# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=552

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 553

---

## [Grok pattern](https://discuss.elastic.co/t/grok-pattern/332618)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 4\
**Last updated:** [May 5, 2023, 9:36am UTC](https://discuss.elastic.co/t/grok-pattern/332618 "2023-05-05T09:36:17Z")

</div>

Hi i am new to logstash can i get help on creating a grok pattern for following log line \[20/Apr/2023:11:25:44.389 +0530\] 200 | 38 ms | 2 B | 172.31.40.179 | 172.31.40.179 | 8DCE7CA611DB96B7B6767151C08E79B6 | - |…

---

## [ECK 8.7.1 Fleet agent error "precondition failed: x509: certificate is valid for..."](https://discuss.elastic.co/t/eck-8-7-1-fleet-agent-error-precondition-failed-x509-certificate-is-valid-for/332629)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 0\
**Last updated:** [May 5, 2023, 9:06am UTC](https://discuss.elastic.co/t/eck-8-7-1-fleet-agent-error-precondition-failed-x509-certificate-is-valid-for/332629 "2023-05-05T09:06:02Z")

</div>

Following Quickstart | Elastic Cloud on Kubernetes \[2.7\] | Elastic to install and run ECK fleet on my EKS but observe the following error in the agent logs: \[elastic-agent-agent-kgzn5\] {"log.level":"error","@timestamp":…

---

## [Visualization for \_stats query](https://discuss.elastic.co/t/visualization-for-stats-query/330828)

<div class="topic-metadata">

**Author:** [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Replies:** 2\
**Last updated:** [May 5, 2023, 8:23am UTC](https://discuss.elastic.co/t/visualization-for-stats-query/330828 "2023-05-05T08:23:21Z")

</div>

Hi all, I need to build a visualization/dashboard (maybe a simple bar graph) with applicational indexes total size (total.store.size). By now, I'm getting it from Kibana dev console, using 'GET index/\_stats?level=clust…

---

## [Elasticsearch data indices is not creating when start\_position = beginning in logstash input file plugin?](https://discuss.elastic.co/t/elasticsearch-data-indices-is-not-creating-when-start-position-beginning-in-logstash-input-file-plugin/332286)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 2\
**Last updated:** [May 5, 2023, 7:46am UTC](https://discuss.elastic.co/t/elasticsearch-data-indices-is-not-creating-when-start-position-beginning-in-logstash-input-file-plugin/332286 "2023-05-05T07:46:45Z")

</div>

input { file { path =\> "/home/logs/info.log" type =\> "accesslog" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" stat\_interval =\> 5 ignore\_older =\> 0 }

---

## [Templating email notifications](https://discuss.elastic.co/t/templating-email-notifications/332535)

<div class="topic-metadata">

**Author:** [@Mark\_DP](https://discuss.elastic.co/u/Mark_DP)\
**Replies:** 5\
**Last updated:** [May 5, 2023, 7:28am UTC](https://discuss.elastic.co/t/templating-email-notifications/332535 "2023-05-05T07:28:19Z")

</div>

Hi all, I hope you can help. I have a liitle problem: I created several alerts which nearly delivers the same text but sometimes a few parts of them changes. So I tried to use variables but did not found al solution. …

---

## [Kibana Dashboard loading](https://discuss.elastic.co/t/kibana-dashboard-loading/329655)

<div class="topic-metadata">

**Author:** [@eleven\_e](https://discuss.elastic.co/u/eleven_e)\
**Replies:** 5\
**Last updated:** [May 5, 2023, 6:54am UTC](https://discuss.elastic.co/t/kibana-dashboard-loading/329655 "2023-05-05T06:54:14Z")

</div>

When I try to open a dashboard it keeps loading.

---

## [Elastic search 8.6 (SSL enabled) certificate check disablement](https://discuss.elastic.co/t/elastic-search-8-6-ssl-enabled-certificate-check-disablement/332438)

<div class="topic-metadata">

**Author:** [@easwaran.jeyaraj](https://discuss.elastic.co/u/easwaran.jeyaraj)\
**Replies:** 1\
**Last updated:** [May 5, 2023, 6:29am UTC](https://discuss.elastic.co/t/elastic-search-8-6-ssl-enabled-certificate-check-disablement/332438 "2023-05-05T06:29:14Z")

</div>

Recently we installed Elastic search 8.6 (SSL enabled) which is running as 3 node in cluster n kubernetes using the operator provided by Elastic. When we call ES from external client, after placing the Certificate (clien…

---

## [My ubuntu 16gb ram machine getting stuck after starting elasticsearch](https://discuss.elastic.co/t/my-ubuntu-16gb-ram-machine-getting-stuck-after-starting-elasticsearch/332509)

