# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=362

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 363

---

## [Watcher logging action - where do (which index) these logs come in?](https://discuss.elastic.co/t/watcher-logging-action-where-do-which-index-these-logs-come-in/348334)

<div class="topic-metadata">

**Author:** [@Edy\_Silva](https://discuss.elastic.co/u/Edy_Silva)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 1:58pm UTC](https://discuss.elastic.co/t/watcher-logging-action-where-do-which-index-these-logs-come-in/348334 "2023-11-30T13:58:53Z")

</div>

I have a watcher that is supposed to perform a logging action. When I execute the watch it says it went well but I can't find this log anywhere.

---

## [No logs for Elasticsearch](https://discuss.elastic.co/t/no-logs-for-elasticsearch/347732)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 12:34pm UTC](https://discuss.elastic.co/t/no-logs-for-elasticsearch/347732 "2023-11-30T12:34:47Z")

</div>

When I open the Stack monitoring page in Kibana it tells me that there are No logs for Elasticsearch and Follow these directions to set up Elasticsearch. Unfortunately the link doesn't really help me. Right at the beginn…

---

## [Elastic docs in PDF](https://discuss.elastic.co/t/elastic-docs-in-pdf/348305)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 11:58am UTC](https://discuss.elastic.co/t/elastic-docs-in-pdf/348305 "2023-11-30T11:58:32Z")

</div>

This is a very simple question but I just wanna make sure. Does Elasticsearch have it's documentation in PDF format available for download anywhere? Thanks for any help in advance! Cheers, Luka

---

## [Profile file cannot be null Logstash error](https://discuss.elastic.co/t/profile-file-cannot-be-null-logstash-error/348224)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 6\
**Last updated:** [November 30, 2023, 10:50am UTC](https://discuss.elastic.co/t/profile-file-cannot-be-null-logstash-error/348224 "2023-11-30T10:50:20Z")

</div>

Hello Community I have an issue in Logstash kinesis input plugin, when I run /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/kinesis.conf I can see logs are coming from AWS and ingested into my Elasticsear…

---

## [Unable to connect to elastic search with certificates](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-with-certificates/348325)

<div class="topic-metadata">

**Author:** [@shrikar18](https://discuss.elastic.co/u/shrikar18)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 10:48am UTC](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-with-certificates/348325 "2023-11-30T10:48:52Z")

</div>

hi everyone , iam new to elasticsearch i have Elasticsearch deployed as pod and iam trying to check the status with a curl command i used https curl --cacert /root/http\_ca.crt -u elastic:$ELASTIC\_PASSWORD protocol://…

---

## [Reg: Logstash JVM OOM](https://discuss.elastic.co/t/reg-logstash-jvm-oom/348041)

<div class="topic-metadata">

**Author:** [@Thumati](https://discuss.elastic.co/u/Thumati)\
**Replies:** 5\
**Last updated:** [November 30, 2023, 7:36am UTC](https://discuss.elastic.co/t/reg-logstash-jvm-oom/348041 "2023-11-30T07:36:46Z")

</div>

Hi Logstash version is 8.4.3 . Logstash settings are done in below way cpu - 1000m, limits - 7 gi, request - 6 gi ,JVM is 67 %. From the metrics of CPU and memory we can see the memory is not even reaching the 3.5 GI …

---

## [Plugin server cannot accept body with get request from plugin ui](https://discuss.elastic.co/t/plugin-server-cannot-accept-body-with-get-request-from-plugin-ui/347721)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [November 30, 2023, 6:45am UTC](https://discuss.elastic.co/t/plugin-server-cannot-accept-body-with-get-request-from-plugin-ui/347721 "2023-11-30T06:45:37Z")

</div>

Hi, I am developing a custom external plugin in React, on Kibana 8.8.1. When I give a GET request from plugin ui to server, with a body; the body is still always undefined, even if I validate it with the basic schema. …

---

## [Elastics/kibana coonect with IBM ace server thru the APM server](https://discuss.elastic.co/t/elastics-kibana-coonect-with-ibm-ace-server-thru-the-apm-server/348289)

<div class="topic-metadata">

**Author:** [@kasunpurnima](https://discuss.elastic.co/u/kasunpurnima)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 5:55am UTC](https://discuss.elastic.co/t/elastics-kibana-coonect-with-ibm-ace-server-thru-the-apm-server/348289 "2023-11-30T05:55:40Z")

</div>

Hi is there anyone is connect elastc with IBM aces server ?

