# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=399

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 400

---

## [Autodiscover for multiple dynamic ports per container](https://discuss.elastic.co/t/autodiscover-for-multiple-dynamic-ports-per-container/158811)

<div class="topic-metadata">

**Author:** [@mng12689](https://discuss.elastic.co/u/mng12689)\
**Replies:** 1\
**Last updated:** [December 4, 2018, 2:07pm UTC](https://discuss.elastic.co/t/autodiscover-for-multiple-dynamic-ports-per-container/158811 "2018-12-04T14:07:01Z")

</div>

Hello, I have metricbeat installed on an EC2 instance that contains multiple docker containers, each with an Envoy proxy inside. Each container exposes 2 Envoy ports on the host (one for application traffic and one for …

---

## [Application logs rotation issue](https://discuss.elastic.co/t/application-logs-rotation-issue/158751)

<div class="topic-metadata">

**Author:** [@W.anjum](https://discuss.elastic.co/u/W.anjum)\
**Replies:** 2\
**Last updated:** [December 4, 2018, 1:43pm UTC](https://discuss.elastic.co/t/application-logs-rotation-issue/158751 "2018-12-04T13:43:23Z")

</div>

I have application that rotates its log files using python file rotation module every hour. Whenever I run filebeat my application crashes with the error 'Cannot Rename: Text File Busy'. I have tried close\_\* option and d…

---

## [Filebeat - how limit events per second?](https://discuss.elastic.co/t/filebeat-how-limit-events-per-second/159099)

<div class="topic-metadata">

**Author:** [@unix196](https://discuss.elastic.co/u/unix196)\
**Replies:** 3\
**Last updated:** [December 4, 2018, 11:40am UTC](https://discuss.elastic.co/t/filebeat-how-limit-events-per-second/159099 "2018-12-04T11:40:44Z")

</div>

Good day everyone. One server have 2 containers with filebeat 6.4. This two containers read logs and generate over 10.000 events per second =\> leads some troubles: server contain other containers which generate some …

---

## [MetricBeat : Vsphere](https://discuss.elastic.co/t/metricbeat-vsphere/159130)

<div class="topic-metadata">

**Author:** [@adelbot](https://discuss.elastic.co/u/adelbot)\
**Replies:** 2\
**Last updated:** [December 4, 2018, 6:59am UTC](https://discuss.elastic.co/t/metricbeat-vsphere/159130 "2018-12-04T06:59:59Z")

</div>

Hello, in virtualmachine.go, i note +1 // If only "Distributed port group" was found, for example. if len(networkRefs) == 0 { return nil, errors.New("no networks found") } Why you don't use "the Distributed port gro…

---

## [Filebeat not harvesting logs and output not sent to ElasticSearch](https://discuss.elastic.co/t/filebeat-not-harvesting-logs-and-output-not-sent-to-elasticsearch/159128)

<div class="topic-metadata">

**Author:** [@kancherlarajesh](https://discuss.elastic.co/u/kancherlarajesh)\
**Replies:** 1\
**Last updated:** [December 3, 2018, 11:21pm UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-logs-and-output-not-sent-to-elasticsearch/159128 "2018-12-03T23:21:53Z")

</div>

Hi There, I am new to ELK. I have configure Elastic Search, Kibana on Linux box and Configure Filebeat on Windows. I am able to view Windows Filebeat details from Kibana however, FileBeat is not sending output to Elasti…

---

## [\[HTTP check\] Override Host header](https://discuss.elastic.co/t/http-check-override-host-header/157660)

<div class="topic-metadata">

**Author:** [@Alexkl](https://discuss.elastic.co/u/Alexkl)\
**Replies:** 1\
**Last updated:** [December 3, 2018, 11:01pm UTC](https://discuss.elastic.co/t/http-check-override-host-header/157660 "2018-12-03T23:01:24Z")

</div>

Hello, I have troubles overriding the Host header. I want to test individually: My CDN My varnish My backend To do that i need to check the IP with a custom Header, if i had to script it i would use Curl: curl -I…

---

## [Can i use heartbeat for this usecase? Sending custom, dynamic payload via tcp](https://discuss.elastic.co/t/can-i-use-heartbeat-for-this-usecase-sending-custom-dynamic-payload-via-tcp/157317)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [December 3, 2018, 10:59pm UTC](https://discuss.elastic.co/t/can-i-use-heartbeat-for-this-usecase-sending-custom-dynamic-payload-via-tcp/157317 "2018-12-03T22:59:00Z")

