# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=54

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 55

---

## [Filebeat - doesn't log kafka processor activity](https://discuss.elastic.co/t/filebeat-doesnt-log-kafka-processor-activity/328623)

<div class="topic-metadata">

**Author:** [@jose\_carlos](https://discuss.elastic.co/u/jose_carlos)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-log-kafka-processor-activity/328623 "2023-03-27T14:20:41Z")

</div>

Hi, Currently monitoring a log file with Filebeat and sending content to Kafka. All is working as expected however, unless we raise the debug level do "debug" we have no idea if Filebeat worked properly. We have a diss…

---

## [Supplement vlan.id to DNS data](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453)

<div class="topic-metadata">

**Author:** [@infofs](https://discuss.elastic.co/u/infofs)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 8:02am UTC](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453 "2023-03-27T08:02:23Z")

</div>

I am sending all DNS traffic to logstash. Is it possible to add vlan data (especially the vlan.id) to this output? This is my packetbeat.yml: # =============================== Network device ===========================…

---

## [Typo or peculiarity related to \`setup.ilm.check\_exists\` in documentation](https://discuss.elastic.co/t/typo-or-peculiarity-related-to-setup-ilm-check-exists-in-documentation/327974)

<div class="topic-metadata">

**Author:** [@NominaSumpta](https://discuss.elastic.co/u/NominaSumpta)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 7:58am UTC](https://discuss.elastic.co/t/typo-or-peculiarity-related-to-setup-ilm-check-exists-in-documentation/327974 "2023-03-27T07:58:11Z")

</div>

The documentation for Metricbeat (https://github.com/elastic/beats/blob/master/libbeat/docs/security/users.asciidoc) says: When using ILM, turn off the ILM setup check The documentation (Configure index lifecycle man…

---

## [\[Newbie\] Multiple dissects in same Filebeat configuration processor](https://discuss.elastic.co/t/newbie-multiple-dissects-in-same-filebeat-configuration-processor/328575)

<div class="topic-metadata">

**Author:** [@Akshay\_M\_B](https://discuss.elastic.co/u/Akshay_M_B)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 6:27am UTC](https://discuss.elastic.co/t/newbie-multiple-dissects-in-same-filebeat-configuration-processor/328575 "2023-03-27T06:27:59Z")

</div>

Hi, I am really new to filebeat and wanted know if there is a way we can have multiple dissect tokenizer based on different file inputs in the same configuration? For my case, I am trying to send logs from nginx as well…

---

## [Monitor multiple directories in monitors.d using heartbeat](https://discuss.elastic.co/t/monitor-multiple-directories-in-monitors-d-using-heartbeat/328053)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [March 25, 2023, 4:10am UTC](https://discuss.elastic.co/t/monitor-multiple-directories-in-monitors-d-using-heartbeat/328053 "2023-03-25T04:10:47Z")

</div>

Hi All, wanted to know do we able to manager directories in monitors.d directories in heartbeat. I wanted to monitor some service and wanted to manage the yml file in directors i.e. each yml files should be under machin…

---

## [Filebeat and Metricbeat get Error 401 Unauthorized](https://discuss.elastic.co/t/filebeat-and-metricbeat-get-error-401-unauthorized/328200)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 7\
**Last updated:** [March 24, 2023, 1:10pm UTC](https://discuss.elastic.co/t/filebeat-and-metricbeat-get-error-401-unauthorized/328200 "2023-03-24T13:10:20Z")

</div>

I recently upgraded from ELK Stack 7.9.3 to 7.17.9. Everything is working great except that Filebeat and Metricbeat will not connect to Elasticsearch anymore unless they are installed on the same server. I get errors lik…

---

## [Fatal error: concurrent map iteration and map write](https://discuss.elastic.co/t/fatal-error-concurrent-map-iteration-and-map-write/328350)

<div class="topic-metadata">

**Author:** [@Z4ck404](https://discuss.elastic.co/u/Z4ck404)\
**Replies:** 5\
**Last updated:** [March 24, 2023, 8:08am UTC](https://discuss.elastic.co/t/fatal-error-concurrent-map-iteration-and-map-write/328350 "2023-03-24T08:08:24Z")

</div>

I am using filebeat with google storage input and elasticsearch as output .. the filebeat starts and throws this error after few seconds : {"log.level":"warn","@timestamp":"2023-03-23T13:46:05.824Z","log.logger":"input…

