discuss.elastic.co/t/can-i-use-co-elastic-logs-processors-dissect-tokenizer-label-without-slash/170483)

<div class="topic-metadata">

**Author:** [@Defozo](https://discuss.elastic.co/u/Defozo)\
**Replies:** 1\
**Last updated:** [March 1, 2019, 6:08pm UTC](https://discuss.elastic.co/t/can-i-use-co-elastic-logs-processors-dissect-tokenizer-label-without-slash/170483 "2019-03-01T18:08:47Z")

</div>

I'd like to deploy my containers to AWS ECS with filebeat autodiscover feature and use co.elastic.logs/processors.dissect.tokenizer to provide the tokenizer but unfortunately AWS ECS does not support / in docker labels: …

---

## [Filebeat and laravel logs](https://discuss.elastic.co/t/filebeat-and-laravel-logs/170295)

<div class="topic-metadata">

**Author:** [@belledota](https://discuss.elastic.co/u/belledota)\
**Replies:** 6\
**Last updated:** [March 1, 2019, 4:00pm UTC](https://discuss.elastic.co/t/filebeat-and-laravel-logs/170295 "2019-03-01T16:00:15Z")

</div>

Hello everyone. Can someone tell me how to set up laravel logs in filebeat (without logstash). In the picture i showed with arrows that i want the log to break: date to timestamp field, type in env field, error-type t…

---

## [Getting all Shell activity](https://discuss.elastic.co/t/getting-all-shell-activity/170236)

<div class="topic-metadata">

**Author:** [@nwed](https://discuss.elastic.co/u/nwed)\
**Replies:** 1\
**Last updated:** [March 1, 2019, 3:48pm UTC](https://discuss.elastic.co/t/getting-all-shell-activity/170236 "2019-03-01T15:48:57Z")

</div>

We have been doing some diligent testing against auditbeat and auditd. This is a very strong solution that doesn't require too much of the host system(with the right rules). We have expanded our testing to make sure that…

---

## [FileBeat not following logfile](https://discuss.elastic.co/t/filebeat-not-following-logfile/170241)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 2\
**Last updated:** [March 1, 2019, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-not-following-logfile/170241 "2019-03-01T15:40:45Z")

</div>

FileBeat is not noticing new entries in our log files. To take one example we have a logfile modified recently (20:59 CET) but the registry is showing 14:40 UTC (15:40 CET): {"source":"D:\\hybris\\log\\tomcat\\access.201902…

---

## [Processor condition pattern input](https://discuss.elastic.co/t/processor-condition-pattern-input/170403)

<div class="topic-metadata">

**Author:** [@Welton\_Leao\_Machado](https://discuss.elastic.co/u/Welton_Leao_Machado)\
**Replies:** 1\
**Last updated:** [March 1, 2019, 1:17pm UTC](https://discuss.elastic.co/t/processor-condition-pattern-input/170403 "2019-03-01T13:17:35Z")

</div>

Hello guys, I have two files on type log input in filebeat.yml. So, in first file, a have pattern multiline and another no have pattern becausa is single line. Is possible use processor conditions to input use pattern …

---

## [Auditbeat configuring file](https://discuss.elastic.co/t/auditbeat-configuring-file/169751)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 1\
**Last updated:** [March 1, 2019, 9:19am UTC](https://discuss.elastic.co/t/auditbeat-configuring-file/169751 "2019-03-01T09:19:02Z")

</div>

Hello , I just tried to work on auditbeat this is my auditbeat.yml file auditbeat.modules: module: file\_integrity paths: /home/rdave/Desktop/xyz.cfg.txt setup.template.enabled: false reload.enabled: true reload.…

---

## [Exclude lines regex for excluding all non json logs is not working](https://discuss.elastic.co/t/exclude-lines-regex-for-excluding-all-non-json-logs-is-not-working/167704)

<div class="topic-metadata">

**Author:** [@venkat\_t](https://discuss.elastic.co/u/venkat_t)\
**Replies:** 11\
**Last updated:** [March 1, 2019, 6:09am UTC](https://discuss.elastic.co/t/exclude-lines-regex-for-excluding-all-non-json-logs-is-not-working/167704 "2019-03-01T06:09:23Z")

</div>

Dear Elastic team, My requirement is to exclude non JSON lines from the file. Data comes into the log file are mainly json and the third-party libraries sometimes emit non-JSON single and multiline logs. JSON logs are s…

