# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=92

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 93

---

## [Elasticsearch ca certificate problem](https://discuss.elastic.co/t/elasticsearch-ca-certificate-problem/304108)

<div class="topic-metadata">

**Author:** [@uaygun](https://discuss.elastic.co/u/uaygun)\
**Replies:** 0\
**Last updated:** [May 6, 2022, 9:36am UTC](https://discuss.elastic.co/t/elasticsearch-ca-certificate-problem/304108 "2022-05-06T09:36:11Z")

</div>

Hi guys; I have a wazuh server with running filebeat and Elasticsearch. When i am trying to establish a connection from remote filebeat to my Elasticsearch i am getting "Exiting: error loading config file: yaml: line 1…

---

## [How to monitor urls with sso authentication](https://discuss.elastic.co/t/how-to-monitor-urls-with-sso-authentication/304133)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 4\
**Last updated:** [May 10, 2022, 12:56am UTC](https://discuss.elastic.co/t/how-to-monitor-urls-with-sso-authentication/304133 "2022-05-10T00:56:02Z")

</div>

Hi, My setup Elasticsearch 6.4.0, kibana 6.4.0 and heartbeat 6.4.0 heartbeat configuration: heartbeat.monitors: - type: http # List or urls to query urls: - https://appname.in.company.com:8443/appname-6.4 …

---

## [Error when installing filebeat on Raspberry PI 3](https://discuss.elastic.co/t/error-when-installing-filebeat-on-raspberry-pi-3/304240)

<div class="topic-metadata">

**Author:** [@Dhia\_Saibi](https://discuss.elastic.co/u/Dhia_Saibi)\
**Replies:** 1\
**Last updated:** [May 10, 2022, 12:34am UTC](https://discuss.elastic.co/t/error-when-installing-filebeat-on-raspberry-pi-3/304240 "2022-05-10T00:34:05Z")

</div>

I'm trying to install filebeat on my raspberry pi 3 following this tutorial https://www.gunnarleffler.com/posts/raspberry\_pi\_filebeats/?fbclid=IwAR1v-agodz-wkxPpwGa56kMOHq3M77K8iCHGS7zoyhx9B4TRwIxU9va76dc but I'm stuck a…

---

## [Java multiline stack trace log shipping with filebeat](https://discuss.elastic.co/t/java-multiline-stack-trace-log-shipping-with-filebeat/304170)

<div class="topic-metadata">

**Author:** [@Alireza\_Zabihi](https://discuss.elastic.co/u/Alireza_Zabihi)\
**Replies:** 5\
**Last updated:** [May 9, 2022, 2:43pm UTC](https://discuss.elastic.co/t/java-multiline-stack-trace-log-shipping-with-filebeat/304170 "2022-05-09T14:43:56Z")

</div>

Hi, Please help me for creating a pattern for this log \[2022-05-07 13:20:53,621\] \[WARN\] \[gateway\_service\] \[reactor.util.Loggers$Slf4JLogger\] \[warn:295\] message: \[b17d8e8c-1, L:/192.168.149.185:33094 - R:orderscl.sepanta…

---

## [Filebeat 8.1.1 Custom Index](https://discuss.elastic.co/t/filebeat-8-1-1-custom-index/302736)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 4\
**Last updated:** [May 9, 2022, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-8-1-1-custom-index/302736 "2022-05-09T14:25:16Z")

</div>

So the same index that has worked for over a year now seems to have stopped when we moved to Elasticsearch v8. Custom index for filebeat. filebeat.inputs: - type: log paths: - LogPathGoeshere:Expired.csv exclude\_…

---

## [Azure Module - Multiple event hubs?](https://discuss.elastic.co/t/azure-module-multiple-event-hubs/303850)

<div class="topic-metadata">

**Author:** [@chris.murray](https://discuss.elastic.co/u/chris.murray)\
**Replies:** 11\
**Last updated:** [May 9, 2022, 12:57pm UTC](https://discuss.elastic.co/t/azure-module-multiple-event-hubs/303850 "2022-05-09T12:57:26Z")

