# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=264

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 265

---

## [Parsing problem when streaming a log file](https://discuss.elastic.co/t/parsing-problem-when-streaming-a-log-file/348268)

<div class="topic-metadata">

**Author:** [@Kyps](https://discuss.elastic.co/u/Kyps)\
**Replies:** 26\
**Last updated:** [December 1, 2023, 6:59pm UTC](https://discuss.elastic.co/t/parsing-problem-when-streaming-a-log-file/348268 "2023-12-01T18:59:02Z")

</div>

Hey everyone, I followed the Stream any log file guide, and have set up a local agent that listens to my log file. But every time I add a new log (manually to test) the parsing just isn't there when it gets indexed in K…

---

## [Logstash stuck](https://discuss.elastic.co/t/logstash-stuck/348442)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 5:54pm UTC](https://discuss.elastic.co/t/logstash-stuck/348442 "2023-12-01T17:54:47Z")

</div>

I am getting to get started with logstash and simply copy a csv file to another file using the following conf: input { file{ path =\> "/Users/test/Desktop/project/test.csv" start\_position =\> "beginning" } } fi…

---

## [I/O dispatch worker terminated abnormally](https://discuss.elastic.co/t/i-o-dispatch-worker-terminated-abnormally/348451)

<div class="topic-metadata">

**Author:** [@elaydi\_elagal](https://discuss.elastic.co/u/elaydi_elagal)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 5:01pm UTC](https://discuss.elastic.co/t/i-o-dispatch-worker-terminated-abnormally/348451 "2023-12-01T17:01:18Z")

</div>

In our production environment we try to fetch all the records based on index, but getting exception "Request cannot be executed i/o reactor status stopped" with high concurrency, we've encountered occasional connection …

---

## [Transmission of logs in real time mode](https://discuss.elastic.co/t/transmission-of-logs-in-real-time-mode/348319)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/transmission-of-logs-in-real-time-mode/348319 "2023-12-01T14:02:50Z")

</div>

Hello everybody Please tell me what the problem might be I have a mail server on which the filebeat agent is installed, it transfers data to another server on which logstash and elastic are installed I randomly displa…

---

## [How to change index rotation timezone for Elasticsearch 8.6 for UTC to localtimezone](https://discuss.elastic.co/t/how-to-change-index-rotation-timezone-for-elasticsearch-8-6-for-utc-to-localtimezone/348411)

<div class="topic-metadata">

**Author:** [@pix9](https://discuss.elastic.co/u/pix9)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 1:49pm UTC](https://discuss.elastic.co/t/how-to-change-index-rotation-timezone-for-elasticsearch-8-6-for-utc-to-localtimezone/348411 "2023-12-01T13:49:57Z")

</div>

Hi everyone, I am facing an issue while running queries on Elasticsearch, we are unable to fetch data between 12:00 AM to 05:30 AM, issue no data can be retrived from index between given time. Upon further investigatio…

---

## [How can I contact to sales?](https://discuss.elastic.co/t/how-can-i-contact-to-sales/348404)

<div class="topic-metadata">

**Author:** [@zabtech](https://discuss.elastic.co/u/zabtech)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 1:31pm UTC](https://discuss.elastic.co/t/how-can-i-contact-to-sales/348404 "2023-12-01T13:31:01Z")

</div>

First I apologize with my bad English. I try to contact with Sales but no one that send anything to my email. ( URL is https://www.elastic.co ) , So I need some advice and a lot of question to ask sale, because we intere…

---

## [Change tie breaker on aggregation](https://discuss.elastic.co/t/change-tie-breaker-on-aggregation/348434)

<div class="topic-metadata">

**Author:** [@Raphael\_Fidelis](https://discuss.elastic.co/u/Raphael_Fidelis)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 1:28pm UTC](https://discuss.elastic.co/t/change-tie-breaker-on-aggregation/348434 "2023-12-01T13:28:30Z")

</div>

Hello. As defined in the terms aggregation docs, Elastic uses alphabetical order as a tie-breaker for the aggregation results. However, I wanted to use the order that is returned by the query, i.e.: hits: \[ { …

---

## [How do we remove Help icon from top right corner in kibana 8.5.3](https://discuss.elastic.co/t/how-do-we-remove-help-icon-from-top-right-corner-in-kibana-8-5-3/347816)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-do-we-remove-help-icon-from-top-right-corner-in-kibana-8-5-3/347816 "2023-12-01T12:31:40Z")

</div>

Hi Team, we are trying to hide the Help Icon from Kibana 8.5.3 on top right corner as below after we logged in. Thanks.

