# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=348

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 349

---

## [Incoorporate APM agent logging with application logging](https://discuss.elastic.co/t/incoorporate-apm-agent-logging-with-application-logging/337464)

<div class="topic-metadata">

**Author:** [@Smoke](https://discuss.elastic.co/u/Smoke)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 1:38pm UTC](https://discuss.elastic.co/t/incoorporate-apm-agent-logging-with-application-logging/337464 "2023-07-03T13:38:58Z")

</div>

Hello all, I am trying to incoorporate the logging coming from the apm agent with my application logging. However, I do not seem to be able to figure out how to use the custom layout class that I defined and use for my …

---

## [Configure NGINX Proxy for Elastic](https://discuss.elastic.co/t/configure-nginx-proxy-for-elastic/337462)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 1:30pm UTC](https://discuss.elastic.co/t/configure-nginx-proxy-for-elastic/337462 "2023-07-03T13:30:52Z")

</div>

I configured three nodes as master. I created a certificate for each one, which is used in HTTP and Transport requests. There is also a username with a password to access the elasticsearch. Note: Since I created the c…

---

## [Index template creation](https://discuss.elastic.co/t/index-template-creation/337049)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 6\
**Last updated:** [July 3, 2023, 12:48pm UTC](https://discuss.elastic.co/t/index-template-creation/337049 "2023-07-03T12:48:36Z")

</div>

during the template creation based on the json data , i am facing the issues for the data, even i have defined the nested type. please suggest . "type": "illegal\_argument\_exception", "reason": "composable template \[…

---

## [A question about separator in logstash](https://discuss.elastic.co/t/a-question-about-separator-in-logstash/337427)

<div class="topic-metadata">

**Author:** [@caixukun](https://discuss.elastic.co/u/caixukun)\
**Replies:** 5\
**Last updated:** [July 3, 2023, 11:44am UTC](https://discuss.elastic.co/t/a-question-about-separator-in-logstash/337427 "2023-07-03T11:44:42Z")

</div>

my data is: 123456@gmail.com----john----password 123456@gmail.com----john----p@ssword 123456@gmail.com----john----123456 123456@gmail.com----john----123456 123456@gmail.com----john----123----456 123456@gmail.com---…

---

## [Elasticsearch es-client pods are down after master node reboot](https://discuss.elastic.co/t/elasticsearch-es-client-pods-are-down-after-master-node-reboot/337442)

<div class="topic-metadata">

**Author:** [@Shyamsundar\_Rajkumar](https://discuss.elastic.co/u/Shyamsundar_Rajkumar)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 10:34am UTC](https://discuss.elastic.co/t/elasticsearch-es-client-pods-are-down-after-master-node-reboot/337442 "2023-07-03T10:34:22Z")

</div>

I have deployed Elasticsearch 7 in our kubernetes cluster. The es-client-7 pods are going down when the master node is rebooted. When checking logs I found "master not discovered yet" . The statefulsets es-master and es…

---

## [Automatic login with embedded dashboard](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179)

<div class="topic-metadata">

**Author:** [@aa09](https://discuss.elastic.co/u/aa09)\
**Replies:** 3\
**Last updated:** [July 3, 2023, 10:07am UTC](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179 "2023-07-03T10:07:58Z")

</div>

I have a dashboard that I want to share to users who are logged in to my application. I followed the documentation and added the following to my elastic.yml xpack.security.authc.providers: basic.basic1: order: 0 ano…

---

## [Hi All, so I have a requirement where I need logstash to capture error log messages and trigger a mail upon that , is that possible with basic open source version. Thanks in advance](https://discuss.elastic.co/t/hi-all-so-i-have-a-requirement-where-i-need-logstash-to-capture-error-log-messages-and-trigger-a-mail-upon-that-is-that-possible-with-basic-open-source-version-thanks-in-advance/337423)

<div class="topic-metadata">

**Author:** [@Akulainelastic](https://discuss.elastic.co/u/Akulainelastic)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 8:33am UTC](https://discuss.elastic.co/t/hi-all-so-i-have-a-requirement-where-i-need-logstash-to-capture-error-log-messages-and-trigger-a-mail-upon-that-is-that-possible-with-basic-open-source-version-thanks-in-advance/337423 "2023-07-03T08:33:42Z")

</div>

Continuing the discussion from Timestamp problem created using dissect:

---

## [Track down responsible queries for deprecation warnings](https://discuss.elastic.co/t/track-down-responsible-queries-for-deprecation-warnings/337425)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 7:51am UTC](https://discuss.elastic.co/t/track-down-responsible-queries-for-deprecation-warnings/337425 "2023-07-03T07:51:31Z")

