# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=77

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 78

---

## [What does mean the "make update" in defining field mapping in filebeat document?](https://discuss.elastic.co/t/what-does-mean-the-make-update-in-defining-field-mapping-in-filebeat-document/313652)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 4\
**Last updated:** [September 5, 2022, 9:45am UTC](https://discuss.elastic.co/t/what-does-mean-the-make-update-in-defining-field-mapping-in-filebeat-document/313652 "2022-09-05T09:45:09Z")

</div>

Hi guys! I need to change some fields type (event.original) in the fields.yml in the filebeat configuration. But my changes don't apply in indexes after restarting filebeat. there is a command in filebeat documentatio…

---

## [How to import a nginx log file(from first log, first line) with filebeat to elastic?](https://discuss.elastic.co/t/how-to-import-a-nginx-log-file-from-first-log-first-line-with-filebeat-to-elastic/313620)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 1\
**Last updated:** [September 4, 2022, 2:15pm UTC](https://discuss.elastic.co/t/how-to-import-a-nginx-log-file-from-first-log-first-line-with-filebeat-to-elastic/313620 "2022-09-04T14:15:49Z")

</div>

Hi guys. I configured a filebeat to import nginx log files to elastic. # Module: nginx # Docs: https://www.elastic.co/guide/en/beats/filebeat/7.16/filebeat-module-nginx.html - module: nginx # Access logs access: …

---

## [Filebeat not reading logs on Kubernetes](https://discuss.elastic.co/t/filebeat-not-reading-logs-on-kubernetes/313545)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 0\
**Last updated:** [September 2, 2022, 11:15am UTC](https://discuss.elastic.co/t/filebeat-not-reading-logs-on-kubernetes/313545 "2022-09-02T11:15:30Z")

</div>

Hi I'm trying to use filebeat as sidecar to one of my pods in our kubernetes clusyer. Below is the configmap that I'm using apiVersion: v1 kind: ConfigMap metadata: name: filebeat-configmap-dev namespace: dev data:…

---

## [If filebeat is deployed with single instance then no issue is observed in multiline handling. If Filebeat is deployed with daemonset then all events does not follow proper multiline pattern thus results in individual events. Is there any bug reported?](https://discuss.elastic.co/t/if-filebeat-is-deployed-with-single-instance-then-no-issue-is-observed-in-multiline-handling-if-filebeat-is-deployed-with-daemonset-then-all-events-does-not-follow-proper-multiline-pattern-thus-results-in-individual-events-is-there-any-bug-reported/313141)

<div class="topic-metadata">

**Author:** [@Chitra1](https://discuss.elastic.co/u/Chitra1)\
**Replies:** 2\
**Last updated:** [September 2, 2022, 7:37am UTC](https://discuss.elastic.co/t/if-filebeat-is-deployed-with-single-instance-then-no-issue-is-observed-in-multiline-handling-if-filebeat-is-deployed-with-daemonset-then-all-events-does-not-follow-proper-multiline-pattern-thus-results-in-individual-events-is-there-any-bug-reported/313141 "2022-09-02T07:37:46Z")

</div>

If filebeat is deployed with single instance then no issue is observed in multiline handling. If Filebeat is deployed with daemonset then all events does not follow proper multiline pattern thus results in individual eve…

---

## [Error in Filebeat logs](https://discuss.elastic.co/t/error-in-filebeat-logs/313049)

<div class="topic-metadata">

**Author:** [@netnal](https://discuss.elastic.co/u/netnal)\
**Replies:** 8\
**Last updated:** [September 1, 2022, 8:46pm UTC](https://discuss.elastic.co/t/error-in-filebeat-logs/313049 "2022-09-01T20:46:53Z")

</div>

Hello, I am trying to ship logs from windows machine to logz.io using Filebeat 8.2 and Filebeat 7.17(for windows). But I see the below error. Failed to connect to backoff(tcp://listener-ca.logz.io:5015)): tls: downgrad…

---

## [Index management requested but the Elasticsearch output is not configured/enabled](https://discuss.elastic.co/t/index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/313296)

