# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=421

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 422

---

## [vSphere module - no sample dashboard](https://discuss.elastic.co/t/vsphere-module-no-sample-dashboard/147774)

<div class="topic-metadata">

**Author:** [@Ken\_Leoni](https://discuss.elastic.co/u/Ken_Leoni)\
**Replies:** 1\
**Last updated:** [September 8, 2018, 3:41am UTC](https://discuss.elastic.co/t/vsphere-module-no-sample-dashboard/147774 "2018-09-08T03:41:35Z")

</div>

I want to make sure I'm not missing anything. The vSphere module doesn't load any sample dashboards correct?

---

## [Filebeat logs have these error messages in the log file](https://discuss.elastic.co/t/filebeat-logs-have-these-error-messages-in-the-log-file/147631)

<div class="topic-metadata">

**Author:** [@Sindhu\_Reddy](https://discuss.elastic.co/u/Sindhu_Reddy)\
**Replies:** 5\
**Last updated:** [September 8, 2018, 12:39am UTC](https://discuss.elastic.co/t/filebeat-logs-have-these-error-messages-in-the-log-file/147631 "2018-09-08T00:39:55Z")

</div>

I am getting the below error pretty often, not sure why this error occurs. Any information regarding this problem is appreciated.The logstashcluster has healthy instances and it is up and running. Filebeat Logs : 2…

---

## [Timeline graph of server connection count](https://discuss.elastic.co/t/timeline-graph-of-server-connection-count/147741)

<div class="topic-metadata">

**Author:** [@MikaelLindstrom](https://discuss.elastic.co/u/MikaelLindstrom)\
**Replies:** 1\
**Last updated:** [September 7, 2018, 7:56pm UTC](https://discuss.elastic.co/t/timeline-graph-of-server-connection-count/147741 "2018-09-07T19:56:34Z")

</div>

Hi, we have a server that's listening on a port and servers can connect to that port (i.e. standard stuff...). I'd like to graph over time the number of active connections (i.e. netstat -anp | grep | grep -c ESTABLISH…

---

## [Operation not permitted \<= New Beat](https://discuss.elastic.co/t/operation-not-permitted-new-beat/147459)

<div class="topic-metadata">

**Author:** [@kmacew](https://discuss.elastic.co/u/kmacew)\
**Replies:** 5\
**Last updated:** [September 7, 2018, 6:46pm UTC](https://discuss.elastic.co/t/operation-not-permitted-new-beat/147459 "2018-09-07T18:46:04Z")

</div>

Hi I followed tutorial how to create new beat (https://www.elastic.co/guide/en/beats/devguide/current/new-beat.html). With tutorial I didn't have much problems. Since trying to add some logic to new beat I encountered s…

---

## [Failed to publish events caused by: write tcp 10.90.66.80:57738-\>10.90.66.48:5044: write: connection reset by peer](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-write-tcp-10-90-66-80-57738-10-90-66-48-write-connection-reset-by-peer/147632)

<div class="topic-metadata">

**Author:** [@fewknow](https://discuss.elastic.co/u/fewknow)\
**Replies:** 3\
**Last updated:** [September 7, 2018, 6:37pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-write-tcp-10-90-66-80-57738-10-90-66-48-write-connection-reset-by-peer/147632 "2018-09-07T18:37:02Z")

</div>

2018-09-06T16:26:36.086-0400 ERROR logstash/async.go:252 Failed to publish events caused by: write tcp 10.90.66.80:57738-\>10.90.66.48:5044: write: connection reset by peer 2018-09-06T16:26:37.086-0400 ERROR pipeline/out…

---

## [How to set different filters for different logs in beats and logstash 6.3.2](https://discuss.elastic.co/t/how-to-set-different-filters-for-different-logs-in-beats-and-logstash-6-3-2/147661)

<div class="topic-metadata">

**Author:** [@Anil\_Bind](https://discuss.elastic.co/u/Anil_Bind)\
**Replies:** 2\
**Last updated:** [September 7, 2018, 8:46am UTC](https://discuss.elastic.co/t/how-to-set-different-filters-for-different-logs-in-beats-and-logstash-6-3-2/147661 "2018-09-07T08:46:32Z")

