# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=416

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 417

---

## [ElasticsearchSecurityException when security is enabled on master node but not the data nodes](https://discuss.elastic.co/t/elasticsearchsecurityexception-when-security-is-enabled-on-master-node-but-not-the-data-nodes/342076)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 6\
**Last updated:** [September 22, 2023, 7:44pm UTC](https://discuss.elastic.co/t/elasticsearchsecurityexception-when-security-is-enabled-on-master-node-but-not-the-data-nodes/342076 "2023-09-22T19:44:26Z")

</div>

I have an ES 7.16.2 cluster running with dedicated master nodes and separate data nodes. If/when - xpack.security.enabled is set to true on the master nodes some of the data nodes have xpack security disabled anonymou…

---

## [Need Help Configuring HTTPS Between Elasticsearch and Kibana](https://discuss.elastic.co/t/need-help-configuring-https-between-elasticsearch-and-kibana/343649)

<div class="topic-metadata">

**Author:** [@sami\_mezghani](https://discuss.elastic.co/u/sami_mezghani)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 6:11pm UTC](https://discuss.elastic.co/t/need-help-configuring-https-between-elasticsearch-and-kibana/343649 "2023-09-22T18:11:55Z")

</div>

Hello forum members, I'm new to Elasticsearch and Kibana, and I'm currently trying to set up a secure connection (HTTPS) between Elasticsearch and Kibana. I've generated the necessary certificates using elasticsearch-ce…

---

## [Logstash Condiational Filtering Issue with Geo Location](https://discuss.elastic.co/t/logstash-condiational-filtering-issue-with-geo-location/343596)

<div class="topic-metadata">

**Author:** [@M\_Hatam](https://discuss.elastic.co/u/M_Hatam)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 5:57pm UTC](https://discuss.elastic.co/t/logstash-condiational-filtering-issue-with-geo-location/343596 "2023-09-22T17:57:09Z")

</div>

Hi Everyone, Sorry if this is answered somewhere else and I would appreciate if you can help. I'm sending logs from FortiGate to Logstash and I want to set geoip location to be sent to Elasticsearch. Since some traffic…

---

## [ECS Field Name (Fortigate Dataset)](https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 5:19pm UTC](https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492 "2023-09-22T17:19:13Z")

</div>

I am collecting Fortigate logs with the Elastic Agent and the Fortigate integration. These are then being shipped to Logstash for some custom enrichment before being pushed to Elastic Cloud. One of the custom enrichmen…

---

## [Analysis phoenitic plugin not found is server down?](https://discuss.elastic.co/t/analysis-phoenitic-plugin-not-found-is-server-down/343632)

<div class="topic-metadata">

**Author:** [@pc-magas](https://discuss.elastic.co/u/pc-magas)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 5:10pm UTC](https://discuss.elastic.co/t/analysis-phoenitic-plugin-not-found-is-server-down/343632 "2023-09-22T17:10:58Z")

</div>

I have this Dockerfile: FROM elasticsearch:7.7.0 RUN elasticsearch-plugin install analysis-phonetic &&\\ elasticsearch-plugin install analysis-icu &&\\ elasticsearch-plugin install gr.skroutz:elasticsearch-skrout…

---

## [Reindexing all data or Reindexing only changes](https://discuss.elastic.co/t/reindexing-all-data-or-reindexing-only-changes/343617)

<div class="topic-metadata">

**Author:** [@Julien\_Hac](https://discuss.elastic.co/u/Julien_Hac)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 3:53pm UTC](https://discuss.elastic.co/t/reindexing-all-data-or-reindexing-only-changes/343617 "2023-09-22T15:53:33Z")

</div>

Hello, I have a question about indexing strategy for my project. Iam a novice and elasticsearch and i need advice and help about my case. In the project, im using primary database postgres, and i have about 10 000 obje…

---

## [{:exception=\>"Java::OrgLogstash::MissingConverterException: Missing Converter handling for full class name=org.bson.types.ObjectId, simple name=ObjectId"}](https://discuss.elastic.co/t/exception-java-missing-converter-handling-for-full-class-name-org-bson-types-objectid-simple-name-objectid/343636)

<div class="topic-metadata">

**Author:** [@EL\_MALKI\_MOHAMED](https://discuss.elastic.co/u/EL_MALKI_MOHAMED)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 3:26pm UTC](https://discuss.elastic.co/t/exception-java-missing-converter-handling-for-full-class-name-org-bson-types-objectid-simple-name-objectid/343636 "2023-09-22T15:26:13Z")

</div>

It not works. Please help me.the problem still persists this is my config : input { jdbc { jdbc\_driver\_library =\> "/etc/logstash/jdbc/mongojdbc3.1.jar" jdbc\_driver\_class =\> "com.dbschema…

