# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=62

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 63

---

## [Bug in Cisco Module for Filebeat 7.17.8](https://discuss.elastic.co/t/bug-in-cisco-module-for-filebeat-7-17-8/322633)

<div class="topic-metadata">

**Author:** [@mmh13](https://discuss.elastic.co/u/mmh13)\
**Replies:** 0\
**Last updated:** [January 6, 2023, 5:12pm UTC](https://discuss.elastic.co/t/bug-in-cisco-module-for-filebeat-7-17-8/322633 "2023-01-06T17:12:28Z")

</div>

Hey, When trying to run Filebeat 7.17.8 with the Cisco module enabled we found that new amp events were not being ingested. The var.first\_interval parameter was respected and initially populated the index with amp even…

---

## [Filebeat Kubernetes autodiscover with post "processor" specific field with another filebeat module](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-with-post-processor-specific-field-with-another-filebeat-module/322503)

<div class="topic-metadata">

**Author:** [@kgfathur](https://discuss.elastic.co/u/kgfathur)\
**Replies:** 7\
**Last updated:** [January 6, 2023, 4:03pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-with-post-processor-specific-field-with-another-filebeat-module/322503 "2023-01-06T16:03:09Z")

</div>

I have setup filbeat on Kubernetes (ECK) with sample and guide from docs: Role Based Access Control for Beats | Elastic Cloud on Kubernetes \[2.5\] Run Filebeat on Kubernetes | Filebeat Reference \[8.5\] Version: ECK: …

---

## [Error dialing x509: certificate signed by unknown authority](https://discuss.elastic.co/t/error-dialing-x509-certificate-signed-by-unknown-authority/322258)

<div class="topic-metadata">

**Author:** [@ntmxglrtayl03](https://discuss.elastic.co/u/ntmxglrtayl03)\
**Replies:** 1\
**Last updated:** [January 6, 2023, 11:18am UTC](https://discuss.elastic.co/t/error-dialing-x509-certificate-signed-by-unknown-authority/322258 "2023-01-06T11:18:08Z")

</div>

I configured them but still got this error Error dialing x509: certificate signed by unknown authority

---

## [Metricbeat AWS Billing Module does not combine Group By options](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497)

<div class="topic-metadata">

**Author:** [@Thomas\_Cate](https://discuss.elastic.co/u/Thomas_Cate)\
**Replies:** 3\
**Last updated:** [January 6, 2023, 1:28am UTC](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497 "2023-01-06T01:28:31Z")

</div>

It looks like the Metricbeat AWS Billing module takes in an arbitrary number of Cost Explorer Group by Dimensions, and then iterates over them individually to generate documents. Ideally it should allow you to pair up d…

---

## [How to optimize config-files of filebeat for many different environments?](https://discuss.elastic.co/t/how-to-optimize-config-files-of-filebeat-for-many-different-environments/322577)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 1\
**Last updated:** [January 5, 2023, 9:57pm UTC](https://discuss.elastic.co/t/how-to-optimize-config-files-of-filebeat-for-many-different-environments/322577 "2023-01-05T21:57:35Z")

</div>

We have 3 different config files for 3 envs on the project. Each env is a separate cluster. All config files are similar to each other but the one difference - field.env, which is related to environment, accordingly. …

---

## [Deploying Winlogbeat with Octopus Deploy](https://discuss.elastic.co/t/deploying-winlogbeat-with-octopus-deploy/322565)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 0\
**Last updated:** [January 5, 2023, 4:08pm UTC](https://discuss.elastic.co/t/deploying-winlogbeat-with-octopus-deploy/322565 "2023-01-05T16:08:07Z")

</div>

Looking for some guidance on using Octopus Deploy to deploy Winlogbeat. The approach I've been trying is to deploy a wrapper Powershell script, which would then invoke the install-service-winlogbeat.ps1 script, which I …

---

## [Kubernetes unit tests failing on arm64 and other non-amd64 platforms](https://discuss.elastic.co/t/kubernetes-unit-tests-failing-on-arm64-and-other-non-amd64-platforms/320909)

