# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=445

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 446

---

## [Getting "event\_agent\_id\_status auth\_metadata\_missing" error while sending logs from standalone elasticagent](https://discuss.elastic.co/t/getting-event-agent-id-status-auth-metadata-missing-error-while-sending-logs-from-standalone-elasticagent/324378)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 2:06am UTC](https://discuss.elastic.co/t/getting-event-agent-id-status-auth-metadata-missing-error-while-sending-logs-from-standalone-elasticagent/324378 "2023-02-01T02:06:18Z")

</div>

I am trying to send the logs from my AKS cluster into Elasticsearch the log that I am getting is "event.agent\_id\_status auth\_metadata\_missing" in my kibana even after all the volume mounts are done correctly here's my …

---

## [How much is xpack-siem, please tell me , thanks](https://discuss.elastic.co/t/how-much-is-xpack-siem-please-tell-me-thanks/324375)

<div class="topic-metadata">

**Author:** [@dingyouqiang](https://discuss.elastic.co/u/dingyouqiang)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 1:04am UTC](https://discuss.elastic.co/t/how-much-is-xpack-siem-please-tell-me-thanks/324375 "2023-02-01T01:04:23Z")

</div>

i don't know the price of xpack and i never use them. I want to know the price , and tell my boss. thanks

---

## [Multiline Logstash that handles timestamp on each line](https://discuss.elastic.co/t/multiline-logstash-that-handles-timestamp-on-each-line/322556)

<div class="topic-metadata">

**Author:** [@Scotsie](https://discuss.elastic.co/u/Scotsie)\
**Replies:** 5\
**Last updated:** [January 31, 2023, 9:58pm UTC](https://discuss.elastic.co/t/multiline-logstash-that-handles-timestamp-on-each-line/322556 "2023-01-31T21:58:46Z")

</div>

I'm currently ingesting logs from multiple devices successfully, one document per row. One particular brand, Polycom, is sending a multiline entry that includes the timestamp for each row. Sample Logging (with normal an…

---

## [Convert NanoSecond Unix timestamp](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368)

<div class="topic-metadata">

**Author:** [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)\
**Replies:** 8\
**Last updated:** [January 31, 2023, 9:57pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368 "2023-01-31T21:57:29Z")

</div>

Hi Folks, Any idea how to convert the nanosecond unix timestamp in logstash filter? date { match =\> \[ "eventtime","UNIX\_MS", "ISO8601" \] target =\> "Epoch" timezone =\> "UT…

---

## [Line break in grok pattern](https://discuss.elastic.co/t/line-break-in-grok-pattern/324369)

<div class="topic-metadata">

**Author:** [@mariana17](https://discuss.elastic.co/u/mariana17)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 8:52pm UTC](https://discuss.elastic.co/t/line-break-in-grok-pattern/324369 "2023-01-31T20:52:38Z")

</div>

I am trying to get the data from a log, however in the middle of the log there is a line break which prevents the Grok filter from reading it correctly. If I adjust it to a single line it works, however, it would require…

---

## [I have a problema with send data from filebeat to Logstash](https://discuss.elastic.co/t/i-have-a-problema-with-send-data-from-filebeat-to-logstash/324366)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 3\
**Last updated:** [January 31, 2023, 8:40pm UTC](https://discuss.elastic.co/t/i-have-a-problema-with-send-data-from-filebeat-to-logstash/324366 "2023-01-31T20:40:01Z")

</div>

Hello, can you help me pleae, I have a filebeat in my local computer and logstash in a VM Ubuntu in VirtualBox, so I check conectivity from my PC to remote server ubuntu with telnet 192.168.1.12 5044 and was successfull …

---

## [Twitter Input - Logstash filter mutate remove\_field - Elasticsearch](https://discuss.elastic.co/t/twitter-input-logstash-filter-mutate-remove-field-elasticsearch/324290)

<div class="topic-metadata">

**Author:** [@xalmer](https://discuss.elastic.co/u/xalmer)\
**Replies:** 10\
**Last updated:** [January 31, 2023, 8:38pm UTC](https://discuss.elastic.co/t/twitter-input-logstash-filter-mutate-remove-field-elasticsearch/324290 "2023-01-31T20:38:45Z")

</div>

Hello eveybody, Im trying to discover the fantastic world of possibilities of ELK. But i stop in a problem, and maybe someone can solve this "equation". Im using the Twitter Input Plugin to receive Twitter data, but i …

---

## [Logstash will not start with /tmp mounted noexec](https://discuss.elastic.co/t/logstash-will-not-start-with-tmp-mounted-noexec/324125)