---

## [How to push a specific log to an existing index?](https://discuss.elastic.co/t/how-to-push-a-specific-log-to-an-existing-index/170331)

<div class="topic-metadata">

**Author:** [@iamashutosh](https://discuss.elastic.co/u/iamashutosh)\
**Replies:** 1\
**Last updated:** [March 1, 2019, 4:27am UTC](https://discuss.elastic.co/t/how-to-push-a-specific-log-to-an-existing-index/170331 "2019-03-01T04:27:44Z")

</div>

Hello Team, I have a specific log that I want to push to elasticsearch's index. Log name: example-2018-02-04.log index name: filebeat-2019.02.04 Here is my filebeat.yml: filebeat: prospectors: - input\_type: log …

---

## [FileBeat Elasticsearch module not closing files after rollover](https://discuss.elastic.co/t/filebeat-elasticsearch-module-not-closing-files-after-rollover/170097)

<div class="topic-metadata">

**Author:** [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Replies:** 4\
**Last updated:** [March 1, 2019, 4:11am UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-module-not-closing-files-after-rollover/170097 "2019-03-01T04:11:13Z")

</div>

Hi, I just had a strange issue, I had enabled the Elasticsearch module in FileBeat. Today, during a healthcheck, I saw that my coordinating node had over 90% disk utilization. On logging on and validating with du -sh I…

---

## [AWS ECS container log, metrics](https://discuss.elastic.co/t/aws-ecs-container-log-metrics/170391)

<div class="topic-metadata">

**Author:** [@joappdev](https://discuss.elastic.co/u/joappdev)\
**Replies:** 0\
**Last updated:** [February 28, 2019, 5:24pm UTC](https://discuss.elastic.co/t/aws-ecs-container-log-metrics/170391 "2019-02-28T17:24:21Z")

</div>

Hi, I'm new here. Planning to use elastic cloud to get logs from AWS ECS containers get metrics (CPU, RAM) from ECS container instance (EC2) get metrics (CPU, RAM) from running containers get APM metrics from my node.…

---

## [Problem getting IIS logs into Kibana using IIS module](https://discuss.elastic.co/t/problem-getting-iis-logs-into-kibana-using-iis-module/169913)

<div class="topic-metadata">

**Author:** [@tm8747a](https://discuss.elastic.co/u/tm8747a)\
**Replies:** 3\
**Last updated:** [February 28, 2019, 8:31pm UTC](https://discuss.elastic.co/t/problem-getting-iis-logs-into-kibana-using-iis-module/169913 "2019-02-28T20:31:25Z")

</div>

I'm trying to setup Filebeats to directly ship some IIS logs to ElasticSearch. While it appears my logs are getting picked up and making it to the server, when I open the Logs section in Kibana I get an entry but it's an…

---

## [Monitor changes in individual folders with FIM module](https://discuss.elastic.co/t/monitor-changes-in-individual-folders-with-fim-module/170398)

<div class="topic-metadata">

**Author:** [@olatunde.tokun](https://discuss.elastic.co/u/olatunde.tokun)\
**Replies:** 1\
**Last updated:** [February 28, 2019, 8:22pm UTC](https://discuss.elastic.co/t/monitor-changes-in-individual-folders-with-fim-module/170398 "2019-02-28T20:22:16Z")

</div>

Hello Auditbeat Team, I want to monitor individual user ssh folders for changes with the FIM module. /home/mary.jane/.ssh /home/frank.sinatra/.ssh /home/john.doe/.ssh Ive tried to use wildcards/regex within FIM but …

---

## [Metricbeat dashboards not showing up](https://discuss.elastic.co/t/metricbeat-dashboards-not-showing-up/170302)

<div class="topic-metadata">

**Author:** [@yash\_sachdeva](https://discuss.elastic.co/u/yash_sachdeva)\
**Replies:** 1\
**Last updated:** [February 28, 2019, 7:25pm UTC](https://discuss.elastic.co/t/metricbeat-dashboards-not-showing-up/170302 "2019-02-28T19:25:47Z")

</div>

Hi Team, I have installed metricbeat on kubernetes as per elastic's standard documentation with autodiscover and kube metadata. Even though I can see metricbeat data on the discover page, the metricbeat kubernetes dashb…

