# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=380

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 381

---

## [How to change IP fields datatype to ip from keyword in packetbeat 6.x](https://discuss.elastic.co/t/how-to-change-ip-fields-datatype-to-ip-from-keyword-in-packetbeat-6-x/169395)

<div class="topic-metadata">

**Author:** [@sohaibomr](https://discuss.elastic.co/u/sohaibomr)\
**Replies:** 3\
**Last updated:** [February 22, 2019, 9:50am UTC](https://discuss.elastic.co/t/how-to-change-ip-fields-datatype-to-ip-from-keyword-in-packetbeat-6-x/169395 "2019-02-22T09:50:35Z")

</div>

Currently in packetbeat 6.x all the ip fields are indexed as datatype keyword in the elasticsearh. How can I change the default type of ip? As suggested in below this issue I have tried to change the datatype using inge…

---

## [Beat's Central Management - Error initializing output: output type undefined](https://discuss.elastic.co/t/beats-central-management-error-initializing-output-output-type-undefined/167495)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 6\
**Last updated:** [February 22, 2019, 5:30am UTC](https://discuss.elastic.co/t/beats-central-management-error-initializing-output-output-type-undefined/167495 "2019-02-22T05:30:26Z")

</div>

Hello World! I'm trying to follow: Beats central management | Metricbeat Reference \[6.6\] | Elastic How central management works | Metricbeat Reference \[6.6\] | Elastic Enroll Beats in central management | Metricbeat R…

---

## [5 of 16 shards failed](https://discuss.elastic.co/t/5-of-16-shards-failed/169294)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 6\
**Last updated:** [February 22, 2019, 5:10am UTC](https://discuss.elastic.co/t/5-of-16-shards-failed/169294 "2019-02-22T05:10:06Z")

</div>

Hello World! I'm using Elastic Stack 6.6.1 and after enrolling beats into Central Management, I now seeing following message in Kibana: 5 of 16 shards failed above message was not prior to enroll, also Infrastructur…

---

## [Failed to encode event: unsupported float value: NaN](https://discuss.elastic.co/t/failed-to-encode-event-unsupported-float-value-nan/168666)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 7\
**Last updated:** [February 21, 2019, 6:59pm UTC](https://discuss.elastic.co/t/failed-to-encode-event-unsupported-float-value-nan/168666 "2019-02-21T18:59:40Z")

</div>

Hello World! I'm using Elastic stack 6.6.0 and I'm seeing following message in: /var/log/metricbeat/metricbeat 2019-02-16T04:20:27.500Z ERROR elasticsearch/client.go:376 Failed to encode event: unsupporte…

---

## [FileBeat debugging and error monitoring](https://discuss.elastic.co/t/filebeat-debugging-and-error-monitoring/169499)

<div class="topic-metadata">

**Author:** [@chitraj8](https://discuss.elastic.co/u/chitraj8)\
**Replies:** 0\
**Last updated:** [February 21, 2019, 10:53pm UTC](https://discuss.elastic.co/t/filebeat-debugging-and-error-monitoring/169499 "2019-02-21T22:53:31Z")

</div>

I am using Filebeat 6.6.1 version and using kafka output with multiple topics. I am beginner to use filebeats trying to read through documentation and do stuff as per the requirement. I do know there is a X-pack monito…

---

## [Certificate signed by unknown authority](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority/169493)

<div class="topic-metadata">

**Author:** [@dilate](https://discuss.elastic.co/u/dilate)\
**Replies:** 0\
**Last updated:** [February 21, 2019, 9:35pm UTC](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority/169493 "2019-02-21T21:35:08Z")

</div>

Hello, sorry for my rough English. I have a problem with filebeat. I have a VPS server with logstash and another server with a file beat agent to perform tests When I look at the filebeat logs I have this error: ERR…

---

## [Metricbeat failed to unmarshal jolokia JSON response](https://discuss.elastic.co/t/metricbeat-failed-to-unmarshal-jolokia-json-response/169433)

