# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=39

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 40

---

## [How to get metrics on telegraf endpoint](https://discuss.elastic.co/t/how-to-get-metrics-on-telegraf-endpoint/341092)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 6:04am UTC](https://discuss.elastic.co/t/how-to-get-metrics-on-telegraf-endpoint/341092 "2023-09-12T06:04:22Z")

</div>

Hi, I'm trying to use metricbeat to read from a server that has exposed host:9050/metrics, in one of the metrics looks like \[...\] # HELP mongodb\_active\_reads Telegraf collected metric # TYPE mongodb\_active\_reads untype…

---

## [Filebeat creating write disk i/o when filtering](https://discuss.elastic.co/t/filebeat-creating-write-disk-i-o-when-filtering/342540)

<div class="topic-metadata">

**Author:** [@rdang](https://discuss.elastic.co/u/rdang)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 1:43pm UTC](https://discuss.elastic.co/t/filebeat-creating-write-disk-i-o-when-filtering/342540 "2023-09-11T13:43:32Z")

</div>

Hi folks, we are using filebeat 6.8 on Ubuntu 18.04.5 LTS with ESM. Filebeat is reading from mysql-audit.log thats configured to log CONNECT and QUERY events. Filebeat sends to a load balancer fronting logstash receiver…

---

## [Metricbeat Azure billing metricset](https://discuss.elastic.co/t/metricbeat-azure-billing-metricset/342037)

<div class="topic-metadata">

**Author:** [@Lalita\_Kumari](https://discuss.elastic.co/u/Lalita_Kumari)\
**Replies:** 2\
**Last updated:** [September 11, 2023, 5:43am UTC](https://discuss.elastic.co/t/metricbeat-azure-billing-metricset/342037 "2023-09-11T05:43:53Z")

</div>

I have Metricbeat installed in my system and have enabled Azure module and right now fetching data subscription wise. But i want to fetch the data Tag wise, more specifically under Subscriptions we have resources and und…

---

## [Issue with Filebeat Kubernetes Configuration for Ingress Logs](https://discuss.elastic.co/t/issue-with-filebeat-kubernetes-configuration-for-ingress-logs/342397)

<div class="topic-metadata">

**Author:** [@Ankur\_Mahajan](https://discuss.elastic.co/u/Ankur_Mahajan)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 5:38am UTC](https://discuss.elastic.co/t/issue-with-filebeat-kubernetes-configuration-for-ingress-logs/342397 "2023-09-11T05:38:43Z")

</div>

I'm attempting to use Filebeat on Kubernetes to ship my ingress logs and take advantage of the Nginx module dashboard. I've followed the configurations provided in the documentation, but I'm encountering an unusual issue…

---

## [Help me - How can I configure firebeat to read log files from log folder](https://discuss.elastic.co/t/help-me-how-can-i-configure-firebeat-to-read-log-files-from-log-folder/342599)

<div class="topic-metadata">

**Author:** [@Huy\_Hoang\_Le](https://discuss.elastic.co/u/Huy_Hoang_Le)\
**Replies:** 3\
**Last updated:** [September 11, 2023, 3:49am UTC](https://discuss.elastic.co/t/help-me-how-can-i-configure-firebeat-to-read-log-files-from-log-folder/342599 "2023-09-11T03:49:04Z")

</div>

I have an app that write log to .log file to a log folder that mounted from container to host. I'm very new to ELK overall so I want filebeat to read .log files generated in that log folder. Here is my filebeat config f…

---

## [Fix to libbeats to split bulk requests which are too large, not working in Elastic Agent 8.9.0?](https://discuss.elastic.co/t/fix-to-libbeats-to-split-bulk-requests-which-are-too-large-not-working-in-elastic-agent-8-9-0/342136)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 6\
**Last updated:** [September 8, 2023, 8:45pm UTC](https://discuss.elastic.co/t/fix-to-libbeats-to-split-bulk-requests-which-are-too-large-not-working-in-elastic-agent-8-9-0/342136 "2023-09-08T20:45:22Z")

