# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=397

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 398

---

## [Custom Modules in Central Management (beats)](https://discuss.elastic.co/t/custom-modules-in-central-management-beats/160400)

<div class="topic-metadata">

**Author:** [@sbreckheimer](https://discuss.elastic.co/u/sbreckheimer)\
**Replies:** 1\
**Last updated:** [December 11, 2018, 7:35pm UTC](https://discuss.elastic.co/t/custom-modules-in-central-management-beats/160400 "2018-12-11T19:35:57Z")

</div>

Hi, I am trying to set up the new central management for filebeat at the moment. Everything works fine as long as I am trying to use the standard modules. Elasticsearch receives all data from the server logs and configur…

---

## [Filebeat I/O Writes Higher Than Expected](https://discuss.elastic.co/t/filebeat-i-o-writes-higher-than-expected/160210)

<div class="topic-metadata">

**Author:** [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Replies:** 2\
**Last updated:** [December 11, 2018, 6:25pm UTC](https://discuss.elastic.co/t/filebeat-i-o-writes-higher-than-expected/160210 "2018-12-11T18:25:15Z")

</div>

Hi, We're running Filebeat using the Kubernetes autodiscover + Docker input and we're seeing the throughput of writes on certain Filebeat instances being more than I'd expect. An example instance is harvesting ~13 log …

---

## [Can't load Filebeat on Windows Server, Fails to create client](https://discuss.elastic.co/t/cant-load-filebeat-on-windows-server-fails-to-create-client/160420)

<div class="topic-metadata">

**Author:** [@Ghoti](https://discuss.elastic.co/u/Ghoti)\
**Replies:** 0\
**Last updated:** [December 11, 2018, 5:41pm UTC](https://discuss.elastic.co/t/cant-load-filebeat-on-windows-server-fails-to-create-client/160420 "2018-12-11T17:41:51Z")

</div>

PS C:\\Program Files\\filebeat-6.5.2-windows-x86\_64\> .\\filebeat.exe setup -e 2018-12-11T12:35:07.693-0500 INFO instance/beat.go:592 Home path: \[C:\\Program Files\\filebeat-6.5.2-windows-x86\_ 64\] Config path: \[C:\\P…

---

## [Cannot make filebeat for aarch64](https://discuss.elastic.co/t/cannot-make-filebeat-for-aarch64/159684)

<div class="topic-metadata">

**Author:** [@kmatsuyama](https://discuss.elastic.co/u/kmatsuyama)\
**Replies:** 3\
**Last updated:** [December 11, 2018, 4:55pm UTC](https://discuss.elastic.co/t/cannot-make-filebeat-for-aarch64/159684 "2018-12-11T16:55:10Z")

</div>

I make the filebeat on a linux aarch machine. My Environment: $ go version go version go1.11.2 linux/arm64 $ git rev-parse HEAD 79a6ff31aec8e371631661add2e52938f250ceba I get make failing with the following error: $…

---

## [Functionbeat failing to deploy due to Alphanumeric Error](https://discuss.elastic.co/t/functionbeat-failing-to-deploy-due-to-alphanumeric-error/159650)

<div class="topic-metadata">

**Author:** [@musayev-io](https://discuss.elastic.co/u/musayev-io)\
**Replies:** 2\
**Last updated:** [December 11, 2018, 4:52pm UTC](https://discuss.elastic.co/t/functionbeat-failing-to-deploy-due-to-alphanumeric-error/159650 "2018-12-11T16:52:17Z")

</div>

I'm trying to deploy Functionbeat with CloudWatch triggers that have dashes and underscores. I'm unable to do so, as I get an error message saying: Function: elasticfunctionbeat, could not deploy, error: ValidationError…

---

## [Filebeat modules visualisation in kibana](https://discuss.elastic.co/t/filebeat-modules-visualisation-in-kibana/160152)

<div class="topic-metadata">

**Author:** [@Pietia](https://discuss.elastic.co/u/Pietia)\
**Replies:** 1\
**Last updated:** [December 11, 2018, 4:36pm UTC](https://discuss.elastic.co/t/filebeat-modules-visualisation-in-kibana/160152 "2018-12-11T16:36:11Z")

