# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=325

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 326

---

## [Retrieving or saving matching document ID when using percolate](https://discuss.elastic.co/t/retrieving-or-saving-matching-document-id-when-using-percolate/351555)

<div class="topic-metadata">

**Author:** [@Krikkits](https://discuss.elastic.co/u/Krikkits)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 10:32am UTC](https://discuss.elastic.co/t/retrieving-or-saving-matching-document-id-when-using-percolate/351555 "2024-01-23T10:32:59Z")

</div>

I am unfamiliar with percolate and honestly a bit confused. My idea is to use percolate on an existing index and not only getting how many match the query, but also which exact ones. The field "\_percolator\_document\_slot"…

---

## [How to user docker secrets with metricbeat](https://discuss.elastic.co/t/how-to-user-docker-secrets-with-metricbeat/349662)

<div class="topic-metadata">

**Author:** [@denisk](https://discuss.elastic.co/u/denisk)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 10:22am UTC](https://discuss.elastic.co/t/how-to-user-docker-secrets-with-metricbeat/349662 "2024-01-23T10:22:05Z")

</div>

I would like to use docker secrets \[1\] to provide credentials for metricbeat to use when running the monitoring modules. Is that possible? I am using the docker image of Metricbeat 8.11.3 from Docker hub. I know metricb…

---

## ["master\_not\_discovered\_exception"](https://discuss.elastic.co/t/master-not-discovered-exception/351548)

<div class="topic-metadata">

**Author:** [@Chulter](https://discuss.elastic.co/u/Chulter)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 10:20am UTC](https://discuss.elastic.co/t/master-not-discovered-exception/351548 "2024-01-23T10:20:35Z")

</div>

Hello everyone, My english is not well so i use google trad. have encountered this error from the start knowing that I work on a Debian 11.5 VM with suricata installed as well as elasticsearch, kibana, filebeat so I on…

---

## [\[Lens\] Sum aggregation with missing values](https://discuss.elastic.co/t/lens-sum-aggregation-with-missing-values/351056)

<div class="topic-metadata">

**Author:** [@lizozom](https://discuss.elastic.co/u/lizozom)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 9:50am UTC](https://discuss.elastic.co/t/lens-sum-aggregation-with-missing-values/351056 "2024-01-23T09:50:26Z")

</div>

I have a lens visualization on top of this data set: I want to show the total item quantity per date. On days where there was no data, I want to show the last value. However, when I choose the sum aggregation and se…

---

## [Kibana7.17](https://discuss.elastic.co/t/kibana7-17/351484)

<div class="topic-metadata">

**Author:** [@Youssef\_Shehadeh](https://discuss.elastic.co/u/Youssef_Shehadeh)\
**Replies:** 5\
**Last updated:** [January 23, 2024, 9:33am UTC](https://discuss.elastic.co/t/kibana7-17/351484 "2024-01-23T09:33:17Z")

</div>

Hello, I'm working on a uni project where I need to use the curator tool. However, it is not compatible with ES8.11, so I configured a three-node cluster (data\_frozen, data\_hot, data\_cold). The cluster health is green, a…

---

## [Failed to flush the buffer](https://discuss.elastic.co/t/failed-to-flush-the-buffer/351538)

<div class="topic-metadata">

**Author:** [@Music\_World](https://discuss.elastic.co/u/Music_World)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 9:15am UTC](https://discuss.elastic.co/t/failed-to-flush-the-buffer/351538 "2024-01-23T09:15:24Z")

</div>

Hi @all I am using elasticsearch version: 7.16.2 and fluentd version: 1.14.4 on aws eks cluster and it's throwing bufferoverflow error like failed to flush the buffer. retry\_times=0 next\_retry\_time=2024-01-19 07:43:43 …

---

## [Cound not run org.elasticsearch.bootstrap.Elasticsearch(v8.12.0) directly in Intellij Idea](https://discuss.elastic.co/t/cound-not-run-org-elasticsearch-bootstrap-elasticsearch-v8-12-0-directly-in-intellij-idea/351594)

