# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=387

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 388

---

## [Metricbeat build size](https://discuss.elastic.co/t/metricbeat-build-size/165307)

<div class="topic-metadata">

**Author:** [@bering](https://discuss.elastic.co/u/bering)\
**Replies:** 1\
**Last updated:** [January 25, 2019, 11:26am UTC](https://discuss.elastic.co/t/metricbeat-build-size/165307 "2019-01-25T11:26:57Z")

</div>

I have built metricbeat.exe (version 6.5.4) from the x-pack directory x-pack/metricbeat. I have added a single extra custom module, and the build filesize is 60.534KB, the metricbeat.exe that i can download from elastic…

---

## [Cannot see logs in Elasticsearch configured through Filebeat](https://discuss.elastic.co/t/cannot-see-logs-in-elasticsearch-configured-through-filebeat/165314)

<div class="topic-metadata">

**Author:** [@huzefabootwala](https://discuss.elastic.co/u/huzefabootwala)\
**Replies:** 3\
**Last updated:** [January 25, 2019, 3:27am UTC](https://discuss.elastic.co/t/cannot-see-logs-in-elasticsearch-configured-through-filebeat/165314 "2019-01-25T03:27:55Z")

</div>

Hello, I have installed Elasticsearch, Kibana and Filebeat but not able to see the logs. These are filebeat logs 2019-01-23T10:07:49.740+1100 INFO instance/beat.go:592 Home path: \[C:\\Users\\hbootwala\\Downloads\\filebeat…

---

## ["Panic" when ignoring SSL Errors with Heartbeat](https://discuss.elastic.co/t/panic-when-ignoring-ssl-errors-with-heartbeat/165559)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 1\
**Last updated:** [January 24, 2019, 2:49pm UTC](https://discuss.elastic.co/t/panic-when-ignoring-ssl-errors-with-heartbeat/165559 "2019-01-24T14:49:24Z")

</div>

We wish to monitor a HTTPS endpoint with Heartbeat but without having a valid signed SSL certificate. Thus we have set ssl.verification\_mode: none but the system is marked as "down". Configuration: heartbeat.monitors:…

---

## [Central Management: output module](https://discuss.elastic.co/t/central-management-output-module/165358)

<div class="topic-metadata">

**Author:** [@kaem2111](https://discuss.elastic.co/u/kaem2111)\
**Replies:** 3\
**Last updated:** [January 24, 2019, 1:49pm UTC](https://discuss.elastic.co/t/central-management-output-module/165358 "2019-01-24T13:49:47Z")

</div>

Hello, I want to configure the following output using beat central management: output: elasticsearch: hosts: \["5.5.5.5"\] username: "user" password: "psw" pipeline: "metricbeat\_enrich" protocol: ht…

---

## [Input multiline JSON?](https://discuss.elastic.co/t/input-multiline-json/165287)

<div class="topic-metadata">

**Author:** [@Jan\_Rodriguez\_Quabu](https://discuss.elastic.co/u/Jan_Rodriguez_Quabu)\
**Replies:** 3\
**Last updated:** [January 24, 2019, 1:36pm UTC](https://discuss.elastic.co/t/input-multiline-json/165287 "2019-01-24T13:36:10Z")

</div>

Hello! I have the following JSON file and I send it to an Amazon Elasticsearch Service using FIlebeat, but Elasticsearch isn't capable to index it properly. { "scan": { "id\_scan": "2019-01-22 19:00:35", "files": \[…

---

## [How to read CPU usage, RAM usage and Disk usage using filebeat?](https://discuss.elastic.co/t/how-to-read-cpu-usage-ram-usage-and-disk-usage-using-filebeat/165561)

<div class="topic-metadata">

**Author:** [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Replies:** 10\
**Last updated:** [January 24, 2019, 12:30pm UTC](https://discuss.elastic.co/t/how-to-read-cpu-usage-ram-usage-and-disk-usage-using-filebeat/165561 "2019-01-24T12:30:31Z")