---

## [Can I limit the search on sub items based on other fields of subitems?](https://discuss.elastic.co/t/can-i-limit-the-search-on-sub-items-based-on-other-fields-of-subitems/343574)

<div class="topic-metadata">

**Author:** [@Carlos\_Barros](https://discuss.elastic.co/u/Carlos_Barros)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 2:51pm UTC](https://discuss.elastic.co/t/can-i-limit-the-search-on-sub-items-based-on-other-fields-of-subitems/343574 "2023-09-22T14:51:37Z")

</div>

Hello guys I'm new in elastic and here comes the doubt. When querying a json index, I need to find in an array of complex objects a string only in some array items. In example: considering the following info I need to…

---

## [Scroll documents with ElasticSearch 8.9 for dotnet](https://discuss.elastic.co/t/scroll-documents-with-elasticsearch-8-9-for-dotnet/343627)

<div class="topic-metadata">

**Author:** [@erhogaihe](https://discuss.elastic.co/u/erhogaihe)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 1:54pm UTC](https://discuss.elastic.co/t/scroll-documents-with-elasticsearch-8-9-for-dotnet/343627 "2023-09-22T13:54:12Z")

</div>

Hi, I am looking for some assisstance in getting scrolling working for ES client (Version 8.9) for .NET. I have tried a few things but cannot get them to work, I have tried as per example in documentation for v7.17 but …

---

## [Filebeat timestamp is shown with a 4hr offset](https://discuss.elastic.co/t/filebeat-timestamp-is-shown-with-a-4hr-offset/343575)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-is-shown-with-a-4hr-offset/343575 "2023-09-22T13:37:51Z")

</div>

We have a Filebeat server (8.9) that ingests Syslog logs. The timestamp shown in GUI is 4 hours earlier than it should be. The timezone is set correctly in Kibana. The timestamp is correct when viewing JSON; it looks lik…

---

## [Elk loses contact with the master every morning at 8am and the cluster turns red](https://discuss.elastic.co/t/elk-loses-contact-with-the-master-every-morning-at-8am-and-the-cluster-turns-red/343621)

<div class="topic-metadata">

**Author:** [@abcdbdocker](https://discuss.elastic.co/u/abcdbdocker)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 1:23pm UTC](https://discuss.elastic.co/t/elk-loses-contact-with-the-master-every-morning-at-8am-and-the-cluster-turns-red/343621 "2023-09-22T13:23:13Z")

</div>

重点词汇 690/5000 传统翻译模型 通用场景 hello Our cluster will turn red after 8 am every day. The cluster size is 6 hot data nodes 3 warm data nodes. The primary node is the same as the hot data node. Recently, we found a strange …

---

## [Elasticsearch Architecture nodes](https://discuss.elastic.co/t/elasticsearch-architecture-nodes/343435)

<div class="topic-metadata">

**Author:** [@Chloe\_Boissavy](https://discuss.elastic.co/u/Chloe_Boissavy)\
**Replies:** 2\
**Last updated:** [September 22, 2023, 11:58am UTC](https://discuss.elastic.co/t/elasticsearch-architecture-nodes/343435 "2023-09-22T11:58:11Z")

</div>

Hello, I have an ECK with 1 kibana + 4 nodes Elasticsearch + 1 Logstash. I am using hot warm cold rotation. I would like to change my design. I would like to change for 1 kibana + 3 nodes HOT + 3 nodes WARM + 3 nodes…

---

## [Create a max of 7 monitoring indices](https://discuss.elastic.co/t/create-a-max-of-7-monitoring-indices/343603)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 4\
**Last updated:** [September 22, 2023, 11:56am UTC](https://discuss.elastic.co/t/create-a-max-of-7-monitoring-indices/343603 "2023-09-22T11:56:24Z")

</div>

Hello, I want to configure monitoring setting as such that only 7 days monitoring indices is created in my cluster in order to monitor for only 7 days and not more.. Also Is there a way that only 1 elasticsearch monito…

---

## [Cannot get the name of indices using logstash](https://discuss.elastic.co/t/cannot-get-the-name-of-indices-using-logstash/343440)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 6\
**Last updated:** [September 22, 2023, 11:34am UTC](https://discuss.elastic.co/t/cannot-get-the-name-of-indices-using-logstash/343440 "2023-09-22T11:34:15Z")

</div>

Hello everyone, How can I get the name of indices using logstash? I have this indices which is from data stream called (backing indices if I correct) .ds-my-neoada-stream-2023.09.14-000001 .ds-my-neoada-stream-2023.09…

