# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=47

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 48

---

## [Filebeat filestream with pipeline and multiline](https://discuss.elastic.co/t/filebeat-filestream-with-pipeline-and-multiline/335015)

<div class="topic-metadata">

**Author:** [@das](https://discuss.elastic.co/u/das)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-filestream-with-pipeline-and-multiline/335015 "2023-06-02T13:12:44Z")

</div>

I have a log format I cannot change that leads into multiline messages. I have a Ingest Pipeline set up in Kibana that works just fine on sample records. My problem is that My multiline parser seems to be ignored (at lea…

---

## [Filebeat with multiple kibana instances](https://discuss.elastic.co/t/filebeat-with-multiple-kibana-instances/335070)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 10:41am UTC](https://discuss.elastic.co/t/filebeat-with-multiple-kibana-instances/335070 "2023-06-02T10:41:20Z")

</div>

Hello , Here I take logs use case as an example, Basically, we'll collect these system logs, application logs for each application on our production, and ship them to different logstash servers and different kibana inst…

---

## [Error running filebeat](https://discuss.elastic.co/t/error-running-filebeat/334116)

<div class="topic-metadata">

**Author:** [@okasha](https://discuss.elastic.co/u/okasha)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 12:15pm UTC](https://discuss.elastic.co/t/error-running-filebeat/334116 "2023-05-23T12:15:55Z")

</div>

hello guys, I'm getting this error when running this the filebeat 8.7.1 on my local machine (both Elasticsearch and kibana are running) when running .\\filebeat.exe setup -e on power shell i couldn't paste the whole …

---

## [Giving filebeat admin rights to read from fileshare](https://discuss.elastic.co/t/giving-filebeat-admin-rights-to-read-from-fileshare/334971)

<div class="topic-metadata">

**Author:** [@\_Zeyad\_Elshater](https://discuss.elastic.co/u/_Zeyad_Elshater)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 12:00pm UTC](https://discuss.elastic.co/t/giving-filebeat-admin-rights-to-read-from-fileshare/334971 "2023-06-01T12:00:47Z")

</div>

Hi all, I have filebeat as a windows service, It supposed to read logs from a fileshare on my VM, which must be accessed using the admin account, when I log on the service of filebeat as the admin account it can't access…

---

## [Error in winlogbeat](https://discuss.elastic.co/t/error-in-winlogbeat/334967)

<div class="topic-metadata">

**Author:** [@mariya](https://discuss.elastic.co/u/mariya)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:37am UTC](https://discuss.elastic.co/t/error-in-winlogbeat/334967 "2023-06-01T11:37:47Z")

</div>

I installed winlogbeat and logstash on my pc I made the changes in the configuration file so it can send logs to the server ELK but it gives me this error :

---

## [Beats and Composable Templates](https://discuss.elastic.co/t/beats-and-composable-templates/334325)

<div class="topic-metadata">

**Author:** [@johncollaros](https://discuss.elastic.co/u/johncollaros)\
**Replies:** 6\
**Last updated:** [June 1, 2023, 11:15am UTC](https://discuss.elastic.co/t/beats-and-composable-templates/334325 "2023-06-01T11:15:22Z")

</div>

Hi, I am in the process of upgrading our Elastic Stack instance from 7.5 -\> 8, and am going through all of the migration tasks. It looks like migration to component templates is going to be a pain. Currently, I am usi…

---

## [Creating Dashboard for apache access logs using Filebeat](https://discuss.elastic.co/t/creating-dashboard-for-apache-access-logs-using-filebeat/333159)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 73\
**Last updated:** [June 1, 2023, 8:48am UTC](https://discuss.elastic.co/t/creating-dashboard-for-apache-access-logs-using-filebeat/333159 "2023-06-01T08:48:05Z")

</div>

Hey I want to create Dashboard using filebeat for apache access logs. I have complete 11 nodes on staging out of which 7 nodes are of elasticsearch(3 master nodes, 2 coordination nodes, 2 data nodes), and other 3 nodes a…

