# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=61

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 62

---

## [Broken documentation links in Metricbeat modules.d yml files](https://discuss.elastic.co/t/broken-documentation-links-in-metricbeat-modules-d-yml-files/323347)

<div class="topic-metadata">

**Author:** [@AndyPC](https://discuss.elastic.co/u/AndyPC)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 1:27am UTC](https://discuss.elastic.co/t/broken-documentation-links-in-metricbeat-modules-d-yml-files/323347 "2023-01-18T01:27:27Z")

</div>

Posting here per instructions to do so before filing a bug on github: All of the modules yml files in metricbeat/modules.d (version 8.6.0) have broken documentation links in the top-of file comment. The links in the do…

---

## [Auditbeat data not being indexed](https://discuss.elastic.co/t/auditbeat-data-not-being-indexed/323294)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 2\
**Last updated:** [January 17, 2023, 1:34pm UTC](https://discuss.elastic.co/t/auditbeat-data-not-being-indexed/323294 "2023-01-17T13:34:12Z")

</div>

Hello, I can ingest the logs if I set up the output.destination to Elasticsearch but when routing the logs via Logstash I am unable to receive/view them at Elasticsearch (through Kibana) THe following the setup with Lo…

---

## [Adding new sink to Beats](https://discuss.elastic.co/t/adding-new-sink-to-beats/323295)

<div class="topic-metadata">

**Author:** [@ag-ramachandran](https://discuss.elastic.co/u/ag-ramachandran)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 8:56am UTC](https://discuss.elastic.co/t/adding-new-sink-to-beats/323295 "2023-01-17T08:56:41Z")

</div>

Support for additional datastores: Azure Data Explorer We have requirements for integration of filebeat to a timeseries database called Azure Data Explorer. Roughly ran through the existing modules, this would be along …

---

## [Filestream parsers multiline pattern parse all file in one hit althoutgh I test my pattern in The Go Playground](https://discuss.elastic.co/t/filestream-parsers-multiline-pattern-parse-all-file-in-one-hit-althoutgh-i-test-my-pattern-in-the-go-playground/323179)

<div class="topic-metadata">

**Author:** [@fouadelnahal](https://discuss.elastic.co/u/fouadelnahal)\
**Replies:** 5\
**Last updated:** [January 17, 2023, 8:30am UTC](https://discuss.elastic.co/t/filestream-parsers-multiline-pattern-parse-all-file-in-one-hit-althoutgh-i-test-my-pattern-in-the-go-playground/323179 "2023-01-17T08:30:10Z")

</div>

Here is the parser in filestream input parsers: - multiline: type: pattern pattern: '^DEBUG|INFO|ERROR' negate: true match: after # flush\_pattern: '^\\s\*$' and this is the log…

---

## [Winlogbeat Alert for certain users in Windows PC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506)

<div class="topic-metadata">

**Author:** [@amis349](https://discuss.elastic.co/u/amis349)\
**Replies:** 4\
**Last updated:** [January 17, 2023, 3:24am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506 "2023-01-17T03:24:11Z")

</div>

Okay I have looked around and found different iterations of a solution. However I am running into a road block, the winlogbeats (below) are not dropping the events for that targetusername or even the event ID. All logs a…

---

## [Filebeat's add\_docker\_metadata stop working after container restart](https://discuss.elastic.co/t/filebeats-add-docker-metadata-stop-working-after-container-restart/322358)

<div class="topic-metadata">

**Author:** [@kowy](https://discuss.elastic.co/u/kowy)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 12:22pm UTC](https://discuss.elastic.co/t/filebeats-add-docker-metadata-stop-working-after-container-restart/322358 "2023-01-16T12:22:00Z")

</div>

We use filebeat from Graylog to collect logs from services run in docker-compose. Filebeat is not started as a linux service, but executed as this command: sudo /usr/share/filebeat/bin/filebeat --path.home /usr/share/f…

