# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=420

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 421

---

## [Multiple distinct multiline patterns; same input file?](https://discuss.elastic.co/t/multiple-distinct-multiline-patterns-same-input-file/148027)

<div class="topic-metadata">

**Author:** [@paulh\_irl](https://discuss.elastic.co/u/paulh_irl)\
**Replies:** 4\
**Last updated:** [September 11, 2018, 10:56pm UTC](https://discuss.elastic.co/t/multiple-distinct-multiline-patterns-same-input-file/148027 "2018-09-11T22:56:03Z")

</div>

Hi all, Wondering what is the best approach to take when dealing with input log files, where the files contain more than one multiline pattern of interest, and where the patterns are of quite different formats? For exa…

---

## [Collect selected container logs from Kubernetes](https://discuss.elastic.co/t/collect-selected-container-logs-from-kubernetes/148177)

<div class="topic-metadata">

**Author:** [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Replies:** 2\
**Last updated:** [September 11, 2018, 9:25pm UTC](https://discuss.elastic.co/t/collect-selected-container-logs-from-kubernetes/148177 "2018-09-11T21:25:43Z")

</div>

I'm trying to find a solution for gathering stdout logs from only selected pods in our Kubernetes cluster. We're huge fans of using annotations to specify the behavior of things. Would be great to be able to set a pod an…

---

## [Trouble parsing multi-line json logs](https://discuss.elastic.co/t/trouble-parsing-multi-line-json-logs/147628)

<div class="topic-metadata">

**Author:** [@kreg](https://discuss.elastic.co/u/kreg)\
**Replies:** 2\
**Last updated:** [September 11, 2018, 8:53pm UTC](https://discuss.elastic.co/t/trouble-parsing-multi-line-json-logs/147628 "2018-09-11T20:53:38Z")

</div>

Beat version 6.4.0 Operating System Windows Maybe what I'm trying to do is unsupported (the answer in Error decoding JSON: json: cannot unmarshal string into Go value of type map\[string\]interface {} would indicat…

---

## [Filebeat with grok,javascript and AVRO codec](https://discuss.elastic.co/t/filebeat-with-grok-javascript-and-avro-codec/147890)

<div class="topic-metadata">

**Author:** [@Lieven\_Merckx](https://discuss.elastic.co/u/Lieven_Merckx)\
**Replies:** 2\
**Last updated:** [September 11, 2018, 8:25pm UTC](https://discuss.elastic.co/t/filebeat-with-grok-javascript-and-avro-codec/147890 "2018-09-11T20:25:30Z")

</div>

In our company we unified our logging system in a single AVRO schema pushed through Kafka. As we needed a logshipper in combination with our ELK stack, we looked at filebeat. As each application decided in the past on t…

---

## [Filebeat OOM](https://discuss.elastic.co/t/filebeat-oom/146736)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 6\
**Last updated:** [September 11, 2018, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-oom/146736 "2018-09-11T19:47:13Z")

</div>

Hi, running filebeat 6.2.2 Today I noticed filebeat was going bonkers... In /var/log/messages I see allot of these... Aug 30 13:30:43 master-0002 kernel: Out of memory: Kill process 19154 (filebeat) score 818 or sacri…

---

## [Filebeat error when parsing .txt log files (Failed to publish events: temporary bulk send failure)](https://discuss.elastic.co/t/filebeat-error-when-parsing-txt-log-files-failed-to-publish-events-temporary-bulk-send-failure/148025)

<div class="topic-metadata">

**Author:** [@jobse.batres](https://discuss.elastic.co/u/jobse.batres)\
**Replies:** 3\
**Last updated:** [September 11, 2018, 3:27pm UTC](https://discuss.elastic.co/t/filebeat-error-when-parsing-txt-log-files-failed-to-publish-events-temporary-bulk-send-failure/148025 "2018-09-11T15:27:39Z")

</div>

Hello, I'm trying to get some log files that in a .txt format to my ElasticSearch instance in AWS. I'm using Filebeat to send the output to my ES cluster. However when I initiate Filebeat on the Windows host, I get th…

