# Issues with ELK

**URL:** <https://discuss.elastic.co/t/issues-with-elk/337326>\
**Category:** Kibana\
**Created:** [June 30, 2023, 2:52pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326 "2023-06-30T14:52:00Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [June 30, 2023, 2:52pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/1 "2023-06-30T14:52:00Z")

</div>

Hi All,  
I have the template siem\_alarm created in my kibana index pattern but i have this error "Error: No indices match pattern "siem\_alarms" at url/bundles/commons.bundle.js:3:1337196"

Does anyone know what could be responsible for this.  
thanks  
pero

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 3, 2023, 8:21pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/2 "2023-07-03T20:21:01Z")

</div>

Hi @pero. What part of Kibana were you accessing when this error came up? Can you run `GET /_cat/indices` in your Kibana Dev Tools and share the results?

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 4, 2023, 3:07pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/3 "2023-07-04T15:07:02Z")

</div>

Hi @nickpeihl,  
Am getting this from when I click on "index pattern, followed by me selecting the specific pattern then I click on the fresh Icon which then open up the 'refresh field list box' then click on refresh button, this will popup an 'error fetching fields with a 'see the full error' button.  
if I run 'GET /\_cat/indices' I get

```auto
  "error": "Incorrect HTTP method for uri [/_cat/indices?pretty] and method [POST], allowed: [GET]",
  "status": 405

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 4, 2023, 4:26pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/4 "2023-07-04T16:26:26Z")

</div>

> [@pero](#):
>
> Am getting this from when I click on "index pattern, followed by me selecting the specific pattern then I click on the fresh Icon which then open up the 'refresh field list box' then click on refresh button

In which version are you? Can you share a screenshot of that page?

This is an weird error for something in Kibana to make a POST request for `_cat/indices`.

---

<div class="post-metadata">

**Author:** ![tagba](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@tagba](https://discuss.elastic.co/u/tagba)\
**Post date:** [July 5, 2023, 9:56am UTC](https://discuss.elastic.co/t/issues-with-elk/337326/5 "2023-07-05T09:56:31Z")

</div>

Hi @nickpeihl /@leandrojmp,

Here are screenshots that can be helpful

 ![Screenshot_1](https://us1.discourse-cdn.com/elastic/original/3X/8/9/89aad0078a9633b996cf3ed9a82d9d232a3c6cbc.jpeg)  
 ![Screenshot_2](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78990349a6f4cc9f1adfc8787881a911c447c21c.jpeg)  
 ![Screenshot_3](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a9333488abed8063e970a5b3ba878a091f2ed59b.jpeg)  
 ![Screenshot_4](https://us1.discourse-cdn.com/elastic/original/3X/8/0/8025897f15666c203d269a0705a3d4a25435169e.jpeg)  
 ![Screenshot_5](https://us1.discourse-cdn.com/elastic/original/3X/4/5/45888ef0eaeda6d8eda6305ec311c75e4e182531.jpeg)  
 ![Screenshot_6](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1b2665534d17b49789d89c440b71fd196be6da79.jpeg)

when I run 'GET /\_cat/indices' on the Kibana Dev Tools this is what I get

 ![Screenshot_7](https://us1.discourse-cdn.com/elastic/original/3X/0/9/0921db798422bec16b1a46f4ca9c64c60ec36d94.jpeg)  
 ![Screenshot_8](https://us1.discourse-cdn.com/elastic/original/3X/7/5/752f6ac3945df608d1d41ff4c4e30f7945e9e28c.jpeg)  
 ![Screenshot_9](https://us1.discourse-cdn.com/elastic/original/3X/5/0/5004b6c16471ef87018b3decac58b5b4fb589941.jpeg)

 ![Screenshot_10](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d08f85e81226c670227054bd49b16a0db4485f37.jpeg)  
 ![Screenshot_11](https://us1.discourse-cdn.com/elastic/original/3X/4/8/486a3734a215bf29e035271f0a05fc127183c596.jpeg)  
 ![Screenshot_12](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff26b685ab7f122eb72625241a0a363d51d3e20a.jpeg)

Thanks for the help

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 5, 2023, 12:37pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/6 "2023-07-05T12:37:06Z")

</div>

> [@pero](#):
>
> ```auto
> "error": "Incorrect HTTP method for uri [/_cat/indices?pretty] and method [POST], allowed: [GET]",
> "status": 405
> 
> ```

And where is this from? You didn't share anything like this.

Also, from what you shared you do not have any indice named `siem_alarms` anymore, you have an indice named `siem_events-*`, but I do not see any `siem_alarms`.

Please run `GET _cat/indices` again and share the result but as plain text using the preformatted text button, the `</>` button.

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 5, 2023, 12:45pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/7 "2023-07-05T12:45:53Z")

</div>

The first index pattern you see as default is 'siem\_alarms' but when I run `GET _cat/indices` I do not see the 'siem\_alarms' and 'siem\_alarm\_events-\*'

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 5, 2023, 12:54pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/8 "2023-07-05T12:54:46Z")

</div>

Hi @leandrojmp,  
when I run `GET /_cat/indices` it get this

