# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=41

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 42

---

## [Doc Size Limits](https://discuss.elastic.co/t/doc-size-limits/340737)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 9:58am UTC](https://discuss.elastic.co/t/doc-size-limits/340737 "2023-08-14T09:58:53Z")

</div>

Hi, Can I ask, does fb impose any default doc size limits? We're getting occasional reports of the beginning of message fields being truncated even though we're using combine\_partial on the docker input. The version of …

---

## [Awslog driver docker](https://discuss.elastic.co/t/awslog-driver-docker/340723)

<div class="topic-metadata">

**Author:** [@Ryan5](https://discuss.elastic.co/u/Ryan5)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 8:42am UTC](https://discuss.elastic.co/t/awslog-driver-docker/340723 "2023-08-14T08:42:30Z")

</div>

We are using AWS ECS EC2 with the awslog docker driver however, the issue is that the awslog driver outputs a binary file with all the .json log lines beginning with stderr and some unicode. Beats seems to crash when the…

---

## [Grok pattern failing for apache custom logs](https://discuss.elastic.co/t/grok-pattern-failing-for-apache-custom-logs/340529)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 7\
**Last updated:** [August 14, 2023, 6:24am UTC](https://discuss.elastic.co/t/grok-pattern-failing-for-apache-custom-logs/340529 "2023-08-14T06:24:28Z")

</div>

i am facing issue for my grok is failing for the apache custom logs as beolw 10.52.245.67 - - \[12/Jul/2023:08:08:51 +0800\] uibau1a "GET /login/runtime.6b0e772316ccb94a9291.js HTTP/1.1" 200 2289bytes "10.168.224.18, 10.5…

---

## [\[Filebeat\]\[httpconf\] AuthenticationMissingOrInvalid](https://discuss.elastic.co/t/filebeat-httpconf-authenticationmissingorinvalid/340269)

<div class="topic-metadata">

**Author:** [@Mohammed\_Amine\_El\_ha](https://discuss.elastic.co/u/Mohammed_Amine_El_ha)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:35pm UTC](https://discuss.elastic.co/t/filebeat-httpconf-authenticationmissingorinvalid/340269 "2023-08-11T18:35:36Z")

</div>

Hi, I need to get logs from a rest API, I tried this config in My filebeat.yml: filebeat.inputs: type: httpjson request.url: ---------------------------------- request.transforms: set: target: header.Authorizatio…

---

## [Is it possible to develop a custom plugin for Filebeat](https://discuss.elastic.co/t/is-it-possible-to-develop-a-custom-plugin-for-filebeat/339952)

<div class="topic-metadata">

**Author:** [@uday22](https://discuss.elastic.co/u/uday22)\
**Replies:** 4\
**Last updated:** [August 11, 2023, 4:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-develop-a-custom-plugin-for-filebeat/339952 "2023-08-11T16:11:03Z")

</div>

Hi, I want to develop a custom plugin for filebeat, where the sensitive information in log files are encrypted. Finding sensitive information can be done by regular expression. I want to know weather the above requireme…

---

## [Winlogbeat ForwardedEvents channels filtering](https://discuss.elastic.co/t/winlogbeat-forwardedevents-channels-filtering/340626)

<div class="topic-metadata">

**Author:** [@stanley783](https://discuss.elastic.co/u/stanley783)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 12:21pm UTC](https://discuss.elastic.co/t/winlogbeat-forwardedevents-channels-filtering/340626 "2023-08-11T12:21:40Z")

</div>

Hi, we have servers forwarding various log channels (System, Security, Powershell..., Defender..) to WEC server via standard WEF service. Installed Winlogbeat on WEC server to forward those logs to ELK. However, we want…

---

## [Auditbeat failed to load rules on aarch64/ARM 64 bits](https://discuss.elastic.co/t/auditbeat-failed-to-load-rules-on-aarch64-arm-64-bits/340612)

<div class="topic-metadata">

**Author:** [@albertchen](https://discuss.elastic.co/u/albertchen)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:47am UTC](https://discuss.elastic.co/t/auditbeat-failed-to-load-rules-on-aarch64-arm-64-bits/340612 "2023-08-11T05:47:56Z")

</div>

Hi sir, When I try to load the following rules on aarch64 platform (ARM 64 bits) -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open\_by\_handle\_at -F exit=-EACCES -k access -a always,exit -F arch=b64…

---

## [Filebeat mssql module multiple drive paths in var.paths config](https://discuss.elastic.co/t/filebeat-mssql-module-multiple-drive-paths-in-var-paths-config/340554)

