# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=59

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 60

---

## [Filebeat x509 certificate signed by unknown authority when calling api endpoint](https://discuss.elastic.co/t/filebeat-x509-certificate-signed-by-unknown-authority-when-calling-api-endpoint/325086)

<div class="topic-metadata">

**Author:** [@tom\_morgan](https://discuss.elastic.co/u/tom_morgan)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 5:16am UTC](https://discuss.elastic.co/t/filebeat-x509-certificate-signed-by-unknown-authority-when-calling-api-endpoint/325086 "2023-02-09T05:16:27Z")

</div>

I am getting this error from filebeat: 2023-02-07 07:14:47 2023-02-07T15:14:47.204Z ERROR \[input.httpjson-stateless\] v2/input.go:129 Error while processing http request: failed to execute http client.Do: fail…

---

## [Redis Module Connection By using Different User rather than redis default user](https://discuss.elastic.co/t/redis-module-connection-by-using-different-user-rather-than-redis-default-user/323410)

<div class="topic-metadata">

**Author:** [@Gopal\_Nipane](https://discuss.elastic.co/u/Gopal_Nipane)\
**Replies:** 1\
**Last updated:** [February 8, 2023, 8:06pm UTC](https://discuss.elastic.co/t/redis-module-connection-by-using-different-user-rather-than-redis-default-user/323410 "2023-02-08T20:06:16Z")

</div>

Can we mention username in metricbeat redis module ie. /etc/metricbeat/modules.d/redis.yml? I tried two approches to add username in module.hosts field: hosts: \["redis://username:password@localhost:6379"\] in modu…

---

## [Azure Function's log streams from Azure Event Hub can't be consumed by Filebeat](https://discuss.elastic.co/t/azure-functions-log-streams-from-azure-event-hub-cant-be-consumed-by-filebeat/325044)

<div class="topic-metadata">

**Author:** [@dfgh012316](https://discuss.elastic.co/u/dfgh012316)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 4:25pm UTC](https://discuss.elastic.co/t/azure-functions-log-streams-from-azure-event-hub-cant-be-consumed-by-filebeat/325044 "2023-02-08T16:25:19Z")

</div>

I enable azure module to streams azure platformlog to Elasticsearch. When I collected the logs of azure postgreSQL and aks, everything worked fine, but when I used the same method to collect the logs of azure function, …

---

## [Add human readable field with lookup](https://discuss.elastic.co/t/add-human-readable-field-with-lookup/325032)

<div class="topic-metadata">

**Author:** [@tonelk](https://discuss.elastic.co/u/tonelk)\
**Replies:** 1\
**Last updated:** [February 8, 2023, 3:53pm UTC](https://discuss.elastic.co/t/add-human-readable-field-with-lookup/325032 "2023-02-08T15:53:43Z")

</div>

Hi, I want to add the human readable description of error codes in my data. I've tried this processors: - add\_fields: when: equals: cisco\_code: "106015" fields: cisco\_description: 'Den…

---

## [How to remove long type](https://discuss.elastic.co/t/how-to-remove-long-type/325015)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 11:52am UTC](https://discuss.elastic.co/t/how-to-remove-long-type/325015 "2023-02-08T11:52:56Z")

</div>

Hi Team, I am wanted to remove long data type form the fields.yml file as it is consuming a large disk space. Doing it for metrocbeat and only using system modules so have remove most of the unused fields from fields.ym…

---

## [Process json with multiple keys of same name via filebeat.yml](https://discuss.elastic.co/t/process-json-with-multiple-keys-of-same-name-via-filebeat-yml/325003)

<div class="topic-metadata">

**Author:** [@stranger](https://discuss.elastic.co/u/stranger)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 10:54am UTC](https://discuss.elastic.co/t/process-json-with-multiple-keys-of-same-name-via-filebeat-yml/325003 "2023-02-08T10:54:27Z")

