# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=43

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 44

---

## [Filebeat Xml decoder linux](https://discuss.elastic.co/t/filebeat-xml-decoder-linux/339096)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 12:31pm UTC](https://discuss.elastic.co/t/filebeat-xml-decoder-linux/339096 "2023-07-24T12:31:32Z")

</div>

Hello Community, I have an issue in xml decoder, I’m trying to decode sysmon for linuxs logs i’m using filebeat to send the logs from ubuntu server to my graylog everything works great however filebeat is decoding the ke…

---

## [Metricbeat windows module not working as expected](https://discuss.elastic.co/t/metricbeat-windows-module-not-working-as-expected/339061)

<div class="topic-metadata">

**Author:** [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 9:19am UTC](https://discuss.elastic.co/t/metricbeat-windows-module-not-working-as-expected/339061 "2023-07-24T09:19:47Z")

</div>

Im trying to find the status of specfic service running on our windows machine. We are trying to get service information using windows Module from metricbeat, but modules doesnt sent any information of about service.. I…

---

## [Landing Filebeat data in two different Kafka clusters](https://discuss.elastic.co/t/landing-filebeat-data-in-two-different-kafka-clusters/338883)

<div class="topic-metadata">

**Author:** [@Kevinesan\_Pillay](https://discuss.elastic.co/u/Kevinesan_Pillay)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 1:22pm UTC](https://discuss.elastic.co/t/landing-filebeat-data-in-two-different-kafka-clusters/338883 "2023-07-20T13:22:33Z")

</div>

Good day, all I have the following environments in place: A functional Production environment: A. Host1 with filebeat polling a file sending to: B. A 3-node Kafka cluster on Topic1. (version: kafka\_2.13-3.2.0) C. 2 …

---

## [What setting is used for filebeat for compression?, like logstash uses:http\_compression =\> true](https://discuss.elastic.co/t/what-setting-is-used-for-filebeat-for-compression-like-logstash-uses-http-compression-true/338854)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 8:29am UTC](https://discuss.elastic.co/t/what-setting-is-used-for-filebeat-for-compression-like-logstash-uses-http-compression-true/338854 "2023-07-20T08:29:37Z")

</div>

Hello All, I'd like to know what settings must be used in filebeat for compression?. In logs i get bulk size issue sometimes.Assuming compression srtting might resolve this like in logstash has http\_compression =\> true…

---

## [Winlogbeat 8.6 process fields not populated](https://discuss.elastic.co/t/winlogbeat-8-6-process-fields-not-populated/338753)

<div class="topic-metadata">

**Author:** [@stanley783](https://discuss.elastic.co/u/stanley783)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:37am UTC](https://discuss.elastic.co/t/winlogbeat-8-6-process-fields-not-populated/338753 "2023-07-20T01:37:08Z")

</div>

Hi, until now using winlogbeat 7.X, tried winlogbeat 8.6.1 but agent does not parse/populate process.XXX fields anymore, it only uses fields in winlog.event\_data.XXX instead. Is there any easy obvious solution, instead …

---

## [Beats release docs for 8.6.2 missing](https://discuss.elastic.co/t/beats-release-docs-for-8-6-2-missing/329335)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 12:31am UTC](https://discuss.elastic.co/t/beats-release-docs-for-8-6-2-missing/329335 "2023-07-20T00:31:50Z")

</div>

After last release 8.7.0 notes for 8.6.2 missing and 8.6.1 present. Can you fix it?

---

## [Add\_host\_metadata not collecting host details](https://discuss.elastic.co/t/add-host-metadata-not-collecting-host-details/338053)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 2:24pm UTC](https://discuss.elastic.co/t/add-host-metadata-not-collecting-host-details/338053 "2023-07-18T14:24:54Z")

</div>

Hi i am using 6.8 metricbeat and server is 7.12 . a. add host metricset and got error , so enable add\_host\_metadata : ~ b . as per documentation . add\_host\_metadata it should collect "host":{ "architecture":"x86\_64"…

---

## [Filebeat multiple modules on single input syslog port](https://discuss.elastic.co/t/filebeat-multiple-modules-on-single-input-syslog-port/338691)

<div class="topic-metadata">

**Author:** [@Amol\_Sahare](https://discuss.elastic.co/u/Amol_Sahare)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 2:17pm UTC](https://discuss.elastic.co/t/filebeat-multiple-modules-on-single-input-syslog-port/338691 "2023-07-18T14:17:27Z")

</div>

Hi All, I have installed filebeat Syslog input and received logs from multiple devices like Vmware Esx, Firewall, Unix, VCenter, Antivirus, etc. Filebeat Yml file: fields\_under\_root: true fields.collector\_node\_id: ${…

