# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=601

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 602

---

## [Winlogbeat.yml path.data and path.logs not working](https://discuss.elastic.co/t/winlogbeat-yml-path-data-and-path-logs-not-working/327882)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 3\
**Last updated:** [March 18, 2023, 9:44pm UTC](https://discuss.elastic.co/t/winlogbeat-yml-path-data-and-path-logs-not-working/327882 "2023-03-18T21:44:59Z")

</div>

Hi, I am trying to change where my logs and data are stored. In my winlogbeat service properties i see this : ""D:\\vm workstation\\winlogbeat\\winlogbeat.exe" --environment=windows\_service -c "D:\\vm workstation\\winlogbeat…

---

## [No config files found in path](https://discuss.elastic.co/t/no-config-files-found-in-path/327879)

<div class="topic-metadata">

**Author:** [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Replies:** 16\
**Last updated:** [March 18, 2023, 6:56pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879 "2023-03-18T18:56:27Z")

</div>

Hello everyone I am new with Logstash and i trying to start Logstash 8.6.2 on a Windows Server 2019 Server to forward syslogs from a Firewall to Wazuh. When I try to run as administrator in PS the command C:\\logstash-8…

---

## [Drop docs that meet certain Grok pattern](https://discuss.elastic.co/t/drop-docs-that-meet-certain-grok-pattern/327889)

<div class="topic-metadata">

**Author:** [@demonsquatch](https://discuss.elastic.co/u/demonsquatch)\
**Replies:** 6\
**Last updated:** [March 18, 2023, 6:41pm UTC](https://discuss.elastic.co/t/drop-docs-that-meet-certain-grok-pattern/327889 "2023-03-18T18:41:25Z")

</div>

Hi all, Currently looking to drop any documents that meet a certain Grok pattern, but am not having much luck on finding anything. In this scenario, I would like do drop anything that matches the pattern of EVENT1 in th…

---

## [Error when creating Index Template: composable template \[ \] template after composition is invalid](https://discuss.elastic.co/t/error-when-creating-index-template-composable-template-template-after-composition-is-invalid/327948)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 4\
**Last updated:** [March 18, 2023, 5:59pm UTC](https://discuss.elastic.co/t/error-when-creating-index-template-composable-template-template-after-composition-is-invalid/327948 "2023-03-18T17:59:31Z")

</div>

When creating an Index Template, I get this error: Error when creating Template: composable template template after composition is invalid I observe that: This error occurs only when I use the normal index template.…

---

## [Elastic agent install error: already installed at: /opt/Elastic/Agent](https://discuss.elastic.co/t/elastic-agent-install-error-already-installed-at-opt-elastic-agent/327926)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 4\
**Last updated:** [March 18, 2023, 4:32pm UTC](https://discuss.elastic.co/t/elastic-agent-install-error-already-installed-at-opt-elastic-agent/327926 "2023-03-18T16:32:36Z")

</div>

Hello, I'm trying to enroll an agent on a healthy fleet server which is also an agent (what i've understood). I'm following the step by step guide from kibana interface in integration panel (see the image below) I'…

---

## [Field\_value\_factor use max of score](https://discuss.elastic.co/t/field-value-factor-use-max-of-score/327971)

<div class="topic-metadata">

**Author:** [@Alexander\_Engel](https://discuss.elastic.co/u/Alexander_Engel)\
**Replies:** 3\
**Last updated:** [March 18, 2023, 3:31pm UTC](https://discuss.elastic.co/t/field-value-factor-use-max-of-score/327971 "2023-03-18T15:31:09Z")

</div>

I have the following query: { "query": { "function\_score": { "boost\_mode": "multiply", "functions": \[ { "field\_value\_factor": { "factor": 0.5, "field": "albums…

---

## [Threat intel Filebeat module - I don't get any data From MISP and i don't know why](https://discuss.elastic.co/t/threat-intel-filebeat-module-i-dont-get-any-data-from-misp-and-i-dont-know-why/327986)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 0\
**Last updated:** [March 18, 2023, 8:48am UTC](https://discuss.elastic.co/t/threat-intel-filebeat-module-i-dont-get-any-data-from-misp-and-i-dont-know-why/327986 "2023-03-18T08:48:39Z")

</div>

Hello, I'm trying to integrate MISP IOC's into Kibana via Threat intel Filebeat Module. When i look at the analytics dicover view in kibana, i see every var.interval (set in the module config) a new hit with an event.o…

---

## [Policy inheritance](https://discuss.elastic.co/t/policy-inheritance/326223)

<div class="topic-metadata">

**Author:** [@indyg](https://discuss.elastic.co/u/indyg)\
**Replies:** 5\
**Last updated:** [March 18, 2023, 12:39pm UTC](https://discuss.elastic.co/t/policy-inheritance/326223 "2023-03-18T12:39:07Z")

