# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=448

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 449

---

## [INFO logs being sent as error logs](https://discuss.elastic.co/t/info-logs-being-sent-as-error-logs/341101)

<div class="topic-metadata">

**Author:** [@marcoaleixo](https://discuss.elastic.co/u/marcoaleixo)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 2:08pm UTC](https://discuss.elastic.co/t/info-logs-being-sent-as-error-logs/341101 "2023-08-18T14:08:40Z")

</div>

hey team, I have my Fleet configured using ElasticCloud and I need to configure the elastic-agent on my Django project where I'm configuring my logging like: ELASTIC\_APM = { 'SERVICE\_NAME': 'alan-backend', 'SERVE…

---

## [Activated Warm Tier Not Able To Shut it Down](https://discuss.elastic.co/t/activated-warm-tier-not-able-to-shut-it-down/341102)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/activated-warm-tier-not-able-to-shut-it-down/341102 "2023-08-18T14:14:12Z")

</div>

Hi, I decided to experiment with the warm data tier instance in ES. It seems to have moved data on to this tier (to be expected). But now I can't remove this instance. From what I've seen, this is a solution: But it …

---

## [General advice on sucking in whole databases into Elastic?](https://discuss.elastic.co/t/general-advice-on-sucking-in-whole-databases-into-elastic/341096)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 1:44pm UTC](https://discuss.elastic.co/t/general-advice-on-sucking-in-whole-databases-into-elastic/341096 "2023-08-18T13:44:23Z")

</div>

Hi all. I'm working on pulling my company's relational data into Elastic using the Logstash JDBC. It's working, but I have a general question. Currently, I've just written a JOIN over two tables containing a few field…

---

## [ILM action failed “check-rollover-ready,Moving to ERROR step”?](https://discuss.elastic.co/t/ilm-action-failed-check-rollover-ready-moving-to-error-step/340922)

<div class="topic-metadata">

**Author:** [@njain213](https://discuss.elastic.co/u/njain213)\
**Replies:** 5\
**Last updated:** [August 18, 2023, 1:43pm UTC](https://discuss.elastic.co/t/ilm-action-failed-check-rollover-ready-moving-to-error-step/340922 "2023-08-18T13:43:40Z")

</div>

Hello Team, I am using ELK stack version 7.9.3 and sometimes I use to get below error when randomly ILM policy stops working and no new index with new date is created and data is getting piled in previous date index. Wh…

---

## [Filebeat restart issue](https://discuss.elastic.co/t/filebeat-restart-issue/341087)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 12:18pm UTC](https://discuss.elastic.co/t/filebeat-restart-issue/341087 "2023-08-18T12:18:15Z")

</div>

Hi, Everytime i restart Filebeat, it install all the default dashboards and searches just like running "filebeat setup". How can i change this behaviour? I sometimes need to restart Filebeat but i do not want to delete…

---

## ["error": "no handler found for uri \[/\_security/role/kib\] and method \[POST\]"](https://discuss.elastic.co/t/error-no-handler-found-for-uri-security-role-kib-and-method-post/341085)

<div class="topic-metadata">

**Author:** [@Ramon\_Moraga\_Fernand](https://discuss.elastic.co/u/Ramon_Moraga_Fernand)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 11:03am UTC](https://discuss.elastic.co/t/error-no-handler-found-for-uri-security-role-kib-and-method-post/341085 "2023-08-18T11:03:32Z")

</div>

I have this elasticsearch.yml configuration(cluster.name: elasticsearch\_cluster discovery.seed\_hosts: \["elasticsearch"\] discovery.type: single-node bootstrap.memory\_lock: true http.host: 0.0.0.0 transport.host: 0.0.…

---

## [Errors from fleet managed elastic agents](https://discuss.elastic.co/t/errors-from-fleet-managed-elastic-agents/339083)

<div class="topic-metadata">

**Author:** [@Jitendra1](https://discuss.elastic.co/u/Jitendra1)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 10:43am UTC](https://discuss.elastic.co/t/errors-from-fleet-managed-elastic-agents/339083 "2023-08-18T10:43:14Z")

</div>

Hi, I am getting few errors from fleet-managed elastic agents, which are listed below as- Please suggest me how to resolve these.

