# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=419

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 420

---

## [Unable to ingest apache2 logs through filebeat](https://discuss.elastic.co/t/unable-to-ingest-apache2-logs-through-filebeat/146309)

<div class="topic-metadata">

**Author:** [@Nithani25](https://discuss.elastic.co/u/Nithani25)\
**Replies:** 7\
**Last updated:** [September 14, 2018, 2:25pm UTC](https://discuss.elastic.co/t/unable-to-ingest-apache2-logs-through-filebeat/146309 "2018-09-14T14:25:14Z")

</div>

Hi Team, I am trying to ingest the apache 2 access and error logs through the filebeat index and getting the below error ./filebeat -e -c filebeat.yml -d "publish" 2018-08-28T02:40:42.896-0700 INFO instance/beat.…

---

## [Error decoding JSON: invalid character '.' looking for beginning of value](https://discuss.elastic.co/t/error-decoding-json-invalid-character-looking-for-beginning-of-value/148172)

<div class="topic-metadata">

**Author:** [@jlavallet](https://discuss.elastic.co/u/jlavallet)\
**Replies:** 2\
**Last updated:** [September 14, 2018, 1:50pm UTC](https://discuss.elastic.co/t/error-decoding-json-invalid-character-looking-for-beginning-of-value/148172 "2018-09-14T13:50:36Z")

</div>

My logs include JSON objects containing decimal type numeric values. Those values begin with a "." and not "0." as it appears the Filebeat JSON parser is expecting. The JSON parser complains about this by reporting the f…

---

## [Monitoring a Windows file Server user info](https://discuss.elastic.co/t/monitoring-a-windows-file-server-user-info/148324)

<div class="topic-metadata">

**Author:** [@alejandro.perez](https://discuss.elastic.co/u/alejandro.perez)\
**Replies:** 1\
**Last updated:** [September 14, 2018, 1:09pm UTC](https://discuss.elastic.co/t/monitoring-a-windows-file-server-user-info/148324 "2018-09-14T13:09:05Z")

</div>

Hello , if i´m monitoring a Windows file Server, How can I log the user info? Thank you in advance.

---

## [Kubernetes Module \[Kubelet SSL\]](https://discuss.elastic.co/t/kubernetes-module-kubelet-ssl/147770)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 10\
**Last updated:** [September 14, 2018, 1:02pm UTC](https://discuss.elastic.co/t/kubernetes-module-kubelet-ssl/147770 "2018-09-14T13:02:37Z")

</div>

Hi everyone, I have installed Kubernetes v1.11.2 by Kubeadm. I have configured Metricbeat (on Kubernetes) in order to get some metrics from Kubelet, however, I am not able to run it. I suppose that I have to use the ce…

---

## [Errors in metric beat log](https://discuss.elastic.co/t/errors-in-metric-beat-log/147918)

<div class="topic-metadata">

**Author:** [@Ihjaz](https://discuss.elastic.co/u/Ihjaz)\
**Replies:** 11\
**Last updated:** [September 14, 2018, 11:48am UTC](https://discuss.elastic.co/t/errors-in-metric-beat-log/147918 "2018-09-14T11:48:59Z")

</div>

Hi, I'm running Metricbeat 6.2.2-1 on RHEL 7.5 with the following kernel version. # uname -r -v 3.10.0-862.11.6.el7.x86\_64 #1 SMP Fri Aug 10 16:55:11 UTC 2018 I'm seeing the below errors in metricbeat log. 2018-09-0…

---

## [File beat multiple path to multiple end points](https://discuss.elastic.co/t/file-beat-multiple-path-to-multiple-end-points/147338)

<div class="topic-metadata">

**Author:** [@vasudevan](https://discuss.elastic.co/u/vasudevan)\
**Replies:** 2\
**Last updated:** [September 14, 2018, 11:31am UTC](https://discuss.elastic.co/t/file-beat-multiple-path-to-multiple-end-points/147338 "2018-09-14T11:31:37Z")

</div>

I wanted to grab logs from different path and then will send it to different end points of logstash. And I am following your official document for the same(https://www.elastic.co/guide/en/beats/filebeat/current/filebeat…