<div class="topic-metadata">

**Author:** [@Henkel](https://discuss.elastic.co/u/Henkel)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 9:10am UTC](https://discuss.elastic.co/t/cound-not-run-org-elasticsearch-bootstrap-elasticsearch-v8-12-0-directly-in-intellij-idea/351594 "2024-01-23T09:10:11Z")

</div>

Hi guys: with elasticsearch version 7.16.0, I can run org.elasticsearch.bootstrap.Elasticsearch directly in Intellij Idea.The configuration of Intellij Idea is as follows： However, with elasticsearch version 8.12.0,…

---

## [In a metric visualization change the color mode based on formula](https://discuss.elastic.co/t/in-a-metric-visualization-change-the-color-mode-based-on-formula/350928)

<div class="topic-metadata">

**Author:** [@SpicyS](https://discuss.elastic.co/u/SpicyS)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 8:58am UTC](https://discuss.elastic.co/t/in-a-metric-visualization-change-the-color-mode-based-on-formula/350928 "2024-01-23T08:58:54Z")

</div>

Hello, I'm building a dashboard and now I want to make a lens metric with average time per costomer. Now this isn't difficult but in the color mode I want it to change color based on a formula. So when the current aver…

---

## [Are processors applied to the filebeat application logs?](https://discuss.elastic.co/t/are-processors-applied-to-the-filebeat-application-logs/351598)

<div class="topic-metadata">

**Author:** [@Dragan\_Bosnjak](https://discuss.elastic.co/u/Dragan_Bosnjak)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 8:30am UTC](https://discuss.elastic.co/t/are-processors-applied-to-the-filebeat-application-logs/351598 "2024-01-23T08:30:03Z")

</div>

I am trying to filter out some filebeat logs with drop\_event processor, but it doesn't seem to work. This is the event: { "log.level":"warn", "@timestamp":"2024-01-01T12:11:22.333Z", "log.logger":"file\_watcher", "log.or…

---

## [\[ERROR\]\[plugins.observability\] Failed to install SLO common resources and summary transforms](https://discuss.elastic.co/t/error-plugins-observability-failed-to-install-slo-common-resources-and-summary-transforms/351587)

<div class="topic-metadata">

**Author:** [@griy](https://discuss.elastic.co/u/griy)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 8:22am UTC](https://discuss.elastic.co/t/error-plugins-observability-failed-to-install-slo-common-resources-and-summary-transforms/351587 "2024-01-23T08:22:03Z")

</div>

I found an error when starting Kibana, \[ERROR\] \[plugins. observability\] Failed to install SLO. When I used bin/kibana plugin to install SLO, an address was provided https://artifacts.elastic.co/downloads/kibana-plugins/S…

---

## [I am trying to deduplicate my events one the basis of timestamp and operation field. But it did not work?](https://discuss.elastic.co/t/i-am-trying-to-deduplicate-my-events-one-the-basis-of-timestamp-and-operation-field-but-it-did-not-work/351599)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 8:18am UTC](https://discuss.elastic.co/t/i-am-trying-to-deduplicate-my-events-one-the-basis-of-timestamp-and-operation-field-but-it-did-not-work/351599 "2024-01-23T08:18:42Z")

</div>

My Log event: { "priority" =\> 13, "host" =\> "172.31.63.35", "consistency" =\> "\\"ONE\\"", "source" =\> "\\"127.0.0.1", "type" =\> "scylladb", "severity" =\> 5…

---

## [Kubernetes deployed Elastic Agent is looped in beat restart](https://discuss.elastic.co/t/kubernetes-deployed-elastic-agent-is-looped-in-beat-restart/350707)