---

## [Trying to create templte from index](https://discuss.elastic.co/t/trying-to-create-templte-from-index/341086)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 10:31am UTC](https://discuss.elastic.co/t/trying-to-create-templte-from-index/341086 "2023-08-18T10:31:19Z")

</div>

I'm trying to create a template through Kibana from an already imported index, so I can reimport them, and apply the template to them (and also apply a lifecycle policy). The index mappings looks like this: { "mappin…

---

## [Filter elasticsearch data with logstash](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077)

<div class="topic-metadata">

**Author:** [@john.hoogeveen](https://discuss.elastic.co/u/john.hoogeveen)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 10:01am UTC](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077 "2023-08-18T10:01:33Z")

</div>

Hello, I am trying to export some data from an elastic stack using logstash but it doesn't work. For this I connected it to a test stack with this config file input { elasticsearch { hosts =\> "localhost:9200" …

---

## [Unable to start Elasticsearch 8.8.2 even after disabling xpack](https://discuss.elastic.co/t/unable-to-start-elasticsearch-8-8-2-even-after-disabling-xpack/341080)

<div class="topic-metadata">

**Author:** [@Abhishek\_Mantripraga](https://discuss.elastic.co/u/Abhishek_Mantripraga)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 7:31am UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-8-8-2-even-after-disabling-xpack/341080 "2023-08-18T07:31:32Z")

</div>

\[2023-08-18T08:03:06,110\]\[WARN \]\[c.a.a.p.i.BasicProfileConfigFileLoader\] \[\] Unable to load config file null java.security.AccessControlException: access denied ("java.io.FilePermission" "/nonexistent/.aws/config" "read")…

---

## [Kibana Lucene query string does not match the result](https://discuss.elastic.co/t/kibana-lucene-query-string-does-not-match-the-result/340703)

<div class="topic-metadata">

**Author:** [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 6:17am UTC](https://discuss.elastic.co/t/kibana-lucene-query-string-does-not-match-the-result/340703 "2023-08-18T06:17:35Z")

</div>

Kibana Lucene query string: host:\*AGC\* AND NOT host:\*LGAGC\* AND NOT host:\*AP\* AND message:"\\:ORA\\-" AND NOT message:"ReconnectableOraErrCodes" However, the query result not 100% match, such the pattern below in documen…

---

## [Remote cluster node query](https://discuss.elastic.co/t/remote-cluster-node-query/341033)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 6\
**Last updated:** [August 18, 2023, 5:18am UTC](https://discuss.elastic.co/t/remote-cluster-node-query/341033 "2023-08-18T05:18:41Z")

</div>

We have an existing elasticsearch stack running basic license, is it possible to add more nodes to the cluster which do not hold any data and only pass data from a location to existing data / master nodes with basic lice…

---

## [Custom TCP port numbers instead of 9200 for elasticsearch](https://discuss.elastic.co/t/custom-tcp-port-numbers-instead-of-9200-for-elasticsearch/341012)

<div class="topic-metadata">

**Author:** [@Penchala\_Abhilash\_Mu](https://discuss.elastic.co/u/Penchala_Abhilash_Mu)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 5:12am UTC](https://discuss.elastic.co/t/custom-tcp-port-numbers-instead-of-9200-for-elasticsearch/341012 "2023-08-18T05:12:06Z")

</div>

Hi Team, As a security best practices, i would like to change the http.port number from 9200 to custom tcp port number.?? Please share the some reference documents Best Reagards, Abhilash

---

## [Im installing elasticsearch 8.9x while inicialicing the nodes i received this error](https://discuss.elastic.co/t/im-installing-elasticsearch-8-9x-while-inicialicing-the-nodes-i-received-this-error/340786)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 4\
**Last updated:** [August 17, 2023, 9:10pm UTC](https://discuss.elastic.co/t/im-installing-elasticsearch-8-9x-while-inicialicing-the-nodes-i-received-this-error/340786 "2023-08-17T21:10:56Z")

</div>

im installing elasticsearch 8.9x but when im starting the nodes and change the password i receive this error the command i use to change is this sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password --url "htt…

---

## [Filebeat failing to start due to YAML error, but which config file is it complaining about?](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 7\
**Last updated:** [August 17, 2023, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047 "2023-08-17T20:48:47Z")

</div>

I'm attempting to use Filebeat to ingest logs from Zeek, but I'm getting the following error when I start Filebeat: Here's my /etc/filebeat/filebeat.yml file: Yamllint tells me that there's an issue with this: "Map…

---

## ["You need permission to create data views" error in new space](https://discuss.elastic.co/t/you-need-permission-to-create-data-views-error-in-new-space/340998)

