# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=388

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 389

---

## [Filebeat Dynamic matching key field](https://discuss.elastic.co/t/filebeat-dynamic-matching-key-field/164919)

<div class="topic-metadata">

**Author:** [@fengxiaoH](https://discuss.elastic.co/u/fengxiaoH)\
**Replies:** 1\
**Last updated:** [January 22, 2019, 11:37am UTC](https://discuss.elastic.co/t/filebeat-dynamic-matching-key-field/164919 "2019-01-22T11:37:06Z")

</div>

My configuration： ## The input config filebeat.inputs: - type: log enabled: true paths: - /data/logs\_backup/baccarat/gate/gate.log fields: document\_type: baccarat\_gatelog fields\_under\_root: true - type:…

---

## [Filebeat cipher configurations](https://discuss.elastic.co/t/filebeat-cipher-configurations/164995)

<div class="topic-metadata">

**Author:** [@Madhan1911](https://discuss.elastic.co/u/Madhan1911)\
**Replies:** 3\
**Last updated:** [January 22, 2019, 11:24am UTC](https://discuss.elastic.co/t/filebeat-cipher-configurations/164995 "2019-01-22T11:24:04Z")

</div>

ssl.cipher\_suites: \[RSA-AES-128-CBC-SHA, RSA-AES-256-CBC-SHA , ECDHE-ECDSA-AES-128-CBC-SHA, ECDHE-ECDSA-AES-256-CBC-SHA, ECDHE-RSA-AES-128-CBC-SHA, ECDHE-RSA-AES-256-CBC-SHA, ECDHE-RSA-AES-128-GCM-SHA256, ECDHE-ECDSA-AES…

---

## [Central Management output to Elasticsearch](https://discuss.elastic.co/t/central-management-output-to-elasticsearch/162660)

<div class="topic-metadata">

**Author:** [@Rasmus\_Fredensborg\_J](https://discuss.elastic.co/u/Rasmus_Fredensborg_J)\
**Replies:** 6\
**Last updated:** [January 22, 2019, 11:18am UTC](https://discuss.elastic.co/t/central-management-output-to-elasticsearch/162660 "2019-01-22T11:18:39Z")

</div>

Hi, Thank you for your amazing products. I just started using Central management for beats and got everything working except for output to Elasticsearch cloud. I looked at this issue but it doesn't seem to be related to…

---

## [Metricbeat fails to communicate with kubelet](https://discuss.elastic.co/t/metricbeat-fails-to-communicate-with-kubelet/164806)

<div class="topic-metadata">

**Author:** [@hohooss](https://discuss.elastic.co/u/hohooss)\
**Replies:** 1\
**Last updated:** [January 22, 2019, 9:42am UTC](https://discuss.elastic.co/t/metricbeat-fails-to-communicate-with-kubelet/164806 "2019-01-22T09:42:34Z")

</div>

Hello, I installed the metricbeat (daemonset) on kubernetes by applying the YAML files. The metricbeat PODs were installed successfully, but there is a communication issue between metricbeat and kubelet due to certific…

---

## [Strange encoding issue each day. Need help to analyze it](https://discuss.elastic.co/t/strange-encoding-issue-each-day-need-help-to-analyze-it/164299)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [January 22, 2019, 8:27am UTC](https://discuss.elastic.co/t/strange-encoding-issue-each-day-need-help-to-analyze-it/164299 "2019-01-22T08:27:56Z")

</div>

Hi all, we are shipping logs using following route: logfile \<- filebeat -\> redis \<- logstash -\> elasticsearch \<- kibana Using filebeat 6.5.2 on windows 2012 R1. Filebeat is installed as service. Each day at about 23:…

---

## [Not receiving correct info about services: "The system cannot find the file specified"](https://discuss.elastic.co/t/not-receiving-correct-info-about-services-the-system-cannot-find-the-file-specified/164331)

<div class="topic-metadata">

**Author:** [@martink](https://discuss.elastic.co/u/martink)\
**Replies:** 15\
**Last updated:** [January 22, 2019, 7:06am UTC](https://discuss.elastic.co/t/not-receiving-correct-info-about-services-the-system-cannot-find-the-file-specified/164331 "2019-01-22T07:06:50Z")

