# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=461

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 462

---

## [Filebeat not ingesting Juniper SRX correctly](https://discuss.elastic.co/t/filebeat-not-ingesting-juniper-srx-correctly/339807)

<div class="topic-metadata">

**Author:** [@fredmoped](https://discuss.elastic.co/u/fredmoped)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 11:57am UTC](https://discuss.elastic.co/t/filebeat-not-ingesting-juniper-srx-correctly/339807 "2023-08-03T11:57:36Z")

</div>

Hi all, I am running Elastic,Kibana and Filebeat 8.8.1 on docker and it somewhat works for what i want to achieve, but i am struggling to get Juniper module to ingest my data correctly. From what i see at : https://git…

---

## [Unable to authenticate user](https://discuss.elastic.co/t/unable-to-authenticate-user/340001)

<div class="topic-metadata">

**Author:** [@Vamsi\_krishna\_Ramaya](https://discuss.elastic.co/u/Vamsi_krishna_Ramaya)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 9:06am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user/340001 "2023-08-03T09:06:16Z")

</div>

Hi, I have been facing some issues with Elasticsearch the error i am getting is “unable to authenticate user \[elastic\] for REST request \[/va\_vrm\_202308030888/\_doc\] Can anyone help to resolve this? Thanks in advance

---

## [Can't install a custom plugin even with a sufficient subscription level - Elastic Cloud](https://discuss.elastic.co/t/cant-install-a-custom-plugin-even-with-a-sufficient-subscription-level-elastic-cloud/339998)

<div class="topic-metadata">

**Author:** [@yechankim-paytalab](https://discuss.elastic.co/u/yechankim-paytalab)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 8:15am UTC](https://discuss.elastic.co/t/cant-install-a-custom-plugin-even-with-a-sufficient-subscription-level-elastic-cloud/339998 "2023-08-03T08:15:01Z")

</div>

Hi there. Somehow I can't install a custom plugin on my Elastic Cloud cluster, even though my subscription level is "Gold" right now. The Type - "An installable plugin (compiled, no source code)" is not clickable for m…

---

## [Monitoring Oracle Alert log by using Logstash](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 8:01am UTC](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889 "2023-08-03T08:01:45Z")

</div>

Hi Team, We had one requirement to monitor oracle alert log by using ELK stack. Could someone guide me . In my environment ELK stack running with 8.x version. Thanks, Debasis

---

## [Secure Logstash and Filebeats communication](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 4\
**Last updated:** [August 3, 2023, 7:51am UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912 "2023-08-03T07:51:17Z")

</div>

We are working on an integration where we need to take logs from Filebeat through Logstash. However, Filebeat and Logstash are hosted in different networks. In order to secure the communication, we want to implement SSL.…

---

## [Numerato/Denominator representation in TSVB](https://discuss.elastic.co/t/numerato-denominator-representation-in-tsvb/340000)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 7:35am UTC](https://discuss.elastic.co/t/numerato-denominator-representation-in-tsvb/340000 "2023-08-03T07:35:33Z")

</div>

Hi Team, I am using filter ratio in Gauge TSVB visualization as below. Now in my data formatter, I want to showcase it as Numerator/Denominator value instead of overall filter ratio value. Is it achievable?

---

## [Group fields in a visualization for time series](https://discuss.elastic.co/t/group-fields-in-a-visualization-for-time-series/325934)

<div class="topic-metadata">

**Author:** [@dannie-ml](https://discuss.elastic.co/u/dannie-ml)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 7:20am UTC](https://discuss.elastic.co/t/group-fields-in-a-visualization-for-time-series/325934 "2023-08-03T07:20:16Z")

</div>

Hi, im new in Elastic and i want to build some visualization of this table: But when building both lens or line chart or vega-lite (in this one i really dont know how to achieve a visualization) but for the other ones…

---

## [Search Applications with Search UI](https://discuss.elastic.co/t/search-applications-with-search-ui/340004)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 7:09am UTC](https://discuss.elastic.co/t/search-applications-with-search-ui/340004 "2023-08-03T07:09:41Z")

</div>

Hi, I tried to integrate Search Applications with Search UI as described in the Kibana frontend when I created a new Search Application sample-search-app. import EnginesAPIConnector from "@elastic/search-ui-engines-con…

