# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=410

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 411

---

## [Multiline parser filebeat 6.4.2](https://discuss.elastic.co/t/multiline-parser-filebeat-6-4-2/153860)

<div class="topic-metadata">

**Author:** [@lukes](https://discuss.elastic.co/u/lukes)\
**Replies:** 4\
**Last updated:** [October 25, 2018, 6:47pm UTC](https://discuss.elastic.co/t/multiline-parser-filebeat-6-4-2/153860 "2018-10-25T18:47:44Z")

</div>

Hi there, I am trying to group multiple lines as a single event depending upon timestamp. I am using Filebeat --\> ElasticSearch --\> Kibana (NO Logstash in between).To begin with i started manipulating the existing plugi…

---

## [Repeated message](https://discuss.elastic.co/t/repeated-message/153737)

<div class="topic-metadata">

**Author:** [@herren\_marc](https://discuss.elastic.co/u/herren_marc)\
**Replies:** 2\
**Last updated:** [October 25, 2018, 6:28pm UTC](https://discuss.elastic.co/t/repeated-message/153737 "2018-10-25T18:28:31Z")

</div>

Hi, I have a simple filebeat configuration sending the output of a tomcat server to my logstash - type: log paths: - '/home/appserver/logs/catalina.out' tags: \[swtp\] multiline.pattern: '^\[\[:space:\]\]+(at|\\.{3…

---

## [POST /\_bulk: first path segment in URL cannot contain colon](https://discuss.elastic.co/t/post-bulk-first-path-segment-in-url-cannot-contain-colon/153242)

<div class="topic-metadata">

**Author:** [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Replies:** 1\
**Last updated:** [October 25, 2018, 4:24pm UTC](https://discuss.elastic.co/t/post-bulk-first-path-segment-in-url-cannot-contain-colon/153242 "2018-10-25T16:24:51Z")

</div>

Hi I deploy a packetbeat-6.4 and obeserve some warning log as follows: 2018-10-17T13:12:01.528+0800 WARN http/http.go:505 Fail to parse HTTP parameters: parse {"index":{"\_index":"packetbeat-6.4.2-2018.10.17","\_type":"d…

---

## [Packetbear drop event doesnt work](https://discuss.elastic.co/t/packetbear-drop-event-doesnt-work/152944)

<div class="topic-metadata">

**Author:** [@Sergey.k](https://discuss.elastic.co/u/Sergey.k)\
**Replies:** 1\
**Last updated:** [October 25, 2018, 2:30pm UTC](https://discuss.elastic.co/t/packetbear-drop-event-doesnt-work/152944 "2018-10-25T14:30:25Z")

</div>

packetbaet version 6.3 Packetbeat don't drop event when path field are equal the text "/application/some-text" packetbeat.yml: packetbeat.interfaces.device: any packetbeat.flows: enabled: false packetbeat.protocol…

---

## [Multiple Multline pattern option](https://discuss.elastic.co/t/multiple-multline-pattern-option/153783)

<div class="topic-metadata">

**Author:** [@osamaikhlas](https://discuss.elastic.co/u/osamaikhlas)\
**Replies:** 1\
**Last updated:** [October 25, 2018, 2:09pm UTC](https://discuss.elastic.co/t/multiple-multline-pattern-option/153783 "2018-10-25T14:09:57Z")

</div>

I have two types of logs one start with (Waiting for message) and other start from (Message Length Received) so how to use multiline pattern with (OR) function with below try i'm not getting any result multiline.pat…

---

## [Filebeat logrotation multiline data loss](https://discuss.elastic.co/t/filebeat-logrotation-multiline-data-loss/153629)

<div class="topic-metadata">

**Author:** [@PeterPloug](https://discuss.elastic.co/u/PeterPloug)\
**Replies:** 1\
**Last updated:** [October 25, 2018, 2:00pm UTC](https://discuss.elastic.co/t/filebeat-logrotation-multiline-data-loss/153629 "2018-10-25T14:00:11Z")

</div>

Hi All OS: red hat filebeat version: 6.4.2 First of I am very new to the entire ELK stack and I am trying to replace Heka with filebeat/logstash. I have an issue where log rotation is dividing a xml event across log …

