# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=90

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 91

---

## [Metricbeat php\_fpm read sockets multiple pools](https://discuss.elastic.co/t/metricbeat-php-fpm-read-sockets-multiple-pools/305340)

<div class="topic-metadata">

**Author:** [@rbos](https://discuss.elastic.co/u/rbos)\
**Replies:** 0\
**Last updated:** [May 22, 2022, 1:17am UTC](https://discuss.elastic.co/t/metricbeat-php-fpm-read-sockets-multiple-pools/305340 "2022-05-22T01:17:21Z")

</div>

Hi, I have php-fpm installed on servers configured with multiple pools; I've set them to point to unix socket files, instead of HTTP, so like in the php-fpm.d files: listen = /var/run/php-fpm/php-fpm-web.sock I can fa…

---

## [How fast can Filebeat send logs from disk?](https://discuss.elastic.co/t/how-fast-can-filebeat-send-logs-from-disk/305295)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 1\
**Last updated:** [May 20, 2022, 3:03pm UTC](https://discuss.elastic.co/t/how-fast-can-filebeat-send-logs-from-disk/305295 "2022-05-20T15:03:53Z")

</div>

Filebeat 7.17 sending over the network to Logstash 6 (we're looking to get it upgraded) running on CentOS 7, 64GB RAM, 2 x 14 core Intel Xeon E5-2690. We've got some logs which often total as much as ~1.4b single line …

---

## [Heartbeat: response code in case of error](https://discuss.elastic.co/t/heartbeat-response-code-in-case-of-error/304493)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 6\
**Last updated:** [May 20, 2022, 1:14pm UTC](https://discuss.elastic.co/t/heartbeat-response-code-in-case-of-error/304493 "2022-05-20T13:14:08Z")

</div>

Hi, I am using heartbeat 6.4.0. I can see that in case of successful connection, unauthorized access, not found it returns http.response.status\_code as 200, 401, 404 respectively. But, in case of errors like below ther…

---

## [Integration Misp using Filebeat](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229)

<div class="topic-metadata">

**Author:** [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Replies:** 4\
**Last updated:** [May 20, 2022, 12:38pm UTC](https://discuss.elastic.co/t/integration-misp-using-filebeat/305229 "2022-05-20T12:38:02Z")

</div>

Hi there, I´m trying to integrate MISP using the documentation using filebeat but no go. I´ve tried both (Misp module and Threatintel module) and none of them gets into ELK Stack. Follow the errors from filebeat journa…

---

## [Multiple beats are not sharing the same data path](https://discuss.elastic.co/t/multiple-beats-are-not-sharing-the-same-data-path/305280)

<div class="topic-metadata">

**Author:** [@Rajesh119](https://discuss.elastic.co/u/Rajesh119)\
**Replies:** 1\
**Last updated:** [May 20, 2022, 11:00am UTC](https://discuss.elastic.co/t/multiple-beats-are-not-sharing-the-same-data-path/305280 "2022-05-20T11:00:15Z")

</div>

Iam new to ELK. Can You please anyone help regarding this issue. filebeat -e -c /etc/filebeat/filebeat.yml {"log.level":"info","@timestamp":"2022-05-20T10:43:40.450Z","log.origin":{"file.name":"instance/beat.go","fil…

---

## [Metricbeat-credential alternatives](https://discuss.elastic.co/t/metricbeat-credential-alternatives/305255)

<div class="topic-metadata">

**Author:** [@sadik](https://discuss.elastic.co/u/sadik)\
**Replies:** 0\
**Last updated:** [May 20, 2022, 6:16am UTC](https://discuss.elastic.co/t/metricbeat-credential-alternatives/305255 "2022-05-20T06:16:53Z")

</div>

Hi Team, In "metricbeat.modules:" session we are using the "AWS\_ACCESS\_KEY\_ID" and "AWS\_SECRET\_ACCESS\_KEY" to estrablish the connection from AWS module(metricset:"lambda") to connecting to kubernetes cluster and getti…

