# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=344

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 345

---

## [Elasticsearch not creating index](https://discuss.elastic.co/t/elasticsearch-not-creating-index/350016)

<div class="topic-metadata">

**Author:** [@bas\_kos](https://discuss.elastic.co/u/bas_kos)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 11:06am UTC](https://discuss.elastic.co/t/elasticsearch-not-creating-index/350016 "2023-12-27T11:06:38Z")

</div>

I have elasticsearch, kibana and logstash installed on docker-compose. docker-compose.yml: version: "3.8" volumes: certs: driver: local esdata01: driver: local kibanadata: driver: local metricbeatd…

---

## [Elk audit logs](https://discuss.elastic.co/t/elk-audit-logs/349924)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 2\
**Last updated:** [December 27, 2023, 5:58am UTC](https://discuss.elastic.co/t/elk-audit-logs/349924 "2023-12-27T05:58:51Z")

</div>

Hey! I'm using on-prem ELK v8.1 I want to check the audit logs of ELK. which user did what activity, what rules are disabled by users, and what modifications are done by them. Currently, I'm using the basic version wi…

---

## [Dropdown select element not effect to essql while select value](https://discuss.elastic.co/t/dropdown-select-element-not-effect-to-essql-while-select-value/349995)

<div class="topic-metadata">

**Author:** [@Dy\_Vanrith](https://discuss.elastic.co/u/Dy_Vanrith)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 4:42am UTC](https://discuss.elastic.co/t/dropdown-select-element-not-effect-to-essql-while-select-value/349995 "2023-12-27T04:42:27Z")

</div>

My expression dropdown element esdocs index="2023.12.22" fields="startAdminDate" | dropdownControl valueColumn="startAdminDate" filterColumn="startAdminDate" filterGroup="VTM" | render table element filters group="VT…

---

## [Logstash V fileBeat](https://discuss.elastic.co/t/logstash-v-filebeat/349979)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 5:09pm UTC](https://discuss.elastic.co/t/logstash-v-filebeat/349979 "2023-12-26T17:09:27Z")

</div>

Hello, We have c# applications , running without docker. we want to write them to Elasticsearch. I have managed to run logstash (right now as exe) and make it write to csv files. next, i will change it to write to e…

---

## [ELK Stack: Logstash shows that it's receiving log entries from Filebeat, but Elasticsearch is not creating my index](https://discuss.elastic.co/t/elk-stack-logstash-shows-that-its-receiving-log-entries-from-filebeat-but-elasticsearch-is-not-creating-my-index/349826)

<div class="topic-metadata">

**Author:** [@BDeveloper](https://discuss.elastic.co/u/BDeveloper)\
**Replies:** 8\
**Last updated:** [December 26, 2023, 4:40pm UTC](https://discuss.elastic.co/t/elk-stack-logstash-shows-that-its-receiving-log-entries-from-filebeat-but-elasticsearch-is-not-creating-my-index/349826 "2023-12-26T16:40:57Z")

</div>

I am new to the ELK stack and I wanted to try and test it out to see if I wanted to use it. I have elasticsearch, kibana, and logstash installed on one virtual machine and I have filebeat and nginx installed on another v…

---

## [Elastic Agent successfully connect to Fleet Server but Elasticsearch did not receive data! bug](https://discuss.elastic.co/t/elastic-agent-successfully-connect-to-fleet-server-but-elasticsearch-did-not-receive-data-bug/349887)

<div class="topic-metadata">

**Author:** [@helloworld404](https://discuss.elastic.co/u/helloworld404)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 4:24pm UTC](https://discuss.elastic.co/t/elastic-agent-successfully-connect-to-fleet-server-but-elasticsearch-did-not-receive-data-bug/349887 "2023-12-26T16:24:54Z")

</div>

OS lsb\_release -a No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 22.04 LTS Release: 22.04 Codename: jammy install Elastic wget -qO - https://artifacts.elastic.co/GPG-KEY-elastic…

---

## [Logstash not sending data to Elasticsearch](https://discuss.elastic.co/t/logstash-not-sending-data-to-elasticsearch/349736)

<div class="topic-metadata">

**Author:** [@gtartjr](https://discuss.elastic.co/u/gtartjr)\
**Replies:** 5\
**Last updated:** [December 26, 2023, 4:06pm UTC](https://discuss.elastic.co/t/logstash-not-sending-data-to-elasticsearch/349736 "2023-12-26T16:06:06Z")

