# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=266

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 267

---

## [Kibana login tracking](https://discuss.elastic.co/t/kibana-login-tracking/346684)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 3\
**Last updated:** [November 28, 2023, 2:14pm UTC](https://discuss.elastic.co/t/kibana-login-tracking/346684 "2023-11-28T14:14:15Z")

</div>

Hi team, Is there a way to know who logged in kibana using specific username? If so, is IP information included? Kibana version used is 7.9.2

---

## [Create a new index with the query's result](https://discuss.elastic.co/t/create-a-new-index-with-the-querys-result/347353)

<div class="topic-metadata">

**Author:** [@Mathieu64](https://discuss.elastic.co/u/Mathieu64)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:00pm UTC](https://discuss.elastic.co/t/create-a-new-index-with-the-querys-result/347353 "2023-11-28T14:00:26Z")

</div>

Hi, I want to send the query's result in a new index : GET myindex/\_search { "size" : 0, "\_source" : false, "aggregations" : { "groupby" : { "composite" : { "size" : 1000, "sources" : \[ …

---

## [No alive nodes. All the 5 nodes seem to be down](https://discuss.elastic.co/t/no-alive-nodes-all-the-5-nodes-seem-to-be-down/348138)

<div class="topic-metadata">

**Author:** [@Test\_Owner](https://discuss.elastic.co/u/Test_Owner)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:15pm UTC](https://discuss.elastic.co/t/no-alive-nodes-all-the-5-nodes-seem-to-be-down/348138 "2023-11-28T13:15:56Z")

</div>

"No alive nodes. All the 5 nodes seem to be down". I get such a problem when executing a request. Previously, the request was executed correctly, but with the increase in records, I have such a problem. What can you adv…

---

## [Elastic-agent entry /proc/net/udp not found](https://discuss.elastic.co/t/elastic-agent-entry-proc-net-udp-not-found/348140)

<div class="topic-metadata">

**Author:** [@atbc](https://discuss.elastic.co/u/atbc)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 12:40pm UTC](https://discuss.elastic.co/t/elastic-agent-entry-proc-net-udp-not-found/348140 "2023-11-28T12:40:33Z")

</div>

Hello, I set up a Fleet server and on this same policy I added a Juniper integration, I see that it listens on the specified ports with the command "sudo ss -tulpn" and I can see the logs arriving with a TCPDUMP. But I …

---

## [Logstash elasticsearch input plugin](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin/347207)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 3\
**Last updated:** [November 28, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin/347207 "2023-11-28T12:39:22Z")

</div>

Hello dears, i am trying to create logstash job that have input from elasticsearch index pattern and to take a specific logs then to save them in a historical index so the configuration as below, input{ elasticsearch …

---

## [How do I configure multiple Kibana modules in metricbeat?](https://discuss.elastic.co/t/how-do-i-configure-multiple-kibana-modules-in-metricbeat/348108)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 12:18pm UTC](https://discuss.elastic.co/t/how-do-i-configure-multiple-kibana-modules-in-metricbeat/348108 "2023-11-28T12:18:35Z")

</div>

I am setting up a dedicated ES cluster for monitoring a production clusted as per official ES documentation. I'm able to get the metrics of ES, and now am trying to get the metrics of the two instances of production Kiba…

---

## [Elasticsearch 8.11.1 fails when using AWS IAM roles for service accounts](https://discuss.elastic.co/t/elasticsearch-8-11-1-fails-when-using-aws-iam-roles-for-service-accounts/347766)

<div class="topic-metadata">

**Author:** [@mornie](https://discuss.elastic.co/u/mornie)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 11:01am UTC](https://discuss.elastic.co/t/elasticsearch-8-11-1-fails-when-using-aws-iam-roles-for-service-accounts/347766 "2023-11-28T11:01:59Z")

</div>

Hi Team I am using eck-operator-2.10.0, and when upgrading the elastic stack from 8.11.0 to 8.11.1, the elasticsearch pods is stuck in an crashloopbackoff state. I have configured AWS IAM roles for service accounts (IR…

---

## [Problem in send log consistently with filebeat](https://discuss.elastic.co/t/problem-in-send-log-consistently-with-filebeat/348121)

<div class="topic-metadata">

**Author:** [@behzad\_alipoor](https://discuss.elastic.co/u/behzad_alipoor)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 10:07am UTC](https://discuss.elastic.co/t/problem-in-send-log-consistently-with-filebeat/348121 "2023-11-28T10:07:30Z")

