# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=402

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 403

---

## [ElastAlert Error smtplib.SMTPSenderRefused: (530, b'5.7.0 Authentication Required. Learn more at\\n5.7.0](https://discuss.elastic.co/t/elastalert-error-smtplib-smtpsenderrefused-530-b5-7-0-authentication-required-learn-more-at-n5-7-0/344766)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 10:00pm UTC](https://discuss.elastic.co/t/elastalert-error-smtplib-smtpsenderrefused-530-b5-7-0-authentication-required-learn-more-at-n5-7-0/344766 "2023-10-10T22:00:32Z")

</div>

I am trying to configure elastalert 2 to read from elasticsearch index and send alert according to configured rule, i am using gmail smtp and app password to achieve this. Every thing is running fine but when i try to te…

---

## [Single shard failing with snapshot](https://discuss.elastic.co/t/single-shard-failing-with-snapshot/344688)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [October 10, 2023, 9:53pm UTC](https://discuss.elastic.co/t/single-shard-failing-with-snapshot/344688 "2023-10-10T21:53:15Z")

</div>

I wish I knew why my backup system is so brittle : ( I have a single shard failing for the last couple of days - from kibana: INTERNAL\_SERVER\_ERROR: UncategorizedExecutionException\[Failed execution\]; nested: Execution…

---

## [How to add a map by pointing to an external map server but not elastic map server?](https://discuss.elastic.co/t/how-to-add-a-map-by-pointing-to-an-external-map-server-but-not-elastic-map-server/344416)

<div class="topic-metadata">

**Author:** [@FredMir](https://discuss.elastic.co/u/FredMir)\
**Replies:** 5\
**Last updated:** [October 10, 2023, 8:55pm UTC](https://discuss.elastic.co/t/how-to-add-a-map-by-pointing-to-an-external-map-server-but-not-elastic-map-server/344416 "2023-10-10T20:55:20Z")

</div>

I want to add a map for data visualization by pointing to a map server already available by my company. I don't have access to internet and I don't want to download docker image for Elastic map server. How can I change t…

---

## [Scripted update fails with "unsupport\_operation\_exception: null"](https://discuss.elastic.co/t/scripted-update-fails-with-unsupport-operation-exception-null/344349)

<div class="topic-metadata">

**Author:** [@s.moran](https://discuss.elastic.co/u/s.moran)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 8:32pm UTC](https://discuss.elastic.co/t/scripted-update-fails-with-unsupport-operation-exception-null/344349 "2023-10-10T20:32:29Z")

</div>

I am seeing an intermittent issue where ES fails to execute a script due to an unsupported\_operation\_exception. The whole error looks like this "error": { "type": "illegal\_argument\_exception", "reason": "failed to …

---

## [Logstash HTTP output plugin](https://discuss.elastic.co/t/logstash-http-output-plugin/344553)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 4\
**Last updated:** [October 10, 2023, 7:12pm UTC](https://discuss.elastic.co/t/logstash-http-output-plugin/344553 "2023-10-10T19:12:26Z")

</div>

I'm trying to use the HTTP output plugin to send a PUT request to a URL but getting a 400 message, and I can't figure out what I'm messing up. I'm using Logstash v8 running in a Docker container. I'm able to successful…

---

## [Issue with ingest pipeline](https://discuss.elastic.co/t/issue-with-ingest-pipeline/344535)

<div class="topic-metadata">

**Author:** [@rafaelrangel](https://discuss.elastic.co/u/rafaelrangel)\
**Replies:** 18\
**Last updated:** [October 10, 2023, 4:45pm UTC](https://discuss.elastic.co/t/issue-with-ingest-pipeline/344535 "2023-10-10T16:45:16Z")

</div>

I have a data entry through Logstash (8.9.1) that does not have a field (hostname) only ip. I created a pipeline using the Elastic API (8.9.1) like this: PUT \_ingest/pipeline/name\_device\_ping { "processors": \[ { …

