# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=390

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 391

---

## [Multiline pattern in filebeat](https://discuss.elastic.co/t/multiline-pattern-in-filebeat/164186)

<div class="topic-metadata">

**Author:** [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Replies:** 1\
**Last updated:** [January 15, 2019, 5:23am UTC](https://discuss.elastic.co/t/multiline-pattern-in-filebeat/164186 "2019-01-15T05:23:29Z")

</div>

Hi All, what would be the multi-line pattern for \</ds:Reference\> \</ds:SignedInfo\> ds:SignatureValue attxcej7XBJ3rqWc9V0FbQwLLtBA7qvdNVmyErRANDUUrTpaxQCOaD8D4PpnVBaTCvana8RGLI1Q AvHgqjaDk6qoBbS27Knznku+T02TbKXAi7TfD…

---

## [Did not find expected \<document start\>](https://discuss.elastic.co/t/did-not-find-expected-document-start/164138)

<div class="topic-metadata">

**Author:** [@Urs\_Bronk](https://discuss.elastic.co/u/Urs_Bronk)\
**Replies:** 1\
**Last updated:** [January 15, 2019, 5:00am UTC](https://discuss.elastic.co/t/did-not-find-expected-document-start/164138 "2019-01-15T05:00:46Z")

</div>

Hi guys, I've been at this for days, I'm still new to filebeat and have setup filebeat on a different server with the same config, but on this server doesn't matter what I try I get the following error and error after e…

---

## [Filebeat not adding kubernetes metadata](https://discuss.elastic.co/t/filebeat-not-adding-kubernetes-metadata/164232)

<div class="topic-metadata">

**Author:** [@jaininshah9](https://discuss.elastic.co/u/jaininshah9)\
**Replies:** 0\
**Last updated:** [January 15, 2019, 4:15am UTC](https://discuss.elastic.co/t/filebeat-not-adding-kubernetes-metadata/164232 "2019-01-15T04:15:53Z")

</div>

I am running a Kubernetes (v1.12.3) cluster and trying to use filebeat to get the data from docker containers. The logs works fine (for testing purpose I am sending it to just files), but there is no kubernetes metadata …

---

## [Mapper\_Parsing\_Exception After Logstash Rollback](https://discuss.elastic.co/t/mapper-parsing-exception-after-logstash-rollback/164183)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [January 14, 2019, 6:31pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-after-logstash-rollback/164183 "2019-01-14T18:31:10Z")

</div>

We recently rolled back Logstash from 6.5.4 to 6.4.1 due to issues with the geoip plugin. Since then I've seen the below log lines in logstash, the value being mapped changes but it's always the same field. How do I re…

---

## [Metricbeat Haproxy dashboards](https://discuss.elastic.co/t/metricbeat-haproxy-dashboards/162784)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 4\
**Last updated:** [January 14, 2019, 4:03pm UTC](https://discuss.elastic.co/t/metricbeat-haproxy-dashboards/162784 "2019-01-14T16:03:38Z")

</div>

Hello Team, I have configured Metricbeat Haproxy Module and i am getting the data over kibana dashboard under Metricbeat Haproxy Dashboards. I am able to see 6 dashboards for only Metricbeat Haproxy which are listed be…

---

## [Filebeat is sending log file data if i stop system module](https://discuss.elastic.co/t/filebeat-is-sending-log-file-data-if-i-stop-system-module/163740)

<div class="topic-metadata">

**Author:** [@Anand\_Rao](https://discuss.elastic.co/u/Anand_Rao)\
**Replies:** 4\
**Last updated:** [January 14, 2019, 12:42pm UTC](https://discuss.elastic.co/t/filebeat-is-sending-log-file-data-if-i-stop-system-module/163740 "2019-01-14T12:42:13Z")

</div>

filebeat is sending log file data if i stop system module. If i enable system module it is sending logs but i don't want system logs. I only logs which are written in log file.

