# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=91

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 92

---

## [Add a field when a match between an external dictionary and a field from a filebeat document occurrs](https://discuss.elastic.co/t/add-a-field-when-a-match-between-an-external-dictionary-and-a-field-from-a-filebeat-document-occurrs/304894)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [May 17, 2022, 7:23am UTC](https://discuss.elastic.co/t/add-a-field-when-a-match-between-an-external-dictionary-and-a-field-from-a-filebeat-document-occurrs/304894 "2022-05-17T07:23:55Z")

</div>

Hi, in filebeat can I add a field when a match between an external dictionary and a field from a filebeat document occurrs? Im already doing this with an ingest pipeline and an enrich proccesor, but the ingestion is to …

---

## [Filebeat doesnt capture log file \[8.2\]](https://discuss.elastic.co/t/filebeat-doesnt-capture-log-file-8-2/304889)

<div class="topic-metadata">

**Author:** [@adliazaddin](https://discuss.elastic.co/u/adliazaddin)\
**Replies:** 0\
**Last updated:** [May 17, 2022, 6:33am UTC](https://discuss.elastic.co/t/filebeat-doesnt-capture-log-file-8-2/304889 "2022-05-17T06:33:40Z")

</div>

Hello, my filebeat doesnt seem to collect my logs (i have multiple source, and filebeat only capture the most bottom part. and adding file in the module.d doesnt capture either) theres nothing on the filebeat log below…

---

## [Error module logstash with metricbeat](https://discuss.elastic.co/t/error-module-logstash-with-metricbeat/304831)

<div class="topic-metadata">

**Author:** [@jojodd](https://discuss.elastic.co/u/jojodd)\
**Replies:** 1\
**Last updated:** [May 17, 2022, 2:09am UTC](https://discuss.elastic.co/t/error-module-logstash-with-metricbeat/304831 "2022-05-17T02:09:06Z")

</div>

I don't understand why I get this error after configuring the logstash module in metricbeat. logstash.node\_stats: json: cannot unmarshal object into Go struct field

---

## [Filebeat Azure Module - Config without Storage Account](https://discuss.elastic.co/t/filebeat-azure-module-config-without-storage-account/304878)

<div class="topic-metadata">

**Author:** [@bashurst](https://discuss.elastic.co/u/bashurst)\
**Replies:** 0\
**Last updated:** [May 16, 2022, 10:14pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-config-without-storage-account/304878 "2022-05-16T22:14:14Z")

</div>

For one of our use cases we are looking to setup a filebeats azure module to pull without using a storage account. As the storage account is only used to hold the pointer and we can handle our own splitting of the refer…

---

## [Can filebeat ingest a JSON-format file as a single document?](https://discuss.elastic.co/t/can-filebeat-ingest-a-json-format-file-as-a-single-document/304872)

<div class="topic-metadata">

**Author:** [@kmp](https://discuss.elastic.co/u/kmp)\
**Replies:** 0\
**Last updated:** [May 16, 2022, 9:29pm UTC](https://discuss.elastic.co/t/can-filebeat-ingest-a-json-format-file-as-a-single-document/304872 "2022-05-16T21:29:11Z")

</div>

I'm guessing this is really simple or ... not so much: we have an application deployed on a number of hosts that has a configuration file in JSON. We'd like to ingest the file as a single document using filebeat, in or…

---

## [Aggregate Json input](https://discuss.elastic.co/t/aggregate-json-input/304842)

<div class="topic-metadata">

**Author:** [@shacharaj](https://discuss.elastic.co/u/shacharaj)\
**Replies:** 1\
**Last updated:** [May 16, 2022, 4:05pm UTC](https://discuss.elastic.co/t/aggregate-json-input/304842 "2022-05-16T16:05:42Z")

</div>

Hello everyone, I am trying to aggregate JSON input I harvest through filebeat, This is my application log file: }{ "timestamp" : "2022-05-16 15:47:40", "level" : "ERROR", "thread" : "main", "logger" : "com.cr…

