# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=406

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 407

---

## [Droping events based on ip adr from sysmon](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734)

<div class="topic-metadata">

**Author:** [@ssi](https://discuss.elastic.co/u/ssi)\
**Replies:** 7\
**Last updated:** [November 9, 2018, 12:32am UTC](https://discuss.elastic.co/t/droping-events-based-on-ip-adr-from-sysmon/155734 "2018-11-09T00:32:05Z")

</div>

hi i believe this is close to what im seeing, at least im trying the same thing and not getting any success. the sysmon is being send from a windows event collector with a winlogbeat agent on to logstash here is the …

---

## [Deleted Winlogbeat, Index patterns not showing in dashboard](https://discuss.elastic.co/t/deleted-winlogbeat-index-patterns-not-showing-in-dashboard/155410)

<div class="topic-metadata">

**Author:** [@Ralph\_Lawrence](https://discuss.elastic.co/u/Ralph_Lawrence)\
**Replies:** 1\
**Last updated:** [November 8, 2018, 3:37pm UTC](https://discuss.elastic.co/t/deleted-winlogbeat-index-patterns-not-showing-in-dashboard/155410 "2018-11-08T15:37:42Z")

</div>

I deleted Winlogbeat index and re added a new one. When i went to the Dashboard, the dedicated dash board that i had was unable to update to the new winlogbeat. Now I have to delete and start over because i get this noti…

---

## [Use ${hostname} in var.paths](https://discuss.elastic.co/t/use-hostname-in-var-paths/155451)

<div class="topic-metadata">

**Author:** [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Replies:** 5\
**Last updated:** [November 8, 2018, 3:25pm UTC](https://discuss.elastic.co/t/use-hostname-in-var-paths/155451 "2018-11-08T15:25:55Z")

</div>

Having 3 nodes in a cluster, enabled elasticsearch module and setting the var.paths to elasticsearch logs path. In these 3 nodes logs are at /var/log/elasticsearch/{hostname}/\*.log. Trying to replace the var.paths in all…

---

## [Filbeat export template](https://discuss.elastic.co/t/filbeat-export-template/155581)

<div class="topic-metadata">

**Author:** [@shauryagarg2006](https://discuss.elastic.co/u/shauryagarg2006)\
**Replies:** 3\
**Last updated:** [November 8, 2018, 2:49pm UTC](https://discuss.elastic.co/t/filbeat-export-template/155581 "2018-11-08T14:49:39Z")

</div>

I am using the version 6.4.2 of filebeat and elasticsearch. I am trying to upload the template into elasticsearch using the setup command. It works fine but when I saw the generated template (also through the filebeat ex…

---

## [Connectex: No connection could be made because the target machine actively refused it](https://discuss.elastic.co/t/connectex-no-connection-could-be-made-because-the-target-machine-actively-refused-it/155380)

<div class="topic-metadata">

**Author:** [@laureate\_dube](https://discuss.elastic.co/u/laureate_dube)\
**Replies:** 5\
**Last updated:** [November 8, 2018, 2:46pm UTC](https://discuss.elastic.co/t/connectex-no-connection-could-be-made-because-the-target-machine-actively-refused-it/155380 "2018-11-08T14:46:31Z")

</div>

I am failing to ship windows logs to an elastic search server using winlogbeat. The winlogbeat log error reads: "No connection could be made because the target machine actively refused it." Firewall on both server and cl…

---

## [Get logs from docker containers in filebeat](https://discuss.elastic.co/t/get-logs-from-docker-containers-in-filebeat/155180)

<div class="topic-metadata">

**Author:** [@bertolis](https://discuss.elastic.co/u/bertolis)\
**Replies:** 2\
**Last updated:** [November 8, 2018, 11:37am UTC](https://discuss.elastic.co/t/get-logs-from-docker-containers-in-filebeat/155180 "2018-11-08T11:37:03Z")

</div>

Hi, lets say i have an elastic stack running in docker. In another pc i have an Alfresco running in docker as well. In the same pc i also have filebeat that is running in docker too. The Alfresco image has tomcat and pos…