---

## [Problem in Embedding iframe](https://discuss.elastic.co/t/problem-in-embedding-iframe/348116)

<div class="topic-metadata">

**Author:** [@Saksham\_Kawatra](https://discuss.elastic.co/u/Saksham_Kawatra)\
**Replies:** 4\
**Last updated:** [November 30, 2023, 5:09am UTC](https://discuss.elastic.co/t/problem-in-embedding-iframe/348116 "2023-11-30T05:09:00Z")

</div>

Hey everyone. I have been encountering a problem while trying to embed iframe of my dashboard into my application. Whenever i try to add credentials on the login page and press enter, the login page appears again, and …

---

## [Elasticsearch statefulset deployment failed with 8.11.1 image version](https://discuss.elastic.co/t/elasticsearch-statefulset-deployment-failed-with-8-11-1-image-version/348286)

<div class="topic-metadata">

**Author:** [@Subhajit](https://discuss.elastic.co/u/Subhajit)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 4:53am UTC](https://discuss.elastic.co/t/elasticsearch-statefulset-deployment-failed-with-8-11-1-image-version/348286 "2023-11-30T04:53:31Z")

</div>

Hello Team, currently I am facing this below error while deploying latest \[elasticsearch:8.11.1\] image with elasticsearch statefulset helm chart. 2023-11-27T17:50:15.202018883Z {"@timestamp":"2023-11-27T17:50:15.200Z",…

---

## [AWS EC2 metrics integration not getting all values](https://discuss.elastic.co/t/aws-ec2-metrics-integration-not-getting-all-values/348278)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 10:29pm UTC](https://discuss.elastic.co/t/aws-ec2-metrics-integration-not-getting-all-values/348278 "2023-11-29T22:29:17Z")

</div>

Hi, I am using Elastic 8.9.2. I'm trying to grab EC2 metrics via Elastic Agent integration (not using metricbeat for some reason). The integration is done, but for some reason, it is not getting all the values. The con…

---

## [Fuzz and stemmer](https://discuss.elastic.co/t/fuzz-and-stemmer/348277)

<div class="topic-metadata">

**Author:** [@staix](https://discuss.elastic.co/u/staix)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 9:59pm UTC](https://discuss.elastic.co/t/fuzz-and-stemmer/348277 "2023-11-29T21:59:36Z")

</div>

Hello. if there is a mistake in the word, then when using fuzz, is it possible to somehow launch a stemmer after fuzz

---

## [How to disable querying ALL fields by default](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249)

<div class="topic-metadata">

**Author:** [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Replies:** 6\
**Last updated:** [November 29, 2023, 7:47pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249 "2023-11-29T19:47:58Z")

</div>

We have some users that are killing our performance because they're not putting a field in their Discover searches...rather they are just putting a single value only so elasticsearch has to search through everything. Th…

---

## [Unable to see the Reporting option under Analytics in the Kibana Privileges](https://discuss.elastic.co/t/unable-to-see-the-reporting-option-under-analytics-in-the-kibana-privileges/348269)

<div class="topic-metadata">

**Author:** [@nmurilo](https://discuss.elastic.co/u/nmurilo)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 6:35pm UTC](https://discuss.elastic.co/t/unable-to-see-the-reporting-option-under-analytics-in-the-kibana-privileges/348269 "2023-11-29T18:35:34Z")

</div>

I'm running a cloud Elastic/Kibana with an Enterprise license. But unable to see the reporting sub-feature option under Analytics session in the kibana privileges tab. Checked all documentation, but I didn't find what …

---

## [URL template in data view now working](https://discuss.elastic.co/t/url-template-in-data-view-now-working/346773)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 4\
**Last updated:** [November 29, 2023, 5:32pm UTC](https://discuss.elastic.co/t/url-template-in-data-view-now-working/346773 "2023-11-29T17:32:22Z")

</div>

Hi All, I am getting 1 field which basically is going to showcase service now ticket no. now i want to map that field as a URL and i am trying to achieve it using URL template in that field. however, its not working at …

---

## [Metricbeat - Can't see linked indices](https://discuss.elastic.co/t/metricbeat-cant-see-linked-indices/348166)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 3:42pm UTC](https://discuss.elastic.co/t/metricbeat-cant-see-linked-indices/348166 "2023-11-29T15:42:28Z")

