# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=415

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 416

---

## [Filebeat multi source logs problem](https://discuss.elastic.co/t/filebeat-multi-source-logs-problem/147850)

<div class="topic-metadata">

**Author:** [@abu.sayeed](https://discuss.elastic.co/u/abu.sayeed)\
**Replies:** 2\
**Last updated:** [October 3, 2018, 9:52am UTC](https://discuss.elastic.co/t/filebeat-multi-source-logs-problem/147850 "2018-10-03T09:52:19Z")

</div>

cat /etc/filebeat/filebeat.yml filebeat.config.modules: path: /etc/filebeat/modules.d/\*.yml reload.enabled: false filebeat.inputs: - type: log enabled: false paths: - /var/log/\*.log - /home/local/example/e…

---

## [Redis input plugin back pressure issue](https://discuss.elastic.co/t/redis-input-plugin-back-pressure-issue/150826)

<div class="topic-metadata">

**Author:** [@Leo\_Kwok](https://discuss.elastic.co/u/Leo_Kwok)\
**Replies:** 6\
**Last updated:** [October 3, 2018, 9:31am UTC](https://discuss.elastic.co/t/redis-input-plugin-back-pressure-issue/150826 "2018-10-03T09:31:56Z")

</div>

Hi, we are using ELK 6.3 with the data flow Filebeat -\> Redis -\> Logstash -\> Elasticsearch. During the last few days we are doing several round of failure tests to study the impact of components down. We noticed when Red…

---

## [Winlogbeat will no longer start](https://discuss.elastic.co/t/winlogbeat-will-no-longer-start/150819)

<div class="topic-metadata">

**Author:** [@popa](https://discuss.elastic.co/u/popa)\
**Replies:** 3\
**Last updated:** [October 3, 2018, 8:24am UTC](https://discuss.elastic.co/t/winlogbeat-will-no-longer-start/150819 "2018-10-03T08:24:17Z")

</div>

I made a configuration change to winlogbeat.yml then issued a Restart-Service winlogbeat. I've done this several times in the past when updating my configuration file without any issues. However, this time the winlogbea…

---

## [Could this be a bug? Not CRLF but LF is used in metricbeat.yml of Windows package](https://discuss.elastic.co/t/could-this-be-a-bug-not-crlf-but-lf-is-used-in-metricbeat-yml-of-windows-package/150809)

<div class="topic-metadata">

**Author:** [@sakurai-youhei](https://discuss.elastic.co/u/sakurai-youhei)\
**Replies:** 2\
**Last updated:** [October 3, 2018, 8:23am UTC](https://discuss.elastic.co/t/could-this-be-a-bug-not-crlf-but-lf-is-used-in-metricbeat-yml-of-windows-package/150809 "2018-10-03T08:23:22Z")

</div>

Hello, Because GitHub issue template suggests questioning here first, I'm opening this topic. Would anyone please authorize this is worth being recorded to GitHub issue as a bug or at least a valuable feature request? …

---

## [Syslog, SSH Login Attempt and Nginx dashboard for Filebeat](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 7\
**Last updated:** [October 3, 2018, 8:01am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652 "2018-10-03T08:01:21Z")

</div>

Hello Team, I am using Logstash pipeline so i can use dashboards available with Filebeat to visualize data in Kibana. I have followed the below link: https://www.elastic.co/guide/en/logstash/5.6/filebeat-modules.html …

---

## [Winlogbeat and ECS](https://discuss.elastic.co/t/winlogbeat-and-ecs/149001)

<div class="topic-metadata">

**Author:** [@thegrockq](https://discuss.elastic.co/u/thegrockq)\
**Replies:** 7\
**Last updated:** [October 2, 2018, 9:33pm UTC](https://discuss.elastic.co/t/winlogbeat-and-ecs/149001 "2018-10-02T21:33:51Z")

</div>

Is there any current or completed effort to convert Windows event log fields to comply with ECS? I've parsed the schema for security-audit logs and made an initial pass through them to convert appropriate fields to what…

