# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=401

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 402

---

## [Get logs of all channel Event](https://discuss.elastic.co/t/get-logs-of-all-channel-event/158065)

<div class="topic-metadata">

**Author:** [@paniccontrol](https://discuss.elastic.co/u/paniccontrol)\
**Replies:** 1\
**Last updated:** [November 27, 2018, 11:10am UTC](https://discuss.elastic.co/t/get-logs-of-all-channel-event/158065 "2018-11-27T11:10:28Z")

</div>

Is there any way to tell winlogbeat to get alls channel that can be present on a machine ? What's can be found by: Get-WinEvent -ListLog \* | Format-List -Property LogName

---

## [How to get diskio read and write counts for a particular process](https://discuss.elastic.co/t/how-to-get-diskio-read-and-write-counts-for-a-particular-process/157692)

<div class="topic-metadata">

**Author:** [@kunapaneni\_siddharth](https://discuss.elastic.co/u/kunapaneni_siddharth)\
**Replies:** 6\
**Last updated:** [November 27, 2018, 11:10am UTC](https://discuss.elastic.co/t/how-to-get-diskio-read-and-write-counts-for-a-particular-process/157692 "2018-11-27T11:10:19Z")

</div>

Can we get the read and write io counts (system.diskio.read.count and system.diskio.write.count) for a specific process(system.process.name)?

---

## [Metricbeat 6.5 zookeeper modules problem](https://discuss.elastic.co/t/metricbeat-6-5-zookeeper-modules-problem/158112)

<div class="topic-metadata">

**Author:** [@sicute](https://discuss.elastic.co/u/sicute)\
**Replies:** 3\
**Last updated:** [November 27, 2018, 9:53am UTC](https://discuss.elastic.co/t/metricbeat-6-5-zookeeper-modules-problem/158112 "2018-11-27T09:53:01Z")

</div>

hi all , I try activate modules zookeeper . here zookeeper.yml :~$ cat /etc/metricbeat/modules.d/zookeeper.yml module: zookeeper enabled: true metricsets: \["mntr"\] period: 10s hosts: \["localhost:2181"\] ~$ an…

---

## [No dashboard data for Filebeat](https://discuss.elastic.co/t/no-dashboard-data-for-filebeat/158249)

<div class="topic-metadata">

**Author:** [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Replies:** 2\
**Last updated:** [November 27, 2018, 8:21am UTC](https://discuss.elastic.co/t/no-dashboard-data-for-filebeat/158249 "2018-11-27T08:21:20Z")

</div>

hello, I have basic System filebeat sending logs to my ELK isntance, I can see the log data in Discover the filebeat is installed on a testbox (not on ELK instance), and I have the following filebeat.yml config, but…

---

## [Filebeat 6.5.1 unable to send syslog](https://discuss.elastic.co/t/filebeat-6-5-1-unable-to-send-syslog/157819)

<div class="topic-metadata">

**Author:** [@princeOfMacedon](https://discuss.elastic.co/u/princeOfMacedon)\
**Replies:** 5\
**Last updated:** [November 27, 2018, 8:00am UTC](https://discuss.elastic.co/t/filebeat-6-5-1-unable-to-send-syslog/157819 "2018-11-27T08:00:31Z")

</div>

Hi all! I'm using filebeat 6.5.1 and I'm encountering this error: filebeat\[29062\]: Exiting: Can only start an input when all related states are finished: {Id:2537-66305 Finished:false Fileinfo:0xc420213860 Source:/var/…

---

## [Fresh install, metricbeat data hard to use in Discover](https://discuss.elastic.co/t/fresh-install-metricbeat-data-hard-to-use-in-discover/157147)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 2\
**Last updated:** [November 26, 2018, 8:54pm UTC](https://discuss.elastic.co/t/fresh-install-metricbeat-data-hard-to-use-in-discover/157147 "2018-11-26T20:54:51Z")

</div>

I decom'd an old server with an old version of ELK, set up a fresh install of current versions on a clean server, and updated the file & metric beats on a couple clients to test things out. I let the 2 beats do their in…

