# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=81

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 82

---

## [Can anyone guide me to correct autodiscover condition?](https://discuss.elastic.co/t/can-anyone-guide-me-to-correct-autodiscover-condition/310359)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 8\
**Last updated:** [July 28, 2022, 1:07am UTC](https://discuss.elastic.co/t/can-anyone-guide-me-to-correct-autodiscover-condition/310359 "2022-07-28T01:07:00Z")

</div>

FB: 7.16.3 I try "- and:" and "and:" both get "missing or invalid condition". filebeat.autodiscover.providers: - type: kubernetes node: ${NODE\_NAME} templates: - condition: and: …

---

## [Bug? Logstash Ouput & Initial Fleet Setup](https://discuss.elastic.co/t/bug-logstash-ouput-initial-fleet-setup/310751)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 1\
**Last updated:** [July 27, 2022, 3:23pm UTC](https://discuss.elastic.co/t/bug-logstash-ouput-initial-fleet-setup/310751 "2022-07-27T15:23:14Z")

</div>

Fleet 8.3.2, fresh install. I have a Fleet Server Policy that uses a Logstash ouput: From the guided install/generated CLI text, it appears that it does not take into account the Logstash output as it sets the --fle…

---

## [Filebeat 7.11.0 multiples path and multiples index](https://discuss.elastic.co/t/filebeat-7-11-0-multiples-path-and-multiples-index/310761)

<div class="topic-metadata">

**Author:** [@pi314](https://discuss.elastic.co/u/pi314)\
**Replies:** 0\
**Last updated:** [July 27, 2022, 2:19pm UTC](https://discuss.elastic.co/t/filebeat-7-11-0-multiples-path-and-multiples-index/310761 "2022-07-27T14:19:11Z")

</div>

Hi, I need to create several indexes for different log files. I am using the following settings: setup.ilm: enabled: false setup.template: enabled: true name: "log\_dev\_testing pattern: "log\_dev\_testing-\*" set…

---

## [Filebeat zeek module shows no data](https://discuss.elastic.co/t/filebeat-zeek-module-shows-no-data/310707)

<div class="topic-metadata">

**Author:** [@Bakhtawar](https://discuss.elastic.co/u/Bakhtawar)\
**Replies:** 0\
**Last updated:** [July 27, 2022, 5:05am UTC](https://discuss.elastic.co/t/filebeat-zeek-module-shows-no-data/310707 "2022-07-27T05:05:15Z")

</div>

Hi, I followed the steps mentioned in your blog to send zeek logs to elastic. I installed zeek version 4.0.7 and filebeat version 7.17.5. Elasticsearch and kibana version is 7.15.0. Filebeats is unable to send zeek logs …

---

## [Copy and ship logs with Filebeat](https://discuss.elastic.co/t/copy-and-ship-logs-with-filebeat/310647)

<div class="topic-metadata">

**Author:** [@biandopa](https://discuss.elastic.co/u/biandopa)\
**Replies:** 1\
**Last updated:** [July 26, 2022, 1:52pm UTC](https://discuss.elastic.co/t/copy-and-ship-logs-with-filebeat/310647 "2022-07-26T13:52:00Z")

</div>

Hello, I wanted to know if there is any option with Filebeat or another tool that creates a copy of the logs and ships them to Elasticsearch instead of only shipping them because we need the logs to stay in the cluster …

---

## [In heartbeat ver. 7.17 browser type is not working](https://discuss.elastic.co/t/in-heartbeat-ver-7-17-browser-type-is-not-working/310284)

<div class="topic-metadata">

**Author:** [@Heet](https://discuss.elastic.co/u/Heet)\
**Replies:** 2\
**Last updated:** [July 26, 2022, 1:45pm UTC](https://discuss.elastic.co/t/in-heartbeat-ver-7-17-browser-type-is-not-working/310284 "2022-07-26T13:45:44Z")

</div>

Trying using using the following code still not working. type: browser id: elastic-website name: Elastic website schedule: "@every 1m" source: inline: script: |- step("load homepage", async () =\> { await page.go…

