# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=417

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 418

---

## [Winlogbeat range doesnt seem to work for drop\_events filter](https://discuss.elastic.co/t/winlogbeat-range-doesnt-seem-to-work-for-drop-events-filter/343556)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 2:41pm UTC](https://discuss.elastic.co/t/winlogbeat-range-doesnt-seem-to-work-for-drop-events-filter/343556 "2023-09-21T14:41:43Z")

</div>

Using version 8.9.1 The range in drop events doesn't seem to work: range.winlog.event\_id: { gte: 1100, lte: 4609 } Its throws a waning and also doesnt send the data. Thanks, JJ

---

## [How can I represent the most recurring document in a Kibana table?](https://discuss.elastic.co/t/how-can-i-represent-the-most-recurring-document-in-a-kibana-table/343288)

<div class="topic-metadata">

**Author:** [@KristinaRaja](https://discuss.elastic.co/u/KristinaRaja)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 1:44pm UTC](https://discuss.elastic.co/t/how-can-i-represent-the-most-recurring-document-in-a-kibana-table/343288 "2023-09-21T13:44:37Z")

</div>

We are using an aggregated based kibana table that displays a bunch of users who had poor calls and where the majority of those poor calls took place, etc...(the user is set as the bucket). For each user, we would like …

---

## [Failed to parse field \[request.body\] of type \[text\] in document with id](https://discuss.elastic.co/t/failed-to-parse-field-request-body-of-type-text-in-document-with-id/343543)

<div class="topic-metadata">

**Author:** [@kaldaray](https://discuss.elastic.co/u/kaldaray)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 1:06pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-request-body-of-type-text-in-document-with-id/343543 "2023-09-21T13:06:52Z")

</div>

Hi all, i have the following log {"@timestamp": "2023-09-21T15:04:43.583+03:00","@version": "1","message": "Request log","thread\_name": "http-nio-8080-exec-9","level": "INFO","level\_value": 20000,"X-REQUEST-ID": "ca17be…

---

## [Assigning lifecycle policy to diffent indices](https://discuss.elastic.co/t/assigning-lifecycle-policy-to-diffent-indices/343527)

<div class="topic-metadata">

**Author:** [@DetlefG](https://discuss.elastic.co/u/DetlefG)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 12:36pm UTC](https://discuss.elastic.co/t/assigning-lifecycle-policy-to-diffent-indices/343527 "2023-09-21T12:36:07Z")

</div>

Hi all, in our installation filebeat is writing indices with different name depending on fields of the message which are sent to elasticsearch. For all these indices the same index template is used. Is it possible to a…

---

## [SQL Lite aggregare on non grouped Column](https://discuss.elastic.co/t/sql-lite-aggregare-on-non-grouped-column/343539)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 12:32pm UTC](https://discuss.elastic.co/t/sql-lite-aggregare-on-non-grouped-column/343539 "2023-09-21T12:32:23Z")

</div>

Hi @leandrojmp , I have a requirement where I need to apply order on a filed in Elasticsearch which is formed dynamically on the fly and it is not part of original index. My Sample document looks like { "deviceType"…

---

## [Measure CPU/Memory for custom libbeat application](https://discuss.elastic.co/t/measure-cpu-memory-for-custom-libbeat-application/343538)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 12:23pm UTC](https://discuss.elastic.co/t/measure-cpu-memory-for-custom-libbeat-application/343538 "2023-09-21T12:23:02Z")

</div>

I have built a custom beat using libbeat library that parses my application logs as intended. Is there an out of the box configuration that can be added in yml file to log cpu and memory stats for this beat. I can use Me…

---

## [How to make multiple lines of json file to single line json file](https://discuss.elastic.co/t/how-to-make-multiple-lines-of-json-file-to-single-line-json-file/343424)

<div class="topic-metadata">

**Author:** [@Narayan\_Rao](https://discuss.elastic.co/u/Narayan_Rao)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 11:29am UTC](https://discuss.elastic.co/t/how-to-make-multiple-lines-of-json-file-to-single-line-json-file/343424 "2023-09-21T11:29:08Z")

</div>

I am having issue with multiple lines json file. With single line json file able to process the file with below configuration. logstash.conf input { beats{ port =\> "5044" codec =\> json } } filter { json…

