# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=414

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 415

---

## [External configuration and 'type'](https://discuss.elastic.co/t/external-configuration-and-type/151457)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 2\
**Last updated:** [October 9, 2018, 1:57pm UTC](https://discuss.elastic.co/t/external-configuration-and-type/151457 "2018-10-09T13:57:36Z")

</div>

Hi, When I set up an external config file with: - type: log The index gets populated with "input.type" and "prospector.type". (whole stack is updated to 6.4.2) If I change that to: - input.type: log None of the…

---

## [Send some extra fields with filebeat apache2 and system module](https://discuss.elastic.co/t/send-some-extra-fields-with-filebeat-apache2-and-system-module/151244)

<div class="topic-metadata">

**Author:** [@cleverrocks](https://discuss.elastic.co/u/cleverrocks)\
**Replies:** 4\
**Last updated:** [October 9, 2018, 12:14pm UTC](https://discuss.elastic.co/t/send-some-extra-fields-with-filebeat-apache2-and-system-module/151244 "2018-10-09T12:14:49Z")

</div>

I am using the filebeat modules apache2 and system for logging. Below is my configuration. filebeat.modules: - module: system syslog: enabled: true var.paths: \["path/syslog"\] auth: enabled: true var.…

---

## [Setup & Build Issue on Filebeat on MAC (High Seria version :10.13.6)](https://discuss.elastic.co/t/setup-build-issue-on-filebeat-on-mac-high-seria-version-10-13-6/151363)

<div class="topic-metadata">

**Author:** [@mishravinay](https://discuss.elastic.co/u/mishravinay)\
**Replies:** 2\
**Last updated:** [October 9, 2018, 11:30am UTC](https://discuss.elastic.co/t/setup-build-issue-on-filebeat-on-mac-high-seria-version-10-13-6/151363 "2018-10-09T11:30:59Z")

</div>

Hi, I am trying to setup and build the filebeat in our mac (OS: High Seria version: 10.13.6). But unfortunately, unable to run the code and debug. can you please help me on this. I download the GOLang and setup, after …

---

## [I am currently using windows, instance/beat.go:743 Exiting: error initializing publisher: No outputs are defined. Please define one under the output section](https://discuss.elastic.co/t/i-am-currently-using-windows-instance-beat-go-743-exiting-error-initializing-publisher-no-outputs-are-defined-please-define-one-under-the-output-section/150953)

<div class="topic-metadata">

**Author:** [@rohit\_kumar\_Jain](https://discuss.elastic.co/u/rohit_kumar_Jain)\
**Replies:** 4\
**Last updated:** [October 9, 2018, 10:58am UTC](https://discuss.elastic.co/t/i-am-currently-using-windows-instance-beat-go-743-exiting-error-initializing-publisher-no-outputs-are-defined-please-define-one-under-the-output-section/150953 "2018-10-09T10:58:22Z")

</div>

I am currently using windows while running filebeat -e -c filebeat.yml -d "publish" command in order to post logs to ES, I am getting this error: instance/beat.go:743 Exiting: error initializing publisher: No outputs…

---

## [HTTP 1024 byte limit on payload](https://discuss.elastic.co/t/http-1024-byte-limit-on-payload/151340)

<div class="topic-metadata">

**Author:** [@tropas](https://discuss.elastic.co/u/tropas)\
**Replies:** 1\
**Last updated:** [October 9, 2018, 8:07am UTC](https://discuss.elastic.co/t/http-1024-byte-limit-on-payload/151340 "2018-10-09T08:07:06Z")

</div>

I think I've found a defect where if an http packet is \> 1024 (as defined by the content-length header) packetbeat doesn't populate the http.request.body attribute. I'm testing this with curl so it could be a way curl is…

---

## [Export dashboard to Kibana fail](https://discuss.elastic.co/t/export-dashboard-to-kibana-fail/151141)

<div class="topic-metadata">

**Author:** [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Replies:** 5\
**Last updated:** [October 8, 2018, 9:33pm UTC](https://discuss.elastic.co/t/export-dashboard-to-kibana-fail/151141 "2018-10-08T21:33:49Z")

