# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=440

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 441

---

## [Why Elastic Search allow to put number in text field?](https://discuss.elastic.co/t/why-elastic-search-allow-to-put-number-in-text-field/341756)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 3:04pm UTC](https://discuss.elastic.co/t/why-elastic-search-allow-to-put-number-in-text-field/341756 "2023-08-27T15:04:54Z")

</div>

Hi, I have mapping like this: "mappings": { "dynamic": "strict", "properties": { "name": { "typ…

---

## [How to use your default defined layer as input for our simple mapbox GL map?](https://discuss.elastic.co/t/how-to-use-your-default-defined-layer-as-input-for-our-simple-mapbox-gl-map/340382)

<div class="topic-metadata">

**Author:** [@jzarei1996](https://discuss.elastic.co/u/jzarei1996)\
**Replies:** 15\
**Last updated:** [August 27, 2023, 1:26pm UTC](https://discuss.elastic.co/t/how-to-use-your-default-defined-layer-as-input-for-our-simple-mapbox-gl-map/340382 "2023-08-27T13:26:02Z")

</div>

Hi everyone. We want to create a sample map from the Mapbox GL JS library in our own plugin according to its documentation. We want a simple mode and during the review we found out that your Maps plugin also uses this li…

---

## [Logstash ingesting Netflow traffic, the probability of parsing errors increases with larger data volumes](https://discuss.elastic.co/t/logstash-ingesting-netflow-traffic-the-probability-of-parsing-errors-increases-with-larger-data-volumes/340539)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 12:02pm UTC](https://discuss.elastic.co/t/logstash-ingesting-netflow-traffic-the-probability-of-parsing-errors-increases-with-larger-data-volumes/340539 "2023-08-27T12:02:45Z")

</div>

I am using Logstash to ingest Netflow traffic and after parsing, I store the data in Kafka. As the Netflow traffic I am ingesting increases, the probability of incorrect structured data being parsed also increases. Howev…

---

## [Presumably udp input threads are soaking up cpu](https://discuss.elastic.co/t/presumably-udp-input-threads-are-soaking-up-cpu/341590)

<div class="topic-metadata">

**Author:** [@udp\_issues\_are\_one](https://discuss.elastic.co/u/udp_issues_are_one)\
**Replies:** 5\
**Last updated:** [August 27, 2023, 11:47am UTC](https://discuss.elastic.co/t/presumably-udp-input-threads-are-soaking-up-cpu/341590 "2023-08-27T11:47:32Z")

</div>

We have logstash running on ubuntu, logstash version 8.4.1 from the ubuntu repositories. We have a number of pipelines running, most of them work fine but the CPU utilization on the box is a bit high. From the linux co…

---

## [Is it possible to search only when there are a certain number of terms in the query?](https://discuss.elastic.co/t/is-it-possible-to-search-only-when-there-are-a-certain-number-of-terms-in-the-query/341420)

<div class="topic-metadata">

**Author:** [@gony](https://discuss.elastic.co/u/gony)\
**Replies:** 2\
**Last updated:** [August 27, 2023, 11:05am UTC](https://discuss.elastic.co/t/is-it-possible-to-search-only-when-there-are-a-certain-number-of-terms-in-the-query/341420 "2023-08-27T11:05:01Z")

</div>

When using a match query, is it possible to search only when there are a certain number of terms in the query? I need that functionality, not for the entire query, but as part of a subquery that I will put inside a bool…

---

## [Install Curator 7.0.0 in rhel](https://discuss.elastic.co/t/install-curator-7-0-0-in-rhel/341223)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 5\
**Last updated:** [August 27, 2023, 8:12am UTC](https://discuss.elastic.co/t/install-curator-7-0-0-in-rhel/341223 "2023-08-27T08:12:51Z")

</div>

As per official doc https://www.elastic.co/guide/en/elasticsearch/client/curator/7.0/pip.html Current system - RHEL 8 Elasticsearch - 7.17.3 I am trying to install curator in linux machine and i have install python3 …

---

## [DNS Queries grok pattern working on devtools but not in kibana dashboards](https://discuss.elastic.co/t/dns-queries-grok-pattern-working-on-devtools-but-not-in-kibana-dashboards/341748)

<div class="topic-metadata">

**Author:** [@Poubelle\_Dirty](https://discuss.elastic.co/u/Poubelle_Dirty)\
**Replies:** 4\
**Last updated:** [August 27, 2023, 7:11am UTC](https://discuss.elastic.co/t/dns-queries-grok-pattern-working-on-devtools-but-not-in-kibana-dashboards/341748 "2023-08-27T07:11:37Z")

