# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=332

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 333

---

## [The logstash reload config manually not work](https://discuss.elastic.co/t/the-logstash-reload-config-manually-not-work/350895)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 1:03am UTC](https://discuss.elastic.co/t/the-logstash-reload-config-manually-not-work/350895 "2024-01-15T01:03:54Z")

</div>

as the topic, i send the kill -SIGHUP xxx to the logstash ,but the config still same. version 8.11.3 linux: Linux CS-gxxt-tyzj-03 4.19.90-52.22.v2207.ky10.aarch64 #1 SMP Tue Mar 14 11:52:45 CST 2023 aarch64 aarch64 aar…

---

## [Creating and using custom functions in painless](https://discuss.elastic.co/t/creating-and-using-custom-functions-in-painless/351037)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 12:01am UTC](https://discuss.elastic.co/t/creating-and-using-custom-functions-in-painless/351037 "2024-01-15T00:01:43Z")

</div>

so here is the thing , i have this long script that define variables of type String\[\] words\_var1 = new String\[\] {'word1','word1','word1'} then i have this function that tries to assign the right word to the right doc b…

---

## [Fetch results where count of nested field is more than 1](https://discuss.elastic.co/t/fetch-results-where-count-of-nested-field-is-more-than-1/351042)

<div class="topic-metadata">

**Author:** [@Hardik\_Sharma](https://discuss.elastic.co/u/Hardik_Sharma)\
**Replies:** 0\
**Last updated:** [January 14, 2024, 11:59pm UTC](https://discuss.elastic.co/t/fetch-results-where-count-of-nested-field-is-more-than-1/351042 "2024-01-14T23:59:11Z")

</div>

So I have a mapping where "configs" is a nested field. \["configs"\]{ "type": "nested", \["properties"\]: {\[56 items\] }} Now I want to fetch docs where 'configs' have more than 1 objects. For this I am using { "scr…

---

## [Rollover not working, Filebeat default index does not have an alias](https://discuss.elastic.co/t/rollover-not-working-filebeat-default-index-does-not-have-an-alias/350655)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 8\
**Last updated:** [January 14, 2024, 5:19pm UTC](https://discuss.elastic.co/t/rollover-not-working-filebeat-default-index-does-not-have-an-alias/350655 "2024-01-14T17:19:15Z")

</div>

Hello, I would like to use rollover to delete all logs, however, I always get an error message. It does not work. I can use only if turn of rollover. I do not modify anything on indexes, I use default Indexes after inst…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[actions-logs\] does not point to index \[actions-logs\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 7\
**Last updated:** [January 14, 2024, 11:04am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916 "2024-01-14T11:04:16Z")

</div>

Got a template with this { "index": { "lifecycle": { "name": "logstash-policy", "rollover\_alias": "actions-logs" }, "number\_of\_replicas": "0" } } Got index with name "actions-logs" But at index "actiong-logs…

---

## [Elastic Agent](https://discuss.elastic.co/t/elastic-agent/350581)

<div class="topic-metadata">

**Author:** [@Marcus\_Berglund](https://discuss.elastic.co/u/Marcus_Berglund)\
**Replies:** 3\
**Last updated:** [January 14, 2024, 9:59am UTC](https://discuss.elastic.co/t/elastic-agent/350581 "2024-01-14T09:59:51Z")

</div>

Hi, My goal is to collect system metrics for a server e.g CPU, Disk etc. I have installed the elastic agent on the server and it show up as healthy in fleet server but there are no metrics. Do I really need to install m…

---

## [Pull logs from filebeat instead of pushing by filebeat](https://discuss.elastic.co/t/pull-logs-from-filebeat-instead-of-pushing-by-filebeat/351016)

<div class="topic-metadata">

**Author:** [@Sohrab.p72](https://discuss.elastic.co/u/Sohrab.p72)\
**Replies:** 2\
**Last updated:** [January 13, 2024, 7:55pm UTC](https://discuss.elastic.co/t/pull-logs-from-filebeat-instead-of-pushing-by-filebeat/351016 "2024-01-13T19:55:23Z")

</div>

Hi, I need elk to pull data from filebeat it means I don't want the data be pushed by Filebeat to any endpoint. Like Node\_exporter for Prometheus which is listening on an endpoint for prometheus, I want filebeat or any…

---

## [Elasticsearch incomplete logs](https://discuss.elastic.co/t/elasticsearch-incomplete-logs/350899)

<div class="topic-metadata">

**Author:** [@Krishna94](https://discuss.elastic.co/u/Krishna94)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 1:37pm UTC](https://discuss.elastic.co/t/elasticsearch-incomplete-logs/350899 "2024-01-13T13:37:32Z")

