# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=423

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 424

---

## [Update the registry file](https://discuss.elastic.co/t/update-the-registry-file/147027)

<div class="topic-metadata">

**Author:** [@saisimo02](https://discuss.elastic.co/u/saisimo02)\
**Replies:** 7\
**Last updated:** [September 3, 2018, 9:15am UTC](https://discuss.elastic.co/t/update-the-registry-file/147027 "2018-09-03T09:15:33Z")

</div>

Hello, I would like to update delete the old data from the file "registry", in fact I am getting now an error message : no left space on device. So I would like to delete information about files already parsed by logst…

---

## [Filebeat 6.3+ IIS module and IIS versions \< 10](https://discuss.elastic.co/t/filebeat-6-3-iis-module-and-iis-versions-10/146391)

<div class="topic-metadata">

**Author:** [@agx](https://discuss.elastic.co/u/agx)\
**Replies:** 1\
**Last updated:** [September 3, 2018, 8:49am UTC](https://discuss.elastic.co/t/filebeat-6-3-iis-module-and-iis-versions-10/146391 "2018-09-03T08:49:21Z")

</div>

Hey everyone, new to the community. I've been using Elastic for a little over a year now. I see that filebeat has an IIS module now (starting with 6.3) but it's only been tested with IIS 10. I am curious if anyone in t…

---

## [Support multiple multiline patterns in filebeat](https://discuss.elastic.co/t/support-multiple-multiline-patterns-in-filebeat/145871)

<div class="topic-metadata">

**Author:** [@agilezebra](https://discuss.elastic.co/u/agilezebra)\
**Replies:** 1\
**Last updated:** [September 3, 2018, 8:48am UTC](https://discuss.elastic.co/t/support-multiple-multiline-patterns-in-filebeat/145871 "2018-09-03T08:48:13Z")

</div>

I'm having trouble parsing Python stack traces satisfactorily in the presence of other multiline output from other docker containers (traefik for example). There doesn't seem to be any mechanism to allow prospecting from…

---

## [How many retries does protologbeat make to logstash?](https://discuss.elastic.co/t/how-many-retries-does-protologbeat-make-to-logstash/145763)

<div class="topic-metadata">

**Author:** [@Rahul1](https://discuss.elastic.co/u/Rahul1)\
**Replies:** 1\
**Last updated:** [September 3, 2018, 8:47am UTC](https://discuss.elastic.co/t/how-many-retries-does-protologbeat-make-to-logstash/145763 "2018-09-03T08:47:14Z")

</div>

What is the default retry while sending the data from protologbeat to logstash in case of failure? Where can I configure those values? Thanks, Rahul

---

## [Beat creation failing](https://discuss.elastic.co/t/beat-creation-failing/146969)

<div class="topic-metadata">

**Author:** [@pohzipohzi](https://discuss.elastic.co/u/pohzipohzi)\
**Replies:** 2\
**Last updated:** [September 3, 2018, 8:37am UTC](https://discuss.elastic.co/t/beat-creation-failing/146969 "2018-09-03T08:37:56Z")

</div>

I'm following the instructions to creating a new beat and ran into an error here. make: \*\*\* No rule to make target 'update', needed by 'setup'. Stop. When I took a look at the generate script, it seems that the update…

---

## [Filebeat 6 fails to connect to proxy server](https://discuss.elastic.co/t/filebeat-6-fails-to-connect-to-proxy-server/146955)

<div class="topic-metadata">

**Author:** [@victor3](https://discuss.elastic.co/u/victor3)\
**Replies:** 1\
**Last updated:** [September 3, 2018, 8:28am UTC](https://discuss.elastic.co/t/filebeat-6-fails-to-connect-to-proxy-server/146955 "2018-09-03T08:28:08Z")

</div>

I am upgrading filebeat 5 to 6.2. As part of upgrade, I introduce filebeat 6 ssl to replace stunnel. It works well when no proxy between filebeat 6 and Logstash server. With proxy server, filebeat 6 fails to connect to …

