# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=65

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 66

---

## [Beat -\> Logstash -\> Elasticsearch configuration problem](https://discuss.elastic.co/t/beat-logstash-elasticsearch-configuration-problem/320801)

<div class="topic-metadata">

**Author:** [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Replies:** 1\
**Last updated:** [December 9, 2022, 3:18pm UTC](https://discuss.elastic.co/t/beat-logstash-elasticsearch-configuration-problem/320801 "2022-12-09T15:18:40Z")

</div>

I have a problem with the data flow configuration: Beat -\> Logstash -\> Elasticsearch I initially configured everything in the flow: Beat -\> Elasticsearch of course I initially did the required setup (adding standard …

---

## [Filebeat filestream input pause when disk queue full?](https://discuss.elastic.co/t/filebeat-filestream-input-pause-when-disk-queue-full/320881)

<div class="topic-metadata">

**Author:** [@KanekaGuidos](https://discuss.elastic.co/u/KanekaGuidos)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-filestream-input-pause-when-disk-queue-full/320881 "2022-12-09T13:37:57Z")

</div>

Dear, I tried searching for an answer, but didn't immediately find one. I'm using filebeat's filestream input (works great!) and setup the disk queue to a max\_size. The documentation of the internal queue states the f…

---

## [Unexpected type mapstr.M warning](https://discuss.elastic.co/t/unexpected-type-mapstr-m-warning/320834)

<div class="topic-metadata">

**Author:** [@Alex\_Lavrov](https://discuss.elastic.co/u/Alex_Lavrov)\
**Replies:** 3\
**Last updated:** [December 9, 2022, 1:05pm UTC](https://discuss.elastic.co/t/unexpected-type-mapstr-m-warning/320834 "2022-12-09T13:05:11Z")

</div>

Hello, I'm sending JSON logs using filebeat and suddenly I started to get this error: {"log.level":"warn","@timestamp":"2022-12-08T23:33:51.575+0200","log.logger":"conditions","log.origin":{"file.name":"conditions/matc…

---

## [Connect filebeat to logstash](https://discuss.elastic.co/t/connect-filebeat-to-logstash/320399)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 5\
**Last updated:** [December 8, 2022, 5:00pm UTC](https://discuss.elastic.co/t/connect-filebeat-to-logstash/320399 "2022-12-08T17:00:30Z")

</div>

Hi! created openssl keys and copied to filebeat host in /etc/ssl/ folder: \[root@fbeat ssl\]# ls -l total 8 lrwxrwxrwx. 1 root root 16 Oct 23 20:02 certs -\> ../pki/tls/certs -rw-r--r--. 1 root root 1704 Nov 28 23:46 l…

---

## [Jboss logs module](https://discuss.elastic.co/t/jboss-logs-module/320813)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 4:59pm UTC](https://discuss.elastic.co/t/jboss-logs-module/320813 "2022-12-08T16:59:01Z")

</div>

Hello! which is the best module in filebeat to parse jboss logs? Thank you

---

## [FIlebeat error-too many cases](https://discuss.elastic.co/t/filebeat-error-too-many-cases/320172)

<div class="topic-metadata">

**Author:** [@bharat97](https://discuss.elastic.co/u/bharat97)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 2:24pm UTC](https://discuss.elastic.co/t/filebeat-error-too-many-cases/320172 "2022-12-08T14:24:28Z")

</div>

Hi Community, My filebeat is crashing with this error. {"log.level":"info","@timestamp":"2022-11-30T14:39:55.579Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":185},"message":"Non-zero m…

---

## [How to setup elastic apm agent in Chalice framework (Python)](https://discuss.elastic.co/t/how-to-setup-elastic-apm-agent-in-chalice-framework-python/320793)

<div class="topic-metadata">

**Author:** [@Abhishek22](https://discuss.elastic.co/u/Abhishek22)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 1:54pm UTC](https://discuss.elastic.co/t/how-to-setup-elastic-apm-agent-in-chalice-framework-python/320793 "2022-12-08T13:54:23Z")

</div>

As we have chalice framework which we deploy to lambda (aws) but there is no any document on how to do the setup of APM agent on chalice framework python. As chalice don't use flask so it is getting difficult to add APM …

---

## [High memory usage of Metricbeat in Kubernetes](https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/320784)

<div class="topic-metadata">

**Author:** [@beatman](https://discuss.elastic.co/u/beatman)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 12:24pm UTC](https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/320784 "2022-12-08T12:24:02Z")

</div>

Hi, Continuing the discussion from High memory usage of Metricbeat in Kubernetes: I'm facing exactly the same problem with metricbeat consuming memory until it gets OOM-killed. This happens on all three k8s clusters I…