</div>

As we're rolling out Fleet to our servers, one question I had around agent policies used by the agents was if it's possible for a policy to inherit the integrations of another like a parent-child relationship? For examp…

---

## [Logstash filter: a field pointing to many format of the same field](https://discuss.elastic.co/t/logstash-filter-a-field-pointing-to-many-format-of-the-same-field/327918)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 3\
**Last updated:** [March 18, 2023, 10:51am UTC](https://discuss.elastic.co/t/logstash-filter-a-field-pointing-to-many-format-of-the-same-field/327918 "2023-03-18T10:51:33Z")

</div>

I have a lot of logs and I want to search through these log lines a callID flow and visualize everything related to that callID into kibana with logstash I made a filter that detects an hexadecimal format for that CallI…

---

## [Logtrail: problem using via reverse proxy](https://discuss.elastic.co/t/logtrail-problem-using-via-reverse-proxy/327951)

<div class="topic-metadata">

**Author:** [@freeman999](https://discuss.elastic.co/u/freeman999)\
**Replies:** 1\
**Last updated:** [March 18, 2023, 9:48am UTC](https://discuss.elastic.co/t/logtrail-problem-using-via-reverse-proxy/327951 "2023-03-18T09:48:21Z")

</div>

Hello everyone: my logtrail plugin doesn't work via reverse proxy nginx. I have the following picture when I try to get logtrail page using domain name https://kibana.domain.com/app/logtrail and I have a working log…

---

## [Elasticsearch 7.16.2 not getting started after upgrading Log4j to 2.20 version](https://discuss.elastic.co/t/elasticsearch-7-16-2-not-getting-started-after-upgrading-log4j-to-2-20-version/327799)

<div class="topic-metadata">

**Author:** [@kgpbharathi](https://discuss.elastic.co/u/kgpbharathi)\
**Replies:** 5\
**Last updated:** [March 17, 2023, 11:50pm UTC](https://discuss.elastic.co/t/elasticsearch-7-16-2-not-getting-started-after-upgrading-log4j-to-2-20-version/327799 "2023-03-17T23:50:25Z")

</div>

We are using elasticsearch with version": { "number": "7.16.2","build\_type": "rpm","lucene\_version": "8.10.1" } We have upgraded elasticsearch log4j files from 2.17 to 2.20 and elasticsearch is failing to start . Once…

---

## [Simple example for using curl to log a message to Logstash using the HTTP input plugin?](https://discuss.elastic.co/t/simple-example-for-using-curl-to-log-a-message-to-logstash-using-the-http-input-plugin/327964)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 1\
**Last updated:** [March 17, 2023, 11:03pm UTC](https://discuss.elastic.co/t/simple-example-for-using-curl-to-log-a-message-to-logstash-using-the-http-input-plugin/327964 "2023-03-17T23:03:39Z")

</div>

I am trying to use curl to to log something, just something, to an index, any index, on a ELK 8.4.1 cluster. On my Logstash node I have the following as part of the configuration in the conf.d directory: input { beat…

---

## [Not being able to set the Kibana password via REST API](https://discuss.elastic.co/t/not-being-able-to-set-the-kibana-password-via-rest-api/327749)

<div class="topic-metadata">

**Author:** [@NebulaLukas](https://discuss.elastic.co/u/NebulaLukas)\
**Replies:** 1\
**Last updated:** [March 17, 2023, 7:41pm UTC](https://discuss.elastic.co/t/not-being-able-to-set-the-kibana-password-via-rest-api/327749 "2023-03-17T19:41:23Z")

</div>

I am using the following docker-compose file that is based on the documentation, but the Kibana password does not seem to be applied since the setup hangs on Setting kibana\_system password and in the Kibana logs I see th…

---

## [Telnet - which IP address do i try to telnet to?](https://discuss.elastic.co/t/telnet-which-ip-address-do-i-try-to-telnet-to/327885)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 2\
**Last updated:** [March 17, 2023, 7:33pm UTC](https://discuss.elastic.co/t/telnet-which-ip-address-do-i-try-to-telnet-to/327885 "2023-03-17T19:33:28Z")

</div>

Hi, I get this message in my winlogbeat logs : {"file.name":"beater/winlogbeat.go","file.line":149},"message":"Winlogbeat is unable to load the ingest pipelines because the Elasticsearch output is not configured/enabled…

---

## [Provide elastic password on debian installation](https://discuss.elastic.co/t/provide-elastic-password-on-debian-installation/327953)

