# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=87

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 88

---

## [Heartbeat won't be monitoring the subdomain URL's](https://discuss.elastic.co/t/heartbeat-wont-be-monitoring-the-subdomain-urls/306842)

<div class="topic-metadata">

**Author:** [@chanduprasad](https://discuss.elastic.co/u/chanduprasad)\
**Replies:** 2\
**Last updated:** [June 15, 2022, 1:18am UTC](https://discuss.elastic.co/t/heartbeat-wont-be-monitoring-the-subdomain-urls/306842 "2022-06-15T01:18:15Z")

</div>

Hi, I am trying to monitoring the https urls using heartbeat implementation. Am able to get the status of url is "UP" for full domain (https://grafana-test.com")url's but its showing always DOWN for the subdomain url's. …

---

## [Getting Could not communicate with fleet-server Checking API will retry with elastic agent + Squid proxy + Fleet setup](https://discuss.elastic.co/t/getting-could-not-communicate-with-fleet-server-checking-api-will-retry-with-elastic-agent-squid-proxy-fleet-setup/307113)

<div class="topic-metadata">

**Author:** [@Sarvesh\_Sharma](https://discuss.elastic.co/u/Sarvesh_Sharma)\
**Replies:** 0\
**Last updated:** [June 14, 2022, 8:24am UTC](https://discuss.elastic.co/t/getting-could-not-communicate-with-fleet-server-checking-api-will-retry-with-elastic-agent-squid-proxy-fleet-setup/307113 "2022-06-14T08:24:39Z")

</div>

We are running elastic agent in our own aws environment which connect to fleet hosted on elastic cloud via a squid proxy. While running the elastic agent, it is able to enroll with fleet successfully but then all of a s…

---

## [Beat service does not restart after "apt upgrade"](https://discuss.elastic.co/t/beat-service-does-not-restart-after-apt-upgrade/305145)

<div class="topic-metadata">

**Author:** [@mh\_xortex](https://discuss.elastic.co/u/mh_xortex)\
**Replies:** 3\
**Last updated:** [June 14, 2022, 11:15am UTC](https://discuss.elastic.co/t/beat-service-does-not-restart-after-apt-upgrade/305145 "2022-06-14T11:15:24Z")

</div>

"unattended upgrades " upgrade our beats (filebeat and metricbeat) but the beat services does not restarted.

---

## [Filebeat resends log files after restart](https://discuss.elastic.co/t/filebeat-resends-log-files-after-restart/303924)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 7\
**Last updated:** [June 14, 2022, 6:04am UTC](https://discuss.elastic.co/t/filebeat-resends-log-files-after-restart/303924 "2022-06-14T06:04:09Z")

</div>

Dear colleagues, I have an issue with Filebeat again - I've noticed that it resends the whole log files after restarting the application despite the log file stating that the registry file has been loaded successfully. …

---

## [Folder status can be monitored via ELK](https://discuss.elastic.co/t/folder-status-can-be-monitored-via-elk/304519)

<div class="topic-metadata">

**Author:** [@rajvel](https://discuss.elastic.co/u/rajvel)\
**Replies:** 5\
**Last updated:** [June 13, 2022, 11:21am UTC](https://discuss.elastic.co/t/folder-status-can-be-monitored-via-elk/304519 "2022-06-13T11:21:22Z")

</div>

Hello Team, I would like to monitor folder date and time change, looks like some of the files will be written on the folder, i want to monitor the parent folder date and time. Please advise.

