# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=392

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 393

---

## [Opensearch adding new value to the old one](https://discuss.elastic.co/t/opensearch-adding-new-value-to-the-old-one/345626)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 9:59am UTC](https://discuss.elastic.co/t/opensearch-adding-new-value-to-the-old-one/345626 "2023-10-24T09:59:38Z")

</div>

I have an opensearch and logstash stack; logstash sending logs from the base and i need to not just replace old values(that’s already works with method update in logstash and templates in opensearch), but adding new to t…

---

## [Rollup job and summarize with distinct values](https://discuss.elastic.co/t/rollup-job-and-summarize-with-distinct-values/345625)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 9:54am UTC](https://discuss.elastic.co/t/rollup-job-and-summarize-with-distinct-values/345625 "2023-10-24T09:54:38Z")

</div>

Hi, Is there a way to have a daily rollup job and instead of aggregations like min, max, etc, we store the distinct values of specific fields instead? Not the distinct count, but the actual values. Thank you.

---

## [Exception when executing JDBC query exception=\>Sequel::DatabaseError, :message=\>"Java::ComMicrosoftSqlserverJdbc::SQLServerException: Connection reset", :cause=\>"# \<Java::ComMicrosoftSqlserverJdbc::SQLServerException: Connection reset](https://discuss.elastic.co/t/exception-when-executing-jdbc-query-exception-sequel-databaseerror-message-java-connection-reset-cause-java-connection-reset/345562)

<div class="topic-metadata">

**Author:** [@Vishweshwar](https://discuss.elastic.co/u/Vishweshwar)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 7:57am UTC](https://discuss.elastic.co/t/exception-when-executing-jdbc-query-exception-sequel-databaseerror-message-java-connection-reset-cause-java-connection-reset/345562 "2023-10-24T07:57:36Z")

</div>

For some time i am able to connect DB but after few seconds i get the error "Exception when executing JDBC query " My logstash config format: input { jdbc { tags =\> "index.conf" jdbc\_connection\_string =\> "jdbc:sqlse…

---

## [Network Packet Capture over Logstash](https://discuss.elastic.co/t/network-packet-capture-over-logstash/344976)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 3\
**Last updated:** [October 24, 2023, 7:15am UTC](https://discuss.elastic.co/t/network-packet-capture-over-logstash/344976 "2023-10-24T07:15:14Z")

</div>

Hi Everyone, I've been having issues trying to use the Network Packet Capture (packetbeat) integration over Logstash. Whenever the Logstash output is configured for fleet, it seems like the integration stops sending da…

---

## [Help with Logstash file input](https://discuss.elastic.co/t/help-with-logstash-file-input/345475)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 11\
**Last updated:** [October 24, 2023, 5:01am UTC](https://discuss.elastic.co/t/help-with-logstash-file-input/345475 "2023-10-24T05:01:02Z")

</div>

I am not receiving the contents of fortune.txt for my ELK implementation. This is the input section: file { path =\> "/etc/elasticsearch/scripts/otherScripts/fortune.txt" sincedb\_path =\> "/dev/null" sta…

---

## [Updating only a few fields out of many](https://discuss.elastic.co/t/updating-only-a-few-fields-out-of-many/345508)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 3\
**Last updated:** [October 24, 2023, 1:57am UTC](https://discuss.elastic.co/t/updating-only-a-few-fields-out-of-many/345508 "2023-10-24T01:57:32Z")

</div>

ES version: 7.10 100 data nodes 1000 primary shards 5 B documents, 12 TB External versioning We are upserting almost 500 M documents a day and it is done via Index API. Each document could have 50 - 300 fields and in t…

---

## [Docker Elasticsearch 8.10.3 Java Crash](https://discuss.elastic.co/t/docker-elasticsearch-8-10-3-java-crash/345137)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 1:36am UTC](https://discuss.elastic.co/t/docker-elasticsearch-8-10-3-java-crash/345137 "2023-10-24T01:36:00Z")

</div>

Hey all, I tried upgrading my docker image from 8.8.0 which has been working fine, to 8.10.3 since thats the latest and encountered a Java crash when doing so. I havent been able to get a container running the 8.10.3 im…

---

## [Index Pattern Refresh](https://discuss.elastic.co/t/index-pattern-refresh/345603)

<div class="topic-metadata">

**Author:** [@Manuel\_Javier\_Martin](https://discuss.elastic.co/u/Manuel_Javier_Martin)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 12:23am UTC](https://discuss.elastic.co/t/index-pattern-refresh/345603 "2023-10-24T00:23:26Z")