---

## [How to do to connect filebeat to kibana?](https://discuss.elastic.co/t/how-to-do-to-connect-filebeat-to-kibana/310566)

<div class="topic-metadata">

**Author:** [@Firas\_Bougrine](https://discuss.elastic.co/u/Firas_Bougrine)\
**Replies:** 2\
**Last updated:** [July 26, 2022, 9:05am UTC](https://discuss.elastic.co/t/how-to-do-to-connect-filebeat-to-kibana/310566 "2022-07-26T09:05:00Z")

</div>

how to connect filebeat to kibana(accessed with https not http) ? because when i try "$ sudo filebeat setup -e" this error appear : \[i use version 8.3.2 for kibana elastic and filebeat \] Exiting: error connecting to Ki…

---

## [Filebeat Include filter](https://discuss.elastic.co/t/filebeat-include-filter/310497)

<div class="topic-metadata">

**Author:** [@tharunkumar](https://discuss.elastic.co/u/tharunkumar)\
**Replies:** 0\
**Last updated:** [July 25, 2022, 5:23am UTC](https://discuss.elastic.co/t/filebeat-include-filter/310497 "2022-07-25T05:23:00Z")

</div>

Module: iis Docs: IIS module | Filebeat Reference \[7.16\] | Elastic module: iis Access logs access: enabled: true input : include\_lines: \["MOUIAPILive","mouiapilive"\] Set custom paths for the log files. If left emp…

---

## [Metribeats to kafka: no dashboard appear in kibana](https://discuss.elastic.co/t/metribeats-to-kafka-no-dashboard-appear-in-kibana/309688)

<div class="topic-metadata">

**Author:** [@emmanuel\_stevens\_LED](https://discuss.elastic.co/u/emmanuel_stevens_LED)\
**Replies:** 20\
**Last updated:** [July 25, 2022, 12:53am UTC](https://discuss.elastic.co/t/metribeats-to-kafka-no-dashboard-appear-in-kibana/309688 "2022-07-25T00:53:19Z")

</div>

Hello, i have an issue with metricbeat. When i send data from metricbeat to kafka and kafka send to logstash and logstash then in kibana. i can display the datas in kibana but i do not see the graphics displays in kiba…

---

## [All JSON inside message property](https://discuss.elastic.co/t/all-json-inside-message-property/310477)

<div class="topic-metadata">

**Author:** [@Itay\_Zemah](https://discuss.elastic.co/u/Itay_Zemah)\
**Replies:** 0\
**Last updated:** [July 24, 2022, 9:59am UTC](https://discuss.elastic.co/t/all-json-inside-message-property/310477 "2022-07-24T09:59:40Z")

</div>

I want to log my NodeJS logs which written to a file. I have configure filebeat to read those files and pass them to my self-managed elasticsearch + kibana. All the json content is written to the message property. I w…

---

## [Elastic-agent status Error: failed to communicate with Elastic Agent daemon](https://discuss.elastic.co/t/elastic-agent-status-error-failed-to-communicate-with-elastic-agent-daemon/308023)

<div class="topic-metadata">

**Author:** [@tidenhub](https://discuss.elastic.co/u/tidenhub)\
**Replies:** 2\
**Last updated:** [July 24, 2022, 9:52am UTC](https://discuss.elastic.co/t/elastic-agent-status-error-failed-to-communicate-with-elastic-agent-daemon/308023 "2022-07-24T09:52:35Z")

</div>

I have installed Elastic Agent 8.2.2 at my Windows 10 host. I can see the service running in the Management tools. But the command to get the status throws an error. PS is running in admin mode. PS C:\\Program Files\\El…

---

## [How to add ssl certificate for MySQL connection for metricbeat](https://discuss.elastic.co/t/how-to-add-ssl-certificate-for-mysql-connection-for-metricbeat/310461)

