# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=431

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 432

---

## [I have different indexes that contain different fields I need to aggregate all of them, what i mean i have index1 and index2 in index1 I have ch and in index2 I have ch2 how can i add ch to ch2 with script or script field](https://discuss.elastic.co/t/i-have-different-indexes-that-contain-different-fields-i-need-to-aggregate-all-of-them-what-i-mean-i-have-index1-and-index2-in-index1-i-have-ch-and-in-index2-i-have-ch2-how-can-i-add-ch-to-ch2-with-script-or-script-field/341959)

<div class="topic-metadata">

**Author:** [@ghramalhajyalhajy](https://discuss.elastic.co/u/ghramalhajyalhajy)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 9:05am UTC](https://discuss.elastic.co/t/i-have-different-indexes-that-contain-different-fields-i-need-to-aggregate-all-of-them-what-i-mean-i-have-index1-and-index2-in-index1-i-have-ch-and-in-index2-i-have-ch2-how-can-i-add-ch-to-ch2-with-script-or-script-field/341959 "2023-08-30T09:05:22Z")

</div>

search index PUT index1/\_doc/1 { "foo": "bar" } GET index2/\_search { "query": { "match": { "foo": "bar" } } }

---

## [Authentication Error setting up Eland on Jupyter Notebook](https://discuss.elastic.co/t/authentication-error-setting-up-eland-on-jupyter-notebook/342404)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 1:06pm UTC](https://discuss.elastic.co/t/authentication-error-setting-up-eland-on-jupyter-notebook/342404 "2023-09-06T13:06:56Z")

</div>

Hi, I am trying to use Eland on Jupyter Notebook. Here is what I wrote on Jupyter import eland as ed import pandas as pd import numpy as np from elasticsearch import Elasticsearch def json(x): import json print…

---

## [Dev Tool response export file](https://discuss.elastic.co/t/dev-tool-response-export-file/342414)

<div class="topic-metadata">

**Author:** [@Mr.Unal](https://discuss.elastic.co/u/Mr.Unal)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 12:59pm UTC](https://discuss.elastic.co/t/dev-tool-response-export-file/342414 "2023-09-06T12:59:21Z")

</div>

Hello I have a lot table in kibana dashboard weekly. I want to get these figures in my excel file with automatically. I tried to use dev tools console but I couldn't export csv format response. Is there any method for …

---

## [PDF document ingestion into elastic](https://discuss.elastic.co/t/pdf-document-ingestion-into-elastic/342443)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 12:44pm UTC](https://discuss.elastic.co/t/pdf-document-ingestion-into-elastic/342443 "2023-09-06T12:44:11Z")

</div>

Hello community How to import word, pdf documents into elastic??

---

## [Kibana not loading....on domain](https://discuss.elastic.co/t/kibana-not-loading-on-domain/342066)

<div class="topic-metadata">

**Author:** [@Saili\_Bakalkar](https://discuss.elastic.co/u/Saili_Bakalkar)\
**Replies:** 4\
**Last updated:** [September 6, 2023, 12:41pm UTC](https://discuss.elastic.co/t/kibana-not-loading-on-domain/342066 "2023-09-06T12:41:16Z")

</div>

I have my website running on port 8080, and on a separate server there is kibana dashboard which is on port 5601. The server where i have my website has httpd configured in such a way that it has two virtual host for 44…

---

## [Node connection to cluster is being refused (AWS ECS)](https://discuss.elastic.co/t/node-connection-to-cluster-is-being-refused-aws-ecs/341989)

<div class="topic-metadata">

**Author:** [@stanyzra](https://discuss.elastic.co/u/stanyzra)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 12:20pm UTC](https://discuss.elastic.co/t/node-connection-to-cluster-is-being-refused-aws-ecs/341989 "2023-09-06T12:20:18Z")

</div>

Hello, I'm trying to deploy a dockerized 3 node Elasticsearch (8.9.1) cluster in AWS ECS. The cluster's bootstraping seens to be okay, but when I try to join a node into it, I get a connection refused error. These are …

---

## [Question elk stack](https://discuss.elastic.co/t/question-elk-stack/342411)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 12:07pm UTC](https://discuss.elastic.co/t/question-elk-stack/342411 "2023-09-06T12:07:52Z")

</div>

Hello , I HAVE A QUESTION IF ANY ONE khnwo please help me how i drop an empty value in the field elk stack (i have a field resultat contain value recu,ajourné,admis ,false) i wont to drop only the value false but with …

