# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=381

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 382

---

## [Best practice for adding/complement additional data to existing documents](https://discuss.elastic.co/t/best-practice-for-adding-complement-additional-data-to-existing-documents/346498)

<div class="topic-metadata">

**Author:** [@daniel-san](https://discuss.elastic.co/u/daniel-san)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:32am UTC](https://discuss.elastic.co/t/best-practice-for-adding-complement-additional-data-to-existing-documents/346498 "2023-11-06T08:32:12Z")

</div>

Hello there, we're only scratched the surface regarding the possibilities in Elasticsearch so the following question/example might be pretty basic: In our example we have multiple Hosts (VDI Workplaces) that are tied/o…

---

## [\[BUG\] Threatintel MISP Plugin runs in endless loop](https://discuss.elastic.co/t/bug-threatintel-misp-plugin-runs-in-endless-loop/344798)

<div class="topic-metadata">

**Author:** [@hti](https://discuss.elastic.co/u/hti)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 7:44am UTC](https://discuss.elastic.co/t/bug-threatintel-misp-plugin-runs-in-endless-loop/344798 "2023-11-06T07:44:57Z")

</div>

Hello, we are running filebeat 8.8.1 and use the threatintel module to ingest data from MISP to elasticsearch. While it is running well most of the time, some MISP events (probably those with many attributes) will resu…

---

## [Queries regarding logsatsh configuration file](https://discuss.elastic.co/t/queries-regarding-logsatsh-configuration-file/346491)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 6:16am UTC](https://discuss.elastic.co/t/queries-regarding-logsatsh-configuration-file/346491 "2023-11-06T06:16:45Z")

</div>

input { beats { port =\> "9006" } } filter { mutate { add\_field =\> { "beat\_version" =\> "%{\[beat\]\[version\]}" } } mutate { add\_field =\> { "log\_file" =\> "%{\[log\]\[file\]\[path\]}" } } mutate { add\_field =\> { "beat\_…

---

## [How to list top 5 IPs with their total usage in Mega Byte](https://discuss.elastic.co/t/how-to-list-top-5-ips-with-their-total-usage-in-mega-byte/346490)

<div class="topic-metadata">

**Author:** [@Indunil75](https://discuss.elastic.co/u/Indunil75)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 5:54am UTC](https://discuss.elastic.co/t/how-to-list-top-5-ips-with-their-total-usage-in-mega-byte/346490 "2023-11-06T05:54:32Z")

</div>

Hi Users, I have setup fortigate firewall with logstash, Elasticsearch and Kibana. It woks fine. In kibana, Dashboard, How to list top 5 IPs with their total usage in Mega Byte. How can I achieve it? Hope to hear from…

---

## [ELK v 7.6.0 Paloalto take certain types of logs](https://discuss.elastic.co/t/elk-v-7-6-0-paloalto-take-certain-types-of-logs/346479)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 5:12am UTC](https://discuss.elastic.co/t/elk-v-7-6-0-paloalto-take-certain-types-of-logs/346479 "2023-11-06T05:12:42Z")

</div>

Hello I am working with ELK v 7.6.0 I have asked the paloalto firewall administrator to send me the logs via Syslog on port 514 to my server where I have ELK. In the linux operating system in the path /etc/ the file r…

---

## [How can I get Gigabyte instead of number of records?](https://discuss.elastic.co/t/how-can-i-get-gigabyte-instead-of-number-of-records/346272)

<div class="topic-metadata">

**Author:** [@Indunil75](https://discuss.elastic.co/u/Indunil75)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 4:34am UTC](https://discuss.elastic.co/t/how-can-i-get-gigabyte-instead-of-number-of-records/346272 "2023-11-06T04:34:02Z")

</div>

I have configured elasticsearch, kibana and logstash. fortigate firewall sends logs. While creating dashboard, It gives count of records. How can I get Gigabyte instead of count of records?

