# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=337

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 338

---

## [Delete by query deletes only 1000 documents, then quits](https://discuss.elastic.co/t/delete-by-query-deletes-only-1000-documents-then-quits/350529)

<div class="topic-metadata">

**Author:** [@d8d4a522fb1d394d9705](https://discuss.elastic.co/u/d8d4a522fb1d394d9705)\
**Replies:** 7\
**Last updated:** [January 8, 2024, 9:14am UTC](https://discuss.elastic.co/t/delete-by-query-deletes-only-1000-documents-then-quits/350529 "2024-01-08T09:14:41Z")

</div>

I am using the following the api to delete documents older than 60 days: POST /index\_name/\_delete\_by\_query?conflicts=proceed { "query": { "range": { "@timestamp": {"lte": "now-60d/d"} } } } My inde…

---

## [Partial ELK component upgrade](https://discuss.elastic.co/t/partial-elk-component-upgrade/350559)

<div class="topic-metadata">

**Author:** [@Septianingrum.17](https://discuss.elastic.co/u/Septianingrum.17)\
**Replies:** 1\
**Last updated:** [January 8, 2024, 8:52am UTC](https://discuss.elastic.co/t/partial-elk-component-upgrade/350559 "2024-01-08T08:52:53Z")

</div>

Hi All, Currently I have run a vulnerability scan and it produces the following information: Users should upgrade to Kibana version 8.11.1 If the Elasticsearch, Logstash and Kibana that I currently use use version 8.…

---

## [Getting incomplete request body in Elasticsearch audit log](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 2\
**Last updated:** [January 8, 2024, 8:41am UTC](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543 "2024-01-08T08:41:57Z")

</div>

I have executed few security APIs , for those I am getting incomplete request body in Elasticsearch Audit log. Below are the example: Query 1: POST /\_security/oauth2/token { "grant\_type": "refresh\_token", "refresh\_…

---

## [I'm trying to build new integration](https://discuss.elastic.co/t/im-trying-to-build-new-integration/349866)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 9\
**Last updated:** [January 8, 2024, 8:17am UTC](https://discuss.elastic.co/t/im-trying-to-build-new-integration/349866 "2024-01-08T08:17:29Z")

</div>

hello, i'm trying to create new integration for collecting k6 metrics via rest api. I just don't understand how can i test my integration i mean i'm trying to connect k6 but idk how can i see it? is there a command for t…

---

## [Dashboards in ndjson format](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128)

<div class="topic-metadata">

**Author:** [@Jean\_BARBIER](https://discuss.elastic.co/u/Jean_BARBIER)\
**Replies:** 6\
**Last updated:** [January 8, 2024, 8:15am UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128 "2024-01-08T08:15:21Z")

</div>

Hello, In the package auditbeat-oss-8.11.2-linux-x86\_64, the dashboards can be found, but they are in json format. Since kibana 7.3 the import format is ndjson. Is there a way to find them in ndjson format ? regards

---

## [Invalid NEST response built from a unsuccessful () low level call on POST: /logs-%2A/\_search?typed\_keys=true](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-unsuccessful-low-level-call-on-post-logs-2a-search-typed-keys-true/350452)

<div class="topic-metadata">

**Author:** [@Sunil\_Bisht](https://discuss.elastic.co/u/Sunil_Bisht)\
**Replies:** 3\
**Last updated:** [January 8, 2024, 8:09am UTC](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-unsuccessful-low-level-call-on-post-logs-2a-search-typed-keys-true/350452 "2024-01-08T08:09:34Z")

</div>

\# Audit trail of this API call: - \[1\] ProductCheckOnStartup: Took: 00:00:03.0728820 - \[2\] ProductCheckFailure: Node: https://\*\*\*\*\*\*\*.aws.found.io:9243/ Took: 00:00:03.0531380 # OriginalException: Elasticsearch.Net.Ela…

---

## [Which installation is better for production](https://discuss.elastic.co/t/which-installation-is-better-for-production/350500)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 5\
**Last updated:** [January 8, 2024, 5:30am UTC](https://discuss.elastic.co/t/which-installation-is-better-for-production/350500 "2024-01-08T05:30:20Z")

</div>

hi, I want to run ELK 8.11 on production environment on oracle linux VMs, Which type of installation is preferred for production environment? RPM based or Archive based? Also, can we use another user apart from "root" …

---

## [In Docker can we use 2 Logstash push log in to one elastic seach?](https://discuss.elastic.co/t/in-docker-can-we-use-2-logstash-push-log-in-to-one-elastic-seach/350542)

<div class="topic-metadata">

**Author:** [@2\_3\_0\_8](https://discuss.elastic.co/u/2_3_0_8)\
**Replies:** 0\
**Last updated:** [January 8, 2024, 3:34am UTC](https://discuss.elastic.co/t/in-docker-can-we-use-2-logstash-push-log-in-to-one-elastic-seach/350542 "2024-01-08T03:34:35Z")

