# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=562

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 563

---

## [Should I create an SQL Output for beats](https://discuss.elastic.co/t/should-i-create-an-sql-output-for-beats/330563)

<div class="topic-metadata">

**Author:** [@Toaster2-0](https://discuss.elastic.co/u/Toaster2-0)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 10:50am UTC](https://discuss.elastic.co/t/should-i-create-an-sql-output-for-beats/330563 "2023-04-24T10:50:59Z")

</div>

Hello, TL;DR: I was thinking about making an output plugin for SQL. I tried the Elastic Stack for a few month with my private project, but the Stack seems too big for it and I am very comfortable in SQL. Now I was sear…

---

## [ECK Anonymous user concatenation of privileges](https://discuss.elastic.co/t/eck-anonymous-user-concatenation-of-privileges/330617)

<div class="topic-metadata">

**Author:** [@Patrick\_Bardo](https://discuss.elastic.co/u/Patrick_Bardo)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 9:07am UTC](https://discuss.elastic.co/t/eck-anonymous-user-concatenation-of-privileges/330617 "2023-04-24T09:07:09Z")

</div>

We are using ECK operator v2.6.1 and Elastic and Kibana v8.6.2. We would like to enable anonymous access of kibana to our users, and have this user be authenticated with elasticsearch to have certain limited permissions.…

---

## [Unable to configure elastic search apt repository as a remote repository in Artifactory](https://discuss.elastic.co/t/unable-to-configure-elastic-search-apt-repository-as-a-remote-repository-in-artifactory/330286)

<div class="topic-metadata">

**Author:** [@joaobaptista](https://discuss.elastic.co/u/joaobaptista)\
**Replies:** 4\
**Last updated:** [April 24, 2023, 9:00am UTC](https://discuss.elastic.co/t/unable-to-configure-elastic-search-apt-repository-as-a-remote-repository-in-artifactory/330286 "2023-04-24T09:00:57Z")

</div>

Hi all, We are trying to configure Elasticsearch apt repository in Artifactory, but it always fails due to a error: "HTTP ERROR 404" We are using the following URL: https://artifacts.elastic.co/packages/8.x/apt The sa…

---

## [Filebeat unable to monitor container custom log path](https://discuss.elastic.co/t/filebeat-unable-to-monitor-container-custom-log-path/329905)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 16\
**Last updated:** [April 24, 2023, 8:40am UTC](https://discuss.elastic.co/t/filebeat-unable-to-monitor-container-custom-log-path/329905 "2023-04-24T08:40:40Z")

</div>

Hello, I want to monitor the containers logs using filebeat kubernetes deplyment and the log format is in json format it is just monitoring the logs from containers but not this json file saved inside the container So …

---

## [What diffirent about nested and bool composite query](https://discuss.elastic.co/t/what-diffirent-about-nested-and-bool-composite-query/330063)

<div class="topic-metadata">

**Author:** [@sslhj](https://discuss.elastic.co/u/sslhj)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:55am UTC](https://discuss.elastic.co/t/what-diffirent-about-nested-and-bool-composite-query/330063 "2023-04-24T07:55:36Z")

</div>

I have devloped a component that translate expression to esdel, now i have an exp like that "((extras.key== ‘k1’ and extras.value==100 ) or (extras.key== “k2” and extras.value==”v2”))", in that, ”extras“ is a nested fie…

---

## [Beats error: No paths were defined for input accessing config](https://discuss.elastic.co/t/beats-error-no-paths-were-defined-for-input-accessing-config/330285)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 3\
**Last updated:** [April 24, 2023, 7:36am UTC](https://discuss.elastic.co/t/beats-error-no-paths-were-defined-for-input-accessing-config/330285 "2023-04-24T07:36:47Z")

</div>

Hi everyone , I am currently trying to configure filebeat to retrieve logs from my palo alto firewall, I have configured and enable the panw modules: - module: panw panos: enabled: true var.input: udp var…

---

## [In Elastic search, can we change the names of retrieved fields of searched response dynamically, like mongoDB projection?](https://discuss.elastic.co/t/in-elastic-search-can-we-change-the-names-of-retrieved-fields-of-searched-response-dynamically-like-mongodb-projection/330599)

<div class="topic-metadata">

**Author:** [@cvam199](https://discuss.elastic.co/u/cvam199)\
**Replies:** 3\
**Last updated:** [April 24, 2023, 6:42am UTC](https://discuss.elastic.co/t/in-elastic-search-can-we-change-the-names-of-retrieved-fields-of-searched-response-dynamically-like-mongodb-projection/330599 "2023-04-24T06:42:21Z")