</div>

Hi, https://www.elastic.co/guide/en/logstash/6.5/logstash-config-for-filebeat-modules.html#logstash-config-for-filebeat-modules What I wish to do is seperate index for PREPROD and for PROD and then visualise those two …

---

## [Parse the data using filebeat](https://discuss.elastic.co/t/parse-the-data-using-filebeat/160407)

<div class="topic-metadata">

**Author:** [@leandro\_matos\_pereir](https://discuss.elastic.co/u/leandro_matos_pereir)\
**Replies:** 0\
**Last updated:** [December 11, 2018, 4:12pm UTC](https://discuss.elastic.co/t/parse-the-data-using-filebeat/160407 "2018-12-11T16:12:33Z")

</div>

Good afternoon. I'm having a hard time filtering information from filebeat / logstash. Here's the current scenario I'm using: filebeat: Installed on 06 servers to collect a log consisting of multi-lines, attached an e…

---

## [Custom log file configuration](https://discuss.elastic.co/t/custom-log-file-configuration/159680)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 3\
**Last updated:** [December 11, 2018, 1:23pm UTC](https://discuss.elastic.co/t/custom-log-file-configuration/159680 "2018-12-11T13:23:29Z")

</div>

i have the custom log file which i want to parse and send the logs to ES from the filebeat configuration. So i had the following filebeat configuration filebeat.prospectors: - type: log enabled: true - /tmp/cust…

---

## [Filebeat does not harvest files after a restart](https://discuss.elastic.co/t/filebeat-does-not-harvest-files-after-a-restart/159608)

<div class="topic-metadata">

**Author:** [@Amit\_Periyapatna](https://discuss.elastic.co/u/Amit_Periyapatna)\
**Replies:** 3\
**Last updated:** [December 11, 2018, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-does-not-harvest-files-after-a-restart/159608 "2018-12-11T13:14:18Z")

</div>

I have configured filebeat to read files from a log directory. Any time I change a configuration in filebeat.yml file and restart filebeat, it stops harvesting files. If I restart after deleting the registry, everythin…

---

## [Filebeat - multiline pattern does not work as expected](https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196)

<div class="topic-metadata">

**Author:** [@mateusz-lubanski-omn](https://discuss.elastic.co/u/mateusz-lubanski-omn)\
**Replies:** 3\
**Last updated:** [December 11, 2018, 1:04pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196 "2018-12-11T13:04:54Z")

</div>

Hi, I set up multiline.\* properties for /etc/filebeat/filebeat.yml as bellow: filebeat.inputs: - type: log paths: - /home/eip/logs/\*.log tail\_files: true multiline.pattern: '^%{TIMESTAMP\_ISO8601}' multiline.negat…

---

## [Multiline pattern & flush pattern in filebeat](https://discuss.elastic.co/t/multiline-pattern-flush-pattern-in-filebeat/159885)

<div class="topic-metadata">

**Author:** [@vennila](https://discuss.elastic.co/u/vennila)\
**Replies:** 1\
**Last updated:** [December 11, 2018, 12:10pm UTC](https://discuss.elastic.co/t/multiline-pattern-flush-pattern-in-filebeat/159885 "2018-12-11T12:10:40Z")

</div>

Hi All, I am using multiline pattern within filebeat.yml to format the logs as follows, filebeat.inputs: document\_type: webapp enabled: true paths: /opt/sample/app.log multiline.pattern: '^., \[\[^\]\]+\]' multiline.…

---

## [Filebeat (6.4.2) autodiscover on Kubernetes. Missing field accessing 'containers.ids.0'](https://discuss.elastic.co/t/filebeat-6-4-2-autodiscover-on-kubernetes-missing-field-accessing-containers-ids-0/154459)

<div class="topic-metadata">

**Author:** [@havlan](https://discuss.elastic.co/u/havlan)\
**Replies:** 11\
**Last updated:** [December 11, 2018, 10:44am UTC](https://discuss.elastic.co/t/filebeat-6-4-2-autodiscover-on-kubernetes-missing-field-accessing-containers-ids-0/154459 "2018-12-11T10:44:04Z")

</div>

I got this strange (I've not seen it before) error from Filebeat running as a daemonset on Kubernetes (minikube) today. It might be a misconfiguration, that's why I'm posting here first. Filebeat yaml: filebeat.yml: |-…

---

## [How can we create assembly file of beats vendor?](https://discuss.elastic.co/t/how-can-we-create-assembly-file-of-beats-vendor/159924)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 1\
**Last updated:** [December 11, 2018, 5:18am UTC](https://discuss.elastic.co/t/how-can-we-create-assembly-file-of-beats-vendor/159924 "2018-12-11T05:18:05Z")

</div>

Please help. what is the way for committing vendor source file. or what is the way for committing vendor assembly file. if it is so, how to make assembly for vendor.

