# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=309

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 310

---

## [Kibana for open mobility data in Berlin](https://discuss.elastic.co/t/kibana-for-open-mobility-data-in-berlin/353056)

<div class="topic-metadata">

**Author:** [@CargoBikoMeter](https://discuss.elastic.co/u/CargoBikoMeter)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 11:12am UTC](https://discuss.elastic.co/t/kibana-for-open-mobility-data-in-berlin/353056 "2024-02-12T11:12:42Z")

</div>

In Berlin we have setup a Kibana based dashboard for open mobility data, which are based on data from Telraam devices. We have setup a system which reads the data via Telraam-API and provides these data as CSV files. The…

---

## [I am having this pipeline problem while integrating Wazuh with ELK](https://discuss.elastic.co/t/i-am-having-this-pipeline-problem-while-integrating-wazuh-with-elk/353034)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 3\
**Last updated:** [February 12, 2024, 10:14am UTC](https://discuss.elastic.co/t/i-am-having-this-pipeline-problem-while-integrating-wazuh-with-elk/353034 "2024-02-12T10:14:10Z")

</div>

What can I do ?

---

## [Add integration for Gitlab monitoring](https://discuss.elastic.co/t/add-integration-for-gitlab-monitoring/353038)

<div class="topic-metadata">

**Author:** [@Alphayeeeet](https://discuss.elastic.co/u/Alphayeeeet)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 9:48am UTC](https://discuss.elastic.co/t/add-integration-for-gitlab-monitoring/353038 "2024-02-12T09:48:23Z")

</div>

We have our own on-premise Gitlab server, which we want to monitor using Elastic Stack. We are currently using Fleet-managed Elastic Agent to ship data from our different systems. As stated out above, we now want to ing…

---

## [Filebeat causing a very large iowait and lagging after uncontrolled reboot](https://discuss.elastic.co/t/filebeat-causing-a-very-large-iowait-and-lagging-after-uncontrolled-reboot/351981)

<div class="topic-metadata">

**Author:** [@emmanuel\_t](https://discuss.elastic.co/u/emmanuel_t)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 9:12am UTC](https://discuss.elastic.co/t/filebeat-causing-a-very-large-iowait-and-lagging-after-uncontrolled-reboot/351981 "2024-02-12T09:12:57Z")

</div>

Hello, we have now for the second time had an issue of filebeat not reacting well to an uncontrolled reboot on production. It causes a large iowait on the server and lags considerably sending logs to the elasticsearch b…

---

## [Elasticsearch http.host default value](https://discuss.elastic.co/t/elasticsearch-http-host-default-value/351384)

<div class="topic-metadata">

**Author:** [@ilya-popkov](https://discuss.elastic.co/u/ilya-popkov)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 9:19am UTC](https://discuss.elastic.co/t/elasticsearch-http-host-default-value/351384 "2024-02-12T09:19:35Z")

</div>

In the elasticsearch version 8.12 docs says "network.host default value is localhost and http.host value defaults is address given by network.host". But for default in fresh new elasticsearch http.host is equal 0.0.0.0 w…

---

## [Elasticsearch-setup-passwords auto -url "http://localhost:9200" i want to run this command but getting error](https://discuss.elastic.co/t/elasticsearch-setup-passwords-auto-url-http-localhost-9200-i-want-to-run-this-command-but-getting-error/352920)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 9:07am UTC](https://discuss.elastic.co/t/elasticsearch-setup-passwords-auto-url-http-localhost-9200-i-want-to-run-this-command-but-getting-error/352920 "2024-02-12T09:07:51Z")

</div>

while running this command in the elasticsearch bin folder cli elasticsearch-setup-passwords auto -url "http://localhost:9200" it is giving this error Failed to authenticate user 'elastic' against http://localhost:920…

---

## [Boost results that starts with exact query](https://discuss.elastic.co/t/boost-results-that-starts-with-exact-query/352959)

<div class="topic-metadata">

**Author:** [@MMkMkMk](https://discuss.elastic.co/u/MMkMkMk)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 8:57am UTC](https://discuss.elastic.co/t/boost-results-that-starts-with-exact-query/352959 "2024-02-12T08:57:17Z")

</div>

Hello, I'm trying to have a full-text query that boost results that starts with the entered query. For instance i have 2 book titles: "Viva Harry Potter" and "Harry Potter and the whatever stone". If the user search fo…

---

## [Log Shipping and Access Issues in Application Pod using filebeat](https://discuss.elastic.co/t/log-shipping-and-access-issues-in-application-pod-using-filebeat/353043)