---

## [How to deal with large number of files in a single directory](https://discuss.elastic.co/t/how-to-deal-with-large-number-of-files-in-a-single-directory/154008)

<div class="topic-metadata">

**Author:** [@Lihang\_Gong](https://discuss.elastic.co/u/Lihang_Gong)\
**Replies:** 2\
**Last updated:** [October 25, 2018, 1:45pm UTC](https://discuss.elastic.co/t/how-to-deal-with-large-number-of-files-in-a-single-directory/154008 "2018-10-25T13:45:36Z")

</div>

Filebeat scans the whole directory to get files which needs to be collected. But when there is a large number of files in the directory, filebeat creates multiple goroutines to collect files causing high I/O wait. Can a…

---

## [How about Sflow support](https://discuss.elastic.co/t/how-about-sflow-support/153222)

<div class="topic-metadata">

**Author:** [@charlesrg](https://discuss.elastic.co/u/charlesrg)\
**Replies:** 2\
**Last updated:** [October 25, 2018, 11:23am UTC](https://discuss.elastic.co/t/how-about-sflow-support/153222 "2018-10-25T11:23:26Z")

</div>

To get data straight from network devices PacketBeat could support SFLOW. It's open and some more info here: https://sflow.org/sFlowOverview.pdf This way I could configure our routers/switches to send flows straight to…

---

## [Filebeat autodiscover: When running on windows filebeat can not be started](https://discuss.elastic.co/t/filebeat-autodiscover-when-running-on-windows-filebeat-can-not-be-started/153801)

<div class="topic-metadata">

**Author:** [@Maxim\_Ozerov](https://discuss.elastic.co/u/Maxim_Ozerov)\
**Replies:** 1\
**Last updated:** [October 25, 2018, 11:19am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-when-running-on-windows-filebeat-can-not-be-started/153801 "2018-10-25T11:19:22Z")

</div>

On windows when adding configuration for autodiscover filebeat can not be started and there is the following error appears: Exiting: error in autodiscover provider settings: error during connect: Get http://%2Fvar%2Frun…

---

## [Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/153470)

<div class="topic-metadata">

**Author:** [@Suat\_Bey](https://discuss.elastic.co/u/Suat_Bey)\
**Replies:** 7\
**Last updated:** [October 25, 2018, 11:04am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/153470 "2018-10-25T11:04:05Z")

</div>

Hi, I have installed ELK just now. And I am trying to get the log file from my ELK machine. Kibana,Elastic and logstash works fine. But , somehow I am not able to get logs using filebeats. "Failed to start Filebeat sen…

---

## [RegEx / RegExp NOT Condition Help](https://discuss.elastic.co/t/regex-regexp-not-condition-help/153588)

<div class="topic-metadata">

**Author:** [@Phil\_Halford](https://discuss.elastic.co/u/Phil_Halford)\
**Replies:** 1\
**Last updated:** [October 25, 2018, 8:17am UTC](https://discuss.elastic.co/t/regex-regexp-not-condition-help/153588 "2018-10-25T08:17:52Z")

</div>

Hi everyone, I'm struggling to figure this out having spent many hours looking at it. Essentially, I have a winlogbeat.yml configuration to drop multiple events. This has been working fine for months. I wanted to add an…

---

## [Multiple conditions with autodiscover & docker containers](https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634)

<div class="topic-metadata">

**Author:** [@vieskees](https://discuss.elastic.co/u/vieskees)\
**Replies:** 2\
**Last updated:** [October 25, 2018, 8:09am UTC](https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634 "2018-10-25T08:09:59Z")

</div>

Hi! I've just set up our ELK stack and I'm struggling with selecting the right containers for the autodiscover setting. I have a application consisting of around 20+ different containers. And around 10 of these containe…

---

## [Exiting: Could not start registrar: Error loading state: open /filebeat/data/registry: permission denied](https://discuss.elastic.co/t/exiting-could-not-start-registrar-error-loading-state-open-filebeat-data-registry-permission-denied/153349)

