# \#functionbeat

**URL:** https://discuss.elastic.co/tag/functionbeat/60.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Please clarify maintenance status for Functionbeat/beats code libraries](https://discuss.elastic.co/t/please-clarify-maintenance-status-for-functionbeat-beats-code-libraries/365416)

<div class="topic-metadata">

**Author:** [@Seagulls](https://discuss.elastic.co/u/Seagulls)\
**Replies:** 1\
**Last updated:** [September 2, 2024, 3:30am UTC](https://discuss.elastic.co/t/please-clarify-maintenance-status-for-functionbeat-beats-code-libraries/365416 "2024-09-02T03:30:32Z")

</div>

I am looking at the beats code libraries here: When I use the link to the Functionbeat documentation, a banner states: Functionbeat reached End of Support on October 18, 2023. You must consider moving your deployment…

---

## [AWS lambda end of support for Go1.x runtime](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-go1-x-runtime/349047)

<div class="topic-metadata">

**Author:** [@rsingh1](https://discuss.elastic.co/u/rsingh1)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 11:37am UTC](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-go1-x-runtime/349047 "2023-12-12T11:37:21Z")

</div>

Hi, My use case is to continue using the functionbeat itself, but since the go1.x runtime will not be supported in AWS lambda, can I create a new build with the gov2 version? On that, Will it be too much of effort doi…

---

## [AWS Lambda end of support for the Go 1.x runtime](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-the-go-1-x-runtime/344983)

<div class="topic-metadata">

**Author:** [@ssdrosos](https://discuss.elastic.co/u/ssdrosos)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 1:28pm UTC](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-the-go-1-x-runtime/344983 "2023-10-13T13:28:53Z")

</div>

Hello, AWS has announced that they will stop the support of the Go 1.x runtime environment. From what I can see in the latest master Dockerfile, the go runtime is still v1: https://github.com/elastic/beats/blob/main/x-…

---

## [Execbeats unable to run powershell](https://discuss.elastic.co/t/execbeats-unable-to-run-powershell/344160)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [September 30, 2023, 12:20pm UTC](https://discuss.elastic.co/t/execbeats-unable-to-run-powershell/344160 "2023-09-30T12:20:50Z")

</div>

I'm a bit stuck trying to get execbeat run a powershell and send the outcome to my elastic cluster. I'm afraid that the problem is the space that exist in windows paths (linux users must be laughing at me now) So my con…

---

## [FunctionBeat not able to get CloudWatch Logs](https://discuss.elastic.co/t/functionbeat-not-able-to-get-cloudwatch-logs/339673)

<div class="topic-metadata">

**Author:** [@Vedant14](https://discuss.elastic.co/u/Vedant14)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 8:50am UTC](https://discuss.elastic.co/t/functionbeat-not-able-to-get-cloudwatch-logs/339673 "2023-08-01T08:50:57Z")

</div>

We are trying to fetch the CloudWatch logs in Elastic using FunctionBeat. The function is getting deployed successfully but not able to give the Cloudwatch data in Elastic. We did the configurations for the FunctionBeat …

---

## [Prevent Functionbeat from deleting log groups](https://discuss.elastic.co/t/prevent-functionbeat-from-deleting-log-groups/338538)

<div class="topic-metadata">

**Author:** [@shlant](https://discuss.elastic.co/u/shlant)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 10:49am UTC](https://discuss.elastic.co/t/prevent-functionbeat-from-deleting-log-groups/338538 "2023-07-17T10:49:26Z")

</div>

So I am wanting to stream logs from a number of existing cloudwatch log groups to my ELK stack. I seem to have the setup basically ready but I noticed during the debugging of the setup process that when I deleted the Clo…

---

## [Elastic forwarder cloudwatch log group wildcard id not working](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987)

<div class="topic-metadata">

**Author:** [@dchocoboo](https://discuss.elastic.co/u/dchocoboo)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:35am UTC](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987 "2023-04-14T09:35:01Z")

</div>

i'm trying to simplify my config.yaml based on this tutorial currently if i put this in my config - type: "cloudwatch-logs" id: "arn:aws:logs:ap-southeast-1:xxxxxxxxxx:log-group:\*:\*" outputs: - type: "el…

