# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=72

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 73

---

## [Filebeat version that refreshes service account kubernetes tokens](https://discuss.elastic.co/t/filebeat-version-that-refreshes-service-account-kubernetes-tokens/314489)

<div class="topic-metadata">

**Author:** [@dedimitr](https://discuss.elastic.co/u/dedimitr)\
**Replies:** 1\
**Last updated:** [October 13, 2022, 4:45am UTC](https://discuss.elastic.co/t/filebeat-version-that-refreshes-service-account-kubernetes-tokens/314489 "2022-10-13T04:45:20Z")

</div>

Using filebeat version 6.6.2. I went through the docs but I just can't figure out to which version should I update, so that it starts refreshing kubernetes service account tokens? 'Service account tokens have an expirat…

---

## [Filebeat-Apache Module- Nodata](https://discuss.elastic.co/t/filebeat-apache-module-nodata/314977)

<div class="topic-metadata">

**Author:** [@emmanuel\_stevens\_LED](https://discuss.elastic.co/u/emmanuel_stevens_LED)\
**Replies:** 5\
**Last updated:** [October 12, 2022, 3:27pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-nodata/314977 "2022-10-12T15:27:56Z")

</div>

Hello, I configure filebeat in my system, the probleme is, whaen i configure the modure system , i receive all datas and graphic, it is not the same for apache. We donot receive anaything I have enable the module and c…

---

## [\[Filebeat\]\[xpack\]\[httpjson\] - OAuth2 use without client secret and with url params is not possible](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691)

<div class="topic-metadata">

**Author:** [@p-leh](https://discuss.elastic.co/u/p-leh)\
**Replies:** 8\
**Last updated:** [October 12, 2022, 9:33am UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691 "2022-10-12T09:33:32Z")

</div>

The xpack input module httpjson for filebeat can handle the OAuth2 process. We want to use httpjson against a cloud foundry setup which is not possible. The problem comes up because on two hard coded contraints: the "…

---

## [Filebeat Input Azure Event Hub Private Endpoint](https://discuss.elastic.co/t/filebeat-input-azure-event-hub-private-endpoint/316422)

<div class="topic-metadata">

**Author:** [@Erylis](https://discuss.elastic.co/u/Erylis)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 9:18am UTC](https://discuss.elastic.co/t/filebeat-input-azure-event-hub-private-endpoint/316422 "2022-10-12T09:18:24Z")

</div>

Hello, I'm trying to connect filebeat with an azure eventhub using a private endpoint. The connection doesn't work properly because of a certificate issue : 2022-10-11T09:06:38.358+0200 ERROR \[azure-eventhub input…

---

## [Filebeat modules via Logstash?](https://discuss.elastic.co/t/filebeat-modules-via-logstash/316307)

<div class="topic-metadata">

**Author:** [@dygland](https://discuss.elastic.co/u/dygland)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 5:20am UTC](https://discuss.elastic.co/t/filebeat-modules-via-logstash/316307 "2022-10-12T05:20:55Z")

</div>

Hello! TLDR: How do we setup and update module dashboards and pipelines without connectivity between filebeat and Kibana/ES hosts directly? Long version: We're using Filebeat without direct access to ES nor Kibana, ev…

---

## [Aws ecs filebeat log collection stops when the application containers are restarted](https://discuss.elastic.co/t/aws-ecs-filebeat-log-collection-stops-when-the-application-containers-are-restarted/311832)

<div class="topic-metadata">

**Author:** [@vaseem\_tt](https://discuss.elastic.co/u/vaseem_tt)\
**Replies:** 6\
**Last updated:** [October 12, 2022, 5:07am UTC](https://discuss.elastic.co/t/aws-ecs-filebeat-log-collection-stops-when-the-application-containers-are-restarted/311832 "2022-10-12T05:07:45Z")

</div>

We collect the logs of the container of our java application on ecs with the container of Filebeat. When any one or multiple container in the AWS ECS intance restart continously, filebeat container stops pushing logs to…

