# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=408

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 409

---

## [Using script processor in elastic-agent integration](https://discuss.elastic.co/t/using-script-processor-in-elastic-agent-integration/342632)

<div class="topic-metadata">

**Author:** [@aaszxc](https://discuss.elastic.co/u/aaszxc)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 3:44pm UTC](https://discuss.elastic.co/t/using-script-processor-in-elastic-agent-integration/342632 "2023-10-03T15:44:52Z")

</div>

Need your help. I don't like that using kubernetes integration in elastic-agents we have one event\_dataset for all logs: kubernetes.container\_logs I would like to split it into several. In filebeat this can be done with…

---

## [Customize filebeat connections](https://discuss.elastic.co/t/customize-filebeat-connections/344239)

<div class="topic-metadata">

**Author:** [@yvangarc](https://discuss.elastic.co/u/yvangarc)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 3:28pm UTC](https://discuss.elastic.co/t/customize-filebeat-connections/344239 "2023-10-03T15:28:51Z")

</div>

Hello, We have been given a logstash endpoint, which goes against 2 replicas running on an infra of k8s. What we see is that there is no control of the logstash pod to which we connect, and that many times our clients e…

---

## [Problem when create index template](https://discuss.elastic.co/t/problem-when-create-index-template/344302)

<div class="topic-metadata">

**Author:** [@Joker\_Thanh](https://discuss.elastic.co/u/Joker_Thanh)\
**Replies:** 5\
**Last updated:** [October 3, 2023, 2:04pm UTC](https://discuss.elastic.co/t/problem-when-create-index-template/344302 "2023-10-03T14:04:38Z")

</div>

i have seen problem when create index template based endpoint /\_index/c1s-template { "error" : { "root\_cause" : \[ { "type" : "illegal\_argument\_exception", "reason" : "IOException while readin…

---

## [Trying to query on length of the nested field](https://discuss.elastic.co/t/trying-to-query-on-length-of-the-nested-field/343853)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 1:41pm UTC](https://discuss.elastic.co/t/trying-to-query-on-length-of-the-nested-field/343853 "2023-10-03T13:41:07Z")

</div>

Hi, i have a mapping for an index of field resume.profile.locations, which is an nested field Here, I need to perform a scripting query... I am getting error call no mapping for that field but, I gave a mapping for …

---

## [Can't delete index template](https://discuss.elastic.co/t/cant-delete-index-template/344310)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 3\
**Last updated:** [October 3, 2023, 1:18pm UTC](https://discuss.elastic.co/t/cant-delete-index-template/344310 "2023-10-03T13:18:43Z")

</div>

Using Kibana 8.8.1 and ES 8.8.1 I deleted an index template as follows and it was acknowledged: DELETE /\_index\_template/my\_template However, when I run the following the template is still there: GET /\_cat/templates?v …

---

## [Getting No mapping Error](https://discuss.elastic.co/t/getting-no-mapping-error/344283)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 12:20pm UTC](https://discuss.elastic.co/t/getting-no-mapping-error/344283 "2023-10-03T12:20:26Z")

</div>

Hii, I tried a lot of queries.. but, Its not works.. It through an error.. Can anyone try this Here is my mapping, PUT array\_sort { "mappings": { "properties": { "Skills": { "type": "nested", …

---

## [AWS S3 repository for snapshot/restore in elasticsearch](https://discuss.elastic.co/t/aws-s3-repository-for-snapshot-restore-in-elasticsearch/342503)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 11:24am UTC](https://discuss.elastic.co/t/aws-s3-repository-for-snapshot-restore-in-elasticsearch/342503 "2023-10-03T11:24:49Z")

</div>

I want to use AWS S3 bucket for Elasticsearch snapshot/restore of indices. I have read the official doc but I am unable to understand what all properties will be needed in my elasticsearch.yml file to connect to my S3 b…

---

## [Change the location of an existing snapshot repository](https://discuss.elastic.co/t/change-the-location-of-an-existing-snapshot-repository/344200)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 9:40am UTC](https://discuss.elastic.co/t/change-the-location-of-an-existing-snapshot-repository/344200 "2023-10-03T09:40:45Z")

</div>

I need to change the location of the repository: but when I do I get this error: we had to move the mountpoint for the shared disk...