</div>

i have problem in sending logs with filebeat to elasticsearch . it sends data and pauses and after miliseconds it sends again data . i set this config : scan\_frequency: 10s close\_inactive: 20s ignore\_older: 30s …

---

## [OpenAI connect with elastic search datasource](https://discuss.elastic.co/t/openai-connect-with-elastic-search-datasource/347901)

<div class="topic-metadata">

**Author:** [@Saurabh\_Agrawal2](https://discuss.elastic.co/u/Saurabh_Agrawal2)\
**Replies:** 5\
**Last updated:** [November 28, 2023, 9:59am UTC](https://discuss.elastic.co/t/openai-connect-with-elastic-search-datasource/347901 "2023-11-28T09:59:18Z")

</div>

I am trying call openAI with my custom index created on Elastic search but when I try to run it I am getting following error: openai.BadRequestError: Error code: 400 - {'error': {'requestid': 'aaa-bbb-404d-8a12-3da23608…

---

## [How to identify the IIS logs in Microsoft Exchange server?](https://discuss.elastic.co/t/how-to-identify-the-iis-logs-in-microsoft-exchange-server/347682)

<div class="topic-metadata">

**Author:** [@DW0728](https://discuss.elastic.co/u/DW0728)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 3:49am UTC](https://discuss.elastic.co/t/how-to-identify-the-iis-logs-in-microsoft-exchange-server/347682 "2023-11-28T03:49:57Z")

</div>

How to identify the client IP info in IIS logs? To have this info, we would like to create a IP Map to quickly know where the mail account is logged on. But currently seems it hard to figure out the client ip info in IIS…

---

## [Data\_stream.namespace in subject for Jira Action](https://discuss.elastic.co/t/data-stream-namespace-in-subject-for-jira-action/347459)

<div class="topic-metadata">

**Author:** [@jguilford](https://discuss.elastic.co/u/jguilford)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:36am UTC](https://discuss.elastic.co/t/data-stream-namespace-in-subject-for-jira-action/347459 "2023-11-28T01:36:54Z")

</div>

Trying to use the data\_stream.namespace in the subject for Jira Action, but it does not pull any data, I see the data in the json for the alert. Please help. { "\_index": ".internal.alerts-security.alerts-default-000001…

---

## [Healthy agents not appearing in endpoint security](https://discuss.elastic.co/t/healthy-agents-not-appearing-in-endpoint-security/347239)

<div class="topic-metadata">

**Author:** [@eric10](https://discuss.elastic.co/u/eric10)\
**Replies:** 3\
**Last updated:** [November 27, 2023, 10:48pm UTC](https://discuss.elastic.co/t/healthy-agents-not-appearing-in-endpoint-security/347239 "2023-11-27T22:48:53Z")

</div>

I'm having issues finding any information on this... I've seen similar posts, but i see that they've been closed out due to no response... I have a healthy agent on a windows host that is able to successfully enroll into…

---

## [Elasticsearch TSDS and geo\_point as dimension](https://discuss.elastic.co/t/elasticsearch-tsds-and-geo-point-as-dimension/347674)

<div class="topic-metadata">

**Author:** [@berg](https://discuss.elastic.co/u/berg)\
**Replies:** 2\
**Last updated:** [November 27, 2023, 10:54pm UTC](https://discuss.elastic.co/t/elasticsearch-tsds-and-geo-point-as-dimension/347674 "2023-11-27T22:54:33Z")

</div>

We are migrating some data sources across to a new cluster, and we have some wireless metrics that count the number of connected devices on each floor of each building. This seemed like an effective use case for TSDS, a…

---

## [Elastic Security - what is the difference between adding something to the fleet, and a host / endpoint?](https://discuss.elastic.co/t/elastic-security-what-is-the-difference-between-adding-something-to-the-fleet-and-a-host-endpoint/348086)

<div class="topic-metadata">

**Author:** [@jordan\_pritchard](https://discuss.elastic.co/u/jordan_pritchard)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 8:56pm UTC](https://discuss.elastic.co/t/elastic-security-what-is-the-difference-between-adding-something-to-the-fleet-and-a-host-endpoint/348086 "2023-11-27T20:56:11Z")

</div>

Hi - I've been testing deploying Elastic Agent. The agent installs without error and I see the agent show up in the fleet, but on roughly half the servers I am testing on, I don't see them show up in Hosts or Endpoints. …