---

## [Elastic Logging Plugin for Docker: "error creating client config: A hosts flag is required"](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-error-creating-client-config-a-hosts-flag-is-required/323202)

<div class="topic-metadata">

**Author:** [@kthy](https://discuss.elastic.co/u/kthy)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 11:12am UTC](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-error-creating-client-config-a-hosts-flag-is-required/323202 "2023-01-16T11:12:18Z")

</div>

This question is about the Elastic Logging Plugin for Docker , which doesn't have it's own category on the Elastic forums. Sad. I have tried creating a docker container with the Elastic logging plugin, but I get an erro…

---

## [Filebeat support required](https://discuss.elastic.co/t/filebeat-support-required/323181)

<div class="topic-metadata">

**Author:** [@Sagar\_Naik](https://discuss.elastic.co/u/Sagar_Naik)\
**Replies:** 13\
**Last updated:** [January 15, 2023, 4:35am UTC](https://discuss.elastic.co/t/filebeat-support-required/323181 "2023-01-15T04:35:53Z")

</div>

getting error : Jan 14 21:30:07 ndc3vmappelk05 filebeat\[2374\]: 2023-01-14T21:30:07.888+0530 ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://10.94.241.145:5043)): dial tcp 10.94…

---

## [Elastic Logging Plugin for Docker: is the connection encrypted?](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-is-the-connection-encrypted/323177)

<div class="topic-metadata">

**Author:** [@kthy](https://discuss.elastic.co/u/kthy)\
**Replies:** 1\
**Last updated:** [January 14, 2023, 4:54pm UTC](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-is-the-connection-encrypted/323177 "2023-01-14T16:54:51Z")

</div>

This question is about the Elastic Logging Plugin for Docker, which doesn't have it's own category on the Elastic forums as far as I can see, but since it is based on Beats I'm posting here. Apologies if misplaced. My q…

---

## [Docs discrepancy in 'Change the index name' vs filebeat.reference.yml](https://discuss.elastic.co/t/docs-discrepancy-in-change-the-index-name-vs-filebeat-reference-yml/323152)

<div class="topic-metadata">

**Author:** [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 3:58pm UTC](https://discuss.elastic.co/t/docs-discrepancy-in-change-the-index-name-vs-filebeat-reference-yml/323152 "2023-01-13T15:58:49Z")

</div>

From Change the index name | Filebeat Reference \[8.6\] | Elastic output.elasticsearch.index: "customname-%{\[agent.version\]}" setup.template.name: "customname" setup.template.pattern: "customname-%{\[agent.version\]}" From…

---

## [\[BUG\] Bug in logs related to Kafka connection](https://discuss.elastic.co/t/bug-bug-in-logs-related-to-kafka-connection/269625)

<div class="topic-metadata">

**Author:** [@dacamposol](https://discuss.elastic.co/u/dacamposol)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 3:10pm UTC](https://discuss.elastic.co/t/bug-bug-in-logs-related-to-kafka-connection/269625 "2023-01-13T15:10:02Z")

</div>

Good afternoon everyone, I think that I have found a bug in the logs of Filebeat, version 7.12.0. I have a Kafka machine in a datacenter, let's call it Datacenter A, and I setup the Filebeat in another datacenter, in t…

---

## [Parse Elasticsearch json logs in filebeat](https://discuss.elastic.co/t/parse-elasticsearch-json-logs-in-filebeat/322533)

<div class="topic-metadata">

**Author:** [@qwinkler](https://discuss.elastic.co/u/qwinkler)\
**Replies:** 6\
**Last updated:** [January 13, 2023, 2:20pm UTC](https://discuss.elastic.co/t/parse-elasticsearch-json-logs-in-filebeat/322533 "2023-01-13T14:20:29Z")

</div>

Hello. I want to properly collect Elasticsearch logs. I have the following architecture. On the Linux node, I have Docker installed. I configured the Journald logging driver using official documentation (Journald loggin…

---

## [Last\_terminated\_reason metric is not collected](https://discuss.elastic.co/t/last-terminated-reason-metric-is-not-collected/323101)