</div>

Hello, we want to finally upgrade our cluster to version 8. According to the Upgrade Assistant in Kibana, we only need to check the deprecation logs. In these I find something like this \[2023-06-30T14:36:47,251\]\[CRITI…

---

## [How to add text with values to a dashboard?](https://discuss.elastic.co/t/how-to-add-text-with-values-to-a-dashboard/337366)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 6:58am UTC](https://discuss.elastic.co/t/how-to-add-text-with-values-to-a-dashboard/337366 "2023-07-03T06:58:31Z")

</div>

I would like to have in my dashboard a widget that says There are currently 200 people in 17 locations The 200 and 17 would actually be numbers calculated from queries (number of records + filters). Is this possible…

---

## [Kibana logs are not getting triggered to Opsgenie](https://discuss.elastic.co/t/kibana-logs-are-not-getting-triggered-to-opsgenie/337413)

<div class="topic-metadata">

**Author:** [@Shyam\_Kumar](https://discuss.elastic.co/u/Shyam_Kumar)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 4:46am UTC](https://discuss.elastic.co/t/kibana-logs-are-not-getting-triggered-to-opsgenie/337413 "2023-07-03T04:46:40Z")

</div>

The alert rule in Kibana is satisfying and giving 2 documents. But, the alert is not triggering to Opsgenie. The integration was done perfectly. Previously for the other alert rule which is same, the alert got trigge…

---

## [About commercial use of the free version](https://discuss.elastic.co/t/about-commercial-use-of-the-free-version/337410)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 3:47am UTC](https://discuss.elastic.co/t/about-commercial-use-of-the-free-version/337410 "2023-07-03T03:47:09Z")

</div>

of the following sites Is "Wildcard field type" of "Free and open-Basic 1,2" available for commercial use free of charge? Is "Free and open -Basic 1, 2" already free for commercial use? I look forward to hearing fro…

---

## ["order" question](https://discuss.elastic.co/t/order-question/337153)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 6\
**Last updated:** [July 2, 2023, 11:54pm UTC](https://discuss.elastic.co/t/order-question/337153 "2023-07-02T23:54:09Z")

</div>

Hello. I would like to ask you something about the text on the official website below. GET /my-index-000001/\_search { "sort" : \[ { "post\_date" : {"order" : "asc", "format": "strict\_date\_optional\_time\_nanos"}}, …

---

## [Gork not work as excpected](https://discuss.elastic.co/t/gork-not-work-as-excpected/337389)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 2, 2023, 4:09pm UTC](https://discuss.elastic.co/t/gork-not-work-as-excpected/337389 "2023-07-02T16:09:51Z")

</div>

Hi Here is my gork filter: \\\[SqlExceptionHelper\\\] SQL (Error|Warning Code): %{NUMBER:error\_code}, SQLState: %{WORD:sql\_state} here is my log: 2023-06-30 01:54:38,867 WARN CUS.InEP-APPGW-121662220 \[SqlExceptionHelper…

---

## [How to receive logs from Kaspersky endpoint security to elasticsearch](https://discuss.elastic.co/t/how-to-receive-logs-from-kaspersky-endpoint-security-to-elasticsearch/336852)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 2\
**Last updated:** [July 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-receive-logs-from-kaspersky-endpoint-security-to-elasticsearch/336852 "2023-07-02T16:01:31Z")

</div>

Hi everyone, i am new in elasticsearch . I configured Fortinet, and it works fine. I want to know how I can retrieve logs and dates from the KES server and solarwinds."

---

## [Training elasticsearch](https://discuss.elastic.co/t/training-elasticsearch/336917)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 4\
**Last updated:** [July 2, 2023, 3:00pm UTC](https://discuss.elastic.co/t/training-elasticsearch/336917 "2023-07-02T15:00:55Z")

</div>

Hi all, As a beginner in elasticsearch and recent gratuate engineering id like to gain a better understanding of market requirements in order to better direct my carrer would you have any tasks or project that would ena…

---

## [Elasticsearch and VeloCloud / VMWare SDWAN](https://discuss.elastic.co/t/elasticsearch-and-velocloud-vmware-sdwan/335810)

<div class="topic-metadata">

**Author:** [@hogie365](https://discuss.elastic.co/u/hogie365)\
**Replies:** 4\
**Last updated:** [July 2, 2023, 8:50am UTC](https://discuss.elastic.co/t/elasticsearch-and-velocloud-vmware-sdwan/335810 "2023-07-02T08:50:39Z")

