# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=356

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 357

---

## [Is possible to print debug message in Filebeat Script Processor](https://discuss.elastic.co/t/is-possible-to-print-debug-message-in-filebeat-script-processor/348801)

<div class="topic-metadata">

**Author:** [@Chen\_Wei](https://discuss.elastic.co/u/Chen_Wei)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 10:29am UTC](https://discuss.elastic.co/t/is-possible-to-print-debug-message-in-filebeat-script-processor/348801 "2023-12-07T10:29:42Z")

</div>

I am using Filebeat to index log file and want to drop duplicated messages in the log file. So I write a JS script and load it with the Script Processor. Now I want to report the duplication in the filebeat log. Add som…

---

## [Upsert a document when document id is autogenerated using upsert?](https://discuss.elastic.co/t/upsert-a-document-when-document-id-is-autogenerated-using-upsert/348747)

<div class="topic-metadata">

**Author:** [@iby\_dev](https://discuss.elastic.co/u/iby_dev)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 9:46am UTC](https://discuss.elastic.co/t/upsert-a-document-when-document-id-is-autogenerated-using-upsert/348747 "2023-12-07T09:46:31Z")

</div>

According to the docs, on the Update API The \<\_id\> field is required. I have a bulk insert process which is sometimes known to insert duplicates given a particular scenario. The ids for us, are auto generated so how d…

---

## [ES create indexes\\reindex are slow when using a synonym file](https://discuss.elastic.co/t/es-create-indexes-reindex-are-slow-when-using-a-synonym-file/348718)

<div class="topic-metadata">

**Author:** [@ryzhovas](https://discuss.elastic.co/u/ryzhovas)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 9:29am UTC](https://discuss.elastic.co/t/es-create-indexes-reindex-are-slow-when-using-a-synonym-file/348718 "2023-12-07T09:29:50Z")

</div>

We have synonym file 38M when we create index with filter "dictionary": { "expand": false, "lenient": true, "synonyms\_path": "linguistics/expert\_20231123/em\_dictionary.txt", …

---

## [Discuss: Security Vulnerabilities: ESA-2023-14 - CVE-2023-31419](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769)

<div class="topic-metadata">

**Author:** [@devkgk](https://discuss.elastic.co/u/devkgk)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 8:32am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769 "2023-12-07T08:32:44Z")

</div>

Hello, everybody. According to the community's safety announcement: " Elasticsearch StackOverflow vulnerability (ESA-2023-14) A flaw was discovered in Elasticsearch, affecting the \_search API that allowed a specially …

---

## [Elastic search certificate issue](https://discuss.elastic.co/t/elastic-search-certificate-issue/348788)

<div class="topic-metadata">

**Author:** [@Dasara\_Saarthak](https://discuss.elastic.co/u/Dasara_Saarthak)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 8:05am UTC](https://discuss.elastic.co/t/elastic-search-certificate-issue/348788 "2023-12-07T08:05:29Z")

</div>

hi iam using helm to deploy elasticsearch this is my statefulset.yml file apiVersion: apps/v1 kind: StatefulSet metadata: annotations: esMajorVersion: "8" meta.helm.sh/release-name: esarticle meta.helm.sh…

---

## [Does date-format of ES7.5.2 not support YYYY?](https://discuss.elastic.co/t/does-date-format-of-es7-5-2-not-support-yyyy/348787)

<div class="topic-metadata">

**Author:** [@MiuNice](https://discuss.elastic.co/u/MiuNice)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 7:54am UTC](https://discuss.elastic.co/t/does-date-format-of-es7-5-2-not-support-yyyy/348787 "2023-12-07T07:54:02Z")

</div>

I created a field named "created" in the index as shown below: "created": { "type": "date", "format": "YYYY-MM-dd'T'HH:mm:ss'Z'" } When I used the range method for querying, I got unexpected results. There is a…

---

## [Elastic Search Indices Migration from Version 5.6 to Version 8.11 (New ES cluster)](https://discuss.elastic.co/t/elastic-search-indices-migration-from-version-5-6-to-version-8-11-new-es-cluster/348784)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 7:01am UTC](https://discuss.elastic.co/t/elastic-search-indices-migration-from-version-5-6-to-version-8-11-new-es-cluster/348784 "2023-12-07T07:01:39Z")

</div>

Hi Team, Indices in ES version 5.6 are compatible with ES version 8.11 (New ES Cluster) if we restore these indices by pointing snapshot repository of ES 5.6 cluster to new ES 8.11 cluster? Can you please share the ste…

---

## [Elasticsearch false mapping](https://discuss.elastic.co/t/elasticsearch-false-mapping/348722)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 6:50am UTC](https://discuss.elastic.co/t/elasticsearch-false-mapping/348722 "2023-12-07T06:50:20Z")

