# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=648

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 649

---

## [Java heap oom on logstash](https://discuss.elastic.co/t/java-heap-oom-on-logstash/324426)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 1:21pm UTC](https://discuss.elastic.co/t/java-heap-oom-on-logstash/324426 "2023-02-01T13:21:03Z")

</div>

Hi I'm using the latest one version of logstash 8.6.0 I meet the same processing error every day for one of pipeline in the meantime I decreased of count of workers and event and increased heap but still is not enough …

---

## [Passing dotnet APM Agent settings in Docker And Kubernetes](https://discuss.elastic.co/t/passing-dotnet-apm-agent-settings-in-docker-and-kubernetes/324427)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 1:03pm UTC](https://discuss.elastic.co/t/passing-dotnet-apm-agent-settings-in-docker-and-kubernetes/324427 "2023-02-01T13:03:08Z")

</div>

Hello I am trying to enable elastic APM with asp dotnet application but not able to find any reference document which says it is possible to enable apm & rum for containerized asp dotnet application Kindly suggest if i…

---

## [Use existing ElasticSearch tar while running integration/functional tests](https://discuss.elastic.co/t/use-existing-elasticsearch-tar-while-running-integration-functional-tests/324425)

<div class="topic-metadata">

**Author:** [@NamB](https://discuss.elastic.co/u/NamB)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 12:48pm UTC](https://discuss.elastic.co/t/use-existing-elasticsearch-tar-while-running-integration-functional-tests/324425 "2023-02-01T12:48:59Z")

</div>

While running Kibana integration tests, could see that a daily Elasticsearch snapshot is downloaded and started. Is there some way to avoid this download and use locally built Elasticsearch file?

---

## [Logtash copy one field to another in a different log](https://discuss.elastic.co/t/logtash-copy-one-field-to-another-in-a-different-log/324423)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logtash-copy-one-field-to-another-in-a-different-log/324423 "2023-02-01T12:39:45Z")

</div>

Hello, I have the following sample log. Feb 1 15:30:49 sudo: pam\_unix(sudo-i:auth): authentication failure; logname= uid=10050 euid=0 tty=/dev/pts/2 user=test Feb 1 15:30:50 sudo: pam\_sss(sudo-i:auth): authent…

---

## [Read Oracle Database Table Data vi Logstash to insert into ElasticSearch](https://discuss.elastic.co/t/read-oracle-database-table-data-vi-logstash-to-insert-into-elasticsearch/323717)

<div class="topic-metadata">

**Author:** [@SP003](https://discuss.elastic.co/u/SP003)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 11:32am UTC](https://discuss.elastic.co/t/read-oracle-database-table-data-vi-logstash-to-insert-into-elasticsearch/323717 "2023-02-01T11:32:17Z")

</div>

Dear all, I am trying to connect with table from Oracle Database, and read records through logstash, and then to insert into Elastic search. And the same I want to do in a Linux system. So far I understood that I have …

---

## [Shared solution with SQL Server](https://discuss.elastic.co/t/shared-solution-with-sql-server/324416)

<div class="topic-metadata">

**Author:** [@Chen\_Shacham](https://discuss.elastic.co/u/Chen_Shacham)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 11:27am UTC](https://discuss.elastic.co/t/shared-solution-with-sql-server/324416 "2023-02-01T11:27:54Z")

</div>

hello. I am trying to connect ELK search with my existing SQL Server ecosystem. I have created a CLR that calls Elastic index with search parameters (using native POST request) and then convert (deseriale) the results…

---

## [Error on running Elasticsearch from the command line](https://discuss.elastic.co/t/error-on-running-elasticsearch-from-the-command-line/324305)

<div class="topic-metadata">

**Author:** [@umairsaeed](https://discuss.elastic.co/u/umairsaeed)\
**Replies:** 9\
**Last updated:** [February 1, 2023, 11:09am UTC](https://discuss.elastic.co/t/error-on-running-elasticsearch-from-the-command-line/324305 "2023-02-01T11:09:12Z")

</div>

I downloaded, unzipped, and run Elasticsearch from the command line successfully. But after closing the command line, I am trying to run the Elasticsearch from the command line again, but it is giving me an error "localh…

---

## [How to change start of the week in date\_histogram based on 1w interval in group\_by transformof pivot](https://discuss.elastic.co/t/how-to-change-start-of-the-week-in-date-histogram-based-on-1w-interval-in-group-by-transformof-pivot/323675)

