# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=377

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 378

---

## [Is there a way to recover kibana\_x file?](https://discuss.elastic.co/t/is-there-a-way-to-recover-kibana-x-file/333319)

<div class="topic-metadata">

**Author:** [@ardit](https://discuss.elastic.co/u/ardit)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:11pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-recover-kibana-x-file/333319 "2023-05-17T23:11:43Z")

</div>

Is there any possibility to recover from lost kibana\_x index? \[opc@elasticsearch-2 ~\]$ curl -XGET http://localhost:9200/\_cat/shards/.kibana\_7.12.0\_001 .kibana\_7.12.0\_001 0 p UNASSIGNED .kibana\_7.12.0\_001 0 r UNASSIG…

---

## [How logstash jdbc plugin fetch data from database](https://discuss.elastic.co/t/how-logstash-jdbc-plugin-fetch-data-from-database/333103)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 14\
**Last updated:** [May 17, 2023, 9:09pm UTC](https://discuss.elastic.co/t/how-logstash-jdbc-plugin-fetch-data-from-database/333103 "2023-05-17T21:09:51Z")

</div>

Hi I have informix database that contain tons of tables and records that need to join some of them and send to elasticsearch. Result of this join are 70 columns and 100M records. Here is the requirements: 1-For first …

---

## [Elastic search practice exam reconnect to the lab](https://discuss.elastic.co/t/elastic-search-practice-exam-reconnect-to-the-lab/333601)

<div class="topic-metadata">

**Author:** [@Kimberly](https://discuss.elastic.co/u/Kimberly)\
**Replies:** 5\
**Last updated:** [May 17, 2023, 7:00pm UTC](https://discuss.elastic.co/t/elastic-search-practice-exam-reconnect-to-the-lab/333601 "2023-05-17T19:00:02Z")

</div>

I am trying to take a practice exam for Elasticsearch. I set it up a week ago and want to resume thru strigo. It is saying "your lab is reconnecting" over 30 minutes but still can't get in. Can some one help? Tx

---

## [Issue with Beats forwarding to logstash](https://discuss.elastic.co/t/issue-with-beats-forwarding-to-logstash/333689)

<div class="topic-metadata">

**Author:** [@vhaispdeaded](https://discuss.elastic.co/u/vhaispdeaded)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 6:49pm UTC](https://discuss.elastic.co/t/issue-with-beats-forwarding-to-logstash/333689 "2023-05-17T18:49:16Z")

</div>

Our enterprise configures our AWS EC2 instances with Auditbeat, Filebeat, Journalbeat, Metricbeat, and Packetbeat to forward to a set of logstash servers. Our /var/log/messages, and /var/log/secure files are filled with …

---

## [Which is better RAM allocation strategy?](https://discuss.elastic.co/t/which-is-better-ram-allocation-strategy/333497)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 6:07pm UTC](https://discuss.elastic.co/t/which-is-better-ram-allocation-strategy/333497 "2023-05-17T18:07:07Z")

</div>

If I have a data node with 128GB of RAM. Is it better to allocate 64GB to ES and 64GB to system? Or would it be ok (or even better) to allocate say 100GB to ES and leave 28GB to system? Our system is write heavy; ther…

---

## [Check if field from XML is object or array of objects?](https://discuss.elastic.co/t/check-if-field-from-xml-is-object-or-array-of-objects/333686)

<div class="topic-metadata">

**Author:** [@Meme-ento](https://discuss.elastic.co/u/Meme-ento)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 5:50pm UTC](https://discuss.elastic.co/t/check-if-field-from-xml-is-object-or-array-of-objects/333686 "2023-05-17T17:50:19Z")

</div>

I have the following case happening. I have an application that is configured to send data via a webhook like push method via HTTP rest api whenever data is inserted in the application database. Im using this functionali…

---

## [How to integrate in-house ticketing tool with ELK using API's](https://discuss.elastic.co/t/how-to-integrate-in-house-ticketing-tool-with-elk-using-apis/333645)

<div class="topic-metadata">

**Author:** [@DhananjayPatil](https://discuss.elastic.co/u/DhananjayPatil)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:42pm UTC](https://discuss.elastic.co/t/how-to-integrate-in-house-ticketing-tool-with-elk-using-apis/333645 "2023-05-17T15:42:41Z")

</div>

Hi Everyone, I am currently working on integrating our in-house ticketing tool with ELK. Specifically, I would like to fetch data from ELK and automatically create incidents in our ticketing tool when specific conditions…

