# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=379

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 380

---

## [Filebeat Error decoding JSON: json: cannot unmarshal string into Go value of type map](https://discuss.elastic.co/t/filebeat-error-decoding-json-json-cannot-unmarshal-string-into-go-value-of-type-map/169064)

<div class="topic-metadata">

**Author:** [@analog\_memories](https://discuss.elastic.co/u/analog_memories)\
**Replies:** 5\
**Last updated:** [February 27, 2019, 10:15am UTC](https://discuss.elastic.co/t/filebeat-error-decoding-json-json-cannot-unmarshal-string-into-go-value-of-type-map/169064 "2019-02-27T10:15:50Z")

</div>

Hello, I have Filebeat 6.5.0, setup with the following filebeat.yml \> filebeat.inputs: \> - type: log \> enabled: true \> paths: \> - "C:/logs/info/\*registry2json.json" \> scan\_frequency: 10s \> json.keys\_…

---

## [Ingest custom nginx log format](https://discuss.elastic.co/t/ingest-custom-nginx-log-format/170005)

<div class="topic-metadata">

**Author:** [@tback](https://discuss.elastic.co/u/tback)\
**Replies:** 1\
**Last updated:** [February 27, 2019, 8:59am UTC](https://discuss.elastic.co/t/ingest-custom-nginx-log-format/170005 "2019-02-27T08:59:55Z")

</div>

I'm using filebeat, my setup is pretty plain: I index nginx log files. Now I wan't to log just one more field ($http\_host). Let's say I prefix every line with that: access\_log /var/log/nginx/access.log main becomes lo…

---

## [How do I output to Redis?](https://discuss.elastic.co/t/how-do-i-output-to-redis/169947)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 1\
**Last updated:** [February 27, 2019, 8:52am UTC](https://discuss.elastic.co/t/how-do-i-output-to-redis/169947 "2019-02-27T08:52:59Z")

</div>

I want to output index data to Redis for storage, can the central management implement it?

---

## [Why can't I import the metricbeat dashboard on Freebsd?](https://discuss.elastic.co/t/why-cant-i-import-the-metricbeat-dashboard-on-freebsd/168365)

<div class="topic-metadata">

**Author:** [@Tutorial\_Linux\_Indon](https://discuss.elastic.co/u/Tutorial_Linux_Indon)\
**Replies:** 8\
**Last updated:** [February 27, 2019, 8:08am UTC](https://discuss.elastic.co/t/why-cant-i-import-the-metricbeat-dashboard-on-freebsd/168365 "2019-02-27T08:08:28Z")

</div>

Good afternoon / afternoon, why can't I import the metricbeat dashboard on Freebsd? Next is the log Metricbaet Output. Feb 14 15:32:32 smtp140 metricbeat\[3834\]: ERROR instance/beat.go:667 Exiting: 1 error: 1 error: me…

---

## [Where does it install FileBeat?](https://discuss.elastic.co/t/where-does-it-install-filebeat/169963)

<div class="topic-metadata">

**Author:** [@Viti](https://discuss.elastic.co/u/Viti)\
**Replies:** 2\
**Last updated:** [February 27, 2019, 7:30am UTC](https://discuss.elastic.co/t/where-does-it-install-filebeat/169963 "2019-02-27T07:30:34Z")

</div>

Hello, We need to install FileBeat for send information to Logstash. We have 3 servers. The servers first and second contains apps and logs and the third contains ELK. Where do we install the FileBeat? We need to i…

---

## [Filebeat configure CentOS 7 with MariaDB](https://discuss.elastic.co/t/filebeat-configure-centos-7-with-mariadb/170093)

<div class="topic-metadata">

**Author:** [@Scraper](https://discuss.elastic.co/u/Scraper)\
**Replies:** 1\
**Last updated:** [February 27, 2019, 4:41am UTC](https://discuss.elastic.co/t/filebeat-configure-centos-7-with-mariadb/170093 "2019-02-27T04:41:19Z")

</div>

Trying to configure Filebeat to pull logs from a vanilla CentOS 7 with MariaDB. Does the default m y s q l module work?