</div>

I am using filebeat, ELK stack. I want to get CPU, RAM, and Disk usage information using filebeat and send it to logstash to elasticsearch to kibana. Version of ELK stack is:- filebeat 6.5.4 ELK 5.6.4 Any body have an…

---

## [Parse log data in filebeat/elasticsearch](https://discuss.elastic.co/t/parse-log-data-in-filebeat-elasticsearch/165602)

<div class="topic-metadata">

**Author:** [@Amrutha\_Kapa](https://discuss.elastic.co/u/Amrutha_Kapa)\
**Replies:** 0\
**Last updated:** [January 24, 2019, 12:26pm UTC](https://discuss.elastic.co/t/parse-log-data-in-filebeat-elasticsearch/165602 "2019-01-24T12:26:40Z")

</div>

I'm having a log as below: 17:40:51.3788 Info {"message":"#ARKAD","level":"Information","timeStamp":"2019-01-21T17:40:51.3878224+05:30","fingerprint":"125722b8-f281-47a6-8bf6-742f3bb111f3","windowsIdentity":"DESKTOP-OP9…

---

## [How to drop multiple message names using filebeat](https://discuss.elastic.co/t/how-to-drop-multiple-message-names-using-filebeat/165551)

<div class="topic-metadata">

**Author:** [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Replies:** 9\
**Last updated:** [January 24, 2019, 12:06pm UTC](https://discuss.elastic.co/t/how-to-drop-multiple-message-names-using-filebeat/165551 "2019-01-24T12:06:18Z")

</div>

Hi, Please some one help me how to drop lines using filebeat. My code is, processors: - drop\_event: when: contains: message: \["AbstractLoggingWriter", "WARN"\] and processors: - drop…

---

## [Can nginx.access.url filed be separated to sub filed?](https://discuss.elastic.co/t/can-nginx-access-url-filed-be-separated-to-sub-filed/165541)

<div class="topic-metadata">

**Author:** [@Steven\_Shi](https://discuss.elastic.co/u/Steven_Shi)\
**Replies:** 0\
**Last updated:** [January 24, 2019, 7:31am UTC](https://discuss.elastic.co/t/can-nginx-access-url-filed-be-separated-to-sub-filed/165541 "2019-01-24T07:31:00Z")

</div>

nginx.access.url is a single filed, can it be separated anymore? eg, like the filed '/api/xxx?id=123&gender=male&age=23', can it be separated to $id, $gender and $age ? Version: ElasticSearch=6.5.4 Kibana=6.5.4 File…

---

## [Geoip Ingest with Elastic Cloud](https://discuss.elastic.co/t/geoip-ingest-with-elastic-cloud/165521)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 3\
**Last updated:** [January 24, 2019, 4:17am UTC](https://discuss.elastic.co/t/geoip-ingest-with-elastic-cloud/165521 "2019-01-24T04:17:22Z")

</div>

According to https://www.elastic.co/guide/en/beats/packetbeat/master/packetbeat-geoip.html It is trivial to configure the Geo-IP ingestion for an Elasticsearch output, however from the document it is not clear how this …

---

## [Beats build artifact lifetimes](https://discuss.elastic.co/t/beats-build-artifact-lifetimes/165520)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 0\
**Last updated:** [January 24, 2019, 2:36am UTC](https://discuss.elastic.co/t/beats-build-artifact-lifetimes/165520 "2019-01-24T02:36:47Z")

</div>

Hi Folks, I am using the arm beats nightlies from Jenkins / Google Cloud storage for some docker containers and when I rebuilt one the other day the resource had moved. I am wondering if I need to copy the packages to…

---

## [Are we able to monitor if a process is running or not using metricbeat?](https://discuss.elastic.co/t/are-we-able-to-monitor-if-a-process-is-running-or-not-using-metricbeat/165442)

<div class="topic-metadata">

**Author:** [@vshankara](https://discuss.elastic.co/u/vshankara)\
**Replies:** 1\
**Last updated:** [January 24, 2019, 2:33am UTC](https://discuss.elastic.co/t/are-we-able-to-monitor-if-a-process-is-running-or-not-using-metricbeat/165442 "2019-01-24T02:33:34Z")

</div>

Are we able to monitor if a process is running or not using metricbeat?

