# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=96

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 97

---

## [Filebeat condition](https://discuss.elastic.co/t/filebeat-condition/302225)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 0\
**Last updated:** [April 12, 2022, 12:28pm UTC](https://discuss.elastic.co/t/filebeat-condition/302225 "2022-04-12T12:28:35Z")

</div>

Hi, I use filebeat to read logs from different paths so for example filebeat.yml filebeat.inputs: - type: log enabled: true paths: - D:\\elastic\_stack\\LOGS\\test-LOGS1\\\* fields: kafka\_topic: "kafka-top…

---

## [Heartbeat doesn't discover anything on Kubernetes](https://discuss.elastic.co/t/heartbeat-doesnt-discover-anything-on-kubernetes/301819)

<div class="topic-metadata">

**Author:** [@tirelibirefe](https://discuss.elastic.co/u/tirelibirefe)\
**Replies:** 4\
**Last updated:** [April 12, 2022, 11:07pm UTC](https://discuss.elastic.co/t/heartbeat-doesnt-discover-anything-on-kubernetes/301819 "2022-04-12T23:07:18Z")

</div>

Hello, I've Elastic Stack 8.1 installed. This is my heartbeat config below: heartbeat.yml: |- heartbeat.autodiscover: # Autodiscover pods providers: - type: kubernetes resource: pod …

---

## [Metricbeat Cluster Monitoring: logstash.node: Could not find field 'id' in Logstash API response](https://discuss.elastic.co/t/metricbeat-cluster-monitoring-logstash-node-could-not-find-field-id-in-logstash-api-response/299651)

<div class="topic-metadata">

**Author:** [@marcus\_lhisp](https://discuss.elastic.co/u/marcus_lhisp)\
**Replies:** 16\
**Last updated:** [April 12, 2022, 6:36pm UTC](https://discuss.elastic.co/t/metricbeat-cluster-monitoring-logstash-node-could-not-find-field-id-in-logstash-api-response/299651 "2022-04-12T18:36:41Z")

</div>

Hello Community, Today I've upgraded our ELK Stack from 8.0 to 8.1. Since then the metricbeat, running on the logstash node, started to log something that I wasn't able to figure out by myself with my "Google-fu". Bes…

---

## [Handling multiline with filebeat](https://discuss.elastic.co/t/handling-multiline-with-filebeat/301000)

<div class="topic-metadata">

**Author:** [@stecino](https://discuss.elastic.co/u/stecino)\
**Replies:** 7\
**Last updated:** [April 12, 2022, 5:05pm UTC](https://discuss.elastic.co/t/handling-multiline-with-filebeat/301000 "2022-04-12T17:05:12Z")

</div>

Hello, I have the following snippet, and I am trying to capture all of it as a multiline \<\< JESI\>\> \[ERROR\] \[TIME:29 Mar 2022 04:34:53\]\[Tid:OUTBOUND\_RECOVERY\_01339\]Exception @\[NodeId=6;Element=Channel@amdocs/eai/adaptor…

---

## [Elastic agent is unable to enroll to fleet](https://discuss.elastic.co/t/elastic-agent-is-unable-to-enroll-to-fleet/301679)

<div class="topic-metadata">

**Author:** [@spo](https://discuss.elastic.co/u/spo)\
**Replies:** 21\
**Last updated:** [April 12, 2022, 2:59pm UTC](https://discuss.elastic.co/t/elastic-agent-is-unable-to-enroll-to-fleet/301679 "2022-04-12T14:59:21Z")

</div>

Hi I have used this documentation to setup fleet but when I try to do the 2nd step in that document to add elastic agent to the fleet am getting an error 2022-04-05T21:42:01.934Z WARN \[tls\] tlscommon/tl…

---

## [Network Interface Monitoring: interface Up/Down alert](https://discuss.elastic.co/t/network-interface-monitoring-interface-up-down-alert/301767)

<div class="topic-metadata">

**Author:** [@700grm](https://discuss.elastic.co/u/700grm)\
**Replies:** 1\
**Last updated:** [April 12, 2022, 12:50pm UTC](https://discuss.elastic.co/t/network-interface-monitoring-interface-up-down-alert/301767 "2022-04-12T12:50:50Z")

