# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=367

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 368

---

## [How to get a NodeClient inside a plugin?](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-plugin/347703)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 10:13am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-plugin/347703 "2023-11-23T10:13:36Z")

</div>

I am currently working on developing a schedule plugin for Elasticsearch. The objective is to display only the index number every 5 minutes. However, I am encountering an issue where the NodeClient is consistently null. …

---

## [Multy-tenany elasticsearch](https://discuss.elastic.co/t/multy-tenany-elasticsearch/347832)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 10:05am UTC](https://discuss.elastic.co/t/multy-tenany-elasticsearch/347832 "2023-11-23T10:05:24Z")

</div>

I am currently working on implementing multi-tenancy in Elasticsearch and have come across two prominent approaches: using a shared index across multiple tenants and having a dedicated index per tenant. As part of my res…

---

## [\["org.elasticsearch.bootstrap.StartupException: ElasticsearchException\[failed to bind service\]; nested: CorruptIndexException\[codec footer mismatch (file truncated?)](https://discuss.elastic.co/t/org-elasticsearch-bootstrap-startupexception-elasticsearchexception-failed-to-bind-service-nested-corruptindexexception-codec-footer-mismatch-file-truncated/347642)

<div class="topic-metadata">

**Author:** [@lins](https://discuss.elastic.co/u/lins)\
**Replies:** 11\
**Last updated:** [November 23, 2023, 8:23am UTC](https://discuss.elastic.co/t/org-elasticsearch-bootstrap-startupexception-elasticsearchexception-failed-to-bind-service-nested-corruptindexexception-codec-footer-mismatch-file-truncated/347642 "2023-11-23T08:23:18Z")

</div>

{"type": "server", "timestamp": "2023-11-21T09:52:52,412Z", "level": "ERROR", "component": "o.e.b.ElasticsearchUncaughtExceptionHandler", "cluster.name": "elasticsearch", "node.name": "elasticsearch-es-master-1", "messag…

---

## [Snowflake to Elasticsearch](https://discuss.elastic.co/t/snowflake-to-elasticsearch/347543)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 8\
**Last updated:** [November 23, 2023, 8:14am UTC](https://discuss.elastic.co/t/snowflake-to-elasticsearch/347543 "2023-11-23T08:14:57Z")

</div>

Hi Team , We are trying to pull data from Snowflake database to Elasticsaerch via Logstash JDBC plugin Input Config: input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/logstash-core/lib/jars/snowflake-jd…

---

## [SSL Certificate issues](https://discuss.elastic.co/t/ssl-certificate-issues/347390)

<div class="topic-metadata">

**Author:** [@nvanalphen](https://discuss.elastic.co/u/nvanalphen)\
**Replies:** 12\
**Last updated:** [November 23, 2023, 8:14am UTC](https://discuss.elastic.co/t/ssl-certificate-issues/347390 "2023-11-23T08:14:56Z")

</div>

I am trying to set up a server to evaluate and determine if/how we can use this solution. Unfortunately I am going mad trying to set it up. I have been trying, searching, reading and trying again for over a week now and…

---

## [How to debug http.max\_content\_length on elasticsearch](https://discuss.elastic.co/t/how-to-debug-http-max-content-length-on-elasticsearch/347754)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-debug-http-max-content-length-on-elasticsearch/347754 "2023-11-22T15:03:21Z")

</div>

Hi Is it possible to trace a log on elasticsearch for http.max\_content\_length ? Thx!

---

## [Elasticapm.properties didn't read in java springboot](https://discuss.elastic.co/t/elasticapm-properties-didnt-read-in-java-springboot/347824)

<div class="topic-metadata">

**Author:** [@kasunpurnima](https://discuss.elastic.co/u/kasunpurnima)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 7:17am UTC](https://discuss.elastic.co/t/elasticapm-properties-didnt-read-in-java-springboot/347824 "2023-11-23T07:17:46Z")

</div>

Hi, Im using below services, java 8 elasticsearch-8.2.3 kibana-8.2.3 apm-server-8.2.3 elastic-apm-agent-1.44.jar When im using elasticapm.properties below details its not take it and not going hit APM service\_name…

---

## [Send output socket tcp or udp in line protocol format](https://discuss.elastic.co/t/send-output-socket-tcp-or-udp-in-line-protocol-format/347810)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 4:37am UTC](https://discuss.elastic.co/t/send-output-socket-tcp-or-udp-in-line-protocol-format/347810 "2023-11-23T04:37:15Z")

</div>

Hi need to send data with tcp or udp in line protocol format instead on influx or http output plugin. Is it possible to create message format like http output plugin? Any idea? Thank

