# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=70

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 71

---

## [Fleet and autodiscovery](https://discuss.elastic.co/t/fleet-and-autodiscovery/317284)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 2\
**Last updated:** [October 31, 2022, 4:42pm UTC](https://discuss.elastic.co/t/fleet-and-autodiscovery/317284 "2022-10-31T16:42:37Z")

</div>

Hello All, I have the following docker containers running with Docker Swarm: Elastic Agent Filebeat Traefik service Spring boot app We are trying to obtain the spring boot app/traefik logs via Elastic Agent but it is…

---

## [Kibana custom dashboard does not show Filebeat metrics values](https://discuss.elastic.co/t/kibana-custom-dashboard-does-not-show-filebeat-metrics-values/317656)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 8\
**Last updated:** [October 31, 2022, 3:24pm UTC](https://discuss.elastic.co/t/kibana-custom-dashboard-does-not-show-filebeat-metrics-values/317656 "2022-10-31T15:24:54Z")

</div>

Hi, Summary of the Issue I'm having: Custom Kibana dashboard I have created to show a few internal Filebeat metrics - does not show their values (just shows zeros for all fields I selected), even though I can see that …

---

## [Filebeat Fortinet Module + Kibana SIEM](https://discuss.elastic.co/t/filebeat-fortinet-module-kibana-siem/317721)

<div class="topic-metadata">

**Author:** [@Rafa\_Moreno](https://discuss.elastic.co/u/Rafa_Moreno)\
**Replies:** 7\
**Last updated:** [October 31, 2022, 8:12am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-kibana-siem/317721 "2022-10-31T08:12:56Z")

</div>

Hi there, I have an installation of kibana and Elasticsearch, I have tried to use the fortinet filebeat module, even the elastic agent, and send the logs by syslogd, I understand that I should be able to see the fortiga…

---

## [Filebeat Kafka module with autodiscover](https://discuss.elastic.co/t/filebeat-kafka-module-with-autodiscover/317537)

<div class="topic-metadata">

**Author:** [@Avivl1](https://discuss.elastic.co/u/Avivl1)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-kafka-module-with-autodiscover/317537 "2022-10-26T14:25:19Z")

</div>

Hi, Im trying to ship logs from Kafka cluster that hosts in Kubernetes cluster with Kafka module to Elasticsearch throw log-stash , I tried to configure my filebeat.yaml and logstash pipeline like the documentation ( we…

---

## [Metricbeat 7.17.7 generate a network overload on our Kubernetes nodes and API](https://discuss.elastic.co/t/metricbeat-7-17-7-generate-a-network-overload-on-our-kubernetes-nodes-and-api/317681)

<div class="topic-metadata">

**Author:** [@sebglon](https://discuss.elastic.co/u/sebglon)\
**Replies:** 0\
**Last updated:** [October 28, 2022, 12:12pm UTC](https://discuss.elastic.co/t/metricbeat-7-17-7-generate-a-network-overload-on-our-kubernetes-nodes-and-api/317681 "2022-10-28T12:12:02Z")

</div>

After upgrading from Metricbeat 7.10 to 7.17.7, we have a production outage due to network overload on our kubernetes nodes network and API. After deleting the MetricBean daemonset, we have no more issue. We have not i…

---

## [Trying to change filebeat index](https://discuss.elastic.co/t/trying-to-change-filebeat-index/317564)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 4\
**Last updated:** [October 27, 2022, 9:21pm UTC](https://discuss.elastic.co/t/trying-to-change-filebeat-index/317564 "2022-10-27T21:21:26Z")

</div>

I am trying to change the index filebeat writes to from the default "filebeat..." to "suricata..." I have the following in my filebeat.yml: # ======================= Elasticsearch template setting ====================…

---

## [Elasticsearch integration with Zabbix](https://discuss.elastic.co/t/elasticsearch-integration-with-zabbix/316489)

<div class="topic-metadata">

**Author:** [@Muhammad\_Umar](https://discuss.elastic.co/u/Muhammad_Umar)\
**Replies:** 0\
**Last updated:** [October 13, 2022, 6:02am UTC](https://discuss.elastic.co/t/elasticsearch-integration-with-zabbix/316489 "2022-10-13T06:02:20Z")