<div class="topic-metadata">

**Author:** [@sebastiaanspeck](https://discuss.elastic.co/u/sebastiaanspeck)\
**Replies:** 3\
**Last updated:** [October 24, 2018, 6:45pm UTC](https://discuss.elastic.co/t/exiting-could-not-start-registrar-error-loading-state-open-filebeat-data-registry-permission-denied/153349 "2018-10-24T18:45:00Z")

</div>

When running /filebeat --setup -e It exits with the next error: 2018-10-22T10:19:29.306+0200 ERROR instance/beat.go:743 Exiting: Could not start registrar: Error loading state: open /filebeat/data/registry: permission …

---

## [Filebeat Processors: Rename does not work](https://discuss.elastic.co/t/filebeat-processors-rename-does-not-work/153163)

<div class="topic-metadata">

**Author:** [@rhino](https://discuss.elastic.co/u/rhino)\
**Replies:** 3\
**Last updated:** [October 24, 2018, 6:41pm UTC](https://discuss.elastic.co/t/filebeat-processors-rename-does-not-work/153163 "2018-10-24T18:41:47Z")

</div>

Hello Community! I want to delete and rename some fields in filebeat with following configurations: processors: - rename: fields: - from: "beat.hostname" to: "host" - drop\_fields: fields: \["beat.name", "beat.ver…

---

## [Filebeat 6.4.2 not sending JSON file](https://discuss.elastic.co/t/filebeat-6-4-2-not-sending-json-file/153859)

<div class="topic-metadata">

**Author:** [@Rolf\_Nufable](https://discuss.elastic.co/u/Rolf_Nufable)\
**Replies:** 0\
**Last updated:** [October 24, 2018, 6:05pm UTC](https://discuss.elastic.co/t/filebeat-6-4-2-not-sending-json-file/153859 "2018-10-24T18:05:45Z")

</div>

Greetings to all, Hi I'm fairly new to ELK and BEATS and I have little success in configurations regarding sending logs to logstash. My problem for now is that filebeat 6.4.2 cannot start whenever I add the Json decodi…

---

## [\[Filebeat\] Windows: add\_docker\_metadata cannot extract Container ID](https://discuss.elastic.co/t/filebeat-windows-add-docker-metadata-cannot-extract-container-id/153830)

<div class="topic-metadata">

**Author:** [@numilex](https://discuss.elastic.co/u/numilex)\
**Replies:** 0\
**Last updated:** [October 24, 2018, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-windows-add-docker-metadata-cannot-extract-container-id/153830 "2018-10-24T14:33:35Z")

</div>

Hi, I'm trying to get FIlebeat to send Docker metadata with logs. Filebeat starts up fine and sends logs correctly, only without Docker metadata. My filebeat.yml looks like this: filebeat.inputs: - type: log …

---

## [Filebeat log path](https://discuss.elastic.co/t/filebeat-log-path/153796)

<div class="topic-metadata">

**Author:** [@motamedi791](https://discuss.elastic.co/u/motamedi791)\
**Replies:** 0\
**Last updated:** [October 24, 2018, 12:34pm UTC](https://discuss.elastic.co/t/filebeat-log-path/153796 "2018-10-24T12:34:36Z")

</div>

My logs are in multiple nested directories as like: /var/log/dir1/dir2/file.log /var/log/dir3/dir4/dir5//file.log ... It there is way to define a dir-based wildcard path in my filebeat.yml as: /var/log/\*\*/\*.log So t…

---

## [Filebeat windows service not starting](https://discuss.elastic.co/t/filebeat-windows-service-not-starting/152475)

<div class="topic-metadata">

**Author:** [@sthambir](https://discuss.elastic.co/u/sthambir)\
**Replies:** 8\
**Last updated:** [October 24, 2018, 10:53am UTC](https://discuss.elastic.co/t/filebeat-windows-service-not-starting/152475 "2018-10-24T10:53:43Z")

</div>

Hi, I can run filebeat on foreground and send logs to logstash (both version 6.3). However, it wouldn't start as a windows service. Logstash successfully runs as a windows service. If I use 'Start-Service' command for …

---

## [Filebeat sending multiple lines as one event](https://discuss.elastic.co/t/filebeat-sending-multiple-lines-as-one-event/153738)