```auto
green open siem_events-2023.07.05 CiM3kFJfSPi_2kisxalL8Q 1 0 288433 0 100.6mb 100.6mb
green open auditbeat-7.4.1-2023.06.30 PUMFLxGIQkmVBc6_S6GrxQ 1 0 334040 0 84.2mb 84.2mb
green open auditbeat-7.4.1-2023.06.27 O6-LaJ9bSQ2FkbCWldNbPA 1 0 297846 0 70.6mb 70.6mb
green open auditbeat-7.4.1-2023.06.26 beqNST1_QSGkQO4iYtppzQ 1 0 63423 0 16mb 16mb
green open auditbeat-7.4.1-2023.06.25 PJgbYcnGR1GIn1lcjVtwNA 1 0 0 0 283b 283b
yellow open %{[@metadata][beat]}-%{[@metadata][version]}-2023.06.29 gWoZN_IuShiwjoWtI43HRA 1 1 6 0 226.6kb 226.6kb
green open auditbeat-2023.07.05 -gKf1Cq2QlCZe3iMP982JA 1 0 332985 0 176mb 176mb
green open auditbeat-2023.07.04 R_-I9uO7RV-lSHYsgl3rsA 1 0 406238 0 230.4mb 230.4mb
green open siem_events-2023.07.01 YH15ewWYQnusW4SYQtXklg 1 0 323862 0 92.1mb 92.1mb
yellow open %{[@metadata][beat]}-%{[@metadata][version]}-2023.06.27 EOyW0xuURlm1KpO7crAeZA 1 1 4 0 110.4kb 110.4kb
green open siem_events-2023.07.02 KhJkRX3ySNyqnGlWEzehPw 1 0 317982 0 90.4mb 90.4mb
green open .kibana_task_manager_1 02WrViHKT_KVpoL1UfR2Rw 1 0 2 0 13.5kb 13.5kb
green open siem_events-2023.07.03 jYLTD6v1SVKmJHt42WLFSQ 1 0 311485 0 88.9mb 88.9mb
green open siem_events-2023.07.04 DfGozML6RY-hLYnDgpBZvg 1 0 219720 0 62.9mb 62.9mb
yellow open %{[@metadata][beat]}-%{[@metadata][version]}-2023.06.26 admFJphwTDqBBxiDHoJgNg 1 1 9 0 56kb 56kb
green open auditbeat-2023.06.30 ct1Cq917TEC1gjsRNqWaXA 1 0 599131 0 324.8mb 324.8mb
green open auditbeat-2023.07.03 CQH4f02jRoek6hEj7mgS4w 1 0 565842 0 313.9mb 313.9mb
green open auditbeat-2023.07.02 PBsPBlrcS1yFoFGqH5-sTw 1 0 576752 0 314mb 314mb
green open siem_events-2023.06.30 Btjlox98QOuOEBmPWOm_hg 1 0 334040 0 95.7mb 95.7mb
green open auditbeat-2023.07.01 LWF5MzgZQdyVUFJWKYsK7A 1 0 586212 0 316mb 316mb
yellow open %{[@metadata][beat]}-%{[@metadata][version]}-2023.05.30 70KyapVHRpa0VhzfJjbDqA 1 1 2 0 127.6kb 127.6kb
green open auditbeat-7.4.1-2023.06.29 eVHINF0WTiiKgx8LNjSa1Q 1 0 323585 0 81.9mb 81.9mb
green open auditbeat-7.4.1-2023.06.28 1C4RviUwQr-2BUMqVgAfJg 1 0 468926 0 114.8mb 114.8mb