---

## [EFK Stack on Kubernetes - Collecting logs from default namespace](https://discuss.elastic.co/t/efk-stack-on-kubernetes-collecting-logs-from-default-namespace/333672)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:31pm UTC](https://discuss.elastic.co/t/efk-stack-on-kubernetes-collecting-logs-from-default-namespace/333672 "2023-05-17T14:31:22Z")

</div>

Hi, I am using EFK stack on Kubernetes, I want to configure fluentd to collect logs from one specific namespace, the default namespace. This is my fleuntd config file: \<label @FLUENT\_LOG\> \<match fluent.\*\*\> …

---

## [Getting Logstash output cannot be used with Fleet Server integration in Fleet Server Policy. Please create a new ElasticSearch output](https://discuss.elastic.co/t/getting-logstash-output-cannot-be-used-with-fleet-server-integration-in-fleet-server-policy-please-create-a-new-elasticsearch-output/330980)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 5\
**Last updated:** [May 17, 2023, 2:24pm UTC](https://discuss.elastic.co/t/getting-logstash-output-cannot-be-used-with-fleet-server-integration-in-fleet-server-policy-please-create-a-new-elasticsearch-output/330980 "2023-05-17T14:24:34Z")

</div>

This is pretty straightforward as you can see : I get this after trying to configure a logstash output on Fleet and going through all the steps. I dont know what to do with this error message as it does not make sens…

---

## [Logstash config - Kafka and CEF](https://discuss.elastic.co/t/logstash-config-kafka-and-cef/333669)

<div class="topic-metadata">

**Author:** [@elizZ](https://discuss.elastic.co/u/elizZ)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:18pm UTC](https://discuss.elastic.co/t/logstash-config-kafka-and-cef/333669 "2023-05-17T14:18:23Z")

</div>

Hi, I have a Logstash input of Kafka(codec cef), that consumes arcsight CEF format events from a kafka topic and writes it to elastic with 'elasticsearch' output I have an issue when some of the events have multiline f…

---

## [Logstash - Syslog Output - Custom message](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333668)

<div class="topic-metadata">

**Author:** [@Nandhini\_Viswanathan](https://discuss.elastic.co/u/Nandhini_Viswanathan)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:07pm UTC](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333668 "2023-05-17T14:07:31Z")

</div>

Hi, Reopening for Discussion. I'm working with Logstash - Syslog Output and I've found problem with custom field message. I'm using Elasticstack 7.10.2 I've installed logstash syslog-output plugin version 3.0.5. /usr…

---

## [Logstash JDBC insert after select completes](https://discuss.elastic.co/t/logstash-jdbc-insert-after-select-completes/333660)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 1:06pm UTC](https://discuss.elastic.co/t/logstash-jdbc-insert-after-select-completes/333660 "2023-05-17T13:06:51Z")

</div>

Hey All Just looking to understand if there is some way that I can run a SQL INSERT before and after a SELECT statement in the filter section to update a tracking table in the DB to say that the select query has started…

---

## [Failed to obtain node locks, tried \[/usr/share/elasticsearch/data\]; maybe these locations are not writable or multiple nodes were started](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started/333657)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 12:54pm UTC](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started/333657 "2023-05-17T12:54:40Z")

</div>

I installed elasticsearch on kubernetes using helm. elasticsearch version: 8.5.1 pods do not stand up. Error in pods log: {"@timestamp":"2023-05-17T12:50:32.223Z", "log.level":"ERROR", "message":"fatal exception while…

---

## [Syslog Ingest Pipeline not targeting data](https://discuss.elastic.co/t/syslog-ingest-pipeline-not-targeting-data/333204)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 12:30pm UTC](https://discuss.elastic.co/t/syslog-ingest-pipeline-not-targeting-data/333204 "2023-05-17T12:30:13Z")

</div>

We're trying to utilize ingest pipelines for some of our Filebeat data and the pipeline doesn't seem to processing any events. We've run this through the grok parser and that provides us with the correct output so I'm n…

---

## [Can I reload after a setting change in elasticsearch.yml?](https://discuss.elastic.co/t/can-i-reload-after-a-setting-change-in-elasticsearch-yml/333565)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 2:40pm UTC](https://discuss.elastic.co/t/can-i-reload-after-a-setting-change-in-elasticsearch-yml/333565 "2023-05-16T14:40:30Z")

</div>

Is there a way to only reload the settings and not the whole stack ?

