# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=441

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 442

---

## [Filebeat Fortinet Module: Mismatch between event.action and event.type in Fortigate Logs](https://discuss.elastic.co/t/filebeat-fortinet-module-mismatch-between-event-action-and-event-type-in-fortigate-logs/341686)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 12:53pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-mismatch-between-event-action-and-event-type-in-fortigate-logs/341686 "2023-08-25T12:53:32Z")

</div>

Hello Elastic Community, We have set up Filebeat to use the Fortinet module for parsing logs from local files that are sent via Syslog to a Syslog server. We are currently running ELK Kibana and Filebeat version 8.7. As…

---

## [Handle specific type of ElasticsearchException](https://discuss.elastic.co/t/handle-specific-type-of-elasticsearchexception/341669)

<div class="topic-metadata">

**Author:** [@Raghunandan](https://discuss.elastic.co/u/Raghunandan)\
**Replies:** 3\
**Last updated:** [August 25, 2023, 11:52am UTC](https://discuss.elastic.co/t/handle-specific-type-of-elasticsearchexception/341669 "2023-08-25T11:52:58Z")

</div>

Hi Team, We are facing a very rare scenario, in our cluster deployment we have used dependent services in which the ES repository bean which creates an index is autowired in other service bean, so on startup index creat…

---

## [Getting "no field found in the mapping" when creating a scripted field](https://discuss.elastic.co/t/getting-no-field-found-in-the-mapping-when-creating-a-scripted-field/341684)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 11:45am UTC](https://discuss.elastic.co/t/getting-no-field-found-in-the-mapping-when-creating-a-scripted-field/341684 "2023-08-25T11:45:15Z")

</div>

Hi team, I am using FortiGate integration in my ELK. So I need to create a new scripted fields for more visibility into that logs. Created a scripted field with the following condition. if ( doc\['fortinet.firewall.acti…

---

## [Using scripted field in search query](https://discuss.elastic.co/t/using-scripted-field-in-search-query/341682)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 11:36am UTC](https://discuss.elastic.co/t/using-scripted-field-in-search-query/341682 "2023-08-25T11:36:03Z")

</div>

hi there i have a question here. so for example I already made a scripted field with the name "api\_key" and I want include that field in my search query like http.code: 403 AND NOT api\_key: unknown I already included t…

---

## [Elastic Agent restore data views](https://discuss.elastic.co/t/elastic-agent-restore-data-views/341678)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 11:06am UTC](https://discuss.elastic.co/t/elastic-agent-restore-data-views/341678 "2023-08-25T11:06:48Z")

</div>

Hi guys! Data views from fleet server integrations have been removed, how could I reinstall data views and templates again? BR

---

## [How create a alert when logstash node goes down in a cluster? please help me how to do it](https://discuss.elastic.co/t/how-create-a-alert-when-logstash-node-goes-down-in-a-cluster-please-help-me-how-to-do-it/341676)

<div class="topic-metadata">

**Author:** [@mahesh\_sadhanagiri](https://discuss.elastic.co/u/mahesh_sadhanagiri)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 10:34am UTC](https://discuss.elastic.co/t/how-create-a-alert-when-logstash-node-goes-down-in-a-cluster-please-help-me-how-to-do-it/341676 "2023-08-25T10:34:50Z")

</div>

I have a cluster with 3 logstash nodes. I want to create an alert to triiger if any of the Logstash node goes down.

---

## [Using multi-term aggregation on rollup jobs](https://discuss.elastic.co/t/using-multi-term-aggregation-on-rollup-jobs/341674)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 10:03am UTC](https://discuss.elastic.co/t/using-multi-term-aggregation-on-rollup-jobs/341674 "2023-08-25T10:03:38Z")

</div>

Hi, Can I use multi-term aggregation on rollup jobs? My goal is to save disk space on older data, which has 6 fields (say, Field1 to Field6). After the rollup, I would like to query for the presence of records with the…

---

## [Logstash configuration file for self join field with error object mapping found a concrete value](https://discuss.elastic.co/t/logstash-configuration-file-for-self-join-field-with-error-object-mapping-found-a-concrete-value/341071)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 8\
**Last updated:** [August 25, 2023, 9:08am UTC](https://discuss.elastic.co/t/logstash-configuration-file-for-self-join-field-with-error-object-mapping-found-a-concrete-value/341071 "2023-08-25T09:08:26Z")

</div>

I've a logstash integration with postgresql table. the table has a self join from incident\_parent\_id to incident\_number. incident\_number ( primary key) incident\_parent\_id ( self join with incident number). But the r…

