# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=389

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 390

---

## [Close\_removed does not work as expected on Windows](https://discuss.elastic.co/t/close-removed-does-not-work-as-expected-on-windows/164768)

<div class="topic-metadata">

**Author:** [@CaptainAye](https://discuss.elastic.co/u/CaptainAye)\
**Replies:** 0\
**Last updated:** [January 18, 2019, 10:06am UTC](https://discuss.elastic.co/t/close-removed-does-not-work-as-expected-on-windows/164768 "2019-01-18T10:06:08Z")

</div>

Hi, I use Filebeat 6.5.4 and I have a problem with close\_removed attribute. I have an application with rotating logs hosted on Windows. When Elasticsearch is down for some time, Logstash persistent\_queue is getting full…

---

## [Multiline pattern with tab](https://discuss.elastic.co/t/multiline-pattern-with-tab/164746)

<div class="topic-metadata">

**Author:** [@victoravr](https://discuss.elastic.co/u/victoravr)\
**Replies:** 1\
**Last updated:** [January 18, 2019, 7:46am UTC](https://discuss.elastic.co/t/multiline-pattern-with-tab/164746 "2019-01-18T07:46:35Z")

</div>

Hi! I'd like to use multiline.pattern in filebeat input (in filebeat.yml) to process tomcat Java logs and send it to logstash+elasticsearch. Below is a piece of the log file: Apr 03, 2018 10:53:44 AM org.apache.catali…

---

## [Tried to parse field \[log\_json\] as object](https://discuss.elastic.co/t/tried-to-parse-field-log-json-as-object/164710)

<div class="topic-metadata">

**Author:** [@Kody\_Peterson](https://discuss.elastic.co/u/Kody_Peterson)\
**Replies:** 0\
**Last updated:** [January 17, 2019, 10:28pm UTC](https://discuss.elastic.co/t/tried-to-parse-field-log-json-as-object/164710 "2019-01-17T22:28:56Z")

</div>

Filebeats is throwing this error but it is not configured to do any json processing. Any thoughts? {"level":"warn","timestamp":"2019-01-17T21:55:19.132Z","caller":"elasticsearch/client.go:521","message":"Cannot index e…

---

## [Is there a way to read a log and send a specific field to a dynamic index?](https://discuss.elastic.co/t/is-there-a-way-to-read-a-log-and-send-a-specific-field-to-a-dynamic-index/164665)

<div class="topic-metadata">

**Author:** [@James\_Land](https://discuss.elastic.co/u/James_Land)\
**Replies:** 0\
**Last updated:** [January 17, 2019, 3:22pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-read-a-log-and-send-a-specific-field-to-a-dynamic-index/164665 "2019-01-17T15:22:23Z")

</div>

I currently have a system that sending some custom audit data from a spring boot application to elastic by using a custom logger to filter the data through logstash. We would like to modify that process to instead log t…

---

## [Error sending information from filebeat to elastic cloud](https://discuss.elastic.co/t/error-sending-information-from-filebeat-to-elastic-cloud/163946)

<div class="topic-metadata">

**Author:** [@fabian1](https://discuss.elastic.co/u/fabian1)\
**Replies:** 3\
**Last updated:** [January 17, 2019, 2:33pm UTC](https://discuss.elastic.co/t/error-sending-information-from-filebeat-to-elastic-cloud/163946 "2019-01-17T14:33:10Z")

</div>

configuration file ERROR

---

## [Alternate way to Import dashboard (index name / index id)](https://discuss.elastic.co/t/alternate-way-to-import-dashboard-index-name-index-id/164406)

<div class="topic-metadata">

**Author:** [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Replies:** 0\
**Last updated:** [January 16, 2019, 5:58am UTC](https://discuss.elastic.co/t/alternate-way-to-import-dashboard-index-name-index-id/164406 "2019-01-16T05:58:40Z")

</div>

I have multiple dashboards and multiple indexes in my ELK setup(6.3.2). Now, I have a dashboard dashboard1 created against index index1 which I was able to export successfully. Am running another instance of ELK(6.3.2) …