---

## [Filebeat will choose the paths depending on your OS. - Listing?](https://discuss.elastic.co/t/filebeat-will-choose-the-paths-depending-on-your-os-listing/170094)

<div class="topic-metadata">

**Author:** [@Scraper](https://discuss.elastic.co/u/Scraper)\
**Replies:** 1\
**Last updated:** [February 27, 2019, 4:39am UTC](https://discuss.elastic.co/t/filebeat-will-choose-the-paths-depending-on-your-os-listing/170094 "2019-02-27T04:39:30Z")

</div>

Is there a listing of the paths per OS? Running CentOS 7 and seem to be finding a lack of path information disturbing. The default modules say "Filebeat will choose the paths depending on your OS." How do I know if Fi…

---

## [Single log entry being divided in ELK stack](https://discuss.elastic.co/t/single-log-entry-being-divided-in-elk-stack/170072)

<div class="topic-metadata">

**Author:** [@BhaveshVasnani](https://discuss.elastic.co/u/BhaveshVasnani)\
**Replies:** 5\
**Last updated:** [February 26, 2019, 10:03pm UTC](https://discuss.elastic.co/t/single-log-entry-being-divided-in-elk-stack/170072 "2019-02-26T22:03:12Z")

</div>

Greetings I have established the pipeline properly and the logs are sent via TCP to Filebeat and then it is being processed and passed further down the pipeline. But the issue is that Elasticsearch and Kibana dashboard …

---

## [Using a CRON job to fetch log files and overwrite current logs](https://discuss.elastic.co/t/using-a-cron-job-to-fetch-log-files-and-overwrite-current-logs/170052)

<div class="topic-metadata">

**Author:** [@julianfr](https://discuss.elastic.co/u/julianfr)\
**Replies:** 0\
**Last updated:** [February 26, 2019, 5:19pm UTC](https://discuss.elastic.co/t/using-a-cron-job-to-fetch-log-files-and-overwrite-current-logs/170052 "2019-02-26T17:19:51Z")

</div>

I'm new to the Elastic Stack and have been learning how to make things work. My client wants to be able to get stats for their hardware device which checks for software upgrades every evening. They use CDN77 to host thei…

---

## [Getting winlogbeat to speak to SecurityOnion](https://discuss.elastic.co/t/getting-winlogbeat-to-speak-to-securityonion/168456)

<div class="topic-metadata">

**Author:** [@johnyoungts](https://discuss.elastic.co/u/johnyoungts)\
**Replies:** 2\
**Last updated:** [February 26, 2019, 5:30pm UTC](https://discuss.elastic.co/t/getting-winlogbeat-to-speak-to-securityonion/168456 "2019-02-26T17:30:41Z")

</div>

I've been given the task to get our companies log monitoring up and going, so I'm really effing new to this. I have Security Onion installed - our local firewall is speaking to it fine - which is good. I have then want…

---

## [Wrong indices, every second](https://discuss.elastic.co/t/wrong-indices-every-second/168219)

<div class="topic-metadata">

**Author:** [@fooc](https://discuss.elastic.co/u/fooc)\
**Replies:** 2\
**Last updated:** [February 26, 2019, 1:01pm UTC](https://discuss.elastic.co/t/wrong-indices-every-second/168219 "2019-02-26T13:01:24Z")

</div>

Hi, When i start winlogbeat and use logstash or direct output to my elk every second an indices is created with wrong timestamps and the server crashes. I think something is wrong with the date notation but i cannot fi…

---

## [Can't see journal logs in kibana](https://discuss.elastic.co/t/cant-see-journal-logs-in-kibana/169862)

<div class="topic-metadata">

**Author:** [@DiogoB](https://discuss.elastic.co/u/DiogoB)\
**Replies:** 9\
**Last updated:** [February 26, 2019, 11:47am UTC](https://discuss.elastic.co/t/cant-see-journal-logs-in-kibana/169862 "2019-02-26T11:47:24Z")

</div>

Hello, I am new to ELK and I'm using elastic cloud on the free trial. I have setup filebeats on an EC2 machine and 2 log files were available instantly on kibana, which I can filter with fields I have setup on the file…

