# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=63

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 64

---

## [Metricbeat does not collect memory and disc io statistics of docker containers](https://discuss.elastic.co/t/metricbeat-does-not-collect-memory-and-disc-io-statistics-of-docker-containers/321663)

<div class="topic-metadata">

**Author:** [@Nil\_Jeffoy](https://discuss.elastic.co/u/Nil_Jeffoy)\
**Replies:** 2\
**Last updated:** [December 25, 2022, 7:15pm UTC](https://discuss.elastic.co/t/metricbeat-does-not-collect-memory-and-disc-io-statistics-of-docker-containers/321663 "2022-12-25T19:15:28Z")

</div>

I have installed Metricbeat and enabled Docker and System modules. I can see CPU usage statistics, but there is no Memory and DicsIO data. Also, I can see memory and other data from System Module. But I need Memory an…

---

## [How to only load enabled-module dashboards with \`filebeat setup\`](https://discuss.elastic.co/t/how-to-only-load-enabled-module-dashboards-with-filebeat-setup/321913)

<div class="topic-metadata">

**Author:** [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Replies:** 0\
**Last updated:** [December 23, 2022, 12:50pm UTC](https://discuss.elastic.co/t/how-to-only-load-enabled-module-dashboards-with-filebeat-setup/321913 "2022-12-23T12:50:03Z")

</div>

It seems that the default behavior of filebeat setup --dashboards is to load all dashboards rather than just dashboards for the modules enabled via config or --modules. Is there a way to only have filebeat setup --dashb…

---

## [How to point Filebeat to send data to existing data stream in Elasticsearch?](https://discuss.elastic.co/t/how-to-point-filebeat-to-send-data-to-existing-data-stream-in-elasticsearch/321833)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 0\
**Last updated:** [December 22, 2022, 11:31am UTC](https://discuss.elastic.co/t/how-to-point-filebeat-to-send-data-to-existing-data-stream-in-elasticsearch/321833 "2022-12-22T11:31:42Z")

</div>

Hi, for context, in the current setup I send data from Filebeat to Logstash, then using tags and an output like below I send data to Elasticsearch, where I have an index template with data streams enabled configured: …

---

## [Couchdb module not generating metrics](https://discuss.elastic.co/t/couchdb-module-not-generating-metrics/321048)

<div class="topic-metadata">

**Author:** [@jonnymccullagh](https://discuss.elastic.co/u/jonnymccullagh)\
**Replies:** 10\
**Last updated:** [December 22, 2022, 10:48am UTC](https://discuss.elastic.co/t/couchdb-module-not-generating-metrics/321048 "2022-12-22T10:48:31Z")

</div>

Hi, I'm having trouble getting metrics from CouchDB into ElasticCloud. System metrics are going ok. I have /etc/metricbeat/modules.d/couchdb.yml as follows: - module: couchdb metricsets: \["server"\] period: 10s hos…

---

## [How to ship app logs from multiple pods using filebeat](https://discuss.elastic.co/t/how-to-ship-app-logs-from-multiple-pods-using-filebeat/321800)

<div class="topic-metadata">

**Author:** [@SumitSingh](https://discuss.elastic.co/u/SumitSingh)\
**Replies:** 1\
**Last updated:** [December 21, 2022, 11:20pm UTC](https://discuss.elastic.co/t/how-to-ship-app-logs-from-multiple-pods-using-filebeat/321800 "2022-12-21T23:20:00Z")

</div>

Hi, I have installed a application using helm and it deployed in AKS. This application have multiples pods spread all over the nodes in AKS. Application logs saved at /opt/app-name/service-name/logs folder in containe…

---

## [Filebeat modules ECS 8.0 support plan](https://discuss.elastic.co/t/filebeat-modules-ecs-8-0-support-plan/321797)

<div class="topic-metadata">

**Author:** [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Replies:** 0\
**Last updated:** [December 21, 2022, 9:19pm UTC](https://discuss.elastic.co/t/filebeat-modules-ecs-8-0-support-plan/321797 "2022-12-21T21:19:36Z")