---

## [Trying to add windows winlogbeat and the standard dashboards, but dashboards are empty](https://discuss.elastic.co/t/trying-to-add-windows-winlogbeat-and-the-standard-dashboards-but-dashboards-are-empty/306106)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 3\
**Last updated:** [June 13, 2022, 8:23am UTC](https://discuss.elastic.co/t/trying-to-add-windows-winlogbeat-and-the-standard-dashboards-but-dashboards-are-empty/306106 "2022-06-13T08:23:20Z")

</div>

Hi All After rebuilding the entire elastic stack to 7.16.3 currently, I wanted to expand the elastic to also monitor our windows servers. I have a winlogbeat config that looks like this: winlogbeat.event\_logs: - nam…

---

## [Manually upload Winlogbeat ndjson files to Elasticsearch](https://discuss.elastic.co/t/manually-upload-winlogbeat-ndjson-files-to-elasticsearch/306046)

<div class="topic-metadata">

**Author:** [@fl33t](https://discuss.elastic.co/u/fl33t)\
**Replies:** 6\
**Last updated:** [June 13, 2022, 2:54am UTC](https://discuss.elastic.co/t/manually-upload-winlogbeat-ndjson-files-to-elasticsearch/306046 "2022-06-13T02:54:39Z")

</div>

Greetings and salutations. I'm looking for a way to manually upload locally generated Winlogbeat (8.1.3) ndjson files to my Elastic stack as the beat has to work offline and cannot connect directly to either ES or Logsta…

---

## [Packetbeat no data but error Cannot index event publisher.Event](https://discuss.elastic.co/t/packetbeat-no-data-but-error-cannot-index-event-publisher-event/306946)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 0\
**Last updated:** [June 11, 2022, 8:04pm UTC](https://discuss.elastic.co/t/packetbeat-no-data-but-error-cannot-index-event-publisher-event/306946 "2022-06-11T20:04:13Z")

</div>

Dear All, I am running ELK 8.2.2 on Debian 11 bullseye and installed packetbeat 8.2.2. "packetbeat setup" brings no errors. And packetbeat test config Config OK packetbeat test output elasticsearch: https://kibana8.h…

---

## [Filebeat config for log group with wildcard for aws-cloudwatch?](https://discuss.elastic.co/t/filebeat-config-for-log-group-with-wildcard-for-aws-cloudwatch/306835)

<div class="topic-metadata">

**Author:** [@jrykowski-huron](https://discuss.elastic.co/u/jrykowski-huron)\
**Replies:** 2\
**Last updated:** [June 11, 2022, 4:29pm UTC](https://discuss.elastic.co/t/filebeat-config-for-log-group-with-wildcard-for-aws-cloudwatch/306835 "2022-06-11T16:29:37Z")

</div>

If set of CloudWatch log groups... example1.{guid} example2.{guid} example3.{guid} Is it possible to configure filebeat.inputs for aws-cloudwatch with a single entry using wildcard? Like for example set above with …

---

## [Can't use variables in containing a slash in elastic-agent configuration](https://discuss.elastic.co/t/cant-use-variables-in-containing-a-slash-in-elastic-agent-configuration/306902)

<div class="topic-metadata">

**Author:** [@antex](https://discuss.elastic.co/u/antex)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 3:39pm UTC](https://discuss.elastic.co/t/cant-use-variables-in-containing-a-slash-in-elastic-agent-configuration/306902 "2022-06-10T15:39:09Z")

</div>

I'm trying to define a condition in an elastic-agent configuration where the variable contains a slash, e.g.: streams: - id: \>- filestream-kubernetes.container\_logs-catchall d…

---

## [Filebeat's harvester cleanup method](https://discuss.elastic.co/t/filebeats-harvester-cleanup-method/306872)

<div class="topic-metadata">

**Author:** [@xiongjunkun](https://discuss.elastic.co/u/xiongjunkun)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 10:59am UTC](https://discuss.elastic.co/t/filebeats-harvester-cleanup-method/306872 "2022-06-10T10:59:57Z")

</div>

Ask a question, when Filebeat's harvester is executed, it will call the cleanup method. Why does it need to send an additional state: h.SendStateUpdate()? Is there something wrong with persisting state through events sen…

---

## [Redis: Error fetching metrics error determining cgroups version: error reading /proc/89458/cgroup](https://discuss.elastic.co/t/redis-error-fetching-metrics-error-determining-cgroups-version-error-reading-proc-89458-cgroup/306280)