---

## [FileBeat consumes free disk space until restart](https://discuss.elastic.co/t/filebeat-consumes-free-disk-space-until-restart/148460)

<div class="topic-metadata">

**Author:** [@dns](https://discuss.elastic.co/u/dns)\
**Replies:** 2\
**Last updated:** [September 14, 2018, 10:13am UTC](https://discuss.elastic.co/t/filebeat-consumes-free-disk-space-until-restart/148460 "2018-09-14T10:13:36Z")

</div>

Hello! Could you please help with Filebeat configuration. Now we have a group of servers with the same Linux version (Ubuntu xenial) and the same FileBeat 5.5.1. Zabbix sometimes handles empty disk space at one server…

---

## [Multiple prospectors in filebeat](https://discuss.elastic.co/t/multiple-prospectors-in-filebeat/148344)

<div class="topic-metadata">

**Author:** [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Replies:** 1\
**Last updated:** [September 14, 2018, 9:36am UTC](https://discuss.elastic.co/t/multiple-prospectors-in-filebeat/148344 "2018-09-14T09:36:42Z")

</div>

Hi i have 10 different type of log files in one folder which all end with ".log" as of now i have been using one prospector to poll all the data using "/.log" as path but now i have to change some multiline settings for…

---

## [Unable to parse apache access logs](https://discuss.elastic.co/t/unable-to-parse-apache-access-logs/148593)

<div class="topic-metadata">

**Author:** [@Nithani25](https://discuss.elastic.co/u/Nithani25)\
**Replies:** 0\
**Last updated:** [September 14, 2018, 9:33am UTC](https://discuss.elastic.co/t/unable-to-parse-apache-access-logs/148593 "2018-09-14T09:33:39Z")

</div>

Hi Team, I am working parsing the apache logs to my index, the logs files seems to discrete. Some seems to COMMON and other COMBINED. How can i successfully parse them

---

## [Monitoring Jenkins with Beats](https://discuss.elastic.co/t/monitoring-jenkins-with-beats/147917)

<div class="topic-metadata">

**Author:** [@koko191](https://discuss.elastic.co/u/koko191)\
**Replies:** 1\
**Last updated:** [September 14, 2018, 9:21am UTC](https://discuss.elastic.co/t/monitoring-jenkins-with-beats/147917 "2018-09-14T09:21:34Z")

</div>

I am trying to monitor the status of Jenkins slaves using one or some of the Beats. One of my ideas was to use Metricbeat to monitor for service running with name "jenkins" but it quickly fails when a slave runs Jenkins…

---

## [Metricbeat version 6.4.0 install on CentOS7 is missing modules](https://discuss.elastic.co/t/metricbeat-version-6-4-0-install-on-centos7-is-missing-modules/148570)

<div class="topic-metadata">

**Author:** [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Replies:** 1\
**Last updated:** [September 14, 2018, 7:30am UTC](https://discuss.elastic.co/t/metricbeat-version-6-4-0-install-on-centos7-is-missing-modules/148570 "2018-09-14T07:30:45Z")

</div>

I installed a actual metricebeat in version 6.4.0 from the actual repository on a CentOS 7 in a patched Version 7.5. The install packages is only 70MB big and all modules are missing. It is reproducable for me on fresh …

---

## [Failed to rotate backups](https://discuss.elastic.co/t/failed-to-rotate-backups/148532)

<div class="topic-metadata">

**Author:** [@Supriya\_Mahawadi](https://discuss.elastic.co/u/Supriya_Mahawadi)\
**Replies:** 0\
**Last updated:** [September 13, 2018, 11:29pm UTC](https://discuss.elastic.co/t/failed-to-rotate-backups/148532 "2018-09-13T23:29:08Z")

</div>

Hi I am getting error while installing filebeats ,can anyone help me in solving .This is my issue: 2018-09-13 16:15:29.1038005 -0700 PDT m=+0.297197001 write error: failed to rotate backups: rename C:\\ELK stack\\filebea…

