# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=563

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 564

---

## [Can I move my sysmon service to another folder](https://discuss.elastic.co/t/can-i-move-my-sysmon-service-to-another-folder/330542)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 8:55pm UTC](https://discuss.elastic.co/t/can-i-move-my-sysmon-service-to-another-folder/330542 "2023-04-21T20:55:11Z")

</div>

When I install sysmon, I can put it in the sysmon folder that I choose. But why does the service reside in C:\\WINDOWS\\Sysmon.exe instead of where I would rather have it? thanks again for any advice or suggestions

---

## [Enhanced data table-Add image and on click it should download the log/excel file](https://discuss.elastic.co/t/enhanced-data-table-add-image-and-on-click-it-should-download-the-log-excel-file/330315)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 8:02pm UTC](https://discuss.elastic.co/t/enhanced-data-table-add-image-and-on-click-it-should-download-the-log-excel-file/330315 "2023-04-21T20:02:18Z")

</div>

Hello @fbaligand , 1)Could you plz let me know if its possible to add image instead of hyperlink to download something? In below image i have achived this through using enhanced table and as per my requirement my inten…

---

## [Regression? Metricbeat dies immediately if kibana isn't running yet (or is still starting)](https://discuss.elastic.co/t/regression-metricbeat-dies-immediately-if-kibana-isnt-running-yet-or-is-still-starting/328756)

<div class="topic-metadata">

**Author:** [@archon810](https://discuss.elastic.co/u/archon810)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 6:24pm UTC](https://discuss.elastic.co/t/regression-metricbeat-dies-immediately-if-kibana-isnt-running-yet-or-is-still-starting/328756 "2023-04-21T18:24:56Z")

</div>

This used to work in v7, but broken in v8, which we upgraded to recently. Restarting kibana and then restarting metricbeat, like so: systemctl restart elasticsearch && systemctl restart kibana && systemctl restart metr…

---

## [PDF From Watcher is returning blank visualizations](https://discuss.elastic.co/t/pdf-from-watcher-is-returning-blank-visualizations/330539)

<div class="topic-metadata">

**Author:** [@swhittenburg](https://discuss.elastic.co/u/swhittenburg)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 4:52pm UTC](https://discuss.elastic.co/t/pdf-from-watcher-is-returning-blank-visualizations/330539 "2023-04-21T16:52:25Z")

</div>

I set up a custom watcher to send me an email of a pdf of a dashboard every x minutes. I had it set to 5 minutes and the pdf would send correctly a couple times and then would be blank, then would be fine again. I'm assu…

---

## [How to delete a runtime field?](https://discuss.elastic.co/t/how-to-delete-a-runtime-field/330526)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-to-delete-a-runtime-field/330526 "2023-04-21T16:47:04Z")

</div>

I am trying to use runtime fields instead of scripted fields and have created one, which I no longer need. Is there any API or from GUI I can delete the runtime fields ?

---

## [Cross index kibana dashboard](https://discuss.elastic.co/t/cross-index-kibana-dashboard/330538)

<div class="topic-metadata">

**Author:** [@George\_ML](https://discuss.elastic.co/u/George_ML)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 4:46pm UTC](https://discuss.elastic.co/t/cross-index-kibana-dashboard/330538 "2023-04-21T16:46:01Z")

</div>

Hello, I am trying to build a dashboard that pulls information from multiple indices. While both indices have the same data, the formatting is different, for example: On index logstash, i have the property resourceId,…

---

## [Canvas add grid lines to graph](https://discuss.elastic.co/t/canvas-add-grid-lines-to-graph/330537)

<div class="topic-metadata">

**Author:** [@goofinator](https://discuss.elastic.co/u/goofinator)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/canvas-add-grid-lines-to-graph/330537 "2023-04-21T16:21:02Z")

</div>

Hello iam trying to add some simple x and y grid lines to my line graph.. I cant find any examples on how to do that. Could anyone please assist me in how i can add them Thanks David

---

## [Logstash JDBC input v5.4.1 crash pipeline when configured server is unreachable or if the server is not listening on db-port](https://discuss.elastic.co/t/logstash-jdbc-input-v5-4-1-crash-pipeline-when-configured-server-is-unreachable-or-if-the-server-is-not-listening-on-db-port/330530)

<div class="topic-metadata">

**Author:** [@VoP](https://discuss.elastic.co/u/VoP)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 3:45pm UTC](https://discuss.elastic.co/t/logstash-jdbc-input-v5-4-1-crash-pipeline-when-configured-server-is-unreachable-or-if-the-server-is-not-listening-on-db-port/330530 "2023-04-21T15:45:32Z")