---

## [How do you deploy configuration file](https://discuss.elastic.co/t/how-do-you-deploy-configuration-file/147967)

<div class="topic-metadata">

**Author:** [@marcandre](https://discuss.elastic.co/u/marcandre)\
**Replies:** 2\
**Last updated:** [September 11, 2018, 2:22pm UTC](https://discuss.elastic.co/t/how-do-you-deploy-configuration-file/147967 "2018-09-11T14:22:55Z")

</div>

Hello, I wonder how people deploy the beats configuration files to all their servers? Right now, I have a configuration file with all module enabled. It use puppet to send the files to all my nodes. It cause a lot of er…

---

## [How to enable ssh module in filebeat for Ubuntu 18.04/16.04](https://discuss.elastic.co/t/how-to-enable-ssh-module-in-filebeat-for-ubuntu-18-04-16-04/148108)

<div class="topic-metadata">

**Author:** [@Aftab\_Ali](https://discuss.elastic.co/u/Aftab_Ali)\
**Replies:** 0\
**Last updated:** [September 11, 2018, 10:30am UTC](https://discuss.elastic.co/t/how-to-enable-ssh-module-in-filebeat-for-ubuntu-18-04-16-04/148108 "2018-09-11T10:30:37Z")

</div>

Dear Team, I am using Ubuntu 16.04 and here is /var/log/syslog and /var/log/auth.log path in Ubuntu 16.04 and as per the tutorials there was /var/log/message and /var/log/secure path is available to configure ssh modul…

---

## [Filebeat timestamp on docker input](https://discuss.elastic.co/t/filebeat-timestamp-on-docker-input/147686)

<div class="topic-metadata">

**Author:** [@prometheus1](https://discuss.elastic.co/u/prometheus1)\
**Replies:** 2\
**Last updated:** [September 11, 2018, 7:10am UTC](https://discuss.elastic.co/t/filebeat-timestamp-on-docker-input/147686 "2018-09-11T07:10:49Z")

</div>

In case of docker input, filebeat attaches the @timestamp field from the docker timestamp. I want to capture the time when filebeat actually read this log along with the docker timestamp in a field, say, @filebeattimesta…

---

## [Filebeat Grok for Date IIS logs](https://discuss.elastic.co/t/filebeat-grok-for-date-iis-logs/147659)

<div class="topic-metadata">

**Author:** [@necrolingus](https://discuss.elastic.co/u/necrolingus)\
**Replies:** 9\
**Last updated:** [September 11, 2018, 6:19am UTC](https://discuss.elastic.co/t/filebeat-grok-for-date-iis-logs/147659 "2018-09-11T06:19:09Z")

</div>

Hi everyone I am trying to import IIS Logs, for now literally one field which is the date and time. Here is what my log file looks like: #Software: IIS Advanced Logging Module #Version: 1.0 #Start-Date: 2018-09-07 05…

---

## [Filebeat setup kibana through proxy](https://discuss.elastic.co/t/filebeat-setup-kibana-through-proxy/147832)

<div class="topic-metadata">

**Author:** [@lexicoder](https://discuss.elastic.co/u/lexicoder)\
**Replies:** 5\
**Last updated:** [September 10, 2018, 10:54pm UTC](https://discuss.elastic.co/t/filebeat-setup-kibana-through-proxy/147832 "2018-09-10T22:54:09Z")

</div>

I'm trying to make filebeat setup kibana behind a proxy but can't seem to see any documentation regarding how to do this.

---

## [Monitoring Specials Event Logs](https://discuss.elastic.co/t/monitoring-specials-event-logs/147914)

<div class="topic-metadata">

**Author:** [@cdra](https://discuss.elastic.co/u/cdra)\
**Replies:** 2\
**Last updated:** [September 10, 2018, 7:28pm UTC](https://discuss.elastic.co/t/monitoring-specials-event-logs/147914 "2018-09-10T19:28:42Z")

</div>

I need to monitoring this event log: ...Microsoft\\Windows\\WLAN-AutoConfig\\Operativo Is it possible?

