This is another log excerpt from today:
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:57:57.405+0200","log.logger":"publisher_pipeline_output","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/publisher/pipeline.(*netClientWorker).run","file.name":"pipeline/client_worker.go","file.line":138},"message":"Connecting to backoff(elasticsearch(https://elk.my.domain:9200))","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:57:57.409+0200","log.logger":"elasticsearch.esclientleg","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/esleg/eslegclient.(*Connection).Ping","file.name":"eslegclient/connection.go","file.line":324},"message":"Attempting to connect to Elasticsearch version 8.19.3 (default)","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:57:57.420+0200","log.logger":"index-management","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/idxmgmt.(*indexManager).Setup","file.name":"idxmgmt/index_support.go","file.line":254},"message":"Auto lifecycle enable success.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:57:57.422+0200","log.logger":"index-management.ilm","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/idxmgmt/lifecycle.(*stdManager).EnsurePolicy","file.name":"lifecycle/standard_manager.go","file.line":111},"message":"lifecycle policy filebeat exists already.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:57:57.422+0200","log.logger":"index-management","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/idxmgmt.applyLifecycleSettingsToTemplate","file.name":"idxmgmt/index_support.go","file.line":402},"message":"Set settings.index.lifecycle.name in template to filebeat as ILM is enabled.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:57:57.431+0200","log.logger":"template_loader","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/template.(*ESLoader).Load","file.name":"template/load.go","file.line":121},"message":"Template \"filebeat-8.19.3\" already exists and will not be overwritten.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:57:57.431+0200","log.logger":"index-management","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/idxmgmt.(*indexManager).Setup","file.name":"idxmgmt/index_support.go","file.line":299},"message":"Loaded index template.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:57:57.432+0200","log.logger":"publisher_pipeline_output","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/publisher/pipeline.(*netClientWorker).run","file.name":"pipeline/client_worker.go","file.line":146},"message":"Connection to backoff(elasticsearch(https://elk.my.domain:9200)) established","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:57:57 elk filebeat[313502]: {"log.level":"debug","@timestamp":"2025-10-02T14:57:57.438+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.(*Client).doBulkRequest","file.name":"elasticsearch/client.go","file.line":317},"message":"doBulkRequest: 111 events have been sent to elasticsearch in 5.917839ms.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:07 elk filebeat[313502]: {"log.level":"warn","@timestamp":"2025-10-02T14:58:07.302+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.NewClient.func3","file.name":"elasticsearch/client.go","file.line":179},"message":"Failed to index 111 events in last 10s: events were dropped! Look at the event log to view the event and cause.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:07 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:58:07.405+0200","log.logger":"input.harvester","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/log.(*Harvester).Run","file.name":"log/harvester.go","file.line":313},"message":"Harvester started for paths: [/var/log/auth.log*]","service.name":"filebeat","input_id":"3802b47a-4011-43fc-a425-a5cd4eaabe88","source_file":"/var/log/auth.log","state_id":"native::96-64773","finished":false,"os_id":"96-64773","old_source":"/var/log/auth.log","old_finished":true,"old_os_id":"96-64773","harvester_id":"941c8ba5-915c-446b-8c69-75b9e189e9a4","ecs.version":"1.6.0"}