</div>

I found this topic from december last year, but it was closed without answer (auto). I have a similar issue: I recently started using the ELK-Stack and now I want to use metricbeat/windows/service to get "heartbeats" fro…

---

## [Error in initing input Filebeat](https://discuss.elastic.co/t/error-in-initing-input-filebeat/163840)

<div class="topic-metadata">

**Author:** [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Replies:** 11\
**Last updated:** [January 22, 2019, 6:43am UTC](https://discuss.elastic.co/t/error-in-initing-input-filebeat/163840 "2019-01-22T06:43:41Z")

</div>

Dear All, Please help me to solve this issue Error bash-4.2$ ./filebeat test config -c filebeat.yml Config OK bash-4.2$ ./filebeat Exiting: Error in initing input: can not convert 'string' into 'bool' accessing 'fi…

---

## [Installing Packetbeat](https://discuss.elastic.co/t/installing-packetbeat/165144)

<div class="topic-metadata">

**Author:** [@daniel.rocha](https://discuss.elastic.co/u/daniel.rocha)\
**Replies:** 1\
**Last updated:** [January 22, 2019, 5:30am UTC](https://discuss.elastic.co/t/installing-packetbeat/165144 "2019-01-22T05:30:08Z")

</div>

I am having trouble getting Packetbeat to install on Kibana. I have gone through the video provided on how to do it, however due to the path information being different I am having a hard time finding out the equivalent.…

---

## [Failed to Import Metricbeat Dashboards](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896)

<div class="topic-metadata">

**Author:** [@SSIDDIQUI](https://discuss.elastic.co/u/SSIDDIQUI)\
**Replies:** 6\
**Last updated:** [January 22, 2019, 4:17am UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896 "2019-01-22T04:17:23Z")

</div>

Hi All, I'm new to ELK and was not involved with the installation of ELK. The delete\_indices.yml script ended up deleting the main .kibana index file which wiped out the dashboards. Once I gave the server a reboot some …

---

## [Support Needed on Metricbeat setup issue](https://discuss.elastic.co/t/support-needed-on-metricbeat-setup-issue/162748)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 31\
**Last updated:** [January 22, 2019, 3:40am UTC](https://discuss.elastic.co/t/support-needed-on-metricbeat-setup-issue/162748 "2019-01-22T03:40:46Z")

</div>

Hi all, below is my metricbeat.yml file. Error msg when running "metricbeat setup": Did not find expected key. \` ###################### Metricbeat Configuration Example ####################### # This file is an e…

---

## [Filebeats deployed inside kubernetes can fetch logs from host containers? (containers outside k8s)](https://discuss.elastic.co/t/filebeats-deployed-inside-kubernetes-can-fetch-logs-from-host-containers-containers-outside-k8s/165072)

<div class="topic-metadata">

**Author:** [@pabloborh](https://discuss.elastic.co/u/pabloborh)\
**Replies:** 1\
**Last updated:** [January 21, 2019, 4:30pm UTC](https://discuss.elastic.co/t/filebeats-deployed-inside-kubernetes-can-fetch-logs-from-host-containers-containers-outside-k8s/165072 "2019-01-21T16:30:47Z")

</div>

I have a filebeats deployed inside kubernetes cluster. I want fetch logs from containers running in k8s node hosts but deployed outside kubernetes. I have the standard filebeats config for kubernetes where it should fet…

---

## [Problem with setting up the kibana dashboards on remote server](https://discuss.elastic.co/t/problem-with-setting-up-the-kibana-dashboards-on-remote-server/165054)

<div class="topic-metadata">

**Author:** [@Alex\_ne](https://discuss.elastic.co/u/Alex_ne)\
**Replies:** 1\
**Last updated:** [January 21, 2019, 2:06pm UTC](https://discuss.elastic.co/t/problem-with-setting-up-the-kibana-dashboards-on-remote-server/165054 "2019-01-21T14:06:40Z")

</div>

Hi all, As I recently started to use ES, I had the following problem: On one server the Elasticsearch and Packetbeat are installed and I have locally installed Kibana on a laptop for creating visualizations. When I tr…

