# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=295

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 296

---

## [Mapping works in default index, but not in custom one](https://discuss.elastic.co/t/mapping-works-in-default-index-but-not-in-custom-one/354347)

<div class="topic-metadata">

**Author:** [@Multiply0057](https://discuss.elastic.co/u/Multiply0057)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 1:21pm UTC](https://discuss.elastic.co/t/mapping-works-in-default-index-but-not-in-custom-one/354347 "2024-02-28T13:21:48Z")

</div>

Hello, fellow Elastic enthusiasts! Despite following the documentation and various online resources, I find myself at a standstill. Here's a brief overview of my setup: My Logstash pipeline is configured to output data…

---

## [Control is disabled although the field exist with a value (I can see it in discover)](https://discuss.elastic.co/t/control-is-disabled-although-the-field-exist-with-a-value-i-can-see-it-in-discover/352140)

<div class="topic-metadata">

**Author:** [@ShayWeizman](https://discuss.elastic.co/u/ShayWeizman)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 1:07pm UTC](https://discuss.elastic.co/t/control-is-disabled-although-the-field-exist-with-a-value-i-can-see-it-in-discover/352140 "2024-02-28T13:07:15Z")

</div>

I'm using Version 7.17.3. I've added few controls and some of them are disabled: Please advise? Thanks, Shay

---

## [Reasonable size for max\_async\_search\_response\_size with 40% of docs - size 200kb - 700kb](https://discuss.elastic.co/t/reasonable-size-for-max-async-search-response-size-with-40-of-docs-size-200kb-700kb/354341)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 12:37pm UTC](https://discuss.elastic.co/t/reasonable-size-for-max-async-search-response-size-with-40-of-docs-size-200kb-700kb/354341 "2024-02-28T12:37:43Z")

</div>

Hello. My cluster is growing. Lately I have done an analysis because of max\_async\_search\_response\_size error - that was making my searches imposible in some cases. Around 40% of my documents (not indexes) are size from…

---

## [Badly formatted index, after interpolation still contains placeholder](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 12:38pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231 "2024-02-28T12:38:17Z")

</div>

Hello, after migration to the 8.12.1 I've started getting error "Badly formatted index, after interpolation still contains placeholder". When I'm trying to process report with Filebeat. More interesting is I get this mes…

---

## [Export from Discovery to CSV](https://discuss.elastic.co/t/export-from-discovery-to-csv/353983)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 12:38pm UTC](https://discuss.elastic.co/t/export-from-discovery-to-csv/353983 "2024-02-28T12:38:17Z")

</div>

I have an ESQL search that outputs a list of unique IP addresses. When I Share to CSV, I'm getting "CSV may contain formulas, The report contains characters which spreadsheet applications can interpret as formulas. Whe…

---

## [Force field type](https://discuss.elastic.co/t/force-field-type/354342)

<div class="topic-metadata">

**Author:** [@goncalobsantos](https://discuss.elastic.co/u/goncalobsantos)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 12:38pm UTC](https://discuss.elastic.co/t/force-field-type/354342 "2024-02-28T12:38:02Z")

</div>

I'm using the SQL integration to get the rows in a table as documents in an index/datastream. The column phone\_number in the table is mapped to a field metrics.sql.phone\_number that is automatically assigned the type nu…

---

## [Create snapshot on on-prem S3](https://discuss.elastic.co/t/create-snapshot-on-on-prem-s3/354336)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 12:20pm UTC](https://discuss.elastic.co/t/create-snapshot-on-on-prem-s3/354336 "2024-02-28T12:20:31Z")

</div>

Hello, I have problem with integration with snapshot. I have on-prem s3 and when I tried to create repository I have a error: Unknown s3 client name \[test\]. Existing client configs: default. PUT \_snapshot/my\_s3\_reposit…

---

## [\[ingest-pipeline\] remove field from target index](https://discuss.elastic.co/t/ingest-pipeline-remove-field-from-target-index/354113)

<div class="topic-metadata">

**Author:** [@seddikalaouiismaili](https://discuss.elastic.co/u/seddikalaouiismaili)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 12:20pm UTC](https://discuss.elastic.co/t/ingest-pipeline-remove-field-from-target-index/354113 "2024-02-28T12:20:02Z")

</div>

Hi community, I'm trying delete some unused fields from index, through the ingest pipeline. Current config : "remove": { "if": "ctx.\_index.contains('stg-index-short-')", "field": "messa…

---

## [No implicit conversion of Pathname into String when logstash plugin installed](https://discuss.elastic.co/t/no-implicit-conversion-of-pathname-into-string-when-logstash-plugin-installed/354328)

