# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=381

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 382

---

## [NVIDIA GPU beat](https://discuss.elastic.co/t/nvidia-gpu-beat/168902)

<div class="topic-metadata">

**Author:** [@gsuboc](https://discuss.elastic.co/u/gsuboc)\
**Replies:** 1\
**Last updated:** [February 18, 2019, 10:55pm UTC](https://discuss.elastic.co/t/nvidia-gpu-beat/168902 "2019-02-18T22:55:31Z")

</div>

Hello, Does anyone have any info about getting nvidia gpu beats for windows?

---

## [Filebeat is not indexing all the logs](https://discuss.elastic.co/t/filebeat-is-not-indexing-all-the-logs/167346)

<div class="topic-metadata">

**Author:** [@zaratustra689](https://discuss.elastic.co/u/zaratustra689)\
**Replies:** 5\
**Last updated:** [February 18, 2019, 8:46pm UTC](https://discuss.elastic.co/t/filebeat-is-not-indexing-all-the-logs/167346 "2019-02-18T20:46:34Z")

</div>

Hello, I have Elastic Stack (ElasticSearch + Kibana + Logstash + Filebeat) up and running in production, and every module is running in docker, with the officials images provided by elastic. Filebeat instance is connec…

---

## [Filebeat configuration with output elasticsearch Issue](https://discuss.elastic.co/t/filebeat-configuration-with-output-elasticsearch-issue/168377)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 2\
**Last updated:** [February 18, 2019, 6:57pm UTC](https://discuss.elastic.co/t/filebeat-configuration-with-output-elasticsearch-issue/168377 "2019-02-18T18:57:39Z")

</div>

HI Team, I'm using filebeat version 6.4.0 configuration with output as elasticsearch but I can't find data into the index. Please find the configuration for your kind reference, ###################### Filebeat Configu…

---

## [Filebeat 6.5.4 not able to create kibana dashboard](https://discuss.elastic.co/t/filebeat-6-5-4-not-able-to-create-kibana-dashboard/168719)

<div class="topic-metadata">

**Author:** [@Mahendra\_Shinde](https://discuss.elastic.co/u/Mahendra_Shinde)\
**Replies:** 1\
**Last updated:** [February 18, 2019, 6:55pm UTC](https://discuss.elastic.co/t/filebeat-6-5-4-not-able-to-create-kibana-dashboard/168719 "2019-02-18T18:55:29Z")

</div>

Hi All, We are new to filebeat and setting monitoring cluster for our prod stack. I am trying to setup filebeat and monitoring on kibana. But Filebeat fail to boot with dashboard error 2019-02-17T14:01:31.944+0530 …

---

## [About Filebeat http endpoint](https://discuss.elastic.co/t/about-filebeat-http-endpoint/168506)

<div class="topic-metadata">

**Author:** [@jack\_liang](https://discuss.elastic.co/u/jack_liang)\
**Replies:** 1\
**Last updated:** [February 18, 2019, 6:51pm UTC](https://discuss.elastic.co/t/about-filebeat-http-endpoint/168506 "2019-02-18T18:51:10Z")

</div>

now , i need to know filebeat is working，five minutes apart. i know http endpoint in version 6.6. now, i enable http endpoint in filebeat.reference.yml, but i use http://localhost:5066/stats in chrome, i don't get any…

---

## [Metricbeat System Module shows docker container metrics instead of host](https://discuss.elastic.co/t/metricbeat-system-module-shows-docker-container-metrics-instead-of-host/168062)

<div class="topic-metadata">

**Author:** [@Cyril\_Silver](https://discuss.elastic.co/u/Cyril_Silver)\
**Replies:** 2\
**Last updated:** [February 18, 2019, 8:06am UTC](https://discuss.elastic.co/t/metricbeat-system-module-shows-docker-container-metrics-instead-of-host/168062 "2019-02-18T08:06:00Z")

</div>

I run Metricbeat in container and it seems Metricbeat collects system metrics from its container and not the host machine. On imported Kibana system dashboards there is only one host with the name equal to the container …

