# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=398

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 399

---

## [How to get filebeat source date field?](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489)

<div class="topic-metadata">

**Author:** [@aabababba](https://discuss.elastic.co/u/aabababba)\
**Replies:** 4\
**Last updated:** [December 7, 2018, 1:56am UTC](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489 "2018-12-07T01:56:40Z")

</div>

like this /home/api/log/20181205/20181205\_152840.log I want "20181205" can out put date field in logstash.

---

## [Filebeat http stats: number of events in queue](https://discuss.elastic.co/t/filebeat-http-stats-number-of-events-in-queue/159190)

<div class="topic-metadata">

**Author:** [@sergeyarl](https://discuss.elastic.co/u/sergeyarl)\
**Replies:** 5\
**Last updated:** [December 7, 2018, 12:40am UTC](https://discuss.elastic.co/t/filebeat-http-stats-number-of-events-in-queue/159190 "2018-12-07T00:40:37Z")

</div>

Hi! What parameter in filebeat stats which are exposed via http (http://localhost:5066/stats?pretty) shows the amount of existing events in spool queue ? We are sending logs from filebeats to logstash and want to monit…

---

## [Filebeat haproxy module](https://discuss.elastic.co/t/filebeat-haproxy-module/159629)

<div class="topic-metadata">

**Author:** [@Mark\_Bassett](https://discuss.elastic.co/u/Mark_Bassett)\
**Replies:** 5\
**Last updated:** [December 6, 2018, 8:22pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629 "2018-12-06T20:22:55Z")

</div>

What is the correct method to get logs to the filebeat haproxy module? I see it is running udp syslog on port 9001 so I just added log 127.0.0.1:9001 local0 notice under the global section, but it looks like it is not…

---

## [6.5.1 central management: monitoring doesn't work any more + specifying non-module settings](https://discuss.elastic.co/t/6-5-1-central-management-monitoring-doesnt-work-any-more-specifying-non-module-settings/159753)

<div class="topic-metadata">

**Author:** [@jonno](https://discuss.elastic.co/u/jonno)\
**Replies:** 2\
**Last updated:** [December 6, 2018, 4:41pm UTC](https://discuss.elastic.co/t/6-5-1-central-management-monitoring-doesnt-work-any-more-specifying-non-module-settings/159753 "2018-12-06T16:41:55Z")

</div>

Just setup my first filebeat with central management, this is great stuff. Problem is, monitoring doesn't work anymore and there is no way to configure it. I tried creating a dummy configuration block specifying 'xpack…

---

## [My custom module ignores pipeline](https://discuss.elastic.co/t/my-custom-module-ignores-pipeline/158946)

<div class="topic-metadata">

**Author:** [@gaetanoziri](https://discuss.elastic.co/u/gaetanoziri)\
**Replies:** 4\
**Last updated:** [December 6, 2018, 4:36pm UTC](https://discuss.elastic.co/t/my-custom-module-ignores-pipeline/158946 "2018-12-06T16:36:33Z")

</div>

Hi, I builded a custom module for my application following this guide. After the setup of this module i can see the messages form my module in kabana, but they are not parsed with my pipeline. Below the steps that i d…

---

## [How often metricbeat system process sends data in elasticsearch?](https://discuss.elastic.co/t/how-often-metricbeat-system-process-sends-data-in-elasticsearch/159672)

<div class="topic-metadata">

**Author:** [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Replies:** 1\
**Last updated:** [December 6, 2018, 4:21pm UTC](https://discuss.elastic.co/t/how-often-metricbeat-system-process-sends-data-in-elasticsearch/159672 "2018-12-06T16:21:03Z")

</div>

Hi, i wanted to know if there are some sort of configuration in metricbeat.yml where we can send the system process say every 10 seconds?

