# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=393

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 394

---

## [Limiting number of CPU usage in filebeat](https://discuss.elastic.co/t/limiting-number-of-cpu-usage-in-filebeat/161490)

<div class="topic-metadata">

**Author:** [@Rishav\_Anand](https://discuss.elastic.co/u/Rishav_Anand)\
**Replies:** 6\
**Last updated:** [January 2, 2019, 12:53pm UTC](https://discuss.elastic.co/t/limiting-number-of-cpu-usage-in-filebeat/161490 "2019-01-02T12:53:49Z")

</div>

I want to limit the CPU usage by filebeat . I have tried using "max\_procs" but it doesn't seem to work . This high CPU usage may affect the performance of my app in production . My filebeat.yml is same as this link but …

---

## [Multiline containing xml , Not working](https://discuss.elastic.co/t/multiline-containing-xml-not-working/162477)

<div class="topic-metadata">

**Author:** [@Ani](https://discuss.elastic.co/u/Ani)\
**Replies:** 1\
**Last updated:** [January 2, 2019, 11:25am UTC](https://discuss.elastic.co/t/multiline-containing-xml-not-working/162477 "2019-01-02T11:25:17Z")

</div>

I am trying to parse xml logs which are in multiline format. The pattern works fine when I checked on The Go Playground , but not working when I actually start filebeat. Input log: 2018-12-31 08:49:42,529 DEBUG AAA 2b…

---

## [Filebeat memory](https://discuss.elastic.co/t/filebeat-memory/162612)

<div class="topic-metadata">

**Author:** [@396175371](https://discuss.elastic.co/u/396175371)\
**Replies:** 1\
**Last updated:** [January 2, 2019, 11:04am UTC](https://discuss.elastic.co/t/filebeat-memory/162612 "2019-01-02T11:04:23Z")

</div>

Filebeat memory usage Is there a calculation formula?

---

## [Filebeat and Nginx module - wrong data types in ES](https://discuss.elastic.co/t/filebeat-and-nginx-module-wrong-data-types-in-es/162505)

<div class="topic-metadata">

**Author:** [@JohnParson](https://discuss.elastic.co/u/JohnParson)\
**Replies:** 3\
**Last updated:** [January 2, 2019, 6:23am UTC](https://discuss.elastic.co/t/filebeat-and-nginx-module-wrong-data-types-in-es/162505 "2019-01-02T06:23:36Z")

</div>

I'm using Nginx module in my Filebeat agent and sending data straight to ES. All data is sent correctly but there are some issues with data types. Almost all are using "text" data type. For example nginx.access.user\_agen…

---

## [Prometheus module is not working](https://discuss.elastic.co/t/prometheus-module-is-not-working/161988)

<div class="topic-metadata">

**Author:** [@oldcodeoberyn](https://discuss.elastic.co/u/oldcodeoberyn)\
**Replies:** 1\
**Last updated:** [December 31, 2018, 10:18pm UTC](https://discuss.elastic.co/t/prometheus-module-is-not-working/161988 "2018-12-31T22:18:00Z")

</div>

I test on V6.4.3 and V6.5.0. First of all, the configuration template in prometheus.yml.disabled is wrong. if we enable this module by mv prometheus.yml.disabled to prometheus.yml, will print ERROR as below 2018-12-24T…

---

## [Is it a bug in Winlogbeat?](https://discuss.elastic.co/t/is-it-a-bug-in-winlogbeat/162011)

<div class="topic-metadata">

**Author:** [@James\_Ronaldo](https://discuss.elastic.co/u/James_Ronaldo)\
**Replies:** 2\
**Last updated:** [December 31, 2018, 5:29pm UTC](https://discuss.elastic.co/t/is-it-a-bug-in-winlogbeat/162011 "2018-12-31T17:29:14Z")

</div>

Source code: https://github.com/elastic/beats/blob/master/winlogbeat/eventlog/wineventlog.go. In the Open method (around line 125), a Windows event named signalEvent is created and then passed to win.Subscribe, however,…

