# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=613

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 614

---

## [Filebeat not reading logs from subdirectories](https://discuss.elastic.co/t/filebeat-not-reading-logs-from-subdirectories/306905)

<div class="topic-metadata">

**Author:** [@garry12](https://discuss.elastic.co/u/garry12)\
**Replies:** 3\
**Last updated:** [June 10, 2022, 6:42pm UTC](https://discuss.elastic.co/t/filebeat-not-reading-logs-from-subdirectories/306905 "2022-06-10T18:42:03Z")

</div>

Hey team, I am relatively new to ELK stack and I am trying to send logs from a linux servers to Elasticsearch. The path I am choosing is - I have installed the filebeat on linux server where my application logs are gett…

---

## [Case insensitive wildcard search in 7.17.0](https://discuss.elastic.co/t/case-insensitive-wildcard-search-in-7-17-0/306903)

<div class="topic-metadata">

**Author:** [@mej101](https://discuss.elastic.co/u/mej101)\
**Replies:** 2\
**Last updated:** [June 10, 2022, 6:33pm UTC](https://discuss.elastic.co/t/case-insensitive-wildcard-search-in-7-17-0/306903 "2022-06-10T18:33:27Z")

</div>

I'm running Elasticsearch 7.17.0, and when I try to run the following query: GET index\_name/\_search { "query": { "wildcard": { "fieldName.subfield": "\*view", "case\_insensitive": true } } } I get…

---

## [ILM policy: Document count reduced but Index count unchanged](https://discuss.elastic.co/t/ilm-policy-document-count-reduced-but-index-count-unchanged/306899)

<div class="topic-metadata">

**Author:** [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 3:15pm UTC](https://discuss.elastic.co/t/ilm-policy-document-count-reduced-but-index-count-unchanged/306899 "2022-06-10T15:15:12Z")

</div>

A timeline of events: At some point, I inadvertently changed max index size changed from 50GB to 1GB. After some time, I began getting circuit-breaker errors about maxing out the Java heap (31GB on each of the 4 nodes)…

---

## [How to get the time a query spends in the queue before the shards receives the query](https://discuss.elastic.co/t/how-to-get-the-time-a-query-spends-in-the-queue-before-the-shards-receives-the-query/306897)

<div class="topic-metadata">

**Author:** [@shivam\_agrawal1](https://discuss.elastic.co/u/shivam_agrawal1)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 1:58pm UTC](https://discuss.elastic.co/t/how-to-get-the-time-a-query-spends-in-the-queue-before-the-shards-receives-the-query/306897 "2022-06-10T13:58:34Z")

</div>

The took\_millis in Elasticsearch slow logs tells the time it takes on execution on the shard level, it does not encounter the time it spends in the queue. How to get the time. a query spends in the queue before it is pas…

---

## [Java::JavaLang::IllegalStateException\` for \`PipelineAction::Create\<main\>\`"](https://discuss.elastic.co/t/java-illegalstateexception-for-pipelineaction-create-main/306871)

<div class="topic-metadata">

**Author:** [@akjain3](https://discuss.elastic.co/u/akjain3)\
**Replies:** 1\
**Last updated:** [June 10, 2022, 12:44pm UTC](https://discuss.elastic.co/t/java-illegalstateexception-for-pipelineaction-create-main/306871 "2022-06-10T12:44:29Z")

</div>

Hi, I am new to logstash and using logstash to add my logs with Elasticsearch. But I can't get through this error. Please help. It is urgent. Using bundled JDK: /Users/akjain3cisco.com/Documents/ELK/logstash-7.15.2/jdk.…

---

## [Issue while running the logstash](https://discuss.elastic.co/t/issue-while-running-the-logstash/306884)

<div class="topic-metadata">

**Author:** [@Akanksha2022](https://discuss.elastic.co/u/Akanksha2022)\
**Replies:** 1\
**Last updated:** [June 10, 2022, 12:16pm UTC](https://discuss.elastic.co/t/issue-while-running-the-logstash/306884 "2022-06-10T12:16:09Z")

</div>

runner - The given configuration is invalid. Reason: Failed to parse right-hand side of conditional \[file\]/etc/logstash/conf.d/logstash-grok.conf:70:45:\`\`\`

