# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=557

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 558

---

## [Not able to connect my apm-agent to my apm-server and data transfer from hosted on same server](https://discuss.elastic.co/t/not-able-to-connect-my-apm-agent-to-my-apm-server-and-data-transfer-from-hosted-on-same-server/330627)

<div class="topic-metadata">

**Author:** [@Tataelastic](https://discuss.elastic.co/u/Tataelastic)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 4:39pm UTC](https://discuss.elastic.co/t/not-able-to-connect-my-apm-agent-to-my-apm-server-and-data-transfer-from-hosted-on-same-server/330627 "2023-04-28T16:39:35Z")

</div>

I have deployed elasticsearch, kibana, apm-server on same server ip: 10.8.30.220 output for http://10.8.30.220:8200 { "build\_date": "2023-01-31T04:33:06Z", "build\_sha": "71a8b4c241eb5b4609862c8354d2aa2270f6c568", "…

---

## [Importing third party filebeat dashboard into Kibana (SecurityOnion)](https://discuss.elastic.co/t/importing-third-party-filebeat-dashboard-into-kibana-securityonion/331076)

<div class="topic-metadata">

**Author:** [@KhemaisKebaili](https://discuss.elastic.co/u/KhemaisKebaili)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 4:31pm UTC](https://discuss.elastic.co/t/importing-third-party-filebeat-dashboard-into-kibana-securityonion/331076 "2023-04-28T16:31:26Z")

</div>

I have a SecurityOnion instance that's hosting an ELK 8.6.1 stack. I enabled the threat intelligence module and I have data coming in and could be visualized using the discovery tool. However , and from my research, when…

---

## [Multisource index on elasticsearch passing by logstash](https://discuss.elastic.co/t/multisource-index-on-elasticsearch-passing-by-logstash/330844)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 10\
**Last updated:** [April 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/multisource-index-on-elasticsearch-passing-by-logstash/330844 "2023-04-28T15:57:42Z")

</div>

hey , im trying to create multiple source input from Filebeat , than injecting them into logstash to apply filters , and finally transfer the sources to elasticsearch as indexes The problem i have , only one index is cr…

---

## [How to use SearchLookup getSource(LeafReaderContext ctx, int doc)](https://discuss.elastic.co/t/how-to-use-searchlookup-getsource-leafreadercontext-ctx-int-doc/331072)

<div class="topic-metadata">

**Author:** [@p4paul](https://discuss.elastic.co/u/p4paul)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/how-to-use-searchlookup-getsource-leafreadercontext-ctx-int-doc/331072 "2023-04-28T15:57:41Z")

</div>

In 8.7.0 the source() method was removed from SearchLookup: How do I use the new getSource method in SearchLookup for a FilterScript given the following use case... public class MyLeafFactory implements FilterScript.…

---

## [Remove random indexes](https://discuss.elastic.co/t/remove-random-indexes/331066)

<div class="topic-metadata">

**Author:** [@Marcelo\_Moro\_Brondan](https://discuss.elastic.co/u/Marcelo_Moro_Brondan)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 2:59pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066 "2023-04-28T14:59:17Z")

</div>

remove random indexesremove random indexesHello! I have an elasticsearch 5.6 in centOS 7 and it is behaving unexpectedly. Random indexes are being created. I am not able to identify the origin and apply a configuration …

---

## [Filtering on pdf reports](https://discuss.elastic.co/t/filtering-on-pdf-reports/329955)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 2:19pm UTC](https://discuss.elastic.co/t/filtering-on-pdf-reports/329955 "2023-04-28T14:19:02Z")

</div>

Hi, when in a dashboard I select share -\> pdf reports - post url to create a report, i get this url: /api/reporting/generate/printablePdfV2?jobParams=(browserTimezone:America/Santiago,layout:(dimensions:(height:1463.984…

---

## [Huge logs - how Tuning filebeat](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 5\
**Last updated:** [April 28, 2023, 12:58pm UTC](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333 "2023-04-28T12:58:35Z")

</div>

Hi everybody, I'm french and i m a very newbie with elasticsearch. Elasticsearch version imposed by security team : 7.10.2 I create a cluster like this with dedicate nodes: 2 master node 1 master only eligible node 1…

---

## [Index template - exclude index seems not working](https://discuss.elastic.co/t/index-template-exclude-index-seems-not-working/331060)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 12:54pm UTC](https://discuss.elastic.co/t/index-template-exclude-index-seems-not-working/331060 "2023-04-28T12:54:14Z")