<div class="topic-metadata">

**Author:** [@divadpoc](https://discuss.elastic.co/u/divadpoc)\
**Replies:** 1\
**Last updated:** [March 17, 2023, 7:30pm UTC](https://discuss.elastic.co/t/provide-elastic-password-on-debian-installation/327953 "2023-03-17T19:30:59Z")

</div>

Hi, is it possible to provide the ELASTIC\_PASSWORD during startup so there's no auto-generated password? I see it's done w/ your provided compose examples, but can't find any information on bare-metal installations. Th…

---

## [What is the difference between xpack.security.http.ssl.verification\_mode and xpack.http.ssl.verification\_mode](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326537)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 11\
**Last updated:** [March 17, 2023, 6:59pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326537 "2023-03-17T18:59:40Z")

</div>

I want to know what is the difference between xpack.security.http.ssl.verification\_mode: certificate and xpack.http.ssl.verification\_mode: certificate Also, can I use both setting at same time...? Thank you..! Hiruni

---

## [Question about Opaque ID in index requests and Opaque ID restrictions/limitations](https://discuss.elastic.co/t/question-about-opaque-id-in-index-requests-and-opaque-id-restrictions-limitations/327963)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 6:22pm UTC](https://discuss.elastic.co/t/question-about-opaque-id-in-index-requests-and-opaque-id-restrictions-limitations/327963 "2023-03-17T18:22:07Z")

</div>

Hello Team, We are currently adding Opaque ID to our Elasticsearch calls to improve traceability in our system. We have also enabled slow logs for both indexing and searching, where Opaque ID is very helpful. So far, I…

---

## [Filebeat failed to start v7.10.2](https://discuss.elastic.co/t/filebeat-failed-to-start-v7-10-2/327957)

<div class="topic-metadata">

**Author:** [@Joshua\_John\_Consulta](https://discuss.elastic.co/u/Joshua_John_Consulta)\
**Replies:** 1\
**Last updated:** [March 17, 2023, 5:57pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-start-v7-10-2/327957 "2023-03-17T17:57:50Z")

</div>

Hi please help me with my problem. My filebeat services stop working. Even though after I restart it. It starts but after a minute it stopped. Please help me. My career depends on it Filbeat status: filebeat.service - …

---

## [Version\_conflict when trying to delete documents using \_delete\_by\_query API](https://discuss.elastic.co/t/version-conflict-when-trying-to-delete-documents-using-delete-by-query-api/327954)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 3:58pm UTC](https://discuss.elastic.co/t/version-conflict-when-trying-to-delete-documents-using-delete-by-query-api/327954 "2023-03-17T15:58:41Z")

</div>

Hello, I'm using Elasticsearch 8.6. I loaded many documents to an index day by day. I made a mistake when uploading the data for one day, so I want to delete all data from that specific day and load the correct informat…

---

## [Multiline and flush pattern issue](https://discuss.elastic.co/t/multiline-and-flush-pattern-issue/327958)

<div class="topic-metadata">

**Author:** [@vipkabra](https://discuss.elastic.co/u/vipkabra)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 5:09pm UTC](https://discuss.elastic.co/t/multiline-and-flush-pattern-issue/327958 "2023-03-17T17:09:48Z")

</div>

Hi All, I have a requirement to pick log lines from log based on some start word, lets assume 'ABC' and combine all following lines until 'XYZ' appears in log file. If XYZ found, combine all log lines and ship them to l…

---

## [Logstash on Windows](https://discuss.elastic.co/t/logstash-on-windows/327906)

<div class="topic-metadata">

**Author:** [@Rakesh\_Mukherjee](https://discuss.elastic.co/u/Rakesh_Mukherjee)\
**Replies:** 1\
**Last updated:** [March 17, 2023, 4:49pm UTC](https://discuss.elastic.co/t/logstash-on-windows/327906 "2023-03-17T16:49:15Z")

</div>

I installed Logstash on Windows and find that my output plugin showing error, please help, the error message is here, Unable to configure plugins: (pluginloading error) couldn't find any output plugin named 'microsoft-se…

---

## [Elasticsearch search response pick(latency) occurs when \_refresh with G1GC](https://discuss.elastic.co/t/elasticsearch-search-response-pick-latency-occurs-when-refresh-with-g1gc/327612)

<div class="topic-metadata">

**Author:** [@doyle.min](https://discuss.elastic.co/u/doyle.min)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 3:18pm UTC](https://discuss.elastic.co/t/elasticsearch-search-response-pick-latency-occurs-when-refresh-with-g1gc/327612 "2023-03-17T15:18:03Z")

