# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=383

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 384

---

## [Filebeat - ERROR instance/beat.go:800](https://discuss.elastic.co/t/filebeat-error-instance-beat-go-800/164843)

<div class="topic-metadata">

**Author:** [@DALG](https://discuss.elastic.co/u/DALG)\
**Replies:** 4\
**Last updated:** [February 8, 2019, 4:56pm UTC](https://discuss.elastic.co/t/filebeat-error-instance-beat-go-800/164843 "2019-02-08T16:56:34Z")

</div>

Hello, I'm trying to start filbeat but apparently I have no input no paths defined for input accessing config. this is the file im using: ###################### Filebeat Configuration Example ###############…

---

## [Filebeat + docker input - cannot drop events according to container name?](https://discuss.elastic.co/t/filebeat-docker-input-cannot-drop-events-according-to-container-name/167666)

<div class="topic-metadata">

**Author:** [@Nico\_Kruger](https://discuss.elastic.co/u/Nico_Kruger)\
**Replies:** 0\
**Last updated:** [February 8, 2019, 4:26pm UTC](https://discuss.elastic.co/t/filebeat-docker-input-cannot-drop-events-according-to-container-name/167666 "2019-02-08T16:26:52Z")

</div>

I cannot for the life of me figure out why the following is not working: This is using the elastic Filebeat 6.5.2 docker container: filebeat.inputs: - type: docker containers.ids: '\*' combine\_partial: true proces…

---

## [Do not see postgresql metrics in kibana after configuring and running metricbeat](https://discuss.elastic.co/t/do-not-see-postgresql-metrics-in-kibana-after-configuring-and-running-metricbeat/167174)

<div class="topic-metadata">

**Author:** [@yurim](https://discuss.elastic.co/u/yurim)\
**Replies:** 9\
**Last updated:** [February 8, 2019, 4:20pm UTC](https://discuss.elastic.co/t/do-not-see-postgresql-metrics-in-kibana-after-configuring-and-running-metricbeat/167174 "2019-02-08T16:20:41Z")

</div>

Hi guys, I might be missing something here please set me straight. Using ELK 6.5.4. enabled postgresql module for metricbeat, edited metricbeat.yml and modules.d/postgresql.yml according the manual. ran metricbeat setup …

---

## [\[publish\] pipeline/retry.go:155 Drop batch](https://discuss.elastic.co/t/publish-pipeline-retry-go-155-drop-batch/167646)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [February 8, 2019, 2:27pm UTC](https://discuss.elastic.co/t/publish-pipeline-retry-go-155-drop-batch/167646 "2019-02-08T14:27:55Z")

</div>

Hi, my pipline looks the following: log -\> filebeat -\> redis Filebeat is giving me a lot of following errors: 2019-02-08T14:22:04.554Z INFO \[publish\] pipeline/retry.go:155 Drop batch 2019-02-08T14:2…

---

## [How to customize fields that Filebeat sends to Elasticsearch?](https://discuss.elastic.co/t/how-to-customize-fields-that-filebeat-sends-to-elasticsearch/167625)

<div class="topic-metadata">

**Author:** [@morenz](https://discuss.elastic.co/u/morenz)\
**Replies:** 0\
**Last updated:** [February 8, 2019, 12:25pm UTC](https://discuss.elastic.co/t/how-to-customize-fields-that-filebeat-sends-to-elasticsearch/167625 "2019-02-08T12:25:50Z")

</div>

Hello folks :slight\_smile: I have an ELK 6.5 server Debian 9 server (Bitnami build for Google Cloud Environment) to which I have to send my PostgreSQL 9.5 server (Debian 9) logs using Filebeat. I chose to send data di…

---

## [Monitoring production cluster using Metricbeat](https://discuss.elastic.co/t/monitoring-production-cluster-using-metricbeat/167455)

<div class="topic-metadata">

**Author:** [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Replies:** 2\
**Last updated:** [February 8, 2019, 11:22am UTC](https://discuss.elastic.co/t/monitoring-production-cluster-using-metricbeat/167455 "2019-02-08T11:22:08Z")

</div>

Unable to create a separate cluster for Monitoring the Elastic stack. I have tried configuring it via both MetricBeat as well as HTTP exporters, but I do not see the monitoring information for my production cluster. All …

