# \#filebeat

**URL:** https://discuss.elastic.co/tag/filebeat/54.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Filebeat postgresql log module produces timestamp fields that are not indexable when using ECS](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640)

<div class="topic-metadata">

**Author:** [@kriller](https://discuss.elastic.co/u/kriller)\
**Replies:** 1\
**Last updated:** [September 24, 2026, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640 "2026-09-24T15:57:40Z")

</div>

When using the ingest-pipeline that filebeat creates for postgresql logs, the resulting event contains the field postgresql.log.timestamp which conflicts with the ecs@mappings component template. The filebeat-9.5.4-post…

---

## [Filebeat performance, 430 containers](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622)

<div class="topic-metadata">

**Author:** [@zerkms](https://discuss.elastic.co/u/zerkms)\
**Replies:** 0\
**Last updated:** [September 24, 2026, 5:18am UTC](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622 "2026-09-24T05:18:13Z")

</div>

I'm migrating from quite an old ES+fluentbit configuration (logging solution for a small kubernetes cluster). And this is quite simple yet inefficient (?) config I came up with (this file is generated by ECK using the B…

---

## [Filebeat with Salesforce input and batch](https://discuss.elastic.co/t/filebeat-with-salesforce-input-and-batch/390433)

<div class="topic-metadata">

**Author:** [@stephaniearce](https://discuss.elastic.co/u/stephaniearce)\
**Replies:** 1\
**Last updated:** [September 16, 2026, 5:59pm UTC](https://discuss.elastic.co/t/filebeat-with-salesforce-input-and-batch/390433 "2026-09-16T17:59:51Z")

</div>

Can anyone explain why I'm running into this issue? I copied the exact config from the docs here: Salesforce input | Beats Salesforce input: object.batch.enabled: true fails with "map has no entry for key batch\_start\_ti…

---

## [Filebeat and Nanosecond Timestamps](https://discuss.elastic.co/t/filebeat-and-nanosecond-timestamps/389204)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [August 31, 2026, 3:55am UTC](https://discuss.elastic.co/t/filebeat-and-nanosecond-timestamps/389204 "2026-08-31T03:55:37Z")

</div>

Hi, Can I get some clarification around how filebeat handles an inbound timestamp field of nanosecond precision when it uses that field to set @timestamp? Also, can filebeat generate nanosecond timestamps?

---

## [Filebeat now processor seams to be buggy](https://discuss.elastic.co/t/filebeat-now-processor-seams-to-be-buggy/389776)

<div class="topic-metadata">

**Author:** [@Toony](https://discuss.elastic.co/u/Toony)\
**Replies:** 14\
**Last updated:** [August 20, 2026, 12:15pm UTC](https://discuss.elastic.co/t/filebeat-now-processor-seams-to-be-buggy/389776 "2026-08-20T12:15:47Z")

</div>

Hi, It seems the now processor behaves strangely If I set a now processor in filebeat at the top yaml level like this: processors: - now: field: metadata.timeline.t1 and configure Logstash like this: input {…

---

## [Int Overflow produces invalid Filebeat stats](https://discuss.elastic.co/t/int-overflow-produces-invalid-filebeat-stats/389458)

<div class="topic-metadata">

**Author:** [@fleaz](https://discuss.elastic.co/u/fleaz)\
**Replies:** 3\
**Last updated:** [August 17, 2026, 1:09pm UTC](https://discuss.elastic.co/t/int-overflow-produces-invalid-filebeat-stats/389458 "2026-08-17T13:09:48Z")

</div>

Hey, we recently discovered some strange metrics coming from our Filebeats (8.19.19 running in k8s) because we have an alert to check for queue usage and alert if the queue gets to full. Sometimes the value for "Queue …

---

## [High Filebeat Disk I/O After Reboot With Ubuntu 24.04](https://discuss.elastic.co/t/high-filebeat-disk-i-o-after-reboot-with-ubuntu-24-04/388881)

<div class="topic-metadata">

**Author:** [@harrelst](https://discuss.elastic.co/u/harrelst)\
**Replies:** 0\
**Last updated:** [July 30, 2026, 3:32am UTC](https://discuss.elastic.co/t/high-filebeat-disk-i-o-after-reboot-with-ubuntu-24-04/388881 "2026-07-30T03:32:40Z")

