# \#beats-module

**URL:** https://discuss.elastic.co/tag/beats-module/29.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [\[Elastic Log Driver\] Structured JSON logs breaks when Docker splits large log lines](https://discuss.elastic.co/t/elastic-log-driver-structured-json-logs-breaks-when-docker-splits-large-log-lines/385448)

<div class="topic-metadata">

**Author:** [@empee](https://discuss.elastic.co/u/empee)\
**Replies:** 0\
**Last updated:** [March 14, 2026, 2:10am UTC](https://discuss.elastic.co/t/elastic-log-driver-structured-json-logs-breaks-when-docker-splits-large-log-lines/385448 "2026-03-14T02:10:11Z")

</div>

Summary When using the Elastic Docker Logging Plugin, applications that already emit structured JSON logs cannot reliably ingest them into Elasticsearch because Docker may split large log lines before they reach the logg…

---

## [Elastic Agent 9.1.5 Fingerprint Processor Inconsistency - Breaks Log Integrity](https://discuss.elastic.co/t/elastic-agent-9-1-5-fingerprint-processor-inconsistency-breaks-log-integrity/382837)

<div class="topic-metadata">

**Author:** [@blakester205](https://discuss.elastic.co/u/blakester205)\
**Replies:** 2\
**Last updated:** [October 20, 2025, 5:09pm UTC](https://discuss.elastic.co/t/elastic-agent-9-1-5-fingerprint-processor-inconsistency-breaks-log-integrity/382837 "2025-10-20T17:09:44Z")

</div>

Elastic Agent 9.1.5 Fingerprint Processor Bug - Different Hashes for Identical Data Hey everyone, I've run into a pretty serious issue with the fingerprint processor in Elastic Agent 9.1.5 that I wanted to share with th…

---

## [Elastic Agent plugin Logs PANW (SYSLOG) reports wrong traffic direction](https://discuss.elastic.co/t/elastic-agent-plugin-logs-panw-syslog-reports-wrong-traffic-direction/382637)

<div class="topic-metadata">

**Author:** [@dmgeurts-mm](https://discuss.elastic.co/u/dmgeurts-mm)\
**Replies:** 2\
**Last updated:** [October 13, 2025, 3:18pm UTC](https://discuss.elastic.co/t/elastic-agent-plugin-logs-panw-syslog-reports-wrong-traffic-direction/382637 "2025-10-13T15:18:06Z")

</div>

network.direction is logged wrong despite configuring the zones under advanced settings in the Agent Policy. In fact the direction appears random as I can find traffic logged with a source zone of WAN and a target zone o…

---

## [Fortinet module \`sentdelta\` and \`rcvddelta\` field type is not number](https://discuss.elastic.co/t/fortinet-module-sentdelta-and-rcvddelta-field-type-is-not-number/382240)

<div class="topic-metadata">

**Author:** [@hylowaker](https://discuss.elastic.co/u/hylowaker)\
**Replies:** 1\
**Last updated:** [September 26, 2025, 1:31pm UTC](https://discuss.elastic.co/t/fortinet-module-sentdelta-and-rcvddelta-field-type-is-not-number/382240 "2025-09-26T13:31:56Z")

</div>

In the Filebeat fortinet module, the fields fortinet.firewall.sentdelta and fortinet.firewall.rcvddelta are set as Keyword type. I am not sure if it is intended or not, but I think these fields should be Long type to su…

---

## [Nginx module in filebeat configuration](https://discuss.elastic.co/t/nginx-module-in-filebeat-configuration/363563)

<div class="topic-metadata">

**Author:** [@tsboris](https://discuss.elastic.co/u/tsboris)\
**Replies:** 2\
**Last updated:** [September 14, 2025, 7:37am UTC](https://discuss.elastic.co/t/nginx-module-in-filebeat-configuration/363563 "2025-09-14T07:37:54Z")

</div>

Hello, Following this thread: Filebeat nginx module I tried to configure my Beat CRD to use the NGINX module as part of the ECK deployment in a Kubernetes cluster. I compare the logs results in Kibana before and after…

---

## [Elastic logging plugin for docker fails to start containers](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-fails-to-start-containers/381592)

<div class="topic-metadata">

**Author:** [@shabeebk](https://discuss.elastic.co/u/shabeebk)\
**Replies:** 0\
**Last updated:** [September 4, 2025, 1:54am UTC](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-fails-to-start-containers/381592 "2025-09-04T01:54:28Z")