<div class="topic-metadata">

**Author:** [@souf\_el\_badraoui](https://discuss.elastic.co/u/souf_el_badraoui)\
**Replies:** 1\
**Last updated:** [February 21, 2019, 9:14pm UTC](https://discuss.elastic.co/t/metricbeat-failed-to-unmarshal-jolokia-json-response/169433 "2019-02-21T21:14:54Z")

</div>

Hello team! I am trying to use the Jolokia module of Metricbeat to collect jmx metrics and get this error: failed to unmarshal jolokia JSON response '{"request":{"type":"version"},"value":{"agent":"1.6.0","protocol":"7…

---

## [Filtering visualitations in dashboard](https://discuss.elastic.co/t/filtering-visualitations-in-dashboard/168895)

<div class="topic-metadata">

**Author:** [@John\_Guzman](https://discuss.elastic.co/u/John_Guzman)\
**Replies:** 2\
**Last updated:** [February 21, 2019, 7:09pm UTC](https://discuss.elastic.co/t/filtering-visualitations-in-dashboard/168895 "2019-02-21T19:09:16Z")

</div>

Hello, I need to filter some visualitations by the nomenclature of the devices on a unique dashboard by sections, for example: at the top show the CPU use average of the devices that contains in the hostname "AAA", "CCC…

---

## [Filebeat input in Logstash is losing fields](https://discuss.elastic.co/t/filebeat-input-in-logstash-is-losing-fields/169460)

<div class="topic-metadata">

**Author:** [@Eni\_Sinanaj](https://discuss.elastic.co/u/Eni_Sinanaj)\
**Replies:** 5\
**Last updated:** [February 21, 2019, 4:57pm UTC](https://discuss.elastic.co/t/filebeat-input-in-logstash-is-losing-fields/169460 "2019-02-21T16:57:43Z")

</div>

I have the following infrastructure: ELK installed as docker containers, each in its own container. And on a virtual machine running CentOS I installed nginx web server and Filebeat to collect the logs. I enabled the n…

---

## [What configs exist for lower latency reads?](https://discuss.elastic.co/t/what-configs-exist-for-lower-latency-reads/168295)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 2\
**Last updated:** [February 21, 2019, 4:09pm UTC](https://discuss.elastic.co/t/what-configs-exist-for-lower-latency-reads/168295 "2019-02-21T16:09:49Z")

</div>

Hi, what are the config settings for filebeat to scan lines as frequently as possible. So I will have two prospectors. 1- One that reads logs regularly, using default settings 2- One that reads "events" (separate file…

---

## [Filebeat registory](https://discuss.elastic.co/t/filebeat-registory/169447)

<div class="topic-metadata">

**Author:** [@Suhas\_K](https://discuss.elastic.co/u/Suhas_K)\
**Replies:** 0\
**Last updated:** [February 21, 2019, 3:27pm UTC](https://discuss.elastic.co/t/filebeat-registory/169447 "2019-02-21T15:27:14Z")

</div>

Hi, I'm using a file beat to read the log file on daily basis, My prospector file looks like this #=========================== Filebeat prospectors ============================= filebeat.prospectors: - type: log #…

---

## [Filebeat High Memory Usage with multiline.negate=true](https://discuss.elastic.co/t/filebeat-high-memory-usage-with-multiline-negate-true/169291)

<div class="topic-metadata">

**Author:** [@derekcal](https://discuss.elastic.co/u/derekcal)\
**Replies:** 1\
**Last updated:** [February 21, 2019, 2:34pm UTC](https://discuss.elastic.co/t/filebeat-high-memory-usage-with-multiline-negate-true/169291 "2019-02-21T14:34:19Z")

</div>

I am running filebeat 6.2.3 and something I noticed is when I have a multiline pattern set and multiline.negate=true, I experience high memory usage. Set multiline.negate=true 2:38 PM 11804 root 20 0 45.2g 4.4g …

---

## [Logs shown in Kibana are behind the current time](https://discuss.elastic.co/t/logs-shown-in-kibana-are-behind-the-current-time/169104)

<div class="topic-metadata">

**Author:** [@aleksei.saiko](https://discuss.elastic.co/u/aleksei.saiko)\
**Replies:** 1\
**Last updated:** [February 21, 2019, 2:31pm UTC](https://discuss.elastic.co/t/logs-shown-in-kibana-are-behind-the-current-time/169104 "2019-02-21T14:31:09Z")