</div>

I am trying to process my json log to extract all the fields. - decode\_json\_fields: fields: \["message"\] target: "" process\_array: false expand\_keys: true overwrite\_keys: false Example of l…

---

## [How to setup ILM for filebeat & metricbeat?](https://discuss.elastic.co/t/how-to-setup-ilm-for-filebeat-metricbeat/322798)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 2\
**Last updated:** [February 8, 2023, 6:17am UTC](https://discuss.elastic.co/t/how-to-setup-ilm-for-filebeat-metricbeat/322798 "2023-02-08T06:17:24Z")

</div>

Hi Everyone. I need to set ILM for some beat services. As you know saving beats docs from the index changed to Datastream in ELK version 8. I could enable index rollup for heartbeat From Stack Management \> Index Lifec…

---

## [How to avoid duplicate data when switching from filebeat's log-input to filestream-input?](https://discuss.elastic.co/t/how-to-avoid-duplicate-data-when-switching-from-filebeats-log-input-to-filestream-input/324878)

<div class="topic-metadata">

**Author:** [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Replies:** 6\
**Last updated:** [February 7, 2023, 6:43pm UTC](https://discuss.elastic.co/t/how-to-avoid-duplicate-data-when-switching-from-filebeats-log-input-to-filestream-input/324878 "2023-02-07T18:43:58Z")

</div>

Hey guys, right now, I'm planning the switch from filebeat's log-input to filestream-input. We have many filebeats running on our numerous servers that are harvesting many log files. We deploy them with an Ansible Play…

---

## [Packetbeat npac version and Defender for Identity](https://discuss.elastic.co/t/packetbeat-npac-version-and-defender-for-identity/323230)

<div class="topic-metadata">

**Author:** [@jaegerschnitzel](https://discuss.elastic.co/u/jaegerschnitzel)\
**Replies:** 8\
**Last updated:** [February 7, 2023, 6:42pm UTC](https://discuss.elastic.co/t/packetbeat-npac-version-and-defender-for-identity/323230 "2023-02-07T18:42:28Z")

</div>

Hi all, we are using Packetbeat for capturing DNS traffic from some of our Windows servers. Defender for Identity is also installed on these servers. Defender for Identity uses npcap OEM 1.00. Packetbeat somehow upda…

---

## [Filebeat locking application logs](https://discuss.elastic.co/t/filebeat-locking-application-logs/324912)

<div class="topic-metadata">

**Author:** [@Anirbaan\_Chowdhury](https://discuss.elastic.co/u/Anirbaan_Chowdhury)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-locking-application-logs/324912 "2023-02-07T14:04:55Z")

</div>

Fillebeat in Windows. I have read topic Filebeat locking files - Elastic Stack / Beats - Discuss the Elastic Stack Hi Experts, Our application (whose logs are harvested by filebeat) repeatedly throws permission denied …

---

## [Metadata missing on startup](https://discuss.elastic.co/t/metadata-missing-on-startup/324886)

<div class="topic-metadata">

**Author:** [@hdost](https://discuss.elastic.co/u/hdost)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 10:33am UTC](https://discuss.elastic.co/t/metadata-missing-on-startup/324886 "2023-02-07T10:33:25Z")

</div>

This question seems to be in a similar vein to a different application, but I have more than just "random" My config is similar to theirs: filebeat.inputs: - type: container paths: - /var/log/con…

---

## [Heartbeat add fild Source IP](https://discuss.elastic.co/t/heartbeat-add-fild-source-ip/324667)

<div class="topic-metadata">

**Author:** [@brunopsitech](https://discuss.elastic.co/u/brunopsitech)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 5:50pm UTC](https://discuss.elastic.co/t/heartbeat-add-fild-source-ip/324667 "2023-02-06T17:50:22Z")

</div>

Would it be possible to add in the options of the monitors an output parameter for a certain IP when performing the ICMP test? It would be used in firewall environments that have 2 or more WANs, so it could be tested whi…