---

## [Filebeat fail to pick log event from the respective path](https://discuss.elastic.co/t/filebeat-fail-to-pick-log-event-from-the-respective-path/168822)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 2\
**Last updated:** [February 26, 2019, 11:00am UTC](https://discuss.elastic.co/t/filebeat-fail-to-pick-log-event-from-the-respective-path/168822 "2019-02-26T11:00:42Z")

</div>

HI Team, I'm using below configuration to process my log from my path to elasticsearch, filebeat.inputs: - type: log enabled: false paths: #- /var/log/\*.log - C:\\Go\\unirest\\go\\unirest\\output.json #=====…

---

## [Not able to start filebeat](https://discuss.elastic.co/t/not-able-to-start-filebeat/169597)

<div class="topic-metadata">

**Author:** [@rajesh-321](https://discuss.elastic.co/u/rajesh-321)\
**Replies:** 7\
**Last updated:** [February 26, 2019, 9:10am UTC](https://discuss.elastic.co/t/not-able-to-start-filebeat/169597 "2019-02-26T09:10:24Z")

</div>

Hi Team I am not able to start the filebeat service. below is the error I am getting \[root@inmbz1196 config\]# service filebeat status ● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsea…

---

## [DNS lookup failure "X.X.X": lookup X.X.X on \[::1\]:53: dial udp \[::1\]:53: socket: too many open files](https://discuss.elastic.co/t/dns-lookup-failure-x-x-x-lookup-x-x-x-on-1-dial-udp-1-socket-too-many-open-files/168667)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [February 25, 2019, 7:47pm UTC](https://discuss.elastic.co/t/dns-lookup-failure-x-x-x-lookup-x-x-x-on-1-dial-udp-1-socket-too-many-open-files/168667 "2019-02-25T19:47:43Z")

</div>

Hello World! I'm using Elastic stack 6.6.1 and my metricbeat worked fine for a while, then it stopped on it's own and I'm seeing following error in /var/log/metricbeat/metricbeat: 2019-02-16T04:36:05.176Z WARN transpor…

---

## [FIlebeat on PfSense](https://discuss.elastic.co/t/filebeat-on-pfsense/169877)

<div class="topic-metadata">

**Author:** [@daniel.gutierrez](https://discuss.elastic.co/u/daniel.gutierrez)\
**Replies:** 1\
**Last updated:** [February 25, 2019, 5:21pm UTC](https://discuss.elastic.co/t/filebeat-on-pfsense/169877 "2019-02-25T17:21:35Z")

</div>

Hello everyone! I have installed 2 ElasticStack on different servers, one for windows and one for linux and everythings works perfectly but I want to install FIlebeat on Pfsense Firewall the question in here is, how ca…

---

## [Filebeat inputs configured to output to multiple logstash pipelines](https://discuss.elastic.co/t/filebeat-inputs-configured-to-output-to-multiple-logstash-pipelines/168580)

<div class="topic-metadata">

**Author:** [@stuartdsmith](https://discuss.elastic.co/u/stuartdsmith)\
**Replies:** 3\
**Last updated:** [February 25, 2019, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-inputs-configured-to-output-to-multiple-logstash-pipelines/168580 "2019-02-25T17:07:52Z")

</div>

We would like to be able to configure filebeat to route different log files to different logstash pipelines. Is there a way to do this? As far as I can tell since we define the logstash port in the main filebeat configu…

---

## [Error creating a new enrollment token](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 4\
**Last updated:** [February 25, 2019, 3:49pm UTC](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320 "2019-02-25T15:49:22Z")

</div>

Hello World! I'm using Elastic Stack 6.6.1 and trying to follow Enroll Beats in central management along with Secrets keystore for secure settings and running into following issue: # echo changeme | filebeat keystore a…

---

## [Filebeat autodiscovery logging twice](https://discuss.elastic.co/t/filebeat-autodiscovery-logging-twice/169718)

<div class="topic-metadata">

**Author:** [@strowi](https://discuss.elastic.co/u/strowi)\
**Replies:** 3\
**Last updated:** [February 25, 2019, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-logging-twice/169718 "2019-02-25T14:44:56Z")

