# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=340

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 341

---

## [Filebeat module ingest pipeline not working in logstash](https://discuss.elastic.co/t/filebeat-module-ingest-pipeline-not-working-in-logstash/338500)

<div class="topic-metadata">

**Author:** [@nbindal](https://discuss.elastic.co/u/nbindal)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 5:55am UTC](https://discuss.elastic.co/t/filebeat-module-ingest-pipeline-not-working-in-logstash/338500 "2023-07-17T05:55:43Z")

</div>

Hi Team, I am using apache module and fileset in Beats+ELK stack where Filebeat is sending logs to logstash, logstash is using Ingest pipeline(we get module ingest pipeline - filebeat-8.7.1-apache-access-pipeline) , but…

---

## [How to sort my data in elasticsearch](https://discuss.elastic.co/t/how-to-sort-my-data-in-elasticsearch/338072)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 8\
**Last updated:** [July 17, 2023, 5:13am UTC](https://discuss.elastic.co/t/how-to-sort-my-data-in-elasticsearch/338072 "2023-07-17T05:13:38Z")

</div>

how to sort by asc in logstash? i want new add field,it's self increment column,and insert dest index,how make it?

---

## [Getting logstasg error in rhel 8 and not running in logstash in rhel 8](https://discuss.elastic.co/t/getting-logstasg-error-in-rhel-8-and-not-running-in-logstash-in-rhel-8/338480)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 4:28am UTC](https://discuss.elastic.co/t/getting-logstasg-error-in-rhel-8-and-not-running-in-logstash-in-rhel-8/338480 "2023-07-17T04:28:47Z")

</div>

Logstash is not running in rhel 8 and getting error while start logstash. logstash version :- 7.4.3 \[ERROR\] 2023-07-15 18:52:56.228 \[main\] Logstash - java.lang.IllegalStateException: Logstash stopped processing because…

---

## [Logstash output by condition](https://discuss.elastic.co/t/logstash-output-by-condition/338376)

<div class="topic-metadata">

**Author:** [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 2:19am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376 "2023-07-17T02:19:05Z")

</div>

Hi Guys, I setup logstash with influxdb plugin, and can send metric to influxdb successfully. But now I meet question with output by condition. run two filebeat instance onto two pc to capture two different log files, …

---

## [Own Output for SNMP Get Values in Logstash](https://discuss.elastic.co/t/own-output-for-snmp-get-values-in-logstash/338440)

<div class="topic-metadata">

**Author:** [@hitman22](https://discuss.elastic.co/u/hitman22)\
**Replies:** 2\
**Last updated:** [July 16, 2023, 10:33pm UTC](https://discuss.elastic.co/t/own-output-for-snmp-get-values-in-logstash/338440 "2023-07-16T22:33:56Z")

</div>

Hello, I have the following Logstash config input { snmp { tags =\> \[ "snmp" \] get =\> \[".1.3.6.1.4.1.9.9.48.1.1.1.5.2",".1.3.6.1.4.1.9.9.109.1.1.1.1.5.1",".1.3.6.1.4.1.9.9.48.1.1.1.5.1"\] hosts =\> \[{host =\> …

---

## [Whitelisting Elastic Agent](https://discuss.elastic.co/t/whitelisting-elastic-agent/338367)

<div class="topic-metadata">

**Author:** [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Replies:** 2\
**Last updated:** [July 16, 2023, 10:27pm UTC](https://discuss.elastic.co/t/whitelisting-elastic-agent/338367 "2023-07-16T22:27:54Z")

</div>

We have one or two systems that are running an additional AV software due to reasons beyond our teams control. That being said, we want to deploy the Elastic Agent on the system and will be enabling Defend. What paths do…

---

## [Collection and storage of information from netflow sources](https://discuss.elastic.co/t/collection-and-storage-of-information-from-netflow-sources/335759)

<div class="topic-metadata">

**Author:** [@BugS](https://discuss.elastic.co/u/BugS)\
**Replies:** 12\
**Last updated:** [July 16, 2023, 12:22pm UTC](https://discuss.elastic.co/t/collection-and-storage-of-information-from-netflow-sources/335759 "2023-07-16T12:22:10Z")

</div>

Hello everyone. Maybe it's a newbie question, but I have limited experience with ELK. Currently, I'm trying to use it as a netflow collector. I've configured everything according to the documentation, but I'm a bit conce…

