# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=403

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 404

---

## [Suddenly metricbeat was not sending date to elasticsearch for 8 to 10 minutes, Why?](https://discuss.elastic.co/t/suddenly-metricbeat-was-not-sending-date-to-elasticsearch-for-8-to-10-minutes-why/157275)

<div class="topic-metadata">

**Author:** [@Aftab\_Ali](https://discuss.elastic.co/u/Aftab_Ali)\
**Replies:** 2\
**Last updated:** [November 20, 2018, 12:05pm UTC](https://discuss.elastic.co/t/suddenly-metricbeat-was-not-sending-date-to-elasticsearch-for-8-to-10-minutes-why/157275 "2018-11-20T12:05:00Z")

</div>

Dear Team, I have a setup of elasticsearch which is configured with metricbeat agent, yesterday for 8 to 9 minutes suddenly elasticsearch did not get metribeat data from the client machine, Suddenly I happened, Please s…

---

## [Filebeat container is starting listening UDP need to change to TCP](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908)

<div class="topic-metadata">

**Author:** [@Ranjith\_M](https://discuss.elastic.co/u/Ranjith_M)\
**Replies:** 4\
**Last updated:** [November 20, 2018, 10:49am UTC](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908 "2018-11-20T10:49:41Z")

</div>

Filebeat Version : 6.5 We need to know how can configure the haproxy module for filebeat . Currently the filebeat container is starting listening UDP connections in localhost:9001, we need to know how change the protoco…

---

## [Multiline, Multi Field input question - newbie here](https://discuss.elastic.co/t/multiline-multi-field-input-question-newbie-here/156166)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 8\
**Last updated:** [November 20, 2018, 10:29am UTC](https://discuss.elastic.co/t/multiline-multi-field-input-question-newbie-here/156166 "2018-11-20T10:29:39Z")

</div>

I am putting together bits and pieces from examples to create my first custom filebeats input. I have 10s of thousands of these files, that I would like to read into ES. cdv\_nrings=8 cdv\_phone=16188835888 cdv\_informat=…

---

## [Import Metricbeat (6.4) dashboard into Kibana 5.6 without direct connection](https://discuss.elastic.co/t/import-metricbeat-6-4-dashboard-into-kibana-5-6-without-direct-connection/157450)

<div class="topic-metadata">

**Author:** [@Eric\_Duquesnoy](https://discuss.elastic.co/u/Eric_Duquesnoy)\
**Replies:** 2\
**Last updated:** [November 20, 2018, 10:09am UTC](https://discuss.elastic.co/t/import-metricbeat-6-4-dashboard-into-kibana-5-6-without-direct-connection/157450 "2018-11-20T10:09:33Z")

</div>

Hi , I run metricbeat 6.4 on different nodes and send the date to one only redis server through a firewall. Afterward these data are sent to ES 5.X via Logstash. I would like to use the metricbeat dashboard for docker…

---

## [Instantaneaously failing to publish events](https://discuss.elastic.co/t/instantaneaously-failing-to-publish-events/157037)

<div class="topic-metadata">

**Author:** [@kgl](https://discuss.elastic.co/u/kgl)\
**Replies:** 4\
**Last updated:** [November 20, 2018, 9:50am UTC](https://discuss.elastic.co/t/instantaneaously-failing-to-publish-events/157037 "2018-11-20T09:50:53Z")

</div>

Hi there, while adding a fifth path into my Filebeat service I came across some problems by not receiving the data in question. Going through the log file I encountered the following lines: Timestamp Loglevel File M…

---

## [Json Parsing using Filebeat](https://discuss.elastic.co/t/json-parsing-using-filebeat/156661)

<div class="topic-metadata">

**Author:** [@Sanj](https://discuss.elastic.co/u/Sanj)\
**Replies:** 2\
**Last updated:** [November 20, 2018, 8:16am UTC](https://discuss.elastic.co/t/json-parsing-using-filebeat/156661 "2018-11-20T08:16:50Z")

</div>

Hi Team, I'm trying to parse a log file which contain data in the format of JSON like mentioned below \< { agentId: "TMS", apiVersion: "v2", entities: \[ { agentId: "ServerName1", name: "UPCWOCHKDGT", cacheManage…

