# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=45

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 46

---

## [Performance hit when multiple filebeats are sending to same ES](https://discuss.elastic.co/t/performance-hit-when-multiple-filebeats-are-sending-to-same-es/335493)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 22\
**Last updated:** [June 27, 2023, 1:09am UTC](https://discuss.elastic.co/t/performance-hit-when-multiple-filebeats-are-sending-to-same-es/335493 "2023-06-27T01:09:44Z")

</div>

Hi, I have a total of 5 servers, all sending Netflow data using filebeat to the same server (1 of the 5 servers) running ES. Each server is also running 2 instances of filebeat, so in total, I have 5 x 2 filebeat instan…

---

## [Filebeat handle multiline](https://discuss.elastic.co/t/filebeat-handle-multiline/334742)

<div class="topic-metadata">

**Author:** [@emily3](https://discuss.elastic.co/u/emily3)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-handle-multiline/334742 "2023-06-26T22:26:54Z")

</div>

we have some logs. most of them are constructed, but for the traceback it was unconstructed and seperated in the log, such as \* 2023-05-30T20:52:15.545314-04:00 ssnode-proxy-1202-f09-2 proxy-server: err STDERR: Tracebac…

---

## [ERROR instance/beat.go:1027 Exiting: 1 error: error loading config file: invalid config: yaml: line 85: did not find expected key Exiting: 1 error: error loading config file: invalid config: yaml: line 85: did not find expected key](https://discuss.elastic.co/t/error-instance-beat-go-1027-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key/335171)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 27\
**Last updated:** [June 26, 2023, 8:02pm UTC](https://discuss.elastic.co/t/error-instance-beat-go-1027-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key/335171 "2023-06-26T20:02:08Z")

</div>

I have configured my filebeat.yml as follows : ###################### Filebeat Configuration Example ######################### # This file is an example configuration file highlighting only the most common # options. T…

---

## [Filebeat create new index at every x hours](https://discuss.elastic.co/t/filebeat-create-new-index-at-every-x-hours/336924)

<div class="topic-metadata">

**Author:** [@6NMgfDwZ3](https://discuss.elastic.co/u/6NMgfDwZ3)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 5:37pm UTC](https://discuss.elastic.co/t/filebeat-create-new-index-at-every-x-hours/336924 "2023-06-26T17:37:53Z")

</div>

Hi all! The storage under ELK is limited, and can't be increased. So I need to delete indexes very often but deleting one-day indexes would result in the unnecessary loss of a massive amount of documents therefore I nee…

---

## [High CPU after updating Filebeat from version 7.12.0 to 8.8.1](https://discuss.elastic.co/t/high-cpu-after-updating-filebeat-from-version-7-12-0-to-8-8-1/336897)

<div class="topic-metadata">

**Author:** [@germain\_nganko](https://discuss.elastic.co/u/germain_nganko)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 10:59am UTC](https://discuss.elastic.co/t/high-cpu-after-updating-filebeat-from-version-7-12-0-to-8-8-1/336897 "2023-06-26T10:59:37Z")

</div>

Description: After updating filebeat from version 7.12.0 to 8.8.1 we started observing high cpu usage. We disabled the cronjob and deployment resources medata on purpose thinking it will help but it didn't really help. A…

---

## [Huge amount of SELinux messages due to Metricbeat & Filebeat](https://discuss.elastic.co/t/huge-amount-of-selinux-messages-due-to-metricbeat-filebeat/336882)

<div class="topic-metadata">

**Author:** [@adityasinghal26](https://discuss.elastic.co/u/adityasinghal26)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 8:54am UTC](https://discuss.elastic.co/t/huge-amount-of-selinux-messages-due-to-metricbeat-filebeat/336882 "2023-06-26T08:54:30Z")

</div>

Hi Team, We are currently running Elasticsearch 8.6 and various beats (filebeat, metricbeat) of version 8.6 in Oracle Kubernetes Engine (OKE) nodes. As part of the implementation, we are seeing below error messages prin…

