# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=57

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 58

---

## [Problem generating Grok from AWS Postgres logs](https://discuss.elastic.co/t/problem-generating-grok-from-aws-postgres-logs/326100)

<div class="topic-metadata">

**Author:** [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 5:13pm UTC](https://discuss.elastic.co/t/problem-generating-grok-from-aws-postgres-logs/326100 "2023-03-01T17:13:11Z")

</div>

Hi, I'm having trouble generating the GROK of AWS logs from the same elasticsearch configuration, as well as from the filebeat.yml file. # ============================== Filebeat inputs =============================== f…

---

## [Filebeat problem](https://discuss.elastic.co/t/filebeat-problem/325831)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:38am UTC](https://discuss.elastic.co/t/filebeat-problem/325831 "2023-03-01T09:38:36Z")

</div>

Hello, I am using filebeat v8 that sends data to kafka. On startup, filebeat sends a chunk of data and then NO data is being transferred. I checked filebeat logs no errors are present. Filebeat registry is accessible an…

---

## [Gradual migration from container input to kubernetes autodiscover](https://discuss.elastic.co/t/gradual-migration-from-container-input-to-kubernetes-autodiscover/325979)

<div class="topic-metadata">

**Author:** [@OranShuster](https://discuss.elastic.co/u/OranShuster)\
**Replies:** 3\
**Last updated:** [March 1, 2023, 9:14am UTC](https://discuss.elastic.co/t/gradual-migration-from-container-input-to-kubernetes-autodiscover/325979 "2023-03-01T09:14:11Z")

</div>

We are currently using a filebeat daemon set with the "old" container input, both version 7.17.x we want to start migrating to the newer approach of hint based log collection for this we need the old filebeat daemon se…

---

## [Interface name](https://discuss.elastic.co/t/interface-name/326736)

<div class="topic-metadata">

**Author:** [@teplyukdimka](https://discuss.elastic.co/u/teplyukdimka)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 8:20am UTC](https://discuss.elastic.co/t/interface-name/326736 "2023-03-01T08:20:49Z")

</div>

Good day. Tell me, please, I collect netflow using filebeat. There are fields '''' "egress\_interface" : 199, "ingress\_interface" : 277, '''' Through SNMP, I found out which network interfaces correspond to these i…

---

## [Elastic agent: "output not supported" using Logstash output on 8.6](https://discuss.elastic.co/t/elastic-agent-output-not-supported-using-logstash-output-on-8-6/326010)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 10:36pm UTC](https://discuss.elastic.co/t/elastic-agent-output-not-supported-using-logstash-output-on-8-6/326010 "2023-02-28T22:36:31Z")

</div>

Hi all, I have a previously working\* Fleet/Agent config with 8.5.3 and Logstash output configured. \* aside from 8.5.1 agents go unhealthy · Issue #1790 · elastic/elastic-agent · GitHub but I have a workaround for this…

---

## [Filebeat gives an error when it outputs to elasticsearch](https://discuss.elastic.co/t/filebeat-gives-an-error-when-it-outputs-to-elasticsearch/326667)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 8:51am UTC](https://discuss.elastic.co/t/filebeat-gives-an-error-when-it-outputs-to-elasticsearch/326667 "2023-02-28T08:51:01Z")

</div>

My elastic cluster version is 8.6.0 and filebeat version is 8.6.0 The log has been successfully read, but there will be some errors in the log output. Failed to connect to backoff (elasticsearch (http://192.168.3.74:30…

---

## [Check if value is 'null' So it Can Be Used in a Fingerprint and Document \_id](https://discuss.elastic.co/t/check-if-value-is-null-so-it-can-be-used-in-a-fingerprint-and-document-id/326632)

<div class="topic-metadata">

**Author:** [@iFamZ](https://discuss.elastic.co/u/iFamZ)\
**Replies:** 12\
**Last updated:** [March 1, 2023, 2:53am UTC](https://discuss.elastic.co/t/check-if-value-is-null-so-it-can-be-used-in-a-fingerprint-and-document-id/326632 "2023-03-01T02:53:21Z")

</div>

Hello, I am working to setup fingerprint on a field if it is not null. If it is null, I will fingerprint a different field (which is never null). Currently, my filebeat processors look like this: processors: - "de…

---

## [Filebeat not collecting all logs](https://discuss.elastic.co/t/filebeat-not-collecting-all-logs/326694)

<div class="topic-metadata">

**Author:** [@Norsu296](https://discuss.elastic.co/u/Norsu296)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 4:17pm UTC](https://discuss.elastic.co/t/filebeat-not-collecting-all-logs/326694 "2023-02-28T16:17:13Z")

</div>

I have issue with filebeat. I'm using autodiscover for kubernetes. Filebeat is collecting logs and sending them to elastic and they are visible in kibana. Some logs are not sending and I don't understand why. I see in Ki…

---

## [I will reword the issue again](https://discuss.elastic.co/t/i-will-reword-the-issue-again/326675)

<div class="topic-metadata">

**Author:** [@learner75](https://discuss.elastic.co/u/learner75)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 1:50pm UTC](https://discuss.elastic.co/t/i-will-reword-the-issue-again/326675 "2023-02-28T13:50:59Z")

</div>

I will reword the issue again.