---

## [Winlogbeat - Crash 7.17.8](https://discuss.elastic.co/t/winlogbeat-crash-7-17-8/324816)

<div class="topic-metadata">

**Author:** [@novaksam](https://discuss.elastic.co/u/novaksam)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 5:14pm UTC](https://discuss.elastic.co/t/winlogbeat-crash-7-17-8/324816 "2023-02-06T17:14:23Z")

</div>

I've been having issues with Winlogbeat for a while now, but I figured I'd finally get someone to look at it. The last working version of Winlogbeat I've used that hasn't shown this issue is 7.17.3, but I wasn't able to …

---

## [Monitoring several url and setting schedule](https://discuss.elastic.co/t/monitoring-several-url-and-setting-schedule/324104)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 3\
**Last updated:** [February 6, 2023, 10:30am UTC](https://discuss.elastic.co/t/monitoring-several-url-and-setting-schedule/324104 "2023-02-06T10:30:06Z")

</div>

Hello, I use heartbeat module to monitor http responses, with Elastic v7.17.6. I have to monitor several url. Do I have to use this syntax : heartbeat.monitors: - type: http urls: \["http://url1", "http://url2", "ht…

---

## [Winlogbeat to kafka](https://discuss.elastic.co/t/winlogbeat-to-kafka/324710)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 0\
**Last updated:** [February 4, 2023, 1:00pm UTC](https://discuss.elastic.co/t/winlogbeat-to-kafka/324710 "2023-02-04T13:00:53Z")

</div>

hi everyone, I am trying to send data using wingbeat to Kafka to Logstash to elastic. but the winlogbeat is not shipping any data to kafka topic. when I started the winlogbeat service it created the topic but no data …

---

## [Beats output to logstash using SSL and Cert Errors](https://discuss.elastic.co/t/beats-output-to-logstash-using-ssl-and-cert-errors/324689)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 8:28pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-using-ssl-and-cert-errors/324689 "2023-02-03T20:28:53Z")

</div>

I am testing SSL from 7.x Beats clients to logstash. Logstash is configured for a wildcard cert to my domain, call it \*.acme.com. Connection works fine if Beats is configured to use a FQDN entry in the output, like log…

---

## [Auditbeat : couldn't connect to any of the configured Elasticsearch hosts](https://discuss.elastic.co/t/auditbeat-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/324640)

<div class="topic-metadata">

**Author:** [@rajith\_pathiraja](https://discuss.elastic.co/u/rajith_pathiraja)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 10:46am UTC](https://discuss.elastic.co/t/auditbeat-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/324640 "2023-02-03T10:46:57Z")

</div>

Im configuring ELK SIEM and im unable to run complete " sudo auditbeat -e setup " as im getting following error Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasti…

---

## [Create multiple index str in filebeat and send logs to them with successfully rolover to next index](https://discuss.elastic.co/t/create-multiple-index-str-in-filebeat-and-send-logs-to-them-with-successfully-rolover-to-next-index/324636)

<div class="topic-metadata">

**Author:** [@Ananya](https://discuss.elastic.co/u/Ananya)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 10:18am UTC](https://discuss.elastic.co/t/create-multiple-index-str-in-filebeat-and-send-logs-to-them-with-successfully-rolover-to-next-index/324636 "2023-02-03T10:18:30Z")

</div>

Hello, I am trying to implement ilm policy. I have multiple index str so I create multiple aliases with their respective bootstrapping index to support them and set is\_write\_index to true. The logs flow to the bootstrap…

---

## [How to collect multiline java stack traces from docker container stout](https://discuss.elastic.co/t/how-to-collect-multiline-java-stack-traces-from-docker-container-stout/324497)

<div class="topic-metadata">

**Author:** [@JocelynFloresz](https://discuss.elastic.co/u/JocelynFloresz)\
**Replies:** 2\
**Last updated:** [February 3, 2023, 3:21am UTC](https://discuss.elastic.co/t/how-to-collect-multiline-java-stack-traces-from-docker-container-stout/324497 "2023-02-03T03:21:09Z")

