# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=99

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 100

---

## [Filebeat config - several apps on one server](https://discuss.elastic.co/t/filebeat-config-several-apps-on-one-server/300837)

<div class="topic-metadata">

**Author:** [@Albert\_Komst](https://discuss.elastic.co/u/Albert_Komst)\
**Replies:** 0\
**Last updated:** [March 28, 2022, 12:07pm UTC](https://discuss.elastic.co/t/filebeat-config-several-apps-on-one-server/300837 "2022-03-28T12:07:14Z")

</div>

Hello, I have few apps I would like to monitor on one server. Filebeat config for app1 looks like below: filebeat: inputs: - fields: fileset: module: app1 name: debug fields\_und…

---

## [Make log from socket listener](https://discuss.elastic.co/t/make-log-from-socket-listener/300559)

<div class="topic-metadata">

**Author:** [@Badb0y](https://discuss.elastic.co/u/Badb0y)\
**Replies:** 2\
**Last updated:** [March 28, 2022, 5:26am UTC](https://discuss.elastic.co/t/make-log-from-socket-listener/300559 "2022-03-28T05:26:58Z")

</div>

Hi, Is there a way to make a log entry with filebeat from these entries that logstash can consume? I have entries like this Thu Mar 24 17:34:49 +07 2022 # table: https, type: ip, size:1048576, used:0 # table: http, t…

---

## [8.1 crowdstrike falcon pipeline](https://discuss.elastic.co/t/8-1-crowdstrike-falcon-pipeline/300631)

<div class="topic-metadata">

**Author:** [@NightSpark](https://discuss.elastic.co/u/NightSpark)\
**Replies:** 0\
**Last updated:** [March 24, 2022, 7:45pm UTC](https://discuss.elastic.co/t/8-1-crowdstrike-falcon-pipeline/300631 "2022-03-24T19:45:21Z")

</div>

Hi, Does 8.1 have a pipeline for the filebeat crowdstrike module? I am getting the following errow after upgrading and when trying to load latest pipelines. filebeat setup --pipelines --modules crowdstrike Exiting: m…

---

## [Unable to install Endpoint Security on windows server](https://discuss.elastic.co/t/unable-to-install-endpoint-security-on-windows-server/299654)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 4\
**Last updated:** [March 27, 2022, 9:38pm UTC](https://discuss.elastic.co/t/unable-to-install-endpoint-security-on-windows-server/299654 "2022-03-27T21:38:52Z")

</div>

Hello, I'm trying to deploy fleet policy that installs endpoint security on windows server, but the agent keep being unhealthy because of endpoint security install failure. try to execute .\\endpoint-security.exe instal…

---

## [There is no option to download the amd64.deb file](https://discuss.elastic.co/t/there-is-no-option-to-download-the-amd64-deb-file/300777)

<div class="topic-metadata">

**Author:** [@alah64](https://discuss.elastic.co/u/alah64)\
**Replies:** 0\
**Last updated:** [March 27, 2022, 9:52am UTC](https://discuss.elastic.co/t/there-is-no-option-to-download-the-amd64-deb-file/300777 "2022-03-27T09:52:36Z")

</div>

hi Why is there no download address for the amd64.deb file from the pages related to downloading stack beats files? For example, see the filebeat download page: Download Filebeat • Lightweight Log Analysis | Elastic T…

---

## [Unknown beats protocol version: 22, 3, 71, 69](https://discuss.elastic.co/t/unknown-beats-protocol-version-22-3-71-69/300730)

<div class="topic-metadata">

**Author:** [@Uzmasaman\_Chanderki](https://discuss.elastic.co/u/Uzmasaman_Chanderki)\
**Replies:** 1\
**Last updated:** [March 26, 2022, 3:02am UTC](https://discuss.elastic.co/t/unknown-beats-protocol-version-22-3-71-69/300730 "2022-03-26T03:02:37Z")

</div>

Hello, I am new to Elasticsearch and Graylog. I have implemented Beats (filebeat heartbeat and metricbeat) on Remote Nomad cluster. I am shipping logs and metric to a centralised server. Everything seems to work fine unt…