</div>

Hello, I'm try export dashboard to Kibana from filebeat but some dashboard give error (field not found). my client i've: filebeat.yml filebeat.inputs: - type: log enabled: true paths: -/var/log/secure filebe…

---

## [Filebeat - accesing event data and fields in the configuration](https://discuss.elastic.co/t/filebeat-accesing-event-data-and-fields-in-the-configuration/151232)

<div class="topic-metadata">

**Author:** [@John\_Doe2](https://discuss.elastic.co/u/John_Doe2)\
**Replies:** 1\
**Last updated:** [October 8, 2018, 7:38pm UTC](https://discuss.elastic.co/t/filebeat-accesing-event-data-and-fields-in-the-configuration/151232 "2018-10-08T19:38:40Z")

</div>

Logstash documentation: https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html i want to define a field on the input like this: filebeat.inputs: - type: log enabled: true …

---

## [How to stop sending duplicate slack notifications of the same error?](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-of-the-same-error/149646)

<div class="topic-metadata">

**Author:** [@ddregalo](https://discuss.elastic.co/u/ddregalo)\
**Replies:** 2\
**Last updated:** [October 8, 2018, 12:35pm UTC](https://discuss.elastic.co/t/how-to-stop-sending-duplicate-slack-notifications-of-the-same-error/149646 "2018-10-08T12:35:44Z")

</div>

I have configured a heartbeat watcher to action a slack notification if the monitor status is down in the production environment and this is working fine buuuuuuuut - what I would like to do is NOT send duplicate notific…

---

## [Filebeat keep reading the file, this blocks the file deletion on the system](https://discuss.elastic.co/t/filebeat-keep-reading-the-file-this-blocks-the-file-deletion-on-the-system/150514)

<div class="topic-metadata">

**Author:** [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Replies:** 7\
**Last updated:** [October 8, 2018, 9:13am UTC](https://discuss.elastic.co/t/filebeat-keep-reading-the-file-this-blocks-the-file-deletion-on-the-system/150514 "2018-10-08T09:13:12Z")

</div>

Hi, We have this configuration: filebeat.prospectors: - type: log enabled: true exclude\_lines: \['^#'\] paths: - D:\\dir\\logfiles\\zip\_archive\\www.dir.com\\\*\\u\*.log - D:\\dir\\logfiles\\zip\_archive\\www81.dir.com\\…

---

## [Winlogbeat default age to ingest](https://discuss.elastic.co/t/winlogbeat-default-age-to-ingest/151374)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 4\
**Last updated:** [October 8, 2018, 4:30am UTC](https://discuss.elastic.co/t/winlogbeat-default-age-to-ingest/151374 "2018-10-08T04:30:29Z")

</div>

Hi all, What is the default time frame winlogbeat will ingest if ignore\_older is not specified? I've deleted some indices for this month and would like to try and retrieve them back but I'm only getting today's Thanks …

---

## [Winlogbeat install issue](https://discuss.elastic.co/t/winlogbeat-install-issue/149211)

<div class="topic-metadata">

**Author:** [@peterch](https://discuss.elastic.co/u/peterch)\
**Replies:** 3\
**Last updated:** [October 8, 2018, 1:32am UTC](https://discuss.elastic.co/t/winlogbeat-install-issue/149211 "2018-10-08T01:32:01Z")

</div>

Dear All, I tried to install winlogbeat and it show success. However, there is no winlogbeat service shown in service. The other machine don't have this issue. May i know any idea? The winlogbeat version is 6.2.4 Than…

---

## [HeartBeat Installation Error](https://discuss.elastic.co/t/heartbeat-installation-error/150970)

<div class="topic-metadata">

**Author:** [@DavisDxb](https://discuss.elastic.co/u/DavisDxb)\
**Replies:** 7\
**Last updated:** [October 7, 2018, 12:26pm UTC](https://discuss.elastic.co/t/heartbeat-installation-error/150970 "2018-10-07T12:26:22Z")

