# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=355

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 356

---

## [Does ElasticSearch support lemmatization? If yes, then how can I search for docs using this?](https://discuss.elastic.co/t/does-elasticsearch-support-lemmatization-if-yes-then-how-can-i-search-for-docs-using-this/348880)

<div class="topic-metadata">

**Author:** [@prabhuaxm](https://discuss.elastic.co/u/prabhuaxm)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 10:35am UTC](https://discuss.elastic.co/t/does-elasticsearch-support-lemmatization-if-yes-then-how-can-i-search-for-docs-using-this/348880 "2023-12-08T10:35:04Z")

</div>

I am using Python wherein I am searching for a string in a list of string using lemmatization (through SpaCy). I want to do the same thing for Elasticsearch but all the documents I have come across till now say that Lemm…

---

## [Enrolling Elastic Agent shows up in Fleet Agents but goes from "Updating" to "Offline"](https://discuss.elastic.co/t/enrolling-elastic-agent-shows-up-in-fleet-agents-but-goes-from-updating-to-offline/348728)

<div class="topic-metadata">

**Author:** [@olivettinho](https://discuss.elastic.co/u/olivettinho)\
**Replies:** 7\
**Last updated:** [December 8, 2023, 8:24am UTC](https://discuss.elastic.co/t/enrolling-elastic-agent-shows-up-in-fleet-agents-but-goes-from-updating-to-offline/348728 "2023-12-08T08:24:34Z")

</div>

Hello, I am trying to enroll Elastic Agent to different Windows Servers. I am running ELK and Fleet-Server via Docker. I am using the given commands by Kibana to install Elastic Agent and it says "Successfully enroled t…

---

## [Uptime alert recovers even though host is still down](https://discuss.elastic.co/t/uptime-alert-recovers-even-though-host-is-still-down/348866)

<div class="topic-metadata">

**Author:** [@Glychee](https://discuss.elastic.co/u/Glychee)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 8:32am UTC](https://discuss.elastic.co/t/uptime-alert-recovers-even-though-host-is-still-down/348866 "2023-12-08T08:32:51Z")

</div>

Running Elasticsearch 8.2.3 and heartbeat 8.2 We've installed heartbeat on a server(manual install) which is polling multiple hosts every 30 seconds and sending the data to Elasticsearch, this data comes in at a steady …

---

## [Kibana Pie Chart custom colors still not assignable](https://discuss.elastic.co/t/kibana-pie-chart-custom-colors-still-not-assignable/348577)

<div class="topic-metadata">

**Author:** [@dc\_3](https://discuss.elastic.co/u/dc_3)\
**Replies:** 10\
**Last updated:** [December 8, 2023, 8:15am UTC](https://discuss.elastic.co/t/kibana-pie-chart-custom-colors-still-not-assignable/348577 "2023-12-08T08:15:18Z")

</div>

Hello, I've researched and checked the forums here for this answer, but unfortunately the suggestions on how to assign custom colors in a pie chart seem unavailable to me. Can you help? Currently, I've only got a choic…

---

## [Is there a way to find the id value of async search?](https://discuss.elastic.co/t/is-there-a-way-to-find-the-id-value-of-async-search/348858)

<div class="topic-metadata">

**Author:** [@SEUNGHYO](https://discuss.elastic.co/u/SEUNGHYO)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 6:02am UTC](https://discuss.elastic.co/t/is-there-a-way-to-find-the-id-value-of-async-search/348858 "2023-12-08T06:02:12Z")

</div>

Hello. missed the async search ID . want to look up the entire registered async search. In such a case, I would like to know how I can look up the ID of async search again. I checked to find the task of async search,…

---

## [Match\_none and must\_not named queries](https://discuss.elastic.co/t/match-none-and-must-not-named-queries/348857)

<div class="topic-metadata">

**Author:** [@OS1](https://discuss.elastic.co/u/OS1)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 5:33am UTC](https://discuss.elastic.co/t/match-none-and-must-not-named-queries/348857 "2023-12-08T05:33:06Z")

</div>

I'm building ES queries dynamically in code, and sometimes I choose to omit some part of the query. I've been using the "\_name" property for logging and debugging, however I wish I could also use it to tell which sub qu…

---

## [After enabling - xpack.security.enabled=true, in kibana logs is not updating](https://discuss.elastic.co/t/after-enabling-xpack-security-enabled-true-in-kibana-logs-is-not-updating/348855)

<div class="topic-metadata">

**Author:** [@venkatesh121](https://discuss.elastic.co/u/venkatesh121)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 5:29am UTC](https://discuss.elastic.co/t/after-enabling-xpack-security-enabled-true-in-kibana-logs-is-not-updating/348855 "2023-12-08T05:29:46Z")