<div class="topic-metadata">

**Author:** [@Craig\_Sharp](https://discuss.elastic.co/u/Craig_Sharp)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:56am UTC](https://discuss.elastic.co/t/filebeat-mssql-module-multiple-drive-paths-in-var-paths-config/340554 "2023-08-11T06:56:39Z")

</div>

I am ingesting mssql logs from a failover cluster. Due to the nature of the cluster each node has a different mount / drive letter for the log data. The cluster may have M:, N:, O: P:, etc. but only one per node. This ma…

---

## ["Parse line error: parsing docker timestamp: parsing time \\"\\" as \\"2006-01-02T15:04:05Z07:00\\": cannot parse \\"\\" as \\"2006\\"","service.name":"filebeat","ecs.version":"1.6.0"}](https://discuss.elastic.co/t/parse-line-error-parsing-docker-timestamp-parsing-time-as-2006-01-02t1505z07-00-cannot-parse-as-2006-service-name-filebeat-ecs-version-1-6-0/338920)

<div class="topic-metadata">

**Author:** [@dell2](https://discuss.elastic.co/u/dell2)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 5:09pm UTC](https://discuss.elastic.co/t/parse-line-error-parsing-docker-timestamp-parsing-time-as-2006-01-02t1505z07-00-cannot-parse-as-2006-service-name-filebeat-ecs-version-1-6-0/338920 "2023-08-10T17:09:19Z")

</div>

filebeat.autodiscover: providers: - type: kubernetes hints.enabled: true json.message\_key: message json.timestamp.key: timestamp json.keys\_under\_root: true …

---

## [Auditbeat authentications log](https://discuss.elastic.co/t/auditbeat-authentications-log/340535)

<div class="topic-metadata">

**Author:** [@lliadan](https://discuss.elastic.co/u/lliadan)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 9:40am UTC](https://discuss.elastic.co/t/auditbeat-authentications-log/340535 "2023-08-10T09:40:34Z")

</div>

Hello ! I'm trying to receive the authentication faillure and success from my devices but i'm having few complications.. From my windows devices, it's ok, i'm able to receive log out / in / failled , with winlogbeat b…

---

## [Source missing in filebeat logs](https://discuss.elastic.co/t/source-missing-in-filebeat-logs/340291)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 5\
**Last updated:** [August 10, 2023, 8:51am UTC](https://discuss.elastic.co/t/source-missing-in-filebeat-logs/340291 "2023-08-10T08:51:34Z")

</div>

Hi Team , I have set up the filebeat to send the custom logs to Elasticsearch cluster, But there is "Source" missing on logs when I see them in Filebeat. I am using filebeat-8.7.0-1.x86\_64 for sending the logs. is …

---

## [Difference in filebeat + ES performance](https://discuss.elastic.co/t/difference-in-filebeat-es-performance/340500)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:10am UTC](https://discuss.elastic.co/t/difference-in-filebeat-es-performance/340500 "2023-08-10T01:10:10Z")

</div>

Hi, I currently have 2 setups: Filebeat v8.3.3 + ES v8.3.3 different physical servers connected to the same subnet 3-node ES (each configured as master + data) Total of 90GB JVM heap Total of 18TB hard disk space (ru…

---

## [Filebeat output.kafka with SASL oauthbearer mecanism](https://discuss.elastic.co/t/filebeat-output-kafka-with-sasl-oauthbearer-mecanism/340474)

<div class="topic-metadata">

**Author:** [@chatim](https://discuss.elastic.co/u/chatim)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 3:09pm UTC](https://discuss.elastic.co/t/filebeat-output-kafka-with-sasl-oauthbearer-mecanism/340474 "2023-08-09T15:09:35Z")

</div>

Hello, i have a kafka cluster that use authentication with sasl oauthbearer mecanism (keycloak), i would like to know if filebeat support sasl/oauthbearer. I already found that it supports sasl/plain & sasl/scram, what…

---

## [Can Elastic Stack replace tools like zabbix?](https://discuss.elastic.co/t/can-elastic-stack-replace-tools-like-zabbix/340357)

<div class="topic-metadata">

**Author:** [@musialny](https://discuss.elastic.co/u/musialny)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 2:57pm UTC](https://discuss.elastic.co/t/can-elastic-stack-replace-tools-like-zabbix/340357 "2023-08-09T14:57:42Z")

</div>

Is Elasticsearch stack capable of distribute network monitoring?

