# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=323

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 324

---

## [Whether Kibana inbuilt "viewer" role can be restricted only to view the Analytics feature for a user](https://discuss.elastic.co/t/whether-kibana-inbuilt-viewer-role-can-be-restricted-only-to-view-the-analytics-feature-for-a-user/351434)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 1\
**Last updated:** [January 25, 2024, 4:30am UTC](https://discuss.elastic.co/t/whether-kibana-inbuilt-viewer-role-can-be-restricted-only-to-view-the-analytics-feature-for-a-user/351434 "2024-01-25T04:30:53Z")

</div>

I am working in default namespace and i want to create an user with viewer role. Whether Kibana inbuilt "viewer" role can be restricted only to view the Analytics feature of kibana for a user and i dont want to create a…

---

## [Create Helper Functions within Pipeline](https://discuss.elastic.co/t/create-helper-functions-within-pipeline/351581)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 11:54pm UTC](https://discuss.elastic.co/t/create-helper-functions-within-pipeline/351581 "2024-01-24T23:54:40Z")

</div>

I have a function in my pipeline that does some math and another that does some translation. Is there a way to create a function like in python, so that I don't have to retype the same code everytime I want to do this op…

---

## [Trying to find the path to the nested found text](https://discuss.elastic.co/t/trying-to-find-the-path-to-the-nested-found-text/351752)

<div class="topic-metadata">

**Author:** [@warrengoldman](https://discuss.elastic.co/u/warrengoldman)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 9:50pm UTC](https://discuss.elastic.co/t/trying-to-find-the-path-to-the-nested-found-text/351752 "2024-01-24T21:50:15Z")

</div>

What I need that I have NOT figured out I would like to get the path(s) to the found text. Where the path would be book name -\> chapter number -\> verse number (which is a sibling to verses.text) What I did figure out …

---

## [Expected one of \[A-Za-z0-9\_-\], \[\\t\\n \\n\], "#","=\>" ... after input {](https://discuss.elastic.co/t/expected-one-of-a-za-z0-9-t-n-n-after-input/351694)

<div class="topic-metadata">

**Author:** [@ZinedineR](https://discuss.elastic.co/u/ZinedineR)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 9:18pm UTC](https://discuss.elastic.co/t/expected-one-of-a-za-z0-9-t-n-n-after-input/351694 "2024-01-24T21:18:42Z")

</div>

The error comes in line 19 column 19 in after input{} I think the configuration is correct but the error shows there's unexpected character input { jdbc { jdbc\_driver\_library =\> "$DRIVER\_PATH" jdbc\_connection\_s…

---

## [Permissions to view and manage agents in fleet](https://discuss.elastic.co/t/permissions-to-view-and-manage-agents-in-fleet/351748)

<div class="topic-metadata">

**Author:** [@psdarwin](https://discuss.elastic.co/u/psdarwin)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 8:52pm UTC](https://discuss.elastic.co/t/permissions-to-view-and-manage-agents-in-fleet/351748 "2024-01-24T20:52:40Z")

</div>

It used to be that you had to be superuser to even have view permissions into fleet. Is that still true? I am hoping to delegate management of fleet agents to another team, but really do not want to give them superuser…

---

## [Running an ESQL query periodally and output the result into an index](https://discuss.elastic.co/t/running-an-esql-query-periodally-and-output-the-result-into-an-index/351481)

<div class="topic-metadata">

**Author:** [@lizozom](https://discuss.elastic.co/u/lizozom)\
**Replies:** 8\
**Last updated:** [January 24, 2024, 8:52pm UTC](https://discuss.elastic.co/t/running-an-esql-query-periodally-and-output-the-result-into-an-index/351481 "2024-01-24T20:52:38Z")

</div>

I have built an ESQL query that calculates today's inventory of products. I want to run it daily and output the result into a different index. I thought of using Transforms, could I use an ESQL query there? If not, I …

---

## [Kibana Heatmap - Filters Axis Side Effect](https://discuss.elastic.co/t/kibana-heatmap-filters-axis-side-effect/349398)