</div>

Hi folks, I am currently unfamiliar with heartbeat. Please tell me if my usecase can be accomplished with heartbeat. usecase: I want to connect to a tcp port. I need to send specific payload to the port. The Payload …

---

## [If more than one filebeat instance started, how do the modules work?](https://discuss.elastic.co/t/if-more-than-one-filebeat-instance-started-how-do-the-modules-work/158950)

<div class="topic-metadata">

**Author:** [@argb](https://discuss.elastic.co/u/argb)\
**Replies:** 1\
**Last updated:** [December 3, 2018, 10:41pm UTC](https://discuss.elastic.co/t/if-more-than-one-filebeat-instance-started-how-do-the-modules-work/158950 "2018-12-03T22:41:04Z")

</div>

For some stupid reasons maybe I have to run more than one filebeat instance, if it is how do the modules work? Every instance will run one time for same files repeatedly? And how should i setup the config files? Of cour…

---

## [To grok or not to grok?](https://discuss.elastic.co/t/to-grok-or-not-to-grok/158926)

<div class="topic-metadata">

**Author:** [@jdswifty](https://discuss.elastic.co/u/jdswifty)\
**Replies:** 1\
**Last updated:** [December 3, 2018, 10:28pm UTC](https://discuss.elastic.co/t/to-grok-or-not-to-grok/158926 "2018-12-03T22:28:46Z")

</div>

Hi Looking for some advice from the elastic community I need to parse the following log entry into separate fields. My initial thoughts were to try & write a grok pattern as the structure is the same for each log entr…

---

## [Filebeat: Connection to Logstash fails, then immediately tries backoff and that works](https://discuss.elastic.co/t/filebeat-connection-to-logstash-fails-then-immediately-tries-backoff-and-that-works/158912)

<div class="topic-metadata">

**Author:** [@bluecoffee](https://discuss.elastic.co/u/bluecoffee)\
**Replies:** 1\
**Last updated:** [December 3, 2018, 10:25pm UTC](https://discuss.elastic.co/t/filebeat-connection-to-logstash-fails-then-immediately-tries-backoff-and-that-works/158912 "2018-12-03T22:25:52Z")

</div>

Hi guys, I have a dockerized Filebeat 6.5.1 instance that monitors my docker containers using the docker input. Basically every time a log line is found by Filebeat, I get a Failed to publish events / connection reset …

---

## [Fresh installation apparently imports logs for few seconds and then stops](https://discuss.elastic.co/t/fresh-installation-apparently-imports-logs-for-few-seconds-and-then-stops/158877)

<div class="topic-metadata">

**Author:** [@Pastrufazio](https://discuss.elastic.co/u/Pastrufazio)\
**Replies:** 1\
**Last updated:** [December 3, 2018, 10:24pm UTC](https://discuss.elastic.co/t/fresh-installation-apparently-imports-logs-for-few-seconds-and-then-stops/158877 "2018-12-03T22:24:44Z")

</div>

Hi all, I installed this new environment: SERVER (loststash+elasticsearch+kibana) logstash 6.5.1 elasticsearch 6.5.1 kibana 6.5.1 REMOTE MACHINE (generating logs) filebeat 5.0.1 I passed to filebeat our old logs,…

---

## [Metricbeat Docker Container uses different field name format](https://discuss.elastic.co/t/metricbeat-docker-container-uses-different-field-name-format/158422)

<div class="topic-metadata">

**Author:** [@krainboltgreene](https://discuss.elastic.co/u/krainboltgreene)\
**Replies:** 2\
**Last updated:** [December 3, 2018, 5:43pm UTC](https://discuss.elastic.co/t/metricbeat-docker-container-uses-different-field-name-format/158422 "2018-12-03T17:43:37Z")

</div>

t docker.container.labels.com\_docker\_compose\_config-hash db6349188d084d7ffc61147577d6256df4eacbcb90e8a573eb05c970e0b56c42 t docker.container.labels.com\_docker\_compose\_container-number 1 t docker.contai…

---

## [Filebeat windows service is not starting](https://discuss.elastic.co/t/filebeat-windows-service-is-not-starting/157776)

