# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=373

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 374

---

## [Please provide us the runbook for upgrade plan from ELK stack 7.9.3 to 8.10](https://discuss.elastic.co/t/please-provide-us-the-runbook-for-upgrade-plan-from-elk-stack-7-9-3-to-8-10/346713)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 4\
**Last updated:** [November 9, 2023, 1:05pm UTC](https://discuss.elastic.co/t/please-provide-us-the-runbook-for-upgrade-plan-from-elk-stack-7-9-3-to-8-10/346713 "2023-11-09T13:05:18Z")

</div>

we are planning to upgrade ELK stack from 7.9.3 to 8.1 ( current ) but we could see the official page says that we must upgrade it to 7.17. Could you please provide the runbook since it's a huge cluster ( filebeat receiv…

---

## [Log4j.proporties](https://discuss.elastic.co/t/log4j-proporties/347279)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 7:49am UTC](https://discuss.elastic.co/t/log4j-proporties/347279 "2023-11-16T07:49:47Z")

</div>

How to update log4j.proporties files Contant using API method.

---

## [Uptime app is missing](https://discuss.elastic.co/t/uptime-app-is-missing/347139)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 3\
**Last updated:** [November 16, 2023, 7:20am UTC](https://discuss.elastic.co/t/uptime-app-is-missing/347139 "2023-11-16T07:20:34Z")

</div>

Hi I cannot find the Uptime app. I am ingesting heartbeat data in heartbeat -\> logstash -\> logstash -\> elasticsearch setup. I am indexing the data into a datastream called heartbeats.http.\*. Now I want to see the data i…

---

## [Why logstash service not work correctly but it is running in the foreground](https://discuss.elastic.co/t/why-logstash-service-not-work-correctly-but-it-is-running-in-the-foreground/347211)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 17\
**Last updated:** [November 16, 2023, 5:38am UTC](https://discuss.elastic.co/t/why-logstash-service-not-work-correctly-but-it-is-running-in-the-foreground/347211 "2023-11-16T05:38:59Z")

</div>

Hi. When I am running logstash in the foreground it is working excellent with follow command /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/pipeline1.conf --path.settings /etc/logstash/ but when I am running …

---

## [How do I set an index-level metadata field using the Elasticsearch-DSL Python client?](https://discuss.elastic.co/t/how-do-i-set-an-index-level-metadata-field-using-the-elasticsearch-dsl-python-client/347142)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 3\
**Last updated:** [November 16, 2023, 5:05am UTC](https://discuss.elastic.co/t/how-do-i-set-an-index-level-metadata-field-using-the-elasticsearch-dsl-python-client/347142 "2023-11-16T05:05:41Z")

</div>

I am using the Elasticsearch-DSL Python client to create a new index that stores objects called IndexedDocument that are subclasses of elasticsearch\_dsl.Document. index\_name = "my-index" index = elasticsearch\_dsl.Index(…

---

## [No SAN option available in verbose mode of elasticsearch-certutil](https://discuss.elastic.co/t/no-san-option-available-in-verbose-mode-of-elasticsearch-certutil/347115)

<div class="topic-metadata">

**Author:** [@carel0x53](https://discuss.elastic.co/u/carel0x53)\
**Replies:** 1\
**Last updated:** [November 16, 2023, 3:35am UTC](https://discuss.elastic.co/t/no-san-option-available-in-verbose-mode-of-elasticsearch-certutil/347115 "2023-11-16T03:35:58Z")

</div>

I was setting up the SSL certificates for Kibana, and when I tried to generate a enrollment token, using this command: (as root) /usr/share/elasticsearch# bin/elasticsearch-create-enrollment-token -s kibana I got the f…

---

## [Filebeat hangs without printing any log](https://discuss.elastic.co/t/filebeat-hangs-without-printing-any-log/347266)

<div class="topic-metadata">

**Author:** [@Chen\_Wei](https://discuss.elastic.co/u/Chen_Wei)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 3:23am UTC](https://discuss.elastic.co/t/filebeat-hangs-without-printing-any-log/347266 "2023-11-16T03:23:55Z")

</div>

We are using filebeat to filter and push postfix logs to logstash, we have installed a customized postfix module and enabled it in filebeat. # Module: postfix - module: postfix mail: enabled: true # Set cust…

---

## [How can i solve 404 error?](https://discuss.elastic.co/t/how-can-i-solve-404-error/347261)

<div class="topic-metadata">

**Author:** [@shan7](https://discuss.elastic.co/u/shan7)\
**Replies:** 1\
**Last updated:** [November 15, 2023, 11:24pm UTC](https://discuss.elastic.co/t/how-can-i-solve-404-error/347261 "2023-11-15T23:24:11Z")

