# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=395

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 396

---

## [Auditbeat notify about files changes](https://discuss.elastic.co/t/auditbeat-notify-about-files-changes/161354)

<div class="topic-metadata">

**Author:** [@HePw](https://discuss.elastic.co/u/HePw)\
**Replies:** 4\
**Last updated:** [December 18, 2018, 6:24pm UTC](https://discuss.elastic.co/t/auditbeat-notify-about-files-changes/161354 "2018-12-18T18:24:52Z")

</div>

Hello, can anybody show me example how to create a notification (email, slack...) when Auditbeat notice changes in files? I've elasticsearch from elastic.co with installed auditbeat on the server, all works fine. But I…

---

## [Functionbeat vs. Logstash SQS and Cloudwatch inputs](https://discuss.elastic.co/t/functionbeat-vs-logstash-sqs-and-cloudwatch-inputs/161359)

<div class="topic-metadata">

**Author:** [@Micah\_Hunsberger](https://discuss.elastic.co/u/Micah_Hunsberger)\
**Replies:** 0\
**Last updated:** [December 18, 2018, 3:25pm UTC](https://discuss.elastic.co/t/functionbeat-vs-logstash-sqs-and-cloudwatch-inputs/161359 "2018-12-18T15:25:04Z")

</div>

I have only barely looked into functionbeat, but I was curious since it pulls from both SQS and Cloudwatch, what would the advantages be of using functionbeat over the SQS and Cloudwatch input plugins for Logstash?

---

## [Filebeat autodiscover for docker does not work on /var/lib/docker/containers](https://discuss.elastic.co/t/filebeat-autodiscover-for-docker-does-not-work-on-var-lib-docker-containers/159766)

<div class="topic-metadata">

**Author:** [@RogerLapin](https://discuss.elastic.co/u/RogerLapin)\
**Replies:** 7\
**Last updated:** [December 18, 2018, 3:04pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-for-docker-does-not-work-on-var-lib-docker-containers/159766 "2018-12-18T15:04:58Z")

</div>

Hi, I am quite puzzled about the autodiscover feature for "tea"ing docker logs. This look quite useful, but despite reading the documentation and the few posts about it, I could not manage to have it fully work. To be…

---

## [Failure to run Filebeat On K8s Cluster - using KubeCTL](https://discuss.elastic.co/t/failure-to-run-filebeat-on-k8s-cluster-using-kubectl/161177)

<div class="topic-metadata">

**Author:** [@ranlandau](https://discuss.elastic.co/u/ranlandau)\
**Replies:** 1\
**Last updated:** [December 18, 2018, 12:58pm UTC](https://discuss.elastic.co/t/failure-to-run-filebeat-on-k8s-cluster-using-kubectl/161177 "2018-12-18T12:58:03Z")

</div>

I've followed instructions from: https://www.elastic.co/blog/shipping-kubernetes-logs-to-elasticsearch-with-filebeat which seems pretty simple and would log my K8S cluster. now i get this: ubuntu@ip-10-0-32-203:~/kubl…

---

## [JVM Memory details using metricbeat](https://discuss.elastic.co/t/jvm-memory-details-using-metricbeat/159868)

<div class="topic-metadata">

**Author:** [@460](https://discuss.elastic.co/u/460)\
**Replies:** 7\
**Last updated:** [December 18, 2018, 7:57am UTC](https://discuss.elastic.co/t/jvm-memory-details-using-metricbeat/159868 "2018-12-18T07:57:45Z")

</div>

Is it possible to get the JVM Memory details using metricbeat in 6.4.0

---

## [Sum network traffic](https://discuss.elastic.co/t/sum-network-traffic/159405)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 7\
**Last updated:** [December 18, 2018, 7:57am UTC](https://discuss.elastic.co/t/sum-network-traffic/159405 "2018-12-18T07:57:06Z")

</div>

Hi, Since this issue has been closed by @jsoriano I'm asking for a solution here. I was just trying out Metricbeat to see if I can log outgoing traffic in an LXC container. I couldn't specify other option than the inte…

