# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=58

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 59

---

## [Filebeats Threat Intel Module integration with Logstash](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 12:53pm UTC](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735 "2023-02-17T12:53:44Z")

</div>

Hi, I have the following self hosted setup on ELK stack 8.6.1 : Firewall (logs) --\> Filebeat --\> Logstash --\> Elasticsearch Cluster I am trying to integrate FIleBeats Threat Intel Module into this setup so that IOCs i…

---

## [ELK running on VM, not able to send logs from physical machine](https://discuss.elastic.co/t/elk-running-on-vm-not-able-to-send-logs-from-physical-machine/325720)

<div class="topic-metadata">

**Author:** [@mvasuraja](https://discuss.elastic.co/u/mvasuraja)\
**Replies:** 4\
**Last updated:** [February 17, 2023, 5:32am UTC](https://discuss.elastic.co/t/elk-running-on-vm-not-able-to-send-logs-from-physical-machine/325720 "2023-02-17T05:32:00Z")

</div>

I am running Ubuntu 22.04 on my physical machine with IP 10.180.7.188. I am also running a Ubuntu 22.04 Virtual machine with IP 10.180.5.246. I have installed the ELK version 7.6.2 on the VM. I have installed filebeat v…

---

## [Filebeat. Read each time from the beginning of the file. How?](https://discuss.elastic.co/t/filebeat-read-each-time-from-the-beginning-of-the-file-how/325693)

<div class="topic-metadata">

**Author:** [@cheburasshka](https://discuss.elastic.co/u/cheburasshka)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 7:26am UTC](https://discuss.elastic.co/t/filebeat-read-each-time-from-the-beginning-of-the-file-how/325693 "2023-02-16T07:26:04Z")

</div>

Hi. Faced with such a need: I need to read the file every time from the beginning of the file and send events. I have a file that is completely updated every 10 seconds, that is, the old content is overwritten with new …

---

## [One rsyslog port vs multiple syslog ports](https://discuss.elastic.co/t/one-rsyslog-port-vs-multiple-syslog-ports/325668)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 12:24am UTC](https://discuss.elastic.co/t/one-rsyslog-port-vs-multiple-syslog-ports/325668 "2023-02-16T00:24:56Z")

</div>

Trying to decide if I can direct all syslog data from cisco and vmware and f5 to a centralized location running elastic agent as syslog and if elastic supports having multiple integration used would that be ideal set…

---

## [Filebeat multiline ignores last line](https://discuss.elastic.co/t/filebeat-multiline-ignores-last-line/325654)

<div class="topic-metadata">

**Author:** [@mariana17](https://discuss.elastic.co/u/mariana17)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 9:47pm UTC](https://discuss.elastic.co/t/filebeat-multiline-ignores-last-line/325654 "2023-02-15T21:47:40Z")

</div>

What I want to do is read these records, each of them is inside braces, so I use multilines in filebeat to be able to read them together, however, the last line "\]}" is not read by filebeat, so the record is unfinished a…

---

## [Filebeat Helm chart run as non root](https://discuss.elastic.co/t/filebeat-helm-chart-run-as-non-root/325649)

<div class="topic-metadata">

**Author:** [@DarthVader](https://discuss.elastic.co/u/DarthVader)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-helm-chart-run-as-non-root/325649 "2023-02-15T16:31:17Z")

</div>

Hello, I have been using Terraform to deploy the filebeat helm chart which currently runs successfully as root. Due to security policies I need to apply the pod security context "fsGroup" or anything similar that will e…

---

## [Config Auditbeat](https://discuss.elastic.co/t/config-auditbeat/325519)

<div class="topic-metadata">

**Author:** [@CodeRed](https://discuss.elastic.co/u/CodeRed)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 10:37pm UTC](https://discuss.elastic.co/t/config-auditbeat/325519 "2023-02-14T22:37:07Z")

