# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=414

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 415

---

## [How to restore a snapshot/how to backup the indexes in my locally installed Elastic Search from Elastic Cloud?](https://discuss.elastic.co/t/how-to-restore-a-snapshot-how-to-backup-the-indexes-in-my-locally-installed-elastic-search-from-elastic-cloud/343852)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 11:06am UTC](https://discuss.elastic.co/t/how-to-restore-a-snapshot-how-to-backup-the-indexes-in-my-locally-installed-elastic-search-from-elastic-cloud/343852 "2023-09-26T11:06:45Z")

</div>

So, I have some indices on my elastic cloud. Initially, I registered a repository on my own AWS S3 bucket and then created a snapshot that has all the indices stored within it. Now, I have installed Elastic Search and Ki…

---

## [How to update ES node transport address](https://discuss.elastic.co/t/how-to-update-es-node-transport-address/343851)

<div class="topic-metadata">

**Author:** [@HadesC](https://discuss.elastic.co/u/HadesC)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:59am UTC](https://discuss.elastic.co/t/how-to-update-es-node-transport-address/343851 "2023-09-26T10:59:32Z")

</div>

I have two Red Hat installed ES 7.9.1 nodes (build type: tar) in my environment, joined to same cluster. Suppose one of the Red Hat nodes should only have private IP 10.121.0.2, somehow there is another private IP 10.12…

---

## [Logstash google pubsub output plugin](https://discuss.elastic.co/t/logstash-google-pubsub-output-plugin/343791)

<div class="topic-metadata">

**Author:** [@Bala\_Joshi](https://discuss.elastic.co/u/Bala_Joshi)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:21am UTC](https://discuss.elastic.co/t/logstash-google-pubsub-output-plugin/343791 "2023-09-26T10:21:32Z")

</div>

hello All, I am trying to injest to google pubsub topic from logstash server. Below are the configuration google\_pubsub { project\_id =\> "xx" topic =\> "xx" json\_key\_file =\> "xx" #Options for configuring the upload …

---

## [SAML Configuration Questions for Elastic Cloud](https://discuss.elastic.co/t/saml-configuration-questions-for-elastic-cloud/343525)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:17am UTC](https://discuss.elastic.co/t/saml-configuration-questions-for-elastic-cloud/343525 "2023-09-26T10:17:37Z")

</div>

Hello Elastic community, I'm currently working on configuring SAML authentication for Elastic Cloud (not ECE). I have the following SAML configuration that I need to implement: xpack.security.authc.realms.saml.saml1: …

---

## [Kibana Lens Annotations](https://discuss.elastic.co/t/kibana-lens-annotations/343639)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 8:27am UTC](https://discuss.elastic.co/t/kibana-lens-annotations/343639 "2023-09-26T08:27:12Z")

</div>

Hi we are creating a Dashboard in Kibana 8.9.0. We are using Lens. Is there a way to have the annotation value be left justified with the tooltip? Or the ability to make it wider?

---

## [How to go to specific transaction details by just clicking on it on bar chart?](https://discuss.elastic.co/t/how-to-go-to-specific-transaction-details-by-just-clicking-on-it-on-bar-chart/343704)

<div class="topic-metadata">

**Author:** [@Hamad](https://discuss.elastic.co/u/Hamad)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 7:07am UTC](https://discuss.elastic.co/t/how-to-go-to-specific-transaction-details-by-just-clicking-on-it-on-bar-chart/343704 "2023-09-26T07:07:47Z")

</div>

Hi everyone! How can i go into details of specific transaction from the bar chart in dashboard? If i click on any transaction in my bar chart, it adds a filter instead of going to that transaction details page. for now i…

---

## [Heartbeat Http & ICMP - Discovery from CMDB](https://discuss.elastic.co/t/heartbeat-http-icmp-discovery-from-cmdb/343835)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 6:31am UTC](https://discuss.elastic.co/t/heartbeat-http-icmp-discovery-from-cmdb/343835 "2023-09-26T06:31:28Z")

</div>

Hello, We would like to build the config file ex: heartbeat.yml from our CMDB (ServiceNow & Netbox) inventory. Is it something possible ? Thanks, Praveen

---

## [Data collection and labeling with some of the Beats](https://discuss.elastic.co/t/data-collection-and-labeling-with-some-of-the-beats/343824)

<div class="topic-metadata">

**Author:** [@Oscar\_Llerena](https://discuss.elastic.co/u/Oscar_Llerena)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 5:20am UTC](https://discuss.elastic.co/t/data-collection-and-labeling-with-some-of-the-beats/343824 "2023-09-26T05:20:17Z")

</div>

Hello everyone, I am currently engaged in an exploration of Elastic Stack's Beats products, specifically Packetbeats, FileBeats, WinlogBeats, and Metricbeats, across Linux and Windows platforms. My end goal is to levera…

