# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=411

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 412

---

## [Multiple FileBeats](https://discuss.elastic.co/t/multiple-filebeats/153114)

<div class="topic-metadata">

**Author:** [@Carlos\_Magalhaes](https://discuss.elastic.co/u/Carlos_Magalhaes)\
**Replies:** 6\
**Last updated:** [October 23, 2018, 10:30am UTC](https://discuss.elastic.co/t/multiple-filebeats/153114 "2018-10-23T10:30:49Z")

</div>

Hi all, Apologies if this is a really dumb question, but been reading so much think I am getting myself confused. I have a filebeat agent running on a machine and its reporting back to my ELK stack server. When I had a…

---

## [Send only filenames to Logstash](https://discuss.elastic.co/t/send-only-filenames-to-logstash/153425)

<div class="topic-metadata">

**Author:** [@celerinsights](https://discuss.elastic.co/u/celerinsights)\
**Replies:** 1\
**Last updated:** [October 23, 2018, 10:00am UTC](https://discuss.elastic.co/t/send-only-filenames-to-logstash/153425 "2018-10-23T10:00:09Z")

</div>

Is it possible to only send the source filenames to logstash from filebeat? Thanks.

---

## [Help me to setup up Filebeat in AIX Server](https://discuss.elastic.co/t/help-me-to-setup-up-filebeat-in-aix-server/153567)

<div class="topic-metadata">

**Author:** [@jahaber\_sadhik](https://discuss.elastic.co/u/jahaber_sadhik)\
**Replies:** 1\
**Last updated:** [October 23, 2018, 9:58am UTC](https://discuss.elastic.co/t/help-me-to-setup-up-filebeat-in-aix-server/153567 "2018-10-23T09:58:30Z")

</div>

Hi, Am new to ELK. I would like to install Filebeat in AIX servers.. Any one guide me Thanks Sadhik

---

## [Rsyslog vs Filbeat (or Logstash)?](https://discuss.elastic.co/t/rsyslog-vs-filbeat-or-logstash/153535)

<div class="topic-metadata">

**Author:** [@af615dbd55cac2cacf32](https://discuss.elastic.co/u/af615dbd55cac2cacf32)\
**Replies:** 0\
**Last updated:** [October 23, 2018, 7:31am UTC](https://discuss.elastic.co/t/rsyslog-vs-filbeat-or-logstash/153535 "2018-10-23T07:31:57Z")

</div>

Hello, I am wondering what product is better for less system resource usage and service stability. As you see below, there are SYSLOG generators and Rsyslogd. Rsyslog receives the logs from multiple source generators (…

---

## [MetricBeat only sending node\* stats to monitoring cluster](https://discuss.elastic.co/t/metricbeat-only-sending-node-stats-to-monitoring-cluster/151645)

<div class="topic-metadata">

**Author:** [@napsterX](https://discuss.elastic.co/u/napsterX)\
**Replies:** 2\
**Last updated:** [October 23, 2018, 7:35am UTC](https://discuss.elastic.co/t/metricbeat-only-sending-node-stats-to-monitoring-cluster/151645 "2018-10-23T07:35:16Z")

</div>

Hi, Below is my Elasticsearch Beat module config: module: elasticsearch metricsets: cluster\_stats index index\_recovery index\_summary node node\_stats pending\_tasks shard period: 10s hosts: \["localhost:9200"\] B…

---

## [Metricsbeat on docker swarm: how to monitor host/system stats?](https://discuss.elastic.co/t/metricsbeat-on-docker-swarm-how-to-monitor-host-system-stats/153297)

<div class="topic-metadata">

**Author:** [@gianpietro](https://discuss.elastic.co/u/gianpietro)\
**Replies:** 3\
**Last updated:** [October 22, 2018, 9:32pm UTC](https://discuss.elastic.co/t/metricsbeat-on-docker-swarm-how-to-monitor-host-system-stats/153297 "2018-10-22T21:32:48Z")

</div>

Hi, The relevant section of my docker compose file looks like this: user: root deploy: mode: global volumes: - /proc:/hostfs/proc:ro - /sys/fs/cgroup:/hostfs/sys/fs/cgroup:ro - /:/hostfs:ro - ./metricbeat.yml…

