# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=50

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 51

---

## [Metricbeat, MSSQL module, TLS Handshake failed unsupported protocol version 301](https://discuss.elastic.co/t/metricbeat-mssql-module-tls-handshake-failed-unsupported-protocol-version-301/332651)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [May 5, 2023, 1:11pm UTC](https://discuss.elastic.co/t/metricbeat-mssql-module-tls-handshake-failed-unsupported-protocol-version-301/332651 "2023-05-05T13:11:21Z")

</div>

Hi, Im getting this error when remotly monitoring a MSSQL database: ERROR instance/beat.go:1014 Exiting: 2 errors: could not create connection to db: error doing ping to db: TLS Handshake failed: tls: server select…

---

## [Creating a new beat but can't see proper output](https://discuss.elastic.co/t/creating-a-new-beat-but-cant-see-proper-output/332645)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 0\
**Last updated:** [May 5, 2023, 12:00pm UTC](https://discuss.elastic.co/t/creating-a-new-beat-but-cant-see-proper-output/332645 "2023-05-05T12:00:35Z")

</div>

Hello i'm new here so if i say something wrong please let me know. I was trying to make a new beat that collects k6 metrics via rest api and then send them into Elasticsearch. I follow the 7.17 Dev Guide " Creating a Bea…

---

## [Add\_kubernetes\_metadata intermittent failure](https://discuss.elastic.co/t/add-kubernetes-metadata-intermittent-failure/332609)

<div class="topic-metadata">

**Author:** [@hamishforbes](https://discuss.elastic.co/u/hamishforbes)\
**Replies:** 0\
**Last updated:** [May 5, 2023, 3:35am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-intermittent-failure/332609 "2023-05-05T03:35:47Z")

</div>

It looks like under some conditions filebeat on Kubernetes is failing to add metadata. I think there's a race here between the log harvester picking up new container logs and the kubernetes pod watcher populating the me…

---

## [Filebeat log processing out of sync (not ordered by timestamp)](https://discuss.elastic.co/t/filebeat-log-processing-out-of-sync-not-ordered-by-timestamp/332577)

<div class="topic-metadata">

**Author:** [@pavank](https://discuss.elastic.co/u/pavank)\
**Replies:** 0\
**Last updated:** [May 4, 2023, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-log-processing-out-of-sync-not-ordered-by-timestamp/332577 "2023-05-04T15:18:45Z")

</div>

Hi there, We are using Filebeat and Logstash to collect container logs from our OCP clusters, where we have deployed Filebeat as a daemonset and Logstash is running on a VM. The logs are then routed to Azure Log Analyti…

---

## [Filebeat error while parsing multiline parser config](https://discuss.elastic.co/t/filebeat-error-while-parsing-multiline-parser-config/331089)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [May 4, 2023, 2:47pm UTC](https://discuss.elastic.co/t/filebeat-error-while-parsing-multiline-parser-config/331089 "2023-05-04T14:47:05Z")

</div>

I am using Filebeat 8.7. I am trying to follow the instructions here: I double checked the indentation. Cannot figure out what is wrong. I just want to make sure a multi-line stack trace is captured into one docume…

---

## [Cert error for intial setup of fileBeat](https://discuss.elastic.co/t/cert-error-for-intial-setup-of-filebeat/329997)

<div class="topic-metadata">

**Author:** [@Nibort](https://discuss.elastic.co/u/Nibort)\
**Replies:** 2\
**Last updated:** [May 4, 2023, 12:27pm UTC](https://discuss.elastic.co/t/cert-error-for-intial-setup-of-filebeat/329997 "2023-05-04T12:27:18Z")

</div>

Hello, I've followed the documention to connect client with filebeat to elasticsearch : Filebeat quick start: installation and configuration | Filebeat Reference \[8.7\] | Elastic My filebeat.yml # ---------------------…

---

## [Elastic Agent fails to read io.stat file with more than one $MAJ:$MIN device number](https://discuss.elastic.co/t/elastic-agent-fails-to-read-io-stat-file-with-more-than-one-maj-min-device-number/330026)

<div class="topic-metadata">

**Author:** [@vitalyrychkov](https://discuss.elastic.co/u/vitalyrychkov)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 2:46pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-to-read-io-stat-file-with-more-than-one-maj-min-device-number/330026 "2023-04-14T14:46:37Z")

</div>

We have a cluster with multiple VM nodes and a physical node, let's say "PH". The physical node has attached network storage with the multi-path option enabled. When elastic-agent (8.7.0) daemonset is deployed in this cl…

---

## [Winlogbeat "channel not found error" floods log](https://discuss.elastic.co/t/winlogbeat-channel-not-found-error-floods-log/332304)