---

## [How to set the Time Zone in filebeat logstash and apm config](https://discuss.elastic.co/t/how-to-set-the-time-zone-in-filebeat-logstash-and-apm-config/305251)

<div class="topic-metadata">

**Author:** [@zhanghao116560](https://discuss.elastic.co/u/zhanghao116560)\
**Replies:** 1\
**Last updated:** [May 20, 2022, 4:22am UTC](https://discuss.elastic.co/t/how-to-set-the-time-zone-in-filebeat-logstash-and-apm-config/305251 "2022-05-20T04:22:19Z")

</div>

hi all: How to Set the Time Zone in filebeat, logstash, apm config file like '%{+yyyy.MM.dd}' like that I want to set the time zone for '%{+yyyy.MM.dd}' index: "apm-%{\[observer.version\]}-%{+yyyy.MM.dd}" indices: …

---

## [Netflow fields not showing in Discovery](https://discuss.elastic.co/t/netflow-fields-not-showing-in-discovery/305234)

<div class="topic-metadata">

**Author:** [@PraveenKT](https://discuss.elastic.co/u/PraveenKT)\
**Replies:** 3\
**Last updated:** [May 20, 2022, 2:37am UTC](https://discuss.elastic.co/t/netflow-fields-not-showing-in-discovery/305234 "2022-05-20T02:37:18Z")

</div>

Filebeat 8.2 is using. I am unable to see the netflow fields in the Discovery. But i am seeeing in "data views". What is the reason?

---

## [Filebeat run at startup](https://discuss.elastic.co/t/filebeat-run-at-startup/304802)

<div class="topic-metadata">

**Author:** [@Bigboy0706](https://discuss.elastic.co/u/Bigboy0706)\
**Replies:** 5\
**Last updated:** [May 20, 2022, 1:52am UTC](https://discuss.elastic.co/t/filebeat-run-at-startup/304802 "2022-05-20T01:52:20Z")

</div>

Hi, I am trying to set up a Filebeat to collect the MacOS endpoint logs. May I know any command or general setting I could set to autostart the Filebeat after rebooting the MacOS? Thanks. Best Regards, Leo Yeung

---

## [Filebeat modules Threatintel "Exiting: module threatintel is configured but has no enabled filesets"](https://discuss.elastic.co/t/filebeat-modules-threatintel-exiting-module-threatintel-is-configured-but-has-no-enabled-filesets/304100)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 5\
**Last updated:** [May 20, 2022, 12:47am UTC](https://discuss.elastic.co/t/filebeat-modules-threatintel-exiting-module-threatintel-is-configured-but-has-no-enabled-filesets/304100 "2022-05-20T00:47:25Z")

</div>

I'm trying to activate the threatintel filebeat module for mining some data of otx alienvault, my module configuration looks like: - module: threatintel otx: enabled: true var.input: httpjson var.url: http…

---

## [How to set cutom index in filebeat](https://discuss.elastic.co/t/how-to-set-cutom-index-in-filebeat/305086)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 3\
**Last updated:** [May 19, 2022, 2:13pm UTC](https://discuss.elastic.co/t/how-to-set-cutom-index-in-filebeat/305086 "2022-05-19T14:13:41Z")

</div>

Hi, I am trying to configure custom index with logstash in filebeat so that its became easy to identify the servers with their index name here is the my filebeat config file. and logstash config file ##################…

---

## [Filebeat not started](https://discuss.elastic.co/t/filebeat-not-started/305129)

<div class="topic-metadata">

**Author:** [@Rajesh119](https://discuss.elastic.co/u/Rajesh119)\
**Replies:** 20\
**Last updated:** [May 19, 2022, 12:53pm UTC](https://discuss.elastic.co/t/filebeat-not-started/305129 "2022-05-19T12:53:41Z")

</div>

Hi, My filebeat was not running, if can i change any settings in filebeat.yml it goes to inactive. sudo service filebeat status ● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.…

