# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=51

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 52

---

## [\_geoip\_database\_unavailable\_GeoLite2-ASN.mmdb](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 22\
**Last updated:** [April 26, 2023, 1:34pm UTC](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772 "2023-04-26T13:34:16Z")

</div>

Hello there, I am running packetbeat-8.4.3-amd64.deb on a node that i want to monitor and I am shiping the metrics to elastcsearch and kibana. I also added geoip data from Enrich events with geoIP information | Packetbea…

---

## [Filestream not processing new log messages](https://discuss.elastic.co/t/filestream-not-processing-new-log-messages/330830)

<div class="topic-metadata">

**Author:** [@yohny](https://discuss.elastic.co/u/yohny)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 11:40am UTC](https://discuss.elastic.co/t/filestream-not-processing-new-log-messages/330830 "2023-04-26T11:40:30Z")

</div>

Hi all, I have a filebeat configured to consume log files using filestream and send them to kibana like this: filebeat.inputs: - type: filestream id: my-stream enabled: true paths: - C:\\my-app\\log…

---

## [Use JSON as input for Packetbeat](https://discuss.elastic.co/t/use-json-as-input-for-packetbeat/330763)

<div class="topic-metadata">

**Author:** [@callamby5](https://discuss.elastic.co/u/callamby5)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 4:11am UTC](https://discuss.elastic.co/t/use-json-as-input-for-packetbeat/330763 "2023-04-26T04:11:09Z")

</div>

I am trying to use packetbeat to view a pcap file in Kibana. I have converted my pcap file into json because I know that is the type of file that packetbeat can take in. I used the command: C:\\Program Files\\Packetbeat\>.…

---

## [Connecting Filebeat from local machine to existing logstash pipeline](https://discuss.elastic.co/t/connecting-filebeat-from-local-machine-to-existing-logstash-pipeline/330764)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 9:08pm UTC](https://discuss.elastic.co/t/connecting-filebeat-from-local-machine-to-existing-logstash-pipeline/330764 "2023-04-25T21:08:47Z")

</div>

I'm attempting to push logs from my local machine using Filebeats through an existing logstash collector node to an existing elastic index. Here is my filebeat.yml file: filebeat.inputs: - type: log enabled: true pa…

---

## [Metricbeat 8.7.0 mysql 8, performance module, 1400+ event rate/sec, 16gb an hour](https://discuss.elastic.co/t/metricbeat-8-7-0-mysql-8-performance-module-1400-event-rate-sec-16gb-an-hour/330769)

<div class="topic-metadata">

**Author:** [@ensemblebd](https://discuss.elastic.co/u/ensemblebd)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 8:44pm UTC](https://discuss.elastic.co/t/metricbeat-8-7-0-mysql-8-performance-module-1400-event-rate-sec-16gb-an-hour/330769 "2023-04-25T20:44:25Z")

</div>

Topic title really says it all. My database has well over 100 databases, most are wordpress - so that's at least 15 tables per. And the module runs the following query: SELECT object\_schema, object\_name, index\_name, c…

---

## [Sending logs from filebeat(WIndows) to Logstash and Elasticsearch(RHEL)](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-and-elasticsearch-rhel/330499)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 7:52pm UTC](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-and-elasticsearch-rhel/330499 "2023-04-25T19:52:48Z")

</div>

Hi, I have installed filebeat on my windows machine. I've enabled the systema nd logstash module. Here is the filebeat.yml - type: filestream # Unique ID among all inputs, an ID is required. id: my-filestream-id …

---

## [Filebeat Config file](https://discuss.elastic.co/t/filebeat-config-file/330724)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-config-file/330724 "2023-04-25T12:56:57Z")

</div>

I Need a help with the file beat config: I'm trying to read the data from a log file whose size remains the same and its modification time is changed every 30 mins.During these 30 mins interval new logs are added in pla…

---

## [What will happen to my upcoming logs in filebeat IF elasticsearch is Down](https://discuss.elastic.co/t/what-will-happen-to-my-upcoming-logs-in-filebeat-if-elasticsearch-is-down/330734)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/what-will-happen-to-my-upcoming-logs-in-filebeat-if-elasticsearch-is-down/330734 "2023-04-25T11:54:29Z")

</div>

Hi I am forwarding Syslogs from Filebeat to Elasticsearch.If for some reasons my elasticsearch is down for hours or days . What will happen to my upcoming logs will filebeat hold or store locally if yes then how long …

---

## [Should I create an SQL Output for beats](https://discuss.elastic.co/t/should-i-create-an-sql-output-for-beats/330563)