---

## [\[HELP winlogbeat.yml\] How to send Removable storage logs to Elasticsearch](https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 4:00pm UTC](https://discuss.elastic.co/t/help-winlogbeat-yml-how-to-send-removable-storage-logs-to-elasticsearch/344738 "2023-10-10T16:00:39Z")

</div>

Hello from Japan I have a question for you respected engineers. I am an inexperienced Japanese engineer with Elastic search. I have installed winlogbeat on my Windows PC and have built an environment to send Windows l…

---

## [Enroll command failed with exit code: 1](https://discuss.elastic.co/t/enroll-command-failed-with-exit-code-1/344739)

<div class="topic-metadata">

**Author:** [@Jean-Claude](https://discuss.elastic.co/u/Jean-Claude)\
**Replies:** 5\
**Last updated:** [October 10, 2023, 3:31pm UTC](https://discuss.elastic.co/t/enroll-command-failed-with-exit-code-1/344739 "2023-10-10T15:31:50Z")

</div>

Hello, i hope you are doing well This my infra ELASTIC v-elkmaster01.sys.u-bordeaux.fr v-elkmaster02.sys.u-bordeaux.fr v-elkmaster03.sys.u-bordeaux.fr p-elkhot01.sys.u-bordeaux.fr p-elkhot02.sys.u-bordeaux.fr p-elkwar…

---

## [Sort the Elasticsearch results based on the matched nested object in search-ui](https://discuss.elastic.co/t/sort-the-elasticsearch-results-based-on-the-matched-nested-object-in-search-ui/344752)

<div class="topic-metadata">

**Author:** [@rommelcanoy](https://discuss.elastic.co/u/rommelcanoy)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 3:14pm UTC](https://discuss.elastic.co/t/sort-the-elasticsearch-results-based-on-the-matched-nested-object-in-search-ui/344752 "2023-10-10T15:14:02Z")

</div>

I want to implement it in Search-UI. How should I do it? For instance, if users search for 'Mucopolysaccharidosis Type 1,' I want to sort the results based on the "score" of the matched nested condition inside this field…

---

## [Get documents based on other documents](https://discuss.elastic.co/t/get-documents-based-on-other-documents/344475)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 5\
**Last updated:** [October 10, 2023, 3:13pm UTC](https://discuss.elastic.co/t/get-documents-based-on-other-documents/344475 "2023-10-10T15:13:32Z")

</div>

Hello, i have multiple indexes with multiple documents grouped in a data view. For documents like {..., field1: value, field2: value, ...}, is there a way to get all documents for which at least one other document exis…

---

## [Which filter(s) to extract array of JSON values, then use array to look up nested JSON objects?](https://discuss.elastic.co/t/which-filter-s-to-extract-array-of-json-values-then-use-array-to-look-up-nested-json-objects/343814)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 11\
**Last updated:** [October 10, 2023, 3:08pm UTC](https://discuss.elastic.co/t/which-filter-s-to-extract-array-of-json-values-then-use-array-to-look-up-nested-json-objects/343814 "2023-10-10T15:08:32Z")

</div>

I have a Logstash pipeline which is processing JSON data from a flat file. The data is somewhat structured like this: { "name": "job1", "tasks": { "75fc": { "name": "restAction", "variables": { "incoming"…

---

## [Elastic-agent kubernetes-integration does not collect kubernetes metrics](https://discuss.elastic.co/t/elastic-agent-kubernetes-integration-does-not-collect-kubernetes-metrics/344749)

<div class="topic-metadata">

**Author:** [@tara](https://discuss.elastic.co/u/tara)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 3:05pm UTC](https://discuss.elastic.co/t/elastic-agent-kubernetes-integration-does-not-collect-kubernetes-metrics/344749 "2023-10-10T15:05:54Z")

</div>

Hello team, I have Elastic Agent deployed with ECK, but for some reason I don't get the kubernetes metrics. Instead I see this error in the logs: {"log.level":"info","@timestamp":"2023-10-10T14:55:42.666Z","message":"c…