---

## [Filebeat module enable](https://discuss.elastic.co/t/filebeat-module-enable/316389)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 12:19am UTC](https://discuss.elastic.co/t/filebeat-module-enable/316389 "2022-10-12T00:19:05Z")

</div>

Hi, Does anyone know if the "filebeat module enable" command does anything other than remove the .disabled from the file name? I am deploying via Ansible, so would like to just rename/overwrite the file without running…

---

## [Filebeat doesn't resolve variable set for kubernetes pod](https://discuss.elastic.co/t/filebeat-doesnt-resolve-variable-set-for-kubernetes-pod/316356)

<div class="topic-metadata">

**Author:** [@jmandrive](https://discuss.elastic.co/u/jmandrive)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 4:03pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-resolve-variable-set-for-kubernetes-pod/316356 "2022-10-11T16:03:24Z")

</div>

Dears, I want to customize index as per the environment (prod, dev , ...), the filebeat couldn't substitue the value of "kubernetes.labels.env" and put instead "na" The index definiton inside output section in filebea…

---

## [Filebeat Error creating runner from config: failed to initialize condition](https://discuss.elastic.co/t/filebeat-error-creating-runner-from-config-failed-to-initialize-condition/316351)

<div class="topic-metadata">

**Author:** [@juliana\_cg](https://discuss.elastic.co/u/juliana_cg)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 3:37pm UTC](https://discuss.elastic.co/t/filebeat-error-creating-runner-from-config-failed-to-initialize-condition/316351 "2022-10-11T15:37:39Z")

</div>

Hello, Got Filebeat installed as a daemonset in Kubernetes cluster, to collect logs from different pods using hint autodiscovery. On filebeat logs we have plenty of errors of this type: ERROR \[autodiscover\] cfg…

---

## [Elastic agent in k8s after several days stops sending same metrics](https://discuss.elastic.co/t/elastic-agent-in-k8s-after-several-days-stops-sending-same-metrics/316342)

<div class="topic-metadata">

**Author:** [@gabrielfsousa](https://discuss.elastic.co/u/gabrielfsousa)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 2:32pm UTC](https://discuss.elastic.co/t/elastic-agent-in-k8s-after-several-days-stops-sending-same-metrics/316342 "2022-10-11T14:32:16Z")

</div>

in 7.16.2 after installing elastic agent in k8s everything works. but after several days stops sending same metrics. if i restart the elastic agent pods, starts working good. there's NOTHING in the logs. ZERO errors …

---

## [🐌 Poor search performance when searching in data stream indexes](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531)

<div class="topic-metadata">

**Author:** [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Replies:** 4\
**Last updated:** [October 11, 2022, 10:48am UTC](https://discuss.elastic.co/t/poor-search-performance-when-searching-in-data-stream-indexes/315531 "2022-10-11T10:48:00Z")

</div>

Hi! :wave: I have a pretty small amount of documents from Metricbeat and I have loaded them into 2 ways into Elasticsearch: Using the default Metricbeat index template and datastream (created by Metricbeat), ILM poli…

---

## [Can Filebeat access certs within a docker container?](https://discuss.elastic.co/t/can-filebeat-access-certs-within-a-docker-container/316004)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 3\
**Last updated:** [October 11, 2022, 8:09am UTC](https://discuss.elastic.co/t/can-filebeat-access-certs-within-a-docker-container/316004 "2022-10-11T08:09:42Z")

</div>

Hi, we are currently running an application on a server through Docker. Unfortunately, the certs and logs are within the container itself. When setting up Filebeat, I was wondering if there was a way to access those cer…

---

## [How to store index in elasticsearch if disk space is full on server](https://discuss.elastic.co/t/how-to-store-index-in-elasticsearch-if-disk-space-is-full-on-server/315520)

<div class="topic-metadata">

**Author:** [@aniketdatir](https://discuss.elastic.co/u/aniketdatir)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 7:21pm UTC](https://discuss.elastic.co/t/how-to-store-index-in-elasticsearch-if-disk-space-is-full-on-server/315520 "2022-10-10T19:21:25Z")

</div>

Hi team, I want to store disk space related data in to elastic index through Metricbeat. kindly guide me how to achieve this?