---

## [I use auditbeat 8.6.2, can't find no login shell command](https://discuss.elastic.co/t/i-use-auditbeat-8-6-2-cant-find-no-login-shell-command/326659)

<div class="topic-metadata">

**Author:** [@chengzhangzuji](https://discuss.elastic.co/u/chengzhangzuji)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 7:12am UTC](https://discuss.elastic.co/t/i-use-auditbeat-8-6-2-cant-find-no-login-shell-command/326659 "2023-02-28T07:12:36Z")

</div>

1.Enviroment: CentOS7、ELK 8.6、Auditbeat 8.6； Two computers，ELK 8.6 in one，auditbeat in the other； Elasticsearch and Kibana installed by docker, auditbeat 8.6 installed by yum; 2. Use the default configure: \[root@loc…

---

## [Using metricbeat in a CRC Instalation of Openshift](https://discuss.elastic.co/t/using-metricbeat-in-a-crc-instalation-of-openshift/326346)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 3:22pm UTC](https://discuss.elastic.co/t/using-metricbeat-in-a-crc-instalation-of-openshift/326346 "2023-02-27T15:22:56Z")

</div>

Hi Im having problems with the instalation of metricbeat using the manifest in the documentation https://raw.githubusercontent.com/elastic/beats/7.17/deploy/kubernetes/metricbeat-kubernetes.yaml this path doesnt exist …

---

## [Filebeat log not in elastic when matching parser](https://discuss.elastic.co/t/filebeat-log-not-in-elastic-when-matching-parser/326609)

<div class="topic-metadata">

**Author:** [@NL-kk](https://discuss.elastic.co/u/NL-kk)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-log-not-in-elastic-when-matching-parser/326609 "2023-02-27T15:16:24Z")

</div>

I just setup a multiline parser because of the multiline error logs of nginx. Before the logs were visible in kibana as seperate log enteries, now they are not visible at all. The single line logs are being logged corr…

---

## [Collect everything from a host](https://discuss.elastic.co/t/collect-everything-from-a-host/326532)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 1:16am UTC](https://discuss.elastic.co/t/collect-everything-from-a-host/326532 "2023-02-27T01:16:36Z")

</div>

Hi, It seems that there is no config which will allow winlogbeat to collect everything available on a given host. event.log: \* I want to deploy winlogbeat across my environment, but hosts have differing roles and ther…

---

## [Filebeat still sending logs even if service is stopped](https://discuss.elastic.co/t/filebeat-still-sending-logs-even-if-service-is-stopped/326029)

<div class="topic-metadata">

**Author:** [@Azkiel19](https://discuss.elastic.co/u/Azkiel19)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:43pm UTC](https://discuss.elastic.co/t/filebeat-still-sending-logs-even-if-service-is-stopped/326029 "2023-02-24T16:43:20Z")

</div>

Hi, I'm new to Filebeats and the ELK stack. To provide an overview, our setup uses: Filebeat -\> sends to Logstash -\> sends to Elastic Search I expected that once I turned off / stop the filebeat service from running …

---

## [\[Filebeat 8.6.1 - httpjson\] invalid memory address or nil pointer dereference](https://discuss.elastic.co/t/filebeat-8-6-1-httpjson-invalid-memory-address-or-nil-pointer-dereference/326365)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 8:19am UTC](https://discuss.elastic.co/t/filebeat-8-6-1-httpjson-invalid-memory-address-or-nil-pointer-dereference/326365 "2023-02-24T08:19:25Z")

</div>

Hello, I try to use httpjson with "chain" and "steps" but I'm stuck on this error "invalid memory address or nil pointer dereference". Here is what I did: a simple httpjson to call an API and get host IDs filebeat.i…

---

## [Custom Logs, fleet pre processor to keep on field as json itself](https://discuss.elastic.co/t/custom-logs-fleet-pre-processor-to-keep-on-field-as-json-itself/326327)

<div class="topic-metadata">

**Author:** [@coderhs](https://discuss.elastic.co/u/coderhs)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 12:59pm UTC](https://discuss.elastic.co/t/custom-logs-fleet-pre-processor-to-keep-on-field-as-json-itself/326327 "2023-02-23T12:59:47Z")