<div class="topic-metadata">

**Author:** [@C0FFEEC0FFEE](https://discuss.elastic.co/u/C0FFEEC0FFEE)\
**Replies:** 2\
**Last updated:** [May 4, 2023, 7:58am UTC](https://discuss.elastic.co/t/winlogbeat-channel-not-found-error-floods-log/332304 "2023-05-04T07:58:56Z")

</div>

Since https://github.com/elastic/beats/pull/34605, the winlogbeat logfile is flooded with "channel not found" errors if a non-existent channel is configured in winlogbeat.yml. For each channel which isn't found, this er…

---

## [Kibana dashboard is healthy , even filebeat service is stopped](https://discuss.elastic.co/t/kibana-dashboard-is-healthy-even-filebeat-service-is-stopped/332228)

<div class="topic-metadata">

**Author:** [@SalmaShaik](https://discuss.elastic.co/u/SalmaShaik)\
**Replies:** 4\
**Last updated:** [May 4, 2023, 5:53am UTC](https://discuss.elastic.co/t/kibana-dashboard-is-healthy-even-filebeat-service-is-stopped/332228 "2023-05-04T05:53:33Z")

</div>

Hi, Filebeat service is not running. But the kibana Dasboard shows as healthy in Elasticsearch Vm's and their respective nodes. Can anyone help me.

---

## [Encoded data in message field using filebeat filestream input](https://discuss.elastic.co/t/encoded-data-in-message-field-using-filebeat-filestream-input/330907)

<div class="topic-metadata">

**Author:** [@Ryan\_Clark](https://discuss.elastic.co/u/Ryan_Clark)\
**Replies:** 3\
**Last updated:** [May 3, 2023, 8:16pm UTC](https://discuss.elastic.co/t/encoded-data-in-message-field-using-filebeat-filestream-input/330907 "2023-05-03T20:16:35Z")

</div>

I'm using filebeat to read in a multiline log. I'm able to get the data into elasticsearch with the multiline event stored into the message field. Log Sample: Date: Wed Apr 19 09:57:45 2023 Computer Name: SystemX User…

---

## [Filebeat JSON Parsing](https://discuss.elastic.co/t/filebeat-json-parsing/331023)

<div class="topic-metadata">

**Author:** [@Tussingh](https://discuss.elastic.co/u/Tussingh)\
**Replies:** 1\
**Last updated:** [May 3, 2023, 2:43pm UTC](https://discuss.elastic.co/t/filebeat-json-parsing/331023 "2023-05-03T14:43:55Z")

</div>

I am trying to ingest below JSON to elastic through filebeat http json input plugin. \[ { "metricId": 185016812, "metricName": "BTM|Application Diagnostic Data|Base Page:20869077|Synthetic Visually Complete Time (ms)"…

---

## [Issue to read logs from radsecproxy](https://discuss.elastic.co/t/issue-to-read-logs-from-radsecproxy/332204)

<div class="topic-metadata">

**Author:** [@Ayah](https://discuss.elastic.co/u/Ayah)\
**Replies:** 2\
**Last updated:** [May 3, 2023, 10:21am UTC](https://discuss.elastic.co/t/issue-to-read-logs-from-radsecproxy/332204 "2023-05-03T10:21:31Z")

</div>

Hello, we have implemented ELK to visualize eduroam log from radsecproxy. Our system was developed following this guideline GitHub - REANNZ/etcbd-public: eduroam tools container-based deployment - public tools it was w…

---

## [Filebeat installation on AIX servers](https://discuss.elastic.co/t/filebeat-installation-on-aix-servers/332026)

<div class="topic-metadata">

**Author:** [@ryanamadala](https://discuss.elastic.co/u/ryanamadala)\
**Replies:** 2\
**Last updated:** [May 3, 2023, 3:22am UTC](https://discuss.elastic.co/t/filebeat-installation-on-aix-servers/332026 "2023-05-03T03:22:12Z")

</div>

Need some help for installing Filebeat agents on AIX servers. Machine details: System Model: IBM,9040-MR9 Processor Type: PowerPC\_POWER9 Processor Implementation Mode: POWER 9 Platform Firmware level: VM940\_050

---

## [System.process.cpu.total.norm.pct is always zero, metricbeat 7.17.9](https://discuss.elastic.co/t/system-process-cpu-total-norm-pct-is-always-zero-metricbeat-7-17-9/332346)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [May 2, 2023, 9:49pm UTC](https://discuss.elastic.co/t/system-process-cpu-total-norm-pct-is-always-zero-metricbeat-7-17-9/332346 "2023-05-02T21:49:20Z")

