# Problems sending .json w filebeat

**URL:** <https://discuss.elastic.co/t/problems-sending-json-w-filebeat/380547>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [July 29, 2025, 2:49pm UTC](https://discuss.elastic.co/t/problems-sending-json-w-filebeat/380547 "2025-07-29T14:49:32Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Flozkel](https://avatars.discourse-cdn.com/v4/letter/f/ac91a4/32.png) [@Flozkel](https://discuss.elastic.co/u/Flozkel)\
**Post date:** [July 29, 2025, 2:49pm UTC](https://discuss.elastic.co/t/problems-sending-json-w-filebeat/380547/1 "2025-07-29T14:49:32Z")

</div>

Hi guys,

For a while I have been trying to setup IDS on my RPI5. I'm rather new on this and experimenting for a homelab. The RPI does run a bit slow when everything is on, but again, its only for training.  
I have been searching this and various forums, bit I haven't been able to get it to work.

I run Suricata on the RPI and Elastic, Kibana and Filebeat in docker containers.  
Suricvata seems to run fine and I have managed to ship fast.log to Elastic. but after a re-install I can get nothing but 6000 empty fiels in Kibana.  
Suricata runs fine and so does Elastic, Kibana and Filebeat seem to do. But I must be missing something.

The Elastic setup is from this guide

> **[Getting started with the Elastic Stack and Docker-Compose](https://www.elastic.co/blog/getting-started-with-the-elastic-stack-and-docker-compose)**
>
> In part one of this two-part series, we’ll dive into configuring the components of a standard Elastic Stack consisting of Elasticsearch, Logstash, Kibana, and Beats (ELK-B), on which we can immediatel...

Here my filebeat.yml, docker-compose.yml (Elastic, Kibana and Filebeat) and suricata.yaml as well as the docker log from the Filebeat container.

> <https://gist.github.com/Jakob2212/abdabcb05ebb01665e713f8664c8aa9e>
>
> There are more than three files. show original
