# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=391

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 392

---

## [Does Filebeat "churn" if input files are missing?](https://discuss.elastic.co/t/does-filebeat-churn-if-input-files-are-missing/163407)

<div class="topic-metadata">

**Author:** [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)\
**Replies:** 2\
**Last updated:** [January 9, 2019, 8:10pm UTC](https://discuss.elastic.co/t/does-filebeat-churn-if-input-files-are-missing/163407 "2019-01-09T20:10:04Z")

</div>

If I have specified a number of logfiles from which to harvest entries, something like this: filebeat.inputs: - type: log enabled: true paths: - /var/log/messages - /var/log/secure - /var/log…

---

## [Winlogbeat too slow?](https://discuss.elastic.co/t/winlogbeat-too-slow/163586)

<div class="topic-metadata">

**Author:** [@paniccontrol](https://discuss.elastic.co/u/paniccontrol)\
**Replies:** 0\
**Last updated:** [January 9, 2019, 4:53pm UTC](https://discuss.elastic.co/t/winlogbeat-too-slow/163586 "2019-01-09T16:53:55Z")

</div>

I am working on the configuration to recover the domain controllers logs : It seems that winlogbeat is slower than the speed of the logs generation. So all the Security logs going to my Elastics have one hour delay (due…

---

## [Winlogbeat Working](https://discuss.elastic.co/t/winlogbeat-working/163379)

<div class="topic-metadata">

**Author:** [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Replies:** 1\
**Last updated:** [January 9, 2019, 6:33pm UTC](https://discuss.elastic.co/t/winlogbeat-working/163379 "2019-01-09T18:33:58Z")

</div>

Hi All, How does winlogbeat works exactly, in short? Like what parameters or depending on what conditions or in any specific intervals, data is shipped from client to ELK server? As in filebeat, there is scan\_frequenc…

---

## [Logstash to filebeat correct migration](https://discuss.elastic.co/t/logstash-to-filebeat-correct-migration/162949)

<div class="topic-metadata">

**Author:** [@ep4sh](https://discuss.elastic.co/u/ep4sh)\
**Replies:** 3\
**Last updated:** [January 9, 2019, 6:24pm UTC](https://discuss.elastic.co/t/logstash-to-filebeat-correct-migration/162949 "2019-01-09T18:24:23Z")

</div>

I have ES standalone, Kibana standalone, logstash cluster, that collects data and Queue with Logstashes as a log "tailers". Main purpose - decrease resources consumption of "endpoint" log harvesters, so i need to chan…

---

## [Unable to Create new Beat based on Metricbeat](https://discuss.elastic.co/t/unable-to-create-new-beat-based-on-metricbeat/163552)

<div class="topic-metadata">

**Author:** [@Eifoen](https://discuss.elastic.co/u/Eifoen)\
**Replies:** 0\
**Last updated:** [January 9, 2019, 2:41pm UTC](https://discuss.elastic.co/t/unable-to-create-new-beat-based-on-metricbeat/163552 "2019-01-09T14:41:24Z")

</div>

Hi Folks, I spend the last 2 days trying to get up and running with my own Beat. I ended up literally installing a dedicated Ubntu 18.04 VM with: python2 (because the build script uses 'python' instead of 'python2' a…

---

## [Filebeat.yml can not convert String into Object](https://discuss.elastic.co/t/filebeat-yml-can-not-convert-string-into-object/163502)

<div class="topic-metadata">

**Author:** [@matanos](https://discuss.elastic.co/u/matanos)\
**Replies:** 3\
**Last updated:** [January 9, 2019, 11:12am UTC](https://discuss.elastic.co/t/filebeat-yml-can-not-convert-string-into-object/163502 "2019-01-09T11:12:23Z")

</div>

aI'm adding by the config file. I've used the filebeat -e -c /etc/filebeat/filebeat.yml command to debug Omitted some comments to dodge the max char count . filebeat.prospectors: Each - is a prospector. Most options…

---

## [Filebeat not reading all docker container logs](https://discuss.elastic.co/t/filebeat-not-reading-all-docker-container-logs/160801)