<div class="topic-metadata">

**Author:** [@jonasjancarik](https://discuss.elastic.co/u/jonasjancarik)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 8:17pm UTC](https://discuss.elastic.co/t/you-need-permission-to-create-data-views-error-in-new-space/340998 "2023-08-17T20:17:33Z")

</div>

I've created a new space in Kibana, but I am unable to access the Analytics features, such as opening dashboards. I'm met with the error message "You need permission to create data views." What's even more confusing is t…

---

## [Enhanced table button functionality in row or near serach bar](https://discuss.elastic.co/t/enhanced-table-button-functionality-in-row-or-near-serach-bar/341027)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 7:20pm UTC](https://discuss.elastic.co/t/enhanced-table-button-functionality-in-row-or-near-serach-bar/341027 "2023-08-17T19:20:06Z")

</div>

Hello @fbaligand , I have a requirement and need suggestion if this is possible or not in ENHANCED TABLE. I have dashboard using enhanced table, in one particular usecases I would not like to store user data directly i…

---

## [ELK/Kibana SSO using Keycloak](https://discuss.elastic.co/t/elk-kibana-sso-using-keycloak/341035)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 7:18pm UTC](https://discuss.elastic.co/t/elk-kibana-sso-using-keycloak/341035 "2023-08-17T19:18:18Z")

</div>

Is the enterprise version of Elasticsearch required for Keycloak OICD integration for single sign on?

---

## [Platinum license with non-prod/prod](https://discuss.elastic.co/t/platinum-license-with-non-prod-prod/341048)

<div class="topic-metadata">

**Author:** [@Stevelee](https://discuss.elastic.co/u/Stevelee)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 7:06pm UTC](https://discuss.elastic.co/t/platinum-license-with-non-prod-prod/341048 "2023-08-17T19:06:10Z")

</div>

Let me explain our situation briefly. We already have contracted platinum version of ES with 3 nodes. And I got two license files for non-prod and prod. In this case, can I adopt license for 3 nodes in each environments…

---

## [ES 8.6.1 How to make the number result hits consistent when re-running the same query over and over](https://discuss.elastic.co/t/es-8-6-1-how-to-make-the-number-result-hits-consistent-when-re-running-the-same-query-over-and-over/341050)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 7:04pm UTC](https://discuss.elastic.co/t/es-8-6-1-how-to-make-the-number-result-hits-consistent-when-re-running-the-same-query-over-and-over/341050 "2023-08-17T19:04:39Z")

</div>

I have and index with 10 primaries and 10 replicas (number\_of\_replica is set to 1). Refresh interval is currently 5s. There is a lot writing activity happenning on that index. I have a query that queries for a specific…

---

## [Can we run bool query in constant\_score](https://discuss.elastic.co/t/can-we-run-bool-query-in-constant-score/341040)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 6:04pm UTC](https://discuss.elastic.co/t/can-we-run-bool-query-in-constant-score/341040 "2023-08-17T18:04:24Z")

</div>

can we run bool query in constant\_score sample query { "query": { "constant\_score": { "filter": { "bool": { "must": \[ { "term": { "account\_id": { …

---

## [Time slider playback](https://discuss.elastic.co/t/time-slider-playback/341043)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 6:01pm UTC](https://discuss.elastic.co/t/time-slider-playback/341043 "2023-08-17T18:01:05Z")

</div>

Hello, I've been reading through the documenation to see if this capability exists, but I've been unable to find it. Is it possible to setup a time range "playback" that is not just a slider intervals within a global ti…

---

## [Could not init registrar: registry file version 1 not supported](https://discuss.elastic.co/t/could-not-init-registrar-registry-file-version-1-not-supported/341039)

<div class="topic-metadata">

**Author:** [@mrahman](https://discuss.elastic.co/u/mrahman)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 5:47pm UTC](https://discuss.elastic.co/t/could-not-init-registrar-registry-file-version-1-not-supported/341039 "2023-08-17T17:47:37Z")

</div>

Hello, I am getting this error related to registry file : │ 2023-08-17T17:23:10.691Z INFO instance/beat.go:297 Setup Beat: filebeat; Version: 7.7.0 …

---

## [Is it possible to gain an ip address from a hostname in forwarded event?](https://discuss.elastic.co/t/is-it-possible-to-gain-an-ip-address-from-a-hostname-in-forwarded-event/341029)