---

## [Metricbeat data size](https://discuss.elastic.co/t/metricbeat-data-size/165515)

<div class="topic-metadata">

**Author:** [@neven.trelec](https://discuss.elastic.co/u/neven.trelec)\
**Replies:** 1\
**Last updated:** [January 24, 2019, 2:26am UTC](https://discuss.elastic.co/t/metricbeat-data-size/165515 "2019-01-24T02:26:25Z")

</div>

Hello, we have setup metricbeat to collect the data from various VMs in our system and we have noticed that metricbeat data size vary significantly accross our VMs. This came as a bit of surprise to us since metricbeat …

---

## [Filebeat auditd logs without Geoip plugin?](https://discuss.elastic.co/t/filebeat-auditd-logs-without-geoip-plugin/165488)

<div class="topic-metadata">

**Author:** [@Jeeppler](https://discuss.elastic.co/u/Jeeppler)\
**Replies:** 0\
**Last updated:** [January 23, 2019, 9:37pm UTC](https://discuss.elastic.co/t/filebeat-auditd-logs-without-geoip-plugin/165488 "2019-01-23T21:37:05Z")

</div>

The AWS ElasticSearch service does not support the ingest-geoip plugin according to their documentation. Is there a way to use the auditd module without the ingest-geoip plugin?

---

## [Metricbeat Error while enrolling: fail to execute the HTTP POST request: Post https://kibana](https://discuss.elastic.co/t/metricbeat-error-while-enrolling-fail-to-execute-the-http-post-request-post-https-kibana/162979)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 2\
**Last updated:** [January 23, 2019, 2:27pm UTC](https://discuss.elastic.co/t/metricbeat-error-while-enrolling-fail-to-execute-the-http-post-request-post-https-kibana/162979 "2019-01-23T14:27:03Z")

</div>

Elasticsearch 6.5.1 XPack enabled, TLS/SSL encryption enabled Setup: Metricbeat--\>Logstash--\>Elasticsearch\<--Kibana I've been trying to enroll a metricbeat on a Windows Server 2016 box through the Central Managaement …

---

## [Unable to exclude\_lines in filebeat](https://discuss.elastic.co/t/unable-to-exclude-lines-in-filebeat/165215)

<div class="topic-metadata">

**Author:** [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Replies:** 21\
**Last updated:** [January 23, 2019, 1:20pm UTC](https://discuss.elastic.co/t/unable-to-exclude-lines-in-filebeat/165215 "2019-01-23T13:20:51Z")

</div>

@warkolm Hi. My log line is 2019-01-22 10:25:01,401 ERROR stderr org.jboss.stdio.AbstractLoggingWriter.write(AbstractLoggingWriter.java:71) - URI: urn:pronto.ver600 2019-01-22 10:25:01,401 ERROR stderr org.jboss.stdi…

---

## [Exclude\_lines are not working in my filebeat](https://discuss.elastic.co/t/exclude-lines-are-not-working-in-my-filebeat/165344)

<div class="topic-metadata">

**Author:** [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Replies:** 2\
**Last updated:** [January 23, 2019, 12:27pm UTC](https://discuss.elastic.co/t/exclude-lines-are-not-working-in-my-filebeat/165344 "2019-01-23T12:27:22Z")

</div>

Hi , My filebeat.yml file is filebeat.prospectors: input\_type: log paths: /u04/jboss/standalone/log/server.log /var/log/soapradius.log /var/log/radius.log exclude\_lines: \['^.AbstractLoggingWriter.write…

---

## [Config file needs to be owned by root or beat user. Best practice?](https://discuss.elastic.co/t/config-file-needs-to-be-owned-by-root-or-beat-user-best-practice/165385)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [January 23, 2019, 12:23pm UTC](https://discuss.elastic.co/t/config-file-needs-to-be-owned-by-root-or-beat-user-best-practice/165385 "2019-01-23T12:23:26Z")

</div>

Hi there, I am trying out filebeat on docker, running my dev instance containerized. For developing logstash pipelines I thought I instanciate just a full stack single instance and use a filebeat container to restart e…

