# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=44

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 45

---

## [Mapping flow logs with ES](https://discuss.elastic.co/t/mapping-flow-logs-with-es/337906)

<div class="topic-metadata">

**Author:** [@nishanth\_cheruku](https://discuss.elastic.co/u/nishanth_cheruku)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 4:40pm UTC](https://discuss.elastic.co/t/mapping-flow-logs-with-es/337906 "2023-07-07T16:40:14Z")

</div>

I am trying to send aws vpc flow logs from S3 to Elasticsearch by filebeats. Can anyone tell me how the mapping of fields is happening? I understand it takes the reference of elastic schema. But i still have the follow…

---

## [Winlogbeat Fatal Error 8.7.0+ name already used](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093)

<div class="topic-metadata">

**Author:** [@dwissm1](https://discuss.elastic.co/u/dwissm1)\
**Replies:** 12\
**Last updated:** [July 7, 2023, 12:33am UTC](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093 "2023-07-07T00:33:28Z")

</div>

Hey Folks, Running into some fatal errors with Winlogbeat. Started happening around 8.7.0 and I am now getting to try to fix it. I was on 8.6.2 and and was working fine, anything 8.7+ it has a fatal error but if I go …

---

## [MountVolume.SetUp failed for volume "elasticsearch-master-certs" : secret "elasticsearch-master-certs" not found](https://discuss.elastic.co/t/mountvolume-setup-failed-for-volume-elasticsearch-master-certs-secret-elasticsearch-master-certs-not-found/337850)

<div class="topic-metadata">

**Author:** [@Shikder\_Reyad](https://discuss.elastic.co/u/Shikder_Reyad)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 11:58pm UTC](https://discuss.elastic.co/t/mountvolume-setup-failed-for-volume-elasticsearch-master-certs-secret-elasticsearch-master-certs-not-found/337850 "2023-07-06T23:58:43Z")

</div>

Warning FailedMount 5s (x8 over 69s) kubelet MountVolume.SetUp failed for volume "elasticsearch-master-certs" : secret "elasticsearch-master-certs" not found container create stuck filebeat-filebeat-bvbnl…

---

## [Heartbeat auto-discover not working for AWS ELB](https://discuss.elastic.co/t/heartbeat-auto-discover-not-working-for-aws-elb/337187)

<div class="topic-metadata">

**Author:** [@michael31](https://discuss.elastic.co/u/michael31)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 9:31pm UTC](https://discuss.elastic.co/t/heartbeat-auto-discover-not-working-for-aws-elb/337187 "2023-07-05T21:31:47Z")

</div>

Hello, I am trying to set up heartbeat for AWS autodiscover ELB in 2 accounts (1 I did succesffully) and on the second with the exact same configuration I am getting the following errors. I configured everything as a far…

---

## [Add id processor filebeat](https://discuss.elastic.co/t/add-id-processor-filebeat/337655)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:39am UTC](https://discuss.elastic.co/t/add-id-processor-filebeat/337655 "2023-07-05T10:39:00Z")

</div>

Hi there, just want to ask, i have configured filebeat as a container and the filebeat has been ingested millions of logs every minutes. first of all, this is my filebeat config precisely on processor part: as can y…

---

## [TCP input failed with Checkpoint syslog integration](https://discuss.elastic.co/t/tcp-input-failed-with-checkpoint-syslog-integration/337609)

<div class="topic-metadata">

**Author:** [@adub08](https://discuss.elastic.co/u/adub08)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 6:04am UTC](https://discuss.elastic.co/t/tcp-input-failed-with-checkpoint-syslog-integration/337609 "2023-07-05T06:04:50Z")

</div>

Hi I've been unable to setup the Checkpoint Elastic integration due to this error. \[elastic\_agent.filebeat\]\[error\] Input 'tcp' failed with: context canceled Settings: Integration info: logfile: disabled UDP: disa…