</div>

It appears that all Filebeat modules currently export ECS version 1.12 fields. Running command from beats/x-pack/filebeat/module: $ ggrep -Fr 'ecs.version: 1.12' | wc -l 140 brsolomon ~/dev/3pty/beats/x-pack/file…

---

## [Filebeat is not reading logs](https://discuss.elastic.co/t/filebeat-is-not-reading-logs/321794)

<div class="topic-metadata">

**Author:** [@ant2ne](https://discuss.elastic.co/u/ant2ne)\
**Replies:** 2\
**Last updated:** [December 21, 2022, 8:43pm UTC](https://discuss.elastic.co/t/filebeat-is-not-reading-logs/321794 "2022-12-21T20:43:15Z")

</div>

root@ub2204elk:/etc/elasticsearch# grep -v "#" elasticsearch.yml |uniq path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch network.host: localhost xpack.security.enabled: true xpack.security.enrollme…

---

## [Log floods: error salvaging message / handle is invalid](https://discuss.elastic.co/t/log-floods-error-salvaging-message-handle-is-invalid/319974)

<div class="topic-metadata">

**Author:** [@psears](https://discuss.elastic.co/u/psears)\
**Replies:** 2\
**Last updated:** [December 21, 2022, 8:03pm UTC](https://discuss.elastic.co/t/log-floods-error-salvaging-message-handle-is-invalid/319974 "2022-12-21T20:03:04Z")

</div>

Winlogbeat 8.4.3, set to log about itself to eventlog logging.level: info logging.selectors: \["\*"\] logging.to\_eventlog: true logging.metrics.period: 5m Every now and then on startup, winlogbeat will go nuts on a host a…

---

## [Override logging.level in a Fleet managed Filebeat?](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688)

<div class="topic-metadata">

**Author:** [@Akash\_Deep](https://discuss.elastic.co/u/Akash_Deep)\
**Replies:** 4\
**Last updated:** [December 21, 2022, 6:50am UTC](https://discuss.elastic.co/t/override-logging-level-in-a-fleet-managed-filebeat/321688 "2022-12-21T06:50:56Z")

</div>

I have a Fleet managed Elastic Agent running as a service which on systemctl start elastic-agent starts-up filebeat with some flags(as seen in the picture). HOW DO I OVERRIDE THE LOGGING.LEVEL IN A MANAGED SETUP? I'…

---

## [Packetbeat unable to monitor mysql traffic](https://discuss.elastic.co/t/packetbeat-unable-to-monitor-mysql-traffic/321690)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [December 20, 2022, 8:40pm UTC](https://discuss.elastic.co/t/packetbeat-unable-to-monitor-mysql-traffic/321690 "2022-12-20T20:40:13Z")

</div>

I'm trying out packetbeat to monitor events for the mysql protocol. Packetbeat seems to be able to detect packets on destination.port: 3306 which is the default mysql port as shown in this screenshot here: But packet…

---

## [\[filebeat 8.5.3\] extracting log\_level from message with dissect processor, ignoring right padding modifier](https://discuss.elastic.co/t/filebeat-8-5-3-extracting-log-level-from-message-with-dissect-processor-ignoring-right-padding-modifier/321683)

<div class="topic-metadata">

**Author:** [@vincen](https://discuss.elastic.co/u/vincen)\
**Replies:** 1\
**Last updated:** [December 20, 2022, 7:40pm UTC](https://discuss.elastic.co/t/filebeat-8-5-3-extracting-log-level-from-message-with-dissect-processor-ignoring-right-padding-modifier/321683 "2022-12-20T19:40:40Z")

</div>

I am trying to run filebeats on log files for a web application, and the messages have padding after the log level. I:DEBUG \[http-nio-8443-exec-45\] RequestCasTicketValidator 20 Dec 2022 11:00:17.221: Loading custom par…

---

## [Filebeat Incompatibility with Opensearch](https://discuss.elastic.co/t/filebeat-incompatibility-with-opensearch/320757)

<div class="topic-metadata">

**Author:** [@Anish\_Mittal](https://discuss.elastic.co/u/Anish_Mittal)\
**Replies:** 3\
**Last updated:** [December 20, 2022, 6:19pm UTC](https://discuss.elastic.co/t/filebeat-incompatibility-with-opensearch/320757 "2022-12-20T18:19:09Z")

