# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=422

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 423

---

## [Kibana dashboards for MySQL seem meaningless](https://discuss.elastic.co/t/kibana-dashboards-for-mysql-seem-meaningless/147231)

<div class="topic-metadata">

**Author:** [@lucasjkr](https://discuss.elastic.co/u/lucasjkr)\
**Replies:** 4\
**Last updated:** [September 6, 2018, 3:08am UTC](https://discuss.elastic.co/t/kibana-dashboards-for-mysql-seem-meaningless/147231 "2018-09-06T03:08:40Z")

</div>

I'm still testing everything out, this is a screenshot of Kibana 6.4 charting MySQL usage on 2 docker instances and one separate server, using Metricbeat 6.4 on each server (well, there is a single docker container monit…

---

## [Docker discovery hosts not resolving](https://discuss.elastic.co/t/docker-discovery-hosts-not-resolving/147125)

<div class="topic-metadata">

**Author:** [@memelet](https://discuss.elastic.co/u/memelet)\
**Replies:** 3\
**Last updated:** [September 5, 2018, 11:00pm UTC](https://discuss.elastic.co/t/docker-discovery-hosts-not-resolving/147125 "2018-09-05T23:00:59Z")

</div>

I have the label on containers co.elastic.metrics/hosts: '${data.host}:5001' And hints enabled in metricbeat.yml metricbeat\_autodiscover: providers: - type: docker hints.enabled: true templ…

---

## [Making dynamic Schema in metricbeat?](https://discuss.elastic.co/t/making-dynamic-schema-in-metricbeat/147480)

<div class="topic-metadata">

**Author:** [@Grigory\_Shamov1](https://discuss.elastic.co/u/Grigory_Shamov1)\
**Replies:** 1\
**Last updated:** [September 5, 2018, 10:34pm UTC](https://discuss.elastic.co/t/making-dynamic-schema-in-metricbeat/147480 "2018-09-05T22:34:22Z")

</div>

Hi, devguide/6.X/creating-metricsets.html recommends using the Schema packages and eventMapping() to convert Golang maps and string values to the common.MapStr with correct types of the values. It looks great. The exa…

---

## [Struggling with storage management](https://discuss.elastic.co/t/struggling-with-storage-management/145978)

<div class="topic-metadata">

**Author:** [@seanva](https://discuss.elastic.co/u/seanva)\
**Replies:** 12\
**Last updated:** [September 5, 2018, 2:50pm UTC](https://discuss.elastic.co/t/struggling-with-storage-management/145978 "2018-09-05T14:50:44Z")

</div>

I'm at about 50 windows servers that index weekly (i.e. winlogbeat 2018.34 would be the latest week of the year) Storage is coming out to be about 10 gigs a week, depending on amount of activity on the servers. This is …

---

## [Ingest node message parsing issue](https://discuss.elastic.co/t/ingest-node-message-parsing-issue/147173)

<div class="topic-metadata">

**Author:** [@miki\_haiat](https://discuss.elastic.co/u/miki_haiat)\
**Replies:** 5\
**Last updated:** [September 5, 2018, 2:13pm UTC](https://discuss.elastic.co/t/ingest-node-message-parsing-issue/147173 "2018-09-05T14:13:11Z")

</div>

Hi , I have some share point log that that i want to use \_ingest in order to process them. its works perfect on the grok debugger but im unable to post it without parsing error this is the grok pattern (?\<parsedti…

---

## [Packetbeat - Postgres - pgsql.error\_code parsing issues](https://discuss.elastic.co/t/packetbeat-postgres-pgsql-error-code-parsing-issues/146541)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [September 5, 2018, 1:12pm UTC](https://discuss.elastic.co/t/packetbeat-postgres-pgsql-error-code-parsing-issues/146541 "2018-09-05T13:12:52Z")

</div>

Hello, The Packetbeat Postgrespgsql.error\_code can also contain non-long type data, such as 42P01 https://www.postgresql.org/docs/8.2/static/errcodes-appendix.html \[2018-08-29T14:31:17,274\]\[DEBUG\]\[o.e.a.b.TransportSha…

---

## [Fields Input](https://discuss.elastic.co/t/fields-input/147406)

<div class="topic-metadata">

**Author:** [@Goyal.vikas87](https://discuss.elastic.co/u/Goyal.vikas87)\
**Replies:** 2\
**Last updated:** [September 5, 2018, 12:46pm UTC](https://discuss.elastic.co/t/fields-input/147406 "2018-09-05T12:46:25Z")

</div>

I want to to add a custom field in my all events using FIELDS input in filebeat.yml. Please confirm how I can parameterize the value of the custom field and if possible can I extractt some part of the \_source field of th…

