# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=386

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 387

---

## [Use JMX (Java Management Interface) for beats (e.g. filebeat) to ship log data](https://discuss.elastic.co/t/use-jmx-java-management-interface-for-beats-e-g-filebeat-to-ship-log-data/166172)

<div class="topic-metadata">

**Author:** [@azam](https://discuss.elastic.co/u/azam)\
**Replies:** 0\
**Last updated:** [January 29, 2019, 1:03pm UTC](https://discuss.elastic.co/t/use-jmx-java-management-interface-for-beats-e-g-filebeat-to-ship-log-data/166172 "2019-01-29T13:03:50Z")

</div>

Hi everyone Is it possible to use JMX for beats (after compiling beats on source machine) to ship data, let's say from one machine (e.g. AIX) to another machine (e.g. Linux) ? Thanks :slight\_smile:

---

## [Filebeat compilation using gcc-go compiler in AIX](https://discuss.elastic.co/t/filebeat-compilation-using-gcc-go-compiler-in-aix/166153)

<div class="topic-metadata">

**Author:** [@azam](https://discuss.elastic.co/u/azam)\
**Replies:** 2\
**Last updated:** [January 29, 2019, 12:57pm UTC](https://discuss.elastic.co/t/filebeat-compilation-using-gcc-go-compiler-in-aix/166153 "2019-01-29T12:57:41Z")

</div>

Hi everyone I am trying to implement filebeat in one of ours test system which is AIX (version 7.2) based. Following all the previous discussions, i have noticed that now gcc-go can be installed in AIX 7.2. And we can c…

---

## [Adding a Command to a Beat](https://discuss.elastic.co/t/adding-a-command-to-a-beat/165851)

<div class="topic-metadata">

**Author:** [@Andre\_Baskin](https://discuss.elastic.co/u/Andre_Baskin)\
**Replies:** 1\
**Last updated:** [January 29, 2019, 12:43pm UTC](https://discuss.elastic.co/t/adding-a-command-to-a-beat/165851 "2019-01-29T12:43:48Z")

</div>

I am wondering what is the preferred method to add a command (or subcommand) to a Beat. The Beat was created from scratch using the instructions in the Beats Developer Guide. The issue I am having is that Cobra library …

---

## [What are the minimal privileges needed for an enrollment user](https://discuss.elastic.co/t/what-are-the-minimal-privileges-needed-for-an-enrollment-user/166144)

<div class="topic-metadata">

**Author:** [@kaem2111](https://discuss.elastic.co/u/kaem2111)\
**Replies:** 1\
**Last updated:** [January 29, 2019, 11:04am UTC](https://discuss.elastic.co/t/what-are-the-minimal-privileges-needed-for-an-enrollment-user/166144 "2019-01-29T11:04:09Z")

</div>

I am using Version 6.5, platinum license When using user, password for enrollment as described in https://www.elastic.co/guide/en/beats/metricbeat/current/enroll-beats.html what are the minimal security role/privilege…

---

## [Var/audit logs messages include wierd characters](https://discuss.elastic.co/t/var-audit-logs-messages-include-wierd-characters/165443)

<div class="topic-metadata">

**Author:** [@qnator](https://discuss.elastic.co/u/qnator)\
**Replies:** 6\
**Last updated:** [January 29, 2019, 6:34am UTC](https://discuss.elastic.co/t/var-audit-logs-messages-include-wierd-characters/165443 "2019-01-29T06:34:36Z")

</div>

Hello, My current setup on my machine is: Elasticsearch 6.5.4 Kibana 6.5.4 logstash 6.5.4 On a remote machine: filebeat 6.5.4 The output for filebeat is logstash and its configured to pu…

---

## [Filebeat is not writing logs when I try to start filebeat service](https://discuss.elastic.co/t/filebeat-is-not-writing-logs-when-i-try-to-start-filebeat-service/165439)

<div class="topic-metadata">

**Author:** [@janu](https://discuss.elastic.co/u/janu)\
**Replies:** 6\
**Last updated:** [January 29, 2019, 6:28am UTC](https://discuss.elastic.co/t/filebeat-is-not-writing-logs-when-i-try-to-start-filebeat-service/165439 "2019-01-29T06:28:24Z")

</div>

When I try to start the filebeat service it is throwing Error 1053 and I don't see logs that are written for this error. Can you please help

