# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=76

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 77

---

## [Packetbeat recording high responce time for connections](https://discuss.elastic.co/t/packetbeat-recording-high-responce-time-for-connections/313772)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 3\
**Last updated:** [September 8, 2022, 5:24pm UTC](https://discuss.elastic.co/t/packetbeat-recording-high-responce-time-for-connections/313772 "2022-09-08T17:24:00Z")

</div>

Hello Environment detail - Packetbeat 8.3 installed on Elasticsearch 8.3 server to monitor the completed connections duration. where we want to know in what time duration the incoming query search connection got comple…

---

## [Filebeat not sending/error sending data to logstash](https://discuss.elastic.co/t/filebeat-not-sending-error-sending-data-to-logstash/314005)

<div class="topic-metadata">

**Author:** [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 3:14pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-error-sending-data-to-logstash/314005 "2022-09-08T15:14:49Z")

</div>

Hello, I'm trying to send mysql logs to logstash, initially there was only logstash configuration, but I ran into the fact that filebeat sent messages in encoded form, so I had to redo the filebeat config, here it is: #…

---

## [Prometheus metrics coming in slowly](https://discuss.elastic.co/t/prometheus-metrics-coming-in-slowly/313921)

<div class="topic-metadata">

**Author:** [@Renato\_D](https://discuss.elastic.co/u/Renato_D)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 1:47pm UTC](https://discuss.elastic.co/t/prometheus-metrics-coming-in-slowly/313921 "2022-09-08T13:47:05Z")

</div>

I'm not entirely sure what is causing this. autodiscover is configured like so: - type: kubernetes include\_annotations: \["prometheus.io.scrape", "prometheus.io.port"\] resource: service templates: - condition:…

---

## [\[Filebeat : v7.9.3\] Invalid memory address or nil pointer dereference](https://discuss.elastic.co/t/filebeat-v7-9-3-invalid-memory-address-or-nil-pointer-dereference/313958)

<div class="topic-metadata">

**Author:** [@iamyeka](https://discuss.elastic.co/u/iamyeka)\
**Replies:** 3\
**Last updated:** [September 8, 2022, 8:30am UTC](https://discuss.elastic.co/t/filebeat-v7-9-3-invalid-memory-address-or-nil-pointer-dereference/313958 "2022-09-08T08:30:46Z")

</div>

Filebeat version: 7.9.3 I met some issue about "invalid memory address or nil pointer dereference" which caused a panic. But i cannot figure out why that happened. Below is the stack of the panic. panic: runtime error:…

---

## [Misconfiguration of filebeat on debian](https://discuss.elastic.co/t/misconfiguration-of-filebeat-on-debian/313864)

<div class="topic-metadata">

**Author:** [@mammodde](https://discuss.elastic.co/u/mammodde)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 9:59am UTC](https://discuss.elastic.co/t/misconfiguration-of-filebeat-on-debian/313864 "2022-09-08T09:59:59Z")

</div>

Good morning, I am trying to install filebeat on debian with the deb file. The problem is that i have misconfigured it, so i tried to uninstall it. After the second installation i encountered a problem: it does not down…

---

## [Filebeat send ' \\u0000 ' and the event loss and the new line append to the last line](https://discuss.elastic.co/t/filebeat-send-u0000-and-the-event-loss-and-the-new-line-append-to-the-last-line/313972)

<div class="topic-metadata">

**Author:** [@codeyoungth](https://discuss.elastic.co/u/codeyoungth)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 9:03am UTC](https://discuss.elastic.co/t/filebeat-send-u0000-and-the-event-loss-and-the-new-line-append-to-the-last-line/313972 "2022-09-08T09:03:27Z")

</div>

my config is as follow: filebeat.inputs: - type: filestream enabled: true id: filebeat-input-log paths: - /app/log/\*/\*.log parsers: - multili…

---

## [Function beat erroring out with license error when shipping log](https://discuss.elastic.co/t/function-beat-erroring-out-with-license-error-when-shipping-log/313959)

