# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=442

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 443

---

## [\[WATCHER\] Is it possible put in the payload the ack state?](https://discuss.elastic.co/t/watcher-is-it-possible-put-in-the-payload-the-ack-state/341594)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 4:58pm UTC](https://discuss.elastic.co/t/watcher-is-it-possible-put-in-the-payload-the-ack-state/341594 "2023-08-24T16:58:30Z")

</div>

Hi, I want to know if it's possible take the acknowledge state of a watcher for an action. This is my scenario: I have a watcher and the actions of it are index and webhook. But I want to include the ack state in the …

---

## [Compare 2 indices and find missing documents](https://discuss.elastic.co/t/compare-2-indices-and-find-missing-documents/341434)

<div class="topic-metadata">

**Author:** [@arks1](https://discuss.elastic.co/u/arks1)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 4:57pm UTC](https://discuss.elastic.co/t/compare-2-indices-and-find-missing-documents/341434 "2023-08-24T16:57:29Z")

</div>

I have 2 indices, index\_a and index\_b. The 2 indices have documents with the almost the exact same template. index\_b has some extra fields which was introduced as part of a new feature, but it also has all the fields al…

---

## [Retry on conflict](https://discuss.elastic.co/t/retry-on-conflict/341591)

<div class="topic-metadata">

**Author:** [@Vamsi\_krishna\_Ramaya](https://discuss.elastic.co/u/Vamsi_krishna_Ramaya)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 4:02pm UTC](https://discuss.elastic.co/t/retry-on-conflict/341591 "2023-08-24T16:02:20Z")

</div>

Hi I am working on a node ja project with elasticsearch so i am trying to create index with out replica even though i added that number\_of\_replicas 0 replica is generating and that gives me problem that document is geti…

---

## [Two nested Grok patterns not working](https://discuss.elastic.co/t/two-nested-grok-patterns-not-working/341533)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 3:54pm UTC](https://discuss.elastic.co/t/two-nested-grok-patterns-not-working/341533 "2023-08-24T15:54:46Z")

</div>

Hey everyone, I'm new to using Logstash and Elasticsearch. I've been working on collecting logs through Filebeat and then using Logstash for parsing and data cleaning. I have two Grok patterns in place. The first one ex…

---

## [Structured Data set in Elastic](https://discuss.elastic.co/t/structured-data-set-in-elastic/341379)

<div class="topic-metadata">

**Author:** [@ishani.sengupta](https://discuss.elastic.co/u/ishani.sengupta)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:44pm UTC](https://discuss.elastic.co/t/structured-data-set-in-elastic/341379 "2023-08-24T15:44:26Z")

</div>

Working on Analytics using ELK stack, the data being used is a structure data where we are facing issue with migration and correlation. Can elastic stack handle structure data within an index or any other ways to handle…

---

## [What is the proper way on migrating you elastic-stack environment?](https://discuss.elastic.co/t/what-is-the-proper-way-on-migrating-you-elastic-stack-environment/341517)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 3:40pm UTC](https://discuss.elastic.co/t/what-is-the-proper-way-on-migrating-you-elastic-stack-environment/341517 "2023-08-24T15:40:43Z")

</div>

Hello, So I have the Elasticsearch, Kibana, Logstash, Fleet-server, and the Package-registry all running on docker containers. I'm still testing things out, but I wanted to know what the proper way to migrate my docker …

---

## [Win32\_Service queries hanging](https://discuss.elastic.co/t/win32-service-queries-hanging/341133)

<div class="topic-metadata">

**Author:** [@\_bruno](https://discuss.elastic.co/u/_bruno)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 3:16pm UTC](https://discuss.elastic.co/t/win32-service-queries-hanging/341133 "2023-08-24T15:16:30Z")

</div>

Environment: Windows version: Windows 10 21H2, fully patched Beats versions: 8.9.0, 8.9.1 (winlogbeat and filebeat) Steps to Reproduce: Install beats versions 8.9.0 or 8.9.1 as a windows service. Attempt to make a W…

---

## [Incorrect configuration and LOGs collection problems](https://discuss.elastic.co/t/incorrect-configuration-and-logs-collection-problems/341471)

<div class="topic-metadata">

**Author:** [@Elite9400](https://discuss.elastic.co/u/Elite9400)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 3:11pm UTC](https://discuss.elastic.co/t/incorrect-configuration-and-logs-collection-problems/341471 "2023-08-24T15:11:12Z")

</div>

hello, I'm trying to use ELK in my laboratory for a study project but I'm having problems collecting log records. I currently set up my test environment like this: VM 1 - SRV401 (Windows Server 2022) I would like thi…

---

## [Aws ingest pipeline error in processor rename "message" to "event.original"](https://discuss.elastic.co/t/aws-ingest-pipeline-error-in-processor-rename-message-to-event-original/341472)