---

## [Kafka consumer lag?](https://discuss.elastic.co/t/kafka-consumer-lag/163884)

<div class="topic-metadata">

**Author:** [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Replies:** 4\
**Last updated:** [January 17, 2019, 10:49am UTC](https://discuss.elastic.co/t/kafka-consumer-lag/163884 "2019-01-17T10:49:59Z")

</div>

I'd somehow got the idea that Metricbeat 6.5 might enable the monitoring of Kafka consumer lag, but on trying it I see that the latest offset is still only in the partition event and the consumer group offset is still on…

---

## [Filebeat auto-deletion of files when harvesting of files complete or remove log file older than 7 days](https://discuss.elastic.co/t/filebeat-auto-deletion-of-files-when-harvesting-of-files-complete-or-remove-log-file-older-than-7-days/164034)

<div class="topic-metadata">

**Author:** [@Saurabh\_Sharma1](https://discuss.elastic.co/u/Saurabh_Sharma1)\
**Replies:** 2\
**Last updated:** [January 17, 2019, 10:03am UTC](https://discuss.elastic.co/t/filebeat-auto-deletion-of-files-when-harvesting-of-files-complete-or-remove-log-file-older-than-7-days/164034 "2019-01-17T10:03:23Z")

</div>

I am facing one critical issue with filebeat, There too much logs available in my log directory, How can I delete the logs older than 7 days

---

## [Add grok filter for costume log data in Filebeat's NGINX module](https://discuss.elastic.co/t/add-grok-filter-for-costume-log-data-in-filebeats-nginx-module/161855)

<div class="topic-metadata">

**Author:** [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Replies:** 4\
**Last updated:** [January 17, 2019, 9:32am UTC](https://discuss.elastic.co/t/add-grok-filter-for-costume-log-data-in-filebeats-nginx-module/161855 "2019-01-17T09:32:30Z")

</div>

Hi I'm not sure if this is the best way to go on about this. If there is a better way, please advice. I've added a new access.log entry for NGINX that tracks the following: $remote\_addr $ssl\_protocol $ssl\_cipher $r…

---

## [Kubernetes - Filebeat can't index event publisher](https://discuss.elastic.co/t/kubernetes-filebeat-cant-index-event-publisher/164595)

<div class="topic-metadata">

**Author:** [@tomaaron](https://discuss.elastic.co/u/tomaaron)\
**Replies:** 0\
**Last updated:** [January 17, 2019, 9:04am UTC](https://discuss.elastic.co/t/kubernetes-filebeat-cant-index-event-publisher/164595 "2019-01-17T09:04:10Z")

</div>

Hey there, I am trying to setup Filebeat v6.5.4 on a selfhosted Kubernetes Cluster to monitor the PHP example guestbook application. I used the provided filebeat-kubernetes.yaml from your GitHub Repo. Metricbeat is alre…

---

## [Filebeat Configuration hosts add\_cloud\_metadata: hosting provider type not detected](https://discuss.elastic.co/t/filebeat-configuration-hosts-add-cloud-metadata-hosting-provider-type-not-detected/164479)

<div class="topic-metadata">

**Author:** [@yasin](https://discuss.elastic.co/u/yasin)\
**Replies:** 0\
**Last updated:** [January 16, 2019, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-configuration-hosts-add-cloud-metadata-hosting-provider-type-not-detected/164479 "2019-01-16T14:20:12Z")

</div>

Dear Elastic Team, When i want to edit file for filebeat it says only read only. I've checked that there is a user available called filebeat in the container but i don't no the password so i'm not able to change anythin…

---

## [Complete file plus tail forever](https://discuss.elastic.co/t/complete-file-plus-tail-forever/164345)

<div class="topic-metadata">

**Author:** [@Nikola\_Radovanovic](https://discuss.elastic.co/u/Nikola_Radovanovic)\
**Replies:** 2\
**Last updated:** [January 17, 2019, 4:42am UTC](https://discuss.elastic.co/t/complete-file-plus-tail-forever/164345 "2019-01-17T04:42:11Z")

</div>

Hi all, sorry if this is already asked but I am complete noob in ELK stuff and need some advice. I have an requirement to track server log files in Angular 2 app, and I am in charge of the backend. I played a little bit…

---

## [Filebeat harvests log from elasticsearch and store field 'timestamp' without converting to utc time](https://discuss.elastic.co/t/filebeat-harvests-log-from-elasticsearch-and-store-field-timestamp-without-converting-to-utc-time/164407)

