# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=384

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 385

---

## [How to convert field to Java properties](https://discuss.elastic.co/t/how-to-convert-field-to-java-properties/346104)

<div class="topic-metadata">

**Author:** [@Hsu\_Demon](https://discuss.elastic.co/u/Hsu_Demon)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 2:11am UTC](https://discuss.elastic.co/t/how-to-convert-field-to-java-properties/346104 "2023-11-02T02:11:09Z")

</div>

I use elasticsearch-java version 8.10.4 rather than spring-data-elasticsearch. In my elasticsearch index, the field is underline-word such as "user\_id". But in my Java Object, it is "userId". when i get the SearchRespo…

---

## [Supply ElasticSearch Keystore password to start ElasticSearch Service](https://discuss.elastic.co/t/supply-elasticsearch-keystore-password-to-start-elasticsearch-service/346160)

<div class="topic-metadata">

**Author:** [@ChrisMannix](https://discuss.elastic.co/u/ChrisMannix)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 6:38pm UTC](https://discuss.elastic.co/t/supply-elasticsearch-keystore-password-to-start-elasticsearch-service/346160 "2023-11-01T18:38:12Z")

</div>

Hi, I have been building my Elasticsearch cluster and I was playing around with the Elasticsearch keystore. If I change the Elasticsearch keystore password, the Elasticsearch service does not start anymore. This makes…

---

## [Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/346233)

<div class="topic-metadata">

**Author:** [@juhigupta](https://discuss.elastic.co/u/juhigupta)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 6:08pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/346233 "2023-11-01T18:08:33Z")

</div>

When I upgrade to 8.8.2 from 7.17.9. I get below error in kibana. Same certificates are working for 7.17.9 in kibana , but same are failing for 8.8.2, Any suggestion please. Below is the error Unable to retrieve versi…

---

## [ELK in docker - fleet server on the host](https://discuss.elastic.co/t/elk-in-docker-fleet-server-on-the-host/346230)

<div class="topic-metadata">

**Author:** [@ken33](https://discuss.elastic.co/u/ken33)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 5:50pm UTC](https://discuss.elastic.co/t/elk-in-docker-fleet-server-on-the-host/346230 "2023-11-01T17:50:57Z")

</div>

Dear all, Sorry for asking a question allready seen question but not enough details to solve the pb. I install elk in docker according to the doc Docker is running on a host 192.168.50.3. Docker network is 172.19.0.0…

---

## [Logstash Sincedb duplicate entries](https://discuss.elastic.co/t/logstash-sincedb-duplicate-entries/346187)

<div class="topic-metadata">

**Author:** [@justin\_sch](https://discuss.elastic.co/u/justin_sch)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 5:46pm UTC](https://discuss.elastic.co/t/logstash-sincedb-duplicate-entries/346187 "2023-11-01T17:46:45Z")

</div>

Hey, I'm using the ELK-Stack to analyze a Log-File. Right now I clone the Log-File via SSH onto my local machine via a bash script every hour. The Logfile gets data appended every minute. This is my conf: input { …

---

## [Splitting different usages in clusters?](https://discuss.elastic.co/t/splitting-different-usages-in-clusters/346215)

<div class="topic-metadata">

**Author:** [@grumpy](https://discuss.elastic.co/u/grumpy)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 4:41pm UTC](https://discuss.elastic.co/t/splitting-different-usages-in-clusters/346215 "2023-11-01T16:41:28Z")

</div>

We have multiple apps indexing their own data. We're setting up our new server and are thinking of optimizing our configurations. When does it make sense to have different clusters for the different apps? What are the …

---

## [Kibana - Visualization aggregation not working on large values of a field](https://discuss.elastic.co/t/kibana-visualization-aggregation-not-working-on-large-values-of-a-field/346213)

<div class="topic-metadata">

**Author:** [@sunildate](https://discuss.elastic.co/u/sunildate)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 3:47pm UTC](https://discuss.elastic.co/t/kibana-visualization-aggregation-not-working-on-large-values-of-a-field/346213 "2023-11-01T15:47:42Z")

</div>

I have aggregated field values with characters length 850. In Visualization after applying aggregation on term not returning field value. I have also updated ignore\_above to 1024. Can you please help me.