</div>

When I query on Elasticsearch (ES) to get some data, I get it in following format: Response: "hits" : \[ { "\_index" : "testpoc", "\_type" : "\_doc", "\_id" : "1", "\_score" : 1.0, …

---

## [Elasticsearch template not working](https://discuss.elastic.co/t/elasticsearch-template-not-working/330574)

<div class="topic-metadata">

**Author:** [@jiankunking](https://discuss.elastic.co/u/jiankunking)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 6:13am UTC](https://discuss.elastic.co/t/elasticsearch-template-not-working/330574 "2023-04-24T06:13:59Z")

</div>

I first write data directly to the specified index, and then create an index template, After the index template is created, I continue to write data into the specified index. At this time, I write the new properties of …

---

## [How can i elasticsearch 2.4.6 jdbc client jar file?](https://discuss.elastic.co/t/how-can-i-elasticsearch-2-4-6-jdbc-client-jar-file/330594)

<div class="topic-metadata">

**Author:** [@a89541457](https://discuss.elastic.co/u/a89541457)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 5:02am UTC](https://discuss.elastic.co/t/how-can-i-elasticsearch-2-4-6-jdbc-client-jar-file/330594 "2023-04-24T05:02:31Z")

</div>

there is no ES 2.4.6 jdbc client jar file... i want to connect elasticsearch 2.4.6 via datagrip. but i fail with this message "This version of the JDBC driver is only compatible with Elasticsearch version 7.10 or new…

---

## [Is Garbage Collection monitoring still needed in ES 6.8](https://discuss.elastic.co/t/is-garbage-collection-monitoring-still-needed-in-es-6-8/330582)

<div class="topic-metadata">

**Author:** [@Praveen\_Banthia](https://discuss.elastic.co/u/Praveen_Banthia)\
**Replies:** 6\
**Last updated:** [April 24, 2023, 5:16am UTC](https://discuss.elastic.co/t/is-garbage-collection-monitoring-still-needed-in-es-6-8/330582 "2023-04-24T05:16:18Z")

</div>

I was reading an old article We are on ES version 6.8 and Java 11 or higher . Is this checking for garbage collection metrics even needed anymore. My assumption G1 GC is fast enough that even with max recommended si…

---

## [Filter message log in logstash](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 2:37am UTC](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524 "2023-04-24T02:37:04Z")

</div>

i want to add filter to logstash to convert message to json format this is my example API response \< HTTP 200 - body: {"result": \[{"status": {"code": -18, "message": "No permission for the resource"}, "url": "/os/hi"}\]…

---

## [Reporting Diagnostics tool fails on capture screenshot](https://discuss.elastic.co/t/reporting-diagnostics-tool-fails-on-capture-screenshot/330080)

<div class="topic-metadata">

**Author:** [@sblack](https://discuss.elastic.co/u/sblack)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 10:59pm UTC](https://discuss.elastic.co/t/reporting-diagnostics-tool-fails-on-capture-screenshot/330080 "2023-04-23T22:59:32Z")

</div>

I ran the Reporting Diagnostics tool and after sometime, the following error is displayed: Something isn't working properly. There was a problem running the diagnostic: Error For additional debugging information, I …

---

## [What aggrigation should I use to achieve this](https://discuss.elastic.co/t/what-aggrigation-should-i-use-to-achieve-this/330206)

<div class="topic-metadata">

**Author:** [@Bishnu\_Sahu](https://discuss.elastic.co/u/Bishnu_Sahu)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 9:14am UTC](https://discuss.elastic.co/t/what-aggrigation-should-i-use-to-achieve-this/330206 "2023-04-18T09:14:45Z")

</div>

Here my index mapping:- { "settings": { "number\_of\_shards": 1 }, "mappings": { "properties": { "timestamp": { "type": "date" }, "leadId": { "type": "keyword" }, …

---

## [Error of ELK stack memory overflow on Windows Server 2012](https://discuss.elastic.co/t/error-of-elk-stack-memory-overflow-on-windows-server-2012/330518)

<div class="topic-metadata">

**Author:** [@DuanTran](https://discuss.elastic.co/u/DuanTran)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 10:38pm UTC](https://discuss.elastic.co/t/error-of-elk-stack-memory-overflow-on-windows-server-2012/330518 "2023-04-23T22:38:11Z")

</div>

I am happy to meet everyone. I am currently in great need of help from Elastic experts. When using ELK on Windows Server 2012, the OpenJVM processes of Elasticsearch and Logstash occupy up to 80% of the system. I have be…

---

## [Kibana cannot connect to the Elastic Package Registry, which provides Elastic Agent integrations](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/330580)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 1:21pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/330580 "2023-04-23T13:21:01Z")