---

## [Heartbeat: Ping TImeout on hosts causes state.duration\_ms to stay at 0?](https://discuss.elastic.co/t/heartbeat-ping-timeout-on-hosts-causes-state-duration-ms-to-stay-at-0/334051)

<div class="topic-metadata">

**Author:** [@scantron](https://discuss.elastic.co/u/scantron)\
**Replies:** 7\
**Last updated:** [July 4, 2023, 3:46pm UTC](https://discuss.elastic.co/t/heartbeat-ping-timeout-on-hosts-causes-state-duration-ms-to-stay-at-0/334051 "2023-07-04T15:46:49Z")

</div>

We are monitoring a few hosts using ICMP on heartbeat. Heartbeat accurately depicts the uptime using the state.duration\_ms field. However, shutting down a host for testing leads to the error.message field of "ping timeou…

---

## [Metricbeat windows module error](https://discuss.elastic.co/t/metricbeat-windows-module-error/337566)

<div class="topic-metadata">

**Author:** [@dchaarifreedomofdev](https://discuss.elastic.co/u/dchaarifreedomofdev)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 1:43pm UTC](https://discuss.elastic.co/t/metricbeat-windows-module-error/337566 "2023-07-04T13:43:14Z")

</div>

I have installed metricbeat 7.17.5 on my windows machine and I enabled the windows module. And I added this configuration : module: windows metricsets: - service enabled: true period: 30s But when I r…

---

## [Filebeat restart question](https://discuss.elastic.co/t/filebeat-restart-question/335194)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 4\
**Last updated:** [July 4, 2023, 10:24am UTC](https://discuss.elastic.co/t/filebeat-restart-question/335194 "2023-07-04T10:24:32Z")

</div>

Hi there, Everytime I need to restart Filebeat, my "scripted fields" and customization to some fields are broken. Also the dashboards are reset. Is this normal? Is there any way that I can fix this behaviour to prevent…

---

## [Logs are not showing in kibana 8.8.0](https://discuss.elastic.co/t/logs-are-not-showing-in-kibana-8-8-0/337396)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 12\
**Last updated:** [July 4, 2023, 2:36am UTC](https://discuss.elastic.co/t/logs-are-not-showing-in-kibana-8-8-0/337396 "2023-07-04T02:36:52Z")

</div>

I have more than 5 servers on filebeat V8.8.0 is running but only 2 server's data is showing on Kibana Discovery tab other server's data is not showing, the configurations are same on all servers even the filebeat.yml is…

---

## [Elastic Agent broken in Kubernetes Integration with Fleet: FailedMount](https://discuss.elastic.co/t/elastic-agent-broken-in-kubernetes-integration-with-fleet-failedmount/337300)

<div class="topic-metadata">

**Author:** [@rjh](https://discuss.elastic.co/u/rjh)\
**Replies:** 4\
**Last updated:** [July 3, 2023, 3:21pm UTC](https://discuss.elastic.co/t/elastic-agent-broken-in-kubernetes-integration-with-fleet-failedmount/337300 "2023-07-03T15:21:03Z")

</div>

I just started my trial to evaluate Elastic as the hosted platform for our Kubernetes observability. Fresh from signing in for the first time, I am following the Kubernetes integration setup flow, which starts by having…

---

## [How filebeat process memory mapped log files](https://discuss.elastic.co/t/how-filebeat-process-memory-mapped-log-files/337447)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Borisov](https://discuss.elastic.co/u/Aleksandr_Borisov)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 11:26am UTC](https://discuss.elastic.co/t/how-filebeat-process-memory-mapped-log-files/337447 "2023-07-03T11:26:17Z")

</div>

I have found really strange behaviour of filebeat. Filebeat stop harvesting memory mapped files. I'm using log files which has constant size. To write data to logs i'm writing just string to memory and kernel flush it up…