---

## [Metricbeat 6.3.2 upgrade breaks?](https://discuss.elastic.co/t/metricbeat-6-3-2-upgrade-breaks/142241)

<div class="topic-metadata">

**Author:** [@arlen](https://discuss.elastic.co/u/arlen)\
**Replies:** 8\
**Last updated:** [February 28, 2019, 3:43pm UTC](https://discuss.elastic.co/t/metricbeat-6-3-2-upgrade-breaks/142241 "2019-02-28T15:43:58Z")

</div>

CentOS 7.5.1804 (from /etc/centos-release) ES 6.3.2 -- checked via curl Metricbeat 6.3.2 (from debug log) System module. (from JSON in debug log) Debug logs don't show a lot that seems helpful. But there's a constant…

---

## [Is it possible to monitor SSL Certificate expiration using heartbeat without the CA certificate?](https://discuss.elastic.co/t/is-it-possible-to-monitor-ssl-certificate-expiration-using-heartbeat-without-the-ca-certificate/167110)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 3\
**Last updated:** [February 28, 2019, 3:34pm UTC](https://discuss.elastic.co/t/is-it-possible-to-monitor-ssl-certificate-expiration-using-heartbeat-without-the-ca-certificate/167110 "2019-02-28T15:34:24Z")

</div>

Hello, I have to monitor the expiration of some SSL Certificates and was making some tests with heartbeat. I know that if you have a http monitor using ssl and the ca certificate you will be able to have the expiration…

---

## [Heartbeat 7 seems to stop running](https://discuss.elastic.co/t/heartbeat-7-seems-to-stop-running/170261)

<div class="topic-metadata">

**Author:** [@RayS](https://discuss.elastic.co/u/RayS)\
**Replies:** 3\
**Last updated:** [February 28, 2019, 2:57pm UTC](https://discuss.elastic.co/t/heartbeat-7-seems-to-stop-running/170261 "2019-02-28T14:57:09Z")

</div>

I'm trying to nail down what is happening with it. I start heartbeat using a simple "./hearbeat &" and it seems to run fine for a couple of hours and then the process dies.

---

## [Winlogbeat capture http traffic and send to graylog](https://discuss.elastic.co/t/winlogbeat-capture-http-traffic-and-send-to-graylog/170217)

<div class="topic-metadata">

**Author:** [@Gopalakrishnan\_N](https://discuss.elastic.co/u/Gopalakrishnan_N)\
**Replies:** 2\
**Last updated:** [February 28, 2019, 2:42pm UTC](https://discuss.elastic.co/t/winlogbeat-capture-http-traffic-and-send-to-graylog/170217 "2019-02-28T14:42:51Z")

</div>

Does Winlogbeat capture HTTP traffic and send to Graylog? Thanks.

---

## [Heartbeat 7 rpm package is missing the Kibana/7 folder with dashboards](https://discuss.elastic.co/t/heartbeat-7-rpm-package-is-missing-the-kibana-7-folder-with-dashboards/169690)

<div class="topic-metadata">

**Author:** [@wazari](https://discuss.elastic.co/u/wazari)\
**Replies:** 6\
**Last updated:** [February 28, 2019, 2:07pm UTC](https://discuss.elastic.co/t/heartbeat-7-rpm-package-is-missing-the-kibana-7-folder-with-dashboards/169690 "2019-02-28T14:07:49Z")

</div>

When installing the Heartbeat package (rpm on CentOS) and configuring the Kibana config file and doing a # sudo heartbeat setup --dashboards the /usr/share/heartbeat/kibana/7 dir is missing so nothing gets configured - d…

---

## [How to Create different index pattern for different filebeat server?](https://discuss.elastic.co/t/how-to-create-different-index-pattern-for-different-filebeat-server/170287)

<div class="topic-metadata">

**Author:** [@Aashish\_Chugh](https://discuss.elastic.co/u/Aashish_Chugh)\
**Replies:** 4\
**Last updated:** [February 28, 2019, 12:29pm UTC](https://discuss.elastic.co/t/how-to-create-different-index-pattern-for-different-filebeat-server/170287 "2019-02-28T12:29:58Z")

</div>

Hi, I want to create a new index pattern for multiple filebeat server , like i have two server one is app and second is db server, for now both the logs is storing in same index. I try many ways to separate them but no…

---

## [Filebeat reports intermittent errors, sometimes successful, sometimes not!](https://discuss.elastic.co/t/filebeat-reports-intermittent-errors-sometimes-successful-sometimes-not/170083)

