# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=384

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 385

---

## [Filebeat as webjob in an Azure App Service](https://discuss.elastic.co/t/filebeat-as-webjob-in-an-azure-app-service/165056)

<div class="topic-metadata">

**Author:** [@Brett\_Larson](https://discuss.elastic.co/u/Brett_Larson)\
**Replies:** 6\
**Last updated:** [February 6, 2019, 4:18pm UTC](https://discuss.elastic.co/t/filebeat-as-webjob-in-an-azure-app-service/165056 "2019-02-06T16:18:32Z")

</div>

Hello, Has anyone got Filebeat to work in an Azure App Service? I'm interested in how I can send the IIS logs using the IIS module from Filebeat running as a webjob to our Elastic cloud cluster. Please let me know, Th…

---

## [Visualizing apache2 logs in Kibana](https://discuss.elastic.co/t/visualizing-apache2-logs-in-kibana/167325)

<div class="topic-metadata">

**Author:** [@dhiraj\_khanna](https://discuss.elastic.co/u/dhiraj_khanna)\
**Replies:** 1\
**Last updated:** [February 6, 2019, 4:12pm UTC](https://discuss.elastic.co/t/visualizing-apache2-logs-in-kibana/167325 "2019-02-06T16:12:37Z")

</div>

I am trying to visualize apache2 logs in the dashboards which ship with Kibana (6.6) on Windows. Here's what I have done: Installed the ingest-user-agent and ingest-geoip plugins in Elasticsearch. Enabled the apach…

---

## [How to fix Filebeat mapper parsing error - tried to parse field\[x\] as object, but found a concrete value?](https://discuss.elastic.co/t/how-to-fix-filebeat-mapper-parsing-error-tried-to-parse-field-x-as-object-but-found-a-concrete-value/162370)

<div class="topic-metadata">

**Author:** [@ddregalo](https://discuss.elastic.co/u/ddregalo)\
**Replies:** 5\
**Last updated:** [February 6, 2019, 3:48pm UTC](https://discuss.elastic.co/t/how-to-fix-filebeat-mapper-parsing-error-tried-to-parse-field-x-as-object-but-found-a-concrete-value/162370 "2019-02-06T15:48:56Z")

</div>

I am using filebeat 6.2.1 to pick up logs, parse as JSON and send them to elasticsearch 6.5.4 and I am getting the following error: WARN elasticsearch/client.go:520 Cannot index event publisher.Event{Content:beat…

---

## [Is there any Beats solution for using a custom binary for decoding logs/metrics?](https://discuss.elastic.co/t/is-there-any-beats-solution-for-using-a-custom-binary-for-decoding-logs-metrics/167319)

<div class="topic-metadata">

**Author:** [@rbendik](https://discuss.elastic.co/u/rbendik)\
**Replies:** 0\
**Last updated:** [February 6, 2019, 3:48pm UTC](https://discuss.elastic.co/t/is-there-any-beats-solution-for-using-a-custom-binary-for-decoding-logs-metrics/167319 "2019-02-06T15:48:10Z")

</div>

Hi all. I would like to test whether an EBK (es, beats, kibana) stack could be setup to work in my situation. I am very new to Beats and only was introduced to it in the past workshop I recently attended. We have a cus…

---

## [Connection marked as failed because the onConnect callback failed: Error loading Elasticsearch template](https://discuss.elastic.co/t/connection-marked-as-failed-because-the-onconnect-callback-failed-error-loading-elasticsearch-template/167209)

<div class="topic-metadata">

**Author:** [@andymelichar](https://discuss.elastic.co/u/andymelichar)\
**Replies:** 3\
**Last updated:** [February 6, 2019, 3:46pm UTC](https://discuss.elastic.co/t/connection-marked-as-failed-because-the-onconnect-callback-failed-error-loading-elasticsearch-template/167209 "2019-02-06T15:46:09Z")

</div>

Having trouble getting metricbeats 6.6 running on a Kubernetes cluster. Used https://github.com/elastic/beats/blob/master/deploy/kubernetes/metricbeat-kubernetes.yaml as my deploy file for kubectl. Edited the file for m…

---

## [Metricbeat - 'system' -\> 'filesystem' metrics does not include network drives](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420)

