# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=382

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 383

---

## [I'm getting this error while running logstash to inserts logs from api server](https://discuss.elastic.co/t/im-getting-this-error-while-running-logstash-to-inserts-logs-from-api-server/168049)

<div class="topic-metadata">

**Author:** [@kartheek91](https://discuss.elastic.co/u/kartheek91)\
**Replies:** 1\
**Last updated:** [February 13, 2019, 5:39pm UTC](https://discuss.elastic.co/t/im-getting-this-error-while-running-logstash-to-inserts-logs-from-api-server/168049 "2019-02-13T17:39:59Z")

</div>

---

## [Journalbeat loses TCP connection to elasticsearch and stops shipping logs](https://discuss.elastic.co/t/journalbeat-loses-tcp-connection-to-elasticsearch-and-stops-shipping-logs/168003)

<div class="topic-metadata">

**Author:** [@Philip\_Potter](https://discuss.elastic.co/u/Philip_Potter)\
**Replies:** 1\
**Last updated:** [February 13, 2019, 3:32pm UTC](https://discuss.elastic.co/t/journalbeat-loses-tcp-connection-to-elasticsearch-and-stops-shipping-logs/168003 "2019-02-13T15:32:28Z")

</div>

I am using journalbeat to ship journal events to a remote elasticsearch (ie over the public internet). We have observed that journalbeat frequently stops shipping logs, but continues running in this broken state. There…

---

## [Enrich (or manipulate) filebeat data](https://discuss.elastic.co/t/enrich-or-manipulate-filebeat-data/168250)

<div class="topic-metadata">

**Author:** [@ooii](https://discuss.elastic.co/u/ooii)\
**Replies:** 0\
**Last updated:** [February 13, 2019, 3:18pm UTC](https://discuss.elastic.co/t/enrich-or-manipulate-filebeat-data/168250 "2019-02-13T15:18:23Z")

</div>

I'm new to the ELK stack and I'm trying to have my Nginx stats in Kibana. For that purpose, I use Filebeat and its Nginx module to send data directly to Elasticseach. I then use Kibana to visualise them. However, I'd lik…

---

## [Multiline pattern with backtick in content](https://discuss.elastic.co/t/multiline-pattern-with-backtick-in-content/168226)

<div class="topic-metadata">

**Author:** [@orgoz](https://discuss.elastic.co/u/orgoz)\
**Replies:** 0\
**Last updated:** [February 13, 2019, 1:07pm UTC](https://discuss.elastic.co/t/multiline-pattern-with-backtick-in-content/168226 "2019-02-13T13:07:54Z")

</div>

Hello, I am trying to use kubernetes autodiscover with multiline pattern matching. It seems working for some java stacktrace but not for all. I found some logs having issue with multiline matching have backtick in the c…

---

## [Filebeat using go lang](https://discuss.elastic.co/t/filebeat-using-go-lang/168153)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 4\
**Last updated:** [February 13, 2019, 7:32am UTC](https://discuss.elastic.co/t/filebeat-using-go-lang/168153 "2019-02-13T07:32:36Z")

</div>

HI Team, I want to know some information about filebeat using golang. Currently, I'm using golang api in that i can use elasticsearch to index my data. Is it possible to use filebeat with that to send data from filebeat…

---

## [How can filebeat confirm the logs sequence that log do not have timestamp?](https://discuss.elastic.co/t/how-can-filebeat-confirm-the-logs-sequence-that-log-do-not-have-timestamp/168139)

<div class="topic-metadata">

**Author:** [@xingnailu](https://discuss.elastic.co/u/xingnailu)\
**Replies:** 0\
**Last updated:** [February 13, 2019, 3:33am UTC](https://discuss.elastic.co/t/how-can-filebeat-confirm-the-logs-sequence-that-log-do-not-have-timestamp/168139 "2019-02-13T03:33:44Z")

</div>

hi~ I am going to collect the logs style like (don't have timestamp): is there some method that can confirm the log is ordered on es ? I know the filebeat config : but the fields can't @timespate. so anybody can …

---

## [Filebeat with CLOGs on FreeBSD / PFsense](https://discuss.elastic.co/t/filebeat-with-clogs-on-freebsd-pfsense/167870)