<div class="topic-metadata">

**Author:** [@emmanuel\_stevens\_LED](https://discuss.elastic.co/u/emmanuel_stevens_LED)\
**Replies:** 4\
**Last updated:** [September 1, 2022, 8:43pm UTC](https://discuss.elastic.co/t/index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/313296 "2022-09-01T20:43:58Z")

</div>

when i run the command : metricbeat setup -e i have the error message : Exiting: index management requested but the Elasticsearch output is not configured/enabled I try to send my datas to kafka. before doing it i sen…

---

## [Auditbeat - auditd module default rules](https://discuss.elastic.co/t/auditbeat-auditd-module-default-rules/313238)

<div class="topic-metadata">

**Author:** [@Ppetro](https://discuss.elastic.co/u/Ppetro)\
**Replies:** 1\
**Last updated:** [September 1, 2022, 7:34pm UTC](https://discuss.elastic.co/t/auditbeat-auditd-module-default-rules/313238 "2022-09-01T19:34:00Z")

</div>

Hi, I am testing Auditbeat with auditd module. I have noticed that even if I don't have any auditd rule listed in my config, I can still see some events generated by this module. I did some research here on the forum a…

---

## [ELK6.0 with filebeat](https://discuss.elastic.co/t/elk6-0-with-filebeat/313154)

<div class="topic-metadata">

**Author:** [@lalitg](https://discuss.elastic.co/u/lalitg)\
**Replies:** 1\
**Last updated:** [September 1, 2022, 7:20pm UTC](https://discuss.elastic.co/t/elk6-0-with-filebeat/313154 "2022-09-01T19:20:23Z")

</div>

Hi, I configure ELK6.0 with filebeat to read logs files generated with log4j. I got below output { "\_index": "filebeat-6.0.0", "\_type": "doc", "\_id": "GawR6YIBaCy-nPSp4SyK", "\_version": 1, "\_score": null, "\_sour…

---

## [Collect log from file via Filebeat to Logstash VS collect from logstash directly](https://discuss.elastic.co/t/collect-log-from-file-via-filebeat-to-logstash-vs-collect-from-logstash-directly/311816)

<div class="topic-metadata">

**Author:** [@thahgr](https://discuss.elastic.co/u/thahgr)\
**Replies:** 3\
**Last updated:** [September 1, 2022, 7:13pm UTC](https://discuss.elastic.co/t/collect-log-from-file-via-filebeat-to-logstash-vs-collect-from-logstash-directly/311816 "2022-09-01T19:13:20Z")

</div>

What are the PROS and CONS of using Filebeat to collect logs from an application writing files against using the File input plugin of Logstash to directly gather them. What is more efficient ?

---

## [How do i know the number of threads of filebeat on window os?](https://discuss.elastic.co/t/how-do-i-know-the-number-of-threads-of-filebeat-on-window-os/313309)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 1\
**Last updated:** [September 1, 2022, 7:08pm UTC](https://discuss.elastic.co/t/how-do-i-know-the-number-of-threads-of-filebeat-on-window-os/313309 "2022-09-01T19:08:58Z")

</div>

On linux, I can find how many threads filebeat daemon use. But i have no idea how to find it on window os. From another discussion, it says "Each harvester is a goroutine". I can assume the number of threads by this. …

---

## [Cisco module IOS error on parsing logs](https://discuss.elastic.co/t/cisco-module-ios-error-on-parsing-logs/313431)

<div class="topic-metadata">

**Author:** [@it\_dev](https://discuss.elastic.co/u/it_dev)\
**Replies:** 0\
**Last updated:** [September 1, 2022, 10:34am UTC](https://discuss.elastic.co/t/cisco-module-ios-error-on-parsing-logs/313431 "2022-09-01T10:34:07Z")

</div>

There are Cisco IOS logs on local machine and filebeat installed on it. Sending that logs to Elasticsearch (Without Logstash). When I discover those logs, error message appears and logs are not parsed: \> GoError: could…

---

## [Can't get any other state on a process exept Running state on Metricbeat](https://discuss.elastic.co/t/cant-get-any-other-state-on-a-process-exept-running-state-on-metricbeat/313428)

<div class="topic-metadata">

**Author:** [@Mor123460](https://discuss.elastic.co/u/Mor123460)\
**Replies:** 0\
**Last updated:** [September 1, 2022, 9:39am UTC](https://discuss.elastic.co/t/cant-get-any-other-state-on-a-process-exept-running-state-on-metricbeat/313428 "2022-09-01T09:39:49Z")

