# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=483

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 484

---

## [Ingest error from one pipeline causing errors in other pipelines](https://discuss.elastic.co/t/ingest-error-from-one-pipeline-causing-errors-in-other-pipelines/338255)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 6:53pm UTC](https://discuss.elastic.co/t/ingest-error-from-one-pipeline-causing-errors-in-other-pipelines/338255 "2023-07-12T18:53:42Z")

</div>

The problem we are experiencing is that an ingest error from the Apache integration (agent) is causing an enrichment processor in a separate pipeline to fail with the same error the Apache processor failed with. This is…

---

## [Elasticsearch 7.17 suddenly prevents login](https://discuss.elastic.co/t/elasticsearch-7-17-suddenly-prevents-login/338249)

<div class="topic-metadata">

**Author:** [@eastdrive](https://discuss.elastic.co/u/eastdrive)\
**Replies:** 4\
**Last updated:** [July 12, 2023, 6:35pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-suddenly-prevents-login/338249 "2023-07-12T18:35:38Z")

</div>

I installed elasticsearch 7.17.11 from the artifacts.elastic.co repo with security, on a fresh Ubuntu 20.04.6 node a couple of days ago, for a Magento 2.4.5-p3 store. It worked fine, certainly allowed me to connect remot…

---

## [Filebeat service is failing again and again](https://discuss.elastic.co/t/filebeat-service-is-failing-again-and-again/337642)

<div class="topic-metadata">

**Author:** [@Kanika\_Gola](https://discuss.elastic.co/u/Kanika_Gola)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 5:33pm UTC](https://discuss.elastic.co/t/filebeat-service-is-failing-again-and-again/337642 "2023-07-12T17:33:47Z")

</div>

---

## [Visualization - Threshold Value Based](https://discuss.elastic.co/t/visualization-threshold-value-based/338026)

<div class="topic-metadata">

**Author:** [@Surabhi\_Pol](https://discuss.elastic.co/u/Surabhi_Pol)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 5:08pm UTC](https://discuss.elastic.co/t/visualization-threshold-value-based/338026 "2023-07-12T17:08:37Z")

</div>

Hi All, We are using Kibana (Stack Management 7.16.1) for analyzing purpose. Here some vital information's about servers/applications - success / failure rate we are visualizing through dashboards - Visualizations (char…

---

## [Cannot increase buffer: current=512000 requested=544768 max=512000](https://discuss.elastic.co/t/cannot-increase-buffer-current-512000-requested-544768-max-512000/338020)

<div class="topic-metadata">

**Author:** [@premkumarmuddeneni](https://discuss.elastic.co/u/premkumarmuddeneni)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 5:06pm UTC](https://discuss.elastic.co/t/cannot-increase-buffer-current-512000-requested-544768-max-512000/338020 "2023-07-12T17:06:36Z")

</div>

We are using Elastic search of V8.7.0 and fluent bit v2.0.10 and kubernetes is v1.24. We had deployed the Fluent bit as a daemon set in kubernetes and collecting the logs from pods and pushing to Elasticsearch We are f…

---

## [Filebeat is using more than 4GB memory](https://discuss.elastic.co/t/filebeat-is-using-more-than-4gb-memory/337952)

<div class="topic-metadata">

**Author:** [@Sharad\_Dubey](https://discuss.elastic.co/u/Sharad_Dubey)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-is-using-more-than-4gb-memory/337952 "2023-07-12T16:53:56Z")

</div>

Hi Champs, My filebeat consumtipn is very high and using more than 4GB of RAM, only log files which I am pushing are some app logs , /var/log/messages and /var/log/secure. Npt sure why this happening. Please help \[roo…

---

## [Kibana Dashboards for inventory tracking with deleted indexes](https://discuss.elastic.co/t/kibana-dashboards-for-inventory-tracking-with-deleted-indexes/337693)

<div class="topic-metadata">

**Author:** [@Sam\_Estes](https://discuss.elastic.co/u/Sam_Estes)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 4:46pm UTC](https://discuss.elastic.co/t/kibana-dashboards-for-inventory-tracking-with-deleted-indexes/337693 "2023-07-12T16:46:43Z")

</div>

Hi, I have an ES database which is updated daily. We maintain two indexes (one for each day's worth of data). During the update, the older of the two indexes is deleted and a new one is created for the new day. We want t…

