# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=540

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 541

---

## [I want to put my grok inside if else block of logstash I want the fields to be displayed in kibana it's executing but not displaying the actual fields](https://discuss.elastic.co/t/i-want-to-put-my-grok-inside-if-else-block-of-logstash-i-want-the-fields-to-be-displayed-in-kibana-its-executing-but-not-displaying-the-actual-fields/333637)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 8:48am UTC](https://discuss.elastic.co/t/i-want-to-put-my-grok-inside-if-else-block-of-logstash-i-want-the-fields-to-be-displayed-in-kibana-its-executing-but-not-displaying-the-actual-fields/333637 "2023-05-17T08:48:56Z")

</div>

filter { if \[IgmpSnooping\] == "%IGMPSNOOPING-6-NO\_IGMP\_QUERIER" { grok { match =\> { "message" =\> "\<%{INT:priority:int}\>%{SYSLOGTIMESTAMP:timestamp}\\s+%{HOSTNAME:device\_name}\\s+\\IgmpSnooping:\\s+%{DATA:IgmpSnooping}\\…

---

## [Grok filter working in online debuggers but not in actual implementation](https://discuss.elastic.co/t/grok-filter-working-in-online-debuggers-but-not-in-actual-implementation/333428)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 3\
**Last updated:** [May 17, 2023, 8:35am UTC](https://discuss.elastic.co/t/grok-filter-working-in-online-debuggers-but-not-in-actual-implementation/333428 "2023-05-17T08:35:10Z")

</div>

This seems to give \_grokparsefailure a hundred percent of the time: if \[event\]\[action\]=="Process Creation" { grok { match =\> { "winlog.event\_data.NewProcessName" =\> "(?\<directory\>.\*)\\\\(?\<exe…

---

## [Count filtering visualization](https://discuss.elastic.co/t/count-filtering-visualization/333527)

<div class="topic-metadata">

**Author:** [@clmtb](https://discuss.elastic.co/u/clmtb)\
**Replies:** 7\
**Last updated:** [May 17, 2023, 8:06am UTC](https://discuss.elastic.co/t/count-filtering-visualization/333527 "2023-05-17T08:06:51Z")

</div>

Hi all, I am trying to create a pretty simple visualization in Kibana in TSVB Table, with the count of different fields but with a filter applied. To be more precise, I want to get the count of every values higher than …

---

## [Ignore\_z\_value is not supported](https://discuss.elastic.co/t/ignore-z-value-is-not-supported/333571)

<div class="topic-metadata">

**Author:** [@gabi939](https://discuss.elastic.co/u/gabi939)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 7:45am UTC](https://discuss.elastic.co/t/ignore-z-value-is-not-supported/333571 "2023-05-17T07:45:05Z")

</div>

Elasticsearch Version 7.7.0 Java Version 1.8.0\_252 OS Version Ubuntu 18.04 Problem Description According to: I should be able to use parameter ignore\_z\_value to ignore z values indexed to geo\_point field. But it do…

---

## [Guidance on mapping and query](https://discuss.elastic.co/t/guidance-on-mapping-and-query/333592)

<div class="topic-metadata">

**Author:** [@ichbindermike](https://discuss.elastic.co/u/ichbindermike)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 6:55am UTC](https://discuss.elastic.co/t/guidance-on-mapping-and-query/333592 "2023-05-17T06:55:27Z")

</div>

I have a question on what might be the best approach to structure my data. I have 8 indices that each contain about 4-7 fields (different ones), but I would like to search across all indices and multiple of those fields.…

---

## [Logstash new record](https://discuss.elastic.co/t/logstash-new-record/333629)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 6:53am UTC](https://discuss.elastic.co/t/logstash-new-record/333629 "2023-05-17T06:53:52Z")

</div>

How to handle the logstash configuration in the case when I run the JDBC query and then there are no results through 1 to 10 minutes, if there is no result I need to generate a new record to store it in as document in th…

---

## [Elasticsearch snapshot/restore to s3](https://discuss.elastic.co/t/elasticsearch-snapshot-restore-to-s3/330517)

<div class="topic-metadata">

**Author:** [@sraman](https://discuss.elastic.co/u/sraman)\
**Replies:** 30\
**Last updated:** [May 17, 2023, 5:27am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-restore-to-s3/330517 "2023-05-17T05:27:31Z")

</div>

Hi, I have installed elasticsearch 8.6.2 & kibana 8.6.2 on the same standalone server for testing purpose. Planning to place the data snapshot to S3 and restore, but facing issues while creating the repository(it's not…