---

## [How can we compile filbeat code in windows or linux?](https://discuss.elastic.co/t/how-can-we-compile-filbeat-code-in-windows-or-linux/159362)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 2\
**Last updated:** [December 5, 2018, 8:49am UTC](https://discuss.elastic.co/t/how-can-we-compile-filbeat-code-in-windows-or-linux/159362 "2018-12-05T08:49:52Z")

</div>

Please help me ? Getting Error : PS C:\\Users\\shubham.jain\\Downloads\\beats-6.4.2\\beats-6.4.2\\filebeat\> go build main.go:23:2: cannot find package "github.com/elastic/beats/filebeat/cmd" in any of: C:\\Go\\src\\github.com\\…

---

## [Tuning up filebeat](https://discuss.elastic.co/t/tuning-up-filebeat/159708)

<div class="topic-metadata">

**Author:** [@ErSumit](https://discuss.elastic.co/u/ErSumit)\
**Replies:** 1\
**Last updated:** [December 6, 2018, 1:52pm UTC](https://discuss.elastic.co/t/tuning-up-filebeat/159708 "2018-12-06T13:52:56Z")

</div>

Filebeat is sending logs to logstash-\> elasticsearch. Increasing number of workers shows slight increase in events rate in monitoring at kibana. Max how much I can increase number of workers. I read somewhere optimum nu…

---

## [Configuration of filebeat.yml on a windows client to ship logs to a centos host](https://discuss.elastic.co/t/configuration-of-filebeat-yml-on-a-windows-client-to-ship-logs-to-a-centos-host/159505)

<div class="topic-metadata">

**Author:** [@hoanguyen195](https://discuss.elastic.co/u/hoanguyen195)\
**Replies:** 3\
**Last updated:** [December 6, 2018, 1:13pm UTC](https://discuss.elastic.co/t/configuration-of-filebeat-yml-on-a-windows-client-to-ship-logs-to-a-centos-host/159505 "2018-12-06T13:13:32Z")

</div>

i want to configure filebeat.yml on windows to transfer log files to centos ELK, service filebeat is run but i can't send the log file

---

## [Winlogbeat to Kafka : failover or loadbalancer](https://discuss.elastic.co/t/winlogbeat-to-kafka-failover-or-loadbalancer/159549)

<div class="topic-metadata">

**Author:** [@blenski](https://discuss.elastic.co/u/blenski)\
**Replies:** 2\
**Last updated:** [December 6, 2018, 12:40pm UTC](https://discuss.elastic.co/t/winlogbeat-to-kafka-failover-or-loadbalancer/159549 "2018-12-06T12:40:33Z")

</div>

Hi I am willing to set up winlogbeat to send logs to my Kafka cluster (3 machines) I have seen that I can set several Kafka destination servers, thanks to the following config output.kafka: initial brokers for readin…

---

## [Is there something about my configuration isn't right? What did I miss?](https://discuss.elastic.co/t/is-there-something-about-my-configuration-isnt-right-what-did-i-miss/159514)

<div class="topic-metadata">

**Author:** [@sailaja\_sailu](https://discuss.elastic.co/u/sailaja_sailu)\
**Replies:** 1\
**Last updated:** [December 6, 2018, 12:35pm UTC](https://discuss.elastic.co/t/is-there-something-about-my-configuration-isnt-right-what-did-i-miss/159514 "2018-12-06T12:35:45Z")

</div>

Hello there I have some issue to parse kubernetes containers multi lines utilizing filebeat and logstash. kubernetes log document are situated in/var/log/containers/\*.log and in a json line structure. Is there something…

---

## [Unable to start filebeats](https://discuss.elastic.co/t/unable-to-start-filebeats/159659)

<div class="topic-metadata">

**Author:** [@Chandana](https://discuss.elastic.co/u/Chandana)\
**Replies:** 10\
**Last updated:** [December 6, 2018, 11:13am UTC](https://discuss.elastic.co/t/unable-to-start-filebeats/159659 "2018-12-06T11:13:34Z")

</div>

I get the below error when I tried to start the filebeat. ● filebeat.service - filebeat Loaded: loaded (/usr/lib/systemd/system/filebeat.service; disabled; vendor preset: disabled) Active: failed (Result: start-limit)…

