# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=443

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 444

---

## [Install via fleet from a local agent repository instead downloading each time?](https://discuss.elastic.co/t/install-via-fleet-from-a-local-agent-repository-instead-downloading-each-time/341544)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 8:02am UTC](https://discuss.elastic.co/t/install-via-fleet-from-a-local-agent-repository-instead-downloading-each-time/341544 "2023-08-24T08:02:35Z")

</div>

well - unfortunately i do not have the best internet connection an installing the updating the agents via fleet takes a lot of time. Is it possible to use a local repository instead so that the agent does not have to be…

---

## [Elastic didn't load properly. Check the server output for more information](https://discuss.elastic.co/t/elastic-didnt-load-properly-check-the-server-output-for-more-information/339530)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 6\
**Last updated:** [August 24, 2023, 7:38am UTC](https://discuss.elastic.co/t/elastic-didnt-load-properly-check-the-server-output-for-more-information/339530 "2023-08-24T07:38:44Z")

</div>

Hi Team, We have installed the Elasticsearch (8.5.1) and Kibana through helm following git hub link GitHub - elastic/helm-charts: You know, for Kubernetes. We are facing intermittent issue on Kibana Ui as " Elastic did …

---

## [How do parse log format apache tomcat](https://discuss.elastic.co/t/how-do-parse-log-format-apache-tomcat/341529)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 7:36am UTC](https://discuss.elastic.co/t/how-do-parse-log-format-apache-tomcat/341529 "2023-08-24T07:36:39Z")

</div>

Good moring everyone! I have a log with the format of the tomcat access log service (localaccesslog.txt) 10.0.xx.xx \[22/Aug/2023:00:00:30 +0700\] "GET /zkau?dtid=z\_qe0&cmd\_0=rmDesktop&opt\_0=i HTTP/1.0" 200 17 0 Now I…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/341408)

<div class="topic-metadata">

**Author:** [@seamanw](https://discuss.elastic.co/u/seamanw)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 7:21am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/341408 "2023-08-24T07:21:33Z")

</div>

I install Elasticsearch and Kibana following the Official document: Install Kibana with Docker | Kibana Guide \[8.9\] | Elastic the command is: docker pull docker.elastic.co/elasticsearch/elasticsearch:8.9.1 docker pull …

---

## [Columns exported from Tabular CSV are reshuffled](https://discuss.elastic.co/t/columns-exported-from-tabular-csv-are-reshuffled/340921)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 10\
**Last updated:** [August 24, 2023, 7:05am UTC](https://discuss.elastic.co/t/columns-exported-from-tabular-csv-are-reshuffled/340921 "2023-08-24T07:05:37Z")

</div>

Hello Team, Columns are getting reshuflled when exported to CSV format When exported in CSV, columns are getting shifted Please can you help me for how to resolve this one

---

## [Multiple fleet entries cleanup](https://discuss.elastic.co/t/multiple-fleet-entries-cleanup/341141)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 12\
**Last updated:** [August 24, 2023, 6:28am UTC](https://discuss.elastic.co/t/multiple-fleet-entries-cleanup/341141 "2023-08-24T06:28:24Z")

</div>

Hello, in my fleet management there's 3 entries for the agent on one machine. Two of them are obsolete. I wonder what is happening if i uninstall with the one fleet server i need for management? Is it somehow possible…

---

## [Random function in Painless?](https://discuss.elastic.co/t/random-function-in-painless/70280)

<div class="topic-metadata">

**Author:** [@Dom-nik](https://discuss.elastic.co/u/Dom-nik)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 6:25am UTC](https://discuss.elastic.co/t/random-function-in-painless/70280 "2023-08-24T06:25:09Z")

</div>

Hello, What is the way to genereate a random value in Painless? Being able to draw one value from a set would be particularly great - I want to use it to add a new field to my mock data and I need a possibility to add…

---

## [ElasticSearch Service Startup Issue](https://discuss.elastic.co/t/elasticsearch-service-startup-issue/341532)

<div class="topic-metadata">

**Author:** [@Jeevagan](https://discuss.elastic.co/u/Jeevagan)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 4:40am UTC](https://discuss.elastic.co/t/elasticsearch-service-startup-issue/341532 "2023-08-24T04:40:06Z")

</div>

Hey everyone, I hope you're doing well. I've been working on setting up an Elasticsearch service using a systemd service file, but I'm encountering an issue when trying to start the application. I'm hoping someone here …

---

## [Logstash-7.17.12 file input not working](https://discuss.elastic.co/t/logstash-7-17-12-file-input-not-working/341527)