---

## [K8 pod -\> stdout -\>?](https://discuss.elastic.co/t/k8-pod-stdout/158604)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 5\
**Last updated:** [December 27, 2018, 6:12pm UTC](https://discuss.elastic.co/t/k8-pod-stdout/158604 "2018-12-27T18:12:51Z")

</div>

I have a simple deployment to a k8 cluster. One pod sending info to stdout and I'd like to pass it along to elastic. (I can see the output in the k8 log). K8 cluster in question has both metricbeat and filebeat daemonse…

---

## [Program for send log from Linux](https://discuss.elastic.co/t/program-for-send-log-from-linux/162414)

<div class="topic-metadata">

**Author:** [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Replies:** 7\
**Last updated:** [December 30, 2018, 9:05am UTC](https://discuss.elastic.co/t/program-for-send-log-from-linux/162414 "2018-12-30T09:05:18Z")

</div>

Hello. What is the best program for send Linux log to ELK? I know syslog-ng or rsyslog exist but which program is best and match with ELK? Thank you.

---

## [Metricbeat kubernetes module can't connect to kubelet](https://discuss.elastic.co/t/metricbeat-kubernetes-module-cant-connect-to-kubelet/161939)

<div class="topic-metadata">

**Author:** [@dnutels](https://discuss.elastic.co/u/dnutels)\
**Replies:** 2\
**Last updated:** [December 29, 2018, 3:49am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module-cant-connect-to-kubelet/161939 "2018-12-29T03:49:17Z")

</div>

Hi. We have a setup, where Metricbeat is deployed as a DaemonSet on a Kubernetes cluster (spefcifically -- AWS EKS). All seems to be functioning properly, but the kubelet connection. To clarify, the following module: …

---

## [Filebeat Nginx module not dropping events](https://discuss.elastic.co/t/filebeat-nginx-module-not-dropping-events/160797)

<div class="topic-metadata">

**Author:** [@arlen](https://discuss.elastic.co/u/arlen)\
**Replies:** 4\
**Last updated:** [December 28, 2018, 3:54pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-not-dropping-events/160797 "2018-12-28T15:54:19Z")

</div>

I'm trying to exclude some events, started out with a more complex processor, but was never once able to make even a simple condition work. drop\_event, with no condition, does what it's supposed to and drops everything. …

---

## [Kibana some figures can not dispaly, the reasion is that local time not synchronized to the servers](https://discuss.elastic.co/t/kibana-some-figures-can-not-dispaly-the-reasion-is-that-local-time-not-synchronized-to-the-servers/161770)

<div class="topic-metadata">

**Author:** [@tongtong](https://discuss.elastic.co/u/tongtong)\
**Replies:** 1\
**Last updated:** [December 28, 2018, 1:03pm UTC](https://discuss.elastic.co/t/kibana-some-figures-can-not-dispaly-the-reasion-is-that-local-time-not-synchronized-to-the-servers/161770 "2018-12-28T13:03:31Z")

</div>

The logs that Metrcibeat generates has inserted into es, but kibana can not display all figures correct, some figure have not data. The reason is mostly your local time is not synchronized to you servers,modify your time…

---

## [Why @timestamp is shown as 'Text' in ES?](https://discuss.elastic.co/t/why-timestamp-is-shown-as-text-in-es/162340)

<div class="topic-metadata">

**Author:** [@Nee\_Defeng](https://discuss.elastic.co/u/Nee_Defeng)\
**Replies:** 0\
**Last updated:** [December 28, 2018, 12:23pm UTC](https://discuss.elastic.co/t/why-timestamp-is-shown-as-text-in-es/162340 "2018-12-28T12:23:42Z")

</div>

In Kibana Discover page, I can see @timestamp is shown as 't' and there was no prompt asking for the Time Filter Field Name (as there is no Date field available in the Index). Why is it like that? I am using newly crea…