<div class="topic-metadata">

**Author:** [@sagarkhatri0605](https://discuss.elastic.co/u/sagarkhatri0605)\
**Replies:** 4\
**Last updated:** [February 1, 2023, 10:55am UTC](https://discuss.elastic.co/t/how-to-change-start-of-the-week-in-date-histogram-based-on-1w-interval-in-group-by-transformof-pivot/323675 "2023-02-01T10:55:09Z")

</div>

I am trying to create a transform with group\_by date\_histogram for interval of 1w (1 week), by default Elasticsearch considers week as Monday-Sunday and aggregates data accordingly, I want the week to start from Sunday i…

---

## [Can not install fleet server's elastic agent in Logstash server](https://discuss.elastic.co/t/can-not-install-fleet-servers-elastic-agent-in-logstash-server/324409)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 10:30am UTC](https://discuss.elastic.co/t/can-not-install-fleet-servers-elastic-agent-in-logstash-server/324409 "2023-02-01T10:30:51Z")

</div>

Hi, I am trying to install fleet server's elastic agent in logstash server, but once I installed it given following error. any support on this?

---

## [Search Match for all tokens from decompound filter](https://discuss.elastic.co/t/search-match-for-all-tokens-from-decompound-filter/322483)

<div class="topic-metadata">

**Author:** [@florin\_olah](https://discuss.elastic.co/u/florin_olah)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 10:03am UTC](https://discuss.elastic.co/t/search-match-for-all-tokens-from-decompound-filter/322483 "2023-02-01T10:03:47Z")

</div>

Hello, I am trying to do the same thing described in the topic here: German compound words in an e-commerce search simple example: searching for "sprachkurs" which is tokenized as "sprachkurs, sprach, kurs" Desired re…

---

## [Watcher Alert with multi match](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 10:03am UTC](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831 "2023-02-01T10:03:36Z")

</div>

Hi Team , I am New to community, I want to set up the watcher alert on the logs with messages like following "message: The user has selected account 84900-1 has no limit left" Where 84900 is account type and 1 is sub…

---

## [ElasticsearchException\[failed to bind service\]; nested: IndexFormatTooNewException\[Format version is not supported](https://discuss.elastic.co/t/elasticsearchexception-failed-to-bind-service-nested-indexformattoonewexception-format-version-is-not-supported/324353)

<div class="topic-metadata">

**Author:** [@Doums\_D](https://discuss.elastic.co/u/Doums_D)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 9:46am UTC](https://discuss.elastic.co/t/elasticsearchexception-failed-to-bind-service-nested-indexformattoonewexception-format-version-is-not-supported/324353 "2023-02-01T09:46:57Z")

</div>

Hello everyone, I have a issue on my elasticsearch server. i extended the storage from 1To to 2To and after rebooting i never could restart my elasticsearch service. Here is what i have actually in my journalctl when i…

---

## [Runtime field kibana](https://discuss.elastic.co/t/runtime-field-kibana/324362)

<div class="topic-metadata">

**Author:** [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 9:45am UTC](https://discuss.elastic.co/t/runtime-field-kibana/324362 "2023-02-01T09:45:55Z")

</div>

hi, i want make three new field that capture alert, source address and destination address from message field. anyone can help me how to do it. i have try using runtime field, but i cannot extract the value from the mes…

---

## [Organisation of the document to index in the java API with a nested field](https://discuss.elastic.co/t/organisation-of-the-document-to-index-in-the-java-api-with-a-nested-field/324400)

<div class="topic-metadata">

**Author:** [@QuentinV](https://discuss.elastic.co/u/QuentinV)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 9:22am UTC](https://discuss.elastic.co/t/organisation-of-the-document-to-index-in-the-java-api-with-a-nested-field/324400 "2023-02-01T09:22:00Z")

</div>

Hello. In my project, I success to connect, create and index documents to an elasticsearch with the new java API but I want to index a file with an nested field and I don't find any information about it. Can you explai…

---

## [Monitor systemd service from dockerized Metricbeat](https://discuss.elastic.co/t/monitor-systemd-service-from-dockerized-metricbeat/324395)

<div class="topic-metadata">

**Author:** [@Yungxin\_Shin](https://discuss.elastic.co/u/Yungxin_Shin)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 8:11am UTC](https://discuss.elastic.co/t/monitor-systemd-service-from-dockerized-metricbeat/324395 "2023-02-01T08:11:34Z")

</div>

I wonder if there's a way to stream the metrics (such as cpu, mem usage, diskio etc.) of systemd services to Elasticsearch through Metricbeat. To monitor the services running on the host, we could use the system module. …

---

## [Error on disable data\_detection](https://discuss.elastic.co/t/error-on-disable-data-detection/324265)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 7:44am UTC](https://discuss.elastic.co/t/error-on-disable-data-detection/324265 "2023-02-01T07:44:27Z")