---

## [I want to create a pipeline like Log files -\> FileBeat -\> Kafka -\> Logstash -\> Elastic -\> Kibana](https://discuss.elastic.co/t/i-want-to-create-a-pipeline-like-log-files-filebeat-kafka-logstash-elastic-kibana/344744)

<div class="topic-metadata">

**Author:** [@Pritam\_Bhirud](https://discuss.elastic.co/u/Pritam_Bhirud)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 2:20pm UTC](https://discuss.elastic.co/t/i-want-to-create-a-pipeline-like-log-files-filebeat-kafka-logstash-elastic-kibana/344744 "2023-10-10T14:20:24Z")

</div>

While sending data from Filebeat to Kafka, the server crashes continuously. While sending data from Kafka to Logstash, the server also crashes continuously. I have installed kafka in one VM (Ubuntu 22.04, 4GB RAM, 4 Co…

---

## [Does Kibana have a way to use a scroll option in dashboard/graphs(lens)?](https://discuss.elastic.co/t/does-kibana-have-a-way-to-use-a-scroll-option-in-dashboard-graphs-lens/344554)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [October 10, 2023, 2:17pm UTC](https://discuss.elastic.co/t/does-kibana-have-a-way-to-use-a-scroll-option-in-dashboard-graphs-lens/344554 "2023-10-10T14:17:51Z")

</div>

Hello, I was wondering how I can display a graph(lens) with time series data where I can drill down without distorting the wide view. A good example of what I want is this from Elastic ML: Not sure if that's availa…

---

## [Problem in data format during bulk insert in Elasticsearch using ElasticsearchClient in Java](https://discuss.elastic.co/t/problem-in-data-format-during-bulk-insert-in-elasticsearch-using-elasticsearchclient-in-java/344746)

<div class="topic-metadata">

**Author:** [@Sushobhan\_Mudi](https://discuss.elastic.co/u/Sushobhan_Mudi)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 1:55pm UTC](https://discuss.elastic.co/t/problem-in-data-format-during-bulk-insert-in-elasticsearch-using-elasticsearchclient-in-java/344746 "2023-10-10T13:55:00Z")

</div>

I am inserting JSON data in Elasticsearch using ElasticearchClient Bulk Insert in Java, the code I have written is static void submitBulkUsingElasticClient(JSONArray data) throws IOException { BulkRequest.Builde…

---

## [AWS Elastic Search update\_by\_query : Trying to create too many scroll contexts](https://discuss.elastic.co/t/aws-elastic-search-update-by-query-trying-to-create-too-many-scroll-contexts/344745)

<div class="topic-metadata">

**Author:** [@ankitpandoh](https://discuss.elastic.co/u/ankitpandoh)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 1:48pm UTC](https://discuss.elastic.co/t/aws-elastic-search-update-by-query-trying-to-create-too-many-scroll-contexts/344745 "2023-10-10T13:48:53Z")

</div>

I am getting below exception while running the update\_by\_query. We have been issuing this request to through Rest API (from our code) to OpensearchCluster in AWS. Initially it seems ok, but when we have a sudden burst o…

---

## [8.2.3 -\> 8.10 ; Breaking change on Elastic Cloud?](https://discuss.elastic.co/t/8-2-3-8-10-breaking-change-on-elastic-cloud/344743)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 1:33pm UTC](https://discuss.elastic.co/t/8-2-3-8-10-breaking-change-on-elastic-cloud/344743 "2023-10-10T13:33:04Z")

</div>

Hello, Actualy i have a deployment on Elastic Cloud in 8.2.3. I would like to uprgrade in 8.10. I was looking for breaking change into the \_migration/deprecations api, and I get 9 warning and 1 critical, all about my …

---

## [Send data from Elastic Agents through Logstash into ElasticSearch](https://discuss.elastic.co/t/send-data-from-elastic-agents-through-logstash-into-elasticsearch/344664)

<div class="topic-metadata">

**Author:** [@Gio\_27](https://discuss.elastic.co/u/Gio_27)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 1:29pm UTC](https://discuss.elastic.co/t/send-data-from-elastic-agents-through-logstash-into-elasticsearch/344664 "2023-10-10T13:29:29Z")