<div class="topic-metadata">

**Author:** [@elizajanus](https://discuss.elastic.co/u/elizajanus)\
**Replies:** 10\
**Last updated:** [January 8, 2019, 5:56pm UTC](https://discuss.elastic.co/t/filebeat-not-reading-all-docker-container-logs/160801 "2019-01-08T17:56:37Z")

</div>

Filebeat is reading some docker container logs, but not all. I checked one of the log files that was being excluded and it has been updating recently but I can't see any information for that container in Kibana. There ar…

---

## [IIS module fields](https://discuss.elastic.co/t/iis-module-fields/163203)

<div class="topic-metadata">

**Author:** [@Costi](https://discuss.elastic.co/u/Costi)\
**Replies:** 2\
**Last updated:** [January 8, 2019, 9:33am UTC](https://discuss.elastic.co/t/iis-module-fields/163203 "2019-01-08T09:33:13Z")

</div>

I have enable IIS module and ingested IIS logs directly to elasticsearch. I can see the logs in kibana but i cannot see the fields available for iis module. I have the same version for plugins as kibana and elasticsearc…

---

## [Wrong indices](https://discuss.elastic.co/t/wrong-indices/162775)

<div class="topic-metadata">

**Author:** [@fooc](https://discuss.elastic.co/u/fooc)\
**Replies:** 2\
**Last updated:** [January 8, 2019, 9:18am UTC](https://discuss.elastic.co/t/wrong-indices/162775 "2019-01-08T09:18:19Z")

</div>

Hi, When i start winlogbeat and use logstash or direct output to my elk every second an indices is created with wrong timestamps and the server crashes. I think something is wrong with the date notation but i cannot fi…

---

## [Question about log with winlogbeat and logstash](https://discuss.elastic.co/t/question-about-log-with-winlogbeat-and-logstash/163228)

<div class="topic-metadata">

**Author:** [@Thibaut603](https://discuss.elastic.co/u/Thibaut603)\
**Replies:** 2\
**Last updated:** [January 8, 2019, 8:35am UTC](https://discuss.elastic.co/t/question-about-log-with-winlogbeat-and-logstash/163228 "2019-01-08T08:35:59Z")

</div>

Hello, I'm student and i need to collect log on Active directory so i will install winlogbeat on it to send event log on logstash but i've a question because this AD is very sensitive pour the enterprise. My question …

---

## [Multiline in TCP input](https://discuss.elastic.co/t/multiline-in-tcp-input/161279)

<div class="topic-metadata">

**Author:** [@elmar.vonlanthen](https://discuss.elastic.co/u/elmar.vonlanthen)\
**Replies:** 2\
**Last updated:** [January 8, 2019, 7:12am UTC](https://discuss.elastic.co/t/multiline-in-tcp-input/161279 "2019-01-08T07:12:17Z")

</div>

Hello I am wondering, if it is possible to use multiline parsing in TCP input. In my tests it is not working. But in UDP input, multiline parsing is working (but not recommended). Filebeat version: 6.5.3 OS: CentOS 7.…

---

## [Metricbeats Windows metricset Invalid data](https://discuss.elastic.co/t/metricbeats-windows-metricset-invalid-data/161040)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 10\
**Last updated:** [January 7, 2019, 6:30pm UTC](https://discuss.elastic.co/t/metricbeats-windows-metricset-invalid-data/161040 "2019-01-07T18:30:46Z")

</div>

Hi- I'm using Windows metricset to collect perfmon data, but I noticed some unreal data for couple of counters which I noticed this in the wildcard query (\*), where as value of \_Total shows 345 but for a single process …

---

## [Issue creating Countbeat aarch64](https://discuss.elastic.co/t/issue-creating-countbeat-aarch64/163208)

<div class="topic-metadata">

**Author:** [@david\_evans](https://discuss.elastic.co/u/david_evans)\
**Replies:** 1\
**Last updated:** [January 7, 2019, 4:02pm UTC](https://discuss.elastic.co/t/issue-creating-countbeat-aarch64/163208 "2019-01-07T16:02:14Z")

