# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=398

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 399

---

## [Timestamp format](https://discuss.elastic.co/t/timestamp-format/344951)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 9\
**Last updated:** [October 16, 2023, 1:02pm UTC](https://discuss.elastic.co/t/timestamp-format/344951 "2023-10-16T13:02:47Z")

</div>

We get the timestamps in this format: '2023-10-01T01:22:33.123Z'. Where can I set the format? And which time zone is preset? How can I find out the timezone from the timestamp? Is that UTC? We use filebeat agents to co…

---

## [Entreprise Resource Unit](https://discuss.elastic.co/t/entreprise-resource-unit/345104)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 12:58pm UTC](https://discuss.elastic.co/t/entreprise-resource-unit/345104 "2023-10-16T12:58:25Z")

</div>

I have a qst about how to calculate Elastic's Enterprise Resource Unit (ERU) licenses. Is it based on system resources or JVM resources? Thank you

---

## [Unable to Display Visualization in custom plugin](https://discuss.elastic.co/t/unable-to-display-visualization-in-custom-plugin/345106)

<div class="topic-metadata">

**Author:** [@Amit\_Dhiman](https://discuss.elastic.co/u/Amit_Dhiman)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 12:52pm UTC](https://discuss.elastic.co/t/unable-to-display-visualization-in-custom-plugin/345106 "2023-10-16T12:52:41Z")

</div>

I am successful to create and display Dashbaords and Lens in my custom plugin. I have some visualizations created in Kibana Admin. I want these visualizations to be rendered into my custom plugin screen. I tried many s…

---

## [Attempted to send a bulk request to elasticsearch, but no there are no living connections in the connection pool. Perhaps Elasticsearch is unreachable or down?](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-but-no-there-are-no-living-connections-in-the-connection-pool-perhaps-elasticsearch-is-unreachable-or-down/345042)

<div class="topic-metadata">

**Author:** [@Yazid\_Abed\_Alqader](https://discuss.elastic.co/u/Yazid_Abed_Alqader)\
**Replies:** 3\
**Last updated:** [October 16, 2023, 12:25pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-but-no-there-are-no-living-connections-in-the-connection-pool-perhaps-elasticsearch-is-unreachable-or-down/345042 "2023-10-16T12:25:35Z")

</div>

Hi I have these error messages in logstash logs: \[2023-10-15T08:01:31,446\]\[WARN \]\[logstash.outputs.elasticsearch\] Marking url as dead. Last error: \[LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableErr…

---

## [Not able to search with date range filter](https://discuss.elastic.co/t/not-able-to-search-with-date-range-filter/345088)

<div class="topic-metadata">

**Author:** [@bhumika](https://discuss.elastic.co/u/bhumika)\
**Replies:** 22\
**Last updated:** [October 16, 2023, 11:35am UTC](https://discuss.elastic.co/t/not-able-to-search-with-date-range-filter/345088 "2023-10-16T11:35:07Z")

</div>

I had integrated Elasticsearch in my ruby on rails project with chewy gem. All the searches are working fine except date range filter I tried every approach but not getting any error or response is always blank array th…

---

## [Observed kernel bug for Elasticsearch 7.17.5 on Debian 12](https://discuss.elastic.co/t/observed-kernel-bug-for-elasticsearch-7-17-5-on-debian-12/345083)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 10:35am UTC](https://discuss.elastic.co/t/observed-kernel-bug-for-elasticsearch-7-17-5-on-debian-12/345083 "2023-10-16T10:35:34Z")

</div>

Hi all, we are running an ES cluster in version 7.17.5 and some of our data nodes are already running on Debian 12. Now recently one data node failed. Elasticsearch itself did not log anything about the incident. Also s…

---

## [Failed to start crawler: starting input failed: error while initializing input: No paths were defined for input accessing](https://discuss.elastic.co/t/failed-to-start-crawler-starting-input-failed-error-while-initializing-input-no-paths-were-defined-for-input-accessing/345085)

<div class="topic-metadata">

**Author:** [@Manula\_Manjitha](https://discuss.elastic.co/u/Manula_Manjitha)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 9:29am UTC](https://discuss.elastic.co/t/failed-to-start-crawler-starting-input-failed-error-while-initializing-input-no-paths-were-defined-for-input-accessing/345085 "2023-10-16T09:29:27Z")

</div>

I have configured two filebeat inputs which the type of them is log. filebeat.inputs: - type: log id: gateway-elk enabled: true paths: - /home/ggg/app/ntp\_gateway/gateway-elk.log fields: {log\_type: gatewayl…

