# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=74

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 75

---

## [Ingest pipeline unable to create new field from message data](https://discuss.elastic.co/t/ingest-pipeline-unable-to-create-new-field-from-message-data/315123)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 5:57am UTC](https://discuss.elastic.co/t/ingest-pipeline-unable-to-create-new-field-from-message-data/315123 "2022-09-26T05:57:40Z")

</div>

Hello Team, We are trying to create an ingest pipeline using filebeat for below log pattern to create new field "elasticsearch.slowlog.took\_millis="16"" from below slowlog message, but unable to find proper documentatio…

---

## [ELK Log Push from Device - Proactive Monitoring](https://discuss.elastic.co/t/elk-log-push-from-device-proactive-monitoring/314880)

<div class="topic-metadata">

**Author:** [@Arunachalam\_Jayarama](https://discuss.elastic.co/u/Arunachalam_Jayarama)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 3:51am UTC](https://discuss.elastic.co/t/elk-log-push-from-device-proactive-monitoring/314880 "2022-09-26T03:51:46Z")

</div>

Dear All, I am looking for a way, by which we can proactively monitor the log push from 100s of devices to ELK. Recently I came across a problem, devices were connected/configured to push the data to ELK stack, but du…

---

## [Filebeat log file input empty in Kibana](https://discuss.elastic.co/t/filebeat-log-file-input-empty-in-kibana/315093)

<div class="topic-metadata">

**Author:** [@Karthik\_ELK](https://discuss.elastic.co/u/Karthik_ELK)\
**Replies:** 1\
**Last updated:** [September 25, 2022, 11:04pm UTC](https://discuss.elastic.co/t/filebeat-log-file-input-empty-in-kibana/315093 "2022-09-25T23:04:45Z")

</div>

Hi, I just started learning ELK stack. I'm trying to send logs via a log file from Filebeat directly to Elastic. Each row in the log file is a json. filebeat.yml file is shown below. I'm running all these services using…

---

## [Multiple log entries in filebeat each with its id and multiple processors](https://discuss.elastic.co/t/multiple-log-entries-in-filebeat-each-with-its-id-and-multiple-processors/314987)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 2\
**Last updated:** [September 23, 2022, 6:41pm UTC](https://discuss.elastic.co/t/multiple-log-entries-in-filebeat-each-with-its-id-and-multiple-processors/314987 "2022-09-23T18:41:42Z")

</div>

I am trying to configure filebeat so that it obtains logs from a server which is running 3 applications, the most logical thing is that each one has its id as a reference, for this configure 3 entries with its specific p…

---

## [Filebeat log gets flooded if no Kafka topic is available](https://discuss.elastic.co/t/filebeat-log-gets-flooded-if-no-kafka-topic-is-available/314702)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 1\
**Last updated:** [September 23, 2022, 5:14pm UTC](https://discuss.elastic.co/t/filebeat-log-gets-flooded-if-no-kafka-topic-is-available/314702 "2022-09-23T17:14:42Z")

</div>

Hi, I have an issue where Filebeat tries to send data to a Kafka topic that doesn't exist anymore. The Filebeat logs are flooded with: 2022-09-19T13:47:29.111Z INFO \[publisher\] pipeline/retry.go:223 d…

---

## [AuditD module - right usage and syntax of -q flag in auditd rules](https://discuss.elastic.co/t/auditd-module-right-usage-and-syntax-of-q-flag-in-auditd-rules/315009)

<div class="topic-metadata">

**Author:** [@Lukas\_Hubl](https://discuss.elastic.co/u/Lukas_Hubl)\
**Replies:** 0\
**Last updated:** [September 23, 2022, 10:52am UTC](https://discuss.elastic.co/t/auditd-module-right-usage-and-syntax-of-q-flag-in-auditd-rules/315009 "2022-09-23T10:52:19Z")

</div>

Hi, I would like to use -q flag in auditd rule, but the rule with the -q flag is not working or even added into the rules list. I have rule like this: -a always,exit -F path=/home/lukashubl/ -q /home/lukashubl/dirtest…

