# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=652

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 653

---

## [There is a way to use search\_after to restart an scroll?](https://discuss.elastic.co/t/there-is-a-way-to-use-search-after-to-restart-an-scroll/324128)

<div class="topic-metadata">

**Author:** [@Guillermo\_Garcia1](https://discuss.elastic.co/u/Guillermo_Garcia1)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 5:13pm UTC](https://discuss.elastic.co/t/there-is-a-way-to-use-search-after-to-restart-an-scroll/324128 "2023-01-27T17:13:45Z")

</div>

It is possible to start an scroll with search\_after ? The idea is to : Create an scroll with a good "sort" Iterate thanks to the scroll\_id and process each batch of docs If when asking for the next batch, a "search\_con…

---

## [How to detect incorrect OID in SNMP input plugin?](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062)

<div class="topic-metadata">

**Author:** [@scantron](https://discuss.elastic.co/u/scantron)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 4:56pm UTC](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062 "2023-01-27T16:56:28Z")

</div>

When using the SNMP input plugin, I am trying to detect when an OID does not work on the given host. For instance, when using snmpget in the command line with an OID that does not correspond to the given host, it would r…

---

## [Why do get results for some strings within a field, but not others?](https://discuss.elastic.co/t/why-do-get-results-for-some-strings-within-a-field-but-not-others/324011)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 4:53pm UTC](https://discuss.elastic.co/t/why-do-get-results-for-some-strings-within-a-field-but-not-others/324011 "2023-01-27T16:53:11Z")

</div>

I can search for ERROR within the message field, but if I try transactionId, I get no hits..

---

## [Missing log events for deleted files within a folder using Auditbeat 8.6 for Windows file integrity](https://discuss.elastic.co/t/missing-log-events-for-deleted-files-within-a-folder-using-auditbeat-8-6-for-windows-file-integrity/324123)

<div class="topic-metadata">

**Author:** [@cyber\_lc51](https://discuss.elastic.co/u/cyber_lc51)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 4:47pm UTC](https://discuss.elastic.co/t/missing-log-events-for-deleted-files-within-a-folder-using-auditbeat-8-6-for-windows-file-integrity/324123 "2023-01-27T16:47:18Z")

</div>

I am using Auditbeat 8.6 for Windows file integrity and have noticed that when I delete a folder, the event is captured and shows that the folder was deleted, but there are no logs of the individual files within the dele…

---

## [Elastic Agent "chown" issues on Mac](https://discuss.elastic.co/t/elastic-agent-chown-issues-on-mac/321337)

<div class="topic-metadata">

**Author:** [@kshort](https://discuss.elastic.co/u/kshort)\
**Replies:** 7\
**Last updated:** [January 27, 2023, 4:33pm UTC](https://discuss.elastic.co/t/elastic-agent-chown-issues-on-mac/321337 "2023-01-27T16:33:24Z")

</div>

I have an issue when adding the elastic-agent on a Mac. I am following the "Install Elastic Agent on your host" instructions provided for Mac by my agent policy. When starting URL enrollment I get the error: "Error: fai…

---

## [Work with multiples inputs/outputs in microsoft-logstash-output-azure-loganalytics plugin](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068)

<div class="topic-metadata">

**Author:** [@Rafael\_Oliveira](https://discuss.elastic.co/u/Rafael_Oliveira)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 4:08pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068 "2023-01-27T16:08:19Z")

</div>

I'm working with microsoft-logstash-output-azure-loganalytics plugin and have to receive different inputs and send to different output based on tags or port. Is is possible? Let's my config file: input { tcp { …

---

## [Kibana 7.10 - "Evidence of administrator activity being logged and monitoring."](https://discuss.elastic.co/t/kibana-7-10-evidence-of-administrator-activity-being-logged-and-monitoring/324059)

<div class="topic-metadata">

**Author:** [@cade.carpenter](https://discuss.elastic.co/u/cade.carpenter)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 2:23pm UTC](https://discuss.elastic.co/t/kibana-7-10-evidence-of-administrator-activity-being-logged-and-monitoring/324059 "2023-01-27T14:23:42Z")

</div>

Hello everyone, I am assisting in data gathering for an upcoming audit and I am trying to use Kibana to search for 'Evidence of admin activity being logged' but I cannot seem to grasp the needed search parameters. I am…

---

## [java.lang.NullPointerException: Cannot invoke "java.util.List.stream()" because the return value of "org.elasticsearch.indices.NodeIndicesStats.getShardStats(org.elasticsearch.index.Index)" is null](https://discuss.elastic.co/t/java-lang-nullpointerexception-cannot-invoke-java-util-list-stream-because-the-return-value-of-org-elasticsearch-indices-nodeindicesstats-getshardstats-org-elasticsearch-index-index-is-null/324091)