</div>

Hi I want to know it can make it ? In Docker can we use 2 or more Logstash push log in to one elastic seach in one VM? if i have many gateway api (1VM for 1 gateway) for my plane i need to use 1 VM to create many logst…

---

## [Use index to judge data,but not found](https://discuss.elastic.co/t/use-index-to-judge-data-but-not-found/350446)

<div class="topic-metadata">

**Author:** [@yunke\_yin](https://discuss.elastic.co/u/yunke_yin)\
**Replies:** 4\
**Last updated:** [January 8, 2024, 1:45am UTC](https://discuss.elastic.co/t/use-index-to-judge-data-but-not-found/350446 "2024-01-08T01:45:23Z")

</div>

please help me. I got many data of the same type. In some cases, the known data must exist, but I need to further confirm which index the data is under. I chose to judge in the following way, but cannot found then throw…

---

## [Changing an existing field type](https://discuss.elastic.co/t/changing-an-existing-field-type/350538)

<div class="topic-metadata">

**Author:** [@m4hjub](https://discuss.elastic.co/u/m4hjub)\
**Replies:** 2\
**Last updated:** [January 8, 2024, 1:12am UTC](https://discuss.elastic.co/t/changing-an-existing-field-type/350538 "2024-01-08T01:12:34Z")

</div>

Hello, I have a requirement to change a field type from String to float. What's the best method without reindexing? In the past we changed the field type, reindexed and had to wait for all the old index with old field t…

---

## [Slow ANN Hybrid search](https://discuss.elastic.co/t/slow-ann-hybrid-search/349837)

<div class="topic-metadata">

**Author:** [@steve\_lee](https://discuss.elastic.co/u/steve_lee)\
**Replies:** 5\
**Last updated:** [January 8, 2024, 12:42am UTC](https://discuss.elastic.co/t/slow-ann-hybrid-search/349837 "2024-01-08T00:42:35Z")

</div>

Hi, I have implemented vector hybrid search using ES dense\_vector field and KNN option in the search API. I have two index with vector field with 512 dimension embeddings (dot\_product). Each index have about 10 milli…

---

## [Elasticsearch shows float types as string in output](https://discuss.elastic.co/t/elasticsearch-shows-float-types-as-string-in-output/350535)

<div class="topic-metadata">

**Author:** [@Ata\_Zangene](https://discuss.elastic.co/u/Ata_Zangene)\
**Replies:** 2\
**Last updated:** [January 7, 2024, 6:08pm UTC](https://discuss.elastic.co/t/elasticsearch-shows-float-types-as-string-in-output/350535 "2024-01-07T18:08:53Z")

</div>

I have a sample schema like this "coordinate": { "properties": { "geo": { "type": "geo\_point" }, "latitude": { "type": "float" }, "longitude": { "type": "float" …

---

## [Unable to create an enrollment token. Elasticsearch node HTTP layer SSL configuration is not configured with a keystore](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-elasticsearch-node-http-layer-ssl-configuration-is-not-configured-with-a-keystore/350527)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 1\
**Last updated:** [January 7, 2024, 2:41pm UTC](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-elasticsearch-node-http-layer-ssl-configuration-is-not-configured-with-a-keystore/350527 "2024-01-07T14:41:13Z")

</div>

Hi Team, I am upgrading elasticsearch from 7.17.0 to 8.11 on ubuntu 22.04 I have completed elasticsearch installation and x-pack while I am creating token for cluster it is showing below error Error: Unable to create …

---

## [Drill down o kibana table based on field's value](https://discuss.elastic.co/t/drill-down-o-kibana-table-based-on-fields-value/349643)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 2\
**Last updated:** [January 7, 2024, 10:21am UTC](https://discuss.elastic.co/t/drill-down-o-kibana-table-based-on-fields-value/349643 "2024-01-07T10:21:35Z")

</div>

I have a data table in my dashboard and the table is split based on a field whose values are names of different cities and table will show the count of different cities. Is it possible to drill down based on the city's n…

---

## [Custom UDP logs are only listening on ipv6](https://discuss.elastic.co/t/custom-udp-logs-are-only-listening-on-ipv6/350497)

<div class="topic-metadata">

**Author:** [@phirestalker](https://discuss.elastic.co/u/phirestalker)\
**Replies:** 7\
**Last updated:** [January 7, 2024, 7:06am UTC](https://discuss.elastic.co/t/custom-udp-logs-are-only-listening-on-ipv6/350497 "2024-01-07T07:06:00Z")

</div>

I set up some custom UDP port integrations. I noticed that a lot of logs were not coming in, so I did netstat on the host. It turns out that it is only listening on ipv6. How can I set it to listen on both or only ipv4?