---

## [Filebeat exclude\_files is not working as expected for windows](https://discuss.elastic.co/t/filebeat-exclude-files-is-not-working-as-expected-for-windows/336829)

<div class="topic-metadata">

**Author:** [@junly](https://discuss.elastic.co/u/junly)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 5:19pm UTC](https://discuss.elastic.co/t/filebeat-exclude-files-is-not-working-as-expected-for-windows/336829 "2023-06-25T17:19:28Z")

</div>

Elastic Filebeat 8.7.0 file path "d:\\log\\LuceneSOA\\排序搜索结果\\2023-06-21.txt", Exclude txt files dated under the file but not working the regexp was verified with regex101.com filebeat.yml input filebeat.inputs: -…

---

## [Filestream input sends duplicates events on restart and during operation](https://discuss.elastic.co/t/filestream-input-sends-duplicates-events-on-restart-and-during-operation/334951)

<div class="topic-metadata">

**Author:** [@michaelbu](https://discuss.elastic.co/u/michaelbu)\
**Replies:** 33\
**Last updated:** [June 25, 2023, 4:22pm UTC](https://discuss.elastic.co/t/filestream-input-sends-duplicates-events-on-restart-and-during-operation/334951 "2023-06-25T16:22:10Z")

</div>

We use more than 1.800 filebeats with the filestream-input in version: $ filebeat version filebeat version 8.7.0 (amd64), libbeat 8.7.0 \[a8dbc6c06381f4fe33a5dc23906d63c04c9e2444 built 2023-03-23 00:37:07 +0000 UTC\] Ro…

---

## [Auditbeat. failed to set audit PID - audiebeat complaining about itself](https://discuss.elastic.co/t/auditbeat-failed-to-set-audit-pid-audiebeat-complaining-about-itself/336841)

<div class="topic-metadata">

**Author:** [@JohnAnderson](https://discuss.elastic.co/u/JohnAnderson)\
**Replies:** 0\
**Last updated:** [June 25, 2023, 4:19pm UTC](https://discuss.elastic.co/t/auditbeat-failed-to-set-audit-pid-audiebeat-complaining-about-itself/336841 "2023-06-25T16:19:43Z")

</div>

Hi everyone! I have got no ideas where to find problem in next situation. When I start/restart container with auditd option socket\_type: unicast, I can see in logs "message":"Failure receiving audit events","service.nam…

---

## [How to extract string from the log and create a new field and send to elastic search index](https://discuss.elastic.co/t/how-to-extract-string-from-the-log-and-create-a-new-field-and-send-to-elastic-search-index/336797)

<div class="topic-metadata">

**Author:** [@mbsarathchandra](https://discuss.elastic.co/u/mbsarathchandra)\
**Replies:** 2\
**Last updated:** [June 25, 2023, 1:02am UTC](https://discuss.elastic.co/t/how-to-extract-string-from-the-log-and-create-a-new-field-and-send-to-elastic-search-index/336797 "2023-06-25T01:02:46Z")

</div>

Hello Everyone, I am currently using Elastic Search Version 8.8.1 installed on RHEL os. Filebeat Version: 8.6.1 The logs are read from the Application server and pushed to Elasticsearch index using filebeat. Data str…

---

## [Duplicate events user log in winlogbeat using drop event filter](https://discuss.elastic.co/t/duplicate-events-user-log-in-winlogbeat-using-drop-event-filter/336536)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 3\
**Last updated:** [June 23, 2023, 1:43pm UTC](https://discuss.elastic.co/t/duplicate-events-user-log-in-winlogbeat-using-drop-event-filter/336536 "2023-06-23T13:43:45Z")

</div>

Hello all, What I want to achieve is to remove the duplicate events. How should I do that? I am stuck here. Here is the scenario: When I successfully login into my lab computer there is the event ID 4672 that duplica…

---

## [Change index name within filebeats module file](https://discuss.elastic.co/t/change-index-name-within-filebeats-module-file/336772)