green open siem_events-2023.06.29 S0mjQNVrTiKUUtd6IKddog 1 0 323585 0 92.9mb 92.9mb
green open siem_events-2023.06.28 lLICYO8IQX2lVHxmq0hXMg 1 0 468926 0 133.7mb 133.7mb
green open siem_events-2023.06.27 5BEn2fZ7RZugDeP0Zls2Fw 1 0 297846 0 83.4mb 83.4mb
green open siem_events-2023.06.26 rswSpbDPS8ub4Ku49UbEXw 1 0 63423 0 18.3mb 18.3mb
green open .apm-agent-configuration mMiItdNzTHOG9d49CNMtjQ 1 0 0 0 283b 283b
green open .kibana_1 5wZ9F7aVRq-Vj0ENYTX_HA 1 0 1031 101 512kb 512kb
green open auditbeat-2023.06.27 eQ_rvQ8pRrCRpd0tloQBbw 1 0 348909 0 179mb 179mb
green open auditbeat-2023.06.28 e1QzxPWrSZ-lPX1GvzjMoQ 1 0 615016 0 338.4mb 338.4mb
green open auditbeat-7.4.1-2023.07.05 gK1Xi86LRL2RsqlgxFUEuQ 1 0 288419 0 70.5mb 70.5mb
green open filebeat-2023.06.23 N_iFrRl3Rdal9EWB-OT7sw 1 0 1706 0 765.2kb 765.2kb
green open auditbeat-7.4.1-2023.07.04 a6rjMzrzSeyhmMz628ziDQ 1 0 219720 0 55.9mb 55.9mb
green open auditbeat-2023.06.25 7tgoi0FvRmOSGfxgpaDqDQ 1 0 12316 0 7.3mb 7.3mb
green open auditbeat-2023.06.26 cPyoN8ovRAm_1bZKP1P6Yg 1 0 520260 0 266.4mb 266.4mb
green open auditbeat-7.4.1-2023.07.03 k54x8kpPQz-UeaU4msiTVg 1 0 311485 0 78.3mb 78.3mb
green open auditbeat-7.4.1-2023.07.02 CGGczPy9SVyqXMneR-Fy4Q 1 0 317982 0 79.4mb 79.4mb
green open auditbeat-7.4.1-2023.07.01 RvFYqN4YTqiYhZGNMs9HOA 1 0 323862 0 81mb 81mb
green open auditbeat-2023.06.29 ulJ1y7ipQuK0fj8hg3i78w 1 0 572598 0 321mb 321mb
green open siem_events-2023.06.25 tQQVKlXwQiadk_cmK-vyoQ 1 0 0 0 283b 283b
yellow open %{[@metadata][beat]}-%{[@metadata][version]}-2023.07.03 fPMo-M5vQXy_GNaD40iyDw 1 1 5 0 363.8kb 363.8kb
green open filebeat-7.4.0-2023.06.23-000001 O_j3Rof0STKkHwR6qCEV9A 1 0 0 0 283b 283b
green open siem_events-2023.06.22 p59TvpB4Q5W3uXOZi-oNmg 1 0 192714 0 55.1mb 55.1mb
yellow open %{[@metadata][beat]}-%{[@metadata][version]}-2023.06.30 BHHsslugSv6QI8HgA69qOg 1 1 3 0 120.5kb 120.5kb
green open auditbeat-2023.06.23 8EDAy-K0RgWo1iDy4Y30xg 1 0 520740 0 297.2mb 297.2mb
green open auditbeat-2023.06.24 E1BaHTRFRti1_4JE7LBQDA 1 0 338259 0 199.2mb 199.2mb
yellow open localhost;9200 Bq81Ji1fRCmeM2MKtGvzTA 1 1 0 0 283b 283b

