# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=296

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 297

---

## [How to setup a proxy in logstash using Windows?](https://discuss.elastic.co/t/how-to-setup-a-proxy-in-logstash-using-windows/354259)

<div class="topic-metadata">

**Author:** [@tcalvillo](https://discuss.elastic.co/u/tcalvillo)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 5:08pm UTC](https://discuss.elastic.co/t/how-to-setup-a-proxy-in-logstash-using-windows/354259 "2024-02-27T17:08:50Z")

</div>

Hello Logstash team, I successfully installed and started Logstash on Windows server 2016. My issue is that I use a proxy and, when I try to see a list of plugins in bin using the below command: C:\\Logstash\\logstash-8.…

---

## [Curator forcemerge Exception](https://discuss.elastic.co/t/curator-forcemerge-exception/354245)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 4:52pm UTC](https://discuss.elastic.co/t/curator-forcemerge-exception/354245 "2024-02-27T16:52:23Z")

</div>

Hi, I have an Elastic cluster running version 8.12.x with curator\_cli version 8.0.10. I recently had an odd timeout/connect issue with curator\_cli while it was doing a forcemerge (scheduled script -- not the focus of t…

---

## [Reindex -API](https://discuss.elastic.co/t/reindex-api/354249)

<div class="topic-metadata">

**Author:** [@Gadapa\_Vasundhara](https://discuss.elastic.co/u/Gadapa_Vasundhara)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 3:56pm UTC](https://discuss.elastic.co/t/reindex-api/354249 "2024-02-27T15:56:43Z")

</div>

Hi Team, Can i know reindex api, how much limit we can do for reindex size

---

## [Filtering nested lists using scripts](https://discuss.elastic.co/t/filtering-nested-lists-using-scripts/354248)

<div class="topic-metadata">

**Author:** [@oliver3](https://discuss.elastic.co/u/oliver3)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 3:02pm UTC](https://discuss.elastic.co/t/filtering-nested-lists-using-scripts/354248 "2024-02-27T15:02:29Z")

</div>

Hi all, I have spent days trying to come up with a very specific query. Here is the challenge: I have an index that stores ecommerce products. One product has lots of variants, which store the variant's price. The pri…

---

## [Elastic agent fleet server stuck in "updating" in UI](https://discuss.elastic.co/t/elastic-agent-fleet-server-stuck-in-updating-in-ui/354237)

<div class="topic-metadata">

**Author:** [@Marcus\_Berglund](https://discuss.elastic.co/u/Marcus_Berglund)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 2:00pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-server-stuck-in-updating-in-ui/354237 "2024-02-27T14:00:45Z")

</div>

Hi, When upgrading from 8.6.2 to 8.12.1 the fleet server agent is stuck at updating. Initially we missed the sha file, but that is fixed. Still no luck. The artifact repo is reachble and we are running on windows. we …

---

## [Pushed Configuration of Mysql and Apache](https://discuss.elastic.co/t/pushed-configuration-of-mysql-and-apache/354206)

<div class="topic-metadata">

**Author:** [@Nouman\_Ahmed](https://discuss.elastic.co/u/Nouman_Ahmed)\
**Replies:** 3\
**Last updated:** [February 27, 2024, 1:24pm UTC](https://discuss.elastic.co/t/pushed-configuration-of-mysql-and-apache/354206 "2024-02-27T13:24:28Z")

</div>

I have a query. When we install a an integration for a service, lets say mysql or Apache. When i use the integration for mysql then which file configuration for msql will be pushed on linux? I can see Elastci-agent.yml b…

---

## [Individual scores query](https://discuss.elastic.co/t/individual-scores-query/354225)

<div class="topic-metadata">

**Author:** [@Rui\_Goncalves](https://discuss.elastic.co/u/Rui_Goncalves)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 1:21pm UTC](https://discuss.elastic.co/t/individual-scores-query/354225 "2024-02-27T13:21:54Z")

