# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=319

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 320

---

## [Im having a firewall pushing logs towards a linux destination server with middle contains linux machine having logstash server](https://discuss.elastic.co/t/im-having-a-firewall-pushing-logs-towards-a-linux-destination-server-with-middle-contains-linux-machine-having-logstash-server/340511)

<div class="topic-metadata">

**Author:** [@sudharsanam132](https://discuss.elastic.co/u/sudharsanam132)\
**Replies:** 4\
**Last updated:** [August 19, 2023, 9:38am UTC](https://discuss.elastic.co/t/im-having-a-firewall-pushing-logs-towards-a-linux-destination-server-with-middle-contains-linux-machine-having-logstash-server/340511 "2023-08-19T09:38:35Z")

</div>

So firewall pushing logs towards logstash server in logstash i have mentioned in the output plugin to the destination server i need to filter my logs if for example:192.168.1.143 contains the ip in the message i need to …

---

## [Elastic Agent integration for Azure IoT log events forwarding to Elasticsearch](https://discuss.elastic.co/t/elastic-agent-integration-for-azure-iot-log-events-forwarding-to-elasticsearch/341144)

<div class="topic-metadata">

**Author:** [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Replies:** 0\
**Last updated:** [August 19, 2023, 7:36am UTC](https://discuss.elastic.co/t/elastic-agent-integration-for-azure-iot-log-events-forwarding-to-elasticsearch/341144 "2023-08-19T07:36:34Z")

</div>

Hello, everyone! Looking for some help. Need to forward Azure IoT Hub log events to Elasticsearch using Elastic Agent integration. Does anyone has any suggestion? For similar cases good solution is Diagnostic settings +…

---

## [Create an API key using a client authenticated by an existing API key](https://discuss.elastic.co/t/create-an-api-key-using-a-client-authenticated-by-an-existing-api-key/341119)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 1\
**Last updated:** [August 19, 2023, 5:11am UTC](https://discuss.elastic.co/t/create-an-api-key-using-a-client-authenticated-by-an-existing-api-key/341119 "2023-08-19T05:11:05Z")

</div>

I am using an API key to create an elasticsearch client. I am using the client to create another API key but is getting an error. Any idea whether the existing key (or the derived key) needs to be created with certain pr…

---

## [Revert to Basic (Free) License - JDBC / ODBC Support?](https://discuss.elastic.co/t/revert-to-basic-free-license-jdbc-odbc-support/341125)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 7:17pm UTC](https://discuss.elastic.co/t/revert-to-basic-free-license-jdbc-odbc-support/341125 "2023-08-18T19:17:39Z")

</div>

Hello, I deployed the ELK stack and used it in TRIAL license mode till now. I plan to revert to the basic (free) license, but I need the functionality to ingest MySQL database data into ELK stack via JDBC ingress pipeli…

---

## [Kibana clock time different from Elasticsearch?](https://discuss.elastic.co/t/kibana-clock-time-different-from-elasticsearch/340960)

<div class="topic-metadata">

**Author:** [@Hannah\_Zhang](https://discuss.elastic.co/u/Hannah_Zhang)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 6:42pm UTC](https://discuss.elastic.co/t/kibana-clock-time-different-from-elasticsearch/340960 "2023-08-18T18:42:51Z")

</div>

It seems the Kibana clock time setting is different from Elasticsearch, so when I posted index into Elasticsearch, I can see that immediately from Elasticsearch, but can't see it with Kibana "Discover" if I set time inte…

---

## [\[ERROR\]\[plugins.securitySolution.endpoint:user-artifact-packager:1.0.0\] EndpointError: Error scheduling task](https://discuss.elastic.co/t/error-plugins-securitysolution-endpoint1-0-0-endpointerror-error-scheduling-task/341121)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 6:01pm UTC](https://discuss.elastic.co/t/error-plugins-securitysolution-endpoint1-0-0-endpointerror-error-scheduling-task/341121 "2023-08-18T18:01:28Z")

</div>

Hi, I am trying to log in to my kibana but I get the following message: I have logged in to the server and I get the following error in the log: \[ERROR\]\[plugins.securitySolution.endpoint:user-artifact-packager:1.0.0…

---

## [Logstash Output for Fleet Managed Elastic Agent](https://discuss.elastic.co/t/logstash-output-for-fleet-managed-elastic-agent/341117)

<div class="topic-metadata">

**Author:** [@elastic\_n00b](https://discuss.elastic.co/u/elastic_n00b)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 5:08pm UTC](https://discuss.elastic.co/t/logstash-output-for-fleet-managed-elastic-agent/341117 "2023-08-18T17:08:22Z")

