# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=412

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 413

---

## [Get maximum performance from on file parser](https://discuss.elastic.co/t/get-maximum-performance-from-on-file-parser/151807)

<div class="topic-metadata">

**Author:** [@mancubus77](https://discuss.elastic.co/u/mancubus77)\
**Replies:** 2\
**Last updated:** [October 18, 2018, 12:31am UTC](https://discuss.elastic.co/t/get-maximum-performance-from-on-file-parser/151807 "2018-10-18T00:31:32Z")

</div>

I have a task to process batch of pcap files generated by monitoring and watchdog scripts. Before I discovered PacktBeat a parsing performed via tshark pdml and a few custom parsers. The stack was ugly, but it was fast e…

---

## [Load only some metricbeat dashboards](https://discuss.elastic.co/t/load-only-some-metricbeat-dashboards/152899)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 4\
**Last updated:** [October 17, 2018, 8:45pm UTC](https://discuss.elastic.co/t/load-only-some-metricbeat-dashboards/152899 "2018-10-17T20:45:21Z")

</div>

I would like to import only some metricbeat dashboards into kibana. The metricbeat setup has no flags for --modules What is the recommended way to do this? On a different note: the documentation shows the filebeat u…

---

## [Winlogbeat install error](https://discuss.elastic.co/t/winlogbeat-install-error/151691)

<div class="topic-metadata">

**Author:** [@paulc](https://discuss.elastic.co/u/paulc)\
**Replies:** 8\
**Last updated:** [October 17, 2018, 8:07pm UTC](https://discuss.elastic.co/t/winlogbeat-install-error/151691 "2018-10-17T20:07:08Z")

</div>

I've followed the instructions via the winlogbeat guide and tried to take ownership of the .ps1 files but as far as I get is supposedly installing the service and setting the startuptype to automatic but when I try to st…

---

## [Metricbeat-6.4.0 rpm package not indexing data in elasticsearch-6.4.0](https://discuss.elastic.co/t/metricbeat-6-4-0-rpm-package-not-indexing-data-in-elasticsearch-6-4-0/152819)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 2\
**Last updated:** [October 17, 2018, 5:45pm UTC](https://discuss.elastic.co/t/metricbeat-6-4-0-rpm-package-not-indexing-data-in-elasticsearch-6-4-0/152819 "2018-10-17T17:45:11Z")

</div>

Installed metricbeat-6.4.0-x86\_64.rpm on RedHat Enterprise Linux Server using below command. curl -L -O https://artifacts.elastic.co/downloads/beats/metricbeat/metricbeat-6.4.2-x86\_64.rpm sudo rpm -vi metricbeat-6.4.2-x…

---

## [Beat detect when it stop sending logs](https://discuss.elastic.co/t/beat-detect-when-it-stop-sending-logs/151852)

<div class="topic-metadata">

**Author:** [@marcandre](https://discuss.elastic.co/u/marcandre)\
**Replies:** 1\
**Last updated:** [October 17, 2018, 12:11pm UTC](https://discuss.elastic.co/t/beat-detect-when-it-stop-sending-logs/151852 "2018-10-17T12:11:31Z")

</div>

Hello, I am using beats module mostly filebeat and metricbeat. I also have a license for x-pack. Is there a way to monitor beat activity and send an alert if a beat module didn't send log for more then 24 hours Thank …

---

## [Filebeat sending the whole log again after stoping and starting filebeat container](https://discuss.elastic.co/t/filebeat-sending-the-whole-log-again-after-stoping-and-starting-filebeat-container/150846)

<div class="topic-metadata">

**Author:** [@elk11](https://discuss.elastic.co/u/elk11)\
**Replies:** 14\
**Last updated:** [October 17, 2018, 10:18am UTC](https://discuss.elastic.co/t/filebeat-sending-the-whole-log-again-after-stoping-and-starting-filebeat-container/150846 "2018-10-17T10:18:57Z")

</div>

Hi, When I stop filebeat container for a while to do some maintenance work on elasticsearch (output) and then start it again, the whole log is being sent again. because of this along with the new info which was written …