<div class="topic-metadata">

**Author:** [@sdvincent](https://discuss.elastic.co/u/sdvincent)\
**Replies:** 3\
**Last updated:** [February 13, 2019, 1:32am UTC](https://discuss.elastic.co/t/filebeat-with-clogs-on-freebsd-pfsense/167870 "2019-02-13T01:32:42Z")

</div>

Continuing the discussion from Filebeat on FreeBSD / PFsense: Has there been any solution to dealing with the CLOG format? I'm running PFSENSE 2.4.4 which sits on FreeBSD 11.2 and I'm running into the same issue where l…

---

## [Bug: Ec2 process access error - causing silent failure](https://discuss.elastic.co/t/bug-ec2-process-access-error-causing-silent-failure/168128)

<div class="topic-metadata">

**Author:** [@ensemblebd](https://discuss.elastic.co/u/ensemblebd)\
**Replies:** 0\
**Last updated:** [February 12, 2019, 11:57pm UTC](https://discuss.elastic.co/t/bug-ec2-process-access-error-causing-silent-failure/168128 "2019-02-12T23:57:51Z")

</div>

On windows, the wininit.exe process can't be accessed by the service (some machines .. EC2 specifically with DataCenter edition 2016 server), which can only be detected by turning on debug logging. Logs look totally nor…

---

## [Log file size vs. quantity](https://discuss.elastic.co/t/log-file-size-vs-quantity/168090)

<div class="topic-metadata">

**Author:** [@nskerl](https://discuss.elastic.co/u/nskerl)\
**Replies:** 0\
**Last updated:** [February 12, 2019, 5:32pm UTC](https://discuss.elastic.co/t/log-file-size-vs-quantity/168090 "2019-02-12T17:32:31Z")

</div>

While troubleshooting high cpu usage by Filebeat (80% sustained, even when logs are idle), I noticed it showed a large number of files (current: 8811) in the registrar: "harvester":{"open\_files":4,"running":4}},"libbeat…

---

## [Filebeat is not returning data to logstash?](https://discuss.elastic.co/t/filebeat-is-not-returning-data-to-logstash/167866)

<div class="topic-metadata">

**Author:** [@kartheek91](https://discuss.elastic.co/u/kartheek91)\
**Replies:** 4\
**Last updated:** [February 12, 2019, 2:35pm UTC](https://discuss.elastic.co/t/filebeat-is-not-returning-data-to-logstash/167866 "2019-02-12T14:35:54Z")

</div>

This is the error I'm getting.Actually I'm installed filebeat in windows server and then I have installed logstash in ubuntu and below is the corresponding conf file. input { beats { port =\> "5044" } } o…

---

## [Filebeat not writing docker containers logs into Elasticsearch](https://discuss.elastic.co/t/filebeat-not-writing-docker-containers-logs-into-elasticsearch/165574)

<div class="topic-metadata">

**Author:** [@akapit](https://discuss.elastic.co/u/akapit)\
**Replies:** 7\
**Last updated:** [February 12, 2019, 2:13pm UTC](https://discuss.elastic.co/t/filebeat-not-writing-docker-containers-logs-into-elasticsearch/165574 "2019-02-12T14:13:36Z")

</div>

Hi, I have several docker containers (using docker-compose) and I'm trying to use Filebeat (from docker) to push my containers logs to elasticsearch with no success. This is my filebeat.yml: filebeat.inputs: - type:…

---

## [Metricbeat (6.6.0) Windows Module Breaks in Win7 server](https://discuss.elastic.co/t/metricbeat-6-6-0-windows-module-breaks-in-win7-server/167589)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 3\
**Last updated:** [February 12, 2019, 12:38pm UTC](https://discuss.elastic.co/t/metricbeat-6-6-0-windows-module-breaks-in-win7-server/167589 "2019-02-12T12:38:33Z")

</div>

Hi- I was trying to pull the perfmon data from a Windows-7 Ultimate server, but it fails abruptly. When I enabled the debug mode and test the modules, I see the below log: C:\\Users\\Administrator\\Desktop\\metricbeat-6.6.…