</div>

Currently i am experimenting with auditbeat the config process i want to collect the whole log due to the auditd rules i added but the log i get is no log auditd here is my config file auditbeat.modules: module: audi…

---

## [Incorrect Filebeat Metrics](https://discuss.elastic.co/t/incorrect-filebeat-metrics/325540)

<div class="topic-metadata">

**Author:** [@vinit0711](https://discuss.elastic.co/u/vinit0711)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 5:19am UTC](https://discuss.elastic.co/t/incorrect-filebeat-metrics/325540 "2023-02-15T05:19:34Z")

</div>

I have Netflow Input For Filebeat . Fiebeat is processing the flow and sending to Elastic. I am receiving following metric logs From filebeat which are generated after every 30s {"monitoring":{"metrics":{"beat":{"cgrou…

---

## [Message: app heartbeat--8.4.3-d6501b26: Missed two check-in elastic-agent standalone](https://discuss.elastic.co/t/message-app-heartbeat-8-4-3-d6501b26-missed-two-check-in-elastic-agent-standalone/325050)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 9:34pm UTC](https://discuss.elastic.co/t/message-app-heartbeat-8-4-3-d6501b26-missed-two-check-in-elastic-agent-standalone/325050 "2023-02-14T21:34:13Z")

</div>

I've used the code mentioned below, and when i log into one of the agents and do ./elastic-agent status i get the following error and the logs for kibana states sample code apiVersion: v1 kind: ConfigMap metadata…

---

## [Why is multiline not working for this unstructured log?](https://discuss.elastic.co/t/why-is-multiline-not-working-for-this-unstructured-log/325510)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 7:32pm UTC](https://discuss.elastic.co/t/why-is-multiline-not-working-for-this-unstructured-log/325510 "2023-02-14T19:32:18Z")

</div>

My multiline: parsers: -multiline: type: pattern pattern: '^\\{' negate: true match: after The format of my log can be like this: { C-FLOW-ID-CAB APN101MQ C-OPERATION-CAB P T-EVENTO-CAB RUNN…

---

## [Filebeat autodiscover stopping too early when kubernetes pod terminates](https://discuss.elastic.co/t/filebeat-autodiscover-stopping-too-early-when-kubernetes-pod-terminates/325491)

<div class="topic-metadata">

**Author:** [@cpaton](https://discuss.elastic.co/u/cpaton)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 2:49pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-stopping-too-early-when-kubernetes-pod-terminates/325491 "2023-02-14T14:49:14Z")

</div>

I am using filebeat with autodiscover within a Kubernetes cluster to capture logs. When a Kubernetes pod terminates filebeat immediately stops reading log entries which can result in log lines at the end of the logs not…

---

## [How do I retrieve statistics from two CEPH clusters using metricbeat autodiscover?](https://discuss.elastic.co/t/how-do-i-retrieve-statistics-from-two-ceph-clusters-using-metricbeat-autodiscover/325386)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 11:54am UTC](https://discuss.elastic.co/t/how-do-i-retrieve-statistics-from-two-ceph-clusters-using-metricbeat-autodiscover/325386 "2023-02-14T11:54:15Z")

</div>

I am retrieving statistics from a CEPH cluster running in a kubernetes deployment using this values file: metricbeat: extraEnvs: - name: CEPH\_API\_USERNAME value: monitoring-ceph - name: CEPH\_API\_PASSWOR…

---

## [Getting a 403 when trying to download a GPG key / install filebeat](https://discuss.elastic.co/t/getting-a-403-when-trying-to-download-a-gpg-key-install-filebeat/325447)

<div class="topic-metadata">

**Author:** [@BlueIceAce](https://discuss.elastic.co/u/BlueIceAce)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 8:56am UTC](https://discuss.elastic.co/t/getting-a-403-when-trying-to-download-a-gpg-key-install-filebeat/325447 "2023-02-14T08:56:00Z")