---

## [Running Metricbeat in Docker on ECS, want to monitor the other Docker images also running on the same cluster](https://discuss.elastic.co/t/running-metricbeat-in-docker-on-ecs-want-to-monitor-the-other-docker-images-also-running-on-the-same-cluster/167369)

<div class="topic-metadata">

**Author:** [@ppafford](https://discuss.elastic.co/u/ppafford)\
**Replies:** 2\
**Last updated:** [February 8, 2019, 11:08am UTC](https://discuss.elastic.co/t/running-metricbeat-in-docker-on-ecs-want-to-monitor-the-other-docker-images-also-running-on-the-same-cluster/167369 "2019-02-08T11:08:54Z")

</div>

the goal: Try to monitor other docker containers on ECS cluster info: metricbeats is also running in docker on the same ECS cluster metricbeat.config.modules: path: ${path.config}/conf.d/\*.yml reload.period: 10s …

---

## [Send whole log file to logstash](https://discuss.elastic.co/t/send-whole-log-file-to-logstash/167415)

<div class="topic-metadata">

**Author:** [@jonbj](https://discuss.elastic.co/u/jonbj)\
**Replies:** 2\
**Last updated:** [February 8, 2019, 8:48am UTC](https://discuss.elastic.co/t/send-whole-log-file-to-logstash/167415 "2019-02-08T08:48:36Z")

</div>

Hi all, I'm quite new to Filebeat, and i need some help. I'm trying to send log to Logstash from Filebeat, and receive the message by mail. I need to send the entire LOG (custom) file in the message, if it contain the …

---

## [Metricbeat default dashboards: how to load into specific space?](https://discuss.elastic.co/t/metricbeat-default-dashboards-how-to-load-into-specific-space/167491)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [February 7, 2019, 7:49pm UTC](https://discuss.elastic.co/t/metricbeat-default-dashboards-how-to-load-into-specific-space/167491 "2019-02-07T19:49:55Z")

</div>

Hi, I am on elastic stack 6.5.4. In the past I created my own metricbeat visualizations and dashboards, but I would like to give the sample dashboards a try to check if they can replace mine or at least to get more ins…

---

## [Metricset creation is broken on forked beats tree?](https://discuss.elastic.co/t/metricset-creation-is-broken-on-forked-beats-tree/167326)

<div class="topic-metadata">

**Author:** [@Grigory\_Shamov](https://discuss.elastic.co/u/Grigory_Shamov)\
**Replies:** 2\
**Last updated:** [February 7, 2019, 7:23pm UTC](https://discuss.elastic.co/t/metricset-creation-is-broken-on-forked-beats-tree/167326 "2019-02-07T19:23:23Z")

</div>

HI, Is it possible to develop metricset on a forked elastic/beats repository? Right now it seems that the build system is broken. When forking the repo, and then doing make create-metricset, the boilerplate code gets c…

---

## [Add\_kubernetes\_metadata does not append kubernetes metadata](https://discuss.elastic.co/t/add-kubernetes-metadata-does-not-append-kubernetes-metadata/167170)

<div class="topic-metadata">

**Author:** [@drinnird](https://discuss.elastic.co/u/drinnird)\
**Replies:** 1\
**Last updated:** [February 7, 2019, 7:02pm UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-does-not-append-kubernetes-metadata/167170 "2019-02-07T19:02:56Z")

</div>

Hi, We are setting up metricbeat + heartbeat + APM on our kubernetes cluster. I am deploying heartbeat through helm chart here: I am deploying with this command: helm install --name heartbeat -f heartbeatVALUES.ya…

---

## [Add time taken to serve request in Apache2 module](https://discuss.elastic.co/t/add-time-taken-to-serve-request-in-apache2-module/167511)

<div class="topic-metadata">

**Author:** [@wiltonms](https://discuss.elastic.co/u/wiltonms)\
**Replies:** 0\
**Last updated:** [February 7, 2019, 7:01pm UTC](https://discuss.elastic.co/t/add-time-taken-to-serve-request-in-apache2-module/167511 "2019-02-07T19:01:48Z")

