# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=413

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 414

---

## [Term query by \_id very slow (30s+) occasionally](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305)

<div class="topic-metadata">

**Author:** [@May\_Zeng](https://discuss.elastic.co/u/May_Zeng)\
**Replies:** 20\
**Last updated:** [September 26, 2023, 8:10pm UTC](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305 "2023-09-26T20:10:48Z")

</div>

Mapping: { "dynamic": "strict", "\_source": { "enabled": false }, "properties": { "data": { "type": "binary", "doc\_values": false, "store": true } } } Query: {"query":{ "bool" …

---

## [Easy way to parse flattened data type?](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:59pm UTC](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926 "2023-09-26T19:59:21Z")

</div>

While I understand the reasoning behind the flattened data type, is there an easy way to split key value pairs out as their own field to use with dashboards / aggregations etc. IE - m365\_defender.event.activity.objects …

---

## [How to close co.elastic.clients.elasticsearch.ElasticsearchClient](https://discuss.elastic.co/t/how-to-close-co-elastic-clients-elasticsearch-elasticsearchclient/343922)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 7:55pm UTC](https://discuss.elastic.co/t/how-to-close-co-elastic-clients-elasticsearch-elasticsearchclient/343922 "2023-09-26T19:55:55Z")

</div>

The HLRC client had a .close() method. Can anyone tell me the correct way to close the new client? Thanks.

---

## [What field shows sign-in due to app or hardware token?](https://discuss.elastic.co/t/what-field-shows-sign-in-due-to-app-or-hardware-token/343925)

<div class="topic-metadata">

**Author:** [@BabyElkUser](https://discuss.elastic.co/u/BabyElkUser)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:49pm UTC](https://discuss.elastic.co/t/what-field-shows-sign-in-due-to-app-or-hardware-token/343925 "2023-09-26T19:49:16Z")

</div>

I'm in Filebeat and am hoping that someone can please help me find the field that holds the information as to whether someone is signing in with an app, like the MFA app, or with a hardware token. This is getting me all…

---

## [Elasticsearch index has multiple document ids](https://discuss.elastic.co/t/elasticsearch-index-has-multiple-document-ids/343923)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 7:36pm UTC](https://discuss.elastic.co/t/elasticsearch-index-has-multiple-document-ids/343923 "2023-09-26T19:36:59Z")

</div>

Hi. I am using Logstash / Elasticsearch (8.5.3) and am indexing json data. In logstash I use http input plugin, filter plugins and elasticsearch output. Currently the auto generated @version field in logstash filter i…

---

## [Not eligible for data streams because config contains one or more settings that are not compatible with data streams: {"index"=\>"logstash-%{+YYYY.MM.dd}"}](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams-index-logstash-yyyy-mm-dd/343803)

<div class="topic-metadata">

**Author:** [@Dinoo](https://discuss.elastic.co/u/Dinoo)\
**Replies:** 7\
**Last updated:** [September 26, 2023, 7:13pm UTC](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams-index-logstash-yyyy-mm-dd/343803 "2023-09-26T19:13:13Z")

</div>

Hi, I am working on the ELK stack using Docker compose. I am following this tutorial: Getting started with the Elastic Stack and Docker-Compose | Elastic Blog. Everything works except Logstash. When I run docker-compose …

---

## [Elastic agent dropwizard configuration](https://discuss.elastic.co/t/elastic-agent-dropwizard-configuration/343920)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 6:48pm UTC](https://discuss.elastic.co/t/elastic-agent-dropwizard-configuration/343920 "2023-09-26T18:48:37Z")

</div>

Does elastic agent support dropwizard configuration ? I couldn't find any documentation on how to enable dropwizard configuration using elastic agent. I am running elastic agent in kubernetes, and would like to know ho…

---

## [Downgrade from ES 8.10.1 TO 8.9.2](https://discuss.elastic.co/t/downgrade-from-es-8-10-1-to-8-9-2/343919)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 6:22pm UTC](https://discuss.elastic.co/t/downgrade-from-es-8-10-1-to-8-9-2/343919 "2023-09-26T18:22:49Z")

</div>

I would like to upgrade my ES to 8.10.1, i want to have the option to downgrade if tests fails. i did my search and did not find any breaking change between 8.9 to 8.10, wanted to confirm is downgrade is possible. ex., …