<div class="topic-metadata">

**Author:** [@Duane\_DSouza](https://discuss.elastic.co/u/Duane_DSouza)\
**Replies:** 1\
**Last updated:** [June 10, 2022, 4:24am UTC](https://discuss.elastic.co/t/redis-error-fetching-metrics-error-determining-cgroups-version-error-reading-proc-89458-cgroup/306280 "2022-06-10T04:24:45Z")

</div>

Hi , I am trying to use metricbeat (version 8.1.2) module for Redis. Redis cluster is managed app.redislabs.com Here is the config: metricsets: \["info", "keyspace"\] hosts: \["redis-16058.internal.xxxxxxxxx.ec2.clo…

---

## [Start request repeated too quickly for filebeat.service](https://discuss.elastic.co/t/start-request-repeated-too-quickly-for-filebeat-service/305005)

<div class="topic-metadata">

**Author:** [@bd67](https://discuss.elastic.co/u/bd67)\
**Replies:** 4\
**Last updated:** [June 10, 2022, 1:43am UTC](https://discuss.elastic.co/t/start-request-repeated-too-quickly-for-filebeat-service/305005 "2022-06-10T01:43:35Z")

</div>

Hello All, I have several servers set up with Filebeat since few months , nothing changed in terms of config for any. Over the past few days I am observing 2 of these servers consistently failing to keep Filebeat servi…

---

## [How to concatenate two fields using add fields processor in filebeat](https://discuss.elastic.co/t/how-to-concatenate-two-fields-using-add-fields-processor-in-filebeat/306488)

<div class="topic-metadata">

**Author:** [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Replies:** 13\
**Last updated:** [June 9, 2022, 4:16pm UTC](https://discuss.elastic.co/t/how-to-concatenate-two-fields-using-add-fields-processor-in-filebeat/306488 "2022-06-09T16:16:45Z")

</div>

I have 2 fields with one field carrying date value and another field carrying time value. I would like to have a single field with both date and time values concatenated. Could you please suggest?

---

## [Packetbeat flooding logs with FindSocketsOfPid errors when on system with short living processes](https://discuss.elastic.co/t/packetbeat-flooding-logs-with-findsocketsofpid-errors-when-on-system-with-short-living-processes/306802)

<div class="topic-metadata">

**Author:** [@Christos\_Arvanitis](https://discuss.elastic.co/u/Christos_Arvanitis)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 1:39pm UTC](https://discuss.elastic.co/t/packetbeat-flooding-logs-with-findsocketsofpid-errors-when-on-system-with-short-living-processes/306802 "2022-06-09T13:39:44Z")

</div>

Hello, Due to the error logging here, on systems running many short living processes, we realized that packetbeat is flooding logs with entries like the following: {"log.level":"error","@timestamp":"2022-06-09T15:25:57…

---

## [Cannot index event publisher.Event](https://discuss.elastic.co/t/cannot-index-event-publisher-event/306420)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 1\
**Last updated:** [June 9, 2022, 8:44am UTC](https://discuss.elastic.co/t/cannot-index-event-publisher-event/306420 "2022-06-09T08:44:07Z")

</div>

Hi there, I got this setup using misp integration with elastic-agent and looks fine apart from there´s no data on the dashboard page. I can see on the data stream that indeed data is coming but no parsed? Maybe?: And…

---

## [Filebeat setup](https://discuss.elastic.co/t/filebeat-setup/306695)

<div class="topic-metadata">

**Author:** [@kaul.abhishek1993](https://discuss.elastic.co/u/kaul.abhishek1993)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 11:43pm UTC](https://discuss.elastic.co/t/filebeat-setup/306695 "2022-06-08T23:43:22Z")

</div>

Hello Team, i am running setup for filebeat on haproxy node. For DB nodes i am connecting to kibana with url http://prodkibana.oodi.iq:80 and its successfull but with haproxy its failing with error " Jun 08 15:15:57 ORY…

---

## [Filebeat and GLIBC Errors on Ubuntu 22.04](https://discuss.elastic.co/t/filebeat-and-glibc-errors-on-ubuntu-22-04/306653)

