# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=417

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 418

---

## [Metricbeat to show network packets over time](https://discuss.elastic.co/t/metricbeat-to-show-network-packets-over-time/149709)

<div class="topic-metadata">

**Author:** [@Drav3nmc](https://discuss.elastic.co/u/Drav3nmc)\
**Replies:** 3\
**Last updated:** [September 25, 2018, 3:04pm UTC](https://discuss.elastic.co/t/metricbeat-to-show-network-packets-over-time/149709 "2018-09-25T15:04:17Z")

</div>

I have metricbeats running on windows server and would like to see a graph of the network traffic over time, to see if i am maxing out network card. I can see the network metricset.name and the system.network.in.bytes a…

---

## [Metricbeat module monitoring self-signed SSL endpoint](https://discuss.elastic.co/t/metricbeat-module-monitoring-self-signed-ssl-endpoint/147779)

<div class="topic-metadata">

**Author:** [@tomaszp](https://discuss.elastic.co/u/tomaszp)\
**Replies:** 2\
**Last updated:** [September 25, 2018, 1:10pm UTC](https://discuss.elastic.co/t/metricbeat-module-monitoring-self-signed-ssl-endpoint/147779 "2018-09-25T13:10:18Z")

</div>

Hi, I'm trying to monitor an SSL endpoint signed with a self-signed certificate with either the dropwizard or jolokia module of Metricbeat. For example, a snipped of jolokia module config: - module: jolokia metricset…

---

## [Is there any automated way of updating the configuration in filebeat?](https://discuss.elastic.co/t/is-there-any-automated-way-of-updating-the-configuration-in-filebeat/149658)

<div class="topic-metadata">

**Author:** [@anra137](https://discuss.elastic.co/u/anra137)\
**Replies:** 2\
**Last updated:** [September 25, 2018, 10:40am UTC](https://discuss.elastic.co/t/is-there-any-automated-way-of-updating-the-configuration-in-filebeat/149658 "2018-09-25T10:40:35Z")

</div>

Hi, We have some static data which is unique to each log file. For example, service.name, service.version etc. This will change everytime new version is deployed. Changing the config each time on all the servers takes l…

---

## [How to configure "clean\_\*"](https://discuss.elastic.co/t/how-to-configure-clean/149662)

<div class="topic-metadata">

**Author:** [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Replies:** 2\
**Last updated:** [September 25, 2018, 9:50am UTC](https://discuss.elastic.co/t/how-to-configure-clean/149662 "2018-09-25T09:50:53Z")

</div>

The filebeat documents have very less information regarding the configuration of "clean\_\*" parameter. Can anyone help me to configure "clean\_\*" parameter. It will be very helpful Thanks

---

## [Different types of json logs to different ES indices without using Logstash](https://discuss.elastic.co/t/different-types-of-json-logs-to-different-es-indices-without-using-logstash/149332)

<div class="topic-metadata">

**Author:** [@soumen](https://discuss.elastic.co/u/soumen)\
**Replies:** 2\
**Last updated:** [September 25, 2018, 8:45am UTC](https://discuss.elastic.co/t/different-types-of-json-logs-to-different-es-indices-without-using-logstash/149332 "2018-09-25T08:45:47Z")

</div>

Hi, I have two different types of json logs (with different fields) which I need to send to two different ES indices. I want to avoid having to setup Logstash just to do this via conditional processing or having to inst…

---

## [Autodiscover with hints, discover pods from all namespaces](https://discuss.elastic.co/t/autodiscover-with-hints-discover-pods-from-all-namespaces/147939)

<div class="topic-metadata">

**Author:** [@havlan](https://discuss.elastic.co/u/havlan)\
**Replies:** 9\
**Last updated:** [September 25, 2018, 7:59am UTC](https://discuss.elastic.co/t/autodiscover-with-hints-discover-pods-from-all-namespaces/147939 "2018-09-25T07:59:25Z")

