# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=49

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 50

---

## [Mulitple Filebeat Instances](https://discuss.elastic.co/t/mulitple-filebeat-instances/330792)

<div class="topic-metadata">

**Author:** [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 12:44pm UTC](https://discuss.elastic.co/t/mulitple-filebeat-instances/330792 "2023-05-16T12:44:24Z")

</div>

Hello, i did setup two filebeat instances on a linux server. One for Syslog and the PANW-Module and the other for the F5-Module. The Syslog/PANW Filebeat was the first one, i did change the index to a different one, bu…

---

## [\[macOS 10.15.7\] Cannot execute filebeat, auditbeat, or metricbeat](https://discuss.elastic.co/t/macos-10-15-7-cannot-execute-filebeat-auditbeat-or-metricbeat/333471)

<div class="topic-metadata">

**Author:** [@Coolgum15](https://discuss.elastic.co/u/Coolgum15)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 11:32am UTC](https://discuss.elastic.co/t/macos-10-15-7-cannot-execute-filebeat-auditbeat-or-metricbeat/333471 "2023-05-16T11:32:05Z")

</div>

Cannot run any of these beats. Same error for all of them (below). Using default configuration, except outputting to logstash server. The logstash server is functional, and my Linux beats are outputting to it just fine. …

---

## [Filebeat CPU and RAM utilization are all over the place](https://discuss.elastic.co/t/filebeat-cpu-and-ram-utilization-are-all-over-the-place/333430)

<div class="topic-metadata">

**Author:** [@Elay17](https://discuss.elastic.co/u/Elay17)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 10:00am UTC](https://discuss.elastic.co/t/filebeat-cpu-and-ram-utilization-are-all-over-the-place/333430 "2023-05-16T10:00:14Z")

</div>

I am currently running ECK 8.6.1 on a bare metal cluster, but I'm experiencing some issues with Filebeats. Depending on the configuration, it either leaks RAM or utilizes an excessive amount of CPU. Here is the configura…

---

## [Error Failed to start crawler: starting input failed: error while initializing input: you must choose between TCP or UDP](https://discuss.elastic.co/t/error-failed-to-start-crawler-starting-input-failed-error-while-initializing-input-you-must-choose-between-tcp-or-udp/333014)

<div class="topic-metadata">

**Author:** [@Mauricio\_Martinez](https://discuss.elastic.co/u/Mauricio_Martinez)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 5:08am UTC](https://discuss.elastic.co/t/error-failed-to-start-crawler-starting-input-failed-error-while-initializing-input-you-must-choose-between-tcp-or-udp/333014 "2023-05-16T05:08:44Z")

</div>

related with the same solution of this post: Filebeat tcp and Udp error I have a questions, if i want to use as input a syslog from another server in that i can't installing something due impacts in the performance, but…

---

## [Filebeat - last update time of log file](https://discuss.elastic.co/t/filebeat-last-update-time-of-log-file/333511)

<div class="topic-metadata">

**Author:** [@dunowhat](https://discuss.elastic.co/u/dunowhat)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 1:11am UTC](https://discuss.elastic.co/t/filebeat-last-update-time-of-log-file/333511 "2023-05-16T01:11:05Z")

</div>

hi there, i am newbie to beats world. can i use filebeat to monitor a logfile updation and send an alert/event if the file is not updated like last 15 mins? if yes, please guide me on parameters

---

## [WinlogBeat stuck @ "Stopping" / Windows-Service](https://discuss.elastic.co/t/winlogbeat-stuck-stopping-windows-service/332879)

<div class="topic-metadata">

**Author:** [@florianmulatz](https://discuss.elastic.co/u/florianmulatz)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 11:38pm UTC](https://discuss.elastic.co/t/winlogbeat-stuck-stopping-windows-service/332879 "2023-05-15T23:38:44Z")

</div>

Good Morning guys - please don't blame me if this topic is already covered somewhere - at least I was not able to find it. I've the problem that my winlogbeat Service (as well as the manually spawned process) never stop…

---

## [Missing logs in k8s](https://discuss.elastic.co/t/missing-logs-in-k8s/333487)

<div class="topic-metadata">

**Author:** [@spi\_nik](https://discuss.elastic.co/u/spi_nik)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 4:15pm UTC](https://discuss.elastic.co/t/missing-logs-in-k8s/333487 "2023-05-15T16:15:57Z")

</div>

Hello. I've issue with harvest logs from my cluster k8s with filebeat. In my config file I use next path: symlinks: true path: - /var/log/containers/\*-${data.kubernetes.container.id}.log But some my apps write a lot…

