# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=351

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 352

---

## [Logstash regex expression in conf xpath](https://discuss.elastic.co/t/logstash-regex-expression-in-conf-xpath/349252)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 5:48pm UTC](https://discuss.elastic.co/t/logstash-regex-expression-in-conf-xpath/349252 "2023-12-13T17:48:31Z")

</div>

Dears, Can we use regex expression in logstash configuration in case of filter and xpath? There is right now such to conditions: ... filter { if "xmlapps" in \[tags\] { xml { source =\> "message" store\_xml =\> …

---

## [Unspecific Machine Learning Job Validation Errors - can't troubleshoot](https://discuss.elastic.co/t/unspecific-machine-learning-job-validation-errors-cant-troubleshoot/349286)

<div class="topic-metadata">

**Author:** [@LogsandParsers](https://discuss.elastic.co/u/LogsandParsers)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 5:43pm UTC](https://discuss.elastic.co/t/unspecific-machine-learning-job-validation-errors-cant-troubleshoot/349286 "2023-12-13T17:43:10Z")

</div>

Hi all, I'm trying to create Machine Learning jobs on Kibana, but in the vast majority of time, they fail with the following error at the 'Validation' stage on Kibana, before the job is run: So, is this a capacity p…

---

## [Kibana - Unable to sync case with alert](https://discuss.elastic.co/t/kibana-unable-to-sync-case-with-alert/349219)

<div class="topic-metadata">

**Author:** [@BigM1](https://discuss.elastic.co/u/BigM1)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 5:41pm UTC](https://discuss.elastic.co/t/kibana-unable-to-sync-case-with-alert/349219 "2023-12-13T17:41:28Z")

</div>

Hello, in Kibana, using the SIEM security alert. When i try to create a case and choses option to sync case with alert it throws error below: "Detected an unhandled Promise rejection. Message: illegal\_argument\_exc…

---

## [Could not add the UUID fingerprint in producer on logstash](https://discuss.elastic.co/t/could-not-add-the-uuid-fingerprint-in-producer-on-logstash/349227)

<div class="topic-metadata">

**Author:** [@pradeep.kumar](https://discuss.elastic.co/u/pradeep.kumar)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 5:40pm UTC](https://discuss.elastic.co/t/could-not-add-the-uuid-fingerprint-in-producer-on-logstash/349227 "2023-12-13T17:40:34Z")

</div>

Hi Team, Im adding the fingerprint of method UUID to avoid the duplication of the data. Im using kafka as producer and Elasticsearch as consumer. Example pipeline conf looks like this input { kafka {…

---

## [Elastic SNMP - Best Practices?](https://discuss.elastic.co/t/elastic-snmp-best-practices/349285)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 5:07pm UTC](https://discuss.elastic.co/t/elastic-snmp-best-practices/349285 "2023-12-13T17:07:47Z")

</div>

Continuing the discussion from Possability to use ELK-Stack for SNMP Monitoring like PRTG, CheckMK: Hello, It would be nice to hear how more people are using Elastic's SNMP (Logstash Input plugin) with a large number o…

---

## [Would dividing the same resources over more nodes improve performance?](https://discuss.elastic.co/t/would-dividing-the-same-resources-over-more-nodes-improve-performance/349264)

<div class="topic-metadata">

**Author:** [@calin](https://discuss.elastic.co/u/calin)\
**Replies:** 5\
**Last updated:** [December 13, 2023, 4:40pm UTC](https://discuss.elastic.co/t/would-dividing-the-same-resources-over-more-nodes-improve-performance/349264 "2023-12-13T16:40:46Z")

</div>

A load test seems to show that resources (CPU, RAM) on the data nodes aren't fully used. Would spreading the same resources over more data nodes help performance ?

---

## [Undefined reading 'searchSourceJSON' Postfix dashboard](https://discuss.elastic.co/t/undefined-reading-searchsourcejson-postfix-dashboard/348952)

<div class="topic-metadata">

**Author:** [@skmessage](https://discuss.elastic.co/u/skmessage)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 4:05pm UTC](https://discuss.elastic.co/t/undefined-reading-searchsourcejson-postfix-dashboard/348952 "2023-12-13T16:05:36Z")

</div>

Greetings! I am trying to port the elastic-kibana-postfix .json files to .ndjson files to visualize a dashboard for Postfix for Elasticsearch 8.10.2. The PR and issue discussion are available at the following links: …

---

## [Security not allowing me to install integration app](https://discuss.elastic.co/t/security-not-allowing-me-to-install-integration-app/349280)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 3:12pm UTC](https://discuss.elastic.co/t/security-not-allowing-me-to-install-integration-app/349280 "2023-12-13T15:12:07Z")

</div>

I have a new install, and I went to add this app, and got this message. I followed the instructions in the listed guide, and even restarted the stack, to no avail. I get this same message.

