# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=244

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 245

---

## [Connecting APM to logstash](https://discuss.elastic.co/t/connecting-apm-to-logstash/351124)

<div class="topic-metadata">

**Author:** [@Affan\_Mir](https://discuss.elastic.co/u/Affan_Mir)\
**Replies:** 0\
**Last updated:** [January 16, 2024, 7:13am UTC](https://discuss.elastic.co/t/connecting-apm-to-logstash/351124 "2024-01-16T07:13:26Z")

</div>

I want to connect my apm-server to my log stash that will do some preprocessing before dumping the metrics into Elasticsearch. According to the documentation listed at Configure the Logstash output | APM User Guide \[8.1…

---

## [Is it possible that with the help of SYSLOG we can push the present log events as well as the past history of events?](https://discuss.elastic.co/t/is-it-possible-that-with-the-help-of-syslog-we-can-push-the-present-log-events-as-well-as-the-past-history-of-events/351123)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [January 16, 2024, 6:58am UTC](https://discuss.elastic.co/t/is-it-possible-that-with-the-help-of-syslog-we-can-push-the-present-log-events-as-well-as-the-past-history-of-events/351123 "2024-01-16T06:58:28Z")

</div>

Any specific configuration required for that??

---

## [Filebeat CEL Input Type - FIle Options](https://discuss.elastic.co/t/filebeat-cel-input-type-file-options/350812)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 7:40pm UTC](https://discuss.elastic.co/t/filebeat-cel-input-type-file-options/350812 "2024-01-15T19:40:12Z")

</div>

I'm using a CEL type input in Filebeat. Currently the filebeat.yml file points at a specific directory/file. What is the syntax to wildcard a portion of the file? (i.e. for the parameter resource.url: file:///home/di…

---

## [Get error when config "value\_serializer" and "key\_serializer" in output part](https://discuss.elastic.co/t/get-error-when-config-value-serializer-and-key-serializer-in-output-part/351062)

<div class="topic-metadata">

**Author:** [@Pengcheng\_Fu](https://discuss.elastic.co/u/Pengcheng_Fu)\
**Replies:** 1\
**Last updated:** [January 15, 2024, 7:34pm UTC](https://discuss.elastic.co/t/get-error-when-config-value-serializer-and-key-serializer-in-output-part/351062 "2024-01-15T19:34:19Z")

</div>

I am testing transfer data between mutile kafka cluster my configuration is below: input { kafka { bootstrap\_servers =\> "10.62.169.206:9092,10.62.220.44:9092,10.62.220.150:9092" topics =\> \["prod-sk…

---

## [Does single node Elasticsearch supports ILM ploicy](https://discuss.elastic.co/t/does-single-node-elasticsearch-supports-ilm-ploicy/350124)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 41\
**Last updated:** [January 15, 2024, 6:46pm UTC](https://discuss.elastic.co/t/does-single-node-elasticsearch-supports-ilm-ploicy/350124 "2024-01-15T18:46:05Z")

</div>

Hello, I have applied the ILM policy because the disk space usage was seen very high. But I don't see any changes in the disk space after implementing the ILM policy for filebeat. shards disk.indices disk.used disk.to…

---

## [Question about Kibana connectors](https://discuss.elastic.co/t/question-about-kibana-connectors/351081)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [January 15, 2024, 4:23pm UTC](https://discuss.elastic.co/t/question-about-kibana-connectors/351081 "2024-01-15T16:23:05Z")

</div>

Hello, I was wandering, the kibana email connetor, is assume that's different from xpack.notification.email namespace in \`elasticsearch.yml. So from a watcher I can only use the xpack one? KR Henk

---

## [How to save a time range in kibana?](https://discuss.elastic.co/t/how-to-save-a-time-range-in-kibana/351065)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 4:12pm UTC](https://discuss.elastic.co/t/how-to-save-a-time-range-in-kibana/351065 "2024-01-15T16:12:28Z")

</div>

I've seen in some kibana instances that instead of selecting the preconfigured range (1 day, 7 days, etc) you can store a custom timerange with a name. Any idea how to do it?

