# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=66

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 67

---

## [Math in Metric Visualization](https://discuss.elastic.co/t/math-in-metric-visualization/320249)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 1\
**Last updated:** [December 1, 2022, 11:14pm UTC](https://discuss.elastic.co/t/math-in-metric-visualization/320249 "2022-12-01T23:14:47Z")

</div>

I am trying to create a metric visualization that shows the system memory in GB (from Metricbeat's system.memory field). However, I was it to display in GB and the field value is shown in bytes (binary). How/where do I a…

---

## [How to rollback Beats and Apm-server?](https://discuss.elastic.co/t/how-to-rollback-beats-and-apm-server/320279)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 2\
**Last updated:** [December 1, 2022, 10:05pm UTC](https://discuss.elastic.co/t/how-to-rollback-beats-and-apm-server/320279 "2022-12-01T22:05:55Z")

</div>

Hey everyone! I am planning to upgrade my cluster from version 7.3.9 to 8.3 (or the newer) but I have to have a rollback plan in case if things go wrong. I could find the rollback process about Kibana and Elasticsearch…

---

## [Metricbeat Missing Data](https://discuss.elastic.co/t/metricbeat-missing-data/320285)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 5\
**Last updated:** [December 1, 2022, 9:49pm UTC](https://discuss.elastic.co/t/metricbeat-missing-data/320285 "2022-12-01T21:49:37Z")

</div>

I have Metricbeat receiving data from Perfmon counters, including Process \> % Processor Time. this is configured to collect every 10 seconds. However, we are missing processes for some reason. In other words, the events …

---

## [I have added a process in metricbeat.yml file to monitor but the process details are not showing in kibana](https://discuss.elastic.co/t/i-have-added-a-process-in-metricbeat-yml-file-to-monitor-but-the-process-details-are-not-showing-in-kibana/320227)

<div class="topic-metadata">

**Author:** [@sourabh\_rawat](https://discuss.elastic.co/u/sourabh_rawat)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 8:51am UTC](https://discuss.elastic.co/t/i-have-added-a-process-in-metricbeat-yml-file-to-monitor-but-the-process-details-are-not-showing-in-kibana/320227 "2022-12-01T08:51:10Z")

</div>

I have added a process in the metricbeat.yml file to monitor but the process details are not showing in kibana dashboard. I am getting the process details in the agent logs but when I try to get the process details usin…

---

## [Overwriting ILM policy is disabled. Set \`setup.ilm.overwrite: true\` for enabling](https://discuss.elastic.co/t/overwriting-ilm-policy-is-disabled-set-setup-ilm-overwrite-true-for-enabling/320217)

<div class="topic-metadata">

**Author:** [@Umer\_Tahir](https://discuss.elastic.co/u/Umer_Tahir)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 7:23am UTC](https://discuss.elastic.co/t/overwriting-ilm-policy-is-disabled-set-setup-ilm-overwrite-true-for-enabling/320217 "2022-12-01T07:23:50Z")

</div>

I am using metric beat Please let me know where can I Set setup.ilm.overwrite: true for enabling. I have already searched in metricbeat.yml but still no clue I have found.

---

## [Filebeat 8.5 pattern not applying to index + the Indices shows as .ds-\<name\>?](https://discuss.elastic.co/t/filebeat-8-5-pattern-not-applying-to-index-the-indices-shows-as-ds-name/320220)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 7:46am UTC](https://discuss.elastic.co/t/filebeat-8-5-pattern-not-applying-to-index-the-indices-shows-as-ds-name/320220 "2022-12-01T07:46:19Z")

</div>

Hello all, I am using the new Filebeat Helm (8.50 to collect logs from several microservices and send them directly to elasticsearch (EFK). I've edited the Values.yaml under daemonset with the following: filebeatCon…

---

## [Defender\_atp module error message](https://discuss.elastic.co/t/defender-atp-module-error-message/320188)

<div class="topic-metadata">

**Author:** [@intsec](https://discuss.elastic.co/u/intsec)\
**Replies:** 0\
**Last updated:** [November 30, 2022, 7:52pm UTC](https://discuss.elastic.co/t/defender-atp-module-error-message/320188 "2022-11-30T19:52:51Z")

</div>

I have finally got my Azure application for defender ATP to connect to my manager but when looking at the logs that are coming in to Kibana they are all with this error.message cannot access method/field \[length\] from a…

---

## [Aws vpcflow parser not loading/executing](https://discuss.elastic.co/t/aws-vpcflow-parser-not-loading-executing/320082)

