# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=492

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 493

---

## [Incoorporate APM agent logging with application logging](https://discuss.elastic.co/t/incoorporate-apm-agent-logging-with-application-logging/337464)

<div class="topic-metadata">

**Author:** [@Smoke](https://discuss.elastic.co/u/Smoke)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 1:38pm UTC](https://discuss.elastic.co/t/incoorporate-apm-agent-logging-with-application-logging/337464 "2023-07-03T13:38:58Z")

</div>

Hello all, I am trying to incoorporate the logging coming from the apm agent with my application logging. However, I do not seem to be able to figure out how to use the custom layout class that I defined and use for my …

---

## [Configure NGINX Proxy for Elastic](https://discuss.elastic.co/t/configure-nginx-proxy-for-elastic/337462)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 1:30pm UTC](https://discuss.elastic.co/t/configure-nginx-proxy-for-elastic/337462 "2023-07-03T13:30:52Z")

</div>

I configured three nodes as master. I created a certificate for each one, which is used in HTTP and Transport requests. There is also a username with a password to access the elasticsearch. Note: Since I created the c…

---

## [Index template creation](https://discuss.elastic.co/t/index-template-creation/337049)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 6\
**Last updated:** [July 3, 2023, 12:48pm UTC](https://discuss.elastic.co/t/index-template-creation/337049 "2023-07-03T12:48:36Z")

</div>

during the template creation based on the json data , i am facing the issues for the data, even i have defined the nested type. please suggest . "type": "illegal\_argument\_exception", "reason": "composable template \[…

---

## [Slow log took time questions](https://discuss.elastic.co/t/slow-log-took-time-questions/337384)

<div class="topic-metadata">

**Author:** [@tengfei225](https://discuss.elastic.co/u/tengfei225)\
**Replies:** 3\
**Last updated:** [July 3, 2023, 12:25pm UTC](https://discuss.elastic.co/t/slow-log-took-time-questions/337384 "2023-07-03T12:25:44Z")

</div>

Hi I have some questions about the slow log took time I want to only get the process time in elasticsearch server using esrally to do the benchmark So I opened the slow log like below PUT /myIndex/\_settings { "i…

---

## [A question about separator in logstash](https://discuss.elastic.co/t/a-question-about-separator-in-logstash/337427)

<div class="topic-metadata">

**Author:** [@caixukun](https://discuss.elastic.co/u/caixukun)\
**Replies:** 5\
**Last updated:** [July 3, 2023, 11:44am UTC](https://discuss.elastic.co/t/a-question-about-separator-in-logstash/337427 "2023-07-03T11:44:42Z")

</div>

my data is: 123456@gmail.com----john----password 123456@gmail.com----john----p@ssword 123456@gmail.com----john----123456 123456@gmail.com----john----123456 123456@gmail.com----john----123----456 123456@gmail.com---…

---

## [How filebeat process memory mapped log files](https://discuss.elastic.co/t/how-filebeat-process-memory-mapped-log-files/337447)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Borisov](https://discuss.elastic.co/u/Aleksandr_Borisov)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 11:26am UTC](https://discuss.elastic.co/t/how-filebeat-process-memory-mapped-log-files/337447 "2023-07-03T11:26:17Z")

</div>

I have found really strange behaviour of filebeat. Filebeat stop harvesting memory mapped files. I'm using log files which has constant size. To write data to logs i'm writing just string to memory and kernel flush it up…

---

## [Elasticsearch es-client pods are down after master node reboot](https://discuss.elastic.co/t/elasticsearch-es-client-pods-are-down-after-master-node-reboot/337442)

<div class="topic-metadata">

**Author:** [@Shyamsundar\_Rajkumar](https://discuss.elastic.co/u/Shyamsundar_Rajkumar)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 10:34am UTC](https://discuss.elastic.co/t/elasticsearch-es-client-pods-are-down-after-master-node-reboot/337442 "2023-07-03T10:34:22Z")

</div>

I have deployed Elasticsearch 7 in our kubernetes cluster. The es-client-7 pods are going down when the master node is rebooted. When checking logs I found "master not discovered yet" . The statefulsets es-master and es…

---

## [ILM Policy getting stuck here](https://discuss.elastic.co/t/ilm-policy-getting-stuck-here/337383)

<div class="topic-metadata">

**Author:** [@dhawal](https://discuss.elastic.co/u/dhawal)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 10:16am UTC](https://discuss.elastic.co/t/ilm-policy-getting-stuck-here/337383 "2023-07-03T10:16:56Z")

</div>

I am getting below mentioned status here for most of the index i have. \[Index name\]lifecycle action \[migrate\] waiting for \[6\] shards to be moved to the \[data\_warm\] tier (tier migration preference configuration is \[data\_…

