# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=401

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 402

---

## [Unable to see logs in Elasticsearch from logstash](https://discuss.elastic.co/t/unable-to-see-logs-in-elasticsearch-from-logstash/344288)

<div class="topic-metadata">

**Author:** [@AnyThink\_A](https://discuss.elastic.co/u/AnyThink_A)\
**Replies:** 8\
**Last updated:** [October 11, 2023, 5:23pm UTC](https://discuss.elastic.co/t/unable-to-see-logs-in-elasticsearch-from-logstash/344288 "2023-10-11T17:23:44Z")

</div>

Hello All, I am trying to deploy ELK stack in lab. I was able to get elastic and kibana up and running with XPAC enabled. But now struggling to get logs in elasticsearch from logstash. Refer config as below elasticsear…

---

## [Error loading model to ElasticSearch](https://discuss.elastic.co/t/error-loading-model-to-elasticsearch/344818)

<div class="topic-metadata">

**Author:** [@RodAndTom](https://discuss.elastic.co/u/RodAndTom)\
**Replies:** 3\
**Last updated:** [October 11, 2023, 4:10pm UTC](https://discuss.elastic.co/t/error-loading-model-to-elasticsearch/344818 "2023-10-11T16:10:39Z")

</div>

Hi, I previously successfully uploaded a NER model from Huggingface to Elasticsearch (8.10) with Eland. Now I'm trying to load a Text Classification and I'm getting an error: docker run -it --rm --network host docke…

---

## [Elasticsearch Shard Failure](https://discuss.elastic.co/t/elasticsearch-shard-failure/344774)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 3\
**Last updated:** [October 11, 2023, 3:58pm UTC](https://discuss.elastic.co/t/elasticsearch-shard-failure/344774 "2023-10-11T15:58:02Z")

</div>

Hi I'm using a single-node elasticsearch server. I have 400+ indices with 100GB+ data in cluster and shard count of each index is 5. When i'm trying to check the data for an index in discover page in kibana. I got the …

---

## [Migrating data from Elastic Search 2.X to 8.X using logstash](https://discuss.elastic.co/t/migrating-data-from-elastic-search-2-x-to-8-x-using-logstash/344760)

<div class="topic-metadata">

**Author:** [@gslp456](https://discuss.elastic.co/u/gslp456)\
**Replies:** 3\
**Last updated:** [October 11, 2023, 3:48pm UTC](https://discuss.elastic.co/t/migrating-data-from-elastic-search-2-x-to-8-x-using-logstash/344760 "2023-10-11T15:48:38Z")

</div>

I have an on-premise elastic cluster running on version 2.3.3. (aka old) I have another on-premise elastic cluster running on version 8.9.0 (aka new) I want to migrate data from one index of old to new using logstash …

---

## [Windows uninstall fails](https://discuss.elastic.co/t/windows-uninstall-fails/344403)

<div class="topic-metadata">

**Author:** [@GonzalezAldo](https://discuss.elastic.co/u/GonzalezAldo)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 3:44pm UTC](https://discuss.elastic.co/t/windows-uninstall-fails/344403 "2023-10-11T15:44:25Z")

</div>

PS C:\\Program Files\\elastic\\Agent\> .\\elastic-agent.exe uninstall Error: can only be uninstalled by executing the installed Elastic Agent at: C:\\Program Files\\Elastic\\Agent\\elastic-agent.exe For help, please see our tro…

---

## [Object mapping error for common field name "error"](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768)

<div class="topic-metadata">

**Author:** [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Replies:** 4\
**Last updated:** [October 11, 2023, 3:43pm UTC](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768 "2023-10-11T15:43:21Z")

</div>

Hello, I am getting the object mapping error. The logs are coming from Kubernetes cluster . On same index , the field "error" comes from App1 as json object , while comes as number from app2, comes as "one word strin…

---

## [Elastic Agent was installed failure on Windows 10](https://discuss.elastic.co/t/elastic-agent-was-installed-failure-on-windows-10/343321)

<div class="topic-metadata">

**Author:** [@yshulin](https://discuss.elastic.co/u/yshulin)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 3:42pm UTC](https://discuss.elastic.co/t/elastic-agent-was-installed-failure-on-windows-10/343321 "2023-10-11T15:42:36Z")

</div>

Elastic Agent was installed failure on Windows 10, and it show "Error: symlink" error message. Elastic Agent Version: 8.6.1 Install command: .\\elastic-agent.exe install --url=https://10.x.x.12:5042 --enrollment-token=…

---

## [Logstash exec input plugin issue](https://discuss.elastic.co/t/logstash-exec-input-plugin-issue/344834)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 3:32pm UTC](https://discuss.elastic.co/t/logstash-exec-input-plugin-issue/344834 "2023-10-11T15:32:13Z")