---

## [Integrate APM Logs Format to ELK](https://discuss.elastic.co/t/integrate-apm-logs-format-to-elk/346345)

<div class="topic-metadata">

**Author:** [@quoctuan2311](https://discuss.elastic.co/u/quoctuan2311)\
**Replies:** 8\
**Last updated:** [November 6, 2023, 3:37am UTC](https://discuss.elastic.co/t/integrate-apm-logs-format-to-elk/346345 "2023-11-06T03:37:50Z")

</div>

I have use ELK Stack to my system. My system have integrate my system logs format { "@timestamp": "2023-11-03T08:47:32.547Z", "log.level": "INFO", "message": "Schedule messages: size=1, markerTime=2023-11-03T15:4…

---

## [What is the best way to get AD authentication logs in ELK](https://discuss.elastic.co/t/what-is-the-best-way-to-get-ad-authentication-logs-in-elk/346482)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 3:01am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-get-ad-authentication-logs-in-elk/346482 "2023-11-06T03:01:25Z")

</div>

What is the best way to ingest AD authentication logs in ELK, through elastic agent or through audit beats .. we don’t want to impact AD server performance

---

## [Kibana-to-elastic: reason: unable to verify the first certificate](https://discuss.elastic.co/t/kibana-to-elastic-reason-unable-to-verify-the-first-certificate/346480)

<div class="topic-metadata">

**Author:** [@agvsap1](https://discuss.elastic.co/u/agvsap1)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 12:27am UTC](https://discuss.elastic.co/t/kibana-to-elastic-reason-unable-to-verify-the-first-certificate/346480 "2023-11-06T00:27:41Z")

</div>

Hi I have installed elasticsearch:8.5.1 and kibana:8.5.1 in gk1 with kubernetes 1.26. The kibana console when try to access elastic reports this error: We can’t establish a connection to Enterprise Search a…

---

## [Node Replacement Procedure](https://discuss.elastic.co/t/node-replacement-procedure/346478)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [November 5, 2023, 11:05pm UTC](https://discuss.elastic.co/t/node-replacement-procedure/346478 "2023-11-05T23:05:01Z")

</div>

Hi All, I have a multi-tier elastic cluster setup. My Hot tier is made up of 4 nodes. I need to replace one of these nodes with a completely new instance (machine). Can anyone recommend the best procedure to follow t…

---

## [Difference in sending static vs "live feeding" logs to logstash via filebeat](https://discuss.elastic.co/t/difference-in-sending-static-vs-live-feeding-logs-to-logstash-via-filebeat/346349)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 2\
**Last updated:** [November 5, 2023, 7:50pm UTC](https://discuss.elastic.co/t/difference-in-sending-static-vs-live-feeding-logs-to-logstash-via-filebeat/346349 "2023-11-05T19:50:06Z")

</div>

We have two different ELK servers which are used to analyse logs from our own application, one is in-house and the other is on the customers site. We have different pipelines for the application itself and then also for …

---

## [Elasticsearch fails to start after reboot](https://discuss.elastic.co/t/elasticsearch-fails-to-start-after-reboot/346462)

<div class="topic-metadata">

**Author:** [@gisly](https://discuss.elastic.co/u/gisly)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 3:15pm UTC](https://discuss.elastic.co/t/elasticsearch-fails-to-start-after-reboot/346462 "2023-11-05T15:15:50Z")

</div>

I am running the following version of Elasticsearch "version" : { "number" : "7.12.0", "build\_flavor" : "default", "build\_type" : "rpm", "build\_hash" : "78722783c38caa25a70982b5b042074cde5d3b3a", "b…

---

## [Why there are not any index on elasticsearch after run filebeat](https://discuss.elastic.co/t/why-there-are-not-any-index-on-elasticsearch-after-run-filebeat/346422)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 9\
**Last updated:** [November 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/why-there-are-not-any-index-on-elasticsearch-after-run-filebeat/346422 "2023-11-05T14:43:56Z")

</div>

My elasticsearch version = 8.10.4 My filebeat version : 8.7 Also these are outputs : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns loo…

---

## [How can create separate filestream with custom name when using filebeat](https://discuss.elastic.co/t/how-can-create-separate-filestream-with-custom-name-when-using-filebeat/346461)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 0\
**Last updated:** [November 5, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-can-create-separate-filestream-with-custom-name-when-using-filebeat/346461 "2023-11-05T13:55:55Z")

</div>

I want to create separate filestream for APP-Logs with specific name "APP-LOGS" when I am run filebeat. How can do it ? What is configuration in filebeat.yml ?