<div class="topic-metadata">

**Author:** [@yuval\_yellin](https://discuss.elastic.co/u/yuval_yellin)\
**Replies:** 11\
**Last updated:** [February 6, 2019, 1:15pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420 "2019-02-06T13:15:12Z")

</div>

Hi all, I am using system module in Metricbeat in order to monitor my computer's drives and I don't see any metrics on network drives, just on local drives. I am using 'filesystem' metricset. Thanks for your help, Yu…

---

## [Filebeat configuration - ssl.verification\_mode: none doesn't work](https://discuss.elastic.co/t/filebeat-configuration-ssl-verification-mode-none-doesnt-work/166327)

<div class="topic-metadata">

**Author:** [@kacedn](https://discuss.elastic.co/u/kacedn)\
**Replies:** 4\
**Last updated:** [February 6, 2019, 12:36pm UTC](https://discuss.elastic.co/t/filebeat-configuration-ssl-verification-mode-none-doesnt-work/166327 "2019-02-06T12:36:02Z")

</div>

Hello Version of filebeat : 6.3.0 I don't understand why ssl.verification\_mode is ignored. In filebeat.yml, i am trying to configure ssl for ElasticSearchOutput. https://www.elastic.co/guide/en/beats/filebeat/current…

---

## [Metricbeat error on Redis module](https://discuss.elastic.co/t/metricbeat-error-on-redis-module/167124)

<div class="topic-metadata">

**Author:** [@Nelson\_Ferreira\_Juni](https://discuss.elastic.co/u/Nelson_Ferreira_Juni)\
**Replies:** 1\
**Last updated:** [February 6, 2019, 11:58am UTC](https://discuss.elastic.co/t/metricbeat-error-on-redis-module/167124 "2019-02-06T11:58:15Z")

</div>

I'm running a master and a slave instance of redis on a local and remote server. When I try to start metricbeat I'm getting this error: ERROR redis/redis.go:72 Error retrieving slowlog len: ERR unknown command SLOWLOG,…

---

## [Never dropping the events](https://discuss.elastic.co/t/never-dropping-the-events/166707)

<div class="topic-metadata">

**Author:** [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Replies:** 14\
**Last updated:** [February 6, 2019, 7:12am UTC](https://discuss.elastic.co/t/never-dropping-the-events/166707 "2019-02-06T07:12:11Z")

</div>

I have used drop\_fields to drop the fields but after restarting winlogbeat and logstash it's doesn't drop the specified field that it is show in kibana winlogbeat.yml is as: (is there is any wrong i have done or why it…

---

## [How to cross check weather my beats are running or not](https://discuss.elastic.co/t/how-to-cross-check-weather-my-beats-are-running-or-not/167213)

<div class="topic-metadata">

**Author:** [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Replies:** 6\
**Last updated:** [February 6, 2019, 4:44am UTC](https://discuss.elastic.co/t/how-to-cross-check-weather-my-beats-are-running-or-not/167213 "2019-02-06T04:44:34Z")

</div>

Hi team, In an environment of monitoring 100 server using packetbeat, How do i know that all 100 beats are running fine and i data is streaming ? Is there any configuration to be done at beats side ? Thanks Ramya

---

## [Problem with filebeat yml file on Windows](https://discuss.elastic.co/t/problem-with-filebeat-yml-file-on-windows/167154)

<div class="topic-metadata">

**Author:** [@dhiraj\_khanna](https://discuss.elastic.co/u/dhiraj_khanna)\
**Replies:** 6\
**Last updated:** [February 6, 2019, 1:17am UTC](https://discuss.elastic.co/t/problem-with-filebeat-yml-file-on-windows/167154 "2019-02-06T01:17:05Z")

</div>

I am quite new to the Elastic stack and trying to experiment with visualization of apache log files in Kibana. I am using filebeat to ingest the apache logs. However when I run .\\filebeat.exe setup -e, I get the followin…

---

## [Set Winlogbeat to wait before shipping events to Logstash](https://discuss.elastic.co/t/set-winlogbeat-to-wait-before-shipping-events-to-logstash/166518)

<div class="topic-metadata">

**Author:** [@elic1997](https://discuss.elastic.co/u/elic1997)\
**Replies:** 1\
**Last updated:** [February 5, 2019, 2:54pm UTC](https://discuss.elastic.co/t/set-winlogbeat-to-wait-before-shipping-events-to-logstash/166518 "2019-02-05T14:54:32Z")