<div class="topic-metadata">

**Author:** [@rindarapu](https://discuss.elastic.co/u/rindarapu)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 11:04am UTC](https://discuss.elastic.co/t/no-implicit-conversion-of-pathname-into-string-when-logstash-plugin-installed/354328 "2024-02-28T11:04:15Z")

</div>

getting "no implicit conversion of Pathname into String" when installing offline plugin. Downloaded logstash 8.12.2 and installed logstash-output-mongodb plugin created offline pack and trying to install on the server…

---

## [Remove new lines when copy/pasting in Discover](https://discuss.elastic.co/t/remove-new-lines-when-copy-pasting-in-discover/354326)

<div class="topic-metadata">

**Author:** [@mch](https://discuss.elastic.co/u/mch)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 11:46am UTC](https://discuss.elastic.co/t/remove-new-lines-when-copy-pasting-in-discover/354326 "2024-02-28T11:46:10Z")

</div>

Hello, I coming back on this subject since the last topic was automatically closed. There is still issues when copy/pasting the Discover's output. In the following example, there is 3 columns (@timestamp, host, report\_…

---

## [Cluster creation best practices](https://discuss.elastic.co/t/cluster-creation-best-practices/354333)

<div class="topic-metadata">

**Author:** [@kruzadmn](https://discuss.elastic.co/u/kruzadmn)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 11:43am UTC](https://discuss.elastic.co/t/cluster-creation-best-practices/354333 "2024-02-28T11:43:08Z")

</div>

Hello everyone. I need to deploy an Elasticsearch cluster. To do this, I have a server in the data center with the following specifications that I need to maximize. CPU: 100 GHz RAM: 1.7 TB DISK: 15 TB SSD I can use …

---

## [Elasticsearch doesn't start](https://discuss.elastic.co/t/elasticsearch-doesnt-start/354319)

<div class="topic-metadata">

**Author:** [@funny\_mackerel](https://discuss.elastic.co/u/funny_mackerel)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 10:59am UTC](https://discuss.elastic.co/t/elasticsearch-doesnt-start/354319 "2024-02-28T10:59:58Z")

</div>

Hi. I have this weird problem. Every time I start bin/elasticsearch it prints Java usage output. I tried it on a newer version I downloaded and it does the same. It worked very well until some point and I can't remember…

---

## [Watcher : webhook action parsing error](https://discuss.elastic.co/t/watcher-webhook-action-parsing-error/354321)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 10:27am UTC](https://discuss.elastic.co/t/watcher-webhook-action-parsing-error/354321 "2024-02-28T10:27:04Z")

</div>

Hi, I'm facing an error from watcher and the webhook action section: The watcher is working fine and send us via email the related information we need (ie count of error from an IP address and subcount of error rela…

---

## [How can we compare two indices in elasticsearch which are expected to be same?](https://discuss.elastic.co/t/how-can-we-compare-two-indices-in-elasticsearch-which-are-expected-to-be-same/354323)

<div class="topic-metadata">

**Author:** [@rampavandev](https://discuss.elastic.co/u/rampavandev)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 10:38am UTC](https://discuss.elastic.co/t/how-can-we-compare-two-indices-in-elasticsearch-which-are-expected-to-be-same/354323 "2024-02-28T10:38:29Z")

</div>

I have a task which deals with comparing two indices on specific fields. I tried this query but I am not sure about the reliability of this query to compare? I have tried below query in Kibana. Please let me know if thi…

---

## [Generating short URL to hide filters](https://discuss.elastic.co/t/generating-short-url-to-hide-filters/354198)

<div class="topic-metadata">

**Author:** [@skouf](https://discuss.elastic.co/u/skouf)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 10:38am UTC](https://discuss.elastic.co/t/generating-short-url-to-hide-filters/354198 "2024-02-28T10:38:23Z")

</div>

Hello We need to transform URL like this kibanaUrl/app/dashboards?auth\_provider\_hint=anonymous1#/view/7adfa750-4c81-11e8-b3d7-01146121b73d?embed=true&\_g=(filters:!(),refreshInterval:(pause:!f,value:0),time:(from:'${sel…

---

## [Is there a way we can have color coding in pie charts based on our requirements?](https://discuss.elastic.co/t/is-there-a-way-we-can-have-color-coding-in-pie-charts-based-on-our-requirements/354311)

<div class="topic-metadata">

**Author:** [@varshii](https://discuss.elastic.co/u/varshii)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 9:33am UTC](https://discuss.elastic.co/t/is-there-a-way-we-can-have-color-coding-in-pie-charts-based-on-our-requirements/354311 "2024-02-28T09:33:00Z")

</div>

I need to change the color patterns used in the pie charts (ie to customize my own color pallet). Is this possible? If yes please let me know how!