---

## [Filebeat running as a container not displaying logs in Kibana](https://discuss.elastic.co/t/filebeat-running-as-a-container-not-displaying-logs-in-kibana/320626)

<div class="topic-metadata">

**Author:** [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Replies:** 11\
**Last updated:** [December 7, 2022, 9:55pm UTC](https://discuss.elastic.co/t/filebeat-running-as-a-container-not-displaying-logs-in-kibana/320626 "2022-12-07T21:55:39Z")

</div>

We are running filebeat:8.1.3 as a docker container using docker-compose file in Linux RHEL machine. We have provided the input type as filestream and provided the path for log files , but still it is not injecting any …

---

## [Missed Events](https://discuss.elastic.co/t/missed-events/320702)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 0\
**Last updated:** [December 7, 2022, 4:25pm UTC](https://discuss.elastic.co/t/missed-events/320702 "2022-12-07T16:25:52Z")

</div>

I have a situation where we are receiving Windows Event ID 3000 sometimes but not other times. This is very problematic, as the event is used to troubleshoot process exits. The endpoint uses Windows Event Forwarding (WEF…

---

## [Docker filebeat installation error](https://discuss.elastic.co/t/docker-filebeat-installation-error/320686)

<div class="topic-metadata">

**Author:** [@AnkurYogi](https://discuss.elastic.co/u/AnkurYogi)\
**Replies:** 0\
**Last updated:** [December 7, 2022, 1:27pm UTC](https://discuss.elastic.co/t/docker-filebeat-installation-error/320686 "2022-12-07T13:27:59Z")

</div>

\<root@ubuntu:/# docker run \\ docker.elastic.co/beats/filebeat:8.5.2 setup -E setup.kibana.host=172.18.0.3:5601 -E output.elasticsearch.hosts=\["172.18.0.2:9200"\] Exiting: couldn't connect to any of the configured E…

---

## [Filebeat not shipping the logs to elasticsearch](https://discuss.elastic.co/t/filebeat-not-shipping-the-logs-to-elasticsearch/320667)

<div class="topic-metadata">

**Author:** [@abaltan](https://discuss.elastic.co/u/abaltan)\
**Replies:** 0\
**Last updated:** [December 7, 2022, 9:57am UTC](https://discuss.elastic.co/t/filebeat-not-shipping-the-logs-to-elasticsearch/320667 "2022-12-07T09:57:08Z")

</div>

Hello, I'm trying to ship the logs using filebeat(filebeat version 7.17.7 (amd64)). my filebeat.yml file: filebeat.inputs: - type: log enabled: true paths: - /var/log/connection\_status/connection.log json.ke…

---

## [Elastic-Agent System integration not sending in data for all mount points](https://discuss.elastic.co/t/elastic-agent-system-integration-not-sending-in-data-for-all-mount-points/320653)

<div class="topic-metadata">

**Author:** [@mkf1](https://discuss.elastic.co/u/mkf1)\
**Replies:** 0\
**Last updated:** [December 7, 2022, 7:44am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-not-sending-in-data-for-all-mount-points/320653 "2022-12-07T07:44:33Z")

</div>

Hi, I'm using Elastic-Agent Docker. Using version 8.5.0. My host server have multiple mount points. E.g. a mount point /app. But Elastic-Agent is not sending in any data about these mount points, see below screenshot: …

---

## [Winlogbeat 8.5 and Windows 11 22H2](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676)

<div class="topic-metadata">

**Author:** [@logs4drew](https://discuss.elastic.co/u/logs4drew)\
**Replies:** 7\
**Last updated:** [December 6, 2022, 8:58pm UTC](https://discuss.elastic.co/t/winlogbeat-8-5-and-windows-11-22h2/318676 "2022-12-06T20:58:41Z")

</div>

Greetings! It appears that variables (e.g. %1, %2) in windows events shipped via winlogbeat do not have these variables replaced with their real values. Example: Credential Manager credentials were read. Subject: Sec…

---

## [How to dissect uneven space in log with filebeat processors](https://discuss.elastic.co/t/how-to-dissect-uneven-space-in-log-with-filebeat-processors/320609)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 1\
**Last updated:** [December 6, 2022, 6:48pm UTC](https://discuss.elastic.co/t/how-to-dissect-uneven-space-in-log-with-filebeat-processors/320609 "2022-12-06T18:48:53Z")

</div>

Hey all, I have a python microservice that output logs like so: INFO ; 2022-12-02 01:30:00; bla bla bla... DEBUG ; 2022-12-02 01:30:00; bla bla bla... Note how the space is different on the loglevel. I am parsing…

---

## [Trouble with enabling TLS between Filebeat and logstash](https://discuss.elastic.co/t/trouble-with-enabling-tls-between-filebeat-and-logstash/320619)