</div>

Hello, Our client needs a way to perform a query and extract the results containing not only the score per row, but also the individual scores of each search keyword. To be more precise, they are performing a query wit…

---

## [Elastic Stack Agentless Installation](https://discuss.elastic.co/t/elastic-stack-agentless-installation/354218)

<div class="topic-metadata">

**Author:** [@spazzrabbit](https://discuss.elastic.co/u/spazzrabbit)\
**Replies:** 7\
**Last updated:** [February 27, 2024, 1:02pm UTC](https://discuss.elastic.co/t/elastic-stack-agentless-installation/354218 "2024-02-27T13:02:58Z")

</div>

Hello everyone ! Is there any way to monitor windows machines without agent/script on target machine ? ForExample: Tool/Script on logstash to login and read logs from the target machine via SSH etc. Then process in the…

---

## [I want to use lamda insead of logstash to send the logs from the local computer to the aws s3 using filebeat](https://discuss.elastic.co/t/i-want-to-use-lamda-insead-of-logstash-to-send-the-logs-from-the-local-computer-to-the-aws-s3-using-filebeat/354183)

<div class="topic-metadata">

**Author:** [@K\_Prem\_sivam\_reddy](https://discuss.elastic.co/u/K_Prem_sivam_reddy)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 12:41pm UTC](https://discuss.elastic.co/t/i-want-to-use-lamda-insead-of-logstash-to-send-the-logs-from-the-local-computer-to-the-aws-s3-using-filebeat/354183 "2024-02-27T12:41:37Z")

</div>

i want to send the logs from the local to the aws s3 using the filebeat and aws s3 and i want to use the lamda , please assist me.

---

## [Request for Retry Limit Feature in Logstash OpenSearch Output Plugin](https://discuss.elastic.co/t/request-for-retry-limit-feature-in-logstash-opensearch-output-plugin/354195)

<div class="topic-metadata">

**Author:** [@nw-engineer](https://discuss.elastic.co/u/nw-engineer)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 12:27pm UTC](https://discuss.elastic.co/t/request-for-retry-limit-feature-in-logstash-opensearch-output-plugin/354195 "2024-02-27T12:27:20Z")

</div>

Dear LogstashTeam, I hope this message finds you well. I am currently using Logstash version 8.4.3 with OpenSearch and have come across a behavior in the OpenSearch output plugin that I believe could be improved for bet…

---

## [Elastic web crawler limitations with platinum license](https://discuss.elastic.co/t/elastic-web-crawler-limitations-with-platinum-license/354213)

<div class="topic-metadata">

**Author:** [@sravank](https://discuss.elastic.co/u/sravank)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 10:21am UTC](https://discuss.elastic.co/t/elastic-web-crawler-limitations-with-platinum-license/354213 "2024-02-27T10:21:37Z")

</div>

Hi team, We are about to purchase the platinum license use the Web Crawl functionality. Can anyone please help me understand on bellow queries. Limitation on adding domains (or number of webpages per domain) collecti…

---

## [Kafka output. How to set a key from message value?](https://discuss.elastic.co/t/kafka-output-how-to-set-a-key-from-message-value/353185)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 10:14am UTC](https://discuss.elastic.co/t/kafka-output-how-to-set-a-key-from-message-value/353185 "2024-02-27T10:14:40Z")

</div>

I'm using logstash to ingest data from Redshift table and put into Kafka. It works great. But how to use input field as Kafka's key?