</div>

Hi together, after an issue with metricbeat i have to re-configure everything again. i deployed on my kuberentes cluster metricbeat-7.17.8. In Kibana i can't see any linked indices but logs tells me no error 2023-1…

---

## [Delete indices after 180 days](https://discuss.elastic.co/t/delete-indices-after-180-days/348148)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 3:25pm UTC](https://discuss.elastic.co/t/delete-indices-after-180-days/348148 "2023-11-29T15:25:11Z")

</div>

Hello, i have create new ILM policy PUT \_ilm/policy/delete-logs-after-6months { "policy": { "phases": { "delete": { "min\_age": "180d", "actions": { "delete": {} } } …

---

## [.NET Core - DefaultMappingFor\<T\> hits multiple indexes](https://discuss.elastic.co/t/net-core-defaultmappingfor-t-hits-multiple-indexes/348250)

<div class="topic-metadata">

**Author:** [@kruegeba](https://discuss.elastic.co/u/kruegeba)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 3:22pm UTC](https://discuss.elastic.co/t/net-core-defaultmappingfor-t-hits-multiple-indexes/348250 "2023-11-29T15:22:46Z")

</div>

We are using the Elastic.Clients.Elasticsearch 8.1 package in our .NET Core application. We are trying to set up the ability to use a single Elastic client, and hit different indexes based on the model type. We have the …

---

## [Fetch multiples traces with a common id](https://discuss.elastic.co/t/fetch-multiples-traces-with-a-common-id/348202)

<div class="topic-metadata">

**Author:** [@casteillet](https://discuss.elastic.co/u/casteillet)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 3:15pm UTC](https://discuss.elastic.co/t/fetch-multiples-traces-with-a-common-id/348202 "2023-11-29T15:15:58Z")

</div>

Hi, I'm new with the Elasticsearch web interface. I'm trying to display player session results on the dashboard. I have three dropdown filters, with difficulty, level selected and name of the player (actor). During a s…

---

## [Elasticsearch's Docuements count dosen't match the exact number of input log lines](https://discuss.elastic.co/t/elasticsearchs-docuements-count-dosent-match-the-exact-number-of-input-log-lines/348217)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 9\
**Last updated:** [November 29, 2023, 3:01pm UTC](https://discuss.elastic.co/t/elasticsearchs-docuements-count-dosent-match-the-exact-number-of-input-log-lines/348217 "2023-11-29T15:01:30Z")

</div>

have a log file containing 2044 lines, but after indexing into Elasticsearch using Logstash, I find only 2043 documents. I suspect that an empty line in the log file might have been skipped by Logstash during indexing. I…

---

## [ML Anomaly Detection count of Processed Records](https://discuss.elastic.co/t/ml-anomaly-detection-count-of-processed-records/348234)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 1:27pm UTC](https://discuss.elastic.co/t/ml-anomaly-detection-count-of-processed-records/348234 "2023-11-29T13:27:31Z")

</div>

Hello everyone, i deployed several anomaly detection jobs with different query\_delay parameters to evaluate which one fits best without losing documents or being to much behind real-time. What's interesting here is tha…

---

## [Compatibility: Filebeat 8.x with Elasticsearch 7.17](https://discuss.elastic.co/t/compatibility-filebeat-8-x-with-elasticsearch-7-17/348238)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 2:18pm UTC](https://discuss.elastic.co/t/compatibility-filebeat-8-x-with-elasticsearch-7-17/348238 "2023-11-29T14:18:04Z")

</div>

Dear Community, I seek guidance regarding a scenario where we aim to use a plugin developed for Filebeat version 8.10.x, which is intended to send data to Elasticsearch 7.17. Considering the potential compatibility chal…

---

## [LogStash returns an error in connection with VMWare](https://discuss.elastic.co/t/logstash-returns-an-error-in-connection-with-vmware/347340)

<div class="topic-metadata">

**Author:** [@heisenberg93](https://discuss.elastic.co/u/heisenberg93)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 2:09pm UTC](https://discuss.elastic.co/t/logstash-returns-an-error-in-connection-with-vmware/347340 "2023-11-29T14:09:14Z")

</div>

Hi, I set the forwarding configuration in a vCenter server to the port of my Elastic server where Logstash is running and set port 9300. Now my Logstash config for this looks like this: input { tcp { …

