# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=410

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 411

---

## [I see this error in logstash-plain.log](https://discuss.elastic.co/t/i-see-this-error-in-logstash-plain-log/344082)

<div class="topic-metadata">

**Author:** [@Mostafa\_Faridi](https://discuss.elastic.co/u/Mostafa_Faridi)\
**Replies:** 23\
**Last updated:** [September 30, 2023, 10:35am UTC](https://discuss.elastic.co/t/i-see-this-error-in-logstash-plain-log/344082 "2023-09-30T10:35:33Z")

</div>

I installed elastcisearch 8.10.20 and kibana 810.2 and logstash 8.10.2 and filebeat 10.8.2 RPM on my oracle Linux, everything is running and I can login to kibana dashboard after adding token and username and password, b…

---

## [Remote Ubuntu installation: no automatic security configuration](https://discuss.elastic.co/t/remote-ubuntu-installation-no-automatic-security-configuration/344162)

<div class="topic-metadata">

**Author:** [@sandbender](https://discuss.elastic.co/u/sandbender)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 10:28pm UTC](https://discuss.elastic.co/t/remote-ubuntu-installation-no-automatic-security-configuration/344162 "2023-09-29T22:28:17Z")

</div>

Hello, I'm trying to remotely install Elasticsearch and Kibana on an Ubuntu 22.04.3 LTS server as described in the Elasticsearch Guide. Unfortunately the automatic security configuration during install does simply not h…

---

## [Ingest pipeline not finding field](https://discuss.elastic.co/t/ingest-pipeline-not-finding-field/344144)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 7\
**Last updated:** [September 29, 2023, 10:08pm UTC](https://discuss.elastic.co/t/ingest-pipeline-not-finding-field/344144 "2023-09-29T22:08:26Z")

</div>

Hi there, When I test my ingest pipeline, which replaces a delimiter with a whitespace, with a document that has the exact field I'm trying to transform, I keep getting this error: \[Field \[field\] not present as part of …

---

## [Pipeline not able to connect to MySQL Aurora Database usine useSSL=True](https://discuss.elastic.co/t/pipeline-not-able-to-connect-to-mysql-aurora-database-usine-usessl-true/344152)

<div class="topic-metadata">

**Author:** [@Ritesh\_Uniyal](https://discuss.elastic.co/u/Ritesh_Uniyal)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 4:58pm UTC](https://discuss.elastic.co/t/pipeline-not-able-to-connect-to-mysql-aurora-database-usine-usessl-true/344152 "2023-09-29T16:58:11Z")

</div>

We have a pipeline that connects to db Mysql aurora. We have enabled ssl on db and its failing to connect. We have tried using both verifyServerCertificate=true&useSSL=true&requireSSL=true and useSSL=true&requireSSL=true&…

---

## [Request/timeline for updating Iron Bank UBI Base Image from 8.6 to 8.8](https://discuss.elastic.co/t/request-timeline-for-updating-iron-bank-ubi-base-image-from-8-6-to-8-8/344150)

<div class="topic-metadata">

**Author:** [@Lemongarbage](https://discuss.elastic.co/u/Lemongarbage)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 3:59pm UTC](https://discuss.elastic.co/t/request-timeline-for-updating-iron-bank-ubi-base-image-from-8-6-to-8-8/344150 "2023-09-29T15:59:58Z")

</div>

Hello, I am wondering if there is an effort to upgrade the base image used for the Iron Bank Elasticsearch image from UBI 8.6 to UBI 8.8. Thank you

---

## [Connector for Elastic Search 8.6.2 and databricks spark 3.4.0](https://discuss.elastic.co/t/connector-for-elastic-search-8-6-2-and-databricks-spark-3-4-0/342746)

