# Latest

**URL:** https://discuss.elastic.co/latest.md?page=571

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 572

---

## [Filebeat-Container neither sends data to elasticsearch nor writes output to console/file](https://discuss.elastic.co/t/filebeat-container-neither-sends-data-to-elasticsearch-nor-writes-output-to-console-file/340904)

<div class="topic-metadata">

**Author:** [@hmmh-sven-scheil](https://discuss.elastic.co/u/hmmh-sven-scheil)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-container-neither-sends-data-to-elasticsearch-nor-writes-output-to-console-file/340904 "2023-08-16T14:08:31Z")

</div>

Hi there, I'am trying to setup a demo scenario, to demonstrate how to collect Tomcat log data from different containers and send it to an elastic stack for log aggregation and log analysis. I try to describe my setup, …

---

## [Elastic Search - how to create index with mapping](https://discuss.elastic.co/t/elastic-search-how-to-create-index-with-mapping/340925)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 2:08pm UTC](https://discuss.elastic.co/t/elastic-search-how-to-create-index-with-mapping/340925 "2023-08-16T14:08:09Z")

</div>

elasticsearch:8.7.1 I am creating index this way: return new CreateIndexRequest.Builder() .index(name) .aliases(alias, new Alias.Builder().build()) .settings(new Inde…

---

## [Invalid CRI error (Filebeat 7.17 + docker)](https://discuss.elastic.co/t/invalid-cri-error-filebeat-7-17-docker/340930)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 1:57pm UTC](https://discuss.elastic.co/t/invalid-cri-error-filebeat-7-17-docker/340930 "2023-08-16T13:57:17Z")

</div>

Hi there! We have a weird problem when Filebeat gets stuck on partial message in Container logs. Parse line error: invalid CRI log format {"level":"error","timestamp":"2023-08-03T11:55:49.674Z","logger":"reader\_docker…

---

## [I am trying to capture audit logs from 2 event hubs but there is data loss or some time not getting the audit logs. I am using below input configuration](https://discuss.elastic.co/t/i-am-trying-to-capture-audit-logs-from-2-event-hubs-but-there-is-data-loss-or-some-time-not-getting-the-audit-logs-i-am-using-below-input-configuration/340924)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 1:21pm UTC](https://discuss.elastic.co/t/i-am-trying-to-capture-audit-logs-from-2-event-hubs-but-there-is-data-loss-or-some-time-not-getting-the-audit-logs-i-am-using-below-input-configuration/340924 "2023-08-16T13:21:40Z")

</div>

input { azure\_event\_hubs { config\_mode =\> "basic" #Insert primary connection string from shared access policies in event hub namespace from azure portal event\_hub\_connections =\> \["\<Shared Acess Pol…

---

## [Registry log.json grows constantly even with filebeat.registry.flush: 60s](https://discuss.elastic.co/t/registry-log-json-grows-constantly-even-with-filebeat-registry-flush-60s/340923)

<div class="topic-metadata">

**Author:** [@pkulenkamp](https://discuss.elastic.co/u/pkulenkamp)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 1:04pm UTC](https://discuss.elastic.co/t/registry-log-json-grows-constantly-even-with-filebeat-registry-flush-60s/340923 "2023-08-16T13:04:24Z")

</div>

Filebeat 7.17.1 I'm looking into decreasing the amount of IO for the filebeat registry in our deployment. I found the filebeat.registry.flush setting after some research and thought that it would do what I wanted. I s…

---

## [Executing multiple .conf files in one instance](https://discuss.elastic.co/t/executing-multiple-conf-files-in-one-instance/340749)

<div class="topic-metadata">

**Author:** [@Tony\_Stark](https://discuss.elastic.co/u/Tony_Stark)\
**Replies:** 9\
**Last updated:** [August 16, 2023, 12:48pm UTC](https://discuss.elastic.co/t/executing-multiple-conf-files-in-one-instance/340749 "2023-08-16T12:48:52Z")