---

## [How to correctly use \`search\_after\` for huge amount of records (100k+)?](https://discuss.elastic.co/t/how-to-correctly-use-search-after-for-huge-amount-of-records-100k/348426)

<div class="topic-metadata">

**Author:** [@MarinTakanov](https://discuss.elastic.co/u/MarinTakanov)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 11:03am UTC](https://discuss.elastic.co/t/how-to-correctly-use-search-after-for-huge-amount-of-records-100k/348426 "2023-12-01T11:03:59Z")

</div>

Can someone explain how to use search\_after for more than 100k records without fetching 10k records just to get the sort value of the last record just to get the next 10k records? Here's an example: I have 100 100 reco…

---

## [When migrating logstash from Centos to Debian I get the tag "\_grokparsefailure"](https://discuss.elastic.co/t/when-migrating-logstash-from-centos-to-debian-i-get-the-tag-grokparsefailure/348328)

<div class="topic-metadata">

**Author:** [@OptimusPrimary](https://discuss.elastic.co/u/OptimusPrimary)\
**Replies:** 5\
**Last updated:** [December 1, 2023, 8:54am UTC](https://discuss.elastic.co/t/when-migrating-logstash-from-centos-to-debian-i-get-the-tag-grokparsefailure/348328 "2023-12-01T08:54:27Z")

</div>

I need to migrate the ELK stack from Centos to Debian, on the server I installed the same version of logstash and the same settings, rights and configs, but the logs are not parsed. The tag "\_grokparsefailure" is assign…

---

## [Search on Array Field in ElasticSearch](https://discuss.elastic.co/t/search-on-array-field-in-elasticsearch/348406)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 8:12am UTC](https://discuss.elastic.co/t/search-on-array-field-in-elasticsearch/348406 "2023-12-01T08:12:00Z")

</div>

Hello, I have inserted data to an index from a csv file. And I have an Ids field like this whose datatype is a text or a keyword. "IDs": \[ "a07f1c55-e34b-467d-bfe2-f65f7e01ae61,3e7083d6-4e0c-4f7f-ac81-0d7c131ab58…

---

## [Dec 1st, 2023: \[EN\] Securing Elasticsearch with HashiCorp Vault](https://discuss.elastic.co/t/dec-1st-2023-en-securing-elasticsearch-with-hashicorp-vault/347280)

<div class="topic-metadata">

**Author:** [@framsouza](https://discuss.elastic.co/u/framsouza)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-1st-2023-en-securing-elasticsearch-with-hashicorp-vault/347280 "2023-12-01T08:00:52Z")

</div>

Are you utilizing both Elasticsearch and HashiCorp in your environment and seeking ways to connect the two? This concise article unveils the steps to effectively employ HashiCorp Vault for automated credential generat…

---

## [Update record in Kafka-Elastic Pipelines through Logstash](https://discuss.elastic.co/t/update-record-in-kafka-elastic-pipelines-through-logstash/348401)

<div class="topic-metadata">

**Author:** [@Alberuni\_Beruni](https://discuss.elastic.co/u/Alberuni_Beruni)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 7:31am UTC](https://discuss.elastic.co/t/update-record-in-kafka-elastic-pipelines-through-logstash/348401 "2023-12-01T07:31:51Z")

</div>

Hi, I am directly ingesting kafka recored from kafka topic to Elasticsearch server, if there is coming records is updated with the existing in Elasticsearch server so how can i handle it with logstash that if creation i…

---

## [I have installed a 7.17.3 metric beat and file beat, both the beats are unable to send data to the logstash](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 13\
**Last updated:** [December 1, 2023, 5:24am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018 "2023-12-01T05:24:15Z")

</div>

Hi Team, I have a 3 node elk cluster 7.17.3 , i have installed metricbeats and file beat on a new server , the logstash ports are opened(5044). i have checked telnet. the connection looks fine. The beats are unable to …

---

## [Overwriting supplied index micro-%{appName}%{+YYYY.MM.dd} with rollover alias vehicle-service](https://discuss.elastic.co/t/overwriting-supplied-index-micro-appname-yyyy-mm-dd-with-rollover-alias-vehicle-service/348354)

<div class="topic-metadata">

**Author:** [@Gaurav\_Sharma3](https://discuss.elastic.co/u/Gaurav_Sharma3)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/overwriting-supplied-index-micro-appname-yyyy-mm-dd-with-rollover-alias-vehicle-service/348354 "2023-12-01T04:05:04Z")

</div>

input { tcp { port =\> 5000 codec =\> json } } output { if \[appName\] =="user-service"{ elasticsearch { hosts =\> \["http://localhost:9200"\] index =\> "micro-%{appName}%{+YYYY.MM.dd}" # Use date-based index names i…