</div>

Hello, I configured Filebeat, Logstash, ES and Kibana, to gather nginx-ingress logs from Kubernetes. Since there's a lot of logs (10 hits in a second), the presented data in Kibana is good, but behind the current time. …

---

## [Auditbeat not capturing Windows failure events](https://discuss.elastic.co/t/auditbeat-not-capturing-windows-failure-events/168963)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 3\
**Last updated:** [February 21, 2019, 1:50pm UTC](https://discuss.elastic.co/t/auditbeat-not-capturing-windows-failure-events/168963 "2019-02-21T13:50:20Z")

</div>

I have created a standard user in Windows and tried to create a file in the C:\\windows\\system32 folder and it failed. My Auditbeat is configured to listen to the above folder. But it does not capture any events during th…

---

## [File Import Timestamps](https://discuss.elastic.co/t/file-import-timestamps/169318)

<div class="topic-metadata">

**Author:** [@Renny](https://discuss.elastic.co/u/Renny)\
**Replies:** 1\
**Last updated:** [February 21, 2019, 1:45pm UTC](https://discuss.elastic.co/t/file-import-timestamps/169318 "2019-02-21T13:45:42Z")

</div>

Hi, Looking for some direction on how to utilize a combination of Filename (2019/02/21 - YYYY/MM/DD) and the first 8 characters of each line in the file (04:16:50 - HH:NN:SS) instead of the generic @timestamp being util…

---

## [Fetching application logs through filebeat in kubernetes environment](https://discuss.elastic.co/t/fetching-application-logs-through-filebeat-in-kubernetes-environment/169328)

<div class="topic-metadata">

**Author:** [@kpiyush](https://discuss.elastic.co/u/kpiyush)\
**Replies:** 10\
**Last updated:** [February 21, 2019, 11:17am UTC](https://discuss.elastic.co/t/fetching-application-logs-through-filebeat-in-kubernetes-environment/169328 "2019-02-21T11:17:16Z")

</div>

I want to collect logs of a golang application thorugh filebeat and send it to logstash. I have a kubernetes cluster. I have following questions regarding deployments: Can I run both application and filebeat through a…

---

## [Metricbeat for Kubernetes 1.13?](https://discuss.elastic.co/t/metricbeat-for-kubernetes-1-13/168830)

<div class="topic-metadata">

**Author:** [@JDev](https://discuss.elastic.co/u/JDev)\
**Replies:** 2\
**Last updated:** [February 21, 2019, 6:39am UTC](https://discuss.elastic.co/t/metricbeat-for-kubernetes-1-13/168830 "2019-02-21T06:39:14Z")

</div>

Hello, I wanted to see the look metrics of kubernetes cluster. Launched, but metrics did not appear. I googled and found that at the new kubernetes versions "localhost:10255" is not working. I looked in the documentat…

---

## [Error creating runner from config: 1 error: no metricsets configured for module 'jolokia'](https://discuss.elastic.co/t/error-creating-runner-from-config-1-error-no-metricsets-configured-for-module-jolokia/168434)

<div class="topic-metadata">

**Author:** [@josemtobar](https://discuss.elastic.co/u/josemtobar)\
**Replies:** 8\
**Last updated:** [February 21, 2019, 4:43am UTC](https://discuss.elastic.co/t/error-creating-runner-from-config-1-error-no-metricsets-configured-for-module-jolokia/168434 "2019-02-21T04:43:59Z")

</div>

Unable to send Jolokia metrics, I get this error in my /var/log/metricbeat/metricbeat error log 2019-02-14T14:52:26.415Z ERROR \[reload\] cfgfile/list.go:104 Error creating runner from config: 1 error: no metricsets confi…

---

## [Docker module seems stopped working](https://discuss.elastic.co/t/docker-module-seems-stopped-working/168969)

<div class="topic-metadata">

**Author:** [@fr0der1c](https://discuss.elastic.co/u/fr0der1c)\
**Replies:** 4\
**Last updated:** [February 21, 2019, 4:04am UTC](https://discuss.elastic.co/t/docker-module-seems-stopped-working/168969 "2019-02-21T04:04:44Z")