---

## [Elastic Forwarder not decoding json](https://discuss.elastic.co/t/elastic-forwarder-not-decoding-json/319330)

<div class="topic-metadata">

**Author:** [@eyear](https://discuss.elastic.co/u/eyear)\
**Replies:** 4\
**Last updated:** [November 29, 2022, 2:32am UTC](https://discuss.elastic.co/t/elastic-forwarder-not-decoding-json/319330 "2022-11-29T02:32:03Z")

</div>

I'm working on setting up the Elastic Forwarder. The documentation states that it automatically discovers json content - but it's not splitting all of the json content out into fields like it does when using the decode\_…

---

## [Functionbeat fails to update with a new cloudwatch log group Could not execute the lambda function](https://discuss.elastic.co/t/functionbeat-fails-to-update-with-a-new-cloudwatch-log-group-could-not-execute-the-lambda-function/315020)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 7:07am UTC](https://discuss.elastic.co/t/functionbeat-fails-to-update-with-a-new-cloudwatch-log-group-could-not-execute-the-lambda-function/315020 "2022-10-14T07:07:16Z")

</div>

We had functionbeat running and i had to remove and recreate it, however im getting the following errors: {"log.level":"info","@timestamp":"2022-09-23T13:55:44.066+0100","log.logger":"aws","log.origin":{"file.name":"aws…

---

## [Error while running Functinbeat](https://discuss.elastic.co/t/error-while-running-functinbeat/314642)

<div class="topic-metadata">

**Author:** [@Shubham\_Shah](https://discuss.elastic.co/u/Shubham_Shah)\
**Replies:** 0\
**Last updated:** [September 18, 2022, 12:02pm UTC](https://discuss.elastic.co/t/error-while-running-functinbeat/314642 "2022-09-18T12:02:27Z")

</div>

Hi Team, While running functionbeat for my testing instance, I got following error as Creation Failed for cloudformation. Error - "Specified ReservedConcurrentExecutions for function decreases account's UnreservedConc…

---

## [Functionbeat unable to extract microsecond @timestamp using decode\_json\_fields](https://discuss.elastic.co/t/functionbeat-unable-to-extract-microsecond-timestamp-using-decode-json-fields/314494)

<div class="topic-metadata">

**Author:** [@adrian-skybaker](https://discuss.elastic.co/u/adrian-skybaker)\
**Replies:** 0\
**Last updated:** [September 15, 2022, 9:55am UTC](https://discuss.elastic.co/t/functionbeat-unable-to-extract-microsecond-timestamp-using-decode-json-fields/314494 "2022-09-15T09:55:15Z")

</div>

I'm having issues extracting a @timestamp field from a nested JSON string (in standard ISO format), It works if the nested timestamp has millisecond precision. It doesn't if it has microsecond or nanosecond precision. T…

---

## [ResourceStatus: CREATE\_FAILED, ResourceStatusReason: Resource handler returned message: \\"The specified log group does not exist](https://discuss.elastic.co/t/resourcestatus-create-failed-resourcestatusreason-resource-handler-returned-message-the-specified-log-group-does-not-exist/313785)

<div class="topic-metadata">

**Author:** [@ayushi.sharma91](https://discuss.elastic.co/u/ayushi.sharma91)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 10:19am UTC](https://discuss.elastic.co/t/resourcestatus-create-failed-resourcestatusreason-resource-handler-returned-message-the-specified-log-group-does-not-exist/313785 "2022-09-13T10:19:25Z")

</div>

I am trying to install functionbeat 8.4 on an AWS (tried it on both amazon linux and Ubuntu). Elasticsearch is self hosted. Followed the installation guide(Functionbeat quick start: installation and configuration | Funct…

---

## [Function beat erroring out with license error when shipping log](https://discuss.elastic.co/t/function-beat-erroring-out-with-license-error-when-shipping-log/313959)

<div class="topic-metadata">

**Author:** [@IbrahimHectare](https://discuss.elastic.co/u/IbrahimHectare)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 8:04am UTC](https://discuss.elastic.co/t/function-beat-erroring-out-with-license-error-when-shipping-log/313959 "2022-09-08T08:04:20Z")