</div>

Hello, After upgrading the Elasticsearch to 9.1.3, the docker containers cannot start due to issue with elastic logging plugin. Background: We have been using Elasticsearch 8.15.4 with docker plugin elastic/elastic-l…

---

## [Filebeat Azure module - mapper\_parsing\_exception for field azure.signinlogs.properties.conditional\_access\_audiences](https://discuss.elastic.co/t/filebeat-azure-module-mapper-parsing-exception-for-field-azure-signinlogs-properties-conditional-access-audiences/378904)

<div class="topic-metadata">

**Author:** [@mczajkowski](https://discuss.elastic.co/u/mczajkowski)\
**Replies:** 1\
**Last updated:** [June 6, 2025, 3:31pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-mapper-parsing-exception-for-field-azure-signinlogs-properties-conditional-access-audiences/378904 "2025-06-06T15:31:01Z")

</div>

Hello It seems there was a change in the Azure Singin logs syntax since 2025-06-04. Since that date the amount of logs grabbing by our Filebeat dramatically decreased. Debug log shows it is caused by "azure.signinlogs.…

---

## [Multiple threat frameworks in a single rule](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533)

<div class="topic-metadata">

**Author:** [@nahuel978](https://discuss.elastic.co/u/nahuel978)\
**Replies:** 3\
**Last updated:** [April 28, 2025, 2:55am UTC](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533 "2025-04-28T02:55:41Z")

</div>

I'm interested in knowing if any Elastic detection rules use two different threat frameworks within the same rule. According to the ECS documentation: The threat.framework field is defined as a keyword, which suggests…

---

## [Osquerybeat Permission Error - No Queries possible](https://discuss.elastic.co/t/osquerybeat-permission-error-no-queries-possible/371400)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 4\
**Last updated:** [March 10, 2025, 12:27pm UTC](https://discuss.elastic.co/t/osquerybeat-permission-error-no-queries-possible/371400 "2025-03-10T12:27:57Z")

</div>

We are using Elastic-Stack 8.16.1 and also Elastic-Agents 8.16.1 integrated in Elastic Fleet. Currently, we are having problems with Osquery on Windows Systems where we traced the problem down to the following errors: …

---

## [Warning is observed huge number of times 'input V2 factory.CheckConfig failed to clone config before checking it. Original config will be checked, it might trigger an input duplication warning: failed to get 'id': missing field accessing 'id''](https://discuss.elastic.co/t/warning-is-observed-huge-number-of-times-input-v2-factory-checkconfig-failed-to-clone-config-before-checking-it-original-config-will-be-checked-it-might-trigger-an-input-duplication-warning-failed-to-get-id-missing-field-accessing-id/374722)

<div class="topic-metadata">

**Author:** [@Sunanda](https://discuss.elastic.co/u/Sunanda)\
**Replies:** 1\
**Last updated:** [February 28, 2025, 9:43pm UTC](https://discuss.elastic.co/t/warning-is-observed-huge-number-of-times-input-v2-factory-checkconfig-failed-to-clone-config-before-checking-it-original-config-will-be-checked-it-might-trigger-an-input-duplication-warning-failed-to-get-id-missing-field-accessing-id/374722 "2025-02-28T21:43:59Z")

</div>

There is one small clarification needed regarding the below warning. Actually, when autodiscover is enabled and tried to deploy the service, we see the below warning repeated continuously with huge number of occurrences…

---

## [Filebeat stopped working after adding a node to the cluster](https://discuss.elastic.co/t/filebeat-stopped-working-after-adding-a-node-to-the-cluster/374785)

<div class="topic-metadata">

**Author:** [@andrejjorje](https://discuss.elastic.co/u/andrejjorje)\
**Replies:** 1\
**Last updated:** [February 20, 2025, 1:36am UTC](https://discuss.elastic.co/t/filebeat-stopped-working-after-adding-a-node-to-the-cluster/374785 "2025-02-20T01:36:49Z")

</div>

Hello everybody. I have installed one node with ELK 8.17.2 on Ubuntu 24.04.Elasticsearch, Kibana and Filebeat.All working. I decided then to install another elasticsearch node for redundancy.Only elasticsearch. I was a…

---

## [Filebeat and metricbeat logs ending up in /var/log/messages](https://discuss.elastic.co/t/filebeat-and-metricbeat-logs-ending-up-in-var-log-messages/374134)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 1\
**Last updated:** [February 10, 2025, 6:53pm UTC](https://discuss.elastic.co/t/filebeat-and-metricbeat-logs-ending-up-in-var-log-messages/374134 "2025-02-10T18:53:39Z")