---

## [Working days - how to find](https://discuss.elastic.co/t/working-days-how-to-find/332404)

<div class="topic-metadata">

**Author:** [@TheyCallMeTrinity](https://discuss.elastic.co/u/TheyCallMeTrinity)\
**Replies:** 8\
**Last updated:** [May 17, 2023, 11:54am UTC](https://discuss.elastic.co/t/working-days-how-to-find/332404 "2023-05-17T11:54:04Z")

</div>

Hi, I have a problem. I'm getting data from the api which lists the rooms that users have booked. Each room has set working days and hours. I need to make a table where the Average real resource usage will be calculat…

---

## [Snapshots retention policy sans snapshots automatiques](https://discuss.elastic.co/t/snapshots-retention-policy-sans-snapshots-automatiques/333386)

<div class="topic-metadata">

**Author:** [@DataXavier](https://discuss.elastic.co/u/DataXavier)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 9:55am UTC](https://discuss.elastic.co/t/snapshots-retention-policy-sans-snapshots-automatiques/333386 "2023-05-17T09:55:08Z")

</div>

Bonjour, Je travaille sur un projet basé sur Elasticsearch. J'ai besoin de créer des snapshots manuellement avec des metadata. Je voudrais mettre une retention policy sur ces snapshots. J'ai essayé avec SLM mais il sem…

---

## [CAPACITY test over the years for STORAGE RAM and so](https://discuss.elastic.co/t/capacity-test-over-the-years-for-storage-ram-and-so/333644)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 9:34am UTC](https://discuss.elastic.co/t/capacity-test-over-the-years-for-storage-ram-and-so/333644 "2023-05-17T09:34:52Z")

</div>

i have number of indexes I would be happy to know if there is a certain formula or what is the correct way to determine how much CAPACITY is needed in 4 years thanks for the help

---

## [I want to put my grok inside if else block of logstash I want the fields to be displayed in kibana it's executing but not displaying the actual fields](https://discuss.elastic.co/t/i-want-to-put-my-grok-inside-if-else-block-of-logstash-i-want-the-fields-to-be-displayed-in-kibana-its-executing-but-not-displaying-the-actual-fields/333637)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 8:48am UTC](https://discuss.elastic.co/t/i-want-to-put-my-grok-inside-if-else-block-of-logstash-i-want-the-fields-to-be-displayed-in-kibana-its-executing-but-not-displaying-the-actual-fields/333637 "2023-05-17T08:48:56Z")

</div>

filter { if \[IgmpSnooping\] == "%IGMPSNOOPING-6-NO\_IGMP\_QUERIER" { grok { match =\> { "message" =\> "\<%{INT:priority:int}\>%{SYSLOGTIMESTAMP:timestamp}\\s+%{HOSTNAME:device\_name}\\s+\\IgmpSnooping:\\s+%{DATA:IgmpSnooping}\\…

---

## [Grok filter working in online debuggers but not in actual implementation](https://discuss.elastic.co/t/grok-filter-working-in-online-debuggers-but-not-in-actual-implementation/333428)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 3\
**Last updated:** [May 17, 2023, 8:35am UTC](https://discuss.elastic.co/t/grok-filter-working-in-online-debuggers-but-not-in-actual-implementation/333428 "2023-05-17T08:35:10Z")

</div>

This seems to give \_grokparsefailure a hundred percent of the time: if \[event\]\[action\]=="Process Creation" { grok { match =\> { "winlog.event\_data.NewProcessName" =\> "(?\<directory\>.\*)\\\\(?\<exe…

---

## [Count filtering visualization](https://discuss.elastic.co/t/count-filtering-visualization/333527)

<div class="topic-metadata">

**Author:** [@clmtb](https://discuss.elastic.co/u/clmtb)\
**Replies:** 7\
**Last updated:** [May 17, 2023, 8:06am UTC](https://discuss.elastic.co/t/count-filtering-visualization/333527 "2023-05-17T08:06:51Z")

</div>

Hi all, I am trying to create a pretty simple visualization in Kibana in TSVB Table, with the count of different fields but with a filter applied. To be more precise, I want to get the count of every values higher than …

---

## [Ignore\_z\_value is not supported](https://discuss.elastic.co/t/ignore-z-value-is-not-supported/333571)

<div class="topic-metadata">

**Author:** [@gabi939](https://discuss.elastic.co/u/gabi939)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 7:45am UTC](https://discuss.elastic.co/t/ignore-z-value-is-not-supported/333571 "2023-05-17T07:45:05Z")

</div>

Elasticsearch Version 7.7.0 Java Version 1.8.0\_252 OS Version Ubuntu 18.04 Problem Description According to: I should be able to use parameter ignore\_z\_value to ignore z values indexed to geo\_point field. But it do…

---

## [Guidance on mapping and query](https://discuss.elastic.co/t/guidance-on-mapping-and-query/333592)

<div class="topic-metadata">

**Author:** [@ichbindermike](https://discuss.elastic.co/u/ichbindermike)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 6:55am UTC](https://discuss.elastic.co/t/guidance-on-mapping-and-query/333592 "2023-05-17T06:55:27Z")