</div>

Hello, I'm new to ELK stack and I encounter a problem. I'm using the DNS grok pattern from here to parse dns queries from my bind server : https://github.com/cjslack/grok-debugger/blob/master/public/patterns/bind It w…

---

## [Help: auditbeat's file\_integrity module not sending logs for created/modified/deleted files](https://discuss.elastic.co/t/help-auditbeats-file-integrity-module-not-sending-logs-for-created-modified-deleted-files/341754)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [August 27, 2023, 2:50am UTC](https://discuss.elastic.co/t/help-auditbeats-file-integrity-module-not-sending-logs-for-created-modified-deleted-files/341754 "2023-08-27T02:50:08Z")

</div>

When I create, modify, or delete a file called test.txt on my server auditbeat does not send a log for it. Not sure why because my other modules appear to be working as intended. Here's the relevant portion from my confi…

---

## [After update , changes order list](https://discuss.elastic.co/t/after-update-changes-order-list/341751)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 5:01pm UTC](https://discuss.elastic.co/t/after-update-changes-order-list/341751 "2023-08-26T17:01:23Z")

</div>

hello , I have a crud . that I list products , in admin area . I change the price of a product , in a CRUD . after , I give a refresh on the page . and it changed the order that is searching this product . does have …

---

## [How can we use your service tile to load our map in Kibana?](https://discuss.elastic.co/t/how-can-we-use-your-service-tile-to-load-our-map-in-kibana/341726)

<div class="topic-metadata">

**Author:** [@jzarei1996](https://discuss.elastic.co/u/jzarei1996)\
**Replies:** 2\
**Last updated:** [August 26, 2023, 3:21pm UTC](https://discuss.elastic.co/t/how-can-we-use-your-service-tile-to-load-our-map-in-kibana/341726 "2023-08-26T15:21:01Z")

</div>

We have created a map from mapbox gl in our plugin in Kibana. My map codes are very simple, please look at them and guide me what to give as options which include layer and source to my map so that your basemap can be sh…

---

## [The issue of fetching duplicate data in Logstash](https://discuss.elastic.co/t/the-issue-of-fetching-duplicate-data-in-logstash/341643)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 2\
**Last updated:** [August 26, 2023, 1:40pm UTC](https://discuss.elastic.co/t/the-issue-of-fetching-duplicate-data-in-logstash/341643 "2023-08-26T13:40:13Z")

</div>

I have written the following code within the input section, but I'm experiencing a problem where data is being fetched redundantly. Which part should I modify? logstash.conf input { beats { port =\> 5044 …

---

## [Empty indexes in Kibana](https://discuss.elastic.co/t/empty-indexes-in-kibana/341745)

<div class="topic-metadata">

**Author:** [@anshtyagi14](https://discuss.elastic.co/u/anshtyagi14)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 12:43pm UTC](https://discuss.elastic.co/t/empty-indexes-in-kibana/341745 "2023-08-26T12:43:40Z")

</div>

I am trying to visualise system logs in kibana, for the process i am using 3's AWS Amazon Linux 2023 EC2 instance in the following way Instance 01 - Filebeat Instance 02 - Logstash Instance 03 - Elasticsearch, Kibana …

---

## [Problems with homebrew installation](https://discuss.elastic.co/t/problems-with-homebrew-installation/341132)

<div class="topic-metadata">

**Author:** [@dpa](https://discuss.elastic.co/u/dpa)\
**Replies:** 2\
**Last updated:** [August 26, 2023, 11:33am UTC](https://discuss.elastic.co/t/problems-with-homebrew-installation/341132 "2023-08-26T11:33:41Z")

</div>

I tried to follow the basic instructions here: Install Elasticsearch on macOS with Homebrew | Elasticsearch Guide \[7.17\] | Elastic but they don't work brew tap elastic/tap - works fine but brew install elastic/tap/ela…

---

## [How to calculate score after filter in Elasticsearch](https://discuss.elastic.co/t/how-to-calculate-score-after-filter-in-elasticsearch/341733)

<div class="topic-metadata">

**Author:** [@at\_ohn](https://discuss.elastic.co/u/at_ohn)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 9:13am UTC](https://discuss.elastic.co/t/how-to-calculate-score-after-filter-in-elasticsearch/341733 "2023-08-26T09:13:54Z")

</div>

Does anyone know how we can get the score to be calculated AFTER the filter is applied? Rescoring doesn't help too because it still takes into account all documents in the index. I need a score that is independent of the…

---

## [Keyword case insensitive search with non-ascii](https://discuss.elastic.co/t/keyword-case-insensitive-search-with-non-ascii/341460)

