# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=392

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 393

---

## [Filter message log in logstash](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 2:37am UTC](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524 "2023-04-24T02:37:04Z")

</div>

i want to add filter to logstash to convert message to json format this is my example API response \< HTTP 200 - body: {"result": \[{"status": {"code": -18, "message": "No permission for the resource"}, "url": "/os/hi"}\]…

---

## [Reporting Diagnostics tool fails on capture screenshot](https://discuss.elastic.co/t/reporting-diagnostics-tool-fails-on-capture-screenshot/330080)

<div class="topic-metadata">

**Author:** [@sblack](https://discuss.elastic.co/u/sblack)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 10:59pm UTC](https://discuss.elastic.co/t/reporting-diagnostics-tool-fails-on-capture-screenshot/330080 "2023-04-23T22:59:32Z")

</div>

I ran the Reporting Diagnostics tool and after sometime, the following error is displayed: Something isn't working properly. There was a problem running the diagnostic: Error For additional debugging information, I …

---

## [Kibana cannot connect to the Elastic Package Registry, which provides Elastic Agent integrations](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/330580)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 1:21pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/330580 "2023-04-23T13:21:01Z")

</div>

There are a few posts noting this error message, without a solution. In case somebody stumbles upon it : This message may be very misleading, in case you did not activate xpack security First, check your service logs…

---

## [Not able to see index log file in elastic search](https://discuss.elastic.co/t/not-able-to-see-index-log-file-in-elastic-search/330571)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 8:06pm UTC](https://discuss.elastic.co/t/not-able-to-see-index-log-file-in-elastic-search/330571 "2023-04-23T20:06:46Z")

</div>

I am sending this log file web\_access.log 54.36.149.41 - - \[22/Jan/2019:03:56:14 +0330\] "GET /filter/27|13%20%D9%85%DA%AF%D8%A7%D9%BE%DB%8C%DA%A9%D8%B3%D9%84,27|%DA%A9%D9%85%D8%AA%D8%B1%20%D8%A7%D8%B2%205%20%D9%85%DA%A…

---

## [Logstash is not able to connect to workplace search](https://discuss.elastic.co/t/logstash-is-not-able-to-connect-to-workplace-search/330585)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 5:27pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-connect-to-workplace-search/330585 "2023-04-23T17:27:44Z")

</div>

Hi Team, I have added workplace search as a output plugin. output { elastic\_workplace\_search { source =\> "6555639ee4f75566c32f4298" access\_token =\> "efzq36opkajivo13judz65n9" url =\> "https://153.1.16.10:3…

---

## [Handle Json file](https://discuss.elastic.co/t/handle-json-file/330562)

<div class="topic-metadata">

**Author:** [@Ashraf123](https://discuss.elastic.co/u/Ashraf123)\
**Replies:** 2\
**Last updated:** [April 23, 2023, 3:35pm UTC](https://discuss.elastic.co/t/handle-json-file/330562 "2023-04-23T15:35:54Z")

</div>

Hello All, I have the following Json file collected by logstash. The problem I'm facing is with Item ID as it add json nested object with for each item. The problem I can't build dashboards for these items with this str…

---

## [Need help adding Fleet server](https://discuss.elastic.co/t/need-help-adding-fleet-server/330565)

<div class="topic-metadata">

**Author:** [@Tanner\_Sutherlin](https://discuss.elastic.co/u/Tanner_Sutherlin)\
**Replies:** 18\
**Last updated:** [April 23, 2023, 2:52pm UTC](https://discuss.elastic.co/t/need-help-adding-fleet-server/330565 "2023-04-23T14:52:11Z")

</div>

I've installed the fleet server on my virtual Ubuntu version 22 machine but I can't get the fleet server to show in Kibana. I checked Ubuntu elastic-agent service and it was showing inactive so I started it with "systemc…

---

## [ES nodes fail to ping with ports open and Telnet'able](https://discuss.elastic.co/t/es-nodes-fail-to-ping-with-ports-open-and-telnetable/330581)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 4\
**Last updated:** [April 23, 2023, 2:25pm UTC](https://discuss.elastic.co/t/es-nodes-fail-to-ping-with-ports-open-and-telnetable/330581 "2023-04-23T14:25:11Z")

