# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=319

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 320

---

## [Kibana cannot use elasticsearch normally - Cluster Red](https://discuss.elastic.co/t/kibana-cannot-use-elasticsearch-normally-cluster-red/352149)

<div class="topic-metadata">

**Author:** [@kei\_ru](https://discuss.elastic.co/u/kei_ru)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 8:19am UTC](https://discuss.elastic.co/t/kibana-cannot-use-elasticsearch-normally-cluster-red/352149 "2024-01-31T08:19:24Z")

</div>

Configuration environment: es-7.17.8 kibana-7.17.8 filebeat-7.17.8 (Elasticsearch is a single node, and the data mount point is the efs file system of AWS) Problem Description: I started to find that kibanan was …

---

## [Difference in Shard & Index count during Snapshot & Restore](https://discuss.elastic.co/t/difference-in-shard-index-count-during-snapshot-restore/352154)

<div class="topic-metadata">

**Author:** [@Vadiraj\_Prahalad](https://discuss.elastic.co/u/Vadiraj_Prahalad)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 6:46am UTC](https://discuss.elastic.co/t/difference-in-shard-index-count-during-snapshot-restore/352154 "2024-01-31T06:46:18Z")

</div>

Hello All, We are performing Elastic Upgrade by building parallel cluster for the existing cluster ( due to organization issues ) I have created Snapshot Policy in Source Cluster to run the snapshot at 5:30 PM PST ever…

---

## [Unable to add additional role to elastic instance in elastic cloud](https://discuss.elastic.co/t/unable-to-add-additional-role-to-elastic-instance-in-elastic-cloud/352081)

<div class="topic-metadata">

**Author:** [@RajuParipelly](https://discuss.elastic.co/u/RajuParipelly)\
**Replies:** 7\
**Last updated:** [January 31, 2024, 6:41am UTC](https://discuss.elastic.co/t/unable-to-add-additional-role-to-elastic-instance-in-elastic-cloud/352081 "2024-01-31T06:41:26Z")

</div>

Hello, I was trying to add additional role to the existing elasticsearch instance in the elastic cloud. I added node.roles : \[remote\_cluster\_client\] but while saving it throws the below error, could any one help me wit…

---

## [Not able to run ALTER query through logstash JDBC plugin](https://discuss.elastic.co/t/not-able-to-run-alter-query-through-logstash-jdbc-plugin/352072)

<div class="topic-metadata">

**Author:** [@rpraveenr](https://discuss.elastic.co/u/rpraveenr)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 6:27am UTC](https://discuss.elastic.co/t/not-able-to-run-alter-query-through-logstash-jdbc-plugin/352072 "2024-01-31T06:27:24Z")

</div>

I am not able to run ALTER queries on my Oracle database through Logstash. Below is the snippet from the config file: input { jdbc { jdbc\_validate\_connection =\> true jdbc\_driver\_library =\> "ojdbc7.ja…

---

## [How to disable or enable a document when do knn search](https://discuss.elastic.co/t/how-to-disable-or-enable-a-document-when-do-knn-search/351677)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 2:19am UTC](https://discuss.elastic.co/t/how-to-disable-or-enable-a-document-when-do-knn-search/351677 "2024-01-31T02:19:04Z")

</div>

Hello, in my index, there are certain documents that I want to disable or hide during a k-nearest neighbors (KNN) search. However, there may be situations where I need to enable or reveal these documents. How can I do th…

---

## [Vertical Data Tables](https://discuss.elastic.co/t/vertical-data-tables/351895)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 11:56pm UTC](https://discuss.elastic.co/t/vertical-data-tables/351895 "2024-01-30T23:56:28Z")

</div>

Hello, Currently, we can create data tables (horizontal) via Lens. Will it be possible to create a vertical data table in the future? Example:

---

## [GEOIP Database Update Issue: Documentation Followed, Databases Not Updating on Ingest Nodes](https://discuss.elastic.co/t/geoip-database-update-issue-documentation-followed-databases-not-updating-on-ingest-nodes/351303)

<div class="topic-metadata">

**Author:** [@Zabulon](https://discuss.elastic.co/u/Zabulon)\
**Replies:** 18\
**Last updated:** [January 30, 2024, 11:19pm UTC](https://discuss.elastic.co/t/geoip-database-update-issue-documentation-followed-databases-not-updating-on-ingest-nodes/351303 "2024-01-30T23:19:48Z")

</div>

Summary: I followed the steps outlined in the section "Use a custom endpoint" of the documentation, but I encountered some unexpected behavior. The GEOIP databases are not updating on Elasticsearch ingest nodes. I'm not …

---

## ["\_dateparsefailure" When trying to overwrite @timestamp field](https://discuss.elastic.co/t/dateparsefailure-when-trying-to-overwrite-timestamp-field/352129)

<div class="topic-metadata">

**Author:** [@rmoss25](https://discuss.elastic.co/u/rmoss25)\
**Replies:** 7\
**Last updated:** [January 30, 2024, 10:10pm UTC](https://discuss.elastic.co/t/dateparsefailure-when-trying-to-overwrite-timestamp-field/352129 "2024-01-30T22:10:18Z")

</div>

Hi, I am trying to solve this issue but don't seem to be having much luck. My log is as follows: 01-JAN-24 00:00:50|1.1.1.1|1|CN=test\_user,OU=test Users,OU=test,OU=Business,DC=test,DC=corp,DC=abc,DC=ca|Z/dtEse7dwP2VEV…

---

## [Synthetics | failed to verify certificate: x509](https://discuss.elastic.co/t/synthetics-failed-to-verify-certificate-x509/351826)

<div class="topic-metadata">

**Author:** [@Aldair\_Barrios](https://discuss.elastic.co/u/Aldair_Barrios)\
**Replies:** 3\
**Last updated:** [January 30, 2024, 9:08pm UTC](https://discuss.elastic.co/t/synthetics-failed-to-verify-certificate-x509/351826 "2024-01-30T21:08:19Z")

</div>

Hello, everyone! I've been trying for a few weeks to use Elasticsearch synthetic monitors. I'm following the documentation Run Elastic Agent in a container | Fleet and Elastic Agent Guide \[8.11\] | Elastic to install the…

---

## [Does ElasticSearch support dampening synonyms?](https://discuss.elastic.co/t/does-elasticsearch-support-dampening-synonyms/352138)

<div class="topic-metadata">

**Author:** [@William\_Ades](https://discuss.elastic.co/u/William_Ades)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 8:40pm UTC](https://discuss.elastic.co/t/does-elasticsearch-support-dampening-synonyms/352138 "2024-01-30T20:40:33Z")

</div>

Our project is currently using Elasticsearch synonyms and we want to dampen the scores returned by matched synonyms. In other words, we want matches to keywords provided in a search query to score higher than matches to …

---

## [Aggregate by time only](https://discuss.elastic.co/t/aggregate-by-time-only/351063)

<div class="topic-metadata">

**Author:** [@Maiky](https://discuss.elastic.co/u/Maiky)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 8:27pm UTC](https://discuss.elastic.co/t/aggregate-by-time-only/351063 "2024-01-30T20:27:49Z")

</div>

I would like to do a count of the amount of log entries over a certain time window, let's say one hour buckets. So log entries from monday 3-4pm should be counted with those from tuesday 3-4pm etc. I have a timestamp fi…

---

## [Logstash Filter If loop](https://discuss.elastic.co/t/logstash-filter-if-loop/352119)

<div class="topic-metadata">

**Author:** [@adityak248](https://discuss.elastic.co/u/adityak248)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 7:50pm UTC](https://discuss.elastic.co/t/logstash-filter-if-loop/352119 "2024-01-30T19:50:53Z")