---

## [Netstat info](https://discuss.elastic.co/t/netstat-info/147342)

<div class="topic-metadata">

**Author:** [@Mayank\_Mahajan](https://discuss.elastic.co/u/Mayank_Mahajan)\
**Replies:** 1\
**Last updated:** [September 5, 2018, 11:46am UTC](https://discuss.elastic.co/t/netstat-info/147342 "2018-09-05T11:46:48Z")

</div>

netstat info netstat | wc -l 502 and Kibana UI attached. Please help me understand, How Can I validate the information shown by Kibana from System OS: CentOS 7.x Kibana: 6.4 ES: 6.4

---

## [Auditbeat: specified rules don't apply](https://discuss.elastic.co/t/auditbeat-specified-rules-dont-apply/146519)

<div class="topic-metadata">

**Author:** [@Guillaume\_Bettayeb](https://discuss.elastic.co/u/Guillaume_Bettayeb)\
**Replies:** 2\
**Last updated:** [September 5, 2018, 11:28am UTC](https://discuss.elastic.co/t/auditbeat-specified-rules-dont-apply/146519 "2018-09-05T11:28:05Z")

</div>

Hi Everyone, Not sure what I am doing wrong here but it seems like auditd does not apply the auditd rules I defined. our Auditbeat uses both available modules, auditd and file\_integrity. and it looks like only the file…

---

## [How to load filebeat or elastic config from a non-default location](https://discuss.elastic.co/t/how-to-load-filebeat-or-elastic-config-from-a-non-default-location/147289)

<div class="topic-metadata">

**Author:** [@motamedi791](https://discuss.elastic.co/u/motamedi791)\
**Replies:** 1\
**Last updated:** [September 5, 2018, 11:02am UTC](https://discuss.elastic.co/t/how-to-load-filebeat-or-elastic-config-from-a-non-default-location/147289 "2018-09-05T11:02:51Z")

</div>

I am using filebeat on my Linux machine as a service (i.e. sudo service start filebeat). The service is started with the config file from the default location: ● filebeat.service - Filebeat sends log files to Logstash o…

---

## [Data loss frequently](https://discuss.elastic.co/t/data-loss-frequently/147201)

<div class="topic-metadata">

**Author:** [@manish\_jaiswal](https://discuss.elastic.co/u/manish_jaiswal)\
**Replies:** 3\
**Last updated:** [September 5, 2018, 10:59am UTC](https://discuss.elastic.co/t/data-loss-frequently/147201 "2018-09-05T10:59:25Z")

</div>

we have more than 135 filebeat running on different instance. each sending data to more than 10 pipeline. getting error on most of the filebeat(Failed to publish events: temporary bulk send failure): 2018-09-04T17:39:2…

---

## [Access logs inside docker container](https://discuss.elastic.co/t/access-logs-inside-docker-container/147334)

<div class="topic-metadata">

**Author:** [@prasanna12510](https://discuss.elastic.co/u/prasanna12510)\
**Replies:** 3\
**Last updated:** [September 5, 2018, 10:22am UTC](https://discuss.elastic.co/t/access-logs-inside-docker-container/147334 "2018-09-05T10:22:48Z")

</div>

how to configure filebeat to ship logs inside the docker container running separately in same machine

---

## [Nginx Access Logs Parsing Using Filebeat On Kubernetes Cluster](https://discuss.elastic.co/t/nginx-access-logs-parsing-using-filebeat-on-kubernetes-cluster/147303)

<div class="topic-metadata">

**Author:** [@Arjun\_Sharma](https://discuss.elastic.co/u/Arjun_Sharma)\
**Replies:** 1\
**Last updated:** [September 5, 2018, 6:53am UTC](https://discuss.elastic.co/t/nginx-access-logs-parsing-using-filebeat-on-kubernetes-cluster/147303 "2018-09-05T06:53:57Z")

</div>

We are using elasticsearch for centralized logging in our application. There are many components in our application which generate logs. All components running in kubernetes cluster. we are using filebeat as deamonset …

---

## [Error loading config file: yaml: line 21: did not find expected key](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-21-did-not-find-expected-key/147081)

<div class="topic-metadata">

**Author:** [@elk11](https://discuss.elastic.co/u/elk11)\
**Replies:** 10\
**Last updated:** [September 5, 2018, 4:41am UTC](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-21-did-not-find-expected-key/147081 "2018-09-05T04:41:16Z")

</div>

I referred other similar discussions but none of those helped. i'm getting this error after adding second prospector. and the error line specified is also at the beginning of the second prospector. Please take a look at …

---

## [Data is not available for syslog dashboard](https://discuss.elastic.co/t/data-is-not-available-for-syslog-dashboard/147026)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 16\
**Last updated:** [September 5, 2018, 3:51am UTC](https://discuss.elastic.co/t/data-is-not-available-for-syslog-dashboard/147026 "2018-09-05T03:51:58Z")

