# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=95

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 96

---

## [High memory usage of Metricbeat in Kubernetes](https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/301961)

<div class="topic-metadata">

**Author:** [@melkamar](https://discuss.elastic.co/u/melkamar)\
**Replies:** 2\
**Last updated:** [April 20, 2022, 7:05am UTC](https://discuss.elastic.co/t/high-memory-usage-of-metricbeat-in-kubernetes/301961 "2022-04-20T07:05:16Z")

</div>

I am trying out collecting metrics and logs from pods in our staging Kubernetes cluster. I have followed the instructions here: Run Metricbeat on Kubernetes | Metricbeat Reference \[8.1\] | Elastic The cluster has two nod…

---

## [Heartbeat download for Windows is actually for Linux/Unix](https://discuss.elastic.co/t/heartbeat-download-for-windows-is-actually-for-linux-unix/302646)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 3\
**Last updated:** [April 19, 2022, 2:20pm UTC](https://discuss.elastic.co/t/heartbeat-download-for-windows-is-actually-for-linux-unix/302646 "2022-04-19T14:20:08Z")

</div>

This page says to download the Windows zip file But the download page does not have a zip file. It defaults to RPM I downloaded the RPM file to the Windows server and used 7Zip to extract it. The extracted file is …

---

## [How to use filebeat to process file that is not log file](https://discuss.elastic.co/t/how-to-use-filebeat-to-process-file-that-is-not-log-file/302706)

<div class="topic-metadata">

**Author:** [@blumre](https://discuss.elastic.co/u/blumre)\
**Replies:** 1\
**Last updated:** [April 19, 2022, 11:07am UTC](https://discuss.elastic.co/t/how-to-use-filebeat-to-process-file-that-is-not-log-file/302706 "2022-04-19T11:07:03Z")

</div>

Hi, I want to collect by filebeat also specific configuration file structured as key=value lines so will be able to use it in Kibana dashboard. I managed to do it for the first time it reads the file but if the file cha…

---

## [MongoDB Metricbeat Module](https://discuss.elastic.co/t/mongodb-metricbeat-module/301098)

<div class="topic-metadata">

**Author:** [@maltewhiite](https://discuss.elastic.co/u/maltewhiite)\
**Replies:** 1\
**Last updated:** [April 19, 2022, 6:29am UTC](https://discuss.elastic.co/t/mongodb-metricbeat-module/301098 "2022-04-19T06:29:26Z")

</div>

mongodb.collstats.insert.count How many X documents are we inserting per Y time in our MongoDB Cluster. And how do I visualize that? What does mongodb.collstats.insert.count show? The Documentation only says: Is i…

---

## [Filebeat 8.1.2 @timestamp off](https://discuss.elastic.co/t/filebeat-8-1-2-timestamp-off/302653)

<div class="topic-metadata">

**Author:** [@afmiller1](https://discuss.elastic.co/u/afmiller1)\
**Replies:** 0\
**Last updated:** [April 18, 2022, 11:00pm UTC](https://discuss.elastic.co/t/filebeat-8-1-2-timestamp-off/302653 "2022-04-18T23:00:39Z")

</div>

Looking at the discovery tab for my filebeat netflow ingestion, it is showing that it’s almost 2:30h behind my current local time. Tried restarting the service with no luck. How do I get the time to update properly?

---

## [Collect logs from Amazon CloudWatch with Elastic Agent](https://discuss.elastic.co/t/collect-logs-from-amazon-cloudwatch-with-elastic-agent/302648)

<div class="topic-metadata">

**Author:** [@spo](https://discuss.elastic.co/u/spo)\
**Replies:** 2\
**Last updated:** [April 18, 2022, 9:59pm UTC](https://discuss.elastic.co/t/collect-logs-from-amazon-cloudwatch-with-elastic-agent/302648 "2022-04-18T21:59:39Z")

</div>

Hi I am trying to pull cloudwatch logs with elastic agent. I have elastic agent running on a windows server. It has the default policy attached to it. To the default policy I have added AWS integration , iis-logs integ…

---

## [Error running winlogbeat setup on windows host](https://discuss.elastic.co/t/error-running-winlogbeat-setup-on-windows-host/302635)