---

## [Modules system and nginx is not showing any data when looking in discover](https://discuss.elastic.co/t/modules-system-and-nginx-is-not-showing-any-data-when-looking-in-discover/339076)

<div class="topic-metadata">

**Author:** [@Prem\_Pratap\_Singh](https://discuss.elastic.co/u/Prem_Pratap_Singh)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 6:38am UTC](https://discuss.elastic.co/t/modules-system-and-nginx-is-not-showing-any-data-when-looking-in-discover/339076 "2023-08-03T06:38:23Z")

</div>

Hi All, I have deployed Elasticsearch, kibana and filebeat on my kubernetes cluster but the enable modules such as nginx and system are not showing any data when i filter it using event.module: system on my dashboard bu…

---

## [How to read logs from newrelic?](https://discuss.elastic.co/t/how-to-read-logs-from-newrelic/339995)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 4:28am UTC](https://discuss.elastic.co/t/how-to-read-logs-from-newrelic/339995 "2023-08-03T04:28:46Z")

</div>

is there any logstash-input-newrelic plugins for read data from new relic enviornment?

---

## [How to query elasticsearch with array as parameter](https://discuss.elastic.co/t/how-to-query-elasticsearch-with-array-as-parameter/339991)

<div class="topic-metadata">

**Author:** [@rae93](https://discuss.elastic.co/u/rae93)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 3:23am UTC](https://discuss.elastic.co/t/how-to-query-elasticsearch-with-array-as-parameter/339991 "2023-08-03T03:23:50Z")

</div>

I have a logstash config like this input { http { port =\> 8092 } } filter { ruby { code =\> ' event.set("\[@metadata\]\[leadArr\]", \[\]) c = event.get("\[@metadata\]\[leads\]") c.each { |value, index| temp = even…

---

## [Elasticsearch 7.4 query\_then\_fetch slow log](https://discuss.elastic.co/t/elasticsearch-7-4-query-then-fetch-slow-log/339780)

<div class="topic-metadata">

**Author:** [@taoyantu](https://discuss.elastic.co/u/taoyantu)\
**Replies:** 7\
**Last updated:** [August 3, 2023, 1:21am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-query-then-fetch-slow-log/339780 "2023-08-03T01:21:22Z")

</div>

A cluster of elasticsearch version 7.4 is deployed. There are about 20 servers in the cluster. Three nodes are started on each machine. The startup memory occupies 30G. The server is 88-core cpu and 256G memory. The ind…

---

## [Logstash failling to make connection to ElasticSearch](https://discuss.elastic.co/t/logstash-failling-to-make-connection-to-elasticsearch/339731)

<div class="topic-metadata">

**Author:** [@Ilyass\_Taybi](https://discuss.elastic.co/u/Ilyass_Taybi)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 11:53pm UTC](https://discuss.elastic.co/t/logstash-failling-to-make-connection-to-elasticsearch/339731 "2023-07-31T23:53:07Z")

</div>

Hello, i am having troubles with Logstash for a week now. I do not know why does the error persists. To start Logstash, i use the following command : ./bin/logstash -f /"relative path to the file"/logstash-sample.conf . …

---

## [Using logstash to route APM data to two servers](https://discuss.elastic.co/t/using-logstash-to-route-apm-data-to-two-servers/339977)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 10:13pm UTC](https://discuss.elastic.co/t/using-logstash-to-route-apm-data-to-two-servers/339977 "2023-08-02T22:13:20Z")

</div>

Im am getting APM data on a APM server, I was wondering if its posible to place a logstash before the APM server, so I can send the same data to another server, so both receive the same data? Something like this: if …

---

## [Elastic-Agent - Collect Custom \[Linux\] text file logs](https://discuss.elastic.co/t/elastic-agent-collect-custom-linux-text-file-logs/339593)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 9:39pm UTC](https://discuss.elastic.co/t/elastic-agent-collect-custom-linux-text-file-logs/339593 "2023-08-02T21:39:08Z")

</div>

Hi, I have created a github issue for this question (Support for Custom \[Linux\] text file logs · Issue #7186 · elastic/integrations · GitHub), but I am also adding it here for greater visibility. We have custom applica…