<div class="topic-metadata">

**Author:** [@chuck1](https://discuss.elastic.co/u/chuck1)\
**Replies:** 6\
**Last updated:** [January 31, 2023, 7:39pm UTC](https://discuss.elastic.co/t/logstash-will-not-start-with-tmp-mounted-noexec/324125 "2023-01-31T19:39:53Z")

</div>

Logstash will not start with the /tmp directory mounted as noexec on RHEL 8.6. We fixed this with Elasticsearch. However, do not have the proper variables, guidance on how to fix this with Logstash. Thank You For Your …

---

## [Pending\_tasks has millions of entries, many of with are exact duplicates of ilm-move-to-step](https://discuss.elastic.co/t/pending-tasks-has-millions-of-entries-many-of-with-are-exact-duplicates-of-ilm-move-to-step/324329)

<div class="topic-metadata">

**Author:** [@jmlucjav](https://discuss.elastic.co/u/jmlucjav)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 6:56pm UTC](https://discuss.elastic.co/t/pending-tasks-has-millions-of-entries-many-of-with-are-exact-duplicates-of-ilm-move-to-step/324329 "2023-01-31T18:56:58Z")

</div>

hi, I have a 7.10.2 cluster, quite large, with 10k indices, and we are having issues with millions of pending tasks being queued at some point. I managed to get a dump of them while they were just 2M, and I saw: 90% …

---

## [TCP input and answer to client](https://discuss.elastic.co/t/tcp-input-and-answer-to-client/324338)

<div class="topic-metadata">

**Author:** [@M\_K1](https://discuss.elastic.co/u/M_K1)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 6:01pm UTC](https://discuss.elastic.co/t/tcp-input-and-answer-to-client/324338 "2023-01-31T18:01:22Z")

</div>

Hello! is it possible to do in logstash? i need to receive strings throuth tcp input and after succssesful recievment i need to answer the client with string for example "ok" or "bad format"

---

## [Running eck in production best practices](https://discuss.elastic.co/t/running-eck-in-production-best-practices/324248)

<div class="topic-metadata">

**Author:** [@elastic-db-user](https://discuss.elastic.co/u/elastic-db-user)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 4:59pm UTC](https://discuss.elastic.co/t/running-eck-in-production-best-practices/324248 "2023-01-31T16:59:09Z")

</div>

I am about to go for running multiple Elasticsearch clusters managed by an eck operator on k8 in production. eIasticsearch, kibana, curator and all other deployments are working as expected. I am wondering if there's any…

---

## [How to ingest firewall log data to elastic security](https://discuss.elastic.co/t/how-to-ingest-firewall-log-data-to-elastic-security/324138)

<div class="topic-metadata">

**Author:** [@yak990](https://discuss.elastic.co/u/yak990)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 4:36pm UTC](https://discuss.elastic.co/t/how-to-ingest-firewall-log-data-to-elastic-security/324138 "2023-01-31T16:36:38Z")

</div>

I've figured out how to parse my firewall logs with logstash, and they are in ECS format now. I can create a new index and edit some settings to get it to show in discover. How do I add the new index pattern to the log…

---

## [Adding rule exceptions](https://discuss.elastic.co/t/adding-rule-exceptions/323422)

<div class="topic-metadata">

**Author:** [@yak990](https://discuss.elastic.co/u/yak990)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 4:09pm UTC](https://discuss.elastic.co/t/adding-rule-exceptions/323422 "2023-01-31T16:09:36Z")

</div>

When adding rule exceptions from existing alerts, it would be great if it auto copied the attributes from the alert into the proposed exception. Right now, I copy down all the relevant attributes into a notebook, and th…

---

## [Data too large indices:data/read/search\[phase/query](https://discuss.elastic.co/t/data-too-large-indices-data-read-search-phase-query/323770)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 10\
**Last updated:** [January 31, 2023, 3:53pm UTC](https://discuss.elastic.co/t/data-too-large-indices-data-read-search-phase-query/323770 "2023-01-31T15:53:51Z")

</div>

Hi How I can increase such value ? for avoid any disturbance in read data over kibana \[parent\] Data too large, data for \[indices:data/read/search\[phase/query\]\] would be \[4093997030/3.8gb\], which is larger than the …

---

## [Elastisearch manifest file](https://discuss.elastic.co/t/elastisearch-manifest-file/324319)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 3:30pm UTC](https://discuss.elastic.co/t/elastisearch-manifest-file/324319 "2023-01-31T15:30:26Z")

</div>

Hi team, Could you please provide any sample manifest files for installing the elasticsearch 8.5.1 (throgh ECK). Thanks&Regards, SM

