# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=328

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 329

---

## [Using Filebeat Modules with Logstash and Differentiating Indices in Elasticsearch](https://discuss.elastic.co/t/using-filebeat-modules-with-logstash-and-differentiating-indices-in-elasticsearch/351438)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 4\
**Last updated:** [January 19, 2024, 2:21pm UTC](https://discuss.elastic.co/t/using-filebeat-modules-with-logstash-and-differentiating-indices-in-elasticsearch/351438 "2024-01-19T14:21:26Z")

</div>

Hi, I am currently using the Apache module in Filebeat to process my Apache logs. My setup involves sending these logs to Logstash and then to Elasticsearch. I understand from the documentation (Working with Filebeat M…

---

## [Logstash input/output plugin SSL configuration error](https://discuss.elastic.co/t/logstash-input-output-plugin-ssl-configuration-error/351447)

<div class="topic-metadata">

**Author:** [@matus.vlcek](https://discuss.elastic.co/u/matus.vlcek)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 1:35pm UTC](https://discuss.elastic.co/t/logstash-input-output-plugin-ssl-configuration-error/351447 "2024-01-19T13:35:25Z")

</div>

Hi guys, I've tried to configure new default approach for logstash to logstash communication using logstash input, output plugins. It works fine without SSL, but I wasn't able to get SSL to work. It outputs this error o…

---

## [Elastic Agent support RHEL 6](https://discuss.elastic.co/t/elastic-agent-support-rhel-6/351372)

<div class="topic-metadata">

**Author:** [@sajmeister](https://discuss.elastic.co/u/sajmeister)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 12:33pm UTC](https://discuss.elastic.co/t/elastic-agent-support-rhel-6/351372 "2024-01-19T12:33:55Z")

</div>

Hiya, We are using Elastic Agent version 8.10.2 and can see it works on RHEL 7 but not on RHEL 6. The Support Matrix also confirms that. We then tried an older version of the Elastic Agent v7.17 on RHEL 6 and that als…

---

## [Timeout Bulk indexing with python client for even low number of documents](https://discuss.elastic.co/t/timeout-bulk-indexing-with-python-client-for-even-low-number-of-documents/351411)

<div class="topic-metadata">

**Author:** [@Rushi\_Goswami](https://discuss.elastic.co/u/Rushi_Goswami)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 11:35am UTC](https://discuss.elastic.co/t/timeout-bulk-indexing-with-python-client-for-even-low-number-of-documents/351411 "2024-01-19T11:35:51Z")

</div>

I have platinum ELK on Azure with Kibana, I have setup 2 ML inference pipelines with ELSER for 2 different indices. Then I have started indexing for both of the indices with ml inference pipeline. But indexing is slowe…

---

## [Querying an alias throws off scoring completely?](https://discuss.elastic.co/t/querying-an-alias-throws-off-scoring-completely/351423)

<div class="topic-metadata">

**Author:** [@pudo](https://discuss.elastic.co/u/pudo)\
**Replies:** 6\
**Last updated:** [January 19, 2024, 9:20am UTC](https://discuss.elastic.co/t/querying-an-alias-throws-off-scoring-completely/351423 "2024-01-19T09:20:10Z")

</div>

Hey all! I’m seeing some really weird behaviour around index aliases, maybe I’m doing something conceptually dumb. We have two indexes of very different size (example: 4mn docs in entities-a and 2(!) docs in entities-b …

---

## [Painless sort not working in call cases on 8.12.0?](https://discuss.elastic.co/t/painless-sort-not-working-in-call-cases-on-8-12-0/351414)

<div class="topic-metadata">

**Author:** [@ilgrosso](https://discuss.elastic.co/u/ilgrosso)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 7:51am UTC](https://discuss.elastic.co/t/painless-sort-not-working-in-call-cases-on-8-12-0/351414 "2024-01-19T07:51:14Z")

</div>

The following is working as expected up to 8.11.4: "sort": \[ { "\_script": { "order": "asc", "script": { "lang": "painless", …

