# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=368

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 369

---

## [Ingest log in specific index](https://discuss.elastic.co/t/ingest-log-in-specific-index/347571)

<div class="topic-metadata">

**Author:** [@Nitin08bisht](https://discuss.elastic.co/u/Nitin08bisht)\
**Replies:** 2\
**Last updated:** [November 22, 2023, 6:16pm UTC](https://discuss.elastic.co/t/ingest-log-in-specific-index/347571 "2023-11-22T18:16:58Z")

</div>

Hi, I'm using ELK version 7.16.2 and I have configured Filebeat and I want to ingest log on dedicated index rather than on default filebeat index. Please help me on this. Please find the filebeat.yml file configuration…

---

## [Logstash unable to receive data from MQTT](https://discuss.elastic.co/t/logstash-unable-to-receive-data-from-mqtt/347712)

<div class="topic-metadata">

**Author:** [@Shah\_Zain](https://discuss.elastic.co/u/Shah_Zain)\
**Replies:** 6\
**Last updated:** [November 22, 2023, 6:08pm UTC](https://discuss.elastic.co/t/logstash-unable-to-receive-data-from-mqtt/347712 "2023-11-22T18:08:10Z")

</div>

Logstash unable to receive data from MQTT. Getting this from logs: //Stack: C:/Users/Shah Zain/Downloads/logstash-8.11.1-windows-x86\_64/logstash-8.11.1/vendor/bundle/jruby/3.1.0/gems/logstash-input-mqtt-0.0.2/lib/logst…

---

## [Ad-hoc data views rationale](https://discuss.elastic.co/t/ad-hoc-data-views-rationale/345355)

<div class="topic-metadata">

**Author:** [@tancredi](https://discuss.elastic.co/u/tancredi)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 6:01pm UTC](https://discuss.elastic.co/t/ad-hoc-data-views-rationale/345355 "2023-11-22T18:01:24Z")

</div>

I'm not sure about the ad-hoc data views use case. I cannot find any rationale behind it in documentation. For now I have a lot of problems as many of lens/visualisations from integrations are using them, then I cannot c…

---

## [Send logstash output to questdb](https://discuss.elastic.co/t/send-logstash-output-to-questdb/347717)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 4\
**Last updated:** [November 22, 2023, 5:57pm UTC](https://discuss.elastic.co/t/send-logstash-output-to-questdb/347717 "2023-11-22T17:57:01Z")

</div>

Hi, how can i send logstash output to questdb? which plugin suitable for this aim and compatible with questdb? which port suitable on questdb for this aim? I have if condition on output if tag = send then write to tab…

---

## [Logstash Permission Issue](https://discuss.elastic.co/t/logstash-permission-issue/347771)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 7\
**Last updated:** [November 22, 2023, 5:40pm UTC](https://discuss.elastic.co/t/logstash-permission-issue/347771 "2023-11-22T17:40:54Z")

</div>

Error Message \[2023-11-22T13:15:51,460\]\[WARN \]\[filewatch.sincedbcollection\]\[main\]\[fd97ffae0e8f2b3b8d71c9b308ee7a3feac45d9133bd3968160c580a4d2e603e\] sincedb\_write: unable to write atomically due to permissions error, fal…

---

## [How to write to the same datastream from MetricBeat and Logstash](https://discuss.elastic.co/t/how-to-write-to-the-same-datastream-from-metricbeat-and-logstash/347778)

<div class="topic-metadata">

**Author:** [@Igal\_Hanoch](https://discuss.elastic.co/u/Igal_Hanoch)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 5:26pm UTC](https://discuss.elastic.co/t/how-to-write-to-the-same-datastream-from-metricbeat-and-logstash/347778 "2023-11-22T17:26:18Z")

</div>

I'm writing metricbeat data from several computes to my elasticsearch. Some metricbeats are writing directly to ElasicSearch and some through logstash. The data from the metricbeat is written to a datastream named .ds-…