</div>

Hi everybody. I dont find the correct syntax to exclude one index of an index pattern in index template 2 index template :slight\_smile: 1st { "order": 0, "index\_patterns": \[ "\*\_\*","-tdir\_business\_prod-\*" \], …

---

## [Rename nested field based on its data type](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044)

<div class="topic-metadata">

**Author:** [@aversecguy](https://discuss.elastic.co/u/aversecguy)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 10:18am UTC](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044 "2023-04-28T10:18:21Z")

</div>

Hello, dear community, I am brand new to logstash, but have to fix a problem: We are gathering eks audit logs and have errors like illegal\_state\_exception error because of the field responseObject.status could be the t…

---

## [Azure Logs Integration with ECS logs](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041)

<div class="topic-metadata">

**Author:** [@CrystalDesignDR](https://discuss.elastic.co/u/CrystalDesignDR)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 10:03am UTC](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041 "2023-04-28T10:03:24Z")

</div>

Hi, we are running Elastic Cloud and want to add Application Logs to it with Elastic Agent, these logs need to be correlated with out APM traces. We are running the Elastic Azure Logs Integration with the Elastic Agent…

---

## [Failed to assign role via role mapping API ldap realm](https://discuss.elastic.co/t/failed-to-assign-role-via-role-mapping-api-ldap-realm/331039)

<div class="topic-metadata">

**Author:** [@GaetanCia](https://discuss.elastic.co/u/GaetanCia)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 9:59am UTC](https://discuss.elastic.co/t/failed-to-assign-role-via-role-mapping-api-ldap-realm/331039 "2023-04-28T09:59:04Z")

</div>

Hi, I have issue to assign a role via the role-mapping setting. I tried to assign a role to a certain group of people who connect from the ldap realm. If i use the native role mapping file, it work fine My role\_mappi…

---

## [2 instances of Filebeat on same Linux server output to same ES](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 3\
**Last updated:** [April 28, 2023, 9:15am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010 "2023-04-28T09:15:09Z")

</div>

Hi, I have a Linux server running Filebeat 8.3.3 taking Netflow as input and writing it out to ES on another server. As the Netflow load is much more than what Filebeat can handle, I'm thinking of splitting the Netflow …

---

## [Elasticsearch how do I properly monitor performance? Is there a good tool? is there a free alternative to datadog?](https://discuss.elastic.co/t/elasticsearch-how-do-i-properly-monitor-performance-is-there-a-good-tool-is-there-a-free-alternative-to-datadog/331028)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 8:28am UTC](https://discuss.elastic.co/t/elasticsearch-how-do-i-properly-monitor-performance-is-there-a-good-tool-is-there-a-free-alternative-to-datadog/331028 "2023-04-28T08:28:14Z")

</div>

Elasticsearch how do I properly monitor performance? Is there a good tool? is there a free alternative to datadog?

---

## [ILM policy created and applied but it's not deleting the data](https://discuss.elastic.co/t/ilm-policy-created-and-applied-but-its-not-deleting-the-data/330727)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 4\
**Last updated:** [April 28, 2023, 8:27am UTC](https://discuss.elastic.co/t/ilm-policy-created-and-applied-but-its-not-deleting-the-data/330727 "2023-04-28T08:27:45Z")

</div>

Hello Experts, I have created the ILM policy and applied to the index . but still it is not deleting the old file. is there anythin i miss or need to add. Please guide me. PUT \_ilm/policy/delete-old-indices { "policy…

---

## [How do I check why my search query takes too long? Is there something like Explain command in SQL databases?](https://discuss.elastic.co/t/how-do-i-check-why-my-search-query-takes-too-long-is-there-something-like-explain-command-in-sql-databases/331029)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 8:26am UTC](https://discuss.elastic.co/t/how-do-i-check-why-my-search-query-takes-too-long-is-there-something-like-explain-command-in-sql-databases/331029 "2023-04-28T08:26:05Z")

</div>

How do I check why my search query takes too long? Is there something like Explain command in SQL databases?