---

## [How to disable add\_host\_metadata processor?](https://discuss.elastic.co/t/how-to-disable-add-host-metadata-processor/162254)

<div class="topic-metadata">

**Author:** [@lukasg](https://discuss.elastic.co/u/lukasg)\
**Replies:** 4\
**Last updated:** [December 28, 2018, 10:59am UTC](https://discuss.elastic.co/t/how-to-disable-add-host-metadata-processor/162254 "2018-12-28T10:59:40Z")

</div>

How can I disable the built-in add\_host\_metadata processor in filebeat \>= 6.3.x? My events already contain a host field with a client IP address that now gets overwritten by the host metadata (I'm attempting to upgrade …

---

## [Filebeat autodiscoverkubernetes](https://discuss.elastic.co/t/filebeat-autodiscoverkubernetes/161967)

<div class="topic-metadata">

**Author:** [@icoolchn](https://discuss.elastic.co/u/icoolchn)\
**Replies:** 2\
**Last updated:** [December 28, 2018, 7:33am UTC](https://discuss.elastic.co/t/filebeat-autodiscoverkubernetes/161967 "2018-12-28T07:33:37Z")

</div>

reference https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-multiple-conditions/161145 The problem is When the condition has “kubernetes.labels.log-index” ，fields:log\_topic: 'labels-{data.kubernetes.labels.l…

---

## [Metricbeat \[6.3\] - missing metricbeat.modules fields](https://discuss.elastic.co/t/metricbeat-6-3-missing-metricbeat-modules-fields/162211)

<div class="topic-metadata">

**Author:** [@Rotem\_Amergi](https://discuss.elastic.co/u/Rotem_Amergi)\
**Replies:** 2\
**Last updated:** [December 28, 2018, 7:32am UTC](https://discuss.elastic.co/t/metricbeat-6-3-missing-metricbeat-modules-fields/162211 "2018-12-28T07:32:47Z")

</div>

Hi , I am using elasticsearch & kibana & logstash version 6.3.2 . I am using metricbeat 6.3 version and want to use to following modules : module: mysql I am trying to connect to secure mysql with cert and I can't w…

---

## [Cannot start Filebeat](https://discuss.elastic.co/t/cannot-start-filebeat/161875)

<div class="topic-metadata">

**Author:** [@angelazhao](https://discuss.elastic.co/u/angelazhao)\
**Replies:** 4\
**Last updated:** [December 27, 2018, 3:04pm UTC](https://discuss.elastic.co/t/cannot-start-filebeat/161875 "2018-12-27T15:04:11Z")

</div>

I'm following the Getting Started with Logstash tutorial (https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html) and am having trouble running Filebeat. My filebeat.yml file looks like this: filebeat.…

---

## [SID To SAMAccountName Translation](https://discuss.elastic.co/t/sid-to-samaccountname-translation/162080)

<div class="topic-metadata">

**Author:** [@M1kep](https://discuss.elastic.co/u/M1kep)\
**Replies:** 1\
**Last updated:** [December 27, 2018, 2:55pm UTC](https://discuss.elastic.co/t/sid-to-samaccountname-translation/162080 "2018-12-27T14:55:15Z")

</div>

Hey there! I've found that WinLogBeat is doing some translation of SID's. I'm hoping to leverage this translation for event logs that have multiple SID's. Ie. Event ID 4757 has an SID field for the member being added. I…

---

## [Filebeat autodiscovery for docker seems to miss collecting logs of crashed containers](https://discuss.elastic.co/t/filebeat-autodiscovery-for-docker-seems-to-miss-collecting-logs-of-crashed-containers/159324)

<div class="topic-metadata">

**Author:** [@farodin91](https://discuss.elastic.co/u/farodin91)\
**Replies:** 3\
**Last updated:** [December 27, 2018, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-for-docker-seems-to-miss-collecting-logs-of-crashed-containers/159324 "2018-12-27T14:48:07Z")

</div>

Hi We are running a multi-node swarm. If services crashes and produces a log entry with the crash exception, these logs are not forward to our Logstash. Besides, we are able to see these logs with docker log. Version: …