---

## [Metricbeat not working on Docker desktop for windows](https://discuss.elastic.co/t/metricbeat-not-working-on-docker-desktop-for-windows/340459)

<div class="topic-metadata">

**Author:** [@BEIIKS](https://discuss.elastic.co/u/BEIIKS)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 12:56pm UTC](https://discuss.elastic.co/t/metricbeat-not-working-on-docker-desktop-for-windows/340459 "2023-08-09T12:56:09Z")

</div>

Hi there, my first issue here :smiley: Im a rookie in ELK, and today I try to use metricbeat to monitor my cpu, ram and etc... ofc that I work with docker desktop as its in development stage so, therefore I understand …

---

## [Using Fingerprint on metricbeat](https://discuss.elastic.co/t/using-fingerprint-on-metricbeat/339584)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 16\
**Last updated:** [August 9, 2023, 12:16am UTC](https://discuss.elastic.co/t/using-fingerprint-on-metricbeat/339584 "2023-08-09T00:16:12Z")

</div>

Hi there i'm trying to send data using metricbeat here v8.8.2 and i'm trying to use fingerprint as replacement of certificate\_authorities but i got an error like this {"log.level":"warn","@timestamp":"2023-07-29T07:26:…

---

## [If statement in winlogbeat configuration](https://discuss.elastic.co/t/if-statement-in-winlogbeat-configuration/340393)

<div class="topic-metadata">

**Author:** [@msylvestre](https://discuss.elastic.co/u/msylvestre)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 6:44pm UTC](https://discuss.elastic.co/t/if-statement-in-winlogbeat-configuration/340393 "2023-08-08T18:44:35Z")

</div>

Hello, I'm trying to add an IF statement in my winlogbeat configuration, but I can't figure out how. Basically I have a field named token that I need to changed based on the agent\_name. What am I missing? #############…

---

## [What is difference between Elastic Agent and Beat?](https://discuss.elastic.co/t/what-is-difference-between-elastic-agent-and-beat/340383)

<div class="topic-metadata">

**Author:** [@musialny](https://discuss.elastic.co/u/musialny)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 3:28pm UTC](https://discuss.elastic.co/t/what-is-difference-between-elastic-agent-and-beat/340383 "2023-08-08T15:28:51Z")

</div>

What is difference between Elastic Agent and Beat?

---

## [Run\_from config](https://discuss.elastic.co/t/run-from-config/340378)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 2:38pm UTC](https://discuss.elastic.co/t/run-from-config/340378 "2023-08-08T14:38:19Z")

</div>

Simple question here, if I have 10 different monitors setup on a single agent, do I have to duplicate the run\_from section (example below) and specify the id for each of them, or if I exclude the id field, will the run\_f…

---

## [ESXI to ELK](https://discuss.elastic.co/t/esxi-to-elk/340366)

<div class="topic-metadata">

**Author:** [@lliadan](https://discuss.elastic.co/u/lliadan)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:06pm UTC](https://discuss.elastic.co/t/esxi-to-elk/340366 "2023-08-08T12:06:04Z")

</div>

Hi ! I'm setting up an ELK server in my company to receive connection logs. My server is ready and operational. I still have one machine to do, but I confess I'm stuck. I need to get the logs from the ESXI server, and…

---

## [Send custom logs to elasticsearch with predefined list of fields](https://discuss.elastic.co/t/send-custom-logs-to-elasticsearch-with-predefined-list-of-fields/338681)

<div class="topic-metadata">

**Author:** [@Johannnnnn](https://discuss.elastic.co/u/Johannnnnn)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 8:43am UTC](https://discuss.elastic.co/t/send-custom-logs-to-elasticsearch-with-predefined-list-of-fields/338681 "2023-08-08T08:43:40Z")

</div>

Disclaimer: I am very confused about filebeat help files. If I need anything more technical than sending a log line to elasticsearch, it does not explain anything. It just states options and leaves me to find out which o…

---

## [Filebeat in docker, permission denied when trying to place registry on the host](https://discuss.elastic.co/t/filebeat-in-docker-permission-denied-when-trying-to-place-registry-on-the-host/339694)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 7:59am UTC](https://discuss.elastic.co/t/filebeat-in-docker-permission-denied-when-trying-to-place-registry-on-the-host/339694 "2023-08-08T07:59:55Z")

</div>

I would like to move the registry outside the filebeat folder, to be able to easy kill it. I have this config file: filebeat\_for\_dmarc: image: docker.elastic.co/beats/filebeat:${STACK\_VERSION} container\_name:…

---

## [Metricbeat docker.network\_summary does not work from within a container?](https://discuss.elastic.co/t/metricbeat-docker-network-summary-does-not-work-from-within-a-container/339226)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 3:33pm UTC](https://discuss.elastic.co/t/metricbeat-docker-network-summary-does-not-work-from-within-a-container/339226 "2023-08-07T15:33:49Z")