---

## [GeoIP filter missing some ECS fields](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 7\
**Last updated:** [May 17, 2023, 5:18am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339 "2023-05-17T05:18:00Z")

</div>

I am using the GeoIP Logstash filter and it seems to not have some desired fields for example \[mmdb\]\[isp\]. Overall it has no as or mmdb fields, as well as some other random fields. It does have all the geo fields however…

---

## [Mismatch between Elastic Query Aggretion and Kibana Visualize Function](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619)

<div class="topic-metadata">

**Author:** [@phong\_elastic](https://discuss.elastic.co/u/phong_elastic)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 4:29am UTC](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619 "2023-05-17T04:29:42Z")

</div>

Hello everyone. I'm trying create a table that have the same data like the table in Lens Visualization by using the Elasticsearch Query. I'm confusing cause there's is a different between the data I get by the query an…

---

## [Logstash Syslog Input - Capture the Connecting Host's IP Address](https://discuss.elastic.co/t/logstash-syslog-input-capture-the-connecting-hosts-ip-address/333602)

<div class="topic-metadata">

**Author:** [@m52](https://discuss.elastic.co/u/m52)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 4:16am UTC](https://discuss.elastic.co/t/logstash-syslog-input-capture-the-connecting-hosts-ip-address/333602 "2023-05-17T04:16:35Z")

</div>

Hi, Newbie to Logstash here and could use some assistance regarding the Syslog input connector. I currently have the Syslog connector working successfully, but noticed the JSON output has a host.ip element that always…

---

## [Auditbeat - User Attribution](https://discuss.elastic.co/t/auditbeat-user-attribution/333620)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 3:53am UTC](https://discuss.elastic.co/t/auditbeat-user-attribution/333620 "2023-05-17T03:53:01Z")

</div>

Hi, We are running auditbeat with the auditd module using standard auditd.rules. We are seeing the events in our Elasticsearch instance, however there is no user attribution tied to the events. It's great that we are …

---

## [Ingest data from 3 databases](https://discuss.elastic.co/t/ingest-data-from-3-databases/330624)

<div class="topic-metadata">

**Author:** [@baba72210](https://discuss.elastic.co/u/baba72210)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 3:45am UTC](https://discuss.elastic.co/t/ingest-data-from-3-databases/330624 "2023-05-17T03:45:39Z")

</div>

Hi everyone, I have a project where I need to index data from 3 differents databases to be able to search for revelant information. I have a Cassandra, a MSSQL and a mongoDB. Do you think it would be possible to use the…

---

## [Elasticsearch createTranslogSyncProcessor part of source code, log level Setting is not appropriate?](https://discuss.elastic.co/t/elasticsearch-createtranslogsyncprocessor-part-of-source-code-log-level-setting-is-not-appropriate/332539)

<div class="topic-metadata">

**Author:** [@yujie\_wang](https://discuss.elastic.co/u/yujie_wang)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:21am UTC](https://discuss.elastic.co/t/elasticsearch-createtranslogsyncprocessor-part-of-source-code-log-level-setting-is-not-appropriate/332539 "2023-05-17T03:21:16Z")

</div>

Hi, Recently, I've been reading the source code of the latest version (8.7.1) of Elasticsearch and I have a question about the log level settings that I can't figure out. I noticed that the "failed to sync translog" is…

---

## [java.lang.IllegalArgumentException: unknown setting \[node.data\] please check that any required plugins are installed, or check the breaking changes documentation for removed settings](https://discuss.elastic.co/t/java-lang-illegalargumentexception-unknown-setting-node-data-please-check-that-any-required-plugins-are-installed-or-check-the-breaking-changes-documentation-for-removed-settings/333558)

<div class="topic-metadata">

**Author:** [@tungnx1](https://discuss.elastic.co/u/tungnx1)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 2:55am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-unknown-setting-node-data-please-check-that-any-required-plugins-are-installed-or-check-the-breaking-changes-documentation-for-removed-settings/333558 "2023-05-17T02:55:06Z")

</div>

help !!! i setup Cluster Elasticsearch. After config file elasticsearch.yml node.name: es-data-1 node.data: true Log: java.lang.IllegalArgumentException: unknown setting \[node.data\] please check that any required pl…