</div>

I am trying to execute multiple .conf files in logstash with logstash -f "path\*.conf" but logstash processes the .conf file the same number of times as the number of .conf files I have , if I have 5 .conf files , I get o…

---

## [Elasticsearch query based on timestamp from kibana (dev tools)](https://discuss.elastic.co/t/elasticsearch-query-based-on-timestamp-from-kibana-dev-tools/340893)

<div class="topic-metadata">

**Author:** [@Mamta\_Bharadwaj](https://discuss.elastic.co/u/Mamta_Bharadwaj)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 12:40pm UTC](https://discuss.elastic.co/t/elasticsearch-query-based-on-timestamp-from-kibana-dev-tools/340893 "2023-08-16T12:40:15Z")

</div>

Hello All, I am using ELK 8.3.3 on Docker. When I am trying to fetch the data with any timestamp range, I am getting the correct output. But when I am trying to fetch the data based on the below, I am getting nothing. P…

---

## [Storage sinze index of a policy](https://discuss.elastic.co/t/storage-sinze-index-of-a-policy/340881)

<div class="topic-metadata">

**Author:** [@agomezgu](https://discuss.elastic.co/u/agomezgu)\
**Replies:** 2\
**Last updated:** [August 16, 2023, 12:36pm UTC](https://discuss.elastic.co/t/storage-sinze-index-of-a-policy/340881 "2023-08-16T12:36:48Z")

</div>

Hi, I'm new to ELKstack and I'm trying to get from an Index Lifecycle Policies "logstash-pro" all the indexes that are in it, and also about this to return me the space occupied by each index. For example, I use the sta…

---

## [Encountering 'Name must match one or more data streams, indices, or index aliases' error when creating a data view in Kibana 8 Discover section](https://discuss.elastic.co/t/encountering-name-must-match-one-or-more-data-streams-indices-or-index-aliases-error-when-creating-a-data-view-in-kibana-8-discover-section/339589)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 4\
**Last updated:** [August 16, 2023, 11:51am UTC](https://discuss.elastic.co/t/encountering-name-must-match-one-or-more-data-streams-indices-or-index-aliases-error-when-creating-a-data-view-in-kibana-8-discover-section/339589 "2023-08-16T11:51:52Z")

</div>

Hello, hope you're doing well. When I try to create a data view in the Discover section of Kibana 8, I encounter the following error message for any index pattern I write in the index pattern field: "Name must match on…

---

## [ES S3 plugin](https://discuss.elastic.co/t/es-s3-plugin/340892)

<div class="topic-metadata">

**Author:** [@EshaSingh32000](https://discuss.elastic.co/u/EshaSingh32000)\
**Replies:** 4\
**Last updated:** [August 16, 2023, 10:44am UTC](https://discuss.elastic.co/t/es-s3-plugin/340892 "2023-08-16T10:44:23Z")

</div>

Currently my Es Version is 7.17.1, and i want to download s3 plugin for same, can anyone provide me link to download s3 plugin for es version 7.17.1

---

## [Changing password of elasticsearch user after expiration of x-pack](https://discuss.elastic.co/t/changing-password-of-elasticsearch-user-after-expiration-of-x-pack/340638)

<div class="topic-metadata">

**Author:** [@Kartik101](https://discuss.elastic.co/u/Kartik101)\
**Replies:** 2\
**Last updated:** [August 16, 2023, 9:53am UTC](https://discuss.elastic.co/t/changing-password-of-elasticsearch-user-after-expiration-of-x-pack/340638 "2023-08-16T09:53:52Z")

</div>

Can we change password of elasticsearch user after expiration of x-pack (installed using basic configuration) for Elasticsearch v5.6.2?

