# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=376

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 377

---

## [Script Processor Conditional](https://discuss.elastic.co/t/script-processor-conditional/347004)

<div class="topic-metadata">

**Author:** [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 11:19am UTC](https://discuss.elastic.co/t/script-processor-conditional/347004 "2023-11-13T11:19:41Z")

</div>

Hi, I have a field - src-station-id in the logs that brings in IP and Hostnames as string. Now in order to create a new field when src-station-id only contains IP, I am trying to get a script processor identify that as…

---

## [Logstash error: \[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (SystemExit) exit org.jruby.exceptions.SystemExit: (SystemExit) exit](https://discuss.elastic.co/t/logstash-error-fatal-org-logstash-logstash-logstash-stopped-processing-because-of-an-error-systemexit-exit-org-jruby-exceptions-systemexit-systemexit-exit/347001)

<div class="topic-metadata">

**Author:** [@Jann](https://discuss.elastic.co/u/Jann)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 11:12am UTC](https://discuss.elastic.co/t/logstash-error-fatal-org-logstash-logstash-logstash-stopped-processing-because-of-an-error-systemexit-exit-org-jruby-exceptions-systemexit-systemexit-exit/347001 "2023-11-13T11:12:28Z")

</div>

Hello, I'm trying to send txt files from my server to my other server (where ELK is running). Otherwise when I try to send files, I receive this error: \[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing bec…

---

## [Kibana elasticseach inaccessible](https://discuss.elastic.co/t/kibana-elasticseach-inaccessible/346450)

<div class="topic-metadata">

**Author:** [@Epangilinangt](https://discuss.elastic.co/u/Epangilinangt)\
**Replies:** 6\
**Last updated:** [November 13, 2023, 10:28am UTC](https://discuss.elastic.co/t/kibana-elasticseach-inaccessible/346450 "2023-11-13T10:28:28Z")

</div>

{ "statusCode": 503, "error": "Service Unavailable", "message": "License is not available." } does anyone help me with this kind of error, tried a lot of troubleshooting still did not work

---

## [Updating field mapping in Index Template](https://discuss.elastic.co/t/updating-field-mapping-in-index-template/345528)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 3\
**Last updated:** [November 13, 2023, 10:10am UTC](https://discuss.elastic.co/t/updating-field-mapping-in-index-template/345528 "2023-11-13T10:10:30Z")

</div>

Hello all, We have an application that sends logs daily to our ELK server. We are an index template which creates an new indice for each day. We are using ELK (with filebeat) 7.10 I am looking to update the mapping to …

---

## [Does anyone use connection pooling in ElasticSearch8.5? How to use it?](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346975)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 10:00am UTC](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346975 "2023-11-13T10:00:19Z")

</div>

Does anyone use connection pooling in Elasticsearch8.5? How to use it?

---

## [Use k8s provider fields in filebeat config](https://discuss.elastic.co/t/use-k8s-provider-fields-in-filebeat-config/346864)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 9:27am UTC](https://discuss.elastic.co/t/use-k8s-provider-fields-in-filebeat-config/346864 "2023-11-13T09:27:07Z")

</div>

Hello everyone! We are deploying the Elastic Agent as a daemonset to slurp up our container logs using hints based autodiscovery. This works and we can selectively parse pods based on the following hint: podTempla…

---

## [Error: failed to publish events: write tcp XX.XX.XX.XX:50882-\>XX.XX.XX.XX:5044: write: broken pipe](https://discuss.elastic.co/t/error-failed-to-publish-events-write-tcp-xx-xx-xx-xx-50882-xx-xx-xx-xx-write-broken-pipe/346852)

<div class="topic-metadata">

**Author:** [@charown](https://discuss.elastic.co/u/charown)\
**Replies:** 12\
**Last updated:** [November 13, 2023, 9:15am UTC](https://discuss.elastic.co/t/error-failed-to-publish-events-write-tcp-xx-xx-xx-xx-50882-xx-xx-xx-xx-write-broken-pipe/346852 "2023-11-13T09:15:26Z")

</div>

I have docker-compose.yml version: "2.4" services: …

---

## [How to access index of array correct in plainess?](https://discuss.elastic.co/t/how-to-access-index-of-array-correct-in-plainess/345617)

<div class="topic-metadata">

**Author:** [@duyhunter1001](https://discuss.elastic.co/u/duyhunter1001)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 8:46am UTC](https://discuss.elastic.co/t/how-to-access-index-of-array-correct-in-plainess/345617 "2023-11-13T08:46:51Z")

</div>

Hi everyone, I'm facing a situation like this. I have index example: PUT my\_index { "mappings": { "properties": { "targetoperator": { type: "keyword" }, "targetvalue": { type: "keyword" } } } …