</div>

Hi there! Weirdly, still did not find a solution to a problem. I'm creating a new cluster right now (v6.8.6). And all nodes only see themselves. All of them set up to be master and have discovery.zen.minimum\_master\_no…

---

## [Elasticsearch cluster planning/sizing](https://discuss.elastic.co/t/elasticsearch-cluster-planning-sizing/330579)

<div class="topic-metadata">

**Author:** [@bentzy](https://discuss.elastic.co/u/bentzy)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-planning-sizing/330579 "2023-04-23T13:49:32Z")

</div>

I want to deploy Elasticsearch with ECK to enable search in a large production GitLab Cluster. I read that Elasticsearch cluster size should be 0.5 of the total of all repos(0.5 \* 2TB). I ask about the ES cluster plannin…

---

## [Kibana tries to connect to 169.254.169.254:80](https://discuss.elastic.co/t/kibana-tries-to-connect-to-169-254-169-254-80/327353)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 19\
**Last updated:** [April 23, 2023, 7:43am UTC](https://discuss.elastic.co/t/kibana-tries-to-connect-to-169-254-169-254-80/327353 "2023-04-23T07:43:51Z")

</div>

Hello elastic community, any idea why Kibana tries to connect to 169.254.169.254:80 for first 5-6 minutes after I start it? I noticed this with version 7.17.9, but I think it was like this at least for all 7.17.X versi…

---

## [How to implement data stream splitting for multiple types in Logstash's Java plugin?](https://discuss.elastic.co/t/how-to-implement-data-stream-splitting-for-multiple-types-in-logstashs-java-plugin/330569)

<div class="topic-metadata">

**Author:** [@woxinfeishi](https://discuss.elastic.co/u/woxinfeishi)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 2:32am UTC](https://discuss.elastic.co/t/how-to-implement-data-stream-splitting-for-multiple-types-in-logstashs-java-plugin/330569 "2023-04-23T02:32:42Z")

</div>

When using the logstash-input-rabbitmq plugin, multiple service logs can be collected by specifying different types in the same Logstash configuration file. Now I want to implement a Java version of the Logstash-input-ro…

---

## [Api\_key privilege](https://discuss.elastic.co/t/api-key-privilege/330558)

<div class="topic-metadata">

**Author:** [@7Alex7](https://discuss.elastic.co/u/7Alex7)\
**Replies:** 0\
**Last updated:** [April 22, 2023, 6:53pm UTC](https://discuss.elastic.co/t/api-key-privilege/330558 "2023-04-22T18:53:33Z")

</div>

I will use Search in my projects but would like to test it before buying. Projects need temporary credentials functionality. The Api\_key looks good for this. One more restriction is that the user must be able to create …

---

## [Calling Elastic search from remote server via https](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254)

<div class="topic-metadata">

**Author:** [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Replies:** 12\
**Last updated:** [April 22, 2023, 10:48am UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254 "2023-04-22T10:48:37Z")

</div>

This works fine on local machine curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic: https://localhost:9200 This does not work remotely curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic: https:/…

---

## [How to handle default value for logstash pipeline efficiently?](https://discuss.elastic.co/t/how-to-handle-default-value-for-logstash-pipeline-efficiently/330335)

<div class="topic-metadata">

**Author:** [@Hatef\_Alipour](https://discuss.elastic.co/u/Hatef_Alipour)\
**Replies:** 2\
**Last updated:** [April 22, 2023, 8:19am UTC](https://discuss.elastic.co/t/how-to-handle-default-value-for-logstash-pipeline-efficiently/330335 "2023-04-22T08:19:22Z")

</div>

I have a logstash pipeline that its filter part looks like this: filter { if condition { prune { blacklist\_names =\> \["^cat\[1-8\]$","^classifier.version$","^accessory\_check$"\] …