---

## [Error updating Security Data View](https://discuss.elastic.co/t/error-updating-security-data-view/331027)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 8:17am UTC](https://discuss.elastic.co/t/error-updating-security-data-view/331027 "2023-04-28T08:17:08Z")

</div>

I am facing an error on my kibana: Error updating Security Data View { "name": "AbortError", "body": null, "message": "The operation was aborted. ", "stack": "o@https://kibana.xxxxxx:5403/59020/bundles/kbn-ui-sh…

---

## [Globla Time Filter for Lens Visualisation](https://discuss.elastic.co/t/globla-time-filter-for-lens-visualisation/330881)

<div class="topic-metadata">

**Author:** [@deepack86](https://discuss.elastic.co/u/deepack86)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 8:13am UTC](https://discuss.elastic.co/t/globla-time-filter-for-lens-visualisation/330881 "2023-04-28T08:13:15Z")

</div>

Hi! I want to make a canvas pad with much lens visualisation. There is globaltimefilter to set the date an time for all lens. If i set a date and time the lens visualtion doesn't scale the time axis The code for the …

---

## [Search after example in java8](https://discuss.elastic.co/t/search-after-example-in-java8/330969)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 8:07am UTC](https://discuss.elastic.co/t/search-after-example-in-java8/330969 "2023-04-28T08:07:34Z")

</div>

I cant follow example mentioned in rest api documentation.Elastic java client is really tough to understand. Can some one share how to use searchafter api with java tutorial. There is some sort field we need to share w…

---

## [Question around setting proper ds / index / ilm](https://discuss.elastic.co/t/question-around-setting-proper-ds-index-ilm/330709)

<div class="topic-metadata">

**Author:** [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Replies:** 6\
**Last updated:** [April 28, 2023, 7:04am UTC](https://discuss.elastic.co/t/question-around-setting-proper-ds-index-ilm/330709 "2023-04-28T07:04:14Z")

</div>

Hi new to ES, i have 12 node cluster and its purpose is to capture all of the logs from apps in our 14 env - lets call them dev1-14. each env has 6 apps server and 2 rp and 2 geodes and jmp box - so 11 servers. on the a…

---

## [Logstash is not showing base64 encoded data for pdf's extracted from urls](https://discuss.elastic.co/t/logstash-is-not-showing-base64-encoded-data-for-pdfs-extracted-from-urls/330386)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 5\
**Last updated:** [April 28, 2023, 6:58am UTC](https://discuss.elastic.co/t/logstash-is-not-showing-base64-encoded-data-for-pdfs-extracted-from-urls/330386 "2023-04-28T06:58:36Z")

</div>

Hi Team, I am using logstash http filter to get pdf from url and extract it. http filter has downloaded pdf and extracted its content on target\_field. But the contents are not proper and also its not base64 encoded. Ho…

---

## [How to create new array by using existing list of strings field in logstash ruby filter](https://discuss.elastic.co/t/how-to-create-new-array-by-using-existing-list-of-strings-field-in-logstash-ruby-filter/330761)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 4:57am UTC](https://discuss.elastic.co/t/how-to-create-new-array-by-using-existing-list-of-strings-field-in-logstash-ruby-filter/330761 "2023-04-28T04:57:00Z")

</div>

Hi Team, I have three arrays created from xml in logstash content.REFERENCE: \[PXXXX, TECHNICAL\_SUPPORT\] content.ROOT: \[INTERNAL\_PRODUCT\_OR\_APPLICATION, TOPICS\] I have to create a result array from above inputs if roo…

---

## [Elastic machine learning - question about Anomaly Explorer](https://discuss.elastic.co/t/elastic-machine-learning-question-about-anomaly-explorer/330780)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 3:14am UTC](https://discuss.elastic.co/t/elastic-machine-learning-question-about-anomaly-explorer/330780 "2023-04-28T03:14:03Z")

</div>

Hi, I am new to Elastic machine learning. I input some data about users access a product API endpoint, and I have set up 2 influncers, which are the user name and product brand name. I make one user enormously to acces…

---

## [Empty alerts in Palo Alto Cortex XDR Integration](https://discuss.elastic.co/t/empty-alerts-in-palo-alto-cortex-xdr-integration/330997)

<div class="topic-metadata">

**Author:** [@dhsmf](https://discuss.elastic.co/u/dhsmf)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 2:05am UTC](https://discuss.elastic.co/t/empty-alerts-in-palo-alto-cortex-xdr-integration/330997 "2023-04-28T02:05:56Z")

</div>

I'm planning to use Palo Alto Cortex XDR Integration to ingest alerts for our analyses. It looks that the Integration often brings almost empty alerts (without file hash, process info and so on, showing reply: 0). Is it …