---

## [General Log Warning Question](https://discuss.elastic.co/t/general-log-warning-question/338443)

<div class="topic-metadata">

**Author:** [@Ray3](https://discuss.elastic.co/u/Ray3)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 8:38pm UTC](https://discuss.elastic.co/t/general-log-warning-question/338443 "2023-07-17T20:38:36Z")

</div>

I deployed metricbeat to a node. Unless I use superuser role, I will get warnings in the log, that it cannot take certain actions as the api key used is unauthorized. I do see data reported in kibana, it appears metric…

---

## [Prevent Functionbeat from deleting log groups](https://discuss.elastic.co/t/prevent-functionbeat-from-deleting-log-groups/338538)

<div class="topic-metadata">

**Author:** [@shlant](https://discuss.elastic.co/u/shlant)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 10:49am UTC](https://discuss.elastic.co/t/prevent-functionbeat-from-deleting-log-groups/338538 "2023-07-17T10:49:26Z")

</div>

So I am wanting to stream logs from a number of existing cloudwatch log groups to my ELK stack. I seem to have the setup basically ready but I noticed during the debugging of the setup process that when I deleted the Clo…

---

## [Unable to create Custom index for metricbeat](https://discuss.elastic.co/t/unable-to-create-custom-index-for-metricbeat/336887)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 9:59am UTC](https://discuss.elastic.co/t/unable-to-create-custom-index-for-metricbeat/336887 "2023-07-17T09:59:18Z")

</div>

Hello, I am trying to create the custom index for metricbeat with same template as metricbeat but not able to create the index using below configs. ###################### Metricbeat Configuration Example ##############…

---

## [Filebeat: Index not getting created at Elasticsearch](https://discuss.elastic.co/t/filebeat-index-not-getting-created-at-elasticsearch/338530)

<div class="topic-metadata">

**Author:** [@mohammad\_messiah](https://discuss.elastic.co/u/mohammad_messiah)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/filebeat-index-not-getting-created-at-elasticsearch/338530 "2023-07-17T09:54:32Z")

</div>

Hi All, I have installed filebeat on few servers but somehow logs are not getting created tried reinstalling the filebeat didn't worked. For previously configured servers index are getting created on daily basis Please …

---

## [Unkown Key in Elasticsearch Template (elastic stack 8.3.3)](https://discuss.elastic.co/t/unkown-key-in-elasticsearch-template-elastic-stack-8-3-3/338100)

<div class="topic-metadata">

**Author:** [@ARm1110](https://discuss.elastic.co/u/ARm1110)\
**Replies:** 4\
**Last updated:** [July 16, 2023, 4:41am UTC](https://discuss.elastic.co/t/unkown-key-in-elasticsearch-template-elastic-stack-8-3-3/338100 "2023-07-16T04:41:16Z")

</div>

elastic stack(filebeat,elasticsearch,kibana,elastic-agent,logstash) =\> 8.3.3 OS: Ubuntu 22.04 Agents: linux base I wanted to run Wazuh manager with Elastic 8.3.3, the Wazuh plugin can't be installed with elastic, I ma…

---

## [Logs not being sent to filebeats and logstash](https://discuss.elastic.co/t/logs-not-being-sent-to-filebeats-and-logstash/338284)

<div class="topic-metadata">

**Author:** [@nikokyu](https://discuss.elastic.co/u/nikokyu)\
**Replies:** 2\
**Last updated:** [July 15, 2023, 10:12pm UTC](https://discuss.elastic.co/t/logs-not-being-sent-to-filebeats-and-logstash/338284 "2023-07-15T22:12:59Z")

</div>

Currently trying to set up Filebeats to try and connect to Logstash to send logs from cisco network syslogs and tacacs logs to a logstash server to be sent to elastic and then displayed on kibana. However, I have not be…

---

## [Metricbeat - how to create two different index templates from me metricbeat.yml](https://discuss.elastic.co/t/metricbeat-how-to-create-two-different-index-templates-from-me-metricbeat-yml/338298)

<div class="topic-metadata">

**Author:** [@Terkea](https://discuss.elastic.co/u/Terkea)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 9:01am UTC](https://discuss.elastic.co/t/metricbeat-how-to-create-two-different-index-templates-from-me-metricbeat-yml/338298 "2023-07-13T09:01:53Z")

</div>

Hello guys, I want to create two different index templates with different ILM policies for each module that I use in metricbeat. My metricbeat.yml metricbeat: modules: - hosts: - http://localhost:5067 metr…

---

## [GeoIp based on custom field source.ip](https://discuss.elastic.co/t/geoip-based-on-custom-field-source-ip/338088)

<div class="topic-metadata">

**Author:** [@vasile](https://discuss.elastic.co/u/vasile)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 7:27am UTC](https://discuss.elastic.co/t/geoip-based-on-custom-field-source-ip/338088 "2023-07-13T07:27:41Z")

