# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=412

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 413

---

## [Filebeat modules vs filestream input](https://discuss.elastic.co/t/filebeat-modules-vs-filestream-input/342871)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 29\
**Last updated:** [September 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/filebeat-modules-vs-filestream-input/342871 "2023-09-27T18:45:19Z")

</div>

Hello, I'm trying to configure filebeat to read a Linux system and auth log file. when I'm using datastream input, the data isn't parsed well; everything is let into the message field without any processing. When I use…

---

## [Heartbeat configuration for 1000+ IPs](https://discuss.elastic.co/t/heartbeat-configuration-for-1000-ips/342803)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 4\
**Last updated:** [September 27, 2023, 6:41pm UTC](https://discuss.elastic.co/t/heartbeat-configuration-for-1000-ips/342803 "2023-09-27T18:41:03Z")

</div>

Hi gurus, We have a requirement to monitor1000+ IPs using Heartbeat 7.17.4. As the baseline test, we pinged one IP address (let's call it device A) with cmd ping and the latency is around 30ms. Then we started adding …

---

## [OIDC with Azure not logged in on Kibana](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680)

<div class="topic-metadata">

**Author:** [@esanolad](https://discuss.elastic.co/u/esanolad)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 6:40pm UTC](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680 "2023-09-27T18:40:38Z")

</div>

Hi all My company is configuring SSO using OIDC on AZURE, everything looks fine but whenever user tries to authenticate, it takes them back to the to the login page. I have checked the logs, there are no errors and ther…

---

## [Delete .reporting index](https://discuss.elastic.co/t/delete-reporting-index/343482)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 6:05pm UTC](https://discuss.elastic.co/t/delete-reporting-index/343482 "2023-09-27T18:05:05Z")

</div>

This is regarding my last raised topic - Kibana 7.17.3 So i have multiple csv reports generated and i want to delete them now those reports comes under .reportinf-\* index. So when i am trying to delete those i am gett…

---

## [Filebeat 8.7.1 utilizing too much of Memory and pods get OOM Killed](https://discuss.elastic.co/t/filebeat-8-7-1-utilizing-too-much-of-memory-and-pods-get-oom-killed/344004)

<div class="topic-metadata">

**Author:** [@gsekar](https://discuss.elastic.co/u/gsekar)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 4:12pm UTC](https://discuss.elastic.co/t/filebeat-8-7-1-utilizing-too-much-of-memory-and-pods-get-oom-killed/344004 "2023-09-27T16:12:19Z")

</div>

We are seeing filebeat pods using a lot of memory and restarting at random intervals due to OOM. Any solution for this? Even in a 3 node kubernetes cluster with very little resources running seeing the issue.

---

## [Elastic search mongo db (elastic-connectors) real-time sync configuration?](https://discuss.elastic.co/t/elastic-search-mongo-db-elastic-connectors-real-time-sync-configuration/343934)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 3:26pm UTC](https://discuss.elastic.co/t/elastic-search-mongo-db-elastic-connectors-real-time-sync-configuration/343934 "2023-09-27T15:26:59Z")

</div>

May I know how to configure Elasticsearch mongo db real-time sync config using elastic connector? Docker: container\_name: els\_connector image: docker.elastic.co/enterprise-search/elastic-connectors:8.10.2.0-SNAPSHOT Im…

---

## [Connecting to ELK from databricks](https://discuss.elastic.co/t/connecting-to-elk-from-databricks/343998)

<div class="topic-metadata">

**Author:** [@ksasidhar1103](https://discuss.elastic.co/u/ksasidhar1103)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 2:35pm UTC](https://discuss.elastic.co/t/connecting-to-elk-from-databricks/343998 "2023-09-27T14:35:10Z")

</div>

Hi, I'm trying to load data into databrciks from ELK with the help of API using python script. Can you suggest me the best option that I can read the huge data like 200 million in single shot. The method now I'm using i…

---

## [Maximum number of attempts exceeded. Restart Kibana to generate a new code and retry](https://discuss.elastic.co/t/maximum-number-of-attempts-exceeded-restart-kibana-to-generate-a-new-code-and-retry/343997)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 2:18pm UTC](https://discuss.elastic.co/t/maximum-number-of-attempts-exceeded-restart-kibana-to-generate-a-new-code-and-retry/343997 "2023-09-27T14:18:00Z")