---

## [Question on Shipping logs from multiple microservice to Elasticsearch](https://discuss.elastic.co/t/question-on-shipping-logs-from-multiple-microservice-to-elasticsearch/300738)

<div class="topic-metadata">

**Author:** [@Pradeep\_Kumar3](https://discuss.elastic.co/u/Pradeep_Kumar3)\
**Replies:** 1\
**Last updated:** [March 26, 2022, 2:58am UTC](https://discuss.elastic.co/t/question-on-shipping-logs-from-multiple-microservice-to-elasticsearch/300738 "2022-03-26T02:58:29Z")

</div>

I am considering pushing the application logs from multiple microservices using filebeats to a remote logstash server. Will the fiebeat acquire the lock on the logstash server to write the file? What are the consideratio…

---

## [Metricbeats using port 9243 instead of 443](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661)

<div class="topic-metadata">

**Author:** [@alphabet5](https://discuss.elastic.co/u/alphabet5)\
**Replies:** 4\
**Last updated:** [March 26, 2022, 1:40am UTC](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661 "2022-03-26T01:40:16Z")

</div>

Using elastic cloud I am trying to connect metricbeats with the provided cloud.id/auth. I'm seeing this in the logs {"log.level":"info","@timestamp":"2022-03-25T05:56:18.524Z","log.logger":"publisher\_pipeline\_output","…

---

## [Winlogbeat Not Logging All Event ID](https://discuss.elastic.co/t/winlogbeat-not-logging-all-event-id/300725)

<div class="topic-metadata">

**Author:** [@cmenuey](https://discuss.elastic.co/u/cmenuey)\
**Replies:** 0\
**Last updated:** [March 25, 2022, 8:12pm UTC](https://discuss.elastic.co/t/winlogbeat-not-logging-all-event-id/300725 "2022-03-25T20:12:16Z")

</div>

Hi all, I installed the ELK stack to try it out, all services on the same windows server. I was able to get the winlogbeat on a couple of domain controllers and shipping logs. I enabled advanced logging to get group mem…

---

## [Metricbeat 7.17.1 error getting filesystem list: open /etc/mtab](https://discuss.elastic.co/t/metricbeat-7-17-1-error-getting-filesystem-list-open-etc-mtab/300625)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [March 25, 2022, 6:25pm UTC](https://discuss.elastic.co/t/metricbeat-7-17-1-error-getting-filesystem-list-open-etc-mtab/300625 "2022-03-25T18:25:37Z")

</div>

Hi we have recently upgraded from 7.9.3 to 7.17.1. We now get this error in the Metricbeat logs 2022-03-24T19:02:27.030Z ERROR module/wrapper.go:259 Error fetching data for metricset system.filesystem: error …

---

## [Metricbeat, Filebeat spawning lots of child procs](https://discuss.elastic.co/t/metricbeat-filebeat-spawning-lots-of-child-procs/300503)

<div class="topic-metadata">

**Author:** [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Replies:** 2\
**Last updated:** [March 25, 2022, 3:31pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat-spawning-lots-of-child-procs/300503 "2022-03-25T15:31:29Z")

</div>

Hello, Im running fbeat, mbeat 7.17 on centos 7 I see it spawning off tons of child procs, is there way to limit this? Whats the reason why so many procs are spawned?

---

## [Metricbeat add\_field from file?](https://discuss.elastic.co/t/metricbeat-add-field-from-file/300718)

<div class="topic-metadata">

**Author:** [@thech](https://discuss.elastic.co/u/thech)\
**Replies:** 0\
**Last updated:** [March 25, 2022, 3:31pm UTC](https://discuss.elastic.co/t/metricbeat-add-field-from-file/300718 "2022-03-25T15:31:15Z")

</div>

Hello, I have Metricbeat and my application running from different containers. The application starts and generates a UUID, storing it in a file app.uuid. I can mount this file to Metricbeat, but how can I add it as a f…

---

## [HTTP monitor and TLS connection in Heartbeat 7.17.0](https://discuss.elastic.co/t/http-monitor-and-tls-connection-in-heartbeat-7-17-0/300343)