---

## [Help on showing Custom File beat Module Fields in Kibana](https://discuss.elastic.co/t/help-on-showing-custom-file-beat-module-fields-in-kibana/161351)

<div class="topic-metadata">

**Author:** [@CoreyF](https://discuss.elastic.co/u/CoreyF)\
**Replies:** 3\
**Last updated:** [January 23, 2019, 11:44am UTC](https://discuss.elastic.co/t/help-on-showing-custom-file-beat-module-fields-in-kibana/161351 "2019-01-23T11:44:00Z")

</div>

Hello, I have created a custom File Beat Module using Creating a New Beat. The data is making it to Elasticsearch and I can see it under the “Discover” Tab in Kibana. In Kibana -\> Visualize -\> Visual Builder -\> Time Ser…

---

## [Once in a while, filebeat lost first charactor while collect log](https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982)

<div class="topic-metadata">

**Author:** [@guisong](https://discuss.elastic.co/u/guisong)\
**Replies:** 3\
**Last updated:** [January 23, 2019, 11:34am UTC](https://discuss.elastic.co/t/once-in-a-while-filebeat-lost-first-charactor-while-collect-log/164982 "2019-01-23T11:34:25Z")

</div>

Once in a while, filebeat lost first charactor while collect log,for example,message start with timestamp string,but it lost some charactors when I get message from elasticsearch. In fact message is start with string …

---

## [UseCase of Apache Metrics.Explain?](https://discuss.elastic.co/t/usecase-of-apache-metrics-explain/165048)

<div class="topic-metadata">

**Author:** [@Bhavesh\_Padharia](https://discuss.elastic.co/u/Bhavesh_Padharia)\
**Replies:** 2\
**Last updated:** [January 23, 2019, 10:49am UTC](https://discuss.elastic.co/t/usecase-of-apache-metrics-explain/165048 "2019-01-23T10:49:49Z")

</div>

Hello please explain me Use Case of Apache Metric.

---

## [Filebeat ignore harvest JSON file](https://discuss.elastic.co/t/filebeat-ignore-harvest-json-file/165163)

<div class="topic-metadata">

**Author:** [@Marek\_Pastier](https://discuss.elastic.co/u/Marek_Pastier)\
**Replies:** 2\
**Last updated:** [January 23, 2019, 7:26am UTC](https://discuss.elastic.co/t/filebeat-ignore-harvest-json-file/165163 "2019-01-23T07:26:36Z")

</div>

Hi guys My configuration for Filebeat ver 6.5 ignore harvesting json log file. My actual configuration /etc/filebeat/filebeat.yml filebeat.inputs: type: log json.keys\_under\_root: true json.add\_error\_key: true pat…

---

## [Filebeat ignoring recursive globs](https://discuss.elastic.co/t/filebeat-ignoring-recursive-globs/165146)

<div class="topic-metadata">

**Author:** [@SpeedyXeon](https://discuss.elastic.co/u/SpeedyXeon)\
**Replies:** 2\
**Last updated:** [January 23, 2019, 5:12am UTC](https://discuss.elastic.co/t/filebeat-ignoring-recursive-globs/165146 "2019-01-23T05:12:22Z")

</div>

Hi, I configured my prospector to use recursive globs, but filebeat is ignoring the configuration and exiting with the error below: Error in initing prospector: Failed to resolve recursive globs in config: multiple \*\*…

---

## [Autodiscover and metadata](https://discuss.elastic.co/t/autodiscover-and-metadata/162980)

<div class="topic-metadata">

**Author:** [@Eric\_Duquesnoy](https://discuss.elastic.co/u/Eric_Duquesnoy)\
**Replies:** 4\
**Last updated:** [January 22, 2019, 6:42pm UTC](https://discuss.elastic.co/t/autodiscover-and-metadata/162980 "2019-01-22T18:42:13Z")

</div>

Hi , I've just tried the new version of Heartbeat (6.5.4) and specifically the autodiscover feature with Docker. For the POC , I launched a Redis and Nginx container along with heartbeat (installed like a linux service…