---

## [Filebeat configuration issue](https://discuss.elastic.co/t/filebeat-configuration-issue/146863)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 1\
**Last updated:** [September 3, 2018, 7:54am UTC](https://discuss.elastic.co/t/filebeat-configuration-issue/146863 "2018-09-03T07:54:46Z")

</div>

Hello All, Earlier i was using ELK6.2.4 and beat version also were 6.2.4. Today i have upgraded my ELK from 6.2.4 to 6.4.0. Before updating my filebeat i was getting logs on kibana6.4.0. But i have updated my filebeat …

---

## [Extend Metricbeat](https://discuss.elastic.co/t/extend-metricbeat/146181)

<div class="topic-metadata">

**Author:** [@Manjukb](https://discuss.elastic.co/u/Manjukb)\
**Replies:** 13\
**Last updated:** [September 3, 2018, 6:50am UTC](https://discuss.elastic.co/t/extend-metricbeat/146181 "2018-09-03T06:50:59Z")

</div>

I understand there is a way to extend metric beats but documentation is bit confusing it says there are two ways to extend Extend Metricbeat directly Create your own Beat and use Metricbeat as a library what i unders…

---

## [Delete filebeat processed file](https://discuss.elastic.co/t/delete-filebeat-processed-file/146607)

<div class="topic-metadata">

**Author:** [@\_kyllr](https://discuss.elastic.co/u/_kyllr)\
**Replies:** 2\
**Last updated:** [September 3, 2018, 6:42am UTC](https://discuss.elastic.co/t/delete-filebeat-processed-file/146607 "2018-09-03T06:42:54Z")

</div>

Hi, does filebeat has a feature that will delete the file after it is processed? Or anyone has an idea how to delete the source file itself when all the data has been read? Thanks in advance!

---

## [Security error with beats\_system account and Filebeat with system module](https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822)

<div class="topic-metadata">

**Author:** [@itblaked](https://discuss.elastic.co/u/itblaked)\
**Replies:** 3\
**Last updated:** [September 3, 2018, 2:47am UTC](https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822 "2018-09-03T02:47:48Z")

</div>

Hey, I'm encountering an error which indicates that the builtin beats\_system user account doesn't have enough permissions in the ES cluster to perform a particular task, though it works when I test with a superuser acco…

---

## [Separately Visualizing Multiple Redis Instances with Filebeat Redis Module](https://discuss.elastic.co/t/separately-visualizing-multiple-redis-instances-with-filebeat-redis-module/146768)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 1\
**Last updated:** [August 31, 2018, 5:57pm UTC](https://discuss.elastic.co/t/separately-visualizing-multiple-redis-instances-with-filebeat-redis-module/146768 "2018-08-31T17:57:02Z")

</div>

Using the redis Filebeat module to collect the logs for multiple redis instances and visualize them with the redis dashboard in Kibana, how to visualize the logs for the redis instances separately? Is there anything that…

---

## [Debug Filebeat](https://discuss.elastic.co/t/debug-filebeat/146817)

<div class="topic-metadata">

**Author:** [@Christian\_Wohrle](https://discuss.elastic.co/u/Christian_Wohrle)\
**Replies:** 2\
**Last updated:** [August 31, 2018, 5:16pm UTC](https://discuss.elastic.co/t/debug-filebeat/146817 "2018-08-31T17:16:15Z")

</div>

I'd like to debug filebeat in goland to understand how it is working internally but I get the error message: could not launch process: could not get .debug\_frame section: could not find .debug\_frame section This is in …

---

## [Filebeat 6.4.0 .deb creates /lib/lsystemd/system/filebeat.service 0755](https://discuss.elastic.co/t/filebeat-6-4-0-deb-creates-lib-lsystemd-system-filebeat-service-0755/146752)

