# Latest

**URL:** https://discuss.elastic.co/latest.md?page=538

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 539

---

## [Grok not parsing](https://discuss.elastic.co/t/grok-not-parsing/343098)

<div class="topic-metadata">

**Author:** [@pshas](https://discuss.elastic.co/u/pshas)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 9:24am UTC](https://discuss.elastic.co/t/grok-not-parsing/343098 "2023-09-18T09:24:33Z")

</div>

logstash.conf # Sample Logstash configuration for creating a simple # Beats -\> Logstash -\> Elasticsearch pipeline. input { beats { port =\> 5044 type = "test" } } filter { if \[type\] == "log" { grok { …

---

## [Backup and restoration possibilities](https://discuss.elastic.co/t/backup-and-restoration-possibilities/343234)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 3\
**Last updated:** [September 18, 2023, 9:19am UTC](https://discuss.elastic.co/t/backup-and-restoration-possibilities/343234 "2023-09-18T09:19:30Z")

</div>

What are all the backup and restoration possibilities offered by the ELK stack version 8.8.1 pls.

---

## [Varnish Metrics with Metricbeat:](https://discuss.elastic.co/t/varnish-metrics-with-metricbeat/342921)

<div class="topic-metadata">

**Author:** [@Deepika\_Gupta](https://discuss.elastic.co/u/Deepika_Gupta)\
**Replies:** 5\
**Last updated:** [September 18, 2023, 9:02am UTC](https://discuss.elastic.co/t/varnish-metrics-with-metricbeat/342921 "2023-09-18T09:02:33Z")

</div>

Hello Team, Greetings! I want to use Metricbeat, part of the Elastic Stack, to collect and monitor Varnish metrics. Metricbeat's Varnish module allows to gather information about cache hits, cache misses, cache size, a…

---

## [Min\_score not working as expected](https://discuss.elastic.co/t/min-score-not-working-as-expected/342970)

<div class="topic-metadata">

**Author:** [@Ayush\_Mehta\_Engineer](https://discuss.elastic.co/u/Ayush_Mehta_Engineer)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 3:06pm UTC](https://discuss.elastic.co/t/min-score-not-working-as-expected/342970 "2023-09-13T15:06:37Z")

</div>

I am trying to fetch the results with a minimum score of 1 using min\_score using the following query but I am still getting responses with null score I know that my query is bit complex and there could be better ways to…

---

## [Why my filebeat settings can only read /var/log/messages. I need to read all files in /var/log and my customized log folder: /suselv/log](https://discuss.elastic.co/t/why-my-filebeat-settings-can-only-read-var-log-messages-i-need-to-read-all-files-in-var-log-and-my-customized-log-folder-suselv-log/343232)

<div class="topic-metadata">

**Author:** [@huanghaiqing1](https://discuss.elastic.co/u/huanghaiqing1)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 8:20am UTC](https://discuss.elastic.co/t/why-my-filebeat-settings-can-only-read-var-log-messages-i-need-to-read-all-files-in-var-log-and-my-customized-log-folder-suselv-log/343232 "2023-09-18T08:20:27Z")

</div>

filebeat.yml part about included logs --\> type: filestream Unique ID among all inputs, an ID is required. id: autoyast1-filestream Change to true to enable this input configuration. enabled: true Paths that should …

---

## [Monitoring filebeat, heartbeat, metricbeat, logstash, kibana stats in kibana dashboards](https://discuss.elastic.co/t/monitoring-filebeat-heartbeat-metricbeat-logstash-kibana-stats-in-kibana-dashboards/342937)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [September 18, 2023, 8:12am UTC](https://discuss.elastic.co/t/monitoring-filebeat-heartbeat-metricbeat-logstash-kibana-stats-in-kibana-dashboards/342937 "2023-09-18T08:12:14Z")

</div>

Hello All, Currently all the beats and logstash sends data directly to Elasticsearch. I have multiple servers installed with heartbeat,metricbeat,logstash and filebeat and now I've requirement to monitor all these comp…

---

## [Group documents by similarity using Elser](https://discuss.elastic.co/t/group-documents-by-similarity-using-elser/342913)

<div class="topic-metadata">

**Author:** [@Anton\_Dambrouski](https://discuss.elastic.co/u/Anton_Dambrouski)\
**Replies:** 3\
**Last updated:** [September 18, 2023, 7:48am UTC](https://discuss.elastic.co/t/group-documents-by-similarity-using-elser/342913 "2023-09-18T07:48:46Z")

</div>

Hello, Is it possible to use ML tokens generated by ELSER (Elastic Learned Sparse EncodeR) to group documents? Let's imagine I have the following list of documents: \[ { "name" : "Apple", price: 1234, "nameTokens" : \<t…