</div>

Afternoon - I'm new to Elasticsearch and want to see if it's possible to connect to a VeloCloud API to pull and analyze logs from the VeloCloud orchestrator. We've been struggling getting back any real content over SNMP…

---

## [Kibana filter incorrectly applied](https://discuss.elastic.co/t/kibana-filter-incorrectly-applied/335337)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 6\
**Last updated:** [July 2, 2023, 12:53am UTC](https://discuss.elastic.co/t/kibana-filter-incorrectly-applied/335337 "2023-07-02T00:53:29Z")

</div>

Hello, When we select this filter It seems to apply not only to "update", but also for example to "update-security".... Seems like a bug to me? Willem

---

## [Find unusual pattern](https://discuss.elastic.co/t/find-unusual-pattern/337145)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 4\
**Last updated:** [July 1, 2023, 4:26pm UTC](https://discuss.elastic.co/t/find-unusual-pattern/337145 "2023-07-01T16:26:41Z")

</div>

Need to find unusual send and receive patterns in huge log file, here is the example: 00:00:01.000 S-001 \< 00:00:01.000 S-002 \< 00:00:01.000 S-003 \< 00:00:01.000 S-004 \< 00:00:01.000 S-005 0…

---

## [One or more required cgroup files or directories not found in logstash](https://discuss.elastic.co/t/one-or-more-required-cgroup-files-or-directories-not-found-in-logstash/337348)

<div class="topic-metadata">

**Author:** [@sanjay\_bhati](https://discuss.elastic.co/u/sanjay_bhati)\
**Replies:** 3\
**Last updated:** [July 1, 2023, 4:02pm UTC](https://discuss.elastic.co/t/one-or-more-required-cgroup-files-or-directories-not-found-in-logstash/337348 "2023-07-01T16:02:14Z")

</div>

I am getting error: One or more required cgroup files or directories not found here is my input file input { file { path =\> "/Users/spbhati/Downloads/S3BucketConfiguration.csv" start\_position =\> "beginning" sincedb…

---

## [With minimum security level no rights with elasitc user](https://discuss.elastic.co/t/with-minimum-security-level-no-rights-with-elasitc-user/337234)

<div class="topic-metadata">

**Author:** [@enp2s6](https://discuss.elastic.co/u/enp2s6)\
**Replies:** 1\
**Last updated:** [July 1, 2023, 3:45pm UTC](https://discuss.elastic.co/t/with-minimum-security-level-no-rights-with-elasitc-user/337234 "2023-07-01T15:45:46Z")

</div>

Hi, if I enable the minimum security settings; Set up minimal security for Elasticsearch And log in with the "elastic" account, I have no rights and can not see anything. When I try to define a user and rights before…

---

## [Netflow Mikrotik no data in elasticsearch](https://discuss.elastic.co/t/netflow-mikrotik-no-data-in-elasticsearch/335692)

<div class="topic-metadata">

**Author:** [@sana1567](https://discuss.elastic.co/u/sana1567)\
**Replies:** 20\
**Last updated:** [July 1, 2023, 2:29pm UTC](https://discuss.elastic.co/t/netflow-mikrotik-no-data-in-elasticsearch/335692 "2023-07-01T14:29:16Z")

</div>

hello please help, installed elastic 8.8 + kibana filebeat + netflow I don't see data in my Elasticsearch also when checking the netflow module - check data - No data has been received from this module yet /etc/filebe…

---

## [Custom index not showing in Kibana V8.8.0](https://discuss.elastic.co/t/custom-index-not-showing-in-kibana-v8-8-0/336621)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 11\
**Last updated:** [July 1, 2023, 1:16pm UTC](https://discuss.elastic.co/t/custom-index-not-showing-in-kibana-v8-8-0/336621 "2023-07-01T13:16:50Z")

</div>

I have multiple filebeats v 7.17.5 are configured on different remote servers with custom index names. I have recently updated my ELk stack to 8.8.0 and also updating the filebeat version to 8.8.0. I also try to add some…

---

## [How to refer to the whole modified event inside http output plugin](https://discuss.elastic.co/t/how-to-refer-to-the-whole-modified-event-inside-http-output-plugin/337232)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:23pm UTC](https://discuss.elastic.co/t/how-to-refer-to-the-whole-modified-event-inside-http-output-plugin/337232 "2023-06-30T18:23:38Z")

</div>

I am trying to map my http payload and put the whole Logstash event inside another json key/field: http { format =\> "json" http\_method =\> "post" url =\> "some url" headers =\> \["some header"\] ma…