---

## [Java API Timeout connection](https://discuss.elastic.co/t/java-api-timeout-connection/340867)

<div class="topic-metadata">

**Author:** [@hld942614](https://discuss.elastic.co/u/hld942614)\
**Replies:** 3\
**Last updated:** [August 16, 2023, 9:39am UTC](https://discuss.elastic.co/t/java-api-timeout-connection/340867 "2023-08-16T09:39:59Z")

</div>

I am using Elastic Java API to write some data into elastic，but I occasionally get some error like this: "java.net.ConnectException: Timeout connecting to \[gt7-elk001.es.asia-east1.gcp.elastic-cloud.com/XX.XX.XXX.XXX:XX…

---

## [Excessive RAM usage, gets OOM killed in logstash](https://discuss.elastic.co/t/excessive-ram-usage-gets-oom-killed-in-logstash/340716)

<div class="topic-metadata">

**Author:** [@tanveer14](https://discuss.elastic.co/u/tanveer14)\
**Replies:** 4\
**Last updated:** [August 16, 2023, 9:05am UTC](https://discuss.elastic.co/t/excessive-ram-usage-gets-oom-killed-in-logstash/340716 "2023-08-16T09:05:30Z")

</div>

Hi! I'm running pipelines on logstash. Everything ran smoothly, but the POD went down for a certain amount of time. In values.yml ll set JVM option as "logstashJavaOpts: "-Xmx5g -Xms3g" still end up getting killed by…

---

## [Logstash ruby code plugin validate JSON](https://discuss.elastic.co/t/logstash-ruby-code-plugin-validate-json/340889)

<div class="topic-metadata">

**Author:** [@z\_z](https://discuss.elastic.co/u/z_z)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 9:01am UTC](https://discuss.elastic.co/t/logstash-ruby-code-plugin-validate-json/340889 "2023-08-16T09:01:42Z")

</div>

My logstash.conf is as follows, it is used to read data from events.txt and use ruby code plugin to add tag to non json event. input { file { path =\> \["/home/events.txt"\] start\_position =\> "beginning…

---

## [Not setting the elasticsearchRef for setting beat output](https://discuss.elastic.co/t/not-setting-the-elasticsearchref-for-setting-beat-output/340878)

<div class="topic-metadata">

**Author:** [@alexns](https://discuss.elastic.co/u/alexns)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 7:44am UTC](https://discuss.elastic.co/t/not-setting-the-elasticsearchref-for-setting-beat-output/340878 "2023-08-16T07:44:42Z")

</div>

Hello, We have a k8s cluster dedicated running monitoring software. Elastic Search is installed here using the ECK operator and the CRD's. On another cluster, we have filebeat running using the deprecated helm charts. …

---

## [Kibana Error Messages](https://discuss.elastic.co/t/kibana-error-messages/340823)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 2\
**Last updated:** [August 16, 2023, 7:11am UTC](https://discuss.elastic.co/t/kibana-error-messages/340823 "2023-08-16T07:11:39Z")

</div>

Hello, Elasticsearch-Kibana: 7.10.2 As can be seen from the error messages in Kibana below It is seen that a critical level of information about the system is revealed. Is there any way to close these error messag…

---

## [ES replica creation](https://discuss.elastic.co/t/es-replica-creation/340872)

<div class="topic-metadata">

**Author:** [@khubaibathar](https://discuss.elastic.co/u/khubaibathar)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 7:07am UTC](https://discuss.elastic.co/t/es-replica-creation/340872 "2023-08-16T07:07:00Z")

</div>

Hi, Can someone tell me if ES is able to create a replica while still in use. Would it affect the performance of the cluster or does this mechanism run in the background. We have an ES cluster which has six nodes.