---

## [Metricbeat service not indexing data in elasticsearch](https://discuss.elastic.co/t/metricbeat-service-not-indexing-data-in-elasticsearch/152705)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 2\
**Last updated:** [October 17, 2018, 9:26am UTC](https://discuss.elastic.co/t/metricbeat-service-not-indexing-data-in-elasticsearch/152705 "2018-10-17T09:26:18Z")

</div>

Windows Server 2008 R2 Standard metricbeat-6.4.0 I am getting below error in metricbeat: elasticsearch/client.go:520 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xbee9999910ae25d0, e…

---

## [Metricbeat not able to apcahe module](https://discuss.elastic.co/t/metricbeat-not-able-to-apcahe-module/152758)

<div class="topic-metadata">

**Author:** [@sukarn001](https://discuss.elastic.co/u/sukarn001)\
**Replies:** 3\
**Last updated:** [October 17, 2018, 8:53am UTC](https://discuss.elastic.co/t/metricbeat-not-able-to-apcahe-module/152758 "2018-10-17T08:53:28Z")

</div>

Hello, I installed metricbeat from RPM in rhel7 64bit, I am able to start it as a service. however when I am running ./metricbeat modules list or any other command it is giving me error Exiting: error loading config fil…

---

## [Comparison of heartbeat and zabbix](https://discuss.elastic.co/t/comparison-of-heartbeat-and-zabbix/152002)

<div class="topic-metadata">

**Author:** [@mukai](https://discuss.elastic.co/u/mukai)\
**Replies:** 2\
**Last updated:** [October 17, 2018, 5:20am UTC](https://discuss.elastic.co/t/comparison-of-heartbeat-and-zabbix/152002 "2018-10-17T05:20:37Z")

</div>

I want to use Heartbeat in our office. Heartbeat is very easy to use and lightweight. However, there is already Zabbix in the office. What are the strengths of Heartbeat? (URL) Heartbeat https://www.elastic.co/produ…

---

## [How can I verify all logs have been shipped?](https://discuss.elastic.co/t/how-can-i-verify-all-logs-have-been-shipped/152725)

<div class="topic-metadata">

**Author:** [@AvivCohn](https://discuss.elastic.co/u/AvivCohn)\
**Replies:** 1\
**Last updated:** [October 16, 2018, 10:15pm UTC](https://discuss.elastic.co/t/how-can-i-verify-all-logs-have-been-shipped/152725 "2018-10-16T22:15:16Z")

</div>

Hello, I have configured FileBeat to ship a log file to Elasticsearch directly. After all harvesters have already automatically stopped with a close\_inactive message, I ran a count check in the filebeat indices in ES. …

---

## [Filebeat live loading config not work](https://discuss.elastic.co/t/filebeat-live-loading-config-not-work/152579)

<div class="topic-metadata">

**Author:** [@darkrasid](https://discuss.elastic.co/u/darkrasid)\
**Replies:** 1\
**Last updated:** [October 16, 2018, 9:22pm UTC](https://discuss.elastic.co/t/filebeat-live-loading-config-not-work/152579 "2018-10-16T21:22:36Z")

</div>

Hi, I'm beginner of filebeat. When I use filebeat live config, filebeat ignores config file. filebeat version: 6.2.2 my filebeat.yml filebeat.config.inputs: enabled: true path: /usr/share/filebeat/inputs.d/\*.yml …

---

## [Not able to create /see any indexs in elasticsearch](https://discuss.elastic.co/t/not-able-to-create-see-any-indexs-in-elasticsearch/152524)

<div class="topic-metadata">

**Author:** [@bob\_ve](https://discuss.elastic.co/u/bob_ve)\
**Replies:** 1\
**Last updated:** [October 16, 2018, 9:17pm UTC](https://discuss.elastic.co/t/not-able-to-create-see-any-indexs-in-elasticsearch/152524 "2018-10-16T21:17:38Z")

</div>

I was not able to see any data or any indexs in elasticsearch . I was using filebeat --\> logstash --\> elasticsearch filebeat.yml filebeat.inputs: -\> type: log paths: /var/log/hadoop/hadoop/hive/gc.log\* document\_ty…