</div>

Hey everyone I have some Fleet-managed Elastic Agents deployed. I would like those agents to send data into logstash for filtering / enrichment and then from logstash to Elasticsearch. I found this piece of doc: Elastic…

---

## [Pre-built Dashboards Not Loading for Users Except Superuser](https://discuss.elastic.co/t/pre-built-dashboards-not-loading-for-users-except-superuser/344642)

<div class="topic-metadata">

**Author:** [@Ankur\_Mahajan](https://discuss.elastic.co/u/Ankur_Mahajan)\
**Replies:** 10\
**Last updated:** [October 10, 2023, 1:26pm UTC](https://discuss.elastic.co/t/pre-built-dashboards-not-loading-for-users-except-superuser/344642 "2023-10-10T13:26:50Z")

</div>

I have encountered an issue with certain pre-built dashboards in our system. These dashboards are failing to load for any users except the superuser. I have verified that all the required permissions are correctly assign…

---

## [NoClassDefFoundError: org/bouncycastle/asn1/ASN1Encodable - Missing ASN.1 Utility Classes](https://discuss.elastic.co/t/noclassdeffounderror-org-bouncycastle-asn1-asn1encodable-missing-asn-1-utility-classes/344734)

<div class="topic-metadata">

**Author:** [@Franco901](https://discuss.elastic.co/u/Franco901)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 12:32pm UTC](https://discuss.elastic.co/t/noclassdeffounderror-org-bouncycastle-asn1-asn1encodable-missing-asn-1-utility-classes/344734 "2023-10-10T12:32:41Z")

</div>

Hello there, I have a Nextcloud instance (V26) with an Elasticsearch V8.2.10 as full text search component. While indexing user data my ES node poorly died this morning with a missing class not found exception. It see…

---

## [Sliding Window Query in Elastic](https://discuss.elastic.co/t/sliding-window-query-in-elastic/344733)

<div class="topic-metadata">

**Author:** [@vignesh\_nayak](https://discuss.elastic.co/u/vignesh_nayak)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 12:26pm UTC](https://discuss.elastic.co/t/sliding-window-query-in-elastic/344733 "2023-10-10T12:26:12Z")

</div>

Hello, I have a log message which has an id, and it will be same for repeating requests. So I need to find repetitive requests from same id in a certain interval(ex:15min) , What would be the easiest way to achieve this,…

---

## [How to set in Discovery max\_analyzed\_offset as a default value?](https://discuss.elastic.co/t/how-to-set-in-discovery-max-analyzed-offset-as-a-default-value/344731)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 11:51am UTC](https://discuss.elastic.co/t/how-to-set-in-discovery-max-analyzed-offset-as-a-default-value/344731 "2023-10-10T11:51:51Z")

</div>

Hello. I have a problem with documents with over 10 mln characters. I'm getting max\_analyzed\_offset error. How can I set max\_analyzed\_offset as a default value so when I will be using Discovery i will not get any error…

---

## [Grok parser question (Invalid json string)](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730)

<div class="topic-metadata">

**Author:** [@superm0](https://discuss.elastic.co/u/superm0)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 11:46am UTC](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730 "2023-10-10T11:46:22Z")

</div>

Hi,please assit me with creating custom grok pattern . I've created custom pattern, it works perfectly in Grok Debugger. But i cant add this expression for parsing data: Error: Invalid Json string. %{SYSLOGTIMESTAMP:…

---

## [Wildcard not working](https://discuss.elastic.co/t/wildcard-not-working/344370)

<div class="topic-metadata">

**Author:** [@yash\_gehi](https://discuss.elastic.co/u/yash_gehi)\
**Replies:** 2\
**Last updated:** [October 10, 2023, 11:24am UTC](https://discuss.elastic.co/t/wildcard-not-working/344370 "2023-10-10T11:24:22Z")

</div>

{ "query":{ "wildcard":{ "id": "C0\*" } } } I'm trying to run a get request through postman using this as a json body. there is around 44k entries with this id. But when I run it I cannot see any data in my resp…