---

## [Failed installing file:///tmp/analysis-phonetic-7.17.7.zip](https://discuss.elastic.co/t/failed-installing-file-tmp-analysis-phonetic-7-17-7-zip/330988)

<div class="topic-metadata">

**Author:** [@markedperf](https://discuss.elastic.co/u/markedperf)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:39pm UTC](https://discuss.elastic.co/t/failed-installing-file-tmp-analysis-phonetic-7-17-7-zip/330988 "2023-04-27T21:39:54Z")

</div>

I am trying to install the analysis-phonetic plugin from a downloaded .zip file. I have copied the files to the local filesystem /tmp directory and inside the container to the /tmp directory. Below is the dockerfile th…

---

## [Definition of plugin "runtimeFields" not found and may have failed to load](https://discuss.elastic.co/t/definition-of-plugin-runtimefields-not-found-and-may-have-failed-to-load/330556)

<div class="topic-metadata">

**Author:** [@Alfredo\_Casanova](https://discuss.elastic.co/u/Alfredo_Casanova)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 7:17pm UTC](https://discuss.elastic.co/t/definition-of-plugin-runtimefields-not-found-and-may-have-failed-to-load/330556 "2023-04-27T19:17:34Z")

</div>

Hi. I just had to reboot my box and now when i submit my password in kibana i'm getting this message. my log file says not about it. Obviously i've tried "clearing my session" as suggested but it did't work.

---

## [Take\_over option not working - logs being reharvested after filebeat restart](https://discuss.elastic.co/t/take-over-option-not-working-logs-being-reharvested-after-filebeat-restart/330983)

<div class="topic-metadata">

**Author:** [@ian.springer-sf](https://discuss.elastic.co/u/ian.springer-sf)\
**Replies:** 5\
**Last updated:** [April 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/take-over-option-not-working-logs-being-reharvested-after-filebeat-restart/330983 "2023-04-27T18:45:35Z")

</div>

I followed the migration guide to migrate my log inputs to filestream inputs, including adding a unique id and setting the "take\_over" option to true. However, upon restarting the filebeat service, all of the logs are re…

---

## [Upscaling Elastic Cloud Instance using Azure CLI](https://discuss.elastic.co/t/upscaling-elastic-cloud-instance-using-azure-cli/330947)

<div class="topic-metadata">

**Author:** [@Jacob\_Concrete](https://discuss.elastic.co/u/Jacob_Concrete)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 6:40pm UTC](https://discuss.elastic.co/t/upscaling-elastic-cloud-instance-using-azure-cli/330947 "2023-04-27T18:40:38Z")

</div>

Hello, I am trying to automate a process of Elastic installation on Azure. One of the steps is to upscale Elasticsearch from 2 zone 240GB storage 8GB RAM to 3 zone 870 GB Storage 29GB RAM after the deployment is created…

---

## [Watcher - trying to print all document hits from search results](https://discuss.elastic.co/t/watcher-trying-to-print-all-document-hits-from-search-results/330978)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 6:16pm UTC](https://discuss.elastic.co/t/watcher-trying-to-print-all-document-hits-from-search-results/330978 "2023-04-27T18:16:38Z")

</div>

Hi, trying to create a watcher to just print all hits on the message field which matches a particular string. All I was able to get to is print individual hits by using this pattern in the actions to send email: Message…

---

## [Logstash on windows sends data directly to the security onion SOC, not elasticsearch on windows?](https://discuss.elastic.co/t/logstash-on-windows-sends-data-directly-to-the-security-onion-soc-not-elasticsearch-on-windows/330985)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 6:09pm UTC](https://discuss.elastic.co/t/logstash-on-windows-sends-data-directly-to-the-security-onion-soc-not-elasticsearch-on-windows/330985 "2023-04-27T18:09:06Z")

</div>

Hi, I am still learning about the sysmon data going to security onion. It seems that using elasticsearch on windows handles only windows data and does not send the data to security onion kibana. You can download kibana…

---

## [Filebeat Module Postgresql](https://discuss.elastic.co/t/filebeat-module-postgresql/330860)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 8\
**Last updated:** [April 27, 2023, 5:04pm UTC](https://discuss.elastic.co/t/filebeat-module-postgresql/330860 "2023-04-27T17:04:25Z")

</div>

Hello everyone, Please I need your help, I have problems with the Postgresql module filbeat, at the time of viewing the log I see that I get the following error message: \[2023-04-26 09:20:02.534 -05 \[2828024\] u\_sistema…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=556)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=558)
