# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=93

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 94

---

## [Filebeats autodiscover on kubernetes doesn't collect logs from annotated pods](https://discuss.elastic.co/t/filebeats-autodiscover-on-kubernetes-doesnt-collect-logs-from-annotated-pods/304018)

<div class="topic-metadata">

**Author:** [@Ivan\_Kovacic](https://discuss.elastic.co/u/Ivan_Kovacic)\
**Replies:** 0\
**Last updated:** [May 5, 2022, 10:19am UTC](https://discuss.elastic.co/t/filebeats-autodiscover-on-kubernetes-doesnt-collect-logs-from-annotated-pods/304018 "2022-05-05T10:19:18Z")

</div>

Hi, I have an issue with filebeat when trying to collect logs from annotated pods, i have been following the documentation but without success. I am using filebeats 7.17 on kubernetes v1.21.5. This is my filebeat confi…

---

## [Attempting to acquire leader lease ... Get "https://10.43.0.1:443/apis/coordination.k8s.io/v1/namespaces/bilalnamespace/leases/metricbeat-cluster-leader": Forbidden](https://discuss.elastic.co/t/attempting-to-acquire-leader-lease-get-https-10-43-0-1-443-apis-coordination-k8s-io-v1-namespaces-bilalnamespace-leases-metricbeat-cluster-leader-forbidden/304012)

<div class="topic-metadata">

**Author:** [@Bilal\_El\_Mahdaoui](https://discuss.elastic.co/u/Bilal_El_Mahdaoui)\
**Replies:** 0\
**Last updated:** [May 5, 2022, 9:44am UTC](https://discuss.elastic.co/t/attempting-to-acquire-leader-lease-get-https-10-43-0-1-443-apis-coordination-k8s-io-v1-namespaces-bilalnamespace-leases-metricbeat-cluster-leader-forbidden/304012 "2022-05-05T09:44:43Z")

</div>

Hello, I want to monitor my Kubernetes cluster using metricbeat, and I'm using for that metricbeat autodiscover feature . Also I use a custom docker image based on my custom debian bullseye image. I made all the neces…

---

## [Organize Filebeat inputs and Directory Hierarchy](https://discuss.elastic.co/t/organize-filebeat-inputs-and-directory-hierarchy/303989)

<div class="topic-metadata">

**Author:** [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Replies:** 0\
**Last updated:** [May 5, 2022, 4:52am UTC](https://discuss.elastic.co/t/organize-filebeat-inputs-and-directory-hierarchy/303989 "2022-05-05T04:52:22Z")

</div>

The log files on my system are stored in the following manner. and these folders finally contain the log files (access, error, audit and csv files) that need to be parsed example: since it is realtime data, n…

---

## [Filebeat 7.17.2 not sending logs to kibana](https://discuss.elastic.co/t/filebeat-7-17-2-not-sending-logs-to-kibana/303590)

<div class="topic-metadata">

**Author:** [@njain213](https://discuss.elastic.co/u/njain213)\
**Replies:** 3\
**Last updated:** [May 5, 2022, 2:15am UTC](https://discuss.elastic.co/t/filebeat-7-17-2-not-sending-logs-to-kibana/303590 "2022-05-05T02:15:02Z")

</div>

Hi Team, I have upgraded filebeat from 5.6.5 to 7.17.2 in windows machine. Filebeat is running fine after upgrade but it is not sending logs to Kibana. When I reverted changes back to 5.6.5 , logs are coming to kibana s…

---

## [Unable to get event host.name in Metricbeat](https://discuss.elastic.co/t/unable-to-get-event-host-name-in-metricbeat/301490)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [May 4, 2022, 6:25pm UTC](https://discuss.elastic.co/t/unable-to-get-event-host-name-in-metricbeat/301490 "2022-05-04T18:25:28Z")

</div>

Hello All, I've written a javascript script processor in which I'm trying to get only those mount points which have reached thrshold greater than some value,ex:greater than 90 %\[kibana-\>panel filter-\> field \> 0.9\],The c…

---

## [\[threatintel Filebeat module\] MISP , not filtering attribites](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-not-filtering-attribites/303668)