---

## [Azure-blob-storage input: fatal error: concurrent map iteration and map write](https://discuss.elastic.co/t/azure-blob-storage-input-fatal-error-concurrent-map-iteration-and-map-write/336364)

<div class="topic-metadata">

**Author:** [@kdobmayer](https://discuss.elastic.co/u/kdobmayer)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 7:22am UTC](https://discuss.elastic.co/t/azure-blob-storage-input-fatal-error-concurrent-map-iteration-and-map-write/336364 "2023-07-03T07:22:54Z")

</div>

I am getting an error using filebeat with azure-blob-storage input plugin. I am using filebeat version 8.8.1 and the following configuration: - type: azure-blob-storage id: \<id\> enabled: true account\_name: \<accoun…

---

## [Filebeat selftest failt: missing field 'output.elasticsearch.hosts'](https://discuss.elastic.co/t/filebeat-selftest-failt-missing-field-output-elasticsearch-hosts/337388)

<div class="topic-metadata">

**Author:** [@enp2s6](https://discuss.elastic.co/u/enp2s6)\
**Replies:** 2\
**Last updated:** [July 2, 2023, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-selftest-failt-missing-field-output-elasticsearch-hosts/337388 "2023-07-02T12:56:11Z")

</div>

Hello, I have elasticsearch and Kibana install and minimal security settings enabled. After reboot everything works great. However, I can not connect to Kibana. Log: ERROR instance/beat.go:1027 Exiting: error ini…

---

## [Filebeat 8.8.0 error loading template: failed to put data stream: could not put data stream: 400 Bad Request](https://discuss.elastic.co/t/filebeat-8-8-0-error-loading-template-failed-to-put-data-stream-could-not-put-data-stream-400-bad-request/337370)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 12\
**Last updated:** [July 2, 2023, 11:40am UTC](https://discuss.elastic.co/t/filebeat-8-8-0-error-loading-template-failed-to-put-data-stream-could-not-put-data-stream-400-bad-request/337370 "2023-07-02T11:40:35Z")

</div>

I have installed the filebeat 8.8.0 and by running the filebeat setup -e the index is created in index template but when trying to create a data view the index is not showing there and while running the filebeat setup co…

---

## [Connection Reset to Logstash](https://discuss.elastic.co/t/connection-reset-to-logstash/337242)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 7:23pm UTC](https://discuss.elastic.co/t/connection-reset-to-logstash/337242 "2023-06-30T19:23:01Z")

</div>

Trying to send Metricbeat to Logstash. Metricbeat logs don't throw any errors, but Logstash shows the following: \[2023-06-29T15:30:02,110\]\[INFO \]\[org.logstash.beats.BeatsHandler\] \[local: 192.168.1.78:5045, remote: 192.…

---

## [Filebeat - elasticsearch output without pipeline management](https://discuss.elastic.co/t/filebeat-elasticsearch-output-without-pipeline-management/337322)

<div class="topic-metadata">

**Author:** [@anon68795679](https://discuss.elastic.co/u/anon68795679)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 2:30pm UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-output-without-pipeline-management/337322 "2023-06-30T14:30:32Z")

</div>

Hi, we want to deliver PostgresSQL logs with the filebeat postgres module to an elasticsearch output. But the filebeat shouldn't manage anything in the elasticsearch. ILM, template and ingest pipelines are managed by o…

---

## [Strange error with empty delimiter in dissect processor in filebeat](https://discuss.elastic.co/t/strange-error-with-empty-delimiter-in-dissect-processor-in-filebeat/337304)

<div class="topic-metadata">

**Author:** [@calipee](https://discuss.elastic.co/u/calipee)\
**Replies:** 3\
**Last updated:** [June 30, 2023, 1:57pm UTC](https://discuss.elastic.co/t/strange-error-with-empty-delimiter-in-dissect-processor-in-filebeat/337304 "2023-06-30T13:57:55Z")

