# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=523

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 524

---

## [Kibana8.8.0 error with 'guidedOnboarding'](https://discuss.elastic.co/t/kibana8-8-0-error-with-guidedonboarding/334700)

<div class="topic-metadata">

**Author:** [@jiwon](https://discuss.elastic.co/u/jiwon)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 2:59pm UTC](https://discuss.elastic.co/t/kibana8-8-0-error-with-guidedonboarding/334700 "2023-06-02T14:59:46Z")

</div>

hello :slight\_smile: I just installed Elasticsearch and Kibana. but I have some problem. I opened Kibana web browser to get started. And I input my enrollment token, username and password. enrollment token, username …

---

## [Problem with login after upgrading to 8.8.0](https://discuss.elastic.co/t/problem-with-login-after-upgrading-to-8-8-0/335083)

<div class="topic-metadata">

**Author:** [@ccaillet](https://discuss.elastic.co/u/ccaillet)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 2:40pm UTC](https://discuss.elastic.co/t/problem-with-login-after-upgrading-to-8-8-0/335083 "2023-06-02T14:40:30Z")

</div>

Hi all, I've upgrade a cluster from 8.7.1 to 8.8.0 it's a small cluster with 3 nodes and two kibana instances. All is working well until the upgrade to 8.8.0. Globally no error during upgrade BUT unable to log in throug…

---

## [RegexpError: undefined](https://discuss.elastic.co/t/regexperror-undefined/334714)

<div class="topic-metadata">

**Author:** [@M\_D](https://discuss.elastic.co/u/M_D)\
**Replies:** 4\
**Last updated:** [June 2, 2023, 2:37pm UTC](https://discuss.elastic.co/t/regexperror-undefined/334714 "2023-06-02T14:37:30Z")

</div>

I am getting the following error using logstash:8.6.2 docker image: \[2023-05-30T18:42:18,144\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<RegexpError: undefined group op…

---

## [How to size the ELK platform for on-premise setup / on-cloud setup](https://discuss.elastic.co/t/how-to-size-the-elk-platform-for-on-premise-setup-on-cloud-setup/335048)

<div class="topic-metadata">

**Author:** [@shpankaj](https://discuss.elastic.co/u/shpankaj)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 1:45pm UTC](https://discuss.elastic.co/t/how-to-size-the-elk-platform-for-on-premise-setup-on-cloud-setup/335048 "2023-06-02T13:45:12Z")

</div>

We have to ingest logs and analyze as part of SOC services covering 100 windows 10 / 11 endpoints, 2 FortiGate F100 firewall, 20 Windows servers, 20 managed network switches of 24 ports, 120 EDR - sentinelOne. What shou…

---

## [Logstash unable to parse specific format of log](https://discuss.elastic.co/t/logstash-unable-to-parse-specific-format-of-log/334815)

<div class="topic-metadata">

**Author:** [@SmoZyNS](https://discuss.elastic.co/u/SmoZyNS)\
**Replies:** 11\
**Last updated:** [June 2, 2023, 1:35pm UTC](https://discuss.elastic.co/t/logstash-unable-to-parse-specific-format-of-log/334815 "2023-06-02T13:35:33Z")

</div>

Hello I am looking for some help since getting some headaches when trying to parse some logs Raw logs cs1Label=username cs1=/test@test.com cn1Label=actionSuccess cn1=1 deviceCustomDate1Label=userActionTime deviceCusto…

---

## [Filebeat filestream with pipeline and multiline](https://discuss.elastic.co/t/filebeat-filestream-with-pipeline-and-multiline/335015)

<div class="topic-metadata">

**Author:** [@das](https://discuss.elastic.co/u/das)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-filestream-with-pipeline-and-multiline/335015 "2023-06-02T13:12:44Z")

</div>

I have a log format I cannot change that leads into multiline messages. I have a Ingest Pipeline set up in Kibana that works just fine on sample records. My problem is that My multiline parser seems to be ignored (at lea…

---

## [Help with creating a Logstash configuration file for Postfix log analysis](https://discuss.elastic.co/t/help-with-creating-a-logstash-configuration-file-for-postfix-log-analysis/335078)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 12:38pm UTC](https://discuss.elastic.co/t/help-with-creating-a-logstash-configuration-file-for-postfix-log-analysis/335078 "2023-06-02T12:38:59Z")

