# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=83

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 84

---

## [Capture network traffic](https://discuss.elastic.co/t/capture-network-traffic/309738)

<div class="topic-metadata">

**Author:** [@brkw](https://discuss.elastic.co/u/brkw)\
**Replies:** 0\
**Last updated:** [July 15, 2022, 1:14pm UTC](https://discuss.elastic.co/t/capture-network-traffic/309738 "2022-07-15T13:14:06Z")

</div>

Hi all. I want to use ELk stack with beats to capture all traffic in my network. I installed ELK stack on VM and I want to capture all the traffic which goes in or out in my network. My configuration is set in this way: …

---

## [Insert a Loadbalancer between Filebeat and Logstash, and encrypt traffic](https://discuss.elastic.co/t/insert-a-loadbalancer-between-filebeat-and-logstash-and-encrypt-traffic/309721)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 0\
**Last updated:** [July 15, 2022, 8:31am UTC](https://discuss.elastic.co/t/insert-a-loadbalancer-between-filebeat-and-logstash-and-encrypt-traffic/309721 "2022-07-15T08:31:01Z")

</div>

Hi, starting from the assumption that filebeat has its loadbalancer; Is it possbile to insert a loadbalancer between logstash and filebeat? And if it's possibile, how can encrypt traffic/data from filebeat to Loadbala…

---

## [Exiting: 1 error: failed to create audit client: failed to get audit status: operation not permitted](https://discuss.elastic.co/t/exiting-1-error-failed-to-create-audit-client-failed-to-get-audit-status-operation-not-permitted/309579)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 2\
**Last updated:** [July 15, 2022, 3:07am UTC](https://discuss.elastic.co/t/exiting-1-error-failed-to-create-audit-client-failed-to-get-audit-status-operation-not-permitted/309579 "2022-07-15T03:07:56Z")

</div>

Hello World! I'm trying to Run Auditbeat on Docker | Auditbeat Reference \[7.17\] | Elastic, yet running into following issue: # docker compose logs --tail 1 auditbeat | Exiting: 1 error: failed to create audit client: …

---

## [How to check the status of application pools](https://discuss.elastic.co/t/how-to-check-the-status-of-application-pools/309537)

<div class="topic-metadata">

**Author:** [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Replies:** 8\
**Last updated:** [July 14, 2022, 9:14pm UTC](https://discuss.elastic.co/t/how-to-check-the-status-of-application-pools/309537 "2022-07-14T21:14:08Z")

</div>

Hi Team, Can you please guide how to check the status of IIS application pools whether it is "started" or "stopped" in Kibana using metricbeat?

---

## [Elastic Agent fails to parse Auditd logs "Failed to parse value \[yes\] as only \[true\] or \[false\] are allowed."](https://discuss.elastic.co/t/elastic-agent-fails-to-parse-auditd-logs-failed-to-parse-value-yes-as-only-true-or-false-are-allowed/309038)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 1\
**Last updated:** [July 14, 2022, 5:15pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-to-parse-auditd-logs-failed-to-parse-value-yes-as-only-true-or-false-are-allowed/309038 "2022-07-14T17:15:42Z")

</div>

When I fixed a different issue, I noticed a bunch of lines show up in the Elastic Agent's Filebeat logs saying it was just dropping them instead of sending them to Elasticsearch. As far as I can tell every line in the a…

---

## [Metricbeat Output to Kafka via Kerberos Error](https://discuss.elastic.co/t/metricbeat-output-to-kafka-via-kerberos-error/309675)

<div class="topic-metadata">

**Author:** [@masonlesser](https://discuss.elastic.co/u/masonlesser)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 5:14pm UTC](https://discuss.elastic.co/t/metricbeat-output-to-kafka-via-kerberos-error/309675 "2022-07-14T17:14:07Z")

</div>

Has anyone been able to get Kerberos output to Kafka to work for Metricbeat (v 7.17) on Windows? I've attempted both keytab and password auth types for Kerberos. The initial error I get is: kafka: client has run out of …

---

## [OpenSSL failed to parse encrypted private key](https://discuss.elastic.co/t/openssl-failed-to-parse-encrypted-private-key/309584)