</div>

Which one is correct: filter { if \[kubernetes\_labels\]\[app\] == "app-name" and \[kubernetes\_container\_name\] == "nginx" { grok { match =\> {"message" =\> 'XXX'}}} else if \[kubernetes\_labels\]\[app\] =…

---

## [Multiple kafka topics using logstash and make index inside output with \`.conf\` file](https://discuss.elastic.co/t/multiple-kafka-topics-using-logstash-and-make-index-inside-output-with-conf-file/352112)

<div class="topic-metadata">

**Author:** [@Tony\_Haf.H](https://discuss.elastic.co/u/Tony_Haf.H)\
**Replies:** 2\
**Last updated:** [January 30, 2024, 6:58pm UTC](https://discuss.elastic.co/t/multiple-kafka-topics-using-logstash-and-make-index-inside-output-with-conf-file/352112 "2024-01-30T18:58:09Z")

</div>

I am using Logstash 8.11, and I have problem like subject title I have consulted a few solutions in other topics, and I still have not solved the problem. Example old topic: How to pull data data from 2 kafka topics us…

---

## [Java API REST Client: Grouping and Counting Results by Multiple Keys](https://discuss.elastic.co/t/java-api-rest-client-grouping-and-counting-results-by-multiple-keys/352004)

<div class="topic-metadata">

**Author:** [@adgam](https://discuss.elastic.co/u/adgam)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 2:47pm UTC](https://discuss.elastic.co/t/java-api-rest-client-grouping-and-counting-results-by-multiple-keys/352004 "2024-01-29T14:47:29Z")

</div>

Hi, I'm working with the base field 'labels' and want to create a search query that groups my results by values for each key. The sample structures include keys like 'application' and 'env.' For instance, I want to grou…

---

## [Kibana error, assumed Required Throughput Per Minute Per Kibana](https://discuss.elastic.co/t/kibana-error-assumed-required-throughput-per-minute-per-kibana/352104)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 5:04pm UTC](https://discuss.elastic.co/t/kibana-error-assumed-required-throughput-per-minute-per-kibana/352104 "2024-01-30T17:04:54Z")

</div>

Hi, Im getting this error from kibana: setting HealthStatus.Error because assumed Required Throughput Per Minute Per Kibana (46.54236111111111) \>= capacityPerMinutePerKibana (18) AND assumedAverageRecurringRequiredThroug…

---

## [Elastic agent can't reroute docs to a different index](https://discuss.elastic.co/t/elastic-agent-cant-reroute-docs-to-a-different-index/351651)

<div class="topic-metadata">

**Author:** [@lizozom](https://discuss.elastic.co/u/lizozom)\
**Replies:** 4\
**Last updated:** [January 30, 2024, 4:41pm UTC](https://discuss.elastic.co/t/elastic-agent-cant-reroute-docs-to-a-different-index/351651 "2024-01-30T16:41:04Z")

</div>

I have fleet agents with a custom logs. I want to route some of the logs to a different index. I created the index task-logs and in the integration, I defined an reroute ingest pipeline. However,the documents don't rea…

---

## [How to force null values with SpringBoot?](https://discuss.elastic.co/t/how-to-force-null-values-with-springboot/352096)

<div class="topic-metadata">

**Author:** [@Bernard\_Le\_Menuet](https://discuss.elastic.co/u/Bernard_Le_Menuet)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 2:20pm UTC](https://discuss.elastic.co/t/how-to-force-null-values-with-springboot/352096 "2024-01-30T14:20:31Z")

</div>

Hello I have a working API saving some null values in Elasticsearch. I need to keep that behaviour for existong consumers. In order to do that with Spring Boot, I am using storeNullValue attribute on spring-data-elast…

