# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=539

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 540

---

## [Not Getting Kubernetes related filters in Kibana when exporting logs from Logstash](https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400)

<div class="topic-metadata">

**Author:** [@Akshay04](https://discuss.elastic.co/u/Akshay04)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:44pm UTC](https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400 "2023-05-17T23:44:02Z")

</div>

Hello, I have configured Fluentbit in my k8s cluster to send logs to S3 and ELK stack to get logs from S3 and Visualise in Kibana. When I create Dataview in kibana for the Index, the kibana dashboard is not giving filte…

---

## [Can we connect to multiple clusters in JAVA using High level rest client](https://discuss.elastic.co/t/can-we-connect-to-multiple-clusters-in-java-using-high-level-rest-client/333310)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:13pm UTC](https://discuss.elastic.co/t/can-we-connect-to-multiple-clusters-in-java-using-high-level-rest-client/333310 "2023-05-17T23:13:32Z")

</div>

Hi team, I have a question about high level rest client lets suppose I have 2 clusters running on two different machines and those clusters have an index with the same name. I have a Java application which fetches dat…

---

## [Is there a way to recover kibana\_x file?](https://discuss.elastic.co/t/is-there-a-way-to-recover-kibana-x-file/333319)

<div class="topic-metadata">

**Author:** [@ardit](https://discuss.elastic.co/u/ardit)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:11pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-recover-kibana-x-file/333319 "2023-05-17T23:11:43Z")

</div>

Is there any possibility to recover from lost kibana\_x index? \[opc@elasticsearch-2 ~\]$ curl -XGET http://localhost:9200/\_cat/shards/.kibana\_7.12.0\_001 .kibana\_7.12.0\_001 0 p UNASSIGNED .kibana\_7.12.0\_001 0 r UNASSIG…

---

## [Elasticsearch Aggregations](https://discuss.elastic.co/t/elasticsearch-aggregations/333615)

<div class="topic-metadata">

**Author:** [@JulioAlbuquerque](https://discuss.elastic.co/u/JulioAlbuquerque)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 10:27pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregations/333615 "2023-05-17T22:27:08Z")

</div>

I have a project in NodeJS with TypeScript that uses the library "@elastic/elasticsearch": "^8.7.0", to connect the server with Elastic Search 8.7.1. I'm trying to make a query where I retrieve the frequency of words fr…

---

## [How logstash jdbc plugin fetch data from database](https://discuss.elastic.co/t/how-logstash-jdbc-plugin-fetch-data-from-database/333103)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 14\
**Last updated:** [May 17, 2023, 9:09pm UTC](https://discuss.elastic.co/t/how-logstash-jdbc-plugin-fetch-data-from-database/333103 "2023-05-17T21:09:51Z")

</div>

Hi I have informix database that contain tons of tables and records that need to join some of them and send to elasticsearch. Result of this join are 70 columns and 100M records. Here is the requirements: 1-For first …

---

## [Looking for help enabling Metricbeat](https://discuss.elastic.co/t/looking-for-help-enabling-metricbeat/333570)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 5\
**Last updated:** [May 17, 2023, 8:45pm UTC](https://discuss.elastic.co/t/looking-for-help-enabling-metricbeat/333570 "2023-05-17T20:45:19Z")

</div>

Hello, I have a single node deploy of Elasticsearch Enterprise Search and Kibana all on version 8.6.2. In this node I enabled self-monitoring with xpack, but am trying to switch to using Metricbeat. While in 'Stack mon…

---

## [Issue with Beats forwarding to logstash](https://discuss.elastic.co/t/issue-with-beats-forwarding-to-logstash/333689)

<div class="topic-metadata">

**Author:** [@vhaispdeaded](https://discuss.elastic.co/u/vhaispdeaded)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 6:49pm UTC](https://discuss.elastic.co/t/issue-with-beats-forwarding-to-logstash/333689 "2023-05-17T18:49:16Z")

</div>

Our enterprise configures our AWS EC2 instances with Auditbeat, Filebeat, Journalbeat, Metricbeat, and Packetbeat to forward to a set of logstash servers. Our /var/log/messages, and /var/log/secure files are filled with …

---

## [Grok error in official Azure integration](https://discuss.elastic.co/t/grok-error-in-official-azure-integration/333585)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 3\
**Last updated:** [May 17, 2023, 6:22pm UTC](https://discuss.elastic.co/t/grok-error-in-official-azure-integration/333585 "2023-05-17T18:22:24Z")