</div>

Hey :slight\_smile: I can't get any other state on a process exept Running state on Metricbeat. According to the documents it's said that it can give you the state of the process under the module SYSTEM and under the me…

---

## [MetricBeat is not sending Kubernets node pods etc data but getting system information](https://discuss.elastic.co/t/metricbeat-is-not-sending-kubernets-node-pods-etc-data-but-getting-system-information/313415)

<div class="topic-metadata">

**Author:** [@saifulshihab](https://discuss.elastic.co/u/saifulshihab)\
**Replies:** 0\
**Last updated:** [September 1, 2022, 7:00am UTC](https://discuss.elastic.co/t/metricbeat-is-not-sending-kubernets-node-pods-etc-data-but-getting-system-information/313415 "2022-09-01T07:00:12Z")

</div>

Hellow I configured metric beat to minitor kubernets cluster node pods deployments. But it is not working as documents. How to check what is the missing in my configuration. I need to troubleshoot the issue. But there …

---

## [Apache integration - own log pattern](https://discuss.elastic.co/t/apache-integration-own-log-pattern/313357)

<div class="topic-metadata">

**Author:** [@elkuser1234](https://discuss.elastic.co/u/elkuser1234)\
**Replies:** 1\
**Last updated:** [September 1, 2022, 5:32am UTC](https://discuss.elastic.co/t/apache-integration-own-log-pattern/313357 "2022-09-01T05:32:56Z")

</div>

Hi I used elk stack 8.3 I would like to use the apache integration, but the log format is non-standard. access\_log\_pattern=%{X-Forwarded-For}i %h %l %u %t \\"%r\\" %s %b \\"%{Referer}i\\" \\"%{User-Agent}i\\" I get the mes…

---

## [Winlogbeat SSL setup with ElasticSearch and Kibana with SSL enabled](https://discuss.elastic.co/t/winlogbeat-ssl-setup-with-elasticsearch-and-kibana-with-ssl-enabled/313094)

<div class="topic-metadata">

**Author:** [@RonH8](https://discuss.elastic.co/u/RonH8)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 9:20am UTC](https://discuss.elastic.co/t/winlogbeat-ssl-setup-with-elasticsearch-and-kibana-with-ssl-enabled/313094 "2022-08-31T09:20:00Z")

</div>

Hey I've set up Elasticsearch and Kibana with SSL enabled for both of them with certificates that were generated using elasticsearch-certutil, running on Ubuntu 22.04.1 LTS. It's my first time setting up Elasticsearch,…

---

## [Unable to connect filebeat with kibana to load dashboard](https://discuss.elastic.co/t/unable-to-connect-filebeat-with-kibana-to-load-dashboard/313300)

<div class="topic-metadata">

**Author:** [@Ahlam\_Abubaker](https://discuss.elastic.co/u/Ahlam_Abubaker)\
**Replies:** 5\
**Last updated:** [August 31, 2022, 9:01am UTC](https://discuss.elastic.co/t/unable-to-connect-filebeat-with-kibana-to-load-dashboard/313300 "2022-08-31T09:01:11Z")

</div>

Hi there, I'm running kibana behind apache2 proxy kibana is running in localhost port 5601 and my apache2 IP & port as 46.246.x.x:yyyy when I ran ./filebeat setup -e command in order to connect filebeat on client ser…

---

## [Squid module does not parse logs](https://discuss.elastic.co/t/squid-module-does-not-parse-logs/313088)

<div class="topic-metadata">

**Author:** [@it\_dev](https://discuss.elastic.co/u/it_dev)\
**Replies:** 22\
**Last updated:** [August 31, 2022, 6:05am UTC](https://discuss.elastic.co/t/squid-module-does-not-parse-logs/313088 "2022-08-31T06:05:03Z")

</div>

I have Linux syslog server. My squid server (separate from Linux syslog) sends all its access.log files to Linux syslog server into /var/log/squid/\*.log There, on my Linux syslog server I have installed filebeat 8.4. I …

---

## [Problems with the Metricbeat Vsphere module](https://discuss.elastic.co/t/problems-with-the-metricbeat-vsphere-module/313203)

