# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=404

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 405

---

## [Automating Filebeat configuration setup](https://discuss.elastic.co/t/automating-filebeat-configuration-setup/157110)

<div class="topic-metadata">

**Author:** [@Brett\_Larson](https://discuss.elastic.co/u/Brett_Larson)\
**Replies:** 0\
**Last updated:** [November 16, 2018, 5:07pm UTC](https://discuss.elastic.co/t/automating-filebeat-configuration-setup/157110 "2018-11-16T17:07:11Z")

</div>

Hello, Is there any built-in way to update the configuration of the filebeat service on Windows? I am looking to update the cloud.auth and cloud.id settings for a large amount of servers after downloading the filebeat t…

---

## [Filebeat multiline some pattern](https://discuss.elastic.co/t/filebeat-multiline-some-pattern/157063)

<div class="topic-metadata">

**Author:** [@garcia](https://discuss.elastic.co/u/garcia)\
**Replies:** 1\
**Last updated:** [November 16, 2018, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-multiline-some-pattern/157063 "2018-11-16T15:40:04Z")

</div>

There is a tomkat application in the docker and I want to set up logging in elk, but the problem is that the logs have a different format 2018-11-16 13:23:07 \[http-nio-127.0.0.1-8080-exec-21\] DEBUG c.j.m.s.filter.AgeCon…

---

## [Drop \_event when regexp dropping every event - apache2 module](https://discuss.elastic.co/t/drop-event-when-regexp-dropping-every-event-apache2-module/157084)

<div class="topic-metadata">

**Author:** [@Alaa\_Ksontini](https://discuss.elastic.co/u/Alaa_Ksontini)\
**Replies:** 0\
**Last updated:** [November 16, 2018, 2:43pm UTC](https://discuss.elastic.co/t/drop-event-when-regexp-dropping-every-event-apache2-module/157084 "2018-11-16T14:43:02Z")

</div>

Hi everyone, I wanted to limit the number of documents stored in Elasticsearch. So I configured a processor in my filebeat.yml at the top-level. My input is the apache2 module which is configured fine. processors: …

---

## [Filebeat and Docker EE](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698)

<div class="topic-metadata">

**Author:** [@Eric\_Duquesnoy](https://discuss.elastic.co/u/Eric_Duquesnoy)\
**Replies:** 6\
**Last updated:** [November 16, 2018, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698 "2018-11-16T14:21:45Z")

</div>

Hi There, We have just installed a Docker EE cluster on 10 nodes (3 UCP , 3 DTR and 6 workers) . Filebeat and Metricbeat are installed on each nodes with this configuration : filebeat.config.modules: path: ${path.co…

---

## [\[beatCM\] 6.5.0 Internal Certificate authority, or Mismatch host how to configure?](https://discuss.elastic.co/t/beatcm-6-5-0-internal-certificate-authority-or-mismatch-host-how-to-configure/156970)

<div class="topic-metadata">

**Author:** [@ToddFerg](https://discuss.elastic.co/u/ToddFerg)\
**Replies:** 1\
**Last updated:** [November 16, 2018, 1:38pm UTC](https://discuss.elastic.co/t/beatcm-6-5-0-internal-certificate-authority-or-mismatch-host-how-to-configure/156970 "2018-11-16T13:38:19Z")

</div>

When I am attempting to enroll a beat to centralized management I'm receiving this error: \[root@dactyl filebeat\]# filebeat -e -v enroll https://thehostname:5601 thetokengivenbykibana -E setup.kibana.ssl.verification\_mo…

---

## [Filebeat resend the harvested log many times](https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739)

<div class="topic-metadata">

**Author:** [@et159](https://discuss.elastic.co/u/et159)\
**Replies:** 3\
**Last updated:** [November 16, 2018, 1:27pm UTC](https://discuss.elastic.co/t/filebeat-resend-the-harvested-log-many-times/156739 "2018-11-16T13:27:15Z")

</div>

I have filebeat sending logs to logstash on AWS, but it's not getting any feedback from logstash, and it resend the files over and over, here is the error msg from Preformatted textilebeat logs , Filebeat version 6.3.2 …