---

## [Create a new filed from a string field in painless script/ Substing in painless](https://discuss.elastic.co/t/create-a-new-filed-from-a-string-field-in-painless-script-substing-in-painless/159871)

<div class="topic-metadata">

**Author:** [@sid\_nikhil](https://discuss.elastic.co/u/sid_nikhil)\
**Replies:** 2\
**Last updated:** [December 11, 2018, 4:51am UTC](https://discuss.elastic.co/t/create-a-new-filed-from-a-string-field-in-painless-script-substing-in-painless/159871 "2018-12-11T04:51:12Z")

</div>

I have a string field message in filebeats index message : "2018-12-07 00:42:57,797;INFO ;ATDSDSFCMTWB03.6612.38.0.0a7eec05-287d-462e-b2b5-bab666ee33e6;1;0;;GetSiteDetailsHandler;2;" I need to split the string & extrac…

---

## [Error initializing beat: error loading config file: stat /etc/filebeat/filebeat.yml: no such file or directory](https://discuss.elastic.co/t/error-initializing-beat-error-loading-config-file-stat-etc-filebeat-filebeat-yml-no-such-file-or-directory/157116)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [December 11, 2018, 2:05am UTC](https://discuss.elastic.co/t/error-initializing-beat-error-loading-config-file-stat-etc-filebeat-filebeat-yml-no-such-file-or-directory/157116 "2018-12-11T02:05:10Z")

</div>

Hello, I removed Elastic's Beats (filebeat & metricbeat package) by issuing apt-get remove filbeat metricbeat and removed directory rm -rf /etc/filebeat /etc/metricbeat as well. I than tried to install it back by issui…

---

## [Filebeat Consumer high memeory!](https://discuss.elastic.co/t/filebeat-consumer-high-memeory/159955)

<div class="topic-metadata">

**Author:** [@rehan.pasha](https://discuss.elastic.co/u/rehan.pasha)\
**Replies:** 1\
**Last updated:** [December 11, 2018, 1:55am UTC](https://discuss.elastic.co/t/filebeat-consumer-high-memeory/159955 "2018-12-11T01:55:52Z")

</div>

Hello there.. We are seeing very high memory consuming by Filebeat application? Can someone shed us some light what could be the reason? What needs to be checked?

---

## [Logstash is not naming indices based on Filebeat tags](https://discuss.elastic.co/t/logstash-is-not-naming-indices-based-on-filebeat-tags/159953)

<div class="topic-metadata">

**Author:** [@a.sailor](https://discuss.elastic.co/u/a.sailor)\
**Replies:** 1\
**Last updated:** [December 11, 2018, 1:48am UTC](https://discuss.elastic.co/t/logstash-is-not-naming-indices-based-on-filebeat-tags/159953 "2018-12-11T01:48:22Z")

</div>

Hi all experts! I have the following configuration: Beats: filebeat.inputs: -type: log enabled: true tags: \["apache-error"\] paths: - /var/log/httpd/error\_log - type: log enabled: true tags: \["apache-ac…

---

## [Add\_kubernetes\_metadata processor](https://discuss.elastic.co/t/add-kubernetes-metadata-processor/160159)

<div class="topic-metadata">

**Author:** [@pranay\_sankpal](https://discuss.elastic.co/u/pranay_sankpal)\
**Replies:** 1\
**Last updated:** [December 10, 2018, 5:35pm UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-processor/160159 "2018-12-10T17:35:52Z")

</div>

Hi, We are setting up packetbeat in kubernetes cluster. I'm following https://github.com/elastic/examples/blob/master/MonitoringKubernetes/packetbeat-kubernetes.yaml Packetbeat kubernetes processor is not adding kubern…