<div class="topic-metadata">

**Author:** [@Jongwook\_Seong](https://discuss.elastic.co/u/Jongwook_Seong)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 4:44am UTC](https://discuss.elastic.co/t/logstash-7-17-12-file-input-not-working/341527 "2023-08-24T04:44:44Z")

</div>

I am using logstash-7.17.12 to input the contents of logstash-test.conf file. The contents of logstash-test.conf are as follows. input { file { path =\> "C:/Users/user/logstash-7.17.12/config/filter-example.log" …

---

## [Elastic Agent Unhealthy - 504 Gateway Timeout - net/hxxp: TLS handshake timeout](https://discuss.elastic.co/t/elastic-agent-unhealthy-504-gateway-timeout-net-hxxp-tls-handshake-timeout/341325)

<div class="topic-metadata">

**Author:** [@Shinej](https://discuss.elastic.co/u/Shinej)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 4:23am UTC](https://discuss.elastic.co/t/elastic-agent-unhealthy-504-gateway-timeout-net-hxxp-tls-handshake-timeout/341325 "2023-08-24T04:23:26Z")

</div>

Hi, Elastic agent is un healthy and not send logs -- Logs below -- appreciate any help. \[elastic\_agent.filebeat\]\[warn\] WinEventLog\[winlog-winlog.winlog-c97bd33a-1398-47bc-88a7-284efdb43f68\] error salvaging message (eve…

---

## [Name or service not known in java RestHighLevelClient](https://discuss.elastic.co/t/name-or-service-not-known-in-java-resthighlevelclient/341415)

<div class="topic-metadata">

**Author:** [@ChiMu\_Yuan](https://discuss.elastic.co/u/ChiMu_Yuan)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:52am UTC](https://discuss.elastic.co/t/name-or-service-not-known-in-java-resthighlevelclient/341415 "2023-08-24T03:52:37Z")

</div>

Hi, everyone. I am using the Elasticsearch High Level REST client to access the service, but I am getting an error Name or service not known. However, I can successfully access the service using curl. Since I upgraded f…

---

## [Elasticsearch Aggregate Search Impact on Performance](https://discuss.elastic.co/t/elasticsearch-aggregate-search-impact-on-performance/340740)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:45am UTC](https://discuss.elastic.co/t/elasticsearch-aggregate-search-impact-on-performance/340740 "2023-08-24T03:45:04Z")

</div>

Is there a leader in ES? For general product comprehensive search and display lists, it is recommended to use direct query or AGG aggregation form, as AGG has little impact on performance

---

## [When the number of documents exceeds 2 billion, the index status becomes RED](https://discuss.elastic.co/t/when-the-number-of-documents-exceeds-2-billion-the-index-status-becomes-red/341461)

<div class="topic-metadata">

**Author:** [@im.jinxinwang](https://discuss.elastic.co/u/im.jinxinwang)\
**Replies:** 5\
**Last updated:** [August 24, 2023, 3:24am UTC](https://discuss.elastic.co/t/when-the-number-of-documents-exceeds-2-billion-the-index-status-becomes-red/341461 "2023-08-24T03:24:29Z")

</div>

Version: 7.8.1 Cause of failure: The number of important index documents in the 7.8.1 open source version of ES has reached the limit of 2147483519 in Lucene. The index status is red, and read and write operations canno…

---

## [Integrate Kibana with an external logging agent](https://discuss.elastic.co/t/integrate-kibana-with-an-external-logging-agent/341523)

<div class="topic-metadata">

**Author:** [@quarkytale](https://discuss.elastic.co/u/quarkytale)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 1:32am UTC](https://discuss.elastic.co/t/integrate-kibana-with-an-external-logging-agent/341523 "2023-08-24T01:32:45Z")

</div>

Is it possible to integrate Kibana with an external logging agent instead of using Elasticsearch. Would appreciate any resources on the same, especially message formats and configuration details.

---

## [Connectors-python mysql - selfsigned SSL can not verify](https://discuss.elastic.co/t/connectors-python-mysql-selfsigned-ssl-can-not-verify/341512)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 12:08am UTC](https://discuss.elastic.co/t/connectors-python-mysql-selfsigned-ssl-can-not-verify/341512 "2023-08-24T00:08:55Z")

</div>

Hello, when I try to connect to our mysql / mariadb database instance using SSL and providing the CA-cert.pem file of the selfsigned certificate, the connectors-python connector outputs an error that the selfsigned SSL …

---

## [Optimizing ElasticSearch startup time for CI](https://discuss.elastic.co/t/optimizing-elasticsearch-startup-time-for-ci/341516)