</div>

I have spent almost 4 days on filebeat and opensearch. I have used Filebeat \[7.0.0, 8.5.2, 6.0.0\] and Opensearch 2.4.0. But getting the error: "pipeline/output.go:100 Failed to connect to backoff(elasticsearch(http://lo…

---

## [Filebeat processor - what is this ~ good for?](https://discuss.elastic.co/t/filebeat-processor-what-is-this-good-for/321616)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [December 20, 2022, 4:24pm UTC](https://discuss.elastic.co/t/filebeat-processor-what-is-this-good-for/321616 "2022-12-20T16:24:14Z")

</div>

Hi there, in a 7.17.4. processor block in filebeat I found this statement; ... processors: add\_docker\_metadata: ~ ... What does this sing ~ stand for or do? Thanks!

---

## [Getting K8s annotations in Filebeat logs](https://discuss.elastic.co/t/getting-k8s-annotations-in-filebeat-logs/321671)

<div class="topic-metadata">

**Author:** [@RudyStolds](https://discuss.elastic.co/u/RudyStolds)\
**Replies:** 0\
**Last updated:** [December 20, 2022, 4:06pm UTC](https://discuss.elastic.co/t/getting-k8s-annotations-in-filebeat-logs/321671 "2022-12-20T16:06:20Z")

</div>

Hi, I'm trying to get additional annotations from my K8s deployment into Elasticsearch. I'm currently on filebeat 7.18.8. My filebeat imputs in the filebeat.yml file look like the code below filebeat.inputs: - type: …

---

## ["stdout only" logs not captured in filebeat while display file with kubectl logs pod](https://discuss.elastic.co/t/stdout-only-logs-not-captured-in-filebeat-while-display-file-with-kubectl-logs-pod/321645)

<div class="topic-metadata">

**Author:** [@Humayun\_Manzer](https://discuss.elastic.co/u/Humayun_Manzer)\
**Replies:** 0\
**Last updated:** [December 20, 2022, 12:38pm UTC](https://discuss.elastic.co/t/stdout-only-logs-not-captured-in-filebeat-while-display-file-with-kubectl-logs-pod/321645 "2022-12-20T12:38:51Z")

</div>

This is the filebeats config I am using via helm charts filebeatConfig: filebeat.yml: | filebeat.inputs: - type: container paths: - /var/log/containers/\*.log processors: …

---

## [Filebeat exclude\_files regex](https://discuss.elastic.co/t/filebeat-exclude-files-regex/321206)

<div class="topic-metadata">

**Author:** [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Replies:** 3\
**Last updated:** [December 20, 2022, 9:49am UTC](https://discuss.elastic.co/t/filebeat-exclude-files-regex/321206 "2022-12-20T09:49:15Z")

</div>

I want to exclude all access logs files from the filebeat except 2 service access logs. I'm using the regex but getting error and filebeat start is failing exclude\_files: \['\\/var\\/log\\/xxx\\/.\*(?!.\*(xxx)).\*\\/.\*(?!.\*(xxx)…

---

## [Filebeat consuming too much CPU](https://discuss.elastic.co/t/filebeat-consuming-too-much-cpu/321497)

<div class="topic-metadata">

**Author:** [@Priya\_Vardhan](https://discuss.elastic.co/u/Priya_Vardhan)\
**Replies:** 15\
**Last updated:** [December 20, 2022, 8:30am UTC](https://discuss.elastic.co/t/filebeat-consuming-too-much-cpu/321497 "2022-12-20T08:30:20Z")

</div>

Hi, Installed filebeat using docker in 3 servers. In each of the servers, CPU reaching to 99% the moment filebeat starts harvesting. Please suggest how we can control CPU usage

---

## [Exclude\_lines in filebeat does not work?](https://discuss.elastic.co/t/exclude-lines-in-filebeat-does-not-work/321535)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 8\
**Last updated:** [December 19, 2022, 11:22am UTC](https://discuss.elastic.co/t/exclude-lines-in-filebeat-does-not-work/321535 "2022-12-19T11:22:44Z")