</div>

Hi, Im using ES 7.10.2, and Im trying to refresh index patterns within python code, I already hit some endpoints GET api/index\_patterns/\_fields\_for\_wildcard?pattern=statsboard\_logs-\*&stored\_fields=\_source&stored\_fields=…

---

## [Logstash / Docker / Root (RW) access](https://discuss.elastic.co/t/logstash-docker-root-rw-access/345600)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 10:12pm UTC](https://discuss.elastic.co/t/logstash-docker-root-rw-access/345600 "2023-10-23T22:12:59Z")

</div>

Hi, I'd like to have a root access to my container logstash. I would like to do things that the logstash user doesn't allow (updating packages with apt update, adding packages like nano with apt install nano, etc). Ho…

---

## [I'm working on new community beat](https://discuss.elastic.co/t/im-working-on-new-community-beat/345594)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 7:33pm UTC](https://discuss.elastic.co/t/im-working-on-new-community-beat/345594 "2023-10-23T19:33:14Z")

</div>

Hello, i'm working on new project that collecting metrics from k6 via restAPI and indexes them then sending them to elasticsearch by beats. I just wonder if anyone working on this?

---

## [Elasticsearch automatic rebalancing process](https://discuss.elastic.co/t/elasticsearch-automatic-rebalancing-process/345582)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 5:39pm UTC](https://discuss.elastic.co/t/elasticsearch-automatic-rebalancing-process/345582 "2023-10-23T17:39:40Z")

</div>

Hi, We are running two (almost) identical Elasticsearch clusters v8.7.0, one of them works perfectly fine and in the second one we have shard balancing issues: is there a way to see why the automatic rebalancing pro…

---

## [ScanError while scrolling more than 10k docs](https://discuss.elastic.co/t/scanerror-while-scrolling-more-than-10k-docs/345517)

<div class="topic-metadata">

**Author:** [@mans4singh](https://discuss.elastic.co/u/mans4singh)\
**Replies:** 5\
**Last updated:** [October 23, 2023, 4:08pm UTC](https://discuss.elastic.co/t/scanerror-while-scrolling-more-than-10k-docs/345517 "2023-10-23T16:08:08Z")

</div>

Hi: I am getting ScanError (ScanError('Scroll request has only succeeded on 7 (+5 skipped) shards out of 15.')) when the search results is large (mostly when it is more than 10k). I have a few questions about it: Wha…

---

## [Elastic Cloud Persistent Queue?](https://discuss.elastic.co/t/elastic-cloud-persistent-queue/345066)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 5\
**Last updated:** [October 23, 2023, 4:00pm UTC](https://discuss.elastic.co/t/elastic-cloud-persistent-queue/345066 "2023-10-23T16:00:53Z")

</div>

I am ingesting logs from an on-prem logstash to Elastic Cloud. My Logstash instance has persistent queue enabled. I ingested a large set of data, about 50 million events from my on-prem Elasticsearch instance using the…

---

## [URL redirect for specific queries instead of search results](https://discuss.elastic.co/t/url-redirect-for-specific-queries-instead-of-search-results/345579)

<div class="topic-metadata">

**Author:** [@Max\_Townsend](https://discuss.elastic.co/u/Max_Townsend)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 3:06pm UTC](https://discuss.elastic.co/t/url-redirect-for-specific-queries-instead-of-search-results/345579 "2023-10-23T15:06:00Z")

</div>

Is it possible to redirect to another page when certain keywords are searched? We are a marketplace and would like to redirect users to specific brand pages instead of a results page. Ability to configure certain queri…

---

## [Fails to receive any log events，when two piplines using the same input port 5044](https://discuss.elastic.co/t/fails-to-receive-any-log-events-when-two-piplines-using-the-same-input-port-5044/345564)

<div class="topic-metadata">

**Author:** [@zhsongbj](https://discuss.elastic.co/u/zhsongbj)\
**Replies:** 2\
**Last updated:** [October 23, 2023, 2:50pm UTC](https://discuss.elastic.co/t/fails-to-receive-any-log-events-when-two-piplines-using-the-same-input-port-5044/345564 "2023-10-23T14:50:04Z")

</div>

I encountered a troubling issue for which I'd like to express my gratitude to anyone who can help. One pipeline consistently failed to receive log events. The problem occurred when two pipelines used the same input port,…

---

## [Correct configuration Elastic Search 8.10.4](https://discuss.elastic.co/t/correct-configuration-elastic-search-8-10-4/345238)

<div class="topic-metadata">

**Author:** [@Fernando\_Oliveira](https://discuss.elastic.co/u/Fernando_Oliveira)\
**Replies:** 9\
**Last updated:** [October 23, 2023, 1:50pm UTC](https://discuss.elastic.co/t/correct-configuration-elastic-search-8-10-4/345238 "2023-10-23T13:50:11Z")