</div>

Hello everyone and thanks for help. I've installed latest versions of elasticsearch, kibana and logstash (8.11.1) on test cluster. Next, created new simple logstash pipeline that listens tcp port, next send data to elas…

---

## [All system.process.memory.rss.pct doesn't add up to give system.memory.used.pct](https://discuss.elastic.co/t/all-system-process-memory-rss-pct-doesnt-add-up-to-give-system-memory-used-pct/348210)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 6:09am UTC](https://discuss.elastic.co/t/all-system-process-memory-rss-pct-doesnt-add-up-to-give-system-memory-used-pct/348210 "2023-12-07T06:09:27Z")

</div>

Hi, Windows Server 2019 Standard metricbeat 8.10.4 System is showing high Memory Usage of 99% in Task Manager. But all the system.process.memory.rss.pct doesn't add up to give that memory usage. No where near it. Try…

---

## [We are getting two different offset values for same message](https://discuss.elastic.co/t/we-are-getting-two-different-offset-values-for-same-message/348779)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 5:44am UTC](https://discuss.elastic.co/t/we-are-getting-two-different-offset-values-for-same-message/348779 "2023-12-07T05:44:39Z")

</div>

Hi, We have two logstash pods which are reading the data from elasticsearch from one index for last 24 hr data and then sending data to Kafka server. We can see two different offset are created for similar log message. …

---

## [Thread is missing when i send logs from ECS fargate to Elastic search](https://discuss.elastic.co/t/thread-is-missing-when-i-send-logs-from-ecs-fargate-to-elastic-search/348774)

<div class="topic-metadata">

**Author:** [@NitinKalburgii](https://discuss.elastic.co/u/NitinKalburgii)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 4:47am UTC](https://discuss.elastic.co/t/thread-is-missing-when-i-send-logs-from-ecs-fargate-to-elastic-search/348774 "2023-12-07T04:47:57Z")

</div>

Hi! I was running my application in ECS fargate(AWS Service) and in AWS monitoring i was getting logs like 2023-12-06T15:28:53.745+05:30 06-12-2023 09:58:53.745 \[main\] INFO \[\] o.a.coyote.http11.Http11NioProtocol.log - I…

---

## [Kibana Failed to parse value 4.0 for setting node.processors must be = 1](https://discuss.elastic.co/t/kibana-failed-to-parse-value-4-0-for-setting-node-processors-must-be-1/347894)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 3:19am UTC](https://discuss.elastic.co/t/kibana-failed-to-parse-value-4-0-for-setting-node-processors-must-be-1/347894 "2023-12-07T03:19:29Z")

</div>

Hi Team, Unable to start Kibana throwing an error as kibana Failed to parse value 4.0 for setting node.processors must be = 1) Elasticsearch cluster running on docker container. Kibana version: 8.8.1 Elasticsearch v…

---

## [Can't Create Enrollment Token](https://discuss.elastic.co/t/cant-create-enrollment-token/348460)

<div class="topic-metadata">

**Author:** [@Bethanie\_Tipton](https://discuss.elastic.co/u/Bethanie_Tipton)\
**Replies:** 6\
**Last updated:** [December 6, 2023, 9:06pm UTC](https://discuss.elastic.co/t/cant-create-enrollment-token/348460 "2023-12-06T21:06:53Z")

</div>

When I try to open elasticsearch-create-enrollment-token, it crashes. I can't do anything with it; I click it, it pops up on my screen for half a second, and then closes.

---

## [Bundling elasticsearch into an offline Electronjs application](https://discuss.elastic.co/t/bundling-elasticsearch-into-an-offline-electronjs-application/348768)

<div class="topic-metadata">

**Author:** [@Joel\_Crawford](https://discuss.elastic.co/u/Joel_Crawford)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 12:56am UTC](https://discuss.elastic.co/t/bundling-elasticsearch-into-an-offline-electronjs-application/348768 "2023-12-07T00:56:59Z")

</div>

Hello, We've been trying to bundle Elasticsearch into an offline Electron application without success. Our goal is to provide offline full-text search functionality in an Electron app. We've used Elasticsearch extensiv…

---

## [Pagination Search - page 1 to page 5](https://discuss.elastic.co/t/pagination-search-page-1-to-page-5/348668)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 9:30pm UTC](https://discuss.elastic.co/t/pagination-search-page-1-to-page-5/348668 "2023-12-06T21:30:06Z")

</div>

Hi, We're trying to implement pagination for our application. We are displaying a table with 10 results per page. And we're wondering if it's possible to go from page 1 (record 1-10) to page 5 (record 51-60) in one jump…

---

## [Multi Index, Kibana Dashboard Controls dropdown](https://discuss.elastic.co/t/multi-index-kibana-dashboard-controls-dropdown/348557)