---

## [Metricbeat upgrade to 6.5.1 removes the host from Kibana dashboards and visualisations](https://discuss.elastic.co/t/metricbeat-upgrade-to-6-5-1-removes-the-host-from-kibana-dashboards-and-visualisations/158169)

<div class="topic-metadata">

**Author:** [@jsanders](https://discuss.elastic.co/u/jsanders)\
**Replies:** 2\
**Last updated:** [November 26, 2018, 8:53pm UTC](https://discuss.elastic.co/t/metricbeat-upgrade-to-6-5-1-removes-the-host-from-kibana-dashboards-and-visualisations/158169 "2018-11-26T20:53:23Z")

</div>

I've been testing an ELK stack setup with metric beats for monitoring and have noticed odd behaviour. If I upgrade metricbeats to 6.5.1 from the elastic.co repos in Ubuntu then the data is still shipped to my logstash/el…

---

## [Finding missing hosts](https://discuss.elastic.co/t/finding-missing-hosts/158225)

<div class="topic-metadata">

**Author:** [@rdesanno](https://discuss.elastic.co/u/rdesanno)\
**Replies:** 0\
**Last updated:** [November 26, 2018, 5:01pm UTC](https://discuss.elastic.co/t/finding-missing-hosts/158225 "2018-11-26T17:01:31Z")

</div>

I work in a semi-large environment running filebeat and auditbeat on most of my hosts, 1536 hosts to be exact. Today is one of those rare days where 1 host is missing or not reporting in and was wondering how others deal…

---

## [Which metricbeat field tells me total memory used by filebeat?](https://discuss.elastic.co/t/which-metricbeat-field-tells-me-total-memory-used-by-filebeat/158218)

<div class="topic-metadata">

**Author:** [@savvy](https://discuss.elastic.co/u/savvy)\
**Replies:** 0\
**Last updated:** [November 26, 2018, 4:35pm UTC](https://discuss.elastic.co/t/which-metricbeat-field-tells-me-total-memory-used-by-filebeat/158218 "2018-11-26T16:35:17Z")

</div>

Hi all, We are collecting different metrics with the help of metricbeat 6.2.3. I want to see the total memory usage by filebeat in each server. What field is it in the metricbeat that shows those data? Is it system.proc…

---

## [Can't get app\_process\_metadata to work in Filebeat](https://discuss.elastic.co/t/cant-get-app-process-metadata-to-work-in-filebeat/158106)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 2\
**Last updated:** [November 26, 2018, 4:26pm UTC](https://discuss.elastic.co/t/cant-get-app-process-metadata-to-work-in-filebeat/158106 "2018-11-26T16:26:42Z")

</div>

I use two add\_process\_metadata directives in my metric beat config to get the parent process info and extra details on the specific process. Now I'm trying to add extra process information to syslog messages pulled in vi…

---

## [Setup output to Elasticsearch through Centralized Management](https://discuss.elastic.co/t/setup-output-to-elasticsearch-through-centralized-management/157881)

<div class="topic-metadata">

**Author:** [@mladen](https://discuss.elastic.co/u/mladen)\
**Replies:** 16\
**Last updated:** [November 26, 2018, 2:24pm UTC](https://discuss.elastic.co/t/setup-output-to-elasticsearch-through-centralized-management/157881 "2018-11-26T14:24:29Z")

</div>

Hello, could you please help me to setup Elasticsearch output. I managed to enroll my metricbeat agent but I don't get any information from agent. As you can see I have created tag razvoj\_metricbeat: And this is my …

---

## [Docker input via autodiscovery not always json-decoding message](https://discuss.elastic.co/t/docker-input-via-autodiscovery-not-always-json-decoding-message/157859)

<div class="topic-metadata">

**Author:** [@lifeofguenter](https://discuss.elastic.co/u/lifeofguenter)\
**Replies:** 4\
**Last updated:** [November 26, 2018, 1:23pm UTC](https://discuss.elastic.co/t/docker-input-via-autodiscovery-not-always-json-decoding-message/157859 "2018-11-26T13:23:56Z")