</div>

When I try to Download Heartbeat 6.3.1 and install it, system shows like this.I didn't get it.Please reply. Reading package lists... Done Building dependency tree Reading state information... Done E: Unable to locate…

---

## [Schedule Metricbeat](https://discuss.elastic.co/t/schedule-metricbeat/151180)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 1\
**Last updated:** [October 6, 2018, 7:50am UTC](https://discuss.elastic.co/t/schedule-metricbeat/151180 "2018-10-06T07:50:02Z")

</div>

Hi- Is there any provision to schedule the metricbeat to run for 24 hours and stop automatically on a windows server. Please let me know. Thanks !

---

## [Yet another connection reset by peer](https://discuss.elastic.co/t/yet-another-connection-reset-by-peer/151239)

<div class="topic-metadata">

**Author:** [@hueyg](https://discuss.elastic.co/u/hueyg)\
**Replies:** 1\
**Last updated:** [October 5, 2018, 7:56pm UTC](https://discuss.elastic.co/t/yet-another-connection-reset-by-peer/151239 "2018-10-05T19:56:25Z")

</div>

First I have red through pages of these posted and there are actually few applicable proposed solutions. I have tried them and still experience the issue. Keep in mind that this is a new ELK turnup on RH 7.5 with Nginx…

---

## [Rejecting mapping update](https://discuss.elastic.co/t/rejecting-mapping-update/150556)

<div class="topic-metadata">

**Author:** [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Replies:** 13\
**Last updated:** [October 5, 2018, 5:17pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556 "2018-10-05T17:17:42Z")

</div>

Hi, I have upgraded my elasticsearch to 6.3.2. After an upgrade i am trying to reindex my data. But i am getting below error. "cause": { "type": "illegal\_argument\_exception", "reason": "Rejecting mapping upd…

---

## [Auditbeat error with add\_process\_metadata missing](https://discuss.elastic.co/t/auditbeat-error-with-add-process-metadata-missing/151228)

<div class="topic-metadata">

**Author:** [@grants](https://discuss.elastic.co/u/grants)\
**Replies:** 2\
**Last updated:** [October 5, 2018, 4:06pm UTC](https://discuss.elastic.co/t/auditbeat-error-with-add-process-metadata-missing/151228 "2018-10-05T16:06:56Z")

</div>

Trying to do a lookup of \[process\]\[ppid\] and push the data into \[process\]\[parent\] but simple testing can't even get auditbeat to start due to an error that the processor is missing. ## config: processors: - add\_process\_…

---

## [Filebeat custom module docker multiline handling](https://discuss.elastic.co/t/filebeat-custom-module-docker-multiline-handling/151034)

<div class="topic-metadata">

**Author:** [@mvasilenko](https://discuss.elastic.co/u/mvasilenko)\
**Replies:** 4\
**Last updated:** [October 5, 2018, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-custom-module-docker-multiline-handling/151034 "2018-10-05T14:25:29Z")

</div>

Hello, I wrote small custom filebeat module for our web app logs parsing, but unable to catch multiline messages with exceptions, we are using filebeat at host, app is running in docker containers, the question is ho…

---

## [Filebeat kubernetes](https://discuss.elastic.co/t/filebeat-kubernetes/150345)

<div class="topic-metadata">

**Author:** [@garcia](https://discuss.elastic.co/u/garcia)\
**Replies:** 2\
**Last updated:** [October 5, 2018, 11:25am UTC](https://discuss.elastic.co/t/filebeat-kubernetes/150345 "2018-10-05T11:25:51Z")

</div>

hello, I have installed this documentation https://www.elastic.co/guide/en/beats/filebeat/master/running-on-kubernetes.html#running-on-kubernetes but I have a problem, logs elasticsearch \[filebeat-6.4.1-2018.09.28\] \[0…

---

## [Custom information in Winlogbeat events](https://discuss.elastic.co/t/custom-information-in-winlogbeat-events/149955)