<div class="topic-metadata">

**Author:** [@Toaster2-0](https://discuss.elastic.co/u/Toaster2-0)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 10:50am UTC](https://discuss.elastic.co/t/should-i-create-an-sql-output-for-beats/330563 "2023-04-24T10:50:59Z")

</div>

Hello, TL;DR: I was thinking about making an output plugin for SQL. I tried the Elastic Stack for a few month with my private project, but the Stack seems too big for it and I am very comfortable in SQL. Now I was sear…

---

## [Filebeat unable to monitor container custom log path](https://discuss.elastic.co/t/filebeat-unable-to-monitor-container-custom-log-path/329905)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 16\
**Last updated:** [April 24, 2023, 8:40am UTC](https://discuss.elastic.co/t/filebeat-unable-to-monitor-container-custom-log-path/329905 "2023-04-24T08:40:40Z")

</div>

Hello, I want to monitor the containers logs using filebeat kubernetes deplyment and the log format is in json format it is just monitoring the logs from containers but not this json file saved inside the container So …

---

## [Beats error: No paths were defined for input accessing config](https://discuss.elastic.co/t/beats-error-no-paths-were-defined-for-input-accessing-config/330285)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 3\
**Last updated:** [April 24, 2023, 7:36am UTC](https://discuss.elastic.co/t/beats-error-no-paths-were-defined-for-input-accessing-config/330285 "2023-04-24T07:36:47Z")

</div>

Hi everyone , I am currently trying to configure filebeat to retrieve logs from my palo alto firewall, I have configured and enable the panw modules: - module: panw panos: enabled: true var.input: udp var…

---

## [Regression? Metricbeat dies immediately if kibana isn't running yet (or is still starting)](https://discuss.elastic.co/t/regression-metricbeat-dies-immediately-if-kibana-isnt-running-yet-or-is-still-starting/328756)

<div class="topic-metadata">

**Author:** [@archon810](https://discuss.elastic.co/u/archon810)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 6:24pm UTC](https://discuss.elastic.co/t/regression-metricbeat-dies-immediately-if-kibana-isnt-running-yet-or-is-still-starting/328756 "2023-04-21T18:24:56Z")

</div>

This used to work in v7, but broken in v8, which we upgraded to recently. Restarting kibana and then restarting metricbeat, like so: systemctl restart elasticsearch && systemctl restart kibana && systemctl restart metr…

---

## [Can you install winlogbeat in another folder](https://discuss.elastic.co/t/can-you-install-winlogbeat-in-another-folder/330400)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 5\
**Last updated:** [April 21, 2023, 3:33pm UTC](https://discuss.elastic.co/t/can-you-install-winlogbeat-in-another-folder/330400 "2023-04-21T15:33:22Z")

</div>

HI, it seems like the install instructions I have seen go into ProgramData or Program files. I want to install to a folder where all of my cyber security stuff? thanks for any advice or suggestions

---

## [Prerequisites for Machine Learning and client Filebeat](https://discuss.elastic.co/t/prerequisites-for-machine-learning-and-client-filebeat/329733)

<div class="topic-metadata">

**Author:** [@kay1](https://discuss.elastic.co/u/kay1)\
**Replies:** 4\
**Last updated:** [April 21, 2023, 2:16pm UTC](https://discuss.elastic.co/t/prerequisites-for-machine-learning-and-client-filebeat/329733 "2023-04-21T14:16:23Z")

</div>

Hi All, I have saw in the documentation, few months ago, that we can only use Machine Learning with a client filebeat \> version 7.14. Can someone confirm the information ? Thank you. KP

---

## [How to add pod annotations to filebeat documents?](https://discuss.elastic.co/t/how-to-add-pod-annotations-to-filebeat-documents/330485)

<div class="topic-metadata">

**Author:** [@lucasdacosta](https://discuss.elastic.co/u/lucasdacosta)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 10:01am UTC](https://discuss.elastic.co/t/how-to-add-pod-annotations-to-filebeat-documents/330485 "2023-04-21T10:01:18Z")

</div>

Hi folks :wave: Am running filebeat within my cluster but I can't figure out how to add fields to my log documents which would include the pod's annotations. That's super relevant for search later. Here's my current co…

---

## [Filebeat/Logstash output split messages into multiple with approximately a maximum field size of 8191 charactes](https://discuss.elastic.co/t/filebeat-logstash-output-split-messages-into-multiple-with-approximately-a-maximum-field-size-of-8191-charactes/330174)

<div class="topic-metadata">

**Author:** [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 12:59am UTC](https://discuss.elastic.co/t/filebeat-logstash-output-split-messages-into-multiple-with-approximately-a-maximum-field-size-of-8191-charactes/330174 "2023-04-18T00:59:40Z")