---

## [Iam not Getting Logs in elasticstack](https://discuss.elastic.co/t/iam-not-getting-logs-in-elasticstack/305126)

<div class="topic-metadata">

**Author:** [@Rajesh119](https://discuss.elastic.co/u/Rajesh119)\
**Replies:** 1\
**Last updated:** [May 19, 2022, 4:58am UTC](https://discuss.elastic.co/t/iam-not-getting-logs-in-elasticstack/305126 "2022-05-19T04:58:45Z")

</div>

Iam not getting logs in elaticsearch please anyone help me regarding this issue. It's helps me alot, last from few days iam struggling. Thanks in advance.

---

## [Extract folder name as field in logstash](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026)

<div class="topic-metadata">

**Author:** [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Replies:** 7\
**Last updated:** [May 19, 2022, 4:38am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026 "2022-05-19T04:38:06Z")

</div>

Hi everyone The following is my filebeat input in my yml file- filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use different inputs for various configurations. # Below a…

---

## [Filebeat eats all space on disks when Elastic is down](https://discuss.elastic.co/t/filebeat-eats-all-space-on-disks-when-elastic-is-down/304653)

<div class="topic-metadata">

**Author:** [@yaks-hw](https://discuss.elastic.co/u/yaks-hw)\
**Replies:** 2\
**Last updated:** [May 18, 2022, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-eats-all-space-on-disks-when-elastic-is-down/304653 "2022-05-18T14:06:44Z")

</div>

Hello All, Our Elastic instance is down sometimes due to high load and human mistakes (we are in the middle of setting everything fine). When this happens, disks are getting full by Filebeat logs that notifies us that i…

---

## [Filebeat sophos module error: Provided Grok expressions do not match field value](https://discuss.elastic.co/t/filebeat-sophos-module-error-provided-grok-expressions-do-not-match-field-value/304675)

<div class="topic-metadata">

**Author:** [@Joshua\_H](https://discuss.elastic.co/u/Joshua_H)\
**Replies:** 16\
**Last updated:** [May 18, 2022, 1:56pm UTC](https://discuss.elastic.co/t/filebeat-sophos-module-error-provided-grok-expressions-do-not-match-field-value/304675 "2022-05-18T13:56:11Z")

</div>

Hello Everyone, I am trying to setup the Filebeat Sophos Module for a Sophos-XG Firewall. Filebeat Output is send directly to Elasticsearch. I enabled the sophos module and the initialized it sucessfully with filebeat…

---

## [Elastic Agent Custom Windows Event Logs](https://discuss.elastic.co/t/elastic-agent-custom-windows-event-logs/304485)

<div class="topic-metadata">

**Author:** [@Joshua\_H](https://discuss.elastic.co/u/Joshua_H)\
**Replies:** 4\
**Last updated:** [May 18, 2022, 12:55pm UTC](https://discuss.elastic.co/t/elastic-agent-custom-windows-event-logs/304485 "2022-05-18T12:55:53Z")

</div>

Hello everyone, I am struggling to add custom Windows Event Logs to my Elastic-Agents / my Agent-Policy and make it work. For example I would like to ingest Elasticsearch with Event Logs from the Serverrole Remotedeskt…

---

## [Filebeat topics with 'when' conditions](https://discuss.elastic.co/t/filebeat-topics-with-when-conditions/305054)

<div class="topic-metadata">

**Author:** [@juliang](https://discuss.elastic.co/u/juliang)\
**Replies:** 0\
**Last updated:** [May 18, 2022, 11:20am UTC](https://discuss.elastic.co/t/filebeat-topics-with-when-conditions/305054 "2022-05-18T11:20:13Z")

</div>

Hi there, I have the below defined in my output.kafka section topics: - topic: "my-topic" when: and: - equals: kubernetes.namespace: "test" - has\_…

