# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=306

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 307

---

## [Cluster.initial\_master\_nodes Settings](https://discuss.elastic.co/t/cluster-initial-master-nodes-settings/353303)

<div class="topic-metadata">

**Author:** [@pras](https://discuss.elastic.co/u/pras)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 8:25am UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-settings/353303 "2024-02-15T08:25:46Z")

</div>

Hi guys I have three node cluster using Elastic 8.6. It is in operation for more than a year. We are going to upgrade to 8.8 soon. I this regard I have a question on cluster.initial\_master\_nodes setting. This setting is…

---

## [Elasticsearch and Kibana upgrade to v8.12.0 from v8.0.0](https://discuss.elastic.co/t/elasticsearch-and-kibana-upgrade-to-v8-12-0-from-v8-0-0/353170)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 8:18am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-upgrade-to-v8-12-0-from-v8-0-0/353170 "2024-02-15T08:18:45Z")

</div>

Hi Team, We are planning to upgrade elasticsearch and Kibana to v8.12.0 from v8.0.0 For beats and ELK communication wea re using ssl true and we are using API key in yaml file of beats like metricbeat. Wanted to know …

---

## [Beats v8.12.0 use with ELK v8.0.0](https://discuss.elastic.co/t/beats-v8-12-0-use-with-elk-v8-0-0/353063)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 8:14am UTC](https://discuss.elastic.co/t/beats-v8-12-0-use-with-elk-v8-0-0/353063 "2024-02-15T08:14:01Z")

</div>

Hi Team, Could anyone help on below scenario. I am using elasticsearch and Kibana of v8.0.0 docker image and wanted to use beats of v8.12.0 of windows (not docker) I do have docker images for beats on few linux machin…

---

## [Sending logs in a my pattern to Logstash via TCP](https://discuss.elastic.co/t/sending-logs-in-a-my-pattern-to-logstash-via-tcp/353336)

<div class="topic-metadata">

**Author:** [@kypdk](https://discuss.elastic.co/u/kypdk)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 7:43am UTC](https://discuss.elastic.co/t/sending-logs-in-a-my-pattern-to-logstash-via-tcp/353336 "2024-02-15T07:43:15Z")

</div>

%d{yyyy-MM-dd HH:mm:ss.SSS} \[%t\] %-5level %logger{36} - %X{requestId} %msg%n%exception{full} in this pattern Can I send to logstash over TCP in json format? I don't want to do xml configuration. I will make all the ad…

---

## [Create ILM on the timestamp field](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [February 15, 2024, 7:12am UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172 "2024-02-15T07:12:52Z")

</div>

Hi Team, I want to create a ILM on the timestamp field (which received as field in the log file itself as epoch time). So I want create the ILM on basis of that field. Could you please let me know how we can achieve the…

---

## [Why my query cannot return any result althought the key exist in the message](https://discuss.elastic.co/t/why-my-query-cannot-return-any-result-althought-the-key-exist-in-the-message/353330)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 6:44am UTC](https://discuss.elastic.co/t/why-my-query-cannot-return-any-result-althought-the-key-exist-in-the-message/353330 "2024-02-15T06:44:21Z")

</div>

Dear Hi This is my log sample \<log realm="channel/192.168.20.10:61615" at="2024-02-14T15:25:04.930" lifespan="383ms"\> \<receive\> \<isomsg direction="incoming"\> \<!-- com.middle.gateway.packager.ShetabISO87APa…

---

## [Increase in container memory with logstash 8.11.3 version](https://discuss.elastic.co/t/increase-in-container-memory-with-logstash-8-11-3-version/353225)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 4:48am UTC](https://discuss.elastic.co/t/increase-in-container-memory-with-logstash-8-11-3-version/353225 "2024-02-15T04:48:39Z")

</div>

Hi, There is gradual increase in container memory in our service which uses logstash 8.11.3. Due to this the container may go to OOM kill within a few days and our service may crash.Can anyone suggest if there is any b…

---

## [Date Variable on index name](https://discuss.elastic.co/t/date-variable-on-index-name/353321)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 4:35am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321 "2024-02-15T04:35:23Z")

</div>

Hello there, I'm curious when there's a pipeline with configured output like this: index =\> "log-%{+YYYY.MM.dd}" where is the date variable referring to? the timestamp on the log, or the timestamp of the logstash se…

---

## [Question about ILM Delete phrase](https://discuss.elastic.co/t/question-about-ilm-delete-phrase/353319)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 3:14am UTC](https://discuss.elastic.co/t/question-about-ilm-delete-phrase/353319 "2024-02-15T03:14:50Z")