</div>

There are a few posts noting this error message, without a solution. In case somebody stumbles upon it : This message may be very misleading, in case you did not activate xpack security First, check your service logs…

---

## [Not able to see index log file in elastic search](https://discuss.elastic.co/t/not-able-to-see-index-log-file-in-elastic-search/330571)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 8:06pm UTC](https://discuss.elastic.co/t/not-able-to-see-index-log-file-in-elastic-search/330571 "2023-04-23T20:06:46Z")

</div>

I am sending this log file web\_access.log 54.36.149.41 - - \[22/Jan/2019:03:56:14 +0330\] "GET /filter/27|13%20%D9%85%DA%AF%D8%A7%D9%BE%DB%8C%DA%A9%D8%B3%D9%84,27|%DA%A9%D9%85%D8%AA%D8%B1%20%D8%A7%D8%B2%205%20%D9%85%DA%A…

---

## [Logstash is not able to connect to workplace search](https://discuss.elastic.co/t/logstash-is-not-able-to-connect-to-workplace-search/330585)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 5:27pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-connect-to-workplace-search/330585 "2023-04-23T17:27:44Z")

</div>

Hi Team, I have added workplace search as a output plugin. output { elastic\_workplace\_search { source =\> "6555639ee4f75566c32f4298" access\_token =\> "efzq36opkajivo13judz65n9" url =\> "https://153.1.16.10:3…

---

## [Failed to start kibana.service - Kibana](https://discuss.elastic.co/t/failed-to-start-kibana-service-kibana/329630)

<div class="topic-metadata">

**Author:** [@Afif\_Haziq](https://discuss.elastic.co/u/Afif_Haziq)\
**Replies:** 4\
**Last updated:** [April 23, 2023, 5:14pm UTC](https://discuss.elastic.co/t/failed-to-start-kibana-service-kibana/329630 "2023-04-23T17:14:41Z")

</div>

Hi, im newbie so im not quite sure what im currently doing. few hours ago ive configured the kibana server. after i reopened the kali purple in my virtualbox the kibana server failed to start and i dont know what and how…

---

## [Handle Json file](https://discuss.elastic.co/t/handle-json-file/330562)

<div class="topic-metadata">

**Author:** [@Ashraf123](https://discuss.elastic.co/u/Ashraf123)\
**Replies:** 2\
**Last updated:** [April 23, 2023, 3:35pm UTC](https://discuss.elastic.co/t/handle-json-file/330562 "2023-04-23T15:35:54Z")

</div>

Hello All, I have the following Json file collected by logstash. The problem I'm facing is with Item ID as it add json nested object with for each item. The problem I can't build dashboards for these items with this str…

---

## [Need help adding Fleet server](https://discuss.elastic.co/t/need-help-adding-fleet-server/330565)

<div class="topic-metadata">

**Author:** [@Tanner\_Sutherlin](https://discuss.elastic.co/u/Tanner_Sutherlin)\
**Replies:** 18\
**Last updated:** [April 23, 2023, 2:52pm UTC](https://discuss.elastic.co/t/need-help-adding-fleet-server/330565 "2023-04-23T14:52:11Z")

</div>

I've installed the fleet server on my virtual Ubuntu version 22 machine but I can't get the fleet server to show in Kibana. I checked Ubuntu elastic-agent service and it was showing inactive so I started it with "systemc…

---

## [ES nodes fail to ping with ports open and Telnet'able](https://discuss.elastic.co/t/es-nodes-fail-to-ping-with-ports-open-and-telnetable/330581)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 4\
**Last updated:** [April 23, 2023, 2:25pm UTC](https://discuss.elastic.co/t/es-nodes-fail-to-ping-with-ports-open-and-telnetable/330581 "2023-04-23T14:25:11Z")

</div>

Hi there! Weirdly, still did not find a solution to a problem. I'm creating a new cluster right now (v6.8.6). And all nodes only see themselves. All of them set up to be master and have discovery.zen.minimum\_master\_no…

---

## [Random fields in "Available fields" in Kibana discover](https://discuss.elastic.co/t/random-fields-in-available-fields-in-kibana-discover/330498)

<div class="topic-metadata">

**Author:** [@rkelastic](https://discuss.elastic.co/u/rkelastic)\
**Replies:** 2\
**Last updated:** [April 23, 2023, 12:16pm UTC](https://discuss.elastic.co/t/random-fields-in-available-fields-in-kibana-discover/330498 "2023-04-23T12:16:40Z")

</div>

I am using a filebeat instance to read data from azure blob storage and see the visualisation in kibana. In Discover tab in kibana, under the "Available fields" section, it is showing list of fields which are not there …