</div>

Hi fellows, I installed elk stack as docker containers with podman in RHEL9. Now after generating the enrollment token for elasticsearch I would like to configure KIBANA but I get this error message: " Maximum number …

---

## [Downloading large amount of logs as CSV using Kibana/Eland](https://discuss.elastic.co/t/downloading-large-amount-of-logs-as-csv-using-kibana-eland/343768)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 8\
**Last updated:** [September 27, 2023, 2:04pm UTC](https://discuss.elastic.co/t/downloading-large-amount-of-logs-as-csv-using-kibana-eland/343768 "2023-09-27T14:04:31Z")

</div>

Hi, I am using Elastic Cloud and am trying to download a large among of logs (over 800 million lines of logs, over span of a few months) as CSV. However when I tried downloading from Discover \> Share \> Generate CSV, it d…

---

## [Filebeat Cisco Modules for Nexus](https://discuss.elastic.co/t/filebeat-cisco-modules-for-nexus/343914)

<div class="topic-metadata">

**Author:** [@acardona](https://discuss.elastic.co/u/acardona)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 5:11pm UTC](https://discuss.elastic.co/t/filebeat-cisco-modules-for-nexus/343914 "2023-09-26T17:11:12Z")

</div>

Hi, I am trying to set up syslogging from a nexus switch to feed into Filebeat's Cisco module that would then feed into Elasticsearch. I tend to get the same error message after enabling the cisco module and running thi…

---

## [Shipping access logs logstash to logstash using http plugins](https://discuss.elastic.co/t/shipping-access-logs-logstash-to-logstash-using-http-plugins/343980)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 12:42pm UTC](https://discuss.elastic.co/t/shipping-access-logs-logstash-to-logstash-using-http-plugins/343980 "2023-09-27T12:42:38Z")

</div>

Hi We have a setup where we ship logs between systems via logstash to logstash using http plugins. The access logs are in ecs format. The problem is, logstash overwrites http, url and others fields, with it's own transp…

---

## [Breaklines character](https://discuss.elastic.co/t/breaklines-character/343840)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 11:50am UTC](https://discuss.elastic.co/t/breaklines-character/343840 "2023-09-27T11:50:31Z")

</div>

Good morning, I have an easy question about the text field when in the string I have breaklines. I have seen that in this moment when I read the index field I something like this: "enEN" : """- Characteristics of the g…

---

## [Elastic-Agent is not getting installed](https://discuss.elastic.co/t/elastic-agent-is-not-getting-installed/343976)

<div class="topic-metadata">

**Author:** [@syedsyed](https://discuss.elastic.co/u/syedsyed)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 11:07am UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-installed/343976 "2023-09-27T11:07:29Z")

</div>

Hello, I have 2 Problems, i have installed the integration of sonicwall in Elasticsearch and enrolled the elastic agent in fleet server by using the debian package, but the service is not getting started and iam getting …

---

## [Report data from Splunk to Elastic](https://discuss.elastic.co/t/report-data-from-splunk-to-elastic/343975)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:47am UTC](https://discuss.elastic.co/t/report-data-from-splunk-to-elastic/343975 "2023-09-27T10:47:47Z")

</div>

So, I have been sending log data to Splunk. And I want to "catch" the data that is sent to Splunk and forward it to Elastic. I tried with Integrations but that did not work. Does anybody have any ideas on how to solve th…

---

## [Json multiline codec is not working and messages are not getting parsed](https://discuss.elastic.co/t/json-multiline-codec-is-not-working-and-messages-are-not-getting-parsed/343172)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 16\
**Last updated:** [September 27, 2023, 10:44am UTC](https://discuss.elastic.co/t/json-multiline-codec-is-not-working-and-messages-are-not-getting-parsed/343172 "2023-09-27T10:44:41Z")

</div>

Hi Team, I an working on logstash json parser and messages are not getting parsed; any clue what could be wrong? Here are original messages \[ { "time": "12/Aug/2023:13:20:52 +0000", "source\_ip": "117.193.217.44",…

---

## [Logstash 8.10.2 fails to start in docker without any log output](https://discuss.elastic.co/t/logstash-8-10-2-fails-to-start-in-docker-without-any-log-output/343973)

<div class="topic-metadata">

**Author:** [@tzfun](https://discuss.elastic.co/u/tzfun)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:36am UTC](https://discuss.elastic.co/t/logstash-8-10-2-fails-to-start-in-docker-without-any-log-output/343973 "2023-09-27T10:36:03Z")

