# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=386

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 387

---

## [Sync Postgresql and Elasticsearch using Filebeat](https://discuss.elastic.co/t/sync-postgresql-and-elasticsearch-using-filebeat/345576)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 1:43pm UTC](https://discuss.elastic.co/t/sync-postgresql-and-elasticsearch-using-filebeat/345576 "2023-10-30T13:43:55Z")

</div>

Hi, I have a considerable amount of information in a Postgresql database. Registers are inserted on this database on demand. We are currently interested in syncronize this database and Elasticsearch in order to have the…

---

## [ELK | Logging | filter out specific ip's generated WARNs?](https://discuss.elastic.co/t/elk-logging-filter-out-specific-ips-generated-warns/346040)

<div class="topic-metadata">

**Author:** [@LucGasper](https://discuss.elastic.co/u/LucGasper)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 1:33pm UTC](https://discuss.elastic.co/t/elk-logging-filter-out-specific-ips-generated-warns/346040 "2023-10-30T13:33:04Z")

</div>

Hi elk lovers, in our Company we are subjected daily to security penetration tests. All these tests are originated by a specific static ip. Our elasticsearch log is therefore filled up with WARNs, especially: ... \[2…

---

## [Windows Service Control Manager error with Elastic Agent](https://discuss.elastic.co/t/windows-service-control-manager-error-with-elastic-agent/346039)

<div class="topic-metadata">

**Author:** [@Bearloggs](https://discuss.elastic.co/u/Bearloggs)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 1:21pm UTC](https://discuss.elastic.co/t/windows-service-control-manager-error-with-elastic-agent/346039 "2023-10-30T13:21:56Z")

</div>

Description When installing and running the Elastic Agent on a Windows 10 or Windows Server 2019 machine, I encounter Service Control Manager errors. The Elastic Agent seems to be functioning as expected on my Windows m…

---

## [Apache Logs Not Parsing with Filebeat Ingestion Pipeline](https://discuss.elastic.co/t/apache-logs-not-parsing-with-filebeat-ingestion-pipeline/345968)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 3\
**Last updated:** [October 30, 2023, 12:37pm UTC](https://discuss.elastic.co/t/apache-logs-not-parsing-with-filebeat-ingestion-pipeline/345968 "2023-10-30T12:37:39Z")

</div>

I have installed Filebeat version 8.10.2 on an Ubuntu server and configured it to send Apache access and error logs to Logstash. While the logs are displayed in Kibana, they are not parsing through their default ingest p…

---

## [Elasticsearch node ram.percent at 100%](https://discuss.elastic.co/t/elasticsearch-node-ram-percent-at-100/346022)

<div class="topic-metadata">

**Author:** [@rahmathm1](https://discuss.elastic.co/u/rahmathm1)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 10:57am UTC](https://discuss.elastic.co/t/elasticsearch-node-ram-percent-at-100/346022 "2023-10-30T10:57:33Z")

</div>

Hi, everyone, We have a 6x6 setup of ES deployed on Kubernetes. When we check node memory statistics, we can see that data nodes are using 100% of ram allocated to them. Below are the resource limits for data nodes: l…

---

## [Run painless script in cron like manner](https://discuss.elastic.co/t/run-painless-script-in-cron-like-manner/346017)

<div class="topic-metadata">

**Author:** [@Pawel\_Gorowicz](https://discuss.elastic.co/u/Pawel_Gorowicz)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 10:01am UTC](https://discuss.elastic.co/t/run-painless-script-in-cron-like-manner/346017 "2023-10-30T10:01:36Z")

</div>

Hi All, I'm searching for an options to run a script in cron like manner. I need to run "\_update\_by\_query" with tiny painless script every few hours to fix some data inside the index. Is there any option to do that ?

---

## [Logstash RSS plugin failed to load after fresh install](https://discuss.elastic.co/t/logstash-rss-plugin-failed-to-load-after-fresh-install/345988)

<div class="topic-metadata">

**Author:** [@developerx](https://discuss.elastic.co/u/developerx)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 9:15am UTC](https://discuss.elastic.co/t/logstash-rss-plugin-failed-to-load-after-fresh-install/345988 "2023-10-30T09:15:35Z")

</div>

Hello, i've an issue with a fresh logstash installation and logstash-input-rss plugin. when trying to test the configuration for a simple RSS reader for just 1 URL i got this error: \[DEBUG\] 2023-10-29 19:57:25.354 \[Con…