Oct 2 14:58:07 elk filebeat[313502]: {"log.level":"debug","@timestamp":"2025-10-02T14:58:07.417+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.(*Client).doBulkRequest","file.name":"elasticsearch/client.go","file.line":317},"message":"doBulkRequest: 64 events have been sent to elasticsearch in 7.92079ms.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:17 elk filebeat[313502]: {"log.level":"warn","@timestamp":"2025-10-02T14:58:17.302+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.NewClient.func3","file.name":"elasticsearch/client.go","file.line":179},"message":"Failed to index 64 events in last 10s: events were dropped! Look at the event log to view the event and cause.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:17 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:58:17.305+0200","log.logger":"monitoring","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/monitoring/report/log.(*reporter).logSnapshot","file.name":"log/log.go","file.line":192},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"cpu":{"id":"filebeat.service"},"memory":{"id":"filebeat.service","mem":{"usage":{"bytes":183050240}}}},"cpu":{"system":{"ticks":50,"time":{"ms":50}},"total":{"ticks":190,"time":{"ms":190},"value":190},"user":{"ticks":140,"time":{"ms":140}}},"handles":{"limit":{"hard":524288,"soft":524287},"open":15},"info":{"ephemeral_id":"7d2a3b4f-6851-45fd-a877-ab585974d991","name":"filebeat","uptime":{"ms":33057},"version":"8.19.3"},"memstats":{"gc_next":47130290,"memory_alloc":35617992,"memory_sys":57169160,"memory_total":69264920,"rss":157614080},"runtime":{"goroutines":60}},"filebeat":{"events":{"active":32,"added":213,"done":181},"harvester":{"open_files":2,"running":2,"started":2}},"libbeat":{"config":{"module":{"running":1,"starts":1},"reloads":1,"scans":1},"output":{"events":{"active":0,"batches":2,"dropped":175,"total":175},"read":{"bytes":9506,"errors":2},"type":"elasticsearch","write":{"bytes":31897,"latency":{"histogram":{"count":2,"max":7,"mean":6,"median":6,"min":5,"p75":7,"p95":7,"p99":7,"p999":7,"stddev":1}}}},"pipeline":{"clients":2,"events":{"active":32,"filtered":6,"published":207,"total":213},"queue":{"acked":175,"added":{"bytes":284208,"events":207},"consumed":{"bytes":242974,"events":175},"filled":{"bytes":41234,"events":32,"pct":0.01},"max_bytes":0,"max_events":3200,"removed":{"bytes":242974,"events":175}}}},"registrar":{"states":{"current":4,"update":181},"writes":{"success":3,"total":3}},"system":{"cpu":{"cores":4},"load":{"1":5.62,"15":4.3,"5":4.72,"norm":{"1":1.405,"15":1.075,"5":1.18}}}},"ecs.version":"1.6.0"}}
Oct 2 14:58:18 elk filebeat[313502]: {"log.level":"debug","@timestamp":"2025-10-02T14:58:18.421+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.(*Client).doBulkRequest","file.name":"elasticsearch/client.go","file.line":317},"message":"doBulkRequest: 62 events have been sent to elasticsearch in 6.589463ms.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:27 elk filebeat[313502]: {"log.level":"warn","@timestamp":"2025-10-02T14:58:27.302+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.NewClient.func3","file.name":"elasticsearch/client.go","file.line":179},"message":"Failed to index 62 events in last 10s: events were dropped! Look at the event log to view the event and cause.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:30 elk filebeat[313502]: {"log.level":"debug","@timestamp":"2025-10-02T14:58:30.426+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.(*Client).doBulkRequest","file.name":"elasticsearch/client.go","file.line":317},"message":"doBulkRequest: 58 events have been sent to elasticsearch in 6.599465ms.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:37 elk filebeat[313502]: {"log.level":"warn","@timestamp":"2025-10-02T14:58:37.302+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.NewClient.func3","file.name":"elasticsearch/client.go","file.line":179},"message":"Failed to index 58 events in last 10s: events were dropped! Look at the event log to view the event and cause.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:42 elk filebeat[313502]: {"log.level":"debug","@timestamp":"2025-10-02T14:58:42.430+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.(*Client).doBulkRequest","file.name":"elasticsearch/client.go","file.line":317},"message":"doBulkRequest: 56 events have been sent to elasticsearch in 6.622743ms.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:47 elk filebeat[313502]: {"log.level":"warn","@timestamp":"2025-10-02T14:58:47.302+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.NewClient.func3","file.name":"elasticsearch/client.go","file.line":179},"message":"Failed to index 56 events in last 10s: events were dropped! Look at the event log to view the event and cause.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:47 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T14:58:47.306+0200","log.logger":"monitoring","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/monitoring/report/log.