<div class="topic-metadata">

**Author:** [@mibeyki](https://discuss.elastic.co/u/mibeyki)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 8:13pm UTC](https://discuss.elastic.co/t/filebeat-and-glibc-errors-on-ubuntu-22-04/306653 "2022-06-08T20:13:26Z")

</div>

Hello, We just deployed filebeat both Ubuntu 22.04 server and Ubuntu 22.04 desktop. However, we cannot be able to get Filebeat connect to Elasticsearch. Both versions of Filebeat and ES is 7.10.1; When you run; file…

---

## [Reverse DNS processor multiple nameservers problem](https://discuss.elastic.co/t/reverse-dns-processor-multiple-nameservers-problem/306704)

<div class="topic-metadata">

**Author:** [@unknotted-evacuee](https://discuss.elastic.co/u/unknotted-evacuee)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 1:56pm UTC](https://discuss.elastic.co/t/reverse-dns-processor-multiple-nameservers-problem/306704 "2022-06-08T13:56:48Z")

</div>

Hey filebeat version 8.0.1 I'm suspecting a problem with using multiple namespaces for the DNS processor. My config looks like this (with dummy ip addresses, and I was testing with a low ttl in failure\_cache): …

---

## [Connect Metricbeat to Elasticsearch 8.2.0 with password mode](https://discuss.elastic.co/t/connect-metricbeat-to-elasticsearch-8-2-0-with-password-mode/306311)

<div class="topic-metadata">

**Author:** [@Dreinale](https://discuss.elastic.co/u/Dreinale)\
**Replies:** 13\
**Last updated:** [June 8, 2022, 3:23pm UTC](https://discuss.elastic.co/t/connect-metricbeat-to-elasticsearch-8-2-0-with-password-mode/306311 "2022-06-08T15:23:49Z")

</div>

HI, I'm trying to connect metricbeat to my elasticsearch which I have configured yesterday with a password mode. (https://www.youtube.com/watch?v=kkrLanotz1I&t=461s). I have 2 users one is for elasticsearch (elastic) …

---

## [Kubernetes Application Logs to App Specific Indexes](https://discuss.elastic.co/t/kubernetes-application-logs-to-app-specific-indexes/306670)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 9:49am UTC](https://discuss.elastic.co/t/kubernetes-application-logs-to-app-specific-indexes/306670 "2022-06-08T09:49:46Z")

</div>

We have filebeat collecting logs in kubernetes. We use a data view that is created to view these logs filebeat-\*. Using the filebeat indexes to search our logs has been working fine up until now, but now we are starti…

---

## [Testing DNS Performance](https://discuss.elastic.co/t/testing-dns-performance/306652)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 8:26am UTC](https://discuss.elastic.co/t/testing-dns-performance/306652 "2022-06-08T08:26:56Z")

</div>

I've installed packetbeat on a windows dns server to try and get some insight into requests and performance Is there anything specific I should be looking at from the dashboard to find out if there are issues I'm looki…

---

## [How to secure Beat communication to Elasticsearch](https://discuss.elastic.co/t/how-to-secure-beat-communication-to-elasticsearch/306538)

<div class="topic-metadata">

**Author:** [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 3:30am UTC](https://discuss.elastic.co/t/how-to-secure-beat-communication-to-elasticsearch/306538 "2022-06-08T03:30:59Z")

</div>

Hello everyone, i've got the following Setup: 3 Node Cluster OS: RedHat 8.6 Kibana: 7.17 Elasticsearch: 7.17 Winlogbeat/Filebeat: 7.17 So i've followed the "Secure your Cluster"-Guides provided: Minimal: Basic: …

---

## [The value in this field is too long and can't be searched or filtered](https://discuss.elastic.co/t/the-value-in-this-field-is-too-long-and-cant-be-searched-or-filtered/306597)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 0\
**Last updated:** [June 7, 2022, 6:18pm UTC](https://discuss.elastic.co/t/the-value-in-this-field-is-too-long-and-cant-be-searched-or-filtered/306597 "2022-06-07T18:18:49Z")

