# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=335

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 336

---

## [Elastic for Aerospace Data](https://discuss.elastic.co/t/elastic-for-aerospace-data/350732)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 2:09pm UTC](https://discuss.elastic.co/t/elastic-for-aerospace-data/350732 "2024-01-10T14:09:27Z")

</div>

Hi everyone, im currently working in a project about aerospace and im considering ELK to store data and do some basic data visualization. The data are GPS coordinate, gyro data, speeds and stuff like that. Anyone have…

---

## [Enterprise-search.yml configuration](https://discuss.elastic.co/t/enterprise-search-yml-configuration/350757)

<div class="topic-metadata">

**Author:** [@awccu](https://discuss.elastic.co/u/awccu)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 2:02pm UTC](https://discuss.elastic.co/t/enterprise-search-yml-configuration/350757 "2024-01-10T14:02:12Z")

</div>

I am having trouble configuring the enterprise-search.yml. Specifically, it is unclear to me how to proceed with configuring enterprise search when the ssl method of configuring the elasticsearch cluster and the kibana w…

---

## [Transform Preview fails with "Please provide a transform \[id\] or the config object"](https://discuss.elastic.co/t/transform-preview-fails-with-please-provide-a-transform-id-or-the-config-object/350730)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 3\
**Last updated:** [January 10, 2024, 10:59am UTC](https://discuss.elastic.co/t/transform-preview-fails-with-please-provide-a-transform-id-or-the-config-object/350730 "2024-01-10T10:59:33Z")

</div>

Hi All, I'm trying to get a transform working, my first one admittedly, but regardless of whether I do API or via browser setup it errors. An example transform preview: POST \_transform/\_preview { "source": { "ind…

---

## [Unable to ship logs using Winlogbeat due to poor Windows API Performance](https://discuss.elastic.co/t/unable-to-ship-logs-using-winlogbeat-due-to-poor-windows-api-performance/350729)

<div class="topic-metadata">

**Author:** [@TheGrea](https://discuss.elastic.co/u/TheGrea)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 10:26am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-using-winlogbeat-due-to-poor-windows-api-performance/350729 "2024-01-10T10:26:22Z")

</div>

Hi Community, when I ship Windows Event Logs from a Windows Event Collector Log, that contain Logs where the provider is not registered on the WEC to Elasticsearch using Winlogbeat (v 8.9.0) the performance is so poor, …

---

## [How Could I send my logs from One EC2 instance to Other EC2 instance](https://discuss.elastic.co/t/how-could-i-send-my-logs-from-one-ec2-instance-to-other-ec2-instance/350724)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 9:59am UTC](https://discuss.elastic.co/t/how-could-i-send-my-logs-from-one-ec2-instance-to-other-ec2-instance/350724 "2024-01-10T09:59:55Z")

</div>

I configured two EC2 instance. In one instance I have Logstash and from other instance I want to send audit logs to Logstash. I am using SYSLOG input plugin to collect the events. input { syslog { port =\> 5…

---

## [Life cycle of a log submitted to elastic search](https://discuss.elastic.co/t/life-cycle-of-a-log-submitted-to-elastic-search/350605)

<div class="topic-metadata">

**Author:** [@minh.tran](https://discuss.elastic.co/u/minh.tran)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 9:59am UTC](https://discuss.elastic.co/t/life-cycle-of-a-log-submitted-to-elastic-search/350605 "2024-01-10T09:59:23Z")

</div>

When a log is submitted to Elasticsearch, I was wondering what is the lifecycle. We specify the index format so we know which view it'll be picked up in kibana. But when does it get indexed, how do we know which which …

---

## [Indices not being deleted with the ILM policy set](https://discuss.elastic.co/t/indices-not-being-deleted-with-the-ilm-policy-set/350658)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 9:54am UTC](https://discuss.elastic.co/t/indices-not-being-deleted-with-the-ilm-policy-set/350658 "2024-01-10T09:54:24Z")

</div>

Hello, I have set an ILM policy for filebeat index as below. The purpose of implementing the ILM policy was because of the huge disk space utilization because of the indices data. Hot phase (Required) Rollover:…

---

## [Fleet-Server Connection Cannot be Confirmed](https://discuss.elastic.co/t/fleet-server-connection-cannot-be-confirmed/350683)

<div class="topic-metadata">

**Author:** [@houstonragan](https://discuss.elastic.co/u/houstonragan)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 9:48am UTC](https://discuss.elastic.co/t/fleet-server-connection-cannot-be-confirmed/350683 "2024-01-10T09:48:42Z")

</div>

I am in the process of trying to set up an Elastic stack and am running into problems with setting up a Fleet Server. My Elasticsearch and Kibana are all set up and performing well, but I need a Fleet Server to start set…