---

## [Kubernetes module not getting resource limits](https://discuss.elastic.co/t/kubernetes-module-not-getting-resource-limits/167210)

<div class="topic-metadata">

**Author:** [@fr0der1c](https://discuss.elastic.co/u/fr0der1c)\
**Replies:** 7\
**Last updated:** [February 16, 2019, 1:25am UTC](https://discuss.elastic.co/t/kubernetes-module-not-getting-resource-limits/167210 "2019-02-16T01:25:25Z")

</div>

I enabled the Kubernetes module (https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-kubernetes.html) and everything works fine. But the kubernetes.pod.memory.usage.limit.pct field is falling back to tota…

---

## [Exporting logs to elasticsearch on kubernetes/aws: functionbeat - Cannot retrieve license](https://discuss.elastic.co/t/exporting-logs-to-elasticsearch-on-kubernetes-aws-functionbeat-cannot-retrieve-license/166039)

<div class="topic-metadata">

**Author:** [@GAHila](https://discuss.elastic.co/u/GAHila)\
**Replies:** 4\
**Last updated:** [February 15, 2019, 8:48pm UTC](https://discuss.elastic.co/t/exporting-logs-to-elasticsearch-on-kubernetes-aws-functionbeat-cannot-retrieve-license/166039 "2019-02-15T20:48:39Z")

</div>

I have kubernetes running on AWS (EKS) (v.6.3.2 from containers in GCP) and dedicated nodes that run Elasticsearch. So we want to export Cloudwatch logs there given we have kibana and everything else goes there. Instal…

---

## [Filebeat, floating point json and scientific notation](https://discuss.elastic.co/t/filebeat-floating-point-json-and-scientific-notation/168646)

<div class="topic-metadata">

**Author:** [@zestep](https://discuss.elastic.co/u/zestep)\
**Replies:** 0\
**Last updated:** [February 15, 2019, 8:36pm UTC](https://discuss.elastic.co/t/filebeat-floating-point-json-and-scientific-notation/168646 "2019-02-15T20:36:29Z")

</div>

Hi all, I'm trying to use filebeat to ingest some json data that contains a variety of timestamps in epoch time represented as large floating point numbers. Filebeat seems to turn these into the equivalent scientific no…

---

## [Stable Version for ELK](https://discuss.elastic.co/t/stable-version-for-elk/168573)

<div class="topic-metadata">

**Author:** [@Aung](https://discuss.elastic.co/u/Aung)\
**Replies:** 2\
**Last updated:** [February 15, 2019, 8:30pm UTC](https://discuss.elastic.co/t/stable-version-for-elk/168573 "2019-02-15T20:30:43Z")

</div>

I would like to know which version is stable for ELK and Filebeat for productions. Please Let me know. As I am newbie , I tested the ELK with filebeat but I faced a lot of issues. Thanks!

---

## [About Machine\_Learning In Kibana](https://discuss.elastic.co/t/about-machine-learning-in-kibana/168491)

<div class="topic-metadata">

**Author:** [@J.Teekaram\_prasath](https://discuss.elastic.co/u/J.Teekaram_prasath)\
**Replies:** 4\
**Last updated:** [February 15, 2019, 5:10pm UTC](https://discuss.elastic.co/t/about-machine-learning-in-kibana/168491 "2019-02-15T17:10:58Z")

</div>

Hi, I need a help. I am new to Machine Learning. My CPU usage in data forecasting showing date and time in X-axis and number of core( system.cpu.total.pct)in Y-axis . Can i able to get Y-axis in percentage? Whether 1 w…

---

## [Winlogbeat Restart Services](https://discuss.elastic.co/t/winlogbeat-restart-services/168188)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 2\
**Last updated:** [February 15, 2019, 3:44pm UTC](https://discuss.elastic.co/t/winlogbeat-restart-services/168188 "2019-02-15T15:44:31Z")

</div>

Quick question. The ignore: 72h function in the Winlogbeat sends logs from 3 days ago. If I were to start winlogbeat and send a days worth of logs + the 3 days before and then restart winlogbeat. Would it send the 3 pr…