<div class="topic-metadata">

**Author:** [@Angelo\_Bryan](https://discuss.elastic.co/u/Angelo_Bryan)\
**Replies:** 1\
**Last updated:** [August 30, 2022, 12:12pm UTC](https://discuss.elastic.co/t/problems-with-the-metricbeat-vsphere-module/313203 "2022-08-30T12:12:19Z")

</div>

Hi team, Has anyone tried Metricbeat's Vsphere module with Vmware versions 7.0? I have obtained the following error: //error in NewClient: Post https://172.23.113.60/sdk: net/http: TLS handshake timeout If anyone has…

---

## [Parsing SSSD logs fails](https://discuss.elastic.co/t/parsing-sssd-logs-fails/312873)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 3\
**Last updated:** [August 30, 2022, 7:05am UTC](https://discuss.elastic.co/t/parsing-sssd-logs-fails/312873 "2022-08-30T07:05:04Z")

</div>

Hello, there seems to be a bug with filebeat when collecting SSSD logs. If there's no process id, the field in the logfile gets filled with the domain stated in the launch options with --domain. Afaik, pid is type long …

---

## [Filebeat -\> ElasticSearch for logrus running on k8s](https://discuss.elastic.co/t/filebeat-elasticsearch-for-logrus-running-on-k8s/312416)

<div class="topic-metadata">

**Author:** [@Austin\_ES\_Questions](https://discuss.elastic.co/u/Austin_ES_Questions)\
**Replies:** 27\
**Last updated:** [August 29, 2022, 9:41pm UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-for-logrus-running-on-k8s/312416 "2022-08-29T21:41:32Z")

</div>

We are trying to get started with Elasticsearch, but can't seem to get json from filebeats into elasticsearch nicely formatted. We are using logrus in go and typescript, which writes to container log files in kubernetes.…

---

## [Some auditd Data Corrupted After 8.4.0 Upgrade](https://discuss.elastic.co/t/some-auditd-data-corrupted-after-8-4-0-upgrade/312973)

<div class="topic-metadata">

**Author:** [@CraigHolyoak](https://discuss.elastic.co/u/CraigHolyoak)\
**Replies:** 1\
**Last updated:** [August 29, 2022, 1:07pm UTC](https://discuss.elastic.co/t/some-auditd-data-corrupted-after-8-4-0-upgrade/312973 "2022-08-29T13:07:12Z")

</div>

I'm seeing some records created from auditd including corrupt data after upgrading to 8.4.0. This are fine after downgrading back to 8.3.3. For example, with minimal config: auditbeat.modules: - module: auditd includ…

---

## [Metricbeat - error... ERROR timeout waiting for event](https://discuss.elastic.co/t/metricbeat-error-error-timeout-waiting-for-event/313165)

<div class="topic-metadata">

**Author:** [@el-jefe3](https://discuss.elastic.co/u/el-jefe3)\
**Replies:** 0\
**Last updated:** [August 29, 2022, 1:00pm UTC](https://discuss.elastic.co/t/metricbeat-error-error-timeout-waiting-for-event/313165 "2022-08-29T13:00:37Z")

</div>

I am attempting to ingest AWS data using metricbeat aws module. I am not getting configuration errors, but I am however getting timeout errors when running metricbeat test modules command. aws... cloudwatch... error.…

---

## [Getting duplicate log entry in dashboard](https://discuss.elastic.co/t/getting-duplicate-log-entry-in-dashboard/311041)

<div class="topic-metadata">

**Author:** [@ssksraja](https://discuss.elastic.co/u/ssksraja)\
**Replies:** 9\
**Last updated:** [August 29, 2022, 9:46am UTC](https://discuss.elastic.co/t/getting-duplicate-log-entry-in-dashboard/311041 "2022-08-29T09:46:44Z")

</div>

Hi All , iam using filebeat for the dasbboard creation for monitoring the jobs and i find log.flags:dissect\_parsing\_error as error and can any one please help to resolve this issue.