</div>

The normal size of a day's Metricbeat data is about 1.8GB. However, yesterday's docs count dropped in half. Also, the Docker panel in Kibana Infra says " There is no data to display." after 3 PM yesterday. So I guess th…

---

## [Failed to connect logstash](https://discuss.elastic.co/t/failed-to-connect-logstash/169135)

<div class="topic-metadata">

**Author:** [@Ani](https://discuss.elastic.co/u/Ani)\
**Replies:** 1\
**Last updated:** [February 20, 2019, 4:08pm UTC](https://discuss.elastic.co/t/failed-to-connect-logstash/169135 "2019-02-20T16:08:56Z")

</div>

Hi , Filebeat is not able to send data to logstash server , I am getting below error from filebeat.log file Failed to connect: Get http://.20..70:5044: read tcp 20..62:35480-\> .20..70:5044: read: connection reset by pe…

---

## [Panic: fatal error: concurrent map iteration and map write](https://discuss.elastic.co/t/panic-fatal-error-concurrent-map-iteration-and-map-write/168435)

<div class="topic-metadata">

**Author:** [@mkorolyov](https://discuss.elastic.co/u/mkorolyov)\
**Replies:** 7\
**Last updated:** [February 20, 2019, 3:37pm UTC](https://discuss.elastic.co/t/panic-fatal-error-concurrent-map-iteration-and-map-write/168435 "2019-02-20T15:37:23Z")

</div>

Hi, We have separate filebeat per running container setup at the moment. Filebeat writing direct to elastic search. After upgrading from 5.6.14 to 6.4.2 filebeat version it started to crash after some time of up and r…

---

## [Merge lines](https://discuss.elastic.co/t/merge-lines/168890)

<div class="topic-metadata">

**Author:** [@Adrian\_Martinez\_Doca](https://discuss.elastic.co/u/Adrian_Martinez_Doca)\
**Replies:** 5\
**Last updated:** [February 20, 2019, 3:18pm UTC](https://discuss.elastic.co/t/merge-lines/168890 "2019-02-20T15:18:47Z")

</div>

Hi, i am new in elastic and i am working to send logs from filebeat to logstash, but i have a issue and i not found solution. the log have multiple related lines ID, information and status, i would like join them in sing…

---

## [Getting logs from application and service log on the event viewer](https://discuss.elastic.co/t/getting-logs-from-application-and-service-log-on-the-event-viewer/169226)

<div class="topic-metadata">

**Author:** [@yaharin\_ben\_ayon](https://discuss.elastic.co/u/yaharin_ben_ayon)\
**Replies:** 2\
**Last updated:** [February 20, 2019, 3:12pm UTC](https://discuss.elastic.co/t/getting-logs-from-application-and-service-log-on-the-event-viewer/169226 "2019-02-20T15:12:19Z")

</div>

Hey guys, can i get logs from the folder "application and service log" on the event viewer and to transfer them with winlogbeat? i can see it only gets logs from the folder windows logs.

---

## [Unstable Events Rate/Throughput](https://discuss.elastic.co/t/unstable-events-rate-throughput/169003)

<div class="topic-metadata">

**Author:** [@Daniel\_Dalacort](https://discuss.elastic.co/u/Daniel_Dalacort)\
**Replies:** 2\
**Last updated:** [February 20, 2019, 1:11pm UTC](https://discuss.elastic.co/t/unstable-events-rate-throughput/169003 "2019-02-20T13:11:52Z")

</div>

Hello! I saw how filebeat metrics and noticed that event rate and throughput looks like jigsaw. but it's not because there is nothing to send. Our logfiles grows faster than filebeat sends events to elasticsearch. I …

---

## [Open TCP connection count](https://discuss.elastic.co/t/open-tcp-connection-count/164482)

<div class="topic-metadata">

**Author:** [@rani](https://discuss.elastic.co/u/rani)\
**Replies:** 11\
**Last updated:** [February 20, 2019, 9:23am UTC](https://discuss.elastic.co/t/open-tcp-connection-count/164482 "2019-02-20T09:23:12Z")