---

## [Kibana tries to connect to 169.254.169.254:80](https://discuss.elastic.co/t/kibana-tries-to-connect-to-169-254-169-254-80/327353)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 19\
**Last updated:** [April 23, 2023, 7:43am UTC](https://discuss.elastic.co/t/kibana-tries-to-connect-to-169-254-169-254-80/327353 "2023-04-23T07:43:51Z")

</div>

Hello elastic community, any idea why Kibana tries to connect to 169.254.169.254:80 for first 5-6 minutes after I start it? I noticed this with version 7.17.9, but I think it was like this at least for all 7.17.X versi…

---

## [How to implement data stream splitting for multiple types in Logstash's Java plugin?](https://discuss.elastic.co/t/how-to-implement-data-stream-splitting-for-multiple-types-in-logstashs-java-plugin/330569)

<div class="topic-metadata">

**Author:** [@woxinfeishi](https://discuss.elastic.co/u/woxinfeishi)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 2:32am UTC](https://discuss.elastic.co/t/how-to-implement-data-stream-splitting-for-multiple-types-in-logstashs-java-plugin/330569 "2023-04-23T02:32:42Z")

</div>

When using the logstash-input-rabbitmq plugin, multiple service logs can be collected by specifying different types in the same Logstash configuration file. Now I want to implement a Java version of the Logstash-input-ro…

---

## [Api\_key privilege](https://discuss.elastic.co/t/api-key-privilege/330558)

<div class="topic-metadata">

**Author:** [@7Alex7](https://discuss.elastic.co/u/7Alex7)\
**Replies:** 0\
**Last updated:** [April 22, 2023, 6:53pm UTC](https://discuss.elastic.co/t/api-key-privilege/330558 "2023-04-22T18:53:33Z")

</div>

I will use Search in my projects but would like to test it before buying. Projects need temporary credentials functionality. The Api\_key looks good for this. One more restriction is that the user must be able to create …

---

## [Calling Elastic search from remote server via https](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254)

<div class="topic-metadata">

**Author:** [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Replies:** 12\
**Last updated:** [April 22, 2023, 10:48am UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254 "2023-04-22T10:48:37Z")

</div>

This works fine on local machine curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic: https://localhost:9200 This does not work remotely curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic: https:/…

---

## [Elasticsearch connection issue](https://discuss.elastic.co/t/elasticsearch-connection-issue/330480)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 6\
**Last updated:** [April 22, 2023, 10:29am UTC](https://discuss.elastic.co/t/elasticsearch-connection-issue/330480 "2023-04-22T10:29:30Z")

</div>

Hello, A bit of a noob on certs stuff and I had a previous question where I think I was complicating things to solve a connection issue to my Elasticsearch deployment: The following is an image and an error message: …

---

## [How to handle default value for logstash pipeline efficiently?](https://discuss.elastic.co/t/how-to-handle-default-value-for-logstash-pipeline-efficiently/330335)

<div class="topic-metadata">

**Author:** [@Hatef\_Alipour](https://discuss.elastic.co/u/Hatef_Alipour)\
**Replies:** 2\
**Last updated:** [April 22, 2023, 8:19am UTC](https://discuss.elastic.co/t/how-to-handle-default-value-for-logstash-pipeline-efficiently/330335 "2023-04-22T08:19:22Z")

</div>

I have a logstash pipeline that its filter part looks like this: filter { if condition { prune { blacklist\_names =\> \["^cat\[1-8\]$","^classifier.version$","^accessory\_check$"\] …

---

## [Visualize count of messages for a specific key (ID) within a time window](https://discuss.elastic.co/t/visualize-count-of-messages-for-a-specific-key-id-within-a-time-window/330545)

<div class="topic-metadata">

**Author:** [@Florian\_Braun](https://discuss.elastic.co/u/Florian_Braun)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 10:08pm UTC](https://discuss.elastic.co/t/visualize-count-of-messages-for-a-specific-key-id-within-a-time-window/330545 "2023-04-21T22:08:37Z")

</div>

In my dataset I get a large amount of messages, each providing an update to an object with a unique ID. What I would like to visualize is how frequent these updates are for each unique ID, more specifically, how often d…

---

## [Sysmon events not getting into the SOC and kibana](https://discuss.elastic.co/t/sysmon-events-not-getting-into-the-soc-and-kibana/330543)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 9:16pm UTC](https://discuss.elastic.co/t/sysmon-events-not-getting-into-the-soc-and-kibana/330543 "2023-04-21T21:16:30Z")

</div>

Hi, I have been trying to get my sysmon events to show up in kibana. Does anyone know if there is a debugging check list that I could follow? I uninstalled and sysmon and winlogbeat. I went into the sysmon.yml and I se…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=561)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=563)