---

## [Exclude documents from Reindex](https://discuss.elastic.co/t/exclude-documents-from-reindex/343615)

<div class="topic-metadata">

**Author:** [@NekoNova](https://discuss.elastic.co/u/NekoNova)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 11:30am UTC](https://discuss.elastic.co/t/exclude-documents-from-reindex/343615 "2023-09-22T11:30:22Z")

</div>

Okay, I am using the C# NEST client to trigger a Reindex of documents between two indexes in our Elasticsearch. The problem is that the Elasticsearch cluster only moves around 888 documents of the million that is there …

---

## [Logstash jdk vulnerability](https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 11:12am UTC](https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578 "2023-09-22T11:12:48Z")

</div>

We are currently running logstash 7.16.3 but are getting flagged for the version of JDK 11.0.13 that it is using and are being told we need to upgrade the JDK version to something higher that 11.0.13. How do one upgrade…

---

## [Kibana 8.9.0](https://discuss.elastic.co/t/kibana-8-9-0/343602)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 10:34am UTC](https://discuss.elastic.co/t/kibana-8-9-0/343602 "2023-09-22T10:34:24Z")

</div>

Kibana dashboard's time range picker always shows the default value and doesn't remember the last used value from your previous login.

---

## [Closed indices in 8.5.3 break stack monitoring](https://discuss.elastic.co/t/closed-indices-in-8-5-3-break-stack-monitoring/343407)

<div class="topic-metadata">

**Author:** [@GregoryJC](https://discuss.elastic.co/u/GregoryJC)\
**Replies:** 5\
**Last updated:** [September 22, 2023, 8:34am UTC](https://discuss.elastic.co/t/closed-indices-in-8-5-3-break-stack-monitoring/343407 "2023-09-22T08:34:15Z")

</div>

In our monitoring cluster I noticed that the stack monitoring elasticsearch overview page broke after I closed only some indices on a cluster.

---

## [Create maximum of 7 monitoring index for kibana](https://discuss.elastic.co/t/create-maximum-of-7-monitoring-index-for-kibana/343604)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 8:06am UTC](https://discuss.elastic.co/t/create-maximum-of-7-monitoring-index-for-kibana/343604 "2023-09-22T08:06:55Z")

</div>

Hello, I want to configure monitoring setting as such that only 7 days monitoring indices is created in my cluster in order to monitor for only 7 days and not more.. Also Is there a way that only 1 kibana monitoring in…

---

## [Heartbeat http.yml config sends data of one service in index and if same service running on diffrent server dont send datah](https://discuss.elastic.co/t/heartbeat-http-yml-config-sends-data-of-one-service-in-index-and-if-same-service-running-on-diffrent-server-dont-send-datah/343600)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 8:03am UTC](https://discuss.elastic.co/t/heartbeat-http-yml-config-sends-data-of-one-service-in-index-and-if-same-service-running-on-diffrent-server-dont-send-datah/343600 "2023-09-22T08:03:31Z")

</div>

Hello All, I have configured services under monitor.d using http.yml.(8.8.2 verion beats) I want to monitor multiple services in various host. Current issue is I'm monitoring same service hosted in two diffrenent serv…

---

## [\[elastic-agent\] \<defunct\> Version 8.9.1](https://discuss.elastic.co/t/elastic-agent-defunct-version-8-9-1/343588)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 2:54am UTC](https://discuss.elastic.co/t/elastic-agent-defunct-version-8-9-1/343588 "2023-09-22T02:54:06Z")

</div>

I am aware of few related issue for elastic-agent going into defunct , they appear to be for older version and a fix was applied for 8.5 We are on version 8.9.1 and still seeing this on Centos 7.x , please advice if …

---

## [Kibana rules/alerts "If alert matches a query" not working for custom fields](https://discuss.elastic.co/t/kibana-rules-alerts-if-alert-matches-a-query-not-working-for-custom-fields/343580)

<div class="topic-metadata">

**Author:** [@arislawrence](https://discuss.elastic.co/u/arislawrence)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 11:54pm UTC](https://discuss.elastic.co/t/kibana-rules-alerts-if-alert-matches-a-query-not-working-for-custom-fields/343580 "2023-09-21T23:54:25Z")

</div>

Elasticsearch, Kibana, Logstash and Beats using version 8.9.1 or 8.10.1 When creating Kibana rules for Log threshold or Metric threshold, the "If alert matches a query" defined is a custom fields, it will not process th…

---

## [ELK stack elasticsearch FIPS Keytool Certificates](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088)

<div class="topic-metadata">

**Author:** [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Replies:** 6\
**Last updated:** [September 21, 2023, 11:51pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088 "2023-09-21T23:51:41Z")

</div>

I am setting up an ELK stack version 7.17.12. We have a separate instance for Elasticsearch, Kibana, and Logstash - but only one instance for each. We are using it with a Wazuh Manager instance as well with a Logstash an…