---

## [Logstash cannot read new lines that are coming from .NET error exception msg](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340)

<div class="topic-metadata">

**Author:** [@theo003](https://discuss.elastic.co/u/theo003)\
**Replies:** 3\
**Last updated:** [January 19, 2024, 8:33am UTC](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340 "2024-01-19T08:33:55Z")

</div>

Hello, Our system is throwing some error exceptions in the logs with the following format: |17 01 2024 08:22:10,614| |ERROR| CreateSession API... File: "File\_name" Line: 290System.InvalidOperationException: "Error\_msg"…

---

## [Buffer overflow issue Flunetd not able to push logs to elasticsearch cluster](https://discuss.elastic.co/t/buffer-overflow-issue-flunetd-not-able-to-push-logs-to-elasticsearch-cluster/351418)

<div class="topic-metadata">

**Author:** [@Music\_World](https://discuss.elastic.co/u/Music_World)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 8:04am UTC](https://discuss.elastic.co/t/buffer-overflow-issue-flunetd-not-able-to-push-logs-to-elasticsearch-cluster/351418 "2024-01-19T08:04:30Z")

</div>

Hi @all I am using elasticsearch version: 7.16.2 and fluentd version: 1.14.4 on aws eks cluster and it's throwing bufferoverflow error like failed to flush the buffer. retry\_times=0 next\_retry\_time=2024-01-19 07:43:43…

---

## [Cannot get 'Index' variant: current variant is 'Update'](https://discuss.elastic.co/t/cannot-get-index-variant-current-variant-is-update/351417)

<div class="topic-metadata">

**Author:** [@jiyong\_qin](https://discuss.elastic.co/u/jiyong_qin)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 8:03am UTC](https://discuss.elastic.co/t/cannot-get-index-variant-current-variant-is-update/351417 "2024-01-19T08:03:16Z")

</div>

hi @all when i use flink(1.14.4) write data to es 8.6.2 use BulkOperation ,then something is wrong. Cannot get 'Index' variant: current variant is 'Update' and Missing required property 'BulkRequest.operations'. I don'…

---

## [How to display the maximum number of shards allowed per node?](https://discuss.elastic.co/t/how-to-display-the-maximum-number-of-shards-allowed-per-node/351308)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 4\
**Last updated:** [January 19, 2024, 7:54am UTC](https://discuss.elastic.co/t/how-to-display-the-maximum-number-of-shards-allowed-per-node/351308 "2024-01-19T07:54:34Z")

</div>

how to display the maximum number of shards allowed per node?

---

## [How does elastic agent configure filebeat](https://discuss.elastic.co/t/how-does-elastic-agent-configure-filebeat/351187)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 9\
**Last updated:** [January 19, 2024, 7:17am UTC](https://discuss.elastic.co/t/how-does-elastic-agent-configure-filebeat/351187 "2024-01-19T07:17:22Z")

</div>

Hi, I've installed an agent and added a custom log integration to the policy. It's working but I'm wondering if there's some documentation which tells me: How does the agent configure filebeat? I searched in the filesy…

---

## [Help on Elastic Search query](https://discuss.elastic.co/t/help-on-elastic-search-query/351409)

<div class="topic-metadata">

**Author:** [@hmulky](https://discuss.elastic.co/u/hmulky)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 6:56am UTC](https://discuss.elastic.co/t/help-on-elastic-search-query/351409 "2024-01-19T06:56:23Z")

</div>

Hello, I think i may need some help here. I have a record in EFK as below orchestrator.resource.name : "akr1r3\*" and (log.file.path : /var/log/abc.log) and (message : "Signing with P-Origination Id \\\\\[F92DAEC5-F1C9-4F8…

---

## [Kibana Area Chart -Split chart twice i.e per release, per brand on X axis](https://discuss.elastic.co/t/kibana-area-chart-split-chart-twice-i-e-per-release-per-brand-on-x-axis/351347)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [January 18, 2024, 10:04am UTC](https://discuss.elastic.co/t/kibana-area-chart-split-chart-twice-i-e-per-release-per-brand-on-x-axis/351347 "2024-01-18T10:04:30Z")

