# Latest

**URL:** https://discuss.elastic.co/latest.md?page=527

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 528

---

## [Parse rabbitmq json log](https://discuss.elastic.co/t/parse-rabbitmq-json-log/344009)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 5\
**Last updated:** [September 27, 2023, 9:32pm UTC](https://discuss.elastic.co/t/parse-rabbitmq-json-log/344009 "2023-09-27T21:32:20Z")

</div>

Hi, got json log message from rabbit as {"timestamp":"2022-12-21 03:14:59.977922+02:00","level":"error","msg":"Error on AMQP connection \<0.32551.1583\>: enotconn (socket is not connected)","domain":"rabbitmq.connection",…

---

## [HIGH PRIORITY -\> how to add subaggregtion in terms aggregation for spring-data-elasticsearch 5.1](https://discuss.elastic.co/t/high-priority-how-to-add-subaggregtion-in-terms-aggregation-for-spring-data-elasticsearch-5-1/344015)

<div class="topic-metadata">

**Author:** [@Abhinav\_Tyagi](https://discuss.elastic.co/u/Abhinav_Tyagi)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:14pm UTC](https://discuss.elastic.co/t/high-priority-how-to-add-subaggregtion-in-terms-aggregation-for-spring-data-elasticsearch-5-1/344015 "2023-09-27T21:14:36Z")

</div>

i am rewriting my older verison elasticsearch implementations. I latest spring-data-elasticsearch 5.1, queryBuilders got removed due to whic i am not able to use/ add "AggregationBuilders" inside my native query. Can a…

---

## [What is the default source of the @timestamp field in Filebeat?](https://discuss.elastic.co/t/what-is-the-default-source-of-the-timestamp-field-in-filebeat/343640)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 8:59pm UTC](https://discuss.elastic.co/t/what-is-the-default-source-of-the-timestamp-field-in-filebeat/343640 "2023-09-27T20:59:01Z")

</div>

I'm ingesting Syslog input with Filebeat, and I'd like to use the timestamp processor to adjust the timezone of the logs (my source is sending them in local time and Kibana is expecting UTC). According to the documentati…

---

## [Multiple input log, reading the same files](https://discuss.elastic.co/t/multiple-input-log-reading-the-same-files/344013)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 8:45pm UTC](https://discuss.elastic.co/t/multiple-input-log-reading-the-same-files/344013 "2023-09-27T20:45:17Z")

</div>

Hi, it is posible to use multiple inputs on the same files, but with different filters? The configuration below works but only if I run filebeat with: ./filebeat.exe -c filebeat.yml not when I run it as a service UPDA…

---

## [Transaction result setting as failure/spindown](https://discuss.elastic.co/t/transaction-result-setting-as-failure-spindown/342950)

<div class="topic-metadata">

**Author:** [@gabriel-f-santos](https://discuss.elastic.co/u/gabriel-f-santos)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 12:28pm UTC](https://discuss.elastic.co/t/transaction-result-setting-as-failure-spindown/342950 "2023-09-13T12:28:12Z")

</div>

Hello everyone! We are using agent and APM extensions for monitoring our serverless application with Python Lambdas. We're following this configuration for SAM applications: APM Agent language and version : Language: …

---

## [APM Flask - Treating all transactions as Errors](https://discuss.elastic.co/t/apm-flask-treating-all-transactions-as-errors/343611)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 5\
**Last updated:** [September 27, 2023, 7:16pm UTC](https://discuss.elastic.co/t/apm-flask-treating-all-transactions-as-errors/343611 "2023-09-27T19:16:38Z")

</div>

Kibana version: 8.9.1 Elasticsearch version: 8.9.1 APM Server version: 8.9.1 APM Agent language and version: Python (Flask) 6.18.0 We are trying to build a proof of concept using Elastic APM and are running into a si…

---

## [Field \[field\] not present as part of path \[field.query\]](https://discuss.elastic.co/t/field-field-not-present-as-part-of-path-field-query/344008)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/field-field-not-present-as-part-of-path-field-query/344008 "2023-09-27T18:45:20Z")

</div>

I'm creating a pipeline with a gsub processor and I keep getting this error when testing the pipeline on a document. I had to add a unique delimiter before ingesting to deal with a whitespace issue. I'm now trying to rep…

---

## [Filebeat modules vs filestream input](https://discuss.elastic.co/t/filebeat-modules-vs-filestream-input/342871)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 29\
**Last updated:** [September 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/filebeat-modules-vs-filestream-input/342871 "2023-09-27T18:45:19Z")

