# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=53

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 54

---

## [Similar configuration for multiple Filebeat inputs](https://discuss.elastic.co/t/similar-configuration-for-multiple-filebeat-inputs/329443)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:34pm UTC](https://discuss.elastic.co/t/similar-configuration-for-multiple-filebeat-inputs/329443 "2023-04-05T14:34:46Z")

</div>

Hi, I am using Filebeat on about ten servers (almost all under Linux except 2 under Windows). I have edited a filebeat.yml file on each one and approximately 10 inputs inside both. Inputs are only 'filestream' type for t…

---

## [Meraki not parsing sport and saddr correctly](https://discuss.elastic.co/t/meraki-not-parsing-sport-and-saddr-correctly/329440)

<div class="topic-metadata">

**Author:** [@pozniako16](https://discuss.elastic.co/u/pozniako16)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:26pm UTC](https://discuss.elastic.co/t/meraki-not-parsing-sport-and-saddr-correctly/329440 "2023-04-05T14:26:17Z")

</div>

Currently in the parsing pipeline for meraki. The sport and saddr are inverted. Address should be in Address:Port format not the opposite.

---

## [New Filebeat Module - ECS not supports email fields](https://discuss.elastic.co/t/new-filebeat-module-ecs-not-supports-email-fields/329339)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 2:59pm UTC](https://discuss.elastic.co/t/new-filebeat-module-ecs-not-supports-email-fields/329339 "2023-04-04T14:59:46Z")

</div>

Hi I'm trying to contribute several new filebeat modules (Postfix and Exchange) and can't use email fields. Seems filebeat tests use old ECS schema. I've tried to change ecs version to the last one but it's not working. …

---

## [Custom service monitoring and autodiscovery](https://discuss.elastic.co/t/custom-service-monitoring-and-autodiscovery/329323)

<div class="topic-metadata">

**Author:** [@denisk](https://discuss.elastic.co/u/denisk)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 1:02pm UTC](https://discuss.elastic.co/t/custom-service-monitoring-and-autodiscovery/329323 "2023-04-04T13:02:49Z")

</div>

Hi, I have set up metric collection of a number of custom microservices using the http module. Per microservice I've create a separate yaml file, and in each yaml file looks something like this: # Each service has its …

---

## [Filebeat - 10000s of messages "Reader was closed. Closing.#011" flooding log](https://discuss.elastic.co/t/filebeat-10000s-of-messages-reader-was-closed-closing-011-flooding-log/329088)

<div class="topic-metadata">

**Author:** [@Alex\_Stuck](https://discuss.elastic.co/u/Alex_Stuck)\
**Replies:** 5\
**Last updated:** [April 5, 2023, 5:31am UTC](https://discuss.elastic.co/t/filebeat-10000s-of-messages-reader-was-closed-closing-011-flooding-log/329088 "2023-04-05T05:31:28Z")

</div>

Hey there Subject says it all. I have a simple filebeat agent pointing to some other team's LS that I don't control. I get spammed with the following line at a rate of up to 1000/minute and it doesn't stop. Here an exam…

---

## [Filebeat doesn't publish logs without "write" permission on index](https://discuss.elastic.co/t/filebeat-doesnt-publish-logs-without-write-permission-on-index/328870)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 5\
**Last updated:** [April 4, 2023, 10:30pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-publish-logs-without-write-permission-on-index/328870 "2023-04-04T22:30:15Z")

</div>

Hello! I created API key for Filebeat to publish log records to Elasticsearch using this documentation as a reference: Grant privileges and roles needed for publishing | Filebeat Reference \[8.6\] | Elastic. But after I d…

---

## [Logging: How to set selectors correctly](https://discuss.elastic.co/t/logging-how-to-set-selectors-correctly/329341)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 3:14pm UTC](https://discuss.elastic.co/t/logging-how-to-set-selectors-correctly/329341 "2023-04-04T15:14:57Z")

</div>

Hi I need to debug some filebeat issues in one of our testsystems. I want to set loglevel to debug and I need help for setting the selectors correctly. I need to have all the logs which are related to registry, harvest…

---

## [Delay in logs in filebeat for only one index](https://discuss.elastic.co/t/delay-in-logs-in-filebeat-for-only-one-index/329282)

<div class="topic-metadata">

**Author:** [@ks-ak](https://discuss.elastic.co/u/ks-ak)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 7:24am UTC](https://discuss.elastic.co/t/delay-in-logs-in-filebeat-for-only-one-index/329282 "2023-04-04T07:24:08Z")

</div>

Hi! I have filebeat with multiple indexes and one particular index is causing the issue and other indexes are sending logs without delayi.e., Sending logs to Kibana is getting delayed by 6 hours for the particular index…