</div>

We use a Filebeat DaemonSet to collect container logs from nodes in our Kubernetes cluster. I recently added some Ubuntu 24.04 nodes to the cluster, and when Filebeat restarts after a reboot generates around 150 MB/s of …

---

## [CISA KEV integration upgrade to 1.10](https://discuss.elastic.co/t/cisa-kev-integration-upgrade-to-1-10/388850)

<div class="topic-metadata">

**Author:** [@rklee](https://discuss.elastic.co/u/rklee)\
**Replies:** 0\
**Last updated:** [July 28, 2026, 8:00pm UTC](https://discuss.elastic.co/t/cisa-kev-integration-upgrade-to-1-10/388850 "2026-07-28T20:00:01Z")

</div>

So I was on a CISA KEV integration before version 1.7. I upgraded it to 1.10 and vulnerability reports are not coming in anymore. The integration says to re-enter configuration details and re-enable the package. However …

---

## [Filebeat to Elastic Agent(otel collector) migration - 9.4.2](https://discuss.elastic.co/t/filebeat-to-elastic-agent-otel-collector-migration-9-4-2/387302)

<div class="topic-metadata">

**Author:** [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Replies:** 7\
**Last updated:** [July 7, 2026, 1:15pm UTC](https://discuss.elastic.co/t/filebeat-to-elastic-agent-otel-collector-migration-9-4-2/387302 "2026-07-07T13:15:03Z")

</div>

I am currently migrating our existing Filebeat-based log collection architecture to the Elastic Agent as OpenTelemetry Collector approach and would appreciate some clarification. I am following the "Elastic Agent as O…

---

## [Filebeat memory usage increases overtime until OOM](https://discuss.elastic.co/t/filebeat-memory-usage-increases-overtime-until-oom/387098)

<div class="topic-metadata">

**Author:** [@ryd-devops](https://discuss.elastic.co/u/ryd-devops)\
**Replies:** 3\
**Last updated:** [June 23, 2026, 6:28pm UTC](https://discuss.elastic.co/t/filebeat-memory-usage-increases-overtime-until-oom/387098 "2026-06-23T18:28:25Z")

</div>

We run filebeat (9.4.2) in our kubernetes clusters, mostly using the autodiscoverfeature and annotations. We have a lot of cronjobs and sidecar containers as well.. from a logging perspective filebeat is working great b…

---

## [Crash in filebeat 9.3.0 on error "concurrent map iteration and map write"](https://discuss.elastic.co/t/crash-in-filebeat-9-3-0-on-error-concurrent-map-iteration-and-map-write/386208)

<div class="topic-metadata">

**Author:** [@grzegorzkw](https://discuss.elastic.co/u/grzegorzkw)\
**Replies:** 1\
**Last updated:** [June 15, 2026, 12:15pm UTC](https://discuss.elastic.co/t/crash-in-filebeat-9-3-0-on-error-concurrent-map-iteration-and-map-write/386208 "2026-06-15T12:15:01Z")

</div>

Hello, One of our filebeat deployments is bumping into the below error which crashes the service overall: fatal error: concurrent map iteration and map write goroutine 1 \[running\]: internal/runtime/maps.fatal({0x69991…

---

## [Filebeat 9.3.1 slow to shutdown, takes \> 50s, using type: filestream,](https://discuss.elastic.co/t/filebeat-9-3-1-slow-to-shutdown-takes-50s-using-type-filestream/386789)

<div class="topic-metadata">

**Author:** [@Alex\_Rune\_Berg](https://discuss.elastic.co/u/Alex_Rune_Berg)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 9:01am UTC](https://discuss.elastic.co/t/filebeat-9-3-1-slow-to-shutdown-takes-50s-using-type-filestream/386789 "2026-06-10T09:01:30Z")

</div>

Our filebeat does not stop quickly after changing it to use the 'type: filestream', we used 'type: log' before and it stopped immediately. We stop filebeat by sending it a -TERM, using pkill -TERM filebeat It normally…

---

## [Filebeat - Single-line JSON log ingestion: expected behavior and required configuration](https://discuss.elastic.co/t/filebeat-single-line-json-log-ingestion-expected-behavior-and-required-configuration/386753)