---

## [Filebeat is blocked since the bulk send failure](https://discuss.elastic.co/t/filebeat-is-blocked-since-the-bulk-send-failure/155331)

<div class="topic-metadata">

**Author:** [@guanghaofan](https://discuss.elastic.co/u/guanghaofan)\
**Replies:** 19\
**Last updated:** [November 8, 2018, 5:30am UTC](https://discuss.elastic.co/t/filebeat-is-blocked-since-the-bulk-send-failure/155331 "2018-11-08T05:30:32Z")

</div>

hi experts, My filebeat case is the filebeat is always blocked since there are some bulk send failures due to the unexpected bad format of log event in each file, then it seems filebeat is busy in trying re-send the fai…

---

## [Filebeat does not read the large log file](https://discuss.elastic.co/t/filebeat-does-not-read-the-large-log-file/155660)

<div class="topic-metadata">

**Author:** [@guanghaofan](https://discuss.elastic.co/u/guanghaofan)\
**Replies:** 2\
**Last updated:** [November 8, 2018, 4:53am UTC](https://discuss.elastic.co/t/filebeat-does-not-read-the-large-log-file/155660 "2018-11-08T04:53:04Z")

</div>

ELK: 6.4.2 one of a large file size is :2523,075,914 more than 2G. all the other files are consumed by filebeat, but left this one, and has no any record in the registry file to this log file. thanks!

---

## [Web site monitoring with Status up/down with downtime](https://discuss.elastic.co/t/web-site-monitoring-with-status-up-down-with-downtime/155657)

<div class="topic-metadata">

**Author:** [@shahid](https://discuss.elastic.co/u/shahid)\
**Replies:** 2\
**Last updated:** [November 7, 2018, 5:52pm UTC](https://discuss.elastic.co/t/web-site-monitoring-with-status-up-down-with-downtime/155657 "2018-11-07T17:52:21Z")

</div>

Hi Tech Team, We have some client websites we are commented to provide them the max up-time . For that i need to show them the real-time graphic from my Kibana dashboard. right now i using heartbeat to ping my client s…

---

## [Numeric value (18446744073709551615) out of range of long (-9223372036854775808 - 9223372036854775807)](https://discuss.elastic.co/t/numeric-value-18446744073709551615-out-of-range-of-long-9223372036854775808-9223372036854775807/155732)

<div class="topic-metadata">

**Author:** [@Jun\_Zhang](https://discuss.elastic.co/u/Jun_Zhang)\
**Replies:** 1\
**Last updated:** [November 7, 2018, 3:30pm UTC](https://discuss.elastic.co/t/numeric-value-18446744073709551615-out-of-range-of-long-9223372036854775808-9223372036854775807/155732 "2018-11-07T15:30:45Z")

</div>

filebeat 6.4.3: 2018-11-07T21:46:19.653+0800 WARN elasticsearch/client.go:520 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xbef0d90aa48b4054, ext:10511332183032, loc:(\*time.L…

---

## [Error Loading the metric-\* index on dashboard](https://discuss.elastic.co/t/error-loading-the-metric-index-on-dashboard/155721)

<div class="topic-metadata">

**Author:** [@shahid](https://discuss.elastic.co/u/shahid)\
**Replies:** 3\
**Last updated:** [November 7, 2018, 3:27pm UTC](https://discuss.elastic.co/t/error-loading-the-metric-index-on-dashboard/155721 "2018-11-07T15:27:24Z")

</div>

Hi Team, I installed a new ELK server and also created a Index for metric beat and file-beats. But i am getting index error on dashboard of metric beat system overview. metricbeat- filebeat1- Please see the scree-sh…

---

## [Winlogbeat not working after enabling SSL but other beats work](https://discuss.elastic.co/t/winlogbeat-not-working-after-enabling-ssl-but-other-beats-work/155071)

<div class="topic-metadata">

**Author:** [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Replies:** 6\
**Last updated:** [November 7, 2018, 3:22pm UTC](https://discuss.elastic.co/t/winlogbeat-not-working-after-enabling-ssl-but-other-beats-work/155071 "2018-11-07T15:22:54Z")