---

## [Make setup throwing error](https://discuss.elastic.co/t/make-setup-throwing-error/161918)

<div class="topic-metadata">

**Author:** [@fillic2002](https://discuss.elastic.co/u/fillic2002)\
**Replies:** 3\
**Last updated:** [December 27, 2018, 2:47pm UTC](https://discuss.elastic.co/t/make-setup-throwing-error/161918 "2018-12-27T14:47:43Z")

</div>

Here is the image of error i am getting as there is no setup target for mage to run. May i get some help in creating a custom beat. i am trying everything on ELK stack 6.5.0 Am i going to run Make.bat or make? for mak…

---

## [Filebeat custom index name without logstash](https://discuss.elastic.co/t/filebeat-custom-index-name-without-logstash/161885)

<div class="topic-metadata">

**Author:** [@pranay\_sankpal](https://discuss.elastic.co/u/pranay_sankpal)\
**Replies:** 7\
**Last updated:** [December 27, 2018, 2:37pm UTC](https://discuss.elastic.co/t/filebeat-custom-index-name-without-logstash/161885 "2018-12-27T14:37:19Z")

</div>

I want to change name of the index. https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#index-option-es I'm referring above link. following is the filebeat.yml file. I'm not seeing any inde…

---

## [Spurious output from Apache2 module](https://discuss.elastic.co/t/spurious-output-from-apache2-module/161858)

<div class="topic-metadata">

**Author:** [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Replies:** 2\
**Last updated:** [December 27, 2018, 2:30pm UTC](https://discuss.elastic.co/t/spurious-output-from-apache2-module/161858 "2018-12-27T14:30:41Z")

</div>

Hello, all. Recently, I enabled the Filebeat Apache2 module, in part to capture geoip data. That seems to be working fine. However, I notice that some output looks to be generated because of a misconfiguration somewhe…

---

## [How to configure nginx module of filebeat with redis output](https://discuss.elastic.co/t/how-to-configure-nginx-module-of-filebeat-with-redis-output/161987)

<div class="topic-metadata">

**Author:** [@YuDang](https://discuss.elastic.co/u/YuDang)\
**Replies:** 1\
**Last updated:** [December 27, 2018, 2:19pm UTC](https://discuss.elastic.co/t/how-to-configure-nginx-module-of-filebeat-with-redis-output/161987 "2018-12-27T14:19:21Z")

</div>

Hi, I am using filebeat(6.5) with redis output, The structure is filebeat-\>redis-\>logstash-\>es-\>kibana. I want to collect nginx log with NGINX module of filebeat, but I can not find the config way, In the \[Filebeat Refe…

---

## [Unmarshalling Error With Route53 Healthcheck an HAproxy](https://discuss.elastic.co/t/unmarshalling-error-with-route53-healthcheck-an-haproxy/161948)

<div class="topic-metadata">

**Author:** [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Replies:** 1\
**Last updated:** [December 27, 2018, 2:00pm UTC](https://discuss.elastic.co/t/unmarshalling-error-with-route53-healthcheck-an-haproxy/161948 "2018-12-27T14:00:43Z")

</div>

Hi, We have a stream of events captured by HAproxy, written to a log and collected by Filebeat. We get an error for what appears to be a broken JSON sent by Route53 health-check (look at the event field): 2018-12-23T1…

---

## [Export Index Template with Dynamic Fields](https://discuss.elastic.co/t/export-index-template-with-dynamic-fields/161938)

<div class="topic-metadata">

**Author:** [@Andre\_Baskin](https://discuss.elastic.co/u/Andre_Baskin)\
**Replies:** 1\
**Last updated:** [December 27, 2018, 1:59pm UTC](https://discuss.elastic.co/t/export-index-template-with-dynamic-fields/161938 "2018-12-27T13:59:10Z")

</div>

I am working on a beat where the field names and types it returns are not known until run time. There is the option to use a custom index template so the user could build such an index template and add it to the beat con…

---

## [Acknowledgement level for filebeat Kafka outout](https://discuss.elastic.co/t/acknowledgement-level-for-filebeat-kafka-outout/161784)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [December 27, 2018, 1:24pm UTC](https://discuss.elastic.co/t/acknowledgement-level-for-filebeat-kafka-outout/161784 "2018-12-27T13:24:45Z")

</div>

Would like to know what is the value which has been set for the acks field for the filebeat kafka output.