</div>

Hi, I have a question about the delete phrase in ILM. I have the ILM policy set when the max 15gb limit is reached in the primary shard then do the roll over and then I want that index to be completely deleted after 3 m…

---

## [Can I use these step to generate elastic search root-ca.pem](https://discuss.elastic.co/t/can-i-use-these-step-to-generate-elastic-search-root-ca-pem/353238)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 1:20am UTC](https://discuss.elastic.co/t/can-i-use-these-step-to-generate-elastic-search-root-ca-pem/353238 "2024-02-15T01:20:02Z")

</div>

./elasticsearch-certutil ca ./elasticsearch-certutil cert --ca elastic-stack-ca.p12 openssl pkcs12 -in elastic-certificates.p12 -clcerts -nokeys -out certificate.pem openssl pkcs12 -in elastic-certificates.p12 -nocert…

---

## [Unresolved or ambiguous specs during Gem::Specification.reset: date (\>= 0), but cannot run gem command to resolve](https://discuss.elastic.co/t/unresolved-or-ambiguous-specs-during-gem-specification-reset-date-0-but-cannot-run-gem-command-to-resolve/351931)

<div class="topic-metadata">

**Author:** [@hughjarse](https://discuss.elastic.co/u/hughjarse)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 1:17am UTC](https://discuss.elastic.co/t/unresolved-or-ambiguous-specs-during-gem-specification-reset-date-0-but-cannot-run-gem-command-to-resolve/351931 "2024-02-15T01:17:52Z")

</div>

Running the logstash-plugin list or logstash-plugin install commands cause the following error. How can I troubleshoot and resolve this problem with the gem command that is built into Logstash? WARN: Unresolved or ambig…

---

## [Kibana: Commonly use - Yesterday is missing](https://discuss.elastic.co/t/kibana-commonly-use-yesterday-is-missing/353055)

<div class="topic-metadata">

**Author:** [@CargoBikoMeter](https://discuss.elastic.co/u/CargoBikoMeter)\
**Replies:** 3\
**Last updated:** [February 14, 2024, 9:03pm UTC](https://discuss.elastic.co/t/kibana-commonly-use-yesterday-is-missing/353055 "2024-02-14T21:03:47Z")

</div>

It would be nice to have an entry "Yesterday" in the field "Commonly used" in the Kibana time window. Why does such entry not already exists? I use Kibana 7.17.16.

---

## [Fleet on GKE (ECK) behind a Google LB 502 errors](https://discuss.elastic.co/t/fleet-on-gke-eck-behind-a-google-lb-502-errors/353309)

<div class="topic-metadata">

**Author:** [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 8:36pm UTC](https://discuss.elastic.co/t/fleet-on-gke-eck-behind-a-google-lb-502-errors/353309 "2024-02-14T20:36:40Z")

</div>

Preformatted texto we run Elastic on GKE using ECK. We are on version 8.12. I just installed the Fleet server yesterday with 4 replicas and they are sitting behind a GCP classic http LB. The servers can be seen on the f…

---

## [Filebeat Autodiscover on Kubernetes not working](https://discuss.elastic.co/t/filebeat-autodiscover-on-kubernetes-not-working/353097)

<div class="topic-metadata">

**Author:** [@Paul\_B](https://discuss.elastic.co/u/Paul_B)\
**Replies:** 4\
**Last updated:** [February 14, 2024, 8:04pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-on-kubernetes-not-working/353097 "2024-02-14T20:04:08Z")

</div>

I'm having trouble getting autodiscover to work correctly in a Kubernetes environment, if I restart the Filebeat daemonset then logs of new pods are collected correctly but if a pod restarts then Filebeat doesn't see the…

---

## [Query Regarding Warning Messages in Logstash Version 8.12.0](https://discuss.elastic.co/t/query-regarding-warning-messages-in-logstash-version-8-12-0/353242)

<div class="topic-metadata">

**Author:** [@Ramya\_Sababathi](https://discuss.elastic.co/u/Ramya_Sababathi)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 6:44pm UTC](https://discuss.elastic.co/t/query-regarding-warning-messages-in-logstash-version-8-12-0/353242 "2024-02-14T18:44:32Z")

</div>

Issue Description: Upon upgrading to Logstash version 8.12.0, I have noticed the following warning messages appearing in the logs: /usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/concurrent-ruby-1.1.9/lib/concurrent…