---

## [\[2018-05-27T08:46:23,536\]\[ERROR\]\[logstash.outputs.elasticsearch\] Encountered a retryable error. Will Retry with exponential backoff {:code=\>413, :url=\>"http://elasticsearch\_address:9200/\_bulk"}](https://discuss.elastic.co/t/2018-05-27t0823-536-error-logstash-outputs-elasticsearch-encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413-url-http-elasticsearch-address-9200-bulk/306876)

<div class="topic-metadata">

**Author:** [@Manohar22](https://discuss.elastic.co/u/Manohar22)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 11:37am UTC](https://discuss.elastic.co/t/2018-05-27t0823-536-error-logstash-outputs-elasticsearch-encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413-url-http-elasticsearch-address-9200-bulk/306876 "2022-06-10T11:37:44Z")

</div>

Continuing the discussion from Logstash stuck on "Will Retry with exponential backoff": we are seeing below error in logstash logs \[2022-06-10T04:59:38,367\]\[ERROR\]\[logstash.filters.ruby \] Ruby exception occurred: \[…

---

## [\[WARN \]\[o.e.x.s.t.n.SecurityNetty4HttpServerTransport\] \[crud\_node\] http client did not trust this server's certificate, closing connection Netty4HttpChannel{localAddress=/127.0.0.1:9200](https://discuss.elastic.co/t/warn-o-e-x-s-t-n-securitynetty4httpservertransport-crud-node-http-client-did-not-trust-this-servers-certificate-closing-connection-netty4httpchannel-localaddress-127-0-0-1-9200/306859)

<div class="topic-metadata">

**Author:** [@Axel\_Ekenberg](https://discuss.elastic.co/u/Axel_Ekenberg)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 9:05am UTC](https://discuss.elastic.co/t/warn-o-e-x-s-t-n-securitynetty4httpservertransport-crud-node-http-client-did-not-trust-this-servers-certificate-closing-connection-netty4httpchannel-localaddress-127-0-0-1-9200/306859 "2022-06-10T09:05:14Z")

</div>

Hi! I just started with the ELK stack and i have downloaded kibana, logstash, Elasticsearch, made a config file in my logstash folder and i start Elasticsearch and it works well and then when i run logstash with "logstas…

---

## [Installing Kibana from source](https://discuss.elastic.co/t/installing-kibana-from-source/306045)

<div class="topic-metadata">

**Author:** [@Amphagory](https://discuss.elastic.co/u/Amphagory)\
**Replies:** 6\
**Last updated:** [June 10, 2022, 10:51am UTC](https://discuss.elastic.co/t/installing-kibana-from-source/306045 "2022-06-10T10:51:50Z")

</div>

Hello, I have built Kibana 8.2.0 from source following these instructions. It has made a folder call build with 3 sub folders: default, Kibana, Kibana-docker. I couldn't find documentation on how to install my build o…

---

## [Need to remove first 10 characters using grok](https://discuss.elastic.co/t/need-to-remove-first-10-characters-using-grok/306864)

<div class="topic-metadata">

**Author:** [@Giuse\_Esse](https://discuss.elastic.co/u/Giuse_Esse)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 9:43am UTC](https://discuss.elastic.co/t/need-to-remove-first-10-characters-using-grok/306864 "2022-06-10T09:43:06Z")

</div>

Hello i need to remove first 10 char in the grok, I can get first 10 but not exclude... grok { match =\> { "message" =\> "(?\<message\>^.{-10})" …

---

## [GeoDistanceQuery Not Working](https://discuss.elastic.co/t/geodistancequery-not-working/306780)

<div class="topic-metadata">

**Author:** [@cugo](https://discuss.elastic.co/u/cugo)\
**Replies:** 1\
**Last updated:** [June 9, 2022, 2:23pm UTC](https://discuss.elastic.co/t/geodistancequery-not-working/306780 "2022-06-09T14:23:05Z")

</div>

I am trying to create a Geo Distance filter using Spring Data Elasticsearch like the one below which is a working example created by JSON. "filter":{ "geo\_distance":{ "distance":"32.42742km", …