</div>

Hi, I have log records like: 2022-12-12T07:07:07.007 \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* bla bla bla To exclude these line I use exclude\_lines: \['^\\n$','^\\\*+$'\] in my filebeat configuration. But anyway I get empty…

---

## [Filebeat AWS module ignore older](https://discuss.elastic.co/t/filebeat-aws-module-ignore-older/321391)

<div class="topic-metadata">

**Author:** [@infernalz2](https://discuss.elastic.co/u/infernalz2)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 9:30am UTC](https://discuss.elastic.co/t/filebeat-aws-module-ignore-older/321391 "2022-12-16T09:30:39Z")

</div>

Hello, I am using Filebeat 7.16.2 with AWS module to download VPC flow logs to elastics from S3. Is there a way to make ignore older files/log. Everytime filebeat gets restarted it writes to elastic everything from the …

---

## [The \`network.protocol: http\` returns nothing for packetbeat](https://discuss.elastic.co/t/the-network-protocol-http-returns-nothing-for-packetbeat/321471)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [December 18, 2022, 5:57am UTC](https://discuss.elastic.co/t/the-network-protocol-http-returns-nothing-for-packetbeat/321471 "2022-12-18T05:57:21Z")

</div>

I installed packetbeat on a server and have it publish event data to elasticsearch version 8.5 and kibana version 8.5. It seems to be working. I set up a simple Rest API on the server with packetbeat and made a few htt…

---

## [Detect ftp commands in ELK](https://discuss.elastic.co/t/detect-ftp-commands-in-elk/321461)

<div class="topic-metadata">

**Author:** [@raph3401](https://discuss.elastic.co/u/raph3401)\
**Replies:** 0\
**Last updated:** [December 17, 2022, 4:57pm UTC](https://discuss.elastic.co/t/detect-ftp-commands-in-elk/321461 "2022-12-17T16:57:19Z")

</div>

Hi all, I'm working on a school lab on the following scenario: a "hacker" got access to my ubuntu server (22.04), installed vsftpd and downloaded some files. I can see the ftp authentication and the traffic on port 21 …

---

## [\[Filebeat\] Bug with multiple aws-cloudwatch logs using log\_group\_name\_prefix](https://discuss.elastic.co/t/filebeat-bug-with-multiple-aws-cloudwatch-logs-using-log-group-name-prefix/319683)

<div class="topic-metadata">

**Author:** [@EDzhelyov](https://discuss.elastic.co/u/EDzhelyov)\
**Replies:** 8\
**Last updated:** [December 16, 2022, 10:09pm UTC](https://discuss.elastic.co/t/filebeat-bug-with-multiple-aws-cloudwatch-logs-using-log-group-name-prefix/319683 "2022-12-16T22:09:12Z")

</div>

I have a lot of running AWS Lambdas and I'm trying to fetch their logs using Filebeat's aws-cloudwatch input type. I'm using the start\_position: beginning in order to backfill the logs when the filebeat starts. When I s…

---

## [Understanding the difference between client and source in packetbeat](https://discuss.elastic.co/t/understanding-the-difference-between-client-and-source-in-packetbeat/321430)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 8:08pm UTC](https://discuss.elastic.co/t/understanding-the-difference-between-client-and-source-in-packetbeat/321430 "2022-12-16T20:08:10Z")

</div>

I'm new to packetbeat and I just got it up and working. When I queried for some data, I noticed situations where the client.geo.country\_iso\_code field did not the same information as the source.geo.country\_iso\_code fie…

---

## [Heartbeat monitor for multiple pods inside 1 deployment](https://discuss.elastic.co/t/heartbeat-monitor-for-multiple-pods-inside-1-deployment/321310)

<div class="topic-metadata">

**Author:** [@OlLap](https://discuss.elastic.co/u/OlLap)\
**Replies:** 1\
**Last updated:** [December 16, 2022, 4:47pm UTC](https://discuss.elastic.co/t/heartbeat-monitor-for-multiple-pods-inside-1-deployment/321310 "2022-12-16T16:47:18Z")

