# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=422

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 423

---

## [Logstash container not receiving log files from Filebeats running on host](https://discuss.elastic.co/t/logstash-container-not-receiving-log-files-from-filebeats-running-on-host/343162)

<div class="topic-metadata">

**Author:** [@David\_Locarno](https://discuss.elastic.co/u/David_Locarno)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 10:48pm UTC](https://discuss.elastic.co/t/logstash-container-not-receiving-log-files-from-filebeats-running-on-host/343162 "2023-09-15T22:48:20Z")

</div>

I am running a RHEL VM with Filebeats installed and three Podman containers running Kibana, Elasticsearch, and Logstash. Almost everything works, except for sending files from Filebeats to my Logstash container's pipelin…

---

## [Cannot parse logs - problem with multiline parse failures](https://discuss.elastic.co/t/cannot-parse-logs-problem-with-multiline-parse-failures/343146)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 4\
**Last updated:** [September 15, 2023, 10:27pm UTC](https://discuss.elastic.co/t/cannot-parse-logs-problem-with-multiline-parse-failures/343146 "2023-09-15T22:27:04Z")

</div>

Hi All, I am having a lot of problems parsing logs especially with different dates and logs having multiline tags. For example: A head (very first 10 lines) of one of my log files, specifically, catalina.out, could be…

---

## [Changing default configuration of Elastic Agent Integration to filter out events before ingestion](https://discuss.elastic.co/t/changing-default-configuration-of-elastic-agent-integration-to-filter-out-events-before-ingestion/343164)

<div class="topic-metadata">

**Author:** [@Sushant\_Bhatnagar](https://discuss.elastic.co/u/Sushant_Bhatnagar)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 9:38pm UTC](https://discuss.elastic.co/t/changing-default-configuration-of-elastic-agent-integration-to-filter-out-events-before-ingestion/343164 "2023-09-15T21:38:27Z")

</div>

Hello, I created an Elastic agent policy to attach it few hosts and while creating it - I checked the Collect agent logs checkbox under Agent Monitoring section. Now in the events in discover tab, I see dataset as "el…

---

## [\[Netflow\] Issues with Module](https://discuss.elastic.co/t/netflow-issues-with-module/343158)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 7:16pm UTC](https://discuss.elastic.co/t/netflow-issues-with-module/343158 "2023-09-15T19:16:02Z")

</div>

Hi! I try to avoid the use of netflow codec of logstash, cause i understand that is deprecated. I configure Netflow Module on filbeat. But does not work. I also configure as an input but still does not work. Netflow …

---

## [Advice needed on making logs available to application developer](https://discuss.elastic.co/t/advice-needed-on-making-logs-available-to-application-developer/341599)

<div class="topic-metadata">

**Author:** [@mubashar.tariq](https://discuss.elastic.co/u/mubashar.tariq)\
**Replies:** 3\
**Last updated:** [September 15, 2023, 6:48pm UTC](https://discuss.elastic.co/t/advice-needed-on-making-logs-available-to-application-developer/341599 "2023-09-15T18:48:25Z")

</div>

Background: We have number of large web applications deployed to WebLogic servers that are running on RedHat Linux 8. Development Teams need access to different logs (e.g. WebLogic, application logs) on these Linux machi…

---

## [Drop filter in Logstash filter not working for the below event](https://discuss.elastic.co/t/drop-filter-in-logstash-filter-not-working-for-the-below-event/343120)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 6:31pm UTC](https://discuss.elastic.co/t/drop-filter-in-logstash-filter-not-working-for-the-below-event/343120 "2023-09-15T18:31:11Z")

</div>

Event in Logstash : { "timestamp" =\> "2023-09-13T05:10:52.527038098Z", "user" =\> "admin", "type" =\> "icd\_postgresql", "status" =\> "INSERT INTO t1 SELECT i/100, i/500 FROM generate\_series(1,1…

---

## [Metricbeat module Apache error - error fetching data: HTTP error 404 in : 404 Not Found](https://discuss.elastic.co/t/metricbeat-module-apache-error-error-fetching-data-http-error-404-in-404-not-found/343078)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 2\
**Last updated:** [September 15, 2023, 6:24pm UTC](https://discuss.elastic.co/t/metricbeat-module-apache-error-error-fetching-data-http-error-404-in-404-not-found/343078 "2023-09-15T18:24:41Z")

</div>

Hi all I having problems when trying to get metrics from my Apache installation running on a Centos 7 VM Env: ECK 2.6.1 1 ES Master Node 8.6.2 running on a single node K3S Kubernetes Cluster installed on Centos 7 Ser…