</div>

Hello, I want to set a time interval, about 5-10 minutes, before sending events with Winlogbeat to Logstash. I read about the internal queue, but I don't fully understand if it does what I need. Is it possible to ship…

---

## [Please add support for TZSP](https://discuss.elastic.co/t/please-add-support-for-tzsp/164202)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 2\
**Last updated:** [February 5, 2019, 2:41pm UTC](https://discuss.elastic.co/t/please-add-support-for-tzsp/164202 "2019-02-05T14:41:05Z")

</div>

I use RouterOS devices which provide the ability to stream wireless traffic over a wired connection (see https://en.wikipedia.org/wiki/TZSP) for the purpose of traffic inspection. I was wondering if there was a way to g…

---

## [Determination Filebeat -\> Elasticsearch performance](https://discuss.elastic.co/t/determination-filebeat-elasticsearch-performance/165800)

<div class="topic-metadata">

**Author:** [@Daniel\_Dalacort](https://discuss.elastic.co/u/Daniel_Dalacort)\
**Replies:** 2\
**Last updated:** [February 5, 2019, 12:32pm UTC](https://discuss.elastic.co/t/determination-filebeat-elasticsearch-performance/165800 "2019-02-05T12:32:06Z")

</div>

Hello! I understand that throughput of filebeat to elastic depends on many things, and before optimization I want to know it's really necessary. I have a high load app that generates huge amount of logs, so I want to m…

---

## [Sending Nginx logs to elasticsearch using Filebeat](https://discuss.elastic.co/t/sending-nginx-logs-to-elasticsearch-using-filebeat/167100)

<div class="topic-metadata">

**Author:** [@Raghav\_Garg](https://discuss.elastic.co/u/Raghav_Garg)\
**Replies:** 0\
**Last updated:** [February 5, 2019, 10:57am UTC](https://discuss.elastic.co/t/sending-nginx-logs-to-elasticsearch-using-filebeat/167100 "2019-02-05T10:57:28Z")

</div>

Hello, I am trying to send nginx logs from my app-server to log-server(elasticsearch) using filebeat. I am using Nginx module for this purpose, and it is working great. But, I am unable to change "index" for these logs…

---

## [Use Metricbeat per Openshift namespace (not per cluster)](https://discuss.elastic.co/t/use-metricbeat-per-openshift-namespace-not-per-cluster/167072)

<div class="topic-metadata">

**Author:** [@manuelpras](https://discuss.elastic.co/u/manuelpras)\
**Replies:** 0\
**Last updated:** [February 5, 2019, 7:53am UTC](https://discuss.elastic.co/t/use-metricbeat-per-openshift-namespace-not-per-cluster/167072 "2019-02-05T07:53:42Z")

</div>

Hi :slight\_smile: we have a namespace in an Openshift cluster which we'd like to monitor using the Kubernetes Metricbeat. For this we downloaded the metricbeat-kubernetes.yaml from your Github account and adapted it to…

---

## [I am not read all log file and am not able to create new index](https://discuss.elastic.co/t/i-am-not-read-all-log-file-and-am-not-able-to-create-new-index/167031)

<div class="topic-metadata">

**Author:** [@nani](https://discuss.elastic.co/u/nani)\
**Replies:** 1\
**Last updated:** [February 5, 2019, 1:28am UTC](https://discuss.elastic.co/t/i-am-not-read-all-log-file-and-am-not-able-to-create-new-index/167031 "2019-02-05T01:28:51Z")

</div>

hi i am new to elasticsearch and filebeat. #=========================== Filebeat inputs ============================= filebeat.inputs: Each - is an input. Most options can be set at the input level, so you can use dif…

---

## [Kube-state-metrics in Openshift](https://discuss.elastic.co/t/kube-state-metrics-in-openshift/167047)

<div class="topic-metadata">

**Author:** [@Matthew\_Reed](https://discuss.elastic.co/u/Matthew_Reed)\
**Replies:** 0\
**Last updated:** [February 5, 2019, 12:18am UTC](https://discuss.elastic.co/t/kube-state-metrics-in-openshift/167047 "2019-02-05T00:18:09Z")