---

## [Alerts from Kibana log monitoring](https://discuss.elastic.co/t/alerts-from-kibana-log-monitoring/337769)

<div class="topic-metadata">

**Author:** [@SMaric](https://discuss.elastic.co/u/SMaric)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 4:46pm UTC](https://discuss.elastic.co/t/alerts-from-kibana-log-monitoring/337769 "2023-07-12T16:46:38Z")

</div>

Hi We have configured Kibana to ingest our application log files Now we want an Alert from Kibana if it sees 2 log file signals (within a reasonable time of each other) Can someone please point me at an example of ho…

---

## [Does kibana will restart if it can't connect to elasticsearh?](https://discuss.elastic.co/t/does-kibana-will-restart-if-it-cant-connect-to-elasticsearh/337545)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 4:36pm UTC](https://discuss.elastic.co/t/does-kibana-will-restart-if-it-cant-connect-to-elasticsearh/337545 "2023-07-12T16:36:21Z")

</div>

Hi there, i have a question about kibana. so i have a VM that installed kibana and elastic there. then at some point, my elastic is experience OOM, so it produce hprof file. but bufore i knew that my elastic was OOM, i …

---

## [Version mismatch message even though versions match](https://discuss.elastic.co/t/version-mismatch-message-even-though-versions-match/337819)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 15\
**Last updated:** [July 12, 2023, 3:49pm UTC](https://discuss.elastic.co/t/version-mismatch-message-even-though-versions-match/337819 "2023-07-12T15:49:08Z")

</div>

Hi all. I'm trying out ELK 8.8.2, and getting this message: Job creation error The client noticed that the server is not Elasticsearch and we do not support this unknown product. All explanations in various posts s…

---

## [Periodic disconnection of same data nodes](https://discuss.elastic.co/t/periodic-disconnection-of-same-data-nodes/338197)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 3:01pm UTC](https://discuss.elastic.co/t/periodic-disconnection-of-same-data-nodes/338197 "2023-07-12T15:01:53Z")

</div>

Hello, I have a cluster with 3 master, 40 data nodes (d1,d2,...,d40). First 5 data nodes have voting only master role. Only the following data nodes have periodic abnormal behavior: d11,d12,d13,d14,d15,d16,d17,d21,d2…

---

## [Select Timeout parameter for python helper async\_bulk](https://discuss.elastic.co/t/select-timeout-parameter-for-python-helper-async-bulk/338037)

<div class="topic-metadata">

**Author:** [@ionFreeman](https://discuss.elastic.co/u/ionFreeman)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:53pm UTC](https://discuss.elastic.co/t/select-timeout-parameter-for-python-helper-async-bulk/338037 "2023-07-12T14:53:22Z")

</div>

Hello! Every so often, my async\_bulk load fails with a Connection Timeout. I have my timeout parameter set to 60; I had set it arbitrarily high, but it didn't pass code review. I can't just wrap the call in tenacity as I…

---

## [Another mysterious work logstash with errors \_grokparsefailure](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 18\
**Last updated:** [July 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327 "2023-07-12T14:51:43Z")

</div>

again I encounter a problem in the work of logstash, and specifically with grock. Everything is fine in the debugger, the messages are parsed, but as soon as I apply this configuration to the production, then these messa…

---

## [Log Stash Sql Server](https://discuss.elastic.co/t/log-stash-sql-server/338233)

<div class="topic-metadata">

**Author:** [@balupad14](https://discuss.elastic.co/u/balupad14)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:49pm UTC](https://discuss.elastic.co/t/log-stash-sql-server/338233 "2023-07-12T14:49:07Z")

</div>

Hi all, I am trying to insert the data into the Elasticsearch from SQL Server. When I run the logstash, I am getting this error. Not eligible for data streams because config contains one or more settings that are not c…

---

## [Multiple instance of kibana sometime error status 404](https://discuss.elastic.co/t/multiple-instance-of-kibana-sometime-error-status-404/337980)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:33pm UTC](https://discuss.elastic.co/t/multiple-instance-of-kibana-sometime-error-status-404/337980 "2023-07-12T14:33:10Z")

</div>

Hi all, I've tried to use multiple instance of kibana to HA. but then sometime i encounter error like this after refresh the page for a few times i was able to load the page but the problems persists very often for …