<div class="topic-metadata">

**Author:** [@aymanmazroui](https://discuss.elastic.co/u/aymanmazroui)\
**Replies:** 2\
**Last updated:** [June 8, 2026, 1:59pm UTC](https://discuss.elastic.co/t/filebeat-single-line-json-log-ingestion-expected-behavior-and-required-configuration/386753 "2026-06-08T13:59:58Z")

</div>

Hi, I have a specific use case and I need to know if Filebeat can handle it. My log files consist of a single very long line of JSON (no newline characters), which can be up to 27 MB in size. The entire file content i…

---

## [Filebeat-logstash question](https://discuss.elastic.co/t/filebeat-logstash-question/386311)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 6\
**Last updated:** [May 13, 2026, 11:48pm UTC](https://discuss.elastic.co/t/filebeat-logstash-question/386311 "2026-05-13T23:48:05Z")

</div>

filebeat.inputs: - type: filestream id: tad-run-logs enabled: true paths: - /run/\*/\*.tl - /run/\*/extra\_info exclude\_files: - '/run/cleanup\_rack/' file\_identity.native: ~ prospe…

---

## [Filebeat filestream offset mismatch when using include\_message with multiline](https://discuss.elastic.co/t/filebeat-filestream-offset-mismatch-when-using-include-message-with-multiline/386057)

<div class="topic-metadata">

**Author:** [@sem1308](https://discuss.elastic.co/u/sem1308)\
**Replies:** 0\
**Last updated:** [April 27, 2026, 7:26pm UTC](https://discuss.elastic.co/t/filebeat-filestream-offset-mismatch-when-using-include-message-with-multiline/386057 "2026-04-27T19:26:47Z")

</div>

Version 8.18.4 Operating System macOS (build & test) Steps to Reproduce 1. Configuration filebeat.inputs: - type: filestream id: filebeat-test paths: - /path/to/log/\* parsers: - include\_message.patterns:…

---

## [Elastic-Agent -\> Logstash high EPS missing events](https://discuss.elastic.co/t/elastic-agent-logstash-high-eps-missing-events/385733)

<div class="topic-metadata">

**Author:** [@mamueh](https://discuss.elastic.co/u/mamueh)\
**Replies:** 0\
**Last updated:** [April 1, 2026, 2:05pm UTC](https://discuss.elastic.co/t/elastic-agent-logstash-high-eps-missing-events/385733 "2026-04-01T14:05:40Z")

</div>

Hi Everyone We have a rather large setup in which we’ve replaced rsyslog with Elastic Agents as log collectors. We’re running 8.19.8. Currently we have around 1200 devices forwarding mostly syslog to a load balancer th…

---

## [Duplicate messages observed in Kafka when using Filebeat with disk queue](https://discuss.elastic.co/t/duplicate-messages-observed-in-kafka-when-using-filebeat-with-disk-queue/385693)

<div class="topic-metadata">

**Author:** [@Thirupathi](https://discuss.elastic.co/u/Thirupathi)\
**Replies:** 1\
**Last updated:** [March 30, 2026, 1:38pm UTC](https://discuss.elastic.co/t/duplicate-messages-observed-in-kafka-when-using-filebeat-with-disk-queue/385693 "2026-03-30T13:38:46Z")

</div>

We are observing duplicate messages being published to Kafka from Filebeat, even when the Kafka broker is up and stable. The issue occurs while using the disk queue (queue.disk ) configuration Kafka Output Configuration…

---

## [How to ensure the integrity of filebeat output data during network fluctuations？](https://discuss.elastic.co/t/how-to-ensure-the-integrity-of-filebeat-output-data-during-network-fluctuations/385625)

<div class="topic-metadata">

**Author:** [@h123123123](https://discuss.elastic.co/u/h123123123)\
**Replies:** 0\
**Last updated:** [March 26, 2026, 2:03am UTC](https://discuss.elastic.co/t/how-to-ensure-the-integrity-of-filebeat-output-data-during-network-fluctuations/385625 "2026-03-26T02:03:20Z")

</div>

The version of Filebeat I am using is 9.3.1. I set max\_retries=-1, expecting that during network fluctuations, all data can be sent to Kafka. The actual test result: data is still lost during network fluctuations. I trie…

