# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=392

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 393

---

## [Filebeat setup --dashboards](https://discuss.elastic.co/t/filebeat-setup-dashboards/160961)

<div class="topic-metadata">

**Author:** [@Thibault](https://discuss.elastic.co/u/Thibault)\
**Replies:** 3\
**Last updated:** [January 4, 2019, 12:16pm UTC](https://discuss.elastic.co/t/filebeat-setup-dashboards/160961 "2019-01-04T12:16:28Z")

</div>

Hi everybody ! I'm a french student and i try to install ELK. I found this tuto: https://github.com/justmeandopensource/elk/blob/master/INSTALL-CentOS7.md I follow it, all works but when i try this command: filebeat …

---

## [Can i send multiple line log directly to elastic search using file beat?](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900)

<div class="topic-metadata">

**Author:** [@Mayurbiw](https://discuss.elastic.co/u/Mayurbiw)\
**Replies:** 8\
**Last updated:** [January 4, 2019, 11:34am UTC](https://discuss.elastic.co/t/can-i-send-multiple-line-log-directly-to-elastic-search-using-file-beat/162900 "2019-01-04T11:34:23Z")

</div>

consider this scenario - This is log file (Directly taken from example conf files in file beat reference) Exception in thread "main" java.lang.NullPointerException at com.example.myproject.Book.getTitle(Book.java:16…

---

## [Filebeat - how control level nested json object parsing - decode\_json\_fields](https://discuss.elastic.co/t/filebeat-how-control-level-nested-json-object-parsing-decode-json-fields/162876)

<div class="topic-metadata">

**Author:** [@azhurbilo](https://discuss.elastic.co/u/azhurbilo)\
**Replies:** 1\
**Last updated:** [January 4, 2019, 10:47am UTC](https://discuss.elastic.co/t/filebeat-how-control-level-nested-json-object-parsing-decode-json-fields/162876 "2019-01-04T10:47:02Z")

</div>

Filebeat - how can I control level of decode\_json\_fields ? max\_depth seems not help in my case :frowning: goal: parsing '/var/lib/docker/containers/\*/\*.log' but controlling max json depth name: "host-01" queue: mem…

---

## [Request for this panel failed for metricbeat dashboard](https://discuss.elastic.co/t/request-for-this-panel-failed-for-metricbeat-dashboard/161793)

<div class="topic-metadata">

**Author:** [@sourav\_dixit](https://discuss.elastic.co/u/sourav_dixit)\
**Replies:** 3\
**Last updated:** [January 4, 2019, 7:53am UTC](https://discuss.elastic.co/t/request-for-this-panel-failed-for-metricbeat-dashboard/161793 "2019-01-04T07:53:02Z")

</div>

For metricbeat system dashboard , on selecting for last 24 hours there is no issue and every visualization is loading as per expectation. Please see the screenshot: But Once I am trying to visualize for last 7 days , …

---

## [Compiling certain version](https://discuss.elastic.co/t/compiling-certain-version/162832)

<div class="topic-metadata">

**Author:** [@lifeofguenter](https://discuss.elastic.co/u/lifeofguenter)\
**Replies:** 3\
**Last updated:** [January 4, 2019, 6:36am UTC](https://discuss.elastic.co/t/compiling-certain-version/162832 "2019-01-04T06:36:15Z")

</div>

I followed the following instructions to compile beats from source: https://discuss.elastic.co/t/building-filebeat-from-source/135559 It works, but even though I downloaded 6.5.4, when outputting the version I get: ~/T…

---

## [Missing Available Fields after Update](https://discuss.elastic.co/t/missing-available-fields-after-update/162536)

<div class="topic-metadata">

**Author:** [@bfrd](https://discuss.elastic.co/u/bfrd)\
**Replies:** 3\
**Last updated:** [January 3, 2019, 10:14pm UTC](https://discuss.elastic.co/t/missing-available-fields-after-update/162536 "2019-01-03T22:14:11Z")

</div>

Hello, Recently upgraded elastic stack and filebeat on clients from around 6.5.1 to 6.5.3. We use the system filebeat module. In Kibana \> Discover I can still search using terms like "system.auth.user: root" but system.…