</div>

hello. Our elasticsearch cluster has 3 master nodes and 12 data nodes installed on 2 IDCs. In front of elasticsearch, there is search api server that multisearches three indexes. It shows an average response time of le…

---

## [Change the cloud provider of deployment in a elasticsearch](https://discuss.elastic.co/t/change-the-cloud-provider-of-deployment-in-a-elasticsearch/327784)

<div class="topic-metadata">

**Author:** [@Eduardo\_Maia](https://discuss.elastic.co/u/Eduardo_Maia)\
**Replies:** 2\
**Last updated:** [March 17, 2023, 3:25pm UTC](https://discuss.elastic.co/t/change-the-cloud-provider-of-deployment-in-a-elasticsearch/327784 "2023-03-17T15:25:07Z")

</div>

Hi, my deployment have only one provider cloud, this provider cloud is Azure, but i need to change this for Google. how can i do it?

---

## [Kibana, Winlogbeat Agent-search with custom variable](https://discuss.elastic.co/t/kibana-winlogbeat-agent-search-with-custom-variable/327102)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 5\
**Last updated:** [March 17, 2023, 1:50pm UTC](https://discuss.elastic.co/t/kibana-winlogbeat-agent-search-with-custom-variable/327102 "2023-03-17T13:50:05Z")

</div>

Hi, I am new to the forum. For some time now, we have been unable to search with our custom variables for winlogbeat logs on only two servers. I have restarted the winlog agent service but the problem still persist. A…

---

## [Containerized Fleet Server failing](https://discuss.elastic.co/t/containerized-fleet-server-failing/327875)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 2\
**Last updated:** [March 17, 2023, 12:53pm UTC](https://discuss.elastic.co/t/containerized-fleet-server-failing/327875 "2023-03-17T12:53:03Z")

</div>

Hello. I am trying to run a containerized fleet server. I am running a docker container pulled using this command: docker pull docker.elastic.co/beats/elastic-agent:8.6.2 But when I run the container I get a number of …

---

## [Metricbeat Agent](https://discuss.elastic.co/t/metricbeat-agent/327798)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 2\
**Last updated:** [March 17, 2023, 12:45pm UTC](https://discuss.elastic.co/t/metricbeat-agent/327798 "2023-03-17T12:45:56Z")

</div>

Hi is it possible to pull all VMs on the server without installing metricbeat on all VMs? example: one server has 100+ VMs, and I want to monitor one server and include the VMs in it, without installing metricbeat on t…

---

## [Do we have any chance to do the custom changes in individual visuals in Kibana except CSS](https://discuss.elastic.co/t/do-we-have-any-chance-to-do-the-custom-changes-in-individual-visuals-in-kibana-except-css/326845)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 5\
**Last updated:** [March 17, 2023, 12:34pm UTC](https://discuss.elastic.co/t/do-we-have-any-chance-to-do-the-custom-changes-in-individual-visuals-in-kibana-except-css/326845 "2023-03-17T12:34:57Z")

</div>

Hi Team, Please help us to do the custom changes in individual visuals in Kibana except CSS. Thanks.

---

## [Rebalancing data between disks](https://discuss.elastic.co/t/rebalancing-data-between-disks/327927)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 12:13pm UTC](https://discuss.elastic.co/t/rebalancing-data-between-disks/327927 "2023-03-17T12:13:49Z")

</div>

Hi Can You give some tips how I can trigger rebalance for equal distribution of data depending on the size of the disk node shards disk.indices disk.used disk.avail disk.total disk.percent es\_data\_hdd\_1\_2 …

---

## [Logstash filter help pleas](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718)

<div class="topic-metadata">

**Author:** [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Replies:** 2\
**Last updated:** [March 17, 2023, 12:10pm UTC](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718 "2023-03-17T12:10:27Z")

</div>

Hi I'm in the process of trying to migrate my config from 6.7 to 8.x I have found I have to rewrite my logstash rules - okay probably a good time to do that. On that note - my filebeat 6.7 client worked fine, when i u…

---

## [Filebeat: Problem to get Domino HCL logs](https://discuss.elastic.co/t/filebeat-problem-to-get-domino-hcl-logs/327920)

<div class="topic-metadata">

**Author:** [@davidedavidedavide](https://discuss.elastic.co/u/davidedavidedavide)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 10:20am UTC](https://discuss.elastic.co/t/filebeat-problem-to-get-domino-hcl-logs/327920 "2023-03-17T10:20:46Z")

</div>

Hi, I'm trying to get logs from a Domino HCL mail server but no data are coming and in the filebeat log i see that the file is inactive It's a single file with overwriting when it reaches the max dimension. i'm trying …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=600)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=602)
