# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=385

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 386

---

## [\[Unresolved\] 5 Metricbeat Kibana Dashboards show various "X of X Shards Failed" messages](https://discuss.elastic.co/t/unresolved-5-metricbeat-kibana-dashboards-show-various-x-of-x-shards-failed-messages/166835)

<div class="topic-metadata">

**Author:** [@wad11656](https://discuss.elastic.co/u/wad11656)\
**Replies:** 3\
**Last updated:** [February 3, 2019, 2:09am UTC](https://discuss.elastic.co/t/unresolved-5-metricbeat-kibana-dashboards-show-various-x-of-x-shards-failed-messages/166835 "2019-02-03T02:09:44Z")

</div>

Host: Debian 9 ELK Stack version: 6.6.0 Logs sent to Logstash or Elasticsearch: Elasticsearch (hopefully Logstash later) Summary: When I go to Dashboards in Kibana and click on the \[Metricbeat\] dashboards, 5 of them …

---

## [Filebeat as Daemonset for all Kubernetes Logs (including nginx)](https://discuss.elastic.co/t/filebeat-as-daemonset-for-all-kubernetes-logs-including-nginx/166752)

<div class="topic-metadata">

**Author:** [@sujituk](https://discuss.elastic.co/u/sujituk)\
**Replies:** 3\
**Last updated:** [February 2, 2019, 10:38pm UTC](https://discuss.elastic.co/t/filebeat-as-daemonset-for-all-kubernetes-logs-including-nginx/166752 "2019-02-02T22:38:29Z")

</div>

I have attached my filebeat which was taken from https://github.com/elastic/beats/blob/6.5/deploy/kubernetes/filebeat-kubernetes.yaml + Added ES endpoint with creds + disabled filebeat.config.inputs + enabled autodiscove…

---

## [Filebeat on more than one server](https://discuss.elastic.co/t/filebeat-on-more-than-one-server/166801)

<div class="topic-metadata">

**Author:** [@jimbolya](https://discuss.elastic.co/u/jimbolya)\
**Replies:** 0\
**Last updated:** [February 2, 2019, 1:14am UTC](https://discuss.elastic.co/t/filebeat-on-more-than-one-server/166801 "2019-02-02T01:14:24Z")

</div>

Not sure if i'm doing this correctly. I have file beat on two servers. The first server that I installed filebeat on is still sending logs. The second server is not. UFW is disable on both. I'm using version 6.5 and…

---

## [Docker Images for ARM 32 or 64-bit (Raspberry PI, AWS)?](https://discuss.elastic.co/t/docker-images-for-arm-32-or-64-bit-raspberry-pi-aws/166798)

<div class="topic-metadata">

**Author:** [@Jeeppler](https://discuss.elastic.co/u/Jeeppler)\
**Replies:** 0\
**Last updated:** [February 2, 2019, 12:20am UTC](https://discuss.elastic.co/t/docker-images-for-arm-32-or-64-bit-raspberry-pi-aws/166798 "2019-02-02T00:20:09Z")

</div>

Elastic offers Docker images for several beats and other products. As far as I understand it, all Docker images are build for amd64 (Intel x86\_64). However, over the last couple of years ARM both 32-bit and 64-bit has b…

---

## [Filebeat is not sending Snort logs to Logstash](https://discuss.elastic.co/t/filebeat-is-not-sending-snort-logs-to-logstash/166797)

<div class="topic-metadata">

**Author:** [@manuelm](https://discuss.elastic.co/u/manuelm)\
**Replies:** 0\
**Last updated:** [February 2, 2019, 12:08am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-snort-logs-to-logstash/166797 "2019-02-02T00:08:55Z")

</div>

Hi! I’m trying to send alerts from Snort IDS to Elasticsearch, therefore I'm using 3 technologies: Elasticsearch- https://pastebin.com/uCNMaZFJ Logstash- https://pastebin.com/zgnbbw9K Filebeat- https://pastebin.com/4…

---

## [How to measure Availability KPIs and downtime from heartbeats?](https://discuss.elastic.co/t/how-to-measure-availability-kpis-and-downtime-from-heartbeats/165903)