<div class="topic-metadata">

**Author:** [@Volodymyr\_Kovtun](https://discuss.elastic.co/u/Volodymyr_Kovtun)\
**Replies:** 5\
**Last updated:** [August 26, 2023, 7:49am UTC](https://discuss.elastic.co/t/keyword-case-insensitive-search-with-non-ascii/341460 "2023-08-26T07:49:13Z")

</div>

Hi Could you please clarify if it is possible to have case-insensitive term.keyword search with non-ascii symbols? It seems not to work. Here is the example: Indexing 4 documents (2 ascii and 2 non-ascii) \>\>\> es.in…

---

## [Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/341729)

<div class="topic-metadata">

**Author:** [@Sasan\_Askari](https://discuss.elastic.co/u/Sasan_Askari)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 7:26am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/341729 "2023-08-26T07:26:01Z")

</div>

Hi everyone! I have written a docoker-compose to up ELK,but when I run it i get Unable to retrieve version information from Elasticsearch nodes from my kibana container! Here is my structure: first my compoese is …

---

## [Slack Integration with ELK stack](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 10\
**Last updated:** [August 26, 2023, 2:02am UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657 "2023-08-26T02:02:40Z")

</div>

Hi I have installed the ELK Stack 8.9.0 in AWS Ubuntu Instance. I was configured the elk stack and it's working fine. So, I want to integrate the slack with elk stack and send the alert to slack channel if any 500 statu…

---

## [Native IntegerRange type in Elastic.Clients (8.9) does not serialize correctly](https://discuss.elastic.co/t/native-integerrange-type-in-elastic-clients-8-9-does-not-serialize-correctly/341581)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 2:26pm UTC](https://discuss.elastic.co/t/native-integerrange-type-in-elastic-clients-8-9-does-not-serialize-correctly/341581 "2023-08-24T14:26:47Z")

</div>

When I use IntegerRange it does not serialize to fields named gt, gte, lt, and lte. I have an index template which sends my field item\_index\_range to an explicit integer\_range type. I shouldn't need to do any mapping at…

---

## [Security Attributes for ELK Kibana](https://discuss.elastic.co/t/security-attributes-for-elk-kibana/341713)

<div class="topic-metadata">

**Author:** [@3rk1n](https://discuss.elastic.co/u/3rk1n)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 5:36pm UTC](https://discuss.elastic.co/t/security-attributes-for-elk-kibana/341713 "2023-08-25T17:36:37Z")

</div>

Hi, I want to close security recommendations for Kubernetes Cluster in Microsoft Defender for Cloud. One of them is "Kubernetes clusters should disable automounting API credentials" and it can be solved by added "autom…

---

## [Composable Index template with java REST](https://discuss.elastic.co/t/composable-index-template-with-java-rest/341634)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 5:25pm UTC](https://discuss.elastic.co/t/composable-index-template-with-java-rest/341634 "2023-08-25T17:25:28Z")

</div>

I'm running 7.15 so it's not the latest binary code. How do I add sorting index in setting? I'm getting invalid sort order error. It seems composable index only takes builder for settings; therefore, I convert all v…

---

## [Security Attributes for Elastic-Operator](https://discuss.elastic.co/t/security-attributes-for-elastic-operator/341710)

<div class="topic-metadata">

**Author:** [@3rk1n](https://discuss.elastic.co/u/3rk1n)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 5:12pm UTC](https://discuss.elastic.co/t/security-attributes-for-elastic-operator/341710 "2023-08-25T17:12:45Z")

</div>

Hi, I want to close security recommendations for Kubernetes Cluster in Microsoft Defender for Cloud. One of them is "Kubernetes clusters should disable automounting API credentials" and it can be solved by added "autom…

---

## [Is it possible to disable HTTP Options method in Elastic Search v7.5?](https://discuss.elastic.co/t/is-it-possible-to-disable-http-options-method-in-elastic-search-v7-5/341700)

<div class="topic-metadata">

**Author:** [@James\_Brown2](https://discuss.elastic.co/u/James_Brown2)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 5:00pm UTC](https://discuss.elastic.co/t/is-it-possible-to-disable-http-options-method-in-elastic-search-v7-5/341700 "2023-08-25T17:00:41Z")

</div>

Hi there, Does anyone know is it possible to disabled HTTP Options method in Elastic Search v7.5? and if it is safe to do so without affecting Elastic Search functionality? Many thanks, James

---

## [Duplicated events](https://discuss.elastic.co/t/duplicated-events/341389)

<div class="topic-metadata">

**Author:** [@Mohammed\_Amine\_El\_ha](https://discuss.elastic.co/u/Mohammed_Amine_El_ha)\
**Replies:** 2\
**Last updated:** [August 25, 2023, 4:26pm UTC](https://discuss.elastic.co/t/duplicated-events/341389 "2023-08-25T16:26:56Z")

