# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=408

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 409

---

## [Filebeats auto-mapping of kubernetes labels causing big issues](https://discuss.elastic.co/t/filebeats-auto-mapping-of-kubernetes-labels-causing-big-issues/154718)

<div class="topic-metadata">

**Author:** [@rocketraman](https://discuss.elastic.co/u/rocketraman)\
**Replies:** 7\
**Last updated:** [November 1, 2018, 7:59pm UTC](https://discuss.elastic.co/t/filebeats-auto-mapping-of-kubernetes-labels-causing-big-issues/154718 "2018-11-01T19:59:32Z")

</div>

Filebeats 6.4.2, with Kubernetes auto-discovery, is failing to index most of my Kubernetes logs, due to errors like this: (status=400): {"type":"mapper\_parsing\_exception","reason":"object mapping for \[kubernetes.labels.…

---

## [Filebeat has problem to record new lines separated](https://discuss.elastic.co/t/filebeat-has-problem-to-record-new-lines-separated/155040)

<div class="topic-metadata">

**Author:** [@bab](https://discuss.elastic.co/u/bab)\
**Replies:** 2\
**Last updated:** [November 1, 2018, 6:34pm UTC](https://discuss.elastic.co/t/filebeat-has-problem-to-record-new-lines-separated/155040 "2018-11-01T18:34:57Z")

</div>

Hi I have following lines, and I am using filebeat to publish this data to logstash and then trying to extract values using grok in Logstash filter, untell now every thing is good (new pattern, multiline config , etc...…

---

## [NagiosCheckBeat additional Config Dir?](https://discuss.elastic.co/t/nagioscheckbeat-additional-config-dir/154518)

<div class="topic-metadata">

**Author:** [@Luis\_N](https://discuss.elastic.co/u/Luis_N)\
**Replies:** 1\
**Last updated:** [November 1, 2018, 5:34pm UTC](https://discuss.elastic.co/t/nagioscheckbeat-additional-config-dir/154518 "2018-11-01T17:34:39Z")

</div>

I know its not the official Beats release, but is there a definition in the yml config to specify additional config yml's ? I am trying to create config files with the "Hostname" of the destination box since every nagios…

---

## [Extract field from Messages section of Windows Event Log](https://discuss.elastic.co/t/extract-field-from-messages-section-of-windows-event-log/154724)

<div class="topic-metadata">

**Author:** [@Dave\_Foster](https://discuss.elastic.co/u/Dave_Foster)\
**Replies:** 1\
**Last updated:** [November 1, 2018, 5:33pm UTC](https://discuss.elastic.co/t/extract-field-from-messages-section-of-windows-event-log/154724 "2018-11-01T17:33:47Z")

</div>

We are trying to extract a couple fields via filters from within the nested 'messages' section of a Windows Event Log. Below is the nested info from event\_data.param2 : \<?xml version="1.0" encoding="utf-16"?\> \<AuditBa…

---

## [Winlogbeat collect Active Directory Security event log slowly](https://discuss.elastic.co/t/winlogbeat-collect-active-directory-security-event-log-slowly/154380)

<div class="topic-metadata">

**Author:** [@peterch](https://discuss.elastic.co/u/peterch)\
**Replies:** 2\
**Last updated:** [November 1, 2018, 5:32pm UTC](https://discuss.elastic.co/t/winlogbeat-collect-active-directory-security-event-log-slowly/154380 "2018-11-01T17:32:04Z")

</div>

Dear All, I have 3 Active Directory machines which installed winlogbeat. I find there are some issues on collecting security event log. According to the below chart, it show the received security event from 3 machine …

---

## [How can I configure the setup.template.pattern param for multiple indices in filebeat?](https://discuss.elastic.co/t/how-can-i-configure-the-setup-template-pattern-param-for-multiple-indices-in-filebeat/154790)

<div class="topic-metadata">

**Author:** [@yongqiang](https://discuss.elastic.co/u/yongqiang)\
**Replies:** 1\
**Last updated:** [November 1, 2018, 5:31pm UTC](https://discuss.elastic.co/t/how-can-i-configure-the-setup-template-pattern-param-for-multiple-indices-in-filebeat/154790 "2018-11-01T17:31:06Z")