---

## [In Metricbeat have provided the process monitoring list in system.yml but not getting process stats in the kibana dashboard](https://discuss.elastic.co/t/in-metricbeat-have-provided-the-process-monitoring-list-in-system-yml-but-not-getting-process-stats-in-the-kibana-dashboard/327183)

<div class="topic-metadata">

**Author:** [@sourabh\_rawat](https://discuss.elastic.co/u/sourabh_rawat)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 3:53am UTC](https://discuss.elastic.co/t/in-metricbeat-have-provided-the-process-monitoring-list-in-system-yml-but-not-getting-process-stats-in-the-kibana-dashboard/327183 "2023-03-24T03:53:08Z")

</div>

Hi I have provided the list of processes to get monitored on my system but I am not getting stats for one of the processes for other listed processes I am getting data but. My system.yml is below # Module: system # Docs…

---

## [Filebeat AWS CloudWatch input loss data](https://discuss.elastic.co/t/filebeat-aws-cloudwatch-input-loss-data/328409)

<div class="topic-metadata">

**Author:** [@jacksparrow414](https://discuss.elastic.co/u/jacksparrow414)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 2:14am UTC](https://discuss.elastic.co/t/filebeat-aws-cloudwatch-input-loss-data/328409 "2023-03-24T02:14:07Z")

</div>

filebeat configuration filebeat.inputs: - type: aws-cloudwatch enabled: true log\_group\_arn: arn log\_stream\_prefix: my-logstream-prefix scan\_frequency: 10s start\_position: end access\_key\_id: omi…

---

## [Heartbeat in eks](https://discuss.elastic.co/t/heartbeat-in-eks/328360)

<div class="topic-metadata">

**Author:** [@amar12](https://discuss.elastic.co/u/amar12)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 4:31pm UTC](https://discuss.elastic.co/t/heartbeat-in-eks/328360 "2023-03-23T16:31:18Z")

</div>

Hi , I want to provision the heart beat in eks , I have purchased the elastic apm account . i want to do the service uptime monitoring.

---

## [How to Install heartbeat in Openshift](https://discuss.elastic.co/t/how-to-install-heartbeat-in-openshift/328048)

<div class="topic-metadata">

**Author:** [@kiran7373](https://discuss.elastic.co/u/kiran7373)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:06pm UTC](https://discuss.elastic.co/t/how-to-install-heartbeat-in-openshift/328048 "2023-03-23T15:06:57Z")

</div>

Our need is to install heartbeat service in Openshift . Unable to find good documentation . Can anyone please suggest.

---

## [Filebeat processors](https://discuss.elastic.co/t/filebeat-processors/328275)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 7:34am UTC](https://discuss.elastic.co/t/filebeat-processors/328275 "2023-03-23T07:34:13Z")

</div>

Hi everyone, I have a question about the filebeat processors (extract\_array, drop\_event, drop\_fields). My filebeat agent collects about 2500 logs lines a second. Do you think that using these processors can lead to hug…

---

## [Two seprate log files to put in separate index](https://discuss.elastic.co/t/two-seprate-log-files-to-put-in-separate-index/327626)

<div class="topic-metadata">

**Author:** [@abhishek1111](https://discuss.elastic.co/u/abhishek1111)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 4:36am UTC](https://discuss.elastic.co/t/two-seprate-log-files-to-put-in-separate-index/327626 "2023-03-23T04:36:12Z")

</div>

Hello Experts :slight\_smile: Need your assistance on below use case of mine where filebeat is running as kubernetes daemon set. I have two log files under same folder in which i want to parse and push data to separate …

---

## [Bug in Cisco FTD Integration's Ingest Pipeline for Message ID's 302013, 302015](https://discuss.elastic.co/t/bug-in-cisco-ftd-integrations-ingest-pipeline-for-message-ids-302013-302015/328292)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 9:42pm UTC](https://discuss.elastic.co/t/bug-in-cisco-ftd-integrations-ingest-pipeline-for-message-ids-302013-302015/328292 "2023-03-22T21:42:06Z")

</div>

We have been getting quite a lot of "Network Traffic to Rare Destination Country" alerts based on the associated ML job, and after looking into each of these detections, the vast majority of them are false-positives for …

---

## [Bug: No Misp event data send to Kibana when Threat intel module used](https://discuss.elastic.co/t/bug-no-misp-event-data-send-to-kibana-when-threat-intel-module-used/327979)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 2:24pm UTC](https://discuss.elastic.co/t/bug-no-misp-event-data-send-to-kibana-when-threat-intel-module-used/327979 "2023-03-22T14:24:03Z")