<div class="topic-metadata">

**Author:** [@Ryan\_Berry1](https://discuss.elastic.co/u/Ryan_Berry1)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 6:41pm UTC](https://discuss.elastic.co/t/kibana-heatmap-filters-axis-side-effect/349398 "2024-01-24T18:41:58Z")

</div>

Hello, My Kibana visualization has an unintended side effect. Some background: my heatmap shows red or green boxes based on the number of failed tests (\>= 1 failed test gives red box). The horizontal axis represents th…

---

## [Filebeat not able to read the csv File where it stops](https://discuss.elastic.co/t/filebeat-not-able-to-read-the-csv-file-where-it-stops/351513)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 6\
**Last updated:** [January 24, 2024, 6:01pm UTC](https://discuss.elastic.co/t/filebeat-not-able-to-read-the-csv-file-where-it-stops/351513 "2024-01-24T18:01:28Z")

</div>

Hi Team, I had observed two times that during filebeat load if my elastic or filebeat server crashes due to any kind of infra-related issue. Then when it comes online the filebeat is not getting read from the point wher…

---

## [How to define tags and ignore\_failure on Java API Client PutPipelineRequest](https://discuss.elastic.co/t/how-to-define-tags-and-ignore-failure-on-java-api-client-putpipelinerequest/351292)

<div class="topic-metadata">

**Author:** [@afzm4](https://discuss.elastic.co/u/afzm4)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 5:21pm UTC](https://discuss.elastic.co/t/how-to-define-tags-and-ignore-failure-on-java-api-client-putpipelinerequest/351292 "2024-01-24T17:21:54Z")

</div>

We are in the process of upgrading to the new Java API client and are running into some problems regarding using PutPipelineRequest. This is how we're defining a PutPipelineRequest: PutPipelineRequest putPipelineRequest…

---

## [Kibana Missing Share Option Setup Guide Prevents Options From Displaying Potentially](https://discuss.elastic.co/t/kibana-missing-share-option-setup-guide-prevents-options-from-displaying-potentially/351657)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 5:18pm UTC](https://discuss.elastic.co/t/kibana-missing-share-option-setup-guide-prevents-options-from-displaying-potentially/351657 "2024-01-24T17:18:42Z")

</div>

Just putting this out there if any other users run into this issue as this may be a possible solution. A user was unable to use the Share feature in the Discover section to export logs even though they have Superuser an…

---

## [Data not getting synced properly from SQL to elastic](https://discuss.elastic.co/t/data-not-getting-synced-properly-from-sql-to-elastic/351742)

<div class="topic-metadata">

**Author:** [@abhishek\_agarwal](https://discuss.elastic.co/u/abhishek_agarwal)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 5:10pm UTC](https://discuss.elastic.co/t/data-not-getting-synced-properly-from-sql-to-elastic/351742 "2024-01-24T17:10:09Z")

</div>

I am syncing data from sql to elastic and in filter in the code block I am appending to map eg features but what is happening is that when I am running the bulk sql query ,not all features are getting appended to each in…

---

## [How to get only matched value for field that has multiple values](https://discuss.elastic.co/t/how-to-get-only-matched-value-for-field-that-has-multiple-values/351667)

<div class="topic-metadata">

**Author:** [@elasticfan1](https://discuss.elastic.co/u/elasticfan1)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 4:57pm UTC](https://discuss.elastic.co/t/how-to-get-only-matched-value-for-field-that-has-multiple-values/351667 "2024-01-24T16:57:29Z")

</div>

Let's say I have a document with a type as you go field that has multiple values. tags : \["cool beans", "great job", hello there"\] I do a phrase prefix search with the term "coo". I want to display the user "cool beans…

---

## [Data not getting synced properly from SQL to elastic](https://discuss.elastic.co/t/data-not-getting-synced-properly-from-sql-to-elastic/351722)

<div class="topic-metadata">

**Author:** [@abhishek\_agarwal](https://discuss.elastic.co/u/abhishek_agarwal)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 3:52pm UTC](https://discuss.elastic.co/t/data-not-getting-synced-properly-from-sql-to-elastic/351722 "2024-01-24T15:52:58Z")

</div>

I am syncing data from sql to elastic and in filter in the code block I am appending to map eg features but what is happening is that when I am running the bulk sql query ,not all features are getting appended to each in…