<div class="topic-metadata">

**Author:** [@Alphayeeeet](https://discuss.elastic.co/u/Alphayeeeet)\
**Replies:** 4\
**Last updated:** [January 23, 2024, 7:58am UTC](https://discuss.elastic.co/t/kubernetes-deployed-elastic-agent-is-looped-in-beat-restart/350707 "2024-01-23T07:58:07Z")

</div>

Hello, I tried to deploy Fleet-managed Elastic Agent with Kubernetes Integration into RedHat OpenShift. When deploying an agent policy update using Fleet, the beats are caught up in a restart loop: Agent version: beats…

---

## [Sub aggregating top\_hits](https://discuss.elastic.co/t/sub-aggregating-top-hits/351163)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 6\
**Last updated:** [January 23, 2024, 7:51am UTC](https://discuss.elastic.co/t/sub-aggregating-top-hits/351163 "2024-01-23T07:51:19Z")

</div>

Hi, I've the below Query { "query": { "bool": { "filter": \[ { "term": { "is\_deleted": 0 } }, …

---

## [Unable to Build Kibana Prometheus Exporter Plugin](https://discuss.elastic.co/t/unable-to-build-kibana-prometheus-exporter-plugin/351515)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 7:12am UTC](https://discuss.elastic.co/t/unable-to-build-kibana-prometheus-exporter-plugin/351515 "2024-01-23T07:12:45Z")

</div>

We have consistently encountered errors related to plugin-helper while attempting to build the Kibana Prometheus Exporter plugin. Please advise. @pjhampton

---

## [./elastic-agent: 2: Syntax error: word unexpected (expecting ")")](https://discuss.elastic.co/t/elastic-agent-2-syntax-error-word-unexpected-expecting/351589)

<div class="topic-metadata">

**Author:** [@axiescholar](https://discuss.elastic.co/u/axiescholar)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 4:44am UTC](https://discuss.elastic.co/t/elastic-agent-2-syntax-error-word-unexpected-expecting/351589 "2024-01-23T04:44:31Z")

</div>

i am getting this error when i am installing agent on kali linux. ./elastic-agent: 1: ./elastic-agent: 1: ELF: not found O@8: not found ./elastic-agent: 2: Syntax error: word unexpected (expecting ")") i am using a V…

---

## [Single line text data is truncated](https://discuss.elastic.co/t/single-line-text-data-is-truncated/350725)

<div class="topic-metadata">

**Author:** [@kevin1811](https://discuss.elastic.co/u/kevin1811)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 2:59am UTC](https://discuss.elastic.co/t/single-line-text-data-is-truncated/350725 "2024-01-23T02:59:04Z")

</div>

When there are multiple line breaks at the end of my file, the last valid complete text message will be truncated based on the number of line breaks at the end of the text txt file {"b":"001T230197002","t":"E0040150ED4…

---

## [Regarding parsing of data in logstash](https://discuss.elastic.co/t/regarding-parsing-of-data-in-logstash/351400)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 1:59am UTC](https://discuss.elastic.co/t/regarding-parsing-of-data-in-logstash/351400 "2024-01-23T01:59:48Z")

</div>

"message" =\> "{\\"namespace\\":\\"oci\_computeagent\\",\\"resourceGroup\\":null,\\"compartmentId\\":\\"ocid1.compartment.oc1..aaaaaaaacu54zo4clgrmfs3faxqqgfxyu2mjlufgslcem3venf2kon2ktmsq\\",\\"name\\":\\"DiskIopsWritten\\",\\"dimensions…

---

## [Error when enrolloning Fleet on ELK](https://discuss.elastic.co/t/error-when-enrolloning-fleet-on-elk/349983)

<div class="topic-metadata">

**Author:** [@Ellery](https://discuss.elastic.co/u/Ellery)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 1:25am UTC](https://discuss.elastic.co/t/error-when-enrolloning-fleet-on-elk/349983 "2024-01-23T01:25:34Z")

