# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=416

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 417

---

## [404 from jolokia module](https://discuss.elastic.co/t/404-from-jolokia-module/147716)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 6\
**Last updated:** [October 1, 2018, 7:07am UTC](https://discuss.elastic.co/t/404-from-jolokia-module/147716 "2018-10-01T07:07:23Z")

</div>

I had a working setup with cassandra + jmx + jolokia + metricbeat not too long ago. Lately Im only getting the message : "HTTP Error 404 in jmx: 404 not found". Presently runnign 6.4. Have tried downgrading to 6.3 to no…

---

## [Multiline Match](https://discuss.elastic.co/t/multiline-match/150499)

<div class="topic-metadata">

**Author:** [@Esity](https://discuss.elastic.co/u/Esity)\
**Replies:** 2\
**Last updated:** [October 1, 2018, 6:31am UTC](https://discuss.elastic.co/t/multiline-match/150499 "2018-10-01T06:31:39Z")

</div>

So I am trying to get multiline to work and am doing something stupid. Anyone see anything inherently wrong? - type: log paths: - "/var/log/elasticsearch/elasticsearch.log" tags: \[ "elasticsearch" \] multiline.patt…

---

## [Filebeat to kafka with Kerberos + SSL](https://discuss.elastic.co/t/filebeat-to-kafka-with-kerberos-ssl/150466)

<div class="topic-metadata">

**Author:** [@cmcbugg](https://discuss.elastic.co/u/cmcbugg)\
**Replies:** 1\
**Last updated:** [October 1, 2018, 6:28am UTC](https://discuss.elastic.co/t/filebeat-to-kafka-with-kerberos-ssl/150466 "2018-10-01T06:28:27Z")

</div>

Hi. I know it’s been asked before, but not seen any update in last year ... can filebeats support Kafka with Kerberos + SSL yet (SASL\_SSL)? Thanks.

---

## [Multiple Filebeat Inputs Files](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348)

<div class="topic-metadata">

**Author:** [@Esity](https://discuss.elastic.co/u/Esity)\
**Replies:** 4\
**Last updated:** [October 1, 2018, 3:20am UTC](https://discuss.elastic.co/t/multiple-filebeat-inputs-files/149348 "2018-10-01T03:20:10Z")

</div>

I was wondering if it is possible to have a conf.d type folder for filebeat to create multiple input items. I know I can list them all in filebeat.yml but that isn't preferable. I also don't think it makes sense to use a…

---

## [Correct way to Start and Stop Winlogbeat with Powershell](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428)

<div class="topic-metadata">

**Author:** [@JKCode](https://discuss.elastic.co/u/JKCode)\
**Replies:** 5\
**Last updated:** [September 30, 2018, 8:17am UTC](https://discuss.elastic.co/t/correct-way-to-start-and-stop-winlogbeat-with-powershell/149428 "2018-09-30T08:17:13Z")

</div>

Hi All, Newbie Alert!! I have been facing issues using Winlogbeats to ship localhost logs (application, system, security, etc.) to Elasticsearch. I have been following the instructions in the documentation, however, I…

---

## [Filebeat to read Log files from sFTP?](https://discuss.elastic.co/t/filebeat-to-read-log-files-from-sftp/150219)

<div class="topic-metadata">

**Author:** [@ratman](https://discuss.elastic.co/u/ratman)\
**Replies:** 2\
**Last updated:** [September 28, 2018, 9:30pm UTC](https://discuss.elastic.co/t/filebeat-to-read-log-files-from-sftp/150219 "2018-09-28T21:30:21Z")

</div>

Hello! I have some \*.log files located at a server I can access via sFTP. So far, I am bringing them to my Elastic machine manually but I'd like to automatise the process. Is there a way to set Filebeat to rretrieve al…

---

## [Kubernetes module 6.2.4 vs 6.4.0 : cpu usage x3](https://discuss.elastic.co/t/kubernetes-module-6-2-4-vs-6-4-0-cpu-usage-x3/148591)