</div>

Configure SSL/TLS for the Logstash output | Fleet and Elastic Agent Guide \[8.8\] | Elastic I am looking at these instructions for configuring logstash as an output for elastic agent and I am a bit confused about the clien…

---

## [INFO logs being sent as error logs](https://discuss.elastic.co/t/info-logs-being-sent-as-error-logs/341101)

<div class="topic-metadata">

**Author:** [@marcoaleixo](https://discuss.elastic.co/u/marcoaleixo)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 2:08pm UTC](https://discuss.elastic.co/t/info-logs-being-sent-as-error-logs/341101 "2023-08-18T14:08:40Z")

</div>

hey team, I have my Fleet configured using ElasticCloud and I need to configure the elastic-agent on my Django project where I'm configuring my logging like: ELASTIC\_APM = { 'SERVICE\_NAME': 'alan-backend', 'SERVE…

---

## [Activated Warm Tier Not Able To Shut it Down](https://discuss.elastic.co/t/activated-warm-tier-not-able-to-shut-it-down/341102)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/activated-warm-tier-not-able-to-shut-it-down/341102 "2023-08-18T14:14:12Z")

</div>

Hi, I decided to experiment with the warm data tier instance in ES. It seems to have moved data on to this tier (to be expected). But now I can't remove this instance. From what I've seen, this is a solution: But it …

---

## [General advice on sucking in whole databases into Elastic?](https://discuss.elastic.co/t/general-advice-on-sucking-in-whole-databases-into-elastic/341096)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 1:44pm UTC](https://discuss.elastic.co/t/general-advice-on-sucking-in-whole-databases-into-elastic/341096 "2023-08-18T13:44:23Z")

</div>

Hi all. I'm working on pulling my company's relational data into Elastic using the Logstash JDBC. It's working, but I have a general question. Currently, I've just written a JOIN over two tables containing a few field…

---

## [ILM action failed “check-rollover-ready,Moving to ERROR step”?](https://discuss.elastic.co/t/ilm-action-failed-check-rollover-ready-moving-to-error-step/340922)

<div class="topic-metadata">

**Author:** [@njain213](https://discuss.elastic.co/u/njain213)\
**Replies:** 5\
**Last updated:** [August 18, 2023, 1:43pm UTC](https://discuss.elastic.co/t/ilm-action-failed-check-rollover-ready-moving-to-error-step/340922 "2023-08-18T13:43:40Z")

</div>

Hello Team, I am using ELK stack version 7.9.3 and sometimes I use to get below error when randomly ILM policy stops working and no new index with new date is created and data is getting piled in previous date index. Wh…

---

## [Change log level for metricbeat on elasticsearch through ECK](https://discuss.elastic.co/t/change-log-level-for-metricbeat-on-elasticsearch-through-eck/341091)

<div class="topic-metadata">

**Author:** [@b2ron](https://discuss.elastic.co/u/b2ron)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 11:45am UTC](https://discuss.elastic.co/t/change-log-level-for-metricbeat-on-elasticsearch-through-eck/341091 "2023-08-18T11:45:57Z")

</div>

I want to change the logging level for the Metricbeat container of an Elasticsearch node installed through ECK. Is this possible or not? Here's the configuration: apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasti…

---

## [Errors from fleet managed elastic agents](https://discuss.elastic.co/t/errors-from-fleet-managed-elastic-agents/339083)

<div class="topic-metadata">

**Author:** [@Jitendra1](https://discuss.elastic.co/u/Jitendra1)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 10:43am UTC](https://discuss.elastic.co/t/errors-from-fleet-managed-elastic-agents/339083 "2023-08-18T10:43:14Z")

</div>

Hi, I am getting few errors from fleet-managed elastic agents, which are listed below as- Please suggest me how to resolve these.

---

## [Trying to create templte from index](https://discuss.elastic.co/t/trying-to-create-templte-from-index/341086)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 10:31am UTC](https://discuss.elastic.co/t/trying-to-create-templte-from-index/341086 "2023-08-18T10:31:19Z")

</div>

I'm trying to create a template through Kibana from an already imported index, so I can reimport them, and apply the template to them (and also apply a lifecycle policy). The index mappings looks like this: { "mappin…

---

## [Filter elasticsearch data with logstash](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077)

<div class="topic-metadata">

**Author:** [@john.hoogeveen](https://discuss.elastic.co/u/john.hoogeveen)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 10:01am UTC](https://discuss.elastic.co/t/filter-elasticsearch-data-with-logstash/341077 "2023-08-18T10:01:33Z")

