# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=313

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 314

---

## [Rabbitmq output plugin](https://discuss.elastic.co/t/rabbitmq-output-plugin/352639)

<div class="topic-metadata">

**Author:** [@milousel](https://discuss.elastic.co/u/milousel)\
**Replies:** 2\
**Last updated:** [February 6, 2024, 7:07pm UTC](https://discuss.elastic.co/t/rabbitmq-output-plugin/352639 "2024-02-06T19:07:39Z")

</div>

Hello, I want to send data from elasticsearch via logstash to rabbitMQ. All components are in separately docker containers. I am new in ELK, so can you tell me what I doing wrong? Logstash.conf input { stdin {…

---

## [Snapshot is deleted automatically once I stop the docker container](https://discuss.elastic.co/t/snapshot-is-deleted-automatically-once-i-stop-the-docker-container/352603)

<div class="topic-metadata">

**Author:** [@susnato](https://discuss.elastic.co/u/susnato)\
**Replies:** 4\
**Last updated:** [February 6, 2024, 5:30pm UTC](https://discuss.elastic.co/t/snapshot-is-deleted-automatically-once-i-stop-the-docker-container/352603 "2024-02-06T17:30:32Z")

</div>

(Hi, I am totally new to Elastic search, so sorry if this is very basic question.) I had an Elasticsearch store running in background using docker. I had used haystack to add some files and embeddings to it. Then I…

---

## [Trying to use a wildcard to filter the Kibana output](https://discuss.elastic.co/t/trying-to-use-a-wildcard-to-filter-the-kibana-output/351921)

<div class="topic-metadata">

**Author:** [@Henriette](https://discuss.elastic.co/u/Henriette)\
**Replies:** 8\
**Last updated:** [February 6, 2024, 3:29pm UTC](https://discuss.elastic.co/t/trying-to-use-a-wildcard-to-filter-the-kibana-output/351921 "2024-02-06T15:29:26Z")

</div>

Hey all - I'm new to Kibana/Elasticsearch, and I'm using it to get the number of views for my blog pages. I'm only interested in views of actual pages, not all the things the bots are hitting.' so i've excluded a number…

---

## [CONNECT to remote clusters](https://discuss.elastic.co/t/connect-to-remote-clusters/352647)

<div class="topic-metadata">

**Author:** [@Nathan\_Nieselpriem](https://discuss.elastic.co/u/Nathan_Nieselpriem)\
**Replies:** 0\
**Last updated:** [February 6, 2024, 3:20pm UTC](https://discuss.elastic.co/t/connect-to-remote-clusters/352647 "2024-02-06T15:20:39Z")

</div>

Hi fellows, I need your help so bad. I am running 2 elasticsearch cluster as docker container http port 9200 transport port 9300 But when I try to configure the remote cluster like that: name docker-cluster seed no…

---

## [\_csvparsing failure in logstash with delimeters](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 5\
**Last updated:** [February 6, 2024, 2:51pm UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499 "2024-02-06T14:51:57Z")

</div>

Hi all, i am testing a logstash pipelines with the csv data which have approx 20 headers but i am trying with the 3 fields and csv delimeter tab is giving me parsing failures . i also tried with the quote\_char but it is…

---

## [Is there a limit on disk size for single ES node?](https://discuss.elastic.co/t/is-there-a-limit-on-disk-size-for-single-es-node/352635)

<div class="topic-metadata">

**Author:** [@umuteyilmaz](https://discuss.elastic.co/u/umuteyilmaz)\
**Replies:** 1\
**Last updated:** [February 6, 2024, 2:04pm UTC](https://discuss.elastic.co/t/is-there-a-limit-on-disk-size-for-single-es-node/352635 "2024-02-06T14:04:29Z")

</div>

Is there a limit on disk size for single ES node? We have 900 GB storage size on ES node, we want to extend to 2 TB, Will I encounter any problems?