</div>

In Beats, I see that this commit was merged in March 2023: " Split large batches on error instead of dropping them" PR 34911 I think that PR 34911 changed the Publish() logic: If I look here: func (client \*Client) …

---

## [Install Winlogbeat with user account](https://discuss.elastic.co/t/install-winlogbeat-with-user-account/342642)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 8:29pm UTC](https://discuss.elastic.co/t/install-winlogbeat-with-user-account/342642 "2023-09-08T20:29:22Z")

</div>

Hi, I am trying to install winlogbeat and run as user who is not an Adminsitrator Saw a link - request for enhancement (\[Winlogbeat\] Document minimum permissions for Windows service user · Issue #15773 · elastic/beats …

---

## [Heartbeat No matching indices found for index pattern heartbeat\*](https://discuss.elastic.co/t/heartbeat-no-matching-indices-found-for-index-pattern-heartbeat/342345)

<div class="topic-metadata">

**Author:** [@BenKenobi](https://discuss.elastic.co/u/BenKenobi)\
**Replies:** 3\
**Last updated:** [September 8, 2023, 2:24pm UTC](https://discuss.elastic.co/t/heartbeat-no-matching-indices-found-for-index-pattern-heartbeat/342345 "2023-09-08T14:24:21Z")

</div>

Hi, I have installed and configured heartbeat according your documentation. I have created a cfg-file tcpdemo.yml and it looks like this: Elastic and Kibana run on the same cluster and heartbeat is installed on anoth…

---

## [Filebeat Setup error: Couldn't load template](https://discuss.elastic.co/t/filebeat-setup-error-couldnt-load-template/342268)

<div class="topic-metadata">

**Author:** [@JNWL](https://discuss.elastic.co/u/JNWL)\
**Replies:** 3\
**Last updated:** [September 8, 2023, 11:02am UTC](https://discuss.elastic.co/t/filebeat-setup-error-couldnt-load-template/342268 "2023-09-08T11:02:43Z")

</div>

Hi All Years ago I set up a Zeek host with filebeat shipping logs to ELK, this worked fine... Trying to replicate it on a new host years later, and a lot has changed! I'm getting the below error: sudo filebeat setup …

---

## [Metricbeat running but didn't appear in monitoring](https://discuss.elastic.co/t/metricbeat-running-but-didnt-appear-in-monitoring/342562)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 9:37am UTC](https://discuss.elastic.co/t/metricbeat-running-but-didnt-appear-in-monitoring/342562 "2023-09-08T09:37:14Z")

</div>

Hello there I found a strange situation here. so I added some logstash nodes to my cluster and used metricbeat to monitor them. but after the metricbeat was running, I checked in my monitoring node, and I found not all …

---

## [How to configure metricbeat k8s to use ssl connection to ES](https://discuss.elastic.co/t/how-to-configure-metricbeat-k8s-to-use-ssl-connection-to-es/342538)

<div class="topic-metadata">

**Author:** [@Mihai-CMM](https://discuss.elastic.co/u/Mihai-CMM)\
**Replies:** 2\
**Last updated:** [September 8, 2023, 6:50am UTC](https://discuss.elastic.co/t/how-to-configure-metricbeat-k8s-to-use-ssl-connection-to-es/342538 "2023-09-08T06:50:31Z")

</div>

Per title i find it impssobile to configure metricbeat and ES on k8s env. Can i please get a full working env for metricbeat? https://raw.githubusercontent.com/elastic/beats/8.9/deploy/kubernetes/metricbeat-kubernetes.…

---

## [Enhanced respone to fsnotify queue overflow errors](https://discuss.elastic.co/t/enhanced-respone-to-fsnotify-queue-overflow-errors/342555)