</div>

Hello, I hope you can help me. I have the following issue: I have successfully installed Elasticsearch and Kibana. Now I'm installing Fleet, but no matter what I do, I encounter the following error: The instalation it's …

---

## [Fleet serve wrong elastic Address](https://discuss.elastic.co/t/fleet-serve-wrong-elastic-address/350332)

<div class="topic-metadata">

**Author:** [@Lukasz\_Skrzat](https://discuss.elastic.co/u/Lukasz_Skrzat)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 1:11am UTC](https://discuss.elastic.co/t/fleet-serve-wrong-elastic-address/350332 "2024-01-23T01:11:42Z")

</div>

HI Installed new ECK instance with fleet server, but i change namespace from Default to logging-stack Changed in fleet configs addresses. Now install new agents to kubernetes integration with fleet token but after …

---

## [When does compression\_level change?](https://discuss.elastic.co/t/when-does-compression-level-change/350659)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 1:04am UTC](https://discuss.elastic.co/t/when-does-compression-level-change/350659 "2024-01-23T01:04:39Z")

</div>

We're on Elastic 8.8.1 and about to upgrade to 8.11.3. Since we have alot of issues with Elastic Agents on our Windows-boxes, esp. when endpoint or agent is being reloaded but also with high cpuutilization (mostly due t…

---

## [Vega Query - Find first match](https://discuss.elastic.co/t/vega-query-find-first-match/351583)

<div class="topic-metadata">

**Author:** [@Ryan\_Clark](https://discuss.elastic.co/u/Ryan_Clark)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:39am UTC](https://discuss.elastic.co/t/vega-query-find-first-match/351583 "2024-01-23T00:39:02Z")

</div>

Hi, I am building status indicators in vega to find certain events in logs and give me a green light if it found it and red light if the event is not found. What I've come up with so far works, but I noticed in the res…

---

## [Filebeats not sending output to Logstash](https://discuss.elastic.co/t/filebeats-not-sending-output-to-logstash/351154)

<div class="topic-metadata">

**Author:** [@pmuno007](https://discuss.elastic.co/u/pmuno007)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:33am UTC](https://discuss.elastic.co/t/filebeats-not-sending-output-to-logstash/351154 "2024-01-23T00:33:26Z")

</div>

I suspect filebeats is not sending output to Logstash since Logstash has not created an index in Elastic Search. There are no errors in logs. Filebeat logs also do not indicate nor mention Logstash connection (not sure i…

---

## [Which crptographic hash algo does elasticsearch 8.7.0 use?](https://discuss.elastic.co/t/which-crptographic-hash-algo-does-elasticsearch-8-7-0-use/351361)

<div class="topic-metadata">

**Author:** [@sahadev\_d](https://discuss.elastic.co/u/sahadev_d)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:28am UTC](https://discuss.elastic.co/t/which-crptographic-hash-algo-does-elasticsearch-8-7-0-use/351361 "2024-01-23T00:28:01Z")

</div>

Hi community, just wanted to know which hashing algo does elasticsearch 8.7.0 uses for internal hashing. also does it by any chance use sha1 or sha0 Please let me know how can i check the version

---

## [Logstash container gets closed automatically after installation of the "logstash-input-mongodb" plugin](https://discuss.elastic.co/t/logstash-container-gets-closed-automatically-after-installation-of-the-logstash-input-mongodb-plugin/351479)

<div class="topic-metadata">

**Author:** [@Vladyslav\_Googlya](https://discuss.elastic.co/u/Vladyslav_Googlya)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:16am UTC](https://discuss.elastic.co/t/logstash-container-gets-closed-automatically-after-installation-of-the-logstash-input-mongodb-plugin/351479 "2024-01-23T00:16:14Z")

</div>

Hi everyone, I'm trying to run the Logstash container in the docker-compose file to sync my MongoDB data with Elastic. But, after the step of installation of the "logstash-input-MongoDB" plugin, the container gets exited…