</div>

Hi! I could not find any documentation regarding how to use autodiscover with hints and discover from all namespaces, is it possible to do this? Elastic stack: 6.4.0 Example Filebeat config: filebeat.autodiscover: …

---

## [Elasticsearch dashboard in 6.4.0?](https://discuss.elastic.co/t/elasticsearch-dashboard-in-6-4-0/149293)

<div class="topic-metadata">

**Author:** [@antwan](https://discuss.elastic.co/u/antwan)\
**Replies:** 2\
**Last updated:** [September 25, 2018, 6:53am UTC](https://discuss.elastic.co/t/elasticsearch-dashboard-in-6-4-0/149293 "2018-09-25T06:53:24Z")

</div>

Hello, I have been upgrading our ELK-stack to 6.4.0, and been working on parsing the logs from Logstash, Elasticsearch and Kibana themselves. I am now trying to get my hands on the example dashboards for Elasticsearch a…

---

## [Include\_lines in My Filebeat Module](https://discuss.elastic.co/t/include-lines-in-my-filebeat-module/149483)

<div class="topic-metadata">

**Author:** [@stevetso](https://discuss.elastic.co/u/stevetso)\
**Replies:** 2\
**Last updated:** [September 25, 2018, 6:31am UTC](https://discuss.elastic.co/t/include-lines-in-my-filebeat-module/149483 "2018-09-25T06:31:53Z")

</div>

I have created my module in filebeat and my log can be ingested. For filebeat.input, there is a feature called "include\_lines", which we could only include the lines which matched the regex. In filebeat module, I tried…

---

## [Filebeat to connect kafka](https://discuss.elastic.co/t/filebeat-to-connect-kafka/149702)

<div class="topic-metadata">

**Author:** [@yarle.lakshman](https://discuss.elastic.co/u/yarle.lakshman)\
**Replies:** 1\
**Last updated:** [September 25, 2018, 6:04am UTC](https://discuss.elastic.co/t/filebeat-to-connect-kafka/149702 "2018-09-25T06:04:09Z")

</div>

hi team ; i am getiing below error while logshishiping from filebeat to kafka; below are details. and exception , please help. filebeat : filebeat-1.3.1-5.el7.x86\_64 Kafka : confluent kafka 5.0 Filebeat config: \[root…

---

## [Filbeat not Starting after enabling Security](https://discuss.elastic.co/t/filbeat-not-starting-after-enabling-security/149611)

<div class="topic-metadata">

**Author:** [@hegdedarsh](https://discuss.elastic.co/u/hegdedarsh)\
**Replies:** 5\
**Last updated:** [September 25, 2018, 6:00am UTC](https://discuss.elastic.co/t/filbeat-not-starting-after-enabling-security/149611 "2018-09-25T06:00:09Z")

</div>

Hi, All the beats were working fine till i had not enabled security(username/password). But when i enabled it, everything went down, and when i try to start the filebeat, it throws an the below error Error:- 2018-09-24…

---

## [Filebeat pipeline error](https://discuss.elastic.co/t/filebeat-pipeline-error/149303)

<div class="topic-metadata">

**Author:** [@jamesl](https://discuss.elastic.co/u/jamesl)\
**Replies:** 1\
**Last updated:** [September 25, 2018, 5:51am UTC](https://discuss.elastic.co/t/filebeat-pipeline-error/149303 "2018-09-25T05:51:43Z")

</div>

Hello. I just recently upgraded my system from 6.4.0 to 6.4.1. Now I'm getting this on my ingest nodes.. Do I need to delete my filebeat pipeline and if so is there a quick procedure? thanks. \[2018-09-20T23:35:10,968…

---

## [Configure file beat not to line by line](https://discuss.elastic.co/t/configure-file-beat-not-to-line-by-line/149292)

<div class="topic-metadata">

**Author:** [@wolecharles\_job](https://discuss.elastic.co/u/wolecharles_job)\
**Replies:** 1\
**Last updated:** [September 25, 2018, 5:49am UTC](https://discuss.elastic.co/t/configure-file-beat-not-to-line-by-line/149292 "2018-09-25T05:49:48Z")