</div>

using the docker-input it seems that sometimes the message is a json: logstash\_1\_7c18eb226755 | "message" =\> "{\\"log\\":\\"192.168.80.1 - - \[22/Nov/2018:10:38:46 +0000\] \\\\\\"GET / HTTP/1.1\\\\\\" 200 612 \\\\\\"-\\\\\\" \\\\\\…

---

## [Azure Functions support](https://discuss.elastic.co/t/azure-functions-support/157766)

<div class="topic-metadata">

**Author:** [@alastairs](https://discuss.elastic.co/u/alastairs)\
**Replies:** 3\
**Last updated:** [November 26, 2018, 1:11pm UTC](https://discuss.elastic.co/t/azure-functions-support/157766 "2018-11-26T13:11:41Z")

</div>

Hi there What's the timeframe for support for Azure Functions in Functionbeat? We're using a custom solution at the moment and would love to give Functionbeat a spin when there's something available. Alastair

---

## [UUID assigned to enrolled Windows Filebeat agent not matching one in Central Management Console](https://discuss.elastic.co/t/uuid-assigned-to-enrolled-windows-filebeat-agent-not-matching-one-in-central-management-console/158051)

<div class="topic-metadata">

**Author:** [@jboshears](https://discuss.elastic.co/u/jboshears)\
**Replies:** 1\
**Last updated:** [November 26, 2018, 12:54pm UTC](https://discuss.elastic.co/t/uuid-assigned-to-enrolled-windows-filebeat-agent-not-matching-one-in-central-management-console/158051 "2018-11-26T12:54:57Z")

</div>

Hello, I upgraded our ELK instance to 6.5.1 and installed the Windows Filebeat 6.5.1 agent on a Windows system I wanted to monitor. All seemed to be running fine. I decided to try out the new Filebeat centralized mana…

---

## [Filebeat consuming disk space](https://discuss.elastic.co/t/filebeat-consuming-disk-space/158145)

<div class="topic-metadata">

**Author:** [@ErSumit](https://discuss.elastic.co/u/ErSumit)\
**Replies:** 5\
**Last updated:** [November 26, 2018, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-consuming-disk-space/158145 "2018-11-26T12:46:24Z")

</div>

Filebeat process is utilizing disk space. No clue why and where? Whenever disk utilization reaches high, I restarted filebeat service and disk utilization reduced. How can I fix this? ''' \[ec2-user@tomcat ~\] df -H Fi…

---

## [Modules reported as "no data" despite data being available](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 7\
**Last updated:** [November 26, 2018, 10:40am UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046 "2018-11-26T10:40:38Z")

</div>

Went into "kibana" / "add data" and checked for data from a few metrics. Some appear to be working (EG system, k8) while others (EG kafka, elastic) (despite having data in dashboards, etc) show here as "no data received"…

---

## [Filebeat send not all log files](https://discuss.elastic.co/t/filebeat-send-not-all-log-files/158073)

<div class="topic-metadata">

**Author:** [@forthgate](https://discuss.elastic.co/u/forthgate)\
**Replies:** 1\
**Last updated:** [November 26, 2018, 8:19am UTC](https://discuss.elastic.co/t/filebeat-send-not-all-log-files/158073 "2018-11-26T08:19:26Z")

</div>

I got this Filebeat config: I got this Filebeat config: filebeat.prospectors: - input\_type: log paths: - /var/lib/docker/containers/\*/\*.log document\_type: docker json.message\_key: log output.elasticsearch: host…

---

## [Mac Mojave, Filebeat, System Module, no syslogs sent](https://discuss.elastic.co/t/mac-mojave-filebeat-system-module-no-syslogs-sent/158079)

<div class="topic-metadata">

**Author:** [@DPattee](https://discuss.elastic.co/u/DPattee)\
**Replies:** 1\
**Last updated:** [November 26, 2018, 12:15am UTC](https://discuss.elastic.co/t/mac-mojave-filebeat-system-module-no-syslogs-sent/158079 "2018-11-26T00:15:33Z")