</div>

I have a question on what might be the best approach to structure my data. I have 8 indices that each contain about 4-7 fields (different ones), but I would like to search across all indices and multiple of those fields.…

---

## [Logstash new record](https://discuss.elastic.co/t/logstash-new-record/333629)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 6:53am UTC](https://discuss.elastic.co/t/logstash-new-record/333629 "2023-05-17T06:53:52Z")

</div>

How to handle the logstash configuration in the case when I run the JDBC query and then there are no results through 1 to 10 minutes, if there is no result I need to generate a new record to store it in as document in th…

---

## [Mismatch between Elastic Query Aggretion and Kibana Visualize Function](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619)

<div class="topic-metadata">

**Author:** [@phong\_elastic](https://discuss.elastic.co/u/phong_elastic)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 4:29am UTC](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619 "2023-05-17T04:29:42Z")

</div>

Hello everyone. I'm trying create a table that have the same data like the table in Lens Visualization by using the Elasticsearch Query. I'm confusing cause there's is a different between the data I get by the query an…

---

## [Logstash Syslog Input - Capture the Connecting Host's IP Address](https://discuss.elastic.co/t/logstash-syslog-input-capture-the-connecting-hosts-ip-address/333602)

<div class="topic-metadata">

**Author:** [@m52](https://discuss.elastic.co/u/m52)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 4:16am UTC](https://discuss.elastic.co/t/logstash-syslog-input-capture-the-connecting-hosts-ip-address/333602 "2023-05-17T04:16:35Z")

</div>

Hi, Newbie to Logstash here and could use some assistance regarding the Syslog input connector. I currently have the Syslog connector working successfully, but noticed the JSON output has a host.ip element that always…

---

## [Ingest data from 3 databases](https://discuss.elastic.co/t/ingest-data-from-3-databases/330624)

<div class="topic-metadata">

**Author:** [@baba72210](https://discuss.elastic.co/u/baba72210)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 3:45am UTC](https://discuss.elastic.co/t/ingest-data-from-3-databases/330624 "2023-05-17T03:45:39Z")

</div>

Hi everyone, I have a project where I need to index data from 3 differents databases to be able to search for revelant information. I have a Cassandra, a MSSQL and a mongoDB. Do you think it would be possible to use the…

---

## [Elasticsearch createTranslogSyncProcessor part of source code, log level Setting is not appropriate?](https://discuss.elastic.co/t/elasticsearch-createtranslogsyncprocessor-part-of-source-code-log-level-setting-is-not-appropriate/332539)

<div class="topic-metadata">

**Author:** [@yujie\_wang](https://discuss.elastic.co/u/yujie_wang)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:21am UTC](https://discuss.elastic.co/t/elasticsearch-createtranslogsyncprocessor-part-of-source-code-log-level-setting-is-not-appropriate/332539 "2023-05-17T03:21:16Z")

</div>

Hi, Recently, I've been reading the source code of the latest version (8.7.1) of Elasticsearch and I have a question about the log level settings that I can't figure out. I noticed that the "failed to sync translog" is…

---

## [java.lang.IllegalArgumentException: unknown setting \[node.data\] please check that any required plugins are installed, or check the breaking changes documentation for removed settings](https://discuss.elastic.co/t/java-lang-illegalargumentexception-unknown-setting-node-data-please-check-that-any-required-plugins-are-installed-or-check-the-breaking-changes-documentation-for-removed-settings/333558)

<div class="topic-metadata">

**Author:** [@tungnx1](https://discuss.elastic.co/u/tungnx1)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 2:55am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-unknown-setting-node-data-please-check-that-any-required-plugins-are-installed-or-check-the-breaking-changes-documentation-for-removed-settings/333558 "2023-05-17T02:55:06Z")

</div>

help !!! i setup Cluster Elasticsearch. After config file elasticsearch.yml node.name: es-data-1 node.data: true Log: java.lang.IllegalArgumentException: unknown setting \[node.data\] please check that any required pl…

---

## [Upgraded go version for 2.7.x](https://discuss.elastic.co/t/upgraded-go-version-for-2-7-x/333608)

<div class="topic-metadata">

**Author:** [@zpear](https://discuss.elastic.co/u/zpear)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 11:58pm UTC](https://discuss.elastic.co/t/upgraded-go-version-for-2-7-x/333608 "2023-05-16T23:58:39Z")

</div>

Hi all, I'm currently running ECK 2.7.0 but noticed a critical injection cve, CVE-2023-24538, that's brought in from the version of golang ECK runs with. I see since then, the go version has been updated (Update docker.i…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=376)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=378)