</div>

Hey, the Azure integration currently (I'm using 8.7.0) fails to ingest some Azure Activity Logs with IPv6 source addresses. The reason is this processor: - grok: field: azure.activitylogs.callerIpAddress patter…

---

## [Which is better RAM allocation strategy?](https://discuss.elastic.co/t/which-is-better-ram-allocation-strategy/333497)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 6:07pm UTC](https://discuss.elastic.co/t/which-is-better-ram-allocation-strategy/333497 "2023-05-17T18:07:07Z")

</div>

If I have a data node with 128GB of RAM. Is it better to allocate 64GB to ES and 64GB to system? Or would it be ok (or even better) to allocate say 100GB to ES and leave 28GB to system? Our system is write heavy; ther…

---

## [Kibana and logstash can't run using docker-compose](https://discuss.elastic.co/t/kibana-and-logstash-cant-run-using-docker-compose/333498)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 5:52pm UTC](https://discuss.elastic.co/t/kibana-and-logstash-cant-run-using-docker-compose/333498 "2023-05-17T17:52:13Z")

</div>

hi ,hello everyone I run the elastic and logstash and kibana and mysql containers using docker-compose this the configuration that i use in my docker-compose file version: '3' services: mysql: container\_name: mysq…

---

## [Check if field from XML is object or array of objects?](https://discuss.elastic.co/t/check-if-field-from-xml-is-object-or-array-of-objects/333686)

<div class="topic-metadata">

**Author:** [@Meme-ento](https://discuss.elastic.co/u/Meme-ento)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 5:50pm UTC](https://discuss.elastic.co/t/check-if-field-from-xml-is-object-or-array-of-objects/333686 "2023-05-17T17:50:19Z")

</div>

I have the following case happening. I have an application that is configured to send data via a webhook like push method via HTTP rest api whenever data is inserted in the application database. Im using this functionali…

---

## [Winlogbeat yml file missing Elasticsearch output SSl Key](https://discuss.elastic.co/t/winlogbeat-yml-file-missing-elasticsearch-output-ssl-key/333679)

<div class="topic-metadata">

**Author:** [@geomandry](https://discuss.elastic.co/u/geomandry)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 4:11pm UTC](https://discuss.elastic.co/t/winlogbeat-yml-file-missing-elasticsearch-output-ssl-key/333679 "2023-05-17T16:11:28Z")

</div>

Configured my stack to SSL and lost log forwarding from Winlogbeat. Everything looks well on yml file with the exception of the Elasticsearch output key path. I did not receive a key when Elasticsearch SSL was configured…

---

## [Painless Script Error, Creating New Variable on Data View](https://discuss.elastic.co/t/painless-script-error-creating-new-variable-on-data-view/333599)

<div class="topic-metadata">

**Author:** [@marscar](https://discuss.elastic.co/u/marscar)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:59pm UTC](https://discuss.elastic.co/t/painless-script-error-creating-new-variable-on-data-view/333599 "2023-05-17T15:59:42Z")

</div>

Hello! I am trying to create a new variable on a Data View using this painless script, but when trying to save, I am getting the generic error "Invalid Painless Script". The error also tells be to fix the highlighted err…

---

## [How do Searchable Snapshot snapshots get cleaned up?](https://discuss.elastic.co/t/how-do-searchable-snapshot-snapshots-get-cleaned-up/329831)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 15\
**Last updated:** [May 17, 2023, 3:54pm UTC](https://discuss.elastic.co/t/how-do-searchable-snapshot-snapshots-get-cleaned-up/329831 "2023-05-17T15:54:36Z")

</div>

Hello All, I was curious if anyone knew the answer to the question: How do searchable snapshot snapshots get cleaned up. To explain the question a bit more, I'll use the below example: I have: A snapshot reposito…

---

## [How to integrate in-house ticketing tool with ELK using API's](https://discuss.elastic.co/t/how-to-integrate-in-house-ticketing-tool-with-elk-using-apis/333645)

<div class="topic-metadata">

**Author:** [@DhananjayPatil](https://discuss.elastic.co/u/DhananjayPatil)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:42pm UTC](https://discuss.elastic.co/t/how-to-integrate-in-house-ticketing-tool-with-elk-using-apis/333645 "2023-05-17T15:42:41Z")

</div>

Hi Everyone, I am currently working on integrating our in-house ticketing tool with ELK. Specifically, I would like to fetch data from ELK and automatically create incidents in our ticketing tool when specific conditions…