</div>

Hi, I am fairely new to the elastic stack I am using filebeat to pull date from a Rest Api and push it to elastic. my configuration file is as follows: # ============================== Filebeat inputs ===============…

---

## [Fleet Server Setup failing](https://discuss.elastic.co/t/fleet-server-setup-failing/341380)

<div class="topic-metadata">

**Author:** [@sai\_kiran1](https://discuss.elastic.co/u/sai_kiran1)\
**Replies:** 11\
**Last updated:** [August 25, 2023, 4:00pm UTC](https://discuss.elastic.co/t/fleet-server-setup-failing/341380 "2023-08-25T16:00:55Z")

</div>

Hello, Trying to enroll fleet in docker env and the enroll is not happening with the below continuous log messages. \[root@eicillp949 ~\]# docker logs --since 10m -f elastic-agent Policy selected for enrollment: fleet-s…

---

## [Challenges of Indexing Large Arrays with Thousands of Fields in ELK Stack for Search Engine Development with Sailsjs](https://discuss.elastic.co/t/challenges-of-indexing-large-arrays-with-thousands-of-fields-in-elk-stack-for-search-engine-development-with-sailsjs/341705)

<div class="topic-metadata">

**Author:** [@priyanshu-kun](https://discuss.elastic.co/u/priyanshu-kun)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 3:52pm UTC](https://discuss.elastic.co/t/challenges-of-indexing-large-arrays-with-thousands-of-fields-in-elk-stack-for-search-engine-development-with-sailsjs/341705 "2023-08-25T15:52:42Z")

</div>

I new to ELK stack and I want to index an array of object and each object have over 3000 fields for building a search engine using sailsjs. I tried lot of way and dig through the web but I cannot able to find the solutio…

---

## [Entreprise Elastic license](https://discuss.elastic.co/t/entreprise-elastic-license/341665)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 3\
**Last updated:** [August 25, 2023, 2:34pm UTC](https://discuss.elastic.co/t/entreprise-elastic-license/341665 "2023-08-25T14:34:32Z")

</div>

Does the enterprise license of Elastic depend on the basic system resource configuration or on the scalability ?

---

## [Syslog input plugin from Logstash, how to configure in Elastic agent?](https://discuss.elastic.co/t/syslog-input-plugin-from-logstash-how-to-configure-in-elastic-agent/341300)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 10\
**Last updated:** [August 25, 2023, 1:31pm UTC](https://discuss.elastic.co/t/syslog-input-plugin-from-logstash-how-to-configure-in-elastic-agent/341300 "2023-08-25T13:31:29Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0). We have about 20 different agent policies, because the various Elastic agents are sending slightly different …

---

## [Use custom analyzer in search query on selected fields only](https://discuss.elastic.co/t/use-custom-analyzer-in-search-query-on-selected-fields-only/341693)

<div class="topic-metadata">

**Author:** [@aniket\_mandhare](https://discuss.elastic.co/u/aniket_mandhare)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 1:25pm UTC](https://discuss.elastic.co/t/use-custom-analyzer-in-search-query-on-selected-fields-only/341693 "2023-08-25T13:25:23Z")

</div>

I want to apply a custom analyzer to selected fields only in a search query without having to modify the field mappings. And also don't want to add subfield while mapping.

---

## [Unable to connect Kibana to Elasticsearch](https://discuss.elastic.co/t/unable-to-connect-kibana-to-elasticsearch/341646)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 5\
**Last updated:** [August 25, 2023, 1:14pm UTC](https://discuss.elastic.co/t/unable-to-connect-kibana-to-elasticsearch/341646 "2023-08-25T13:14:29Z")

</div>

Hi there, I am having an ES cluster running with the following config, with self signed certificates:- sudo docker run -it --privileged -p 9200:9200 -p 9300:9300 -e discovery.type=multi-node -e "cluster.name=my-elasti…

---

## [Elasticsearch nodes RED](https://discuss.elastic.co/t/elasticsearch-nodes-red/341638)

<div class="topic-metadata">

**Author:** [@d6036de2b54af16665f4](https://discuss.elastic.co/u/d6036de2b54af16665f4)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elasticsearch-nodes-red/341638 "2023-08-25T12:55:22Z")

</div>

HI, On Elasticsearch Status is Showing as RED. With GET \_cat/allocation/?v Command i tried to check which nodes has no shards Allocated but it not giving that information like which node has 0 shards allocated. That's…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=439)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=441)