---

## [File beat Multiline issue for node.js error](https://discuss.elastic.co/t/file-beat-multiline-issue-for-node-js-error/352219)

<div class="topic-metadata">

**Author:** [@apsh](https://discuss.elastic.co/u/apsh)\
**Replies:** 1\
**Last updated:** [February 6, 2024, 12:51pm UTC](https://discuss.elastic.co/t/file-beat-multiline-issue-for-node-js-error/352219 "2024-02-06T12:51:47Z")

</div>

Continuing the discussion from File beat Multiline issue: I am reshare this issue as it is still continue to have

---

## [Ubuntu VMware logserver + Fortigate 30E firewall](https://discuss.elastic.co/t/ubuntu-vmware-logserver-fortigate-30e-firewall/352537)

<div class="topic-metadata">

**Author:** [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Replies:** 3\
**Last updated:** [February 6, 2024, 12:46pm UTC](https://discuss.elastic.co/t/ubuntu-vmware-logserver-fortigate-30e-firewall/352537 "2024-02-06T12:46:33Z")

</div>

Hi, I need a bit of help from those wiser. I've built a virtual machine log server that runs on Ubuntu. The log server has an ELK stack installed through which logs from other virtual machines (normal Ubuntu and Windows…

---

## [Example usage of GetSourceRequest](https://discuss.elastic.co/t/example-usage-of-getsourcerequest/351923)

<div class="topic-metadata">

**Author:** [@Tony\_Clarke](https://discuss.elastic.co/u/Tony_Clarke)\
**Replies:** 4\
**Last updated:** [February 6, 2024, 12:39pm UTC](https://discuss.elastic.co/t/example-usage-of-getsourcerequest/351923 "2024-02-06T12:39:37Z")

</div>

Trying to use ElasticsearchClient to get the source of a document. No problem getting the document but when I use GetSourceRequest as below it results in an error during deserialization. I couldn't find any unit tests or…

---

## [Where i can i get the implementation examples of java api client with elasticsearch for all type of query request and responses](https://discuss.elastic.co/t/where-i-can-i-get-the-implementation-examples-of-java-api-client-with-elasticsearch-for-all-type-of-query-request-and-responses/352625)

<div class="topic-metadata">

**Author:** [@Krishna\_Sailesh](https://discuss.elastic.co/u/Krishna_Sailesh)\
**Replies:** 1\
**Last updated:** [February 6, 2024, 12:23pm UTC](https://discuss.elastic.co/t/where-i-can-i-get-the-implementation-examples-of-java-api-client-with-elasticsearch-for-all-type-of-query-request-and-responses/352625 "2024-02-06T12:23:54Z")

</div>

Hi Team I am revamping the HLRC code with a Java Api Client package. there is a lot of syntax changes in the Java Api Client package. where can I get the all package docs and examples for connecting to elasticsearch in …

---

## [Is the nodes load a criteria for shard allocation?](https://discuss.elastic.co/t/is-the-nodes-load-a-criteria-for-shard-allocation/352170)

<div class="topic-metadata">

**Author:** [@voharunado](https://discuss.elastic.co/u/voharunado)\
**Replies:** 17\
**Last updated:** [February 6, 2024, 12:06pm UTC](https://discuss.elastic.co/t/is-the-nodes-load-a-criteria-for-shard-allocation/352170 "2024-02-06T12:06:38Z")

</div>

Hi, I would like to know if Elasticsearch is taking the load of the nodes to decide how to reballance shards? I have seen cluster.routing.allocation.balance.write\_load in the documentation, but I'm not sure how that wor…

---

## [UpdateRequest with JSON in JavaAPIClient getting parsing error](https://discuss.elastic.co/t/updaterequest-with-json-in-javaapiclient-getting-parsing-error/352533)

<div class="topic-metadata">

**Author:** [@Krishna\_Sailesh](https://discuss.elastic.co/u/Krishna_Sailesh)\
**Replies:** 4\
**Last updated:** [February 6, 2024, 12:02pm UTC](https://discuss.elastic.co/t/updaterequest-with-json-in-javaapiclient-getting-parsing-error/352533 "2024-02-06T12:02:04Z")