<div class="topic-metadata">

**Author:** [@Ahmed\_Adel](https://discuss.elastic.co/u/Ahmed_Adel)\
**Replies:** 1\
**Last updated:** [February 1, 2019, 9:54pm UTC](https://discuss.elastic.co/t/how-to-measure-availability-kpis-and-downtime-from-heartbeats/165903 "2019-02-01T21:54:17Z")

</div>

I've configured heartbeat file to send a heartbeat every 30 seconds, now if i received a beat with monitor\_status "down", and the next beat was up. Is there are a field represents the downtime between the beats? what i…

---

## [ModuleNotFoundError: No module named 'yaml' on execute make update on filebeat](https://discuss.elastic.co/t/modulenotfounderror-no-module-named-yaml-on-execute-make-update-on-filebeat/166636)

<div class="topic-metadata">

**Author:** [@gleon](https://discuss.elastic.co/u/gleon)\
**Replies:** 0\
**Last updated:** [January 31, 2019, 8:28pm UTC](https://discuss.elastic.co/t/modulenotfounderror-no-module-named-yaml-on-execute-make-update-on-filebeat/166636 "2019-01-31T20:28:04Z")

</div>

Hi everyone I'm experiencing the following error while trying to do make update on filebeat source \[administratoruser@linux-centos-7-201901171514 filebeat\]$ pwd /home/administratoruser/go/src/github.com/elastic/beats/…

---

## [Filebeat paths can't start with double dash](https://discuss.elastic.co/t/filebeat-paths-cant-start-with-double-dash/165918)

<div class="topic-metadata">

**Author:** [@SrHades](https://discuss.elastic.co/u/SrHades)\
**Replies:** 2\
**Last updated:** [February 1, 2019, 5:49pm UTC](https://discuss.elastic.co/t/filebeat-paths-cant-start-with-double-dash/165918 "2019-02-01T17:49:28Z")

</div>

Hello, I'm trying to configure my paths which are at \\......... At configuration I configure it as \\\\...\\...\\... but filebeat load it as ......... Here an image: And here the config loaded: Anyone guess what's h…

---

## [IIS module fields doesn't show up in discover page](https://discuss.elastic.co/t/iis-module-fields-doesnt-show-up-in-discover-page/166728)

<div class="topic-metadata">

**Author:** [@Costi](https://discuss.elastic.co/u/Costi)\
**Replies:** 0\
**Last updated:** [February 1, 2019, 12:07pm UTC](https://discuss.elastic.co/t/iis-module-fields-doesnt-show-up-in-discover-page/166728 "2019-02-01T12:07:36Z")

</div>

Hi! I am using filebeat to ingest IIS logs into elasticsearch. I am able to see the ingested logs, but i cannot see the fields available for the IIS module in the Available fields section in the Discover page. The iis …

---

## [Setting a different format for @timestamp](https://discuss.elastic.co/t/setting-a-different-format-for-timestamp/166721)

<div class="topic-metadata">

**Author:** [@PaoloZ](https://discuss.elastic.co/u/PaoloZ)\
**Replies:** 0\
**Last updated:** [February 1, 2019, 11:34am UTC](https://discuss.elastic.co/t/setting-a-different-format-for-timestamp/166721 "2019-02-01T11:34:11Z")

</div>

Hi, I am new to Filebeat and I am wondering if there is a way to have a different format for @timestamp field in Elasticsearch. ... "@timestamp" : "2019-02-01T10:52:29.852Z", ... Can I force the format to something li…

---

## [Filebeat temporarily unable to connect to ES](https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 3\
**Last updated:** [February 1, 2019, 10:09am UTC](https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697 "2019-02-01T10:09:00Z")

</div>

If Filebeat, running as a service, cannot temporarily connect to the destination Elasticsearch instance then what is the process? Does it continually retry until the destination is available? Does it just error out? I…

---

## [Multiple tags for each container and running on ec2-instance](https://discuss.elastic.co/t/multiple-tags-for-each-container-and-running-on-ec2-instance/165944)