---

## [Config Path](https://discuss.elastic.co/t/config-path/164773)

<div class="topic-metadata">

**Author:** [@mylyo](https://discuss.elastic.co/u/mylyo)\
**Replies:** 13\
**Last updated:** [January 21, 2019, 12:21pm UTC](https://discuss.elastic.co/t/config-path/164773 "2019-01-21T12:21:39Z")

</div>

Hi, As begginner at Elastic, iam tryning to install Elastic stack on my machine (Mac IOS). Actually i have a problem with Filebeat. i am trying to add a new index via Filebeat. Config is ok but when i run it i have alw…

---

## [Filebeat error write:connection reset by peer](https://discuss.elastic.co/t/filebeat-error-write-connection-reset-by-peer/164782)

<div class="topic-metadata">

**Author:** [@kvaga](https://discuss.elastic.co/u/kvaga)\
**Replies:** 14\
**Last updated:** [January 21, 2019, 11:26am UTC](https://discuss.elastic.co/t/filebeat-error-write-connection-reset-by-peer/164782 "2019-01-21T11:26:11Z")

</div>

client - filebeat-6.5.4-1.x86\_64 Log - logstash-6.5.4-1.noarch logs from client 2019-01-18T13:56:20.033+0300 ERROR logstash/async.go:256 Failed to publish events caused by: write tcp 10.129.10.8:34714-\>10.129.1…

---

## [Parse host url error docker event](https://discuss.elastic.co/t/parse-host-url-error-docker-event/164127)

<div class="topic-metadata">

**Author:** [@ncasaux](https://discuss.elastic.co/u/ncasaux)\
**Replies:** 4\
**Last updated:** [January 18, 2019, 3:41pm UTC](https://discuss.elastic.co/t/parse-host-url-error-docker-event/164127 "2019-01-18T15:41:25Z")

</div>

Hello, I try to use Metricbeat with the autodiscover feature for docker, with following config Metricbeat.yml: output.elasticsearch: hosts: \["elasticsearch:9200"\] setup.template.name: "metricbeat" setup.template.se…

---

## ["Task" field from event viewer is not parsed into elasticsearch](https://discuss.elastic.co/t/task-field-from-event-viewer-is-not-parsed-into-elasticsearch/162259)

<div class="topic-metadata">

**Author:** [@saravanan\_palanivel](https://discuss.elastic.co/u/saravanan_palanivel)\
**Replies:** 5\
**Last updated:** [January 21, 2019, 7:06am UTC](https://discuss.elastic.co/t/task-field-from-event-viewer-is-not-parsed-into-elasticsearch/162259 "2019-01-21T07:06:28Z")

</div>

Hi, We are trying to use "Winlogbeat" with output into Elasticsearch. We are almost successful in getting most of the fields from event viewer to elasticsearch, but except "Task". Even though 'Task' has value in Window…

---

## [Santa Module](https://discuss.elastic.co/t/santa-module/164861)

<div class="topic-metadata">

**Author:** [@rpsing](https://discuss.elastic.co/u/rpsing)\
**Replies:** 2\
**Last updated:** [January 20, 2019, 5:25pm UTC](https://discuss.elastic.co/t/santa-module/164861 "2019-01-20T17:25:28Z")

</div>

I see that the documentation references filebeat supporting the santa module (https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-santa.html#configuring-santa-module) but the latest version of filebeat …

---

## [Metricbeat inside docker provides correct Total CPU/RAM, but incorrect process top N](https://discuss.elastic.co/t/metricbeat-inside-docker-provides-correct-total-cpu-ram-but-incorrect-process-top-n/164939)

<div class="topic-metadata">

**Author:** [@Dmitriy\_Baskakov](https://discuss.elastic.co/u/Dmitriy_Baskakov)\
**Replies:** 0\
**Last updated:** [January 20, 2019, 12:52pm UTC](https://discuss.elastic.co/t/metricbeat-inside-docker-provides-correct-total-cpu-ram-but-incorrect-process-top-n/164939 "2019-01-20T12:52:30Z")

</div>

I run metricbeat 6.5.4 inside docker container using docker-compose. I use default configuration from docs: metricbeat: image: docker.elastic.co/beats/metricbeat:6.5.4 network\_mode: host user: root vo…

---

## [Auditbeat not picking up authentication events in CentOs 7](https://discuss.elastic.co/t/auditbeat-not-picking-up-authentication-events-in-centos-7/164304)