</div>

I'm trying to disable data\_detection via curl. I delete the shard curl -s -H 'Content-Type: application/json' -X DELETE 'http://localhost:9200/video?pretty' { "acknowledged" : true } then curl -H 'Content-Type: ap…

---

## [Upgrade Elasticsearch to 7.17.8](https://discuss.elastic.co/t/upgrade-elasticsearch-to-7-17-8/324391)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 7:27am UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-to-7-17-8/324391 "2023-02-01T07:27:09Z")

</div>

I'm trying to upgrade my elasticsearch to version 7.17.8 from version 7.14.0. I have a single instant with kibana and logstash included. Current version has quiet a lot of data so it's hard to back it up. When I upgr…

---

## [Kibana control has white back ground](https://discuss.elastic.co/t/kibana-control-has-white-back-ground/323367)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 6:48am UTC](https://discuss.elastic.co/t/kibana-control-has-white-back-ground/323367 "2023-02-01T06:48:59Z")

</div>

Kibana 8.5.3 after upgrade I notice that background is white and hardly able to read on it. how do I fix it. whole dashbaord is in dark mode. it was working ok on 7.x version. this selection is old style control which…

---

## [Export of Users & Roles in Kibana as CSV](https://discuss.elastic.co/t/export-of-users-roles-in-kibana-as-csv/324196)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 3:25am UTC](https://discuss.elastic.co/t/export-of-users-roles-in-kibana-as-csv/324196 "2023-02-01T03:25:29Z")

</div>

Hi all, For my internal purposes, I want to export a CSV of all users , roles and their permissions. I know I can see them in Roles & Users, but want an export of CSV. I believe every user is created as seperate inde…

---

## [Azure Event Hub Explanation](https://discuss.elastic.co/t/azure-event-hub-explanation/324373)

<div class="topic-metadata">

**Author:** [@gabrieligbastos](https://discuss.elastic.co/u/gabrieligbastos)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 2:37am UTC](https://discuss.elastic.co/t/azure-event-hub-explanation/324373 "2023-02-01T02:37:23Z")

</div>

Hello, Im new to ELK Stack, and Im trying to increase observability with it. Im here have some doubts that I could not find a answer in other topics, probably because my problem is just too newbie! :slight\_smile: I dep…

---

## [Logstash occupies superior folder of log folder](https://discuss.elastic.co/t/logstash-occupies-superior-folder-of-log-folder/324379)

<div class="topic-metadata">

**Author:** [@Steven29](https://discuss.elastic.co/u/Steven29)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 2:27am UTC](https://discuss.elastic.co/t/logstash-occupies-superior-folder-of-log-folder/324379 "2023-02-01T02:27:12Z")

</div>

I assigned the path ' /AllLog/Logstash'. But sometimes when I start the logstash, log(log of logstash) is not stacked because the AllLog folder is full(capacity). But when I stop the logstash, the capacity of AllLog f…

---

## [Getting "event\_agent\_id\_status auth\_metadata\_missing" error while sending logs from standalone elasticagent](https://discuss.elastic.co/t/getting-event-agent-id-status-auth-metadata-missing-error-while-sending-logs-from-standalone-elasticagent/324378)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 2:06am UTC](https://discuss.elastic.co/t/getting-event-agent-id-status-auth-metadata-missing-error-while-sending-logs-from-standalone-elasticagent/324378 "2023-02-01T02:06:18Z")

</div>

I am trying to send the logs from my AKS cluster into Elasticsearch the log that I am getting is "event.agent\_id\_status auth\_metadata\_missing" in my kibana even after all the volume mounts are done correctly here's my …

---

## [Multiline Logstash that handles timestamp on each line](https://discuss.elastic.co/t/multiline-logstash-that-handles-timestamp-on-each-line/322556)

<div class="topic-metadata">

**Author:** [@Scotsie](https://discuss.elastic.co/u/Scotsie)\
**Replies:** 5\
**Last updated:** [January 31, 2023, 9:58pm UTC](https://discuss.elastic.co/t/multiline-logstash-that-handles-timestamp-on-each-line/322556 "2023-01-31T21:58:46Z")

</div>

I'm currently ingesting logs from multiple devices successfully, one document per row. One particular brand, Polycom, is sending a multiline entry that includes the timestamp for each row. Sample Logging (with normal an…

---

## [Convert NanoSecond Unix timestamp](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368)

<div class="topic-metadata">

**Author:** [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)\
**Replies:** 8\
**Last updated:** [January 31, 2023, 9:57pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368 "2023-01-31T21:57:29Z")