---

## [CPU usage values are not accurate](https://discuss.elastic.co/t/cpu-usage-values-are-not-accurate/157623)

<div class="topic-metadata">

**Author:** [@roopeshetty](https://discuss.elastic.co/u/roopeshetty)\
**Replies:** 2\
**Last updated:** [December 18, 2018, 6:50am UTC](https://discuss.elastic.co/t/cpu-usage-values-are-not-accurate/157623 "2018-12-18T06:50:11Z")

</div>

Hi Guys, We are using Metricbeat to verify the CPU and Memory usage reports of few Windows servers by using Kibana dashobards. We are using Field “system.memory.used.pct” for memory usage which is giving the accurate va…

---

## [Allocate a type in filebeat](https://discuss.elastic.co/t/allocate-a-type-in-filebeat/160853)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 2\
**Last updated:** [December 18, 2018, 5:04am UTC](https://discuss.elastic.co/t/allocate-a-type-in-filebeat/160853 "2018-12-18T05:04:13Z")

</div>

I am facing a issue my filebeat config is filebeat.prospectors: input\_type: log paths: /home/rdave/Desktop/ELK/\* fields: document\_type: test multiline: pattern: '^{"+\\w\[a-z\]' negate: true match: before output…

---

## [Dissect filter not removing whitespace padding via suffix "-\>"](https://discuss.elastic.co/t/dissect-filter-not-removing-whitespace-padding-via-suffix/161233)

<div class="topic-metadata">

**Author:** [@boss](https://discuss.elastic.co/u/boss)\
**Replies:** 0\
**Last updated:** [December 18, 2018, 2:10am UTC](https://discuss.elastic.co/t/dissect-filter-not-removing-whitespace-padding-via-suffix/161233 "2018-12-18T02:10:18Z")

</div>

I was under the impression that the suffix -\> would remove all whitespace padding to the right of my field. Ex. "value": "some\_value ‌‌ ‌‌ ‌‌ ‌‌ " Would become "value": "some\_value" Either that assumption is incorre…

---

## [Filebeat不能写kafka不能自动rebalance](https://discuss.elastic.co/t/filebeat-kafka-rebalance/161224)

<div class="topic-metadata">

**Author:** [@kimileonis](https://discuss.elastic.co/u/kimileonis)\
**Replies:** 0\
**Last updated:** [December 18, 2018, 12:23am UTC](https://discuss.elastic.co/t/filebeat-kafka-rebalance/161224 "2018-12-18T00:23:21Z")

</div>

求助，当kafka集群的机器突然down了，filebeat不能自动rebalance，也就不会再收集日志写kafka，有谁遇到过吗

---

## [Exclude lines does not appear to be working](https://discuss.elastic.co/t/exclude-lines-does-not-appear-to-be-working/161204)

<div class="topic-metadata">

**Author:** [@swright-eti](https://discuss.elastic.co/u/swright-eti)\
**Replies:** 0\
**Last updated:** [December 17, 2018, 8:24pm UTC](https://discuss.elastic.co/t/exclude-lines-does-not-appear-to-be-working/161204 "2018-12-17T20:24:20Z")

</div>

There seem to be lots of cases of this issue. Anyway, here is mine. I want to exclude the dashed line. I have the following configuration for Filebeat. - type: log enabled: true paths: - /usr/cbridge/msg/c…

---

## [Filebeat Logstash Default Dashboards not loading](https://discuss.elastic.co/t/filebeat-logstash-default-dashboards-not-loading/160793)

<div class="topic-metadata">

**Author:** [@swright-eti](https://discuss.elastic.co/u/swright-eti)\
**Replies:** 5\
**Last updated:** [December 17, 2018, 6:32pm UTC](https://discuss.elastic.co/t/filebeat-logstash-default-dashboards-not-loading/160793 "2018-12-17T18:32:43Z")

</div>

I am having some trouble understanding getting the default dashboards for Filebeat's Logstash module working. I see Filebeat shipping data. I see that ElasticSearch has indexes for filebeat. I can search it using the De…

---

## [Packet beat Service Start](https://discuss.elastic.co/t/packet-beat-service-start/161002)

<div class="topic-metadata">

**Author:** [@kamesh\_siva](https://discuss.elastic.co/u/kamesh_siva)\
**Replies:** 3\
**Last updated:** [December 17, 2018, 6:31pm UTC](https://discuss.elastic.co/t/packet-beat-service-start/161002 "2018-12-17T18:31:11Z")

