# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=88

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 89

---

## [Unable to load software.log into elasticsearch](https://discuss.elastic.co/t/unable-to-load-software-log-into-elasticsearch/306309)

<div class="topic-metadata">

**Author:** [@Chandrapaul](https://discuss.elastic.co/u/Chandrapaul)\
**Replies:** 7\
**Last updated:** [June 6, 2022, 3:18pm UTC](https://discuss.elastic.co/t/unable-to-load-software-log-into-elasticsearch/306309 "2022-06-06T15:18:49Z")

</div>

I'm trying to load software logs from zeek into Elasticsearch. But if I run filebeat after adding software log path to zeek.yml in filebeat then I'm getting error : "Exiting: Failed to start crawler: creating module re…

---

## [How to decode html file in heartbeat/filebeat](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232)

<div class="topic-metadata">

**Author:** [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Replies:** 5\
**Last updated:** [June 2, 2022, 6:33pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232 "2022-06-02T18:33:32Z")

</div>

Hi All, I have tried decoding XML file using decode\_xml processor in both heartbeat and filebeat and it worked as expected. Now I would like to decode html file. I didn't find a way to do that. Could you please sugges…

---

## [Metricbeat dosen't show metrics on Kibana](https://discuss.elastic.co/t/metricbeat-dosent-show-metrics-on-kibana/306448)

<div class="topic-metadata">

**Author:** [@alexander2](https://discuss.elastic.co/u/alexander2)\
**Replies:** 0\
**Last updated:** [June 6, 2022, 12:37pm UTC](https://discuss.elastic.co/t/metricbeat-dosent-show-metrics-on-kibana/306448 "2022-06-06T12:37:33Z")

</div>

Hello everyone, i'm having trouble seeing the metrics on my kibana dashboard. I have ELK deployed on my kubernetes cluster and a remote virtual machine (centos 8) which i installed metricbeat. i changed the output to lo…

---

## [Filebeat stopping randomly - Any way to send an email when logs are incomplete?](https://discuss.elastic.co/t/filebeat-stopping-randomly-any-way-to-send-an-email-when-logs-are-incomplete/306436)

<div class="topic-metadata">

**Author:** [@LionsELK](https://discuss.elastic.co/u/LionsELK)\
**Replies:** 0\
**Last updated:** [June 6, 2022, 9:20am UTC](https://discuss.elastic.co/t/filebeat-stopping-randomly-any-way-to-send-an-email-when-logs-are-incomplete/306436 "2022-06-06T09:20:09Z")

</div>

Hi all, Filebeat randomly stops running and we need to restart it with the filebeat command to check and pull any necessary records but is there a way I can set up ELK to notify me via email if there's any gaps in the r…

---

## [Split single line log into multiple line log using filebeat](https://discuss.elastic.co/t/split-single-line-log-into-multiple-line-log-using-filebeat/306021)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [June 6, 2022, 8:56am UTC](https://discuss.elastic.co/t/split-single-line-log-into-multiple-line-log-using-filebeat/306021 "2022-06-06T08:56:13Z")

</div>

Hi All, I have a single long line and i wanted to split the single log line into multiple line. Example Here I want to skip the log whenever E2ETRACEEVENT comes So the output should be like: Let me know if we …

---

## [Filebeat not picking up some files](https://discuss.elastic.co/t/filebeat-not-picking-up-some-files/306386)

<div class="topic-metadata">

**Author:** [@ShefZee](https://discuss.elastic.co/u/ShefZee)\
**Replies:** 1\
**Last updated:** [June 5, 2022, 8:01am UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-some-files/306386 "2022-06-05T08:01:51Z")

</div>

I am trying to send tomcat logs to ELK. I am using Filebeat to scan the files. My log file name would be "project\_err.DD-MM-YYYY". In filebeat configuration, I am giving the file name as foldername\\project\_err\* But fileb…

---

## [Parsing fortigate logs with filebeat modules](https://discuss.elastic.co/t/parsing-fortigate-logs-with-filebeat-modules/306391)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 0\
**Last updated:** [June 4, 2022, 8:54pm UTC](https://discuss.elastic.co/t/parsing-fortigate-logs-with-filebeat-modules/306391 "2022-06-04T20:54:35Z")