</div>

hi, I configured the filebeat.yml with followings: filebeat.inputs: type: log enabled: true paths: D:\\ECLog\\dev\*.log fields: service: dev-econtract multiline.pattern: ^\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}.\\d{4…

---

## [Filebeat 6.4.2 consumes high CPU and lots of memory on windows server 2012 R2](https://discuss.elastic.co/t/filebeat-6-4-2-consumes-high-cpu-and-lots-of-memory-on-windows-server-2012-r2/154805)

<div class="topic-metadata">

**Author:** [@yongqiang](https://discuss.elastic.co/u/yongqiang)\
**Replies:** 1\
**Last updated:** [November 1, 2018, 5:29pm UTC](https://discuss.elastic.co/t/filebeat-6-4-2-consumes-high-cpu-and-lots-of-memory-on-windows-server-2012-r2/154805 "2018-11-01T17:29:09Z")

</div>

hi, I setup a filebeat on window server 2012 R2 to collect some log files ( not too much files \<10, file size for each one is less than 100M). The system is as follows. I noticed that it consumes almost 20% CPU and …

---

## [Decompressing HTTP](https://discuss.elastic.co/t/decompressing-http/154937)

<div class="topic-metadata">

**Author:** [@tropas](https://discuss.elastic.co/u/tropas)\
**Replies:** 1\
**Last updated:** [November 1, 2018, 5:27pm UTC](https://discuss.elastic.co/t/decompressing-http/154937 "2018-11-01T17:27:00Z")

</div>

What’s the best way to decompress a compressed HTTP body? I think using a bespoke ruby function in Logstash could do it (although I’d need to learn ruby first and Logstash doesn’t give you the most user friendly error co…

---

## [Using Heartbeat as a Speed Test](https://discuss.elastic.co/t/using-heartbeat-as-a-speed-test/154931)

<div class="topic-metadata">

**Author:** [@Josiah\_Raiche](https://discuss.elastic.co/u/Josiah_Raiche)\
**Replies:** 2\
**Last updated:** [November 1, 2018, 3:22pm UTC](https://discuss.elastic.co/t/using-heartbeat-as-a-speed-test/154931 "2018-11-01T15:22:35Z")

</div>

I'm trying to use Heartbeat to roughly check intranet speed. I have a large file on an internal server and I can reach it with heartbeat. I'm testing on a slow internet connection. In the browser it takes over a minute …

---

## [Filebeat add\_kubernetes\_metadata and IPv6](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018)

<div class="topic-metadata">

**Author:** [@hhoover](https://discuss.elastic.co/u/hhoover)\
**Replies:** 3\
**Last updated:** [November 1, 2018, 3:09pm UTC](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018 "2018-11-01T15:09:06Z")

</div>

When using filebeat in a Kubernetes cluster as a pod, using the add\_kubernetes\_metadata processor, the processor can't handle IPv6 addresses if an IPv6 address resolves from https://kubernetes.default.svc.cluster.local. …

---

## [Monitor Open TCP Connections](https://discuss.elastic.co/t/monitor-open-tcp-connections/154830)

<div class="topic-metadata">

**Author:** [@rani](https://discuss.elastic.co/u/rani)\
**Replies:** 4\
**Last updated:** [November 1, 2018, 1:05pm UTC](https://discuss.elastic.co/t/monitor-open-tcp-connections/154830 "2018-11-01T13:05:22Z")

</div>

Hi all I'm currently trying to find a way to monitor all open TCP connections via Kibana. I can't find a way to get this data via beats. Is there a way I'm missing? Thanks in advance for your help.

