# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=336

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 337

---

## [After Successful logstash execution, it's taking time to reflect the same in Kibana](https://discuss.elastic.co/t/after-successful-logstash-execution-its-taking-time-to-reflect-the-same-in-kibana/350645)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [January 9, 2024, 12:50pm UTC](https://discuss.elastic.co/t/after-successful-logstash-execution-its-taking-time-to-reflect-the-same-in-kibana/350645 "2024-01-09T12:50:54Z")

</div>

Hi Team, After Successful logstash execution, it's taking time to reflect the same in Kibana (approx 3 hrs). Please let us know the reason why this is happening. Thanks.

---

## [I want to Install Logstash in EC2 Linux UBUNTU 22.04 and want to run Syslog input Configuration but facing ERROR](https://discuss.elastic.co/t/i-want-to-install-logstash-in-ec2-linux-ubuntu-22-04-and-want-to-run-syslog-input-configuration-but-facing-error/350571)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 3\
**Last updated:** [January 9, 2024, 12:41pm UTC](https://discuss.elastic.co/t/i-want-to-install-logstash-in-ec2-linux-ubuntu-22-04-and-want-to-run-syslog-input-configuration-but-facing-error/350571 "2024-01-09T12:41:04Z")

</div>

I Followed this URL: Installing Logstash | Logstash Reference \[7.14\] | Elastic APT one I followed. Then after the Installation I set the path of bin in Environment variable using below command. 1- Location of logstas…

---

## [Is it possible to do Load balancing using Kafka Input Plugin](https://discuss.elastic.co/t/is-it-possible-to-do-load-balancing-using-kafka-input-plugin/350447)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 5\
**Last updated:** [January 9, 2024, 12:22pm UTC](https://discuss.elastic.co/t/is-it-possible-to-do-load-balancing-using-kafka-input-plugin/350447 "2024-01-09T12:22:26Z")

</div>

This is Configuartion I am Using. input { kafka{ #Insert any one string from the kafka\_brokers\_sasl from the service credential in the Event stream. bootstrap\_servers =\> "\<kafka\_brokers\_sasl\>" #Insert the …

---

## [Why in ElasticsearchOperations in UpdateQuery params put how string but not List object?](https://discuss.elastic.co/t/why-in-elasticsearchoperations-in-updatequery-params-put-how-string-but-not-list-object/350647)

<div class="topic-metadata">

**Author:** [@Marina\_S](https://discuss.elastic.co/u/Marina_S)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 12:02pm UTC](https://discuss.elastic.co/t/why-in-elasticsearchoperations-in-updatequery-params-put-how-string-but-not-list-object/350647 "2024-01-09T12:02:06Z")

</div>

I use ElasticsearchOperations directories its the List Directory String scriptText = "if (ctx.\_source.businessPartnerParams != null) { " + "ctx.\_source.businessPartnerParams.bpName = 'test 3 ' " + "}"; HashMap\<S…

---

## [Elk setup for 6 months logs storage](https://discuss.elastic.co/t/elk-setup-for-6-months-logs-storage/350427)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 16\
**Last updated:** [January 9, 2024, 11:10am UTC](https://discuss.elastic.co/t/elk-setup-for-6-months-logs-storage/350427 "2024-01-09T11:10:59Z")

</div>

What should be my setup for elk if I want to keep the logs for 6 months? My flow is syslog-ng -------kafka --------logstash---------elasticsearch --------kibana . My per day data is 120GB. I want to know the number of…

---

## [How many users can access Elasticsearch and Kibana at the same time?](https://discuss.elastic.co/t/how-many-users-can-access-elasticsearch-and-kibana-at-the-same-time/350375)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 2\
**Last updated:** [January 9, 2024, 11:08am UTC](https://discuss.elastic.co/t/how-many-users-can-access-elasticsearch-and-kibana-at-the-same-time/350375 "2024-01-09T11:08:26Z")

</div>

Hi, I am running a Elasticsearch and Kibana(V8.10) instance on a single windows server which has 8vCPU and 32gb of RAM. I would like to get a rough idea on how much load can the Elastic and Kibana instance can handle a…

