# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=405

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 406

---

## [Metricbeat etcd module can't work with etcd v3.3.8](https://discuss.elastic.co/t/metricbeat-etcd-module-cant-work-with-etcd-v3-3-8/155739)

<div class="topic-metadata">

**Author:** [@Jun\_Zhang](https://discuss.elastic.co/u/Jun_Zhang)\
**Replies:** 3\
**Last updated:** [November 14, 2018, 12:22pm UTC](https://discuss.elastic.co/t/metricbeat-etcd-module-cant-work-with-etcd-v3-3-8/155739 "2018-11-14T12:22:01Z")

</div>

my config: metricbeat.modules: - module: etcd metricsets: \["leader", "self", "store"\] period: 10s hosts: \["https://172.27.128.71:2379"\] ssl: certificate: "/etc/cert/client.pem" key: "/etc/cert/client-key…

---

## [Filebeat HTTP(S) output with load balancing support](https://discuss.elastic.co/t/filebeat-http-s-output-with-load-balancing-support/156633)

<div class="topic-metadata">

**Author:** [@sarsivas](https://discuss.elastic.co/u/sarsivas)\
**Replies:** 0\
**Last updated:** [November 14, 2018, 10:47am UTC](https://discuss.elastic.co/t/filebeat-http-s-output-with-load-balancing-support/156633 "2018-11-14T10:47:55Z")

</div>

Logstash Looks logstash supports HTTP output, but it don't have load balancing using round robin algorithm for for multiple output host. Filebeat Looks Filebeat support load balancing but not support HTTP output. Eg:…

---

## [How can I monitor a specific process via metricbeat on Kibana dashboard?](https://discuss.elastic.co/t/how-can-i-monitor-a-specific-process-via-metricbeat-on-kibana-dashboard/152824)

<div class="topic-metadata">

**Author:** [@Swati\_Singh](https://discuss.elastic.co/u/Swati_Singh)\
**Replies:** 3\
**Last updated:** [November 14, 2018, 8:19am UTC](https://discuss.elastic.co/t/how-can-i-monitor-a-specific-process-via-metricbeat-on-kibana-dashboard/152824 "2018-11-14T08:19:39Z")

</div>

Hi, I am a beginner in usage of Elastic Stack. I plan to use it for monitoring various machines in a network. I have a system A where elasticsearch and kibana is installed with System B & C where metricbeat is install…

---

## [What is the pre-requisite for beats to run on windows machine](https://discuss.elastic.co/t/what-is-the-pre-requisite-for-beats-to-run-on-windows-machine/154829)

<div class="topic-metadata">

**Author:** [@somu\_p](https://discuss.elastic.co/u/somu_p)\
**Replies:** 3\
**Last updated:** [November 13, 2018, 4:28pm UTC](https://discuss.elastic.co/t/what-is-the-pre-requisite-for-beats-to-run-on-windows-machine/154829 "2018-11-13T16:28:23Z")

</div>

i have two question regarding metric beats: i cant find the pre-requite document for metrixbeats on your website. please share the same for metric beats, Logstack and Elastic search. beats give new record for every sec…

---

## [Filebeat source log file line length sanity check needed](https://discuss.elastic.co/t/filebeat-source-log-file-line-length-sanity-check-needed/152486)

<div class="topic-metadata">

**Author:** [@meritus](https://discuss.elastic.co/u/meritus)\
**Replies:** 4\
**Last updated:** [November 13, 2018, 3:26pm UTC](https://discuss.elastic.co/t/filebeat-source-log-file-line-length-sanity-check-needed/152486 "2018-11-13T15:26:50Z")

</div>

Hi there. This weekend i had a situation where my logfile got somehow corrupted having binary data at the beginning (0x00), and there normal txt data appended to it. And filebeat was scanning this file to put it into ES…

---

## [Conditional filebeat output to logstash](https://discuss.elastic.co/t/conditional-filebeat-output-to-logstash/156303)

<div class="topic-metadata">

**Author:** [@rrs](https://discuss.elastic.co/u/rrs)\
**Replies:** 2\
**Last updated:** [November 13, 2018, 2:26pm UTC](https://discuss.elastic.co/t/conditional-filebeat-output-to-logstash/156303 "2018-11-13T14:26:32Z")

