# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=413

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 414

---

## [Error in Metricbeats](https://discuss.elastic.co/t/error-in-metricbeats/152409)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 2\
**Last updated:** [October 15, 2018, 9:00am UTC](https://discuss.elastic.co/t/error-in-metricbeats/152409 "2018-10-15T09:00:55Z")

</div>

Hi- I executed the metricbeats with the below config: - module: windows metricsets: \[perfmon\] period: 10s perfmon.ignore\_non\_existent\_counters: true perfmon.counters: - instance\_label: process\_processor\_tim…

---

## [Sending to Ingest Node](https://discuss.elastic.co/t/sending-to-ingest-node/152287)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 3\
**Last updated:** [October 15, 2018, 7:16am UTC](https://discuss.elastic.co/t/sending-to-ingest-node/152287 "2018-10-15T07:16:00Z")

</div>

Hi, I'm considering sending directly from filebeat to elasticsearch ingest nodes. Can I ask, how reliable is this vs using the beats protocol to logstash? Regards, D

---

## [Windows/Perfmon Fatal Error](https://discuss.elastic.co/t/windows-perfmon-fatal-error/151651)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 20\
**Last updated:** [October 15, 2018, 7:11am UTC](https://discuss.elastic.co/t/windows-perfmon-fatal-error/151651 "2018-10-15T07:11:48Z")

</div>

Hi- I added a performance counter in the windows modules and execute module test command, the result was also ok. When I start the service, I see the below message in the logs: recovered from panic while fetching 'win…

---

## [Packetbeats use mysql module, respontime display negative，path not only tablename](https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327)

<div class="topic-metadata">

**Author:** [@test987654123](https://discuss.elastic.co/u/test987654123)\
**Replies:** 3\
**Last updated:** [October 15, 2018, 7:06am UTC](https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327 "2018-10-15T07:06:28Z")

</div>

Hi, I am Sorry, My English is not good， Please understand。 I use packetbeats as mysql Behavioral audit，Collect Architecture is packetbeats --\> kafka --\> logstash --\> es --\> kibana/grafana。 I has three problem. path …

---

## [Changing index pattern refuses to start](https://discuss.elastic.co/t/changing-index-pattern-refuses-to-start/152026)

<div class="topic-metadata">

**Author:** [@mortenb123](https://discuss.elastic.co/u/mortenb123)\
**Replies:** 2\
**Last updated:** [October 13, 2018, 12:18am UTC](https://discuss.elastic.co/t/changing-index-pattern-refuses-to-start/152026 "2018-10-13T00:18:40Z")

</div>

Hi according to: Configure the Elasticsearch output | Winlogbeat Reference \[master\] | Elastic But if I add index: "winlogbeat-%{\[beat.version\]}-%{+yyyy.MM.dd}" winlogbeat do not start up

---

## [Debug Unmatched Responses and tcp dropped because of gaps](https://discuss.elastic.co/t/debug-unmatched-responses-and-tcp-dropped-because-of-gaps/151722)

<div class="topic-metadata">

**Author:** [@manavkapoor](https://discuss.elastic.co/u/manavkapoor)\
**Replies:** 3\
**Last updated:** [October 13, 2018, 12:15am UTC](https://discuss.elastic.co/t/debug-unmatched-responses-and-tcp-dropped-because-of-gaps/151722 "2018-10-13T00:15:36Z")

</div>

Hello. I have configured Packetbeat and currently I have packetbeat flows going into a remote monitoring cluster. However, I am having trouble getting http logging sent to this same remote monitoring cluster and really …

---

## [Kubernetes, Filebeat, and Kafka connection issues](https://discuss.elastic.co/t/kubernetes-filebeat-and-kafka-connection-issues/150751)

<div class="topic-metadata">

**Author:** [@grant.moz](https://discuss.elastic.co/u/grant.moz)\
**Replies:** 5\
**Last updated:** [October 12, 2018, 11:55pm UTC](https://discuss.elastic.co/t/kubernetes-filebeat-and-kafka-connection-issues/150751 "2018-10-12T23:55:14Z")