---

## [How to set number\_of\_replicas at creation index at elasticsearch?](https://discuss.elastic.co/t/how-to-set-number-of-replicas-at-creation-index-at-elasticsearch/343529)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 10:42am UTC](https://discuss.elastic.co/t/how-to-set-number-of-replicas-at-creation-index-at-elasticsearch/343529 "2023-09-21T10:42:21Z")

</div>

How to set number\_of\_replicas at creation index at elasticsearch ? I am using template with { "index": { "number\_of\_replicas": "0", "mapping": { "total\_fields": { "limit": "10000" } }, "refresh\_interval": "5s" …

---

## [Unable to authenticate Kibana to Elasticsearch on v8.0.1](https://discuss.elastic.co/t/unable-to-authenticate-kibana-to-elasticsearch-on-v8-0-1/343524)

<div class="topic-metadata">

**Author:** [@Anushree](https://discuss.elastic.co/u/Anushree)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 10:11am UTC](https://discuss.elastic.co/t/unable-to-authenticate-kibana-to-elasticsearch-on-v8-0-1/343524 "2023-09-21T10:11:26Z")

</div>

I've been attempting to establish authentication between Kibana and Elasticsearch version 8.0.1, using the "kibana\_system" user. Unfortunately, I've encountered a 401 error. My Elasticsearch instance is a single-node set…

---

## [Implement Search After in Java](https://discuss.elastic.co/t/implement-search-after-in-java/343512)

<div class="topic-metadata">

**Author:** [@Kumar25](https://discuss.elastic.co/u/Kumar25)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 9:46am UTC](https://discuss.elastic.co/t/implement-search-after-in-java/343512 "2023-09-21T09:46:42Z")

</div>

Hi All, I just migrated Elastic search from 7.17 to 8.2 in Java, but my code is breaking because many libraries are deprecated now, previously we used scroll but now I need to use search after, can you please help me on…

---

## [Elastic license](https://discuss.elastic.co/t/elastic-license/343515)

<div class="topic-metadata">

**Author:** [@DVCS](https://discuss.elastic.co/u/DVCS)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 9:46am UTC](https://discuss.elastic.co/t/elastic-license/343515 "2023-09-21T09:46:01Z")

</div>

Hi all, I have elastic cloud istance with Enterprise license. I opened a ticket to get information about ingest pipline. Support give me same info about it but also tell me that my current subscription level is outside…

---

## [Kubernetes Monitoring using Elastic-Agent](https://discuss.elastic.co/t/kubernetes-monitoring-using-elastic-agent/343521)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 9:40am UTC](https://discuss.elastic.co/t/kubernetes-monitoring-using-elastic-agent/343521 "2023-09-21T09:40:34Z")

</div>

Hello, We would like to use " Add Kubernetes integration" to our existing policy in Fleet. So, would like to understand where we need the configurations of our Kubernetes clusters which need to be monitored and authetic…

---

## [Ingesting Strange Behavior](https://discuss.elastic.co/t/ingesting-strange-behavior/343520)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 9:32am UTC](https://discuss.elastic.co/t/ingesting-strange-behavior/343520 "2023-09-21T09:32:26Z")

</div>

Hi there, I have trouble with ingesting from one of our logs. let me tell you the conditions first: we have been ingesting our logs from OCP4 to Elastic through Logstash and generally, we have 2 sites of the Elastic …

---

## [Split string variable by Mustache in Rules (Kibana)](https://discuss.elastic.co/t/split-string-variable-by-mustache-in-rules-kibana/343519)

<div class="topic-metadata">

**Author:** [@VolodymyrPopyk](https://discuss.elastic.co/u/VolodymyrPopyk)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 9:32am UTC](https://discuss.elastic.co/t/split-string-variable-by-mustache-in-rules-kibana/343519 "2023-09-21T09:32:12Z")

</div>

Is it possible split Rule action variable {{rule.name}} by Mustache. Split symbol \_ I didn´t find some way to do this!