---

## [Elastic Cross Cluster Replication of Data Stream](https://discuss.elastic.co/t/elastic-cross-cluster-replication-of-data-stream/346178)

<div class="topic-metadata">

**Author:** [@adsandie](https://discuss.elastic.co/u/adsandie)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 3:05pm UTC](https://discuss.elastic.co/t/elastic-cross-cluster-replication-of-data-stream/346178 "2023-11-01T15:05:00Z")

</div>

Both Cluster are using v8.9.1 Hi, this is a new upgrade from 7.16.3 to 8.9.1 and we just reconfigured CCR. This is our first time using CCR on a data stream. We have been using CCR before on Index (metricbeat-, filebeat…

---

## [Timestamp from log files to @timestamp](https://discuss.elastic.co/t/timestamp-from-log-files-to-timestamp/346199)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 4\
**Last updated:** [November 1, 2023, 2:39pm UTC](https://discuss.elastic.co/t/timestamp-from-log-files-to-timestamp/346199 "2023-11-01T14:39:12Z")

</div>

Hey, !NOTE! i'm new to the elk stack in all its facettes. I have some Problems with displaying my logfiles from an laravel application. I'm running laravel on one server and my elk stack on another i installed logstas…

---

## [Metricbeat on Windows only returns volumes with drive letter](https://discuss.elastic.co/t/metricbeat-on-windows-only-returns-volumes-with-drive-letter/345807)

<div class="topic-metadata">

**Author:** [@kenmich](https://discuss.elastic.co/u/kenmich)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 2:33pm UTC](https://discuss.elastic.co/t/metricbeat-on-windows-only-returns-volumes-with-drive-letter/345807 "2023-11-01T14:33:05Z")

</div>

I'm running metricbeat 8.10.2 on Windows Server Core 2022. It's a physical server with multiple physical disks, where only one of these is mounted with a drive letter (C:). All other disk, both SATA and NVMe are mounted…

---

## [Is it possible to create a aggregated runtime field and compare them?](https://discuss.elastic.co/t/is-it-possible-to-create-a-aggregated-runtime-field-and-compare-them/346205)

<div class="topic-metadata">

**Author:** [@turbo23](https://discuss.elastic.co/u/turbo23)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 2:24pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-aggregated-runtime-field-and-compare-them/346205 "2023-11-01T14:24:21Z")

</div>

Hello, I want to create a dashboard that shows OK if my data\_stream distinct counted hostnames equals to my distinct counted hostnames in the cmdb index or shows NOK if it no longer equals both values. My idea: Compare…

---

## [Elastic Agent upgrade through Fleet and using Custom Agent Binary Source](https://discuss.elastic.co/t/elastic-agent-upgrade-through-fleet-and-using-custom-agent-binary-source/346206)

<div class="topic-metadata">

**Author:** [@hamidallaoui](https://discuss.elastic.co/u/hamidallaoui)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 2:16pm UTC](https://discuss.elastic.co/t/elastic-agent-upgrade-through-fleet-and-using-custom-agent-binary-source/346206 "2023-11-01T14:16:32Z")

</div>

Hi All, Did someone already test to upgrade Elastic Agent through Fleet and using Custom Agent Binary Source ? We tried from our side by giving url of reverse proxy (Nginx) but it did not work. Thank you for your feed…

---

## [Kibana search fails to find string](https://discuss.elastic.co/t/kibana-search-fails-to-find-string/346163)

<div class="topic-metadata">

**Author:** [@ChazJaz](https://discuss.elastic.co/u/ChazJaz)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/kibana-search-fails-to-find-string/346163 "2023-11-01T14:02:51Z")

</div>

When I try a simple KQL search for the character pattern: message: "}\]}}}" it finds no results even though I can see that string pattern in some entries of an unfiltered query of my data stream. According to the KQL do…

---

## [EFK | Filebeat](https://discuss.elastic.co/t/efk-filebeat/345211)

<div class="topic-metadata">

**Author:** [@Hassan\_Ahmed](https://discuss.elastic.co/u/Hassan_Ahmed)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/efk-filebeat/345211 "2023-11-01T14:02:05Z")