</div>

Hi, I'm new to Elastic. I'm looking into Beats agents for network interface monitoring: if the interface is up or down. However I don't see any relevant fields that can be used to do this job, I will appreciate any help. …

---

## [Winlogbeat - not getting all the logs](https://discuss.elastic.co/t/winlogbeat-not-getting-all-the-logs/302222)

<div class="topic-metadata">

**Author:** [@Gadula](https://discuss.elastic.co/u/Gadula)\
**Replies:** 0\
**Last updated:** [April 12, 2022, 12:11pm UTC](https://discuss.elastic.co/t/winlogbeat-not-getting-all-the-logs/302222 "2022-04-12T12:11:11Z")

</div>

Hello, I am newbie in Kibana, Elasticsearch and rest of tools in stack. So I'm not sure is the problem with Winlogbeat. I have installed Winlogbeat on my servers and I am getting the logs correctly. They are visible i…

---

## [Collecting logstash stats on K8S with metricbeat](https://discuss.elastic.co/t/collecting-logstash-stats-on-k8s-with-metricbeat/302207)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [April 12, 2022, 10:05am UTC](https://discuss.elastic.co/t/collecting-logstash-stats-on-k8s-with-metricbeat/302207 "2022-04-12T10:05:00Z")

</div>

Hi, I am just starting to move our stack to a containerised environment using K8S. It's all going well so far with Elasticsearch, Kibana and Logstash all running. I usually monitor our logstash pipelines with metricbe…

---

## [Filebeat.sock file do not exists anymore when deploy and configure elastic-agent using Ansible](https://discuss.elastic.co/t/filebeat-sock-file-do-not-exists-anymore-when-deploy-and-configure-elastic-agent-using-ansible/301992)

<div class="topic-metadata">

**Author:** [@Danny\_Dumenigo](https://discuss.elastic.co/u/Danny_Dumenigo)\
**Replies:** 13\
**Last updated:** [April 11, 2022, 8:17pm UTC](https://discuss.elastic.co/t/filebeat-sock-file-do-not-exists-anymore-when-deploy-and-configure-elastic-agent-using-ansible/301992 "2022-04-11T20:17:44Z")

</div>

Hello Community: Im triying to automate the deployment of elastic-agents using Ansible. I have two roles for this. Using the first, I enroll the agent using the respective command, all well until this point. The agent …

---

## [Elastic Agent Doesn't Seem to Restart ElasticEndpoint Security Service](https://discuss.elastic.co/t/elastic-agent-doesnt-seem-to-restart-elasticendpoint-security-service/302131)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [April 11, 2022, 3:55pm UTC](https://discuss.elastic.co/t/elastic-agent-doesnt-seem-to-restart-elasticendpoint-security-service/302131 "2022-04-11T15:55:46Z")

</div>

Hi All, I was recently doing some troubleshooting with a degraded Elastic Agent install, and I noticed that when you restart the elastic-agent it doesn't actually cause a restart of the Elastic Endpoint service, therefo…

---

## [Filebeat harvesting only its own logs not other service on Nomad Cluster](https://discuss.elastic.co/t/filebeat-harvesting-only-its-own-logs-not-other-service-on-nomad-cluster/302125)

<div class="topic-metadata">

**Author:** [@Uzmasaman\_Chanderki](https://discuss.elastic.co/u/Uzmasaman_Chanderki)\
**Replies:** 0\
**Last updated:** [April 11, 2022, 3:25pm UTC](https://discuss.elastic.co/t/filebeat-harvesting-only-its-own-logs-not-other-service-on-nomad-cluster/302125 "2022-04-11T15:25:08Z")

</div>

I have filebeat running on Nomad cluster. It is only sending its own logs to the central server. There are other services running too but its unable to harvest their logs. Can anyone suggest what could be the problem? T…

---

## [Request: OpenVPN integration](https://discuss.elastic.co/t/request-openvpn-integration/302119)

<div class="topic-metadata">

**Author:** [@sculptordwarf](https://discuss.elastic.co/u/sculptordwarf)\
**Replies:** 0\
**Last updated:** [April 11, 2022, 2:50pm UTC](https://discuss.elastic.co/t/request-openvpn-integration/302119 "2022-04-11T14:50:58Z")

</div>

Request for adding OpenVPN logs as a supported integration.

