# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=82

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 83

---

## [Filebeat 8.3.2 module and file stream issues](https://discuss.elastic.co/t/filebeat-8-3-2-module-and-file-stream-issues/310192)

<div class="topic-metadata">

**Author:** [@CynorSense](https://discuss.elastic.co/u/CynorSense)\
**Replies:** 1\
**Last updated:** [July 21, 2022, 12:55pm UTC](https://discuss.elastic.co/t/filebeat-8-3-2-module-and-file-stream-issues/310192 "2022-07-21T12:55:58Z")

</div>

Modules in filebeat 8.3.2 had changed the file input to filestream and indexing is happening through filestream. When we enable modules. It is not working at all. We tried to enable manually using filebeat setup --pip…

---

## [Need to drop the commented lines and some lines matching the specified string](https://discuss.elastic.co/t/need-to-drop-the-commented-lines-and-some-lines-matching-the-specified-string/310120)

<div class="topic-metadata">

**Author:** [@dhanu1](https://discuss.elastic.co/u/dhanu1)\
**Replies:** 2\
**Last updated:** [July 21, 2022, 12:55pm UTC](https://discuss.elastic.co/t/need-to-drop-the-commented-lines-and-some-lines-matching-the-specified-string/310120 "2022-07-21T12:55:45Z")

</div>

I have installed ELK in one server and filebeat in other server where logs resides. My logs are moved and able to view in Kibana. But I dont need the commented lines and lines with certains text to be displayed in kibana…

---

## [Elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/310010)

<div class="topic-metadata">

**Author:** [@Nguy\_n\_H\_u\_Phu](https://discuss.elastic.co/u/Nguy_n_H_u_Phu)\
**Replies:** 2\
**Last updated:** [July 21, 2022, 12:47pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-send-logs-to-filebeat-and-or-logstash/310010 "2022-07-21T12:47:48Z")

</div>

I have input but cant show output! I need help! filebeat.yml filebeat.inputs: type: filestream id: router1 enabled: true paths: /u01/redis\_app/run/tomcat-deploy-camidlog/logs/report\_log/report.log output.logstash: …

---

## [PANOS filebeat doesn't parse VPN logs](https://discuss.elastic.co/t/panos-filebeat-doesnt-parse-vpn-logs/310289)

<div class="topic-metadata">

**Author:** [@anubisg1](https://discuss.elastic.co/u/anubisg1)\
**Replies:** 0\
**Last updated:** [July 21, 2022, 12:35pm UTC](https://discuss.elastic.co/t/panos-filebeat-doesnt-parse-vpn-logs/310289 "2022-07-21T12:35:21Z")

</div>

as per title, the following is an example of logs received and parsed by panos beat. Notice that event.original has been preserved but it's content related to the actual message is lost after parsing. { "\_index": ".d…

---

## [Filebeat over a shared network](https://discuss.elastic.co/t/filebeat-over-a-shared-network/310157)

<div class="topic-metadata">

**Author:** [@Steve666](https://discuss.elastic.co/u/Steve666)\
**Replies:** 4\
**Last updated:** [July 21, 2022, 7:44am UTC](https://discuss.elastic.co/t/filebeat-over-a-shared-network/310157 "2022-07-21T07:44:39Z")

</div>

Hi, I have a setup with 5 machines (5 pc's) that makes their own logfiles. All those 5 machines are connected to one (another) PC that runs filebeat. Filebeat processes all logfiles from the 5 machines but when I rest…

---

## [Winlogbeat data missing](https://discuss.elastic.co/t/winlogbeat-data-missing/310148)

<div class="topic-metadata">

**Author:** [@HTM](https://discuss.elastic.co/u/HTM)\
**Replies:** 5\
**Last updated:** [July 21, 2022, 6:05am UTC](https://discuss.elastic.co/t/winlogbeat-data-missing/310148 "2022-07-21T06:05:44Z")