</div>

Hello there. I have a use case where we do have different applications running in separate containers. We want to monitor the user activity by keeping track of the open TCP connections on each application. I am using t…

---

## [Prometheus Decimal Quantiles](https://discuss.elastic.co/t/prometheus-decimal-quantiles/167034)

<div class="topic-metadata">

**Author:** [@smonasco](https://discuss.elastic.co/u/smonasco)\
**Replies:** 1\
**Last updated:** [February 20, 2019, 9:17am UTC](https://discuss.elastic.co/t/prometheus-decimal-quantiles/167034 "2019-02-20T09:17:20Z")

</div>

In Prometheus, it is valid to discuss quantiles like the 99.9th and 99th quantile, but the prometheus module of metricbeat attempts to create fields like: "quantiles": { "99": { ...} , "99.9": {...} } "99" and "99.9…

---

## [Network Traffic per interface](https://discuss.elastic.co/t/network-traffic-per-interface/168994)

<div class="topic-metadata">

**Author:** [@stevizik](https://discuss.elastic.co/u/stevizik)\
**Replies:** 1\
**Last updated:** [February 20, 2019, 6:05am UTC](https://discuss.elastic.co/t/network-traffic-per-interface/168994 "2019-02-20T06:05:18Z")

</div>

Hi all, i want to take metrics using Metricbeat from my hosts specifically per network interface. I know that System Module delivers network traffic as a sum. That's ok but in some interfaces i want to monitor the traf…

---

## [Kibana Host Overview dashboard not showing all Metricbeats clients](https://discuss.elastic.co/t/kibana-host-overview-dashboard-not-showing-all-metricbeats-clients/167928)

<div class="topic-metadata">

**Author:** [@snovak](https://discuss.elastic.co/u/snovak)\
**Replies:** 2\
**Last updated:** [February 19, 2019, 7:30pm UTC](https://discuss.elastic.co/t/kibana-host-overview-dashboard-not-showing-all-metricbeats-clients/167928 "2019-02-19T19:30:25Z")

</div>

Previously we had a pinned search filter for host.name that would allow our users to pull down and select a host from a list. Now that list is only showing MetricBeat hosts which have the latest 6.0 version of the agent…

---

## [Failed to upload elasticsearch logs to elasticsearch/kibana with filebeat module](https://discuss.elastic.co/t/failed-to-upload-elasticsearch-logs-to-elasticsearch-kibana-with-filebeat-module/168782)

<div class="topic-metadata">

**Author:** [@Arcefi](https://discuss.elastic.co/u/Arcefi)\
**Replies:** 2\
**Last updated:** [February 18, 2019, 12:20pm UTC](https://discuss.elastic.co/t/failed-to-upload-elasticsearch-logs-to-elasticsearch-kibana-with-filebeat-module/168782 "2019-02-18T12:20:37Z")

</div>

Hello, I´m new to elasticsearch and today I tried to send some elasticsearch server logs up to my elastic-stack with filebeat, using filebeat modules. Unfortunately, it didn´t work... I don´t know how I can fix this o…

---

## [Error 1067: The process terminated unexpectedly while starting metricbeat service on Windows server 2016 and 2019](https://discuss.elastic.co/t/error-1067-the-process-terminated-unexpectedly-while-starting-metricbeat-service-on-windows-server-2016-and-2019/168810)

<div class="topic-metadata">

**Author:** [@ShilpaT](https://discuss.elastic.co/u/ShilpaT)\
**Replies:** 1\
**Last updated:** [February 19, 2019, 2:37am UTC](https://discuss.elastic.co/t/error-1067-the-process-terminated-unexpectedly-while-starting-metricbeat-service-on-windows-server-2016-and-2019/168810 "2019-02-19T02:37:29Z")

</div>

Everytime I am trying to start metricbeat service, the error 'Error 1067: The process terminated unexpectedly' is shown. I have tried this on Windows server 2012, 2016 and 2019. Same result on every OS. What could be the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=379)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=381)