</div>

After enabling - xpack.security.enabled=true, in kibana logs is not updating but if i changed - xpack.security.enabled=true to false its updating note: already added passwords in docker-copose.yml file ./elasticsearch-…

---

## [Failed to create client for go-elasticsearch](https://discuss.elastic.co/t/failed-to-create-client-for-go-elasticsearch/348848)

<div class="topic-metadata">

**Author:** [@Bosees](https://discuss.elastic.co/u/Bosees)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 2:27am UTC](https://discuss.elastic.co/t/failed-to-create-client-for-go-elasticsearch/348848 "2023-12-08T02:27:00Z")

</div>

I'm trying to create a client using go-elasticsearch with a viewer permission user who can only play a read role. The problem is that I'm getting a 403 error. Here is the corresponding error log "type":"security\_excepti…

---

## [Field is of the wrong type](https://discuss.elastic.co/t/field-is-of-the-wrong-type/348762)

<div class="topic-metadata">

**Author:** [@soad20000](https://discuss.elastic.co/u/soad20000)\
**Replies:** 10\
**Last updated:** [December 7, 2023, 10:57pm UTC](https://discuss.elastic.co/t/field-is-of-the-wrong-type/348762 "2023-12-07T22:57:50Z")

</div>

Hello, I am getting an error when trying to use some fields that apparently aren't being mapped correctly. The fields are source.ip, source.port, destination.ip, and destination.port I have checked the mapping of th…

---

## [Snapshot backup via api not working as expacted](https://discuss.elastic.co/t/snapshot-backup-via-api-not-working-as-expacted/348841)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 9:14pm UTC](https://discuss.elastic.co/t/snapshot-backup-via-api-not-working-as-expacted/348841 "2023-12-07T21:14:16Z")

</div>

I am running backup via bash and it is working successfully but backing up lot of unwanted backup with it. here is code for indice in daily\_check\_index-2023 do curl -XPUT -u ${elk\_admin\_user}:${elk\_admin\_password} "${…

---

## [Guides on getting Elastic 8 working with a Java backend?](https://discuss.elastic.co/t/guides-on-getting-elastic-8-working-with-a-java-backend/348765)

<div class="topic-metadata">

**Author:** [@DenverCoder9](https://discuss.elastic.co/u/DenverCoder9)\
**Replies:** 10\
**Last updated:** [December 7, 2023, 8:44pm UTC](https://discuss.elastic.co/t/guides-on-getting-elastic-8-working-with-a-java-backend/348765 "2023-12-07T20:44:26Z")

</div>

Hello. Been working in Java to try getting Elasticsearch up and working in a Java backend and not having good luck with finding examples of how to have it working. A lot of the materials I've seen use RestHighLevelClien…

---

## [SNMP Trap - Encoding Issue](https://discuss.elastic.co/t/snmp-trap-encoding-issue/347034)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 6:57pm UTC](https://discuss.elastic.co/t/snmp-trap-encoding-issue/347034 "2023-12-07T18:57:49Z")

</div>

Hello, I am using snmp trap input plugin to receive snmp traps. I am receiving SNMP v1 traps but on some fields there seems to be hex binary encoding. Here's a sample of my messages: #\<SNMP::VarBind:0x329c49fd @name=…

---

## [Delete audit rules on server](https://discuss.elastic.co/t/delete-audit-rules-on-server/348792)

<div class="topic-metadata">

**Author:** [@bav](https://discuss.elastic.co/u/bav)\
**Replies:** 3\
**Last updated:** [December 7, 2023, 6:15pm UTC](https://discuss.elastic.co/t/delete-audit-rules-on-server/348792 "2023-12-07T18:15:57Z")

</div>

Hello I have a simple and basic question to auditbeat and auditd, but which I can not answer to myself at the moment. How could I delete or reverse the audit.rules and file.integrity which got created on an server? This…

---

## [Elasticsearch curl output returning error](https://discuss.elastic.co/t/elasticsearch-curl-output-returning-error/348836)

<div class="topic-metadata">

**Author:** [@Kamesh\_Pratapa](https://discuss.elastic.co/u/Kamesh_Pratapa)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 6:01pm UTC](https://discuss.elastic.co/t/elasticsearch-curl-output-returning-error/348836 "2023-12-07T18:01:13Z")

</div>

Hi all, I am trying to setup ELK cluster with 7.16 version with X-pack enabled and SSL certificates configured. I am doing it in ubuntu where we have ansible code to deploy the stack which was developed by a person ear…

---

## [How to input the evtx file in logstash](https://discuss.elastic.co/t/how-to-input-the-evtx-file-in-logstash/348834)

<div class="topic-metadata">

**Author:** [@musk\_elon](https://discuss.elastic.co/u/musk_elon)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 5:15pm UTC](https://discuss.elastic.co/t/how-to-input-the-evtx-file-in-logstash/348834 "2023-12-07T17:15:14Z")