</div>

Hello, I'm trying to configure filebeat to read a Linux system and auth log file. when I'm using datastream input, the data isn't parsed well; everything is let into the message field without any processing. When I use…

---

## [Heartbeat configuration for 1000+ IPs](https://discuss.elastic.co/t/heartbeat-configuration-for-1000-ips/342803)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 4\
**Last updated:** [September 27, 2023, 6:41pm UTC](https://discuss.elastic.co/t/heartbeat-configuration-for-1000-ips/342803 "2023-09-27T18:41:03Z")

</div>

Hi gurus, We have a requirement to monitor1000+ IPs using Heartbeat 7.17.4. As the baseline test, we pinged one IP address (let's call it device A) with cmd ping and the latency is around 30ms. Then we started adding …

---

## [OIDC with Azure not logged in on Kibana](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680)

<div class="topic-metadata">

**Author:** [@esanolad](https://discuss.elastic.co/u/esanolad)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 6:40pm UTC](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680 "2023-09-27T18:40:38Z")

</div>

Hi all My company is configuring SSO using OIDC on AZURE, everything looks fine but whenever user tries to authenticate, it takes them back to the to the login page. I have checked the logs, there are no errors and ther…

---

## [Parse AWS EC2 logs Error](https://discuss.elastic.co/t/parse-aws-ec2-logs-error/344005)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 6:07pm UTC](https://discuss.elastic.co/t/parse-aws-ec2-logs-error/344005 "2023-09-27T18:07:51Z")

</div>

Hi Engineers, I set up Observability Logs Stream in Kibana for AWS EC2 logs. I have received the aws.ec2\_logs, but Message showed "Fail to find message". When I clicked the "View Details" button, the log contents have b…

---

## [Delete .reporting index](https://discuss.elastic.co/t/delete-reporting-index/343482)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 6:05pm UTC](https://discuss.elastic.co/t/delete-reporting-index/343482 "2023-09-27T18:05:05Z")

</div>

This is regarding my last raised topic - Kibana 7.17.3 So i have multiple csv reports generated and i want to delete them now those reports comes under .reportinf-\* index. So when i am trying to delete those i am gett…

---

## [Filebeat 8.7.1 utilizing too much of Memory and pods get OOM Killed](https://discuss.elastic.co/t/filebeat-8-7-1-utilizing-too-much-of-memory-and-pods-get-oom-killed/344004)

<div class="topic-metadata">

**Author:** [@gsekar](https://discuss.elastic.co/u/gsekar)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 4:12pm UTC](https://discuss.elastic.co/t/filebeat-8-7-1-utilizing-too-much-of-memory-and-pods-get-oom-killed/344004 "2023-09-27T16:12:19Z")

</div>

We are seeing filebeat pods using a lot of memory and restarting at random intervals due to OOM. Any solution for this? Even in a 3 node kubernetes cluster with very little resources running seeing the issue.

---

## [Elastic search mongo db (elastic-connectors) real-time sync configuration?](https://discuss.elastic.co/t/elastic-search-mongo-db-elastic-connectors-real-time-sync-configuration/343934)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 3:26pm UTC](https://discuss.elastic.co/t/elastic-search-mongo-db-elastic-connectors-real-time-sync-configuration/343934 "2023-09-27T15:26:59Z")

</div>

May I know how to configure Elasticsearch mongo db real-time sync config using elastic connector? Docker: container\_name: els\_connector image: docker.elastic.co/enterprise-search/elastic-connectors:8.10.2.0-SNAPSHOT Im…

---

## [Connecting to ELK from databricks](https://discuss.elastic.co/t/connecting-to-elk-from-databricks/343998)

<div class="topic-metadata">

**Author:** [@ksasidhar1103](https://discuss.elastic.co/u/ksasidhar1103)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 2:35pm UTC](https://discuss.elastic.co/t/connecting-to-elk-from-databricks/343998 "2023-09-27T14:35:10Z")

</div>

Hi, I'm trying to load data into databrciks from ELK with the help of API using python script. Can you suggest me the best option that I can read the huge data like 200 million in single shot. The method now I'm using i…

