# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=409

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 410

---

## [Filebeat not harvesting all files in a folder](https://discuss.elastic.co/t/filebeat-not-harvesting-all-files-in-a-folder/153293)

<div class="topic-metadata">

**Author:** [@Srinivasa\_Prasad](https://discuss.elastic.co/u/Srinivasa_Prasad)\
**Replies:** 3\
**Last updated:** [October 30, 2018, 11:57am UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-all-files-in-a-folder/153293 "2018-10-30T11:57:19Z")

</div>

I have a log folder with 744 files, but filebeat has read only 155 files. Is there a setting that controls max number of files to be read. I am using docker-compose and mapped bind mount volume of local log directory to…

---

## [Metricbeat not reporting on port 10255 anymore using latest kubernetes, how to use the secured port 10250?](https://discuss.elastic.co/t/metricbeat-not-reporting-on-port-10255-anymore-using-latest-kubernetes-how-to-use-the-secured-port-10250/153605)

<div class="topic-metadata">

**Author:** [@pastorsx](https://discuss.elastic.co/u/pastorsx)\
**Replies:** 5\
**Last updated:** [October 30, 2018, 11:42am UTC](https://discuss.elastic.co/t/metricbeat-not-reporting-on-port-10255-anymore-using-latest-kubernetes-how-to-use-the-secured-port-10250/153605 "2018-10-30T11:42:19Z")

</div>

Hi all, I've been using metricbeat through its helm chart to install in a kubernetes cluster. It used to work by going though port 10255 which was a non-secured read only port.. but it seems latest releases of kubernete…

---

## [Reopening: Beats on Power AIX?](https://discuss.elastic.co/t/reopening-beats-on-power-aix/137134)

<div class="topic-metadata">

**Author:** [@JHer](https://discuss.elastic.co/u/JHer)\
**Replies:** 2\
**Last updated:** [October 30, 2018, 5:39am UTC](https://discuss.elastic.co/t/reopening-beats-on-power-aix/137134 "2018-10-30T05:39:09Z")

</div>

Hello, I would like to reopen discussion about Beats (for me its FileBeat and MetricBeat primarly) on AIX. In one year old topic (Beats on Power AIX?), the only answer was about porting GoLang to AIX. According to GitHu…

---

## [Auditbeat Errors - Do Not Pass Go Do Not Collect $200](https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539)

<div class="topic-metadata">

**Author:** [@jc034240](https://discuss.elastic.co/u/jc034240)\
**Replies:** 3\
**Last updated:** [October 30, 2018, 2:34am UTC](https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539 "2018-10-30T02:34:02Z")

</div>

What's the rule on spacing? Below are two different spacing scenarios and the related errors for logstash as an output. #----------------------------- Logstash output -------------------------------- # Zero space in fro…

---

## [Need help with multiline pattern in complex log file](https://discuss.elastic.co/t/need-help-with-multiline-pattern-in-complex-log-file/154515)

<div class="topic-metadata">

**Author:** [@Ryan\_Ivis](https://discuss.elastic.co/u/Ryan_Ivis)\
**Replies:** 2\
**Last updated:** [October 29, 2018, 9:16pm UTC](https://discuss.elastic.co/t/need-help-with-multiline-pattern-in-complex-log-file/154515 "2018-10-29T21:16:59Z")

</div>

All logs start with the following 2018-10-29T14:42:32,484 DEBUG \[7DDvqyNAoe6UmkmcfvP8hw\] Which to me looks like Timestamp,MessageType TypeOfLog \[MessageID\] How would i create a multiline filter for this in filebeat?