---

## [Filebeat queue.disk keeps piling up even when Logstash persisted queue remains relatively empty](https://discuss.elastic.co/t/filebeat-queue-disk-keeps-piling-up-even-when-logstash-persisted-queue-remains-relatively-empty/343221)

<div class="topic-metadata">

**Author:** [@sergeyarl](https://discuss.elastic.co/u/sergeyarl)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 6:40am UTC](https://discuss.elastic.co/t/filebeat-queue-disk-keeps-piling-up-even-when-logstash-persisted-queue-remains-relatively-empty/343221 "2023-09-18T06:40:03Z")

</div>

Hi! So we are using the following chain: Filebeats, that run in a K8s cluster (1 Filebeat instance on each k8s worker node) -\> 2 Logstash nodes behind AWS ALB -\> Elastic search cluster Everything works pretty well. …

---

## [FsCrawler 2.10 Rest Service upload returns error for file more than 20 MB](https://discuss.elastic.co/t/fscrawler-2-10-rest-service-upload-returns-error-for-file-more-than-20-mb/342706)

<div class="topic-metadata">

**Author:** [@Nilesh\_Pegasus](https://discuss.elastic.co/u/Nilesh_Pegasus)\
**Replies:** 12\
**Last updated:** [September 18, 2023, 6:00am UTC](https://discuss.elastic.co/t/fscrawler-2-10-rest-service-upload-returns-error-for-file-more-than-20-mb/342706 "2023-09-18T06:00:00Z")

</div>

Hi, I am using FsCrawler 2.10 with elasticsearch 8.9, I am trying to upload a 20Mb .msg file using rest service of FsCrawler, but it gives error. Please note that I am able to upload smaller files without any issues. F…

---

## [Add nested and sibling aggregation in data.search() in plugin](https://discuss.elastic.co/t/add-nested-and-sibling-aggregation-in-data-search-in-plugin/340763)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 5:45am UTC](https://discuss.elastic.co/t/add-nested-and-sibling-aggregation-in-data-search-in-plugin/340763 "2023-09-18T05:45:24Z")

</div>

Hi, I am developing a custom plugin in Kibana using React, in Kibana 8.8.1. I am using search (low-level) of data plugin to query Elasticsearch. This is the request body: const request = { id: searchId, t…

---

## [Logstash stop working due to FFI not available: null](https://discuss.elastic.co/t/logstash-stop-working-due-to-ffi-not-available-null/343174)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 5:37am UTC](https://discuss.elastic.co/t/logstash-stop-working-due-to-ffi-not-available-null/343174 "2023-09-18T05:37:38Z")

</div>

Logstash stopped working due to FFI not available: null . I have already provided the tmp path in Jvm.options # set the I/O temp directory #-Djava.io.tmpdir=$HOME -Djava.io.tmpdir=/home/apmuser/tmp drwxrwxr-x. 2 logsta…

---

## [ELK to monitor job](https://discuss.elastic.co/t/elk-to-monitor-job/342422)

<div class="topic-metadata">

**Author:** [@murran\_rais](https://discuss.elastic.co/u/murran_rais)\
**Replies:** 6\
**Last updated:** [September 18, 2023, 5:00am UTC](https://discuss.elastic.co/t/elk-to-monitor-job/342422 "2023-09-18T05:00:33Z")

</div>

hi, im new with ELK, wanna ask, can ELK monitor job from Apache airflow, SQL or other applications? and can elk monitor comprehensivly like give information about history of the job, last run time of the job, condition o…

---

## [How to do header control in Kibana?](https://discuss.elastic.co/t/how-to-do-header-control-in-kibana/343216)

<div class="topic-metadata">

**Author:** [@dudqlssky96](https://discuss.elastic.co/u/dudqlssky96)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 4:22am UTC](https://discuss.elastic.co/t/how-to-do-header-control-in-kibana/343216 "2023-09-18T04:22:19Z")

</div>

I'd like to change the logo part from Kibana version 8.9. Please help me if you know how

---

## [Docker.elastic.co: support IPv6](https://discuss.elastic.co/t/docker-elastic-co-support-ipv6/342984)

<div class="topic-metadata">

**Author:** [@lus](https://discuss.elastic.co/u/lus)\
**Replies:** 5\
**Last updated:** [September 18, 2023, 3:30am UTC](https://discuss.elastic.co/t/docker-elastic-co-support-ipv6/342984 "2023-09-18T03:30:15Z")

</div>

Hello. I am currently trying to set up Elasticsearch using Docker on an IPv6-only server. Though Elasticsearch seems to be available via Docker Hub, it seems outdated and recommended to use the docker.elastic.co regist…

---

## [Infer model Text embedding in Java](https://discuss.elastic.co/t/infer-model-text-embedding-in-java/343192)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 1\
**Last updated:** [September 17, 2023, 12:37pm UTC](https://discuss.elastic.co/t/infer-model-text-embedding-in-java/343192 "2023-09-17T12:37:52Z")

