# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=400

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 401

---

## [How to configure spacesid for multiple spaces in beats](https://discuss.elastic.co/t/how-to-configure-spacesid-for-multiple-spaces-in-beats/158884)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 4\
**Last updated:** [November 30, 2018, 11:19am UTC](https://discuss.elastic.co/t/how-to-configure-spacesid-for-multiple-spaces-in-beats/158884 "2018-11-30T11:19:10Z")

</div>

Hello I am wondering how to configure spacesid in the beats config files for supporting multiple spaces. I have tried with beatsid: \['Default', 'test', 'test2'\] but it's not working because it's requiring a string instea…

---

## [Ignoring old files](https://discuss.elastic.co/t/ignoring-old-files/158372)

<div class="topic-metadata">

**Author:** [@tryptych](https://discuss.elastic.co/u/tryptych)\
**Replies:** 1\
**Last updated:** [November 30, 2018, 9:43am UTC](https://discuss.elastic.co/t/ignoring-old-files/158372 "2018-11-30T09:43:46Z")

</div>

I'm new to beats. I am having a lot of trouble getting filebeat to ignore old files. I have ignore\_older: 48h in my filebeats.yml but it does not seem to be working. Why? My folder contains millions of files and it's imp…

---

## [Regarding Filebeat and Kubernetes](https://discuss.elastic.co/t/regarding-filebeat-and-kubernetes/158557)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [November 30, 2018, 8:36am UTC](https://discuss.elastic.co/t/regarding-filebeat-and-kubernetes/158557 "2018-11-30T08:36:17Z")

</div>

Hi, I'm weighing using a filebeat daemonset for shipping logs output by docker and written to disk on kubernetes nodes. Can I ask, is filebeat able to manage the logs on disk? That is, if the disk usage grows above a …

---

## [Harvestor not starting for all files](https://discuss.elastic.co/t/harvestor-not-starting-for-all-files/158585)

<div class="topic-metadata">

**Author:** [@ErSumit](https://discuss.elastic.co/u/ErSumit)\
**Replies:** 2\
**Last updated:** [November 30, 2018, 8:13am UTC](https://discuss.elastic.co/t/harvestor-not-starting-for-all-files/158585 "2018-11-30T08:13:26Z")

</div>

I have added few parameters into filebeat.yml and restarted it found filebeat is not starting harvestor for all files multiline.timeout: 25s close\_timeout: 60m close\_removed: true ignore\_older: 48h clean\_inac…

---

## [signalEvent not be closed](https://discuss.elastic.co/t/signalevent-not-be-closed/157966)

<div class="topic-metadata">

**Author:** [@wenhaochen](https://discuss.elastic.co/u/wenhaochen)\
**Replies:** 4\
**Last updated:** [November 30, 2018, 3:01am UTC](https://discuss.elastic.co/t/signalevent-not-be-closed/157966 "2018-11-30T03:01:13Z")

</div>

Hi， code from https://github.com/elastic/beats/blob/master/winlogbeat/eventlog/wineventlog.go#L125 signalEvent not be closed, handle leak might happen when calling Open()func many times ? and one more thing confus…

---

## [Add iis.access.user\_agent.original to be searchable / displayable?](https://discuss.elastic.co/t/add-iis-access-user-agent-original-to-be-searchable-displayable/158647)

<div class="topic-metadata">

**Author:** [@Brett\_Larson](https://discuss.elastic.co/u/Brett_Larson)\
**Replies:** 3\
**Last updated:** [November 29, 2018, 8:48pm UTC](https://discuss.elastic.co/t/add-iis-access-user-agent-original-to-be-searchable-displayable/158647 "2018-11-29T20:48:43Z")

</div>

Hello, Is it possible to make the index filed for Apache or IIS or Nginx for the .access.user\_agent.original string show up as searchable and aggregatable? I'd like to have this show up as sometimes all of the user age…

