# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=56

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 57

---

## [Osquery Manager integration: Settings page stuck updating](https://discuss.elastic.co/t/osquery-manager-integration-settings-page-stuck-updating/327508)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 11:15pm UTC](https://discuss.elastic.co/t/osquery-manager-integration-settings-page-stuck-updating/327508 "2023-03-12T23:15:57Z")

</div>

Hi there, I have an air-gapped install using the Elastic Docker image for the integration registry. The Docker container is running on that same node as Kibana. This is all fine and integration installs and such are wor…

---

## [Filebeat custom module](https://discuss.elastic.co/t/filebeat-custom-module/327509)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 11:49pm UTC](https://discuss.elastic.co/t/filebeat-custom-module/327509 "2023-03-12T23:49:26Z")

</div>

Not finding the doc of modules sufficient to make me a custom module. Would it be possible to convert a filebeat.inputs section to a filebeat.config.modules configuration? Eg. having working filestream like this: - t…

---

## [Filebeat vs elastic putput](https://discuss.elastic.co/t/filebeat-vs-elastic-putput/327506)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 10\
**Last updated:** [March 12, 2023, 9:47pm UTC](https://discuss.elastic.co/t/filebeat-vs-elastic-putput/327506 "2023-03-12T21:47:10Z")

</div>

Hi Need a wall to play against here TIA :slight\_smile: What am I missing out on, I wonder, when trying to launch filebeat.service. I'm see these errors: ==\> /var/log/filebeat/filebeat-20230312.ndjson \<== {"log.level":…

---

## [Error filebeat - Trying to retrieve too many docvalue\_fields](https://discuss.elastic.co/t/error-filebeat-trying-to-retrieve-too-many-docvalue-fields/327394)

<div class="topic-metadata">

**Author:** [@Maria\_Gabriela\_Perez](https://discuss.elastic.co/u/Maria_Gabriela_Perez)\
**Replies:** 1\
**Last updated:** [March 11, 2023, 4:30pm UTC](https://discuss.elastic.co/t/error-filebeat-trying-to-retrieve-too-many-docvalue-fields/327394 "2023-03-11T16:30:01Z")

</div>

\[illegal\_argument\_exception\] Trying to retrieve too many docvalue\_fields. Must be less than or equal to: \[200\] but was \[208\]. This limit can be set by changing the \[index.max\_docvalue\_fields\_search\] index level setting.

---

## [Slow indexing speed, possibly related to filebeat misconfiguration](https://discuss.elastic.co/t/slow-indexing-speed-possibly-related-to-filebeat-misconfiguration/327283)

<div class="topic-metadata">

**Author:** [@alexandrpaliy](https://discuss.elastic.co/u/alexandrpaliy)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 9:05pm UTC](https://discuss.elastic.co/t/slow-indexing-speed-possibly-related-to-filebeat-misconfiguration/327283 "2023-03-10T21:05:38Z")

</div>

I have actually no idea which tag/subforum to use, because I have an issue with a general filebeat -\> logstash -\> elasticsearch pipelinem and I am not entirely sure, is this issue related to ES indexing performance, or i…

---

## [Not able to send data from filebeat to elastic cloud however with same settings it works on EFK stack on linux](https://discuss.elastic.co/t/not-able-to-send-data-from-filebeat-to-elastic-cloud-however-with-same-settings-it-works-on-efk-stack-on-linux/327390)

<div class="topic-metadata">

**Author:** [@sameer\_rathod](https://discuss.elastic.co/u/sameer_rathod)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 10:40am UTC](https://discuss.elastic.co/t/not-able-to-send-data-from-filebeat-to-elastic-cloud-however-with-same-settings-it-works-on-efk-stack-on-linux/327390 "2023-03-10T10:40:52Z")

</div>

I am using elastic cloud and when I used filebeat to send IIS logs from windows machine, elasticsearch only received the error logs and not even a single access logs from default directory. In last two days I tried setti…

---

## [Packetbeat isn't capture mysql network traffic](https://discuss.elastic.co/t/packetbeat-isnt-capture-mysql-network-traffic/327378)

<div class="topic-metadata">

**Author:** [@Ivan\_Picca](https://discuss.elastic.co/u/Ivan_Picca)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 10:12am UTC](https://discuss.elastic.co/t/packetbeat-isnt-capture-mysql-network-traffic/327378 "2023-03-10T10:12:57Z")

</div>

hey guys. I'm stuck. I got this problem. I've configured packetbeat to capture network traffic. I've 1 server contains elk stack and another host where i' ve installed packetbeat and mysql. The main idea is forward pack…

---

## [Prometheus collector query defined once, applied everywhere](https://discuss.elastic.co/t/prometheus-collector-query-defined-once-applied-everywhere/327400)