---

## [Packetbeat capture HAPROXY TCP data](https://discuss.elastic.co/t/packetbeat-capture-haproxy-tcp-data/162814)

<div class="topic-metadata">

**Author:** [@rangana.minesh](https://discuss.elastic.co/u/rangana.minesh)\
**Replies:** 0\
**Last updated:** [January 3, 2019, 1:24pm UTC](https://discuss.elastic.co/t/packetbeat-capture-haproxy-tcp-data/162814 "2019-01-03T13:24:03Z")

</div>

Hi , Is there any more accurate way capture HAproxy TCP data using packetbeat. I know flow type is there, but it doesn't give much information. I need to capture haproxy frond and back pools which connecting via TCP.

---

## [Metricbeat module question - Does the module need to be enabled before you have use it?](https://discuss.elastic.co/t/metricbeat-module-question-does-the-module-need-to-be-enabled-before-you-have-use-it/162864)

<div class="topic-metadata">

**Author:** [@mickmill54](https://discuss.elastic.co/u/mickmill54)\
**Replies:** 1\
**Last updated:** [January 3, 2019, 7:18pm UTC](https://discuss.elastic.co/t/metricbeat-module-question-does-the-module-need-to-be-enabled-before-you-have-use-it/162864 "2019-01-03T19:18:35Z")

</div>

Do I need to enable a module before I use it or can enabling the module be controlled in the metricbeat.yml config file? for example: do I need to do this first? ./metricbeat modules enable windows or is this the sa…

---

## [How to configure multiple sql instance in windows/metricbeat.yml](https://discuss.elastic.co/t/how-to-configure-multiple-sql-instance-in-windows-metricbeat-yml/161978)

<div class="topic-metadata">

**Author:** [@Akila](https://discuss.elastic.co/u/Akila)\
**Replies:** 2\
**Last updated:** [January 3, 2019, 6:26pm UTC](https://discuss.elastic.co/t/how-to-configure-multiple-sql-instance-in-windows-metricbeat-yml/161978 "2019-01-03T18:26:45Z")

</div>

We have installed metricbeat in windows and configured perfmon entry in windows.yml file to capture SQL instance ( MSSQL ) counters for single instance. In windows.yml file we hot-coded instance name under "instance\_nam…

---

## [Filebeat Exclude\_lines config not working](https://discuss.elastic.co/t/filebeat-exclude-lines-config-not-working/160761)

<div class="topic-metadata">

**Author:** [@Miguel\_Leite](https://discuss.elastic.co/u/Miguel_Leite)\
**Replies:** 4\
**Last updated:** [January 3, 2019, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-config-not-working/160761 "2019-01-03T14:48:25Z")

</div>

Hello, I'm trying to ignore some log lines using Filebeat: exclude\_lines: \['StateManagerComponent\[\[:space:\]\]ERROR - ProcessConfirmBlock - Unknown blockUid'\] This is supposed to match and exclude this specific log line…

---

## [Dynamic Index Name Creation Based on Updated @Timestamp Field](https://discuss.elastic.co/t/dynamic-index-name-creation-based-on-updated-timestamp-field/162178)

<div class="topic-metadata">

**Author:** [@devops\_mike](https://discuss.elastic.co/u/devops_mike)\
**Replies:** 3\
**Last updated:** [January 3, 2019, 2:45pm UTC](https://discuss.elastic.co/t/dynamic-index-name-creation-based-on-updated-timestamp-field/162178 "2019-01-03T14:45:29Z")

</div>

We would like to process old IIS Log files and have the data stored in indices that correspond to the event's date, and not the date which it was harvested. We are using version 6.5.3 for Elasticsearch, Filebeats, and th…

---

## [1. Redis Connections from beats agent 2. How beat behave when redis is full](https://discuss.elastic.co/t/1-redis-connections-from-beats-agent-2-how-beat-behave-when-redis-is-full/161903)

