# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=531

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 532

---

## [Configpathloader no config files found in path= /etc/logstash/conf.d/\*.conf](https://discuss.elastic.co/t/configpathloader-no-config-files-found-in-path-etc-logstash-conf-d-conf/334465)

<div class="topic-metadata">

**Author:** [@Saud555](https://discuss.elastic.co/u/Saud555)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 6:03pm UTC](https://discuss.elastic.co/t/configpathloader-no-config-files-found-in-path-etc-logstash-conf-d-conf/334465 "2023-05-26T18:03:54Z")

</div>

I am getting an error while running the logstash Error configpathloader no config files found in path= /etc/logstash/conf.d/\* I have logstash.yml and pipelines.yml in place and cross checked all the configuration. but…

---

## [Failed to install microsoft-sentinel-logstash-output-plugin , error execution expired](https://discuss.elastic.co/t/failed-to-install-microsoft-sentinel-logstash-output-plugin-error-execution-expired/331085)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 2\
**Last updated:** [May 26, 2023, 5:54pm UTC](https://discuss.elastic.co/t/failed-to-install-microsoft-sentinel-logstash-output-plugin-error-execution-expired/331085 "2023-05-26T17:54:47Z")

</div>

Hi, I am unable to install the microsoft-sentinel-logstash-output-plugin on logstash server. I am running rhel7.9. I get the following error : ERROR: Something went wrong when installing install, microsoft-sentinel-lo…

---

## [How can I extract a sub-field from a field and print it as a separate field in filebeat?](https://discuss.elastic.co/t/how-can-i-extract-a-sub-field-from-a-field-and-print-it-as-a-separate-field-in-filebeat/334103)

<div class="topic-metadata">

**Author:** [@varunsingla](https://discuss.elastic.co/u/varunsingla)\
**Replies:** 9\
**Last updated:** [May 26, 2023, 5:46pm UTC](https://discuss.elastic.co/t/how-can-i-extract-a-sub-field-from-a-field-and-print-it-as-a-separate-field-in-filebeat/334103 "2023-05-26T17:46:03Z")

</div>

"msg":"{"appName":"abc","eventCategory":"Authentication event","eventType":"Operator record change","id":"12345","ipAddress":"0.0.1.1","nodeID":"nodeabc","operation":"update","operatorID":"admin","operatorRecID":"DATAADM…

---

## [Is it possible to remove Inactive Agents from Fleet?](https://discuss.elastic.co/t/is-it-possible-to-remove-inactive-agents-from-fleet/334043)

<div class="topic-metadata">

**Author:** [@kreed](https://discuss.elastic.co/u/kreed)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 3:51pm UTC](https://discuss.elastic.co/t/is-it-possible-to-remove-inactive-agents-from-fleet/334043 "2023-05-26T15:51:34Z")

</div>

After uninstalling an Agent, as expected the agent shows a status of Offline in Fleet. Then once the agent is unenrolled, it goes to a status of Inactive. A previous question I had asked on this forum was if it is possib…

---

## [Beats Agent Documentation Incorrect on base image used](https://discuss.elastic.co/t/beats-agent-documentation-incorrect-on-base-image-used/334452)

<div class="topic-metadata">

**Author:** [@lgst1997](https://discuss.elastic.co/u/lgst1997)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 3:50pm UTC](https://discuss.elastic.co/t/beats-agent-documentation-incorrect-on-base-image-used/334452 "2023-05-26T15:50:51Z")

</div>

Documentation in the beats agent shows that the docker base image os is CentOS 7 but its actually Ubuntu. This issue is also present in the v7.17.10 documentation. Ex: Run Filebeat on Docker | Filebeat Reference \[8.8\] |…

---

## [Elastic APM](https://discuss.elastic.co/t/elastic-apm/334309)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 3:47pm UTC](https://discuss.elastic.co/t/elastic-apm/334309 "2023-05-26T15:47:11Z")

</div>

hello when i try to run apm on containet its gives me this error while it was running normaly before i think the problrm is in repo of elastic apm this is the logs error of apm

---

## [Manipulation of Drilldown position](https://discuss.elastic.co/t/manipulation-of-drilldown-position/334442)

<div class="topic-metadata">

**Author:** [@martinsbleu](https://discuss.elastic.co/u/martinsbleu)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/manipulation-of-drilldown-position/334442 "2023-05-26T14:38:16Z")

</div>

Hello Team, After reading drilldown documentation, pardon if I am wrong but I couldn't find how to position drilldowns. For example, given 3 drilldowns : The number are the order which drilldown are created. and my…