</div>

Hello everybody Can someone help to correctly create a configuration file that will display the fields from the postfix log that from status Message-id in Kiban in one line and not as in the screenshot I will be g…

---

## [Migrating Fluent Mappings from NEST to Elastic.Clients.Elasticsearch 8.1.1 Client](https://discuss.elastic.co/t/migrating-fluent-mappings-from-nest-to-elastic-clients-elasticsearch-8-1-1-client/335077)

<div class="topic-metadata">

**Author:** [@jrogalan](https://discuss.elastic.co/u/jrogalan)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 12:33pm UTC](https://discuss.elastic.co/t/migrating-fluent-mappings-from-nest-to-elastic-clients-elasticsearch-8-1-1-client/335077 "2023-06-02T12:33:02Z")

</div>

How are we supposed to migrate a code like the following using NEST 7.17.5 to the new Elastic.Clients.Elasticsearch 8.1.1 client where the method .Object does not accept any longer the generic type of the child object. …

---

## [Cannot find write index](https://discuss.elastic.co/t/cannot-find-write-index/334683)

<div class="topic-metadata">

**Author:** [@Shreyansh\_Narang](https://discuss.elastic.co/u/Shreyansh_Narang)\
**Replies:** 13\
**Last updated:** [June 2, 2023, 11:46am UTC](https://discuss.elastic.co/t/cannot-find-write-index/334683 "2023-06-02T11:46:41Z")

</div>

Getting below error policy \[ilm\_cedar\] for index \[cedar-00001\] failed on step \[{"phase":"hot","action":"rollover","name":"check-rollover-ready"}\]. Moving to ERROR step java.lang.IllegalArgumentException: rollover targe…

---

## [Invalid version of beats protocol: 69 and 70](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69-and-70/334823)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 4\
**Last updated:** [June 2, 2023, 11:04am UTC](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69-and-70/334823 "2023-06-02T11:04:38Z")

</div>

Hello everybody Help to understand the problem There is an Oracle Linux 8 server on which Postfix and Filebeat 8.7.1 are installed Filebeat configuration # ============================== Filebeat inputs =============…

---

## [LogStash::Json::ParserError: Unexpected end-of-input: expected close marker for Array](https://discuss.elastic.co/t/logstash-unexpected-end-of-input-expected-close-marker-for-array/335071)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 10:54am UTC](https://discuss.elastic.co/t/logstash-unexpected-end-of-input-expected-close-marker-for-array/335071 "2023-06-02T10:54:46Z")

</div>

Hi Experts, I want to ingest data from a text file (refer data.txt) to elastic using logstash and in order to achieve it, I have created the logstash.conf file as mentioned below - logstash.conf - input { file { …

---

## [Query\_string search exact phrase causes performance issues](https://discuss.elastic.co/t/query-string-search-exact-phrase-causes-performance-issues/335055)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 10:44am UTC](https://discuss.elastic.co/t/query-string-search-exact-phrase-causes-performance-issues/335055 "2023-06-02T10:44:22Z")

</div>

Hi all, When I make query\_string search exact phrase in Elasticsearch, POST /myindex\_\*/\_search { "query": { "query\_string": { "query": "\\"Classe A\\"" } } The query is run and shows hits, but sho…

---

## [Filebeat with multiple kibana instances](https://discuss.elastic.co/t/filebeat-with-multiple-kibana-instances/335070)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 10:41am UTC](https://discuss.elastic.co/t/filebeat-with-multiple-kibana-instances/335070 "2023-06-02T10:41:20Z")

</div>

Hello , Here I take logs use case as an example, Basically, we'll collect these system logs, application logs for each application on our production, and ship them to different logstash servers and different kibana inst…

---

## [Elastic Stack 8.3.3 - config changes fails](https://discuss.elastic.co/t/elastic-stack-8-3-3-config-changes-fails/334969)

<div class="topic-metadata">

**Author:** [@afmin](https://discuss.elastic.co/u/afmin)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 10:10am UTC](https://discuss.elastic.co/t/elastic-stack-8-3-3-config-changes-fails/334969 "2023-06-02T10:10:19Z")

</div>

Hi I am trying to increase my Master Nodes with more diskspace. The two nodes are used with 82 and 83% diskspace. When I try an config change from 1 to 2 availability zones it fails by the step "Calling Elasticsearch no…