</div>

\[2023-10-16 12:43:41\] | DEBUG | watch\_dir | django.utils.autoreload | Watching dir /home/hassan/Documents/PROJECTS/vault-api/venv/lib/python3.10/site-packages/oauth2\_provider/locale with glob. I have a log file above wi…

---

## [Log4j2 Rolling File Strategy Only Rolls Once](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 4\
**Last updated:** [November 1, 2023, 1:48pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320 "2023-11-01T13:48:40Z")

</div>

I'm having issues with the log4j2 rolling file appender. It only writes the first rollover file. Here's my config: status = error name = LogstashPropertiesConfig appender.console.type = Console appender.console.name =…

---

## [Azure Blob Storage to Elasticsearch - SaaS Elastic Cloud in Azure](https://discuss.elastic.co/t/azure-blob-storage-to-elasticsearch-saas-elastic-cloud-in-azure/346194)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 11:44am UTC](https://discuss.elastic.co/t/azure-blob-storage-to-elasticsearch-saas-elastic-cloud-in-azure/346194 "2023-11-01T11:44:52Z")

</div>

What are the options to load the JSON/CSV files from Azure Blob Storage to Elasticsearch (Elastic Cloud in Azure) I see the following filebeat module is in Beta.

---

## [Metricbeat does not see all processes](https://discuss.elastic.co/t/metricbeat-does-not-see-all-processes/346193)

<div class="topic-metadata">

**Author:** [@vlados31999](https://discuss.elastic.co/u/vlados31999)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 11:10am UTC](https://discuss.elastic.co/t/metricbeat-does-not-see-all-processes/346193 "2023-11-01T11:10:48Z")

</div>

Hi, everybody metricbeat does not see processes whose parent services.exe Help please

---

## [Get records from index based on result from another search](https://discuss.elastic.co/t/get-records-from-index-based-on-result-from-another-search/346074)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 5\
**Last updated:** [November 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/get-records-from-index-based-on-result-from-another-search/346074 "2023-11-01T10:41:01Z")

</div>

Hi, I have an index where we collect the requests to our api somthing like this : myindex: url: /some/path service: someservice uuid: xxx-yyy-zzz-uuu And I have a requirement to get or correlate all urls that…

---

## [Use time filter on auto-interval date histogram](https://discuss.elastic.co/t/use-time-filter-on-auto-interval-date-histogram/345964)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 8:49am UTC](https://discuss.elastic.co/t/use-time-filter-on-auto-interval-date-histogram/345964 "2023-11-01T08:49:14Z")

</div>

Hello, I'm using version 8.6.0 of elastic cloud. I'm trying to develop a chart similar to the TSVB time series, but the way my data is loaded I need to do it in Vega. I'm using auto-interval date histogram to separate …

---

## [How can I format a column in Lens so it can operate as a sum of time?](https://discuss.elastic.co/t/how-can-i-format-a-column-in-lens-so-it-can-operate-as-a-sum-of-time/346151)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 8:41am UTC](https://discuss.elastic.co/t/how-can-i-format-a-column-in-lens-so-it-can-operate-as-a-sum-of-time/346151 "2023-11-01T08:41:58Z")

</div>

Basically, I have a column in my index that returns the total of time a device is down like this: But as I go further in time range it turns into something like this: I need to format this into the right amount of …

---

## [Fleet-server installation error](https://discuss.elastic.co/t/fleet-server-installation-error/346179)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 8:06am UTC](https://discuss.elastic.co/t/fleet-server-installation-error/346179 "2023-11-01T08:06:19Z")

</div>

Hi I'm trying to run fleet I tried with self generated fleet-server certificate and with basic one without generating certificate but ended up having an error.