<div class="topic-metadata">

**Author:** [@blindsnowmobile](https://discuss.elastic.co/u/blindsnowmobile)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 9:11pm UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-startup-time-for-ci/341516 "2023-08-23T21:11:20Z")

</div>

We use Elasticsearch in our integration tests, which run many times every day. Running ES in this way has a different set of requirements than in our production environment. We need ES to start as fast as possible with…

---

## [Looking for data in Kibana](https://discuss.elastic.co/t/looking-for-data-in-kibana/341383)

<div class="topic-metadata">

**Author:** [@Naveen.Bhonagiri](https://discuss.elastic.co/u/Naveen.Bhonagiri)\
**Replies:** 5\
**Last updated:** [August 23, 2023, 8:41pm UTC](https://discuss.elastic.co/t/looking-for-data-in-kibana/341383 "2023-08-23T20:41:46Z")

</div>

HI Team, I am looking for a help, i am having some devices list (approx 900 devices) which are injecting logs to Elastic, i want help in finding the devices that never sent logs to elastic from my actual devices. If an…

---

## [Can Rollover API / ILM be used to keep only x days data in an index at any point of time](https://discuss.elastic.co/t/can-rollover-api-ilm-be-used-to-keep-only-x-days-data-in-an-index-at-any-point-of-time/341410)

<div class="topic-metadata">

**Author:** [@Aditya1996](https://discuss.elastic.co/u/Aditya1996)\
**Replies:** 14\
**Last updated:** [August 23, 2023, 6:44pm UTC](https://discuss.elastic.co/t/can-rollover-api-ilm-be-used-to-keep-only-x-days-data-in-an-index-at-any-point-of-time/341410 "2023-08-23T18:44:02Z")

</div>

I have read a few threads regarding this question , Most of them suggest using DeleteBy Query as Rollover API seems to delete/move to other phase the indices and create the new ones based on given condition. I could not…

---

## [Elastic Agent stopped sending ssh failed logs](https://discuss.elastic.co/t/elastic-agent-stopped-sending-ssh-failed-logs/341369)

<div class="topic-metadata">

**Author:** [@hoomant](https://discuss.elastic.co/u/hoomant)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 6:04pm UTC](https://discuss.elastic.co/t/elastic-agent-stopped-sending-ssh-failed-logs/341369 "2023-08-23T18:04:32Z")

</div>

Hi I have setup elastic agent in an elasticsearch 8.7 environment and up to a few days ago everything was working fine but now it is not sending the ssh failed events to the elasticsearch which was a no problem in previo…

---

## [Data parse from multiple rsyslog to logstash to elasticsearch](https://discuss.elastic.co/t/data-parse-from-multiple-rsyslog-to-logstash-to-elasticsearch/341506)

<div class="topic-metadata">

**Author:** [@ermilan2309](https://discuss.elastic.co/u/ermilan2309)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 5:38pm UTC](https://discuss.elastic.co/t/data-parse-from-multiple-rsyslog-to-logstash-to-elasticsearch/341506 "2023-08-23T17:38:28Z")

</div>

Hello, I am new to ELK. I have deployed my ELK with this article. https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-22-04 I skipped the nginx par…

---

## [Stored fields](https://discuss.elastic.co/t/stored-fields/341503)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 5:02pm UTC](https://discuss.elastic.co/t/stored-fields/341503 "2023-08-23T17:02:30Z")

</div>

Looking for help interacting with stored fields returned from the search. Specifically hit.fields() returns a map of string and JsonData. How do you turn that JsonData into something you can manipulate? Thanks. SearchRe…

---

## [Logstash stops processing AWS WAF logs when fields exceed 1000 (or any number)](https://discuss.elastic.co/t/logstash-stops-processing-aws-waf-logs-when-fields-exceed-1000-or-any-number/341497)

<div class="topic-metadata">

**Author:** [@feo13](https://discuss.elastic.co/u/feo13)\
**Replies:** 4\
**Last updated:** [August 23, 2023, 4:41pm UTC](https://discuss.elastic.co/t/logstash-stops-processing-aws-waf-logs-when-fields-exceed-1000-or-any-number/341497 "2023-08-23T16:41:41Z")

</div>

Hi there, I'm ingesting AWS WAF logs and it works fine for a few minutes but then stops with the following error: response=\>{"index"=\>{"\_index"=\>"waf-logs-2023.08.01", "\_id"=\>"rjCKGYoBsxYs-jwL007l", "status"=\>400, "err…

