# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=588

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 589

---

## [Winlogbeat is not Connecting to Logstash Which is not connecting to Elasticsearch](https://discuss.elastic.co/t/winlogbeat-is-not-connecting-to-logstash-which-is-not-connecting-to-elasticsearch/328713)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 7\
**Last updated:** [March 29, 2023, 9:55am UTC](https://discuss.elastic.co/t/winlogbeat-is-not-connecting-to-logstash-which-is-not-connecting-to-elasticsearch/328713 "2023-03-29T09:55:55Z")

</div>

I have a small lab that consists of 2 ES nodes with basic security enabled using a TLS certificate, Kibana, Logstash, and a Windows 10 machine. The thing is that i'm not able to connect winbeat to logstash. Logstash Err…

---

## [How to monitor Publish and Delivery Rate of messages in RabbitMQ Queues using Metricbeat?](https://discuss.elastic.co/t/how-to-monitor-publish-and-delivery-rate-of-messages-in-rabbitmq-queues-using-metricbeat/328354)

<div class="topic-metadata">

**Author:** [@Karan\_Vyas](https://discuss.elastic.co/u/Karan_Vyas)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 9:40am UTC](https://discuss.elastic.co/t/how-to-monitor-publish-and-delivery-rate-of-messages-in-rabbitmq-queues-using-metricbeat/328354 "2023-03-29T09:40:28Z")

</div>

I am trying to monitor the publish and delivery rate of messages in RabbitMQ using Metricbeat, but I can't find any Metricbeat field that provides these metrics. I have already configured Metricbeat to monitor my Rabbit…

---

## [Issue for connection from proxy server to kibana](https://discuss.elastic.co/t/issue-for-connection-from-proxy-server-to-kibana/328783)

<div class="topic-metadata">

**Author:** [@minkiyo](https://discuss.elastic.co/u/minkiyo)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 9:10am UTC](https://discuss.elastic.co/t/issue-for-connection-from-proxy-server-to-kibana/328783 "2023-03-29T09:10:25Z")

</div>

Hello Nowadays, I am building proxy server in front of Elastic cluster(k List item ibana). Broswer --\> new proxy server (nginx --\> express) --\> Elastic cluster(kibana). All the Kibana url will be passing in new pr…

---

## [Elasticsearch for Windows 10 - arrghh](https://discuss.elastic.co/t/elasticsearch-for-windows-10-arrghh/328629)

<div class="topic-metadata">

**Author:** [@AndyJay1](https://discuss.elastic.co/u/AndyJay1)\
**Replies:** 3\
**Last updated:** [March 29, 2023, 9:10am UTC](https://discuss.elastic.co/t/elasticsearch-for-windows-10-arrghh/328629 "2023-03-29T09:10:11Z")

</div>

Hi all. I'm trying to install (run) elasticsearch 8.6.2 on my local Windows 10 machine. I'm installing Magento 2.4.5 whcih requires elasticsearch. Starting elasticsearch.bat as the administrator (and a user) just won'…

---

## [CircuitBreakingException: \[parent\] Data too large IN ES 7.3.2](https://discuss.elastic.co/t/circuitbreakingexception-parent-data-too-large-in-es-7-3-2/328788)

<div class="topic-metadata">

**Author:** [@Rahul\_Sen](https://discuss.elastic.co/u/Rahul_Sen)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 9:01am UTC](https://discuss.elastic.co/t/circuitbreakingexception-parent-data-too-large-in-es-7-3-2/328788 "2023-03-29T09:01:59Z")

</div>

Hi, We recently started to get multiple shards failures in one of our Kibana dashboards, and on checking the response it was found that we getting CircuitBreakingException: \[parent\] Data too large, exact error is given …

---

## [How ssl handshake will be happening for logstash output syslog client and syslog server side](https://discuss.elastic.co/t/how-ssl-handshake-will-be-happening-for-logstash-output-syslog-client-and-syslog-server-side/328795)

<div class="topic-metadata">

**Author:** [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 8:50am UTC](https://discuss.elastic.co/t/how-ssl-handshake-will-be-happening-for-logstash-output-syslog-client-and-syslog-server-side/328795 "2023-03-29T08:50:20Z")

</div>

How should we configure Syslog ssl certiificate at logstash(client) and syslog server end. From document what I understood is we will be having ssl\_cacert , ssl\_cert, ssl\_key at client end that is logstash. How about Se…