---

## [Removing Data View Filelds](https://discuss.elastic.co/t/removing-data-view-filelds/304825)

<div class="topic-metadata">

**Author:** [@mehrnaz](https://discuss.elastic.co/u/mehrnaz)\
**Replies:** 0\
**Last updated:** [May 16, 2022, 1:15pm UTC](https://discuss.elastic.co/t/removing-data-view-filelds/304825 "2022-05-16T13:15:54Z")

</div>

Hello, I am trying to create a dashboard in Grafana with my Elasticsearch database. However, the fields that I am interested in are not showing up in Grafana. I am interested in the Available fields that I can see in Ki…

---

## [Integrate snort3 with elastic stack using filebeat](https://discuss.elastic.co/t/integrate-snort3-with-elastic-stack-using-filebeat/304749)

<div class="topic-metadata">

**Author:** [@Onsrm](https://discuss.elastic.co/u/Onsrm)\
**Replies:** 1\
**Last updated:** [May 16, 2022, 12:19am UTC](https://discuss.elastic.co/t/integrate-snort3-with-elastic-stack-using-filebeat/304749 "2022-05-16T00:19:02Z")

</div>

hello, i want to integrate snort3 with elk stack. when i use this command : sudo filebeat setup -E output.logstash.enabled=false -E output.elasticsearch.hosts=\['192.168.200.100:9200'\] -E setup.kibana.host=192.168.200.1…

---

## [Help: winlogbeat.yaml error](https://discuss.elastic.co/t/help-winlogbeat-yaml-error/304727)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 3\
**Last updated:** [May 14, 2022, 12:34pm UTC](https://discuss.elastic.co/t/help-winlogbeat-yaml-error/304727 "2022-05-14T12:34:38Z")

</div>

I copied and pasted the same winlogbeat.yaml file o ver to a new server to use. However it is giving an error. I never got this error on the old servers that I was using. Here is the error: PS C:\\Program Files\\Winlogbe…

---

## [No such index \[.ds-.fleet-actions-results-\*\]](https://discuss.elastic.co/t/no-such-index-ds-fleet-actions-results/302181)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 2\
**Last updated:** [May 14, 2022, 2:01am UTC](https://discuss.elastic.co/t/no-such-index-ds-fleet-actions-results/302181 "2022-05-14T02:01:05Z")

</div>

Can't modify settings for these indicies via Dev Tool or UI and the data stream doesn't have a delete action. PUT /.ds-.fleet-actions-results-\*/\_settings { "index" : { "number\_of\_replicas" : 0 } } { "error" …

---

## [ELK STACK - suricatas](https://discuss.elastic.co/t/elk-stack-suricatas/304560)

<div class="topic-metadata">

**Author:** [@TARIK\_MAZOUZ](https://discuss.elastic.co/u/TARIK_MAZOUZ)\
**Replies:** 1\
**Last updated:** [May 13, 2022, 9:47pm UTC](https://discuss.elastic.co/t/elk-stack-suricatas/304560 "2022-05-13T21:47:55Z")

</div>

hey everyone, i hope u all doing good, please i need your help here, well i have installed 3 VM, first one is the server where i've already install Elasticsearch and kibana, the second VM is a linux client , and the thir…

---

## [Multiline with type filestram](https://discuss.elastic.co/t/multiline-with-type-filestram/304695)

<div class="topic-metadata">

**Author:** [@adrianfusco](https://discuss.elastic.co/u/adrianfusco)\
**Replies:** 0\
**Last updated:** [May 13, 2022, 3:02pm UTC](https://discuss.elastic.co/t/multiline-with-type-filestram/304695 "2022-05-13T15:02:44Z")

</div>

Hello, I see type:log is going to be deprecated (Log input | Filebeat Reference \[8.2\] | Elastic) and we should use filestream instead of this one. I'm trying to parse some output from ansible. A very simple basic examp…