---

## [How to filebeat config to multi-line?](https://discuss.elastic.co/t/how-to-filebeat-config-to-multi-line/157460)

<div class="topic-metadata">

**Author:** [@teichae](https://discuss.elastic.co/u/teichae)\
**Replies:** 1\
**Last updated:** [November 20, 2018, 4:46am UTC](https://discuss.elastic.co/t/how-to-filebeat-config-to-multi-line/157460 "2018-11-20T04:46:29Z")

</div>

Hi, guys. I want to create a multi-line rule in filebeat. How do I specify a multi-line rule in the format shown below? 2018:11:20 01:58:22.721 INFO --- \[http-nio-8080-exec-10\] o.a.coyote.http11.Http11Processor : Err…

---

## [Filebeat IIS logs not sending all logs - how can I troubleshoot?](https://discuss.elastic.co/t/filebeat-iis-logs-not-sending-all-logs-how-can-i-troubleshoot/157082)

<div class="topic-metadata">

**Author:** [@Brett\_Larson](https://discuss.elastic.co/u/Brett_Larson)\
**Replies:** 1\
**Last updated:** [November 20, 2018, 5:51am UTC](https://discuss.elastic.co/t/filebeat-iis-logs-not-sending-all-logs-how-can-i-troubleshoot/157082 "2018-11-20T05:51:44Z")

</div>

Hello, We are in the process of moving from OMS to Elastic using the managed cloud. I have setup filebeat and the IIS module however i'm not seeing that logs are ingested at the same rate they are in OMS. There is in fa…

---

## [Metricbeat modules.d as hostpath](https://discuss.elastic.co/t/metricbeat-modules-d-as-hostpath/157458)

<div class="topic-metadata">

**Author:** [@Pavan\_Kumar2](https://discuss.elastic.co/u/Pavan_Kumar2)\
**Replies:** 0\
**Last updated:** [November 20, 2018, 1:48am UTC](https://discuss.elastic.co/t/metricbeat-modules-d-as-hostpath/157458 "2018-11-20T01:48:08Z")

</div>

Hi, I new to elastic beats. I have a question regarding metricbeat.. Whenever I try to use hostpath for modules.d for metricbeat, the data in modules.d in pod gets removed and replaced by nothing (modules.d folder becom…

---

## [Filesystem metricset not reporting nfs and other host filesystems](https://discuss.elastic.co/t/filesystem-metricset-not-reporting-nfs-and-other-host-filesystems/157133)

<div class="topic-metadata">

**Author:** [@cchenna](https://discuss.elastic.co/u/cchenna)\
**Replies:** 0\
**Last updated:** [November 16, 2018, 8:42pm UTC](https://discuss.elastic.co/t/filesystem-metricset-not-reporting-nfs-and-other-host-filesystems/157133 "2018-11-16T20:42:25Z")

</div>

Using the Filesystem metricset and only 2 host filesystem usage is being reported. I don't see the other host filesystems and also the nfs filesystem usage mounted to the server. Following is the config i am using: mo…

---

## [No longer needed](https://discuss.elastic.co/t/no-longer-needed/157099)

<div class="topic-metadata">

**Author:** [@Ben\_Hastings](https://discuss.elastic.co/u/Ben_Hastings)\
**Replies:** 1\
**Last updated:** [November 19, 2018, 9:29pm UTC](https://discuss.elastic.co/t/no-longer-needed/157099 "2018-11-19T21:29:20Z")

</div>

the system wouldn't let me delete the post, so I've deleted the content instead.

---

## [Filebeat 6.5.0 does not send data to logstash 6.5.0](https://discuss.elastic.co/t/filebeat-6-5-0-does-not-send-data-to-logstash-6-5-0/157428)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 3\
**Last updated:** [November 19, 2018, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-6-5-0-does-not-send-data-to-logstash-6-5-0/157428 "2018-11-19T20:48:20Z")

</div>

Hello, I am using filebeat 6.5.0 with the following configuration: filebeat.inputs: - type: log enabled: true paths: - /home/jetty/logs/\*.log exclude\_files: /home/jetty/logs/OLD/\* filebeat.config.modules: p…