</div>

Hello, Got some JDBC inputs configured in logstash, and after upgrade from logstash 7.16.2 and logstash-integration-jdbc (5.1.8) to logstash 8.6.2 and logstash-integration-jdbc (5.4.1), the pipeline crashes when the con…

---

## [Can you install winlogbeat in another folder](https://discuss.elastic.co/t/can-you-install-winlogbeat-in-another-folder/330400)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 5\
**Last updated:** [April 21, 2023, 3:33pm UTC](https://discuss.elastic.co/t/can-you-install-winlogbeat-in-another-folder/330400 "2023-04-21T15:33:22Z")

</div>

HI, it seems like the install instructions I have seen go into ProgramData or Program files. I want to install to a folder where all of my cyber security stuff? thanks for any advice or suggestions

---

## [Hamming Distance on Binary Strings - Latest](https://discuss.elastic.co/t/hamming-distance-on-binary-strings-latest/330292)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 5\
**Last updated:** [April 21, 2023, 2:27pm UTC](https://discuss.elastic.co/t/hamming-distance-on-binary-strings-latest/330292 "2023-04-21T14:27:14Z")

</div>

Hello, I want to do hamming distance on binary strings in elasticsearch, and I want to control the distance. In my case, the binary strings have a length of 256 and I want everything with a hamming distance of 32 or be…

---

## [Prerequisites for Machine Learning and client Filebeat](https://discuss.elastic.co/t/prerequisites-for-machine-learning-and-client-filebeat/329733)

<div class="topic-metadata">

**Author:** [@kay1](https://discuss.elastic.co/u/kay1)\
**Replies:** 4\
**Last updated:** [April 21, 2023, 2:16pm UTC](https://discuss.elastic.co/t/prerequisites-for-machine-learning-and-client-filebeat/329733 "2023-04-21T14:16:23Z")

</div>

Hi All, I have saw in the documentation, few months ago, that we can only use Machine Learning with a client filebeat \> version 7.14. Can someone confirm the information ? Thank you. KP

---

## [Split or cut from context\_hits iteration in Elasticsearch query rule](https://discuss.elastic.co/t/split-or-cut-from-context-hits-iteration-in-elasticsearch-query-rule/330521)

<div class="topic-metadata">

**Author:** [@Josep\_Martinez](https://discuss.elastic.co/u/Josep_Martinez)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 1:13pm UTC](https://discuss.elastic.co/t/split-or-cut-from-context-hits-iteration-in-elasticsearch-query-rule/330521 "2023-04-21T13:13:57Z")

</div>

Hello. I'm newbie in Elasticsearch monitoring. I'm trying to get only a few strings or characters from an context\_hits iteration like this: {{#context.hits}} {{\_source.message}} {{/context.hits}} I have too many info…

---

## [Permanent filter](https://discuss.elastic.co/t/permanent-filter/330370)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 1:08pm UTC](https://discuss.elastic.co/t/permanent-filter/330370 "2023-04-21T13:08:53Z")

</div>

Is there a way to make a "permanent filter" or make a filter non-removable? The reason for this is, I want the user to only see data relevant to their company. If they simply removed the filter, they would be able to vi…

---

## [How to have an array that pulls up linux commands](https://discuss.elastic.co/t/how-to-have-an-array-that-pulls-up-linux-commands/330116)

<div class="topic-metadata">

**Author:** [@Wad1636](https://discuss.elastic.co/u/Wad1636)\
**Replies:** 6\
**Last updated:** [April 21, 2023, 1:06pm UTC](https://discuss.elastic.co/t/how-to-have-an-array-that-pulls-up-linux-commands/330116 "2023-04-21T13:06:34Z")

</div>

Good morning, I would like to have a reassembly of the commands type on linux live and put them in a table, the problem I can't already find how to reassemble the commands. Thanks for your future help.