</div>

I am trying to update the existing record with Java API client but getting the below issue. index record json { "docId": "1", "id": 1, "name": "aegon", "details": { "id":1234 } } // update json Str…

---

## [Problems setting up documents using geo\_point](https://discuss.elastic.co/t/problems-setting-up-documents-using-geo-point/352618)

<div class="topic-metadata">

**Author:** [@Dennis\_Christensen](https://discuss.elastic.co/u/Dennis_Christensen)\
**Replies:** 4\
**Last updated:** [February 6, 2024, 11:54am UTC](https://discuss.elastic.co/t/problems-setting-up-documents-using-geo-point/352618 "2024-02-06T11:54:58Z")

</div>

I am using C# Nest version 8, and have an Index of hotels with GeoLocation. My document have the following property: public GeoCoordinate geoCoordinate { get; set; } When I try to do a geo search I end up with an empt…

---

## [Exact match Query: ex: When I am trying to search for marble flooring the following matches should be fetched](https://discuss.elastic.co/t/exact-match-query-ex-when-i-am-trying-to-search-for-marble-flooring-the-following-matches-should-be-fetched/352589)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 9\
**Last updated:** [February 6, 2024, 11:54am UTC](https://discuss.elastic.co/t/exact-match-query-ex-when-i-am-trying-to-search-for-marble-flooring-the-following-matches-should-be-fetched/352589 "2024-02-06T11:54:39Z")

</div>

When I am trying to search for marble flooring the following matches should be fetched marble flooring marbles flooring flooring marble flooring marbles marble floor marbles floor marble marbles flooring floor { "si…

---

## [Metricbeat built-in tomcat dashboard that is a bug?](https://discuss.elastic.co/t/metricbeat-built-in-tomcat-dashboard-that-is-a-bug/352502)

<div class="topic-metadata">

**Author:** [@ljh](https://discuss.elastic.co/u/ljh)\
**Replies:** 4\
**Last updated:** [February 6, 2024, 10:21am UTC](https://discuss.elastic.co/t/metricbeat-built-in-tomcat-dashboard-that-is-a-bug/352502 "2024-02-06T10:21:04Z")

</div>

in bytes'sent visualize , title receive but field is sent,is a bug or have a reason?

---

## [Keyword Array Field Removes Duplicates in Queries](https://discuss.elastic.co/t/keyword-array-field-removes-duplicates-in-queries/352582)

<div class="topic-metadata">

**Author:** [@aeroplane380](https://discuss.elastic.co/u/aeroplane380)\
**Replies:** 2\
**Last updated:** [February 6, 2024, 9:52am UTC](https://discuss.elastic.co/t/keyword-array-field-removes-duplicates-in-queries/352582 "2024-02-06T09:52:24Z")

</div>

This post relates to a problem I have encountered in my business production database, but will be described with a minimal reproducible example. I have an index with the following mapping: { "properties": { "test…

---

## [Indexing rate became very low in elastic cluster](https://discuss.elastic.co/t/indexing-rate-became-very-low-in-elastic-cluster/352377)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 14\
**Last updated:** [February 6, 2024, 9:38am UTC](https://discuss.elastic.co/t/indexing-rate-became-very-low-in-elastic-cluster/352377 "2024-02-06T09:38:42Z")

</div>

Hi sir. @stephenb The indexing rate of our cluster become very low and even search results are getting delayed. cluster details: 3 Master nodes - cpu 4 cores -RAM 16GB 4 Data nodes (out of 4 one node is given both ing…

---

## [Kibana URL is not loading](https://discuss.elastic.co/t/kibana-url-is-not-loading/352074)

<div class="topic-metadata">

**Author:** [@Subhs](https://discuss.elastic.co/u/Subhs)\
**Replies:** 5\
**Last updated:** [February 6, 2024, 9:31am UTC](https://discuss.elastic.co/t/kibana-url-is-not-loading/352074 "2024-02-06T09:31:59Z")

</div>

Kibana URL is not loading for me. URL I am trying to access is localhost:5601. When I start Kibana in the back-end (putty session) I can see Kibana is running in the logs.