<div class="topic-metadata">

**Author:** [@kalyan27](https://discuss.elastic.co/u/kalyan27)\
**Replies:** 3\
**Last updated:** [February 1, 2019, 6:21am UTC](https://discuss.elastic.co/t/multiple-tags-for-each-container-and-running-on-ec2-instance/165944 "2019-02-01T06:21:13Z")

</div>

Hi, Logs storing on native path(locally) we are running multiple containers (Container A and Container B) on AWS ECS.. and specific folder of ec2-instance (Linux) are mounted on each container docker files. so logs are…

---

## [Network and firewall monitoring](https://discuss.elastic.co/t/network-and-firewall-monitoring/166644)

<div class="topic-metadata">

**Author:** [@Abm](https://discuss.elastic.co/u/Abm)\
**Replies:** 0\
**Last updated:** [January 31, 2019, 9:08pm UTC](https://discuss.elastic.co/t/network-and-firewall-monitoring/166644 "2019-01-31T21:08:46Z")

</div>

Hi Is it possible to monitor below items at network level or firewall level. Connections in Use Active interfaces Number of Tunnels in use Number of user Sessions in use alerting on excess failed session setups En…

---

## [Monitoring Chassis health](https://discuss.elastic.co/t/monitoring-chassis-health/166641)

<div class="topic-metadata">

**Author:** [@Abm](https://discuss.elastic.co/u/Abm)\
**Replies:** 0\
**Last updated:** [January 31, 2019, 8:58pm UTC](https://discuss.elastic.co/t/monitoring-chassis-health/166641 "2019-01-31T20:58:29Z")

</div>

Hi We are looking to monitor Chassis Health (Fans, Power Supplies, etc.). I was looking into metric beat but couldn't find metric beat supports it or not. Help me how we can capture this. Thanks

---

## [Syscall/dll\_windows.go Error With all Beats](https://discuss.elastic.co/t/syscall-dll-windows-go-error-with-all-beats/163781)

<div class="topic-metadata">

**Author:** [@John\_Guzman](https://discuss.elastic.co/u/John_Guzman)\
**Replies:** 2\
**Last updated:** [January 31, 2019, 8:50pm UTC](https://discuss.elastic.co/t/syscall-dll-windows-go-error-with-all-beats/163781 "2019-01-31T20:50:38Z")

</div>

Hello! I need to install MetricBeat, WinlogBeat, and a beat of mine in a Windows Server 2003 R2 Service Pack 2 x86 machine, but i still getting this error. It's urgent to have those beats installed, changing SO is not a…

---

## [Add sequential number](https://discuss.elastic.co/t/add-sequential-number/166632)

<div class="topic-metadata">

**Author:** [@jenyphur](https://discuss.elastic.co/u/jenyphur)\
**Replies:** 0\
**Last updated:** [January 31, 2019, 7:34pm UTC](https://discuss.elastic.co/t/add-sequential-number/166632 "2019-01-31T19:34:45Z")

</div>

Hey there...is there a way to have Filebeats add a sequential number to our logs? In some other services, we use log4j 2 to create a sequential number for us and cloud foundry picks it up and then we use it for sorting …

---

## [Filebeat autodiscover exclude\_lines regex](https://discuss.elastic.co/t/filebeat-autodiscover-exclude-lines-regex/166559)

<div class="topic-metadata">

**Author:** [@danijelh](https://discuss.elastic.co/u/danijelh)\
**Replies:** 3\
**Last updated:** [January 31, 2019, 5:02pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-exclude-lines-regex/166559 "2019-01-31T17:02:01Z")

</div>

Hi. I am trying to exclude certain lines from pushing them to the ELK stack. We are using dockers and everything is working fine, but excluded lines are still being pushed to the ELK. Our config: filebeat.registry\_fil…

---

## [Metricbeat collect from single namespace](https://discuss.elastic.co/t/metricbeat-collect-from-single-namespace/166126)

<div class="topic-metadata">

**Author:** [@remmeier](https://discuss.elastic.co/u/remmeier)\
**Replies:** 2\
**Last updated:** [January 31, 2019, 1:12pm UTC](https://discuss.elastic.co/t/metricbeat-collect-from-single-namespace/166126 "2019-01-31T13:12:18Z")

