# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=78

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 79

---

## [The filestream input](https://discuss.elastic.co/t/the-filestream-input/312948)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 1\
**Last updated:** [August 25, 2022, 6:07pm UTC](https://discuss.elastic.co/t/the-filestream-input/312948 "2022-08-25T18:07:35Z")

</div>

what's the role of the the filestream input ??? filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use different inputs for various configurations. # Below are the input spe…

---

## [Metricbeat http module cant parse query key with period in it](https://discuss.elastic.co/t/metricbeat-http-module-cant-parse-query-key-with-period-in-it/312540)

<div class="topic-metadata">

**Author:** [@Nimar\_Arora](https://discuss.elastic.co/u/Nimar_Arora)\
**Replies:** 13\
**Last updated:** [August 25, 2022, 5:30pm UTC](https://discuss.elastic.co/t/metricbeat-http-module-cant-parse-query-key-with-period-in-it/312540 "2022-08-25T17:30:48Z")

</div>

query key-values such as resource.kafka.id: XXXX are being encoded as resource=map%5Bkafka%3Amap%5Bid%3AXXXX%5D%5D instead of resource.kafka.id=XXXX This is my metricbeat http module configuration: - module: http met…

---

## [GPG key fails to import for filebeat on Centos9](https://discuss.elastic.co/t/gpg-key-fails-to-import-for-filebeat-on-centos9/312946)

<div class="topic-metadata">

**Author:** [@sbradley](https://discuss.elastic.co/u/sbradley)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 4:28pm UTC](https://discuss.elastic.co/t/gpg-key-fails-to-import-for-filebeat-on-centos9/312946 "2022-08-25T16:28:50Z")

</div>

Following the instructions here Repositories for APT and YUM | Filebeat Reference \[8.4\] | Elastic I attempt to import the GPG key and receive the following error: error: https://packages.elastic.co/GPG-KEY-elasticsearc…

---

## [Filebeat keeps file handle on deleted logfile](https://discuss.elastic.co/t/filebeat-keeps-file-handle-on-deleted-logfile/312608)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 6\
**Last updated:** [August 25, 2022, 1:29pm UTC](https://discuss.elastic.co/t/filebeat-keeps-file-handle-on-deleted-logfile/312608 "2022-08-25T13:29:43Z")

</div>

Hi, I have following issue and hope you can provide a solution. We are using elastic stack for monitoring our application. Priority 1: application must run Priority 2: monitoring should run to support and monitor the…

---

## [Error 1053 when starting winlogbeat or auditbeat](https://discuss.elastic.co/t/error-1053-when-starting-winlogbeat-or-auditbeat/312917)

<div class="topic-metadata">

**Author:** [@mammodde](https://discuss.elastic.co/u/mammodde)\
**Replies:** 1\
**Last updated:** [August 25, 2022, 1:12pm UTC](https://discuss.elastic.co/t/error-1053-when-starting-winlogbeat-or-auditbeat/312917 "2022-08-25T13:12:17Z")

</div>

Goodmorning, when i try to Start-Service winlogbeat i receive the error 1053m same thing for auditbeat. for the yml files i followed the getting started guide, so there should not be any error. i have a keystore and it…

---

## [Filebeatt doesn't create multiple index](https://discuss.elastic.co/t/filebeatt-doesnt-create-multiple-index/312717)

<div class="topic-metadata">

**Author:** [@pauldon2](https://discuss.elastic.co/u/pauldon2)\
**Replies:** 2\
**Last updated:** [August 25, 2022, 12:00pm UTC](https://discuss.elastic.co/t/filebeatt-doesnt-create-multiple-index/312717 "2022-08-25T12:00:26Z")

</div>

I use elasticsearch 8.3.3 and filebeat 8.3.3 I try read logs from different docker contaiters by using filebeat and when direct write to different indices to elasticsearch. My filebeat.yml # =========================…

