# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=396

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 397

---

## [Unable to load dashboards](https://discuss.elastic.co/t/unable-to-load-dashboards/160972)

<div class="topic-metadata">

**Author:** [@jkevan](https://discuss.elastic.co/u/jkevan)\
**Replies:** 0\
**Last updated:** [December 14, 2018, 9:00pm UTC](https://discuss.elastic.co/t/unable-to-load-dashboards/160972 "2018-12-14T21:00:28Z")

</div>

I'm Unable to load the dashboards from beats into my elasticsearch cluster (6.4.2) beats are all 6.4.2. bin/journalbeat setup -e -E output.logstash.enabled=false -E output.elasticsearch.hosts=\['IPADDRESS:9200', 'IPA…

---

## [Heartbeat Proxy Authentication Settings](https://discuss.elastic.co/t/heartbeat-proxy-authentication-settings/160899)

<div class="topic-metadata">

**Author:** [@johnnyinc](https://discuss.elastic.co/u/johnnyinc)\
**Replies:** 1\
**Last updated:** [December 14, 2018, 4:27pm UTC](https://discuss.elastic.co/t/heartbeat-proxy-authentication-settings/160899 "2018-12-14T16:27:58Z")

</div>

Proxy Authentication I want to check the availability of an http site using heartbeat. I have setup the heartbeat like below: type: http schedule: '@every 1m' urls: \["https://10.123.4.56:9000", "https://10.123.4.58:…

---

## [Windows Event Id 401 not generated in event viewer](https://discuss.elastic.co/t/windows-event-id-401-not-generated-in-event-viewer/160895)

<div class="topic-metadata">

**Author:** [@godfather7](https://discuss.elastic.co/u/godfather7)\
**Replies:** 0\
**Last updated:** [December 14, 2018, 11:37am UTC](https://discuss.elastic.co/t/windows-event-id-401-not-generated-in-event-viewer/160895 "2018-12-14T11:37:53Z")

</div>

Event ID 401 suggest which process is using up processor time and is impacting the performance of boot time in source name of Windows-Diagnostic-Performance. What Should i do to get this event id 401

---

## [Metricbeat startup ERROR](https://discuss.elastic.co/t/metricbeat-startup-error/160749)

<div class="topic-metadata">

**Author:** [@syedmd](https://discuss.elastic.co/u/syedmd)\
**Replies:** 1\
**Last updated:** [December 14, 2018, 9:50am UTC](https://discuss.elastic.co/t/metricbeat-startup-error/160749 "2018-12-14T09:50:06Z")

</div>

Hi, I'm trying to connect metric beat with elasticsearch, it says ( Couldn't connect to any of the configured Elasticsearch hosts. Errors: \[Error connection to Elasticsearch http://IP:9200: Get http://IP:9200: dial tcp …

---

## [Metricbeat 6.5.1 - Setup command with flag --path.config ignored](https://discuss.elastic.co/t/metricbeat-6-5-1-setup-command-with-flag-path-config-ignored/160405)

<div class="topic-metadata">

**Author:** [@ORich](https://discuss.elastic.co/u/ORich)\
**Replies:** 3\
**Last updated:** [December 14, 2018, 9:33am UTC](https://discuss.elastic.co/t/metricbeat-6-5-1-setup-command-with-flag-path-config-ignored/160405 "2018-12-14T09:33:32Z")

</div>

Dear all, according to "metricbeat help setup" output, --path.config flag is supported. Unfortunately, when running the command line : metricbeat setup -e --path.config /opt/application/metricbeat/current/conf, I get th…

---

## [Auditbeat: set "-e 2" on startup?](https://discuss.elastic.co/t/auditbeat-set-e-2-on-startup/160832)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 1\
**Last updated:** [December 14, 2018, 3:59am UTC](https://discuss.elastic.co/t/auditbeat-set-e-2-on-startup/160832 "2018-12-14T03:59:50Z")

</div>

I'm trying to completely replace auditd on a number of systems that have quite specific security requirements for auditd, namely that the enabled flag is set to immutable (-e 2) on startup. Copying the existing audit ru…

---

## [Beat Stops Sending Events When Journal Rotates](https://discuss.elastic.co/t/beat-stops-sending-events-when-journal-rotates/160805)