---

## [Http requests as a beat](https://discuss.elastic.co/t/http-requests-as-a-beat/148019)

<div class="topic-metadata">

**Author:** [@mattz](https://discuss.elastic.co/u/mattz)\
**Replies:** 9\
**Last updated:** [September 13, 2018, 7:02pm UTC](https://discuss.elastic.co/t/http-requests-as-a-beat/148019 "2018-09-13T19:02:26Z")

</div>

I have a small golang application that listens to http post requests on various routes. The data received represents messages on a messaging bus. Our current solution is to write json to a file that's tail'd by filebeat. …

---

## [Metricbeat6.4.0 panic when add add\_host\_metadata in configfile](https://discuss.elastic.co/t/metricbeat6-4-0-panic-when-add-add-host-metadata-in-configfile/148413)

<div class="topic-metadata">

**Author:** [@zyshn](https://discuss.elastic.co/u/zyshn)\
**Replies:** 2\
**Last updated:** [September 13, 2018, 9:53am UTC](https://discuss.elastic.co/t/metricbeat6-4-0-panic-when-add-add-host-metadata-in-configfile/148413 "2018-09-13T09:53:57Z")

</div>

processors: - add\_host\_metadata: netinfo.enabled: false metricbeat6.4.0 sometimes panic(random time:1hour or 1day), when add add\_host\_metadata in configfile, error like: fatal error: concurrent map writes /roo…

---

## [Haproxy module with master version](https://discuss.elastic.co/t/haproxy-module-with-master-version/148094)

<div class="topic-metadata">

**Author:** [@pollux](https://discuss.elastic.co/u/pollux)\
**Replies:** 2\
**Last updated:** [September 13, 2018, 8:34am UTC](https://discuss.elastic.co/t/haproxy-module-with-master-version/148094 "2018-09-13T08:34:48Z")

</div>

HI, I compiled filebeat from master (go get + make) and it works. I launch filebeat with the haproxy module. The conf is: module: haproxy http: enabled: true var.input: "file" var.paths: \["/var/log/haproxy.log"\] T…

---

## [Require Baseurl for filebeat 6.3.1 installation](https://discuss.elastic.co/t/require-baseurl-for-filebeat-6-3-1-installation/148412)

<div class="topic-metadata">

**Author:** [@Nithani25](https://discuss.elastic.co/u/Nithani25)\
**Replies:** 0\
**Last updated:** [September 13, 2018, 6:11am UTC](https://discuss.elastic.co/t/require-baseurl-for-filebeat-6-3-1-installation/148412 "2018-09-13T06:11:17Z")

</div>

HI Team, I need the baseurl for yum filebeat installation, I am trying to install 6.3.1 version now.

---

## [Map Disk utilization](https://discuss.elastic.co/t/map-disk-utilization/148406)

<div class="topic-metadata">

**Author:** [@Lutfi\_Haris](https://discuss.elastic.co/u/Lutfi_Haris)\
**Replies:** 0\
**Last updated:** [September 13, 2018, 4:34am UTC](https://discuss.elastic.co/t/map-disk-utilization/148406 "2018-09-13T04:34:02Z")

</div>

Hi, I using metricbeat to monitor the utilization for disk. I able to visualize the disk drive C: and D: but some of my disk is map to folder(as screenshot). How can I monitor it?

---

## [Issues with regexes and kubernetes hints based autodiscovery with filebeat 6.4.0](https://discuss.elastic.co/t/issues-with-regexes-and-kubernetes-hints-based-autodiscovery-with-filebeat-6-4-0/148231)

<div class="topic-metadata">

**Author:** [@Alex\_Scoble](https://discuss.elastic.co/u/Alex_Scoble)\
**Replies:** 2\
**Last updated:** [September 12, 2018, 4:39pm UTC](https://discuss.elastic.co/t/issues-with-regexes-and-kubernetes-hints-based-autodiscovery-with-filebeat-6-4-0/148231 "2018-09-12T16:39:26Z")

</div>

What I'm about to describe works fine in filebeat 6.3.1. The below only happens when I upgrade the filebeat daemonset for kubernetes to 6.4.0. We are using hints based autodiscovery in kubernetes. The pod annotations ar…

---

## [Metricbeats autodiscovery failing in kubernetes](https://discuss.elastic.co/t/metricbeats-autodiscovery-failing-in-kubernetes/147071)

