# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=42

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 43

---

## [Aruba ClearPass Integration with FIlebeat and Elasticsearch](https://discuss.elastic.co/t/aruba-clearpass-integration-with-filebeat-and-elasticsearch/340058)

<div class="topic-metadata">

**Author:** [@kibana\_user17](https://discuss.elastic.co/u/kibana_user17)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 2:15pm UTC](https://discuss.elastic.co/t/aruba-clearpass-integration-with-filebeat-and-elasticsearch/340058 "2023-08-03T14:15:17Z")

</div>

Anyone here have done integration between elasticsearch and aruba clear pass manager?

---

## [Access container logs with libbeat / filebeat with non-root user](https://discuss.elastic.co/t/access-container-logs-with-libbeat-filebeat-with-non-root-user/340050)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 1:39pm UTC](https://discuss.elastic.co/t/access-container-logs-with-libbeat-filebeat-with-non-root-user/340050 "2023-08-03T13:39:31Z")

</div>

I have filebeat / libbeat running as non-root user and want to read docker container logs from /var/lib/docker/container . I have mounted the directory within beat pod but the directory has 700 permission by default, i.e…

---

## [Regarding Container Input](https://discuss.elastic.co/t/regarding-container-input/339707)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 14\
**Last updated:** [August 3, 2023, 1:06pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707 "2023-08-03T13:06:17Z")

</div>

Hi, I see that combine\_partial is not a parameter for the container input. Does the input now automatically handle docker's 16kb message limit? Thx D

---

## [Filebeat not ingesting Juniper SRX correctly](https://discuss.elastic.co/t/filebeat-not-ingesting-juniper-srx-correctly/339807)

<div class="topic-metadata">

**Author:** [@fredmoped](https://discuss.elastic.co/u/fredmoped)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 11:57am UTC](https://discuss.elastic.co/t/filebeat-not-ingesting-juniper-srx-correctly/339807 "2023-08-03T11:57:36Z")

</div>

Hi all, I am running Elastic,Kibana and Filebeat 8.8.1 on docker and it somewhat works for what i want to achieve, but i am struggling to get Juniper module to ingest my data correctly. From what i see at : https://git…

---

## [Modules system and nginx is not showing any data when looking in discover](https://discuss.elastic.co/t/modules-system-and-nginx-is-not-showing-any-data-when-looking-in-discover/339076)

<div class="topic-metadata">

**Author:** [@Prem\_Pratap\_Singh](https://discuss.elastic.co/u/Prem_Pratap_Singh)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 6:38am UTC](https://discuss.elastic.co/t/modules-system-and-nginx-is-not-showing-any-data-when-looking-in-discover/339076 "2023-08-03T06:38:23Z")

</div>

Hi All, I have deployed Elasticsearch, kibana and filebeat on my kubernetes cluster but the enable modules such as nginx and system are not showing any data when i filter it using event.module: system on my dashboard bu…

---

## [Drop event processor not working on Filebeat](https://discuss.elastic.co/t/drop-event-processor-not-working-on-filebeat/339725)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 4\
**Last updated:** [August 2, 2023, 6:01pm UTC](https://discuss.elastic.co/t/drop-event-processor-not-working-on-filebeat/339725 "2023-08-02T18:01:38Z")

</div>

Hello, I'm trying to create a drop\_event processor to only allow elasticsearch audit logs which have a request.name = "AuthenticateRequest". Clearly my process it not working as all events are not matching and everythin…

---

## [Auditbeat lost events](https://discuss.elastic.co/t/auditbeat-lost-events/339935)

<div class="topic-metadata">

**Author:** [@KevinShi](https://discuss.elastic.co/u/KevinShi)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 11:34am UTC](https://discuss.elastic.co/t/auditbeat-lost-events/339935 "2023-08-02T11:34:50Z")

</div>

My auditbeat drop all events when it start a minutes. And auditbeat status info: Aug 02 19:11:51 auditbeat\[29357\]: 2023-08-02T19:11:51.440+0800 INFO \[auditd\] auditd/audit\_linux.go:286 audit…

---

## [Minimal Filebeat configuration for sending Logstash message in JSON format to Logstash](https://discuss.elastic.co/t/minimal-filebeat-configuration-for-sending-logstash-message-in-json-format-to-logstash/339811)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 8\
**Last updated:** [August 1, 2023, 6:51pm UTC](https://discuss.elastic.co/t/minimal-filebeat-configuration-for-sending-logstash-message-in-json-format-to-logstash/339811 "2023-08-01T18:51:32Z")

</div>

Until now, we have had Logstash produce its log messages in plain-text format (written to /var/log/logstash/logstash-plain.log). And we had Filebeat ship the log messages to a Logstash cluster where the log messages were…

