# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=69

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 70

---

## [Missing fields from Metricbeat AWS Module](https://discuss.elastic.co/t/missing-fields-from-metricbeat-aws-module/317215)

<div class="topic-metadata">

**Author:** [@chicoco](https://discuss.elastic.co/u/chicoco)\
**Replies:** 6\
**Last updated:** [November 9, 2022, 3:49pm UTC](https://discuss.elastic.co/t/missing-fields-from-metricbeat-aws-module/317215 "2022-11-09T15:49:21Z")

</div>

Hello, I am new to Metricbeat, I want to monitor my AWS services, The overview dashboard is missing a lot of information, I started with EC2 CPU Utilization I found aws.ec2.cpu.total.pct field is missing although I trie…

---

## [Jenkins metrics using metricbeat](https://discuss.elastic.co/t/jenkins-metrics-using-metricbeat/318508)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 8\
**Last updated:** [November 9, 2022, 1:12pm UTC](https://discuss.elastic.co/t/jenkins-metrics-using-metricbeat/318508 "2022-11-09T13:12:52Z")

</div>

Hi, I've installed metricbeat on jenkins server and configured the elasticsearch output and kibana dashboards in metricbeat.yml. After starting metricbeat i am getting too many entries in the dashboard page of elk serve…

---

## [Ingest Pipeline - ignore\_failure is ignored](https://discuss.elastic.co/t/ingest-pipeline-ignore-failure-is-ignored/318484)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 5\
**Last updated:** [November 9, 2022, 12:19pm UTC](https://discuss.elastic.co/t/ingest-pipeline-ignore-failure-is-ignored/318484 "2022-11-09T12:19:21Z")

</div>

Hi, We are attempting to ingest PANW events via filebeat-\>logstash-\>elasticsearch. The filebeat-8.4.0-panw-panos-pipeline fails due to the second processor being: rename "message" to "event.original" Our event alread…

---

## [Netflow Poor Performance with filebeat 7.13](https://discuss.elastic.co/t/netflow-poor-performance-with-filebeat-7-13/318512)

<div class="topic-metadata">

**Author:** [@vinit0711](https://discuss.elastic.co/u/vinit0711)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 6:54am UTC](https://discuss.elastic.co/t/netflow-poor-performance-with-filebeat-7-13/318512 "2022-11-09T06:54:32Z")

</div>

I am capturing netflow packets and displaying the information on kibana dashboard .I am able to do so but around 30-40 % packets are being dropped . I am verfiying the packets in tcp dump and the some packets not able to…

---

## [Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/318400)

<div class="topic-metadata">

**Author:** [@bta16](https://discuss.elastic.co/u/bta16)\
**Replies:** 12\
**Last updated:** [November 9, 2022, 5:43am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/318400 "2022-11-09T05:43:09Z")

</div>

Hi there, i configure suricata-\>filebeat-\>kibana but when i Check that data is received from the Filebeat suricata module. There is no data. I think i get an error in filebeat. any information in my situation: i install…

---

## [Filebeat PubSub module throughput issue](https://discuss.elastic.co/t/filebeat-pubsub-module-throughput-issue/318488)

<div class="topic-metadata">

**Author:** [@wendel](https://discuss.elastic.co/u/wendel)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 1:51am UTC](https://discuss.elastic.co/t/filebeat-pubsub-module-throughput-issue/318488 "2022-11-09T01:51:06Z")

</div>

I have a single Filebeat 8.4.3 instance running in AWS pulling GCP audit events from a GCP PubSub topic and output to Kafka Topic. Tried various configuration/settings without any success going above 650 messages/s in Fi…

---

## [Metricbeat - Limit of total fields \[1000\] has been exceeded](https://discuss.elastic.co/t/metricbeat-limit-of-total-fields-1000-has-been-exceeded/317660)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 1\
**Last updated:** [November 8, 2022, 2:44pm UTC](https://discuss.elastic.co/t/metricbeat-limit-of-total-fields-1000-has-been-exceeded/317660 "2022-11-08T14:44:30Z")