<div class="topic-metadata">

**Author:** [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Replies:** 3\
**Last updated:** [January 17, 2019, 3:57am UTC](https://discuss.elastic.co/t/filebeat-harvests-log-from-elasticsearch-and-store-field-timestamp-without-converting-to-utc-time/164407 "2019-01-17T03:57:54Z")

</div>

hi I am using elasticsearch module of filebeat to harvest log files of elasticsearch and visualizing log info in kibana. Having configured and started filebeat, the log is successfully stored in elasticsearch and show…

---

## [Filebeat error while importing kibana dashboard](https://discuss.elastic.co/t/filebeat-error-while-importing-kibana-dashboard/163954)

<div class="topic-metadata">

**Author:** [@samnayak](https://discuss.elastic.co/u/samnayak)\
**Replies:** 3\
**Last updated:** [January 17, 2019, 2:29am UTC](https://discuss.elastic.co/t/filebeat-error-while-importing-kibana-dashboard/163954 "2019-01-17T02:29:43Z")

</div>

I am getting below error while running filebeat. Can anyone help? 2019-01-11T14:54:40.684-0600 ERROR instance/beat.go:800 Exiting: Error importing Kibana dashboards: fail to create the Kibana loader: Error creating Kiba…

---

## [Multiline log files](https://discuss.elastic.co/t/multiline-log-files/164155)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 4\
**Last updated:** [January 17, 2019, 2:26am UTC](https://discuss.elastic.co/t/multiline-log-files/164155 "2019-01-17T02:26:40Z")

</div>

I am looking to configure filebeats to deal with the following data sample... ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Time of Server Script Exception : 26 January 2018 13:38:0…

---

## [Filebeat 6.4.2 and 6.5.1: Read line error: "parsing CRI timestamp" and "invalid CRI log format"](https://discuss.elastic.co/t/filebeat-6-4-2-and-6-5-1-read-line-error-parsing-cri-timestamp-and-invalid-cri-log-format/159383)

<div class="topic-metadata">

**Author:** [@rocketraman](https://discuss.elastic.co/u/rocketraman)\
**Replies:** 8\
**Last updated:** [January 16, 2019, 11:24pm UTC](https://discuss.elastic.co/t/filebeat-6-4-2-and-6-5-1-read-line-error-parsing-cri-timestamp-and-invalid-cri-log-format/159383 "2019-01-16T23:24:34Z")

</div>

I am getting various CRI parsing errors, on both Filebeat 6.4.2 and 6.5.1. I have cleared all filebeat state and restarted Filebeat, but these errors always occur. Here are a couple: 2018-12-04T02:32:18.636Z ERROR log/h…

---

## [Please help: Create new beats](https://discuss.elastic.co/t/please-help-create-new-beats/163560)

<div class="topic-metadata">

**Author:** [@rafaelbattesti](https://discuss.elastic.co/u/rafaelbattesti)\
**Replies:** 3\
**Last updated:** [January 16, 2019, 10:01pm UTC](https://discuss.elastic.co/t/please-help-create-new-beats/163560 "2019-01-16T22:01:49Z")

</div>

Hello elastic community. I am starting off a project around Beats and trying to first setup my environment. I followed the steps on: https://www.elastic.co/guide/en/beats/devguide/master/new-beat.html But the result w…

---

## [Winlogbeat getting x509: certificate signed by unknown authority when sending to elasticsearch](https://discuss.elastic.co/t/winlogbeat-getting-x509-certificate-signed-by-unknown-authority-when-sending-to-elasticsearch/164352)

<div class="topic-metadata">

**Author:** [@ciphee](https://discuss.elastic.co/u/ciphee)\
**Replies:** 2\
**Last updated:** [January 16, 2019, 6:00pm UTC](https://discuss.elastic.co/t/winlogbeat-getting-x509-certificate-signed-by-unknown-authority-when-sending-to-elasticsearch/164352 "2019-01-16T18:00:15Z")

</div>

Hello, I have recently sucessfully connected my winlogbeat to logstash, however now I am trying to connect it to elastic in order to do the --setup dashboards and --setup index. I was trying to disable logstash and conn…

