# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=397

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 398

---

## [Custom UDP with PANW integration](https://discuss.elastic.co/t/custom-udp-with-panw-integration/344214)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 4\
**Last updated:** [October 17, 2023, 12:19pm UTC](https://discuss.elastic.co/t/custom-udp-with-panw-integration/344214 "2023-10-17T12:19:41Z")

</div>

Hello, I used PANOS integration that work great for me. Now I want to change my configuration and use Custom UDP Logs integration. In advanced options I changed Ingest pipelines "logs-udp.generic@custom". I also te…

---

## [Logstash doesn't parse new files in directory](https://discuss.elastic.co/t/logstash-doesnt-parse-new-files-in-directory/345197)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 4\
**Last updated:** [October 17, 2023, 11:13am UTC](https://discuss.elastic.co/t/logstash-doesnt-parse-new-files-in-directory/345197 "2023-10-17T11:13:16Z")

</div>

Logstash doesn't parse new logs files in directory Here's my config input { file{ path =\> "/home/user/Documents/bdu/\*.json" sincedb\_path =\> "/dev/null" type =\> "bdu" codec =\> "json" } } output { …

---

## [Sample code to find similar HTML Documents](https://discuss.elastic.co/t/sample-code-to-find-similar-html-documents/345140)

<div class="topic-metadata">

**Author:** [@Ata\_Zangene](https://discuss.elastic.co/u/Ata_Zangene)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 9:55am UTC](https://discuss.elastic.co/t/sample-code-to-find-similar-html-documents/345140 "2023-10-17T09:55:12Z")

</div>

Hi, I want to index around 10 million of web pages HTML code in elasticsearch, now, I want to give the HTML content as a search query and get the most similar documents related to the search query ( which is an HTML ) s…

---

## [Please help me with this error](https://discuss.elastic.co/t/please-help-me-with-this-error/345074)

<div class="topic-metadata">

**Author:** [@Ankit\_kumar\_Srivasta](https://discuss.elastic.co/u/Ankit_kumar_Srivasta)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/please-help-me-with-this-error/345074 "2023-10-17T09:54:55Z")

</div>

I am getting this error log in aws lambda when i am trying to capture transaction labels. 2023-10-16 07:50:32,698 \[elastic-apm-server-reporter\] ERROR co.elastic.apm.agent.report.IntakeV2ReportingEventHandler - Failed to…

---

## [ELK STACK - LICENSE CLARIFICATION](https://discuss.elastic.co/t/elk-stack-license-clarification/345171)

<div class="topic-metadata">

**Author:** [@venkatesh\_prasanth](https://discuss.elastic.co/u/venkatesh_prasanth)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 9:52am UTC](https://discuss.elastic.co/t/elk-stack-license-clarification/345171 "2023-10-17T09:52:00Z")

</div>

Hi, So Basically I would like to use ELK as monitoring stack for our own purpose, Can We get alerting like mail alert for hearbeat down or anything on this Download Elastic Products | Elastic what are the limitations?…

---

## [How to add a map using GeoServer and kibana 8.10](https://discuss.elastic.co/t/how-to-add-a-map-using-geoserver-and-kibana-8-10/345130)

<div class="topic-metadata">

**Author:** [@Erez\_Danieli](https://discuss.elastic.co/u/Erez_Danieli)\
**Replies:** 6\
**Last updated:** [October 17, 2023, 9:21am UTC](https://discuss.elastic.co/t/how-to-add-a-map-using-geoserver-and-kibana-8-10/345130 "2023-10-17T09:21:19Z")

</div>

Hi there Elastic team, I'm looking for some guidance on how to add a custom map using a geoserver. I have went over the instructions on this blog Kibana and a Custom Tile Server for NHL Data | Elastic Blog and and I ca…

---

## [How to auto delete data older than 2 month or 30 days from elastcisearch index?](https://discuss.elastic.co/t/how-to-auto-delete-data-older-than-2-month-or-30-days-from-elastcisearch-index/345161)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 5\
**Last updated:** [October 17, 2023, 7:40am UTC](https://discuss.elastic.co/t/how-to-auto-delete-data-older-than-2-month-or-30-days-from-elastcisearch-index/345161 "2023-10-17T07:40:02Z")

</div>

Note: I am not using date in index name like index -yyyy-mm . any method to do this i am using python Elasticsearch client to store data in es database.