</div>

Hello, I have never used filebeat for parsing the fortigate logs. I have consulted several pages on the internet about this. I concluded that the best approach is to install Filebeat at the logstash server, after acti…

---

## [Filebeat - Update Index Template and create new index](https://discuss.elastic.co/t/filebeat-update-index-template-and-create-new-index/306003)

<div class="topic-metadata">

**Author:** [@Hardik\_Sanghavi](https://discuss.elastic.co/u/Hardik_Sanghavi)\
**Replies:** 3\
**Last updated:** [June 4, 2022, 11:41am UTC](https://discuss.elastic.co/t/filebeat-update-index-template-and-create-new-index/306003 "2022-06-04T11:41:16Z")

</div>

Hello, I am new to Filebeat. I used the standard configuration setup for filebeat and got it to ship data to Elasticsearch. I have added some custom fields and they automatically got the "keyword" type. I changed the…

---

## [Filebeat service is not starting in debian docker image](https://discuss.elastic.co/t/filebeat-service-is-not-starting-in-debian-docker-image/306340)

<div class="topic-metadata">

**Author:** [@Kumar\_Nikhil](https://discuss.elastic.co/u/Kumar_Nikhil)\
**Replies:** 0\
**Last updated:** [June 3, 2022, 1:08pm UTC](https://discuss.elastic.co/t/filebeat-service-is-not-starting-in-debian-docker-image/306340 "2022-06-03T13:08:07Z")

</div>

We are trying to install filebeat in debian docker image. NAME="Debian GNU/Linux" VERSION\_ID="9" VERSION="9 (stretch)" ID=debian HOME\_URL=" Its successfully building the image. But when we run the image and check f…

---

## [Filebeat harvest logs from encyrpted file](https://discuss.elastic.co/t/filebeat-harvest-logs-from-encyrpted-file/306025)

<div class="topic-metadata">

**Author:** [@florinsfetea](https://discuss.elastic.co/u/florinsfetea)\
**Replies:** 2\
**Last updated:** [June 3, 2022, 12:53pm UTC](https://discuss.elastic.co/t/filebeat-harvest-logs-from-encyrpted-file/306025 "2022-06-03T12:53:39Z")

</div>

Hello people, how would one go about collecting logs from an encrypted log file that has to be first decrypted I have some /var/log/my\_encrypted\_log.log to read this I have to pipe the contents to an binary that decry…

---

## [Can Auditbeat file integrity module detect unmount and mount of CIFS filesystem](https://discuss.elastic.co/t/can-auditbeat-file-integrity-module-detect-unmount-and-mount-of-cifs-filesystem/306336)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 0\
**Last updated:** [June 3, 2022, 12:52pm UTC](https://discuss.elastic.co/t/can-auditbeat-file-integrity-module-detect-unmount-and-mount-of-cifs-filesystem/306336 "2022-06-03T12:52:23Z")

</div>

Hi Community, Can I use the Auditbeat file integrity module to detect if a share (Windows and CIFS) is mounted and unmounted? Any risc of Auditbeat to block unmounting the share? Best regards Flemming

---

## [Configure beats to reload certificates?](https://discuss.elastic.co/t/configure-beats-to-reload-certificates/305976)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 2\
**Last updated:** [June 3, 2022, 6:25am UTC](https://discuss.elastic.co/t/configure-beats-to-reload-certificates/305976 "2022-06-03T06:25:05Z")

</div>

We deploy most beattypes to hosts managed by different service providers. The beats ships data to Logstash beats endpoints protected with TLS and firewalls. This setup works very well. However, changing expired TLS cert…

---

## [Filebeat multiline json](https://discuss.elastic.co/t/filebeat-multiline-json/306287)

<div class="topic-metadata">

**Author:** [@Panda\_Free](https://discuss.elastic.co/u/Panda_Free)\
**Replies:** 0\
**Last updated:** [June 3, 2022, 6:03am UTC](https://discuss.elastic.co/t/filebeat-multiline-json/306287 "2022-06-03T06:03:28Z")