<div class="topic-metadata">

**Author:** [@Krishna\_Sai\_Nag\_G](https://discuss.elastic.co/u/Krishna_Sai_Nag_G)\
**Replies:** 2\
**Last updated:** [May 5, 2023, 5:26am UTC](https://discuss.elastic.co/t/my-ubuntu-16gb-ram-machine-getting-stuck-after-starting-elasticsearch/332509 "2023-05-05T05:26:59Z")

</div>

My ubuntu 16gb ram machine getting stuck after starting elasticsearch I have seen this in google when checking for it and i have added in /etc/elasticsearch/jvm.options.d/ in that folder i have created one file with …

---

## [Add\_kubernetes\_metadata intermittent failure](https://discuss.elastic.co/t/add-kubernetes-metadata-intermittent-failure/332609)

<div class="topic-metadata">

**Author:** [@hamishforbes](https://discuss.elastic.co/u/hamishforbes)\
**Replies:** 0\
**Last updated:** [May 5, 2023, 3:35am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-intermittent-failure/332609 "2023-05-05T03:35:47Z")

</div>

It looks like under some conditions filebeat on Kubernetes is failing to add metadata. I think there's a race here between the log harvester picking up new container logs and the kubernetes pod watcher populating the me…

---

## [Elastic Lifecycle Management Rollover](https://discuss.elastic.co/t/elastic-lifecycle-management-rollover/332511)

<div class="topic-metadata">

**Author:** [@cboissavy](https://discuss.elastic.co/u/cboissavy)\
**Replies:** 0\
**Last updated:** [May 4, 2023, 7:54am UTC](https://discuss.elastic.co/t/elastic-lifecycle-management-rollover/332511 "2023-05-04T07:54:56Z")

</div>

Hello, I have an ECK with 4 pods elasticsearch v8.6.2. I would like to configure a lifecycle policy hot-warm-cold-delete. I created it "Retention-365" and I create a rollover index with the command : PUT assainissem…

---

## [Sophos XG module not separating data into variables ( Fleet And Elastic Agent )](https://discuss.elastic.co/t/sophos-xg-module-not-separating-data-into-variables-fleet-and-elastic-agent/332516)

<div class="topic-metadata">

**Author:** [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Replies:** 0\
**Last updated:** [May 4, 2023, 8:25am UTC](https://discuss.elastic.co/t/sophos-xg-module-not-separating-data-into-variables-fleet-and-elastic-agent/332516 "2023-05-04T08:25:24Z")

</div>

I cannot see the fields (variables) in the message. All data is inside a field called event. code any suggestion?

---

## [Integrations with fleet server or filebeat module](https://discuss.elastic.co/t/integrations-with-fleet-server-or-filebeat-module/332520)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 11:35pm UTC](https://discuss.elastic.co/t/integrations-with-fleet-server-or-filebeat-module/332520 "2023-05-04T23:35:01Z")

</div>

Hi everyone, I currently need to retrieve syslogs from my palo alto firewall, and I just saw that I can either use filebeat's panw module or deploy a fleet servers and use palo alto integration. So I was wondering what…

---

## [Migration from 7.10 to 7.17 then to 8.7](https://discuss.elastic.co/t/migration-from-7-10-to-7-17-then-to-8-7/332568)

<div class="topic-metadata">

**Author:** [@Lilia](https://discuss.elastic.co/u/Lilia)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 11:20pm UTC](https://discuss.elastic.co/t/migration-from-7-10-to-7-17-then-to-8-7/332568 "2023-05-04T23:20:46Z")

</div>

Hey team, could you please help me with some advices, what is the best approach when i need to migrate custom plugins from the versions mentioned in the topic? I have checked the documentation and apparently should first…

---

## [Reindex with Terms query](https://discuss.elastic.co/t/reindex-with-terms-query/331087)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 12\
**Last updated:** [May 4, 2023, 8:11pm UTC](https://discuss.elastic.co/t/reindex-with-terms-query/331087 "2023-05-04T20:11:06Z")

</div>

Hello, Everyday I create an index with a size of approximately 10 GB of size. Once the index is completed, I need to reindex a certain set of documents into a new filtered index. To filter the documents I'm using a Ter…

---

## [Sorting results of a search template with variable value of sorting field](https://discuss.elastic.co/t/sorting-results-of-a-search-template-with-variable-value-of-sorting-field/331078)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 7\
**Last updated:** [May 4, 2023, 6:03pm UTC](https://discuss.elastic.co/t/sorting-results-of-a-search-template-with-variable-value-of-sorting-field/331078 "2023-05-04T18:03:09Z")

</div>

Good day, I'm trying to make a search template with variable sorting parameter. I have a search template without variable sorting, it looks like this and it works: Field1 - the field that i'm sorting with. \`\`\`PUT \_scr…