---

## [Grok issues / Fingerprint issues: Value not imported into ES after 6.x - 7-x update](https://discuss.elastic.co/t/grok-issues-fingerprint-issues-value-not-imported-into-es-after-6-x-7-x-update/344357)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 9\
**Last updated:** [October 16, 2023, 8:48am UTC](https://discuss.elastic.co/t/grok-issues-fingerprint-issues-value-not-imported-into-es-after-6-x-7-x-update/344357 "2023-10-16T08:48:05Z")

</div>

Hello, I am new to ELK stack especially the filtering / Grok in Logstash, We are having issues importing DATA:servicename value into ES after moving from 6.3.X to a 7.14 version. The grok below is part of our applica…

---

## [Best approach to update huge # of documents (millions) single query](https://discuss.elastic.co/t/best-approach-to-update-huge-of-documents-millions-single-query/345080)

<div class="topic-metadata">

**Author:** [@vtadmin](https://discuss.elastic.co/u/vtadmin)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 8:59am UTC](https://discuss.elastic.co/t/best-approach-to-update-huge-of-documents-millions-single-query/345080 "2023-10-16T08:59:47Z")

</div>

I'm using elastic for storing documents with multiple attributes that can go on and off (like active or inactive). They can go up to 1-2 million per index. On a daily basis I need to synchronize those documents who can…

---

## [Clean filter when going back from a drilldown](https://discuss.elastic.co/t/clean-filter-when-going-back-from-a-drilldown/345068)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 7:02am UTC](https://discuss.elastic.co/t/clean-filter-when-going-back-from-a-drilldown/345068 "2023-10-16T07:02:28Z")

</div>

How can we clean filter when going back from a drilldown?

---

## [Question About Snapshot and Restore](https://discuss.elastic.co/t/question-about-snapshot-and-restore/345058)

<div class="topic-metadata">

**Author:** [@Faker](https://discuss.elastic.co/u/Faker)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 2:23am UTC](https://discuss.elastic.co/t/question-about-snapshot-and-restore/345058 "2023-10-16T02:23:16Z")

</div>

Hello, I am struggling with Elasticsearch on Docker and have few questions. Even if you don't know the answers to all the questions, I'd appreciate it if you could answer them. Snapshot and Restore : Does Restoring P…

---

## [Fingerprinting source with Elastic Agent](https://discuss.elastic.co/t/fingerprinting-source-with-elastic-agent/345054)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 12:05am UTC](https://discuss.elastic.co/t/fingerprinting-source-with-elastic-agent/345054 "2023-10-16T00:05:27Z")

</div>

I am ingesting logs into Elastic Cloud using an Elastic Agent. The agent sends logs to a logstash instance where I do some custom enrichment and then it goes to the cloud to be processed by an Elastic ingest pipeline. I…

---

## [Logstash JDBC unable to run multiple statements and ingest data from different tables](https://discuss.elastic.co/t/logstash-jdbc-unable-to-run-multiple-statements-and-ingest-data-from-different-tables/345015)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 7\
**Last updated:** [October 15, 2023, 5:19pm UTC](https://discuss.elastic.co/t/logstash-jdbc-unable-to-run-multiple-statements-and-ingest-data-from-different-tables/345015 "2023-10-15T17:19:10Z")

</div>

Hi, I'm running Logstash version 8.10.2 in a Docker container to ingest data from a MySQL DB into Elastic. I don't know why the first statement is executed but the second one does not execute. Below is my logstash con…

---

## [Duplicate Data](https://discuss.elastic.co/t/duplicate-data/345053)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 3:05pm UTC](https://discuss.elastic.co/t/duplicate-data/345053 "2023-10-15T15:05:10Z")

</div>

Hello, We have time series indexes created daily in Elasticsearch. We upgraded from version 7.10.2 to 8.10.2. While running our tests, we observed that the data coming with the creation of the first index is duplicate. …

---

## [Getting many more results than expected](https://discuss.elastic.co/t/getting-many-more-results-than-expected/345045)

<div class="topic-metadata">

**Author:** [@Shlomo\_Koppel](https://discuss.elastic.co/u/Shlomo_Koppel)\
**Replies:** 3\
**Last updated:** [October 15, 2023, 2:04pm UTC](https://discuss.elastic.co/t/getting-many-more-results-than-expected/345045 "2023-10-15T14:04:12Z")