---

## [Filebeat is not sending a continuous stream to Logstash](https://discuss.elastic.co/t/filebeat-is-not-sending-a-continuous-stream-to-logstash/342862)

<div class="topic-metadata">

**Author:** [@surfingjoe](https://discuss.elastic.co/u/surfingjoe)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 10:06pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-a-continuous-stream-to-logstash/342862 "2023-09-21T22:06:54Z")

</div>

I'm running a development set of servers (not production). I have an ELK server, a web server, and a reverse proxy server. Data from the web server and the reverse proxy have successfully been sent into Logstash on the E…

---

## [Msearch Java Elasticsearch 8.9](https://discuss.elastic.co/t/msearch-java-elasticsearch-8-9/343570)

<div class="topic-metadata">

**Author:** [@jfuehner](https://discuss.elastic.co/u/jfuehner)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 6:04pm UTC](https://discuss.elastic.co/t/msearch-java-elasticsearch-8-9/343570 "2023-09-21T18:04:42Z")

</div>

I am trying to use the Java 8.9 client to send multi-search requests (Multi search API | Elasticsearch Guide \[8.10\] | Elastic) but am getting a NullPointerException when waiting for the results to come back… Is there a …

---

## [Cannot start ES after upgrading from 7.x to 8.x](https://discuss.elastic.co/t/cannot-start-es-after-upgrading-from-7-x-to-8-x/343494)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 5:56pm UTC](https://discuss.elastic.co/t/cannot-start-es-after-upgrading-from-7-x-to-8-x/343494 "2023-09-21T17:56:57Z")

</div>

This is the error in my journalctl: Sep 20 11:39:43 ELK-Stack.uhtasi.local systemd\[1\]: Starting Elasticsearch... Sep 20 11:39:50 ELK-Stack.uhtasi.local systemd-entrypoint\[29322\]: Error occurred during initialization of…

---

## [Lost aws module (rds metricset) metrics after upgrade from 7.17 -\> 8.8.2](https://discuss.elastic.co/t/lost-aws-module-rds-metricset-metrics-after-upgrade-from-7-17-8-8-2/343388)

<div class="topic-metadata">

**Author:** [@m\_standfuss](https://discuss.elastic.co/u/m_standfuss)\
**Replies:** 3\
**Last updated:** [September 21, 2023, 5:51pm UTC](https://discuss.elastic.co/t/lost-aws-module-rds-metricset-metrics-after-upgrade-from-7-17-8-8-2/343388 "2023-09-21T17:51:13Z")

</div>

After upgrading from 7.17 to 8.8.2 we are no longer getting any of our rds metrics from the aws module. We are running on EKS in AWS, nothing changed in terms of the modules configured, overall metricbeats configuration…

---

## [KIbana Maps Join Field not being displayed in the map](https://discuss.elastic.co/t/kibana-maps-join-field-not-being-displayed-in-the-map/343560)

<div class="topic-metadata">

**Author:** [@MartinGarcia](https://discuss.elastic.co/u/MartinGarcia)\
**Replies:** 3\
**Last updated:** [September 21, 2023, 5:41pm UTC](https://discuss.elastic.co/t/kibana-maps-join-field-not-being-displayed-in-the-map/343560 "2023-09-21T17:41:32Z")

</div>

Hi, I'm using Kibana Maps and trying to display a sum of capital on each boundary layer associated with it. Before I was able to display but with the latest Kibana version it doesn´t display the sum in the map itsefl, on…

---

## [Force starting Elasticsearch, even with incorrect index files](https://discuss.elastic.co/t/force-starting-elasticsearch-even-with-incorrect-index-files/343480)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 8\
**Last updated:** [September 21, 2023, 4:16pm UTC](https://discuss.elastic.co/t/force-starting-elasticsearch-even-with-incorrect-index-files/343480 "2023-09-21T16:16:07Z")

</div>

Hi there! I tried to start Elasticsearch 8.6 with loading data from index which was initially created by Elasticsearch 7.13. It fails to start with message \[2023-09-20T11:17:13,331\]\[ERROR\]\[o.e.b.Elasticsearch \] \[…

---

## [Ability to create multiple datastreams with Elastic integrations?](https://discuss.elastic.co/t/ability-to-create-multiple-datastreams-with-elastic-integrations/343325)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 2:42pm UTC](https://discuss.elastic.co/t/ability-to-create-multiple-datastreams-with-elastic-integrations/343325 "2023-09-21T14:42:32Z")

</div>

Hello everyone, I'm currently exploring Elastic integrations and have a question regarding the creation of multiple datastreams. I noticed that in the integration example with Cisco ISE, there are about ten Ingest Pipel…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=415)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=417)