</div>

I have set up function beat on AWS, to ship my cloudwatch logs. When the functionbeat is invoked to send the logs, it errors out due to an enterprise license being returned. licenser/elastic\_fetcher.go:136 Invalid resp…

---

## [The final policy size is bigger than the limit](https://discuss.elastic.co/t/the-final-policy-size-is-bigger-than-the-limit/312720)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 3:17pm UTC](https://discuss.elastic.co/t/the-final-policy-size-is-bigger-than-the-limit/312720 "2022-08-23T15:17:49Z")

</div>

I use functionbeat to ship aws lambda function logs to elasticsearch. I added a new log group today and when i attempt to update functionbeat i get the following error: The final policy size (20576) is bigger than the l…

---

## [ELK-functionbeat-not-able-to-push-data](https://discuss.elastic.co/t/elk-functionbeat-not-able-to-push-data/311662)

<div class="topic-metadata">

**Author:** [@vijay23vikram](https://discuss.elastic.co/u/vijay23vikram)\
**Replies:** 0\
**Last updated:** [August 8, 2022, 5:17pm UTC](https://discuss.elastic.co/t/elk-functionbeat-not-able-to-push-data/311662 "2022-08-08T17:17:46Z")

</div>

Hello Team, We are facing the below error in AWS function beat lambda. Cannot index event publisher.Event{Content:beat.Event More error details as below: Error: 2022-07-22T15:15:01.087Z WARN \[elasticsearch\] elastics…

---

## [How to integrate AWS Lambda with plugin Elastic](https://discuss.elastic.co/t/how-to-integrate-aws-lambda-with-plugin-elastic/306506)

<div class="topic-metadata">

**Author:** [@Renato\_Souza](https://discuss.elastic.co/u/Renato_Souza)\
**Replies:** 33\
**Last updated:** [July 7, 2022, 11:57am UTC](https://discuss.elastic.co/t/how-to-integrate-aws-lambda-with-plugin-elastic/306506 "2022-07-07T11:57:37Z")

</div>

I am using functions beat to get logs from aws lambda (cloudwatch). But, i know exists an integration ready for AWS Lambda at Browse all integrations in cloud Elastic. I don't find documentation how to use this integrati…

---

## [Optionnal triggers in functionbeat](https://discuss.elastic.co/t/optionnal-triggers-in-functionbeat/308425)

<div class="topic-metadata">

**Author:** [@Lucas\_Zientek](https://discuss.elastic.co/u/Lucas_Zientek)\
**Replies:** 0\
**Last updated:** [June 29, 2022, 7:14am UTC](https://discuss.elastic.co/t/optionnal-triggers-in-functionbeat/308425 "2022-06-29T07:14:29Z")

</div>

Hello everyone, I have an issue on my functionbeat configuration, I want to have no triggers declared in my functionbeat.yml file. I am deploying the functionbeat lambda on aws using cloudformation that I edited myself…

---

## [How to retrieve data aws Lambda](https://discuss.elastic.co/t/how-to-retrieve-data-aws-lambda/307781)

<div class="topic-metadata">

**Author:** [@Renato\_Souza](https://discuss.elastic.co/u/Renato_Souza)\
**Replies:** 0\
**Last updated:** [June 21, 2022, 4:23pm UTC](https://discuss.elastic.co/t/how-to-retrieve-data-aws-lambda/307781 "2022-06-21T16:23:37Z")

</div>

How to retrieve data from AWS Lambda. I'm using functionbeat, but even with SAR I only retrieve CloudWatch logs as well. I would like support to know how to use these elastic integrations with AWS and I was able to dire…

---

## [Functionbeat unable to export cloudwatch logs to elastic](https://discuss.elastic.co/t/functionbeat-unable-to-export-cloudwatch-logs-to-elastic/305927)

<div class="topic-metadata">

**Author:** [@rishabhtryroll](https://discuss.elastic.co/u/rishabhtryroll)\
**Replies:** 2\
**Last updated:** [May 31, 2022, 7:16am UTC](https://discuss.elastic.co/t/functionbeat-unable-to-export-cloudwatch-logs-to-elastic/305927 "2022-05-31T07:16:51Z")