---

## [How to troubleshoot Windows Filebeat to logstash](https://discuss.elastic.co/t/how-to-troubleshoot-windows-filebeat-to-logstash/165690)

<div class="topic-metadata">

**Author:** [@Freebird](https://discuss.elastic.co/u/Freebird)\
**Replies:** 3\
**Last updated:** [January 29, 2019, 4:34am UTC](https://discuss.elastic.co/t/how-to-troubleshoot-windows-filebeat-to-logstash/165690 "2019-01-29T04:34:53Z")

</div>

Hi, I'm very new to all this and having problems figuring some basics. I got elastic and kibana running, and then got logstash running and taking stdin and giving me output to stdout. Now I set logstash to (hopefully)…

---

## [Missing values IIS Module](https://discuss.elastic.co/t/missing-values-iis-module/165075)

<div class="topic-metadata">

**Author:** [@Francois\_013](https://discuss.elastic.co/u/Francois_013)\
**Replies:** 2\
**Last updated:** [January 28, 2019, 10:13pm UTC](https://discuss.elastic.co/t/missing-values-iis-module/165075 "2019-01-28T22:13:43Z")

</div>

Hello, I’m using the IIS module from filebeat. I’ve giving it a default configuration because i do not require anymore at this moment. Now i’m running into the problem that the data does not get correctly ingested by …

---

## [Beats Central Management Failure to connect after enrolling wrong Beat id with Logstash encryption](https://discuss.elastic.co/t/beats-central-management-failure-to-connect-after-enrolling-wrong-beat-id-with-logstash-encryption/165478)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 1\
**Last updated:** [January 28, 2019, 8:14pm UTC](https://discuss.elastic.co/t/beats-central-management-failure-to-connect-after-enrolling-wrong-beat-id-with-logstash-encryption/165478 "2019-01-28T20:14:51Z")

</div>

I ran in to a few issues using the Beats Central Management feature so I figured I'd put my troubleshooting steps out there as it seems like some others might be experiencing the same issues. We have 6.5.4 ES/Kibana/Log…

---

## [User ID cannot be displayed properly](https://discuss.elastic.co/t/user-id-cannot-be-displayed-properly/165341)

<div class="topic-metadata">

**Author:** [@jingzhao](https://discuss.elastic.co/u/jingzhao)\
**Replies:** 4\
**Last updated:** [January 28, 2019, 4:10pm UTC](https://discuss.elastic.co/t/user-id-cannot-be-displayed-properly/165341 "2019-01-28T16:10:28Z")

</div>

User ID cannot be displayed properly

---

## [Metricbeat -E option does not respect metricbeat.modules.cpu.metrics setting](https://discuss.elastic.co/t/metricbeat-e-option-does-not-respect-metricbeat-modules-cpu-metrics-setting/165188)

<div class="topic-metadata">

**Author:** [@s.pawluk.krd](https://discuss.elastic.co/u/s.pawluk.krd)\
**Replies:** 1\
**Last updated:** [January 28, 2019, 3:36pm UTC](https://discuss.elastic.co/t/metricbeat-e-option-does-not-respect-metricbeat-modules-cpu-metrics-setting/165188 "2019-01-28T15:36:30Z")

</div>

Hi. I'm using ELK stack version 6.5.4 on Windows environment. I tried to automate beats installation using comandline parameters. I noticed that metricbeat does not respect metricbet.modules.cpu.metrics setting. metri…

---

## [How to calculate new fields to be added in filebeat](https://discuss.elastic.co/t/how-to-calculate-new-fields-to-be-added-in-filebeat/165871)

<div class="topic-metadata">

**Author:** [@aalvino](https://discuss.elastic.co/u/aalvino)\
**Replies:** 1\
**Last updated:** [January 28, 2019, 2:07pm UTC](https://discuss.elastic.co/t/how-to-calculate-new-fields-to-be-added-in-filebeat/165871 "2019-01-28T14:07:06Z")

</div>

Hi All, I am relatively new to Elkstack. I am in the process of setting up Elkstack for analysis of my haproxy configuration on Ubuntu machines. I have 6.5.4 versions for Filebeat, Elasticsearch and Kibana. What I ne…

---

## [FTP input](https://discuss.elastic.co/t/ftp-input/165996)

<div class="topic-metadata">

**Author:** [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Replies:** 0\
**Last updated:** [January 28, 2019, 12:13pm UTC](https://discuss.elastic.co/t/ftp-input/165996 "2019-01-28T12:13:55Z")