---

## [LDAP Elasticsearch](https://discuss.elastic.co/t/ldap-elasticsearch/348205)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 12:22pm UTC](https://discuss.elastic.co/t/ldap-elasticsearch/348205 "2023-11-29T12:22:33Z")

</div>

Hello , I want to know how to connect Elasticsearch to an external LDAP, and if I am in a cluster that contains multiple nodes, do I need to configure LDAP on all Elasticsearch nodes or just one of them (and wich one :…

---

## [Updating entities indexed by Hibernate Search](https://discuss.elastic.co/t/updating-entities-indexed-by-hibernate-search/348207)

<div class="topic-metadata">

**Author:** [@Muhammad\_namjas](https://discuss.elastic.co/u/Muhammad_namjas)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 9:25am UTC](https://discuss.elastic.co/t/updating-entities-indexed-by-hibernate-search/348207 "2023-11-29T09:25:38Z")

</div>

I created a new entity connected to Hibernate Elastic Search and indexed it. Upon retrieving the indexed data, I noticed that updating the entity using the student ID resulted in deleting the existing data and re-inserti…

---

## [Json filter not parsing AWS WAF Logs](https://discuss.elastic.co/t/json-filter-not-parsing-aws-waf-logs/347639)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 5\
**Last updated:** [November 29, 2023, 11:45am UTC](https://discuss.elastic.co/t/json-filter-not-parsing-aws-waf-logs/347639 "2023-11-29T11:45:34Z")

</div>

Hello Community, I having issue with parsing AWS Waf logs using Logstash filter plugin, here is the breakdown I'm pulling logs from AWS using kinesis input and the I'm filtering the log message using :- filter { jso…

---

## [Kibana custom branding](https://discuss.elastic.co/t/kibana-custom-branding/348194)

<div class="topic-metadata">

**Author:** [@Rutuja\_More](https://discuss.elastic.co/u/Rutuja_More)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 11:35am UTC](https://discuss.elastic.co/t/kibana-custom-branding/348194 "2023-11-29T11:35:45Z")

</div>

Does the custom branding feature of the elastic enterprise version , allow us to change the "Welcome to elastic" part of kibana login page to something like " Welcome to xyz"??? If yes then how?????

---

## [FSCrawler, custom Tika parser](https://discuss.elastic.co/t/fscrawler-custom-tika-parser/348219)

<div class="topic-metadata">

**Author:** [@Eldar\_Madyarov](https://discuss.elastic.co/u/Eldar_Madyarov)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/fscrawler-custom-tika-parser/348219 "2023-11-29T11:06:17Z")

</div>

I have created a custom Tika Parser, added a new type to custom-mimetypes.xml, built a jar. Then a put this jar to FSCrawler lib directory. But still FSCrawler doesn't see my Parser and using EmptyParser... What did I …

---

## [Search requests still get rejected at the same number of queued requests despite having increased \`queue\_size\`](https://discuss.elastic.co/t/search-requests-still-get-rejected-at-the-same-number-of-queued-requests-despite-having-increased-queue-size/346716)

<div class="topic-metadata">

**Author:** [@JvSPV](https://discuss.elastic.co/u/JvSPV)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 10:43am UTC](https://discuss.elastic.co/t/search-requests-still-get-rejected-at-the-same-number-of-queued-requests-despite-having-increased-queue-size/346716 "2023-11-29T10:43:06Z")

</div>

We have a cluster of five nodes. For a lot of processing, our system sends search requests to Elasticsearch 7.17 in bursts, which fill up its queue\_size and Elasticsearch will start rejecting requests. However, our syst…

---

## [Elastic-agent AWS cloudtrail integration fails](https://discuss.elastic.co/t/elastic-agent-aws-cloudtrail-integration-fails/348161)

<div class="topic-metadata">

**Author:** [@Merdesz](https://discuss.elastic.co/u/Merdesz)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 9:35am UTC](https://discuss.elastic.co/t/elastic-agent-aws-cloudtrail-integration-fails/348161 "2023-11-29T09:35:43Z")

</div>

Trying to set up Elastic-agent with the AWS cloudtrail integration, but it always fails to connect: \[elastic\_agent.filebeat\]\[error\] Input 'aws-s3' failed with: failed to initialize s3 poller: failed to get AWS region fo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=361)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=363)