---

## [Syslog parser fails on double backslashes in structured data](https://discuss.elastic.co/t/syslog-parser-fails-on-double-backslashes-in-structured-data/385386)

<div class="topic-metadata">

**Author:** [@briandoesdev](https://discuss.elastic.co/u/briandoesdev)\
**Replies:** 2\
**Last updated:** [March 10, 2026, 1:35pm UTC](https://discuss.elastic.co/t/syslog-parser-fails-on-double-backslashes-in-structured-data/385386 "2026-03-10T13:35:19Z")

</div>

Hello everyone, My org is using the Custom UDP Logs integration to ingest RFC 5424 syslog messages from several network appliances. One of the appliances includes structured data with a parameter value containing a doub…

---

## [How to limit bandwidth usage of Windows Filebeat](https://discuss.elastic.co/t/how-to-limit-bandwidth-usage-of-windows-filebeat/385357)

<div class="topic-metadata">

**Author:** [@waitspring](https://discuss.elastic.co/u/waitspring)\
**Replies:** 1\
**Last updated:** [March 6, 2026, 6:18am UTC](https://discuss.elastic.co/t/how-to-limit-bandwidth-usage-of-windows-filebeat/385357 "2026-03-06T06:18:36Z")

</div>

Hello, every big brothers: I installed Filebeat in Windows Server 2012, and make Filebeat send log data to Kafka. I want to limit Filebeat’s bandwidth usage in 50Kbit, because my Windows Server 2012 only has 2Mbit band…

---

## [container input: CRI partial line reassembly ignores max\_bytes, causing OOM](https://discuss.elastic.co/t/container-input-cri-partial-line-reassembly-ignores-max-bytes-causing-oom/385340)

<div class="topic-metadata">

**Author:** [@raychinov](https://discuss.elastic.co/u/raychinov)\
**Replies:** 1\
**Last updated:** [March 5, 2026, 2:15pm UTC](https://discuss.elastic.co/t/container-input-cri-partial-line-reassembly-ignores-max-bytes-causing-oom/385340 "2026-03-05T14:15:36Z")

</div>

Filebeat version 8.19.12 Operating system and version Linux (Kubernetes with containerd runtime) Description of the problem including expected versus actual behavior When a container log contains many consecutive CRI p…

---

## [Logstash/Filebeat lag issue - Logs delayed by hours](https://discuss.elastic.co/t/logstash-filebeat-lag-issue-logs-delayed-by-hours/385101)

<div class="topic-metadata">

**Author:** [@Cesar\_Mejia](https://discuss.elastic.co/u/Cesar_Mejia)\
**Replies:** 45\
**Last updated:** [March 5, 2026, 1:02pm UTC](https://discuss.elastic.co/t/logstash-filebeat-lag-issue-logs-delayed-by-hours/385101 "2026-03-05T13:02:46Z")

</div>

Hello Elastic Community, I am experiencing a significant lag in log ingestion where logs are arriving with a variable delay (sometimes hours late) despite having a high-performance environment. I would appreciate your a…

---

## [Filebeat - duplicated logs when using journald Input with systemd units](https://discuss.elastic.co/t/filebeat-duplicated-logs-when-using-journald-input-with-systemd-units/385347)

<div class="topic-metadata">

**Author:** [@maxp1](https://discuss.elastic.co/u/maxp1)\
**Replies:** 1\
**Last updated:** [March 5, 2026, 12:15am UTC](https://discuss.elastic.co/t/filebeat-duplicated-logs-when-using-journald-input-with-systemd-units/385347 "2026-03-05T00:15:46Z")

</div>

Hello, I've encountered an issue while using the journald input in Filebeat, specifically when specifying individual systemd units. Instead of separating logs based on the systemd unit, Filebeat seems to be processing th…

---

## [Filebeat Event Publishing Delay to Kafka](https://discuss.elastic.co/t/filebeat-event-publishing-delay-to-kafka/385064)

<div class="topic-metadata">

**Author:** [@Thirupathi](https://discuss.elastic.co/u/Thirupathi)\
**Replies:** 9\
**Last updated:** [February 24, 2026, 8:52am UTC](https://discuss.elastic.co/t/filebeat-event-publishing-delay-to-kafka/385064 "2026-02-24T08:52:30Z")