<div class="topic-metadata">

**Author:** [@jocha](https://discuss.elastic.co/u/jocha)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 10:35pm UTC](https://discuss.elastic.co/t/openssl-failed-to-parse-encrypted-private-key/309584 "2022-07-13T22:35:13Z")

</div>

Hello, Is this issue from before still a problem with filebeats? Filebeat private key parse error - #6 by adrisr Also running on openssl version 1.x, when using encrypted pem key with key\_passphrase getting: Exiting: …

---

## [Got permission denied while trying to connect to the Docker daemon socket at unix:///var/run/docker.sock](https://discuss.elastic.co/t/got-permission-denied-while-trying-to-connect-to-the-docker-daemon-socket-at-unix-var-run-docker-sock/307692)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 5:31pm UTC](https://discuss.elastic.co/t/got-permission-denied-while-trying-to-connect-to-the-docker-daemon-socket-at-unix-var-run-docker-sock/307692 "2022-07-13T17:31:03Z")

</div>

Hello World! I'm trying to Run Filebeat on Docker | Filebeat Reference \[7.17\] | Elastic yet running into following issue: % docker-compose logs --tail 2 filebeat filebeat | 2022-06-20T19:05:12.965Z ERROR instance…

---

## [Monitoring Beats installed server](https://discuss.elastic.co/t/monitoring-beats-installed-server/309554)

<div class="topic-metadata">

**Author:** [@Muhammed\_Ashique](https://discuss.elastic.co/u/Muhammed_Ashique)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 4:34pm UTC](https://discuss.elastic.co/t/monitoring-beats-installed-server/309554 "2022-07-13T16:34:17Z")

</div>

I have installed filebeat and Winlogbeat around 700 servers. I want to monitor these servers if any servers failed to sent logs in Elasticsearch. How can i do this ?

---

## [Metricbeat credentials config help](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283)

<div class="topic-metadata">

**Author:** [@sadik](https://discuss.elastic.co/u/sadik)\
**Replies:** 5\
**Last updated:** [July 13, 2022, 2:37pm UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283 "2022-07-13T14:37:46Z")

</div>

HI Team, In " metricbeat.yml" configuration file we are using the below values for estrablish the connection to AWS. metricbeat.modules: - module: aws period: 300s metricsets: - lambda access\_key\_id…

---

## [Azure App Service Web Job won't start after update: Exiting: The system cannot find the file specified](https://discuss.elastic.co/t/azure-app-service-web-job-wont-start-after-update-exiting-the-system-cannot-find-the-file-specified/309449)

<div class="topic-metadata">

**Author:** [@daymansiege](https://discuss.elastic.co/u/daymansiege)\
**Replies:** 0\
**Last updated:** [July 12, 2022, 5:56pm UTC](https://discuss.elastic.co/t/azure-app-service-web-job-wont-start-after-update-exiting-the-system-cannot-find-the-file-specified/309449 "2022-07-12T17:56:51Z")

</div>

Hi! I was using 7.9.2 filebeat successfully as Azure Web Job with IIS module enabled. Was running it as this: run.cmd: set JOB\_DIR=%~dp0 %JOB\_DIR%filebeat.exe --environment=windows\_service -c %JOB\_DIR%filebeat.yml --…

---

## [Filebeat central log server and hostname](https://discuss.elastic.co/t/filebeat-central-log-server-and-hostname/308832)

<div class="topic-metadata">

**Author:** [@parisila](https://discuss.elastic.co/u/parisila)\
**Replies:** 1\
**Last updated:** [July 12, 2022, 10:51pm UTC](https://discuss.elastic.co/t/filebeat-central-log-server-and-hostname/308832 "2022-07-12T22:51:52Z")

</div>

I have a central log server receiving all system and audit logs. The system logs all go into the same log file and have the host name in the message. I only have filebeat running on the central log server processing lo…

---

## [Timestamp in Windows event message encoded ANSI/Windows-12 adds garbage value when converted in utf8 by winlogbeat](https://discuss.elastic.co/t/timestamp-in-windows-event-message-encoded-ansi-windows-12-adds-garbage-value-when-converted-in-utf8-by-winlogbeat/299069)