---

## [Filebeat netflow template missing](https://discuss.elastic.co/t/filebeat-netflow-template-missing/334925)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 8:40am UTC](https://discuss.elastic.co/t/filebeat-netflow-template-missing/334925 "2023-06-01T08:40:19Z")

</div>

I have configured filebeat netflow.yml to receive netflow data my filebeat.yml input filebeat.inputs: # filestream is an input for collecting log messages from files. - type: filestream # Unique ID among all inputs…

---

## [Filebeat process different log paths and write data to seperate index,Without use of logstash and follow ILM/rollover alias defined in template](https://discuss.elastic.co/t/filebeat-process-different-log-paths-and-write-data-to-seperate-index-without-use-of-logstash-and-follow-ilm-rollover-alias-defined-in-template/332593)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 17\
**Last updated:** [June 1, 2023, 7:12am UTC](https://discuss.elastic.co/t/filebeat-process-different-log-paths-and-write-data-to-seperate-index-without-use-of-logstash-and-follow-ilm-rollover-alias-defined-in-template/332593 "2023-06-01T07:12:46Z")

</div>

Hello All, I've a requirement where I will be having diffrent log path defined in server and Filebeat will read this paths and should write the data to there respective elastic index. The ILM policy and required rollo…

---

## [Issue with Inaccurate Traffic Statistics in Packetbeat](https://discuss.elastic.co/t/issue-with-inaccurate-traffic-statistics-in-packetbeat/334891)

<div class="topic-metadata">

**Author:** [@Yongb\_Xu](https://discuss.elastic.co/u/Yongb_Xu)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 1:57am UTC](https://discuss.elastic.co/t/issue-with-inaccurate-traffic-statistics-in-packetbeat/334891 "2023-06-01T01:57:53Z")

</div>

Hi everyone, I'm working on a project that requires the use of Elastic + Packetbeat for network traffic statistics. I have set up my environment with Elastic, Packetbeat, and Kibana all installed on a single virtual mac…

---

## [After a folder is deleted and recreated, file\_integrity events are missing until service restart](https://discuss.elastic.co/t/after-a-folder-is-deleted-and-recreated-file-integrity-events-are-missing-until-service-restart/334873)

<div class="topic-metadata">

**Author:** [@James\_Nelson1](https://discuss.elastic.co/u/James_Nelson1)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 9:30pm UTC](https://discuss.elastic.co/t/after-a-folder-is-deleted-and-recreated-file-integrity-events-are-missing-until-service-restart/334873 "2023-05-31T21:30:05Z")

</div>

We're still on v7.17.x of auditbeat on CentOS, but I think this applies across versions. Say we are using the file\_integrity module for these paths: - /apps - /apps/myapp When the directory /apps/myapp is deleted and r…

---

## [How to add logging integration for getting filebeat logs in kibana dashboard](https://discuss.elastic.co/t/how-to-add-logging-integration-for-getting-filebeat-logs-in-kibana-dashboard/332553)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 16\
**Last updated:** [May 31, 2023, 8:26pm UTC](https://discuss.elastic.co/t/how-to-add-logging-integration-for-getting-filebeat-logs-in-kibana-dashboard/332553 "2023-05-31T20:26:46Z")

</div>

We are not getting the logs as filebeat is not configured, so please help me in logging integration for kibana dashboard

---

## [Ndjson parser doesn't expand keys if target is set](https://discuss.elastic.co/t/ndjson-parser-doesnt-expand-keys-if-target-is-set/334799)

<div class="topic-metadata">

**Author:** [@anon68795679](https://discuss.elastic.co/u/anon68795679)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:13pm UTC](https://discuss.elastic.co/t/ndjson-parser-doesnt-expand-keys-if-target-is-set/334799 "2023-05-31T13:13:05Z")