---

## [Filebeat, nginx, elastic stack. Code printing out in Filebeat log](https://discuss.elastic.co/t/filebeat-nginx-elastic-stack-code-printing-out-in-filebeat-log/312899)

<div class="topic-metadata">

**Author:** [@marklad78](https://discuss.elastic.co/u/marklad78)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 10:11am UTC](https://discuss.elastic.co/t/filebeat-nginx-elastic-stack-code-printing-out-in-filebeat-log/312899 "2022-08-25T10:11:59Z")

</div>

Hi there folks, Hope you can help me as I'm at a bit of a loss. I've configured Filebeat v7.17.5 to enable the nginx module to scrape some logs located at /usr/local/kong/logs/access.log and /usr/local/kong/logs/error.…

---

## [Threat Intel Problems](https://discuss.elastic.co/t/threat-intel-problems/312801)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 11:23am UTC](https://discuss.elastic.co/t/threat-intel-problems/312801 "2022-08-24T11:23:40Z")

</div>

I'm trying to know if my threatintel.yml is working right? Because i'm trying to use misp on threat intel but is don't display anything but the other modules are displaying information, for example, the abuseURL. misp: …

---

## [Set registry and log files, owner and group](https://discuss.elastic.co/t/set-registry-and-log-files-owner-and-group/312769)

<div class="topic-metadata">

**Author:** [@nahiko](https://discuss.elastic.co/u/nahiko)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 7:08am UTC](https://discuss.elastic.co/t/set-registry-and-log-files-owner-and-group/312769 "2022-08-24T07:08:10Z")

</div>

Hi! I am using filebeat 7.17 I start Filebeat using a domain user (with systemd) The log files and registry file that Filebeat writes while it is working, are owned by the same user that starts Filebeat what is correc…

---

## [Monitoring an Elasticsearch Cluster with a Single Metricbeat Instance](https://discuss.elastic.co/t/monitoring-an-elasticsearch-cluster-with-a-single-metricbeat-instance/311399)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 1\
**Last updated:** [August 24, 2022, 5:47am UTC](https://discuss.elastic.co/t/monitoring-an-elasticsearch-cluster-with-a-single-metricbeat-instance/311399 "2022-08-24T05:47:11Z")

</div>

We are currently on version 7.17.5 with the full ELK stack and are working on getting ready to jump to 8.x with the help of Upgrade Assistant. One of the cluster issues is: Setting \[xpack.monitoring.collection.enabled…

---

## [Filebeat config using keystore and arrays broke with Kibana 8 update](https://discuss.elastic.co/t/filebeat-config-using-keystore-and-arrays-broke-with-kibana-8-update/312680)

<div class="topic-metadata">

**Author:** [@archon810](https://discuss.elastic.co/u/archon810)\
**Replies:** 1\
**Last updated:** [August 23, 2022, 7:29pm UTC](https://discuss.elastic.co/t/filebeat-config-using-keystore-and-arrays-broke-with-kibana-8-update/312680 "2022-08-23T19:29:55Z")

</div>

Hi there, For years we've successfully used kibana filebeats where the var.paths variable was specified using the keystore rather than being hardcoded in the config file, like so: vi /etc/filebeat/modules.d/custom\_ngin…

---

## [The final policy size is bigger than the limit](https://discuss.elastic.co/t/the-final-policy-size-is-bigger-than-the-limit/312720)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 3:17pm UTC](https://discuss.elastic.co/t/the-final-policy-size-is-bigger-than-the-limit/312720 "2022-08-23T15:17:49Z")

</div>

I use functionbeat to ship aws lambda function logs to elasticsearch. I added a new log group today and when i attempt to update functionbeat i get the following error: The final policy size (20576) is bigger than the l…

---

## [Add module threatintel to filebeat](https://discuss.elastic.co/t/add-module-threatintel-to-filebeat/312456)

<div class="topic-metadata">

**Author:** [@dounia](https://discuss.elastic.co/u/dounia)\
**Replies:** 18\
**Last updated:** [August 23, 2022, 8:18am UTC](https://discuss.elastic.co/t/add-module-threatintel-to-filebeat/312456 "2022-08-23T08:18:46Z")

</div>

Hi, I'm adding threatintel module to filebeat , but when I restart filebeat service it failed, I get this error : Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch..