---

## [File Beat to Elasticsearch unable to publish Events](https://discuss.elastic.co/t/file-beat-to-elasticsearch-unable-to-publish-events/354092)

<div class="topic-metadata">

**Author:** [@Mani\_Manikanta](https://discuss.elastic.co/u/Mani_Manikanta)\
**Replies:** 7\
**Last updated:** [February 27, 2024, 10:11am UTC](https://discuss.elastic.co/t/file-beat-to-elasticsearch-unable-to-publish-events/354092 "2024-02-27T10:11:34Z")

</div>

Hi Team, Why I am Getting the below Error 2024-02-26T14:40:53.019+0700 ERROR \[elasticsearch\] elasticsearch/client.go:226 failed to perform any bulk index operations: Post "https://x.x.x.x:9200/\_bulk": net/http…

---

## [How to find all SIEM rules where field "timestampOverride" is not equal to "event.ingested"?](https://discuss.elastic.co/t/how-to-find-all-siem-rules-where-field-timestampoverride-is-not-equal-to-event-ingested/352383)

<div class="topic-metadata">

**Author:** [@dsv](https://discuss.elastic.co/u/dsv)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 10:10am UTC](https://discuss.elastic.co/t/how-to-find-all-siem-rules-where-field-timestampoverride-is-not-equal-to-event-ingested/352383 "2024-02-27T10:10:33Z")

</div>

Hey everyone 8.12.0 Trying to find SIEM detection rules where field "timestampOverride" is not equal to "event.ingested" GET kbn:/api/alerting/rules/\_find?search\_fields=params.timestampOverride&search=event.ingested …

---

## [Unable to setup kafka with metricbeat](https://discuss.elastic.co/t/unable-to-setup-kafka-with-metricbeat/354210)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 10:02am UTC](https://discuss.elastic.co/t/unable-to-setup-kafka-with-metricbeat/354210 "2024-02-27T10:02:03Z")

</div>

metricbeat.yml path: ${path.config}/modules.d/\*.yml reload.enabled: true setup.kibana: host: "https://#.#.#.#:443" protocol: "https" ssl.verification\_mode: none output.elasticsearch: hosts: \["https://ec1:9200","ht…

---

## [Finding documents with message field exceeding 1 mln characters](https://discuss.elastic.co/t/finding-documents-with-message-field-exceeding-1-mln-characters/353788)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 4\
**Last updated:** [February 27, 2024, 8:47am UTC](https://discuss.elastic.co/t/finding-documents-with-message-field-exceeding-1-mln-characters/353788 "2024-02-27T08:47:17Z")

</div>

Hello. I'm getting error regarding exceeded message field length (over 1 mln characters). I want to identify them. I found a script in painless language: GET /your\_index/\_search { "query": { "bool": { "mu…

---

## [Unable to run elasticsearch rally in docker](https://discuss.elastic.co/t/unable-to-run-elasticsearch-rally-in-docker/354174)

<div class="topic-metadata">

**Author:** [@uttamkrpanda](https://discuss.elastic.co/u/uttamkrpanda)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 8:16am UTC](https://discuss.elastic.co/t/unable-to-run-elasticsearch-rally-in-docker/354174 "2024-02-27T08:16:30Z")

</div>

I am unable to run elasticsearch rally with docker its getting "No such file or directory" error . How can i fix this ? docker run elastic/rally race --track=nyc\_taxis --test-mode --pipeline=benchmark-only --target-hos…

---

## [CSV export in discover without . keyword fields](https://discuss.elastic.co/t/csv-export-in-discover-without-keyword-fields/354173)

<div class="topic-metadata">

**Author:** [@sai7276p](https://discuss.elastic.co/u/sai7276p)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 7:40am UTC](https://discuss.elastic.co/t/csv-export-in-discover-without-keyword-fields/354173 "2024-02-27T07:40:32Z")

</div>

Hello, I am using 8.11x stack in my cluster and I want to extract CSV export in discover without .keyword fields. Is there any way to do this? other than selecting available fields from left side of discover page or dat…

---

## [How to get Percentage from count of records](https://discuss.elastic.co/t/how-to-get-percentage-from-count-of-records/353902)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [February 27, 2024, 6:57am UTC](https://discuss.elastic.co/t/how-to-get-percentage-from-count-of-records/353902 "2024-02-27T06:57:00Z")