</div>

{ "error": { "root\_cause": \[ { "type": "index\_not\_found\_exception", "reason": "no such index \[sources\]", "resource.type": "index\_or\_alias", "resource.id": "sources", "index\_uuid": "na", "index": "sources" } \], …

---

## [Bulk Upload Csv Files Into Standalone ELK Stack In Docker](https://discuss.elastic.co/t/bulk-upload-csv-files-into-standalone-elk-stack-in-docker/344317)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 9\
**Last updated:** [November 15, 2023, 11:21pm UTC](https://discuss.elastic.co/t/bulk-upload-csv-files-into-standalone-elk-stack-in-docker/344317 "2023-11-15T23:21:24Z")

</div>

I have a bunch of csv files I wish to ingest into Elasticsearch/Kibana that are localhost in a docker containers. Wish to seek advice on how I can best ingest these csv files that have 100,000+ rows and be represented a…

---

## [Connect Apm-server to Elasticsearch via HTTPS](https://discuss.elastic.co/t/connect-apm-server-to-elasticsearch-via-https/347250)

<div class="topic-metadata">

**Author:** [@jlugo](https://discuss.elastic.co/u/jlugo)\
**Replies:** 1\
**Last updated:** [November 15, 2023, 10:35pm UTC](https://discuss.elastic.co/t/connect-apm-server-to-elasticsearch-via-https/347250 "2023-11-15T22:35:10Z")

</div>

So I've been struggling to get this working. I installed Kibana with Elasticsearch via auto configuration on Linux. Kibana connects to Elasticsearch no problem via https. However, I can't get apm-server to connect to e…

---

## [AWS EKS metric beat missing cluster information](https://discuss.elastic.co/t/aws-eks-metric-beat-missing-cluster-information/347258)

<div class="topic-metadata">

**Author:** [@Steve\_Foster](https://discuss.elastic.co/u/Steve_Foster)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 9:22pm UTC](https://discuss.elastic.co/t/aws-eks-metric-beat-missing-cluster-information/347258 "2023-11-15T21:22:19Z")

</div>

We have a number of EKS clusters and can see that we are missing some metadata related to the cluster is missing in metrics The items that we are missing are orchestrator.cluster.id orchestrator.cluster.name these ar…

---

## [Logstash deletes source files and not creating index - date parsing issue](https://discuss.elastic.co/t/logstash-deletes-source-files-and-not-creating-index-date-parsing-issue/347243)

<div class="topic-metadata">

**Author:** [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Replies:** 10\
**Last updated:** [November 15, 2023, 8:54pm UTC](https://discuss.elastic.co/t/logstash-deletes-source-files-and-not-creating-index-date-parsing-issue/347243 "2023-11-15T20:54:21Z")

</div>

I am using Elastic and logstash 8.11 running in docker. When logstash starts it deletes log files from the source directory but nothing is passed to elastic - no index is created. I am not sure why logstash is deleting…

---

## [Unable to upgrade Fleet Server past 8.5.3](https://discuss.elastic.co/t/unable-to-upgrade-fleet-server-past-8-5-3/344941)

<div class="topic-metadata">

**Author:** [@Vestyn](https://discuss.elastic.co/u/Vestyn)\
**Replies:** 16\
**Last updated:** [November 15, 2023, 8:43pm UTC](https://discuss.elastic.co/t/unable-to-upgrade-fleet-server-past-8-5-3/344941 "2023-11-15T20:43:49Z")

</div>

I've been stuck trying to upgrade our Fleet Server past version 8.5.3. Every time I push the update manually (via curl) or through Kibana, I get some random errors (see below) and it reverts back to 8.5.3. For clarificat…

---

## [Elastic agent 8.4.3 - No policy response available](https://discuss.elastic.co/t/elastic-agent-8-4-3-no-policy-response-available/345303)

<div class="topic-metadata">

**Author:** [@elastic\_fan](https://discuss.elastic.co/u/elastic_fan)\
**Replies:** 8\
**Last updated:** [November 15, 2023, 8:23pm UTC](https://discuss.elastic.co/t/elastic-agent-8-4-3-no-policy-response-available/345303 "2023-11-15T20:23:18Z")

</div>

Hello, The Elastic UI displays the following error "No policy response available" Status output: ./elastic-agent status Status: FAILED Message: app endpoint-security--8.4.3-3a97d14d: Missed two check-ins Applica…

---

## [Does ES reindex a shard that's been moved to another node?](https://discuss.elastic.co/t/does-es-reindex-a-shard-thats-been-moved-to-another-node/346819)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 13\
**Last updated:** [November 15, 2023, 7:58pm UTC](https://discuss.elastic.co/t/does-es-reindex-a-shard-thats-been-moved-to-another-node/346819 "2023-11-15T19:58:11Z")

</div>

I have noticed that the document indexing rate for a new data node stays higher than all other existing data nodes for few days after it's been introduced into the cluster. Is this expected?