<div class="topic-metadata">

**Author:** [@ibra\_013](https://discuss.elastic.co/u/ibra_013)\
**Replies:** 4\
**Last updated:** [May 4, 2022, 1:09pm UTC](https://discuss.elastic.co/t/threatintel-filebeat-module-misp-not-filtering-attribites/303668 "2022-05-04T13:09:42Z")

</div>

Hi team, i'm using the below config to filters some attributes type, but when i look at my index i find all the attributes types , is something i'm doing it wrong ? Filebeat 7.17.3 misp: enabled: true # Input…

---

## [Elasticsearch do not create index from Filebeat](https://discuss.elastic.co/t/elasticsearch-do-not-create-index-from-filebeat/303862)

<div class="topic-metadata">

**Author:** [@Hoa\_Nguy\_n\_Van](https://discuss.elastic.co/u/Hoa_Nguy_n_Van)\
**Replies:** 3\
**Last updated:** [May 4, 2022, 10:25am UTC](https://discuss.elastic.co/t/elasticsearch-do-not-create-index-from-filebeat/303862 "2022-05-04T10:25:20Z")

</div>

Hello, I have a problem in creating index json in filebeat. It can not parse log file. This is my log file: This is my filebeat config: This is announcement from filebeat: How can I solve this ? Please. And…

---

## [How to forward logs from specific file to Logstash](https://discuss.elastic.co/t/how-to-forward-logs-from-specific-file-to-logstash/303922)

<div class="topic-metadata">

**Author:** [@kirankatkar](https://discuss.elastic.co/u/kirankatkar)\
**Replies:** 0\
**Last updated:** [May 4, 2022, 9:24am UTC](https://discuss.elastic.co/t/how-to-forward-logs-from-specific-file-to-logstash/303922 "2022-05-04T09:24:06Z")

</div>

Hello All, I want help in below scenario: We want to integrate one SAAS based application with ELK. For that, using API calls we collected logs and dump into one \*.json file. (on Ubuntu server). Now we want to forward…

---

## [Issues with winlogbeat set up](https://discuss.elastic.co/t/issues-with-winlogbeat-set-up/303793)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [May 3, 2022, 6:59pm UTC](https://discuss.elastic.co/t/issues-with-winlogbeat-set-up/303793 "2022-05-03T18:59:07Z")

</div>

ES version 7.16.2, winlogbeat 7.16.1 Trying to get winlogbeat working on a new cluster. We seem to have got thought the setup phase and started to send data. Each event gets a warning (status=400): {"type":"illegal\_a…

---

## [Fortinet Logs Integration](https://discuss.elastic.co/t/fortinet-logs-integration/303788)

<div class="topic-metadata">

**Author:** [@jumpie](https://discuss.elastic.co/u/jumpie)\
**Replies:** 8\
**Last updated:** [May 3, 2022, 6:27pm UTC](https://discuss.elastic.co/t/fortinet-logs-integration/303788 "2022-05-03T18:27:15Z")

</div>

Hello, I've installed the Fortinet Logs Integration and configured the Fortigate to send syslogs for 9004. I was able to test that the Fortigate is sending logs but nothing shows up in Elastic. Is there something I am m…

---

## [Packetbeat on windows 10 : error connecting to kibana, fail to get the kibana version : HTTP GET request to http://192.168.217.128:5601](https://discuss.elastic.co/t/packetbeat-on-windows-10-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-192-168-217-128-5601/303655)

<div class="topic-metadata">

**Author:** [@TARIK\_MAZOUZ](https://discuss.elastic.co/u/TARIK_MAZOUZ)\
**Replies:** 21\
**Last updated:** [May 3, 2022, 5:17pm UTC](https://discuss.elastic.co/t/packetbeat-on-windows-10-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-192-168-217-128-5601/303655 "2022-05-03T17:17:34Z")

</div>

hey everybody, so i do have a problem with packetbeat in my windows 10 VM, so when i execute the command is powershell as an administrator , .\\packetbeat.exe setup -e , the error i get is : Exiting: error connecting to …