</div>

I am using Filebeat to collect logs output by docker to Logstash, to Elastic Search. The data flow is from docker stdout -\> Filebeat (autodiscovery) -\> Logstash -\> ES Logstash docker.elastic.co/logstash/logstash:6.8.23 …

---

## [Filebeat cannot connect to kafka with SASL\_PLAINTEXT](https://discuss.elastic.co/t/filebeat-cannot-connect-to-kafka-with-sasl-plaintext/330501)

<div class="topic-metadata">

**Author:** [@sankooc](https://discuss.elastic.co/u/sankooc)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 8:32am UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-to-kafka-with-sasl-plaintext/330501 "2023-04-21T08:32:03Z")

</div>

Hi the problem occurs when collect data from kafka then send to logstash. the filebeat failed to connect kafka kafka version: 2.5.1 filebeat version: 8.6.2 kafka server config security.inter.broker.protocol=SASL\_PL…

---

## [Setup.template.name Setup template.pattern have to be set](https://discuss.elastic.co/t/setup-template-name-setup-template-pattern-have-to-be-set/330383)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 1:47am UTC](https://discuss.elastic.co/t/setup-template-name-setup-template-pattern-have-to-be-set/330383 "2023-04-21T01:47:42Z")

</div>

I am trying to send packetbeat data to another index and it is giving me this error. Error initializing beat: setup.template.name and setup.template.pattern have to be set …

---

## [Do we need to add ECS Logger to our Filebeat just to get log.level as a field in the JSON?](https://discuss.elastic.co/t/do-we-need-to-add-ecs-logger-to-our-filebeat-just-to-get-log-level-as-a-field-in-the-json/329779)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 7\
**Last updated:** [April 20, 2023, 9:00pm UTC](https://discuss.elastic.co/t/do-we-need-to-add-ecs-logger-to-our-filebeat-just-to-get-log-level-as-a-field-in-the-json/329779 "2023-04-20T21:00:38Z")

</div>

I've been rereading the Filebeat documentation to try to deepen my understanding of how it works. We have been configuring Filebeat manually with inputs like this: - type: filestream id: my-api fields: app\_id: …

---

## [.\\winlogbeat.exe -c winlogbeat.yml hangs](https://discuss.elastic.co/t/winlogbeat-exe-c-winlogbeat-yml-hangs/330465)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 6:23pm UTC](https://discuss.elastic.co/t/winlogbeat-exe-c-winlogbeat-yml-hangs/330465 "2023-04-20T18:23:18Z")

</div>

Hi, I could not delete the winglogbeat service, but when I used the command .\\unstall etc that was suggested, I had to reboot to delete it. Then running this ".\\winlogbeat.exe -c winlogbeat.yml" in powershell hangs. It…

---

## [Critical security vulnerabilities reported with go version 1.19.7](https://discuss.elastic.co/t/critical-security-vulnerabilities-reported-with-go-version-1-19-7/330200)

<div class="topic-metadata">

**Author:** [@manojrkrish](https://discuss.elastic.co/u/manojrkrish)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 3:58pm UTC](https://discuss.elastic.co/t/critical-security-vulnerabilities-reported-with-go-version-1-19-7/330200 "2023-04-20T15:58:41Z")

</div>

Hi, Recently few critical vulnerabilities are reported in go version 1.19.7 with below CVEs. https://nvd.nist.gov/vuln/detail/CVE-2023-24536 https://nvd.nist.gov/vuln/detail/CVE-2023-24537 https://nvd.nist.gov/vuln/d…

---

## [Datastream behavior in filebeat?](https://discuss.elastic.co/t/datastream-behavior-in-filebeat/330325)

<div class="topic-metadata">

**Author:** [@matheuscirillo](https://discuss.elastic.co/u/matheuscirillo)\
**Replies:** 4\
**Last updated:** [April 20, 2023, 11:32am UTC](https://discuss.elastic.co/t/datastream-behavior-in-filebeat/330325 "2023-04-20T11:32:11Z")

</div>

A very simple filebeat.yml configuration: filebeat: inputs: - type: filestream id: vouchers-logs-stream paths: - /path/to/logs/\*.log json: keys\_under\_root: true add\_error\_key: true …

---

## [Journald input cannot read read zstd compressed journal](https://discuss.elastic.co/t/journald-input-cannot-read-read-zstd-compressed-journal/330379)

<div class="topic-metadata">

**Author:** [@ederst](https://discuss.elastic.co/u/ederst)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 9:58am UTC](https://discuss.elastic.co/t/journald-input-cannot-read-read-zstd-compressed-journal/330379 "2023-04-20T09:58:07Z")