</div>

Hi, Im using system module of metricbeat and process metricset, this is the configuration - module: system period: 300s metricsets: - cpu - memory - network - process system.process.cpu.total.norm.p…

---

## [Filebeat: permission denied](https://discuss.elastic.co/t/filebeat-permission-denied/330592)

<div class="topic-metadata">

**Author:** [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Replies:** 6\
**Last updated:** [May 2, 2023, 4:33pm UTC](https://discuss.elastic.co/t/filebeat-permission-denied/330592 "2023-05-02T16:33:15Z")

</div>

Hi all! Need your help in solving the problem: Unexpected file opening error: "Failed opening /mnt/var/log/auth.log: open /mnt/var/log/auth.log: permission denied" My environment: docker-compose filebeat:8.7.0 user …

---

## [Cluster with packetbeat](https://discuss.elastic.co/t/cluster-with-packetbeat/330929)

<div class="topic-metadata">

**Author:** [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)\
**Replies:** 16\
**Last updated:** [May 2, 2023, 10:21am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929 "2023-05-02T10:21:24Z")

</div>

Hello, I'm trying to form a cluster and in this cluster I want to add several nodes and install packtbeat on each node. But when I do that, the data sent from packtbeat is shared across the entire cluster. Is there any w…

---

## [Auditbeat btmp file monitoring glitch (saved size or offset illogical)](https://discuss.elastic.co/t/auditbeat-btmp-file-monitoring-glitch-saved-size-or-offset-illogical/332037)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 6:47pm UTC](https://discuss.elastic.co/t/auditbeat-btmp-file-monitoring-glitch-saved-size-or-offset-illogical/332037 "2023-05-01T18:47:55Z")

</div>

Hi, I have auditbeat 7.17.8 installed on an RHEL 7 system. RHEL7 rotates out the BTMP file out at the start of every month. So, starting today I am seeing the following message every few seconds in syslog: May 1 12:…

---

## [FileBeat 7.x ARM32 based Image](https://discuss.elastic.co/t/filebeat-7-x-arm32-based-image/331865)

<div class="topic-metadata">

**Author:** [@Kamesh\_Pratapa](https://discuss.elastic.co/u/Kamesh_Pratapa)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 5:31pm UTC](https://discuss.elastic.co/t/filebeat-7-x-arm32-based-image/331865 "2023-05-01T17:31:20Z")

</div>

Hi, I am unable to locate the filebeat and metric beat ARM 32bit architecture based image in the official download location. Can someone help me to point the location ? Regards, Kamesh.

---

## [Filebeat kubernetes unable to format json logs into fields](https://discuss.elastic.co/t/filebeat-kubernetes-unable-to-format-json-logs-into-fields/330795)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 2\
**Last updated:** [May 1, 2023, 5:48am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-unable-to-format-json-logs-into-fields/330795 "2023-05-01T05:48:55Z")

</div>

Hello, i want to ingested containers json log data using filebeat deployed on kubernetes, i am able to ingest the logs to but i am unable to format the json logs in to fields following is the logs visible in kibana …

---

## [When is filebeat 8.7.1 available for download](https://discuss.elastic.co/t/when-is-filebeat-8-7-1-available-for-download/331091)

<div class="topic-metadata">

**Author:** [@pavanrangain](https://discuss.elastic.co/u/pavanrangain)\
**Replies:** 2\
**Last updated:** [April 29, 2023, 7:23am UTC](https://discuss.elastic.co/t/when-is-filebeat-8-7-1-available-for-download/331091 "2023-04-29T07:23:59Z")

</div>

Saw this a few days back - Beats version 8.7.1 | Beats Platform Reference \[8.7\] | Elastic But there is no release artifacts present for downloading. When can we expect them to be available ?

---

## [Filebeat not harvesting newly added records](https://discuss.elastic.co/t/filebeat-not-harvesting-newly-added-records/330603)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 4:52pm UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-newly-added-records/330603 "2023-04-28T16:52:29Z")

</div>

Hi,I have a filebeat which is running on windows server 2019.The data is actively getting written to that log file but it's timestamp changes every 30 mins.I trying to reading log file,but for some reason the newly added…

---

## [Importing third party filebeat dashboard into Kibana (SecurityOnion)](https://discuss.elastic.co/t/importing-third-party-filebeat-dashboard-into-kibana-securityonion/331076)

<div class="topic-metadata">

**Author:** [@KhemaisKebaili](https://discuss.elastic.co/u/KhemaisKebaili)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 4:31pm UTC](https://discuss.elastic.co/t/importing-third-party-filebeat-dashboard-into-kibana-securityonion/331076 "2023-04-28T16:31:26Z")

