# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=314

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 315

---

## [Formal grammar for DSL?](https://discuss.elastic.co/t/formal-grammar-for-dsl/352564)

<div class="topic-metadata">

**Author:** [@Steph\_van\_Schalkwyk](https://discuss.elastic.co/u/Steph_van_Schalkwyk)\
**Replies:** 0\
**Last updated:** [February 5, 2024, 7:02pm UTC](https://discuss.elastic.co/t/formal-grammar-for-dsl/352564 "2024-02-05T19:02:21Z")

</div>

Continuing the discussion from Formal Grammar of Query DSL?: Still looking. I can find SQL and Painless grammars, but not DSL.

---

## [Corrupt primary shard, how to recover from replica shard?](https://discuss.elastic.co/t/corrupt-primary-shard-how-to-recover-from-replica-shard/352561)

<div class="topic-metadata">

**Author:** [@ncluff](https://discuss.elastic.co/u/ncluff)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 6:34pm UTC](https://discuss.elastic.co/t/corrupt-primary-shard-how-to-recover-from-replica-shard/352561 "2024-02-05T18:34:49Z")

</div>

I have an index with 3 primary shards and 1 replica. Primary shard 1 for some reason goes corrupt. The error mentions merge failed, org.apache.lucene.index.CorruptIndexException which I'm looking into. Am I right thinkin…

---

## [Was CRC32 in version 7.x of Elasticsearch?](https://discuss.elastic.co/t/was-crc32-in-version-7-x-of-elasticsearch/352558)

<div class="topic-metadata">

**Author:** [@ncluff](https://discuss.elastic.co/u/ncluff)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 5:58pm UTC](https://discuss.elastic.co/t/was-crc32-in-version-7-x-of-elasticsearch/352558 "2024-02-05T17:58:33Z")

</div>

I noticed this post where David Turner mentions the troubleshooting guide for corruption. The documentation started in 8.3, but I'm curious if this is the same for version 7.17.4? Backstory, I have a deployment on VMWar…

---

## [Configuring Logstash to Accept Both SSL and Non-SSL Connections](https://discuss.elastic.co/t/configuring-logstash-to-accept-both-ssl-and-non-ssl-connections/352528)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 4:28pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-accept-both-ssl-and-non-ssl-connections/352528 "2024-02-05T16:28:57Z")

</div>

Hi, I'm currently working on setting up Logstash to accept both SSL and non-SSL connections from Beats. From my understanding, I would need to configure two separate Beats inputs on different ports. For example: input …

---

## [Error while trying to new node to existing cluster. Bootstrap settings failed](https://discuss.elastic.co/t/error-while-trying-to-new-node-to-existing-cluster-bootstrap-settings-failed/352404)

<div class="topic-metadata">

**Author:** [@charvi23](https://discuss.elastic.co/u/charvi23)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 3:43pm UTC](https://discuss.elastic.co/t/error-while-trying-to-new-node-to-existing-cluster-bootstrap-settings-failed/352404 "2024-02-05T15:43:28Z")

</div>

Getting error while adding new node to cluster. \[1\] bootstrap checks failed. You must address the points described in the following \[1\] lines before starting Elasticsearch. For more information see \[ https://www.elastic…

---

## [Can't parse event as syslog rfc3164](https://discuss.elastic.co/t/cant-parse-event-as-syslog-rfc3164/352307)

<div class="topic-metadata">

**Author:** [@Amol\_Sahare](https://discuss.elastic.co/u/Amol_Sahare)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 2:50pm UTC](https://discuss.elastic.co/t/cant-parse-event-as-syslog-rfc3164/352307 "2024-02-05T14:50:35Z")

</div>

Hello, We are having problems with the'syslog' input of filebeat. I'm using the script for sending a single log to the filebeat syslog input. I've noticed that the same message is being parsed because I can see the eve…

---

## [How to parse Mime x-wine-extension-ini files](https://discuss.elastic.co/t/how-to-parse-mime-x-wine-extension-ini-files/352541)

<div class="topic-metadata">

**Author:** [@Admin\_Zee9](https://discuss.elastic.co/u/Admin_Zee9)\
**Replies:** 0\
**Last updated:** [February 5, 2024, 2:06pm UTC](https://discuss.elastic.co/t/how-to-parse-mime-x-wine-extension-ini-files/352541 "2024-02-05T14:06:14Z")