</div>

In openshift 3.11, kube-state-metrics is deployed using https rather than http. How do you set up the metricbeat yml configuration to get state\_\* metrics from kube-state-metrics with an https configuration? I have been u…

---

## [Filebeat paths: /u01/logs/access\_log.2019-02-04](https://discuss.elastic.co/t/filebeat-paths-u01-logs-access-log-2019-02-04/167021)

<div class="topic-metadata">

**Author:** [@Shashidhar\_Wl](https://discuss.elastic.co/u/Shashidhar_Wl)\
**Replies:** 0\
**Last updated:** [February 4, 2019, 8:37pm UTC](https://discuss.elastic.co/t/filebeat-paths-u01-logs-access-log-2019-02-04/167021 "2019-02-04T20:37:09Z")

</div>

Filebeat is not accepting the path when the date extension. Can some one give me the correct format to add to the filebeat configuration. type: log tags: \["acesslogs"\] enabled: true paths: /u01/httpd/logs/access\_lo…

---

## [Filebeat to logstash connect: no route to host](https://discuss.elastic.co/t/filebeat-to-logstash-connect-no-route-to-host/167002)

<div class="topic-metadata">

**Author:** [@hsam](https://discuss.elastic.co/u/hsam)\
**Replies:** 0\
**Last updated:** [February 4, 2019, 5:06pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-connect-no-route-to-host/167002 "2019-02-04T17:06:15Z")

</div>

Everything is up and running but filebeat cannot contact logstash which is on another machine logstash.conf input { beats { port =\> 5044 } } output { elasticsearch { hosts =\> \["http://localhost:9200"\] index =\> …

---

## [Heartbeat.config.monitors option not working on 6.5.4?](https://discuss.elastic.co/t/heartbeat-config-monitors-option-not-working-on-6-5-4/166755)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 6\
**Last updated:** [February 4, 2019, 4:59pm UTC](https://discuss.elastic.co/t/heartbeat-config-monitors-option-not-working-on-6-5-4/166755 "2019-02-04T16:59:45Z")

</div>

Hello, I'm trying to use heartbeat to monitor the uptime of some devices and looking into the documentation I saw that is possible to have your monitors in a separated file instead of having them in the main heartbeat.y…

---

## [FileBeat Send Data to Apache Nifi](https://discuss.elastic.co/t/filebeat-send-data-to-apache-nifi/166999)

<div class="topic-metadata">

**Author:** [@samwzm](https://discuss.elastic.co/u/samwzm)\
**Replies:** 0\
**Last updated:** [February 4, 2019, 4:58pm UTC](https://discuss.elastic.co/t/filebeat-send-data-to-apache-nifi/166999 "2019-02-04T16:58:59Z")

</div>

Hi, there, Is it possible for Filebeat to send data/logs to Apache Nifi? I can't find any related document. Please advise. Thanks, Sam

---

## [Write connection reset by peer - Filebeat \> Logstash](https://discuss.elastic.co/t/write-connection-reset-by-peer-filebeat-logstash/166993)

<div class="topic-metadata">

**Author:** [@IcedGoblin](https://discuss.elastic.co/u/IcedGoblin)\
**Replies:** 0\
**Last updated:** [February 4, 2019, 4:32pm UTC](https://discuss.elastic.co/t/write-connection-reset-by-peer-filebeat-logstash/166993 "2019-02-04T16:32:56Z")

</div>

Hi After some help please with an error sending logs to Logstash using Filebeat. Configuration is working and logs are received however we are receiving the following error: - 2019-02-04T16:13:07.288Z ERROR lo…

---

## [Filebeat not sending data to redis with 2 servers in the hosts config](https://discuss.elastic.co/t/filebeat-not-sending-data-to-redis-with-2-servers-in-the-hosts-config/166992)

<div class="topic-metadata">

**Author:** [@Bruno\_Calzetta](https://discuss.elastic.co/u/Bruno_Calzetta)\
**Replies:** 0\
**Last updated:** [February 4, 2019, 4:30pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-data-to-redis-with-2-servers-in-the-hosts-config/166992 "2019-02-04T16:30:30Z")

</div>

Hi, I'm using Filebeat to send data to redis and depending on the region, one of the redis servers is not available (firewall), but want to keep the same config so the released code/config is the same for all regions. W…