</div>

Hello, I hope my question finds you and your loved ones safe and healthy. I am having errors trying to ingest system metrics (system module) from a single Ubuntu system running 22.04.1 using Metricbeat (version 7.17.7 …

---

## [Autodiscover with custom pipeline](https://discuss.elastic.co/t/autodiscover-with-custom-pipeline/318377)

<div class="topic-metadata">

**Author:** [@zeitler](https://discuss.elastic.co/u/zeitler)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 2:00am UTC](https://discuss.elastic.co/t/autodiscover-with-custom-pipeline/318377 "2022-11-08T02:00:32Z")

</div>

Hi I'm sorry if this has been already asked and explained, but I'm missing it... My goal is to have a custom grok configuration. My configuration: filebeat.autodiscover: providers: - type: kubernetes node…

---

## [How can fields received by Filebeat http\_endpoint be add to the document root](https://discuss.elastic.co/t/how-can-fields-received-by-filebeat-http-endpoint-be-add-to-the-document-root/317847)

<div class="topic-metadata">

**Author:** [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Replies:** 0\
**Last updated:** [October 31, 2022, 8:25pm UTC](https://discuss.elastic.co/t/how-can-fields-received-by-filebeat-http-endpoint-be-add-to-the-document-root/317847 "2022-10-31T20:25:27Z")

</div>

(post deleted by author)

---

## [Kubernetes Pod and container memory usage always at 0](https://discuss.elastic.co/t/kubernetes-pod-and-container-memory-usage-always-at-0/317665)

<div class="topic-metadata">

**Author:** [@sebglon](https://discuss.elastic.co/u/sebglon)\
**Replies:** 4\
**Last updated:** [November 7, 2022, 4:44pm UTC](https://discuss.elastic.co/t/kubernetes-pod-and-container-memory-usage-always-at-0/317665 "2022-11-07T16:44:22Z")

</div>

Hi, I have an issue on MetricBeat v8.4.2. I use it to collect Kubernetes (v1.22.2) metrics. But i always have kubernetes.container.memory.usage.bytes and kubernetes.pod.memory.usage.bytes at 0 Here are my clusterRole…

---

## [Filebeat Fail to get Kibana Version \> x509: certificate signed by unknown authority](https://discuss.elastic.co/t/filebeat-fail-to-get-kibana-version-x509-certificate-signed-by-unknown-authority/318349)

<div class="topic-metadata">

**Author:** [@janis.cimins](https://discuss.elastic.co/u/janis.cimins)\
**Replies:** 0\
**Last updated:** [November 7, 2022, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-fail-to-get-kibana-version-x509-certificate-signed-by-unknown-authority/318349 "2022-11-07T15:57:46Z")

</div>

Hello! I have set up basic Elastic+Kibana setup and I\`m trying to get Filebeat up and running on the server. I have configured it as from quick start guide, but I get this error: Exiting: error connecting to Kibana: …

---

## [Avoiding data loss with filebeat in a K8S environment](https://discuss.elastic.co/t/avoiding-data-loss-with-filebeat-in-a-k8s-environment/318324)

<div class="topic-metadata">

**Author:** [@Ganapati\_Basimsetti](https://discuss.elastic.co/u/Ganapati_Basimsetti)\
**Replies:** 0\
**Last updated:** [November 7, 2022, 11:18am UTC](https://discuss.elastic.co/t/avoiding-data-loss-with-filebeat-in-a-k8s-environment/318324 "2022-11-07T11:18:07Z")

</div>

Hello There, We are in the process of setting up filebeat in the K8S environment running as a DaemonSet. We are evaluating the possibilities of data loss - logs generated by the application are not uploaded to Logstash …

---

## [Filebeat doesn't seem to create index](https://discuss.elastic.co/t/filebeat-doesnt-seem-to-create-index/318303)

<div class="topic-metadata">

**Author:** [@romakolesnikow](https://discuss.elastic.co/u/romakolesnikow)\
**Replies:** 3\
**Last updated:** [November 7, 2022, 9:09am UTC](https://discuss.elastic.co/t/filebeat-doesnt-seem-to-create-index/318303 "2022-11-07T09:09:15Z")