---

## [Is this config good ? Especially the regex one](https://discuss.elastic.co/t/is-this-config-good-especially-the-regex-one/153382)

<div class="topic-metadata">

**Author:** [@merceskoba](https://discuss.elastic.co/u/merceskoba)\
**Replies:** 2\
**Last updated:** [October 22, 2018, 3:48pm UTC](https://discuss.elastic.co/t/is-this-config-good-especially-the-regex-one/153382 "2018-10-22T15:48:27Z")

</div>

Hello dears, I have a filebeat config as filebeat.yml Could you take a look on it and check if there is a mistake or not. Because, my filebeat is running correctly but when i check in Graylog2 web ui, i still find the…

---

## [Auditbeat - Retrieve account of the user that performed the action](https://discuss.elastic.co/t/auditbeat-retrieve-account-of-the-user-that-performed-the-action/153428)

<div class="topic-metadata">

**Author:** [@lucas.alvarez](https://discuss.elastic.co/u/lucas.alvarez)\
**Replies:** 0\
**Last updated:** [October 22, 2018, 3:06pm UTC](https://discuss.elastic.co/t/auditbeat-retrieve-account-of-the-user-that-performed-the-action/153428 "2018-10-22T15:06:49Z")

</div>

Hello everybody!. I would like to know if there's a way in Auditbeat to retrieve the username that performed the action on the file. So far you can get the file owner, but there's no information about who performed that…

---

## [Add environment variables on filebeat start](https://discuss.elastic.co/t/add-environment-variables-on-filebeat-start/152855)

<div class="topic-metadata">

**Author:** [@leslie](https://discuss.elastic.co/u/leslie)\
**Replies:** 5\
**Last updated:** [October 22, 2018, 2:53pm UTC](https://discuss.elastic.co/t/add-environment-variables-on-filebeat-start/152855 "2018-10-22T14:53:11Z")

</div>

i am using filebeat 6.0.0 which without add\_host\_metadata processor; and my os is Windows. now i hope to add an IP field to the filebeat result of all modules, but i don't want to set an Environment Variable globally. D…

---

## [Help with exclude\_files](https://discuss.elastic.co/t/help-with-exclude-files/153175)

<div class="topic-metadata">

**Author:** [@sbampa](https://discuss.elastic.co/u/sbampa)\
**Replies:** 1\
**Last updated:** [October 22, 2018, 1:52pm UTC](https://discuss.elastic.co/t/help-with-exclude-files/153175 "2018-10-22T13:52:19Z")

</div>

Hi all, i need to exclude some files from the filebeat read. Files look like as: \*\_log\*.echo how can i match this syntax? I tried different expression, but no one work.

---

## [Filebeat - non-deterministic error (pipestatus 141) when read from stdin](https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968)

<div class="topic-metadata">

**Author:** [@krrz](https://discuss.elastic.co/u/krrz)\
**Replies:** 3\
**Last updated:** [October 22, 2018, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968 "2018-10-22T13:50:28Z")

</div>

Hi, when I start filebeat reading from stdin sometime its end with 141 pipe status. # filebeat.1 zcat somefile.gz | filebeat -c filebeat.yml --once; rc=${PIPESTATUS\[\*\]}; echo $rc 0 0 # filebeat zcat somefile.gz | fileb…

---

## [Metricbeat 6.4.1 - config test gives false ok](https://discuss.elastic.co/t/metricbeat-6-4-1-config-test-gives-false-ok/153033)

<div class="topic-metadata">

**Author:** [@ariemenschneider](https://discuss.elastic.co/u/ariemenschneider)\
**Replies:** 3\
**Last updated:** [October 22, 2018, 12:20pm UTC](https://discuss.elastic.co/t/metricbeat-6-4-1-config-test-gives-false-ok/153033 "2018-10-22T12:20:46Z")

</div>

Hi, I'm trying to set up Metricbeat dashboards in our Kibana, but I'm getting authorization failures: metricbeat setup --dashboards Loading dashboards (Kibana must be running and reachable) Exiting: Error importing Kib…