<div class="topic-metadata">

**Author:** [@kfalconer](https://discuss.elastic.co/u/kfalconer)\
**Replies:** 1\
**Last updated:** [December 14, 2018, 3:17am UTC](https://discuss.elastic.co/t/beat-stops-sending-events-when-journal-rotates/160805 "2018-12-14T03:17:40Z")

</div>

The Journal beat service appears to stop ending log events after the journal is rotated. -rw-r-----+ 1 root systemd-journal 16M Dec 13 13:10 system@662da6c735c64e5f98db920498125e8e-0000000001f1a3dc-00057ce953492eca.jou…

---

## [Auditbeats traffic is reaching ELK but no index is created](https://discuss.elastic.co/t/auditbeats-traffic-is-reaching-elk-but-no-index-is-created/160808)

<div class="topic-metadata">

**Author:** [@koocaroo](https://discuss.elastic.co/u/koocaroo)\
**Replies:** 1\
**Last updated:** [December 13, 2018, 11:47pm UTC](https://discuss.elastic.co/t/auditbeats-traffic-is-reaching-elk-but-no-index-is-created/160808 "2018-12-13T23:47:14Z")

</div>

I currently have auditbeats setup and running with the below configuration, i can see traffic come from the host to Elastic on port 9200 via tcpdump when doing actions that would generate the audit events. However when i…

---

## [Filebeat not harvesting new lines on Windows 2008 R2/IIS](https://discuss.elastic.co/t/filebeat-not-harvesting-new-lines-on-windows-2008-r2-iis/160256)

<div class="topic-metadata">

**Author:** [@dluxem](https://discuss.elastic.co/u/dluxem)\
**Replies:** 3\
**Last updated:** [December 13, 2018, 9:57pm UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-new-lines-on-windows-2008-r2-iis/160256 "2018-12-13T21:57:27Z")

</div>

We are running in to a problem where filebeat is only harvesting lines on startup or when new files are created. Once it reads to the current "end of file" of an existing log, no new entries are harvested despite the log…

---

## [Grok expression works in debugger but fails when posted on the pipeline simulation api](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816)

<div class="topic-metadata">

**Author:** [@Dovid](https://discuss.elastic.co/u/Dovid)\
**Replies:** 4\
**Last updated:** [December 13, 2018, 9:53pm UTC](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816 "2018-12-13T21:53:03Z")

</div>

Here is my simulate JSON POST \_ingest/pipeline/\_simulate { "pipeline": { "description": "ASDF log pipeline", "processors": \[ { "grok": { "field": "message", "patterns": \[ …

---

## [Filebeat: read file inside container](https://discuss.elastic.co/t/filebeat-read-file-inside-container/160528)

<div class="topic-metadata">

**Author:** [@pranay\_sankpal](https://discuss.elastic.co/u/pranay_sankpal)\
**Replies:** 1\
**Last updated:** [December 13, 2018, 1:32pm UTC](https://discuss.elastic.co/t/filebeat-read-file-inside-container/160528 "2018-12-13T13:32:57Z")

</div>

Hi, We are setting up logging for services running on kubernetes. These services generates logs file in the APP\_DIR inside a container. How can I ship these logs to ES? I've refered : https://www.elastic.co/guide/en/b…

---

## [Filebeat stop sending logs](https://discuss.elastic.co/t/filebeat-stop-sending-logs/160747)

<div class="topic-metadata">

**Author:** [@povisx1](https://discuss.elastic.co/u/povisx1)\
**Replies:** 1\
**Last updated:** [December 13, 2018, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-stop-sending-logs/160747 "2018-12-13T13:39:23Z")

</div>

Hi, I have a problem, that after log rotate (my logs rotate every hour) after half hour it looks like that filebeat stop sending the logs to logstash, maybe someone can help me with this. My config: #=================…

---

## [Cannot get multiline config correct in 6.5.1](https://discuss.elastic.co/t/cannot-get-multiline-config-correct-in-6-5-1/160682)

<div class="topic-metadata">

**Author:** [@pappaola](https://discuss.elastic.co/u/pappaola)\
**Replies:** 1\
**Last updated:** [December 13, 2018, 11:10am UTC](https://discuss.elastic.co/t/cannot-get-multiline-config-correct-in-6-5-1/160682 "2018-12-13T11:10:18Z")