<div class="topic-metadata">

**Author:** [@IbrahimHectare](https://discuss.elastic.co/u/IbrahimHectare)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 8:04am UTC](https://discuss.elastic.co/t/function-beat-erroring-out-with-license-error-when-shipping-log/313959 "2022-09-08T08:04:20Z")

</div>

I have set up function beat on AWS, to ship my cloudwatch logs. When the functionbeat is invoked to send the logs, it errors out due to an enterprise license being returned. licenser/elastic\_fetcher.go:136 Invalid resp…

---

## [Create custom heartbeat index](https://discuss.elastic.co/t/create-custom-heartbeat-index/313793)

<div class="topic-metadata">

**Author:** [@franckfct](https://discuss.elastic.co/u/franckfct)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 12:58am UTC](https://discuss.elastic.co/t/create-custom-heartbeat-index/313793 "2022-09-08T00:58:34Z")

</div>

Hi, I'm trying during several days to make custom index in 'heartbeat'. The goal is to redirect output for diferrents clients. Here my main config in /etc/heartbeat/heartbeat.yml fields\_under\_root: true setup.ilm.ena…

---

## [What i do in this situation?](https://discuss.elastic.co/t/what-i-do-in-this-situation/313909)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 9:00pm UTC](https://discuss.elastic.co/t/what-i-do-in-this-situation/313909 "2022-09-07T21:00:39Z")

</div>

I installed Filebeat, Elasticsearch, and Kibana 8.4.1 in ubuntu I collect FortiGate logs with Integration of Fortinet, in the "discover" the name of the index is filebeat-\* and I want to name it FortiGate like this exa…

---

## [Error establishing direct connection to mongo node Error output: no reachable servers](https://discuss.elastic.co/t/error-establishing-direct-connection-to-mongo-node-error-output-no-reachable-servers/313395)

<div class="topic-metadata">

**Author:** [@Asher\_Manangan](https://discuss.elastic.co/u/Asher_Manangan)\
**Replies:** 6\
**Last updated:** [September 7, 2022, 12:09pm UTC](https://discuss.elastic.co/t/error-establishing-direct-connection-to-mongo-node-error-output-no-reachable-servers/313395 "2022-09-07T12:09:00Z")

</div>

Hi, Here is the log: Error establishing direct connection to mongo node at \[127.0.0.1:27017\]. Error output: no reachable servers I tried a lot of things, but after so many days, I can't find it work. Here is my mong…

---

## [Filebeat index](https://discuss.elastic.co/t/filebeat-index/313849)

<div class="topic-metadata">

**Author:** [@Milan\_Dangol](https://discuss.elastic.co/u/Milan_Dangol)\
**Replies:** 4\
**Last updated:** [September 7, 2022, 7:28am UTC](https://discuss.elastic.co/t/filebeat-index/313849 "2022-09-07T07:28:45Z")

</div>

Greetings everyone, I have a question regarding filebeat index. The scenarios is: I am transferring Nginx access and error logs from filebeat to my Elasticsearch server. Is the size of filbeat index is equal to the si…

---

## [Metricbeat](https://discuss.elastic.co/t/metricbeat/313660)

<div class="topic-metadata">

**Author:** [@Shashi\_Prakash](https://discuss.elastic.co/u/Shashi_Prakash)\
**Replies:** 15\
**Last updated:** [September 7, 2022, 6:49am UTC](https://discuss.elastic.co/t/metricbeat/313660 "2022-09-07T06:49:59Z")

</div>

i am geting error in connecting metricbeat to kibana as it shows in logs ERROR \[kibana.stats\] stats/stats.go:82 error making http request: Get http://localhost:5601/api/status: dial tcp 127.0.0.1:5601: connection refuse…

---

## [Can we pull up logs using Web API either through filebeat or logstash?](https://discuss.elastic.co/t/can-we-pull-up-logs-using-web-api-either-through-filebeat-or-logstash/313841)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 4\
**Last updated:** [September 7, 2022, 3:48am UTC](https://discuss.elastic.co/t/can-we-pull-up-logs-using-web-api-either-through-filebeat-or-logstash/313841 "2022-09-07T03:48:44Z")