<div class="topic-metadata">

**Author:** [@AliNjie](https://discuss.elastic.co/u/AliNjie)\
**Replies:** 1\
**Last updated:** [October 5, 2018, 10:10am UTC](https://discuss.elastic.co/t/custom-information-in-winlogbeat-events/149955 "2018-10-05T10:10:34Z")

</div>

Hi, Is there any way to include custom hardware information like serial number the events that Winlogbeat sends? By default, I see that the hostname and Winlogbeat version is included by default but I would like to incl…

---

## [Disk Usage empty in Kibana](https://discuss.elastic.co/t/disk-usage-empty-in-kibana/149296)

<div class="topic-metadata">

**Author:** [@bering](https://discuss.elastic.co/u/bering)\
**Replies:** 4\
**Last updated:** [October 5, 2018, 9:12am UTC](https://discuss.elastic.co/t/disk-usage-empty-in-kibana/149296 "2018-10-05T09:12:15Z")

</div>

I am running ES 6.4, Kibana 6.4 and metricbeat 6.4.1 I have metricbeat running on 2 servers and on one server the disk usage is empty in kibana The other server is showing fine Both servers run MS Server 2012 R2 a…

---

## [Postgresql Module?](https://discuss.elastic.co/t/postgresql-module/150633)

<div class="topic-metadata">

**Author:** [@killmasta93](https://discuss.elastic.co/u/killmasta93)\
**Replies:** 4\
**Last updated:** [October 5, 2018, 4:15am UTC](https://discuss.elastic.co/t/postgresql-module/150633 "2018-10-05T04:15:47Z")

</div>

Hi, I was wondering if someone could shed some light. currently have Kibana 6 with logstash and elasticsearch. The idea is one VM which has the postgresql to send the logs using filebeat to another VM which has ELK, I …

---

## [Dropping Events using Winlogbeat Processors](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781)

<div class="topic-metadata">

**Author:** [@popa](https://discuss.elastic.co/u/popa)\
**Replies:** 5\
**Last updated:** [October 5, 2018, 1:07am UTC](https://discuss.elastic.co/t/dropping-events-using-winlogbeat-processors/150781 "2018-10-05T01:07:43Z")

</div>

Good morning! I've done some reading in Winlogbeat's documentation and wanted to confirm the syntax of a processor that I'm trying to implement. I have a noisy event that I want to drop before it makes it to Logstash -…

---

## [Process logs in json with a "message" key not working with filebeat 6.4.1](https://discuss.elastic.co/t/process-logs-in-json-with-a-message-key-not-working-with-filebeat-6-4-1/150688)

<div class="topic-metadata">

**Author:** [@MatMatMatMatMatMat](https://discuss.elastic.co/u/MatMatMatMatMatMat)\
**Replies:** 3\
**Last updated:** [October 4, 2018, 9:38am UTC](https://discuss.elastic.co/t/process-logs-in-json-with-a-message-key-not-working-with-filebeat-6-4-1/150688 "2018-10-04T09:38:56Z")

</div>

Hello, I have an app that produce logs in that form : { "time": "2018-10-01T16:59:33+02:00", "level": "INFO", "component\_name": "test", "request\_type": "incomming\_request", "request\_peer": "front", "session\_id": …

---

## [Filebeat output to AWS Kinesis Stream or Firehose](https://discuss.elastic.co/t/filebeat-output-to-aws-kinesis-stream-or-firehose/151005)

<div class="topic-metadata">

**Author:** [@John-Pierre\_Atallah](https://discuss.elastic.co/u/John-Pierre_Atallah)\
**Replies:** 1\
**Last updated:** [October 4, 2018, 9:36am UTC](https://discuss.elastic.co/t/filebeat-output-to-aws-kinesis-stream-or-firehose/151005 "2018-10-04T09:36:49Z")

</div>

Hello friends, I'm looking to utilize a complete AWS services infrastructure to send application logs into AWS's ES domain service. I'm currently using filebeats. However, I don't see the ability to specify a firehose …