</div>

We have a situation where our machine logs based on user input..A user clicks a button,it logs and click another it logs to another line.So say a user click 5 times ..we have 5 line logs..I know filebeat read line by lin…

---

## [Can't execute winlogbeat.exe](https://discuss.elastic.co/t/cant-execute-winlogbeat-exe/148594)

<div class="topic-metadata">

**Author:** [@Pinno\_Lin](https://discuss.elastic.co/u/Pinno_Lin)\
**Replies:** 10\
**Last updated:** [September 25, 2018, 2:43am UTC](https://discuss.elastic.co/t/cant-execute-winlogbeat-exe/148594 "2018-09-25T02:43:46Z")

</div>

Hi, I want to install winlogbeat in Windows 2016 Standard x64 with Winlogbeat 6.4.0 x64 When I execute the winlogbeat.exe to confirm the configuration file or anything, The console also response error in below. what's…

---

## [Filebeat CPU shoots 100 times when sending to kafka topic using a field](https://discuss.elastic.co/t/filebeat-cpu-shoots-100-times-when-sending-to-kafka-topic-using-a-field/146898)

<div class="topic-metadata">

**Author:** [@krunalvora](https://discuss.elastic.co/u/krunalvora)\
**Replies:** 7\
**Last updated:** [September 24, 2018, 8:29pm UTC](https://discuss.elastic.co/t/filebeat-cpu-shoots-100-times-when-sending-to-kafka-topic-using-a-field/146898 "2018-09-24T20:29:10Z")

</div>

When using the filebeat config output like: output.kafka: hosts: - \<kafka\>:9092 topic: 'topic' The CPU usage of filebeat is around ~15m in kubernetes. But when I try to dynamically set the topic …

---

## [Filebeat getting restarted even after stopping it. what should i do?](https://discuss.elastic.co/t/filebeat-getting-restarted-even-after-stopping-it-what-should-i-do/149657)

<div class="topic-metadata">

**Author:** [@pramodchoudhari](https://discuss.elastic.co/u/pramodchoudhari)\
**Replies:** 3\
**Last updated:** [September 24, 2018, 12:14pm UTC](https://discuss.elastic.co/t/filebeat-getting-restarted-even-after-stopping-it-what-should-i-do/149657 "2018-09-24T12:14:27Z")

</div>

i am killing the filebeat process but even after stopping it filebeat process gets restarted again what should i do ? Please help!!

---

## [Average response time on Haproxy Dashboard](https://discuss.elastic.co/t/average-response-time-on-haproxy-dashboard/149391)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 5\
**Last updated:** [September 24, 2018, 10:06am UTC](https://discuss.elastic.co/t/average-response-time-on-haproxy-dashboard/149391 "2018-09-24T10:06:29Z")

</div>

Hello Team, I am using ELK 6.4.0 and beates (filebeats, metricbeat) 6.4.0. I have exported the dashboard for HAPROXY. But when i am seeing the Average Response Time for HAPROXY on Kibana dashboard its showing very high…

---

## [Running metricbeat service on dedicated non standard port](https://discuss.elastic.co/t/running-metricbeat-service-on-dedicated-non-standard-port/149412)

<div class="topic-metadata">

**Author:** [@tushar\_raut](https://discuss.elastic.co/u/tushar_raut)\
**Replies:** 8\
**Last updated:** [September 24, 2018, 9:56am UTC](https://discuss.elastic.co/t/running-metricbeat-service-on-dedicated-non-standard-port/149412 "2018-09-24T09:56:04Z")

</div>

Hi, I just want to confirm Is it possible to run metricbeat on some specific port which is non standard port and open on my setup? Metricbeat service uses dynamic port and there is nothing I found for configuration cha…

---

## [Is there a predefined dashboard for http module](https://discuss.elastic.co/t/is-there-a-predefined-dashboard-for-http-module/149195)