---

## [No event.category in Winlogbeat](https://discuss.elastic.co/t/no-event-category-in-winlogbeat/343346)

<div class="topic-metadata">

**Author:** [@Ronger03](https://discuss.elastic.co/u/Ronger03)\
**Replies:** 6\
**Last updated:** [September 21, 2023, 8:33am UTC](https://discuss.elastic.co/t/no-event-category-in-winlogbeat/343346 "2023-09-21T08:33:15Z")

</div>

Hello, I configured winlogbeat to send windows events to Logstash but I see no event.category field in the events received on Logstash. Then I tried to debug by disable Logstash output, enable file output and still see…

---

## [Calculate max value of each http code](https://discuss.elastic.co/t/calculate-max-value-of-each-http-code/343019)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 8:23am UTC](https://discuss.elastic.co/t/calculate-max-value-of-each-http-code/343019 "2023-09-21T08:23:21Z")

</div>

Hello there, I have a question about visualization here. First, this is an overview of my panel as you can see there are 3 HTTP codes at 11:00 and I used breakdown by http\_status field. So, the question is how if I …

---

## [Data is not saved in Elasticsearch](https://discuss.elastic.co/t/data-is-not-saved-in-elasticsearch/343506)

<div class="topic-metadata">

**Author:** [@gwa99a9](https://discuss.elastic.co/u/gwa99a9)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 7:46am UTC](https://discuss.elastic.co/t/data-is-not-saved-in-elasticsearch/343506 "2023-09-21T07:46:28Z")

</div>

Hi All, My ELK setup is, Logstash running in k8s, version 7.16.2 Elasticsearch in vm with cluster of 4 data nodes and 2 coordinators all running version 7.16.2 Issue: Data is not saved into Elasticsearch and there ar…

---

## [Kibana SSO via Azure role permissions issue](https://discuss.elastic.co/t/kibana-sso-via-azure-role-permissions-issue/343514)

<div class="topic-metadata">

**Author:** [@najeeb](https://discuss.elastic.co/u/najeeb)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/kibana-sso-via-azure-role-permissions-issue/343514 "2023-09-21T08:17:45Z")

</div>

We've implemented single sign-on (SSO) for Kibana 8.10.1, using Azure, and created two roles "superuser" and "basic user." The "basic user" role has security tab restrictions in workspace, yet when a basic user logs in,…

---

## [How to parse multiple nested arrays](https://discuss.elastic.co/t/how-to-parse-multiple-nested-arrays/343409)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/how-to-parse-multiple-nested-arrays/343409 "2023-09-21T08:17:16Z")

</div>

Hello everyone, I am trying to parse a json document using logstash version 8.3.3. The json document has multiple nested arrays, to flatten the document split is being used inside the filter. The issue is that the split…

---

## [Kibana arbitrary code execution (ESA-2023-07) Does this affect Elasticsearch 8.5.2 with Kibana 8.5.2](https://discuss.elastic.co/t/kibana-arbitrary-code-execution-esa-2023-07-does-this-affect-elasticsearch-8-5-2-with-kibana-8-5-2/343508)

<div class="topic-metadata">

**Author:** [@Chel](https://discuss.elastic.co/u/Chel)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 7:38am UTC](https://discuss.elastic.co/t/kibana-arbitrary-code-execution-esa-2023-07-does-this-affect-elasticsearch-8-5-2-with-kibana-8-5-2/343508 "2023-09-21T07:38:32Z")

</div>

Does CVE-2023-31414 and CVE-2023-31415 affects the users using ES 8.5.2 with Kibana 8.5.2 in self managed docker container? Could you please elobarate how it can affect us like where the attacker can run the javascript w…

---

## [Logstash not create index in Elasticsearch](https://discuss.elastic.co/t/logstash-not-create-index-in-elasticsearch/343429)

<div class="topic-metadata">

**Author:** [@Raffy\_Revanza](https://discuss.elastic.co/u/Raffy_Revanza)\
**Replies:** 3\
**Last updated:** [September 21, 2023, 7:15am UTC](https://discuss.elastic.co/t/logstash-not-create-index-in-elasticsearch/343429 "2023-09-21T07:15:15Z")

</div>

So, i want to send my CSV file in my laptop to elasticsearch to build a dashboard. I have configured the conf files and it success on my logstash, but the index not readable by elastic ? why ? here's the logs "response:…

---

## [Logged out of elk](https://discuss.elastic.co/t/logged-out-of-elk/343445)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 6:46am UTC](https://discuss.elastic.co/t/logged-out-of-elk/343445 "2023-09-21T06:46:51Z")

</div>

I am logged out of my admin account of elk and am not able to log in again. any idea how to get back to my account?