---

## [Dashboard is not created](https://discuss.elastic.co/t/dashboard-is-not-created/343828)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 4:58am UTC](https://discuss.elastic.co/t/dashboard-is-not-created/343828 "2023-09-26T04:58:28Z")

</div>

Hi, I am creating dashboard by importing ndjson file. Using below API to import, POST \<kibana host\>:\<port\>/s/\<space\_id\>/api/saved\_objects/\_import Issue is dashboard is created with new dashboard id not with the one p…

---

## [ELK - Enable Kibana Login (Basic Auth) without SSL/TLS on Multi Instance Docker Swarm Cluster](https://discuss.elastic.co/t/elk-enable-kibana-login-basic-auth-without-ssl-tls-on-multi-instance-docker-swarm-cluster/343827)

<div class="topic-metadata">

**Author:** [@vdcharter](https://discuss.elastic.co/u/vdcharter)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 4:24am UTC](https://discuss.elastic.co/t/elk-enable-kibana-login-basic-auth-without-ssl-tls-on-multi-instance-docker-swarm-cluster/343827 "2023-09-26T04:24:47Z")

</div>

Hi, I have a multi node - multi instance (VM and BareMetal servers) docker swarm cluster for my ELK Stack with 3 ES Masters, 3 Kibana Nodes, data nodes etc. ES and Kibana Version - 7.17.8 I want to enable basic authent…

---

## [Asking how to nested logstash](https://discuss.elastic.co/t/asking-how-to-nested-logstash/343826)

<div class="topic-metadata">

**Author:** [@Shi\_Eng\_Ng](https://discuss.elastic.co/u/Shi_Eng_Ng)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:47am UTC](https://discuss.elastic.co/t/asking-how-to-nested-logstash/343826 "2023-09-26T03:47:33Z")

</div>

"archives\_id": null, "level\_of\_detail": null, "items": \[ { "barcode": "000892", "brn": "4188", "collection": "\["Books"\]", "updated\_time": "2023-09-13 11:36:56.000000", "suffix": "LAI", "status": "Available", "a…

---

## [Winlogbeat stopping due to Exception](https://discuss.elastic.co/t/winlogbeat-stopping-due-to-exception/343819)

<div class="topic-metadata">

**Author:** [@risshukla](https://discuss.elastic.co/u/risshukla)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:22am UTC](https://discuss.elastic.co/t/winlogbeat-stopping-due-to-exception/343819 "2023-09-26T01:22:35Z")

</div>

We've been using Winlogbeat to forward Workstation logs to Logstash. However, we've encountered an issue after installing Winlogbeat (versions 8.10.2) on our Windows Server 2022. The issue is as follows: Exception 0xc0…

---

## [Unable to Upload Winevt to Elastic Stack](https://discuss.elastic.co/t/unable-to-upload-winevt-to-elastic-stack/343809)

<div class="topic-metadata">

**Author:** [@scott\_securit360](https://discuss.elastic.co/u/scott_securit360)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:20pm UTC](https://discuss.elastic.co/t/unable-to-upload-winevt-to-elastic-stack/343809 "2023-09-25T21:20:18Z")

</div>

Hello! I've recently enabled Security on my Elastic stack (7.17) using the documentation here. I've completed up until the "Configure Beats security" section, as that is not needed in my environment. I'm using the Bur…

---

## [Elastic Fleet - Add GeoData to winlog through Ingest Pipeline](https://discuss.elastic.co/t/elastic-fleet-add-geodata-to-winlog-through-ingest-pipeline/343805)

<div class="topic-metadata">

**Author:** [@Shane\_Martin](https://discuss.elastic.co/u/Shane_Martin)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 7:56pm UTC](https://discuss.elastic.co/t/elastic-fleet-add-geodata-to-winlog-through-ingest-pipeline/343805 "2023-09-25T19:56:06Z")

</div>

Trying to add geo data based on the winlog.event\_data.destinationIp field. I'm trying to use the custom ingest pipeline in fleets / integration. Testing the pipeline with test data seems to work, but the geo fields in …

---

## [vlSelectionResolve is not being called on specific scenario](https://discuss.elastic.co/t/vlselectionresolve-is-not-being-called-on-specific-scenario/343800)

<div class="topic-metadata">

**Author:** [@EdRayQO](https://discuss.elastic.co/u/EdRayQO)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:53pm UTC](https://discuss.elastic.co/t/vlselectionresolve-is-not-being-called-on-specific-scenario/343800 "2023-09-25T18:53:08Z")

</div>

Hello everyone, I'm struggling with a bug I found when implementing a custom visualization using Vega. I'm reposting this from Stackoverflow (Where the Vega folks suggest posting) because nobody is awnsering, so I'm tryi…