---

## [Index paramétrer mais pas fonctionnel](https://discuss.elastic.co/t/index-parametrer-mais-pas-fonctionnel/304573)

<div class="topic-metadata">

**Author:** [@Deix42](https://discuss.elastic.co/u/Deix42)\
**Replies:** 1\
**Last updated:** [May 13, 2022, 10:26am UTC](https://discuss.elastic.co/t/index-parametrer-mais-pas-fonctionnel/304573 "2022-05-13T10:26:44Z")

</div>

Bonjour à tous ! Débutant dans Elasticsearch et dans les bases de données, pour un projet j'ai fais une configuration avec filebeat qui envoie les informations directement à Elasticsearch. Le fichier que j'envoie est de…

---

## [FunctionBeat integration with OpenSearch AWS](https://discuss.elastic.co/t/functionbeat-integration-with-opensearch-aws/304650)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 1\
**Last updated:** [May 13, 2022, 8:32am UTC](https://discuss.elastic.co/t/functionbeat-integration-with-opensearch-aws/304650 "2022-05-13T08:32:51Z")

</div>

Hello guys, I want to ask if somebody has used FunctionBeat to ingest/integrate with OpenSearch from AWS? What i want to accomplish is this: OpenSearch -\> logstash -\> Elasticsearch (running on azure) I have no experi…

---

## [Beats setup.template date format only accepts string, url, or date](https://discuss.elastic.co/t/beats-setup-template-date-format-only-accepts-string-url-or-date/304636)

<div class="topic-metadata">

**Author:** [@eddyariki](https://discuss.elastic.co/u/eddyariki)\
**Replies:** 0\
**Last updated:** [May 13, 2022, 5:46am UTC](https://discuss.elastic.co/t/beats-setup-template-date-format-only-accepts-string-url-or-date/304636 "2022-05-13T05:46:12Z")

</div>

In my filebeat configuration, I am trying to append a field of type date with a format specified. setup.template: overwrite: false append\_fields: - name: testfield type: date format: "dd/MMM/yyyy:HH:mm:ss …

---

## [How to set routing allocation on the filebeat template](https://discuss.elastic.co/t/how-to-set-routing-allocation-on-the-filebeat-template/304601)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [May 12, 2022, 3:22pm UTC](https://discuss.elastic.co/t/how-to-set-routing-allocation-on-the-filebeat-template/304601 "2022-05-12T15:22:23Z")

</div>

I use ECK and i have filebeat setup. I have 3 nodeset Elasticsearch cluster, one which is named "monitoring" i have defined the node attri according to the following docs (Index-level shard allocation filtering | Elastic…

---

## [Error while stopping harverster group](https://discuss.elastic.co/t/error-while-stopping-harverster-group/304590)

<div class="topic-metadata">

**Author:** [@leonelfonseca](https://discuss.elastic.co/u/leonelfonseca)\
**Replies:** 0\
**Last updated:** [May 12, 2022, 2:39pm UTC](https://discuss.elastic.co/t/error-while-stopping-harverster-group/304590 "2022-05-12T14:39:12Z")

</div>

Hi, can anyone explain about this error message that appears in the Filebeat log ? \> Error while stopping harverster group: task failures error while adding new reader to the bookkeeper harvester is already running…

---

## [Apache tomcat module](https://discuss.elastic.co/t/apache-tomcat-module/304563)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [May 12, 2022, 11:50am UTC](https://discuss.elastic.co/t/apache-tomcat-module/304563 "2022-05-12T11:50:32Z")

</div>

Hello team, We configured apache module in our server but we are able to get only below two types of message in our ELK. Can any one please help on this Error: HTTP error 404 in : 404 error making http request: Post…

---

## [Filebeat filestream input rereading rotated log files](https://discuss.elastic.co/t/filebeat-filestream-input-rereading-rotated-log-files/300038)