</div>

I have setup a self hosted elastic stack with kibana to track logs for a web application (ruby on rails). I am pushing the production logs to elastic using fleet. I am creating the log in JSON fromat from the application…

---

## [\[ES 8.6.1\]Elastic agent not deleting SQS message after processing](https://discuss.elastic.co/t/es-8-6-1-elastic-agent-not-deleting-sqs-message-after-processing/325372)

<div class="topic-metadata">

**Author:** [@rubal033](https://discuss.elastic.co/u/rubal033)\
**Replies:** 9\
**Last updated:** [February 23, 2023, 8:57am UTC](https://discuss.elastic.co/t/es-8-6-1-elastic-agent-not-deleting-sqs-message-after-processing/325372 "2023-02-23T08:57:40Z")

</div>

Hi I am using Elastic agent integration to monitor ELB logs (via s3-sqs setup). I am able to see ELB logs in Elasticsearch cluster but my SQS inflight messages are keep on increasing. Looks like agent is not able to del…

---

## [Kubernetes: Filebeat parses JSON in message field no matter if I want or not](https://discuss.elastic.co/t/kubernetes-filebeat-parses-json-in-message-field-no-matter-if-i-want-or-not/326089)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 8:45am UTC](https://discuss.elastic.co/t/kubernetes-filebeat-parses-json-in-message-field-no-matter-if-i-want-or-not/326089 "2023-02-23T08:45:15Z")

</div>

I want to use Filebeat (current version) to collect logs from our Kubernetes Cluster by using this manual: Run Filebeat on Kubernetes | Filebeat Reference \[8.6\] | Elastic I want to control if the message of a cointainer…

---

## [Unable to connect filebeat to elastic search host](https://discuss.elastic.co/t/unable-to-connect-filebeat-to-elastic-search-host/326260)

<div class="topic-metadata">

**Author:** [@Shrivatsa\_Rao](https://discuss.elastic.co/u/Shrivatsa_Rao)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 6:10am UTC](https://discuss.elastic.co/t/unable-to-connect-filebeat-to-elastic-search-host/326260 "2023-02-23T06:10:10Z")

</div>

Hi I am running filebeat docker image with following command docker run docker.elastic.co/beats/filebeat:8.6.2 setup -E setup.kibana.host=http://localhost:5601 -E output.elasticsearch.hosts=\["https://localhost:9200"\] b…

---

## [Having issue to setup filebeat](https://discuss.elastic.co/t/having-issue-to-setup-filebeat/326235)

<div class="topic-metadata">

**Author:** [@ermilan2309](https://discuss.elastic.co/u/ermilan2309)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 11:18pm UTC](https://discuss.elastic.co/t/having-issue-to-setup-filebeat/326235 "2023-02-22T23:18:59Z")

</div>

Hello I am having issue while setup the filebeat module for threat hunting. This is the error I am getting.. root@wazuh:/etc/kibana# sudo filebeat setup Overwriting ILM policy is disabled. Set setup.ilm.overwrite: tru…

---

## [Filebeat to elastic/cloud not using defined index in yml config](https://discuss.elastic.co/t/filebeat-to-elastic-cloud-not-using-defined-index-in-yml-config/326216)

<div class="topic-metadata">

**Author:** [@tymercer](https://discuss.elastic.co/u/tymercer)\
**Replies:** 9\
**Last updated:** [February 22, 2023, 10:35pm UTC](https://discuss.elastic.co/t/filebeat-to-elastic-cloud-not-using-defined-index-in-yml-config/326216 "2023-02-22T22:35:07Z")

</div>

First, I am new to all of this and have next to no knowledge of how all of our systems were setup originally as I took this over when the person in charge of it left the company. ELK 6.8.12, Filebeats 6.4 (yes, old, it …

---

## [Unable to send logs using Filebeat to Logstash](https://discuss.elastic.co/t/unable-to-send-logs-using-filebeat-to-logstash/326114)

<div class="topic-metadata">

**Author:** [@Chris\_W1](https://discuss.elastic.co/u/Chris_W1)\
**Replies:** 11\
**Last updated:** [February 22, 2023, 2:57pm UTC](https://discuss.elastic.co/t/unable-to-send-logs-using-filebeat-to-logstash/326114 "2023-02-22T14:57:53Z")

</div>

Hi Team, I am trying to send logs in .json file on one of my server to Logstash using Filebeat. Below are the configs I did on the Filebeat & Logstash but I am not able to send it successfully. Your suggestions and help…

---

## [Elasticsearch monitoring by metricbeat creating index with pattern .ds-.monitoring-es-8-mb-yyyy.mm.dd-\*](https://discuss.elastic.co/t/elasticsearch-monitoring-by-metricbeat-creating-index-with-pattern-ds-monitoring-es-8-mb-yyyy-mm-dd/326084)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 2:55pm UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-by-metricbeat-creating-index-with-pattern-ds-monitoring-es-8-mb-yyyy-mm-dd/326084 "2023-02-21T14:55:58Z")