<div class="topic-metadata">

**Author:** [@sasvmware](https://discuss.elastic.co/u/sasvmware)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 2:12pm UTC](https://discuss.elastic.co/t/java-lang-nullpointerexception-cannot-invoke-java-util-list-stream-because-the-return-value-of-org-elasticsearch-indices-nodeindicesstats-getshardstats-org-elasticsearch-index-index-is-null/324091 "2023-01-27T14:12:40Z")

</div>

Hi We are getting below in prod \[2023-01-26T23:55:54,079\]\[ERROR\]\[o.e.x.m.c.c.ClusterStatsCollector\] \[xxx-prd-elkmd1.xxxxxx.com\] collector \[cluster\_stats\] failed to collect data java.lang.NullPointerException: Cannot i…

---

## [Logstash starting error with JSON codec plugin](https://discuss.elastic.co/t/logstash-starting-error-with-json-codec-plugin/324100)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 1:43pm UTC](https://discuss.elastic.co/t/logstash-starting-error-with-json-codec-plugin/324100 "2023-01-27T13:43:49Z")

</div>

Hi, I'm trying to send some logs with rsyslog in JSON format to my logstash v8.6 server, but it seems that there is a problem with my JSON codec. Here is the error log : \[2023-01-27T11:31:47,917\]\[INFO \]\[logstash.runne…

---

## [Integración con Microsoft Exchange Online Message Trace](https://discuss.elastic.co/t/integracion-con-microsoft-exchange-online-message-trace/324111)

<div class="topic-metadata">

**Author:** [@Gonzalo\_Sandoval\_A](https://discuss.elastic.co/u/Gonzalo_Sandoval_A)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 1:29pm UTC](https://discuss.elastic.co/t/integracion-con-microsoft-exchange-online-message-trace/324111 "2023-01-27T13:29:49Z")

</div>

Hi, I need to integrate the Microsoft Exchange Online Message Trace, I am using the elastic agent integration and I don't know which url to put, please help as I think there is missing information and I am not very rela…

---

## [Add message in Kibana login page](https://discuss.elastic.co/t/add-message-in-kibana-login-page/324110)

<div class="topic-metadata">

**Author:** [@ismael\_boumedien](https://discuss.elastic.co/u/ismael_boumedien)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 1:24pm UTC](https://discuss.elastic.co/t/add-message-in-kibana-login-page/324110 "2023-01-27T13:24:49Z")

</div>

Hi, We want to add a message in Kibana login page. We are using Kibana 5.6.8, Is't possible. If yes please advice us. Regards Ismaël

---

## [Logstash 8.5.2 how to parse special character in a string value](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107)

<div class="topic-metadata">

**Author:** [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 1:14pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107 "2023-01-27T13:14:10Z")

</div>

Parsing a value of string field http://127.0.0.1:27336/notify logstash maps in Elastic search index many values for the original string. In this case values are http, 127.0.0.1, 27336 and notify. When it encounters t…

---

## [Data streams vs ILM when using Fleet](https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017)

<div class="topic-metadata">

**Author:** [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 2:59pm UTC](https://discuss.elastic.co/t/data-streams-vs-ilm-when-using-fleet/324017 "2023-01-26T14:59:34Z")

</div>

Hello, We are moving away from Beats towards the Centralised Elastic Agent / Fleet but struggling to understand the concept behind how the new approach is meant to work with ILM. We have multiple infrastructures to pull…

---

## [Target field in ndjson](https://discuss.elastic.co/t/target-field-in-ndjson/324014)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 12:25pm UTC](https://discuss.elastic.co/t/target-field-in-ndjson/324014 "2023-01-27T12:25:49Z")

</div>

Hi! I have a log file with json records like { "request": { "foo": "bar" }, "response": { "foo": "bar" } } and the following configuration for filebeat - type: filestream paths: - /path/to/file …

---

## [C# Elasticsearch 8.0.3+ 400 Bad Request media\_type\_header\_exception](https://discuss.elastic.co/t/c-elasticsearch-8-0-3-400-bad-request-media-type-header-exception/322816)

<div class="topic-metadata">

**Author:** [@KoalaBear](https://discuss.elastic.co/u/KoalaBear)\
**Replies:** 11\
**Last updated:** [January 27, 2023, 12:08pm UTC](https://discuss.elastic.co/t/c-elasticsearch-8-0-3-400-bad-request-media-type-header-exception/322816 "2023-01-27T12:08:39Z")

</div>

Just started with a new small project with Elasticsearch, while developing Elasticsearch it is currently running in Docker (docker-elk), with the added "http.cors" things: http.cors.enabled: true http.cors.allow-origin:…