<div class="topic-metadata">

**Author:** [@hamelg](https://discuss.elastic.co/u/hamelg)\
**Replies:** 5\
**Last updated:** [September 28, 2018, 2:41pm UTC](https://discuss.elastic.co/t/kubernetes-module-6-2-4-vs-6-4-0-cpu-usage-x3/148591 "2018-09-28T14:41:37Z")

</div>

We have a pod running the module kubernetes in our openshift cluster. We had upgraded metricbeat from 6.2.4 to 6.4.0. We have noticed that metricbeat 6.4.0 consummates 3 times cpu than 6.2.4. Here is our the metricbeat …

---

## [Filebeat clients specified by ip addresses for 'force\_peer'](https://discuss.elastic.co/t/filebeat-clients-specified-by-ip-addresses-for-force-peer/150009)

<div class="topic-metadata">

**Author:** [@peter\_j](https://discuss.elastic.co/u/peter_j)\
**Replies:** 2\
**Last updated:** [September 28, 2018, 2:27pm UTC](https://discuss.elastic.co/t/filebeat-clients-specified-by-ip-addresses-for-force-peer/150009 "2018-09-28T14:27:25Z")

</div>

Hello I'm authenticating FileBeat clients on Logstash over ssl (ssl\_verify\_mode: force\_peer). I created self signed cert ../bin/elasticsearch-certutil ca --pem --silent --out ca.zip then generated logstash and filebe…

---

## [Getting logs from pods via filebeat](https://discuss.elastic.co/t/getting-logs-from-pods-via-filebeat/150274)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [September 28, 2018, 2:19pm UTC](https://discuss.elastic.co/t/getting-logs-from-pods-via-filebeat/150274 "2018-09-28T14:19:59Z")

</div>

Im hoping to get logs from my k8 pods (which are writing to stdout/stderr) via filebeat. At this point all Im seeing are what's being written to /var/log/messages on the k8 host. Ive started the daemonset sample from ht…

---

## [Connect filebeat to elasticsearch](https://discuss.elastic.co/t/connect-filebeat-to-elasticsearch/150240)

<div class="topic-metadata">

**Author:** [@mcoa](https://discuss.elastic.co/u/mcoa)\
**Replies:** 1\
**Last updated:** [September 28, 2018, 1:09pm UTC](https://discuss.elastic.co/t/connect-filebeat-to-elasticsearch/150240 "2018-09-28T13:09:25Z")

</div>

Hello, i've a filebeat-6.4.1-1 and try connect to ELK (elasticsearch-5.6 and kibana-5.6.12) but not connect and not index create in to Kibana. My filebeat.yml is: filebeat.inputs: - type: log enabled: true paths: …

---

## [Filebeat NATS output](https://discuss.elastic.co/t/filebeat-nats-output/150263)

<div class="topic-metadata">

**Author:** [@mtmk](https://discuss.elastic.co/u/mtmk)\
**Replies:** 1\
**Last updated:** [September 28, 2018, 1:04pm UTC](https://discuss.elastic.co/t/filebeat-nats-output/150263 "2018-09-28T13:04:09Z")

</div>

Is there anyone wanting to use NATS as output to Filebeat? Specifically the NATS Streaming Server: https://github.com/nats-io/nats-streaming-server I have some experience with Kafka (and I would use Kafka if my attempt…

---

## [Can filebeat delete the file after complete the transfer](https://discuss.elastic.co/t/can-filebeat-delete-the-file-after-complete-the-transfer/150289)

<div class="topic-metadata">

**Author:** [@walkexk](https://discuss.elastic.co/u/walkexk)\
**Replies:** 2\
**Last updated:** [September 28, 2018, 8:17am UTC](https://discuss.elastic.co/t/can-filebeat-delete-the-file-after-complete-the-transfer/150289 "2018-09-28T08:17:08Z")

</div>

or touch off a script to do the delete.