---

## [Edit static lookup with API](https://discuss.elastic.co/t/edit-static-lookup-with-api/346111)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 10:24am UTC](https://discuss.elastic.co/t/edit-static-lookup-with-api/346111 "2023-11-05T10:24:11Z")

</div>

I have the following problem. I have an X field in every document, but not in every document I have a Y field. I would like the information from field Y to appear in place of field X. Specifically, it is about the occurr…

---

## [Import Pretrained Model to Elasticsearch Cluster](https://discuss.elastic.co/t/import-pretrained-model-to-elasticsearch-cluster/346440)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 3:09am UTC](https://discuss.elastic.co/t/import-pretrained-model-to-elasticsearch-cluster/346440 "2023-11-05T03:09:09Z")

</div>

Hello everyone. I have a question about import sentence-transformer model to elasticsearch cluster. When I run the python script below, I see only 1 node has allocated my mode, but I want to allocate my model in 2 nodes …

---

## [This error seems to be related to mapping issues in Elasticsearch, below error found in logstash](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414)

<div class="topic-metadata">

**Author:** [@Sreecharanhope](https://discuss.elastic.co/u/Sreecharanhope)\
**Replies:** 4\
**Last updated:** [November 5, 2023, 2:38am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414 "2023-11-05T02:38:14Z")

</div>

2023-11-04T10:33:48,353\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil}, …

---

## [How to create a document where the \_id has spaces (Dev Tools)](https://discuss.elastic.co/t/how-to-create-a-document-where-the-id-has-spaces-dev-tools/346404)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 9\
**Last updated:** [November 4, 2023, 10:08pm UTC](https://discuss.elastic.co/t/how-to-create-a-document-where-the-id-has-spaces-dev-tools/346404 "2023-11-04T22:08:45Z")

</div>

I am attempting to create a document in an index where \_id has spaces. I get a parsing exception in Dev Tools. Here is the start of POST statement: POST /label-expression/\_doc/(AB\_123 | CD\_123) I must have the spaces, …

---

## [Query for the fields which is non empty](https://discuss.elastic.co/t/query-for-the-fields-which-is-non-empty/345764)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 5\
**Last updated:** [November 4, 2023, 6:27pm UTC](https://discuss.elastic.co/t/query-for-the-fields-which-is-non-empty/345764 "2023-11-04T18:27:32Z")

</div>

Hi Team, I'm reaching out query that I have, I want a query which returns the field with any random value inside it and filter out the empty records. For eg: In my case, I have a FileContent.content field and it has va…

---

## [This error seems to be related to mapping issues in Elasticsearch, ](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch/346427)

<div class="topic-metadata">

**Author:** [@jamesjames](https://discuss.elastic.co/u/jamesjames)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 4:06pm UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch/346427 "2023-11-04T16:06:29Z")

</div>

2023-11-04T10:33:48,353\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil}, …

---

## [What happened to the .Net client?](https://discuss.elastic.co/t/what-happened-to-the-net-client/346068)

<div class="topic-metadata">

**Author:** [@Eric\_Paul](https://discuss.elastic.co/u/Eric_Paul)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 2:21pm UTC](https://discuss.elastic.co/t/what-happened-to-the-net-client/346068 "2023-11-04T14:21:45Z")

</div>

OK it's been a bit since I coded against elasticsearch. Now it looks like there is a new client to replace nest. But the documentation is severely lacking. I don't see any examples of code except for the most basic stuff…

---

## [Kibana Plugin](https://discuss.elastic.co/t/kibana-plugin/346245)

<div class="topic-metadata">

**Author:** [@Srini-99](https://discuss.elastic.co/u/Srini-99)\
**Replies:** 1\
**Last updated:** [November 4, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-plugin/346245 "2023-11-04T12:49:09Z")

</div>

Hi! I wanted to create a custom plugin to add on to kibana. since i had Elasticsearch and kibana already set up and running, i started my plugin development in the 'plugin' of kibana. (system - win11) when i start kib…

---

## [Extract JSON log from JSON](https://discuss.elastic.co/t/extract-json-log-from-json/346353)

<div class="topic-metadata">

**Author:** [@AlarleCKe](https://discuss.elastic.co/u/AlarleCKe)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 11:33am UTC](https://discuss.elastic.co/t/extract-json-log-from-json/346353 "2023-11-04T11:33:26Z")