---

## [Exclude file from being processed](https://discuss.elastic.co/t/exclude-file-from-being-processed/150778)

<div class="topic-metadata">

**Author:** [@bdobsonca](https://discuss.elastic.co/u/bdobsonca)\
**Replies:** 5\
**Last updated:** [October 4, 2018, 9:23am UTC](https://discuss.elastic.co/t/exclude-file-from-being-processed/150778 "2018-10-04T09:23:05Z")

</div>

Hello, I have /var/log/elasticsearch/gc.log.0.current currently flooding my logs. I would like to know the best way to exclude this? I am running Filebeats 6.4.2. I have tried: exclude\_files with the following: \['\\.cur…

---

## [What happens when truncating file?](https://discuss.elastic.co/t/what-happens-when-truncating-file/150668)

<div class="topic-metadata">

**Author:** [@iqjumps](https://discuss.elastic.co/u/iqjumps)\
**Replies:** 3\
**Last updated:** [October 4, 2018, 9:12am UTC](https://discuss.elastic.co/t/what-happens-when-truncating-file/150668 "2018-10-04T09:12:43Z")

</div>

I use logrotate utility and it executes ftruncate(fdcurr, 0) in copytruncate mode When it truncates file which Filebeat was reading, Will Filebeat's offset reset to zero or throw error? Thanks

---

## [How to get status of Zombie process in mertricbeat metrics?](https://discuss.elastic.co/t/how-to-get-status-of-zombie-process-in-mertricbeat-metrics/150845)

<div class="topic-metadata">

**Author:** [@Aftab\_Ali](https://discuss.elastic.co/u/Aftab_Ali)\
**Replies:** 4\
**Last updated:** [October 4, 2018, 9:10am UTC](https://discuss.elastic.co/t/how-to-get-status-of-zombie-process-in-mertricbeat-metrics/150845 "2018-10-04T09:10:13Z")

</div>

Dear Team, I tried many times to get the status of zombies process, I did not get a zombie process, I followed the steps, please help me.

---

## [SSH and Syslog not reaching on kibana](https://discuss.elastic.co/t/ssh-and-syslog-not-reaching-on-kibana/150967)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 2\
**Last updated:** [October 4, 2018, 7:49am UTC](https://discuss.elastic.co/t/ssh-and-syslog-not-reaching-on-kibana/150967 "2018-10-04T07:49:11Z")

</div>

Hello Team, I am using ELK 6.4.0 and beat (Filebeat) 6.4.0. My architecture is Filebeat-\>Logstash-\>Elasticsearch-\>Kibana. I have installed Filebeat on my 20 servers and sending auth.log, syslog, nginx access.log and ap…

---

## [Can't able to create index in ES via filebeat](https://discuss.elastic.co/t/cant-able-to-create-index-in-es-via-filebeat/150227)

<div class="topic-metadata">

**Author:** [@prem\_kumar](https://discuss.elastic.co/u/prem_kumar)\
**Replies:** 2\
**Last updated:** [October 3, 2018, 1:29pm UTC](https://discuss.elastic.co/t/cant-able-to-create-index-in-es-via-filebeat/150227 "2018-10-03T13:29:06Z")

</div>

I am new to ELK and I am trying to load logs from Filebeats to ES but index are not getting created. I have looked into lot of threads in this forum regarding this but I can't able to find a solution. I can able to load…

---

## [Monitoring Filebeat via Centreon](https://discuss.elastic.co/t/monitoring-filebeat-via-centreon/150841)

<div class="topic-metadata">

**Author:** [@Arcturus999](https://discuss.elastic.co/u/Arcturus999)\
**Replies:** 1\
**Last updated:** [October 3, 2018, 9:52am UTC](https://discuss.elastic.co/t/monitoring-filebeat-via-centreon/150841 "2018-10-03T09:52:59Z")

</div>

Hi guys, We've been using Filebeat for quite some time now, and as our infrastructure is increasing in size, we begun to have more and more Filebeats accross our servers. We are currently using Centreon to monitor our i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=413)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=415)