</div>

I am seeing that metricbeat/filebeat running on Linux are logging their messages to /var/log/messages instead of file. Here is my configuration: logging.level: info logging.to\_syslog: false logging.to\_files: true loggi…

---

## [Lackluster azure.resource.type data in billing metricset](https://discuss.elastic.co/t/lackluster-azure-resource-type-data-in-billing-metricset/373886)

<div class="topic-metadata">

**Author:** [@janb](https://discuss.elastic.co/u/janb)\
**Replies:** 0\
**Last updated:** [January 30, 2025, 11:03am UTC](https://discuss.elastic.co/t/lackluster-azure-resource-type-data-in-billing-metricset/373886 "2025-01-30T11:03:19Z")

</div>

Hi, we've introduced azure billing metricset into our metricbeat (8.15.2 version) configuration, and I've noticed that azure.resource.type is a little lackluster. Microsoft.Compute microsoft.compute Microsoft.Storage…

---

## [\[Metricbeat\]\[Elasticsearch module\] "basepath" configuration field is not working properly. Bug ?](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-basepath-configuration-field-is-not-working-properly-bug/372776)

<div class="topic-metadata">

**Author:** [@jeremy\_f](https://discuss.elastic.co/u/jeremy_f)\
**Replies:** 0\
**Last updated:** [January 3, 2025, 10:46pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-basepath-configuration-field-is-not-working-properly-bug/372776 "2025-01-03T22:46:01Z")

</div>

Hello, Scenario : I try to retrieve metrics from an Elasticsearch service through an Nginx reverse proxy. Elasticsearch endpoint is https :// FQDN:443 /elasticsearch. Metricbeat version is 8.15.2 This is the reason wh…

---

## [Heavy SQL execution timeout](https://discuss.elastic.co/t/heavy-sql-execution-timeout/372480)

<div class="topic-metadata">

**Author:** [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Replies:** 0\
**Last updated:** [December 27, 2024, 2:57pm UTC](https://discuss.elastic.co/t/heavy-sql-execution-timeout/372480 "2024-12-27T14:57:28Z")

</div>

Hi everyone, I’m having trouble configuring the timeout in the SQL module of Metricbeat. My SQL queries are still taking longer than the default timeout period and i didnt find a way to solve it. Has anyone else exper…

---

## [Winlogbeat is not sending logs to new version of Apache Kafka with KRaft](https://discuss.elastic.co/t/winlogbeat-is-not-sending-logs-to-new-version-of-apache-kafka-with-kraft/368812)

<div class="topic-metadata">

**Author:** [@IamYipi](https://discuss.elastic.co/u/IamYipi)\
**Replies:** 2\
**Last updated:** [October 21, 2024, 7:43am UTC](https://discuss.elastic.co/t/winlogbeat-is-not-sending-logs-to-new-version-of-apache-kafka-with-kraft/368812 "2024-10-21T07:43:35Z")

</div>

Hi everyone, I'm having a problem with Apache Kafka, related with the configuration of the output format. The arquitecture I created is with docker containers, where Apache Kafka is one and the windows host (virtualize…

---

## [Is it not possible to use / in the client\_id for the Kafka output plugin in Filebeat?](https://discuss.elastic.co/t/is-it-not-possible-to-use-in-the-client-id-for-the-kafka-output-plugin-in-filebeat/368587)

<div class="topic-metadata">

**Author:** [@henry.ahn](https://discuss.elastic.co/u/henry.ahn)\
**Replies:** 1\
**Last updated:** [October 11, 2024, 6:13pm UTC](https://discuss.elastic.co/t/is-it-not-possible-to-use-in-the-client-id-for-the-kafka-output-plugin-in-filebeat/368587 "2024-10-11T18:13:00Z")

</div>

Hi, All! I configured the client.id in Filebeat for Kafka with a / character. However, I encountered the following error: ERROR \[kafka\] kafka/config.go:287 Invalid kafka configuration: kafka: invalid configuration (Cli…

---

## [Beats left old index templates after upgrade](https://discuss.elastic.co/t/beats-left-old-index-templates-after-upgrade/368626)

<div class="topic-metadata">

**Author:** [@SteelDi](https://discuss.elastic.co/u/SteelDi)\
**Replies:** 0\
**Last updated:** [October 10, 2024, 12:18pm UTC](https://discuss.elastic.co/t/beats-left-old-index-templates-after-upgrade/368626 "2024-10-10T12:18:24Z")