</div>

There are 2 issues I'm encountering using filebeat on my Mac. Older versions of filebeat, elastic, and Mac OS worked, but I've decom'd those servers so can't do any direct comparisons. filebeat version 6.5.0 (amd64), li…

---

## [Tool to generate Windows events](https://discuss.elastic.co/t/tool-to-generate-windows-events/157533)

<div class="topic-metadata">

**Author:** [@Suny](https://discuss.elastic.co/u/Suny)\
**Replies:** 1\
**Last updated:** [November 25, 2018, 10:35pm UTC](https://discuss.elastic.co/t/tool-to-generate-windows-events/157533 "2018-11-25T22:35:35Z")

</div>

We would like to generate different kinds of events, of a broad range of MS products and of Windows itself, ideally faking different hostnames as sender. Does anyone know of a tool to achieve this?

---

## [Docker container custom logs - how to process them into kibana](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188)

<div class="topic-metadata">

**Author:** [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Replies:** 7\
**Last updated:** [November 24, 2018, 9:56am UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188 "2018-11-24T09:56:25Z")

</div>

I have many containers running on server. One of them is nginx - I enabled filebeat module nginx, I have also created /etc/logstash/conf.d/nginx.conf -taken from website https://www.elastic.co/guide/en/logstash/current/l…

---

## [Auditbeat](https://discuss.elastic.co/t/auditbeat/157487)

<div class="topic-metadata">

**Author:** [@DavisDxb](https://discuss.elastic.co/u/DavisDxb)\
**Replies:** 1\
**Last updated:** [November 23, 2018, 10:35am UTC](https://discuss.elastic.co/t/auditbeat/157487 "2018-11-23T10:35:29Z")

</div>

I installed Auditbeat 6.5 in Ubuntu 16.4 Platform.Installation correct,It is running status Active.But in Kibana indices not found shows, How I resolve the Issue.

---

## [Can filebeat send to different LS servers based on hostname criteria](https://discuss.elastic.co/t/can-filebeat-send-to-different-ls-servers-based-on-hostname-criteria/157028)

<div class="topic-metadata">

**Author:** [@minz](https://discuss.elastic.co/u/minz)\
**Replies:** 2\
**Last updated:** [November 16, 2018, 2:31pm UTC](https://discuss.elastic.co/t/can-filebeat-send-to-different-ls-servers-based-on-hostname-criteria/157028 "2018-11-16T14:31:54Z")

</div>

Hello, I'm wondering if filebeat can be configured with many output.logstash hosts but would send the data only to one LS acording to a condition. For instance, I have 4 machines (F1,F2,F3,F4) owning the same configura…

---

## [Metricbeat Unable to Connect to ElasticSearch, DNS Lookup Failed?](https://discuss.elastic.co/t/metricbeat-unable-to-connect-to-elasticsearch-dns-lookup-failed/154387)

<div class="topic-metadata">

**Author:** [@dlimantoro](https://discuss.elastic.co/u/dlimantoro)\
**Replies:** 10\
**Last updated:** [November 23, 2018, 1:31am UTC](https://discuss.elastic.co/t/metricbeat-unable-to-connect-to-elasticsearch-dns-lookup-failed/154387 "2018-11-23T01:31:43Z")

</div>

Hi, I have a server that hosts the elasticsearch (call it server A, it's located at 10.150.160.145) and my metricbeat is deployed to many servers on the same network. 9 out of 10 manages to send its metricbeat data to se…

---

## [Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch - Certificate problem?](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch-certificate-problem/157909)

<div class="topic-metadata">

**Author:** [@rpaterson](https://discuss.elastic.co/u/rpaterson)\
**Replies:** 1\
**Last updated:** [November 22, 2018, 5:23pm UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch-certificate-problem/157909 "2018-11-22T17:23:54Z")