---

## [How to automatically enable the \_size field with Beats?](https://discuss.elastic.co/t/how-to-automatically-enable-the-size-field-with-beats/348820)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 8\
**Last updated:** [December 13, 2023, 3:20pm UTC](https://discuss.elastic.co/t/how-to-automatically-enable-the-size-field-with-beats/348820 "2023-12-13T15:20:10Z")

</div>

Hey there, I was trying to use the mapper-size plugin. Following the official documentation, I saw that I have to enable into index's mapping the \_size field. My doubt is, how can I do it automatically using Beats? When…

---

## [Kibana drilldown on lens metrics doesn't work](https://discuss.elastic.co/t/kibana-drilldown-on-lens-metrics-doesnt-work/348698)

<div class="topic-metadata">

**Author:** [@Prakash\_Gupta](https://discuss.elastic.co/u/Prakash_Gupta)\
**Replies:** 5\
**Last updated:** [December 13, 2023, 3:10pm UTC](https://discuss.elastic.co/t/kibana-drilldown-on-lens-metrics-doesnt-work/348698 "2023-12-13T15:10:52Z")

</div>

I am trying to add a dashboard drill for a lens metrics. It let's me add the dashboard link but the visualization is not clickable. I am using Kibana 8.10 version. Could someone tell me if I am missing some setting or th…

---

## [Retention of -ds.monitoring\*](https://discuss.elastic.co/t/retention-of-ds-monitoring/349277)

<div class="topic-metadata">

**Author:** [@SteffiAutumn](https://discuss.elastic.co/u/SteffiAutumn)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/retention-of-ds-monitoring/349277 "2023-12-13T15:02:52Z")

</div>

Unfortunately our indices created by Metricbeat 8 are not cleaned up, although the policy looks ok. Looking at the responsible policy I'd expect the indices to be deleted after 6 days, but they're not and we need to clea…

---

## [\[eck-stack\] Unable to gather kubernetes logs via agent while passing ELASTICSEARCH\_CA to agent](https://discuss.elastic.co/t/eck-stack-unable-to-gather-kubernetes-logs-via-agent-while-passing-elasticsearch-ca-to-agent/349198)

<div class="topic-metadata">

**Author:** [@sevaho](https://discuss.elastic.co/u/sevaho)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 2:59pm UTC](https://discuss.elastic.co/t/eck-stack-unable-to-gather-kubernetes-logs-via-agent-while-passing-elasticsearch-ca-to-agent/349198 "2023-12-13T14:59:53Z")

</div>

Hello everyone, Hope you're all doing well! I've been diving into setting up Elasticsearch on Kubernetes, and it's been quite the journey. I've been at it for the past two weeks, with my main goal being to seamlessly fe…

---

## [Displaying Clusters of Last Hits on Kibana Maps](https://discuss.elastic.co/t/displaying-clusters-of-last-hits-on-kibana-maps/349232)

<div class="topic-metadata">

**Author:** [@yuval3210](https://discuss.elastic.co/u/yuval3210)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 2:03pm UTC](https://discuss.elastic.co/t/displaying-clusters-of-last-hits-on-kibana-maps/349232 "2023-12-13T14:03:16Z")

</div>

TL;DR: Is there a way to configure Kibana maps to display clusters based only on the last hits for each entity, rather than aggregating all hits over the selected timeframe? Hello Elastic Community :slight\_smile: I'm …

---

## [Dense search for large documents](https://discuss.elastic.co/t/dense-search-for-large-documents/349248)

<div class="topic-metadata">

**Author:** [@mwon](https://discuss.elastic.co/u/mwon)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 2:10pm UTC](https://discuss.elastic.co/t/dense-search-for-large-documents/349248 "2023-12-13T14:10:54Z")

</div>

Hi, I want to use ES to index documents and do semantic search with knn. For this type of search we need to encode every document with an embedding model and index each vector for future search of some also encoded quer…

---

## [Script processor for retaning relevant fields not working](https://discuss.elastic.co/t/script-processor-for-retaning-relevant-fields-not-working/348320)

<div class="topic-metadata">

**Author:** [@vishnuhngama](https://discuss.elastic.co/u/vishnuhngama)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 1:35pm UTC](https://discuss.elastic.co/t/script-processor-for-retaning-relevant-fields-not-working/348320 "2023-12-13T13:35:10Z")

</div>

I am writing a script processor which will retain only the relevant fields and remove all the other fields . Here 'message','custom\_field','@timestamp','\_index','\_id','\_version','index\_name','tags', is getting retained b…

---

## [KIbana having (filtering groups)](https://discuss.elastic.co/t/kibana-having-filtering-groups/349142)

<div class="topic-metadata">

**Author:** [@chenchen40](https://discuss.elastic.co/u/chenchen40)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 1:25pm UTC](https://discuss.elastic.co/t/kibana-having-filtering-groups/349142 "2023-12-13T13:25:44Z")

</div>

Hi guys, using 8.6, i can't find option to filter out groups with values i don't want to show. What do i miss?