<div class="topic-metadata">

**Author:** [@jeanfabrice](https://discuss.elastic.co/u/jeanfabrice)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 10:33pm UTC](https://discuss.elastic.co/t/prometheus-collector-query-defined-once-applied-everywhere/327400 "2023-03-09T22:33:31Z")

</div>

Hi, I'm using Metricbeat 8.6.2 and I'm trying to collect Prometheus metrics using the official Prom snmp exporter. This particular exporter requires passing a URL query string to configure the snmp endpoint to collect t…

---

## [Convert Keyword to object data type](https://discuss.elastic.co/t/convert-keyword-to-object-data-type/327355)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 12:23pm UTC](https://discuss.elastic.co/t/convert-keyword-to-object-data-type/327355 "2023-03-09T12:23:34Z")

</div>

Hi Team I want to convert a keyword data type field to object data type, i know we can do by editing the data stream but as i am using a ingest pipeline which is creating a the field in keyword data type so wanted to kno…

---

## [Filebeat for AWS Cloudwatch does not support timestamps with milliseconds](https://discuss.elastic.co/t/filebeat-for-aws-cloudwatch-does-not-support-timestamps-with-milliseconds/327338)

<div class="topic-metadata">

**Author:** [@Tomas\_Mocek](https://discuss.elastic.co/u/Tomas_Mocek)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:59am UTC](https://discuss.elastic.co/t/filebeat-for-aws-cloudwatch-does-not-support-timestamps-with-milliseconds/327338 "2023-03-09T08:59:08Z")

</div>

Hi, we are using AWS Filebeat CloudWatch input, and everything works as expected, however, the logs are fetched without milliseconds precision. I believe this is caused because of this code, which cuts milliseconds ret…

---

## [Configuration issues - Filebeat for shipping messages from a Kafka topic to Elasticsearch](https://discuss.elastic.co/t/configuration-issues-filebeat-for-shipping-messages-from-a-kafka-topic-to-elasticsearch/327315)

<div class="topic-metadata">

**Author:** [@dvoracek-martin](https://discuss.elastic.co/u/dvoracek-martin)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 1:04am UTC](https://discuss.elastic.co/t/configuration-issues-filebeat-for-shipping-messages-from-a-kafka-topic-to-elasticsearch/327315 "2023-03-09T01:04:01Z")

</div>

Hi! I'd like to have Filebeat set up the way that it would consume messages from Kafka topic and then send them to Elasticsearch. Is there a way, how to set it all up in docker-compose? I could register Logstash as a Kaf…

---

## [Metricbeat not sending data or Elasticsearch not recieving (?)](https://discuss.elastic.co/t/metricbeat-not-sending-data-or-elasticsearch-not-recieving/326863)

<div class="topic-metadata">

**Author:** [@enigmatic](https://discuss.elastic.co/u/enigmatic)\
**Replies:** 12\
**Last updated:** [March 9, 2023, 9:06am UTC](https://discuss.elastic.co/t/metricbeat-not-sending-data-or-elasticsearch-not-recieving/326863 "2023-03-09T09:06:34Z")

</div>

Hi Guys, hope you can help me out in the following. i'm using: Elasticseearch 8.4.3 metricbeat 8.4.3 kubernetes / AWS EKS I've deployed metricbeat in a kubernetes cluster. it gathering all sort of data and i also wa…

---

## [How to get logs from jupyter notebook instances generated by jupyterhub](https://discuss.elastic.co/t/how-to-get-logs-from-jupyter-notebook-instances-generated-by-jupyterhub/327290)

<div class="topic-metadata">

**Author:** [@SirReno](https://discuss.elastic.co/u/SirReno)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 4:45pm UTC](https://discuss.elastic.co/t/how-to-get-logs-from-jupyter-notebook-instances-generated-by-jupyterhub/327290 "2023-03-08T16:45:50Z")

</div>

Hello eveyone; We have a jupyterhub (that is being monitored by filebeat) that spawns individual jupyter-notebooks (based on docker image), since it spawns a pod, the filebeat that monitors jupyterhub, cant reach the in…

---

## [Filebeat Helm chart 8.x requires \`elasticsearch-master-certs\`](https://discuss.elastic.co/t/filebeat-helm-chart-8-x-requires-elasticsearch-master-certs/325049)

<div class="topic-metadata">

**Author:** [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 2:15pm UTC](https://discuss.elastic.co/t/filebeat-helm-chart-8-x-requires-elasticsearch-master-certs/325049 "2023-03-08T14:15:55Z")

</div>

We are using beats to ship our logs from k8s to the elastic cloud. I would like to upgrade our beats helm chart version from 7.x to 8.x and it introduces a breaking change where i would have to create a secret with elas…

---

## [Filebeat shared folder](https://discuss.elastic.co/t/filebeat-shared-folder/327106)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-shared-folder/327106 "2023-03-08T14:04:32Z")