</div>

I pulled image docker.elastic.co/logstash/logstash:8.10.2 to run a container, and it works in docker on mac os but neither works in docker on Debian 11. Docker for mac and debian 11 are both version 24.0.6. There is no…

---

## [CircuitBreakingException when load huge data by bulk write](https://discuss.elastic.co/t/circuitbreakingexception-when-load-huge-data-by-bulk-write/343410)

<div class="topic-metadata">

**Author:** [@ericsoul](https://discuss.elastic.co/u/ericsoul)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 9:24am UTC](https://discuss.elastic.co/t/circuitbreakingexception-when-load-huge-data-by-bulk-write/343410 "2023-09-27T09:24:18Z")

</div>

I got many errors like Caused by: org.elasticsearch.common.breaker.CircuitBreakingException: \[parent\] Data too large, data for \[indices:data/write/bulk\[s\]\] would be \[30897445494/28.7gb\], which is larger than the limit…

---

## [How to create finger print ingest pipeline for nested field?](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845)

<div class="topic-metadata">

**Author:** [@mhsankar](https://discuss.elastic.co/u/mhsankar)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845 "2023-09-27T09:23:58Z")

</div>

Hi every body. I have a mapping with nested field. I want to identify a finger print for every rows in nested field . how can create this ingest pipeline? I\`m using Elasticsearch v 7.17.7 my mapping: PUT test-neste…

---

## [Performance is low when using cluster mode](https://discuss.elastic.co/t/performance-is-low-when-using-cluster-mode/343964)

<div class="topic-metadata">

**Author:** [@AndreWanga](https://discuss.elastic.co/u/AndreWanga)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/performance-is-low-when-using-cluster-mode/343964 "2023-09-27T09:23:12Z")

</div>

Elasticsearch Version 7.4.0 Java Version from official docker image OS Version from official docker image Problem Description I have set up an Elasticsearch cluster using the official Elasticsearch image. I have confi…

---

## [ElasticSearch Cluster with two Nodes](https://discuss.elastic.co/t/elasticsearch-cluster-with-two-nodes/343874)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 8:37am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-with-two-nodes/343874 "2023-09-27T08:37:15Z")

</div>

I've always appreciated the support of this community, and I hope it can assist me once more. Here's the situation: I currently have Elasticsearch installed on my VM1, but I've encountered disk space issues, and the clus…

---

## [Getting one of index in red and did rolling restart of elastic cluster but still in red](https://discuss.elastic.co/t/getting-one-of-index-in-red-and-did-rolling-restart-of-elastic-cluster-but-still-in-red/343957)

<div class="topic-metadata">

**Author:** [@Jeet\_Lal\_Bhatrai](https://discuss.elastic.co/u/Jeet_Lal_Bhatrai)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 8:27am UTC](https://discuss.elastic.co/t/getting-one-of-index-in-red-and-did-rolling-restart-of-elastic-cluster-but-still-in-red/343957 "2023-09-27T08:27:54Z")

</div>

Getting one of index in red and did rolling restart of elastic cluster but still in red

---

## [Tutorial elastic search full text query search engine](https://discuss.elastic.co/t/tutorial-elastic-search-full-text-query-search-engine/343929)

<div class="topic-metadata">

**Author:** [@cmansilla](https://discuss.elastic.co/u/cmansilla)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 5:36am UTC](https://discuss.elastic.co/t/tutorial-elastic-search-full-text-query-search-engine/343929 "2023-09-27T05:36:23Z")

</div>

Hi im looking for tutorial about build a search engine (proof of concept in windows or centos) with Elasticsearch, any idea where i can start?, we have about 500k files (html, word and pdf files) for start, we was search…

---

## [How can I fix this to suggest phrases after say, three characters have been entered?](https://discuss.elastic.co/t/how-can-i-fix-this-to-suggest-phrases-after-say-three-characters-have-been-entered/343755)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 7\
**Last updated:** [September 27, 2023, 4:34am UTC](https://discuss.elastic.co/t/how-can-i-fix-this-to-suggest-phrases-after-say-three-characters-have-been-entered/343755 "2023-09-27T04:34:30Z")

</div>

My query { "suggest": { "text" : "Tes", "simple\_phrase" : { "phrase" : { "field" : "Active\_Substance\_mstr.trigram", "size" : 1, "max\_errors" : 6, "direct\_generator" : \[ { "field" : "Active\_Substan…

