# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=425

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 426

---

## [Error: could not parse \[webhook\] action failed parsing http request template](https://discuss.elastic.co/t/error-could-not-parse-webhook-action-failed-parsing-http-request-template/342917)

<div class="topic-metadata">

**Author:** [@rathasatekun](https://discuss.elastic.co/u/rathasatekun)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 7:38am UTC](https://discuss.elastic.co/t/error-could-not-parse-webhook-action-failed-parsing-http-request-template/342917 "2023-09-13T07:38:59Z")

</div>

I try to create Watcher , when i save it error could not parse \[webhook\] action \[42407423-32c4-4a72-aedf-03e31c4d6856/xxxx\_webhook\]. failed parsing http request template "actions": { "gosd\_webhook": { "transform": { …

---

## [Logstash output to loki](https://discuss.elastic.co/t/logstash-output-to-loki/342910)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 7:04am UTC](https://discuss.elastic.co/t/logstash-output-to-loki/342910 "2023-09-13T07:04:39Z")

</div>

Hi is there any way to send data from logstash to loki or promtial or grafana?

---

## [Elastic search response parsing error](https://discuss.elastic.co/t/elastic-search-response-parsing-error/342909)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 6:59am UTC](https://discuss.elastic.co/t/elastic-search-response-parsing-error/342909 "2023-09-13T06:59:17Z")

</div>

I am using 7.4 El;asticSearchClient and querying to Elasticsearch. I am getting response in profile object like below "profile": { "shards": \[ { "id": "\[GArOi1iwQHGY2qpSalRgHw\]\[hbs-search-3\]\[0\]", "searches": \[ { …

---

## [How to get iml policy's use by in ES 7.10?](https://discuss.elastic.co/t/how-to-get-iml-policys-use-by-in-es-7-10/342776)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 6:20am UTC](https://discuss.elastic.co/t/how-to-get-iml-policys-use-by-in-es-7-10/342776 "2023-09-13T06:20:20Z")

</div>

The \_ilm/policy/my\_policy api can get which indices use this policy in current version, but in 7.10, the response does not contains in\_use\_by info. How to get the similar info(in\_use\_by) in ES 7.10? I noticed Kibana c…

---

## [Kibana status is Yellow due to plugins degraded (after upgrade to version 8.8.2)](https://discuss.elastic.co/t/kibana-status-is-yellow-due-to-plugins-degraded-after-upgrade-to-version-8-8-2/342901)

<div class="topic-metadata">

**Author:** [@chethan\_m](https://discuss.elastic.co/u/chethan_m)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 5:33am UTC](https://discuss.elastic.co/t/kibana-status-is-yellow-due-to-plugins-degraded-after-upgrade-to-version-8-8-2/342901 "2023-09-13T05:33:18Z")

</div>

Hi, I just upgraded elasticseach/ kibana to 8.8.2. Cluster health is Green. But Kibana status is Yellow (when I navigate to http:///status ) What is see is there are lot of plugins in yellow status with the message de…

---

## [What happens if my Elasticsearch cluster has only two nodes with a significant difference in disk storage space?](https://discuss.elastic.co/t/what-happens-if-my-elasticsearch-cluster-has-only-two-nodes-with-a-significant-difference-in-disk-storage-space/342895)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 4:06am UTC](https://discuss.elastic.co/t/what-happens-if-my-elasticsearch-cluster-has-only-two-nodes-with-a-significant-difference-in-disk-storage-space/342895 "2023-09-13T04:06:24Z")

</div>

According to the official documentation, when the disk space reaches 85%, replica allocation becomes challenging, at 90% replicas start getting relocated to other nodes (but since I have only two nodes and the principle …

---

## [Identify what a ".save" file is and its purpose](https://discuss.elastic.co/t/identify-what-a-save-file-is-and-its-purpose/342750)

<div class="topic-metadata">

**Author:** [@sampad1](https://discuss.elastic.co/u/sampad1)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 1:22am UTC](https://discuss.elastic.co/t/identify-what-a-save-file-is-and-its-purpose/342750 "2023-09-13T01:22:38Z")

</div>

After deleting some documents from an index, I noticed a compound-file (.cfs) .save file extension as in \_01.cfs.save . I have looked for this file in open source docs/searches and within the community, but I have been u…

---

## [File input not sending to Elasticsearch](https://discuss.elastic.co/t/file-input-not-sending-to-elasticsearch/342891)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 12:55am UTC](https://discuss.elastic.co/t/file-input-not-sending-to-elasticsearch/342891 "2023-09-13T00:55:05Z")

</div>

Hi I am just wondering if someone could look over these relevant portions of my Logstash config to see if there is an issue: input { file { path =\> "/etc/elasticsearch/scripts/otherScripts/fortune.txt" codec =\>…