</div>

Hello All, I've a requirement and mostly I'm aware this won't be possible , but for second opinion need feedback if this can be done in some way. I am using normal area chart and problem is can SPLIT THE CHART TWICE , …

---

## [How to filter based on a pair of matching geopoints within a radius?](https://discuss.elastic.co/t/how-to-filter-based-on-a-pair-of-matching-geopoints-within-a-radius/350265)

<div class="topic-metadata">

**Author:** [@mike\_mivance](https://discuss.elastic.co/u/mike_mivance)\
**Replies:** 5\
**Last updated:** [January 18, 2024, 8:31pm UTC](https://discuss.elastic.co/t/how-to-filter-based-on-a-pair-of-matching-geopoints-within-a-radius/350265 "2024-01-18T20:31:34Z")

</div>

Hi All, I am trying to match based on two geopoints (origin and destination) within a radius so that if both the query geopoints are within their respective radiuses, they will be included in the results. For instance, i…

---

## [Convert string LLA to Geo-Point](https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 3\
**Last updated:** [January 18, 2024, 7:47pm UTC](https://discuss.elastic.co/t/convert-string-lla-to-geo-point/351376 "2024-01-18T19:47:14Z")

</div>

I have a string field that is in Latitude, Longitude, Altitude. In the pipeline, I am taking the location in x, y, z in ECEF coordinates and converting to LLA: - pipeline.id: entity-state-processing config.str…

---

## [I'm having a problem in Kibana every time I open a space in elastic](https://discuss.elastic.co/t/im-having-a-problem-in-kibana-every-time-i-open-a-space-in-elastic/351374)

<div class="topic-metadata">

**Author:** [@Leomar.V](https://discuss.elastic.co/u/Leomar.V)\
**Replies:** 0\
**Last updated:** [January 18, 2024, 6:16pm UTC](https://discuss.elastic.co/t/im-having-a-problem-in-kibana-every-time-i-open-a-space-in-elastic/351374 "2024-01-18T18:16:30Z")

</div>

---

## [Codec multiline grok pattern for Logstash](https://discuss.elastic.co/t/codec-multiline-grok-pattern-for-logstash/351334)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 6\
**Last updated:** [January 18, 2024, 5:55pm UTC](https://discuss.elastic.co/t/codec-multiline-grok-pattern-for-logstash/351334 "2024-01-18T17:55:10Z")

</div>

Hey, so i am parsing multiline logs using Logstash. I need consider each log line will start with {"offset": currently it is printing into single line that's why it is coming in one message only We are not using file…

---

## [Is it possible to mount a part of memory as a tmpfs filesystem and store the vector files there?](https://discuss.elastic.co/t/is-it-possible-to-mount-a-part-of-memory-as-a-tmpfs-filesystem-and-store-the-vector-files-there/351369)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 0\
**Last updated:** [January 18, 2024, 4:23pm UTC](https://discuss.elastic.co/t/is-it-possible-to-mount-a-part-of-memory-as-a-tmpfs-filesystem-and-store-the-vector-files-there/351369 "2024-01-18T16:23:43Z")

</div>

Hi all, I have been struggling for a while to keep an Elasticsearch cluster performant for vectors search, while indexing new data. I am researching different strategies on how to keep the index up-to-date, while being …

---

## [Logstash.input.imap error SSL](https://discuss.elastic.co/t/logstash-input-imap-error-ssl/349772)

<div class="topic-metadata">

**Author:** [@drissm](https://discuss.elastic.co/u/drissm)\
**Replies:** 3\
**Last updated:** [January 18, 2024, 3:51pm UTC](https://discuss.elastic.co/t/logstash-input-imap-error-ssl/349772 "2024-01-18T15:51:22Z")