---

## [Mimecast integration no longer ingesting siem logs](https://discuss.elastic.co/t/mimecast-integration-no-longer-ingesting-siem-logs/353192)

<div class="topic-metadata">

**Author:** [@jeffmaley](https://discuss.elastic.co/u/jeffmaley)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 5:27pm UTC](https://discuss.elastic.co/t/mimecast-integration-no-longer-ingesting-siem-logs/353192 "2024-02-14T17:27:51Z")

</div>

I'm using the Mimecast integration and it's suddenly stopped ingesting the siem logs. The logs on the elastic agent indicate that events are being published, but they are not showing up in the index in ELK. Has anyone ru…

---

## [Top\_hits sort within the nested bucket](https://discuss.elastic.co/t/top-hits-sort-within-the-nested-bucket/353302)

<div class="topic-metadata">

**Author:** [@mavwolverine](https://discuss.elastic.co/u/mavwolverine)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 5:16pm UTC](https://discuss.elastic.co/t/top-hits-sort-within-the-nested-bucket/353302 "2024-02-14T17:16:45Z")

</div>

document has categories array with \[{"categoryId": 123, "sortOrder": 456},{"categoryId": 124, "sortOrder": 12}\] Used terms to create buckets on categoryId, now I want to sort using sortOrder inside each bucket for that …

---

## [Creating a second index with subset of fields from first index](https://discuss.elastic.co/t/creating-a-second-index-with-subset-of-fields-from-first-index/353265)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 4:15pm UTC](https://discuss.elastic.co/t/creating-a-second-index-with-subset-of-fields-from-first-index/353265 "2024-02-14T16:15:55Z")

</div>

Hello Elastic community, I'm seeking advice on how to efficiently create a second index containing only a subset of fields from a primary index based on certain conditions. To provide some context, let's say I have a p…

---

## [Elastic search server do not respond on curl request](https://discuss.elastic.co/t/elastic-search-server-do-not-respond-on-curl-request/353258)

<div class="topic-metadata">

**Author:** [@Shahram](https://discuss.elastic.co/u/Shahram)\
**Replies:** 3\
**Last updated:** [February 14, 2024, 4:05pm UTC](https://discuss.elastic.co/t/elastic-search-server-do-not-respond-on-curl-request/353258 "2024-02-14T16:05:22Z")

</div>

I noticed my Elasticsearch could not be accessible via curl, so I started from scratch on a new vm. I used this config file for docker-compose.yml: version: '3.6' services: Elasticsearch: image: elasticsearch:7.1…

---

## [Delete\_by\_query returns empty](https://discuss.elastic.co/t/delete-by-query-returns-empty/353294)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 4:01pm UTC](https://discuss.elastic.co/t/delete-by-query-returns-empty/353294 "2024-02-14T16:01:05Z")

</div>

I try to delete the old records in my index, but the delete\_by\_query returns empty to me. I have a lot of data in the index, it should not be zero. Please help me to check where the problem is. Thank you! Here is my cur…

---

## [Size of the facet in the query affects the number of results of specific facet](https://discuss.elastic.co/t/size-of-the-facet-in-the-query-affects-the-number-of-results-of-specific-facet/353296)

<div class="topic-metadata">

**Author:** [@Daniel\_Botran\_Quiros](https://discuss.elastic.co/u/Daniel_Botran_Quiros)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 3:51pm UTC](https://discuss.elastic.co/t/size-of-the-facet-in-the-query-affects-the-number-of-results-of-specific-facet/353296 "2024-02-14T15:51:27Z")

</div>

Hello, I am implementing App Search for an e-commerce, and I've just realized that the size of the facet in the queries affects to certain counts in the response. My query is like this: { "query": "galletas", "pa…

---

## [Filestream Fingerprint Mode](https://discuss.elastic.co/t/filestream-fingerprint-mode/352667)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 4\
**Last updated:** [February 14, 2024, 3:49pm UTC](https://discuss.elastic.co/t/filestream-fingerprint-mode/352667 "2024-02-14T15:49:44Z")

</div>

Hi I had a question regarding this new fingerprint mode with filestream. Introducing Filestream fingerprint mode | Elastic Blog Does the file id created with fingerprint uses the filename as well as the content of the …

---

## [How to mask the content which will be available in persistence queue file](https://discuss.elastic.co/t/how-to-mask-the-content-which-will-be-available-in-persistence-queue-file/353075)

<div class="topic-metadata">

**Author:** [@siva0030](https://discuss.elastic.co/u/siva0030)\
**Replies:** 6\
**Last updated:** [February 14, 2024, 3:03pm UTC](https://discuss.elastic.co/t/how-to-mask-the-content-which-will-be-available-in-persistence-queue-file/353075 "2024-02-14T15:03:54Z")