<div class="topic-metadata">

**Author:** [@kommineni24](https://discuss.elastic.co/u/kommineni24)\
**Replies:** 3\
**Last updated:** [December 3, 2018, 5:17pm UTC](https://discuss.elastic.co/t/filebeat-windows-service-is-not-starting/157776 "2018-12-03T17:17:41Z")

</div>

Hi, Am using filebeat to read log files and stash it in logstash. But am not able to start the service of filebeat. As am new to ELK, I followed the instructions given in the guide and it says the below command to be e…

---

## [Parse JSON logs from only certain Kubernetes deployments](https://discuss.elastic.co/t/parse-json-logs-from-only-certain-kubernetes-deployments/158377)

<div class="topic-metadata">

**Author:** [@benjamingorman](https://discuss.elastic.co/u/benjamingorman)\
**Replies:** 7\
**Last updated:** [December 3, 2018, 2:11pm UTC](https://discuss.elastic.co/t/parse-json-logs-from-only-certain-kubernetes-deployments/158377 "2018-12-03T14:11:04Z")

</div>

Hi! I have a question about parsing JSON log messages produced by Kubernetes deployments. I've already seen this thread, this page in the docs, and this page. None of those seem relevant however. The problem is that so…

---

## [Typo in syslog\_rfc3164.rl causes parsing errors for December syslog dates](https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030)

<div class="topic-metadata">

**Author:** [@rhclayto](https://discuss.elastic.co/u/rhclayto)\
**Replies:** 2\
**Last updated:** [December 3, 2018, 2:03pm UTC](https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030 "2018-12-03T14:03:23Z")

</div>

For confirmed bugs, please report: Version: 6.3.2 Operating System: FreeBSD GitHub Link: https://github.com/elastic/beats/issues/9323 Steps to Reproduce: With the system clock on the computer where filebeat is install…

---

## [Unable to bring containers down/stop containers whilst metricbeat is running](https://discuss.elastic.co/t/unable-to-bring-containers-down-stop-containers-whilst-metricbeat-is-running/157345)

<div class="topic-metadata">

**Author:** [@adaisley](https://discuss.elastic.co/u/adaisley)\
**Replies:** 3\
**Last updated:** [December 3, 2018, 11:42am UTC](https://discuss.elastic.co/t/unable-to-bring-containers-down-stop-containers-whilst-metricbeat-is-running/157345 "2018-12-03T11:42:21Z")

</div>

Hi guys. We have several hosts running metricbeat via docker and sometimes when bringing other containers down with docker-compose/stopping them also using docker-compose, we get the following error: ERROR: for \[contai…

---

## [Java stacktrace multiline](https://discuss.elastic.co/t/java-stacktrace-multiline/158430)

<div class="topic-metadata">

**Author:** [@bbking](https://discuss.elastic.co/u/bbking)\
**Replies:** 2\
**Last updated:** [December 1, 2018, 1:18am UTC](https://discuss.elastic.co/t/java-stacktrace-multiline/158430 "2018-12-01T01:18:24Z")

</div>

I'm trying to use multiline in Filebeat to parse Java stacktrace as shown below but still have a hard time extracting and grouping all needed data. \[Mon Nov 26 02:58:42 PST 2018\] HEARTBEAT count=1 rev=\*\*\* PRODUCT- URI:…

---

## [Error creating runner from config: reading docker input config: missing field accessing 'containers.ids.0'](https://discuss.elastic.co/t/error-creating-runner-from-config-reading-docker-input-config-missing-field-accessing-containers-ids-0/158589)

<div class="topic-metadata">

**Author:** [@farodin91](https://discuss.elastic.co/u/farodin91)\
**Replies:** 4\
**Last updated:** [December 3, 2018, 7:34am UTC](https://discuss.elastic.co/t/error-creating-runner-from-config-reading-docker-input-config-missing-field-accessing-containers-ids-0/158589 "2018-12-03T07:34:48Z")

</div>

I have the same bug for docker container instead of kubernetes pods Filebeat (6.4.2) autodiscover on Kubernetes. Missing field accessing 'containers.ids.0' Please include configurations and logs if available. 2018-11-2…

---

## [Unable to use kubernetes metadata in custom fields](https://discuss.elastic.co/t/unable-to-use-kubernetes-metadata-in-custom-fields/158855)