---

## [Please suggest best mechanism to sync from Mongo db to elastic search in kubernetes (on prem)?](https://discuss.elastic.co/t/please-suggest-best-mechanism-to-sync-from-mongo-db-to-elastic-search-in-kubernetes-on-prem/343937)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 4:22am UTC](https://discuss.elastic.co/t/please-suggest-best-mechanism-to-sync-from-mongo-db-to-elastic-search-in-kubernetes-on-prem/343937 "2023-09-27T04:22:33Z")

</div>

Please suggest best mechanism to sync from Mongo db to Elasticsearch in kubernetes (on prem)? Thank you

---

## [How to replace fleet tls cert when expired?](https://discuss.elastic.co/t/how-to-replace-fleet-tls-cert-when-expired/343941)

<div class="topic-metadata">

**Author:** [@chengye233](https://discuss.elastic.co/u/chengye233)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 2:11am UTC](https://discuss.elastic.co/t/how-to-replace-fleet-tls-cert-when-expired/343941 "2023-09-27T02:11:58Z")

</div>

Hi, I'm using fleet -server with tls cert. Recently, the cert will be expired and I need to replace a new one. All elastic-stack version is 8.4 Last year, I used this command to install: sudo elastic-agent-8.4.3-linux…

---

## [\[indices:admin/flush\[s\]\[r\]\] is unauthorized for user \[user\] with effective roles \[grant\_kibana\_system\_indices,superuser\] on restricted indices \[my-restricted-index\], this action is granted by the index privileges \[maintenance,manage,all\]](https://discuss.elastic.co/t/indices-admin-flush-s-r-is-unauthorized-for-user-user-with-effective-roles-grant-kibana-system-indices-superuser-on-restricted-indices-my-restricted-index-this-action-is-granted-by-the-index-privileges-maintenance-manage-all/343629)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 11:32pm UTC](https://discuss.elastic.co/t/indices-admin-flush-s-r-is-unauthorized-for-user-user-with-effective-roles-grant-kibana-system-indices-superuser-on-restricted-indices-my-restricted-index-this-action-is-granted-by-the-index-privileges-maintenance-manage-all/343629 "2023-09-26T23:32:53Z")

</div>

Continuing the discussion from Action \[indices:admin/flush\[s\]\] is unauthorized for user \[admin\] with roles \[superuser\] on restricted indices \[.kibana\_task\_manager\_7.17.5\_001\], this action is granted by the index privileg…

---

## [Elastic connectors release version download error](https://discuss.elastic.co/t/elastic-connectors-release-version-download-error/343933)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 9:45pm UTC](https://discuss.elastic.co/t/elastic-connectors-release-version-download-error/343933 "2023-09-26T21:45:42Z")

</div>

Hi, May I know how to get the elastic connector release version (I can successfully download and install snap shot version but getting an error during the release version) ? container\_name: els\_connector image: docker…

---

## [Mysql slow log](https://discuss.elastic.co/t/mysql-slow-log/343917)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 8:28pm UTC](https://discuss.elastic.co/t/mysql-slow-log/343917 "2023-09-26T20:28:54Z")

</div>

Hi all, I am not able to successfully parse Mysql's slow log using logstash. The log file: # Time: 2018-02-27T09:20:14.122543Z # User@Host: user\[user\] @ \[nnn.nnn.nnn.nn\] Id: 148 # Query\_time: 10.275441 Lock\_time: …

---

## [Term query by \_id very slow (30s+) occasionally](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305)

<div class="topic-metadata">

**Author:** [@May\_Zeng](https://discuss.elastic.co/u/May_Zeng)\
**Replies:** 20\
**Last updated:** [September 26, 2023, 8:10pm UTC](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305 "2023-09-26T20:10:48Z")

</div>

Mapping: { "dynamic": "strict", "\_source": { "enabled": false }, "properties": { "data": { "type": "binary", "doc\_values": false, "store": true } } } Query: {"query":{ "bool" …

---

## [Easy way to parse flattened data type?](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:59pm UTC](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926 "2023-09-26T19:59:21Z")

</div>

While I understand the reasoning behind the flattened data type, is there an easy way to split key value pairs out as their own field to use with dashboards / aggregations etc. IE - m365\_defender.event.activity.objects …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=411)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=413)