---

## [Monitor Remote Server](https://discuss.elastic.co/t/monitor-remote-server/157935)

<div class="topic-metadata">

**Author:** [@ELE](https://discuss.elastic.co/u/ELE)\
**Replies:** 6\
**Last updated:** [November 29, 2018, 7:58pm UTC](https://discuss.elastic.co/t/monitor-remote-server/157935 "2018-11-29T19:58:44Z")

</div>

Hi, I just install on single VM elastic & metricbeat I'm able to view the host overview in Kibana dashboard, but I have two questions: Is there metricbeat view per process (not host), like dashboard which showing th…

---

## [Error while make setup in beat in windows 10](https://discuss.elastic.co/t/error-while-make-setup-in-beat-in-windows-10/157960)

<div class="topic-metadata">

**Author:** [@sumanjha](https://discuss.elastic.co/u/sumanjha)\
**Replies:** 4\
**Last updated:** [November 29, 2018, 3:25pm UTC](https://discuss.elastic.co/t/error-while-make-setup-in-beat-in-windows-10/157960 "2018-11-29T15:25:04Z")

</div>

hi team, I am getting error while make setup the custom beat in cmd after generating the beat. please help D:\\custom beat\\src\\github.com\\Elastic\\mybeat\>make setup INFO: Could not find files for the given pattern(s). …

---

## [How to monitor inode using metricbeat?](https://discuss.elastic.co/t/how-to-monitor-inode-using-metricbeat/158279)

<div class="topic-metadata">

**Author:** [@Aftab\_Ali](https://discuss.elastic.co/u/Aftab_Ali)\
**Replies:** 4\
**Last updated:** [November 29, 2018, 3:13pm UTC](https://discuss.elastic.co/t/how-to-monitor-inode-using-metricbeat/158279 "2018-11-29T15:13:06Z")

</div>

Dear Team, Suddenly, My server's inodes got full used ( 100% ), I am not able to create any directory in Linux system, Please guide me how to monitor linux system inode monitoring using metricbeat?

---

## [Filebeat6.5.1 also has memory leaks?](https://discuss.elastic.co/t/filebeat6-5-1-also-has-memory-leaks/158443)

<div class="topic-metadata">

**Author:** [@guot6261](https://discuss.elastic.co/u/guot6261)\
**Replies:** 0\
**Last updated:** [November 28, 2018, 2:50am UTC](https://discuss.elastic.co/t/filebeat6-5-1-also-has-memory-leaks/158443 "2018-11-28T02:50:15Z")

</div>

Hi filebeat experts, We still have the memory leak problem on filbeat 6.5.1. Can anyone help us to resolved it or give us some suggestions? We once used filebeat 6.0 in our production environment but found that there w…

---

## [Remove input.type and prospector.type fields that appear in Kibana's hits](https://discuss.elastic.co/t/remove-input-type-and-prospector-type-fields-that-appear-in-kibanas-hits/154361)

<div class="topic-metadata">

**Author:** [@dx123](https://discuss.elastic.co/u/dx123)\
**Replies:** 1\
**Last updated:** [October 29, 2018, 7:11pm UTC](https://discuss.elastic.co/t/remove-input-type-and-prospector-type-fields-that-appear-in-kibanas-hits/154361 "2018-10-29T19:11:50Z")

</div>

I'm using Filebeat to ingest some files into Logstash for data manipulation and thereafter indexed to Elasticsearch and displayed in Kibana. However I have fields such as input.type and prospector.type that has the "log"…

---

## [Log Forwarding not working from any clients](https://discuss.elastic.co/t/log-forwarding-not-working-from-any-clients/158001)

<div class="topic-metadata">

**Author:** [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Replies:** 6\
**Last updated:** [November 29, 2018, 7:27am UTC](https://discuss.elastic.co/t/log-forwarding-not-working-from-any-clients/158001 "2018-11-29T07:27:38Z")

</div>

Hi All, I'm facing some weird situation. Recently, I installed ELK on Redhat which was successful. Now, I installed filebeat on client machine (Redhat) and log forwarding was happening, then went further and installed f…