---

## [Secure logstash connection to elasticsearch](https://discuss.elastic.co/t/secure-logstash-connection-to-elasticsearch/337369)

<div class="topic-metadata">

**Author:** [@PeroWong](https://discuss.elastic.co/u/PeroWong)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 10:12am UTC](https://discuss.elastic.co/t/secure-logstash-connection-to-elasticsearch/337369 "2023-07-03T10:12:26Z")

</div>

I follow the tutorial(Install Elasticsearch with Docker | Elasticsearch Guide \[8.8\] | Elastic) creating certs in the docker-compose.yml services setup. And I follow the guide to config logstash scure Secure your connect…

---

## [Automatic login with embedded dashboard](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179)

<div class="topic-metadata">

**Author:** [@aa09](https://discuss.elastic.co/u/aa09)\
**Replies:** 3\
**Last updated:** [July 3, 2023, 10:07am UTC](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179 "2023-07-03T10:07:58Z")

</div>

I have a dashboard that I want to share to users who are logged in to my application. I followed the documentation and added the following to my elastic.yml xpack.security.authc.providers: basic.basic1: order: 0 ano…

---

## [Some fleet agent are not reporting to fleet server and cpu,memory metrics are not showing on fleet manager UI .Please suggest how i can troubleshoot](https://discuss.elastic.co/t/some-fleet-agent-are-not-reporting-to-fleet-server-and-cpu-memory-metrics-are-not-showing-on-fleet-manager-ui-please-suggest-how-i-can-troubleshoot/336068)

<div class="topic-metadata">

**Author:** [@irshadalam](https://discuss.elastic.co/u/irshadalam)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 9:16am UTC](https://discuss.elastic.co/t/some-fleet-agent-are-not-reporting-to-fleet-server-and-cpu-memory-metrics-are-not-showing-on-fleet-manager-ui-please-suggest-how-i-can-troubleshoot/336068 "2023-07-03T09:16:31Z")

</div>

Hi,Some fleet agent are not reporting cpu,memory metrics on fleet manager UI portal. I have checked below - 1.Agent installed and showing in healthy state. 2.telnet to fleet server is fine. 3.ca certificate are also …

---

## [Hi All, so I have a requirement where I need logstash to capture error log messages and trigger a mail upon that , is that possible with basic open source version. Thanks in advance](https://discuss.elastic.co/t/hi-all-so-i-have-a-requirement-where-i-need-logstash-to-capture-error-log-messages-and-trigger-a-mail-upon-that-is-that-possible-with-basic-open-source-version-thanks-in-advance/337423)

<div class="topic-metadata">

**Author:** [@Akulainelastic](https://discuss.elastic.co/u/Akulainelastic)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 8:33am UTC](https://discuss.elastic.co/t/hi-all-so-i-have-a-requirement-where-i-need-logstash-to-capture-error-log-messages-and-trigger-a-mail-upon-that-is-that-possible-with-basic-open-source-version-thanks-in-advance/337423 "2023-07-03T08:33:42Z")

</div>

Continuing the discussion from Timestamp problem created using dissect:

---

## [Aggregation results in human readable number by default](https://discuss.elastic.co/t/aggregation-results-in-human-readable-number-by-default/337316)

<div class="topic-metadata">

**Author:** [@Irfan\_Harun](https://discuss.elastic.co/u/Irfan_Harun)\
**Replies:** 4\
**Last updated:** [July 3, 2023, 7:58am UTC](https://discuss.elastic.co/t/aggregation-results-in-human-readable-number-by-default/337316 "2023-07-03T07:58:32Z")

</div>

Hello all, This is the first time, I'm working with a Kibana and I've been asked to make changes to an existing visualization. the visualization shows an aggregated value using sum(my\_field). assuming the result of su…

---

## [Track down responsible queries for deprecation warnings](https://discuss.elastic.co/t/track-down-responsible-queries-for-deprecation-warnings/337425)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 7:51am UTC](https://discuss.elastic.co/t/track-down-responsible-queries-for-deprecation-warnings/337425 "2023-07-03T07:51:31Z")

</div>

Hello, we want to finally upgrade our cluster to version 8. According to the Upgrade Assistant in Kibana, we only need to check the deprecation logs. In these I find something like this \[2023-06-30T14:36:47,251\]\[CRITI…

---

## [Transform nicing](https://discuss.elastic.co/t/transform-nicing/337277)

<div class="topic-metadata">

**Author:** [@ddolcimascolo](https://discuss.elastic.co/u/ddolcimascolo)\
**Replies:** 2\
**Last updated:** [July 3, 2023, 7:48am UTC](https://discuss.elastic.co/t/transform-nicing/337277 "2023-07-03T07:48:27Z")