<div class="topic-metadata">

**Author:** [@CyberSeppi](https://discuss.elastic.co/u/CyberSeppi)\
**Replies:** 2\
**Last updated:** [October 24, 2018, 8:03am UTC](https://discuss.elastic.co/t/filebeat-sending-multiple-lines-as-one-event/153738 "2018-10-24T08:03:13Z")

</div>

Hi there, I´m sending apache access logs to elasticsearch using filebeat -\> logstash. The configuration is like that filebeat.yml filebeat.prospectors: filebeat.config.inputs: enabled: true path: conf.d/\*.yml re…

---

## [Custom filebeat module](https://discuss.elastic.co/t/custom-filebeat-module/149797)

<div class="topic-metadata">

**Author:** [@mraz1337](https://discuss.elastic.co/u/mraz1337)\
**Replies:** 5\
**Last updated:** [October 24, 2018, 8:00am UTC](https://discuss.elastic.co/t/custom-filebeat-module/149797 "2018-10-24T08:00:01Z")

</div>

Filebeat configuration supports multiple inputs, how can be this achived with custom module config.yml ? I would like to tag single path with the unique value. type: log paths: - C:/Logs1/\*/\*.log -\> tag1 - C:/Logs…

---

## [Beats on Client side Machine](https://discuss.elastic.co/t/beats-on-client-side-machine/153618)

<div class="topic-metadata">

**Author:** [@somu\_p](https://discuss.elastic.co/u/somu_p)\
**Replies:** 1\
**Last updated:** [October 24, 2018, 6:16am UTC](https://discuss.elastic.co/t/beats-on-client-side-machine/153618 "2018-10-24T06:16:28Z")

</div>

i am new to ES i would like to monitor 100000 endpoint with Metric Beats. Can you please help me with below question: Can i monitor 100000 system with beats. is it possible? can i store those data to Elastic search, s…

---

## [Winlogbeat output to Logstash connection is ERROR](https://discuss.elastic.co/t/winlogbeat-output-to-logstash-connection-is-error/153708)

<div class="topic-metadata">

**Author:** [@sordager](https://discuss.elastic.co/u/sordager)\
**Replies:** 0\
**Last updated:** [October 24, 2018, 4:49am UTC](https://discuss.elastic.co/t/winlogbeat-output-to-logstash-connection-is-error/153708 "2018-10-24T04:49:18Z")

</div>

Hello. When I sent the Event Log to Logstash 6.4 using winlogbeat 6.4, it was found that the connection was wrong. However, it is normal to send Log to Logstash using filebeats on the same computer. The Logstash confi…

---

## [Host Metrics not captured for centos7](https://discuss.elastic.co/t/host-metrics-not-captured-for-centos7/152875)

<div class="topic-metadata">

**Author:** [@Jas\_Ahluwalia](https://discuss.elastic.co/u/Jas_Ahluwalia)\
**Replies:** 9\
**Last updated:** [October 23, 2018, 10:48pm UTC](https://discuss.elastic.co/t/host-metrics-not-captured-for-centos7/152875 "2018-10-23T22:48:31Z")

</div>

Hi, I'm running metricbeat in a docker container. I'm unable to see the host's metrics in the dashboard (e.g. cpu usage, memory, etc.). Below is what i have in my docker compose file in terms of volume mounts and flags…

---

## [Ignore registry after a reboot](https://discuss.elastic.co/t/ignore-registry-after-a-reboot/153472)

<div class="topic-metadata">

**Author:** [@sajjad](https://discuss.elastic.co/u/sajjad)\
**Replies:** 2\
**Last updated:** [October 23, 2018, 7:26pm UTC](https://discuss.elastic.co/t/ignore-registry-after-a-reboot/153472 "2018-10-23T19:26:55Z")

</div>

I am running Filebeat 6.2.2 on a bunch of systems to forward to Logstash and facing an issue when one of them has a problem and reboots. After the reboot, Filebeat ingests all the logs and eats up system resources, while…

---

## [Combining all beats into a single Docker image](https://discuss.elastic.co/t/combining-all-beats-into-a-single-docker-image/153668)