<div class="topic-metadata">

**Author:** [@James\_Nelson1](https://discuss.elastic.co/u/James_Nelson1)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 9:19pm UTC](https://discuss.elastic.co/t/enhanced-respone-to-fsnotify-queue-overflow-errors/342555 "2023-09-07T21:19:51Z")

</div>

Hi Auditbeat folks. I'm considering a feature request, or maybe even a PR to enhance Auditbeat's file\_integrity behavior on Linux platforms when the "fsnotify queue overflow" message is encountered. See eventreader\_fsnot…

---

## [Winlogbeat "ignore\_older" rule not working](https://discuss.elastic.co/t/winlogbeat-ignore-older-rule-not-working/342454)

<div class="topic-metadata">

**Author:** [@cesq](https://discuss.elastic.co/u/cesq)\
**Replies:** 6\
**Last updated:** [September 7, 2023, 10:12am UTC](https://discuss.elastic.co/t/winlogbeat-ignore-older-rule-not-working/342454 "2023-09-07T10:12:12Z")

</div>

I've been deploying winlogbeat with graylog-sidecar and for some reason the "ignore\_older" option does not work for me. I am using the latest graylog-sidecar version as well as winlogbeat. In my configuration I have spe…

---

## [Metricbeat illegal\_argument\_exception error](https://discuss.elastic.co/t/metricbeat-illegal-argument-exception-error/341919)

<div class="topic-metadata">

**Author:** [@wleight](https://discuss.elastic.co/u/wleight)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 6:28pm UTC](https://discuss.elastic.co/t/metricbeat-illegal-argument-exception-error/341919 "2023-09-06T18:28:18Z")

</div>

Hi, I'm trying to set up Metricbeat -\> Elastic (8.9.0 on Ubuntu) using the HTTP JSON metricset, and had no problems at first, but then the output that is retrieved changed and now Metricbeat tells me "Cannot index event…

---

## [Filebeat not sending suricata logs to elasticsearch](https://discuss.elastic.co/t/filebeat-not-sending-suricata-logs-to-elasticsearch/342399)

<div class="topic-metadata">

**Author:** [@Dhruv\_Kumar](https://discuss.elastic.co/u/Dhruv_Kumar)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 8:44am UTC](https://discuss.elastic.co/t/filebeat-not-sending-suricata-logs-to-elasticsearch/342399 "2023-09-06T08:44:51Z")

</div>

Hello . I have a server in which i am running suricata . In the same server I have installed filebeat which i am using to send my suricata logs to Elasticsearch .I have setup es and kibana inside a vm .After starting eve…

---

## [Filebeat how to delete indexes automaticality after a few days](https://discuss.elastic.co/t/filebeat-how-to-delete-indexes-automaticality-after-a-few-days/342308)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 7:47am UTC](https://discuss.elastic.co/t/filebeat-how-to-delete-indexes-automaticality-after-a-few-days/342308 "2023-09-06T07:47:51Z")

</div>

Hello I have installed ELK and I would like to optimise it a little bit. CentOS Linux release 7.9.2009 (Core) bin/kibana --version 8.6.2 bin/elasticsearch --version Version: 8.6.2, Build: I'm using filebeat and aft…

---

## [Services error](https://discuss.elastic.co/t/services-error/342372)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:41pm UTC](https://discuss.elastic.co/t/services-error/342372 "2023-09-05T19:41:08Z")

</div>

When I try to start the winlogbeat service on windows server 2012 and 2016 : throwing the error : Windows could not start the winlogbeat service on local computer. Error 1067 : The process Terminated unexpectedly. Plea…

---

## [Filebeat threshold set](https://discuss.elastic.co/t/filebeat-threshold-set/342356)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 4:02pm UTC](https://discuss.elastic.co/t/filebeat-threshold-set/342356 "2023-09-05T16:02:41Z")

</div>

Thanks in advance, Is there any possibility to implement the below requirement. We are using filebeat agent to forward data to logstash. To avoid log burst, is there a way to set a threshold limit on the amount of log…