</div>

Hello there, We are at ELK 6.4.2 (just upgraded) and beats are at 6.3.2. I did try winlogbeat 6.4.2, the same error. Recently we enabled X-Pack and set up SSL\\TLS on Logstash/Elasticsearch/Kibana. the Beats (filebeat…

---

## [Failed to connect to backoff elasticsearch with Metricbeat](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-with-metricbeat/155424)

<div class="topic-metadata">

**Author:** [@xavtauran](https://discuss.elastic.co/u/xavtauran)\
**Replies:** 2\
**Last updated:** [November 7, 2018, 2:35pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-with-metricbeat/155424 "2018-11-07T14:35:02Z")

</div>

Hello all, I'm a begginer withl ELK, so please be kind :slight\_smile: I make a moke-up to centralize logs with ELK. I have one server where ELK is installed, one firewall (Stomrshield) and one pc client. With ELK I re…

---

## [Basic questions and problems with creating a metricset](https://discuss.elastic.co/t/basic-questions-and-problems-with-creating-a-metricset/155549)

<div class="topic-metadata">

**Author:** [@TheUndertaker](https://discuss.elastic.co/u/TheUndertaker)\
**Replies:** 2\
**Last updated:** [November 7, 2018, 2:13pm UTC](https://discuss.elastic.co/t/basic-questions-and-problems-with-creating-a-metricset/155549 "2018-11-07T14:13:42Z")

</div>

Hi all :slight\_smile: I ran into some very basic problems that I have difficulty solving. I am trying to make a new metricset under the system module. I have downloaded the repo, ran make create-metricset. I got the ne…

---

## [Filebeat Multiline Java Stack Trace](https://discuss.elastic.co/t/filebeat-multiline-java-stack-trace/150003)

<div class="topic-metadata">

**Author:** [@luggo](https://discuss.elastic.co/u/luggo)\
**Replies:** 12\
**Last updated:** [November 7, 2018, 9:37am UTC](https://discuss.elastic.co/t/filebeat-multiline-java-stack-trace/150003 "2018-11-07T09:37:36Z")

</div>

Hey there, I try to find out how to use Filebeat for my Java Log files. Actually it's not a big deal, except for my problems with multiline messages, because my Java Logs include Stack Traces. Can someone help me to fi…

---

## [\[SOLVED\]Getting duplicate entries with Filebeat to Logstash Setup](https://discuss.elastic.co/t/solved-getting-duplicate-entries-with-filebeat-to-logstash-setup/155669)

<div class="topic-metadata">

**Author:** [@plex1030](https://discuss.elastic.co/u/plex1030)\
**Replies:** 6\
**Last updated:** [November 7, 2018, 8:50am UTC](https://discuss.elastic.co/t/solved-getting-duplicate-entries-with-filebeat-to-logstash-setup/155669 "2018-11-07T08:50:14Z")

</div>

Hi, My setup has been working perfectly for a week now but today I noticed that an entire logfile got submitted twice (the whole content was written around the same time so it was probably transmitted as one batch). Th…

---

## [Sampling\_rate](https://discuss.elastic.co/t/sampling-rate/153544)

<div class="topic-metadata">

**Author:** [@merceskoba](https://discuss.elastic.co/u/merceskoba)\
**Replies:** 4\
**Last updated:** [October 24, 2018, 6:01pm UTC](https://discuss.elastic.co/t/sampling-rate/153544 "2018-10-24T18:01:41Z")

</div>

Hello dear, Is there sampling\_rate in filebeat service ? For example, sampling\_rate: 0.1, it means 0.1 is 10/100 or 10%. So, filebeat will send the logs only 10% of logs. sampling\_rate or sampling\_filter maybe...

