# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=495

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 496

---

## [Threatintel module filebeat](https://discuss.elastic.co/t/threatintel-module-filebeat/317858)

<div class="topic-metadata">

**Author:** [@emmanuel\_stevens\_LED](https://discuss.elastic.co/u/emmanuel_stevens_LED)\
**Replies:** 6\
**Last updated:** [November 18, 2022, 4:25pm UTC](https://discuss.elastic.co/t/threatintel-module-filebeat/317858 "2022-11-18T16:25:07Z")

</div>

Hello, I activate the theatintel module for filebeat but still doesn t get any datas i have this in my logs ''' Nov 1 03:00:02 hostname filebeat\[560069\]: {"log.level":"info","@timestamp":"2022-11-01T03:00:02.308Z"…

---

## [Inconsistent results with http\_poller & XML parsing](https://discuss.elastic.co/t/inconsistent-results-with-http-poller-xml-parsing/319310)

<div class="topic-metadata">

**Author:** [@jdswifty](https://discuss.elastic.co/u/jdswifty)\
**Replies:** 1\
**Last updated:** [November 18, 2022, 3:53pm UTC](https://discuss.elastic.co/t/inconsistent-results-with-http-poller-xml-parsing/319310 "2022-11-18T15:53:09Z")

</div>

Looking for some advice here on an issue i'm facing with http\_poller & xml parsing. I'm polling 2 urls every 60 secs that return XML & getting some very inconsistent results. Sometimes i'm getting perfect output (3 dis…

---

## [Logstash ConfigurationError](https://discuss.elastic.co/t/logstash-configurationerror/319218)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 4\
**Last updated:** [November 18, 2022, 3:33pm UTC](https://discuss.elastic.co/t/logstash-configurationerror/319218 "2022-11-18T15:33:05Z")

</div>

Hello, When I run logstash with this configuration file I get these errors. Do you have a solution? Best regards, /etc/logstash/conf.d/logstash-syslog.conf input { tcp { port =\> 5000 type =\> syslog } u…

---

## [Problems starting logstash (snmptrap)](https://discuss.elastic.co/t/problems-starting-logstash-snmptrap/319230)

<div class="topic-metadata">

**Author:** [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Replies:** 3\
**Last updated:** [November 18, 2022, 3:14pm UTC](https://discuss.elastic.co/t/problems-starting-logstash-snmptrap/319230 "2022-11-18T15:14:32Z")

</div>

Hello, I have a problem starting logstash. If I start logstash via "systemctl start logstash.service" I get the following error message: \[2022-11-17T18:11:59,947\]\[WARN \]\[logstash.inputs.snmptrap \]\[main\]\[eed358a3fbc602…

---

## [Logstash configuration error](https://discuss.elastic.co/t/logstash-configuration-error/319270)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 5\
**Last updated:** [November 18, 2022, 3:12pm UTC](https://discuss.elastic.co/t/logstash-configuration-error/319270 "2022-11-18T15:12:54Z")

</div>

Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:vpn, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\t\\r\\n\], "#", \[A-Za-z0-9\_-\], '"', "'", \[A-Za-z\_\], "-", \[0-9\], …

---

## [Index for rule erros](https://discuss.elastic.co/t/index-for-rule-erros/319064)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 2\
**Last updated:** [November 18, 2022, 2:56pm UTC](https://discuss.elastic.co/t/index-for-rule-erros/319064 "2022-11-18T14:56:05Z")

</div>

Hello! I need create dashboard, which contains rule errors. Which index does contain rule errors?

