# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=46

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 47

---

## [Push & install winlogbeat to 100s of pcs](https://discuss.elastic.co/t/push-install-winlogbeat-to-100s-of-pcs/336134)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 7:02pm UTC](https://discuss.elastic.co/t/push-install-winlogbeat-to-100s-of-pcs/336134 "2023-06-15T19:02:59Z")

</div>

Hi All, I am using elastic stack v8.1 . I am facing a scenario where i have to install winlogbeat and sysmon to more than 300 desktop pcs running on Windows 10. However, installing the beat manually will be time consumi…

---

## [My Filebeat configuration can't listen to my logs inside my Kubernetes pods](https://discuss.elastic.co/t/my-filebeat-configuration-cant-listen-to-my-logs-inside-my-kubernetes-pods/336132)

<div class="topic-metadata">

**Author:** [@Derhoer](https://discuss.elastic.co/u/Derhoer)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 6:57pm UTC](https://discuss.elastic.co/t/my-filebeat-configuration-cant-listen-to-my-logs-inside-my-kubernetes-pods/336132 "2023-06-15T18:57:56Z")

</div>

I have web app service that run in go and produce a log that I stored inside /var/logs/app/app.log. This service is running inside a Kubernetes pods. And I have another pods that running Filebeat to listen to logs produc…

---

## [Parsing input as JSON: invalid character '\\x00' looking for beginning of value Filebeat](https://discuss.elastic.co/t/parsing-input-as-json-invalid-character-x00-looking-for-beginning-of-value-filebeat/336095)

<div class="topic-metadata">

**Author:** [@Lou003](https://discuss.elastic.co/u/Lou003)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 12:40pm UTC](https://discuss.elastic.co/t/parsing-input-as-json-invalid-character-x00-looking-for-beginning-of-value-filebeat/336095 "2023-06-15T12:40:12Z")

</div>

Hi everybody! I made a configuration where the data is imported in Elastic through a pipeline using filebeat. This gives in Discover the following error: parsing input as JSON: invalid character '\\x00' looking for begin…

---

## [Filebeat send logs to different port](https://discuss.elastic.co/t/filebeat-send-logs-to-different-port/335729)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 9\
**Last updated:** [June 14, 2023, 8:40pm UTC](https://discuss.elastic.co/t/filebeat-send-logs-to-different-port/335729 "2023-06-14T20:40:51Z")

</div>

Hi there, i have a question according to the title of this topic. if i have 8 logstash, then i config the filebeat to send the logs to 4 logstash using port 5045 and 5090 to another 4 logstash. is it possible? if yes, …

---

## [A possible bug about Kafka output ErrBreakerOpen](https://discuss.elastic.co/t/a-possible-bug-about-kafka-output-errbreakeropen/335816)

<div class="topic-metadata">

**Author:** [@Ferrari248](https://discuss.elastic.co/u/Ferrari248)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 3:29am UTC](https://discuss.elastic.co/t/a-possible-bug-about-kafka-output-errbreakeropen/335816 "2023-06-13T03:29:27Z")

</div>

I find an issue which is possibly a bug in kafka output of FIleBeat8.7: libbeat/outputs/kafka/client.go: func (r \*msgRef) fail(msg \*message, err error) { switch err { case sarama.ErrInvalidMessage: ... case sarama…

---

## [Filebeat: How to edit apache module ingest pipeline](https://discuss.elastic.co/t/filebeat-how-to-edit-apache-module-ingest-pipeline/335749)

<div class="topic-metadata">

**Author:** [@Akshaychdev](https://discuss.elastic.co/u/Akshaychdev)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 9:17am UTC](https://discuss.elastic.co/t/filebeat-how-to-edit-apache-module-ingest-pipeline/335749 "2023-06-12T09:17:09Z")

</div>

Using Elasticsearch and Kibana 7.17 with Filebeat and Filebeat-apache module to index apache access and error logs to elasticsearch. I need to add some more filtering to Apache Error log message, for that prepared the n…

---

## [How can I add add an extra field to all documents indexed by beats](https://discuss.elastic.co/t/how-can-i-add-add-an-extra-field-to-all-documents-indexed-by-beats/335622)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 4:24pm UTC](https://discuss.elastic.co/t/how-can-i-add-add-an-extra-field-to-all-documents-indexed-by-beats/335622 "2023-06-11T16:24:54Z")

</div>

Hi all. Lets imagine that I have a single elasticsearch cluster to store document from two different companies Company1 has server1 server2 and server3 Company2 has server1 server2 and server3 For me the easier…