</div>

I'm starting a new Elastic installation search and Kibana, version 8.10.4.. My goal is to make a better distribution following some recommendations I saw, for example 3 master, 2 data hot, 2 warm in different zones.. S…

---

## [Kibana Lens - Line Type - How to show the percentage of each terms](https://discuss.elastic.co/t/kibana-lens-line-type-how-to-show-the-percentage-of-each-terms/345321)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 1:46pm UTC](https://discuss.elastic.co/t/kibana-lens-line-type-how-to-show-the-percentage-of-each-terms/345321 "2023-10-23T13:46:27Z")

</div>

Hi all, I would like to create a visualization of Line type using Lens that display the percentage of each terms. The challange here is: in some documents, I have a field of type array with different values So, as exa…

---

## [Foilebeat IIS Module Config](https://discuss.elastic.co/t/foilebeat-iis-module-config/345325)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 4\
**Last updated:** [October 23, 2023, 12:08pm UTC](https://discuss.elastic.co/t/foilebeat-iis-module-config/345325 "2023-10-23T12:08:57Z")

</div>

I am working on version 8.10.2 of Elastic, Kibana and Filebeat. I am trying to get IIS.YML to work but I am running into a some errors. I am running this command: .\\filebeat.exe -e -c D:\\Filebeat\\modules.d\\iis.yml and…

---

## [Date Histogram bucket boundaries](https://discuss.elastic.co/t/date-histogram-bucket-boundaries/345301)

<div class="topic-metadata">

**Author:** [@arunachala](https://discuss.elastic.co/u/arunachala)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 11:18am UTC](https://discuss.elastic.co/t/date-histogram-bucket-boundaries/345301 "2023-10-23T11:18:35Z")

</div>

Hi, I understand that the bucket boundaries for date\_histogram are calculated with respect to epoch time. Is there any option to change this to a specific time? I am trying to achieve similar results as what some of da…

---

## [Aggregate two records in one index](https://discuss.elastic.co/t/aggregate-two-records-in-one-index/345503)

<div class="topic-metadata">

**Author:** [@reza\_sabz](https://discuss.elastic.co/u/reza_sabz)\
**Replies:** 6\
**Last updated:** [October 23, 2023, 9:52am UTC](https://discuss.elastic.co/t/aggregate-two-records-in-one-index/345503 "2023-10-23T09:52:42Z")

</div>

Hello guys, I have an index with a lot of records, like these: "\_source": { "terminal\_number": " 123456", "date": "2023-10-18 12:02:31.676", "iin": " 111111111 ", "service\_type": "o.t.s.transactions.trm.TerminalServ…

---

## [Issues with kibana visualization data table not showing matching results](https://discuss.elastic.co/t/issues-with-kibana-visualization-data-table-not-showing-matching-results/345553)

<div class="topic-metadata">

**Author:** [@Srikanth\_V](https://discuss.elastic.co/u/Srikanth_V)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 9:31am UTC](https://discuss.elastic.co/t/issues-with-kibana-visualization-data-table-not-showing-matching-results/345553 "2023-10-23T09:31:19Z")

</div>

Dear, I am using kibana data table visualization to show various fields in my dashboard. There is an issue that I am facing with regards to missing rows. I have 2 indexes, for french and dutch. There seems to be a mism…

---

## [Help constructing yaml file](https://discuss.elastic.co/t/help-constructing-yaml-file/345550)

<div class="topic-metadata">

**Author:** [@Emorta](https://discuss.elastic.co/u/Emorta)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 9:25am UTC](https://discuss.elastic.co/t/help-constructing-yaml-file/345550 "2023-10-23T09:25:05Z")

</div>

Hello, I'm trying to monitor Windows events (security only) and DHCP event logs (files). The first part works well; logs are collected and shipped, and it has been running for 3 months. I now want to add file logging for…

---

## [Elasticsearch "ignore\_above" issues. Unable to use the updated mapping setting after reindex](https://discuss.elastic.co/t/elasticsearch-ignore-above-issues-unable-to-use-the-updated-mapping-setting-after-reindex/345498)

<div class="topic-metadata">

**Author:** [@Shi\_Eng\_Ng](https://discuss.elastic.co/u/Shi_Eng_Ng)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-ignore-above-issues-unable-to-use-the-updated-mapping-setting-after-reindex/345498 "2023-10-23T08:35:47Z")

</div>

Index Mapping(In Kibana) GET /new\_index/\_mapping I already reset the "ignore\_above" to the larger size, but it seems not working for my index when I query for searching. I heard from other solutions that I need to rei…