---

## [Formatting a date in an alert email](https://discuss.elastic.co/t/formatting-a-date-in-an-alert-email/332312)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 6\
**Last updated:** [May 4, 2023, 4:44pm UTC](https://discuss.elastic.co/t/formatting-a-date-in-an-alert-email/332312 "2023-05-04T16:44:43Z")

</div>

Hi, I use Kibana 7.17. In "Rules and Connectors", I created an alert generating an email. In this email, I display a date (value of a field) like : 2023-04-28T17:23:23.943Z The user would like a date like 28/04/…

---

## [\_source field in jdbc output](https://discuss.elastic.co/t/source-field-in-jdbc-output/332583)

<div class="topic-metadata">

**Author:** [@Valeriy\_Dzhura](https://discuss.elastic.co/u/Valeriy_Dzhura)\
**Replies:** 0\
**Last updated:** [May 4, 2023, 4:34pm UTC](https://discuss.elastic.co/t/source-field-in-jdbc-output/332583 "2023-05-04T16:34:26Z")

</div>

Hello guys, I'm new in logstash. I have a question how I can return \_source field from elastic input to jdbc output. This is necessary for getting main fields and \_source should be stored like varchar(max) For example:…

---

## [How to upload json.file via logstash into elasticserch? What I did wrong?](https://discuss.elastic.co/t/how-to-upload-json-file-via-logstash-into-elasticserch-what-i-did-wrong/331377)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 4:26pm UTC](https://discuss.elastic.co/t/how-to-upload-json-file-via-logstash-into-elasticserch-what-i-did-wrong/331377 "2023-05-04T16:26:56Z")

</div>

json.file \[ { "sku":"00000290", "categories":"1\_brands,1\_restaurant\_equipment,2\_brand\_rm\_gastro,2\_food\_holding\_and\_warming\_equipment,3\_steam\_heaters\_and\_buffets,4\_bain\_marie\_heaters,categoryE7E7163", "family":"TV…

---

## [Error connecting Logstash to PostgresSQL Database](https://discuss.elastic.co/t/error-connecting-logstash-to-postgressql-database/331059)

<div class="topic-metadata">

**Author:** [@vineasouza](https://discuss.elastic.co/u/vineasouza)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 4:14pm UTC](https://discuss.elastic.co/t/error-connecting-logstash-to-postgressql-database/331059 "2023-05-04T16:14:50Z")

</div>

Hello guys, I'm trying to connect Logstash to a PostgresSQL database, but every time I run the pipeline, I'm getting the error Unable to configure plugins: (ArgumentError) Cannot determine timezone from nil . I've trie…

---

## [Configuring Fuzzy Search in Elasticsearch for Non-Dictionary Words](https://discuss.elastic.co/t/configuring-fuzzy-search-in-elasticsearch-for-non-dictionary-words/332519)

<div class="topic-metadata">

**Author:** [@Gurjap\_Singh](https://discuss.elastic.co/u/Gurjap_Singh)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 3:31pm UTC](https://discuss.elastic.co/t/configuring-fuzzy-search-in-elasticsearch-for-non-dictionary-words/332519 "2023-05-04T15:31:55Z")

</div>

I am encountering an issue with fuzzy search in Elasticsearch. When a user searches for the term "cooler", I want only products that match that exact term to be returned, and I do not want products with similar terms lik…

---

## [How to check weather filebeat is able to communicate with kibana dashboard or not](https://discuss.elastic.co/t/how-to-check-weather-filebeat-is-able-to-communicate-with-kibana-dashboard-or-not/332483)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 3:18pm UTC](https://discuss.elastic.co/t/how-to-check-weather-filebeat-is-able-to-communicate-with-kibana-dashboard-or-not/332483 "2023-05-04T15:18:47Z")

</div>

How to check weather filebeat is able to communicate with ELK or kibana dashboard ? If not communicating, then how to know the reason behind it?

---

## [Filebeat log processing out of sync (not ordered by timestamp)](https://discuss.elastic.co/t/filebeat-log-processing-out-of-sync-not-ordered-by-timestamp/332577)

<div class="topic-metadata">

**Author:** [@pavank](https://discuss.elastic.co/u/pavank)\
**Replies:** 0\
**Last updated:** [May 4, 2023, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-log-processing-out-of-sync-not-ordered-by-timestamp/332577 "2023-05-04T15:18:45Z")

</div>

Hi there, We are using Filebeat and Logstash to collect container logs from our OCP clusters, where we have deployed Filebeat as a daemonset and Logstash is running on a VM. The logs are then routed to Azure Log Analyti…