---

## [Is Filebeat an java application , whether it uses java security providers for secure connection](https://discuss.elastic.co/t/is-filebeat-an-java-application-whether-it-uses-java-security-providers-for-secure-connection/156921)

<div class="topic-metadata">

**Author:** [@Madhan1911](https://discuss.elastic.co/u/Madhan1911)\
**Replies:** 4\
**Last updated:** [November 16, 2018, 1:26pm UTC](https://discuss.elastic.co/t/is-filebeat-an-java-application-whether-it-uses-java-security-providers-for-secure-connection/156921 "2018-11-16T13:26:29Z")

</div>

Hi , is filebeat an java application or C++ binary ?? because from the rpm extract i couldnt conclude much. If it is an java based application does it use java.security providers for establishing secure connections ?? …

---

## [Filebeat 6.5.0 - Error: unknown command "enroll" for "filebeat"](https://discuss.elastic.co/t/filebeat-6-5-0-error-unknown-command-enroll-for-filebeat/156729)

<div class="topic-metadata">

**Author:** [@AndrewMcQ](https://discuss.elastic.co/u/AndrewMcQ)\
**Replies:** 6\
**Last updated:** [November 16, 2018, 10:22am UTC](https://discuss.elastic.co/t/filebeat-6-5-0-error-unknown-command-enroll-for-filebeat/156729 "2018-11-16T10:22:32Z")

</div>

Testing new Beats central management and the 6.5.0 version of filebeat (downloaded today) states that "enroll" is an unknown command for filebeat. C:\\beats\\filebeat-6.5.0-windows-x86\_64\>filebeat.exe enroll Error: unkno…

---

## [Is it possible to run Auditbeat on Ubuntu on Power (ppc64le) hardware?](https://discuss.elastic.co/t/is-it-possible-to-run-auditbeat-on-ubuntu-on-power-ppc64le-hardware/156702)

<div class="topic-metadata">

**Author:** [@nlh](https://discuss.elastic.co/u/nlh)\
**Replies:** 7\
**Last updated:** [November 16, 2018, 8:48am UTC](https://discuss.elastic.co/t/is-it-possible-to-run-auditbeat-on-ubuntu-on-power-ppc64le-hardware/156702 "2018-11-16T08:48:20Z")

</div>

Question pretty much says it. Having to migrate to a beast of a machine with Ubuntu and a Power architecture. https://www.elastic.co/downloads/beats/auditbeat ,deb is the wrong architecture, but not sure what the Linux…

---

## [Problems to deploy Metricbeat in Kubernetes](https://discuss.elastic.co/t/problems-to-deploy-metricbeat-in-kubernetes/156247)

<div class="topic-metadata">

**Author:** [@Artur\_Becker](https://discuss.elastic.co/u/Artur_Becker)\
**Replies:** 8\
**Last updated:** [November 16, 2018, 7:42am UTC](https://discuss.elastic.co/t/problems-to-deploy-metricbeat-in-kubernetes/156247 "2018-11-16T07:42:35Z")

</div>

Hello, there, I have a problem deploying a Metricbeat in Kubernetes. I use the following documentation: https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-kubernetes.html But when I deploy a Metricbeat…

---

## [DHCP with Packetbeat?](https://discuss.elastic.co/t/dhcp-with-packetbeat/156497)

<div class="topic-metadata">

**Author:** [@ariesow](https://discuss.elastic.co/u/ariesow)\
**Replies:** 3\
**Last updated:** [November 16, 2018, 6:41am UTC](https://discuss.elastic.co/t/dhcp-with-packetbeat/156497 "2018-11-16T06:41:17Z")

</div>

Hi, May I know if we can use packet beat to monitor DHCP traffic ?