</div>

Hello, Has anyone had to deal with parsing a MIME type x-wine-extension-ini file? I need to convert many of them to CSV or XML using AWS Athena. I found that a Grok pattern could be helpful, but this is the first time…

---

## [Watcher ssl fail](https://discuss.elastic.co/t/watcher-ssl-fail/351444)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 1:57pm UTC](https://discuss.elastic.co/t/watcher-ssl-fail/351444 "2024-02-05T13:57:40Z")

</div>

Hello, I read the documentation about sending email with PDF dashboard in the attachment \>\>\> Automatically generate reports | Kibana Guide \[8.9\] | Elastic I wanted to create my own watcher. My Kibana version is 7.17.8 …

---

## [About the ILM policy implented and on the post observations](https://discuss.elastic.co/t/about-the-ilm-policy-implented-and-on-the-post-observations/351851)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 6\
**Last updated:** [February 5, 2024, 1:16pm UTC](https://discuss.elastic.co/t/about-the-ilm-policy-implented-and-on-the-post-observations/351851 "2024-02-05T13:16:52Z")

</div>

Hello, Recently I have implemented ILM policy on of the production setup. However, the rollover for the existing ILM policy seems to be working fine. But I am seeing indices for other version e.g. 8.x are utilizing the…

---

## [Unable to access 'path.data' (/data/db/elasticsearch)](https://discuss.elastic.co/t/unable-to-access-path-data-data-db-elasticsearch/352302)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 1:36pm UTC](https://discuss.elastic.co/t/unable-to-access-path-data-data-db-elasticsearch/352302 "2024-02-05T13:36:32Z")

</div>

This is my Statefulset for Elasticsearch spec: podManagementPolicy: OrderedReady replicas: 3 revisionHistoryLimit: 10 selector: matchLabels: app: elasticsearch serviceName: elasticsearch-data templ…

---

## [Monitor database metrics using elastic](https://discuss.elastic.co/t/monitor-database-metrics-using-elastic/352530)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 1:19pm UTC](https://discuss.elastic.co/t/monitor-database-metrics-using-elastic/352530 "2024-02-05T13:19:06Z")

</div>

Is it possible to monitor database metrics like connection time, page reads, open connections, uptime, long running queries, etc using elastic?

---

## [Registering S3 repository from private subnet fails with "Unauthorized"](https://discuss.elastic.co/t/registering-s3-repository-from-private-subnet-fails-with-unauthorized/352527)

<div class="topic-metadata">

**Author:** [@strophy](https://discuss.elastic.co/u/strophy)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 12:56pm UTC](https://discuss.elastic.co/t/registering-s3-repository-from-private-subnet-fails-with-unauthorized/352527 "2024-02-05T12:56:05Z")

</div>

I'm trying to register an S3 repository for a test cluster of two instances running Elasticsearch 8.12.0 in a private AWS subnet using IAM instance profiles instead of access keys. The subnet security group has outgoing …

---

## [What is the risk of running Rally on production?](https://discuss.elastic.co/t/what-is-the-risk-of-running-rally-on-production/352433)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 11:48am UTC](https://discuss.elastic.co/t/what-is-the-risk-of-running-rally-on-production/352433 "2024-02-05T11:48:20Z")

</div>

I have ran Rally on a staging instance and wanted to compare the performance to our existing production cluster. From the documentation: First of all: Please (please, please) do NOT run Rally against your production clu…

---

## [Java api client 7.x with Elasticsearch server 8.x](https://discuss.elastic.co/t/java-api-client-7-x-with-elasticsearch-server-8-x/352369)

<div class="topic-metadata">

**Author:** [@SElasticsearch](https://discuss.elastic.co/u/SElasticsearch)\
**Replies:** 3\
**Last updated:** [February 5, 2024, 11:35am UTC](https://discuss.elastic.co/t/java-api-client-7-x-with-elasticsearch-server-8-x/352369 "2024-02-05T11:35:37Z")

</div>

We have a scenario where our application needs to connect with both 7.x and 8.x Elasticsearch server. Using Java API client 7.17.16 and it works with Elasticsearch server 7.x. Used (HttpHeaders.CONTENT\_TYPE, "applicatio…

---

## [Are Conditional Aggregations Possible?](https://discuss.elastic.co/t/are-conditional-aggregations-possible/352518)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [February 5, 2024, 10:21am UTC](https://discuss.elastic.co/t/are-conditional-aggregations-possible/352518 "2024-02-05T10:21:06Z")

</div>

I want to run a count query with an associated aggregation, but only run the aggregation if the count for the query is below a certain number. Is this possible?