---

## [Elasticsearch performance in HDD vs SSD and 32 GB vs 64 GB of RAM](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 24\
**Last updated:** [June 2, 2023, 9:47am UTC](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622 "2023-06-02T09:47:22Z")

</div>

I understand from what I have read that ES works best in conjunction with a sweet spot of 64 GB RAM per node and a fair bit of SSD (3-4 TB per node, with multiple shards in each node to handle primary copies and replicas…

---

## [There is a problem with elastic agent pushing logstash](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335063)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 9:13am UTC](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335063 "2023-06-02T09:13:29Z")

</div>

By changing the original strategy of the elastic agent to push the log to Elasticsearch to push to the new strategy to push to logstash, why the log is still in the original Elasticsearch, but not pushed to the new lo…

---

## [Elasticsearch 7.10.2 error](https://discuss.elastic.co/t/elasticsearch-7-10-2-error/334975)

<div class="topic-metadata">

**Author:** [@anderstr1](https://discuss.elastic.co/u/anderstr1)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 9:08am UTC](https://discuss.elastic.co/t/elasticsearch-7-10-2-error/334975 "2023-06-02T09:08:53Z")

</div>

I am trying to setup Elasticsearch version 7.10.2 using the official docker image. I only need a single-node cluster and I have successfully managed to set it up locally in the container. This is the output from health …

---

## [How to remove low correlation results?](https://discuss.elastic.co/t/how-to-remove-low-correlation-results/335056)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 8:31am UTC](https://discuss.elastic.co/t/how-to-remove-low-correlation-results/335056 "2023-06-02T08:31:03Z")

</div>

I want to be able to filter my search results for less relevant results. So I use the min\_score for filtering. like this: GET xxx/\_search { "min\_score": 2.8, "query": { "match": { "xxx": "xxxx" } }…

---

## [Help with Grok (syntax issue as well as question regarding double quotes)](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 7\
**Last updated:** [June 2, 2023, 7:19am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891 "2023-06-02T07:19:40Z")

</div>

This is a sample log that I want to parse: type=EXECVE msg=audit(1684525987.999:148345): argc=2 a0="vim" a1="logstash-syslog.conf" This is the grok filter I am trying: type=%{WORD:type} msg=audit\\(%{NUMBER:audit}\\): a…

---

## [Exporting message fields from Elasticsearch for one years](https://discuss.elastic.co/t/exporting-message-fields-from-elasticsearch-for-one-years/335029)

<div class="topic-metadata">

**Author:** [@Brat\_Qaqa](https://discuss.elastic.co/u/Brat_Qaqa)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 6:44am UTC](https://discuss.elastic.co/t/exporting-message-fields-from-elasticsearch-for-one-years/335029 "2023-06-02T06:44:35Z")

</div>

Hi, what is the best/easiest way of exporting message field from Elasticsearch to some text/json file?

---

## [Suggestion needed in painless script](https://discuss.elastic.co/t/suggestion-needed-in-painless-script/335052)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 6:20am UTC](https://discuss.elastic.co/t/suggestion-needed-in-painless-script/335052 "2023-06-02T06:20:51Z")

</div>

Hi Team, Sorry, I am new to painless script and ES transform. Please bear with me on the query below. I have scenario to define a painless script in ES transform where the script needs to increase the timestamp by 1sec…

---

## [Need help in setting up Elasticsearch cluster](https://discuss.elastic.co/t/need-help-in-setting-up-elasticsearch-cluster/334642)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 8\
**Last updated:** [June 2, 2023, 5:57am UTC](https://discuss.elastic.co/t/need-help-in-setting-up-elasticsearch-cluster/334642 "2023-06-02T05:57:18Z")

</div>

Hi there, I am trying to run 2 nodes of elasticsearch and want them to form a cluster. But while running i am getting:- {"@timestamp":"2023-05-30T07:06:22.601Z", "log.level": "WARN", "message":"This node is a fully-fo…

---

## [How can I unwind array in elasticsearch](https://discuss.elastic.co/t/how-can-i-unwind-array-in-elasticsearch/335046)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 5:14am UTC](https://discuss.elastic.co/t/how-can-i-unwind-array-in-elasticsearch/335046 "2023-06-02T05:14:35Z")

</div>

Hii { "size": 0, "aggs": { "location\_buckets": { "composite": { "size": 1000, "sources": \[ { "city": { "terms": { "field": "location.city…

