# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=316

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 317

---

## [Logstash stats API is showing wrong events values](https://discuss.elastic.co/t/logstash-stats-api-is-showing-wrong-events-values/352419)

<div class="topic-metadata">

**Author:** [@Freddy\_Laffita\_Almag](https://discuss.elastic.co/u/Freddy_Laffita_Almag)\
**Replies:** 0\
**Last updated:** [February 2, 2024, 3:17pm UTC](https://discuss.elastic.co/t/logstash-stats-api-is-showing-wrong-events-values/352419 "2024-02-02T15:17:53Z")

</div>

Hello everyone: I'm using logstash from a docker image, I'm consulting the stats API to show the logs processed by a pipeline to the user, but when I send 200 logs every 0.01 seconds the event information is showing wro…

---

## [What is the best procedure to delete indices?](https://discuss.elastic.co/t/what-is-the-best-procedure-to-delete-indices/351778)

<div class="topic-metadata">

**Author:** [@7a6b6f](https://discuss.elastic.co/u/7a6b6f)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 3:17pm UTC](https://discuss.elastic.co/t/what-is-the-best-procedure-to-delete-indices/351778 "2024-02-02T15:17:38Z")

</div>

Hello everyone, I have a question regarding the deletion of indices in an ELK (Elasticsearch, Logstash, Kibana) Docker-compose stack. Specifically, I would like to know the recommended procedure for deleting indices, an…

---

## [ConnectionError: socket hang up](https://discuss.elastic.co/t/connectionerror-socket-hang-up/351009)

<div class="topic-metadata">

**Author:** [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Replies:** 4\
**Last updated:** [February 2, 2024, 2:37pm UTC](https://discuss.elastic.co/t/connectionerror-socket-hang-up/351009 "2024-02-02T14:37:29Z")

</div>

I successfully run this docker compose locally on macOS and can work with ELK, but when running the same compose I encounter the following errors: \[2024-01-13T14:26:44.001+00:00\]\[ERROR\]\[plugins.security.authorization\]…

---

## [Query on ELK stack version 8.12: post installation](https://discuss.elastic.co/t/query-on-elk-stack-version-8-12-post-installation/352304)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 1:44pm UTC](https://discuss.elastic.co/t/query-on-elk-stack-version-8-12-post-installation/352304 "2024-02-02T13:44:00Z")

</div>

Hello, I have installed ELK stack version 8.12 on one of the test instance. The purpose was to assign the existing ILM policy set for ver 7.17, as I could see new indices are being built with filebeat version 8.x on a p…

---

## [Logstash netflow codec says "no template has been received" but it did receive one](https://discuss.elastic.co/t/logstash-netflow-codec-says-no-template-has-been-received-but-it-did-receive-one/352397)

<div class="topic-metadata">

**Author:** [@m0nkeyc0de](https://discuss.elastic.co/u/m0nkeyc0de)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 1:30pm UTC](https://discuss.elastic.co/t/logstash-netflow-codec-says-no-template-has-been-received-but-it-did-receive-one/352397 "2024-02-02T13:30:06Z")

</div>

Hello, the Logstash codec logstash-codec-netflow says it can't decode a flowset because no template has been received. When looking in the packet capture, a template has been sent. \[2024-02-02T13:10:19,136\]\[WARN \]\[logst…

---

## [Kibana oidc (azure) role assignment not working (too many groups)](https://discuss.elastic.co/t/kibana-oidc-azure-role-assignment-not-working-too-many-groups/350568)

<div class="topic-metadata">

**Author:** [@rafi0101](https://discuss.elastic.co/u/rafi0101)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 12:15pm UTC](https://discuss.elastic.co/t/kibana-oidc-azure-role-assignment-not-working-too-many-groups/350568 "2024-02-02T12:15:11Z")

</div>

I am using Kibana/Elasticsearch with Oidc (Microsoft Azure) for authentication. Currently I have the problem that not all defined role mappings are working correctly. We are using Azure groups in role mappings to assig…

---

## [BulkInsert fails with knn\_vector data type](https://discuss.elastic.co/t/bulkinsert-fails-with-knn-vector-data-type/352390)

<div class="topic-metadata">

**Author:** [@CodeNinja](https://discuss.elastic.co/u/CodeNinja)\
**Replies:** 0\
**Last updated:** [February 2, 2024, 11:58am UTC](https://discuss.elastic.co/t/bulkinsert-fails-with-knn-vector-data-type/352390 "2024-02-02T11:58:44Z")