<div class="topic-metadata">

**Author:** [@Yasir](https://discuss.elastic.co/u/Yasir)\
**Replies:** 0\
**Last updated:** [July 23, 2022, 7:14pm UTC](https://discuss.elastic.co/t/how-to-add-ssl-certificate-for-mysql-connection-for-metricbeat/310461 "2022-07-23T19:14:37Z")

</div>

Hello - I am trying to add the ssl certificate for the mysql connection in mysql.yml for the Mysql module in metricbeat. Anyone knows what settings should work? Thank you. Yasir

---

## [Enable filebeat caching during unavailablity](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 4\
**Last updated:** [July 23, 2022, 5:15pm UTC](https://discuss.elastic.co/t/enable-filebeat-caching-during-unavailablity/308608 "2022-07-23T17:15:39Z")

</div>

Hello, I hope you and your loved ones are safe and healthy. I am running a cluster that collects logs from sources on the internet. I need to enable caching of logs in case the next hop is not reachable as dropping log…

---

## [Filebeat autodiscover kubernetes and set indexname per namespace](https://discuss.elastic.co/t/filebeat-autodiscover-kubernetes-and-set-indexname-per-namespace/310443)

<div class="topic-metadata">

**Author:** [@farhad\_kh](https://discuss.elastic.co/u/farhad_kh)\
**Replies:** 0\
**Last updated:** [July 23, 2022, 7:20am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-kubernetes-and-set-indexname-per-namespace/310443 "2022-07-23T07:20:02Z")

</div>

hi i want to use autodiscover for log shiping to elastic and i neesd add indexname per namespace but i get errore whene deploy manifest 2022-07-23T07:15:19.798Z ERROR instance/beat.go:916 Exiting: error in …

---

## [Elastic Agent Start Failure: Pipe Access Denied](https://discuss.elastic.co/t/elastic-agent-start-failure-pipe-access-denied/310421)

<div class="topic-metadata">

**Author:** [@Molly\_S\_17](https://discuss.elastic.co/u/Molly_S_17)\
**Replies:** 0\
**Last updated:** [July 22, 2022, 5:43pm UTC](https://discuss.elastic.co/t/elastic-agent-start-failure-pipe-access-denied/310421 "2022-07-22T17:43:47Z")

</div>

I'm attempting to start a standalone Elastic Agent on a Windows 10 machine (which has Winlogbeat working successfully on it) and have all of the proper files on my machine, along with an elastic-agent.yml file with the u…

---

## [Elastic ILM Configuration](https://discuss.elastic.co/t/elastic-ilm-configuration/310401)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 6\
**Last updated:** [July 22, 2022, 4:51pm UTC](https://discuss.elastic.co/t/elastic-ilm-configuration/310401 "2022-07-22T16:51:43Z")

</div>

I have filebeat writing directly into elastic and now need to configure ILM. My task is to do this through configuration so that it is deployable without user intervention. Is there are documentation that details how t…

---

## [Document for filebeat configuration](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 8\
**Last updated:** [July 22, 2022, 3:43pm UTC](https://discuss.elastic.co/t/document-for-filebeat-configuration/310396 "2022-07-22T15:43:52Z")

</div>

Is there a link anywhere that details a full filebeat configuration file? I want to know all of the configuration options that are possible. I have searched but not found anything.

---

## [Elastic Agent : AWS CloudWatch Fleet Integration Fail with RequestCanceledError](https://discuss.elastic.co/t/elastic-agent-aws-cloudwatch-fleet-integration-fail-with-requestcancelederror/310380)

<div class="topic-metadata">

**Author:** [@davide.lilliu](https://discuss.elastic.co/u/davide.lilliu)\
**Replies:** 2\
**Last updated:** [July 22, 2022, 1:30pm UTC](https://discuss.elastic.co/t/elastic-agent-aws-cloudwatch-fleet-integration-fail-with-requestcancelederror/310380 "2022-07-22T13:30:19Z")

</div>

Hi, i'm trying to set up an AWS integration to bring Lambda log group. I'm already using the AWS integration to have some metrics, so a don't think is a credential problem. I followed this guide AWS | Elastic Documenta…