---

## [Filebeat issue in configuration file](https://discuss.elastic.co/t/filebeat-issue-in-configuration-file/147062)

<div class="topic-metadata">

**Author:** [@amritesh\_mishra](https://discuss.elastic.co/u/amritesh_mishra)\
**Replies:** 13\
**Last updated:** [September 5, 2018, 12:12pm UTC](https://discuss.elastic.co/t/filebeat-issue-in-configuration-file/147062 "2018-09-05T12:12:15Z")

</div>

We have created this config file but file beat is sending only one file at a time it is not sending the second path file which i have put in the filebeat config file. this is the config filebeat: prospectors: paths:…

---

## [Http module: "invalid character '\<' looking for beginning of value"](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082)

<div class="topic-metadata">

**Author:** [@MarkusB](https://discuss.elastic.co/u/MarkusB)\
**Replies:** 8\
**Last updated:** [September 27, 2018, 10:36am UTC](https://discuss.elastic.co/t/http-module-invalid-character-looking-for-beginning-of-value/148082 "2018-09-27T10:36:25Z")

</div>

Hi all, My first steps with Elastic, so maybe a dumb question. Running 6.4.0 with Metricbeat http module polling a SmartMeter. Test with Google Chrome: http://192.168.13.50:8080/xml/json.php?mode=infomin JSON Reply o…

---

## [Statsdbeat available](https://discuss.elastic.co/t/statsdbeat-available/149524)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 3\
**Last updated:** [September 27, 2018, 8:12am UTC](https://discuss.elastic.co/t/statsdbeat-available/149524 "2018-09-27T08:12:13Z")

</div>

Listening for UDP statsd packages and sending them to ElasticSearch Source code here: We use it for storing application counters (submitted via a statsdclient) into Elastic Search e.g. https://github.com/alexcesaro…

---

## [Error: no buffer space available](https://discuss.elastic.co/t/error-no-buffer-space-available/149535)

<div class="topic-metadata">

**Author:** [@Sanjeev\_Gopal](https://discuss.elastic.co/u/Sanjeev_Gopal)\
**Replies:** 1\
**Last updated:** [September 27, 2018, 2:53am UTC](https://discuss.elastic.co/t/error-no-buffer-space-available/149535 "2018-09-27T02:53:49Z")

</div>

Am using Heartbeat to ICMP check 2500+ endpoints, and over double the number of TCP ports. On a RHEL 6 bare metal server, there are no issues. But on an Ubuntu 18 VM, I'm starting to see a large number of these errors: …

---

## [Track individual sql statements executed in a DB](https://discuss.elastic.co/t/track-individual-sql-statements-executed-in-a-db/149721)

<div class="topic-metadata">

**Author:** [@wat0075](https://discuss.elastic.co/u/wat0075)\
**Replies:** 5\
**Last updated:** [September 27, 2018, 12:44am UTC](https://discuss.elastic.co/t/track-individual-sql-statements-executed-in-a-db/149721 "2018-09-27T00:44:29Z")

</div>

Hello group, I am an ES newbie and one of the things I am looking at is to use ES to monitor our databases to track the sql statements that are being executed in the database over time. With this solution I would like …

---

## [Dashboard setup failure](https://discuss.elastic.co/t/dashboard-setup-failure/149922)

<div class="topic-metadata">

**Author:** [@relentless](https://discuss.elastic.co/u/relentless)\
**Replies:** 3\
**Last updated:** [September 26, 2018, 10:36pm UTC](https://discuss.elastic.co/t/dashboard-setup-failure/149922 "2018-09-26T22:36:27Z")

</div>

Hi I'm trying to perform the dashboard setup. Using kibana 5.6.9 Receive the following error on setup. Using the command metricbeat -c metricbeat.yml setup --dashboards error loading C:\\temp\\metricbeat\\kibana\\5\\inde…

---

## [About date format](https://discuss.elastic.co/t/about-date-format/149934)

<div class="topic-metadata">

**Author:** [@liwenlin](https://discuss.elastic.co/u/liwenlin)\
**Replies:** 1\
**Last updated:** [September 26, 2018, 9:47pm UTC](https://discuss.elastic.co/t/about-date-format/149934 "2018-09-26T21:47:41Z")

</div>

@timestamp format is like this 2018-09-26T04:27:03.368Z。but this is not what i want. is there any method to transfer it to yyyy-MM-dd HH:mm:ss or add a new field as yyyy-MM-dd HH:mm:ss ? Thank you.