---

## [Problema de thread\_pool.write.queue\_size](https://discuss.elastic.co/t/problema-de-thread-pool-write-queue-size/348387)

<div class="topic-metadata">

**Author:** [@Kelvin\_A\_Escobar\_Mor](https://discuss.elastic.co/u/Kelvin_A_Escobar_Mor)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:41am UTC](https://discuss.elastic.co/t/problema-de-thread-pool-write-queue-size/348387 "2023-12-01T03:41:27Z")

</div>

Tengo problema con encolamiento en mis cluster esperimento problema de rendimeiento y en ocaciones mi cluster se cae por carga quisera saber cual es una buena alternativa para abordar temas de thread\_pool.write.queue\_siz…

---

## [How can I get a client ip of search request in ielasticsearch?](https://discuss.elastic.co/t/how-can-i-get-a-client-ip-of-search-request-in-ielasticsearch/348284)

<div class="topic-metadata">

**Author:** [@yunpeng.jiangyp](https://discuss.elastic.co/u/yunpeng.jiangyp)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 2:44am UTC](https://discuss.elastic.co/t/how-can-i-get-a-client-ip-of-search-request-in-ielasticsearch/348284 "2023-12-01T02:44:12Z")

</div>

Hi guys: I found a slow search request , but i didn't know the search request's client ip . Can I get a client ip of search request in elasticsearch?

---

## [Un acknowledged events in PQ](https://discuss.elastic.co/t/un-acknowledged-events-in-pq/348379)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 2:29am UTC](https://discuss.elastic.co/t/un-acknowledged-events-in-pq/348379 "2023-12-01T02:29:01Z")

</div>

Hi Team, Is there any way to check the ununacknowledged events from the Persistent Queue method. Unfortunately we are not able to use the metric queue\_persisted\_growth\_events to find the ununacknowledged. Regards Kan…

---

## [MongoDB Output plugin 3.1.7 error](https://discuss.elastic.co/t/mongodb-output-plugin-3-1-7-error/348372)

<div class="topic-metadata">

**Author:** [@Daniela\_Juliana\_Sanc](https://discuss.elastic.co/u/Daniela_Juliana_Sanc)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 11:18pm UTC](https://discuss.elastic.co/t/mongodb-output-plugin-3-1-7-error/348372 "2023-11-30T23:18:46Z")

</div>

Hi, I am not able to connect to MongoDB Compass Version 7.0.3 with below error.Using plugin version 3.1.7. \[WARN \]\[logstash.outputs.mongodb \]\[main\] MONGODB | Failed to handshake with localhost:27017: ArgumentError: wro…

---

## [Endpoint Agent clock problem in sleep mode](https://discuss.elastic.co/t/endpoint-agent-clock-problem-in-sleep-mode/347741)

<div class="topic-metadata">

**Author:** [@simoner](https://discuss.elastic.co/u/simoner)\
**Replies:** 4\
**Last updated:** [November 30, 2023, 11:14pm UTC](https://discuss.elastic.co/t/endpoint-agent-clock-problem-in-sleep-mode/347741 "2023-11-30T23:14:08Z")

</div>

Hello, I found a problem with Endpoint agent and sleep mode. When my computer wakes itself up from sleep mode Endpoint Agent logs: {"file":{"line":140,"name":"Entry.cpp"}}},"message":"Entry.cpp:140 The system clock ad…

---

## [ServiceNow SecOps connector](https://discuss.elastic.co/t/servicenow-secops-connector/348374)

<div class="topic-metadata">

**Author:** [@John\_McAfee1](https://discuss.elastic.co/u/John_McAfee1)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 10:20pm UTC](https://discuss.elastic.co/t/servicenow-secops-connector/348374 "2023-11-30T22:20:09Z")

</div>

Hello, I am testing the SecOps service now connector on my Personal Development Instance provided by serive now. I have followed the instructions outlined in the documentation: ServiceNow SecOps connector and action | …

---

## [Kibana degraded after upgrade](https://discuss.elastic.co/t/kibana-degraded-after-upgrade/348160)

<div class="topic-metadata">

**Author:** [@rudyfaile](https://discuss.elastic.co/u/rudyfaile)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 8:53pm UTC](https://discuss.elastic.co/t/kibana-degraded-after-upgrade/348160 "2023-11-30T20:53:35Z")

</div>

Hi, I upgraded my ELK stack running on self-hosted kubernetes. My Elasticsearch cluster is green, but my kibana instance is spewing error logs like: │ kibana \[2023-11-28T15:24:58.959+00:00\]\[ERROR\]\[plugins.taskManager\] …

---

## [NodeEnvironment.assertEnvIsLocked threw java.io.IOException: The device is not ready](https://discuss.elastic.co/t/nodeenvironment-assertenvislocked-threw-java-io-ioexception-the-device-is-not-ready/348089)

