# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=75

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 76

---

## [After filebeat upgrades & preserving registry it sending duplicate events](https://discuss.elastic.co/t/after-filebeat-upgrades-preserving-registry-it-sending-duplicate-events/313701)

<div class="topic-metadata">

**Author:** [@krish0608](https://discuss.elastic.co/u/krish0608)\
**Replies:** 14\
**Last updated:** [September 16, 2022, 4:15pm UTC](https://discuss.elastic.co/t/after-filebeat-upgrades-preserving-registry-it-sending-duplicate-events/313701 "2022-09-16T16:15:01Z")

</div>

I am having a trouble with duplicate events in elasticsearch after updating it to 7.17.3 from 5.6.5. In case of Linux its working as expected but in windows its sending duplicate events. Below are my configurations: ===…

---

## [Unable to see winlogbeat logs in the analytics discover](https://discuss.elastic.co/t/unable-to-see-winlogbeat-logs-in-the-analytics-discover/314590)

<div class="topic-metadata">

**Author:** [@Neyo](https://discuss.elastic.co/u/Neyo)\
**Replies:** 0\
**Last updated:** [September 16, 2022, 4:58pm UTC](https://discuss.elastic.co/t/unable-to-see-winlogbeat-logs-in-the-analytics-discover/314590 "2022-09-16T16:58:28Z")

</div>

I'm unable to see the logs in the dashboard, Please give some advice: winlogbeat.yml file: ###################### Winlogbeat Configuration Example ######################## # This file is an example configuration file …

---

## [Filebeat hogged the IO](https://discuss.elastic.co/t/filebeat-hogged-the-io/314581)

<div class="topic-metadata">

**Author:** [@silence-linhl](https://discuss.elastic.co/u/silence-linhl)\
**Replies:** 0\
**Last updated:** [September 16, 2022, 2:35pm UTC](https://discuss.elastic.co/t/filebeat-hogged-the-io/314581 "2022-09-16T14:35:20Z")

</div>

filebeat hogged the IO After starting filebeat, I found that the IO of the machine became very high. After the digging, it was found that filebeat kept writing to disk a file named checkpoint.new after it was started. S…

---

## [Auditbeat logs write to /var/log/messages](https://discuss.elastic.co/t/auditbeat-logs-write-to-var-log-messages/314361)

<div class="topic-metadata">

**Author:** [@masonlu2014](https://discuss.elastic.co/u/masonlu2014)\
**Replies:** 3\
**Last updated:** [September 16, 2022, 12:32pm UTC](https://discuss.elastic.co/t/auditbeat-logs-write-to-var-log-messages/314361 "2022-09-16T12:32:09Z")

</div>

hi guys, we are sawing weird issue, we are using auditbeat as pod running on our kubenets cluster, however in some day, we saw there is a large audit events has been write to our work node /var/log/message, and i can co…

---

## [Slow performance Logstash/Filebeat](https://discuss.elastic.co/t/slow-performance-logstash-filebeat/314040)

<div class="topic-metadata">

**Author:** [@AsapNoCare](https://discuss.elastic.co/u/AsapNoCare)\
**Replies:** 6\
**Last updated:** [September 16, 2022, 7:19am UTC](https://discuss.elastic.co/t/slow-performance-logstash-filebeat/314040 "2022-09-16T07:19:12Z")

</div>

Hi everyone, It’s the first time I ask for help so feel free to tell me if you need more information from me. Something else, English is not my native language so sorry in advance for the mistakes. Here is my data flo…

---

## [When does the pending count become 0](https://discuss.elastic.co/t/when-does-the-pending-count-become-0/313649)

<div class="topic-metadata">

**Author:** [@hanhee](https://discuss.elastic.co/u/hanhee)\
**Replies:** 3\
**Last updated:** [September 16, 2022, 12:36am UTC](https://discuss.elastic.co/t/when-does-the-pending-count-become-0/313649 "2022-09-16T00:36:58Z")

</div>

hi I do not speak English well. sorry my servers log file create 100/1min every day and delete all 12:00 pm but registry json not show flag "remove" and log.json, number.json just keeps getting bigger. i wonder Wh…