---

## [Issues with complex range query](https://discuss.elastic.co/t/issues-with-complex-range-query/350643)

<div class="topic-metadata">

**Author:** [@teemukarvinen](https://discuss.elastic.co/u/teemukarvinen)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 10:46am UTC](https://discuss.elastic.co/t/issues-with-complex-range-query/350643 "2024-01-09T10:46:16Z")

</div>

Hi, I have documents that contain array of allocation for person. Mapping: "Allocations": { "properties": { "endDate": { "type": "date" }, "startDate": { "type": "date" }, "state": { …

---

## [Onprem Elastic Kibana - Fleet - Kubernetes integration -No POD logs or metrics](https://discuss.elastic.co/t/onprem-elastic-kibana-fleet-kubernetes-integration-no-pod-logs-or-metrics/350642)

<div class="topic-metadata">

**Author:** [@chadleywilson](https://discuss.elastic.co/u/chadleywilson)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 10:17am UTC](https://discuss.elastic.co/t/onprem-elastic-kibana-fleet-kubernetes-integration-no-pod-logs-or-metrics/350642 "2024-01-09T10:17:25Z")

</div>

Hi I have setup Elastic with Kibana on an onprem standalone server. I setup using the deb packages. I was pestered by the GUI to use Fleet Server, so after a lot of frustrating fiddling I managed to get it to work and…

---

## [Productionising ELK](https://discuss.elastic.co/t/productionising-elk/350634)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 8:27am UTC](https://discuss.elastic.co/t/productionising-elk/350634 "2024-01-09T08:27:20Z")

</div>

Hello, I have done POC for following use cases using the ELK and metricbeat - a) Monitoring 5-10 servers using metric beats b) stashed data into elasticsearch from an excel files every 15 minutes and created a dashboa…

---

## [Getting this error - java.util.concurrent.CancellationException: Request execution cancelled](https://discuss.elastic.co/t/getting-this-error-java-util-concurrent-cancellationexception-request-execution-cancelled/350579)

<div class="topic-metadata">

**Author:** [@mr.fantastic](https://discuss.elastic.co/u/mr.fantastic)\
**Replies:** 2\
**Last updated:** [January 9, 2024, 7:09am UTC](https://discuss.elastic.co/t/getting-this-error-java-util-concurrent-cancellationexception-request-execution-cancelled/350579 "2024-01-09T07:09:58Z")

</div>

I am facing this issue, where my app tried to send search requests to es and encounters this issue. my client config is - \> RestClientBuilder restClientBuilder = RestClient.builder(new HttpHost(elasticSearchProps.getHo…

---

## [Elastic Agents in K8S ECK with ingest port for Cloudflare HTTP](https://discuss.elastic.co/t/elastic-agents-in-k8s-eck-with-ingest-port-for-cloudflare-http/350618)

<div class="topic-metadata">

**Author:** [@Dallas\_Toth](https://discuss.elastic.co/u/Dallas_Toth)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 2:33am UTC](https://discuss.elastic.co/t/elastic-agents-in-k8s-eck-with-ingest-port-for-cloudflare-http/350618 "2024-01-09T02:33:59Z")

</div>

I have my stack running with ECK and healthy Agents being ran with integrations for kubernetes system elasticsearch and kibana. I have hit an issue with the Cloudflare HTTP integration which now requires a open port of 9…

---

## [How to write queries to pull a specific data in ELK](https://discuss.elastic.co/t/how-to-write-queries-to-pull-a-specific-data-in-elk/349481)

<div class="topic-metadata">

**Author:** [@Kumbum](https://discuss.elastic.co/u/Kumbum)\
**Replies:** 5\
**Last updated:** [January 8, 2024, 8:28pm UTC](https://discuss.elastic.co/t/how-to-write-queries-to-pull-a-specific-data-in-elk/349481 "2024-01-08T20:28:36Z")

</div>

Hi Team, How to write queries to pull specific information in the custom dashboards. I want to pull specific information in the drop-down list in the custom dashboard. I was able to create a drop-down list(control type…

