# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=433

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 434

---

## [Elastic Agent fleet-managed advanced filebeat configuration](https://discuss.elastic.co/t/elastic-agent-fleet-managed-advanced-filebeat-configuration/342310)

<div class="topic-metadata">

**Author:** [@martcus](https://discuss.elastic.co/u/martcus)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:23am UTC](https://discuss.elastic.co/t/elastic-agent-fleet-managed-advanced-filebeat-configuration/342310 "2023-09-05T07:23:54Z")

</div>

Hi! We use the elastic agent fleet-managed solution extensively, especially with the custom logs integration for monitoring application logs. We need to set the filebeat close\_\*, scan\_frequency and ignore\_older paramet…

---

## [Color coding on different value](https://discuss.elastic.co/t/color-coding-on-different-value/342226)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 4\
**Last updated:** [September 5, 2023, 7:23am UTC](https://discuss.elastic.co/t/color-coding-on-different-value/342226 "2023-09-05T07:23:31Z")

</div>

In my document I have 3 fields, first is timestamp, second is absolute\_value and third is percentage\_value. I want show this data in Table type visualization . So in rows I am show timestamp and in metrics i want displa…

---

## [Logstash in k8s - parsing nested json from MongoDB and get every nested json as separated field](https://discuss.elastic.co/t/logstash-in-k8s-parsing-nested-json-from-mongodb-and-get-every-nested-json-as-separated-field/341755)

<div class="topic-metadata">

**Author:** [@Denis\_Lezgin](https://discuss.elastic.co/u/Denis_Lezgin)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:11am UTC](https://discuss.elastic.co/t/logstash-in-k8s-parsing-nested-json-from-mongodb-and-get-every-nested-json-as-separated-field/341755 "2023-09-05T07:11:15Z")

</div>

Hi there, I'm using Logstash to take documents from specific MongoDB collection, and save it to Elasticsearch. Nested fields are being saved to "log\_entry" as one JSON, starting with "BSON" or "ID", depends on manipul…

---

## [Bulk inserts more documents than given](https://discuss.elastic.co/t/bulk-inserts-more-documents-than-given/342280)

<div class="topic-metadata">

**Author:** [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 6:30am UTC](https://discuss.elastic.co/t/bulk-inserts-more-documents-than-given/342280 "2023-09-05T06:30:29Z")

</div>

Elasticsearched configured in single-node mode, I have ~1 million elements, but after bulk insert operation I see 10 million elements. I use this python code: def generate\_docs(data): for item in data: doc =…

---

## [Bulk API hangs forever python cloud function](https://discuss.elastic.co/t/bulk-api-hangs-forever-python-cloud-function/342221)

<div class="topic-metadata">

**Author:** [@Thani\_Ath\_Nain\_Khurs](https://discuss.elastic.co/u/Thani_Ath_Nain_Khurs)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 6:25am UTC](https://discuss.elastic.co/t/bulk-api-hangs-forever-python-cloud-function/342221 "2023-09-05T06:25:50Z")

</div>

I am new to Elasticsearch and this issue is driving me crazy. My use case involves getting all documents in elastic-search, min-max normalising some fields and then updating documents in bulk but my bulk call just hangs …

---

## [Key value searching](https://discuss.elastic.co/t/key-value-searching/342279)

<div class="topic-metadata">

**Author:** [@Katya](https://discuss.elastic.co/u/Katya)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 6:12am UTC](https://discuss.elastic.co/t/key-value-searching/342279 "2023-09-05T06:12:18Z")

</div>

Hello everyone. I'm trying to find logs in Kibana which contain the key and value in the table's key, but don't know which syntax is correct for this search. Example: The table contains the key "body". "body" is a JS…

---

## [Elastic.Clients.Elasticsearch .NET client - calling Vector tile search API](https://discuss.elastic.co/t/elastic-clients-elasticsearch-net-client-calling-vector-tile-search-api/341422)

<div class="topic-metadata">

**Author:** [@Jarrod](https://discuss.elastic.co/u/Jarrod)\
**Replies:** 5\
**Last updated:** [September 5, 2023, 5:10am UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-net-client-calling-vector-tile-search-api/341422 "2023-09-05T05:10:55Z")

</div>

I am trying to call the Vector tile search API using the new v8 .NET client but receiving an exception. Specifically 8.9.2 as of writing. I understand it doesn't have official support in the client, but it appears I sho…

---

## [What does it mean a shard executing a search locally?](https://discuss.elastic.co/t/what-does-it-mean-a-shard-executing-a-search-locally/342298)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 4:31am UTC](https://discuss.elastic.co/t/what-does-it-mean-a-shard-executing-a-search-locally/342298 "2023-09-05T04:31:17Z")