</div>

Hello, I have FTP access to a server without root and I want to index files arriving to this server through filebeat to logstash. is there a way to do this

---

## [Failed to connect to backoff elasticsearch](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch/165921)

<div class="topic-metadata">

**Author:** [@gleon](https://discuss.elastic.co/u/gleon)\
**Replies:** 0\
**Last updated:** [January 27, 2019, 11:29pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch/165921 "2019-01-27T23:29:19Z")

</div>

Hello all, i'm begginer with ELK and having trouble shipping log events from filebeat to logstash. The scenario consists in: Machine 1) Linux ubuntu 18.04 running oracle virtual box. Machine 2) Linux centos 7 virtuali…

---

## [Auditbeat showing logs that are filtered out](https://discuss.elastic.co/t/auditbeat-showing-logs-that-are-filtered-out/165212)

<div class="topic-metadata">

**Author:** [@arhue](https://discuss.elastic.co/u/arhue)\
**Replies:** 1\
**Last updated:** [January 27, 2019, 4:49pm UTC](https://discuss.elastic.co/t/auditbeat-showing-logs-that-are-filtered-out/165212 "2019-01-27T16:49:08Z")

</div>

Hello, I'm trying to set log monitoring for servers but I can see logs that I have filtered out in Kibana. I want to it to only log entries where auid is between 2000 and 2099(including both). For that I have configured…

---

## [Can what types of logs are taken from winlogbeat](https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885)

<div class="topic-metadata">

**Author:** [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Replies:** 3\
**Last updated:** [January 27, 2019, 4:22pm UTC](https://discuss.elastic.co/t/can-what-types-of-logs-are-taken-from-winlogbeat/163885 "2019-01-27T16:22:51Z")

</div>

I have doubt i have to take logs from one windows machine main criteria is I want a log that has information URL Access and use drive access and print access for that i want use which types of beat either winlogbeat is…

---

## [Winlogbeat.event\_logs adding level causes data to stop flowing into Elasticsearch](https://discuss.elastic.co/t/winlogbeat-event-logs-adding-level-causes-data-to-stop-flowing-into-elasticsearch/160967)

<div class="topic-metadata">

**Author:** [@jeffpool](https://discuss.elastic.co/u/jeffpool)\
**Replies:** 2\
**Last updated:** [January 27, 2019, 4:12pm UTC](https://discuss.elastic.co/t/winlogbeat-event-logs-adding-level-causes-data-to-stop-flowing-into-elasticsearch/160967 "2019-01-27T16:12:48Z")

</div>

When I add level to any name, Application, Security or System, to only get those level events, the connection from the server in question, Windows Server 2008, breaks. Removing the level, and the connection comes back. …

---

## [Change file scan frequency in Winlogbeat](https://discuss.elastic.co/t/change-file-scan-frequency-in-winlogbeat/162950)

<div class="topic-metadata">

**Author:** [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Replies:** 2\
**Last updated:** [January 27, 2019, 3:44pm UTC](https://discuss.elastic.co/t/change-file-scan-frequency-in-winlogbeat/162950 "2019-01-27T15:44:17Z")

</div>

As in filebeat there is an option to change file scan frequency. Can someone please let me know what is for winlogbeat ? Is it "refresh\_frequency:10m" or "rotate\_every\_kb: 10000" ? https://www.elastic.co/guide/en/beats…

---

## [Winlogbeat removes the event\_id of - 4624 and - 4634 in event\_logs, but it is still collected when kibana queries data. What else do you need to set up?](https://discuss.elastic.co/t/winlogbeat-removes-the-event-id-of-4624-and-4634-in-event-logs-but-it-is-still-collected-when-kibana-queries-data-what-else-do-you-need-to-set-up/165160)

<div class="topic-metadata">

**Author:** [@96470621](https://discuss.elastic.co/u/96470621)\
**Replies:** 1\
**Last updated:** [January 27, 2019, 3:40pm UTC](https://discuss.elastic.co/t/winlogbeat-removes-the-event-id-of-4624-and-4634-in-event-logs-but-it-is-still-collected-when-kibana-queries-data-what-else-do-you-need-to-set-up/165160 "2019-01-27T15:40:20Z")

</div>

---

## [Unable to use custom filebeat.yml configuration for kubernetes](https://discuss.elastic.co/t/unable-to-use-custom-filebeat-yml-configuration-for-kubernetes/165879)