<div class="topic-metadata">

**Author:** [@Karthik\_Ramachandran](https://discuss.elastic.co/u/Karthik_Ramachandran)\
**Replies:** 3\
**Last updated:** [January 3, 2019, 2:44pm UTC](https://discuss.elastic.co/t/1-redis-connections-from-beats-agent-2-how-beat-behave-when-redis-is-full/161903 "2019-01-03T14:44:05Z")

</div>

All Trying to understand how many connections beats would make to redis (To rightsize redis from connection perspective) Setup: Azure Redis Sending data using Filebeat and Metricbeat from Linux Systems. Filebeat is en…

---

## [Beats monitoring and central management through Logstash](https://discuss.elastic.co/t/beats-monitoring-and-central-management-through-logstash/161661)

<div class="topic-metadata">

**Author:** [@admlko](https://discuss.elastic.co/u/admlko)\
**Replies:** 2\
**Last updated:** [January 3, 2019, 1:39pm UTC](https://discuss.elastic.co/t/beats-monitoring-and-central-management-through-logstash/161661 "2019-01-03T13:39:38Z")

</div>

Hi, We have deployed multiple Logstash instances to separate geolocations and there are multiple Beats instances connected to each Logstash instance in their own geolocation. In a way, it is a distributed setup to diffe…

---

## [Kubernetes autodiscover sending logs from only some of the identical nodes in one of our clusters](https://discuss.elastic.co/t/kubernetes-autodiscover-sending-logs-from-only-some-of-the-identical-nodes-in-one-of-our-clusters/162520)

<div class="topic-metadata">

**Author:** [@benbertrands](https://discuss.elastic.co/u/benbertrands)\
**Replies:** 8\
**Last updated:** [January 3, 2019, 1:14pm UTC](https://discuss.elastic.co/t/kubernetes-autodiscover-sending-logs-from-only-some-of-the-identical-nodes-in-one-of-our-clusters/162520 "2019-01-03T13:14:49Z")

</div>

Hi, We're running filebeat as a deamonset on all nodes of our on-premises kubernetes clusters. (Filebeat sends logs to logstash, logstash does some processesing and sends them on to elasticsearch.) On one of our clust…

---

## [Logging messages sent to rabbitmq with packetbeat](https://discuss.elastic.co/t/logging-messages-sent-to-rabbitmq-with-packetbeat/162646)

<div class="topic-metadata">

**Author:** [@alek](https://discuss.elastic.co/u/alek)\
**Replies:** 4\
**Last updated:** [January 3, 2019, 12:01pm UTC](https://discuss.elastic.co/t/logging-messages-sent-to-rabbitmq-with-packetbeat/162646 "2019-01-03T12:01:37Z")

</div>

We try to setup packetbeat to 6.5.4 to parse AMQP protocol. However we don't see messages body sent to Elastic and indexed. Do we miss something ?

---

## [Custom index name for Filebeat System module output](https://discuss.elastic.co/t/custom-index-name-for-filebeat-system-module-output/161892)

<div class="topic-metadata">

**Author:** [@thethomp](https://discuss.elastic.co/u/thethomp)\
**Replies:** 1\
**Last updated:** [January 3, 2019, 11:57am UTC](https://discuss.elastic.co/t/custom-index-name-for-filebeat-system-module-output/161892 "2019-01-03T11:57:06Z")

</div>

Hello, I'm new to using modules with filebeat, but I'm interested in using the System module to write out syslogs from my Centos7 servers to ES. It looks like by default it will just write to the standard filebeat-\* ind…

---

## [Use environmental variables in filebeat configuration?](https://discuss.elastic.co/t/use-environmental-variables-in-filebeat-configuration/162772)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 2\
**Last updated:** [January 3, 2019, 9:28am UTC](https://discuss.elastic.co/t/use-environmental-variables-in-filebeat-configuration/162772 "2019-01-03T09:28:26Z")

</div>

Hi, I would like to add some fields to some log inputs. Lets say I have an environmental variable path1=my\_first\_instance Is it possible to configure something like this in the input configuration? fields: instanc…

---

## [Unable to understand func Asset in Filebeat modules codebase](https://discuss.elastic.co/t/unable-to-understand-func-asset-in-filebeat-modules-codebase/162549)

