# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=304

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 305

---

## [Elastic badrequest error: contains unrecognized parameter: \[type\]](https://discuss.elastic.co/t/elastic-badrequest-error-contains-unrecognized-parameter-type/353427)

<div class="topic-metadata">

**Author:** [@Vicapelli](https://discuss.elastic.co/u/Vicapelli)\
**Replies:** 4\
**Last updated:** [February 17, 2024, 9:45pm UTC](https://discuss.elastic.co/t/elastic-badrequest-error-contains-unrecognized-parameter-type/353427 "2024-02-17T21:45:37Z")

</div>

I am using Elasticsearch in a Rails application through the Elasticsearch-rails gem. After creating the indexes, I want to import the data into these indexes. But I am getting the following error: Elastic::Transport::T…

---

## [Logstash TCP encoder](https://discuss.elastic.co/t/logstash-tcp-encoder/353469)

<div class="topic-metadata">

**Author:** [@kypdk](https://discuss.elastic.co/u/kypdk)\
**Replies:** 3\
**Last updated:** [February 17, 2024, 3:54pm UTC](https://discuss.elastic.co/t/logstash-tcp-encoder/353469 "2024-02-17T15:54:41Z")

</div>

The logs go to the logstash server, but they are not indexed because they are not in the format I want. How should I configure it? output { elasticsearch { hosts =\> "elasticsearch:9200" …

---

## [Azure SAML configuration using free elastic/kibana version](https://discuss.elastic.co/t/azure-saml-configuration-using-free-elastic-kibana-version/353497)

<div class="topic-metadata">

**Author:** [@Pablo\_Lencinas](https://discuss.elastic.co/u/Pablo_Lencinas)\
**Replies:** 2\
**Last updated:** [February 17, 2024, 3:45pm UTC](https://discuss.elastic.co/t/azure-saml-configuration-using-free-elastic-kibana-version/353497 "2024-02-17T15:45:55Z")

</div>

Hi. I'm using elastic/kibana and elastiflow to collect netflow traffic and I would like to configure SAML authentication using Azure AD. I'm using Elastic v8.7.0 (free version). It is possible to configure this feature? …

---

## [Elasticsearch Query: search result not same when am searching for wooden door and wooden doors](https://discuss.elastic.co/t/elasticsearch-query-search-result-not-same-when-am-searching-for-wooden-door-and-wooden-doors/353504)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 1\
**Last updated:** [February 17, 2024, 12:15pm UTC](https://discuss.elastic.co/t/elasticsearch-query-search-result-not-same-when-am-searching-for-wooden-door-and-wooden-doors/353504 "2024-02-17T12:15:25Z")

</div>

when am search for wooden door and wooden doors results not show the same. Query which i have used to fetch the data { "query": { "bool": { "should": \[ { "mat…

---

## [First time user - Unable to get Filebeat \> logstash](https://discuss.elastic.co/t/first-time-user-unable-to-get-filebeat-logstash/352451)

<div class="topic-metadata">

**Author:** [@eezeetee](https://discuss.elastic.co/u/eezeetee)\
**Replies:** 18\
**Last updated:** [February 17, 2024, 5:24am UTC](https://discuss.elastic.co/t/first-time-user-unable-to-get-filebeat-logstash/352451 "2024-02-17T05:24:46Z")

</div>

I've been trying to get a home monitoring system up and running and i've fallen flat. My goal was to get MQTT and other messages into filebeat, thru logstash and into Kibana to build a dashboard. I've followed a few gu…

---

## [Lens - Pie Chart Summary](https://discuss.elastic.co/t/lens-pie-chart-summary/353493)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [February 17, 2024, 2:18am UTC](https://discuss.elastic.co/t/lens-pie-chart-summary/353493 "2024-02-17T02:18:39Z")

</div>

Hello, I was wondering if there's a way to make a summary pie chart. The problem is with pie charts, I can't seem to be able to "Last Value" of a keyword. But in a data table, I can. This is an example of the data ta…

---

## [Elastic-filebeat-nginx-kibana-docker compose](https://discuss.elastic.co/t/elastic-filebeat-nginx-kibana-docker-compose/353457)