---

## [Show search result based on keywords](https://discuss.elastic.co/t/show-search-result-based-on-keywords/305617)

<div class="topic-metadata">

**Author:** [@silvermanoj](https://discuss.elastic.co/u/silvermanoj)\
**Replies:** 7\
**Last updated:** [June 10, 2022, 8:48am UTC](https://discuss.elastic.co/t/show-search-result-based-on-keywords/305617 "2022-06-10T08:48:36Z")

</div>

I am using Elasticsearch version 8. When I try to query a combination of two words that are stored in two different attributes, I get the search result but the record match with post\_title are not coming first For examp…

---

## [BitSet.or took high cpu usage](https://discuss.elastic.co/t/bitset-or-took-high-cpu-usage/306786)

<div class="topic-metadata">

**Author:** [@chembohuang](https://discuss.elastic.co/u/chembohuang)\
**Replies:** 2\
**Last updated:** [June 10, 2022, 8:35am UTC](https://discuss.elastic.co/t/bitset-or-took-high-cpu-usage/306786 "2022-06-10T08:35:14Z")

</div>

Continuing the discussion from BitSet.or consumes almost 60% cpu: We found sth. new here. In fact , we ran into this problem twice after the topic was closed. And We found some similarities in these cases: this proble…

---

## [Getting an idea for resources required to locally deploy the ELK stack](https://discuss.elastic.co/t/getting-an-idea-for-resources-required-to-locally-deploy-the-elk-stack/306853)

<div class="topic-metadata">

**Author:** [@ahamza](https://discuss.elastic.co/u/ahamza)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 8:12am UTC](https://discuss.elastic.co/t/getting-an-idea-for-resources-required-to-locally-deploy-the-elk-stack/306853 "2022-06-10T08:12:56Z")

</div>

Hey, I've recently started reading up on the ELK stack and I want to understand what sort of hardware requirements I would have to do an on-premise deployment. I have about 9.5GB + 3.5GB (~13GB total) of log data comi…

---

## [\[SOLVED WITH SADES\] Kibana server is not ready yet. After a reboot it stopped working](https://discuss.elastic.co/t/solved-with-sades-kibana-server-is-not-ready-yet-after-a-reboot-it-stopped-working/306847)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 1\
**Last updated:** [June 10, 2022, 6:30am UTC](https://discuss.elastic.co/t/solved-with-sades-kibana-server-is-not-ready-yet-after-a-reboot-it-stopped-working/306847 "2022-06-10T06:30:37Z")

</div>

It is not the first time that I have faced this error, in an operational installation, that after a restart of either the server or a restart of the elasticcsearch + kibana service, has as a result this fatal message tha…

---

## [Bar chart ordering Kibana Lens](https://discuss.elastic.co/t/bar-chart-ordering-kibana-lens/306758)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 3\
**Last updated:** [June 10, 2022, 5:51am UTC](https://discuss.elastic.co/t/bar-chart-ordering-kibana-lens/306758 "2022-06-10T05:51:32Z")

</div>

Hi, I have a horizontal bar chart in Kibana lens which has $ value on the horizontal axis, top 3 products on the vertical axis and "group other values by other" turned off, and breakdown by manager names with top 3 man…

---

## [Legends on map](https://discuss.elastic.co/t/legends-on-map/306778)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 2\
**Last updated:** [June 10, 2022, 5:29am UTC](https://discuss.elastic.co/t/legends-on-map/306778 "2022-06-10T05:29:36Z")

</div>

Is there a way to adjust the number template on the legends on a Kibana map. For e.g. it is currently showing the full length for large numbers. what if we want to show the numbers trimmed as $1000k etc. instead of the …

---

## [How to filter an index by the maximum value of a field?](https://discuss.elastic.co/t/how-to-filter-an-index-by-the-maximum-value-of-a-field/306755)

<div class="topic-metadata">

**Author:** [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Replies:** 1\
**Last updated:** [June 10, 2022, 1:21am UTC](https://discuss.elastic.co/t/how-to-filter-an-index-by-the-maximum-value-of-a-field/306755 "2022-06-10T01:21:43Z")