---

## [Elasticsearch relevency search](https://discuss.elastic.co/t/elasticsearch-relevency-search/354274)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 3:48am UTC](https://discuss.elastic.co/t/elasticsearch-relevency-search/354274 "2024-02-28T03:48:52Z")

</div>

my search documents have the value of Doc 1 { "keyword\_values": "washbasin" } Doc 2 { "keyword\_values": "wash basin" } Doc 3 { "keyword\_values": "wash and basin" } Doc 4 { "keyword\_values": "wash …

---

## [Question about performance available with elastic cloud](https://discuss.elastic.co/t/question-about-performance-available-with-elastic-cloud/353988)

<div class="topic-metadata">

**Author:** [@skouf](https://discuss.elastic.co/u/skouf)\
**Replies:** 5\
**Last updated:** [February 28, 2024, 8:14am UTC](https://discuss.elastic.co/t/question-about-performance-available-with-elastic-cloud/353988 "2024-02-28T08:14:10Z")

</div>

Hello We are investigating the paid solutions with elasticsearch. We saw that the first option in the cloud is a 45 Gb storage, and only 1 Gb of RAM. Because we have some apps that have more than 1 million of docs (an…

---

## [PFsense Integration Issue](https://discuss.elastic.co/t/pfsense-integration-issue/354308)

<div class="topic-metadata">

**Author:** [@jaspreetjhans](https://discuss.elastic.co/u/jaspreetjhans)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 8:03am UTC](https://discuss.elastic.co/t/pfsense-integration-issue/354308 "2024-02-28T08:03:35Z")

</div>

Hi After integration Pfsense , i am getting bellow error Provided Grok expressions do not match field value: \[\<134\>1 2024-02-28T09:58:56+02:00 OPNSense01.localdomain filterlog 90364 - \[meta sequenceId="1089"\] 56,,,fae5…

---

## [Can I get the data analysis range time?](https://discuss.elastic.co/t/can-i-get-the-data-analysis-range-time/354306)

<div class="topic-metadata">

**Author:** [@yuta.otsubo](https://discuss.elastic.co/u/yuta.otsubo)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 7:50am UTC](https://discuss.elastic.co/t/can-i-get-the-data-analysis-range-time/354306 "2024-02-28T07:50:50Z")

</div>

I want to get the data analysis range time in kibana alert and use it for message setting. kibana version: 7.7.1 The monitor settings are as follows { "size": 0, "query": { "bool": { "filte…

---

## [Parsing file containing sectional metadata and data](https://discuss.elastic.co/t/parsing-file-containing-sectional-metadata-and-data/354020)

<div class="topic-metadata">

**Author:** [@Diamond\_Mohanty](https://discuss.elastic.co/u/Diamond_Mohanty)\
**Replies:** 5\
**Last updated:** [February 28, 2024, 6:38am UTC](https://discuss.elastic.co/t/parsing-file-containing-sectional-metadata-and-data/354020 "2024-02-28T06:38:04Z")

</div>

I have a file with a structure where the actual events follow their meta. For example, the file has contents like below Columns = Name|Age|Gender Delimiter = | John|23|M Jane|25|F Columns = Country,State Delimiter…

---

## [Windows Server Integration to Elastic Search is failing elastic agent fleet enrollment is happening but elastic agent not starting and not sending data](https://discuss.elastic.co/t/windows-server-integration-to-elastic-search-is-failing-elastic-agent-fleet-enrollment-is-happening-but-elastic-agent-not-starting-and-not-sending-data/354239)

<div class="topic-metadata">

**Author:** [@nkreddyp](https://discuss.elastic.co/u/nkreddyp)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 5:58am UTC](https://discuss.elastic.co/t/windows-server-integration-to-elastic-search-is-failing-elastic-agent-fleet-enrollment-is-happening-but-elastic-agent-not-starting-and-not-sending-data/354239 "2024-02-28T05:58:31Z")

</div>

please any one faces this kind of issue please help me i'm stuck almost from one month to integrate windows server due to this issue i have used selfsigned certificates for fleet server and Elasticsearch {"log.level":"i…

---

## [How to update elastic-agent API key?](https://discuss.elastic.co/t/how-to-update-elastic-agent-api-key/354293)

<div class="topic-metadata">

**Author:** [@Mang-Joo](https://discuss.elastic.co/u/Mang-Joo)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 5:57am UTC](https://discuss.elastic.co/t/how-to-update-elastic-agent-api-key/354293 "2024-02-28T05:57:05Z")

</div>

hello. I want to unenroll and re-enroll an agent in fleet. Where can I update the API KEY? I want a way other than reinstalling.