</div>

Hi All, New Elastic user here:) My setup: Ubuntu 22.04 LTS Server, running ELK Stack. My kibana.yml: My Elasticsearch.yml: I Have added our Sophos firewall using the Sophos Filebeat module. I can read a…

---

## [Does Filebeat's timestamp processor need the source field to only contain the time?](https://discuss.elastic.co/t/does-filebeats-timestamp-processor-need-the-source-field-to-only-contain-the-time/309130)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 6\
**Last updated:** [July 20, 2022, 8:20pm UTC](https://discuss.elastic.co/t/does-filebeats-timestamp-processor-need-the-source-field-to-only-contain-the-time/309130 "2022-07-20T20:20:01Z")

</div>

What my subject says. I'm currently telling timestamp to use the message field as the source, and I'm not sure it's actually working. Do I need to parse out the time from the message before using the timestamp processor? …

---

## [Filebeat haproxy module - with custom log\_format - how could it ever work?](https://discuss.elastic.co/t/filebeat-haproxy-module-with-custom-log-format-how-could-it-ever-work/310199)

<div class="topic-metadata">

**Author:** [@jrwren](https://discuss.elastic.co/u/jrwren)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 7:56pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-with-custom-log-format-how-could-it-ever-work/310199 "2022-07-20T19:56:07Z")

</div>

It isn't clear from the docs here HAproxy module | Filebeat Reference \[master\] | Elastic How the logs are parsed. If I have customized the haproxy logs using a log-format directive in my haproxy.conf, how can filebeat …

---

## [Failed to publish events: connect: connection refused](https://discuss.elastic.co/t/failed-to-publish-events-connect-connection-refused/309785)

<div class="topic-metadata">

**Author:** [@knitehias](https://discuss.elastic.co/u/knitehias)\
**Replies:** 3\
**Last updated:** [July 20, 2022, 2:31pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-connect-connection-refused/309785 "2022-07-20T14:31:35Z")

</div>

Hi Experts, I am using beats-\>logstash-\>elasticsearch-kibana stack. Every now and then my file beat will log error log then no other logging at all 2022-07-16T10:04:26.148Z ERROR \[publisher\_pipeline\_output\] pipeli…

---

## [Beats connection to elasticsearch](https://discuss.elastic.co/t/beats-connection-to-elasticsearch/309701)

<div class="topic-metadata">

**Author:** [@Amiya\_Pani](https://discuss.elastic.co/u/Amiya_Pani)\
**Replies:** 8\
**Last updated:** [July 20, 2022, 8:30am UTC](https://discuss.elastic.co/t/beats-connection-to-elasticsearch/309701 "2022-07-20T08:30:07Z")

</div>

I am trying to start a filebeat on docker to point the output to elasticsearch which is on same docker. While giving the command docker run docker.elastic.co/beats/filebeat:8.3.2 setup -E setup.kibana.host=192.168.0.109…

---

## [Problems using multiline configurations](https://discuss.elastic.co/t/problems-using-multiline-configurations/309991)

<div class="topic-metadata">

**Author:** [@Hkh9966](https://discuss.elastic.co/u/Hkh9966)\
**Replies:** 4\
**Last updated:** [July 20, 2022, 8:06am UTC](https://discuss.elastic.co/t/problems-using-multiline-configurations/309991 "2022-07-20T08:06:33Z")

</div>

hello guys! I would like to ask a question about multi-line merging. I tried to test using the example provided by the official, but it didn't work.This is the link : Manage multiline messages | Filebeat Reference \[8.3\]…

---

## [Metricbeat restart with server](https://discuss.elastic.co/t/metricbeat-restart-with-server/309910)

<div class="topic-metadata">

**Author:** [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Replies:** 2\
**Last updated:** [July 20, 2022, 7:50am UTC](https://discuss.elastic.co/t/metricbeat-restart-with-server/309910 "2022-07-20T07:50:36Z")

</div>

Hello Experts, I am a beginner in Elasticsearch. I want to register Metricbeat as service (not sure if it should be called as a service ) on Linux. I have instlled Metricbeat and ran it in background using "./Metricbe…