---

## [Filebeat is not forwarding log to logstach](https://discuss.elastic.co/t/filebeat-is-not-forwarding-log-to-logstach/159283)

<div class="topic-metadata">

**Author:** [@Rakesh\_Thangapandian](https://discuss.elastic.co/u/Rakesh_Thangapandian)\
**Replies:** 7\
**Last updated:** [December 6, 2018, 8:16am UTC](https://discuss.elastic.co/t/filebeat-is-not-forwarding-log-to-logstach/159283 "2018-12-06T08:16:22Z")

</div>

Hi , I have created a dockerfile for filebeat and configured yaml files to listen for nginx module input and forward it to logstach. But the issue is my filebeat harvester didn't detect the nginx log update and so its n…

---

## [Grok extract field problem](https://discuss.elastic.co/t/grok-extract-field-problem/159636)

<div class="topic-metadata">

**Author:** [@ferdina](https://discuss.elastic.co/u/ferdina)\
**Replies:** 2\
**Last updated:** [December 6, 2018, 5:59am UTC](https://discuss.elastic.co/t/grok-extract-field-problem/159636 "2018-12-06T05:59:00Z")

</div>

I have a problem in the production process Version es 651 filebeat 651 Modify the nginx template to extract the cookies from the nginx log "grok": { "field": "message", "patterns":\[ ""?%{IPV4:nginx.access.remote\_ip…

---

## [Watcher Metricbeat](https://discuss.elastic.co/t/watcher-metricbeat/159606)

<div class="topic-metadata">

**Author:** [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Replies:** 1\
**Last updated:** [December 6, 2018, 3:35am UTC](https://discuss.elastic.co/t/watcher-metricbeat/159606 "2018-12-06T03:35:19Z")

</div>

Hello, I am running Metricbeat data from 10 different hosts and sending the data to one index,There is a java process running on each server. I want to create a watcher to trigger an email when the java process is down …

---

## [Issue: logstash module's \`format: json\` not work and json pipeline not matched?](https://discuss.elastic.co/t/issue-logstash-modules-format-json-not-work-and-json-pipeline-not-matched/159329)

<div class="topic-metadata">

**Author:** [@youzipi](https://discuss.elastic.co/u/youzipi)\
**Replies:** 2\
**Last updated:** [December 6, 2018, 1:44am UTC](https://discuss.elastic.co/t/issue-logstash-modules-format-json-not-work-and-json-pipeline-not-matched/159329 "2018-12-06T01:44:01Z")

</div>

the former question is because my filebeat config not create the json pipeline in es. I send it by modify the default format. Now I have new questions ,as described in the issue. I cannot create the json pipeline by t…

---

## [Filebeat 6.4.2 Read line error: invalid CRI log format; File](https://discuss.elastic.co/t/filebeat-6-4-2-read-line-error-invalid-cri-log-format-file/154506)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 17\
**Last updated:** [December 5, 2018, 9:11pm UTC](https://discuss.elastic.co/t/filebeat-6-4-2-read-line-error-invalid-cri-log-format-file/154506 "2018-12-05T21:11:33Z")

</div>

Hi, I've seen this: https://github.com/elastic/beats/issues/8175, and it looks like the fix is merged into the 6.4.2 release. However, I'm still seeing this error frequently. 2018-10-29T18:58:06.818Z INFO log/harvester…

---

## [Multiline and '\\n' extra character](https://discuss.elastic.co/t/multiline-and-n-extra-character/159485)

<div class="topic-metadata">

**Author:** [@trelo](https://discuss.elastic.co/u/trelo)\
**Replies:** 1\
**Last updated:** [December 5, 2018, 3:41pm UTC](https://discuss.elastic.co/t/multiline-and-n-extra-character/159485 "2018-12-05T15:41:58Z")

</div>

Hi, I successfully turned my multiline log into single line, but now this log has '\\n' character and double quotes are also escaped - ". Any solution how to stop this behavior and configure filebeat to join lines "as i…