</div>

Hi Team, I need to pull up the logs using web API; can someone suggest a method by which I could pull up the logs using web api? Or do I need to write a script and then pull up the logs? TIA Blason R

---

## [Auditbeat dashboard in kibana shows empty results](https://discuss.elastic.co/t/auditbeat-dashboard-in-kibana-shows-empty-results/313782)

<div class="topic-metadata">

**Author:** [@Sargu\_Xcode](https://discuss.elastic.co/u/Sargu_Xcode)\
**Replies:** 2\
**Last updated:** [September 7, 2022, 1:07am UTC](https://discuss.elastic.co/t/auditbeat-dashboard-in-kibana-shows-empty-results/313782 "2022-09-07T01:07:56Z")

</div>

Hi All , I am trying to build a monitoring system for auditctl using auditbeat on Elasticsearch 7.8.1 and Kibana 7.8.1. Everything is successfully setup , including auditbeat. But the auditbeat dashboard seems empty whe…

---

## [Only one log is output from auditbeat](https://discuss.elastic.co/t/only-one-log-is-output-from-auditbeat/313726)

<div class="topic-metadata">

**Author:** [@aurantiacus](https://discuss.elastic.co/u/aurantiacus)\
**Replies:** 3\
**Last updated:** [September 7, 2022, 12:58am UTC](https://discuss.elastic.co/t/only-one-log-is-output-from-auditbeat/313726 "2022-09-07T00:58:41Z")

</div>

I am using auditbeat (6.4) on windows 10. I have specified the C drive as the monitoring destination. Other computers output a lot of data in 'file\_integrity'. When I start auditbeat on only one computer, I get only o…

---

## [Missing field from my sqs queue](https://discuss.elastic.co/t/missing-field-from-my-sqs-queue/312746)

<div class="topic-metadata">

**Author:** [@nexus1](https://discuss.elastic.co/u/nexus1)\
**Replies:** 4\
**Last updated:** [September 6, 2022, 7:21pm UTC](https://discuss.elastic.co/t/missing-field-from-my-sqs-queue/312746 "2022-09-06T19:21:14Z")

</div>

We are running Elasticsearch on Kubernetes using the Elastic Cloud Operator. We use the input sqs plugin to pull events for our SQS queues Recently, we discovered the logs from one of our queues have the field aws.sqs.…

---

## [Filebeat limit processing events](https://discuss.elastic.co/t/filebeat-limit-processing-events/313485)

<div class="topic-metadata">

**Author:** [@amandagmsd](https://discuss.elastic.co/u/amandagmsd)\
**Replies:** 3\
**Last updated:** [September 6, 2022, 7:08pm UTC](https://discuss.elastic.co/t/filebeat-limit-processing-events/313485 "2022-09-06T19:08:16Z")

</div>

Hi, Is there a way to increase the number of processing events of filebeat? Example: I have a configuration for filebeat to read aws cloudwatch logs, but the biggest number that is on log debug is 100 for processing e…

---

## [Parsing error on Metricbeat 8.3 with HAProxy 1.5](https://discuss.elastic.co/t/parsing-error-on-metricbeat-8-3-with-haproxy-1-5/313202)

<div class="topic-metadata">

**Author:** [@shim1st](https://discuss.elastic.co/u/shim1st)\
**Replies:** 3\
**Last updated:** [September 6, 2022, 4:27pm UTC](https://discuss.elastic.co/t/parsing-error-on-metricbeat-8-3-with-haproxy-1-5/313202 "2022-09-06T16:27:30Z")

</div>

I installed Metricbeat 8.3 on CentOS and enabled HAProxy. Error occured like below. {"log.level":"debug","@timestamp":"2022-08-29T17:12:03.771+0900","log.logger":"processors","log.origin":{"file.name":"processing/proce…

---

## [Change Name in Stack Monitoring](https://discuss.elastic.co/t/change-name-in-stack-monitoring/312896)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 4\
**Last updated:** [September 6, 2022, 4:24pm UTC](https://discuss.elastic.co/t/change-name-in-stack-monitoring/312896 "2022-09-06T16:24:14Z")