</div>

Hi, it seems that there is the same issue with the ndjson parser like in the decode\_json\_fields processor some time ago: Expand fields in \`decode\_json\_fields\` if target is set by kvch · Pull Request #32010 · elastic/bea…

---

## [Heartbeat parsing JSON object for HTTP monitor failure](https://discuss.elastic.co/t/heartbeat-parsing-json-object-for-http-monitor-failure/334335)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:05pm UTC](https://discuss.elastic.co/t/heartbeat-parsing-json-object-for-http-monitor-failure/334335 "2023-05-31T13:05:18Z")

</div>

hey there, I am using Heartbeat 8.x and according to I was trying to check the Sendgrid SMTP service using the public url https://status.sendgrid.com/api/v2/components.json Using this code: - type: http id: sendgr…

---

## [Elastic-agent failed to enroll due to TLS access denied alert](https://discuss.elastic.co/t/elastic-agent-failed-to-enroll-due-to-tls-access-denied-alert/334699)

<div class="topic-metadata">

**Author:** [@kmahyyg](https://discuss.elastic.co/u/kmahyyg)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 10:18am UTC](https://discuss.elastic.co/t/elastic-agent-failed-to-enroll-due-to-tls-access-denied-alert/334699 "2023-05-31T10:18:09Z")

</div>

This is a really interesting issue. Code related: elastic-agent/client.go at cda5b7e75d080c6be9e9220dfa607c145cf598b4 · elastic/elastic-agent · GitHub I've using self-signed CA to deploy elastic-agent in internal envir…

---

## [How Filebeat is configured with ELK](https://discuss.elastic.co/t/how-filebeat-is-configured-with-elk/332496)

<div class="topic-metadata">

**Author:** [@SalmaShaik](https://discuss.elastic.co/u/SalmaShaik)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 12:12am UTC](https://discuss.elastic.co/t/how-filebeat-is-configured-with-elk/332496 "2023-05-31T00:12:26Z")

</div>

Hi, How filebeat is configured with ELK. How filebeat is used to get logs from the servers in the Kibana dashboard. I want to know about these questions can anyone clarify me?

---

## [Kubernetes beats deployment yaml syntax error linked from support documents to GitHub](https://discuss.elastic.co/t/kubernetes-beats-deployment-yaml-syntax-error-linked-from-support-documents-to-github/334722)

<div class="topic-metadata">

**Author:** [@AndrewDatTeranet](https://discuss.elastic.co/u/AndrewDatTeranet)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 10:15pm UTC](https://discuss.elastic.co/t/kubernetes-beats-deployment-yaml-syntax-error-linked-from-support-documents-to-github/334722 "2023-05-30T22:15:52Z")

</div>

I believe there is a syntax error in the daemonset configuration in all the beats example/refrence yaml's in the elastic beats repo on GitHub. see below for the issue with the filbeat config (though it looks like that s…

---

## [Events get dropped by restricting api key (winlogbeat & kibana) - Help plz](https://discuss.elastic.co/t/events-get-dropped-by-restricting-api-key-winlogbeat-kibana-help-plz/329403)

<div class="topic-metadata">

**Author:** [@Martesch](https://discuss.elastic.co/u/Martesch)\
**Replies:** 5\
**Last updated:** [May 30, 2023, 2:23pm UTC](https://discuss.elastic.co/t/events-get-dropped-by-restricting-api-key-winlogbeat-kibana-help-plz/329403 "2023-05-30T14:23:45Z")

</div>

hello everyone i need help. this is about the fact that i noticed that in our kibana, which collects our windows event logs certain logs are missing, and this since a certain date, from 31.01.23 to 01.02.23 the amount o…

---

## [Filebeat unable to find match for dissect pattern](https://discuss.elastic.co/t/filebeat-unable-to-find-match-for-dissect-pattern/333856)