---

## [Winlogbeat mapping to OCSF](https://discuss.elastic.co/t/winlogbeat-mapping-to-ocsf/333605)

<div class="topic-metadata">

**Author:** [@Zachary\_Schmerber](https://discuss.elastic.co/u/Zachary_Schmerber)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:03pm UTC](https://discuss.elastic.co/t/winlogbeat-mapping-to-ocsf/333605 "2023-05-16T21:03:40Z")

</div>

Hello, I am trying to find a way to remove the ECS mappings that defaults in winlogbeats and move to OCSF mapping. Anyone know where the logic for the ECS transformations lives or have a repo for winlogbeat that dose not…

---

## [Kibana and logstash can't run using docker-compose](https://discuss.elastic.co/t/kibana-and-logstash-cant-run-using-docker-compose/333566)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 11:48pm UTC](https://discuss.elastic.co/t/kibana-and-logstash-cant-run-using-docker-compose/333566 "2023-05-16T23:48:35Z")

</div>

hi ,hello everyone I run the elastic and logstash and kibana and mysql containers using docker-compose this the configuration that i use in my docker-compose file version: '3' services: mysql: container\_name: mysql ho…

---

## [Logstash cannot identify config file, it stops after starting , i am using docker desktop](https://discuss.elastic.co/t/logstash-cannot-identify-config-file-it-stops-after-starting-i-am-using-docker-desktop/333613)

<div class="topic-metadata">

**Author:** [@sakshi1](https://discuss.elastic.co/u/sakshi1)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 10:45pm UTC](https://discuss.elastic.co/t/logstash-cannot-identify-config-file-it-stops-after-starting-i-am-using-docker-desktop/333613 "2023-05-16T22:45:14Z")

</div>

so , i wrote an elasticsearch.yaml , which contains the configuration of elasticsearch, kibana and logstash. i will just attach the text version: '3.3' services: elasticsearch: image: docker.elastic.co/elasticsear…

---

## [No persistent volumes available for this claim on kubernetes](https://discuss.elastic.co/t/no-persistent-volumes-available-for-this-claim-on-kubernetes/333607)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:08pm UTC](https://discuss.elastic.co/t/no-persistent-volumes-available-for-this-claim-on-kubernetes/333607 "2023-05-16T21:08:53Z")

</div>

I'm trying to set up elasticsearch on kubernetes with Helm(helm install elasticsearch elastic/elasticsearch -n efk). I get the error "no persistent volumes available for this claim and no storage class is set". In my ku…

---

## [How to create the Multiple Index for each Apache Webserver](https://discuss.elastic.co/t/how-to-create-the-multiple-index-for-each-apache-webserver/333492)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 8:21pm UTC](https://discuss.elastic.co/t/how-to-create-the-multiple-index-for-each-apache-webserver/333492 "2023-05-16T20:21:01Z")

</div>

Hi, I'm a new to ELK stack. Can anyone advice me for my below doubt. For example, I have a two apache webserver and I installed filebeat on that and I enabled apache module. Also I configured apache.conf file in logsta…

---

## [Error in Multiline parser of timestamp](https://discuss.elastic.co/t/error-in-multiline-parser-of-timestamp/333598)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 7:39pm UTC](https://discuss.elastic.co/t/error-in-multiline-parser-of-timestamp/333598 "2023-05-16T19:39:48Z")

</div>

Having an issue with a multiline parser in one of own filebeat instance type of Redhat AMQ log which puzzles me, so any hints are appreciated, TIA. See all events dropped in filebeat log due to error like this: {\\"type…

---

## [Index Retention by Filesize](https://discuss.elastic.co/t/index-retention-by-filesize/333489)

<div class="topic-metadata">

**Author:** [@Chacko42](https://discuss.elastic.co/u/Chacko42)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 7:25pm UTC](https://discuss.elastic.co/t/index-retention-by-filesize/333489 "2023-05-16T19:25:39Z")

</div>

Hi Community, we are currently building up a logging infrastructure for our network stuff. The plan is like with switching or firewall logs, to let the logs rotate, as soon as the configured disk space is full. I had a …

---

## [Kibana dashboard filters that recognize multiple views?](https://discuss.elastic.co/t/kibana-dashboard-filters-that-recognize-multiple-views/333507)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 6:31pm UTC](https://discuss.elastic.co/t/kibana-dashboard-filters-that-recognize-multiple-views/333507 "2023-05-16T18:31:01Z")

</div>

I created a dashboard that shows visualizations . Each visualization references a different Kibana data view. And each kibana data view references a different index. For example, let's say I have two indices with the f…