<div class="topic-metadata">

**Author:** [@hyungsun\_lim](https://discuss.elastic.co/u/hyungsun_lim)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 8:03am UTC](https://discuss.elastic.co/t/last-terminated-reason-metric-is-not-collected/323101 "2023-01-13T08:03:47Z")

</div>

I want to collect 'kubernetes.container.status.last\_terminated\_reason' metric in document (Kubernetes fields | Metricbeat Reference \[8.6\] | Elastic) So i use metricbeat(v7.10.1) to collect k8s event data. metricbeat.co…

---

## [Event creation and processing times differ](https://discuss.elastic.co/t/event-creation-and-processing-times-differ/323051)

<div class="topic-metadata">

**Author:** [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 5:45pm UTC](https://discuss.elastic.co/t/event-creation-and-processing-times-differ/323051 "2023-01-12T17:45:27Z")

</div>

Hi, let's talk about the config first: elk 7.17.5 (8 cpu, 20 ram, 2.5T disk space) and another host with filebeat 7.17.8 with zeek and suricata module enabled. I am using suricata and zeek as ids, i noticed that suricat…

---

## [Filebeat ERROR x509: certificate signed by unknown authority](https://discuss.elastic.co/t/filebeat-error-x509-certificate-signed-by-unknown-authority/322861)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 24\
**Last updated:** [January 12, 2023, 4:38pm UTC](https://discuss.elastic.co/t/filebeat-error-x509-certificate-signed-by-unknown-authority/322861 "2023-01-12T16:38:15Z")

</div>

Hi! in my filebeat.yaml I configured output.elasticsearch: section like this tyoutput.elasticsearch: # Array of hosts to connect to. hosts: \["10.142.77.174:9200"\] # Protocol - either \`http\` (default) or \`https\`…

---

## [Drop\_event when no value in both TargetUserName and Workstation fields (event id 4776)](https://discuss.elastic.co/t/drop-event-when-no-value-in-both-targetusername-and-workstation-fields-event-id-4776/322715)

<div class="topic-metadata">

**Author:** [@yankaiqian](https://discuss.elastic.co/u/yankaiqian)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 12:18pm UTC](https://discuss.elastic.co/t/drop-event-when-no-value-in-both-targetusername-and-workstation-fields-event-id-4776/322715 "2023-01-12T12:18:28Z")

</div>

winlogbeat-7.17.0 I tried to drop the events that id is 4776 and no value in both TargetUsername and Workstation, but it doesn't work, may I know how to write the condition part and get it work? Here is the part of the…

---

## [Valores en blanco desde el modulo Netflow](https://discuss.elastic.co/t/valores-en-blanco-desde-el-modulo-netflow/323012)

<div class="topic-metadata">

**Author:** [@ZekeJ](https://discuss.elastic.co/u/ZekeJ)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 10:27am UTC](https://discuss.elastic.co/t/valores-en-blanco-desde-el-modulo-netflow/323012 "2023-01-12T10:27:37Z")

</div>

Hola, aquí un novato de elastic stack. Estoy intentando monitorizar los interfaces de mi palo alto a través del modulo NetFlow. En principio parece que llegan logs, pero todos los campos relativos a NetFlow ( por ejempl…

---

## [Netflow Module sends null fields](https://discuss.elastic.co/t/netflow-module-sends-null-fields/323011)

<div class="topic-metadata">

**Author:** [@ZekeJ](https://discuss.elastic.co/u/ZekeJ)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 10:25am UTC](https://discuss.elastic.co/t/netflow-module-sends-null-fields/323011 "2023-01-12T10:25:32Z")

</div>

Hello, this is an elastic stack newbie. I am trying to monitor the interfaces of my Palo Alto through the NetFlow module. At first it seems that logs arrive, but all the fields related to NetFlow (for example the netflo…

---

## [Configure multiple logs location on filebeat](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 10\
**Last updated:** [January 12, 2023, 1:36am UTC](https://discuss.elastic.co/t/configure-multiple-logs-location-on-filebeat/322971 "2023-01-12T01:36:53Z")