</div>

I am using function beat to export cloud watch logs to elastic but got no data in the indices. Followed that doc https://www.elastic.co/guide/en/beats/functionbeat/current/functionbeat-installation-configuration.html T…

---

## [FunctionBeat integration with OpenSearch AWS](https://discuss.elastic.co/t/functionbeat-integration-with-opensearch-aws/304650)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 1\
**Last updated:** [May 13, 2022, 8:32am UTC](https://discuss.elastic.co/t/functionbeat-integration-with-opensearch-aws/304650 "2022-05-13T08:32:51Z")

</div>

Hello guys, I want to ask if somebody has used FunctionBeat to ingest/integrate with OpenSearch from AWS? What i want to accomplish is this: OpenSearch -\> logstash -\> Elasticsearch (running on azure) I have no experi…

---

## [Functionbeat ingest error handling](https://discuss.elastic.co/t/functionbeat-ingest-error-handling/301617)

<div class="topic-metadata">

**Author:** [@lyson](https://discuss.elastic.co/u/lyson)\
**Replies:** 0\
**Last updated:** [April 5, 2022, 9:57am UTC](https://discuss.elastic.co/t/functionbeat-ingest-error-handling/301617 "2022-04-05T09:57:21Z")

</div>

We are using functionbeat to forward CloudWatch logs and some custom events via SQS and we are trying to find the best way to make sure events are not lost. We identified different types of errors that can be handled di…

---

## [Functionbeat Cannot index event - security\_exception](https://discuss.elastic.co/t/functionbeat-cannot-index-event-security-exception/299016)

<div class="topic-metadata">

**Author:** [@carl0s](https://discuss.elastic.co/u/carl0s)\
**Replies:** 0\
**Last updated:** [March 7, 2022, 11:05pm UTC](https://discuss.elastic.co/t/functionbeat-cannot-index-event-security-exception/299016 "2022-03-07T23:05:40Z")

</div>

After upgrading to 7.17 none of my logs are being processed, lots of 403 errors: { "type": "security\_exception", "reason": "action \[indices:data/write/bulk\[s\]\] is unauthorized for API key id \[\<removed\>\] of user …

---

## [The first connection to logstash is always an error](https://discuss.elastic.co/t/the-first-connection-to-logstash-is-always-an-error/296253)

<div class="topic-metadata">

**Author:** [@driveirk](https://discuss.elastic.co/u/driveirk)\
**Replies:** 7\
**Last updated:** [March 3, 2022, 8:18am UTC](https://discuss.elastic.co/t/the-first-connection-to-logstash-is-always-an-error/296253 "2022-03-03T08:18:51Z")

</div>

When running lambda, I always see "retry" first, and then immediately connect to backoff. How to make logs sent on first connection? Is there any way to enable more readable logs? config functionbeat functionbeat:…

---

## [Function: cloudwatch, could not deploy, error: bucket 'functionbeat-deploy' already exist and you don't have permission to access it](https://discuss.elastic.co/t/function-cloudwatch-could-not-deploy-error-bucket-functionbeat-deploy-already-exist-and-you-dont-have-permission-to-access-it/293455)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 5\
**Last updated:** [February 28, 2022, 9:10am UTC](https://discuss.elastic.co/t/function-cloudwatch-could-not-deploy-error-bucket-functionbeat-deploy-already-exist-and-you-dont-have-permission-to-access-it/293455 "2022-02-28T09:10:26Z")

</div>

I had version 7.12 deployed of functionbeat, i removed it successfully using ./functionbeat -v -e -d "\*" remove cloudwatch I then configurd version 7.16 version of functionbeat and i am trying to deploy it but i get the…

---

## [Unable to deploy Functionbeat 7.16.3](https://discuss.elastic.co/t/unable-to-deploy-functionbeat-7-16-3/296857)

<div class="topic-metadata">

**Author:** [@Bhavani\_Ananth](https://discuss.elastic.co/u/Bhavani_Ananth)\
**Replies:** 0\
**Last updated:** [February 10, 2022, 2:38pm UTC](https://discuss.elastic.co/t/unable-to-deploy-functionbeat-7-16-3/296857 "2022-02-10T14:38:25Z")