<div class="topic-metadata">

**Author:** [@gigaset](https://discuss.elastic.co/u/gigaset)\
**Replies:** 5\
**Last updated:** [March 25, 2022, 9:59am UTC](https://discuss.elastic.co/t/http-monitor-and-tls-connection-in-heartbeat-7-17-0/300343 "2022-03-25T09:59:59Z")

</div>

Hi, I'm using Heartbeat v7.17.0, and it looks like there is a problem with establishing the TLS connection in the HTTP monitor. The first problem is that the config option ssl.verification\_mode: none seems not to work. …

---

## [Couldn't Harvest log file from Docker](https://discuss.elastic.co/t/couldnt-harvest-log-file-from-docker/300667)

<div class="topic-metadata">

**Author:** [@chathuwadev\_dev](https://discuss.elastic.co/u/chathuwadev_dev)\
**Replies:** 0\
**Last updated:** [March 25, 2022, 7:47am UTC](https://discuss.elastic.co/t/couldnt-harvest-log-file-from-docker/300667 "2022-03-25T07:47:09Z")

</div>

Hi All, I am beginner for ELK stack, Below my work scenario I am going to centralize logs from my Microservices Also i used ELK stack and i already config it in docker-compose.yml Kibana,Elasticsearch and Logs…

---

## [Need assistance with creating daily winlogbeat indices that follow an ILM policy](https://discuss.elastic.co/t/need-assistance-with-creating-daily-winlogbeat-indices-that-follow-an-ilm-policy/300665)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [March 25, 2022, 7:25am UTC](https://discuss.elastic.co/t/need-assistance-with-creating-daily-winlogbeat-indices-that-follow-an-ilm-policy/300665 "2022-03-25T07:25:43Z")

</div>

I created a winlogbeat index with a PUT request as so : PUT /%3Cwinlogbeat-%7Bnow%2Fd%7D-000001%3E { "aliases": { "winlogbeat": { "is\_write\_index": true } } } It then asked me to select a rollover alias from a dropdown…

---

## [Filebeat and Logstash tuning - How to align performance](https://discuss.elastic.co/t/filebeat-and-logstash-tuning-how-to-align-performance/300268)

<div class="topic-metadata">

**Author:** [@bar0n36](https://discuss.elastic.co/u/bar0n36)\
**Replies:** 1\
**Last updated:** [March 24, 2022, 10:22pm UTC](https://discuss.elastic.co/t/filebeat-and-logstash-tuning-how-to-align-performance/300268 "2022-03-24T22:22:55Z")

</div>

I am in the process of trying to ingest a massive backlog of logs (10s of TB) via Filebeat \> Logstash \> Ingest Node \> Elasticsearch. I have scaled out the pipeline extensively and am now at a point where I am struggling…

---

## [Incorrect HTTP method for uri \[/\<filebeat-7.16.0-{now/d}-000001\>\] and method \[PUT\], allowed: \[POST\]](https://discuss.elastic.co/t/incorrect-http-method-for-uri-filebeat-7-16-0-now-d-000001-and-method-put-allowed-post/300629)

<div class="topic-metadata">

**Author:** [@claudioemmanuel](https://discuss.elastic.co/u/claudioemmanuel)\
**Replies:** 0\
**Last updated:** [March 24, 2022, 7:41pm UTC](https://discuss.elastic.co/t/incorrect-http-method-for-uri-filebeat-7-16-0-now-d-000001-and-method-put-allowed-post/300629 "2022-03-24T19:41:08Z")

</div>

I'm running on nginx in my docker container, I installed filebeat and configured it so that the nginx access and error logs are sent directly to my elastic/kibana but the logs are not appearing or being sent. Running a …

---

## [Multiple Filebeat logs path configuration stops the filebeat](https://discuss.elastic.co/t/multiple-filebeat-logs-path-configuration-stops-the-filebeat/300471)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [March 24, 2022, 5:54pm UTC](https://discuss.elastic.co/t/multiple-filebeat-logs-path-configuration-stops-the-filebeat/300471 "2022-03-24T17:54:51Z")

</div>

Hello All, 1)After I'm configuring multiple filebeat path in filebeat.yml,filebeat gets stopped with below error: Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing …

