# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=97

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 98

---

## [Filebeat daemon](https://discuss.elastic.co/t/filebeat-daemon/301777)

<div class="topic-metadata">

**Author:** [@The-morpho](https://discuss.elastic.co/u/The-morpho)\
**Replies:** 4\
**Last updated:** [April 7, 2022, 1:59pm UTC](https://discuss.elastic.co/t/filebeat-daemon/301777 "2022-04-07T13:59:26Z")

</div>

Hello , I want to get filebeat on docker, i followed the instructions here : How to run Filebeat with Docker and use it with ELK stack But when i try to run the Filebeat container using this configuration : docker run…

---

## [What is the correct way to deploy \`Elastic Agent\` 8 via Docker?](https://discuss.elastic.co/t/what-is-the-correct-way-to-deploy-elastic-agent-8-via-docker/301688)

<div class="topic-metadata">

**Author:** [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Replies:** 1\
**Last updated:** [April 7, 2022, 10:54am UTC](https://discuss.elastic.co/t/what-is-the-correct-way-to-deploy-elastic-agent-8-via-docker/301688 "2022-04-07T10:54:47Z")

</div>

I am trying to configure Elastic Stack using docker-compose.yml as follows, where Kibana gets the API key via bin/elasticsearch-create-enrollment-token -s kibana. version: "3.8" services: elasticsearch-node01: i…

---

## [Unable launch winlogbeats on windows 10 x86](https://discuss.elastic.co/t/unable-launch-winlogbeats-on-windows-10-x86/301863)

<div class="topic-metadata">

**Author:** [@lolo54000](https://discuss.elastic.co/u/lolo54000)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 12:18pm UTC](https://discuss.elastic.co/t/unable-launch-winlogbeats-on-windows-10-x86/301863 "2022-04-07T12:18:58Z")

</div>

Hi I want to install winlogbeat on windows 10 pro x86 (20h2). (my processor is a core I3 2100 ) I download the last version (8.1.1) in zip format and when i want to launch winlogbeat.exe i have an error that tell me : …

---

## [Missing CPU Memory and network data](https://discuss.elastic.co/t/missing-cpu-memory-and-network-data/301856)

<div class="topic-metadata">

**Author:** [@Sonal1](https://discuss.elastic.co/u/Sonal1)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 10:52am UTC](https://discuss.elastic.co/t/missing-cpu-memory-and-network-data/301856 "2022-04-07T10:52:28Z")

</div>

Hi, We are trying to pull data for nodes from converge cloud but cpu, memory and network are shown as zero. Other data is coming. Is it so that metricbeat donot pull data for cpu, memory and network from converge cloud …

---

## [Running filebeat with the setup command docker](https://discuss.elastic.co/t/running-filebeat-with-the-setup-command-docker/301853)

<div class="topic-metadata">

**Author:** [@The-morpho](https://discuss.elastic.co/u/The-morpho)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 10:08am UTC](https://discuss.elastic.co/t/running-filebeat-with-the-setup-command-docker/301853 "2022-04-07T10:08:20Z")

</div>

Hi everyone, i'm trying to install elk and filebeat on docker, well i uploaded the image of elk and it worked i can go to the kibana dashboard and view elastic ,... Now I want to install filebeat image so i followed the…

---

## [Filebeat Azure Module Base64 Issue](https://discuss.elastic.co/t/filebeat-azure-module-base64-issue/301198)

<div class="topic-metadata">

**Author:** [@Gosborne](https://discuss.elastic.co/u/Gosborne)\
**Replies:** 8\
**Last updated:** [April 7, 2022, 10:06am UTC](https://discuss.elastic.co/t/filebeat-azure-module-base64-issue/301198 "2022-04-07T10:06:14Z")

</div>

Good Afternoon, We currently get the error below when running the azure module on Filebeat 8.0.1 @timestamp":"2022-03-31T12:45:12.573Z","log.logger":"azure-eventhub input","log.origin":{"file.name":"azureeventhub/input…