---

## [Problem with loading dashboards - Data too large](https://discuss.elastic.co/t/problem-with-loading-dashboards-data-too-large/350437)

<div class="topic-metadata">

**Author:** [@PustyB](https://discuss.elastic.co/u/PustyB)\
**Replies:** 3\
**Last updated:** [January 7, 2024, 4:52am UTC](https://discuss.elastic.co/t/problem-with-loading-dashboards-data-too-large/350437 "2024-01-07T04:52:38Z")

</div>

I've been having a problem lately with my elastica stack that was installed on kubernetes. Well, when trying to visualize myself data in kiban when I select a longer period of time (more data) it pops up this error: Req…

---

## [Can you modify web scraper extraction rules for reserved field name: body\_content?](https://discuss.elastic.co/t/can-you-modify-web-scraper-extraction-rules-for-reserved-field-name-body-content/350513)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 0\
**Last updated:** [January 6, 2024, 4:21pm UTC](https://discuss.elastic.co/t/can-you-modify-web-scraper-extraction-rules-for-reserved-field-name-body-content/350513 "2024-01-06T16:21:27Z")

</div>

By default, body\_content grabs content that's irrelevant for my use case. Instead of creating a new field with custom extraction rules, I'd rather edit the rules for body\_content to avoid creating unused fields in my doc…

---

## [The s3 input for creating the index does not work with preffix and csv files](https://discuss.elastic.co/t/the-s3-input-for-creating-the-index-does-not-work-with-preffix-and-csv-files/350496)

<div class="topic-metadata">

**Author:** [@Marcos\_Daniel\_Santos](https://discuss.elastic.co/u/Marcos_Daniel_Santos)\
**Replies:** 3\
**Last updated:** [January 6, 2024, 12:33pm UTC](https://discuss.elastic.co/t/the-s3-input-for-creating-the-index-does-not-work-with-preffix-and-csv-files/350496 "2024-01-06T12:33:04Z")

</div>

Hi everyone, I have a bucekt s3 with 2 csv files, one that is a securityhub repot and the other a guardduty report, both AWS services and security. I'm using the preffix to get my object, using the logstash -f file.conf…

---

## [How to replace unicode \\u00a0 with space with ingest pipeline processor](https://discuss.elastic.co/t/how-to-replace-unicode-u00a0-with-space-with-ingest-pipeline-processor/350484)

<div class="topic-metadata">

**Author:** [@Bowfish](https://discuss.elastic.co/u/Bowfish)\
**Replies:** 1\
**Last updated:** [January 6, 2024, 12:29pm UTC](https://discuss.elastic.co/t/how-to-replace-unicode-u00a0-with-space-with-ingest-pipeline-processor/350484 "2024-01-06T12:29:52Z")

</div>

I want to replace all non breaking space (\\u00a0) characters with a normal spaces in a gsub processor in an ingest pipeline. I tried it with this: POST \_ingest/pipeline/\_simulate { "pipeline": { "processors": \[ …

---

## [Adding support for new protocols under packetbeat](https://discuss.elastic.co/t/adding-support-for-new-protocols-under-packetbeat/350425)

<div class="topic-metadata">

**Author:** [@ACodingfreak](https://discuss.elastic.co/u/ACodingfreak)\
**Replies:** 2\
**Last updated:** [January 6, 2024, 12:38am UTC](https://discuss.elastic.co/t/adding-support-for-new-protocols-under-packetbeat/350425 "2024-01-06T00:38:31Z")

</div>

Hi All, I do have couple of questions with respect to packetbeat and need your help in understanding the same Is there any updated article or document in adding support for new protocols in packetbeat? Did anyone …

---

## [Help understanding boolean should query results](https://discuss.elastic.co/t/help-understanding-boolean-should-query-results/350495)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 10:46pm UTC](https://discuss.elastic.co/t/help-understanding-boolean-should-query-results/350495 "2024-01-05T22:46:45Z")

</div>

Hello, I'm not understanding why the following query does not show any documents hits for the "support\_files.bgp\_evpn\_routes" field. It does show hits for the first match\_phrase (name a). As a troubleshooting test, I c…

---

## [Kibana Maps Service Custom Icons in the Layer Style Section](https://discuss.elastic.co/t/kibana-maps-service-custom-icons-in-the-layer-style-section/205304)

<div class="topic-metadata">

**Author:** [@14kporter](https://discuss.elastic.co/u/14kporter)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 8:37pm UTC](https://discuss.elastic.co/t/kibana-maps-service-custom-icons-in-the-layer-style-section/205304 "2024-01-05T20:37:37Z")

</div>

Currently I am using Kibana Map Service and plotting Geopoints. I want to change the icons of the points to something that is not one of the pre-selected Maiki icons and import another icon in the SVG format. Is this …