---

## [Elastic Search searchAfter funcitonality not working](https://discuss.elastic.co/t/elastic-search-searchafter-funcitonality-not-working/332561)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 2\
**Last updated:** [May 4, 2023, 2:52pm UTC](https://discuss.elastic.co/t/elastic-search-searchafter-funcitonality-not-working/332561 "2023-05-04T14:52:47Z")

</div>

Hi I am using the Elasticsearch 8 java client. I have created one field createdtime which stores epoch timestamp. Now I first send one request like this query:{ widcard:{name:foo}. sort:\[creattedtime,asc\] it returns…

---

## [Filebeat error while parsing multiline parser config](https://discuss.elastic.co/t/filebeat-error-while-parsing-multiline-parser-config/331089)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [May 4, 2023, 2:47pm UTC](https://discuss.elastic.co/t/filebeat-error-while-parsing-multiline-parser-config/331089 "2023-05-04T14:47:05Z")

</div>

I am using Filebeat 8.7. I am trying to follow the instructions here: I double checked the indentation. Cannot figure out what is wrong. I just want to make sure a multi-line stack trace is captured into one docume…

---

## [Updating kibana dashboards](https://discuss.elastic.co/t/updating-kibana-dashboards/330690)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 2:31pm UTC](https://discuss.elastic.co/t/updating-kibana-dashboards/330690 "2023-05-04T14:31:43Z")

</div>

I have a bunch of dashboards that I maintain . I do this from a privileged account, ordinary users have read only access. When I make changes to a dashboard and save them. I then login as an unprivileged user and the…

---

## [Truncated float number to int problem](https://discuss.elastic.co/t/truncated-float-number-to-int-problem/330811)

<div class="topic-metadata">

**Author:** [@David\_Hermo\_Blanco](https://discuss.elastic.co/u/David_Hermo_Blanco)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 1:47pm UTC](https://discuss.elastic.co/t/truncated-float-number-to-int-problem/330811 "2023-05-04T13:47:41Z")

</div>

I have a float number of shipping price. When I go to new table in dashboard, this field has a integer number.

---

## [Elasticsearch filesystem recovery?](https://discuss.elastic.co/t/elasticsearch-filesystem-recovery/332472)

<div class="topic-metadata">

**Author:** [@PMDubuc](https://discuss.elastic.co/u/PMDubuc)\
**Replies:** 3\
**Last updated:** [May 4, 2023, 1:23pm UTC](https://discuss.elastic.co/t/elasticsearch-filesystem-recovery/332472 "2023-05-04T13:23:38Z")

</div>

We have an old (version 2.4.3) 3 node elastic cluster that has lost index files on the data/nodes/0/indices/ filesystem of 2 of the nodes after having been shut down for a time. If we bring the cluster back up will the…

---

## [How to use Elastic Canvas?](https://discuss.elastic.co/t/how-to-use-elastic-canvas/331051)

<div class="topic-metadata">

**Author:** [@jiage\_liu](https://discuss.elastic.co/u/jiage_liu)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 1:21pm UTC](https://discuss.elastic.co/t/how-to-use-elastic-canvas/331051 "2023-05-04T13:21:47Z")

</div>

Hi , :grinning: Now our team wants to use Canvas in our new project. so I have below some questions: Can using API generate Canvas for different users? Can I add dynamics query conditions in Canvas (I try to add a que…

---

## [Logstash Service is active but still data is not passing to Elastic search](https://discuss.elastic.co/t/logstash-service-is-active-but-still-data-is-not-passing-to-elastic-search/332423)

<div class="topic-metadata">

**Author:** [@Sharath\_Subhash](https://discuss.elastic.co/u/Sharath_Subhash)\
**Replies:** 3\
**Last updated:** [May 4, 2023, 1:07pm UTC](https://discuss.elastic.co/t/logstash-service-is-active-but-still-data-is-not-passing-to-elastic-search/332423 "2023-05-04T13:07:40Z")

</div>

Hi, I am new to Logstash and Elastic search. I am currently going through documents and trying to fix a issue. Our logstash service is running active but data is not passing to Elasticsearch. "logstash.version"=\>"7.17.7…

---

## [Cert error for intial setup of fileBeat](https://discuss.elastic.co/t/cert-error-for-intial-setup-of-filebeat/329997)

<div class="topic-metadata">

**Author:** [@Nibort](https://discuss.elastic.co/u/Nibort)\
**Replies:** 2\
**Last updated:** [May 4, 2023, 12:27pm UTC](https://discuss.elastic.co/t/cert-error-for-intial-setup-of-filebeat/329997 "2023-05-04T12:27:18Z")

</div>

Hello, I've followed the documention to connect client with filebeat to elasticsearch : Filebeat quick start: installation and configuration | Filebeat Reference \[8.7\] | Elastic My filebeat.yml # ---------------------…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=551)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=553)