---

## [Unable connect to Elasticsearch from another machine](https://discuss.elastic.co/t/unable-connect-to-elasticsearch-from-another-machine/352204)

<div class="topic-metadata">

**Author:** [@MinaYousry](https://discuss.elastic.co/u/MinaYousry)\
**Replies:** 1\
**Last updated:** [February 6, 2024, 9:30am UTC](https://discuss.elastic.co/t/unable-connect-to-elasticsearch-from-another-machine/352204 "2024-02-06T09:30:02Z")

</div>

I installed Elasticsearch on one machine and my application, developed with Spring Boot, on another machine. When I try to connect, I face a connection refused error. However, when I run the command : curl http://server…

---

## [How to pass specific characters password to ElasticSearch through Sulu/ArticleBundle](https://discuss.elastic.co/t/how-to-pass-specific-characters-password-to-elasticsearch-through-sulu-articlebundle/352544)

<div class="topic-metadata">

**Author:** [@Agdi](https://discuss.elastic.co/u/Agdi)\
**Replies:** 6\
**Last updated:** [February 6, 2024, 9:24am UTC](https://discuss.elastic.co/t/how-to-pass-specific-characters-password-to-elasticsearch-through-sulu-articlebundle/352544 "2024-02-06T09:24:18Z")

</div>

Elasticsearch Version 6.8.0 Installed Plugins Sulu - SuluArticle/Bundle Java Version bundled OS Version Ubuntu 20.04 Problem Description I'm working on a project using Sulu 2.4.15 - php 8.2 - Symfony 5.5 - Sulu/Artic…

---

## [Upgrading cluster and its monitoring cluster](https://discuss.elastic.co/t/upgrading-cluster-and-its-monitoring-cluster/352608)

<div class="topic-metadata">

**Author:** [@Gerardo\_Zenobi](https://discuss.elastic.co/u/Gerardo_Zenobi)\
**Replies:** 2\
**Last updated:** [February 6, 2024, 8:48am UTC](https://discuss.elastic.co/t/upgrading-cluster-and-its-monitoring-cluster/352608 "2024-02-06T08:48:59Z")

</div>

Hi there, When I set up my separate monitoring cluster for my production cluster, I did it in the same version 8.8.2 as the production one. Now I want to upgrade the production cluster version to 8.12. How should I pr…

---

## [After ES7.5 why "WHERE isn't (yet) compatible with scalar functions on nested fields"](https://discuss.elastic.co/t/after-es7-5-why-where-isnt-yet-compatible-with-scalar-functions-on-nested-fields/352611)

<div class="topic-metadata">

**Author:** [@muhao1020](https://discuss.elastic.co/u/muhao1020)\
**Replies:** 0\
**Last updated:** [February 6, 2024, 8:48am UTC](https://discuss.elastic.co/t/after-es7-5-why-where-isnt-yet-compatible-with-scalar-functions-on-nested-fields/352611 "2024-02-06T08:48:12Z")

</div>

ref : SQL Limitations | Elasticsearch Guide \[7.10\] | Elastic why above limit occurded?

---

## [Cannot add node to ELK cluster 8. ( redhat - rpm package)](https://discuss.elastic.co/t/cannot-add-node-to-elk-cluster-8-redhat-rpm-package/352609)

<div class="topic-metadata">

**Author:** [@duong\_pham](https://discuss.elastic.co/u/duong_pham)\
**Replies:** 0\
**Last updated:** [February 6, 2024, 8:34am UTC](https://discuss.elastic.co/t/cannot-add-node-to-elk-cluster-8-redhat-rpm-package/352609 "2024-02-06T08:34:24Z")

</div>

Hi all, I am new with ELK I follow the guide on internet to install ELK cluster 8. on redhat 7 by rpm package ( 3 nodes) But i met this error \[root@elk02 elasticsearch\]# /usr/share/elasticsearch/bin/elasticsearch-rec…

---

## [Logstash Email Output Plugin not using environmental variables](https://discuss.elastic.co/t/logstash-email-output-plugin-not-using-environmental-variables/352579)