<div class="topic-metadata">

**Author:** [@Arsalan\_Muhammad](https://discuss.elastic.co/u/Arsalan_Muhammad)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 8:41am UTC](https://discuss.elastic.co/t/log-shipping-and-access-issues-in-application-pod-using-filebeat/353043 "2024-02-12T08:41:45Z")

</div>

I'm encountering difficulties shipping logs from my application pod, which is operational within the abc namespace, to the Elasticsearch cluster. Despite my efforts, I haven't been successful in resolving this issue. Cou…

---

## [How to use minimum\_should\_match for prefix search?](https://discuss.elastic.co/t/how-to-use-minimum-should-match-for-prefix-search/352363)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 7:38am UTC](https://discuss.elastic.co/t/how-to-use-minimum-should-match-for-prefix-search/352363 "2024-02-12T07:38:10Z")

</div>

I want to make a search-as-you-type search service (with tokenization, analyzer etc.) and to use minimum\_should\_match in it, i.e. to show pages with three of four typed tokens but not with two of four. What is the best …

---

## [What is the best way to search one index with keyword and another index with vector and combine the search results?](https://discuss.elastic.co/t/what-is-the-best-way-to-search-one-index-with-keyword-and-another-index-with-vector-and-combine-the-search-results/352628)

<div class="topic-metadata">

**Author:** [@zli](https://discuss.elastic.co/u/zli)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 7:33am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-search-one-index-with-keyword-and-another-index-with-vector-and-combine-the-search-results/352628 "2024-02-12T07:33:17Z")

</div>

Hi there, I'm currently working on a project where I need to perform searches across multiple indices in Elasticsearch and combine the results into a single ranked list. I have one index where keyword search is performe…

---

## [Best practices for managing lifecycles of small units of data](https://discuss.elastic.co/t/best-practices-for-managing-lifecycles-of-small-units-of-data/352670)

<div class="topic-metadata">

**Author:** [@japem](https://discuss.elastic.co/u/japem)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 7:28am UTC](https://discuss.elastic.co/t/best-practices-for-managing-lifecycles-of-small-units-of-data/352670 "2024-02-12T07:28:48Z")

</div>

I have a use case where I have small-ish units of data (generally \<1GB) that I want to be able to manage the lifecycles of separately. Essentially, each user has information that we want to store in a hot data tier durin…

---

## [Logstash pipeline indexing error](https://discuss.elastic.co/t/logstash-pipeline-indexing-error/352388)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 7:26am UTC](https://discuss.elastic.co/t/logstash-pipeline-indexing-error/352388 "2024-02-12T07:26:42Z")

</div>

Hi team, I am using ELK stack 8.12 for observability. I am collecting input data from SNMP plugin and filtering the data as per my requirement but while doing that i have multiple index for multiple events that I am col…

---

## [Elasticsearch Java Api Client (7.17.16) - GetIndexResponse](https://discuss.elastic.co/t/elasticsearch-java-api-client-7-17-16-getindexresponse/353035)

<div class="topic-metadata">

**Author:** [@SElasticsearch](https://discuss.elastic.co/u/SElasticsearch)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 5:41am UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-7-17-16-getindexresponse/353035 "2024-02-12T05:41:55Z")

</div>

I am trying to fetch the list of index names matching an index prefix (for example: abc-2024-02\*) GetIndexRequest request = new GetIndexRequest.Builder().index("abc-2024-02\*").allowNoIndices(false).expandWildcards(Expan…

---

## [Canvas table to have a count](https://discuss.elastic.co/t/canvas-table-to-have-a-count/353028)

<div class="topic-metadata">

**Author:** [@encathal](https://discuss.elastic.co/u/encathal)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 3:18am UTC](https://discuss.elastic.co/t/canvas-table-to-have-a-count/353028 "2024-02-12T03:18:29Z")

</div>

Hi, I have a question how can I turn my fields.userinfo.Email.Keywords into a count column. I tried a few ways and I keep getting errors. Thanks

---

## [Kibana CPU Load](https://discuss.elastic.co/t/kibana-cpu-load/353030)

<div class="topic-metadata">

**Author:** [@zsnops](https://discuss.elastic.co/u/zsnops)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 1:49am UTC](https://discuss.elastic.co/t/kibana-cpu-load/353030 "2024-02-12T01:49:35Z")

</div>

Hi, I am running a small single ELK instance just for visualizing some logs. Because the process consumes around 12 % CPU when idle, I have tried to deactivate a few things in kibana.yml: telemetry.enabled: false xpac…

---

## [Ingest Pipeline Creating Grok Pattern with string as dependency](https://discuss.elastic.co/t/ingest-pipeline-creating-grok-pattern-with-string-as-dependency/353014)