</div>

I'm trying to dissect the log message and pattern shown in the following error. I validated my input using an dissect-tester by jorgelbg where it works without any issues. I think its especially strange that the delimi…

---

## [Auditbeat process.args shortened](https://discuss.elastic.co/t/auditbeat-process-args-shortened/337298)

<div class="topic-metadata">

**Author:** [@radovan](https://discuss.elastic.co/u/radovan)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 10:02am UTC](https://discuss.elastic.co/t/auditbeat-process-args-shortened/337298 "2023-06-30T10:02:49Z")

</div>

Hi, I noticed some time ago, that sometimes process.args get shortened in a way that 3 dots are put there instead of more arguments from the commandline so it looks like this: (this is from socket event.dataset, arg…

---

## [SHA1 error msgs from 'dnf update' (centos9.x)](https://discuss.elastic.co/t/sha1-error-msgs-from-dnf-update-centos9-x/337206)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 2:10am UTC](https://discuss.elastic.co/t/sha1-error-msgs-from-dnf-update-centos9-x/337206 "2023-06-30T02:10:36Z")

</div>

Looks like elastic is signing 8.8.x \*beat package updates with SHA1. CentOS 9 doesn't support this anymore. I can bypass it but maybe it's time to update these to something that's supported? journal is chock full of er…

---

## [Filebeat setup. could not load template error](https://discuss.elastic.co/t/filebeat-setup-could-not-load-template-error/337135)

<div class="topic-metadata">

**Author:** [@ashmistry](https://discuss.elastic.co/u/ashmistry)\
**Replies:** 7\
**Last updated:** [June 29, 2023, 6:38pm UTC](https://discuss.elastic.co/t/filebeat-setup-could-not-load-template-error/337135 "2023-06-29T18:38:14Z")

</div>

Trying to setup filebeat on my stack. It's Elasticsearch OSS 7.10.2 with opensearch 2.4.1. I am using filebeat oss 7.12.1 and got a successful test output \[root\]# filebeat test output elasticsearch: https://xyz:9200... …

---

## [Help with grok filter for \[::ffff:127.0.0.1\] hybrid + port](https://discuss.elastic.co/t/help-with-grok-filter-for-127-0-0-1-hybrid-port/337198)

<div class="topic-metadata">

**Author:** [@SedonD](https://discuss.elastic.co/u/SedonD)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 5:26pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-for-127-0-0-1-hybrid-port/337198 "2023-06-29T17:26:19Z")

</div>

Hi there, I need some help to filter (Grok) the following, f.e.: \[::ffff:88.88.88.88\]:4262,... this is a log snippet where I need to filter out the IP and port from the following formats... "New request 366c89e6-9c94-…

---

## [Add more metrics](https://discuss.elastic.co/t/add-more-metrics/337046)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 2:37pm UTC](https://discuss.elastic.co/t/add-more-metrics/337046 "2023-06-29T14:37:05Z")

</div>

Hi Team, We are using ELK stack with platinum license . In our architecture we are using metricbeat for monitoring Oracle database . We are using metricbeat 7.17 version but in that only few metricsets are available t…

---

## [Only one instance of metricbeat/filebeat can connect to elastic](https://discuss.elastic.co/t/only-one-instance-of-metricbeat-filebeat-can-connect-to-elastic/337200)

<div class="topic-metadata">

**Author:** [@marcin8352](https://discuss.elastic.co/u/marcin8352)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 1:19pm UTC](https://discuss.elastic.co/t/only-one-instance-of-metricbeat-filebeat-can-connect-to-elastic/337200 "2023-06-29T13:19:57Z")

</div>

Hello, I have an issue connecting 2 machines to elasticsearch. I have 2 redundant machines in azure which have the same software installed, both have metricbeat and filebeat installed which works just fine. Lets call t…