<div class="topic-metadata">

**Author:** [@randyhaley](https://discuss.elastic.co/u/randyhaley)\
**Replies:** 0\
**Last updated:** [April 18, 2022, 4:15pm UTC](https://discuss.elastic.co/t/error-running-winlogbeat-setup-on-windows-host/302635 "2022-04-18T16:15:25Z")

</div>

I am attempting to run the winlogbeat.exe setup -e command from my windows machine. ES/Kibana is in the AWS cloud and I am connecting via the public dns of my AWS instance. When I run the setup command, it states that th…

---

## [Harvester not started for new files in configured paths](https://discuss.elastic.co/t/harvester-not-started-for-new-files-in-configured-paths/294332)

<div class="topic-metadata">

**Author:** [@dchsueh](https://discuss.elastic.co/u/dchsueh)\
**Replies:** 7\
**Last updated:** [April 18, 2022, 3:19pm UTC](https://discuss.elastic.co/t/harvester-not-started-for-new-files-in-configured-paths/294332 "2022-04-18T15:19:48Z")

</div>

Hello, I have a problem I've verified in filebeat 6.8.3, 7.5.1, and 7.16.3 I have a filebeat.yml filebeat.inputs, type log, with three configured paths with \*\* in the middle portions, something like - /var/log/a/b/\*…

---

## [Run filebeat setup fail](https://discuss.elastic.co/t/run-filebeat-setup-fail/302626)

<div class="topic-metadata">

**Author:** [@The-morpho](https://discuss.elastic.co/u/The-morpho)\
**Replies:** 0\
**Last updated:** [April 18, 2022, 2:18pm UTC](https://discuss.elastic.co/t/run-filebeat-setup-fail/302626 "2022-04-18T14:18:09Z")

</div>

Hi i just install elasticsearch and kibana on docker, i want to work with filebeat, so i followed the official documentation Run filebeat setup So i run this command: docker run docker.elastic.co/beats/filebeat:8.1.2 …

---

## [Filebeat 8.1.2 - cisco module is not creating neither index nor data stream after I deleted the first data stream, index template, index pattern and pipeline to start all over](https://discuss.elastic.co/t/filebeat-8-1-2-cisco-module-is-not-creating-neither-index-nor-data-stream-after-i-deleted-the-first-data-stream-index-template-index-pattern-and-pipeline-to-start-all-over/302359)

<div class="topic-metadata">

**Author:** [@Adrian\_Gtz](https://discuss.elastic.co/u/Adrian_Gtz)\
**Replies:** 1\
**Last updated:** [April 18, 2022, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-8-1-2-cisco-module-is-not-creating-neither-index-nor-data-stream-after-i-deleted-the-first-data-stream-index-template-index-pattern-and-pipeline-to-start-all-over/302359 "2022-04-18T12:56:41Z")

</div>

I enabled cisco module and set up filebeat.yml to output Elasticsearch with user and password. At the begining everything went well. But I decided to start all over and when I deleted the data stream, related index templ…

---

## [CPU becomes overloaded when rebooting OS](https://discuss.elastic.co/t/cpu-becomes-overloaded-when-rebooting-os/302612)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 0\
**Last updated:** [April 18, 2022, 10:32am UTC](https://discuss.elastic.co/t/cpu-becomes-overloaded-when-rebooting-os/302612 "2022-04-18T10:32:58Z")

</div>

We have CentOS6.9 with Filebeat 7.12.1 installed. It has been working normally, but the CPU load increased dramatically when the OS was rebooted. As soon as we stopped Filebeat, the CPU load dropped, so we believe that…

---

## [Unable to use of beats (here journalbeat) with AWS ElasticSearch 7.10](https://discuss.elastic.co/t/unable-to-use-of-beats-here-journalbeat-with-aws-elasticsearch-7-10/301062)

<div class="topic-metadata">

**Author:** [@obourdon](https://discuss.elastic.co/u/obourdon)\
**Replies:** 3\
**Last updated:** [April 18, 2022, 6:58am UTC](https://discuss.elastic.co/t/unable-to-use-of-beats-here-journalbeat-with-aws-elasticsearch-7-10/301062 "2022-04-18T06:58:54Z")