<div class="topic-metadata">

**Author:** [@v.popov](https://discuss.elastic.co/u/v.popov)\
**Replies:** 4\
**Last updated:** [February 16, 2024, 8:14pm UTC](https://discuss.elastic.co/t/elastic-filebeat-nginx-kibana-docker-compose/353457 "2024-02-16T20:14:53Z")

</div>

Попробуем сначала на русском. Всем привет, я работаю с Elastic через docker compose. У меня сейчас 2 вопроса: 1- Почему у меня огромное количество отдаваемых логов от nginx? После создания index filebeat-\* перехожу к л…

---

## [Add context to suggestions field while re-indexing](https://discuss.elastic.co/t/add-context-to-suggestions-field-while-re-indexing/353407)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 6\
**Last updated:** [February 16, 2024, 7:18pm UTC](https://discuss.elastic.co/t/add-context-to-suggestions-field-while-re-indexing/353407 "2024-02-16T19:18:25Z")

</div>

so i'v been trying to add suggester to my old index which had docs with the fields -name --\> text -category --\> long -status --\> long i created a new index with the same mapping as the old one and i add the suggestio…

---

## [Windows install : jruby not found](https://discuss.elastic.co/t/windows-install-jruby-not-found/353487)

<div class="topic-metadata">

**Author:** [@jim.patterson](https://discuss.elastic.co/u/jim.patterson)\
**Replies:** 3\
**Last updated:** [February 16, 2024, 7:17pm UTC](https://discuss.elastic.co/t/windows-install-jruby-not-found/353487 "2024-02-16T19:17:55Z")

</div>

The error message I am getting: "could not find jruby in D:\\elastic\_stack\\logstash-8.12.0\\vendor\\jruby" I've opened and extracted the logstash-8.12.0-windows-x86\_64 file with 7zip, I didn't use windows default zip file…

---

## [Very High Cpu Usage for search](https://discuss.elastic.co/t/very-high-cpu-usage-for-search/352110)

<div class="topic-metadata">

**Author:** [@bharat\_bhushan\_ship](https://discuss.elastic.co/u/bharat_bhushan_ship)\
**Replies:** 8\
**Last updated:** [February 16, 2024, 6:14pm UTC](https://discuss.elastic.co/t/very-high-cpu-usage-for-search/352110 "2024-02-16T18:14:44Z")

</div>

I have a cluster (ES version 7.0.3) with 3 nodes with ubuntu servers and i have not declare any node as a master or data node, by default it elect one master and other data nodes itself. And i have only one index on this…

---

## [Logstash-filter-fingerprint failing intermittently](https://discuss.elastic.co/t/logstash-filter-fingerprint-failing-intermittently/353317)

<div class="topic-metadata">

**Author:** [@ellje](https://discuss.elastic.co/u/ellje)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 5:51pm UTC](https://discuss.elastic.co/t/logstash-filter-fingerprint-failing-intermittently/353317 "2024-02-16T17:51:27Z")

</div>

My pipeline starts up fine and eventually fails for this error, and has only happened twice in a long period of time, but I would like to understand what is the issue. Getting the following error: Pipeline worker error…

---

## [Multipipeline Sending data to wrong index](https://discuss.elastic.co/t/multipipeline-sending-data-to-wrong-index/353428)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 5:22pm UTC](https://discuss.elastic.co/t/multipipeline-sending-data-to-wrong-index/353428 "2024-02-16T17:22:29Z")

</div>

Hello all, I am trying to implement multiple pipelines, but it appears the output of one is being sent to two indices; its own and the other pipelines. $logstash --version Using bundled JDK: /usr/share/logstash/jdk logs…

---

## [Syslog output plugin message parameter ignored](https://discuss.elastic.co/t/syslog-output-plugin-message-parameter-ignored/352560)

<div class="topic-metadata">

**Author:** [@mutt13y](https://discuss.elastic.co/u/mutt13y)\
**Replies:** 3\
**Last updated:** [February 16, 2024, 5:22pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-message-parameter-ignored/352560 "2024-02-16T17:22:14Z")