<div class="topic-metadata">

**Author:** [@Raunak17](https://discuss.elastic.co/u/Raunak17)\
**Replies:** 1\
**Last updated:** [July 12, 2022, 8:00pm UTC](https://discuss.elastic.co/t/timestamp-in-windows-event-message-encoded-ansi-windows-12-adds-garbage-value-when-converted-in-utf8-by-winlogbeat/299069 "2022-07-12T20:00:41Z")

</div>

The windows event message is below when converted to utf8, it is adding garbage value "The system time has changed to â€Ž2022â€Ž-â€Ž03â€Ž-â€Ž08T09:51:08.763000000Z from â€Ž2022â€Ž-â€Ž03â€Ž-â€Ž08T09:50:14.842044400Z.…

---

## [Failed to load process information for PID 32338: readlink /proc/32338/exe: permission denied](https://discuss.elastic.co/t/failed-to-load-process-information-for-pid-32338-readlink-proc-32338-exe-permission-denied/309420)

<div class="topic-metadata">

**Author:** [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Replies:** 0\
**Last updated:** [July 12, 2022, 12:47pm UTC](https://discuss.elastic.co/t/failed-to-load-process-information-for-pid-32338-readlink-proc-32338-exe-permission-denied/309420 "2022-07-12T12:47:52Z")

</div>

Hello, i have auditbeat version 8.3.2 running in kubernetes and i am getting this kind of error all of the time failed to load process information for PID 32338: readlink /proc/32338/exe: permission denied I am using c…

---

## [Watcher.go logs old docker container events as if they are new and may log error if container has been removed](https://discuss.elastic.co/t/watcher-go-logs-old-docker-container-events-as-if-they-are-new-and-may-log-error-if-container-has-been-removed/309355)

<div class="topic-metadata">

**Author:** [@chad.showalter](https://discuss.elastic.co/u/chad.showalter)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 7:09pm UTC](https://discuss.elastic.co/t/watcher-go-logs-old-docker-container-events-as-if-they-are-new-and-may-log-error-if-container-has-been-removed/309355 "2022-07-11T19:09:50Z")

</div>

We are using filebeat to publish our application logs to graylog. Both our application and filebeat are running in docker containers. When we turn on debug logging in filebeat, we observe that a debug logging statement…

---

## [Error: fleet-server failed: context canceled | Error - dial tcp 172.18.0.2:9200: i/o timeout](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled-error-dial-tcp-172-18-0-2-i-o-timeout/306411)

<div class="topic-metadata">

**Author:** [@ilia19945](https://discuss.elastic.co/u/ilia19945)\
**Replies:** 5\
**Last updated:** [July 10, 2022, 4:57pm UTC](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled-error-dial-tcp-172-18-0-2-i-o-timeout/306411 "2022-07-10T16:57:18Z")

</div>

Kibana version: v 8.2.2 Elasticsearch version: v 8.2.2 APM Server version: v 8.2.2 APM Agent language and version: Python 3.10.0 Browser version: Google Chrome Version 102.0.5005.63 (Official Build) (64-bit) O…

---

## [Exiting: error unpacking config data: more than one namespace configured accessing 'output' (source:'heartbeat.yml')](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-heartbeat-yml/309161)

<div class="topic-metadata">

**Author:** [@Ronald1](https://discuss.elastic.co/u/Ronald1)\
**Replies:** 1\
**Last updated:** [July 8, 2022, 4:28pm UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-heartbeat-yml/309161 "2022-07-08T16:28:00Z")

</div>

Hello, I run ELK stack using Docker Compose. See Install Elasticsearch with Docker | Elasticsearch Guide \[8.3\] | Elastic. It works fine. I can login using Kibana. I want to run Heartbeat on Docker as well, using Run He…

---

## [Filebeat using IAM role for ECS tasks does not work](https://discuss.elastic.co/t/filebeat-using-iam-role-for-ecs-tasks-does-not-work/308851)

<div class="topic-metadata">

**Author:** [@masato](https://discuss.elastic.co/u/masato)\
**Replies:** 1\
**Last updated:** [July 8, 2022, 5:01am UTC](https://discuss.elastic.co/t/filebeat-using-iam-role-for-ecs-tasks-does-not-work/308851 "2022-07-08T05:01:30Z")