</div>

I have tried to install 6.5.1 on a windows machine, before I was running 6.1.2. Everything has gone alright except the multiline config for my filebeat (6.5.1 win\_x86). I tried using the "same" config (there are some mi…

---

## [Server based filebeat index name](https://discuss.elastic.co/t/server-based-filebeat-index-name/160474)

<div class="topic-metadata">

**Author:** [@Chetan\_Rana](https://discuss.elastic.co/u/Chetan_Rana)\
**Replies:** 7\
**Last updated:** [December 13, 2018, 9:35am UTC](https://discuss.elastic.co/t/server-based-filebeat-index-name/160474 "2018-12-13T09:35:44Z")

</div>

Hi, If filebeat is installed in multiple servers. How to make sure that that logstash able to make index in elasticsearch like filebeat-{servername}-\*. As of now default one is filebeat-\*. The version i am using of fil…

---

## [Fielddata is disabled on text fields by default. Alternatively use a keyword field instead](https://discuss.elastic.co/t/fielddata-is-disabled-on-text-fields-by-default-alternatively-use-a-keyword-field-instead/160553)

<div class="topic-metadata">

**Author:** [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Replies:** 4\
**Last updated:** [December 13, 2018, 9:23am UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-text-fields-by-default-alternatively-use-a-keyword-field-instead/160553 "2018-12-13T09:23:22Z")

</div>

Does this mean that I need to make changes in some json file ? Actually, I have installed metricbeat along with its default dashboard. Now, when I load dashboard using one of the default dashboards of metricbeat I get e…

---

## [Unbounded growth of bytes.Buffer in libbeat/outputs/elasticsearch/enc.go](https://discuss.elastic.co/t/unbounded-growth-of-bytes-buffer-in-libbeat-outputs-elasticsearch-enc-go/160593)

<div class="topic-metadata">

**Author:** [@Nick\_Peirson](https://discuss.elastic.co/u/Nick_Peirson)\
**Replies:** 0\
**Last updated:** [December 12, 2018, 5:48pm UTC](https://discuss.elastic.co/t/unbounded-growth-of-bytes-buffer-in-libbeat-outputs-elasticsearch-enc-go/160593 "2018-12-12T17:48:03Z")

</div>

We've built a beat against the latest libbeat and we found that over time the RSS memory and heap allocations, as reported by go, steadily increased and wasn't freed. Doing some analysis I tracked it down to the underly…

---

## [Filebeat setup is not idempotent](https://discuss.elastic.co/t/filebeat-setup-is-not-idempotent/160211)

<div class="topic-metadata">

**Author:** [@ORich](https://discuss.elastic.co/u/ORich)\
**Replies:** 1\
**Last updated:** [December 13, 2018, 8:44am UTC](https://discuss.elastic.co/t/filebeat-setup-is-not-idempotent/160211 "2018-12-13T08:44:56Z")

</div>

According to Filebeat documentation : "the setup command loads the recommended index template for writing to Elasticsearch and deploys the sample dashboards (if available) for visualizing the data in Kibana. This is a o…

---

## [Get info on who asked DNS Question](https://discuss.elastic.co/t/get-info-on-who-asked-dns-question/160450)

<div class="topic-metadata">

**Author:** [@Marko\_Todoric](https://discuss.elastic.co/u/Marko_Todoric)\
**Replies:** 7\
**Last updated:** [December 13, 2018, 8:39am UTC](https://discuss.elastic.co/t/get-info-on-who-asked-dns-question/160450 "2018-12-13T08:39:13Z")

</div>

Hey guys, First of all, great project!! Ever since I've found out about ELK Stack I've been hooked up! I would like to monitor DNS traffic using packetbeat, I've set everything up and it works, but it doesn't seem like…

---

## [Beat.name set in config is not used when metricbeat starts](https://discuss.elastic.co/t/beat-name-set-in-config-is-not-used-when-metricbeat-starts/160608)