</div>

I am unable to get Logstash to read data and send to Elasticsearch index. My Elastcistac is 8.11.2, under a Docker for Windows platform. I have 2 jsonl formatted files that I need to index into Elasticsearch by a unique …

---

## [Display the last 100k documents](https://discuss.elastic.co/t/display-the-last-100k-documents/349961)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 3\
**Last updated:** [December 26, 2023, 3:58pm UTC](https://discuss.elastic.co/t/display-the-last-100k-documents/349961 "2023-12-26T15:58:24Z")

</div>

I want to display the last 100k documents for all indices. Each index with the last 100k

---

## [I want to search only the last data entered. That is, the search is in only 100,000 per index you have, I want to search, these data are loaded into the cache and are searched only ](https://discuss.elastic.co/t/i-want-to-search-only-the-last-data-entered-that-is-the-search-is-in-only-100-000-per-index-you-have-i-want-to-search-these-data-are-loaded-into-the-cache-and-are-searched-only/349970)

<div class="topic-metadata">

**Author:** [@deep111](https://discuss.elastic.co/u/deep111)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 3:56pm UTC](https://discuss.elastic.co/t/i-want-to-search-only-the-last-data-entered-that-is-the-search-is-in-only-100-000-per-index-you-have-i-want-to-search-these-data-are-loaded-into-the-cache-and-are-searched-only/349970 "2023-12-26T15:56:26Z")

</div>

Json format

---

## [Index Life Cycle Management](https://discuss.elastic.co/t/index-life-cycle-management/349964)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [December 26, 2023, 3:10pm UTC](https://discuss.elastic.co/t/index-life-cycle-management/349964 "2023-12-26T15:10:24Z")

</div>

HI Team, Can Index rollover happened on the basis of field value of attribute instead of calendar date. Thanks, Debasis

---

## [MSK to Elasticksearch using logstash](https://discuss.elastic.co/t/msk-to-elasticksearch-using-logstash/349945)

<div class="topic-metadata">

**Author:** [@Gersi\_Tafili](https://discuss.elastic.co/u/Gersi_Tafili)\
**Replies:** 4\
**Last updated:** [December 26, 2023, 1:14pm UTC](https://discuss.elastic.co/t/msk-to-elasticksearch-using-logstash/349945 "2023-12-26T13:14:29Z")

</div>

I have create MSK in AWS also Elastic search cluster hostes in AWS. I am trying to read data from topic in MSK and send this data to elasticsearch index. input { kafka { bootstrap\_servers =\> "x:9096" topics =\>…

---

## [Elastic Agent](https://discuss.elastic.co/t/elastic-agent/349925)

<div class="topic-metadata">

**Author:** [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-agent/349925 "2023-12-26T12:55:16Z")

</div>

Dear team, In my current organization have at least 5000 employees. So, when I use the ELK for security information and event management, is it ok for all employees? Thanks and regards,

---

## [Can not create a custom normalizer using char filter \[html\_strip\]](https://discuss.elastic.co/t/can-not-create-a-custom-normalizer-using-char-filter-html-strip/349939)

<div class="topic-metadata">

**Author:** [@voaix](https://discuss.elastic.co/u/voaix)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:45pm UTC](https://discuss.elastic.co/t/can-not-create-a-custom-normalizer-using-char-filter-html-strip/349939 "2023-12-26T12:45:20Z")

</div>

Hello, I try to save the custom normalizer as part of composite template. Receiving below error: illegal\_argument\_exception', 'Custom normalizer \[lower\_normalizer\] may not use char filter \[html\_strip\] Normalizer is de…

---

## [Select option from drop downs and update,delete the documents accordingly in kibana](https://discuss.elastic.co/t/select-option-from-drop-downs-and-update-delete-the-documents-accordingly-in-kibana/349931)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:43pm UTC](https://discuss.elastic.co/t/select-option-from-drop-downs-and-update-delete-the-documents-accordingly-in-kibana/349931 "2023-12-26T12:43:33Z")

</div>

Hello All, I've a requirement in kibana where in I want to select options from drop down(This is possible using options, I am aware of this). Now this is where I'm struggling: After selecting multiple options from drop…

---

## [Using must query in filter section of DSl elastic](https://discuss.elastic.co/t/using-must-query-in-filter-section-of-dsl-elastic/349953)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:20pm UTC](https://discuss.elastic.co/t/using-must-query-in-filter-section-of-dsl-elastic/349953 "2023-12-26T12:20:25Z")

