# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=64

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 65

---

## [Packet Beats for DNS logs](https://discuss.elastic.co/t/packet-beats-for-dns-logs/321236)

<div class="topic-metadata">

**Author:** [@jrpayne30506](https://discuss.elastic.co/u/jrpayne30506)\
**Replies:** 5\
**Last updated:** [December 16, 2022, 12:32am UTC](https://discuss.elastic.co/t/packet-beats-for-dns-logs/321236 "2022-12-16T00:32:22Z")

</div>

I have set up a Graylog server in order to send my DNS logs to and installed Packetbeat on the Windows DNS server. In the instructions I found for configuring the yml file, it said to use either the username and password…

---

## [Filebeat index ILM error](https://discuss.elastic.co/t/filebeat-index-ilm-error/321320)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 0\
**Last updated:** [December 15, 2022, 3:01pm UTC](https://discuss.elastic.co/t/filebeat-index-ilm-error/321320 "2022-12-15T15:01:12Z")

</div>

Blockquote Hi Team , We are getting below error in elasticsearch ILM error : Blockquote illegal\_argument\_exception: index.lifecycle.rollover\_alias \[filebeat-7.17.1\] does not point to index \[filebeat-7.17.1-o365-…

---

## [Unable to use the replace filter on filebeat.yml](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305)

<div class="topic-metadata">

**Author:** [@maviles](https://discuss.elastic.co/u/maviles)\
**Replies:** 4\
**Last updated:** [December 15, 2022, 5:44pm UTC](https://discuss.elastic.co/t/unable-to-use-the-replace-filter-on-filebeat-yml/321305 "2022-12-15T17:44:26Z")

</div>

I cannot replace the value of a field using the "replace" processor on filebeat.yml. The service is running but the field returns a null value. See the configuration below: replace: fields: - field: "decoded.cef.sev…

---

## [Heartbeat issue : Bad Gateway: couldn't connect to any of the configured Elasticsearch hosts](https://discuss.elastic.co/t/heartbeat-issue-bad-gateway-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/321270)

<div class="topic-metadata">

**Author:** [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Replies:** 3\
**Last updated:** [December 15, 2022, 3:14pm UTC](https://discuss.elastic.co/t/heartbeat-issue-bad-gateway-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/321270 "2022-12-15T15:14:28Z")

</div>

Hello Experts, I am having issue to connect Heartbeat to Elasticsearch instance (Cloud). Background: I have a Linux server, Heartbeat Version 7.5.0 is running on it and sending Data to Elasticsearch instance (Cloud). …

---

## [Grok Pattern](https://discuss.elastic.co/t/grok-pattern/321273)

<div class="topic-metadata">

**Author:** [@imdroid](https://discuss.elastic.co/u/imdroid)\
**Replies:** 0\
**Last updated:** [December 15, 2022, 8:33am UTC](https://discuss.elastic.co/t/grok-pattern/321273 "2022-12-15T08:33:10Z")

</div>

Hello, I'm trying to configure an ingest pipeline for my apache tomcat logs, need some help in generating a grok pattern for the below stack trace. \< 2022-12-15 06:24:37,468 \[DiscoveryClient-2\] ERROR \[/\] com.netflix.d…

---

## [\--ca-sha256 not working for Elastic Agent enrollment; error reported: "fail to enroll: fail to execute request to fleet-server: x509: certificate signed by unknown authority"](https://discuss.elastic.co/t/ca-sha256-not-working-for-elastic-agent-enrollment-error-reported-fail-to-enroll-fail-to-execute-request-to-fleet-server-x509-certificate-signed-by-unknown-authority/320270)

<div class="topic-metadata">

**Author:** [@username11](https://discuss.elastic.co/u/username11)\
**Replies:** 3\
**Last updated:** [December 15, 2022, 12:54am UTC](https://discuss.elastic.co/t/ca-sha256-not-working-for-elastic-agent-enrollment-error-reported-fail-to-enroll-fail-to-execute-request-to-fleet-server-x509-certificate-signed-by-unknown-authority/320270 "2022-12-15T00:54:18Z")

</div>

Hi. I am currently working on deploying Fleet + Elastic Agent in a test-ish environment. I've had success in enrolling the agents into Fleet as follows: sudo ./elastic-agent install --url=https://fleet1.local:8220 --enr…