---

## [Add\_kubernetes\_metadata with elatsicsearch on kubernetes, elasticsearch-operator does not add k8s field in kibana](https://discuss.elastic.co/t/add-kubernetes-metadata-with-elatsicsearch-on-kubernetes-elasticsearch-operator-does-not-add-k8s-field-in-kibana/304646)

<div class="topic-metadata">

**Author:** [@ryuseongryong](https://discuss.elastic.co/u/ryuseongryong)\
**Replies:** 1\
**Last updated:** [May 18, 2022, 8:15am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-with-elatsicsearch-on-kubernetes-elasticsearch-operator-does-not-add-k8s-field-in-kibana/304646 "2022-05-18T08:15:56Z")

</div>

hi, I've got a problem with add\_kubernetes\_metadata setting in my filebeat.yaml set-up with Elasticsearch-operator and Elasticsearch, metricbeat and filebeat, kibana as elasticsearch.k8s.elastic.co/v1, beat.k8s.elastic.…

---

## [Filebeat allow only specific line or content](https://discuss.elastic.co/t/filebeat-allow-only-specific-line-or-content/305017)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 5\
**Last updated:** [May 18, 2022, 7:47am UTC](https://discuss.elastic.co/t/filebeat-allow-only-specific-line-or-content/305017 "2022-05-18T07:47:23Z")

</div>

Hello, How can I allow only specific lines and for specific log files as well? example: I have lots of files in the inputs.d file but for the xyz.log file, I wanna set up the filter only to allow "out of memory" line o…

---

## [Wrong Mapping of ECS fields on fleet-managed datastreams causing multiple issues](https://discuss.elastic.co/t/wrong-mapping-of-ecs-fields-on-fleet-managed-datastreams-causing-multiple-issues/305014)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 0\
**Last updated:** [May 18, 2022, 4:27am UTC](https://discuss.elastic.co/t/wrong-mapping-of-ecs-fields-on-fleet-managed-datastreams-causing-multiple-issues/305014 "2022-05-18T04:27:37Z")

</div>

Hi, We recently migrated part of our environment from beats to the elastic-agent managed by fleet integrations. While this makes agent management very easy, it introduced a lot of mapping issues which then cause search …

---

## [New filebeat implementation for Fortinet module not starting](https://discuss.elastic.co/t/new-filebeat-implementation-for-fortinet-module-not-starting/304995)

<div class="topic-metadata">

**Author:** [@doublejz](https://discuss.elastic.co/u/doublejz)\
**Replies:** 1\
**Last updated:** [May 17, 2022, 9:12pm UTC](https://discuss.elastic.co/t/new-filebeat-implementation-for-fortinet-module-not-starting/304995 "2022-05-17T21:12:41Z")

</div>

I'm not sure what I'm missing here. I apologize for being a noob but I've just started getting into setting up my ELK stack and can't figure this out. I thought I had it all configured but yet filebeat won't start and I…

---

## [Packetbeat not sending to Logstash after Elastic-Agent uninstall](https://discuss.elastic.co/t/packetbeat-not-sending-to-logstash-after-elastic-agent-uninstall/303059)

<div class="topic-metadata">

**Author:** [@fl33t](https://discuss.elastic.co/u/fl33t)\
**Replies:** 2\
**Last updated:** [May 17, 2022, 5:09pm UTC](https://discuss.elastic.co/t/packetbeat-not-sending-to-logstash-after-elastic-agent-uninstall/303059 "2022-05-17T17:09:07Z")

</div>

While experimenting with elastic-agent/fleet-server I noticed that once the agent was uninstalled, packetbeat didn't seem able to send to logstash anymore. No more indexes, nothing. The sequence is basically: Packetbe…

---

## [Filebeat filestream input not releasing file handler with hard-linked file](https://discuss.elastic.co/t/filebeat-filestream-input-not-releasing-file-handler-with-hard-linked-file/304041)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [May 17, 2022, 4:12pm UTC](https://discuss.elastic.co/t/filebeat-filestream-input-not-releasing-file-handler-with-hard-linked-file/304041 "2022-05-17T16:12:20Z")