---

## [Windows filebeat to logstash to elasticsearch](https://discuss.elastic.co/t/windows-filebeat-to-logstash-to-elasticsearch/165679)

<div class="topic-metadata">

**Author:** [@richard.poole](https://discuss.elastic.co/u/richard.poole)\
**Replies:** 9\
**Last updated:** [February 12, 2019, 9:04am UTC](https://discuss.elastic.co/t/windows-filebeat-to-logstash-to-elasticsearch/165679 "2019-02-12T09:04:00Z")

</div>

I'm fairly new to ELK, but not completely hopeless, I hope. I am running filebeat on a Windows server to collect tomcat8 access logs (eClinicalWorks on Windows). I got the grok pattern correct as far as any pattern tes…

---

## [How to set custom fileds via CLI when ingesting with filebeat?](https://discuss.elastic.co/t/how-to-set-custom-fileds-via-cli-when-ingesting-with-filebeat/167892)

<div class="topic-metadata">

**Author:** [@holgerbrandl](https://discuss.elastic.co/u/holgerbrandl)\
**Replies:** 2\
**Last updated:** [February 12, 2019, 7:44am UTC](https://discuss.elastic.co/t/how-to-set-custom-fileds-via-cli-when-ingesting-with-filebeat/167892 "2019-02-12T07:44:16Z")

</div>

Hi there, when running filebeat I'd like to set some custom fields and tags via a CLI parameter. zcat mylog.gz | filebeat -e config yml -E "tags=\['huhu'\]" -E "fields.app\_id=\['foo'\]" The corresponing bits in config are …

---

## [Unable to load Kibana Dashboards via MetricBeat](https://discuss.elastic.co/t/unable-to-load-kibana-dashboards-via-metricbeat/166712)

<div class="topic-metadata">

**Author:** [@mark.penner](https://discuss.elastic.co/u/mark.penner)\
**Replies:** 8\
**Last updated:** [February 12, 2019, 12:00am UTC](https://discuss.elastic.co/t/unable-to-load-kibana-dashboards-via-metricbeat/166712 "2019-02-12T00:00:01Z")

</div>

Hi, I am running Metricbeat6.5.4 in a Docker container on DCOS. I have been able to send all "Metrics" logs to Elastic search and then to Kibana (v6) successfully. The issue i am having is when setting the "setup.dashb…

---

## [Filebeat multi-line pattern splitting events](https://discuss.elastic.co/t/filebeat-multi-line-pattern-splitting-events/167791)

<div class="topic-metadata">

**Author:** [@dinesh1](https://discuss.elastic.co/u/dinesh1)\
**Replies:** 1\
**Last updated:** [February 11, 2019, 11:07pm UTC](https://discuss.elastic.co/t/filebeat-multi-line-pattern-splitting-events/167791 "2019-02-11T23:07:37Z")

</div>

Hi Team my logs looks like 2018-01-24 16:00:00,487 INFO (testAdapter.java:156) - IP Address : 192.168.0.7 2018-01-24 16:00:00,487 INFO (testAdapter.java:156) - eureka access successfull 2018-01-24 16:00:00,487 INFO…

---

## [Metricbeats and Kibana](https://discuss.elastic.co/t/metricbeats-and-kibana/167537)

<div class="topic-metadata">

**Author:** [@lgwapnitsky](https://discuss.elastic.co/u/lgwapnitsky)\
**Replies:** 4\
**Last updated:** [February 11, 2019, 8:28pm UTC](https://discuss.elastic.co/t/metricbeats-and-kibana/167537 "2019-02-11T20:28:43Z")

</div>

Working with a fresh installation of Kibana and metricbeats. The latter feeds through logstash. I've gone through setting up the dashboards multiple times, but keep winding up with errors like the following: The reques…

---

## [Adding metricbeat custom fields through a logstash instance not working for me](https://discuss.elastic.co/t/adding-metricbeat-custom-fields-through-a-logstash-instance-not-working-for-me/167723)

<div class="topic-metadata">

**Author:** [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Replies:** 2\
**Last updated:** [February 11, 2019, 8:26pm UTC](https://discuss.elastic.co/t/adding-metricbeat-custom-fields-through-a-logstash-instance-not-working-for-me/167723 "2019-02-11T20:26:53Z")