---

## [Unknown error while bulk indexing](https://discuss.elastic.co/t/unknown-error-while-bulk-indexing/350536)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 2\
**Last updated:** [January 8, 2024, 7:04pm UTC](https://discuss.elastic.co/t/unknown-error-while-bulk-indexing/350536 "2024-01-08T19:04:00Z")

</div>

I'm getting some errors during bulk indexing that I cant seem to extract the reason for. Below is my code. Do you see any issues? I feel like this should be pulling out the reason given the explanation in the docs. asyn…

---

## [Logstash is not printing the whole exception log in a single message](https://discuss.elastic.co/t/logstash-is-not-printing-the-whole-exception-log-in-a-single-message/350556)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 4\
**Last updated:** [January 8, 2024, 6:50pm UTC](https://discuss.elastic.co/t/logstash-is-not-printing-the-whole-exception-log-in-a-single-message/350556 "2024-01-08T18:50:46Z")

</div>

Below is my exception log which I'm sending to logstash through filebeat but it only prints the single line of it. It is not considering the whole message: Failed to complete request: org.springframework.web.multipart.M…

---

## [Enrich pipeline - how to get sum of enriched values from array](https://discuss.elastic.co/t/enrich-pipeline-how-to-get-sum-of-enriched-values-from-array/350604)

<div class="topic-metadata">

**Author:** [@pataposha](https://discuss.elastic.co/u/pataposha)\
**Replies:** 1\
**Last updated:** [January 8, 2024, 6:00pm UTC](https://discuss.elastic.co/t/enrich-pipeline-how-to-get-sum-of-enriched-values-from-array/350604 "2024-01-08T18:00:40Z")

</div>

Hi! I'm trying to apply "enrich pipeline" to my data to be able to filter/sort my main index with new fields. These fields are originally stored in a separate index. Let's say I have two indices: index1 - main index …

---

## [How to filter out results using scriptQuery?](https://discuss.elastic.co/t/how-to-filter-out-results-using-scriptquery/350607)

<div class="topic-metadata">

**Author:** [@ElasticDev1](https://discuss.elastic.co/u/ElasticDev1)\
**Replies:** 0\
**Last updated:** [January 8, 2024, 5:54pm UTC](https://discuss.elastic.co/t/how-to-filter-out-results-using-scriptquery/350607 "2024-01-08T17:54:14Z")

</div>

I am trying to filter the results returned by Elasticsearch and I am using painless script, since the data that needs to be used is on the index. My mapping looks like this: { "took": 100, "timed\_out": false, "\_sh…

---

## [Notification of new instances of Metricbeat](https://discuss.elastic.co/t/notification-of-new-instances-of-metricbeat/350479)

<div class="topic-metadata">

**Author:** [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Replies:** 6\
**Last updated:** [January 8, 2024, 5:41pm UTC](https://discuss.elastic.co/t/notification-of-new-instances-of-metricbeat/350479 "2024-01-08T17:41:34Z")

</div>

Hello, I have an 8.8.x Elastic deployment with ~1,000 instances of Metricbeat monitoring systems supporting few hundred products across our enterprise. Each instance of Metricbeat is auto-provisioned (not using Fleet) …

---

## [DataStream Over Index with ILM](https://discuss.elastic.co/t/datastream-over-index-with-ilm/350078)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [January 8, 2024, 4:26pm UTC](https://discuss.elastic.co/t/datastream-over-index-with-ilm/350078 "2024-01-08T16:26:50Z")

</div>

Hi Team, Could you please help me to understand the use of data stream over normal index on which we can apply template and ILM policy to rollover to a new Index once it meets the policy defined in ILM. Because while c…

---

## [How to close the connection using Go client?](https://discuss.elastic.co/t/how-to-close-the-connection-using-go-client/350123)

<div class="topic-metadata">

**Author:** [@elleWajexi](https://discuss.elastic.co/u/elleWajexi)\
**Replies:** 1\
**Last updated:** [January 8, 2024, 4:16pm UTC](https://discuss.elastic.co/t/how-to-close-the-connection-using-go-client/350123 "2024-01-08T16:16:43Z")