</div>

Hey, guys! I get a 403 error when I try to download the GPG key, as well as when installing filebeat through apt repository. Adding a GPG key via Ansible: "msg": "Failed to download key at https://artifacts.elastic.co…

---

## [Exiting: couldn't connect to ElasticSearch at](https://discuss.elastic.co/t/exiting-couldnt-connect-to-elasticsearch-at/325234)

<div class="topic-metadata">

**Author:** [@zyaza](https://discuss.elastic.co/u/zyaza)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 4:12am UTC](https://discuss.elastic.co/t/exiting-couldnt-connect-to-elasticsearch-at/325234 "2023-02-14T04:12:12Z")

</div>

sudo auditbeat -e setup This command ends with Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at "ip adress of ubunt server:9200: Get "up adress:9200"…

---

## [Reading a .csv file from a remote url using filebeat and httpjson](https://discuss.elastic.co/t/reading-a-csv-file-from-a-remote-url-using-filebeat-and-httpjson/325415)

<div class="topic-metadata">

**Author:** [@Cristiane\_Naves](https://discuss.elastic.co/u/Cristiane_Naves)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 7:30pm UTC](https://discuss.elastic.co/t/reading-a-csv-file-from-a-remote-url-using-filebeat-and-httpjson/325415 "2023-02-13T19:30:44Z")

</div>

Hi, I'm trying to monitor a remote URL that contains a .csv file. I need to retrieve the file and make it available in Logstash. I'm new to this, and I'm not sure how to get started. Can anyone offer some guidance or s…

---

## [Beats upgrade from 7.10 to 8.x](https://discuss.elastic.co/t/beats-upgrade-from-7-10-to-8-x/325370)

<div class="topic-metadata">

**Author:** [@ShubhamKumarJena](https://discuss.elastic.co/u/ShubhamKumarJena)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 4:49pm UTC](https://discuss.elastic.co/t/beats-upgrade-from-7-10-to-8-x/325370 "2023-02-13T16:49:23Z")

</div>

Hello Guys, We are planning to upgrade our BEATS from 7.10(already EOL) to 8.x soon. Can some body share their experience while they upgrdaed from 7.x to 8.x and give me some of their learnings. I am aware about the fil…

---

## [Filebeat cannot connect to kafka with SASL\_PLAIN authentication enabled?](https://discuss.elastic.co/t/filebeat-cannot-connect-to-kafka-with-sasl-plain-authentication-enabled/325391)

<div class="topic-metadata">

**Author:** [@GuiSong01](https://discuss.elastic.co/u/GuiSong01)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-to-kafka-with-sasl-plain-authentication-enabled/325391 "2023-02-13T14:31:02Z")

</div>

My filebeat cannot connect to kafka with SASL\_PLAIN authentication enabled,and error massage is: 2023-02-10T11:59:56.014+0800 ERROR \[kafka\] kafka/client.go:317 Kafka (topic=test-logs): kafka: client has run out of avail…

---

## [Filebeat high availability, avoiding duplicated results](https://discuss.elastic.co/t/filebeat-high-availability-avoiding-duplicated-results/324615)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 6\
**Last updated:** [February 13, 2023, 2:00pm UTC](https://discuss.elastic.co/t/filebeat-high-availability-avoiding-duplicated-results/324615 "2023-02-13T14:00:09Z")

</div>

Dear Elastic Community, I am looking for a solution to retrieve logs from multiple servers and I have considered using Filebeat for this purpose. My main concern is to ensure high availability, avoiding duplicated resu…

---

## [Removing Data Without Deleting Index While Using Filebeat on Elasticsearch](https://discuss.elastic.co/t/removing-data-without-deleting-index-while-using-filebeat-on-elasticsearch/324761)

<div class="topic-metadata">

**Author:** [@SFD13](https://discuss.elastic.co/u/SFD13)\
**Replies:** 11\
**Last updated:** [February 13, 2023, 10:49am UTC](https://discuss.elastic.co/t/removing-data-without-deleting-index-while-using-filebeat-on-elasticsearch/324761 "2023-02-13T10:49:18Z")