</div>

I have ELK setup on one server and logs i am trying to read on another. But on kibana i dont see index created from filebeat. Filebeat console output works properly and showing my logs. filebeat.yml: filebeat.inputs: -…

---

## [Rsyslog to remote elk](https://discuss.elastic.co/t/rsyslog-to-remote-elk/318100)

<div class="topic-metadata">

**Author:** [@Ayah](https://discuss.elastic.co/u/Ayah)\
**Replies:** 3\
**Last updated:** [November 7, 2022, 6:36am UTC](https://discuss.elastic.co/t/rsyslog-to-remote-elk/318100 "2022-11-07T06:36:36Z")

</div>

Dears, I am new in ELK, we have ELK system to collect logs from a radsecproxy.log in other server. the logstash is configured to accept radsecproxy log format only and shapping them. Now we need to forward same logs to…

---

## [Index key XXX did not match any of the cached resources (intermittent issue)](https://discuss.elastic.co/t/index-key-xxx-did-not-match-any-of-the-cached-resources-intermittent-issue/318219)

<div class="topic-metadata">

**Author:** [@vddmpo](https://discuss.elastic.co/u/vddmpo)\
**Replies:** 0\
**Last updated:** [November 4, 2022, 9:07pm UTC](https://discuss.elastic.co/t/index-key-xxx-did-not-match-any-of-the-cached-resources-intermittent-issue/318219 "2022-11-04T21:07:21Z")

</div>

Hi, There is intermittent problem with "add\_kubernetes\_metadata" (resource type: pod) when the log is not enriched. The debug logs show the following: {"log.level":"debug","@timestamp":"2022-11-04T18:57:06.524Z","log.l…

---

## [Filebeat - processors parameters not being applied to all logs](https://discuss.elastic.co/t/filebeat-processors-parameters-not-being-applied-to-all-logs/318206)

<div class="topic-metadata">

**Author:** [@godisnemus](https://discuss.elastic.co/u/godisnemus)\
**Replies:** 0\
**Last updated:** [November 4, 2022, 3:47pm UTC](https://discuss.elastic.co/t/filebeat-processors-parameters-not-being-applied-to-all-logs/318206 "2022-11-04T15:47:53Z")

</div>

Fairly new to this. I'm trying to understand why some of our Filebeat logs are not being subject to the parameters defined in "processors". It is my understanding that the processor parameters should be applied to all d…

---

## [Heartbeat 8.5.0 mapper error workaround](https://discuss.elastic.co/t/heartbeat-8-5-0-mapper-error-workaround/318133)

<div class="topic-metadata">

**Author:** [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Replies:** 0\
**Last updated:** [November 3, 2022, 7:00pm UTC](https://discuss.elastic.co/t/heartbeat-8-5-0-mapper-error-workaround/318133 "2022-11-03T19:00:11Z")

</div>

Hi all, Andrew from Elastic here, Tech Lead for Heartbeat. We're sorry to report that Heartbeat 8.5.0 has a severe bug that will break indexing in most installs after ~30m of runtime. The good news is there's an easy wor…

---

## [Regarding ignore fieds](https://discuss.elastic.co/t/regarding-ignore-fieds/317803)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 9\
**Last updated:** [November 3, 2022, 7:48am UTC](https://discuss.elastic.co/t/regarding-ignore-fieds/317803 "2022-11-03T07:48:42Z")

</div>

Hi team, We would like to explore the ignore fields in Filebeat. Our purpose is to deleted the older files after denoted the value looks below. After implemented the ignore\_older as 2h in filebeat. The logs has stop…

---

## [Send output to elastic search specific index with ilm\_rollover?](https://discuss.elastic.co/t/send-output-to-elastic-search-specific-index-with-ilm-rollover/317818)