---

## [Filebeat 6.3.2 syslogs are not logging to elastcisearch](https://discuss.elastic.co/t/filebeat-6-3-2-syslogs-are-not-logging-to-elastcisearch/149490)

<div class="topic-metadata">

**Author:** [@mouli\_v](https://discuss.elastic.co/u/mouli_v)\
**Replies:** 14\
**Last updated:** [October 2, 2018, 8:34pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-syslogs-are-not-logging-to-elastcisearch/149490 "2018-10-02T20:34:55Z")

</div>

System module is enabled, but syslogs are logging with 7hrs delay. Adjusted var.convert\_timezone: true in /etc/filebeat/modules.d/system.yml, still no luck. Can someone take a look into it. /etc/filebeat/modules.d/syste…

---

## [Metricbeat process metricset fails to run](https://discuss.elastic.co/t/metricbeat-process-metricset-fails-to-run/150498)

<div class="topic-metadata">

**Author:** [@koko191](https://discuss.elastic.co/u/koko191)\
**Replies:** 1\
**Last updated:** [October 2, 2018, 8:24pm UTC](https://discuss.elastic.co/t/metricbeat-process-metricset-fails-to-run/150498 "2018-10-02T20:24:59Z")

</div>

Some context on my issue: I am trying to run Metricbeat as a service on a Windows machine. Metricbeat was installed using Chocolatey and the Metricbeat service was also installed using the script from Chocolatey. These …

---

## [Metricbeat Logstash output more frequent than YML files specify](https://discuss.elastic.co/t/metricbeat-logstash-output-more-frequent-than-yml-files-specify/149980)

<div class="topic-metadata">

**Author:** [@fxr801](https://discuss.elastic.co/u/fxr801)\
**Replies:** 3\
**Last updated:** [October 2, 2018, 8:18pm UTC](https://discuss.elastic.co/t/metricbeat-logstash-output-more-frequent-than-yml-files-specify/149980 "2018-10-02T20:18:21Z")

</div>

Hi All, I recently installed Metricbeat on a server with just the default System module, and CPU and Memory metricsets enabled. I set the period in both the metricbeat and system YML files to be 10 seconds, and set the…

---

## [Configuring Auditbeat to only report modifications to files I want to monitor](https://discuss.elastic.co/t/configuring-auditbeat-to-only-report-modifications-to-files-i-want-to-monitor/150611)

<div class="topic-metadata">

**Author:** [@nnarain](https://discuss.elastic.co/u/nnarain)\
**Replies:** 6\
**Last updated:** [October 2, 2018, 6:33pm UTC](https://discuss.elastic.co/t/configuring-auditbeat-to-only-report-modifications-to-files-i-want-to-monitor/150611 "2018-10-02T18:33:31Z")

</div>

Hey, I'd like some advice on configuring my Auditbeat instance to report modifications to the files I've specified. I get a lot of other entries into my elastic index that are not relevant to the rules I've specified. C…

---

## [Filebeat "fatal error: concurrent map iteration and map write"](https://discuss.elastic.co/t/filebeat-fatal-error-concurrent-map-iteration-and-map-write/150736)

<div class="topic-metadata">

**Author:** [@shoffmeister](https://discuss.elastic.co/u/shoffmeister)\
**Replies:** 3\
**Last updated:** [October 2, 2018, 6:03pm UTC](https://discuss.elastic.co/t/filebeat-fatal-error-concurrent-map-iteration-and-map-write/150736 "2018-10-02T18:03:03Z")

</div>

Hi, on startup of the filebeat 6.4.0 docker image I get "fatal error: concurrent map iteration and map write" I am aware of the thread Filebeat Autodiscover gives fatal error: concurrent map iteration and map write whi…

---

## [TTY logging decoding](https://discuss.elastic.co/t/tty-logging-decoding/150548)

<div class="topic-metadata">

**Author:** [@bluiks](https://discuss.elastic.co/u/bluiks)\
**Replies:** 12\
**Last updated:** [October 2, 2018, 4:31pm UTC](https://discuss.elastic.co/t/tty-logging-decoding/150548 "2018-10-02T16:31:26Z")