---

## [Need help in configuring filebeat 8.9 on windows server 2012 R2](https://discuss.elastic.co/t/need-help-in-configuring-filebeat-8-9-on-windows-server-2012-r2/339836)

<div class="topic-metadata">

**Author:** [@Shan2](https://discuss.elastic.co/u/Shan2)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 4:36pm UTC](https://discuss.elastic.co/t/need-help-in-configuring-filebeat-8-9-on-windows-server-2012-r2/339836 "2023-08-01T16:36:48Z")

</div>

Hi All, First time implementing filebeat 8.9 on windows to pick files from Samba share and send it to Elasticsearch. The netwoek firewall rules has been allowed and telnet is also happening from windows server. We are g…

---

## [Configuring Filebeat to pack openresty/nginx logs and visualize in Kibana dashboards](https://discuss.elastic.co/t/configuring-filebeat-to-pack-openresty-nginx-logs-and-visualize-in-kibana-dashboards/339300)

<div class="topic-metadata">

**Author:** [@kpagcha](https://discuss.elastic.co/u/kpagcha)\
**Replies:** 4\
**Last updated:** [August 1, 2023, 12:15pm UTC](https://discuss.elastic.co/t/configuring-filebeat-to-pack-openresty-nginx-logs-and-visualize-in-kibana-dashboards/339300 "2023-08-01T12:15:25Z")

</div>

I am totally new with the ELK stack and not really a sysadmin either, just a web developer trying to figure this out. I have two droplets: one where I installed the ELK stack successfully to some extent (managed to vi…

---

## [Ingest CSVs with filebeat into elastic cloud](https://discuss.elastic.co/t/ingest-csvs-with-filebeat-into-elastic-cloud/339790)

<div class="topic-metadata">

**Author:** [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 11:34am UTC](https://discuss.elastic.co/t/ingest-csvs-with-filebeat-into-elastic-cloud/339790 "2023-08-01T11:34:07Z")

</div>

I was able to import a csv using filebeat to elastic cloud. I did the following: First i uploaded the csv to elastic in order to have the filebeat yml configuration. Then I modified the filebeat.yml and installed fileb…

---

## [Override filebeat input paths using command line configuration override?](https://discuss.elastic.co/t/override-filebeat-input-paths-using-command-line-configuration-override/339482)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 9:52am UTC](https://discuss.elastic.co/t/override-filebeat-input-paths-using-command-line-configuration-override/339482 "2023-08-01T09:52:00Z")

</div>

I have a filebeat filestream input which parses a complicated message format. There are a few edge cases I'd like to create standalone tests for. I'd like to test single instances of the the message format from the comma…

---

## [Handling of Multiline Scenarios](https://discuss.elastic.co/t/handling-of-multiline-scenarios/339069)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:32am UTC](https://discuss.elastic.co/t/handling-of-multiline-scenarios/339069 "2023-08-01T09:32:42Z")

</div>

Hi, We have a need to add a second multiline block to our filebeat config. What isn't clear to me is the order in which multiline blocks are executed. Am I right to assume that they're executed in the order that the con…

---

## [Secure traffic via HTTPS - using kafka.output](https://discuss.elastic.co/t/secure-traffic-via-https-using-kafka-output/338779)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 9:26am UTC](https://discuss.elastic.co/t/secure-traffic-via-https-using-kafka-output/338779 "2023-08-01T09:26:31Z")

</div>

I'd like to start using elastic-agent but doing so requires that I setup xpack security. In the docs (here) it gives an example for sending data directly to elasticsearch. We use 'kafka.output'. Is this not supported …

---

## [Winlogbeat/filebeat not sending data to elasticsearch](https://discuss.elastic.co/t/winlogbeat-filebeat-not-sending-data-to-elasticsearch/339135)

<div class="topic-metadata">

**Author:** [@Nirmal](https://discuss.elastic.co/u/Nirmal)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:25am UTC](https://discuss.elastic.co/t/winlogbeat-filebeat-not-sending-data-to-elasticsearch/339135 "2023-08-01T09:25:02Z")

</div>

I am getting error when I run this command for winlogbeat .\\winlogbeat.exe setup -e and for filebeat filebeat setup -e error massage {"log.level":"error","@timestamp":"2023-07-24T22:08:16.309+0100","log.origin":{"fi…