</div>

Hi, I am making the following query: {'bool': {'must': \[{'terms': {'doc.attributes.type.keyword': \['Attachment', 'Document'\]}}, {'terms': {'doc.internal\_id': \['xxxx83a1c00f7004b52dxxxx'\]}}\], 'filter': \[{'range': {'doc.…

---

## [Reindexing a big index without down time](https://discuss.elastic.co/t/reindexing-a-big-index-without-down-time/345050)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 12:59pm UTC](https://discuss.elastic.co/t/reindexing-a-big-index-without-down-time/345050 "2023-10-15T12:59:19Z")

</div>

Hi. I have a really big index with 100 millions of documents. I want to add some new fields, change existing ones and delete the redundant ones by applying explicit index. I will also use alias to switch the indiced. …

---

## [Filebeat stops sending logs to logstash, "message":"Harvester could not be started on existing file](https://discuss.elastic.co/t/filebeat-stops-sending-logs-to-logstash-message-harvester-could-not-be-started-on-existing-file/345048)

<div class="topic-metadata">

**Author:** [@aleem](https://discuss.elastic.co/u/aleem)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-stops-sending-logs-to-logstash-message-harvester-could-not-be-started-on-existing-file/345048 "2023-10-15T12:46:22Z")

</div>

Filebeat stops sending logs to logstash and needs a manual restart to resume. Logs for specific containers are stopped, while other container's logs are still going to logstash. {"log.level":"error","@timestamp":"2023-1…

---

## [Dashboards are not picking right fields](https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 1\
**Last updated:** [October 15, 2023, 2:07am UTC](https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032 "2023-10-15T02:07:45Z")

</div>

I am sending data from multiple Linux servers to Logstash using Filebeat, which then forwards the data to Elasticsearch after applying parsing rules for SSH logs. The problem is that when I open the default SSH dashboard…

---

## [Logstash Cloudwatch plugin error for bringing logs into Elastic](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error-for-bringing-logs-into-elastic/345037)

<div class="topic-metadata">

**Author:** [@uprashan](https://discuss.elastic.co/u/uprashan)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 2:10am UTC](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error-for-bringing-logs-into-elastic/345037 "2023-10-15T02:10:51Z")

</div>

Hi all. I'm running into the Cloudwatch plugin error for Logstash when trying to bring logs (non metrics) as a stream into Logstash.. I'm running the 8.5.3 version of Logstash... Earlier cloudwatch\_logs plugin doesn't se…

---

## [Using Fields in NEST client library](https://discuss.elastic.co/t/using-fields-in-nest-client-library/345033)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 6:15pm UTC](https://discuss.elastic.co/t/using-fields-in-nest-client-library/345033 "2023-10-14T18:15:05Z")

</div>

When using the Fieds options just to get a selection of fileds using the NEST client library and setting the Source(false), the Hits object's fields property is null. How are we supposed to get access to the values retu…

---

## [Wanted to have alerts in my email when a process goes down. Thanks](https://discuss.elastic.co/t/wanted-to-have-alerts-in-my-email-when-a-process-goes-down-thanks/345030)

<div class="topic-metadata">

**Author:** [@Abhiyash\_Agrawal](https://discuss.elastic.co/u/Abhiyash_Agrawal)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 3:06pm UTC](https://discuss.elastic.co/t/wanted-to-have-alerts-in-my-email-when-a-process-goes-down-thanks/345030 "2023-10-14T15:06:42Z")

</div>

Wants to have an alert in my email when data of pipelines goes down and is it possible to get screen shot of kibana dashboards in the same email. Thanks

---

## [Kafka should include ip](https://discuss.elastic.co/t/kafka-should-include-ip/345029)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 2:42pm UTC](https://discuss.elastic.co/t/kafka-should-include-ip/345029 "2023-10-14T14:42:38Z")

</div>

my logstash has 2 pipelines one is listening for http request and other one is listening kafka The data coming from http pipeline includes host:{ip} and url in \_source section however the data from kafka does not have …

---

## [Logstash - systemd-journald suppressed mensagens](https://discuss.elastic.co/t/logstash-systemd-journald-suppressed-mensagens/344080)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 8\
**Last updated:** [October 14, 2023, 2:10pm UTC](https://discuss.elastic.co/t/logstash-systemd-journald-suppressed-mensagens/344080 "2023-10-14T14:10:38Z")

</div>

Hi, Always when I restarting my logstash I see this message below: Nowadays I have CPU problem and I am trying fix it. I saw a person in the forum talk about change RateLimitBurst parameter into /etc/systemd/journa…