---

## [Force cluster to elect new master node](https://discuss.elastic.co/t/force-cluster-to-elect-new-master-node/352094)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 3\
**Last updated:** [January 30, 2024, 2:14pm UTC](https://discuss.elastic.co/t/force-cluster-to-elect-new-master-node/352094 "2024-01-30T14:14:49Z")

</div>

I added a master-only node to my cluster. How do I trigger the active master role to the new node? I want to leave at least 2 of my data nodes as eligible masters, but have my cluster prioritize use of the dedicated ma…

---

## [Can I use filebeat to send its own logs to Elasticsearch?](https://discuss.elastic.co/t/can-i-use-filebeat-to-send-its-own-logs-to-elasticsearch/352090)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 1:09pm UTC](https://discuss.elastic.co/t/can-i-use-filebeat-to-send-its-own-logs-to-elasticsearch/352090 "2024-01-30T13:09:17Z")

</div>

Now I'm using -e to start filebeat. But I'm going to collect logs in the files, can I config filebeat to send its own logs to Elasticsearch?

---

## [Fleet Agent Upgrade](https://discuss.elastic.co/t/fleet-agent-upgrade/351053)

<div class="topic-metadata">

**Author:** [@Alphayeeeet](https://discuss.elastic.co/u/Alphayeeeet)\
**Replies:** 8\
**Last updated:** [January 30, 2024, 12:11pm UTC](https://discuss.elastic.co/t/fleet-agent-upgrade/351053 "2024-01-30T12:11:31Z")

</div>

When using Fleet to upgrade the Elastic Agent, Kibana and Elasticsearch needed to bu upgraded first, before the Agent Upgrade becomes available according to the docs. If I upgrade Kibana/Elasticsearch from 8.11.1 to 8.1…

---

## [Elasticsearch with firefunctions](https://discuss.elastic.co/t/elasticsearch-with-firefunctions/352086)

<div class="topic-metadata">

**Author:** [@Saidani\_Aziz](https://discuss.elastic.co/u/Saidani_Aziz)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 12:44pm UTC](https://discuss.elastic.co/t/elasticsearch-with-firefunctions/352086 "2024-01-30T12:44:17Z")

</div>

hello please i'm looking for an exemple on how to create 3 fire functions that allows to save and update and search in the elasticsearch.i'm not sure if i'm asking the right question but i hope you understand my desire …

---

## [Timings shown in Dev Console](https://discuss.elastic.co/t/timings-shown-in-dev-console/351530)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [January 30, 2024, 11:49am UTC](https://discuss.elastic.co/t/timings-shown-in-dev-console/351530 "2024-01-30T11:49:11Z")

</div>

Hi Team, We had query on time returned (right hand corner in dev tools console)while querying the index value via GET rest API commands. If I had index having 1M records and while trying to fetch all records so time sh…

---

## [How to define a proper grok pattern for php error logs](https://discuss.elastic.co/t/how-to-define-a-proper-grok-pattern-for-php-error-logs/351978)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 8\
**Last updated:** [January 30, 2024, 11:35am UTC](https://discuss.elastic.co/t/how-to-define-a-proper-grok-pattern-for-php-error-logs/351978 "2024-01-30T11:35:14Z")

</div>

Hello, I'm creating a connection for elasticsearch and want to upload PHP error logs by creating a script using logstash PHP error logs format-- \[16-Jan-2024 13:39:08 Asia/Calcutta\] PHP Warning: Module 'mcrypt' alrea…

---

## [Kibana role privileges in upgrade 7.15.2 to 7.17.10](https://discuss.elastic.co/t/kibana-role-privileges-in-upgrade-7-15-2-to-7-17-10/350589)

<div class="topic-metadata">

**Author:** [@rcopping](https://discuss.elastic.co/u/rcopping)\
**Replies:** 4\
**Last updated:** [January 30, 2024, 11:14am UTC](https://discuss.elastic.co/t/kibana-role-privileges-in-upgrade-7-15-2-to-7-17-10/350589 "2024-01-30T11:14:59Z")