---

## [Sophos XG logs that removes the pipe but are in the Elastichsearch](https://discuss.elastic.co/t/sophos-xg-logs-that-removes-the-pipe-but-are-in-the-elastichsearch/334601)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 1\
**Last updated:** [June 9, 2023, 10:58am UTC](https://discuss.elastic.co/t/sophos-xg-logs-that-removes-the-pipe-but-are-in-the-elastichsearch/334601 "2023-06-09T10:58:22Z")

</div>

Thank you for your time. I’m new to the ELK system. I’m collecting information from a Sophos XG 19.5 The structure I have is: Firewall XG (19.5) --\> Filebeat (7.17.10) -\> Elastichsearch (7.17.8) I have detected that…

---

## [Filebeat failed to start](https://discuss.elastic.co/t/filebeat-failed-to-start/335601)

<div class="topic-metadata">

**Author:** [@Terkea](https://discuss.elastic.co/u/Terkea)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 9:20am UTC](https://discuss.elastic.co/t/filebeat-failed-to-start/335601 "2023-06-09T09:20:46Z")

</div>

Hello guys, I have been struggling for quite some time with my filebeat setup. I have installed filebeat 7.10 on an ubuntu instance. Somehow part of the logs were sent to my cluster, but now when I check the systemctl …

---

## [Connecting Winlogbeat with pfsense](https://discuss.elastic.co/t/connecting-winlogbeat-with-pfsense/334811)

<div class="topic-metadata">

**Author:** [@mariya](https://discuss.elastic.co/u/mariya)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 11:07pm UTC](https://discuss.elastic.co/t/connecting-winlogbeat-with-pfsense/334811 "2023-06-08T23:07:14Z")

</div>

Hi ! I have set up a CentOS virtual machine running ELK server. Also in vmware I installed Windows virtual machine with Winlogbeat, and a pfSense virtual machine. I want to configure Winlogbeat to send Windows logs to Lo…

---

## [Sending stdout and stderr to different elasticsearch hosts and kibana](https://discuss.elastic.co/t/sending-stdout-and-stderr-to-different-elasticsearch-hosts-and-kibana/335445)

<div class="topic-metadata">

**Author:** [@Shobana\_Nagarajan](https://discuss.elastic.co/u/Shobana_Nagarajan)\
**Replies:** 3\
**Last updated:** [June 8, 2023, 10:51pm UTC](https://discuss.elastic.co/t/sending-stdout-and-stderr-to-different-elasticsearch-hosts-and-kibana/335445 "2023-06-08T22:51:22Z")

</div>

Hi, I have a requirement to send stdout and stderr to different Elastic and Kibana hosts. I have deployed two filebeat containers. Here are my filebeat.yml. 1.filebeat.stdout.yml filebeat.config: modules: path: …

---

## [Defender\_atp module error message](https://discuss.elastic.co/t/defender-atp-module-error-message/335551)

<div class="topic-metadata">

**Author:** [@phager](https://discuss.elastic.co/u/phager)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 3:43pm UTC](https://discuss.elastic.co/t/defender-atp-module-error-message/335551 "2023-06-08T15:43:24Z")

</div>

I have Filebeat configured with defender atp module and am seeing very few valid records coming into Elasticsearch. Most records contain the following cannot access method/field \[length\] from a null def reference Can a…

---

## [Auditbeat inputs question](https://discuss.elastic.co/t/auditbeat-inputs-question/335328)

<div class="topic-metadata">

**Author:** [@zaheerabbas1988](https://discuss.elastic.co/u/zaheerabbas1988)\
**Replies:** 2\
**Last updated:** [June 8, 2023, 3:37pm UTC](https://discuss.elastic.co/t/auditbeat-inputs-question/335328 "2023-06-08T15:37:51Z")

</div>

Hello ELK community, I have a scenario where I need to input a specific log file into Auditbeat. In Filebeat, I can achieve this easily by configuring the log file path in the filebeat.inputs section. However, I was won…

---

## [Extract certain fields from JSON](https://discuss.elastic.co/t/extract-certain-fields-from-json/335487)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 3:33pm UTC](https://discuss.elastic.co/t/extract-certain-fields-from-json/335487 "2023-06-08T15:33:48Z")

</div>

Hi, I am forwarding filebeat logs to an ES, and I would like to only extract certain fields in the JSON message and write them to ES. For example, if I have the JSON message below: { "field1": "info", "field2":…