---

## [Elasticsearch doesn't see data](https://discuss.elastic.co/t/elasticsearch-doesnt-see-data/328702)

<div class="topic-metadata">

**Author:** [@freeman999](https://discuss.elastic.co/u/freeman999)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 8:49am UTC](https://discuss.elastic.co/t/elasticsearch-doesnt-see-data/328702 "2023-03-29T08:49:44Z")

</div>

hello everyone, I have running elasticsearch in docker container. Data stores like: "Mounts": \[ { "Type": "bind", "Source": "/opt/elasticsearch/data", "Destin…

---

## [Does es node prioritize local shard for searching?](https://discuss.elastic.co/t/does-es-node-prioritize-local-shard-for-searching/328790)

<div class="topic-metadata">

**Author:** [@clp991666](https://discuss.elastic.co/u/clp991666)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 8:19am UTC](https://discuss.elastic.co/t/does-es-node-prioritize-local-shard-for-searching/328790 "2023-03-29T08:19:24Z")

</div>

Hi, I use es cluster to serve a small index (\<1G) for searching and aggregation and so only 1 shard is assigned and 1 replica. As 1 node does not able to serve all the request fast enough so the cluster scale to 10 node…

---

## [Cannot parse empty date](https://discuss.elastic.co/t/cannot-parse-empty-date/328687)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 7:25am UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/328687 "2023-03-29T07:25:25Z")

</div>

Hi there, i'm facing an issue about empty date field. so my data is ingested from csv file. and some row has a empty date field. i already made a condition like this but i keep getting error like this response=\>{"in…

---

## [\[newbie\] Going from Curator to ILM](https://discuss.elastic.co/t/newbie-going-from-curator-to-ilm/328595)

<div class="topic-metadata">

**Author:** [@jeroenp](https://discuss.elastic.co/u/jeroenp)\
**Replies:** 3\
**Last updated:** [March 29, 2023, 6:45am UTC](https://discuss.elastic.co/t/newbie-going-from-curator-to-ilm/328595 "2023-03-29T06:45:23Z")

</div>

Hi, I'm rather new with Elastic and one of the things on our to-do list is to configure ILM on our ELK stack and stop the use of Curator. I've read some stuff about and watched howto's on using ILM, but are there any c…

---

## ["ORA-00942: table or view does not exist" for Oracle Metrics in Elastic Agent](https://discuss.elastic.co/t/ora-00942-table-or-view-does-not-exist-for-oracle-metrics-in-elastic-agent/328571)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 3\
**Last updated:** [March 29, 2023, 5:29am UTC](https://discuss.elastic.co/t/ora-00942-table-or-view-does-not-exist-for-oracle-metrics-in-elastic-agent/328571 "2023-03-29T05:29:29Z")

</div>

Hello all, I am using the Elastic Agent with the Oracle integration to monitor the metrics of our Oracle DB. In the logs I find the error Error fetching data for metricset sql.query: fetch variable mode failed: dpiStmt\_…

---

## [How to set a hyperlink in markdown field](https://discuss.elastic.co/t/how-to-set-a-hyperlink-in-markdown-field/328701)

<div class="topic-metadata">

**Author:** [@terrymu](https://discuss.elastic.co/u/terrymu)\
**Replies:** 3\
**Last updated:** [March 29, 2023, 5:15am UTC](https://discuss.elastic.co/t/how-to-set-a-hyperlink-in-markdown-field/328701 "2023-03-29T05:15:22Z")

</div>

Hi experts, I have set a hyperlink in markdown field from kibana GUI. Like below: test please check result2 \*\*\[baidu\](http://www.baidu.com)\*\* And the layout shows as below: But the link of jumped result is: htt…

---

## [Node enrollment token TTL?](https://discuss.elastic.co/t/node-enrollment-token-ttl/328762)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 3:11am UTC](https://discuss.elastic.co/t/node-enrollment-token-ttl/328762 "2023-03-29T03:11:28Z")

</div>

Is there a time-to-live/expiration date for node enrollment tokens? If so, what is it?

---

## [ELK - 8.6 (Filebeat to logstash) - only write ops with an op\_type of create are allowed in data streams](https://discuss.elastic.co/t/elk-8-6-filebeat-to-logstash-only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/328401)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 12\
**Last updated:** [March 29, 2023, 1:54am UTC](https://discuss.elastic.co/t/elk-8-6-filebeat-to-logstash-only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/328401 "2023-03-29T01:54:53Z")

</div>

Hello everyone: I got 2 physical server - one got elastic and 2nd one got Logstash & Kibana. I got filebeat running on our customer server from where I am harvesting data from the application log. Below is the error w…