</div>

Hey followed this guide to install ELK on a Ubuntu VM. https://www.howtoforge.com/tutorial/ubuntu-elastic-stack/ Can't get filebeat to start. Don't know what I've done wrong. Get this error when running 'sudo service fi…

---

## [How can we Reload full filebeat.yml?](https://discuss.elastic.co/t/how-can-we-reload-full-filebeat-yml/157754)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 3\
**Last updated:** [November 22, 2018, 4:07pm UTC](https://discuss.elastic.co/t/how-can-we-reload-full-filebeat-yml/157754 "2018-11-22T16:07:59Z")

</div>

please help........ Can we implement this feature using signal and channel in windows.

---

## [Need inode or file timestamp in the event](https://discuss.elastic.co/t/need-inode-or-file-timestamp-in-the-event/157711)

<div class="topic-metadata">

**Author:** [@laxman1](https://discuss.elastic.co/u/laxman1)\
**Replies:** 3\
**Last updated:** [November 22, 2018, 2:20pm UTC](https://discuss.elastic.co/t/need-inode-or-file-timestamp-in-the-event/157711 "2018-11-22T14:20:38Z")

</div>

Hi, We are facing a log rotation problem while filebeat is streaming a particular file. I have a File named Log\_34.txt and when it was streaming it gets renamed to Log\_34.txt2018 and a new file with Log\_34.txt gets cre…

---

## [Skip log rotation at service restart?](https://discuss.elastic.co/t/skip-log-rotation-at-service-restart/157876)

<div class="topic-metadata">

**Author:** [@antwan](https://discuss.elastic.co/u/antwan)\
**Replies:** 4\
**Last updated:** [November 22, 2018, 2:04pm UTC](https://discuss.elastic.co/t/skip-log-rotation-at-service-restart/157876 "2018-11-22T14:04:35Z")

</div>

Continuing the discussion from Filebeat's logs rotation malfunctioning: Did you look into disabling log rotation at service restart? Would be a welcome feature. /Anders

---

## [How's working filebeat module with ingest pipeline?](https://discuss.elastic.co/t/hows-working-filebeat-module-with-ingest-pipeline/157837)

<div class="topic-metadata">

**Author:** [@kingil](https://discuss.elastic.co/u/kingil)\
**Replies:** 1\
**Last updated:** [November 22, 2018, 1:52pm UTC](https://discuss.elastic.co/t/hows-working-filebeat-module-with-ingest-pipeline/157837 "2018-11-22T13:52:17Z")

</div>

Hello, guys! I am working with syslog + logstash + ES + kibana. Now, i have an idea: escape logstash, add filebeat to hosts and use it with modules (i hearing that filebeat can grok events with ingest pipelines on ES n…

---

## [Converting filebeat.template.json to fields.yml](https://discuss.elastic.co/t/converting-filebeat-template-json-to-fields-yml/157850)

<div class="topic-metadata">

**Author:** [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Replies:** 1\
**Last updated:** [November 22, 2018, 1:32pm UTC](https://discuss.elastic.co/t/converting-filebeat-template-json-to-fields-yml/157850 "2018-11-22T13:32:38Z")

</div>

I am in the process of upgrading from filebeat 5 alpha 4 (-: to latest 6.5.1 How do I convert filebeat.template.json to fields.yml? Whats the syntax for the first part of the document with mappings and dynamic\_templates…

---

## [Timestamps precision in beats](https://discuss.elastic.co/t/timestamps-precision-in-beats/154646)

<div class="topic-metadata">

**Author:** [@George\_Sovetov](https://discuss.elastic.co/u/George_Sovetov)\
**Replies:** 10\
**Last updated:** [November 22, 2018, 1:31pm UTC](https://discuss.elastic.co/t/timestamps-precision-in-beats/154646 "2018-11-22T13:31:21Z")

</div>

What does Filebeat do about timestamps? Especially when "backpressure" feature is working. More generally, how do I get synchronized timestamps? On machines, time may misalign and, moreover, it may change while Filebea…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=400)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=402)