---

## [Getting latest data per user\_id in time series data without latest transforms?](https://discuss.elastic.co/t/getting-latest-data-per-user-id-in-time-series-data-without-latest-transforms/337329)

<div class="topic-metadata">

**Author:** [@MaterializedView](https://discuss.elastic.co/u/MaterializedView)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:21pm UTC](https://discuss.elastic.co/t/getting-latest-data-per-user-id-in-time-series-data-without-latest-transforms/337329 "2023-06-30T18:21:00Z")

</div>

I have a users index. Users have various status "New", "Waiting", "Completed". A status can go from "Completed" to "New" again. So in time series it would look something like user\_id, status, timestamp 1 NEW…

---

## [Force Logstash Finish on Error](https://discuss.elastic.co/t/force-logstash-finish-on-error/337331)

<div class="topic-metadata">

**Author:** [@palomasun](https://discuss.elastic.co/u/palomasun)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:03pm UTC](https://discuss.elastic.co/t/force-logstash-finish-on-error/337331 "2023-06-30T17:03:07Z")

</div>

Hi, I use logstash 7.12.1 and I would like to avoid, in case of any error, a ethernal loop: For instance, if my configuration file doesn´t have a certification path it , loops: "unreacheble elastic... " Is there a way…

---

## [Elasticsearch-PHP \[8.8\] - Search for field in date-range, Client Helpers SearchResponseIterator & SearchHitIterator](https://discuss.elastic.co/t/elasticsearch-php-8-8-search-for-field-in-date-range-client-helpers-searchresponseiterator-searchhititerator/337237)

<div class="topic-metadata">

**Author:** [@DavidDPD](https://discuss.elastic.co/u/DavidDPD)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 4:41pm UTC](https://discuss.elastic.co/t/elasticsearch-php-8-8-search-for-field-in-date-range-client-helpers-searchresponseiterator-searchhititerator/337237 "2023-06-30T16:41:08Z")

</div>

The poor documentation of Elasticsearch continues to hamper expanding my usage, and even poorer vagueness in the PHP API documentation. This seems like a simple example. Search for field (it is a tag field, it can have…

---

## [Logstash duplication](https://discuss.elastic.co/t/logstash-duplication/335847)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 3:06pm UTC](https://discuss.elastic.co/t/logstash-duplication/335847 "2023-06-30T15:06:12Z")

</div>

Hello I have created a logstash pipeline via the http\_poller plugin in order to collect information from an API link. In order to manage the duplication of documents, I used the 'fingerprint' plugin in the filter part …

---

## [SQS Input Plugin retries](https://discuss.elastic.co/t/sqs-input-plugin-retries/337321)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 2:27pm UTC](https://discuss.elastic.co/t/sqs-input-plugin-retries/337321 "2023-06-30T14:27:44Z")

</div>

I have a Logstash pipeline that receives events from an AWS SQS queue via the SQS Input Plugin. If there is a failure during data processing, will SQS retry the event, or do I need a Logstash DLQ to handle intermittent f…

---

## [Fleet Server 8.8.1 on prems boot issue](https://discuss.elastic.co/t/fleet-server-8-8-1-on-prems-boot-issue/337312)

<div class="topic-metadata">

**Author:** [@johnjohnsp1](https://discuss.elastic.co/u/johnjohnsp1)\
**Replies:** 3\
**Last updated:** [June 30, 2023, 2:08pm UTC](https://discuss.elastic.co/t/fleet-server-8-8-1-on-prems-boot-issue/337312 "2023-06-30T14:08:46Z")

</div>

Hi, i have deployed on prems elasticsearch,kibana and fleet (version 8) on a Centos 8 distro, now every time i boot up the server i see the fleet service is up and running, but, once i go to the fleet sheet i see the ag…

---

## [Is SIEM still free as Elastic Security? I cant seem to find the download for it. Anyone?](https://discuss.elastic.co/t/is-siem-still-free-as-elastic-security-i-cant-seem-to-find-the-download-for-it-anyone/337112)

<div class="topic-metadata">

**Author:** [@gabe-elastic](https://discuss.elastic.co/u/gabe-elastic)\
**Replies:** 6\
**Last updated:** [June 30, 2023, 1:39pm UTC](https://discuss.elastic.co/t/is-siem-still-free-as-elastic-security-i-cant-seem-to-find-the-download-for-it-anyone/337112 "2023-06-30T13:39:52Z")

</div>

Is SIEM still free as Elastic Security? I cant seem to find the download for it. Anyone?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=347)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=349)