---

## [Harvester stats always 0, no harvester logs at all but logs shipping](https://discuss.elastic.co/t/harvester-stats-always-0-no-harvester-logs-at-all-but-logs-shipping/328204)

<div class="topic-metadata">

**Author:** [@Alex\_Stuck](https://discuss.elastic.co/u/Alex_Stuck)\
**Replies:** 29\
**Last updated:** [March 29, 2023, 2:06am UTC](https://discuss.elastic.co/t/harvester-stats-always-0-no-harvester-logs-at-all-but-logs-shipping/328204 "2023-03-29T02:06:22Z")

</div>

Hey there, new to filebeats. I'm watching a large directory at the root (/log/\*/\*\*) and am sending the logs to another team's LS that I don't control. We are seeing what looks like a major lag at time from some systems …

---

## [Match with type phrase\_prefix doesn't work when words mix numbers and letters](https://discuss.elastic.co/t/match-with-type-phrase-prefix-doesnt-work-when-words-mix-numbers-and-letters/328743)

<div class="topic-metadata">

**Author:** [@Raphael\_Fidelis](https://discuss.elastic.co/u/Raphael_Fidelis)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 10:44pm UTC](https://discuss.elastic.co/t/match-with-type-phrase-prefix-doesnt-work-when-words-mix-numbers-and-letters/328743 "2023-03-28T22:44:17Z")

</div>

I'm trying to query as such: { "match": { "query": "100", "fields": "description", "type": "phrase\_prefix" } } However, if I search for "100" wanting to find, for example, a document with the "d…

---

## [Logstash runs but shows no output on server](https://discuss.elastic.co/t/logstash-runs-but-shows-no-output-on-server/328754)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 9:50pm UTC](https://discuss.elastic.co/t/logstash-runs-but-shows-no-output-on-server/328754 "2023-03-28T21:50:46Z")

</div>

I'm new to the Elastic Stack. I have a logstash config which parses and filters csv files and it looks like this: input { file { path =\> "/path/to/file" start\_position =\> "beginning" sincedb\_path =\>…

---

## [Upgrade assistant](https://discuss.elastic.co/t/upgrade-assistant/328740)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 6:44pm UTC](https://discuss.elastic.co/t/upgrade-assistant/328740 "2023-03-28T18:44:21Z")

</div>

I have 8.5 and can't find upgrade assistant? where did it moved? I am logged in as user elastic

---

## [Document-level security on eleastic vs solr](https://discuss.elastic.co/t/document-level-security-on-eleastic-vs-solr/328488)

<div class="topic-metadata">

**Author:** [@SandraIsCool](https://discuss.elastic.co/u/SandraIsCool)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 6:32pm UTC](https://discuss.elastic.co/t/document-level-security-on-eleastic-vs-solr/328488 "2023-03-28T18:32:54Z")

</div>

We are using Solr now but perhaps elastic is a better choice for us. Looking to see if it makes sense to switch: Scenario I am working on a Customer Service Ticketing solution where we need to search ticket metadata, n…

---

## [Ctx.trigger.triggered\_time math and formatting](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501)

<div class="topic-metadata">

**Author:** [@ffmdsuperit](https://discuss.elastic.co/u/ffmdsuperit)\
**Replies:** 7\
**Last updated:** [March 28, 2023, 6:24pm UTC](https://discuss.elastic.co/t/ctx-trigger-triggered-time-math-and-formatting/328501 "2023-03-28T18:24:59Z")

</div>

I have a Watcher that filters on a timestamp range. I'd like to capture the searched timestamp range by saving something like "Start": "ctx.trigger.triggered\_time - 23m" and "End": "ctx.trigger.triggered\_time - 22m" into…

---

## [Exaggerated consumption of ES instance](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616)

<div class="topic-metadata">

**Author:** [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Replies:** 9\
**Last updated:** [March 28, 2023, 5:09pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616 "2023-03-28T17:09:54Z")

</div>

Hello! I have an Elastic cloud cluster where I have 2 instances. Each instance is 120GB in size and works as replicas in different Availability Zones for redundancy. Something strange happened that I can't understand w…

---

## [No MySQL Enterprise module available](https://discuss.elastic.co/t/no-mysql-enterprise-module-available/328159)

<div class="topic-metadata">

**Author:** [@Samuel\_Ruiz](https://discuss.elastic.co/u/Samuel_Ruiz)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 3:48pm UTC](https://discuss.elastic.co/t/no-mysql-enterprise-module-available/328159 "2023-03-28T15:48:49Z")

</div>

In my filebeat module directory (/usr/share/filebeat/module) there is no mysqlenterprise directory with the configuration of the mysqlenterprise module. Where can i find this conf?