---

## [Document other than log files](https://discuss.elastic.co/t/document-other-than-log-files/165234)

<div class="topic-metadata">

**Author:** [@Gokulprasath\_Narayan](https://discuss.elastic.co/u/Gokulprasath_Narayan)\
**Replies:** 1\
**Last updated:** [January 22, 2019, 3:58pm UTC](https://discuss.elastic.co/t/document-other-than-log-files/165234 "2019-01-22T15:58:15Z")

</div>

I want to push all the files having different format(doc,csv..) in a directory to elastic. My final ouptut should be the name of the file having the search text. can anyone help.

---

## [Prevent inclusion of Authorization header](https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917)

<div class="topic-metadata">

**Author:** [@Michael\_Daly](https://discuss.elastic.co/u/Michael_Daly)\
**Replies:** 3\
**Last updated:** [January 22, 2019, 3:51pm UTC](https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917 "2019-01-22T15:51:14Z")

</div>

To get FileBeat working with AWS ES, the Authorization http header must not be included in the http request. How can I prevent FileBeat sending a basic auth header? Setting -E output.elasticsearch.username="" -E output…

---

## [Exporting Only Part of a Message](https://discuss.elastic.co/t/exporting-only-part-of-a-message/165150)

<div class="topic-metadata">

**Author:** [@seth.yes](https://discuss.elastic.co/u/seth.yes)\
**Replies:** 2\
**Last updated:** [January 22, 2019, 3:50pm UTC](https://discuss.elastic.co/t/exporting-only-part-of-a-message/165150 "2019-01-22T15:50:00Z")

</div>

I am looking to use Filebeat 6.5 to only export only the json of a log message. Current unrelated issues disallow me from modifying the way the raw message is formatted, nor the way the data is processed or indexed once …

---

## [Create logging Index without filebeat](https://discuss.elastic.co/t/create-logging-index-without-filebeat/162820)

<div class="topic-metadata">

**Author:** [@Marc\_Fielding](https://discuss.elastic.co/u/Marc_Fielding)\
**Replies:** 2\
**Last updated:** [January 22, 2019, 3:39pm UTC](https://discuss.elastic.co/t/create-logging-index-without-filebeat/162820 "2019-01-22T15:39:21Z")

</div>

Happy New Year, So quick question, currently I'm pushing out AWS Cloudwatch logs to an index in my ES cluster - these logs have index pattern of cwl-\* I noticed in the new version of Kibana there's a "Logs" section but…

---

## [Filebeat multiline is not working as expected](https://discuss.elastic.co/t/filebeat-multiline-is-not-working-as-expected/165033)

<div class="topic-metadata">

**Author:** [@Abu\_Tahir](https://discuss.elastic.co/u/Abu_Tahir)\
**Replies:** 2\
**Last updated:** [January 22, 2019, 3:36pm UTC](https://discuss.elastic.co/t/filebeat-multiline-is-not-working-as-expected/165033 "2019-01-22T15:36:54Z")

</div>

The below set of lines are my test log \[2016-08-24 11:49:14,389\] Started new event \[2016-08-24 11:49:14,395\] Content of processing something \[2016-08-24 11:49:14,399\] End event \[2016-08-24 11:49:14,389\] Started new even…

---

## [Mapper\_parsing\_exception, hashicorp vault audit, "error" in inner json](https://discuss.elastic.co/t/mapper-parsing-exception-hashicorp-vault-audit-error-in-inner-json/165119)

<div class="topic-metadata">

**Author:** [@mkohns](https://discuss.elastic.co/u/mkohns)\
**Replies:** 1\
**Last updated:** [January 22, 2019, 3:30pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-hashicorp-vault-audit-error-in-inner-json/165119 "2019-01-22T15:30:47Z")

</div>

Hi! Following Setup: -\> Docker 18.09 -\> Filebeat 6.4.1 running in container with docker sock mounted -\> Hashicorp Vault running in container with audit enabled -\> extract from filebeat.yml ... filebeat.autodiscover…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=386)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=388)