---

## [Problem with csv import into a fresh elasticsearch and kibana environment](https://discuss.elastic.co/t/problem-with-csv-import-into-a-fresh-elasticsearch-and-kibana-environment/346877)

<div class="topic-metadata">

**Author:** [@um3n](https://discuss.elastic.co/u/um3n)\
**Replies:** 4\
**Last updated:** [November 13, 2023, 8:44am UTC](https://discuss.elastic.co/t/problem-with-csv-import-into-a-fresh-elasticsearch-and-kibana-environment/346877 "2023-11-13T08:44:40Z")

</div>

Hi guys, I'm hoping to get some help with a problem I'm having. I just installed two Elasticsearch nodes in a cluster with a Kibana frontend (also freshly installed). I have configured everything according to the docum…

---

## [Using analyze API for encryption at rest](https://discuss.elastic.co/t/using-analyze-api-for-encryption-at-rest/346960)

<div class="topic-metadata">

**Author:** [@harispy](https://discuss.elastic.co/u/harispy)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 7:46am UTC](https://discuss.elastic.co/t/using-analyze-api-for-encryption-at-rest/346960 "2023-11-13T07:46:21Z")

</div>

Hi everyone. we want to encrypt one field of our documents in Elastic and I went through lots of methods for doing this and none of them was good with our situation (for example third-party proxy and plugins because the…

---

## [Having log error while trying to install pega 8.5 on kubernetes cluster](https://discuss.elastic.co/t/having-log-error-while-trying-to-install-pega-8-5-on-kubernetes-cluster/346943)

<div class="topic-metadata">

**Author:** [@musheer](https://discuss.elastic.co/u/musheer)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 5:12am UTC](https://discuss.elastic.co/t/having-log-error-while-trying-to-install-pega-8-5-on-kubernetes-cluster/346943 "2023-11-13T05:12:39Z")

</div>

Hi, when i installed pega 8.5 on kubernetes cluster ,the pod of pega search was in pending state and i checked the logs and got following error .Need to solve this issue as soon as possible.Please help ERROR: kubectl …

---

## [Warm nodes respond poorly](https://discuss.elastic.co/t/warm-nodes-respond-poorly/346552)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 4\
**Last updated:** [November 12, 2023, 6:12pm UTC](https://discuss.elastic.co/t/warm-nodes-respond-poorly/346552 "2023-11-12T18:12:54Z")

</div>

Hello, I have the following issue. Our largest datastream ("C") is responding poorly to the queries. The main parts of the stack: 10\*hot nodes (each: 16 cores, 60GB+ memory) 6\*warm nodes (each: 16 cores, 60GB+ memo…

---

## [Eql with time range](https://discuss.elastic.co/t/eql-with-time-range/346928)

<div class="topic-metadata">

**Author:** [@mary-20](https://discuss.elastic.co/u/mary-20)\
**Replies:** 0\
**Last updated:** [November 12, 2023, 1:30pm UTC](https://discuss.elastic.co/t/eql-with-time-range/346928 "2023-11-12T13:30:22Z")

</div>

Hi guys, I'm looking for EQL to match logs with a timestamp within the last 5 minutes. I have read a with maxspan statement, but it has some limitation: It must be used with sequence it starts at the first event’s ti…

---

## [Adding data for all documents in an index](https://discuss.elastic.co/t/adding-data-for-all-documents-in-an-index/346761)

<div class="topic-metadata">

**Author:** [@dor](https://discuss.elastic.co/u/dor)\
**Replies:** 2\
**Last updated:** [November 12, 2023, 7:10am UTC](https://discuss.elastic.co/t/adding-data-for-all-documents-in-an-index/346761 "2023-11-12T07:10:50Z")

</div>

Hi, My case is the following: I have data in elastic indexes. At some stage, I'm running some post-processing on this data using Python, and I have a new field that I want to be able to make queries on. For example, th…

---

## [How to remove master nodes from the elasticsearch cluster](https://discuss.elastic.co/t/how-to-remove-master-nodes-from-the-elasticsearch-cluster/346732)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 7\
**Last updated:** [November 11, 2023, 6:20pm UTC](https://discuss.elastic.co/t/how-to-remove-master-nodes-from-the-elasticsearch-cluster/346732 "2023-11-11T18:20:36Z")

</div>

How could I delete two master nodes that are in my cluster, I currently have 3 master nodes, the cluster version is 7.17. thank you

---

## [How to remove fields not required when sending logs via elastic agent](https://discuss.elastic.co/t/how-to-remove-fields-not-required-when-sending-logs-via-elastic-agent/346892)