</div>

So, judging from this error I've been getting today: lanewell-metricbeat-app | {"log.level":"error","@timestamp":"2023-07-25T20:06:51.398Z","log.origin":{"file.name":"module/wrapper.go","file.line":263},"message":"Erro…

---

## [Multiline regexp](https://discuss.elastic.co/t/multiline-regexp/340257)

<div class="topic-metadata">

**Author:** [@Drewolf](https://discuss.elastic.co/u/Drewolf)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 10:41am UTC](https://discuss.elastic.co/t/multiline-regexp/340257 "2023-08-07T10:41:35Z")

</div>

background I want to write a regular expression that matches the line which contain "Exception" and does not contain "DebugModeException". In the following example, the first line contains "DebugModeException" and doe…

---

## [Runtime/cgo: pthread\_create failed: Operation not permitted SIGABRT: abort PC=0x7f46dd713a7c m=2 sigcode=18446744073709551610](https://discuss.elastic.co/t/runtime-cgo-pthread-create-failed-operation-not-permitted-sigabrt-abort-pc-0x7f46dd713a7c-m-2-sigcode-18446744073709551610/340253)

<div class="topic-metadata">

**Author:** [@linxx](https://discuss.elastic.co/u/linxx)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 10:11am UTC](https://discuss.elastic.co/t/runtime-cgo-pthread-create-failed-operation-not-permitted-sigabrt-abort-pc-0x7f46dd713a7c-m-2-sigcode-18446744073709551610/340253 "2023-08-07T10:11:06Z")

</div>

linxx@ubuntu:~/module/filebeat-6.8.13-linux-x86\_64$ ./filebeat -e 2023-08-07T11:29:18.205+0800 INFO instance/beat.go:611 Home path: \[/home/linxx/module/filebeat-6.8.13-linux-x86\_64\] Config path: \[/home/linxx/mo…

---

## [Filebeat processors drop\_fields has no effect](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213)

<div class="topic-metadata">

**Author:** [@Drewolf](https://discuss.elastic.co/u/Drewolf)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 3:14am UTC](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213 "2023-08-07T03:14:00Z")

</div>

background this processors can not drop field "agent\_name" my filebeat config filebeat.inputs: - type: container paths: # - /var/log/containers/xgimi-launcher\*.log - /var/log/containers/\*.log processor…

---

## [Issue with metricbeat kibana module when using custom path for Kibana](https://discuss.elastic.co/t/issue-with-metricbeat-kibana-module-when-using-custom-path-for-kibana/338976)

<div class="topic-metadata">

**Author:** [@Pierig\_Le\_Saux](https://discuss.elastic.co/u/Pierig_Le_Saux)\
**Replies:** 4\
**Last updated:** [August 5, 2023, 1:30am UTC](https://discuss.elastic.co/t/issue-with-metricbeat-kibana-module-when-using-custom-path-for-kibana/338976 "2023-08-05T01:30:47Z")

</div>

My kibana setup uses SERVER\_PUBLICBASEURL = http://www.example.com/kibana SERVER\_BASEPATH = /kibana SERVER\_REWRITEBASEPATH = "true" My metricbeat autodiscovery for the kibana module uses: - condition: contains: …

---

## [Data is redundant in filebeat system module](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096)

<div class="topic-metadata">

**Author:** [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 5:18pm UTC](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096 "2023-08-04T17:18:07Z")

</div>

Hi, i indexed linux secure log via filebeat system module. And the user.name field is duplicated. Most user.name has two versions. The version that start with a blank and the other version that doesn't. There a…

---

## [Double Quotes being truncated](https://discuss.elastic.co/t/double-quotes-being-truncated/340143)

<div class="topic-metadata">

**Author:** [@tech7857](https://discuss.elastic.co/u/tech7857)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 2:41pm UTC](https://discuss.elastic.co/t/double-quotes-being-truncated/340143 "2023-08-04T14:41:02Z")

</div>

Hi We are shipping all our K8s logs to ELK. We noticed that double quotes are being truncated in ELK. Not sure what is the issue. Can you please guide us K8s logs "{\\r\\n \\"param1\\": true,\\r\\n \\"param2\\":…

---

## [Filebeat Index](https://discuss.elastic.co/t/filebeat-index/340008)

<div class="topic-metadata">

**Author:** [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Replies:** 4\
**Last updated:** [August 3, 2023, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-index/340008 "2023-08-03T14:33:38Z")

</div>

Hello, I have installed filebeat and uploaded a CSV to obtain the filebeat configuration for the installation, creating a new index and pipeline. the yml file looks like this: filebeat.inputs: - type: log paths: - C…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=40)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=42)