(*reporter).logSnapshot","file.name":"log/log.go","file.line":192},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":183586816}}}},"cpu":{"system":{"ticks":60,"time":{"ms":10}},"total":{"ticks":220,"time":{"ms":30},"value":220},"user":{"ticks":160,"time":{"ms":20}}},"handles":{"limit":{"hard":524288,"soft":524287},"open":13},"info":{"ephemeral_id":"7d2a3b4f-6851-45fd-a877-ab585974d991","uptime":{"ms":63057},"version":"8.19.3"},"memstats":{"gc_next":47130290,"memory_alloc":39530616,"memory_total":73177544,"rss":158572544},"runtime":{"goroutines":56}},"filebeat":{"events":{"active":1,"added":145,"done":176},"harvester":{"open_files":2,"running":2}},"libbeat":{"config":{"module":{"running":1}},"output":{"events":{"active":0,"batches":3,"dropped":176,"total":176},"read":{"bytes":1847,"errors":3},"write":{"bytes":28389,"latency":{"histogram":{"count":5,"max":7,"mean":6,"median":6,"min":5,"p75":6.5,"p95":7,"p99":7,"p999":7,"stddev":0.6324555320336759}}}},"pipeline":{"clients":2,"events":{"active":1,"published":145,"total":145},"queue":{"acked":176,"added":{"bytes":188362,"events":145},"consumed":{"bytes":228442,"events":176},"filled":{"bytes":1154,"events":1,"pct":0.0003125},"max_bytes":0,"max_events":3200,"removed":{"bytes":228442,"events":176}}}},"registrar":{"states":{"current":4,"update":176},"writes":{"success":3,"total":3}},"system":{"load":{"1":5.57,"15":4.34,"5":4.8,"norm":{"1":1.3925,"15":1.085,"5":1.2}}}},"ecs.version":"1.6.0"}}
Oct 2 14:58:54 elk filebeat[313502]: {"log.level":"debug","@timestamp":"2025-10-02T14:58:54.437+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.(*Client).doBulkRequest","file.name":"elasticsearch/client.go","file.line":317},"message":"doBulkRequest: 31 events have been sent to elasticsearch in 6.34368ms.","service.name":"filebeat","ecs.version":"1.6.0"}
Oct 2 14:58:57 elk filebeat[313502]: {"log.level":"warn","@timestamp":"2025-10-02T14:58:57.302+0200","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.NewClient.func3","file.name":"elasticsearch/client.go","file.line":179},"message":"Failed to index 31 events in last 10s: events were dropped! Look at the event log to view the event and cause.","service.name":"filebeat","ecs.version":"1.6.0"}
Below you can find the 30s metrics log:
Oct 2 15:00:17 elk filebeat[313502]: {"log.level":"info","@timestamp":"2025-10-02T15:00:17.305+0200","log.logger":"monitoring","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/monitoring/report/log.(*reporter).logSnapshot","file.name":"log/log.go","file.line":192},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":184909824}}}},"cpu":{"system":{"ticks":80,"time":{"ms":10}},"total":{"ticks":310,"time":{"ms":30},"value":310},"user":{"ticks":230,"time":{"ms":20}}},"handles":{"limit":{"hard":524288,"soft":524287},"open":13},"info":{"ephemeral_id":"7d2a3b4f-6851-45fd-a877-ab585974d991","uptime":{"ms":153057},"version":"8.19.3"},"memstats":{"gc_next":47739730,"memory_alloc":30341296,"memory_sys":262144,"memory_total":83799728,"rss":158572544},"runtime":{"goroutines":56}},"filebeat":{"events":{"active":29,"added":119,"done":146},"harvester":{"open_files":2,"running":2}},"libbeat":{"config":{"module":{"running":1}},"output":{"events":{"active":0,"batches":3,"dropped":146,"total":146},"read":{"bytes":1748,"errors":3},"write":{"bytes":23786,"latency":{"histogram":{"count":13,"max":7,"mean":5.923076923076923,"median":6,"min":5,"p75":6,"p95":7,"p99":7,"p999":7,"stddev":0.6153846153846154}}}},"pipeline":{"clients":2,"events":{"active":29,"published":119,"total":119},"queue":{"acked":146,"added":{"bytes":155555,"events":119},"consumed":{"bytes":189579,"events":146},"filled":{"bytes":37131,"events":29,"pct":0.0090625},"max_bytes":0,"max_events":3200,"removed":{"bytes":189579,"events":146}}}},"registrar":{"states":{"current":4,"update":146},"writes":{"success":3,"total":3}},"system":{"load":{"1":4.07,"15":4.29,"5":4.53,"norm":{"1":1.0175,"15":1.0725,"5":1.1325}}}},"ecs.version":"1.6.0"}}
This is the /inputs
endpoint result:
root@elk /e/filebeat# http 127.0.0.1:5066/inputs/
HTTP/1.1 200 OK
Content-Encoding: gzip
Content-Length: 27
Content-Type: application/json; charset=utf-8
Date: Thu, 02 Oct 2025 13:01:25 GMT
Vary: Accept-Encoding
[]
In fact, I don’t have any input enabled in the Filebeat configuration, but I have the system module enabled:
root@elk /e/filebeat# cat /etc/filebeat/modules.d/system.yml
# Ansible managed
# Filebeat default configuration for module system on Linux
- module: system
syslog:
enabled: true
var.paths: ["/var/log/syslog*"]
auth:
enabled: true
var.paths: ["/var/log/auth.log*"]
Thank you!