</div>

Hello All, I am using BulkInsert (Java client) to ingest with an Index that has knn\_vector Data Type. Currently, I am able to ingest when I create document with a POJO Class object for every row that insert into Index. …

---

## [How we can drop transport event type in Elasticsearch 8.12 version](https://discuss.elastic.co/t/how-we-can-drop-transport-event-type-in-elasticsearch-8-12-version/352358)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 5:43am UTC](https://discuss.elastic.co/t/how-we-can-drop-transport-event-type-in-elasticsearch-8-12-version/352358 "2024-02-02T05:43:40Z")

</div>

Hi Team, I am getting system generated log in Elasticsearch Audit logs file. can you please provide me solution to avoid the system generated logs in audit log. I did below configuration in elasticsearch.yml file Mi…

---

## [AWS S3 buclet with SQS failed processing SQS S3 event notification](https://discuss.elastic.co/t/aws-s3-buclet-with-sqs-failed-processing-sqs-s3-event-notification/350664)

<div class="topic-metadata">

**Author:** [@Merdesz](https://discuss.elastic.co/u/Merdesz)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 9:01am UTC](https://discuss.elastic.co/t/aws-s3-buclet-with-sqs-failed-processing-sqs-s3-event-notification/350664 "2024-02-02T09:01:54Z")

</div>

Hi! Trying to set up the AWS Cloudtrail integration with elastic-agent/fleet. The integration is able to pull the SQS messages, but then it says "Failed processing SQS message. AWS Permissions: And it doesn't …

---

## [Getting Error in Elasticsearch 8.12 version](https://discuss.elastic.co/t/getting-error-in-elasticsearch-8-12-version/352371)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 8:07am UTC](https://discuss.elastic.co/t/getting-error-in-elasticsearch-8-12-version/352371 "2024-02-02T08:07:34Z")

</div>

I am getting error while starting the Elasticsearch please provide the solution for this. Error java.lang.IllegalArgumentException: unknown setting \[xpack.security.audit.logfile.events.ignore\_filters.users\] please chec…

---

## [Add custom fields to metadata with elastic agent jar](https://discuss.elastic.co/t/add-custom-fields-to-metadata-with-elastic-agent-jar/352370)

<div class="topic-metadata">

**Author:** [@Namita\_Jaokar](https://discuss.elastic.co/u/Namita_Jaokar)\
**Replies:** 0\
**Last updated:** [February 2, 2024, 7:52am UTC](https://discuss.elastic.co/t/add-custom-fields-to-metadata-with-elastic-agent-jar/352370 "2024-02-02T07:52:13Z")

</div>

Hi, I need to add custom fields in metadata of the transactions captured by the java agent jar . Is there any way I can achieve this? I read about global\_labels inclusion in elastic agent properties file, But i need to…

---

## [Kibana.yml file with server.host having integer host name issue](https://discuss.elastic.co/t/kibana-yml-file-with-server-host-having-integer-host-name-issue/351946)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 4:24am UTC](https://discuss.elastic.co/t/kibana-yml-file-with-server-host-having-integer-host-name-issue/351946 "2024-02-02T04:24:31Z")

</div>

I am getting Fatal Error with invalid host name for Kibana service because of server has host name starting with integer. Any idea why Kibana service doesnt like host name starting with integer because as per RFC 1123, …

---

## [Schedule backup using kibana](https://discuss.elastic.co/t/schedule-backup-using-kibana/352266)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 6\
**Last updated:** [February 2, 2024, 4:10am UTC](https://discuss.elastic.co/t/schedule-backup-using-kibana/352266 "2024-02-02T04:10:03Z")

</div>

Hi Team, I schedule a job on Kibana to take schedule backup. the job should be fire every day 15:00pm for that my cron expression is 0 0 15 ? \* \* but on Kibana it is showing 08:30pm

---

## [A potential bug with Filebeat script processor](https://discuss.elastic.co/t/a-potential-bug-with-filebeat-script-processor/351914)

<div class="topic-metadata">

**Author:** [@Calvin\_Li](https://discuss.elastic.co/u/Calvin_Li)\
**Replies:** 6\
**Last updated:** [February 2, 2024, 4:06am UTC](https://discuss.elastic.co/t/a-potential-bug-with-filebeat-script-processor/351914 "2024-02-02T04:06:42Z")

</div>

Hi team, thanks for your great work! I'm using filebeat 8.10.3, and seeing a potential bug with it. I'm using the script processor to do some caching & filtering of log messages. To be specific, I'm using a LRU cache to…