</div>

Hi Team, I am facing the fallowing issue when trying to start paket beat service 2018-12-15T18:58:18.806+0530 INFO instance/beat.go:278 Setup Beat: packetbeat; Version: 6.5.3 2018-12-15T18:58:18.807+0530 I…

---

## [Filebeat6.5.1版本无法清除注册文件状态](https://discuss.elastic.co/t/filebeat6-5-1/160870)

<div class="topic-metadata">

**Author:** [@396175371](https://discuss.elastic.co/u/396175371)\
**Replies:** 1\
**Last updated:** [December 17, 2018, 3:57pm UTC](https://discuss.elastic.co/t/filebeat6-5-1/160870 "2018-12-17T15:57:37Z")

</div>

Filebeat 6.5.1, Red Hat 4.4.7 我在使用filebeat6.5.1版本时 使用以下配置 registry文件不能删除 inactive状态的文件 filebeat 配置如下 filebeat.inputs: - type: log enabled: true paths: - /vol/\*.log encoding: utf-8 exclude\_files: \['.\*gc.log…

---

## [\[Important\] Filebeat goroutine leaking fixing (issue 7820) is missing in v6.5](https://discuss.elastic.co/t/important-filebeat-goroutine-leaking-fixing-issue-7820-is-missing-in-v6-5/161068)

<div class="topic-metadata">

**Author:** [@oldcodeoberyn](https://discuss.elastic.co/u/oldcodeoberyn)\
**Replies:** 2\
**Last updated:** [December 17, 2018, 2:22pm UTC](https://discuss.elastic.co/t/important-filebeat-goroutine-leaking-fixing-issue-7820-is-missing-in-v6-5/161068 "2018-12-17T14:22:38Z")

</div>

I don't know what is the reason behind that, but the correction bing in by https://github.com/elastic/beats/pull/7820, are missing in Filebeat v6.5, this cause that we suffer the the memory leak issue again after upgrade…

---

## [I am not able to send the json file to elasticsearch through filebeat](https://discuss.elastic.co/t/i-am-not-able-to-send-the-json-file-to-elasticsearch-through-filebeat/161135)

<div class="topic-metadata">

**Author:** [@SunilT](https://discuss.elastic.co/u/SunilT)\
**Replies:** 1\
**Last updated:** [December 17, 2018, 2:05pm UTC](https://discuss.elastic.co/t/i-am-not-able-to-send-the-json-file-to-elasticsearch-through-filebeat/161135 "2018-12-17T14:05:16Z")

</div>

I am trying to send the data to elasticsearch through kibana. But I am not able to view it in kibana. I feel there is a some error in my configuration file or my json format. My filebeat.yml file is below: #===========…

---

## [Read filebeat configration from Http URL?](https://discuss.elastic.co/t/read-filebeat-configration-from-http-url/160738)

<div class="topic-metadata">

**Author:** [@sahadevan](https://discuss.elastic.co/u/sahadevan)\
**Replies:** 3\
**Last updated:** [December 17, 2018, 2:00pm UTC](https://discuss.elastic.co/t/read-filebeat-configration-from-http-url/160738 "2018-12-17T14:00:07Z")

</div>

Team, Is there any way to read filebeat configuration from an URL? I want to start filebeat in windows from command line like this " filebeat.exe --path.config='http://XXXXXX/filebeat.yml' " Please help me.

---

## [Can i read a formatted json file via filebeat?](https://discuss.elastic.co/t/can-i-read-a-formatted-json-file-via-filebeat/161015)

<div class="topic-metadata">

**Author:** [@fillic2002](https://discuss.elastic.co/u/fillic2002)\
**Replies:** 7\
**Last updated:** [December 17, 2018, 1:38pm UTC](https://discuss.elastic.co/t/can-i-read-a-formatted-json-file-via-filebeat/161015 "2018-12-17T13:38:29Z")

</div>

I see the beat is lightweight and don't want to go through logstash heavy processing pipeline. Is there a way i can use any beat to parse my json file and parse individual field as part of index column? i am reading many…

