# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=350

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 351

---

## [Access Elasticsearch Data as a Remote Oracle Database](https://discuss.elastic.co/t/access-elasticsearch-data-as-a-remote-oracle-database/349350)

<div class="topic-metadata">

**Author:** [@onr1onr1](https://discuss.elastic.co/u/onr1onr1)\
**Replies:** 11\
**Last updated:** [December 14, 2023, 2:38pm UTC](https://discuss.elastic.co/t/access-elasticsearch-data-as-a-remote-oracle-database/349350 "2023-12-14T14:38:03Z")

</div>

We want to set up a dblink from the Oracle database to eleastic search and pull information, but we get the following error in the dblink. We could not find a source on this site, so we did it by following the steps in …

---

## [Not able to read the data from external json file in logstash config](https://discuss.elastic.co/t/not-able-to-read-the-data-from-external-json-file-in-logstash-config/349257)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 10\
**Last updated:** [December 14, 2023, 1:26pm UTC](https://discuss.elastic.co/t/not-able-to-read-the-data-from-external-json-file-in-logstash-config/349257 "2023-12-14T13:26:32Z")

</div>

I'm trying to search the host value from current event and looking for same value in json file. If Json block has the host value I'm just converting the block into struct value and inserting as a new column in index. ou…

---

## [Advanced Watcher to send alert of condition has been met for more than 1 hour](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247)

<div class="topic-metadata">

**Author:** [@ChrisKelly](https://discuss.elastic.co/u/ChrisKelly)\
**Replies:** 9\
**Last updated:** [December 14, 2023, 1:08pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247 "2023-12-14T13:08:02Z")

</div>

I want to create an advanced Watcher that will only send an alert email out if my conditions have been met more over an hour. Essentially, I am monitoring specific servers and watching if their CPU exceeds 50%. If it go…

---

## [Is there any recommended ratio between the number of master, data, coordinator and ingestion nodes?](https://discuss.elastic.co/t/is-there-any-recommended-ratio-between-the-number-of-master-data-coordinator-and-ingestion-nodes/349270)

<div class="topic-metadata">

**Author:** [@calin](https://discuss.elastic.co/u/calin)\
**Replies:** 13\
**Last updated:** [December 14, 2023, 1:05pm UTC](https://discuss.elastic.co/t/is-there-any-recommended-ratio-between-the-number-of-master-data-coordinator-and-ingestion-nodes/349270 "2023-12-14T13:05:23Z")

</div>

Currently working with equal number of master, data and coordinator nodes (10). Need to add some ingestion nodes. They all have 2 CPU/node, master and coordinator have 4 GB each, data has 16 GB. I haven't done the sizi…

---

## [How can we ingest fields dynamically in integation package](https://discuss.elastic.co/t/how-can-we-ingest-fields-dynamically-in-integation-package/349338)

<div class="topic-metadata">

**Author:** [@Niraj\_Rathod](https://discuss.elastic.co/u/Niraj_Rathod)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 9:05am UTC](https://discuss.elastic.co/t/how-can-we-ingest-fields-dynamically-in-integation-package/349338 "2023-12-14T09:05:13Z")

</div>

We are trying to fetch MongoDB Atlas logs. In MongoDB Atlas Activity Logs there is an object named “attr” under which there are many dynamic fields that change depending on logs, these fields can't be mentioned in “field…

---

## [Decode xml file](https://discuss.elastic.co/t/decode-xml-file/349292)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 12:51pm UTC](https://discuss.elastic.co/t/decode-xml-file/349292 "2023-12-14T12:51:16Z")

</div>

Hi, I have a file with the following information as example: \<sDPCallDataRecord\> \<accountAdjustment\> \<information1\>aloha\</information1\> \<information2\>ola\</information2\> \</accoun…

---

## [Elasticsearch Upgrade issue](https://discuss.elastic.co/t/elasticsearch-upgrade-issue/349159)

<div class="topic-metadata">

**Author:** [@Ifteakhar\_ali](https://discuss.elastic.co/u/Ifteakhar_ali)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 2:23pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-issue/349159 "2023-12-12T14:23:43Z")

</div>

Hello Team, I am facing issue while upgrading elasticsearch from elasticsearch-6.8.11-1.noarch to elasticsearch-7.10.2-aarch64.rpm. Kindly advise Current ES Version : elasticsearch-6.8.11-1.noarch Current OS Version :…

---

## [How to build filebeat with x-pack](https://discuss.elastic.co/t/how-to-build-filebeat-with-x-pack/349371)

<div class="topic-metadata">

**Author:** [@evanzhang87](https://discuss.elastic.co/u/evanzhang87)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-to-build-filebeat-with-x-pack/349371 "2023-12-14T12:31:36Z")

</div>

hello, I want to build filebeat without without makefile, just use go build, but I want to use some modules from x-pack such as awss3 input, how can I build ?