</div>

Commonly I can use the below pattern to collect logs from multiline. multiline.pattern: '^\[\[:space:\]\]+(at|\\.{3})\[\[:space:\]\]+\\b|^Caused by:' multiline.negate: false multiline.match: after But in my use case,…

---

## [Filebeat multiline - how to tell filebeat when a message ends while parsing Microsoft Defender ATP logs](https://discuss.elastic.co/t/filebeat-multiline-how-to-tell-filebeat-when-a-message-ends-while-parsing-microsoft-defender-atp-logs/324564)

<div class="topic-metadata">

**Author:** [@Sal\_C](https://discuss.elastic.co/u/Sal_C)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 4:18pm UTC](https://discuss.elastic.co/t/filebeat-multiline-how-to-tell-filebeat-when-a-message-ends-while-parsing-microsoft-defender-atp-logs/324564 "2023-02-02T16:18:13Z")

</div>

Hello, I'm trying to integrate Microsoft Defender ATP with Graylog, and I'm pulling in events using the Microsoft API. The output is spread across multiple lines, so I'm using the multiline function within filebeat to p…

---

## [Tags written to .monitoring-es-8-mb by metricbeat is not searchable](https://discuss.elastic.co/t/tags-written-to-monitoring-es-8-mb-by-metricbeat-is-not-searchable/324562)

<div class="topic-metadata">

**Author:** [@Abhi\_Abhishek](https://discuss.elastic.co/u/Abhi_Abhishek)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 4:07pm UTC](https://discuss.elastic.co/t/tags-written-to-monitoring-es-8-mb-by-metricbeat-is-not-searchable/324562 "2023-02-02T16:07:07Z")

</div>

The tags added through processors in metricbeat.yml writes to monitoring-es-8-mb index which shows tags field when searched with only index name. Metricbeat.yml config processors: - add\_tags: tags: \[Earth\] …

---

## [Winlogbeat read Windows Event id 4732 but not Member Security ID?](https://discuss.elastic.co/t/winlogbeat-read-windows-event-id-4732-but-not-member-security-id/322759)

<div class="topic-metadata">

**Author:** [@hansbrah7](https://discuss.elastic.co/u/hansbrah7)\
**Replies:** 2\
**Last updated:** [February 2, 2023, 3:06pm UTC](https://discuss.elastic.co/t/winlogbeat-read-windows-event-id-4732-but-not-member-security-id/322759 "2023-02-02T15:06:32Z")

</div>

We have noticed that the Winlogbeat agent will read and ship up the event id 4732 (User added to local Security Group) but we noticed that it is missing the Member Security ID (which is the user that is getting added). …

---

## [HTTP error 401 in : 401 Unauthorized","service.name":"metricbeat"](https://discuss.elastic.co/t/http-error-401-in-401-unauthorized-service-name-metricbeat/323923)

<div class="topic-metadata">

**Author:** [@bagafoot](https://discuss.elastic.co/u/bagafoot)\
**Replies:** 8\
**Last updated:** [February 2, 2023, 9:59am UTC](https://discuss.elastic.co/t/http-error-401-in-401-unauthorized-service-name-metricbeat/323923 "2023-02-02T09:59:55Z")

</div>

The metric beats service status showing that connection estabilished to elasticsearch but I get this errors metricbeats.yml path: ${path.config}/modules.d/\*.yml reload.enabled: false setup.template.settings: inde…

---

## [Filebeat still shows old version even if service is a later version](https://discuss.elastic.co/t/filebeat-still-shows-old-version-even-if-service-is-a-later-version/322410)

<div class="topic-metadata">

**Author:** [@Azkiel19](https://discuss.elastic.co/u/Azkiel19)\
**Replies:** 5\
**Last updated:** [February 2, 2023, 5:56am UTC](https://discuss.elastic.co/t/filebeat-still-shows-old-version-even-if-service-is-a-later-version/322410 "2023-02-02T05:56:32Z")