<div class="topic-metadata">

**Author:** [@HHobeck](https://discuss.elastic.co/u/HHobeck)\
**Replies:** 2\
**Last updated:** [November 11, 2023, 12:48pm UTC](https://discuss.elastic.co/t/how-to-remove-fields-not-required-when-sending-logs-via-elastic-agent/346892 "2023-11-11T12:48:23Z")

</div>

Dear community. I have exactly the same issue like shi in Reference \[1\] but with the different that I'm using elastic agent with custom log integration. Under the surface I guess file beat will be used but I have no luc…

---

## [Kibana not responding following 8.11.0 upgrade](https://discuss.elastic.co/t/kibana-not-responding-following-8-11-0-upgrade/346889)

<div class="topic-metadata">

**Author:** [@jdswifty](https://discuss.elastic.co/u/jdswifty)\
**Replies:** 4\
**Last updated:** [November 11, 2023, 11:01am UTC](https://discuss.elastic.co/t/kibana-not-responding-following-8-11-0-upgrade/346889 "2023-11-11T11:01:08Z")

</div>

Just completed upgrading both ES & Kibana from 8.9.0 to 8.11.0 & the kibana web front end is not responding at all seeing no obvious errors in the logs \[2023-11-10T16:07:48.509+00:00\]\[INFO \]\[http.server.Preboot\] http s…

---

## [Best strategy to join two clusters](https://discuss.elastic.co/t/best-strategy-to-join-two-clusters/346883)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [November 11, 2023, 7:05am UTC](https://discuss.elastic.co/t/best-strategy-to-join-two-clusters/346883 "2023-11-11T07:05:36Z")

</div>

Hi, A customer hand me two clusters, these are in two servers, on each server there are 3 nodes on dockers, what will the best strategy to join these two clusters? Also I was thinking that would be better to get rid of …

---

## [I create a model in Elasticsearch after some time later my Elasticsearch model does not found](https://discuss.elastic.co/t/i-create-a-model-in-elasticsearch-after-some-time-later-my-elasticsearch-model-does-not-found/346903)

<div class="topic-metadata">

**Author:** [@rakibulinux](https://discuss.elastic.co/u/rakibulinux)\
**Replies:** 1\
**Last updated:** [November 11, 2023, 3:48am UTC](https://discuss.elastic.co/t/i-create-a-model-in-elasticsearch-after-some-time-later-my-elasticsearch-model-does-not-found/346903 "2023-11-11T03:48:20Z")

</div>

Hi, @stephenb, how are you today? I create a model in elasticsearch after some time later my elasticsearch model does not found. I see it's automatically get removed. And throwing me this error. {"error":{"root\_cause":\[…

---

## [Auditbeat 8.11 does not provide container id without privilege mode when cgroup v2 is enabled](https://discuss.elastic.co/t/auditbeat-8-11-does-not-provide-container-id-without-privilege-mode-when-cgroup-v2-is-enabled/346901)

<div class="topic-metadata">

**Author:** [@deva\_raj1](https://discuss.elastic.co/u/deva_raj1)\
**Replies:** 0\
**Last updated:** [November 11, 2023, 2:28am UTC](https://discuss.elastic.co/t/auditbeat-8-11-does-not-provide-container-id-without-privilege-mode-when-cgroup-v2-is-enabled/346901 "2023-11-11T02:28:04Z")

</div>

Auditbeat 8.11 throughs error when installed as k8 daemonset with cgroup v2 . DEBUG \[gosigar\_cid\_provider\] add\_process\_metadata/gosigar\_cid\_provider.go:63 failed to get cgroups for pid=1395: failed to read cgro…

---

## [Is it possible to create an alert in case an Elastic Agent goes offline?](https://discuss.elastic.co/t/is-it-possible-to-create-an-alert-in-case-an-elastic-agent-goes-offline/346878)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 2\
**Last updated:** [November 11, 2023, 12:55am UTC](https://discuss.elastic.co/t/is-it-possible-to-create-an-alert-in-case-an-elastic-agent-goes-offline/346878 "2023-11-11T00:55:03Z")

</div>

I have a few Elastic-Agents working on metric collection but we got a problem for when one of them goes down. I know so far that there's an alerting option for metrics/logs threshold but I'm not sure about how to set an …

---

## [GeoIP enrich IP addresses broken if fileting with include\_fields](https://discuss.elastic.co/t/geoip-enrich-ip-addresses-broken-if-fileting-with-include-fields/346824)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 10:50pm UTC](https://discuss.elastic.co/t/geoip-enrich-ip-addresses-broken-if-fileting-with-include-fields/346824 "2023-11-10T22:50:23Z")

</div>

I'm logging DNS packets without dns.response\_code: NOERROR. This part works fine. But when I try to smile down the logged data, by adding a filter to drop all but some selected fields, GeoIP breaks. GeoIP can't be used …

