# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=98

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 99

---

## [FIlebeat modules proxy](https://discuss.elastic.co/t/filebeat-modules-proxy/301506)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 2\
**Last updated:** [April 4, 2022, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-modules-proxy/301506 "2022-04-04T13:14:01Z")

</div>

Hey, I was wondering if it was possible to include proxy settings for o365 module or any other module that need to perform requests online ? looks like envars and proxy\_url are not working. Is it possible to implement…

---

## [Metricbeat jolokia module jmx.application|instance](https://discuss.elastic.co/t/metricbeat-jolokia-module-jmx-application-instance/301500)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [April 4, 2022, 11:24am UTC](https://discuss.elastic.co/t/metricbeat-jolokia-module-jmx-application-instance/301500 "2022-04-04T11:24:40Z")

</div>

The metricbeat v.8.1 module jolokia speaks not much about these: jmx.application: jmx.instance: what are they meant for?

---

## [Metricbeat jolokia vs Red Hat AMQ servers vs HTTP error 403](https://discuss.elastic.co/t/metricbeat-jolokia-vs-red-hat-amq-servers-vs-http-error-403/301401)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [April 4, 2022, 7:24am UTC](https://discuss.elastic.co/t/metricbeat-jolokia-vs-red-hat-amq-servers-vs-http-error-403/301401 "2022-04-04T07:24:18Z")

</div>

Trying to fetch data through jolokia module from Red Hat AMQ process(es) on a host. Have this module.d/jojokia.yml: - module: jolokia metricsets: \["jmx"\] period: 1m hosts: \["http://localhost:5008"\] namespace: "…

---

## [Unable to setup filebeat dashboard on kibana](https://discuss.elastic.co/t/unable-to-setup-filebeat-dashboard-on-kibana/301265)

<div class="topic-metadata">

**Author:** [@spo](https://discuss.elastic.co/u/spo)\
**Replies:** 3\
**Last updated:** [April 4, 2022, 12:30am UTC](https://discuss.elastic.co/t/unable-to-setup-filebeat-dashboard-on-kibana/301265 "2022-04-04T00:30:21Z")

</div>

HI I have filebeat on a ec2 windows instance.I am trying to pull IIS logs .Elasticsearch, Kibana are in docker containers on an ubuntu instance.Filebeat is not in docker. So when i try to setup filebeat dashboard on kib…

---

## [Heartbeat behind proxy](https://discuss.elastic.co/t/heartbeat-behind-proxy/301194)

<div class="topic-metadata">

**Author:** [@sulfred](https://discuss.elastic.co/u/sulfred)\
**Replies:** 2\
**Last updated:** [April 3, 2022, 11:15pm UTC](https://discuss.elastic.co/t/heartbeat-behind-proxy/301194 "2022-04-03T23:15:03Z")

</div>

I am running heartbeat in a container. The version of the heartbeat is heartbeat:8.1.0. My heartbeat is running behind the proxy and output to the elastic cloud. In the docker-compose.yml environment: HTTP\_PROXY: "ht…

---

## [Winlogbeat Index is yellow. Having weird errors in discover tab, and I cannot view winlog data](https://discuss.elastic.co/t/winlogbeat-index-is-yellow-having-weird-errors-in-discover-tab-and-i-cannot-view-winlog-data/301373)

<div class="topic-metadata">

**Author:** [@jthare](https://discuss.elastic.co/u/jthare)\
**Replies:** 1\
**Last updated:** [April 2, 2022, 12:58am UTC](https://discuss.elastic.co/t/winlogbeat-index-is-yellow-having-weird-errors-in-discover-tab-and-i-cannot-view-winlog-data/301373 "2022-04-02T00:58:40Z")

</div>

Just set up a Wec server to forward windows event logs to my elk stack via the setup powershell script. We were successful in the command running, but now we're receiving the logs. I just can't view them in Discover and …