---

## [How can i get from Execbeat if a script successfully executed](https://discuss.elastic.co/t/how-can-i-get-from-execbeat-if-a-script-successfully-executed/152504)

<div class="topic-metadata">

**Author:** [@bab](https://discuss.elastic.co/u/bab)\
**Replies:** 1\
**Last updated:** [October 16, 2018, 9:13pm UTC](https://discuss.elastic.co/t/how-can-i-get-from-execbeat-if-a-script-successfully-executed/152504 "2018-10-16T21:13:19Z")

</div>

Hello all, I am using execbeat (ttps://github.com/christiangalsterer/execbeat) with ELK 6.3. I would like to know if certain my scripts are successfully executed AND if not i would like to report the issue. actually m…

---

## [Cp865 encoded logs](https://discuss.elastic.co/t/cp865-encoded-logs/152238)

<div class="topic-metadata">

**Author:** [@eikeskog](https://discuss.elastic.co/u/eikeskog)\
**Replies:** 3\
**Last updated:** [October 16, 2018, 9:06pm UTC](https://discuss.elastic.co/t/cp865-encoded-logs/152238 "2018-10-16T21:06:40Z")

</div>

Hi, Some of the files I am trying to read are encoded in cp865. I tried to set encoding: "cp865", but it seems that cp865 is not supported. # Configure the file encoding for reading files with international characters …

---

## [Multiple filebeat instances appear as one beat on kibana x-pack monitoring](https://discuss.elastic.co/t/multiple-filebeat-instances-appear-as-one-beat-on-kibana-x-pack-monitoring/151833)

<div class="topic-metadata">

**Author:** [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Replies:** 3\
**Last updated:** [October 16, 2018, 9:02pm UTC](https://discuss.elastic.co/t/multiple-filebeat-instances-appear-as-one-beat-on-kibana-x-pack-monitoring/151833 "2018-10-16T21:02:43Z")

</div>

We have 9 filebeats running, none with a 'name' specified - and so defaulting to the hostname. Visualising beat.name shows all 9 sending events. However, only 2 beats in Kibana under the monitoring section (latest vers…

---

## [How to run filebeat 6.4.1 as service?](https://discuss.elastic.co/t/how-to-run-filebeat-6-4-1-as-service/152344)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 2\
**Last updated:** [October 16, 2018, 8:59pm UTC](https://discuss.elastic.co/t/how-to-run-filebeat-6-4-1-as-service/152344 "2018-10-16T20:59:17Z")

</div>

Please suggest

---

## [I can't send older log](https://discuss.elastic.co/t/i-cant-send-older-log/151987)

<div class="topic-metadata">

**Author:** [@OlivierPCN](https://discuss.elastic.co/u/OlivierPCN)\
**Replies:** 3\
**Last updated:** [October 16, 2018, 8:53pm UTC](https://discuss.elastic.co/t/i-cant-send-older-log/151987 "2018-10-16T20:53:58Z")

</div>

Hello, I use filebeat to send slow log to logstash. I use the mysql module for that. But when I try to send an old file, filebeat send only the last slow query of the file. I already tried to delete the registry and I s…

---

## [Single unavailable Kafka topic blocks delivery to other available topics](https://discuss.elastic.co/t/single-unavailable-kafka-topic-blocks-delivery-to-other-available-topics/152189)

<div class="topic-metadata">

**Author:** [@tsuhachev](https://discuss.elastic.co/u/tsuhachev)\
**Replies:** 1\
**Last updated:** [October 16, 2018, 8:48pm UTC](https://discuss.elastic.co/t/single-unavailable-kafka-topic-blocks-delivery-to-other-available-topics/152189 "2018-10-16T20:48:52Z")

</div>

filebeat version 5.4.1 (amd64), libbeat 5.4.1 on CentOs 7 filebeat.prospectors: - input\_type: log backoff: 200ms max\_backoff: 500ms scan\_frequency: 2s paths: - /logs/login-events.log document\_type: name fields: …

---

## [Unable to push filebeat published messages to kafka output](https://discuss.elastic.co/t/unable-to-push-filebeat-published-messages-to-kafka-output/152170)