</div>

Hello, I'm trying to integrate IOCs from MISP to Elastic stack (ELK) using the Filebeat Threat intel module. I'm receiving event in Analytics Discover panel of Kibana with filebeat-\* toggle on: (see below image) B…

---

## [Filebeat with multiple log path should direct to different Index and Should follow ILM,ILM policy and rollover already defined in elastic](https://discuss.elastic.co/t/filebeat-with-multiple-log-path-should-direct-to-different-index-and-should-follow-ilm-ilm-policy-and-rollover-already-defined-in-elastic/328236)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 11:17am UTC](https://discuss.elastic.co/t/filebeat-with-multiple-log-path-should-direct-to-different-index-and-should-follow-ilm-ilm-policy-and-rollover-already-defined-in-elastic/328236 "2023-03-22T11:17:03Z")

</div>

Hello All, I've a requirement wherein I would like to have single filebeat.yml and this will have different log paths and will direct the data to respective diffrent index according to path. Now this filebeat.yml would…

---

## [Double values filebeat](https://discuss.elastic.co/t/double-values-filebeat/328217)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 8:09am UTC](https://discuss.elastic.co/t/double-values-filebeat/328217 "2023-03-22T08:09:16Z")

</div>

Hello, I'm trying to read my log server.json into logstash /kibana. Now I have opened a topic for this before, and I was advised to ask further questions in the filebeat forum. For the record. I've already gotten a lit…

---

## [Can Filebeat handle same load as Logstash while being a lightweight shipper](https://discuss.elastic.co/t/can-filebeat-handle-same-load-as-logstash-while-being-a-lightweight-shipper/328212)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 6:43am UTC](https://discuss.elastic.co/t/can-filebeat-handle-same-load-as-logstash-while-being-a-lightweight-shipper/328212 "2023-03-22T06:43:09Z")

</div>

if I am using Logstash / Filebeat as a Log server . in term of memory and other things . which tool is better to go with.

---

## [Ingesting syslog from NetApp ONTAP](https://discuss.elastic.co/t/ingesting-syslog-from-netapp-ontap/328170)

<div class="topic-metadata">

**Author:** [@diselkgd7](https://discuss.elastic.co/u/diselkgd7)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:58am UTC](https://discuss.elastic.co/t/ingesting-syslog-from-netapp-ontap/328170 "2023-03-22T00:58:51Z")

</div>

I've configured our storage to send syslog to filebeat but when I examine what's been ingested in kibana - the whole syslog message is crammed in one "message" field while the rest of the 26 fields have values relating t…

---

## [Failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/327681)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 7:45pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/327681 "2023-03-21T19:45:08Z")

</div>

Hello everyone. I am trying to modify some parameters of the logs that come from fleet with the "custom logs" integration. I have created the following pipeline: LOG LINE: 2023-02-28 09:04:01,937 ERROR \[org.jboss.rem…

---

## [Auditbeat Equivalent for Elastic Agent](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 6:08pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171 "2023-03-21T18:08:27Z")

</div>

When will there be an Auditbeat-equivalent Integration for Elastic Agent? We are trying to move exclusively to Elastic Agent, but the same monitoring done by Auditbeat is still not yet available that I can see. Eric

---

## [How to avoid host.name field in filebeat](https://discuss.elastic.co/t/how-to-avoid-host-name-field-in-filebeat/327578)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 4:06pm UTC](https://discuss.elastic.co/t/how-to-avoid-host-name-field-in-filebeat/327578 "2023-03-21T16:06:24Z")

</div>

Hi Team, I am sending data to elasticsearch using filebeat once the file were harvested I can see field host.name where the value is hostname of the VM { "\_index": "filebeat-7.17.6-2023.03.13-000001", "\_type":…

---

## [Metricbeat setup: one-time?](https://discuss.elastic.co/t/metricbeat-setup-one-time/327959)

<div class="topic-metadata">

**Author:** [@NominaSumpta](https://discuss.elastic.co/u/NominaSumpta)\
**Replies:** 11\
**Last updated:** [March 21, 2023, 2:02pm UTC](https://discuss.elastic.co/t/metricbeat-setup-one-time/327959 "2023-03-21T14:02:55Z")

</div>

Is metricbeat setup meant to be run once per cluster? The documentation (Metricbeat quick start: installation and configuration | Metricbeat Reference \[8.6\] | Elastic) does not say. It is implied that this command is m…