---

## [I want to get last record saved to Elasticsearch](https://discuss.elastic.co/t/i-want-to-get-last-record-saved-to-elasticsearch/338235)

<div class="topic-metadata">

**Author:** [@Valerie\_Barbacion](https://discuss.elastic.co/u/Valerie_Barbacion)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 2:32pm UTC](https://discuss.elastic.co/t/i-want-to-get-last-record-saved-to-elasticsearch/338235 "2023-07-12T14:32:51Z")

</div>

Hi Pals, I have a question about throwing request to Elasticsearch. For example given I will going to send a first message to Elasticsearch with has a field value "Sample" and then I send again another message with diffe…

---

## [Not able to fetch data from openshift cluster, when using different namespace](https://discuss.elastic.co/t/not-able-to-fetch-data-from-openshift-cluster-when-using-different-namespace/338232)

<div class="topic-metadata">

**Author:** [@suryakant.k](https://discuss.elastic.co/u/suryakant.k)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 2:12pm UTC](https://discuss.elastic.co/t/not-able-to-fetch-data-from-openshift-cluster-when-using-different-namespace/338232 "2023-07-12T14:12:16Z")

</div>

I need to add elastic agent host in openshift kubernetes cluster, When I am changing namespace in yaml file to elk from kube-system, Pods are not getting ready, daemonset is not ready. But when I am using kube-system a…

---

## [When namespace in kube-state-metrics are changed from kube-system to other, Daemonset is not ready](https://discuss.elastic.co/t/when-namespace-in-kube-state-metrics-are-changed-from-kube-system-to-other-daemonset-is-not-ready/338231)

<div class="topic-metadata">

**Author:** [@suryakant.k](https://discuss.elastic.co/u/suryakant.k)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 1:55pm UTC](https://discuss.elastic.co/t/when-namespace-in-kube-state-metrics-are-changed-from-kube-system-to-other-daemonset-is-not-ready/338231 "2023-07-12T13:55:54Z")

</div>

I want to install a elastic-agent in openshift kubernetes cluster, for that I was installing a kube-state-metrics with elk namespace as I dont want to install it in kube-system namespace. After running command, I get th…

---

## [Values field event.action for Cisco ASA integration](https://discuss.elastic.co/t/values-field-event-action-for-cisco-asa-integration/337794)

<div class="topic-metadata">

**Author:** [@frederikvandeputte](https://discuss.elastic.co/u/frederikvandeputte)\
**Replies:** 6\
**Last updated:** [July 12, 2023, 2:04pm UTC](https://discuss.elastic.co/t/values-field-event-action-for-cisco-asa-integration/337794 "2023-07-12T14:04:30Z")

</div>

Hi Currently parsed events coming from Cisco ASA firewall ingest pipeline show 4 types of values in field event.action: firewall-rule; flow-expiration; flow-creation and error. Value "firewall-rule" is very much a us…

---

## [Creating graph in kibana](https://discuss.elastic.co/t/creating-graph-in-kibana/338208)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 12:58pm UTC](https://discuss.elastic.co/t/creating-graph-in-kibana/338208 "2023-07-12T12:58:19Z")

</div>

Hi i want to try out kibana graphs. How can i get started? i am referring this document But i don't find the graphs option in the menu in kibana. I am using kibana 8.7

---

## [To get message field for json filter](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 12:44pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968 "2023-07-12T12:44:48Z")

</div>

Hi Team, I use json filter to parse my json data but my json data has "message" value. that's why ı'm not able to get standard message field which have all parsed log. I just have "message" field which come from json l…

---

## [Data storage stragety](https://discuss.elastic.co/t/data-storage-stragety/338159)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 12:04pm UTC](https://discuss.elastic.co/t/data-storage-stragety/338159 "2023-07-12T12:04:50Z")

</div>

Hi, I wonder if I already have couple indices that contains a big size of data. I wonder if using snapshot or best compression are good ways to help reduding the size of the existing indices. I have looked at the docu…

---

## [Problem with new script](https://discuss.elastic.co/t/problem-with-new-script/337800)

<div class="topic-metadata">

**Author:** [@Valerija](https://discuss.elastic.co/u/Valerija)\
**Replies:** 33\
**Last updated:** [July 12, 2023, 11:49am UTC](https://discuss.elastic.co/t/problem-with-new-script/337800 "2023-07-12T11:49:08Z")