</div>

Can't seem to find a solution for this. Here's the situation: I am setting up a PoC environment, which has two Azure event hubs configured to input Azure AD data (which themselves are coming from separate environments)…

---

## [Use Yara custom rules with Osquery-Manager](https://discuss.elastic.co/t/use-yara-custom-rules-with-osquery-manager/302789)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 6\
**Last updated:** [May 9, 2022, 11:23am UTC](https://discuss.elastic.co/t/use-yara-custom-rules-with-osquery-manager/302789 "2022-05-09T11:23:00Z")

</div>

Hello Team, Is It possible to use yara custom rules with osquery manager integration ?? I'm using version 7.17.1 Many thanks.

---

## [Winlogbeat output kafka, but not same fields as Elastic output](https://discuss.elastic.co/t/winlogbeat-output-kafka-but-not-same-fields-as-elastic-output/304226)

<div class="topic-metadata">

**Author:** [@CemG](https://discuss.elastic.co/u/CemG)\
**Replies:** 0\
**Last updated:** [May 9, 2022, 9:00am UTC](https://discuss.elastic.co/t/winlogbeat-output-kafka-but-not-same-fields-as-elastic-output/304226 "2022-05-09T09:00:50Z")

</div>

Hello, I get Windows logs with Winlogbeat, and I output them to Kafka. The issue is that when I use Winlogbeat dashboard in Elasticsearch, there are missing fields, and I would like to use them. And when I use Elastic…

---

## [How to add certs to hearbeat](https://discuss.elastic.co/t/how-to-add-certs-to-hearbeat/303554)

<div class="topic-metadata">

**Author:** [@Francisco\_Yanez](https://discuss.elastic.co/u/Francisco_Yanez)\
**Replies:** 9\
**Last updated:** [May 9, 2022, 8:48am UTC](https://discuss.elastic.co/t/how-to-add-certs-to-hearbeat/303554 "2022-05-09T08:48:45Z")

</div>

Hello Community, I am trying to add to heartbeat (all our infra is running in kubernetes) all our pods that have certs so we can monitor those via https and alert when is time to renew them. To access those via http I n…

---

## [Filebeat not close delete filehandler](https://discuss.elastic.co/t/filebeat-not-close-delete-filehandler/304221)

<div class="topic-metadata">

**Author:** [@mvasilenko](https://discuss.elastic.co/u/mvasilenko)\
**Replies:** 0\
**Last updated:** [May 9, 2022, 8:32am UTC](https://discuss.elastic.co/t/filebeat-not-close-delete-filehandler/304221 "2022-05-09T08:32:22Z")

</div>

we are running filebeat 6.8.22 with inputs as docker containers and it doesn't release file handlers for deleted files filebeat.inputs: - type: docker close\_inactive: 5m close\_removed: true clean\_removed: true c…

---

## [Filebeat can not collect logs data from mounted disk](https://discuss.elastic.co/t/filebeat-can-not-collect-logs-data-from-mounted-disk/303134)

<div class="topic-metadata">

**Author:** [@sahinguler](https://discuss.elastic.co/u/sahinguler)\
**Replies:** 5\
**Last updated:** [May 9, 2022, 8:04am UTC](https://discuss.elastic.co/t/filebeat-can-not-collect-logs-data-from-mounted-disk/303134 "2022-05-09T08:04:04Z")

</div>

Hi all, I used filebeat for collecting my logs and my filebeat version is 7.16.3. When I collect my logs from /var/lib/docker/containers/${data.docker.container.id}/\*.log, logs were collected. If I used /mnt/.. (my mou…

---

## [Fleet agent upgrade fails 8.1.2](https://discuss.elastic.co/t/fleet-agent-upgrade-fails-8-1-2/302970)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 12\
**Last updated:** [May 9, 2022, 8:12am UTC](https://discuss.elastic.co/t/fleet-agent-upgrade-fails-8-1-2/302970 "2022-05-09T08:12:41Z")