---

## [Turning a Filebeat Log into a configured index](https://discuss.elastic.co/t/turning-a-filebeat-log-into-a-configured-index/309926)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 8\
**Last updated:** [July 20, 2022, 4:23am UTC](https://discuss.elastic.co/t/turning-a-filebeat-log-into-a-configured-index/309926 "2022-07-20T04:23:53Z")

</div>

So I've been using Filebeat for a while and so far it worked fined, but is getting into the cluster a single message; I want to have it setted into the cluster as separate fields in a way that I could manipulate it bet…

---

## [Problem with fleet server, intake/v2/events not found](https://discuss.elastic.co/t/problem-with-fleet-server-intake-v2-events-not-found/310051)

<div class="topic-metadata">

**Author:** [@Cpt\_Falcon](https://discuss.elastic.co/u/Cpt_Falcon)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 4:41pm UTC](https://discuss.elastic.co/t/problem-with-fleet-server-intake-v2-events-not-found/310051 "2022-07-19T16:41:57Z")

</div>

Hello, I'm currently trying to use fleet server locally on docker desktop. I feel like I've almost got it working but there seems to be a bug with the fleet server as intake/v2/events does not exist? I really don't unde…

---

## [Pushing log to elastic.co and splitting message](https://discuss.elastic.co/t/pushing-log-to-elastic-co-and-splitting-message/310053)

<div class="topic-metadata">

**Author:** [@milosz](https://discuss.elastic.co/u/milosz)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 5:33pm UTC](https://discuss.elastic.co/t/pushing-log-to-elastic-co-and-splitting-message/310053 "2022-07-19T17:33:23Z")

</div>

Hi, I'm using elastic.co and filebeat. My config is: cloud.id: cloud.auth: filebeat.inputs: - type: log enabled: true paths: - /var/www/vhosts/doomain/logs/access\_ssl\_log tags: domain fields: log\_type:…

---

## [Incorrect Kibana Mappings From Winlogbeats Setup Command](https://discuss.elastic.co/t/incorrect-kibana-mappings-from-winlogbeats-setup-command/309953)

<div class="topic-metadata">

**Author:** [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Replies:** 2\
**Last updated:** [July 19, 2022, 3:47pm UTC](https://discuss.elastic.co/t/incorrect-kibana-mappings-from-winlogbeats-setup-command/309953 "2022-07-19T15:47:24Z")

</div>

I have installed Winlogbeat on my computer and data seems to be flowing correctly. My data flows through my stack as shown Winlogbeat -\> logstash -\> elasticsearch I am trying to setup the index templates for Winlogbeat…

---

## [\[metricbeat\] - Prometheus module - invalid escape sequence '\\"'](https://discuss.elastic.co/t/metricbeat-prometheus-module-invalid-escape-sequence/308421)

<div class="topic-metadata">

**Author:** [@harikvemula](https://discuss.elastic.co/u/harikvemula)\
**Replies:** 2\
**Last updated:** [July 19, 2022, 10:30am UTC](https://discuss.elastic.co/t/metricbeat-prometheus-module-invalid-escape-sequence/308421 "2022-07-19T10:30:41Z")

</div>

Hi, Metricbeat: 7.10.2 I am trying to use Metricbeat prometheus module to pull metrics from Spring boot application with micrometer prometheus format . It fails with the following error 2022-06-29T12:21:37.658 +0000 …

---

## [Creating Custom Field in Kibana and fetching the values from a particular line in message](https://discuss.elastic.co/t/creating-custom-field-in-kibana-and-fetching-the-values-from-a-particular-line-in-message/309889)

<div class="topic-metadata">

**Author:** [@Dhinesh\_Prabakaran](https://discuss.elastic.co/u/Dhinesh_Prabakaran)\
**Replies:** 1\
**Last updated:** [July 19, 2022, 10:19am UTC](https://discuss.elastic.co/t/creating-custom-field-in-kibana-and-fetching-the-values-from-a-particular-line-in-message/309889 "2022-07-19T10:19:34Z")