---

## [Anomaly rules, select multiple services](https://discuss.elastic.co/t/anomaly-rules-select-multiple-services/343799)

<div class="topic-metadata">

**Author:** [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:41pm UTC](https://discuss.elastic.co/t/anomaly-rules-select-multiple-services/343799 "2023-09-25T18:41:30Z")

</div>

Hello, I'm currently utilizing the Anomaly rule under "Rules and Connectors" within the "Stack Management". I've encountered a situation where I need to select specific services to send emails to distinct addresses. Ho…

---

## [Encounter error "Saved field "timeStamp" of data view "index-name" is invalid for use with the "Date Histogram" aggregation. Please select a new field](https://discuss.elastic.co/t/encounter-error-saved-field-timestamp-of-data-view-index-name-is-invalid-for-use-with-the-date-histogram-aggregation-please-select-a-new-field/343798)

<div class="topic-metadata">

**Author:** [@Long\_Nguyen](https://discuss.elastic.co/u/Long_Nguyen)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:20pm UTC](https://discuss.elastic.co/t/encounter-error-saved-field-timestamp-of-data-view-index-name-is-invalid-for-use-with-the-date-histogram-aggregation-please-select-a-new-field/343798 "2023-09-25T18:20:16Z")

</div>

Hello everyone, I'm running Elastic Stack 8.3.0. I encounter the following error in Kibana "Discover" with an index: The index is indexed from the following csv file (some fields have been redacted): timeStamp…

---

## [Is it possible to have the cluster use a node's hardware specs for allocation decisions?](https://discuss.elastic.co/t/is-it-possible-to-have-the-cluster-use-a-nodes-hardware-specs-for-allocation-decisions/343634)

<div class="topic-metadata">

**Author:** [@Mike\_Snare](https://discuss.elastic.co/u/Mike_Snare)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 5:59pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-the-cluster-use-a-nodes-hardware-specs-for-allocation-decisions/343634 "2023-09-25T17:59:44Z")

</div>

I know that it's possible to use custom attributes in allocations for things like rack-awareness, but I'm more interested in whether or not elastic is capable of taking a node's hardware specs into consideration when dec…

---

## [High resource usage of query with large term filter](https://discuss.elastic.co/t/high-resource-usage-of-query-with-large-term-filter/343585)

<div class="topic-metadata">

**Author:** [@Ray\_Zhang](https://discuss.elastic.co/u/Ray_Zhang)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 5:15pm UTC](https://discuss.elastic.co/t/high-resource-usage-of-query-with-large-term-filter/343585 "2023-09-25T17:15:32Z")

</div>

We are running some rather large queries with about 6 thousand of term values in the filter sections. The queries take 20 to 40 more seconds to run and much more CPU usage were observed when running with the large term …

---

## [CSV export from kibana dashboard through external API call](https://discuss.elastic.co/t/csv-export-from-kibana-dashboard-through-external-api-call/340299)

<div class="topic-metadata">

**Author:** [@manish0803](https://discuss.elastic.co/u/manish0803)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 4:43pm UTC](https://discuss.elastic.co/t/csv-export-from-kibana-dashboard-through-external-api-call/340299 "2023-09-25T16:43:22Z")

</div>

Hi, I have researched and implemented the csv export functionality by calling the export link provided by Kibana. referenced : Automatically generate reports | Kibana Guide \[8.6\] | Elastic However, when I use the link…

---

## [.JSON Conf File for Logstash](https://discuss.elastic.co/t/json-conf-file-for-logstash/343638)

<div class="topic-metadata">

**Author:** [@Google-Cloud-DFIR](https://discuss.elastic.co/u/Google-Cloud-DFIR)\
**Replies:** 19\
**Last updated:** [September 25, 2023, 4:17pm UTC](https://discuss.elastic.co/t/json-conf-file-for-logstash/343638 "2023-09-25T16:17:01Z")

</div>

Hello, I've been trying to configure this .conf file to help parse out .json files correctly. This script is able to ingest Google Cloud Audit Logs (in .json), but fails to parse it correctly: input { # stdin {} …

---

## [How to find polygons that contain a given point in Elasticsearch](https://discuss.elastic.co/t/how-to-find-polygons-that-contain-a-given-point-in-elasticsearch/343769)

<div class="topic-metadata">

**Author:** [@Pranav\_Kapur](https://discuss.elastic.co/u/Pranav_Kapur)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:05pm UTC](https://discuss.elastic.co/t/how-to-find-polygons-that-contain-a-given-point-in-elasticsearch/343769 "2023-09-25T16:05:57Z")

</div>

I need to build a query on a database with around 50k terrain polygons (stored as geo\_shape polygons on ES) where I give a point and it returns every polygon that contains this point. I tried to create it, but getting i…