---

## [Exiting: more than one namespace configured accessing config](https://discuss.elastic.co/t/exiting-more-than-one-namespace-configured-accessing-config/164365)

<div class="topic-metadata">

**Author:** [@meetdave2611997](https://discuss.elastic.co/u/meetdave2611997)\
**Replies:** 1\
**Last updated:** [January 16, 2019, 4:41pm UTC](https://discuss.elastic.co/t/exiting-more-than-one-namespace-configured-accessing-config/164365 "2019-01-16T16:41:11Z")

</div>

Hi I am using Filebeat to send logs to Logstash for filtering and then to Elasticsearch. Here I am trying to add new beats monitoring feature in the stack and I am getting the following error while starting Filebeat. 2…

---

## [Filebeat failed to inject events in dynamic index name having docker metadata](https://discuss.elastic.co/t/filebeat-failed-to-inject-events-in-dynamic-index-name-having-docker-metadata/164478)

<div class="topic-metadata">

**Author:** [@Lucas\_Dehandschutter](https://discuss.elastic.co/u/Lucas_Dehandschutter)\
**Replies:** 0\
**Last updated:** [January 16, 2019, 2:00pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-inject-events-in-dynamic-index-name-having-docker-metadata/164478 "2019-01-16T14:00:58Z")

</div>

Hi, We have a Docker Swarm running a bunch of microservices. To monitor their logs we have: Filebeat reading docker logs based on a prospector configuration, enriching those logs with docker's metadata and pushing t…

---

## [Metricbeat on kubernetes ,field beat.hostname got the pod name and no the host name](https://discuss.elastic.co/t/metricbeat-on-kubernetes-field-beat-hostname-got-the-pod-name-and-no-the-host-name/164438)

<div class="topic-metadata">

**Author:** [@nchap](https://discuss.elastic.co/u/nchap)\
**Replies:** 2\
**Last updated:** [January 16, 2019, 12:52pm UTC](https://discuss.elastic.co/t/metricbeat-on-kubernetes-field-beat-hostname-got-the-pod-name-and-no-the-host-name/164438 "2019-01-16T12:52:12Z")

</div>

Hi everybody, i have install the elasticseach, kibana, filebeat and metricbeat on a aks cluster using helm. But for the metricbeat who collect the state metric, on the field "beat.hostname" the value is the pod name and…

---

## [How to use filebeat to collect particular kind of .log file from different hosts and display the result inside it for each host on Kibana dashboard?](https://discuss.elastic.co/t/how-to-use-filebeat-to-collect-particular-kind-of-log-file-from-different-hosts-and-display-the-result-inside-it-for-each-host-on-kibana-dashboard/163526)

<div class="topic-metadata">

**Author:** [@Swati\_Singh](https://discuss.elastic.co/u/Swati_Singh)\
**Replies:** 2\
**Last updated:** [January 16, 2019, 11:04am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-to-collect-particular-kind-of-log-file-from-different-hosts-and-display-the-result-inside-it-for-each-host-on-kibana-dashboard/163526 "2019-01-16T11:04:24Z")

</div>

Hi, I want to use filebeat to collect a particular kind of logs from different machines and send those to my kibana-elasticsearch host. Eg. Installation logs of a particular component from all machines, stating if inst…

---

## [Shards Failed](https://discuss.elastic.co/t/shards-failed/164067)

<div class="topic-metadata">

**Author:** [@epjp](https://discuss.elastic.co/u/epjp)\
**Replies:** 1\
**Last updated:** [January 16, 2019, 10:22am UTC](https://discuss.elastic.co/t/shards-failed/164067 "2019-01-16T10:22:11Z")

</div>

I have created a Data Table Visualization that gives me the "system.uptime.duration.ms" for 4 Windows servers running Metricbeat 6.5.4. Unfortunately, no matter what timeframe I query, I get "20 Shards out of X Failed" …

---

## [Filebeat locks the file rotation for log4j causing the files to grow enormously](https://discuss.elastic.co/t/filebeat-locks-the-file-rotation-for-log4j-causing-the-files-to-grow-enormously/164428)