<div class="topic-metadata">

**Author:** [@swright-eti](https://discuss.elastic.co/u/swright-eti)\
**Replies:** 2\
**Last updated:** [December 13, 2018, 8:32am UTC](https://discuss.elastic.co/t/beat-name-set-in-config-is-not-used-when-metricbeat-starts/160608 "2018-12-13T08:32:23Z")

</div>

Just getting started with ElasticStack and I have a configuration issue with metricbeat. Following the directions in this post I set: beat.name: yellow470.qa When metricbeat starts I see this in the log: 2018-12-12T13…

---

## [Load external configuration files with autodiscover](https://discuss.elastic.co/t/load-external-configuration-files-with-autodiscover/160044)

<div class="topic-metadata">

**Author:** [@hamid.haghshenas](https://discuss.elastic.co/u/hamid.haghshenas)\
**Replies:** 3\
**Last updated:** [December 13, 2018, 8:20am UTC](https://discuss.elastic.co/t/load-external-configuration-files-with-autodiscover/160044 "2018-12-13T08:20:24Z")

</div>

I'm going to monitor Docker Swarm containers using Metricbeat, which is itself a Swarm service. I've heard that I should use autodiscover instead of using modules directly. Say I want to monitor services running uWSGI a…

---

## [How to use Metricbeat to monitor Docker Swarm containers, hosts and external services](https://discuss.elastic.co/t/how-to-use-metricbeat-to-monitor-docker-swarm-containers-hosts-and-external-services/160037)

<div class="topic-metadata">

**Author:** [@hamid.haghshenas](https://discuss.elastic.co/u/hamid.haghshenas)\
**Replies:** 3\
**Last updated:** [December 13, 2018, 8:20am UTC](https://discuss.elastic.co/t/how-to-use-metricbeat-to-monitor-docker-swarm-containers-hosts-and-external-services/160037 "2018-12-13T08:20:02Z")

</div>

We need to monitor: a number of Docker Swarm services, each may have multiple containers on multiple hosts (A host may run several containers of the same service), hosts running Docker Swarm, and Some external services…

---

## [Is the Filebeat able to listen if there is a new file in the folder and push that file to elasticsearch?](https://discuss.elastic.co/t/is-the-filebeat-able-to-listen-if-there-is-a-new-file-in-the-folder-and-push-that-file-to-elasticsearch/160671)

<div class="topic-metadata">

**Author:** [@lungelo\_zondo](https://discuss.elastic.co/u/lungelo_zondo)\
**Replies:** 2\
**Last updated:** [December 13, 2018, 7:00am UTC](https://discuss.elastic.co/t/is-the-filebeat-able-to-listen-if-there-is-a-new-file-in-the-folder-and-push-that-file-to-elasticsearch/160671 "2018-12-13T07:00:10Z")

</div>

Want to automatically read new files from a folder.

---

## [Configuration URL giving error as unknown escape character](https://discuss.elastic.co/t/configuration-url-giving-error-as-unknown-escape-character/160175)

<div class="topic-metadata">

**Author:** [@jarvis](https://discuss.elastic.co/u/jarvis)\
**Replies:** 1\
**Last updated:** [December 12, 2018, 7:28pm UTC](https://discuss.elastic.co/t/configuration-url-giving-error-as-unknown-escape-character/160175 "2018-12-12T19:28:29Z")

</div>

I am configuring the below URL in the heartbeat configuration file. The Url requires MSEC authentication with the mentioned creds. My username contains a "backslash" and passowrd contains a '#' URL - http://user\\name:p…

---

## [How to output to multiple indexes straight from filebeat.yml](https://discuss.elastic.co/t/how-to-output-to-multiple-indexes-straight-from-filebeat-yml/160602)

<div class="topic-metadata">

**Author:** [@Min\_Li](https://discuss.elastic.co/u/Min_Li)\
**Replies:** 1\
**Last updated:** [December 12, 2018, 7:17pm UTC](https://discuss.elastic.co/t/how-to-output-to-multiple-indexes-straight-from-filebeat-yml/160602 "2018-12-12T19:17:52Z")

</div>

how to change logstash conf file to filebeats, multiple input to multiple indexes straight to elastic logstash.conf input { file { path =\> "/var/loginmgr/portal.txt" type =\> "loginmgr" start\_position =\> "beginning" …