---

## [How to move a complete fields tree to another level](https://discuss.elastic.co/t/how-to-move-a-complete-fields-tree-to-another-level/152050)

<div class="topic-metadata">

**Author:** [@Lu\_Do](https://discuss.elastic.co/u/Lu_Do)\
**Replies:** 2\
**Last updated:** [October 21, 2018, 7:21pm UTC](https://discuss.elastic.co/t/how-to-move-a-complete-fields-tree-to-another-level/152050 "2018-10-21T19:21:52Z")

</div>

Hello, I want to move a whole subset of fields to another level, Example I want to move docker.container.label.org.myorg.\* to root level ? Is there any way to do this without using : - rename: fields: …

---

## [Issue with Json?](https://discuss.elastic.co/t/issue-with-json/153091)

<div class="topic-metadata">

**Author:** [@killmasta93](https://discuss.elastic.co/u/killmasta93)\
**Replies:** 3\
**Last updated:** [October 20, 2018, 10:24pm UTC](https://discuss.elastic.co/t/issue-with-json/153091 "2018-10-20T22:24:46Z")

</div>

Hi, I was wondering if someone could shed some light on the issue im having. Currently have Elastic Search 6. Im currently trying to send .json files to the Elastic search via logstash. the issue im having on the filebe…

---

## [IIS Module - not groking](https://discuss.elastic.co/t/iis-module-not-groking/152914)

<div class="topic-metadata">

**Author:** [@devops\_mike](https://discuss.elastic.co/u/devops_mike)\
**Replies:** 3\
**Last updated:** [October 19, 2018, 9:05pm UTC](https://discuss.elastic.co/t/iis-module-not-groking/152914 "2018-10-19T21:05:01Z")

</div>

I have inherited a partially constructed ELK environment. Previous to my efforts, IIS logs have not entered the system. Looking at previous source control checkins, the Dev before me was running everything locally on the…

---

## [Filebeat in Docker: logging.to\_files is ignored](https://discuss.elastic.co/t/filebeat-in-docker-logging-to-files-is-ignored/147224)

<div class="topic-metadata">

**Author:** [@bluecoffee](https://discuss.elastic.co/u/bluecoffee)\
**Replies:** 11\
**Last updated:** [October 19, 2018, 2:22pm UTC](https://discuss.elastic.co/t/filebeat-in-docker-logging-to-files-is-ignored/147224 "2018-10-19T14:22:55Z")

</div>

Hi! I'm running Filebeat as a Docker container. I bind-mount a config file "filebeat.yml" that defines logging to files, but the logs still end up in the console, not in a file. The config file is being read (other con…

---

## [Extracting data from logs using Filebeat](https://discuss.elastic.co/t/extracting-data-from-logs-using-filebeat/153083)

<div class="topic-metadata">

**Author:** [@merceskoba](https://discuss.elastic.co/u/merceskoba)\
**Replies:** 2\
**Last updated:** [October 19, 2018, 12:55pm UTC](https://discuss.elastic.co/t/extracting-data-from-logs-using-filebeat/153083 "2018-10-19T12:55:05Z")

</div>

Hello dear, My company is using Scalyr for monitoring logs. Now, i am making the POC using Graylog2. In Scalyr, there is a scalyr agent that manage logs before send to Graylog. For example, { path: “/var/log/nginx/…

---

## [Require suggestion for the processing multi-line logs: filebeat or logstash](https://discuss.elastic.co/t/require-suggestion-for-the-processing-multi-line-logs-filebeat-or-logstash/152976)

<div class="topic-metadata">

**Author:** [@ajb](https://discuss.elastic.co/u/ajb)\
**Replies:** 3\
**Last updated:** [October 19, 2018, 12:35pm UTC](https://discuss.elastic.co/t/require-suggestion-for-the-processing-multi-line-logs-filebeat-or-logstash/152976 "2018-10-19T12:35:56Z")