---

## [Metricbeat dashboards](https://discuss.elastic.co/t/metricbeat-dashboards/156933)

<div class="topic-metadata">

**Author:** [@ELE](https://discuss.elastic.co/u/ELE)\
**Replies:** 2\
**Last updated:** [November 16, 2018, 5:41am UTC](https://discuss.elastic.co/t/metricbeat-dashboards/156933 "2018-11-16T05:41:01Z")

</div>

Hi, I'm trying to loads the dashboards from the Metricbeat package to kibana From some reason I'm getting the following error Why it fail to contact Kibana ? \[root@skyeuropeelk metricbeat\]# metricbeat setup --dashboa…

---

## [SSH field not showing up with System module](https://discuss.elastic.co/t/ssh-field-not-showing-up-with-system-module/154599)

<div class="topic-metadata">

**Author:** [@dvelasco](https://discuss.elastic.co/u/dvelasco)\
**Replies:** 2\
**Last updated:** [November 16, 2018, 4:53am UTC](https://discuss.elastic.co/t/ssh-field-not-showing-up-with-system-module/154599 "2018-11-16T04:53:30Z")

</div>

Hello, I've setup an Elastic Stack and some Filebeat clients with System module enabled, but the SSH fields doesn't show up. Fileset.module and fileset.name are correct, and the messages I receive in Elastic have the f…

---

## [FileBeat Assumes UTC](https://discuss.elastic.co/t/filebeat-assumes-utc/156909)

<div class="topic-metadata">

**Author:** [@dison4linux](https://discuss.elastic.co/u/dison4linux)\
**Replies:** 1\
**Last updated:** [November 15, 2018, 10:24pm UTC](https://discuss.elastic.co/t/filebeat-assumes-utc/156909 "2018-11-15T22:24:50Z")

</div>

There is a closed thread here: Where @andrewkroh says, "I would recommend running all your systems with UTC time..." Does that mean all systems in the Elastic stack? Or all systems that we'd ever want to ingest logs …

---

## [Is Auditbeat a replacement for auditd in Linux?](https://discuss.elastic.co/t/is-auditbeat-a-replacement-for-auditd-in-linux/156926)

<div class="topic-metadata">

**Author:** [@Wanderer](https://discuss.elastic.co/u/Wanderer)\
**Replies:** 3\
**Last updated:** [November 15, 2018, 10:18pm UTC](https://discuss.elastic.co/t/is-auditbeat-a-replacement-for-auditd-in-linux/156926 "2018-11-15T22:18:07Z")

</div>

After reading this from the auditbeat docs it looks like it is saying it is a replacement for auditd in Linux. Is this the intended use case for auditbeat? When running Auditbeat with the auditd module enabled, you migh…

---

## [How to enable Beats central management](https://discuss.elastic.co/t/how-to-enable-beats-central-management/156897)

<div class="topic-metadata">

**Author:** [@jettro](https://discuss.elastic.co/u/jettro)\
**Replies:** 3\
**Last updated:** [November 15, 2018, 6:25pm UTC](https://discuss.elastic.co/t/how-to-enable-beats-central-management/156897 "2018-11-15T18:25:18Z")

</div>

I noticed the very cool feature of Beats central management. In the example there is a beats button on the management screen. I don't see it. I only see the elasticsearch and kibana part. Am I doing something wrong, or d…

---

## [Filebeat and file descriptor](https://discuss.elastic.co/t/filebeat-and-file-descriptor/156894)

<div class="topic-metadata">

**Author:** [@Eric\_Duquesnoy](https://discuss.elastic.co/u/Eric_Duquesnoy)\
**Replies:** 0\
**Last updated:** [November 15, 2018, 3:08pm UTC](https://discuss.elastic.co/t/filebeat-and-file-descriptor/156894 "2018-11-15T15:08:56Z")

</div>

We run Filebeat in version 6.4.2 with this configuration (installed like a linux agent) filebeat.autodiscover: providers: - type: docker templates: - condition: regexp: d…

---

## [How to avoid sending duplicated log data to Redis](https://discuss.elastic.co/t/how-to-avoid-sending-duplicated-log-data-to-redis/156831)

<div class="topic-metadata">

**Author:** [@Jin1129](https://discuss.elastic.co/u/Jin1129)\
**Replies:** 1\
**Last updated:** [November 15, 2018, 4:00pm UTC](https://discuss.elastic.co/t/how-to-avoid-sending-duplicated-log-data-to-redis/156831 "2018-11-15T16:00:58Z")

