# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=281

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 282

---

## [Oracle DB monitoring - Error while running metricbeat](https://discuss.elastic.co/t/oracle-db-monitoring-error-while-running-metricbeat/346084)

<div class="topic-metadata">

**Author:** [@nandhini\_r](https://discuss.elastic.co/u/nandhini_r)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 6:35am UTC](https://discuss.elastic.co/t/oracle-db-monitoring-error-while-running-metricbeat/346084 "2023-10-31T06:35:19Z")

</div>

Hi, I have been struggle on how to monitored an oracle DB instance, using the ELK stack. I have install everything Elasticsearch, Logstash, Kibana, Metricbeat but I am getting some error and I will attach the error in t…

---

## [Kibana cookies contain "--" characters in the SID which causes the user requests to get blocked in the azure WAF](https://discuss.elastic.co/t/kibana-cookies-contain-characters-in-the-sid-which-causes-the-user-requests-to-get-blocked-in-the-azure-waf/346087)

<div class="topic-metadata">

**Author:** [@sahadev\_d](https://discuss.elastic.co/u/sahadev_d)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 5:45am UTC](https://discuss.elastic.co/t/kibana-cookies-contain-characters-in-the-sid-which-causes-the-user-requests-to-get-blocked-in-the-azure-waf/346087 "2023-10-31T05:45:08Z")

</div>

Hi Community, We are facing issue while using kibana using with URL, Whenever the user log-in to kibana with the RBAs user creds the user gets 403 error from the kibana servers. As we debugged the issue we came to know…

---

## [ElasticEndpoint authorization is automatically closed in FDA](https://discuss.elastic.co/t/elasticendpoint-authorization-is-automatically-closed-in-fda/345693)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 3:42am UTC](https://discuss.elastic.co/t/elasticendpoint-authorization-is-automatically-closed-in-fda/345693 "2023-10-31T03:42:26Z")

</div>

After installing elastic agent versions 8.4.1 and 8.9.1, I have clicked and checked in FDA to authorize ElasticEndpoint. However, after running on the computer for a period of time, the authorization of ElasticEndpoint i…

---

## [ElasticSearch Fleet - Outdated Policy](https://discuss.elastic.co/t/elasticsearch-fleet-outdated-policy/346082)

<div class="topic-metadata">

**Author:** [@crypt0ace](https://discuss.elastic.co/u/crypt0ace)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 3:37am UTC](https://discuss.elastic.co/t/elasticsearch-fleet-outdated-policy/346082 "2023-10-31T03:37:25Z")

</div>

Hello! I just added a Windows integration in my home lab in the Elasticsearch and I got this error Then when i view the integrations I can see Windows got added but I can also see this "Outdated Policy" with my agen…

---

## [Elastic data large exception (Data too large, data for \[http\_request\])](https://discuss.elastic.co/t/elastic-data-large-exception-data-too-large-data-for-http-request/345907)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 12:25am UTC](https://discuss.elastic.co/t/elastic-data-large-exception-data-too-large-data-for-http-request/345907 "2023-10-31T00:25:14Z")

</div>

Hello, Could you please help on below issue . we getting this issue on Elastic and kibana. \`1e9fa016\]\[trial #34\] null during Elasticsearch operation (ElasticsearchStatusException\[Elasticsearch exception \[type=circuit\_b…

---

## [Data too large for response \[parent\]](https://discuss.elastic.co/t/data-too-large-for-response-parent/346048)

<div class="topic-metadata">

**Author:** [@uhlirradek95](https://discuss.elastic.co/u/uhlirradek95)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 12:22am UTC](https://discuss.elastic.co/t/data-too-large-for-response-parent/346048 "2023-10-31T00:22:48Z")

</div>

Hi, could you please help me to understand following exception? Cluster configuration: 3 nodes each 6CPU, 32GB RAM, completely on SSD While making a search request, following exception occours: \[Invalid response ret…

---

## [Syslog severity and facility not set when upgrading version](https://discuss.elastic.co/t/syslog-severity-and-facility-not-set-when-upgrading-version/345695)

<div class="topic-metadata">

**Author:** [@Andrea\_De\_Pinto](https://discuss.elastic.co/u/Andrea_De_Pinto)\
**Replies:** 3\
**Last updated:** [October 30, 2023, 3:13pm UTC](https://discuss.elastic.co/t/syslog-severity-and-facility-not-set-when-upgrading-version/345695 "2023-10-30T15:13:31Z")