---

## [Logstash to influxdb2 aggregate datapoints issue](https://discuss.elastic.co/t/logstash-to-influxdb2-aggregate-datapoints-issue/347809)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 4:14am UTC](https://discuss.elastic.co/t/logstash-to-influxdb2-aggregate-datapoints-issue/347809 "2023-11-23T04:14:32Z")

</div>

Hi I have lots of log lines like this in exact same time, when i try to use logstash to pars and send to influxdb2, influx or ligstash aggregates some lines! e.g here is the sample lines that aggregate is I\[847676\] 20…

---

## [Elasticsearch Cluster Down automatically](https://discuss.elastic.co/t/elasticsearch-cluster-down-automatically/347808)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 3:49am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-down-automatically/347808 "2023-11-23T03:49:13Z")

</div>

Hi Team, I deployed Elasticsearch Cluster on docker with 2 nodes (two containers). everything working well. but due to some technical issues sometimes need to restart the containers at that time master node up and runnin…

---

## [Reason: Setting "monitoring.enabled" doesn't exist](https://discuss.elastic.co/t/reason-setting-monitoring-enabled-doesnt-exist/347731)

<div class="topic-metadata">

**Author:** [@Vivi\_Allen](https://discuss.elastic.co/u/Vivi_Allen)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 3:48am UTC](https://discuss.elastic.co/t/reason-setting-monitoring-enabled-doesnt-exist/347731 "2023-11-23T03:48:33Z")

</div>

I want to enable monitor for logstash with metricbeat. Following this guide Collect Logstash monitoring data with Metricbeat | Logstash Reference \[8.11\] | Elastic, I add monitoring.enabled: false to the logstash.yml. T…

---

## [ElasticsearchTemplate/client 8.7.1 with springboot 3.x Aggregation](https://discuss.elastic.co/t/elasticsearchtemplate-client-8-7-1-with-springboot-3-x-aggregation/347740)

<div class="topic-metadata">

**Author:** [@Priyank07](https://discuss.elastic.co/u/Priyank07)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 1:33pm UTC](https://discuss.elastic.co/t/elasticsearchtemplate-client-8-7-1-with-springboot-3-x-aggregation/347740 "2023-11-22T13:33:02Z")

</div>

Hi, I want to query elasticsearch document with aggregation. My use case : I want to sum the amount based on term aggregation on a particular field. I am able to do it with elasticsearch 7.17.3. Now I have to update i…

---

## [Logstash / problem with windows index](https://discuss.elastic.co/t/logstash-problem-with-windows-index/347545)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 3:35am UTC](https://discuss.elastic.co/t/logstash-problem-with-windows-index/347545 "2023-11-23T03:35:21Z")

</div>

Hello, could you please help me? Im using Elastic version 8.11.1 Im trying to create new 2 indexes for windows and linux. This code below is working for linux (it is automaticaly creating indexes every day), but it i…

---

## [org.elasticsearch.hadoop.rest.EsHadoopRemoteException: illegal\_argument\_exception: value for key \[X-Opaque-Id\] already present](https://discuss.elastic.co/t/org-elasticsearch-hadoop-rest-eshadoopremoteexception-illegal-argument-exception-value-for-key-x-opaque-id-already-present/347380)

<div class="topic-metadata">

**Author:** [@Akhil\_parmar](https://discuss.elastic.co/u/Akhil_parmar)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 3:18am UTC](https://discuss.elastic.co/t/org-elasticsearch-hadoop-rest-eshadoopremoteexception-illegal-argument-exception-value-for-key-x-opaque-id-already-present/347380 "2023-11-23T03:18:13Z")

</div>

I am working on ETL job where target to load data to elasticsearch, I am facing an error when trying to index document org.elasticsearch.hadoop.rest.EsHadoopRemoteException: illegal\_argument\_exception: value for key \[X-…

---

## [Can I convert epoch time via data views to be readable?](https://discuss.elastic.co/t/can-i-convert-epoch-time-via-data-views-to-be-readable/347677)

<div class="topic-metadata">

**Author:** [@geeboy1](https://discuss.elastic.co/u/geeboy1)\
**Replies:** 6\
**Last updated:** [November 23, 2023, 3:15am UTC](https://discuss.elastic.co/t/can-i-convert-epoch-time-via-data-views-to-be-readable/347677 "2023-11-23T03:15:45Z")

</div>

good day, my app log is in epoch time format (sample: 1700529701700), can I convert this using script in data views to be human readable format in discover menu? or any suggestion how to convert this? i saw this in goo…