---

## [How to listen only specific http ports in 6.5.1](https://discuss.elastic.co/t/how-to-listen-only-specific-http-ports-in-6-5-1/159251)

<div class="topic-metadata">

**Author:** [@Arunachalam\_lakshman](https://discuss.elastic.co/u/Arunachalam_lakshman)\
**Replies:** 5\
**Last updated:** [December 5, 2018, 3:38pm UTC](https://discuss.elastic.co/t/how-to-listen-only-specific-http-ports-in-6-5-1/159251 "2018-12-05T15:38:58Z")

</div>

I'm trying to use packetbeats 6.5.1 on my mac I'd like to listen only local elastic HTTP port (9200) and my spring boot application which queries elastic (port 8078). How do I listen only to these two? What do i miss? A…

---

## [Drop fields from Apache2 module](https://discuss.elastic.co/t/drop-fields-from-apache2-module/159382)

<div class="topic-metadata">

**Author:** [@Mikael\_VERO](https://discuss.elastic.co/u/Mikael_VERO)\
**Replies:** 2\
**Last updated:** [December 5, 2018, 2:40pm UTC](https://discuss.elastic.co/t/drop-fields-from-apache2-module/159382 "2018-12-05T14:40:53Z")

</div>

Hi, I have an issue I am strugling with since some times and I can't find anything on this forum. I hope you'll be able to help me since i'm desperate. I am trying to drop some fields from the apache2 module of filebe…

---

## [Unable to parse IIS logs](https://discuss.elastic.co/t/unable-to-parse-iis-logs/157073)

<div class="topic-metadata">

**Author:** [@JacovanZyl](https://discuss.elastic.co/u/JacovanZyl)\
**Replies:** 6\
**Last updated:** [December 5, 2018, 11:31am UTC](https://discuss.elastic.co/t/unable-to-parse-iis-logs/157073 "2018-12-05T11:31:36Z")

</div>

Hi there I am having some difficulty parsing IIS logs into the discrete fields. The following tags keeps showing up: "tags": \[ "beats\_input\_codec\_plain\_applied", "\_grokparsefailure", "\_geoip\_lookup\_failure" If …

---

## [Beat make setup error](https://discuss.elastic.co/t/beat-make-setup-error/159512)

<div class="topic-metadata">

**Author:** [@sumanjha](https://discuss.elastic.co/u/sumanjha)\
**Replies:** 0\
**Last updated:** [December 5, 2018, 10:46am UTC](https://discuss.elastic.co/t/beat-make-setup-error/159512 "2018-12-05T10:46:01Z")

</div>

HI Team, I am getting below error while executing make setup command in git bash after generating the raw beat template /c/Go/src/github.com/elastic/suman/lsbeat $ make setup FIND: Parameter format not correct FIND: …

---

## [Module socket\_summary get open connections](https://discuss.elastic.co/t/module-socket-summary-get-open-connections/159117)

<div class="topic-metadata">

**Author:** [@rani](https://discuss.elastic.co/u/rani)\
**Replies:** 4\
**Last updated:** [December 5, 2018, 6:02am UTC](https://discuss.elastic.co/t/module-socket-summary-get-open-connections/159117 "2018-12-05T06:02:50Z")

</div>

Hello there I'm using the new system module "socket\_summary", to monitor my sockets. Is it possible to monitor the open TCP & UDP connections as well with this module (if not are there other options)? For example can I …

---

## [HAProxy dashboard, error loading](https://discuss.elastic.co/t/haproxy-dashboard-error-loading/159398)

<div class="topic-metadata">

**Author:** [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Replies:** 3\
**Last updated:** [December 5, 2018, 12:55am UTC](https://discuss.elastic.co/t/haproxy-dashboard-error-loading/159398 "2018-12-05T00:55:32Z")

</div>

Using Filebeat 6.5.1: After moving the HAProxy dashboard object to "..\\kibana\\6\\dashboard\\Filebeat-haproxy-overview.json" and attempting to run filebeat setup --dashboards, the following error occurs \> 2018-12-04T08:2…

