# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=40

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 41

---

## [Problem multiline pattern matching](https://discuss.elastic.co/t/problem-multiline-pattern-matching/341107)

<div class="topic-metadata">

**Author:** [@mcondamin](https://discuss.elastic.co/u/mcondamin)\
**Replies:** 8\
**Last updated:** [August 28, 2023, 5:25pm UTC](https://discuss.elastic.co/t/problem-multiline-pattern-matching/341107 "2023-08-28T17:25:52Z")

</div>

Hi guys ! I defer to you because I encounter a problem concerning the configuration of the pattern to aggregate several lines of logs on the same document. Here is an excerpt from my log: 2023-08-17 16:13:15.389 |CB R…

---

## [Error during build for Beats version 8.9.1](https://discuss.elastic.co/t/error-during-build-for-beats-version-8-9-1/341778)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 12:25pm UTC](https://discuss.elastic.co/t/error-during-build-for-beats-version-8-9-1/341778 "2023-08-28T12:25:28Z")

</div>

Hi, I am facing the below error while building the beats repo. Please help to resolve the issue. Thanks Error: running "go build -o build/golang-crossbuild/filebeat-linux-amd64 -buildmode pie -trimpath -tags=withjourna…

---

## [Help: auditbeat's file\_integrity module not sending logs for created/modified/deleted files](https://discuss.elastic.co/t/help-auditbeats-file-integrity-module-not-sending-logs-for-created-modified-deleted-files/341754)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [August 27, 2023, 2:50am UTC](https://discuss.elastic.co/t/help-auditbeats-file-integrity-module-not-sending-logs-for-created-modified-deleted-files/341754 "2023-08-27T02:50:08Z")

</div>

When I create, modify, or delete a file called test.txt on my server auditbeat does not send a log for it. Not sure why because my other modules appear to be working as intended. Here's the relevant portion from my confi…

---

## [Duplicated events](https://discuss.elastic.co/t/duplicated-events/341389)

<div class="topic-metadata">

**Author:** [@Mohammed\_Amine\_El\_ha](https://discuss.elastic.co/u/Mohammed_Amine_El_ha)\
**Replies:** 2\
**Last updated:** [August 25, 2023, 4:26pm UTC](https://discuss.elastic.co/t/duplicated-events/341389 "2023-08-25T16:26:56Z")

</div>

Hi, I am fairely new to the elastic stack I am using filebeat to pull date from a Rest Api and push it to elastic. my configuration file is as follows: # ============================== Filebeat inputs ===============…

---

## [Filebeat Fortinet Module: Mismatch between event.action and event.type in Fortigate Logs](https://discuss.elastic.co/t/filebeat-fortinet-module-mismatch-between-event-action-and-event-type-in-fortigate-logs/341686)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 12:53pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-mismatch-between-event-action-and-event-type-in-fortigate-logs/341686 "2023-08-25T12:53:32Z")

</div>

Hello Elastic Community, We have set up Filebeat to use the Fortinet module for parsing logs from local files that are sent via Syslog to a Syslog server. We are currently running ELK Kibana and Filebeat version 8.7. As…

---

## [Filebeat system module does not send process name](https://discuss.elastic.co/t/filebeat-system-module-does-not-send-process-name/341423)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 10:25pm UTC](https://discuss.elastic.co/t/filebeat-system-module-does-not-send-process-name/341423 "2023-08-24T22:25:00Z")

</div>

Does anyone encounter this? There is no data in field: process name

---

## [Win32\_Service queries hanging](https://discuss.elastic.co/t/win32-service-queries-hanging/341133)

<div class="topic-metadata">

**Author:** [@\_bruno](https://discuss.elastic.co/u/_bruno)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 3:16pm UTC](https://discuss.elastic.co/t/win32-service-queries-hanging/341133 "2023-08-24T15:16:30Z")

</div>

Environment: Windows version: Windows 10 21H2, fully patched Beats versions: 8.9.0, 8.9.1 (winlogbeat and filebeat) Steps to Reproduce: Install beats versions 8.9.0 or 8.9.1 as a windows service. Attempt to make a W…

---

## [Incorrect configuration and LOGs collection problems](https://discuss.elastic.co/t/incorrect-configuration-and-logs-collection-problems/341471)

<div class="topic-metadata">

**Author:** [@Elite9400](https://discuss.elastic.co/u/Elite9400)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 3:11pm UTC](https://discuss.elastic.co/t/incorrect-configuration-and-logs-collection-problems/341471 "2023-08-24T15:11:12Z")