---

## [Issues installing Auditbeat on Oracle Linux and Red Hat](https://discuss.elastic.co/t/issues-installing-auditbeat-on-oracle-linux-and-red-hat/147847)

<div class="topic-metadata">

**Author:** [@homood](https://discuss.elastic.co/u/homood)\
**Replies:** 1\
**Last updated:** [September 10, 2018, 7:26pm UTC](https://discuss.elastic.co/t/issues-installing-auditbeat-on-oracle-linux-and-red-hat/147847 "2018-09-10T19:26:27Z")

</div>

I am trying to install Auditbeat on Oracle Linux 6.8 and Red Hat 7.5 but I can't run the service after installation. The following are the error messages I get: On Oracle Linux: 2018-09-03T09:04:49.775+0300 INFO …

---

## [Configure \*Beats to not require GET request on Elasticsearch server](https://discuss.elastic.co/t/configure-beats-to-not-require-get-request-on-elasticsearch-server/147420)

<div class="topic-metadata">

**Author:** [@nnarain](https://discuss.elastic.co/u/nnarain)\
**Replies:** 2\
**Last updated:** [September 10, 2018, 6:56pm UTC](https://discuss.elastic.co/t/configure-beats-to-not-require-get-request-on-elasticsearch-server/147420 "2018-09-10T18:56:38Z")

</div>

Current HAProxy configuration is to block GET requests on the Elasticsearch server. This means that the "Ping" requests fail as they use HTTP GET requests. Is it possible to configure Auditbeat to not require the ping a…

---

## [Filebeat penalty for unused log path inputs](https://discuss.elastic.co/t/filebeat-penalty-for-unused-log-path-inputs/147739)

<div class="topic-metadata">

**Author:** [@grantk](https://discuss.elastic.co/u/grantk)\
**Replies:** 3\
**Last updated:** [September 10, 2018, 3:38pm UTC](https://discuss.elastic.co/t/filebeat-penalty-for-unused-log-path-inputs/147739 "2018-09-10T15:38:42Z")

</div>

I would like to use a common configuration for filebeats across servers, some of which may not have all apps installed. Can you quantify the performance/utilization penalty for paths that do not exist of type log? Than…

---

## [Query Regarding Filebeat](https://discuss.elastic.co/t/query-regarding-filebeat/147672)

<div class="topic-metadata">

**Author:** [@Akhilesh-Tiwari](https://discuss.elastic.co/u/Akhilesh-Tiwari)\
**Replies:** 9\
**Last updated:** [September 10, 2018, 1:31pm UTC](https://discuss.elastic.co/t/query-regarding-filebeat/147672 "2018-09-10T13:31:19Z")

</div>

HI @magnusbaeck and @elastic My Requirement is, Reading the logs from filebeat in windows System and push that logs into a different windows system's File. without using logstash and elasticsearch. is it possib…

---

## [Kafka Logs not working](https://discuss.elastic.co/t/kafka-logs-not-working/147830)

<div class="topic-metadata">

**Author:** [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Replies:** 1\
**Last updated:** [September 10, 2018, 1:42pm UTC](https://discuss.elastic.co/t/kafka-logs-not-working/147830 "2018-09-10T13:42:18Z")

</div>

I installed FileBEat (Confirmed that its working) then I configured Kafka with the following configuration - module: kafka # All logs log: enabled: true # Set custom paths for Kafka. If left empty, # Fi…

---

## [How to get IP through metricbeat from Windows systems?](https://discuss.elastic.co/t/how-to-get-ip-through-metricbeat-from-windows-systems/147235)

<div class="topic-metadata">

**Author:** [@shahid3507](https://discuss.elastic.co/u/shahid3507)\
**Replies:** 5\
**Last updated:** [September 10, 2018, 1:03pm UTC](https://discuss.elastic.co/t/how-to-get-ip-through-metricbeat-from-windows-systems/147235 "2018-09-10T13:03:53Z")

</div>

I am using elk stack and metricbeat for getting metrices from windows machines but as socket metricset is not supported for windows, Is there any way to get IP from windows systems through metricbeat.