---

## [Problem of connecting python client with elasticsearch](https://discuss.elastic.co/t/problem-of-connecting-python-client-with-elasticsearch/334437)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 12\
**Last updated:** [May 26, 2023, 2:10pm UTC](https://discuss.elastic.co/t/problem-of-connecting-python-client-with-elasticsearch/334437 "2023-05-26T14:10:12Z")

</div>

I am unable to connect with elastic using python client The code which run with no issue is from elasticsearch import Elasticsearch es = Elasticsearch(\['http://\<your\_ip\_address\>:\<your\_port\>'\]) (I use my ip and port w…

---

## [ILM keep rolling over empty indexes](https://discuss.elastic.co/t/ilm-keep-rolling-over-empty-indexes/332480)

<div class="topic-metadata">

**Author:** [@Adam\_Lin](https://discuss.elastic.co/u/Adam_Lin)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 1:52pm UTC](https://discuss.elastic.co/t/ilm-keep-rolling-over-empty-indexes/332480 "2023-05-26T13:52:39Z")

</div>

Hi according to the following release note, since 8.5.3, ILM won't rollover the empty index by default. I'm using the elk server v8.6.0, and with the ILM policy { "testpolicy" : { "version" : 2, "modified\_d…

---

## [Kibana webhook payload in XML](https://discuss.elastic.co/t/kibana-webhook-payload-in-xml/333864)

<div class="topic-metadata">

**Author:** [@batman](https://discuss.elastic.co/u/batman)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 1:45pm UTC](https://discuss.elastic.co/t/kibana-webhook-payload-in-xml/333864 "2023-05-26T13:45:51Z")

</div>

Hello All, I would want to send events from Kibana to external ticketing system but the external system accepts only xml as payload for processing. Is it possible to somehow send xml as events payload from Kibana ? Hin…

---

## [Filebeat connection vers Elasticsearch](https://discuss.elastic.co/t/filebeat-connection-vers-elasticsearch/334007)

<div class="topic-metadata">

**Author:** [@Lucas\_Chauvry](https://discuss.elastic.co/u/Lucas_Chauvry)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 1:38pm UTC](https://discuss.elastic.co/t/filebeat-connection-vers-elasticsearch/334007 "2023-05-26T13:38:44Z")

</div>

Bonjour, Je commence dans l'apprentissage d'ELK et je suis bloqué sur la configuration. Mon ELK fonctionne correctement, j'arrive a joindre Elasticsearch sur mon IP et le bon port. Cependant, lors de la configuration …

---

## [Elasticsearch dynamic date field mapping](https://discuss.elastic.co/t/elasticsearch-dynamic-date-field-mapping/334436)

<div class="topic-metadata">

**Author:** [@riani.oussama](https://discuss.elastic.co/u/riani.oussama)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 1:25pm UTC](https://discuss.elastic.co/t/elasticsearch-dynamic-date-field-mapping/334436 "2023-05-26T13:25:26Z")

</div>

Hi, I have a problem in handling dates in my indexes. My indexes were created automatically from my application. In one index the field "CreationDate" is of type text (Tue May 23 10:55:12 CEST 2023), in another index …

---

## [I lose all my data when master node restarts](https://discuss.elastic.co/t/i-lose-all-my-data-when-master-node-restarts/334410)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 7\
**Last updated:** [May 26, 2023, 12:54pm UTC](https://discuss.elastic.co/t/i-lose-all-my-data-when-master-node-restarts/334410 "2023-05-26T12:54:45Z")

</div>

Hi, I have EKF stack on Kubernetes, now I have 1 client node, 1 master node and 3 data nodes. When my master node restarts I lose all the data and indices that I have and my master's UUID changes, so I need to restart a…

---

## [Request for Updated Blog Post: Elastic Stack Monitoring with ES 8.7](https://discuss.elastic.co/t/request-for-updated-blog-post-elastic-stack-monitoring-with-es-8-7/333673)

<div class="topic-metadata">

**Author:** [@davidkov](https://discuss.elastic.co/u/davidkov)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 12:39pm UTC](https://discuss.elastic.co/t/request-for-updated-blog-post-elastic-stack-monitoring-with-es-8-7/333673 "2023-05-26T12:39:14Z")

</div>

Dear Sir, @shaunak I would like to express my gratitude for your insightful blog post titled 'Elastic Stack monitoring with Metricbeat via Logstash or Kafka' It has been instrumental in helping me set up a centralized …

---

## [Ruby error found during Logstash start with IBM Semeru Java](https://discuss.elastic.co/t/ruby-error-found-during-logstash-start-with-ibm-semeru-java/334431)

<div class="topic-metadata">

**Author:** [@KevinT1](https://discuss.elastic.co/u/KevinT1)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 12:35pm UTC](https://discuss.elastic.co/t/ruby-error-found-during-logstash-start-with-ibm-semeru-java/334431 "2023-05-26T12:35:53Z")