<div class="topic-metadata">

**Author:** [@TD1900](https://discuss.elastic.co/u/TD1900)\
**Replies:** 2\
**Last updated:** [February 28, 2019, 7:06am UTC](https://discuss.elastic.co/t/filebeat-reports-intermittent-errors-sometimes-successful-sometimes-not/170083 "2019-02-28T07:06:07Z")

</div>

Here is the output of docker logs! The original version 6.4.1 had this error, but now I change to 6.6.1 and still have this problem. Please help me analyze it, thank you! 2019-02-27T08:01:31.471+0700 ERROR pipeline/ou…

---

## [Filebeat repo](https://discuss.elastic.co/t/filebeat-repo/170090)

<div class="topic-metadata">

**Author:** [@danielc](https://discuss.elastic.co/u/danielc)\
**Replies:** 1\
**Last updated:** [February 27, 2019, 9:50pm UTC](https://discuss.elastic.co/t/filebeat-repo/170090 "2019-02-27T21:50:21Z")

</div>

Today, we're experiencing below errors when we install filebeat-5.6. Is there any issue with the repo? https://artifacts.elastic.co/packages/5.x/yum/repodata/repomd.xml: \[Errno 14\] problem making ssl connection Trying o…

---

## [Changing the index name for winlogbeat sent to elasticsearch](https://discuss.elastic.co/t/changing-the-index-name-for-winlogbeat-sent-to-elasticsearch/168722)

<div class="topic-metadata">

**Author:** [@bradfordaemorton](https://discuss.elastic.co/u/bradfordaemorton)\
**Replies:** 6\
**Last updated:** [February 27, 2019, 7:15pm UTC](https://discuss.elastic.co/t/changing-the-index-name-for-winlogbeat-sent-to-elasticsearch/168722 "2019-02-27T19:15:31Z")

</div>

Hi All, Just trying to change the name of the winlogbeat index to something more meaningful. Currently I get the following error: Exiting: setup.template.name and setup.template.pattern have to be set if index name is…

---

## [Packet beat - index created monthly](https://discuss.elastic.co/t/packet-beat-index-created-monthly/170203)

<div class="topic-metadata">

**Author:** [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Replies:** 2\
**Last updated:** [February 27, 2019, 6:52pm UTC](https://discuss.elastic.co/t/packet-beat-index-created-monthly/170203 "2019-02-27T18:52:44Z")

</div>

I want to have packetbeat index created monthly. In pcketbeat.yml I have chnaged configuration option as follow: #-------------------------- Elasticsearch output ------------------------------ output.elasticsearch: …

---

## [Best practices for multiple instances of file beat vs. one filebeat instance with multiple prospectors](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043)

<div class="topic-metadata">

**Author:** [@roblopes](https://discuss.elastic.co/u/roblopes)\
**Replies:** 4\
**Last updated:** [February 27, 2019, 1:52pm UTC](https://discuss.elastic.co/t/best-practices-for-multiple-instances-of-file-beat-vs-one-filebeat-instance-with-multiple-prospectors/170043 "2019-02-27T13:52:53Z")

</div>

Hi, I am replacing an existing enterprise logging system by Elastic Stack. I have hundreds of applications currently using the current system. Those applications they are spread across 3 or 4 servers (depending on the e…

---

## [Auditbeat tagging the events wrongly](https://discuss.elastic.co/t/auditbeat-tagging-the-events-wrongly/166682)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 3\
**Last updated:** [February 27, 2019, 1:15pm UTC](https://discuss.elastic.co/t/auditbeat-tagging-the-events-wrongly/166682 "2019-02-27T13:15:17Z")

</div>

OS : Centos 7 Version of Auditbeat : 6.4.0 Issue: When a file is modified, auditbeat used to tag it as "updated". But for some reason, it is updating as "created" only. Also file deletion events are not tagged too. Why…

---

## [Systemd logs from the docker service with filebeat](https://discuss.elastic.co/t/systemd-logs-from-the-docker-service-with-filebeat/170128)

<div class="topic-metadata">

**Author:** [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Replies:** 1\
**Last updated:** [February 27, 2019, 10:55am UTC](https://discuss.elastic.co/t/systemd-logs-from-the-docker-service-with-filebeat/170128 "2019-02-27T10:55:09Z")

</div>

Is there any way to get these kind of logs?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=377)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=379)