</div>

Hi All, We have done setup of ELK with 5.6.3 and filebeat-5.6.3 also installed on hosts to push logs. It is running fine. We need segregation for prod/dev indexes for which we have done another setup for my 'dev' envir…

---

## [Filebeat in Kubernetes - How to push logs for a specific k8s namespace](https://discuss.elastic.co/t/filebeat-in-kubernetes-how-to-push-logs-for-a-specific-k8s-namespace/154868)

<div class="topic-metadata">

**Author:** [@anuranjit](https://discuss.elastic.co/u/anuranjit)\
**Replies:** 2\
**Last updated:** [November 13, 2018, 1:15pm UTC](https://discuss.elastic.co/t/filebeat-in-kubernetes-how-to-push-logs-for-a-specific-k8s-namespace/154868 "2018-11-13T13:15:51Z")

</div>

We are using filebeat configuration as in https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-docker.html . We are able to successfully push the logs from kubernetes to Elasticsearch for containers.ids…

---

## [Filebeat does not send the message due to inode reused](https://discuss.elastic.co/t/filebeat-does-not-send-the-message-due-to-inode-reused/156217)

<div class="topic-metadata">

**Author:** [@guanghaofan](https://discuss.elastic.co/u/guanghaofan)\
**Replies:** 14\
**Last updated:** [November 13, 2018, 11:56am UTC](https://discuss.elastic.co/t/filebeat-does-not-send-the-message-due-to-inode-reused/156217 "2018-11-13T11:56:52Z")

</div>

hi expert, I use the filebeat to import the data files to e.s, and there's a script keeping running in the background to scan the filog lebeat log, the data file(XXX) will be removed once it found a harvester eof event …

---

## [Metricbeat kubernetes module state\_node metricset failed to parse node labels](https://discuss.elastic.co/t/metricbeat-kubernetes-module-state-node-metricset-failed-to-parse-node-labels/156269)

<div class="topic-metadata">

**Author:** [@Jun\_Zhang](https://discuss.elastic.co/u/Jun_Zhang)\
**Replies:** 2\
**Last updated:** [November 13, 2018, 11:32am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-module-state-node-metricset-failed-to-parse-node-labels/156269 "2018-11-13T11:32:17Z")

</div>

metricbeat log： 2018-11-12T17:54:45.479+0800 WARN elasticsearch/client.go:520 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xbef27156c82fe362, ext:1463147003462, loc:(\*time.Location)(0x…

---

## [Metricbeat： fatal error: concurrent map read and map write](https://discuss.elastic.co/t/metricbeat-fatal-error-concurrent-map-read-and-map-write/156399)

<div class="topic-metadata">

**Author:** [@Jun\_Zhang](https://discuss.elastic.co/u/Jun_Zhang)\
**Replies:** 2\
**Last updated:** [November 13, 2018, 11:27am UTC](https://discuss.elastic.co/t/metricbeat-fatal-error-concurrent-map-read-and-map-write/156399 "2018-11-13T11:27:07Z")

</div>

metricbeat: 6.4.3 OS: CentOS 7.5 Docker: 18.06-1 metricbeat logs: 2018-11-13T12:22:10.262+0800 ERROR kubernetes/watcher.go:254 kubernetes: Watching API error EOF 2018-11-13T12:22:10.262+0800 INFO k…

---

## [Filebeat is not sending the log data to Elasticsearch](https://discuss.elastic.co/t/filebeat-is-not-sending-the-log-data-to-elasticsearch/156355)

<div class="topic-metadata">

**Author:** [@Francisco\_Yanez](https://discuss.elastic.co/u/Francisco_Yanez)\
**Replies:** 0\
**Last updated:** [November 12, 2018, 9:59pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-the-log-data-to-elasticsearch/156355 "2018-11-12T21:59:18Z")

</div>

Francisco\_YanezFrancisco Yañez 22m Hello I have just installed Elastic stack on my server and all is working fine but on the client I am trying to ship logs and it is just not working I have read quite a few posts and …

---

## [Failed to connect to backoff - Filebeat and ELK in different environemnts with NAT](https://discuss.elastic.co/t/failed-to-connect-to-backoff-filebeat-and-elk-in-different-environemnts-with-nat/155538)