<div class="topic-metadata">

**Author:** [@skbly7](https://discuss.elastic.co/u/skbly7)\
**Replies:** 2\
**Last updated:** [January 3, 2019, 8:34am UTC](https://discuss.elastic.co/t/unable-to-understand-func-asset-in-filebeat-modules-codebase/162549 "2019-01-03T08:34:42Z")

</div>

Hi, Possible noob question as I am newbie to Beats codebase. I was trying to go through source code and understand how FileBeat modules work specifically. I came across func Asset during the same which I couldn't unde…

---

## [Filebeat alternative on RHEL5](https://discuss.elastic.co/t/filebeat-alternative-on-rhel5/162658)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 4\
**Last updated:** [January 3, 2019, 8:12am UTC](https://discuss.elastic.co/t/filebeat-alternative-on-rhel5/162658 "2019-01-03T08:12:34Z")

</div>

Hi, I am introducing the elastic stack into different project in our company. Unfortunately we are using here some older versions of redhat (5.6), where filebeat is currently not running because the kernel is too old. …

---

## [Winlogbeat wont send logs](https://discuss.elastic.co/t/winlogbeat-wont-send-logs/162288)

<div class="topic-metadata">

**Author:** [@kevin.baker](https://discuss.elastic.co/u/kevin.baker)\
**Replies:** 2\
**Last updated:** [January 2, 2019, 7:01pm UTC](https://discuss.elastic.co/t/winlogbeat-wont-send-logs/162288 "2019-01-02T19:01:13Z")

</div>

Forgive me, Ive been using Elk for less than a week. i am trying to get windows logs forwarded to Logstash, but cant seem to get them to go. I have seen a few different setups with SSL Certs and what not, are those requi…

---

## [Latest Release Has Incorrect Version](https://discuss.elastic.co/t/latest-release-has-incorrect-version/162483)

<div class="topic-metadata">

**Author:** [@TheDarkula](https://discuss.elastic.co/u/TheDarkula)\
**Replies:** 2\
**Last updated:** [January 2, 2019, 7:00pm UTC](https://discuss.elastic.co/t/latest-release-has-incorrect-version/162483 "2019-01-02T19:00:11Z")

</div>

When building from the latest release, the output of filebeat version is filebeat version 6.5.5 (amd64), libbeat 6.5.5, not the expected 6.5.4

---

## [Winlogbeat doesn't connect to logstash server but filebeat does](https://discuss.elastic.co/t/winlogbeat-doesnt-connect-to-logstash-server-but-filebeat-does/160511)

<div class="topic-metadata">

**Author:** [@nu11ahnung](https://discuss.elastic.co/u/nu11ahnung)\
**Replies:** 1\
**Last updated:** [January 2, 2019, 6:55pm UTC](https://discuss.elastic.co/t/winlogbeat-doesnt-connect-to-logstash-server-but-filebeat-does/160511 "2019-01-02T18:55:14Z")

</div>

When I run winlogbeat I get this Error ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://l92.168.0.86:5044)): lookup 192.168.0.86: no such host which is kinda weird since Test-NetConnection 192.168…

---

## [Filebeat Management - Output Configuration Block not saving](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380)

<div class="topic-metadata">

**Author:** [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Replies:** 21\
**Last updated:** [January 2, 2019, 6:35pm UTC](https://discuss.elastic.co/t/filebeat-management-output-configuration-block-not-saving/161380 "2019-01-02T18:35:48Z")

</div>

Hi, I'm using filebeat centralized management, and things are setting properly. But when I try to create a new beat tag with Output configuration block in Kibana UI it hanged in saving page and not saving it for me. …

---

## [How to log tls data in flow](https://discuss.elastic.co/t/how-to-log-tls-data-in-flow/162499)

<div class="topic-metadata">

**Author:** [@mrspring](https://discuss.elastic.co/u/mrspring)\
**Replies:** 1\
**Last updated:** [January 2, 2019, 3:48pm UTC](https://discuss.elastic.co/t/how-to-log-tls-data-in-flow/162499 "2019-01-02T15:48:05Z")

