# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=498

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 499

---

## [Filebeat not shipping logs to logstash](https://discuss.elastic.co/t/filebeat-not-shipping-logs-to-logstash/318951)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 4\
**Last updated:** [November 16, 2022, 6:05am UTC](https://discuss.elastic.co/t/filebeat-not-shipping-logs-to-logstash/318951 "2022-11-16T06:05:32Z")

</div>

Hi I am setting up ELK stack for POC. I have installed ELK 7.17 version. Installed all the packages separately like different machine. Now i have installed file beat and enabled logstash module but i don't see any logs…

---

## [Restrict data access in Kibana dashboards](https://discuss.elastic.co/t/restrict-data-access-in-kibana-dashboards/318774)

<div class="topic-metadata">

**Author:** [@Venkatesh\_Guruprasad](https://discuss.elastic.co/u/Venkatesh_Guruprasad)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 3:13am UTC](https://discuss.elastic.co/t/restrict-data-access-in-kibana-dashboards/318774 "2022-11-16T03:13:05Z")

</div>

We are using Kibana dashboards as an embedded URL experience. Based on the user we want to display only relevant records and filters to the users. As an example, we have one index which stores records for all customers.…

---

## [Row calculation in Enhanced Table](https://discuss.elastic.co/t/row-calculation-in-enhanced-table/316971)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 3:38pm UTC](https://discuss.elastic.co/t/row-calculation-in-enhanced-table/316971 "2022-10-19T15:38:45Z")

</div>

Hi, I am trying to calculate row in the enhanced table where I am computing row1/ Grand total i.e. 30/187 =16.04%, refer to the pic attached with post. I have tried this in enhanced table but couldn't find any such feat…

---

## [How to parse glastopf honeypot log json using logstash for kibana visualization?](https://discuss.elastic.co/t/how-to-parse-glastopf-honeypot-log-json-using-logstash-for-kibana-visualization/319010)

<div class="topic-metadata">

**Author:** [@Febrian12345](https://discuss.elastic.co/u/Febrian12345)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 12:45am UTC](https://discuss.elastic.co/t/how-to-parse-glastopf-honeypot-log-json-using-logstash-for-kibana-visualization/319010 "2022-11-16T00:45:12Z")

</div>

I have a raw data in json format that I want to visualize in Kibana, but I'm having trouble parsing the data in logstash, previously I was able to visualize raw data for honeypot dionaea and cowrie. please help me in doi…

---

## [Logstash stopped processing because of an error](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error/319009)

<div class="topic-metadata">

**Author:** [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Replies:** 1\
**Last updated:** [November 16, 2022, 12:05am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error/319009 "2022-11-16T00:05:16Z")

</div>

First time installing logstash and need some help please and thanks! \[2022-11-15T18:45:54,229\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.version"=\>"8.5.0", "jruby.version"=\>"jruby 9.3.8.0 (2.6.8) 20…

---

## [Locate json field with jsonpath (logstash)](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812)

<div class="topic-metadata">

**Author:** [@AdxDaz](https://discuss.elastic.co/u/AdxDaz)\
**Replies:** 4\
**Last updated:** [November 15, 2022, 11:31pm UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812 "2022-11-15T23:31:32Z")

</div>

Hi Elastic team, I have the next Json: {"response-code":"4000","response":{"result":\[{"DetailsPageURL":"/show.do?resourceid=22&method=show&PRINTER\_FRIENDLY=true","TODAYUNAVAILPERCENT":"0","Attribute":\[{"DISPLAYNAME":"T…

---

## [Sharing Kibana Visualization Search as Iframe and running into Issues on Google Chrome](https://discuss.elastic.co/t/sharing-kibana-visualization-search-as-iframe-and-running-into-issues-on-google-chrome/317016)

