# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=360

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 361

---

## [Compare 2 fields in different indexes in Kibana](https://discuss.elastic.co/t/compare-2-fields-in-different-indexes-in-kibana/347930)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 9:26pm UTC](https://discuss.elastic.co/t/compare-2-fields-in-different-indexes-in-kibana/347930 "2023-12-01T21:26:47Z")

</div>

Hi. I would like to create a report in Kibana that compares the value of 2 fields that exist in different indexes, and output a True or False if they do or do not match. E.g. index1.fieldA, index2.fieldA, is\_match I wa…

---

## [Connecting Kibana to different elastic single nodes](https://discuss.elastic.co/t/connecting-kibana-to-different-elastic-single-nodes/347830)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 9:15pm UTC](https://discuss.elastic.co/t/connecting-kibana-to-different-elastic-single-nodes/347830 "2023-12-01T21:15:04Z")

</div>

Hi, I am looking for a way to connect single Kibana to different kinds of elastic single nodes dynamically (without restarting the Kibana). When enabling Stack Monitoring, is there an option to define where to crea…

---

## [Security update associated with CVE-2023-31418 has confusing wording](https://discuss.elastic.co/t/security-update-associated-with-cve-2023-31418-has-confusing-wording/348457)

<div class="topic-metadata">

**Author:** [@jlasica](https://discuss.elastic.co/u/jlasica)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 8:48pm UTC](https://discuss.elastic.co/t/security-update-associated-with-cve-2023-31418-has-confusing-wording/348457 "2023-12-01T20:48:35Z")

</div>

According to this security update: Elasticsearch 8.9.0, 7.17.13 Security Update "Elastic Cloud Enterprise up to versions 2.13.3 and 3.6.0" -- does this mean that Elastic Cloud Enterprise is vulnerable all versions prior…

---

## [Elastic agent needs elasticseach ca from elastic cloud](https://discuss.elastic.co/t/elastic-agent-needs-elasticseach-ca-from-elastic-cloud/348273)

<div class="topic-metadata">

**Author:** [@logger](https://discuss.elastic.co/u/logger)\
**Replies:** 6\
**Last updated:** [December 1, 2023, 7:38pm UTC](https://discuss.elastic.co/t/elastic-agent-needs-elasticseach-ca-from-elastic-cloud/348273 "2023-12-01T19:38:26Z")

</div>

Hi there, currently I am a bit confused with the installation of fleet and elastic-agent. I am using the elastic cloud for elasticsearch, kibana and fleet. On my testserver, debian 10, we are behind a proxy. I have ex…

---

## [Parsing problem when streaming a log file](https://discuss.elastic.co/t/parsing-problem-when-streaming-a-log-file/348268)

<div class="topic-metadata">

**Author:** [@Kyps](https://discuss.elastic.co/u/Kyps)\
**Replies:** 26\
**Last updated:** [December 1, 2023, 6:59pm UTC](https://discuss.elastic.co/t/parsing-problem-when-streaming-a-log-file/348268 "2023-12-01T18:59:02Z")

</div>

Hey everyone, I followed the Stream any log file guide, and have set up a local agent that listens to my log file. But every time I add a new log (manually to test) the parsing just isn't there when it gets indexed in K…

---

## [Logstash stuck](https://discuss.elastic.co/t/logstash-stuck/348442)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 5:54pm UTC](https://discuss.elastic.co/t/logstash-stuck/348442 "2023-12-01T17:54:47Z")

</div>

I am getting to get started with logstash and simply copy a csv file to another file using the following conf: input { file{ path =\> "/Users/test/Desktop/project/test.csv" start\_position =\> "beginning" } } fi…

---

## [FScrawler "Failed to create elasticsearch client"](https://discuss.elastic.co/t/fscrawler-failed-to-create-elasticsearch-client/348438)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 5:42pm UTC](https://discuss.elastic.co/t/fscrawler-failed-to-create-elasticsearch-client/348438 "2023-12-01T17:42:45Z")

</div>

Hi, Im getting an error when I tried to run FScrawler to index a pdf to elasticsearch. Elastic version 8.9.2 on docker OS: redhat Firewall off Working curl: curl --cacert /u01/ca.crt https://localhost:9200 FScrawler…

---

## [I/O dispatch worker terminated abnormally](https://discuss.elastic.co/t/i-o-dispatch-worker-terminated-abnormally/348451)

<div class="topic-metadata">

**Author:** [@elaydi\_elagal](https://discuss.elastic.co/u/elaydi_elagal)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 5:01pm UTC](https://discuss.elastic.co/t/i-o-dispatch-worker-terminated-abnormally/348451 "2023-12-01T17:01:18Z")