<div class="topic-metadata">

**Author:** [@CaptainAye](https://discuss.elastic.co/u/CaptainAye)\
**Replies:** 0\
**Last updated:** [January 16, 2019, 9:38am UTC](https://discuss.elastic.co/t/filebeat-locks-the-file-rotation-for-log4j-causing-the-files-to-grow-enormously/164428 "2019-01-16T09:38:37Z")

</div>

Hello, Sometimes the logs in my application are not rolled as they should be and they grow in size (the limit is 10mb) I receive an exception if Filebeat logs: Err: error setting up harvester: Harvester setup failed. …

---

## [Configuration example of filebeat haproxy module](https://discuss.elastic.co/t/configuration-example-of-filebeat-haproxy-module/164372)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 2\
**Last updated:** [January 16, 2019, 5:52am UTC](https://discuss.elastic.co/t/configuration-example-of-filebeat-haproxy-module/164372 "2019-01-16T05:52:52Z")

</div>

I'm trying to get the filebeat haproxy module to work. I probably need one working example (or a list of what is required from all the dependencies) haproxy version 1.7.7 filebeat -version Flag --version has been …

---

## [Beats Setup Options](https://discuss.elastic.co/t/beats-setup-options/164335)

<div class="topic-metadata">

**Author:** [@RhysEvans](https://discuss.elastic.co/u/RhysEvans)\
**Replies:** 0\
**Last updated:** [January 15, 2019, 3:45pm UTC](https://discuss.elastic.co/t/beats-setup-options/164335 "2019-01-15T15:45:08Z")

</div>

Hi I am trying to automate the setup of an Elastic Stack using docker. At present most of it is working, however I do have a question around the setup of beats. I am hoping you can help. Basically I want to automate th…

---

## [Cannot Parse error: Lexical error](https://discuss.elastic.co/t/cannot-parse-error-lexical-error/164173)

<div class="topic-metadata">

**Author:** [@Luis\_Alejandro\_Galan](https://discuss.elastic.co/u/Luis_Alejandro_Galan)\
**Replies:** 2\
**Last updated:** [January 15, 2019, 2:53pm UTC](https://discuss.elastic.co/t/cannot-parse-error-lexical-error/164173 "2019-01-15T14:53:04Z")

</div>

I just upgraded Kibana to version 6.5.3 but the client servers are still using version 6.3. My other services are parsing just fine and the logs for the the new servers i've recently added are in similar format to the re…

---

## [Filebeat crashing with out of memory](https://discuss.elastic.co/t/filebeat-crashing-with-out-of-memory/163580)

<div class="topic-metadata">

**Author:** [@damianconnolly](https://discuss.elastic.co/u/damianconnolly)\
**Replies:** 4\
**Last updated:** [January 15, 2019, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-crashing-with-out-of-memory/163580 "2019-01-15T13:00:22Z")

</div>

Hi, I'm trying to setup Beats for a new application, and Beats crashes after a few minutes of running, before any logs are even sent to Kafka. The log file I'm reading from is pretty huge (32GB) and I think the problem …

---

## [Filebeat - proper configuration to parse nested JSON](https://discuss.elastic.co/t/filebeat-proper-configuration-to-parse-nested-json/164277)

<div class="topic-metadata">

**Author:** [@mariomechoulam](https://discuss.elastic.co/u/mariomechoulam)\
**Replies:** 0\
**Last updated:** [January 15, 2019, 9:29am UTC](https://discuss.elastic.co/t/filebeat-proper-configuration-to-parse-nested-json/164277 "2019-01-15T09:29:18Z")

</div>

Hello! I am having a hard time finding the right configuration for Filebeat to be able to correctly parse nested JSON log lines. The main level is parsed without any issues, but nothing that I've tried has worked after …

---

## [Filebeat hostname lowercase uppercase](https://discuss.elastic.co/t/filebeat-hostname-lowercase-uppercase/164231)

<div class="topic-metadata">

**Author:** [@nayun\_oh](https://discuss.elastic.co/u/nayun_oh)\
**Replies:** 3\
**Last updated:** [January 15, 2019, 5:55am UTC](https://discuss.elastic.co/t/filebeat-hostname-lowercase-uppercase/164231 "2019-01-15T05:55:00Z")

</div>

Hi I find out that filebeat sometimes writes hostname in lowercase letters. I don't know why. Thank you in advance

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=388)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=390)