---

## [Is it possible to have Auditbeat filter before sending the results](https://discuss.elastic.co/t/is-it-possible-to-have-auditbeat-filter-before-sending-the-results/158210)

<div class="topic-metadata">

**Author:** [@nlh](https://discuss.elastic.co/u/nlh)\
**Replies:** 5\
**Last updated:** [December 10, 2018, 3:58pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-auditbeat-filter-before-sending-the-results/158210 "2018-12-10T15:58:41Z")

</div>

I'd like to filter out a number of processes, before Auditbeat sends to Logstash. Sure the filter works on Logstash, but it is causing lots of reporting and network traffic that could be avoided. So Auditbeat is on one …

---

## [Dashboard on isolate environment](https://discuss.elastic.co/t/dashboard-on-isolate-environment/160192)

<div class="topic-metadata">

**Author:** [@Lo\_Tel](https://discuss.elastic.co/u/Lo_Tel)\
**Replies:** 1\
**Last updated:** [December 10, 2018, 2:51pm UTC](https://discuss.elastic.co/t/dashboard-on-isolate-environment/160192 "2018-12-10T14:51:28Z")

</div>

Hi, i've put winlogbeat 6.5.2 in an isolate windows server who only see kafka. yml has been changed to send all data via kafka and it works well. But i can't have the dashboards. i downloaded the beats-dashboards-6.5.…

---

## [No services sent out. Message error : The system cannot find the file specified](https://discuss.elastic.co/t/no-services-sent-out-message-error-the-system-cannot-find-the-file-specified/159906)

<div class="topic-metadata">

**Author:** [@jorisbos](https://discuss.elastic.co/u/jorisbos)\
**Replies:** 2\
**Last updated:** [December 10, 2018, 1:24pm UTC](https://discuss.elastic.co/t/no-services-sent-out-message-error-the-system-cannot-find-the-file-specified/159906 "2018-12-10T13:24:39Z")

</div>

I'm running metricbeat on four of our servers and they have been working for a couple of weeks. Until today where one of the machines stopped sending the windows services. I now only get a single event: @timestamp D…

---

## [Filebeat default modules + custom log files](https://discuss.elastic.co/t/filebeat-default-modules-custom-log-files/159961)

<div class="topic-metadata">

**Author:** [@coudenysj](https://discuss.elastic.co/u/coudenysj)\
**Replies:** 1\
**Last updated:** [December 10, 2018, 10:32am UTC](https://discuss.elastic.co/t/filebeat-default-modules-custom-log-files/159961 "2018-12-10T10:32:26Z")

</div>

Hi, I'm playing around with filebeat, and was wondering if what I'm trying to do is correct/the way to go. I'm running filebeat with some modules enabled (apache2, mysql & system). On the one hand, I want to extract s…

---

## [How can I reduce filebeat cup usage](https://discuss.elastic.co/t/how-can-i-reduce-filebeat-cup-usage/160131)

<div class="topic-metadata">

**Author:** [@Tony\_fu](https://discuss.elastic.co/u/Tony_fu)\
**Replies:** 0\
**Last updated:** [December 10, 2018, 9:35am UTC](https://discuss.elastic.co/t/how-can-i-reduce-filebeat-cup-usage/160131 "2018-12-10T09:35:12Z")

</div>

I put filebeat on my test server, I test it , cpu usage to 40%,then i set "scan\_frequency" to 30s, the cpu usage to 20%,. Now I want to continue to reduce to 10%,but it cannot by set "scan\_frequency" to 60s. Is there…

---

## [How to build custom beat on Windows machine?](https://discuss.elastic.co/t/how-to-build-custom-beat-on-windows-machine/159872)

<div class="topic-metadata">

**Author:** [@fillic2002](https://discuss.elastic.co/u/fillic2002)\
**Replies:** 1\
**Last updated:** [December 10, 2018, 8:00am UTC](https://discuss.elastic.co/t/how-to-build-custom-beat-on-windows-machine/159872 "2018-12-10T08:00:48Z")

</div>

Looks like there are so many dependencies in order to create a custom beat... didn't like..... I am trying to build a simple custom beat and i dont know how to run "make setup" in windows. If the code is in GOlang why th…