---

## [Filebeat 8.4.1: Autodiscovery and processor not working as expected as per the doc](https://discuss.elastic.co/t/filebeat-8-4-1-autodiscovery-and-processor-not-working-as-expected-as-per-the-doc/314530)

<div class="topic-metadata">

**Author:** [@Ivan\_Gonzalez](https://discuss.elastic.co/u/Ivan_Gonzalez)\
**Replies:** 0\
**Last updated:** [September 15, 2022, 5:12pm UTC](https://discuss.elastic.co/t/filebeat-8-4-1-autodiscovery-and-processor-not-working-as-expected-as-per-the-doc/314530 "2022-09-15T17:12:13Z")

</div>

Hi. I am new to filebeat (previously using fluentbit to send kubernetes logs to graylog) and I am struggling with some things that seems not to work as it is in the doc. Maybe I am missing something, so please be benevo…

---

## [Metricbeat - Azure: Linux OS Guest metrics not included in compute\_vm metricset](https://discuss.elastic.co/t/metricbeat-azure-linux-os-guest-metrics-not-included-in-compute-vm-metricset/314519)

<div class="topic-metadata">

**Author:** [@Harm](https://discuss.elastic.co/u/Harm)\
**Replies:** 0\
**Last updated:** [September 15, 2022, 2:00pm UTC](https://discuss.elastic.co/t/metricbeat-azure-linux-os-guest-metrics-not-included-in-compute-vm-metricset/314519 "2022-09-15T14:00:04Z")

</div>

Hi, I have created a data collection rule in Azure Monitor to collect both Windows and Linux Guest OS metrics (type: Performance Counters). I was happily surprised to see that the Windows Guest OS metrics are already co…

---

## [Functionbeat unable to extract microsecond @timestamp using decode\_json\_fields](https://discuss.elastic.co/t/functionbeat-unable-to-extract-microsecond-timestamp-using-decode-json-fields/314494)

<div class="topic-metadata">

**Author:** [@adrian-skybaker](https://discuss.elastic.co/u/adrian-skybaker)\
**Replies:** 0\
**Last updated:** [September 15, 2022, 9:55am UTC](https://discuss.elastic.co/t/functionbeat-unable-to-extract-microsecond-timestamp-using-decode-json-fields/314494 "2022-09-15T09:55:15Z")

</div>

I'm having issues extracting a @timestamp field from a nested JSON string (in standard ISO format), It works if the nested timestamp has millisecond precision. It doesn't if it has microsecond or nanosecond precision. T…

---

## [Logs from filebeat not being written to kafka topic](https://discuss.elastic.co/t/logs-from-filebeat-not-being-written-to-kafka-topic/314490)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 0\
**Last updated:** [September 15, 2022, 9:38am UTC](https://discuss.elastic.co/t/logs-from-filebeat-not-being-written-to-kafka-topic/314490 "2022-09-15T09:38:29Z")

</div>

Hi, I have filebeat application deployed on ec2 instance. I'm trying to connect to kafka that is deployed on EKS cluster. When I'm trying to connect to kafka, the connection gets established but nothing is being writte…

---

## [Trouble with Filebeat Nginx module](https://discuss.elastic.co/t/trouble-with-filebeat-nginx-module/314434)

<div class="topic-metadata">

**Author:** [@marklad78](https://discuss.elastic.co/u/marklad78)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 3:22pm UTC](https://discuss.elastic.co/t/trouble-with-filebeat-nginx-module/314434 "2022-09-14T15:22:33Z")

</div>

Filebeat/ELK version 7.10.2 We're attempting to consume nginx-esque kong logs from /usr/local/kong/logs/access.log through filebeat running on the same machine as the kong instance using the nginx module. The followi…

---

## [Azure AD (modlue:o365) logs are not fetched consistently by filebeat](https://discuss.elastic.co/t/azure-ad-modlue-o365-logs-are-not-fetched-consistently-by-filebeat/314369)