</div>

Hi All, I am using logstash's exec input plugin to pull data from ManageEngine via the REST API using a Python script. The script takes around 2 mins to run and return json lines. The pipeline runs fine for a few iterat…

---

## [Field type of message](https://discuss.elastic.co/t/field-type-of-message/344789)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 3:20pm UTC](https://discuss.elastic.co/t/field-type-of-message/344789 "2023-10-11T15:20:06Z")

</div>

Hello, we're using the Elastic Stack to store server logs. Currently, the field message is mapped as text field. Today, I tried to search for "oom-kill", but I couldn't get a search to work that matched exacly that. It …

---

## [Without the write permission of the kibana directory, how to launch kibana properly](https://discuss.elastic.co/t/without-the-write-permission-of-the-kibana-directory-how-to-launch-kibana-properly/344543)

<div class="topic-metadata">

**Author:** [@Lingran\_Xiao](https://discuss.elastic.co/u/Lingran_Xiao)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 3:17pm UTC](https://discuss.elastic.co/t/without-the-write-permission-of-the-kibana-directory-how-to-launch-kibana-properly/344543 "2023-10-11T15:17:25Z")

</div>

Hi, I don't have the write permission of the kibana-8.7.1 directory, but my group want me to finish the deployment of kibana. I specify the config directory by using the environment variable KBN\_PATH\_CONF. And when I tr…

---

## [Reindexing failure - "all shards failed" - "arraycopy: length -9 is negative"](https://discuss.elastic.co/t/reindexing-failure-all-shards-failed-arraycopy-length-9-is-negative/344401)

<div class="topic-metadata">

**Author:** [@tpolera](https://discuss.elastic.co/u/tpolera)\
**Replies:** 3\
**Last updated:** [October 11, 2023, 2:11pm UTC](https://discuss.elastic.co/t/reindexing-failure-all-shards-failed-arraycopy-length-9-is-negative/344401 "2023-10-11T14:11:41Z")

</div>

Hello, we're having a recent issue with reindexing that is failing after a short period of time. We recently discovered a mistake with our original index that only had 1 shard set upon creation when we should've had 20. …

---

## [How to take profit of compression for a Time Serie Data Stream](https://discuss.elastic.co/t/how-to-take-profit-of-compression-for-a-time-serie-data-stream/344811)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 4\
**Last updated:** [October 11, 2023, 1:05pm UTC](https://discuss.elastic.co/t/how-to-take-profit-of-compression-for-a-time-serie-data-stream/344811 "2023-10-11T13:05:26Z")

</div>

Hello, Every hour I generate a bulk request with several documents into a data stream, each update sets a @timestamp field for all the bulk of documents. (the idea is to keep track of a source of data in time). The pro…

---

## [Overwrite the value for String field](https://discuss.elastic.co/t/overwrite-the-value-for-string-field/344813)

<div class="topic-metadata">

**Author:** [@My\_Google\_Account](https://discuss.elastic.co/u/My_Google_Account)\
**Replies:** 5\
**Last updated:** [October 11, 2023, 1:43pm UTC](https://discuss.elastic.co/t/overwrite-the-value-for-string-field/344813 "2023-10-11T13:43:05Z")

</div>

Good day ! could you please help me with the following question: how can i overwrite or (what plugin should i use?) the following value to another one: from /server/oauth2/userinfo/slaves/\* to /server/oauth2/userinfo …

---

## [Runtime Fields disappearing after ILM Rollover](https://discuss.elastic.co/t/runtime-fields-disappearing-after-ilm-rollover/344815)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 12:06pm UTC](https://discuss.elastic.co/t/runtime-fields-disappearing-after-ilm-rollover/344815 "2023-10-11T12:06:56Z")

</div>

I added a runtime field to multiple indices using the following script: PUT my-index-000309/\_mapping {"runtime":{"agent.host\_prod\_flag":{"type":"keyword","script":{"source":"if (doc\['agent.hostname.keyword'\].size () != …

---

## [Visualization In Kibana after Merging/Mapping](https://discuss.elastic.co/t/visualization-in-kibana-after-merging-mapping/344801)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 11:29am UTC](https://discuss.elastic.co/t/visualization-in-kibana-after-merging-mapping/344801 "2023-10-11T11:29:32Z")

</div>

"Hello Community, I've always found great support here, and I'm hoping for the same assistance again. In my application, I'm dealing with three different types of logs. These logs are sent to Logstash via Filebeat, wher…

---

## [Where is logstash log](https://discuss.elastic.co/t/where-is-logstash-log/344800)

<div class="topic-metadata">

**Author:** [@ChiMu\_Yuan](https://discuss.elastic.co/u/ChiMu_Yuan)\
**Replies:** 2\
**Last updated:** [October 11, 2023, 11:10am UTC](https://discuss.elastic.co/t/where-is-logstash-log/344800 "2023-10-11T11:10:21Z")

</div>

Hello everyone, I installed logstash with yum. But I can't start it. And the log is empty. How can i find the error log Thank you.