<div class="topic-metadata">

**Author:** [@reshippie](https://discuss.elastic.co/u/reshippie)\
**Replies:** 1\
**Last updated:** [August 31, 2018, 4:49pm UTC](https://discuss.elastic.co/t/filebeat-6-4-0-deb-creates-lib-lsystemd-system-filebeat-service-0755/146752 "2018-08-31T16:49:55Z")

</div>

I've been seeing the following syslog message across all of our hosts running Filebeat since we upgraded to 6.4.0: Aug 30 16:52:59 elk-00 systemd\[1\]: Configuration file /lib/systemd/system/filebeat.service is marked ex…

---

## [Filebeat 6.3.2 and logstash 6.2.3 does not work](https://discuss.elastic.co/t/filebeat-6-3-2-and-logstash-6-2-3-does-not-work/146743)

<div class="topic-metadata">

**Author:** [@vitassecuriti](https://discuss.elastic.co/u/vitassecuriti)\
**Replies:** 1\
**Last updated:** [August 31, 2018, 4:46pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-and-logstash-6-2-3-does-not-work/146743 "2018-08-31T16:46:32Z")

</div>

Someone checked the return compatibility of filebeat-6.3.2 and logstash 6.2.3 versions? I have ELK a stack. Logstash accepts a stream, puts in redis and behind that from him sends Elasticsearch. Today I tried to adjust …

---

## [Is Metric beat dashboard for postgres available with anyone](https://discuss.elastic.co/t/is-metric-beat-dashboard-for-postgres-available-with-anyone/145961)

<div class="topic-metadata">

**Author:** [@Saktthevel](https://discuss.elastic.co/u/Saktthevel)\
**Replies:** 0\
**Last updated:** [August 24, 2018, 6:18pm UTC](https://discuss.elastic.co/t/is-metric-beat-dashboard-for-postgres-available-with-anyone/145961 "2018-08-24T18:18:34Z")

</div>

Did anyone have dashboard set for postgres in metric eat, which is not in default dashboards??

---

## [Read line error: invalid CRI log; filbeat halts processing logs](https://discuss.elastic.co/t/read-line-error-invalid-cri-log-filbeat-halts-processing-logs/146284)

<div class="topic-metadata">

**Author:** [@Jarek\_Miszkinis](https://discuss.elastic.co/u/Jarek_Miszkinis)\
**Replies:** 11\
**Last updated:** [August 31, 2018, 10:12am UTC](https://discuss.elastic.co/t/read-line-error-invalid-cri-log-filbeat-halts-processing-logs/146284 "2018-08-31T10:12:25Z")

</div>

Some log files trigger following error mesg and stops the log file from being processed: filebeat-vng6q filebeat 2018-08-28T07:32:54.968Z ERROR log/harvester.go:275 Read line error: invalid CRI log; File: /var/lib/docke…

---

## [Filebeat-Multiline](https://discuss.elastic.co/t/filebeat-multiline/145710)

<div class="topic-metadata">

**Author:** [@SJN8](https://discuss.elastic.co/u/SJN8)\
**Replies:** 4\
**Last updated:** [August 31, 2018, 6:43am UTC](https://discuss.elastic.co/t/filebeat-multiline/145710 "2018-08-31T06:43:33Z")

</div>

Hi All, I have below logs pattern but not able to club them in multiline , Aug 23, 2018 2:38:23 AM org.apache.catalina.core.StandardServer await INFO: A valid shutdown command was received via the shutdown port. Stoppi…

---

## [No indices match pattern with "filebeat-\*",](https://discuss.elastic.co/t/no-indices-match-pattern-with-filebeat/146725)

<div class="topic-metadata">

**Author:** [@sri\_lakshmi](https://discuss.elastic.co/u/sri_lakshmi)\
**Replies:** 2\
**Last updated:** [August 31, 2018, 5:17am UTC](https://discuss.elastic.co/t/no-indices-match-pattern-with-filebeat/146725 "2018-08-31T05:17:09Z")