---

## [DEPRECATED: Treating the CommonName field on X.509 certificates as a host name when no Subject Alternative Names are present is going to be removed](https://discuss.elastic.co/t/deprecated-treating-the-commonname-field-on-x-509-certificates-as-a-host-name-when-no-subject-alternative-names-are-present-is-going-to-be-removed/333326)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 3:28pm UTC](https://discuss.elastic.co/t/deprecated-treating-the-commonname-field-on-x-509-certificates-as-a-host-name-when-no-subject-alternative-names-are-present-is-going-to-be-removed/333326 "2023-05-17T15:28:30Z")

</div>

I am getting the following deprecation warning in both filebeat and metricbeat. I am currently using ES 7.17.9, but will be upgrading to 8.x soon: DEPRECATED: Treating the CommonName field on X.509 certificates as a ho…

---

## [Is it possible to have multiple SQL queries into the Expression Editor?](https://discuss.elastic.co/t/is-it-possible-to-have-multiple-sql-queries-into-the-expression-editor/333596)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:15pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-multiple-sql-queries-into-the-expression-editor/333596 "2023-05-17T15:15:42Z")

</div>

For the context, I have a query that brings me data from the last 24hous. And would like to have a second column which will deal only with information from the last 6minutes. The thing is, if I do both like: @timestamp…

---

## [How to upgrade ELK on docker from 8.4.3 to 8.7.0](https://discuss.elastic.co/t/how-to-upgrade-elk-on-docker-from-8-4-3-to-8-7-0/331352)

<div class="topic-metadata">

**Author:** [@Thales\_Eduardo](https://discuss.elastic.co/u/Thales_Eduardo)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-to-upgrade-elk-on-docker-from-8-4-3-to-8-7-0/331352 "2023-05-17T14:48:21Z")

</div>

I have an elastdocker (elk version 8.4.3) in production for some time and I would like to upgrade the elk version (8.4.3 to 8.7.0). Volumes are configured on the instance to use persistent storage. The procedure would …

---

## [EFK Stack on Kubernetes - Collecting logs from default namespace](https://discuss.elastic.co/t/efk-stack-on-kubernetes-collecting-logs-from-default-namespace/333672)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:31pm UTC](https://discuss.elastic.co/t/efk-stack-on-kubernetes-collecting-logs-from-default-namespace/333672 "2023-05-17T14:31:22Z")

</div>

Hi, I am using EFK stack on Kubernetes, I want to configure fluentd to collect logs from one specific namespace, the default namespace. This is my fleuntd config file: \<label @FLUENT\_LOG\> \<match fluent.\*\*\> …

---

## [Getting Logstash output cannot be used with Fleet Server integration in Fleet Server Policy. Please create a new ElasticSearch output](https://discuss.elastic.co/t/getting-logstash-output-cannot-be-used-with-fleet-server-integration-in-fleet-server-policy-please-create-a-new-elasticsearch-output/330980)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 5\
**Last updated:** [May 17, 2023, 2:24pm UTC](https://discuss.elastic.co/t/getting-logstash-output-cannot-be-used-with-fleet-server-integration-in-fleet-server-policy-please-create-a-new-elasticsearch-output/330980 "2023-05-17T14:24:34Z")

</div>

This is pretty straightforward as you can see : I get this after trying to configure a logstash output on Fleet and going through all the steps. I dont know what to do with this error message as it does not make sens…

---

## [Logstash config - Kafka and CEF](https://discuss.elastic.co/t/logstash-config-kafka-and-cef/333669)

<div class="topic-metadata">

**Author:** [@elizZ](https://discuss.elastic.co/u/elizZ)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:18pm UTC](https://discuss.elastic.co/t/logstash-config-kafka-and-cef/333669 "2023-05-17T14:18:23Z")

</div>

Hi, I have a Logstash input of Kafka(codec cef), that consumes arcsight CEF format events from a kafka topic and writes it to elastic with 'elasticsearch' output I have an issue when some of the events have multiline f…

---

## [Logstash - Syslog Output - Custom message](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333668)

<div class="topic-metadata">

**Author:** [@Nandhini\_Viswanathan](https://discuss.elastic.co/u/Nandhini_Viswanathan)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:07pm UTC](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333668 "2023-05-17T14:07:31Z")