</div>

Hello, I have to install Filebeat on a server (windows). Filebeat will have to read logs file on a shared folder. In my .yml, i got that : filebeat.inputs: - type: log paths: - \\\\dpm\\\*.log But this doesn't work…

---

## [Change Wilnogbeat index name](https://discuss.elastic.co/t/change-wilnogbeat-index-name/327273)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 1:08pm UTC](https://discuss.elastic.co/t/change-wilnogbeat-index-name/327273 "2023-03-08T13:08:03Z")

</div>

Hi, I want to change index name from winlogbeat and i am following your instructions. This is my yml file: But still getting this error: Exiting: error loading template: failed to put data stream: could not put data…

---

## [Filebeat connection error with logstash](https://discuss.elastic.co/t/filebeat-connection-error-with-logstash/327208)

<div class="topic-metadata">

**Author:** [@sebglon](https://discuss.elastic.co/u/sebglon)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 8:24am UTC](https://discuss.elastic.co/t/filebeat-connection-error-with-logstash/327208 "2023-03-08T08:24:03Z")

</div>

Hi, We have a K8s cluster with more than 30 nodes. on each nodes we have a filebeat agent to collect container logs and node logs. filebeat agents send data to 3 logstash on the same cluster. On some nodes and after …

---

## [Metricbeat VM Can't Connect To Elasticsearch On Different Device](https://discuss.elastic.co/t/metricbeat-vm-cant-connect-to-elasticsearch-on-different-device/326722)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 44\
**Last updated:** [March 8, 2023, 12:47am UTC](https://discuss.elastic.co/t/metricbeat-vm-cant-connect-to-elasticsearch-on-different-device/326722 "2023-03-08T00:47:22Z")

</div>

Hello i'm new on ELK, Metricbeat on my VM can't connect to my laptop for monitoring the system on VM, i already following the instruction from many source but still can't connect from Metricbeat VM to my laptop for monit…

---

## [Building beats with oss lisence](https://discuss.elastic.co/t/building-beats-with-oss-lisence/327187)

<div class="topic-metadata">

**Author:** [@Udemy\_Guy](https://discuss.elastic.co/u/Udemy_Guy)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 2:13pm UTC](https://discuss.elastic.co/t/building-beats-with-oss-lisence/327187 "2023-03-07T14:13:09Z")

</div>

We are trying to rebuild beats with oss licensing, anyone can guide? We used "mage build" but looks like it does not build it as oss.

---

## [Data from Filebeat Not Showing in Elastic](https://discuss.elastic.co/t/data-from-filebeat-not-showing-in-elastic/326922)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/data-from-filebeat-not-showing-in-elastic/326922 "2023-03-07T13:41:09Z")

</div>

Hi, Hoping you can help. I am fairly new to Elastic Stack, but the company i work for have a running implementation monitoring Apache logs. I am attempting to add to the functionality by also monitoring the access log …

---

## [Parsing multiple JSON entries merged inside 1 "message" of filebeat input Azure Blob Storage](https://discuss.elastic.co/t/parsing-multiple-json-entries-merged-inside-1-message-of-filebeat-input-azure-blob-storage/323153)

<div class="topic-metadata">

**Author:** [@Marquito](https://discuss.elastic.co/u/Marquito)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 12:46pm UTC](https://discuss.elastic.co/t/parsing-multiple-json-entries-merged-inside-1-message-of-filebeat-input-azure-blob-storage/323153 "2023-03-07T12:46:38Z")

</div>

Hello Everyone, I am currently trying to parse a message that contains multiple JSON entries with filebeat input Azure Blob Storage. I have tried using decode\_json\_fields, multiline but it seems like "multiline" only wo…

---

## [Can't assume role in filebeat cloudwatch input when IAM policy can assume multiple roles](https://discuss.elastic.co/t/cant-assume-role-in-filebeat-cloudwatch-input-when-iam-policy-can-assume-multiple-roles/327159)

<div class="topic-metadata">

**Author:** [@stwang](https://discuss.elastic.co/u/stwang)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 9:10am UTC](https://discuss.elastic.co/t/cant-assume-role-in-filebeat-cloudwatch-input-when-iam-policy-can-assume-multiple-roles/327159 "2023-03-07T09:10:55Z")

</div>

We are using filebeat 7.17.5, and we are using CloudWatch input, we want to retrieve log from another AWS account b and AWS account c. So in filebeat AWS role, we have a policy which allow to assume roles for other two …

---

## [Filebeat - Single line log without newline character](https://discuss.elastic.co/t/filebeat-single-line-log-without-newline-character/327157)

<div class="topic-metadata">

**Author:** [@True](https://discuss.elastic.co/u/True)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 8:45am UTC](https://discuss.elastic.co/t/filebeat-single-line-log-without-newline-character/327157 "2023-03-07T08:45:51Z")