---

## [Bytes Sent shown as 0 for beats monitoring](https://discuss.elastic.co/t/bytes-sent-shown-as-0-for-beats-monitoring/163928)

<div class="topic-metadata">

**Author:** [@Hari\_Prasad](https://discuss.elastic.co/u/Hari_Prasad)\
**Replies:** 6\
**Last updated:** [January 14, 2019, 12:10pm UTC](https://discuss.elastic.co/t/bytes-sent-shown-as-0-for-beats-monitoring/163928 "2019-01-14T12:10:02Z")

</div>

I have enabled beats monitoring by setting the below in the filebeats.yml xpack.monitoring: enabled: true elasticsearch: hosts: \["http://host1:port","http://host2:port"\] But in Kibana, though i am getting …

---

## [Filebeat Kubernetes Autodiscovery Template Problem (6.5.4)](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-template-problem-6-5-4/163916)

<div class="topic-metadata">

**Author:** [@Namik\_Mesic](https://discuss.elastic.co/u/Namik_Mesic)\
**Replies:** 2\
**Last updated:** [January 14, 2019, 11:21am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-template-problem-6-5-4/163916 "2019-01-14T11:21:31Z")

</div>

I am trying to use filebeat kubernetes with autodiscovery and templates just as shown in the documentation, however I am unable to make the templates work. What I am trying to achieve: Send logs only when ceartain ann…

---

## [Filebeat module ingest logic execution](https://discuss.elastic.co/t/filebeat-module-ingest-logic-execution/164122)

<div class="topic-metadata">

**Author:** [@ep4sh](https://discuss.elastic.co/u/ep4sh)\
**Replies:** 2\
**Last updated:** [January 14, 2019, 10:44am UTC](https://discuss.elastic.co/t/filebeat-module-ingest-logic-execution/164122 "2019-01-14T10:44:23Z")

</div>

First, im sorry for, probably, stupid q, but it is implicit for me. If i configure and run filebeat with some modules , will it increase resource consumption on Filebeat Node (current machine) or ES node (remote, in my…

---

## [Whether the filebeat enabled mysql module supports direct pass to kafka](https://discuss.elastic.co/t/whether-the-filebeat-enabled-mysql-module-supports-direct-pass-to-kafka/162389)

<div class="topic-metadata">

**Author:** [@ytc301](https://discuss.elastic.co/u/ytc301)\
**Replies:** 6\
**Last updated:** [January 14, 2019, 7:18am UTC](https://discuss.elastic.co/t/whether-the-filebeat-enabled-mysql-module-supports-direct-pass-to-kafka/162389 "2019-01-14T07:18:12Z")

</div>

I want to use the filebeat mysql module to directly pass the stream to the kafka cluster through the own pipeline, but found that the delivery is unsuccessful, the kafka cluster consumer does not generate logs, I try to …

---

## [Filebeat not pushing events to multiple Kafka broker in a single Kafka cluster](https://discuss.elastic.co/t/filebeat-not-pushing-events-to-multiple-kafka-broker-in-a-single-kafka-cluster/163250)

<div class="topic-metadata">

**Author:** [@Hari\_Prasad](https://discuss.elastic.co/u/Hari_Prasad)\
**Replies:** 1\
**Last updated:** [January 14, 2019, 3:33am UTC](https://discuss.elastic.co/t/filebeat-not-pushing-events-to-multiple-kafka-broker-in-a-single-kafka-cluster/163250 "2019-01-14T03:33:20Z")

</div>

The Filebeat in my setup pushes the events to a Kafka cluster with 2 brokers. I have added only one node in the host list but both the brokers in the cluster were discovered. I understood this from the Filebeat logs. Bu…

---

## [Create new output for neo4j](https://discuss.elastic.co/t/create-new-output-for-neo4j/164013)

<div class="topic-metadata">

**Author:** [@Ramachandran\_Duraisa](https://discuss.elastic.co/u/Ramachandran_Duraisa)\
**Replies:** 0\
**Last updated:** [January 13, 2019, 3:42am UTC](https://discuss.elastic.co/t/create-new-output-for-neo4j/164013 "2019-01-13T03:42:34Z")

</div>

Looking for a solution to create product categorization. Based on the analysis graph db (Neo4j) would be the right choice. The product source would be csv from SAP on a regular basis. reading csv data using filebeat and…

---

## [Rabbitmq plugin field problem](https://discuss.elastic.co/t/rabbitmq-plugin-field-problem/162922)

<div class="topic-metadata">

**Author:** [@Izek](https://discuss.elastic.co/u/Izek)\
**Replies:** 15\
**Last updated:** [January 12, 2019, 4:14pm UTC](https://discuss.elastic.co/t/rabbitmq-plugin-field-problem/162922 "2019-01-12T16:14:44Z")