</div>

Hi, please help, spent more one week and cannot get correct parse settings. I have file from AWS Athena query, csv, but coverted to pure multiline json. Structure: \[{ "useridentity":"{type=somevalue={attributes={…

---

## [Multiple Heartbeat In One Windows Server](https://discuss.elastic.co/t/multiple-heartbeat-in-one-windows-server/306249)

<div class="topic-metadata">

**Author:** [@Nicole1](https://discuss.elastic.co/u/Nicole1)\
**Replies:** 6\
**Last updated:** [June 2, 2022, 10:47pm UTC](https://discuss.elastic.co/t/multiple-heartbeat-in-one-windows-server/306249 "2022-06-02T22:47:57Z")

</div>

can we have multiple heartbeats in one windows server because we want to monitor 3 different series of endpoints(appcodes).with 3 different heartbeat.yml

---

## [Create 2 versions of the same index (one with less fields)](https://discuss.elastic.co/t/create-2-versions-of-the-same-index-one-with-less-fields/305506)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 9\
**Last updated:** [June 2, 2022, 5:46pm UTC](https://discuss.elastic.co/t/create-2-versions-of-the-same-index-one-with-less-fields/305506 "2022-06-02T17:46:56Z")

</div>

Hello, I have the requirement of ingesting metricbeat/filebeat data twice, once with all the default fields, and a second time with only the fields the dashboards will be using. This two versions will have different re…

---

## [Filebeat exclude\_files is not working as expected](https://discuss.elastic.co/t/filebeat-exclude-files-is-not-working-as-expected/305995)

<div class="topic-metadata">

**Author:** [@omeryosef](https://discuss.elastic.co/u/omeryosef)\
**Replies:** 6\
**Last updated:** [June 2, 2022, 9:29am UTC](https://discuss.elastic.co/t/filebeat-exclude-files-is-not-working-as-expected/305995 "2022-06-02T09:29:58Z")

</div>

Hi everyone, I have the following structure of directories and I am trying to avoid duplications by excluding "current" dir: # ls -l total 12 drwxrwxr-x 11 node node 4096 May 25 10:42 3.123.0 drwxrwxr-x 11 node node 40…

---

## [Resource metricbeat-7.17.1 exists, but it is not an alias](https://discuss.elastic.co/t/resource-metricbeat-7-17-1-exists-but-it-is-not-an-alias/306030)

<div class="topic-metadata">

**Author:** [@Evgeny\_Barykin](https://discuss.elastic.co/u/Evgeny_Barykin)\
**Replies:** 6\
**Last updated:** [June 2, 2022, 7:49am UTC](https://discuss.elastic.co/t/resource-metricbeat-7-17-1-exists-but-it-is-not-an-alias/306030 "2022-06-02T07:49:12Z")

</div>

Hello! I have an issue with connecting second cluster to Elasticsearch. I changed dynamic mappings and added best\_compression to the settings, but now I get an error every time I try to connect new beats to it. If I le…

---

## [Trying to build grok pattern for impossible logfile fetched with filebeat sent to logstash](https://discuss.elastic.co/t/trying-to-build-grok-pattern-for-impossible-logfile-fetched-with-filebeat-sent-to-logstash/306192)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 0\
**Last updated:** [June 2, 2022, 7:10am UTC](https://discuss.elastic.co/t/trying-to-build-grok-pattern-for-impossible-logfile-fetched-with-filebeat-sent-to-logstash/306192 "2022-06-02T07:10:33Z")

</div>

I've gotten this logfile from UNICA by IBM. It's impossible :slight\_smile: A few lines of example. 18 feb 2016 10:37:46,292 - ERROR - An error occured while scanning for the next trigger to fire. org.quartz.JobPersiste…

---

## [Custom beat to monitor a file in a server folder is possible?](https://discuss.elastic.co/t/custom-beat-to-monitor-a-file-in-a-server-folder-is-possible/306142)

<div class="topic-metadata">

**Author:** [@dannie-ml](https://discuss.elastic.co/u/dannie-ml)\
**Replies:** 2\
**Last updated:** [June 2, 2022, 12:50am UTC](https://discuss.elastic.co/t/custom-beat-to-monitor-a-file-in-a-server-folder-is-possible/306142 "2022-06-02T00:50:17Z")