---

## [ECK and Platinum license](https://discuss.elastic.co/t/eck-and-platinum-license/344718)

<div class="topic-metadata">

**Author:** [@chriske](https://discuss.elastic.co/u/chriske)\
**Replies:** 2\
**Last updated:** [October 10, 2023, 11:05am UTC](https://discuss.elastic.co/t/eck-and-platinum-license/344718 "2023-10-10T11:05:07Z")

</div>

Hello! I would like to ask if, theoretically, I have a Platinum license and I want to use ECK (Elastic Cloud on Kubernetes), is it possible to run ECK with a basic license while activating the Platinum license for Elast…

---

## [1 index having two shards went unassigned, when we do the cluster explain we received below response. Request you to assist on this issue](https://discuss.elastic.co/t/1-index-having-two-shards-went-unassigned-when-we-do-the-cluster-explain-we-received-below-response-request-you-to-assist-on-this-issue/344725)

<div class="topic-metadata">

**Author:** [@Jefferson\_Lourthusam](https://discuss.elastic.co/u/Jefferson_Lourthusam)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 10:25am UTC](https://discuss.elastic.co/t/1-index-having-two-shards-went-unassigned-when-we-do-the-cluster-explain-we-received-below-response-request-you-to-assist-on-this-issue/344725 "2023-10-10T10:25:52Z")

</div>

{ "index" : "audit\_latestchargesave\_26112022", "shard" : 0, "primary" : true, "current\_state" : "unassigned", "unassigned\_info" : { "reason" : "NODE\_LEFT", "at" : "2023-07-17T20:07:51.278Z", "detail…

---

## [Multilined csv error while parsing](https://discuss.elastic.co/t/multilined-csv-error-while-parsing/344715)

<div class="topic-metadata">

**Author:** [@younes-gr](https://discuss.elastic.co/u/younes-gr)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 9:00am UTC](https://discuss.elastic.co/t/multilined-csv-error-while-parsing/344715 "2023-10-10T09:00:06Z")

</div>

I am trying to process a csv file containing logs from several applications. Containing 10 columns like shown in the mapping at the end. I run into errors while trying to parse it because the'field\_8\_request' that usual…

---

## [All pipelines shutdown after one is not working](https://discuss.elastic.co/t/all-pipelines-shutdown-after-one-is-not-working/344653)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 12\
**Last updated:** [October 10, 2023, 9:48am UTC](https://discuss.elastic.co/t/all-pipelines-shutdown-after-one-is-not-working/344653 "2023-10-10T09:48:35Z")

</div>

i have 2 pipelines one is for kafka and other one is for http when kafka is not working and logstash can not create connection to kafka it terminates http pipeline too i asked to chat gpt it said Run each pipeline as a…

---

## [Elasticsearch 7.17 index with alias - granting privileges best practice](https://discuss.elastic.co/t/elasticsearch-7-17-index-with-alias-granting-privileges-best-practice/344721)

<div class="topic-metadata">

**Author:** [@zvonimir](https://discuss.elastic.co/u/zvonimir)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 9:35am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-index-with-alias-granting-privileges-best-practice/344721 "2023-10-10T09:35:11Z")

</div>

Hi. What would be best practice for granting read security privileges on index with alias on Elasticsearch 7.17? Granting read privilege only on alias is deprecated but granting read privilege only on index isn't workin…

---

## [The problem when create HTTPS for elasticsearch](https://discuss.elastic.co/t/the-problem-when-create-https-for-elasticsearch/344708)

<div class="topic-metadata">

**Author:** [@Tai\_Nguyen\_Huu](https://discuss.elastic.co/u/Tai_Nguyen_Huu)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 8:37am UTC](https://discuss.elastic.co/t/the-problem-when-create-https-for-elasticsearch/344708 "2023-10-10T08:37:25Z")

</div>

Hi guys, I am having the problem with setup HTTPS for elasticsearch stack. I created certifacate with private key with one certificate for every node with command elasticsearch-certutil http I am understanding that. I…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=401)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=403)