<div class="topic-metadata">

**Author:** [@Linux\_Artists](https://discuss.elastic.co/u/Linux_Artists)\
**Replies:** 1\
**Last updated:** [November 3, 2022, 6:49am UTC](https://discuss.elastic.co/t/send-output-to-elastic-search-specific-index-with-ilm-rollover/317818 "2022-11-03T06:49:20Z")

</div>

Hello, Running elasticsearch kibana and filebeat I will like to make an index and pattern with ILM. On Elasticsearch I did while \[\[ "$(curl -s -o /dev/null -w '%{http\_code}\\n' $ES\_URL)" != "200" \]\]; do sleep…

---

## [Logbeat PanOS module not working](https://discuss.elastic.co/t/logbeat-panos-module-not-working/317915)

<div class="topic-metadata">

**Author:** [@ithamster](https://discuss.elastic.co/u/ithamster)\
**Replies:** 0\
**Last updated:** [November 1, 2022, 5:54pm UTC](https://discuss.elastic.co/t/logbeat-panos-module-not-working/317915 "2022-11-01T17:54:08Z")

</div>

I am new to Elasticsearch, Kibana and Filebeats. We have setup logbeat module for panos and panw.yml has following information: - module: panw panos: enabled: true var.syslog\_host: 0.0.0.0 var.syslog\_port: 514 We …

---

## [ELK Stack filebeat config for multiple clients](https://discuss.elastic.co/t/elk-stack-filebeat-config-for-multiple-clients/317957)

<div class="topic-metadata">

**Author:** [@PJ111288](https://discuss.elastic.co/u/PJ111288)\
**Replies:** 1\
**Last updated:** [November 2, 2022, 9:47pm UTC](https://discuss.elastic.co/t/elk-stack-filebeat-config-for-multiple-clients/317957 "2022-11-02T21:47:54Z")

</div>

Hello Saviors, I have running ELK stack with 1 Master and 1 client setup with filebeat. I am trying to add more clients in this stack and configured one more filebeat client but no logs are forwarding to LogServer. My …

---

## [I was not getting any errors in filebeat but logs are not parsing. Please help me on this. I was new to this](https://discuss.elastic.co/t/i-was-not-getting-any-errors-in-filebeat-but-logs-are-not-parsing-please-help-me-on-this-i-was-new-to-this/318009)

<div class="topic-metadata">

**Author:** [@Nikhil\_Kotni](https://discuss.elastic.co/u/Nikhil_Kotni)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 3:09pm UTC](https://discuss.elastic.co/t/i-was-not-getting-any-errors-in-filebeat-but-logs-are-not-parsing-please-help-me-on-this-i-was-new-to-this/318009 "2022-11-02T15:09:35Z")

</div>

filebeat logs: 2022-11-02T18:11:20.778+0530 DEBUG \[publisher\] memqueue/ackloop.go:131 ackloop: done send ack 2022-11-02T18:11:20.778+0530 DEBUG \[registrar\] registrar/registrar.go:263 Processing 1 events 2022-11-02T18:1…

---

## [Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/318023)

<div class="topic-metadata">

**Author:** [@stefanny\_chavez\_anto](https://discuss.elastic.co/u/stefanny_chavez_anto)\
**Replies:** 1\
**Last updated:** [November 2, 2022, 9:39pm UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/318023 "2022-11-02T21:39:38Z")

</div>

× filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; vendor preset: enabled) Active: failed (Result: exit-code) since We…

---

## [Go get github.com/elastic/beats@v8 fails](https://discuss.elastic.co/t/go-get-github-com-elastic-beats-v8-fails/318027)

<div class="topic-metadata">

**Author:** [@Andrew\_Martinez](https://discuss.elastic.co/u/Andrew_Martinez)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 4:26pm UTC](https://discuss.elastic.co/t/go-get-github-com-elastic-beats-v8-fails/318027 "2022-11-02T16:26:28Z")

</div>

Was looking at github.com/elastic/beats and saw releases for v8.\*.\*, but the go.mod file for all of those tagged versions has module github.com/elastic/beats/v7. It seems like they should be module github.com/elastic/bea…