---

## [Module fields coming from filebeat](https://discuss.elastic.co/t/module-fields-coming-from-filebeat/154244)

<div class="topic-metadata">

**Author:** [@grantk](https://discuss.elastic.co/u/grantk)\
**Replies:** 2\
**Last updated:** [October 29, 2018, 7:46pm UTC](https://discuss.elastic.co/t/module-fields-coming-from-filebeat/154244 "2018-10-29T19:46:57Z")

</div>

I've just configured filebeat to log to ES hosted by elastic. It is working fine but there are hundreds of unused fields i.e. apache, traefik.access., mysql.. It seems the default config points to a modules directory: …

---

## [Send Tomcat8 (catalina.out) log to show in kibana](https://discuss.elastic.co/t/send-tomcat8-catalina-out-log-to-show-in-kibana/154239)

<div class="topic-metadata">

**Author:** [@debsdaniel](https://discuss.elastic.co/u/debsdaniel)\
**Replies:** 2\
**Last updated:** [October 29, 2018, 7:35pm UTC](https://discuss.elastic.co/t/send-tomcat8-catalina-out-log-to-show-in-kibana/154239 "2018-10-29T19:35:47Z")

</div>

Hi. This is my first post here. I hope be in the right way. I have installed Full Stack Elastic (Elasticsearch, Kibana, Logstash) in a ubuntu 18.04 server, all is ok. Then I have installed filebeat 6.4.2 in each serv…

---

## [New Packetbeat Protocol - accessing lower layer Info](https://discuss.elastic.co/t/new-packetbeat-protocol-accessing-lower-layer-info/154468)

<div class="topic-metadata">

**Author:** [@dhughes](https://discuss.elastic.co/u/dhughes)\
**Replies:** 1\
**Last updated:** [October 29, 2018, 6:39pm UTC](https://discuss.elastic.co/t/new-packetbeat-protocol-accessing-lower-layer-info/154468 "2018-10-29T18:39:00Z")

</div>

We've created our own UDP protocol in Packetbeat. We're successfully accessed the payload past UDP using the Payload field within the Packet struct. We see the tuple information as well for IP. What we're wondering ho…

---

## [Filebeat holding the file and not allowing the daily job to replace](https://discuss.elastic.co/t/filebeat-holding-the-file-and-not-allowing-the-daily-job-to-replace/154328)

<div class="topic-metadata">

**Author:** [@Uttam](https://discuss.elastic.co/u/Uttam)\
**Replies:** 1\
**Last updated:** [October 29, 2018, 6:18pm UTC](https://discuss.elastic.co/t/filebeat-holding-the-file-and-not-allowing-the-daily-job-to-replace/154328 "2018-10-29T18:18:12Z")

</div>

Hi there, Currently we are having an issue while creating a new process to send data from SQL table to Kafka. We created 2 SQL agent jobs, each to create(replaces same file daily) the a file daily on our server which …

---

## [Metricbeat : Why is the count of the beat varying so much](https://discuss.elastic.co/t/metricbeat-why-is-the-count-of-the-beat-varying-so-much/154435)

<div class="topic-metadata">

**Author:** [@Ruthvik\_Sai](https://discuss.elastic.co/u/Ruthvik_Sai)\
**Replies:** 2\
**Last updated:** [October 29, 2018, 4:29pm UTC](https://discuss.elastic.co/t/metricbeat-why-is-the-count-of-the-beat-varying-so-much/154435 "2018-10-29T16:29:36Z")

</div>

! The above is the pic of metricbeat running from 5 desktop end points

---

## [Creating own beat with no GIT access](https://discuss.elastic.co/t/creating-own-beat-with-no-git-access/154219)

<div class="topic-metadata">

**Author:** [@TheUndertaker](https://discuss.elastic.co/u/TheUndertaker)\
**Replies:** 2\
**Last updated:** [October 29, 2018, 3:49pm UTC](https://discuss.elastic.co/t/creating-own-beat-with-no-git-access/154219 "2018-10-29T15:49:56Z")

</div>

Hi all, A newbe to elastic, so pardon my lack of knowledge :wink: My goal is to create more beats to metricbeat to gather more data. The whole infra I have (even development servers) is behind a firewall. I won't have …

---

## [How to set ELK6 in one ubuntu EC2 instance and Filebeat in another ubuntu EC2 instance? Anybody has the whole settings?](https://discuss.elastic.co/t/how-to-set-elk6-in-one-ubuntu-ec2-instance-and-filebeat-in-another-ubuntu-ec2-instance-anybody-has-the-whole-settings/154099)

<div class="topic-metadata">

**Author:** [@fuwei1234](https://discuss.elastic.co/u/fuwei1234)\
**Replies:** 1\
**Last updated:** [October 29, 2018, 2:11pm UTC](https://discuss.elastic.co/t/how-to-set-elk6-in-one-ubuntu-ec2-instance-and-filebeat-in-another-ubuntu-ec2-instance-anybody-has-the-whole-settings/154099 "2018-10-29T14:11:00Z")