</div>

I did not try Auditbeat yet, but based on what I read so far it does not support decoding type=USER\_TTY or type=TTY audit records. Is this correct? If it is correct, then this would be extremely disappointing. It would …

---

## [ARM support](https://discuss.elastic.co/t/arm-support/142235)

<div class="topic-metadata">

**Author:** [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Replies:** 10\
**Last updated:** [October 2, 2018, 3:07pm UTC](https://discuss.elastic.co/t/arm-support/142235 "2018-10-02T15:07:41Z")

</div>

Has there been any discussion regarding adding official arm64 support for Beats? I feel like this just makes sense since with IoT / sensor data collection you'd want some sort of "lightweight data shipper" to Elasticsear…

---

## [Filebeat parsing logs with timedate utc](https://discuss.elastic.co/t/filebeat-parsing-logs-with-timedate-utc/148362)

<div class="topic-metadata">

**Author:** [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Replies:** 2\
**Last updated:** [October 2, 2018, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-parsing-logs-with-timedate-utc/148362 "2018-10-02T13:00:59Z")

</div>

Hi I have running a server with filebeat to parse all linux centos log files. My filebeat.yml be default: filebeat.inputs: type: log enabled: true paths: /var/log/\*.log document\_type: syslog Output direct to…

---

## [Metricbeat autodiscovery kubernetes](https://discuss.elastic.co/t/metricbeat-autodiscovery-kubernetes/139328)

<div class="topic-metadata">

**Author:** [@mat1010](https://discuss.elastic.co/u/mat1010)\
**Replies:** 21\
**Last updated:** [October 2, 2018, 11:39am UTC](https://discuss.elastic.co/t/metricbeat-autodiscovery-kubernetes/139328 "2018-10-02T11:39:58Z")

</div>

I'm running metricbeat 6.3.0 with autodiscovery enabled as daemonset on my K8s cluster in GCP as described in the documentation The autodiscovery works fine once I attach the proper annotations to my pods. Anyway once I…

---

## [JSON logs not being uploaded](https://discuss.elastic.co/t/json-logs-not-being-uploaded/150646)

<div class="topic-metadata">

**Author:** [@etoews](https://discuss.elastic.co/u/etoews)\
**Replies:** 3\
**Last updated:** [October 2, 2018, 10:24am UTC](https://discuss.elastic.co/t/json-logs-not-being-uploaded/150646 "2018-10-02T10:24:16Z")

</div>

I've configured Filebeat to harvest some OpenShift Audit logs. The logs are in JSON format so I'm using the JSON Log input. However, the logs simply aren't getting uploaded to ElasticSearch (via Logstash). Well...I'm un…

---

## [Intentionally delaying log harvesting at startup](https://discuss.elastic.co/t/intentionally-delaying-log-harvesting-at-startup/149855)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 6\
**Last updated:** [October 2, 2018, 8:39am UTC](https://discuss.elastic.co/t/intentionally-delaying-log-harvesting-at-startup/149855 "2018-10-02T08:39:52Z")

</div>

I have a use case where I need to delay the log harvesting. As I read my best option would be scan\_frequency but I'm not sure if that applies for the first start and how it keeps track of this information (I suspect that…

---

## [Libbeat does not allow updates when publishing to Elasticsearch?](https://discuss.elastic.co/t/libbeat-does-not-allow-updates-when-publishing-to-elasticsearch/148031)

<div class="topic-metadata">

**Author:** [@stoth](https://discuss.elastic.co/u/stoth)\
**Replies:** 4\
**Last updated:** [October 2, 2018, 4:09am UTC](https://discuss.elastic.co/t/libbeat-does-not-allow-updates-when-publishing-to-elasticsearch/148031 "2018-10-02T04:09:03Z")

</div>

NOTE: After doing additional research and managing to find the code preventing updates, I've revised this post to be more accurate and succinct. ISSUE: When using the beat.Client to publish \[bulk\] beat.Events to the Ela…