---

## [No Alerts in Winlogbeat](https://discuss.elastic.co/t/no-alerts-in-winlogbeat/328698)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 10:15am UTC](https://discuss.elastic.co/t/no-alerts-in-winlogbeat/328698 "2023-04-03T10:15:06Z")

</div>

Hi there I´m trying to run Winlogbeat. I installed everything but I can´t see any alerts. It seem that it isn´t possible for me to find the problem :frowning: Elasticsearch, Kibana and Winlogbeat are running without …

---

## [Filebeat MSSQL Module - Log Unreadable](https://discuss.elastic.co/t/filebeat-mssql-module-log-unreadable/329066)

<div class="topic-metadata">

**Author:** [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 9:13pm UTC](https://discuss.elastic.co/t/filebeat-mssql-module-log-unreadable/329066 "2023-03-31T21:13:36Z")

</div>

I installed filebeat 8.7 on my SQL Server and enabled the MSSQL module. Filebeat is normally collecting the logs from the folders I configured, but the original log message is unreadable: 72.\\u0000\\u0000\\u0000\\u0000��…

---

## [Issue connecting to Elastic from Metricbeat](https://discuss.elastic.co/t/issue-connecting-to-elastic-from-metricbeat/327833)

<div class="topic-metadata">

**Author:** [@SANTHOSH\_R](https://discuss.elastic.co/u/SANTHOSH_R)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 5:32am UTC](https://discuss.elastic.co/t/issue-connecting-to-elastic-from-metricbeat/327833 "2023-03-31T05:32:09Z")

</div>

I am getting following error , when i tried to connect to elastic (which is in another server) from metricbeat server. What could be the issue ? Can you guys help on it . Thanks in Advance PS C:\\ELK\_PROD\\Metricbeat\> .\\m…

---

## [Recommended settings with close\_removed and clean\_removed false](https://discuss.elastic.co/t/recommended-settings-with-close-removed-and-clean-removed-false/327226)

<div class="topic-metadata">

**Author:** [@running\_banana](https://discuss.elastic.co/u/running_banana)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 5:26am UTC](https://discuss.elastic.co/t/recommended-settings-with-close-removed-and-clean-removed-false/327226 "2023-03-31T05:26:23Z")

</div>

Hi, We were looking to tune our filebeat.autodiscover settings to better handle scraping of ephemeral docker containers. The main issue we have is that when the container is stopped and removed, its log file also gets r…

---

## [Elastic Agents infinitely revisioning, stops sending data to Elasticsearch](https://discuss.elastic.co/t/elastic-agents-infinitely-revisioning-stops-sending-data-to-elasticsearch/328996)

<div class="topic-metadata">

**Author:** [@johnkim](https://discuss.elastic.co/u/johnkim)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 4:50am UTC](https://discuss.elastic.co/t/elastic-agents-infinitely-revisioning-stops-sending-data-to-elasticsearch/328996 "2023-03-31T04:50:34Z")

</div>

I have a combination of problem symptoms that may be caused by multiple issues, but since I don't know for sure what is the cause I'm compiling my issues into one thread. First, my ECK is self-managed. There are two thi…

---

## [Filebeat Registry File Growing](https://discuss.elastic.co/t/filebeat-registry-file-growing/328983)

<div class="topic-metadata">

**Author:** [@Rich\_Liberty](https://discuss.elastic.co/u/Rich_Liberty)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 11:23pm UTC](https://discuss.elastic.co/t/filebeat-registry-file-growing/328983 "2023-03-30T23:23:25Z")

</div>

Filebeats 7.4.0 running in a relatively large and busy Tanzu Kubernetes cluster (1.20.x) The Filebeat registry file /var/lib/filebeat-data/registry/filebeat/data.json grows causing disk throttling as the file size gets…

---

## [High CPU usage after updating filebeat from 7.12.0 to 8.6.2](https://discuss.elastic.co/t/high-cpu-usage-after-updating-filebeat-from-7-12-0-to-8-6-2/327249)

<div class="topic-metadata">

**Author:** [@germain\_nganko](https://discuss.elastic.co/u/germain_nganko)\
**Replies:** 10\
**Last updated:** [March 30, 2023, 11:17pm UTC](https://discuss.elastic.co/t/high-cpu-usage-after-updating-filebeat-from-7-12-0-to-8-6-2/327249 "2023-03-30T23:17:57Z")

</div>

After updating to filebeat to 8.6.2 I observe an increase in cpu usage. also tested on 8.6.1 same thing, went back to 8.0.0 and could also observe an increase there, however less than in 8.6.2 and 8.6.1. Is there anythi…

---

## [Icmp not responding as expected in Elastic](https://discuss.elastic.co/t/icmp-not-responding-as-expected-in-elastic/328900)