---

## [Filebeat and Logstash not connecting](https://discuss.elastic.co/t/filebeat-and-logstash-not-connecting/338302)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 4\
**Last updated:** [July 15, 2023, 1:55pm UTC](https://discuss.elastic.co/t/filebeat-and-logstash-not-connecting/338302 "2023-07-15T13:55:09Z")

</div>

I am reaching out to seek your expertise and guidance regarding an issue I am facing with transferring logs from Filebeat to Logstash. I have a setup where Filebeat is installed on 'Server1', which sends logs to Logstash…

---

## [Inaccessibility of Artifact Link for Elasticsearch Versions 2.x and 5.x: Seeking Clarification](https://discuss.elastic.co/t/inaccessibility-of-artifact-link-for-elasticsearch-versions-2-x-and-5-x-seeking-clarification/338457)

<div class="topic-metadata">

**Author:** [@amit\_phulera](https://discuss.elastic.co/u/amit_phulera)\
**Replies:** 3\
**Last updated:** [July 15, 2023, 11:54am UTC](https://discuss.elastic.co/t/inaccessibility-of-artifact-link-for-elasticsearch-versions-2-x-and-5-x-seeking-clarification/338457 "2023-07-15T11:54:07Z")

</div>

We have been using the following artifact link (https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-{{ elasticsearch\_version }}-linux-x86\_64.tar.gz) to download and test various components on elasticsearch…

---

## [How do return exact term matching irrespective of order?](https://discuss.elastic.co/t/how-do-return-exact-term-matching-irrespective-of-order/338297)

<div class="topic-metadata">

**Author:** [@at\_ohn](https://discuss.elastic.co/u/at_ohn)\
**Replies:** 3\
**Last updated:** [July 15, 2023, 6:30am UTC](https://discuss.elastic.co/t/how-do-return-exact-term-matching-irrespective-of-order/338297 "2023-07-15T06:30:12Z")

</div>

Hi community, appreciate if anyone has any insights on this. We want to return only exact matches irrespective of the order of the terms, and disregard any terms that are not in the query. For example, if we search "Ne…

---

## [TSVB Table, is it possible to remove rows where the count value is zero](https://discuss.elastic.co/t/tsvb-table-is-it-possible-to-remove-rows-where-the-count-value-is-zero/338424)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 3\
**Last updated:** [July 14, 2023, 10:42pm UTC](https://discuss.elastic.co/t/tsvb-table-is-it-possible-to-remove-rows-where-the-count-value-is-zero/338424 "2023-07-14T22:42:03Z")

</div>

Hi there! I have a TSVB table that displays the most recent version value (Last Value) over the last 31 days for the devices in the environment. Each device creates multiple records a day as we perform the automatic che…

---

## [Using scripts with aggregation](https://discuss.elastic.co/t/using-scripts-with-aggregation/338378)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 9:13pm UTC](https://discuss.elastic.co/t/using-scripts-with-aggregation/338378 "2023-07-14T21:13:38Z")

</div>

Hi, I have a use case where the value of a field name signal can be 0, 1, or 2. I have to perform aggregation on this field but there are few records in the index without the field. For the field not\_exist, I need to as…

---

## [Logstash gets stuck in pipelines](https://discuss.elastic.co/t/logstash-gets-stuck-in-pipelines/337247)

<div class="topic-metadata">

**Author:** [@Tony\_K](https://discuss.elastic.co/u/Tony_K)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 9:00pm UTC](https://discuss.elastic.co/t/logstash-gets-stuck-in-pipelines/337247 "2023-07-14T21:00:16Z")

</div>

I have a simple csv file where i like to upload to elasticsearch. My sample csv file contains 2 records. it gets stuck at pipelines. Please see below. I am running this on windows 11 Thank you for your helo. uploa…

---

## [Ingest pipeline: copy all fields that contains a word to a single new field](https://discuss.elastic.co/t/ingest-pipeline-copy-all-fields-that-contains-a-word-to-a-single-new-field/338432)

<div class="topic-metadata">

**Author:** [@drjz](https://discuss.elastic.co/u/drjz)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 8:48pm UTC](https://discuss.elastic.co/t/ingest-pipeline-copy-all-fields-that-contains-a-word-to-a-single-new-field/338432 "2023-07-14T20:48:02Z")

</div>

Hi all, I am puzzling with the Script processor in an Ingest pipeline to copy all fields to a single new field. This is the same idea as using the copy\_to in the mapping, but instead of creating the copy in the index, we…