---

## [Identify Whether a message sent by Filebeat is Multiline or not](https://discuss.elastic.co/t/identify-whether-a-message-sent-by-filebeat-is-multiline-or-not/150032)

<div class="topic-metadata">

**Author:** [@KumarSaurabh](https://discuss.elastic.co/u/KumarSaurabh)\
**Replies:** 1\
**Last updated:** [September 26, 2018, 9:22pm UTC](https://discuss.elastic.co/t/identify-whether-a-message-sent-by-filebeat-is-multiline-or-not/150032 "2018-09-26T21:22:42Z")

</div>

I am working on FileBeat 6.4 and sending data to logstash. I am using multiline settings to send java exception stack trace. Is there any metadata sent to logstash by FIlebeat when it sends multiline message? If no, th…

---

## [JSON Line Splitting inside string logs](https://discuss.elastic.co/t/json-line-splitting-inside-string-logs/150022)

<div class="topic-metadata">

**Author:** [@sbienert](https://discuss.elastic.co/u/sbienert)\
**Replies:** 1\
**Last updated:** [September 26, 2018, 9:21pm UTC](https://discuss.elastic.co/t/json-line-splitting-inside-string-logs/150022 "2018-09-26T21:21:18Z")

</div>

Hello, I have normal string logs from Log4j. Some of them contain JSON queries inside but Filebeat writes them to Elasticsearch as if each line of the JSON is a separate log because as of right now I only have the defau…

---

## [/usr/local/bin/docker-entrypoint: line 8: exec: filebeat: not found](https://discuss.elastic.co/t/usr-local-bin-docker-entrypoint-line-8-exec-filebeat-not-found/149935)

<div class="topic-metadata">

**Author:** [@elk11](https://discuss.elastic.co/u/elk11)\
**Replies:** 1\
**Last updated:** [September 26, 2018, 9:14pm UTC](https://discuss.elastic.co/t/usr-local-bin-docker-entrypoint-line-8-exec-filebeat-not-found/149935 "2018-09-26T21:14:57Z")

</div>

I deployed filebeat container through ansible. The container went in restarting loop. Below is the output of 'docker logs filebeat' /usr/local/bin/docker-entrypoint: line 8: exec: filebeat: not found /usr/local/bin/doc…

---

## [Apache module bad timestamp from error log file](https://discuss.elastic.co/t/apache-module-bad-timestamp-from-error-log-file/149893)

<div class="topic-metadata">

**Author:** [@Aurelien\_Bras](https://discuss.elastic.co/u/Aurelien_Bras)\
**Replies:** 1\
**Last updated:** [September 26, 2018, 9:13pm UTC](https://discuss.elastic.co/t/apache-module-bad-timestamp-from-error-log-file/149893 "2018-09-26T21:13:25Z")

</div>

Hi here, Using lastest filebeat/elasticsearch/kibana (6.4.1), when sending apache error log, it read timestamp writted in local time from log file and override timestamp in UTC format (sended by filebeat), then all logs…

---

## [Packetbeat capture only use query not others like select, insert, update](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287)

<div class="topic-metadata">

**Author:** [@Yecine](https://discuss.elastic.co/u/Yecine)\
**Replies:** 4\
**Last updated:** [September 26, 2018, 7:04pm UTC](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287 "2018-09-26T19:04:06Z")

</div>

I have configured packetbeat to monitor mysql and redirect that ELK The issue that i have is that it only detect use query and no other query like selects or inserts updates i don''t understand why. The port configured…