---

## [Best practices for maintaining custom Metricbeats](https://discuss.elastic.co/t/best-practices-for-maintaining-custom-metricbeats/346895)

<div class="topic-metadata">

**Author:** [@Keith\_Wegner](https://discuss.elastic.co/u/Keith_Wegner)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 8:23pm UTC](https://discuss.elastic.co/t/best-practices-for-maintaining-custom-metricbeats/346895 "2023-11-10T20:23:05Z")

</div>

My software team has extended Metricbeat a few times, creating new modules/metricsets. We're looking for advice regarding the best way to maintain the Git repository (i.e., keeping with Elastic Beat's main branch). Curre…

---

## [Logstash and Kafka Input](https://discuss.elastic.co/t/logstash-and-kafka-input/346638)

<div class="topic-metadata">

**Author:** [@rpd](https://discuss.elastic.co/u/rpd)\
**Replies:** 7\
**Last updated:** [November 10, 2023, 7:48pm UTC](https://discuss.elastic.co/t/logstash-and-kafka-input/346638 "2023-11-10T19:48:36Z")

</div>

Hello Folks, I have a query about an observed side-effect of my Logstash kafka-input configuration. It is not directly apparent to me what the problem is and hope people with deep expertise can help me out here. We hav…

---

## [Host Elastic Maps Service locally](https://discuss.elastic.co/t/host-elastic-maps-service-locally/346347)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 12\
**Last updated:** [November 10, 2023, 4:33pm UTC](https://discuss.elastic.co/t/host-elastic-maps-service-locally/346347 "2023-11-10T16:33:50Z")

</div>

I use an offline virtual machine (Red Hat), and I want to create some maps. So, I followed the documentation of hosting Elastic maps service locally, and I'm going to use the Docker image for the map server. However, wh…

---

## [Am I right in thinking Lucene regex doesn't support lookahead?](https://discuss.elastic.co/t/am-i-right-in-thinking-lucene-regex-doesnt-support-lookahead/346882)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 4:02pm UTC](https://discuss.elastic.co/t/am-i-right-in-thinking-lucene-regex-doesnt-support-lookahead/346882 "2023-11-10T16:02:41Z")

</div>

Creating a new visualisation I just came across a curious case of regex filtering. The following Regex Lucene filter is what I had to use to show only values containing both upper and lower caps: Works dns.question.na…

---

## [Do we have to install new agent for every new host for Fleet](https://discuss.elastic.co/t/do-we-have-to-install-new-agent-for-every-new-host-for-fleet/346846)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 3:34pm UTC](https://discuss.elastic.co/t/do-we-have-to-install-new-agent-for-every-new-host-for-fleet/346846 "2023-11-10T15:34:42Z")

</div>

I was currently exploring regarding elasticsearch fleet and I set up a basic fleet server and a enrolled an elastic-agent on one machine, for example, "machine-A" with a agent policy: "p1", Agent policy p1 is configured …

---

## [Ruby filter to pack string value into object](https://discuss.elastic.co/t/ruby-filter-to-pack-string-value-into-object/346854)

<div class="topic-metadata">

**Author:** [@rcz](https://discuss.elastic.co/u/rcz)\
**Replies:** 7\
**Last updated:** [November 10, 2023, 2:17pm UTC](https://discuss.elastic.co/t/ruby-filter-to-pack-string-value-into-object/346854 "2023-11-10T14:17:09Z")

</div>

I have a client that sends HTTP request events with a nested structure, like: context.response.body context.response.code context.response.headers.Content-Length context.response.headers.Content-Type etc.. But sometime…

---

## [Help to understand match fields](https://discuss.elastic.co/t/help-to-understand-match-fields/346851)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 2:08pm UTC](https://discuss.elastic.co/t/help-to-understand-match-fields/346851 "2023-11-10T14:08:24Z")

</div>

I have a Problem i have a es database with a huge amount of text and now i try to understand why one article is not found. Here we have our ES-Indexsettings: { "stories": { "aliases": {}, "mappings": { "stories…

---

## [Nested json with multi field parsing through logstash](https://discuss.elastic.co/t/nested-json-with-multi-field-parsing-through-logstash/345549)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 15\
**Last updated:** [November 10, 2023, 1:31pm UTC](https://discuss.elastic.co/t/nested-json-with-multi-field-parsing-through-logstash/345549 "2023-11-10T13:31:21Z")

</div>

Please help me with below log how do I parse it ? {"@timestamp":"2023-10-11T07:38:56.607Z","log.level":"error","message":"API REQUEST TIME","ecs":{"version":"1.6.0"},"requestedAPI":\["https://cloudservices.indiatimes.com…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=375)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=377)