<div class="topic-metadata">

**Author:** [@rkumar](https://discuss.elastic.co/u/rkumar)\
**Replies:** 0\
**Last updated:** [January 27, 2019, 5:08am UTC](https://discuss.elastic.co/t/unable-to-use-custom-filebeat-yml-configuration-for-kubernetes/165879 "2019-01-27T05:08:23Z")

</div>

Hi, I am unable to use my custom filebeat.yml using args\["-c","/user/share/filebeat/prospectors.d/default.yml\] in the kubernetes deployment , Following is the logs generated ... {"log":"Exiting: error loading config…

---

## [Data type for filebeat data being ignored](https://discuss.elastic.co/t/data-type-for-filebeat-data-being-ignored/165395)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 0\
**Last updated:** [January 23, 2019, 11:50am UTC](https://discuss.elastic.co/t/data-type-for-filebeat-data-being-ignored/165395 "2019-01-23T11:50:17Z")

</div>

I have data coming in from kubernetes -\> stdout -\> filebeat -\> logstash -\> elastic. Looking at the data in Kibana I see that it doesn't have a recognized type. (IE it's marked with a '?' and can't be searched for a chart…

---

## [Filebeat does not harvest logs](https://discuss.elastic.co/t/filebeat-does-not-harvest-logs/165519)

<div class="topic-metadata">

**Author:** [@alfian](https://discuss.elastic.co/u/alfian)\
**Replies:** 4\
**Last updated:** [January 26, 2019, 6:02am UTC](https://discuss.elastic.co/t/filebeat-does-not-harvest-logs/165519 "2019-01-26T06:02:02Z")

</div>

I have deploy filebeat in kubernetes as daemon set (the node is ubuntu 18.04), but some of the filebeat pod do not send any log, it did not harvest any log. What might cause this? This is my filebeat configuration: ---…

---

## [Filebeat version 6.3.\* (amd64), libbeat 6.3.\* unable to resolve DNS lookups for downstream hosts after restarting](https://discuss.elastic.co/t/filebeat-version-6-3-amd64-libbeat-6-3-unable-to-resolve-dns-lookups-for-downstream-hosts-after-restarting/165817)

<div class="topic-metadata">

**Author:** [@esmith](https://discuss.elastic.co/u/esmith)\
**Replies:** 0\
**Last updated:** [January 25, 2019, 7:11pm UTC](https://discuss.elastic.co/t/filebeat-version-6-3-amd64-libbeat-6-3-unable-to-resolve-dns-lookups-for-downstream-hosts-after-restarting/165817 "2019-01-25T19:11:28Z")

</div>

Currently seeing an issue on linux hosts running filebeat 6.3.\* in which filebeat, if stopped and restarted for any reason, is no longer able to resolve dns lookups for downstream hosts such as elasticsearch, etc. I am …

---

## [Parsing JSON with filebeat](https://discuss.elastic.co/t/parsing-json-with-filebeat/165489)

<div class="topic-metadata">

**Author:** [@bladerunner512](https://discuss.elastic.co/u/bladerunner512)\
**Replies:** 1\
**Last updated:** [January 25, 2019, 5:34pm UTC](https://discuss.elastic.co/t/parsing-json-with-filebeat/165489 "2019-01-25T17:34:11Z")

</div>

Trying to ship single-line JSON in log file directly to Elasticsearch, but getting entire line with "message" as key: January 23rd 2019, 15:51:15.634 @timestamp:January 23rd 2019, 15:51:15.634 source:/usr/share/filebe…

---

## [Metricbeat is unable to send data to elastic search](https://discuss.elastic.co/t/metricbeat-is-unable-to-send-data-to-elastic-search/165787)

<div class="topic-metadata">

**Author:** [@chethan\_sarathy](https://discuss.elastic.co/u/chethan_sarathy)\
**Replies:** 3\
**Last updated:** [January 25, 2019, 5:22pm UTC](https://discuss.elastic.co/t/metricbeat-is-unable-to-send-data-to-elastic-search/165787 "2019-01-25T17:22:29Z")

</div>

Hello, I have setup Elasticsearch and Kibana in a VM and then started setting up metricbeat. Elasticsearch & Kibana is working fine. But I am unable to send metricbeat data to elastic search. Once I start running metri…