<div class="topic-metadata">

**Author:** [@arunpmohan](https://discuss.elastic.co/u/arunpmohan)\
**Replies:** 3\
**Last updated:** [January 19, 2019, 10:09am UTC](https://discuss.elastic.co/t/auditbeat-not-picking-up-authentication-events-in-centos-7/164304 "2019-01-19T10:09:25Z")

</div>

I am trying to ship the authentication related of my CentOS 7 to Elasticsearch. Strangely I am not getting any authentication events. When I ran the debug command auditbeat -c auditbeat.conf -d -e "\*" , I found somethin…

---

## [How to write auditlogs output to local and logstash](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829)

<div class="topic-metadata">

**Author:** [@post2tr](https://discuss.elastic.co/u/post2tr)\
**Replies:** 7\
**Last updated:** [January 19, 2019, 6:44am UTC](https://discuss.elastic.co/t/how-to-write-auditlogs-output-to-local-and-logstash/163829 "2019-01-19T06:44:47Z")

</div>

Using the auditbeat how to write the audit logs to the local disk ( for internal company requirements ) and logstash . Currently i get error message one outputs is allowed ie., either local or logstash .. The Dashboards…

---

## [java.lang.IllegalArgumentException: Provided Grok expressions do not match field value](https://discuss.elastic.co/t/java-lang-illegalargumentexception-provided-grok-expressions-do-not-match-field-value/164870)

<div class="topic-metadata">

**Author:** [@Vincent\_Le](https://discuss.elastic.co/u/Vincent_Le)\
**Replies:** 0\
**Last updated:** [January 19, 2019, 12:41am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-provided-grok-expressions-do-not-match-field-value/164870 "2019-01-19T00:41:33Z")

</div>

Hi all, I am somewhat new to Grok filter and I realize that there are many posts around this topic, but I can't seem to figure out what's wrong. I am actually using an example from one of the Elastic team member showin…

---

## [\[monitoring\] log/log.go:144 Non-zero metrics in the last 30s](https://discuss.elastic.co/t/monitoring-log-log-go-144-non-zero-metrics-in-the-last-30s/164514)

<div class="topic-metadata">

**Author:** [@miloni\_134](https://discuss.elastic.co/u/miloni_134)\
**Replies:** 0\
**Last updated:** [January 16, 2019, 5:26pm UTC](https://discuss.elastic.co/t/monitoring-log-log-go-144-non-zero-metrics-in-the-last-30s/164514 "2019-01-16T17:26:42Z")

</div>

Hello there, I want to send the output of filebeat to the logstash. I have installed the filebeat and logstash on my PC and configured it as per the requirements, but for some reason i am unable to send or receive any …

---

## [Can Filebeat send to one specific partition in Kafka cluster?](https://discuss.elastic.co/t/can-filebeat-send-to-one-specific-partition-in-kafka-cluster/164859)

<div class="topic-metadata">

**Author:** [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Replies:** 0\
**Last updated:** [January 18, 2019, 8:32pm UTC](https://discuss.elastic.co/t/can-filebeat-send-to-one-specific-partition-in-kafka-cluster/164859 "2019-01-18T20:32:10Z")

</div>

Hello, We have a scenario where we are sending data from one filbeat(6.3.2) agent to a three partition kafka(0.0.10.) topic. We are wanting filebeat to only send to one of the partitions in the kafka cluster. I found t…

---

## [Filebeat not filtering data according to fields in decode\_json\_fields](https://discuss.elastic.co/t/filebeat-not-filtering-data-according-to-fields-in-decode-json-fields/164866)

<div class="topic-metadata">

**Author:** [@akshaygawali](https://discuss.elastic.co/u/akshaygawali)\
**Replies:** 0\
**Last updated:** [January 18, 2019, 9:37pm UTC](https://discuss.elastic.co/t/filebeat-not-filtering-data-according-to-fields-in-decode-json-fields/164866 "2019-01-18T21:37:31Z")

</div>

In my filebeat configuration, I am trying pass json file to filebeat and want specific fields in the json to filtered and passed to elasticsearch. I am not using logstash. Below is my filebeat config: - type: log path…