<div class="topic-metadata">

**Author:** [@AMITH1284](https://discuss.elastic.co/u/AMITH1284)\
**Replies:** 2\
**Last updated:** [December 3, 2018, 6:01am UTC](https://discuss.elastic.co/t/unable-to-use-kubernetes-metadata-in-custom-fields/158855 "2018-12-03T06:01:46Z")

</div>

I am unable to access kubernetes metadata in custom fields. Can someone please help? config: - type: docker containers.ids: - "\*" fields\_under\_root: true processors: - add\_kubernet…

---

## [Is it possible to archive and analyze 1 year metricbeat in kibana](https://discuss.elastic.co/t/is-it-possible-to-archive-and-analyze-1-year-metricbeat-in-kibana/158273)

<div class="topic-metadata">

**Author:** [@sarava](https://discuss.elastic.co/u/sarava)\
**Replies:** 14\
**Last updated:** [December 3, 2018, 6:27am UTC](https://discuss.elastic.co/t/is-it-possible-to-archive-and-analyze-1-year-metricbeat-in-kibana/158273 "2018-12-03T06:27:15Z")

</div>

Hi, Can anyone help me? How to do archive and analyze the metricbeat data in kibana. How to setup the infrastructure as well ??

---

## [One(1) date-field as default in index templates is not enough, or is it?](https://discuss.elastic.co/t/one-1-date-field-as-default-in-index-templates-is-not-enough-or-is-it/159012)

<div class="topic-metadata">

**Author:** [@antwan](https://discuss.elastic.co/u/antwan)\
**Replies:** 0\
**Last updated:** [December 1, 2018, 6:02pm UTC](https://discuss.elastic.co/t/one-1-date-field-as-default-in-index-templates-is-not-enough-or-is-it/159012 "2018-12-01T18:02:27Z")

</div>

It would be beneficial to have one more, i.e: @timestamp when the logs are written, solves the question "When did the incident occur?" @received\_at when the logs are read, solves the question "When did we know the inci…

---

## [Unable to start the metric beat in ELK 6.5.4](https://discuss.elastic.co/t/unable-to-start-the-metric-beat-in-elk-6-5-4/158859)

<div class="topic-metadata">

**Author:** [@subhash.parise](https://discuss.elastic.co/u/subhash.parise)\
**Replies:** 8\
**Last updated:** [December 1, 2018, 3:21am UTC](https://discuss.elastic.co/t/unable-to-start-the-metric-beat-in-elk-6-5-4/158859 "2018-12-01T03:21:30Z")

</div>

Hi Team, I have successfully installed and enabled mongod module for metricbeat in elk 6.5.4 while starting the metricbeat facing below error and i have checked metricbeat.yml file seems fine. \*\*Error Log: \*\* 2018-11…

---

## [I need send different logs to different output destination, but why filebeat don't suport?](https://discuss.elastic.co/t/i-need-send-different-logs-to-different-output-destination-but-why-filebeat-dont-suport/158834)

<div class="topic-metadata">

**Author:** [@argb](https://discuss.elastic.co/u/argb)\
**Replies:** 4\
**Last updated:** [November 30, 2018, 9:21pm UTC](https://discuss.elastic.co/t/i-need-send-different-logs-to-different-output-destination-but-why-filebeat-dont-suport/158834 "2018-11-30T21:21:12Z")

</div>

I have many different kinds of logs, such as php system mysql etc, on same server, and i need to send them to different output destinations, it's very common use cases, and it's very import! But WHY can't filebeat supor…

---

## [How to use IIS Module with Logstash?](https://discuss.elastic.co/t/how-to-use-iis-module-with-logstash/158368)

<div class="topic-metadata">

**Author:** [@devops\_mike](https://discuss.elastic.co/u/devops_mike)\
**Replies:** 7\
**Last updated:** [November 30, 2018, 8:38pm UTC](https://discuss.elastic.co/t/how-to-use-iis-module-with-logstash/158368 "2018-11-30T20:38:50Z")

</div>

I would like to parse my IIS logs into more fields. Both the URL as well as the query string contains data I would like to extract and store in a field. It seems like sending the logs to Logstash rather than directly to…

---

## [Error: unknown command "enroll" for "metricbeat"](https://discuss.elastic.co/t/error-unknown-command-enroll-for-metricbeat/157132)