</div>

Hi Folks, I need some help understanding Query phase of distributed search in ES better, step 2 specifically. Node 3 forwards the search request to a primary or replica copy of every shard in the index. Each shard ex…

---

## [New Control Panel widget not working in Kibana](https://discuss.elastic.co/t/new-control-panel-widget-not-working-in-kibana/340255)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 4:25am UTC](https://discuss.elastic.co/t/new-control-panel-widget-not-working-in-kibana/340255 "2023-09-05T04:25:07Z")

</div>

Hi Team, in 8.x version, Elastic has introduced controls option in kibana dashboard itself. however, in below case, it is not depicting the expected result. if i use control via visualization, it is working as expected…

---

## [Create a widget that change the color especially for uptime dashboard](https://discuss.elastic.co/t/create-a-widget-that-change-the-color-especially-for-uptime-dashboard/340323)

<div class="topic-metadata">

**Author:** [@sixsenseninja](https://discuss.elastic.co/u/sixsenseninja)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 3:41am UTC](https://discuss.elastic.co/t/create-a-widget-that-change-the-color-especially-for-uptime-dashboard/340323 "2023-09-05T03:41:58Z")

</div>

Is there a way to create a widget in Kibana that able to change its color when hit certain threshold? for Example below, we have widget that will turn to orange when hit 80% and red if it is hit 90%. Below was captured …

---

## [How does kibana UI figures out that it has to scale up the interval if the query is going to results into too many buckets exception](https://discuss.elastic.co/t/how-does-kibana-ui-figures-out-that-it-has-to-scale-up-the-interval-if-the-query-is-going-to-results-into-too-many-buckets-exception/342193)

<div class="topic-metadata">

**Author:** [@S\_Star](https://discuss.elastic.co/u/S_Star)\
**Replies:** 4\
**Last updated:** [September 5, 2023, 12:03am UTC](https://discuss.elastic.co/t/how-does-kibana-ui-figures-out-that-it-has-to-scale-up-the-interval-if-the-query-is-going-to-results-into-too-many-buckets-exception/342193 "2023-09-05T00:03:19Z")

</div>

How does Kibana UI figures out that it has to scale up the interval if the query is going to results into too many buckets exception ? Is it some fixed logic or it determines this by actually making a query to ES which …

---

## [Connecting to elastic](https://discuss.elastic.co/t/connecting-to-elastic/342288)

<div class="topic-metadata">

**Author:** [@Guilhermitos](https://discuss.elastic.co/u/Guilhermitos)\
**Replies:** 3\
**Last updated:** [September 4, 2023, 11:34pm UTC](https://discuss.elastic.co/t/connecting-to-elastic/342288 "2023-09-04T23:34:28Z")

</div>

Hi guys, i have some doubt about connecting elasticsearch on python, is it really needed to have ca\_certs? i have tried to use verify\_certs=False but i'm getting an error, in this case is SSLError(\[SSL: DH\_KEY\_TOO\_SMALL\]…

---

## [Looking for developers for a UX Research study!](https://discuss.elastic.co/t/looking-for-developers-for-a-ux-research-study/342272)

<div class="topic-metadata">

**Author:** [@Gabriel\_Hughes](https://discuss.elastic.co/u/Gabriel_Hughes)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 8:24pm UTC](https://discuss.elastic.co/t/looking-for-developers-for-a-ux-research-study/342272 "2023-09-04T20:24:36Z")

</div>

Hi all, The Search product team at Elastic is looking for developers with experience building applications using Elasticsearch to participate in a study on the application development experience with Elastic. Our goal i…

---

## [Tomcat access log analysis](https://discuss.elastic.co/t/tomcat-access-log-analysis/341688)

<div class="topic-metadata">

**Author:** [@Brian\_Michelsen](https://discuss.elastic.co/u/Brian_Michelsen)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 5:39pm UTC](https://discuss.elastic.co/t/tomcat-access-log-analysis/341688 "2023-09-04T17:39:14Z")

</div>

Hi, I have setup Elasticseach, Logstash and Kibana to analyse response times on a application. The pattern of the access log is: %a %{request.id}r %{request.username}r %t &quot;%m %U%{sanitized.query}r %H&quot; %s %b %…

---

## [Deploying elastic agent apm server on kubernates from fleet server](https://discuss.elastic.co/t/deploying-elastic-agent-apm-server-on-kubernates-from-fleet-server/342284)

<div class="topic-metadata">

**Author:** [@Mansoor\_Ur\_Rehman](https://discuss.elastic.co/u/Mansoor_Ur_Rehman)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 6:44pm UTC](https://discuss.elastic.co/t/deploying-elastic-agent-apm-server-on-kubernates-from-fleet-server/342284 "2023-09-04T18:44:24Z")