---

## [Optimizing single-node search performance](https://discuss.elastic.co/t/optimizing-single-node-search-performance/319292)

<div class="topic-metadata">

**Author:** [@Jozef](https://discuss.elastic.co/u/Jozef)\
**Replies:** 3\
**Last updated:** [November 18, 2022, 2:13pm UTC](https://discuss.elastic.co/t/optimizing-single-node-search-performance/319292 "2022-11-18T14:13:20Z")

</div>

Hello all, I am relatively new to Elasticsearch, and am currently trying to optimize a single-node ES instance. I am trying to understand a concept, which seems to have conflicting information. First of all, the data I…

---

## [How can I know kibana dashboard latency, max indexing tps, data volume queried per time etc](https://discuss.elastic.co/t/how-can-i-know-kibana-dashboard-latency-max-indexing-tps-data-volume-queried-per-time-etc/319306)

<div class="topic-metadata">

**Author:** [@qksjdhi1212](https://discuss.elastic.co/u/qksjdhi1212)\
**Replies:** 1\
**Last updated:** [November 18, 2022, 1:47pm UTC](https://discuss.elastic.co/t/how-can-i-know-kibana-dashboard-latency-max-indexing-tps-data-volume-queried-per-time-etc/319306 "2022-11-18T13:47:32Z")

</div>

I wanted to test my es to find ideal cluster volume in my production level (the number of shards and their size etc) I watched one video Quantitative Cluster Sizing and decided to follow steps in the video (Quantitati…

---

## [How to use DATEDIFF with logstash jdbc\_static filter](https://discuss.elastic.co/t/how-to-use-datediff-with-logstash-jdbc-static-filter/319293)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 0\
**Last updated:** [November 18, 2022, 12:11pm UTC](https://discuss.elastic.co/t/how-to-use-datediff-with-logstash-jdbc-static-filter/319293 "2022-11-18T12:11:16Z")

</div>

Hi, I want to calculate the DATEDIFF under logstash and use it later under filter-\>jdbc\_static -\>local\_lookups query for comparison. when I tried to Calculate DATEDIFF under filter-\>jdbc\_static -\>local\_lookups , I g…

---

## [Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"NoMethodError", :message=\>"undefined method \`close' for nil:NilClass"](https://discuss.elastic.co/t/failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-nomethoderror-message-undefined-method-close-for-nil-nilclass/319186)

<div class="topic-metadata">

**Author:** [@Vedansh\_Singhal](https://discuss.elastic.co/u/Vedansh_Singhal)\
**Replies:** 10\
**Last updated:** [November 18, 2022, 11:14am UTC](https://discuss.elastic.co/t/failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-nomethoderror-message-undefined-method-close-for-nil-nilclass/319186 "2022-11-18T11:14:37Z")

</div>

\[2022-11-17T09:26:38,925\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.version"=\>"6.8.23"} \[2022-11-17T09:26:42,617\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::Pipel…

---

## [Connection exception during geoip database \[ERROR\]\[o.e.i.g.GeoIpDownloader \]\[WUWVC0ASX02\]](https://discuss.elastic.co/t/connection-exception-during-geoip-database-error-o-e-i-g-geoipdownloader-wuwvc0asx02/318942)

<div class="topic-metadata">

**Author:** [@Kamil\_BdBelfort](https://discuss.elastic.co/u/Kamil_BdBelfort)\
**Replies:** 4\
**Last updated:** [November 18, 2022, 9:45am UTC](https://discuss.elastic.co/t/connection-exception-during-geoip-database-error-o-e-i-g-geoipdownloader-wuwvc0asx02/318942 "2022-11-18T09:45:36Z")

</div>

Hi there, I've downloaded the latest version of elasticsearch 8.5.1 and when I try to run it (bin\\elasticsearch.bat) I get this error: \[2022-11-15T01:08:55,761\]\[ERROR\]\[o.e.i.g.GeoIpDownloader \] \[WUWVC0ASX02\] exception…

---

## [Separate yum repos for each architecture](https://discuss.elastic.co/t/separate-yum-repos-for-each-architecture/319220)

<div class="topic-metadata">

**Author:** [@sokratis](https://discuss.elastic.co/u/sokratis)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 4:19pm UTC](https://discuss.elastic.co/t/separate-yum-repos-for-each-architecture/319220 "2022-11-17T16:19:06Z")

</div>

Hello, I noticed that all rpms come under the same yum repo (as documented): \[logstash-8.x\] name=Elastic repository for 8.x packages baseurl=https://artifacts.elastic.co/packages/8.x/yum gpgcheck=1 gpgkey=https://artif…