---

## [Issue with activemq module in metricbeat](https://discuss.elastic.co/t/issue-with-activemq-module-in-metricbeat/300499)

<div class="topic-metadata">

**Author:** [@christopherjhachey](https://discuss.elastic.co/u/christopherjhachey)\
**Replies:** 2\
**Last updated:** [March 24, 2022, 4:35pm UTC](https://discuss.elastic.co/t/issue-with-activemq-module-in-metricbeat/300499 "2022-03-24T16:35:00Z")

</div>

Getting the following error trying to use activemq module in metricbeat framework. Exiting: 3 errors: metricset 'activemq/broker' not found; metricset 'activemq/queue' not found; metricset 'activemq/topic' not found I'…

---

## [Log .NET Runtime source is not recovering](https://discuss.elastic.co/t/log-net-runtime-source-is-not-recovering/300463)

<div class="topic-metadata">

**Author:** [@lsbitri88](https://discuss.elastic.co/u/lsbitri88)\
**Replies:** 2\
**Last updated:** [March 24, 2022, 3:26pm UTC](https://discuss.elastic.co/t/log-net-runtime-source-is-not-recovering/300463 "2022-03-24T15:26:10Z")

</div>

Hi, the winlogs from the .Net Runtime source with the message below are not recovered \<La description de l’ID d’événement 0 dans la source .NET Runtime est introuvable. Le composant qui a déclenché cet événement n’est …

---

## [Unable to start filebeat getting Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at http://localhost:5601: Failed to parse JSON response: invalid character '\<' l](https://discuss.elastic.co/t/unable-to-start-filebeat-getting-exiting-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts-errors-error-connecting-to-elasticsearch-at-http-localhost-failed-to-parse-json-response-invalid-character-l/300412)

<div class="topic-metadata">

**Author:** [@sureshaws](https://discuss.elastic.co/u/sureshaws)\
**Replies:** 3\
**Last updated:** [March 24, 2022, 3:01pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-getting-exiting-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts-errors-error-connecting-to-elasticsearch-at-http-localhost-failed-to-parse-json-response-invalid-character-l/300412 "2022-03-24T15:01:14Z")

</div>

Getting the below error Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at http://localhost:5601: Failed to parse JSON response: invalid character '\<' l …

---

## [Filebeat 8.1 locks renamed rolling logs forever](https://discuss.elastic.co/t/filebeat-8-1-locks-renamed-rolling-logs-forever/300428)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 1\
**Last updated:** [March 24, 2022, 2:58pm UTC](https://discuss.elastic.co/t/filebeat-8-1-locks-renamed-rolling-logs-forever/300428 "2022-03-24T14:58:11Z")

</div>

After switching from Filebeat 7.17 to Filebeat 8.1 and introducing type filestream into our configuration, it seems that Filebeat locks renamed logs forever, causing disk space issues. We have a log4j based logs that ro…

---

## [How configuration options Auditbeat in windows 10](https://discuss.elastic.co/t/how-configuration-options-auditbeat-in-windows-10/300455)

<div class="topic-metadata">

**Author:** [@nour41\_nour41](https://discuss.elastic.co/u/nour41_nour41)\
**Replies:** 1\
**Last updated:** [March 24, 2022, 2:55pm UTC](https://discuss.elastic.co/t/how-configuration-options-auditbeat-in-windows-10/300455 "2022-03-24T14:55:31Z")

</div>

how configuration options Auditbeat in windows 10

---

## [How do I verify that packetbeat transmits data to Elasticsearch](https://discuss.elastic.co/t/how-do-i-verify-that-packetbeat-transmits-data-to-elasticsearch/300297)

<div class="topic-metadata">

**Author:** [@BlackFox](https://discuss.elastic.co/u/BlackFox)\
**Replies:** 1\
**Last updated:** [March 24, 2022, 2:22pm UTC](https://discuss.elastic.co/t/how-do-i-verify-that-packetbeat-transmits-data-to-elasticsearch/300297 "2022-03-24T14:22:59Z")

</div>

Now I have two hosts. ES and Kibana are deployed on host A (Ubuntu, single network card) and packetbeat is deployed on host B (Ubuntu, dual network card). Host B can open ports 9200 and 5601 of host A by using Firefox b…