---

## [Maximum number of attempts exceeded. Restart Kibana to generate a new code and retry](https://discuss.elastic.co/t/maximum-number-of-attempts-exceeded-restart-kibana-to-generate-a-new-code-and-retry/343997)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 2:18pm UTC](https://discuss.elastic.co/t/maximum-number-of-attempts-exceeded-restart-kibana-to-generate-a-new-code-and-retry/343997 "2023-09-27T14:18:00Z")

</div>

Hi fellows, I installed elk stack as docker containers with podman in RHEL9. Now after generating the enrollment token for elasticsearch I would like to configure KIBANA but I get this error message: " Maximum number …

---

## [Downloading large amount of logs as CSV using Kibana/Eland](https://discuss.elastic.co/t/downloading-large-amount-of-logs-as-csv-using-kibana-eland/343768)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 8\
**Last updated:** [September 27, 2023, 2:04pm UTC](https://discuss.elastic.co/t/downloading-large-amount-of-logs-as-csv-using-kibana-eland/343768 "2023-09-27T14:04:31Z")

</div>

Hi, I am using Elastic Cloud and am trying to download a large among of logs (over 800 million lines of logs, over span of a few months) as CSV. However when I tried downloading from Discover \> Share \> Generate CSV, it d…

---

## [Filebeat Cisco Modules for Nexus](https://discuss.elastic.co/t/filebeat-cisco-modules-for-nexus/343914)

<div class="topic-metadata">

**Author:** [@acardona](https://discuss.elastic.co/u/acardona)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 5:11pm UTC](https://discuss.elastic.co/t/filebeat-cisco-modules-for-nexus/343914 "2023-09-26T17:11:12Z")

</div>

Hi, I am trying to set up syslogging from a nexus switch to feed into Filebeat's Cisco module that would then feed into Elasticsearch. I tend to get the same error message after enabling the cisco module and running thi…

---

## ["logs threshold rule" adding comparator: "MATCHES"](https://discuss.elastic.co/t/logs-threshold-rule-adding-comparator-matches/343986)

<div class="topic-metadata">

**Author:** [@BRINDAH\_B](https://discuss.elastic.co/u/BRINDAH_B)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 12:51pm UTC](https://discuss.elastic.co/t/logs-threshold-rule-adding-comparator-matches/343986 "2023-09-27T12:51:22Z")

</div>

Missing "comparator": "MATCHES" or "MATCHES PHRASE" in "logs threshold rule". I want end-user to be able to search text fields in that rule. Is this possible? At this stage we are not able to grant "all" privilege for e…

---

## [Shipping access logs logstash to logstash using http plugins](https://discuss.elastic.co/t/shipping-access-logs-logstash-to-logstash-using-http-plugins/343980)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 12:42pm UTC](https://discuss.elastic.co/t/shipping-access-logs-logstash-to-logstash-using-http-plugins/343980 "2023-09-27T12:42:38Z")

</div>

Hi We have a setup where we ship logs between systems via logstash to logstash using http plugins. The access logs are in ecs format. The problem is, logstash overwrites http, url and others fields, with it's own transp…

---

## [APM Server status is You have correctly setup APM Serve But Agent status is No data has been received](https://discuss.elastic.co/t/apm-server-status-is-you-have-correctly-setup-apm-serve-but-agent-status-is-no-data-has-been-received/343901)

<div class="topic-metadata">

**Author:** [@Karthick\_MJ](https://discuss.elastic.co/u/Karthick_MJ)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 12:14pm UTC](https://discuss.elastic.co/t/apm-server-status-is-you-have-correctly-setup-apm-serve-but-agent-status-is-no-data-has-been-received/343901 "2023-09-27T12:14:30Z")

</div>

Hello Team, I'm trying to configure APM for my Java project. APM Server says "You have correctly setup APM server" but Agent says "No data bas been received from agent yet" whereas I can the jar logs says "Elastics APM…

---

## [Breaklines character](https://discuss.elastic.co/t/breaklines-character/343840)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 11:50am UTC](https://discuss.elastic.co/t/breaklines-character/343840 "2023-09-27T11:50:31Z")

</div>

Good morning, I have an easy question about the text field when in the string I have breaklines. I have seen that in this moment when I read the index field I something like this: "enEN" : """- Characteristics of the g…

---

## [Elastic-Agent is not getting installed](https://discuss.elastic.co/t/elastic-agent-is-not-getting-installed/343976)

<div class="topic-metadata">

**Author:** [@syedsyed](https://discuss.elastic.co/u/syedsyed)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 11:07am UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-installed/343976 "2023-09-27T11:07:29Z")