---

## [Decode\_json\_fields not](https://discuss.elastic.co/t/decode-json-fields-not/349367)

<div class="topic-metadata">

**Author:** [@Areeb\_Siddiqui](https://discuss.elastic.co/u/Areeb_Siddiqui)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 12:10pm UTC](https://discuss.elastic.co/t/decode-json-fields-not/349367 "2023-12-14T12:10:24Z")

</div>

I am using filebeat on kubernetes. My filebeat.yaml looks like this: filebeat.autodiscover: providers: - type: kubernetes node: ${NODE\_NAME} templates: - condition: equals: …

---

## [Filebeat: Utilizing Google Pub/Sub to Read Logs from Google Cloud Storage – Equivalent to SQS in AWS](https://discuss.elastic.co/t/filebeat-utilizing-google-pub-sub-to-read-logs-from-google-cloud-storage-equivalent-to-sqs-in-aws/349361)

<div class="topic-metadata">

**Author:** [@b2ron](https://discuss.elastic.co/u/b2ron)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 11:42am UTC](https://discuss.elastic.co/t/filebeat-utilizing-google-pub-sub-to-read-logs-from-google-cloud-storage-equivalent-to-sqs-in-aws/349361 "2023-12-14T11:42:57Z")

</div>

I have applications that can only write to either AWS S3 or Google Cloud Storage. Every hour, these applications generate a large number of small log files. Previously, these logs were written to AWS S3 with notification…

---

## [Ingest error with logstash](https://discuss.elastic.co/t/ingest-error-with-logstash/349195)

<div class="topic-metadata">

**Author:** [@hollo](https://discuss.elastic.co/u/hollo)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 11:39am UTC](https://discuss.elastic.co/t/ingest-error-with-logstash/349195 "2023-12-14T11:39:19Z")

</div>

Hi. I've created a filebeat -\> logstash -\> elastic flow for iptables logs. Filebeat uses the default iptables module. Logstash has minimal config (beat input, elastic output, no filter). The Logstash pipeline comes f…

---

## [Failed to reload inputs: 1 error: Error creating runner from config: log\_group\_arn, log\_group\_name and log\_group\_name\_prefix config parametercannot all be empty accessing config](https://discuss.elastic.co/t/failed-to-reload-inputs-1-error-error-creating-runner-from-config-log-group-arn-log-group-name-and-log-group-name-prefix-config-parametercannot-all-be-empty-accessing-config/349353)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 11:14am UTC](https://discuss.elastic.co/t/failed-to-reload-inputs-1-error-error-creating-runner-from-config-log-group-arn-log-group-name-and-log-group-name-prefix-config-parametercannot-all-be-empty-accessing-config/349353 "2023-12-14T11:14:21Z")

</div>

Hi Team, I was trying to integrate AWS cloudwatch and collect logs from specific log groups. I have configured below options Role ARN Default AWS Region Log Group ARN Log Group Name But I am facing below …

---

## [Filebeat & index patterns mapping issue](https://discuss.elastic.co/t/filebeat-index-patterns-mapping-issue/348162)

<div class="topic-metadata">

**Author:** [@Satsan](https://discuss.elastic.co/u/Satsan)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 11:02am UTC](https://discuss.elastic.co/t/filebeat-index-patterns-mapping-issue/348162 "2023-12-14T11:02:17Z")

</div>

The data I recently entered in the Filebeat YAML file is not appearing in the index patterns. However, the old data is still visible, and I can successfully map it in the index patterns. Filebeat on win machine. Filebe…

---

## [How to combine 2 indexes in 1 graph](https://discuss.elastic.co/t/how-to-combine-2-indexes-in-1-graph/349335)

<div class="topic-metadata">

**Author:** [@remco\_zwaan](https://discuss.elastic.co/u/remco_zwaan)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 10:22am UTC](https://discuss.elastic.co/t/how-to-combine-2-indexes-in-1-graph/349335 "2023-12-14T10:22:55Z")

</div>

0 We have 2 indexes called lodging\_index and price\_index. The relation is lodgings has many prices. In the price\_index there is a field called lodging\_id. We use this indexes in our api for frontend purpose. First call …

---

## [Unavailable\_shards\_exception](https://discuss.elastic.co/t/unavailable-shards-exception/349343)

<div class="topic-metadata">

**Author:** [@Vittorio\_Morellini](https://discuss.elastic.co/u/Vittorio_Morellini)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 9:34am UTC](https://discuss.elastic.co/t/unavailable-shards-exception/349343 "2023-12-14T09:34:06Z")

</div>

I have a problem since 2 days on my production inde4x on Elasticsearch. Every night I re-create the index by deleteing it and re-creating with a reindex command from a source index. Now it is happening this error and t…