<div class="topic-metadata">

**Author:** [@IBenabd](https://discuss.elastic.co/u/IBenabd)\
**Replies:** 4\
**Last updated:** [September 23, 2018, 9:27am UTC](https://discuss.elastic.co/t/is-there-a-predefined-dashboard-for-http-module/149195 "2018-09-23T09:27:12Z")

</div>

Are they a predefined dashboard in http module? My goal: analyze the metrics of a spring app, using http module to ship the metrics and visualize them using kibana!! if there is not a prepared dashboard what is t…

---

## [beat.Event and big.Int mapping](https://discuss.elastic.co/t/beat-event-and-big-int-mapping/149197)

<div class="topic-metadata">

**Author:** [@paulkeogh](https://discuss.elastic.co/u/paulkeogh)\
**Replies:** 1\
**Last updated:** [September 22, 2018, 1:48pm UTC](https://discuss.elastic.co/t/beat-event-and-big-int-mapping/149197 "2018-09-22T13:48:40Z")

</div>

libbeats seems to map \*big.Int types to strings when publishing - is there any way I can force this to a numeric type by using \_meta/fields.yml configuration ?

---

## [Sending JSON to Elasticsearch](https://discuss.elastic.co/t/sending-json-to-elasticsearch/149520)

<div class="topic-metadata">

**Author:** [@koocaroo](https://discuss.elastic.co/u/koocaroo)\
**Replies:** 1\
**Last updated:** [September 22, 2018, 6:11am UTC](https://discuss.elastic.co/t/sending-json-to-elasticsearch/149520 "2018-09-22T06:11:21Z")

</div>

I have JSON logs that i would like to send to ElasticSearch with filebeat, but when i do, all the fields in the JSON do not actually become searchable fields in ES/Kibana. How do i make the fields from the JSON into sear…

---

## [Run metricbeat in docker](https://discuss.elastic.co/t/run-metricbeat-in-docker/148522)

<div class="topic-metadata">

**Author:** [@bertolis](https://discuss.elastic.co/u/bertolis)\
**Replies:** 5\
**Last updated:** [September 21, 2018, 4:08pm UTC](https://discuss.elastic.co/t/run-metricbeat-in-docker/148522 "2018-09-21T16:08:38Z")

</div>

Hi, i am running elk with docker-compose, i get status green in elasticsearch and i can also login to kibana. When i run "sudo ./metricbeat -e -c metricbeat.yml" from the tar.gz i downloaded, i get an index in elastics…

---

## [Harvest logs between a certain date](https://discuss.elastic.co/t/harvest-logs-between-a-certain-date/149194)

<div class="topic-metadata">

**Author:** [@mgreco2k](https://discuss.elastic.co/u/mgreco2k)\
**Replies:** 7\
**Last updated:** [September 21, 2018, 1:54pm UTC](https://discuss.elastic.co/t/harvest-logs-between-a-certain-date/149194 "2018-09-21T13:54:11Z")

</div>

I want filebeat to harvest logs that have a date between 9/14/2018 @ 12:00:00 to 9/17/2018 @ 18:00:00 and I'm not sure how to do that ?

---

## [Kafka ouput with SASL\_SSL authentication](https://discuss.elastic.co/t/kafka-ouput-with-sasl-ssl-authentication/149422)

<div class="topic-metadata">

**Author:** [@Ronanh](https://discuss.elastic.co/u/Ronanh)\
**Replies:** 2\
**Last updated:** [September 21, 2018, 12:01pm UTC](https://discuss.elastic.co/t/kafka-ouput-with-sasl-ssl-authentication/149422 "2018-09-21T12:01:08Z")

</div>

Hello, I need to send logs with filebeat to a Kafka broker where I am not administrator. This broker has SSL and authentication enabled and I failed to configure filebeat to connect to it properly. Our Kafka administr…

---

## [Multiple Filebeat Instances on Windows Hosts](https://discuss.elastic.co/t/multiple-filebeat-instances-on-windows-hosts/149390)