---

## [Cause of i/o timeout errors](https://discuss.elastic.co/t/cause-of-i-o-timeout-errors/301330)

<div class="topic-metadata">

**Author:** [@theMike](https://discuss.elastic.co/u/theMike)\
**Replies:** 0\
**Last updated:** [April 1, 2022, 1:48pm UTC](https://discuss.elastic.co/t/cause-of-i-o-timeout-errors/301330 "2022-04-01T13:48:18Z")

</div>

Hi, I'm trying to figure out the root cause of this filebeat issue. Basically filebeat 7.15.2 connecting to Kafka. When filebeat starts it sends for approx 5 to 10 min then, at a certin point the following happens: 69…

---

## [Filebeat syslog problem](https://discuss.elastic.co/t/filebeat-syslog-problem/301328)

<div class="topic-metadata">

**Author:** [@adis3421](https://discuss.elastic.co/u/adis3421)\
**Replies:** 0\
**Last updated:** [April 1, 2022, 1:43pm UTC](https://discuss.elastic.co/t/filebeat-syslog-problem/301328 "2022-04-01T13:43:12Z")

</div>

Hi, I using filebeat via logstash and normaly connect to elasticsearch. In normal connect is ok but via logstash I have a problem: illegal\_argument\_exception at shard 0 index filebeat-8.1.2-2022.04.01 node x1NX6Z2sRz2p…

---

## [Elastic Agent Heartbeat Folder filled with Core Dumps](https://discuss.elastic.co/t/elastic-agent-heartbeat-folder-filled-with-core-dumps/301262)

<div class="topic-metadata">

**Author:** [@RichiCoder](https://discuss.elastic.co/u/RichiCoder)\
**Replies:** 7\
**Last updated:** [April 1, 2022, 2:50am UTC](https://discuss.elastic.co/t/elastic-agent-heartbeat-folder-filled-with-core-dumps/301262 "2022-04-01T02:50:57Z")

</div>

Howdy! We're using the Elastic Agent's synthetic agent running in docker to monitor some web properties. There's no visible issues or errors, but after some time the agent "dies" for lack of a better term. After some inv…

---

## [No Result from osquery elastic agent 7.14.0](https://discuss.elastic.co/t/no-result-from-osquery-elastic-agent-7-14-0/281097)

<div class="topic-metadata">

**Author:** [@cheapsupps](https://discuss.elastic.co/u/cheapsupps)\
**Replies:** 12\
**Last updated:** [March 31, 2022, 5:26pm UTC](https://discuss.elastic.co/t/no-result-from-osquery-elastic-agent-7-14-0/281097 "2022-03-31T17:26:36Z")

</div>

I have tried to run the query using osquery manager on one of my agent select \* from users However, no result is returned. I got the below message from my agent logs {"log.level":"warn","@timestamp":"2021-08-11T08:27…

---

## [Elastic agent fiebeat error spam](https://discuss.elastic.co/t/elastic-agent-fiebeat-error-spam/301206)

<div class="topic-metadata">

**Author:** [@daymansiege](https://discuss.elastic.co/u/daymansiege)\
**Replies:** 0\
**Last updated:** [March 31, 2022, 2:11pm UTC](https://discuss.elastic.co/t/elastic-agent-fiebeat-error-spam/301206 "2022-03-31T14:11:11Z")

</div>

Hello! I am trying to setup Elastic Agent to monitor Kubernetes cluster (Azure). I have successfully installed and configured agents using this guide (had to change image version to 8.1.1 as 8.1.2 does not exist) But …

---

## [Filebeat Cisco Module and IOS fields not showing up as documented](https://discuss.elastic.co/t/filebeat-cisco-module-and-ios-fields-not-showing-up-as-documented/298857)

<div class="topic-metadata">

**Author:** [@ulysse31](https://discuss.elastic.co/u/ulysse31)\
**Replies:** 1\
**Last updated:** [March 31, 2022, 10:26am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-and-ios-fields-not-showing-up-as-documented/298857 "2022-03-31T10:26:36Z")