---

## [Pod annotation co.elastic.logs/pipeline does not work?](https://discuss.elastic.co/t/pod-annotation-co-elastic-logs-pipeline-does-not-work/313670)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 4\
**Last updated:** [September 23, 2022, 10:14am UTC](https://discuss.elastic.co/t/pod-annotation-co-elastic-logs-pipeline-does-not-work/313670 "2022-09-23T10:14:27Z")

</div>

Hi, I have a Logstash pipeline pipeline running in kubernetes. I am collecting all logs from the Kubernetes cluster using filebeat with activated hit based autodiscover. I would like to force filebeat to use a specific …

---

## [Problems getting filebeats to work with API keys](https://discuss.elastic.co/t/problems-getting-filebeats-to-work-with-api-keys/314982)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 0\
**Last updated:** [September 23, 2022, 12:43am UTC](https://discuss.elastic.co/t/problems-getting-filebeats-to-work-with-api-keys/314982 "2022-09-23T00:43:02Z")

</div>

I have just got filebeats (7.17.1) working on a bunch of ubuntu systems. I initially tried to use API keys for authentication but got errors from filebeat "API key: invalid ApiKey value" when it connects to the ES serv…

---

## [O365 module: No such input type exist: 'o365audit'](https://discuss.elastic.co/t/o365-module-no-such-input-type-exist-o365audit/314848)

<div class="topic-metadata">

**Author:** [@sriramb12](https://discuss.elastic.co/u/sriramb12)\
**Replies:** 4\
**Last updated:** [September 22, 2022, 7:52pm UTC](https://discuss.elastic.co/t/o365-module-no-such-input-type-exist-o365audit/314848 "2022-09-22T19:52:58Z")

</div>

The beat is throwing this error: Sep 21 14:57:51 xxxx.lan filebeat\[17245\]: {"log.level":"debug","@timestamp":"2022-09-21T14:57:51.483+0530","log.logger":"processors","log.origin":{"file.name":"processors/processor.go","…

---

## [What is the default time-frame for a query ? where to configure the same?](https://discuss.elastic.co/t/what-is-the-default-time-frame-for-a-query-where-to-configure-the-same/314946)

<div class="topic-metadata">

**Author:** [@sriramb12](https://discuss.elastic.co/u/sriramb12)\
**Replies:** 1\
**Last updated:** [September 22, 2022, 3:00pm UTC](https://discuss.elastic.co/t/what-is-the-default-time-frame-for-a-query-where-to-configure-the-same/314946 "2022-09-22T15:00:01Z")

</div>

When the filebeat makes a query, it should be able to specify the time period (say last 1 day, 1hr etc) to get the logs. I am not able to find the config. parameter in the filebeat.yml (or in o365.yml) For instance when…

---

## [Linux Auditd monitoring of file operations in mounted folder](https://discuss.elastic.co/t/linux-auditd-monitoring-of-file-operations-in-mounted-folder/314940)

<div class="topic-metadata">

**Author:** [@Lukas\_Hubl](https://discuss.elastic.co/u/Lukas_Hubl)\
**Replies:** 0\
**Last updated:** [September 22, 2022, 12:21pm UTC](https://discuss.elastic.co/t/linux-auditd-monitoring-of-file-operations-in-mounted-folder/314940 "2022-09-22T12:21:51Z")

</div>

I have multi node kubernetes cluster and I would like to monitor file operations that are made by containers in mounted persistent volume. I found the all PV data are located at nodes in /var/lib/kubelet/pods/\<container-…

---

## [Filtering data in Filebeat](https://discuss.elastic.co/t/filtering-data-in-filebeat/314918)

<div class="topic-metadata">

**Author:** [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Replies:** 0\
**Last updated:** [September 22, 2022, 7:15am UTC](https://discuss.elastic.co/t/filtering-data-in-filebeat/314918 "2022-09-22T07:15:34Z")

</div>

Hello ! I work on a Proxmox server where I installed a Firewall PfSense router with three interfaces (LAN, DMZ, WAN) with different "user" VMs and as well as servers (web and bdd). So I installed Wazuh and Suricata to …