---

## [Winlogbeat only last log shows in Kibana](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004)

<div class="topic-metadata">

**Author:** [@Loggeruk](https://discuss.elastic.co/u/Loggeruk)\
**Replies:** 5\
**Last updated:** [November 1, 2018, 12:28pm UTC](https://discuss.elastic.co/t/winlogbeat-only-last-log-shows-in-kibana/155004 "2018-11-01T12:28:03Z")

</div>

Hi all, I am trying to setup my elastic server running logstash, kibana and elasticsearch (installed via a binami package) Everything is running ok but when trying to gather windows logs from a machine using winlogbeat …

---

## [EventID 4801 and 4800 are not getting visualised in Kibana through Winlogbeat](https://discuss.elastic.co/t/eventid-4801-and-4800-are-not-getting-visualised-in-kibana-through-winlogbeat/154625)

<div class="topic-metadata">

**Author:** [@SunilT](https://discuss.elastic.co/u/SunilT)\
**Replies:** 4\
**Last updated:** [November 1, 2018, 6:38am UTC](https://discuss.elastic.co/t/eventid-4801-and-4800-are-not-getting-visualised-in-kibana-through-winlogbeat/154625 "2018-11-01T06:38:18Z")

</div>

I have configured the winlogbeat.yml file to take EventID:4801,4800,4624,4625, but when I am checking on Kibana, it is showing me logs of EventID:4625 and 4624. No logs are getting generated for EventId: 4800 and 4801. I…

---

## [Unable to use rename processor](https://discuss.elastic.co/t/unable-to-use-rename-processor/154733)

<div class="topic-metadata">

**Author:** [@rocketraman](https://discuss.elastic.co/u/rocketraman)\
**Replies:** 2\
**Last updated:** [November 1, 2018, 6:28am UTC](https://discuss.elastic.co/t/unable-to-use-rename-processor/154733 "2018-11-01T06:28:44Z")

</div>

I am trying to use the rename processor in Filebeat 6.4.2 like this: processors: - rename: fields: - from: "app.kubernetes.io/name" to: "app" - from: "app.kubernetes.io/…

---

## [Auditbeat File arrival monitoring](https://discuss.elastic.co/t/auditbeat-file-arrival-monitoring/154620)

<div class="topic-metadata">

**Author:** [@Prabu\_RS](https://discuss.elastic.co/u/Prabu_RS)\
**Replies:** 3\
**Last updated:** [October 31, 2018, 8:23pm UTC](https://discuss.elastic.co/t/auditbeat-file-arrival-monitoring/154620 "2018-10-31T20:23:10Z")

</div>

Hi , I would like to monitor all files in specific directories say for ex /xxx/xxx/\* The purpose of the requirement is to monitor file arrival for batch jobs. And also would like to show to the users in kibana dashboar…

---

## [FIlebeat with services inside of docker compose via autodiscover](https://discuss.elastic.co/t/filebeat-with-services-inside-of-docker-compose-via-autodiscover/154886)

<div class="topic-metadata">

**Author:** [@krainboltgreene](https://discuss.elastic.co/u/krainboltgreene)\
**Replies:** 8\
**Last updated:** [October 31, 2018, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-with-services-inside-of-docker-compose-via-autodiscover/154886 "2018-10-31T18:41:09Z")

</div>

Alright, so lets say I have these services: services: redis: ... filebeat: ... And this filebeat configuration: filebeat.autodiscover: providers: - type: docker templates: - config: …

---

## [Reading both container logs and host logs on K8s?](https://discuss.elastic.co/t/reading-both-container-logs-and-host-logs-on-k8s/154683)

<div class="topic-metadata">

**Author:** [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Replies:** 6\
**Last updated:** [October 31, 2018, 4:36pm UTC](https://discuss.elastic.co/t/reading-both-container-logs-and-host-logs-on-k8s/154683 "2018-10-31T16:36:04Z")

</div>

This is probably a typo or something I haven't spotted despite staring at it for hours, but just in case ... I'm running Filebeat in K8s as a Daemon Set, with Kubernetes type autodiscover configured and working fine to …

---

## [Filebeat agent installed on the client](https://discuss.elastic.co/t/filebeat-agent-installed-on-the-client/154862)

<div class="topic-metadata">

**Author:** [@Shahid\_Chaudhary](https://discuss.elastic.co/u/Shahid_Chaudhary)\
**Replies:** 1\
**Last updated:** [October 31, 2018, 4:33pm UTC](https://discuss.elastic.co/t/filebeat-agent-installed-on-the-client/154862 "2018-10-31T16:33:16Z")