---

## [Suricata filebeat logs not real time](https://discuss.elastic.co/t/suricata-filebeat-logs-not-real-time/321045)

<div class="topic-metadata">

**Author:** [@Adilla\_Rhiskani](https://discuss.elastic.co/u/Adilla_Rhiskani)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 2:57pm UTC](https://discuss.elastic.co/t/suricata-filebeat-logs-not-real-time/321045 "2022-12-12T14:57:00Z")

</div>

I have setup new cluster elasticsearch for IDS using suricata , I have set JVM for ingest, master, data01, data02 each 2GB. but when I start file beat I got this error {"log.level":"info","@timestamp":"2022-12-12T14:50:…

---

## [IIS module under filebeat not populating fields in discover](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242)

<div class="topic-metadata">

**Author:** [@Priya\_Vardhan](https://discuss.elastic.co/u/Priya_Vardhan)\
**Replies:** 7\
**Last updated:** [December 14, 2022, 11:22pm UTC](https://discuss.elastic.co/t/iis-module-under-filebeat-not-populating-fields-in-discover/321242 "2022-12-14T23:22:40Z")

</div>

Hi All, I have enabled IIS module under filebeat after providing the log path for both access and error. I can see the IIS fields getting loaded in filebeat index, but it is not showing in discover. The data is not av…

---

## [Metricbeats reported version mismatch](https://discuss.elastic.co/t/metricbeats-reported-version-mismatch/321071)

<div class="topic-metadata">

**Author:** [@serge1](https://discuss.elastic.co/u/serge1)\
**Replies:** 6\
**Last updated:** [December 14, 2022, 5:17pm UTC](https://discuss.elastic.co/t/metricbeats-reported-version-mismatch/321071 "2022-12-14T17:17:00Z")

</div>

Hello! I'm installing beats v. 8.5.1 on my machines. When I query installed version with /var/lib/metricbeat/metricbeat version, it reports itself as 8.5.1. However in Humio where I ship the metrics, Agent version is po…

---

## [Filebeat Docker - Elasticsearch Host Issue](https://discuss.elastic.co/t/filebeat-docker-elasticsearch-host-issue/320083)

<div class="topic-metadata">

**Author:** [@mwsprotte](https://discuss.elastic.co/u/mwsprotte)\
**Replies:** 6\
**Last updated:** [December 14, 2022, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-docker-elasticsearch-host-issue/320083 "2022-12-14T15:18:04Z")

</div>

Hello Everyone! I'm trying to run Filebeat in a Docker Container folowing this documentation: https://www.elastic.co/guide/en/beats/filebeat/current/running-on-docker.html#\_run\_the\_filebeat\_setup but in the second step, …

---

## [Parse array in Json log file with Filebeat 7.7.1](https://discuss.elastic.co/t/parse-array-in-json-log-file-with-filebeat-7-7-1/320736)

<div class="topic-metadata">

**Author:** [@roshann](https://discuss.elastic.co/u/roshann)\
**Replies:** 2\
**Last updated:** [December 14, 2022, 12:12pm UTC](https://discuss.elastic.co/t/parse-array-in-json-log-file-with-filebeat-7-7-1/320736 "2022-12-14T12:12:17Z")

</div>

Hi, I have a json log file as below: { "Format": "IDEA0", "ID": "1c5ae2e1-bf16-43d6-9233-5865f83ad180", "DetectTime": "2022-12-03T11:17:23.589015+00:00", "EventTime": "2022-12-03T11:17:23.589020+00:00", "Category": \["A…

---

## [The maxiunm fields support in auditbeat](https://discuss.elastic.co/t/the-maxiunm-fields-support-in-auditbeat/321205)

<div class="topic-metadata">

**Author:** [@masonlu2014](https://discuss.elastic.co/u/masonlu2014)\
**Replies:** 0\
**Last updated:** [December 14, 2022, 10:23am UTC](https://discuss.elastic.co/t/the-maxiunm-fields-support-in-auditbeat/321205 "2022-12-14T10:23:48Z")

</div>

hello team, may i know what the biggest length can be support in auditbeat ? as i tested, it looks like auditbeat truncated the fields vaule here when it long enough for example, when i enter a super long fake curl co…