---

## [Error: Using autodiscovery on OpenShift/Kubernetes without granting node permission to SA](https://discuss.elastic.co/t/error-using-autodiscovery-on-openshift-kubernetes-without-granting-node-permission-to-sa/303819)

<div class="topic-metadata">

**Author:** [@helmen](https://discuss.elastic.co/u/helmen)\
**Replies:** 0\
**Last updated:** [May 3, 2022, 10:44am UTC](https://discuss.elastic.co/t/error-using-autodiscovery-on-openshift-kubernetes-without-granting-node-permission-to-sa/303819 "2022-05-03T10:44:32Z")

</div>

Hi, I want to upgrade from metricbeat 7.10.3 to 7.11+, including the autodiscovery feature on Openshift/Kubernetes, but always get the following error. E0503 09:16:45.462276 8 reflector.go:138\] pkg/mod/k8s.io/cli…

---

## [Elastic Agent Standalone Configuration Input types logFile and filestream difference](https://discuss.elastic.co/t/elastic-agent-standalone-configuration-input-types-logfile-and-filestream-difference/303773)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 0\
**Last updated:** [May 2, 2022, 8:16pm UTC](https://discuss.elastic.co/t/elastic-agent-standalone-configuration-input-types-logfile-and-filestream-difference/303773 "2022-05-02T20:16:44Z")

</div>

Elastic agent reference config file: Trying to setup standalone agent. came across few questions: In the inputs section, I have type as logFile and filestream, would like to know the difference and when to use which…

---

## [Grok pattern for date format](https://discuss.elastic.co/t/grok-pattern-for-date-format/302923)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 1\
**Last updated:** [May 2, 2022, 9:26pm UTC](https://discuss.elastic.co/t/grok-pattern-for-date-format/302923 "2022-05-02T21:26:39Z")

</div>

Hi, I am looking to ingest a custom set of logs and i need some help with a grok date format. I would like to convert the following date as the timestamp 19 April 2022 15:38:20 Any help would be appreciated. I have be…

---

## [Filebeat and Fortinet](https://discuss.elastic.co/t/filebeat-and-fortinet/303397)

<div class="topic-metadata">

**Author:** [@Christer\_Palmen](https://discuss.elastic.co/u/Christer_Palmen)\
**Replies:** 1\
**Last updated:** [May 2, 2022, 8:56pm UTC](https://discuss.elastic.co/t/filebeat-and-fortinet/303397 "2022-05-02T20:56:49Z")

</div>

Blockquote Hello. Filebeat seems to have built in Index patterns and templates for some Fortinet products, which is good from my point of view. What I would like to do is to instead of using the default index that F…

---

## [Packetbeat setup fail](https://discuss.elastic.co/t/packetbeat-setup-fail/303406)

<div class="topic-metadata">

**Author:** [@OBT](https://discuss.elastic.co/u/OBT)\
**Replies:** 3\
**Last updated:** [May 2, 2022, 4:21pm UTC](https://discuss.elastic.co/t/packetbeat-setup-fail/303406 "2022-05-02T16:21:34Z")

</div>

im trying to use packetbeat but i have some problem about the packetbeat.yml can someone help me thx!

---

## [Docker implementation - Filebeats 7.17.2 - drop\_events not working](https://discuss.elastic.co/t/docker-implementation-filebeats-7-17-2-drop-events-not-working/303647)

<div class="topic-metadata">

**Author:** [@amills157](https://discuss.elastic.co/u/amills157)\
**Replies:** 8\
**Last updated:** [May 1, 2022, 4:44pm UTC](https://discuss.elastic.co/t/docker-implementation-filebeats-7-17-2-drop-events-not-working/303647 "2022-05-01T16:44:06Z")

</div>

I am trying to setup filebeats to monitor some docker containers - I am using autodiscover, but I don't want to be logging anything from my stack (Elastic, Kibana, Filebeats itself). I have tried to use drop\_events but i…