---

## [Debian 7.9 Filebeat 6.5.4 wrong path](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261)

<div class="topic-metadata">

**Author:** [@Abraxas](https://discuss.elastic.co/u/Abraxas)\
**Replies:** 8\
**Last updated:** [January 25, 2019, 3:30pm UTC](https://discuss.elastic.co/t/debian-7-9-filebeat-6-5-4-wrong-path/165261 "2019-01-25T15:30:52Z")

</div>

Hi, I am running Debian 7.9 and I have installed filebeat 6.5.4 with apt-get. For some reason it starts with wrong paths: INFO instance/beat.go:592 Home path: \[/usr/share/filebeat/bin\] Config path: \[/usr/share/f…

---

## [Journalbeat writes registry file to /registry instead of /var/lib/journalbeat/registry](https://discuss.elastic.co/t/journalbeat-writes-registry-file-to-registry-instead-of-var-lib-journalbeat-registry/165744)

<div class="topic-metadata">

**Author:** [@SpComb](https://discuss.elastic.co/u/SpComb)\
**Replies:** 2\
**Last updated:** [January 25, 2019, 12:47pm UTC](https://discuss.elastic.co/t/journalbeat-writes-registry-file-to-registry-instead-of-var-lib-journalbeat-registry/165744 "2019-01-25T12:47:26Z")

</div>

I encountered the following error when trying to reconfigure journalbeat to run as non-root, even though the journalbeat user has write permissions to /var/lib/journalbeat: 2019-01-25T09:55:07.494Z ERROR instance/beat.g…

---

## [Multiple Logstash IPs in Filebeat](https://discuss.elastic.co/t/multiple-logstash-ips-in-filebeat/165716)

<div class="topic-metadata">

**Author:** [@Harsh\_Sharma](https://discuss.elastic.co/u/Harsh_Sharma)\
**Replies:** 1\
**Last updated:** [January 25, 2019, 12:38pm UTC](https://discuss.elastic.co/t/multiple-logstash-ips-in-filebeat/165716 "2019-01-25T12:38:05Z")

</div>

Hello, I'm using ELK 6.5.4. I have 3 logstash server (10.5.2.1, 10.5.2.2, 10.5.2.3) and a LB (10.5.1.1) on these 3 logstash server. Now in filebeat Logstash output instead of providing LB ip could I mention all the 3 I…

---

## [Wrong path.data and path.logs for filebeat windows in installation script](https://discuss.elastic.co/t/wrong-path-data-and-path-logs-for-filebeat-windows-in-installation-script/164499)

<div class="topic-metadata">

**Author:** [@dennis\_ukhanov](https://discuss.elastic.co/u/dennis_ukhanov)\
**Replies:** 2\
**Last updated:** [January 25, 2019, 12:30pm UTC](https://discuss.elastic.co/t/wrong-path-data-and-path-logs-for-filebeat-windows-in-installation-script/164499 "2019-01-25T12:30:52Z")

</div>

I believe Windows PowerShell script install-service-filebeat.ps1contains wrong path for data and logs folder. On my Windows Server 2012R2 I see"C:\\ProgramData\\filebeat"and"C:\\ProgramData\\filebeat\\logs"respectively so ser…

---

## [After reboot EC2 instance, Filebeat cannot send log to logstash: ERROR	logstash/async.go:256	Failed to publish events caused by: write tcp 127.0.0.1:52242-\>127.0.0.1:5043: write: connection reset by peer](https://discuss.elastic.co/t/after-reboot-ec2-instance-filebeat-cannot-send-log-to-logstash-error-logstash-async-go-256-failed-to-publish-events-caused-by-write-tcp-127-0-0-1-52242-127-0-0-1-write-connection-reset-by-peer/165648)

<div class="topic-metadata">

**Author:** [@fuwei1234](https://discuss.elastic.co/u/fuwei1234)\
**Replies:** 1\
**Last updated:** [January 25, 2019, 12:19pm UTC](https://discuss.elastic.co/t/after-reboot-ec2-instance-filebeat-cannot-send-log-to-logstash-error-logstash-async-go-256-failed-to-publish-events-caused-by-write-tcp-127-0-0-1-52242-127-0-0-1-write-connection-reset-by-peer/165648 "2019-01-25T12:19:30Z")

</div>

After I reboot EC2, filebeat can no longer send log to logstash, I change port from 5044 to 5043 and filebeat has this error. 019-01-24T19:01:48.060Z INFO pipeline/output.go:95 Connecting to backoff(async(tcp://0.0.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=385)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=387)