---

## [Kibana Dashbaords into UI Mobile application](https://discuss.elastic.co/t/kibana-dashbaords-into-ui-mobile-application/338438)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/kibana-dashbaords-into-ui-mobile-application/338438 "2023-07-14T20:02:09Z")

</div>

Hi, I have created a dashboard for my organization to track supply chain traceability. We have a mobile application UI also and we want to have the dashboard in that also. Can you please guide me, on how to embed it into…

---

## [Elastic Search 7.17.9 ClusterFormationFailure](https://discuss.elastic.co/t/elastic-search-7-17-9-clusterformationfailure/337963)

<div class="topic-metadata">

**Author:** [@SSRR](https://discuss.elastic.co/u/SSRR)\
**Replies:** 5\
**Last updated:** [July 14, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-search-7-17-9-clusterformationfailure/337963 "2023-07-14T18:29:09Z")

</div>

I am facing some issues in my elasticsearch cluster related to Cluster Formation with 2 nodes. I'm trying to upgrade from elasticsearch from 7.17.0 to 7.17.9. Node1 is set as master and Node2 is not. I stopped elastics…

---

## [Making a field hidden in search \_source](https://discuss.elastic.co/t/making-a-field-hidden-in-search-source/338418)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 3\
**Last updated:** [July 14, 2023, 5:48pm UTC](https://discuss.elastic.co/t/making-a-field-hidden-in-search-source/338418 "2023-07-14T17:48:05Z")

</div>

I have a index which has TBs of data now I am adding a new field to it say foo using ingest pipeline http://localhost:9200/\_ingest/pipeline/add { "processors" : \[{ "set": { "field" : "foo", …

---

## [Aggregation Query filtering on results](https://discuss.elastic.co/t/aggregation-query-filtering-on-results/338343)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 8\
**Last updated:** [July 14, 2023, 5:11pm UTC](https://discuss.elastic.co/t/aggregation-query-filtering-on-results/338343 "2023-07-14T17:11:12Z")

</div>

I have this query: GET user\_info,user\_auth\_cards\_info/\_search { "size": 0, "aggs": { "sorted\_user\_id": { "terms": { "field": "user\_id", "size": 15 }, "aggs": { "filtered…

---

## [RUM for hybrid mobile apps](https://discuss.elastic.co/t/rum-for-hybrid-mobile-apps/338010)

<div class="topic-metadata">

**Author:** [@dduarte](https://discuss.elastic.co/u/dduarte)\
**Replies:** 3\
**Last updated:** [July 14, 2023, 3:14pm UTC](https://discuss.elastic.co/t/rum-for-hybrid-mobile-apps/338010 "2023-07-14T15:14:53Z")

</div>

Hi all, We use OutSystems to develop mobile applications, which are ReactJS hybrid mobile applications underneath. As we prepare to go-live, and even though some metrics can be retrieved using the RUM agent, other metr…

---

## [KIBANA - STATE POP-UP DISPLAYS AMOUNT ONLY IN REGION MAP](https://discuss.elastic.co/t/kibana-state-pop-up-displays-amount-only-in-region-map/338384)

<div class="topic-metadata">

**Author:** [@Sinchana\_P](https://discuss.elastic.co/u/Sinchana_P)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 3:35pm UTC](https://discuss.elastic.co/t/kibana-state-pop-up-displays-amount-only-in-region-map/338384 "2023-07-14T15:35:14Z")

</div>

KIBANA - STATE POP-UP DISPLAYS AMOUNT ONLY IN REGION MAP First time when the region map visualization is loaded, only amount is displayed. If any filter is applied on the map, then it starts showing state name as well. …

---

## [Phase out VM from cluster](https://discuss.elastic.co/t/phase-out-vm-from-cluster/338422)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 2\
**Last updated:** [July 14, 2023, 2:50pm UTC](https://discuss.elastic.co/t/phase-out-vm-from-cluster/338422 "2023-07-14T14:50:57Z")

</div>

Hi, I have an issue where one of my hot nodes has a larger disk than needed. Since I can't downsize the disk and due to the volume of data, I can't simply copy over to a smaller disk. So I thought it'd be the easiest (…

---

## [Kafka logstash logs are showing into filebeat logstash index](https://discuss.elastic.co/t/kafka-logstash-logs-are-showing-into-filebeat-logstash-index/337419)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 10\
**Last updated:** [July 14, 2023, 2:27pm UTC](https://discuss.elastic.co/t/kafka-logstash-logs-are-showing-into-filebeat-logstash-index/337419 "2023-07-14T14:27:36Z")