---

## [Elastic Agent ignores the Agent Binary Download location setting](https://discuss.elastic.co/t/elastic-agent-ignores-the-agent-binary-download-location-setting/320276)

<div class="topic-metadata">

**Author:** [@username11](https://discuss.elastic.co/u/username11)\
**Replies:** 4\
**Last updated:** [December 14, 2022, 6:34am UTC](https://discuss.elastic.co/t/elastic-agent-ignores-the-agent-binary-download-location-setting/320276 "2022-12-14T06:34:19Z")

</div>

Hi. This is basically a repeat of this thread, which did not get any replies. Right now I am testing the Elastic Agents in a test environment, which does not have direct internet access (and neither will my live environm…

---

## [Forgot how to get geoip enrichment to work for packetbeat](https://discuss.elastic.co/t/forgot-how-to-get-geoip-enrichment-to-work-for-packetbeat/321170)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [December 14, 2022, 12:15am UTC](https://discuss.elastic.co/t/forgot-how-to-get-geoip-enrichment-to-work-for-packetbeat/321170 "2022-12-14T00:15:33Z")

</div>

I got geoip enrichment working with packetbeat a few days ago in a test set up with elasticsearch 8.5 and kibana 8.5. But I tore down the servers this morning so that I can repeat the installation. For some reason, th…

---

## [Cannot see any host in elastic security and also cannot see any data from auditbeat or winlogbeat](https://discuss.elastic.co/t/cannot-see-any-host-in-elastic-security-and-also-cannot-see-any-data-from-auditbeat-or-winlogbeat/320983)

<div class="topic-metadata">

**Author:** [@Mohaiminul\_Islam](https://discuss.elastic.co/u/Mohaiminul_Islam)\
**Replies:** 13\
**Last updated:** [December 13, 2022, 9:03pm UTC](https://discuss.elastic.co/t/cannot-see-any-host-in-elastic-security-and-also-cannot-see-any-data-from-auditbeat-or-winlogbeat/320983 "2022-12-13T21:03:26Z")

</div>

I am trying to create a home lab. I have setup everything in ubuntu machine in vmware. The auditbeat is also in this machine. But I cannot see any data from auditbeat or even the host itself in security overview. Then I …

---

## [Nginx module on k8s - access and error from the same path?](https://discuss.elastic.co/t/nginx-module-on-k8s-access-and-error-from-the-same-path/321126)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 0\
**Last updated:** [December 13, 2022, 12:57pm UTC](https://discuss.elastic.co/t/nginx-module-on-k8s-access-and-error-from-the-same-path/321126 "2022-12-13T12:57:27Z")

</div>

Hey, So I have a micro service with nginx, I am using filebeat nginx module to read the logs: filebeat.autodiscover: providers: - type: kubernetes hints.enabled: true tem…

---

## [Filebeat internal logs are getting repeated](https://discuss.elastic.co/t/filebeat-internal-logs-are-getting-repeated/321115)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 0\
**Last updated:** [December 13, 2022, 11:25am UTC](https://discuss.elastic.co/t/filebeat-internal-logs-are-getting-repeated/321115 "2022-12-13T11:25:48Z")

</div>

Filebeat internal logs are repeating which is unwanted. 2022-12-13T11:03:51.516Z INFO log/input.go:157 Configured paths: \[/var/log/pods/7d447f4fea175a79a4bdac6296034497a897f2b94391cc73f7dadc4b5b806624/\*-json.log /var/lo…

---

## [Source.geo.country\_name field is missing](https://discuss.elastic.co/t/source-geo-country-name-field-is-missing/321113)

<div class="topic-metadata">

**Author:** [@udaypatel07](https://discuss.elastic.co/u/udaypatel07)\
**Replies:** 0\
**Last updated:** [December 13, 2022, 11:18am UTC](https://discuss.elastic.co/t/source-geo-country-name-field-is-missing/321113 "2022-12-13T11:18:20Z")

</div>

Hi, I have integrated Sonicwall Firewall with ELK for the last 6 months, and I'm receiving logs correctly but suddenly I'm facing a problem in one of the Sonicwall module fields which are the source.geo.country\_name & de…