<div class="topic-metadata">

**Author:** [@pupit](https://discuss.elastic.co/u/pupit)\
**Replies:** 1\
**Last updated:** [February 11, 2024, 10:57pm UTC](https://discuss.elastic.co/t/ingest-pipeline-creating-grok-pattern-with-string-as-dependency/353014 "2024-02-11T22:57:36Z")

</div>

Hi, I am exploring ingest pipeline. The grok is working as expected. But, I am looking into just executing/running the grok pattern if the field have a certain string. How can I add a if condition where "if message =~…

---

## [Jar hell issue during loading custom plugin in elastic 8.4.1](https://discuss.elastic.co/t/jar-hell-issue-during-loading-custom-plugin-in-elastic-8-4-1/353016)

<div class="topic-metadata">

**Author:** [@msubbu](https://discuss.elastic.co/u/msubbu)\
**Replies:** 1\
**Last updated:** [February 11, 2024, 4:00pm UTC](https://discuss.elastic.co/t/jar-hell-issue-during-loading-custom-plugin-in-elastic-8-4-1/353016 "2024-02-11T16:00:31Z")

</div>

Hello Team, we are facing below while loading one of our custom plugin into Elasticsearch 8.4.1. Kindly need your valuable inputs on below issue.. Exception in thread "main" java.lang.IllegalStateException: failed to lo…

---

## [Unable to drop fields in filebeat using drop\_field](https://discuss.elastic.co/t/unable-to-drop-fields-in-filebeat-using-drop-field/352978)

<div class="topic-metadata">

**Author:** [@vyjayanth](https://discuss.elastic.co/u/vyjayanth)\
**Replies:** 11\
**Last updated:** [February 11, 2024, 1:56pm UTC](https://discuss.elastic.co/t/unable-to-drop-fields-in-filebeat-using-drop-field/352978 "2024-02-11T13:56:22Z")

</div>

Looking to drop a field called: Event.Original using drop\_field. As Message Field produces same information as Event.Original. I worked with remove\_field of logstash filter, but it isn’t reflecting by dropping the field…

---

## [XML into JSON value](https://discuss.elastic.co/t/xml-into-json-value/352933)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 5\
**Last updated:** [February 11, 2024, 8:09am UTC](https://discuss.elastic.co/t/xml-into-json-value/352933 "2024-02-11T08:09:09Z")

</div>

Hey, If i have a Json message, into has an element "error" : "\<?xml version=\\"1.0\\" encoding=\\"UTF-8\\"?\> zefzefzfzef " how can extract and parse XML for create a sub-doc with all element xml example : "json" : "value…

---

## [Elasticsearch High CPU usage](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage/352998)

<div class="topic-metadata">

**Author:** [@kkkk7](https://discuss.elastic.co/u/kkkk7)\
**Replies:** 2\
**Last updated:** [February 11, 2024, 2:54am UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage/352998 "2024-02-11T02:54:59Z")

</div>

Hello I'm using version 7.3.2 (this is a project since 2019 so a bit old version) After a years pass by my elastic stack CPU usage very high so we decide extends the CPU core but seem like the usage will growth bigger …

---

## [Metricbeat can't connect to Oracle 10g database](https://discuss.elastic.co/t/metricbeat-cant-connect-to-oracle-10g-database/352931)

<div class="topic-metadata">

**Author:** [@gurbelunder](https://discuss.elastic.co/u/gurbelunder)\
**Replies:** 8\
**Last updated:** [February 10, 2024, 5:11pm UTC](https://discuss.elastic.co/t/metricbeat-cant-connect-to-oracle-10g-database/352931 "2024-02-10T17:11:55Z")

</div>

Hi community, I'm trying to configure metricbeat on a Windows Server 2008 R2 server for 3 oracle 10.2.0.5 databases. I know both is not newest, but customer uses this still and of course these databases are important a…

---

## [Getting the "Can't apply \[synonyms\_set\]! Loading synonyms from index is supported only for search time synonyms!" error when creating index](https://discuss.elastic.co/t/getting-the-cant-apply-synonyms-set-loading-synonyms-from-index-is-supported-only-for-search-time-synonyms-error-when-creating-index/352990)

<div class="topic-metadata">

**Author:** [@Hatef\_Alipour](https://discuss.elastic.co/u/Hatef_Alipour)\
**Replies:** 2\
**Last updated:** [February 10, 2024, 12:11pm UTC](https://discuss.elastic.co/t/getting-the-cant-apply-synonyms-set-loading-synonyms-from-index-is-supported-only-for-search-time-synonyms-error-when-creating-index/352990 "2024-02-10T12:11:58Z")

</div>

We have an index in Elasticsearch 7.17, It uses synonym files you can see the full structure below: { "my-index" : { "settings" : { "index" : { "routing" : { "allocation" : { "i…