</div>

Filebeat agent is installed on my client machine but machine is now showing on the ELK dashboard. What can be the issue. i already check the service status of filebeat is running ubuntu@ip-10-0-1-243:~$ sudo service fi…

---

## [Edit log before parsing?](https://discuss.elastic.co/t/edit-log-before-parsing/154855)

<div class="topic-metadata">

**Author:** [@OffColour](https://discuss.elastic.co/u/OffColour)\
**Replies:** 1\
**Last updated:** [October 31, 2018, 2:15pm UTC](https://discuss.elastic.co/t/edit-log-before-parsing/154855 "2018-10-31T14:15:57Z")

</div>

Hi, I've got some logs that are badly formed JSON. I know the exact field with the problem (it's missing a value), but getting all the components that are doing this fixed is going to take some time. Is there any way t…

---

## [Filebeat Kafka output message compression](https://discuss.elastic.co/t/filebeat-kafka-output-message-compression/153916)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [October 31, 2018, 1:11pm UTC](https://discuss.elastic.co/t/filebeat-kafka-output-message-compression/153916 "2018-10-31T13:11:20Z")

</div>

Would like to know whether filebeat compresses the log events before sending to Kafka.

---

## [Filebeat to Logstash : How to keep lines order](https://discuss.elastic.co/t/filebeat-to-logstash-how-to-keep-lines-order/154612)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 6\
**Last updated:** [October 31, 2018, 12:35pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-how-to-keep-lines-order/154612 "2018-10-31T12:35:19Z")

</div>

Hello, I use a filebeat instance to read some log files and send them to a logstash instance on another server to store them as a file output. On one of the logs, line order is not critical, so I haven't encountered th…

---

## [Metricbeat: Harddisk space used changing very dynamically](https://discuss.elastic.co/t/metricbeat-harddisk-space-used-changing-very-dynamically/154604)

<div class="topic-metadata">

**Author:** [@Ruthvik\_Sai](https://discuss.elastic.co/u/Ruthvik_Sai)\
**Replies:** 4\
**Last updated:** [October 31, 2018, 10:52am UTC](https://discuss.elastic.co/t/metricbeat-harddisk-space-used-changing-very-dynamically/154604 "2018-10-31T10:52:34Z")

</div>

! Why is the hard disk space varying so dynamically?? The above is the cumulative hard disk space used from 5 desktop end points. To get the the above visualisation for used space, I used sum aggregation followed…

---

## [Logstash output for filebeat xpack monitoring](https://discuss.elastic.co/t/logstash-output-for-filebeat-xpack-monitoring/153471)

<div class="topic-metadata">

**Author:** [@jgrevich](https://discuss.elastic.co/u/jgrevich)\
**Replies:** 4\
**Last updated:** [October 31, 2018, 10:39am UTC](https://discuss.elastic.co/t/logstash-output-for-filebeat-xpack-monitoring/153471 "2018-10-31T10:39:48Z")

</div>

Is it possible to configure filebeat to send its monitoring metrics through logstash rather than have filebeat access the ES cluster directly? I can't seem to figure out how to do this and the documentation seems to sug…

---

## [Filebeat Multiline Patterns not working for us](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working-for-us/153594)

<div class="topic-metadata">

**Author:** [@vishnuduttpv](https://discuss.elastic.co/u/vishnuduttpv)\
**Replies:** 10\
**Last updated:** [October 31, 2018, 10:13am UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working-for-us/153594 "2018-10-31T10:13:50Z")

</div>

I wish to parse the tomcat logs. But I am facing problem in multiline handling in Filebeat. The logs are not parsed as per the requirement. Getting grokparse failures. Upon checking, I could see that the line starts does…

---

## [Need help with Logstash/Filebeat working with Kibana](https://discuss.elastic.co/t/need-help-with-logstash-filebeat-working-with-kibana/153501)