<div class="topic-metadata">

**Author:** [@hidanny](https://discuss.elastic.co/u/hidanny)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 3:10pm UTC](https://discuss.elastic.co/t/sharing-kibana-visualization-search-as-iframe-and-running-into-issues-on-google-chrome/317016 "2022-10-19T15:10:00Z")

</div>

Hi All, Just to note, the IFrame is rendering completely fine on Firefox. I am only encountering this on Google Chrome. Basically, I am trying to embed a Kibana IFrame on a React website. However, I am getting messag…

---

## [Logstash startup error](https://discuss.elastic.co/t/logstash-startup-error/318511)

<div class="topic-metadata">

**Author:** [@harijld](https://discuss.elastic.co/u/harijld)\
**Replies:** 7\
**Last updated:** [November 15, 2022, 9:02pm UTC](https://discuss.elastic.co/t/logstash-startup-error/318511 "2022-11-15T21:02:56Z")

</div>

HI All, I am trying to bring up Logstash on production server, getting below. Same set up working fine in UAT. Error Message 2022-11-08T15:30:28,121\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.vers…

---

## [How Periodic\_flush common setting helpful in ruby logstash filter?](https://discuss.elastic.co/t/how-periodic-flush-common-setting-helpful-in-ruby-logstash-filter/318980)

<div class="topic-metadata">

**Author:** [@priti](https://discuss.elastic.co/u/priti)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 6:45pm UTC](https://discuss.elastic.co/t/how-periodic-flush-common-setting-helpful-in-ruby-logstash-filter/318980 "2022-11-15T18:45:37Z")

</div>

I added periodic\_flush =\> true in ruby filter but I didn't found any difference. ruby { path =\> \<ruby file path\> periodic\_flush =\> true }

---

## [Date\_time\_exception: Field Year cannot be printed as the value -292275055 exceeds the maximum print width of 4\]](https://discuss.elastic.co/t/date-time-exception-field-year-cannot-be-printed-as-the-value-292275055-exceeds-the-maximum-print-width-of-4/318900)

<div class="topic-metadata">

**Author:** [@hchen1](https://discuss.elastic.co/u/hchen1)\
**Replies:** 2\
**Last updated:** [November 15, 2022, 6:15pm UTC](https://discuss.elastic.co/t/date-time-exception-field-year-cannot-be-printed-as-the-value-292275055-exceeds-the-maximum-print-width-of-4/318900 "2022-11-15T18:15:28Z")

</div>

I got date\_time\_exception after disabling dynamic mapping and adding mapping for a Date attribute like this: "mappings": { "dynamic": false, ........ "updateDate": { "type": "date", …

---

## [Send parts of a message to different Elasticsearch indices from a single Logstash instance](https://discuss.elastic.co/t/send-parts-of-a-message-to-different-elasticsearch-indices-from-a-single-logstash-instance/318950)

<div class="topic-metadata">

**Author:** [@powerful\_clouds](https://discuss.elastic.co/u/powerful_clouds)\
**Replies:** 4\
**Last updated:** [November 15, 2022, 4:14pm UTC](https://discuss.elastic.co/t/send-parts-of-a-message-to-different-elasticsearch-indices-from-a-single-logstash-instance/318950 "2022-11-15T16:14:06Z")

</div>

Suppose my message has fields A and B. I want to separately send each of the fields to the same ES instance, but to different indices. Is that possible? E.g. if this is the message: {"A": some text, "B": some more text},…

---

## [DLQ settings to handle bulk ingest encoding error](https://discuss.elastic.co/t/dlq-settings-to-handle-bulk-ingest-encoding-error/318802)

<div class="topic-metadata">

**Author:** [@tharris1](https://discuss.elastic.co/u/tharris1)\
**Replies:** 3\
**Last updated:** [November 15, 2022, 3:43pm UTC](https://discuss.elastic.co/t/dlq-settings-to-handle-bulk-ingest-encoding-error/318802 "2022-11-15T15:43:54Z")

