# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=357

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 358

---

## [How to know if the result was due to a fuzzysearch?](https://discuss.elastic.co/t/how-to-know-if-the-result-was-due-to-a-fuzzysearch/348726)

<div class="topic-metadata">

**Author:** [@vidhaat](https://discuss.elastic.co/u/vidhaat)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 1:50pm UTC](https://discuss.elastic.co/t/how-to-know-if-the-result-was-due-to-a-fuzzysearch/348726 "2023-12-06T13:50:34Z")

</div>

I have a query where I get results which may or may not have fuzzy search results. I want to get analytics on what results are the result of fuzzy search. How can this be achieved ? { "query": { "bool": { "f…

---

## [Grok-Debugger API-Endpoint](https://discuss.elastic.co/t/grok-debugger-api-endpoint/348317)

<div class="topic-metadata">

**Author:** [@justin\_sch](https://discuss.elastic.co/u/justin_sch)\
**Replies:** 5\
**Last updated:** [December 6, 2023, 1:01pm UTC](https://discuss.elastic.co/t/grok-debugger-api-endpoint/348317 "2023-12-06T13:01:52Z")

</div>

Hey, I'd like to use the grokdebuggerof the devtools via an api-endpoint. Unfortunally I can't find any documentation of this, is this tool even available via the rest-api?

---

## [Logstash stdout output text as in file](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675)

<div class="topic-metadata">

**Author:** [@carter.kovrov](https://discuss.elastic.co/u/carter.kovrov)\
**Replies:** 6\
**Last updated:** [December 6, 2023, 11:48am UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675 "2023-12-06T11:48:31Z")

</div>

Hi all Tell me how to display information as in a file without additional fields? For example, there is a file app.log with the contents 12-15-2023 app running... 12-15-2023 app login user test necessary information …

---

## [JDBC Static Filter Plugin - Error handling, how to skip enrichment when Database is down](https://discuss.elastic.co/t/jdbc-static-filter-plugin-error-handling-how-to-skip-enrichment-when-database-is-down/347204)

<div class="topic-metadata">

**Author:** [@tori](https://discuss.elastic.co/u/tori)\
**Replies:** 2\
**Last updated:** [December 6, 2023, 10:40am UTC](https://discuss.elastic.co/t/jdbc-static-filter-plugin-error-handling-how-to-skip-enrichment-when-database-is-down/347204 "2023-12-06T10:40:58Z")

</div>

Hi, We've got logstash fetching some information from a MySQL database for log enrichment via JDBC Static Filter Plugin. The settings work just fine when things are working as expected: ... jdbc\_static { l…

---

## [SWEET32 Vulnerability Remediation for Elastic Fleet](https://discuss.elastic.co/t/sweet32-vulnerability-remediation-for-elastic-fleet/348598)

<div class="topic-metadata">

**Author:** [@jakechoi](https://discuss.elastic.co/u/jakechoi)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 10:28am UTC](https://discuss.elastic.co/t/sweet32-vulnerability-remediation-for-elastic-fleet/348598 "2023-12-06T10:28:39Z")

</div>

Apologies if this is the wrong location to post this topic. I've been troubleshooting a vulnerability found by our Nessus scanner on our Kibana instance. Nessus shows that the port used by our fleet on our Kibana instan…

---

## [Kibana Azure AD SSO Authentication](https://discuss.elastic.co/t/kibana-azure-ad-sso-authentication/348692)

<div class="topic-metadata">

**Author:** [@Ilter\_Sag](https://discuss.elastic.co/u/Ilter_Sag)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 8:37am UTC](https://discuss.elastic.co/t/kibana-azure-ad-sso-authentication/348692 "2023-12-06T08:37:34Z")

</div>

Hello, I am trying to setup Kibana Authentication with Azure AD SSO and getting this error. What will be the cause of that error? My server has connection to login.microsoftonline.com and can fetch federation xml. Ela…

---

## [Stack Monitoring with Fleet/elastic-agent](https://discuss.elastic.co/t/stack-monitoring-with-fleet-elastic-agent/347244)

<div class="topic-metadata">

**Author:** [@rastro](https://discuss.elastic.co/u/rastro)\
**Replies:** 36\
**Last updated:** [December 6, 2023, 8:25am UTC](https://discuss.elastic.co/t/stack-monitoring-with-fleet-elastic-agent/347244 "2023-12-06T08:25:21Z")

</div>

In Kibana, when you go to Stack Monitoring, it says "No monitoring data found" and suggests using Metricbeat. Except, shouldn't we be using Elastic Agent? So, how can I get the Stack Monitoring page working with Agent?…

---

## [Custom analyzer for search and indexing](https://discuss.elastic.co/t/custom-analyzer-for-search-and-indexing/348661)