</div>

Hi, First of all, I am using version 6.3.2 for all the beats and elk stack. I have elk setup on centOS 7 and the node is windows server 2012 r2, I was able to filter IIS logs by using below filter. filter { if \[@meta…

---

## [Metricbeat memory usage](https://discuss.elastic.co/t/metricbeat-memory-usage/147670)

<div class="topic-metadata">

**Author:** [@Zane\_Storha](https://discuss.elastic.co/u/Zane_Storha)\
**Replies:** 1\
**Last updated:** [September 7, 2018, 12:25pm UTC](https://discuss.elastic.co/t/metricbeat-memory-usage/147670 "2018-09-07T12:25:56Z")

</div>

What is the most effective way to decrease size of indexes ? I'ts already more than 15gb big per day and can't see any data in Kibana longer than last 15 minutes.

---

## [Monitoring PDFs and Words files](https://discuss.elastic.co/t/monitoring-pdfs-and-words-files/147698)

<div class="topic-metadata">

**Author:** [@alejandro.perez](https://discuss.elastic.co/u/alejandro.perez)\
**Replies:** 1\
**Last updated:** [September 7, 2018, 11:37am UTC](https://discuss.elastic.co/t/monitoring-pdfs-and-words-files/147698 "2018-09-07T11:37:22Z")

</div>

Good, First of all ask for forgiveness if the question I'm going to ask is a bit stupid, but I can not find information about it. Is it possible to monitor the records on a WORD or PDF document? As for example .. acces…

---

## [Metric beat unable to write data](https://discuss.elastic.co/t/metric-beat-unable-to-write-data/146926)

<div class="topic-metadata">

**Author:** [@ReasonDuan](https://discuss.elastic.co/u/ReasonDuan)\
**Replies:** 3\
**Last updated:** [September 7, 2018, 5:14am UTC](https://discuss.elastic.co/t/metric-beat-unable-to-write-data/146926 "2018-09-07T05:14:55Z")

</div>

When crossing the day, when the data needs to be written to the new index, the ES will be unable to write. Then I stop some metricbeat instances and it will return to normal. Metricbeat Version: 6.3.1 ES Version: 5.5.…

---

## [Can't to get a data from filebeats](https://discuss.elastic.co/t/cant-to-get-a-data-from-filebeats/147079)

<div class="topic-metadata">

**Author:** [@Hulio](https://discuss.elastic.co/u/Hulio)\
**Replies:** 7\
**Last updated:** [September 7, 2018, 4:18am UTC](https://discuss.elastic.co/t/cant-to-get-a-data-from-filebeats/147079 "2018-09-07T04:18:02Z")

</div>

Hello, I'm trying setup elk + filebeats. It's my first time. If I right understand, It can show me filtered logs and any metrics. I install it in docker (with docker-compose) and now I have containers: elasticsearch, lo…

---

## [Beat not waiting for elasticsearch when sending dashboard](https://discuss.elastic.co/t/beat-not-waiting-for-elasticsearch-when-sending-dashboard/147468)

<div class="topic-metadata">

**Author:** [@Jas\_Ahluwalia](https://discuss.elastic.co/u/Jas_Ahluwalia)\
**Replies:** 3\
**Last updated:** [September 6, 2018, 9:29pm UTC](https://discuss.elastic.co/t/beat-not-waiting-for-elasticsearch-when-sending-dashboard/147468 "2018-09-06T21:29:46Z")

</div>

Hi, I'm runinng the ELK stack in docker containers (6.4). I have Metricbeat with custom dashboards that i'm mounting into the container. If elasticsearch isn't up, I get the folowing error: metricbeat\_1 | Exiting: Err…

---

## [Multiple DNS requests](https://discuss.elastic.co/t/multiple-dns-requests/147634)

<div class="topic-metadata">

**Author:** [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Replies:** 0\
**Last updated:** [September 6, 2018, 8:38pm UTC](https://discuss.elastic.co/t/multiple-dns-requests/147634 "2018-09-06T20:38:53Z")