---

## [Kibana No results match your search criteria or wrong configurations](https://discuss.elastic.co/t/kibana-no-results-match-your-search-criteria-or-wrong-configurations/341541)

<div class="topic-metadata">

**Author:** [@Elite9400](https://discuss.elastic.co/u/Elite9400)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 9:44am UTC](https://discuss.elastic.co/t/kibana-no-results-match-your-search-criteria-or-wrong-configurations/341541 "2023-08-25T09:44:42Z")

</div>

hello, I'm trying to use ELK in my laboratory for a study project but I'm having problems collecting log records. I currently set up my test environment like this: VM 1 - SRV401 (Windows Server 2022) I would like thi…

---

## [Huge disk read count when MapperParsingException](https://discuss.elastic.co/t/huge-disk-read-count-when-mapperparsingexception/341673)

<div class="topic-metadata">

**Author:** [@ShanYang](https://discuss.elastic.co/u/ShanYang)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 9:41am UTC](https://discuss.elastic.co/t/huge-disk-read-count-when-mapperparsingexception/341673 "2023-08-25T09:41:52Z")

</div>

I found that the indexing efficiency of the entire cluster gradually decreased with each passing day. After checking the size of all the indices, I didn't find any abnormalities. However, at the same time, I noticed an…

---

## [Importing ndjson file of kibana dashboards from DEV kibana to Prod Kibana using jenkins](https://discuss.elastic.co/t/importing-ndjson-file-of-kibana-dashboards-from-dev-kibana-to-prod-kibana-using-jenkins/341653)

<div class="topic-metadata">

**Author:** [@Mangesh\_Mathe](https://discuss.elastic.co/u/Mangesh_Mathe)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 9:22am UTC](https://discuss.elastic.co/t/importing-ndjson-file-of-kibana-dashboards-from-dev-kibana-to-prod-kibana-using-jenkins/341653 "2023-08-25T09:22:29Z")

</div>

Hello Elastic Team, Elastic and Kibana version : v 8.4.2 configured on: Azure elastic cloud How can we import ndjson file of kibana dashboards from DEV kibana to Prod Kibana using jenkins? Our requirement is to integ…

---

## [Adding Custom headers to Kibana Dashboard Pdf Report](https://discuss.elastic.co/t/adding-custom-headers-to-kibana-dashboard-pdf-report/341464)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 9:18am UTC](https://discuss.elastic.co/t/adding-custom-headers-to-kibana-dashboard-pdf-report/341464 "2023-08-25T09:18:49Z")

</div>

Hi , I'm using Kibana 7.10 version in one of my old servers. I'm downloading a pdf report of the dashboard under "Reporting" Section. But I need to customize the Dashboard pdf header. Currently it shows blank. Is …

---

## [Rally op\_metrics throughput is null](https://discuss.elastic.co/t/rally-op-metrics-throughput-is-null/341667)

<div class="topic-metadata">

**Author:** [@hyt](https://discuss.elastic.co/u/hyt)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 8:48am UTC](https://discuss.elastic.co/t/rally-op-metrics-throughput-is-null/341667 "2023-08-25T08:48:44Z")

</div>

es: 7.17.9 rally: 2.6.0 and 2.8.0 python: 3.8 cmd: esrally race --track=http\_logs --target-hosts=172.20.236.173:9200 --pipeline=benchmark-only --kill-running-processes --track-params=rally\_params.json --offline trac…

---

## [Elasticsearch being open source](https://discuss.elastic.co/t/elasticsearch-being-open-source/341632)

<div class="topic-metadata">

**Author:** [@JasonGoldman](https://discuss.elastic.co/u/JasonGoldman)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 7:56am UTC](https://discuss.elastic.co/t/elasticsearch-being-open-source/341632 "2023-08-25T07:56:31Z")

</div>

The GitHub repository of Elasticsearch and Elastic's website should not be afraid to call Elasticsearch "open source". The upcoming release of the Open Source Definition (v1.11) will acknowledge that Server Side Public L…

---

## [Comparing disk usage on ES with different configurations](https://discuss.elastic.co/t/comparing-disk-usage-on-es-with-different-configurations/341655)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 7:15am UTC](https://discuss.elastic.co/t/comparing-disk-usage-on-es-with-different-configurations/341655 "2023-08-25T07:15:30Z")

</div>

Hi, I'm trying to optimize the disk usage on my Elasticsearch (version 8.8), and I want to see how much disk space was used (saved) after configuring different things, e.g. dynamic vs static mapping, default compression…