---

## [Unable to send or receive log details](https://discuss.elastic.co/t/unable-to-send-or-receive-log-details/157381)

<div class="topic-metadata">

**Author:** [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Replies:** 16\
**Last updated:** [November 29, 2018, 7:25am UTC](https://discuss.elastic.co/t/unable-to-send-or-receive-log-details/157381 "2018-11-29T07:25:57Z")

</div>

Hi Team, This is the new setup of ELK. Till now, everything has been installed properly. Kibana dashboard is up and running, elasticsearch, logstash, filebeat and nginx has been installed successfully. I am facing some …

---

## [How to disable dynamic\_templates in packetbeat](https://discuss.elastic.co/t/how-to-disable-dynamic-templates-in-packetbeat/158695)

<div class="topic-metadata">

**Author:** [@mhsankar](https://discuss.elastic.co/u/mhsankar)\
**Replies:** 0\
**Last updated:** [November 29, 2018, 6:40am UTC](https://discuss.elastic.co/t/how-to-disable-dynamic-templates-in-packetbeat/158695 "2018-11-29T06:40:38Z")

</div>

Hi when start packetbeat .it create an index template in elastic. it has a section called dynamic\_templates how can i remove this section in packetbeat.yml? i dont want create new field if not exists.

---

## [Filebeat and logstash-output with loadbalance](https://discuss.elastic.co/t/filebeat-and-logstash-output-with-loadbalance/158473)

<div class="topic-metadata">

**Author:** [@unix196](https://discuss.elastic.co/u/unix196)\
**Replies:** 2\
**Last updated:** [November 29, 2018, 5:49am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-output-with-loadbalance/158473 "2018-11-29T05:49:18Z")

</div>

from documentation: loadbalance: If set to true and multiple Logstash hosts are configured, the output plugin load balances published events onto all Logstash hosts. If set to false, the output plugin sends all events…

---

## [Filebeat is unable to read from the source directory and write to destination file](https://discuss.elastic.co/t/filebeat-is-unable-to-read-from-the-source-directory-and-write-to-destination-file/158673)

<div class="topic-metadata">

**Author:** [@mudigonda05](https://discuss.elastic.co/u/mudigonda05)\
**Replies:** 1\
**Last updated:** [November 29, 2018, 4:17am UTC](https://discuss.elastic.co/t/filebeat-is-unable-to-read-from-the-source-directory-and-write-to-destination-file/158673 "2018-11-29T04:17:50Z")

</div>

Hi, I am new to Filebeat. I am trying to read a file using filebeat and save the read content to a new file in my local system. I have pulled the docker image from the elastic docker repository and have mounted filebea…

---

## [\[Ubuntu\] Metricbeat Service Privilege Levels](https://discuss.elastic.co/t/ubuntu-metricbeat-service-privilege-levels/158668)

<div class="topic-metadata">

**Author:** [@mhasanbulli](https://discuss.elastic.co/u/mhasanbulli)\
**Replies:** 0\
**Last updated:** [November 29, 2018, 12:55am UTC](https://discuss.elastic.co/t/ubuntu-metricbeat-service-privilege-levels/158668 "2018-11-29T00:55:31Z")

</div>

Hello, As part of our internal standards for Linux (Ubuntu) VMs, when it is necessary to install a service, we create a user account, assign that user account to security groups and run that new service using that parti…

---

## [Create rollup job fails - Rejecting mapping update due to multiple types](https://discuss.elastic.co/t/create-rollup-job-fails-rejecting-mapping-update-due-to-multiple-types/158594)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [November 28, 2018, 2:57pm UTC](https://discuss.elastic.co/t/create-rollup-job-fails-rejecting-mapping-update-due-to-multiple-types/158594 "2018-11-28T14:57:50Z")

</div>

hi all, currently I'm collecting documents using Metricbeat (v.6.5.1) client. I have enabled only the system module. when I try to create a rollup job I face this error: Request failed with a error. An internal server…

---

## [Trying to set up a filebeat-ES-Kibana cluster](https://discuss.elastic.co/t/trying-to-set-up-a-filebeat-es-kibana-cluster/158513)