---

## [TCP data splitted into several documents](https://discuss.elastic.co/t/tcp-data-splitted-into-several-documents/317986)

<div class="topic-metadata">

**Author:** [@Fangy](https://discuss.elastic.co/u/Fangy)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 1:14pm UTC](https://discuss.elastic.co/t/tcp-data-splitted-into-several-documents/317986 "2022-11-02T13:14:37Z")

</div>

Hi. I'm trying to ingest some new type of message. The message header is very similar to the syslog format, but the message itself is an xml format. Each line in the message ends with 0x0a (LF). These packets are ingeste…

---

## [Filebeat cannot create custom index - even when ilm is disabled](https://discuss.elastic.co/t/filebeat-cannot-create-custom-index-even-when-ilm-is-disabled/317688)

<div class="topic-metadata">

**Author:** [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Replies:** 14\
**Last updated:** [November 2, 2022, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-cannot-create-custom-index-even-when-ilm-is-disabled/317688 "2022-11-02T12:46:17Z")

</div>

Hi Team, I would like to ask for help as I cannot create custom index even when setup.ilm.enabled: is set to false. Below is my filebeat config. Thanks. setup.ilm.enabled: false setup.template.enabled: true setup.te…

---

## [Filebeat high read io when collecting log data](https://discuss.elastic.co/t/filebeat-high-read-io-when-collecting-log-data/317857)

<div class="topic-metadata">

**Author:** [@Zhi\_Li](https://discuss.elastic.co/u/Zhi_Li)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 9:18am UTC](https://discuss.elastic.co/t/filebeat-high-read-io-when-collecting-log-data/317857 "2022-11-02T09:18:10Z")

</div>

I have a Filebeat setup to collect log data in SATA, but it does have a high read IO of around 20mb/s. below is my Filebeat config, it outputs to Kafka cluster. im just wondering is there any way to slow down the Filebea…

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to http://X.X.X.X:5601/api/status fails: fail to execute the HTTP GET request: Get "http://X.X.X.X:5601/api/status": context deadline exceeded. Response:](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-x-x-x-x-5601-api-status-fails-fail-to-execute-the-http-get-request-get-http-x-x-x-x-5601-api-status-context-deadline-exceeded-response/317848)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 22\
**Last updated:** [November 1, 2022, 11:36pm UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-x-x-x-x-5601-api-status-fails-fail-to-execute-the-http-get-request-get-http-x-x-x-x-5601-api-status-context-deadline-exceeded-response/317848 "2022-11-01T23:36:27Z")

</div>

Hello, I'm having errors loading --dashboards from filebeats to kibana. But when running the command below, it returns me the following message: \[rcmag.kta@XXXXXXXX ~\]$ sudo filebeat setup --dashboards Loading dashboar…

---

## [No threat intelligence data](https://discuss.elastic.co/t/no-threat-intelligence-data/317638)

<div class="topic-metadata">

**Author:** [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Replies:** 4\
**Last updated:** [November 1, 2022, 9:55am UTC](https://discuss.elastic.co/t/no-threat-intelligence-data/317638 "2022-11-01T09:55:39Z")

</div>

I have installed multiple threatintel modules through my Filebeats collector, enabled them, and can verify I can view the various assets in Elastic. However the Security - Overview Dashboard still shows "no threat intel…

---

## [Is Filebeat OSS support solaris sparc and AIX servers](https://discuss.elastic.co/t/is-filebeat-oss-support-solaris-sparc-and-aix-servers/317876)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 1\
**Last updated:** [November 1, 2022, 8:57am UTC](https://discuss.elastic.co/t/is-filebeat-oss-support-solaris-sparc-and-aix-servers/317876 "2022-11-01T08:57:56Z")

</div>

Hello team Is Filebeat OSS support solaris sparc and AIX servers? If not is there any alternative agent for solaris Sparc to push logs into logstash servers.

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=68)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=70)