---

## [Query and Aggregation result doesn't match](https://discuss.elastic.co/t/query-and-aggregation-result-doesnt-match/350362)

<div class="topic-metadata">

**Author:** [@shufan](https://discuss.elastic.co/u/shufan)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:07pm UTC](https://discuss.elastic.co/t/query-and-aggregation-result-doesnt-match/350362 "2024-01-05T19:07:59Z")

</div>

Hi team, got a strange issue when doing query and aggregation. Here is my script GET userindex/\_search { "\_source":\["response4"\], "query":{ "bool": { "filter": \[ {"script": { "script": { …

---

## [Percolating returns more results that i expect](https://discuss.elastic.co/t/percolating-returns-more-results-that-i-expect/350481)

<div class="topic-metadata">

**Author:** [@oli.girling](https://discuss.elastic.co/u/oli.girling)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 6:56pm UTC](https://discuss.elastic.co/t/percolating-returns-more-results-that-i-expect/350481 "2024-01-05T18:56:42Z")

</div>

Smashing my head against the wall with this, wondering if anyone can point anything out thats obvious. Using ES 5.6 (I know its out of date, im in the process of upgrading) I have an advert in ES GET /gb/classified/15…

---

## [Installed Elastic-Agent cannot be removed](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473)

<div class="topic-metadata">

**Author:** [@ghuie](https://discuss.elastic.co/u/ghuie)\
**Replies:** 9\
**Last updated:** [January 5, 2024, 6:50pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473 "2024-01-05T18:50:54Z")

</div>

So, I have a self-hosted ELK Stack (v. 8.11) in which I've been working for a few weeks. I've configured the certificates using the elasticsearch-certutil util and Elastic + Kibana are working fine. After that I wanted…

---

## [Elastic agent uninstall](https://discuss.elastic.co/t/elastic-agent-uninstall/349659)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 9\
**Last updated:** [January 5, 2024, 5:53pm UTC](https://discuss.elastic.co/t/elastic-agent-uninstall/349659 "2024-01-05T17:53:32Z")

</div>

Hello, it seeemed to be simple but, im trying to uninstall elastic agent, but unfortunately no luck root@elk:/opt/elastic-agent-8.11.2-linux-x86\_64# elastic-agent uninstall Error: can only be uninstalled by executing …

---

## [Visualize documents that have multiple versions](https://discuss.elastic.co/t/visualize-documents-that-have-multiple-versions/350480)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 5:25pm UTC](https://discuss.elastic.co/t/visualize-documents-that-have-multiple-versions/350480 "2024-01-05T17:25:00Z")

</div>

Hello community! I am trying to build visualizations in Kibana for documents that have multiple revisions. Just in case, I know that Elasticsearch does not keep the previous versions of the documents, however, in this t…

---

## [How i put a response into a kibana URL](https://discuss.elastic.co/t/how-i-put-a-response-into-a-kibana-url/350410)

<div class="topic-metadata">

**Author:** [@Natanael\_Rodrigues](https://discuss.elastic.co/u/Natanael_Rodrigues)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 3:25pm UTC](https://discuss.elastic.co/t/how-i-put-a-response-into-a-kibana-url/350410 "2024-01-05T15:25:06Z")

</div>

Hello all, I have a script that will execute at a Unix serve curl -X POST "htt..xxxxx/xxxxx\*/\_search?pretty=" -H 'authorization: Basic xxxxxxxx' -H 'content-type: application/json' -d '{ "aggs": { "2": { …

---

## [Plugin index-pattern loading issues on multiple spaces](https://discuss.elastic.co/t/plugin-index-pattern-loading-issues-on-multiple-spaces/350396)

<div class="topic-metadata">

**Author:** [@JSFern83](https://discuss.elastic.co/u/JSFern83)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 4:06pm UTC](https://discuss.elastic.co/t/plugin-index-pattern-loading-issues-on-multiple-spaces/350396 "2024-01-05T16:06:25Z")

</div>

Hi All, Our team is having trouble getting our plugin to load on multiple spaces. We have created an index-pattern for each space. Below is the configuration for the index-patterns saved in Elasticsearch. Space 1 { …

---

## [How to map geo points (coordinates) to reginal layer](https://discuss.elastic.co/t/how-to-map-geo-points-coordinates-to-reginal-layer/350225)

<div class="topic-metadata">

**Author:** [@mharari](https://discuss.elastic.co/u/mharari)\
**Replies:** 5\
**Last updated:** [January 5, 2024, 3:43pm UTC](https://discuss.elastic.co/t/how-to-map-geo-points-coordinates-to-reginal-layer/350225 "2024-01-05T15:43:04Z")

</div>

I have docs with a geo location field (coordinates I get from the user's browser), and I want to add a layer to my map - where those geo locations are mapped into regions map ? like so - All I have is coordinates . I…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=336)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=338)