---

## [Cluster shards disbalance](https://discuss.elastic.co/t/cluster-shards-disbalance/350714)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 3\
**Last updated:** [January 10, 2024, 9:41am UTC](https://discuss.elastic.co/t/cluster-shards-disbalance/350714 "2024-01-10T09:41:19Z")

</div>

Hello. Thanks in advance for any help I have a 3-nodes cluster containing different amount of shards on each node. Earlier it runs elasticsearch 8.4.3 and all was nearly-fine, but after upgrading to 8.11.1 things seems …

---

## [Elasticsearch Cluster Disk Write Performance](https://discuss.elastic.co/t/elasticsearch-cluster-disk-write-performance/350711)

<div class="topic-metadata">

**Author:** [@sheng855174](https://discuss.elastic.co/u/sheng855174)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 9:22am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-disk-write-performance/350711 "2024-01-10T09:22:16Z")

</div>

Hello everyone, I have an ELK cluster and encountered performance problems, which caused most data to be written 10 minutes slower than the actual time. This problem occurs occasionally. I want to know the cause of thi…

---

## [Fuziness not working when querying in larger index](https://discuss.elastic.co/t/fuziness-not-working-when-querying-in-larger-index/350503)

<div class="topic-metadata">

**Author:** [@SriramOnGrid](https://discuss.elastic.co/u/SriramOnGrid)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 8:49am UTC](https://discuss.elastic.co/t/fuziness-not-working-when-querying-in-larger-index/350503 "2024-01-10T08:49:44Z")

</div>

Hi team, I wanted to fuziness for the purpose of finding the words with minor spelling mistakes. The query I am using is { "query": { "bool": { "must": \[ { "match": { "respon…

---

## [Updating Elasticsearch Indices conditionally when referring to 2 database table](https://discuss.elastic.co/t/updating-elasticsearch-indices-conditionally-when-referring-to-2-database-table/350663)

<div class="topic-metadata">

**Author:** [@jainesh\_singh](https://discuss.elastic.co/u/jainesh_singh)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 6:45am UTC](https://discuss.elastic.co/t/updating-elasticsearch-indices-conditionally-when-referring-to-2-database-table/350663 "2024-01-10T06:45:37Z")

</div>

Description: We have two SQL tables: FileDetail for storing file details and FileUserActivity for file activities. Using Logstash, we're indexing data into Elasticsearch with a flat index approach, combining file detail…

---

## [Remove Parent fields in logstash filter](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 6:45am UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646 "2024-01-10T06:45:26Z")

</div>

I have large log json message which I have to parse to visualize at kibana. I have used json filter first to parse message but there are generated lots of parent and dynamic fields. Due to dynamic fields in each log me…

---

## [Elasticsearch Data Streams: Update Strategies, Concerns, and Alternatives](https://discuss.elastic.co/t/elasticsearch-data-streams-update-strategies-concerns-and-alternatives/350546)

<div class="topic-metadata">

**Author:** [@jainesh\_singh](https://discuss.elastic.co/u/jainesh_singh)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-data-streams-update-strategies-concerns-and-alternatives/350546 "2024-01-10T06:32:19Z")

</div>

Hi Team, I am stuck and need your help!! UseCase: I am using elasticsearch where i am storing activities in a data stream. I want to perform update operation on this Data stream. There is time based range queries tha…

---

## [●\[TLS\] How to resolve the security concern of writing plaintext usernames and passwords in the yml file](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 4\
**Last updated:** [January 10, 2024, 6:15am UTC](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626 "2024-01-10T06:15:30Z")

</div>

I have a question about https communication (encryption) between "client PC ←→ Elasticsearch server" & "Kibana server ←→ Elasticsearch server". We are concerned that username/password information may be leaked by specif…

---

## [Regarding encrypted communication between Elasticsearch servers](https://discuss.elastic.co/t/regarding-encrypted-communication-between-elasticsearch-servers/350621)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 2\
**Last updated:** [January 10, 2024, 1:39am UTC](https://discuss.elastic.co/t/regarding-encrypted-communication-between-elasticsearch-servers/350621 "2024-01-10T01:39:35Z")

</div>

Hello from Japan I have a question for you respected engineers. I am an inexperienced Japanese engineer with Elasticsearch. I prepared three servers with Elasticsearch V8.11 installed and built an Elastic cluster. I …

---

## [Pre v5 index compatibility with Elasticsearch v8](https://discuss.elastic.co/t/pre-v5-index-compatibility-with-elasticsearch-v8/350680)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 5\
**Last updated:** [January 9, 2024, 11:14pm UTC](https://discuss.elastic.co/t/pre-v5-index-compatibility-with-elasticsearch-v8/350680 "2024-01-09T23:14:55Z")