</div>

the message parameter for the syslog output plugin is documented as used to set the syslog message (default "%{message}") The parameter is defined here logstash-output-syslog/lib/logstash/outputs/syslog.rb at main · log…

---

## [FATAL Error: Cannot find module '../../../../packages/kbn-config-schema'](https://discuss.elastic.co/t/fatal-error-cannot-find-module-packages-kbn-config-schema/353481)

<div class="topic-metadata">

**Author:** [@trosagnant](https://discuss.elastic.co/u/trosagnant)\
**Replies:** 0\
**Last updated:** [February 16, 2024, 3:57pm UTC](https://discuss.elastic.co/t/fatal-error-cannot-find-module-packages-kbn-config-schema/353481 "2024-02-16T15:57:28Z")

</div>

ELK version: 8.5.3 yarn version: 1.22.19 So I'm developing a Kibana plugin and whenever I need to call @kbn/config-schema inside of it, I get the fatal error on Kibana startup after installation of said plugin (pasted …

---

## [Elastic agent an system Integrations generate infinite void indixes with infinite rollover](https://discuss.elastic.co/t/elastic-agent-an-system-integrations-generate-infinite-void-indixes-with-infinite-rollover/353478)

<div class="topic-metadata">

**Author:** [@hectorGC](https://discuss.elastic.co/u/hectorGC)\
**Replies:** 0\
**Last updated:** [February 16, 2024, 3:36pm UTC](https://discuss.elastic.co/t/elastic-agent-an-system-integrations-generate-infinite-void-indixes-with-infinite-rollover/353478 "2024-02-16T15:36:00Z")

</div>

Suddenly after normal work of the team we suffered a big amount of metrics logs, looking at that we discovered that the integrations of elastic-agent and system indexes started to make rollover of all namespaces. Continu…

---

## [Once Filebeat/Elasticsearch has ingested log files, can the logs themselves be deleted?](https://discuss.elastic.co/t/once-filebeat-elasticsearch-has-ingested-log-files-can-the-logs-themselves-be-deleted/353473)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 2:49pm UTC](https://discuss.elastic.co/t/once-filebeat-elasticsearch-has-ingested-log-files-can-the-logs-themselves-be-deleted/353473 "2024-02-16T14:49:37Z")

</div>

I'm using Filebeat/Elasticsearch to index Zeek network traffic logs. I'm missing a key piece of understanding about Filebeat/Elasticsearch. Once the logs have been ingested and indexed, are the logs themselves accessed t…

---

## [Lens - No results found](https://discuss.elastic.co/t/lens-no-results-found/353306)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 6\
**Last updated:** [February 16, 2024, 2:35pm UTC](https://discuss.elastic.co/t/lens-no-results-found/353306 "2024-02-16T14:35:42Z")

</div>

Hello, So I made a bar vertically stacked graph, when there's data it populates the graph based on the time interval. This is expected behavior. The problem is if there's no data then it shows "no results found", t…

---

## [Revent Windows Service Changes c:\\programdata\\?](https://discuss.elastic.co/t/revent-windows-service-changes-c-programdata/353423)

<div class="topic-metadata">

**Author:** [@Aaron\_C\_de\_Bruyn](https://discuss.elastic.co/u/Aaron_C_de_Bruyn)\
**Replies:** 4\
**Last updated:** [February 16, 2024, 2:33pm UTC](https://discuss.elastic.co/t/revent-windows-service-changes-c-programdata/353423 "2024-02-16T14:33:38Z")

</div>

I just updated Winlogbeat on a Windows Server from 8.9.2 to 8.12.1 and the winlogbeat service won't start. I did some quick digging, and the service runs: "C:\\Program Files\\Elastic\\Beats\\8.12.1\\winlogbeat\\winlogbeat.ex…

---

## [Issue with Filebeat Zeek module](https://discuss.elastic.co/t/issue-with-filebeat-zeek-module/353458)

<div class="topic-metadata">

**Author:** [@OwenGauci](https://discuss.elastic.co/u/OwenGauci)\
**Replies:** 17\
**Last updated:** [February 16, 2024, 2:32pm UTC](https://discuss.elastic.co/t/issue-with-filebeat-zeek-module/353458 "2024-02-16T14:32:31Z")