---

## [Question about Cloudtrail ingest processor for file.path](https://discuss.elastic.co/t/question-about-cloudtrail-ingest-processor-for-file-path/311405)

<div class="topic-metadata">

**Author:** [@styks90](https://discuss.elastic.co/u/styks90)\
**Replies:** 2\
**Last updated:** [August 23, 2022, 5:18am UTC](https://discuss.elastic.co/t/question-about-cloudtrail-ingest-processor-for-file-path/311405 "2022-08-23T05:18:54Z")

</div>

We've noticed while using filebeat to process logs from Cloudtrail that for some reason the processor looks at the previous S3 object and are unsure of the reasoning behind it: - rename: field: "json.previousDig…

---

## [Get info of SSL client certificate used for beats in logs send to Logstash](https://discuss.elastic.co/t/get-info-of-ssl-client-certificate-used-for-beats-in-logs-send-to-logstash/312654)

<div class="topic-metadata">

**Author:** [@jeroen.antsec](https://discuss.elastic.co/u/jeroen.antsec)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 9:45pm UTC](https://discuss.elastic.co/t/get-info-of-ssl-client-certificate-used-for-beats-in-logs-send-to-logstash/312654 "2022-08-22T21:45:42Z")

</div>

Hi. I would like to have the CN of the certificate that is used to connect from winlogbeat/filebeat to logstash as seperate field in logstash/elastic. Does anybody know if this is possible? I cannot find this anywhere …

---

## [Fillebeat keeps restarting in Kuberneates](https://discuss.elastic.co/t/fillebeat-keeps-restarting-in-kuberneates/309702)

<div class="topic-metadata">

**Author:** [@Jehutywong](https://discuss.elastic.co/u/Jehutywong)\
**Replies:** 3\
**Last updated:** [August 22, 2022, 4:01pm UTC](https://discuss.elastic.co/t/fillebeat-keeps-restarting-in-kuberneates/309702 "2022-08-22T16:01:33Z")

</div>

Filebeat Version: 8.3.2 (image gets from docker.elastic.co/beats/filebeat:8.3.2) I have roughly 40k logs in an NFS folder for Filebeat to collect. The Pod keeps restart itself in every ~10 minutes. And showing this erro…

---

## [Filebeat exclude lines with multiline](https://discuss.elastic.co/t/filebeat-exclude-lines-with-multiline/312171)

<div class="topic-metadata">

**Author:** [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 3:34pm UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-with-multiline/312171 "2022-08-22T15:34:27Z")

</div>

Hello, Is there any way we can exclude the lines first before splitting the logs via multiline pattern? I have one specific logs with 3 different log patterns, the problem is, the output is incorrect due the extra line…

---

## [No cpu/memory information from metricbeat docker module monitoring windows container](https://discuss.elastic.co/t/no-cpu-memory-information-from-metricbeat-docker-module-monitoring-windows-container/311923)

<div class="topic-metadata">

**Author:** [@ragustin](https://discuss.elastic.co/u/ragustin)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 3:21pm UTC](https://discuss.elastic.co/t/no-cpu-memory-information-from-metricbeat-docker-module-monitoring-windows-container/311923 "2022-08-22T15:21:18Z")

</div>

Hi, I'm trying to monitor my Windows Containers with metricbeat 8.3.3, and it seems that metricbeat is not gathering the stats for CPU, memory for Windows Containers. Operating System: Windows Server 2019

---

## [Multiline under multiline filebeat](https://discuss.elastic.co/t/multiline-under-multiline-filebeat/311904)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 2\
**Last updated:** [August 22, 2022, 3:17pm UTC](https://discuss.elastic.co/t/multiline-under-multiline-filebeat/311904 "2022-08-22T15:17:06Z")