---

## [L2norm script in source compiles error because Cannot cast from \[double\] to \[int\]](https://discuss.elastic.co/t/l2norm-script-in-source-compiles-error-because-cannot-cast-from-double-to-int/347799)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 1:38am UTC](https://discuss.elastic.co/t/l2norm-script-in-source-compiles-error-because-cannot-cast-from-double-to-int/347799 "2023-11-23T01:38:56Z")

</div>

"source": "double norm=l2norm(params.queryVector, 'vec')^2; return 1/(1+norm);" or "source": "1/(1+l2norm(params.queryVector, 'vec')^2)" or "source": "1.0/(1.0+l2norm(params.queryVector, 'vec')^2)" all result in "c…

---

## [Importing Index Patterns](https://discuss.elastic.co/t/importing-index-patterns/347275)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:28pm UTC](https://discuss.elastic.co/t/importing-index-patterns/347275 "2023-11-22T22:28:04Z")

</div>

Hello there, I have read it is possible to export index patterns from one elasticsearch cluster to another. Will this include all the fields and scripted fields and is this a viable way of insuring the mapping is the s…

---

## [How to parse a stringify sale on the label?](https://discuss.elastic.co/t/how-to-parse-a-stringify-sale-on-the-label/347794)

<div class="topic-metadata">

**Author:** [@thiagobr](https://discuss.elastic.co/u/thiagobr)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 10:25pm UTC](https://discuss.elastic.co/t/how-to-parse-a-stringify-sale-on-the-label/347794 "2023-11-22T22:25:52Z")

</div>

I'm using the library "@elastic/apm-rum-angular": "^2.1.7" for Angular 11, I'm already receiving the data through transaction + span + addLabels. However, the addLabel parameter only accepts string, boolean or number, a…

---

## [ALB health check failure while checking Elasticsearch cluster health](https://discuss.elastic.co/t/alb-health-check-failure-while-checking-elasticsearch-cluster-health/347018)

<div class="topic-metadata">

**Author:** [@siddharthavempa](https://discuss.elastic.co/u/siddharthavempa)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 1:33pm UTC](https://discuss.elastic.co/t/alb-health-check-failure-while-checking-elasticsearch-cluster-health/347018 "2023-11-13T13:33:35Z")

</div>

Hi Team, I am creating a two node Elasticsearch cluster in AWS using EC2 instances. I installed Elasticsearch in node-1 using rpm. Then I used the below commands to modify the elasticsearch.yaml file and started elasti…

---

## [Display partially structured data into multiple columns in Kibana Discover](https://discuss.elastic.co/t/display-partially-structured-data-into-multiple-columns-in-kibana-discover/347254)

<div class="topic-metadata">

**Author:** [@Selma](https://discuss.elastic.co/u/Selma)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:11pm UTC](https://discuss.elastic.co/t/display-partially-structured-data-into-multiple-columns-in-kibana-discover/347254 "2023-11-22T22:11:25Z")

</div>

I am trying to get the data as separate columns based on the fields serviceName, flowName, correlationId and timestamp from below log field. can this be achieved through scripts in Kibana UI itself ? If not is there an a…

---

## [Upgrading system indices to version 8](https://discuss.elastic.co/t/upgrading-system-indices-to-version-8/347364)

<div class="topic-metadata">

**Author:** [@bermanb](https://discuss.elastic.co/u/bermanb)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:07pm UTC](https://discuss.elastic.co/t/upgrading-system-indices-to-version-8/347364 "2023-11-22T22:07:23Z")

</div>

We recently updated Elasticsearch and Kibana from 7.17 to 8.10.2, and noticed that we can't find how to upgrade the system indices from 7 to 8 (like in the 7 to 8 upgrade assistant where we were able to upgrade our indic…

---

## [Winlogbeat error on alias](https://discuss.elastic.co/t/winlogbeat-error-on-alias/347785)

<div class="topic-metadata">

**Author:** [@Michael\_Ryan\_Dinio](https://discuss.elastic.co/u/Michael_Ryan_Dinio)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:00pm UTC](https://discuss.elastic.co/t/winlogbeat-error-on-alias/347785 "2023-11-22T22:00:30Z")

</div>

Hi I got an error on my client with Winlogbeat running below is the error log 2023-11-22T03:58:49.082+0800 ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(elasticsearch(https://54.…

---

## [Color stops acting strange](https://discuss.elastic.co/t/color-stops-acting-strange/347701)

<div class="topic-metadata">

**Author:** [@Negan](https://discuss.elastic.co/u/Negan)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:57pm UTC](https://discuss.elastic.co/t/color-stops-acting-strange/347701 "2023-11-22T21:57:13Z")

</div>

Hi. The colour stops I am trying to use are not showing as they should be. See images: as you can see in this image for some reason it starts to be green at -60,21 while it needs to be green under 0. I tried changing…

