# Okta module in filebeat retrieving an error failed to find message

**URL:** <https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456>\
**Category:** Beats\
**Tags:** beats-module, metricbeat\
**Created:** [June 17, 2020, 11:06am UTC](https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456 "2020-06-17T11:06:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohan\_vel](https://avatars.discourse-cdn.com/v4/letter/m/49beb7/32.png) [@Mohan\_vel](https://discuss.elastic.co/u/Mohan_vel)\
**Post date:** [June 17, 2020, 11:06am UTC](https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456/1 "2020-06-17T11:06:49Z")

</div>

Hi all, i am using the filebeat to ship the logs from Okta to elasticsearch, connection established successfully and elaticsearch is receiving the event.dataset from okta when i look into the log messages it's showing **failed to find message** attached sample logs for reference.

```auto
    16:41:15.656 okta.system failed to find message

    16:41:16.656 okta.system failed to find message

```

**module.yml**

```auto
    - module: okta
      system:
        enabled: true
        var.url: https://dfdxxxx.okta.com/api/v1/logs
        var.api_key: '0xxxxxKXoqQ45654363v7CMzxxxxxpz'

```

Could some one help me to resolve this issue? Thanks in advance

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [June 18, 2020, 7:12am UTC](https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456/2 "2020-06-18T07:12:45Z")

</div>

Hi @Mohan_vel 🙂

Can you post a full log running metricbeat with `metricbeat -e -d "*"`, please? At first sight I don't see anything wrong in your config

---

<div class="post-metadata">

**Author:** ![Mohan\_vel](https://avatars.discourse-cdn.com/v4/letter/m/49beb7/32.png) [@Mohan\_vel](https://discuss.elastic.co/u/Mohan_vel)\
**Post date:** [June 18, 2020, 5:55pm UTC](https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456/3 "2020-06-18T17:55:55Z")

</div>

Hi @Mario_Castro,

Thanks for the reply as suggested i have given my log of filebeat might be helpful to you reach me in case if need any more clarification.

` `My filebeat command : .\filebeat.exe -c filebeat.yml -e` `

```auto
    2020-06-18T23:10:35.752+0530 INFO [publisher_pipeline_output] pipeline/output.go:111 Connection to backoff(elasticsearch(https://d6b421cb7csg6fg28e97a748730c5.eastus2.azure.elastic-cloud.com:9243)) established
    2020-06-18T23:10:35.791+0530 INFO [httpjson] httpjson/input.go:374 Continuing with pagination to URL: https://dev-dfdxxxx.okta.com/api/v1/logs?after=1592225702381_2 {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}
    2020-06-18T23:10:36.202+0530 INFO [httpjson] httpjson/input.go:374 Continuing with pagination to URL: https://dev-dfdxxxx.okta.com/api/v1/logs?after=1592243828313_1 {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}
    2020-06-18T23:10:36.602+0530 INFO [httpjson] httpjson/input.go:374 Continuing with pagination to URL: https://dev-dfdxxxx.okta.com/api/v1/logs?after=1592245378996_1 {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}
    2020-06-18T23:10:37.011+0530 INFO [httpjson] httpjson/input.go:374 Continuing with pagination to URL: https://dev-dfdxxxx.okta.com/api/v1/logs?after=1592297516961_1 {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}
    2020-06-18T23:10:37.465+0530 INFO [httpjson] httpjson/input.go:374 Continuing with pagination to URL: https://dev-dfdxxxx.okta.com/api/v1/logs?after=1592389227010_1 {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}
    2020-06-18T23:10:37.930+0530 INFO [httpjson] httpjson/input.go:374 Continuing with pagination to URL: https://dev-dfdxxxx.okta.com/api/v1/logs?after=1592470669470_1 {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}
    2020-06-18T23:10:38.349+0530 INFO [httpjson] httpjson/input.go:374 Continuing with pagination to URL: https://dev-dfdxxxx.okta.com/api/v1/logs?after=1592486666699_1 {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}
    2020-06-18T23:10:38.719+0530 INFO [httpjson] httpjson/input.go:374 Continuing with pagination to URL: https://dev-dfdxxxx.okta.com/api/v1/logs?after=1592491927890_1 {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}

    2020-06-18T23:11:38.964+0530 INFO [httpjson] httpjson/input.go:443 Process another repeated request. {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}

    2020-06-18T23:11:38.964+0530 INFO [httpjson] httpjson/input.go:443 Process another repeated request. {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}

    2020-06-18T23:11:38.964+0530 INFO [httpjson] httpjson/input.go:443 Process another repeated request. {"url": "https://dev-dfdxxxx.okta.com/api/v1/logs"}

```

Process another repeated request. This is what repeated.

---

<div class="post-metadata">

**Author:** ![Mohan\_vel](https://avatars.discourse-cdn.com/v4/letter/m/49beb7/32.png) [@Mohan\_vel](https://discuss.elastic.co/u/Mohan_vel)\
**Post date:** [June 22, 2020, 1:49pm UTC](https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456/4 "2020-06-22T13:49:22Z")

</div>

Hi @Mario_Castro,

Any update.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2020, 3:49pm UTC](https://discuss.elastic.co/t/okta-module-in-filebeat-retrieving-an-error-failed-to-find-message/237456/5 "2020-07-20T15:49:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