</div>

Hi, i'm currently playing with hint-based autodiscovery in kubernetes. So far my tests with an nginx-deployment seem to work fine, except that the logline appears twice in elasticsearch. One time as "message", the othe…

---

## [Filebeat modules (nginx, logstash, elasticsearch, kibana) don't work with autodiscover](https://discuss.elastic.co/t/filebeat-modules-nginx-logstash-elasticsearch-kibana-dont-work-with-autodiscover/169382)

<div class="topic-metadata">

**Author:** [@Stancho](https://discuss.elastic.co/u/Stancho)\
**Replies:** 5\
**Last updated:** [February 25, 2019, 1:24pm UTC](https://discuss.elastic.co/t/filebeat-modules-nginx-logstash-elasticsearch-kibana-dont-work-with-autodiscover/169382 "2019-02-25T13:24:07Z")

</div>

Hi guys, I am experiencing some problems configuring autodiscover with filebeat modules. The filebeat modules don't seem to work, the logs are not being parsed at all. On the other hand autodiscover works without any pr…

---

## [I get error type "Could not locate thatindex-pattern-field" then Dashboard not loading](https://discuss.elastic.co/t/i-get-error-type-could-not-locate-thatindex-pattern-field-then-dashboard-not-loading/169143)

<div class="topic-metadata">

**Author:** [@khergner](https://discuss.elastic.co/u/khergner)\
**Replies:** 2\
**Last updated:** [February 25, 2019, 6:56am UTC](https://discuss.elastic.co/t/i-get-error-type-could-not-locate-thatindex-pattern-field-then-dashboard-not-loading/169143 "2019-02-25T06:56:33Z")

</div>

Hi everyone I am using new I want to use nginx module to filebeat, I made settings for logstash to nginx modules then filebeat start service. I installed plugin geoip & user-agent for elasticsearch. Nginx modules is ac…

---

## [Producer/broker/16 maximum request accumulated, waiting for space kafka output](https://discuss.elastic.co/t/producer-broker-16-maximum-request-accumulated-waiting-for-space-kafka-output/169145)

<div class="topic-metadata">

**Author:** [@userguy](https://discuss.elastic.co/u/userguy)\
**Replies:** 4\
**Last updated:** [February 25, 2019, 11:21am UTC](https://discuss.elastic.co/t/producer-broker-16-maximum-request-accumulated-waiting-for-space-kafka-output/169145 "2019-02-25T11:21:32Z")

</div>

Hello I am seeing this message in my filebeat Messages , As of now i have set bulk to 3072 and will see if there is any improvement . Additional query i have is how does worker impact in kafka output .By default is one …

---

## [Rationale for indexing url as keyword?](https://discuss.elastic.co/t/rationale-for-indexing-url-as-keyword/169560)

<div class="topic-metadata">

**Author:** [@tback](https://discuss.elastic.co/u/tback)\
**Replies:** 2\
**Last updated:** [February 25, 2019, 8:52am UTC](https://discuss.elastic.co/t/rationale-for-indexing-url-as-keyword/169560 "2019-02-25T08:52:03Z")

</div>

I'm curious about the rationale for indexing urls as keyword by default (in my case it's nginx.access.url, but I noticed it's the same for apache and others) . The documentation states that Keyword fields are searchable…

---

## [Windows Beats - Beta status](https://discuss.elastic.co/t/windows-beats-beta-status/169697)

<div class="topic-metadata">

**Author:** [@nybeat](https://discuss.elastic.co/u/nybeat)\
**Replies:** 4\
**Last updated:** [February 24, 2019, 8:43pm UTC](https://discuss.elastic.co/t/windows-beats-beta-status/169697 "2019-02-24T20:43:53Z")

</div>

Hello, we are working with a large US client with many 1000s of Windows 64-bit OS servers. The client's architecture policies will not let an unsupported (beta) elements of their Elastic Platinum license be deployed i…

---

## [Beats Benchmarking Reports for Linux and/or Windows platforms](https://discuss.elastic.co/t/beats-benchmarking-reports-for-linux-and-or-windows-platforms/169699)