</div>

Hi All, We've been using ELK to monitor our network and infrastructure logs. We have a requirement. We need to create a custom field name in filebeat so that we can use it as a unique key to filter the log messages in …

---

## [Setup.template.enabled: false. not work for disable default mapping](https://discuss.elastic.co/t/setup-template-enabled-false-not-work-for-disable-default-mapping/309720)

<div class="topic-metadata">

**Author:** [@sinbargit](https://discuss.elastic.co/u/sinbargit)\
**Replies:** 1\
**Last updated:** [July 19, 2022, 2:08am UTC](https://discuss.elastic.co/t/setup-template-enabled-false-not-work-for-disable-default-mapping/309720 "2022-07-19T02:08:40Z")

</div>

filebeat version 7.1.1. I set setup.template.enabled: false. but there are still other fields like network.\* in my index. And after I set my own template, the template is used, but still certain fields in my index. J…

---

## [Heartbeat - Avoid journey timeout](https://discuss.elastic.co/t/heartbeat-avoid-journey-timeout/309421)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 1\
**Last updated:** [July 18, 2022, 8:29pm UTC](https://discuss.elastic.co/t/heartbeat-avoid-journey-timeout/309421 "2022-07-18T20:29:58Z")

</div>

Hello, I'm working with synthetic monitoring. How can I prevent the journey from finishing when one of the steps throws an error or timeout and 2 steps remain pending? unfortunately I have a small number of logins on a…

---

## [Confirm connection](https://discuss.elastic.co/t/confirm-connection/309498)

<div class="topic-metadata">

**Author:** [@puritymind85](https://discuss.elastic.co/u/puritymind85)\
**Replies:** 1\
**Last updated:** [July 18, 2022, 6:39pm UTC](https://discuss.elastic.co/t/confirm-connection/309498 "2022-07-18T18:39:48Z")

</div>

Hello. Configuring ELK it is necessary to configure fleet and agent. The agent is running on the 3rd installation point fleet still shows Confirm connection. Tell me what could be the problem? Everything is installed on…

---

## [Dedicated index logs-ti\* (Threat Intel module) in Filebeat](https://discuss.elastic.co/t/dedicated-index-logs-ti-threat-intel-module-in-filebeat/309908)

<div class="topic-metadata">

**Author:** [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Replies:** 0\
**Last updated:** [July 18, 2022, 1:52pm UTC](https://discuss.elastic.co/t/dedicated-index-logs-ti-threat-intel-module-in-filebeat/309908 "2022-07-18T13:52:26Z")

</div>

I have a minor problem, According to the documentation, the logs from the Threat Intel module in Filebeat can reside in a dedicated logs-ti\* index. Quick link to the page: Enable threat intelligence integrations | Elas…

---

## [Problems With Winlogbeat](https://discuss.elastic.co/t/problems-with-winlogbeat/308508)

<div class="topic-metadata">

**Author:** [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Replies:** 3\
**Last updated:** [July 18, 2022, 12:22pm UTC](https://discuss.elastic.co/t/problems-with-winlogbeat/308508 "2022-07-18T12:22:56Z")

</div>

Hello, I am trying to setup Winlogbeat and I am running into some issues. I was able to get it configured correctly and when I run it in debug mode it seems to run fine. .\\winlogbeat.exe -c winlogbeat.yml -e -v -d "\*" W…

---

## [Filebeat: Autodiscover with Nomad + Docker Metadata](https://discuss.elastic.co/t/filebeat-autodiscover-with-nomad-docker-metadata/309404)

<div class="topic-metadata">

**Author:** [@adsr](https://discuss.elastic.co/u/adsr)\
**Replies:** 2\
**Last updated:** [July 18, 2022, 12:10pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-with-nomad-docker-metadata/309404 "2022-07-18T12:10:26Z")

</div>

Hi everyone, I am currently struggling with adding the docker metadata to my events which are fetched via the filebeat autodiscover nomad provider. filebeat.yml tyfilebeat.autodiscover: providers: - type: nomad …