---

## [Testing kibana 8.5](https://discuss.elastic.co/t/testing-kibana-8-5/344727)

<div class="topic-metadata">

**Author:** [@mzm1370](https://discuss.elastic.co/u/mzm1370)\
**Replies:** 3\
**Last updated:** [October 14, 2023, 11:11am UTC](https://discuss.elastic.co/t/testing-kibana-8-5/344727 "2023-10-14T11:11:17Z")

</div>

Hello, I want to put the success and failure logs of Kibana automatic test into the file, please help me

---

## [2GB enough RAM for a 300MB dataset?](https://discuss.elastic.co/t/2gb-enough-ram-for-a-300mb-dataset/345021)

<div class="topic-metadata">

**Author:** [@kiko](https://discuss.elastic.co/u/kiko)\
**Replies:** 1\
**Last updated:** [October 14, 2023, 6:44am UTC](https://discuss.elastic.co/t/2gb-enough-ram-for-a-300mb-dataset/345021 "2023-10-14T06:44:56Z")

</div>

Hi, I'm having a hard time finding the required RAM for a dataset like mine: it's 300 MB in size, and has around 300 products and 250 product categories. Each product's JSON is around 10-15 KB in size.

---

## [Elastic Agent not sending Data to Elastic search From KVM but works for VMWare](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012)

<div class="topic-metadata">

**Author:** [@AnyThink\_A](https://discuss.elastic.co/u/AnyThink_A)\
**Replies:** 4\
**Last updated:** [October 14, 2023, 3:12am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012 "2023-10-14T03:12:04Z")

</div>

Hello Team, In further lab setup. I am facing a strange issue. I have two setups LAB Windows -\> VMware (UBUNTU) Windows -\> VMware (Windows) Both guests are connected through host-only adapter. SANDBOX Windows -\> …

---

## [Developer reference and config value validation](https://discuss.elastic.co/t/developer-reference-and-config-value-validation/345016)

<div class="topic-metadata">

**Author:** [@tlinker13](https://discuss.elastic.co/u/tlinker13)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 8:46pm UTC](https://discuss.elastic.co/t/developer-reference-and-config-value-validation/345016 "2023-10-13T20:46:20Z")

</div>

Hey all, Background: I have to implement a new module and metricset to search LDAP directories. MY config.yml shall look somewhat like that: - module: ldap metricsets: \["ldapsearch"\] enabled: true period: 10s …

---

## [Mounting disk at home/kafka\_data which has 20Gb already and data as well](https://discuss.elastic.co/t/mounting-disk-at-home-kafka-data-which-has-20gb-already-and-data-as-well/344991)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 5\
**Last updated:** [October 13, 2023, 5:33pm UTC](https://discuss.elastic.co/t/mounting-disk-at-home-kafka-data-which-has-20gb-already-and-data-as-well/344991 "2023-10-13T17:33:57Z")

</div>

typ\*\* command lsblk for checking the space added NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT sda 8:0 0 40G 0 disk ├─sda1 8:1 0 …

---

## [CloudFlare Logpull Integration Recovering Log Gaps](https://discuss.elastic.co/t/cloudflare-logpull-integration-recovering-log-gaps/345011)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 4:14pm UTC](https://discuss.elastic.co/t/cloudflare-logpull-integration-recovering-log-gaps/345011 "2023-10-13T16:14:24Z")

</div>

I ran into an issue where the Elastic Agent stopped pulling logs. I resolved that issue by reinstalling the CloudFlare integration. However, I now have a gap in my logs from when it failed to when I got it back online.…

---

## ["Web Server Misconfiguration: Insecure Content-Type Setting" vulnerability detected after version upgrade](https://discuss.elastic.co/t/web-server-misconfiguration-insecure-content-type-setting-vulnerability-detected-after-version-upgrade/344625)

<div class="topic-metadata">

**Author:** [@Septianingrum.17](https://discuss.elastic.co/u/Septianingrum.17)\
**Replies:** 1\
**Last updated:** [October 13, 2023, 2:27pm UTC](https://discuss.elastic.co/t/web-server-misconfiguration-insecure-content-type-setting-vulnerability-detected-after-version-upgrade/344625 "2023-10-13T14:27:36Z")

</div>

After I upgraded the elastic stack to 8.6.0 and carried out a vulnerability scan on Kibana using the microfocus tool, there were vulnerabilities as follows: I have made changes to the Kibana configuration, namely cha…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=397)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=399)