<div class="topic-metadata">

**Author:** [@erhank](https://discuss.elastic.co/u/erhank)\
**Replies:** 4\
**Last updated:** [November 30, 2022, 5:18pm UTC](https://discuss.elastic.co/t/aws-vpcflow-parser-not-loading-executing/320082 "2022-11-30T17:18:57Z")

</div>

filebeat 8.4.3 attempting to consume AWS vpcflow logs from S3 and output to logstash S3 consumption is happening correctly, but ingest pipeline fails to run on messages -- the output messages simply contain original mes…

---

## [Filebeat not picking up the data and logs path from config file](https://discuss.elastic.co/t/filebeat-not-picking-up-the-data-and-logs-path-from-config-file/320168)

<div class="topic-metadata">

**Author:** [@Arjun\_Meena](https://discuss.elastic.co/u/Arjun_Meena)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 5:09pm UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-the-data-and-logs-path-from-config-file/320168 "2022-11-30T17:09:03Z")

</div>

We are running the filebeat as a service on our ec2 machine. Below is the configuration file. # ============================== Filebeat inputs =============================== filebeat.inputs: - type: log enabled: tr…

---

## [Why use Filebeat before Logstash?](https://discuss.elastic.co/t/why-use-filebeat-before-logstash/320171)

<div class="topic-metadata">

**Author:** [@scantron](https://discuss.elastic.co/u/scantron)\
**Replies:** 0\
**Last updated:** [November 30, 2022, 3:48pm UTC](https://discuss.elastic.co/t/why-use-filebeat-before-logstash/320171 "2022-11-30T15:48:35Z")

</div>

Hi all, I am working with syslogs from various different networking devices all going to the same port. Filebeat does not allow you to use multiple modules to parse logs all coming in on the same port. So Logstash is ho…

---

## [How to properly use two Filebeat modules listening on the same port?](https://discuss.elastic.co/t/how-to-properly-use-two-filebeat-modules-listening-on-the-same-port/320098)

<div class="topic-metadata">

**Author:** [@scantron](https://discuss.elastic.co/u/scantron)\
**Replies:** 5\
**Last updated:** [November 30, 2022, 3:39pm UTC](https://discuss.elastic.co/t/how-to-properly-use-two-filebeat-modules-listening-on-the-same-port/320098 "2022-11-30T15:39:58Z")

</div>

I currently have Fortinet and Cisco modules enabled on the same filebeat instance, and have a cisco meraki network device sending syslogs as well as fortinet firewall logs to the same port, 5514. I am using Docker with a…

---

## [Auditbeat get package vendor](https://discuss.elastic.co/t/auditbeat-get-package-vendor/320139)

<div class="topic-metadata">

**Author:** [@robdiluca](https://discuss.elastic.co/u/robdiluca)\
**Replies:** 0\
**Last updated:** [November 30, 2022, 10:56am UTC](https://discuss.elastic.co/t/auditbeat-get-package-vendor/320139 "2022-11-30T10:56:49Z")

</div>

Hi all, I'm trying to use Auditbeat's system module to get currently installed packages on monitored hosts. While being very useful, I noticed it does not send any information about the package vendor. Here what I obta…

---

## [Metricbeat docker host process - permission denied](https://discuss.elastic.co/t/metricbeat-docker-host-process-permission-denied/320015)

<div class="topic-metadata">

**Author:** [@Harm](https://discuss.elastic.co/u/Harm)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 8:51am UTC](https://discuss.elastic.co/t/metricbeat-docker-host-process-permission-denied/320015 "2022-11-30T08:51:30Z")

</div>

Hi, I'm trying to use a docker container to monitor my host os processes. It looked quited straightforward by mapping the /proc filesystem to the container and pointing the module hostfs setting to the correct directory…

---

## [How to put each file name as index name to store Elasticsearch via Filebeat](https://discuss.elastic.co/t/how-to-put-each-file-name-as-index-name-to-store-elasticsearch-via-filebeat/319755)

<div class="topic-metadata">

**Author:** [@Furkan\_Gulseren](https://discuss.elastic.co/u/Furkan_Gulseren)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:48am UTC](https://discuss.elastic.co/t/how-to-put-each-file-name-as-index-name-to-store-elasticsearch-via-filebeat/319755 "2022-11-30T00:48:44Z")

</div>

Hello, How can I put each filename as index name to store elasticsearch via filebeat? i am using Filebeat to send log files to elasticsearch via logstash conf. i am using wildcard(\*) to get all of the files in director…

---

## [Normalizing Host Name](https://discuss.elastic.co/t/normalizing-host-name/319124)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 4\
**Last updated:** [November 29, 2022, 9:16pm UTC](https://discuss.elastic.co/t/normalizing-host-name/319124 "2022-11-29T21:16:00Z")

</div>

I am getting values for the host.name field in both upper and lower case, which makes searches difficult. What is the simplest way to normalize this field so that it in converted to all caps?