</div>

My filebeat version is 6.4.2 as I just mentioned, I want to avoid sending duplicated data to my Redis. Assume I have a json file and it contains single json data as follow { "create" : { "\_index" : "movies", "\_type" :…

---

## [Filebeat CPU usage](https://discuss.elastic.co/t/filebeat-cpu-usage/153038)

<div class="topic-metadata">

**Author:** [@matw](https://discuss.elastic.co/u/matw)\
**Replies:** 7\
**Last updated:** [November 15, 2018, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-cpu-usage/153038 "2018-11-15T15:58:02Z")

</div>

We're using filebeat to forward logs to a redis server, then they're processed with logstash and indexed by elasticsearch One of our customers complains, that filebeat needs more resources than the process that writes t…

---

## [Filebeat Publish Issue](https://discuss.elastic.co/t/filebeat-publish-issue/156623)

<div class="topic-metadata">

**Author:** [@lazam](https://discuss.elastic.co/u/lazam)\
**Replies:** 3\
**Last updated:** [November 15, 2018, 3:36pm UTC](https://discuss.elastic.co/t/filebeat-publish-issue/156623 "2018-11-15T15:36:49Z")

</div>

Hello! We're using Filebeat (5.6) storing to Elasticsearch (5.6). We suddenly noticed that we're not receiving data from FIlebeat after couple of hours. The filebeat config looks like this: filebeat.prospectors: - inp…

---

## [How to "drill down" through Filebeat monitoring to identify emergent errors or trends?](https://discuss.elastic.co/t/how-to-drill-down-through-filebeat-monitoring-to-identify-emergent-errors-or-trends/156551)

<div class="topic-metadata">

**Author:** [@tomj](https://discuss.elastic.co/u/tomj)\
**Replies:** 2\
**Last updated:** [November 15, 2018, 3:21pm UTC](https://discuss.elastic.co/t/how-to-drill-down-through-filebeat-monitoring-to-identify-emergent-errors-or-trends/156551 "2018-11-15T15:21:08Z")

</div>

We are currently doing a trial of Elastic Cloud and we're using Filebeat to gather logs from a few hosts. At the moment we're taking some simple performance measurements and (generally) things look positive. In our pro…

---

## [How to use pipelines/processors with autodiscover](https://discuss.elastic.co/t/how-to-use-pipelines-processors-with-autodiscover/156659)

<div class="topic-metadata">

**Author:** [@Denis\_Baryshev](https://discuss.elastic.co/u/Denis_Baryshev)\
**Replies:** 1\
**Last updated:** [November 15, 2018, 3:16pm UTC](https://discuss.elastic.co/t/how-to-use-pipelines-processors-with-autodiscover/156659 "2018-11-15T15:16:41Z")

</div>

Hello I have the following config file, and I'm already pretty lost and I don't know where to direct log-format json logs to my custom "json-message" pipeline or where to use "decode\_json\_fields". Please help filebeat…

---

## [X509: certificate signed by unknown authority](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/156815)

<div class="topic-metadata">

**Author:** [@Nithani25](https://discuss.elastic.co/u/Nithani25)\
**Replies:** 1\
**Last updated:** [November 15, 2018, 2:30pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/156815 "2018-11-15T14:30:48Z")

</div>

Hi Team, I have installed heartbeat in one of my server and try parsing them to elastic search for some specific urls' all i could see "x509: certificate signed by unknown authority" messages in the kibana. My heartbeat…

---

## [How to query json url with http module](https://discuss.elastic.co/t/how-to-query-json-url-with-http-module/155572)

<div class="topic-metadata">

**Author:** [@Aert](https://discuss.elastic.co/u/Aert)\
**Replies:** 2\
**Last updated:** [November 15, 2018, 10:06am UTC](https://discuss.elastic.co/t/how-to-query-json-url-with-http-module/155572 "2018-11-15T10:06:19Z")

</div>

Hello Team, I have enabled http module in metricbeat and am currently trying to get the HTTP body of a JSON endpoint. For now it doesn't work, the error.message i get is: json: cannot unmarshal array into Go value of …

---

## [Filebeats cuts off first part of log event](https://discuss.elastic.co/t/filebeats-cuts-off-first-part-of-log-event/155057)