---

## [Several inputs for modules](https://discuss.elastic.co/t/several-inputs-for-modules/301851)

<div class="topic-metadata">

**Author:** [@Thermi](https://discuss.elastic.co/u/Thermi)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 9:55am UTC](https://discuss.elastic.co/t/several-inputs-for-modules/301851 "2022-04-07T09:55:04Z")

</div>

Hello, I need to configure several inputs for any particular module, but most modules only have one, or generally a way to specify the mode/type/protocol of one (syslog over TLS, syslog over UDP, reading from a log file…

---

## [Custom log integration with json file - no data](https://discuss.elastic.co/t/custom-log-integration-with-json-file-no-data/301847)

<div class="topic-metadata">

**Author:** [@maar](https://discuss.elastic.co/u/maar)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 9:36am UTC](https://discuss.elastic.co/t/custom-log-integration-with-json-file-no-data/301847 "2022-04-07T09:36:41Z")

</div>

I successfully added the agent: I added Custom Logs integration to the Default policy: Custom configurations: agent.logging.json: true json.keys\_under\_root: true json.add\_error\_key: true Contents of the /…

---

## [Filebeat multiline Pattern on Apache Logs does not work as expected (Filebeat -\> Logstash -\> ES)](https://discuss.elastic.co/t/filebeat-multiline-pattern-on-apache-logs-does-not-work-as-expected-filebeat-logstash-es/301747)

<div class="topic-metadata">

**Author:** [@Bndlr](https://discuss.elastic.co/u/Bndlr)\
**Replies:** 2\
**Last updated:** [April 7, 2022, 6:23am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-on-apache-logs-does-not-work-as-expected-filebeat-logstash-es/301747 "2022-04-07T06:23:13Z")

</div>

Hello, if have the following multiline pattern in Filebeat Configuration: multiline.pattern: ^((-)\*\[0-9\]{4}-\[0-9\]{2}-\[0-9\]{2}|\[0-9\]{1,3}\\.\[0-9\]{1,3}\\.\[0-9\]{1,3}\\.\[0-9\]{1,3} ) to handle mulitline Log Patterns that cont…

---

## [How to upgrade more than 1 Elastic Agent at the same time](https://discuss.elastic.co/t/how-to-upgrade-more-than-1-elastic-agent-at-the-same-time/301745)

<div class="topic-metadata">

**Author:** [@JimG](https://discuss.elastic.co/u/JimG)\
**Replies:** 2\
**Last updated:** [April 7, 2022, 6:14am UTC](https://discuss.elastic.co/t/how-to-upgrade-more-than-1-elastic-agent-at-the-same-time/301745 "2022-04-07T06:14:19Z")

</div>

Hi, Is it possible to upgrade more than 1 Elastic agent at a time? I dont know if it is a missing feature or if i just dont have the knowledge how to do this. With 750+ enrolled agents, it's a long proces to manual upg…

---

## [Filebeat - Kubernetes Autodiscovery with ElasticSearch Module](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-with-elasticsearch-module/301815)

<div class="topic-metadata">

**Author:** [@Jonathan\_Mabrito](https://discuss.elastic.co/u/Jonathan_Mabrito)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 1:50am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-with-elasticsearch-module/301815 "2022-04-07T01:50:45Z")

</div>

Hi There, Hoping someone might be able to help with getting Filebeats Autodiscovery up. I am trying to detect my Elasticsearch containers in my Kubernetes Cluster (using vanilla K8's). Here is my proposed K8's file: a…

---

## [Elasticsearch node with Metricbeat not registering in Kibana](https://discuss.elastic.co/t/elasticsearch-node-with-metricbeat-not-registering-in-kibana/301548)

<div class="topic-metadata">

**Author:** [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Replies:** 4\
**Last updated:** [April 6, 2022, 4:38pm UTC](https://discuss.elastic.co/t/elasticsearch-node-with-metricbeat-not-registering-in-kibana/301548 "2022-04-06T16:38:52Z")

</div>

I've added a 4th identical ES node to my cluster, and for some reason Metricbeat is not reporting correctly to Kibana. The only error from the Metricbeat logs is: Apr 4 17:58:35 elk-5 metricbeat\[8781\]: 2022-04-04T10:5…