</div>

We are using filebeat 6.2.3 to output data to Kafka. We are seeing issues when kafka is down, filebeat continues to make large number of DNS requests to resolve the kafka hosts. Any thoughts/ideas on how we can possibly…

---

## [Active Inactive Metricbeats Monitoring](https://discuss.elastic.co/t/active-inactive-metricbeats-monitoring/147626)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [September 6, 2018, 7:28pm UTC](https://discuss.elastic.co/t/active-inactive-metricbeats-monitoring/147626 "2018-09-06T19:28:45Z")

</div>

Is there a way to see what servers have active and also inactive metricbeats? Over the past two week we went from 118 nodes (Linux and Win) to 97. We are trying to find a way to ensure we are continually getting data fr…

---

## [Fileset 6.4.0: Error: elasticsearch/log is configured but doesn't exist](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 4\
**Last updated:** [September 6, 2018, 5:45pm UTC](https://discuss.elastic.co/t/fileset-6-4-0-error-elasticsearch-log-is-configured-but-doesnt-exist/146921 "2018-09-06T17:45:40Z")

</div>

I'm using the Filebeat Elasticsearch module introduced in filebeat 6.4.0, but I get this error when I run filebeat: ERROR \[autodiscover\] cfgfile/list.go:104 Error creating runner from config: Fileset elasticsearch/log i…

---

## [How to configure winlogbeat to use existing index in elasticsearch](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533)

<div class="topic-metadata">

**Author:** [@Teja](https://discuss.elastic.co/u/Teja)\
**Replies:** 4\
**Last updated:** [September 6, 2018, 5:04pm UTC](https://discuss.elastic.co/t/how-to-configure-winlogbeat-to-use-existing-index-in-elasticsearch/147533 "2018-09-06T17:04:33Z")

</div>

Hi Team, I have index in my elastic instance with index pattern "version-1-2018-". Now, I want my windows logs to be embark under this "version-1-2018-". i have did the uploaded the "win beat pattern" in my elasticsear…

---

## [Filebeat preventing creation of new logs in rotation?](https://discuss.elastic.co/t/filebeat-preventing-creation-of-new-logs-in-rotation/147594)

<div class="topic-metadata">

**Author:** [@bogbrush](https://discuss.elastic.co/u/bogbrush)\
**Replies:** 2\
**Last updated:** [September 6, 2018, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-preventing-creation-of-new-logs-in-rotation/147594 "2018-09-06T15:45:42Z")

</div>

My software currently cycles logs by gzipping the filled log and creating a new one with the same name. I have a Filebeat harvesting from the unzipped log only. The beat happily reads in the unzipped log as it is being …

---

## [Packetbeat input from pcap -\> all sniffed field on ELK](https://discuss.elastic.co/t/packetbeat-input-from-pcap-all-sniffed-field-on-elk/147440)

<div class="topic-metadata">

**Author:** [@mardux](https://discuss.elastic.co/u/mardux)\
**Replies:** 5\
**Last updated:** [September 6, 2018, 3:04pm UTC](https://discuss.elastic.co/t/packetbeat-input-from-pcap-all-sniffed-field-on-elk/147440 "2018-09-06T15:04:49Z")

</div>

Hi all. i try to import a pcap file in ELK, using packetbeat. in my pcap file i have about 100k packets (999671 packet are HTTP traffic on port 80, the rest other protocol and port, like TLS/HTTPS on port 443) using t…

---

## [The "fields" property only works with the dictionary type](https://discuss.elastic.co/t/the-fields-property-only-works-with-the-dictionary-type/147578)

<div class="topic-metadata">

**Author:** [@devantoine](https://discuss.elastic.co/u/devantoine)\
**Replies:** 2\
**Last updated:** [September 6, 2018, 2:49pm UTC](https://discuss.elastic.co/t/the-fields-property-only-works-with-the-dictionary-type/147578 "2018-09-06T14:49:12Z")

</div>

Hi, The "fields" property is here to add custom fields to an input. The doc says: Fields can be scalar values, arrays, dictionaries, or any nested combination of these. But if you set a scalar value like this: f…