</div>

Hi, I have filebeat to read my inputs and logstash is the shipper to elasticsearch. But could found that the data in filebeat is not sending to elasticsearch completely. Pls do help. Thank you Athira Krishna

---

## [Elastic Agent and index names](https://discuss.elastic.co/t/elastic-agent-and-index-names/350985)

<div class="topic-metadata">

**Author:** [@wrender1](https://discuss.elastic.co/u/wrender1)\
**Replies:** 5\
**Last updated:** [January 13, 2024, 1:21pm UTC](https://discuss.elastic.co/t/elastic-agent-and-index-names/350985 "2024-01-13T13:21:30Z")

</div>

I'm deploying the Elastic Agent in standalone on Kubernetes. I've got he default yaml file, but I'm having a hard time with the index naming that it creates. It is a little unclear to me from the documentation. Do the i…

---

## [Do not alert for no data for decommissioned server](https://discuss.elastic.co/t/do-not-alert-for-no-data-for-decommissioned-server/350997)

<div class="topic-metadata">

**Author:** [@Kodito](https://discuss.elastic.co/u/Kodito)\
**Replies:** 4\
**Last updated:** [January 13, 2024, 10:41am UTC](https://discuss.elastic.co/t/do-not-alert-for-no-data-for-decommissioned-server/350997 "2024-01-13T10:41:08Z")

</div>

My cluster fires a kibana alert when there is no metricbeat data for a server for the last 15 minutes, which is very useful in the case where there is an issue with the beat/server. However, when a server is decommissio…

---

## [Rollover Index Throws Exception](https://discuss.elastic.co/t/rollover-index-throws-exception/349687)

<div class="topic-metadata">

**Author:** [@krish1](https://discuss.elastic.co/u/krish1)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:52am UTC](https://discuss.elastic.co/t/rollover-index-throws-exception/349687 "2024-01-13T09:52:04Z")

</div>

I have an index which uses ILM. The index rolls over every week. We use Spring-data to read and write for Elasticsearch. My index just rolled over today and we are having trouble with writing to it. It fails with the fol…

---

## [A node in my elasticsearch has full disk](https://discuss.elastic.co/t/a-node-in-my-elasticsearch-has-full-disk/350811)

<div class="topic-metadata">

**Author:** [@Tai\_Nguyen\_Huu](https://discuss.elastic.co/u/Tai_Nguyen_Huu)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:12am UTC](https://discuss.elastic.co/t/a-node-in-my-elasticsearch-has-full-disk/350811 "2024-01-13T09:12:49Z")

</div>

Hi all, I have a elasticsearch cluster with 10 node, one node in my elasticsearch had full disk and it was removed from cluster by elasticsearch. the Disk of other nodes in my cluster still have 70% disk. How to I can re…

---

## [How to configure login kibana custom file build version 8.5.0?](https://discuss.elastic.co/t/how-to-configure-login-kibana-custom-file-build-version-8-5-0/351004)

<div class="topic-metadata">

**Author:** [@Cody-Test](https://discuss.elastic.co/u/Cody-Test)\
**Replies:** 0\
**Last updated:** [January 13, 2024, 4:50am UTC](https://discuss.elastic.co/t/how-to-configure-login-kibana-custom-file-build-version-8-5-0/351004 "2024-01-13T04:50:09Z")

</div>

Hello Guy, I can't configure or edit the default login page of the Kibana application on Linux using the .deb package after extracting the current storage directory at /usr/share/kibana/x-pack/plugins/security/security.…

---

## [Changing winlogbeat from elasticsearch to logstash](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865)

<div class="topic-metadata">

**Author:** [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 10:33pm UTC](https://discuss.elastic.co/t/changing-winlogbeat-from-elasticsearch-to-logstash/350865 "2024-01-12T22:33:11Z")

</div>

Hi, I started off a cluster with winlogbeat going directly to elasticsearch and using the pre-built dashboards. All that worked well out of the box. Now I'd like to send my winlogbeat data through logstash so I can do s…

---

## [Recreate the automatically generated certificates](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987)

<div class="topic-metadata">

**Author:** [@pxeedust](https://discuss.elastic.co/u/pxeedust)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 10:25pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987 "2024-01-12T22:25:55Z")

</div>

Sorry for the beginner question, but I am having trouble regenerating the certificates that were made at deployment. I'm not familiar with how certificates work so I was hoping there might be a script that just regenerat…