</div>

We are using beats with elastic in k8s, and every time after beats upgrade old index templates still left. And problem that the ILM still seen this templates and did rollover on all old indexes. And now i have a lot of t…

---

## [Filestream monitorization issue](https://discuss.elastic.co/t/filestream-monitorization-issue/366406)

<div class="topic-metadata">

**Author:** [@Samuel\_Ruiz\_Garcia](https://discuss.elastic.co/u/Samuel_Ruiz_Garcia)\
**Replies:** 1\
**Last updated:** [September 11, 2024, 12:33pm UTC](https://discuss.elastic.co/t/filestream-monitorization-issue/366406 "2024-09-11T12:33:43Z")

</div>

We have a monitoring on some logs of an application. This monitoring was already done since version 7.17.9 with filestream (because of the log deprecation issue). A few weeks ago we upgraded the whole cluster to version …

---

## [Provided expression do not match field value filebeat 8.15.0 fortinet module](https://discuss.elastic.co/t/provided-expression-do-not-match-field-value-filebeat-8-15-0-fortinet-module/365612)

<div class="topic-metadata">

**Author:** [@fracorbas](https://discuss.elastic.co/u/fracorbas)\
**Replies:** 1\
**Last updated:** [August 29, 2024, 2:21pm UTC](https://discuss.elastic.co/t/provided-expression-do-not-match-field-value-filebeat-8-15-0-fortinet-module/365612 "2024-08-29T14:21:56Z")

</div>

I'm trying to analyze Fortinet FortiGate logs with the filebeat module "Fortinet". The only informations and solutions I found about this was Topics from 2019-2020 with a filebeat version 7.5 which was way too long ago. …

---

## [Endpoint logs spammed with: ProcFile.cpp:701 and ProcFile.cpp:175 related messages](https://discuss.elastic.co/t/endpoint-logs-spammed-with-procfile-cpp-701-and-procfile-cpp-175-related-messages/365125)

<div class="topic-metadata">

**Author:** [@buzzdeee](https://discuss.elastic.co/u/buzzdeee)\
**Replies:** 0\
**Last updated:** [August 19, 2024, 9:59am UTC](https://discuss.elastic.co/t/endpoint-logs-spammed-with-procfile-cpp-701-and-procfile-cpp-175-related-messages/365125 "2024-08-19T09:59:04Z")

</div>

Looking at the "\[Elastic Agent\] Agent Info" dashboard, I noticed quite a number of hosts reporting a lot of errors in the "\[Elastic Agent\] Agents with Errors" looking closer, seems /opt/Elastic/Endpoint/state/log/endpoi…

---

## [No data has been received from this module yet message (Module Suricata)](https://discuss.elastic.co/t/no-data-has-been-received-from-this-module-yet-message-module-suricata/359799)

<div class="topic-metadata">

**Author:** [@leaft2312](https://discuss.elastic.co/u/leaft2312)\
**Replies:** 1\
**Last updated:** [May 20, 2024, 2:37pm UTC](https://discuss.elastic.co/t/no-data-has-been-received-from-this-module-yet-message-module-suricata/359799 "2024-05-20T14:37:36Z")

</div>

I configured filebeat.yml, /modules.d/suricata.yml but i don't see data from suricata module filebeat.yml: #=========================== Filebeat inputs ============================= filebeat.inputs: # Each - is an…

---

## [No data from my Metricbeat Docker Module](https://discuss.elastic.co/t/no-data-from-my-metricbeat-docker-module/358157)

<div class="topic-metadata">

**Author:** [@morningjacket](https://discuss.elastic.co/u/morningjacket)\
**Replies:** 0\
**Last updated:** [April 24, 2024, 8:09pm UTC](https://discuss.elastic.co/t/no-data-from-my-metricbeat-docker-module/358157 "2024-04-24T20:09:18Z")

</div>

Hello all, I am trying to get my Metricbeat docker module to connect to my ES/Kibana. I believe the issue is isolated to the docker module as I am able to see system module metrics. I have enabled the module root@hos…

---

## [Default value for number of workers missing in Logstash output documentation](https://discuss.elastic.co/t/default-value-for-number-of-workers-missing-in-logstash-output-documentation/357608)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 0\
**Last updated:** [April 17, 2024, 11:43am UTC](https://discuss.elastic.co/t/default-value-for-number-of-workers-missing-in-logstash-output-documentation/357608 "2024-04-17T11:43:09Z")