---

## [Failing to get filebeat with suricata module to work](https://discuss.elastic.co/t/failing-to-get-filebeat-with-suricata-module-to-work/314835)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 7\
**Last updated:** [September 22, 2022, 5:14am UTC](https://discuss.elastic.co/t/failing-to-get-filebeat-with-suricata-module-to-work/314835 "2022-09-22T05:14:29Z")

</div>

I have installed filebeat (7.17.1) on an ubuntu system. Run the setup stuff and loaded the dashboards into kibana. I have also "enabled" the suricata module, first by simply adding the appropriate stuff into /etc/fileb…

---

## [Filebeat.input and filebeat.config.modules:](https://discuss.elastic.co/t/filebeat-input-and-filebeat-config-modules/314773)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 7\
**Last updated:** [September 21, 2022, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-input-and-filebeat-config-modules/314773 "2022-09-21T13:16:32Z")

</div>

Hello, First I don't understand the role of this option in the config of filebeat , i read the docuentation but i don't understand exactly the fonction of it because i let it false and i receive the logs of the ubuntu in…

---

## [How to define multiline in filebeat.inputs base on image?](https://discuss.elastic.co/t/how-to-define-multiline-in-filebeat-inputs-base-on-image/314780)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 2\
**Last updated:** [September 21, 2022, 4:58am UTC](https://discuss.elastic.co/t/how-to-define-multiline-in-filebeat-inputs-base-on-image/314780 "2022-09-21T04:58:31Z")

</div>

Hey, in our cluster some apps are sending logs as multiline, and the problem is that the log structure is different from app to app. How can we set up an 'if' condition that will include the multiline.pattern: …

---

## [Elastic Agent Tags in Discover](https://discuss.elastic.co/t/elastic-agent-tags-in-discover/314742)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 2\
**Last updated:** [September 21, 2022, 2:07am UTC](https://discuss.elastic.co/t/elastic-agent-tags-in-discover/314742 "2022-09-21T02:07:58Z")

</div>

Hi, We are creating/updating Tags for VM's from Fleet management UI. But these tags are not available in Discover section. Is this limitation ? Thanks, Praveen

---

## [Filebeat 8.4.1 slow](https://discuss.elastic.co/t/filebeat-8-4-1-slow/314783)

<div class="topic-metadata">

**Author:** [@rschwa2](https://discuss.elastic.co/u/rschwa2)\
**Replies:** 0\
**Last updated:** [September 20, 2022, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-8-4-1-slow/314783 "2022-09-20T14:23:41Z")

</div>

I upgraded elk to 8.4.1 recently, from 8.3.2. I noticed that filebeat is much slower reading our zeek logs. I configured filebeat to read from one zeek log (conn.log) and output to the console (redirected to /dev/null)…

---

## [How can I Filebeat multiple files that are radically different](https://discuss.elastic.co/t/how-can-i-filebeat-multiple-files-that-are-radically-different/314350)

<div class="topic-metadata">

**Author:** [@dimmthewitted1](https://discuss.elastic.co/u/dimmthewitted1)\
**Replies:** 5\
**Last updated:** [September 20, 2022, 10:43pm UTC](https://discuss.elastic.co/t/how-can-i-filebeat-multiple-files-that-are-radically-different/314350 "2022-09-20T22:43:45Z")

</div>

Is this community still active ? I want to ingest two files from my web server, the apache access logs and the modsecurity logs. The modsecurity logs I will have to setup some serious GROK filters. Filebeat and my in…

---

## [Filebeat sending events to Logstash output more than once](https://discuss.elastic.co/t/filebeat-sending-events-to-logstash-output-more-than-once/314560)

<div class="topic-metadata">

**Author:** [@stevesimpson](https://discuss.elastic.co/u/stevesimpson)\
**Replies:** 1\
**Last updated:** [September 20, 2022, 8:21am UTC](https://discuss.elastic.co/t/filebeat-sending-events-to-logstash-output-more-than-once/314560 "2022-09-20T08:21:17Z")

</div>

I have Filebeat configured with Loadbalance: True with multiple Logstash servers in the Logstash Output. Everything works fine, I see a nice distribution across all of the Logstash instances. To prevent duplicates I hav…