</div>

GET rds\_database-\*/\_search { "\_source": \["failure\_error\_text"\], "query": { "bool": { "filter": \[ { "must":\[ { "term":{ "status.keyword":"F" …

---

## [Using toJson in big search template](https://discuss.elastic.co/t/using-tojson-in-big-search-template/349951)

<div class="topic-metadata">

**Author:** [@bertie](https://discuss.elastic.co/u/bertie)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 11:51am UTC](https://discuss.elastic.co/t/using-tojson-in-big-search-template/349951 "2023-12-26T11:51:18Z")

</div>

I cannot figure out how I should use the toJson when prototyping templates in the kibana dev console. If I simply use it like others mustache functions like the following example Kibana simply classifies it as a "bad str…

---

## [Duplicate messages with logstash and log4net RollingFileAppender](https://discuss.elastic.co/t/duplicate-messages-with-logstash-and-log4net-rollingfileappender/349932)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 10:53am UTC](https://discuss.elastic.co/t/duplicate-messages-with-logstash-and-log4net-rollingfileappender/349932 "2023-12-26T10:53:46Z")

</div>

Hello, My app writes events using log4net with rolling file appender. I get messages duplicated in the file gerenated by logstash. I found the issue mentioned also here However, I am not sure about the solution. Cou…

---

## [Sort is incorrect](https://discuss.elastic.co/t/sort-is-incorrect/349906)

<div class="topic-metadata">

**Author:** [@Binh\_Phan\_Thanh](https://discuss.elastic.co/u/Binh_Phan_Thanh)\
**Replies:** 12\
**Last updated:** [December 26, 2023, 10:45am UTC](https://discuss.elastic.co/t/sort-is-incorrect/349906 "2023-12-26T10:45:04Z")

</div>

My mapping: { "my\_index": { "mappings": { "properties": { "attributesRecommend": { "type": "text", "fields": { "keyword": { "type": "keyword", …

---

## [Add another one sorting to lift 3 docs to positions 3,4,5](https://discuss.elastic.co/t/add-another-one-sorting-to-lift-3-docs-to-positions-3-4-5/349918)

<div class="topic-metadata">

**Author:** [@sahkdevel](https://discuss.elastic.co/u/sahkdevel)\
**Replies:** 2\
**Last updated:** [December 26, 2023, 8:49am UTC](https://discuss.elastic.co/t/add-another-one-sorting-to-lift-3-docs-to-positions-3-4-5/349918 "2023-12-26T08:49:48Z")

</div>

I have a query with several sortings. Here is the sorting part: "sort": \[ "isHistorical", "\_score", { "\_script": { "type": "number", "script": { …

---

## [Lucene : Regex & group by](https://discuss.elastic.co/t/lucene-regex-group-by/349929)

<div class="topic-metadata">

**Author:** [@Jagadeesh\_Venkatesh](https://discuss.elastic.co/u/Jagadeesh_Venkatesh)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 7:59am UTC](https://discuss.elastic.co/t/lucene-regex-group-by/349929 "2023-12-26T07:59:56Z")

</div>

write a regular expression for this " Generating JWT token for user : psi-sci-3 " using Lucene in Kibana search to extract the keyword "psi-sci-3" and group by count by "psi-sci-3"?

---

## [Elasticsearch Java Client Aggregation Exception - all shards failed](https://discuss.elastic.co/t/elasticsearch-java-client-aggregation-exception-all-shards-failed/349860)

<div class="topic-metadata">

**Author:** [@bharath.krishn2](https://discuss.elastic.co/u/bharath.krishn2)\
**Replies:** 7\
**Last updated:** [December 26, 2023, 7:10am UTC](https://discuss.elastic.co/t/elasticsearch-java-client-aggregation-exception-all-shards-failed/349860 "2023-12-26T07:10:28Z")

</div>

Hi, I'm trying to create an aggregation on Elasticsearch through Java client using this below link But I'm getting the exception: co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/search\] failed: \[…

---

## [Logstash with log4net](https://discuss.elastic.co/t/logstash-with-log4net/349919)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 11:39pm UTC](https://discuss.elastic.co/t/logstash-with-log4net/349919 "2023-12-25T23:39:20Z")

</div>

Hello, we have c# app (many microservices), running without docker. for now, All the microservices use log4net to log to file. we want to write those logs to log4net. the question is how to do it ? Question 1: w…

---

## [I can not login elastic](https://discuss.elastic.co/t/i-can-not-login-elastic/348450)

<div class="topic-metadata">

**Author:** [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Replies:** 32\
**Last updated:** [December 25, 2023, 8:10pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450 "2023-12-25T20:10:10Z")