</div>

I normally connect to an elastic server, save the connection to a global variable, and reuse it in my entire app. var es \*elasticsearch.Client func elasticConnect() { cfg := elasticsearch.Config{ CloudID: …

---

## [Two node cluster - master assign](https://discuss.elastic.co/t/two-node-cluster-master-assign/350587)

<div class="topic-metadata">

**Author:** [@Oscar\_Yerpes](https://discuss.elastic.co/u/Oscar_Yerpes)\
**Replies:** 5\
**Last updated:** [January 8, 2024, 3:36pm UTC](https://discuss.elastic.co/t/two-node-cluster-master-assign/350587 "2024-01-08T15:36:02Z")

</div>

Hello all, I have a two-node cluster, with node01 designated as master: node.roles: \[ master, data, ingest \] node02 only has node.roles: \[ data, ingest \] In order to switch the master node, can I just simply move th…

---

## [RPM for Kibana 7.17.16 missing](https://discuss.elastic.co/t/rpm-for-kibana-7-17-16-missing/350438)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 7\
**Last updated:** [January 8, 2024, 3:03pm UTC](https://discuss.elastic.co/t/rpm-for-kibana-7-17-16-missing/350438 "2024-01-08T15:03:15Z")

</div>

Hello, it seems like that the RPM for Kibana 7.17.16. is missing in the official https://artifacts.elastic.co/packages/7.x/yum. Why is that and is the version going to be downloadable soon? Thanks in advance

---

## [Script for getting a date field and searching in a nested object both in the same object](https://discuss.elastic.co/t/script-for-getting-a-date-field-and-searching-in-a-nested-object-both-in-the-same-object/350597)

<div class="topic-metadata">

**Author:** [@metopas1991](https://discuss.elastic.co/u/metopas1991)\
**Replies:** 0\
**Last updated:** [January 8, 2024, 2:43pm UTC](https://discuss.elastic.co/t/script-for-getting-a-date-field-and-searching-in-a-nested-object-both-in-the-same-object/350597 "2024-01-08T14:43:49Z")

</div>

Hello there, I am using elasticsearch 8.11 and have an index shown below: PUT /topics/ { "settings": { "index.mapping.total\_fields.limit": 2000, "number\_of\_shards": 1, "analysis": { "filter": { …

---

## [Elastic repository problem?](https://discuss.elastic.co/t/elastic-repository-problem/350370)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 6\
**Last updated:** [January 8, 2024, 2:05pm UTC](https://discuss.elastic.co/t/elastic-repository-problem/350370 "2024-01-08T14:05:22Z")

</div>

Hi, I'm currently upgrade ELK stack tot the lastest version. Yesterday I started with data nodes and master. I notice the link was very slow and at the end of the day, I had to relaunch the download few times to end it…

---

## [How many users can access Elasticsearch and Kibana at the same time?](https://discuss.elastic.co/t/how-many-users-can-access-elasticsearch-and-kibana-at-the-same-time/350392)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 8\
**Last updated:** [January 8, 2024, 1:55pm UTC](https://discuss.elastic.co/t/how-many-users-can-access-elasticsearch-and-kibana-at-the-same-time/350392 "2024-01-08T13:55:27Z")

</div>

Hi, I am running a Elasticsearch and Kibana(V8.10) instance on a single windows server which has 8vCPU and 32gb of RAM. I would like to get a rough idea on how much load can the Elastic and Kibana instance can handle a…

---

## [I am trying to Install SYSLOG input plugin in Logstash which I installed in EC2 Ubuntu Linux but nto able to do this](https://discuss.elastic.co/t/i-am-trying-to-install-syslog-input-plugin-in-logstash-which-i-installed-in-ec2-ubuntu-linux-but-nto-able-to-do-this/350443)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 3\
**Last updated:** [January 8, 2024, 12:35pm UTC](https://discuss.elastic.co/t/i-am-trying-to-install-syslog-input-plugin-in-logstash-which-i-installed-in-ec2-ubuntu-linux-but-nto-able-to-do-this/350443 "2024-01-08T12:35:55Z")