---

## [Filebeat not able to send logs to logstash (Filebeat fails to connect logstash)](https://discuss.elastic.co/t/filebeat-not-able-to-send-logs-to-logstash-filebeat-fails-to-connect-logstash/164821)

<div class="topic-metadata">

**Author:** [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Replies:** 2\
**Last updated:** [January 18, 2019, 8:22pm UTC](https://discuss.elastic.co/t/filebeat-not-able-to-send-logs-to-logstash-filebeat-fails-to-connect-logstash/164821 "2019-01-18T20:22:53Z")

</div>

I'm using two servers on the cloud on one server (A) I installed filebeat and on second server (B) I have installed logstash, elasticsearch, and kibana. So I'm facing problem while sending logs from server A to server B …

---

## [Beginners guide to building a beat](https://discuss.elastic.co/t/beginners-guide-to-building-a-beat/164713)

<div class="topic-metadata">

**Author:** [@dorry](https://discuss.elastic.co/u/dorry)\
**Replies:** 1\
**Last updated:** [January 18, 2019, 8:07pm UTC](https://discuss.elastic.co/t/beginners-guide-to-building-a-beat/164713 "2019-01-18T20:07:44Z")

</div>

Hello There, I was wondering if you could help me please. I have been trying to compile and run the example lsbeat and heartbeat from the source code. I have followed the lsbeat blog and various other documents i could…

---

## [Issue with ingest of haproxy logs into KIbana](https://discuss.elastic.co/t/issue-with-ingest-of-haproxy-logs-into-kibana/164719)

<div class="topic-metadata">

**Author:** [@aalvino](https://discuss.elastic.co/u/aalvino)\
**Replies:** 2\
**Last updated:** [January 18, 2019, 5:00pm UTC](https://discuss.elastic.co/t/issue-with-ingest-of-haproxy-logs-into-kibana/164719 "2019-01-18T17:00:55Z")

</div>

I have signed up today for the free trial of elasticsearch. I am mostly interested in using hosted Kibana with elastic search. I am attempting to import some of my companies production data from an haproxy configuration.…

---

## [HTTPS not working for subject alternative name (SAN)](https://discuss.elastic.co/t/https-not-working-for-subject-alternative-name-san/163977)

<div class="topic-metadata">

**Author:** [@Ran\_Raines\_Moshe](https://discuss.elastic.co/u/Ran_Raines_Moshe)\
**Replies:** 1\
**Last updated:** [January 18, 2019, 3:59pm UTC](https://discuss.elastic.co/t/https-not-working-for-subject-alternative-name-san/163977 "2019-01-18T15:59:47Z")

</div>

I get this error while you can see the url do exists in the list Get https://asp-xxx-app-671.dev.mydomain.com:44330/xxx/: x509: certificate is valid for "xxxxxxx.dev.mydomain.com",".xxxxxxx.dev.mydomain.com","asp-xxx-ap…

---

## [Panic in job: runtime error: invalid memory address or nil pointer deference](https://discuss.elastic.co/t/panic-in-job-runtime-error-invalid-memory-address-or-nil-pointer-deference/163431)

<div class="topic-metadata">

**Author:** [@ElasticN00b](https://discuss.elastic.co/u/ElasticN00b)\
**Replies:** 1\
**Last updated:** [January 18, 2019, 3:43pm UTC](https://discuss.elastic.co/t/panic-in-job-runtime-error-invalid-memory-address-or-nil-pointer-deference/163431 "2019-01-18T15:43:22Z")

</div>

I'm running into an interesting panic error when I'm trying to set up a http heartbeat to see if a URL is running. The URL is a bamboo front end and all I'm trying to do is make sure the web interface is up. OS: CentOS…

---

## [FileBeat is not sending logfile to logstash](https://discuss.elastic.co/t/filebeat-is-not-sending-logfile-to-logstash/164784)

<div class="topic-metadata">

**Author:** [@nitin.jangid](https://discuss.elastic.co/u/nitin.jangid)\
**Replies:** 4\
**Last updated:** [January 18, 2019, 2:03pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logfile-to-logstash/164784 "2019-01-18T14:03:13Z")

</div>

Hi there, I am trying to ingest log data into logstash using filebeat. For that I have made filebeat as service in my system localhost and configured with path of log file and logstash host in filebeat.yml. filebeat.y…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=387)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=389)