---

## [How do I extract partial fields from log.file.path](https://discuss.elastic.co/t/how-do-i-extract-partial-fields-from-log-file-path/309854)

<div class="topic-metadata">

**Author:** [@regyhuang](https://discuss.elastic.co/u/regyhuang)\
**Replies:** 0\
**Last updated:** [July 18, 2022, 7:36am UTC](https://discuss.elastic.co/t/how-do-i-extract-partial-fields-from-log-file-path/309854 "2022-07-18T07:36:11Z")

</div>

for example log.file.path:/data/logs/service-name/service-name.log I want to extract the service-name of log.file.path as a tags ,How to configure filebeat.yml

---

## [How to add an additional ingest pipeline to filebeat when using a module](https://discuss.elastic.co/t/how-to-add-an-additional-ingest-pipeline-to-filebeat-when-using-a-module/309834)

<div class="topic-metadata">

**Author:** [@Zack1](https://discuss.elastic.co/u/Zack1)\
**Replies:** 5\
**Last updated:** [July 18, 2022, 3:06am UTC](https://discuss.elastic.co/t/how-to-add-an-additional-ingest-pipeline-to-filebeat-when-using-a-module/309834 "2022-07-18T03:06:59Z")

</div>

I have apache logs, so I use the apache module in filebeat. However, I also want to apply an ingest pipeline I have made that adds an email field, but apparently the output.elasticsearch.pipeline option doesn't work when…

---

## [Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/309477)

<div class="topic-metadata">

**Author:** [@Nishi\_Shah](https://discuss.elastic.co/u/Nishi_Shah)\
**Replies:** 2\
**Last updated:** [July 17, 2022, 10:53pm UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-sends-log-files-to-logstash-or-directly-to-elasticsearch/309477 "2022-07-17T22:53:44Z")

</div>

I am trying to configure filebeat(7.17.5). when i restart filebeat only status is showing active \[root@ELK-LAB-VM filebeat\]# systemctl status filebeat ● filebeat.service - Filebeat sends log files to Logstash or dir…

---

## [How to parse CRI logs](https://discuss.elastic.co/t/how-to-parse-cri-logs/309814)

<div class="topic-metadata">

**Author:** [@redoran](https://discuss.elastic.co/u/redoran)\
**Replies:** 0\
**Last updated:** [July 17, 2022, 10:35am UTC](https://discuss.elastic.co/t/how-to-parse-cri-logs/309814 "2022-07-17T10:35:33Z")

</div>

Hello, (sry for my english) I'm trying to parse CRI logs. Logs not in JSON format are not parsed. An example of logs that are parsed correctly 2022-07-15T14:50:51.994932036Z stdout F {"@timestamp":"timestamp","@versio…

---

## [Unable to bulk\_create index-pattern](https://discuss.elastic.co/t/unable-to-bulk-create-index-pattern/309754)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [July 15, 2022, 8:48pm UTC](https://discuss.elastic.co/t/unable-to-bulk-create-index-pattern/309754 "2022-07-15T20:48:10Z")

</div>

Hello World! I'm trying to follow these: Grant privileges and roles needed for setup | Auditbeat Reference \[7.17\] | Elastic Grant privileges and roles needed for setup | Filebeat Reference \[7.17\] | Elastic Grant privi…

---

## [: i/o timeout](https://discuss.elastic.co/t/i-o-timeout/309648)

<div class="topic-metadata">

**Author:** [@Rook1](https://discuss.elastic.co/u/Rook1)\
**Replies:** 2\
**Last updated:** [July 15, 2022, 3:14pm UTC](https://discuss.elastic.co/t/i-o-timeout/309648 "2022-07-15T15:14:35Z")

</div>

Hello, i have a problems with heartbeat. It's work normally before and now very often shows down( : i/o timeout ) but internet's is good if i tried open sites manually is too open good. I don;t understand why heartbeat a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=81)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=83)