</div>

Hi, guys. Apologies if this is not appropriate, I just feel like I'm falling over at the first hurdle... I'm following the tutorial Create your own beat but when it comes to actually building it I am getting no where..…

---

## [How to configure different machine servers log in filebeat and send it to logstash](https://discuss.elastic.co/t/how-to-configure-different-machine-servers-log-in-filebeat-and-send-it-to-logstash/162597)

<div class="topic-metadata">

**Author:** [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Replies:** 7\
**Last updated:** [January 7, 2019, 3:47pm UTC](https://discuss.elastic.co/t/how-to-configure-different-machine-servers-log-in-filebeat-and-send-it-to-logstash/162597 "2019-01-07T15:47:25Z")

</div>

Hi All, I'm trying to get logs (not syslog) from different machine servers and want to send those logs to logstash to elasticsearch to kibana. but in kibana I'm getting only system logs not other logs that I'm expecting…

---

## [Controlling harvester settings on kubernetes autodiscovery](https://discuss.elastic.co/t/controlling-harvester-settings-on-kubernetes-autodiscovery/163226)

<div class="topic-metadata">

**Author:** [@kstoney](https://discuss.elastic.co/u/kstoney)\
**Replies:** 0\
**Last updated:** [January 7, 2019, 2:37pm UTC](https://discuss.elastic.co/t/controlling-harvester-settings-on-kubernetes-autodiscovery/163226 "2019-01-07T14:37:50Z")

</div>

Hi, I'm wanting to set the following settings on my kubernetes log file ingestion: close\_inactive: 10s harvester\_limit: 10 However, I can't work out where to put them as the documentation only covers them on on the lo…

---

## [How to save multiple index data into one index in metricbeat](https://discuss.elastic.co/t/how-to-save-multiple-index-data-into-one-index-in-metricbeat/163037)

<div class="topic-metadata">

**Author:** [@karthick\_tgi](https://discuss.elastic.co/u/karthick_tgi)\
**Replies:** 2\
**Last updated:** [January 7, 2019, 10:00am UTC](https://discuss.elastic.co/t/how-to-save-multiple-index-data-into-one-index-in-metricbeat/163037 "2019-01-07T10:00:09Z")

</div>

Hi Team, In metricbeat we have multiple index and we can store all the existing index data into one index. Is there any option to config this please let me know Metricbear version : 6x above Thanks and regards, Kart…

---

## ['Start-Service' is not recognized as an internal or external command, operable program or batch file](https://discuss.elastic.co/t/start-service-is-not-recognized-as-an-internal-or-external-command-operable-program-or-batch-file/163095)

<div class="topic-metadata">

**Author:** [@ahmer\_haque](https://discuss.elastic.co/u/ahmer_haque)\
**Replies:** 2\
**Last updated:** [January 7, 2019, 5:43am UTC](https://discuss.elastic.co/t/start-service-is-not-recognized-as-an-internal-or-external-command-operable-program-or-batch-file/163095 "2019-01-07T05:43:05Z")

</div>

\-/var/log/.log #-C:/Program Files/elasticsearch/logs/ can u please help me to sort this problem? Exiting: No paths were defined for input accessing config Exiting: No paths were defined for input accessing config

---

## [\[Error\] pipeline/output.go:74 Failed to connect: dial tcp](https://discuss.elastic.co/t/error-pipeline-output-go-74-failed-to-connect-dial-tcp/162222)

<div class="topic-metadata">

**Author:** [@Waranon](https://discuss.elastic.co/u/Waranon)\
**Replies:** 2\
**Last updated:** [January 5, 2019, 1:38pm UTC](https://discuss.elastic.co/t/error-pipeline-output-go-74-failed-to-connect-dial-tcp/162222 "2019-01-05T13:38:23Z")

</div>

I got Failed to connect: dial tcp x.x.x.x:5044: getsockopt: connection refused /etc/filebeat/filebeat.yml filebeat.prospectors: input\_type: log paths: /var/log/cms/\*.log output.logstash: hosts: \["x.x.x.x:5044"\] …