<div class="topic-metadata">

**Author:** [@blademan](https://discuss.elastic.co/u/blademan)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 8:46pm UTC](https://discuss.elastic.co/t/nodeenvironment-assertenvislocked-threw-java-io-ioexception-the-device-is-not-ready/348089 "2023-11-30T20:46:15Z")

</div>

ES is deployed on an Azure VMSS (Windows VMs). It's throwing java.io.IOException "The device is not ready" on some VMs when creating shards, while working well on some other VMs at the same time. Here is what the except…

---

## [Filebeat Context Error](https://discuss.elastic.co/t/filebeat-context-error/348366)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 8:41pm UTC](https://discuss.elastic.co/t/filebeat-context-error/348366 "2023-11-30T20:41:57Z")

</div>

I was able to push a new CEL input to Filebeat v8.7.1 via puppet. When we launch filebeat v.8.7.1 I see this message pop up in the log: {"log.level":"info","@timestamp":"2023-11-30T19:59:28.167Z","log.logger":"input.ce…

---

## [Can not create a document has mutlipolygon having hole](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/348177)

<div class="topic-metadata">

**Author:** [@Sai\_Suvam\_Patnaik](https://discuss.elastic.co/u/Sai_Suvam_Patnaik)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 6:31pm UTC](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/348177 "2023-11-30T18:31:07Z")

</div>

Hi, can anyone help me I am facing a following. Summary Can not create a document has mutlipolygon having hole. I do not know why responses reason is correct or this is bug? I have visualize the multipolygon, using …

---

## [\[Kibana\] High and inconsistent RAM usage after upgrade to 8.11.1](https://discuss.elastic.co/t/kibana-high-and-inconsistent-ram-usage-after-upgrade-to-8-11-1/347825)

<div class="topic-metadata">

**Author:** [@byildiz](https://discuss.elastic.co/u/byildiz)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 4:32pm UTC](https://discuss.elastic.co/t/kibana-high-and-inconsistent-ram-usage-after-upgrade-to-8-11-1/347825 "2023-11-30T16:32:22Z")

</div>

Hi guys, we have updated our Elastic Stack to the current latest version 8.11.1. But we have observed a higher RAM usage and data lacks related to the kibana instance, therefore we didn't continue to update our prod sta…

---

## [ML Anomaly Job with exclude\_frequent option](https://discuss.elastic.co/t/ml-anomaly-job-with-exclude-frequent-option/348047)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:53pm UTC](https://discuss.elastic.co/t/ml-anomaly-job-with-exclude-frequent-option/348047 "2023-11-30T14:53:51Z")

</div>

Hello everyone, i was reading through the docs and became curious Say i create two detectors. One detector is high\_sum(a) over b The other detector is high\_sum(a) by c. Now, if i define exclude\_frequent = over for …

---

## [Filebeat reads logs from various locations?](https://discuss.elastic.co/t/filebeat-reads-logs-from-various-locations/348332)

<div class="topic-metadata">

**Author:** [@Satsan](https://discuss.elastic.co/u/Satsan)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-reads-logs-from-various-locations/348332 "2023-11-30T14:16:27Z")

</div>

Filebeat reads logs from various locations in same yml file and sends them to the ELK (Elasticsearch, Logstash, and Kibana) stack for processing and analysis? For instance: -log.file.path: /etc/home/usr/logs -log.fil…

---

## [Unexpected Behavior of Kibana Query for Filtering Logs with Specific Keywords](https://discuss.elastic.co/t/unexpected-behavior-of-kibana-query-for-filtering-logs-with-specific-keywords/348055)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:04pm UTC](https://discuss.elastic.co/t/unexpected-behavior-of-kibana-query-for-filtering-logs-with-specific-keywords/348055 "2023-11-30T14:04:30Z")

</div>

I'm using a Kibana query (log\_message:(Started\* OR Disabled\*)) to filter logs that start with the keywords "Started" or "Disabled". However, I've noticed that this query also returns log lines containing these keywords i…

---

## [Watcher logging action - where do (which index) these logs come in?](https://discuss.elastic.co/t/watcher-logging-action-where-do-which-index-these-logs-come-in/348334)

<div class="topic-metadata">

**Author:** [@Edy\_Silva](https://discuss.elastic.co/u/Edy_Silva)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 1:58pm UTC](https://discuss.elastic.co/t/watcher-logging-action-where-do-which-index-these-logs-come-in/348334 "2023-11-30T13:58:53Z")

</div>

I have a watcher that is supposed to perform a logging action. When I execute the watch it says it went well but I can't find this log anywhere.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=263)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=265)