</div>

Hello, i have a logstash v8.11.3 with input.imap plugin v3.2.1. Here is my pipeline and the ssl error i have input { imap { host =\> "myhost" password =\> "mypassword" port =\> 993 user =\> "myemail@mydoma…

---

## [Calculating Windows User Session Duration](https://discuss.elastic.co/t/calculating-windows-user-session-duration/351362)

<div class="topic-metadata">

**Author:** [@pcharles1](https://discuss.elastic.co/u/pcharles1)\
**Replies:** 0\
**Last updated:** [January 18, 2024, 3:05pm UTC](https://discuss.elastic.co/t/calculating-windows-user-session-duration/351362 "2024-01-18T15:05:28Z")

</div>

I need to calculate Windows user session duration times using winlogbeat event codes like 4624 (login) and 4634 (logout) & create a visualization to display each user's duration. I'm using a heatmap visualization. I foun…

---

## [Generate multiple alerts from elastic query](https://discuss.elastic.co/t/generate-multiple-alerts-from-elastic-query/351113)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 10\
**Last updated:** [January 18, 2024, 3:03pm UTC](https://discuss.elastic.co/t/generate-multiple-alerts-from-elastic-query/351113 "2024-01-18T15:03:19Z")

</div>

I want to generate an alert whenever a pod is restarted in kubernetes. I am planning to use kubernetes.container.status.restarts to identify whether pods are restarted or not. I would like to have a single elasticsear…

---

## [Arabic decode](https://discuss.elastic.co/t/arabic-decode/351027)

<div class="topic-metadata">

**Author:** [@abdullah144](https://discuss.elastic.co/u/abdullah144)\
**Replies:** 3\
**Last updated:** [January 18, 2024, 2:44pm UTC](https://discuss.elastic.co/t/arabic-decode/351027 "2024-01-18T14:44:37Z")

</div>

Hi , when I log some data in Arabic is came like this on Kibana : "&#1588;ــريك" how can I let the Kibana convert it to Arabic direct? Thanks,

---

## [Drop event in procesor result in no records](https://discuss.elastic.co/t/drop-event-in-procesor-result-in-no-records/351352)

<div class="topic-metadata">

**Author:** [@Ruben\_Bahntje](https://discuss.elastic.co/u/Ruben_Bahntje)\
**Replies:** 2\
**Last updated:** [January 18, 2024, 1:29pm UTC](https://discuss.elastic.co/t/drop-event-in-procesor-result-in-no-records/351352 "2024-01-18T13:29:07Z")

</div>

I am using Fleet to configure agent policies for windows servers. I configure to get several security events 4624, 4625, 4771 and drop events when LogonType = 3 I ve configure procesor like this: drop\_event: when: …

---

## [Automating Sophos Central Agent Policies Integration via Python](https://discuss.elastic.co/t/automating-sophos-central-agent-policies-integration-via-python/351349)

<div class="topic-metadata">

**Author:** [@bl4ck-m33k4t](https://discuss.elastic.co/u/bl4ck-m33k4t)\
**Replies:** 1\
**Last updated:** [January 18, 2024, 1:21pm UTC](https://discuss.elastic.co/t/automating-sophos-central-agent-policies-integration-via-python/351349 "2024-01-18T13:21:58Z")

</div>

Hi everyone, I'm currently working on automating the deployment of Sophos Central Agent policies using Python. My goal is to create policies and add integrations programmatically. However, I'm facing challenges with the…

---

## [Legacy index templates deprecation](https://discuss.elastic.co/t/legacy-index-templates-deprecation/351356)

<div class="topic-metadata">

**Author:** [@cisupport-zkb](https://discuss.elastic.co/u/cisupport-zkb)\
**Replies:** 1\
**Last updated:** [January 18, 2024, 12:40pm UTC](https://discuss.elastic.co/t/legacy-index-templates-deprecation/351356 "2024-01-18T12:40:43Z")

</div>

Hi everyone, I have a question about legacy index templates. I know that are deprecated since Elasticsearch v7.9, but in what future Elasticsearch version will be definitively removed, so that only composable resp. comp…