</div>

By default, beats which are sending monitoring data to a dedicated monitoring cluster (by setting 'monitoring.elasticsearch.monitoring.enabled: true') are showing up in Kibana Stack Monitoring with their hostname without…

---

## [Disable system module](https://discuss.elastic.co/t/disable-system-module/313790)

<div class="topic-metadata">

**Author:** [@maheshmotukuri](https://discuss.elastic.co/u/maheshmotukuri)\
**Replies:** 0\
**Last updated:** [September 6, 2022, 12:15pm UTC](https://discuss.elastic.co/t/disable-system-module/313790 "2022-09-06T12:15:33Z")

</div>

I'm running metricbeat in container Run Metricbeat on Docker | Metricbeat Reference \[8.4\] | Elastic but don't have any idea how to disable systems module or any other module ? tried to disable in metricbeat.yaml metr…

---

## [How to use subnet in hosts field of metricbeat modules](https://discuss.elastic.co/t/how-to-use-subnet-in-hosts-field-of-metricbeat-modules/313758)

<div class="topic-metadata">

**Author:** [@maheshmotukuri](https://discuss.elastic.co/u/maheshmotukuri)\
**Replies:** 0\
**Last updated:** [September 6, 2022, 7:46am UTC](https://discuss.elastic.co/t/how-to-use-subnet-in-hosts-field-of-metricbeat-modules/313758 "2022-09-06T07:46:13Z")

</div>

Would like to use subnet of hosts for collecting metrics from Prometheus exporter instead of list of IP's in hosts collection. currently it supports metricbeat.modules: - module: prometheus period: 10s metricsets: …

---

## [Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data)](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/313546)

<div class="topic-metadata">

**Author:** [@Sargu\_Xcode](https://discuss.elastic.co/u/Sargu_Xcode)\
**Replies:** 2\
**Last updated:** [September 6, 2022, 7:10am UTC](https://discuss.elastic.co/t/exiting-data-path-already-locked-by-another-beat-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/313546 "2022-09-06T07:10:10Z")

</div>

hello everyone , i am new to ELK , was trying to setup ELK with Auditbeat to monitor linux auditd logs, but it seems to break. kibana is not showing desired output and when attempted to check i got this log . appreciate…

---

## [Deploy Winlogbeat with SCCM](https://discuss.elastic.co/t/deploy-winlogbeat-with-sccm/313746)

<div class="topic-metadata">

**Author:** [@ivan\_Rivas](https://discuss.elastic.co/u/ivan_Rivas)\
**Replies:** 0\
**Last updated:** [September 6, 2022, 6:45am UTC](https://discuss.elastic.co/t/deploy-winlogbeat-with-sccm/313746 "2022-09-06T06:45:07Z")

</div>

Hi, I am trying to install a winlogbeat with SCCM and when I launch the package everything seems fine, but when I search for the winlogbeat service, it says it does not exist. Does anyone know what could be the reason? …

---

## [Winlogbeat: missing data in user\_data field](https://discuss.elastic.co/t/winlogbeat-missing-data-in-user-data-field/313730)

<div class="topic-metadata">

**Author:** [@apawlowski](https://discuss.elastic.co/u/apawlowski)\
**Replies:** 0\
**Last updated:** [September 6, 2022, 4:47am UTC](https://discuss.elastic.co/t/winlogbeat-missing-data-in-user-data-field/313730 "2022-09-06T04:47:19Z")

</div>

Hi, we are trying to ship event ID 81 of the channel "Microsoft-Windows-CAPI2". However, we realized that data is missing. The actual event in the Windows event log looks like this: - \<Event xmlns="http://schemas.micr…

---

## [Error fetching data for metricset logstash.node: Could not find field 'id' in Logstash API response](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-could-not-find-field-id-in-logstash-api-response/311717)