---

## [How to integrate Elasticsearch (8.x) with Nest.js](https://discuss.elastic.co/t/how-to-integrate-elasticsearch-8-x-with-nest-js/341166)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 3\
**Last updated:** [August 25, 2023, 6:09am UTC](https://discuss.elastic.co/t/how-to-integrate-elasticsearch-8-x-with-nest-js/341166 "2023-08-25T06:09:16Z")

</div>

I have a question about connecting Elasticsearch with Nest.js. When I make an API call to Elasticsearch, it works fine. In Nest.js, I've written the code as follows. search.module.ts import { Module } from '@nestj…

---

## [Login to kibana and access it from my website](https://discuss.elastic.co/t/login-to-kibana-and-access-it-from-my-website/341639)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 5:58am UTC](https://discuss.elastic.co/t/login-to-kibana-and-access-it-from-my-website/341639 "2023-08-25T05:58:30Z")

</div>

Hi i am trying to embed the kibana url in zabbix dashboard url widget. when i put in the kibana url, instead of giving login page it gives a blank page. Is there a way to do this?

---

## [Logstash 8.6 add a field "log.file.path"](https://discuss.elastic.co/t/logstash-8-6-add-a-field-log-file-path/341597)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 3\
**Last updated:** [August 25, 2023, 3:33am UTC](https://discuss.elastic.co/t/logstash-8-6-add-a-field-log-file-path/341597 "2023-08-25T03:33:38Z")

</div>

Hi there I use .conf file to ingest data in my index. With the version 8.6 is added the field "log.file.path." I tried with mutate { remove\_field =\> \[ "message", "@version","host","log.file.path" \] } without suceed. …

---

## [Accurate decryption logstash data in Javascript](https://discuss.elastic.co/t/accurate-decryption-logstash-data-in-javascript/341538)

<div class="topic-metadata">

**Author:** [@Nik\_Ameer](https://discuss.elastic.co/u/Nik_Ameer)\
**Replies:** 2\
**Last updated:** [August 25, 2023, 3:26am UTC](https://discuss.elastic.co/t/accurate-decryption-logstash-data-in-javascript/341538 "2023-08-25T03:26:16Z")

</div>

I used logstash to encrypt my data using the cipher filter. My logstash.conf file are like so cipher { algorithm =\> "aes-256-cbc" cipher\_padding =\> 1 mode =\> "encrypt" so…

---

## [Does pre-filtered approximate kNN still need entire data in memory?](https://discuss.elastic.co/t/does-pre-filtered-approximate-knn-still-need-entire-data-in-memory/341636)

<div class="topic-metadata">

**Author:** [@veesahni](https://discuss.elastic.co/u/veesahni)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 2:35am UTC](https://discuss.elastic.co/t/does-pre-filtered-approximate-knn-still-need-entire-data-in-memory/341636 "2023-08-25T02:35:04Z")

</div>

This article on tuning approximate kNN states "You should ensure that data nodes have at least enough RAM to hold the vector data and index structures". Does this still apply when doing filtered kNN search? To be clear…

---

## [Filebeat system module does not send process name](https://discuss.elastic.co/t/filebeat-system-module-does-not-send-process-name/341423)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 10:25pm UTC](https://discuss.elastic.co/t/filebeat-system-module-does-not-send-process-name/341423 "2023-08-24T22:25:00Z")

</div>

Does anyone encounter this? There is no data in field: process name

---

## [Implement Multi-tenancy using an Index per tenant or 10 index per tenant which is better approach](https://discuss.elastic.co/t/implement-multi-tenancy-using-an-index-per-tenant-or-10-index-per-tenant-which-is-better-approach/341610)

<div class="topic-metadata">

**Author:** [@HARSHAL\_CHAUDHARI](https://discuss.elastic.co/u/HARSHAL_CHAUDHARI)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 9:11pm UTC](https://discuss.elastic.co/t/implement-multi-tenancy-using-an-index-per-tenant-or-10-index-per-tenant-which-is-better-approach/341610 "2023-08-24T21:11:22Z")

</div>

Implement Multi-tenancy using an Index per tenant or 10 indexes per tenant which is a better approach, by considering Security, Scalability, Cost-effectiveness, and Complexity.