---

## [Panw.panos TCP grok errors](https://discuss.elastic.co/t/panw-panos-tcp-grok-errors/350993)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 10:03pm UTC](https://discuss.elastic.co/t/panw-panos-tcp-grok-errors/350993 "2024-01-12T22:03:55Z")

</div>

Good day all. I have a question about the Palo Alto Next-Gen Firewall integration. It has two input types, TCP and UDP. We have a client that wanted to move from the UDP to the TCP/SSL connection for security, so we did…

---

## [Support for script\_score in function\_score in Golang client](https://discuss.elastic.co/t/support-for-script-score-in-function-score-in-golang-client/350991)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:34pm UTC](https://discuss.elastic.co/t/support-for-script-score-in-function-score-in-golang-client/350991 "2024-01-12T21:34:41Z")

</div>

Hi. The docs show the following example for using script\_score within function\_score: "query" : { "score\_mode": "multiply", "rescore\_query" : { "function\_score" : { "script\_s…

---

## [Plugin logstash.inputs.tcp debug logging showing many "initialized channel" messages](https://discuss.elastic.co/t/plugin-logstash-inputs-tcp-debug-logging-showing-many-initialized-channel-messages/350990)

<div class="topic-metadata">

**Author:** [@bbenne821](https://discuss.elastic.co/u/bbenne821)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:30pm UTC](https://discuss.elastic.co/t/plugin-logstash-inputs-tcp-debug-logging-showing-many-initialized-channel-messages/350990 "2024-01-12T21:30:53Z")

</div>

Running OSS logstash 2.8.2, bundled JDK, on CentOS 7 Linux plugin tcp input specifying "tcp\_keep\_alive=true". Experiencing recurring "closing due: java.net.SocketException: Connection reset" errors for this pipeline (var…

---

## [Force new field to type "keyword" or "text"](https://discuss.elastic.co/t/force-new-field-to-type-keyword-or-text/349665)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 8:49pm UTC](https://discuss.elastic.co/t/force-new-field-to-type-keyword-or-text/349665 "2024-01-12T20:49:30Z")

</div>

Hello, I'm currently struggling with an annoying problem who lead to many lost logs into my Elastic cluster. The problem happen when a field that hasn't been defined into the default filebeat template is created. When …

---

## [Errors: reason\\":\\"Unrecognized compile-time parameter(s)](https://discuss.elastic.co/t/errors-reason-unrecognized-compile-time-parameter-s/350988)

<div class="topic-metadata">

**Author:** [@ElasticDev1](https://discuss.elastic.co/u/ElasticDev1)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 8:28pm UTC](https://discuss.elastic.co/t/errors-reason-unrecognized-compile-time-parameter-s/350988 "2024-01-12T20:28:40Z")

</div>

I have written a scriptquery that should work but I keep getting this error "Unrecognized compile-time parameter(s)". I have even super simplified my script where I just "return true", and continue to get the same error…

---

## [Return just some fields using Transform](https://discuss.elastic.co/t/return-just-some-fields-using-transform/350887)

<div class="topic-metadata">

**Author:** [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Replies:** 7\
**Last updated:** [January 12, 2024, 7:24pm UTC](https://discuss.elastic.co/t/return-just-some-fields-using-transform/350887 "2024-01-12T19:24:41Z")

</div>

Hi there! I'm setting up a latest transform, and I would like to know if is it possible to return just some fields (from the original index) into the new transform index. I've tried to copy those needed fields and then …

---

## [Unable to start Logstash as a service. Errors with: Unable to locate required config /etc/logstash/logstash.conf](https://discuss.elastic.co/t/unable-to-start-logstash-as-a-service-errors-with-unable-to-locate-required-config-etc-logstash-logstash-conf/350938)

<div class="topic-metadata">

**Author:** [@Maiky](https://discuss.elastic.co/u/Maiky)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 6:33pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-as-a-service-errors-with-unable-to-locate-required-config-etc-logstash-logstash-conf/350938 "2024-01-12T18:33:40Z")

</div>

Hi, On RHEL7 I'm able to run logstash v 7.17 directly as root like so: logstash -f /home/maiky/first-pipeline.conf --config.reload.automatic However when trying to run it as a service, I get the following error: Job …

---

## [Toggling rules on or off](https://discuss.elastic.co/t/toggling-rules-on-or-off/350435)

<div class="topic-metadata">

**Author:** [@Gromit27](https://discuss.elastic.co/u/Gromit27)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 5:53pm UTC](https://discuss.elastic.co/t/toggling-rules-on-or-off/350435 "2024-01-12T17:53:52Z")