</div>

Hi everyone, I am using filebeat-\* index with some fields on Elasticsearch. I want to remove all data on the elasticsearch which I used but that index remains. It means that without deleting index name and contents (ava…

---

## [Configure Filebeat to not delete AWS SQS message if the message does not match the file\_selectors](https://discuss.elastic.co/t/configure-filebeat-to-not-delete-aws-sqs-message-if-the-message-does-not-match-the-file-selectors/325299)

<div class="topic-metadata">

**Author:** [@b2ron](https://discuss.elastic.co/u/b2ron)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 7:29am UTC](https://discuss.elastic.co/t/configure-filebeat-to-not-delete-aws-sqs-message-if-the-message-does-not-match-the-file-selectors/325299 "2023-02-13T07:29:37Z")

</div>

AWS S3 is configured to send event notification to SQS queue Filebeat is using aws-s3 to pull logs from S3 through the SQS queue filebeat.inputs: - type: aws-s3 queue\_url: https://sqs.us-east-2.amazonaws.com/aws-…

---

## [Metricbeat: TLS Verification Disabled: certificate signed by unknown authority](https://discuss.elastic.co/t/metricbeat-tls-verification-disabled-certificate-signed-by-unknown-authority/324751)

<div class="topic-metadata">

**Author:** [@Cactus7600](https://discuss.elastic.co/u/Cactus7600)\
**Replies:** 4\
**Last updated:** [February 12, 2023, 4:19pm UTC](https://discuss.elastic.co/t/metricbeat-tls-verification-disabled-certificate-signed-by-unknown-authority/324751 "2023-02-12T16:19:32Z")

</div>

Hi. I disabled certificate validation within Metricbeat, yet it's still throwing untrusted certificate errors when hitting Elasticsearch. I'm using these versions: Elasticsearch: 7.16.2 Metricbeat: 7.16.1 I have the…

---

## [Ingesting Windows events forwarded by Splunk heavy forwarders](https://discuss.elastic.co/t/ingesting-windows-events-forwarded-by-splunk-heavy-forwarders/323460)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 5\
**Last updated:** [February 12, 2023, 2:41pm UTC](https://discuss.elastic.co/t/ingesting-windows-events-forwarded-by-splunk-heavy-forwarders/323460 "2023-02-12T14:41:05Z")

</div>

Hiya We are currently moving our SIEM from Splunk to Elastic. Due to a tight deadline and network/firewall configuration we will be adding the Elastic endpoint to our current Splunk Heavy Forwarders. This approach wor…

---

## [Metricbeat timeout](https://discuss.elastic.co/t/metricbeat-timeout/325147)

<div class="topic-metadata">

**Author:** [@imaad](https://discuss.elastic.co/u/imaad)\
**Replies:** 4\
**Last updated:** [February 10, 2023, 3:40pm UTC](https://discuss.elastic.co/t/metricbeat-timeout/325147 "2023-02-10T15:40:56Z")

</div>

Hello all, I have a question about the RabbitMQ module, specially about the queue metricset. My metricbeat send a request every 10s but my rabbitMQ take more than 10s to respond. So, I think that metricbeat continue se…

---

## [How to reduce disk usage for metricbeat](https://discuss.elastic.co/t/how-to-reduce-disk-usage-for-metricbeat/325145)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 1:39pm UTC](https://discuss.elastic.co/t/how-to-reduce-disk-usage-for-metricbeat/325145 "2023-02-10T13:39:05Z")

</div>

Hi Team, I am using metricbeat to monitor around 200+ environments, and using system module. But it is comusing lot of disk space daily it use 10 GB of disk space to store the monitor data. Can we do any work to make…