---

## [Multiple Out Of Memory Errors occurring, sometimes causing Cluster State Red Alerts](https://discuss.elastic.co/t/multiple-out-of-memory-errors-occurring-sometimes-causing-cluster-state-red-alerts/334985)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 4:03am UTC](https://discuss.elastic.co/t/multiple-out-of-memory-errors-occurring-sometimes-causing-cluster-state-red-alerts/334985 "2023-06-02T04:03:34Z")

</div>

We are getting many Out Of Memory errors on one cluster, but other clusters with similar size are not facing the issue. All the errors are of same type. \[2023-06-01T11:30:41,368\]\[ERROR\]\[o.e.b.ElasticsearchUncaughtExcept…

---

## [Output HTTP: Problem to send @metadata from one pipeline into another](https://discuss.elastic.co/t/output-http-problem-to-send-metadata-from-one-pipeline-into-another/335043)

<div class="topic-metadata">

**Author:** [@junchao](https://discuss.elastic.co/u/junchao)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 3:38am UTC](https://discuss.elastic.co/t/output-http-problem-to-send-metadata-from-one-pipeline-into-another/335043 "2023-06-02T03:38:38Z")

</div>

I am trying to send the value of \[@metadata\]\[usertag\] from one pipeline 1 to pipeline 2. I tried to parse the value using "headers" setting but the value parsed is the string: "%{\[@metadata\]\[usertag\]}" and not the vari…

---

## [Embedding query to baseurl](https://discuss.elastic.co/t/embedding-query-to-baseurl/334984)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 1:03am UTC](https://discuss.elastic.co/t/embedding-query-to-baseurl/334984 "2023-06-02T01:03:44Z")

</div>

I have url to connect to elasticsearch forexample ip:9200 I have query suppose { "query": { "range": { "@timestamp": { "gte": "now-1d/d", "lt": "now/d" } } }, "aggs": { …

---

## [Can we use dense vector field in ES v7.10 for free?](https://discuss.elastic.co/t/can-we-use-dense-vector-field-in-es-v7-10-for-free/334994)

<div class="topic-metadata">

**Author:** [@Vivek\_Sagar](https://discuss.elastic.co/u/Vivek_Sagar)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 1:02am UTC](https://discuss.elastic.co/t/can-we-use-dense-vector-field-in-es-v7-10-for-free/334994 "2023-06-02T01:02:56Z")

</div>

With my installation of elasticsearch v7.10. I see x-pack enabled is true. So I am assuming the free features in x-pack is available to use. When i create a mapping with data type dense vector, I am able to do so and al…

---

## [Understanding subscriptions](https://discuss.elastic.co/t/understanding-subscriptions/335026)

<div class="topic-metadata">

**Author:** [@kevingscott](https://discuss.elastic.co/u/kevingscott)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 12:37am UTC](https://discuss.elastic.co/t/understanding-subscriptions/335026 "2023-06-02T00:37:27Z")

</div>

Hello, We are trying to estimate the cost of implementing Elastic and I am confused about how the subscriptions work. Let's say that we purchased the Premium subscription and then deployed a Dev, QA and Production envi…

---

## [Fleet server managed elastic agent deployment in a azure managed kubernetes cluster running windows](https://discuss.elastic.co/t/fleet-server-managed-elastic-agent-deployment-in-a-azure-managed-kubernetes-cluster-running-windows/335038)

<div class="topic-metadata">

**Author:** [@rtalreja](https://discuss.elastic.co/u/rtalreja)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:14pm UTC](https://discuss.elastic.co/t/fleet-server-managed-elastic-agent-deployment-in-a-azure-managed-kubernetes-cluster-running-windows/335038 "2023-06-01T23:14:47Z")

</div>

I want help with elastic-agent daemonset deployment on an Azure managed Kubernetes cluster. This agent is configured on fleet server via a policy. Searching online I found elastic-agent-managed-kubernetes.yaml file for …

---

## [Ingest EVTX file with Elastic Agent](https://discuss.elastic.co/t/ingest-evtx-file-with-elastic-agent/335031)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 7:41pm UTC](https://discuss.elastic.co/t/ingest-evtx-file-with-elastic-agent/335031 "2023-06-01T19:41:59Z")

</div>

I know that it is possible to ingest evtx files with Winlogbeat (Not sure how to read from .evtx files | Winlogbeat Reference \[8.8\] | Elastic) Is there a way to do this with Elastic Agent?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=522)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=524)