---

## [Runtime Field issue in indexes that contain nested objects](https://discuss.elastic.co/t/runtime-field-issue-in-indexes-that-contain-nested-objects/351737)

<div class="topic-metadata">

**Author:** [@victorhmorales](https://discuss.elastic.co/u/victorhmorales)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 3:52pm UTC](https://discuss.elastic.co/t/runtime-field-issue-in-indexes-that-contain-nested-objects/351737 "2024-01-24T15:52:45Z")

</div>

Hello there, I'm trying to use Runtime Fields in indexes that contain nested objects, but it's not working. I tried to add them by 'Discover', 'Lens Editor, 'Data View management' and also 'Kibana Dev Tools'. I'm runni…

---

## [Filebeat v8.11.3 crashes with "panic: sync: negative WaitGroup counter" again and again](https://discuss.elastic.co/t/filebeat-v8-11-3-crashes-with-panic-sync-negative-waitgroup-counter-again-and-again/351703)

<div class="topic-metadata">

**Author:** [@orion-ua](https://discuss.elastic.co/u/orion-ua)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-v8-11-3-crashes-with-panic-sync-negative-waitgroup-counter-again-and-again/351703 "2024-01-24T15:18:43Z")

</div>

After upgrading to Filebeat agent v8.11.3 it started to crash quite often with the following panic message: Jan 24 06:13:44 my-hostname filebeat\[1534\]: panic: sync: negative WaitGroup counter Jan 24 06:13:44 my-hostname…

---

## [Upgrade Elasticsearch 8.2 to 8.x leads to ssl problems](https://discuss.elastic.co/t/upgrade-elasticsearch-8-2-to-8-x-leads-to-ssl-problems/351724)

<div class="topic-metadata">

**Author:** [@Ljapunov](https://discuss.elastic.co/u/Ljapunov)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 3:14pm UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-8-2-to-8-x-leads-to-ssl-problems/351724 "2024-01-24T15:14:38Z")

</div>

Hi everyone, I tried to upgrade two different clusters containing 3 or 5 nodes. Both are running elasticsearch 8.2.0 and I tried upgrading to different versions 8.11.4, 8.5.3 and 8.4.3. But all attempts failed with the …

---

## [Using the context. in Body of E-mail for rules and connection](https://discuss.elastic.co/t/using-the-context-in-body-of-e-mail-for-rules-and-connection/351728)

<div class="topic-metadata">

**Author:** [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 2:47pm UTC](https://discuss.elastic.co/t/using-the-context-in-body-of-e-mail-for-rules-and-connection/351728 "2024-01-24T14:47:38Z")

</div>

Hello, We are using the Elastic version v 7.16.3 . I am trying to create the alert notification by using the Rules and connectors. The rule is working fine. however I can't put the required data in the e-mail notifica…

---

## [Host isolation permission issue](https://discuss.elastic.co/t/host-isolation-permission-issue/350492)

<div class="topic-metadata">

**Author:** [@nmurilo](https://discuss.elastic.co/u/nmurilo)\
**Replies:** 6\
**Last updated:** [January 24, 2024, 2:33pm UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492 "2024-01-24T14:33:39Z")

</div>

I’m trying to grant host isolate perms configuring the "Role Mappings" but without success. Tried the same configuration steps (same rule) for regular Kibana users and it works like a charm. Have I missed something? …

---

## [Kibana upgrade from 7 to 8.12 errors with security\_exception on saved objects migration](https://discuss.elastic.co/t/kibana-upgrade-from-7-to-8-12-errors-with-security-exception-on-saved-objects-migration/351669)

<div class="topic-metadata">

**Author:** [@michael.brizic](https://discuss.elastic.co/u/michael.brizic)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 2:16pm UTC](https://discuss.elastic.co/t/kibana-upgrade-from-7-to-8-12-errors-with-security-exception-on-saved-objects-migration/351669 "2024-01-24T14:16:09Z")

</div>

I checked Upgrade Assistant prior to performing the upgrade. I was also on the latest version of 7.17 before upgrading. I'm attempting to upgrade to version 8.12 on my locally running development environment. Thus, I …