---

## [Sysmon events not getting into the SOC and kibana](https://discuss.elastic.co/t/sysmon-events-not-getting-into-the-soc-and-kibana/330543)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 9:16pm UTC](https://discuss.elastic.co/t/sysmon-events-not-getting-into-the-soc-and-kibana/330543 "2023-04-21T21:16:30Z")

</div>

Hi, I have been trying to get my sysmon events to show up in kibana. Does anyone know if there is a debugging check list that I could follow? I uninstalled and sysmon and winlogbeat. I went into the sysmon.yml and I se…

---

## [Can I move my sysmon service to another folder](https://discuss.elastic.co/t/can-i-move-my-sysmon-service-to-another-folder/330542)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 8:55pm UTC](https://discuss.elastic.co/t/can-i-move-my-sysmon-service-to-another-folder/330542 "2023-04-21T20:55:11Z")

</div>

When I install sysmon, I can put it in the sysmon folder that I choose. But why does the service reside in C:\\WINDOWS\\Sysmon.exe instead of where I would rather have it? thanks again for any advice or suggestions

---

## [How to delete a runtime field?](https://discuss.elastic.co/t/how-to-delete-a-runtime-field/330526)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-to-delete-a-runtime-field/330526 "2023-04-21T16:47:04Z")

</div>

I am trying to use runtime fields instead of scripted fields and have created one, which I no longer need. Is there any API or from GUI I can delete the runtime fields ?

---

## [Cross index kibana dashboard](https://discuss.elastic.co/t/cross-index-kibana-dashboard/330538)

<div class="topic-metadata">

**Author:** [@George\_ML](https://discuss.elastic.co/u/George_ML)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 4:46pm UTC](https://discuss.elastic.co/t/cross-index-kibana-dashboard/330538 "2023-04-21T16:46:01Z")

</div>

Hello, I am trying to build a dashboard that pulls information from multiple indices. While both indices have the same data, the formatting is different, for example: On index logstash, i have the property resourceId,…

---

## [Hamming Distance on Binary Strings - Latest](https://discuss.elastic.co/t/hamming-distance-on-binary-strings-latest/330292)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 5\
**Last updated:** [April 21, 2023, 2:27pm UTC](https://discuss.elastic.co/t/hamming-distance-on-binary-strings-latest/330292 "2023-04-21T14:27:14Z")

</div>

Hello, I want to do hamming distance on binary strings in elasticsearch, and I want to control the distance. In my case, the binary strings have a length of 256 and I want everything with a hamming distance of 32 or be…

---

## [Permanent filter](https://discuss.elastic.co/t/permanent-filter/330370)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 1:08pm UTC](https://discuss.elastic.co/t/permanent-filter/330370 "2023-04-21T13:08:53Z")

</div>

Is there a way to make a "permanent filter" or make a filter non-removable? The reason for this is, I want the user to only see data relevant to their company. If they simply removed the filter, they would be able to vi…

---

## [How to have an array that pulls up linux commands](https://discuss.elastic.co/t/how-to-have-an-array-that-pulls-up-linux-commands/330116)

<div class="topic-metadata">

**Author:** [@Wad1636](https://discuss.elastic.co/u/Wad1636)\
**Replies:** 6\
**Last updated:** [April 21, 2023, 1:06pm UTC](https://discuss.elastic.co/t/how-to-have-an-array-that-pulls-up-linux-commands/330116 "2023-04-21T13:06:34Z")

</div>

Good morning, I would like to have a reassembly of the commands type on linux live and put them in a table, the problem I can't already find how to reassemble the commands. Thanks for your future help.