---

## [Does plugin logstash-input-kinesis support Amazon Kinesis EFO(enhanced fan-out)?](https://discuss.elastic.co/t/does-plugin-logstash-input-kinesis-support-amazon-kinesis-efo-enhanced-fan-out/352988)

<div class="topic-metadata">

**Author:** [@ilove2git](https://discuss.elastic.co/u/ilove2git)\
**Replies:** 0\
**Last updated:** [February 10, 2024, 7:42am UTC](https://discuss.elastic.co/t/does-plugin-logstash-input-kinesis-support-amazon-kinesis-efo-enhanced-fan-out/352988 "2024-02-10T07:42:03Z")

</div>

Hi, I notice that this plugin logstash-input-kinesis \[Kinesis input plugin | Logstash Reference \[8.12\] | Elastic\] supports to receive events through \[AWS Kinesis\]http://docs.aws.amazon.com/kinesis/latest/dev/introductio…

---

## [Super user elastic can't run as regular user](https://discuss.elastic.co/t/super-user-elastic-cant-run-as-regular-user/352974)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 10:02pm UTC](https://discuss.elastic.co/t/super-user-elastic-cant-run-as-regular-user/352974 "2024-02-09T22:02:15Z")

</div>

Shouldn't elastic user be able to run\_as anyone? I have a proxy in front of Kibana and in the past I could set it to run as a user I would use the elastic user to authenticate and then run as someone else. Now it's sa…

---

## [Filebeat: failed to parse rx\_queue: strconv.ParseInt: parsing "0000AC00": invalid syntax](https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 10:01pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893 "2024-02-09T22:01:31Z")

</div>

Hi, I'm using the UDP input in filebeat for collecting logs, and I'm seeing it periodically errors like this: 2024-02-08T12:48:19.399-0700 WARN \[input.udp\] map\[file.line:251 file.name:udp/input.go function:github.com/e…

---

## [How to automate query from trained ML model](https://discuss.elastic.co/t/how-to-automate-query-from-trained-ml-model/352956)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 8:49pm UTC](https://discuss.elastic.co/t/how-to-automate-query-from-trained-ml-model/352956 "2024-02-09T20:49:56Z")

</div>

Hi, we have added a custom model among the machine learning models. During testing, we obtain, as a result, a vector that we use in the following query: GET indexname/\_search { "query": { "script\_score": { …

---

## [Search and Pagination in .Net](https://discuss.elastic.co/t/search-and-pagination-in-net/352973)

<div class="topic-metadata">

**Author:** [@eric.paul](https://discuss.elastic.co/u/eric.paul)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 7:42pm UTC](https://discuss.elastic.co/t/search-and-pagination-in-net/352973 "2024-02-09T19:42:26Z")

</div>

I am looking for an example of how to use search\_after for pagination using the elastic.client in c#. I can see where the method is and that it takes a type of ICollection\<FieldValue\>? but I do not know how to get this f…

---

## [Filebeat -\> Elasticsearch ingestion: Document loss](https://discuss.elastic.co/t/filebeat-elasticsearch-ingestion-document-loss/352952)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 7\
**Last updated:** [February 9, 2024, 7:24pm UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-ingestion-document-loss/352952 "2024-02-09T19:24:34Z")

</div>

Hello, We are having some problems with document loss when ingesting data into Elasticsearch using Filebeat. I'll describe our approach to data ingest. We are running a process. This process generates some data that we…

---

## [Filebeat Client talking to googleusercontent](https://discuss.elastic.co/t/filebeat-client-talking-to-googleusercontent/352951)

<div class="topic-metadata">

**Author:** [@drops](https://discuss.elastic.co/u/drops)\
**Replies:** 2\
**Last updated:** [February 9, 2024, 4:40pm UTC](https://discuss.elastic.co/t/filebeat-client-talking-to-googleusercontent/352951 "2024-02-09T16:40:29Z")

</div>

Hi there, I just noticed that the filebeat agents installed on the clients are talking quite frequently to 34.111.17.235 (235.17.111.34.bc.googleusercontent.com). Is it possible to configure the agents not to do that wi…

---

## [Kibana not optimizing custom plugins](https://discuss.elastic.co/t/kibana-not-optimizing-custom-plugins/352939)

<div class="topic-metadata">

**Author:** [@ssimmons](https://discuss.elastic.co/u/ssimmons)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 4:21pm UTC](https://discuss.elastic.co/t/kibana-not-optimizing-custom-plugins/352939 "2024-02-09T16:21:10Z")

</div>

I'm trying to move our custom plugins from Kibana 8.6 to 8.12. On version 8.6, I can run yarn knb bootstrap and then yarn start. This would run the optimizer on my custom plugins and then do a hot reload of Kibana when …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=308)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=310)