---

## [Filebeat not starting in virtual environment](https://discuss.elastic.co/t/filebeat-not-starting-in-virtual-environment/154207)

<div class="topic-metadata">

**Author:** [@Ishara\_Ruchiranga](https://discuss.elastic.co/u/Ishara_Ruchiranga)\
**Replies:** 13\
**Last updated:** [November 6, 2018, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-not-starting-in-virtual-environment/154207 "2018-11-06T19:47:58Z")

</div>

Hi we have built a tool to analyze our logs in our application. But when we try to start the Filebeat it just give the follow message and stop. Please give me a solution EDIT: Also I tried in multiple filebeat versi…

---

## ['make clean' and 'permssion denied'](https://discuss.elastic.co/t/make-clean-and-permssion-denied/155578)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 2\
**Last updated:** [November 6, 2018, 6:21pm UTC](https://discuss.elastic.co/t/make-clean-and-permssion-denied/155578 "2018-11-06T18:21:26Z")

</div>

I'm building a custom metric module. Running into some issues: 'make package' is currently failing on me. A rerun causes also causes permission issues: rm: cannot remove 'build/package/modules.d-darwin/golang\_push.ym…

---

## [Keeping \`message\` field intact with module parsing](https://discuss.elastic.co/t/keeping-message-field-intact-with-module-parsing/155452)

<div class="topic-metadata">

**Author:** [@rocketraman](https://discuss.elastic.co/u/rocketraman)\
**Replies:** 4\
**Last updated:** [November 6, 2018, 5:10pm UTC](https://discuss.elastic.co/t/keeping-message-field-intact-with-module-parsing/155452 "2018-11-06T17:10:51Z")

</div>

Parsing the message field with filebeat processors is great, as it allows structured search for logs, but one thing that surprises me is that the message field itself is destroyed. This means that just casual viewing of …

---

## [Filebeat : "Failed to connect to backoff"](https://discuss.elastic.co/t/filebeat-failed-to-connect-to-backoff/155535)

<div class="topic-metadata">

**Author:** [@RogerLapin](https://discuss.elastic.co/u/RogerLapin)\
**Replies:** 3\
**Last updated:** [November 6, 2018, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-connect-to-backoff/155535 "2018-11-06T16:53:57Z")

</div>

Greetings, I have been trying to have filebeat running on a swarm cluster, with what looked like quite a basic configuration (according to me!). Using logstash's gelf driver to direct log into logstash works well. But …

---

## [Setup Beats error time out](https://discuss.elastic.co/t/setup-beats-error-time-out/155389)

<div class="topic-metadata">

**Author:** [@shahid](https://discuss.elastic.co/u/shahid)\
**Replies:** 3\
**Last updated:** [November 6, 2018, 3:23pm UTC](https://discuss.elastic.co/t/setup-beats-error-time-out/155389 "2018-11-06T15:23:46Z")

</div>

Hi Team, i am getting the below below when i am tryting to setup the file and meteric beats on my client machines. sudo metricbeat -e setup sudo filebeat -e setup ERROR instance/beat.go:743 Exiting: Error importing K…

---

## [How do I convert JSON child arrays to docs in Metricbeat http module](https://discuss.elastic.co/t/how-do-i-convert-json-child-arrays-to-docs-in-metricbeat-http-module/155463)

<div class="topic-metadata">

**Author:** [@sharrah](https://discuss.elastic.co/u/sharrah)\
**Replies:** 1\
**Last updated:** [November 6, 2018, 3:21pm UTC](https://discuss.elastic.co/t/how-do-i-convert-json-child-arrays-to-docs-in-metricbeat-http-module/155463 "2018-11-06T15:21:31Z")

</div>

I am using the http module in metricbeat. I have several beats working this way which make requests to return a JSON array at the top (no problem). I have a new request that produces a JSON array under a parent. I need t…

---

## [Filebeat + elasticsearch make duplicates events](https://discuss.elastic.co/t/filebeat-elasticsearch-make-duplicates-events/151825)

<div class="topic-metadata">

**Author:** [@Horus](https://discuss.elastic.co/u/Horus)\
**Replies:** 19\
**Last updated:** [November 6, 2018, 11:35am UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-make-duplicates-events/151825 "2018-11-06T11:35:35Z")

</div>

I have a trouble with events dublicates in elasticsearch. I used filebeat to aggregate events from logback logs. It's config: filebeat.inputs: - type: log enabled: true paths: - /#/\*/#/\*/#/logs/\*.log - /…