---

## [Changing fleet settings installs two endpoint security instances](https://discuss.elastic.co/t/changing-fleet-settings-installs-two-endpoint-security-instances/310404)

<div class="topic-metadata">

**Author:** [@tmahany419](https://discuss.elastic.co/u/tmahany419)\
**Replies:** 0\
**Last updated:** [July 22, 2022, 1:16pm UTC](https://discuss.elastic.co/t/changing-fleet-settings-installs-two-endpoint-security-instances/310404 "2022-07-22T13:16:09Z")

</div>

Here's a vm I have running endpoint security: I changed the Default output for Agent integrations and for Agent monitoring , which should not affect this policy. It even gave me a warning that the change woul…

---

## [Filebeat Configuration](https://discuss.elastic.co/t/filebeat-configuration/310399)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 0\
**Last updated:** [July 22, 2022, 12:42pm UTC](https://discuss.elastic.co/t/filebeat-configuration/310399 "2022-07-22T12:42:30Z")

</div>

I am trying to configure filebeat to write logs to elastic. I have got the logs to go into elastic, but want know to set up ilm. I have setup.ilm: enabled: true policy\_name: "My\_Policy" And when looking in elastic …

---

## [\[Filebeat\]\[Checkpoint module\] data stream timestamp field \[@timestamp\] is missing](https://discuss.elastic.co/t/filebeat-checkpoint-module-data-stream-timestamp-field-timestamp-is-missing/309802)

<div class="topic-metadata">

**Author:** [@bbs2web](https://discuss.elastic.co/u/bbs2web)\
**Replies:** 7\
**Last updated:** [July 22, 2022, 9:25am UTC](https://discuss.elastic.co/t/filebeat-checkpoint-module-data-stream-timestamp-field-timestamp-is-missing/309802 "2022-07-22T09:25:49Z")

</div>

Hi, I'm trying to ingest CheckPoint native Syslog exports of security gateway (firewall) logs. My understanding is that integration was previously via CEF, which did not pass through sufficient detail, but that the nati…

---

## [Drop Field - Meta data value](https://discuss.elastic.co/t/drop-field-meta-data-value/310045)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 3\
**Last updated:** [July 22, 2022, 6:40am UTC](https://discuss.elastic.co/t/drop-field-meta-data-value/310045 "2022-07-22T06:40:38Z")

</div>

Hi team, We would like to know more on drop fields from Filebeat and Metricbeat data, As we implemented in Dev environment and we able to see the dropped field in dev Kibana. so we need to implement in same as in test …

---

## [Where does Metricbeat get its system.diskio data?](https://discuss.elastic.co/t/where-does-metricbeat-get-its-system-diskio-data/310303)

<div class="topic-metadata">

**Author:** [@defalt](https://discuss.elastic.co/u/defalt)\
**Replies:** 2\
**Last updated:** [July 22, 2022, 6:27am UTC](https://discuss.elastic.co/t/where-does-metricbeat-get-its-system-diskio-data/310303 "2022-07-22T06:27:56Z")

</div>

Hello, this is more of a technical question. Where does Metricbeat get its data about system.diskio? I had problems with my disks in my cluster so I want to accurately track my total disk writes. I installed Metricbeat …

---

## [Monitoring process status](https://discuss.elastic.co/t/monitoring-process-status/310298)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 3\
**Last updated:** [July 22, 2022, 6:16am UTC](https://discuss.elastic.co/t/monitoring-process-status/310298 "2022-07-22T06:16:37Z")

</div>

Hi, is there a way to monitor just the process status (up/down), just like Heartbeat monitors do? In the documentation for Heartbeat, there's no such possibility. I can use Metricbeat to collect metrics of the processes…

---

## [Heartbeat HTTP method OPTIONS](https://discuss.elastic.co/t/heartbeat-http-method-options/310280)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 2\
**Last updated:** [July 22, 2022, 6:09am UTC](https://discuss.elastic.co/t/heartbeat-http-method-options/310280 "2022-07-22T06:09:17Z")