</div>

Hi all, I just started the logging of the syslog data sent by my cisco IOS switches into elastic (with filebeat 7.17.0 and Elasticsearch 7.17.0). I setup a filebeat with "usual config" like: ios: enabled: true …

---

## [Netflow sends larger documents than others](https://discuss.elastic.co/t/netflow-sends-larger-documents-than-others/301152)

<div class="topic-metadata">

**Author:** [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Replies:** 0\
**Last updated:** [March 31, 2022, 12:58am UTC](https://discuss.elastic.co/t/netflow-sends-larger-documents-than-others/301152 "2022-03-31T00:58:51Z")

</div>

good morning I have a question and I have a filebeat running that is sending me netflow to my Elasticsearch, but I have noticed that there are more documents in some times than others, why does it look like this? i.e. ne…

---

## [Error in building k8 objects when using terraform to create filebeat as a resource](https://discuss.elastic.co/t/error-in-building-k8-objects-when-using-terraform-to-create-filebeat-as-a-resource/301145)

<div class="topic-metadata">

**Author:** [@surprised\_ferret](https://discuss.elastic.co/u/surprised_ferret)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 9:19pm UTC](https://discuss.elastic.co/t/error-in-building-k8-objects-when-using-terraform-to-create-filebeat-as-a-resource/301145 "2022-03-30T21:19:47Z")

</div>

I am trying to do something similar to this post over at Hashicorp: Terraform and helm\_release - #7 by stuart-c - Essentially, installing filebeat on a kubernetes cluster inside AKS. Here’s my filebeat config file (file…

---

## [Metricset system: users and service](https://discuss.elastic.co/t/metricset-system-users-and-service/301093)

<div class="topic-metadata">

**Author:** [@rdinis](https://discuss.elastic.co/u/rdinis)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 1:14pm UTC](https://discuss.elastic.co/t/metricset-system-users-and-service/301093 "2022-03-30T13:14:53Z")

</div>

Hi, I'm running metricbeat on container and i have found this error: {"level":"error","timestamp":"2022-03-27T16:12:45.481Z","logger":"reload","caller":"cfgfile/list.go:99","message":"Error creating runner from config:…

---

## [Filebeat with AWS ELB logs = newbie problems](https://discuss.elastic.co/t/filebeat-with-aws-elb-logs-newbie-problems/301077)

<div class="topic-metadata">

**Author:** [@Bartosz\_Bubak](https://discuss.elastic.co/u/Bartosz_Bubak)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 11:19am UTC](https://discuss.elastic.co/t/filebeat-with-aws-elb-logs-newbie-problems/301077 "2022-03-30T11:19:59Z")

</div>

Hi, I am relatively "new" to ELK, I have some basics in administration and use, but I don't feel like a specialist in any way. I will briefly describe the problem I am struggling with. On one of our services (hosted on…

---

## [Does initial interval work on start up for google workspace module?](https://discuss.elastic.co/t/does-initial-interval-work-on-start-up-for-google-workspace-module/300701)

<div class="topic-metadata">

**Author:** [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Replies:** 2\
**Last updated:** [March 30, 2022, 10:11am UTC](https://discuss.elastic.co/t/does-initial-interval-work-on-start-up-for-google-workspace-module/300701 "2022-03-30T10:11:06Z")

</div>

Hello. I would like to ask question for google workspace module . Doc says , filebeat will poll up to var.initial\_interval when the filebeat starts. It will poll events up to this time period when the module starts. …

---

## [Use ^ for absolute input paths?](https://discuss.elastic.co/t/use-for-absolute-input-paths/301034)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 6:53am UTC](https://discuss.elastic.co/t/use-for-absolute-input-paths/301034 "2022-03-30T06:53:54Z")

</div>

Hello, I recently read about the filebeat filestream input. On prospector.scanner.include\_files, there is an example saying you should use ^ in patterns if they're an absolute path. Does this transfer to the input paths…