<div class="topic-metadata">

**Author:** [@TheNewGuy123](https://discuss.elastic.co/u/TheNewGuy123)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 1:03pm UTC](https://discuss.elastic.co/t/icmp-not-responding-as-expected-in-elastic/328900 "2023-03-30T13:03:26Z")

</div>

Hey, I setup my heartbeat monitoring and I have configured all three kind of monitors: http, tcp and icmp. So I got tcp and http to work correctly, but no luck with icmp (which is the one I actually need). So I am checki…

---

## [Metricbeat configuration for custom application](https://discuss.elastic.co/t/metricbeat-configuration-for-custom-application/328925)

<div class="topic-metadata">

**Author:** [@Abdul\_Ahad](https://discuss.elastic.co/u/Abdul_Ahad)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 10:48am UTC](https://discuss.elastic.co/t/metricbeat-configuration-for-custom-application/328925 "2023-03-30T10:48:08Z")

</div>

Hi Team, We got an application deployed in Openshift which got a /metrics end point. Could you please help on how to configure metricbeat to push the metrics from this application to elasticsearch. Currently I am able t…

---

## [Negative cluster hash](https://discuss.elastic.co/t/negative-cluster-hash/328912)

<div class="topic-metadata">

**Author:** [@SteelDi](https://discuss.elastic.co/u/SteelDi)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 9:23am UTC](https://discuss.elastic.co/t/negative-cluster-hash/328912 "2023-03-30T09:23:05Z")

</div>

Hello. After i moved elasticsearch from docker to k8s helm chart, i getiing many emails from watcher with node was changed alerts. Is it normal then i see negative sluster hash? "\_score": null, …

---

## [Name IPs (source and destination) in packetbeat flows](https://discuss.elastic.co/t/name-ips-source-and-destination-in-packetbeat-flows/327851)

<div class="topic-metadata">

**Author:** [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 7:14pm UTC](https://discuss.elastic.co/t/name-ips-source-and-destination-in-packetbeat-flows/327851 "2023-03-29T19:14:39Z")

</div>

Hello, I'm using packetbeat to monitor internal networks flows. I'd like to know how I can add a name for each known IP (for example 10.10.10.1 is my DHCP server, I want to add field source.name : 'DHCP Server' and dest…

---

## [The number of nested documents has exceeded the allowed limit of \[10000\]](https://discuss.elastic.co/t/the-number-of-nested-documents-has-exceeded-the-allowed-limit-of-10000/328852)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 5:02pm UTC](https://discuss.elastic.co/t/the-number-of-nested-documents-has-exceeded-the-allowed-limit-of-10000/328852 "2023-03-29T17:02:00Z")

</div>

Hello! We are reciving the following error: The number of nested documents has exceeded the allowed limit of \[10000\]. This limit can be set by changing the \[index.mapping.nested\_objects.limit\] index level setting. We …

---

## [Filestream and sequencing](https://discuss.elastic.co/t/filestream-and-sequencing/328809)

<div class="topic-metadata">

**Author:** [@kakoni](https://discuss.elastic.co/u/kakoni)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 12:47pm UTC](https://discuss.elastic.co/t/filestream-and-sequencing/328809 "2023-03-29T12:47:46Z")

</div>

Hi. Lets say that I've got log directory full of old files; data\_20230301.log data\_20230402.log .. data\_20230329.log and so on. Is it somehow possible to configure filestream input so that these files are read/proc…

---

## [Winlogbeat is not Connecting to Logstash Which is not connecting to Elasticsearch](https://discuss.elastic.co/t/winlogbeat-is-not-connecting-to-logstash-which-is-not-connecting-to-elasticsearch/328713)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 7\
**Last updated:** [March 29, 2023, 9:55am UTC](https://discuss.elastic.co/t/winlogbeat-is-not-connecting-to-logstash-which-is-not-connecting-to-elasticsearch/328713 "2023-03-29T09:55:55Z")

</div>

I have a small lab that consists of 2 ES nodes with basic security enabled using a TLS certificate, Kibana, Logstash, and a Windows 10 machine. The thing is that i'm not able to connect winbeat to logstash. Logstash Err…

---

## [How to monitor Publish and Delivery Rate of messages in RabbitMQ Queues using Metricbeat?](https://discuss.elastic.co/t/how-to-monitor-publish-and-delivery-rate-of-messages-in-rabbitmq-queues-using-metricbeat/328354)

<div class="topic-metadata">

**Author:** [@Karan\_Vyas](https://discuss.elastic.co/u/Karan_Vyas)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 9:40am UTC](https://discuss.elastic.co/t/how-to-monitor-publish-and-delivery-rate-of-messages-in-rabbitmq-queues-using-metricbeat/328354 "2023-03-29T09:40:28Z")