</div>

Hi! let's say I need to send logs from a few directories to elasticsearch, like this: /var/log/logfolder1/server.log /var/log/logfolder2/server.log /var/log/logfolder3/server.log /var/log/logfolder4/server.log wha…

---

## [Patch management](https://discuss.elastic.co/t/patch-management/322887)

<div class="topic-metadata">

**Author:** [@calm\_silence](https://discuss.elastic.co/u/calm_silence)\
**Replies:** 1\
**Last updated:** [January 11, 2023, 11:30pm UTC](https://discuss.elastic.co/t/patch-management/322887 "2023-01-11T23:30:44Z")

</div>

Can we do patch management of multiple servers running in any cloud Using ELK stack? if yes then how?

---

## [Filebeat is unable to create custom index](https://discuss.elastic.co/t/filebeat-is-unable-to-create-custom-index/322755)

<div class="topic-metadata">

**Author:** [@AdityaKhajuria](https://discuss.elastic.co/u/AdityaKhajuria)\
**Replies:** 11\
**Last updated:** [January 11, 2023, 11:19am UTC](https://discuss.elastic.co/t/filebeat-is-unable-to-create-custom-index/322755 "2023-01-11T11:19:55Z")

</div>

Hi team, Im trying to create custom index with Filebeat and ive read the official docs and disabled the ilm (setup.ilm.enabled: false) and also configured the template name and pattern but now index template is getting …

---

## [Filebeat Warnings in Office 365 Logs](https://discuss.elastic.co/t/filebeat-warnings-in-office-365-logs/322841)

<div class="topic-metadata">

**Author:** [@Rohit\_Kumbhar](https://discuss.elastic.co/u/Rohit_Kumbhar)\
**Replies:** 1\
**Last updated:** [January 10, 2023, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-warnings-in-office-365-logs/322841 "2023-01-10T15:40:37Z")

</div>

Hi Elastic Team, I am running Multiple O365 Tenants in filebeat but some of the tenants giving following warning Got error 500 The input stream is not a valid binary format. The starting contents (in bytes) are: 22-68…

---

## [/hostfs/sys/fs/cgroup/io.stat: input does not match format](https://discuss.elastic.co/t/hostfs-sys-fs-cgroup-io-stat-input-does-not-match-format/322837)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 12:48pm UTC](https://discuss.elastic.co/t/hostfs-sys-fs-cgroup-io-stat-input-does-not-match-format/322837 "2023-01-10T12:48:02Z")

</div>

Hi, I am getting constantly the following errormessage in my metricbeat logs: \[elastic\_agent.metricbeat\]\[error\] error getting cgroup stats for V2: error fetching stats for controller io: error fetching IO stats: error …

---

## [Filebeat daemonset in Kubernetes is slow (or fails) to harvest logs from multiple pods](https://discuss.elastic.co/t/filebeat-daemonset-in-kubernetes-is-slow-or-fails-to-harvest-logs-from-multiple-pods/322634)

<div class="topic-metadata">

**Author:** [@melkamar](https://discuss.elastic.co/u/melkamar)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 12:08pm UTC](https://discuss.elastic.co/t/filebeat-daemonset-in-kubernetes-is-slow-or-fails-to-harvest-logs-from-multiple-pods/322634 "2023-01-10T12:08:58Z")

</div>

Hi! After a full day of pulling my hair I’m giving up and want to ask for help here :pray: I have a Kubernetes cluster where I am running a Filebeat daemonset. I noticed that the logs from some of the pods go missing so…

---

## [Monitor Filebeat read/write throughput](https://discuss.elastic.co/t/monitor-filebeat-read-write-throughput/322805)

<div class="topic-metadata">

**Author:** [@anando](https://discuss.elastic.co/u/anando)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 8:53am UTC](https://discuss.elastic.co/t/monitor-filebeat-read-write-throughput/322805 "2023-01-10T08:53:19Z")