</div>

The resulting index does work for adding one field but every configuration I tried does not work for more than one field. Below works for one field but not more than one. Not sure what I am missing. Maybe a logstash …

---

## [Using Filebeat's Multiline to combine 2 lines only](https://discuss.elastic.co/t/using-filebeats-multiline-to-combine-2-lines-only/167364)

<div class="topic-metadata">

**Author:** [@cbril](https://discuss.elastic.co/u/cbril)\
**Replies:** 2\
**Last updated:** [February 11, 2019, 5:05pm UTC](https://discuss.elastic.co/t/using-filebeats-multiline-to-combine-2-lines-only/167364 "2019-02-11T17:05:20Z")

</div>

I have a log with an interesting format where it has a timestamp on one line and then the message on the next line. I am trying to use Filebeat's multiline to combine the line with the timestamp and the following line wi…

---

## [Beats - Central Management (Beta)](https://discuss.elastic.co/t/beats-central-management-beta/167692)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 2\
**Last updated:** [February 11, 2019, 4:58pm UTC](https://discuss.elastic.co/t/beats-central-management-beta/167692 "2019-02-11T16:58:53Z")

</div>

Hello World! I'm trying out Kibana -\> Beats -\> Central Management (Beta) and finding a lot of issues with it... This functionality is in beta and is subject to change. The design and code is less mature than official …

---

## [Average size of a windows event log with best compression](https://discuss.elastic.co/t/average-size-of-a-windows-event-log-with-best-compression/167889)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [February 11, 2019, 3:44pm UTC](https://discuss.elastic.co/t/average-size-of-a-windows-event-log-with-best-compression/167889 "2019-02-11T15:44:03Z")

</div>

Hi all, I was just wondering if anyone knows the average size of a windows event log with best compression enabled and / or without best compression enabled. Regards, Jason

---

## [Failing to send beats from Postgres](https://discuss.elastic.co/t/failing-to-send-beats-from-postgres/167556)

<div class="topic-metadata">

**Author:** [@juanmav](https://discuss.elastic.co/u/juanmav)\
**Replies:** 3\
**Last updated:** [February 11, 2019, 2:21pm UTC](https://discuss.elastic.co/t/failing-to-send-beats-from-postgres/167556 "2019-02-11T14:21:16Z")

</div>

I've configured and enabled the postgresql module with the following config: # Module: postgresql # Docs: https://www.elastic.co/guide/en/beats/metricbeat/6.x/metricbeat-module-postgresql.html - module: postgresql me…

---

## [How to move ruby code from logstash.conf into ingest pipeline?](https://discuss.elastic.co/t/how-to-move-ruby-code-from-logstash-conf-into-ingest-pipeline/167690)

<div class="topic-metadata">

**Author:** [@apaulsen](https://discuss.elastic.co/u/apaulsen)\
**Replies:** 3\
**Last updated:** [February 11, 2019, 11:56am UTC](https://discuss.elastic.co/t/how-to-move-ruby-code-from-logstash-conf-into-ingest-pipeline/167690 "2019-02-11T11:56:51Z")

</div>

I've a logstash configuration file which contains ruby code. How can I script the ruby part of the logstash filter in ingest pipeline? It's a server with filebeat. All part except the ruby code I "moved" into the inge…

---

## [Setup time counter in Winlogbeats](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612)

<div class="topic-metadata">

**Author:** [@compsecstudent](https://discuss.elastic.co/u/compsecstudent)\
**Replies:** 4\
**Last updated:** [February 10, 2019, 3:51pm UTC](https://discuss.elastic.co/t/setup-time-counter-in-winlogbeats/167612 "2019-02-10T15:51:53Z")

</div>

Is it possible for Winlogbeat to include a time counter, for example when it starts sending logs the time counter would start at 0 then go by minutes (or hours) when sending logs? Or is there a way to capture Winlogbeat…