</div>

Hi, Checking into Elastic - the beat version still shows as 5.6.5 even though the service we have running is already at 6.8.13 and confirmed it is still sending logs real time. Already tried restarting the filebeat ser…

---

## [Filebeat output logtash - wrong value in "host" field seen in elasticsearch Index](https://discuss.elastic.co/t/filebeat-output-logtash-wrong-value-in-host-field-seen-in-elasticsearch-index/324493)

<div class="topic-metadata">

**Author:** [@madhu\_sudan](https://discuss.elastic.co/u/madhu_sudan)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 2:31am UTC](https://discuss.elastic.co/t/filebeat-output-logtash-wrong-value-in-host-field-seen-in-elasticsearch-index/324493 "2023-02-02T02:31:08Z")

</div>

I see value for "host" field as the container IP, but was expecting the hostname of the docker host. host 192.168.254.4 Also added processors: add\_docker\_metadata: ~

---

## [Filebeat log fails to publish events](https://discuss.elastic.co/t/filebeat-log-fails-to-publish-events/324127)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 9\
**Last updated:** [February 1, 2023, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-log-fails-to-publish-events/324127 "2023-02-01T14:23:15Z")

</div>

Hello, Our ELK cluster has been stable for a long time, but recently we have started seeing the following error in the filebeat log: ERROR logstash/async.go:256 Failed to publish events caused by: write tcp xx.xx.x…

---

## [Monitor systemd service from dockerized Metricbeat](https://discuss.elastic.co/t/monitor-systemd-service-from-dockerized-metricbeat/324395)

<div class="topic-metadata">

**Author:** [@Yungxin\_Shin](https://discuss.elastic.co/u/Yungxin_Shin)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 8:11am UTC](https://discuss.elastic.co/t/monitor-systemd-service-from-dockerized-metricbeat/324395 "2023-02-01T08:11:34Z")

</div>

I wonder if there's a way to stream the metrics (such as cpu, mem usage, diskio etc.) of systemd services to Elasticsearch through Metricbeat. To monitor the services running on the host, we could use the system module. …

---

## [Nginx Logs Can't Be Parsed Because Symlinks](https://discuss.elastic.co/t/nginx-logs-cant-be-parsed-because-symlinks/323958)

<div class="topic-metadata">

**Author:** [@Christian\_Jacobs](https://discuss.elastic.co/u/Christian_Jacobs)\
**Replies:** 7\
**Last updated:** [January 31, 2023, 8:42pm UTC](https://discuss.elastic.co/t/nginx-logs-cant-be-parsed-because-symlinks/323958 "2023-01-31T20:42:49Z")

</div>

Currently I have an nginx container that has filebeat running in the background. \[nginx:latest as base\] I have enabled the nginx module with filebeat modules enable nginx, my filebeat.yml has an input defined for the lo…

---

## [Issue about starting beats](https://discuss.elastic.co/t/issue-about-starting-beats/324176)

<div class="topic-metadata">

**Author:** [@chris3](https://discuss.elastic.co/u/chris3)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 7:30am UTC](https://discuss.elastic.co/t/issue-about-starting-beats/324176 "2023-01-31T07:30:35Z")

</div>

Hi All, I was wondering if you can advise on this issue I am getting with starting the beats or if anyone has seen this issue before. I have created a virtual machine on virtual box with an Ubuntu OS. I have tried to s…

---

## [Heartbeat Ping](https://discuss.elastic.co/t/heartbeat-ping/324132)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 5:22am UTC](https://discuss.elastic.co/t/heartbeat-ping/324132 "2023-01-31T05:22:57Z")

</div>

Hi Team, I have installed heartbeat on few VMs to monitor icmp. However, if the agent stops the data stops coming from the node. However, i want to get notified that the host is down. How can i achieve the same? Kindly…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=58)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=60)