</div>

Hi there, I'm using Elastic and kibana v7.17, and I want to get the percentage from each term in my table. look at this picture below as you can see there are many counts of records of each term on the right side, ho…

---

## [Windows Elastic-Agent Group Deployment](https://discuss.elastic.co/t/windows-elastic-agent-group-deployment/354149)

<div class="topic-metadata">

**Author:** [@Patrick.kirk](https://discuss.elastic.co/u/Patrick.kirk)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 10:18pm UTC](https://discuss.elastic.co/t/windows-elastic-agent-group-deployment/354149 "2024-02-26T22:18:13Z")

</div>

I’m looking at doing a mass deployment of the windows elastic agent (1000+ workstations) and looking for a “best or recommend” way. I have not seen an MSI for the agent. What are the recommendations for this?

---

## [Lab mentions to add the path --certificate-authorities=/home/elastic/certs/ca/ca.crt. But doesn't say where to add. Or maybe I missed something](https://discuss.elastic.co/t/lab-mentions-to-add-the-path-certificate-authorities-home-elastic-certs-ca-ca-crt-but-doesnt-say-where-to-add-or-maybe-i-missed-something/354151)

<div class="topic-metadata">

**Author:** [@ericatwood](https://discuss.elastic.co/u/ericatwood)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 9:41pm UTC](https://discuss.elastic.co/t/lab-mentions-to-add-the-path-certificate-authorities-home-elastic-certs-ca-ca-crt-but-doesnt-say-where-to-add-or-maybe-i-missed-something/354151 "2024-02-26T21:41:30Z")

</div>

!\[image|690x286\](upload://fDHjrY46od2qYIcWn7yTf2VEtIt.png

---

## [Logs dont' show up when trying to use filter](https://discuss.elastic.co/t/logs-dont-show-up-when-trying-to-use-filter/354120)

<div class="topic-metadata">

**Author:** [@haktoggle](https://discuss.elastic.co/u/haktoggle)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 8:47pm UTC](https://discuss.elastic.co/t/logs-dont-show-up-when-trying-to-use-filter/354120 "2024-02-26T20:47:24Z")

</div>

Hi, I'm attempting to utilize the filter with the accessible logs that are displayed on one of my dashboards; however, those available logs do not appear when using a filter. For example, the logs are displaying, and I…

---

## [Error about schema casting when updating documents attributes different than the error ones](https://discuss.elastic.co/t/error-about-schema-casting-when-updating-documents-attributes-different-than-the-error-ones/354142)

<div class="topic-metadata">

**Author:** [@alexandervcc](https://discuss.elastic.co/u/alexandervcc)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 5:44pm UTC](https://discuss.elastic.co/t/error-about-schema-casting-when-updating-documents-attributes-different-than-the-error-ones/354142 "2024-02-26T17:44:33Z")

</div>

Hello, I got some issue with elastic. I have a request which updates docs on elastics. this looks like: POST /index/\_update\_by\_query { "query":{ "match":{ "load": "sync" } }, …

---

## [How To Fix : code 429 - circuit\_breaking\_exception - Data too large, data for \[indices:data/write/bulk\[s\]\]](https://discuss.elastic.co/t/how-to-fix-code-429-circuit-breaking-exception-data-too-large-data-for-indices-data-write-bulk-s/354138)

<div class="topic-metadata">

**Author:** [@Leo\_K](https://discuss.elastic.co/u/Leo_K)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 4:37pm UTC](https://discuss.elastic.co/t/how-to-fix-code-429-circuit-breaking-exception-data-too-large-data-for-indices-data-write-bulk-s/354138 "2024-02-26T16:37:23Z")

</div>

Hello everyone, Configuration : Elastic Cloud - ES 8.11 I've been benchmarking Elastic for the past days and had multiple errors coming up and I couldn't find a viable answer on the most annoying one : { \_index: 'MY\_I…