</div>

Logstash version: logstash-8.7.1 JDK: \> $ ./java -version \> java version "11.0.18" 2023-01-17 \> IBM Semeru Runtime Certified Edition 11.0.18.0 (build 11.0.18+10) \> Eclipse OpenJ9 VM 11.0.18.0 (build openj9-0.36.1, JRE …

---

## [Filebeat+pipeline+es log duplication Help!](https://discuss.elastic.co/t/filebeat-pipeline-es-log-duplication-help/334406)

<div class="topic-metadata">

**Author:** [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 12:23pm UTC](https://discuss.elastic.co/t/filebeat-pipeline-es-log-duplication-help/334406 "2023-05-26T12:23:27Z")

</div>

When I use the following configuration of filebeat+pipeline to collect nginx logs, multiple duplicate logs will be generated in Elasticsearch, but I cannot find the reason, despite testing many times. Could you please he…

---

## [How we can create two index in logstash](https://discuss.elastic.co/t/how-we-can-create-two-index-in-logstash/334082)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 12:10pm UTC](https://discuss.elastic.co/t/how-we-can-create-two-index-in-logstash/334082 "2023-05-26T12:10:38Z")

</div>

Hello, Anyone came across below scenario, I have a json as input and am filtering the data later creating index in output block to push it into elastic Here i want to split the data into two set and want them to send…

---

## [Mapping parser exception](https://discuss.elastic.co/t/mapping-parser-exception/334322)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 12:06pm UTC](https://discuss.elastic.co/t/mapping-parser-exception/334322 "2023-05-26T12:06:07Z")

</div>

I am using Elasticsearch 8.7.0....... While inserting any document I am getting this kind of error. In previously versions which includes the field path where got and error now It Shows only RequestError(400, 'mapper\_p…

---

## [Fortinet traffic logs: how to create a dashboard that shows generated traffic per host?](https://discuss.elastic.co/t/fortinet-traffic-logs-how-to-create-a-dashboard-that-shows-generated-traffic-per-host/334421)

<div class="topic-metadata">

**Author:** [@CyberPingU](https://discuss.elastic.co/u/CyberPingU)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 10:35am UTC](https://discuss.elastic.co/t/fortinet-traffic-logs-how-to-create-a-dashboard-that-shows-generated-traffic-per-host/334421 "2023-05-26T10:35:01Z")

</div>

Hello, I'm using filebeat with elastic and kibana to manage my fortinet (7.2.4) logs. I cannot understand how to create a dashboard that is showing me how much traffic a host is doing. I thought that I could use desti…

---

## [Vega: text information when dont get logs](https://discuss.elastic.co/t/vega-text-information-when-dont-get-logs/334416)

<div class="topic-metadata">

**Author:** [@martinez061](https://discuss.elastic.co/u/martinez061)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 10:08am UTC](https://discuss.elastic.co/t/vega-text-information-when-dont-get-logs/334416 "2023-05-26T10:08:21Z")

</div>

Hi, Code below is checking the status of the website from few location.Each location has own IP address. Its working properly, but when i dont got any logs from specyfic location the rectangle is dissapering. How to add…

---

## [ELK8: at least one primary shard for the index \[.security-profile-8\] is unavailable](https://discuss.elastic.co/t/elk8-at-least-one-primary-shard-for-the-index-security-profile-8-is-unavailable/334413)

<div class="topic-metadata">

**Author:** [@tingH](https://discuss.elastic.co/u/tingH)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 9:53am UTC](https://discuss.elastic.co/t/elk8-at-least-one-primary-shard-for-the-index-security-profile-8-is-unavailable/334413 "2023-05-26T09:53:28Z")

</div>

\[2023-05-26T14:43:26.066+08:00\]\[ERROR\]\[plugins.security.user-profile\] Failed to activate user profile: {"error":{"root\_cause":\[{"type":"unavailable\_shards\_exception","reason":"at least one primary shard for the index \[.s…

---

## [Logstash pipeline for aws cloudfront fixing timestamp issue](https://discuss.elastic.co/t/logstash-pipeline-for-aws-cloudfront-fixing-timestamp-issue/334411)

<div class="topic-metadata">

**Author:** [@miiimooo](https://discuss.elastic.co/u/miiimooo)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 9:38am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-aws-cloudfront-fixing-timestamp-issue/334411 "2023-05-26T09:38:52Z")

</div>

This took me ages to figure out so I thought it might be helpful for someone else. I'm parsing AWS CloudFront standard logs in logstash (v8.x) The included grok pattern worked fine for me apart from the timestamp, sinc…