</div>

Hi all, I am trying to parse a log message. The original log looks like this: Jul 10 08:51:10 prometheus sshd\[19074\]: Accepted password for my\_user from 1.1.1.1 port 1111 ssh2 My filebeat conf is bellow: --- filebeat…

---

## [Filebeat service is failing again and again](https://discuss.elastic.co/t/filebeat-service-is-failing-again-and-again/337642)

<div class="topic-metadata">

**Author:** [@Kanika\_Gola](https://discuss.elastic.co/u/Kanika_Gola)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 5:33pm UTC](https://discuss.elastic.co/t/filebeat-service-is-failing-again-and-again/337642 "2023-07-12T17:33:47Z")

</div>

---

## [Filebeat is using more than 4GB memory](https://discuss.elastic.co/t/filebeat-is-using-more-than-4gb-memory/337952)

<div class="topic-metadata">

**Author:** [@Sharad\_Dubey](https://discuss.elastic.co/u/Sharad_Dubey)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-is-using-more-than-4gb-memory/337952 "2023-07-12T16:53:56Z")

</div>

Hi Champs, My filebeat consumtipn is very high and using more than 4GB of RAM, only log files which I am pushing are some app logs , /var/log/messages and /var/log/secure. Npt sure why this happening. Please help \[roo…

---

## [Error creating input: each processor must have exactly one action,but found 2 actions (add\_locale,decode\_json\_fields)](https://discuss.elastic.co/t/error-creating-input-each-processor-must-have-exactly-one-action-but-found-2-actions-add-locale-decode-json-fields/338201)

<div class="topic-metadata">

**Author:** [@farhad\_kh](https://discuss.elastic.co/u/farhad_kh)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:07am UTC](https://discuss.elastic.co/t/error-creating-input-each-processor-must-have-exactly-one-action-but-found-2-actions-add-locale-decode-json-fields/338201 "2023-07-12T10:07:59Z")

</div>

hello i have a cluster kubeadm and collecting logs with filebeat autodiscover and i get this error after depoly 2023-07-12T09:34:19.588Z INFO log/input.go:152 Configured paths: \[/var/log/pods/\*\_554a0c…

---

## [Filebeat integration with DataDog](https://discuss.elastic.co/t/filebeat-integration-with-datadog/338163)

<div class="topic-metadata">

**Author:** [@KSimon](https://discuss.elastic.co/u/KSimon)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 4:09am UTC](https://discuss.elastic.co/t/filebeat-integration-with-datadog/338163 "2023-07-12T04:09:39Z")

</div>

Hello, we have a use case to use Filebeat as a transporter of logs from one Cloud Source and feed the logs to DataDog and Kafka. There is a documentation for Kafka Output, however, there are no documentations to support…

---

## [Filebeat not sending data to elasticsearch](https://discuss.elastic.co/t/filebeat-not-sending-data-to-elasticsearch/338154)

<div class="topic-metadata">

**Author:** [@gigallo](https://discuss.elastic.co/u/gigallo)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 9:46pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-data-to-elasticsearch/338154 "2023-07-11T21:46:02Z")

</div>

Hi 've installed elasticsearch 8.5 and Kibana 8.5 in my kubernetes cluster simply applying the official helm file in the elastic repo. Now I'm trying to install filebeat with the following conf: filebeat.inputs: - …

---

## [Metricbeat and Heartbeat 8.x custom index Name should pickup from template ,but creates always bedefault index name](https://discuss.elastic.co/t/metricbeat-and-heartbeat-8-x-custom-index-name-should-pickup-from-template-but-creates-always-bedefault-index-name/337557)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 22\
**Last updated:** [July 11, 2023, 3:40pm UTC](https://discuss.elastic.co/t/metricbeat-and-heartbeat-8-x-custom-index-name-should-pickup-from-template-but-creates-always-bedefault-index-name/337557 "2023-07-11T15:40:37Z")

</div>

Hello All, I'm migrating metricbeat and heartbeat from 7.9.1 to 8.7.1 version and current challenge is I'm unbale to create custom index name defined in my index template and metricbeat.yml. I'm not sure how come every…

---

## [Rename json field from the mongo log with filebeat processor](https://discuss.elastic.co/t/rename-json-field-from-the-mongo-log-with-filebeat-processor/338111)

<div class="topic-metadata">

**Author:** [@slashlinux](https://discuss.elastic.co/u/slashlinux)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/rename-json-field-from-the-mongo-log-with-filebeat-processor/338111 "2023-07-11T13:52:29Z")

</div>

Hi guys, I'm trying to use the official website documentation for filebeat renaming field from the json but doesn't work so I ve decided to post here what i ve done and learn more about my mistake. I want to rename for …

---

## [Winlogbeat logs sent through logstash aren't parsed correctly](https://discuss.elastic.co/t/winlogbeat-logs-sent-through-logstash-arent-parsed-correctly/338076)