</div>

I have a SecurityOnion instance that's hosting an ELK 8.6.1 stack. I enabled the threat intelligence module and I have data coming in and could be visualized using the discovery tool. However , and from my research, when…

---

## [Huge logs - how Tuning filebeat](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 5\
**Last updated:** [April 28, 2023, 12:58pm UTC](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333 "2023-04-28T12:58:35Z")

</div>

Hi everybody, I'm french and i m a very newbie with elasticsearch. Elasticsearch version imposed by security team : 7.10.2 I create a cluster like this with dedicate nodes: 2 master node 1 master only eligible node 1…

---

## [2 instances of Filebeat on same Linux server output to same ES](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 3\
**Last updated:** [April 28, 2023, 9:15am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010 "2023-04-28T09:15:09Z")

</div>

Hi, I have a Linux server running Filebeat 8.3.3 taking Netflow as input and writing it out to ES on another server. As the Netflow load is much more than what Filebeat can handle, I'm thinking of splitting the Netflow …

---

## [Take\_over option not working - logs being reharvested after filebeat restart](https://discuss.elastic.co/t/take-over-option-not-working-logs-being-reharvested-after-filebeat-restart/330983)

<div class="topic-metadata">

**Author:** [@ian.springer-sf](https://discuss.elastic.co/u/ian.springer-sf)\
**Replies:** 5\
**Last updated:** [April 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/take-over-option-not-working-logs-being-reharvested-after-filebeat-restart/330983 "2023-04-27T18:45:35Z")

</div>

I followed the migration guide to migrate my log inputs to filestream inputs, including adding a unique id and setting the "take\_over" option to true. However, upon restarting the filebeat service, all of the logs are re…

---

## [Filebeat Module Postgresql](https://discuss.elastic.co/t/filebeat-module-postgresql/330860)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 8\
**Last updated:** [April 27, 2023, 5:04pm UTC](https://discuss.elastic.co/t/filebeat-module-postgresql/330860 "2023-04-27T17:04:25Z")

</div>

Hello everyone, Please I need your help, I have problems with the Postgresql module filbeat, at the time of viewing the log I see that I get the following error message: \[2023-04-26 09:20:02.534 -05 \[2828024\] u\_sistema…

---

## [Collect logs from multiple machine, what needs to be installed?](https://discuss.elastic.co/t/collect-logs-from-multiple-machine-what-needs-to-be-installed/330833)

<div class="topic-metadata">

**Author:** [@Jay\_Timbadia](https://discuss.elastic.co/u/Jay_Timbadia)\
**Replies:** 5\
**Last updated:** [April 27, 2023, 1:53pm UTC](https://discuss.elastic.co/t/collect-logs-from-multiple-machine-what-needs-to-be-installed/330833 "2023-04-27T13:53:56Z")

</div>

Continuing the discussion from How to collect the logs from multiple machines to my server efficiently?: Hi @jsoriano, really followed the chat. Just one thing, I have logs placed in different machine, so should I insta…

---

## [Updating Custom HTTP ingestion results in a 504 error](https://discuss.elastic.co/t/updating-custom-http-ingestion-results-in-a-504-error/330879)

<div class="topic-metadata">

**Author:** [@chenderson](https://discuss.elastic.co/u/chenderson)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 9:46am UTC](https://discuss.elastic.co/t/updating-custom-http-ingestion-results-in-a-504-error/330879 "2023-04-27T09:46:27Z")

</div>

I have added an integration to my stack running in Azure Kubernetes using the "Custom HTTP" integration. When I first create the integration everything works as expected and documents are ingested when I send them to th…

---

## [Elastic Stack with Chain of certificates](https://discuss.elastic.co/t/elastic-stack-with-chain-of-certificates/330265)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 5:52pm UTC](https://discuss.elastic.co/t/elastic-stack-with-chain-of-certificates/330265 "2023-04-26T17:52:06Z")

</div>

I want to enable Security when using Filebeat and Logstash. I have created a Root CA. This Root Certificate creates an Intermediate CA. The intermediate CA is then used to create and sign my client and sever certificates…

---

## [Filebeat log format](https://discuss.elastic.co/t/filebeat-log-format/330801)

<div class="topic-metadata">

**Author:** [@evanzhang87](https://discuss.elastic.co/u/evanzhang87)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-log-format/330801 "2023-04-26T14:16:18Z")

</div>

Hello, I'm using latest beats, but my log format is json, {"log.level":"info","@timestamp":"2023-04-26T15:59:22.412+0800","log.origin":{"file.name":"instance/beat.go","file.line":779},"message":"Home path: \[/Users/evan/…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=49)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=51)