</div>

Hi Folks, Any idea how to convert the nanosecond unix timestamp in logstash filter? date { match =\> \[ "eventtime","UNIX\_MS", "ISO8601" \] target =\> "Epoch" timezone =\> "UT…

---

## [Line break in grok pattern](https://discuss.elastic.co/t/line-break-in-grok-pattern/324369)

<div class="topic-metadata">

**Author:** [@mariana17](https://discuss.elastic.co/u/mariana17)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 8:52pm UTC](https://discuss.elastic.co/t/line-break-in-grok-pattern/324369 "2023-01-31T20:52:38Z")

</div>

I am trying to get the data from a log, however in the middle of the log there is a line break which prevents the Grok filter from reading it correctly. If I adjust it to a single line it works, however, it would require…

---

## [Nginx Logs Can't Be Parsed Because Symlinks](https://discuss.elastic.co/t/nginx-logs-cant-be-parsed-because-symlinks/323958)

<div class="topic-metadata">

**Author:** [@Christian\_Jacobs](https://discuss.elastic.co/u/Christian_Jacobs)\
**Replies:** 7\
**Last updated:** [January 31, 2023, 8:42pm UTC](https://discuss.elastic.co/t/nginx-logs-cant-be-parsed-because-symlinks/323958 "2023-01-31T20:42:49Z")

</div>

Currently I have an nginx container that has filebeat running in the background. \[nginx:latest as base\] I have enabled the nginx module with filebeat modules enable nginx, my filebeat.yml has an input defined for the lo…

---

## [I have a problema with send data from filebeat to Logstash](https://discuss.elastic.co/t/i-have-a-problema-with-send-data-from-filebeat-to-logstash/324366)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 3\
**Last updated:** [January 31, 2023, 8:40pm UTC](https://discuss.elastic.co/t/i-have-a-problema-with-send-data-from-filebeat-to-logstash/324366 "2023-01-31T20:40:01Z")

</div>

Hello, can you help me pleae, I have a filebeat in my local computer and logstash in a VM Ubuntu in VirtualBox, so I check conectivity from my PC to remote server ubuntu with telnet 192.168.1.12 5044 and was successfull …

---

## [Twitter Input - Logstash filter mutate remove\_field - Elasticsearch](https://discuss.elastic.co/t/twitter-input-logstash-filter-mutate-remove-field-elasticsearch/324290)

<div class="topic-metadata">

**Author:** [@xalmer](https://discuss.elastic.co/u/xalmer)\
**Replies:** 10\
**Last updated:** [January 31, 2023, 8:38pm UTC](https://discuss.elastic.co/t/twitter-input-logstash-filter-mutate-remove-field-elasticsearch/324290 "2023-01-31T20:38:45Z")

</div>

Hello eveybody, Im trying to discover the fantastic world of possibilities of ELK. But i stop in a problem, and maybe someone can solve this "equation". Im using the Twitter Input Plugin to receive Twitter data, but i …

---

## [Logstash will not start with /tmp mounted noexec](https://discuss.elastic.co/t/logstash-will-not-start-with-tmp-mounted-noexec/324125)

<div class="topic-metadata">

**Author:** [@chuck1](https://discuss.elastic.co/u/chuck1)\
**Replies:** 6\
**Last updated:** [January 31, 2023, 7:39pm UTC](https://discuss.elastic.co/t/logstash-will-not-start-with-tmp-mounted-noexec/324125 "2023-01-31T19:39:53Z")

</div>

Logstash will not start with the /tmp directory mounted as noexec on RHEL 8.6. We fixed this with Elasticsearch. However, do not have the proper variables, guidance on how to fix this with Logstash. Thank You For Your …

---

## [Pending\_tasks has millions of entries, many of with are exact duplicates of ilm-move-to-step](https://discuss.elastic.co/t/pending-tasks-has-millions-of-entries-many-of-with-are-exact-duplicates-of-ilm-move-to-step/324329)

<div class="topic-metadata">

**Author:** [@jmlucjav](https://discuss.elastic.co/u/jmlucjav)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 6:56pm UTC](https://discuss.elastic.co/t/pending-tasks-has-millions-of-entries-many-of-with-are-exact-duplicates-of-ilm-move-to-step/324329 "2023-01-31T18:56:58Z")

</div>

hi, I have a 7.10.2 cluster, quite large, with 10k indices, and we are having issues with millions of pending tasks being queued at some point. I managed to get a dump of them while they were just 2M, and I saw: 90% …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=647)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=649)