---

## [Failed to start Filebeat MISP treats](https://discuss.elastic.co/t/failed-to-start-filebeat-misp-treats/303056)

<div class="topic-metadata">

**Author:** [@Tetsuho](https://discuss.elastic.co/u/Tetsuho)\
**Replies:** 5\
**Last updated:** [May 1, 2022, 1:54pm UTC](https://discuss.elastic.co/t/failed-to-start-filebeat-misp-treats/303056 "2022-05-01T13:54:50Z")

</div>

Hi Everyone im glad to be part of this comunity. Im here beacause a got a error message when I try to start the filebeat service after do some modifications related to a enable de MISP threat intel Logs. Here is the fil…

---

## [Filebeat not sending to Logstash until it's terminated](https://discuss.elastic.co/t/filebeat-not-sending-to-logstash-until-its-terminated/303565)

<div class="topic-metadata">

**Author:** [@alex\_london](https://discuss.elastic.co/u/alex_london)\
**Replies:** 5\
**Last updated:** [April 30, 2022, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-to-logstash-until-its-terminated/303565 "2022-04-30T17:07:28Z")

</div>

I've just started my Elastic Stack adventure and got myself stuck in what must be the simplest problem, but for the life of me cannot figure it out... My environment: Logstash 8.1.3 in Docker (Ubuntu 20.04) Filebeat 8…

---

## [How to get rid of event.original field?](https://discuss.elastic.co/t/how-to-get-rid-of-event-original-field/303604)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 6\
**Last updated:** [April 29, 2022, 3:03pm UTC](https://discuss.elastic.co/t/how-to-get-rid-of-event-original-field/303604 "2022-04-29T15:03:26Z")

</div>

After upgrading to ELK 8.1, I noticed that every event has the "event.original" field containing all of the log data. This is highly unwanted, how to prevent this field from being sent from Filebeat? I tried doing it on…

---

## [Log warning about missing Windows Events](https://discuss.elastic.co/t/log-warning-about-missing-windows-events/303600)

<div class="topic-metadata">

**Author:** [@Tadas](https://discuss.elastic.co/u/Tadas)\
**Replies:** 0\
**Last updated:** [April 29, 2022, 12:20pm UTC](https://discuss.elastic.co/t/log-warning-about-missing-windows-events/303600 "2022-04-29T12:20:55Z")

</div>

Hi! There is no good way to detect situations where Winlogbeat is starting up and unable to continue ingesting events from the last bookmarked position (i.e. event log has rolled forward and some events have been lost). …

---

## [\[Filebeat\]\[K8S\] How to process multiple types of logs (1 single + 2 different multiple lines) in one file?](https://discuss.elastic.co/t/filebeat-k8s-how-to-process-multiple-types-of-logs-1-single-2-different-multiple-lines-in-one-file/303160)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 2\
**Last updated:** [April 29, 2022, 10:51am UTC](https://discuss.elastic.co/t/filebeat-k8s-how-to-process-multiple-types-of-logs-1-single-2-different-multiple-lines-in-one-file/303160 "2022-04-29T10:51:24Z")

</div>

Hello guys, can anyone give me tip how to process multiple types of logs in one file for this usecase: In the log file I have 3 types of log: 1) PHP-FPM Access log (is single-line) 10.102.0.141 - 25/Apr/2022:11:17:5…

---

## [Netflow application ID to application name](https://discuss.elastic.co/t/netflow-application-id-to-application-name/303549)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [April 28, 2022, 6:51pm UTC](https://discuss.elastic.co/t/netflow-application-id-to-application-name/303549 "2022-04-28T18:51:10Z")

</div>

Im getting netflow data from multiples machines using filebeat, one of the fields I get is netflow.application\_id and I need to transate the Id to the name of the application, the format of the application\_id is this: 3,…

---

## [Events time difference between event.created and event.ingested](https://discuss.elastic.co/t/events-time-difference-between-event-created-and-event-ingested/303269)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 12\
**Last updated:** [April 28, 2022, 12:44pm UTC](https://discuss.elastic.co/t/events-time-difference-between-event-created-and-event-ingested/303269 "2022-04-28T12:44:40Z")

</div>

Hello, I am using elk stack v8. traffic is flowing winlog-\>kafka - \> logstash -\> Elasticsearch. there is a time difference between "event created" and "event.ingest". the time difference is around 1 hour. Logstash co…