---

## [Kibana 8.9.1 yarn build issue](https://discuss.elastic.co/t/kibana-8-9-1-yarn-build-issue/346993)

<div class="topic-metadata">

**Author:** [@epyonss](https://discuss.elastic.co/u/epyonss)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:44pm UTC](https://discuss.elastic.co/t/kibana-8-9-1-yarn-build-issue/346993 "2023-11-22T21:44:16Z")

</div>

hi guys "I tried to use the 'yarn build --skip-os-packages' command to build 'kibana source', but I'm encountering the following results. Any suggestions? Thanks

---

## [What is the proper request body format for saved\_objects/\_bulk\_delete API?](https://discuss.elastic.co/t/what-is-the-proper-request-body-format-for-saved-objects-bulk-delete-api/346813)

<div class="topic-metadata">

**Author:** [@Evgeni\_Dzhelyov](https://discuss.elastic.co/u/Evgeni_Dzhelyov)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:41pm UTC](https://discuss.elastic.co/t/what-is-the-proper-request-body-format-for-saved-objects-bulk-delete-api/346813 "2023-11-22T21:41:36Z")

</div>

I'm unable to use the bulk\_delete API on 8.8.2 neither using Kibana Console or curl. Can you give me a working example? curl -X POST "http://localhost:5601/api/saved\_objects/\_bulk\_delete" -H 'kbn-xsrf: true' -H 'Content…

---

## [Filtering the redundant dataView column value](https://discuss.elastic.co/t/filtering-the-redundant-dataview-column-value/347087)

<div class="topic-metadata">

**Author:** [@talk2raja](https://discuss.elastic.co/u/talk2raja)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:38pm UTC](https://discuss.elastic.co/t/filtering-the-redundant-dataview-column-value/347087 "2023-11-22T21:38:18Z")

</div>

I am using an Elasticsearch query, trying to send an alert based on FPS\_MIN, My query & conditions, My problem is, that I got 39 hits, I am looping the hits result in alert action message section, server.name value…

---

## [Filter stays when moving to another dashboard](https://discuss.elastic.co/t/filter-stays-when-moving-to-another-dashboard/347751)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 3\
**Last updated:** [November 22, 2023, 8:22pm UTC](https://discuss.elastic.co/t/filter-stays-when-moving-to-another-dashboard/347751 "2023-11-22T20:22:03Z")

</div>

Hi, after updating from 7.17.5 to 8.9.2 Im having some issues with vega-lite links. this is what worked before: "transform": \[ { "calculate": "'../app/dashboards#/view/6a0b5de8-55a0-5c59-8427-6bf1f9a8…

---

## [Kibana Log Error on Start](https://discuss.elastic.co/t/kibana-log-error-on-start/347783)

<div class="topic-metadata">

**Author:** [@sgrubb](https://discuss.elastic.co/u/sgrubb)\
**Replies:** 4\
**Last updated:** [November 22, 2023, 8:07pm UTC](https://discuss.elastic.co/t/kibana-log-error-on-start/347783 "2023-11-22T20:07:30Z")

</div>

Hello! I recently upgraded my elasticsearch and kibana from 8.3 to 8.11. elasticsearch is running fine but I can not get kibana to start after the upgrade. I installed Kibana via manual Deb and am using the same .yml fil…

---

## [Changing Index Mapping & Making Long Texts Keyword For Elasticsearch](https://discuss.elastic.co/t/changing-index-mapping-making-long-texts-keyword-for-elasticsearch/347709)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 3\
**Last updated:** [November 22, 2023, 6:35pm UTC](https://discuss.elastic.co/t/changing-index-mapping-making-long-texts-keyword-for-elasticsearch/347709 "2023-11-22T18:35:03Z")

</div>

Moving forward, should I find a need to change my index mapping after the data is ingested, I have this description column which I realised was ingested as Text and not a keyword. PUT /ats-mainline-logs-2023-01,ats-mai…

---

## [Imported dashboard and their "sub" dashboards does not work in Kibana](https://discuss.elastic.co/t/imported-dashboard-and-their-sub-dashboards-does-not-work-in-kibana/346096)

<div class="topic-metadata">

**Author:** [@petlit2049](https://discuss.elastic.co/u/petlit2049)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 6:22pm UTC](https://discuss.elastic.co/t/imported-dashboard-and-their-sub-dashboards-does-not-work-in-kibana/346096 "2023-11-22T18:22:54Z")

</div>

I use ansible in order to list the available (imported) beat-dashboards. I select a number of dashboards to import to a number of spaces and it works fine. However, I get a 404 error when I click a "sub/included" dashboa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=366)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=368)
