# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=382

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 383

---

## [Accessing Aggregation buckets to get the \`key\` value and \`\_doc\` values](https://discuss.elastic.co/t/accessing-aggregation-buckets-to-get-the-key-value-and-doc-values/346391)

<div class="topic-metadata">

**Author:** [@Santosh\_mandyajayara](https://discuss.elastic.co/u/Santosh_mandyajayara)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 5:12pm UTC](https://discuss.elastic.co/t/accessing-aggregation-buckets-to-get-the-key-value-and-doc-values/346391 "2023-11-03T17:12:50Z")

</div>

We were using the Rest High Level Client before and below was the usage to access the aggregation buckets from the SearchResponse ParsedStringTerms aggregation1 = searchResponse.getAggregations().get(AGGREGATION1.name…

---

## [Deleting indices older than 30 days with policy problem](https://discuss.elastic.co/t/deleting-indices-older-than-30-days-with-policy-problem/346388)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 4:51pm UTC](https://discuss.elastic.co/t/deleting-indices-older-than-30-days-with-policy-problem/346388 "2023-11-03T16:51:25Z")

</div>

I am using an application that creates daily indices, using legacy index template. Two types of indices are created: jaeger-spans-date and jaeger-services-date (where date is the date produced). Using the kibana UI, I c…

---

## [Elastic Agent Disk Queue](https://discuss.elastic.co/t/elastic-agent-disk-queue/346382)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 3:42pm UTC](https://discuss.elastic.co/t/elastic-agent-disk-queue/346382 "2023-11-03T15:42:03Z")

</div>

Does Elastic Agent support disk queue? How do you configure it?

---

## [API Key for Kibana Reporting](https://discuss.elastic.co/t/api-key-for-kibana-reporting/345662)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 8\
**Last updated:** [November 3, 2023, 2:27pm UTC](https://discuss.elastic.co/t/api-key-for-kibana-reporting/345662 "2023-11-03T14:27:54Z")

</div>

I need to generate an API key which will allow a user to generate a report in Kibana and then download it, once it's generated. What permissions do I need to set? I haven't been able to determine this from the docs. Thx…

---

## [Logstash + S3 Input plugin with High Availability](https://discuss.elastic.co/t/logstash-s3-input-plugin-with-high-availability/346370)

<div class="topic-metadata">

**Author:** [@Pedro\_Baldanta](https://discuss.elastic.co/u/Pedro_Baldanta)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 2:01pm UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-with-high-availability/346370 "2023-11-03T14:01:38Z")

</div>

Hi all: I need to implement high availability of Logstash reading log files from S3. Is there any way to implement HA via scaleout without duplicating the events? Each VM is going to store until which file has read, s…

---

## [Fleet with own artifact registry fails cause of external GPG validation](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904)

<div class="topic-metadata">

**Author:** [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Replies:** 5\
**Last updated:** [November 3, 2023, 1:51pm UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904 "2023-11-03T13:51:42Z")

</div>

I have in an environment as described here Air Gapped Env artifacts hosted my own artifact registry. This is also cleanly queried during upgrade see log. However, a GPG validation is attempted externally. But why? Wher…

---

## [How do we customize the login page in latest version 8.10.2](https://discuss.elastic.co/t/how-do-we-customize-the-login-page-in-latest-version-8-10-2/346359)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 12:57pm UTC](https://discuss.elastic.co/t/how-do-we-customize-the-login-page-in-latest-version-8-10-2/346359 "2023-11-03T12:57:08Z")

</div>

Hi Team, How do we customize the login page in latest version of ELK 8.10.2 Observed that when compared to previous versions (8.5.2) here we find many changes in folder structure also. Requesting team to provide solut…

---

## [Visualize logs from two Suricata filebeat modules in one dashboard](https://discuss.elastic.co/t/visualize-logs-from-two-suricata-filebeat-modules-in-one-dashboard/346306)

<div class="topic-metadata">

**Author:** [@edpuig97](https://discuss.elastic.co/u/edpuig97)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 12:35pm UTC](https://discuss.elastic.co/t/visualize-logs-from-two-suricata-filebeat-modules-in-one-dashboard/346306 "2023-11-03T12:35:21Z")

</div>

Hi, I'm using Filebeat's suricata module from two suricata hosts, when I setup those, only the last of them is showed in the Kibana dashboards. Is any way to show both of them? Thanks in advance.