---

## [Log Filtration Issue with Filebeat and Logstash Configuration](https://discuss.elastic.co/t/log-filtration-issue-with-filebeat-and-logstash-configuration/340609)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 18\
**Last updated:** [August 16, 2023, 6:02am UTC](https://discuss.elastic.co/t/log-filtration-issue-with-filebeat-and-logstash-configuration/340609 "2023-08-16T06:02:59Z")

</div>

Hello everyone, I'm using Filebeat to send three different logs to Logstash, where I'm applying parsing through filters. In the parsing process, I've taken into consideration the logs that are visible in the observation…

---

## [Getting 'Badly formatted index, after interpolation still contains placeholder' error when trying to ingest AWS WAF logs](https://discuss.elastic.co/t/getting-badly-formatted-index-after-interpolation-still-contains-placeholder-error-when-trying-to-ingest-aws-waf-logs/340862)

<div class="topic-metadata">

**Author:** [@feo13](https://discuss.elastic.co/u/feo13)\
**Replies:** 3\
**Last updated:** [August 16, 2023, 4:38am UTC](https://discuss.elastic.co/t/getting-badly-formatted-index-after-interpolation-still-contains-placeholder-error-when-trying-to-ingest-aws-waf-logs/340862 "2023-08-16T04:38:19Z")

</div>

Hi there, I'm trying to ingest AWS WAF logs with logstash-8.9.0 and send them to my local ELK stack but am getting a 'Badly formatted index, after interpolation still contains placeholder' error. Here's my logstash co…

---

## [Filter combined\_fields result](https://discuss.elastic.co/t/filter-combined-fields-result/340812)

<div class="topic-metadata">

**Author:** [@Samuel\_Litvack](https://discuss.elastic.co/u/Samuel_Litvack)\
**Replies:** 3\
**Last updated:** [August 15, 2023, 5:13pm UTC](https://discuss.elastic.co/t/filter-combined-fields-result/340812 "2023-08-15T17:13:03Z")

</div>

Hi I'm working on a people search website. I already have my databases indexed and it is currently possible to search for a person by fullname using combined\_fields query like this. { "query":{ "combined\_field…

---

## [Kibana watcher alerting for Elastic agents](https://discuss.elastic.co/t/kibana-watcher-alerting-for-elastic-agents/340865)

<div class="topic-metadata">

**Author:** [@TirathS](https://discuss.elastic.co/u/TirathS)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 4:03am UTC](https://discuss.elastic.co/t/kibana-watcher-alerting-for-elastic-agents/340865 "2023-08-16T04:03:17Z")

</div>

Hello All, I am looking for a possible way to create a custom threshold alert that will monitor if the elastic agent goes down and doesn't come back up in 5-10mins, it should send us an email. Have anyone done it befor…

---

## [How to search and display log events linked through a series of UUIDs](https://discuss.elastic.co/t/how-to-search-and-display-log-events-linked-through-a-series-of-uuids/340854)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 2:43am UTC](https://discuss.elastic.co/t/how-to-search-and-display-log-events-linked-through-a-series-of-uuids/340854 "2023-08-16T02:43:27Z")

</div>

Hi, We have an application which communicates with various microservices. Some initial request to an endpoint /api on A might generate several requests to systems B and C, and they themselves might generate further req…

---

## [Crawl ADFS Authenticated Website using Enterprise crawler](https://discuss.elastic.co/t/crawl-adfs-authenticated-website-using-enterprise-crawler/340852)

<div class="topic-metadata">

**Author:** [@gupashis1978](https://discuss.elastic.co/u/gupashis1978)\
**Replies:** 1\
**Last updated:** [August 15, 2023, 10:09pm UTC](https://discuss.elastic.co/t/crawl-adfs-authenticated-website-using-enterprise-crawler/340852 "2023-08-15T22:09:39Z")

</div>

Requirement is to crawl website having ADFS Authentication. Enterprise crawler support basic Http Authentication and HTTP proxy authentication. What are the ways to crawl ADFS Authenticated sites. Using the Elastic Clou…

---

## [Error when Setting up Email Alert in Kibana](https://discuss.elastic.co/t/error-when-setting-up-email-alert-in-kibana/340850)