<div class="topic-metadata">

**Author:** [@B4S71](https://discuss.elastic.co/u/B4S71)\
**Replies:** 3\
**Last updated:** [September 21, 2018, 9:08am UTC](https://discuss.elastic.co/t/multiple-filebeat-instances-on-windows-hosts/149390 "2018-09-21T09:08:41Z")

</div>

Hi there, We currently run a number of Hosts, Exchange-Servers at that. For Problem identification, we require two kinds of logs: Exchange Servers generate IIS-Logs, which are useful for getting return codes over user &…

---

## [Metricbeat in container - missing docker logs](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890)

<div class="topic-metadata">

**Author:** [@ncasaux](https://discuss.elastic.co/u/ncasaux)\
**Replies:** 6\
**Last updated:** [September 20, 2018, 7:39pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890 "2018-09-20T19:39:07Z")

</div>

Hello, I followed the steps described in the documentation https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-docker.html and it works great! The only issue I have is that the command "docker logs " do…

---

## [Need help in Ports used in Beat and elastic](https://discuss.elastic.co/t/need-help-in-ports-used-in-beat-and-elastic/148643)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 3\
**Last updated:** [September 20, 2018, 3:03pm UTC](https://discuss.elastic.co/t/need-help-in-ports-used-in-beat-and-elastic/148643 "2018-09-20T15:03:41Z")

</div>

I want to send filebeat and packetbeat data from azureserver-1 to azureserver-2. So so what are the ports i need to open for that in inbound and outbound on both servers? i am using default ports for beats in azureserve…

---

## [Can the filebeat syslog listener forward syslog output?](https://discuss.elastic.co/t/can-the-filebeat-syslog-listener-forward-syslog-output/149192)

<div class="topic-metadata">

**Author:** [@sgreszcz](https://discuss.elastic.co/u/sgreszcz)\
**Replies:** 1\
**Last updated:** [September 20, 2018, 11:08am UTC](https://discuss.elastic.co/t/can-the-filebeat-syslog-listener-forward-syslog-output/149192 "2018-09-20T11:08:38Z")

</div>

It's not too clear in the filebeat syslog input documentation, but can filebeat output in RFC3164 or RFC5424 format (to file or to other remote syslog destination) or can it only write to JSON (Logstash/Elastic/local fil…

---

## [Filebeat does not read new lines](https://discuss.elastic.co/t/filebeat-does-not-read-new-lines/149140)

<div class="topic-metadata">

**Author:** [@kater](https://discuss.elastic.co/u/kater)\
**Replies:** 2\
**Last updated:** [September 20, 2018, 7:22am UTC](https://discuss.elastic.co/t/filebeat-does-not-read-new-lines/149140 "2018-09-20T07:22:27Z")

</div>

Hello. I'm currently using a 6.4 ELK stack and 6.4 Filebeat on a other server. A squid is running and the access.log get new lines but Filebeat is not able to read it. I even tried to "echo \>\>" the file but Filebeat …

---

## [Windows.service.user would be awesome](https://discuss.elastic.co/t/windows-service-user-would-be-awesome/148642)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [September 19, 2018, 9:16pm UTC](https://discuss.elastic.co/t/windows-service-user-would-be-awesome/148642 "2018-09-19T21:16:10Z")

</div>

Hello, I was working with the Metricbeat windows service metricset and I think it would be a nice addition if the user which is configured to run the service could be added? The field could be called windows.service.us…

---

## [A question on the spooling to disk](https://discuss.elastic.co/t/a-question-on-the-spooling-to-disk/149018)

<div class="topic-metadata">

**Author:** [@sentient](https://discuss.elastic.co/u/sentient)\
**Replies:** 4\
**Last updated:** [September 19, 2018, 6:09pm UTC](https://discuss.elastic.co/t/a-question-on-the-spooling-to-disk/149018 "2018-09-19T18:09:26Z")

</div>

When events cannot be send to Elastic Search, events are nicely written to disk. On restart the events are send to ElasticSearch. I was wondering, do we always need to restart? Or can we set an option to retry to submi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=416)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=418)