<div class="topic-metadata">

**Author:** [@Jonathan\_Albrecht](https://discuss.elastic.co/u/Jonathan_Albrecht)\
**Replies:** 1\
**Last updated:** [January 5, 2023, 2:05pm UTC](https://discuss.elastic.co/t/kubernetes-unit-tests-failing-on-arm64-and-other-non-amd64-platforms/320909 "2023-01-05T14:05:11Z")

</div>

I'd like to ask about some test failures and then open an issue if it makes sense. I'm running the metricbeat unit tests on arm64 and s390x and I'm getting these test failures: FAIL github.com/elastic/beats/v7/metri…

---

## [Filebeat not shipping logs to Elasticsearch service on K8S](https://discuss.elastic.co/t/filebeat-not-shipping-logs-to-elasticsearch-service-on-k8s/322227)

<div class="topic-metadata">

**Author:** [@Max9998](https://discuss.elastic.co/u/Max9998)\
**Replies:** 7\
**Last updated:** [January 5, 2023, 3:28am UTC](https://discuss.elastic.co/t/filebeat-not-shipping-logs-to-elasticsearch-service-on-k8s/322227 "2023-01-05T03:28:23Z")

</div>

Hello, I have deployed Filebeat using the Helm chart on K8s as a daemonset. We would like to use Filebeat to send Kubelet, Containerd, and docker logs to Elasticsearch Service. The config yaml is below: filebeat.inputs…

---

## [Issue with Log4J @timestamp format](https://discuss.elastic.co/t/issue-with-log4j-timestamp-format/322088)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 1\
**Last updated:** [January 4, 2023, 7:49am UTC](https://discuss.elastic.co/t/issue-with-log4j-timestamp-format/322088 "2023-01-04T07:49:17Z")

</div>

Hello there! I'm trying to ship log files from Filebeat into Logstash but I got an issue with @timestamp format Here is one example of line Filebeat read from the file : {"@timestamp":"2022-12-28T01:03:16,911Z","hostN…

---

## [Usage of filestream](https://discuss.elastic.co/t/usage-of-filestream/320009)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 7\
**Last updated:** [January 4, 2023, 6:24am UTC](https://discuss.elastic.co/t/usage-of-filestream/320009 "2023-01-04T06:24:54Z")

</div>

Hello, I have a few question about the topic filestream and it's difference to the input log. Do I only need an id when using multiple filebeat inputs in a single yml or always? Currently im not using any ids but im …

---

## [Filebeat service wont start even after 'test output' and 'setup -e' shows positive results](https://discuss.elastic.co/t/filebeat-service-wont-start-even-after-test-output-and-setup-e-shows-positive-results/322416)

<div class="topic-metadata">

**Author:** [@Hari\_Krishnan1](https://discuss.elastic.co/u/Hari_Krishnan1)\
**Replies:** 5\
**Last updated:** [January 4, 2023, 6:03am UTC](https://discuss.elastic.co/t/filebeat-service-wont-start-even-after-test-output-and-setup-e-shows-positive-results/322416 "2023-01-04T06:03:59Z")

</div>

Hello community! , I am quite new to filebeat and logstash and I am looking to append logs from a node application into kibana using filebeat and logstash. I have tried the following steps from the documentation provid…

---

## [Custom logs ingest: how?](https://discuss.elastic.co/t/custom-logs-ingest-how/321928)

<div class="topic-metadata">

**Author:** [@Johannnnnn](https://discuss.elastic.co/u/Johannnnnn)\
**Replies:** 4\
**Last updated:** [January 3, 2023, 3:40pm UTC](https://discuss.elastic.co/t/custom-logs-ingest-how/321928 "2023-01-03T15:40:57Z")

</div>

I have a very simple logfile in json format that I want to send to elasticsearch The Filebeat quick setup page is not clear on how to make this work. This is an excerpt of the file to input. This is all the complexity …

---

## [Cannot search on field \[event.original\] since it is not indexed](https://discuss.elastic.co/t/cannot-search-on-field-event-original-since-it-is-not-indexed/322381)