</div>

Hello, I have kafka-logstash conf and logstash reciveing the logs from kafka. here is the config. input { kafka { topics =\> \["sitlogtopic","locallogtopic"\] bootstrap\_servers =\> "ddr-kafkadev.pvt.cci…

---

## [Parsing firewall logs in logstash](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 1:31pm UTC](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405 "2023-07-14T13:31:25Z")

</div>

Hello, our sophos firewall are sending logs to filebeat, then filebeat send to logstash. In logstash im trying to separate field called "action" to be able to filter it under elasticsearch. So far no luck. I managed to …

---

## [Eck stack helm install, expose ingress](https://discuss.elastic.co/t/eck-stack-helm-install-expose-ingress/338399)

<div class="topic-metadata">

**Author:** [@simonebenati](https://discuss.elastic.co/u/simonebenati)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 10:31am UTC](https://discuss.elastic.co/t/eck-stack-helm-install-expose-ingress/338399 "2023-07-14T10:31:30Z")

</div>

Hello, I installed eck operator via helm and then the eck stack via helm. Now I want to expose via ingress Elasticsearch but I am not able to find anywhere in the helm values or docs the value in order to expose an ingr…

---

## [Metrics alert based on ratio](https://discuss.elastic.co/t/metrics-alert-based-on-ratio/338397)

<div class="topic-metadata">

**Author:** [@dspeschabls](https://discuss.elastic.co/u/dspeschabls)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 10:10am UTC](https://discuss.elastic.co/t/metrics-alert-based-on-ratio/338397 "2023-07-14T10:10:40Z")

</div>

We have a Spring Boot application and push its metrics to elastic, among others also usage of API paths. This generates one document per uri (path) and outcome with count per time unit. Example: {uri="api/v2/dosomethin…

---

## [Elastic SIEM Detection Rules / Exception Containers / Exception Lists](https://discuss.elastic.co/t/elastic-siem-detection-rules-exception-containers-exception-lists/338390)

<div class="topic-metadata">

**Author:** [@tsigouris007](https://discuss.elastic.co/u/tsigouris007)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 8:45am UTC](https://discuss.elastic.co/t/elastic-siem-detection-rules-exception-containers-exception-lists/338390 "2023-07-14T08:45:53Z")

</div>

Hello, I have created a Terraform Provider for the Elastic SIEM components. You can find the Git repo here: https://github.com/tsigouris007/terraform-provider-elastic-siem-detection The provider is also published to t…

---

## [Xpack disable](https://discuss.elastic.co/t/xpack-disable/338350)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 7:10am UTC](https://discuss.elastic.co/t/xpack-disable/338350 "2023-07-14T07:10:16Z")

</div>

ES Version: 7.10.2 Query 1 : If I need to disable xpack I need to make yml changes to make xpack settings to false and restart each nodes ? Query1 My Understanding is : Yes, there is no API call to disable or enable dy…

---

## [Kibana data-table visualization not displaying all data rows](https://discuss.elastic.co/t/kibana-data-table-visualization-not-displaying-all-data-rows/337861)

<div class="topic-metadata">

**Author:** [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Replies:** 6\
**Last updated:** [July 14, 2023, 5:25am UTC](https://discuss.elastic.co/t/kibana-data-table-visualization-not-displaying-all-data-rows/337861 "2023-07-14T05:25:18Z")

</div>

I’m trying to create a Data Table visualization and I have below issue. My buckets selections as follows. In discover page, i can able to view the data , each fields value and its rows without any problem. But in v…

---

## [Feedback regarding Synthetics Tests](https://discuss.elastic.co/t/feedback-regarding-synthetics-tests/335587)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 11\
**Last updated:** [July 14, 2023, 5:12am UTC](https://discuss.elastic.co/t/feedback-regarding-synthetics-tests/335587 "2023-07-14T05:12:03Z")

</div>

Dear all, We are currently evaluating the Synthetic Monitoring of Elastic with 2 applications (1 Java with JSP, 1 Angular) and although we did not create huge tests yet, I would like to give our opinion about the curren…

---

## [Logstash grok pattern for apache error log](https://discuss.elastic.co/t/logstash-grok-pattern-for-apache-error-log/337676)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 4:59am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-for-apache-error-log/337676 "2023-07-14T04:59:24Z")

</div>

Hi experts, Can any one tell me that how to configure the logstash grok custom pattern for apache web server error log. below is my apache web server sample error log, \[Fri Jun 09 08:26:38.311375 2023\] \[proxy\_fcgi:err…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=339)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=341)