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 5, 2023, 12:59pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/9 "2023-07-05T12:59:22Z")

</div>

> [@pero](#):
>
> The first index pattern you see as default is 'siem\_alarms' but when I run `GET _cat/indices` I do not see the 'siem\_alarms' and 'siem\_alarm\_events-\*'

This means that someone with access to your Elasticsearch cluster created the index pattern `siem_alarms` and set it as the default index pattern when there was at least one index that matched that index pattern.

For some reason you do not have any index that matches this index pattern anymore, but only you can answer why, maybe someone deleted it or those indices are not being created anymore, or it was an alias that it is not present on your data anymore, you will need to investigate what happened.

Do you have an index pattern for the indices `siem_events-*`? If not you just need to create one and set it as default.

Also, 7.4 is pretty old, you should look into update to 7.17 and after date upgrade to 8.8.2.

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 5, 2023, 1:11pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/10 "2023-07-05T13:11:16Z")

</div>

Hi @leandrojmp, @nickpeihl  
this was an error from something else please. so ignore it  
["error": "Incorrect HTTP method for uri [/\_cat/indices?pretty] and method [POST], allowed: [GET]",  
"status": 405"]

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 5, 2023, 1:13pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/11 "2023-07-05T13:13:47Z")

</div>

No problem.

But as I said, there is no issue in Elasticsearch in this case.

You just have a default index pattern and your cluster does not have any indices that matches that index pattern anymore, so the message is expected.

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 5, 2023, 1:23pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/12 "2023-07-05T13:23:47Z")

</div>

Hi @leandrojmp,

I have the index pattern for the 'siem\_alarms and siem\_alarm\_events created in elasticsearch and I can actually see the logs of this two patterns. Am very new to ELK. And am trying to integrate it with Dsiem

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 5, 2023, 1:26pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/13 "2023-07-05T13:26:09Z")

</div>

> [@pero](#):
>
> I have the index pattern for the 'siem\_alarms and siem\_alarm\_events created in elasticsearch and I can actually see the logs of this two patterns.

Can you show where you are seeing it? From what you shared you do not have any index named `siem_alarms`, so you do not have any index that matches that index pattern.

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 5, 2023, 1:39pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/14 "2023-07-05T13:39:38Z")

</div>

@nickpeihl, @leandrojmp,

The logs from both the 'siem\_alarms and siem\_alarm\_events' are in the dsiem application.

```auto

![alarm_events|574x207](upload://1RLLAsm6Vkzsmgo2nX3N4xIokmP.jpeg)

![alarm_logs1|690x446](upload://3IIiezv5Ou5nO47ml7Gf6hmR2iY.jpeg)

 
![logs|442x43](upload://vRvoYCZPiI1TT1qcTHbu1qEN4JT.jpeg)

```

As you can see, these are being index to elasticsearch I believe

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 5, 2023, 1:49pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/15 "2023-07-05T13:49:37Z")

</div>

> [@pero](#):
>
> The logs from both the 'siem\_alarms and siem\_alarm\_events' are in the dsiem application.

I can't see the images and I do not know what is _dsiem_.

Also, do not tag people, there is no need, if they are in a conversation they will be already notified.