---

## [Migrating from logstash to filebeat with field continent code](https://discuss.elastic.co/t/migrating-from-logstash-to-filebeat-with-field-continent-code/302111)

<div class="topic-metadata">

**Author:** [@jhaos](https://discuss.elastic.co/u/jhaos)\
**Replies:** 0\
**Last updated:** [April 11, 2022, 2:09pm UTC](https://discuss.elastic.co/t/migrating-from-logstash-to-filebeat-with-field-continent-code/302111 "2022-04-11T14:09:01Z")

</div>

Hi, I'm currently using in my environment for ingestion filebeat\>logstash\>Elasticsearch, in order to reduce the resources we are going to take out logstash and start using filebeat instead directly to ingest the data to …

---

## [Elastic fleet change datastream name based on field value](https://discuss.elastic.co/t/elastic-fleet-change-datastream-name-based-on-field-value/301155)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 9\
**Last updated:** [April 11, 2022, 10:49am UTC](https://discuss.elastic.co/t/elastic-fleet-change-datastream-name-based-on-field-value/301155 "2022-04-11T10:49:37Z")

</div>

Hi, I need to set different ILM policies based on logs field value (one for PROD , other for NONPROD), so I created an ingest pipeline that renames the \_index field as @ruflin suggested in a github issue and works good w…

---

## [Eror : No indices match pattern “filebeat-\*” - filebeat 8.1.2](https://discuss.elastic.co/t/eror-no-indices-match-pattern-filebeat-filebeat-8-1-2/302075)

<div class="topic-metadata">

**Author:** [@Ruhan\_Khandakar](https://discuss.elastic.co/u/Ruhan_Khandakar)\
**Replies:** 0\
**Last updated:** [April 11, 2022, 8:24am UTC](https://discuss.elastic.co/t/eror-no-indices-match-pattern-filebeat-filebeat-8-1-2/302075 "2022-04-11T08:24:16Z")

</div>

Hi, Please help getting No matching indices found: No indices match pattern "filebeat-\*" this error, with filebeat-8.1.2 Here is my filebeat.yml configuration ###################### Filebeat Configuration Example ###…

---

## [Connectivity Issue between Winlog - Kafka - Logstash](https://discuss.elastic.co/t/connectivity-issue-between-winlog-kafka-logstash/302071)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 0\
**Last updated:** [April 11, 2022, 7:34am UTC](https://discuss.elastic.co/t/connectivity-issue-between-winlog-kafka-logstash/302071 "2022-04-11T07:34:51Z")

</div>

Hello, I am using elastic stack v8 composed of: 2 servers: Masters + data 1 server: data + kibana 1 server: kafka + logstash winglogbeat configuration output.kafka: hosts: \["X.X.X.X:9092"\] topic: "Win…

---

## [Hide username/password ebats](https://discuss.elastic.co/t/hide-username-password-ebats/302062)

<div class="topic-metadata">

**Author:** [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Replies:** 0\
**Last updated:** [April 11, 2022, 2:43am UTC](https://discuss.elastic.co/t/hide-username-password-ebats/302062 "2022-04-11T02:43:47Z")

</div>

right there is a password and username, how do I make the beats that I have don't include it but can still be connected?

---

## [Setting the number of shards and replicas in /etc/filebeat/filebeat.yml](https://discuss.elastic.co/t/setting-the-number-of-shards-and-replicas-in-etc-filebeat-filebeat-yml/302029)

<div class="topic-metadata">

**Author:** [@ristov1](https://discuss.elastic.co/u/ristov1)\
**Replies:** 7\
**Last updated:** [April 10, 2022, 9:53am UTC](https://discuss.elastic.co/t/setting-the-number-of-shards-and-replicas-in-etc-filebeat-filebeat-yml/302029 "2022-04-10T09:53:20Z")

</div>

According to filebeat documentation (Configure Elasticsearch index template loading | Filebeat Reference \[8.1\] | Elastic), it should be possible to set the number of shards and replicas for Filebeat indexes with the foll…