---

## [Newcomer multiline.pattern question](https://discuss.elastic.co/t/newcomer-multiline-pattern-question/300934)

<div class="topic-metadata">

**Author:** [@covfefe](https://discuss.elastic.co/u/covfefe)\
**Replies:** 3\
**Last updated:** [March 30, 2022, 2:33am UTC](https://discuss.elastic.co/t/newcomer-multiline-pattern-question/300934 "2022-03-30T02:33:36Z")

</div>

Hi, new to filebeat and multiline.pattern configuration as a whole. I was reading up on multiline.pattern examples and came across this where the example used was multiline.pattern: '\[1\]'. But lets say if each line …

---

## [Metricbeat giving start\_time wrong](https://discuss.elastic.co/t/metricbeat-giving-start-time-wrong/301011)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 0\
**Last updated:** [March 29, 2022, 10:04pm UTC](https://discuss.elastic.co/t/metricbeat-giving-start-time-wrong/301011 "2022-03-29T22:04:04Z")

</div>

I have version 7.12.0 and some process is giving me wrong start time. here is example and I can only track it down when it is running h101024:/proc/3333% cat stat 3333 (adb9-ompi) S 3329 3333 2764 0 -1 1073741824 1033…

---

## [JSON logs in filestream input not added correctly on Elasticsearch](https://discuss.elastic.co/t/json-logs-in-filestream-input-not-added-correctly-on-elasticsearch/300989)

<div class="topic-metadata">

**Author:** [@MartinNouv](https://discuss.elastic.co/u/MartinNouv)\
**Replies:** 0\
**Last updated:** [March 29, 2022, 4:17pm UTC](https://discuss.elastic.co/t/json-logs-in-filestream-input-not-added-correctly-on-elasticsearch/300989 "2022-03-29T16:17:15Z")

</div>

Greetings Elastic Community ! I have an issue about my implementations of some JSON logs into Elasticsearch with a filebeat. First i didn't used the parsers function, and so all the fields was not implemented and all t…

---

## [Filebeat ssl issue](https://discuss.elastic.co/t/filebeat-ssl-issue/300984)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 0\
**Last updated:** [March 29, 2022, 2:45pm UTC](https://discuss.elastic.co/t/filebeat-ssl-issue/300984 "2022-03-29T14:45:30Z")

</div>

Hello, I ran into a weird issue where I was getting the following error on one of my logstash servers as I was trying to set up filebeats: ERROR \[esclientleg\] transport/logging.go:37 Error dialing x509: Certificate sig…

---

## [Filebeat using default input path instead of my log path](https://discuss.elastic.co/t/filebeat-using-default-input-path-instead-of-my-log-path/300982)

<div class="topic-metadata">

**Author:** [@benny111](https://discuss.elastic.co/u/benny111)\
**Replies:** 0\
**Last updated:** [March 29, 2022, 2:26pm UTC](https://discuss.elastic.co/t/filebeat-using-default-input-path-instead-of-my-log-path/300982 "2022-03-29T14:26:33Z")

</div>

I have a filebeat installed in Ubuntu 20.04. I have changed my input file path to my own log path. But when it starts to service, it seems to collect the default system logs. I tried to use sudo /usr/share/filebeat/b…

---

## [Permissions issues after upgrading heartbeat to 8.0](https://discuss.elastic.co/t/permissions-issues-after-upgrading-heartbeat-to-8-0/297383)

<div class="topic-metadata">

**Author:** [@Marc-Antoine\_J](https://discuss.elastic.co/u/Marc-Antoine_J)\
**Replies:** 7\
**Last updated:** [March 29, 2022, 1:48pm UTC](https://discuss.elastic.co/t/permissions-issues-after-upgrading-heartbeat-to-8-0/297383 "2022-03-29T13:48:46Z")

</div>

Good Day, I recently upgrade my test installation of the Elastic Stack to 8.0. The Elasticsearch and kibana installations went fine. On the heartbeat side I'm getting the following errors: Cannot index event publisher.…