</div>

I am trying to monitor the publish and delivery rate of messages in RabbitMQ using Metricbeat, but I can't find any Metricbeat field that provides these metrics. I have already configured Metricbeat to monitor my Rabbit…

---

## [Harvester stats always 0, no harvester logs at all but logs shipping](https://discuss.elastic.co/t/harvester-stats-always-0-no-harvester-logs-at-all-but-logs-shipping/328204)

<div class="topic-metadata">

**Author:** [@Alex\_Stuck](https://discuss.elastic.co/u/Alex_Stuck)\
**Replies:** 29\
**Last updated:** [March 29, 2023, 2:06am UTC](https://discuss.elastic.co/t/harvester-stats-always-0-no-harvester-logs-at-all-but-logs-shipping/328204 "2023-03-29T02:06:22Z")

</div>

Hey there, new to filebeats. I'm watching a large directory at the root (/log/\*/\*\*) and am sending the logs to another team's LS that I don't control. We are seeing what looks like a major lag at time from some systems …

---

## [No MySQL Enterprise module available](https://discuss.elastic.co/t/no-mysql-enterprise-module-available/328159)

<div class="topic-metadata">

**Author:** [@Samuel\_Ruiz](https://discuss.elastic.co/u/Samuel_Ruiz)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 3:48pm UTC](https://discuss.elastic.co/t/no-mysql-enterprise-module-available/328159 "2023-03-28T15:48:49Z")

</div>

In my filebeat module directory (/usr/share/filebeat/module) there is no mysqlenterprise directory with the configuration of the mysqlenterprise module. Where can i find this conf?

---

## [Windows servers in observavility/metrics/inventory?](https://discuss.elastic.co/t/windows-servers-in-observavility-metrics-inventory/328717)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 2:16pm UTC](https://discuss.elastic.co/t/windows-servers-in-observavility-metrics-inventory/328717 "2023-03-28T14:16:51Z")

</div>

Which metricset is needed to see windows servers in observavility/metrics/inventory?

---

## [How to convert incoming JSON data from HTTP response into a string and store it in a new field in Metricbeat?](https://discuss.elastic.co/t/how-to-convert-incoming-json-data-from-http-response-into-a-string-and-store-it-in-a-new-field-in-metricbeat/328700)

<div class="topic-metadata">

**Author:** [@Karan\_Vyas](https://discuss.elastic.co/u/Karan_Vyas)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 10:12am UTC](https://discuss.elastic.co/t/how-to-convert-incoming-json-data-from-http-response-into-a-string-and-store-it-in-a-new-field-in-metricbeat/328700 "2023-03-28T10:12:32Z")

</div>

I am using Metricbeat's HTTP module to make a request to the RabbitMQ API to retrieve queue data. However, the Metricbeat RabbitMQ module does not include some fields like incoming and delivery rate, so I am making the r…

---

## [Processes tab loads forever](https://discuss.elastic.co/t/processes-tab-loads-forever/328694)

<div class="topic-metadata">

**Author:** [@Ivan\_Hosea](https://discuss.elastic.co/u/Ivan_Hosea)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 9:32am UTC](https://discuss.elastic.co/t/processes-tab-loads-forever/328694 "2023-03-28T09:32:55Z")

</div>

Hi I installed metricbeat on my linux host, when I checked on inventory, the processes tab seemed to not be able to load, but when I checked on discover, metricbeat is still able to get the system.process logs properly.…

---

## [How to clear filebeat so it does not into kibana?](https://discuss.elastic.co/t/how-to-clear-filebeat-so-it-does-not-into-kibana/328485)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 1:28am UTC](https://discuss.elastic.co/t/how-to-clear-filebeat-so-it-does-not-into-kibana/328485 "2023-03-28T01:28:34Z")

</div>

Hi, I know I filebeat in my security onion so-status. I am using windows 10. The events get into my kibana, even when i so-elastic-clear and so-nsm-clear. How can I clear filebeat so kibana is completely empty? thanks …

---

## [Filebeat / Haproxy : Grok in pipeline need to have both request and response headers captured to parse them](https://discuss.elastic.co/t/filebeat-haproxy-grok-in-pipeline-need-to-have-both-request-and-response-headers-captured-to-parse-them/328637)

<div class="topic-metadata">

**Author:** [@lpoujol](https://discuss.elastic.co/u/lpoujol)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 4:10pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-grok-in-pipeline-need-to-have-both-request-and-response-headers-captured-to-parse-them/328637 "2023-03-27T16:10:35Z")

</div>

Hi I've been testing Filebeat (8.6.2) to collect logs generated by HAProxy 2.2. The logs are directly sent to Elasticsearch, and treated by the haproxy pipeline setup by Filebeat. In my Haproxy setup, I only capture re…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=52)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=54)