---

## [Logstash Value too large to output](https://discuss.elastic.co/t/logstash-value-too-large-to-output/323495)

<div class="topic-metadata">

**Author:** [@Doremanilka](https://discuss.elastic.co/u/Doremanilka)\
**Replies:** 10\
**Last updated:** [January 27, 2023, 11:43am UTC](https://discuss.elastic.co/t/logstash-value-too-large-to-output/323495 "2023-01-27T11:43:09Z")

</div>

Hello, I have new core app that I need to parse. This app has strange big message output field and I need somehow add it to ELK. Log pattern: grok { match =\> \[ "message", "%{DATA:\[event\]\[ti…

---

## [Start-Service heartbeat fails](https://discuss.elastic.co/t/start-service-heartbeat-fails/323600)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 27\
**Last updated:** [January 27, 2023, 11:01am UTC](https://discuss.elastic.co/t/start-service-heartbeat-fails/323600 "2023-01-27T11:01:43Z")

</div>

Hello, I have installed heartbeat on a Windows server. When I start the service, it stops immediately. with the command : "Start-Service heartbeat" it says nothing, but I can see with the command "sc.exe query…

---

## [Index changes notifications (document creation, update, deletion within the index / doc and more)](https://discuss.elastic.co/t/index-changes-notifications-document-creation-update-deletion-within-the-index-doc-and-more/324069)

<div class="topic-metadata">

**Author:** [@RAVI\_GOPALANI](https://discuss.elastic.co/u/RAVI_GOPALANI)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 10:11am UTC](https://discuss.elastic.co/t/index-changes-notifications-document-creation-update-deletion-within-the-index-doc-and-more/324069 "2023-01-27T10:11:09Z")

</div>

Hi, I am looking for alerting / notification for document creation, update, deletion within the index / doc. Does there any api available within the Elasticsearch / logstash for alerting the changes done at Index / Doc…

---

## [Single Server Single Node vs Single Server Multiple Node](https://discuss.elastic.co/t/single-server-single-node-vs-single-server-multiple-node/324081)

<div class="topic-metadata">

**Author:** [@sramana235](https://discuss.elastic.co/u/sramana235)\
**Replies:** 4\
**Last updated:** [January 27, 2023, 10:06am UTC](https://discuss.elastic.co/t/single-server-single-node-vs-single-server-multiple-node/324081 "2023-01-27T10:06:16Z")

</div>

As the title suggests, I wonder if it is better to configure a single node or multiple nodes when configuring a node on a single server. I understood that the reason for configuring multiple nodes can have the advantage…

---

## [Received plaintext http traffic on an https channel](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/324074)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 10:01am UTC](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/324074 "2023-01-27T10:01:14Z")

</div>

Is it normal for this to appear as a warning in the elasticsearch logs? The first time I installed elasticsearch, this is what I saw in the elasticsearch logs. \[2023-01-27T06:18:35,815\]\[WARN \]\[o.e.x.s.t.n.SecurityNetty…

---

## [Elastic Agent - Import only the latest data using Journald integration](https://discuss.elastic.co/t/elastic-agent-import-only-the-latest-data-using-journald-integration/324097)

<div class="topic-metadata">

**Author:** [@daniele.saccon](https://discuss.elastic.co/u/daniele.saccon)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 9:53am UTC](https://discuss.elastic.co/t/elastic-agent-import-only-the-latest-data-using-journald-integration/324097 "2023-01-27T09:53:16Z")

</div>

Hello everybody, I'm using the Journald integration for the Elastic Agent. Is it possible to import only the last 7 days of the Journald instead of all the data? If it is possible how can I do? Thanks Daniele

---

## [Query a field that has a colon](https://discuss.elastic.co/t/query-a-field-that-has-a-colon/323966)

<div class="topic-metadata">

**Author:** [@ilias\_ioannou](https://discuss.elastic.co/u/ilias_ioannou)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 9:34am UTC](https://discuss.elastic.co/t/query-a-field-that-has-a-colon/323966 "2023-01-27T09:34:21Z")

</div>

Hello, Is it possible to use elasticsearch dsl python client to implement a query that will run against a filed with colon? For example if a field is this properties.grid:code then a successfull query would be the foll…

---

## [Kibana Dev Tool Autocomplete](https://discuss.elastic.co/t/kibana-dev-tool-autocomplete/320916)

<div class="topic-metadata">

**Author:** [@M.Arbaz\_Ali](https://discuss.elastic.co/u/M.Arbaz_Ali)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 9:33am UTC](https://discuss.elastic.co/t/kibana-dev-tool-autocomplete/320916 "2023-01-27T09:33:53Z")