---

## [Cannot start filebeat with configuration file](https://discuss.elastic.co/t/cannot-start-filebeat-with-configuration-file/333338)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 19\
**Last updated:** [May 15, 2023, 2:23pm UTC](https://discuss.elastic.co/t/cannot-start-filebeat-with-configuration-file/333338 "2023-05-15T14:23:31Z")

</div>

I'm not able to start filebeat with below config file: filebeat.inputs: - type: filestream id: input1-id paths: - /home/yasser/data/sample1.log output.elasticsearch: hosts: \["https://localhost:9200"\] …

---

## [Logging.files.name not working in filebeat 8.7.1](https://discuss.elastic.co/t/logging-files-name-not-working-in-filebeat-8-7-1/333462)

<div class="topic-metadata">

**Author:** [@Weiyu\_Fang](https://discuss.elastic.co/u/Weiyu_Fang)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 1:06pm UTC](https://discuss.elastic.co/t/logging-files-name-not-working-in-filebeat-8-7-1/333462 "2023-05-15T13:06:50Z")

</div>

I upgraded my filebeat from 7.6 to 8.7, then I found the filebeat logs lost in my ES. I googled and found that Beats logs are now ECS compliant, which matches my situation where the logs name is like filebeat-20230515.nd…

---

## [Import CSV with date fields not usable as timestamp field](https://discuss.elastic.co/t/import-csv-with-date-fields-not-usable-as-timestamp-field/333373)

<div class="topic-metadata">

**Author:** [@Vortex\_SLT](https://discuss.elastic.co/u/Vortex_SLT)\
**Replies:** 6\
**Last updated:** [May 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/import-csv-with-date-fields-not-usable-as-timestamp-field/333373 "2023-05-14T20:02:32Z")

</div>

Hello, I'm currently try to use a date fields imported form a CVS via filebeat to the elasticsearch. (v 7.17.10) The field have this format : "2023-03-07 15:19:11" and I would like to use it as timestamp field. I trie…

---

## [Winlogbeat 8.4.3 "Start-Service winlogbeat" error](https://discuss.elastic.co/t/winlogbeat-8-4-3-start-service-winlogbeat-error/331532)

<div class="topic-metadata">

**Author:** [@Banuka\_In\_A\_Shoe](https://discuss.elastic.co/u/Banuka_In_A_Shoe)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 4:13am UTC](https://discuss.elastic.co/t/winlogbeat-8-4-3-start-service-winlogbeat-error/331532 "2023-05-15T04:13:31Z")

</div>

Hello, I'm installing winlogbeat on a windows server 2019 machine. I'm fairly certain the config files are ok as the following commands output a positive response. (Also my file/audit/metrics run fine on Linux) .\\winl…

---

## [Does filebeat support ordered pubsub?](https://discuss.elastic.co/t/does-filebeat-support-ordered-pubsub/332835)

<div class="topic-metadata">

**Author:** [@iFamZ](https://discuss.elastic.co/u/iFamZ)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:38pm UTC](https://discuss.elastic.co/t/does-filebeat-support-ordered-pubsub/332835 "2023-05-14T23:38:47Z")

</div>

I am working on a project that sends events (two types - open and closed) to an ordered pubsub (verified that the subscription is ordered with an ordering key). I am then consuming this data from the pubsub into my elast…

---

## [Configuring the same source container twice](https://discuss.elastic.co/t/configuring-the-same-source-container-twice/333258)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 6\
**Last updated:** [May 13, 2023, 3:58pm UTC](https://discuss.elastic.co/t/configuring-the-same-source-container-twice/333258 "2023-05-13T15:58:15Z")

</div>

Hi, I need to filter events coming from the same source in filebeat level and tag them (filtred not filtred for ex) before sending them to logstash. And I wonder if there is some options to duplicate events (like clone…

---

## [Multithreading in Kafka input plugin for Filebeat](https://discuss.elastic.co/t/multithreading-in-kafka-input-plugin-for-filebeat/333309)

<div class="topic-metadata">

**Author:** [@Hichem](https://discuss.elastic.co/u/Hichem)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/multithreading-in-kafka-input-plugin-for-filebeat/333309 "2023-05-12T13:33:11Z")

</div>

I'm using the Filebeat Kafka input plugin to consume data from Kafka and send it to Elastic. I noticed Filebeat starts 1 consumer thread only. Is there a way to increase the number of consumers? I tried changing the ma…

---

## [Abbreviation CST timezone issue when use postgresql filebeat module](https://discuss.elastic.co/t/abbreviation-cst-timezone-issue-when-use-postgresql-filebeat-module/333251)

<div class="topic-metadata">

**Author:** [@yanhj93](https://discuss.elastic.co/u/yanhj93)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:29am UTC](https://discuss.elastic.co/t/abbreviation-cst-timezone-issue-when-use-postgresql-filebeat-module/333251 "2023-05-12T03:29:09Z")