---

## [Index Polygons and MultiPolygons with logstash](https://discuss.elastic.co/t/index-polygons-and-multipolygons-with-logstash/347235)

<div class="topic-metadata">

**Author:** [@Henri\_L](https://discuss.elastic.co/u/Henri_L)\
**Replies:** 2\
**Last updated:** [November 15, 2023, 6:48pm UTC](https://discuss.elastic.co/t/index-polygons-and-multipolygons-with-logstash/347235 "2023-11-15T18:48:49Z")

</div>

Hi I use ES to index geo-shapes like Polygon and MultiPolygon from CSV via logstash but I can't find a way to make ES ingest properly the datas... I use the following code but it failed for Polygon with holes and MultiP…

---

## [Problem connecting logstash and elasticsearch](https://discuss.elastic.co/t/problem-connecting-logstash-and-elasticsearch/346982)

<div class="topic-metadata">

**Author:** [@Belbo\_belbo](https://discuss.elastic.co/u/Belbo_belbo)\
**Replies:** 4\
**Last updated:** [November 15, 2023, 4:52pm UTC](https://discuss.elastic.co/t/problem-connecting-logstash-and-elasticsearch/346982 "2023-11-15T16:52:24Z")

</div>

Hi, I'm doing a simple setup on minikube to practice with the stack. I have a sidecar pod with a container that generates logs and filebeats, then I have elasticsearch, logstash and kibana pods. I have this problem betwe…

---

## [Elasticsearch 8 no longer throws Http Error 429](https://discuss.elastic.co/t/elasticsearch-8-no-longer-throws-http-error-429/347237)

<div class="topic-metadata">

**Author:** [@melchiorGr](https://discuss.elastic.co/u/melchiorGr)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 4:01pm UTC](https://discuss.elastic.co/t/elasticsearch-8-no-longer-throws-http-error-429/347237 "2023-11-15T16:01:30Z")

</div>

Our customers are running ES-8.x solely for our app on dedicated hardware, but since upgrade from Elastichsearch Server 7.13.x to Server 8.x indexing requests do no longer produce Http Response code 429 (which is recover…

---

## [Filebeat CPU Load and Log File Size Issues](https://discuss.elastic.co/t/filebeat-cpu-load-and-log-file-size-issues/347233)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 3:01pm UTC](https://discuss.elastic.co/t/filebeat-cpu-load-and-log-file-size-issues/347233 "2023-11-15T15:01:28Z")

</div>

Hello everyone, I'm relatively new to IT and currently facing some challenges with Filebeat that I hope the community can help me with. The issue I'm encountering is related to the CPU load of Filebeat. The filebeat pr…

---

## [Grock for \[10/26/23 10:48:30:823 CEST\] date format for Logstash filter](https://discuss.elastic.co/t/grock-for-10-26-23-1030-823-cest-date-format-for-logstash-filter/346871)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 1\
**Last updated:** [November 15, 2023, 2:38pm UTC](https://discuss.elastic.co/t/grock-for-10-26-23-1030-823-cest-date-format-for-logstash-filter/346871 "2023-11-15T14:38:02Z")

</div>

Hello. I'm looking for grock filter matching this format \[10/26/23 10:48:30:823 CEST\] can't find any match from predefined formats. I need it to my Logstash filter. Any ideas ?

---

## [Create multiple indexes](https://discuss.elastic.co/t/create-multiple-indexes/346629)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 3\
**Last updated:** [November 15, 2023, 2:13pm UTC](https://discuss.elastic.co/t/create-multiple-indexes/346629 "2023-11-15T14:13:20Z")

</div>

I am trying to send two json logs from server A to my logstash server. Previously, when we only sent a json log file from server A to the logstash server, it was possible to create a data view and view the log in discov…

---

## [How to handle replay of eventhub data](https://discuss.elastic.co/t/how-to-handle-replay-of-eventhub-data/347230)

<div class="topic-metadata">

**Author:** [@favetelinguis](https://discuss.elastic.co/u/favetelinguis)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-handle-replay-of-eventhub-data/347230 "2023-11-15T14:02:15Z")

</div>

I am currently running some disaster recovery tests on out logstash which uses the Azure Eventhub input plugin and elastic output. My test includes changing the URL to elastic so that sending will fail. However once I re…

---

## [Basics for ES Security (SSL/PWD) on remote deployed Dockers](https://discuss.elastic.co/t/basics-for-es-security-ssl-pwd-on-remote-deployed-dockers/347070)