</div>

I am working on getting logs out of Kubernetes using the "stable/filebeat" Helm chart. Everything is running on Ubuntu 16.04 servers. There seems to be a change between two versions of the filebeat-oss Docker container …

---

## [Filebeat configuration file permission](https://discuss.elastic.co/t/filebeat-configuration-file-permission/152063)

<div class="topic-metadata">

**Author:** [@sumitdatta](https://discuss.elastic.co/u/sumitdatta)\
**Replies:** 1\
**Last updated:** [October 12, 2018, 11:49pm UTC](https://discuss.elastic.co/t/filebeat-configuration-file-permission/152063 "2018-10-12T23:49:38Z")

</div>

Hi all, We are trying to configure filebeat to our openshift cluster. Filebeat configuration file will be directly taken from openshift persistence volume at the time of container creation and we don't have root privile…

---

## [Disable 'Host' output field from filebeat](https://discuss.elastic.co/t/disable-host-output-field-from-filebeat/151635)

<div class="topic-metadata">

**Author:** [@meetdave2611997](https://discuss.elastic.co/u/meetdave2611997)\
**Replies:** 3\
**Last updated:** [October 12, 2018, 10:36pm UTC](https://discuss.elastic.co/t/disable-host-output-field-from-filebeat/151635 "2018-10-12T22:36:45Z")

</div>

Hi First we were using filebeat version 6.2.4 in which filebeat automatically exported 'host' field as string but when we updated filebeat to 6.4.2, newer version started exporting 'host' field as an object and this led…

---

## [Https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html](https://discuss.elastic.co/t/https-www-elastic-co-guide-en-logstash-current-advanced-pipeline-html/151253)

<div class="topic-metadata">

**Author:** [@mreloysanchez](https://discuss.elastic.co/u/mreloysanchez)\
**Replies:** 4\
**Last updated:** [October 12, 2018, 10:29pm UTC](https://discuss.elastic.co/t/https-www-elastic-co-guide-en-logstash-current-advanced-pipeline-html/151253 "2018-10-12T22:29:47Z")

</div>

https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html

---

## [Service Metricset for Unix](https://discuss.elastic.co/t/service-metricset-for-unix/151303)

<div class="topic-metadata">

**Author:** [@armsepehr](https://discuss.elastic.co/u/armsepehr)\
**Replies:** 8\
**Last updated:** [October 12, 2018, 6:27pm UTC](https://discuss.elastic.co/t/service-metricset-for-unix/151303 "2018-10-12T18:27:14Z")

</div>

Hello lovely community, I am looking for a module in Metricbeat to send the status for each service in the client to the elasticsearch, and create such a dashboard. After googling, I found windows module in metricbeat…

---

## [Filebeat include\_lines performance v.s. grep](https://discuss.elastic.co/t/filebeat-include-lines-performance-v-s-grep/151751)

<div class="topic-metadata">

**Author:** [@dontscrambleme](https://discuss.elastic.co/u/dontscrambleme)\
**Replies:** 1\
**Last updated:** [October 12, 2018, 5:36pm UTC](https://discuss.elastic.co/t/filebeat-include-lines-performance-v-s-grep/151751 "2018-10-12T17:36:28Z")

</div>

I use filebeat to harvest lines including keywords and send it to logstash for post processing. But the time filebeat searching for the string is much longer than running grep in Ubuntu shell I don't have number to sh…

---

## [Reachable\_only: true setting with Winlogbeat Kafka output does not seem to work](https://discuss.elastic.co/t/reachable-only-true-setting-with-winlogbeat-kafka-output-does-not-seem-to-work/151529)

<div class="topic-metadata">

**Author:** [@holdenkilbride](https://discuss.elastic.co/u/holdenkilbride)\
**Replies:** 3\
**Last updated:** [October 12, 2018, 5:15pm UTC](https://discuss.elastic.co/t/reachable-only-true-setting-with-winlogbeat-kafka-output-does-not-seem-to-work/151529 "2018-10-12T17:15:11Z")