</div>

I saw the document about rabbitmq plugin and there is field "rabbitmq.exchange.messages". But in my metricbeat with version 6.5.4-1, these fields still missing. What version will have this field added? elastic rabbitm…

---

## [Os/exec Operation Not Permitted when beats is imported](https://discuss.elastic.co/t/os-exec-operation-not-permitted-when-beats-is-imported/164006)

<div class="topic-metadata">

**Author:** [@tehmoon](https://discuss.elastic.co/u/tehmoon)\
**Replies:** 2\
**Last updated:** [January 12, 2019, 7:42pm UTC](https://discuss.elastic.co/t/os-exec-operation-not-permitted-when-beats-is-imported/164006 "2019-01-12T19:42:55Z")

</div>

Hi! It looks like when importing os/exec and using it to spawn command, on linux amd64, it fails with an Operation not permitted. This is a code sample https://play.golang.com/p/kriZT9RpYlr that you should be able to r…

---

## [Filebeats to ship data directly to AWS ElasticSearch managed service](https://discuss.elastic.co/t/filebeats-to-ship-data-directly-to-aws-elasticsearch-managed-service/163988)

<div class="topic-metadata">

**Author:** [@kejsi](https://discuss.elastic.co/u/kejsi)\
**Replies:** 3\
**Last updated:** [January 12, 2019, 11:43am UTC](https://discuss.elastic.co/t/filebeats-to-ship-data-directly-to-aws-elasticsearch-managed-service/163988 "2019-01-12T11:43:06Z")

</div>

Hi all, I already see threads that depict it as not feasible to send data to AWS ES service, since these posts are about 1 year old, I'd like to ask whether any of you has had success with this approach? I really can't…

---

## [Need help with errors during starting filebeat service, please help with verifying the yml file](https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654)

<div class="topic-metadata">

**Author:** [@clouddev](https://discuss.elastic.co/u/clouddev)\
**Replies:** 3\
**Last updated:** [January 12, 2019, 5:10am UTC](https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654 "2019-01-12T05:10:49Z")

</div>

When I am trying to start the filebeat service I get an error saying.. graylog@graylog:/etc/filebeat$ service filebeat status ● filebeat.service - filebeat Loaded: loaded (/lib/systemd/system/filebeat.service; enable…

---

## [Fields Date dd.mm.YYYY and Time 00:00:00 unable to map from String to Date formatted](https://discuss.elastic.co/t/fields-date-dd-mm-yyyy-and-time-0000-unable-to-map-from-string-to-date-formatted/163949)

<div class="topic-metadata">

**Author:** [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Replies:** 0\
**Last updated:** [January 11, 2019, 7:01pm UTC](https://discuss.elastic.co/t/fields-date-dd-mm-yyyy-and-time-0000-unable-to-map-from-string-to-date-formatted/163949 "2019-01-11T19:01:19Z")

</div>

Hi all, I'm new to the Elastic Stack and do my first steps. While all is going well Beats \> Logstash \> ES \> Kibana I'm fighting with an obviously easy question but hard for me to figure out how to. Date and Time fro…

---

## [CPU usage does not match the CPU usage in Task Manager](https://discuss.elastic.co/t/cpu-usage-does-not-match-the-cpu-usage-in-task-manager/163776)

<div class="topic-metadata">

**Author:** [@zaeemshah](https://discuss.elastic.co/u/zaeemshah)\
**Replies:** 1\
**Last updated:** [January 11, 2019, 5:37pm UTC](https://discuss.elastic.co/t/cpu-usage-does-not-match-the-cpu-usage-in-task-manager/163776 "2019-01-11T17:37:47Z")

</div>

Hi, I have just downloaded metricbeat and have successfully shipped the stats over to a third party elk saas provider. I have purposely spiked my CPU using Cpustress tool and it is remaining constantly above 85%-100% r…

---

## [Filebeat does not parse postgresql logs properly](https://discuss.elastic.co/t/filebeat-does-not-parse-postgresql-logs-properly/163569)