---

## [Network Maps with Packetbeat- Using Graphs?](https://discuss.elastic.co/t/network-maps-with-packetbeat-using-graphs/353993)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 4:25pm UTC](https://discuss.elastic.co/t/network-maps-with-packetbeat-using-graphs/353993 "2024-02-26T16:25:49Z")

</div>

Hello, I am new to using Graphs. I was wondering with Packetbeat/Network Packet Capture integration, if it was possible to create a graph or topology of the traffic between source.ip and destination.ip . If graphs can h…

---

## [Kibana URL uses a Single host to serve all request](https://discuss.elastic.co/t/kibana-url-uses-a-single-host-to-serve-all-request/353003)

<div class="topic-metadata">

**Author:** [@upadhyayaaman](https://discuss.elastic.co/u/upadhyayaaman)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 4:17pm UTC](https://discuss.elastic.co/t/kibana-url-uses-a-single-host-to-serve-all-request/353003 "2024-02-26T16:17:09Z")

</div>

Hi All, We have 3 nodes in the cluster with 1 primary and 2 replicas. For DR activities we perform below steps : We are setting number of replica to 1 and then Exclude 1st node from cluster in single DC , while other…

---

## [Kibana cannot visualize my variables. ](https://discuss.elastic.co/t/kibana-cannot-visualize-my-variables/354069)

<div class="topic-metadata">

**Author:** [@Clinton\_Pillay](https://discuss.elastic.co/u/Clinton_Pillay)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 3:37pm UTC](https://discuss.elastic.co/t/kibana-cannot-visualize-my-variables/354069 "2024-02-26T15:37:48Z")

</div>

So im completely new to Kibana, and having challanges creating visualzations. I have my data imported sucessfully into Elasticsearch. I have 2 values(date(ISO8601 date and value(number type)). So I want to visualize a …

---

## [Question regarding filebeat indexes for version 8.11.x and ILM](https://discuss.elastic.co/t/question-regarding-filebeat-indexes-for-version-8-11-x-and-ilm/352726)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 9\
**Last updated:** [February 26, 2024, 3:04pm UTC](https://discuss.elastic.co/t/question-regarding-filebeat-indexes-for-version-8-11-x-and-ilm/352726 "2024-02-26T15:04:49Z")

</div>

Hi @all I am seeing an issue on the ELK production server w.r.t to ILM. We have a production server (standalone) where ELK stack is installed and has the version 7.17.15. Recently ILM policy was implemented and is run…

---

## [Json.keys\_under\_root ignored for JSON documents larger than 4096 bytes](https://discuss.elastic.co/t/json-keys-under-root-ignored-for-json-documents-larger-than-4096-bytes/354127)

<div class="topic-metadata">

**Author:** [@vegard](https://discuss.elastic.co/u/vegard)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 2:46pm UTC](https://discuss.elastic.co/t/json-keys-under-root-ignored-for-json-documents-larger-than-4096-bytes/354127 "2024-02-26T14:46:38Z")

</div>

Hi, we seem to be hitting a hard limit on our Custom Logs integration for the Elastic Agent, ingesting json logs. We have the following custom configuration: json: keys\_under\_root: true This works fine for all json …

---

## [Updating elasticsearch CA but \_ssl/certificates return wrong result](https://discuss.elastic.co/t/updating-elasticsearch-ca-but-ssl-certificates-return-wrong-result/354085)

<div class="topic-metadata">

**Author:** [@petertw6235](https://discuss.elastic.co/u/petertw6235)\
**Replies:** 5\
**Last updated:** [February 26, 2024, 1:08pm UTC](https://discuss.elastic.co/t/updating-elasticsearch-ca-but-ssl-certificates-return-wrong-result/354085 "2024-02-26T13:08:29Z")

</div>

Hi, Elasticsearch version: 7.17.9 I tried to update the TLS certificate because the CA will expire this year. I found this guide \[same CA\] (Update certificates with the same CA | Elasticsearch Guide \[7.17\] | Elastic) …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=295)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=297)