---

## [Mapping file \_settings.json does not exist for elasticsearch version 8 in](https://discuss.elastic.co/t/mapping-file-settings-json-does-not-exist-for-elasticsearch-version-8-in/340908)

<div class="topic-metadata">

**Author:** [@prashant\_chaturvedi](https://discuss.elastic.co/u/prashant_chaturvedi)\
**Replies:** 5\
**Last updated:** [September 6, 2023, 12:00pm UTC](https://discuss.elastic.co/t/mapping-file-settings-json-does-not-exist-for-elasticsearch-version-8-in/340908 "2023-09-06T12:00:25Z")

</div>

I have installed elasticsearch search 8.9.0 and fscrawaler 2.10 -SNAPSHOT which in the document page says that this is test but still i get the error java.lang.IllegalArgumentException: Mapping file \_settings.json does …

---

## [Elasticsearch storage on containers](https://discuss.elastic.co/t/elasticsearch-storage-on-containers/340829)

<div class="topic-metadata">

**Author:** [@anderstr1](https://discuss.elastic.co/u/anderstr1)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 11:33am UTC](https://discuss.elastic.co/t/elasticsearch-storage-on-containers/340829 "2023-09-06T11:33:40Z")

</div>

Our goal is to run Elasticsearch on docker containers. Until now we have only managed to run it properly on an Azure Virtual Machine. Our challenge is regarding storage. When using Elasticsearch, I understand that a typ…

---

## [Configuring a Cluster with public certificates](https://discuss.elastic.co/t/configuring-a-cluster-with-public-certificates/342430)

<div class="topic-metadata">

**Author:** [@RuthGl](https://discuss.elastic.co/u/RuthGl)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 10:38am UTC](https://discuss.elastic.co/t/configuring-a-cluster-with-public-certificates/342430 "2023-09-06T10:38:27Z")

</div>

Hello! How to set up a cluster with public certificates? I have certificates from AlphaSSL with wildcard \*.mydomain.com : root\_ca.crt intermediate.crt mydomain.key mydomain.crt How can I properly configure transpor…

---

## [How to see the list of users who accessed to a particular dashboard in Kibana?](https://discuss.elastic.co/t/how-to-see-the-list-of-users-who-accessed-to-a-particular-dashboard-in-kibana/342324)

<div class="topic-metadata">

**Author:** [@RJG](https://discuss.elastic.co/u/RJG)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 10:28am UTC](https://discuss.elastic.co/t/how-to-see-the-list-of-users-who-accessed-to-a-particular-dashboard-in-kibana/342324 "2023-09-06T10:28:35Z")

</div>

Can we see the list of users and the accessed time for a particular dashboard in Kibana GUI

---

## [How to get the field value from an object](https://discuss.elastic.co/t/how-to-get-the-field-value-from-an-object/342246)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-to-get-the-field-value-from-an-object/342246 "2023-09-06T09:57:43Z")

</div>

i've a case\_number which has a field "task\_id". i need to use that id to get all task details. i tried to get the value , it is empty. please help me out. Here is the Elasticsearch pulled data { "\_index": "logs…

---

## [Elasticsearch has accumulated a lot of pending tasks, and stop indexing](https://discuss.elastic.co/t/elasticsearch-has-accumulated-a-lot-of-pending-tasks-and-stop-indexing/341414)

<div class="topic-metadata">

**Author:** [@ShanYang](https://discuss.elastic.co/u/ShanYang)\
**Replies:** 12\
**Last updated:** [September 6, 2023, 9:16am UTC](https://discuss.elastic.co/t/elasticsearch-has-accumulated-a-lot-of-pending-tasks-and-stop-indexing/341414 "2023-09-06T09:16:53Z")

</div>

Phenomenon: When generating a new index across days, elasticsearch stop indexing. The cluster health show green but with many pending task. Used Get \_tasks?, I saw thousands transport task and hundreds direct task. Clu…

---

## [Kibana won't open on web - This site can’t be reached, kibana.pci.local took too long to respond](https://discuss.elastic.co/t/kibana-wont-open-on-web-this-site-can-t-be-reached-kibana-pci-local-took-too-long-to-respond/342408)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 8:51am UTC](https://discuss.elastic.co/t/kibana-wont-open-on-web-this-site-can-t-be-reached-kibana-pci-local-took-too-long-to-respond/342408 "2023-09-06T08:51:17Z")

</div>

Hi, I have EFK stack on Kubernetes in production and everything was working fine until this morning, now Kibana won't open on web and there weren't any errors in the logs. After I restarted Kibana this is in the logs: \[…