<div class="topic-metadata">

**Author:** [@Zekir](https://discuss.elastic.co/u/Zekir)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 6:41pm UTC](https://discuss.elastic.co/t/trouble-with-enabling-tls-between-filebeat-and-logstash/320619 "2022-12-06T18:41:32Z")

</div>

Hello guys, I'm here because i got some troubles while enabling TLS between filebeat and logstash For a little context I'm all my machines run under debian 11, i got 3 servers, first is filebeat who communicate with a …

---

## [Activemq module give Grok error on filebeat](https://discuss.elastic.co/t/activemq-module-give-grok-error-on-filebeat/320608)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 3:58pm UTC](https://discuss.elastic.co/t/activemq-module-give-grok-error-on-filebeat/320608 "2022-12-06T15:58:35Z")

</div>

Hello all, Running in k8s I have activemq and filebeat, elasticsearch, kibana. filebeat collect the logs from activemq like so: filebeat.autodiscover: providers: - type: kubernetes …

---

## [Ingesting IBM BigFix Client Logs](https://discuss.elastic.co/t/ingesting-ibm-bigfix-client-logs/318437)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 2\
**Last updated:** [December 6, 2022, 12:47pm UTC](https://discuss.elastic.co/t/ingesting-ibm-bigfix-client-logs/318437 "2022-12-06T12:47:05Z")

</div>

I am needing to ingest the IBM BigFix client logs located at C:\\Program Files (x86)\\BigFix Enterprise\\BES Client\\\_BESData\\\_Global\\Logs. Is there either a Beat module or Logstash plugin which would handle parsing these lo…

---

## [How to write a painless script that get all the error from the EKS cluster as I want to create an error dashboad in kibana](https://discuss.elastic.co/t/how-to-write-a-painless-script-that-get-all-the-error-from-the-eks-cluster-as-i-want-to-create-an-error-dashboad-in-kibana/320533)

<div class="topic-metadata">

**Author:** [@ANIKET\_YADAV](https://discuss.elastic.co/u/ANIKET_YADAV)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 7:31am UTC](https://discuss.elastic.co/t/how-to-write-a-painless-script-that-get-all-the-error-from-the-eks-cluster-as-i-want-to-create-an-error-dashboad-in-kibana/320533 "2022-12-06T07:31:28Z")

</div>

I want to create an error field in filebeat index pattern as I need to create an error dashboard that fetch me the error of my pods running in EKS cluster but for that it is required to write a script to add a field... P…

---

## [Filbeat with netflow as input and elastic output for oss elastic 7.6.1](https://discuss.elastic.co/t/filbeat-with-netflow-as-input-and-elastic-output-for-oss-elastic-7-6-1/320421)

<div class="topic-metadata">

**Author:** [@shaikmuzakkir](https://discuss.elastic.co/u/shaikmuzakkir)\
**Replies:** 4\
**Last updated:** [December 6, 2022, 7:09am UTC](https://discuss.elastic.co/t/filbeat-with-netflow-as-input-and-elastic-output-for-oss-elastic-7-6-1/320421 "2022-12-06T07:09:25Z")

</div>

Elastic cluster we have is of open source 7.6.1 version. We need filebeat to have netflow as input and elastic as output to write to our cluster. With filebeat open source, netflow is not enabled as input ERROR inst…

---

## [Filebeat nginx module](https://discuss.elastic.co/t/filebeat-nginx-module/320400)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 5\
**Last updated:** [December 5, 2022, 11:36pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module/320400 "2022-12-05T23:36:21Z")

</div>

Hello, I am trying to use filebeat with nginx module to collect logs from nginx-ingress-controller and send directly to elasti but I keep getting an error: Provided Grok expressions do not match field value: \[172.17.0.…

---

## [The Windows x86\_64 MSI file for Packetbeat 8.3.2 won't work with default\_route](https://discuss.elastic.co/t/the-windows-x86-64-msi-file-for-packetbeat-8-3-2-wont-work-with-default-route/320446)

<div class="topic-metadata">

**Author:** [@beejaygee](https://discuss.elastic.co/u/beejaygee)\
**Replies:** 2\
**Last updated:** [December 5, 2022, 2:12pm UTC](https://discuss.elastic.co/t/the-windows-x86-64-msi-file-for-packetbeat-8-3-2-wont-work-with-default-route/320446 "2022-12-05T14:12:42Z")

</div>

The Windows x86\_64 MSI file for Packetbeat 8.3.2 won't work with default\_route setting. I have found that if I compile the v8.3.2 source and swap the exe out for my compiled version that it works as expected. If I use th…

---

## [Monitor host machine using metricbeat system module from inside a metricbeat docker container](https://discuss.elastic.co/t/monitor-host-machine-using-metricbeat-system-module-from-inside-a-metricbeat-docker-container/320420)