---

## [Error parsing CRI timestamp](https://discuss.elastic.co/t/error-parsing-cri-timestamp/168425)

<div class="topic-metadata">

**Author:** [@Robin\_GILH](https://discuss.elastic.co/u/Robin_GILH)\
**Replies:** 1\
**Last updated:** [February 15, 2019, 11:10am UTC](https://discuss.elastic.co/t/error-parsing-cri-timestamp/168425 "2019-02-15T11:10:34Z")

</div>

Hello, I'm using Filebeat 6.6.0 to monitor an Nginx ingress controller on Kubernetes. It seems that no matter how I format the logs, Filebeat choke after some minutes/hours on a log line and produce this parsing error : …

---

## [How to send filebeat's logs in Elastic search](https://discuss.elastic.co/t/how-to-send-filebeats-logs-in-elastic-search/168537)

<div class="topic-metadata">

**Author:** [@skvithalani](https://discuss.elastic.co/u/skvithalani)\
**Replies:** 0\
**Last updated:** [February 15, 2019, 7:43am UTC](https://discuss.elastic.co/t/how-to-send-filebeats-logs-in-elastic-search/168537 "2019-02-15T07:43:54Z")

</div>

I am trying to send logs generated by filebeat to Elastic search so that any error occurring in filebeat can be seen at central place. Please guide me if this is recommended or how should I do it. Because filebeat watch…

---

## [Error while enrolling: fail to execute the HTTP POST request: Post https://A.B.C:443/api/beats/agent/XXX-XXX-XXX-XXX-XXX: x509: certificate signed by unknown authority](https://discuss.elastic.co/t/error-while-enrolling-fail-to-execute-the-http-post-request-post-https-a-b-c-443-api-beats-agent-xxx-xxx-xxx-xxx-xxx-x509-certificate-signed-by-unknown-authority/167377)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 5\
**Last updated:** [February 15, 2019, 9:36am UTC](https://discuss.elastic.co/t/error-while-enrolling-fail-to-execute-the-http-post-request-post-https-a-b-c-443-api-beats-agent-xxx-xxx-xxx-xxx-xxx-x509-certificate-signed-by-unknown-authority/167377 "2019-02-15T09:36:22Z")

</div>

Hello World! @pierhugues am still trying to get an answer to following: Is there a work around or ... Please advise.

---

## [Bash: mage: command not found](https://discuss.elastic.co/t/bash-mage-command-not-found/168510)

<div class="topic-metadata">

**Author:** [@liquidslr](https://discuss.elastic.co/u/liquidslr)\
**Replies:** 2\
**Last updated:** [February 15, 2019, 5:44am UTC](https://discuss.elastic.co/t/bash-mage-command-not-found/168510 "2019-02-15T05:44:54Z")

</div>

Getting the following error when trying to make packetbeat Installing mage v1.8.0 from vendor dir. bash: mage: command not found make: \[mage\] Error 127 (ignored) Machine: macOs 10.14.3

---

## [Disk IO not configured properly](https://discuss.elastic.co/t/disk-io-not-configured-properly/168357)

<div class="topic-metadata">

**Author:** [@iamashutosh](https://discuss.elastic.co/u/iamashutosh)\
**Replies:** 3\
**Last updated:** [February 15, 2019, 3:59am UTC](https://discuss.elastic.co/t/disk-io-not-configured-properly/168357 "2019-02-15T03:59:33Z")

</div>

Hello Team, I'm trying to add disk IO to metricbeat in system.yml. I'm using AWS EC2. The only option that is causing the problem is DiskIO, when I comment it, metricbeat starts. Here is my config: - module: system …

---

## [Constant high cpu usage from Filebeat](https://discuss.elastic.co/t/constant-high-cpu-usage-from-filebeat/168028)

<div class="topic-metadata">

**Author:** [@bugggbear](https://discuss.elastic.co/u/bugggbear)\
**Replies:** 7\
**Last updated:** [February 14, 2019, 9:39pm UTC](https://discuss.elastic.co/t/constant-high-cpu-usage-from-filebeat/168028 "2019-02-14T21:39:58Z")