---

## [How to create a heatmap chart?](https://discuss.elastic.co/t/how-to-create-a-heatmap-chart/329427)

<div class="topic-metadata">

**Author:** [@OlegG](https://discuss.elastic.co/u/OlegG)\
**Replies:** 2\
**Last updated:** [April 7, 2023, 6:05am UTC](https://discuss.elastic.co/t/how-to-create-a-heatmap-chart/329427 "2023-04-07T06:05:21Z")

</div>

The vertical axis is days (not configured, but this is my desire), the horizontal is the hours of one day (not configured, but this is my desire), the resulting squares from their intersection are the counter of what …

---

## [Connect packetbeat to logstash](https://discuss.elastic.co/t/connect-packetbeat-to-logstash/330515)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 11:30am UTC](https://discuss.elastic.co/t/connect-packetbeat-to-logstash/330515 "2023-04-21T11:30:25Z")

</div>

I'm trying to pass data from packetbeat to logstash and I get this error "packetbeat setup output Exiting: index management requested but the Elasticsearch output is not configured/enabled " These are my settings. #…

---

## [LoLogs are not coming from filebeat to logstash to elasticsearch](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 10:17am UTC](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509 "2023-04-21T10:17:23Z")

</div>

Hi, I have installed filebeat on my windows machine. I've enabled the systema nd logstash module. Here is the filebeat.yml - type: filestream # Unique ID among all inputs, an ID is required. id: my-filestream-id …

---

## [How to add pod annotations to filebeat documents?](https://discuss.elastic.co/t/how-to-add-pod-annotations-to-filebeat-documents/330485)

<div class="topic-metadata">

**Author:** [@lucasdacosta](https://discuss.elastic.co/u/lucasdacosta)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 10:01am UTC](https://discuss.elastic.co/t/how-to-add-pod-annotations-to-filebeat-documents/330485 "2023-04-21T10:01:18Z")

</div>

Hi folks :wave: Am running filebeat within my cluster but I can't figure out how to add fields to my log documents which would include the pod's annotations. That's super relevant for search later. Here's my current co…

---

## [Data not getting reflected in transform index](https://discuss.elastic.co/t/data-not-getting-reflected-in-transform-index/330507)

<div class="topic-metadata">

**Author:** [@jainesh\_singh](https://discuss.elastic.co/u/jainesh_singh)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 9:57am UTC](https://discuss.elastic.co/t/data-not-getting-reflected-in-transform-index/330507 "2023-04-21T09:57:36Z")

</div>

Hi Team, We have configured Elasticsearch along with logstash. Our setup is: There is a data stream with the following mapping: @timestamp (ingest generated by logstash) { "id": "1", "activityTime": "202…

---

## [Elasticsearch Failing. .kibana\_task\_manager\_8.5.0\_001 Failed engine index/write.lock](https://discuss.elastic.co/t/elasticsearch-failing-kibana-task-manager-8-5-0-001-failed-engine-index-write-lock/328775)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 9:36am UTC](https://discuss.elastic.co/t/elasticsearch-failing-kibana-task-manager-8-5-0-001-failed-engine-index-write-lock/328775 "2023-04-21T09:36:08Z")

</div>

Hi, Version: 8.5.1 currently I have a lot of trouble to keep the ELK alive. It failed twice exactly after 11 days. I am using Elastic & Kibana on Kubernetes Rancher. Deployed single node cluster Using NFS as Persist…

---

## [Logstash : Codec multi line problem | failed to parse field \[time\] of type \[date\] in document](https://discuss.elastic.co/t/logstash-codec-multi-line-problem-failed-to-parse-field-time-of-type-date-in-document/330394)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [April 21, 2023, 9:21am UTC](https://discuss.elastic.co/t/logstash-codec-multi-line-problem-failed-to-parse-field-time-of-type-date-in-document/330394 "2023-04-21T09:21:05Z")

</div>

I think that there is a problem in my multi line pattern but I don't understand where :frowning: Here is my codec : file { path =\> "/var/log/all\_logs/\*\*/serverlogs/localhost.\*.log" start\_position =\> "beginnin…

---

## [How to send data to the index node](https://discuss.elastic.co/t/how-to-send-data-to-the-index-node/330318)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 4\
**Last updated:** [April 21, 2023, 9:19am UTC](https://discuss.elastic.co/t/how-to-send-data-to-the-index-node/330318 "2023-04-21T09:19:47Z")

</div>

Hello, I wanted to set up a cluster with some nodes and I wanted to install packetbeat on each node so I could monitor the network and then send all the data to the node's packetbeat index.x . It was possible? What would…

---

## [Filebeat/Logstash output split messages into multiple with approximately a maximum field size of 8191 charactes](https://discuss.elastic.co/t/filebeat-logstash-output-split-messages-into-multiple-with-approximately-a-maximum-field-size-of-8191-charactes/330174)

<div class="topic-metadata">

**Author:** [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 12:59am UTC](https://discuss.elastic.co/t/filebeat-logstash-output-split-messages-into-multiple-with-approximately-a-maximum-field-size-of-8191-charactes/330174 "2023-04-18T00:59:40Z")