</div>

After the stack upgrade to the latest 8.1.3 the agents are unable to upgrade error: failed verification of agent binary: 2 errors occurred:\\n\\t\* fetching asc file from 'C:\\\\Program Files\\\\Elastic\\\\Agent\\\\data\\\\elastic-…

---

## [What happens if I let my beats service run constantly](https://discuss.elastic.co/t/what-happens-if-i-let-my-beats-service-run-constantly/304036)

<div class="topic-metadata">

**Author:** [@smam](https://discuss.elastic.co/u/smam)\
**Replies:** 2\
**Last updated:** [May 9, 2022, 6:08am UTC](https://discuss.elastic.co/t/what-happens-if-i-let-my-beats-service-run-constantly/304036 "2022-05-09T06:08:45Z")

</div>

Hello, I have a script that changes my winlogbeat.yml as a scheduled task. What happens if I start the winlogbeat service? Would he notice the change of data and still use it or would I have to stop the service, change…

---

## [Install winlogbeat dashboard](https://discuss.elastic.co/t/install-winlogbeat-dashboard/304198)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [May 9, 2022, 3:53am UTC](https://discuss.elastic.co/t/install-winlogbeat-dashboard/304198 "2022-05-09T03:53:09Z")

</div>

Is there a way to install the winlogbeat dashboards on the machine running kibana? All the docs imply that this can only be done from the windows system that are being monitored (of which there are many) and I don't hav…

---

## [Filebeat Docker input: exclude container by name](https://discuss.elastic.co/t/filebeat-docker-input-exclude-container-by-name/304202)

<div class="topic-metadata">

**Author:** [@alifsaddid](https://discuss.elastic.co/u/alifsaddid)\
**Replies:** 0\
**Last updated:** [May 9, 2022, 2:21am UTC](https://discuss.elastic.co/t/filebeat-docker-input-exclude-container-by-name/304202 "2022-05-09T02:21:37Z")

</div>

Hi, I am having a problem on configuring filebeat. I am running filebeat, logstash, Elasticsearch, and kibana on Docker. I want to retrieve logs of all existing containers, except from filebeat, logstash, Elasticsearch,…

---

## [My filebeat start occur error](https://discuss.elastic.co/t/my-filebeat-start-occur-error/304188)

<div class="topic-metadata">

**Author:** [@zhanghao116560](https://discuss.elastic.co/u/zhanghao116560)\
**Replies:** 2\
**Last updated:** [May 9, 2022, 12:37am UTC](https://discuss.elastic.co/t/my-filebeat-start-occur-error/304188 "2022-05-09T00:37:05Z")

</div>

Here is my configuration information: processors: - add\_host\_metadata: ~ - add\_cloud\_metadata: ~ - drop\_fields: fields: \["beat"\] I want to add a filter to remove the beat attribute, However, a startup error o…

---

## [How to delete field in filebeat7.8.0](https://discuss.elastic.co/t/how-to-delete-field-in-filebeat7-8-0/302908)

<div class="topic-metadata">

**Author:** [@kiddingl](https://discuss.elastic.co/u/kiddingl)\
**Replies:** 6\
**Last updated:** [May 7, 2022, 8:36am UTC](https://discuss.elastic.co/t/how-to-delete-field-in-filebeat7-8-0/302908 "2022-05-07T08:36:58Z")

</div>

I collect log file and output to es with filebeat, But I get many unused fileds,like this: The many of field which is no value, How to delete it

---

## [Winlogbeat dashboard missing fields](https://discuss.elastic.co/t/winlogbeat-dashboard-missing-fields/304123)

<div class="topic-metadata">

**Author:** [@CemG](https://discuss.elastic.co/u/CemG)\
**Replies:** 1\
**Last updated:** [May 6, 2022, 12:18pm UTC](https://discuss.elastic.co/t/winlogbeat-dashboard-missing-fields/304123 "2022-05-06T12:18:48Z")

</div>

Hello, I have an issue with winlogbeat output. When I am trying to see information with Winlogbeat dashboards in Kibana, it says that there is missing fields in my data when I output to kafka because my architecture is…