---

## ["Saved 'field' parameter is now invalid" for SSH login attempts](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423)

<div class="topic-metadata">

**Author:** [@tuxedojoe](https://discuss.elastic.co/u/tuxedojoe)\
**Replies:** 3\
**Last updated:** [December 4, 2018, 7:41pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423 "2018-12-04T19:41:06Z")

</div>

Hi, I'm very new to ELK and followed this guide: It all went relatively smooth until I got the stack running. The imported dashboards is not working. I get the logs but all the preloaded dashboards give me a: "Saved…

---

## [Beat.name is not a keyword?](https://discuss.elastic.co/t/beat-name-is-not-a-keyword/159320)

<div class="topic-metadata">

**Author:** [@dao](https://discuss.elastic.co/u/dao)\
**Replies:** 1\
**Last updated:** [December 4, 2018, 2:42pm UTC](https://discuss.elastic.co/t/beat-name-is-not-a-keyword/159320 "2018-12-04T14:42:05Z")

</div>

Hello, I have seen that beat.name is not a keyword when using the basic mapping. Is it done on purpose? What is the best practice to allow beat.name to be a keyword? It is very useful to create visualization on beat.na…

---

## [System.diskio metrics written sparsely?](https://discuss.elastic.co/t/system-diskio-metrics-written-sparsely/159231)

<div class="topic-metadata">

**Author:** [@jeffkirk1](https://discuss.elastic.co/u/jeffkirk1)\
**Replies:** 2\
**Last updated:** [December 4, 2018, 2:34pm UTC](https://discuss.elastic.co/t/system-diskio-metrics-written-sparsely/159231 "2018-12-04T14:34:38Z")

</div>

Hey folks, I was wondering if the Metricbeats behavior I'm seeing with system.diskio metrics is the norm or if I might have a configuration issue. I've deployed Metricbeat on about 2700 servers (almost all of which are …

---

## [Why won't metricbeat capture system.core.\* fields?](https://discuss.elastic.co/t/why-wont-metricbeat-capture-system-core-fields/159226)

<div class="topic-metadata">

**Author:** [@hokiegeek2](https://discuss.elastic.co/u/hokiegeek2)\
**Replies:** 3\
**Last updated:** [December 4, 2018, 2:27pm UTC](https://discuss.elastic.co/t/why-wont-metricbeat-capture-system-core-fields/159226 "2018-12-04T14:27:43Z")

</div>

I can capture system.cpu\* and system.process\* metrics with the attached metribeat.full.yaml file but not system.core.\* or system.diskio.\*. Any ideas?

---

## [Metricbeat system module, processes seems to only see metricbeat.exe](https://discuss.elastic.co/t/metricbeat-system-module-processes-seems-to-only-see-metricbeat-exe/158964)

<div class="topic-metadata">

**Author:** [@devops\_mike](https://discuss.elastic.co/u/devops_mike)\
**Replies:** 4\
**Last updated:** [December 4, 2018, 2:26pm UTC](https://discuss.elastic.co/t/metricbeat-system-module-processes-seems-to-only-see-metricbeat-exe/158964 "2018-12-04T14:26:37Z")

</div>

I am using metricbeats v 6.4. I would like to see top 5 processes by CPU and Memory. However I only see metricbeat.exe for system.process.name. I added the processes filter and set it to regex on anything ('.'). After th…

---

## [Multiline codec with Docker log driver logs](https://discuss.elastic.co/t/multiline-codec-with-docker-log-driver-logs/159155)

<div class="topic-metadata">

**Author:** [@sgarap](https://discuss.elastic.co/u/sgarap)\
**Replies:** 3\
**Last updated:** [December 4, 2018, 2:15pm UTC](https://discuss.elastic.co/t/multiline-codec-with-docker-log-driver-logs/159155 "2018-12-04T14:15:28Z")

</div>

Hi, I am using logstash 6.5 and filebeat 6.5. I want to ship all docker container logs to logstash/elasticsearch. The docker container logs are formatted through JSON log driver and each line of stack trace is created a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=397)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=399)