<div class="topic-metadata">

**Author:** [@NS\_Midhun](https://discuss.elastic.co/u/NS_Midhun)\
**Replies:** 0\
**Last updated:** [January 3, 2023, 2:25pm UTC](https://discuss.elastic.co/t/cannot-search-on-field-event-original-since-it-is-not-indexed/322381 "2023-01-03T14:25:24Z")

</div>

I have 7.17v version, i see the apache server logs in filebeat kibana dashboard. But it gives the message with event.original instead of message. when i try to write a lucene query to search all GET req for example, it d…

---

## [Filebeat: "memory leak" via filebeat.autodiscover and \>\>200.000 goroutines](https://discuss.elastic.co/t/filebeat-memory-leak-via-filebeat-autodiscover-and-200-000-goroutines/322082)

<div class="topic-metadata">

**Author:** [@HarryTuttle](https://discuss.elastic.co/u/HarryTuttle)\
**Replies:** 5\
**Last updated:** [January 3, 2023, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-memory-leak-via-filebeat-autodiscover-and-200-000-goroutines/322082 "2023-01-03T13:00:25Z")

</div>

Hi, we use filebeat (8.5.3) to scrape logs from kubernetes (1.24) nodes and send them to logstash (8.5.3). We have been doing this since filebeat 6.x and have adjusted the configs to the best of our knowledge during the…

---

## [Certificate error occurred when installing the fleet server](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710)

<div class="topic-metadata">

**Author:** [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Replies:** 46\
**Last updated:** [December 23, 2022, 3:12am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710 "2022-12-23T03:12:45Z")

</div>

My Elasticsearch and Kibana versions are 8.5.0. When installing the fly, certificate errors are reported all the time. My elasticsearch has set three nodes, and the certificate generated by using the （elasticsearch-certu…

---

## [Year is missing from original log file, log events are stored as current year](https://discuss.elastic.co/t/year-is-missing-from-original-log-file-log-events-are-stored-as-current-year/322300)

<div class="topic-metadata">

**Author:** [@r123](https://discuss.elastic.co/u/r123)\
**Replies:** 0\
**Last updated:** [January 2, 2023, 11:11am UTC](https://discuss.elastic.co/t/year-is-missing-from-original-log-file-log-events-are-stored-as-current-year/322300 "2023-01-02T11:11:27Z")

</div>

Hi there, I have been testing the ELK-Stack recently. The ELK-Stack runs on a standalone server (elk-host01) After setting everything up, I have installed the elastic-agent on another server (srv-docker01). The logs ar…

---

## [Collect all logs from a Windows host with Winlogbeat](https://discuss.elastic.co/t/collect-all-logs-from-a-windows-host-with-winlogbeat/322278)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [January 2, 2023, 3:40am UTC](https://discuss.elastic.co/t/collect-all-logs-from-a-windows-host-with-winlogbeat/322278 "2023-01-02T03:40:20Z")

</div>

Hi, Does anyone know if there is a default config to collect everything available from a Windows host? We are currently running configs to collect specific logs such as System, Security; however we would like to collec…

---

## [Windows Mass Beats Deployment](https://discuss.elastic.co/t/windows-mass-beats-deployment/322055)

<div class="topic-metadata">

**Author:** [@Nathan.Arnall](https://discuss.elastic.co/u/Nathan.Arnall)\
**Replies:** 3\
**Last updated:** [December 31, 2022, 12:37am UTC](https://discuss.elastic.co/t/windows-mass-beats-deployment/322055 "2022-12-31T00:37:08Z")

</div>

Powershell script for deploying beats modules. Can be used with group policy. Hopefully this can be of use to anyone else starting out with the ELK stack. $beats = "Metricbeat", "Heartbeat", "Auditbeat", "Winlogbeat", …

---

## [From Filebeat to Logstash (and next to Elasticsearch) - pipeline processing](https://discuss.elastic.co/t/from-filebeat-to-logstash-and-next-to-elasticsearch-pipeline-processing/322171)

<div class="topic-metadata">

**Author:** [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Replies:** 2\
**Last updated:** [December 30, 2022, 2:35pm UTC](https://discuss.elastic.co/t/from-filebeat-to-logstash-and-next-to-elasticsearch-pipeline-processing/322171 "2022-12-30T14:35:42Z")