</div>

Hello Team, We are using Logstash (8.11.3) in our monitoring to receive data from different source systems (via Filebeat, Metricbeat, and Winlogbeat). On the Logstash side, we are using a persistence queue. Since, Logs…

---

## [Alerts Webhook with basic license ELK 8.12](https://discuss.elastic.co/t/alerts-webhook-with-basic-license-elk-8-12/353216)

<div class="topic-metadata">

**Author:** [@riosje](https://discuss.elastic.co/u/riosje)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 2:24pm UTC](https://discuss.elastic.co/t/alerts-webhook-with-basic-license-elk-8-12/353216 "2024-02-14T14:24:30Z")

</div>

Is there a way to trigger a webhook or reach out any external resource with the basic license using the Alerts monitoring?

---

## [Highlighting performance issues with stored field and fvh highlighter](https://discuss.elastic.co/t/highlighting-performance-issues-with-stored-field-and-fvh-highlighter/353240)

<div class="topic-metadata">

**Author:** [@jsfi](https://discuss.elastic.co/u/jsfi)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 1:58pm UTC](https://discuss.elastic.co/t/highlighting-performance-issues-with-stored-field-and-fvh-highlighter/353240 "2024-02-14T13:58:42Z")

</div>

Hello, I'm having a very similar issue to Elastic query takes over 1 minute due to time spent in "HighlightPhase" I have documents with an optional attachments text field that for some documents can be quite big (up to…

---

## [Network Connections from ES Cluster](https://discuss.elastic.co/t/network-connections-from-es-cluster/353287)

<div class="topic-metadata">

**Author:** [@neophilipp](https://discuss.elastic.co/u/neophilipp)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 1:44pm UTC](https://discuss.elastic.co/t/network-connections-from-es-cluster/353287 "2024-02-14T13:44:41Z")

</div>

Hi, i am relativ new with the ELK Stack. For Security Reasons I need to know, if there is a communication needed FROM Elasticsearch to Fleet Server, Kibana or something else in ELK Stack. We want put our ES Cluster in a…

---

## [\[.NET SDK v7\] IsValid vs ThrowExceptions and bulk](https://discuss.elastic.co/t/net-sdk-v7-isvalid-vs-throwexceptions-and-bulk/353281)

<div class="topic-metadata">

**Author:** [@mnj](https://discuss.elastic.co/u/mnj)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 1:28pm UTC](https://discuss.elastic.co/t/net-sdk-v7-isvalid-vs-throwexceptions-and-bulk/353281 "2024-02-14T13:28:03Z")

</div>

The docs say: By default, the client won’t throw on any ElasticsearchClientException but instead return an invalid response that can be detected by checking the .IsValid property on the response. You can change this be…

---

## [Windows Event Log connector with Logstash](https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274)

<div class="topic-metadata">

**Author:** [@RemyB](https://discuss.elastic.co/u/RemyB)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 1:07pm UTC](https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274 "2024-02-14T13:07:05Z")

</div>

Hello all, I would like to thank you in advance for your time reading my following issue : In order to install the windows integrations (Windows Event Logs/Windows) and benefit from the provided visualisations and the …

---

## [Postfix monitoring using ELK](https://discuss.elastic.co/t/postfix-monitoring-using-elk/353125)

<div class="topic-metadata">

**Author:** [@uzzaldas](https://discuss.elastic.co/u/uzzaldas)\
**Replies:** 3\
**Last updated:** [February 14, 2024, 12:20pm UTC](https://discuss.elastic.co/t/postfix-monitoring-using-elk/353125 "2024-02-14T12:20:39Z")

</div>

I want to monitor Postfix logs using ELK stack. I tried postfix filter and grok pattern as below. But I am getting following errors from logstash. ELK Version: 8.9.2 Logstash Error: logstash\_1 | \[2024-02-13T05:3…

---

## [Error uninstalling the elastic agent](https://discuss.elastic.co/t/error-uninstalling-the-elastic-agent/353142)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 11:14am UTC](https://discuss.elastic.co/t/error-uninstalling-the-elastic-agent/353142 "2024-02-14T11:14:57Z")

</div>

i am running the uninstall command where the command have to be run but still showing error PS C:\\Program Files\\Elastic\\Agent\> .\\elastic-agent.exe uninstall Error: can only be uninstalled by executing the installed Elas…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=305)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=307)