---

## [I want know the elastic search enterprise version pricing model](https://discuss.elastic.co/t/i-want-know-the-elastic-search-enterprise-version-pricing-model/351073)

<div class="topic-metadata">

**Author:** [@Pintu](https://discuss.elastic.co/u/Pintu)\
**Replies:** 1\
**Last updated:** [January 15, 2024, 2:55pm UTC](https://discuss.elastic.co/t/i-want-know-the-elastic-search-enterprise-version-pricing-model/351073 "2024-01-15T14:55:06Z")

</div>

I want to know the enterprise version pricing model

---

## [Ensuring Document Ordering in Bulk Ingestion](https://discuss.elastic.co/t/ensuring-document-ordering-in-bulk-ingestion/350972)

<div class="topic-metadata">

**Author:** [@Ivelin\_Yanev](https://discuss.elastic.co/u/Ivelin_Yanev)\
**Replies:** 11\
**Last updated:** [January 15, 2024, 2:41pm UTC](https://discuss.elastic.co/t/ensuring-document-ordering-in-bulk-ingestion/350972 "2024-01-15T14:41:04Z")

</div>

Hi everyone, I'm currently working on implementing bulk operations for documents. In my scenario, I receive PubSub messages and generate corresponding Elasticsearch documents using the data from these PubSub messages. I…

---

## [Release Notes Page of 8.11.4 for Kibana unavailable](https://discuss.elastic.co/t/release-notes-page-of-8-11-4-for-kibana-unavailable/351008)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [January 15, 2024, 1:27pm UTC](https://discuss.elastic.co/t/release-notes-page-of-8-11-4-for-kibana-unavailable/351008 "2024-01-15T13:27:59Z")

</div>

Please check https://www.elastic.co/guide/en/kibana/8.11/release-notes-8.11.4.html

---

## [Error when recovering snapshot](https://discuss.elastic.co/t/error-when-recovering-snapshot/350640)

<div class="topic-metadata">

**Author:** [@Epic555](https://discuss.elastic.co/u/Epic555)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/error-when-recovering-snapshot/350640 "2024-01-15T10:27:44Z")

</div>

I created a snapshot with curl from 1 cluster. When I try to recover a snapshot with curl on another cluster, 2nd Cluster cannot allocate all indices. Cluster 1 has 2 nodes, cluster 2 has 1 node. I have a file "snap-hb19…

---

## [Kibana not starting & Cluster Status Yellow](https://discuss.elastic.co/t/kibana-not-starting-cluster-status-yellow/351052)

<div class="topic-metadata">

**Author:** [@aguskhohar](https://discuss.elastic.co/u/aguskhohar)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/kibana-not-starting-cluster-status-yellow/351052 "2024-01-15T10:27:18Z")

</div>

Hi guys, Could you help me, why my kibana not starting, and im check the cluster status Yellow? Collect in elastic Log : \[2024-01-14T22:53:17,827\]\[INFO \]\[o.e.i.m.MapperService \] \[Desktop\] \[.kibana-observability-ai-…

---

## [Error connecting to package registry : reason: self-signed certificate in certificate chain](https://discuss.elastic.co/t/error-connecting-to-package-registry-reason-self-signed-certificate-in-certificate-chain/351057)

<div class="topic-metadata">

**Author:** [@Gabin\_17](https://discuss.elastic.co/u/Gabin_17)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 8:40am UTC](https://discuss.elastic.co/t/error-connecting-to-package-registry-reason-self-signed-certificate-in-certificate-chain/351057 "2024-01-15T08:40:52Z")

</div>

Hello everyone ! I have this issue when i start Kibana. I saw different solution on linux but not on windows and I work on windows Failed to fetch latest version of synthetics from registry: Error connecting to package…

---

## [I'm facing .elasticsearch.bootstrap.StartupException: java.lang.IllegalArgumentException: you cannot specify a keystore and key file](https://discuss.elastic.co/t/im-facing-elasticsearch-bootstrap-startupexception-java-lang-illegalargumentexception-you-cannot-specify-a-keystore-and-key-file/350942)

<div class="topic-metadata">

**Author:** [@bshiwanand](https://discuss.elastic.co/u/bshiwanand)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 8:15am UTC](https://discuss.elastic.co/t/im-facing-elasticsearch-bootstrap-startupexception-java-lang-illegalargumentexception-you-cannot-specify-a-keystore-and-key-file/350942 "2024-01-15T08:15:22Z")

</div>

I'm trying to enable xpack security enable so that internal and external communication will happen on https instead of http so please guide me how I do that, and guide me how to resolve below error. Error: {"type": "de…

---

## [Index pattern has no field but the other index pattern is working properly, i can't also connect to mapping using curl](https://discuss.elastic.co/t/index-pattern-has-no-field-but-the-other-index-pattern-is-working-properly-i-cant-also-connect-to-mapping-using-curl/350540)