---

## [Metricbeat is not capturing CPU and DISK information](https://discuss.elastic.co/t/metricbeat-is-not-capturing-cpu-and-disk-information/153075)

<div class="topic-metadata">

**Author:** [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Replies:** 20\
**Last updated:** [November 19, 2018, 5:33pm UTC](https://discuss.elastic.co/t/metricbeat-is-not-capturing-cpu-and-disk-information/153075 "2018-11-19T17:33:47Z")

</div>

Hello Team, I have enabled system module in metricbeat but all I see is Processora details in Elasticsearch but I don;t find anything CPU/CORE/DISK related information captured. any idea? system.yml Dell-TMO-CT-Cass1…

---

## [Adding fields when using autodiscovery](https://discuss.elastic.co/t/adding-fields-when-using-autodiscovery/157135)

<div class="topic-metadata">

**Author:** [@Daniel\_Jensen](https://discuss.elastic.co/u/Daniel_Jensen)\
**Replies:** 1\
**Last updated:** [November 19, 2018, 5:19pm UTC](https://discuss.elastic.co/t/adding-fields-when-using-autodiscovery/157135 "2018-11-19T17:19:42Z")

</div>

I have been trying to add custom fields to logs being picked up by filebeat when running in kubernetes using a DaemonSet. My logging provider requires this and I'm having quite a bit of trouble simply adding fields base…

---

## [Can't enable system module: Compressor detection can only be called on some xcontent bytes or compressed xcontent bytes](https://discuss.elastic.co/t/cant-enable-system-module-compressor-detection-can-only-be-called-on-some-xcontent-bytes-or-compressed-xcontent-bytes/156971)

<div class="topic-metadata">

**Author:** [@AlexJ](https://discuss.elastic.co/u/AlexJ)\
**Replies:** 3\
**Last updated:** [November 19, 2018, 2:08pm UTC](https://discuss.elastic.co/t/cant-enable-system-module-compressor-detection-can-only-be-called-on-some-xcontent-bytes-or-compressed-xcontent-bytes/156971 "2018-11-19T14:08:48Z")

</div>

Hello. I am running Filebeat 6.4 and Elasticsearch 6.3 on Amazon Linux 2018.03 and am receiving the following error in my filebeat log: { "level":"error", "timestamp":"2018-11-16T03:56:40.395Z", "caller":"pipeline/outpu…

---

## [\[Metricbeat\] uwsgi unexpected end of JSON input](https://discuss.elastic.co/t/metricbeat-uwsgi-unexpected-end-of-json-input/157311)

<div class="topic-metadata">

**Author:** [@Gennady\_Karev](https://discuss.elastic.co/u/Gennady_Karev)\
**Replies:** 0\
**Last updated:** [November 19, 2018, 9:16am UTC](https://discuss.elastic.co/t/metricbeat-uwsgi-unexpected-end-of-json-input/157311 "2018-11-19T09:16:08Z")

</div>

Hi there, after configuring uwsig module, Ive got errors 2018-11-19T09:15:20.299Z ERROR status/data.go:65 uwsgi statistics parsing failed with error: %!(EXTRA \*json.SyntaxError=unexpected end of JSON inpu…

---

## [Exiting: 1 error: no metricsets configured for module 'http'](https://discuss.elastic.co/t/exiting-1-error-no-metricsets-configured-for-module-http/157342)

<div class="topic-metadata">

**Author:** [@kvs\_raju](https://discuss.elastic.co/u/kvs_raju)\
**Replies:** 0\
**Last updated:** [November 19, 2018, 12:15pm UTC](https://discuss.elastic.co/t/exiting-1-error-no-metricsets-configured-for-module-http/157342 "2018-11-19T12:15:05Z")

</div>

I am trying to configure metric beat for windows module. Facing following error while initiating the configs to kibana. Exiting: 1 error: no metricsets configured for module 'http'

---

## [Avoid to create new visualizations](https://discuss.elastic.co/t/avoid-to-create-new-visualizations/156866)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 5\
**Last updated:** [November 19, 2018, 10:50am UTC](https://discuss.elastic.co/t/avoid-to-create-new-visualizations/156866 "2018-11-19T10:50:51Z")