---

## [Filebeat sends no logs to Kafka](https://discuss.elastic.co/t/filebeat-sends-no-logs-to-kafka/320968)

<div class="topic-metadata">

**Author:** [@nota](https://discuss.elastic.co/u/nota)\
**Replies:** 2\
**Last updated:** [December 13, 2022, 10:41am UTC](https://discuss.elastic.co/t/filebeat-sends-no-logs-to-kafka/320968 "2022-12-13T10:41:44Z")

</div>

Running Filebeat 8.5.3 on Ubuntu 20.04. I am trying to send some logs to Kafka using FIlebeat. This is my filebeat.yml filebeat.inputs: - type: filestream id: jenkinsfilestream enabled: true paths: - "/var/log…

---

## [Filebeat duplicate logs](https://discuss.elastic.co/t/filebeat-duplicate-logs/321032)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 7\
**Last updated:** [December 13, 2022, 8:46am UTC](https://discuss.elastic.co/t/filebeat-duplicate-logs/321032 "2022-12-13T08:46:57Z")

</div>

Hello everyone, for prevent the duplication data that can be received from Filebeat I used this Logstash filtration fingerprint { source =\> "message" target =\> "\[@metadata\]\[fingerprint\]" method =\> "SHA1" key =\> "ke…

---

## [Co.elastic.metrics/raw to "simpler" format](https://discuss.elastic.co/t/co-elastic-metrics-raw-to-simpler-format/321009)

<div class="topic-metadata">

**Author:** [@firecow](https://discuss.elastic.co/u/firecow)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 8:49am UTC](https://discuss.elastic.co/t/co-elastic-metrics-raw-to-simpler-format/321009 "2022-12-12T08:49:34Z")

</div>

Hey guys, i'm trying to convert this to a more "simpler" version for better Yaml anchoring reusage. co.elastic.metrics/raw: \>- \[ { "enabled": "true", "module": "http", "metricsets": \[ …

---

## [Metric Beat stops after few Minutes in AWS EC2 Server](https://discuss.elastic.co/t/metric-beat-stops-after-few-minutes-in-aws-ec2-server/320680)

<div class="topic-metadata">

**Author:** [@Umer\_Tahir](https://discuss.elastic.co/u/Umer_Tahir)\
**Replies:** 3\
**Last updated:** [December 12, 2022, 8:30am UTC](https://discuss.elastic.co/t/metric-beat-stops-after-few-minutes-in-aws-ec2-server/320680 "2022-12-12T08:30:00Z")

</div>

I have installed Metricbeats on my ECS Docker Instance and I am monitoring logs of Docker from ECS to Elastic Search Kabana Dashboard. There is an issue with the Kabana that whenever I do any release by updating docker i…

---

## [Error fetching data for metricset logstash.node\_stats: error making http request: Get \\"http://localhost:9600/\\": dial tcp 127.0.0.1:9600: connect: connection refused](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-stats-error-making-http-request-get-http-localhost-9600-dial-tcp-127-0-0-1-connect-connection-refused/321005)

<div class="topic-metadata">

**Author:** [@maxxl](https://discuss.elastic.co/u/maxxl)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 8:12am UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-stats-error-making-http-request-get-http-localhost-9600-dial-tcp-127-0-0-1-connect-connection-refused/321005 "2022-12-12T08:12:53Z")

</div>

3 logstash node works fine i\`m add 4th node configs the sames /etc/metricbeat/modules.d/logstash-xpack.yml # Module: logstash # Docs: https://www.elastic.co/guide/en/beats/metricbeat/main/metricbeat-module-logstas…

---

## [Questions about the system.memory field](https://discuss.elastic.co/t/questions-about-the-system-memory-field/320984)

<div class="topic-metadata">

**Author:** [@inwoox](https://discuss.elastic.co/u/inwoox)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 2:08am UTC](https://discuss.elastic.co/t/questions-about-the-system-memory-field/320984 "2022-12-12T02:08:35Z")

</div>

As the number in this field increased, the memory usage increased significantly with it. what is this? system.memory.page\_stats.pgsteal\_direct.pages system.memory.page\_stats.pgscan\_direct.pages Thank you always.