---

## [Packetbeat 8.5 high CPU usage after updade from 7.17.7](https://discuss.elastic.co/t/packetbeat-8-5-high-cpu-usage-after-updade-from-7-17-7/320058)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 2:50pm UTC](https://discuss.elastic.co/t/packetbeat-8-5-high-cpu-usage-after-updade-from-7-17-7/320058 "2022-11-29T14:50:15Z")

</div>

After packetbeat update from 7.17.7 to 8.5.0 all our hosts show high CPU usage. Packetbeat used only for DNS traffic screening. Even after we enabled only ICMP in config we see more than 15% CPU usage but before it was …

---

## [Elastic Forwarder not decoding json](https://discuss.elastic.co/t/elastic-forwarder-not-decoding-json/319330)

<div class="topic-metadata">

**Author:** [@eyear](https://discuss.elastic.co/u/eyear)\
**Replies:** 4\
**Last updated:** [November 29, 2022, 2:32am UTC](https://discuss.elastic.co/t/elastic-forwarder-not-decoding-json/319330 "2022-11-29T02:32:03Z")

</div>

I'm working on setting up the Elastic Forwarder. The documentation states that it automatically discovers json content - but it's not splitting all of the json content out into fields like it does when using the decode\_…

---

## [X509 certificate signed by unknown authority - received "bad\_certificate"](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-received-bad-certificate/319939)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 0\
**Last updated:** [November 28, 2022, 11:11am UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority-received-bad-certificate/319939 "2022-11-28T11:11:45Z")

</div>

Hi, I came across some erros with metricbeat and the elasticsearch-xpack module. Here is the error i get from metricbeat : Nov 28 12:03:27 S0CO000ELS04 metricbeat\[4636\]: 2022-11-28T12:03:27.827+0100#011ERROR#011module…

---

## [Filebeat shipping same (rotated) logs over and over](https://discuss.elastic.co/t/filebeat-shipping-same-rotated-logs-over-and-over/319357)

<div class="topic-metadata">

**Author:** [@ori45654](https://discuss.elastic.co/u/ori45654)\
**Replies:** 2\
**Last updated:** [November 28, 2022, 2:40pm UTC](https://discuss.elastic.co/t/filebeat-shipping-same-rotated-logs-over-and-over/319357 "2022-11-28T14:40:47Z")

</div>

Hey, I want tp ship .log files from one server to another through filebeat-8.4.2-windows, they're both windows servers. the log files are rotated, from xxx.log to xxx.lo\_ . I'm testing new configurations in filebeat.yml …

---

## [How to get the cpu usage of a user process?](https://discuss.elastic.co/t/how-to-get-the-cpu-usage-of-a-user-process/319919)

<div class="topic-metadata">

**Author:** [@sourabh\_rawat](https://discuss.elastic.co/u/sourabh_rawat)\
**Replies:** 0\
**Last updated:** [November 28, 2022, 8:46am UTC](https://discuss.elastic.co/t/how-to-get-the-cpu-usage-of-a-user-process/319919 "2022-11-28T08:46:25Z")

</div>

Hi, I am trying to get the CPU usage of a process running in the user context but the process is not showing on the metrics overview page, I am able to get the details of processes which are running in the root context …

---

## [Auditd module is not converting process arg hexadecimal to ASCII](https://discuss.elastic.co/t/auditd-module-is-not-converting-process-arg-hexadecimal-to-ascii/319909)

<div class="topic-metadata">

**Author:** [@LucianoHanna](https://discuss.elastic.co/u/LucianoHanna)\
**Replies:** 0\
**Last updated:** [November 28, 2022, 6:12am UTC](https://discuss.elastic.co/t/auditd-module-is-not-converting-process-arg-hexadecimal-to-ascii/319909 "2022-11-28T06:12:23Z")

</div>

Hi! I am getting "6563686F205C226172672068657820656E636F6465645C22" where should be "echo "arg hex encoded"". It's a problem with my configuration or it's a problem with auditd module? P.S.: I have tested with ausearc…

---

## [Connect filebeat to ELK](https://discuss.elastic.co/t/connect-filebeat-to-elk/319482)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 18\
**Last updated:** [November 27, 2022, 6:31pm UTC](https://discuss.elastic.co/t/connect-filebeat-to-elk/319482 "2022-11-27T18:31:05Z")

</div>

Hello! Could you provide link to connect filebeat to logstash ? jboss logs will be transmitted Thank you