</div>

i have setup a elasticsearch, kibana and fleet server with elasticsearch self signed certificates successfully, i have also deployed a apm integration on a server with fleet server. the apm server listens on port http:/…

---

## [Adding Links to a Dashboard When the Linked Dashboards are in a Different Space](https://discuss.elastic.co/t/adding-links-to-a-dashboard-when-the-linked-dashboards-are-in-a-different-space/341407)

<div class="topic-metadata">

**Author:** [@kevfar](https://discuss.elastic.co/u/kevfar)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 5:25pm UTC](https://discuss.elastic.co/t/adding-links-to-a-dashboard-when-the-linked-dashboards-are-in-a-different-space/341407 "2023-09-04T17:25:07Z")

</div>

Hello! I am working on a Kibana dashboard (version 7.17) that contains links to two other dashboards. One of the links works, however the second linked dashboard exists in a separate space. Also, depending on the environ…

---

## [Logstash dateparse error](https://discuss.elastic.co/t/logstash-dateparse-error/342209)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [September 4, 2023, 5:16pm UTC](https://discuss.elastic.co/t/logstash-dateparse-error/342209 "2023-09-04T17:16:42Z")

</div>

I have a logstash pipleline working from years. worked since 7.1 till 8.5.3 (no problem on any upgrade) two month ago when I upgraded to 8.5.3 it was still working fine. suddenly it stop working due to date parsing fai…

---

## [Multi-node cluster across multiple virtual machines](https://discuss.elastic.co/t/multi-node-cluster-across-multiple-virtual-machines/341951)

<div class="topic-metadata">

**Author:** [@Cody](https://discuss.elastic.co/u/Cody)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 7:53am UTC](https://discuss.elastic.co/t/multi-node-cluster-across-multiple-virtual-machines/341951 "2023-08-30T07:53:09Z")

</div>

Hello, i am trying to run a 3 node cluster for Elasticsearch and kibana across 3 Virtual machines, each VM running 1 node each. I refer to the documentation " Start a multi-node cluster with Docker Compose" at https://ww…

---

## [(1) Can Kibana users enter in-line comments with # or // alongside query and (2) will these be picked up by query logging?](https://discuss.elastic.co/t/1-can-kibana-users-enter-in-line-comments-with-or-alongside-query-and-2-will-these-be-picked-up-by-query-logging/340565)

<div class="topic-metadata">

**Author:** [@Interspektikal](https://discuss.elastic.co/u/Interspektikal)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 4:24pm UTC](https://discuss.elastic.co/t/1-can-kibana-users-enter-in-line-comments-with-or-alongside-query-and-2-will-these-be-picked-up-by-query-logging/340565 "2023-09-04T16:24:42Z")

</div>

I've searched google and the GitHub repo alongside the forums but haven't been able to find an answer to this question (doesn't help searching "comment" brings up French posts asking "how" to do something!). From search…

---

## [Intermittent exception in index call](https://discuss.elastic.co/t/intermittent-exception-in-index-call/340903)

<div class="topic-metadata">

**Author:** [@Luiz\_Basile](https://discuss.elastic.co/u/Luiz_Basile)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 4:06pm UTC](https://discuss.elastic.co/t/intermittent-exception-in-index-call/340903 "2023-09-04T16:06:00Z")

</div>

We are using Elasticsearch java, in a lambda function. The below log is in lambda Apparently this exception is happening when you use the Elastic of other component and quickly trigger the lambda function. Any suggestio…

---

## [How to grab subset parts of a string, using its keys to map onto return value](https://discuss.elastic.co/t/how-to-grab-subset-parts-of-a-string-using-its-keys-to-map-onto-return-value/340855)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 3:35pm UTC](https://discuss.elastic.co/t/how-to-grab-subset-parts-of-a-string-using-its-keys-to-map-onto-return-value/340855 "2023-09-04T15:35:47Z")

</div>

Trying to do something which should be simple. Using Painless, take a value like "1.4" and another like "1.5", and using the first and second number, pop the name from a dictionary. I know there are methods like substr, …

---

## [Cleaning up of indexes](https://discuss.elastic.co/t/cleaning-up-of-indexes/340885)

<div class="topic-metadata">

**Author:** [@vishnu\_ishpujani](https://discuss.elastic.co/u/vishnu_ishpujani)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 3:32pm UTC](https://discuss.elastic.co/t/cleaning-up-of-indexes/340885 "2023-09-04T15:32:57Z")

</div>

Hi , I need to cleanup indexes data from Elastic cluster, what is the best way to perform the task as deleting from Dev tools is taking too much time and affecting cluster as well?