---

## [Concurrent Enrich Policy Execution](https://discuss.elastic.co/t/concurrent-enrich-policy-execution/346011)

<div class="topic-metadata">

**Author:** [@Akshey](https://discuss.elastic.co/u/Akshey)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 8:32am UTC](https://discuss.elastic.co/t/concurrent-enrich-policy-execution/346011 "2023-10-30T08:32:36Z")

</div>

Hi Team, We've added an enrichment policy to join data among two indexes. The indexes are dynamic, hence we are running the execute policy query whenever there's an update in the source index. The problem is when there …

---

## [Problem with Template File Not Applying Correctly in Logstash](https://discuss.elastic.co/t/problem-with-template-file-not-applying-correctly-in-logstash/346006)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 7:09am UTC](https://discuss.elastic.co/t/problem-with-template-file-not-applying-correctly-in-logstash/346006 "2023-10-30T07:09:06Z")

</div>

We are experiencing an issue with Logstash where the user\_dictionary\_rules, stopwords, and synonyms data are not being properly indexed based on the template file in an EC2 environment. When these data sets, specificall…

---

## [Why is the ssl\_key\_passphrase missing in the plugins-outputs-elasticsearch?](https://discuss.elastic.co/t/why-is-the-ssl-key-passphrase-missing-in-the-plugins-outputs-elasticsearch/345999)

<div class="topic-metadata">

**Author:** [@hengya\_liu](https://discuss.elastic.co/u/hengya_liu)\
**Replies:** 6\
**Last updated:** [October 30, 2023, 6:27am UTC](https://discuss.elastic.co/t/why-is-the-ssl-key-passphrase-missing-in-the-plugins-outputs-elasticsearch/345999 "2023-10-30T06:27:43Z")

</div>

Logstash 8.10 ssl\_key\_passphrase is Missing. If we set the SSL certificate, do we have to use the unencrypted key or use a keystore?

---

## [Index Created but No Document got written](https://discuss.elastic.co/t/index-created-but-no-document-got-written/346004)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 4:57am UTC](https://discuss.elastic.co/t/index-created-but-no-document-got-written/346004 "2023-10-30T04:57:40Z")

</div>

Just set a more specific index template with a higher priority value than the more general one, and looking to apply this template instead of the general one. Then I removed related data stream (which wipes off all the r…

---

## [Configure Elastic agent to collect AWS RDS SLOW logs loaded in S3](https://discuss.elastic.co/t/configure-elastic-agent-to-collect-aws-rds-slow-logs-loaded-in-s3/346003)

<div class="topic-metadata">

**Author:** [@douglas0923](https://discuss.elastic.co/u/douglas0923)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 4:54am UTC](https://discuss.elastic.co/t/configure-elastic-agent-to-collect-aws-rds-slow-logs-loaded-in-s3/346003 "2023-10-30T04:54:21Z")

</div>

Hi there Is there a way to configure the Elastic Agent to directly read the slow logs from the S3 bucket instead of the local file path? Additionally, I feel that configuring this through Kibana's Fleet GUI might be ch…

---

## [Synonym search latency](https://discuss.elastic.co/t/synonym-search-latency/346001)

<div class="topic-metadata">

**Author:** [@vanduong](https://discuss.elastic.co/u/vanduong)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 3:51am UTC](https://discuss.elastic.co/t/synonym-search-latency/346001 "2023-10-30T03:51:00Z")

</div>

I recently utilized synonyms in an Elasticsearch context. After reading a blog that discusses the advantages of applying synonyms at search time as opposed to index time, I began to wonder if using synonyms at search tim…

---

## [\[Packetbeat\] packet loss for mysql queries](https://discuss.elastic.co/t/packetbeat-packet-loss-for-mysql-queries/345857)

<div class="topic-metadata">

**Author:** [@lenovore](https://discuss.elastic.co/u/lenovore)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 2:23am UTC](https://discuss.elastic.co/t/packetbeat-packet-loss-for-mysql-queries/345857 "2023-10-30T02:23:21Z")

</div>

Version: packetbeat-8.10.4、packetbeat-7.10.2 Operating System: ubuntu20.04 #18471 #20890 Three years have passed, and the problem of packet loss in MySQL queries remains unresolved. sql: use dba\_backup; select \* fr…

---

## [How to configure prometheus ssl host with metricbeat?](https://discuss.elastic.co/t/how-to-configure-prometheus-ssl-host-with-metricbeat/345997)