---

## [Is filebeat parse the timestamp from the log line and use it as the timestamp of the event?](https://discuss.elastic.co/t/is-filebeat-parse-the-timestamp-from-the-log-line-and-use-it-as-the-timestamp-of-the-event/161813)

<div class="topic-metadata">

**Author:** [@pradeep57498755](https://discuss.elastic.co/u/pradeep57498755)\
**Replies:** 4\
**Last updated:** [December 26, 2018, 7:35am UTC](https://discuss.elastic.co/t/is-filebeat-parse-the-timestamp-from-the-log-line-and-use-it-as-the-timestamp-of-the-event/161813 "2018-12-26T07:35:10Z")

</div>

Hi, Am using filebeat on graylog and i want to parse the timestamp from the log line and use it as the timestamp field using filebeat ,how can i grok the log timestamp without logstash log sample Thu Dec 20 12:36:56 +0…

---

## [Adding ES nodes](https://discuss.elastic.co/t/adding-es-nodes/162071)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 0\
**Last updated:** [December 25, 2018, 1:59pm UTC](https://discuss.elastic.co/t/adding-es-nodes/162071 "2018-12-25T13:59:43Z")

</div>

Currently i am using 3 nodes ES cluster in my filebeat agent output.elasticsearch mentioned in array format. what is the best approach to use that output.elasticsearch setting when i add or delete nodes so that i can ma…

---

## [Add aliases to filebeat template?](https://discuss.elastic.co/t/add-aliases-to-filebeat-template/161867)

<div class="topic-metadata">

**Author:** [@AlanW](https://discuss.elastic.co/u/AlanW)\
**Replies:** 1\
**Last updated:** [December 25, 2018, 5:57am UTC](https://discuss.elastic.co/t/add-aliases-to-filebeat-template/161867 "2018-12-25T05:57:21Z")

</div>

Is there any way to set an index alias when configuring a template in filebeat.yml? According to https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html we can set the number of shards and replicas…

---

## [Filebeat doesn't send data when executed as daemon](https://discuss.elastic.co/t/filebeat-doesnt-send-data-when-executed-as-daemon/161932)

<div class="topic-metadata">

**Author:** [@leanfrei](https://discuss.elastic.co/u/leanfrei)\
**Replies:** 1\
**Last updated:** [December 23, 2018, 3:48am UTC](https://discuss.elastic.co/t/filebeat-doesnt-send-data-when-executed-as-daemon/161932 "2018-12-23T03:48:09Z")

</div>

Hi, I've installed filebeat in an Amazon Linux and changed the /etc/init.d/filebeat to run as a non root user called "filebeat-usr". I also changed ownership of all filebeat files to "filebeat-usr". When I do sudo su f…

---

## [Add docker metadata not working even after trying all possible combinations](https://discuss.elastic.co/t/add-docker-metadata-not-working-even-after-trying-all-possible-combinations/158075)

<div class="topic-metadata">

**Author:** [@diya](https://discuss.elastic.co/u/diya)\
**Replies:** 8\
**Last updated:** [November 27, 2018, 12:19am UTC](https://discuss.elastic.co/t/add-docker-metadata-not-working-even-after-trying-all-possible-combinations/158075 "2018-11-27T00:19:28Z")

</div>

Am able to visualise the docker logs on kibana but with container id. I want to add container name to my logs for easy filtering.I have tried add\_docker\_metadata: ~ but in vain.I have tried differnt possible combinations…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=392)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=394)