---

## [After upgrading the filebeat 8.8.2 getting the error like publish events: temporary bulk send failure","service.name":"filebeat","ecs.version":"1.6.0"](https://discuss.elastic.co/t/after-upgrading-the-filebeat-8-8-2-getting-the-error-like-publish-events-temporary-bulk-send-failure-service-name-filebeat-ecs-version-1-6-0/339200)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:16am UTC](https://discuss.elastic.co/t/after-upgrading-the-filebeat-8-8-2-getting-the-error-like-publish-events-temporary-bulk-send-failure-service-name-filebeat-ecs-version-1-6-0/339200 "2023-08-01T09:16:08Z")

</div>

Hi, I have upgraded to the filebeat to 8.8.2. Configured it. After started in log I am getting the below error. {"log.level":"error","@timestamp":"2023-07-25T14:38:53.614+0200","log.logger":"publisher\_pipeline\_output",…

---

## [FunctionBeat not able to get CloudWatch Logs](https://discuss.elastic.co/t/functionbeat-not-able-to-get-cloudwatch-logs/339673)

<div class="topic-metadata">

**Author:** [@Vedant14](https://discuss.elastic.co/u/Vedant14)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 8:50am UTC](https://discuss.elastic.co/t/functionbeat-not-able-to-get-cloudwatch-logs/339673 "2023-08-01T08:50:57Z")

</div>

We are trying to fetch the CloudWatch logs in Elastic using FunctionBeat. The function is getting deployed successfully but not able to give the Cloudwatch data in Elastic. We did the configurations for the FunctionBeat …

---

## [Failed to start Filebeat](https://discuss.elastic.co/t/failed-to-start-filebeat/339743)

<div class="topic-metadata">

**Author:** [@rkannan](https://discuss.elastic.co/u/rkannan)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 8:36am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat/339743 "2023-08-01T08:36:49Z")

</div>

Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch , please find the attached screen shot,

---

## [Filebeat to add extra fields for logstash 7.17, it worked previously but not anymore?](https://discuss.elastic.co/t/filebeat-to-add-extra-fields-for-logstash-7-17-it-worked-previously-but-not-anymore/339670)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-to-add-extra-fields-for-logstash-7-17-it-worked-previously-but-not-anymore/339670 "2023-07-31T13:12:14Z")

</div>

I have my dmarc interpreter running here, and noticed that it didn't produce any data to the kibana. It looks like the config is ignored with the 7.17, and back when it was 6.x it worked. Can you tell me what I've done…

---

## [Auditbeat logs many warnings](https://discuss.elastic.co/t/auditbeat-logs-many-warnings/339689)

<div class="topic-metadata">

**Author:** [@floriankoenig-work](https://discuss.elastic.co/u/floriankoenig-work)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 12:10pm UTC](https://discuss.elastic.co/t/auditbeat-logs-many-warnings/339689 "2023-07-31T12:10:27Z")

</div>

I've noticed auditbeat spamming (sometimes ~10/sec) the log with following messages: Jul 30 00:04:44 HOSTNAME auditbeat\[2327385\]: {"log.level":"warn","@timestamp":"2023-07-30T00:04:44.668+0200","log.logger":"process","l…

---

## [Is it possible to for winlogbeat to send original raw logs?](https://discuss.elastic.co/t/is-it-possible-to-for-winlogbeat-to-send-original-raw-logs/339559)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 4:37pm UTC](https://discuss.elastic.co/t/is-it-possible-to-for-winlogbeat-to-send-original-raw-logs/339559 "2023-07-28T16:37:54Z")

</div>

For management reasons I need to ask: Is it possible to send the raw windows log (xml or text uncooked) via winlogbeat? Thanks

---

## [Filebeat only sends the first log input](https://discuss.elastic.co/t/filebeat-only-sends-the-first-log-input/339549)

<div class="topic-metadata">

**Author:** [@dcz01](https://discuss.elastic.co/u/dcz01)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-only-sends-the-first-log-input/339549 "2023-07-28T13:09:37Z")

</div>

Hello, I got an filebeat.yml with an filebeat 7.8.0 instance on an server which should send some logs to a central logstash but it only sends the first log input and the others seemd to be ignored or anything else. Can…

---

## [Filebeat set add\_id: ~ does not take effect](https://discuss.elastic.co/t/filebeat-set-add-id-does-not-take-effect/336825)

<div class="topic-metadata">

**Author:** [@yt\_h](https://discuss.elastic.co/u/yt_h)\
**Replies:** 17\
**Last updated:** [July 28, 2023, 3:19am UTC](https://discuss.elastic.co/t/filebeat-set-add-id-does-not-take-effect/336825 "2023-07-28T03:19:49Z")

</div>

I have a filebeat 7.16.2 to extract messages in kafka 3.4. After setting add\_id: ~, restarting filebeat will repeatedly send data to elasticsearch. filebeat.yml: filebeat.yml: | filebeat.inputs: - type: kafka h…