---

## [ElasticSearch output of Filebeat is empty, displays http error 400 Bad Request](https://discuss.elastic.co/t/elasticsearch-output-of-filebeat-is-empty-displays-http-error-400-bad-request/352407)

<div class="topic-metadata">

**Author:** [@NotTheRealV](https://discuss.elastic.co/u/NotTheRealV)\
**Replies:** 32\
**Last updated:** [February 28, 2024, 4:53am UTC](https://discuss.elastic.co/t/elasticsearch-output-of-filebeat-is-empty-displays-http-error-400-bad-request/352407 "2024-02-28T04:53:08Z")

</div>

So installed Elasticsearch (v8.12.0) for Windows as per the guide given here: Elasticsearch Installation Guide. I similarly, installed Kibana (v8.12.0) for Windows as per the guide given here: Kibana Installation Guide. …

---

## [Requesting help with Case-insensitive Analyzer](https://discuss.elastic.co/t/requesting-help-with-case-insensitive-analyzer/354273)

<div class="topic-metadata">

**Author:** [@mvkfg](https://discuss.elastic.co/u/mvkfg)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 3:06am UTC](https://discuss.elastic.co/t/requesting-help-with-case-insensitive-analyzer/354273 "2024-02-28T03:06:51Z")

</div>

Hello, I have enabled a "lowercase" analyzer across all my indices, but I have run into an error while using it. My query parameter: "query": { "query\_string": { "query": "username.keyword:\\"Test\\"", "…

---

## [Custom name with Filebeat](https://discuss.elastic.co/t/custom-name-with-filebeat/354275)

<div class="topic-metadata">

**Author:** [@griffer98](https://discuss.elastic.co/u/griffer98)\
**Replies:** 4\
**Last updated:** [February 27, 2024, 10:30pm UTC](https://discuss.elastic.co/t/custom-name-with-filebeat/354275 "2024-02-27T22:30:22Z")

</div>

I am trying to send data from filebeat straight to elasticsearch. But no matter what I do I can't get the name to be what I want. I have tried everything the docs and all the forums are saying to do but nothing works. I …

---

## [We can use the scripted field to return a URL string and string field formatter to format that URL string into an hyper link when rendered. But what if I want to add the URL based on some conditions? For some fields I need the URL and for some not?](https://discuss.elastic.co/t/we-can-use-the-scripted-field-to-return-a-url-string-and-string-field-formatter-to-format-that-url-string-into-an-hyper-link-when-rendered-but-what-if-i-want-to-add-the-url-based-on-some-conditions-for-some-fields-i-need-the-url-and-for-some-not/354230)

<div class="topic-metadata">

**Author:** [@borahmridul](https://discuss.elastic.co/u/borahmridul)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 9:47pm UTC](https://discuss.elastic.co/t/we-can-use-the-scripted-field-to-return-a-url-string-and-string-field-formatter-to-format-that-url-string-into-an-hyper-link-when-rendered-but-what-if-i-want-to-add-the-url-based-on-some-conditions-for-some-fields-i-need-the-url-and-for-some-not/354230 "2024-02-27T21:47:00Z")

</div>

Please help as it is on priority.

---

## [Sending data to new Data Stream with Elastic Agent](https://discuss.elastic.co/t/sending-data-to-new-data-stream-with-elastic-agent/353926)

<div class="topic-metadata">

**Author:** [@wrender1](https://discuss.elastic.co/u/wrender1)\
**Replies:** 19\
**Last updated:** [February 27, 2024, 8:09pm UTC](https://discuss.elastic.co/t/sending-data-to-new-data-stream-with-elastic-agent/353926 "2024-02-27T20:09:54Z")

</div>

Hi, We are trying to use a Standalone Elastic Agent on Kubernetes. Right now it is creating indexes for us, and sending all container logs to it. The indexes end up looking like: logs-kubernetes.container\_logs-cluster-…

---

## [Counting results by a value](https://discuss.elastic.co/t/counting-results-by-a-value/354256)

<div class="topic-metadata">

**Author:** [@user-27022024](https://discuss.elastic.co/u/user-27022024)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 8:18pm UTC](https://discuss.elastic.co/t/counting-results-by-a-value/354256 "2024-02-27T20:18:10Z")

</div>

We store our load balancer logs in elasticsarch and use kibana for querying. In Kibana - Discover I can add a filter for IP address which will display the IP address from each request. But is it possible to just count e…

---

## [One-line log file](https://discuss.elastic.co/t/one-line-log-file/354060)

<div class="topic-metadata">

**Author:** [@Kamil2](https://discuss.elastic.co/u/Kamil2)\
**Replies:** 3\
**Last updated:** [February 27, 2024, 8:30pm UTC](https://discuss.elastic.co/t/one-line-log-file/354060 "2024-02-27T20:30:35Z")

</div>

Is it possible for filebeat to send the entire contents of the log file to index every specific time interval? I want to save the state of a specific process to a file, overwrite the file each time and not keep historica…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=294)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=296)