---

## [Filebeat not sending suricata logs to elasticsearch](https://discuss.elastic.co/t/filebeat-not-sending-suricata-logs-to-elasticsearch/342399)

<div class="topic-metadata">

**Author:** [@Dhruv\_Kumar](https://discuss.elastic.co/u/Dhruv_Kumar)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 8:44am UTC](https://discuss.elastic.co/t/filebeat-not-sending-suricata-logs-to-elasticsearch/342399 "2023-09-06T08:44:51Z")

</div>

Hello . I have a server in which i am running suricata . In the same server I have installed filebeat which i am using to send my suricata logs to Elasticsearch .I have setup es and kibana inside a vm .After starting eve…

---

## [How to Select only Last Day Filters in LENS](https://discuss.elastic.co/t/how-to-select-only-last-day-filters-in-lens/341436)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 8:19am UTC](https://discuss.elastic.co/t/how-to-select-only-last-day-filters-in-lens/341436 "2023-09-06T08:19:24Z")

</div>

Hello Team @Marco\_Liberati When I apply the parameter "reducedTimeRange='1d'" to select values for a variable, it's currently retrieving data from the last 24 hours instead of the specific time range I want, which is fr…

---

## [Empty row in Security Alerts table](https://discuss.elastic.co/t/empty-row-in-security-alerts-table/342407)

<div class="topic-metadata">

**Author:** [@francesco.amato](https://discuss.elastic.co/u/francesco.amato)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 8:17am UTC](https://discuss.elastic.co/t/empty-row-in-security-alerts-table/342407 "2023-09-06T08:17:23Z")

</div>

Hi to all I have a strange problem with the Security Alerts page I have empty rows in the bottom table, only in one page. If I change page, I see my records. I don't know if it is a problem in my Elastic instance or …

---

## [Filebeat how to delete indexes automaticality after a few days](https://discuss.elastic.co/t/filebeat-how-to-delete-indexes-automaticality-after-a-few-days/342308)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 7:47am UTC](https://discuss.elastic.co/t/filebeat-how-to-delete-indexes-automaticality-after-a-few-days/342308 "2023-09-06T07:47:51Z")

</div>

Hello I have installed ELK and I would like to optimise it a little bit. CentOS Linux release 7.9.2009 (Core) bin/kibana --version 8.6.2 bin/elasticsearch --version Version: 8.6.2, Build: I'm using filebeat and aft…

---

## [ES server specs for a good search performance](https://discuss.elastic.co/t/es-server-specs-for-a-good-search-performance/342355)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 7:39am UTC](https://discuss.elastic.co/t/es-server-specs-for-a-good-search-performance/342355 "2023-09-06T07:39:43Z")

</div>

So we have a situation where we want to make a mini-search engine for our project - the total volume of the data being 5 PB. We want to create a backup, so the total size to be needed overall is 10 PB, approximately. The…

---

## [Elastic agent Failed Connect Failed to connect to backoff 401 Unauthorized](https://discuss.elastic.co/t/elastic-agent-failed-connect-failed-to-connect-to-backoff-401-unauthorized/342395)

<div class="topic-metadata">

**Author:** [@Khunakorn](https://discuss.elastic.co/u/Khunakorn)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 6:33am UTC](https://discuss.elastic.co/t/elastic-agent-failed-connect-failed-to-connect-to-backoff-401-unauthorized/342395 "2023-09-06T06:33:06Z")

</div>

{"log.level":"error","@timestamp":"2023-09-06T04:35:47.597Z","message":"Failed to connect to backoff(elasticsearch(cloud.com:443)): 401 Unauthorized: {"error":{"root\_cause":\[{"type":"security\_exception","reason":"unable …

---

## [Not all fields are indexed](https://discuss.elastic.co/t/not-all-fields-are-indexed/342369)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 5:34am UTC](https://discuss.elastic.co/t/not-all-fields-are-indexed/342369 "2023-09-06T05:34:19Z")

</div>

I indexed several raw json documents using BulkRequest index BinaryData from json string. If I run a match all query, I am getting back all my documents. However only certain fields are searchable. Why aren't all field…

---

## [Does Elastic Agent support Docker label based autodiscovery?](https://discuss.elastic.co/t/does-elastic-agent-support-docker-label-based-autodiscovery/342383)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 11:13pm UTC](https://discuss.elastic.co/t/does-elastic-agent-support-docker-label-based-autodiscovery/342383 "2023-09-05T23:13:24Z")

</div>

While experimenting with using Metricbeat and Filebeat directly, I found the documentation on hint based auto-discovery that would send the docker logs and metrics through the correct pipelines for different modules. Lik…