</div>

Hello, I am trying to set up winlogbeat to still publish to available partitions in the event the leader partition is unreachable (due to DNS, routing issues, etc.). The broker is still online in this scenario. I am j…

---

## [Filebeat and Logstash in Kubernetes](https://discuss.elastic.co/t/filebeat-and-logstash-in-kubernetes/151219)

<div class="topic-metadata">

**Author:** [@tsbu](https://discuss.elastic.co/u/tsbu)\
**Replies:** 3\
**Last updated:** [October 12, 2018, 5:11pm UTC](https://discuss.elastic.co/t/filebeat-and-logstash-in-kubernetes/151219 "2018-10-12T17:11:19Z")

</div>

Hello, I'm running Filebeat as daemonset in seperate kubernete cluster and sending logs to multiple logstash statefulsets which is running in other Kubernetes cluster. So, do I need to create seperate Logstash Service …

---

## [Heartbeat to every pod in kubernetes](https://discuss.elastic.co/t/heartbeat-to-every-pod-in-kubernetes/152111)

<div class="topic-metadata">

**Author:** [@pastorsx](https://discuss.elastic.co/u/pastorsx)\
**Replies:** 1\
**Last updated:** [October 12, 2018, 10:24am UTC](https://discuss.elastic.co/t/heartbeat-to-every-pod-in-kubernetes/152111 "2018-10-12T10:24:24Z")

</div>

Hi, I am trying to use heartbeat to track availability of every pod in my kubernetes environment .... is there a way to do so. The add\_kubernetes\_metada doesn't seem to work and I assumed it should be something like thi…

---

## [Applying docker input to Nginx module with autodiscover](https://discuss.elastic.co/t/applying-docker-input-to-nginx-module-with-autodiscover/152032)

<div class="topic-metadata">

**Author:** [@Claude\_Juif](https://discuss.elastic.co/u/Claude_Juif)\
**Replies:** 1\
**Last updated:** [October 12, 2018, 10:01am UTC](https://discuss.elastic.co/t/applying-docker-input-to-nginx-module-with-autodiscover/152032 "2018-10-12T10:01:46Z")

</div>

Hi people, I'm currently struggling to apply docker input to the Nginx module with filebeat 6.4.1. Here is my filebeat configuration file : filebeat.autodiscover: providers: - type: docker templates: …

---

## [Filebeat not parsing apache logs](https://discuss.elastic.co/t/filebeat-not-parsing-apache-logs/152171)

<div class="topic-metadata">

**Author:** [@faulander](https://discuss.elastic.co/u/faulander)\
**Replies:** 1\
**Last updated:** [October 12, 2018, 7:34am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-apache-logs/152171 "2018-10-12T07:34:36Z")

</div>

Filebeat: 6.4.2 Apache: 2.4.34 Logs get shipped perfectly, but not parsed:

---

## [Connecting Filebeat to Logstash](https://discuss.elastic.co/t/connecting-filebeat-to-logstash/151725)

<div class="topic-metadata">

**Author:** [@Samuel\_Dare](https://discuss.elastic.co/u/Samuel_Dare)\
**Replies:** 1\
**Last updated:** [October 11, 2018, 10:57am UTC](https://discuss.elastic.co/t/connecting-filebeat-to-logstash/151725 "2018-10-11T10:57:06Z")

</div>

I am new to elasticsearch and following the tutorial here: I have hit a stumbling block as I can connect the servers with the ELK stack configured with the the server that is logging activity to file beat. I have nar…

---

## [Filebeat 5.2 processor doesn't work](https://discuss.elastic.co/t/filebeat-5-2-processor-doesnt-work/151912)

<div class="topic-metadata">

**Author:** [@mikhail\_mironov](https://discuss.elastic.co/u/mikhail_mironov)\
**Replies:** 2\
**Last updated:** [October 11, 2018, 9:05am UTC](https://discuss.elastic.co/t/filebeat-5-2-processor-doesnt-work/151912 "2018-10-11T09:05:35Z")