<div class="topic-metadata">

**Author:** [@pooh97](https://discuss.elastic.co/u/pooh97)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:05am UTC](https://discuss.elastic.co/t/how-to-configure-prometheus-ssl-host-with-metricbeat/345997 "2023-10-30T02:05:07Z")

</div>

This is my first time on elasticsearch. I have to get metrics from prometheus hosts with ssl. I'll describe my develop environment in advance. I'm using metricbeat 8.8.2 on A Server. But I want to scrap Prometheus fe…

---

## [Index data storage into a cluster](https://discuss.elastic.co/t/index-data-storage-into-a-cluster/344298)

<div class="topic-metadata">

**Author:** [@MattzGB](https://discuss.elastic.co/u/MattzGB)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 11:07pm UTC](https://discuss.elastic.co/t/index-data-storage-into-a-cluster/344298 "2023-10-29T23:07:13Z")

</div>

I have an elasticsearch cluster with 3 nodes where the elasticsearch service is installed on each node. When I check the cluster health and the index on each node, I can see that the cluster is green and that the 25GB i…

---

## [Prioritizing Indices for Search Speed](https://discuss.elastic.co/t/prioritizing-indices-for-search-speed/345973)

<div class="topic-metadata">

**Author:** [@maorethians](https://discuss.elastic.co/u/maorethians)\
**Replies:** 2\
**Last updated:** [October 29, 2023, 10:09pm UTC](https://discuss.elastic.co/t/prioritizing-indices-for-search-speed/345973 "2023-10-29T22:09:48Z")

</div>

We have an Elasticsearch instance, containing 100s of indices in it with different, statically-defined mappings. Is there a way to prioritize some of them for read/write operations not to be affected by low-priority ones…

---

## [Question about discuss.elastic.co](https://discuss.elastic.co/t/question-about-discuss-elastic-co/345984)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 2\
**Last updated:** [October 29, 2023, 5:32pm UTC](https://discuss.elastic.co/t/question-about-discuss-elastic-co/345984 "2023-10-29T17:32:20Z")

</div>

Hello: I was trying to ask a question on discuss.elastic.co and I see that I cannot do that anymore. Not sure why. Maybe you could find out why I am blacklisted there.

---

## [How to activate sysmon event ID 3](https://discuss.elastic.co/t/how-to-activate-sysmon-event-id-3/345977)

<div class="topic-metadata">

**Author:** [@yassinebad](https://discuss.elastic.co/u/yassinebad)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 3:51pm UTC](https://discuss.elastic.co/t/how-to-activate-sysmon-event-id-3/345977 "2023-10-29T15:51:26Z")

</div>

Hey everyone, I am sending my logs from a windows node using winlogbeat and sysmon64 to my ELK stack. While in discover panel in kibana I can see my logs with different events ID of sysmon, but I have noticed that the …

---

## [Logstash create many zero document indexes](https://discuss.elastic.co/t/logstash-create-many-zero-document-indexes/345522)

<div class="topic-metadata">

**Author:** [@Amzath\_Khan](https://discuss.elastic.co/u/Amzath_Khan)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 12:28pm UTC](https://discuss.elastic.co/t/logstash-create-many-zero-document-indexes/345522 "2023-10-29T12:28:25Z")

</div>

I'm sending data from a Microsoft SQL Server database into elasticsearch using logstash 8.x. It functions well. However, logstash multiplies indexes with no documents and raises the shared. It takes over an hour to reach…

---

## [HAYSTACK\_CONNECTIONS](https://discuss.elastic.co/t/haystack-connections/345829)

<div class="topic-metadata">

**Author:** [@sdarwin](https://discuss.elastic.co/u/sdarwin)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 11:49am UTC](https://discuss.elastic.co/t/haystack-connections/345829 "2023-10-29T11:49:29Z")

</div>

Hi, Not sure which category to post this in. Django Haystack GitHub - django-haystack/django-haystack: Modular search for Django supports Elasticsearch as a backend search engine. The connection is specified this way: H…

---

## [Elastic 8.10.3 failed to establish trust with server at \[\<unknown host\>\]; the server provided a certificate with subject name](https://discuss.elastic.co/t/elastic-8-10-3-failed-to-establish-trust-with-server-at-unknown-host-the-server-provided-a-certificate-with-subject-name/345656)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 8\
**Last updated:** [October 29, 2023, 11:21am UTC](https://discuss.elastic.co/t/elastic-8-10-3-failed-to-establish-trust-with-server-at-unknown-host-the-server-provided-a-certificate-with-subject-name/345656 "2023-10-29T11:21:41Z")