</div>

Hi guys, We make use of transforms extensively in a production cluster (6 nodes of 20 CPU 32GB RAM, all nodes have all roles) with approximatively 250 transforms running in continuous mode. Some transforms have a freque…

---

## [Azure-blob-storage input: fatal error: concurrent map iteration and map write](https://discuss.elastic.co/t/azure-blob-storage-input-fatal-error-concurrent-map-iteration-and-map-write/336364)

<div class="topic-metadata">

**Author:** [@kdobmayer](https://discuss.elastic.co/u/kdobmayer)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 7:22am UTC](https://discuss.elastic.co/t/azure-blob-storage-input-fatal-error-concurrent-map-iteration-and-map-write/336364 "2023-07-03T07:22:54Z")

</div>

I am getting an error using filebeat with azure-blob-storage input plugin. I am using filebeat version 8.8.1 and the following configuration: - type: azure-blob-storage id: \<id\> enabled: true account\_name: \<accoun…

---

## [How to add text with values to a dashboard?](https://discuss.elastic.co/t/how-to-add-text-with-values-to-a-dashboard/337366)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 6:58am UTC](https://discuss.elastic.co/t/how-to-add-text-with-values-to-a-dashboard/337366 "2023-07-03T06:58:31Z")

</div>

I would like to have in my dashboard a widget that says There are currently 200 people in 17 locations The 200 and 17 would actually be numbers calculated from queries (number of records + filters). Is this possible…

---

## [Caused by: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate",](https://discuss.elastic.co/t/caused-by-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/337415)

<div class="topic-metadata">

**Author:** [@Khumendra](https://discuss.elastic.co/u/Khumendra)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 5:46am UTC](https://discuss.elastic.co/t/caused-by-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/337415 "2023-07-03T05:46:30Z")

</div>

Hi Team, Please help me on this when I am trying to integrate apm-server I get this error. kubectl logs elasticsearch-master-0 -n \[namespace\] "stacktrace": \["io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHa…

---

## [About commercial use of the free version](https://discuss.elastic.co/t/about-commercial-use-of-the-free-version/337410)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 3:47am UTC](https://discuss.elastic.co/t/about-commercial-use-of-the-free-version/337410 "2023-07-03T03:47:09Z")

</div>

of the following sites Is "Wildcard field type" of "Free and open-Basic 1,2" available for commercial use free of charge? Is "Free and open -Basic 1, 2" already free for commercial use? I look forward to hearing fro…

---

## ["order" question](https://discuss.elastic.co/t/order-question/337153)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 6\
**Last updated:** [July 2, 2023, 11:54pm UTC](https://discuss.elastic.co/t/order-question/337153 "2023-07-02T23:54:09Z")

</div>

Hello. I would like to ask you something about the text on the official website below. GET /my-index-000001/\_search { "sort" : \[ { "post\_date" : {"order" : "asc", "format": "strict\_date\_optional\_time\_nanos"}}, …

---

## [Gork not work as excpected](https://discuss.elastic.co/t/gork-not-work-as-excpected/337389)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 2, 2023, 4:09pm UTC](https://discuss.elastic.co/t/gork-not-work-as-excpected/337389 "2023-07-02T16:09:51Z")

</div>

Hi Here is my gork filter: \\\[SqlExceptionHelper\\\] SQL (Error|Warning Code): %{NUMBER:error\_code}, SQLState: %{WORD:sql\_state} here is my log: 2023-06-30 01:54:38,867 WARN CUS.InEP-APPGW-121662220 \[SqlExceptionHelper…

---

## [How to receive logs from Kaspersky endpoint security to elasticsearch](https://discuss.elastic.co/t/how-to-receive-logs-from-kaspersky-endpoint-security-to-elasticsearch/336852)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 2\
**Last updated:** [July 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-receive-logs-from-kaspersky-endpoint-security-to-elasticsearch/336852 "2023-07-02T16:01:31Z")

</div>

Hi everyone, i am new in elasticsearch . I configured Fortinet, and it works fine. I want to know how I can retrieve logs and dates from the KES server and solarwinds."