</div>

Hi all, I'm trying to use default Metricbeat visualizations and dashboard of System module. Working just with one cluster I have not any issue but if I start to play with another cluster (i.e. another environment), I w…

---

## [Winlogbeat sending sysmon data to kibana](https://discuss.elastic.co/t/winlogbeat-sending-sysmon-data-to-kibana/154168)

<div class="topic-metadata">

**Author:** [@godfather7](https://discuss.elastic.co/u/godfather7)\
**Replies:** 7\
**Last updated:** [November 19, 2018, 6:47am UTC](https://discuss.elastic.co/t/winlogbeat-sending-sysmon-data-to-kibana/154168 "2018-11-19T06:47:46Z")

</div>

in the kibana dashboard, winlogbeat records the sysmon event and send it to elasticsearch and henceforth to kibana. there are 3 field name on time basis and i am not able to understand the difference between them namely …

---

## [Json\_parse\_exception Illegal character CTRL-CHAR](https://discuss.elastic.co/t/json-parse-exception-illegal-character-ctrl-char/156790)

<div class="topic-metadata">

**Author:** [@AlexJ](https://discuss.elastic.co/u/AlexJ)\
**Replies:** 6\
**Last updated:** [November 19, 2018, 12:13am UTC](https://discuss.elastic.co/t/json-parse-exception-illegal-character-ctrl-char/156790 "2018-11-19T00:13:11Z")

</div>

Hi, I was trying to set up shipping of a JSON log to Elasticsearch via Filebeat and received this strange error. Now it won't go away. The error is: { "level":"error", "timestamp":"2018-11-15T05:30:08.926Z", "caller":"e…

---

## [Using metricbeat hostpath for modules.d](https://discuss.elastic.co/t/using-metricbeat-hostpath-for-modules-d/157203)

<div class="topic-metadata">

**Author:** [@Pavan\_Kumar2](https://discuss.elastic.co/u/Pavan_Kumar2)\
**Replies:** 0\
**Last updated:** [November 18, 2018, 3:41am UTC](https://discuss.elastic.co/t/using-metricbeat-hostpath-for-modules-d/157203 "2018-11-18T03:41:11Z")

</div>

Hi, I new to elastic beats. I have a question regarding metricbeat.. Whenever I try to use hostpath for modules.d for metricbeat, the data in modules.d in pod gets removed and replaced by nothing (modules.d folder becom…

---

## [Monitor NTP in Linux](https://discuss.elastic.co/t/monitor-ntp-in-linux/157184)

<div class="topic-metadata">

**Author:** [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Replies:** 0\
**Last updated:** [November 17, 2018, 4:19pm UTC](https://discuss.elastic.co/t/monitor-ntp-in-linux/157184 "2018-11-17T16:19:02Z")

</div>

Hello ELK Experts, Is there way to monitor NTP clock using ELK? we have 400 nodes C\* cluster and looking for any plugins or tools to monitor NTP and report if any drift. Thanks Chandra

---

## [Filebeat sends logs into cluster](https://discuss.elastic.co/t/filebeat-sends-logs-into-cluster/156657)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 4\
**Last updated:** [November 17, 2018, 11:17am UTC](https://discuss.elastic.co/t/filebeat-sends-logs-into-cluster/156657 "2018-11-17T11:17:19Z")

</div>

hi all I installed filebeat on VM1 and installed two nodes of elasticsearch on VM2 and VM3 which these two nodes make a cluster. Now, i want to ship logs into cluster using filebeat. in the "output.elasticsearch" part o…

---

## [Filebeat with 2 kafka outputs](https://discuss.elastic.co/t/filebeat-with-2-kafka-outputs/157137)

<div class="topic-metadata">

**Author:** [@rodher](https://discuss.elastic.co/u/rodher)\
**Replies:** 1\
**Last updated:** [November 17, 2018, 8:28am UTC](https://discuss.elastic.co/t/filebeat-with-2-kafka-outputs/157137 "2018-11-17T08:28:25Z")

</div>

Hello ! I have an issue with Filebeat when I try to send data logs to 2 Kafka nodes at the same time The following is the Output Kafka section of the filebeat.yml file: output.kafka: enabled: true hosts: \[ "192.168.…