---

## [Create custom plugin to route](https://discuss.elastic.co/t/create-custom-plugin-to-route/349342)

<div class="topic-metadata">

**Author:** [@tung\_duong](https://discuss.elastic.co/u/tung_duong)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 9:33am UTC](https://discuss.elastic.co/t/create-custom-plugin-to-route/349342 "2023-12-14T09:33:14Z")

</div>

\-1 I am new to Elasticsearch. I currently need to design a plugin with the task of navigating my use of Elasticsearch. Specifically: I already have semantic search models, which can be used as an API, with output be…

---

## [Composite aggregation pagination](https://discuss.elastic.co/t/composite-aggregation-pagination/349340)

<div class="topic-metadata">

**Author:** [@Thishon](https://discuss.elastic.co/u/Thishon)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 9:28am UTC](https://discuss.elastic.co/t/composite-aggregation-pagination/349340 "2023-12-14T09:28:36Z")

</div>

I am using Elasticsearch and i want to show results by pagination so i choosed composite method. but i couldnt sort the result by outer source buckets.

---

## [When 2 of 3 masters die, how to restore the cluster?](https://discuss.elastic.co/t/when-2-of-3-masters-die-how-to-restore-the-cluster/349324)

<div class="topic-metadata">

**Author:** [@ycice](https://discuss.elastic.co/u/ycice)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 8:58am UTC](https://discuss.elastic.co/t/when-2-of-3-masters-die-how-to-restore-the-cluster/349324 "2023-12-14T08:58:24Z")

</div>

Hi, i am using ES version 7.17.0 My cluster consists of 3 master-eligible 2 data + ingest 2 Coordinating 1 kibana and they are running on AWS EC2 as docker container. 1 EC2 has 1 container And i am testing availab…

---

## [Continuous transformation is not update](https://discuss.elastic.co/t/continuous-transformation-is-not-update/349212)

<div class="topic-metadata">

**Author:** [@Zosmex](https://discuss.elastic.co/u/Zosmex)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 8:34am UTC](https://discuss.elastic.co/t/continuous-transformation-is-not-update/349212 "2023-12-14T08:34:29Z")

</div>

I created a pivot continuous transformation to automatically count the data in each location. Each document has an 'updated\_at' field which is a timestamp in epoch second format when each document was last modified. Aft…

---

## [Tenable Vulnerability Integration not producing Data Stream](https://discuss.elastic.co/t/tenable-vulnerability-integration-not-producing-data-stream/349332)

<div class="topic-metadata">

**Author:** [@longansoju](https://discuss.elastic.co/u/longansoju)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 7:54am UTC](https://discuss.elastic.co/t/tenable-vulnerability-integration-not-producing-data-stream/349332 "2023-12-14T07:54:38Z")

</div>

I have a elastic fleet cluster set up and I've configured one of my agents to use the Tenable Vulnerability Management Integration. However, under Fleet \> Data Streams, there is no Tenable Data Stream being generated. M…

---

## [One filebeat to more IPs anad ports per appliaction](https://discuss.elastic.co/t/one-filebeat-to-more-ips-anad-ports-per-appliaction/349327)

<div class="topic-metadata">

**Author:** [@ROVIS\_EU](https://discuss.elastic.co/u/ROVIS_EU)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 6:41am UTC](https://discuss.elastic.co/t/one-filebeat-to-more-ips-anad-ports-per-appliaction/349327 "2023-12-14T06:41:03Z")

</div>

Hello, excuse me but isn't time for some changes? I watched some threads here and on another sites a many people ask for more different target IPs or ports, for example: we have hundreds servers with JBoss, on each of …

---

## [The Persistent Volume Claim (PVC) persists even after scaling in the Logstash deployment](https://discuss.elastic.co/t/the-persistent-volume-claim-pvc-persists-even-after-scaling-in-the-logstash-deployment/349323)

<div class="topic-metadata">

**Author:** [@Vignesh\_M](https://discuss.elastic.co/u/Vignesh_M)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 5:57am UTC](https://discuss.elastic.co/t/the-persistent-volume-claim-pvc-persists-even-after-scaling-in-the-logstash-deployment/349323 "2023-12-14T05:57:32Z")

</div>

Hi All, We are using the elastic/logstash Helm chart to deploy Logstash (StatefulSet) with persistent volume enabled in one of our Kubernetes clusters. While attempting to downscale the Logstash pod count, we observed t…

---

## [Cloudwatch input plugin configuration details for fetching AWS/ECS metrics](https://discuss.elastic.co/t/cloudwatch-input-plugin-configuration-details-for-fetching-aws-ecs-metrics/349321)

<div class="topic-metadata">

**Author:** [@mittal\_rawal1](https://discuss.elastic.co/u/mittal_rawal1)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 5:39am UTC](https://discuss.elastic.co/t/cloudwatch-input-plugin-configuration-details-for-fetching-aws-ecs-metrics/349321 "2023-12-14T05:39:30Z")