---

## [While configuring the elastic search cluster with two elk nodes. i am getting the error](https://discuss.elastic.co/t/while-configuring-the-elastic-search-cluster-with-two-elk-nodes-i-am-getting-the-error/349947)

<div class="topic-metadata">

**Author:** [@Jaladanki\_Varaprasad](https://discuss.elastic.co/u/Jaladanki_Varaprasad)\
**Replies:** 1\
**Last updated:** [January 18, 2024, 11:22am UTC](https://discuss.elastic.co/t/while-configuring-the-elastic-search-cluster-with-two-elk-nodes-i-am-getting-the-error/349947 "2024-01-18T11:22:08Z")

</div>

mote\_cluster\_client, data, data\_cold\] \[2023-12-26T11:21:03,744\]\[ERROR\]\[o.e.b.Elasticsearch \] \[elk-node-2\] fatal exception while booting Elasticsearch org.elasticsearch.ElasticsearchSecurityException: failed to loa…

---

## [Merge Data Streams from Integrations](https://discuss.elastic.co/t/merge-data-streams-from-integrations/351346)

<div class="topic-metadata">

**Author:** [@longansoju](https://discuss.elastic.co/u/longansoju)\
**Replies:** 0\
**Last updated:** [January 18, 2024, 10:02am UTC](https://discuss.elastic.co/t/merge-data-streams-from-integrations/351346 "2024-01-18T10:02:13Z")

</div>

My setup is consists Fleet Management together with Tenable Integration. The issue with this is Tenable's Integration comes with multiple data streams. The two that I'm focusing on are asset and vulnerability. I wan…

---

## [How to set a specific bin folder for Elasticsearch 7.14](https://discuss.elastic.co/t/how-to-set-a-specific-bin-folder-for-elasticsearch-7-14/351344)

<div class="topic-metadata">

**Author:** [@sbottura](https://discuss.elastic.co/u/sbottura)\
**Replies:** 0\
**Last updated:** [January 18, 2024, 9:51am UTC](https://discuss.elastic.co/t/how-to-set-a-specific-bin-folder-for-elasticsearch-7-14/351344 "2024-01-18T09:51:44Z")

</div>

Hello, I have two different instances of elasticsearch on the same disk on a virtual machine and I am currently using elasticsearch 7.14.1. I just discovered, however, that when elasticsearch 7.14.1 is running, it uses …

---

## [Duplicate Documents Generated by Kibana for ICMP Monitor Down and Recovery Statuses](https://discuss.elastic.co/t/duplicate-documents-generated-by-kibana-for-icmp-monitor-down-and-recovery-statuses/351258)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 2\
**Last updated:** [January 18, 2024, 9:42am UTC](https://discuss.elastic.co/t/duplicate-documents-generated-by-kibana-for-icmp-monitor-down-and-recovery-statuses/351258 "2024-01-18T09:42:31Z")

</div>

Hello, I've been experiencing an issue where Kibana's monitoring is generating duplicate documents for both 'down' and 'recovery' statuses across all hosts. Below, I have provided the configuration of the rule and addit…

---

## [Elastic enterprise search - BadGatewayError \[502\] 'The instance rejected the connection.'](https://discuss.elastic.co/t/elastic-enterprise-search-badgatewayerror-502-the-instance-rejected-the-connection/351341)

<div class="topic-metadata">

**Author:** [@MarieD](https://discuss.elastic.co/u/MarieD)\
**Replies:** 0\
**Last updated:** [January 18, 2024, 9:37am UTC](https://discuss.elastic.co/t/elastic-enterprise-search-badgatewayerror-502-the-instance-rejected-the-connection/351341 "2024-01-18T09:37:07Z")

</div>

Hi everyone, We've been using Elasticsearch through App Search. We've been getting the following error from time to time (~3% of our requests): elastic\_enterprise\_search.exceptions.BadGatewayError: \[502\] {'ok': False,…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=327)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=329)