</div>

Hello All, I am using ELK6.4.0 and beats 6.4.0. I have enabled the filebeat system module and getting the data over dashboard for syslog and auth.log. But when i am checking the filebeat dashboard for syslog no data is …

---

## [Kibana hashboards empty](https://discuss.elastic.co/t/kibana-hashboards-empty/146774)

<div class="topic-metadata">

**Author:** [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Replies:** 5\
**Last updated:** [September 4, 2018, 10:19pm UTC](https://discuss.elastic.co/t/kibana-hashboards-empty/146774 "2018-09-04T22:19:49Z")

</div>

Hello, I set up ELK and beats... Elasticsearch on one node, and Logstash and Kibana on another node. Also, we have filebeat, metricbeat, auditbeat, packetbeat, and winlogbeat from remote servers sending logs/metrics to…

---

## [Filebeat - last handler in the pipeline did not handle the exception](https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202)

<div class="topic-metadata">

**Author:** [@irom77](https://discuss.elastic.co/u/irom77)\
**Replies:** 3\
**Last updated:** [September 4, 2018, 6:42pm UTC](https://discuss.elastic.co/t/filebeat-last-handler-in-the-pipeline-did-not-handle-the-exception/147202 "2018-09-04T18:42:48Z")

</div>

I am getting below error with filebeat/logstash. \[2018-09-04T12:05:09,164\]\[WARN \]\[io.netty.channel.DefaultChannelPipeline\] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually mea…

---

## [Metricbeat service throwing error](https://discuss.elastic.co/t/metricbeat-service-throwing-error/147101)

<div class="topic-metadata">

**Author:** [@ravikt](https://discuss.elastic.co/u/ravikt)\
**Replies:** 6\
**Last updated:** [September 4, 2018, 6:10pm UTC](https://discuss.elastic.co/t/metricbeat-service-throwing-error/147101 "2018-09-04T18:10:26Z")

</div>

I am trying to add the below config in the metricbeat configuration file and restarting the service is throwing the attached error. #------------------------------- Windows Module ------------------------------ module…

---

## [Filebeat index help](https://discuss.elastic.co/t/filebeat-index-help/146766)

<div class="topic-metadata">

**Author:** [@David\_Moreno](https://discuss.elastic.co/u/David_Moreno)\
**Replies:** 3\
**Last updated:** [September 4, 2018, 3:52pm UTC](https://discuss.elastic.co/t/filebeat-index-help/146766 "2018-09-04T15:52:33Z")

</div>

Hello, I'm trying to get an index to show more than one server's logs. My test server I get the logs, but my main ELK I don't see their logs in kibana. In kibana I made an index with filebeat\*, but this index only shows…

---

## [Metricbeat reporting all processes as "Sleeping"](https://discuss.elastic.co/t/metricbeat-reporting-all-processes-as-sleeping/145897)

<div class="topic-metadata">

**Author:** [@gonzalomk](https://discuss.elastic.co/u/gonzalomk)\
**Replies:** 3\
**Last updated:** [September 4, 2018, 1:53pm UTC](https://discuss.elastic.co/t/metricbeat-reporting-all-processes-as-sleeping/145897 "2018-09-04T13:53:52Z")

</div>

Hi I have installed metricbeat 6.3.2 together with kube-state-metrics 1.3.1 in our openshift cluster and I'm able to see all the system metrics. The problem that I find is that all processes under system.process.state m…

---

## [Metric beat module list empty](https://discuss.elastic.co/t/metric-beat-module-list-empty/147064)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 5\
**Last updated:** [September 4, 2018, 1:43pm UTC](https://discuss.elastic.co/t/metric-beat-module-list-empty/147064 "2018-09-04T13:43:36Z")

</div>

Hello Team, I am using ELK6.4.0 and beat 6.4.0. Today i have installed the metricbeat6.4.0 over my 3 ubuntu16.04 servers. When i installed them all things were working properly except disk data was not avaialble on dash…

---

## [Visualization for metricbeat](https://discuss.elastic.co/t/visualization-for-metricbeat/146507)

<div class="topic-metadata">

**Author:** [@Anil\_Bind](https://discuss.elastic.co/u/Anil_Bind)\
**Replies:** 2\
**Last updated:** [September 4, 2018, 11:07am UTC](https://discuss.elastic.co/t/visualization-for-metricbeat/146507 "2018-09-04T11:07:07Z")

</div>

what all visualizations can I create using winlogbeat and metricbeat's data? I have created server uptime, disk usage, Windows successful logons and failed logons.