---

## [While connecting to activemq using metricbeat, I am getting that error like error making http request: Post transport connection broken: malformed HTTP status code "MaxInactivityDurationInitalDelay"](https://discuss.elastic.co/t/while-connecting-to-activemq-using-metricbeat-i-am-getting-that-error-like-error-making-http-request-post-transport-connection-broken-malformed-http-status-code-maxinactivitydurationinitaldelay/335537)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 1:26pm UTC](https://discuss.elastic.co/t/while-connecting-to-activemq-using-metricbeat-i-am-getting-that-error-like-error-making-http-request-post-transport-connection-broken-malformed-http-status-code-maxinactivitydurationinitaldelay/335537 "2023-06-08T13:26:12Z")

</div>

Hi Team, I am getting the below error while connecting to activemq through metricbeat. " ERROR module/wrapper.go:259 Error fetching data for metricset activemq.queue: error making http request: Post "ht…

---

## [Autodiscover not working](https://discuss.elastic.co/t/autodiscover-not-working/335522)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 11:12am UTC](https://discuss.elastic.co/t/autodiscover-not-working/335522 "2023-06-08T11:12:30Z")

</div>

Greetiings, We enable auto discover with following and it harvest logs from all pods. filebeat.autodiscover: providers: - type: kubernetes hints.enabled: true hints.default\_config: type: con…

---

## [Stopping filebeats affects metricbeat http module](https://discuss.elastic.co/t/stopping-filebeats-affects-metricbeat-http-module/335410)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 9:50am UTC](https://discuss.elastic.co/t/stopping-filebeats-affects-metricbeat-http-module/335410 "2023-06-08T09:50:10Z")

</div>

Hello, I use Elasticsearch 7.17.6 on a WIndows server. I started two services : metricbeat and filebeat metricbeat runs modules : system, sql and http metricbeat-http tests http routes every minute filebeat was …

---

## [How does Metricbeat get the diskio data of NAS？](https://discuss.elastic.co/t/how-does-metricbeat-get-the-diskio-data-of-nas/335488)

<div class="topic-metadata">

**Author:** [@CatLoveFishma](https://discuss.elastic.co/u/CatLoveFishma)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 3:31am UTC](https://discuss.elastic.co/t/how-does-metricbeat-get-the-diskio-data-of-nas/335488 "2023-06-08T03:31:48Z")

</div>

I have a NAS mounted on my Linux machine. I want to know how to use metricbeat to monitor the disk of nas？

---

## [Add\_docker\_metadata cannot process containers that already exited](https://discuss.elastic.co/t/add-docker-metadata-cannot-process-containers-that-already-exited/335435)

<div class="topic-metadata">

**Author:** [@Maciej\_Piasecki](https://discuss.elastic.co/u/Maciej_Piasecki)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 11:46am UTC](https://discuss.elastic.co/t/add-docker-metadata-cannot-process-containers-that-already-exited/335435 "2023-06-07T11:46:29Z")

</div>

For the input type container if the log file is discovered after the container is stopped, the add\_metadata\_processor reports {"file.name":"add\_docker\_metadata/add\_docker\_metadata.go","file.line":213},"message":"Contain…

---

## [Issue with sending apache logs to elasticsearch with different indices](https://discuss.elastic.co/t/issue-with-sending-apache-logs-to-elasticsearch-with-different-indices/335424)

<div class="topic-metadata">

**Author:** [@Akshaychdev](https://discuss.elastic.co/u/Akshaychdev)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 9:49am UTC](https://discuss.elastic.co/t/issue-with-sending-apache-logs-to-elasticsearch-with-different-indices/335424 "2023-06-07T09:49:21Z")

</div>

I am new to ELK and I want to use filebeat to fetch and transfer apache access and error logs to elasticsearch index directly. However, I need to send the logs to different indices (rather than the default filebeat\* inde…

---

## [Event.type field in system module logs not ECS compliant](https://discuss.elastic.co/t/event-type-field-in-system-module-logs-not-ecs-compliant/333579)

<div class="topic-metadata">

**Author:** [@Lorygold](https://discuss.elastic.co/u/Lorygold)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 1:59pm UTC](https://discuss.elastic.co/t/event-type-field-in-system-module-logs-not-ecs-compliant/333579 "2023-05-16T13:59:40Z")

</div>

Good morning, I activated the system module of Filebeat (version 8.7.1) in order to collect the ssh logins on an Ubuntu VM. I can see them on Kibana, but the event.type field is info event if it is an authentication log…

---

## [Can heartbeat parse the html response of a URL?](https://discuss.elastic.co/t/can-heartbeat-parse-the-html-response-of-a-url/335374)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:03pm UTC](https://discuss.elastic.co/t/can-heartbeat-parse-the-html-response-of-a-url/335374 "2023-06-06T21:03:12Z")

</div>

I am trying to parse the html response body of a URL in http monitor type and this is my config: - type: http enabled: true id: narvar name: Narvar urls: \["https://status.narvar.com/"\] schedule: '@every 10s' …