<div class="topic-metadata">

**Author:** [@mhickok](https://discuss.elastic.co/u/mhickok)\
**Replies:** 0\
**Last updated:** [October 23, 2018, 6:58pm UTC](https://discuss.elastic.co/t/combining-all-beats-into-a-single-docker-image/153668 "2018-10-23T18:58:32Z")

</div>

Hello all, this is more of a Docker-related question that Beats, but I thought I would see if anyone else tried to do this. I want my beats image to be as close to the official image as possible, but I want to have all …

---

## [Creating beats from Metricbeat - inherit modules?](https://discuss.elastic.co/t/creating-beats-from-metricbeat-inherit-modules/153654)

<div class="topic-metadata">

**Author:** [@Grigory\_Shamov](https://discuss.elastic.co/u/Grigory_Shamov)\
**Replies:** 0\
**Last updated:** [October 23, 2018, 5:10pm UTC](https://discuss.elastic.co/t/creating-beats-from-metricbeat-inherit-modules/153654 "2018-10-23T17:10:46Z")

</div>

Hi, When one creates Metricbeat-based beats, as described here: https://www.elastic.co/guide/en/beats/devguide/current/creating-beat-from-metricbeat.html it would create an empty Metricbeat with no modules, and then a…

---

## [How to start winlogbeat automatically](https://discuss.elastic.co/t/how-to-start-winlogbeat-automatically/153648)

<div class="topic-metadata">

**Author:** [@saad](https://discuss.elastic.co/u/saad)\
**Replies:** 1\
**Last updated:** [October 23, 2018, 4:53pm UTC](https://discuss.elastic.co/t/how-to-start-winlogbeat-automatically/153648 "2018-10-23T16:53:53Z")

</div>

How to start Winlogbeat automatically when server restart?

---

## [Metricbeat parse docker image labels error](https://discuss.elastic.co/t/metricbeat-parse-docker-image-labels-error/152986)

<div class="topic-metadata">

**Author:** [@Jun\_Zhang](https://discuss.elastic.co/u/Jun_Zhang)\
**Replies:** 2\
**Last updated:** [October 23, 2018, 2:51pm UTC](https://discuss.elastic.co/t/metricbeat-parse-docker-image-labels-error/152986 "2018-10-23T14:51:06Z")

</div>

metricbeat parses "docker.image.labels" error，should be 5 labels： { "\_index": "metricbeat-power-6.4.1-2018.10.18", "\_type": "doc", "\_id": "yD3PhmYBo726M9O3TIlB", "\_version": 1, "\_score": null, "\_source": { …

---

## [Filesystem metricset of metricbeat (running in docker ) system module can't get host filesystem statistics](https://discuss.elastic.co/t/filesystem-metricset-of-metricbeat-running-in-docker-system-module-cant-get-host-filesystem-statistics/152987)

<div class="topic-metadata">

**Author:** [@Jun\_Zhang](https://discuss.elastic.co/u/Jun_Zhang)\
**Replies:** 2\
**Last updated:** [October 23, 2018, 2:48pm UTC](https://discuss.elastic.co/t/filesystem-metricset-of-metricbeat-running-in-docker-system-module-cant-get-host-filesystem-statistics/152987 "2018-10-23T14:48:53Z")

</div>

My metcibeat yaml is following： apiVersion: extensions/v1beta1 kind: DaemonSet metadata: name: metricbeat namespace: metricbeat labels: k8s-app: metricbeat spec: template: metadata: labels: …

---

## [How to import bundled index pattern and Kibana dashboard from beats 6.3.0 using basic auth?](https://discuss.elastic.co/t/how-to-import-bundled-index-pattern-and-kibana-dashboard-from-beats-6-3-0-using-basic-auth/153592)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 0\
**Last updated:** [October 23, 2018, 12:12pm UTC](https://discuss.elastic.co/t/how-to-import-bundled-index-pattern-and-kibana-dashboard-from-beats-6-3-0-using-basic-auth/153592 "2018-10-23T12:12:21Z")

</div>

Hi, I am using ELK GA 6.3.0. I am trying to import bundled dashboard and index pattern from Heartbeat. I have set basic auth in my elasticsearch, and I am trying out the below command; ./heartbeat setup --dashboards --…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=409)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=411)