---

## [Dynamic configuration parameters](https://discuss.elastic.co/t/dynamic-configuration-parameters/147188)

<div class="topic-metadata">

**Author:** [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Replies:** 4\
**Last updated:** [September 4, 2018, 11:04am UTC](https://discuss.elastic.co/t/dynamic-configuration-parameters/147188 "2018-09-04T11:04:43Z")

</div>

In filebeat configuration I would like to have dynamic variable like : filebeat.inputs: - type: ${some.type} enabled: true paths: - ${some.thing.like.variable} multiline.pattern: '^\[\[:space:\]\]+(at|\\.{3})\\b|^C…

---

## [No docker.container.image on docker/cpu stats?](https://discuss.elastic.co/t/no-docker-container-image-on-docker-cpu-stats/147169)

<div class="topic-metadata">

**Author:** [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Replies:** 1\
**Last updated:** [September 4, 2018, 10:21am UTC](https://discuss.elastic.co/t/no-docker-container-image-on-docker-cpu-stats/147169 "2018-09-04T10:21:23Z")

</div>

When filtering for metricset.module:docker AND metricset.name:cpu, I get a docker.container.name but no docker.container.image populated. Is this by design/a result of my config/a bug?

---

## [Metricbeat kubernetes WARN unable to index event](https://discuss.elastic.co/t/metricbeat-kubernetes-warn-unable-to-index-event/147092)

<div class="topic-metadata">

**Author:** [@Alex\_Armstrong](https://discuss.elastic.co/u/Alex_Armstrong)\
**Replies:** 1\
**Last updated:** [September 4, 2018, 10:03am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-warn-unable-to-index-event/147092 "2018-09-04T10:03:57Z")

</div>

We only have one warning level error being logged by metricbeat which stated as unable to index an event with a mapper\_parsing\_exception. Could you please advise on how to correct this. log sample: 2018-09-03T14:13:05.…

---

## [Filebeat not indexing data to elasticsearch](https://discuss.elastic.co/t/filebeat-not-indexing-data-to-elasticsearch/147134)

<div class="topic-metadata">

**Author:** [@sandhyap](https://discuss.elastic.co/u/sandhyap)\
**Replies:** 1\
**Last updated:** [September 4, 2018, 7:40am UTC](https://discuss.elastic.co/t/filebeat-not-indexing-data-to-elasticsearch/147134 "2018-09-04T07:40:22Z")

</div>

Hi, I use beat 6.4.0... Beats not indexing data to elastic search. filebeat.yml looks like below filebeat.inputs: Each - is an input. Most options can be set at the input level, so you can use different inputs for va…

---

## [Beat/Module for build metrics](https://discuss.elastic.co/t/beat-module-for-build-metrics/145444)

<div class="topic-metadata">

**Author:** [@nimDevOps](https://discuss.elastic.co/u/nimDevOps)\
**Replies:** 9\
**Last updated:** [September 3, 2018, 5:31pm UTC](https://discuss.elastic.co/t/beat-module-for-build-metrics/145444 "2018-09-03T17:31:31Z")

</div>

I'm trying to figure out what would be the approach to collect build metrics on build agent. Imagine we have VM or docker image which is created per build and destroyed after build is completed. During the build ( compi…

---

## [Cant enable metricbeat modules](https://discuss.elastic.co/t/cant-enable-metricbeat-modules/146949)

<div class="topic-metadata">

**Author:** [@Divit\_Sharma](https://discuss.elastic.co/u/Divit_Sharma)\
**Replies:** 2\
**Last updated:** [September 3, 2018, 3:35pm UTC](https://discuss.elastic.co/t/cant-enable-metricbeat-modules/146949 "2018-09-03T15:35:47Z")

</div>

\[root@f7af2d4dd6a1 modules.d\]# metricbeat modules enable system Module system doesn't exist! metricbeat modules list Enabled: Disabled: \[root@f7af2d4dd6a1 modules.d\]# dir aerospike.yml.disabled golang.yml.disa…

---

## [How to configure dropwizard module?](https://discuss.elastic.co/t/how-to-configure-dropwizard-module/146978)

<div class="topic-metadata">

**Author:** [@Ilia](https://discuss.elastic.co/u/Ilia)\
**Replies:** 2\
**Last updated:** [September 3, 2018, 1:44pm UTC](https://discuss.elastic.co/t/how-to-configure-dropwizard-module/146978 "2018-09-03T13:44:05Z")

</div>

I have a spring-boot - dropwizard hello world application. The following is a print-screen from jvisualvm of the application ... This is also what I can see from http://localhost:8080/metrics in a browser: { "mem"…

---

## [MetricBeat Stopping](https://discuss.elastic.co/t/metricbeat-stopping/146998)

<div class="topic-metadata">

**Author:** [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Replies:** 2\
**Last updated:** [September 3, 2018, 12:21pm UTC](https://discuss.elastic.co/t/metricbeat-stopping/146998 "2018-09-03T12:21:46Z")

</div>

I ran 2 exact installations of MetricBeat and the beat works on 1 (I See data on Kibana) but the other one gives this error. For my naked eye everything looks identical! Can someone please help? 2018-09-02T18:05:49.337-…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=421)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=423)