<div class="topic-metadata">

**Author:** [@luckymishra](https://discuss.elastic.co/u/luckymishra)\
**Replies:** 8\
**Last updated:** [September 29, 2023, 3:53pm UTC](https://discuss.elastic.co/t/connector-for-elastic-search-8-6-2-and-databricks-spark-3-4-0/342746 "2023-09-29T15:53:14Z")

</div>

I am trying to connect Elastic Search using spark in data bricks but keep getting this error org.elasticsearch.hadoop.EsHadoopIllegalArgumentException: Cannot detect ES version - typically this happens if the network/Ela…

---

## [Packetbeat's tls report has not bytes\_out field](https://discuss.elastic.co/t/packetbeats-tls-report-has-not-bytes-out-field/344145)

<div class="topic-metadata">

**Author:** [@hansc](https://discuss.elastic.co/u/hansc)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 3:28pm UTC](https://discuss.elastic.co/t/packetbeats-tls-report-has-not-bytes-out-field/344145 "2023-09-29T15:28:56Z")

</div>

I have packetbeat 8.10.2 installed in Debian 11. The protocols configurations are - type: http ports: \[80, 8080, 8000, 18083\] - type: tls ports: - 443 # HTTPS I am successfully see the bytes\_in and bytes\_o…

---

## [Swagger implementation in Kibana custom pluggin](https://discuss.elastic.co/t/swagger-implementation-in-kibana-custom-pluggin/344141)

<div class="topic-metadata">

**Author:** [@Lilia](https://discuss.elastic.co/u/Lilia)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 2:52pm UTC](https://discuss.elastic.co/t/swagger-implementation-in-kibana-custom-pluggin/344141 "2023-09-29T14:52:12Z")

</div>

Hi all, I'm trying to implement swagger as a tool in my front-end kibana custom pluggin, but i keep getting error that i need appropriate loader to handle file types which needs to be done in a webpack file, have anyone…

---

## [Logstash wrapping the data with document](https://discuss.elastic.co/t/logstash-wrapping-the-data-with-document/344135)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 4\
**Last updated:** [September 29, 2023, 1:25pm UTC](https://discuss.elastic.co/t/logstash-wrapping-the-data-with-document/344135 "2023-09-29T13:25:13Z")

</div>

I'm sending data with python on both kafka and http request however kafka pipeline wraps the data with "document". the data on the top is coming from kafka pipeline and the below from http pipeline And these are my…

---

## [Action \[indices:admin/create\] is unauthorized for user](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990)

<div class="topic-metadata">

**Author:** [@brunoflament](https://discuss.elastic.co/u/brunoflament)\
**Replies:** 5\
**Last updated:** [September 29, 2023, 12:59pm UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990 "2023-09-29T12:59:06Z")

</div>

Hi, I try to create a index but i have this error : PUT toto-1 ( curl -k -u "logstash:password" -X PUT "https://localhost:9200/toto-1) {"error":{"root\_cause":\[{"type":"security\_exception","reason":"action \[indices:adm…

---

## [Filtering elastic search results based on score](https://discuss.elastic.co/t/filtering-elastic-search-results-based-on-score/344136)

<div class="topic-metadata">

**Author:** [@mreddy9](https://discuss.elastic.co/u/mreddy9)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 12:30pm UTC](https://discuss.elastic.co/t/filtering-elastic-search-results-based-on-score/344136 "2023-09-29T12:30:16Z")

</div>

Hi All, I'm using the following c# code to query the elastic and trying to filter the results which has less than 50% score but it still returning all results which has score more than 50%. Please help to resolve this i…

---

## [Failed to parse field \[document.error\] of type \[text\] in document](https://discuss.elastic.co/t/failed-to-parse-field-document-error-of-type-text-in-document/344108)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 5\
**Last updated:** [September 29, 2023, 12:19pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-document-error-of-type-text-in-document/344108 "2023-09-29T12:19:35Z")

</div>

I'm sending data to logstash through kafka python client. this is the object i send {"user\_id":"kafka12","service\_name":"kafka12","activity\_type":"kafka","error":{"message":"Invalid username","component\_id":"Y456"},"add…

---

## [Elastic deleted documents](https://discuss.elastic.co/t/elastic-deleted-documents/344097)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 6\
**Last updated:** [September 29, 2023, 12:10pm UTC](https://discuss.elastic.co/t/elastic-deleted-documents/344097 "2023-09-29T12:10:21Z")

</div>

All the documents which are ingested by logstash are deleted automatically. Please find the screen shot. I do not have any ISM policy to delete document. Any help!