</div>

Hello :smiling\_face\_with\_tear: Is there any possible method for shipping single-line logs without newline characters from Filebeat to Kafka? I'm using 8.6.1 Stack, and in Filebeat, filestream (log) type. The log is cr…

---

## [Auditbeat Version 8.4.1 event.category](https://discuss.elastic.co/t/auditbeat-version-8-4-1-event-category/327137)

<div class="topic-metadata">

**Author:** [@jjacksonrkk](https://discuss.elastic.co/u/jjacksonrkk)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:08am UTC](https://discuss.elastic.co/t/auditbeat-version-8-4-1-event-category/327137 "2023-03-07T05:08:18Z")

</div>

Auditbeat version 8.4.1 is in use. When debugging, event.category occurs as \["intrusion\_detection", "process"\] When running the auditbeat daemon service, event.category appears only as process, what should I set in audi…

---

## [Failed to publish events](https://discuss.elastic.co/t/failed-to-publish-events/327090)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 5:18pm UTC](https://discuss.elastic.co/t/failed-to-publish-events/327090 "2023-03-06T17:18:56Z")

</div>

Hi All, We see the following error in filebeat log resulting in loss of data: pipeline/output.go:121 Failed to publish events: write tcp 19.14.25.26:42660-\>14.18.8.1:5044: write: connection reset by peer It seems tha…

---

## [Metricbeat sends timestamp as keyword type instead of date type to Elasticsearch, old template endpoints work instead of new one](https://discuss.elastic.co/t/metricbeat-sends-timestamp-as-keyword-type-instead-of-date-type-to-elasticsearch-old-template-endpoints-work-instead-of-new-one/326703)

<div class="topic-metadata">

**Author:** [@learner75](https://discuss.elastic.co/u/learner75)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 8:05am UTC](https://discuss.elastic.co/t/metricbeat-sends-timestamp-as-keyword-type-instead-of-date-type-to-elasticsearch-old-template-endpoints-work-instead-of-new-one/326703 "2023-03-06T08:05:05Z")

</div>

Current problem: Metricbeat sends timestamp as keyword type instead of date type. Have to use a separate command with the old index template api to update mapping. Background: Our ELK stack was upgraded from 6.8.23 to …

---

## [Metricbeat services restarted automatically](https://discuss.elastic.co/t/metricbeat-services-restarted-automatically/326822)

<div class="topic-metadata">

**Author:** [@ArpitChoudhary](https://discuss.elastic.co/u/ArpitChoudhary)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 6:53am UTC](https://discuss.elastic.co/t/metricbeat-services-restarted-automatically/326822 "2023-03-06T06:53:36Z")

</div>

Hello Guys. Facing an issue , Metricbeat service is recursively getting restarting. Please find below status/log of service.

---

## [Filebeat consume high CPU usage](https://discuss.elastic.co/t/filebeat-consume-high-cpu-usage/326152)

<div class="topic-metadata">

**Author:** [@Jalin](https://discuss.elastic.co/u/Jalin)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 2:00am UTC](https://discuss.elastic.co/t/filebeat-consume-high-cpu-usage/326152 "2023-03-06T02:00:30Z")

</div>

Filebeat consume high CPU usage (about 25%) when processing logs and scanning files. Here is my environment: Windows 10 Pro 64-bit 4 core Here is my configuration: filebeat.inputs: - type: log id: log enab…

---

## [Failed to expand fields: cannot expand "field" found conflicting key](https://discuss.elastic.co/t/failed-to-expand-fields-cannot-expand-field-found-conflicting-key/326924)

<div class="topic-metadata">

**Author:** [@nobeerhere](https://discuss.elastic.co/u/nobeerhere)\
**Replies:** 2\
**Last updated:** [March 4, 2023, 7:26pm UTC](https://discuss.elastic.co/t/failed-to-expand-fields-cannot-expand-field-found-conflicting-key/326924 "2023-03-04T19:26:30Z")

</div>

hi there I am using ECS logging for Java and so far it worked fine. I now have the issue that the log structure changed a bit (field trace.id & transation.id are new) and i am having a conflicting key value. This also m…

---

## [Kubernetes Node Condition NetworkUnavailable missing from metricbeat](https://discuss.elastic.co/t/kubernetes-node-condition-networkunavailable-missing-from-metricbeat/326789)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 6:52pm UTC](https://discuss.elastic.co/t/kubernetes-node-condition-networkunavailable-missing-from-metricbeat/326789 "2023-03-02T18:52:05Z")

</div>

The kubernetes Node Condition 'NetworkUnavailable' is missing from metricbeat. Can you please elaborate to why that is? Thank you, Kris

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=55)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=57)