---

## [Prometheus metricset - query vs. collector](https://discuss.elastic.co/t/prometheus-metricset-query-vs-collector/325140)

<div class="topic-metadata">

**Author:** [@Honken77](https://discuss.elastic.co/u/Honken77)\
**Replies:** 2\
**Last updated:** [February 10, 2023, 10:44am UTC](https://discuss.elastic.co/t/prometheus-metricset-query-vs-collector/325140 "2023-02-10T10:44:56Z")

</div>

Hi! At the moment I am collecting metrics from my OpenShift cluster with the collector metricset like so: metricbeat.modules: - module: prometheus period: 15s timeout: 15s hosts: \["https://prometheus-k8s.openshif…

---

## [Packetbeat TLS \[Client|Server\] hello Ciphers on one string](https://discuss.elastic.co/t/packetbeat-tls-client-server-hello-ciphers-on-one-string/325229)

<div class="topic-metadata">

**Author:** [@franpom](https://discuss.elastic.co/u/franpom)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 9:06am UTC](https://discuss.elastic.co/t/packetbeat-tls-client-server-hello-ciphers-on-one-string/325229 "2023-02-10T09:06:32Z")

</div>

Hello, Would it be possible to integrate an additional field concerning the tls client support\_ciphers? This field currently is broken down for each cipher presented. The problem is that we lose the order of preferenc…

---

## [Filebeat kafka input message is incomplete and full of Unicode characters](https://discuss.elastic.co/t/filebeat-kafka-input-message-is-incomplete-and-full-of-unicode-characters/324139)

<div class="topic-metadata">

**Author:** [@gfar72](https://discuss.elastic.co/u/gfar72)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 11:19pm UTC](https://discuss.elastic.co/t/filebeat-kafka-input-message-is-incomplete-and-full-of-unicode-characters/324139 "2023-02-09T23:19:18Z")

</div>

Hi Forum We have a filebeat instance that uses the kafka input to read from a topic. The instance is able to connect to the topic, but the output of the "message" key is incomplete, and full of Unicode characters see t…

---

## [Unable to add multiple hostname while configuring CPU and Memory Alerts](https://discuss.elastic.co/t/unable-to-add-multiple-hostname-while-configuring-cpu-and-memory-alerts/325189)

<div class="topic-metadata">

**Author:** [@soumya201](https://discuss.elastic.co/u/soumya201)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:35pm UTC](https://discuss.elastic.co/t/unable-to-add-multiple-hostname-while-configuring-cpu-and-memory-alerts/325189 "2023-02-09T19:35:05Z")

</div>

---

## [Monitoring Apache Kafka MirrorMaker 2](https://discuss.elastic.co/t/monitoring-apache-kafka-mirrormaker-2/324587)

<div class="topic-metadata">

**Author:** [@perrocontodo](https://discuss.elastic.co/u/perrocontodo)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 10:29am UTC](https://discuss.elastic.co/t/monitoring-apache-kafka-mirrormaker-2/324587 "2023-02-09T10:29:55Z")

</div>

I was wondering if there are any plans to update the Metricbeat module for Kafka, to allow monitoring of MirrorMaker 2. AFAICS there are a few metricsets that make use of JMX to extract information about Kafka. For examp…

---

## [\[Filebeat\] panic: runtime error: makeslice: len out of range](https://discuss.elastic.co/t/filebeat-panic-runtime-error-makeslice-len-out-of-range/325096)

<div class="topic-metadata">

**Author:** [@g00221501](https://discuss.elastic.co/u/g00221501)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:00am UTC](https://discuss.elastic.co/t/filebeat-panic-runtime-error-makeslice-len-out-of-range/325096 "2023-02-09T07:00:03Z")

</div>

I have a k8s node with a label of “1235679543222322113” as the key. Getting a panic when starting filebeat for collector the node info. Version: 7.13 Operating System: Linux Steps to Reproduce: k8s node with a label o…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=57)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=59)