---

## [Restrict nested data in result of search](https://discuss.elastic.co/t/restrict-nested-data-in-result-of-search/343918)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 5:38pm UTC](https://discuss.elastic.co/t/restrict-nested-data-in-result-of-search/343918 "2023-09-26T17:38:21Z")

</div>

I have a index that stores tasks to do, in it there is a user id, task id and inside there is nested data that is used to store a timer that the user started and finished working on a task. I have a script that I used i…

---

## [Indexing Subtitles and Maintaining Timestamps](https://discuss.elastic.co/t/indexing-subtitles-and-maintaining-timestamps/343708)

<div class="topic-metadata">

**Author:** [@ADarkDividedGem](https://discuss.elastic.co/u/ADarkDividedGem)\
**Replies:** 7\
**Last updated:** [September 26, 2023, 5:32pm UTC](https://discuss.elastic.co/t/indexing-subtitles-and-maintaining-timestamps/343708 "2023-09-26T17:32:00Z")

</div>

I am wanting to index subtitles and also maintain the timestamp data. My initial thought was to make each line of text a document with the start and end timestamps stored as fields for that document. For example the fol…

---

## [Error when querying Elasticsearch from Logstash](https://discuss.elastic.co/t/error-when-querying-elasticsearch-from-logstash/343907)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:19pm UTC](https://discuss.elastic.co/t/error-when-querying-elasticsearch-from-logstash/343907 "2023-09-26T15:19:17Z")

</div>

I'm using Elasticsearch input plugin in logstash to query the Elastic data. But I'm getting the below error Ignoring clear\_scroll exception {:message=\>"\[404\] {\\"succeeded\\":true,\\"num\_freed\\":0}", :exception=\>Elasticsea…

---

## [Email action message](https://discuss.elastic.co/t/email-action-message/343910)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:55pm UTC](https://discuss.elastic.co/t/email-action-message/343910 "2023-09-26T15:55:52Z")

</div>

Hello, I have an alert using rule from security section. My aim is to gather some information into the mail alert from the alert: In my example, I would like to take the username & the ip: {{#context.hits}} Username:…

---

## [Trace Search](https://discuss.elastic.co/t/trace-search/343908)

<div class="topic-metadata">

**Author:** [@techtuga](https://discuss.elastic.co/u/techtuga)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:26pm UTC](https://discuss.elastic.co/t/trace-search/343908 "2023-09-26T15:26:37Z")

</div>

Hi there, We are getting application feeds from an opentelemetry/java 1.23.1 agent, trough Otel Collector 0.82.0 to APM 8.9.1 Server, the feeds are arriving fine into the APM index: Anyway when trying to to filter u…

---

## [Discovery in multi node cluster using docker compose](https://discuss.elastic.co/t/discovery-in-multi-node-cluster-using-docker-compose/343199)

<div class="topic-metadata">

**Author:** [@JoyceBabu](https://discuss.elastic.co/u/JoyceBabu)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 3:21pm UTC](https://discuss.elastic.co/t/discovery-in-multi-node-cluster-using-docker-compose/343199 "2023-09-26T15:21:38Z")

</div>

I am trying to create a three node ElasticSEarch cluster following the tutorial When I set cluster.initial\_master\_nodes to es1,es2,es3, I am getting the warning this node is locked into cluster UUID \[lUWf3vbtRcarnQX…

---

## [How to add persistent data to filebeat](https://discuss.elastic.co/t/how-to-add-persistent-data-to-filebeat/341981)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 2:55pm UTC](https://discuss.elastic.co/t/how-to-add-persistent-data-to-filebeat/341981 "2023-09-26T14:55:15Z")

</div>

I have some log files that only in the first line it will display the version of the file, but I want to use that version everywhere in the log. is there a way I can store that data and use it for the rest of the file? …

---

## [Can't connect to autonomoous oracledb cloud](https://discuss.elastic.co/t/cant-connect-to-autonomoous-oracledb-cloud/343081)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 2:54pm UTC](https://discuss.elastic.co/t/cant-connect-to-autonomoous-oracledb-cloud/343081 "2023-09-26T14:54:13Z")