---

## [ELK monog module printing null value in event.original](https://discuss.elastic.co/t/elk-monog-module-printing-null-value-in-event-original/342349)

<div class="topic-metadata">

**Author:** [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 2:10pm UTC](https://discuss.elastic.co/t/elk-monog-module-printing-null-value-in-event-original/342349 "2023-09-05T14:10:55Z")

</div>

We are exporting the mongo logs using mongodb filebeat module but few values in event.original comes as blank value but when we switch to json i can see the field has a value in it. Can somebody help in identifying the i…

---

## [Filebeat now working on Kubernetes 1.24](https://discuss.elastic.co/t/filebeat-now-working-on-kubernetes-1-24/342334)

<div class="topic-metadata">

**Author:** [@Marco\_Lagalla](https://discuss.elastic.co/u/Marco_Lagalla)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:34am UTC](https://discuss.elastic.co/t/filebeat-now-working-on-kubernetes-1-24/342334 "2023-09-05T10:34:13Z")

</div>

Hi, I have a cluster running Kubernetes version 1.24, hosted on AWS EKS. Into the cluster there are multiple workloads segregated by namespace. Filebeat is installed to run as a DaemonSet, and should be able to collec…

---

## [BUG: panic when packetbeat parsing HTTP host header with non-standard format](https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258)

<div class="topic-metadata">

**Author:** [@moonD4rk](https://discuss.elastic.co/u/moonD4rk)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 12:09pm UTC](https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258 "2023-09-04T12:09:24Z")

</div>

Summary: Packetbeat(all version) encounters a panic when parsing HTTP requests that have a non-standard Host header. The issue occurs in the function extractHostHeader and manifests as an "index out of range" panic. Ste…

---

## [Filebeat sends malformed logs](https://discuss.elastic.co/t/filebeat-sends-malformed-logs/342078)

<div class="topic-metadata">

**Author:** [@MheniMerz](https://discuss.elastic.co/u/MheniMerz)\
**Replies:** 6\
**Last updated:** [September 3, 2023, 9:59pm UTC](https://discuss.elastic.co/t/filebeat-sends-malformed-logs/342078 "2023-09-03T21:59:07Z")

</div>

Hi, i'm using filebeat to receive logs from a Juniper firewall and forward them to logstash which then sends them to elasticsearch. i configured my juniper firewall to use the required log format structured-data + brie…

---

## [Help Needed: Setting Up Encrypted UDP Log Forwarding in Filebeat to Filebeat](https://discuss.elastic.co/t/help-needed-setting-up-encrypted-udp-log-forwarding-in-filebeat-to-filebeat/341952)

<div class="topic-metadata">

**Author:** [@randv](https://discuss.elastic.co/u/randv)\
**Replies:** 2\
**Last updated:** [September 3, 2023, 6:52am UTC](https://discuss.elastic.co/t/help-needed-setting-up-encrypted-udp-log-forwarding-in-filebeat-to-filebeat/341952 "2023-09-03T06:52:38Z")

</div>

Hello All, I am currently working on a project that involves securing log forwarding using encrypted UDP. I have a specific use case where I need to forward logs from one server to another over encrypted UDP, and I'm s…

---

## [Filebeat not collecting logs for hints based autodiscover in kubernetes](https://discuss.elastic.co/t/filebeat-not-collecting-logs-for-hints-based-autodiscover-in-kubernetes/342134)

<div class="topic-metadata">

**Author:** [@sayantanvlabs](https://discuss.elastic.co/u/sayantanvlabs)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 3:50pm UTC](https://discuss.elastic.co/t/filebeat-not-collecting-logs-for-hints-based-autodiscover-in-kubernetes/342134 "2023-09-01T15:50:28Z")

</div>

I am trying to get logs from pods annotated with co.elastic.logs/enabled: "true" into elasticsearch using filebeat. But it is not working. I am attaching the configurations I am using, please let me know if I am missing …