</div>

There are several instructions, but each one got different errors. The most recent errors is: dial up... ERROR dial tcp IP-address:5044: getsockopt: connection refused Filebeat.yml has added logstash public IP logstas…

---

## [Auditbeat on windows for FIM](https://discuss.elastic.co/t/auditbeat-on-windows-for-fim/154255)

<div class="topic-metadata">

**Author:** [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Replies:** 3\
**Last updated:** [October 29, 2018, 1:21pm UTC](https://discuss.elastic.co/t/auditbeat-on-windows-for-fim/154255 "2018-10-29T13:21:15Z")

</div>

Hi There, Is it possible use auditbeat to monitor ( FIM ) for windows for network file shares or windows file shares for GDPR , if we have some confidential data, is it possible to mention the path of the shared folders…

---

## [Packetbeat Dashboard Help](https://discuss.elastic.co/t/packetbeat-dashboard-help/153467)

<div class="topic-metadata">

**Author:** [@David\_Moreno](https://discuss.elastic.co/u/David_Moreno)\
**Replies:** 1\
**Last updated:** [October 29, 2018, 12:02pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-help/153467 "2018-10-29T12:02:36Z")

</div>

Hello Im trying to install a packetbeat dashboard on my ELK server. Im running the command: packetbeat setup --dashboards And I get this: Loading dashboards (Kibana must be running and reachable) Exiting: Error impor…

---

## [Metricbeat Host Metadata on Kubernetes](https://discuss.elastic.co/t/metricbeat-host-metadata-on-kubernetes/154341)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 2\
**Last updated:** [October 29, 2018, 8:04am UTC](https://discuss.elastic.co/t/metricbeat-host-metadata-on-kubernetes/154341 "2018-10-29T08:04:56Z")

</div>

Hi everyone, I am currently working with Metricbeat in order to monitor Kubernetes. I'm using Metricbeat manifest from Beats Github (Link). I am testing a new feature called host metadata . If I use this new feature, M…

---

## [How to simulate output from Winlogbeat to logstash for testing](https://discuss.elastic.co/t/how-to-simulate-output-from-winlogbeat-to-logstash-for-testing/154309)

<div class="topic-metadata">

**Author:** [@gasparuben](https://discuss.elastic.co/u/gasparuben)\
**Replies:** 3\
**Last updated:** [October 28, 2018, 11:14pm UTC](https://discuss.elastic.co/t/how-to-simulate-output-from-winlogbeat-to-logstash-for-testing/154309 "2018-10-28T23:14:08Z")

</div>

hello, I am trying to write some logstash rules to capture log on/off events on Windows machines. To extract security events from the Eventvwr I do something like that on eventvwr: $starttime = (get-date).addhours(-1…

---

## [Parsing specific files with Kubernetes autodiscover (hints)](https://discuss.elastic.co/t/parsing-specific-files-with-kubernetes-autodiscover-hints/154344)

<div class="topic-metadata">

**Author:** [@havlan](https://discuss.elastic.co/u/havlan)\
**Replies:** 1\
**Last updated:** [October 28, 2018, 11:04pm UTC](https://discuss.elastic.co/t/parsing-specific-files-with-kubernetes-autodiscover-hints/154344 "2018-10-28T23:04:50Z")

</div>

Is it possible to log or tail specific files specified with Kuberneres filebeat hints or something? Say a service is logging specific events to a file, is it possible to extract these with filebeat? Is hint modules the w…

---

## [Reading data from a "changing" log file](https://discuss.elastic.co/t/reading-data-from-a-changing-log-file/154233)

<div class="topic-metadata">

**Author:** [@nccbk](https://discuss.elastic.co/u/nccbk)\
**Replies:** 1\
**Last updated:** [October 28, 2018, 5:27pm UTC](https://discuss.elastic.co/t/reading-data-from-a-changing-log-file/154233 "2018-10-28T17:27:36Z")