<div class="topic-metadata">

**Author:** [@sriramb12](https://discuss.elastic.co/u/sriramb12)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 11:21am UTC](https://discuss.elastic.co/t/azure-ad-modlue-o365-logs-are-not-fetched-consistently-by-filebeat/314369 "2022-09-14T11:21:15Z")

</div>

Hi Team I am New to the filebeat usage. I am trying to fetch logs from azure tenant using o365 module. I am able to get the logs sometimes but sometimes the expected logs are missing. I expect the logs when there is som…

---

## [Can filebeat 8.4 send to older elasticsearch 7.15](https://discuss.elastic.co/t/can-filebeat-8-4-send-to-older-elasticsearch-7-15/314310)

<div class="topic-metadata">

**Author:** [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Replies:** 1\
**Last updated:** [September 14, 2022, 5:26am UTC](https://discuss.elastic.co/t/can-filebeat-8-4-send-to-older-elasticsearch-7-15/314310 "2022-09-14T05:26:17Z")

</div>

Hello, Is it possible for filebeat 8.4 to send to an older cluster such as elasticsearch 7.15?

---

## [Sending fortinalyzer logs to SIEM](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 5\
**Last updated:** [September 13, 2022, 10:29pm UTC](https://discuss.elastic.co/t/sending-fortinalyzer-logs-to-siem/314149 "2022-09-13T22:29:37Z")

</div>

Hello Community Are the fortianalyzer supported by filebeat? if yes can you help me with its configuration at filebeat level by specifying the part to be addressed? Thanks,

---

## [Filebeat docker container - Can we modify filebeat.yml file using docker ENTRYPOINT](https://discuss.elastic.co/t/filebeat-docker-container-can-we-modify-filebeat-yml-file-using-docker-entrypoint/314230)

<div class="topic-metadata">

**Author:** [@ramreddy](https://discuss.elastic.co/u/ramreddy)\
**Replies:** 7\
**Last updated:** [September 13, 2022, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-docker-container-can-we-modify-filebeat-yml-file-using-docker-entrypoint/314230 "2022-09-13T19:47:25Z")

</div>

Hi, we are using docker/ECS filebeat containers, currently as part of docker build we copy filebeat-(aws\_account).yml to /usr/share/filebeat/filebeat.yml with account specific values. But while doing this process we have…

---

## [Change elastic's index name to a kubernetes pod label](https://discuss.elastic.co/t/change-elastics-index-name-to-a-kubernetes-pod-label/314324)

<div class="topic-metadata">

**Author:** [@Ivan\_Gonzalez](https://discuss.elastic.co/u/Ivan_Gonzalez)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 6:03pm UTC](https://discuss.elastic.co/t/change-elastics-index-name-to-a-kubernetes-pod-label/314324 "2022-09-13T18:03:53Z")

</div>

Hi guys. I am migrating from fluentbit to filebeat to ship logs from kubernetes to graylog 4. The idea is to create 'graylog-application\_name' indexes to let me know identify properly which data holds each index. As f…

---

## [Monitor Kafka using kafka module from metricbeat](https://discuss.elastic.co/t/monitor-kafka-using-kafka-module-from-metricbeat/314291)

<div class="topic-metadata">

**Author:** [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 12:10pm UTC](https://discuss.elastic.co/t/monitor-kafka-using-kafka-module-from-metricbeat/314291 "2022-09-13T12:10:09Z")

</div>

Hi Team, I want to do kafka monitoring using metricbeat kafka module version 7.17v. I have followed the document -\> kafka-module Configured the output to elasticsearch in metricbeat.yml file. Executed the below two c…

---

## [ResourceStatus: CREATE\_FAILED, ResourceStatusReason: Resource handler returned message: \\"The specified log group does not exist](https://discuss.elastic.co/t/resourcestatus-create-failed-resourcestatusreason-resource-handler-returned-message-the-specified-log-group-does-not-exist/313785)

<div class="topic-metadata">

**Author:** [@ayushi.sharma91](https://discuss.elastic.co/u/ayushi.sharma91)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 10:19am UTC](https://discuss.elastic.co/t/resourcestatus-create-failed-resourcestatusreason-resource-handler-returned-message-the-specified-log-group-does-not-exist/313785 "2022-09-13T10:19:25Z")