---

## [Step missing? - Deploy medium installation](https://discuss.elastic.co/t/step-missing-deploy-medium-installation/330520)

<div class="topic-metadata">

**Author:** [@steman-provinzial](https://discuss.elastic.co/u/steman-provinzial)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 12:31pm UTC](https://discuss.elastic.co/t/step-missing-deploy-medium-installation/330520 "2023-04-21T12:31:16Z")

</div>

Hi there! In the documentation for showing how to install a medium installation: ...it is said: This first host holds all roles to help bootstrap the rest of the installation, but you will remove some of its roles in…

---

## [LoLogs are not coming from filebeat to logstash to elasticsearch](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 10:17am UTC](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509 "2023-04-21T10:17:23Z")

</div>

Hi, I have installed filebeat on my windows machine. I've enabled the systema nd logstash module. Here is the filebeat.yml - type: filestream # Unique ID among all inputs, an ID is required. id: my-filestream-id …

---

## [How to send data to the index node](https://discuss.elastic.co/t/how-to-send-data-to-the-index-node/330318)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 4\
**Last updated:** [April 21, 2023, 9:19am UTC](https://discuss.elastic.co/t/how-to-send-data-to-the-index-node/330318 "2023-04-21T09:19:47Z")

</div>

Hello, I wanted to set up a cluster with some nodes and I wanted to install packetbeat on each node so I could monitor the network and then send all the data to the node's packetbeat index.x . It was possible? What would…

---

## [Best way to deploy ELK on K8S bare metal](https://discuss.elastic.co/t/best-way-to-deploy-elk-on-k8s-bare-metal/330502)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 8:50am UTC](https://discuss.elastic.co/t/best-way-to-deploy-elk-on-k8s-bare-metal/330502 "2023-04-21T08:50:06Z")

</div>

Hi Can You share same samples of HELM charts or yaml's for deploy such cluster on 3 bare metal servers. Each of these server has 256 GB RAM and 5xSSD with 9xHDD I need to insure data tier (hot, warm) Can You suggest s…

---

## [Logstash timestamp shift](https://discuss.elastic.co/t/logstash-timestamp-shift/330397)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 7\
**Last updated:** [April 21, 2023, 7:51am UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397 "2023-04-21T07:51:56Z")

</div>

Hi ! I came across a strange behavior while parsing a timestamp epoch style date { match =\> \[ "eventtime\_ms","UNIX" \] target =\> "\[event\]\[created\]" timezone =\> "Etc/GMT+2" } date { match…

---

## [Size of an index](https://discuss.elastic.co/t/size-of-an-index/330387)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [April 21, 2023, 4:55am UTC](https://discuss.elastic.co/t/size-of-an-index/330387 "2023-04-21T04:55:13Z")

</div>

I have 9 tenants. Each tenant is about 1 TB. Could I create 1 index for each tenant? so 9 indices in total? this would mean each index is 1 TB 9 TB of data over 9 indices. To maintain safe shard size, my index will hav…

---

## [Logstash MYSQL jdbc](https://discuss.elastic.co/t/logstash-mysql-jdbc/330410)

<div class="topic-metadata">

**Author:** [@gabrile\_jaime\_gomez](https://discuss.elastic.co/u/gabrile_jaime_gomez)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 6:00am UTC](https://discuss.elastic.co/t/logstash-mysql-jdbc/330410 "2023-04-21T06:00:28Z")

</div>

H i, I'm trying to integrate with mysql and I get the following error. \[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"Java::JavaLang…

---

## [PlainElastic Agent Installation](https://discuss.elastic.co/t/plainelastic-agent-installation/330402)

<div class="topic-metadata">

**Author:** [@Christian\_V](https://discuss.elastic.co/u/Christian_V)\
**Replies:** 2\
**Last updated:** [April 21, 2023, 5:44am UTC](https://discuss.elastic.co/t/plainelastic-agent-installation/330402 "2023-04-21T05:44:21Z")

</div>

Hello, I tried to install via zip/tar on either on windows or linux host, both finished and there is a connection to the self managed fleet server. On Windows if i call diagnost I get the message: Error: failed to fet…

---

## [Elasticsearch helm](https://discuss.elastic.co/t/elasticsearch-helm/330391)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 4\
**Last updated:** [April 21, 2023, 4:26am UTC](https://discuss.elastic.co/t/elasticsearch-helm/330391 "2023-04-21T04:26:45Z")

</div>

Warning Unhealthy 11s (x31 over 4m50s) kubelet Readiness probe failed: Waiting for elasticsearch cluster to become ready (request params: "wait\_for\_status=green&timeout=2s" ) Cluster is not yet ready (requ…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=391)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=393)