---

## [Getting the following erro when trying to filter by the threat enrcihements matched field](https://discuss.elastic.co/t/getting-the-following-erro-when-trying-to-filter-by-the-threat-enrcihements-matched-field/344127)

<div class="topic-metadata">

**Author:** [@geekzy](https://discuss.elastic.co/u/geekzy)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 10:39am UTC](https://discuss.elastic.co/t/getting-the-following-erro-when-trying-to-filter-by-the-threat-enrcihements-matched-field/344127 "2023-09-29T10:39:35Z")

</div>

I am trying to filter by the following KQL query in the GUI: "threat.enrichments.matched.field: source.ip" However I get the following error: "threat.enrichments.matched.field is a nested field, but is not in a nested…

---

## [Metricbeat non-positive interval for NewTicker](https://discuss.elastic.co/t/metricbeat-non-positive-interval-for-newticker/344122)

<div class="topic-metadata">

**Author:** [@gergelyzsamboki-seon](https://discuss.elastic.co/u/gergelyzsamboki-seon)\
**Replies:** 1\
**Last updated:** [September 29, 2023, 10:28am UTC](https://discuss.elastic.co/t/metricbeat-non-positive-interval-for-newticker/344122 "2023-09-29T10:28:26Z")

</div>

hi. i'm trying to monitor a logstash cluster with metricbeat and logstash-xpack module. However after starting metricbeat, one datapoint is logged into elasticsearch, then an error is logged saying non-negative interval …

---

## [Unable to verify the first certificate on postman](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 3\
**Last updated:** [September 29, 2023, 9:22am UTC](https://discuss.elastic.co/t/unable-to-verify-the-first-certificate-on-postman/344071 "2023-09-29T09:22:52Z")

</div>

Hi I've setup a Elastic and Kibana instance on Windows server Both instances are secured with LetsEncrypt certificate. When I try to use the elasticsearch API on POSTMAN i get the "Unable to verify the first certificate…

---

## [Usecase product list filter in E-commerce web app](https://discuss.elastic.co/t/usecase-product-list-filter-in-e-commerce-web-app/344116)

<div class="topic-metadata">

**Author:** [@hieuneo](https://discuss.elastic.co/u/hieuneo)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 8:14am UTC](https://discuss.elastic.co/t/usecase-product-list-filter-in-e-commerce-web-app/344116 "2023-09-29T08:14:03Z")

</div>

Hello everyone, I have a usecase and hope you can help me find a solution I have a Product index, with fields brandId and categoryId,..., I need to filter by many brandId and many categoryId and aggregate by brandId and…

---

## [Version conflict issue while updating data continously](https://discuss.elastic.co/t/version-conflict-issue-while-updating-data-continously/344065)

<div class="topic-metadata">

**Author:** [@bhumika](https://discuss.elastic.co/u/bhumika)\
**Replies:** 8\
**Last updated:** [September 29, 2023, 7:50am UTC](https://discuss.elastic.co/t/version-conflict-issue-while-updating-data-continously/344065 "2023-09-29T07:50:19Z")

</div>

Describe the bug/error/problem I am getting this error sometimes while updating the index of user. "error": "\[409\] {"error":{"root\_cause":\[{"type":"version\_conflict\_engine\_exception","reason":"\[2568\]: version conflict,…