---

## [Filebeat processor not doing anything](https://discuss.elastic.co/t/filebeat-processor-not-doing-anything/342890)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 11:11pm UTC](https://discuss.elastic.co/t/filebeat-processor-not-doing-anything/342890 "2023-09-12T23:11:49Z")

</div>

I'm trying to use a processor to split up syslog messages into separate fields (using the '=' character as a delimiter). Here's my processor: - type: syslog format: auto protocol.udp: host: "0.0.0.0:9002" tags…

---

## [Syslog to BigQuery help](https://discuss.elastic.co/t/syslog-to-bigquery-help/342816)

<div class="topic-metadata">

**Author:** [@Russ\_Starr](https://discuss.elastic.co/u/Russ_Starr)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 8:53pm UTC](https://discuss.elastic.co/t/syslog-to-bigquery-help/342816 "2023-09-12T20:53:04Z")

</div>

Hi, I am new to logstash and I've been doing some reading and grok debugging. My goal is really simple. I have a Linux box with logstash and I want to receive syslog messages from all my systems and forward them to Googl…

---

## [Error: ElasticSearch won't start when downgraded from 8.9.2 to 8.4.1](https://discuss.elastic.co/t/error-elasticsearch-wont-start-when-downgraded-from-8-9-2-to-8-4-1/342879)

<div class="topic-metadata">

**Author:** [@ujosyula](https://discuss.elastic.co/u/ujosyula)\
**Replies:** 8\
**Last updated:** [September 12, 2023, 8:52pm UTC](https://discuss.elastic.co/t/error-elasticsearch-wont-start-when-downgraded-from-8-9-2-to-8-4-1/342879 "2023-09-12T20:52:35Z")

</div>

I see this error when I try to downgrade. The version of elasticsearch is 8.4.1, but the service won't start. \[2023-09-12T09:52:39,253\]\[ERROR\]\[o.e.b.Elasticsearch \] fatal exception while booting Elasticsearch j…

---

## [How extract a value from grock pattern in a new field](https://discuss.elastic.co/t/how-extract-a-value-from-grock-pattern-in-a-new-field/342855)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 7:38pm UTC](https://discuss.elastic.co/t/how-extract-a-value-from-grock-pattern-in-a-new-field/342855 "2023-09-12T19:38:10Z")

</div>

Hi, I'm trying to create new field called Systeme from a grock pattern whitch match the value of Systeme but it's always empty does anyone have an idea about how to do that. I'm using ingest pipeline like this: "gro…

---

## [Read the current date file in filebeat](https://discuss.elastic.co/t/read-the-current-date-file-in-filebeat/342726)

<div class="topic-metadata">

**Author:** [@Golam\_Rabbi](https://discuss.elastic.co/u/Golam_Rabbi)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 7:08pm UTC](https://discuss.elastic.co/t/read-the-current-date-file-in-filebeat/342726 "2023-09-12T19:08:19Z")

</div>

I have some custom log files for my company. The log file naming pattern is like this "api\_datalogger\_11-09-23". Here 11-09-23 means that the log file of September 11, 2023. Now I want to set my filebeat inputs to read t…

---

## [Logstash 8.9.0 docker logs to stdout. how to provide custom path for it?](https://discuss.elastic.co/t/logstash-8-9-0-docker-logs-to-stdout-how-to-provide-custom-path-for-it/342594)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 7:07pm UTC](https://discuss.elastic.co/t/logstash-8-9-0-docker-logs-to-stdout-how-to-provide-custom-path-for-it/342594 "2023-09-12T19:07:53Z")

</div>

What is the file and path that needs to changed to provide custom log path for logstash-plain.log and so on. Please advise

---

## [Getting started graph analytics 7.17](https://discuss.elastic.co/t/getting-started-graph-analytics-7-17/342881)

<div class="topic-metadata">

**Author:** [@hud](https://discuss.elastic.co/u/hud)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 6:24pm UTC](https://discuss.elastic.co/t/getting-started-graph-analytics-7-17/342881 "2023-09-12T18:24:28Z")

</div>

hi all am trying to recreate graph analytics like that from siren Wondering if there was a tutorial / sample data for getting started in creating the graphs. Not sure if this is available on 7.17. Best Hud

---

## [How to use frozen storage the right way](https://discuss.elastic.co/t/how-to-use-frozen-storage-the-right-way/342839)

<div class="topic-metadata">

**Author:** [@axel\_r](https://discuss.elastic.co/u/axel_r)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 4:08pm UTC](https://discuss.elastic.co/t/how-to-use-frozen-storage-the-right-way/342839 "2023-09-12T16:08:12Z")