---

## [Data dog+Kibana plugin](https://discuss.elastic.co/t/data-dog-kibana-plugin/317274)

<div class="topic-metadata">

**Author:** [@Racheli\_Vagenfeld](https://discuss.elastic.co/u/Racheli_Vagenfeld)\
**Replies:** 1\
**Last updated:** [October 23, 2022, 2:34pm UTC](https://discuss.elastic.co/t/data-dog-kibana-plugin/317274 "2022-10-23T14:34:53Z")

</div>

Hi, I want to use this: Datadog output plugin | Logstash Reference \[8.4\] | Elastic\](Datadog output plugin | Logstash Reference \[8.4\] | Elastic Is there anyway to make the integration based on specific filter of kibana …

---

## [Parse a json file that includes an xml](https://discuss.elastic.co/t/parse-a-json-file-that-includes-an-xml/317312)

<div class="topic-metadata">

**Author:** [@Alexandros](https://discuss.elastic.co/u/Alexandros)\
**Replies:** 7\
**Last updated:** [November 18, 2022, 8:40am UTC](https://discuss.elastic.co/t/parse-a-json-file-that-includes-an-xml/317312 "2022-11-18T08:40:06Z")

</div>

Hello all, I want to send the following json document to elasticsearch through logstash. "short\_message": "\<?xml version="1.0" encoding="utf-8"?\> \<ImportMessageBase xmlns:xsi="http://www.w3.org/2001/XMLSchem…

---

## [【Windows】pipe\\\\elastic-agent-system: Access is denied](https://discuss.elastic.co/t/windows-pipe-elastic-agent-system-access-is-denied/316344)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 4\
**Last updated:** [November 18, 2022, 8:09am UTC](https://discuss.elastic.co/t/windows-pipe-elastic-agent-system-access-is-denied/316344 "2022-11-18T08:09:59Z")

</div>

I am installing Elastic Agent 8.4.1 on a Win10 system using the command line and I get the following error and the server fleet keeps showing updates, how do I fix it? The error is displayed： Error: failed to communica…

---

## [Https://discuss.elastic.co/t/logstash-not-working-with-jdk-11-0-16/315105/5](https://discuss.elastic.co/t/https-discuss-elastic-co-t-logstash-not-working-with-jdk-11-0-16-315105-5/317480)

<div class="topic-metadata">

**Author:** [@shivani\_aggarwal](https://discuss.elastic.co/u/shivani_aggarwal)\
**Replies:** 4\
**Last updated:** [November 18, 2022, 6:27am UTC](https://discuss.elastic.co/t/https-discuss-elastic-co-t-logstash-not-working-with-jdk-11-0-16-315105-5/317480 "2022-11-18T06:27:11Z")

</div>

Hi, This is in continuation of my prev query that got auto-closed. Summary: Logstash 7.17.3 is not working with jdk \>= 11.0.16 As per @stephenb 's response, I've checked LS\_JAVA\_HOME is properly set. I see that th…

---

## [Getting empty response from server](https://discuss.elastic.co/t/getting-empty-response-from-server/319175)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 9\
**Last updated:** [November 18, 2022, 4:42am UTC](https://discuss.elastic.co/t/getting-empty-response-from-server/319175 "2022-11-18T04:42:00Z")

</div>

Hi I've installed elk stack of version 8.5.1. All services are active. But when i try to access curl http://localhost:9200 or publicip:9200 getting empty response error path.data: /var/lib/elasticsearch path.logs: /var…

---

## [Date parsing issue](https://discuss.elastic.co/t/date-parsing-issue/319246)

<div class="topic-metadata">

**Author:** [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Replies:** 5\
**Last updated:** [November 18, 2022, 4:27am UTC](https://discuss.elastic.co/t/date-parsing-issue/319246 "2022-11-18T04:27:36Z")

</div>

I m having strange issue with Date parsing. Here is my config. input { stdin { } } output { stdout { codec =\> rubydebug } } filter { date { match =\> \["message", "ISO8601"\] } } when i run echo '2022-11-17 15:…