---

## [Performance degrade after using Elastic 8](https://discuss.elastic.co/t/performance-degrade-after-using-elastic-8/345703)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 3\
**Last updated:** [November 1, 2023, 8:00am UTC](https://discuss.elastic.co/t/performance-degrade-after-using-elastic-8/345703 "2023-11-01T08:00:08Z")

</div>

We have been using elastic 7.17 Our application has load tests and we generally measure the performance After upgrading to elastic 8, we see lot of difference in the results we had when compared to elastic 7 We also n…

---

## [Best approach to combine two different ES instances in one instance](https://discuss.elastic.co/t/best-approach-to-combine-two-different-es-instances-in-one-instance/346177)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 7:34am UTC](https://discuss.elastic.co/t/best-approach-to-combine-two-different-es-instances-in-one-instance/346177 "2023-11-01T07:34:05Z")

</div>

I have two instances running from two different drives. I would like to combine both. I have two approaches. Shutdown second node and use the data path of the second node in the first node as a multi-data path option c…

---

## [Filebeat setup command showing missing references under dasboard directory](https://discuss.elastic.co/t/filebeat-setup-command-showing-missing-references-under-dasboard-directory/346172)

<div class="topic-metadata">

**Author:** [@Akshay\_Ranka](https://discuss.elastic.co/u/Akshay_Ranka)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 5:38am UTC](https://discuss.elastic.co/t/filebeat-setup-command-showing-missing-references-under-dasboard-directory/346172 "2023-11-01T05:38:16Z")

</div>

I installed filebeat and it is up and running as a service. BUT i am not able to run the setup command for filebeat it is showing errors as missing references. It shows error with the json files in the dashboard folder

---

## [Consider comma separated values in a field as separate values while aggregating](https://discuss.elastic.co/t/consider-comma-separated-values-in-a-field-as-separate-values-while-aggregating/345804)

<div class="topic-metadata">

**Author:** [@Gagan\_Saluja](https://discuss.elastic.co/u/Gagan_Saluja)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 4:26am UTC](https://discuss.elastic.co/t/consider-comma-separated-values-in-a-field-as-separate-values-while-aggregating/345804 "2023-11-01T04:26:34Z")

</div>

Hi, i want to do aggregation on a field which has values like doc1\_field: "A" doc2\_field: "A, B" doc3\_field: "A, B, C" What mappings / settings I can use so that when I aggregate on this field I should get results l…

---

## [Maximum document for rollup job](https://discuss.elastic.co/t/maximum-document-for-rollup-job/346169)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/maximum-document-for-rollup-job/346169 "2023-11-01T04:05:45Z")

</div>

Hello there, I want to ask about rollup job. Currently, i've been created a rollup job with 1s interval and 5 fields on terms and 2 fields for metrics and 60.000 page size. And the total document for the production inde…

---

## [Ilm rollover error on datastream index](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 2:30am UTC](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164 "2023-11-01T02:30:10Z")

</div>

I one index of a datastream showing an ILM error: java.lang.IllegalStateException: no rollover info found for \[.ds-sec-events-2023.08.12-000015\] with rollover target \[sec-events\], the index has not yet rolled over with …

---

## [Hardware Requirements - Self hosted in Cloud](https://discuss.elastic.co/t/hardware-requirements-self-hosted-in-cloud/346067)

<div class="topic-metadata">

**Author:** [@bEngineer](https://discuss.elastic.co/u/bEngineer)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 10:27pm UTC](https://discuss.elastic.co/t/hardware-requirements-self-hosted-in-cloud/346067 "2023-10-31T22:27:27Z")

</div>

Hi everyone, I'm researching scalability costs for an elasticsearch search engine project. I understand some hardware requirements on a small scale, large scale I'm having a hard time wrapping my head around it. I have…

---

## [Find transactions flow](https://discuss.elastic.co/t/find-transactions-flow/346059)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 5:39pm UTC](https://discuss.elastic.co/t/find-transactions-flow/346059 "2023-10-31T17:39:29Z")

</div>

Hi Is there anyway to find transaction flow like this i have log file contain 50 million transactions like this 16:30:53:002 moduleA:\[C1\]L\[143\]F\[10\]ID\[123456\] 16:30:54:002 moduleA:\[C2\]L\[143\]F\[20\]ID\[123456\] 16:30:55:00…

---

## [Elasticsearch Export Import](https://discuss.elastic.co/t/elasticsearch-export-import/346143)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 4:11pm UTC](https://discuss.elastic.co/t/elasticsearch-export-import/346143 "2023-10-31T16:11:44Z")

</div>

Hi Team, I had a requirement where I need export/ import one of the index data to a separate cluster. Is there any such tool which help me to achieve the same. Thanks, Debasis

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=383)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=385)