---

## [Ndjson appears to be ignoring my log line](https://discuss.elastic.co/t/ndjson-appears-to-be-ignoring-my-log-line/315971)

<div class="topic-metadata">

**Author:** [@ledzepp4eva](https://discuss.elastic.co/u/ledzepp4eva)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 7:14pm UTC](https://discuss.elastic.co/t/ndjson-appears-to-be-ignoring-my-log-line/315971 "2022-10-10T19:14:47Z")

</div>

Hey, I am hoping you can point out my silly mistake here. filebeat.inputs: - type: filestream id: nginx-stream-json-id paths: - /var/log/nginx/\*.stream.access.log parser: - ndjson: t…

---

## [Docker Filebeats for raspberrpi 4 aarch64](https://discuss.elastic.co/t/docker-filebeats-for-raspberrpi-4-aarch64/316011)

<div class="topic-metadata">

**Author:** [@Nlmyr](https://discuss.elastic.co/u/Nlmyr)\
**Replies:** 3\
**Last updated:** [October 10, 2022, 5:39pm UTC](https://discuss.elastic.co/t/docker-filebeats-for-raspberrpi-4-aarch64/316011 "2022-10-10T17:39:38Z")

</div>

Is Docker Filebeats for raspberrpi 4 aarch64 available?

---

## [Build your own Beat in Go](https://discuss.elastic.co/t/build-your-own-beat-in-go/316066)

<div class="topic-metadata">

**Author:** [@adrianfusco](https://discuss.elastic.co/u/adrianfusco)\
**Replies:** 4\
**Last updated:** [October 10, 2022, 5:38pm UTC](https://discuss.elastic.co/t/build-your-own-beat-in-go/316066 "2022-10-10T17:38:11Z")

</div>

I needed to send messages to Logstash using Beat from a little app I'm developing in Go. I've seen different ways to do it without doing calling services as filebeat to not create a dependency. I was taking a look to t…

---

## [Winlogbeat may leak PublisherHandle, and lead to failure of sysmon uninstalling](https://discuss.elastic.co/t/winlogbeat-may-leak-publisherhandle-and-lead-to-failure-of-sysmon-uninstalling/316246)

<div class="topic-metadata">

**Author:** [@Serinalice](https://discuss.elastic.co/u/Serinalice)\
**Replies:** 0\
**Last updated:** [October 10, 2022, 4:21pm UTC](https://discuss.elastic.co/t/winlogbeat-may-leak-publisherhandle-and-lead-to-failure-of-sysmon-uninstalling/316246 "2022-10-10T16:21:06Z")

</div>

When I use "github.com/elastic/beats/v7/winlogbeat" library to build my app which manages sysmon and reads events of sysmon from windows event system, I found the app uninstall sysmon failed. This is the minimal code to …

---

## [Filebeat can't process all the logs](https://discuss.elastic.co/t/filebeat-cant-process-all-the-logs/316017)

<div class="topic-metadata">

**Author:** [@adityak248](https://discuss.elastic.co/u/adityak248)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-cant-process-all-the-logs/316017 "2022-10-10T15:56:01Z")

</div>

Hello team, Greeting, I have a setup that will push the logs from filebeat to logstash to elastic. Here is my filebeat configs filebeat.inputs: - type: log enabled: true paths: - '/var/www/log/myapp.log' clos…

---

## [File Mirroring via FileBeat or Logstash](https://discuss.elastic.co/t/file-mirroring-via-filebeat-or-logstash/315973)

<div class="topic-metadata">

**Author:** [@shocko](https://discuss.elastic.co/u/shocko)\
**Replies:** 8\
**Last updated:** [October 9, 2022, 9:45pm UTC](https://discuss.elastic.co/t/file-mirroring-via-filebeat-or-logstash/315973 "2022-10-09T21:45:48Z")