<div class="topic-metadata">

**Author:** [@Nikhil\_G\_P](https://discuss.elastic.co/u/Nikhil_G_P)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 9:21pm UTC](https://discuss.elastic.co/t/multi-index-kibana-dashboard-controls-dropdown/348557 "2023-12-06T21:21:37Z")

</div>

Hi Team, I hope this message finds you well. I wanted to bring to your attention a small challenge we're currently facing with our Kibana dashboards. We are utilizing Kibana version 8.11.1 and have set up two indices, n…

---

## [Logstash service is active, enabled but netstat output shows port not listening](https://discuss.elastic.co/t/logstash-service-is-active-enabled-but-netstat-output-shows-port-not-listening/348695)

<div class="topic-metadata">

**Author:** [@jayadevp](https://discuss.elastic.co/u/jayadevp)\
**Replies:** 17\
**Last updated:** [December 6, 2023, 7:54pm UTC](https://discuss.elastic.co/t/logstash-service-is-active-enabled-but-netstat-output-shows-port-not-listening/348695 "2023-12-06T19:54:58Z")

</div>

If i run the command to manually run logstash " sudo /usr/share/logstash/bin/logstash -f "/etc/logstash/conf.d/fortigate.conf" --config.reload.automatic" im able to see the output and netstat also shows port listening …

---

## [Scroll inner\_hits in Elasticsearch](https://discuss.elastic.co/t/scroll-inner-hits-in-elasticsearch/348757)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 7:38pm UTC](https://discuss.elastic.co/t/scroll-inner-hits-in-elasticsearch/348757 "2023-12-06T19:38:04Z")

</div>

I have a document that has nested items, and in some cases I need to query documents that have nested items that match the filter applied in the search and return all nested items that match. To do this, in the search q…

---

## [No d for data node anymore?](https://discuss.elastic.co/t/no-d-for-data-node-anymore/348736)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 7:20pm UTC](https://discuss.elastic.co/t/no-d-for-data-node-anymore/348736 "2023-12-06T19:20:53Z")

</div>

Looking at the documentation cat nodes API | Elasticsearch Guide \[8.11\] | Elastic It appears that a "Hot" node should have roles hd ... but that's not true in real life. Is a hot node not a "data" node? Are 'data\_content…

---

## [Logstash doesn't get logs from other container in Azure container group](https://discuss.elastic.co/t/logstash-doesnt-get-logs-from-other-container-in-azure-container-group/348755)

<div class="topic-metadata">

**Author:** [@TheNewGuy123](https://discuss.elastic.co/u/TheNewGuy123)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 5:50pm UTC](https://discuss.elastic.co/t/logstash-doesnt-get-logs-from-other-container-in-azure-container-group/348755 "2023-12-06T17:50:34Z")

</div>

Hey, I'm trying to debug why my Azure container based Logstash being a side car to my test application that periodically sends out logs with gelf isn't consuming those logs. So both containers (logstash and my app) are h…

---

## [Updating to version 7.17.15 caused the 'Failed to publish events' issue caused connection reset by peer](https://discuss.elastic.co/t/updating-to-version-7-17-15-caused-the-failed-to-publish-events-issue-caused-connection-reset-by-peer/348740)

<div class="topic-metadata">

**Author:** [@Saleh\_Houshangi](https://discuss.elastic.co/u/Saleh_Houshangi)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 4:10pm UTC](https://discuss.elastic.co/t/updating-to-version-7-17-15-caused-the-failed-to-publish-events-issue-caused-connection-reset-by-peer/348740 "2023-12-06T16:10:49Z")

</div>

After updating Elasticsearch and Logstash from version 7.17.5 to 7.17.15, all Filebeat instances sporadically encounter the following error in the log file: caa27ea3-c641-4ad2-9f03-578f008a4013'} 2023-12-06T16:06:56.260…

---

## [Use Logstash for access REST APIs and do complex queries or better Connector Clients](https://discuss.elastic.co/t/use-logstash-for-access-rest-apis-and-do-complex-queries-or-better-connector-clients/348725)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 3:47pm UTC](https://discuss.elastic.co/t/use-logstash-for-access-rest-apis-and-do-complex-queries-or-better-connector-clients/348725 "2023-12-06T15:47:55Z")

</div>

Hi anybody, has anybody experiences in using Logstash to gather data from a complex REST/JSON API. The API delivers user specific data similar to OneDrive or SharePoint. That means I have to access the (1) users list a…

---

## [How can set providers.docker.host when deploying elastic-agent via docker?](https://discuss.elastic.co/t/how-can-set-providers-docker-host-when-deploying-elastic-agent-via-docker/348737)

<div class="topic-metadata">

**Author:** [@JohannesKoch](https://discuss.elastic.co/u/JohannesKoch)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 3:45pm UTC](https://discuss.elastic.co/t/how-can-set-providers-docker-host-when-deploying-elastic-agent-via-docker/348737 "2023-12-06T15:45:24Z")