---

## [Vaccum Deleted Documents](https://discuss.elastic.co/t/vaccum-deleted-documents/339974)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 9:13pm UTC](https://discuss.elastic.co/t/vaccum-deleted-documents/339974 "2023-08-02T21:13:53Z")

</div>

I learned that Elasticsearch does not update a document, but instead, deletes the current document and creates a new one with the updates. It happens that I have several documents that are updated several times during t…

---

## [Error displaying fleet agents -"Error fetching agents Cannot read properties of undefined (reading 'map')"](https://discuss.elastic.co/t/error-displaying-fleet-agents-error-fetching-agents-cannot-read-properties-of-undefined-reading-map/339840)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 3\
**Last updated:** [August 2, 2023, 8:09pm UTC](https://discuss.elastic.co/t/error-displaying-fleet-agents-error-fetching-agents-cannot-read-properties-of-undefined-reading-map/339840 "2023-08-02T20:09:56Z")

</div>

One fine morning, fleet section just decided not to show agents enrolled in a particular policy. I suspected two issues, @timestamp was not present in some of the fleet related indices, I added mapping for the same, seco…

---

## [\_template vs \_index\_template](https://discuss.elastic.co/t/template-vs-index-template/339969)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:13pm UTC](https://discuss.elastic.co/t/template-vs-index-template/339969 "2023-08-02T19:13:16Z")

</div>

I'm running ES 7.15. \_template seems to be legacy. \_index\_template is the one moving forward. I also noticed that there's no command to list all \_index\_templates. Is there a template migration guide somewhere?

---

## [Job for elasticsearch.service failed because the control process exited with error code.](https://discuss.elastic.co/t/job-for-elasticsearch-service-failed-because-the-control-process-exited-with-error-code/339884)

<div class="topic-metadata">

**Author:** [@Armel](https://discuss.elastic.co/u/Armel)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 6:13pm UTC](https://discuss.elastic.co/t/job-for-elasticsearch-service-failed-because-the-control-process-exited-with-error-code/339884 "2023-08-02T18:13:38Z")

</div>

---

## [Drop event processor not working on Filebeat](https://discuss.elastic.co/t/drop-event-processor-not-working-on-filebeat/339725)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 4\
**Last updated:** [August 2, 2023, 6:01pm UTC](https://discuss.elastic.co/t/drop-event-processor-not-working-on-filebeat/339725 "2023-08-02T18:01:38Z")

</div>

Hello, I'm trying to create a drop\_event processor to only allow elasticsearch audit logs which have a request.name = "AuthenticateRequest". Clearly my process it not working as all events are not matching and everythin…

---

## [Fleet Self Sign Certficiate in Certificate Chain](https://discuss.elastic.co/t/fleet-self-sign-certficiate-in-certificate-chain/339949)

<div class="topic-metadata">

**Author:** [@amarcelq](https://discuss.elastic.co/u/amarcelq)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 2:19pm UTC](https://discuss.elastic.co/t/fleet-self-sign-certficiate-in-certificate-chain/339949 "2023-08-02T14:19:22Z")

</div>

Hi, unfortunatly I encounter the following error. I don't have any clue which certificate is needed to be added. request to https://epr.elastic.co/categories?kibana.version=8.9.0 failed, reason: self signed certificate…

---

## [How to filter out strings starting with any from a list of strings](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 2:18pm UTC](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948 "2023-08-02T14:18:33Z")

</div>

Hi, I'm wanting to filter out strings starting with a number of characters. I've been able to solve this using a DSL query. Let me provide the example first: # Cleanup DELETE discuss-338708 # Create an index PUT discus…

---

## [Remote Reindex from a datastream to another index](https://discuss.elastic.co/t/remote-reindex-from-a-datastream-to-another-index/339951)

<div class="topic-metadata">

**Author:** [@San72](https://discuss.elastic.co/u/San72)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 2:37pm UTC](https://discuss.elastic.co/t/remote-reindex-from-a-datastream-to-another-index/339951 "2023-08-02T14:37:59Z")

</div>

Hi Guys, we are trying to reindex some data (from another cluster) and ran into an issue. POST \_reindex { "source": { "remote": { "host": "https://COOL\_IP\_ADDRESS:9200", "username": "elastic", "passw…

---

## [Tried making a runtime script to modify field, but now visualize with the index shows all empty fields](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 6\
**Last updated:** [August 2, 2023, 1:35pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708 "2023-08-02T13:35:52Z")