</div>

Do I understand correctly that the number of workers for a Logstash output is 1 by default? Let's take Filebeat as an example: The default value is documented for the Elasticsearch output: The default value is 1 . …

---

## [Can’t get HAPROXY to send stats or info data to Metricbeat](https://discuss.elastic.co/t/can-t-get-haproxy-to-send-stats-or-info-data-to-metricbeat/357019)

<div class="topic-metadata">

**Author:** [@nhdev](https://discuss.elastic.co/u/nhdev)\
**Replies:** 4\
**Last updated:** [April 9, 2024, 4:24pm UTC](https://discuss.elastic.co/t/can-t-get-haproxy-to-send-stats-or-info-data-to-metricbeat/357019 "2024-04-09T16:24:02Z")

</div>

\- module: haproxy metricsets: \["info", "stat"\] period: 10s hosts: \["tcp://\[unique\_host\]:14567"\] username : "haproxy" password : "haproxy" enabled: true global log 127.0.0.1 local0 chroot …

---

## [How to configure kafka with kraft with metricbeat 8.12](https://discuss.elastic.co/t/how-to-configure-kafka-with-kraft-with-metricbeat-8-12/356979)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 0\
**Last updated:** [April 8, 2024, 1:57pm UTC](https://discuss.elastic.co/t/how-to-configure-kafka-with-kraft-with-metricbeat-8-12/356979 "2024-04-08T13:57:43Z")

</div>

I have a cluster of three nodes for kafka with kraft with a running cluster of elasticsearch on others 7 nodes with 2 logstash and one kibana. I want to monitor the topics/partitions/replicas/consumergroups/brokers of …

---

## [Elevated Memory Utilization and Errors in Filebeat When Integrating External MISP CTI Log Source](https://discuss.elastic.co/t/elevated-memory-utilization-and-errors-in-filebeat-when-integrating-external-misp-cti-log-source/354726)

<div class="topic-metadata">

**Author:** [@sunith](https://discuss.elastic.co/u/sunith)\
**Replies:** 6\
**Last updated:** [March 8, 2024, 5:21pm UTC](https://discuss.elastic.co/t/elevated-memory-utilization-and-errors-in-filebeat-when-integrating-external-misp-cti-log-source/354726 "2024-03-08T17:21:56Z")

</div>

Summary: Our Elastic setup incorporates two MISP CTI log sources— one internal and one external—both managed within the Henkel environment. Upon integrating these MISP instances using the filebeat API method, we have ide…

---

## [Azure Billing](https://discuss.elastic.co/t/azure-billing/354010)

<div class="topic-metadata">

**Author:** [@aquintananieves2](https://discuss.elastic.co/u/aquintananieves2)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 5:54pm UTC](https://discuss.elastic.co/t/azure-billing/354010 "2024-02-23T17:54:48Z")

</div>

When using the Azure Billing integrations, it works only using a single subscription. When adding a Billing Account ID or Department ID, it stops working. Has anyone run into this issue, or does this need to be reported …

---

## [How to get list of installed software/products from windows Server?](https://discuss.elastic.co/t/how-to-get-list-of-installed-software-products-from-windows-server/353088)

<div class="topic-metadata">

**Author:** [@Padam](https://discuss.elastic.co/u/Padam)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 9:38am UTC](https://discuss.elastic.co/t/how-to-get-list-of-installed-software-products-from-windows-server/353088 "2024-02-15T09:38:51Z")

</div>

Hi All, Greetings!!! Could you please help me to get all list products/ software, version and their EOL details?

---

## [A potential bug with Filebeat script processor](https://discuss.elastic.co/t/a-potential-bug-with-filebeat-script-processor/351914)

<div class="topic-metadata">

**Author:** [@Calvin\_Li](https://discuss.elastic.co/u/Calvin_Li)\
**Replies:** 6\
**Last updated:** [February 2, 2024, 4:06am UTC](https://discuss.elastic.co/t/a-potential-bug-with-filebeat-script-processor/351914 "2024-02-02T04:06:42Z")

</div>

Hi team, thanks for your great work! I'm using filebeat 8.10.3, and seeing a potential bug with it. I'm using the script processor to do some caching & filtering of log messages. To be specific, I'm using a LRU cache to…

[Next page](https://discuss.elastic.co/tag/beats-module/29.md?match_all_tags=true&page=1&tags%5B%5D=beats-module)