</div>

Hello, Is is possible with heartbeat configuration monitor all pods (replicas) inside one deployment together to see on Kibana UI something like "3/3 are UP" or "1/3 are UP"? My current configuration creates new entry …

---

## [Multiple configurations to be enabled for filebeat](https://discuss.elastic.co/t/multiple-configurations-to-be-enabled-for-filebeat/321303)

<div class="topic-metadata">

**Author:** [@tejal\_kubde](https://discuss.elastic.co/u/tejal_kubde)\
**Replies:** 2\
**Last updated:** [December 16, 2022, 2:36pm UTC](https://discuss.elastic.co/t/multiple-configurations-to-be-enabled-for-filebeat/321303 "2022-12-16T14:36:42Z")

</div>

Hi, I have a multiple types of log files which requires different configurations such as includes for one type of file and exclude for other file type. I generally used to do my configuration in filebeat.yml, which requ…

---

## [Filebeat service failed](https://discuss.elastic.co/t/filebeat-service-failed/321361)

<div class="topic-metadata">

**Author:** [@Mohaiminul\_Islam](https://discuss.elastic.co/u/Mohaiminul_Islam)\
**Replies:** 2\
**Last updated:** [December 16, 2022, 11:22am UTC](https://discuss.elastic.co/t/filebeat-service-failed/321361 "2022-12-16T11:22:37Z")

</div>

Hi, I am running the elk stack in EC2 instance. I have installed the filebeat and enable nginx and system. But my filebeat is not starting. Here is the error × filebeat.service - Filebeat sends log files to Logstash or…

---

## [Filter for specific folder activity](https://discuss.elastic.co/t/filter-for-specific-folder-activity/321395)

<div class="topic-metadata">

**Author:** [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 10:07am UTC](https://discuss.elastic.co/t/filter-for-specific-folder-activity/321395 "2022-12-16T10:07:18Z")

</div>

Hello I wanted to know if it's possible to add a filter in winlogbeat to only have the activity of a specific folder and all it's files inside it, and itself by the way if the folder is renamed, deleted or something else…

---

## [Filebeat Failed to connect to backoff(async(tcp:logstash:5044](https://discuss.elastic.co/t/filebeat-failed-to-connect-to-backoff-async-tcp5044/321390)

<div class="topic-metadata">

**Author:** [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 9:27am UTC](https://discuss.elastic.co/t/filebeat-failed-to-connect-to-backoff-async-tcp5044/321390 "2022-12-16T09:27:25Z")

</div>

I have set two VMs, one Ubuntu where I've installed ELK and another CentOS where I've installed Filebeat. I want to forward CentOS logs to ELK via filebeat. I have configured all my files correctly (I think) but when I r…

---

## [Elastic Agent System integration not collecting Windows Event Log](https://discuss.elastic.co/t/elastic-agent-system-integration-not-collecting-windows-event-log/320344)

<div class="topic-metadata">

**Author:** [@username11](https://discuss.elastic.co/u/username11)\
**Replies:** 1\
**Last updated:** [December 16, 2022, 7:32am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-not-collecting-windows-event-log/320344 "2022-12-16T07:32:08Z")

</div>

Hi. I am testing Elastic Agent (v8.0.1) + Fleet (v.8.5.2), and I'm currently having a problem with collecting Windows Event Log on a test machine. I have set up the agent and it does connect to Fleet and Elasticsearch, a…

---

## [Filebeat reading logs repeatedly](https://discuss.elastic.co/t/filebeat-reading-logs-repeatedly/321364)

<div class="topic-metadata">

**Author:** [@GodSlayer\_Inferno](https://discuss.elastic.co/u/GodSlayer_Inferno)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 4:01am UTC](https://discuss.elastic.co/t/filebeat-reading-logs-repeatedly/321364 "2022-12-16T04:01:37Z")

</div>

I am deploying filebeat on a Linux server to manage logs on a webdrive mounted. Filebeat read the logs and send the content to logstash repeatedly, generating duplicated content. The frequency of each line appearing is a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=62)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=64)