<div class="topic-metadata">

**Author:** [@johnny90210](https://discuss.elastic.co/u/johnny90210)\
**Replies:** 2\
**Last updated:** [November 28, 2018, 10:28am UTC](https://discuss.elastic.co/t/trying-to-set-up-a-filebeat-es-kibana-cluster/158513 "2018-11-28T10:28:36Z")

</div>

hi, I'm trying to set up a Docker cluster where Filebeat forwards logs to ES, which I can then view in Kibana. All components are v5.6.13. The cluster comes up fine but I don't see the logs being forwarded. There are no…

---

## [Function beat is for x-pack only](https://discuss.elastic.co/t/function-beat-is-for-x-pack-only/156832)

<div class="topic-metadata">

**Author:** [@shahid](https://discuss.elastic.co/u/shahid)\
**Replies:** 3\
**Last updated:** [November 28, 2018, 7:06am UTC](https://discuss.elastic.co/t/function-beat-is-for-x-pack-only/156832 "2018-11-28T07:06:03Z")

</div>

Hi Team, First of all , i would like to say "Good work" to all funcationbeat tech team. my question is . 1 - Is this only for X-pack users? 2 - do i need to install this beat on my ELK and shipper servers? I am us…

---

## [Auditbeat setting unspecified rule](https://discuss.elastic.co/t/auditbeat-setting-unspecified-rule/157045)

<div class="topic-metadata">

**Author:** [@nlh](https://discuss.elastic.co/u/nlh)\
**Replies:** 9\
**Last updated:** [November 28, 2018, 1:24am UTC](https://discuss.elastic.co/t/auditbeat-setting-unspecified-rule/157045 "2018-11-28T01:24:05Z")

</div>

Hi, Running Auditbeat 6.4.2 and the rules in the .yml file are: audit\_rules: | -w /etc/auditbeat/auditbeat.yml -p wa -k auditbeat\_issue -w /etc/passwd -p wa -k passwd\_changes -w /PTC/ -p wr -k ptc\_code\_acc…

---

## [Select() return -1,errno=1. run filebeat by golang code](https://discuss.elastic.co/t/select-return-1-errno-1-run-filebeat-by-golang-code/157969)

<div class="topic-metadata">

**Author:** [@zhaoya881010](https://discuss.elastic.co/u/zhaoya881010)\
**Replies:** 4\
**Last updated:** [November 27, 2018, 11:43pm UTC](https://discuss.elastic.co/t/select-return-1-errno-1-run-filebeat-by-golang-code/157969 "2018-11-27T23:43:55Z")

</div>

i found question," select return -1,error=1", run filebeate in my instance. test code: main.go: package main /\* #include \<sys/types.h\> #include \<sys/socket.h\> #include \<stdio.h\> #include \<netinet/in.h\> #include \<…

---

## [Filbeat still OOMs?](https://discuss.elastic.co/t/filbeat-still-ooms/156211)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 36\
**Last updated:** [November 27, 2018, 8:55pm UTC](https://discuss.elastic.co/t/filbeat-still-ooms/156211 "2018-11-27T20:55:05Z")

</div>

Hi, running 6.4.2 I see this in my /var/log/messages Nov 11 18:49:37 xxxxxx-0002 systemd: filebeat.service: main process exited, code=exited, status=2/INVALIDARGUMENT Nov 11 18:49:37 xxxxxx-0002 systemd: Unit filebea…

---

## [Filebeat hitting payload size limit with AWS ElasticSearch](https://discuss.elastic.co/t/filebeat-hitting-payload-size-limit-with-aws-elasticsearch/158396)

<div class="topic-metadata">

**Author:** [@spiffytech](https://discuss.elastic.co/u/spiffytech)\
**Replies:** 2\
**Last updated:** [November 27, 2018, 8:17pm UTC](https://discuss.elastic.co/t/filebeat-hitting-payload-size-limit-with-aws-elasticsearch/158396 "2018-11-27T20:17:26Z")

</div>

ElasticSearch is telling FileBeat that the payload is too large. I've tried setting bulk\_max\_size to 1 and still have the problem. My logs shouldn't be over 10MB in a single message, but maybe I'm wrong about that. Here…