</div>

Hi, I have recently started testing to use metricbeat for elasticsearch's monitoring. i have elasticsearch deployed as statefulset and metricbeat as daemonset on azure kubernetes services cluster. i have configured met…

---

## [Multiline settings for handling edge cases of stdout logs of mixed ndjson and java](https://discuss.elastic.co/t/multiline-settings-for-handling-edge-cases-of-stdout-logs-of-mixed-ndjson-and-java/324189)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 8:40pm UTC](https://discuss.elastic.co/t/multiline-settings-for-handling-edge-cases-of-stdout-logs-of-mixed-ndjson-and-java/324189 "2023-02-21T20:40:47Z")

</div>

Hi, I am currently working with a system that has spring apps running as wars in tomcat, and am currently sending the logs to an ingest pipeline using filebeat. Unfortunately due to legacy reasons, logs are being output…

---

## [Query on Logstash to Elasticsearch and third party](https://discuss.elastic.co/t/query-on-logstash-to-elasticsearch-and-third-party/325990)

<div class="topic-metadata">

**Author:** [@ianrobo](https://discuss.elastic.co/u/ianrobo)\
**Replies:** 3\
**Last updated:** [February 21, 2023, 7:36am UTC](https://discuss.elastic.co/t/query-on-logstash-to-elasticsearch-and-third-party/325990 "2023-02-21T07:36:39Z")

</div>

Hi, I have an isue which should be simple to resolve but can not. Basically we send all our log data to a beat on a server in the DMZ an then that forwards onto Elastic. However we now have a requirement to forward on…

---

## [Confirmation please](https://discuss.elastic.co/t/confirmation-please/325956)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 6:56am UTC](https://discuss.elastic.co/t/confirmation-please/325956 "2023-02-21T06:56:41Z")

</div>

Hello again I have not still could connect filebeat to elasticsearch buy the error that is showed to me is that "the proxy needs autentification" so, Can anybody confirm to me that filebeat can not pass HTTP proxies? If…

---

## [Fleet-server can not running, "only 1 fleet-server input can be defined accessing config" occur in the log files](https://discuss.elastic.co/t/fleet-server-can-not-running-only-1-fleet-server-input-can-be-defined-accessing-config-occur-in-the-log-files/325951)

<div class="topic-metadata">

**Author:** [@hds1989824](https://discuss.elastic.co/u/hds1989824)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 1:56am UTC](https://discuss.elastic.co/t/fleet-server-can-not-running-only-1-fleet-server-input-can-be-defined-accessing-config-occur-in-the-log-files/325951 "2023-02-21T01:56:10Z")

</div>

first, my elk server version is 7.17.7,and deploy by docker ,such as logstach,kibana,elasticsearch,server ip is 10.30.25.223 。port forward has added to the firewall (sonicwall), 10.30.25.223: 5601，10.30.25.223:920…

---

## [Filebeat azure module multiple eventhubs in self managed elastic version 8.6.1](https://discuss.elastic.co/t/filebeat-azure-module-multiple-eventhubs-in-self-managed-elastic-version-8-6-1/325455)

<div class="topic-metadata">

**Author:** [@Dov\_Zelinger](https://discuss.elastic.co/u/Dov_Zelinger)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 10:19pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-multiple-eventhubs-in-self-managed-elastic-version-8-6-1/325455 "2023-02-20T22:19:30Z")

</div>

Hi, As written in the below link, the issue was resolved. multiple-event-hubs Unfortunately, the issue still exists. When configuring multiple platformlogs as can be seen below, only one of them gets active and that …

---

## [Using Arithmetic in pipeline.yml Processor](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725)

<div class="topic-metadata">

**Author:** [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 6:11pm UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725 "2023-02-20T18:11:52Z")

</div>

Hello, I'm appointed to update or rewriting an old ELK project. In the old version we used Logstash and its corresponding 'filebeat.cfg' file. I was rebuilding an IngestPipeline in a 'pipeline.yml'. In Losgtash we had f…

---

## [How to use request.ssl in Filebeat httpjson Input](https://discuss.elastic.co/t/how-to-use-request-ssl-in-filebeat-httpjson-input/325966)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 11:35am UTC](https://discuss.elastic.co/t/how-to-use-request-ssl-in-filebeat-httpjson-input/325966 "2023-02-20T11:35:50Z")

</div>

Hi there, i want to know how using request.ssl in Filebeat input on httpjson type. So, here's an overview of the config I made: filebeat.inputs: - type: httpjson config\_version: 2 request.url: https://192.168.0.217:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=56)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=58)