</div>

I am using Filebeat to collect logs output by docker to Logstash, to Elastic Search. The data flow is from docker stdout -\> Filebeat (autodiscovery) -\> Logstash -\> ES Logstash docker.elastic.co/logstash/logstash:6.8.23 …

---

## [Fscrawler in docker Exception in thread "main" java.util.NoSuchElementException](https://discuss.elastic.co/t/fscrawler-in-docker-exception-in-thread-main-java-util-nosuchelementexception/330398)

<div class="topic-metadata">

**Author:** [@lenchester](https://discuss.elastic.co/u/lenchester)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 9:00am UTC](https://discuss.elastic.co/t/fscrawler-in-docker-exception-in-thread-main-java-util-nosuchelementexception/330398 "2023-04-21T09:00:20Z")

</div>

Hi I am launching Fscrawler with Elasticsearch and kibana inside docker containers and I am getting following error | Exception in thread "main" java.util.NoSuchElementException fscrawler | at java.b…

---

## [Logstash JDBC input plugin: Stopped execution without any error log](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-stopped-execution-without-any-error-log/330186)

<div class="topic-metadata">

**Author:** [@adityasinghal26](https://discuss.elastic.co/u/adityasinghal26)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 8:40am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-stopped-execution-without-any-error-log/330186 "2023-04-21T08:40:41Z")

</div>

Hi Team, I am using Logstash 7.17 as a Kubernetes Deployment (replicas - 2). This logstash has only single pipeline which takes JDBC input from Oracle Database and indexes the records into Elasticsearch 7.17 (running on…

---

## [Filebeat cannot connect to kafka with SASL\_PLAINTEXT](https://discuss.elastic.co/t/filebeat-cannot-connect-to-kafka-with-sasl-plaintext/330501)

<div class="topic-metadata">

**Author:** [@sankooc](https://discuss.elastic.co/u/sankooc)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 8:32am UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-to-kafka-with-sasl-plaintext/330501 "2023-04-21T08:32:03Z")

</div>

Hi the problem occurs when collect data from kafka then send to logstash. the filebeat failed to connect kafka kafka version: 2.5.1 filebeat version: 8.6.2 kafka server config security.inter.broker.protocol=SASL\_PL…

---

## [Logstash timestamp shift](https://discuss.elastic.co/t/logstash-timestamp-shift/330397)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 7\
**Last updated:** [April 21, 2023, 7:51am UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397 "2023-04-21T07:51:56Z")

</div>

Hi ! I came across a strange behavior while parsing a timestamp epoch style date { match =\> \[ "eventtime\_ms","UNIX" \] target =\> "\[event\]\[created\]" timezone =\> "Etc/GMT+2" } date { match…

---

## [Can't reindex: Error extracting routing: Routing values must be strings](https://discuss.elastic.co/t/cant-reindex-error-extracting-routing-routing-values-must-be-strings/330479)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 8:09am UTC](https://discuss.elastic.co/t/cant-reindex-error-extracting-routing-routing-values-must-be-strings/330479 "2023-04-21T08:09:37Z")

</div>

Hi I can't reindex, I get this error "failures": \[ { "index": "metricbeat-000003", "cause": { "type": "illegal\_argument\_exception", "reason": "Error extracting routing: Routing values …

---

## [Write the same data to two S3 repositories?](https://discuss.elastic.co/t/write-the-same-data-to-two-s3-repositories/330306)

<div class="topic-metadata">

**Author:** [@jeod](https://discuss.elastic.co/u/jeod)\
**Replies:** 4\
**Last updated:** [April 21, 2023, 8:00am UTC](https://discuss.elastic.co/t/write-the-same-data-to-two-s3-repositories/330306 "2023-04-21T08:00:39Z")

</div>

Hi Guys, Is it possible to create 2 x S3 repositories, and join or link both repositories as my frozen tier?. We have two local 2 DCs with S3 object storage in each DC. - So I would like to have my frozen-tier represen…

---

## [Reduce Dashboard Loading Time](https://discuss.elastic.co/t/reduce-dashboard-loading-time/330491)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 2\
**Last updated:** [April 21, 2023, 7:22am UTC](https://discuss.elastic.co/t/reduce-dashboard-loading-time/330491 "2023-04-21T07:22:04Z")

</div>

I have a kibana dashboard which contains 7 vega lite visualisations & 2 kibana lens visualisations. Version used: 8.6.2 The dashboard takes around 13-14 sec to load. Most of the time is spent in loading Kibana. HOW TO …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=562)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=564)