---

## [ILM to delete only doc counts in a simple indice elasticsearch](https://discuss.elastic.co/t/ilm-to-delete-only-doc-counts-in-a-simple-indice-elasticsearch/351714)

<div class="topic-metadata">

**Author:** [@Musled](https://discuss.elastic.co/u/Musled)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 1:59pm UTC](https://discuss.elastic.co/t/ilm-to-delete-only-doc-counts-in-a-simple-indice-elasticsearch/351714 "2024-01-24T13:59:24Z")

</div>

Hi there ! I'm working on a lifecycle for my indices in elasticsearch. To put you in context, I recover the logs of 20 applications with the ELK stack but I notice that my storage disk is filling up very quickly. Ther…

---

## [Best practice to install elastic on premise](https://discuss.elastic.co/t/best-practice-to-install-elastic-on-premise/351715)

<div class="topic-metadata">

**Author:** [@elasticexpert](https://discuss.elastic.co/u/elasticexpert)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 1:54pm UTC](https://discuss.elastic.co/t/best-practice-to-install-elastic-on-premise/351715 "2024-01-24T13:54:23Z")

</div>

Hey! I have an elasticsearch cluster and I have a really serious problem which you can see here. Maybe this comment will exlplain it:. I have 10 servers with 750 GB RAM and 72 Cores and 8 disks. Right now, Elasticse…

---

## [Fileabeat in UAT is 8.2.0 filebeat in PROD is 7.9.3](https://discuss.elastic.co/t/fileabeat-in-uat-is-8-2-0-filebeat-in-prod-is-7-9-3/351682)

<div class="topic-metadata">

**Author:** [@Hanuma](https://discuss.elastic.co/u/Hanuma)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 1:35pm UTC](https://discuss.elastic.co/t/fileabeat-in-uat-is-8-2-0-filebeat-in-prod-is-7-9-3/351682 "2024-01-24T13:35:42Z")

</div>

Hi Team, Can you please let us know the difference between filebeat version 7.9.3 and 8.2.0. Will this create issue in Available fields in Elastic search. we have issue in Available fields not showing in PROD those re…

---

## [Exception caught while applying mutate filter {:exception=\>"Could not set field 'product' on object 'x' to value 'y'.This is probably due to trying to set a field like \[foo\]\[bar\] = someValuewhen \[foo\] is not either a map or a string"}](https://discuss.elastic.co/t/exception-caught-while-applying-mutate-filter-exception-could-not-set-field-product-on-object-x-to-value-y-this-is-probably-due-to-trying-to-set-a-field-like-foo-bar-somevaluewhen-foo-is-not-either-a-map-or-a-string/351707)

<div class="topic-metadata">

**Author:** [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 1:22pm UTC](https://discuss.elastic.co/t/exception-caught-while-applying-mutate-filter-exception-could-not-set-field-product-on-object-x-to-value-y-this-is-probably-due-to-trying-to-set-a-field-like-foo-bar-somevaluewhen-foo-is-not-either-a-map-or-a-string/351707 "2024-01-24T13:22:41Z")

</div>

When attempting to rename fields as in the following example: mutate { rename =\> { "vendor" =\> "\[abc\]\[vendor\]" "vendor\_product" =\> "\[abc\]\[vendor\]\[product\]" "vendor\_product\_version" =\> "\[abc\]\[vend…

---

## [Not able to get elastic agent system integration in the Kibana UI](https://discuss.elastic.co/t/not-able-to-get-elastic-agent-system-integration-in-the-kibana-ui/351704)

<div class="topic-metadata">

**Author:** [@Ashwani\_Shukla](https://discuss.elastic.co/u/Ashwani_Shukla)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 12:50pm UTC](https://discuss.elastic.co/t/not-able-to-get-elastic-agent-system-integration-in-the-kibana-ui/351704 "2024-01-24T12:50:36Z")

</div>

I have deployed the ES and Kibana in a separate VMs and fleet server in the kibana server itself. But after adding the fleet server, there is no option for system integration to collect the logs from elastic agent in Kib…

---

## [Merge failed errors from indices with quantized vectors](https://discuss.elastic.co/t/merge-failed-errors-from-indices-with-quantized-vectors/351412)