<div class="topic-metadata">

**Author:** [@ninom](https://discuss.elastic.co/u/ninom)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 4:46pm UTC](https://discuss.elastic.co/t/is-it-possible-to-gain-an-ip-address-from-a-hostname-in-forwarded-event/341029 "2023-08-17T16:46:47Z")

</div>

For context: windows machine -\> server -\> winlogbeats Not sure if there is a way to use either dns lookup or possibly some other method for the server to get the ip address of the windows machine from a forwarded windo…

---

## [Parsing log in logstash with format xml and json embebed](https://discuss.elastic.co/t/parsing-log-in-logstash-with-format-xml-and-json-embebed/341031)

<div class="topic-metadata">

**Author:** [@Oscar\_Lopez](https://discuss.elastic.co/u/Oscar_Lopez)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 4:21pm UTC](https://discuss.elastic.co/t/parsing-log-in-logstash-with-format-xml-and-json-embebed/341031 "2023-08-17T16:21:53Z")

</div>

hello everyone Hello everyone, at this moment I am trying to ingest some logs in elasticsearch with logstash with the following structure: \<ns0:MessageID xmlns:ns0="http://www.ZZZ.com/namespaces/tnt/plugins/jms"\>ID:XXX…

---

## [javax.net.ssl.SSLHandshakeException: Empty client certificate chain](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-empty-client-certificate-chain/341024)

<div class="topic-metadata">

**Author:** [@nick\_harper1](https://discuss.elastic.co/u/nick_harper1)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 2:10pm UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-empty-client-certificate-chain/341024 "2023-08-17T14:10:54Z")

</div>

I have configured a cert that has both server and client enabled but when using this for transport on 9300 I get: exception caught on transport layer \[Netty4TcpChannel{localAddress=/10.15.4.16:9300, remoteAddress=/10.15…

---

## [Send a blocking bulk index request via the Elasticsearch Java client (8.9)](https://discuss.elastic.co/t/send-a-blocking-bulk-index-request-via-the-elasticsearch-java-client-8-9/341020)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 1:45pm UTC](https://discuss.elastic.co/t/send-a-blocking-bulk-index-request-via-the-elasticsearch-java-client-8-9/341020 "2023-08-17T13:45:06Z")

</div>

Hi, I have written a Spring Boot based integration test where I use the bulk api to index some documents. This is the main loop of the reindexAll() method: for (page in pageExports) { bulkRequest.operations…

---

## [Memory Pressure Getting Very High Very Quickly Due to Potentially Expensive Query](https://discuss.elastic.co/t/memory-pressure-getting-very-high-very-quickly-due-to-potentially-expensive-query/341021)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 1:34pm UTC](https://discuss.elastic.co/t/memory-pressure-getting-very-high-very-quickly-due-to-potentially-expensive-query/341021 "2023-08-17T13:34:20Z")

</div>

Hi, I'm running into a problem where memory pressure is getting very high very quickly when I make ES calls using a query with a lot of excludes. It seems to work fine for certain values of elastic\_tag\_subdomain but fo…

---

## [Problems migrating from filebeat 5 to 7 - not gettings the data/fields we need in logstash](https://discuss.elastic.co/t/problems-migrating-from-filebeat-5-to-7-not-gettings-the-data-fields-we-need-in-logstash/340974)

<div class="topic-metadata">

**Author:** [@fjkoz](https://discuss.elastic.co/u/fjkoz)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 1:21pm UTC](https://discuss.elastic.co/t/problems-migrating-from-filebeat-5-to-7-not-gettings-the-data-fields-we-need-in-logstash/340974 "2023-08-17T13:21:50Z")

</div>

Hi all, Rather new to ELK in general, I am trying to migrate from filebeat v5.6.4 to filebeat 7.17.3. The problem is that the messages from the new install are not being parsed correctly. I know the document\_type as typ…

---

## [What is the inner workings of a GET operation?](https://discuss.elastic.co/t/what-is-the-inner-workings-of-a-get-operation/341018)

<div class="topic-metadata">

**Author:** [@jyaquinas](https://discuss.elastic.co/u/jyaquinas)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 1:09pm UTC](https://discuss.elastic.co/t/what-is-the-inner-workings-of-a-get-operation/341018 "2023-08-17T13:09:02Z")

</div>

I'm a little confused about the inner workings of GET in elasticsearch. The document states that the GET operation is realtime. I'm using version 6.8, and the documentation for this version also states the following: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=447)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=449)