---

## [Disable fleet setting](https://discuss.elastic.co/t/disable-fleet-setting/323526)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 3:04pm UTC](https://discuss.elastic.co/t/disable-fleet-setting/323526 "2023-01-31T15:04:24Z")

</div>

I have following in my configuration xpack.fleet.agents.enabled: false but log on kibana shows this. why is it still does fleet setup. Am I missing something. \[2023-01-19T14:16:08.293+00:00\]\[INFO \]\[status\] Kibana is n…

---

## [Elastic Platinum License Pricing](https://discuss.elastic.co/t/elastic-platinum-license-pricing/324317)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-platinum-license-pricing/324317 "2023-01-31T14:21:23Z")

</div>

Hello Can someone please help me with info on how to determine the pricing associated with the Platinum license using self-managed ELK instance and how that will vary with the volume of the data or the resources consump…

---

## [Logstash filter split array of json into individual objects](https://discuss.elastic.co/t/logstash-filter-split-array-of-json-into-individual-objects/324245)

<div class="topic-metadata">

**Author:** [@sajjad\_akram](https://discuss.elastic.co/u/sajjad_akram)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 1:43pm UTC](https://discuss.elastic.co/t/logstash-filter-split-array-of-json-into-individual-objects/324245 "2023-01-31T13:43:34Z")

</div>

Hi , iam trying to ingest each json object of array as a new entry/event in dynatrace using logstash. This is my json array {"RequestEventList":\[{"Instant":"2023-01-27T09:00:01.16141Z","RequestKey":"3fcbef69-9-10a608…

---

## [Not able to skip reading oids for down host in logstash Snmp file](https://discuss.elastic.co/t/not-able-to-skip-reading-oids-for-down-host-in-logstash-snmp-file/324335)

<div class="topic-metadata">

**Author:** [@himanshu\_rajput2](https://discuss.elastic.co/u/himanshu_rajput2)\
**Replies:** 0\
**Last updated:** [January 31, 2023, 1:20pm UTC](https://discuss.elastic.co/t/not-able-to-skip-reading-oids-for-down-host-in-logstash-snmp-file/324335 "2023-01-31T13:20:11Z")

</div>

I am using 7.6.2 version of logstash. We are fetching snmp data using walk in logstash conf file. I have used feature of multiple hosts. It is working fine but if any one host is down then it reads all oid for that host …

---

## [Best configuration for 3 Node Cluster](https://discuss.elastic.co/t/best-configuration-for-3-node-cluster/324318)

<div class="topic-metadata">

**Author:** [@sidchaug](https://discuss.elastic.co/u/sidchaug)\
**Replies:** 5\
**Last updated:** [January 31, 2023, 12:55pm UTC](https://discuss.elastic.co/t/best-configuration-for-3-node-cluster/324318 "2023-01-31T12:55:35Z")

</div>

HI There, Currently we having 3 ES nodes(node-1, node-2 and node-3 each of 3TB) , we are creating indexex on daily basic. When we run the command we note that we have 3 PRI & 3 Replicas, is this the best configuration? …

---

## [Kibana control v 8.5.3 does not support scripted fields neither field created in data view](https://discuss.elastic.co/t/kibana-control-v-8-5-3-does-not-support-scripted-fields-neither-field-created-in-data-view/324257)

<div class="topic-metadata">

**Author:** [@monica.brandao](https://discuss.elastic.co/u/monica.brandao)\
**Replies:** 3\
**Last updated:** [January 31, 2023, 12:48pm UTC](https://discuss.elastic.co/t/kibana-control-v-8-5-3-does-not-support-scripted-fields-neither-field-created-in-data-view/324257 "2023-01-31T12:48:29Z")

</div>

In a previous version of Kibana I had some controls that in the new version are deprecated. As I imported the visualizatiosn to the new version, I changed the control to the new verson funcionality,. One of my fields w…

---

## [Dynamical way of getting name and path of Logstash config file](https://discuss.elastic.co/t/dynamical-way-of-getting-name-and-path-of-logstash-config-file/324324)

<div class="topic-metadata">

**Author:** [@sigbo](https://discuss.elastic.co/u/sigbo)\
**Replies:** 0\
**Last updated:** [January 31, 2023, 12:22pm UTC](https://discuss.elastic.co/t/dynamical-way-of-getting-name-and-path-of-logstash-config-file/324324 "2023-01-31T12:22:23Z")

</div>

We have a lot of Logstash configuration files and some handle almost the same data. Along with Logstash we have several other scripts ingesting data into Elasticsearch. Because of the sheer amount, we'd like to be able …

---

## [Error on Running Logstash](https://discuss.elastic.co/t/error-on-running-logstash/324299)

<div class="topic-metadata">

**Author:** [@Meghana1](https://discuss.elastic.co/u/Meghana1)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 11:38am UTC](https://discuss.elastic.co/t/error-on-running-logstash/324299 "2023-01-31T11:38:12Z")