</div>

autocomplete in dev tools console not working after GET there is no option of list of \_cluster or \_cat just showing a limited list when have (\_processor,\_search/template etc etc) but not showing \_cat or \_cluster

---

## [MetricBeat 8.6.0 - error getting connection to system bus: dial unix /var/run/dbus/system\_bus\_socket: connect: no such file or directory](https://discuss.elastic.co/t/metricbeat-8-6-0-error-getting-connection-to-system-bus-dial-unix-var-run-dbus-system-bus-socket-connect-no-such-file-or-directory/323618)

<div class="topic-metadata">

**Author:** [@Ednei\_Rodrigues](https://discuss.elastic.co/u/Ednei_Rodrigues)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/metricbeat-8-6-0-error-getting-connection-to-system-bus-dial-unix-var-run-dbus-system-bus-socket-connect-no-such-file-or-directory/323618 "2023-01-27T09:23:24Z")

</div>

Hello, how are you doing ? So, I've installed metricbeat in my ubuntu server ( Ubuntu 20.04.5 LTS ) and I enabled three modules: root@SBG5PC4:~# metricbeat modules list Enabled: mysql nginx system I have been working…

---

## [Elastic cluster running out of space, can't get cluster health to green](https://discuss.elastic.co/t/elastic-cluster-running-out-of-space-cant-get-cluster-health-to-green/323906)

<div class="topic-metadata">

**Author:** [@lostsoul352](https://discuss.elastic.co/u/lostsoul352)\
**Replies:** 6\
**Last updated:** [January 27, 2023, 9:22am UTC](https://discuss.elastic.co/t/elastic-cluster-running-out-of-space-cant-get-cluster-health-to-green/323906 "2023-01-27T09:22:35Z")

</div>

I have a 2 node elastic cluster. I noticed that I was not able to add more data to it, and it turned out the filesystem space is over at the flood limit on both machines. So to try and recover from this I shut down the …

---

## [Java class ElasticsearchClient v. 7.17.8](https://discuss.elastic.co/t/java-class-elasticsearchclient-v-7-17-8/324041)

<div class="topic-metadata">

**Author:** [@habdank](https://discuss.elastic.co/u/habdank)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 7:43am UTC](https://discuss.elastic.co/t/java-class-elasticsearchclient-v-7-17-8/324041 "2023-01-27T07:43:26Z")

</div>

Hi, Java doc for ElasticsearchClient v. 7.17.8 ElasticsearchClient (java-client 7.17.8 API) states that ElasticsearchClient is java class. However using \<dependency\> \<groupId\>org.elasticsearch.clie…

---

## [FilestreamWhen updating log files, updated logs and old logs display in graylog](https://discuss.elastic.co/t/filestreamwhen-updating-log-files-updated-logs-and-old-logs-display-in-graylog/324089)

<div class="topic-metadata">

**Author:** [@leesy9610](https://discuss.elastic.co/u/leesy9610)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 7:31am UTC](https://discuss.elastic.co/t/filestreamwhen-updating-log-files-updated-logs-and-old-logs-display-in-graylog/324089 "2023-01-27T07:31:00Z")

</div>

Hi, I used graylog, logtash, filebeat When updating log files, updated logs and old logs display in graylog. I only want the updated log to come out. help me please...

---

## [Elasticsearch, Kibana does not work](https://discuss.elastic.co/t/elasticsearch-kibana-does-not-work/323472)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 16\
**Last updated:** [January 27, 2023, 6:45am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-does-not-work/323472 "2023-01-27T06:45:39Z")

</div>

I have an issue with Elasticsearch. After restarting ubuntu, Kibana does not show any logs.

---

## [Inconsistency in data stream rollover](https://discuss.elastic.co/t/inconsistency-in-data-stream-rollover/323883)

<div class="topic-metadata">

**Author:** [@sagarkhatri0605](https://discuss.elastic.co/u/sagarkhatri0605)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 6:32am UTC](https://discuss.elastic.co/t/inconsistency-in-data-stream-rollover/323883 "2023-01-27T06:32:33Z")

</div>

We want hourly rollover of the index and then index should get deleted after 12 hour. To achieve this we have created data stream with a ILM policy which rollover index every 1hr and then the index goes into the warm ph…

---

## [Time based indexes](https://discuss.elastic.co/t/time-based-indexes/324067)

<div class="topic-metadata">

**Author:** [@mardo](https://discuss.elastic.co/u/mardo)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 6:31am UTC](https://discuss.elastic.co/t/time-based-indexes/324067 "2023-01-27T06:31:04Z")

</div>

Its my understanding to remove data if it is 15 days old time based indexes is the way to go. I can't find any documentation or how-to article to accomplish this easily. I am using Kibana. Any help would be appreciate…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=651)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=653)