---

## [Kibana\_system password reset but only affected one master node in the ELK cluster](https://discuss.elastic.co/t/kibana-system-password-reset-but-only-affected-one-master-node-in-the-elk-cluster/342205)

<div class="topic-metadata">

**Author:** [@vpelagatti](https://discuss.elastic.co/u/vpelagatti)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 2:45pm UTC](https://discuss.elastic.co/t/kibana-system-password-reset-but-only-affected-one-master-node-in-the-elk-cluster/342205 "2023-09-04T14:45:02Z")

</div>

Hi, I'm using an ELK cluster with two master nodes elastic01 and elastic02. Cluster has been upgraded from version 7.17 to 8.2. I've reset kibana\_system password on elastic01 but it didn't reset on second master node (e…

---

## [Add Multiple CSV Files to Kibana Dsahboard](https://discuss.elastic.co/t/add-multiple-csv-files-to-kibana-dsahboard/342115)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 2:35pm UTC](https://discuss.elastic.co/t/add-multiple-csv-files-to-kibana-dsahboard/342115 "2023-09-04T14:35:55Z")

</div>

Hi Team, Is there any way to upload multiple CSV files into kibana dashboard? Thanks, Debasis

---

## [Kibana login with service account](https://discuss.elastic.co/t/kibana-login-with-service-account/342130)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 3\
**Last updated:** [September 4, 2023, 2:23pm UTC](https://discuss.elastic.co/t/kibana-login-with-service-account/342130 "2023-09-04T14:23:42Z")

</div>

We have embedded kibana dashboard into our application and do not want to show login page of kibana to the user once the user has already logged-in to the application. We are using basic license of Elasticsearch. Can w…

---

## [Fortinet FortiGate Firewall Logs integration](https://discuss.elastic.co/t/fortinet-fortigate-firewall-logs-integration/342116)

<div class="topic-metadata">

**Author:** [@francesco.amato](https://discuss.elastic.co/u/francesco.amato)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 12:40pm UTC](https://discuss.elastic.co/t/fortinet-fortigate-firewall-logs-integration/342116 "2023-09-01T12:40:00Z")

</div>

Hi to all I can't figure out why the Fortigate Firewall Logs Integration doesn't send logs to my Elasticsearch server I can use the filebeat module but not the fleet integration I have setup the Fortigate Firewall to …

---

## [Choose the second Value in Query Table for Canvas](https://discuss.elastic.co/t/choose-the-second-value-in-query-table-for-canvas/342059)

<div class="topic-metadata">

**Author:** [@Rademu1349](https://discuss.elastic.co/u/Rademu1349)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 1:23pm UTC](https://discuss.elastic.co/t/choose-the-second-value-in-query-table-for-canvas/342059 "2023-09-04T13:23:14Z")

</div>

Hello all, I am trying to display a top 3 ranking in a canvas. For this I need the highest score, the middle score and the lowest score. The highest score is correctly queried but I am not able to determine the 2nd sco…

---

## [java.lang.IllegalArgumentException: Mapping file \_settings.json does not exist for elasticsearch version 8](https://discuss.elastic.co/t/java-lang-illegalargumentexception-mapping-file-settings-json-does-not-exist-for-elasticsearch-version-8/340910)

<div class="topic-metadata">

**Author:** [@prashant\_chaturvedi](https://discuss.elastic.co/u/prashant_chaturvedi)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 11:41am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-mapping-file-settings-json-does-not-exist-for-elasticsearch-version-8/340910 "2023-08-16T11:41:01Z")

</div>

i have installed elasticsearch(8.9.0) and fscrawler (2.10) which shows that its been tested in document but still the fscrawaler is throwing the below error "java.lang.IllegalArgumentException: Mapping file \_settings.js…

---

## [Run remote KQL query](https://discuss.elastic.co/t/run-remote-kql-query/341615)

<div class="topic-metadata">

**Author:** [@mladen](https://discuss.elastic.co/u/mladen)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 1:19pm UTC](https://discuss.elastic.co/t/run-remote-kql-query/341615 "2023-09-04T13:19:42Z")

</div>

Hi, We have some saved searches written using Kibana Query Language in Kibana. Now we have an idea to automatize the process of getting data. Idea is to create some bash scripts and using curl to run saved queries in Ki…

---

## [Observing index of an Elastic node with Metricbeat not possible?](https://discuss.elastic.co/t/observing-index-of-an-elastic-node-with-metricbeat-not-possible/335791)

<div class="topic-metadata">

**Author:** [@Zaphod](https://discuss.elastic.co/u/Zaphod)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 12:35pm UTC](https://discuss.elastic.co/t/observing-index-of-an-elastic-node-with-metricbeat-not-possible/335791 "2023-09-04T12:35:34Z")

</div>

I would like to monitor an existing Elasticsearch node (ES A) (in Docker container) to control the performance concerning a distinct index, because the CPU of the node increases to 200%-500% intermittently for a few hour…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=432)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=434)