---

## [Unable to search phrase anywhere in the text](https://discuss.elastic.co/t/unable-to-search-phrase-anywhere-in-the-text/348081)

<div class="topic-metadata">

**Author:** [@Mistgun\_Scripts](https://discuss.elastic.co/u/Mistgun_Scripts)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 8:10pm UTC](https://discuss.elastic.co/t/unable-to-search-phrase-anywhere-in-the-text/348081 "2023-11-27T20:10:12Z")

</div>

So I'm trying to search for a given phrase in text, already tried different methods e.g match\_phrase/query\_string but I still get invalid results. Let's say we have such documents with titles: "This is a phrase" "Anot…

---

## [Anomaly Detection for input logs (Elastic Agents)](https://discuss.elastic.co/t/anomaly-detection-for-input-logs-elastic-agents/346073)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 20\
**Last updated:** [November 27, 2023, 5:26pm UTC](https://discuss.elastic.co/t/anomaly-detection-for-input-logs-elastic-agents/346073 "2023-11-27T17:26:14Z")

</div>

I want to create something like a Machine Learning or Threshold rule that triggers when my infrastructure loses events from elastic agents. For example, the medium of events per day is 500k logs. But if I will get only …

---

## [How to view file content](https://discuss.elastic.co/t/how-to-view-file-content/348036)

<div class="topic-metadata">

**Author:** [@min\_liu](https://discuss.elastic.co/u/min_liu)\
**Replies:** 4\
**Last updated:** [November 27, 2023, 3:45pm UTC](https://discuss.elastic.co/t/how-to-view-file-content/348036 "2023-11-27T15:45:03Z")

</div>

I would like to know what is written inside the Elasticsearch data directory file. Is there a tool available to view the file content? thanks

---

## [Elastic Forwarder for Cloudwatch](https://discuss.elastic.co/t/elastic-forwarder-for-cloudwatch/348056)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elastic-forwarder-for-cloudwatch/348056 "2023-11-27T13:49:39Z")

</div>

Hi, We're using the Elastic Serverless forwarder with Cloudwatch and I was wondering if anyone can clarify these questions? What are the parameters around the subscription filter, is it every time a new log hits Cloud…

---

## [Metricbeat, filebeat](https://discuss.elastic.co/t/metricbeat-filebeat/348049)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 2:42pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat/348049 "2023-11-27T14:42:28Z")

</div>

I am trying to find Metricbeat and filebeat versions for AIX systems, with no luck is elastic support AIX servers with filebeat and metricbeat?

---

## ["Input not supported" with File Integrity Monitoring on Elastic Agent](https://discuss.elastic.co/t/input-not-supported-with-file-integrity-monitoring-on-elastic-agent/346671)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 12:35pm UTC](https://discuss.elastic.co/t/input-not-supported-with-file-integrity-monitoring-on-elastic-agent/346671 "2023-11-27T12:35:11Z")

</div>

As stated in the title, once adding the FIM integration to my Ubuntu 22.04 server. The fleet agent turned "Unhealthy", and shows "input not supported". Once I remove the FIM integration, then everything works just fine a…

---

## [Update an event fields based on another event](https://discuss.elastic.co/t/update-an-event-fields-based-on-another-event/347975)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 5\
**Last updated:** [November 27, 2023, 12:25pm UTC](https://discuss.elastic.co/t/update-an-event-fields-based-on-another-event/347975 "2023-11-27T12:25:34Z")

</div>

Hi, i have some logs indexed in elasticsearch by logstash that provides two types of events: { "@timestamp": "Nov 23, 2023 @ 15:24:33.064", "Detection ID": "ldt:87654321", "logSource": "CS De…

---

## [Elastic serverless forwarder json formatting](https://discuss.elastic.co/t/elastic-serverless-forwarder-json-formatting/347959)

<div class="topic-metadata">

**Author:** [@vsv0001](https://discuss.elastic.co/u/vsv0001)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 11:45am UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-json-formatting/347959 "2023-11-27T11:45:01Z")

</div>

we write our logs in json format to cloudwatch. does elastic serverless forwarder have any way (Deploy Elastic Serverless Forwarder | Elastic Serverless Forwarder Guide | Elastic) to send the logs in a json structure to…

---

## [Keyword typed field partially matching user query](https://discuss.elastic.co/t/keyword-typed-field-partially-matching-user-query/348033)