</div>

In our production environment we try to fetch all the records based on index, but getting exception "Request cannot be executed i/o reactor status stopped" with high concurrency, we've encountered occasional connection …

---

## [Optimizing Storage Costs for Historical Data in Elasticsearch on Azure: Seeking Community Advice](https://discuss.elastic.co/t/optimizing-storage-costs-for-historical-data-in-elasticsearch-on-azure-seeking-community-advice/348440)

<div class="topic-metadata">

**Author:** [@identifysun](https://discuss.elastic.co/u/identifysun)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:41pm UTC](https://discuss.elastic.co/t/optimizing-storage-costs-for-historical-data-in-elasticsearch-on-azure-seeking-community-advice/348440 "2023-12-01T15:41:26Z")

</div>

I have an Elasticsearch cluster deployed on Azure. I need to retain historical data in Elasticsearch and currently use snapshot policies to store snapshots in Azure Blob storage. However, over time, I noticed that the st…

---

## [ELK 8.9.0 Caniuse Error during yarn build cause missing plugin build folder](https://discuss.elastic.co/t/elk-8-9-0-caniuse-error-during-yarn-build-cause-missing-plugin-build-folder/348171)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 8\
**Last updated:** [December 1, 2023, 3:13pm UTC](https://discuss.elastic.co/t/elk-8-9-0-caniuse-error-during-yarn-build-cause-missing-plugin-build-folder/348171 "2023-12-01T15:13:03Z")

</div>

I am seeing this error below during yarn build of our plugin. We had no build errors a few weeks ago. We do not get a build anymore, we should see this output in the logs below from yarn build, but we do not anymore. s…

---

## [Kibana visualization - Average of sum of grouped values](https://discuss.elastic.co/t/kibana-visualization-average-of-sum-of-grouped-values/348326)

<div class="topic-metadata">

**Author:** [@Gianfranco\_Demarco](https://discuss.elastic.co/u/Gianfranco_Demarco)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 3:02pm UTC](https://discuss.elastic.co/t/kibana-visualization-average-of-sum-of-grouped-values/348326 "2023-12-01T15:02:43Z")

</div>

Hello, i'm trying to achieve the following result using Kibana visualizations (Lens or others). I have an index where each document is a service delivery to a user. The documents have a cost and a user\_id. I want two…

---

## [Permanent truncate detection](https://discuss.elastic.co/t/permanent-truncate-detection/348254)

<div class="topic-metadata">

**Author:** [@terrainc](https://discuss.elastic.co/u/terrainc)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 2:33pm UTC](https://discuss.elastic.co/t/permanent-truncate-detection/348254 "2023-12-01T14:33:45Z")

</div>

Each 10min filebeat resending file to ELK. In logs we can find "File was truncated. Reading file from offset 0....". File wasn't rotated (state-id the same) or truncated. This file rotated daily only by logrotate (daily,…

---

## [Transmission of logs in real time mode](https://discuss.elastic.co/t/transmission-of-logs-in-real-time-mode/348319)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/transmission-of-logs-in-real-time-mode/348319 "2023-12-01T14:02:50Z")

</div>

Hello everybody Please tell me what the problem might be I have a mail server on which the filebeat agent is installed, it transfers data to another server on which logstash and elastic are installed I randomly displa…

---

## [How to change index rotation timezone for Elasticsearch 8.6 for UTC to localtimezone](https://discuss.elastic.co/t/how-to-change-index-rotation-timezone-for-elasticsearch-8-6-for-utc-to-localtimezone/348411)

<div class="topic-metadata">

**Author:** [@pix9](https://discuss.elastic.co/u/pix9)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 1:49pm UTC](https://discuss.elastic.co/t/how-to-change-index-rotation-timezone-for-elasticsearch-8-6-for-utc-to-localtimezone/348411 "2023-12-01T13:49:57Z")

</div>

Hi everyone, I am facing an issue while running queries on Elasticsearch, we are unable to fetch data between 12:00 AM to 05:30 AM, issue no data can be retrived from index between given time. Upon further investigatio…

---

## [Change tie breaker on aggregation](https://discuss.elastic.co/t/change-tie-breaker-on-aggregation/348434)

<div class="topic-metadata">

**Author:** [@Raphael\_Fidelis](https://discuss.elastic.co/u/Raphael_Fidelis)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 1:28pm UTC](https://discuss.elastic.co/t/change-tie-breaker-on-aggregation/348434 "2023-12-01T13:28:30Z")

</div>

Hello. As defined in the terms aggregation docs, Elastic uses alphabetical order as a tie-breaker for the aggregation results. However, I wanted to use the order that is returned by the query, i.e.: hits: \[ { …