<div class="topic-metadata">

**Author:** [@Alexandros\_Aristopan](https://discuss.elastic.co/u/Alexandros_Aristopan)\
**Replies:** 2\
**Last updated:** [January 11, 2019, 2:42pm UTC](https://discuss.elastic.co/t/filebeat-does-not-parse-postgresql-logs-properly/163569 "2019-01-11T14:42:32Z")

</div>

Hello, I recently installed filebeat and followed the documentation to enable the postgresql module, in order to use kibana dashboards for psql. When checking ES filebeat index mappings i can see the postgres.log.(\*) f…

---

## [Failed to parse JSON response: json: cannot unmarshal string into Go struct field .Version of type struct { Number string }\]](https://discuss.elastic.co/t/failed-to-parse-json-response-json-cannot-unmarshal-string-into-go-struct-field-version-of-type-struct-number-string/163321)

<div class="topic-metadata">

**Author:** [@Bhavesh\_Padharia](https://discuss.elastic.co/u/Bhavesh_Padharia)\
**Replies:** 16\
**Last updated:** [January 11, 2019, 12:25pm UTC](https://discuss.elastic.co/t/failed-to-parse-json-response-json-cannot-unmarshal-string-into-go-struct-field-version-of-type-struct-number-string/163321 "2019-01-11T12:25:39Z")

</div>

How to solve this error? Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: \[Error connection to Elasticsearch http://localhost:9600: Failed to parse JSON response: json: cannot unmarshal …

---

## [Remote Filebeat can't send logs to Logstash](https://discuss.elastic.co/t/remote-filebeat-cant-send-logs-to-logstash/163688)

<div class="topic-metadata">

**Author:** [@Wellguys](https://discuss.elastic.co/u/Wellguys)\
**Replies:** 3\
**Last updated:** [January 11, 2019, 11:59am UTC](https://discuss.elastic.co/t/remote-filebeat-cant-send-logs-to-logstash/163688 "2019-01-11T11:59:06Z")

</div>

Hello. I'm having some problems understanding how to connect a filebeat from another server to my ELK server. I have a filebeat running on the ELK server with no issue and kibana is showing me all the logs needed, but …

---

## [Filebeats not harvesting new file](https://discuss.elastic.co/t/filebeats-not-harvesting-new-file/163400)

<div class="topic-metadata">

**Author:** [@NickRoper](https://discuss.elastic.co/u/NickRoper)\
**Replies:** 4\
**Last updated:** [January 11, 2019, 5:58am UTC](https://discuss.elastic.co/t/filebeats-not-harvesting-new-file/163400 "2019-01-11T05:58:58Z")

</div>

Hi, I'm new to the ELK stack so apologies if this is a stupid question. I've downloaded and installed the following: elasticsearch-6.5.4 kibana-6.5.4 logstash-6.5.4 filebeats-6.54 I have everything installed and have…

---

## ["INFO Non-zero metrics in the last 30s" with Winlogbeat](https://discuss.elastic.co/t/info-non-zero-metrics-in-the-last-30s-with-winlogbeat/163760)

<div class="topic-metadata">

**Author:** [@gaglimax](https://discuss.elastic.co/u/gaglimax)\
**Replies:** 1\
**Last updated:** [January 10, 2019, 3:08pm UTC](https://discuss.elastic.co/t/info-non-zero-metrics-in-the-last-30s-with-winlogbeat/163760 "2019-01-10T15:08:19Z")

</div>

Hi ! I'm trying to send Forwarded Events logs with Winlogbeat to a Logstash instance. Here is my winlogbeat.yml file : winlogbeat.event\_logs: - name: ForwardedEvents setup.kibana: host: "192.168.101.119:5601" ou…

---

## [Filebeat agent sending logs some days and it doesnt send logs somedays if i dont restart](https://discuss.elastic.co/t/filebeat-agent-sending-logs-some-days-and-it-doesnt-send-logs-somedays-if-i-dont-restart/163227)

<div class="topic-metadata">

**Author:** [@jerin](https://discuss.elastic.co/u/jerin)\
**Replies:** 3\
**Last updated:** [January 10, 2019, 1:17pm UTC](https://discuss.elastic.co/t/filebeat-agent-sending-logs-some-days-and-it-doesnt-send-logs-somedays-if-i-dont-restart/163227 "2019-01-10T13:17:28Z")

</div>

filebeat need to restart to send logs to logstash .