---

## [I want to read key value kafka headers](https://discuss.elastic.co/t/i-want-to-read-key-value-kafka-headers/344711)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 3\
**Last updated:** [October 11, 2023, 11:00am UTC](https://discuss.elastic.co/t/i-want-to-read-key-value-kafka-headers/344711 "2023-10-11T11:00:47Z")

</div>

Hello I want to read key value kafka headers but it is not giving me any output Can anyone please help me with the configuration or piece of code to read key value from kafka headers. My old ticket reference -

---

## [Fleet metrics data seems incorrect](https://discuss.elastic.co/t/fleet-metrics-data-seems-incorrect/342936)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 4\
**Last updated:** [October 11, 2023, 9:22am UTC](https://discuss.elastic.co/t/fleet-metrics-data-seems-incorrect/342936 "2023-10-11T09:22:48Z")

</div>

Could someone explain what metrics are being used on the fleet page It seems like the CPU and memory metrics are not matching the one on the server, for the first one for example it says 130 MB however the server its…

---

## [Connector in KIbana not showing "Define Time field for each document"](https://discuss.elastic.co/t/connector-in-kibana-not-showing-define-time-field-for-each-document/344796)

<div class="topic-metadata">

**Author:** [@Ashish\_Kumar4](https://discuss.elastic.co/u/Ashish_Kumar4)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 8:08am UTC](https://discuss.elastic.co/t/connector-in-kibana-not-showing-define-time-field-for-each-document/344796 "2023-10-11T08:08:09Z")

</div>

I have self hosted the ELK stack and in that while adding a connector i can see that there is no option coming for "Define Time field for each document" as shown in kibana documentation. Version : 8.7 Link for document…

---

## [XML Array parsing](https://discuss.elastic.co/t/xml-array-parsing/344795)

<div class="topic-metadata">

**Author:** [@Matthias\_Brauchle](https://discuss.elastic.co/u/Matthias_Brauchle)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 8:04am UTC](https://discuss.elastic.co/t/xml-array-parsing/344795 "2023-10-11T08:04:45Z")

</div>

Hello, Setup: Elasticsearch Elastic Agent with the CEL Integration (Documentation) XML Processor Ingest Pipeline My goal is to store the output in Elasticsearch (of course). The URL is from Cisco CUCM and responds w…

---

## [A slow query problem in elasticsearch (aggregation)](https://discuss.elastic.co/t/a-slow-query-problem-in-elasticsearch-aggregation/344793)

<div class="topic-metadata">

**Author:** [@haipeng.zhao](https://discuss.elastic.co/u/haipeng.zhao)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 7:59am UTC](https://discuss.elastic.co/t/a-slow-query-problem-in-elasticsearch-aggregation/344793 "2023-10-11T07:59:48Z")

</div>

Please help me optimize this query. The index is 800mb and the query time is about to exceed 1 second. { "from": 0, "size": 300, "explain": "true", "\_source": \[ "sku\_id", "upc", "…

---

## [Impact of CVE-2023-4863, CVE-2023-5129, & CVE-2023-5217 to Elasticsearch v7.17.10](https://discuss.elastic.co/t/impact-of-cve-2023-4863-cve-2023-5129-cve-2023-5217-to-elasticsearch-v7-17-10/344790)

<div class="topic-metadata">

**Author:** [@Ravi\_Rao](https://discuss.elastic.co/u/Ravi_Rao)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 7:58am UTC](https://discuss.elastic.co/t/impact-of-cve-2023-4863-cve-2023-5129-cve-2023-5217-to-elasticsearch-v7-17-10/344790 "2023-10-11T07:58:32Z")

</div>

This is regarding CVE-2023-4863 , CVE-2023-5129 , CVE-2023-5217 new vulnerabilities identified and seeking confirmation on Elastic search v7.17.x is impacted with these new vulnerabilities or not ? Any updates availa…

---

## [Duplicate content when using azure-blob-storage input](https://discuss.elastic.co/t/duplicate-content-when-using-azure-blob-storage-input/344046)

<div class="topic-metadata">

**Author:** [@djesus](https://discuss.elastic.co/u/djesus)\
**Replies:** 4\
**Last updated:** [October 11, 2023, 7:00am UTC](https://discuss.elastic.co/t/duplicate-content-when-using-azure-blob-storage-input/344046 "2023-10-11T07:00:34Z")

</div>

Hello everyone, I'm encountering an issue while using the azure-blob-storage input in Filebeat, where I'm consistently getting duplicate entries each time I poll for data. Here's the setup: We have a container in Azure…