</div>

Hello, I have 2 Problems, i have installed the integration of sonicwall in Elasticsearch and enrolled the elastic agent in fleet server by using the debian package, but the service is not getting started and iam getting …

---

## [Report data from Splunk to Elastic](https://discuss.elastic.co/t/report-data-from-splunk-to-elastic/343975)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:47am UTC](https://discuss.elastic.co/t/report-data-from-splunk-to-elastic/343975 "2023-09-27T10:47:47Z")

</div>

So, I have been sending log data to Splunk. And I want to "catch" the data that is sent to Splunk and forward it to Elastic. I tried with Integrations but that did not work. Does anybody have any ideas on how to solve th…

---

## [Json multiline codec is not working and messages are not getting parsed](https://discuss.elastic.co/t/json-multiline-codec-is-not-working-and-messages-are-not-getting-parsed/343172)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 16\
**Last updated:** [September 27, 2023, 10:44am UTC](https://discuss.elastic.co/t/json-multiline-codec-is-not-working-and-messages-are-not-getting-parsed/343172 "2023-09-27T10:44:41Z")

</div>

Hi Team, I an working on logstash json parser and messages are not getting parsed; any clue what could be wrong? Here are original messages \[ { "time": "12/Aug/2023:13:20:52 +0000", "source\_ip": "117.193.217.44",…

---

## [Logstash 8.10.2 fails to start in docker without any log output](https://discuss.elastic.co/t/logstash-8-10-2-fails-to-start-in-docker-without-any-log-output/343973)

<div class="topic-metadata">

**Author:** [@tzfun](https://discuss.elastic.co/u/tzfun)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:36am UTC](https://discuss.elastic.co/t/logstash-8-10-2-fails-to-start-in-docker-without-any-log-output/343973 "2023-09-27T10:36:03Z")

</div>

I pulled image docker.elastic.co/logstash/logstash:8.10.2 to run a container, and it works in docker on mac os but neither works in docker on Debian 11. Docker for mac and debian 11 are both version 24.0.6. There is no…

---

## [Threat Intelligence Integration won't show any data](https://discuss.elastic.co/t/threat-intelligence-integration-wont-show-any-data/343541)

<div class="topic-metadata">

**Author:** [@Gio\_27](https://discuss.elastic.co/u/Gio_27)\
**Replies:** 7\
**Last updated:** [September 27, 2023, 9:47am UTC](https://discuss.elastic.co/t/threat-intelligence-integration-wont-show-any-data/343541 "2023-09-27T09:47:23Z")

</div>

Good morning, I have installed the Threat Intelligence Integration, I also have a fleet managed server and I am currently tracking different hosts with different integrations and i am managing all of that through 2 agen…

---

## [Solution for monitoring](https://discuss.elastic.co/t/solution-for-monitoring/343916)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 9:37am UTC](https://discuss.elastic.co/t/solution-for-monitoring/343916 "2023-09-27T09:37:20Z")

</div>

Hello community I hope you are well. After unpacking the ELK stack I'd like to do some tests to track my local logs and metrics but I don't really know how to go about it. I'm using the latest version of the stack.

---

## [CircuitBreakingException when load huge data by bulk write](https://discuss.elastic.co/t/circuitbreakingexception-when-load-huge-data-by-bulk-write/343410)

<div class="topic-metadata">

**Author:** [@ericsoul](https://discuss.elastic.co/u/ericsoul)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 9:24am UTC](https://discuss.elastic.co/t/circuitbreakingexception-when-load-huge-data-by-bulk-write/343410 "2023-09-27T09:24:18Z")

</div>

I got many errors like Caused by: org.elasticsearch.common.breaker.CircuitBreakingException: \[parent\] Data too large, data for \[indices:data/write/bulk\[s\]\] would be \[30897445494/28.7gb\], which is larger than the limit…

---

## [How to create finger print ingest pipeline for nested field?](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845)

<div class="topic-metadata">

**Author:** [@mhsankar](https://discuss.elastic.co/u/mhsankar)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845 "2023-09-27T09:23:58Z")

</div>

Hi every body. I have a mapping with nested field. I want to identify a finger print for every rows in nested field . how can create this ingest pipeline? I\`m using Elasticsearch v 7.17.7 my mapping: PUT test-neste…

[Previous page](https://discuss.elastic.co/latest.md?page=526)

[Next page](https://discuss.elastic.co/latest.md?page=528)