</div>

Currently, the container Image of filebeat ships with Ubuntu 20.04 ("focal") as OS which uses libsystemd0 version 245. However, this is incompatible with newer Host OS versions, as most of them use a systemd version \>=2…

---

## [Licence check is making the auditbeat connection fail with AWS elasticsearch](https://discuss.elastic.co/t/licence-check-is-making-the-auditbeat-connection-fail-with-aws-elasticsearch/330338)

<div class="topic-metadata">

**Author:** [@Rajnish\_Robin](https://discuss.elastic.co/u/Rajnish_Robin)\
**Replies:** 6\
**Last updated:** [April 20, 2023, 8:05am UTC](https://discuss.elastic.co/t/licence-check-is-making-the-auditbeat-connection-fail-with-aws-elasticsearch/330338 "2023-04-20T08:05:27Z")

</div>

I am using auditbeat version 7.5.2 and AWS opensearch based elasticsearch engine version 7.10.2 The connection to the elasticsearch is breaking with the following error: connection marked as failed because the onConne…

---

## [Ingest logs from a web API that require auth in a separate request](https://discuss.elastic.co/t/ingest-logs-from-a-web-api-that-require-auth-in-a-separate-request/330113)

<div class="topic-metadata">

**Author:** [@Miguel\_Azorin](https://discuss.elastic.co/u/Miguel_Azorin)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 7:46am UTC](https://discuss.elastic.co/t/ingest-logs-from-a-web-api-that-require-auth-in-a-separate-request/330113 "2023-04-20T07:46:09Z")

</div>

Hi! We are currently facing a situation in which we need to request the logs to an external API. Our initial idea was to do this using Filebeat's httpjson plugin, but now we are uncertain that this can be achieved, give…

---

## [To know about the compression logs](https://discuss.elastic.co/t/to-know-about-the-compression-logs/329808)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 6:37am UTC](https://discuss.elastic.co/t/to-know-about-the-compression-logs/329808 "2023-04-20T06:37:50Z")

</div>

Hi Team, We would like to know about the compression logs. These compression logs are generated when we increase the compression level in filebeat.yml. We are processing the logs from filebeat -\> kafka -\> Logstash -\> …

---

## [Handshake... ERROR x509: certificate signed by unknown authorityhandshake](https://discuss.elastic.co/t/handshake-error-x509-certificate-signed-by-unknown-authorityhandshake/329741)

<div class="topic-metadata">

**Author:** [@songhe](https://discuss.elastic.co/u/songhe)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 6:06am UTC](https://discuss.elastic.co/t/handshake-error-x509-certificate-signed-by-unknown-authorityhandshake/329741 "2023-04-20T06:06:34Z")

</div>

version:7.17.9 filebeat command：filebeat test output elasticsearch: https://10.202.250.243:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 10.202.250.243 dial up... OK TLS... …

---

## [INstall filebeat on windows](https://discuss.elastic.co/t/install-filebeat-on-windows/330343)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 4:12am UTC](https://discuss.elastic.co/t/install-filebeat-on-windows/330343 "2023-04-20T04:12:19Z")

</div>

Hi, I am following the steps mentioned in the document elastic.co Filebeat quick start: installation and configuration | Filebeat Reference... to install filebeat on windows. but when i run the following command .\\…

---

## [Install filebeat on windows](https://discuss.elastic.co/t/install-filebeat-on-windows/330279)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 8:58am UTC](https://discuss.elastic.co/t/install-filebeat-on-windows/330279 "2023-04-19T08:58:06Z")

</div>

Hi, I am following the steps mentioned in the document to install filebeat on windows. but when i run the following command .\\install-service-filebeat.ps1 or PowerShell.exe -ExecutionPolicy UnRestricted -File .\\ins…

---

## [How to monitor core usage metrics on Oracle 19c when multiple SIDs on a host](https://discuss.elastic.co/t/how-to-monitor-core-usage-metrics-on-oracle-19c-when-multiple-sids-on-a-host/328957)

<div class="topic-metadata">

**Author:** [@James\_Whittington](https://discuss.elastic.co/u/James_Whittington)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 4:41pm UTC](https://discuss.elastic.co/t/how-to-monitor-core-usage-metrics-on-oracle-19c-when-multiple-sids-on-a-host/328957 "2023-04-19T16:41:14Z")

</div>

I have a delima on how to approach monitoring some key usage based metrics on a Oracle Database server where multiple SIDs reside. We use elastic cloud, version at 8.6, currently just using fleet managed elastic agents. …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=50)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=52)