---

## [Linux install of Filebeat under different directory](https://discuss.elastic.co/t/linux-install-of-filebeat-under-different-directory/337130)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 9:56pm UTC](https://discuss.elastic.co/t/linux-install-of-filebeat-under-different-directory/337130 "2023-06-28T21:56:07Z")

</div>

Hi all, In the past I've followed the Filebeat installation instructions for RPM installation on Linux verbatim without issue. But now we have a machine that lacks space under /etc, so we want to install it under /opt …

---

## [Beats 8.7.x has disappeared in the Beats Release Notes?!](https://discuss.elastic.co/t/beats-8-7-x-has-disappeared-in-the-beats-release-notes/337066)

<div class="topic-metadata">

**Author:** [@bjosve](https://discuss.elastic.co/u/bjosve)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 11:39am UTC](https://discuss.elastic.co/t/beats-8-7-x-has-disappeared-in-the-beats-release-notes/337066 "2023-06-28T11:39:25Z")

</div>

Hi, It seems as Beats 8.7.x has disappeared in the Beats Release Notes. Is this a mistake or a note to avoid Beats 8.7? Best Regards, Bjorn Svensson

---

## [How to connect to Kafka using filebeat with PLAINTEXT SecurityProtocol?](https://discuss.elastic.co/t/how-to-connect-to-kafka-using-filebeat-with-plaintext-securityprotocol/336996)

<div class="topic-metadata">

**Author:** [@wymli](https://discuss.elastic.co/u/wymli)\
**Replies:** 3\
**Last updated:** [June 28, 2023, 7:06am UTC](https://discuss.elastic.co/t/how-to-connect-to-kafka-using-filebeat-with-plaintext-securityprotocol/336996 "2023-06-28T07:06:15Z")

</div>

At present, the security-protocols of kafka mainly include the following PLAINTEXT, SSL, SASL\_PLAINTEXT, SASL\_SSL. But I checked the kafka-output documentation: Configure the Kafka output | Filebeat Reference \[8.8\] | Ela…

---

## [How to configure filebeat log format to human readable instead of json?](https://discuss.elastic.co/t/how-to-configure-filebeat-log-format-to-human-readable-instead-of-json/337032)

<div class="topic-metadata">

**Author:** [@wymli](https://discuss.elastic.co/u/wymli)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 3:55am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-log-format-to-human-readable-instead-of-json/337032 "2023-06-28T03:55:48Z")

</div>

With -e option, Filebeat version 7.9.1 will output logs in this human-readable way. e.g. 2023-06-28T11:51:10.059 + 0800 INFO \[publisher\] pipeline/retry.go: 223 done But filebeat version 8.8.1 does not, outputs the lo…

---

## [Potential memory leak issue with filebeat and metricbeat](https://discuss.elastic.co/t/potential-memory-leak-issue-with-filebeat-and-metricbeat/334353)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 8\
**Last updated:** [June 27, 2023, 4:01pm UTC](https://discuss.elastic.co/t/potential-memory-leak-issue-with-filebeat-and-metricbeat/334353 "2023-06-27T16:01:27Z")

</div>

Since upgrading from ELK 7.17.1 to ELK 8.6.2 (and even with ELK 8.7.1) we are experiencing OOMKilled on filebeat and metricbeat pods. We had no issues with ELK 7.17.1. Increasing the resources allocations does not resolv…

---

## [Error fetching data for metricset logstash.node\_stats: error making http request: port 9600 connection refused](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-stats-error-making-http-request-port-9600-connection-refused/336965)

<div class="topic-metadata">

**Author:** [@deepier](https://discuss.elastic.co/u/deepier)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 9:48am UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-stats-error-making-http-request-port-9600-connection-refused/336965 "2023-06-27T09:48:45Z")

</div>

Hello Everyone, Good day, I already setup my elastic and metricbeat. I already enable some metricbeat modules like elasticsearch-xpack configured the yml. Now im tryng to add logstash via metricbeat but when i restart…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=43)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=45)