</div>

Hi, I'm having trouble getting data to transfer correctly from Filebeat to Logstash (then to Elasticsearch). When I configure in filebeat.yml output directly to Elasticsearch everything is ok. However, when I configur…

---

## [Filebeat netflow port 2055 bound to host](https://discuss.elastic.co/t/filebeat-netflow-port-2055-bound-to-host/322101)

<div class="topic-metadata">

**Author:** [@shaikmuzakkir](https://discuss.elastic.co/u/shaikmuzakkir)\
**Replies:** 2\
**Last updated:** [December 30, 2022, 7:16am UTC](https://discuss.elastic.co/t/filebeat-netflow-port-2055-bound-to-host/322101 "2022-12-30T07:16:45Z")

</div>

Hi We are using the filebeat image - docker.elastic.co/beats/filebeat:8.4.3 and see the netflow port 2055 is bound to the host. We are using the below config for netflow as input: - type: netflow max\_message…

---

## [How can I send custom logs in a specific location to filebeat running inside docker](https://discuss.elastic.co/t/how-can-i-send-custom-logs-in-a-specific-location-to-filebeat-running-inside-docker/322106)

<div class="topic-metadata">

**Author:** [@Raja\_Muneer](https://discuss.elastic.co/u/Raja_Muneer)\
**Replies:** 18\
**Last updated:** [December 29, 2022, 4:29pm UTC](https://discuss.elastic.co/t/how-can-i-send-custom-logs-in-a-specific-location-to-filebeat-running-inside-docker/322106 "2022-12-29T16:29:56Z")

</div>

I am new to filebeat and elk. I am trying to send custom logs using filebeat to Elasticsearch directly.Both the elk stack and filebeat are running inside docker containers.. The custom logs are in the folder home/usernam…

---

## [Filebeat in k8s pod cannot read log file : No such file or directory](https://discuss.elastic.co/t/filebeat-in-k8s-pod-cannot-read-log-file-no-such-file-or-directory/322074)

<div class="topic-metadata">

**Author:** [@cat-rat](https://discuss.elastic.co/u/cat-rat)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 9:00am UTC](https://discuss.elastic.co/t/filebeat-in-k8s-pod-cannot-read-log-file-no-such-file-or-directory/322074 "2022-12-29T09:00:04Z")

</div>

\--- apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: kube-system labels: k8s-app: filebeat data: filebeat.yml: |- filebeat.inputs: - type: container fields\_under\_root: t…

---

## [Query on Azure Module Authentication for Metricbeat](https://discuss.elastic.co/t/query-on-azure-module-authentication-for-metricbeat/322023)

<div class="topic-metadata">

**Author:** [@vin89](https://discuss.elastic.co/u/vin89)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 8:36am UTC](https://discuss.elastic.co/t/query-on-azure-module-authentication-for-metricbeat/322023 "2022-12-29T08:36:02Z")

</div>

We are planning to use azure module for metricbeat for monitoring and alerting in our organization, so as per documentation we could see it uses client\_id and client\_secret for authentication. Do we have any other ways t…

---

## [Failures not displayed in kibana](https://discuss.elastic.co/t/failures-not-displayed-in-kibana/322120)

<div class="topic-metadata">

**Author:** [@ant2ne](https://discuss.elastic.co/u/ant2ne)\
**Replies:** 1\
**Last updated:** [December 28, 2022, 7:39pm UTC](https://discuss.elastic.co/t/failures-not-displayed-in-kibana/322120 "2022-12-28T19:39:01Z")

</div>

this is probably a user error. But I don't know how to google this one. cat tcp.yml |grep -v "#" |uniq id: ssh-status name: ssh-status check enabled: true hosts: \["192.168.1.139:22", "192.168.1.96:22", "8.8.8.8…

---

## [Filebeat inconsistent with date-based index name when input type is "container"](https://discuss.elastic.co/t/filebeat-inconsistent-with-date-based-index-name-when-input-type-is-container/322050)