---

## [Elastic Alert Rules - History of an alert being disabled/enabled](https://discuss.elastic.co/t/elastic-alert-rules-history-of-an-alert-being-disabled-enabled/344723)

<div class="topic-metadata">

**Author:** [@ElasticNovis](https://discuss.elastic.co/u/ElasticNovis)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 8:01am UTC](https://discuss.elastic.co/t/elastic-alert-rules-history-of-an-alert-being-disabled-enabled/344723 "2023-10-17T08:01:18Z")

</div>

We are using v8.9.0. Is it possible to see a history of when a rule/alert (Stack Management\>Alerts and Insights\>Rules)? I am interested to see the history of when an alert was enabled/disabled. The history of the chang…

---

## [Logstash / elastic-agent how to create rule on events emitted rate](https://discuss.elastic.co/t/logstash-elastic-agent-how-to-create-rule-on-events-emitted-rate/345173)

<div class="topic-metadata">

**Author:** [@antoine\_duriez](https://discuss.elastic.co/u/antoine_duriez)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 8:01am UTC](https://discuss.elastic.co/t/logstash-elastic-agent-how-to-create-rule-on-events-emitted-rate/345173 "2023-10-17T08:01:10Z")

</div>

Hello community, All data collected by my elastic agents (\>4000) is processed by a pair of logstashes. In the Stack Monitoring dashboard I can see the pipeline and the number of events emitted. I would like to know wh…

---

## [Relp error: Relp::InappropriateCommand open expecting syslog](https://discuss.elastic.co/t/relp-error-relp-inappropriatecommand-open-expecting-syslog/345125)

<div class="topic-metadata">

**Author:** [@MarcoV](https://discuss.elastic.co/u/MarcoV)\
**Replies:** 2\
**Last updated:** [October 17, 2023, 7:52am UTC](https://discuss.elastic.co/t/relp-error-relp-inappropriatecommand-open-expecting-syslog/345125 "2023-10-17T07:52:35Z")

</div>

Hello everyone. I have this warning in my logstash log: Relp error: Relp::InappropriateCommand open expecting syslog My logstash configuration filter has input relp as input but with this error the log from syslog are…

---

## [Elastic search v 7.17.10 : x-pack-SSL authentication](https://discuss.elastic.co/t/elastic-search-v-7-17-10-x-pack-ssl-authentication/345172)

<div class="topic-metadata">

**Author:** [@Deepika\_Gupta](https://discuss.elastic.co/u/Deepika_Gupta)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 7:43am UTC](https://discuss.elastic.co/t/elastic-search-v-7-17-10-x-pack-ssl-authentication/345172 "2023-10-17T07:43:17Z")

</div>

Hi Team, In Elasticsearch, we have a cluster node, enabling x-pack, On Master node: x-pack enabled successfully, certification authorities successfully On a Slave node: x-pack enabled successfully, but certification a…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/345162)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 7:31am UTC](https://discuss.elastic.co/t/elasticsearch/345162 "2023-10-17T07:31:01Z")

</div>

Suddenly am getting this Error in Elasticsearch: org.elasticsearch.ElasticsearchException: Trying to create too many scroll contexts. Must be less than or equal to: \[500\]. This limit can be set by changing the \[search.m…

---

## [Ingest pipeline - extract regex from events](https://discuss.elastic.co/t/ingest-pipeline-extract-regex-from-events/345133)

<div class="topic-metadata">

**Author:** [@xyz3](https://discuss.elastic.co/u/xyz3)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 6:36am UTC](https://discuss.elastic.co/t/ingest-pipeline-extract-regex-from-events/345133 "2023-10-17T06:36:18Z")

</div>

Hello I need to extract some text string from existing index field: IMSChargingIdentifier and place it into new, separate field. New, incoming events should be parsed exactly the same way. Here is sample record from t…

---

## [Snapshot restore](https://discuss.elastic.co/t/snapshot-restore/345160)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 5:36am UTC](https://discuss.elastic.co/t/snapshot-restore/345160 "2023-10-17T05:36:28Z")

</div>

I have been restoring snapshots which caused some missing errors for some time but I only could find it possible one by one. Is there any way that I can restore all missing or erroneous snapshot all at once?

---

## [After AKS Node Restart - We have lost Disk Queue](https://discuss.elastic.co/t/after-aks-node-restart-we-have-lost-disk-queue/345158)

<div class="topic-metadata">

**Author:** [@zoheb](https://discuss.elastic.co/u/zoheb)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 5:22am UTC](https://discuss.elastic.co/t/after-aks-node-restart-we-have-lost-disk-queue/345158 "2023-10-17T05:22:51Z")

</div>

Hi Team, Yesterday we have restarted our AKS Nodes and we have lost the disk queue. We see a new folder being created at AKS Node. Here is the configuration file for filebeat: volumeMounts: - name: config mountPath:…

---

## [How to restart an Elasticsearch cluster (2 master node, 2 data node, 1 voting-only master-eligible node) after a 1 master node and 1 data node failed due to hardware failure without losing data?](https://discuss.elastic.co/t/how-to-restart-an-elasticsearch-cluster-2-master-node-2-data-node-1-voting-only-master-eligible-node-after-a-1-master-node-and-1-data-node-failed-due-to-hardware-failure-without-losing-data/345027)