---

## [Metricbeat 8.11.1 not reporting cgroup.io.pressure for some machines](https://discuss.elastic.co/t/metricbeat-8-11-1-not-reporting-cgroup-io-pressure-for-some-machines/347777)

<div class="topic-metadata">

**Author:** [@dhairav](https://discuss.elastic.co/u/dhairav)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 5:23pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-1-not-reporting-cgroup-io-pressure-for-some-machines/347777 "2023-11-22T17:23:48Z")

</div>

We are using one of the more recent versions of Metricbeat - v8.1.1 for 2 types of instances. Cloud Instances (Ubuntu 22.04) and Bare Metal installations (Debian 11). I have observed specifically that the metrics under …

---

## [Full Screen by default, dashboard Kibana 8](https://discuss.elastic.co/t/full-screen-by-default-dashboard-kibana-8/347733)

<div class="topic-metadata">

**Author:** [@Erez\_Danieli](https://discuss.elastic.co/u/Erez_Danieli)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 4:37pm UTC](https://discuss.elastic.co/t/full-screen-by-default-dashboard-kibana-8/347733 "2023-11-22T16:37:45Z")

</div>

Hello everyone, I want to start the computer with a browser in full screen mode, I was able to do that. In addition, I would like my Kibana DASHBOARD to be in full screen mode automatically, as can be done manually by …

---

## [Index and template conditions](https://discuss.elastic.co/t/index-and-template-conditions/347763)

<div class="topic-metadata">

**Author:** [@luke.camilleri](https://discuss.elastic.co/u/luke.camilleri)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 3:16pm UTC](https://discuss.elastic.co/t/index-and-template-conditions/347763 "2023-11-22T15:16:52Z")

</div>

Hi Everyone, I am trying to configure filebeat to output to a totally different index in case a certain condition is met as shown below but also to use a different index template: - type: log enabled: true paths: …

---

## [Docker Secrets with Compose](https://discuss.elastic.co/t/docker-secrets-with-compose/347758)

<div class="topic-metadata">

**Author:** [@bremoi](https://discuss.elastic.co/u/bremoi)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 3:07pm UTC](https://discuss.elastic.co/t/docker-secrets-with-compose/347758 "2023-11-22T15:07:24Z")

</div>

Hi, I'm trying to use Docker Secrets using the official Docker Compose file. I'm able to use secrets with Elasticsearch through the "ELASTIC\_PASSWORD\_FILE" variable, but I didn't find the equivalent for "ELASTICSEARCH\_…

---

## [Grok isn't getting parsed (grok debugger is parsing it fine but it's throwing error in logstash)](https://discuss.elastic.co/t/grok-isnt-getting-parsed-grok-debugger-is-parsing-it-fine-but-its-throwing-error-in-logstash/347706)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 10\
**Last updated:** [November 22, 2023, 3:06pm UTC](https://discuss.elastic.co/t/grok-isnt-getting-parsed-grok-debugger-is-parsing-it-fine-but-its-throwing-error-in-logstash/347706 "2023-11-22T15:06:46Z")

</div>

\- "22/Nov/2023:12:21:04 +0530" 196.24.23.101 GET "GET /api/status HTTP/1.1" 191 200 439 83 - "nginx/1.23.4 (health check server\_103.225.61.177\_Pool-1\_http\_ok)" 127.0.0.1:8080 200 0.002 0.002 0.000 0.002 - pauth.mumbcms.…

---

## [Kibana not accessible after 8.11.1 update](https://discuss.elastic.co/t/kibana-not-accessible-after-8-11-1-update/347438)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 12\
**Last updated:** [November 22, 2023, 2:10pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-after-8-11-1-update/347438 "2023-11-22T14:10:19Z")

</div>

Hello All, We updated our stak to 8.11.1 and now the Kibana website is inaccessible. I receive a this page cannot be reached error. I have verified that Kibana is up and running and we updated our nodes and Logstash but…