---

## [Auditbeat - map changes to users](https://discuss.elastic.co/t/auditbeat-map-changes-to-users/134703)

<div class="topic-metadata">

**Author:** [@nwed](https://discuss.elastic.co/u/nwed)\
**Replies:** 3\
**Last updated:** [September 10, 2018, 12:01pm UTC](https://discuss.elastic.co/t/auditbeat-map-changes-to-users/134703 "2018-09-10T12:01:58Z")

</div>

Hello, we are looking at leveraging auditbeat to replace a commercial FIM solution in use. One of our requirements is that any changes initiated by users, are mapped and notated in the logs. Is anyone aware of an easy wa…

---

## [Metricbeat Autodiscover - error parsing URL: empty host](https://discuss.elastic.co/t/metricbeat-autodiscover-error-parsing-url-empty-host/147888)

<div class="topic-metadata">

**Author:** [@simioa](https://discuss.elastic.co/u/simioa)\
**Replies:** 2\
**Last updated:** [September 10, 2018, 11:57am UTC](https://discuss.elastic.co/t/metricbeat-autodiscover-error-parsing-url-empty-host/147888 "2018-09-10T11:57:18Z")

</div>

Metricbeat Version used: 6.4.0 Kubernetes Version: 1.10 Hi, I'm trying to get the Prometheus Collector working with Hints based autodiscovery in Kubernetes. Unfortunately I always get the following Error: ERROR \[au…

---

## [Importing CSV data via metricbeat](https://discuss.elastic.co/t/importing-csv-data-via-metricbeat/147913)

<div class="topic-metadata">

**Author:** [@sribalaji\_dac](https://discuss.elastic.co/u/sribalaji_dac)\
**Replies:** 2\
**Last updated:** [September 10, 2018, 10:05am UTC](https://discuss.elastic.co/t/importing-csv-data-via-metricbeat/147913 "2018-09-10T10:05:47Z")

</div>

Is there a way to import CSV output from an api(http) call using metricbeat ?

---

## [Kibana The aggregations key is missing from the response ERROR](https://discuss.elastic.co/t/kibana-the-aggregations-key-is-missing-from-the-response-error/147717)

<div class="topic-metadata">

**Author:** [@jabu](https://discuss.elastic.co/u/jabu)\
**Replies:** 2\
**Last updated:** [September 10, 2018, 9:25am UTC](https://discuss.elastic.co/t/kibana-the-aggregations-key-is-missing-from-the-response-error/147717 "2018-09-10T09:25:59Z")

</div>

Hi i just followed this tutorial: Starting with the Elasticsearch Platform and its Solutions | Elastic To set up a little ELK-stack on my Ubuntu VM. I used metricbeats so that i could monitor my VM as practice. My Kiba…

---

## [Filebeat not passing logs through logstash](https://discuss.elastic.co/t/filebeat-not-passing-logs-through-logstash/147926)

<div class="topic-metadata">

**Author:** [@Naveen\_Reddy\_Sama](https://discuss.elastic.co/u/Naveen_Reddy_Sama)\
**Replies:** 0\
**Last updated:** [September 10, 2018, 9:16am UTC](https://discuss.elastic.co/t/filebeat-not-passing-logs-through-logstash/147926 "2018-09-10T09:16:02Z")

</div>

Hi folks am passing logs from filebeat through logstash filter, am unable to pass the logs. but when am passing directly to kibana am able to get logs in kibana. my file beat yml filebeat.prospectors: type: log pat…

---

## [Question about filebeat monitor metrics](https://discuss.elastic.co/t/question-about-filebeat-monitor-metrics/147923)

<div class="topic-metadata">

**Author:** [@zahgboat](https://discuss.elastic.co/u/zahgboat)\
**Replies:** 0\
**Last updated:** [September 10, 2018, 8:59am UTC](https://discuss.elastic.co/t/question-about-filebeat-monitor-metrics/147923 "2018-09-10T08:59:09Z")