---

## [Can anyone please explain me the time difference between the json view and the table view?](https://discuss.elastic.co/t/can-anyone-please-explain-me-the-time-difference-between-the-json-view-and-the-table-view/344906)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 6\
**Last updated:** [October 23, 2023, 6:46am UTC](https://discuss.elastic.co/t/can-anyone-please-explain-me-the-time-difference-between-the-json-view-and-the-table-view/344906 "2023-10-23T06:46:17Z")

</div>

Hi Team, I am using an elastic cloud account. My application is sending the data with timestamp in Sydney timezone. I have configured the same in kibana as well. I am almost seeing 11 hours difference between time stamp…

---

## [Create a graph where the connections' width is based on another column](https://discuss.elastic.co/t/create-a-graph-where-the-connections-width-is-based-on-another-column/345543)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 6:20am UTC](https://discuss.elastic.co/t/create-a-graph-where-the-connections-width-is-based-on-another-column/345543 "2023-10-23T06:20:37Z")

</div>

Hi, I have an index with 3 fields - source.ip, destination.ip, and num\_bytes. Is there a way to create a graph (from the graph analytics feature) where the vertices are the source.ip and destination.ip, and the width of…

---

## [Not condition met after configure watcher alert to email](https://discuss.elastic.co/t/not-condition-met-after-configure-watcher-alert-to-email/345538)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 4:10am UTC](https://discuss.elastic.co/t/not-condition-met-after-configure-watcher-alert-to-email/345538 "2023-10-23T04:10:18Z")

</div>

Hi everyone! I have text configured alert send watcher to email. However it is seem wrong text and not condition met send to email: code: { "trigger": { "schedule": { "interval": "1m" } }, "input": { "search":…

---

## [How to suppress ElasticSearch output stats](https://discuss.elastic.co/t/how-to-suppress-elasticsearch-output-stats/345533)

<div class="topic-metadata">

**Author:** [@hs121](https://discuss.elastic.co/u/hs121)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 2:34am UTC](https://discuss.elastic.co/t/how-to-suppress-elasticsearch-output-stats/345533 "2023-10-23T02:34:26Z")

</div>

Hi, Upon creating connection to Elasticsearch or indexing using python API, the output console shows elastic\_transport.transport stats. Is there a way I can suppress this information? Thanks e.g nodes = \[ https://el…

---

## [ElasticSearch 7.10 Spark hadoop support for sign requests ( AWS Signature V4)](https://discuss.elastic.co/t/elasticsearch-7-10-spark-hadoop-support-for-sign-requests-aws-signature-v4/345531)

<div class="topic-metadata">

**Author:** [@deepblue1618](https://discuss.elastic.co/u/deepblue1618)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 1:48am UTC](https://discuss.elastic.co/t/elasticsearch-7-10-spark-hadoop-support-for-sign-requests-aws-signature-v4/345531 "2023-10-23T01:48:48Z")

</div>

We are using Elasticsearch v7.10 and use spark to write bulk documents to the index. I was under the impression that we can sign request by passing headers like beow: df.write.mode("append").format('org.elasticsearch.s…

---

## [Custom sorting](https://discuss.elastic.co/t/custom-sorting/345525)

<div class="topic-metadata">

**Author:** [@maxim-pushchinskiy](https://discuss.elastic.co/u/maxim-pushchinskiy)\
**Replies:** 1\
**Last updated:** [October 22, 2023, 4:52pm UTC](https://discuss.elastic.co/t/custom-sorting/345525 "2023-10-22T16:52:26Z")

</div>

I have documents like: POST /your-index-name/\_doc/1 { "bbCategories": \["Shirts"\], "otherField": "value1" } POST /your-index-name/\_doc/2 { "bbCategories": \["Trousers"\], "otherField": "value2" } POST /your-index…

---

## [Elasticsearch stopped working , it is not extracting contents from documents](https://discuss.elastic.co/t/elasticsearch-stopped-working-it-is-not-extracting-contents-from-documents/345072)

<div class="topic-metadata">

**Author:** [@priyankaa](https://discuss.elastic.co/u/priyankaa)\
**Replies:** 16\
**Last updated:** [October 21, 2023, 10:24pm UTC](https://discuss.elastic.co/t/elasticsearch-stopped-working-it-is-not-extracting-contents-from-documents/345072 "2023-10-21T22:24:26Z")

</div>

due to disk storage got full , Elasticsearch was stopped working , so we have now increased it , still after increasing disk storage Elasticsearch is not working , I performed reindexing as per my senior suggestion , but…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=391)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=393)