---

## [Advanced Watch](https://discuss.elastic.co/t/advanced-watch/338906)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 7\
**Last updated:** [September 5, 2023, 9:30pm UTC](https://discuss.elastic.co/t/advanced-watch/338906 "2023-09-05T21:30:01Z")

</div>

Hi, I am using ELK in Supply Chain Traceability Company. 1 -- I wanted to create a Watcher to send "Alerts" from Kibana for the inventory items and it should be continuous alerts through email notification. Suppose a…

---

## [Block java.exe outbound in firewall](https://discuss.elastic.co/t/block-java-exe-outbound-in-firewall/342374)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:55pm UTC](https://discuss.elastic.co/t/block-java-exe-outbound-in-firewall/342374 "2023-09-05T19:55:19Z")

</div>

Hi. I have an Elastic cluster with 4 nodes, all on Windows Server. We are using Windows Defender Firewall to limit access to ports 9200 and 9300 between the nodes. We have now been asked if we can limit the OpenJDK java.…

---

## [ElasticSearch TASKS API - Task is given to a different client node after 1 minute of execution](https://discuss.elastic.co/t/elasticsearch-tasks-api-task-is-given-to-a-different-client-node-after-1-minute-of-execution/340801)

<div class="topic-metadata">

**Author:** [@es2learn](https://discuss.elastic.co/u/es2learn)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:41pm UTC](https://discuss.elastic.co/t/elasticsearch-tasks-api-task-is-given-to-a-different-client-node-after-1-minute-of-execution/340801 "2023-09-05T19:41:43Z")

</div>

Hi Team, I had a weird observation in our Elasticsearch Cluster. We have an ES Query that will be executed from a python script. When the Query is being fired from python, right away a task will get created under GET /…

---

## [Services error](https://discuss.elastic.co/t/services-error/342372)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:41pm UTC](https://discuss.elastic.co/t/services-error/342372 "2023-09-05T19:41:08Z")

</div>

When I try to start the winlogbeat service on windows server 2012 and 2016 : throwing the error : Windows could not start the winlogbeat service on local computer. Error 1067 : The process Terminated unexpectedly. Plea…

---

## [Cisco filebeat module not listening on port as configured](https://discuss.elastic.co/t/cisco-filebeat-module-not-listening-on-port-as-configured/341988)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 18\
**Last updated:** [September 5, 2023, 7:26pm UTC](https://discuss.elastic.co/t/cisco-filebeat-module-not-listening-on-port-as-configured/341988 "2023-09-05T19:26:40Z")

</div>

We have an existing functional Elastic instance running with Filebeat 8.9, running on Ubuntu 22.04. We're attempting to add Cisco logs using the Cisco filebeat module. However, we're not seeing any logs coming in. We hav…

---

## [Windows server 2012 and 2008](https://discuss.elastic.co/t/windows-server-2012-and-2008/342371)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 7:11pm UTC](https://discuss.elastic.co/t/windows-server-2012-and-2008/342371 "2023-09-05T19:11:21Z")

</div>

Hi Everyone, Recently start working on Kibana. I have created the dashboard and working on windows server 2008 and 2012 looking for advice. which file do I need to install winlogbeat is there any compatible version of w…

---

## [Difficulty Making a REST API Call to ElasticSearch](https://discuss.elastic.co/t/difficulty-making-a-rest-api-call-to-elasticsearch/342296)

<div class="topic-metadata">

**Author:** [@Conrad414](https://discuss.elastic.co/u/Conrad414)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 6:51pm UTC](https://discuss.elastic.co/t/difficulty-making-a-rest-api-call-to-elasticsearch/342296 "2023-09-05T18:51:14Z")

</div>

Hello, I'm currently trying to follow the steps for installing Elasticsearch with Docker Install Elasticsearch with Docker | Elasticsearch Guide \[8.11\] | Elastic and I'm struggling with making a REST API call to Elastics…

---

## [Stored fields and SearchResponse](https://discuss.elastic.co/t/stored-fields-and-searchresponse/342062)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 7\
**Last updated:** [September 5, 2023, 7:00pm UTC](https://discuss.elastic.co/t/stored-fields-and-searchresponse/342062 "2023-09-05T19:00:34Z")

</div>

Example: SearchResponse\<ObjectNode\> searchResponse = elasticsearchClient.search(searchRequest, ObjectNode.class); Hit\<ObjectNode\> hit = searchResponse.hits().hits().get(0); Map\<String, JsonData\> fields = hit.fields(); J…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=430)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=432)