<div class="topic-metadata">

**Author:** [@Dan007](https://discuss.elastic.co/u/Dan007)\
**Replies:** 5\
**Last updated:** [November 12, 2018, 9:12pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-filebeat-and-elk-in-different-environemnts-with-nat/155538 "2018-11-12T21:12:57Z")

</div>

Hi, I have two different environments: in "environment-a" there is ELK stack running using docker containers, and in "environment-b" there is a dockerised application that should sent logs using filebeat. The environme…

---

## [Filebeat on Windows - do not start](https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037)

<div class="topic-metadata">

**Author:** [@picoroma](https://discuss.elastic.co/u/picoroma)\
**Replies:** 3\
**Last updated:** [November 12, 2018, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037 "2018-11-12T21:06:38Z")

</div>

I'm trying to configure filebeats on a windows server where is running Tomcat 8.5. The goal is to send Tomcat log files to Elasticsearch or to Logstash. I Have, for this installed and configured an ELK stack. So, ES, …

---

## [Log JSON decoding errors of TCP input](https://discuss.elastic.co/t/log-json-decoding-errors-of-tcp-input/156156)

<div class="topic-metadata">

**Author:** [@njam](https://discuss.elastic.co/u/njam)\
**Replies:** 1\
**Last updated:** [November 12, 2018, 8:55pm UTC](https://discuss.elastic.co/t/log-json-decoding-errors-of-tcp-input/156156 "2018-11-12T20:55:25Z")

</div>

I'm setting up a Filebeat TCP input, that parses each line as JSON and sends the resulting fields to Elasticsearch. filebeat.inputs: - type: tcp host: "0.0.0.0:5000" processors: - decode\_json\_fields: fields: \["me…

---

## [No logs on Kibana discover under filebeat-\* index](https://discuss.elastic.co/t/no-logs-on-kibana-discover-under-filebeat-index/156136)

<div class="topic-metadata">

**Author:** [@Shahid\_Chaudhary](https://discuss.elastic.co/u/Shahid_Chaudhary)\
**Replies:** 1\
**Last updated:** [November 12, 2018, 8:51pm UTC](https://discuss.elastic.co/t/no-logs-on-kibana-discover-under-filebeat-index/156136 "2018-11-12T20:51:33Z")

</div>

I installed new ELK server single node . on the first login i am getting the error of indice idex . here is my filebeat logs form y ELK server. sudo service filebeat restart root@ip-172-31-10-222:# sudo tail -f /var…

---

## [Tags in modules](https://discuss.elastic.co/t/tags-in-modules/156066)

<div class="topic-metadata">

**Author:** [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Replies:** 1\
**Last updated:** [November 12, 2018, 8:45pm UTC](https://discuss.elastic.co/t/tags-in-modules/156066 "2018-11-12T20:45:01Z")

</div>

Can we use tags in modules, I was trying to tag the logs in elasticsearch module but the tag is not assigned to the particular path module: elasticsearch server: enabled: true var.paths: \["/var/log/elasticsearch/se…

---

## [Solved: How to get JSON example from blog to work with new index (hint: format YML correctly!)](https://discuss.elastic.co/t/solved-how-to-get-json-example-from-blog-to-work-with-new-index-hint-format-yml-correctly/156103)

<div class="topic-metadata">

**Author:** [@devops\_mike](https://discuss.elastic.co/u/devops_mike)\
**Replies:** 3\
**Last updated:** [November 12, 2018, 3:56pm UTC](https://discuss.elastic.co/t/solved-how-to-get-json-example-from-blog-to-work-with-new-index-hint-format-yml-correctly/156103 "2018-11-12T15:56:26Z")

</div>

I am following along with this guide: https://www.elastic.co/blog/structured-logging-filebeat It very closely matches my data. The difference is I need this to go into its own index. My data is JSON formatted and only i…