---

## [Configure Two Instances of Filebeat](https://discuss.elastic.co/t/configure-two-instances-of-filebeat/347841)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 8\
**Last updated:** [December 1, 2023, 12:51pm UTC](https://discuss.elastic.co/t/configure-two-instances-of-filebeat/347841 "2023-12-01T12:51:08Z")

</div>

Hi Team, I had requirement like, need to run two instances of filebeat and both instances will load data to a particular Index. Is it possible to achieve the same if yes could you please let us know how we can do the s…

---

## [How do we remove Help icon from top right corner in kibana 8.5.3](https://discuss.elastic.co/t/how-do-we-remove-help-icon-from-top-right-corner-in-kibana-8-5-3/347816)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-do-we-remove-help-icon-from-top-right-corner-in-kibana-8-5-3/347816 "2023-12-01T12:31:40Z")

</div>

Hi Team, we are trying to hide the Help Icon from Kibana 8.5.3 on top right corner as below after we logged in. Thanks.

---

## [Maps is shown in field statistic but not in dashboard](https://discuss.elastic.co/t/maps-is-shown-in-field-statistic-but-not-in-dashboard/348350)

<div class="topic-metadata">

**Author:** [@DVD\_MNC](https://discuss.elastic.co/u/DVD_MNC)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 11:04am UTC](https://discuss.elastic.co/t/maps-is-shown-in-field-statistic-but-not-in-dashboard/348350 "2023-12-01T11:04:10Z")

</div>

Hi all, I'm facing some problem to draw a dashboard with geopoints. As you can see i have a value mapped as geopoint, minimap is shown in fields statistic tabs. But when i try to build a dashboard, kibana replies me sa…

---

## [How to correctly use \`search\_after\` for huge amount of records (100k+)?](https://discuss.elastic.co/t/how-to-correctly-use-search-after-for-huge-amount-of-records-100k/348426)

<div class="topic-metadata">

**Author:** [@MarinTakanov](https://discuss.elastic.co/u/MarinTakanov)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 11:03am UTC](https://discuss.elastic.co/t/how-to-correctly-use-search-after-for-huge-amount-of-records-100k/348426 "2023-12-01T11:03:59Z")

</div>

Can someone explain how to use search\_after for more than 100k records without fetching 10k records just to get the sort value of the last record just to get the next 10k records? Here's an example: I have 100 100 reco…

---

## [Windows FIM Module - how to use custom path without recursive](https://discuss.elastic.co/t/windows-fim-module-how-to-use-custom-path-without-recursive/348423)

<div class="topic-metadata">

**Author:** [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 10:51am UTC](https://discuss.elastic.co/t/windows-fim-module-how-to-use-custom-path-without-recursive/348423 "2023-12-01T10:51:52Z")

</div>

Hello, I have Windows Client and Windows DFS Server with multiple shares. I want to monitor File/folder activities aka File Integrity Monitoring. I already tried with Winlogbeat by monitoring Event ID 4656 and 4663 bu…

---

## [When migrating logstash from Centos to Debian I get the tag "\_grokparsefailure"](https://discuss.elastic.co/t/when-migrating-logstash-from-centos-to-debian-i-get-the-tag-grokparsefailure/348328)

<div class="topic-metadata">

**Author:** [@OptimusPrimary](https://discuss.elastic.co/u/OptimusPrimary)\
**Replies:** 5\
**Last updated:** [December 1, 2023, 8:54am UTC](https://discuss.elastic.co/t/when-migrating-logstash-from-centos-to-debian-i-get-the-tag-grokparsefailure/348328 "2023-12-01T08:54:27Z")

</div>

I need to migrate the ELK stack from Centos to Debian, on the server I installed the same version of logstash and the same settings, rights and configs, but the logs are not parsed. The tag "\_grokparsefailure" is assign…

---

## [Search on Array Field in ElasticSearch](https://discuss.elastic.co/t/search-on-array-field-in-elasticsearch/348406)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 8:12am UTC](https://discuss.elastic.co/t/search-on-array-field-in-elasticsearch/348406 "2023-12-01T08:12:00Z")

</div>

Hello, I have inserted data to an index from a csv file. And I have an Ids field like this whose datatype is a text or a keyword. "IDs": \[ "a07f1c55-e34b-467d-bfe2-f65f7e01ae61,3e7083d6-4e0c-4f7f-ac81-0d7c131ab58…

---

## [Filebeat not working with pipeline nor \* in csv is working](https://discuss.elastic.co/t/filebeat-not-working-with-pipeline-nor-in-csv-is-working/348388)