---

## [Fleet managed elastic agent](https://discuss.elastic.co/t/fleet-managed-elastic-agent/328454)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 3:37pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent/328454 "2023-03-28T15:37:33Z")

</div>

Hi Team, I want to gather some information regarding fleet. when fleet uses metricbeat to collect the data, is it possible to modify the configuration of metricbeat? //Ankita

---

## [Lack of proper SSL credentials is crashing logstash](https://discuss.elastic.co/t/lack-of-proper-ssl-credentials-is-crashing-logstash/328728)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 3:30pm UTC](https://discuss.elastic.co/t/lack-of-proper-ssl-credentials-is-crashing-logstash/328728 "2023-03-28T15:30:25Z")

</div>

Is it possible to handle SSL exceptions gracefully in Logstash and prevent it from crashing out? At the moment I have SSL enabled on Filebeat side of things, as well as in Logstash. Everything is working fine if these SS…

---

## [Create links to each log](https://discuss.elastic.co/t/create-links-to-each-log/328626)

<div class="topic-metadata">

**Author:** [@bekk777](https://discuss.elastic.co/u/bekk777)\
**Replies:** 6\
**Last updated:** [March 28, 2023, 3:10pm UTC](https://discuss.elastic.co/t/create-links-to-each-log/328626 "2023-03-28T15:10:48Z")

</div>

Hi, I have been struggling with this issue for many days. I ask you to help. How to create your own links for each log, let's say, through \_doc \_id. Since each \_doc has a unique \_id, right? Is it possible to generate li…

---

## [Set Field Value in Painless Script by Field Name as String](https://discuss.elastic.co/t/set-field-value-in-painless-script-by-field-name-as-string/328719)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 2:25pm UTC](https://discuss.elastic.co/t/set-field-value-in-painless-script-by-field-name-as-string/328719 "2023-03-28T14:25:23Z")

</div>

TL;DR I'm trying to pass in a nested key to a Painless script as a string and set that key from the script, but it's not working. How do I do this?# Use Case Long Version Use Case As a user, I need to perform the same t…

---

## [Windows servers in observavility/metrics/inventory?](https://discuss.elastic.co/t/windows-servers-in-observavility-metrics-inventory/328717)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 2:16pm UTC](https://discuss.elastic.co/t/windows-servers-in-observavility-metrics-inventory/328717 "2023-03-28T14:16:51Z")

</div>

Which metricset is needed to see windows servers in observavility/metrics/inventory?

---

## [Distributing load test driver, docker container limitation](https://discuss.elastic.co/t/distributing-load-test-driver-docker-container-limitation/328484)

<div class="topic-metadata">

**Author:** [@Rich2023](https://discuss.elastic.co/u/Rich2023)\
**Replies:** 4\
**Last updated:** [March 28, 2023, 2:13pm UTC](https://discuss.elastic.co/t/distributing-load-test-driver-docker-container-limitation/328484 "2023-03-28T14:13:11Z")

</div>

Preamble that I'm relatively new to Elasticsearch, load testing, and by no means a cloud infrastructure expert... I've had success with esrally and creating a new track to test a custom search query load, both against a…

---

## [Elasticsearch JMX Error](https://discuss.elastic.co/t/elasticsearch-jmx-error/328651)

<div class="topic-metadata">

**Author:** [@abrooky](https://discuss.elastic.co/u/abrooky)\
**Replies:** 4\
**Last updated:** [March 28, 2023, 2:12pm UTC](https://discuss.elastic.co/t/elasticsearch-jmx-error/328651 "2023-03-28T14:12:05Z")

</div>

On CentOS 7 I get this error with most Elasticsearch commands; Does anyone know how I can reslove it? I've spent ages on Google. TIA. :slight\_smile: # bin/elasticsearch-create-enrollment-token -s kibana 2023-03-27 21:0…

---

## [Newbie help \> report of values diff'ed over time](https://discuss.elastic.co/t/newbie-help-report-of-values-diffed-over-time/328492)

<div class="topic-metadata">

**Author:** [@robyb](https://discuss.elastic.co/u/robyb)\
**Replies:** 7\
**Last updated:** [March 28, 2023, 1:39pm UTC](https://discuss.elastic.co/t/newbie-help-report-of-values-diffed-over-time/328492 "2023-03-28T13:39:22Z")

</div>

Can I start my first post with an intro. I'm a Product Manager, so speak to me like I'm not an engineer... :slight\_smile: I have the following dataset. A list of Microsoft license types and a count of number of users …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=587)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=589)