</div>

Hi guys, I'm trying to find a way to add a custom log format in the filebeat apache2 module. My apache logs have the time taken to serve the request, which is important for me to know. Def. \> %D The time taken to se…

---

## [Unable to run commands using exec.Command from Beat ( Linux )](https://discuss.elastic.co/t/unable-to-run-commands-using-exec-command-from-beat-linux/167360)

<div class="topic-metadata">

**Author:** [@deepujain](https://discuss.elastic.co/u/deepujain)\
**Replies:** 3\
**Last updated:** [February 7, 2019, 6:29pm UTC](https://discuss.elastic.co/t/unable-to-run-commands-using-exec-command-from-beat-linux/167360 "2019-02-07T18:29:35Z")

</div>

I have a working beat created using Beats framework. However i am not able to execute bash commands from inside using exec.Command(). Build process of this beat is same that is listed on beats framework. \[root@10.142.…

---

## [XML File: multiple lines that not share a root-tag](https://discuss.elastic.co/t/xml-file-multiple-lines-that-not-share-a-root-tag/167465)

<div class="topic-metadata">

**Author:** [@TimTim](https://discuss.elastic.co/u/TimTim)\
**Replies:** 1\
**Last updated:** [February 7, 2019, 4:12pm UTC](https://discuss.elastic.co/t/xml-file-multiple-lines-that-not-share-a-root-tag/167465 "2019-02-07T16:12:20Z")

</div>

My problem is that I am reading log files with XML in it. BUT........ it looks like this: \<exclusive-start id="51" timestamp="2018-09-18T21:28:08.474" intervalms="4907.088"\> \<response-info timems="0.023" idlems="0.023…

---

## [Output to multiple indexes Filebeat 6.5](https://discuss.elastic.co/t/output-to-multiple-indexes-filebeat-6-5/167341)

<div class="topic-metadata">

**Author:** [@Stancho](https://discuss.elastic.co/u/Stancho)\
**Replies:** 2\
**Last updated:** [February 7, 2019, 4:02pm UTC](https://discuss.elastic.co/t/output-to-multiple-indexes-filebeat-6-5/167341 "2019-02-07T16:02:48Z")

</div>

Hi, i am trying to configure filebeat to put data into multiple indexes. That is why I define for every prospector a field "category" (fields.category: myApp) and use this field in the parameters "setup.template.name=fi…

---

## [Filebeat Multiline Docker Log](https://discuss.elastic.co/t/filebeat-multiline-docker-log/167153)

<div class="topic-metadata">

**Author:** [@shauryagarg2006](https://discuss.elastic.co/u/shauryagarg2006)\
**Replies:** 6\
**Last updated:** [February 7, 2019, 3:48pm UTC](https://discuss.elastic.co/t/filebeat-multiline-docker-log/167153 "2019-02-07T15:48:35Z")

</div>

filebeat.inputs: - type: log paths: - "/var/lib/docker/containers/\*/\*.log" json.keys\_under\_root: true json.add\_error\_key: true json.message\_key: log processors: - rename: fields: …

---

## [List of URLS in heartbeat.yml doesn’t show in Heartbeat dashboard](https://discuss.elastic.co/t/list-of-urls-in-heartbeat-yml-doesn-t-show-in-heartbeat-dashboard/167475)

<div class="topic-metadata">

**Author:** [@Iraida07](https://discuss.elastic.co/u/Iraida07)\
**Replies:** 0\
**Last updated:** [February 7, 2019, 3:14pm UTC](https://discuss.elastic.co/t/list-of-urls-in-heartbeat-yml-doesn-t-show-in-heartbeat-dashboard/167475 "2019-02-07T15:14:53Z")

</div>

Hi guys. I recently configure 18 Urls to query in the heartbeat.yml file, heartbeat worked fine but since a few days when I open the heartbeat dashboard, I just have five urls listed. I checked the configuration file (h…

---

## [Suspending heartbeat for servers during maintenance windows](https://discuss.elastic.co/t/suspending-heartbeat-for-servers-during-maintenance-windows/167446)