---

## [Could not find logstash.yml](https://discuss.elastic.co/t/could-not-find-logstash-yml/343776)

<div class="topic-metadata">

**Author:** [@atulrana20](https://discuss.elastic.co/u/atulrana20)\
**Replies:** 16\
**Last updated:** [September 29, 2023, 7:29am UTC](https://discuss.elastic.co/t/could-not-find-logstash-yml/343776 "2023-09-29T07:29:50Z")

</div>

WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults Could not find log4j2 configuration at p…

---

## [Getting wrong method GET for \_ssl/certificates ES 7.17](https://discuss.elastic.co/t/getting-wrong-method-get-for-ssl-certificates-es-7-17/343811)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 7\
**Last updated:** [September 29, 2023, 6:54am UTC](https://discuss.elastic.co/t/getting-wrong-method-get-for-ssl-certificates-es-7-17/343811 "2023-09-29T06:54:17Z")

</div>

Has anyone seen this? It works fine on my 8.x clusters ... # curl -X GET "localhost:9200/\_ssl/certificates?pretty" { "error" : "Incorrect HTTP method for uri \[/\_ssl/certificates?pretty\] and method \[GET\], allowed: \[PO…

---

## [What Node to I point to](https://discuss.elastic.co/t/what-node-to-i-point-to/344096)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 4\
**Last updated:** [September 29, 2023, 3:41am UTC](https://discuss.elastic.co/t/what-node-to-i-point-to/344096 "2023-09-29T03:41:14Z")

</div>

I have a cluster with 3 x Master, 4 x Hot, 4 x Warm and 2 x Ingest. With Kibana and when I want to send data to the cluster, what is the recommended set of nodes to point to? Is it just the Masters, Hot or Warm nodes o…

---

## [Change node hostname](https://discuss.elastic.co/t/change-node-hostname/338312)

<div class="topic-metadata">

**Author:** [@cesar.hernandez.a3se](https://discuss.elastic.co/u/cesar.hernandez.a3se)\
**Replies:** 7\
**Last updated:** [September 29, 2023, 3:19am UTC](https://discuss.elastic.co/t/change-node-hostname/338312 "2023-09-29T03:19:50Z")

</div>

Hi We have a 7 node ES cluster (v7.17.5) and we need to change the hostnames of all nodes. I know how to do it on Linux, but, is there anything I need to change on Elasticsearch? My elasticsearch.yml uses ip address (n…

---

## [Having trouble adding muliple tables using logstash](https://discuss.elastic.co/t/having-trouble-adding-muliple-tables-using-logstash/344020)

<div class="topic-metadata">

**Author:** [@Mustapha\_Hadj](https://discuss.elastic.co/u/Mustapha_Hadj)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 11:30pm UTC](https://discuss.elastic.co/t/having-trouble-adding-muliple-tables-using-logstash/344020 "2023-09-28T23:30:01Z")

</div>

so i have 7 tables in my sql database and i'v been trying to add all of them to an index trough logstash jdbc using a query file , the query goes somthing like SELECT \* FROM \[TABLE\]; SELECT \* FROM \[TABLE\]; SELECT \* FR…

---

## [How to boost scoring for whole word hits over substring hits](https://discuss.elastic.co/t/how-to-boost-scoring-for-whole-word-hits-over-substring-hits/344095)

<div class="topic-metadata">

**Author:** [@cookersjs](https://discuss.elastic.co/u/cookersjs)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 12:38am UTC](https://discuss.elastic.co/t/how-to-boost-scoring-for-whole-word-hits-over-substring-hits/344095 "2023-09-29T00:38:30Z")

</div>

Hi there, I'd like to make it so that single-word query results that contain the entire query word by itself get higher scoring over results that contain the query word within another word. For example in the case I am…

---

## [Winlogbeat stop and start services](https://discuss.elastic.co/t/winlogbeat-stop-and-start-services/343282)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 9:43pm UTC](https://discuss.elastic.co/t/winlogbeat-stop-and-start-services/343282 "2023-09-28T21:43:37Z")