---

## [Registry filebeat with file overwritten daily](https://discuss.elastic.co/t/registry-filebeat-with-file-overwritten-daily/301771)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 0\
**Last updated:** [April 6, 2022, 2:05pm UTC](https://discuss.elastic.co/t/registry-filebeat-with-file-overwritten-daily/301771 "2022-04-06T14:05:57Z")

</div>

hello! I have a filebeat reading a document and sending the logs to kafka. My client has a single file that is overwritten every day. I understand how the filebeat registry works when new records are added to the docu…

---

## [Filebeat stops harvesting logs after a point of time](https://discuss.elastic.co/t/filebeat-stops-harvesting-logs-after-a-point-of-time/301746)

<div class="topic-metadata">

**Author:** [@Chirag\_Baid](https://discuss.elastic.co/u/Chirag_Baid)\
**Replies:** 0\
**Last updated:** [April 6, 2022, 11:26am UTC](https://discuss.elastic.co/t/filebeat-stops-harvesting-logs-after-a-point-of-time/301746 "2022-04-06T11:26:46Z")

</div>

After a point of time Filebeats fails to show logs in Kibana cloud but I can see all my logs in the filebeat docker container which means filebeat not streaming logs to Elasticsearch

---

## [How to generate new file per metricbeat event](https://discuss.elastic.co/t/how-to-generate-new-file-per-metricbeat-event/301732)

<div class="topic-metadata">

**Author:** [@AMBUJ\_DUBEY](https://discuss.elastic.co/u/AMBUJ_DUBEY)\
**Replies:** 0\
**Last updated:** [April 6, 2022, 9:44am UTC](https://discuss.elastic.co/t/how-to-generate-new-file-per-metricbeat-event/301732 "2022-04-06T09:44:12Z")

</div>

How can I generate a new file for every new metricbeat event? Below config creates a file named metricbeat and keeps appending data into it. output.file: enabled: true path: "/tmp/metricbeat"

---

## [Send metrics from specific namespaces in kubernetes using metricbeat](https://discuss.elastic.co/t/send-metrics-from-specific-namespaces-in-kubernetes-using-metricbeat/301726)

<div class="topic-metadata">

**Author:** [@Sherlock06](https://discuss.elastic.co/u/Sherlock06)\
**Replies:** 0\
**Last updated:** [April 6, 2022, 9:01am UTC](https://discuss.elastic.co/t/send-metrics-from-specific-namespaces-in-kubernetes-using-metricbeat/301726 "2022-04-06T09:01:25Z")

</div>

is there a way for us to configure the metric beat config file to be able to fetch cpu/memory metrics only from specific namespaces in kubernetes. We are running a metric beat pod as daemon set on open-shift. Using metri…

---

## [Logs are stopped](https://discuss.elastic.co/t/logs-are-stopped/301622)

<div class="topic-metadata">

**Author:** [@Arraso26](https://discuss.elastic.co/u/Arraso26)\
**Replies:** 2\
**Last updated:** [April 5, 2022, 12:45pm UTC](https://discuss.elastic.co/t/logs-are-stopped/301622 "2022-04-05T12:45:20Z")

</div>

well, the logs come to me fine for about 50 minutes but suddenly it stops, if anyone knows how to fix it I would appreciate it, here are the logs and the configuration files. 2022-04-05T12:25:01.688+0200 INFO beat…

---

## [Filebeat elasticsearch output index setting breaking change?](https://discuss.elastic.co/t/filebeat-elasticsearch-output-index-setting-breaking-change/301667)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 0\
**Last updated:** [April 5, 2022, 8:04pm UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-output-index-setting-breaking-change/301667 "2022-04-05T20:04:51Z")

</div>

In prior filebeat doc (at least in 7.5.0) the output index section stated: The index setting is ignored when index lifecycle management is enabled. If you’re sending events to a cluster that supports index lifecycle ma…