<div class="topic-metadata">

**Author:** [@mattk202](https://discuss.elastic.co/u/mattk202)\
**Replies:** 2\
**Last updated:** [February 6, 2024, 2:07am UTC](https://discuss.elastic.co/t/logstash-email-output-plugin-not-using-environmental-variables/352579 "2024-02-06T02:07:14Z")

</div>

Hi All, I'm very new to Elastic and Logstash and am having some issues outputting environmental variables to my email output plugin. I have installed my stack through Selks (Suricata, Logstash, evebox etc etc) and all …

---

## [How to run curl and hide the username's password from command?](https://discuss.elastic.co/t/how-to-run-curl-and-hide-the-usernames-password-from-command/352567)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 3\
**Last updated:** [February 5, 2024, 11:57pm UTC](https://discuss.elastic.co/t/how-to-run-curl-and-hide-the-usernames-password-from-command/352567 "2024-02-05T23:57:34Z")

</div>

How to run curl and hide the username's password from command?

---

## [Export and import dashboard](https://discuss.elastic.co/t/export-and-import-dashboard/352445)

<div class="topic-metadata">

**Author:** [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 10:58pm UTC](https://discuss.elastic.co/t/export-and-import-dashboard/352445 "2024-02-05T22:58:35Z")

</div>

Hi, I need to export three dashboards from cluster-A (on-prem v8.10.4) and import into cluster-B (cloud v8.11.1). What is the best way to do this? Although they're listed on "Saved Objects", I can't find a way to do th…

---

## [Removing empty fields from an event (2024 edition!)](https://discuss.elastic.co/t/removing-empty-fields-from-an-event-2024-edition/352571)

<div class="topic-metadata">

**Author:** [@Supermathie](https://discuss.elastic.co/u/Supermathie)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 9:55pm UTC](https://discuss.elastic.co/t/removing-empty-fields-from-an-event-2024-edition/352571 "2024-02-05T21:55:15Z")

</div>

Continuing the discussion from Never ending story: how to check and remove empty fields, arrays etc: There's no simple way to (recursively) get all field names in an event, but one can do this: filter { ruby { …

---

## [How to get count of specific value in elasticsearch java clinet](https://discuss.elastic.co/t/how-to-get-count-of-specific-value-in-elasticsearch-java-clinet/352465)

<div class="topic-metadata">

**Author:** [@Abdalrazag\_Al-Shrufa](https://discuss.elastic.co/u/Abdalrazag_Al-Shrufa)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 9:43pm UTC](https://discuss.elastic.co/t/how-to-get-count-of-specific-value-in-elasticsearch-java-clinet/352465 "2024-02-05T21:43:49Z")

</div>

I am using elasticsearch-java 8.12, and I want to get the count of specific value, in my example I have log index, and there is a field called result, I want to get the number of documents that the result field is "corr…

---

## [Integration of FortiGate Firewall with Elasticsearch](https://discuss.elastic.co/t/integration-of-fortigate-firewall-with-elasticsearch/352287)

<div class="topic-metadata">

**Author:** [@Eepe123](https://discuss.elastic.co/u/Eepe123)\
**Replies:** 3\
**Last updated:** [February 5, 2024, 9:06pm UTC](https://discuss.elastic.co/t/integration-of-fortigate-firewall-with-elasticsearch/352287 "2024-02-05T21:06:35Z")

</div>

So im trying to configure fortigate30e sending logs straight to kibana by using this blog post from infrasecuritycode: integration of fortigate firewall with elasticsearch i have a screenshot of a error im getting its s…

---

## [Canvas: Extending Element to continue on Next Page](https://discuss.elastic.co/t/canvas-extending-element-to-continue-on-next-page/351584)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 7:37pm UTC](https://discuss.elastic.co/t/canvas-extending-element-to-continue-on-next-page/351584 "2024-02-05T19:37:58Z")

</div>

Hello, I am pretty new to Canvas, I am able to create a markdown table using Elastic SQL. The query retrieves a limit of 50 results. The report looks great as expected but It can only fit 17 on one page. I was wonderi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=312)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=314)