</div>

Reopening this as my previous entry was closed for what I consider as a wrong reason not leading to any helpful answer/solution As detailed in Unable to use of beats (here journalbeat) with AWS ElasticSearch 7.x · Issu…

---

## [Filebeat load json file like bulk mode](https://discuss.elastic.co/t/filebeat-load-json-file-like-bulk-mode/302504)

<div class="topic-metadata">

**Author:** [@walid\_louis](https://discuss.elastic.co/u/walid_louis)\
**Replies:** 7\
**Last updated:** [April 16, 2022, 6:24pm UTC](https://discuss.elastic.co/t/filebeat-load-json-file-like-bulk-mode/302504 "2022-04-16T18:24:05Z")

</div>

Hey Everybody, i have worked with Elasticsearch on inserting data with the \_bulk mode with the Api(json ) , and now i want to insert data with the Filebeat loading file with the same json used with bulk mode..... and h…

---

## [Checking log parsing using the Simulate API](https://discuss.elastic.co/t/checking-log-parsing-using-the-simulate-api/302518)

<div class="topic-metadata">

**Author:** [@aleding](https://discuss.elastic.co/u/aleding)\
**Replies:** 10\
**Last updated:** [April 15, 2022, 11:58pm UTC](https://discuss.elastic.co/t/checking-log-parsing-using-the-simulate-api/302518 "2022-04-15T23:58:17Z")

</div>

Disclaimer: As with the OP of the linked thread, I too am learning but the Simulate API is a little confusing to me so apologies for my noobiness. Thank you in advance for your insights and feedback. In this thread ES …

---

## [Is there another way to import template at boot?](https://discuss.elastic.co/t/is-there-another-way-to-import-template-at-boot/301544)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 4\
**Last updated:** [April 15, 2022, 10:35am UTC](https://discuss.elastic.co/t/is-there-another-way-to-import-template-at-boot/301544 "2022-04-15T10:35:06Z")

</div>

Hey there, I am configuring several Beats with a custom mapping. I would just to know if there is another way to load custom template (setup.template.\*) at startup or I must use the fields.yml file. I mean, if I have hu…

---

## [Unable to get autodiscover to play nice with mongodb using a kubernetes provider](https://discuss.elastic.co/t/unable-to-get-autodiscover-to-play-nice-with-mongodb-using-a-kubernetes-provider/302474)

<div class="topic-metadata">

**Author:** [@Renato\_D](https://discuss.elastic.co/u/Renato_D)\
**Replies:** 0\
**Last updated:** [April 14, 2022, 10:48pm UTC](https://discuss.elastic.co/t/unable-to-get-autodiscover-to-play-nice-with-mongodb-using-a-kubernetes-provider/302474 "2022-04-14T22:48:15Z")

</div>

Metricbeat: 7.10.2 We have several mongodb instances across many clusters and would like to enhance the metrics output of all our mongo pods so we can start making some pretty graphs. I've been trying, in vein, to get …

---

## [Not fetching Data streams](https://discuss.elastic.co/t/not-fetching-data-streams/302448)

<div class="topic-metadata">

**Author:** [@spo](https://discuss.elastic.co/u/spo)\
**Replies:** 1\
**Last updated:** [April 14, 2022, 3:46pm UTC](https://discuss.elastic.co/t/not-fetching-data-streams/302448 "2022-04-14T15:46:24Z")

</div>

Hi I have a fleet server , status : healthy. I have added AWS and IIS integrations to the agent policy( Default Fleet Server policy) of the fleet server but I do not see any logs pulling in the data stream pane from th…

---

## [Filebeat Barracuda module](https://discuss.elastic.co/t/filebeat-barracuda-module/300008)

<div class="topic-metadata">

**Author:** [@janis.cimins](https://discuss.elastic.co/u/janis.cimins)\
**Replies:** 4\
**Last updated:** [April 14, 2022, 6:34am UTC](https://discuss.elastic.co/t/filebeat-barracuda-module/300008 "2022-04-14T06:34:55Z")

</div>

Hello! I have a problem with ingest barracuda logs. But I have trouble on setting up barracuda module. It gives me this error when I enable module and run "sudo filebeat setup -e" 2022-03-15T15:32:39.986Z ERROR instanc…