</div>

Elasticsearch version : 7.16.3 Functionbeat: 7.16.3 OS : Ubuntu 20.04.3 LTS a. When I try to deploy functionbeat (version 7.16.3) in S3 bucket, I get the following exception Function: cloudwatch, could not deploy, er…

---

## [Could not create the CloudFormation stack request](https://discuss.elastic.co/t/could-not-create-the-cloudformation-stack-request/295437)

<div class="topic-metadata">

**Author:** [@Jason\_Zhang2](https://discuss.elastic.co/u/Jason_Zhang2)\
**Replies:** 4\
**Last updated:** [January 27, 2022, 1:12am UTC](https://discuss.elastic.co/t/could-not-create-the-cloudformation-stack-request/295437 "2022-01-27T01:12:01Z")

</div>

Hi, There We're trying to use functionbeat to add cloudwatch log into Elasticsearch. And it always gave this error 'Could not create the CloudFormation stack request'. This page mentioned that it's caused by region se…

---

## [Duplicate Documents](https://discuss.elastic.co/t/duplicate-documents/295343)

<div class="topic-metadata">

**Author:** [@driveirk](https://discuss.elastic.co/u/driveirk)\
**Replies:** 2\
**Last updated:** [January 26, 2022, 10:15am UTC](https://discuss.elastic.co/t/duplicate-documents/295343 "2022-01-26T10:15:07Z")

</div>

If there are communication problems, then in some cases the logs come 2 or 3 times, all the logs of one call are duplicated. Functionbeat config: functionbeat: provider: aws: deploy\_bucket: functionbeat-dep…

---

## [Functionbeat GCP pub/sub requiring storage entry point when only pub/sub is enabled](https://discuss.elastic.co/t/functionbeat-gcp-pub-sub-requiring-storage-entry-point-when-only-pub-sub-is-enabled/295254)

<div class="topic-metadata">

**Author:** [@Sebastian\_Borys](https://discuss.elastic.co/u/Sebastian_Borys)\
**Replies:** 4\
**Last updated:** [January 24, 2022, 9:24pm UTC](https://discuss.elastic.co/t/functionbeat-gcp-pub-sub-requiring-storage-entry-point-when-only-pub-sub-is-enabled/295254 "2022-01-24T21:24:44Z")

</div>

Deploying functionbeat on GCP with entry point RunPubSub returns an error complaining about storage entry point, which I am not using. I get the following error upon deploy Deployment failure: Build failed: # functions…

---

## [Functionbeat 7.16.2 parses quoted strings with periods as objects](https://discuss.elastic.co/t/functionbeat-7-16-2-parses-quoted-strings-with-periods-as-objects/294097)

<div class="topic-metadata">

**Author:** [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Replies:** 0\
**Last updated:** [January 12, 2022, 1:16am UTC](https://discuss.elastic.co/t/functionbeat-7-16-2-parses-quoted-strings-with-periods-as-objects/294097 "2022-01-12T01:16:44Z")

</div>

We maintain a set of billing tags on our AWS resources that are prefixed with "cost.". The 7.16.2 version of functionbeat errors out on those tags, despite me quoting the tag strings in the yaml file, it interprets them …

---

## [Using functionbeat environment variables](https://discuss.elastic.co/t/using-functionbeat-environment-variables/293707)

<div class="topic-metadata">

**Author:** [@Sultan](https://discuss.elastic.co/u/Sultan)\
**Replies:** 0\
**Last updated:** [January 7, 2022, 6:12am UTC](https://discuss.elastic.co/t/using-functionbeat-environment-variables/293707 "2022-01-07T06:12:03Z")

</div>

Hi, We are trying to use functionbeat to deploy a lambda function in AWS which eventually would ship kinesis logs to our elastic cloud. We do not want to keep the elastic credentials (ie. cloud.auth, cloud.id etc) in th…

[Next page](https://discuss.elastic.co/tag/functionbeat/60.md?match_all_tags=true&page=1&tags%5B%5D=functionbeat)