---

## [Adding an array of events even if there is only one](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567)

<div class="topic-metadata">

**Author:** [@ylevaill](https://discuss.elastic.co/u/ylevaill)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:07am UTC](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567 "2024-01-23T00:07:38Z")

</div>

Hello, I use this filter : json { source =\> "message" add\_field =\> { "\[events\]\[id\]" =\> "%{\_id}" } add\_field =\> { "\[events\]\[nom\]" =\> "%{eventName}" } add\_field =\> { "\[events\]\[timestamp\]" =\> "%{ti…

---

## [Can't drop field in checkpoint filebeat module](https://discuss.elastic.co/t/cant-drop-field-in-checkpoint-filebeat-module/349656)

<div class="topic-metadata">

**Author:** [@krystian](https://discuss.elastic.co/u/krystian)\
**Replies:** 2\
**Last updated:** [January 22, 2024, 11:38pm UTC](https://discuss.elastic.co/t/cant-drop-field-in-checkpoint-filebeat-module/349656 "2024-01-22T23:38:30Z")

</div>

I want drop field in checkpoint filebeat module. I try write in "filelds" rule\_name and rule.name and prefix it "checkpoint" but it doesn't work. Please somebody help me. filebeat.yml processors: - drop\_fields: …

---

## [How to resolve ILM errors about missing "scaling\_factor"?](https://discuss.elastic.co/t/how-to-resolve-ilm-errors-about-missing-scaling-factor/345937)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 18\
**Last updated:** [January 22, 2024, 9:13pm UTC](https://discuss.elastic.co/t/how-to-resolve-ilm-errors-about-missing-scaling-factor/345937 "2024-01-22T21:13:32Z")

</div>

My ILM policy is configured to downsample metrics. The policy does work, and I have metrics being downsampled, but a few indices are stuck with lifecycle errors. Specifically several .ds-metrics-docker.memory-default... …

---

## [Modsecurity log (split on audit\_data\[messages\]) Only String and Array types are splittable](https://discuss.elastic.co/t/modsecurity-log-split-on-audit-data-messages-only-string-and-array-types-are-splittable/351507)

<div class="topic-metadata">

**Author:** [@sunnysigara](https://discuss.elastic.co/u/sunnysigara)\
**Replies:** 4\
**Last updated:** [January 22, 2024, 8:50pm UTC](https://discuss.elastic.co/t/modsecurity-log-split-on-audit-data-messages-only-string-and-array-types-are-splittable/351507 "2024-01-22T20:50:57Z")

</div>

{ "transaction": { "time": "20/Jan/2024:00:10:51 +0530", "transaction\_id": "16717361827536742843", "remote\_address": "20.1.198.110", "remote\_port": 80, "local\_address": "127.0.…

---

## [Kibana Discover / Dashboards Read Only](https://discuss.elastic.co/t/kibana-discover-dashboards-read-only/351286)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 6\
**Last updated:** [January 22, 2024, 8:35pm UTC](https://discuss.elastic.co/t/kibana-discover-dashboards-read-only/351286 "2024-01-22T20:35:20Z")

</div>

Hello All, We wish to lock down access on a customer sites ELK in a way that they can view the Analytics/Discover & Dashboards but not edit. The indices already exist. I have created a space,role and user with this aim…

---

## [In pipeline: translate causes logstash to crash](https://discuss.elastic.co/t/in-pipeline-translate-causes-logstash-to-crash/351386)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 4\
**Last updated:** [January 22, 2024, 7:22pm UTC](https://discuss.elastic.co/t/in-pipeline-translate-causes-logstash-to-crash/351386 "2024-01-22T19:22:22Z")

</div>

I'm using a JSON dictionary to convert values to strings, it looks like this: { "1.1.0.80.1.\*.\*": "Motorcycle -\> Generic Scooter (Small)", "1.1.0.80.2.\*.\*": "Motorcycle -\> Generic Sport/Street (Mid-Size)", …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=324)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=326)