<div class="topic-metadata">

**Author:** [@johncam](https://discuss.elastic.co/u/johncam)\
**Replies:** 2\
**Last updated:** [February 7, 2019, 2:51pm UTC](https://discuss.elastic.co/t/suspending-heartbeat-for-servers-during-maintenance-windows/167446 "2019-02-07T14:51:52Z")

</div>

I have configured a heartbeat.yml file to poll a number of servers and URLs at 60s intervals, and have further configured an alert that runs at 60s intervals to send out alerts for any server that is offline - all of whi…

---

## [Filebeat 6.6.0 doesn't harvest old logfile (even at first time run)](https://discuss.elastic.co/t/filebeat-6-6-0-doesnt-harvest-old-logfile-even-at-first-time-run/167468)

<div class="topic-metadata">

**Author:** [@animal](https://discuss.elastic.co/u/animal)\
**Replies:** 0\
**Last updated:** [February 7, 2019, 2:37pm UTC](https://discuss.elastic.co/t/filebeat-6-6-0-doesnt-harvest-old-logfile-even-at-first-time-run/167468 "2019-02-07T14:37:32Z")

</div>

Hello. I use filebeat-\>logstash-\>elasticsearch \<- kibana . I am facing an issue with filebeat, it doesn't harvest logfile, even at first run. I tried to stop filebeat, remove registry file and start filebeat again withou…

---

## [Dedot Kubernetes labels and annotations](https://discuss.elastic.co/t/dedot-kubernetes-labels-and-annotations/167457)

<div class="topic-metadata">

**Author:** [@anton-johansson](https://discuss.elastic.co/u/anton-johansson)\
**Replies:** 0\
**Last updated:** [February 7, 2019, 1:18pm UTC](https://discuss.elastic.co/t/dedot-kubernetes-labels-and-annotations/167457 "2019-02-07T13:18:41Z")

</div>

I'm using Filebeat with Kubernetes autodiscovery. I'm using version 6.5.3 for all Elastic components. I've had some struggle with Kubernetes labels and annotations which can contain dots and slashes. I know that this pul…

---

## [Filebeat and updating documents](https://discuss.elastic.co/t/filebeat-and-updating-documents/167355)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 1\
**Last updated:** [February 7, 2019, 1:34pm UTC](https://discuss.elastic.co/t/filebeat-and-updating-documents/167355 "2019-02-07T13:34:11Z")

</div>

I am using Filebeat to bring database information into Elasticsearch. In some instances the existing table data (that has already been imported into Elasticsearch) is updated. How can I use Filebeat to update this data…

---

## [Multiple pipelines for ingest Node](https://discuss.elastic.co/t/multiple-pipelines-for-ingest-node/167427)

<div class="topic-metadata">

**Author:** [@mylyo](https://discuss.elastic.co/u/mylyo)\
**Replies:** 2\
**Last updated:** [February 7, 2019, 1:15pm UTC](https://discuss.elastic.co/t/multiple-pipelines-for-ingest-node/167427 "2019-02-07T13:15:39Z")

</div>

Hello, I created a filebeat where i defined multiple sources for input as this way : filebeat.input: .... paths: -"my\_path\\\*.log In order to obtain the appropriate data, i set a pipeline that concerns one among t…

---

## [Getting issue to read the log generated by Service fabric](https://discuss.elastic.co/t/getting-issue-to-read-the-log-generated-by-service-fabric/167224)

<div class="topic-metadata">

**Author:** [@apbute](https://discuss.elastic.co/u/apbute)\
**Replies:** 8\
**Last updated:** [February 7, 2019, 1:12pm UTC](https://discuss.elastic.co/t/getting-issue-to-read-the-log-generated-by-service-fabric/167224 "2019-02-07T13:12:02Z")

</div>

We have service fabric application with asp.net core and trying to display the service fabric log and application log in Kibana using filebeat without logtash but we are facing issue with the same. Could you please assi…

---

## [Make functionbeat logs show in "Logs" section of Kibana](https://discuss.elastic.co/t/make-functionbeat-logs-show-in-logs-section-of-kibana/165453)

<div class="topic-metadata">

**Author:** [@Marc\_Fielding](https://discuss.elastic.co/u/Marc_Fielding)\
**Replies:** 4\
**Last updated:** [February 7, 2019, 1:03pm UTC](https://discuss.elastic.co/t/make-functionbeat-logs-show-in-logs-section-of-kibana/165453 "2019-02-07T13:03:16Z")