</div>

Hello, I'm using filebeat (6.4.3) to ship Apache logs (and some system ones) directly to ES. Currently Filebeat is configured by using apache2 module and wildcard path setting, pointing to a directory with near 16 000 …

---

## [Importing logs using metricbeat](https://discuss.elastic.co/t/importing-logs-using-metricbeat/167793)

<div class="topic-metadata">

**Author:** [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Replies:** 5\
**Last updated:** [February 14, 2019, 4:07pm UTC](https://discuss.elastic.co/t/importing-logs-using-metricbeat/167793 "2019-02-14T16:07:18Z")

</div>

Hi i am new to elk....can someone help me what if I disable the logstash output and enable elasticsearch output in metricbeat.yml while importing data from different servers using metricbeat?

---

## [How to change the default type of MetricBeat index when ingest data to ES](https://discuss.elastic.co/t/how-to-change-the-default-type-of-metricbeat-index-when-ingest-data-to-es/168137)

<div class="topic-metadata">

**Author:** [@jiangziang](https://discuss.elastic.co/u/jiangziang)\
**Replies:** 1\
**Last updated:** [February 14, 2019, 4:00pm UTC](https://discuss.elastic.co/t/how-to-change-the-default-type-of-metricbeat-index-when-ingest-data-to-es/168137 "2019-02-14T16:00:44Z")

</div>

Hello, everyone. I added 2 custom fields in "metricbeat.yml" like following: fields: {xaxis: 1, yaxis: 1} After data store in ES, those 2 fields are defined as "String" type in the mapping definition: { "fields": { …

---

## [How to monitor replica logs](https://discuss.elastic.co/t/how-to-monitor-replica-logs/168443)

<div class="topic-metadata">

**Author:** [@samwzm](https://discuss.elastic.co/u/samwzm)\
**Replies:** 0\
**Last updated:** [February 14, 2019, 3:48pm UTC](https://discuss.elastic.co/t/how-to-monitor-replica-logs/168443 "2019-02-14T15:48:28Z")

</div>

Hi, there, For many servers (especially for big company's servers), they are composed by multiple servers as a cluster. So, the logs are also replica on all the servers. In this case, if we install filebeat/beats on eac…

---

## [Filebeat not parsing nginx when output is not to elastic](https://discuss.elastic.co/t/filebeat-not-parsing-nginx-when-output-is-not-to-elastic/168439)

<div class="topic-metadata">

**Author:** [@Barak\_Liato](https://discuss.elastic.co/u/Barak_Liato)\
**Replies:** 0\
**Last updated:** [February 14, 2019, 3:10pm UTC](https://discuss.elastic.co/t/filebeat-not-parsing-nginx-when-output-is-not-to-elastic/168439 "2019-02-14T15:10:47Z")

</div>

I am using filebeat in kubernetes to send logs to logstash. logstash pass the logs to elastic. When I output the logs from filebeat to elastic the nginx fields are being parsed. Example of a document when the filebeat …

---

## [WinLogBeats.exe version](https://discuss.elastic.co/t/winlogbeats-exe-version/163254)

<div class="topic-metadata">

**Author:** [@brodiemac](https://discuss.elastic.co/u/brodiemac)\
**Replies:** 5\
**Last updated:** [February 14, 2019, 2:30pm UTC](https://discuss.elastic.co/t/winlogbeats-exe-version/163254 "2019-02-14T14:30:47Z")

</div>

I'm tasked with deploying this in our organization and keeping it up to date. I'm having a difficult with the latter part of this as the winlogbeat.exe application doesn't have a version in its properties. How is anyon…

---

## [Filebeat High Memory and CPU usage](https://discuss.elastic.co/t/filebeat-high-memory-and-cpu-usage/167624)

<div class="topic-metadata">

**Author:** [@Raul](https://discuss.elastic.co/u/Raul)\
**Replies:** 1\
**Last updated:** [February 14, 2019, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-high-memory-and-cpu-usage/167624 "2019-02-14T12:46:07Z")