</div>

Hi all, I am new to Filebeat. In our environment, we have deployed an Elasticsearch cluster using ECK on the k8s cluster. k8s cluster has 1 master node and 3 worker nodes. ELK cluster is deployed with 1 coordinating n…

---

## [Filebeat and updating existing docs](https://discuss.elastic.co/t/filebeat-and-updating-existing-docs/320781)

<div class="topic-metadata">

**Author:** [@Marcin\_Frankiewicz](https://discuss.elastic.co/u/Marcin_Frankiewicz)\
**Replies:** 30\
**Last updated:** [January 9, 2023, 12:57pm UTC](https://discuss.elastic.co/t/filebeat-and-updating-existing-docs/320781 "2023-01-09T12:57:04Z")

</div>

Hi, I'm trying to update documents when they exists.. it is possible with filebeat? Logstash has that functionality... output { elasticsearch { doc\_as\_upsert =\> true document\_id =\> "%{fingerprint}" The fing…

---

## [Filebeat autodiscover filestream input have error logs with ID already exists](https://discuss.elastic.co/t/filebeat-autodiscover-filestream-input-have-error-logs-with-id-already-exists/322716)

<div class="topic-metadata">

**Author:** [@andry.zhu](https://discuss.elastic.co/u/andry.zhu)\
**Replies:** 0\
**Last updated:** [January 9, 2023, 9:35am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-filestream-input-have-error-logs-with-id-already-exists/322716 "2023-01-09T09:35:24Z")

</div>

HI! I am running a filebeat version 8.5.3 daemonset in kubernetes cluster. I has configured autodiscover filestream input each namespace. it have error logs with ID already exists are often reported during run time. My …

---

## [Filebeat: active (running) then code=exited, status=2 or code=exited, status=1](https://discuss.elastic.co/t/filebeat-active-running-then-code-exited-status-2-or-code-exited-status-1/322233)

<div class="topic-metadata">

**Author:** [@Anthony\_Allen](https://discuss.elastic.co/u/Anthony_Allen)\
**Replies:** 11\
**Last updated:** [January 7, 2023, 1:49am UTC](https://discuss.elastic.co/t/filebeat-active-running-then-code-exited-status-2-or-code-exited-status-1/322233 "2023-01-07T01:49:49Z")

</div>

I am running Elasticsearch/Kibana 7.14. on Ubuntu 22.04 on the backend of an Apache reverse proxy. Filebeat is on another Ubuntu 22.04 on the backend of the same reverse proxy. Other beats are on the Filebeat's machine. …

---

## [Not able to use Filebeat-OSS AWS-S3 input](https://discuss.elastic.co/t/not-able-to-use-filebeat-oss-aws-s3-input/322595)

<div class="topic-metadata">

**Author:** [@Gaurav\_yadav1](https://discuss.elastic.co/u/Gaurav_yadav1)\
**Replies:** 1\
**Last updated:** [January 7, 2023, 2:04am UTC](https://discuss.elastic.co/t/not-able-to-use-filebeat-oss-aws-s3-input/322595 "2023-01-07T02:04:59Z")

</div>

I am getting - Exiting: Failed to start crawler: starting input failed: error while initializing input: Error creating input. No such input type exist: 'aws-s3' What is the difference between Filebeat and Filebeat-OSS? …

---

## [Filebeat CrashLoopBackOff](https://discuss.elastic.co/t/filebeat-crashloopbackoff/320830)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 8\
**Last updated:** [January 6, 2023, 7:32pm UTC](https://discuss.elastic.co/t/filebeat-crashloopbackoff/320830 "2023-01-06T19:32:57Z")

</div>

After installing filebeat from the new Helm 8.5 in our cluster k8s, 5 of the pods are stuck in CrashLoopBackOff: {"log.level":"error","@timestamp":"2022-12-08T21:13:19.258Z","log.origin":{"file.name":"instance/beat.go",…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=60)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=62)