<div class="topic-metadata">

**Author:** [@ThuyNguyen](https://discuss.elastic.co/u/ThuyNguyen)\
**Replies:** 5\
**Last updated:** [October 17, 2023, 3:36am UTC](https://discuss.elastic.co/t/how-to-restart-an-elasticsearch-cluster-2-master-node-2-data-node-1-voting-only-master-eligible-node-after-a-1-master-node-and-1-data-node-failed-due-to-hardware-failure-without-losing-data/345027 "2023-10-17T03:36:05Z")

</div>

Hi team, I have an Elasticsearch cluster which is setup across 3 servers through docker. Here is the configuration that I used: server 1: 1 voting-only master server 2: 1 master node, 1 data node, and snapshot server …

---

## [Signals to consider the nature of operation](https://discuss.elastic.co/t/signals-to-consider-the-nature-of-operation/343681)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 3\
**Last updated:** [October 17, 2023, 3:11am UTC](https://discuss.elastic.co/t/signals-to-consider-the-nature-of-operation/343681 "2023-10-17T03:11:36Z")

</div>

Hello folks, I recently came across this post Elasticsearch memory-bound tasks. Basis which I am trying to understand the nature of a search request to my cluster. Following are some questions I have What are the sig…

---

## [How can i setup alerts in kibana for a dashboard?](https://discuss.elastic.co/t/how-can-i-setup-alerts-in-kibana-for-a-dashboard/344538)

<div class="topic-metadata">

**Author:** [@Abhiyash\_Agrawal](https://discuss.elastic.co/u/Abhiyash_Agrawal)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 3:01am UTC](https://discuss.elastic.co/t/how-can-i-setup-alerts-in-kibana-for-a-dashboard/344538 "2023-10-17T03:01:26Z")

</div>

I hope this message finds you well. I am reaching out to inquire about the possibilities of setting up alerts in Kibana for specific dashboard charts within defined durations. Our team has been utilizing Kibana for dat…

---

## [How to rollover index that is ending with date](https://discuss.elastic.co/t/how-to-rollover-index-that-is-ending-with-date/344827)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 6\
**Last updated:** [October 17, 2023, 2:00am UTC](https://discuss.elastic.co/t/how-to-rollover-index-that-is-ending-with-date/344827 "2023-10-17T02:00:40Z")

</div>

Hi, I have some indices in the cluster that have index names as follows: abc-asd-2023-10-09 abc-asd-2023-10-10 abc-asd-2023-10-11 There is no function running in the cluster to create daily indices. I wanted to add…

---

## [How to properly use Publicly signed Certifiate in kibana to communicate witih elastic?](https://discuss.elastic.co/t/how-to-properly-use-publicly-signed-certifiate-in-kibana-to-communicate-witih-elastic/345034)

<div class="topic-metadata">

**Author:** [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Replies:** 19\
**Last updated:** [October 17, 2023, 12:17am UTC](https://discuss.elastic.co/t/how-to-properly-use-publicly-signed-certifiate-in-kibana-to-communicate-witih-elastic/345034 "2023-10-17T00:17:01Z")

</div>

My elasticsearch.yml configuration xpack.security.http.ssl: enabled: true keystore.path: certs/certificates.p12 Bellow procedure has been followed to create certificate.p12 \> cat private-key.key certificate.crt \> …

---

## [Exam Put vs POST](https://discuss.elastic.co/t/exam-put-vs-post/344954)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 11:36pm UTC](https://discuss.elastic.co/t/exam-put-vs-post/344954 "2023-10-16T23:36:13Z")

</div>

Hi, I've found myself getting a bit confused as to when the appropriate time to use a PUT vs POST when going about the labs. I'm noticing very subtle differences, primarily around server config state, but it seems that m…

---

## [How to login to Kibana embedded in an iframe using API](https://discuss.elastic.co/t/how-to-login-to-kibana-embedded-in-an-iframe-using-api/344895)

<div class="topic-metadata">

**Author:** [@Sanchet\_Nagarnaik](https://discuss.elastic.co/u/Sanchet_Nagarnaik)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 10:29pm UTC](https://discuss.elastic.co/t/how-to-login-to-kibana-embedded-in-an-iframe-using-api/344895 "2023-10-16T22:29:50Z")

</div>

I have a ReactJS and Go based web application. I have a Kibana dashboard embedded in an iframe. Now when a user logs into the application, then that user must be automatically logged into Kibana as well. And the Kibana d…