---

## [Best way to check if a database (postgres and mssql) is up and running using metricbeat?](https://discuss.elastic.co/t/best-way-to-check-if-a-database-postgres-and-mssql-is-up-and-running-using-metricbeat/339336)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 2:24pm UTC](https://discuss.elastic.co/t/best-way-to-check-if-a-database-postgres-and-mssql-is-up-and-running-using-metricbeat/339336 "2023-07-27T14:24:23Z")

</div>

Hi, what whould the best way to check if a database (postgres and mssql) is up and running using metricbeat? I need to create alerts if a database is down, in kibana "Alerts an Insights -\> rules" there is an option to a…

---

## [Winlogbeat 8.8.2 is not sending events to any pipeline](https://discuss.elastic.co/t/winlogbeat-8-8-2-is-not-sending-events-to-any-pipeline/339349)

<div class="topic-metadata">

**Author:** [@pctrindade](https://discuss.elastic.co/u/pctrindade)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 9:11pm UTC](https://discuss.elastic.co/t/winlogbeat-8-8-2-is-not-sending-events-to-any-pipeline/339349 "2023-07-26T21:11:56Z")

</div>

I am currently indexing the Windows Security log, and the events are being sent to Elasticsearch and successfully indexed. However, if I do not specify the pipeline named 'winlogbeat-8.8.2-security' in the output, the ev…

---

## [Data duplication problem after server migration](https://discuss.elastic.co/t/data-duplication-problem-after-server-migration/339186)

<div class="topic-metadata">

**Author:** [@charlielin](https://discuss.elastic.co/u/charlielin)\
**Replies:** 8\
**Last updated:** [July 26, 2023, 4:41pm UTC](https://discuss.elastic.co/t/data-duplication-problem-after-server-migration/339186 "2023-07-26T16:41:44Z")

</div>

Hi There: Currently, we are using Filebeat (version 7.15.2) to harvest logs of program A and send them to Kafka. Due to some reason, we will do some operations called Server Migration freqently. Server Migration means…

---

## [\[filebeat ASA Module\] outbound traffic log is parsed in reverse for the source and destination IP](https://discuss.elastic.co/t/filebeat-asa-module-outbound-traffic-log-is-parsed-in-reverse-for-the-source-and-destination-ip/339269)

<div class="topic-metadata">

**Author:** [@Keunwoo\_Lee](https://discuss.elastic.co/u/Keunwoo_Lee)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 12:54pm UTC](https://discuss.elastic.co/t/filebeat-asa-module-outbound-traffic-log-is-parsed-in-reverse-for-the-source-and-destination-ip/339269 "2023-07-26T12:54:04Z")

</div>

Hi. I am collecting logs using the cisco asa module, and the outbound traffic log is parsed in reverse for the source and destination IP. eg) DNS query traffic elasticsearch 8.8.1 kibana 8.8.1 filebeat 8.8.2 /mo…

---

## [Heartbeat auto reload configuration file](https://discuss.elastic.co/t/heartbeat-auto-reload-configuration-file/339163)

<div class="topic-metadata">

**Author:** [@michael31](https://discuss.elastic.co/u/michael31)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 4:25am UTC](https://discuss.elastic.co/t/heartbeat-auto-reload-configuration-file/339163 "2023-07-26T04:25:41Z")

</div>

Hello, I am setting up heartbeat with auto reload configuration files under the monitor.d path. It works fine and loads new config files but the problem is that it loads only for new files, if I edit an existing file an…

---

## [401 error when setting up filebeat google\_workspace integration](https://discuss.elastic.co/t/401-error-when-setting-up-filebeat-google-workspace-integration/338417)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 7\
**Last updated:** [July 25, 2023, 10:12pm UTC](https://discuss.elastic.co/t/401-error-when-setting-up-filebeat-google-workspace-integration/338417 "2023-07-25T22:12:52Z")

</div>

Hi All, I'm using filebeat (7.17.9) and trying to setup google workspace integration. I've followed all the steps in: I've got a json credential file: { "type": "service\_account", "project\_id": "gwm-168856537013…

---

## [Metricbeat missing dashboards](https://discuss.elastic.co/t/metricbeat-missing-dashboards/339139)

<div class="topic-metadata">

**Author:** [@Ryaninsolencee](https://discuss.elastic.co/u/Ryaninsolencee)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 3:17am UTC](https://discuss.elastic.co/t/metricbeat-missing-dashboards/339139 "2023-07-25T03:17:16Z")

</div>

As i configured my elasticsearch to https, i changed all the necessary .yml files to include the https for elastic. but now my metricbeat doesnt work anymore and im also missing the dashboard fields elasticsearch and ki…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=41)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=43)