---

## [Self developed metricbeat module throws in docker a strange error](https://discuss.elastic.co/t/self-developed-metricbeat-module-throws-in-docker-a-strange-error/301560)

<div class="topic-metadata">

**Author:** [@PascalThalmann](https://discuss.elastic.co/u/PascalThalmann)\
**Replies:** 1\
**Last updated:** [April 10, 2022, 4:45am UTC](https://discuss.elastic.co/t/self-developed-metricbeat-module-throws-in-docker-a-strange-error/301560 "2022-04-10T04:45:38Z")

</div>

Hi, I developed a metricbeat module and metricset. I ran "mage update" and "mage build" and tested it in my VM and it ran perfectly. I then zipped the following files, copied dit to another VM (Ubuntu as well) and star…

---

## [When ilm is enabled metricbeat can't communicate with kibana](https://discuss.elastic.co/t/when-ilm-is-enabled-metricbeat-cant-communicate-with-kibana/302024)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 0\
**Last updated:** [April 9, 2022, 12:14pm UTC](https://discuss.elastic.co/t/when-ilm-is-enabled-metricbeat-cant-communicate-with-kibana/302024 "2022-04-09T12:14:24Z")

</div>

Hi guys!! I use ELK v7.16.2 I test the metricbeat on my test server with a direct connection (IP). Now in the production environment, I use reverse proxy on ELK domains. On the test environment, everything is ok, als…

---

## [Adding Geo data to monitored hosts](https://discuss.elastic.co/t/adding-geo-data-to-monitored-hosts/301933)

<div class="topic-metadata">

**Author:** [@Christian\_SANCHEZ](https://discuss.elastic.co/u/Christian_SANCHEZ)\
**Replies:** 6\
**Last updated:** [April 8, 2022, 5:37pm UTC](https://discuss.elastic.co/t/adding-geo-data-to-monitored-hosts/301933 "2022-04-08T17:37:27Z")

</div>

Hello I have heartbeat running and sending correctly data to my ES. I would like to add geo data to the hosts I monitor to show them on a Map I know we can add geo data to the observer, but is there a way to add geo d…

---

## [Filebeat (google\_workspace module) retrieving partial events on initial startup](https://discuss.elastic.co/t/filebeat-google-workspace-module-retrieving-partial-events-on-initial-startup/301180)

<div class="topic-metadata">

**Author:** [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Replies:** 7\
**Last updated:** [April 8, 2022, 10:23am UTC](https://discuss.elastic.co/t/filebeat-google-workspace-module-retrieving-partial-events-on-initial-startup/301180 "2022-04-08T10:23:35Z")

</div>

Hello I would like to ask question related to below topic. I want to retrieve events backtracking up to 96 h for drive events . However, I was only able to retrieve partial of them . Looking at DEBUG log , the start…

---

## [Removing fields from Index](https://discuss.elastic.co/t/removing-fields-from-index/301623)

<div class="topic-metadata">

**Author:** [@The-morpho](https://discuss.elastic.co/u/The-morpho)\
**Replies:** 4\
**Last updated:** [April 8, 2022, 5:56am UTC](https://discuss.elastic.co/t/removing-fields-from-index/301623 "2022-04-08T05:56:17Z")

</div>

Hi sorry for bothering you everytime. I upload some logs into elastic via filebeat, but there is some other information added to my original logs like the host name os kernel ..., and the main message become unformatted…

---

## [Metricbeat Output to Logstash, Can monitor in Stack Monitoring?](https://discuss.elastic.co/t/metricbeat-output-to-logstash-can-monitor-in-stack-monitoring/301919)

<div class="topic-metadata">

**Author:** [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Replies:** 0\
**Last updated:** [April 8, 2022, 3:55am UTC](https://discuss.elastic.co/t/metricbeat-output-to-logstash-can-monitor-in-stack-monitoring/301919 "2022-04-08T03:55:09Z")

</div>

Hi, I monitor logstash node by using metricbeat, and configure metricbeat output to logstash -\> Elasticsearch. I can received all the metricbeat events to metricbeat-\* However, can I show the metricbeat monitoring in …