---

## [Using ELSER for multiple fields](https://discuss.elastic.co/t/using-elser-for-multiple-fields/341347)

<div class="topic-metadata">

**Author:** [@Rottonscope](https://discuss.elastic.co/u/Rottonscope)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 7:44pm UTC](https://discuss.elastic.co/t/using-elser-for-multiple-fields/341347 "2023-08-24T19:44:16Z")

</div>

Hello! I've just begun exploring ELSER and I'm interesting in knowing if there is any guidance out there for scenarios whereby I want to run inference on multiple fields, e.g. Title and also Description. The documentati…

---

## [Multi-Tenant - Shard and Index strategy / Optimizing Elasticsearch configuration?](https://discuss.elastic.co/t/multi-tenant-shard-and-index-strategy-optimizing-elasticsearch-configuration/341605)

<div class="topic-metadata">

**Author:** [@HARSHAL\_CHAUDHARI](https://discuss.elastic.co/u/HARSHAL_CHAUDHARI)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 7:40pm UTC](https://discuss.elastic.co/t/multi-tenant-shard-and-index-strategy-optimizing-elasticsearch-configuration/341605 "2023-08-24T19:40:30Z")

</div>

Hi Team, Could you please suggest the Elasticsearch configuration? (for scale and performance) My use case is below I have 1000 - 2000 thousands of customers - each customer has a 100-200 index, How data nodes can b…

---

## [.NET: Using NEST 7.x high-level client against Elasticsearch 6.x:](https://discuss.elastic.co/t/net-using-nest-7-x-high-level-client-against-elasticsearch-6-x/340768)

<div class="topic-metadata">

**Author:** [@Thomas\_Doman](https://discuss.elastic.co/u/Thomas_Doman)\
**Replies:** 6\
**Last updated:** [August 24, 2023, 7:12pm UTC](https://discuss.elastic.co/t/net-using-nest-7-x-high-level-client-against-elasticsearch-6-x/340768 "2023-08-24T19:12:08Z")

</div>

Continuing the discussion from .NET: Using newer NEST high-level client against previous version of Elasticsearch: @stephenb we've gotten to point of trying this out now. We've seen that using NEST 7.x against an ES 6.…

---

## [Availavility reports](https://discuss.elastic.co/t/availavility-reports/340659)

<div class="topic-metadata">

**Author:** [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 7:03pm UTC](https://discuss.elastic.co/t/availavility-reports/340659 "2023-08-24T19:03:30Z")

</div>

hi, im looking for a way to have an availability report with maintenance windows exluded from the calculation. I have an index with availavility events that have basic status of 0 or 1, i can easily calculate the percen…

---

## [Pre-filter KNN vector search](https://discuss.elastic.co/t/pre-filter-knn-vector-search/341585)

<div class="topic-metadata">

**Author:** [@veesahni](https://discuss.elastic.co/u/veesahni)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 7:01pm UTC](https://discuss.elastic.co/t/pre-filter-knn-vector-search/341585 "2023-08-24T19:01:59Z")

</div>

I'm trying to understand how to best implement a pre-filtered KNN vector search. To be clear: I'd like to pre-filter the total number of docs down to a smaller set, and then run a vector search that leverages a vector in…

---

## [How do drop logs from being forwarded? My drop rule doesn't seem to be working](https://discuss.elastic.co/t/how-do-drop-logs-from-being-forwarded-my-drop-rule-doesnt-seem-to-be-working/341520)

<div class="topic-metadata">

**Author:** [@feo13](https://discuss.elastic.co/u/feo13)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 6:48pm UTC](https://discuss.elastic.co/t/how-do-drop-logs-from-being-forwarded-my-drop-rule-doesnt-seem-to-be-working/341520 "2023-08-24T18:48:44Z")

</div>

I'm ingesting AWS WAF logs and would like to drop the 'ALLOW' logs. I have the following filter in place but it doesn't seem to be working: filter { if "\\"action\\":\\"ALLOW\\"" in \[message\] { drop {} } if \[ty…

---

## [Help with file name to date logstash grok](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592)

<div class="topic-metadata">

**Author:** [@ethranes](https://discuss.elastic.co/u/ethranes)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 5:07pm UTC](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592 "2023-08-24T17:07:15Z")

</div>

Hi, the date isn't included in my log files. But the filename itself has the date. So I'm trying to extract the year month and day from the filename and then put that into a field. But logstash can't parse my filename, I…

---

## [What is the impact of aggregated queries on performance](https://discuss.elastic.co/t/what-is-the-impact-of-aggregated-queries-on-performance/341525)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 4:59pm UTC](https://discuss.elastic.co/t/what-is-the-impact-of-aggregated-queries-on-performance/341525 "2023-08-24T16:59:46Z")

</div>

What is the impact of aggregated queries on performance, with a data volume of 300000, requiring 2-3 layers of aggregation :grinning:

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=440)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=442)