</div>

I tried to extract log files from Zabbix to Grafana, which came out successful. Now I want to extract the same from Grafana to Elasticsearch and view the same in Kibana. Is this possible?? If “yes” explain it briefly (o…

---

## [Mage package is failed in windows](https://discuss.elastic.co/t/mage-package-is-failed-in-windows/317592)

<div class="topic-metadata">

**Author:** [@nosor70637](https://discuss.elastic.co/u/nosor70637)\
**Replies:** 0\
**Last updated:** [October 27, 2022, 7:18am UTC](https://discuss.elastic.co/t/mage-package-is-failed-in-windows/317592 "2022-10-27T07:18:22Z")

</div>

Hi, I try to build metricbeat in my windows machine, run mage package command threw error like below C:\\Program Files\\Go\\src\\beats\\metricbeat\>mage package Generated fields.yml for metricbeat to C:\\Program Files\\Go\\src\\b…

---

## [Filebeat PANW module](https://discuss.elastic.co/t/filebeat-panw-module/317357)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 2\
**Last updated:** [October 27, 2022, 3:25am UTC](https://discuss.elastic.co/t/filebeat-panw-module/317357 "2022-10-27T03:25:08Z")

</div>

Hi, Can anyone point me in the right direction getting the panw module to work. We are running filebeat 8.4 but everything I try results in: Exiting: module panw is configured but has no enabled filesets panw module …

---

## [WinEventLog\[System\] error salvaging message: failed in EvtFormatMessage: The specified resource type cannot be found in the image file](https://discuss.elastic.co/t/wineventlog-system-error-salvaging-message-failed-in-evtformatmessage-the-specified-resource-type-cannot-be-found-in-the-image-file/317579)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 0\
**Last updated:** [October 27, 2022, 3:13am UTC](https://discuss.elastic.co/t/wineventlog-system-error-salvaging-message-failed-in-evtformatmessage-the-specified-resource-type-cannot-be-found-in-the-image-file/317579 "2022-10-27T03:13:59Z")

</div>

I don't know much about windows server system, what does this error mean? How to solve? Thanks for any suggestion. {"log.level":"info","@timestamp":"2022-10-27T10:31:51.822+0800","log.origin":{"file.name":"instance/beat…

---

## [Multiline filebeat parser for aws module](https://discuss.elastic.co/t/multiline-filebeat-parser-for-aws-module/317576)

<div class="topic-metadata">

**Author:** [@Shakib\_farooq](https://discuss.elastic.co/u/Shakib_farooq)\
**Replies:** 0\
**Last updated:** [October 27, 2022, 2:32am UTC](https://discuss.elastic.co/t/multiline-filebeat-parser-for-aws-module/317576 "2022-10-27T02:32:45Z")

</div>

Hello, I am ingesting logs from AWS cloudwatch using the Aws input filebeat module but getting single-line logs in kibana. I tried to use multiline parsers as shown in the image but still, it doesn't seem to work. …

---

## [Filebeat Can't parse MSSQL Logs](https://discuss.elastic.co/t/filebeat-cant-parse-mssql-logs/316773)

<div class="topic-metadata">

**Author:** [@praveenpesala33](https://discuss.elastic.co/u/praveenpesala33)\
**Replies:** 4\
**Last updated:** [October 26, 2022, 9:01pm UTC](https://discuss.elastic.co/t/filebeat-cant-parse-mssql-logs/316773 "2022-10-26T21:01:29Z")

</div>

I have installed filebeat 7.15.1 on windows server with mssql logs module. When I run filebeat in foreground with .\\filebeat.exe -c .\\filebeat.yml -e -d "\*" , it can not parse the logs. Filebeat Config: filebeat.inputs…

---

## [Get token OAuth from Heartbeat before monitoring a service](https://discuss.elastic.co/t/get-token-oauth-from-heartbeat-before-monitoring-a-service/317526)

<div class="topic-metadata">

**Author:** [@rbr66](https://discuss.elastic.co/u/rbr66)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 2:34pm UTC](https://discuss.elastic.co/t/get-token-oauth-from-heartbeat-before-monitoring-a-service/317526 "2022-10-26T14:34:34Z")