---

## [Trying to use pipelines with filebeat output.elasticsearch](https://discuss.elastic.co/t/trying-to-use-pipelines-with-filebeat-output-elasticsearch/156361)

<div class="topic-metadata">

**Author:** [@srkrishna](https://discuss.elastic.co/u/srkrishna)\
**Replies:** 2\
**Last updated:** [November 17, 2018, 3:53am UTC](https://discuss.elastic.co/t/trying-to-use-pipelines-with-filebeat-output-elasticsearch/156361 "2018-11-17T03:53:12Z")

</div>

Hello, I configured multiple .yml config file for different types of logs. Now i need to add conditions to send outputs 1. to elasticsearch and 2.logstash this is based on a condition with fields.logtype value. After…

---

## [Heartbeat Config advice](https://discuss.elastic.co/t/heartbeat-config-advice/155611)

<div class="topic-metadata">

**Author:** [@Francois\_013](https://discuss.elastic.co/u/Francois_013)\
**Replies:** 5\
**Last updated:** [November 17, 2018, 3:21am UTC](https://discuss.elastic.co/t/heartbeat-config-advice/155611 "2018-11-17T03:21:08Z")

</div>

Hi, I’m trying to configure a heartbeat http monitor to monitor a https URL protected by a client certificate. But it seems that I cannot get it working in a proper way. I’ve tried serval configs listed below: Config …

---

## [Filebeat 6.5.0 service error 216 0xd8 after failed enrollment](https://discuss.elastic.co/t/filebeat-6-5-0-service-error-216-0xd8-after-failed-enrollment/157134)

<div class="topic-metadata">

**Author:** [@analog\_memories](https://discuss.elastic.co/u/analog_memories)\
**Replies:** 0\
**Last updated:** [November 16, 2018, 8:46pm UTC](https://discuss.elastic.co/t/filebeat-6-5-0-service-error-216-0xd8-after-failed-enrollment/157134 "2018-11-16T20:46:59Z")

</div>

After installing and successfully getting Filebeat to run as a service on a Windows 10 1803 build, I tried to enroll this endpoint. To execute the enrollment, I had to stop the Filebeat service on the windows system. I …

---

## [Filebeat not creating index in Kibana](https://discuss.elastic.co/t/filebeat-not-creating-index-in-kibana/157128)

<div class="topic-metadata">

**Author:** [@elasticuser10](https://discuss.elastic.co/u/elasticuser10)\
**Replies:** 0\
**Last updated:** [November 16, 2018, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-not-creating-index-in-kibana/157128 "2018-11-16T19:47:42Z")

</div>

Hi! I'm using ELK6.3.2 Logstash, Elastic Search, Kibana and Filebeat. All the services are running with No Errors. I see that the Filebeat is able to recognize my configured path and the new log files but I don't see an…

---

## [Monitor the state - JSON data - body mismatch](https://discuss.elastic.co/t/monitor-the-state-json-data-body-mismatch/156916)

<div class="topic-metadata">

**Author:** [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Replies:** 2\
**Last updated:** [November 16, 2018, 6:22pm UTC](https://discuss.elastic.co/t/monitor-the-state-json-data-body-mismatch/156916 "2018-11-16T18:22:25Z")

</div>

heartbeat.yml heartbeat.monitors: type: http urls: \["https://x.x.x.x:xxx/x/x/x"\] ssl.verification\_mode: none check.request: method: GET headers: 'x-auth-token': 'xxxxx' check.response: status: 200 body: '{"st…

---

## [Filebeat combines mulitple lines into one](https://discuss.elastic.co/t/filebeat-combines-mulitple-lines-into-one/156725)

<div class="topic-metadata">

**Author:** [@zahodi](https://discuss.elastic.co/u/zahodi)\
**Replies:** 2\
**Last updated:** [November 16, 2018, 6:08pm UTC](https://discuss.elastic.co/t/filebeat-combines-mulitple-lines-into-one/156725 "2018-11-16T18:08:12Z")

</div>

For some reason filebeat combines multiple lines in my log into a single event. Also for some reason filebeat is not shipping the metadata for these messages and I'm not sure if it's related. sample source lines in a fi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=402)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=404)