---

## [Error on make setup](https://discuss.elastic.co/t/error-on-make-setup/147473)

<div class="topic-metadata">

**Author:** [@AnZot](https://discuss.elastic.co/u/AnZot)\
**Replies:** 4\
**Last updated:** [September 6, 2018, 1:49pm UTC](https://discuss.elastic.co/t/error-on-make-setup/147473 "2018-09-06T13:49:48Z")

</div>

Hi, I'm trying to create a new beat by using this guide - https://www.elastic.co/guide/en/beats/devguide/6.4/new-beat.html After I generated my beat and trying to setup it with 'make setup' command I received this error…

---

## [Parsing problem for iis server log using filebeat 6.3.2](https://discuss.elastic.co/t/parsing-problem-for-iis-server-log-using-filebeat-6-3-2/146227)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 7\
**Last updated:** [September 6, 2018, 1:36pm UTC](https://discuss.elastic.co/t/parsing-problem-for-iis-server-log-using-filebeat-6-3-2/146227 "2018-09-06T13:36:24Z")

</div>

i have a log like below #Software: Microsoft Internet Information Services 7.5 #Version: 1.0 #Date: 2018-08-28 18:24:25 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) s…

---

## [How to do sniff data from all connected network in windows packetbeat](https://discuss.elastic.co/t/how-to-do-sniff-data-from-all-connected-network-in-windows-packetbeat/146734)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 5\
**Last updated:** [September 6, 2018, 1:28pm UTC](https://discuss.elastic.co/t/how-to-do-sniff-data-from-all-connected-network-in-windows-packetbeat/146734 "2018-09-06T13:28:13Z")

</div>

How to sniff data from all connected network in packetbeat how to do packetbeat.interfaces.device: all in windows ? is there a way for that ?

---

## [Error starting filebeat reading CA certificate](https://discuss.elastic.co/t/error-starting-filebeat-reading-ca-certificate/147419)

<div class="topic-metadata">

**Author:** [@jabu](https://discuss.elastic.co/u/jabu)\
**Replies:** 2\
**Last updated:** [September 6, 2018, 12:54pm UTC](https://discuss.elastic.co/t/error-starting-filebeat-reading-ca-certificate/147419 "2018-09-06T12:54:59Z")

</div>

I'm unable to start filebeat This is the log file 2018-09-05T06:04:27-07:00 INFO Home path: \[/usr/share/filebeat\] Config path: \[/etc/filebeat\] Data path: \[/var/lib/filebeat\] Logs path: \[/var/log/filebeat\] 2018-09-05T06…

---

## [MetricBeat - Unable to create dynamic namespace](https://discuss.elastic.co/t/metricbeat-unable-to-create-dynamic-namespace/147147)

<div class="topic-metadata">

**Author:** [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Replies:** 4\
**Last updated:** [September 6, 2018, 12:15pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-create-dynamic-namespace/147147 "2018-09-06T12:15:54Z")

</div>

MetricBeat - Unable to create dynamic namespace. My project requirement is to create a dynamic namespace(based on hostname). How do i get access to host name or beat name inside metricbeat.yml I tried something simila…

---

## [FileBeat6.2.4 ERROR	logstash/async.go:235	Failed to publish events caused by: write tcp 192.168.1.2:19616-\>192.168.1.3:5044: write: connection reset by peer](https://discuss.elastic.co/t/filebeat6-2-4-error-logstash-async-go-235-failed-to-publish-events-caused-by-write-tcp-192-168-1-2-19616-192-168-1-3-write-connection-reset-by-peer/147503)

<div class="topic-metadata">

**Author:** [@xiaozuo](https://discuss.elastic.co/u/xiaozuo)\
**Replies:** 7\
**Last updated:** [September 6, 2018, 9:06am UTC](https://discuss.elastic.co/t/filebeat6-2-4-error-logstash-async-go-235-failed-to-publish-events-caused-by-write-tcp-192-168-1-2-19616-192-168-1-3-write-connection-reset-by-peer/147503 "2018-09-06T09:06:29Z")

</div>

Hello. I'm using the filebeat 6.2.4, but I get this error when I run filebeat, how to solve? 2018-09-06T14:00:09.729+0800 DEBUG \[harvester\] log/log.go:85 End of file reached: /var/log/messages; Backoff now. 2018-09-06T…