---

## [Kibana service giving "FATAL Error: \[config validation of \[server\].host\]: value must be a valid hostname (see RFC 1123)" error](https://discuss.elastic.co/t/kibana-service-giving-fatal-error-config-validation-of-server-host-value-must-be-a-valid-hostname-see-rfc-1123-error/351913)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 4:02am UTC](https://discuss.elastic.co/t/kibana-service-giving-fatal-error-config-validation-of-server-host-value-must-be-a-valid-hostname-see-rfc-1123-error/351913 "2024-02-02T04:02:00Z")

</div>

On the VM where we have installed Elasticsearch and Kibana service, Kibana service is giving "FATAL Error: \[config validation of \[server\].host\]: value must be a valid hostname (see RFC 1123)" error. After troubleshootin…

---

## [Webhook connector generated invalid """ json elements](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950)

<div class="topic-metadata">

**Author:** [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 2:18am UTC](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950 "2024-02-02T02:18:41Z")

</div>

Hi, I'm using the webhook connector to send some JSON data to a webhook destination whenever a rule triggers. One of the JSON fields I'm sending is multiline, but anytime I try to embed \\ns in the JSON, kibana converts…

---

## [Should I increase my amount of RAM?](https://discuss.elastic.co/t/should-i-increase-my-amount-of-ram/352214)

<div class="topic-metadata">

**Author:** [@louisdeveloper](https://discuss.elastic.co/u/louisdeveloper)\
**Replies:** 9\
**Last updated:** [February 2, 2024, 1:57am UTC](https://discuss.elastic.co/t/should-i-increase-my-amount-of-ram/352214 "2024-02-02T01:57:22Z")

</div>

I noticed that the RAM usage percentage of my nodes is quite high. Based on these logs, should I increase the amount of RAM on my servers? The master is usually the master-01 machine, but in the log it is as master-02,…

---

## [How to Azure Entra ID Groups for SAML SSO?](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340)

<div class="topic-metadata">

**Author:** [@World\_Python](https://discuss.elastic.co/u/World_Python)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 11:38pm UTC](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340 "2024-02-01T23:38:50Z")

</div>

Following these docs: Config: xpack: security: authc: realms: saml: saml1: order: 3 attributes.dn: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddr…

---

## [‏how to display the documents of an index in kibana 7.5?](https://discuss.elastic.co/t/how-to-display-the-documents-of-an-index-in-kibana-7-5/352118)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 10:59pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-of-an-index-in-kibana-7-5/352118 "2024-02-01T22:59:34Z")

</div>

‏how to list the contents and view the documents of an index in kibana 7.5, using index management or api?

---

## [Logstash Fingerprint Plugin Target Unchanged](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247)

<div class="topic-metadata">

**Author:** [@Cheese](https://discuss.elastic.co/u/Cheese)\
**Replies:** 3\
**Last updated:** [February 1, 2024, 9:44pm UTC](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247 "2024-02-01T21:44:30Z")

</div>

HI all, Needing some help with using the Fingerprint plugin. I use the fingerprint plugin to generate a SHA-1 signature using a base string and a key. My logstash config file is like so: mutate { add\_field { "si…

---

## [Logstash creates page file size that reaches its limit causing other pages to not be created](https://discuss.elastic.co/t/logstash-creates-page-file-size-that-reaches-its-limit-causing-other-pages-to-not-be-created/352200)

<div class="topic-metadata">

**Author:** [@tcapp24](https://discuss.elastic.co/u/tcapp24)\
**Replies:** 11\
**Last updated:** [February 1, 2024, 8:46pm UTC](https://discuss.elastic.co/t/logstash-creates-page-file-size-that-reaches-its-limit-causing-other-pages-to-not-be-created/352200 "2024-02-01T20:46:29Z")

</div>

We 're currently running Logstash 7.17.8 using a docker container on a Linux VM. We have run into an issue where Logstash creates page.0 which quickly fills up and reaches its queue.page\_capacity of 256mb. Once it reach…

---

## [Api calls for Kibana](https://discuss.elastic.co/t/api-calls-for-kibana/352328)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 7:45pm UTC](https://discuss.elastic.co/t/api-calls-for-kibana/352328 "2024-02-01T19:45:17Z")

</div>

Hi there, I am setting up Elk stack on a eks cluster using helm charts. In regards to the helm chart and in general. What configuration elements should be enabled to allow me to set data views with a simple api call? I…

---

## [Filebeat not sending most logs across the network](https://discuss.elastic.co/t/filebeat-not-sending-most-logs-across-the-network/351472)