</div>

Hi, I split each log using multiline filebeat: - type: log enabled: true paths: - D:\\elastic\_stack\\journal\\\* fields: kafka\_topic: "kafka-topic-1" multiline.type: pattern multiline.pattern: '^\\s…

---

## [Unable to capture application log via filebeat but filebeat service gets stopped every one second after modifying yml file](https://discuss.elastic.co/t/unable-to-capture-application-log-via-filebeat-but-filebeat-service-gets-stopped-every-one-second-after-modifying-yml-file/311869)

<div class="topic-metadata">

**Author:** [@Nishi\_Shah](https://discuss.elastic.co/u/Nishi_Shah)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 3:13pm UTC](https://discuss.elastic.co/t/unable-to-capture-application-log-via-filebeat-but-filebeat-service-gets-stopped-every-one-second-after-modifying-yml-file/311869 "2022-08-22T15:13:40Z")

</div>

Hi, I am trying to capture application logs from windows system via filebeat but service gets stopped every one second after modifying yml file. Unable to get data in kibana dashboard. Attached filebeat yml file .. Kind…

---

## [Filebeat can't read log file continuously](https://discuss.elastic.co/t/filebeat-cant-read-log-file-continuously/311756)

<div class="topic-metadata">

**Author:** [@mgazanayi](https://discuss.elastic.co/u/mgazanayi)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 3:09pm UTC](https://discuss.elastic.co/t/filebeat-cant-read-log-file-continuously/311756 "2022-08-22T15:09:00Z")

</div>

Hello, I'm trying to continuously read a log file, and output it to an other file. (In reality, I'm trying to isolate why Filebeat only reads the log file once). Here is my Filebeat configuration: filebeat.inputs: - t…

---

## [Filebeat: Apache module : two paths and two access inputs to configure](https://discuss.elastic.co/t/filebeat-apache-module-two-paths-and-two-access-inputs-to-configure/311404)

<div class="topic-metadata">

**Author:** [@hboris](https://discuss.elastic.co/u/hboris)\
**Replies:** 2\
**Last updated:** [August 22, 2022, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-two-paths-and-two-access-inputs-to-configure/311404 "2022-08-22T14:50:17Z")

</div>

Hello, I am a newbie and i am planing to install elastic stack. Here is my architecture Here is what my apache module conf looks like: #-------------------------------- Apache Module ------------------------------…

---

## [Lack of debug logs on Filebeat kafka output](https://discuss.elastic.co/t/lack-of-debug-logs-on-filebeat-kafka-output/312633)

<div class="topic-metadata">

**Author:** [@Steve\_McDuff](https://discuss.elastic.co/u/Steve_McDuff)\
**Replies:** 0\
**Last updated:** [August 22, 2022, 2:47pm UTC](https://discuss.elastic.co/t/lack-of-debug-logs-on-filebeat-kafka-output/312633 "2022-08-22T14:47:45Z")

</div>

While using filebeat, I encountered an odd issue where two servers configured with the same way behaved very differently. One of them works perfectly fine and the other one works at a very slow pace. So I know the proble…

---

## [Filebeat file path not working](https://discuss.elastic.co/t/filebeat-file-path-not-working/311473)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-file-path-not-working/311473 "2022-08-22T14:44:56Z")

</div>

I have filebeat deployed through ECK on my Kubernetes cluster. I want to read the logs from a specific pod whose log file name is something like this dev-be-svc-logistic-8c9bfbd85-qs6ng\_smartbox-dev\_dev-be-svc-logistic-4…

---

## [Elastic ECK Filebeat logs from a pod](https://discuss.elastic.co/t/elastic-eck-filebeat-logs-from-a-pod/312409)

<div class="topic-metadata">

**Author:** [@joepa37](https://discuss.elastic.co/u/joepa37)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 6:22am UTC](https://discuss.elastic.co/t/elastic-eck-filebeat-logs-from-a-pod/312409 "2022-08-22T06:22:28Z")