---

## [Perforce server log module for Filebeat](https://discuss.elastic.co/t/perforce-server-log-module-for-filebeat/147168)

<div class="topic-metadata">

**Author:** [@robaato](https://discuss.elastic.co/u/robaato)\
**Replies:** 6\
**Last updated:** [September 6, 2018, 7:53am UTC](https://discuss.elastic.co/t/perforce-server-log-module-for-filebeat/147168 "2018-09-06T07:53:02Z")

</div>

Hi Am looking at developing this - wrapping up a log parsing library to integrate into Filebeat. The issue is around matching up start/end log entries, together with various intervening log entries for some commands (l…

---

## [Filebeat isn't filtering and sending huge logs](https://discuss.elastic.co/t/filebeat-isnt-filtering-and-sending-huge-logs/147360)

<div class="topic-metadata">

**Author:** [@elk11](https://discuss.elastic.co/u/elk11)\
**Replies:** 7\
**Last updated:** [September 6, 2018, 7:33am UTC](https://discuss.elastic.co/t/filebeat-isnt-filtering-and-sending-huge-logs/147360 "2018-09-06T07:33:58Z")

</div>

Hi, This is in continuation of: Error loading config file: yaml: line 21: did not find expected key Config file: filebeat.prospectors: - type: log enabled: true paths: - /usr/share/filebeat/dockerlogs/3780b560…

---

## [Filebeat prospector enable / disabled being ignored](https://discuss.elastic.co/t/filebeat-prospector-enable-disabled-being-ignored/147456)

<div class="topic-metadata">

**Author:** [@TechSavvy](https://discuss.elastic.co/u/TechSavvy)\
**Replies:** 1\
**Last updated:** [September 6, 2018, 7:19am UTC](https://discuss.elastic.co/t/filebeat-prospector-enable-disabled-being-ignored/147456 "2018-09-06T07:19:56Z")

</div>

Hello. We were using the ELK stack with Filebeat prospector input configured, running everything on 6.3.1. Everything was working as expected. A week ago, upgraded ES, LS, and Kibana to 6.4.0 but left Filebeat on 6.3.1…

---

## [Event\_data.param# instead of the correct fields](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805)

<div class="topic-metadata">

**Author:** [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Replies:** 5\
**Last updated:** [September 6, 2018, 3:45am UTC](https://discuss.elastic.co/t/event-data-param-instead-of-the-correct-fields/146805 "2018-09-06T03:45:49Z")

</div>

Hi, On kibana when I forwarded the logs I don't see like message id or message fields and a parsed fields, I just see this event\_data.param. How can I send in the proper format? This is the raw json. Our flow loks li…

---

## [How does beat communicate with applications and logstash?](https://discuss.elastic.co/t/how-does-beat-communicate-with-applications-and-logstash/147392)

<div class="topic-metadata">

**Author:** [@Malay\_Peaas](https://discuss.elastic.co/u/Malay_Peaas)\
**Replies:** 4\
**Last updated:** [September 6, 2018, 5:09am UTC](https://discuss.elastic.co/t/how-does-beat-communicate-with-applications-and-logstash/147392 "2018-09-06T05:09:59Z")

</div>

Hi, I am new to Elastic stack, I read about how to configure FileBeat/WinLogBeat etc. to read logs from application/OS and output them to logstash. I would like to know that how does beat communicate with logstash and a…

---

## [Dashboard Metricbeat Zookeeper missing](https://discuss.elastic.co/t/dashboard-metricbeat-zookeeper-missing/147409)

<div class="topic-metadata">

**Author:** [@sicute](https://discuss.elastic.co/u/sicute)\
**Replies:** 2\
**Last updated:** [September 6, 2018, 3:48am UTC](https://discuss.elastic.co/t/dashboard-metricbeat-zookeeper-missing/147409 "2018-09-06T03:48:53Z")

</div>

Hi I try deploy elk kibana , but the dashboard metricbeat was missing . Metricbeat version 6.4 And Here I paste my screen . Here list modules: Here my elk

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=420)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=422)