</div>

Setup I followed for Installation: Step to install : 1- Go to root : sudo su - 2- Download and install the Public Signing Key: wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /…

---

## [File beat High Availability to avoid data loss and avoid duplicates records](https://discuss.elastic.co/t/file-beat-high-availability-to-avoid-data-loss-and-avoid-duplicates-records/349358)

<div class="topic-metadata">

**Author:** [@amjad](https://discuss.elastic.co/u/amjad)\
**Replies:** 11\
**Last updated:** [January 8, 2024, 12:32pm UTC](https://discuss.elastic.co/t/file-beat-high-availability-to-avoid-data-loss-and-avoid-duplicates-records/349358 "2024-01-08T12:32:39Z")

</div>

Dear Elastic Community, My main concern is to ensure high availability, avoiding duplicated results. Is it possible to have two Filebeats in two different server to cover for each other in case one of them fails, ensuri…

---

## [Need help in how to show popup in elastic dashboard and also is it possible to call external api's](https://discuss.elastic.co/t/need-help-in-how-to-show-popup-in-elastic-dashboard-and-also-is-it-possible-to-call-external-apis/350432)

<div class="topic-metadata">

**Author:** [@Ashigha\_JR](https://discuss.elastic.co/u/Ashigha_JR)\
**Replies:** 7\
**Last updated:** [January 8, 2024, 11:20am UTC](https://discuss.elastic.co/t/need-help-in-how-to-show-popup-in-elastic-dashboard-and-also-is-it-possible-to-call-external-apis/350432 "2024-01-08T11:20:40Z")

</div>

Hi, Need to show popup in the elastic dashboard while clicking on any link/button. While clicking on link/button we need to call one external api to show the information in the popup. Is any feature available in elastic …

---

## [LogStash filter for matching timestamp example: \[2024-01-04 23:00:00,931\]](https://discuss.elastic.co/t/logstash-filter-for-matching-timestamp-example-2024-01-04-2300-931/350549)

<div class="topic-metadata">

**Author:** [@criss79](https://discuss.elastic.co/u/criss79)\
**Replies:** 2\
**Last updated:** [January 8, 2024, 10:07am UTC](https://discuss.elastic.co/t/logstash-filter-for-matching-timestamp-example-2024-01-04-2300-931/350549 "2024-01-08T10:07:02Z")

</div>

Hi guys, I am having difficulties to match this timestamp format for a log entry that looks like this: \[timestamp\] \[Loglevel\] message Log entry example: \[2024-01-04 23:00:00,931\] \[INFO\] Multi\_Language.UserInfoContain…

---

## [Query slower with ES 5 compared with ES 7](https://discuss.elastic.co/t/query-slower-with-es-5-compared-with-es-7/350563)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 1\
**Last updated:** [January 8, 2024, 10:05am UTC](https://discuss.elastic.co/t/query-slower-with-es-5-compared-with-es-7/350563 "2024-01-08T10:05:33Z")

</div>

Hi experts! We recently migrated from a ES 5 to a 7 version. We observed that some of our original queries became slower than before. An example of query : GET /\[index\_name\]/\_search?search\_type=dfs\_query\_then\_fetch {…

---

## [Kibana Generate PDF function Returns Internal Server Error](https://discuss.elastic.co/t/kibana-generate-pdf-function-returns-internal-server-error/350455)

<div class="topic-metadata">

**Author:** [@mbathann](https://discuss.elastic.co/u/mbathann)\
**Replies:** 3\
**Last updated:** [January 8, 2024, 10:03am UTC](https://discuss.elastic.co/t/kibana-generate-pdf-function-returns-internal-server-error/350455 "2024-01-08T10:03:48Z")

</div>

Hi Guys, Kindly assist I have encountered an issue with KIbana, when i try to generate PDF reports, it returns internal Server error, please see error log message below, I'm new to elastic. Kibana reporting error ":\["e…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=335)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=337)