</div>

When I run the following command bin/logstash -f /etc/logstash/logstash-sample.conf . I get the following error runner - An unexpected error occurred! {:error=\>java.nio.file.AccessDeniedException: /usr/share/logstash/…

---

## [Logstash csv export =\> export of unwanted documents multiple times](https://discuss.elastic.co/t/logstash-csv-export-export-of-unwanted-documents-multiple-times/324315)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 0\
**Last updated:** [January 31, 2023, 10:26am UTC](https://discuss.elastic.co/t/logstash-csv-export-export-of-unwanted-documents-multiple-times/324315 "2023-01-31T10:26:44Z")

</div>

Hello, I'm currently experiencing weird behavior of my logstash pipeline. Maybe someone has an idea what I'm currently doing wrong. What I'm trying to do I use a logstash pipeline to extract data from elasticsearch an…

---

## [Logstash unable to process more no of documents](https://discuss.elastic.co/t/logstash-unable-to-process-more-no-of-documents/324213)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 9:44am UTC](https://discuss.elastic.co/t/logstash-unable-to-process-more-no-of-documents/324213 "2023-01-31T09:44:01Z")

</div>

Hello All, I'm tyring to process 40000 documents by running perl script.The issue faced is that in stack management I can see the index being get cereated but the documents are not inserting the index. For a seperate u…

---

## [Why does the query response time optimized significantly after disabling indices.queries.cache.size](https://discuss.elastic.co/t/why-does-the-query-response-time-optimized-significantly-after-disabling-indices-queries-cache-size/324204)

<div class="topic-metadata">

**Author:** [@xiaodid](https://discuss.elastic.co/u/xiaodid)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 8:18am UTC](https://discuss.elastic.co/t/why-does-the-query-response-time-optimized-significantly-after-disabling-indices-queries-cache-size/324204 "2023-01-31T08:18:17Z")

</div>

We have a ES 7.9.16 cluster which has 1 master node and 3 data nodes. Each data node has 31 Gb heap size. We created 2 indexes, each index contains 2.5 billion docs. The query response time is about 1 second while query…

---

## [What is the implication of making a large text field as keyword (using multi-fields)?](https://discuss.elastic.co/t/what-is-the-implication-of-making-a-large-text-field-as-keyword-using-multi-fields/324224)

<div class="topic-metadata">

**Author:** [@DarwinGoyal](https://discuss.elastic.co/u/DarwinGoyal)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 8:07am UTC](https://discuss.elastic.co/t/what-is-the-implication-of-making-a-large-text-field-as-keyword-using-multi-fields/324224 "2023-01-31T08:07:55Z")

</div>

What are the considerations that I should take into account while making a field as keyword? To provide some search capabilities I need to make a text field as keyword. I am not sure if there are any performance implica…

---

## [How to add password authorization](https://discuss.elastic.co/t/how-to-add-password-authorization/323713)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 14\
**Last updated:** [January 31, 2023, 7:52am UTC](https://discuss.elastic.co/t/how-to-add-password-authorization/323713 "2023-01-31T07:52:15Z")

</div>

Hi I've setup elk stack version 8.6.0. I've disabled authorization initially because ive installed it using a ansible playbook. by any way can i setup authorization from front end after i access kibana from front end?

---

## [Cluster\_block\_exception does not allow me to delete an index](https://discuss.elastic.co/t/cluster-block-exception-does-not-allow-me-to-delete-an-index/324218)

<div class="topic-metadata">

**Author:** [@DarwinGoyal](https://discuss.elastic.co/u/DarwinGoyal)\
**Replies:** 6\
**Last updated:** [January 31, 2023, 7:50am UTC](https://discuss.elastic.co/t/cluster-block-exception-does-not-allow-me-to-delete-an-index/324218 "2023-01-31T07:50:46Z")

</div>

I created one index with "blocks.metadata": true. PUT darwin-test-shard/\_settings { "blocks.metadata": true } Now whenever I try to access \_cat/indices, I get { "error" : { "root\_cause" : \[ { "ty…

---

## [Log Source](https://discuss.elastic.co/t/log-source/324249)

<div class="topic-metadata">

**Author:** [@Phoenix1](https://discuss.elastic.co/u/Phoenix1)\
**Replies:** 3\
**Last updated:** [January 31, 2023, 7:25am UTC](https://discuss.elastic.co/t/log-source/324249 "2023-01-31T07:25:27Z")

</div>

How to get the list of all Log sources ingestng logs in Elastic security.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=444)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=446)