</div>

I have configured a Elastic ECK Beat with autodiscover for all pod logs, but I need to add logs from a specific pod log file. I have tried with module and log config but not working yet. The access.log file exists on th…

---

## [Threat Intel MISP](https://discuss.elastic.co/t/threat-intel-misp/312292)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 3\
**Last updated:** [August 19, 2022, 2:36pm UTC](https://discuss.elastic.co/t/threat-intel-misp/312292 "2022-08-19T14:36:19Z")

</div>

I'm trying to use Threat Intel MISP on filebeat and when i start the filebeat i have this error Aug 17 14:11:20 ubuntuserver filebeat\[18895\]: {"log.level":"error","@timestamp":"2022-08-17T14:11:20.550Z","log.logger":"in…

---

## [Logstash doesn't receive logs from kafka (filebeat transfer logs to kafka)](https://discuss.elastic.co/t/logstash-doesnt-receive-logs-from-kafka-filebeat-transfer-logs-to-kafka/311972)

<div class="topic-metadata">

**Author:** [@NAM\_VO](https://discuss.elastic.co/u/NAM_VO)\
**Replies:** 15\
**Last updated:** [August 19, 2022, 3:26am UTC](https://discuss.elastic.co/t/logstash-doesnt-receive-logs-from-kafka-filebeat-transfer-logs-to-kafka/311972 "2022-08-19T03:26:16Z")

</div>

Hi, I'm currently using: filebeat 8.3.3 (installed on Windows), Elasticsearch version 8.3.3 logstash 8.3.3 kafka 3.2.1 elk, kafka are on 1 server (192.168.9.70) the Windows IP which installing filebeat is 192.168.9.…

---

## [Tomcat filebeat module expected log format?](https://discuss.elastic.co/t/tomcat-filebeat-module-expected-log-format/272450)

<div class="topic-metadata">

**Author:** [@sarahw](https://discuss.elastic.co/u/sarahw)\
**Replies:** 2\
**Last updated:** [August 17, 2022, 1:20pm UTC](https://discuss.elastic.co/t/tomcat-filebeat-module-expected-log-format/272450 "2022-08-17T13:20:24Z")

</div>

I have been trying to use the Tomcat module for filebeat 7.9 (Tomcat module | Filebeat Reference \[7.9\] | Elastic) to ingest tomcat access logs from files but my log files are producing errors. I'd like to know what forma…

---

## [Grok formatting](https://discuss.elastic.co/t/grok-formatting/312312)

<div class="topic-metadata">

**Author:** [@Paulo\_Neto](https://discuss.elastic.co/u/Paulo_Neto)\
**Replies:** 6\
**Last updated:** [August 18, 2022, 1:17pm UTC](https://discuss.elastic.co/t/grok-formatting/312312 "2022-08-18T13:17:12Z")

</div>

I am trying to format the text according to the example below: %{TIMESTAMP\_ISO8601:time} %{WORD:method} %{URIPATH:uri\_requested} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:client\_ip} %{NOTSPACE:http\_version} %{NOTSP…

---

## [Filebeat setup: 400 Bad Request no handler found for uri \[//\_ilm/policy/filebeat\]](https://discuss.elastic.co/t/filebeat-setup-400-bad-request-no-handler-found-for-uri-ilm-policy-filebeat/311900)

<div class="topic-metadata">

**Author:** [@Nick95](https://discuss.elastic.co/u/Nick95)\
**Replies:** 4\
**Last updated:** [August 18, 2022, 12:40pm UTC](https://discuss.elastic.co/t/filebeat-setup-400-bad-request-no-handler-found-for-uri-ilm-policy-filebeat/311900 "2022-08-18T12:40:45Z")

</div>

Hi, I try to run a filebeat on a server. Elastic and Kibana are installed on another server and are pushed on 443 port via a nginx reverse proxy. Kibana GUI is working on the IP I set up (https with self-generated certi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=77)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=79)