---

## [Problems getting logs in with winlogbeat](https://discuss.elastic.co/t/problems-getting-logs-in-with-winlogbeat/302169)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 10\
**Last updated:** [April 13, 2022, 8:56pm UTC](https://discuss.elastic.co/t/problems-getting-logs-in-with-winlogbeat/302169 "2022-04-13T20:56:38Z")

</div>

ES version 7.16.2 trying to upload sysmon data using winlogbeat. Cluster has "security" enabled and the winlogbeat clients are now connecting an there are no errors in the ES logs. We are using API keys -- this took so…

---

## [Filebeat hangs on Windows Server](https://discuss.elastic.co/t/filebeat-hangs-on-windows-server/300654)

<div class="topic-metadata">

**Author:** [@Cuong\_Hoang](https://discuss.elastic.co/u/Cuong_Hoang)\
**Replies:** 0\
**Last updated:** [March 25, 2022, 3:23am UTC](https://discuss.elastic.co/t/filebeat-hangs-on-windows-server/300654 "2022-03-25T03:23:50Z")

</div>

Hi all. I have a problem with beats (winlogbeat, filebeat) on Windows Server 2016. I use filebeat to collect IIS logs. Server information: OS Name: Microsoft Windows Server 2016 Standard OS Version: 10.0.14393 N/A Bu…

---

## [Winlogbeat & Logstash - Ingest Pipelines](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758)

<div class="topic-metadata">

**Author:** [@bct.timo.crabbe](https://discuss.elastic.co/u/bct.timo.crabbe)\
**Replies:** 4\
**Last updated:** [April 13, 2022, 6:31pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758 "2022-04-13T18:31:39Z")

</div>

Hi everyone, I am having an issue with the ingest pipelines for powershell while using winlogbeat and the logstash output (both version 8.1.0). The powershell events seem not to be processed by the pipeline. There is a…

---

## [Beats in elastic-agent reporting "failed to connect to backoff"](https://discuss.elastic.co/t/beats-in-elastic-agent-reporting-failed-to-connect-to-backoff/299506)

<div class="topic-metadata">

**Author:** [@trudyc](https://discuss.elastic.co/u/trudyc)\
**Replies:** 5\
**Last updated:** [April 13, 2022, 5:16pm UTC](https://discuss.elastic.co/t/beats-in-elastic-agent-reporting-failed-to-connect-to-backoff/299506 "2022-04-13T17:16:47Z")

</div>

Apologies in advance if I ask ignorant questions, or don't provide all relevant info in my post. I'm not an expert sysadmin, or network admin, or security admin. I've inherited Elastic from a departed co-worker, and have…

---

## [Fleet Server - Waiting on default policy with Fleet Server integration](https://discuss.elastic.co/t/fleet-server-waiting-on-default-policy-with-fleet-server-integration/302281)

<div class="topic-metadata">

**Author:** [@tirelibirefe](https://discuss.elastic.co/u/tirelibirefe)\
**Replies:** 0\
**Last updated:** [April 12, 2022, 11:13pm UTC](https://discuss.elastic.co/t/fleet-server-waiting-on-default-policy-with-fleet-server-integration/302281 "2022-04-12T23:13:25Z")

</div>

Hello, I am not able to run Fleet. Probably I miss something but not sure; tried also quickstart yaml files, and I got the same result. Kibana Config: apiVersion: kibana.k8s.elastic.co/v1 kind: Kibana metadata: name…

---

## [Error running sudo filebeat setup command](https://discuss.elastic.co/t/error-running-sudo-filebeat-setup-command/302273)

<div class="topic-metadata">

**Author:** [@LeonardoCoco](https://discuss.elastic.co/u/LeonardoCoco)\
**Replies:** 1\
**Last updated:** [April 13, 2022, 4:51pm UTC](https://discuss.elastic.co/t/error-running-sudo-filebeat-setup-command/302273 "2022-04-13T16:51:33Z")

</div>

I'm configuring Elasticsearch, Kibana and Filebeat from scratch. I have already configured the Elasticsearch.yam, kibana.yam files and I am finishing the filebeat installation, but when executing the command below, the …