---

## [Training elasticsearch](https://discuss.elastic.co/t/training-elasticsearch/336917)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 4\
**Last updated:** [July 2, 2023, 3:00pm UTC](https://discuss.elastic.co/t/training-elasticsearch/336917 "2023-07-02T15:00:55Z")

</div>

Hi all, As a beginner in elasticsearch and recent gratuate engineering id like to gain a better understanding of market requirements in order to better direct my carrer would you have any tasks or project that would ena…

---

## [Filebeat selftest failt: missing field 'output.elasticsearch.hosts'](https://discuss.elastic.co/t/filebeat-selftest-failt-missing-field-output-elasticsearch-hosts/337388)

<div class="topic-metadata">

**Author:** [@enp2s6](https://discuss.elastic.co/u/enp2s6)\
**Replies:** 2\
**Last updated:** [July 2, 2023, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-selftest-failt-missing-field-output-elasticsearch-hosts/337388 "2023-07-02T12:56:11Z")

</div>

Hello, I have elasticsearch and Kibana install and minimal security settings enabled. After reboot everything works great. However, I can not connect to Kibana. Log: ERROR instance/beat.go:1027 Exiting: error ini…

---

## [Filebeat 8.8.0 error loading template: failed to put data stream: could not put data stream: 400 Bad Request](https://discuss.elastic.co/t/filebeat-8-8-0-error-loading-template-failed-to-put-data-stream-could-not-put-data-stream-400-bad-request/337370)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 12\
**Last updated:** [July 2, 2023, 11:40am UTC](https://discuss.elastic.co/t/filebeat-8-8-0-error-loading-template-failed-to-put-data-stream-could-not-put-data-stream-400-bad-request/337370 "2023-07-02T11:40:35Z")

</div>

I have installed the filebeat 8.8.0 and by running the filebeat setup -e the index is created in index template but when trying to create a data view the index is not showing there and while running the filebeat setup co…

---

## [Elasticsearch and VeloCloud / VMWare SDWAN](https://discuss.elastic.co/t/elasticsearch-and-velocloud-vmware-sdwan/335810)

<div class="topic-metadata">

**Author:** [@hogie365](https://discuss.elastic.co/u/hogie365)\
**Replies:** 4\
**Last updated:** [July 2, 2023, 8:50am UTC](https://discuss.elastic.co/t/elasticsearch-and-velocloud-vmware-sdwan/335810 "2023-07-02T08:50:39Z")

</div>

Afternoon - I'm new to Elasticsearch and want to see if it's possible to connect to a VeloCloud API to pull and analyze logs from the VeloCloud orchestrator. We've been struggling getting back any real content over SNMP…

---

## [How to detect status transition in ingested log data](https://discuss.elastic.co/t/how-to-detect-status-transition-in-ingested-log-data/337335)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 2\
**Last updated:** [July 2, 2023, 4:00am UTC](https://discuss.elastic.co/t/how-to-detect-status-transition-in-ingested-log-data/337335 "2023-07-02T04:00:52Z")

</div>

I would like to ask for a high-level advice how to approach the following problem (we have on-premise Elastic 8.8.0). Periodically every 30 seconds, the following data about status of a resource is ingested into Elastic…

---

## [Kibana filter incorrectly applied](https://discuss.elastic.co/t/kibana-filter-incorrectly-applied/335337)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 6\
**Last updated:** [July 2, 2023, 12:53am UTC](https://discuss.elastic.co/t/kibana-filter-incorrectly-applied/335337 "2023-07-02T00:53:29Z")

</div>

Hello, When we select this filter It seems to apply not only to "update", but also for example to "update-security".... Seems like a bug to me? Willem

---

## [Find unusual pattern](https://discuss.elastic.co/t/find-unusual-pattern/337145)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 4\
**Last updated:** [July 1, 2023, 4:26pm UTC](https://discuss.elastic.co/t/find-unusual-pattern/337145 "2023-07-01T16:26:41Z")

</div>

Need to find unusual send and receive patterns in huge log file, here is the example: 00:00:01.000 S-001 \< 00:00:01.000 S-002 \< 00:00:01.000 S-003 \< 00:00:01.000 S-004 \< 00:00:01.000 S-005 0…

---

## [One or more required cgroup files or directories not found in logstash](https://discuss.elastic.co/t/one-or-more-required-cgroup-files-or-directories-not-found-in-logstash/337348)

<div class="topic-metadata">

**Author:** [@sanjay\_bhati](https://discuss.elastic.co/u/sanjay_bhati)\
**Replies:** 3\
**Last updated:** [July 1, 2023, 4:02pm UTC](https://discuss.elastic.co/t/one-or-more-required-cgroup-files-or-directories-not-found-in-logstash/337348 "2023-07-01T16:02:14Z")

</div>

I am getting error: One or more required cgroup files or directories not found here is my input file input { file { path =\> "/Users/spbhati/Downloads/S3BucketConfiguration.csv" start\_position =\> "beginning" sincedb…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=491)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=493)