<div class="topic-metadata">

**Author:** [@dosterberg](https://discuss.elastic.co/u/dosterberg)\
**Replies:** 3\
**Last updated:** [July 11, 2023, 12:51pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-sent-through-logstash-arent-parsed-correctly/338076 "2023-07-11T12:51:00Z")

</div>

Hi everyone! I'm new to ELK and have been enjoying very much working with it so far. I am currently evaluating ELK with Elastic Security as a SIEM in a test environment. I have tried sending both data from filebeat with …

---

## [Can I install both agent winlogbeat and exabeam on same server?](https://discuss.elastic.co/t/can-i-install-both-agent-winlogbeat-and-exabeam-on-same-server/338054)

<div class="topic-metadata">

**Author:** [@witsarut](https://discuss.elastic.co/u/witsarut)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 4:35am UTC](https://discuss.elastic.co/t/can-i-install-both-agent-winlogbeat-and-exabeam-on-same-server/338054 "2023-07-11T04:35:36Z")

</div>

Hello Everyone, Can I do install both agent winlogbeat and exabeam on same server ? If can do that, It's have a effected to server i.e. high CPU consume. Thanks,

---

## [How do I setup pipelines with no direct access from Filebeat to Elastic?](https://discuss.elastic.co/t/how-do-i-setup-pipelines-with-no-direct-access-from-filebeat-to-elastic/337836)

<div class="topic-metadata">

**Author:** [@jbilbro](https://discuss.elastic.co/u/jbilbro)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 1:31pm UTC](https://discuss.elastic.co/t/how-do-i-setup-pipelines-with-no-direct-access-from-filebeat-to-elastic/337836 "2023-07-10T13:31:45Z")

</div>

Post my company being aquired, we have been asked to migrate from our on-prem Splunk to our parent company's AWS ELK. This is all new to me, so I'm needing some help knowing the right path forward. They are having us us…

---

## [Filebeat K8s deployment - Duplicated Filestream ID](https://discuss.elastic.co/t/filebeat-k8s-deployment-duplicated-filestream-id/338008)

<div class="topic-metadata">

**Author:** [@msanft](https://discuss.elastic.co/u/msanft)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 9:40am UTC](https://discuss.elastic.co/t/filebeat-k8s-deployment-duplicated-filestream-id/338008 "2023-07-10T09:40:27Z")

</div>

Hey all, I'm deploying Filebeat in a Kubernetes cluster as a daemonset. I see the following error message in the Filebeat Pod logs: { "log.level":"error", "@timestamp":"2023-07-10T09:18:38.720Z", "log.logger":…

---

## [Filebeat TCP input with SSL - Logs not received in correct format](https://discuss.elastic.co/t/filebeat-tcp-input-with-ssl-logs-not-received-in-correct-format/337994)

<div class="topic-metadata">

**Author:** [@wasimasif](https://discuss.elastic.co/u/wasimasif)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 6:47am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-ssl-logs-not-received-in-correct-format/337994 "2023-07-10T06:47:36Z")

</div>

I have created a TCP input but i have to secure communication using SSL. Following is my filebeat input configuration. This input starts and don't have any errors. Clients is also able to connect (verified via openssl ). …

---

## [Getting Error "Exiting: /usr/share/filebeat/data/filebeat.lock: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data)"](https://discuss.elastic.co/t/getting-error-exiting-usr-share-filebeat-data-filebeat-lock-data-path-already-locked-by-another-beat-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/337991)

<div class="topic-metadata">

**Author:** [@Sharad\_Nautiyal](https://discuss.elastic.co/u/Sharad_Nautiyal)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 6:12am UTC](https://discuss.elastic.co/t/getting-error-exiting-usr-share-filebeat-data-filebeat-lock-data-path-already-locked-by-another-beat-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/337991 "2023-07-10T06:12:39Z")

</div>

Hi Everyone, We have a central system to monitor logs for all the K8s clusters pods including specific label. There are specific pods for which we want to setup a different pre-processing system but when we are deployi…

---

## [Filebeat cloudwatch input not reading dynamic log groups/ log streams](https://discuss.elastic.co/t/filebeat-cloudwatch-input-not-reading-dynamic-log-groups-log-streams/337982)

<div class="topic-metadata">

**Author:** [@arungiyer](https://discuss.elastic.co/u/arungiyer)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 3:45am UTC](https://discuss.elastic.co/t/filebeat-cloudwatch-input-not-reading-dynamic-log-groups-log-streams/337982 "2023-07-10T03:45:51Z")

</div>

I am using filebeat docker image (8.7.1) to run an ecs service that reads cloudwatch logs and send to an index. My cloudwatch log groups gets created dynamically so i am using "log\_group\_name\_prefix" to identify all log …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=42)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=44)