---

## [Error after 5.x to 6.4.3 upgrade](https://discuss.elastic.co/t/error-after-5-x-to-6-4-3-upgrade/156160)

<div class="topic-metadata">

**Author:** [@mpaulsen](https://discuss.elastic.co/u/mpaulsen)\
**Replies:** 1\
**Last updated:** [November 12, 2018, 12:53pm UTC](https://discuss.elastic.co/t/error-after-5-x-to-6-4-3-upgrade/156160 "2018-11-12T12:53:46Z")

</div>

I am upgrading Elasticsearch and all components, but running into issues with Metricbeat. Error: 2018-11-10T21:32:13.652+0100 WARN elasticsearch/client.go:520 Cannot index event publisher.Event{Content:beat.Event{Times…

---

## [Using Filebeat with the rollover pattern](https://discuss.elastic.co/t/using-filebeat-with-the-rollover-pattern/154402)

<div class="topic-metadata">

**Author:** [@sterago](https://discuss.elastic.co/u/sterago)\
**Replies:** 9\
**Last updated:** [November 12, 2018, 12:44pm UTC](https://discuss.elastic.co/t/using-filebeat-with-the-rollover-pattern/154402 "2018-11-12T12:44:46Z")

</div>

Hi, my team and I are looking for a solution to keep the size of indices below a certain threshold and we are looking at the Rollover API with interest. We are already using Curator for data retention purposes and thoug…

---

## [Custom beat module ready, how to install?](https://discuss.elastic.co/t/custom-beat-module-ready-how-to-install/155601)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 1\
**Last updated:** [November 12, 2018, 12:40pm UTC](https://discuss.elastic.co/t/custom-beat-module-ready-how-to-install/155601 "2018-11-12T12:40:33Z")

</div>

I got myself through some hiccups, but I finally got the 'make package' working. Now a few questions I can build with or without snapshot. Not sure what the difference is I can install my custom package sudo dpkg -i…

---

## [How we can drop log line using filebeat](https://discuss.elastic.co/t/how-we-can-drop-log-line-using-filebeat/155147)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 4\
**Last updated:** [November 12, 2018, 5:01am UTC](https://discuss.elastic.co/t/how-we-can-drop-log-line-using-filebeat/155147 "2018-11-12T05:01:26Z")

</div>

Hello Team, I am aware how we can exclude a particular log type (line) using filebeat and i have implemented it and its working fine. But now i am getting 20 line of same log type and i want to exclude 19 of them at fi…

---

## [Packetbeat Exiting: Sniffer main loop failed: Unsupported link type: UnknownLinkType(12)](https://discuss.elastic.co/t/packetbeat-exiting-sniffer-main-loop-failed-unsupported-link-type-unknownlinktype-12/155370)

<div class="topic-metadata">

**Author:** [@beat2beat](https://discuss.elastic.co/u/beat2beat)\
**Replies:** 2\
**Last updated:** [November 8, 2018, 11:43am UTC](https://discuss.elastic.co/t/packetbeat-exiting-sniffer-main-loop-failed-unsupported-link-type-unknownlinktype-12/155370 "2018-11-08T11:43:50Z")

</div>

Hello, I came into this exception when trying to read a valid pcap file. I can read the file with tcpdump -r . I verified that this is a valid pcap file (d4 c3 b2 a1 header), but still getting this exception. I noticed…

---

## [Autodiscover and processors](https://discuss.elastic.co/t/autodiscover-and-processors/156101)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 2\
**Last updated:** [November 9, 2018, 11:50pm UTC](https://discuss.elastic.co/t/autodiscover-and-processors/156101 "2018-11-09T23:50:34Z")

</div>

Hi, If I have the following config metricbeat.autodiscover: providers: - type: kubernetes host: ${NODE\_NAME} hints.enabled: true Is it redundant to also specify: processors:…

---

## [Aggregate data after month to get smaller index](https://discuss.elastic.co/t/aggregate-data-after-month-to-get-smaller-index/155941)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 2\
**Last updated:** [November 9, 2018, 2:52pm UTC](https://discuss.elastic.co/t/aggregate-data-after-month-to-get-smaller-index/155941 "2018-11-09T14:52:15Z")

</div>

hi all, I would like to have a method to aggregate informations collected using Metricbeat. Currently I have the system module enabled that collects details every 30 seconds. this situation is really good if I want to …