</div>

filebeat.modules: - module: postgresql log: enabled: true var.paths: \["/data/pgdata/pg\_log/\*.log"\] input: tags: "server" processors: - drop\_fields: …

---

## [How to interpret CPU and memory stats?](https://discuss.elastic.co/t/how-to-interpret-cpu-and-memory-stats/332976)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 3:29pm UTC](https://discuss.elastic.co/t/how-to-interpret-cpu-and-memory-stats/332976 "2023-05-11T15:29:38Z")

</div>

Hi! Filebeat logs metric stats in its log file, I am wondering what CPU and memstat mean. Do these show CPU and memory utilization of the beat on the server? Adding a sample for reference. 2023-05-05T10:26:56.954Z …

---

## [Filestream id](https://discuss.elastic.co/t/filestream-id/333075)

<div class="topic-metadata">

**Author:** [@haralambop](https://discuss.elastic.co/u/haralambop)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:51pm UTC](https://discuss.elastic.co/t/filestream-id/333075 "2023-05-11T13:51:19Z")

</div>

I have several filestream inputs type: filestream id: filestream1 type: filestream id: filestream2 type: filestream id: filestream3 How can I inserts the Ids ( filestream1,filestream2,filestream3) in the e…

---

## [Filebeat.yml config file permissions owner](https://discuss.elastic.co/t/filebeat-yml-config-file-permissions-owner/333190)

<div class="topic-metadata">

**Author:** [@lmrc](https://discuss.elastic.co/u/lmrc)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:17pm UTC](https://discuss.elastic.co/t/filebeat-yml-config-file-permissions-owner/333190 "2023-05-11T13:17:23Z")

</div>

Hello, I get an error when I start Filebeat about the permissions of the filebeat.yml file error loading config file: config file ("/etc/filebeat/filebeat.yml") can only be writable by the owner but the permissions are…

---

## [ pipeline/output.go:180  failed to publish events: client is not connected](https://discuss.elastic.co/t/pipeline-output-go-180-failed-to-publish-events-client-is-not-connected/333154)

<div class="topic-metadata">

**Author:** [@sandhya\_131](https://discuss.elastic.co/u/sandhya_131)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 5:40am UTC](https://discuss.elastic.co/t/pipeline-output-go-180-failed-to-publish-events-client-is-not-connected/333154 "2023-05-11T05:40:59Z")

</div>

Hello Everyone, I have ELK setup in kubernetes 1.23 cluster, I have filebeat in one namespace in the cluster as daemonset. For the master nodes we have filebeat deployed on the nodes while building the ami. Earlier we h…

---

## [Split large json file](https://discuss.elastic.co/t/split-large-json-file/333145)

<div class="topic-metadata">

**Author:** [@sree3](https://discuss.elastic.co/u/sree3)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 4:09am UTC](https://discuss.elastic.co/t/split-large-json-file/333145 "2023-05-11T04:09:14Z")

</div>

Hi All, Trying to split a single json file into multiple one's and then to output those single files Could someone please help to get this done Input Data is json file { "Computer": "node2", "ContainerID": "cbcf", …

---

## [How to extract custom field value from first line and add it into later lines with Filebeat](https://discuss.elastic.co/t/how-to-extract-custom-field-value-from-first-line-and-add-it-into-later-lines-with-filebeat/333140)

<div class="topic-metadata">

**Author:** [@lma\_yb](https://discuss.elastic.co/u/lma_yb)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 1:21am UTC](https://discuss.elastic.co/t/how-to-extract-custom-field-value-from-first-line-and-add-it-into-later-lines-with-filebeat/333140 "2023-05-11T01:21:27Z")

</div>

I am using filebeat to import log file which has some meta data in the first few lines into ELK. The log file format looks like this: Hostname: xxx Created: \<time\> Format: XXX ----Actual logs--- I want to extract the …

---

## [Winlogbeat 8.7.1 service crashes immediately after starting](https://discuss.elastic.co/t/winlogbeat-8-7-1-service-crashes-immediately-after-starting/332948)

<div class="topic-metadata">

**Author:** [@Mike7](https://discuss.elastic.co/u/Mike7)\
**Replies:** 6\
**Last updated:** [May 10, 2023, 2:39pm UTC](https://discuss.elastic.co/t/winlogbeat-8-7-1-service-crashes-immediately-after-starting/332948 "2023-05-10T14:39:54Z")

</div>

Hi All, On a fresh install (Server 2022) the Winlogbeat service crashes immediately after starting (when there are events in the monitored log present) or - when the log is cleared - it crashes after the first event com…