---

## [How to change Filebeat input fileformat to different one other than Apachelog](https://discuss.elastic.co/t/how-to-change-filebeat-input-fileformat-to-different-one-other-than-apachelog/161146)

<div class="topic-metadata">

**Author:** [@AshokJ](https://discuss.elastic.co/u/AshokJ)\
**Replies:** 0\
**Last updated:** [December 17, 2018, 12:44pm UTC](https://discuss.elastic.co/t/how-to-change-filebeat-input-fileformat-to-different-one-other-than-apachelog/161146 "2018-12-17T12:44:53Z")

</div>

Hi, I am looking forward to how Filebeat send the data to Elasticsearch (from the example: Apache2 Filebeat with sample log from the below link) and yes I could visualize apache\_log through Kibana. So my input is differ…

---

## [Elasticsearch update api from custom made Beat](https://discuss.elastic.co/t/elasticsearch-update-api-from-custom-made-beat/161111)

<div class="topic-metadata">

**Author:** [@rcartier](https://discuss.elastic.co/u/rcartier)\
**Replies:** 0\
**Last updated:** [December 17, 2018, 10:16am UTC](https://discuss.elastic.co/t/elasticsearch-update-api-from-custom-made-beat/161111 "2018-12-17T10:16:08Z")

</div>

I'm trying to use the ES update API from my custom made Beat. Here is what I'm trying to reproduce in my Beat implementation: POST test/\_doc/1/\_update { "doc" : { "name" : "new\_name" } } I saw there is …

---

## [Filebeat not creating index in ES 6.5.1](https://discuss.elastic.co/t/filebeat-not-creating-index-in-es-6-5-1/160785)

<div class="topic-metadata">

**Author:** [@vishnujyothi](https://discuss.elastic.co/u/vishnujyothi)\
**Replies:** 2\
**Last updated:** [December 17, 2018, 9:53am UTC](https://discuss.elastic.co/t/filebeat-not-creating-index-in-es-6-5-1/160785 "2018-12-17T09:53:22Z")

</div>

Hi Am using filebeat 6.5.1 connected to ES 6.5 , was trying/googling to find a fix to index creation problem. metricbeat and heartbeat installed in same machine are working fine (creating index and all) ALL my ES/Kiban…

---

## [Deployed metricbeat by containerized but have beat.name and beat.name.keywords](https://discuss.elastic.co/t/deployed-metricbeat-by-containerized-but-have-beat-name-and-beat-name-keywords/160689)

<div class="topic-metadata">

**Author:** [@wqy960504](https://discuss.elastic.co/u/wqy960504)\
**Replies:** 2\
**Last updated:** [December 17, 2018, 4:13am UTC](https://discuss.elastic.co/t/deployed-metricbeat-by-containerized-but-have-beat-name-and-beat-name-keywords/160689 "2018-12-17T04:13:20Z")

</div>

Hello! I have deployed elasticsearch, metricbeat and kibana in kubernetes by containerized . When I want to query data from elasticsearch by kibana, I find that there are beat.name and beat.name.keyword. what shou…

---

## [Currently, there are only 8 beats tools listed on the official website, any more?](https://discuss.elastic.co/t/currently-there-are-only-8-beats-tools-listed-on-the-official-website-any-more/161067)

<div class="topic-metadata">

**Author:** [@zcx](https://discuss.elastic.co/u/zcx)\
**Replies:** 2\
**Last updated:** [December 17, 2018, 3:07am UTC](https://discuss.elastic.co/t/currently-there-are-only-8-beats-tools-listed-on-the-official-website-any-more/161067 "2018-12-17T03:07:37Z")

</div>

as above,thanks

---

## [Winlogbeat can't send event id 4663, 4660](https://discuss.elastic.co/t/winlogbeat-cant-send-event-id-4663-4660/161030)

<div class="topic-metadata">

**Author:** [@dodaeche](https://discuss.elastic.co/u/dodaeche)\
**Replies:** 0\
**Last updated:** [December 16, 2018, 1:32pm UTC](https://discuss.elastic.co/t/winlogbeat-cant-send-event-id-4663-4660/161030 "2018-12-16T13:32:09Z")