<div class="topic-metadata">

**Author:** [@elastic12](https://discuss.elastic.co/u/elastic12)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 9:31pm UTC](https://discuss.elastic.co/t/error-when-setting-up-email-alert-in-kibana/340850 "2023-08-15T21:31:39Z")

</div>

We are trying to setup an email alert for Elasticsearch query regarding log threshold in Kibana. We are using Microsoft Email and using Outlook as Service. For username and password, we are using Kibana's username and p…

---

## [Attempting to create a Double Field, Changes to keyword when data is imported](https://discuss.elastic.co/t/attempting-to-create-a-double-field-changes-to-keyword-when-data-is-imported/340848)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 7:52pm UTC](https://discuss.elastic.co/t/attempting-to-create-a-double-field-changes-to-keyword-when-data-is-imported/340848 "2023-08-15T19:52:27Z")

</div>

Hello, I've got an empty dev index that I'm attempting to test some aggregations and a dashboard on. The problem I'm encountering is that when I push logs through to the index via a filebeat collector node the type for …

---

## [Elasticsearch + filebeat + apache on docker environment](https://discuss.elastic.co/t/elasticsearch-filebeat-apache-on-docker-environment/340842)

<div class="topic-metadata">

**Author:** [@Jackson\_Luz](https://discuss.elastic.co/u/Jackson_Luz)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 5:07pm UTC](https://discuss.elastic.co/t/elasticsearch-filebeat-apache-on-docker-environment/340842 "2023-08-15T17:07:20Z")

</div>

Hello! Newbie here. Imagine the following scenario: a Docker environment where there are 3 containers. One is running Elasticsearch, another has Filebeat, and the third one contains Apache. All of them are on the same ne…

---

## [How to change the field types of a index pattern?](https://discuss.elastic.co/t/how-to-change-the-field-types-of-a-index-pattern/340838)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 1\
**Last updated:** [August 15, 2023, 4:27pm UTC](https://discuss.elastic.co/t/how-to-change-the-field-types-of-a-index-pattern/340838 "2023-08-15T16:27:25Z")

</div>

I am using a dis-logger that accepts the raw logs, and transforms them into a more useful form. For a given field, I might first transform it from int to string in the dis-logger python file, say ForceID might go from \[1…

---

## [XContentBuilder](https://discuss.elastic.co/t/xcontentbuilder/340839)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 4:02pm UTC](https://discuss.elastic.co/t/xcontentbuilder/340839 "2023-08-15T16:02:02Z")

</div>

Referencing this post - Ways to build Json doc in ES8 Java API client Is it advised not to use XContentBuilder with the new Java API Client? Will that be deprecated? Thanks.

---

## [How to parse array of objects into separate field](https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692)

<div class="topic-metadata">

**Author:** [@Subhashini](https://discuss.elastic.co/u/Subhashini)\
**Replies:** 3\
**Last updated:** [August 15, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-parse-array-of-objects-into-separate-field/340692 "2023-08-15T16:01:00Z")

</div>

I have some log look like ########2023-08-12######### {‘crewrosters’: \[ { ‘crew\_roster’ : ‘det1’, 'empno': 1} , {‘crew\_roster’ : ‘det2’, 'empno': 2} , {‘crew\_roster’ : ‘det3’, 'empno': 3} \] } I need to parse the data …

---

## [Filebeat Cisco module Nexus fileset dissect\_parsing\_error flag](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548)

<div class="topic-metadata">

**Author:** [@obol89](https://discuss.elastic.co/u/obol89)\
**Replies:** 2\
**Last updated:** [August 15, 2023, 1:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548 "2023-08-15T13:45:04Z")

</div>

I'm trying to use Filebeat with Cisco module and Nexus fileset, but it seems like these logs aren't parsed properly. In every document I see - dissect\_parsing\_error in log.flags. It looks like that: filebeat versio…

[Previous page](https://discuss.elastic.co/latest.md?page=570)

[Next page](https://discuss.elastic.co/latest.md?page=572)