</div>

Hello everyone, I'd like some clarification and information on data tiers frozen in an Elastic Cloud environment. I'm not sure if I understand how this works and I can't find any documentation that answers my questions…

---

## [Bulk import role mappings from one cluster to another via API](https://discuss.elastic.co/t/bulk-import-role-mappings-from-one-cluster-to-another-via-api/342869)

<div class="topic-metadata">

**Author:** [@AndrewDatTeranet](https://discuss.elastic.co/u/AndrewDatTeranet)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 4:16pm UTC](https://discuss.elastic.co/t/bulk-import-role-mappings-from-one-cluster-to-another-via-api/342869 "2023-09-12T16:16:29Z")

</div>

I am attempting to dump all role mappings out of one cluster into another by using the Role Mapping API. I use the generic: GET /\_security/role\_mapping to dump all the mappings but cannot find a way to easily bulk imp…

---

## [Painless Elasticsearch update do not handle big numbers](https://discuss.elastic.co/t/painless-elasticsearch-update-do-not-handle-big-numbers/342633)

<div class="topic-metadata">

**Author:** [@DidierB](https://discuss.elastic.co/u/DidierB)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 4:10pm UTC](https://discuss.elastic.co/t/painless-elasticsearch-update-do-not-handle-big-numbers/342633 "2023-09-12T16:10:37Z")

</div>

Hello, I'm using an index that contains big numbers (tracking data byte count per IP). Each time I see an IP in the log I extract the size of the request and add it to an index with the IP as a key. The index has a mapp…

---

## [Anyone have an easy way to make Metricbeat use Time Series Data Streams (TSDS)?](https://discuss.elastic.co/t/anyone-have-an-easy-way-to-make-metricbeat-use-time-series-data-streams-tsds/342375)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 3:17pm UTC](https://discuss.elastic.co/t/anyone-have-an-easy-way-to-make-metricbeat-use-time-series-data-streams-tsds/342375 "2023-09-12T15:17:44Z")

</div>

Long story short, we need to shrink our resource usage with our Elastic Stack. Part of my attempts at that has been implementing down sampling. But, after finally reading the docs carefully enough, I found out that we ne…

---

## [Filebeat registry/log.json size keeps increasing though there are no new log entries in my application log](https://discuss.elastic.co/t/filebeat-registry-log-json-size-keeps-increasing-though-there-are-no-new-log-entries-in-my-application-log/342757)

<div class="topic-metadata">

**Author:** [@palansk](https://discuss.elastic.co/u/palansk)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 3:14pm UTC](https://discuss.elastic.co/t/filebeat-registry-log-json-size-keeps-increasing-though-there-are-no-new-log-entries-in-my-application-log/342757 "2023-09-12T15:14:15Z")

</div>

Filebeat is making entry to log.json file even though are no new logs being added to my application log file. Below is the excerpt of the log.json file {"k":"filebeat::logs::native::670096-64768","v":{"ttl":-1,"FileSta…

---

## [I am not able to save actual values in index connector created my new index, values like rule\_id, action\_id etc. How can I do this?](https://discuss.elastic.co/t/i-am-not-able-to-save-actual-values-in-index-connector-created-my-new-index-values-like-rule-id-action-id-etc-how-can-i-do-this/342857)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 2:50pm UTC](https://discuss.elastic.co/t/i-am-not-able-to-save-actual-values-in-index-connector-created-my-new-index-values-like-rule-id-action-id-etc-how-can-i-do-this/342857 "2023-09-12T14:50:09Z")

</div>

I am not able to save actual values in index connector created my new index, values like rule\_id, action\_id etc. How can I do this ? Please help.

---

## [Calculate the size of logs in a specific time period](https://discuss.elastic.co/t/calculate-the-size-of-logs-in-a-specific-time-period/342845)

<div class="topic-metadata">

**Author:** [@nickmannouch](https://discuss.elastic.co/u/nickmannouch)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 2:47pm UTC](https://discuss.elastic.co/t/calculate-the-size-of-logs-in-a-specific-time-period/342845 "2023-09-12T14:47:05Z")

</div>

Hi, We can see that in a specific 12 hour period, we have 1.3 million log entries. We want to see how much disk space was consumed by this. We thought we could just add 'bytes' as a metric to the graph. However, bytes …

---

## [Backup policy](https://discuss.elastic.co/t/backup-policy/342853)

<div class="topic-metadata">

**Author:** [@sravanth\_cabbu](https://discuss.elastic.co/u/sravanth_cabbu)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 2:39pm UTC](https://discuss.elastic.co/t/backup-policy/342853 "2023-09-12T14:39:34Z")