</div>

I have an index with 130 fields. One field I would like to change ranges over longs: 0, 1, 2. In order to do this, I added a runtime field with the following description: def names = \['0': 'Other', '1':'Friendly', '2':…

---

## [Trying to delete documents in index older than XXX](https://discuss.elastic.co/t/trying-to-delete-documents-in-index-older-than-xxx/339852)

<div class="topic-metadata">

**Author:** [@guy\_guy](https://discuss.elastic.co/u/guy_guy)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 7:45pm UTC](https://discuss.elastic.co/t/trying-to-delete-documents-in-index-older-than-xxx/339852 "2023-08-01T19:45:00Z")

</div>

I need to delete some documents from indexes older than XXX days, but delete\_by\_query doesn't seem to be working for me. Here is an example query I'm trying to run POST shipment-log/\_delete\_by\_query { "query": { …

---

## [Ingest Real time logs to elasticsearch using Logstash](https://discuss.elastic.co/t/ingest-real-time-logs-to-elasticsearch-using-logstash/339788)

<div class="topic-metadata">

**Author:** [@harshal](https://discuss.elastic.co/u/harshal)\
**Replies:** 3\
**Last updated:** [August 2, 2023, 1:17pm UTC](https://discuss.elastic.co/t/ingest-real-time-logs-to-elasticsearch-using-logstash/339788 "2023-08-02T13:17:55Z")

</div>

I want to Ingest Realtime logs of Apps into Elasticsearch using Logstash and Create Report on Kibana, So Guide me

---

## [How to monitor different ES cloud clusters from different organizations centrally using ES cloud monitoring cluster.](https://discuss.elastic.co/t/how-to-monitor-different-es-cloud-clusters-from-different-organizations-centrally-using-es-cloud-monitoring-cluster/339813)

<div class="topic-metadata">

**Author:** [@latsayya](https://discuss.elastic.co/u/latsayya)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 1:17pm UTC](https://discuss.elastic.co/t/how-to-monitor-different-es-cloud-clusters-from-different-organizations-centrally-using-es-cloud-monitoring-cluster/339813 "2023-08-02T13:17:26Z")

</div>

Is there any feature in the Elastic Cloud version to monitor all our customers' ES production clusters from our cluster as central monitoring? Please suggest how we can do it if there is no available straight feature. A…

---

## [Unable to get logs to elastalert with helk](https://discuss.elastic.co/t/unable-to-get-logs-to-elastalert-with-helk/339926)

<div class="topic-metadata">

**Author:** [@deloittepocra](https://discuss.elastic.co/u/deloittepocra)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 1:16pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-to-elastalert-with-helk/339926 "2023-08-02T13:16:59Z")

</div>

Hi Team, I have successfully set up helk by following the instructions provided in the GitHub repository. Additionally, I have configured winlogbeat to send my event/sysmon logs to Kibana through Kafka. Now, my goal is …

---

## [Unknown reason of All Elastic indices deletion repeatedly](https://discuss.elastic.co/t/unknown-reason-of-all-elastic-indices-deletion-repeatedly/339934)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 6\
**Last updated:** [August 2, 2023, 12:25pm UTC](https://discuss.elastic.co/t/unknown-reason-of-all-elastic-indices-deletion-repeatedly/339934 "2023-08-02T12:25:49Z")

</div>

My elasticsearch instance is deployed in an EC2 instance and due to some reason, all my indices got deleted on 20th of July. After recovering the data on 30th, they got deleted again on 31st and then on 1st of August aga…

---

## [Filter vector search results to get only relevant documents?](https://discuss.elastic.co/t/filter-vector-search-results-to-get-only-relevant-documents/339543)

<div class="topic-metadata">

**Author:** [@john\_nicolas](https://discuss.elastic.co/u/john_nicolas)\
**Replies:** 10\
**Last updated:** [August 2, 2023, 12:15pm UTC](https://discuss.elastic.co/t/filter-vector-search-results-to-get-only-relevant-documents/339543 "2023-08-02T12:15:55Z")

</div>

I am not an expert in elastic queries, I have not found a solution to filter my results. My index contains 450,000 documents. The issue is that when I perform a search, it always returns all 450,000 documents, sorted by …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=460)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=462)