---

## [Error while creating index pattern](https://discuss.elastic.co/t/error-while-creating-index-pattern/317593)

<div class="topic-metadata">

**Author:** [@Kartik101](https://discuss.elastic.co/u/Kartik101)\
**Replies:** 2\
**Last updated:** [November 18, 2022, 4:12am UTC](https://discuss.elastic.co/t/error-while-creating-index-pattern/317593 "2022-11-18T04:12:37Z")

</div>

I am using ES 7.10.2 and Kibana7.10.2, and getting below error in "nohup.out" file (running kibana in background) while creating index pattern: {"type":"error","@timestamp":"2022-08-23T13:53:37Z","tags":\["connection","c…

---

## [Change logstash index creation format](https://discuss.elastic.co/t/change-logstash-index-creation-format/319254)

<div class="topic-metadata">

**Author:** [@koreagrammer](https://discuss.elastic.co/u/koreagrammer)\
**Replies:** 0\
**Last updated:** [November 18, 2022, 2:56am UTC](https://discuss.elastic.co/t/change-logstash-index-creation-format/319254 "2022-11-18T02:56:14Z")

</div>

How do I set the logstash output index name to the client IP where metricbeat is installed? I just want logstash output index format to have below Metricbeat-{metricbeat.client.ip}-metricbeat.version-{YYYY.MM.DD}

---

## [Waiting for input plugin, Dropping events to unblock input plugin, Pipeline terminated](https://discuss.elastic.co/t/waiting-for-input-plugin-dropping-events-to-unblock-input-plugin-pipeline-terminated/319081)

<div class="topic-metadata">

**Author:** [@AdxDaz](https://discuss.elastic.co/u/AdxDaz)\
**Replies:** 3\
**Last updated:** [November 17, 2022, 11:19pm UTC](https://discuss.elastic.co/t/waiting-for-input-plugin-dropping-events-to-unblock-input-plugin-pipeline-terminated/319081 "2022-11-17T23:19:38Z")

</div>

Hi Elastic team, I was working in the next post "Locate json field with jsonpath (logstash) - #2 by Badger" and despite the code works, i have the next error when the position of the json value change: \[2022-11-15T09:3…

---

## [Has anybody run ES cluster on AWS using either is4gen or im4gn? vs say i4i?](https://discuss.elastic.co/t/has-anybody-run-es-cluster-on-aws-using-either-is4gen-or-im4gn-vs-say-i4i/319249)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 11:06pm UTC](https://discuss.elastic.co/t/has-anybody-run-es-cluster-on-aws-using-either-is4gen-or-im4gn-vs-say-i4i/319249 "2022-11-17T23:06:55Z")

</div>

I'm curious if there's any performance difference. Since these are all storage optimized instance. I'm mainly curious about ARM vs Intel performance delta. We are mostly write heavy. Something like 80+% write vs read…

---

## [Two file output in Logstash](https://discuss.elastic.co/t/two-file-output-in-logstash/319056)

<div class="topic-metadata">

**Author:** [@Vrops](https://discuss.elastic.co/u/Vrops)\
**Replies:** 4\
**Last updated:** [November 17, 2022, 10:07pm UTC](https://discuss.elastic.co/t/two-file-output-in-logstash/319056 "2022-11-17T22:07:51Z")

</div>

Hello, I have explored several forums but can't find any answers to my question. I'm trying to get 2 Filebeat inputs and redirect them via Logstash with 2 different file outputs. Here are my configuration files: file…

---

## [Reporting SQL relational data (Oracle) in Kibana](https://discuss.elastic.co/t/reporting-sql-relational-data-oracle-in-kibana/319178)

<div class="topic-metadata">

**Author:** [@Gianluca\_De\_Pasquale](https://discuss.elastic.co/u/Gianluca_De_Pasquale)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 11:14am UTC](https://discuss.elastic.co/t/reporting-sql-relational-data-oracle-in-kibana/319178 "2022-11-17T11:14:27Z")