---

## [Filebeat will hang forever until you force a shutdown with "kill -9"](https://discuss.elastic.co/t/filebeat-will-hang-forever-until-you-force-a-shutdown-with-kill-9/314407)

<div class="topic-metadata">

**Author:** [@silence-linhl](https://discuss.elastic.co/u/silence-linhl)\
**Replies:** 2\
**Last updated:** [September 20, 2022, 8:16am UTC](https://discuss.elastic.co/t/filebeat-will-hang-forever-until-you-force-a-shutdown-with-kill-9/314407 "2022-09-20T08:16:48Z")

</div>

When I start filebeat with the config file below, I can't stop it using Ctrl + C config file : debug.yaml # genaral max\_procs: 1 logging.metrics.enabled: false # log logging.to\_files: true logging.files: path: /data…

---

## [Add fields to traefik module output](https://discuss.elastic.co/t/add-fields-to-traefik-module-output/314740)

<div class="topic-metadata">

**Author:** [@titiyoyo](https://discuss.elastic.co/u/titiyoyo)\
**Replies:** 0\
**Last updated:** [September 20, 2022, 6:30am UTC](https://discuss.elastic.co/t/add-fields-to-traefik-module-output/314740 "2022-09-20T06:30:54Z")

</div>

Hello, I'm trying to add fields to logs parsed by the traefik module but I can't get it to work. I tried various syntaxes without luck. By my understanding of the documenation, the following should be working... but is…

---

## [Parsing IIS Logs](https://discuss.elastic.co/t/parsing-iis-logs/314732)

<div class="topic-metadata">

**Author:** [@smartdave](https://discuss.elastic.co/u/smartdave)\
**Replies:** 0\
**Last updated:** [September 20, 2022, 5:17am UTC](https://discuss.elastic.co/t/parsing-iis-logs/314732 "2022-09-20T05:17:35Z")

</div>

I have set up filebeat with the IIS module. I have this sending to Logstash. My probkem is that I have a couple of servers with a couple of different configs for logging. Is there a way to tell filebeats/iis module to…

---

## [Heartbeat container stuck in crashloopbackoff](https://discuss.elastic.co/t/heartbeat-container-stuck-in-crashloopbackoff/314623)

<div class="topic-metadata">

**Author:** [@skander\_khalfet](https://discuss.elastic.co/u/skander_khalfet)\
**Replies:** 1\
**Last updated:** [September 20, 2022, 2:11am UTC](https://discuss.elastic.co/t/heartbeat-container-stuck-in-crashloopbackoff/314623 "2022-09-20T02:11:53Z")

</div>

Hey; i'm trying to deploy heartbeat on kubernetes using this configuration file file. as i deployed the file heartbeat pod is stuck in crashloopbackoff with exit code 126. as i searched for the problem i think there's a…

---

## [Showing Error While Setting up winlogbeat in windows](https://discuss.elastic.co/t/showing-error-while-setting-up-winlogbeat-in-windows/314724)

<div class="topic-metadata">

**Author:** [@kibanarockstar](https://discuss.elastic.co/u/kibanarockstar)\
**Replies:** 2\
**Last updated:** [September 20, 2022, 12:44am UTC](https://discuss.elastic.co/t/showing-error-while-setting-up-winlogbeat-in-windows/314724 "2022-09-20T00:44:07Z")

</div>

It is showing this error after running command ".\\winlogbeat.exe setup " . Not sure How to resolve this issue.