<div class="topic-metadata">

**Author:** [@GaijinSystems](https://discuss.elastic.co/u/GaijinSystems)\
**Replies:** 3\
**Last updated:** [December 28, 2022, 7:12pm UTC](https://discuss.elastic.co/t/filebeat-inconsistent-with-date-based-index-name-when-input-type-is-container/322050 "2022-12-28T19:12:24Z")

</div>

Hello, all. I was wondering if anyone has ever stumbled across this and if there are any workarounds (I've been bashing my head against it for entirely too long now...). I have multiple servers using filebeat to ship l…

---

## [Exiting: Failed to start crawler: creating module reloader failed:](https://discuss.elastic.co/t/exiting-failed-to-start-crawler-creating-module-reloader-failed/321604)

<div class="topic-metadata">

**Author:** [@ant2ne](https://discuss.elastic.co/u/ant2ne)\
**Replies:** 9\
**Last updated:** [December 28, 2022, 4:37pm UTC](https://discuss.elastic.co/t/exiting-failed-to-start-crawler-creating-module-reloader-failed/321604 "2022-12-28T16:37:42Z")

</div>

using: https://www.elastic.co/guide/en/elastic-stack/current/installing-elastic-stack.html Versions on ubuntu 22.04. /usr/share/logstash/bin/logstash -V Using bundled JDK: /usr/share/logstash/jdk logstash 8.5.3 /usr…

---

## [Beats instance detected Click 'Set up monitoring' below to start monitoring this instance](https://discuss.elastic.co/t/beats-instance-detected-click-set-up-monitoring-below-to-start-monitoring-this-instance/322008)

<div class="topic-metadata">

**Author:** [@ant2ne](https://discuss.elastic.co/u/ant2ne)\
**Replies:** 7\
**Last updated:** [December 28, 2022, 4:27pm UTC](https://discuss.elastic.co/t/beats-instance-detected-click-set-up-monitoring-below-to-start-monitoring-this-instance/322008 "2022-12-28T16:27:41Z")

</div>

All services are running. I log into 5601, click the drop down hamburger | Management | Stack Monitoring But there is no 'Set up monitoring' to click on. root@ub2204elk:/etc# cat metricbeat/metricbeat.yml | grep -v …

---

## [Iptables events not being published in elasticsearch](https://discuss.elastic.co/t/iptables-events-not-being-published-in-elasticsearch/320994)

<div class="topic-metadata">

**Author:** [@jasongil](https://discuss.elastic.co/u/jasongil)\
**Replies:** 3\
**Last updated:** [December 28, 2022, 4:02am UTC](https://discuss.elastic.co/t/iptables-events-not-being-published-in-elasticsearch/320994 "2022-12-28T04:02:25Z")

</div>

Beginner / intermediate Elastic user here. I have filebeat configured to listen on port 9001/UDP for iptables events that are sent to it via syslogd by my firewall. This has worked fine for years. I recently noticed th…

---

## [Painless script to enrich data in an index GPO GUID to Name](https://discuss.elastic.co/t/painless-script-to-enrich-data-in-an-index-gpo-guid-to-name/322011)

<div class="topic-metadata">

**Author:** [@welch27330](https://discuss.elastic.co/u/welch27330)\
**Replies:** 0\
**Last updated:** [December 26, 2022, 9:00pm UTC](https://discuss.elastic.co/t/painless-script-to-enrich-data-in-an-index-gpo-guid-to-name/322011 "2022-12-26T21:00:55Z")

</div>

When Winlogbeat ingest data from a domain controller it uses the GUID from GPO. I wanted to see if there was a way to create a new field within the index that would translate the GUID to the actual GPO name. I've looked …

---

## [Default ILM creating issues](https://discuss.elastic.co/t/default-ilm-creating-issues/321882)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 1\
**Last updated:** [December 26, 2022, 5:52pm UTC](https://discuss.elastic.co/t/default-ilm-creating-issues/321882 "2022-12-26T17:52:20Z")

</div>

Hi Team, I am using vmetricbeat and heartbeat to collect data from multiple devices. I want to setup ILM for automatic index cleaning as well. However, both creates a default policy and are not allowing to use other ILM…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=61)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=63)