---

## [Unable to Install Fleet Server - EOF](https://discuss.elastic.co/t/unable-to-install-fleet-server-eof/319847)

<div class="topic-metadata">

**Author:** [@tmeuze](https://discuss.elastic.co/u/tmeuze)\
**Replies:** 8\
**Last updated:** [November 26, 2022, 6:08pm UTC](https://discuss.elastic.co/t/unable-to-install-fleet-server-eof/319847 "2022-11-26T18:08:16Z")

</div>

Hello, I'm hitting a wall trying to install Fleet Server on the same host as my ELK stack (v8.5.2). The result is always the same: Elastic Agent will be installed at /opt/Elastic/Agent and will run as a service. Do you…

---

## [Filebeat apache module not collecting any logs](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832)

<div class="topic-metadata">

**Author:** [@cesq](https://discuss.elastic.co/u/cesq)\
**Replies:** 4\
**Last updated:** [November 26, 2022, 4:55pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832 "2022-11-26T16:55:52Z")

</div>

So I have been playing around with collecting data using filebeat and sending it via sidecar to my graylog server. I wanted to try out the apache module, so I wrote the configuration for this (following the docs of cours…

---

## [Kubernetes filebeat not sending logs to secured Elasticsearch](https://discuss.elastic.co/t/kubernetes-filebeat-not-sending-logs-to-secured-elasticsearch/319334)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 8\
**Last updated:** [November 25, 2022, 6:53pm UTC](https://discuss.elastic.co/t/kubernetes-filebeat-not-sending-logs-to-secured-elasticsearch/319334 "2022-11-25T18:53:46Z")

</div>

Hello Team We are facing an issue where we have setup the filebeat on kubernetes environment it is working well if we setup the output without https but while setting the output as secured elasticsearch node i.e. https:…

---

## [Question about processors order in Filebeat](https://discuss.elastic.co/t/question-about-processors-order-in-filebeat/319820)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 1\
**Last updated:** [November 25, 2022, 4:33pm UTC](https://discuss.elastic.co/t/question-about-processors-order-in-filebeat/319820 "2022-11-25T16:33:38Z")

</div>

Hi, I'm struggling to find an answer to a seemingly simple question: in which order are processors executed if I have them configured both in filebeat.yml (globally, not in the input) and in a Filebeat module? Unfortun…

---

## [Barracuda WAF integration](https://discuss.elastic.co/t/barracuda-waf-integration/318749)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 2\
**Last updated:** [November 25, 2022, 2:11pm UTC](https://discuss.elastic.co/t/barracuda-waf-integration/318749 "2022-11-25T14:11:43Z")

</div>

Has anyone managed to successfully send Barracuda WAF logs to the Barracuda integration in Fleet?

---

## [Filebeat failed to load](https://discuss.elastic.co/t/filebeat-failed-to-load/319749)

<div class="topic-metadata">

**Author:** [@shubham.s](https://discuss.elastic.co/u/shubham.s)\
**Replies:** 4\
**Last updated:** [November 25, 2022, 8:03am UTC](https://discuss.elastic.co/t/filebeat-failed-to-load/319749 "2022-11-25T08:03:22Z")

</div>

● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/usr/lib/systemd/system/filebeat.service; disabled; vendor preset: disabled) Active: failed (Result: start-lim…

---

## [Filebeat batch size taking default value and not changing](https://discuss.elastic.co/t/filebeat-batch-size-taking-default-value-and-not-changing/319796)

<div class="topic-metadata">

**Author:** [@vinit0711](https://discuss.elastic.co/u/vinit0711)\
**Replies:** 0\
**Last updated:** [November 25, 2022, 7:39am UTC](https://discuss.elastic.co/t/filebeat-batch-size-taking-default-value-and-not-changing/319796 "2022-11-25T07:39:53Z")

</div>

I am running a single Node Elastic Cluster on a Server . Filebeat is used as collector for netflow data . Further Filebeat is giving output to Elastic . I am trying to improve the indexing rate in elastic by changing th…

---

## [Heartbeat not in elastic support matrix since 8.3.0](https://discuss.elastic.co/t/heartbeat-not-in-elastic-support-matrix-since-8-3-0/319208)

<div class="topic-metadata">

**Author:** [@Jonathan\_Albrecht](https://discuss.elastic.co/u/Jonathan_Albrecht)\
**Replies:** 3\
**Last updated:** [November 24, 2022, 10:01pm UTC](https://discuss.elastic.co/t/heartbeat-not-in-elastic-support-matrix-since-8-3-0/319208 "2022-11-24T22:01:35Z")

</div>

The elastic support matrix Support Matrix | Elastic doesn't have any entries for heartbeat for versions after 8.3.0. Are 8.4.0 and later versions still supported on any distros?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=65)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=67)