<div class="topic-metadata">

**Author:** [@jazzl0ver](https://discuss.elastic.co/u/jazzl0ver)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 12:31pm UTC](https://discuss.elastic.co/t/change-index-name-within-filebeats-module-file/336772 "2023-06-23T12:31:02Z")

</div>

Hi, Filebeat version is 7.10.2 According to Configuring Input Type for Filebeat Module I was trying to do the same for the index: # cat /etc/filebeat/modules.d/haproxy.yml # Module: haproxy # Docs: https://www.elastic…

---

## [Winlogbeat ingest pipelines missing geoIP](https://discuss.elastic.co/t/winlogbeat-ingest-pipelines-missing-geoip/334575)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 5\
**Last updated:** [June 23, 2023, 11:51am UTC](https://discuss.elastic.co/t/winlogbeat-ingest-pipelines-missing-geoip/334575 "2023-06-23T11:51:07Z")

</div>

Winlogbeat ingest pipelines Security and Sysmon missing geoIP. It is on purpose? All filebeat ingest pipelines have geoIP enrichment and it seems strange that winlogbeat missing geoIP.

---

## [Winlogbeat stops sending logs](https://discuss.elastic.co/t/winlogbeat-stops-sending-logs/336756)

<div class="topic-metadata">

**Author:** [@Fursel](https://discuss.elastic.co/u/Fursel)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:31am UTC](https://discuss.elastic.co/t/winlogbeat-stops-sending-logs/336756 "2023-06-23T11:31:57Z")

</div>

Hello, We are collecting events from DCs and somehow lately winlogbeat stopps sending them on multiple devices. I did set logging for debug logging.level: debug logging.to\_file: true logging.files: path: 'C:\\Progra…

---

## [Metric Beat - windows services](https://discuss.elastic.co/t/metric-beat-windows-services/336734)

<div class="topic-metadata">

**Author:** [@sreeraj\_palat](https://discuss.elastic.co/u/sreeraj_palat)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 5:19am UTC](https://discuss.elastic.co/t/metric-beat-windows-services/336734 "2023-06-23T05:19:47Z")

</div>

iam installed metricbeat in 5 servers. i want to monitor the windows services in the kibana dashboard. i can get the installed services in windows. how can i get the cpu memory usage of each services

---

## [Filebeat 7.17.0 - Unable to parse time field "Jun 21 09:16:38" with \[Stamp\]](https://discuss.elastic.co/t/filebeat-7-17-0-unable-to-parse-time-field-jun-21-0938-with-stamp/336703)

<div class="topic-metadata">

**Author:** [@vavaux](https://discuss.elastic.co/u/vavaux)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 1:41pm UTC](https://discuss.elastic.co/t/filebeat-7-17-0-unable-to-parse-time-field-jun-21-0938-with-stamp/336703 "2023-06-22T13:41:01Z")

</div>

Hello, Quite newbie on ELK & Filebeat (using v7.17.0), I'm trying to parse and retrieve the log line date as timestamp from following logs: Jun 19 22:08:00: WARNING: RCP timeout when waiting for ping response. Disconne…

---

## [Beat-xpack module doesn’t work on localhost 5066 port](https://discuss.elastic.co/t/beat-xpack-module-doesn-t-work-on-localhost-5066-port/334909)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 6\
**Last updated:** [June 22, 2023, 11:41am UTC](https://discuss.elastic.co/t/beat-xpack-module-doesn-t-work-on-localhost-5066-port/334909 "2023-06-22T11:41:11Z")

</div>

Hello, I am trying to use Beat Module for monitoring Metricbeat on Kibana-Stack Monitoring. I am using this in metricbeat.yml - module: beat xpack.enabled: true period: 10s hosts: \[ "http://localhost:5066…

---

## [Getting JSON data out of message field imported with filebeat](https://discuss.elastic.co/t/getting-json-data-out-of-message-field-imported-with-filebeat/335872)

<div class="topic-metadata">

**Author:** [@Lou003](https://discuss.elastic.co/u/Lou003)\
**Replies:** 3\
**Last updated:** [June 22, 2023, 8:49am UTC](https://discuss.elastic.co/t/getting-json-data-out-of-message-field-imported-with-filebeat/335872 "2023-06-22T08:49:29Z")