---

## [How to get rid of Standalone Cluster in Kibana Stack Monitoring?](https://discuss.elastic.co/t/how-to-get-rid-of-standalone-cluster-in-kibana-stack-monitoring/301159)

<div class="topic-metadata">

**Author:** [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Replies:** 2\
**Last updated:** [April 8, 2022, 2:23am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-standalone-cluster-in-kibana-stack-monitoring/301159 "2022-04-08T02:23:15Z")

</div>

I'm monitoring Elasticsearch by using metricbeats and monitor my metricbeats using beats-xpack After I monitored metricbeats, on the stack monitoring \> cluster, it appeared the standalone cluster & my cluster.. Read th…

---

## [After add a fleet server，How to add watching my windows pc docker data?](https://discuss.elastic.co/t/after-add-a-fleet-server-how-to-add-watching-my-windows-pc-docker-data/301911)

<div class="topic-metadata">

**Author:** [@aliuq](https://discuss.elastic.co/u/aliuq)\
**Replies:** 0\
**Last updated:** [April 8, 2022, 1:52am UTC](https://discuss.elastic.co/t/after-add-a-fleet-server-how-to-add-watching-my-windows-pc-docker-data/301911 "2022-04-08T01:52:00Z")

</div>

excute below command, it does't works in 7.15.0, and got a error message Access is denied .\\elastic-agent.exe install -f \` --fleet-server-es=http://192.168.2.122:9200 \` --fleet-server-service-token=XXXXXXXXXXXXXX…

---

## [How can I represent a config key containing a dot/period/full-stop "."?](https://discuss.elastic.co/t/how-can-i-represent-a-config-key-containing-a-dot-period-full-stop/301907)

<div class="topic-metadata">

**Author:** [@javabrett](https://discuss.elastic.co/u/javabrett)\
**Replies:** 0\
**Last updated:** [April 8, 2022, 12:56am UTC](https://discuss.elastic.co/t/how-can-i-represent-a-config-key-containing-a-dot-period-full-stop/301907 "2022-04-08T00:56:53Z")

</div>

TL;DR: Can beats/metricsbeat/prometheus module tolerate a config key that contains dots/periods/full-stops, given the Beats go-ucfg config-processsing. I am using metricbeat and module prometheus. For the Prometheus sc…

---

## [Docker container performance monitor](https://discuss.elastic.co/t/docker-container-performance-monitor/299165)

<div class="topic-metadata">

**Author:** [@kirankatkar](https://discuss.elastic.co/u/kirankatkar)\
**Replies:** 2\
**Last updated:** [April 7, 2022, 3:27pm UTC](https://discuss.elastic.co/t/docker-container-performance-monitor/299165 "2022-04-07T15:27:30Z")

</div>

Hello, We have our ELK (on prem) as SIEM solution. Now we have an requirement is like, we want to monitor multiple docker container performance (cpu usage, memory usage, etc). Those all docker container were installed o…

---

## [Winlogbeat performance issue](https://discuss.elastic.co/t/winlogbeat-performance-issue/301886)

<div class="topic-metadata">

**Author:** [@kirankatkar](https://discuss.elastic.co/u/kirankatkar)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 3:11pm UTC](https://discuss.elastic.co/t/winlogbeat-performance-issue/301886 "2022-04-07T15:11:41Z")

</div>

Hello All, Can you please help to understand and resolve the issue. Environment is like: Multiple location (branches) having many on prem Win Servers where winlogbeat is installed and their we had dedicated on prem sy…

---

## [Filebeat Registry Issue handling large number of files](https://discuss.elastic.co/t/filebeat-registry-issue-handling-large-number-of-files/301885)

<div class="topic-metadata">

**Author:** [@KillerDAN](https://discuss.elastic.co/u/KillerDAN)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 3:10pm UTC](https://discuss.elastic.co/t/filebeat-registry-issue-handling-large-number-of-files/301885 "2022-04-07T15:10:55Z")

</div>

Currently running filebeat 7.17.2. I have a setup where filebeat is "scrapping" a folder where per minute 5 (or more in future) CSV files are dropped and filebeat exports to kafka. (CSV are TWAMP telemetry data) Typic…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=95)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=97)