---

## [Importing dashboard to kibana Via api](https://discuss.elastic.co/t/importing-dashboard-to-kibana-via-api/334281)

<div class="topic-metadata">

**Author:** [@\_Zeyad\_Elshater](https://discuss.elastic.co/u/_Zeyad_Elshater)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 9:38am UTC](https://discuss.elastic.co/t/importing-dashboard-to-kibana-via-api/334281 "2023-05-26T09:38:44Z")

</div>

When importing saved object to kibana through the Api, it changes the IDs of the saved object automatically, thus gives me error when trying to access some objects that I referenced with their ID number, how to avoid thi…

---

## [Changing font size or font names in Kibana table charts](https://discuss.elastic.co/t/changing-font-size-or-font-names-in-kibana-table-charts/334372)

<div class="topic-metadata">

**Author:** [@Venkatesh\_Guruprasad](https://discuss.elastic.co/u/Venkatesh_Guruprasad)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 9:31am UTC](https://discuss.elastic.co/t/changing-font-size-or-font-names-in-kibana-table-charts/334372 "2023-05-26T09:31:18Z")

</div>

We have deployed Kibana iFrames using Elastic Cloud. There is no options to change the font size in Kibana table charts or via Lens-\>Tables charts. Has anyone done this in the context of iFrames? If so, how can we solve…

---

## [Slower Perfomance with Elaticsearch cluster in kubernetes compared to Docker](https://discuss.elastic.co/t/slower-perfomance-with-elaticsearch-cluster-in-kubernetes-compared-to-docker/332395)

<div class="topic-metadata">

**Author:** [@samdevops](https://discuss.elastic.co/u/samdevops)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 9:23am UTC](https://discuss.elastic.co/t/slower-perfomance-with-elaticsearch-cluster-in-kubernetes-compared-to-docker/332395 "2023-05-26T09:23:27Z")

</div>

Hi All, I've had the same topic opened before but it seems like our issue has returned after implementing the feedback and testing once more. As mentioned in the title we seem to notice much slower performance when our …

---

## [Elastic-agent: output by integration and not by policy](https://discuss.elastic.co/t/elastic-agent-output-by-integration-and-not-by-policy/334252)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 2\
**Last updated:** [May 26, 2023, 9:13am UTC](https://discuss.elastic.co/t/elastic-agent-output-by-integration-and-not-by-policy/334252 "2023-05-26T09:13:16Z")

</div>

Hi, i have an instance of elastic-agent on a server where i have multiple integrations. for most of them I need the Elasticsearch output. But, I also have some log files on that server which I want to send to Logstash f…

---

## [Can I take backup of indices from one cluster and restore it to another cluster](https://discuss.elastic.co/t/can-i-take-backup-of-indices-from-one-cluster-and-restore-it-to-another-cluster/334387)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 14\
**Last updated:** [May 26, 2023, 8:55am UTC](https://discuss.elastic.co/t/can-i-take-backup-of-indices-from-one-cluster-and-restore-it-to-another-cluster/334387 "2023-05-26T08:55:37Z")

</div>

Can I take backup of indices from one cluster and restore it to another cluster by simply copying the snapshot/backup repository folder and sending it to another cluster and from there I will perform restore operation is…

---

## [High iops from filebeat](https://discuss.elastic.co/t/high-iops-from-filebeat/334399)

<div class="topic-metadata">

**Author:** [@dimovvasiliy](https://discuss.elastic.co/u/dimovvasiliy)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 6:37am UTC](https://discuss.elastic.co/t/high-iops-from-filebeat/334399 "2023-05-26T06:37:55Z")

</div>

Hi there! I faced with a filebeat high io consumption problem. Sometimes some of my filebeat daemons start to make abnormal number of io requests (thousands per seond). I checked it and found that filebeat make a checkp…

---

## [Taking backup on one system and restoring it in another system](https://discuss.elastic.co/t/taking-backup-on-one-system-and-restoring-it-in-another-system/334392)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 2\
**Last updated:** [May 26, 2023, 6:22am UTC](https://discuss.elastic.co/t/taking-backup-on-one-system-and-restoring-it-in-another-system/334392 "2023-05-26T06:22:41Z")

</div>

I have Elasticsearch running on one system where I take backup of indices regularly into a snapshot, but these indices(snapshot) I want to restore to different system. How can I proceed. I am unable to find clear answer…

---

## [Kibana Error - Error while updating search session conflict](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-conflict/334396)

<div class="topic-metadata">

**Author:** [@Yos](https://discuss.elastic.co/u/Yos)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 6:11am UTC](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-conflict/334396 "2023-05-26T06:11:31Z")

</div>

Kibana Version : 8.5.3 Hello The following error is intermittently logged in Kibana's logs Is there a lack of authority? Or Is it an error that can be ignored? If you can give me any information on the cause or how …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=530)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=532)