</div>

Hi Team, We have recently upgrade from 7.15.2 to 7.17.10 and it appears the privileges hierarchy has changed . We used to use the following for a dashboard role to manage dashboard editing in kibana and this had runtim…

---

## [RHEL6 MetricBeat Service Start Issues](https://discuss.elastic.co/t/rhel6-metricbeat-service-start-issues/352077)

<div class="topic-metadata">

**Author:** [@sajmeister](https://discuss.elastic.co/u/sajmeister)\
**Replies:** 4\
**Last updated:** [January 30, 2024, 10:58am UTC](https://discuss.elastic.co/t/rhel6-metricbeat-service-start-issues/352077 "2024-01-30T10:58:59Z")

</div>

Hi, We are having issues getting the MetricBeat service to start on RHEL 6 servers. We installed metricbeat-7.17.0-x86\_64.rpm and filebeat-7.17.0-x86\_64.rpm. The FileBeat service starts successfully. However the Metr…

---

## [Unable to parse watcher payload field which contains a json](https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157)

<div class="topic-metadata">

**Author:** [@AlekseyK](https://discuss.elastic.co/u/AlekseyK)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 10:55am UTC](https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157 "2024-01-30T10:55:06Z")

</div>

Hello, I have a watcher that works perfectly fine and when executed I get an email in html format listing basic string and numeric fields I chose to select from a hit. I use a webhook action to email the results. Now, I…

---

## [One to many relation](https://discuss.elastic.co/t/one-to-many-relation/352035)

<div class="topic-metadata">

**Author:** [@imane\_ajroudi](https://discuss.elastic.co/u/imane_ajroudi)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 10:31am UTC](https://discuss.elastic.co/t/one-to-many-relation/352035 "2024-01-30T10:31:06Z")

</div>

Hello guys , please i need help urgennnt ,, ihave this mapping , normaly i should have data ,each item should have multipple detail\_name, detail\_description, type\_name ,, but i have only one each item ,, this is my mappi…

---

## [How do configure display field response time on kibana of integration nginx](https://discuss.elastic.co/t/how-do-configure-display-field-response-time-on-kibana-of-integration-nginx/351951)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 2\
**Last updated:** [January 30, 2024, 9:24am UTC](https://discuss.elastic.co/t/how-do-configure-display-field-response-time-on-kibana-of-integration-nginx/351951 "2024-01-30T09:24:17Z")

</div>

I have configured elastic-agent with integration nginx. However, it does not have a responsetime field on kibana like the following image: And I was tried configured prossessors pipelines but it is error Ple…

---

## [Only return nested child objects with deep nesting](https://discuss.elastic.co/t/only-return-nested-child-objects-with-deep-nesting/351799)

<div class="topic-metadata">

**Author:** [@iamlindoro](https://discuss.elastic.co/u/iamlindoro)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 10:02am UTC](https://discuss.elastic.co/t/only-return-nested-child-objects-with-deep-nesting/351799 "2024-01-30T10:02:31Z")

</div>

Hi, very new to Elasticsearch so please forgive the potentially stupid question which is surely related either to my query or to my mapping. In short, I have index "cases" which is the parent of nested object stages, wh…

---

## [Search Special char support](https://discuss.elastic.co/t/search-special-char-support/352058)

<div class="topic-metadata">

**Author:** [@Sankar\_S](https://discuss.elastic.co/u/Sankar_S)\
**Replies:** 2\
**Last updated:** [January 30, 2024, 9:35am UTC](https://discuss.elastic.co/t/search-special-char-support/352058 "2024-01-30T09:35:45Z")

</div>

Hello All, I have a field called title and it has value "title" : "Toddler- $kitkat @taste &roll ^yart !here #you %ice ^oops \*jam (pot) \[beat\] pep |old {jet} \`egg /lol" For given input i would like to match any term s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=318)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=320)