---

## [Additional Elastic Agent Integrations needed](https://discuss.elastic.co/t/additional-elastic-agent-integrations-needed/346308)

<div class="topic-metadata">

**Author:** [@dwortmann](https://discuss.elastic.co/u/dwortmann)\
**Replies:** 2\
**Last updated:** [November 3, 2023, 12:09pm UTC](https://discuss.elastic.co/t/additional-elastic-agent-integrations-needed/346308 "2023-11-03T12:09:51Z")

</div>

We are current users of Elastic stack and are using FileBeat modules to assist with parsing of data. We have begun to review the Elastic Agent and have found there are several additional integrations that are available …

---

## [How to search these kind of texts without Synonyms](https://discuss.elastic.co/t/how-to-search-these-kind-of-texts-without-synonyms/346362)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 11:55am UTC](https://discuss.elastic.co/t/how-to-search-these-kind-of-texts-without-synonyms/346362 "2023-11-03T11:55:42Z")

</div>

Hi, When I search with this query, { "match":{ "company":{ "query":"walmart" } } …

---

## [User for filebeat](https://discuss.elastic.co/t/user-for-filebeat/346361)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 11:38am UTC](https://discuss.elastic.co/t/user-for-filebeat/346361 "2023-11-03T11:38:41Z")

</div>

How can I create a user for filebeat via the console? The user would of course have to be able to send logs over. I get the following message in the logs: "this action is granted by the cluster privileges \[monitor, manag…

---

## [ECK | Filebeat | Kubernetes Logs are missing / no field data](https://discuss.elastic.co/t/eck-filebeat-kubernetes-logs-are-missing-no-field-data/346360)

<div class="topic-metadata">

**Author:** [@TimK](https://discuss.elastic.co/u/TimK)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 11:34am UTC](https://discuss.elastic.co/t/eck-filebeat-kubernetes-logs-are-missing-no-field-data/346360 "2023-11-03T11:34:46Z")

</div>

Hi there! We recently deployed the Elastic Cloud on Kubernetes for a Kubernetes Cluster in Azure. Our goal is to collect the log information from the pods. I applied the following Filebeat YAML from the Doc (with the …

---

## [\[Filebeat\] Filebeat with K8S autodicover using hints keeps refreshing all pod config every 10s](https://discuss.elastic.co/t/filebeat-filebeat-with-k8s-autodicover-using-hints-keeps-refreshing-all-pod-config-every-10s/346339)

<div class="topic-metadata">

**Author:** [@Lebvanih](https://discuss.elastic.co/u/Lebvanih)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 10:56am UTC](https://discuss.elastic.co/t/filebeat-filebeat-with-k8s-autodicover-using-hints-keeps-refreshing-all-pod-config-every-10s/346339 "2023-11-03T10:56:40Z")

</div>

Hello, We noticed this issue quite long ago (High CPU Usage on some filebeat instances), but we finally had time to dig a bit more on a more recent version of filebeat too (8.10.1). From what we recently noticed, out l…

---

## [Take snapshot of only the global state and feature state in elasticsearch](https://discuss.elastic.co/t/take-snapshot-of-only-the-global-state-and-feature-state-in-elasticsearch/346352)

<div class="topic-metadata">

**Author:** [@nishant27](https://discuss.elastic.co/u/nishant27)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 10:45am UTC](https://discuss.elastic.co/t/take-snapshot-of-only-the-global-state-and-feature-state-in-elasticsearch/346352 "2023-11-03T10:45:46Z")

</div>

I have created a policy in elasticsearch kibana for taking backup of only the "global state" and "feature state" of the cluster. But when i run the policy, it fails with "index\_not\_found\_exception". Is there any way to…

---

## [Elastic nodes started to give hardware error on esxi 8.01c servers](https://discuss.elastic.co/t/elastic-nodes-started-to-give-hardware-error-on-esxi-8-01c-servers/346208)

<div class="topic-metadata">

**Author:** [@cemkayar](https://discuss.elastic.co/u/cemkayar)\
**Replies:** 8\
**Last updated:** [November 3, 2023, 9:56am UTC](https://discuss.elastic.co/t/elastic-nodes-started-to-give-hardware-error-on-esxi-8-01c-servers/346208 "2023-11-03T09:56:09Z")

</div>

Hi, After upgrading ESXi servers from 7.0.3l to 8.0.1c some of the elastic clusters started to give hardware errors during index hash. If move the problematic elastics VMs to the old version of the esxi servers (7.0.3l …

---

## [After stopping elasticserver 8.x it is shown status deactivating](https://discuss.elastic.co/t/after-stopping-elasticserver-8-x-it-is-shown-status-deactivating/346329)