</div>

Hi Elastic team, Im trying to process logs from liferay (a CMS application) liferay logs daily single file contains above 1000 lines Sample log lines inside log file 13:56:59,178 INFO \[ContainerBackgroundProcesso…

---

## [How filebeat handle json string with backslash](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012)

<div class="topic-metadata">

**Author:** [@kimown](https://discuss.elastic.co/u/kimown)\
**Replies:** 4\
**Last updated:** [October 19, 2018, 12:31pm UTC](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012 "2018-10-19T12:31:46Z")

</div>

Hi, I am using keys\_under\_root https://www.elastic.co/guide/en/beats/filebeat/5.2/configuration-filebeat-options.html#config-json I know {\\"text\\":\\"message with backslash\\"} is not a valid json string, so filebeat tre…

---

## [Specific logs to kibana from filebeat](https://discuss.elastic.co/t/specific-logs-to-kibana-from-filebeat/152695)

<div class="topic-metadata">

**Author:** [@kritikajj](https://discuss.elastic.co/u/kritikajj)\
**Replies:** 1\
**Last updated:** [October 19, 2018, 11:10am UTC](https://discuss.elastic.co/t/specific-logs-to-kibana-from-filebeat/152695 "2018-10-19T11:10:54Z")

</div>

Hi, A short snippet of log file which I want to visualize in Kibana is attached here. How can I configure my filebeat or ELK to reflect log fields highlighted here in bold and italics to reflect in Index Pattern fields…

---

## [Custom nginx module log format error](https://discuss.elastic.co/t/custom-nginx-module-log-format-error/152791)

<div class="topic-metadata">

**Author:** [@damonops](https://discuss.elastic.co/u/damonops)\
**Replies:** 3\
**Last updated:** [October 19, 2018, 10:33am UTC](https://discuss.elastic.co/t/custom-nginx-module-log-format-error/152791 "2018-10-19T10:33:27Z")

</div>

my filebeat nginx log format: "\\"?%{IP\_LIST:nginx.access.remote\_ip\_list} - %{DATA:nginx.access.user\_name} \\\\\[%{HTTPDATE:nginx.access.time}\\\\\] \\"%{GREEDYDATA:nginx.access.info}\\" %{NUMBER:nginx.access.response\_code} %{…

---

## [Filebeat on kubernetes - access denied](https://discuss.elastic.co/t/filebeat-on-kubernetes-access-denied/152678)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 6\
**Last updated:** [October 19, 2018, 9:57am UTC](https://discuss.elastic.co/t/filebeat-on-kubernetes-access-denied/152678 "2018-10-19T09:57:40Z")

</div>

Ive created a filebeat daemonset for my k8 cluster using (roughly) these params: https://github.com/elastic/beats/blob/master/deploy/kubernetes/filebeat/filebeat-daemonset.yaml. Of 5 cluster hosts 4 are working fine and…

---

## [Metricbeat missing kube-state-metrics](https://discuss.elastic.co/t/metricbeat-missing-kube-state-metrics/148663)

<div class="topic-metadata">

**Author:** [@violetaria](https://discuss.elastic.co/u/violetaria)\
**Replies:** 9\
**Last updated:** [October 19, 2018, 2:44am UTC](https://discuss.elastic.co/t/metricbeat-missing-kube-state-metrics/148663 "2018-10-19T02:44:55Z")

</div>

I have ELK stack with filebeat & metricbeat reporting to logstash. Filebeat works fine. I can see kubernetes.. and system.. in the Metricbeat data but do not see kube-state-metrics data and cannot figure out what I am d…

---

## [Best practices to import millions of old log files to es](https://discuss.elastic.co/t/best-practices-to-import-millions-of-old-log-files-to-es/153089)

<div class="topic-metadata">

**Author:** [@guanghaofan](https://discuss.elastic.co/u/guanghaofan)\
**Replies:** 1\
**Last updated:** [October 19, 2018, 1:57am UTC](https://discuss.elastic.co/t/best-practices-to-import-millions-of-old-log-files-to-es/153089 "2018-10-19T01:57:47Z")