---

## [Metricbeat Postgres Activity event has all empty values](https://discuss.elastic.co/t/metricbeat-postgres-activity-event-has-all-empty-values/158400)

<div class="topic-metadata">

**Author:** [@krainboltgreene](https://discuss.elastic.co/u/krainboltgreene)\
**Replies:** 0\
**Last updated:** [November 27, 2018, 6:53pm UTC](https://discuss.elastic.co/t/metricbeat-postgres-activity-event-has-all-empty-values/158400 "2018-11-27T18:53:17Z")

</div>

{ "docker": { "container": { "id": "78ffe79a6d7221fb806a13fc35d54d24c4111f086026d1968e3fceb4c1504340", "name": "20181126185317\_sentry-postgres\_1", "image": "postgres:10.5-alpine", "labels": { "com": { …

---

## [Can not get host Primary Username Tag in auditbeat](https://discuss.elastic.co/t/can-not-get-host-primary-username-tag-in-auditbeat/158188)

<div class="topic-metadata">

**Author:** [@bertolis](https://discuss.elastic.co/u/bertolis)\
**Replies:** 2\
**Last updated:** [November 27, 2018, 4:44pm UTC](https://discuss.elastic.co/t/can-not-get-host-primary-username-tag-in-auditbeat/158188 "2018-11-27T16:44:42Z")

</div>

I run auditbeat with "docker-compose up". On "Executions" tab on Kibana's Dashboard i try to monitor sudo commands from different users on the host machine, but eve if switch users and run sudo commands, auditbeat show t…

---

## [Filebeat not getting data from all configured sources](https://discuss.elastic.co/t/filebeat-not-getting-data-from-all-configured-sources/158337)

<div class="topic-metadata">

**Author:** [@Astarandel](https://discuss.elastic.co/u/Astarandel)\
**Replies:** 3\
**Last updated:** [November 27, 2018, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-not-getting-data-from-all-configured-sources/158337 "2018-11-27T15:45:41Z")

</div>

Greetings, we are experiencing the following issue with Filebeat. After we start the Filebeat instance it registers three inputs. Unfortunately it pulls info only from one. Here is the debug log. 018-11-27T11:34:26.895…

---

## [Downgrade Filebeat](https://discuss.elastic.co/t/downgrade-filebeat/158354)

<div class="topic-metadata">

**Author:** [@bayoumben](https://discuss.elastic.co/u/bayoumben)\
**Replies:** 1\
**Last updated:** [November 27, 2018, 2:25pm UTC](https://discuss.elastic.co/t/downgrade-filebeat/158354 "2018-11-27T14:25:19Z")

</div>

It's installed via yum.

---

## [Filebeat + Visualize Map dont' work](https://discuss.elastic.co/t/filebeat-visualize-map-dont-work/156075)

<div class="topic-metadata">

**Author:** [@autorun1918](https://discuss.elastic.co/u/autorun1918)\
**Replies:** 3\
**Last updated:** [November 27, 2018, 2:14pm UTC](https://discuss.elastic.co/t/filebeat-visualize-map-dont-work/156075 "2018-11-27T14:14:47Z")

</div>

Hello all, I have problem with my filebeat iis logs. I have this: But when i go to Visualize -\> Coordinate Map and configure like that: Map dont show Circle Markers.

---

## [How to check if filebeat is up to date with the input file](https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989)

<div class="topic-metadata">

**Author:** [@Aakash\_Ratkal](https://discuss.elastic.co/u/Aakash_Ratkal)\
**Replies:** 3\
**Last updated:** [November 27, 2018, 11:15am UTC](https://discuss.elastic.co/t/how-to-check-if-filebeat-is-up-to-date-with-the-input-file/156989 "2018-11-27T11:15:06Z")

</div>

I am using filebeat to ingest my log file. I need to handle the case where my application scales down and on of the instance is terminated. In this case, is there any way, I can check if all my log lines have been ingest…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=399)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=401)