<div class="topic-metadata">

**Author:** [@Matt\_Vasquez](https://discuss.elastic.co/u/Matt_Vasquez)\
**Replies:** 3\
**Last updated:** [November 30, 2018, 3:22pm UTC](https://discuss.elastic.co/t/error-unknown-command-enroll-for-metricbeat/157132 "2018-11-30T15:22:49Z")

</div>

Anyone know if Beats Central Management in 6.5 is supported on Metricbeat 6.5 for Windows?? using: PS C:\\Program Files\\metricbeat\> metricbeat.exe enroll https://localhost:5601/kibana d20f2f72baab42 c78a1961267424c086 T…

---

## [Error(out of memory): running "make update"](https://discuss.elastic.co/t/error-out-of-memory-running-make-update/157597)

<div class="topic-metadata">

**Author:** [@gaetanoziri](https://discuss.elastic.co/u/gaetanoziri)\
**Replies:** 7\
**Last updated:** [November 30, 2018, 3:14pm UTC](https://discuss.elastic.co/t/error-out-of-memory-running-make-update/157597 "2018-11-30T15:14:01Z")

</div>

Hi, I am trying to build a custom filebeat module following this guide. As the last step the command make update returns: Error: running "make update" failed with exit code 2 I've no idea what's causing this problem. …

---

## [Filebeat - Haproxy - Dashboard](https://discuss.elastic.co/t/filebeat-haproxy-dashboard/158328)

<div class="topic-metadata">

**Author:** [@aviator](https://discuss.elastic.co/u/aviator)\
**Replies:** 5\
**Last updated:** [November 30, 2018, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-dashboard/158328 "2018-11-30T13:39:00Z")

</div>

Hi Have run the filebeat setup binary (6.5.1 linux) and have various sample dashboards but not HA-Proxy. I see there is a file Filebeat-haproxy-overview.json which I tried to blindly import from saved objects in Kibana…

---

## [Filebeat Windows/Linux discrepancies](https://discuss.elastic.co/t/filebeat-windows-linux-discrepancies/158228)

<div class="topic-metadata">

**Author:** [@aleksandar.todorov](https://discuss.elastic.co/u/aleksandar.todorov)\
**Replies:** 5\
**Last updated:** [November 30, 2018, 12:32pm UTC](https://discuss.elastic.co/t/filebeat-windows-linux-discrepancies/158228 "2018-11-30T12:32:11Z")

</div>

I see a discrepancy in Filebeat output between Linux and Windows. ELK setup: ELK server - Ubuntu 18.04.1 LTS Elasticsearch version 6.3.2 Logstash version 6.3.2 Kibana version 6.3.2 ELK node 1 - Ubuntu 18.04.1 LTS, F…

---

## [Tag a message on the filebeat side to be able to filter on kibana ( HTTP response codes )](https://discuss.elastic.co/t/tag-a-message-on-the-filebeat-side-to-be-able-to-filter-on-kibana-http-response-codes/158500)

<div class="topic-metadata">

**Author:** [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Replies:** 4\
**Last updated:** [November 30, 2018, 11:25am UTC](https://discuss.elastic.co/t/tag-a-message-on-the-filebeat-side-to-be-able-to-filter-on-kibana-http-response-codes/158500 "2018-11-30T11:25:13Z")

</div>

Hi, I have this configuration: filebeat.prospectors: - type: log enabled: true paths: - /var/log/messages - /var/log/secure - /var/log/audit/audit.log - /var/log/yum.log - /root/.bash\_history …

---

## [How can filebeat crawling and send to kafka in real time](https://discuss.elastic.co/t/how-can-filebeat-crawling-and-send-to-kafka-in-real-time/158706)

<div class="topic-metadata">

**Author:** [@Ruiyi\_Luo](https://discuss.elastic.co/u/Ruiyi_Luo)\
**Replies:** 1\
**Last updated:** [November 30, 2018, 11:22am UTC](https://discuss.elastic.co/t/how-can-filebeat-crawling-and-send-to-kafka-in-real-time/158706 "2018-11-30T11:22:37Z")

</div>

However I optimize with various config params. There are always 3 seconds delay. My filebeat.yml as below: filebeat.inputs: type: log enabled: true fields: log\_topics: ngaudio\_test paths: /data/logs/action-pos…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=398)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=400)