</div>

Hi Is it possible to make use of metricbeat/kubernetes to collect data from a single namespace? Background is we would like bundle it with a product to monitor itself. That product will run within a dedicated Kubernetes…

---

## [Multiline filter not working as expected](https://discuss.elastic.co/t/multiline-filter-not-working-as-expected/166536)

<div class="topic-metadata">

**Author:** [@Abhishek\_Rane](https://discuss.elastic.co/u/Abhishek_Rane)\
**Replies:** 1\
**Last updated:** [January 31, 2019, 10:51am UTC](https://discuss.elastic.co/t/multiline-filter-not-working-as-expected/166536 "2019-01-31T10:51:19Z")

</div>

Hi Elastic/Filebeat Team, I am trying to configure filebeat along with logstash and Elasticsearch but not getting expected result in Kibana dashboard as logs are getting split into multiple line please find sample logs …

---

## [Unable to configure Redis password topology with filebeat](https://discuss.elastic.co/t/unable-to-configure-redis-password-topology-with-filebeat/166533)

<div class="topic-metadata">

**Author:** [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Replies:** 0\
**Last updated:** [January 31, 2019, 10:40am UTC](https://discuss.elastic.co/t/unable-to-configure-redis-password-topology-with-filebeat/166533 "2019-01-31T10:40:13Z")

</div>

Hi, I want to verify the "password\_topology" with "password" parameter in filebeat-5.4.3. But due to lack of documentation I can't understand the password topology. Can anyone guide me to understand the Redis password …

---

## [Ine 7: did not find expected key](https://discuss.elastic.co/t/ine-7-did-not-find-expected-key/166526)

<div class="topic-metadata">

**Author:** [@Liran\_Menashe](https://discuss.elastic.co/u/Liran_Menashe)\
**Replies:** 0\
**Last updated:** [January 31, 2019, 10:14am UTC](https://discuss.elastic.co/t/ine-7-did-not-find-expected-key/166526 "2019-01-31T10:14:29Z")

</div>

Hi everyone, can anybody help me with this error? 2019-01-31T11:56:12.339+0200 INFO instance/beat.go:410 filebeat stopped. 2019-01-31T11:56:12.339+0200 ERROR instance/beat.go:800 Exiting: 1 error: inv…

---

## [Multiline Command not working for Start and End of event](https://discuss.elastic.co/t/multiline-command-not-working-for-start-and-end-of-event/166444)

<div class="topic-metadata">

**Author:** [@miloni\_134](https://discuss.elastic.co/u/miloni_134)\
**Replies:** 0\
**Last updated:** [January 30, 2019, 11:12pm UTC](https://discuss.elastic.co/t/multiline-command-not-working-for-start-and-end-of-event/166444 "2019-01-30T23:12:49Z")

</div>

Hello, I have a log file which looks something like this: 2018-12-13 04:49:35,019 \[thread: Start\] INFO StateManager \[(null)\] (StartLogInfo) - StartLog passed info start 2018-12-13 04:49:35,020 \[thread: Start\] INFO S…

---

## [Filebeat OSQuery cannot locate index pattern](https://discuss.elastic.co/t/filebeat-osquery-cannot-locate-index-pattern/166290)

<div class="topic-metadata">

**Author:** [@rcoundon](https://discuss.elastic.co/u/rcoundon)\
**Replies:** 3\
**Last updated:** [January 30, 2019, 9:26pm UTC](https://discuss.elastic.co/t/filebeat-osquery-cannot-locate-index-pattern/166290 "2019-01-30T21:26:03Z")

</div>

Using ElasticCloud 6.6.0 I'm trying to ship OSQuery data via Filebeat to Elasticstash. On the machine with Filebeat I've set it up to connect to the Elastic Cloud Elasticsearch cluster and run "filebeat setup" where it …

---

## [Beats](https://discuss.elastic.co/t/beats/166361)

<div class="topic-metadata">

**Author:** [@Costi](https://discuss.elastic.co/u/Costi)\
**Replies:** 1\
**Last updated:** [January 30, 2019, 1:33pm UTC](https://discuss.elastic.co/t/beats/166361 "2019-01-30T13:33:46Z")