<div class="topic-metadata">

**Author:** [@ssanja](https://discuss.elastic.co/u/ssanja)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 6:33am UTC](https://discuss.elastic.co/t/custom-analyzer-for-search-and-indexing/348661 "2023-12-06T06:33:34Z")

</div>

Hello, when creating an index I specifically created a custom analyzer which should be used for indexing and searching (see the example code below) "settings": { "analysis": { "analyzer": { "custom\_…

---

## [Azure AD SSO setting behind a proxy not working](https://discuss.elastic.co/t/azure-ad-sso-setting-behind-a-proxy-not-working/346654)

<div class="topic-metadata">

**Author:** [@Ilter\_Sag](https://discuss.elastic.co/u/Ilter_Sag)\
**Replies:** 5\
**Last updated:** [December 6, 2023, 5:28am UTC](https://discuss.elastic.co/t/azure-ad-sso-setting-behind-a-proxy-not-working/346654 "2023-12-06T05:28:36Z")

</div>

Hello, I am trying to integrate Azure AD to Elasticsearch cluster behind a proxy. I tried the proxy parameter settings below but could not succeeded. You can find the log behind that post. It say it cannot access to mic…

---

## [Using Debug.explain kills data nodes. (8.11.1)](https://discuss.elastic.co/t/using-debug-explain-kills-data-nodes-8-11-1/348690)

<div class="topic-metadata">

**Author:** [@ong-ar](https://discuss.elastic.co/u/ong-ar)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 3:35am UTC](https://discuss.elastic.co/t/using-debug-explain-kills-data-nodes-8-11-1/348690 "2023-12-06T03:35:44Z")

</div>

Elasticsearch Version Version: 8.11.1, Build: rpm/6f9ff581fbcde658e6f69d6ce03050f060d1fd0c/2023-11-11T10:05:59.421038163Z, JVM: 21.0.1 Installed Plugins Java Version openjdk version "21.0.1" OS Version 6.1.61-85.141.…

---

## [How to Implement a Flexible Search Method in Java with Low Level Client to Filter, Sort, and Limit Fields?](https://discuss.elastic.co/t/how-to-implement-a-flexible-search-method-in-java-with-low-level-client-to-filter-sort-and-limit-fields/346253)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 4\
**Last updated:** [December 6, 2023, 2:29am UTC](https://discuss.elastic.co/t/how-to-implement-a-flexible-search-method-in-java-with-low-level-client-to-filter-sort-and-limit-fields/346253 "2023-12-06T02:29:18Z")

</div>

Hello, I'm working on implementing a search method in Java that needs to support several variations of search criteria. Specifically, I need the method to be able to: Search by a term within certain fields, conditiona…

---

## [Fields are not populating from logstash to elastic](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593)

<div class="topic-metadata">

**Author:** [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Replies:** 10\
**Last updated:** [December 5, 2023, 10:44pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593 "2023-12-05T22:44:34Z")

</div>

I am using logstash to populate elastic I have it set so this filter: filter { json { source =\> "message" target =\> "jsoncontent" remove\_field =\> \["message"\] } } and jsoncontent: {"switchname": "swi…

---

## [Accuracy of date histogram sub-aggregation doc count under terms aggregation](https://discuss.elastic.co/t/accuracy-of-date-histogram-sub-aggregation-doc-count-under-terms-aggregation/348685)

<div class="topic-metadata">

**Author:** [@myronmarston](https://discuss.elastic.co/u/myronmarston)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 10:26pm UTC](https://discuss.elastic.co/t/accuracy-of-date-histogram-sub-aggregation-doc-count-under-terms-aggregation/348685 "2023-12-05T22:26:57Z")

</div>

Hello, I am working on query that combines a terms aggregation with a date histogram sub-aggregation. I would like to get the doc count of each sub-aggregation bucket, determine if it is accurate, and, if it is not acc…

---

## [Kibana Password User Interface](https://discuss.elastic.co/t/kibana-password-user-interface/348669)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 10:15pm UTC](https://discuss.elastic.co/t/kibana-password-user-interface/348669 "2023-12-05T22:15:49Z")

</div>

Hello, Again I ejjeje, I can't get past this point, what should I do? And if I don't want to be prompted for a password, what can I do?