---

## [Unable to setup the elastic cluster](https://discuss.elastic.co/t/unable-to-setup-the-elastic-cluster/347730)

<div class="topic-metadata">

**Author:** [@Balajivsn](https://discuss.elastic.co/u/Balajivsn)\
**Replies:** 3\
**Last updated:** [November 22, 2023, 1:36pm UTC](https://discuss.elastic.co/t/unable-to-setup-the-elastic-cluster/347730 "2023-11-22T13:36:17Z")

</div>

Team, i was trying to setup a elasticsearch cluster using vm's on local machine i was able to setup the configuration and started the service but i couldn't able to form the cluster as it shows #curl localhost:9200/\_…

---

## [ElasticsearchClient Java Circuit Breaker errors and retries](https://discuss.elastic.co/t/elasticsearchclient-java-circuit-breaker-errors-and-retries/347736)

<div class="topic-metadata">

**Author:** [@ewolfman](https://discuss.elastic.co/u/ewolfman)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 1:19pm UTC](https://discuss.elastic.co/t/elasticsearchclient-java-circuit-breaker-errors-and-retries/347736 "2023-11-22T13:19:14Z")

</div>

Hi, Using ElasticsearchClient (co.elastic, not RHLC), I have a bulkrequest inserting data. When it fails due to circuit breaker exceptions, I would like to implement some kind of retry. Currently I simply iterate over …

---

## [Max\_result\_window of all the results saved](https://discuss.elastic.co/t/max-result-window-of-all-the-results-saved/347734)

<div class="topic-metadata">

**Author:** [@bhumika](https://discuss.elastic.co/u/bhumika)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 12:59pm UTC](https://discuss.elastic.co/t/max-result-window-of-all-the-results-saved/347734 "2023-11-22T12:59:29Z")

</div>

{"level":"DEBUG","time":"2023-11-22 12:53:27 +0000","message":" \\u001b\[1m\\u001b\[32mUsersIndex Search (106.5ms)\\u001b\[0m {:index=\>\["users"\], :body=\>{:size=\>20000, :query=\>{:bool=\>{:must=\>}}}}"} Elasticsearch::Transport:…

---

## [Which type of Load Balancer for use with pool of fleet servers](https://discuss.elastic.co/t/which-type-of-load-balancer-for-use-with-pool-of-fleet-servers/347727)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 11:38am UTC](https://discuss.elastic.co/t/which-type-of-load-balancer-for-use-with-pool-of-fleet-servers/347727 "2023-11-22T11:38:51Z")

</div>

I am deploying a pool of fleet servers to support my agents. As is recommended i am goi g to place these behind a load balancer and to have all agents communicate via the load balancer. My initial thought is to go with…

---

## [Elasticsearch painless script l2norm are different from l2\_norm knnSearch](https://discuss.elastic.co/t/elasticsearch-painless-script-l2norm-are-different-from-l2-norm-knnsearch/347718)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 10:42am UTC](https://discuss.elastic.co/t/elasticsearch-painless-script-l2norm-are-different-from-l2-norm-knnsearch/347718 "2023-11-22T10:42:49Z")

</div>

I would like to test l2norm by this: POST /\_scripts/painless/\_execute { "script": { "source": "l2norm(params.v1, params.v2)", "params": { "v1": \[1.0, 1.0\], "v2": \[1.0, 1.0\] } } } However, it…

---

## [Does \_delete\_by\_query close the scroll context once it has completed or leave it to expire](https://discuss.elastic.co/t/does-delete-by-query-close-the-scroll-context-once-it-has-completed-or-leave-it-to-expire/347713)

<div class="topic-metadata">

**Author:** [@willbo](https://discuss.elastic.co/u/willbo)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 9:45am UTC](https://discuss.elastic.co/t/does-delete-by-query-close-the-scroll-context-once-it-has-completed-or-leave-it-to-expire/347713 "2023-11-22T09:45:08Z")

</div>

We have a spark application that needs to use \_delete\_by\_query to do some cleanup after it's finished indexing during a spark task. We're finding that this is causing us to hit the scroll context limit. Our delete reques…

---

## [How can I get the most recent value in a 'Metric'](https://discuss.elastic.co/t/how-can-i-get-the-most-recent-value-in-a-metric/347641)