---

## [Is the precision of cardinality aggregation decided by total unique value count or filtered unique value count?](https://discuss.elastic.co/t/is-the-precision-of-cardinality-aggregation-decided-by-total-unique-value-count-or-filtered-unique-value-count/349073)

<div class="topic-metadata">

**Author:** [@henrhoi](https://discuss.elastic.co/u/henrhoi)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/is-the-precision-of-cardinality-aggregation-decided-by-total-unique-value-count-or-filtered-unique-value-count/349073 "2023-12-13T13:07:14Z")

</div>

Hi, We have an index with a field containing ~30,000 unique values. When doing a filtered cardinality aggregation on this field, which should return ~650 unique values, we experience non-deterministic results (±25). W…

---

## [Aggregations Migration ES7 to ES8.11.1](https://discuss.elastic.co/t/aggregations-migration-es7-to-es8-11-1/349255)

<div class="topic-metadata">

**Author:** [@Dev1234](https://discuss.elastic.co/u/Dev1234)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 12:03pm UTC](https://discuss.elastic.co/t/aggregations-migration-es7-to-es8-11-1/349255 "2023-12-13T12:03:42Z")

</div>

Hello dear community, I am currently migrating our ES7 to ES8 and am now encountering the problem that I cannot find a solution as to how I can migrate SearchHits or the .get(String) method. public static Set\<Integer\> …

---

## [Changing from Elasticsearch 7.10.2 OSS to Basic version](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347523)

<div class="topic-metadata">

**Author:** [@Talha1](https://discuss.elastic.co/u/Talha1)\
**Replies:** 3\
**Last updated:** [December 13, 2023, 11:55am UTC](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347523 "2023-12-13T11:55:24Z")

</div>

Hi, I'm currently using Elasticsearch version 7.10. OSS version but when trying to implement security ran into challenges which turns out is because I am not on the basic version of Elasticsearch. Is there a way I can ch…

---

## [Is this the correct impl' for customizing \`\_id\` meta data field](https://discuss.elastic.co/t/is-this-the-correct-impl-for-customizing-id-meta-data-field/349059)

<div class="topic-metadata">

**Author:** [@iby\_dev](https://discuss.elastic.co/u/iby_dev)\
**Replies:** 17\
**Last updated:** [December 13, 2023, 10:48am UTC](https://discuss.elastic.co/t/is-this-the-correct-impl-for-customizing-id-meta-data-field/349059 "2023-12-13T10:48:33Z")

</div>

To get Elasticsearch docker image version: image: docker.elastic.co/elasticsearch/elasticsearch:7.16.2 To accept a client side customized UUID on the \_id field i had to change the: dynamic: strict property to true. Al…

---

## [Issue with Parquet File Retrieval from S3](https://discuss.elastic.co/t/issue-with-parquet-file-retrieval-from-s3/349236)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 9:26am UTC](https://discuss.elastic.co/t/issue-with-parquet-file-retrieval-from-s3/349236 "2023-12-13T09:26:09Z")

</div>

Hello everyone, I'm facing an issue while trying to retrieve a Parquet file from S3 using Filebeat. Below, I've included configuration details: filebeat.inputs: - type: aws-s3 bucket\_arn: ${BUCKET\_ARN} bucket\_list\_…

---

## [org.apache.http.ConnectionClosedException: Connection is closed](https://discuss.elastic.co/t/org-apache-http-connectionclosedexception-connection-is-closed/348402)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 9:06am UTC](https://discuss.elastic.co/t/org-apache-http-connectionclosedexception-connection-is-closed/348402 "2023-12-13T09:06:07Z")

</div>

org.apache.http.ConnectionClosedException: Connection is closed at org.elasticsearch.client.RestClient.extractAndWrapCause(RestClient.java:920) at org.elasticsearch.client.RestClient.performRequest(RestClient.java:300) …