---

## [EBS disk type for High traffic Elasticsearch Cluster](https://discuss.elastic.co/t/ebs-disk-type-for-high-traffic-elasticsearch-cluster/344244)

<div class="topic-metadata">

**Author:** [@SiorMeir](https://discuss.elastic.co/u/SiorMeir)\
**Replies:** 3\
**Last updated:** [October 3, 2023, 9:31am UTC](https://discuss.elastic.co/t/ebs-disk-type-for-high-traffic-elasticsearch-cluster/344244 "2023-10-03T09:31:15Z")

</div>

We encountered a dilemma during the setup of a new cluster of ES version 8 with Elastic Cloud for Kubernetes (EKS) operator on AWS with Elastic Block Storage (EBS) as the data hosting service. EBS offers different speci…

---

## [Looking for confirmation: we cannot use the watcher to 'just' generate reports](https://discuss.elastic.co/t/looking-for-confirmation-we-cannot-use-the-watcher-to-just-generate-reports/343728)

<div class="topic-metadata">

**Author:** [@mpjjonker](https://discuss.elastic.co/u/mpjjonker)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 9:19am UTC](https://discuss.elastic.co/t/looking-for-confirmation-we-cannot-use-the-watcher-to-just-generate-reports/343728 "2023-10-03T09:19:12Z")

</div>

My use case is to schedule reporting but NOT to e-mail them as attachment. On this page, there is an option to call the API using a script, of course we can do this, but than we have to find a scheduling solution outsi…

---

## [Setting min=max in ngram tokenizers](https://discuss.elastic.co/t/setting-min-max-in-ngram-tokenizers/344218)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 5\
**Last updated:** [October 3, 2023, 9:09am UTC](https://discuss.elastic.co/t/setting-min-max-in-ngram-tokenizers/344218 "2023-10-03T09:09:05Z")

</div>

The docs suggest setting min=max on ngrams - but this results in a very poor search experience. Assuming 3,3 and searching for "rough" you will never find "trough". Only if you search "tro", "rou" or any other 3 characte…

---

## [How to sory array type field using the length](https://discuss.elastic.co/t/how-to-sory-array-type-field-using-the-length/344210)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 8:59am UTC](https://discuss.elastic.co/t/how-to-sory-array-type-field-using-the-length/344210 "2023-10-03T08:59:59Z")

</div>

Hi, I want to create an index having with one array field.. Then, how can I give mapping for that array field which is available to sort using the length of that array. One more thing that it supports that the array hav…

---

## [How to embed kibana dashboard in html code?](https://discuss.elastic.co/t/how-to-embed-kibana-dashboard-in-html-code/343748)

<div class="topic-metadata">

**Author:** [@Jyoti\_Pandey](https://discuss.elastic.co/u/Jyoti_Pandey)\
**Replies:** 11\
**Last updated:** [October 3, 2023, 8:56am UTC](https://discuss.elastic.co/t/how-to-embed-kibana-dashboard-in-html-code/343748 "2023-10-03T08:56:29Z")

</div>

i paste the iframe code in any external site, kibana login page appears when i enter my username and password the login page just gets reloaded and asks for the username and password again. the same process is repeating …

---

## [Elasticsearch span\_multi query rewrite parameter getting same result for top\_terms\_n top\_terms\_boost\_n and top\_terms\_blended\_freqs\_n?](https://discuss.elastic.co/t/elasticsearch-span-multi-query-rewrite-parameter-getting-same-result-for-top-terms-n-top-terms-boost-n-and-top-terms-blended-freqs-n/344295)

<div class="topic-metadata">

**Author:** [@Naman\_Mahor](https://discuss.elastic.co/u/Naman_Mahor)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 8:34am UTC](https://discuss.elastic.co/t/elasticsearch-span-multi-query-rewrite-parameter-getting-same-result-for-top-terms-n-top-terms-boost-n-and-top-terms-blended-freqs-n/344295 "2023-10-03T08:34:01Z")

</div>

I m trying below query with "explain": true on million of articles. but top\_terms, top\_terms\_boost and top\_terms\_blended\_freqs returning me the same result. "query": { "span\_multi": { "match": { "pref…

---

## [Port configured for logstash does not turn up (5044)](https://discuss.elastic.co/t/port-configured-for-logstash-does-not-turn-up-5044/344213)

<div class="topic-metadata">

**Author:** [@Manula\_Manjitha](https://discuss.elastic.co/u/Manula_Manjitha)\
**Replies:** 13\
**Last updated:** [October 3, 2023, 8:11am UTC](https://discuss.elastic.co/t/port-configured-for-logstash-does-not-turn-up-5044/344213 "2023-10-03T08:11:14Z")

</div>

I have configured a logstash on my server and the configurations in /etc/logstash/conf.d/beats.conf file are as follows. input { beats { port =\> 5044 host =\> "192.168.14.189" } } filter { if \[type\] =="sy…

---

## [Getting the facets info using search API facets](https://discuss.elastic.co/t/getting-the-facets-info-using-search-api-facets/344289)