</div>

Hi! Let's say i have a cluster with 2 nodes and for different reasons both of them are down. What happened with the data that is collecting with metricbeat? Is stored somewhere else, somewhere local? Or it's not going t…

---

## [Logstash logs does not appears in the index created by Filebeat](https://discuss.elastic.co/t/logstash-logs-does-not-appears-in-the-index-created-by-filebeat/163372)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 7\
**Last updated:** [January 30, 2019, 12:26pm UTC](https://discuss.elastic.co/t/logstash-logs-does-not-appears-in-the-index-created-by-filebeat/163372 "2019-01-30T12:26:30Z")

</div>

Hi All, I have installed the filebeat component for log/monitor purposes for Logstash activities as it was described under the Logs menu item at Kibana. Maybe I have miss-configured something, but only the file opening…

---

## [HTTP request cancellation](https://discuss.elastic.co/t/http-request-cancellation/166320)

<div class="topic-metadata">

**Author:** [@landalf97](https://discuss.elastic.co/u/landalf97)\
**Replies:** 0\
**Last updated:** [January 30, 2019, 9:30am UTC](https://discuss.elastic.co/t/http-request-cancellation/166320 "2019-01-30T09:30:06Z")

</div>

Hi to everyone, I'm fairly new to elk and all its beats. Anyway I have a strong necessity to know when an http requests I'm monitoring has been cancelled by the client(obviously if that happens before transaction\_timeo…

---

## [Bind Metricbeats to specific ip address](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273)

<div class="topic-metadata">

**Author:** [@cdroescher](https://discuss.elastic.co/u/cdroescher)\
**Replies:** 7\
**Last updated:** [January 30, 2019, 9:07am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273 "2019-01-30T09:07:24Z")

</div>

Hi everyone, I want to bind Metricbeats to a specific IP-address. Is there a way to do so? For a Elasticsearch node I am able to set it in /etc/elasticsearch/elasticsearch.yml but for Metricbeats I am missing a setting…

---

## [Filebeat monitoring not showing "total event rates"](https://discuss.elastic.co/t/filebeat-monitoring-not-showing-total-event-rates/166224)

<div class="topic-metadata">

**Author:** [@bbking](https://discuss.elastic.co/u/bbking)\
**Replies:** 1\
**Last updated:** [January 30, 2019, 8:55am UTC](https://discuss.elastic.co/t/filebeat-monitoring-not-showing-total-event-rates/166224 "2019-01-30T08:55:23Z")

</div>

Hi, I turned on filebeat monitoring but the data shown in Kibana is not correct. Both "Total Events Rate" and "Bytes Sent Rate" are 0. Did I miss any setup? Config: xpack.monitoring: enabled: true elasticsearc…

---

## [AWS discovery from filebeat/metricbeat?](https://discuss.elastic.co/t/aws-discovery-from-filebeat-metricbeat/166130)

<div class="topic-metadata">

**Author:** [@Jeremy\_Lecour](https://discuss.elastic.co/u/Jeremy_Lecour)\
**Replies:** 2\
**Last updated:** [January 29, 2019, 5:20pm UTC](https://discuss.elastic.co/t/aws-discovery-from-filebeat-metricbeat/166130 "2019-01-29T17:20:18Z")

</div>

Hi, my Squid proxy is catching these requests and I wonder if they are from Filebeat or Metricbeat. They are the only Go binaries on the server. If so, how can I disable this AWS discovery feature ? X.X.X.X - - \[07/Ja…

---

## [Yet another case of Filebeat not reading/sending logs to LS](https://discuss.elastic.co/t/yet-another-case-of-filebeat-not-reading-sending-logs-to-ls/166215)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 2\
**Last updated:** [January 29, 2019, 5:08pm UTC](https://discuss.elastic.co/t/yet-another-case-of-filebeat-not-reading-sending-logs-to-ls/166215 "2019-01-29T17:08:09Z")

</div>

I have filebeat version 6.5.4 (amd64), libbeat 6.5.4 running on Ubuntu 16.04.5 LTS. It is configured to monitor the bro logs (I mean Zeek logs) and send those to Logstash. Up until this past weekend, it was working jus…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=384)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=386)