<div class="topic-metadata">

**Author:** [@CMonty](https://discuss.elastic.co/u/CMonty)\
**Replies:** 7\
**Last updated:** [October 31, 2018, 9:51am UTC](https://discuss.elastic.co/t/need-help-with-logstash-filebeat-working-with-kibana/153501 "2018-10-31T09:51:38Z")

</div>

I am trying to ingest data into kibana using a logstash via a filebeat but the data isn't being transferred by my filebeat for some reason... Would you guys be able to help? The link below is the code to my logstash-sam…

---

## [Filebeat installation as service but under custom folder](https://discuss.elastic.co/t/filebeat-installation-as-service-but-under-custom-folder/152915)

<div class="topic-metadata">

**Author:** [@shivaprasadrao.b](https://discuss.elastic.co/u/shivaprasadrao.b)\
**Replies:** 3\
**Last updated:** [October 31, 2018, 8:33am UTC](https://discuss.elastic.co/t/filebeat-installation-as-service-but-under-custom-folder/152915 "2018-10-31T08:33:14Z")

</div>

I have setup filbeat using below: curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-6.4.0-x86\_64.rpm sudo rpm -vi filebeat-6.4.0-x86\_64.rpm Filebeat is successfully set up as service, but the f…

---

## [Application usage in desktop using winlogbeat in kibana](https://discuss.elastic.co/t/application-usage-in-desktop-using-winlogbeat-in-kibana/154587)

<div class="topic-metadata">

**Author:** [@godfather7](https://discuss.elastic.co/u/godfather7)\
**Replies:** 1\
**Last updated:** [October 30, 2018, 4:13pm UTC](https://discuss.elastic.co/t/application-usage-in-desktop-using-winlogbeat-in-kibana/154587 "2018-10-30T16:13:51Z")

</div>

Actually I am not able to get the meaning of the count which we can see in the kibana dashboard. Moreover how can we get application usage time using winlogbeat and sysmon in kibana dashboard

---

## [Upstream journalbeat project - how do I build this?](https://discuss.elastic.co/t/upstream-journalbeat-project-how-do-i-build-this/154668)

<div class="topic-metadata">

**Author:** [@dictvm](https://discuss.elastic.co/u/dictvm)\
**Replies:** 1\
**Last updated:** [October 30, 2018, 3:23pm UTC](https://discuss.elastic.co/t/upstream-journalbeat-project-how-do-i-build-this/154668 "2018-10-30T15:23:26Z")

</div>

I've noticed that there's a new beats project in the repo called journalbeat . It seems to be a completely new project that's similar in functionality to this one. However, I can't yet find any documentation for it. Wi…

---

## [How to manage different paths for different hosts](https://discuss.elastic.co/t/how-to-manage-different-paths-for-different-hosts/154584)

<div class="topic-metadata">

**Author:** [@arushan](https://discuss.elastic.co/u/arushan)\
**Replies:** 3\
**Last updated:** [October 30, 2018, 2:44pm UTC](https://discuss.elastic.co/t/how-to-manage-different-paths-for-different-hosts/154584 "2018-10-30T14:44:12Z")

</div>

Hi, Im working on to install filebeat in multiple hosts via ansible. In my case, the log paths are different for each hosts. So i would like to know how to create a common filebeat config with different paths for diff…

---

## [How can filebeat recognize some fields?](https://discuss.elastic.co/t/how-can-filebeat-recognize-some-fields/154666)

<div class="topic-metadata">

**Author:** [@stefano.bisi](https://discuss.elastic.co/u/stefano.bisi)\
**Replies:** 1\
**Last updated:** [October 30, 2018, 1:40pm UTC](https://discuss.elastic.co/t/how-can-filebeat-recognize-some-fields/154666 "2018-10-30T13:40:31Z")

</div>

Good Morning How is it possibile to "label" some filed? for example, actually filebeat put into the field "message" these information "October 30th 2018, 14:23:46.839 30/10/2018 14:23:44 Added iexplorer.exe …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=407)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=409)