---

## [Potential logs loss on a WEC server via Winlogbeat](https://discuss.elastic.co/t/potential-logs-loss-on-a-wec-server-via-winlogbeat/331561)

<div class="topic-metadata">

**Author:** [@rpe](https://discuss.elastic.co/u/rpe)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 2:58pm UTC](https://discuss.elastic.co/t/potential-logs-loss-on-a-wec-server-via-winlogbeat/331561 "2023-05-16T14:58:53Z")

</div>

Hello, I deployed a WEC with a customer to forward its Windows logs to our SIEM, following the Elastic WEC Server cookbook. However, after synchronizing with the customer, he generated some events that we didn't receiv…

---

## [Csv parse failure](https://discuss.elastic.co/t/csv-parse-failure/333049)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 2:45pm UTC](https://discuss.elastic.co/t/csv-parse-failure/333049 "2023-05-16T14:45:10Z")

</div>

Hello, I'm trying to parse a CSV file with Logstash, but I'm encountering a CSV parse failure. Can you please help me?

---

## [Mutate -\> Copy is not working as expected](https://discuss.elastic.co/t/mutate-copy-is-not-working-as-expected/333541)

<div class="topic-metadata">

**Author:** [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 2:42pm UTC](https://discuss.elastic.co/t/mutate-copy-is-not-working-as-expected/333541 "2023-05-16T14:42:54Z")

</div>

Im working on some json data, transforming and remapping fields add\_field, rename plugins are working as expected But whenever im using copy, output does not include these \[events\]\[date\], \[env\]\[app\] fields. But does in…

---

## [How to create dynamic Query DSL for Includes](https://discuss.elastic.co/t/how-to-create-dynamic-query-dsl-for-includes/333581)

<div class="topic-metadata">

**Author:** [@Koi\_Kin](https://discuss.elastic.co/u/Koi_Kin)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 2:38pm UTC](https://discuss.elastic.co/t/how-to-create-dynamic-query-dsl-for-includes/333581 "2023-05-16T14:38:20Z")

</div>

I have this query: .Search\<Person\>("person", s =\> s .Index("person") .Source(s =\> s .Includes(i =\> i .Fields( f =\> f.Id, ) ) ) .Query(q =\> q …

---

## [Loadbalancing config in Kibana](https://discuss.elastic.co/t/loadbalancing-config-in-kibana/333464)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 1:31pm UTC](https://discuss.elastic.co/t/loadbalancing-config-in-kibana/333464 "2023-05-16T13:31:36Z")

</div>

Hi All, Filebeat output has an ability to be configured with load balancing config as follows: output.logstash: hosts: \["hostA:5044","hostB:5044","hostC:5044"\] loadbalance: true Do we have a similar set up for K…

---

## [Mulitple Filebeat Instances](https://discuss.elastic.co/t/mulitple-filebeat-instances/330792)

<div class="topic-metadata">

**Author:** [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 12:44pm UTC](https://discuss.elastic.co/t/mulitple-filebeat-instances/330792 "2023-05-16T12:44:24Z")

</div>

Hello, i did setup two filebeat instances on a linux server. One for Syslog and the PANW-Module and the other for the F5-Module. The Syslog/PANW Filebeat was the first one, i did change the index to a different one, bu…

---

## [Curator not can find indecies](https://discuss.elastic.co/t/curator-not-can-find-indecies/333465)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 12:28pm UTC](https://discuss.elastic.co/t/curator-not-can-find-indecies/333465 "2023-05-16T12:28:27Z")

</div>

I have an issue with deleting indexes! this is my Action file: actions: 1: action: delete\_indices description: \>- Delete indices. Find which to delete by first limiting the list to logstash- prefi…

---

## [Add a quick range based on server time to Kibana Time filter quick ranges](https://discuss.elastic.co/t/add-a-quick-range-based-on-server-time-to-kibana-time-filter-quick-ranges/333564)

<div class="topic-metadata">

**Author:** [@gizem](https://discuss.elastic.co/u/gizem)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 12:07pm UTC](https://discuss.elastic.co/t/add-a-quick-range-based-on-server-time-to-kibana-time-filter-quick-ranges/333564 "2023-05-16T12:07:14Z")

</div>

Hello, I want to add a quick range based on server time to Kibana. For example: \<{ "from": "now-15m", "to": "now", "display": "Last 15 minutes" }, /\> 'now' is set by client time. But if client time is wrong, filt…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=539)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=541)