</div>

Hi, I Installed Zeek on an Ubuntu 22 VM and would like to send logs to Elasticsearch/Kibana using Filebeat. I followed Zeek Logs Intergation Tutorial but it's not able to send the logs. These are on separate Ubuntu 22 VM…

---

## [When filebeat logs are deleted, does this delete Elasticsearch indices?](https://discuss.elastic.co/t/when-filebeat-logs-are-deleted-does-this-delete-elasticsearch-indices/353408)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 5\
**Last updated:** [February 16, 2024, 2:21pm UTC](https://discuss.elastic.co/t/when-filebeat-logs-are-deleted-does-this-delete-elasticsearch-indices/353408 "2024-02-16T14:21:52Z")

</div>

I have an elasticsearch cluster which ingests logs from Filebeat. I'm trying to limit the total size of the indices. If I delete the raw files that filebeat is ingesting, will the corresponding Elasticsearch indices be d…

---

## [Very uneven distribution of docs accross shards](https://discuss.elastic.co/t/very-uneven-distribution-of-docs-accross-shards/353463)

<div class="topic-metadata">

**Author:** [@Emil](https://discuss.elastic.co/u/Emil)\
**Replies:** 8\
**Last updated:** [February 16, 2024, 1:30pm UTC](https://discuss.elastic.co/t/very-uneven-distribution-of-docs-accross-shards/353463 "2024-02-16T13:30:44Z")

</div>

We've been indexing documents to an index with 20 primary shards, but the shards have grown to have uneven sizes (smallest is 3.2 GB, largest 31.7GB, so 10 times as large) Investigating, I found out that while the total…

---

## [Elastic Search 2.4.1 Windows Service](https://discuss.elastic.co/t/elastic-search-2-4-1-windows-service/353453)

<div class="topic-metadata">

**Author:** [@Franco.dicarlo](https://discuss.elastic.co/u/Franco.dicarlo)\
**Replies:** 1\
**Last updated:** [February 16, 2024, 12:46pm UTC](https://discuss.elastic.co/t/elastic-search-2-4-1-windows-service/353453 "2024-02-16T12:46:23Z")

</div>

Hi to all, I have a 2.4.1 Elastic Search installed as a service on a windows server. I was working with ES in c#, I was trying to delete items in a specific index. Unfortunately I deleted more data than necessary,I im…

---

## [Master not discovered or elected yet, when stopping Elasticsearch service](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-when-stopping-elasticsearch-service/353377)

<div class="topic-metadata">

**Author:** [@andrejze](https://discuss.elastic.co/u/andrejze)\
**Replies:** 18\
**Last updated:** [February 16, 2024, 12:45pm UTC](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-when-stopping-elasticsearch-service/353377 "2024-02-16T12:45:50Z")

</div>

OS: Debian 10 (buster), 4.19.0-25-amd64 #1 SMP Debian 4.19.289-2 (2023-08-08) Elasticsearch: 8.12.0 Cluster: 3 nodes, all master eligible When stopping Elasticsearch service on any node, operation gets stuck with err…

---

## [Docker nginx elasticsearch](https://discuss.elastic.co/t/docker-nginx-elasticsearch/352374)

<div class="topic-metadata">

**Author:** [@v.popov](https://discuss.elastic.co/u/v.popov)\
**Replies:** 6\
**Last updated:** [February 16, 2024, 11:39am UTC](https://discuss.elastic.co/t/docker-nginx-elasticsearch/352374 "2024-02-16T11:39:22Z")

</div>

Hi guys. I need help. I have configured everything that is needed, in my opinion, but I can’t understand why the server doesn’t want to connect to the log analytics agent. I wanted to do a test, but I was stuck with the …

---

## [How to Enable SSL only for Kibana not Elasticsearch](https://discuss.elastic.co/t/how-to-enable-ssl-only-for-kibana-not-elasticsearch/353349)