</div>

hello, I'm trying to use ELK in my laboratory for a study project but I'm having problems collecting log records. I currently set up my test environment like this: VM 1 - SRV401 (Windows Server 2022) I would like thi…

---

## [Ingest DNS queres from Windows DNS server using Winlogbeat](https://discuss.elastic.co/t/ingest-dns-queres-from-windows-dns-server-using-winlogbeat/341560)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 9:49am UTC](https://discuss.elastic.co/t/ingest-dns-queres-from-windows-dns-server-using-winlogbeat/341560 "2023-08-24T09:49:48Z")

</div>

Hello Community, I want to ingest to elasticsearch all DNS Queries from my MS-DNS-server 2019, How to configure winlogbeat, and that is the EvtLog name. Thanks

---

## [Can't get the logs of process.name field](https://discuss.elastic.co/t/cant-get-the-logs-of-process-name-field/341431)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 6:38am UTC](https://discuss.elastic.co/t/cant-get-the-logs-of-process-name-field/341431 "2023-08-23T06:38:58Z")

</div>

Hello, can someone tell me what is wrong why I can't get the logs on field:process.name ? I just following the instruction here https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-system.html and …

---

## [Cannot write Filebeat output to Elastic running on Docker Container on my MAC](https://discuss.elastic.co/t/cannot-write-filebeat-output-to-elastic-running-on-docker-container-on-my-mac/339970)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 5\
**Last updated:** [August 22, 2023, 11:24pm UTC](https://discuss.elastic.co/t/cannot-write-filebeat-output-to-elastic-running-on-docker-container-on-my-mac/339970 "2023-08-22T23:24:16Z")

</div>

I have created a 3 node Elastic Docker Container using the instructions from Elastic 8.2.3, and upgraded it to 8.7.1. I am able to successfully create objects in the Elastic database, and the docker-compose command succ…

---

## [File beat - handle too big registry file](https://discuss.elastic.co/t/file-beat-handle-too-big-registry-file/340719)

<div class="topic-metadata">

**Author:** [@sean\_kotler](https://discuss.elastic.co/u/sean_kotler)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 8:32pm UTC](https://discuss.elastic.co/t/file-beat-handle-too-big-registry-file/340719 "2023-08-22T20:32:53Z")

</div>

Hi Team, I would like to understand how to handle filebeat too big registry file when logs files needs to be process only once (old logs(logs that are already in my logs folder, before my filebeat service will be in use…

---

## [Filebeat Intermittently Hanging with Increasing Memory Cache while Processing High-Traffic Nginx Accesslog](https://discuss.elastic.co/t/filebeat-intermittently-hanging-with-increasing-memory-cache-while-processing-high-traffic-nginx-accesslog/339335)

<div class="topic-metadata">

**Author:** [@ryoni88](https://discuss.elastic.co/u/ryoni88)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-intermittently-hanging-with-increasing-memory-cache-while-processing-high-traffic-nginx-accesslog/339335 "2023-08-21T17:07:09Z")

</div>

Hello, I have set up a process using Filebeat to send a high traffic Nginx accesslog to Logstash. However, Filebeat intermittently hangs, with a consistent pattern of increasing memory cache. Both Filebeat and Nginx ar…

---

## [Can I use hints based autodiscovery with Docker Swarm secrets?](https://discuss.elastic.co/t/can-i-use-hints-based-autodiscovery-with-docker-swarm-secrets/340497)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 3:21pm UTC](https://discuss.elastic.co/t/can-i-use-hints-based-autodiscovery-with-docker-swarm-secrets/340497 "2023-08-21T15:21:54Z")

</div>

Per Securely manage credentials while monitoring Kubernetes workloads with autodiscovery | Elastic Blog it is possible to use Kubernetes secrets with hints based autodiscovery. Can I do the same with Docker Swarm secret…

---

## [Using kube-state-metrics (custom resource state metrics) breaks metricbeat](https://discuss.elastic.co/t/using-kube-state-metrics-custom-resource-state-metrics-breaks-metricbeat/341249)

<div class="topic-metadata">

**Author:** [@MKruger777](https://discuss.elastic.co/u/MKruger777)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 1:32pm UTC](https://discuss.elastic.co/t/using-kube-state-metrics-custom-resource-state-metrics-breaks-metricbeat/341249 "2023-08-21T13:32:04Z")

</div>

Hi there, I am running metricbeat:8.6.1 and prometheus:2.43.1 on AKS 1.25.6 Both of these are scraping metrics from kube-state-metrics:2.8.2 Because of an edge case we were forced to make use of the Custom Resource St…