<div class="topic-metadata">

**Author:** [@subrahmanyam](https://discuss.elastic.co/u/subrahmanyam)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 8:58am UTC](https://discuss.elastic.co/t/after-stopping-elasticserver-8-x-it-is-shown-status-deactivating/346329 "2023-11-03T08:58:01Z")

</div>

Loaded: loaded (/etc/systemd/system/Elasticsearch8.service; enabled; vendor preset: disabled) Active: deactivating (stop-sigterm) since Thu 2023-11-02 13:28:39 GMT; 16h ago Process: 2780103 ExecStop=/test/config/elasti…

---

## [Online monitoring log sending devices in logstash machine](https://discuss.elastic.co/t/online-monitoring-log-sending-devices-in-logstash-machine/346337)

<div class="topic-metadata">

**Author:** [@Mohsen\_R.Marandi](https://discuss.elastic.co/u/Mohsen_R.Marandi)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 8:24am UTC](https://discuss.elastic.co/t/online-monitoring-log-sending-devices-in-logstash-machine/346337 "2023-11-03T08:24:36Z")

</div>

Hi every one I have set up logstash on a large scale network. Is there a way to online monitor log sending devices? Tanks

---

## [Issues with collecting Dependabot alerts using GitHub integration](https://discuss.elastic.co/t/issues-with-collecting-dependabot-alerts-using-github-integration/346277)

<div class="topic-metadata">

**Author:** [@bil15](https://discuss.elastic.co/u/bil15)\
**Replies:** 7\
**Last updated:** [November 3, 2023, 8:16am UTC](https://discuss.elastic.co/t/issues-with-collecting-dependabot-alerts-using-github-integration/346277 "2023-11-03T08:16:24Z")

</div>

Hello! I'm trying to ingest Dependabot alerts from a GitHub organization to Elastic but I'm encountering some issues. The most interesting part is that I use the same PAT and input parameters (organization, tag set, et…

---

## [Filebeat not reached to Kafka but Metricbeat reached](https://discuss.elastic.co/t/filebeat-not-reached-to-kafka-but-metricbeat-reached/346335)

<div class="topic-metadata">

**Author:** [@jongpchubb](https://discuss.elastic.co/u/jongpchubb)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 8:02am UTC](https://discuss.elastic.co/t/filebeat-not-reached-to-kafka-but-metricbeat-reached/346335 "2023-11-03T08:02:46Z")

</div>

I'm using Filebeat and Metricbeat version 8.9 on Redhat. Metricbeat has no any problem that can send a log to Kafka and shown on OpenSearch to be a dashboard. But Filebeat has no any error in the log that can connect and…

---

## [Logstash Stuck Indexing Pipeline and throwing Error - warning: already initialized constant Manticore::Client::HttpPost](https://discuss.elastic.co/t/logstash-stuck-indexing-pipeline-and-throwing-error-warning-already-initialized-constant-manticore-httppost/345948)

<div class="topic-metadata">

**Author:** [@mnasim1](https://discuss.elastic.co/u/mnasim1)\
**Replies:** 5\
**Last updated:** [November 3, 2023, 5:52am UTC](https://discuss.elastic.co/t/logstash-stuck-indexing-pipeline-and-throwing-error-warning-already-initialized-constant-manticore-httppost/345948 "2023-11-03T05:52:57Z")

</div>

Logstash was running fine and successfully reading data from the Postgres Database for indexing. However, it suddenly started throwing the following errors, causing the indexing pipeline to become stuck: logstash-8.6.2…

---

## [Logstash 8.10.4 breaking changes](https://discuss.elastic.co/t/logstash-8-10-4-breaking-changes/346312)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [November 3, 2023, 4:55am UTC](https://discuss.elastic.co/t/logstash-8-10-4-breaking-changes/346312 "2023-11-03T04:55:19Z")

</div>

"status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[host\] of type \[text\] in document with id 'xxxxxxx'. added this to resolve the above mutate { rename =\> { "\[host\]" =\> …

---

## [Nested JSON in CSV](https://discuss.elastic.co/t/nested-json-in-csv/346310)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 4:54am UTC](https://discuss.elastic.co/t/nested-json-in-csv/346310 "2023-11-03T04:54:39Z")

</div>

I have a CSV file with 1500 rows of data. I am wanting to optimize how I have certain data and nest it in Elastic. Here's an example: Name, Location, Age, Favorite Colors Bob, USA, 32, Orange, Pink Jane, USA, 28, Gr…