<div class="topic-metadata">

**Author:** [@Aswanth\_Parambath](https://discuss.elastic.co/u/Aswanth_Parambath)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 7:35am UTC](https://discuss.elastic.co/t/getting-the-facets-info-using-search-api-facets/344289 "2023-10-03T07:35:41Z")

</div>

I have data in the format { field1:"data", field2 :{ innerField1 : "data2", innerField2: "data3" } } i want to implement the facets with search AP…

---

## [Kibana discover chart section not showing correct time](https://discuss.elastic.co/t/kibana-discover-chart-section-not-showing-correct-time/344201)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 4\
**Last updated:** [October 3, 2023, 7:04am UTC](https://discuss.elastic.co/t/kibana-discover-chart-section-not-showing-correct-time/344201 "2023-10-03T07:04:38Z")

</div>

good day, my script in the backend/source server is running hourly. The behavior of my script will run every hour to capture the previous hour count. my concern is this discover chart (green bar) why it is showing 0800 …

---

## [Can't create API role for Gitlab Advanced Search](https://discuss.elastic.co/t/cant-create-api-role-for-gitlab-advanced-search/344131)

<div class="topic-metadata">

**Author:** [@Oscar\_Yerpes](https://discuss.elastic.co/u/Oscar_Yerpes)\
**Replies:** 2\
**Last updated:** [October 3, 2023, 5:42am UTC](https://discuss.elastic.co/t/cant-create-api-role-for-gitlab-advanced-search/344131 "2023-10-03T05:42:54Z")

</div>

Hi all, As a part of enabling Gitlab Advanced Search using Elastic as a backend, I need to create a role in Elastic. Elastic API returns this error message when doing GET or POST actions: GET \_security/role { "error…

---

## [Little bit confused on min\_age parameter in ilm](https://discuss.elastic.co/t/little-bit-confused-on-min-age-parameter-in-ilm/299049)

<div class="topic-metadata">

**Author:** [@gokulnath112](https://discuss.elastic.co/u/gokulnath112)\
**Replies:** 4\
**Last updated:** [October 3, 2023, 4:12am UTC](https://discuss.elastic.co/t/little-bit-confused-on-min-age-parameter-in-ilm/299049 "2023-10-03T04:12:36Z")

</div>

Greetings...! Im currently using below ilm policy for my project. I just want to know the life span of an index. PUT \_ilm/policy/hot\_warm\_delete { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { "…

---

## [Logstash Upgrade and 8.10.1 net snmp error](https://discuss.elastic.co/t/logstash-upgrade-and-8-10-1-net-snmp-error/343307)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 6\
**Last updated:** [October 3, 2023, 1:39am UTC](https://discuss.elastic.co/t/logstash-upgrade-and-8-10-1-net-snmp-error/343307 "2023-10-03T01:39:51Z")

</div>

After the upgrade logstash doesn't start Any else experience this? Thank you! org.jruby.exceptions.LoadError: (LoadError) no such file to load -- net/smtp at org.jruby.RubyKernel.require(org/jruby/RubyKernel.java:1057)…

---

## [What are the use cases of EQL in elasticsearch?](https://discuss.elastic.co/t/what-are-the-use-cases-of-eql-in-elasticsearch/343554)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 9:56pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-of-eql-in-elasticsearch/343554 "2023-10-02T21:56:53Z")

</div>

What are the use cases of EQL in elasticsearch , Please explain with example ?

---

## [Can we Pin Column in Lens Table Visualization?](https://discuss.elastic.co/t/can-we-pin-column-in-lens-table-visualization/343534)

<div class="topic-metadata">

**Author:** [@ArpithaS](https://discuss.elastic.co/u/ArpithaS)\
**Replies:** 1\
**Last updated:** [October 2, 2023, 9:50pm UTC](https://discuss.elastic.co/t/can-we-pin-column-in-lens-table-visualization/343534 "2023-10-02T21:50:40Z")

</div>

i have created a table viz using Lens . Can i hide only the column headings in kibana version 7.14? and Pin the first column ?