---

## [Packetbeat not sending logs to kibana](https://discuss.elastic.co/t/packetbeat-not-sending-logs-to-kibana/150618)

<div class="topic-metadata">

**Author:** [@David\_Moreno](https://discuss.elastic.co/u/David_Moreno)\
**Replies:** 1\
**Last updated:** [October 1, 2018, 10:11pm UTC](https://discuss.elastic.co/t/packetbeat-not-sending-logs-to-kibana/150618 "2018-10-01T22:11:48Z")

</div>

Hello, I'm playing around packetbeat to add in my elk stack for a log management. My packetbeat runs, I check on its status and it says its running. When I go to its log files I see this: 2018-10-01T14:09:02.414-0700 IN…

---

## [Failed to parse\[host\]?](https://discuss.elastic.co/t/failed-to-parse-host/150489)

<div class="topic-metadata">

**Author:** [@paulkeogh](https://discuss.elastic.co/u/paulkeogh)\
**Replies:** 3\
**Last updated:** [October 1, 2018, 8:17pm UTC](https://discuss.elastic.co/t/failed-to-parse-host/150489 "2018-10-01T20:17:23Z")

</div>

I am developing a custom beats client. After a recent upgrade on my elastic server, the beat is now failing to publish with an error of; 2018-09-30T22:25:17.152+0100 WARN elasticsearch/client.go:520 Canno…

---

## [Can Filebeat halt on failed published event?](https://discuss.elastic.co/t/can-filebeat-halt-on-failed-published-event/149956)

<div class="topic-metadata">

**Author:** [@tunder](https://discuss.elastic.co/u/tunder)\
**Replies:** 4\
**Last updated:** [September 30, 2018, 10:43am UTC](https://discuss.elastic.co/t/can-filebeat-halt-on-failed-published-event/149956 "2018-09-30T10:43:21Z")

</div>

Hi, Is there such an option to stop publishing (anything new) when output fails for whatever reason? To give an example My Filebeat config (minimal) is like this: filebeat.prospectors: - type: log json.keys\_under\_r…

---

## [Filebeat audit module and close\_timeout](https://discuss.elastic.co/t/filebeat-audit-module-and-close-timeout/150560)

<div class="topic-metadata">

**Author:** [@mikkop71](https://discuss.elastic.co/u/mikkop71)\
**Replies:** 1\
**Last updated:** [October 1, 2018, 11:30am UTC](https://discuss.elastic.co/t/filebeat-audit-module-and-close-timeout/150560 "2018-10-01T11:30:32Z")

</div>

Version: 5.4.1 We have a problem that Filebeat keeps audit log file locked after log rotation. Restarting Filebeat is workaround to the issue. Question is can we use close\_timeout with this module or is there some equ…

---

## [Startup error in auditbeat](https://discuss.elastic.co/t/startup-error-in-auditbeat/150520)

<div class="topic-metadata">

**Author:** [@Balamurali](https://discuss.elastic.co/u/Balamurali)\
**Replies:** 2\
**Last updated:** [October 1, 2018, 10:39am UTC](https://discuss.elastic.co/t/startup-error-in-auditbeat/150520 "2018-10-01T10:39:49Z")

</div>

Hi All, I'm getting below startup error in auditbeat tar package installation. 2018-10-01T00:00:12.242-0700 ERROR instance/beat.go:743 Exiting: 1 error: 1 error: failed to unpack the auditd config: 1 error: failed load…

---

## [Packetbeat Flows and Kubernetes not working fine](https://discuss.elastic.co/t/packetbeat-flows-and-kubernetes-not-working-fine/149725)

<div class="topic-metadata">

**Author:** [@rikatz](https://discuss.elastic.co/u/rikatz)\
**Replies:** 1\
**Last updated:** [October 1, 2018, 10:24am UTC](https://discuss.elastic.co/t/packetbeat-flows-and-kubernetes-not-working-fine/149725 "2018-10-01T10:24:52Z")

</div>

I've been trying to use Packetbeat to map my Kubernetes Cluster traffic without success. The idea here is to use Packetbeat to map all the flows from the Cluster and store them into Elasticsearch, enriching those events…