---

## [Logstash Proxy Credentials](https://discuss.elastic.co/t/logstash-proxy-credentials/352414)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 9:22am UTC](https://discuss.elastic.co/t/logstash-proxy-credentials/352414 "2024-02-05T09:22:33Z")

</div>

Good afternoon colleagues! I have a logstash service in local and an elastic server in cloud. To reach it via curl I need to set --proxy https://proxy:8080 and --proxy-user 'user\\moreusername:password' . How can I do …

---

## [How can I generate root-ca.pem file for Elasticsearch](https://discuss.elastic.co/t/how-can-i-generate-root-ca-pem-file-for-elasticsearch/352511)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 9:16am UTC](https://discuss.elastic.co/t/how-can-i-generate-root-ca-pem-file-for-elasticsearch/352511 "2024-02-05T09:16:19Z")

</div>

How can I generate root-ca.pem file for Elasticsearch ,Would be great if some help me

---

## [Pass Kibana log in credentials to external backend server](https://discuss.elastic.co/t/pass-kibana-log-in-credentials-to-external-backend-server/351965)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 8:34am UTC](https://discuss.elastic.co/t/pass-kibana-log-in-credentials-to-external-backend-server/351965 "2024-02-05T08:34:48Z")

</div>

Hi, I am creating a custom plugin in React JS. The plugin has UI, which communicates with an external backend/server managed by me. When user logs into Kibana, I want to pass those credentials (which was used to log i…

---

## [Kibana Home Dashboard showing critical In Red and Non critical Green](https://discuss.elastic.co/t/kibana-home-dashboard-showing-critical-in-red-and-non-critical-green/352190)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 6\
**Last updated:** [February 5, 2024, 7:58am UTC](https://discuss.elastic.co/t/kibana-home-dashboard-showing-critical-in-red-and-non-critical-green/352190 "2024-02-05T07:58:40Z")

</div>

Hello All, Is there anyway I can transfer my Old implementaion to show HOME monitoring page to admins in this new way. This first approach is not required as per customer and asked instead for second approach that I do…

---

## [Highlighting the latest logs within Visualization/Discover](https://discuss.elastic.co/t/highlighting-the-latest-logs-within-visualization-discover/352285)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 5:41am UTC](https://discuss.elastic.co/t/highlighting-the-latest-logs-within-visualization-discover/352285 "2024-02-05T05:41:52Z")

</div>

Is there any way to highlight the new logs within the discovery or visualization ? I just want to highlight the latest, like the top 10 latest logs. or any coloring mechanism that should be erased when the user clicks o…

---

## [NearRealTime aggregation on recent inserted document](https://discuss.elastic.co/t/nearrealtime-aggregation-on-recent-inserted-document/352481)

<div class="topic-metadata">

**Author:** [@abduimrn](https://discuss.elastic.co/u/abduimrn)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 5:20am UTC](https://discuss.elastic.co/t/nearrealtime-aggregation-on-recent-inserted-document/352481 "2024-02-05T05:20:50Z")

</div>

Hello, Elasticsearch is Near Real Time. Which in short it indicates that after issuing an insert request, it will not directly appear to all search and aggregation queries. In my application I first insert a document t…

---

## [Can not login elastic web interface](https://discuss.elastic.co/t/can-not-login-elastic-web-interface/352500)

<div class="topic-metadata">

**Author:** [@Ting\_sf](https://discuss.elastic.co/u/Ting_sf)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 4:18am UTC](https://discuss.elastic.co/t/can-not-login-elastic-web-interface/352500 "2024-02-05T04:18:34Z")

</div>

I can not login elastic web interface at localhose:5601. Not matter what I put in username and password, it shows “we couldn’t log you in, please try again” I do have user “elastic” and password correct, but can not log…

---

## [Logstash output email plugin failure](https://discuss.elastic.co/t/logstash-output-email-plugin-failure/351847)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 9\
**Last updated:** [February 5, 2024, 3:38am UTC](https://discuss.elastic.co/t/logstash-output-email-plugin-failure/351847 "2024-02-05T03:38:51Z")