</div>

Hi there, Is there any document or instruction on how to use the machine learning api in java? For example, how can I convert this query into java POST /\_ml/trained\_models/My\_model/\_infer { "docs": { "text\_field…

---

## [Get analytics with potential alerts if anomalies detected](https://discuss.elastic.co/t/get-analytics-with-potential-alerts-if-anomalies-detected/343177)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 5\
**Last updated:** [September 17, 2023, 11:20am UTC](https://discuss.elastic.co/t/get-analytics-with-potential-alerts-if-anomalies-detected/343177 "2023-09-17T11:20:31Z")

</div>

I'm researching options how to get some analytics, for instance, I want to look into ERRORs in log\_level column, and if its amount increases drastically, I want to receive an alert. There should be many such cases and it…

---

## [Winlogbeat unable to start due to error](https://discuss.elastic.co/t/winlogbeat-unable-to-start-due-to-error/343190)

<div class="topic-metadata">

**Author:** [@risshukla](https://discuss.elastic.co/u/risshukla)\
**Replies:** 0\
**Last updated:** [September 17, 2023, 9:23am UTC](https://discuss.elastic.co/t/winlogbeat-unable-to-start-due-to-error/343190 "2023-09-17T09:23:28Z")

</div>

We've been using Winlogbeat to forward Workstation logs to Logstash. However, we've encountered an issue after installing Winlogbeat (versions 8.9.2 and 8.10.0) on our Windows Server 2022. The issue is as follows: Exce…

---

## [Filebeat query EKS worker node /var/log](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745)

<div class="topic-metadata">

**Author:** [@xUmaRix](https://discuss.elastic.co/u/xUmaRix)\
**Replies:** 2\
**Last updated:** [September 17, 2023, 3:38am UTC](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745 "2023-09-17T03:38:12Z")

</div>

Hi, I'm trying to ship EKS worker node auth.log, syslog and audit.log files which located under /var/log. I've deploy filebeat and logstash in EKS cluster however I saw under filebeat pods there's a lot of error log s…

---

## [ElasticSearch on giant compute nodes](https://discuss.elastic.co/t/elasticsearch-on-giant-compute-nodes/343183)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 0\
**Last updated:** [September 16, 2023, 9:10pm UTC](https://discuss.elastic.co/t/elasticsearch-on-giant-compute-nodes/343183 "2023-09-16T21:10:30Z")

</div>

The standard paradigm which I see is usually recommended for ES (mainly for query purpose) is a collection or cluster of nodes - the nodes being typically SSD, the RAM usually recommended as 64 GB, with shard size not ex…

---

## [Custom Query | Default Query for React Js Search UI](https://discuss.elastic.co/t/custom-query-default-query-for-react-js-search-ui/343181)

<div class="topic-metadata">

**Author:** [@faruque\_holiday](https://discuss.elastic.co/u/faruque_holiday)\
**Replies:** 0\
**Last updated:** [September 16, 2023, 6:45pm UTC](https://discuss.elastic.co/t/custom-query-default-query-for-react-js-search-ui/343181 "2023-09-16T18:45:51Z")

</div>

Hi , I'm interested in learning how to craft custom or default queries for a search UI. This might involve tasks such as retrieving specific data based on particular attribute values before rendering, or implementing que…

---

## [Elastic Search .Net client doesnt have Fuzziness?](https://discuss.elastic.co/t/elastic-search-net-client-doesnt-have-fuzziness/343176)

<div class="topic-metadata">

**Author:** [@senadk](https://discuss.elastic.co/u/senadk)\
**Replies:** 0\
**Last updated:** [September 16, 2023, 12:30pm UTC](https://discuss.elastic.co/t/elastic-search-net-client-doesnt-have-fuzziness/343176 "2023-09-16T12:30:24Z")

</div>

Hello, Im having trouble with adding Fuzziness to my Match query, see the below code: var client = new ElasticsearchClient(new Uri("http://elasticsearch:9200")); var response = await client.SearchAsync\<Ex…

---

## [ELK SSL config problem](https://discuss.elastic.co/t/elk-ssl-config-problem/342668)

<div class="topic-metadata">

**Author:** [@p81061473525](https://discuss.elastic.co/u/p81061473525)\
**Replies:** 3\
**Last updated:** [September 16, 2023, 11:26am UTC](https://discuss.elastic.co/t/elk-ssl-config-problem/342668 "2023-09-16T11:26:22Z")

</div>

Hello, recently I've been practicing setting up ELK 8.9. My target architecture looks like this: Filebeat -\> Logstash -\> ES \<- Kibana. I encountered difficulties when configuring encryption. Currently, my architecture …