</div>

Is there any way of knowing if a rule is toggled on or off, can I see that in an index or something? I would like to create a rule that is triggered when a rule is toggeld from status on to status off. BR

---

## [Group results in visualization](https://discuss.elastic.co/t/group-results-in-visualization/350735)

<div class="topic-metadata">

**Author:** [@KaBergmanis](https://discuss.elastic.co/u/KaBergmanis)\
**Replies:** 5\
**Last updated:** [January 12, 2024, 5:31pm UTC](https://discuss.elastic.co/t/group-results-in-visualization/350735 "2024-01-12T17:31:05Z")

</div>

Hello! I've set up search that pulls out OS versions from VPN data feed. All working as expected. Then I created pie chart showing count of OS versions, again, so far so good, please see attached. Issue: There are mul…

---

## [Invalid UTF-8](https://discuss.elastic.co/t/invalid-utf-8/350978)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 7\
**Last updated:** [January 12, 2024, 5:10pm UTC](https://discuss.elastic.co/t/invalid-utf-8/350978 "2024-01-12T17:10:44Z")

</div>

I've been using ruby to decode hex to ascii if (\[field\]) { mutate { gsub =\> \[ "\[field\]", ":", "" \] } ruby { code =\> 'event.set("\[field\]", \[event.get("\[field\]")\].pack("H\*"))' } } but I'v…

---

## [Need Help Monitoring Windows Logs with ELK Stack](https://discuss.elastic.co/t/need-help-monitoring-windows-logs-with-elk-stack/350130)

<div class="topic-metadata">

**Author:** [@qu\_c\_th\_nguy\_n](https://discuss.elastic.co/u/qu_c_th_nguy_n)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 4:59pm UTC](https://discuss.elastic.co/t/need-help-monitoring-windows-logs-with-elk-stack/350130 "2024-01-12T16:59:40Z")

</div>

Hey everyone, I'm a newbie trying to figure out how to monitor Windows log events using ELK Stack and Winlogbeat. I've got them installed, but now I'm a bit lost on what to do with all the info. Any advice, tutorials, …

---

## [Sum average](https://discuss.elastic.co/t/sum-average/350945)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 4:51pm UTC](https://discuss.elastic.co/t/sum-average/350945 "2024-01-12T16:51:24Z")

</div>

could you help me create a dashboard and a canvas, which first adds up to a group and then makes an average, dividing

---

## [Setting default number of replicas for new indexes?](https://discuss.elastic.co/t/setting-default-number-of-replicas-for-new-indexes/350835)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 4\
**Last updated:** [January 12, 2024, 4:49pm UTC](https://discuss.elastic.co/t/setting-default-number-of-replicas-for-new-indexes/350835 "2024-01-12T16:49:49Z")

</div>

addidng index.number\_of\_replicas: 0 to /etc/elasticsearch/elasticsearch.yml doesn't work. With this option elasticsearch doesn't start. at the log i see fatal exception while booting Elasticsearch java.lang.IllegalArgu…

---

## [Declaring static string array](https://discuss.elastic.co/t/declaring-static-string-array/350880)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 3:57pm UTC](https://discuss.elastic.co/t/declaring-static-string-array/350880 "2024-01-12T15:57:07Z")

</div>

So i'v been trying to create a very simple array of strings like so : String\[\] painfull\_lang = \[ "word1","word2","word3"\]; but i keep getting syntax errors Cannot cast from \[java.util.ArrayList\] to \[java.lang.String…

---

## [\[Upgrade from 7.6.2 to 7.17.15\] Cannot find symbol import org.elasticsearch.client.RestClientBuilder;](https://discuss.elastic.co/t/upgrade-from-7-6-2-to-7-17-15-cannot-find-symbol-import-org-elasticsearch-client-restclientbuilder/350894)

<div class="topic-metadata">

**Author:** [@chrisssss](https://discuss.elastic.co/u/chrisssss)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 12:55am UTC](https://discuss.elastic.co/t/upgrade-from-7-6-2-to-7-17-15-cannot-find-symbol-import-org-elasticsearch-client-restclientbuilder/350894 "2024-01-12T00:55:16Z")

</div>

Hello, I am trying to upgrade the elasticsearch for java from 7.6.2 to 7.16.15, but the following classes seem to be deprecated: .......Producer.java:15: error: cannot find symbol import org.elasticsearch.client.RestCl…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=331)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=333)