</div>

Hi Team, We are upgrading RHEL7 to 8 and installed ES. We have NAS mount in place and restored all indices. So in the process of cutover from rhel 7 to 8, we have to add the backup policy to rhel 8 for snapshot. we have…

---

## [Ingest Pipeline Dissect Pattern unable to match Append modifiers](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765 "2023-09-12T14:20:31Z")

</div>

This is is the dissect pattern %{+dateStr} %(+dateStr) %{logLevel} %{className} %{httpNio} %{+messageContent} %{+messageContent} %{+messageContent} %{} This is a sample line from the document that the dissect is failin…

---

## [Java api bulk opreration](https://discuss.elastic.co/t/java-api-bulk-opreration/342659)

<div class="topic-metadata">

**Author:** [@zgy](https://discuss.elastic.co/u/zgy)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 2:04pm UTC](https://discuss.elastic.co/t/java-api-bulk-opreration/342659 "2023-09-12T14:04:31Z")

</div>

hello,I'm a student , and learning elasticsearch recently. when I use the java bulk api follow the official guides as Bulk: indexing multiple documents | Elasticsearch Java API Client \[8.3\] | Elastic. but it's occured a…

---

## [Reading new data from elastic using logstash to rabbitMQ](https://discuss.elastic.co/t/reading-new-data-from-elastic-using-logstash-to-rabbitmq/342844)

<div class="topic-metadata">

**Author:** [@Shay\_Hershko](https://discuss.elastic.co/u/Shay_Hershko)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 1:51pm UTC](https://discuss.elastic.co/t/reading-new-data-from-elastic-using-logstash-to-rabbitmq/342844 "2023-09-12T13:51:59Z")

</div>

Hi, I want to send every new data entered to index in elastic to a RabbitMQ queue every second. I tried using logstash for it but for some reason it send all the data and not just the new one. I saw you can use time st…

---

## [Update By Query | Alias](https://discuss.elastic.co/t/update-by-query-alias/342834)

<div class="topic-metadata">

**Author:** [@ankitpandoh](https://discuss.elastic.co/u/ankitpandoh)\
**Replies:** 5\
**Last updated:** [September 12, 2023, 1:51pm UTC](https://discuss.elastic.co/t/update-by-query-alias/342834 "2023-09-12T13:51:26Z")

</div>

I am able to add a document to an index say my-main-index having some alias my-alias-index. When I did a search like below, I was able to get the documents. GET /my-main-index/\_search { "query":{ "match\_all": {} …

---

## [Feasibility to send alerts only if consecutive errors are occurred using elastalert](https://discuss.elastic.co/t/feasibility-to-send-alerts-only-if-consecutive-errors-are-occurred-using-elastalert/341485)

<div class="topic-metadata">

**Author:** [@prathameshdvk](https://discuss.elastic.co/u/prathameshdvk)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 1:34pm UTC](https://discuss.elastic.co/t/feasibility-to-send-alerts-only-if-consecutive-errors-are-occurred-using-elastalert/341485 "2023-09-12T13:34:38Z")

</div>

Hi All, I am trying to setup alerting using elastalert and I am trying to achieve below scenarios. scenario 1: Send alert if there are 3 consecutive 400 errors. (Which is working fine) scenario 2: Do not send alert if…

---

## [ElasticSearch v7 docker container not starting on RHEL 8.8](https://discuss.elastic.co/t/elasticsearch-v7-docker-container-not-starting-on-rhel-8-8/341913)

<div class="topic-metadata">

**Author:** [@hakakuma](https://discuss.elastic.co/u/hakakuma)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:31pm UTC](https://discuss.elastic.co/t/elasticsearch-v7-docker-container-not-starting-on-rhel-8-8/341913 "2023-09-12T13:31:07Z")

</div>

When we try to run elasticsearch v7.17.0 or v7.17.12, we are facing an error to start the container. It fails with "2023-08-29T12:34:54.499254418+05:30 stderr F chroot: cannot change root directory to '/': Operation not …

---

## [Help me: Unable to parse response body for Bulk Request posted](https://discuss.elastic.co/t/help-me-unable-to-parse-response-body-for-bulk-request-posted/342793)

<div class="topic-metadata">

**Author:** [@adibas](https://discuss.elastic.co/u/adibas)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:09pm UTC](https://discuss.elastic.co/t/help-me-unable-to-parse-response-body-for-bulk-request-posted/342793 "2023-09-12T13:09:33Z")

</div>

Error Details: java.io.IOException: Unable to parse response body for Response{requestLine=POST /\_bulk?timeout=1m HTTP/1.1, host=eu-west-1.es.amazonaws.com, response=HTTP/1.1 200 OK} Tried to investigate and I see the …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=424)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=426)