</div>

There is a field in the index by the name of date but the data of that field is not in a proper date format its only a number. So I want a filter to include only the data of maximum data of date field I mean how to creat…

---

## [Custom jar deployment](https://discuss.elastic.co/t/custom-jar-deployment/306832)

<div class="topic-metadata">

**Author:** [@igladyshev](https://discuss.elastic.co/u/igladyshev)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 9:35pm UTC](https://discuss.elastic.co/t/custom-jar-deployment/306832 "2022-06-09T21:35:16Z")

</div>

Hello. I am trying to consume kafka topics and output them to s3. All works when we consume topics published in Avro, but we are struggling to make it working for JSON topics. I understood there is an option of using spe…

---

## [In Scripted Field 'Create Field' grayed out and 'Name' input box missing only for some index patterns](https://discuss.elastic.co/t/in-scripted-field-create-field-grayed-out-and-name-input-box-missing-only-for-some-index-patterns/306824)

<div class="topic-metadata">

**Author:** [@nofmxc](https://discuss.elastic.co/u/nofmxc)\
**Replies:** 5\
**Last updated:** [June 9, 2022, 7:52pm UTC](https://discuss.elastic.co/t/in-scripted-field-create-field-grayed-out-and-name-input-box-missing-only-for-some-index-patterns/306824 "2022-06-09T19:52:38Z")

</div>

I'm trying to create a scripted field for an index. For my 'dev-logs' index it works great, but for my 'logs' index, the UI won't let me save the scripted field since the button is greyed out. Also weirdly there is no op…

---

## [Log Path for ECK Agent Daemonset](https://discuss.elastic.co/t/log-path-for-eck-agent-daemonset/305825)

<div class="topic-metadata">

**Author:** [@rstasiunas1](https://discuss.elastic.co/u/rstasiunas1)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 7:45pm UTC](https://discuss.elastic.co/t/log-path-for-eck-agent-daemonset/305825 "2022-06-09T19:45:41Z")

</div>

I deployed the Kubernetes integration to an ECK daemonset deployment version 8.2.2 in Amazon EKS running on Bottlerocket hosts. I’m not getting any container or audit logs. When I exec into one of the agent pods, there i…

---

## [Modify values in json array with Ruby](https://discuss.elastic.co/t/modify-values-in-json-array-with-ruby/306756)

<div class="topic-metadata">

**Author:** [@Long\_Nguyen](https://discuss.elastic.co/u/Long_Nguyen)\
**Replies:** 4\
**Last updated:** [June 9, 2022, 6:42pm UTC](https://discuss.elastic.co/t/modify-values-in-json-array-with-ruby/306756 "2022-06-09T18:42:30Z")

</div>

Hello everyone, I have a json structure as follows: { "server":\[ { "active":true, "objID":1 }, { "active":true, "objID":2 }, { "active":false, …

---

## [Logstash runs out of memory as soon pipelines are triggered](https://discuss.elastic.co/t/logstash-runs-out-of-memory-as-soon-pipelines-are-triggered/306821)

<div class="topic-metadata">

**Author:** [@charvi23](https://discuss.elastic.co/u/charvi23)\
**Replies:** 1\
**Last updated:** [June 9, 2022, 5:19pm UTC](https://discuss.elastic.co/t/logstash-runs-out-of-memory-as-soon-pipelines-are-triggered/306821 "2022-06-09T17:19:13Z")

</div>

My logstash has started suddenly running out of memory, though no changes have been made to the pipeline. Following is the error log. My server has 14-15 GB of memory free. Tried allocating different memory in jvm.optio…

---

## [Logstash shutdown with no error](https://discuss.elastic.co/t/logstash-shutdown-with-no-error/306807)

<div class="topic-metadata">

**Author:** [@Hosein\_Kashefikaram](https://discuss.elastic.co/u/Hosein_Kashefikaram)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 4:43pm UTC](https://discuss.elastic.co/t/logstash-shutdown-with-no-error/306807 "2022-06-09T16:43:26Z")

</div>

I got following messages after starting Logstash Jun 09 10:48:10 local systemd\[1\]: Started logstash. Jun 09 10:48:10 local logstash\[3191\]: Using bundled JDK: /usr/share/logstash/jdk Jun 09 10:48:11 local logstash\[3191\]:…