</div>

Can you explain please, why my processor doesn't work? My config: filebeat: …

---

## [Manual Edit of Registry file](https://discuss.elastic.co/t/manual-edit-of-registry-file/151473)

<div class="topic-metadata">

**Author:** [@lask001](https://discuss.elastic.co/u/lask001)\
**Replies:** 6\
**Last updated:** [October 10, 2018, 4:13pm UTC](https://discuss.elastic.co/t/manual-edit-of-registry-file/151473 "2018-10-10T16:13:32Z")

</div>

I have manually edited the registry file on one of my filebeats containers in an attempt to get it to reprocess specific files. It will load the edited registry, and the logs indicate that it no longer recognizes the the…

---

## [Filebeat stops connecting to Elastic after a while](https://discuss.elastic.co/t/filebeat-stops-connecting-to-elastic-after-a-while/150882)

<div class="topic-metadata">

**Author:** [@Dmitriy\_Parkhonin](https://discuss.elastic.co/u/Dmitriy_Parkhonin)\
**Replies:** 8\
**Last updated:** [October 10, 2018, 3:52pm UTC](https://discuss.elastic.co/t/filebeat-stops-connecting-to-elastic-after-a-while/150882 "2018-10-10T15:52:05Z")

</div>

I have a setup with several dozens of filebeats (v.6.2.2) that are connected to Elastic (v.6.2.2 too). Each filebeat monitors for several dozens of log files. Some of the beats stop functioning properly sometimes, I ca…

---

## [Multiple deleted .tmp files left open by filebeat service](https://discuss.elastic.co/t/multiple-deleted-tmp-files-left-open-by-filebeat-service/148373)

<div class="topic-metadata">

**Author:** [@planetvortex](https://discuss.elastic.co/u/planetvortex)\
**Replies:** 9\
**Last updated:** [October 10, 2018, 2:32pm UTC](https://discuss.elastic.co/t/multiple-deleted-tmp-files-left-open-by-filebeat-service/148373 "2018-10-10T14:32:24Z")

</div>

I backed out of posting a question on this thinking it was just my own wrongdoing...now I'm not so certain. (and it still may be) I have a log file that is being written out by tomcat, fairly regularly, has intermittent…

---

## [Error creating input: No paths were defined for input accessing config](https://discuss.elastic.co/t/error-creating-input-no-paths-were-defined-for-input-accessing-config/151596)

<div class="topic-metadata">

**Author:** [@eagle1209](https://discuss.elastic.co/u/eagle1209)\
**Replies:** 7\
**Last updated:** [October 10, 2018, 2:04pm UTC](https://discuss.elastic.co/t/error-creating-input-no-paths-were-defined-for-input-accessing-config/151596 "2018-10-10T14:04:13Z")

</div>

Hello, I am trial ashosted Elasticsearch Service. And i try to start filebeat, but i have some problem. I try install filebeat but it come to stopped. Here is my command: When i open log in C:\\ProgramData\\filebeat\\lo…

---

## [How do we differentiate inbound and outbound traffic in packetbeat](https://discuss.elastic.co/t/how-do-we-differentiate-inbound-and-outbound-traffic-in-packetbeat/151679)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 2\
**Last updated:** [October 10, 2018, 1:16pm UTC](https://discuss.elastic.co/t/how-do-we-differentiate-inbound-and-outbound-traffic-in-packetbeat/151679 "2018-10-10T13:16:54Z")

</div>

How do we differentiate inbound and outbound traffic in packetbeat ? or how do we can find out connection to server and connection from server ?