---

## [Connection reset when ingesting data from Filebeat to Logstash](https://discuss.elastic.co/t/connection-reset-when-ingesting-data-from-filebeat-to-logstash/348681)

<div class="topic-metadata">

**Author:** [@epronetlc](https://discuss.elastic.co/u/epronetlc)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 8:55pm UTC](https://discuss.elastic.co/t/connection-reset-when-ingesting-data-from-filebeat-to-logstash/348681 "2023-12-05T20:55:06Z")

</div>

I have Filebeat 8.11.1 configured on a server running Windows Server 2019 with an output to Logstash. I have Logstash 8.11.1 configured on a server running Windows Server 2022 with an input from beats and an output to JD…

---

## [Default ingest pipeline overwritten](https://discuss.elastic.co/t/default-ingest-pipeline-overwritten/348640)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 5\
**Last updated:** [December 5, 2023, 6:05pm UTC](https://discuss.elastic.co/t/default-ingest-pipeline-overwritten/348640 "2023-12-05T18:05:17Z")

</div>

Hi, I created an index template \`logs-{dataset\_name}-default' as well as setting up a data stream. I also setup a default ingest pipeline for this index. However after a number of days (and maybe coincidentally an Elas…

---

## [Grok\_timeout coming in logstash logs](https://discuss.elastic.co/t/grok-timeout-coming-in-logstash-logs/348623)

<div class="topic-metadata">

**Author:** [@Biswajit\_naik](https://discuss.elastic.co/u/Biswajit_naik)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 5:25pm UTC](https://discuss.elastic.co/t/grok-timeout-coming-in-logstash-logs/348623 "2023-12-05T17:25:00Z")

</div>

when i process multiple type of logs by grok parser ,if the one of logline is not matched with the filter parser ,then i am excepting that it should be come grok parser faliure ,but it comes grok timeout warning in Logst…

---

## [Drop logstash logs not containing certain field](https://discuss.elastic.co/t/drop-logstash-logs-not-containing-certain-field/348626)

<div class="topic-metadata">

**Author:** [@e.vedelaar](https://discuss.elastic.co/u/e.vedelaar)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 5:23pm UTC](https://discuss.elastic.co/t/drop-logstash-logs-not-containing-certain-field/348626 "2023-12-05T17:23:13Z")

</div>

I want to drop all logs who don't contain the dns.question.name field (or if the field is empty) how would i do this?

---

## [Critical vulns in logstash docker: CVE-2022-46337, CVE-2021-26291](https://discuss.elastic.co/t/critical-vulns-in-logstash-docker-cve-2022-46337-cve-2021-26291/348637)

<div class="topic-metadata">

**Author:** [@AdrianTT](https://discuss.elastic.co/u/AdrianTT)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 5:11pm UTC](https://discuss.elastic.co/t/critical-vulns-in-logstash-docker-cve-2022-46337-cve-2021-26291/348637 "2023-12-05T17:11:36Z")

</div>

trivy reports in the logstash:8.11 docker image the following critical vulns: CVE-2022-46337 in org.apache.derby:derby (derby-10.14.1.0.jar) CVE-2021-26291 in org.apache.maven:maven-compat (maven-compat-3.3.9.jar), org…

---

## [How to connect to \`elasticsearch\` version \`8.x\` using \`API Key\` from \`logstash\`?](https://discuss.elastic.co/t/how-to-connect-to-elasticsearch-version-8-x-using-api-key-from-logstash/348612)

<div class="topic-metadata">

**Author:** [@pushanbhattacharya](https://discuss.elastic.co/u/pushanbhattacharya)\
**Replies:** 4\
**Last updated:** [December 5, 2023, 4:21pm UTC](https://discuss.elastic.co/t/how-to-connect-to-elasticsearch-version-8-x-using-api-key-from-logstash/348612 "2023-12-05T16:21:34Z")

</div>

Hi, I have been using ELK since last 5 years. My codebase is mostly for logstash where the input is a JDBC connection (DB) and after filtering output is the Elasticsearch cluster (for most of the cases). So far I was u…

---

## [On Docker containers. Kibana connect to cloud instead the Elasticsearch container](https://discuss.elastic.co/t/on-docker-containers-kibana-connect-to-cloud-instead-the-elasticsearch-container/348336)

<div class="topic-metadata">

**Author:** [@Juan\_Pablo\_Scodelari](https://discuss.elastic.co/u/Juan_Pablo_Scodelari)\
**Replies:** 7\
**Last updated:** [December 5, 2023, 3:33pm UTC](https://discuss.elastic.co/t/on-docker-containers-kibana-connect-to-cloud-instead-the-elasticsearch-container/348336 "2023-12-05T15:33:45Z")

</div>

Hi, I want to install and run locally Elasticsearch and Kibana with Docker. I've tried several methods and reinstalled everything, many times with no success. I can't get Kibana to connect to the elasticsearch in the …

---

## [Add Geojson Files to Elastic Map Service](https://discuss.elastic.co/t/add-geojson-files-to-elastic-map-service/348646)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 3:10pm UTC](https://discuss.elastic.co/t/add-geojson-files-to-elastic-map-service/348646 "2023-12-05T15:10:31Z")