---

## [How to serialize/deserialize FieldValue object?](https://discuss.elastic.co/t/how-to-serialize-deserialize-fieldvalue-object/341498)

<div class="topic-metadata">

**Author:** [@icruces](https://discuss.elastic.co/u/icruces)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 3:40pm UTC](https://discuss.elastic.co/t/how-to-serialize-deserialize-fieldvalue-object/341498 "2023-08-23T15:40:24Z")

</div>

I have upgraded the Java API from 8.2 to the latest. The method Hit::sort now returns a List\<FieldValue\> instead of List\<String\>. I understand this is the correct way but it breaks my app as I was base64 encoding/decodin…

---

## [About Kibana UI](https://discuss.elastic.co/t/about-kibana-ui/340993)

<div class="topic-metadata">

**Author:** [@Vamsi\_Ramisetti](https://discuss.elastic.co/u/Vamsi_Ramisetti)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 2:55pm UTC](https://discuss.elastic.co/t/about-kibana-ui/340993 "2023-08-23T14:55:58Z")

</div>

In Kibana UI in the above uploaded image the document filed is showing empty but the timestamp is displaying. The logs is coming but not displaying in the document field

---

## [Postgresql to Elastic Search](https://discuss.elastic.co/t/postgresql-to-elastic-search/341319)

<div class="topic-metadata">

**Author:** [@oreobiskuit](https://discuss.elastic.co/u/oreobiskuit)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 2:51pm UTC](https://discuss.elastic.co/t/postgresql-to-elastic-search/341319 "2023-08-23T14:51:44Z")

</div>

Hi everyone, I'm new to Elasticsearch. Currently I'm trying to replicate my db from postgresql and transform it to Elasticsearch. I've tried using google datastream (since my db is deployed in cloudSql) to cloud storage…

---

## [Cross Cluster Search - 7.17 on EC2 to 8.8 on Kubernetes](https://discuss.elastic.co/t/cross-cluster-search-7-17-on-ec2-to-8-8-on-kubernetes/341391)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 1:59pm UTC](https://discuss.elastic.co/t/cross-cluster-search-7-17-on-ec2-to-8-8-on-kubernetes/341391 "2023-08-23T13:59:10Z")

</div>

I have a 7.17 cluster running on EC2 nodes in AWS. No security enabled. I'm trying to connect it to an 8.8 cluster on K8s with security enabled. Is this even possible? Having no issues connecting to other 7.17 clusters …

---

## [Fleet: Logstash Load Balancing?](https://discuss.elastic.co/t/fleet-logstash-load-balancing/341479)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 4\
**Last updated:** [August 23, 2023, 1:44pm UTC](https://discuss.elastic.co/t/fleet-logstash-load-balancing/341479 "2023-08-23T13:44:03Z")

</div>

I don't see this documented anywhere. For Fleet-managed Logstash Output, is there a way to loadbalance among the Logstash endpoints specified?

---

## [Is reading elastic logs from a node directly possible?](https://discuss.elastic.co/t/is-reading-elastic-logs-from-a-node-directly-possible/341473)

<div class="topic-metadata">

**Author:** [@mscch](https://discuss.elastic.co/u/mscch)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 1:41pm UTC](https://discuss.elastic.co/t/is-reading-elastic-logs-from-a-node-directly-possible/341473 "2023-08-23T13:41:19Z")

</div>

Hi all Is there a way to read logs (sent to elastic by Logstash) directly from an Elasticsearch node? Our Elasticsearch version is 8.30. Because of a Ransomware attack, we currently do not have access to the Kibana VM.…

---

## [KQL SearchBar not visible](https://discuss.elastic.co/t/kql-searchbar-not-visible/341482)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 1:33pm UTC](https://discuss.elastic.co/t/kql-searchbar-not-visible/341482 "2023-08-23T13:33:16Z")

</div>

Hello, I am developing a customized kibana plugin, I want to visualize this KQL Searchbar with the filters and without the time range I tried this \<TopNavMenu appName={PLUGIN\_ID} showSearchBar={true} …

---

## [Logs Pulling Architecture](https://discuss.elastic.co/t/logs-pulling-architecture/341438)

<div class="topic-metadata">

**Author:** [@Raz\_Maabari](https://discuss.elastic.co/u/Raz_Maabari)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 1:10pm UTC](https://discuss.elastic.co/t/logs-pulling-architecture/341438 "2023-08-23T13:10:00Z")

</div>

Filebeat uses a "push" architecture, sending logs to logstash or elastic. Is there a feature or product that would enable elastic to receive hosts' logs using a "pull" architecture? In my setup, I have network connectiv…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=442)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=444)