</div>

input { cloudwatch { namespace =\> "AWS/ECS" period =\> 6000 interval =\> 6000000 metrics =\> \["Average", "Minimum", "Maximum", "Sum", "Sample Count","CPUUtilization"\] filters =\> { "ClusterName" =\> "microservices" "S…

---

## [Unable to login using elastic](https://discuss.elastic.co/t/unable-to-login-using-elastic/349304)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 5:17am UTC](https://discuss.elastic.co/t/unable-to-login-using-elastic/349304 "2023-12-14T05:17:40Z")

</div>

Hi, I have upgraded elastic 6.8 to 7.17. and i have taken the .security-6 file backup as .security-6-reindexed. but. while performing upgrade to 8.x.x version. nodes are showing the following error java.lang.IllegalS…

---

## [Error connecting to package registry](https://discuss.elastic.co/t/error-connecting-to-package-registry/349299)

<div class="topic-metadata">

**Author:** [@A\_Niu](https://discuss.elastic.co/u/A_Niu)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 1:17am UTC](https://discuss.elastic.co/t/error-connecting-to-package-registry/349299 "2023-12-14T01:17:04Z")

</div>

My Kibana is running behind corporate proxy, with curl, epr.elastic.co is reachable, but with Kibana service, I got below error, and added signer certificates into /etc/default/kibana NODE\_EXTRA\_CA\_CERTS="/etc/kibana/ce…

---

## [Files too big for Sentinel plugin](https://discuss.elastic.co/t/files-too-big-for-sentinel-plugin/348530)

<div class="topic-metadata">

**Author:** [@Joseph\_Leiber](https://discuss.elastic.co/u/Joseph_Leiber)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 11:41pm UTC](https://discuss.elastic.co/t/files-too-big-for-sentinel-plugin/348530 "2023-12-13T23:41:01Z")

</div>

Hi Logstash Experts - This is my first time dealing with Logstash, so I'm not quite sure why the logs are being formatted like this, whether this is expected/normal, or how to handle them. I'm hitting an issue with log…

---

## [Help in resetting filebeat registry to reread in log files](https://discuss.elastic.co/t/help-in-resetting-filebeat-registry-to-reread-in-log-files/349216)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 3\
**Last updated:** [December 13, 2023, 10:10pm UTC](https://discuss.elastic.co/t/help-in-resetting-filebeat-registry-to-reread-in-log-files/349216 "2023-12-13T22:10:50Z")

</div>

Hello, does anyone know how to reset the filebeat registry so I can reread in existing log files. This is for testing purposes... This is for filebeat version 8.10.4. I tried deleting the files in /var/lib/filebeat/r…

---

## [There is a way to set the time of the day when the index rollover will happen?](https://discuss.elastic.co/t/there-is-a-way-to-set-the-time-of-the-day-when-the-index-rollover-will-happen/348915)

<div class="topic-metadata">

**Author:** [@abiliocastro](https://discuss.elastic.co/u/abiliocastro)\
**Replies:** 8\
**Last updated:** [December 13, 2023, 9:50pm UTC](https://discuss.elastic.co/t/there-is-a-way-to-set-the-time-of-the-day-when-the-index-rollover-will-happen/348915 "2023-12-13T21:50:32Z")

</div>

I have an index template like the following: { "index": { "lifecycle": { "name": "indexname\_ilm\_policy", "rollover\_alias": "indexname" }, "number\_of\_replicas": "2", "refresh\_interval": "60s…

---

## [How to know the Acknowledge of message on logstash](https://discuss.elastic.co/t/how-to-know-the-acknowledge-of-message-on-logstash/349225)

<div class="topic-metadata">

**Author:** [@pradeep.kumar](https://discuss.elastic.co/u/pradeep.kumar)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 8:06pm UTC](https://discuss.elastic.co/t/how-to-know-the-acknowledge-of-message-on-logstash/349225 "2023-12-13T20:06:50Z")

</div>

Hi Team, we want to know whether the messages in the queue are acknowledged or not. We use a persistent queue on the logstash. Please let us know is there any way to get the status of it.

---

## [Elasticsearch server crashing with new version release](https://discuss.elastic.co/t/elasticsearch-server-crashing-with-new-version-release/349274)

<div class="topic-metadata">

**Author:** [@R7ST](https://discuss.elastic.co/u/R7ST)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 6:22pm UTC](https://discuss.elastic.co/t/elasticsearch-server-crashing-with-new-version-release/349274 "2023-12-13T18:22:49Z")

</div>

I have two ubuntu 22.04 servers with elasticsearch (two separate installations) and this is the second time both servers goes down at the same time. The same error message appears in both logs (below) The error occurs …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=349)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=351)