</div>

Heya, So I'd like to use the nice new tail functionality for our Lambda logs in Kibana, the logs themselves are going into a filebeat index, but when I click "Logs" it tells me there are none available and obviously as …

---

## [Force logstash+FILEBEAT to reindex csv file](https://discuss.elastic.co/t/force-logstash-filebeat-to-reindex-csv-file/166219)

<div class="topic-metadata">

**Author:** [@Aralex](https://discuss.elastic.co/u/Aralex)\
**Replies:** 7\
**Last updated:** [February 7, 2019, 10:42am UTC](https://discuss.elastic.co/t/force-logstash-filebeat-to-reindex-csv-file/166219 "2019-02-07T10:42:33Z")

</div>

Hi, I'm trying to do the same as in this post: except a big difference: the solution in the post above is using only logstash, while my pipeline ships data using filebeat to logstash. The file input plugin of logstash…

---

## [Using Keystores - not working (v6.6.0)](https://discuss.elastic.co/t/using-keystores-not-working-v6-6-0/167301)

<div class="topic-metadata">

**Author:** [@mark.lawton2](https://discuss.elastic.co/u/mark.lawton2)\
**Replies:** 1\
**Last updated:** [February 7, 2019, 9:04am UTC](https://discuss.elastic.co/t/using-keystores-not-working-v6-6-0/167301 "2019-02-07T09:04:47Z")

</div>

Hello, I'm trying to use a keystore value in my beat configuration and I can't seem to get it working... For example - I'm currently trying it with heartbeat. THIS WORKS - output.elasticsearch: password: "clear\_text…

---

## [Setting up Beats on a shared Cluster](https://discuss.elastic.co/t/setting-up-beats-on-a-shared-cluster/167392)

<div class="topic-metadata">

**Author:** [@andreas.maier](https://discuss.elastic.co/u/andreas.maier)\
**Replies:** 0\
**Last updated:** [February 7, 2019, 8:15am UTC](https://discuss.elastic.co/t/setting-up-beats-on-a-shared-cluster/167392 "2019-02-07T08:15:21Z")

</div>

Hello everybody, I have a more or less central openshift cluster I have to use for my applications. There are multiple other projects/namespaces on the cluster I have no access rights on and will also not get any rights…

---

## [Confg \`setup.template.settings.index.lifecycle.name\` is not working](https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253)

<div class="topic-metadata">

**Author:** [@kimxogus](https://discuss.elastic.co/u/kimxogus)\
**Replies:** 3\
**Last updated:** [February 7, 2019, 5:31am UTC](https://discuss.elastic.co/t/confg-setup-template-settings-index-lifecycle-name-is-not-working/166253 "2019-02-07T05:31:57Z")

</div>

I'm using official filebeat and metricbeat docker image in kubernetes. I set setup.template.settings.index.lifecycle.name config as log-policy and checked that config is properly set in beat pods, but log shows 2019-01…

---

## [Filebeat doesn't parse postgresql csvlog files](https://discuss.elastic.co/t/filebeat-doesnt-parse-postgresql-csvlog-files/167351)

<div class="topic-metadata">

**Author:** [@yurim](https://discuss.elastic.co/u/yurim)\
**Replies:** 0\
**Last updated:** [February 6, 2019, 7:48pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-parse-postgresql-csvlog-files/167351 "2019-02-06T19:48:52Z")

</div>

Hi guys, Using 6.5.4 stack. configured filebeat with postgresql module and trying to parse postgres csvlog files into ES and visualize in Kibana. In Kibana filebeat-\* index I can see postgres.log.\* fields (9 of them), b…

---

## [How to get the all disks(Drive) via metricbeat?](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927)

<div class="topic-metadata">

**Author:** [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Replies:** 6\
**Last updated:** [February 6, 2019, 5:18pm UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927 "2019-02-06T17:18:52Z")

</div>

Hi all, I have three disks, want to get three disks in kibana but I am able to get only one disk. I have added the name of those disk in system.yml configuration file but still, only one/dev/xvda1 is getting in kibana. …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=382)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=384)