</div>

Hi I can't connect to an oracle db in oracle cloud, it gives me an error Got minus one from a read call. I've been trying many things in the discussions but nothing seems to work for me: this is my input: input{ j…

---

## [Packetbeat MongoDB in Windows Server doesn't work](https://discuss.elastic.co/t/packetbeat-mongodb-in-windows-server-doesnt-work/343903)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 2:53pm UTC](https://discuss.elastic.co/t/packetbeat-mongodb-in-windows-server-doesnt-work/343903 "2023-09-26T14:53:30Z")

</div>

Hi I'm trying to monitor mongodb connections using packetbeat, doing it locally on my mongodb works fine: this is my configuration: packetbeat.interfaces: - device: \\Device\\NPF\_{422A5385-8A2F-46AB-8B71-2C94764B14FA} …

---

## [Importing / Exporting dashboards and agent policy's](https://discuss.elastic.co/t/importing-exporting-dashboards-and-agent-policys/343878)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 2:24pm UTC](https://discuss.elastic.co/t/importing-exporting-dashboards-and-agent-policys/343878 "2023-09-26T14:24:39Z")

</div>

Hi, I would like to export my dashboards and agent policies to use in another Elastic cluster. Is this possible to do? If so, how can I do this? Thanks!

---

## [StatusCode:401, Unauthorized - Kibana - API request](https://discuss.elastic.co/t/statuscode-401-unauthorized-kibana-api-request/343899)

<div class="topic-metadata">

**Author:** [@tfournier](https://discuss.elastic.co/u/tfournier)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 2:18pm UTC](https://discuss.elastic.co/t/statuscode-401-unauthorized-kibana-api-request/343899 "2023-09-26T14:18:06Z")

</div>

Hi there, I'm not able to find Kibana cases by API request. This is the error I get : {"statusCode":401,"error":"Unauthorized","message":"Unauthorized"} I'm trying to find cases with this curl : curl --user usern…

---

## [How to parse values as key value not array](https://discuss.elastic.co/t/how-to-parse-values-as-key-value-not-array/342896)

<div class="topic-metadata">

**Author:** [@dreambeam](https://discuss.elastic.co/u/dreambeam)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-parse-values-as-key-value-not-array/342896 "2023-09-26T14:02:17Z")

</div>

Hi there. I am trying parse a text file containing values below. 15, 3241 16, 800 17, 1 Below if my logstash configuration. When I checked in Kibana , I have the field document displayed as a array. "hcount": \[ 800 \] …

---

## [Configuring alerts on event](https://discuss.elastic.co/t/configuring-alerts-on-event/343892)

<div class="topic-metadata">

**Author:** [@oll](https://discuss.elastic.co/u/oll)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:45pm UTC](https://discuss.elastic.co/t/configuring-alerts-on-event/343892 "2023-09-26T13:45:20Z")

</div>

Hello! Help me to find a way to notify about winlogbeat event c for example event.code 4625 - An account failed to log on. The idea is to notify the administrator if the number of failed logins from a user exceeds for…

---

## [Unable to send metricbeat to aws MSK kafka with sasl\_ssl authentication](https://discuss.elastic.co/t/unable-to-send-metricbeat-to-aws-msk-kafka-with-sasl-ssl-authentication/343885)

<div class="topic-metadata">

**Author:** [@Kotesh\_Nataru](https://discuss.elastic.co/u/Kotesh_Nataru)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:25pm UTC](https://discuss.elastic.co/t/unable-to-send-metricbeat-to-aws-msk-kafka-with-sasl-ssl-authentication/343885 "2023-09-26T13:25:26Z")

</div>

I have created AWS MSK service with SASL\_SSL authentication and able to send/receive data through python code to it. i am trying to send metricbeat and getting the below error. this if from windows machine Here is the m…

---

## [Search\_after still gives me duplicates](https://discuss.elastic.co/t/search-after-still-gives-me-duplicates/343861)

<div class="topic-metadata">

**Author:** [@George\_Githinji](https://discuss.elastic.co/u/George_Githinji)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 1:22pm UTC](https://discuss.elastic.co/t/search-after-still-gives-me-duplicates/343861 "2023-09-26T13:22:32Z")

</div>

Hi, I have implemented a search-after pattern in my Elasticsearch implementation with a hope of solving duplicate issue we are currently facing. On the first request, I am getting a batch of 100 and then get the raw\_scor…