</div>

Per Upgrade Elasticsearch | Elasticsearch Guide \[8.11\] | Elastic, "indices created in 6.x or earlier...use the archive functionality" which makes it sound like any version \<= 6 should work. Maybe slightly contradictory,…

---

## [Kibana : How to search a value in JSON field](https://discuss.elastic.co/t/kibana-how-to-search-a-value-in-json-field/350321)

<div class="topic-metadata">

**Author:** [@Aziza\_AJOUAOU](https://discuss.elastic.co/u/Aziza_AJOUAOU)\
**Replies:** 8\
**Last updated:** [January 9, 2024, 6:00pm UTC](https://discuss.elastic.co/t/kibana-how-to-search-a-value-in-json-field/350321 "2024-01-09T18:00:38Z")

</div>

Hello .I would like to searck in kibana all documents that contains this specific value Y100000005 . So , i tried in search bar : But Kibana dosen't return Any document! I have in kibana the document below (it con…

---

## [Load Balance Output to both hot nodes](https://discuss.elastic.co/t/load-balance-output-to-both-hot-nodes/350415)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 13\
**Last updated:** [January 9, 2024, 5:53pm UTC](https://discuss.elastic.co/t/load-balance-output-to-both-hot-nodes/350415 "2024-01-09T17:53:30Z")

</div>

I have two hot nodes in my cluster. I currently just have on node in the Outputs. Can I just add the 2nd node to the list of outputs?

---

## [GeoIP Filter in ECS-Compatiblity mode requires a \`target\` when \`source\` is not an \`ip\` sub-field, eg. \[client\]\[ip\]](https://discuss.elastic.co/t/geoip-filter-in-ecs-compatiblity-mode-requires-a-target-when-source-is-not-an-ip-sub-field-eg-client-ip/350343)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 3\
**Last updated:** [January 9, 2024, 5:19pm UTC](https://discuss.elastic.co/t/geoip-filter-in-ecs-compatiblity-mode-requires-a-target-when-source-is-not-an-ip-sub-field-eg-client-ip/350343 "2024-01-09T17:19:26Z")

</div>

Hi, i'm trying to setup Parsing Logs with Logstash | Logstash Reference \[8.11\] | Elastic. But i get errors: \[2024-01-04T00:06:45,246\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline error {:pipeline\_id=\>"main", :exc…

---

## [Output based on grok message](https://discuss.elastic.co/t/output-based-on-grok-message/350670)

<div class="topic-metadata">

**Author:** [@Brandon\_Kauffman](https://discuss.elastic.co/u/Brandon_Kauffman)\
**Replies:** 3\
**Last updated:** [January 9, 2024, 5:17pm UTC](https://discuss.elastic.co/t/output-based-on-grok-message/350670 "2024-01-09T17:17:40Z")

</div>

I am trying to output based on different sysloghosts input { udp { port =\> 5010 type =\> "obs\_test\_udp" } } filter { grok { match =\> {"message" =\> "\<%{POSINT:syslog\_priority}\>%{POSINT:syslog\_version} %{T…

---

## [co.elastic.clients.json.JsonpMappingException: Error deserializing co.elastic.clients.elasticsearch.\_types.query\_dsl.MatchQuery: Invalid enum 'NONE'](https://discuss.elastic.co/t/co-elastic-clients-json-jsonpmappingexception-error-deserializing-co-elastic-clients-elasticsearch-types-query-dsl-matchquery-invalid-enum-none/350660)

<div class="topic-metadata">

**Author:** [@MADHAV\_JHA\_Govind](https://discuss.elastic.co/u/MADHAV_JHA_Govind)\
**Replies:** 7\
**Last updated:** [January 9, 2024, 5:13pm UTC](https://discuss.elastic.co/t/co-elastic-clients-json-jsonpmappingexception-error-deserializing-co-elastic-clients-elasticsearch-types-query-dsl-matchquery-invalid-enum-none/350660 "2024-01-09T17:13:09Z")

</div>

Hi Team, I am facing issue while sending the query as json to Elasticsearch using latest client which is 8.11.1 please help me if i Iam trying anything wrong. StringReader queryJson = new StringReader(query); SearchRes…

---

## [Not able to get orchestrator.cluster.name and some info in kubernetes dashboards are not getting populated](https://discuss.elastic.co/t/not-able-to-get-orchestrator-cluster-name-and-some-info-in-kubernetes-dashboards-are-not-getting-populated/350272)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 1\
**Last updated:** [January 9, 2024, 4:25pm UTC](https://discuss.elastic.co/t/not-able-to-get-orchestrator-cluster-name-and-some-info-in-kubernetes-dashboards-are-not-getting-populated/350272 "2024-01-09T16:25:53Z")

</div>

i have installed fleet managed elastic agent on my kubernetes env which is already installed with kube-state-metrics but some of the dashboards are not getting populated properly and orchestrator.cluster.name is field is…