---

## [Transform checkpoints not optimized with date histogram](https://discuss.elastic.co/t/transform-checkpoints-not-optimized-with-date-histogram/343561)

<div class="topic-metadata">

**Author:** [@Imran\_Arshad](https://discuss.elastic.co/u/Imran_Arshad)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:01pm UTC](https://discuss.elastic.co/t/transform-checkpoints-not-optimized-with-date-histogram/343561 "2023-09-25T16:01:20Z")

</div>

I am running a transform that groups by 2 fields: 1. terms on a keyword field (client\_id), 2. date histogram on a date field (transaction\_time). For sync, I am using a separate date field (updated\_at) that is basically t…

---

## [How does logstash handle multiline logs in a load balancing configuration](https://discuss.elastic.co/t/how-does-logstash-handle-multiline-logs-in-a-load-balancing-configuration/343780)

<div class="topic-metadata">

**Author:** [@Ror](https://discuss.elastic.co/u/Ror)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 3:18pm UTC](https://discuss.elastic.co/t/how-does-logstash-handle-multiline-logs-in-a-load-balancing-configuration/343780 "2023-09-25T15:18:17Z")

</div>

Hi all, We collect our infrastructure logs with filebeat on elastic cloud. We'd like to add a logstash cluster (multiple logstash instances load-balanced) between our filebeat agents and our elastic cloud cluster. The …

---

## [No way to rollover mutable timeseries data](https://discuss.elastic.co/t/no-way-to-rollover-mutable-timeseries-data/343784)

<div class="topic-metadata">

**Author:** [@kmcclellan](https://discuss.elastic.co/u/kmcclellan)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 2:57pm UTC](https://discuss.elastic.co/t/no-way-to-rollover-mutable-timeseries-data/343784 "2023-09-25T14:57:56Z")

</div>

Since datastreams are append-only, Tutorial: Automate rollover with ILM | Elasticsearch Guide \[8.10\] | Elastic suggests an alternative technique for rolling over mutable documents: In these cases, you can use an index …

---

## [How different are Elasticsearch and OpenSearch?](https://discuss.elastic.co/t/how-different-are-elasticsearch-and-opensearch/343691)

<div class="topic-metadata">

**Author:** [@heermaas3](https://discuss.elastic.co/u/heermaas3)\
**Replies:** 6\
**Last updated:** [September 25, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-different-are-elasticsearch-and-opensearch/343691 "2023-09-25T14:48:50Z")

</div>

I wanted to ask for a neutral opinion on the differences between Elasticsearch and OpenSearch. Are there differences in use/integrating them into my Software? Do I have to write different code to use both of them? Can …

---

## [GROK pattern help for Audit Log](https://discuss.elastic.co/t/grok-pattern-help-for-audit-log/343761)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 2:48pm UTC](https://discuss.elastic.co/t/grok-pattern-help-for-audit-log/343761 "2023-09-25T14:48:14Z")

</div>

I am struggling to find an appropriate GROK pattern to appropriately dissect my log that is being generated by the xpack Audit. My Logs currently look like {"type":"audit", "timestamp":"2023-09-07T14:34:58,359+0100", "…

---

## [How to implement Phrase suggester using .net elastic.clients.elasticsearch?](https://discuss.elastic.co/t/how-to-implement-phrase-suggester-using-net-elastic-clients-elasticsearch/343757)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 1:25pm UTC](https://discuss.elastic.co/t/how-to-implement-phrase-suggester-using-net-elastic-clients-elasticsearch/343757 "2023-09-25T13:25:39Z")

</div>

How to implement Phrase suggester using .net elastic.clients.elasticsearch in a best way

---

## [Mapper\_exception while using runtime dynamic mapping](https://discuss.elastic.co/t/mapper-exception-while-using-runtime-dynamic-mapping/343764)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 1:13pm UTC](https://discuss.elastic.co/t/mapper-exception-while-using-runtime-dynamic-mapping/343764 "2023-09-25T13:13:49Z")

</div>

Hi, We are using runtime dynamic mapping for indices and receiving below error while indexing. Indexing failed for some events, type: mapper\_exception, reason: timed out while waiting for a dynamic mapping update Even…

---

## [Update ILM and link to an existing index](https://discuss.elastic.co/t/update-ilm-and-link-to-an-existing-index/343762)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/update-ilm-and-link-to-an-existing-index/343762 "2023-09-25T13:03:21Z")

</div>

Hello, I have to update an ILM and update link to an existing index but i have a doubt on my API call Is that good one? curl -u elastic:xxxx -k -X PUT "https://elasticsearch-1:9200/index-raw-syslog/settings?pretty" -H…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=413)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=415)