<div class="topic-metadata">

**Author:** [@andreastoom](https://discuss.elastic.co/u/andreastoom)\
**Replies:** 5\
**Last updated:** [September 6, 2022, 4:29am UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-could-not-find-field-id-in-logstash-api-response/311717 "2022-09-06T04:29:01Z")

</div>

Hi, I have just upgraded our ELK-stack to 8.3.3 and I am migrating the monitoring to use Metricbeat. Elasticsearch and Kibana works without any issues. However for Logstash I'm seeing the following in the logs { "l…

---

## [Can Filebeat-OSS send data to Elasticsearch non OSS?](https://discuss.elastic.co/t/can-filebeat-oss-send-data-to-elasticsearch-non-oss/313534)

<div class="topic-metadata">

**Author:** [@SitoRBJ](https://discuss.elastic.co/u/SitoRBJ)\
**Replies:** 1\
**Last updated:** [September 6, 2022, 1:11am UTC](https://discuss.elastic.co/t/can-filebeat-oss-send-data-to-elasticsearch-non-oss/313534 "2022-09-06T01:11:56Z")

</div>

Hello everyone! I remember seeing some problems when trying to send data from a Filebeat-OSS to a standard Elasticsearch, i.e. not OSS. Is there any restriction on this or any known problem or can this communication be…

---

## [Fleet Server not starting with Elastic Agent (Error: fleet-server failed: context canceled)](https://discuss.elastic.co/t/fleet-server-not-starting-with-elastic-agent-error-fleet-server-failed-context-canceled/313662)

<div class="topic-metadata">

**Author:** [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Replies:** 1\
**Last updated:** [September 5, 2022, 2:52pm UTC](https://discuss.elastic.co/t/fleet-server-not-starting-with-elastic-agent-error-fleet-server-failed-context-canceled/313662 "2022-09-05T14:52:04Z")

</div>

Hello There! I am trying to set up my fleet server and elastic agent. I am asked to do this: sudo elastic-agent enroll --url=https://{{ip\_address}}:{{port\_number\_1}} \\ --fleet-server-es=https://{{ip\_address}}:{{port…

---

## [Filebeat harvester unable to open file and unable to send logs to logstash](https://discuss.elastic.co/t/filebeat-harvester-unable-to-open-file-and-unable-to-send-logs-to-logstash/313675)

<div class="topic-metadata">

**Author:** [@SumitSingh](https://discuss.elastic.co/u/SumitSingh)\
**Replies:** 1\
**Last updated:** [September 5, 2022, 2:45pm UTC](https://discuss.elastic.co/t/filebeat-harvester-unable-to-open-file-and-unable-to-send-logs-to-logstash/313675 "2022-09-05T14:45:49Z")

</div>

Hello Folks, I have installed Elastic filebeat as a sidecar container in kubernetes cluster with main application "Sonarqube". I want to ships the sonarqube logs to logstash. Filebeat container is running and reading so…

---

## [Filebeat 7.17 is not logging to files under Ubuntu](https://discuss.elastic.co/t/filebeat-7-17-is-not-logging-to-files-under-ubuntu/313671)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 6\
**Last updated:** [September 5, 2022, 12:55pm UTC](https://discuss.elastic.co/t/filebeat-7-17-is-not-logging-to-files-under-ubuntu/313671 "2022-09-05T12:55:39Z")

</div>

Hi, I have a question similar to this one: Filebeat not logging to /var/log/filebeat With the exception that the version I'm using (7.17.6, DEB package) does not use "-e" by default according to documentation: Filebeat…

---

## [Json.ignore\_decoding\_error: true automatically enables json processing for everything?](https://discuss.elastic.co/t/json-ignore-decoding-error-true-automatically-enables-json-processing-for-everything/311721)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 2\
**Last updated:** [September 5, 2022, 10:15am UTC](https://discuss.elastic.co/t/json-ignore-decoding-error-true-automatically-enables-json-processing-for-everything/311721 "2022-09-05T10:15:53Z")

</div>

Hi folks, On our openshift clusters we have a wide range of applications and workloads running, which write logs in different ways. If some developers write logs in json we want to enable them to annotate their workloa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=75)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=77)