---

## [Metricbeat cannot use fields in template name](https://discuss.elastic.co/t/metricbeat-cannot-use-fields-in-template-name/320907)

<div class="topic-metadata">

**Author:** [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Replies:** 1\
**Last updated:** [December 11, 2022, 8:53pm UTC](https://discuss.elastic.co/t/metricbeat-cannot-use-fields-in-template-name/320907 "2022-12-11T20:53:06Z")

</div>

Elasticsearch version 8.5.2 metricbeat version 8.5.2 I am getting this issue when trying to customize template pattern in metricbeat below is my configuration, I want to use data stream and but not the default one, the …

---

## [Filebeat |Microsoft Defender ATP module pull same events multiple times](https://discuss.elastic.co/t/filebeat-microsoft-defender-atp-module-pull-same-events-multiple-times/320980)

<div class="topic-metadata">

**Author:** [@OZGURCE](https://discuss.elastic.co/u/OZGURCE)\
**Replies:** 0\
**Last updated:** [December 11, 2022, 8:56pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-defender-atp-module-pull-same-events-multiple-times/320980 "2022-12-11T20:56:03Z")

</div>

I have configured FileBeat Microsoft Defender ATP Module but FileBeat pull same event 20 times. Microsoft module interval time is, var.interval: 5m I couldn't find any variable for this options. Could someone please …

---

## [Filebeat in Container mode + multiline Parser](https://discuss.elastic.co/t/filebeat-in-container-mode-multiline-parser/320945)

<div class="topic-metadata">

**Author:** [@fidelgonzo](https://discuss.elastic.co/u/fidelgonzo)\
**Replies:** 1\
**Last updated:** [December 10, 2022, 5:47pm UTC](https://discuss.elastic.co/t/filebeat-in-container-mode-multiline-parser/320945 "2022-12-10T17:47:32Z")

</div>

I have a problem with Filebeat (7.17) that when trying to read multiline Java Stacktrace logs, it works without problems when input.type: filestream but when running the same in our Kubernetes stack, as input.type: conta…

---

## [Metricbeat on RHEL 9 / Alma 9 / Rocky 9](https://discuss.elastic.co/t/metricbeat-on-rhel-9-alma-9-rocky-9/320703)

<div class="topic-metadata">

**Author:** [@fieryfly](https://discuss.elastic.co/u/fieryfly)\
**Replies:** 3\
**Last updated:** [December 10, 2022, 5:08am UTC](https://discuss.elastic.co/t/metricbeat-on-rhel-9-alma-9-rocky-9/320703 "2022-12-10T05:08:54Z")

</div>

Hello, I was looking through the product compatibility page Support Matrix | Elastic and didn't see a column for RHEL 9 under metricbeat. While running metricbeat, I see an error: runtime/cgo: pthread\_create failed: O…

---

## [Field names not parsing in Auditbeat](https://discuss.elastic.co/t/field-names-not-parsing-in-auditbeat/320914)

<div class="topic-metadata">

**Author:** [@kossde](https://discuss.elastic.co/u/kossde)\
**Replies:** 2\
**Last updated:** [December 10, 2022, 3:17am UTC](https://discuss.elastic.co/t/field-names-not-parsing-in-auditbeat/320914 "2022-12-10T03:17:56Z")

</div>

I feel like I'm missing something here. Auditbeat is up and running on an ubunutu server and I'm getting auditd, system, and file integrity logs but some fields referenced by the Elasticsearch prebuilt linux rules aren…

---

## [Metricbeat/system cpuinfo metricset tests fail on non-amd64 platforms](https://discuss.elastic.co/t/metricbeat-system-cpuinfo-metricset-tests-fail-on-non-amd64-platforms/320929)

<div class="topic-metadata">

**Author:** [@Jonathan\_Albrecht](https://discuss.elastic.co/u/Jonathan_Albrecht)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 7:52pm UTC](https://discuss.elastic.co/t/metricbeat-system-cpuinfo-metricset-tests-fail-on-non-amd64-platforms/320929 "2022-12-09T19:52:37Z")

</div>

Two tests in metricbeat/module/system/test\_system.py: test\_core test\_core\_with\_cpu\_ticks fail on at least arm64 and s390x because the parser for /proc/cpuinfo only supports linux amd64 cpuinfo file format currently. I…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=63)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=65)