---

## [Creating custom filebeat module](https://discuss.elastic.co/t/creating-custom-filebeat-module/162956)

<div class="topic-metadata">

**Author:** [@ep4sh](https://discuss.elastic.co/u/ep4sh)\
**Replies:** 3\
**Last updated:** [January 10, 2019, 10:56am UTC](https://discuss.elastic.co/t/creating-custom-filebeat-module/162956 "2019-01-10T10:56:43Z")

</div>

Okay, i read https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html And i almost have done: mkdir -p ${GOPATH}/src/github.com/elastic cd ${GOPATH}/src/github.com/elastic git clone https:/…

---

## [Filebeat still process old log file](https://discuss.elastic.co/t/filebeat-still-process-old-log-file/163104)

<div class="topic-metadata">

**Author:** [@merceskoba](https://discuss.elastic.co/u/merceskoba)\
**Replies:** 4\
**Last updated:** [January 10, 2019, 9:53am UTC](https://discuss.elastic.co/t/filebeat-still-process-old-log-file/163104 "2019-01-10T09:53:45Z")

</div>

Hello guys, I have a problem and just found the root cause yesterday. So, there were Filebeat and Logrotate in an instance. When Logrotate executed, Filebeat still read the old file. Even though the file is gone. Thi…

---

## [How to setup multiple input and output in Filebeat config?](https://discuss.elastic.co/t/how-to-setup-multiple-input-and-output-in-filebeat-config/163325)

<div class="topic-metadata">

**Author:** [@ronald8192](https://discuss.elastic.co/u/ronald8192)\
**Replies:** 11\
**Last updated:** [January 10, 2019, 8:25am UTC](https://discuss.elastic.co/t/how-to-setup-multiple-input-and-output-in-filebeat-config/163325 "2019-01-10T08:25:26Z")

</div>

I need to have 2 set of input files and output target in Filebeat config. My current filebeat.yml config looks like this: filebeat.inputs: - type: log enabled: true paths: - /path/to/log-1.log filebeat.config.m…

---

## [Lambda created but no data in Elastic Cloud](https://discuss.elastic.co/t/lambda-created-but-no-data-in-elastic-cloud/163341)

<div class="topic-metadata">

**Author:** [@Ian\_Morris](https://discuss.elastic.co/u/Ian_Morris)\
**Replies:** 2\
**Last updated:** [January 10, 2019, 8:21am UTC](https://discuss.elastic.co/t/lambda-created-but-no-data-in-elastic-cloud/163341 "2019-01-10T08:21:47Z")

</div>

Hi functionbeat version 6.5.4 I have just created an Elastic Cloud trial. I am trying to use Functionbeat to send CloudWatch Logs to the Elastic Cloud trial. In this case, the CloudWatch Log I have selected contains Cl…

---

## [Filebeat not reading log files from given paths](https://discuss.elastic.co/t/filebeat-not-reading-log-files-from-given-paths/163473)

<div class="topic-metadata">

**Author:** [@yachitha](https://discuss.elastic.co/u/yachitha)\
**Replies:** 2\
**Last updated:** [January 10, 2019, 4:51am UTC](https://discuss.elastic.co/t/filebeat-not-reading-log-files-from-given-paths/163473 "2019-01-10T04:51:59Z")

</div>

I have created a docker image with ELK stack by using docker-compose. I have used filebeat to read log files, filebeat gives output to logstash and logstash gives outputs to elasticsearch and then finally elasticsearch g…

---

## [Filebeats to ship Node Application logs](https://discuss.elastic.co/t/filebeats-to-ship-node-application-logs/163597)

<div class="topic-metadata">

**Author:** [@adityak248](https://discuss.elastic.co/u/adityak248)\
**Replies:** 8\
**Last updated:** [January 9, 2019, 9:01pm UTC](https://discuss.elastic.co/t/filebeats-to-ship-node-application-logs/163597 "2019-01-09T21:01:06Z")

</div>

Hello People, I was wondering if there is any way i could ship the logs from my node app to elasticsearch. I did try doing it but for some reason logs wont show up which are mentioned in the filebeat.yml. Pretty sure i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=389)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=391)