---

## [How can I visualize aggregation results using Vega?](https://discuss.elastic.co/t/how-can-i-visualize-aggregation-results-using-vega/342907)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 1\
**Last updated:** [September 16, 2023, 6:50am UTC](https://discuss.elastic.co/t/how-can-i-visualize-aggregation-results-using-vega/342907 "2023-09-16T06:50:23Z")

</div>

I'm a newbie to Vega. Appreciate it if you can help me to build a visualizer on the aggregated results that I have as follows. For every release, I'd like to show the sum of duration per workflow (e.g., A, B, and C) bas…

---

## [Sum of duration field of max per group in Elasticsearch](https://discuss.elastic.co/t/sum-of-duration-field-of-max-per-group-in-elasticsearch/342285)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 22\
**Last updated:** [September 16, 2023, 6:31am UTC](https://discuss.elastic.co/t/sum-of-duration-field-of-max-per-group-in-elasticsearch/342285 "2023-09-16T06:31:01Z")

</div>

I would like to create a visualizer by summing up duration field after retrieving max id per group in Elasticsearch. For example: Data is: id workflow sid duration 1 A x1 1m 1 A x2 2m 2 A x1 2m 2 A x2 3m …

---

## [Need help in finding dependency map for nimbus jose jwt](https://discuss.elastic.co/t/need-help-in-finding-dependency-map-for-nimbus-jose-jwt/343169)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 1\
**Last updated:** [September 16, 2023, 5:07am UTC](https://discuss.elastic.co/t/need-help-in-finding-dependency-map-for-nimbus-jose-jwt/343169 "2023-09-16T05:07:04Z")

</div>

i have this vulnerability from elastic docker image net.minidev:json-smart 2.4.8 2.4.9 Java usr/share/elasticsearch/modules/x-pack-security/nimbus-jose-jwt-9.23.jar where can i find the nimbus config to update and what…

---

## [Fixing vulnerablities in logstash code](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 1\
**Last updated:** [September 16, 2023, 5:05am UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168 "2023-09-16T05:05:34Z")

</div>

my company check for vulnerablities and i see bunch of vulnerablities in logstash. an example is below to fix this vulnerablity, should i upgrade guava or does jruby needs to be upgraded. if jruby needs to be upgraded …

---

## [Disk usage/shard allocation problems during snapshot creation](https://discuss.elastic.co/t/disk-usage-shard-allocation-problems-during-snapshot-creation/342768)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 4\
**Last updated:** [September 16, 2023, 4:51am UTC](https://discuss.elastic.co/t/disk-usage-shard-allocation-problems-during-snapshot-creation/342768 "2023-09-16T04:51:22Z")

</div>

version 7.17.12 last night my cluster stoped ingesting data. One node ran out of disk after snapshot started. That node normally has plenty of headroom: 57% available: 1.85TB total: 4.30TB logs show: \[2023-09-12T00…

---

## [Mapping date in milliseconds to basic\_date\_time](https://discuss.elastic.co/t/mapping-date-in-milliseconds-to-basic-date-time/343160)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [September 15, 2023, 11:19pm UTC](https://discuss.elastic.co/t/mapping-date-in-milliseconds-to-basic-date-time/343160 "2023-09-15T23:19:06Z")

</div>

I followed the instructions here: I ran this command as instructed: PUT /\_index\_template/itential\_jobs\_template { "index\_patterns": \["itential-jobs-\*"\], "template": { "mappings": { "properties": { "start\_ti…

---

## [Logstash container not receiving log files from Filebeats running on host](https://discuss.elastic.co/t/logstash-container-not-receiving-log-files-from-filebeats-running-on-host/343162)

<div class="topic-metadata">

**Author:** [@David\_Locarno](https://discuss.elastic.co/u/David_Locarno)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 10:48pm UTC](https://discuss.elastic.co/t/logstash-container-not-receiving-log-files-from-filebeats-running-on-host/343162 "2023-09-15T22:48:20Z")

</div>

I am running a RHEL VM with Filebeats installed and three Podman containers running Kibana, Elasticsearch, and Logstash. Almost everything works, except for sending files from Filebeats to my Logstash container's pipelin…

---

## [Cannot parse logs - problem with multiline parse failures](https://discuss.elastic.co/t/cannot-parse-logs-problem-with-multiline-parse-failures/343146)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 4\
**Last updated:** [September 15, 2023, 10:27pm UTC](https://discuss.elastic.co/t/cannot-parse-logs-problem-with-multiline-parse-failures/343146 "2023-09-15T22:27:04Z")

</div>

Hi All, I am having a lot of problems parsing logs especially with different dates and logs having multiline tags. For example: A head (very first 10 lines) of one of my log files, specifically, catalina.out, could be…

[Previous page](https://discuss.elastic.co/latest.md?page=537)

[Next page](https://discuss.elastic.co/latest.md?page=539)