</div>

Hi, I am working on ELK & Filebeat(6.4.0 version),i want to visualize the apache2 and mysql logs on kibana dashboard through filebeat.I enabled the modules in modules.d and giving the log path to apache2.yml & mysql.yml…

---

## [How to disable xpack check in Filebeat](https://discuss.elastic.co/t/how-to-disable-xpack-check-in-filebeat/145997)

<div class="topic-metadata">

**Author:** [@xiaowangwindow](https://discuss.elastic.co/u/xiaowangwindow)\
**Replies:** 12\
**Last updated:** [August 31, 2018, 3:37am UTC](https://discuss.elastic.co/t/how-to-disable-xpack-check-in-filebeat/145997 "2018-08-31T03:37:58Z")

</div>

hello, I am a newbie to use ES and Kibana in Amazon Elasticsearch Service, which do not support xpack plugin. I use Filebeat to send nginx log to ES directly. However, when run sudo filebeat setup -e, error happen like …

---

## [Filebeat and Elasticsearch combination not showing realtime logs in Kibana](https://discuss.elastic.co/t/filebeat-and-elasticsearch-combination-not-showing-realtime-logs-in-kibana/146596)

<div class="topic-metadata">

**Author:** [@Dean\_Armada](https://discuss.elastic.co/u/Dean_Armada)\
**Replies:** 2\
**Last updated:** [August 31, 2018, 1:42am UTC](https://discuss.elastic.co/t/filebeat-and-elasticsearch-combination-not-showing-realtime-logs-in-kibana/146596 "2018-08-31T01:42:22Z")

</div>

I am using Filebeat, ElasticSearch and Kibana for scraping all the logs in our Docker Swarm. We used to use logspout for scraping logs then ELK but it consumes too much resources so we switched to Filebeat. But the probl…

---

## [\[metricbeat\]\[Prometheus\] MICROMETER](https://discuss.elastic.co/t/metricbeat-prometheus-micrometer/146591)

<div class="topic-metadata">

**Author:** [@adelbot](https://discuss.elastic.co/u/adelbot)\
**Replies:** 0\
**Last updated:** [August 30, 2018, 12:50am UTC](https://discuss.elastic.co/t/metricbeat-prometheus-micrometer/146591 "2018-08-30T00:50:01Z")

</div>

Has anyone ever made a dashboard for micrometer metrics on springboot ? Read you

---

## [Filebeat Autodiscover gives fatal error: concurrent map iteration and map write](https://discuss.elastic.co/t/filebeat-autodiscover-gives-fatal-error-concurrent-map-iteration-and-map-write/145296)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 9\
**Last updated:** [August 30, 2018, 5:43pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-gives-fatal-error-concurrent-map-iteration-and-map-write/145296 "2018-08-30T17:43:46Z")

</div>

Using the official filebeat docker image form elastic, I get fatal error: concurrent map iteration and map write (detailed logs included below) when using the filebeat.autodiscover in the config file. However, I cannot r…

---

## [Filebeat 6.3.2 doesn´t detect every started container](https://discuss.elastic.co/t/filebeat-6-3-2-doesn-t-detect-every-started-container/146643)

<div class="topic-metadata">

**Author:** [@Christian\_Wohrle](https://discuss.elastic.co/u/Christian_Wohrle)\
**Replies:** 6\
**Last updated:** [August 30, 2018, 5:31pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-doesn-t-detect-every-started-container/146643 "2018-08-30T17:31:39Z")

</div>

I´m using filebeat 6.3.2 to ship container logs. This is my current filebeat configuration (see below). --- filebeat.autodiscover: providers: - type: docker templates: - condition: conta…

---

## [MetricBeat to capture all available Mbeans from Jolokia](https://discuss.elastic.co/t/metricbeat-to-capture-all-available-mbeans-from-jolokia/146273)

<div class="topic-metadata">

**Author:** [@Kathir\_J](https://discuss.elastic.co/u/Kathir_J)\
**Replies:** 4\
**Last updated:** [August 30, 2018, 4:30pm UTC](https://discuss.elastic.co/t/metricbeat-to-capture-all-available-mbeans-from-jolokia/146273 "2018-08-30T16:30:16Z")