</div>

Hi, I did the migration from the version 6.8 to the 8.9 and I have a logstash pipeline that use the syslog to feed my elasticsearch. This is the configuration I have on the 6.8 : input { syslog { type =\> "sy…

---

## [How to handle unmapped fields](https://discuss.elastic.co/t/how-to-handle-unmapped-fields/345991)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 4\
**Last updated:** [October 30, 2023, 2:35pm UTC](https://discuss.elastic.co/t/how-to-handle-unmapped-fields/345991 "2023-10-30T14:35:14Z")

</div>

filter { grok { id =\> "name school grok filter" match =\> { 'message' =\> '^.\*name=\\'%{WORD:student.name}\\'.\*school=\\'%{WORD:student.school}\\''} } } For example, with WORD:student.name I would like to create a…

---

## [Extract Exception Class](https://discuss.elastic.co/t/extract-exception-class/346046)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:21pm UTC](https://discuss.elastic.co/t/extract-exception-class/346046 "2023-10-30T14:21:54Z")

</div>

Hello, what is the best way to extract the exception from the following log? I only need the exception class NullpointerException e.g. My attempt: %{TIMESTAMP\_ISO8601:log\_timestamp}.%{LOGLEVEL:log\_level}.\[%{GREEDYDATA:…

---

## [search profile breakdown](https://discuss.elastic.co/t/search-profile-breakdown/346041)

<div class="topic-metadata">

**Author:** [@getsolaris](https://discuss.elastic.co/u/getsolaris)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:17pm UTC](https://discuss.elastic.co/t/search-profile-breakdown/346041 "2023-10-30T14:17:59Z")

</div>

hello, I'm using Elasticsearch's profile API to try and figure out what's taking so long. I currently have an index implemented with parent-child modeling. When I run a has\_child query, I am getting a high match in my…

---

## [Sync Postgresql and Elasticsearch using Filebeat](https://discuss.elastic.co/t/sync-postgresql-and-elasticsearch-using-filebeat/345576)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 1:43pm UTC](https://discuss.elastic.co/t/sync-postgresql-and-elasticsearch-using-filebeat/345576 "2023-10-30T13:43:55Z")

</div>

Hi, I have a considerable amount of information in a Postgresql database. Registers are inserted on this database on demand. We are currently interested in syncronize this database and Elasticsearch in order to have the…

---

## [ELK | Logging | filter out specific ip's generated WARNs?](https://discuss.elastic.co/t/elk-logging-filter-out-specific-ips-generated-warns/346040)

<div class="topic-metadata">

**Author:** [@LucGasper](https://discuss.elastic.co/u/LucGasper)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 1:33pm UTC](https://discuss.elastic.co/t/elk-logging-filter-out-specific-ips-generated-warns/346040 "2023-10-30T13:33:04Z")

</div>

Hi elk lovers, in our Company we are subjected daily to security penetration tests. All these tests are originated by a specific static ip. Our elasticsearch log is therefore filled up with WARNs, especially: ... \[2…

---

## [Elasticsearch node ram.percent at 100%](https://discuss.elastic.co/t/elasticsearch-node-ram-percent-at-100/346022)

<div class="topic-metadata">

**Author:** [@rahmathm1](https://discuss.elastic.co/u/rahmathm1)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 10:57am UTC](https://discuss.elastic.co/t/elasticsearch-node-ram-percent-at-100/346022 "2023-10-30T10:57:33Z")

</div>

Hi, everyone, We have a 6x6 setup of ES deployed on Kubernetes. When we check node memory statistics, we can see that data nodes are using 100% of ram allocated to them. Below are the resource limits for data nodes: l…

---

## [Logstash RSS plugin failed to load after fresh install](https://discuss.elastic.co/t/logstash-rss-plugin-failed-to-load-after-fresh-install/345988)

<div class="topic-metadata">

**Author:** [@developerx](https://discuss.elastic.co/u/developerx)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 9:15am UTC](https://discuss.elastic.co/t/logstash-rss-plugin-failed-to-load-after-fresh-install/345988 "2023-10-30T09:15:35Z")

</div>

Hello, i've an issue with a fresh logstash installation and logstash-input-rss plugin. when trying to test the configuration for a simple RSS reader for just 1 URL i got this error: \[DEBUG\] 2023-10-29 19:57:25.354 \[Con…