<div class="topic-metadata">

**Author:** [@nybeat](https://discuss.elastic.co/u/nybeat)\
**Replies:** 1\
**Last updated:** [February 24, 2019, 7:41pm UTC](https://discuss.elastic.co/t/beats-benchmarking-reports-for-linux-and-or-windows-platforms/169699 "2019-02-24T19:41:07Z")

</div>

Hello Team, Can someone refer me to any convincing empirical benchmarking reports/papers on Beats system utilization levels for Linux and/or Windows OS platforms ? ( Winlogbeat, Metricbeat, Filebeat ) We are forming a…

---

## [MySQL Logs not sent to MetricBeat](https://discuss.elastic.co/t/mysql-logs-not-sent-to-metricbeat/168753)

<div class="topic-metadata">

**Author:** [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Replies:** 3\
**Last updated:** [February 23, 2019, 1:01pm UTC](https://discuss.elastic.co/t/mysql-logs-not-sent-to-metricbeat/168753 "2019-02-23T13:01:07Z")

</div>

i am having an issue similar to this https://discuss.elastic.co/t/no-data-mysql-dashboard-version-mismatch/146480 I have validated my config however no data is being sent to elastic search. Any ideas?

---

## [Filebeat stop to harvest for nginx log \[Solved\]](https://discuss.elastic.co/t/filebeat-stop-to-harvest-for-nginx-log-solved/169489)

<div class="topic-metadata">

**Author:** [@Lucio\_Palmieri](https://discuss.elastic.co/u/Lucio_Palmieri)\
**Replies:** 1\
**Last updated:** [February 22, 2019, 9:22pm UTC](https://discuss.elastic.co/t/filebeat-stop-to-harvest-for-nginx-log-solved/169489 "2019-02-22T21:22:44Z")

</div>

Hi everyone, I'm trying to use ELK to analyze Nginx access.log, but when I run Filebeat, I get a few hours of logging until Filebeat enters in an infinite loop where it says: "Harvester for file is still running ..." F…

---

## [Filebeat system module events timestamp in kibana](https://discuss.elastic.co/t/filebeat-system-module-events-timestamp-in-kibana/169140)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 3\
**Last updated:** [February 22, 2019, 6:27pm UTC](https://discuss.elastic.co/t/filebeat-system-module-events-timestamp-in-kibana/169140 "2019-02-22T18:27:36Z")

</div>

Dear Members, I had installed filebeat 6.3.2 agent in linux server and enabled the filebeat system module. When i view the events in kibana it's showing +3 hours ahead . my server timzone is GMT +3 . If i change the k…

---

## [Metricbeat is throwing a weird error](https://discuss.elastic.co/t/metricbeat-is-throwing-a-weird-error/169591)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 0\
**Last updated:** [February 22, 2019, 2:09pm UTC](https://discuss.elastic.co/t/metricbeat-is-throwing-a-weird-error/169591 "2019-02-22T14:09:24Z")

</div>

Hello, I have installed the lastest metricbeat on a node version 6.6.1. Configuration has the minimal changes: metricbeat.config.modules: path: ${path.config}/modules.d/\*.yml reload.enabled: false setup.template.se…

---

## [Metricbeatv6.6 new beat: \`make release\` failure on Mac](https://discuss.elastic.co/t/metricbeatv6-6-new-beat-make-release-failure-on-mac/169579)

<div class="topic-metadata">

**Author:** [@ratheesh.nair](https://discuss.elastic.co/u/ratheesh.nair)\
**Replies:** 0\
**Last updated:** [February 22, 2019, 12:39pm UTC](https://discuss.elastic.co/t/metricbeatv6-6-new-beat-make-release-failure-on-mac/169579 "2019-02-22T12:39:40Z")

</div>

Hi, I am developing a new beat and followed docs at https://www.elastic.co/guide/en/beats/devguide/6.6/creating-beat-from-metricbeat.html. $ pwd /Users/bob/workspace/go.ws/src/github.com/elastic/beats $ git branch \* 6.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=378)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=380)