</div>

Hi, Reopening for Discussion. I'm working with Logstash - Syslog Output and I've found problem with custom field message. I'm using Elasticstack 7.10.2 I've installed logstash syslog-output plugin version 3.0.5. /usr…

---

## [Issue to setup Fleet Server](https://discuss.elastic.co/t/issue-to-setup-fleet-server/333209)

<div class="topic-metadata">

**Author:** [@Shoeb\_Masum](https://discuss.elastic.co/u/Shoeb_Masum)\
**Replies:** 3\
**Last updated:** [May 17, 2023, 1:48pm UTC](https://discuss.elastic.co/t/issue-to-setup-fleet-server/333209 "2023-05-17T13:48:49Z")

</div>

Continuing the discussion from How to get started with Elastic APM?: @Wave I've taken two VM as suggested - VM1 (elasticsearch, kibana): 192.168.1.41 VM2 (Fleet Elastic Agent): 192.168.1.42 I've install Elasticsearc…

---

## [Logstash JDBC insert after select completes](https://discuss.elastic.co/t/logstash-jdbc-insert-after-select-completes/333660)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 1:06pm UTC](https://discuss.elastic.co/t/logstash-jdbc-insert-after-select-completes/333660 "2023-05-17T13:06:51Z")

</div>

Hey All Just looking to understand if there is some way that I can run a SQL INSERT before and after a SELECT statement in the filter section to update a tracking table in the DB to say that the select query has started…

---

## [Failed to obtain node locks, tried \[/usr/share/elasticsearch/data\]; maybe these locations are not writable or multiple nodes were started](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started/333657)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 12:54pm UTC](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started/333657 "2023-05-17T12:54:40Z")

</div>

I installed elasticsearch on kubernetes using helm. elasticsearch version: 8.5.1 pods do not stand up. Error in pods log: {"@timestamp":"2023-05-17T12:50:32.223Z", "log.level":"ERROR", "message":"fatal exception while…

---

## [Can I reload after a setting change in elasticsearch.yml?](https://discuss.elastic.co/t/can-i-reload-after-a-setting-change-in-elasticsearch-yml/333565)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 2:40pm UTC](https://discuss.elastic.co/t/can-i-reload-after-a-setting-change-in-elasticsearch-yml/333565 "2023-05-16T14:40:30Z")

</div>

Is there a way to only reload the settings and not the whole stack ?

---

## [Working days - how to find](https://discuss.elastic.co/t/working-days-how-to-find/332404)

<div class="topic-metadata">

**Author:** [@TheyCallMeTrinity](https://discuss.elastic.co/u/TheyCallMeTrinity)\
**Replies:** 8\
**Last updated:** [May 17, 2023, 11:54am UTC](https://discuss.elastic.co/t/working-days-how-to-find/332404 "2023-05-17T11:54:04Z")

</div>

Hi, I have a problem. I'm getting data from the api which lists the rooms that users have booked. Each room has set working days and hours. I need to make a table where the Average real resource usage will be calculat…

---

## [Fortigate Issues](https://discuss.elastic.co/t/fortigate-issues/333653)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 11:20am UTC](https://discuss.elastic.co/t/fortigate-issues/333653 "2023-05-17T11:20:12Z")

</div>

I have deployed the Fortigate integration using Fleet to one of my Elastic Agents. When I run tcpdump, I see a lot of UDP traffic on the host running the agent. However; I don't see any of that data in Elastic. I'm ev…

---

## [CAPACITY test over the years for STORAGE RAM and so](https://discuss.elastic.co/t/capacity-test-over-the-years-for-storage-ram-and-so/333644)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 9:34am UTC](https://discuss.elastic.co/t/capacity-test-over-the-years-for-storage-ram-and-so/333644 "2023-05-17T09:34:52Z")

</div>

i have number of indexes I would be happy to know if there is a certain formula or what is the correct way to determine how much CAPACITY is needed in 4 years thanks for the help

---

## [How to show zero value in len](https://discuss.elastic.co/t/how-to-show-zero-value-in-len/333517)

<div class="topic-metadata">

**Author:** [@tonyaw](https://discuss.elastic.co/u/tonyaw)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 9:21am UTC](https://discuss.elastic.co/t/how-to-show-zero-value-in-len/333517 "2023-05-17T09:21:33Z")

</div>

I had a search result which has non-zero per 2 hours. I want to use Lens to show a sawtooth graph per hour(contains both non-zero value and zero value). May I ask how to configure it? Currently, I got a straight line re…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=538)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=540)