<div class="topic-metadata">

**Author:** [@hyattcs](https://discuss.elastic.co/u/hyattcs)\
**Replies:** 4\
**Last updated:** [November 14, 2018, 8:34pm UTC](https://discuss.elastic.co/t/filebeats-cuts-off-first-part-of-log-event/155057 "2018-11-14T20:34:57Z")

</div>

I'm using beats, logstash, elasticsearch to read log info in json, add some fields and index it. Beats is set up to treat a single line in the logs as an event, and each json object should be on a single line. I notice…

---

## [Packetbeat causing 100% CPU usage](https://discuss.elastic.co/t/packetbeat-causing-100-cpu-usage/151628)

<div class="topic-metadata">

**Author:** [@radu.capverde](https://discuss.elastic.co/u/radu.capverde)\
**Replies:** 3\
**Last updated:** [November 14, 2018, 3:53pm UTC](https://discuss.elastic.co/t/packetbeat-causing-100-cpu-usage/151628 "2018-11-14T15:53:16Z")

</div>

Hello, We have multiple VMs that are running packetbeat and on some of them (8 VMs) the CPU usage is constantly at 100% due to packetbeat. We have had one instance where one VM became completely unresponsive due to this…

---

## [Can we add fields value based on regex patterns in include\_lines for the same log](https://discuss.elastic.co/t/can-we-add-fields-value-based-on-regex-patterns-in-include-lines-for-the-same-log/156604)

<div class="topic-metadata">

**Author:** [@krishanagrawal](https://discuss.elastic.co/u/krishanagrawal)\
**Replies:** 1\
**Last updated:** [November 14, 2018, 3:41pm UTC](https://discuss.elastic.co/t/can-we-add-fields-value-based-on-regex-patterns-in-include-lines-for-the-same-log/156604 "2018-11-14T15:41:06Z")

</div>

I am parsing a log file which has error from 3 different process. I have added the input file in path and have added the 3 regex pattern in include line unique to 3 processes. Can I add field column which will be popul…

---

## [Cmd to locate filebeat config](https://discuss.elastic.co/t/cmd-to-locate-filebeat-config/156565)

<div class="topic-metadata">

**Author:** [@aravinm](https://discuss.elastic.co/u/aravinm)\
**Replies:** 1\
**Last updated:** [November 14, 2018, 3:35pm UTC](https://discuss.elastic.co/t/cmd-to-locate-filebeat-config/156565 "2018-11-14T15:35:44Z")

</div>

Hi, may i please know the command to locate the filebeat config file using command prompt using ubuntu? Thank you for your time.

---

## [Filebeat and kubernetes with custom index](https://discuss.elastic.co/t/filebeat-and-kubernetes-with-custom-index/156336)

<div class="topic-metadata">

**Author:** [@CSaavedra](https://discuss.elastic.co/u/CSaavedra)\
**Replies:** 3\
**Last updated:** [November 14, 2018, 3:08pm UTC](https://discuss.elastic.co/t/filebeat-and-kubernetes-with-custom-index/156336 "2018-11-14T15:08:32Z")

</div>

Hi guys, Im try to create a custom indexes for my different apps in a kubernetes cluster, but this not working :frowning: anyone know any way to create this ? Here is a part of my code output.elasticsearch: hosts: …

---

## [Metricbeat: http server metricset doesn't use namespace config option](https://discuss.elastic.co/t/metricbeat-http-server-metricset-doesnt-use-namespace-config-option/156669)

<div class="topic-metadata">

**Author:** [@Jun\_Zhang](https://discuss.elastic.co/u/Jun_Zhang)\
**Replies:** 1\
**Last updated:** [November 14, 2018, 1:51pm UTC](https://discuss.elastic.co/t/metricbeat-http-server-metricset-doesnt-use-namespace-config-option/156669 "2018-11-14T13:51:35Z")

</div>

Metricbeat: 6.4.3 http module configuration: - module: http metricsets: - server host: "localhost" port: "800" paths: - path: "/foo" namespace: "foo" $ curl -H "Content-Type: application/json" http:/…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=403)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=405)