</div>

Hi, We have a health check service that for security reasons we have secured by OAuth, then to invoke it we need to have a valid token. Our current monitor is as follows: Is it possible to get a token every so often…

---

## [Filebeat monitoring metrics are "dropped" when a GEOIP pipeline is used](https://discuss.elastic.co/t/filebeat-monitoring-metrics-are-dropped-when-a-geoip-pipeline-is-used/317063)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 23\
**Last updated:** [October 26, 2022, 12:53pm UTC](https://discuss.elastic.co/t/filebeat-monitoring-metrics-are-dropped-when-a-geoip-pipeline-is-used/317063 "2022-10-26T12:53:32Z")

</div>

Hi, this question comes as a result of solving one mystery in this post: Filebeat monitoring metrics not visible in ElasticSearch - #30 by stephenb - huge Thank You to @stephenb for his help! - where Filebeat monitoring…

---

## [Metricbeat - Error creating runner from config: failed to initialize condition](https://discuss.elastic.co/t/metricbeat-error-creating-runner-from-config-failed-to-initialize-condition/317449)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [October 26, 2022, 7:02am UTC](https://discuss.elastic.co/t/metricbeat-error-creating-runner-from-config-failed-to-initialize-condition/317449 "2022-10-26T07:02:53Z")

</div>

Attempting to fetch various bean data from Jboss instances by means of jolokia some works others fail though I can fetch them with curl, any hints appreciated on what/which condition is missing or faulty, TIA! Getting e…

---

## [Unable to configuring HeartBeat autodiscovery with hints in ECK setup](https://discuss.elastic.co/t/unable-to-configuring-heartbeat-autodiscovery-with-hints-in-eck-setup/317309)

<div class="topic-metadata">

**Author:** [@diadoom](https://discuss.elastic.co/u/diadoom)\
**Replies:** 4\
**Last updated:** [October 25, 2022, 5:39pm UTC](https://discuss.elastic.co/t/unable-to-configuring-heartbeat-autodiscovery-with-hints-in-eck-setup/317309 "2022-10-25T17:39:21Z")

</div>

hello! I'm trying to configure heartbeat in ECK using the autodiscovery configuration with hints, however using the config in ECK does not seem to work. It used to work when I had a self managed elastic setup running i…

---

## [Metricbeat Configuration on eck](https://discuss.elastic.co/t/metricbeat-configuration-on-eck/317257)

<div class="topic-metadata">

**Author:** [@emmanuel\_stevens\_LED](https://discuss.elastic.co/u/emmanuel_stevens_LED)\
**Replies:** 7\
**Last updated:** [October 25, 2022, 5:31pm UTC](https://discuss.elastic.co/t/metricbeat-configuration-on-eck/317257 "2022-10-25T17:31:48Z")

</div>

Hello, I am trying to send data from a container ubuntu to eck. Below you can see my configuration output.elasticsearch: Array of hosts to connect to. hosts: \["https://elasticsearch-es-internal-http:9200"\] Protocol…

---

## [Filebeat on local laptop does not talk to the Elasticsearch (also on local laptop) - dial tcp \[::1\]:9200: connect: cannot assign requested address](https://discuss.elastic.co/t/filebeat-on-local-laptop-does-not-talk-to-the-elasticsearch-also-on-local-laptop-dial-tcp-1-connect-cannot-assign-requested-address/317145)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 6\
**Last updated:** [October 24, 2022, 8:13pm UTC](https://discuss.elastic.co/t/filebeat-on-local-laptop-does-not-talk-to-the-elasticsearch-also-on-local-laptop-dial-tcp-1-connect-cannot-assign-requested-address/317145 "2022-10-24T20:13:24Z")

</div>

Hi, I am trying to setup Elsticsearch 8, Kibana and Filebeat 8 all on my local laptop, using this guide: I've got ES and Kibana running in Docker containers and communicating just fine. Next, I want to send events fr…

---

## [WINLOGBEAT-NIFI-LISTENBEATS1.18.0 don't work correctly](https://discuss.elastic.co/t/winlogbeat-nifi-listenbeats1-18-0-dont-work-correctly/317110)