</div>

Hello Team, i am using elk 8.5.3 and in the logstash output plugin , its failing with SMTP syntax error as pasted below ERROR\]\[logstash.outputs.email \]\[main\]\[9ab43dc1824014b9cc39372f569aeded7925e535ec037015bed8af1439…

---

## [Wallboard display](https://discuss.elastic.co/t/wallboard-display/352495)

<div class="topic-metadata">

**Author:** [@Ross\_Wakelin](https://discuss.elastic.co/u/Ross_Wakelin)\
**Replies:** 1\
**Last updated:** [February 4, 2024, 10:31pm UTC](https://discuss.elastic.co/t/wallboard-display/352495 "2024-02-04T22:31:39Z")

</div>

Hi We are setting up a new Security management room, and want to have some dashboards etc. from Kibana displayed permanently on a wall screen. I can't seem to find any hints or tips anywhere on how to set up autologon …

---

## [Regex double quotation use Lucene on Elasticsearch](https://discuss.elastic.co/t/regex-double-quotation-use-lucene-on-elasticsearch/352484)

<div class="topic-metadata">

**Author:** [@S\_n\_Ngo\_Hoang](https://discuss.elastic.co/u/S_n_Ngo_Hoang)\
**Replies:** 0\
**Last updated:** [February 4, 2024, 2:48pm UTC](https://discuss.elastic.co/t/regex-double-quotation-use-lucene-on-elasticsearch/352484 "2024-02-04T14:48:48Z")

</div>

Hello everyone, I'm new to ELK and I'm eager to learn about searching and regex with Lucene. I want to know how to regex double quotation marks in logs. For example, in the "message" field, I want to filter logs that con…

---

## [Unnest JSON](https://discuss.elastic.co/t/unnest-json/352447)

<div class="topic-metadata">

**Author:** [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Replies:** 6\
**Last updated:** [February 4, 2024, 2:28pm UTC](https://discuss.elastic.co/t/unnest-json/352447 "2024-02-04T14:28:21Z")

</div>

Good Day, I am trying to unnest a JSON log and I can't seem to get it to work. When I try to unnest I get the already unnested JSON showing up 3 times and I while I am able to unnest the JSON I can't write the actual f…

---

## [About reindex](https://discuss.elastic.co/t/about-reindex/350833)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 6\
**Last updated:** [February 4, 2024, 9:21am UTC](https://discuss.elastic.co/t/about-reindex/350833 "2024-02-04T09:21:53Z")

</div>

I have a concern when reindex, which is how to ensure seamless integration during the re indexing process as the original index continues to write data?

---

## [Can anyone provide a arm image of package-registry for the env?](https://discuss.elastic.co/t/can-anyone-provide-a-arm-image-of-package-registry-for-the-env/351428)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 3\
**Last updated:** [February 4, 2024, 8:49am UTC](https://discuss.elastic.co/t/can-anyone-provide-a-arm-image-of-package-registry-for-the-env/351428 "2024-02-04T08:49:42Z")

</div>

my elk works at the air-gapped env. i need to deploy a package-registry for the fleet,but the image only the amd,anyone helps?

---

## [Logstash keystore create error](https://discuss.elastic.co/t/logstash-keystore-create-error/351854)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 2\
**Last updated:** [February 4, 2024, 8:23am UTC](https://discuss.elastic.co/t/logstash-keystore-create-error/351854 "2024-02-04T08:23:32Z")

</div>

logstash version 7.11.1 when i try to create a keystore but got an error as \>uninitialized constant LogStash::Util::Password, how to resolve this? \[elk@centos70\_112 logstash-7.11.1\]$ ./bin/logstash-keystore --path.sett…

---

## [Logstash failed to differentiate log filtering based on data source IP address](https://discuss.elastic.co/t/logstash-failed-to-differentiate-log-filtering-based-on-data-source-ip-address/352471)

<div class="topic-metadata">

**Author:** [@pacoxpk](https://discuss.elastic.co/u/pacoxpk)\
**Replies:** 2\
**Last updated:** [February 4, 2024, 7:03am UTC](https://discuss.elastic.co/t/logstash-failed-to-differentiate-log-filtering-based-on-data-source-ip-address/352471 "2024-02-04T07:03:56Z")

</div>

Send logs from multiple systems through syslog to logstash, which can receive logs normally. In order to distinguish logs sent from different systems, it is necessary to distinguish them based on the IP address of the da…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=313)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=315)