<div class="topic-metadata">

**Author:** [@Louis\_Liu](https://discuss.elastic.co/u/Louis_Liu)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 12:20pm UTC](https://discuss.elastic.co/t/merge-failed-errors-from-indices-with-quantized-vectors/351412 "2024-01-24T12:20:52Z")

</div>

I just upgraded our es cluster to 8.12.0. I created indices with quantized vectors, and started to migrate data. After few hours of data insert, the servers reports marking and sending shard failed due to \[shard failur…

---

## [Problem with an IF statement not working](https://discuss.elastic.co/t/problem-with-an-if-statement-not-working/351608)

<div class="topic-metadata">

**Author:** [@FaisalParkar](https://discuss.elastic.co/u/FaisalParkar)\
**Replies:** 10\
**Last updated:** [January 24, 2024, 10:15am UTC](https://discuss.elastic.co/t/problem-with-an-if-statement-not-working/351608 "2024-01-24T10:15:42Z")

</div>

Hello Everyone, I hope someone is able to assist. I am running ELK stack 8.11.3 and am using Logstash to ingest Syslogs in a CEF format. I have everything working and it works nicely, however I want to add an IF stateme…

---

## [Elasticsearch unstable cluster](https://discuss.elastic.co/t/elasticsearch-unstable-cluster/350157)

<div class="topic-metadata">

**Author:** [@elasticexpert](https://discuss.elastic.co/u/elasticexpert)\
**Replies:** 26\
**Last updated:** [January 24, 2024, 9:55am UTC](https://discuss.elastic.co/t/elasticsearch-unstable-cluster/350157 "2024-01-24T09:55:18Z")

</div>

Hey! I have an elastic cluster (version 8.11.1, upgraded from 8.5.3 but the problem is before the upgrade) with 10 datanode physical servers that is unstable (node are disconnecting and connecting automaticly) with two r…

---

## [\[elastic\_agent\]\[error\] Cannot checkin in with fleet-server, retrying](https://discuss.elastic.co/t/elastic-agent-error-cannot-checkin-in-with-fleet-server-retrying/351595)

<div class="topic-metadata">

**Author:** [@AnkurYogi](https://discuss.elastic.co/u/AnkurYogi)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 8:34am UTC](https://discuss.elastic.co/t/elastic-agent-error-cannot-checkin-in-with-fleet-server-retrying/351595 "2024-01-23T08:34:58Z")

</div>

Hi everyone All my agents are showing offline and I am not sure why. Here are some logs and info to start the discussion..! { "log.level": "info", "@timestamp": "2024-01-23T06:21:39.097Z", "message": "ApiKey fail…

---

## [Logs proccessed via Filebeat](https://discuss.elastic.co/t/logs-proccessed-via-filebeat/351698)

<div class="topic-metadata">

**Author:** [@Pavlo\_Pylypiv](https://discuss.elastic.co/u/Pavlo_Pylypiv)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 8:58am UTC](https://discuss.elastic.co/t/logs-proccessed-via-filebeat/351698 "2024-01-24T08:58:51Z")

</div>

Hi! I would like to ask you what filebeat does with logs, which are not related to module? For example, I have Barracuda WAF and Barracuda FW running through Filebeat Barracuda Module (it works only for WAF). Will filebe…

---

## [How to filter specific fields of nginx logs in filebeat before importing in elastic?](https://discuss.elastic.co/t/how-to-filter-specific-fields-of-nginx-logs-in-filebeat-before-importing-in-elastic/351475)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 4\
**Last updated:** [January 24, 2024, 8:21am UTC](https://discuss.elastic.co/t/how-to-filter-specific-fields-of-nginx-logs-in-filebeat-before-importing-in-elastic/351475 "2024-01-24T08:21:00Z")

</div>

Hi Guys, I have a filebeat for importing nginx logs to elasticsearch. this is a sample of my logs: 5.125.\*\*\*\*\* - - \[20/Jan/2024:12:50:39 +0000\] "GET /findEnemy?\_s\_=hT%2FF&\_u\_=7367&baseScore=1831&blevel=11&btid=170536&c…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=322)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=324)