</div>

hi my disk space is full and I can not login to elastic web how can I clear cache disk plz help me

---

## [Logstash terminating pipelines error "const\_missing, block in JDBC"](https://discuss.elastic.co/t/logstash-terminating-pipelines-error-const-missing-block-in-jdbc/349715)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 3\
**Last updated:** [December 25, 2023, 1:10pm UTC](https://discuss.elastic.co/t/logstash-terminating-pipelines-error-const-missing-block-in-jdbc/349715 "2023-12-25T13:10:21Z")

</div>

Hello, I have a problem when running logstash with multiple pipelines (around 70). Logstash will always terminate some of them if i run more than 30 concurrently 1- First error : \[ERROR\]\[logstash.javapipeline \]\[bkge…

---

## [Error with http-plugin output Encountered non-2xx HTTP code 400](https://discuss.elastic.co/t/error-with-http-plugin-output-encountered-non-2xx-http-code-400/348215)

<div class="topic-metadata">

**Author:** [@bilal\_adoui](https://discuss.elastic.co/u/bilal_adoui)\
**Replies:** 3\
**Last updated:** [December 25, 2023, 10:27am UTC](https://discuss.elastic.co/t/error-with-http-plugin-output-encountered-non-2xx-http-code-400/348215 "2023-12-25T10:27:04Z")

</div>

Hi, I am trying to send a notification from Logstash to our Teams channel, using HTTP plugin however I am getting : \[HTTP Output Failure\] Encountered non-2xx HTTP code 400 {:response\_code=\>400 and this is my output c…

---

## [Elasticsearch Aggregations Pagination](https://discuss.elastic.co/t/elasticsearch-aggregations-pagination/349915)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 9:54am UTC](https://discuss.elastic.co/t/elasticsearch-aggregations-pagination/349915 "2023-12-25T09:54:21Z")

</div>

Dear Elasticsearch Team, I hope this message finds you well. I am currently working with an alert index in Elasticsearch, which contains information such as "device-ref" and "alert type." My goal is to retrieve the late…

---

## [Enabling kibana Audit logs to monitor login/logout activities](https://discuss.elastic.co/t/enabling-kibana-audit-logs-to-monitor-login-logout-activities/349760)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [December 25, 2023, 8:59am UTC](https://discuss.elastic.co/t/enabling-kibana-audit-logs-to-monitor-login-logout-activities/349760 "2023-12-25T08:59:20Z")

</div>

Hello team, We are enabling kibana Audit logs to monitor login/logout activities. But we need only authentication type logs and event.category: database or web we need to drop. We have added below config in kibana.yml …

---

## [Logstash pipelines not visible in stack monitoring](https://discuss.elastic.co/t/logstash-pipelines-not-visible-in-stack-monitoring/349894)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 4\
**Last updated:** [December 25, 2023, 6:56am UTC](https://discuss.elastic.co/t/logstash-pipelines-not-visible-in-stack-monitoring/349894 "2023-12-25T06:56:04Z")

</div>

I'm unable to monitor pipelines through kibana ==\> So i tried to pick elasticsearch, then ingest pipelines and this error popped up upon trying to install elasticsearch integration ==\> How can i monitor pipelin…

---

## [Elastic agent not sending logs to elastic search](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-to-elastic-search/349909)

<div class="topic-metadata">

**Author:** [@ramapdev](https://discuss.elastic.co/u/ramapdev)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 5:18am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-to-elastic-search/349909 "2023-12-25T05:18:48Z")

</div>

HI All, i am able to launch the elastic agent and fleet successfully \[ec2-user@ip-172-31-56-159 testlogs\]$ sudo /usr/bin/elastic-agent status ┌─ fleet │ └─ status: (HEALTHY) Connected └─ elastic-agent └─ status: (…

---

## [My grok Pattern is not working using Filebeat](https://discuss.elastic.co/t/my-grok-pattern-is-not-working-using-filebeat/349897)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Kholil](https://discuss.elastic.co/u/Ibrahim_Kholil)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 6:40pm UTC](https://discuss.elastic.co/t/my-grok-pattern-is-not-working-using-filebeat/349897 "2023-12-24T18:40:12Z")

</div>

\*\* ###################### Filebeat Configuration Example #########################\*\* # This file is an example configuration file highlighting only the most common # options. The filebeat.reference.yml file from the sa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=343)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=345)