</div>

Hi all, just a theoric question about Kibana reporting capabilities. We have a Oracle database where there are at least 10 tables we want to report data of. We started using Microsoft Power Bi and the results were ver…

---

## [Impossible query response?](https://discuss.elastic.co/t/impossible-query-response/319236)

<div class="topic-metadata">

**Author:** [@iamthealex1](https://discuss.elastic.co/u/iamthealex1)\
**Replies:** 3\
**Last updated:** [November 17, 2022, 7:50pm UTC](https://discuss.elastic.co/t/impossible-query-response/319236 "2022-11-17T19:50:35Z")

</div>

POST /metricbeat-2022.11.17/\_search { "size": 2, "\_source": \["system.process.cpu.total.pct"\], "query": { "bool": { "must": \[ {"match": { "event.dataset": "system.process" }}, {"range": {…

---

## [Adding more log directories to System Integration](https://discuss.elastic.co/t/adding-more-log-directories-to-system-integration/319237)

<div class="topic-metadata">

**Author:** [@ster1ingArch3r](https://discuss.elastic.co/u/ster1ingArch3r)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 7:17pm UTC](https://discuss.elastic.co/t/adding-more-log-directories-to-system-integration/319237 "2022-11-17T19:17:28Z")

</div>

Heres what I have going on. I have created the elastic stack 3 nodes +a kibana Node which also is serving as my fleet server. I can deploy agents to new servers and endpoints and collect data from them. Unfortunately one…

---

## [Create some tasks that may never finish](https://discuss.elastic.co/t/create-some-tasks-that-may-never-finish/318990)

<div class="topic-metadata">

**Author:** [@Sunt-ing](https://discuss.elastic.co/u/Sunt-ing)\
**Replies:** 6\
**Last updated:** [November 17, 2022, 6:50pm UTC](https://discuss.elastic.co/t/create-some-tasks-that-may-never-finish/318990 "2022-11-17T18:50:34Z")

</div>

In order to create a testbed for anomaly detection, I need to create some tasks that may never finish (unless you manually kill them) in ES. Is there any way to do that? I do find some problems with storage hardware may …

---

## [Elastic Analyst lab license](https://discuss.elastic.co/t/elastic-analyst-lab-license/319104)

<div class="topic-metadata">

**Author:** [@Michael\_Scott](https://discuss.elastic.co/u/Michael_Scott)\
**Replies:** 4\
**Last updated:** [November 17, 2022, 6:46pm UTC](https://discuss.elastic.co/t/elastic-analyst-lab-license/319104 "2022-11-17T18:46:43Z")

</div>

Hey All, I'm a little confused as my strigo labs only have a basic license meaning that there are several features of the course I cannot carry out. Any advice on how to deal with this? I have the standard subscription…

---

## [Removing xpack.maps.enabled as advised breaks Kibana](https://discuss.elastic.co/t/removing-xpack-maps-enabled-as-advised-breaks-kibana/319222)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 2\
**Last updated:** [November 17, 2022, 5:18pm UTC](https://discuss.elastic.co/t/removing-xpack-maps-enabled-as-advised-breaks-kibana/319222 "2022-11-17T17:18:12Z")

</div>

Kibana 7.17 The Kibana Upgrade Assistant is showing me a Critical issue: Setting "xpack.maps.enabled" is deprecated Configuring "xpack.maps.enabled" is deprecated and will be removed in 8.0.0. How to fix Remove "xp…

---

## [Custom Logs integration, drop\_fields processor doesn't work](https://discuss.elastic.co/t/custom-logs-integration-drop-fields-processor-doesnt-work/319228)

<div class="topic-metadata">

**Author:** [@luca.derugeriis](https://discuss.elastic.co/u/luca.derugeriis)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 5:16pm UTC](https://discuss.elastic.co/t/custom-logs-integration-drop-fields-processor-doesnt-work/319228 "2022-11-17T17:16:04Z")

</div>

Hi everyone, I'm trying get a drop\_fields processor working inside Custom Logs integration in Elastic Agent. This is my configuration in the "processors" text area in the integration page on kibana. - drop\_fields: …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=494)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=496)