</div>

I have a large set of archived data to ingest into Elastic and some of the log entries have encoding issues that building up and causing the logstash ingest pipeline to stall. I have DLQ enabled but still getting indefin…

---

## [Add file path as a field](https://discuss.elastic.co/t/add-file-path-as-a-field/318966)

<div class="topic-metadata">

**Author:** [@Matan\_Malka](https://discuss.elastic.co/u/Matan_Malka)\
**Replies:** 5\
**Last updated:** [November 15, 2022, 3:40pm UTC](https://discuss.elastic.co/t/add-file-path-as-a-field/318966 "2022-11-15T15:40:53Z")

</div>

Hey guys, Is it possible to add a field for the file path? input{ file{ path =\> \[ "/bitnami/jenkins/jenkins\_home/jobs/create-machine/builds/\*\*/log", "/bitnami/jenkins/jenkins\_home/jobs/delete-machine/builds/\*\*/log"…

---

## [Logstash Pipeline with elasticsearch output missing in Stack Monitoring](https://discuss.elastic.co/t/logstash-pipeline-with-elasticsearch-output-missing-in-stack-monitoring/318439)

<div class="topic-metadata">

**Author:** [@peet](https://discuss.elastic.co/u/peet)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 12:23pm UTC](https://discuss.elastic.co/t/logstash-pipeline-with-elasticsearch-output-missing-in-stack-monitoring/318439 "2022-11-15T12:23:54Z")

</div>

Hi! We are currently setting up monitoring for our Logstash instances. Metricbeat on the Logstash is configured as described in the instructions: - module: logstash metricsets: - node - node\_stats xpack.en…

---

## [Logstash document\_id for 3 joined tables](https://discuss.elastic.co/t/logstash-document-id-for-3-joined-tables/318896)

<div class="topic-metadata">

**Author:** [@Swati\_Kanade](https://discuss.elastic.co/u/Swati_Kanade)\
**Replies:** 2\
**Last updated:** [November 15, 2022, 11:58am UTC](https://discuss.elastic.co/t/logstash-document-id-for-3-joined-tables/318896 "2022-11-15T11:58:15Z")

</div>

Hi, I am new to ELK stack search. I have created an index by joining 3 tables - message, message\_recipient and message\_attachments - using inner join on message and message\_recipient and left outer join on message\_attach…

---

## [Get most recent hit by some field on Discover](https://discuss.elastic.co/t/get-most-recent-hit-by-some-field-on-discover/318824)

<div class="topic-metadata">

**Author:** [@liorh](https://discuss.elastic.co/u/liorh)\
**Replies:** 2\
**Last updated:** [November 15, 2022, 10:30am UTC](https://discuss.elastic.co/t/get-most-recent-hit-by-some-field-on-discover/318824 "2022-11-15T10:30:23Z")

</div>

Hi Attached is a screenshot of my Discover. How can I make it to show me only the most recent row per event.transactionId? I marked those rows. Thank you very much

---

## [Clean up Indices? ..... free some storage](https://discuss.elastic.co/t/clean-up-indices-free-some-storage/318925)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 4\
**Last updated:** [November 15, 2022, 8:06am UTC](https://discuss.elastic.co/t/clean-up-indices-free-some-storage/318925 "2022-11-15T08:06:14Z")

</div>

storage utilised over 90% and until now I haven't cleaned up any indices. What would be the perfect way to clean up indices or delete some old index data ? I've searched a lot but there's too much confusion over the in…

---

## [Want to know stable latest elastic version](https://discuss.elastic.co/t/want-to-know-stable-latest-elastic-version/318939)

<div class="topic-metadata">

**Author:** [@priti](https://discuss.elastic.co/u/priti)\
**Replies:** 2\
**Last updated:** [November 15, 2022, 9:24am UTC](https://discuss.elastic.co/t/want-to-know-stable-latest-elastic-version/318939 "2022-11-15T09:24:18Z")

</div>

We are planning to build ELK cluster in our environment. Need to know which is the latest stable version is good to setup ?