</div>

Currently, I can see the following flows EthFlow OutterVlanFlow VLanFlow OutterIPv4Flow IPv4Flow OutterIPv6Flow IPv6Flow ICMPv4Flow ICMPv6Flow UDPFlow TCPFlow Is there any way to support TLSFlow? I need some …

---

## [Access connection data using flow Id](https://discuss.elastic.co/t/access-connection-data-using-flow-id/162507)

<div class="topic-metadata">

**Author:** [@mrspring](https://discuss.elastic.co/u/mrspring)\
**Replies:** 1\
**Last updated:** [January 2, 2019, 3:47pm UTC](https://discuss.elastic.co/t/access-connection-data-using-flow-id/162507 "2019-01-02T15:47:46Z")

</div>

Hi there I need to support TLS data in flow. Is it possible to get packets data to extract connection from protos.ProtocolData and then extract TLS data from connection.

---

## [Central Management and Docker](https://discuss.elastic.co/t/central-management-and-docker/162654)

<div class="topic-metadata">

**Author:** [@Rasmus\_Fredensborg\_J](https://discuss.elastic.co/u/Rasmus_Fredensborg_J)\
**Replies:** 3\
**Last updated:** [January 2, 2019, 2:27pm UTC](https://discuss.elastic.co/t/central-management-and-docker/162654 "2019-01-02T14:27:16Z")

</div>

Hi, Thank you for your amazing products. I'm trying to use Central Management to configure filebeats that run in their own Docker containers. The problem is that the filebeat containers may restart, and when this happen…

---

## [Configuring pipeline in filebeat module - nginx](https://discuss.elastic.co/t/configuring-pipeline-in-filebeat-module-nginx/162561)

<div class="topic-metadata">

**Author:** [@crazywizard](https://discuss.elastic.co/u/crazywizard)\
**Replies:** 3\
**Last updated:** [January 2, 2019, 2:12pm UTC](https://discuss.elastic.co/t/configuring-pipeline-in-filebeat-module-nginx/162561 "2019-01-02T14:12:35Z")

</div>

I'm trying to figure out how to configure a pipeline in my nginx filebeat module. This link https://www.elastic.co/guide/en/beats/filebeat/master/configuring-ingest-node.html shows a general top-level configuration for …

---

## [Store SSL/TLS configuration directly in beat configuration file](https://discuss.elastic.co/t/store-ssl-tls-configuration-directly-in-beat-configuration-file/162183)

<div class="topic-metadata">

**Author:** [@nick-george](https://discuss.elastic.co/u/nick-george)\
**Replies:** 3\
**Last updated:** [January 2, 2019, 1:31pm UTC](https://discuss.elastic.co/t/store-ssl-tls-configuration-directly-in-beat-configuration-file/162183 "2019-01-02T13:31:53Z")

</div>

Apologies if this has already been asked and answered (I couldn't find it). Is it possible to store TLS certificate & key data directly in the beat configuration files (e.g filebeat.yml)? For example: output.elasticse…

---

## [Not reading /var/lib/docker/containers?](https://discuss.elastic.co/t/not-reading-var-lib-docker-containers/162446)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [January 2, 2019, 1:28pm UTC](https://discuss.elastic.co/t/not-reading-var-lib-docker-containers/162446 "2019-01-02T13:28:56Z")

</div>

Am hoping to use filebeat to get stdout from my containers running on kubernetes. So far no luck here. Looking at filesystem on kubernetes hosts I see that /var/lib/docker/containers has permissions only for root drwx-…

---

## [How to combine two lines based on the pattern](https://discuss.elastic.co/t/how-to-combine-two-lines-based-on-the-pattern/162338)

<div class="topic-metadata">

**Author:** [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Replies:** 1\
**Last updated:** [January 2, 2019, 12:54pm UTC](https://discuss.elastic.co/t/how-to-combine-two-lines-based-on-the-pattern/162338 "2019-01-02T12:54:20Z")

</div>

I have the input logs like this: C1 is completed on 2018-12-27. C2 is running. Now it is 2018-12-28. What I want to output to ES is: C1: 2018-12-27 C2: 2018-12-28 Basically it needs to combine line #2 and #3 into …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=391)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=393)