---

## [Normalizer](https://discuss.elastic.co/t/normalizer/149997)

<div class="topic-metadata">

**Author:** [@a.korshunov](https://discuss.elastic.co/u/a.korshunov)\
**Replies:** 2\
**Last updated:** [September 26, 2018, 1:17pm UTC](https://discuss.elastic.co/t/normalizer/149997 "2018-09-26T13:17:41Z")

</div>

Hi! I parse IIS logs with Filebeat. Field " iis.access.referrer" has values with GET-method parametes. Example: "https://www.google.com/search?q=elasticsearch" I want to see only host name ("www.google.com") in Kibana …

---

## [Filebeat on Windows ==\> Logstash Ubuntu](https://discuss.elastic.co/t/filebeat-on-windows-logstash-ubuntu/149820)

<div class="topic-metadata">

**Author:** [@Kartik\_Ramachandran](https://discuss.elastic.co/u/Kartik_Ramachandran)\
**Replies:** 1\
**Last updated:** [September 26, 2018, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-logstash-ubuntu/149820 "2018-09-26T13:14:14Z")

</div>

I have setup Filebeat on multiple Linux and macOS machines. They are able to send data to my logstash server (Ubuntu). However, when I try to send data from a Windows machine, I get the following error: 2018-09-24T15:21…

---

## [Filebeat mongo module, grok pattern is incorrect for Mongo 4](https://discuss.elastic.co/t/filebeat-mongo-module-grok-pattern-is-incorrect-for-mongo-4/149767)

<div class="topic-metadata">

**Author:** [@Matthew\_Zeemann](https://discuss.elastic.co/u/Matthew_Zeemann)\
**Replies:** 1\
**Last updated:** [September 26, 2018, 1:08pm UTC](https://discuss.elastic.co/t/filebeat-mongo-module-grok-pattern-is-incorrect-for-mongo-4/149767 "2018-09-26T13:08:58Z")

</div>

I am trying to use Filebeat to send MongoDB 4 logs to Elastic and it is failing. I have a log messages from Mongo that grok is failing to match against the supplied fields, e.g. 2018-09-25T05:16:13.012+0000 I STORAGE \[…

---

## [How to make Filebeat 6.4.1 read custom application logs?](https://discuss.elastic.co/t/how-to-make-filebeat-6-4-1-read-custom-application-logs/149805)

<div class="topic-metadata">

**Author:** [@Revit](https://discuss.elastic.co/u/Revit)\
**Replies:** 2\
**Last updated:** [September 26, 2018, 6:22am UTC](https://discuss.elastic.co/t/how-to-make-filebeat-6-4-1-read-custom-application-logs/149805 "2018-09-26T06:22:02Z")

</div>

Hello, I am new into this ELK stuff. I have question: how to make filebeat read custom log (for example vmware log) and send it to logstash? I already read the guide and I am quite clueless. Do I need make new custom mo…

---

## [Idea: rate limit Filebeat published events by a percentage](https://discuss.elastic.co/t/idea-rate-limit-filebeat-published-events-by-a-percentage/149333)

<div class="topic-metadata">

**Author:** [@lucas.at.section.io](https://discuss.elastic.co/u/lucas.at.section.io)\
**Replies:** 2\
**Last updated:** [September 25, 2018, 3:53pm UTC](https://discuss.elastic.co/t/idea-rate-limit-filebeat-published-events-by-a-percentage/149333 "2018-09-25T15:53:49Z")

</div>

This is a new feature which I'd like to contribute, but wanted to get some feedback. The idea is to limit the amount of events published, essentially scaling back the output, and thereby the pressure put on downstream c…

---

## [Defining dynamic types in field.yml](https://discuss.elastic.co/t/defining-dynamic-types-in-field-yml/149173)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 2\
**Last updated:** [September 25, 2018, 3:45pm UTC](https://discuss.elastic.co/t/defining-dynamic-types-in-field-yml/149173 "2018-09-25T15:45:57Z")

</div>

I'm struggling a bit to define dynamic types in field.yml for my Statsdbeat There are some fields that are predefined. But some some fields are dynamic. My fields.yml is defined as - key: statsdbeat title: statsdbea…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=415)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=417)