---

## [Elasticsearch as vector db](https://discuss.elastic.co/t/elasticsearch-as-vector-db/349192)

<div class="topic-metadata">

**Author:** [@Alexander\_Gamanyuk1](https://discuss.elastic.co/u/Alexander_Gamanyuk1)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 9:04am UTC](https://discuss.elastic.co/t/elasticsearch-as-vector-db/349192 "2023-12-13T09:04:05Z")

</div>

I've been using Elasticsearch since early 2010. We have multiple self-hosted clusters with a few terabytes of data, used for search, analytics, and other use cases. But recently, we started building Retrieval Augmented …

---

## [Fleet initial error](https://discuss.elastic.co/t/fleet-initial-error/347225)

<div class="topic-metadata">

**Author:** [@mohd\_sa](https://discuss.elastic.co/u/mohd_sa)\
**Replies:** 17\
**Last updated:** [December 13, 2023, 8:12am UTC](https://discuss.elastic.co/t/fleet-initial-error/347225 "2023-12-13T08:12:49Z")

</div>

Hi after upgrade from 8.9.1 to 8.11.1 , I have error on fleet page "unable to initialize fleet, uninstall token is missing the token"

---

## [How to maintain product availability in Elasticsearch?](https://discuss.elastic.co/t/how-to-maintain-product-availability-in-elasticsearch/349226)

<div class="topic-metadata">

**Author:** [@Aadhar\_Bhatt](https://discuss.elastic.co/u/Aadhar_Bhatt)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-maintain-product-availability-in-elasticsearch/349226 "2023-12-13T07:27:52Z")

</div>

Hey everyone, I'm setting up an eCommerce search system on Elasticsearch with about 6 million product listings across 3000 stores. I need advice on storing availability data efficiently within ES. This data updates freq…

---

## [Logstash is unable to connect to Elasticsearch where entire ELK is setup in docker](https://discuss.elastic.co/t/logstash-is-unable-to-connect-to-elasticsearch-where-entire-elk-is-setup-in-docker/349224)

<div class="topic-metadata">

**Author:** [@Nurarao](https://discuss.elastic.co/u/Nurarao)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 7:04am UTC](https://discuss.elastic.co/t/logstash-is-unable-to-connect-to-elasticsearch-where-entire-elk-is-setup-in-docker/349224 "2023-12-13T07:04:15Z")

</div>

Hi, I was setting up the ELK setup using docker and using certs too. The Elastic has 3 nodes (es01, es02, es03) which is running separate containers and even Kibana , logstash also running in individual containers. The …

---

## [Filebeat-god is stopped](https://discuss.elastic.co/t/filebeat-god-is-stopped/349153)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 3\
**Last updated:** [December 13, 2023, 6:07am UTC](https://discuss.elastic.co/t/filebeat-god-is-stopped/349153 "2023-12-13T06:07:42Z")

</div>

I have installed wazuh in docker. After users count reached 100 filebeat has stopped. service filebeat start Failed to get D-Bus connection: Operation not permitted Starting filebeat: 2023-12-12T13:18:58.565Z INFO …

---

## [How to add day of month field but with certain timezone](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [December 13, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207 "2023-12-13T04:42:18Z")

</div>

i want to create a "day of month" field for my visualization. I already did this using a scripted field before. but since I chose Grafana to visualize my data, I can't use that scripted field there. so I want to generate…

---

## [Elasticsearch/Kibana Fleet and APM via Docker Compose](https://discuss.elastic.co/t/elasticsearch-kibana-fleet-and-apm-via-docker-compose/349204)

<div class="topic-metadata">

**Author:** [@michael.brizic](https://discuss.elastic.co/u/michael.brizic)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 1:31am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-fleet-and-apm-via-docker-compose/349204 "2023-12-13T01:31:36Z")

</div>

Hi, I'm attempting to run the Elasticsearch/Kibana stack along with elastic-agent as a Fleet Server and APM Server via Docker Compose in order that I may have a complete local development setup that I can spin up and do…

---

## [Need help to create a grok patter for my syslog pattern](https://discuss.elastic.co/t/need-help-to-create-a-grok-patter-for-my-syslog-pattern/349103)

<div class="topic-metadata">

**Author:** [@ameeto17](https://discuss.elastic.co/u/ameeto17)\
**Replies:** 2\
**Last updated:** [December 12, 2023, 10:17pm UTC](https://discuss.elastic.co/t/need-help-to-create-a-grok-patter-for-my-syslog-pattern/349103 "2023-12-12T22:17:28Z")

</div>

my log message looks like this message Dec 12 12:01:27 ppdtest302 test-checker: Context SHA of TEST Software Version 3.0.1\_RC5 0b1f71223180bf0df9330b13e17f8d7c62dfdaad16b97a80b8a25c99409c1109 How do i use a grok patte…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=350)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=352)