---

## [Heartbeat HTTP monitor evaluate a Date JSON response Field](https://discuss.elastic.co/t/heartbeat-http-monitor-evaluate-a-date-json-response-field/303999)

<div class="topic-metadata">

**Author:** [@mktbec](https://discuss.elastic.co/u/mktbec)\
**Replies:** 4\
**Last updated:** [May 6, 2022, 6:58am UTC](https://discuss.elastic.co/t/heartbeat-http-monitor-evaluate-a-date-json-response-field/303999 "2022-05-06T06:58:21Z")

</div>

Hi everyone I need to evaluate a Date field in a JSON response with a heartbeat monitor. it look like there is a date() option using gval, but I can't make it work. the HTTP response looks like this. { "syncTables" …

---

## [Output elasticsearch of filebeat](https://discuss.elastic.co/t/output-elasticsearch-of-filebeat/304075)

<div class="topic-metadata">

**Author:** [@zfx](https://discuss.elastic.co/u/zfx)\
**Replies:** 6\
**Last updated:** [May 6, 2022, 5:42am UTC](https://discuss.elastic.co/t/output-elasticsearch-of-filebeat/304075 "2022-05-06T05:42:58Z")

</div>

If I want to use filebeat of metadata fields to instead of es of document id. What should i d

---

## [Connectivity issue in Filebeat and kafka server](https://discuss.elastic.co/t/connectivity-issue-in-filebeat-and-kafka-server/304037)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 2\
**Last updated:** [May 6, 2022, 5:17am UTC](https://discuss.elastic.co/t/connectivity-issue-in-filebeat-and-kafka-server/304037 "2022-05-06T05:17:25Z")

</div>

Hi, I'm using filebeat to send logs to Kafka topic. The source system is a server with an IP that is not static and it's an on-prem server. The destination server is a AWS Ec2 instance. Currently I'm not able to make co…

---

## [Prometheus module URL encoding](https://discuss.elastic.co/t/prometheus-module-url-encoding/304083)

<div class="topic-metadata">

**Author:** [@Yuvaraj1](https://discuss.elastic.co/u/Yuvaraj1)\
**Replies:** 0\
**Last updated:** [May 6, 2022, 4:12am UTC](https://discuss.elastic.co/t/prometheus-module-url-encoding/304083 "2022-05-06T04:12:40Z")

</div>

Version: 8.2.0 docker image The problem faced is that the url https://api.telemetry.confluent.cloud/v2/metrics/cloud/export?resource.kafka.id=AAABBBCCC when encoded ? as %3F causing a 404 error. How to pass query param…

---

## [Index Lifecycle Rollover Alias is Empty in Winlogbeat Indices](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-is-empty-in-winlogbeat-indices/302415)

<div class="topic-metadata">

**Author:** [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Replies:** 5\
**Last updated:** [May 6, 2022, 2:11am UTC](https://discuss.elastic.co/t/index-lifecycle-rollover-alias-is-empty-in-winlogbeat-indices/302415 "2022-05-06T02:11:54Z")

</div>

Hi, I'm having below errors "index.lifecycle.rollover\_alias" in winlogbeats indices. Index lifecycle error illegal\_argument\_exception: setting \[index.lifecycle.rollover\_alias\] for index \[winlogbeat-8.1.2-2022.04.14\] is…

---

## [Filebeat on RHEL7: Docker input not showing up in Kibana](https://discuss.elastic.co/t/filebeat-on-rhel7-docker-input-not-showing-up-in-kibana/303869)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 3\
**Last updated:** [May 5, 2022, 10:56pm UTC](https://discuss.elastic.co/t/filebeat-on-rhel7-docker-input-not-showing-up-in-kibana/303869 "2022-05-05T22:56:53Z")

</div>

I first set up and installed Filebeat, using RPM, on a Red Hat Linux VM with a plain filestream input, with path set to /var/log/redist\_6379.log. I then ran sudo service filebeat start and verified I can see log output …