<div class="topic-metadata">

**Author:** [@Negan](https://discuss.elastic.co/u/Negan)\
**Replies:** 4\
**Last updated:** [November 22, 2023, 9:28am UTC](https://discuss.elastic.co/t/how-can-i-get-the-most-recent-value-in-a-metric/347641 "2023-11-22T09:28:03Z")

</div>

Hello all! Currently trying to get the most recent value of a transactiondurationtime. I got a data table with the name of transaction, average transaction duration, recent transaction duration (which I need to have/ca…

---

## [How to link input contain to output contain](https://discuss.elastic.co/t/how-to-link-input-contain-to-output-contain/347635)

<div class="topic-metadata">

**Author:** [@Christian\_1974](https://discuss.elastic.co/u/Christian_1974)\
**Replies:** 9\
**Last updated:** [November 22, 2023, 8:36am UTC](https://discuss.elastic.co/t/how-to-link-input-contain-to-output-contain/347635 "2023-11-22T08:36:42Z")

</div>

Hi, I have a question. I have this in my input file : root@Big-Monster:/etc/logstash/conf.d# cat 00\_input.conf input { file { id =\> "TEST-Syslog" path =\> \[ "/var/log/syslog" \] } file { id =\> "TEST-C…

---

## [Data streams and Analyzers](https://discuss.elastic.co/t/data-streams-and-analyzers/347697)

<div class="topic-metadata">

**Author:** [@Mertozturkk](https://discuss.elastic.co/u/Mertozturkk)\
**Replies:** 2\
**Last updated:** [November 22, 2023, 8:06am UTC](https://discuss.elastic.co/t/data-streams-and-analyzers/347697 "2023-11-22T08:06:12Z")

</div>

When we create an index, we can add a custom analyzer to text fields. Can we do the same in a datastream?

---

## [Nodes can't find each other in a single server setup](https://discuss.elastic.co/t/nodes-cant-find-each-other-in-a-single-server-setup/347601)

<div class="topic-metadata">

**Author:** [@said1296](https://discuss.elastic.co/u/said1296)\
**Replies:** 10\
**Last updated:** [November 22, 2023, 6:45am UTC](https://discuss.elastic.co/t/nodes-cant-find-each-other-in-a-single-server-setup/347601 "2023-11-22T06:45:23Z")

</div>

Hi, I've been trying all day to run a 2-node cluster on a single server for testing purposes using Docker. But I keep getting: "log.level": "WARN", "message":"master not discovered yet: have discovered \[{node-2}{k8wUeU…

---

## [How we can use Search Query in Elastic.Clients.Elasticsearch](https://discuss.elastic.co/t/how-we-can-use-search-query-in-elastic-clients-elasticsearch/347691)

<div class="topic-metadata">

**Author:** [@Jahanzaib](https://discuss.elastic.co/u/Jahanzaib)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 5:02am UTC](https://discuss.elastic.co/t/how-we-can-use-search-query-in-elastic-clients-elasticsearch/347691 "2023-11-22T05:02:43Z")

</div>

'''var response = await \_client.SearchAsync(s =\> s .Index("indici\_timeline\_death\_patient\_vector\_ml") .From(0) .Size(10) .Query(q =\> q .Bool(b =\> b .Must(m =\> m .Term(mu =\> mu.Field(f =\> f.patientid).Value(formData…

---

## [Elasticsearch session management](https://discuss.elastic.co/t/elasticsearch-session-management/347631)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 4:18am UTC](https://discuss.elastic.co/t/elasticsearch-session-management/347631 "2023-11-22T04:18:00Z")

</div>

Hi Team, I have Elasticsearch cluster with two nodes one as master one as data node. I am using this as database cluster and integrating to application. in this case i want to manage the session idle and active timeout.…

---

## [Quarkus Connect to Elastic failed,https protocol is not supported.Connect is closed](https://discuss.elastic.co/t/quarkus-connect-to-elastic-failed-https-protocol-is-not-supported-connect-is-closed/347686)