</div>

I am trying to install functionbeat 8.4 on an AWS (tried it on both amazon linux and Ubuntu). Elasticsearch is self hosted. Followed the installation guide(Functionbeat quick start: installation and configuration | Funct…

---

## [Meticbeat can not collect all metric for MSSQL perfomance counter](https://discuss.elastic.co/t/meticbeat-can-not-collect-all-metric-for-mssql-perfomance-counter/313742)

<div class="topic-metadata">

**Author:** [@sondog](https://discuss.elastic.co/u/sondog)\
**Replies:** 4\
**Last updated:** [September 13, 2022, 4:58am UTC](https://discuss.elastic.co/t/meticbeat-can-not-collect-all-metric-for-mssql-perfomance-counter/313742 "2022-09-13T04:58:07Z")

</div>

Elasticsearch Version : 8.0.0 Kbana Version : 8.0.0 Metricbeat Version : 8.0.0 MSSQL version : Micvrosoft SQL Server 2017 in documentaion, metricbeat can collect 16 metric for performance counter but, i can get …

---

## [Metricbeat modules list is empty](https://discuss.elastic.co/t/metricbeat-modules-list-is-empty/314020)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 7\
**Last updated:** [September 13, 2022, 1:06am UTC](https://discuss.elastic.co/t/metricbeat-modules-list-is-empty/314020 "2022-09-13T01:06:37Z")

</div>

\[root@rbdcelastic01 metricbeat\]# metricbeat modules list Enabled: Disabled: \[root@rbdcelastic01 metricbeat\]# vim metricbeat.yml # =========================== Modules configuration ============================ metric…

---

## [Autodiscover (k8s) and Kafka module](https://discuss.elastic.co/t/autodiscover-k8s-and-kafka-module/314198)

<div class="topic-metadata">

**Author:** [@AssafKatz3](https://discuss.elastic.co/u/AssafKatz3)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 1:49pm UTC](https://discuss.elastic.co/t/autodiscover-k8s-and-kafka-module/314198 "2022-09-12T13:49:48Z")

</div>

Hi, I am trying to understand how can I use Hints based autodiscover with Kafka module while both are running on k8s. Thaksm

---

## [Filebeat output to file](https://discuss.elastic.co/t/filebeat-output-to-file/314135)

<div class="topic-metadata">

**Author:** [@sriramb12](https://discuss.elastic.co/u/sriramb12)\
**Replies:** 17\
**Last updated:** [September 12, 2022, 2:58am UTC](https://discuss.elastic.co/t/filebeat-output-to-file/314135 "2022-09-12T02:58:16Z")

</div>

New to the filebeat and to elastic. I need to fetch o365 logs from azure tenant. I dont want to use ELK stack but just get the json files I configured /etc/filebeat/modules.d/o365.yml also file output under /etc/file…

---

## [Missing authentication credentials for REST request](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588)

<div class="topic-metadata">

**Author:** [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Replies:** 29\
**Last updated:** [September 11, 2022, 6:19pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588 "2022-09-11T18:19:34Z")

</div>

Hi, I'm new to ELK Stack. So far I have configured \[Elasticsearch - Kibana - Logstash\] but the Filebeat configuration is causing issues. Note: All four services are running fine When I run the following command \</\> s…

---

## [Add life cycle policy on metricbeat indices](https://discuss.elastic.co/t/add-life-cycle-policy-on-metricbeat-indices/313905)

<div class="topic-metadata">

**Author:** [@Idan\_Ahal](https://discuss.elastic.co/u/Idan_Ahal)\
**Replies:** 4\
**Last updated:** [September 11, 2022, 10:53am UTC](https://discuss.elastic.co/t/add-life-cycle-policy-on-metricbeat-indices/313905 "2022-09-11T10:53:45Z")

</div>

I'm trying to add a life cycle policy to my indices through Kibana. I created an index template and a lifecycle policy but I get this error: setting \[index.lifecycle.rollover\_alias\] for index \[jobmetrics-preprod-2022.09.…