</div>

Hello, everyone. I want to know how to input the evtx file in logstash. output is json. help me. thanks

---

## [I got this error in using logstash](https://discuss.elastic.co/t/i-got-this-error-in-using-logstash/348665)

<div class="topic-metadata">

**Author:** [@musk\_elon](https://discuss.elastic.co/u/musk_elon)\
**Replies:** 13\
**Last updated:** [December 7, 2023, 5:11pm UTC](https://discuss.elastic.co/t/i-got-this-error-in-using-logstash/348665 "2023-12-07T17:11:08Z")

</div>

Hello. I installed the logstash and set the configuration. # Sample Logstash configuration for creating a simple # Beats -\> Logstash -\> Elasticsearch pipeline. input { file{ type =\>"csv" path =\> "Z:/5/upwork/…

---

## [\[ERROR\] Logstash: \_dateparsefailure for xml output using the date plugin](https://discuss.elastic.co/t/error-logstash-dateparsefailure-for-xml-output-using-the-date-plugin/348742)

<div class="topic-metadata">

**Author:** [@Jospaul](https://discuss.elastic.co/u/Jospaul)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 5:06pm UTC](https://discuss.elastic.co/t/error-logstash-dateparsefailure-for-xml-output-using-the-date-plugin/348742 "2023-12-07T17:06:12Z")

</div>

I am getting a dateparsefailure when trying to match the @timestamp with the UNIX\_MS date. I tried it as a separate field and that fails too - Below is the filter - filter { xml { source =\> "message" …

---

## [Unable to start Filebeat due to hostPath volume](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-hostpath-volume/348831)

<div class="topic-metadata">

**Author:** [@Caesar](https://discuss.elastic.co/u/Caesar)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 4:51pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-hostpath-volume/348831 "2023-12-07T16:51:01Z")

</div>

Hello folks. I am facing an issue when trying to deploy Filebeat because there is an OPA policy that prevents the use of hostPath volumes. Is there any alternative method to make it work without relying on hostPath? n…

---

## [ILM - Does not trigger rollover](https://discuss.elastic.co/t/ilm-does-not-trigger-rollover/348711)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 7\
**Last updated:** [December 7, 2023, 4:53pm UTC](https://discuss.elastic.co/t/ilm-does-not-trigger-rollover/348711 "2023-12-07T16:53:32Z")

</div>

Hi, I've configured ILM on datastream and a rollover policy. The goal is to have my datastream backing indices to rollover daily. The ILM is configured as follow : Two weeks passed, still on the same backing indic…

---

## [Curl: (60) SSL certificate problem: self signed certificate in certificate chain](https://discuss.elastic.co/t/curl-60-ssl-certificate-problem-self-signed-certificate-in-certificate-chain/347472)

<div class="topic-metadata">

**Author:** [@Dasara\_Saarthak](https://discuss.elastic.co/u/Dasara_Saarthak)\
**Replies:** 17\
**Last updated:** [December 7, 2023, 4:36pm UTC](https://discuss.elastic.co/t/curl-60-ssl-certificate-problem-self-signed-certificate-in-certificate-chain/347472 "2023-12-07T16:36:58Z")

</div>

curl --cacert certs/ca/ca.crt -u elastic:"xyz" 'url' iam getting the below error while trying to execute the above curl command curl: (60) SSL certificate problem: self signed certificate in certificate chain but the…

---

## [Create a metric out of the last values from multiple log files](https://discuss.elastic.co/t/create-a-metric-out-of-the-last-values-from-multiple-log-files/348748)

<div class="topic-metadata">

**Author:** [@Jospaul](https://discuss.elastic.co/u/Jospaul)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 3:58pm UTC](https://discuss.elastic.co/t/create-a-metric-out-of-the-last-values-from-multiple-log-files/348748 "2023-12-07T15:58:47Z")

</div>

I need to find the current active threads in a system. The log files spit this information per log file, but as I am running multiple of them in parallel. There are multiple log files created each showing the active thre…

---

## [Ignore\_inactive does not work in filebeat with filestream config type](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/348822)

<div class="topic-metadata">

**Author:** [@josepcorrea](https://discuss.elastic.co/u/josepcorrea)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/348822 "2023-12-07T15:13:10Z")

</div>

When I use the filestream type instead of the log type, filebeat always reads the entire log file from the beginning. - type: filestream id: test\_id enable: true paths: - "/usr/share/filebeat/inputs.d/\*.log" …

---

## [What is the max id for rollover in index name](https://discuss.elastic.co/t/what-is-the-max-id-for-rollover-in-index-name/348802)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 3\
**Last updated:** [December 7, 2023, 2:58pm UTC](https://discuss.elastic.co/t/what-is-the-max-id-for-rollover-in-index-name/348802 "2023-12-07T14:58:46Z")