</div>

Hello out there! I am pretty new on the elastic and hope for your help :slightly\_smiling\_face: My plan is to use python to read sensor data and log it on another machine. I wanna use logstash to parse my file and send …

---

## [Filebeat encodes harvested content before shipping](https://discuss.elastic.co/t/filebeat-encodes-harvested-content-before-shipping/153976)

<div class="topic-metadata">

**Author:** [@CyberSeppi](https://discuss.elastic.co/u/CyberSeppi)\
**Replies:** 6\
**Last updated:** [October 27, 2018, 8:06pm UTC](https://discuss.elastic.co/t/filebeat-encodes-harvested-content-before-shipping/153976 "2018-10-27T20:06:31Z")

</div>

Hi guys, first the problem I´m running filebeat on an apache webserver and want to ship the access logs to logstash. I ran into problems with the content of shipment and already narrowed it down to filebeat: The outp…

---

## [Heartbeat HTTP "use of closed network connection"](https://discuss.elastic.co/t/heartbeat-http-use-of-closed-network-connection/147876)

<div class="topic-metadata">

**Author:** [@Simon\_Hardman](https://discuss.elastic.co/u/Simon_Hardman)\
**Replies:** 6\
**Last updated:** [October 26, 2018, 5:01pm UTC](https://discuss.elastic.co/t/heartbeat-http-use-of-closed-network-connection/147876 "2018-10-26T17:01:31Z")

</div>

When using a HTTP Heartbeat (6.4.0 on Centos 7.5) I'm finding it works fine if I only check the response status, but if I include a check on the response body I always get an error about "use of closed network connection…

---

## [Filebeat rename processor with conditions](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371)

<div class="topic-metadata">

**Author:** [@havlan](https://discuss.elastic.co/u/havlan)\
**Replies:** 7\
**Last updated:** [October 26, 2018, 1:33pm UTC](https://discuss.elastic.co/t/filebeat-rename-processor-with-conditions/153371 "2018-10-26T13:33:28Z")

</div>

Hi! I'm trying to rename some fields from kubernetes annotations based on an when conditions, due to not finding any good resources, I was wondering if someone of you could help me with this. My goal is to rename events…

---

## [Filebeat 5.6.12 issues running in Kubernates](https://discuss.elastic.co/t/filebeat-5-6-12-issues-running-in-kubernates/153494)

<div class="topic-metadata">

**Author:** [@AkshathPatkar](https://discuss.elastic.co/u/AkshathPatkar)\
**Replies:** 9\
**Last updated:** [October 26, 2018, 12:48pm UTC](https://discuss.elastic.co/t/filebeat-5-6-12-issues-running-in-kubernates/153494 "2018-10-26T12:48:17Z")

</div>

We are having issues while running filebeat as a deamon set. File beat version : 5.6.12 We are running file beat as a deamonset across our different kubernates clusters. We are running deamonset in its own name sapce …

---

## [Integration Of ELK Stack With Salt Stack](https://discuss.elastic.co/t/integration-of-elk-stack-with-salt-stack/154155)

<div class="topic-metadata">

**Author:** [@SJN8](https://discuss.elastic.co/u/SJN8)\
**Replies:** 1\
**Last updated:** [October 26, 2018, 12:35pm UTC](https://discuss.elastic.co/t/integration-of-elk-stack-with-salt-stack/154155 "2018-10-26T12:35:59Z")

</div>

Hi All, I have working ELK Stack in PROD . We now have a requirement to Manage ELK Stack via Salt Stack . Operations like , Installation , configuration and management of ELK need to be done by SALT STACK . I have be…

---

## [Filebeat not getting new IIS events after initial load](https://discuss.elastic.co/t/filebeat-not-getting-new-iis-events-after-initial-load/154002)

<div class="topic-metadata">

**Author:** [@rstasiunas](https://discuss.elastic.co/u/rstasiunas)\
**Replies:** 9\
**Last updated:** [October 26, 2018, 12:20pm UTC](https://discuss.elastic.co/t/filebeat-not-getting-new-iis-events-after-initial-load/154002 "2018-10-26T12:20:39Z")

</div>

I'm trying to stream IIS advanced logs via Filebeat to Logstash -\> Elasticsearch. If I delete the registry files and restart filebeat it loads all of the data, but does not load any additional log lines after the initia…