---

## [Why does the documentation lack so many topics?](https://discuss.elastic.co/t/why-does-the-documentation-lack-so-many-topics/343746)

<div class="topic-metadata">

**Author:** [@du-it](https://discuss.elastic.co/u/du-it)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 1:16pm UTC](https://discuss.elastic.co/t/why-does-the-documentation-lack-so-many-topics/343746 "2023-09-26T13:16:49Z")

</div>

To be able to replace org.elasticsearch.\* classes with co.elastic.\* classes it would be very helpful to find a good documentation with a lot of examples. Why is it poorly possible to find any? For instance, what are the…

---

## [Installation and configuring metricbeat in docker](https://discuss.elastic.co/t/installation-and-configuring-metricbeat-in-docker/343736)

<div class="topic-metadata">

**Author:** [@swikriti.debnath](https://discuss.elastic.co/u/swikriti.debnath)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 12:29pm UTC](https://discuss.elastic.co/t/installation-and-configuring-metricbeat-in-docker/343736 "2023-09-26T12:29:42Z")

</div>

Already seen metric beat installation detailed video but without docker . Please arrange one detailed series on metric beat docker installation and configuration.

---

## [Use a NEST based Client with Indices created from fscrawler](https://discuss.elastic.co/t/use-a-nest-based-client-with-indices-created-from-fscrawler/343782)

<div class="topic-metadata">

**Author:** [@Voidi](https://discuss.elastic.co/u/Voidi)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 12:20pm UTC](https://discuss.elastic.co/t/use-a-nest-based-client-with-indices-created-from-fscrawler/343782 "2023-09-26T12:20:17Z")

</div>

I want create Client program based on the NEST Library which queries an Index created with GitHub - dadoonet/fscrawler: Elasticsearch File System Crawler (FS Crawler) . Most NEST tutorials show that i should create a cl…

---

## [How to ignore last element of array in elastic watcher \\ mustache template](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 12:12pm UTC](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801 "2023-09-26T12:12:49Z")

</div>

Hello! I have an issue when trying to set an elasticsearch watcher. Here is the part of its config: "input": { "chain": { "inputs": \[ { "\*\*first\*\*": { "search": { …

---

## [Date math Incorrect HTTP method for uri](https://discuss.elastic.co/t/date-math-incorrect-http-method-for-uri/343843)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 11:30am UTC](https://discuss.elastic.co/t/date-math-incorrect-http-method-for-uri/343843 "2023-09-26T11:30:53Z")

</div>

Hi I just want to create index with date math from dev tool console for rollover but I got below error: request PUT /%3Cindex\_test-%7Bnow%2Fd%7BYYYYMMDD%7D%7D%3E { "aliases": { "logs\_write": {} } } { "error…

---

## [Elastic apm instrumentation not working for my Flask application running in python 3.x](https://discuss.elastic.co/t/elastic-apm-instrumentation-not-working-for-my-flask-application-running-in-python-3-x/343693)

<div class="topic-metadata">

**Author:** [@Ankit\_kumar\_Srivasta](https://discuss.elastic.co/u/Ankit_kumar_Srivasta)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 11:22am UTC](https://discuss.elastic.co/t/elastic-apm-instrumentation-not-working-for-my-flask-application-running-in-python-3-x/343693 "2023-09-26T11:22:04Z")

</div>

I am unable to find out transaction traces on kibana server after using the apm object like this. app = Flask(\_\_name\_\_) app.secret\_key = "ahugekey@netcore#2019" app.config\['ELASTIC\_APM'\] = { 'SERVICE\_NAME': 'o…

---

## [Help with POST URL](https://discuss.elastic.co/t/help-with-post-url/343444)

<div class="topic-metadata">

**Author:** [@ElasticNovis](https://discuss.elastic.co/u/ElasticNovis)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 11:14am UTC](https://discuss.elastic.co/t/help-with-post-url/343444 "2023-09-26T11:14:49Z")

</div>

Hi, I am new to POST URLs but my goal is to generate a pdf from a dashboard automatically, and save it locally to a shared area. I have got my POST URL of my dashboard and using Unix curl command I have tried to get the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=412)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=414)