<div class="topic-metadata">

**Author:** [@IamYipi](https://discuss.elastic.co/u/IamYipi)\
**Replies:** 2\
**Last updated:** [October 23, 2022, 11:32pm UTC](https://discuss.elastic.co/t/winlogbeat-nifi-listenbeats1-18-0-dont-work-correctly/317110 "2022-10-23T23:32:44Z")

</div>

Hi All, I ship windows events using ListenBeats in NiFi, when the data arrived is duplicated in 2 FlowFiles. I show winlogbeat's config: winlogbeat.event\_logs: name: Microsoft-Windows-Windows Defender/Operational -…

---

## [Can't setup Elasticsearch cluster monitoring with Metricbeat](https://discuss.elastic.co/t/cant-setup-elasticsearch-cluster-monitoring-with-metricbeat/317159)

<div class="topic-metadata">

**Author:** [@Ensjo](https://discuss.elastic.co/u/Ensjo)\
**Replies:** 0\
**Last updated:** [October 21, 2022, 1:36am UTC](https://discuss.elastic.co/t/cant-setup-elasticsearch-cluster-monitoring-with-metricbeat/317159 "2022-10-21T01:36:44Z")

</div>

Hello. I have a cluster with 3 Elasticsearch master servers (7.17.6) on Windows 10. Here is my elasticsearch.yml for the first server (commented lines deleted, names and IPs edited): cluster.name: MyCluster node.name: M…

---

## [Filebeat service doesn't send apache logs](https://discuss.elastic.co/t/filebeat-service-doesnt-send-apache-logs/317277)

<div class="topic-metadata">

**Author:** [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Replies:** 1\
**Last updated:** [October 23, 2022, 4:19pm UTC](https://discuss.elastic.co/t/filebeat-service-doesnt-send-apache-logs/317277 "2022-10-23T16:19:49Z")

</div>

This is my current configuration file. filebeat.inputs: - type: log enabled: true paths: - /var/log/apache2/\*.log output.logstash: hosts: \["localhost:5044"\] enabled: true setup.dashboards.enabled: true set…

---

## [Windows could not start the elastic winglogbeat-Oss 8.3.3 service](https://discuss.elastic.co/t/windows-could-not-start-the-elastic-winglogbeat-oss-8-3-3-service/316455)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 6\
**Last updated:** [October 22, 2022, 3:40pm UTC](https://discuss.elastic.co/t/windows-could-not-start-the-elastic-winglogbeat-oss-8-3-3-service/316455 "2022-10-22T15:40:06Z")

</div>

Hi, I installed winlogbeat. I tried to start the service and I got this?

---

## [Cannot get Auditbeat add\_docker\_metadata to work](https://discuss.elastic.co/t/cannot-get-auditbeat-add-docker-metadata-to-work/317243)

<div class="topic-metadata">

**Author:** [@m-a-x-e-d](https://discuss.elastic.co/u/m-a-x-e-d)\
**Replies:** 0\
**Last updated:** [October 22, 2022, 9:37am UTC](https://discuss.elastic.co/t/cannot-get-auditbeat-add-docker-metadata-to-work/317243 "2022-10-22T09:37:29Z")

</div>

Hello there! I am running an ELK Stack 7.17.6 in Docker on Linux and am trying to collect audit data with auditbeat. Everything works fine, but for some reason, no docker metadata is added to events, even if the process…

---

## [Auditbeat configuration pass dynamic shell environment variable](https://discuss.elastic.co/t/auditbeat-configuration-pass-dynamic-shell-environment-variable/316752)

<div class="topic-metadata">

**Author:** [@satendra1987](https://discuss.elastic.co/u/satendra1987)\
**Replies:** 6\
**Last updated:** [October 21, 2022, 6:01am UTC](https://discuss.elastic.co/t/auditbeat-configuration-pass-dynamic-shell-environment-variable/316752 "2022-10-21T06:01:15Z")

</div>

Hi, we need to get a custom field in auditbeat kibana logs and this field value has to come from a shell environment variable. this shell environment variable value can be different on each shell opened. Thanks Satend…