---

## [Filebeat blocks when reading STDIN and output is unavailable](https://discuss.elastic.co/t/filebeat-blocks-when-reading-stdin-and-output-is-unavailable/151600)

<div class="topic-metadata">

**Author:** [@rarruda](https://discuss.elastic.co/u/rarruda)\
**Replies:** 2\
**Last updated:** [October 10, 2018, 11:58am UTC](https://discuss.elastic.co/t/filebeat-blocks-when-reading-stdin-and-output-is-unavailable/151600 "2018-10-10T11:58:46Z")

</div>

Hi, I am using filebeat to read from STDIN from the STDOUT of an application. However once the filebeat's buffer is full, it stops reading from the STDIN, which blocks the execution of the application. This happens if t…

---

## [Filebeats Client Configuration](https://discuss.elastic.co/t/filebeats-client-configuration/151664)

<div class="topic-metadata">

**Author:** [@JDT1969](https://discuss.elastic.co/u/JDT1969)\
**Replies:** 2\
**Last updated:** [October 10, 2018, 8:13am UTC](https://discuss.elastic.co/t/filebeats-client-configuration/151664 "2018-10-10T08:13:29Z")

</div>

I am completely new to the world of ElasticSearch, Kibana and Beats so please forgive the basic questions. I have managed to get ElasticSearch, Kibana and all required Beats set up and running with the exception of File…

---

## [IP field do not add every time](https://discuss.elastic.co/t/ip-field-do-not-add-every-time/149380)

<div class="topic-metadata">

**Author:** [@leslie](https://discuss.elastic.co/u/leslie)\
**Replies:** 3\
**Last updated:** [October 10, 2018, 2:53am UTC](https://discuss.elastic.co/t/ip-field-do-not-add-every-time/149380 "2018-10-10T02:53:24Z")

</div>

when config filebeat input , i use host metadata to add server ip as below - add\_host\_metadata: netinfo.enabled: true - rename: fields: - from: "host.ip" to: "ip" ignore\_missing: true fail…

---

## [Filebeat without Kibana](https://discuss.elastic.co/t/filebeat-without-kibana/151621)

<div class="topic-metadata">

**Author:** [@McElroy](https://discuss.elastic.co/u/McElroy)\
**Replies:** 1\
**Last updated:** [October 9, 2018, 9:26pm UTC](https://discuss.elastic.co/t/filebeat-without-kibana/151621 "2018-10-09T21:26:11Z")

</div>

How can I run filebeat without a kibana config? When I delete the kibana parameter from the config, I get 2018-10-09T13:45:44.644+0200 ERROR instance/beat.go:743 Exiting: Error importing Kibana dashboards: fail to crea…

---

## [Filebeat sending whole log everytime instead of just newly added lines](https://discuss.elastic.co/t/filebeat-sending-whole-log-everytime-instead-of-just-newly-added-lines/151702)

<div class="topic-metadata">

**Author:** [@elk11](https://discuss.elastic.co/u/elk11)\
**Replies:** 1\
**Last updated:** [October 9, 2018, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-sending-whole-log-everytime-instead-of-just-newly-added-lines/151702 "2018-10-09T19:47:17Z")

</div>

Hi, Filebeat is sending whole log every time for addition of even one new line in log file. because of this I'm ending up with lot of duplicate data. Below is my config file: filebeat.prospectors: - type: log enable…

---

## [System module working but not logging all lines in /var/log/messages](https://discuss.elastic.co/t/system-module-working-but-not-logging-all-lines-in-var-log-messages/151524)

<div class="topic-metadata">

**Author:** [@Chris\_Searle](https://discuss.elastic.co/u/Chris_Searle)\
**Replies:** 2\
**Last updated:** [October 9, 2018, 5:34pm UTC](https://discuss.elastic.co/t/system-module-working-but-not-logging-all-lines-in-var-log-messages/151524 "2018-10-09T17:34:35Z")

</div>

Running 6.4 on debian stretch. OK - so I think I have the system module configured (default paths etc). New to trying the modules system - it's been filebeats and logstash up to now. In kibana I can see the dashboards …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=412)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=414)