---

## [Winlogbeat disconnects every 10min](https://discuss.elastic.co/t/winlogbeat-disconnects-every-10min/149443)

<div class="topic-metadata">

**Author:** [@Wintermute2k6](https://discuss.elastic.co/u/Wintermute2k6)\
**Replies:** 2\
**Last updated:** [October 1, 2018, 9:34am UTC](https://discuss.elastic.co/t/winlogbeat-disconnects-every-10min/149443 "2018-10-01T09:34:11Z")

</div>

Hi ! I have an small issue with an winlogbeat. It works but unexpectedly it is disconnected somehow evey 10 minutes. 2018-09-20T10:03:29.716+0200 ERROR logstash/async.go:252 Failed to publish events caused by: write t…

---

## [Beat wich Trigger script on server for ELK](https://discuss.elastic.co/t/beat-wich-trigger-script-on-server-for-elk/149795)

<div class="topic-metadata">

**Author:** [@bab](https://discuss.elastic.co/u/bab)\
**Replies:** 1\
**Last updated:** [October 1, 2018, 8:32am UTC](https://discuss.elastic.co/t/beat-wich-trigger-script-on-server-for-elk/149795 "2018-10-01T08:32:21Z")

</div>

hi all, I need a beat which can trigger scripts on the server and document their result for ELK stack 6.3. some like Topbeat . any idea can help pleas. Thnak you

---

## [Docker swarm container log monitoring - require help](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115)

<div class="topic-metadata">

**Author:** [@sl1729](https://discuss.elastic.co/u/sl1729)\
**Replies:** 4\
**Last updated:** [October 1, 2018, 7:20am UTC](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115 "2018-10-01T07:20:38Z")

</div>

Hello All, We got filebeat monitoring setup for the VM hosted apps and now trying to monitor logs of containers of docker swarm setup which uses json-file as a logging driver. I have a filebeat (docker worker node) --\> …

---

## [How to execute multiple.yml files in single filebeat instan e](https://discuss.elastic.co/t/how-to-execute-multiple-yml-files-in-single-filebeat-instan-e/150168)

<div class="topic-metadata">

**Author:** [@Goyal.vikas87](https://discuss.elastic.co/u/Goyal.vikas87)\
**Replies:** 3\
**Last updated:** [October 1, 2018, 7:18am UTC](https://discuss.elastic.co/t/how-to-execute-multiple-yml-files-in-single-filebeat-instan-e/150168 "2018-10-01T07:18:59Z")

</div>

I have 2.yml files placed in a directory say /root/input.d. I want to execute both files using one filebeat instance. Also whenever new filebeat.yml is placed in same directory, filebeat picks new yml automatically. And…

---

## [How to configure jolokia with tomcat using metricbeat?](https://discuss.elastic.co/t/how-to-configure-jolokia-with-tomcat-using-metricbeat/149541)

<div class="topic-metadata">

**Author:** [@Aftab\_Ali](https://discuss.elastic.co/u/Aftab_Ali)\
**Replies:** 6\
**Last updated:** [October 1, 2018, 7:11am UTC](https://discuss.elastic.co/t/how-to-configure-jolokia-with-tomcat-using-metricbeat/149541 "2018-10-01T07:11:31Z")

</div>

Dear Team, I want to see Tomcat internal metric like JVM memory and Threads count and more, i followed the steps:- Step 1:- download the JAVA agent from https://jolokia.org/download.html package name is jolokia-jvm-1…

---

## [Filebeat system module](https://discuss.elastic.co/t/filebeat-system-module/150283)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 6\
**Last updated:** [October 1, 2018, 7:07am UTC](https://discuss.elastic.co/t/filebeat-system-module/150283 "2018-10-01T07:07:55Z")

</div>

Hello Team, I am using ELK 6.4.0 and Beats (Filebeat, Metricbeat) 6.4.0. Currently my architecture is Beat-\>Logstash-\>Elasticsearch-\>Kibana. I am using Filebeat System module and ouput in filebeat.yml is logstash. In t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=414)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=416)