---

## [Deal with small indices (ILM Policy)](https://discuss.elastic.co/t/deal-with-small-indices-ilm-policy/342979)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 3\
**Last updated:** [September 15, 2023, 4:33pm UTC](https://discuss.elastic.co/t/deal-with-small-indices-ilm-policy/342979 "2023-09-15T16:33:25Z")

</div>

Hello partners! :wave: I have set up an Elastic Stack cluster and i am performing multiple ingestions. Some of these ingestions are abundant, ingesting around 50 GB per day, however, others contain 500... 10000 docs...…

---

## [Srping data elasticsearch document count info using built in reactive client](https://discuss.elastic.co/t/srping-data-elasticsearch-document-count-info-using-built-in-reactive-client/343148)

<div class="topic-metadata">

**Author:** [@D1sturbance](https://discuss.elastic.co/u/D1sturbance)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 2:50pm UTC](https://discuss.elastic.co/t/srping-data-elasticsearch-document-count-info-using-built-in-reactive-client/343148 "2023-09-15T14:50:57Z")

</div>

My problem: I am trying to get indices information: IndexName IndexCreationDate IndexAlias IndexDocumentCount IndexSize I am able to get some of that information via GetIndexResponse mentioned below. Which holds alia…

---

## [Add dynamic date range in CSV post url](https://discuss.elastic.co/t/add-dynamic-date-range-in-csv-post-url/342500)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 2\
**Last updated:** [September 15, 2023, 2:56pm UTC](https://discuss.elastic.co/t/add-dynamic-date-range-in-csv-post-url/342500 "2023-09-15T14:56:20Z")

</div>

I am using ES 7.x and trying to add POST URL from CSV share feature into another system. Is there a way to add date range dynamically Link here because the url provided by UI has fixed date and we do not want to come to …

---

## [EQL Language trouble when creating custom rule](https://discuss.elastic.co/t/eql-language-trouble-when-creating-custom-rule/343144)

<div class="topic-metadata">

**Author:** [@Brandon\_Duffy](https://discuss.elastic.co/u/Brandon_Duffy)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 2:02pm UTC](https://discuss.elastic.co/t/eql-language-trouble-when-creating-custom-rule/343144 "2023-09-15T14:02:43Z")

</div>

Hello, I've been working on this rule for some time now, and it is only partially working. I am able to see the net.exe related alerts populate, and used to see 'systeminfo', 'hostname', 'nslookup', now i do not. I can…

---

## [Kibana Maps world countries does not have names](https://discuss.elastic.co/t/kibana-maps-world-countries-does-not-have-names/342872)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 3\
**Last updated:** [September 15, 2023, 1:08pm UTC](https://discuss.elastic.co/t/kibana-maps-world-countries-does-not-have-names/342872 "2023-09-15T13:08:27Z")

</div>

I chose Data source EMS Boundaries Layer \[world\_countries\] , when I added a new layer to the map. The map does not contain the country names. Please check the attachment. How do I display the names? Thanks.

---

## [Custom filebeat docker image error](https://discuss.elastic.co/t/custom-filebeat-docker-image-error/343140)

<div class="topic-metadata">

**Author:** [@matheuscirillo](https://discuss.elastic.co/u/matheuscirillo)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 1:05pm UTC](https://discuss.elastic.co/t/custom-filebeat-docker-image-error/343140 "2023-09-15T13:05:45Z")

</div>

The custom image configuration section on the docs says that we can do the following to create a customized image: FROM docker.elastic.co/beats/filebeat:8.10.0 COPY --chown=root:filebeat filebeat.yml /usr/share/filebeat…

---

## [One ELK Node is Down](https://discuss.elastic.co/t/one-elk-node-is-down/343041)

<div class="topic-metadata">

**Author:** [@linux\_admin](https://discuss.elastic.co/u/linux_admin)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 12:53pm UTC](https://discuss.elastic.co/t/one-elk-node-is-down/343041 "2023-09-15T12:53:30Z")

</div>

Dear All, I have ELK cluster consists of three nodes elk01, elk02, elk03. One node elk01 is suddenly down. When I check the logs /var/log/elasticsearch/elasticsearch.log of elk01, I found these errors: "\[elk01\] Authent…

---

## [BulkIngester and Integration Testing](https://discuss.elastic.co/t/bulkingester-and-integration-testing/341595)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 7\
**Last updated:** [September 15, 2023, 12:29pm UTC](https://discuss.elastic.co/t/bulkingester-and-integration-testing/341595 "2023-09-15T12:29:29Z")

</div>

Can someone point me to some examples of integration testing while using the BulkIngester? Specifically how to test a class method that uses the BulkIngester. I'm having timing issues with calling flush on the BulkIngest…

---

## [Painless script to convert from HEX to string](https://discuss.elastic.co/t/painless-script-to-convert-from-hex-to-string/343134)

<div class="topic-metadata">

**Author:** [@alextg](https://discuss.elastic.co/u/alextg)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 11:12am UTC](https://discuss.elastic.co/t/painless-script-to-convert-from-hex-to-string/343134 "2023-09-15T11:12:40Z")

</div>

Hi, I need to convert an HEX field to string using Painless script. Please advise how can this be achieved.