<div class="topic-metadata">

**Author:** [@spino17](https://discuss.elastic.co/u/spino17)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 10:03am UTC](https://discuss.elastic.co/t/keyword-typed-field-partially-matching-user-query/348033 "2023-11-27T10:03:25Z")

</div>

I am using ES 7.9 version. I have a category index with document like doc\_1 = { "value": "laptops" } doc-2 = { "value": "air cooler" } with following schema: { "mappings": { "properties": { "v…

---

## [Elasticsearch configure 2 network host](https://discuss.elastic.co/t/elasticsearch-configure-2-network-host/348024)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 9:31am UTC](https://discuss.elastic.co/t/elasticsearch-configure-2-network-host/348024 "2023-11-27T09:31:09Z")

</div>

Hi, Is it possible to configure elasticsearch to be accessible for both localhost and and ip address?

---

## [Custom index not getting created in Kibana](https://discuss.elastic.co/t/custom-index-not-getting-created-in-kibana/347970)

<div class="topic-metadata">

**Author:** [@sunil\_s](https://discuss.elastic.co/u/sunil_s)\
**Replies:** 5\
**Last updated:** [November 27, 2023, 5:21am UTC](https://discuss.elastic.co/t/custom-index-not-getting-created-in-kibana/347970 "2023-11-27T05:21:12Z")

</div>

Unable to create new index in ES. Please find below Filebeat configuration filebeat.inputs: - type: log enabled: true paths: - xxx.log processors: - add\_cloud\_metadata: ~ - add\_docker\_metadata: ~ - add\_k…

---

## [Logstash filter to create a subfield based on specific text in a log message](https://discuss.elastic.co/t/logstash-filter-to-create-a-subfield-based-on-specific-text-in-a-log-message/347978)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 7:39pm UTC](https://discuss.elastic.co/t/logstash-filter-to-create-a-subfield-based-on-specific-text-in-a-log-message/347978 "2023-11-26T19:39:20Z")

</div>

I've been working on a Logstash configuration where I'm trying to create a subfield within the 'message1' field based on a specific text pattern ('Started'). Here's a snippet of my current Logstash filter: filter { gr…

---

## [NVMe storage with bitnami helm chart](https://discuss.elastic.co/t/nvme-storage-with-bitnami-helm-chart/347952)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 2\
**Last updated:** [November 26, 2023, 6:01pm UTC](https://discuss.elastic.co/t/nvme-storage-with-bitnami-helm-chart/347952 "2023-11-26T18:01:14Z")

</div>

Does bitnami helm chart support NVMe storage?

---

## [\[APM\] Using custom tags and labels for Latency and Error correlations](https://discuss.elastic.co/t/apm-using-custom-tags-and-labels-for-latency-and-error-correlations/347995)

<div class="topic-metadata">

**Author:** [@Jakub\_Zilinek](https://discuss.elastic.co/u/Jakub_Zilinek)\
**Replies:** 0\
**Last updated:** [November 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/apm-using-custom-tags-and-labels-for-latency-and-error-correlations/347995 "2023-11-26T14:38:14Z")

</div>

Hello, We are using Java/Kotlin OpenTelemetry SDK on our spring micro services. We would like to use new feature to analyse error and latency correlations more here - Find transaction latency and failure correlations | …

---

## [/etc/default/logstash](https://discuss.elastic.co/t/etc-default-logstash/347994)

<div class="topic-metadata">

**Author:** [@Tal\_Blat](https://discuss.elastic.co/u/Tal_Blat)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 1:57pm UTC](https://discuss.elastic.co/t/etc-default-logstash/347994 "2023-11-26T13:57:46Z")

</div>

Hi How do i add to logstash env file "/etc/default/logstash" a line with the following format: ELK\_SERVERS="host1:9200","host2:9200","host3:9200","host4:9200" Thanks

---

## [7.2 Rollover Command Fails](https://discuss.elastic.co/t/7-2-rollover-command-fails/347981)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 3\
**Last updated:** [November 26, 2023, 12:31pm UTC](https://discuss.elastic.co/t/7-2-rollover-command-fails/347981 "2023-11-26T12:31:47Z")

</div>

Course: Certified Elasticsearch Engineer Version: 8.1 Hi, in module 7.2, at the rollover step to refrewsh component template, the rollover solution fails due to missing items in the payload. POST my\_metrics-service.st…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=265)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=267)