---

## [Filebeat not collecting logs from EKS](https://discuss.elastic.co/t/filebeat-not-collecting-logs-from-eks/344939)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 6:26pm UTC](https://discuss.elastic.co/t/filebeat-not-collecting-logs-from-eks/344939 "2023-10-16T18:26:25Z")

</div>

I have deployed EBK (8.5.3) stack on AWS EKS with following manifest filebeat.yaml--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: filebeat subjects: - kind: ServiceAccount name…

---

## [Display sum of difference of a field between two day](https://discuss.elastic.co/t/display-sum-of-difference-of-a-field-between-two-day/345129)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 5:54pm UTC](https://discuss.elastic.co/t/display-sum-of-difference-of-a-field-between-two-day/345129 "2023-10-16T17:54:55Z")

</div>

I have daily data I would like to display difference of sum(total\_size) - sum(total\_size) basically difference of today - yesterday.

---

## [Filebeat/Logstash poor disk.queue read performance: is that the maximum i can get?](https://discuss.elastic.co/t/filebeat-logstash-poor-disk-queue-read-performance-is-that-the-maximum-i-can-get/345056)

<div class="topic-metadata">

**Author:** [@sergeyarl](https://discuss.elastic.co/u/sergeyarl)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 5:53pm UTC](https://discuss.elastic.co/t/filebeat-logstash-poor-disk-queue-read-performance-is-that-the-maximum-i-can-get/345056 "2023-10-16T17:53:28Z")

</div>

Testing performance of Filebeat disk.queue. Environment: AWS EC2 OS: Centos 7.x Machine parameters (FB, LS): CPU 8 vcores, RAM 16GB Filebeat version: filebeat-8.10.3-1.x86\_64 Logstash version: logstash-8.10.3-1.x86\_…

---

## [Kibana rule - raise alert when CPU is over 90% for the last 5 min](https://discuss.elastic.co/t/kibana-rule-raise-alert-when-cpu-is-over-90-for-the-last-5-min/344404)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 6\
**Last updated:** [October 16, 2023, 5:02pm UTC](https://discuss.elastic.co/t/kibana-rule-raise-alert-when-cpu-is-over-90-for-the-last-5-min/344404 "2023-10-16T17:02:22Z")

</div>

Hi gurus, I'm new to Rules in Kibana so I need your help. I need to raise an email alert when the CPU is constantly exceeding 90% for the past 5 minutes. The way I configured the rule is the following: The alert i…

---

## [Log ELSER inference time](https://discuss.elastic.co/t/log-elser-inference-time/345057)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 4:47pm UTC](https://discuss.elastic.co/t/log-elser-inference-time/345057 "2023-10-16T16:47:16Z")

</div>

When using ELSER, you can find the "Avg. inference time" under Kibana \> Analytics \> Machine Learning \> Model Management \> Trained Models. I cannot find any logs related to inference time when searching in Analytics \> Di…

---

## [Use winlogbeat to convert windows event logs to json?](https://discuss.elastic.co/t/use-winlogbeat-to-convert-windows-event-logs-to-json/345126)

<div class="topic-metadata">

**Author:** [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 4:00pm UTC](https://discuss.elastic.co/t/use-winlogbeat-to-convert-windows-event-logs-to-json/345126 "2023-10-16T16:00:30Z")

</div>

Is it still possible to use winlogbeat to convert evtx files to json? I was trying to use the powershell script from here - If(Test-Path -path $pwd\\winlogbeat.exe) { echo "Starting conversion from EVTX to JSON ..."…

---

## [No Data streams](https://discuss.elastic.co/t/no-data-streams/344985)

<div class="topic-metadata">

**Author:** [@Jean-Claude](https://discuss.elastic.co/u/Jean-Claude)\
**Replies:** 4\
**Last updated:** [October 16, 2023, 2:10pm UTC](https://discuss.elastic.co/t/no-data-streams/344985 "2023-10-16T14:10:30Z")

</div>

Hello, i hope you are doing well This my infra ELASTIC v-elkmaster01.sys.u-bordeaux.fr v-elkmaster02.sys.u-bordeaux.fr v-elkmaster03.sys.u-bordeaux.fr p-elkhot01.sys.u-bordeaux.fr p-elkhot02.sys.u-bordeaux.fr p-elkwar…

---

## [Enabling Native Multi-Factor Authentication in On-Premises versions](https://discuss.elastic.co/t/enabling-native-multi-factor-authentication-in-on-premises-versions/345108)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 1:18pm UTC](https://discuss.elastic.co/t/enabling-native-multi-factor-authentication-in-on-premises-versions/345108 "2023-10-16T13:18:32Z")

</div>

Hello everyone, I'm currently using Elasticsearch in an on-premises environment and I'm exploring options to enhance the security of my cluster. I was wondering if enabling a native multi-factor authentication is possib…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=396)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=398)