</div>

I have the following use case for several directories containing log files: Tail these files and write out to another location with the same filename For example, our app is creating files names myapp\_.log and we need…

---

## [Why I have log duplication when filebeat read rotating log files and stop filebeat for specific time manually and default close inactive reached](https://discuss.elastic.co/t/why-i-have-log-duplication-when-filebeat-read-rotating-log-files-and-stop-filebeat-for-specific-time-manually-and-default-close-inactive-reached/314663)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 6\
**Last updated:** [October 8, 2022, 4:58am UTC](https://discuss.elastic.co/t/why-i-have-log-duplication-when-filebeat-read-rotating-log-files-and-stop-filebeat-for-specific-time-manually-and-default-close-inactive-reached/314663 "2022-10-08T04:58:17Z")

</div>

I set filebeat to read logs from rotating logs (rotated when 5 mg is reached) and below is my config : - type: log fields: source: 'filebeat2' logID: logbackup fields\_under\_root: true enabled: true paths: - /…

---

## [Filebeat ILM policy question](https://discuss.elastic.co/t/filebeat-ilm-policy-question/316077)

<div class="topic-metadata">

**Author:** [@Mark\_Visser](https://discuss.elastic.co/u/Mark_Visser)\
**Replies:** 8\
**Last updated:** [October 7, 2022, 5:11pm UTC](https://discuss.elastic.co/t/filebeat-ilm-policy-question/316077 "2022-10-07T17:11:57Z")

</div>

Hello, For my filebeat rollover to work it expects an alias to be set on the index. In the past you were able to pass along a rollover\_alias in the filebeat config but that is not possible anymore. I found you can manu…

---

## [Metricbeat 7.17.6 - Cannot index event](https://discuss.elastic.co/t/metricbeat-7-17-6-cannot-index-event/316057)

<div class="topic-metadata">

**Author:** [@jColfej](https://discuss.elastic.co/u/jColfej)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 9:47am UTC](https://discuss.elastic.co/t/metricbeat-7-17-6-cannot-index-event/316057 "2022-10-07T09:47:39Z")

</div>

Following our cluster upgrade to Elasticsearch 7.17.6, we had to migrate the monitoring stack using Metricbeat. In Kibana, monitoring is not working, hosts are marked as unmonitored even though Metricbeat is on all host…

---

## [How to view contents of heartbeat keystore](https://discuss.elastic.co/t/how-to-view-contents-of-heartbeat-keystore/315933)

<div class="topic-metadata">

**Author:** [@swchandu](https://discuss.elastic.co/u/swchandu)\
**Replies:** 2\
**Last updated:** [October 7, 2022, 4:26am UTC](https://discuss.elastic.co/t/how-to-view-contents-of-heartbeat-keystore/315933 "2022-10-07T04:26:47Z")

</div>

Hi, I am trying to check if we can display the contents and values of the heartbeat.keystore. Is there any command to display the entries and values? I am unable to find the documentation on this. can someone help me …

---

## [Kafka-beats-logstash](https://discuss.elastic.co/t/kafka-beats-logstash/314902)

<div class="topic-metadata">

**Author:** [@emmanuel\_stevens\_LED](https://discuss.elastic.co/u/emmanuel_stevens_LED)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 3:50pm UTC](https://discuss.elastic.co/t/kafka-beats-logstash/314902 "2022-10-06T15:50:42Z")

</div>

Hello, I have difficulties with a task. I received help from @stephenb to configure My ELKK, it works fine. https://discuss.elastic.co/t/metribeats-to-kafka-no-dashboard-appear-in-kibana/309688/15 My probleme is for t…

---

## [Filter unstructured logs with filebeat before sending to logstash](https://discuss.elastic.co/t/filter-unstructured-logs-with-filebeat-before-sending-to-logstash/315960)