<div class="topic-metadata">

**Author:** [@Alex\_Armstrong](https://discuss.elastic.co/u/Alex_Armstrong)\
**Replies:** 8\
**Last updated:** [September 12, 2018, 2:13pm UTC](https://discuss.elastic.co/t/metricbeats-autodiscovery-failing-in-kubernetes/147071 "2018-09-12T14:13:02Z")

</div>

Autodiscover not working for metricbeat 6.4.0 in kubernetes 1.9.6. Nginx module in this use case, uwsgi also tried. Declaring the module and giving an nginx ip outside of autodiscover works. below is the configmap bein…

---

## [Transport.go 125 SSL client failed to connect with dial tcp \<IP:Address of ELK\>5044 getsockopt connection refused](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706)

<div class="topic-metadata">

**Author:** [@murthy.mvvs](https://discuss.elastic.co/u/murthy.mvvs)\
**Replies:** 7\
**Last updated:** [September 12, 2018, 12:14pm UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706 "2018-09-12T12:14:43Z")

</div>

Hi Team, The filebeat seems to be running, but giving the following error. transport.go:125: SSL client failed to connect with: dial tcp \<IP address where elastic search, logstash and kibana are hosted\>: getsockopt: co…

---

## [How to read json data using filebeat and preserve attribute names in Logstash](https://discuss.elastic.co/t/how-to-read-json-data-using-filebeat-and-preserve-attribute-names-in-logstash/148115)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 3\
**Last updated:** [September 12, 2018, 12:10pm UTC](https://discuss.elastic.co/t/how-to-read-json-data-using-filebeat-and-preserve-attribute-names-in-logstash/148115 "2018-09-12T12:10:53Z")

</div>

Hi all, I have single line log files (\\n delimiter) in which logs are entered in json format like; {"f1":"data1","timestamp":"2018-09-10T12:33:15.878+0000","f2":"data2","f3":1234,"f4":"data4","server":"192.168.0.1","f5…

---

## [Filebeat for Kubernetes](https://discuss.elastic.co/t/filebeat-for-kubernetes/148152)

<div class="topic-metadata">

**Author:** [@tehho](https://discuss.elastic.co/u/tehho)\
**Replies:** 4\
**Last updated:** [September 12, 2018, 12:07pm UTC](https://discuss.elastic.co/t/filebeat-for-kubernetes/148152 "2018-09-12T12:07:43Z")

</div>

Im using Kubernetes and would like to add filebeat to all stdouts. I have followed: https://raw.githubusercontent.com/elastic/beats/master/deploy/kubernetes/filebeat-kubernetes.yaml and have the filebeat running. How e…

---

## [Create several prospectors or several paths in one prospector ? What is the best practice?](https://discuss.elastic.co/t/create-several-prospectors-or-several-paths-in-one-prospector-what-is-the-best-practice/148116)

<div class="topic-metadata">

**Author:** [@dyl](https://discuss.elastic.co/u/dyl)\
**Replies:** 5\
**Last updated:** [September 12, 2018, 12:06pm UTC](https://discuss.elastic.co/t/create-several-prospectors-or-several-paths-in-one-prospector-what-is-the-best-practice/148116 "2018-09-12T12:06:50Z")

</div>

Hello. I have severals directory to listen thanks to filebeat on my server : /data/EDT/1/batchsefluid/files/logs/ /data/EDT/2/batchsefluid/files/logs/ /data/EDT/3/batchsefluid/files/logs/ /data/EDT/4/batchsefluid/fi…

---

## [Filebeat broken](https://discuss.elastic.co/t/filebeat-broken/148280)

<div class="topic-metadata">

**Author:** [@mouli\_v](https://discuss.elastic.co/u/mouli_v)\
**Replies:** 0\
**Last updated:** [September 12, 2018, 8:44am UTC](https://discuss.elastic.co/t/filebeat-broken/148280 "2018-09-12T08:44:42Z")

</div>

Our elastic search instance is with 6.2.4 version "version" : { "number" : "6.2.4", "build\_hash" : "ccec39f", "build\_date" : "2018-04-12T20:37:28.497551Z", "build\_snapshot" : false, "lucene\_version"…