<div class="topic-metadata">

**Author:** [@obol89](https://discuss.elastic.co/u/obol89)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 1:38pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-find-match-for-dissect-pattern/333856 "2023-05-30T13:38:03Z")

</div>

Hi Everyone, I couldn't find a reason, why Filebeat is going into the loop with "Unable to find match for dissect pattern" when it reaches the end of the file with filestream input mode. I'm parsing multiple very simila…

---

## [Insecure param does not complete disable verification](https://discuss.elastic.co/t/insecure-param-does-not-complete-disable-verification/334673)

<div class="topic-metadata">

**Author:** [@kmahyyg](https://discuss.elastic.co/u/kmahyyg)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 10:49am UTC](https://discuss.elastic.co/t/insecure-param-does-not-complete-disable-verification/334673 "2023-05-30T10:49:44Z")

</div>

I use --insecure when enrolling agent into fleet server in development environment. With some unable-to-say restrictions, this development environment cannot connect to CRL server. However, in current environment, the c…

---

## [Netflow from some Huawei AR devices aren't captured](https://discuss.elastic.co/t/netflow-from-some-huawei-ar-devices-arent-captured/334657)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 9:13am UTC](https://discuss.elastic.co/t/netflow-from-some-huawei-ar-devices-arent-captured/334657 "2023-05-30T09:13:28Z")

</div>

I have multiple devices sending netflow towards my filebeat server and filebeat haven't captured data from some devices. These devices are Huawei AR model and even though netflow data are visible here, they seems to be m…

---

## [Filebeat autodiscover mode is flooding my kubernetes API](https://discuss.elastic.co/t/filebeat-autodiscover-mode-is-flooding-my-kubernetes-api/333648)

<div class="topic-metadata">

**Author:** [@NeVraX](https://discuss.elastic.co/u/NeVraX)\
**Replies:** 5\
**Last updated:** [May 30, 2023, 8:48am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-mode-is-flooding-my-kubernetes-api/333648 "2023-05-30T08:48:17Z")

</div>

Hello, I'm working on a managed kubernetes cluster with a cloud provider which offers limited K8S API performance (slow master nodes). I have installed filebeat 8.5.1 with the official Helm chart. They say that my fil…

---

## [MQTT Input - Default qos level?](https://discuss.elastic.co/t/mqtt-input-default-qos-level/334055)

<div class="topic-metadata">

**Author:** [@QuestBevan](https://discuss.elastic.co/u/QuestBevan)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 7:18pm UTC](https://discuss.elastic.co/t/mqtt-input-default-qos-level/334055 "2023-05-29T19:18:36Z")

</div>

Hi All, Could someone please confirm what the default value for the 'qos' setting is, within the MQTT input module. Thanks

---

## [Kafka Connection Failure](https://discuss.elastic.co/t/kafka-connection-failure/334612)

<div class="topic-metadata">

**Author:** [@varunsingla](https://discuss.elastic.co/u/varunsingla)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 6:26pm UTC](https://discuss.elastic.co/t/kafka-connection-failure/334612 "2023-05-29T18:26:37Z")

</div>

I am getting the following error when I am trying to configure output.kafka on my filebeat configuration: "log.logger":"kafka","log.origin":{"file.name":"kafka/client.go","file.line":406},"message":"Kafka publish failed…

---

## [Using Metricbeat to send Filebeat logs to ES](https://discuss.elastic.co/t/using-metricbeat-to-send-filebeat-logs-to-es/333850)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 6\
**Last updated:** [May 29, 2023, 5:43am UTC](https://discuss.elastic.co/t/using-metricbeat-to-send-filebeat-logs-to-es/333850 "2023-05-29T05:43:19Z")

</div>

Hi, I'm running both Filebeat 8.3.3 and Metricbeat 8.3.3 on my RHEL 7.9 server, and sending the logs to another server which is hosting Elasticsearch and Kibana. My filebeat is sending syslog to the ES (I'm simply usin…