</div>

Hi everybody, I have a problem with indexing filebeat output generated from a JSON file. This JSON file has been created by converting a PCAP file and using jq to make it not pretty. After using filebeat this file has b…

---

## [Winlogbeat doesn’t work since change of version](https://discuss.elastic.co/t/winlogbeat-doesn-t-work-since-change-of-version/335087)

<div class="topic-metadata">

**Author:** [@blop135](https://discuss.elastic.co/u/blop135)\
**Replies:** 3\
**Last updated:** [June 22, 2023, 7:37am UTC](https://discuss.elastic.co/t/winlogbeat-doesn-t-work-since-change-of-version/335087 "2023-06-22T07:37:14Z")

</div>

Hi everyone, I have a little problem here. I decided to update from the version 6.8.4 to the version 7.17.7. The installation of winlogbeat went well but then it says in the logs that the connexion to Kafka is establish…

---

## [Https://docker-auth.elastic.co not working](https://discuss.elastic.co/t/https-docker-auth-elastic-co-not-working/334665)

<div class="topic-metadata">

**Author:** [@ITMBF](https://discuss.elastic.co/u/ITMBF)\
**Replies:** 6\
**Last updated:** [June 22, 2023, 5:01am UTC](https://discuss.elastic.co/t/https-docker-auth-elastic-co-not-working/334665 "2023-06-22T05:01:38Z")

</div>

Hi guys, I am looking to build a ppc64le version of filebeat and try to get the golang-crossbuild containers. In order to do that I want to obtain them from docker.elastic.co/beats-dev/golang-crossbuild:\[TAG\] When run…

---

## [What is the FileBeats version that is compatible in Oracle Solaris 11.3?](https://discuss.elastic.co/t/what-is-the-filebeats-version-that-is-compatible-in-oracle-solaris-11-3/336466)

<div class="topic-metadata">

**Author:** [@kam89](https://discuss.elastic.co/u/kam89)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 4:02am UTC](https://discuss.elastic.co/t/what-is-the-filebeats-version-that-is-compatible-in-oracle-solaris-11-3/336466 "2023-06-21T04:02:49Z")

</div>

Hi, Is there any FileBeats version that is compatible in Oracle Solaris 11.3? Thank you and Regards

---

## [Beats Native Grok Processor](https://discuss.elastic.co/t/beats-native-grok-processor/336521)

<div class="topic-metadata">

**Author:** [@james-mchugh](https://discuss.elastic.co/u/james-mchugh)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 2:32am UTC](https://discuss.elastic.co/t/beats-native-grok-processor/336521 "2023-06-21T02:32:22Z")

</div>

Hello everyone. I am looking into adding a Grok processor to Beats/Filebeat as requested in \[Filebeat\] Add grok Processor as native beat/filebeat processor · Issue #30073 · elastic/beats · GitHub. Our team has already c…

---

## [Metricbeat GCP Billing metricset fails with timeout error](https://discuss.elastic.co/t/metricbeat-gcp-billing-metricset-fails-with-timeout-error/336516)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 11:05pm UTC](https://discuss.elastic.co/t/metricbeat-gcp-billing-metricset-fails-with-timeout-error/336516 "2023-06-20T23:05:32Z")

</div>

I enabled the gcp module for metricbeat and used the billing metricset as: - module: gcp metricsets: - billing period: 24h project\_id: "project" credentials\_file\_path: "/etc/metricbeat/service-account.json" …

---

## [Recursive glob pattern depth](https://discuss.elastic.co/t/recursive-glob-pattern-depth/336471)

<div class="topic-metadata">

**Author:** [@unknotted-evacuee](https://discuss.elastic.co/u/unknotted-evacuee)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 1:04pm UTC](https://discuss.elastic.co/t/recursive-glob-pattern-depth/336471 "2023-06-20T13:04:27Z")

</div>

We are trying to recursively capture logs from a file tree that gets quite deep. According to the documentation here: filestream input | Filebeat Reference \[8.8\] | Elastic This states that: "If enabled it expands a sing…