</div>

Hello, I have an issue with memory and CPU consumption when starting filebeat. I have a log folder with over 100 files of around 100Mb each. I am not interest in all the files, as not all of them are current, so I have s…

---

## [How to set up a watcher for the status of beats](https://discuss.elastic.co/t/how-to-set-up-a-watcher-for-the-status-of-beats/168260)

<div class="topic-metadata">

**Author:** [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Replies:** 2\
**Last updated:** [February 14, 2019, 11:56am UTC](https://discuss.elastic.co/t/how-to-set-up-a-watcher-for-the-status-of-beats/168260 "2019-02-14T11:56:50Z")

</div>

Hello We have Filebeat, Metricbeat, Packetbeat, and Auditbeat all enabled across multiple servers. I am stumped as to how to set up a watcher that alerts me if a beat in a specific server goes down. I've looked at Cen…

---

## [Multiline vs aggregate](https://discuss.elastic.co/t/multiline-vs-aggregate/162300)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 12\
**Last updated:** [February 14, 2019, 11:08am UTC](https://discuss.elastic.co/t/multiline-vs-aggregate/162300 "2019-02-14T11:08:17Z")

</div>

I have log file with this structure: ID,Tag,Value 10179265,37,21 10179265,2001001,15020737 10179265,2003001,0 10179265,2005000,ARM\_OPERATOR 10179265,2005002,Int\_OPERATOR 10160893,37,21 10160893,2001001,15054905 …

---

## [Module nginx save documents twice with kubernetes autodiscover](https://discuss.elastic.co/t/module-nginx-save-documents-twice-with-kubernetes-autodiscover/163483)

<div class="topic-metadata">

**Author:** [@orgoz](https://discuss.elastic.co/u/orgoz)\
**Replies:** 4\
**Last updated:** [February 14, 2019, 8:58am UTC](https://discuss.elastic.co/t/module-nginx-save-documents-twice-with-kubernetes-autodiscover/163483 "2019-02-14T08:58:44Z")

</div>

Hi, I am trying to use Kubernetes Autodiscover with filebeat 6.4.0. It is working except my nginx log are stored twice : one in original format, and one after parsing. For example, for this log line : 10.142.0.4 - \[10…

---

## [Create alerts in packetbeat monitoring](https://discuss.elastic.co/t/create-alerts-in-packetbeat-monitoring/167970)

<div class="topic-metadata">

**Author:** [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Replies:** 6\
**Last updated:** [February 14, 2019, 5:59am UTC](https://discuss.elastic.co/t/create-alerts-in-packetbeat-monitoring/167970 "2019-02-14T05:59:44Z")

</div>

I am monitoring packetbeat using xpack. Monitoring beats,if my packetbeat goe's down i should get notified through mail,how could i create watcher alert in this scenario. Thanks Ramya

---

## [Ingest a text file as a single log with the help of filebeat](https://discuss.elastic.co/t/ingest-a-text-file-as-a-single-log-with-the-help-of-filebeat/167790)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 2\
**Last updated:** [February 14, 2019, 5:32am UTC](https://discuss.elastic.co/t/ingest-a-text-file-as-a-single-log-with-the-help-of-filebeat/167790 "2019-02-14T05:32:42Z")

</div>

I want to ingest a text file as a single log in elasticsearch any input would be really appreciated Best Regards Shrikant

---

## [Winlogbeat wont start as a Service](https://discuss.elastic.co/t/winlogbeat-wont-start-as-a-service/168265)

<div class="topic-metadata">

**Author:** [@dfoley84](https://discuss.elastic.co/u/dfoley84)\
**Replies:** 3\
**Last updated:** [February 13, 2019, 10:22pm UTC](https://discuss.elastic.co/t/winlogbeat-wont-start-as-a-service/168265 "2019-02-13T22:22:54Z")

</div>

Hi, I am after install Elastic search and Kibana for the main task of holding WEF logs from our Servers: while trying to start winlog "service-start winlogbeat" I am getting the following Error: However I am able to…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=380)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=382)