---

## [Synthetics / Heartbeat 8.4.0 Release - New Workflow Video Walkthrough](https://discuss.elastic.co/t/synthetics-heartbeat-8-4-0-release-new-workflow-video-walkthrough/314713)

<div class="topic-metadata">

**Author:** [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Replies:** 0\
**Last updated:** [September 19, 2022, 4:28pm UTC](https://discuss.elastic.co/t/synthetics-heartbeat-8-4-0-release-new-workflow-video-walkthrough/314713 "2022-09-19T16:28:18Z")

</div>

Hey all, it's a little late in coming seeing as 8.4.0 was released almost a month ago, but we wanted to give you a walkthrough of what's new with the Elastic Uptime / Synthetics workflow in 8.4.0. We're trying something …

---

## [Heartbeat error "error when creating "heartbeat-kubernetes.yaml": Deployment in version "v1" cannot be handled as a Deployment: unable to parse quantity's suffix" when deploying on kubernetes](https://discuss.elastic.co/t/heartbeat-error-error-when-creating-heartbeat-kubernetes-yaml-deployment-in-version-v1-cannot-be-handled-as-a-deployment-unable-to-parse-quantitys-suffix-when-deploying-on-kubernetes/314597)

<div class="topic-metadata">

**Author:** [@alexander2](https://discuss.elastic.co/u/alexander2)\
**Replies:** 1\
**Last updated:** [September 19, 2022, 3:05pm UTC](https://discuss.elastic.co/t/heartbeat-error-error-when-creating-heartbeat-kubernetes-yaml-deployment-in-version-v1-cannot-be-handled-as-a-deployment-unable-to-parse-quantitys-suffix-when-deploying-on-kubernetes/314597 "2022-09-19T15:05:29Z")

</div>

Hello everyone, i'm trying to deploy heartbeat on kubernetes to monitor kubernetes pods and services. i used the elastic official documentation yaml file. this is the full configuration file apiVersion: v1 kind: Config…

---

## [Fleet Agent: Logstash output: Invalid version of beats protocol](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 11\
**Last updated:** [September 19, 2022, 2:32pm UTC](https://discuss.elastic.co/t/fleet-agent-logstash-output-invalid-version-of-beats-protocol/314624 "2022-09-19T14:32:19Z")

</div>

This is my Logstash config input { elastic\_agent { port =\> 5044 ssl =\> false } } filter { mutate { add\_field =\> { "foo" =\> "bar gustavito" } } } output { elasticsear…

---

## [Filebeat 8.3](https://discuss.elastic.co/t/filebeat-8-3/314630)

<div class="topic-metadata">

**Author:** [@abaltan](https://discuss.elastic.co/u/abaltan)\
**Replies:** 8\
**Last updated:** [September 19, 2022, 8:40am UTC](https://discuss.elastic.co/t/filebeat-8-3/314630 "2022-09-19T08:40:52Z")

</div>

Hello, Hope you doing well. we are upgrading Filebeat from 7.12 to 8.3 and we are using the config file below. But for some reason filebeat is not working. Could you please check if there is anything we need to modify …

---

## [Error while running Functinbeat](https://discuss.elastic.co/t/error-while-running-functinbeat/314642)

<div class="topic-metadata">

**Author:** [@Shubham\_Shah](https://discuss.elastic.co/u/Shubham_Shah)\
**Replies:** 0\
**Last updated:** [September 18, 2022, 12:02pm UTC](https://discuss.elastic.co/t/error-while-running-functinbeat/314642 "2022-09-18T12:02:27Z")

</div>

Hi Team, While running functionbeat for my testing instance, I got following error as Creation Failed for cloudformation. Error - "Specified ReservedConcurrentExecutions for function decreases account's UnreservedConc…

---

## [Elastic Agent Configured By Fleet - Integrations Using MetricBeat - this action is granted by the index privileges error](https://discuss.elastic.co/t/elastic-agent-configured-by-fleet-integrations-using-metricbeat-this-action-is-granted-by-the-index-privileges-error/314603)

<div class="topic-metadata">

**Author:** [@dnimon](https://discuss.elastic.co/u/dnimon)\
**Replies:** 0\
**Last updated:** [September 16, 2022, 9:15pm UTC](https://discuss.elastic.co/t/elastic-agent-configured-by-fleet-integrations-using-metricbeat-this-action-is-granted-by-the-index-privileges-error/314603 "2022-09-16T21:15:20Z")

</div>

I am running into an issue when trying to use Elastic Fleet and the elastic agents. I am using 8.4.1 for all parts (kibana, elastic, elastic-agent). I was able to setup a elastic-agent on the elastic/kibana server to se…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=73)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=75)