---

## [Pipeline/output.go:180 failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/pipeline-output-go-180-failed-to-publish-events-temporary-bulk-send-failure/299453)

<div class="topic-metadata">

**Author:** [@anubisg1](https://discuss.elastic.co/u/anubisg1)\
**Replies:** 6\
**Last updated:** [April 5, 2022, 4:58pm UTC](https://discuss.elastic.co/t/pipeline-output-go-180-failed-to-publish-events-temporary-bulk-send-failure/299453 "2022-04-05T16:58:00Z")

</div>

i have defined the following pipeline called "suzieq" and tested it against 2 documents PUT \_ingest/pipeline/suzieq { "version": 2, "processors": \[ { "dissect": { "field": "message", "patte…

---

## [Harvester could not be started on existing file due to registry already stopped](https://discuss.elastic.co/t/harvester-could-not-be-started-on-existing-file-due-to-registry-already-stopped/301644)

<div class="topic-metadata">

**Author:** [@mhadidg](https://discuss.elastic.co/u/mhadidg)\
**Replies:** 0\
**Last updated:** [April 5, 2022, 1:47pm UTC](https://discuss.elastic.co/t/harvester-could-not-be-started-on-existing-file-due-to-registry-already-stopped/301644 "2022-04-05T13:47:51Z")

</div>

After deploying Elasticsearch, Kibana with FileBeat version 8.1.2 in a Kubernetes Cluster, I've noticed the following error message coming over and over: Harvester could not be started on existing file: /var/log/contain…

---

## [Parse json with filebeat and send to logstash](https://discuss.elastic.co/t/parse-json-with-filebeat-and-send-to-logstash/301643)

<div class="topic-metadata">

**Author:** [@aviad.co1](https://discuss.elastic.co/u/aviad.co1)\
**Replies:** 0\
**Last updated:** [April 5, 2022, 1:35pm UTC](https://discuss.elastic.co/t/parse-json-with-filebeat-and-send-to-logstash/301643 "2022-04-05T13:35:56Z")

</div>

Hi, I have the following json : \[{"nqdf": 24, "qqqf": 34}\] and I try to send him to logstash. this is my filebeat.yml : type: log enabled: true paths: C:\\beats\\jsonfiles\*.json json.keys\_under\_root: true json.me…

---

## [Filebeat not reading logs 🤨](https://discuss.elastic.co/t/filebeat-not-reading-logs/301242)

<div class="topic-metadata">

**Author:** [@Tellz](https://discuss.elastic.co/u/Tellz)\
**Replies:** 1\
**Last updated:** [April 5, 2022, 12:47pm UTC](https://discuss.elastic.co/t/filebeat-not-reading-logs/301242 "2022-04-05T12:47:29Z")

</div>

Hi, I have a Kubernetes cluster, where in pods I should read logs of one application (Airflow) located in such structure: /usr/local/airflow/logs/{jobname}/{jobname}/{timestamp}/1.log (example: /usr/local/airflow/logs/so…

---

## [Does metricbeat Redis output support Redis Stream?](https://discuss.elastic.co/t/does-metricbeat-redis-output-support-redis-stream/301634)

<div class="topic-metadata">

**Author:** [@AMBUJ\_DUBEY](https://discuss.elastic.co/u/AMBUJ_DUBEY)\
**Replies:** 1\
**Last updated:** [April 5, 2022, 12:39pm UTC](https://discuss.elastic.co/t/does-metricbeat-redis-output-support-redis-stream/301634 "2022-04-05T12:39:31Z")

</div>

The above link says that we can use Redis as an output for metricbeat. But it seems the Redis stream is not supported. Configure the Redis output | Metricbeat Reference \[8.1\] | Elastic Please confirm if we can use Re…

---

## [Heartbeats / Uptime not visible after upgrade to 8.1](https://discuss.elastic.co/t/heartbeats-uptime-not-visible-after-upgrade-to-8-1/301413)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 3\
**Last updated:** [April 5, 2022, 10:17am UTC](https://discuss.elastic.co/t/heartbeats-uptime-not-visible-after-upgrade-to-8-1/301413 "2022-04-05T10:17:11Z")