---

## [Unable to execute metric beat command & unable to view on kibana](https://discuss.elastic.co/t/unable-to-execute-metric-beat-command-unable-to-view-on-kibana/147349)

<div class="topic-metadata">

**Author:** [@kranthi\_851](https://discuss.elastic.co/u/kranthi_851)\
**Replies:** 7\
**Last updated:** [September 12, 2018, 7:47am UTC](https://discuss.elastic.co/t/unable-to-execute-metric-beat-command-unable-to-view-on-kibana/147349 "2018-09-12T07:47:55Z")

</div>

Hi All, Two problems I am facing currently with the metric beat I have installed metricbeat on pc successfully but now I am unable to enable the modules. Its showing as apache not exist. Current my working directory i…

---

## [Updating winlogbeat.yml and adding more event logs](https://discuss.elastic.co/t/updating-winlogbeat-yml-and-adding-more-event-logs/148246)

<div class="topic-metadata">

**Author:** [@popa](https://discuss.elastic.co/u/popa)\
**Replies:** 3\
**Last updated:** [September 12, 2018, 6:36am UTC](https://discuss.elastic.co/t/updating-winlogbeat-yml-and-adding-more-event-logs/148246 "2018-09-12T06:36:30Z")

</div>

I'm currently running a Windows Event Forwarding / Windows Event Collector setup. All of our endpoints send logs to the WEC server where Winlogbeat is installed. I'm currently sending Sysmon logs (WEC6-Sysmon) centrally…

---

## [How to differentiate type of logs in prospectus of file beats](https://discuss.elastic.co/t/how-to-differentiate-type-of-logs-in-prospectus-of-file-beats/148264)

<div class="topic-metadata">

**Author:** [@Chandana](https://discuss.elastic.co/u/Chandana)\
**Replies:** 0\
**Last updated:** [September 12, 2018, 6:35am UTC](https://discuss.elastic.co/t/how-to-differentiate-type-of-logs-in-prospectus-of-file-beats/148264 "2018-09-12T06:35:56Z")

</div>

Hi, I am a newbee in file beats. In logstash conf I used to differentiate the logs in input-\> file-\> using the "type". According to that type I create the different indices for different log in the output-\>Elasticsearc…

---

## [Filebeat auditd module](https://discuss.elastic.co/t/filebeat-auditd-module/148150)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 3\
**Last updated:** [September 12, 2018, 4:58am UTC](https://discuss.elastic.co/t/filebeat-auditd-module/148150 "2018-09-12T04:58:57Z")

</div>

Filebeat auditd module Enabled the filebeat auditd module but the events are not parsing . Provided Grok expressions do not match field value: \[node=cro04 type=SYSCALL msg=audit(1536673014.739:52297): arch=c000003e sysc…

---

## [Trying to understand why filebeat dropped events during logstash failure](https://discuss.elastic.co/t/trying-to-understand-why-filebeat-dropped-events-during-logstash-failure/147937)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 4\
**Last updated:** [September 12, 2018, 4:40am UTC](https://discuss.elastic.co/t/trying-to-understand-why-filebeat-dropped-events-during-logstash-failure/147937 "2018-09-12T04:40:44Z")

</div>

Hi, I run filebeat to send Bro logs from a machine(sensor) to my logstash server. During the weekend, a power cycle caused all our infrastructure to reboot. While the sensor started up correctly, logstash server had som…

---

## [I can't start windows service in Windows 10](https://discuss.elastic.co/t/i-cant-start-windows-service-in-windows-10/147700)

<div class="topic-metadata">

**Author:** [@cdra](https://discuss.elastic.co/u/cdra)\
**Replies:** 4\
**Last updated:** [September 12, 2018, 1:42am UTC](https://discuss.elastic.co/t/i-cant-start-windows-service-in-windows-10/147700 "2018-09-12T01:42:32Z")

</div>

I can't start windows service in Windows 10. Errors are: EventLog\[Application\] Open() error. No events will be read from this source. EventLog\[Security\] Open() error. No events will be read from this source. EventLog\[…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=418)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=420)