---

## [How to solve issue when change type from log to filestream in filebeat and duplication?](https://discuss.elastic.co/t/how-to-solve-issue-when-change-type-from-log-to-filestream-in-filebeat-and-duplication/314133)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 0\
**Last updated:** [September 11, 2022, 9:19am UTC](https://discuss.elastic.co/t/how-to-solve-issue-when-change-type-from-log-to-filestream-in-filebeat-and-duplication/314133 "2022-09-11T09:19:17Z")

</div>

filestream ,the successor of log input, is now generally available in Filebeat and the version I use is 7.15. I have a single active log and I am using log as input type in filebeat.yml .and I found it is better to chang…

---

## [New install Metricbeat failing to run setup](https://discuss.elastic.co/t/new-install-metricbeat-failing-to-run-setup/314127)

<div class="topic-metadata">

**Author:** [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Replies:** 2\
**Last updated:** [September 11, 2022, 5:55am UTC](https://discuss.elastic.co/t/new-install-metricbeat-failing-to-run-setup/314127 "2022-09-11T05:55:19Z")

</div>

Hi got a new install, looking at metricbeat, I have it monitoring the ELK cluster, but I want the system plugin to work. I noticed the dashboards where missing so I tried metricbeat setup --dashboards --index-manageme…

---

## [Create an alert on a process\\service that stopped running](https://discuss.elastic.co/t/create-an-alert-on-a-process-service-that-stopped-running/314125)

<div class="topic-metadata">

**Author:** [@Mor123460](https://discuss.elastic.co/u/Mor123460)\
**Replies:** 0\
**Last updated:** [September 10, 2022, 9:24pm UTC](https://discuss.elastic.co/t/create-an-alert-on-a-process-service-that-stopped-running/314125 "2022-09-10T21:24:51Z")

</div>

Hey. As i understand, there isn't a log created when a process stop running, because it's simply disappearing. So, how can i create an alert on a log with specific command line that stopped arriving from a metricbeat? …

---

## [IAS NPS radius parser with dissect on filebeat](https://discuss.elastic.co/t/ias-nps-radius-parser-with-dissect-on-filebeat/314076)

<div class="topic-metadata">

**Author:** [@florinsfetea](https://discuss.elastic.co/u/florinsfetea)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 4:26pm UTC](https://discuss.elastic.co/t/ias-nps-radius-parser-with-dissect-on-filebeat/314076 "2022-09-09T16:26:39Z")

</div>

Hello People, I was searching for a solution to parse our NPS logs via filebeat and dissect and could not seems to find a related topic for this. I am using fleet and a custom log integration to collect the logs So he…

---

## [How to remove "Elastic Cloud agent policy" elastic agents that are Offline in Fleet](https://discuss.elastic.co/t/how-to-remove-elastic-cloud-agent-policy-elastic-agents-that-are-offline-in-fleet/313987)

<div class="topic-metadata">

**Author:** [@dabo](https://discuss.elastic.co/u/dabo)\
**Replies:** 1\
**Last updated:** [September 9, 2022, 3:07pm UTC](https://discuss.elastic.co/t/how-to-remove-elastic-cloud-agent-policy-elastic-agents-that-are-offline-in-fleet/313987 "2022-09-09T15:07:37Z")

</div>

Hi, We are using Elastic Cloud 8.3.3 version now and currently have 264 offline elastic agent assigned to this \[Elastic Cloud agent policy\]. Are they still only removable via API? The number of agents is increasing …

---

## [Packetbeat not monitoring https protocol](https://discuss.elastic.co/t/packetbeat-not-monitoring-https-protocol/313766)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 5:50pm UTC](https://discuss.elastic.co/t/packetbeat-not-monitoring-https-protocol/313766 "2022-09-08T17:50:36Z")

</div>

Hello Environment detail - We are having Elasticsearch cluster running with secured http port 9200, 9201 & 9202 with version 8.3 We have installed packetbeat v8.3 on elasticsearch server to monitor the http traffic on…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=74)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=76)