---

## [Coordinating Nodes High Circuit Breaker Tripped Counts](https://discuss.elastic.co/t/coordinating-nodes-high-circuit-breaker-tripped-counts/344161)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 11\
**Last updated:** [November 3, 2023, 2:37am UTC](https://discuss.elastic.co/t/coordinating-nodes-high-circuit-breaker-tripped-counts/344161 "2023-11-03T02:37:24Z")

</div>

Hi All, I'm curious if anyone has any ideas on an issue I'm seeing. I have a cluster of 33 nodes, 3 of these nodes are coordinating only nodes that handle all requests. I've been noticing that these coordinating nodes…

---

## [Manually Add node to cluster Elasticsearch 8.6](https://discuss.elastic.co/t/manually-add-node-to-cluster-elasticsearch-8-6/346322)

<div class="topic-metadata">

**Author:** [@syifelastic](https://discuss.elastic.co/u/syifelastic)\
**Replies:** 4\
**Last updated:** [November 3, 2023, 1:52am UTC](https://discuss.elastic.co/t/manually-add-node-to-cluster-elasticsearch-8-6/346322 "2023-11-03T01:52:51Z")

</div>

Hello. I have a 3 node Elasticsearch cluster. I originally set up the 3 nodes with an enrollment token. However, I later changed from http keystore to a certificate/key configuration in the yml. This breaks the enrollme…

---

## [Http.p12 structure and use of keytool](https://discuss.elastic.co/t/http-p12-structure-and-use-of-keytool/346325)

<div class="topic-metadata">

**Author:** [@ken33](https://discuss.elastic.co/u/ken33)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 11:04pm UTC](https://discuss.elastic.co/t/http-p12-structure-and-use-of-keytool/346325 "2023-11-02T23:04:35Z")

</div>

Hi, In elasticsearch, I can execute : /usr/share/elasticsearch/jdk/bin/keytool -list -keystore http.p12.orig Enter keystore password: Keystore type: PKCS12 Keystore provider: SUN Your keystore contains 2 entries h…

---

## [Creating a Tag Cloud](https://discuss.elastic.co/t/creating-a-tag-cloud/346289)

<div class="topic-metadata">

**Author:** [@vils](https://discuss.elastic.co/u/vils)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 8:55pm UTC](https://discuss.elastic.co/t/creating-a-tag-cloud/346289 "2023-11-02T20:55:35Z")

</div>

Hello all, I have a field that displays feedback. I was hoping to create a tag cloud of the most popular words from the feedback, to get a feel of what customers are saying. Does anyone know how I could do this?

---

## [Index Object structure](https://discuss.elastic.co/t/index-object-structure/346156)

<div class="topic-metadata">

**Author:** [@volkerfrank](https://discuss.elastic.co/u/volkerfrank)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 6:36pm UTC](https://discuss.elastic.co/t/index-object-structure/346156 "2023-11-02T18:36:29Z")

</div>

Hi, how can I index a document with this fields to an index? .. "gitlab": { "path": "/api/v4/jobs/request", "method": "POST", …

---

## [ElastiSearch consuming above 90% RAM memory continuously](https://discuss.elastic.co/t/elastisearch-consuming-above-90-ram-memory-continuously/345812)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 6:31pm UTC](https://discuss.elastic.co/t/elastisearch-consuming-above-90-ram-memory-continuously/345812 "2023-11-02T18:31:11Z")

</div>

Hello, Elastic Search continuously occupying above 90% . Total RAM : 108 GB JVM: 32 GB ( 28Gb used out of 32GB) Single Node Elastic search. Could you please suggest/help how to reduce the RAM usage. Thanks in adva…

---

## [Logstash multiline charset =\> "UTF-8"](https://discuss.elastic.co/t/logstash-multiline-charset-utf-8/346146)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 4\
**Last updated:** [November 2, 2023, 5:14pm UTC](https://discuss.elastic.co/t/logstash-multiline-charset-utf-8/346146 "2023-11-02T17:14:56Z")

</div>

\[2023-10-31T12:01:11,534\]\[WARN \]\[logstash.codecs.multiline\]\[main\]\[a029b778777f02de25308ca25697ff60da99dc3bc13beaf4e1c2d010740b27d8\] Received an event that has a different character encoding than you configured. {:text=\>"…

---

## [If there is an error log in an application, how to send log files onto elastic search](https://discuss.elastic.co/t/if-there-is-an-error-log-in-an-application-how-to-send-log-files-onto-elastic-search/345906)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 21\
**Last updated:** [November 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/if-there-is-an-error-log-in-an-application-how-to-send-log-files-onto-elastic-search/345906 "2023-11-02T16:01:42Z")

</div>

if there is an error log in an application, how to send log files onto Elasticsearch

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=381)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=383)