</div>

I have a doubt in making a custom beat that reads or monitors the state of a file, example: In a server, a file is within the Inbound folder if stays the file for more than 5 minutes in this folder and doesnt move to th…

---

## [Type usage in libbeat/outputs/elasticsearch/client causes issue on OpenSearch 2.0+ engine](https://discuss.elastic.co/t/type-usage-in-libbeat-outputs-elasticsearch-client-causes-issue-on-opensearch-2-0-engine/306166)

<div class="topic-metadata">

**Author:** [@Suraj\_Singh](https://discuss.elastic.co/u/Suraj_Singh)\
**Replies:** 2\
**Last updated:** [June 1, 2022, 9:40pm UTC](https://discuss.elastic.co/t/type-usage-in-libbeat-outputs-elasticsearch-client-causes-issue-on-opensearch-2-0-engine/306166 "2022-06-01T21:40:44Z")

</div>

With \_type removal in OpenSearch 2.0+ (previously deprecated in Elasticsearch 7.x); beat still uses \_type as DocType while building BulkRequest meta data; resulting in illegal\_argument\_exception from OpenSearch engine. E…

---

## [Monitor per Core w/ Metricbeat](https://discuss.elastic.co/t/monitor-per-core-w-metricbeat/306139)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 0\
**Last updated:** [June 1, 2022, 2:15pm UTC](https://discuss.elastic.co/t/monitor-per-core-w-metricbeat/306139 "2022-06-01T14:15:18Z")

</div>

I am needing to monitor processes running per CPU core using Metricbeat. I currently have the the windows.yml module configured with the perfmon metricset, however it is only showing the overall CPU and I'm needing to se…

---

## [Keep restarting Filebeat, Filebeat will lose some log](https://discuss.elastic.co/t/keep-restarting-filebeat-filebeat-will-lose-some-log/306138)

<div class="topic-metadata">

**Author:** [@xiongjunkun](https://discuss.elastic.co/u/xiongjunkun)\
**Replies:** 0\
**Last updated:** [June 1, 2022, 2:13pm UTC](https://discuss.elastic.co/t/keep-restarting-filebeat-filebeat-will-lose-some-log/306138 "2022-06-01T14:13:57Z")

</div>

I'm testing Filebeat 7.12.0 for possible loss of logs, my input configuration is as follows: - type: log enabled: true paths: -/xxx/xxx.log I also wrote a python program: write 50,000 logs, and sleep for 1~2 se…

---

## [Filebeat json parser is trying to parse excluded lines](https://discuss.elastic.co/t/filebeat-json-parser-is-trying-to-parse-excluded-lines/304674)

<div class="topic-metadata">

**Author:** [@dosmanak](https://discuss.elastic.co/u/dosmanak)\
**Replies:** 5\
**Last updated:** [June 1, 2022, 8:56am UTC](https://discuss.elastic.co/t/filebeat-json-parser-is-trying-to-parse-excluded-lines/304674 "2022-06-01T08:56:07Z")

</div>

filebeat log is filled with errors "Error decoding JSON: invalid character" filebeat.yml --- filebeat.inputs: - type: filestream id: 0 paths: - '/data/mixed\_json\_plain.log' exclude\_lines: \[ "^PLAIN"…

---

## [DNS lookup failure "elasticsearch"](https://discuss.elastic.co/t/dns-lookup-failure-elasticsearch/305939)

<div class="topic-metadata">

**Author:** [@kosmylo](https://discuss.elastic.co/u/kosmylo)\
**Replies:** 6\
**Last updated:** [June 1, 2022, 3:41am UTC](https://discuss.elastic.co/t/dns-lookup-failure-elasticsearch/305939 "2022-06-01T03:41:36Z")

</div>

I have a simple express app with Nginx and I use Filebeat with ELK stack. Filebeat takes in charge of streaming log file from Nginx to Logstash then processing it and visualize to Kibana. This pipeline works fine. Howeve…