---

## [Error restoring state from URL - Kibana Dashboard](https://discuss.elastic.co/t/error-restoring-state-from-url-kibana-dashboard/343281)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 5:53am UTC](https://discuss.elastic.co/t/error-restoring-state-from-url-kibana-dashboard/343281 "2023-09-21T05:53:54Z")

</div>

Hello Elastic community, I am currently facing an issue with constructing a URL for Kibana dashboards with specific filters based on a given parameter. The objective is to filter the dashboard based on the user login ar…

---

## [How to get or extract Count of fields using logstash](https://discuss.elastic.co/t/how-to-get-or-extract-count-of-fields-using-logstash/343501)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-get-or-extract-count-of-fields-using-logstash/343501 "2023-09-21T04:42:50Z")

</div>

Hello, I want to extract or get count of fields using logstash. Below is the query i have written but when i put this query in logstash it does not work this query does not give me the count. pls help GET /abc-int-apl…

---

## [Winlog beat connection issues](https://discuss.elastic.co/t/winlog-beat-connection-issues/343286)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 3:44am UTC](https://discuss.elastic.co/t/winlog-beat-connection-issues/343286 "2023-09-21T03:44:39Z")

</div>

Hi, We are seeing a large number of connections from winlogbeat to EH Kafka. We have increased the keep alive setting as per the kafka recommendation by MS to 180,000 and also changing the partition setting to random. I…

---

## [Filebeat Kafka input compatibility](https://discuss.elastic.co/t/filebeat-kafka-input-compatibility/343500)

<div class="topic-metadata">

**Author:** [@niaomingjian](https://discuss.elastic.co/u/niaomingjian)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 3:36am UTC](https://discuss.elastic.co/t/filebeat-kafka-input-compatibility/343500 "2023-09-21T03:36:29Z")

</div>

The doc says: This input works with all Kafka versions in between 0.11 and 2.8.0. Older versions might work as well, but are not supported. My kafka Cluster version is 3.3. Does kafka input of filebeat support kafk…

---

## [Aggregate function help](https://discuss.elastic.co/t/aggregate-function-help/343432)

<div class="topic-metadata">

**Author:** [@Ameeruddin\_Mohammed](https://discuss.elastic.co/u/Ameeruddin_Mohammed)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 11:55pm UTC](https://discuss.elastic.co/t/aggregate-function-help/343432 "2023-09-20T23:55:05Z")

</div>

hi, i have logs in this format and i want to start the aggregation when start comes in the line and end the aggregation when end occurs. the aggregation is based on "username". i was able to use aggregate function but…

---

## [FileBeat on OpenShift Cluster (RHOCS ) - Operation not permitted error](https://discuss.elastic.co/t/filebeat-on-openshift-cluster-rhocs-operation-not-permitted-error/343421)

<div class="topic-metadata">

**Author:** [@vinay.bommarati](https://discuss.elastic.co/u/vinay.bommarati)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 2:16am UTC](https://discuss.elastic.co/t/filebeat-on-openshift-cluster-rhocs-operation-not-permitted-error/343421 "2023-09-21T02:16:09Z")

</div>

Hi All , I have used FIleBeat docker image and created a daemon set on our Openshift cluster and gave necessary permissions to run as a privileged container as per documentation. Here is my volume and volume mount sect…

---

## [class RestHighLevelClient in package client is deprecated](https://discuss.elastic.co/t/class-resthighlevelclient-in-package-client-is-deprecated/343399)

<div class="topic-metadata">

**Author:** [@Nassereddine](https://discuss.elastic.co/u/Nassereddine)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 9:23pm UTC](https://discuss.elastic.co/t/class-resthighlevelclient-in-package-client-is-deprecated/343399 "2023-09-20T21:23:14Z")

</div>

I am upgrading Elasticsearch from 7.9.2 to 7.17.6 and then to 8.4.2, in the first step i am upgrading the es cluster to the 7.17.6 version , and compiling all other ES clients, the compilation is good for all the other …

---

## [Logstash with email output plugin "no such file to load -- net/smtp"](https://discuss.elastic.co/t/logstash-with-email-output-plugin-no-such-file-to-load-net-smtp/343490)

<div class="topic-metadata">

**Author:** [@lee.clemens](https://discuss.elastic.co/u/lee.clemens)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 9:21pm UTC](https://discuss.elastic.co/t/logstash-with-email-output-plugin-no-such-file-to-load-net-smtp/343490 "2023-09-20T21:21:47Z")

</div>

Hello, I recently upgraded RHEL 9 from logstash-8.8.2-1.x86\_64 to logstash-8.10.1-1.x86\_64 and now logstash fails to start. We are using the email output plugin and see this error in the logs: \[2023-09-20T13:48:49,401…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=416)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=418)