---

## [Part of the file bit 'daemonset pod' is CrashLoopBackOff](https://discuss.elastic.co/t/part-of-the-file-bit-daemonset-pod-is-crashloopbackoff/334261)

<div class="topic-metadata">

**Author:** [@oliverpark999](https://discuss.elastic.co/u/oliverpark999)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 12:52am UTC](https://discuss.elastic.co/t/part-of-the-file-bit-daemonset-pod-is-crashloopbackoff/334261 "2023-05-29T00:52:13Z")

</div>

I configured Filebeat + Logstash in Kubernetes environment. It is working normally, but some of the Filebeat 'demonsets' do not appear to be working normally. What kind of problem? filebeat-1 1/1 Runn…

---

## [filebeat:Frequently occurring "should have been dropped, but couldn't as state is not finished"](https://discuss.elastic.co/t/filebeat-frequently-occurring-should-have-been-dropped-but-couldnt-as-state-is-not-finished/334497)

<div class="topic-metadata">

**Author:** [@micmeow](https://discuss.elastic.co/u/micmeow)\
**Replies:** 1\
**Last updated:** [May 27, 2023, 10:25am UTC](https://discuss.elastic.co/t/filebeat-frequently-occurring-should-have-been-dropped-but-couldnt-as-state-is-not-finished/334497 "2023-05-27T10:25:21Z")

</div>

Hello. If you know how fix that, lend me your wisdom. I use filebeat to transfer logs to Logstash to Opensearch. When I checked the filebeat log, I found that the same log file transfer errors were occurring frequently…

---

## [How can I extract a sub-field from a field and print it as a separate field in filebeat?](https://discuss.elastic.co/t/how-can-i-extract-a-sub-field-from-a-field-and-print-it-as-a-separate-field-in-filebeat/334103)

<div class="topic-metadata">

**Author:** [@varunsingla](https://discuss.elastic.co/u/varunsingla)\
**Replies:** 9\
**Last updated:** [May 26, 2023, 5:46pm UTC](https://discuss.elastic.co/t/how-can-i-extract-a-sub-field-from-a-field-and-print-it-as-a-separate-field-in-filebeat/334103 "2023-05-26T17:46:03Z")

</div>

"msg":"{"appName":"abc","eventCategory":"Authentication event","eventType":"Operator record change","id":"12345","ipAddress":"0.0.1.1","nodeID":"nodeabc","operation":"update","operatorID":"admin","operatorRecID":"DATAADM…

---

## [Beats Agent Documentation Incorrect on base image used](https://discuss.elastic.co/t/beats-agent-documentation-incorrect-on-base-image-used/334452)

<div class="topic-metadata">

**Author:** [@lgst1997](https://discuss.elastic.co/u/lgst1997)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 3:50pm UTC](https://discuss.elastic.co/t/beats-agent-documentation-incorrect-on-base-image-used/334452 "2023-05-26T15:50:51Z")

</div>

Documentation in the beats agent shows that the docker base image os is CentOS 7 but its actually Ubuntu. This issue is also present in the v7.17.10 documentation. Ex: Run Filebeat on Docker | Filebeat Reference \[8.8\] |…

---

## [Filebeat connection vers Elasticsearch](https://discuss.elastic.co/t/filebeat-connection-vers-elasticsearch/334007)

<div class="topic-metadata">

**Author:** [@Lucas\_Chauvry](https://discuss.elastic.co/u/Lucas_Chauvry)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 1:38pm UTC](https://discuss.elastic.co/t/filebeat-connection-vers-elasticsearch/334007 "2023-05-26T13:38:44Z")

</div>

Bonjour, Je commence dans l'apprentissage d'ELK et je suis bloqué sur la configuration. Mon ELK fonctionne correctement, j'arrive a joindre Elasticsearch sur mon IP et le bon port. Cependant, lors de la configuration …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=46)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=48)