<div class="topic-metadata">

**Author:** [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Replies:** 2\
**Last updated:** [December 4, 2022, 12:32am UTC](https://discuss.elastic.co/t/monitor-host-machine-using-metricbeat-system-module-from-inside-a-metricbeat-docker-container/320420 "2022-12-04T00:32:12Z")

</div>

We are using metricbeat docker container version 8.1.3 to monitor Linux RHEL machines. Used docker-compose file to spin up metricbeat container. Enabled system module to monitor system metrics. But we are not able to …

---

## [Filebeat does not send data to logstash](https://discuss.elastic.co/t/filebeat-does-not-send-data-to-logstash/320292)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 6\
**Last updated:** [December 2, 2022, 8:23pm UTC](https://discuss.elastic.co/t/filebeat-does-not-send-data-to-logstash/320292 "2022-12-02T20:23:53Z")

</div>

Hi! here is my filebeat config filebeat.inputs: - type: syslog id: my-filestream-id enabled: true paths: - /var/log/\*.log - /var/log/nginx/access\*.log - /var/log/messages - /bar/log/secure filebea…

---

## [Filebeats connected but no logs](https://discuss.elastic.co/t/filebeats-connected-but-no-logs/320393)

<div class="topic-metadata">

**Author:** [@ardue](https://discuss.elastic.co/u/ardue)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 7:16pm UTC](https://discuss.elastic.co/t/filebeats-connected-but-no-logs/320393 "2022-12-02T19:16:46Z")

</div>

Hello, I have a problem, I can't see the logs on kibana while the filebeat connection is good: Here is the configuration of filebeat.yml: ###################### Filebeat Configuration Example #########################…

---

## [Winlogbeat 8.4 - Processors - Drop Event](https://discuss.elastic.co/t/winlogbeat-8-4-processors-drop-event/320160)

<div class="topic-metadata">

**Author:** [@prolle](https://discuss.elastic.co/u/prolle)\
**Replies:** 1\
**Last updated:** [December 2, 2022, 2:28pm UTC](https://discuss.elastic.co/t/winlogbeat-8-4-processors-drop-event/320160 "2022-12-02T14:28:17Z")

</div>

Hi, i'm trying to drop an event from being sent to my elastic cluster. On the Windows integration i have added a processor under the Windows Powershell channel and the Microsoft-Windows-Powershell/Operational channel. T…

---

## [Filebeat 8.5.2 Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/filebeat-8-5-2-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/320268)

<div class="topic-metadata">

**Author:** [@ardue](https://discuss.elastic.co/u/ardue)\
**Replies:** 5\
**Last updated:** [December 2, 2022, 2:14pm UTC](https://discuss.elastic.co/t/filebeat-8-5-2-failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/320268 "2022-12-02T14:14:00Z")

</div>

Hello when I run filebeat I get this error: sudo service filebeat status filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/lib/systemd/system/filebeat.service; …

---

## [Drop\_event from Win firewall](https://discuss.elastic.co/t/drop-event-from-win-firewall/320334)

<div class="topic-metadata">

**Author:** [@vabe](https://discuss.elastic.co/u/vabe)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 8:16am UTC](https://discuss.elastic.co/t/drop-event-from-win-firewall/320334 "2022-12-02T08:16:38Z")

</div>

Hey guys, I'm looking for help here as a last resort. Can't find a solution.. I want to drop events from Win firewall log the line is: message 2022-12-02 08:53:10 ALLOW TCP 127.0.0.1 127.0.0.1 50740 389 0 - 0 0 0 - …

---

## [Filebeat Error](https://discuss.elastic.co/t/filebeat-error/320316)

<div class="topic-metadata">

**Author:** [@lucas.Jung](https://discuss.elastic.co/u/lucas.Jung)\
**Replies:** 2\
**Last updated:** [December 2, 2022, 8:30am UTC](https://discuss.elastic.co/t/filebeat-error/320316 "2022-12-02T08:30:05Z")

</div>

I set filebeat to use the ingest node of okta, but an error occurs and filebit does not run. ERROR \[esclientleg\] transport/logging.go:37 Error dialing x509: certificate signed by unknown authority {"network": "t…

---

## [Error parsing datetime using Script Processor](https://discuss.elastic.co/t/error-parsing-datetime-using-script-processor/320332)

<div class="topic-metadata">

**Author:** [@m14](https://discuss.elastic.co/u/m14)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 8:02am UTC](https://discuss.elastic.co/t/error-parsing-datetime-using-script-processor/320332 "2022-12-02T08:02:34Z")

</div>

Hi, I need to get the date and time from the log record. In JavaScript I can just do the following: var d = new Date("Oct 27, 2022 1:39:57 PM"); But the script processor seems nto to be able to do this. When I try (…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=64)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=66)