<div class="topic-metadata">

**Author:** [@Epangilinangt](https://discuss.elastic.co/u/Epangilinangt)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 3:15am UTC](https://discuss.elastic.co/t/index-pattern-has-no-field-but-the-other-index-pattern-is-working-properly-i-cant-also-connect-to-mapping-using-curl/350540 "2024-01-15T03:15:18Z")

</div>

Index pattern has no field but the other index pattern is working properly, i can't also connect to mapping using curl

---

## [The logstash reload config manually not work](https://discuss.elastic.co/t/the-logstash-reload-config-manually-not-work/350895)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 1:03am UTC](https://discuss.elastic.co/t/the-logstash-reload-config-manually-not-work/350895 "2024-01-15T01:03:54Z")

</div>

as the topic, i send the kill -SIGHUP xxx to the logstash ,but the config still same. version 8.11.3 linux: Linux CS-gxxt-tyzj-03 4.19.90-52.22.v2207.ky10.aarch64 #1 SMP Tue Mar 14 11:52:45 CST 2023 aarch64 aarch64 aar…

---

## [Rollover not working, Filebeat default index does not have an alias](https://discuss.elastic.co/t/rollover-not-working-filebeat-default-index-does-not-have-an-alias/350655)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 8\
**Last updated:** [January 14, 2024, 5:19pm UTC](https://discuss.elastic.co/t/rollover-not-working-filebeat-default-index-does-not-have-an-alias/350655 "2024-01-14T17:19:15Z")

</div>

Hello, I would like to use rollover to delete all logs, however, I always get an error message. It does not work. I can use only if turn of rollover. I do not modify anything on indexes, I use default Indexes after inst…

---

## [Elastic Detection Rules](https://discuss.elastic.co/t/elastic-detection-rules/351032)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 0\
**Last updated:** [January 14, 2024, 5:01pm UTC](https://discuss.elastic.co/t/elastic-detection-rules/351032 "2024-01-14T17:01:48Z")

</div>

I want to make a rule that trigger an alert when The Ids Generates certain alert. Let's assume I have an IDS rule says that when Facebook is accessed trigger an alert. I want to make a rule in siem also to Trigger to te…

---

## [Elasticsearch node is at 100% disk usage, unable to edit configuration](https://discuss.elastic.co/t/elasticsearch-node-is-at-100-disk-usage-unable-to-edit-configuration/351017)

<div class="topic-metadata">

**Author:** [@Sanskar\_Panchal](https://discuss.elastic.co/u/Sanskar_Panchal)\
**Replies:** 5\
**Last updated:** [January 14, 2024, 4:18pm UTC](https://discuss.elastic.co/t/elasticsearch-node-is-at-100-disk-usage-unable-to-edit-configuration/351017 "2024-01-14T16:18:45Z")

</div>

Hi, One of my Elasticsearch instance is at 100% disk usage. Which has resulted into NODE\_LEFT. Which then caused " This cluster has 39 unavailable primaries, 101 unavailable replicas." And cluster is now at red healt…

---

## [Sizing Elastic Stack for a PoC (security use case)](https://discuss.elastic.co/t/sizing-elastic-stack-for-a-poc-security-use-case/350733)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 6\
**Last updated:** [January 14, 2024, 2:12pm UTC](https://discuss.elastic.co/t/sizing-elastic-stack-for-a-poc-security-use-case/350733 "2024-01-14T14:12:04Z")

</div>

Hello Everyone, I was asked to make a PoC to show the capability the Elastic as a SIEM so the PoC will take logs from (Fortigate Firewall, Two WIndows PCs, one Windows server for file sharing) So I will setup Elasticsea…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[actions-logs\] does not point to index \[actions-logs\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 7\
**Last updated:** [January 14, 2024, 11:04am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916 "2024-01-14T11:04:16Z")

</div>

Got a template with this { "index": { "lifecycle": { "name": "logstash-policy", "rollover\_alias": "actions-logs" }, "number\_of\_replicas": "0" } } Got index with name "actions-logs" But at index "actiong-logs…

---

## [Elastic Agent](https://discuss.elastic.co/t/elastic-agent/350581)

<div class="topic-metadata">

**Author:** [@Marcus\_Berglund](https://discuss.elastic.co/u/Marcus_Berglund)\
**Replies:** 3\
**Last updated:** [January 14, 2024, 9:59am UTC](https://discuss.elastic.co/t/elastic-agent/350581 "2024-01-14T09:59:51Z")

</div>

Hi, My goal is to collect system metrics for a server e.g CPU, Disk etc. I have installed the elastic agent on the server and it show up as healthy in fleet server but there are no metrics. Do I really need to install m…