<div class="topic-metadata">

**Author:** [@mastinder](https://discuss.elastic.co/u/mastinder)\
**Replies:** 5\
**Last updated:** [December 1, 2023, 7:59am UTC](https://discuss.elastic.co/t/filebeat-not-working-with-pipeline-nor-in-csv-is-working/348388 "2023-12-01T07:59:35Z")

</div>

PUT \_ingest/pipeline/csv\_pipeline { "description": "A pipeline to parse CSV data", "processors": \[ { "csv": { "field": "message", "target\_fields": \["cluster", "index", "ilm\_policy", "time\_si…

---

## [Inquiry Regarding the "Webhook - Case Management" Connector's Transition from Technical Preview](https://discuss.elastic.co/t/inquiry-regarding-the-webhook-case-management-connectors-transition-from-technical-preview/348270)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 7:57am UTC](https://discuss.elastic.co/t/inquiry-regarding-the-webhook-case-management-connectors-transition-from-technical-preview/348270 "2023-12-01T07:57:08Z")

</div>

Hello Elastic Community, I am currently considering the integration of a "Webhook - Case Management" connector with our IT Service Management (ITSM) system. Given its current status as a feature in technical preview, I'…

---

## [Cannot search my pdf files](https://discuss.elastic.co/t/cannot-search-my-pdf-files/348297)

<div class="topic-metadata">

**Author:** [@Mandy\_Poon](https://discuss.elastic.co/u/Mandy_Poon)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 7:44am UTC](https://discuss.elastic.co/t/cannot-search-my-pdf-files/348297 "2023-12-01T07:44:33Z")

</div>

I have a pdf file and there is a wording "XXX Contract ID - 170458" on the pdf. However I cannot search my file if I use "Contract ID - 170458". (I can search the pdf file if I use "170458") Anyone can help? Thank yo…

---

## [Update record in Kafka-Elastic Pipelines through Logstash](https://discuss.elastic.co/t/update-record-in-kafka-elastic-pipelines-through-logstash/348401)

<div class="topic-metadata">

**Author:** [@Alberuni\_Beruni](https://discuss.elastic.co/u/Alberuni_Beruni)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 7:31am UTC](https://discuss.elastic.co/t/update-record-in-kafka-elastic-pipelines-through-logstash/348401 "2023-12-01T07:31:51Z")

</div>

Hi, I am directly ingesting kafka recored from kafka topic to Elasticsearch server, if there is coming records is updated with the existing in Elasticsearch server so how can i handle it with logstash that if creation i…

---

## [AWS Integration - Poor Performance](https://discuss.elastic.co/t/aws-integration-poor-performance/348397)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 6:20am UTC](https://discuss.elastic.co/t/aws-integration-poor-performance/348397 "2023-12-01T06:20:35Z")

</div>

I have deployed an elastic agent with the AWS Integration in order to process VPC and CloudTrail logs. The logs are being placed to seperate S3 buckets which in turn then trigger an event to an SQS queue - one for the V…

---

## [MetricBeat: System module does not seems to send any data to ES](https://discuss.elastic.co/t/metricbeat-system-module-does-not-seems-to-send-any-data-to-es/348302)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 6:06am UTC](https://discuss.elastic.co/t/metricbeat-system-module-does-not-seems-to-send-any-data-to-es/348302 "2023-12-01T06:06:52Z")

</div>

I have metricbeat running inside a docker container, and have been able to successfully get docker and ES stack monitored. I'm trying to extend the monitoring to the system. However, I'm unable to see any of the system s…

---

## [Limit on number of remote clusters in Cross-cluster search](https://discuss.elastic.co/t/limit-on-number-of-remote-clusters-in-cross-cluster-search/348395)

<div class="topic-metadata">

**Author:** [@Naveen\_Kumar\_S](https://discuss.elastic.co/u/Naveen_Kumar_S)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 5:52am UTC](https://discuss.elastic.co/t/limit-on-number-of-remote-clusters-in-cross-cluster-search/348395 "2023-12-01T05:52:03Z")

</div>

Brief Info: I am planning to create a multi-cluster (around 50 clusters) Elasticsearch setup to store a large amount of data (around 7 years of enterprise data). This number is based on thorough planning considering the…

---

## [I have installed a 7.17.3 metric beat and file beat, both the beats are unable to send data to the logstash](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 13\
**Last updated:** [December 1, 2023, 5:24am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018 "2023-12-01T05:24:15Z")

</div>

Hi Team, I have a 3 node elk cluster 7.17.3 , i have installed metricbeats and file beat on a new server , the logstash ports are opened(5044). i have checked telnet. the connection looks fine. The beats are unable to …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=359)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=361)