</div>

Hi Team, I am using ingest pipeline for dissect and i have given a pattern as %{key1} %{key2} which is working fine. But the i am unable to use the key1 and key2 for dashboard as it a ignore value warning is comming wh…

---

## [Filebeat log with no new line character](https://discuss.elastic.co/t/filebeat-log-with-no-new-line-character/306591)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 0\
**Last updated:** [June 7, 2022, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-log-with-no-new-line-character/306591 "2022-06-07T16:15:53Z")

</div>

Hi All, Wanted to know is their any way to use filebeat to harvest logs from a file which has only single line and with no new line character. I know harvester need a new line character to read the logs but do we have …

---

## [Anomali threat intel dashboard not populating](https://discuss.elastic.co/t/anomali-threat-intel-dashboard-not-populating/306496)

<div class="topic-metadata">

**Author:** [@Charles\_Allen](https://discuss.elastic.co/u/Charles_Allen)\
**Replies:** 3\
**Last updated:** [June 7, 2022, 2:40am UTC](https://discuss.elastic.co/t/anomali-threat-intel-dashboard-not-populating/306496 "2022-06-07T02:40:05Z")

</div>

Hello, I am trying to see Anomali threat intel data in kibana but the dashboard is just empty. I am running Elasticsearch 7.17.4 I have uncommented the anomali guest account and password. I am seeing results within …

---

## [Metricbeat aws module cant collect s3\_dailystorage metrics](https://discuss.elastic.co/t/metricbeat-aws-module-cant-collect-s3-dailystorage-metrics/306512)

<div class="topic-metadata">

**Author:** [@desluk](https://discuss.elastic.co/u/desluk)\
**Replies:** 0\
**Last updated:** [June 7, 2022, 2:16am UTC](https://discuss.elastic.co/t/metricbeat-aws-module-cant-collect-s3-dailystorage-metrics/306512 "2022-06-07T02:16:29Z")

</div>

Hi mate, I'm trying to collect the ec2, lambda, s3\_dailystorage via the aws module, ec2 and lambda are fine, but no s3 data can be collected. Below is my AWS module config: - module: aws period: 300s regions: …

---

## [Monitoring .NET Core EventCounters with Metricbeat or Filebeat?](https://discuss.elastic.co/t/monitoring-net-core-eventcounters-with-metricbeat-or-filebeat/306414)

<div class="topic-metadata">

**Author:** [@Inammathe\_Inna](https://discuss.elastic.co/u/Inammathe_Inna)\
**Replies:** 0\
**Last updated:** [June 5, 2022, 10:19pm UTC](https://discuss.elastic.co/t/monitoring-net-core-eventcounters-with-metricbeat-or-filebeat/306414 "2022-06-05T22:19:48Z")

</div>

Hi guys, So apparently .NET Core on Windows no longer writes to the metricset perfmon. It instead uses EventCounters - EventCounters in .NET Core | Microsoft Docs Has anybody found an elegant way to send these metrics…

---

## [Unable to monitor URL in heartbeat](https://discuss.elastic.co/t/unable-to-monitor-url-in-heartbeat/306453)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 1\
**Last updated:** [June 6, 2022, 11:49pm UTC](https://discuss.elastic.co/t/unable-to-monitor-url-in-heartbeat/306453 "2022-06-06T23:49:28Z")

</div>

I am trying to add below URL in heartbeat but it is giving error like 401 Authentication requested or 403 Forbidden I am missing anything? - type: http urls: \["http://myurl.net:9000"\] username: abcd password: #ab…

---

## [Error installing Fleet Server](https://discuss.elastic.co/t/error-installing-fleet-server/306216)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 4\
**Last updated:** [June 6, 2022, 6:54pm UTC](https://discuss.elastic.co/t/error-installing-fleet-server/306216 "2022-06-06T18:54:47Z")

</div>

Hi, My setup: Elasticsearch 8.1.0, Kibana 8.1.0, Elastic Agent 8.1.0 Downloaded elastic agent on my windows machine. Ran the following command: elastic-agent.exe install --fleet-server-es=https://localhost:9200 --fl…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=86)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=88)