---

## [Creating an enrich policy from collapsed data](https://discuss.elastic.co/t/creating-an-enrich-policy-from-collapsed-data/318629)

<div class="topic-metadata">

**Author:** [@cwe](https://discuss.elastic.co/u/cwe)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 8:23am UTC](https://discuss.elastic.co/t/creating-an-enrich-policy-from-collapsed-data/318629 "2022-11-15T08:23:34Z")

</div>

Hi Elastic community I have an index containing many documents per host.id describing the currently running software. This information might change over time, due to software updates. I can use a collapse query to get …

---

## [How to query with GROUP BY and COUNT(\*)](https://discuss.elastic.co/t/how-to-query-with-group-by-and-count/318936)

<div class="topic-metadata">

**Author:** [@Remon\_Andrew](https://discuss.elastic.co/u/Remon_Andrew)\
**Replies:** 0\
**Last updated:** [November 15, 2022, 8:20am UTC](https://discuss.elastic.co/t/how-to-query-with-group-by-and-count/318936 "2022-11-15T08:20:29Z")

</div>

Hi all, I have this query that I used to run on MySQL: SELECT from\_mobile\_number, event\_name, COUNT(\*) AS count FROM analytics\_events WHERE date \>= '2022-10-01 00:00:00' AND date \<= '2022-09-30 23:59:59' AND from\_mobil…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/318924)

<div class="topic-metadata">

**Author:** [@giri1](https://discuss.elastic.co/u/giri1)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 7:10am UTC](https://discuss.elastic.co/t/elasticsearch/318924 "2022-11-15T07:10:12Z")

</div>

hey search\_as\_type is not working when i connect it through java. Completion is showing error when i used it with bool query

---

## [Index Pattern error in Kibana 7.10.2](https://discuss.elastic.co/t/index-pattern-error-in-kibana-7-10-2/316888)

<div class="topic-metadata">

**Author:** [@abhi474](https://discuss.elastic.co/u/abhi474)\
**Replies:** 2\
**Last updated:** [October 19, 2022, 4:39am UTC](https://discuss.elastic.co/t/index-pattern-error-in-kibana-7-10-2/316888 "2022-10-19T04:39:59Z")

</div>

while creating Index pattern for sample data, I am getting below error : {"type":"error","@timestamp":"2022-10-18T04:31:00Z","tags":\["connection","client","error"\],"pid":63727,"level":"error","error":{"message":"Parse E…

---

## [Generating metrics from documents present in index](https://discuss.elastic.co/t/generating-metrics-from-documents-present-in-index/318130)

<div class="topic-metadata">

**Author:** [@Vikash\_Kumar\_Sharma](https://discuss.elastic.co/u/Vikash_Kumar_Sharma)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 6:14am UTC](https://discuss.elastic.co/t/generating-metrics-from-documents-present-in-index/318130 "2022-11-15T06:14:32Z")

</div>

Hi I have an index that has the following documents timestamp:t1, job:j1, status:started timestamp:t2, job:j1, status:completed timestamp:t1, job:j2, status:started timestamp:t2, job:j2, status:completed So from these…

---

## [Kibana error: Unable to retrieve version information from Elasticsearch nodes. socket hang up](https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421)

<div class="topic-metadata">

**Author:** [@grigoryevandrey](https://discuss.elastic.co/u/grigoryevandrey)\
**Replies:** 3\
**Last updated:** [November 15, 2022, 6:07am UTC](https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421 "2022-11-15T06:07:31Z")

</div>

I am getting this error inside the kibana container, therefore ingress returns 503 error and container is never ready. When i am doing curl to elasticsearch from inside the kibana container, it successfully returns a re…

---

## [Reindex api errors out while reindexing when documents in the index exceed 2147483519](https://discuss.elastic.co/t/reindex-api-errors-out-while-reindexing-when-documents-in-the-index-exceed-2147483519/318771)