---

## [Kafka output not working on Filebeat ECK](https://discuss.elastic.co/t/kafka-output-not-working-on-filebeat-eck/311975)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 7\
**Last updated:** [August 29, 2022, 9:42am UTC](https://discuss.elastic.co/t/kafka-output-not-working-on-filebeat-eck/311975 "2022-08-29T09:42:45Z")

</div>

I'm using filebeat on ECK. I have kafka output but it's not working as expected. There are no logs in filebeat to show that connection with kafka has been established. Below is my deployment file apiVersion: beat.k8s.e…

---

## [Docker beat?](https://discuss.elastic.co/t/docker-beat/313074)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [August 29, 2022, 3:45am UTC](https://discuss.elastic.co/t/docker-beat/313074 "2022-08-29T03:45:42Z")

</div>

Dear all, I thought something like docker beat did exist? What is the best practice to replace the docker beat? Thanky you and kind regards!

---

## [DNS lookup failure | Failed to connect to backoff(async(tcp | no such host](https://discuss.elastic.co/t/dns-lookup-failure-failed-to-connect-to-backoff-async-tcp-no-such-host/313111)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 10\
**Last updated:** [August 28, 2022, 10:54pm UTC](https://discuss.elastic.co/t/dns-lookup-failure-failed-to-connect-to-backoff-async-tcp-no-such-host/313111 "2022-08-28T22:54:00Z")

</div>

dear friends, please help: I have several servers with beats, kibana, logstash and elasticsearch (these are not docker(!)). trying to send logs from metricbeat to elasticsearch via logstash. here is my metricbeat.yml con…

---

## [Unable to connect filebeat with elasticsearch " Authentication to realm default\_native failed"](https://discuss.elastic.co/t/unable-to-connect-filebeat-with-elasticsearch-authentication-to-realm-default-native-failed/313095)

<div class="topic-metadata">

**Author:** [@Ahlam\_Abubaker](https://discuss.elastic.co/u/Ahlam_Abubaker)\
**Replies:** 1\
**Last updated:** [August 28, 2022, 3:34pm UTC](https://discuss.elastic.co/t/unable-to-connect-filebeat-with-elasticsearch-authentication-to-realm-default-native-failed/313095 "2022-08-28T15:34:43Z")

</div>

I'm trying to test the connection between filebeat on server and elasticsearch running on another server "both are on the same network" I'm getting this output when running this command ./filebeat test output ........…

---

## [Parsing issue with Event ID 4740](https://discuss.elastic.co/t/parsing-issue-with-event-id-4740/313034)

<div class="topic-metadata">

**Author:** [@LuKaaS](https://discuss.elastic.co/u/LuKaaS)\
**Replies:** 1\
**Last updated:** [August 26, 2022, 5:36pm UTC](https://discuss.elastic.co/t/parsing-issue-with-event-id-4740/313034 "2022-08-26T17:36:21Z")

</div>

Hello everybody, We are facing a parsing issue with the Event ID 4740 (A user account was locked) with Winlogbeat. Winlogbeat version : 8.2.3 Winlogbeat log : { "ecs": { "version": "8.0.0" }, …

---

## [AWS WAF data with filebeat/metricbeat](https://discuss.elastic.co/t/aws-waf-data-with-filebeat-metricbeat/313017)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [August 26, 2022, 11:34am UTC](https://discuss.elastic.co/t/aws-waf-data-with-filebeat-metricbeat/313017 "2022-08-26T11:34:47Z")

</div>

Im looking to export logs/metrics from aws waf to elasticsearch, however i dont see any mention of WAF under the aws module of either filebeat or metricbeat. So how exactly do i integrate this. filebeat: metricbeat:

---

## [Apache, Filebeat, Kibana 8.3.3](https://discuss.elastic.co/t/apache-filebeat-kibana-8-3-3/312696)

<div class="topic-metadata">

**Author:** [@Gunnar](https://discuss.elastic.co/u/Gunnar)\
**Replies:** 5\
**Last updated:** [August 26, 2022, 8:38am UTC](https://discuss.elastic.co/t/apache-filebeat-kibana-8-3-3/312696 "2022-08-26T08:38:26Z")

</div>

Hello, I'm new to Filebeat and Kibana. I'm having a strange issue, I'm sending apache logfiles to Elasticsearch using the apache module. On Kibana logfile shows like this: 13:06:23.462 www.xxx.de 185.191.171.22 - - \[23…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=76)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=78)