---

## [Unable to exclude metricbeat metrics with drop\_events](https://discuss.elastic.co/t/unable-to-exclude-metricbeat-metrics-with-drop-events/335378)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 7:49pm UTC](https://discuss.elastic.co/t/unable-to-exclude-metricbeat-metrics-with-drop-events/335378 "2023-06-06T19:49:31Z")

</div>

I've tried quite a few different syntax and I'm not able to get metricbeat to exclude metrics. I'm not getting any errors on startup either. Here is my config: setup: template: enabled: true …

---

## [Getting strange errors after enabling kubernetes metadata in filebeat](https://discuss.elastic.co/t/getting-strange-errors-after-enabling-kubernetes-metadata-in-filebeat/335306)

<div class="topic-metadata">

**Author:** [@sunil\_s](https://discuss.elastic.co/u/sunil_s)\
**Replies:** 12\
**Last updated:** [June 6, 2023, 4:33pm UTC](https://discuss.elastic.co/t/getting-strange-errors-after-enabling-kubernetes-metadata-in-filebeat/335306 "2023-06-06T16:33:46Z")

</div>

Getting below errors when running filebeat evel":"error","@timestamp":"2023-06-06T08:37:11.110Z","log.logger":"kubernetes","log.origin":{"file.name":"add\_kubernetes\_metadata/matchers.go","file.line":95},"message":"Error…

---

## [Kubernetes annotation - array value declaration](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 1:39pm UTC](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304 "2023-06-06T13:39:11Z")

</div>

How do we convert the following filebeat config into kubernetes pod annotation level. processors: - decode\_json\_fields: fields: \["message","msg"\] target: "qrapp" add\_error\_key: true kuber…

---

## [Metricbeat Promethes merging queries](https://discuss.elastic.co/t/metricbeat-promethes-merging-queries/334704)

<div class="topic-metadata">

**Author:** [@evileric77](https://discuss.elastic.co/u/evileric77)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 8:59pm UTC](https://discuss.elastic.co/t/metricbeat-promethes-merging-queries/334704 "2023-06-05T20:59:19Z")

</div>

This has been mentioned before here: But as there is no resolution there I'm posting here and will open an issue on github shortly. With the Prometheus module if you define 2 items that leverage the module, metricbeat …

---

## [When/how often/from where does "filebeat setup -e" need to be run?](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 4:45pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246 "2023-06-05T16:45:31Z")

</div>

I'm trying to wrap my head around "filebeat setup -e". Let's say I've already got filebeat up and running with a couple of modules, and I want to roll out a new module to a bunch of servers. Which of these would make s…

---

## [Exiting: error loading config file: yaml: line 26: did not find expected key](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-26-did-not-find-expected-key/334250)

<div class="topic-metadata">

**Author:** [@FredMir](https://discuss.elastic.co/u/FredMir)\
**Replies:** 8\
**Last updated:** [June 5, 2023, 1:47pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-26-did-not-find-expected-key/334250 "2023-06-05T13:47:56Z")

</div>

I installed filebeat-7.16.3-x86\_64.rpm on a different server and trying to send output logs to logstash but I receive this error when try to run filebeat. Also, when trying to enable modules I get the same error. Would y…

---

## [Add\_docker\_metadata is not able to pick container.labels.com\_amazonaws\_ecs\_container-name for a short living containers](https://discuss.elastic.co/t/add-docker-metadata-is-not-able-to-pick-container-labels-com-amazonaws-ecs-container-name-for-a-short-living-containers/335196)

<div class="topic-metadata">

**Author:** [@Maciej\_Piasecki](https://discuss.elastic.co/u/Maciej_Piasecki)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 9:32am UTC](https://discuss.elastic.co/t/add-docker-metadata-is-not-able-to-pick-container-labels-com-amazonaws-ecs-container-name-for-a-short-living-containers/335196 "2023-06-05T09:32:40Z")

</div>

Hi, I am running some short living containers and I noticed that add\_docker\_metadata is not able to access container.labels.com\_amazonaws\_ecs\_container-name at a random frequency. I am using a rename like this: - re…

---

## [SSL/TLS connection between ELK-Stack with Docker](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040)

<div class="topic-metadata">

**Author:** [@Lokutus25](https://discuss.elastic.co/u/Lokutus25)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 8:01am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040 "2023-06-05T08:01:08Z")

</div>

Hi, I have a big problem with my ELK-Stack (version 8.7.0) created with docker. I have created elasticsearch, kibana, logstash and filebeat with docker-compose. elasticsearch and kibana connects per ssl with the token…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=45)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=47)