---

## [What protocols need work?](https://discuss.elastic.co/t/what-protocols-need-work/160070)

<div class="topic-metadata">

**Author:** [@grantcurell](https://discuss.elastic.co/u/grantcurell)\
**Replies:** 1\
**Last updated:** [December 10, 2018, 12:35am UTC](https://discuss.elastic.co/t/what-protocols-need-work/160070 "2018-12-10T00:35:33Z")

</div>

I'm reading through the contributor's guide and the first thing it says is to ask on the forums to see who is already working what. I'm looking for a project to work on in my free time and was thinking I could help expa…

---

## [Maintaining the correct sequence of log events for the Logstash Elapsed Plugin](https://discuss.elastic.co/t/maintaining-the-correct-sequence-of-log-events-for-the-logstash-elapsed-plugin/159802)

<div class="topic-metadata">

**Author:** [@Franz\_Allan\_Valencia](https://discuss.elastic.co/u/Franz_Allan_Valencia)\
**Replies:** 1\
**Last updated:** [December 8, 2018, 4:41pm UTC](https://discuss.elastic.co/t/maintaining-the-correct-sequence-of-log-events-for-the-logstash-elapsed-plugin/159802 "2018-12-08T16:41:05Z")

</div>

Hi, We have a microservice architecture and we want to measure how long an event gets processed from MicroserviceA to MicroserviceB, from MicroserviceA to MicroserviceC, from MicroserviceA to MicroserviceXYZ, etc Each …

---

## [Metricbeat sends data but can see data in kibana upon restart only](https://discuss.elastic.co/t/metricbeat-sends-data-but-can-see-data-in-kibana-upon-restart-only/159966)

<div class="topic-metadata">

**Author:** [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Replies:** 1\
**Last updated:** [December 8, 2018, 12:48am UTC](https://discuss.elastic.co/t/metricbeat-sends-data-but-can-see-data-in-kibana-upon-restart-only/159966 "2018-12-08T00:48:34Z")

</div>

metricbeat collects data and sends data to logstash - elasticsearch. All of sudden there is no data in elasticsearch and don't see any errors or debug in elasticsearch and logstash logs. when I check the status of metric…

---

## [Kafka output config through Central Management is missing topic name](https://discuss.elastic.co/t/kafka-output-config-through-central-management-is-missing-topic-name/158830)

<div class="topic-metadata">

**Author:** [@gmbehan](https://discuss.elastic.co/u/gmbehan)\
**Replies:** 3\
**Last updated:** [December 7, 2018, 5:16pm UTC](https://discuss.elastic.co/t/kafka-output-config-through-central-management-is-missing-topic-name/158830 "2018-12-07T17:16:24Z")

</div>

When adding a Kafka output config, I can add the hostname but not the Kafka topic name. The config is downloaded successfully by the beat but the logs show an error due to the missing topic config. management.yml confi…

---

## [Convert DATA to number](https://discuss.elastic.co/t/convert-data-to-number/159601)

<div class="topic-metadata">

**Author:** [@Ritten](https://discuss.elastic.co/u/Ritten)\
**Replies:** 2\
**Last updated:** [December 7, 2018, 9:59am UTC](https://discuss.elastic.co/t/convert-data-to-number/159601 "2018-12-07T09:59:29Z")

</div>

Hi. I have a long string divided with semicolon that I successfully have divided into several DATA fields, but I can't solve this problem. One of the DATA fields contains this 812.50.00. I need to get that DATA converte…

---

## [Filebeat setup is error](https://discuss.elastic.co/t/filebeat-setup-is-error/159830)

<div class="topic-metadata">

**Author:** [@hoanguyen195](https://discuss.elastic.co/u/hoanguyen195)\
**Replies:** 1\
**Last updated:** [December 7, 2018, 3:57am UTC](https://discuss.elastic.co/t/filebeat-setup-is-error/159830 "2018-12-07T03:57:30Z")

</div>

PS C:\\Program Files\\Filebeat\> .\\filebeat.exe setup Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: \[Error connection to Elasticsearch http: //10.0.1.182:9200: Get http://10.0.1.182:9200:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=396)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=398)