</div>

From the logs, we can see that the logger timestamp indicates a noticeable time gap between event processing and event publishing to Kafka. Due to this delay, events are not being pushed to Kafka in real-time as expected…

---

## [Read latest logs from a file](https://discuss.elastic.co/t/read-latest-logs-from-a-file/384957)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [February 8, 2026, 10:06am UTC](https://discuss.elastic.co/t/read-latest-logs-from-a-file/384957 "2026-02-08T10:06:09Z")

</div>

Hello Folks, I have one log file and it is containing all logs since November 2025 to till now. For doing the parsing of logs i’ve copy-paste sample logs to test.log file and it worked. My question is How to read last…

---

## [Creating an alarm that outputs the group name](https://discuss.elastic.co/t/creating-an-alarm-that-outputs-the-group-name/384911)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 2\
**Last updated:** [February 6, 2026, 9:31am UTC](https://discuss.elastic.co/t/creating-an-alarm-that-outputs-the-group-name/384911 "2026-02-06T09:31:24Z")

</div>

I am trying to build an alert that emits data via a web hook. The alert has grouping, so multiple alerts can fire an any one time. What I’ve not managed to do is get the group name to be included in the data sent throu…

---

## [SentinelOne Integration with ELK](https://discuss.elastic.co/t/sentinelone-integration-with-elk/384924)

<div class="topic-metadata">

**Author:** [@Jayesh\_Auti](https://discuss.elastic.co/u/Jayesh_Auti)\
**Replies:** 4\
**Last updated:** [February 5, 2026, 1:22pm UTC](https://discuss.elastic.co/t/sentinelone-integration-with-elk/384924 "2026-02-05T13:22:13Z")

</div>

Hi Guys, I am integrating SentinelOne with ELK, after adding console URL and API key it showing me to add elastic agent. Elastic agent is required for these type of integrations? Can anyone help me with this? Than…

---

## [Filebeat Unable to Handle Single Large Event (~5GB)](https://discuss.elastic.co/t/filebeat-unable-to-handle-single-large-event-5gb/384782)

<div class="topic-metadata">

**Author:** [@Thirupathi](https://discuss.elastic.co/u/Thirupathi)\
**Replies:** 1\
**Last updated:** [January 29, 2026, 1:57pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-handle-single-large-event-5gb/384782 "2026-01-29T13:57:18Z")

</div>

We are facing an issue where Filebeat is not able to process or hold a single large event of approximately 5 GB . Due to this limitation, the event is not being shipped successfully to Elasticsearch. This appears to be …

---

## [Use filebeat processor to concatenate string](https://discuss.elastic.co/t/use-filebeat-processor-to-concatenate-string/384725)

<div class="topic-metadata">

**Author:** [@mistrhanky1](https://discuss.elastic.co/u/mistrhanky1)\
**Replies:** 2\
**Last updated:** [January 26, 2026, 3:15pm UTC](https://discuss.elastic.co/t/use-filebeat-processor-to-concatenate-string/384725 "2026-01-26T15:15:49Z")

</div>

I have a situation where a customer has a custom syslog file for the Citrix ADC Netscaler. I would like to use the fleet integration for this but it doesn’t support the header format they have. I would like to modify tha…

---

## [When using s3-compatible service as inputs, path\_style is un-useful](https://discuss.elastic.co/t/when-using-s3-compatible-service-as-inputs-path-style-is-un-useful/384709)

<div class="topic-metadata">

**Author:** [@luxin88](https://discuss.elastic.co/u/luxin88)\
**Replies:** 0\
**Last updated:** [January 23, 2026, 9:33am UTC](https://discuss.elastic.co/t/when-using-s3-compatible-service-as-inputs-path-style-is-un-useful/384709 "2026-01-23T09:33:30Z")

</div>

filebeat: inputs: - type: aws-s3 endpoint: "http://obs.cn-north-4.myhuaweicloud.com" access\_key\_id: "###" secret\_access\_key: "###" non\_aws\_bucket\_name: log-parse path\_style: false …

[Next page](https://discuss.elastic.co/tag/filebeat/54.md?match_all_tags=true&page=1&tags%5B%5D=filebeat)