---

## [Decode\_base64\_field giving weird results](https://discuss.elastic.co/t/decode-base64-field-giving-weird-results/340962)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 1:09pm UTC](https://discuss.elastic.co/t/decode-base64-field-giving-weird-results/340962 "2023-08-21T13:09:29Z")

</div>

Hello, Requirement: We are sending emails (using custom cron jobs) whenever host is down in Elasticsearch Uptime (Heartbeat). We have a need to send link to single monitor, whenever it is down. Not sure how to achieve …

---

## [Filestream data duplication in filebeat 8.9.1](https://discuss.elastic.co/t/filestream-data-duplication-in-filebeat-8-9-1/341222)

<div class="topic-metadata">

**Author:** [@germain\_nganko](https://discuss.elastic.co/u/germain_nganko)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 10:28am UTC](https://discuss.elastic.co/t/filestream-data-duplication-in-filebeat-8-9-1/341222 "2023-08-21T10:28:48Z")

</div>

Hello, I read various issues regarding the data duplication error messages in filebeat logs, However I haven't really understood what the root cause is. Please can some one explain me really what the root cause is? below…

---

## [How many Meticbeat modules can be processed at the same time?](https://discuss.elastic.co/t/how-many-meticbeat-modules-can-be-processed-at-the-same-time/341210)

<div class="topic-metadata">

**Author:** [@rhakdnj](https://discuss.elastic.co/u/rhakdnj)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/how-many-meticbeat-modules-can-be-processed-at-the-same-time/341210 "2023-08-21T08:17:25Z")

</div>

Hello. First of all, thank you for providing such a simple beat. Now I'm running haproxy as a process unit. As a result, we provide a specific haproxy\_id for each process. Accordingly, we make a haproxy module for eac…

---

## [Gather Heartbeat Monitor Data from S3 Bucket](https://discuss.elastic.co/t/gather-heartbeat-monitor-data-from-s3-bucket/341058)

<div class="topic-metadata">

**Author:** [@szhao](https://discuss.elastic.co/u/szhao)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 4:19pm UTC](https://discuss.elastic.co/t/gather-heartbeat-monitor-data-from-s3-bucket/341058 "2023-08-18T16:19:31Z")

</div>

Are you able to configure the heatbeat.config.monitors: path variable to be set to a S3 bucket? As of now, I would like to automatically generate the monitor .yaml files, store them in a S3 bucket, and then through anoth…

---

## [Filebeat restart issue](https://discuss.elastic.co/t/filebeat-restart-issue/341087)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 12:18pm UTC](https://discuss.elastic.co/t/filebeat-restart-issue/341087 "2023-08-18T12:18:15Z")

</div>

Hi, Everytime i restart Filebeat, it install all the default dashboards and searches just like running "filebeat setup". How can i change this behaviour? I sometimes need to restart Filebeat but i do not want to delete…

---

## [Could not init registrar: registry file version 1 not supported](https://discuss.elastic.co/t/could-not-init-registrar-registry-file-version-1-not-supported/341039)

<div class="topic-metadata">

**Author:** [@mrahman](https://discuss.elastic.co/u/mrahman)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 5:47pm UTC](https://discuss.elastic.co/t/could-not-init-registrar-registry-file-version-1-not-supported/341039 "2023-08-17T17:47:37Z")

</div>

Hello, I am getting this error related to registry file : │ 2023-08-17T17:23:10.691Z INFO instance/beat.go:297 Setup Beat: filebeat; Version: 7.7.0 …

---

## [Is it possible to gain an ip address from a hostname in forwarded event?](https://discuss.elastic.co/t/is-it-possible-to-gain-an-ip-address-from-a-hostname-in-forwarded-event/341029)

<div class="topic-metadata">

**Author:** [@ninom](https://discuss.elastic.co/u/ninom)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 4:46pm UTC](https://discuss.elastic.co/t/is-it-possible-to-gain-an-ip-address-from-a-hostname-in-forwarded-event/341029 "2023-08-17T16:46:47Z")

</div>

For context: windows machine -\> server -\> winlogbeats Not sure if there is a way to use either dns lookup or possibly some other method for the server to get the ip address of the windows machine from a forwarded windo…

---

## [Problems migrating from filebeat 5 to 7 - not gettings the data/fields we need in logstash](https://discuss.elastic.co/t/problems-migrating-from-filebeat-5-to-7-not-gettings-the-data-fields-we-need-in-logstash/340974)

<div class="topic-metadata">

**Author:** [@fjkoz](https://discuss.elastic.co/u/fjkoz)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 1:21pm UTC](https://discuss.elastic.co/t/problems-migrating-from-filebeat-5-to-7-not-gettings-the-data-fields-we-need-in-logstash/340974 "2023-08-17T13:21:50Z")