---

## [Concurrent Enrich Policy Execution](https://discuss.elastic.co/t/concurrent-enrich-policy-execution/346011)

<div class="topic-metadata">

**Author:** [@Akshey](https://discuss.elastic.co/u/Akshey)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 8:32am UTC](https://discuss.elastic.co/t/concurrent-enrich-policy-execution/346011 "2023-10-30T08:32:36Z")

</div>

Hi Team, We've added an enrichment policy to join data among two indexes. The indexes are dynamic, hence we are running the execute policy query whenever there's an update in the source index. The problem is when there …

---

## [Problem with Template File Not Applying Correctly in Logstash](https://discuss.elastic.co/t/problem-with-template-file-not-applying-correctly-in-logstash/346006)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 7:09am UTC](https://discuss.elastic.co/t/problem-with-template-file-not-applying-correctly-in-logstash/346006 "2023-10-30T07:09:06Z")

</div>

We are experiencing an issue with Logstash where the user\_dictionary\_rules, stopwords, and synonyms data are not being properly indexed based on the template file in an EC2 environment. When these data sets, specificall…

---

## [Synonym search latency](https://discuss.elastic.co/t/synonym-search-latency/346001)

<div class="topic-metadata">

**Author:** [@vanduong](https://discuss.elastic.co/u/vanduong)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 3:51am UTC](https://discuss.elastic.co/t/synonym-search-latency/346001 "2023-10-30T03:51:00Z")

</div>

I recently utilized synonyms in an Elasticsearch context. After reading a blog that discusses the advantages of applying synonyms at search time as opposed to index time, I began to wonder if using synonyms at search tim…

---

## [Index data storage into a cluster](https://discuss.elastic.co/t/index-data-storage-into-a-cluster/344298)

<div class="topic-metadata">

**Author:** [@MattzGB](https://discuss.elastic.co/u/MattzGB)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 11:07pm UTC](https://discuss.elastic.co/t/index-data-storage-into-a-cluster/344298 "2023-10-29T23:07:13Z")

</div>

I have an elasticsearch cluster with 3 nodes where the elasticsearch service is installed on each node. When I check the cluster health and the index on each node, I can see that the cluster is green and that the 25GB i…

---

## [Prioritizing Indices for Search Speed](https://discuss.elastic.co/t/prioritizing-indices-for-search-speed/345973)

<div class="topic-metadata">

**Author:** [@maorethians](https://discuss.elastic.co/u/maorethians)\
**Replies:** 2\
**Last updated:** [October 29, 2023, 10:09pm UTC](https://discuss.elastic.co/t/prioritizing-indices-for-search-speed/345973 "2023-10-29T22:09:48Z")

</div>

We have an Elasticsearch instance, containing 100s of indices in it with different, statically-defined mappings. Is there a way to prioritize some of them for read/write operations not to be affected by low-priority ones…

---

## [Question about discuss.elastic.co](https://discuss.elastic.co/t/question-about-discuss-elastic-co/345984)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 2\
**Last updated:** [October 29, 2023, 5:32pm UTC](https://discuss.elastic.co/t/question-about-discuss-elastic-co/345984 "2023-10-29T17:32:20Z")

</div>

Hello: I was trying to ask a question on discuss.elastic.co and I see that I cannot do that anymore. Not sure why. Maybe you could find out why I am blacklisted there.

---

## [How to activate sysmon event ID 3](https://discuss.elastic.co/t/how-to-activate-sysmon-event-id-3/345977)

<div class="topic-metadata">

**Author:** [@yassinebad](https://discuss.elastic.co/u/yassinebad)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 3:51pm UTC](https://discuss.elastic.co/t/how-to-activate-sysmon-event-id-3/345977 "2023-10-29T15:51:26Z")

</div>

Hey everyone, I am sending my logs from a windows node using winlogbeat and sysmon64 to my ELK stack. While in discover panel in kibana I can see my logs with different events ID of sysmon, but I have noticed that the …

---

## [Logstash create many zero document indexes](https://discuss.elastic.co/t/logstash-create-many-zero-document-indexes/345522)

<div class="topic-metadata">

**Author:** [@Amzath\_Khan](https://discuss.elastic.co/u/Amzath_Khan)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 12:28pm UTC](https://discuss.elastic.co/t/logstash-create-many-zero-document-indexes/345522 "2023-10-29T12:28:25Z")

</div>

I'm sending data from a Microsoft SQL Server database into elasticsearch using logstash 8.x. It functions well. However, logstash multiplies indexes with no documents and raises the shared. It takes over an hour to reach…

---

## [How to restore .security index from snapshot](https://discuss.elastic.co/t/how-to-restore-security-index-from-snapshot/344959)