</div>

Hello, I have already setup elasticsearch, kibana and a fleet-server. They are all reachable and do get data from an elastic-agent running inside docker on another host. I don't like the idea of mounting the docker so…

---

## [Failed Snapshot using S3 Repository](https://discuss.elastic.co/t/failed-snapshot-using-s3-repository/348682)

<div class="topic-metadata">

**Author:** [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 3:13pm UTC](https://discuss.elastic.co/t/failed-snapshot-using-s3-repository/348682 "2023-12-06T15:13:32Z")

</div>

Guys, I am trying to take a snapshot of all my indexes in an S3 repository, I already checked the credentials and so on at the time of creating it and there was no problem, the problem occurs at the time of taking the sn…

---

## [Use logstash to connect VMware vCenter API?](https://discuss.elastic.co/t/use-logstash-to-connect-vmware-vcenter-api/348517)

<div class="topic-metadata">

**Author:** [@pyk346](https://discuss.elastic.co/u/pyk346)\
**Replies:** 7\
**Last updated:** [December 6, 2023, 2:33pm UTC](https://discuss.elastic.co/t/use-logstash-to-connect-vmware-vcenter-api/348517 "2023-12-06T14:33:35Z")

</div>

I'm trying to utilize the elastic logstash to obtain VMware vcenter datacenter metrics via API but failed to connect them. The vCenter version is 8.0.1. I had successfully configured "syslog" as input and recieved logs…

---

## [How to Setup File Integrity Monitoring with winlogbeat-7.3.2](https://discuss.elastic.co/t/how-to-setup-file-integrity-monitoring-with-winlogbeat-7-3-2/348655)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 2:40pm UTC](https://discuss.elastic.co/t/how-to-setup-file-integrity-monitoring-with-winlogbeat-7-3-2/348655 "2023-12-06T14:40:39Z")

</div>

Hi Team, I am trying to setup FIM feature using winlogbeat for windows servers. I can see there are ECS fields available ECS fields | Winlogbeat Reference \[7.3\] | Elastic But I don't see any proper configuration to se…

---

## [Event.Module (Auditd) for Auditbeat](https://discuss.elastic.co/t/event-module-auditd-for-auditbeat/348716)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 2\
**Last updated:** [December 6, 2023, 2:28pm UTC](https://discuss.elastic.co/t/event-module-auditd-for-auditbeat/348716 "2023-12-06T14:28:44Z")

</div>

Am trying to monitor logs in with Auditbeat version 7.4. specifically the auditd module.I have created a yml file to send send the logs to logstash. please how do I extract the time and date of each event in the auditd …

---

## [Missing metrics in Logstash node stats](https://discuss.elastic.co/t/missing-metrics-in-logstash-node-stats/348710)

<div class="topic-metadata">

**Author:** [@ofekinger](https://discuss.elastic.co/u/ofekinger)\
**Replies:** 3\
**Last updated:** [December 6, 2023, 2:20pm UTC](https://discuss.elastic.co/t/missing-metrics-in-logstash-node-stats/348710 "2023-12-06T14:20:08Z")

</div>

Hello everyone, I went over the code for a few Logstash plugins and noticed they had metrics that I can't see when running: curl http://localhost:9600/\_node/stats I'm talking about metrics like: And a few other plac…

---

## [Download Windows Agent from source artifacts.elastic.co](https://discuss.elastic.co/t/download-windows-agent-from-source-artifacts-elastic-co/348654)

<div class="topic-metadata">

**Author:** [@Tybe\_sacha](https://discuss.elastic.co/u/Tybe_sacha)\
**Replies:** 4\
**Last updated:** [December 6, 2023, 2:00pm UTC](https://discuss.elastic.co/t/download-windows-agent-from-source-artifacts-elastic-co/348654 "2023-12-06T14:00:04Z")

</div>

Hi, I'm trying to install the Fleet Server and Windows Agent. Here is text I paste : $ProgressPreference = 'SilentlyContinue' Invoke-WebRequest -Uri https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-ag…

---

## [JVM very greedy with memory. How do I get it to shrink when possible?](https://discuss.elastic.co/t/jvm-very-greedy-with-memory-how-do-i-get-it-to-shrink-when-possible/348657)

<div class="topic-metadata">

**Author:** [@Vulume](https://discuss.elastic.co/u/Vulume)\
**Replies:** 2\
**Last updated:** [December 6, 2023, 1:57pm UTC](https://discuss.elastic.co/t/jvm-very-greedy-with-memory-how-do-i-get-it-to-shrink-when-possible/348657 "2023-12-06T13:57:37Z")

</div>

I want my JVM to give back memory to the OS if it's not using it. I don't care about performance. When I set -Xms128m -Xmx4g, I see the JVM's memory usage grow while indexing and searching, but it never shrinks again af…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=355)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=357)