<div class="topic-metadata">

**Author:** [@Ihms](https://discuss.elastic.co/u/Ihms)\
**Replies:** 2\
**Last updated:** [October 6, 2022, 3:05pm UTC](https://discuss.elastic.co/t/filter-unstructured-logs-with-filebeat-before-sending-to-logstash/315960 "2022-10-06T15:05:40Z")

</div>

Hello, I'm new to Elasticsearch and have some questions. Filebeat is fetching way too many logs and for the sake of bandwidth, I want to filter the logs at the edge before sending to logstash. The logs don't have the s…

---

## [Data loss when sending logs to Kibana through Filebeat](https://discuss.elastic.co/t/data-loss-when-sending-logs-to-kibana-through-filebeat/315926)

<div class="topic-metadata">

**Author:** [@xyu](https://discuss.elastic.co/u/xyu)\
**Replies:** 7\
**Last updated:** [October 6, 2022, 1:59pm UTC](https://discuss.elastic.co/t/data-loss-when-sending-logs-to-kibana-through-filebeat/315926 "2022-10-06T13:59:31Z")

</div>

Hi, I am new to elastic stalk and currently I am facing some difficulties to read all the logs in JSON format. {"code":"28000","file":"auth.c","length":164,"level":"error","line":"496","message":"no entry for host","na…

---

## [Filebeat setup: error loading index pattern: returned 413 to import file: invalid character ‘\<’ looking for beginning of value](https://discuss.elastic.co/t/filebeat-setup-error-loading-index-pattern-returned-413-to-import-file-invalid-character-looking-for-beginning-of-value/315329)

<div class="topic-metadata">

**Author:** [@Nick95](https://discuss.elastic.co/u/Nick95)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-setup-error-loading-index-pattern-returned-413-to-import-file-invalid-character-looking-for-beginning-of-value/315329 "2022-10-06T13:50:49Z")

</div>

Hi, I try to run a filebeat on a server. Elastic and Kibana are installed on another server and are pushed on 443 port via a Nginx reverse proxy. Kibana GUI is working on the IP I set up (https with self-generated certi…

---

## [Host File or Wildcards for Heartbeat](https://discuss.elastic.co/t/host-file-or-wildcards-for-heartbeat/315906)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 1\
**Last updated:** [October 5, 2022, 6:48pm UTC](https://discuss.elastic.co/t/host-file-or-wildcards-for-heartbeat/315906 "2022-10-05T18:48:46Z")

</div>

I'm trying to set up Heartbeat and looking for an efficient way to manage the host list for the icmp monitor. Is there an option to either reference a host file or to somehow use wildcards for the hosts list? I've looked…

---

## [Drop irrelevant filebeat docker metadata not working](https://discuss.elastic.co/t/drop-irrelevant-filebeat-docker-metadata-not-working/315887)

<div class="topic-metadata">

**Author:** [@Chma](https://discuss.elastic.co/u/Chma)\
**Replies:** 0\
**Last updated:** [October 5, 2022, 2:23pm UTC](https://discuss.elastic.co/t/drop-irrelevant-filebeat-docker-metadata-not-working/315887 "2022-10-05T14:23:23Z")

</div>

I am using filebeat to ship container logs to ELK. I have way too many metadata that I don't need. container.id, container.name, conatiner.labels, container.image and so on. The only one I need her is container.name, so…

---

## [Metricbeat PostgreSQL module missing Database Name](https://discuss.elastic.co/t/metricbeat-postgresql-module-missing-database-name/315881)

<div class="topic-metadata">

**Author:** [@robdiluca](https://discuss.elastic.co/u/robdiluca)\
**Replies:** 0\
**Last updated:** [October 5, 2022, 1:09pm UTC](https://discuss.elastic.co/t/metricbeat-postgresql-module-missing-database-name/315881 "2022-10-05T13:09:41Z")

</div>

Hi all, I'm using the Metricbeat PostgreSQL module and the related default Kibana Dashboard. However, when activating the "statement" metricset, I noticed the documents it produce do not contain the field "postgresql.da…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=71)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=73)