---

## [Dynamic inputs path from command line Option -E](https://discuss.elastic.co/t/dynamic-inputs-path-from-command-line-option-e/160518)

<div class="topic-metadata">

**Author:** [@sahadevan](https://discuss.elastic.co/u/sahadevan)\
**Replies:** 0\
**Last updated:** [December 12, 2018, 10:36am UTC](https://discuss.elastic.co/t/dynamic-inputs-path-from-command-line-option-e/160518 "2018-12-12T10:36:56Z")

</div>

Previously, I have used filebeat 5.4.0 and able to set the filebeat input path dynamically by modifying the install-service-filebeat script like #start filebeat service if ($filebeat\_input\_path.length -gt 0) { …

---

## [Filebeat modules pipeline selection](https://discuss.elastic.co/t/filebeat-modules-pipeline-selection/160320)

<div class="topic-metadata">

**Author:** [@coudenysj](https://discuss.elastic.co/u/coudenysj)\
**Replies:** 2\
**Last updated:** [December 12, 2018, 9:07am UTC](https://discuss.elastic.co/t/filebeat-modules-pipeline-selection/160320 "2018-12-12T09:07:59Z")

</div>

I was wondering how the filebeat modules create and select the pipeline names. I have these in my ES setup: filebeat-6.4.3-nginx-access-default filebeat-6.4.3-mysql-slowlog-pipeline etc... And I can see the content o…

---

## [Central Management: Wrong beat id](https://discuss.elastic.co/t/central-management-wrong-beat-id/160498)

<div class="topic-metadata">

**Author:** [@nick.e](https://discuss.elastic.co/u/nick.e)\
**Replies:** 0\
**Last updated:** [December 12, 2018, 8:21am UTC](https://discuss.elastic.co/t/central-management-wrong-beat-id/160498 "2018-12-12T08:21:38Z")

</div>

Today I wanted to try out the new Central Management. For some reason, the metricbeat does not receive its configuration from central management. I did the following steps: Fresh installation of Elasticsearch and Kib…

---

## [How to convert "nanocore" to percentage?](https://discuss.elastic.co/t/how-to-convert-nanocore-to-percentage/160085)

<div class="topic-metadata">

**Author:** [@kycfeel](https://discuss.elastic.co/u/kycfeel)\
**Replies:** 2\
**Last updated:** [December 12, 2018, 7:18am UTC](https://discuss.elastic.co/t/how-to-convert-nanocore-to-percentage/160085 "2018-12-12T07:18:03Z")

</div>

Hey there. I built a monitoring environment with metricbeat for kubernetes, and realized the official dashboard is showing container cpu usage as "nanocore". (the visualization is using kubernetes.container.cpu.usag…

---

## [Timestamped events not going to correct index up until 08:59:59.999 JST](https://discuss.elastic.co/t/timestamped-events-not-going-to-correct-index-up-until-0859-999-jst/160462)

<div class="topic-metadata">

**Author:** [@popa](https://discuss.elastic.co/u/popa)\
**Replies:** 2\
**Last updated:** [December 12, 2018, 6:24am UTC](https://discuss.elastic.co/t/timestamped-events-not-going-to-correct-index-up-until-0859-999-jst/160462 "2018-12-12T06:24:36Z")

</div>

As the title implies, my timestamped events are being added to the wrong index everyday up until 08:59:59.999 JST. Before 09:00:00 JST @timestamp November 20th 2018, 08:59:59.835 \_index winlogbeat-6.4…

---

## [Metricbeat seems to be reading the same config value and getting different values](https://discuss.elastic.co/t/metricbeat-seems-to-be-reading-the-same-config-value-and-getting-different-values/160438)

<div class="topic-metadata">

**Author:** [@cachedout](https://discuss.elastic.co/u/cachedout)\
**Replies:** 3\
**Last updated:** [December 11, 2018, 10:37pm UTC](https://discuss.elastic.co/t/metricbeat-seems-to-be-reading-the-same-config-value-and-getting-different-values/160438 "2018-12-11T22:37:53Z")

</div>

Hi all! Forgive me if this is simply my own ignorance about Beats architecture as it very well might be but I've come across something very curious and I'd love some input from the developer community. Assume the follo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=395)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=397)