---

## [Beats - x509: certificate signed by unknown authority](https://discuss.elastic.co/t/beats-x509-certificate-signed-by-unknown-authority/153988)

<div class="topic-metadata">

**Author:** [@Oliver\_Hough](https://discuss.elastic.co/u/Oliver_Hough)\
**Replies:** 2\
**Last updated:** [November 9, 2018, 11:11am UTC](https://discuss.elastic.co/t/beats-x509-certificate-signed-by-unknown-authority/153988 "2018-11-09T11:11:32Z")

</div>

I am getting x509: certificate signed by unknown authority in Metricbeat logs while trying to ship to Logstash. On the same host though, Filebeat is able to ship logs successfully to the same Logstash server using the sa…

---

## [Filebeat stopped sending logs in realtime](https://discuss.elastic.co/t/filebeat-stopped-sending-logs-in-realtime/154125)

<div class="topic-metadata">

**Author:** [@Napsty](https://discuss.elastic.co/u/Napsty)\
**Replies:** 7\
**Last updated:** [November 9, 2018, 10:30am UTC](https://discuss.elastic.co/t/filebeat-stopped-sending-logs-in-realtime/154125 "2018-11-09T10:30:48Z")

</div>

I briefly mentioned this problem to Carlos Pérez at the OSSummit this week and he suggested to post my problem here. Since a couple of weeks we have a problem on a particular host (a VM) that Only parts of the logs ar…

---

## [How use Stop method?](https://discuss.elastic.co/t/how-use-stop-method/155833)

<div class="topic-metadata">

**Author:** [@zhaoya881010](https://discuss.elastic.co/u/zhaoya881010)\
**Replies:** 4\
**Last updated:** [November 9, 2018, 8:27am UTC](https://discuss.elastic.co/t/how-use-stop-method/155833 "2018-11-09T08:27:14Z")

</div>

i found start filebeat "cmd.RootCmd.Execute()" method,but i don't know stop method. no Stop api in the simple cmd interface,i don't hope stoped by "ctrl+c/d". the filebeat as module to my app. i hope i call “cmd.RootCmd…

---

## [Ansible script module could not daemonize filebeat](https://discuss.elastic.co/t/ansible-script-module-could-not-daemonize-filebeat/156003)

<div class="topic-metadata">

**Author:** [@Ali\_Sahin](https://discuss.elastic.co/u/Ali_Sahin)\
**Replies:** 0\
**Last updated:** [November 9, 2018, 8:22am UTC](https://discuss.elastic.co/t/ansible-script-module-could-not-daemonize-filebeat/156003 "2018-11-09T08:22:01Z")

</div>

Sudo service filebeat start does not work when running script remote with ansible. Ansible --version: ansible 2.4.1.0 config file = /etc/ansible/ansible.cfg configured module search path = \[u'/home/ec2-user/.ansible/…

---

## [Filebeat ignores stdout logs with autodiscover of docker containers](https://discuss.elastic.co/t/filebeat-ignores-stdout-logs-with-autodiscover-of-docker-containers/155544)

<div class="topic-metadata">

**Author:** [@givorenon](https://discuss.elastic.co/u/givorenon)\
**Replies:** 1\
**Last updated:** [November 9, 2018, 7:13am UTC](https://discuss.elastic.co/t/filebeat-ignores-stdout-logs-with-autodiscover-of-docker-containers/155544 "2018-11-09T07:13:30Z")

</div>

Here is my filebeat.yml filebeat.autodiscover: providers: - type: docker #hints.enabled: true templates: - condition: contains: docker.container.name: agent …

---

## [Can not setup beat templates on elasticsearch nodes](https://discuss.elastic.co/t/can-not-setup-beat-templates-on-elasticsearch-nodes/155943)

<div class="topic-metadata">

**Author:** [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Replies:** 1\
**Last updated:** [November 9, 2018, 4:30am UTC](https://discuss.elastic.co/t/can-not-setup-beat-templates-on-elasticsearch-nodes/155943 "2018-11-09T04:30:51Z")

</div>

Hello there, I need to setup the index templates on metribeats (actually all beats, metricbeat is the first one). I got the following: \[root@beatshost user1\]# /usr/share/metricbeat/bin/metricbeat setup --template --…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=404)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=406)