</div>

I'm using winlogbeat-6.5.3-windows-x86\_64 version on my desktop PC. I have setup my pc logging Object Access and winlogbeat works well. When I remove my test.txt file on my PC, Event ID 4660, 4663, and 4658 was generat…

---

## [Filebeat test config failing](https://discuss.elastic.co/t/filebeat-test-config-failing/161016)

<div class="topic-metadata">

**Author:** [@fillic2002](https://discuss.elastic.co/u/fillic2002)\
**Replies:** 1\
**Last updated:** [December 16, 2018, 7:12am UTC](https://discuss.elastic.co/t/filebeat-test-config-failing/161016 "2018-12-16T07:12:51Z")

</div>

i am getting error on executing below filebeat yml. if i remove last three lines on json, everything looks ok. But as per the elastic document those three lines are the latest one in case i am reading json log. Then wh…

---

## [Winlogbeat match eventdata param1](https://discuss.elastic.co/t/winlogbeat-match-eventdata-param1/160953)

<div class="topic-metadata">

**Author:** [@Siva\_](https://discuss.elastic.co/u/Siva_)\
**Replies:** 2\
**Last updated:** [December 16, 2018, 2:44am UTC](https://discuss.elastic.co/t/winlogbeat-match-eventdata-param1/160953 "2018-12-16T02:44:37Z")

</div>

Hi community, How can i use the eventdata param1 to filter in winlogbeat? currently, I am using regex on the message but hoping to avoid it for performance. processors: - drop\_event: when: not: regexp: …

---

## [FreeBSD Version of the System Module has the Uptime Metricset Disabled](https://discuss.elastic.co/t/freebsd-version-of-the-system-module-has-the-uptime-metricset-disabled/159437)

<div class="topic-metadata">

**Author:** [@rhclayto](https://discuss.elastic.co/u/rhclayto)\
**Replies:** 4\
**Last updated:** [December 16, 2018, 2:10am UTC](https://discuss.elastic.co/t/freebsd-version-of-the-system-module-has-the-uptime-metricset-disabled/159437 "2018-12-16T02:10:21Z")

</div>

I have noticed that the the FreeBSD version of metricbeat has the uptime metricset of the system module disabled (or not enabled) in the Go build tags for the metricset. Consequently, when building metricbeat on FreeBSD,…

---

## [Centralized beats configuration](https://discuss.elastic.co/t/centralized-beats-configuration/158969)

<div class="topic-metadata">

**Author:** [@rpendela](https://discuss.elastic.co/u/rpendela)\
**Replies:** 4\
**Last updated:** [December 15, 2018, 12:04pm UTC](https://discuss.elastic.co/t/centralized-beats-configuration/158969 "2018-12-15T12:04:37Z")

</div>

I am trying to utilize the centralize beats feature but seems it requires to configure plain format of user credentials in filebeat.yml file. #========================= Central Management ===============================…

---

## [Bottleneck Data Pipeline](https://discuss.elastic.co/t/bottleneck-data-pipeline/160756)

<div class="topic-metadata">

**Author:** [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)\
**Replies:** 7\
**Last updated:** [December 15, 2018, 12:00pm UTC](https://discuss.elastic.co/t/bottleneck-data-pipeline/160756 "2018-12-15T12:00:34Z")

</div>

I have a csv with more than 300kr of rows per hr. I use filebeat to ship data into elasticsearch. My problem is that, the sending of data is very slow like 2k of rows per 3-5mins only and sometimes it stops for a while. …

---

## [Upgrading libbeat and generated files](https://discuss.elastic.co/t/upgrading-libbeat-and-generated-files/158953)

<div class="topic-metadata">

**Author:** [@retzkek](https://discuss.elastic.co/u/retzkek)\
**Replies:** 1\
**Last updated:** [December 14, 2018, 10:28pm UTC](https://discuss.elastic.co/t/upgrading-libbeat-and-generated-files/158953 "2018-12-14T22:28:48Z")

</div>

What's the recommended procedure for upgrading the version of libbeat used by a beat? For point releases I expect just updating the vendored version will suffice, but what about major versions? Is there any way to update…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=394)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=396)