</div>

Hi, We are having issues stoping and starting winlogbeat agent. It eventually timeouts . Process kill seems ok.Is there any known issue around this? We are just using Powershell scrip to stop and start the service. Sec…

---

## [What is the correct way to insert document in elastic search using multiple documents using multiple threads in c#](https://discuss.elastic.co/t/what-is-the-correct-way-to-insert-document-in-elastic-search-using-multiple-documents-using-multiple-threads-in-c/343711)

<div class="topic-metadata">

**Author:** [@mreddy9](https://discuss.elastic.co/u/mreddy9)\
**Replies:** 5\
**Last updated:** [September 28, 2023, 9:41pm UTC](https://discuss.elastic.co/t/what-is-the-correct-way-to-insert-document-in-elastic-search-using-multiple-documents-using-multiple-threads-in-c/343711 "2023-09-28T21:41:14Z")

</div>

Hi All, I'm using multiple threads in c# to isert documents in c# as below but some times document is not inserted into elstic search search. var indexResponse = elasticClient.IndexDocument(testReport); But if I try t…

---

## [Duplicates after index rollover](https://discuss.elastic.co/t/duplicates-after-index-rollover/344084)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 16\
**Last updated:** [September 28, 2023, 6:49pm UTC](https://discuss.elastic.co/t/duplicates-after-index-rollover/344084 "2023-09-28T18:49:49Z")

</div>

Good afternoon. The problem that I am going to comment is a common problem but I do not know if elastic has already given a solution. We have an api ingest via logstash that we have to attack it 7 days ago because thro…

---

## [Able to access Elastic and Kibana in localhost but not outside](https://discuss.elastic.co/t/able-to-access-elastic-and-kibana-in-localhost-but-not-outside/344083)

<div class="topic-metadata">

**Author:** [@Yue\_CHEN](https://discuss.elastic.co/u/Yue_CHEN)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 6:42pm UTC](https://discuss.elastic.co/t/able-to-access-elastic-and-kibana-in-localhost-but-not-outside/344083 "2023-09-28T18:42:49Z")

</div>

New to Elastic search, set up new instance in azure windows vm. Able to access Elastic and Kibana in localhost but not outside for some reason. Here are settings from Elastic.yml network.host: 10.x.x.x is private IP a…

---

## [How to change specialized data node role to generic data node role](https://discuss.elastic.co/t/how-to-change-specialized-data-node-role-to-generic-data-node-role/344089)

<div class="topic-metadata">

**Author:** [@Hemanth\_Gowda](https://discuss.elastic.co/u/Hemanth_Gowda)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 5:57pm UTC](https://discuss.elastic.co/t/how-to-change-specialized-data-node-role-to-generic-data-node-role/344089 "2023-09-28T17:57:04Z")

</div>

Hi, We have 5 data nodes with below node roles as shown below. All data nodes are allocated with 2 TB of storage. We are seeing high storage usage on node1 and node2 due to specific specialized data roles defined to nod…

---

## [BucketSelectorPipelineAggregationBuilder missing from elasticsearch 8.9.2](https://discuss.elastic.co/t/bucketselectorpipelineaggregationbuilder-missing-from-elasticsearch-8-9-2/344067)

<div class="topic-metadata">

**Author:** [@rishavgu](https://discuss.elastic.co/u/rishavgu)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 4:30pm UTC](https://discuss.elastic.co/t/bucketselectorpipelineaggregationbuilder-missing-from-elasticsearch-8-9-2/344067 "2023-09-28T16:30:16Z")

</div>

We are upgrading our Elasticsearch from 8.5.3 to 8.9.2 and our migration is failing with following error: Cannot resolve symbol 'BucketSelectorPipelineAggregationBuilder' Seems like in 8.9.2 this class file has been rem…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=409)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=411)