</div>

hi filebeat experts, I'm going to import a huge amount of old files into ES, and my situation is there are millions of log files. So the main challenge is how to auto removed the log file once it's completely consumed b…

---

## [Filebeat Consume High Amount of Memory](https://discuss.elastic.co/t/filebeat-consume-high-amount-of-memory/152929)

<div class="topic-metadata">

**Author:** [@fiq](https://discuss.elastic.co/u/fiq)\
**Replies:** 1\
**Last updated:** [October 18, 2018, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-consume-high-amount-of-memory/152929 "2018-10-18T22:26:08Z")

</div>

Hi, Filebeat on one of our machine is consuming high amount of memory. Our filebeat configuration is like this below : - type: log paths: - /var/log/fmw/app/portal/portal-api.log include\_lines: \['^\\d{4}-\\d{2}-…

---

## [Apache logs not sending to logstash](https://discuss.elastic.co/t/apache-logs-not-sending-to-logstash/152527)

<div class="topic-metadata">

**Author:** [@ppafford](https://discuss.elastic.co/u/ppafford)\
**Replies:** 5\
**Last updated:** [October 18, 2018, 9:00pm UTC](https://discuss.elastic.co/t/apache-logs-not-sending-to-logstash/152527 "2018-10-18T21:00:24Z")

</div>

This is my setup Running Filebeat in it's own Docker container on ECS https://www.elastic.co/guide/en/beats/filebeat/current/running-on-docker.html Mount the log volume /var/log and create the filebeat directory there…

---

## [Filebeat handles rotated files issue](https://discuss.elastic.co/t/filebeat-handles-rotated-files-issue/152298)

<div class="topic-metadata">

**Author:** [@IngZero2](https://discuss.elastic.co/u/IngZero2)\
**Replies:** 3\
**Last updated:** [October 18, 2018, 8:56pm UTC](https://discuss.elastic.co/t/filebeat-handles-rotated-files-issue/152298 "2018-10-18T20:56:21Z")

</div>

Hi all, i've installed Filebeat on a AKS cluster with 5 nodes. I've a stranger behaviour with rotated containers log files. Docker rotation rule is { "live-restore": true, "log-driver": "json-file", "log-opts": { "ma…

---

## [Configure filebeat to send only new events](https://discuss.elastic.co/t/configure-filebeat-to-send-only-new-events/152940)

<div class="topic-metadata">

**Author:** [@elk11](https://discuss.elastic.co/u/elk11)\
**Replies:** 1\
**Last updated:** [October 18, 2018, 11:33am UTC](https://discuss.elastic.co/t/configure-filebeat-to-send-only-new-events/152940 "2018-10-18T11:33:59Z")

</div>

Hi, We had successfully set up the ELK stack to our production environment. We can also see the logs (logs are unstructured) output on our Kibana Server. Everything is working fine for us. But the only thing we are con…

---

## [How to separate index of filebeat coming from 2 or more hosts](https://discuss.elastic.co/t/how-to-separate-index-of-filebeat-coming-from-2-or-more-hosts/152463)

<div class="topic-metadata">

**Author:** [@mark.quilates](https://discuss.elastic.co/u/mark.quilates)\
**Replies:** 10\
**Last updated:** [October 18, 2018, 10:17am UTC](https://discuss.elastic.co/t/how-to-separate-index-of-filebeat-coming-from-2-or-more-hosts/152463 "2018-10-18T10:17:55Z")

</div>

Hi Guys, Can you help me, I have 2 filebeats in separate host and I used logstash pipeline. The thing is I want the other filebeat it to stored its data in new index. How can I make that? To have new index name in my …

---

## [Filebeat 6.4.2 the timestamp is not right](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748)

<div class="topic-metadata">

**Author:** [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Replies:** 5\
**Last updated:** [October 18, 2018, 2:38am UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748 "2018-10-18T02:38:43Z")

</div>

filebeat 6.4.2 the timestamp is not right. i use filebeat 6.4.2 to es the time is +8 not right my machine timezone is Wed Oct 10 13:03:45 CST 2018 but the filebeat time write into es is like "@timestamp" : "2018-1…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=410)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=412)