---

## [Problem with JSON logs](https://discuss.elastic.co/t/problem-with-json-logs/167687)

<div class="topic-metadata">

**Author:** [@Utundu](https://discuss.elastic.co/u/Utundu)\
**Replies:** 2\
**Last updated:** [February 9, 2019, 5:31pm UTC](https://discuss.elastic.co/t/problem-with-json-logs/167687 "2019-02-09T17:31:29Z")

</div>

Hi, I'm new to the Elastic Stack and I can't manage to build a pipeline for my Java logs. I use the Logstack Logstash appender, Filebeat and Elastic Search for now. Here is my Filebeat configuration. filebeat.inp…

---

## [WinlogBeat DNS analytical log capture](https://discuss.elastic.co/t/winlogbeat-dns-analytical-log-capture/167644)

<div class="topic-metadata">

**Author:** [@Jeremya5](https://discuss.elastic.co/u/Jeremya5)\
**Replies:** 1\
**Last updated:** [February 9, 2019, 2:05am UTC](https://discuss.elastic.co/t/winlogbeat-dns-analytical-log-capture/167644 "2019-02-09T02:05:43Z")

</div>

hi all, So the latest version of WinlogBeat now support all windows event logs. Currently i'm collecting (example below) across the my company. I would also like to collect the DNS analytical log, however i'm not sure h…

---

## [Number of active sessions](https://discuss.elastic.co/t/number-of-active-sessions/167090)

<div class="topic-metadata">

**Author:** [@Costi](https://discuss.elastic.co/u/Costi)\
**Replies:** 5\
**Last updated:** [February 9, 2019, 2:02am UTC](https://discuss.elastic.co/t/number-of-active-sessions/167090 "2019-02-09T02:02:55Z")

</div>

Hi! Does anyone know how can i see the total number of active sessions? I tried to use winlogbeat and search by event\_id but i think my approach isn't the correct one. Thanks!

---

## [\[Unresolved\] Absolutely nothing shows in any \[Filebeat\] Kibana Dashboards ("No results found")](https://discuss.elastic.co/t/unresolved-absolutely-nothing-shows-in-any-filebeat-kibana-dashboards-no-results-found/166839)

<div class="topic-metadata">

**Author:** [@wad11656](https://discuss.elastic.co/u/wad11656)\
**Replies:** 17\
**Last updated:** [February 8, 2019, 10:53pm UTC](https://discuss.elastic.co/t/unresolved-absolutely-nothing-shows-in-any-filebeat-kibana-dashboards-no-results-found/166839 "2019-02-08T22:53:17Z")

</div>

Host: Debian 9 ELK Stack version: 6.6.0 Sending logs through Elasticsearch or Logstash: Elasticsearch (hopefully Logstash later) Summary: I get "No results found :neutral\_face:" on every \[Filebeat\] Dashboard in Kiban…

---

## [Filebeat rabbitmq module](https://discuss.elastic.co/t/filebeat-rabbitmq-module/167688)

<div class="topic-metadata">

**Author:** [@adrian.aneci](https://discuss.elastic.co/u/adrian.aneci)\
**Replies:** 0\
**Last updated:** [February 8, 2019, 9:24pm UTC](https://discuss.elastic.co/t/filebeat-rabbitmq-module/167688 "2019-02-08T21:24:35Z")

</div>

Hello, Are there any plans to add a rabbitmq module for filebeat? Or is there any logstash grok filter available to parse rabbitmq logs? I've searched on elastic forum but only found an old topic(https://discuss.elast…

---

## [Problem connecting filebeat (v. 6.6.0) with ingress pipeline](https://discuss.elastic.co/t/problem-connecting-filebeat-v-6-6-0-with-ingress-pipeline/167521)

<div class="topic-metadata">

**Author:** [@apaulsen](https://discuss.elastic.co/u/apaulsen)\
**Replies:** 1\
**Last updated:** [February 8, 2019, 6:40pm UTC](https://discuss.elastic.co/t/problem-connecting-filebeat-v-6-6-0-with-ingress-pipeline/167521 "2019-02-08T18:40:55Z")

</div>

Problem to connect filebeat version 6.6.0 with ingress pipeline Done: created a (custom) ingress pipeline "my\_pipeline" enrolled a new Beat of typ filebeat in may ECE-Deplyment enrolled filebeat on my server, where th…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=381)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=383)