---

## [How to enriching events with "dynamic" data from a file](https://discuss.elastic.co/t/how-to-enriching-events-with-dynamic-data-from-a-file/328019)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 9\
**Last updated:** [March 21, 2023, 3:10am UTC](https://discuss.elastic.co/t/how-to-enriching-events-with-dynamic-data-from-a-file/328019 "2023-03-21T03:10:25Z")

</div>

Tinkering with how to enrich filebeat events by tagging/labelling with data picked from a text that might change infrequently but still change (days, weeks, months). We're talking off application version data, so wheneve…

---

## [IBM Cloud Metric Beat Module Contribution to the Beats Community](https://discuss.elastic.co/t/ibm-cloud-metric-beat-module-contribution-to-the-beats-community/327569)

<div class="topic-metadata">

**Author:** [@prashantaruadvi](https://discuss.elastic.co/u/prashantaruadvi)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 12:02pm UTC](https://discuss.elastic.co/t/ibm-cloud-metric-beat-module-contribution-to-the-beats-community/327569 "2023-03-20T12:02:55Z")

</div>

Hi Team, We have built the IBM cloud metric beat module, we would like to contribute back to the community, can you please help us what is right way to contribute, thanks in advance.

---

## [Groks solution in filebeat](https://discuss.elastic.co/t/groks-solution-in-filebeat/327133)

<div class="topic-metadata">

**Author:** [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 3:22am UTC](https://discuss.elastic.co/t/groks-solution-in-filebeat/327133 "2023-03-07T03:22:29Z")

</div>

Hello community, Having encountered the problem of how to apply groks in filebeat, I want to share with you the solution I found with the PROCESSORS section and the Dissect function, I hope it helps you, as well as havi…

---

## [How to use event.category intrusion\_detection](https://discuss.elastic.co/t/how-to-use-event-category-intrusion-detection/327316)

<div class="topic-metadata">

**Author:** [@jjacksonrkk](https://discuss.elastic.co/u/jjacksonrkk)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 1:52am UTC](https://discuss.elastic.co/t/how-to-use-event-category-intrusion-detection/327316 "2023-03-09T01:52:46Z")

</div>

How can I activate intrusion\_detection in auditbeat event.category? When debugging, log.logger occurs as a publisher and the event.category includes intrusion\_detection, but when the daemon service is run, the intrusion…

---

## [Filebeat logs stored in /tmp are causing pod eviction](https://discuss.elastic.co/t/filebeat-logs-stored-in-tmp-are-causing-pod-eviction/327221)

<div class="topic-metadata">

**Author:** [@Varun\_Sriram](https://discuss.elastic.co/u/Varun_Sriram)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 6:21pm UTC](https://discuss.elastic.co/t/filebeat-logs-stored-in-tmp-are-causing-pod-eviction/327221 "2023-03-07T18:21:21Z")

</div>

Hi all, i am seeing an issue on my environment which is using filebeat for logging and monitoring where files with large amounts of storage used are getting created. I presume these are log files created by filebeat and…

---

## [Receiving harvestor errors and invalid CRI log format on filebeat](https://discuss.elastic.co/t/receiving-harvestor-errors-and-invalid-cri-log-format-on-filebeat/327347)

<div class="topic-metadata">

**Author:** [@Narendra](https://discuss.elastic.co/u/Narendra)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 10:41am UTC](https://discuss.elastic.co/t/receiving-harvestor-errors-and-invalid-cri-log-format-on-filebeat/327347 "2023-03-09T10:41:06Z")

</div>

Hi, I have an ELK setup with deamonset filebeat(7.14) as input from 31 kubernetes nodes moved to logstash and then to ES. From couple of days we and are facing log drop and getting below logs in Filebeat. \<\<\<\<\<\<\<\<\<\< …

---

## [Filebeat consumes all memory](https://discuss.elastic.co/t/filebeat-consumes-all-memory/327592)

<div class="topic-metadata">

**Author:** [@Radoslav\_Stefanov](https://discuss.elastic.co/u/Radoslav_Stefanov)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 10:39pm UTC](https://discuss.elastic.co/t/filebeat-consumes-all-memory/327592 "2023-03-19T22:39:45Z")

</div>

Hi! I have the following setup to ingest logs from s3. filebeat pulls data from s3 and sends it to logstash. logstash ingests into elastic. The problem is after a while (usually a day or two) filebeat consumes all se…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=53)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=55)