---

## [Elastic agent on Raspberry Pi](https://discuss.elastic.co/t/elastic-agent-on-raspberry-pi/305182)

<div class="topic-metadata">

**Author:** [@l3keboy](https://discuss.elastic.co/u/l3keboy)\
**Replies:** 15\
**Last updated:** [May 31, 2022, 6:55pm UTC](https://discuss.elastic.co/t/elastic-agent-on-raspberry-pi/305182 "2022-05-31T18:55:39Z")

</div>

Hello All! I am trying to install the elastic agent to a raspberry pi and trying to enroll it onto our fleet server. When trying to install the agent I get the error: ./elastic-agent: 1: Syntax error: word unexpected (…

---

## [Filebeat sending a json file to stdout but filebeat errors "Error decoding JSON: invalid character" for the stdout logs](https://discuss.elastic.co/t/filebeat-sending-a-json-file-to-stdout-but-filebeat-errors-error-decoding-json-invalid-character-for-the-stdout-logs/305989)

<div class="topic-metadata">

**Author:** [@Adrian\_Romero](https://discuss.elastic.co/u/Adrian_Romero)\
**Replies:** 1\
**Last updated:** [May 31, 2022, 1:54pm UTC](https://discuss.elastic.co/t/filebeat-sending-a-json-file-to-stdout-but-filebeat-errors-error-decoding-json-invalid-character-for-the-stdout-logs/305989 "2022-05-31T13:54:31Z")

</div>

Hi people! here is the deal, I using k8s, my apps write down thier logs into a json formatted file, so I decided to send this file to the stdout (with a soft link kind of how nginx does it), so now if you check the stdou…

---

## [Filebeat suricata](https://discuss.elastic.co/t/filebeat-suricata/305863)

<div class="topic-metadata">

**Author:** [@TARIK\_MAZOUZ](https://discuss.elastic.co/u/TARIK_MAZOUZ)\
**Replies:** 9\
**Last updated:** [May 31, 2022, 1:52pm UTC](https://discuss.elastic.co/t/filebeat-suricata/305863 "2022-05-31T13:52:44Z")

</div>

hey ELK STACK community, please i've installed filebeat , and i wanted to install suricata module, so i've did install it, the problem is i don't get any information in kibana from suricata ? did i've missed something or…

---

## [Create new indices on each Beats update](https://discuss.elastic.co/t/create-new-indices-on-each-beats-update/306016)

<div class="topic-metadata">

**Author:** [@queried1](https://discuss.elastic.co/u/queried1)\
**Replies:** 0\
**Last updated:** [May 31, 2022, 8:59am UTC](https://discuss.elastic.co/t/create-new-indices-on-each-beats-update/306016 "2022-05-31T08:59:08Z")

</div>

Hello! I have an ELK cluster, the topology is quite simple: Linux\_host -\> Logstash\_node -\> Elasticsearch\_nde Each Linux\_host has filebeat+auditbeat installed and sends data to the Logstash\_node. The Logstash\_node rec…

---

## [Unable to parse svclog using filbeat](https://discuss.elastic.co/t/unable-to-parse-svclog-using-filbeat/305778)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 4\
**Last updated:** [May 31, 2022, 7:52am UTC](https://discuss.elastic.co/t/unable-to-parse-svclog-using-filbeat/305778 "2022-05-31T07:52:14Z")

</div>

Hi Team, I am unable to parse the svclog ( a XML family) using Filebeat. Please suggest how i can par

---

## [Functionbeat unable to export cloudwatch logs to elastic](https://discuss.elastic.co/t/functionbeat-unable-to-export-cloudwatch-logs-to-elastic/305927)

<div class="topic-metadata">

**Author:** [@rishabhtryroll](https://discuss.elastic.co/u/rishabhtryroll)\
**Replies:** 2\
**Last updated:** [May 31, 2022, 7:16am UTC](https://discuss.elastic.co/t/functionbeat-unable-to-export-cloudwatch-logs-to-elastic/305927 "2022-05-31T07:16:51Z")

</div>

I am using function beat to export cloud watch logs to elastic but got no data in the indices. Followed that doc https://www.elastic.co/guide/en/beats/functionbeat/current/functionbeat-installation-configuration.html T…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=87)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=89)