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 5, 2023, 1:55pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/16 "2023-07-05T13:55:05Z")

</div>

Hi @leandrojmp; @nickpeihl ,

here are the patterns using `GET /_template/siem_alarms-*`

```auto
{
  "siem_alarms-*" : {
    "order" : 0,
    "version" : 1,
    "index_patterns" : [
      "siem_alarms-*"
    ],
    "settings" : {
      "index" : {
        "number_of_shards" : "1",
        "number_of_replicas" : "0",
        "refresh_interval" : "1s"
      }
    },
    "mappings" : {
      "dynamic_templates" : [
        {
          "string_as_keywords" : {
            "mapping" : {
              "norms" : false,
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "ignore_above" : 256,
                  "type" : "keyword"
                }
              }
            },
            "match_mapping_type" : "string"
          }
        }
      ],
      "properties" : {
        "src_ips" : {
          "type" : "ip"
        },
        "dst_ips" : {
          "type" : "ip"
        }
      }
    },
    "aliases" : {
      "siem_alarms" : { },
      "siem_alarms_id_lookup" : { }
    }
  }
}

```

` GET /_template/siem_alarms`

```auto
{
  "siem_alarms" : {
    "order" : 0,
    "version" : 1,
    "index_patterns" : [
      "siem_alarms-*"
    ],
    "settings" : {
      "index" : {
        "number_of_shards" : "1",
        "number_of_replicas" : "0",
        "refresh_interval" : "1s"
      }
    },
    "mappings" : {
      "dynamic_templates" : [
        {
          "strings_as_keywords" : {
            "mapping" : {
              "norms" : false,
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "ignore_above" : 256,
                  "type" : "keyword"
                }
              }
            },
            "match_mapping_type" : "string"
          }
        }
      ],
      "properties" : {
        "src_ips" : {
          "type" : "ip"
        },
        "dst_ips" : {
          "type" : "ip"
        }
      }
    },
    "aliases" : {
      "siem_alarms" : { },
      "siem_alarms_id_lookup" : { }
    }
  }
}

```

` GET /_template/siem_alarm_events`

```auto
{
  "siem_alarm_events" : {
    "order" : 0,
    "version" : 1,
    "index_patterns" : [
      "siem_alarm_events-*"
    ],
    "settings" : {
      "index" : {
        "number_of_shards" : "1",
        "number_of_replicas" : "0",
        "refresh_interval" : "1s"
      }
    },
    "mappings" : {
      "dynamic_templates" : [
        {
          "strings_as_keywords" : {
            "mapping" : {
              "norms" : false,
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "ignore_above" : 256,
                  "type" : "keyword"
                }
              }
            },
            "match_mapping_type" : "string"
          }
        }
      ]
    },
    "aliases" : { }
  }
}

```

However I can see index patterns `GET /_template/siem_alarms-*` and `GET /_template/siem_alarms`  
could that be the cause of the problem because I only need one

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 5, 2023, 2:01pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/17 "2023-07-05T14:01:15Z")

</div>

Dsiem is a correlation engine like Ossim

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 5, 2023, 2:06pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/18 "2023-07-05T14:06:06Z")

</div>

> [@pero](#):
>
> could that be the cause of the problem because I only need one

No, this is not the cause of the problem, the cause of the problem was already explained, you do not have any indice in your cluster that match your index pattern.

Those templates will be applied to any index named `siem_alarms-*` like `siem_alarms-2023.07`, and they have an alias to `siem_alarms`.

So if you have an index named `siem_alarms-2023.07.05` the index pattern will match this indice because of the alias.

But you do not have any index named `siem_alarms-*` in Elasticsearch.

If you have this data in other tool you need to explain how you get the data from that other tool and send them to Elasticsearch, because currently you do not have this data in Elasticsearch.

So the main issue is, how do you get data from Dsiem into Elasticsearch? What tool do you use? This processos is probably not working anymore.

Also, please do not tag people as already asked.

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 5, 2023, 2:38pm UTC](https://discuss.elastic.co/t/issues-with-elk/337326/19 "2023-07-05T14:38:41Z")

</div>

will look at my logstash pipeline then. because am using logstash to send my data from filebeat.

---

<div class="post-metadata">

**Author:** ![pero](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@pero](https://discuss.elastic.co/u/pero)\
**Post date:** [July 6, 2023, 10:39am UTC](https://discuss.elastic.co/t/issues-with-elk/337326/20 "2023-07-06T10:39:49Z")

</div>

I have it resolved. Am really grateful for the quick response from you all

[Next page](https://discuss.elastic.co/t/issues-with-elk/337326.md?page=2)