</div>

Hi, Heartbeats and the Uptime tool in Kibana were working fine under version 7.x. MY heartbeat agent sits on a remote server, runs it's heartbeat checks and send the results to my Elastic Cloud deployment. After upgra…

---

## [Functionbeat ingest error handling](https://discuss.elastic.co/t/functionbeat-ingest-error-handling/301617)

<div class="topic-metadata">

**Author:** [@lyson](https://discuss.elastic.co/u/lyson)\
**Replies:** 0\
**Last updated:** [April 5, 2022, 9:57am UTC](https://discuss.elastic.co/t/functionbeat-ingest-error-handling/301617 "2022-04-05T09:57:21Z")

</div>

We are using functionbeat to forward CloudWatch logs and some custom events via SQS and we are trying to find the best way to make sure events are not lost. We identified different types of errors that can be handled di…

---

## [Error in setting up the Metricbeat](https://discuss.elastic.co/t/error-in-setting-up-the-metricbeat/301512)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 0\
**Last updated:** [April 4, 2022, 12:43pm UTC](https://discuss.elastic.co/t/error-in-setting-up-the-metricbeat/301512 "2022-04-04T12:43:11Z")

</div>

Hi guys!! I have a problem with Metricbeat V 7.16.2 I have two VPS, one of them for test another one is product environment. I ran the metricbeat successfully on my test server, but in the production environment, I go…

---

## [My filebeat won't receive any log](https://discuss.elastic.co/t/my-filebeat-wont-receive-any-log/301577)

<div class="topic-metadata">

**Author:** [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Replies:** 1\
**Last updated:** [April 5, 2022, 3:30am UTC](https://discuss.elastic.co/t/my-filebeat-wont-receive-any-log/301577 "2022-04-05T03:30:09Z")

</div>

hi everyone, why my filebeat stop receive any log? here's the config filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use different inputs for various configurations. # B…

---

## [Integration limits?](https://discuss.elastic.co/t/integration-limits/301553)

<div class="topic-metadata">

**Author:** [@hebph001](https://discuss.elastic.co/u/hebph001)\
**Replies:** 1\
**Last updated:** [April 4, 2022, 10:59pm UTC](https://discuss.elastic.co/t/integration-limits/301553 "2022-04-04T22:59:32Z")

</div>

Hi Elasticians, I would like to know how many integrations a single Elastic Agent can support? I can't find this information in the documentation. Thanks, Philippe

---

## [IIS - Taken time - event.duration?](https://discuss.elastic.co/t/iis-taken-time-event-duration/301546)

<div class="topic-metadata">

**Author:** [@mgfeal](https://discuss.elastic.co/u/mgfeal)\
**Replies:** 0\
**Last updated:** [April 4, 2022, 5:56pm UTC](https://discuss.elastic.co/t/iis-taken-time-event-duration/301546 "2022-04-04T17:56:02Z")

</div>

Hi, I was reading this topic: And we also use to put in our dashboards the "Taken Time" from IIS. So, is correct that event.duration is the value for taken time? If it's not correct, how can we use it? Thanks!

---

## [Heartbeat subcommands unable to run on 7.17.x and 8.0.x docker images](https://discuss.elastic.co/t/heartbeat-subcommands-unable-to-run-on-7-17-x-and-8-0-x-docker-images/299630)

<div class="topic-metadata">

**Author:** [@cdavid15](https://discuss.elastic.co/u/cdavid15)\
**Replies:** 7\
**Last updated:** [April 4, 2022, 1:45pm UTC](https://discuss.elastic.co/t/heartbeat-subcommands-unable-to-run-on-7-17-x-and-8-0-x-docker-images/299630 "2022-04-04T13:45:17Z")

</div>

Hi all, I am trying to run the heartbeat setup but I am getting the following error only on the 7.17.0, 7.17.1 and 8.0.0 docker images: /usr/local/bin/docker-entrypoint: line 25: exec: setup: not found It appears the …

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=96)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=98)