</div>

Hi everyone, I´m trying to create an index based on a script output. The script itself creates an NDJSON like: {"packages/current\_version":"3.7.3-2+deb10u5","packages/candidate\_version":"3.7.3-2+deb10u6","packages/prio…

---

## [Elasticsearch vector](https://discuss.elastic.co/t/elasticsearch-vector/346425)

<div class="topic-metadata">

**Author:** [@zhl19911203](https://discuss.elastic.co/u/zhl19911203)\
**Replies:** 0\
**Last updated:** [November 4, 2023, 11:00am UTC](https://discuss.elastic.co/t/elasticsearch-vector/346425 "2023-11-04T11:00:48Z")

</div>

Is there an official example of how to add, delete, modify, and check vector data in Elasticsearch8.10.2 version? Using Elasticsearch Java client operations

---

## [Why filebeat cannot start and stop after a few second](https://discuss.elastic.co/t/why-filebeat-cannot-start-and-stop-after-a-few-second/346406)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 5:22am UTC](https://discuss.elastic.co/t/why-filebeat-cannot-start-and-stop-after-a-few-second/346406 "2023-11-04T05:22:03Z")

</div>

My elasticsearch version = 8.10.4 filebeat version : 8.7 I cannot install latest version of filebeat on my redhat 6.4 . Now when start filebeat . it is stopping after a few second . and this is my filebeat log : ta…

---

## [Logstash http\_pollar Rest API push more than 1000 records](https://discuss.elastic.co/t/logstash-http-pollar-rest-api-push-more-than-1000-records/346374)

<div class="topic-metadata">

**Author:** [@puneetsharma2](https://discuss.elastic.co/u/puneetsharma2)\
**Replies:** 12\
**Last updated:** [November 3, 2023, 6:35pm UTC](https://discuss.elastic.co/t/logstash-http-pollar-rest-api-push-more-than-1000-records/346374 "2023-11-03T18:35:20Z")

</div>

Logstash http\_pollar Rest API push more than 1000 records As we are using HTTP\_POLLAR to execute the rest API and push the response in elastic index in one go. But default only 1000 records are pushing in elastic. How …

---

## [Show only time with out date](https://discuss.elastic.co/t/show-only-time-with-out-date/345059)

<div class="topic-metadata">

**Author:** [@naveed786.shaik](https://discuss.elastic.co/u/naveed786.shaik)\
**Replies:** 7\
**Last updated:** [November 3, 2023, 11:10pm UTC](https://discuss.elastic.co/t/show-only-time-with-out-date/345059 "2023-11-03T23:10:49Z")

</div>

Hi All, Need a help with Kibana dashboard , I could see the customization for date and time, in version 8.6.0 of the dashboard. I am trying to get indexed data with only time where need to exclude date. Please suggest …

---

## [Unable to load pipelines arraycopy: length -1 is negative](https://discuss.elastic.co/t/unable-to-load-pipelines-arraycopy-length-1-is-negative/346407)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 8:55pm UTC](https://discuss.elastic.co/t/unable-to-load-pipelines-arraycopy-length-1-is-negative/346407 "2023-11-03T20:55:42Z")

</div>

Hi there, I noticed one of my ingest pipelines didn't appear to be working, and when I went to look at the ingest pipelines, this error message popped up. I haven't been able to find this error anywhere else on any foru…

---

## [Certificate signed by unknown authority](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority/346348)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 6\
**Last updated:** [November 3, 2023, 8:12pm UTC](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority/346348 "2023-11-03T20:12:00Z")

</div>

This is my filebeat.yml file but when I want to check it shows error : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: …

---

## [High cpu for new data nodes for several days?](https://discuss.elastic.co/t/high-cpu-for-new-data-nodes-for-several-days/346400)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 7:22pm UTC](https://discuss.elastic.co/t/high-cpu-for-new-data-nodes-for-several-days/346400 "2023-11-03T19:22:55Z")

</div>

Has anybody experienced this? Or is this normal? After adding 6 new data nodes, the high CPU (bouncing off 100%) often persisted for several days (around 5 days). The shards are balanced within a day of new node addit…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=380)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=382)