</div>

Hi, in the documentation of Heartbeat 8.3.2 the listed methods available are: "HEAD", "GET" and "POST". For my use case, I require the "OPTIONS" method, as GET generates an unwanted null message in our system. Is there…

---

## [Error fortinet module - 7.17.3](https://discuss.elastic.co/t/error-fortinet-module-7-17-3/310348)

<div class="topic-metadata">

**Author:** [@jdxuul](https://discuss.elastic.co/u/jdxuul)\
**Replies:** 1\
**Last updated:** [July 21, 2022, 10:48pm UTC](https://discuss.elastic.co/t/error-fortinet-module-7-17-3/310348 "2022-07-21T22:48:53Z")

</div>

Hi guys, Actually i tried to parse fortigate firewall logs with the filebeat module however I'm getting a strange input values into the documents. Looking the pipeline is someting related to timezone, i've tried to cha…

---

## [Convert/Ingest Docker container Environment Variables into Filebeat/Logstash fields](https://discuss.elastic.co/t/convert-ingest-docker-container-environment-variables-into-filebeat-logstash-fields/310340)

<div class="topic-metadata">

**Author:** [@Julian\_Barnett](https://discuss.elastic.co/u/Julian_Barnett)\
**Replies:** 0\
**Last updated:** [July 21, 2022, 9:17pm UTC](https://discuss.elastic.co/t/convert-ingest-docker-container-environment-variables-into-filebeat-logstash-fields/310340 "2022-07-21T21:17:04Z")

</div>

I'm currently using filebeat 8.3.0 and we're copying a few container LABELS to fields via something like this: - copy\_fields: fields: - from: container.labels.custom\_label to: custom\_label We ha…

---

## [Winlogbeat Service Still Running but Security Log Events No Longer Published After Windows Auto-Archives Event Log- Sometimes](https://discuss.elastic.co/t/winlogbeat-service-still-running-but-security-log-events-no-longer-published-after-windows-auto-archives-event-log-sometimes/310325)

<div class="topic-metadata">

**Author:** [@eafrost.cissp](https://discuss.elastic.co/u/eafrost.cissp)\
**Replies:** 1\
**Last updated:** [July 21, 2022, 6:44pm UTC](https://discuss.elastic.co/t/winlogbeat-service-still-running-but-security-log-events-no-longer-published-after-windows-auto-archives-event-log-sometimes/310325 "2022-07-21T18:44:03Z")

</div>

I'm running Elastic Stack v8.2.0 on Windows. I've noticed that sometimes/randomly winlogbeat stops publishing events when the Windows event log fills up and auto-archives itself. The winlogbeat service is still running b…

---

## [Parsing custom log timestamps, how?](https://discuss.elastic.co/t/parsing-custom-log-timestamps-how/310205)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 3\
**Last updated:** [July 21, 2022, 5:41pm UTC](https://discuss.elastic.co/t/parsing-custom-log-timestamps-how/310205 "2022-07-21T17:41:58Z")

</div>

I'm having issues figuring out how to get a timestamp out of a custom log. I've been trying to use the dissect and timestamp processors via the Custom configurations field in the fleet policy -\> custom log screen. Here…

---

## [GCP PubSub input stops suddenly due to RST\_STREAM](https://discuss.elastic.co/t/gcp-pubsub-input-stops-suddenly-due-to-rst-stream/310194)

<div class="topic-metadata">

**Author:** [@stevensim226](https://discuss.elastic.co/u/stevensim226)\
**Replies:** 1\
**Last updated:** [July 21, 2022, 12:57pm UTC](https://discuss.elastic.co/t/gcp-pubsub-input-stops-suddenly-due-to-rst-stream/310194 "2022-07-21T12:57:02Z")

</div>

I'm currently using Filebeat 7.17.5 in Docker pulled from the official docker repository I keep getting this error at random intervals since 19th July 2022 (I have been using Filebeat for \>1 year) which stops pubsub log…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=80)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=82)