</div>

Hi team, I've tried to run filebeat with the cisco module (umbrella) in the ECS task. The umbrella module is configured without access\_key\_id and secret\_access\_key. I think I can now achieve filebeat using the IAM role …

---

## [Drop Processors on .yml file](https://discuss.elastic.co/t/drop-processors-on-yml-file/309109)

<div class="topic-metadata">

**Author:** [@maviles](https://discuss.elastic.co/u/maviles)\
**Replies:** 6\
**Last updated:** [July 7, 2022, 6:17pm UTC](https://discuss.elastic.co/t/drop-processors-on-yml-file/309109 "2022-07-07T18:17:07Z")

</div>

Hi, I am unable to use the following drop processors on yml processors: drop\_event.when: network: destination.ip: \['8.8.8.8/32', '8.8.4.4/32', '10.10.10.10/32'\]

---

## [Changing ownership of filebeat installtion from root](https://discuss.elastic.co/t/changing-ownership-of-filebeat-installtion-from-root/307521)

<div class="topic-metadata">

**Author:** [@navin1093](https://discuss.elastic.co/u/navin1093)\
**Replies:** 5\
**Last updated:** [July 7, 2022, 4:19pm UTC](https://discuss.elastic.co/t/changing-ownership-of-filebeat-installtion-from-root/307521 "2022-07-07T16:19:34Z")

</div>

Hi experts, I installed filebeat as root in my RedHat. We did using yum install filebeat-version.rpm. Now what happened is, when install, we did it as root user. I believe there is security risk by installing as root u…

---

## [Multiline events not parsed correctly](https://discuss.elastic.co/t/multiline-events-not-parsed-correctly/309123)

<div class="topic-metadata">

**Author:** [@DLP\_Admin](https://discuss.elastic.co/u/DLP_Admin)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 1:57pm UTC](https://discuss.elastic.co/t/multiline-events-not-parsed-correctly/309123 "2022-07-07T13:57:36Z")

</div>

We are trying to replace custom log parsing performed via Filebeat + Logstash by using the Elastic Agent + Fleet. We built and tested the Ingest Pipeline successfully, and set up the Fleet infrastructure. Reading the log…

---

## [Lofg file not getting picked up from filebeat](https://discuss.elastic.co/t/lofg-file-not-getting-picked-up-from-filebeat/309105)

<div class="topic-metadata">

**Author:** [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 12:26pm UTC](https://discuss.elastic.co/t/lofg-file-not-getting-picked-up-from-filebeat/309105 "2022-07-07T12:26:54Z")

</div>

Hello, Facing issue where log files are not getting picked up from filebeat in same dir. files - files1.log (this is not getting picked up) files-access.log (this file gets picked up) filebeat config filebeat.input…

---

## [How to integrate AWS Lambda with plugin Elastic](https://discuss.elastic.co/t/how-to-integrate-aws-lambda-with-plugin-elastic/306506)

<div class="topic-metadata">

**Author:** [@Renato\_Souza](https://discuss.elastic.co/u/Renato_Souza)\
**Replies:** 33\
**Last updated:** [July 7, 2022, 11:57am UTC](https://discuss.elastic.co/t/how-to-integrate-aws-lambda-with-plugin-elastic/306506 "2022-07-07T11:57:37Z")

</div>

I am using functions beat to get logs from aws lambda (cloudwatch). But, i know exists an integration ready for AWS Lambda at Browse all integrations in cloud Elastic. I don't find documentation how to use this integrati…

---

## [Metricbeat monitoring logstash via kubernetes service endpoint issues](https://discuss.elastic.co/t/metricbeat-monitoring-logstash-via-kubernetes-service-endpoint-issues/309064)

<div class="topic-metadata">

**Author:** [@aaronpjak](https://discuss.elastic.co/u/aaronpjak)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 1:59am UTC](https://discuss.elastic.co/t/metricbeat-monitoring-logstash-via-kubernetes-service-endpoint-issues/309064 "2022-07-07T01:59:18Z")

</div>

Hi, I am trying to use metricbeat to monitor my logstash instances. I have logstash deployed using the official helm chart and I am running multiple logstash pods behind the kubernetes service. When I use the service en…