---

## [Metricbeat on Kubernetes does not work with conditions](https://discuss.elastic.co/t/metricbeat-on-kubernetes-does-not-work-with-conditions/303506)

<div class="topic-metadata">

**Author:** [@melkamar](https://discuss.elastic.co/u/melkamar)\
**Replies:** 0\
**Last updated:** [April 28, 2022, 11:54am UTC](https://discuss.elastic.co/t/metricbeat-on-kubernetes-does-not-work-with-conditions/303506 "2022-04-28T11:54:09Z")

</div>

Hi! I want to set up a metricbeat data collection for some pods in my cluster. I already have a working filebeat configuration where I collect logs from certain pods based on autodiscover template conditions. But the sam…

---

## [Stack Monitoring with elastic agent / fleet?](https://discuss.elastic.co/t/stack-monitoring-with-elastic-agent-fleet/303266)

<div class="topic-metadata">

**Author:** [@gabrielfsousa](https://discuss.elastic.co/u/gabrielfsousa)\
**Replies:** 1\
**Last updated:** [April 28, 2022, 2:19am UTC](https://discuss.elastic.co/t/stack-monitoring-with-elastic-agent-fleet/303266 "2022-04-28T02:19:29Z")

</div>

Can we Stack Monitoring with elastic agent / fleet ?

---

## [Winlogbeat experimental api missmatch between paresed fields and rendered event](https://discuss.elastic.co/t/winlogbeat-experimental-api-missmatch-between-paresed-fields-and-rendered-event/303388)

<div class="topic-metadata">

**Author:** [@SH\_HSOC](https://discuss.elastic.co/u/SH_HSOC)\
**Replies:** 4\
**Last updated:** [April 27, 2022, 5:18pm UTC](https://discuss.elastic.co/t/winlogbeat-experimental-api-missmatch-between-paresed-fields-and-rendered-event/303388 "2022-04-27T17:18:49Z")

</div>

Hi folks, in Winlogbeat I recently switched from the default windows event log API to the experimental one, because winlogbeat was capping out at roughly 1800 events per second and our Windows event collector getting a …

---

## [Filebeat HAProxy module does not parse tcplog format](https://discuss.elastic.co/t/filebeat-haproxy-module-does-not-parse-tcplog-format/303422)

<div class="topic-metadata">

**Author:** [@CaptAintHere](https://discuss.elastic.co/u/CaptAintHere)\
**Replies:** 0\
**Last updated:** [April 27, 2022, 2:55pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-does-not-parse-tcplog-format/303422 "2022-04-27T14:55:18Z")

</div>

Hi, I'm trying to use the HAProxy module of Filebeat with a TCP frontend in HAProxy but the grok does not seem to work with the log lines generated by the option tcplog of HAProxy. This GitHub issue mentions that the o…

---

## [Filebeat Harvester not starting](https://discuss.elastic.co/t/filebeat-harvester-not-starting/302891)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 3\
**Last updated:** [April 27, 2022, 1:05pm UTC](https://discuss.elastic.co/t/filebeat-harvester-not-starting/302891 "2022-04-27T13:05:36Z")

</div>

Hello, We have installed Filebeat on docker container connecting to logstah on linux server. It was working fine till a week back. AWS machine got restarted and post that, logstash is not harvesting new files. Harvester…

---

## [Filebeat is connected to Kafka, but it doesn't send Log](https://discuss.elastic.co/t/filebeat-is-connected-to-kafka-but-it-doesnt-send-log/303302)

<div class="topic-metadata">

**Author:** [@CemG](https://discuss.elastic.co/u/CemG)\
**Replies:** 6\
**Last updated:** [April 27, 2022, 9:41am UTC](https://discuss.elastic.co/t/filebeat-is-connected-to-kafka-but-it-doesnt-send-log/303302 "2022-04-27T09:41:37Z")

</div>

Hello, It is been 2 days that I have this issue. I would like to send log from a computer to elastic by the following way : Filebeat → Kafka → Logstash → Elasticsearch But Filebeat do not send log to Kafka and I don'…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=92)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=94)