<div class="topic-metadata">

**Author:** [@Nithani25](https://discuss.elastic.co/u/Nithani25)\
**Replies:** 1\
**Last updated:** [October 16, 2018, 8:44pm UTC](https://discuss.elastic.co/t/unable-to-push-filebeat-published-messages-to-kafka-output/152170 "2018-10-16T20:44:22Z")

</div>

Hi Team, I am working on a setup where i am trying to push my filebeat read messages to kafka output. though i could see filebeat publishing messages, i couldn't recieve anything in kafka topic. Below is my filebeat.yml…

---

## [Build a new filebeat](https://discuss.elastic.co/t/build-a-new-filebeat/152159)

<div class="topic-metadata">

**Author:** [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Replies:** 1\
**Last updated:** [October 16, 2018, 8:42pm UTC](https://discuss.elastic.co/t/build-a-new-filebeat/152159 "2018-10-16T20:42:31Z")

</div>

Hi, I'd like to build a specific filebeat for our team. We have many team in the company and all team wants to have their own filebeat so if a reinstall happens we will not overwrite their configs and don't touch any o…

---

## [Metricbeat and Packetbeat](https://discuss.elastic.co/t/metricbeat-and-packetbeat/151809)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 4\
**Last updated:** [October 16, 2018, 5:38pm UTC](https://discuss.elastic.co/t/metricbeat-and-packetbeat/151809 "2018-10-16T17:38:34Z")

</div>

Hi, My Linux system configuration shows cat /etc/os-release NAME="Red Hat Enterprise Linux Server" VERSION="7.4 (Maipo)" ID="rhel" ID\_LIKE="fedora" VARIANT="Server" VARIANT\_ID="server" VERSION\_ID="7.4" PRETTY…

---

## [Docker autodiscover seems to ignore close\_inactive option](https://discuss.elastic.co/t/docker-autodiscover-seems-to-ignore-close-inactive-option/151944)

<div class="topic-metadata">

**Author:** [@larslevie](https://discuss.elastic.co/u/larslevie)\
**Replies:** 4\
**Last updated:** [October 16, 2018, 4:18pm UTC](https://discuss.elastic.co/t/docker-autodiscover-seems-to-ignore-close-inactive-option/151944 "2018-10-16T16:18:29Z")

</div>

I've got the following configuration: filebeat.autodiscover: providers: - type: docker container.ids: - "\*" hints.enabled: true close\_inactive: 7m ignore\_older: 7d processors:…

---

## [Event Data field not created in Kibana](https://discuss.elastic.co/t/event-data-field-not-created-in-kibana/152681)

<div class="topic-metadata">

**Author:** [@Sketchy](https://discuss.elastic.co/u/Sketchy)\
**Replies:** 0\
**Last updated:** [October 16, 2018, 2:20pm UTC](https://discuss.elastic.co/t/event-data-field-not-created-in-kibana/152681 "2018-10-16T14:20:48Z")

</div>

I am using filesystem auditing and logging event 4656. Is there a way I can have beats create a field for "Accesses" from the data below? All other fields get created except for Accesses. I want beats to only pickup lo…

---

## [Parsing problem for iis server error log using filebeat 6.3.2](https://discuss.elastic.co/t/parsing-problem-for-iis-server-error-log-using-filebeat-6-3-2/148639)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 8\
**Last updated:** [October 16, 2018, 10:32am UTC](https://discuss.elastic.co/t/parsing-problem-for-iis-server-error-log-using-filebeat-6-3-2/148639 "2018-10-16T10:32:05Z")

</div>

My IIS HTTPERROR log is like below 2018-07-11 05:02:45 10.100.4.168 51477 10.100.4.97 47001 HTTP/1.1 GET /..\\pixfir~1\\how\_to\_login.html 403 - Forbidden - i am getting parse error in filebeat. How to solve it ? Grock…

---

## [Metricbeat Kibana dashboards - "Overview" - intermittent results](https://discuss.elastic.co/t/metricbeat-kibana-dashboards-overview-intermittent-results/145451)