---

## [Change data stream name in filebeat 8.\*](https://discuss.elastic.co/t/change-data-stream-name-in-filebeat-8/301531)

<div class="topic-metadata">

**Author:** [@Andres\_Altamirano](https://discuss.elastic.co/u/Andres_Altamirano)\
**Replies:** 6\
**Last updated:** [April 13, 2022, 3:58pm UTC](https://discuss.elastic.co/t/change-data-stream-name-in-filebeat-8/301531 "2022-04-13T15:58:35Z")

</div>

We used to store filebeat data from different sources in a different index due to storage size and document category using different ILM policies. Now we can't do that because if we use ILM, we can't change the index na…

---

## [How parse mysql slow queries into elastic](https://discuss.elastic.co/t/how-parse-mysql-slow-queries-into-elastic/302364)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 0\
**Last updated:** [April 13, 2022, 4:01pm UTC](https://discuss.elastic.co/t/how-parse-mysql-slow-queries-into-elastic/302364 "2022-04-13T16:01:24Z")

</div>

Hi, I have a mysql in GCP to which I have already configured a sink to pubsub and from a VM with filebeat installed I am able to send the slow queries that reach me to the pubsub to elastic. My problem is that the slow…

---

## [Heartbeat 8.1.0 Kubernetes Autodiscovery Memory Leak](https://discuss.elastic.co/t/heartbeat-8-1-0-kubernetes-autodiscovery-memory-leak/300543)

<div class="topic-metadata">

**Author:** [@Protopopys](https://discuss.elastic.co/u/Protopopys)\
**Replies:** 6\
**Last updated:** [April 13, 2022, 3:18pm UTC](https://discuss.elastic.co/t/heartbeat-8-1-0-kubernetes-autodiscovery-memory-leak/300543 "2022-04-13T15:18:24Z")

</div>

Hello Heartbeat 8.1.0 has a memory leak with enabled Kubernetes autodiscovery and Openshift kills the container on memory limit reached. We have the issue on all Openshift nodes. Heartbeat Version: 8.1.0 Openshif…

---

## [Calculate difference between current and previous values](https://discuss.elastic.co/t/calculate-difference-between-current-and-previous-values/302237)

<div class="topic-metadata">

**Author:** [@700grm](https://discuss.elastic.co/u/700grm)\
**Replies:** 1\
**Last updated:** [April 13, 2022, 12:11pm UTC](https://discuss.elastic.co/t/calculate-difference-between-current-and-previous-values/302237 "2022-04-13T12:11:09Z")

</div>

Hi, I'm trying to create Watcher Alert for dropped packets system.network.in.dropped (the system metrics are shipped with Metricbeats) if more than 50 dropped packets are present alert should be generated. To do this I n…

---

## [Missing Datastreams in Fleet UI](https://discuss.elastic.co/t/missing-datastreams-in-fleet-ui/302326)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 0\
**Last updated:** [April 13, 2022, 12:04pm UTC](https://discuss.elastic.co/t/missing-datastreams-in-fleet-ui/302326 "2022-04-13T12:04:04Z")

</div>

Somehow my Fleet Managed Data Streams have gone missing in the UI, despite everything else working, the data exists.

---

## [file.name":"module/wrapper.go","file.line":259},"message":"Error fetching data for metricset kibana.status: error making http request: Get \\"https://kibana/api/status\\": x509: certificate signed by unknown authority](https://discuss.elastic.co/t/file-name-module-wrapper-go-file-line-259-message-error-fetching-data-for-metricset-kibana-status-error-making-http-request-get-https-kibana-api-status-x509-certificate-signed-by-unknown-authority/302304)

<div class="topic-metadata">

**Author:** [@gabrielfsousa](https://discuss.elastic.co/u/gabrielfsousa)\
**Replies:** 0\
**Last updated:** [April 13, 2022, 8:47am UTC](https://discuss.elastic.co/t/file-name-module-wrapper-go-file-line-259-message-error-fetching-data-for-metricset-kibana-status-error-making-http-request-get-https-kibana-api-status-x509-certificate-signed-by-unknown-authority/302304 "2022-04-13T08:47:16Z")

</div>

Im using fleet server and elastic agent to monitoring kibana, i have cert error fleet server is running in a container bootstrap with ansible env: FLEET\_SERVER\_ENABLE: "1" FLEET\_URL: "{{ docker\_fleet\_serv…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=94)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=96)