---

## [Need help with setting up Apache2 to monitor the session time on every website](https://discuss.elastic.co/t/need-help-with-setting-up-apache2-to-monitor-the-session-time-on-every-website/147145)

<div class="topic-metadata">

**Author:** [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)\
**Replies:** 41\
**Last updated:** [November 6, 2018, 11:20am UTC](https://discuss.elastic.co/t/need-help-with-setting-up-apache2-to-monitor-the-session-time-on-every-website/147145 "2018-11-06T11:20:43Z")

</div>

Hi, I'm new to this Kibana/logstash stuff, and due to the current situation, so I'm seeking some help here. My objective: Setting up Apache2 on Kibana/Logstash server so that I can get the following information from t…

---

## [Is it possible to remove Beat Fields without using processors?](https://discuss.elastic.co/t/is-it-possible-to-remove-beat-fields-without-using-processors/155533)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 2\
**Last updated:** [November 6, 2018, 11:16am UTC](https://discuss.elastic.co/t/is-it-possible-to-remove-beat-fields-without-using-processors/155533 "2018-11-06T11:16:30Z")

</div>

Hi, I am using ELK GA 6.3.0. I use filebeat to read log files. I have noticed filebeat is shipping it's meta along with log file's content, like; "beat" =\> { "version" =\> "6.3.0", "name" =\> "iflyresdev70", …

---

## [\[ASK\] Other log collector or log sender](https://discuss.elastic.co/t/ask-other-log-collector-or-log-sender/155499)

<div class="topic-metadata">

**Author:** [@merceskoba](https://discuss.elastic.co/u/merceskoba)\
**Replies:** 2\
**Last updated:** [November 6, 2018, 9:11am UTC](https://discuss.elastic.co/t/ask-other-log-collector-or-log-sender/155499 "2018-11-06T09:11:11Z")

</div>

Hello Guys Do you know other log collector such as Filebeat ? Filebeat doesn't has sampling\_rate(https://www.scalyr.com/help/scalyr-agent#filter) My company doesn't want using Scalyr anymore. That's so expensive :slig…

---

## [Can i get the pod labels in the metricsets](https://discuss.elastic.co/t/can-i-get-the-pod-labels-in-the-metricsets/152079)

<div class="topic-metadata">

**Author:** [@pastorsx](https://discuss.elastic.co/u/pastorsx)\
**Replies:** 4\
**Last updated:** [November 5, 2018, 10:24pm UTC](https://discuss.elastic.co/t/can-i-get-the-pod-labels-in-the-metricsets/152079 "2018-11-05T22:24:09Z")

</div>

Hi, I am interested in using metric beat but I need to do some filtering of pods based on labels for some kibana visualizations.... Is there a way to do so?... I would have expected the pod metricset in kubernetes to s…

---

## [Apache2 module parsing](https://discuss.elastic.co/t/apache2-module-parsing/155429)

<div class="topic-metadata">

**Author:** [@rocketraman](https://discuss.elastic.co/u/rocketraman)\
**Replies:** 3\
**Last updated:** [November 5, 2018, 8:01pm UTC](https://discuss.elastic.co/t/apache2-module-parsing/155429 "2018-11-05T20:01:24Z")

</div>

I have a Kubernetes pod annotated with hint co.elastic.logs/module: apache2. I have a source log that looks like this: ::ffff:10.5.1.62 - - \[05/Nov/2018:15:39:18 +0000\] "GET /config HTTP/1.1" 304 - "https://myserver.com…

---

## [Multiple prospectors with multiple add\_fields](https://discuss.elastic.co/t/multiple-prospectors-with-multiple-add-fields/155173)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 3\
**Last updated:** [November 5, 2018, 4:45pm UTC](https://discuss.elastic.co/t/multiple-prospectors-with-multiple-add-fields/155173 "2018-11-05T16:45:38Z")

</div>

hi all, is it possible to use 2 different prospectors and 2 different fields? I mean, the first prospector will check the files S:\\data\\log\_temp.dat and add the field type: temporary while the second prospector will che…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=405)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=407)