---

## [Want to loop post text into MS team Channel but Error](https://discuss.elastic.co/t/want-to-loop-post-text-into-ms-team-channel-but-error/343129)

<div class="topic-metadata">

**Author:** [@rathasatekun](https://discuss.elastic.co/u/rathasatekun)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 10:24am UTC](https://discuss.elastic.co/t/want-to-loop-post-text-into-ms-team-channel-but-error/343129 "2023-09-15T10:24:48Z")

</div>

Hi Elastic team I have watcher data from search from indices and then make text for post into ms team channel but i can not send text value into ms team channel it's error: "Newtonsoft.Json.JsonReaderException: After pa…

---

## [Read-only URL Repository](https://discuss.elastic.co/t/read-only-url-repository/343104)

<div class="topic-metadata">

**Author:** [@frh](https://discuss.elastic.co/u/frh)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 10:17am UTC](https://discuss.elastic.co/t/read-only-url-repository/343104 "2023-09-15T10:17:45Z")

</div>

Hi, I just created read-only URL repository and give it a name as "test". I got this error when verify repository: { "error": { "root\_cause": \[ { "type": "repository\_exception", "reason": "\[…

---

## [Scores are inconsistent with data and query](https://discuss.elastic.co/t/scores-are-inconsistent-with-data-and-query/343121)

<div class="topic-metadata">

**Author:** [@appsol](https://discuss.elastic.co/u/appsol)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 9:03am UTC](https://discuss.elastic.co/t/scores-are-inconsistent-with-data-and-query/343121 "2023-09-15T09:03:05Z")

</div>

Hello, My document has a title field and an intro field. I have given greater importance to the title field over the intro field in my query, yet all other fields being equal, the intro field is getting a higher score t…

---

## [Not able to connect to elastic from kibana](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-from-kibana/341652)

<div class="topic-metadata">

**Author:** [@chitra\_perumal](https://discuss.elastic.co/u/chitra_perumal)\
**Replies:** 16\
**Last updated:** [September 15, 2023, 8:00am UTC](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-from-kibana/341652 "2023-09-15T08:00:12Z")

</div>

Hello, I am trying to set up the OIDC authentication for Kibana in SSO . I have followed the steps from elastic guide. The CA and HTTP certificates are created as per the details provided in above link. The elastic is…

---

## [Adding Documents via REST API in ElasticSearch](https://discuss.elastic.co/t/adding-documents-via-rest-api-in-elasticsearch/343102)

<div class="topic-metadata">

**Author:** [@sanyam](https://discuss.elastic.co/u/sanyam)\
**Replies:** 4\
**Last updated:** [September 15, 2023, 6:45am UTC](https://discuss.elastic.co/t/adding-documents-via-rest-api-in-elasticsearch/343102 "2023-09-15T06:45:18Z")

</div>

I am getting this error while trying to run this code to add data/document In Elasticsearch version 6.4.1 in windows curl -X POST "localhost:9200/clusters/\_doc" -H "Content-Type" : application/json -d "{ "field1":"valu…

---

## [Filebeat not sending docker logs to logstash after enabling x-pack security features](https://discuss.elastic.co/t/filebeat-not-sending-docker-logs-to-logstash-after-enabling-x-pack-security-features/343100)

<div class="topic-metadata">

**Author:** [@Ajai\_Raj](https://discuss.elastic.co/u/Ajai_Raj)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 5:02am UTC](https://discuss.elastic.co/t/filebeat-not-sending-docker-logs-to-logstash-after-enabling-x-pack-security-features/343100 "2023-09-15T05:02:01Z")

</div>

Please help me in this i've been trying to create a user in ELK after enabling the x-pack security feature in my elasticsearch.yml file. The docker container logs are not syncing in kibana after i enable the security fea…

---

## [Logstash Grok Pattern Watchguard Firewall](https://discuss.elastic.co/t/logstash-grok-pattern-watchguard-firewall/342317)