---

## [How to use "DAY" Grok Pattern on Filebeat Multiline](https://discuss.elastic.co/t/how-to-use-day-grok-pattern-on-filebeat-multiline/300910)

<div class="topic-metadata">

**Author:** [@mvasqueznr](https://discuss.elastic.co/u/mvasqueznr)\
**Replies:** 1\
**Last updated:** [March 29, 2022, 12:31pm UTC](https://discuss.elastic.co/t/how-to-use-day-grok-pattern-on-filebeat-multiline/300910 "2022-03-29T12:31:42Z")

</div>

Hi. I'm use the next configuration to read a multiline file on logstash. For identify the begin of the message I use a grok pattern file { path =\> "Sample\_Type1/\*" start\_position =\> "beginning" …

---

## [Java 17 Compatibility](https://discuss.elastic.co/t/java-17-compatibility/300915)

<div class="topic-metadata">

**Author:** [@shivaraj\_eric](https://discuss.elastic.co/u/shivaraj_eric)\
**Replies:** 2\
**Last updated:** [March 29, 2022, 7:16am UTC](https://discuss.elastic.co/t/java-17-compatibility/300915 "2022-03-29T07:16:14Z")

</div>

Does latest version of file beat is compatible with java 17?.Need to know on the same compatibility for the following ELK component as well. Logstash

---

## [Filebeat timestamp processor no year](https://discuss.elastic.co/t/filebeat-timestamp-processor-no-year/300896)

<div class="topic-metadata">

**Author:** [@kdotson](https://discuss.elastic.co/u/kdotson)\
**Replies:** 0\
**Last updated:** [March 28, 2022, 10:42pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-processor-no-year/300896 "2022-03-28T22:42:03Z")

</div>

Hello, I am trying to get filebeats to update the @timestamp with the timestamp processor but I think because the log timestamp is missing the year I am having some trouble. example log: Mar 12 07:06:38 asdefg/xx.xx.x…

---

## [Elastic Agent Enrollment behind Proxy Server](https://discuss.elastic.co/t/elastic-agent-enrollment-behind-proxy-server/300888)

<div class="topic-metadata">

**Author:** [@alphabet5](https://discuss.elastic.co/u/alphabet5)\
**Replies:** 1\
**Last updated:** [March 28, 2022, 9:27pm UTC](https://discuss.elastic.co/t/elastic-agent-enrollment-behind-proxy-server/300888 "2022-03-28T21:27:38Z")

</div>

I am trying to add Elastic Agents to windows hosts. These hosts need to communicate through a proxy (using squid currently). I've tried adding the registry keys before running the install command, as well as using envir…

---

## [XOR on field values](https://discuss.elastic.co/t/xor-on-field-values/300346)

<div class="topic-metadata">

**Author:** [@franpom](https://discuss.elastic.co/u/franpom)\
**Replies:** 1\
**Last updated:** [March 28, 2022, 1:23pm UTC](https://discuss.elastic.co/t/xor-on-field-values/300346 "2022-03-28T13:23:25Z")

</div>

Hello, Is it possible to use the XOR function in packetbeat processors or in Advanced / JSON input on field values? My goal is to do XOR on field values retrieved by packetbeat.

---

## [Metricbeat Output to Secure Elasticsearch Error](https://discuss.elastic.co/t/metricbeat-output-to-secure-elasticsearch-error/300830)

<div class="topic-metadata">

**Author:** [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Replies:** 2\
**Last updated:** [March 28, 2022, 1:02pm UTC](https://discuss.elastic.co/t/metricbeat-output-to-secure-elasticsearch-error/300830 "2022-03-28T13:02:23Z")

</div>

Hi, I'm using ELK Stack 8.0, which is Elasticsearch running in secured mode. I'm having the problem to output my metricbeat to Elasticsearch. Below is the error when I run the command "metricbeat setup -e" {"log.leve…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=97)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=99)