</div>

Hello, I am trying to export some data from an elastic stack using logstash but it doesn't work. For this I connected it to a test stack with this config file input { elasticsearch { hosts =\> "localhost:9200" …

---

## [Unable to start Elasticsearch 8.8.2 even after disabling xpack](https://discuss.elastic.co/t/unable-to-start-elasticsearch-8-8-2-even-after-disabling-xpack/341080)

<div class="topic-metadata">

**Author:** [@Abhishek\_Mantripraga](https://discuss.elastic.co/u/Abhishek_Mantripraga)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 7:31am UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-8-8-2-even-after-disabling-xpack/341080 "2023-08-18T07:31:32Z")

</div>

\[2023-08-18T08:03:06,110\]\[WARN \]\[c.a.a.p.i.BasicProfileConfigFileLoader\] \[\] Unable to load config file null java.security.AccessControlException: access denied ("java.io.FilePermission" "/nonexistent/.aws/config" "read")…

---

## [Unable to see pods, pvc and svc's after deployment with ECK](https://discuss.elastic.co/t/unable-to-see-pods-pvc-and-svcs-after-deployment-with-eck/341073)

<div class="topic-metadata">

**Author:** [@Sreenivas1](https://discuss.elastic.co/u/Sreenivas1)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 7:06am UTC](https://discuss.elastic.co/t/unable-to-see-pods-pvc-and-svcs-after-deployment-with-eck/341073 "2023-08-18T07:06:45Z")

</div>

Hi Team, I was able to deploy a 3 master+data node cluster in Kubernetes environment using yaml configuration on ECK managed Kubernetes environment and it was working fine. Later, while I was checking something I have …

---

## [Kibana Lucene query string does not match the result](https://discuss.elastic.co/t/kibana-lucene-query-string-does-not-match-the-result/340703)

<div class="topic-metadata">

**Author:** [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 6:17am UTC](https://discuss.elastic.co/t/kibana-lucene-query-string-does-not-match-the-result/340703 "2023-08-18T06:17:35Z")

</div>

Kibana Lucene query string: host:\*AGC\* AND NOT host:\*LGAGC\* AND NOT host:\*AP\* AND message:"\\:ORA\\-" AND NOT message:"ReconnectableOraErrCodes" However, the query result not 100% match, such the pattern below in documen…

---

## [Remote cluster node query](https://discuss.elastic.co/t/remote-cluster-node-query/341033)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 6\
**Last updated:** [August 18, 2023, 5:18am UTC](https://discuss.elastic.co/t/remote-cluster-node-query/341033 "2023-08-18T05:18:41Z")

</div>

We have an existing elasticsearch stack running basic license, is it possible to add more nodes to the cluster which do not hold any data and only pass data from a location to existing data / master nodes with basic lice…

---

## [Custom TCP port numbers instead of 9200 for elasticsearch](https://discuss.elastic.co/t/custom-tcp-port-numbers-instead-of-9200-for-elasticsearch/341012)

<div class="topic-metadata">

**Author:** [@Penchala\_Abhilash\_Mu](https://discuss.elastic.co/u/Penchala_Abhilash_Mu)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 5:12am UTC](https://discuss.elastic.co/t/custom-tcp-port-numbers-instead-of-9200-for-elasticsearch/341012 "2023-08-18T05:12:06Z")

</div>

Hi Team, As a security best practices, i would like to change the http.port number from 9200 to custom tcp port number.?? Please share the some reference documents Best Reagards, Abhilash

---

## [Security alerts not generated for each document](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049)

<div class="topic-metadata">

**Author:** [@nlcsdev](https://discuss.elastic.co/u/nlcsdev)\
**Replies:** 5\
**Last updated:** [August 18, 2023, 4:00am UTC](https://discuss.elastic.co/t/security-alerts-not-generated-for-each-document/341049 "2023-08-18T04:00:44Z")

</div>

I have a processor that sends vulnerability reports to an index, and thousands of documents can be ingested within seconds. I've set up an alert through security using custom query, where the query just filters for docum…

---

## [Im installing elasticsearch 8.9x while inicialicing the nodes i received this error](https://discuss.elastic.co/t/im-installing-elasticsearch-8-9x-while-inicialicing-the-nodes-i-received-this-error/340786)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 4\
**Last updated:** [August 17, 2023, 9:10pm UTC](https://discuss.elastic.co/t/im-installing-elasticsearch-8-9x-while-inicialicing-the-nodes-i-received-this-error/340786 "2023-08-17T21:10:56Z")