---

## [Which visualization should i choose for displaying Host.version](https://discuss.elastic.co/t/which-visualization-should-i-choose-for-displaying-host-version/335927)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 8:46am UTC](https://discuss.elastic.co/t/which-visualization-should-i-choose-for-displaying-host-version/335927 "2023-06-20T08:46:10Z")

</div>

i am want to display host confirmation i dashboard like cpu count, total memory , host.os.version . which visualisation should i choose . as all require aggregate function but . these are not . and more over for my …

---

## [What is the best candidate for the Filestream ID for Autodiscover Kubernetes Provider?](https://discuss.elastic.co/t/what-is-the-best-candidate-for-the-filestream-id-for-autodiscover-kubernetes-provider/336397)

<div class="topic-metadata">

**Author:** [@lprakashv](https://discuss.elastic.co/u/lprakashv)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 7:30am UTC](https://discuss.elastic.co/t/what-is-the-best-candidate-for-the-filestream-id-for-autodiscover-kubernetes-provider/336397 "2023-06-20T07:30:46Z")

</div>

Based on thg logs, it seems that the filestream ID is not unique and this could cause data duplication. However, my rationale towards setting a combination of ${data.kubernetes.pod.name} and ${data.kubernetes.container.i…

---

## [aws-cloudwatch obtaining logs exception](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401)

<div class="topic-metadata">

**Author:** [@Askas00](https://discuss.elastic.co/u/Askas00)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 7:38pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401 "2023-06-19T19:38:14Z")

</div>

When I use the aws-cloudwatch input plug-in to obtain the logs stored in cloudwatchlogs, the number of logs obtained is inconsistent with the number of logs in cloudwatchlogs. The route53 logs are stored in cloudwatchlog…

---

## [Filebeat log to multiple outputs like file and syslog](https://discuss.elastic.co/t/filebeat-log-to-multiple-outputs-like-file-and-syslog/335743)

<div class="topic-metadata">

**Author:** [@michaelbu](https://discuss.elastic.co/u/michaelbu)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 2:53pm UTC](https://discuss.elastic.co/t/filebeat-log-to-multiple-outputs-like-file-and-syslog/335743 "2023-06-19T14:53:04Z")

</div>

Hi, I'm using filebeat on Linux in this version: $ rpm -qa | grep filebeat filebeat-8.7.0-1.x86\_64 I would like to log filebeat to logfiles and also to syslog. This is the configuration snippet: logging: to\_files: …

---

## [X-pack/metricbeat/module/statsd: Unable to parse float values (statsd module) of counter metric type](https://discuss.elastic.co/t/x-pack-metricbeat-module-statsd-unable-to-parse-float-values-statsd-module-of-counter-metric-type/330095)

<div class="topic-metadata">

**Author:** [@shmsr\_elastic](https://discuss.elastic.co/u/shmsr_elastic)\
**Replies:** 1\
**Last updated:** [June 17, 2023, 7:04pm UTC](https://discuss.elastic.co/t/x-pack-metricbeat-module-statsd-unable-to-parse-float-values-statsd-module-of-counter-metric-type/330095 "2023-06-17T19:04:59Z")

</div>

I was exploring statsd's module code in beats while making some changes to the same and I noticed that the for metrics of type counter, we just support integers (of base 10 and 64 bitsize) and in case it is not the same…

---

## [Creating pipelines for multiple configuration](https://discuss.elastic.co/t/creating-pipelines-for-multiple-configuration/336223)

<div class="topic-metadata">

**Author:** [@vishukadam](https://discuss.elastic.co/u/vishukadam)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 1:19pm UTC](https://discuss.elastic.co/t/creating-pipelines-for-multiple-configuration/336223 "2023-06-16T13:19:50Z")

</div>

Hi , I am trying to configure Logstash to read mulitple configurations (viz. A.conf and B.conf). Each configuration create separate index viz. indexA annd indexB, which i defined in the configuration file. Running indiv…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=44)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=46)