</div>

Hi all, Rather new to ELK in general, I am trying to migrate from filebeat v5.6.4 to filebeat 7.17.3. The problem is that the messages from the new install are not being parsed correctly. I know the document\_type as typ…

---

## [Disable IPv6 / / AAAA lookups](https://discuss.elastic.co/t/disable-ipv6-aaaa-lookups/341006)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 11:54am UTC](https://discuss.elastic.co/t/disable-ipv6-aaaa-lookups/341006 "2023-08-17T11:54:25Z")

</div>

Hi, I found out that in my GCP stack, my internal DNS setup is costing more than I anticipated. Unfortunately, it seems that there's a lookup cache issue, however, if I could prevent Filebeat using IPv6 / AAAA lookups (…

---

## [Kubernetes container labels](https://discuss.elastic.co/t/kubernetes-container-labels/340942)

<div class="topic-metadata">

**Author:** [@Omar\_Al](https://discuss.elastic.co/u/Omar_Al)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 3:59pm UTC](https://discuss.elastic.co/t/kubernetes-container-labels/340942 "2023-08-16T15:59:08Z")

</div>

We are in the process of creating a new instance of filebeat where we switch the container runtime to containerd, and we previously searched for a label in the docker container, but since we switched to containerd, we wo…

---

## [Invalid CRI error (Filebeat 7.17 + docker)](https://discuss.elastic.co/t/invalid-cri-error-filebeat-7-17-docker/340930)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 1:57pm UTC](https://discuss.elastic.co/t/invalid-cri-error-filebeat-7-17-docker/340930 "2023-08-16T13:57:17Z")

</div>

Hi there! We have a weird problem when Filebeat gets stuck on partial message in Container logs. Parse line error: invalid CRI log format {"level":"error","timestamp":"2023-08-03T11:55:49.674Z","logger":"reader\_docker…

---

## [Registry log.json grows constantly even with filebeat.registry.flush: 60s](https://discuss.elastic.co/t/registry-log-json-grows-constantly-even-with-filebeat-registry-flush-60s/340923)

<div class="topic-metadata">

**Author:** [@pkulenkamp](https://discuss.elastic.co/u/pkulenkamp)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 1:04pm UTC](https://discuss.elastic.co/t/registry-log-json-grows-constantly-even-with-filebeat-registry-flush-60s/340923 "2023-08-16T13:04:24Z")

</div>

Filebeat 7.17.1 I'm looking into decreasing the amount of IO for the filebeat registry in our deployment. I found the filebeat.registry.flush setting after some research and thought that it would do what I wanted. I s…

---

## [Not setting the elasticsearchRef for setting beat output](https://discuss.elastic.co/t/not-setting-the-elasticsearchref-for-setting-beat-output/340878)

<div class="topic-metadata">

**Author:** [@alexns](https://discuss.elastic.co/u/alexns)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 7:44am UTC](https://discuss.elastic.co/t/not-setting-the-elasticsearchref-for-setting-beat-output/340878 "2023-08-16T07:44:42Z")

</div>

Hello, We have a k8s cluster dedicated running monitoring software. Elastic Search is installed here using the ECK operator and the CRD's. On another cluster, we have filebeat running using the deprecated helm charts. …

---

## [Filebeat Cisco module Nexus fileset dissect\_parsing\_error flag](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548)

<div class="topic-metadata">

**Author:** [@obol89](https://discuss.elastic.co/u/obol89)\
**Replies:** 2\
**Last updated:** [August 15, 2023, 1:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548 "2023-08-15T13:45:04Z")

</div>

I'm trying to use Filebeat with Cisco module and Nexus fileset, but it seems like these logs aren't parsed properly. In every document I see - dissect\_parsing\_error in log.flags. It looks like that: filebeat versio…

---

## [Filebeat cannot connect with Elasticsearch (ELK Stack setup for Suricata)](https://discuss.elastic.co/t/filebeat-cannot-connect-with-elasticsearch-elk-stack-setup-for-suricata/340728)

<div class="topic-metadata">

**Author:** [@jstnolmeme](https://discuss.elastic.co/u/jstnolmeme)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 10:15am UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-with-elasticsearch-elk-stack-setup-for-suricata/340728 "2023-08-14T10:15:18Z")

</div>

I'm new to Elastic, so please go easy on me :)). I am working on a project that requires ELK stack to monitor and display dashboards, based on logs collected from the IDS, Suricata. I am running a Droplet instance on D…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=39)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=41)