<div class="topic-metadata">

**Author:** [@dna01](https://discuss.elastic.co/u/dna01)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/how-to-restore-security-index-from-snapshot/344959 "2023-10-29T11:06:56Z")

</div>

what is the recommended approach to restore .security index from snapshot? the index needs to be closed to be restored, but once it is closed, users cannot login anymore. and the whole database stuck since it cannot lo…

---

## [Logs don't show up on kibana](https://discuss.elastic.co/t/logs-dont-show-up-on-kibana/345930)

<div class="topic-metadata">

**Author:** [@yassinebad](https://discuss.elastic.co/u/yassinebad)\
**Replies:** 8\
**Last updated:** [October 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/logs-dont-show-up-on-kibana/345930 "2023-10-29T11:06:23Z")

</div>

Hey I am using winlogbeat on my windows machine with sysmon64. my winlogbeat.yml file is configured correctly. I have checked with the config command. once I run ./winlogbeat.exe setup -e ! my index and dashboards get …

---

## [Logstash cvs plugin not sending data to index](https://discuss.elastic.co/t/logstash-cvs-plugin-not-sending-data-to-index/345924)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 7:36am UTC](https://discuss.elastic.co/t/logstash-cvs-plugin-not-sending-data-to-index/345924 "2023-10-29T07:36:29Z")

</div>

Hello All, I have csv files under one folder in windows system and need to send the data in elastic index using logstash. I'm not sure why data is not showing in index,though index getting created. Need key and value a…

---

## [LogStash::Error: Don't know how to handle \`Java::JavaLang::IllegalStateException\` for \`PipelineAction::Create\<main\>\`](https://discuss.elastic.co/t/logstash-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/345882)

<div class="topic-metadata">

**Author:** [@fae](https://discuss.elastic.co/u/fae)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 6:53am UTC](https://discuss.elastic.co/t/logstash-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/345882 "2023-10-29T06:53:11Z")

</div>

Need help troubleshooting logstash java issue, it was working fine until a while ago when it started throwing up this error below: systemctl status logstash -l ● logstash.service - Logstash service (ELK stack). Loade…

---

## [Restore snapshot with curl](https://discuss.elastic.co/t/restore-snapshot-with-curl/345961)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 2\
**Last updated:** [October 28, 2023, 5:49pm UTC](https://discuss.elastic.co/t/restore-snapshot-with-curl/345961 "2023-10-28T17:49:04Z")

</div>

Hi, I have snapshot of indexes pattern .\*, now after Kibana problems due power off I have to restore .kibana\* indexes to fix my problems. How can I do it with curl (as Kibana doesn't work)?

---

## [I have the same problem](https://discuss.elastic.co/t/i-have-the-same-problem/345963)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 2\
**Last updated:** [October 28, 2023, 1:54pm UTC](https://discuss.elastic.co/t/i-have-the-same-problem/345963 "2023-10-28T13:54:04Z")

</div>

Continuing the discussion from How to re-run cluster with different cluster uuid:

---

## [Get all ids with Python](https://discuss.elastic.co/t/get-all-ids-with-python/344689)

<div class="topic-metadata">

**Author:** [@marc.schwarzschild](https://discuss.elastic.co/u/marc.schwarzschild)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 9:51pm UTC](https://discuss.elastic.co/t/get-all-ids-with-python/344689 "2023-10-27T21:51:21Z")

</div>

Hi, I'd like to use the elastic\_enterprise\_search.AppSearch package to get all our document ids. I have tried many things and always hit the 10k result limit. I understand that "scrolling" may be the solution but have…

---

## [Java APM agent crashes JVM Corretto 17 on AWS EB Linux 2023](https://discuss.elastic.co/t/java-apm-agent-crashes-jvm-corretto-17-on-aws-eb-linux-2023/345956)

<div class="topic-metadata">

**Author:** [@Daniele\_Renda](https://discuss.elastic.co/u/Daniele_Renda)\
**Replies:** 0\
**Last updated:** [October 27, 2023, 8:42pm UTC](https://discuss.elastic.co/t/java-apm-agent-crashes-jvm-corretto-17-on-aws-eb-linux-2023/345956 "2023-10-27T20:42:12Z")

</div>

Hi, I hope I'm not wrong posting here this problem. It seems that a recurrent JVM crash that happens lately in our AWS ES cluster depends on ES APM agent. I filed an issue here Probably the bug in on the JVM but I thi…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=280)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=282)