---

## [Windows elastic-agent-8.2.3-windows-x86\_64](https://discuss.elastic.co/t/windows-elastic-agent-8-2-3-windows-x86-64/309056)

<div class="topic-metadata">

**Author:** [@mluer](https://discuss.elastic.co/u/mluer)\
**Replies:** 0\
**Last updated:** [July 6, 2022, 11:19pm UTC](https://discuss.elastic.co/t/windows-elastic-agent-8-2-3-windows-x86-64/309056 "2022-07-06T23:19:14Z")

</div>

I installed a previous version of this agent without issue. This agent has a problem with the installer and it creates an Agent Folder and copies the files, then creates another agent folder inside this one and copies i…

---

## [Auditd ingest pipeline with forwarded logs](https://discuss.elastic.co/t/auditd-ingest-pipeline-with-forwarded-logs/309054)

<div class="topic-metadata">

**Author:** [@parisila](https://discuss.elastic.co/u/parisila)\
**Replies:** 0\
**Last updated:** [July 6, 2022, 10:23pm UTC](https://discuss.elastic.co/t/auditd-ingest-pipeline-with-forwarded-logs/309054 "2022-07-06T22:23:37Z")

</div>

I have a central log server where all my audit logs are sent via rsyslog. I was running into an issue where the standard auditd ingest pipeline didn't properly parse the audit log because when it is sent from a remote h…

---

## [Winlogbeat Drop Event Processor No Longer Working After Update to v8](https://discuss.elastic.co/t/winlogbeat-drop-event-processor-no-longer-working-after-update-to-v8/309026)

<div class="topic-metadata">

**Author:** [@eafrost.cissp](https://discuss.elastic.co/u/eafrost.cissp)\
**Replies:** 0\
**Last updated:** [July 6, 2022, 3:05pm UTC](https://discuss.elastic.co/t/winlogbeat-drop-event-processor-no-longer-working-after-update-to-v8/309026 "2022-07-06T15:05:50Z")

</div>

Prior to updating my Elastic Stack to v8.2.0, the following winlogbeat drop event processor worked as expected. It only kept Windows Security log event.code 4688 events if the process.parent.name equaled cmd.exe or power…

---

## [8.2.3 Agent unhealthy, when "Network Packet Capture" integration is enabled in agent policy](https://discuss.elastic.co/t/8-2-3-agent-unhealthy-when-network-packet-capture-integration-is-enabled-in-agent-policy/307396)

<div class="topic-metadata">

**Author:** [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Replies:** 5\
**Last updated:** [July 6, 2022, 1:35pm UTC](https://discuss.elastic.co/t/8-2-3-agent-unhealthy-when-network-packet-capture-integration-is-enabled-in-agent-policy/307396 "2022-07-06T13:35:57Z")

</div>

I created a elastic cloud trial instance yesterday, but my Windows client is unhealthy. elastic-agent status output shows: Status: FAILED Message: (no message) Applications: \* osquerybeat (HEALTHY) …

---

## [Will Filebeat work on Rocky Linux?](https://discuss.elastic.co/t/will-filebeat-work-on-rocky-linux/308875)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 2\
**Last updated:** [July 6, 2022, 10:13am UTC](https://discuss.elastic.co/t/will-filebeat-work-on-rocky-linux/308875 "2022-07-06T10:13:21Z")

</div>

Hello, I'm looking for a way to get Filebeat to work on Rocky Linux. I have deployed Filebeat on several servers and have been collecting logs with ElasticSearch. This is the first time I would like to deploy Filebeat o…

---

## [Elastic Agent and AWS ECS](https://discuss.elastic.co/t/elastic-agent-and-aws-ecs/308859)

<div class="topic-metadata">

**Author:** [@Nick\_Bolten](https://discuss.elastic.co/u/Nick_Bolten)\
**Replies:** 1\
**Last updated:** [July 6, 2022, 9:56am UTC](https://discuss.elastic.co/t/elastic-agent-and-aws-ecs/308859 "2022-07-06T09:56:19Z")

</div>

Hi, I am trying to find a way to use Elastic Agent to monitor containers in AWS ECS. I did not manage to find any official guide by Elastic. Just wondering if anyone have done this before or know how to achieve this.

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=82)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=84)