</div>

Hello Team, I really enjoyed working with Metricbeat and jolokia together to get my application Mbeans. Below is my module configuration from metricbeat.yml In this I have one static Mbean name which will never get ch…

---

## [Filebeat with kafka.output](https://discuss.elastic.co/t/filebeat-with-kafka-output/146483)

<div class="topic-metadata">

**Author:** [@Steve1](https://discuss.elastic.co/u/Steve1)\
**Replies:** 6\
**Last updated:** [August 30, 2018, 1:47pm UTC](https://discuss.elastic.co/t/filebeat-with-kafka-output/146483 "2018-08-30T13:47:36Z")

</div>

So i use filebeat 6.4.0 - Apache Kafka 2.11-2.0.0

---

## [More than one namespace configured accessing 'output'](https://discuss.elastic.co/t/more-than-one-namespace-configured-accessing-output/146646)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 1\
**Last updated:** [August 30, 2018, 12:44pm UTC](https://discuss.elastic.co/t/more-than-one-namespace-configured-accessing-output/146646 "2018-08-30T12:44:43Z")

</div>

I am using two filebeat configuration files. One config file is sending to Elasticsearch (filebeat.yml) and the other is sending to Logstash (filebeat2.yml). I chain these two config files with the following command: co…

---

## [Missin Kibana Dashboard for Elasticsearch and Kibana Modules](https://discuss.elastic.co/t/missin-kibana-dashboard-for-elasticsearch-and-kibana-modules/146636)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 1\
**Last updated:** [August 30, 2018, 12:43pm UTC](https://discuss.elastic.co/t/missin-kibana-dashboard-for-elasticsearch-and-kibana-modules/146636 "2018-08-30T12:43:14Z")

</div>

In Filebeat 6.4, Kibana and Elasticsearch modules were added so I am using the filebeat modules to collect the logs for Logstash, Elasticsearch and Kibana and visualize them in Kibana. However, after setting up and loadi…

---

## [FIlebeat Input Type](https://discuss.elastic.co/t/filebeat-input-type/146674)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 3\
**Last updated:** [August 30, 2018, 11:13am UTC](https://discuss.elastic.co/t/filebeat-input-type/146674 "2018-08-30T11:13:57Z")

</div>

Could be a stupid question, can we manipulate the input type in the filebeat.yml to be whatever string we want? I want to uniquely identify logs that come from this server (without having to create a separate index for …

---

## [Packetbeat and Mongodb 4](https://discuss.elastic.co/t/packetbeat-and-mongodb-4/146302)

<div class="topic-metadata">

**Author:** [@tuthan](https://discuss.elastic.co/u/tuthan)\
**Replies:** 4\
**Last updated:** [August 30, 2018, 8:55am UTC](https://discuss.elastic.co/t/packetbeat-and-mongodb-4/146302 "2018-08-30T08:55:30Z")

</div>

Hi everyone, I'm seeking for help here. I recently upgrade the mongodb to version 4. Since then seem i could not see any more traffic (Query, insert, update, find). There are bunch of 2018-08-28T15:55:50.264+0700 ERROR …

---

## [Filebeat data convert filed string to number on elasticsearch](https://discuss.elastic.co/t/filebeat-data-convert-filed-string-to-number-on-elasticsearch/146484)

<div class="topic-metadata">

**Author:** [@tomoncle](https://discuss.elastic.co/u/tomoncle)\
**Replies:** 2\
**Last updated:** [August 30, 2018, 2:04am UTC](https://discuss.elastic.co/t/filebeat-data-convert-filed-string-to-number-on-elasticsearch/146484 "2018-08-30T02:04:01Z")

</div>

I modified the default access pipline of the filebeat nginx module. The changes are as follows: increase request\_time & upstream\_response\_time { "grok": { "field": "message", "patterns":\[ "…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=422)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=424)