---

## [Filebeat pod continuously restarting : Liveness probe failed: rss\_mem 341245952](https://discuss.elastic.co/t/filebeat-pod-continuously-restarting-liveness-probe-failed-rss-mem-341245952/341980)

<div class="topic-metadata">

**Author:** [@Sam\_John](https://discuss.elastic.co/u/Sam_John)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 6:28am UTC](https://discuss.elastic.co/t/filebeat-pod-continuously-restarting-liveness-probe-failed-rss-mem-341245952/341980 "2023-09-01T06:28:25Z")

</div>

filebeat pod in a k8s worker node is continuously restarting with following error message when the pods in the worker node increases: Error Message from filebeat pod: Warning Unhealthy 44m kubelet, k8s-worker-2 Livenes…

---

## [I want to use udp to output logs to logstash](https://discuss.elastic.co/t/i-want-to-use-udp-to-output-logs-to-logstash/342052)

<div class="topic-metadata">

**Author:** [@manymany](https://discuss.elastic.co/u/manymany)\
**Replies:** 1\
**Last updated:** [August 31, 2023, 2:04pm UTC](https://discuss.elastic.co/t/i-want-to-use-udp-to-output-logs-to-logstash/342052 "2023-08-31T14:04:11Z")

</div>

Filebeat Version: 8.4.3 ERROR: unsupported network type udp.

---

## [Missing some fields in some document](https://discuss.elastic.co/t/missing-some-fields-in-some-document/341066)

<div class="topic-metadata">

**Author:** [@thutrang](https://discuss.elastic.co/u/thutrang)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 10:06am UTC](https://discuss.elastic.co/t/missing-some-fields-in-some-document/341066 "2023-08-30T10:06:53Z")

</div>

I am using Packetbeat version 7.12.1 to collect DNS data from network flows, then sending it to Logstash, and finally forwarding it to Elasticsearch. I am encountering an issue where certain documents in Elasticsearch ar…

---

## [Help me !,about filebeat processors config](https://discuss.elastic.co/t/help-me-about-filebeat-processors-config/341956)

<div class="topic-metadata">

**Author:** [@iamlizekun](https://discuss.elastic.co/u/iamlizekun)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 8:09am UTC](https://discuss.elastic.co/t/help-me-about-filebeat-processors-config/341956 "2023-08-30T08:09:20Z")

</div>

I have a requirement to limit different log push rates for different docker containers, and I found processors.rate\_ The limit parameter successfully limits the logs of all containers, but I want to use processors.fields…

---

## [Failed to start crawler: creating module reloader failed in filebeat](https://discuss.elastic.co/t/failed-to-start-crawler-creating-module-reloader-failed-in-filebeat/341922)

<div class="topic-metadata">

**Author:** [@SOMU\_REDDY](https://discuss.elastic.co/u/SOMU_REDDY)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 4:23am UTC](https://discuss.elastic.co/t/failed-to-start-crawler-creating-module-reloader-failed-in-filebeat/341922 "2023-08-30T04:23:46Z")

</div>

getting this error while trying to send logs to Elasticsearch using this ./filebeat -c filebeat.yml -e getting this message":"Exiting: Failed to start crawler: creating module reloader failed: loading configs: 1 error: i…

---

## [Beats vs multiple outputs while transisting to a new elastic cluster](https://discuss.elastic.co/t/beats-vs-multiple-outputs-while-transisting-to-a-new-elastic-cluster/341799)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 9:56pm UTC](https://discuss.elastic.co/t/beats-vs-multiple-outputs-while-transisting-to-a-new-elastic-cluster/341799 "2023-08-29T21:56:42Z")

</div>

Running a PoC with filebeat + metricbeat agents on a number of endpoints sending data through ingest nodes running various pipelines on the filebeat events. While preparing move to a new elastic cluster, we would like t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=38)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=40)