---

## [Winlogbeat doesn't drop events](https://discuss.elastic.co/t/winlogbeat-doesnt-drop-events/332557)

<div class="topic-metadata">

**Author:** [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 1:08pm UTC](https://discuss.elastic.co/t/winlogbeat-doesnt-drop-events/332557 "2023-05-10T13:08:27Z")

</div>

Hi there, How the hell are we supposed to configure winlogbeats (ecs.version : 1.6.0) to drop events ? I've tried, many, many variations, but none of them worked. - name: Security processors: - drop\_event.…

---

## [Gather logs from podman containers](https://discuss.elastic.co/t/gather-logs-from-podman-containers/333073)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 10:44am UTC](https://discuss.elastic.co/t/gather-logs-from-podman-containers/333073 "2023-05-10T10:44:40Z")

</div>

Hi, If I understand the documentation correctly the best practice for shipping logs of docker-container is the following: using container input - type: container stream: stdout paths: - "/var/log/containers/\*.…

---

## [Can not access json.orig\_bytes and json.resp\_bytes in filebeat zeek's module](https://discuss.elastic.co/t/can-not-access-json-orig-bytes-and-json-resp-bytes-in-filebeat-zeeks-module/333029)

<div class="topic-metadata">

**Author:** [@pakban3242](https://discuss.elastic.co/u/pakban3242)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 7:05am UTC](https://discuss.elastic.co/t/can-not-access-json-orig-bytes-and-json-resp-bytes-in-filebeat-zeeks-module/333029 "2023-05-10T07:05:00Z")

</div>

Hi , i want to bring zeek logs to Elasticsearch , but this two modules are not included json.orig\_bytes","json.resp\_bytes i have changed this file /usr/share/filebeat/module/zeek/connection/config/connection.yml and …

---

## [Does anyone know if Filebeat keystore is as secure as the Linux Shadow file?](https://discuss.elastic.co/t/does-anyone-know-if-filebeat-keystore-is-as-secure-as-the-linux-shadow-file/332611)

<div class="topic-metadata">

**Author:** [@danielc](https://discuss.elastic.co/u/danielc)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 2:44pm UTC](https://discuss.elastic.co/t/does-anyone-know-if-filebeat-keystore-is-as-secure-as-the-linux-shadow-file/332611 "2023-05-09T14:44:10Z")

</div>

Does anyone know if Filebeat keystore is reversible? is it as secure as the Linux Shadow file?

---

## [How to collect data in character special device like /dev/kmsg?](https://discuss.elastic.co/t/how-to-collect-data-in-character-special-device-like-dev-kmsg/332801)

<div class="topic-metadata">

**Author:** [@linrl3](https://discuss.elastic.co/u/linrl3)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 2:35am UTC](https://discuss.elastic.co/t/how-to-collect-data-in-character-special-device-like-dev-kmsg/332801 "2023-05-09T02:35:47Z")

</div>

Like the title said, how can I use filebeat to collect from character device, for example /dev/kmsg.

---

## [\[Filebeat 8.6.2\] How to add additional fileds in apache module](https://discuss.elastic.co/t/filebeat-8-6-2-how-to-add-additional-fileds-in-apache-module/332840)

<div class="topic-metadata">

**Author:** [@rohitguptaggg](https://discuss.elastic.co/u/rohitguptaggg)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 11:04pm UTC](https://discuss.elastic.co/t/filebeat-8-6-2-how-to-add-additional-fileds-in-apache-module/332840 "2023-05-08T23:04:12Z")

</div>

Hello, I am using filebeat 6.8.2 and i have enabled the apache module and trying to add some extra fields but not working i alsi tried : Add fields | Filebeat Reference \[8.7\] | Elastic but this is not working with the …

---

## [Active Directory perfmon counter in metricbeat](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 1:42pm UTC](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537 "2023-05-08T13:42:51Z")

</div>

Hi! I have two questions about Active Directory perfmon counters. I´ve created some counters based on this article: And in this article I have seen then that this syntax no longer exists: Now I'm not sure how to …

---

## [\[Packetbeat\] bpf\_filter setting does not work in packetbeat 8.x.](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622)

<div class="topic-metadata">

**Author:** [@md-irohas](https://discuss.elastic.co/u/md-irohas)\
**Replies:** 2\
**Last updated:** [May 6, 2023, 2:08am UTC](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622 "2023-05-06T02:08:17Z")

</div>

I am using packetbeat (v8.7.0) in my home network and find that the packetbeat.interfaces.bpf\_filter setting in packetbeat.yml does not work. I read the source code and find that the bpf\_filter value is not addressed co…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=48)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=50)