---

## [Define Runtime Field as Clickable URL](https://discuss.elastic.co/t/define-runtime-field-as-clickable-url/344784)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 6:07am UTC](https://discuss.elastic.co/t/define-runtime-field-as-clickable-url/344784 "2023-10-11T06:07:59Z")

</div>

Referring to the attached screenshot of Scripted Field, it was working using Kibana 7.17.0. Expected to see the label shows up on Kibana as 1234567 (es\_id) and the clickable URL being resolved using URL template, e.g. ht…

---

## [Documentation on pkg.go.dev (godoc) not working](https://discuss.elastic.co/t/documentation-on-pkg-go-dev-godoc-not-working/344783)

<div class="topic-metadata">

**Author:** [@tlinker13](https://discuss.elastic.co/u/tlinker13)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 5:38am UTC](https://discuss.elastic.co/t/documentation-on-pkg-go-dev-godoc-not-working/344783 "2023-10-11T05:38:46Z")

</div>

Hey all, I try to write a first metricbeat module/metricset and need to dive into the MapStrAPI, but there is no content displayed at libbeat's godoc page saying: "Documentation not displayed due to license restriction…

---

## [Kibana console 's message section show messy code only for elasticsearch server's messages, but ok for other servers forwarding messages by filebeat](https://discuss.elastic.co/t/kibana-console-s-message-section-show-messy-code-only-for-elasticsearch-servers-messages-but-ok-for-other-servers-forwarding-messages-by-filebeat/344775)

<div class="topic-metadata">

**Author:** [@huanghaiqing1](https://discuss.elastic.co/u/huanghaiqing1)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 3:06am UTC](https://discuss.elastic.co/t/kibana-console-s-message-section-show-messy-code-only-for-elasticsearch-servers-messages-but-ok-for-other-servers-forwarding-messages-by-filebeat/344775 "2023-10-11T03:06:04Z")

</div>

Here I setup kibana/elasticsearch/filebeat in one server: autoyast1, and it also plays as syslog server by store all forwarding messages from managed servers. Today I found ONLY the server itself's message shows as messy…

---

## [ElasticSearch custom index and mapping | local json data visualization issue](https://discuss.elastic.co/t/elasticsearch-custom-index-and-mapping-local-json-data-visualization-issue/344571)

<div class="topic-metadata">

**Author:** [@Srini-99](https://discuss.elastic.co/u/Srini-99)\
**Replies:** 11\
**Last updated:** [October 11, 2023, 2:34am UTC](https://discuss.elastic.co/t/elasticsearch-custom-index-and-mapping-local-json-data-visualization-issue/344571 "2023-10-11T02:34:42Z")

</div>

Hi! I have setup elasticsearch, kibana, filebeat. With the other beats, i am able to collect logs and visualize them. But i want to be able to upload logs that are in json format and visualize them. The logs that i wa…

---

## [How to highlight the matching subtext in elasticsearch](https://discuss.elastic.co/t/how-to-highlight-the-matching-subtext-in-elasticsearch/344754)

<div class="topic-metadata">

**Author:** [@Karthikeyan\_Amaresan](https://discuss.elastic.co/u/Karthikeyan_Amaresan)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 1:08am UTC](https://discuss.elastic.co/t/how-to-highlight-the-matching-subtext-in-elasticsearch/344754 "2023-10-11T01:08:52Z")

</div>

I am getting expected highlighting of substring matching user search keyword in companyName and country fields. However in emailId field instead of highlighting the substring the entire field is getting highlighted. Que…

---

## [A question around logstash S3 input plugin](https://discuss.elastic.co/t/a-question-around-logstash-s3-input-plugin/344769)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 2\
**Last updated:** [October 11, 2023, 1:04am UTC](https://discuss.elastic.co/t/a-question-around-logstash-s3-input-plugin/344769 "2023-10-11T01:04:04Z")

</div>

Hi All, We run logstash on multiple EC2 instances behind a loadbalancer for reliability purposes. We are thinking of using the S3 input plugin. Since the servers are created by auto-scaling process of AWS, they are exac…

---

## [Split my json input in logstash and push to ES](https://discuss.elastic.co/t/split-my-json-input-in-logstash-and-push-to-es/344767)

<div class="topic-metadata">

**Author:** [@shdasgupta](https://discuss.elastic.co/u/shdasgupta)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 12:17am UTC](https://discuss.elastic.co/t/split-my-json-input-in-logstash-and-push-to-es/344767 "2023-10-11T00:17:44Z")

</div>

Hi, I have a gzipped json coming from kafka and I need to push it to ES after some transformations. With the help of this forum, I was able solve some of my problem. Right now i need to split the decompressed json into s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=400)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=402)