---

## [\[Spring Data Elasticsearch\] Exception during save regardless of success](https://discuss.elastic.co/t/spring-data-elasticsearch-exception-during-save-regardless-of-success/306813)

<div class="topic-metadata">

**Author:** [@Almost\_Familiar](https://discuss.elastic.co/u/Almost_Familiar)\
**Replies:** 1\
**Last updated:** [June 9, 2022, 3:59pm UTC](https://discuss.elastic.co/t/spring-data-elasticsearch-exception-during-save-regardless-of-success/306813 "2022-06-09T15:59:21Z")

</div>

Hello everyone, we are using version Spring Boot 2.7.0 with Spring Data Elasticsearch, with reactive code. We prefer to make our requests with native queries via the ReactiveElasticsearchOperations interface. For an i…

---

## [Average count record per Min using LENS](https://discuss.elastic.co/t/average-count-record-per-min-using-lens/306379)

<div class="topic-metadata">

**Author:** [@dfraz](https://discuss.elastic.co/u/dfraz)\
**Replies:** 3\
**Last updated:** [June 9, 2022, 1:38pm UTC](https://discuss.elastic.co/t/average-count-record-per-min-using-lens/306379 "2022-06-09T13:38:44Z")

</div>

I need to calculate the Average count record ( orders ) per Min and then multiply by 60 to get an estimation of orders per hour. Can it be done with LENS ? Thanks in advance

---

## [Need help to configure http output plugin for https](https://discuss.elastic.co/t/need-help-to-configure-http-output-plugin-for-https/306773)

<div class="topic-metadata">

**Author:** [@guillaumeV](https://discuss.elastic.co/u/guillaumeV)\
**Replies:** 1\
**Last updated:** [June 9, 2022, 2:17pm UTC](https://discuss.elastic.co/t/need-help-to-configure-http-output-plugin-for-https/306773 "2022-06-09T14:17:00Z")

</div>

Hello i would like to send data via http output plugin (Http output plugin | Logstash Reference \[8.19\] | Elastic) to a https url . I have a very simple example with "https://www.google.com" which is not working is it pos…

---

## [Error executing 'postInstallation': EACCES: permission denied, mkdir '/bitnami/kibana/data'](https://discuss.elastic.co/t/error-executing-postinstallation-eacces-permission-denied-mkdir-bitnami-kibana-data/306798)

<div class="topic-metadata">

**Author:** [@mohamed\_atef](https://discuss.elastic.co/u/mohamed_atef)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 2:03pm UTC](https://discuss.elastic.co/t/error-executing-postinstallation-eacces-permission-denied-mkdir-bitnami-kibana-data/306798 "2022-06-09T14:03:57Z")

</div>

i have issue when i try to run kibana on K8S cluster via helm chart Error executing 'postInstallation': EACCES: permission denied, mkdir '/bitnami/kibana/data'

---

## [Grok pattern for snort alerts](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625)

<div class="topic-metadata">

**Author:** [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Replies:** 4\
**Last updated:** [June 9, 2022, 1:54pm UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625 "2022-06-09T13:54:27Z")

</div>

HI everyone, Need help constructing grok pattern for the snort alert log file. I have the so far, but the output is incomplete - %{MONTHNUM:month}\\/%{MONTHDAY:day}-%{HOUR:hour}:%{MINUTE:minute}:%{SECOND:second}\\s+\\\[\\\*\\…

---

## [Jira Connector - Version supported](https://discuss.elastic.co/t/jira-connector-version-supported/306801)

<div class="topic-metadata">

**Author:** [@Orlando\_Gonzalez](https://discuss.elastic.co/u/Orlando_Gonzalez)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 1:30pm UTC](https://discuss.elastic.co/t/jira-connector-version-supported/306801 "2022-06-09T13:30:20Z")

</div>

Hi everybody We are trying to configure the Jira connector from an ELK 7.15.0, where the Jira Service Desk is Server Onpremise version 4.9.1. So far we have not been able to configure it, can you tell us if this configu…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=612)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=614)