<div class="topic-metadata">

**Author:** [@reshippie](https://discuss.elastic.co/u/reshippie)\
**Replies:** 34\
**Last updated:** [February 1, 2024, 7:16pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-most-logs-across-the-network/351472 "2024-02-01T19:16:01Z")

</div>

I changed the output to console and verified that filebeat is actually examining the logs and there are hundreds of lines that should be sent to Logstash. The only error messages that journalctl shows are about empty fi…

---

## [After Reindex, no more new records](https://discuss.elastic.co/t/after-reindex-no-more-new-records/352335)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 6:09pm UTC](https://discuss.elastic.co/t/after-reindex-no-more-new-records/352335 "2024-02-01T18:09:12Z")

</div>

I want to change the type of the geo field, so I reindex the current index. The reindex was successful. I have recovered all the records in the past. But no more new record are coming in. The docs.count and store.size do…

---

## [How do I store the data from an Elasticsearch store](https://discuss.elastic.co/t/how-do-i-store-the-data-from-an-elasticsearch-store/351597)

<div class="topic-metadata">

**Author:** [@susnato](https://discuss.elastic.co/u/susnato)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 6:07pm UTC](https://discuss.elastic.co/t/how-do-i-store-the-data-from-an-elasticsearch-store/351597 "2024-02-01T18:07:01Z")

</div>

(Hi, I am totally new to Elastic search, so sorry if this is very basic question.) I have an Elasticsearch store running in background using docker. I have added some files and corresponding embeddings to it and now…

---

## [JAVA APM Agent, System CPU reporting with java 8](https://discuss.elastic.co/t/java-apm-agent-system-cpu-reporting-with-java-8/352326)

<div class="topic-metadata">

**Author:** [@Yasim\_Zeballos](https://discuss.elastic.co/u/Yasim_Zeballos)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 4:07pm UTC](https://discuss.elastic.co/t/java-apm-agent-system-cpu-reporting-with-java-8/352326 "2024-02-01T16:07:27Z")

</div>

Kibana version: 7.17.X Elasticsearch version: 7.17.X APM Server version: 7.17.X jar java agent: opentelemetry-javaagent-2.0.0.jar Java version: Java 8 As image shows, only thread count is shown. Why CPU usage is…

---

## [How to segregate from which source elastic is receiving messages?](https://discuss.elastic.co/t/how-to-segregate-from-which-source-elastic-is-receiving-messages/352323)

<div class="topic-metadata">

**Author:** [@Sanjay\_Kumar2](https://discuss.elastic.co/u/Sanjay_Kumar2)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 3:53pm UTC](https://discuss.elastic.co/t/how-to-segregate-from-which-source-elastic-is-receiving-messages/352323 "2024-02-01T15:53:41Z")

</div>

As a part of ELK migration we are trying to setup our new cluster in a shared AKS cluster. Issue is, we have the flow as Filebeat -\> Ingress -\> Logstash entry -\> Logstash indexing -\> Kafka -\> Elastic. Currently as a part…

---

## [I get status: Red page when connecting to kibana](https://discuss.elastic.co/t/i-get-status-red-page-when-connecting-to-kibana/352317)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 3:26pm UTC](https://discuss.elastic.co/t/i-get-status-red-page-when-connecting-to-kibana/352317 "2024-02-01T15:26:13Z")

</div>

I get status: Red page when connecting to kibana. The elasticsearch log say that not enough master nodes discovered. The cluster have 3 nodes and only one node is up. I tried to power on the other nodes but after a whi…

---

## [Logstash Tab / Space Delimiter](https://discuss.elastic.co/t/logstash-tab-space-delimiter/352231)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 6\
**Last updated:** [February 1, 2024, 2:56pm UTC](https://discuss.elastic.co/t/logstash-tab-space-delimiter/352231 "2024-02-01T14:56:22Z")

</div>

Hi All. I am trying to ingest some IIS logs into Elastic via logtstash. They are CSVs but the separator is NOT a ,. How can I account for a space or a tab as the separator. I have multiple different kinds of files w…

---

## [Knowlegde Graphs, ELK and NEO4j](https://discuss.elastic.co/t/knowlegde-graphs-elk-and-neo4j/351686)

<div class="topic-metadata">

**Author:** [@wil93](https://discuss.elastic.co/u/wil93)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 2:47pm UTC](https://discuss.elastic.co/t/knowlegde-graphs-elk-and-neo4j/351686 "2024-02-01T14:47:48Z")

</div>

Hello, I would like to use ‘knowledge graph’ capabilities to detect and identify potential relationships and patterns in data (1). That data is currently stored in Elasticsearch indices. I would like to detect relation…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=315)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=317)