---

## [TLS Key location after installation](https://discuss.elastic.co/t/tls-key-location-after-installation/350615)

<div class="topic-metadata">

**Author:** [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Replies:** 5\
**Last updated:** [January 9, 2024, 4:06pm UTC](https://discuss.elastic.co/t/tls-key-location-after-installation/350615 "2024-01-09T16:06:09Z")

</div>

I'm on my second attempt at installing ES and Metricbeats to monitor the node (Ubuntu 22.04). I'm still unable to get Metricbeat to connect due to lack of the TLS key, which I can't locate. Per the doc at Install Elasti…

---

## [How to replace multiple newlines with two newlines in ingest pipeline gsub](https://discuss.elastic.co/t/how-to-replace-multiple-newlines-with-two-newlines-in-ingest-pipeline-gsub/350570)

<div class="topic-metadata">

**Author:** [@Bowfish](https://discuss.elastic.co/u/Bowfish)\
**Replies:** 6\
**Last updated:** [January 9, 2024, 3:56pm UTC](https://discuss.elastic.co/t/how-to-replace-multiple-newlines-with-two-newlines-in-ingest-pipeline-gsub/350570 "2024-01-09T15:56:59Z")

</div>

I want to replace multiple (more than 3) newlines (\\n\\n\\n) with two newlines (\\n\\n). If I set "\\n\\n" as a replacement string the the gsub object it replaces \\n\\n\\n\\ with nn. Here you can find my \_simulate ingest pipelin…

---

## [Display current date in Canvas Workpad](https://discuss.elastic.co/t/display-current-date-in-canvas-workpad/350466)

<div class="topic-metadata">

**Author:** [@Matheus\_Rodrigues](https://discuss.elastic.co/u/Matheus_Rodrigues)\
**Replies:** 1\
**Last updated:** [January 9, 2024, 2:42pm UTC](https://discuss.elastic.co/t/display-current-date-in-canvas-workpad/350466 "2024-01-09T14:42:44Z")

</div>

Hello, I want to display the current day in text format on my Canvas Workpad, e.g.: 05th, December, or something like that. Do you have any ideas on how I can do it? FYI the date information is in the @timestamp field. …

---

## [ElasticAbout Elasticsearch & Kibana process persistence](https://discuss.elastic.co/t/elasticabout-elasticsearch-kibana-process-persistence/350622)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [January 9, 2024, 2:39pm UTC](https://discuss.elastic.co/t/elasticabout-elasticsearch-kibana-process-persistence/350622 "2024-01-09T14:39:41Z")

</div>

Hello from Japan I have a question for you respected engineers. I am an inexperienced Japanese engineer with Elasticsearch. I have a question about how to make Elasticsearch & Kibana version 8.11 process persistent us…

---

## [Elastic plugin SSL handskake](https://discuss.elastic.co/t/elastic-plugin-ssl-handskake/350661)

<div class="topic-metadata">

**Author:** [@Francisco\_Javier\_Ort](https://discuss.elastic.co/u/Francisco_Javier_Ort)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 1:58pm UTC](https://discuss.elastic.co/t/elastic-plugin-ssl-handskake/350661 "2024-01-09T13:58:40Z")

</div>

Hi All, We have a plugin installed in elastic that connects to an url, when trying to connbect we get an SSLHandshake exception We have deployed the application in a GKE cluster and all the certificates looks correctl…

---

## [Best practice to aggregate by issue status](https://discuss.elastic.co/t/best-practice-to-aggregate-by-issue-status/350596)

<div class="topic-metadata">

**Author:** [@lizozom](https://discuss.elastic.co/u/lizozom)\
**Replies:** 4\
**Last updated:** [January 9, 2024, 1:15pm UTC](https://discuss.elastic.co/t/best-practice-to-aggregate-by-issue-status/350596 "2024-01-09T13:15:33Z")

</div>

I have an index that stores logs of issue status changes (imaging something like GH issues). An issue can be either open or closed. I want to show a metric of how many issues are currently open or closed. What would be…

---

## [Как в ElasticsearchOperations в UpdateQuery в скрипте достать params листом а не стрингой?](https://discuss.elastic.co/t/elasticsearchoperations-updatequery-params/350653)

<div class="topic-metadata">

**Author:** [@Marina\_S](https://discuss.elastic.co/u/Marina_S)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 12:53pm UTC](https://discuss.elastic.co/t/elasticsearchoperations-updatequery-params/350653 "2024-01-09T12:53:54Z")

</div>

Я использую ElasticsearchOperations directories это лист объектов List Directory String scriptText = "if (ctx.\_source.businessPartnerParams != null) { " + "ctx.\_source.businessPartnerParams.bpName = 'test 3 ' " + "}"…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=334)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=336)