---

## [Elasticsearch incomplete logs](https://discuss.elastic.co/t/elasticsearch-incomplete-logs/350899)

<div class="topic-metadata">

**Author:** [@Krishna94](https://discuss.elastic.co/u/Krishna94)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 1:37pm UTC](https://discuss.elastic.co/t/elasticsearch-incomplete-logs/350899 "2024-01-13T13:37:32Z")

</div>

Hi, I have filebeat to read my inputs and logstash is the shipper to elasticsearch. But could found that the data in filebeat is not sending to elasticsearch completely. Pls do help. Thank you Athira Krishna

---

## [Elastic Agent and index names](https://discuss.elastic.co/t/elastic-agent-and-index-names/350985)

<div class="topic-metadata">

**Author:** [@wrender1](https://discuss.elastic.co/u/wrender1)\
**Replies:** 5\
**Last updated:** [January 13, 2024, 1:21pm UTC](https://discuss.elastic.co/t/elastic-agent-and-index-names/350985 "2024-01-13T13:21:30Z")

</div>

I'm deploying the Elastic Agent in standalone on Kubernetes. I've got he default yaml file, but I'm having a hard time with the index naming that it creates. It is a little unclear to me from the documentation. Do the i…

---

## [installing SIEM in ELK](https://discuss.elastic.co/t/installing-siem-in-elk/350008)

<div class="topic-metadata">

**Author:** [@Maksim\_Alchinov](https://discuss.elastic.co/u/Maksim_Alchinov)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:55am UTC](https://discuss.elastic.co/t/installing-siem-in-elk/350008 "2024-01-13T09:55:14Z")

</div>

Hello, I have installed the EKL stack on my test stand, for further work and analysis of logs we need to install SIEM. How can this be done? How can I load correlation rules for log analysis?

---

## [A node in my elasticsearch has full disk](https://discuss.elastic.co/t/a-node-in-my-elasticsearch-has-full-disk/350811)

<div class="topic-metadata">

**Author:** [@Tai\_Nguyen\_Huu](https://discuss.elastic.co/u/Tai_Nguyen_Huu)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:12am UTC](https://discuss.elastic.co/t/a-node-in-my-elasticsearch-has-full-disk/350811 "2024-01-13T09:12:49Z")

</div>

Hi all, I have a elasticsearch cluster with 10 node, one node in my elasticsearch had full disk and it was removed from cluster by elasticsearch. the Disk of other nodes in my cluster still have 70% disk. How to I can re…

---

## [How to configure login kibana custom file build version 8.5.0?](https://discuss.elastic.co/t/how-to-configure-login-kibana-custom-file-build-version-8-5-0/351004)

<div class="topic-metadata">

**Author:** [@Cody-Test](https://discuss.elastic.co/u/Cody-Test)\
**Replies:** 0\
**Last updated:** [January 13, 2024, 4:50am UTC](https://discuss.elastic.co/t/how-to-configure-login-kibana-custom-file-build-version-8-5-0/351004 "2024-01-13T04:50:09Z")

</div>

Hello Guy, I can't configure or edit the default login page of the Kibana application on Linux using the .deb package after extracting the current storage directory at /usr/share/kibana/x-pack/plugins/security/security.…

---

## [Recreate the automatically generated certificates](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987)

<div class="topic-metadata">

**Author:** [@pxeedust](https://discuss.elastic.co/u/pxeedust)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 10:25pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987 "2024-01-12T22:25:55Z")

</div>

Sorry for the beginner question, but I am having trouble regenerating the certificates that were made at deployment. I'm not familiar with how certificates work so I was hoping there might be a script that just regenerat…

---

## [Panw.panos TCP grok errors](https://discuss.elastic.co/t/panw-panos-tcp-grok-errors/350993)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 10:03pm UTC](https://discuss.elastic.co/t/panw-panos-tcp-grok-errors/350993 "2024-01-12T22:03:55Z")

</div>

Good day all. I have a question about the Palo Alto Next-Gen Firewall integration. It has two input types, TCP and UDP. We have a client that wanted to move from the UDP to the TCP/SSL connection for security, so we did…

---

## [Support for script\_score in function\_score in Golang client](https://discuss.elastic.co/t/support-for-script-score-in-function-score-in-golang-client/350991)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:34pm UTC](https://discuss.elastic.co/t/support-for-script-score-in-function-score-in-golang-client/350991 "2024-01-12T21:34:41Z")

</div>

Hi. The docs show the following example for using script\_score within function\_score: "query" : { "score\_mode": "multiply", "rescore\_query" : { "function\_score" : { "script\_s…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=243)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=245)