</div>

Hi , I am new to ES Stack . I am trying to improve the performance of filebeat publishing events to logstash by monitioring tool. I find it disturbing when I saw the Graph of Event Rate : Though I have read the no…

---

## [FileBeat 6.4.0 on Windows as non-service app and environment variables](https://discuss.elastic.co/t/filebeat-6-4-0-on-windows-as-non-service-app-and-environment-variables/146677)

<div class="topic-metadata">

**Author:** [@prwillmot](https://discuss.elastic.co/u/prwillmot)\
**Replies:** 4\
**Last updated:** [September 10, 2018, 5:37am UTC](https://discuss.elastic.co/t/filebeat-6-4-0-on-windows-as-non-service-app-and-environment-variables/146677 "2018-09-10T05:37:29Z")

</div>

With FileBeat 6.4.0 on Windows (running as a stand-alone app from command line, not a service) we are trying to use various environment variable string values as custom field values per reference document content at http…

---

## [How do I send logs to elastic search which is set up on a VM , from a docker filebeat](https://discuss.elastic.co/t/how-do-i-send-logs-to-elastic-search-which-is-set-up-on-a-vm-from-a-docker-filebeat/147722)

<div class="topic-metadata">

**Author:** [@rohit84](https://discuss.elastic.co/u/rohit84)\
**Replies:** 1\
**Last updated:** [September 9, 2018, 1:31pm UTC](https://discuss.elastic.co/t/how-do-i-send-logs-to-elastic-search-which-is-set-up-on-a-vm-from-a-docker-filebeat/147722 "2018-09-09T13:31:08Z")

</div>

Thhis is my filebeat.yml - output: elasticsearch: enabled: true hosts: - http://\<my\_external\_host\_having\_elasticsearch\_instance\>:9200 # ssl # certificate\_authorities: \_ # - /etc/pki/tls/certs/logstash-beats.cr…

---

## [Config.go don't react to any changes](https://discuss.elastic.co/t/config-go-dont-react-to-any-changes/147853)

<div class="topic-metadata">

**Author:** [@kmacew](https://discuss.elastic.co/u/kmacew)\
**Replies:** 1\
**Last updated:** [September 9, 2018, 11:15am UTC](https://discuss.elastic.co/t/config-go-dont-react-to-any-changes/147853 "2018-09-09T11:15:39Z")

</div>

Hi I followed tutorial how to create your own beat (https://www.elastic.co/guide/en/beats/devguide/current/new-beat.html). I found strange behavior, I might be doing something wrong, please correct me. I edited config/c…

---

## [Adding metrics](https://discuss.elastic.co/t/adding-metrics/147839)

<div class="topic-metadata">

**Author:** [@Hulio](https://discuss.elastic.co/u/Hulio)\
**Replies:** 1\
**Last updated:** [September 9, 2018, 8:21am UTC](https://discuss.elastic.co/t/adding-metrics/147839 "2018-09-09T08:21:39Z")

</div>

I installed metricbeat, but how can i add metrics to dashboard? I add index but in discover no data.

---

## [Show logs from nginx](https://discuss.elastic.co/t/show-logs-from-nginx/147845)

<div class="topic-metadata">

**Author:** [@Hulio](https://discuss.elastic.co/u/Hulio)\
**Replies:** 3\
**Last updated:** [September 9, 2018, 8:13am UTC](https://discuss.elastic.co/t/show-logs-from-nginx/147845 "2018-09-09T08:13:18Z")

</div>

I'm trying to visualise data as table. I want to show errors 404 with route as message. How can I do that? I can get a count, but not message.

---

## [System module and Nginx module dashboard](https://discuss.elastic.co/t/system-module-and-nginx-module-dashboard/147561)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 4\
**Last updated:** [September 8, 2018, 3:38am UTC](https://discuss.elastic.co/t/system-module-and-nginx-module-dashboard/147561 "2018-09-08T03:38:07Z")

</div>

Hello Team, I have enabled the system module and nginx module for filebeat. I am getting the logs on kibana dashboard from both the modules. But when i am check the filebeat dashboard for nginx and syslog no data is ava…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=419)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=421)