---

## [No modules or inputs enabled - GCP vpcflow](https://discuss.elastic.co/t/no-modules-or-inputs-enabled-gcp-vpcflow/344246)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 7\
**Last updated:** [October 2, 2023, 9:21pm UTC](https://discuss.elastic.co/t/no-modules-or-inputs-enabled-gcp-vpcflow/344246 "2023-10-02T21:21:54Z")

</div>

hey there, I am really confused about the correct configuration of Filebeat v8.8.1 GCP module. I need to enable the vpcflow module, so I configured the gcp.yml file in this way: - module: gcp vpcflow: enabled: t…

---

## [Elasticsearch 8.9.1 indexing bottleneck on i3.2xlarge and d3.2xlarge nodes in EKS using ECK](https://discuss.elastic.co/t/elasticsearch-8-9-1-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks-using-eck/342001)

<div class="topic-metadata">

**Author:** [@Chris\_Austin](https://discuss.elastic.co/u/Chris_Austin)\
**Replies:** 10\
**Last updated:** [October 2, 2023, 8:09pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-1-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks-using-eck/342001 "2023-10-02T20:09:08Z")

</div>

Last May I asked a similar question about performance in 7.17.10, but ran out of things to try and the discussion was auto-closed due to inactivity. I'll avoid repeating the same context info from that post (the initial …

---

## [Error adding a 4th node to existing ES cluster](https://discuss.elastic.co/t/error-adding-a-4th-node-to-existing-es-cluster/344252)

<div class="topic-metadata">

**Author:** [@Bolmar](https://discuss.elastic.co/u/Bolmar)\
**Replies:** 0\
**Last updated:** [October 2, 2023, 6:02pm UTC](https://discuss.elastic.co/t/error-adding-a-4th-node-to-existing-es-cluster/344252 "2023-10-02T18:02:51Z")

</div>

ERROR: Skipping security auto configuration because this node is configured to bootstrap or to join a multi-node cluster, which is not supported. Steps for joining 4th node (First approach): Extract ES software (elast…

---

## [Multiple TCP output plugins in Logstash](https://discuss.elastic.co/t/multiple-tcp-output-plugins-in-logstash/344204)

<div class="topic-metadata">

**Author:** [@Mano](https://discuss.elastic.co/u/Mano)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 3:37pm UTC](https://discuss.elastic.co/t/multiple-tcp-output-plugins-in-logstash/344204 "2023-10-02T15:37:07Z")

</div>

Hi, I am planning to send logs to 2 different servers over TCP. My output section looks looks something like, output { tcp { host =\> "XX.X.XXX.XXX" #ip address of server 1 m…

---

## [Connecting metricbeat to elasticsearch using ssl connection](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121)

<div class="topic-metadata">

**Author:** [@website](https://discuss.elastic.co/u/website)\
**Replies:** 5\
**Last updated:** [October 2, 2023, 2:42pm UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121 "2023-10-02T14:42:36Z")

</div>

Good afternoon, can you help with connecting metricbeat to elasticsearch wazuh The file /etc/elasticsearch/elasticsearch.yml looks like this: network.host: 0.0.0.0 node.name: elasticsearch cluster.initial\_master\_nodes:…

---

## [Unable to authenticate user \[kibana\_system\]](https://discuss.elastic.co/t/unable-to-authenticate-user-kibana-system/344192)

<div class="topic-metadata">

**Author:** [@MdRashid](https://discuss.elastic.co/u/MdRashid)\
**Replies:** 8\
**Last updated:** [October 2, 2023, 2:41pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-kibana-system/344192 "2023-10-02T14:41:53Z")

</div>

Hi, Error "type":"log","@timestamp":"2023-10-01T18:33:17+00:00","tags":\["info","plugins-service"\],"pid":1219,"message":"Plugin \\"metricsEntities\\" is disabled."} {"type":"log","@timestamp":"2023-10-01T18:33:17+00:00","…

---

## [Migrating HLRC IndexLifecycleClient to ES:8.8.1](https://discuss.elastic.co/t/migrating-hlrc-indexlifecycleclient-to-es-8-8-1/344236)

<div class="topic-metadata">

**Author:** [@UP2711](https://discuss.elastic.co/u/UP2711)\
**Replies:** 0\
**Last updated:** [October 2, 2023, 2:38pm UTC](https://discuss.elastic.co/t/migrating-hlrc-indexlifecycleclient-to-es-8-8-1/344236 "2023-10-02T14:38:31Z")

</div>

I'm in the process of migrating from Elasticsearch version 7.17.0 to version 8.8.1. In my existing code, I'm using the High-Level Rest Client (HLRC) to manage Index Lifecycle Policies. However, in Elasticsearch version 8…

---

## [Elastic search key, password encryption](https://discuss.elastic.co/t/elastic-search-key-password-encryption/344230)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 1\
**Last updated:** [October 2, 2023, 2:32pm UTC](https://discuss.elastic.co/t/elastic-search-key-password-encryption/344230 "2023-10-02T14:32:15Z")

</div>

is it possible to use a encrypted key between client and elasticsearch? i know the question is not very clear because i have little knowledge about the topic. What i need is a encryption system between the people who s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=407)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=409)