---

## [Filebeat Nginx module not producing url.domain field if domain contains "\_" (underscore)](https://discuss.elastic.co/t/filebeat-nginx-module-not-producing-url-domain-field-if-domain-contains-underscore/317146)

<div class="topic-metadata">

**Author:** [@haikosaw](https://discuss.elastic.co/u/haikosaw)\
**Replies:** 2\
**Last updated:** [October 20, 2022, 7:46pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-not-producing-url-domain-field-if-domain-contains-underscore/317146 "2022-10-20T19:46:42Z")

</div>

Hello. I´m having an issue where I'm using the Nginx module in Filebeat 8.4.2 (via ES\_Agent and Fleet). After searching for a while why sometimes I would get the url.domain field, and sometimes not, I noticed that when…

---

## [Show failed GDM logins on Login Dasboard](https://discuss.elastic.co/t/show-failed-gdm-logins-on-login-dasboard/317039)

<div class="topic-metadata">

**Author:** [@dredshaw](https://discuss.elastic.co/u/dredshaw)\
**Replies:** 2\
**Last updated:** [October 20, 2022, 3:43pm UTC](https://discuss.elastic.co/t/show-failed-gdm-logins-on-login-dasboard/317039 "2022-10-20T15:43:58Z")

</div>

I am using Auditbeat on a standalone system in a closed area with no internet access. I set up Elasticsearch, Kibana, and Auditbeat to audit the system. This was easy enough. I Would like to get the Login Dashboard to…

---

## [Unable to get local Kibana to read any data from remote Metricbeat](https://discuss.elastic.co/t/unable-to-get-local-kibana-to-read-any-data-from-remote-metricbeat/317056)

<div class="topic-metadata">

**Author:** [@nola](https://discuss.elastic.co/u/nola)\
**Replies:** 3\
**Last updated:** [October 20, 2022, 2:54pm UTC](https://discuss.elastic.co/t/unable-to-get-local-kibana-to-read-any-data-from-remote-metricbeat/317056 "2022-10-20T14:54:52Z")

</div>

I have Kibana installed on my local machine and have Elasticsearch and Metricbeat installed on a remote AWS EC2 instance. For simplicity, let's say the public IP address of the AWS box is http://1.2.3.4. In my local ki…

---

## [Filebeat not respect order of file?](https://discuss.elastic.co/t/filebeat-not-respect-order-of-file/317011)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 6\
**Last updated:** [October 20, 2022, 12:35pm UTC](https://discuss.elastic.co/t/filebeat-not-respect-order-of-file/317011 "2022-10-20T12:35:00Z")

</div>

filebeat at indexed at last to "server.log.2022-07-27" but the last is server.log why? not respect the name of file but the size of file? -rw-r--r--. 1 wildfly wildfly 0 Apr 20 18:25 audit.log -rw-r--r--. 1 wi…

---

## [Custom Fields Cannot Process by Filebeat](https://discuss.elastic.co/t/custom-fields-cannot-process-by-filebeat/317103)

<div class="topic-metadata">

**Author:** [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Replies:** 0\
**Last updated:** [October 20, 2022, 11:50am UTC](https://discuss.elastic.co/t/custom-fields-cannot-process-by-filebeat/317103 "2022-10-20T11:50:40Z")

</div>

Hi Team, I successfully able to dissect log.original field in my cisco module and turn it into a custom field host.name. When I try to make indices using this custom field host.name, the indices where not created. Tha…

---

## [Index Creation for Fortinet Devices Fail](https://discuss.elastic.co/t/index-creation-for-fortinet-devices-fail/316116)

<div class="topic-metadata">

**Author:** [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Replies:** 2\
**Last updated:** [October 20, 2022, 10:19am UTC](https://discuss.elastic.co/t/index-creation-for-fortinet-devices-fail/316116 "2022-10-20T10:19:45Z")

</div>

Hello Elastic Team, I would like to ask for help for I my filebeat seems like to fail creating index for my fortinet firewall (I use Fortinet filebeat module). Filebeat version is 7.17.15. However, the fortigate logs fa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=69)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=71)