<div class="topic-metadata">

**Author:** [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Replies:** 14\
**Last updated:** [October 16, 2018, 7:26am UTC](https://discuss.elastic.co/t/metricbeat-kibana-dashboards-overview-intermittent-results/145451 "2018-10-16T07:26:58Z")

</div>

I'd love some assistance with the below issues, is there anything I can do to diagnose? Issue 1 I'm looking at a fresh "\[Metricbeat Kubernetes\] - Overview" dashboard. The top-left stats (Nodes, Deployments, Desired Po…

---

## [How can I pick logs from a specific directory and display on Kibana dashboard](https://discuss.elastic.co/t/how-can-i-pick-logs-from-a-specific-directory-and-display-on-kibana-dashboard/152166)

<div class="topic-metadata">

**Author:** [@Muhammad\_Hasan](https://discuss.elastic.co/u/Muhammad_Hasan)\
**Replies:** 1\
**Last updated:** [October 15, 2018, 10:51pm UTC](https://discuss.elastic.co/t/how-can-i-pick-logs-from-a-specific-directory-and-display-on-kibana-dashboard/152166 "2018-10-15T22:51:50Z")

</div>

I am a newbie on elastic-stack. I setup a elastic-stack and filebeat on Ubuntu 16.04 on local environment. Now I want to read log files from a specific directory through Filebeat. In my case "LogFile" is my directory whi…

---

## [Filebeat forward to Kibana ssh auth fail](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709)

<div class="topic-metadata">

**Author:** [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Replies:** 9\
**Last updated:** [October 15, 2018, 10:46pm UTC](https://discuss.elastic.co/t/filebeat-forward-to-kibana-ssh-auth-fail/151709 "2018-10-15T22:46:01Z")

</div>

Hello, I've filebeat and system module for check ssh auth but in Kibana dont register the ssh action. My filebeat.yml: filebeat.inputs: - type: log enabled: true paths: - /var/log/secure - /var/log/message…

---

## [Filebeat sending json date field as text](https://discuss.elastic.co/t/filebeat-sending-json-date-field-as-text/152353)

<div class="topic-metadata">

**Author:** [@DougC](https://discuss.elastic.co/u/DougC)\
**Replies:** 11\
**Last updated:** [October 15, 2018, 8:23pm UTC](https://discuss.elastic.co/t/filebeat-sending-json-date-field-as-text/152353 "2018-10-15T20:23:38Z")

</div>

Hi. I've been trying to teach myself the Elastic Stack by trying to index data generated by speedtest-cli on my local Ubuntu shell. When I use Logstash to send the results to Elasticsearch the timestamp field comes thr…

---

## [Document dollar-sign interpolation of configuration settings in config file](https://discuss.elastic.co/t/document-dollar-sign-interpolation-of-configuration-settings-in-config-file/152110)

<div class="topic-metadata">

**Author:** [@AdamGardner](https://discuss.elastic.co/u/AdamGardner)\
**Replies:** 4\
**Last updated:** [October 15, 2018, 8:02pm UTC](https://discuss.elastic.co/t/document-dollar-sign-interpolation-of-configuration-settings-in-config-file/152110 "2018-10-15T20:02:46Z")

</div>

So, most interpolation you want to do in a filebeat config file is done with a percent sign and curly brackets, %{like.this}. However, you can also interpolate environment variables with a dollar sign, ${LIKE\_THIS}. I've…

---

## [Beats for MS Sql and oracle dB](https://discuss.elastic.co/t/beats-for-ms-sql-and-oracle-db/152317)

<div class="topic-metadata">

**Author:** [@Haresh\_Perera](https://discuss.elastic.co/u/Haresh_Perera)\
**Replies:** 2\
**Last updated:** [October 15, 2018, 9:31am UTC](https://discuss.elastic.co/t/beats-for-ms-sql-and-oracle-db/152317 "2018-10-15T09:31:38Z")

</div>

Dear team We are looking at a solution to monitor MS Sql and oracle database using elk Is there a documented solution for this Using file beats and metrics beats Can elk works as DAM database activity monitoring Tha…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=411)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=413)