<div class="topic-metadata">

**Author:** [@Simon7](https://discuss.elastic.co/u/Simon7)\
**Replies:** 6\
**Last updated:** [September 15, 2023, 5:22am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-watchguard-firewall/342317 "2023-09-15T05:22:41Z")

</div>

Hey Guys, this is my first topic here in this forum. I have established an Elasticsearch log management in our company. I'm having a bit of trouble with the grok pattern. If I can't use integrations, I need to create m…

---

## [Elasticsearch error in running service JAVA error](https://discuss.elastic.co/t/elasticsearch-error-in-running-service-java-error/342782)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 15\
**Last updated:** [September 15, 2023, 4:51am UTC](https://discuss.elastic.co/t/elasticsearch-error-in-running-service-java-error/342782 "2023-09-15T04:51:26Z")

</div>

systemctl status elasticsearch × elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled) Active: failed (Result: exit-code) since Tue 2…

---

## [URI too long with custom routing](https://discuss.elastic.co/t/uri-too-long-with-custom-routing/342993)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 7\
**Last updated:** [September 15, 2023, 2:55am UTC](https://discuss.elastic.co/t/uri-too-long-with-custom-routing/342993 "2023-09-15T02:55:25Z")

</div>

Hi Team, I'm experimenting with custom routing to bring down the latency of search requests in my cluster. The routing\_ids are assigned in groups of N. For ex. a key with 1000 associated documents will be mapped to 10 d…

---

## [Error while using .scan() function call](https://discuss.elastic.co/t/error-while-using-scan-function-call/343039)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 6\
**Last updated:** [September 15, 2023, 2:17am UTC](https://discuss.elastic.co/t/error-while-using-scan-function-call/343039 "2023-09-15T02:17:54Z")

</div>

Hi, I have the following Python code to query my ES cluster (v8.8.0). from elasticsearch import Elasticsearch from elasticsearch\_dsl import Search for i in range(0, 100): s = Search(using=es, index=index\_name) \\ …

---

## [Can Logstash use a file in an Azure BLOB container as its direct input?](https://discuss.elastic.co/t/can-logstash-use-a-file-in-an-azure-blob-container-as-its-direct-input/343080)

<div class="topic-metadata">

**Author:** [@Eugene\_Goldberg](https://discuss.elastic.co/u/Eugene_Goldberg)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 9:34pm UTC](https://discuss.elastic.co/t/can-logstash-use-a-file-in-an-azure-blob-container-as-its-direct-input/343080 "2023-09-14T21:34:13Z")

</div>

Greetings, I am trying to configure Logstash to ingest changes to a JSON file which is stored in Azure BLOB storage container. There used to be an input plugin called \`\`\` logstash-input-azureblob When I attempted to i…

---

## [How to set up alert based on value change over given amount of time](https://discuss.elastic.co/t/how-to-set-up-alert-based-on-value-change-over-given-amount-of-time/341083)

<div class="topic-metadata">

**Author:** [@Ruben\_Bajo](https://discuss.elastic.co/u/Ruben_Bajo)\
**Replies:** 6\
**Last updated:** [September 14, 2023, 9:08pm UTC](https://discuss.elastic.co/t/how-to-set-up-alert-based-on-value-change-over-given-amount-of-time/341083 "2023-09-14T21:08:07Z")

</div>

I have a costume log that contains a value that constantly increases over the day and gets back to 0 every midnight. I would like to set up a rule that can alert if this growth stops but I did not find a way to do that. …

---

## [Termsuggester in new Elasticsearch client library](https://discuss.elastic.co/t/termsuggester-in-new-elasticsearch-client-library/343070)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 8:38pm UTC](https://discuss.elastic.co/t/termsuggester-in-new-elasticsearch-client-library/343070 "2023-09-14T20:38:02Z")

</div>

We could not find any option to supply accuracy with term suggest. But Elasticsearch core lib provided that option. https://www.javadoc.io/doc/org.elasticsearch/elasticsearch/latest/org.elasticsearch.server/org/elastics…

---

## [ELK snapshot ERROR](https://discuss.elastic.co/t/elk-snapshot-error/342798)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 10:06am UTC](https://discuss.elastic.co/t/elk-snapshot-error/342798 "2023-09-12T10:06:49Z")

</div>

Hi, when i try to make snapchot of mi cluster at NFS configuration it fails with this error: { "type": "snapshot\_exception", "reason": "\[backups:snapshot-diarias-2023.09.12-y65vkdogt8y\_lbs\_ajcoaq/OuM8ZsvmQnqhHOczBm0…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=421)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=423)