<div class="topic-metadata">

**Author:** [@duoplay91095](https://discuss.elastic.co/u/duoplay91095)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 3:43am UTC](https://discuss.elastic.co/t/quarkus-connect-to-elastic-failed-https-protocol-is-not-supported-connect-is-closed/347686 "2023-11-22T03:43:23Z")

</div>

I want to connect company's elasticsearch. Version elasticsearch : 8.5.3 quarkus : 3.5.1 maven : 3.9.5 JAVA : 17.0.9 I clone from quarkus-quickstarts Here is my code // forTestSllPassword private String keySto…

---

## [\[new user\] Unable to start Kibana](https://discuss.elastic.co/t/new-user-unable-to-start-kibana/347566)

<div class="topic-metadata">

**Author:** [@Amry](https://discuss.elastic.co/u/Amry)\
**Replies:** 2\
**Last updated:** [November 22, 2023, 2:43am UTC](https://discuss.elastic.co/t/new-user-unable-to-start-kibana/347566 "2023-11-22T02:43:34Z")

</div>

Hi guys, I'm trying to install the ELK stack on a Windows machine. I followed the official instructions, and installing Elasticsearch as a service proceeded without a hitch, I got the password for the elastic account. T…

---

## [Filebeat v7.17.15 linux binary fails to start filebeat on x86](https://discuss.elastic.co/t/filebeat-v7-17-15-linux-binary-fails-to-start-filebeat-on-x86/347561)

<div class="topic-metadata">

**Author:** [@Pratik\_Joshi](https://discuss.elastic.co/u/Pratik_Joshi)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 11:45pm UTC](https://discuss.elastic.co/t/filebeat-v7-17-15-linux-binary-fails-to-start-filebeat-on-x86/347561 "2023-11-21T23:45:21Z")

</div>

It turns out that the beats v7.17.15 fails to start up on an x86 Linux environment whereas it comes up successfully on the x86\_64 Linux. Steps to reproduce: Pull the beats v7.17.15 from the Beats repo as per the insta…

---

## [\[Auditbeat\] Unsupported syscalls: umount for x86\_64](https://discuss.elastic.co/t/auditbeat-unsupported-syscalls-umount-for-x86-64/347655)

<div class="topic-metadata">

**Author:** [@Coolgum15](https://discuss.elastic.co/u/Coolgum15)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 10:01pm UTC](https://discuss.elastic.co/t/auditbeat-unsupported-syscalls-umount-for-x86-64/347655 "2023-11-21T22:01:50Z")

</div>

When adding new syscalls to auditbeat on a RHEL 9.2 VM, I found that only umount2 is supported. Errors:

---

## [Add Es Spark Accumulators](https://discuss.elastic.co/t/add-es-spark-accumulators/347127)

<div class="topic-metadata">

**Author:** [@glegoux](https://discuss.elastic.co/u/glegoux)\
**Replies:** 2\
**Last updated:** [November 21, 2023, 9:30pm UTC](https://discuss.elastic.co/t/add-es-spark-accumulators/347127 "2023-11-21T21:30:41Z")

</div>

Hello :wave:, I did a pull request. These metrics will be very useful to monitor a Spark application using the extension Elasticsearch for Hadoop. What do you think about it?

---

## [Error - failed version compatibility check with elasticsearch: x509: certificate signed by unknown authority"](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-x509-certificate-signed-by-unknown-authority/347664)

<div class="topic-metadata">

**Author:** [@YULEIDY\_PENAGOS\_BERM](https://discuss.elastic.co/u/YULEIDY_PENAGOS_BERM)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 7:03pm UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-x509-certificate-signed-by-unknown-authority/347664 "2023-11-21T19:03:03Z")

</div>

Buen día, Soy nueva en este tema de elasticsearch y necesito configurar mi fleet server, pero me agrega el error que se ve en imagen. Por favor, necesito de su ayuda para que me digan que debo tener en cuenta o que paso…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=367)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=369)