<div class="topic-metadata">

**Author:** [@mark.elwin](https://discuss.elastic.co/u/mark.elwin)\
**Replies:** 3\
**Last updated:** [November 15, 2023, 1:49pm UTC](https://discuss.elastic.co/t/basics-for-es-security-ssl-pwd-on-remote-deployed-dockers/347070 "2023-11-15T13:49:07Z")

</div>

Elasticsearch is great utility for establishing search, and the Docker containers make deploying remotely a wonderful breeze. So far my team has succeeded in establishing the remote deployment of Docker contains when xpa…

---

## [Elastic cluster on Docker swarm](https://discuss.elastic.co/t/elastic-cluster-on-docker-swarm/347226)

<div class="topic-metadata">

**Author:** [@BEIIKS](https://discuss.elastic.co/u/BEIIKS)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 1:08pm UTC](https://discuss.elastic.co/t/elastic-cluster-on-docker-swarm/347226 "2023-11-15T13:08:14Z")

</div>

Hello :smiley: Unfortunately Im going to ask a common question on elastic cluster, but for some unkown reason that I found pretty strange, there is no answer at the moment. Im trying to deploy elastic cluster on 3 dock…

---

## [False positive?](https://discuss.elastic.co/t/false-positive/347135)

<div class="topic-metadata">

**Author:** [@armada](https://discuss.elastic.co/u/armada)\
**Replies:** 1\
**Last updated:** [November 15, 2023, 1:37pm UTC](https://discuss.elastic.co/t/false-positive/347135 "2023-11-15T13:37:04Z")

</div>

Even though I sent a report, there is no response or solution. Isn't there such a lack of maintenance?

---

## [Data retention](https://discuss.elastic.co/t/data-retention/347129)

<div class="topic-metadata">

**Author:** [@admin365](https://discuss.elastic.co/u/admin365)\
**Replies:** 7\
**Last updated:** [November 15, 2023, 1:15pm UTC](https://discuss.elastic.co/t/data-retention/347129 "2023-11-15T13:15:15Z")

</div>

Hello! I've successfully configured a Debian-based Elasticsearch cluster with three nodes. Everything is functioning well. Currently, I need guidance on activating a data retention period of three months. Can you provid…

---

## [LDAP authentification for Kibana 8.8](https://discuss.elastic.co/t/ldap-authentification-for-kibana-8-8/347205)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [November 15, 2023, 11:09am UTC](https://discuss.elastic.co/t/ldap-authentification-for-kibana-8-8/347205 "2023-11-15T11:09:34Z")

</div>

Hello, I want to set up LDAP integration to manage groups, allowing them access to different spaces within the Kibana 8.8 interface. Additionally, I want to handle permissions through an external LDAP. Is this at the…

---

## [Cannot upgrade to 8.11 over apt, like documentation suggests](https://discuss.elastic.co/t/cannot-upgrade-to-8-11-over-apt-like-documentation-suggests/347216)

<div class="topic-metadata">

**Author:** [@awiederkehr](https://discuss.elastic.co/u/awiederkehr)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 10:37am UTC](https://discuss.elastic.co/t/cannot-upgrade-to-8-11-over-apt-like-documentation-suggests/347216 "2023-11-15T10:37:27Z")

</div>

Hello, the 8.11.0 and 8.11.1 is not available over the APT repo like the documentation suggests. The last version listed on stable is 8.10.4.

---

## [Restore from S3 Snapshot](https://discuss.elastic.co/t/restore-from-s3-snapshot/347210)

<div class="topic-metadata">

**Author:** [@Vadiraj\_Prahalad](https://discuss.elastic.co/u/Vadiraj_Prahalad)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 9:52am UTC](https://discuss.elastic.co/t/restore-from-s3-snapshot/347210 "2023-11-15T09:52:21Z")

</div>

Hello Everyone, We are trying to Restore the snapshot from S3 bucket. The snapshot is taken from a different cluster (7.12) & getting restored in different cluster (7.17 ). Below is the error during the restore activit…

---

## [Kibana does not start after upgrade to 8.11.0](https://discuss.elastic.co/t/kibana-does-not-start-after-upgrade-to-8-11-0/346994)

<div class="topic-metadata">

**Author:** [@tori](https://discuss.elastic.co/u/tori)\
**Replies:** 1\
**Last updated:** [November 15, 2023, 9:14am UTC](https://discuss.elastic.co/t/kibana-does-not-start-after-upgrade-to-8-11-0/346994 "2023-11-15T09:14:11Z")

</div>

We recently upgraded our on-prem Elastic stack deployment to 8.11.0 Kibana refuses to start after the upgrade (/var/log/kibana/kibana.log): {"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.6.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=372)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=374)