<div class="topic-metadata">

**Author:** [@lpeter](https://discuss.elastic.co/u/lpeter)\
**Replies:** 14\
**Last updated:** [May 12, 2022, 9:08am UTC](https://discuss.elastic.co/t/filebeat-filestream-input-rereading-rotated-log-files/300038 "2022-05-12T09:08:23Z")

</div>

Hello! I'm running into this very common problem of rotated files being reread and resent. I'm using Filebeat 8.1.0 with the new(ish) filestream input plugin. I've read the docs of the plugin and the article on this spe…

---

## [Drop agent / ecs fields from filebeat (previous solves here only partially work)](https://discuss.elastic.co/t/drop-agent-ecs-fields-from-filebeat-previous-solves-here-only-partially-work/304508)

<div class="topic-metadata">

**Author:** [@elk-user-99](https://discuss.elastic.co/u/elk-user-99)\
**Replies:** 0\
**Last updated:** [May 11, 2022, 9:44pm UTC](https://discuss.elastic.co/t/drop-agent-ecs-fields-from-filebeat-previous-solves-here-only-partially-work/304508 "2022-05-11T21:44:37Z")

</div>

Hey all, I'm attempting to use filebeat to send documents into ES, however even though I've got a processor set up to drop fields, some are still stubbornly getting sent. in my filebeat.yml file: - drop\_fields: …

---

## [Moving Cloud Instances - Elastic Agent](https://discuss.elastic.co/t/moving-cloud-instances-elastic-agent/304492)

<div class="topic-metadata">

**Author:** [@notladr](https://discuss.elastic.co/u/notladr)\
**Replies:** 0\
**Last updated:** [May 11, 2022, 5:03pm UTC](https://discuss.elastic.co/t/moving-cloud-instances-elastic-agent/304492 "2022-05-11T17:03:45Z")

</div>

Firstly, I apologize if this is an elementary question, but didn't see anything with search results. I have Elastic Cloud deployed in my lab - not any production environments. When deploying the Windows Elastic Agent, …

---

## [How to obtain socket information for particular applications/processes using metricbeat?](https://discuss.elastic.co/t/how-to-obtain-socket-information-for-particular-applications-processes-using-metricbeat/304484)

<div class="topic-metadata">

**Author:** [@sangameshcs](https://discuss.elastic.co/u/sangameshcs)\
**Replies:** 0\
**Last updated:** [May 11, 2022, 3:55pm UTC](https://discuss.elastic.co/t/how-to-obtain-socket-information-for-particular-applications-processes-using-metricbeat/304484 "2022-05-11T15:55:04Z")

</div>

Hi, I am using metric-beat to collect information about processes running on remote hosts which use sockets, and I am able to collect the metrics/information about the processes and socket data is one of them but I am no…

---

## [Metricbeat sql module - specify database name when connecting to MSSQL](https://discuss.elastic.co/t/metricbeat-sql-module-specify-database-name-when-connecting-to-mssql/304336)

<div class="topic-metadata">

**Author:** [@ianufurnish.com](https://discuss.elastic.co/u/ianufurnish.com)\
**Replies:** 8\
**Last updated:** [May 11, 2022, 8:35am UTC](https://discuss.elastic.co/t/metricbeat-sql-module-specify-database-name-when-connecting-to-mssql/304336 "2022-05-11T08:35:26Z")

</div>

According to the documentation, it doesn't appear to be possible to specify the database name when connecting to Microsoft SQL. I'd like to use this module to connect to Azure SQL in order to run a query against a databa…

---

## [Filebeat not picking up logs](https://discuss.elastic.co/t/filebeat-not-picking-up-logs/304407)

<div class="topic-metadata">

**Author:** [@Likhitha\_adulla](https://discuss.elastic.co/u/Likhitha_adulla)\
**Replies:** 0\
**Last updated:** [May 11, 2022, 4:39am UTC](https://discuss.elastic.co/t/filebeat-not-picking-up-logs/304407 "2022-05-11T04:39:41Z")