<div class="topic-metadata">

**Author:** [@ersalil](https://discuss.elastic.co/u/ersalil)\
**Replies:** 4\
**Last updated:** [February 16, 2024, 10:20am UTC](https://discuss.elastic.co/t/how-to-enable-ssl-only-for-kibana-not-elasticsearch/353349 "2024-02-16T10:20:35Z")

</div>

Hello, I have a go application which is using elastic client, I want to enable the ssl for communication between kibana and elasticsearch but not go client with elasticsearch. Note: Editing go code is not in option. Ca…

---

## [503 Error encountered during the upgrade of Logstash from version 8.10.4 to 8.12.1](https://discuss.elastic.co/t/503-error-encountered-during-the-upgrade-of-logstash-from-version-8-10-4-to-8-12-1/353442)

<div class="topic-metadata">

**Author:** [@Ramya\_Sababathi](https://discuss.elastic.co/u/Ramya_Sababathi)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 10:15am UTC](https://discuss.elastic.co/t/503-error-encountered-during-the-upgrade-of-logstash-from-version-8-10-4-to-8-12-1/353442 "2024-02-16T10:15:57Z")

</div>

Hi, I recently performed the first upgrade of Logstash from version 8.10.4 to 8.12.1 and encountered an error during the process. It's important to note that this error only occurs during the initial upgrade and not dur…

---

## [KIBANA 8.12.0 to 8.12.1 error](https://discuss.elastic.co/t/kibana-8-12-0-to-8-12-1-error/352862)

<div class="topic-metadata">

**Author:** [@Tikelo](https://discuss.elastic.co/u/Tikelo)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 8:30am UTC](https://discuss.elastic.co/t/kibana-8-12-0-to-8-12-1-error/352862 "2024-02-16T08:30:31Z")

</div>

Hi, I upgrade my stack 7.17.16 to 7.17.18 and my stack 8.12.0 to 8.12.1 Elasticsearch, logstash, filebeat \> ok Kibana start but when i try access i have same error OS : debian 11 (install with deb package) My config…

---

## [Can we add two differen types of visulization in one visulization only?](https://discuss.elastic.co/t/can-we-add-two-differen-types-of-visulization-in-one-visulization-only/353366)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 3\
**Last updated:** [February 16, 2024, 5:51am UTC](https://discuss.elastic.co/t/can-we-add-two-differen-types-of-visulization-in-one-visulization-only/353366 "2024-02-16T05:51:57Z")

</div>

Hi, is it possible in KIBANA To add two different types of visualization in one visualization only ? For example : can we combine data table and line graph in one visualization ?

---

## [AMQP Metadata from RabbitMQ input plugin](https://discuss.elastic.co/t/amqp-metadata-from-rabbitmq-input-plugin/352711)

<div class="topic-metadata">

**Author:** [@Big-Edd](https://discuss.elastic.co/u/Big-Edd)\
**Replies:** 5\
**Last updated:** [February 16, 2024, 1:46am UTC](https://discuss.elastic.co/t/amqp-metadata-from-rabbitmq-input-plugin/352711 "2024-02-16T01:46:37Z")

</div>

Hello Everyone, We are inputting AMQP messages from RabbitMQ. These come to RabbitMQ via SMTP utilizing the rabbitmq-email plugin, so the AMQP headers contain some SMTP information we need. By default it seems that onl…

---

## [Filebeat error on Windows: index management requested but the Elasticsearch output is not configured/enabled](https://discuss.elastic.co/t/filebeat-error-on-windows-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/353310)

<div class="topic-metadata">

**Author:** [@tcalvillo](https://discuss.elastic.co/u/tcalvillo)\
**Replies:** 17\
**Last updated:** [February 15, 2024, 9:42pm UTC](https://discuss.elastic.co/t/filebeat-error-on-windows-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/353310 "2024-02-15T21:42:26Z")

</div>

Hello Filebeat team, I did my due-diligence and did read all the posts with same error as mine but still stuck. I'm following this doc-\> Filebeat quick start: installation and configuration | Filebeat Reference \[8.12\] …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=303)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=305)