</div>

We have some geojson files that we created that we would like to add to our Elastic Map Service instance. Examples - airports.geojson that has geo points of airports worldwide us\_states\_territories.geojson that includ…

---

## [A question about Logstash S3 output plugin behaviour](https://discuss.elastic.co/t/a-question-about-logstash-s3-output-plugin-behaviour/348651)

<div class="topic-metadata">

**Author:** [@milon.james](https://discuss.elastic.co/u/milon.james)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:33pm UTC](https://discuss.elastic.co/t/a-question-about-logstash-s3-output-plugin-behaviour/348651 "2023-12-05T14:33:35Z")

</div>

Hello, Would like to know what is the default behaviour of Logstash S3 output plugin if we stop the process. Can we configure the plugin to close all the open temporary files and push them to S3 before the process shuts…

---

## [Remove N leading bytes from TCP input](https://discuss.elastic.co/t/remove-n-leading-bytes-from-tcp-input/348650)

<div class="topic-metadata">

**Author:** [@rcz](https://discuss.elastic.co/u/rcz)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:29pm UTC](https://discuss.elastic.co/t/remove-n-leading-bytes-from-tcp-input/348650 "2023-12-05T14:29:03Z")

</div>

Hi, We are receiving some dubious Protobuf-encoded messages on our TCP input. The sender is leading with a custom length-header of 4 bytes. If we manually dissect the messages, remove the first 4 bytes, and then give …

---

## [CreateIndexRequest with date math](https://discuss.elastic.co/t/createindexrequest-with-date-math/348496)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 1:52pm UTC](https://discuss.elastic.co/t/createindexrequest-with-date-math/348496 "2023-12-05T13:52:55Z")

</div>

Hi I am using RestHighLevelClient 7.13. I am trying to create an index with date math: CreateIndexRequest cir = new CreateIndexRequest("\<books-{now/d}-0001\>"); It create an index with the name books, without the date…

---

## [One Kibana for multiple Elastic Clusters](https://discuss.elastic.co/t/one-kibana-for-multiple-elastic-clusters/348539)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 1:18pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-elastic-clusters/348539 "2023-12-05T13:18:56Z")

</div>

Hi everyone, I have a technical doubt regarding the capabilities of Kibana. I currently run an Elasticsearch Cluster with some storage issues and we cannot increase the storage size due to some limitations. However, we …

---

## [Logstash config](https://discuss.elastic.co/t/logstash-config/348644)

<div class="topic-metadata">

**Author:** [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 1:16pm UTC](https://discuss.elastic.co/t/logstash-config/348644 "2023-12-05T13:16:17Z")

</div>

I have installed 7.15.0 version of Logstash. I have the following config file: input { file { path =\> "C:/Users/ELK Stack/data/sample.csv" start\_position =\> "beginning" sincedb\_path =\> "NUL" } } filter { csv {…

---

## ["has no content yet" spam](https://discuss.elastic.co/t/has-no-content-yet-spam/347003)

<div class="topic-metadata">

**Author:** [@terrainc](https://discuss.elastic.co/u/terrainc)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 1:10pm UTC](https://discuss.elastic.co/t/has-no-content-yet-spam/347003 "2023-12-05T13:10:07Z")

</div>

After Fix empty file edge case by rdner · Pull Request #36076 · elastic/beats · GitHub my logs now full of spam "has no content yet, skipping" for all zero size logs. And on the "warning" level =(

---

## [The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/348635)

<div class="topic-metadata">

**Author:** [@GRK](https://discuss.elastic.co/u/GRK)\
**Replies:** 7\
**Last updated:** [December 5, 2023, 12:29pm UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/348635 "2023-12-05T12:29:19Z")

</div>

Invalid NEST response built from a unsuccessful () low level call on HEAD: /indexname Audit trail of this API call: \[1\] ProductCheckOnStartup: Took: \[2\] ProductCheckFailure: Node: OriginalException: Elasticsearch.Net…

---

## [Master node is not able to collect garbage memory](https://discuss.elastic.co/t/master-node-is-not-able-to-collect-garbage-memory/348625)

<div class="topic-metadata">

**Author:** [@equisde](https://discuss.elastic.co/u/equisde)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 10:46am UTC](https://discuss.elastic.co/t/master-node-is-not-able-to-collect-garbage-memory/348625 "2023-12-05T10:46:06Z")

</div>

The active master node in my Elasticsearch cluster is not able to collect garbage memory. All other standby master nodes are fine. Symptoms: Heap gets increasing forever ES Version: 7.16.3 Nodes: 3 master nodes,…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=356)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=358)