---

## [Filebeat multiline works as single liners](https://discuss.elastic.co/t/filebeat-multiline-works-as-single-liners/166967)

<div class="topic-metadata">

**Author:** [@ep4sh](https://discuss.elastic.co/u/ep4sh)\
**Replies:** 1\
**Last updated:** [February 4, 2019, 4:03pm UTC](https://discuss.elastic.co/t/filebeat-multiline-works-as-single-liners/166967 "2019-02-04T16:03:29Z")

</div>

I have 2 inputs with multiline logs. And expected working logstash: First: codec =\> multiline { pattern =\> "^\\d" negate =\> true what =\> previous…

---

## [Merticbeat isn't working with if else condition](https://discuss.elastic.co/t/merticbeat-isnt-working-with-if-else-condition/165734)

<div class="topic-metadata">

**Author:** [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Replies:** 3\
**Last updated:** [February 4, 2019, 1:09pm UTC](https://discuss.elastic.co/t/merticbeat-isnt-working-with-if-else-condition/165734 "2019-02-04T13:09:20Z")

</div>

I'm using Filebeat to collect custom logs and Metricbeat to monitor system (CPU, RAM, DISK SPACE). I'm able to do this without using if condition and if I'm using if conduction in the logstash filter then it is not worki…

---

## [Filebeat doesn't send logs to Logstash](https://discuss.elastic.co/t/filebeat-doesnt-send-logs-to-logstash/166940)

<div class="topic-metadata">

**Author:** [@KindTomato](https://discuss.elastic.co/u/KindTomato)\
**Replies:** 0\
**Last updated:** [February 4, 2019, 10:37am UTC](https://discuss.elastic.co/t/filebeat-doesnt-send-logs-to-logstash/166940 "2019-02-04T10:37:06Z")

</div>

Hey my filebeat stopped sending logs last friday and I'm wondering as to what reason is it: journalctl -fu filebeat -\> ERROR Failed to connect to backoff(async(tcp://\<logstash\_ip\>:5044)): dial tcp \<logstash\_ip\>:5044: c…

---

## [Incorrect Journalbeat container output fields for Docker journald messages](https://discuss.elastic.co/t/incorrect-journalbeat-container-output-fields-for-docker-journald-messages/166017)

<div class="topic-metadata">

**Author:** [@SpComb](https://discuss.elastic.co/u/SpComb)\
**Replies:** 3\
**Last updated:** [February 4, 2019, 12:22pm UTC](https://discuss.elastic.co/t/incorrect-journalbeat-container-output-fields-for-docker-journald-messages/166017 "2019-02-04T12:22:52Z")

</div>

These two journalbeat translated fields for the Docker --log-driver=journald messages seem wrong: conatiner.id\_truncated is typo'd (also in git master): https://github.com/elastic/beats/blob/v6.5.4/journalbeat/reader/fi…

---

## [Error.message/type](https://discuss.elastic.co/t/error-message-type/166947)

<div class="topic-metadata">

**Author:** [@erdo](https://discuss.elastic.co/u/erdo)\
**Replies:** 0\
**Last updated:** [February 4, 2019, 11:35am UTC](https://discuss.elastic.co/t/error-message-type/166947 "2019-02-04T11:35:26Z")

</div>

I am using file beat to send my log file to the kibana but within my table I am seeing these two fields and I dont want them to be seen until I am facing with a parse error. my yml file: filebeat.prospectors: # Each…

---

## [Do you have any idea that easily converts my DBX file in PST file format?](https://discuss.elastic.co/t/do-you-have-any-idea-that-easily-converts-my-dbx-file-in-pst-file-format/166928)

<div class="topic-metadata">

**Author:** [@fantryenter](https://discuss.elastic.co/u/fantryenter)\
**Replies:** 1\
**Last updated:** [February 4, 2019, 10:01am UTC](https://discuss.elastic.co/t/do-you-have-any-idea-that-easily-converts-my-dbx-file-in-pst-file-format/166928 "2019-02-04T10:01:54Z")

</div>

How to convert DBX to PST file format? If you know this about, easy way to convert PST file format from Outlook Express so please describe this method. Manual method available but this method is a very long process. Its …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=383)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=385)