---

## [Filebeat missing authentication](https://discuss.elastic.co/t/filebeat-missing-authentication/162151)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 18\
**Last updated:** [January 5, 2019, 4:54am UTC](https://discuss.elastic.co/t/filebeat-missing-authentication/162151 "2019-01-05T04:54:06Z")

</div>

hi all, kindly, i installed filebeat, elasticsearch and kibana in my VMware; notably i am not using logstash. After that, i installed X-pack for kibana and elasticsearch,when i start elasticsearch and kibana, kibana con…

---

## [Unknown target specified: setup](https://discuss.elastic.co/t/unknown-target-specified-setup/160713)

<div class="topic-metadata">

**Author:** [@fillic2002](https://discuss.elastic.co/u/fillic2002)\
**Replies:** 9\
**Last updated:** [January 5, 2019, 2:00am UTC](https://discuss.elastic.co/t/unknown-target-specified-setup/160713 "2019-01-05T02:00:40Z")

</div>

Hi There, I am trying to create a custom beat and getting below mentioned error while running "make setup" command. ref: https://www.elastic.co/guide/en/beats/devguide/current/setting-up-beat.html "Unknown target speci…

---

## [Mapping definition for \[body\] has unsupported parameters](https://discuss.elastic.co/t/mapping-definition-for-body-has-unsupported-parameters/161765)

<div class="topic-metadata">

**Author:** [@Zorkmid](https://discuss.elastic.co/u/Zorkmid)\
**Replies:** 7\
**Last updated:** [January 5, 2019, 12:03am UTC](https://discuss.elastic.co/t/mapping-definition-for-body-has-unsupported-parameters/161765 "2019-01-05T00:03:43Z")

</div>

Hello All, I've got the follow setup installed: packetbeat-6.5.4-1.x86\_64 (installed on 2 different downstream servers) elasticsearch-6.5.4-1.noarch (installed on 6 physical servers - setup as 3 data and 3 masters) k…

---

## [Heartbeat scalability](https://discuss.elastic.co/t/heartbeat-scalability/162912)

<div class="topic-metadata">

**Author:** [@dorry](https://discuss.elastic.co/u/dorry)\
**Replies:** 3\
**Last updated:** [January 4, 2019, 11:07pm UTC](https://discuss.elastic.co/t/heartbeat-scalability/162912 "2019-01-04T23:07:09Z")

</div>

Hello, i was wondering if i could seek some advice please. We have a use case for Heartbeat to monitor ICMP ping reachability around 25,000 network devices. Does anyone have any insight or best practices on how to make…

---

## [Heartbeat check against websocket URL](https://discuss.elastic.co/t/heartbeat-check-against-websocket-url/160033)

<div class="topic-metadata">

**Author:** [@Franz\_Allan\_Valencia](https://discuss.elastic.co/u/Franz_Allan_Valencia)\
**Replies:** 2\
**Last updated:** [January 4, 2019, 9:57pm UTC](https://discuss.elastic.co/t/heartbeat-check-against-websocket-url/160033 "2019-01-04T21:57:01Z")

</div>

Hi, Is there a way I can check my webservice's websocket's "heartbeat"? I just want heartbeat to be able to connect to a websocket URL and verify a JSON response. I'm currently trying this but its failing - type: http…

---

## [Kibana dashboard import: failed to parse field visualization.kibanaSavedObjectMeta.searchSourceJSON](https://discuss.elastic.co/t/kibana-dashboard-import-failed-to-parse-field-visualization-kibanasavedobjectmeta-searchsourcejson/162169)

<div class="topic-metadata">

**Author:** [@matoro](https://discuss.elastic.co/u/matoro)\
**Replies:** 7\
**Last updated:** [January 4, 2019, 7:52pm UTC](https://discuss.elastic.co/t/kibana-dashboard-import-failed-to-parse-field-visualization-kibanasavedobjectmeta-searchsourcejson/162169 "2019-01-04T19:52:42Z")

</div>

Hi, just got filebeat installed with modules and pregenerated dashboards via make fields and make kibana. When trying to run for the first time with setup.dashboards.enabled: true, all dashboards error out with the foll…