</div>

Hi there, I created a simple new script and it works w/o problems: def totalGood = doc\['actualQuantity'\].value - doc\['failureQuantity'\].value; return totalGood; Then I tried to create another one and this one does not…

---

## [Issues with pushing packages to my own package registry](https://discuss.elastic.co/t/issues-with-pushing-packages-to-my-own-package-registry/338209)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 11:40am UTC](https://discuss.elastic.co/t/issues-with-pushing-packages-to-my-own-package-registry/338209 "2023-07-12T11:40:24Z")

</div>

I have created new package and i want to push it to my custom hosted package registry? How to update the packages list in my custom hosted package registry?

---

## [How to upgrade metricbeat from 7.17.11 to 7.17.xx or 8.1.xx?](https://discuss.elastic.co/t/how-to-upgrade-metricbeat-from-7-17-11-to-7-17-xx-or-8-1-xx/338183)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/how-to-upgrade-metricbeat-from-7-17-11-to-7-17-xx-or-8-1-xx/338183 "2023-07-12T11:13:59Z")

</div>

How do i upgrade next time from 7.17.11 to 7.17.xx ? or 8.x.x Is there any command which i can use in the Kibana DEV Tool ? Or how is the possible and easy way to do it ?

---

## [Start logstash error](https://discuss.elastic.co/t/start-logstash-error/338146)

<div class="topic-metadata">

**Author:** [@liqiu](https://discuss.elastic.co/u/liqiu)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 8:05pm UTC](https://discuss.elastic.co/t/start-logstash-error/338146 "2023-07-11T20:05:01Z")

</div>

I have configured the logstash.yml configuration file logstash.yml： input {stdin{}} output {stdout{}} But when I enter ./logstash to start, the following error occurs \[2023-07-12T01:16:59,926\]\[INFO \]\[logstash.runner …

---

## [Error creating input: each processor must have exactly one action,but found 2 actions (add\_locale,decode\_json\_fields)](https://discuss.elastic.co/t/error-creating-input-each-processor-must-have-exactly-one-action-but-found-2-actions-add-locale-decode-json-fields/338201)

<div class="topic-metadata">

**Author:** [@farhad\_kh](https://discuss.elastic.co/u/farhad_kh)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:07am UTC](https://discuss.elastic.co/t/error-creating-input-each-processor-must-have-exactly-one-action-but-found-2-actions-add-locale-decode-json-fields/338201 "2023-07-12T10:07:59Z")

</div>

hello i have a cluster kubeadm and collecting logs with filebeat autodiscover and i get this error after depoly 2023-07-12T09:34:19.588Z INFO log/input.go:152 Configured paths: \[/var/log/pods/\*\_554a0c…

---

## [How Elastic APM estimate SQL duraion](https://discuss.elastic.co/t/how-elastic-apm-estimate-sql-duraion/338198)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:04am UTC](https://discuss.elastic.co/t/how-elastic-apm-estimate-sql-duraion/338198 "2023-07-12T10:04:32Z")

</div>

Hi I ran Elastic APM agent with my Application that use jdbc to connect to database. Now I compare top sql duration of Elastic APM agent and database log with below query on kibana: service.target.type : "sqli" and s…

---

## [Help with query please](https://discuss.elastic.co/t/help-with-query-please/338191)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 8:59am UTC](https://discuss.elastic.co/t/help-with-query-please/338191 "2023-07-12T08:59:04Z")

</div>

POST user\_info,user\_auth\_cards\_info/\_search { "size": 0, "query": { "bool": { "filter": \[ { "multi\_match": { "query": "test", "fields": \[ "e\_name.auto…

---

## [Each log line is split into a different document in Elastic](https://discuss.elastic.co/t/each-log-line-is-split-into-a-different-document-in-elastic/338144)

<div class="topic-metadata">

**Author:** [@Merav\_Yaacov](https://discuss.elastic.co/u/Merav_Yaacov)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 5:37am UTC](https://discuss.elastic.co/t/each-log-line-is-split-into-a-different-document-in-elastic/338144 "2023-07-12T05:37:53Z")

</div>

Hi, What can be the reason that each line of log file is split into single document in Elastic? That's how Logstash is configured: input { file { type =\> "log" path =\> \["/etc/logstash/conf.d/files/\*.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=482)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=484)