</div>

Hello good morning! I am trying to create an elastic cluster in version 8.10.3 but when starting the coordinator role I get the following error: \[ithrtc3aen1elk1-coordinator-1\] failed to establish trust with server at …

---

## [Can not connect Logstash to Elasticsearch](https://discuss.elastic.co/t/can-not-connect-logstash-to-elasticsearch/345867)

<div class="topic-metadata">

**Author:** [@liaotoca](https://discuss.elastic.co/u/liaotoca)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 11:15am UTC](https://discuss.elastic.co/t/can-not-connect-logstash-to-elasticsearch/345867 "2023-10-29T11:15:16Z")

</div>

I follow the instructions here Secure your connection to Elasticsearch | Logstash Reference \[8.10\] | Elastic but if I did not put the username/password, logstash reported 401, if I put in the user name /password, the sta…

---

## [Master Node cant connect](https://discuss.elastic.co/t/master-node-cant-connect/345899)

<div class="topic-metadata">

**Author:** [@Nerd0](https://discuss.elastic.co/u/Nerd0)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 11:11am UTC](https://discuss.elastic.co/t/master-node-cant-connect/345899 "2023-10-29T11:11:27Z")

</div>

Hi, I have a problem caused by: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors I configured 3 nod…

---

## [How to restore .security index from snapshot](https://discuss.elastic.co/t/how-to-restore-security-index-from-snapshot/344959)

<div class="topic-metadata">

**Author:** [@dna01](https://discuss.elastic.co/u/dna01)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/how-to-restore-security-index-from-snapshot/344959 "2023-10-29T11:06:56Z")

</div>

what is the recommended approach to restore .security index from snapshot? the index needs to be closed to be restored, but once it is closed, users cannot login anymore. and the whole database stuck since it cannot lo…

---

## [Logs don't show up on kibana](https://discuss.elastic.co/t/logs-dont-show-up-on-kibana/345930)

<div class="topic-metadata">

**Author:** [@yassinebad](https://discuss.elastic.co/u/yassinebad)\
**Replies:** 8\
**Last updated:** [October 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/logs-dont-show-up-on-kibana/345930 "2023-10-29T11:06:23Z")

</div>

Hey I am using winlogbeat on my windows machine with sysmon64. my winlogbeat.yml file is configured correctly. I have checked with the config command. once I run ./winlogbeat.exe setup -e ! my index and dashboards get …

---

## [Logstash cvs plugin not sending data to index](https://discuss.elastic.co/t/logstash-cvs-plugin-not-sending-data-to-index/345924)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 7:36am UTC](https://discuss.elastic.co/t/logstash-cvs-plugin-not-sending-data-to-index/345924 "2023-10-29T07:36:29Z")

</div>

Hello All, I have csv files under one folder in windows system and need to send the data in elastic index using logstash. I'm not sure why data is not showing in index,though index getting created. Need key and value a…

---

## [LogStash::Error: Don't know how to handle \`Java::JavaLang::IllegalStateException\` for \`PipelineAction::Create\<main\>\`](https://discuss.elastic.co/t/logstash-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/345882)

<div class="topic-metadata">

**Author:** [@fae](https://discuss.elastic.co/u/fae)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 6:53am UTC](https://discuss.elastic.co/t/logstash-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/345882 "2023-10-29T06:53:11Z")

</div>

Need help troubleshooting logstash java issue, it was working fine until a while ago when it started throwing up this error below: systemctl status logstash -l ● logstash.service - Logstash service (ELK stack). Loade…

---

## [Restore snapshot with curl](https://discuss.elastic.co/t/restore-snapshot-with-curl/345961)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 2\
**Last updated:** [October 28, 2023, 5:49pm UTC](https://discuss.elastic.co/t/restore-snapshot-with-curl/345961 "2023-10-28T17:49:04Z")

</div>

Hi, I have snapshot of indexes pattern .\*, now after Kibana problems due power off I have to restore .kibana\* indexes to fix my problems. How can I do it with curl (as Kibana doesn't work)?

---

## [I have the same problem](https://discuss.elastic.co/t/i-have-the-same-problem/345963)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 2\
**Last updated:** [October 28, 2023, 1:54pm UTC](https://discuss.elastic.co/t/i-have-the-same-problem/345963 "2023-10-28T13:54:04Z")

</div>

Continuing the discussion from How to re-run cluster with different cluster uuid:

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=385)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=387)