---

## [X-pack license in 6.4.2](https://discuss.elastic.co/t/x-pack-license-in-6-4-2/154133)

<div class="topic-metadata">

**Author:** [@fliperzero](https://discuss.elastic.co/u/fliperzero)\
**Replies:** 1\
**Last updated:** [October 26, 2018, 7:45am UTC](https://discuss.elastic.co/t/x-pack-license-in-6-4-2/154133 "2018-10-26T07:45:55Z")

</div>

Hello Guys! You wrote that X-Pack has a number of features, that require different license levels. On 6.3 (or 6.4), you can Use some of the X-Pack features under the default, free, "basic" license that never expi…

---

## [How to configure parsing for Kubernetes?](https://discuss.elastic.co/t/how-to-configure-parsing-for-kubernetes/153884)

<div class="topic-metadata">

**Author:** [@spiffytech](https://discuss.elastic.co/u/spiffytech)\
**Replies:** 1\
**Last updated:** [October 26, 2018, 7:03am UTC](https://discuss.elastic.co/t/how-to-configure-parsing-for-kubernetes/153884 "2018-10-26T07:03:03Z")

</div>

I'm trying to activate multiline log parsing for Kubernetes, hopefully only on pods with a certain label. Where's the right place in the daemonset bundle yaml to set this?

---

## [Metricbeat service stops on CentOS](https://discuss.elastic.co/t/metricbeat-service-stops-on-centos/154021)

<div class="topic-metadata">

**Author:** [@carlosMitratech](https://discuss.elastic.co/u/carlosMitratech)\
**Replies:** 1\
**Last updated:** [October 25, 2018, 10:56pm UTC](https://discuss.elastic.co/t/metricbeat-service-stops-on-centos/154021 "2018-10-25T22:56:03Z")

</div>

We have metricbeat installed on a CentOS server, it works good during 4 hours, but after that, the service just stops and no more data is sent to ElastiSearch. We are using the same configuration and template (system) on…

---

## [Filebeat docker input: Error getting container info: \<nil\>](https://discuss.elastic.co/t/filebeat-docker-input-error-getting-container-info-nil/153878)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 3\
**Last updated:** [October 25, 2018, 9:20pm UTC](https://discuss.elastic.co/t/filebeat-docker-input-error-getting-container-info-nil/153878 "2018-10-25T21:20:37Z")

</div>

Hi, Running filebeat 6.3.2 with "- add\_docker\_metadata" set, and periodically see this in the logs: ERROR docker/watcher.go:233 Error getting container info: \<nil\> Can you please provide some information as to what ma…

---

## [DNS bursts when elasticsearch become unreachable](https://discuss.elastic.co/t/dns-bursts-when-elasticsearch-become-unreachable/153791)

<div class="topic-metadata">

**Author:** [@caub](https://discuss.elastic.co/u/caub)\
**Replies:** 3\
**Last updated:** [October 25, 2018, 6:42pm UTC](https://discuss.elastic.co/t/dns-bursts-when-elasticsearch-become-unreachable/153791 "2018-10-25T18:42:45Z")

</div>

Hi, I'm having very very frequent DNS requests when filebeat can't reach elasticsearch This happens in a docker swarm (ran on on google-cloud compute), when one manager node (running elasticsearch) is restarted, then o…

---

## [Filebeat not sending single line include\_lines until multiline is added to the configuration, then removed and service is restarted](https://discuss.elastic.co/t/filebeat-not-sending-single-line-include-lines-until-multiline-is-added-to-the-configuration-then-removed-and-service-is-restarted/153463)

<div class="topic-metadata">

**Author:** [@mattsdevop](https://discuss.elastic.co/u/mattsdevop)\
**Replies:** 2\
**Last updated:** [October 25, 2018, 7:12pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-single-line-include-lines-until-multiline-is-added-to-the-configuration-then-removed-and-service-is-restarted/153463 "2018-10-25T19:12:07Z")

</div>

I am facing what appears to be a bug, but wanted to bring it here first in order to confirm this before filing a bug report on github. Overview: I have a filebeat.yml that includes multiline and single line log type sec…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=408)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=410)