---

## [Upgrade to Version 8](https://discuss.elastic.co/t/upgrade-to-version-8/304052)

<div class="topic-metadata">

**Author:** [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Replies:** 1\
**Last updated:** [May 5, 2022, 10:47pm UTC](https://discuss.elastic.co/t/upgrade-to-version-8/304052 "2022-05-05T22:47:59Z")

</div>

Hello, I want to upgrade the Elastic Stack to Version 8. Because we have some AIX Servers in our environment, I used the Beats that were made available by Bull Freeware some years ago and are running version 7.5.x. As …

---

## [Packetbeat Version 8.2 file size](https://discuss.elastic.co/t/packetbeat-version-8-2-file-size/304053)

<div class="topic-metadata">

**Author:** [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Replies:** 0\
**Last updated:** [May 5, 2022, 3:32pm UTC](https://discuss.elastic.co/t/packetbeat-version-8-2-file-size/304053 "2022-05-05T15:32:35Z")

</div>

What major changes have been made in version 8.2? The file size has changed from more than 80M in version 8.1.2 to 160M now.

---

## [File is not a certificate adding metricbeat issue](https://discuss.elastic.co/t/file-is-not-a-certificate-adding-metricbeat-issue/303951)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [May 5, 2022, 2:07pm UTC](https://discuss.elastic.co/t/file-is-not-a-certificate-adding-metricbeat-issue/303951 "2022-05-05T14:07:34Z")

</div>

Hello team, While starting metricbeat , i am getting below error. D:\\path\\cert.jks; file is not a certificate adding tomcat.yml module: # Module: tomcat # Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.5/…

---

## [\[filebeat\] - Json processor](https://discuss.elastic.co/t/filebeat-json-processor/303789)

<div class="topic-metadata">

**Author:** [@JH82](https://discuss.elastic.co/u/JH82)\
**Replies:** 1\
**Last updated:** [May 5, 2022, 1:20pm UTC](https://discuss.elastic.co/t/filebeat-json-processor/303789 "2022-05-05T13:20:15Z")

</div>

Hello, I try to make a JSON transform with processor in filebeat (with http\_endpoint as input). 2 questions : when I send a simple json message like {"message":"OK"} I receive : {"message": "success"} but I get man…

---

## [Dial tcp {kubelet\_ip}:10250 i/o timeout while trying to get Metricbeat to talk to Azure Kubernetes Service](https://discuss.elastic.co/t/dial-tcp-kubelet-ip-10250-i-o-timeout-while-trying-to-get-metricbeat-to-talk-to-azure-kubernetes-service/303874)

<div class="topic-metadata">

**Author:** [@surprised\_ferret](https://discuss.elastic.co/u/surprised_ferret)\
**Replies:** 5\
**Last updated:** [May 5, 2022, 12:33pm UTC](https://discuss.elastic.co/t/dial-tcp-kubelet-ip-10250-i-o-timeout-while-trying-to-get-metricbeat-to-talk-to-azure-kubernetes-service/303874 "2022-05-05T12:33:23Z")

</div>

Getting these errors when trying to install metricbeat as a daemonset using terraform. What could be the issue, metricbeat or AKS ? 2022-05-03T20:09:01.492Z ERROR module/wrapper.go:259 Error fetching data for metricset…

---

## [Windows server 2003 and Elastic agent](https://discuss.elastic.co/t/windows-server-2003-and-elastic-agent/304029)

<div class="topic-metadata">

**Author:** [@JimG](https://discuss.elastic.co/u/JimG)\
**Replies:** 0\
**Last updated:** [May 5, 2022, 12:10pm UTC](https://discuss.elastic.co/t/windows-server-2003-and-elastic-agent/304029 "2022-05-05T12:10:55Z")

</div>

Allright.. I know Windows server 2003 logs is not supported. But is it possible to solve? I use a powershell script to collect Windows server 2003 logs to a Windows server 2022 then Im using Elastic Agent with a custom…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=91)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=93)