---

## [Exclude\_line regex](https://discuss.elastic.co/t/exclude-line-regex/161645)

<div class="topic-metadata">

**Author:** [@Miguel\_Leite](https://discuss.elastic.co/u/Miguel_Leite)\
**Replies:** 6\
**Last updated:** [January 4, 2019, 3:21pm UTC](https://discuss.elastic.co/t/exclude-line-regex/161645 "2019-01-04T15:21:36Z")

</div>

NetState 47880 2018/12/20 08:44:02.422 StateManagerComponent ERROR - ProcessConfirmBlock - Unknown blockUid Does anyone know how to match by regex: StateManagerComponent ERROR - ProcessConfirmBlock - Unknown blockUid

---

## [Creating an index for each Docker container log using Filebeats](https://discuss.elastic.co/t/creating-an-index-for-each-docker-container-log-using-filebeats/162873)

<div class="topic-metadata">

**Author:** [@Joseph\_Gange](https://discuss.elastic.co/u/Joseph_Gange)\
**Replies:** 4\
**Last updated:** [January 4, 2019, 2:59pm UTC](https://discuss.elastic.co/t/creating-an-index-for-each-docker-container-log-using-filebeats/162873 "2019-01-04T14:59:54Z")

</div>

I'm using Filebeats to capture and send my Docker container logs to Elasticsearch. I am adding the Docker metadata and I would like to name each index with the associated service name. Based on the default template, I wa…

---

## [Central Management filebeat enrollment fail](https://discuss.elastic.co/t/central-management-filebeat-enrollment-fail/160412)

<div class="topic-metadata">

**Author:** [@GregoryB-T](https://discuss.elastic.co/u/GregoryB-T)\
**Replies:** 4\
**Last updated:** [January 4, 2019, 1:50pm UTC](https://discuss.elastic.co/t/central-management-filebeat-enrollment-fail/160412 "2019-01-04T13:50:41Z")

</div>

Hi I'm trying to enroll filebeat to the Central Management but since I use a custom cert I have this error Error while enrolling: fail to execute the HTTP POST request: Post https://+++++++++/api/beats/agent/++++-++++…

---

## [How to deploy Kibana with preconfigured index pattern](https://discuss.elastic.co/t/how-to-deploy-kibana-with-preconfigured-index-pattern/161555)

<div class="topic-metadata">

**Author:** [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)\
**Replies:** 6\
**Last updated:** [January 4, 2019, 2:12pm UTC](https://discuss.elastic.co/t/how-to-deploy-kibana-with-preconfigured-index-pattern/161555 "2019-01-04T14:12:27Z")

</div>

I'm trying to make the leap between developing and using ELK (plus Filebeat) to deploying it. I need to deploy Kibana in such a way as to have index pattern "filebeat-\*" already configured/resident in Kibana so that user…

---

## [Winlogbeat record\_number sequnetial count](https://discuss.elastic.co/t/winlogbeat-record-number-sequnetial-count/162690)

<div class="topic-metadata">

**Author:** [@chris\_lawrence](https://discuss.elastic.co/u/chris_lawrence)\
**Replies:** 2\
**Last updated:** [January 4, 2019, 1:28pm UTC](https://discuss.elastic.co/t/winlogbeat-record-number-sequnetial-count/162690 "2019-01-04T13:28:23Z")

</div>

Hi we want to analyse how to use winlogbeat to monitor security as a replacement to splunk at the moment we have numerous questions on how to migrate from splunk to elasticsearch one question is how do we monitor the …

---

## [Best way to test locally](https://discuss.elastic.co/t/best-way-to-test-locally/162942)

<div class="topic-metadata">

**Author:** [@yorkshirestingo](https://discuss.elastic.co/u/yorkshirestingo)\
**Replies:** 1\
**Last updated:** [January 4, 2019, 1:18pm UTC](https://discuss.elastic.co/t/best-way-to-test-locally/162942 "2019-01-04T13:18:39Z")

</div>

Hi all, I've decided to use Functionbeat for a new project but to sell it to my team I've been trying to set up a local example using docker-compose running Localstack and elk together; my vision was to deploy functionb…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=390)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=392)