---

## [Documentation for Fleet API usage](https://discuss.elastic.co/t/documentation-for-fleet-api-usage/300390)

<div class="topic-metadata">

**Author:** [@trudyc](https://discuss.elastic.co/u/trudyc)\
**Replies:** 2\
**Last updated:** [March 23, 2022, 2:53pm UTC](https://discuss.elastic.co/t/documentation-for-fleet-api-usage/300390 "2022-03-23T14:53:46Z")

</div>

Hello all, I am looking for better documentation about using the Fleet API in Elastic/Kibana 7.17. I have looked at https://github.com/elastic/kibana/blob/7.17/x-pack/plugins/fleet/common/openapi/README.md https://pe…

---

## [High CPU Usage on some filebeat instances](https://discuss.elastic.co/t/high-cpu-usage-on-some-filebeat-instances/298426)

<div class="topic-metadata">

**Author:** [@Lebvanih](https://discuss.elastic.co/u/Lebvanih)\
**Replies:** 3\
**Last updated:** [March 23, 2022, 12:25pm UTC](https://discuss.elastic.co/t/high-cpu-usage-on-some-filebeat-instances/298426 "2022-03-23T12:25:15Z")

</div>

Hello, Some information about the system as this can help: Installation inside K8S using elastic helm charts. Filebeat version 7.16.3 Amount of pods per nodes: ~160 Amount of logs harvested per nodes: ~100 CPU usage r…

---

## [Filebeat: Exiting: couldn't connect to any of the configured Elasticsearch hosts](https://discuss.elastic.co/t/filebeat-exiting-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/297997)

<div class="topic-metadata">

**Author:** [@RomanKau](https://discuss.elastic.co/u/RomanKau)\
**Replies:** 6\
**Last updated:** [March 23, 2022, 8:01am UTC](https://discuss.elastic.co/t/filebeat-exiting-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/297997 "2022-03-23T08:01:08Z")

</div>

Running Windows 10 the Elastic and Kibana as .bat work fine but configuring beats from .zip download fails for me. I run all on the same machine and only changed the .yml file with this guide: Even after a reset to de…

---

## [Ignore\_inactive does not work in filebeat with filestream config type (filebeat version:8.1.0)](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type-filebeat-version-8-1-0/300410)

<div class="topic-metadata">

**Author:** [@BinGuoGuo](https://discuss.elastic.co/u/BinGuoGuo)\
**Replies:** 0\
**Last updated:** [March 23, 2022, 6:45am UTC](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type-filebeat-version-8-1-0/300410 "2022-03-23T06:45:31Z")

</div>

When I use the filestream type instead of the log type, filebeat always reads the entire log file from the beginning. - type: filestream id: test\_id enable: true paths: - "/usr/share/filebeat/inputs.d/\*.log" …

---

## [Ignore\_inactive is not working](https://discuss.elastic.co/t/ignore-inactive-is-not-working/299193)

<div class="topic-metadata">

**Author:** [@lingminzeng](https://discuss.elastic.co/u/lingminzeng)\
**Replies:** 4\
**Last updated:** [March 23, 2022, 6:18am UTC](https://discuss.elastic.co/t/ignore-inactive-is-not-working/299193 "2022-03-23T06:18:37Z")

</div>

\#filebeat-8.0.0 filebeat.inputs: \* type: filestream enabled: true paths: \* /var/log/\*.log ignore\_inactive: since\_last\_start I configure ignore\_inactive: since\_last\_start,but filebeat still read at the beginning posit…

---

## [Filebeat to support TLS1.3](https://discuss.elastic.co/t/filebeat-to-support-tls1-3/299045)

<div class="topic-metadata">

**Author:** [@Nikhitha](https://discuss.elastic.co/u/Nikhitha)\
**Replies:** 4\
**Last updated:** [March 22, 2022, 4:22pm UTC](https://discuss.elastic.co/t/filebeat-to-support-tls1-3/299045 "2022-03-22T16:22:19Z")

</div>

Does filebeat 7.16.0 suport TLS 1.3?

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=98)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=100)