</div>

im installing elasticsearch 8.9x but when im starting the nodes and change the password i receive this error the command i use to change is this sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password --url "htt…

---

## [Filebeat failing to start due to YAML error, but which config file is it complaining about?](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 7\
**Last updated:** [August 17, 2023, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047 "2023-08-17T20:48:47Z")

</div>

I'm attempting to use Filebeat to ingest logs from Zeek, but I'm getting the following error when I start Filebeat: Here's my /etc/filebeat/filebeat.yml file: Yamllint tells me that there's an issue with this: "Map…

---

## ["You need permission to create data views" error in new space](https://discuss.elastic.co/t/you-need-permission-to-create-data-views-error-in-new-space/340998)

<div class="topic-metadata">

**Author:** [@jonasjancarik](https://discuss.elastic.co/u/jonasjancarik)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 8:17pm UTC](https://discuss.elastic.co/t/you-need-permission-to-create-data-views-error-in-new-space/340998 "2023-08-17T20:17:33Z")

</div>

I've created a new space in Kibana, but I am unable to access the Analytics features, such as opening dashboards. I'm met with the error message "You need permission to create data views." What's even more confusing is t…

---

## [ELK/Kibana SSO using Keycloak](https://discuss.elastic.co/t/elk-kibana-sso-using-keycloak/341035)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 7:18pm UTC](https://discuss.elastic.co/t/elk-kibana-sso-using-keycloak/341035 "2023-08-17T19:18:18Z")

</div>

Is the enterprise version of Elasticsearch required for Keycloak OICD integration for single sign on?

---

## [ES 8.6.1 How to make the number result hits consistent when re-running the same query over and over](https://discuss.elastic.co/t/es-8-6-1-how-to-make-the-number-result-hits-consistent-when-re-running-the-same-query-over-and-over/341050)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 7:04pm UTC](https://discuss.elastic.co/t/es-8-6-1-how-to-make-the-number-result-hits-consistent-when-re-running-the-same-query-over-and-over/341050 "2023-08-17T19:04:39Z")

</div>

I have and index with 10 primaries and 10 replicas (number\_of\_replica is set to 1). Refresh interval is currently 5s. There is a lot writing activity happenning on that index. I have a query that queries for a specific…

---

## [Time slider playback](https://discuss.elastic.co/t/time-slider-playback/341043)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 6:01pm UTC](https://discuss.elastic.co/t/time-slider-playback/341043 "2023-08-17T18:01:05Z")

</div>

Hello, I've been reading through the documenation to see if this capability exists, but I've been unable to find it. Is it possible to setup a time range "playback" that is not just a slider intervals within a global ti…

---

## [Parsing log in logstash with format xml and json embebed](https://discuss.elastic.co/t/parsing-log-in-logstash-with-format-xml-and-json-embebed/341031)

<div class="topic-metadata">

**Author:** [@Oscar\_Lopez](https://discuss.elastic.co/u/Oscar_Lopez)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 4:21pm UTC](https://discuss.elastic.co/t/parsing-log-in-logstash-with-format-xml-and-json-embebed/341031 "2023-08-17T16:21:53Z")

</div>

hello everyone Hello everyone, at this moment I am trying to ingest some logs in elasticsearch with logstash with the following structure: \<ns0:MessageID xmlns:ns0="http://www.ZZZ.com/namespaces/tnt/plugins/jms"\>ID:XXX…

---

## [javax.net.ssl.SSLHandshakeException: Empty client certificate chain](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-empty-client-certificate-chain/341024)

<div class="topic-metadata">

**Author:** [@nick\_harper1](https://discuss.elastic.co/u/nick_harper1)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 2:10pm UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-empty-client-certificate-chain/341024 "2023-08-17T14:10:54Z")

</div>

I have configured a cert that has both server and client enabled but when using this for transport on 9300 I get: exception caught on transport layer \[Netty4TcpChannel{localAddress=/10.15.4.16:9300, remoteAddress=/10.15…

---

## [Feature/Fix Requests Flow](https://discuss.elastic.co/t/feature-fix-requests-flow/340760)

<div class="topic-metadata">

**Author:** [@Gelinski](https://discuss.elastic.co/u/Gelinski)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 1:49pm UTC](https://discuss.elastic.co/t/feature-fix-requests-flow/340760 "2023-08-17T13:49:22Z")

</div>

Hello folks, I have a few doubts regarding the Elastic support so I need some help to answer the following questions. Is there any official flow to request a new feature or fixes for Elastic Observability products? Ho…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=318)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=320)