</div>

I have filebeat running as a docker container which is collecting the application logs from the other docker container writing logs to a specified folder on the host. The issue is only some of the logs are missing as fi…

---

## [Create custom beat for drone sensor data](https://discuss.elastic.co/t/create-custom-beat-for-drone-sensor-data/304395)

<div class="topic-metadata">

**Author:** [@gustavofring](https://discuss.elastic.co/u/gustavofring)\
**Replies:** 0\
**Last updated:** [May 10, 2022, 11:21pm UTC](https://discuss.elastic.co/t/create-custom-beat-for-drone-sensor-data/304395 "2022-05-10T23:21:31Z")

</div>

Dear contributors, I'd like to visualize drone sensor data through kibana. But, there is no mavlink-beat for it, so I am willing to create it. But, I read that the custom beat is deprecated since ELK stack v7.16. Wha…

---

## [System Integration not Parsing SSH Failures](https://discuss.elastic.co/t/system-integration-not-parsing-ssh-failures/304394)

<div class="topic-metadata">

**Author:** [@ericbarnes](https://discuss.elastic.co/u/ericbarnes)\
**Replies:** 0\
**Last updated:** [May 10, 2022, 8:52pm UTC](https://discuss.elastic.co/t/system-integration-not-parsing-ssh-failures/304394 "2022-05-10T20:52:52Z")

</div>

Elasticsearch/Kibana Version = 8.2 I'm starting a new cluster and want to verify all of the default dashboards and ingest paths are working correctly. I am using Fleet to manage the agents and integrations. For the Sys…

---

## [Monitor urls with Windows Authentication](https://discuss.elastic.co/t/monitor-urls-with-windows-authentication/304337)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 3\
**Last updated:** [May 10, 2022, 2:40pm UTC](https://discuss.elastic.co/t/monitor-urls-with-windows-authentication/304337 "2022-05-10T14:40:41Z")

</div>

Hi, I am using heartbeat 6.4.0 I am trying to monitor an https url, below is my configuration: heartbeat.monitors: - type: http urls: - https://myurl.company.com/ schedule: '@every 5m' username: user passw…

---

## [Write to kafka topic in a secure way](https://discuss.elastic.co/t/write-to-kafka-topic-in-a-secure-way/304309)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 1\
**Last updated:** [May 10, 2022, 9:39am UTC](https://discuss.elastic.co/t/write-to-kafka-topic-in-a-secure-way/304309 "2022-05-10T09:39:06Z")

</div>

I'm using filebeat to write logs to Kafka topic. My Kafka server is running on a different ec2 server. I want to create a secure connection between the server from which I'm sending logs and the Kafka server. Is there a…

---

## [Filebeat autodiscover namespace\_defaults not work](https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901)

<div class="topic-metadata">

**Author:** [@lcc3108](https://discuss.elastic.co/u/lcc3108)\
**Replies:** 3\
**Last updated:** [May 10, 2022, 4:49am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901 "2022-05-10T04:49:09Z")

</div>

Hello. I'm using Elasticsearch filebeat 7.17. According to the document, filebeat can use namespace's annotation when pod's annotation does not exist. But it seems to be working against my expectations. The followi…

---

## [Add fields do not work Winlogbeat](https://discuss.elastic.co/t/add-fields-do-not-work-winlogbeat/304232)

<div class="topic-metadata">

**Author:** [@CemG](https://discuss.elastic.co/u/CemG)\
**Replies:** 1\
**Last updated:** [May 10, 2022, 1:46am UTC](https://discuss.elastic.co/t/add-fields-do-not-work-winlogbeat/304232 "2022-05-10T01:46:27Z")

</div>

Hello, I would like to add fields in \_source by using fields config, and also I tested with pocessors. But I don't even see the fields that I wanted to add Processors config processors: - add\_fields: target: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=90)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=92)