<div class="topic-metadata">

**Author:** [@Srikant\_Magdum](https://discuss.elastic.co/u/Srikant_Magdum)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 6:06am UTC](https://discuss.elastic.co/t/reindex-api-errors-out-while-reindexing-when-documents-in-the-index-exceed-2147483519/318771 "2022-11-15T06:06:57Z")

</div>

One of my shard in the index is in red state as the documents in that shard exceeded 2147483519 as below : failed shard on node \[GK1he55KSJmqQXx-qDrPFQ\]: shard failure, reason \[no-op origin\[PRIMARY\] seq#\[350554097\] fail…

---

## [Unable to retrieve version information from Elasticsearch nodes. security\_exception](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/318919)

<div class="topic-metadata">

**Author:** [@Vivek\_Arumugam](https://discuss.elastic.co/u/Vivek_Arumugam)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 6:01am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/318919 "2022-11-15T06:01:43Z")

</div>

Hi Team, I am getting the following error while installing kibana.please help on this issue. Unable to retrieve version information from Elasticsearch nodes. security\_exception: \[security\_exception\] Reason: missing aut…

---

## [Unable to start elastic search in AKS cluster, throwing bootstrap errors](https://discuss.elastic.co/t/unable-to-start-elastic-search-in-aks-cluster-throwing-bootstrap-errors/318921)

<div class="topic-metadata">

**Author:** [@sunil\_s](https://discuss.elastic.co/u/sunil_s)\
**Replies:** 0\
**Last updated:** [November 15, 2022, 5:14am UTC](https://discuss.elastic.co/t/unable-to-start-elastic-search-in-aks-cluster-throwing-bootstrap-errors/318921 "2022-11-15T05:14:51Z")

</div>

PFB errors {"@timestamp":"2022-11-15T05:06:07.108Z", "log.level": "INFO", "message":"Native controller process has stopped - no new native processes can be started", "ecs.version": "1.2.0","service.name":"ES\_ECS","event…

---

## [Kibana error in /app/security/manage](https://discuss.elastic.co/t/kibana-error-in-app-security-manage/317076)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 1:08am UTC](https://discuss.elastic.co/t/kibana-error-in-app-security-manage/317076 "2022-11-15T01:08:33Z")

</div>

Error Error: Cannot read properties of undefined (reading 'includes') at i (http://172.16.14.193:5601/55572/bundles/plugin/securitySolution/8.0.0/securitySolution.chunk.0.js:3:15967) at http://172.16.14.193:5601…

---

## [Kibana process crashes - high memory usage](https://discuss.elastic.co/t/kibana-process-crashes-high-memory-usage/317132)

<div class="topic-metadata">

**Author:** [@dslavescu](https://discuss.elastic.co/u/dslavescu)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 1:05am UTC](https://discuss.elastic.co/t/kibana-process-crashes-high-memory-usage/317132 "2022-11-15T01:05:01Z")

</div>

Hello, I am using ELK 7.12.1 and Kibana 7.12.1 in a production env. I am encountering an issue with my Kibana , the process keeps crashing. The app is hosted on 1 VM , having 8 GB of RAM. At first i did not do any modi…

---

## [Help with creating a search](https://discuss.elastic.co/t/help-with-creating-a-search/318450)

<div class="topic-metadata">

**Author:** [@cdeblois](https://discuss.elastic.co/u/cdeblois)\
**Replies:** 2\
**Last updated:** [November 10, 2022, 6:59pm UTC](https://discuss.elastic.co/t/help-with-creating-a-search/318450 "2022-11-10T18:59:16Z")

</div>

Hello, I'm trying to see if there's a way to make an API call so we can know when an index or an indices has not been written to for a specific period of time. Is there a way to do this? I've been wracking my brain try…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=497)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=499)