</div>

Hello, I have a use case where I ingest files created by the Wazuh agent, these files are created in paths with the following format: /var/ossec/logs/archives/YYYY/MM/ossec-archive-dd.json For example: /var/ossec/log…

---

## [Problem with checkpoint module and datastream](https://discuss.elastic.co/t/problem-with-checkpoint-module-and-datastream/304965)

<div class="topic-metadata">

**Author:** [@Salvatore\_Mattei](https://discuss.elastic.co/u/Salvatore_Mattei)\
**Replies:** 0\
**Last updated:** [May 17, 2022, 3:53pm UTC](https://discuss.elastic.co/t/problem-with-checkpoint-module-and-datastream/304965 "2022-05-17T15:53:20Z")

</div>

Hi, we are ingesting data using checkpoint filebeat module. Some records are not ingested and gives this error: May 17 09:24:45 XXXX filebeat\[3110397\]: 2022-05-17T09:24:45.674Z#011WARN#011\[elasticsearch\]#011elasticsea…

---

## [Filebeat haproxy with dns processor](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 9\
**Last updated:** [May 17, 2022, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501 "2022-05-17T12:56:47Z")

</div>

I have succssfully send haproxy log to Elasticsearch using filebeat. next step I am trying to do is to change destination.ip and source.ip to name but I don't think I am using dns processor correctly. I am not getting…

---

## [Filebeat 7.16 drop\_fields processor not working](https://discuss.elastic.co/t/filebeat-7-16-drop-fields-processor-not-working/304916)

<div class="topic-metadata">

**Author:** [@Sederfo](https://discuss.elastic.co/u/Sederfo)\
**Replies:** 0\
**Last updated:** [May 17, 2022, 10:09am UTC](https://discuss.elastic.co/t/filebeat-7-16-drop-fields-processor-not-working/304916 "2022-05-17T10:09:21Z")

</div>

Hello! We are having trouble dropping fields from messages using Filebeat 7.16. We tried to drop fields using the "drop\_fields" processor: processors: - drop\_fields: fields: \["cisco.ftd.message\_id"\] ignor…

---

## [SSL configuration assistance](https://discuss.elastic.co/t/ssl-configuration-assistance/304778)

<div class="topic-metadata">

**Author:** [@rajvel](https://discuss.elastic.co/u/rajvel)\
**Replies:** 6\
**Last updated:** [May 17, 2022, 9:51am UTC](https://discuss.elastic.co/t/ssl-configuration-assistance/304778 "2022-05-17T09:51:16Z")

</div>

Hello Team, We are having a single node ELK configuration, In the same server we have installed Elasticsearch logstash and kibana (8.0.1) (on-premises) As per the guide if we are installing the elasticsearch generates …

---

## [Filebeat rate limiting question](https://discuss.elastic.co/t/filebeat-rate-limiting-question/304898)

<div class="topic-metadata">

**Author:** [@can.ozdemir](https://discuss.elastic.co/u/can.ozdemir)\
**Replies:** 0\
**Last updated:** [May 17, 2022, 8:19am UTC](https://discuss.elastic.co/t/filebeat-rate-limiting-question/304898 "2022-05-17T08:19:46Z")

</div>

Hello there, we would like to limit the producer rates from our filebeat into kafka. I found rate\_limit processor from below link can be used, but I am confused about what dropping the events mean. Is filebeat retrying t…

---

## [How to set "enabled":"False" to a field in filebeat](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806)

<div class="topic-metadata">

**Author:** [@Kuo\_Hugo](https://discuss.elastic.co/u/Kuo_Hugo)\
**Replies:** 6\
**Last updated:** [May 17, 2022, 8:15am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806 "2022-05-17T08:15:34Z")

</div>

Add it to setup.template.fields file. But the index template doesn't have the "enabled: false" applied. Is there a way to disable a field from indexing ? - name: message level: core type: text enabled: fa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=89)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=91)