</div>

Hi, I have created index with rollover policy (with 9 digits: 000000001) : PUT /\<my-index-{now/d}-000000001\> After rollover it create the new index with 6 digits: 000002 Is there a way to increase the number of digit…

---

## [Links Panel Font SIze](https://discuss.elastic.co/t/links-panel-font-size/348811)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 1:23pm UTC](https://discuss.elastic.co/t/links-panel-font-size/348811 "2023-12-07T13:23:28Z")

</div>

Hello, I love the new Links Panel, but the default font size is way too big imho. In the previous years we always made menus with the Markdown panel, which allows to resize the font size. Please please add this funct…

---

## [Logstash custom DATE fields (extracted by regex or custom patterns) how to convert it to DATE field](https://discuss.elastic.co/t/logstash-custom-date-fields-extracted-by-regex-or-custom-patterns-how-to-convert-it-to-date-field/348419)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 7\
**Last updated:** [December 7, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-custom-date-fields-extracted-by-regex-or-custom-patterns-how-to-convert-it-to-date-field/348419 "2023-12-07T12:45:28Z")

</div>

Hello everyone. Currently, I'm in the stage of writing custom Grok filters in Logstash. I have many different logs - some of them have a date format that fits ISO8601 format. But unfortunately when I use this format in m…

---

## [Is there caching for knn search so it returns records if same querry is fired](https://discuss.elastic.co/t/is-there-caching-for-knn-search-so-it-returns-records-if-same-querry-is-fired/348783)

<div class="topic-metadata">

**Author:** [@Himanshu\_Pal](https://discuss.elastic.co/u/Himanshu_Pal)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:22pm UTC](https://discuss.elastic.co/t/is-there-caching-for-knn-search-so-it-returns-records-if-same-querry-is-fired/348783 "2023-12-07T12:22:18Z")

</div>

i fired 100 querries to elastic knn search with 0.4 million records and calculated average time per querry which was about 200 ms for first iteration. i re fired same querries just after 5 sec and response time per quer…

---

## [Extract specific string from a field in ELK](https://discuss.elastic.co/t/extract-specific-string-from-a-field-in-elk/348799)

<div class="topic-metadata">

**Author:** [@Satheesh](https://discuss.elastic.co/u/Satheesh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:07pm UTC](https://discuss.elastic.co/t/extract-specific-string-from-a-field-in-elk/348799 "2023-12-07T12:07:43Z")

</div>

I am newbie in ELK. In my ELK, a single document has multiple fields (k8s.pod,k8s.ns,timestamp,logtag,stream and message etc.,). In the message field, I am getting the logs like below e\[36m15:25:47.508e\[0;39m e\[1;30m\[de…

---

## [Hide all panels, using control or filter](https://discuss.elastic.co/t/hide-all-panels-using-control-or-filter/348804)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:03pm UTC](https://discuss.elastic.co/t/hide-all-panels-using-control-or-filter/348804 "2023-12-07T12:03:15Z")

</div>

Hello Team, Please help to tell how to hide all panels, of a dashboard using controls or filter

---

## [Not able to get file logs from otel collector to elasticsearch using APM server](https://discuss.elastic.co/t/not-able-to-get-file-logs-from-otel-collector-to-elasticsearch-using-apm-server/348214)

<div class="topic-metadata">

**Author:** [@Akshay\_Ranka](https://discuss.elastic.co/u/Akshay_Ranka)\
**Replies:** 5\
**Last updated:** [December 7, 2023, 11:56am UTC](https://discuss.elastic.co/t/not-able-to-get-file-logs-from-otel-collector-to-elasticsearch-using-apm-server/348214 "2023-12-07T11:56:08Z")

</div>

extensions: health\_check: pprof: endpoint: 0.0.0.0:1777 zpages: endpoint: 0.0.0.0:55679 receivers: filelog: include: \[/path/to log/.log\] operators: - type: regex\_parser regex: '^(?P\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2…

---

## [Running Logstah in Windows](https://discuss.elastic.co/t/running-logstah-in-windows/348749)

<div class="topic-metadata">

**Author:** [@Alberto\_Jimenez1](https://discuss.elastic.co/u/Alberto_Jimenez1)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 10:52am UTC](https://discuss.elastic.co/t/running-logstah-in-windows/348749 "2023-12-07T10:52:37Z")

</div>

Im running in Windows Logstah the basic Test Official website recommends: logstash.bat -e "input { stdin { } } output { stdout {} }" but I receive following error in the cmd: \`\`\` "\[FATAL\] 2023-12-06 14:24:21.428 \[ma…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=354)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=356)