<div class="topic-metadata">

**Author:** [@diogoeverson](https://discuss.elastic.co/u/diogoeverson)\
**Replies:** 8\
**Last updated:** [August 24, 2023, 2:46pm UTC](https://discuss.elastic.co/t/aws-ingest-pipeline-error-in-processor-rename-message-to-event-original/341472 "2023-08-24T14:46:48Z")

</div>

Parse aws vpcflow or cloudtrail logs is not working. When testing the pipeline auto generate by filebeat it returns an error: field \[event.original\] already exists. Processors: \[ { "drop": { "if": "ctx.mess…

---

## [How many records does jdbc input plugin can read at once?](https://discuss.elastic.co/t/how-many-records-does-jdbc-input-plugin-can-read-at-once/341561)

<div class="topic-metadata">

**Author:** [@Sreenivas1](https://discuss.elastic.co/u/Sreenivas1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 2:43pm UTC](https://discuss.elastic.co/t/how-many-records-does-jdbc-input-plugin-can-read-at-once/341561 "2023-08-24T14:43:13Z")

</div>

Hi Team, We have to pull data of 70million records from oracle database in a week and load into elastic cluster of 3 nodes. So we have a scheduler in database side which will load 50k or 1million records in 6min to a te…

---

## [Reload Logstash config on shutdown](https://discuss.elastic.co/t/reload-logstash-config-on-shutdown/341545)

<div class="topic-metadata">

**Author:** [@Ljapunov](https://discuss.elastic.co/u/Ljapunov)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 2:25pm UTC](https://discuss.elastic.co/t/reload-logstash-config-on-shutdown/341545 "2023-08-24T14:25:19Z")

</div>

Hi everyone, we have a multiple-node logstash cluster using a distributor pipeline that distributes events depending on their types, eg input { beats { # ... } } output { if \[type\] == "foo" { pi…

---

## [Why my Logstash work normal with an recursively error log](https://discuss.elastic.co/t/why-my-logstash-work-normal-with-an-recursively-error-log/341537)

<div class="topic-metadata">

**Author:** [@waitspring](https://discuss.elastic.co/u/waitspring)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 2:07pm UTC](https://discuss.elastic.co/t/why-my-logstash-work-normal-with-an-recursively-error-log/341537 "2023-08-24T14:07:52Z")

</div>

I have make my logstash conf as: ... ... filter { grok { match =\> { "message" =\> \[ "\\\<时间: (?\<timestamp\>.\*)\\\> \\\<进程号:(?\<process\>%{NUMBER}+)\\\>(?\<body\>.\*$)", "\\\<时间:(?\<t…

---

## [Elastic.Clients fails indexing my data type with an IntegerRange (integer\_range) in it even though I'm using a template mapping](https://discuss.elastic.co/t/elastic-clients-fails-indexing-my-data-type-with-an-integerrange-integer-range-in-it-even-though-im-using-a-template-mapping/341513)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 2:07pm UTC](https://discuss.elastic.co/t/elastic-clients-fails-indexing-my-data-type-with-an-integerrange-integer-range-in-it-even-though-im-using-a-template-mapping/341513 "2023-08-24T14:07:30Z")

</div>

The problem was caused by the use of the JsonPropertyName decorator on my data structure properties.

---

## [Index is getting deleted automatically](https://discuss.elastic.co/t/index-is-getting-deleted-automatically/341578)

<div class="topic-metadata">

**Author:** [@HardikSCaypro](https://discuss.elastic.co/u/HardikSCaypro)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 1:58pm UTC](https://discuss.elastic.co/t/index-is-getting-deleted-automatically/341578 "2023-08-24T13:58:40Z")

</div>

Hello Team, We are using Elasticsearch from last few years. However recently we found that few of our indexes were getting deleted automatically, so we searched and found that we should reinstall it in different system. …

---

## [Logstash uses 80GB of memory with pipelines and 10 configurations](https://discuss.elastic.co/t/logstash-uses-80gb-of-memory-with-pipelines-and-10-configurations/341474)

<div class="topic-metadata">

**Author:** [@nilsen](https://discuss.elastic.co/u/nilsen)\
**Replies:** 11\
**Last updated:** [August 24, 2023, 1:20pm UTC](https://discuss.elastic.co/t/logstash-uses-80gb-of-memory-with-pipelines-and-10-configurations/341474 "2023-08-24T13:20:06Z")

</div>

A while back we had issues when we ran multiple Logstash instances, each using around 1GB of memory. We got advised to use pipelines instead. Keep in mind we are still in the POC stages, so very new to the ELK stack. We …

---

## [Wildcard search string in Discover](https://discuss.elastic.co/t/wildcard-search-string-in-discover/341575)

<div class="topic-metadata">

**Author:** [@wapevo5067](https://discuss.elastic.co/u/wapevo5067)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 12:30pm UTC](https://discuss.elastic.co/t/wildcard-search-string-in-discover/341575 "2023-08-24T12:30:38Z")

</div>

V 7.17 I am using Discover from Analytics section. I am just using the simple search box. Lets say I have lots of logs which are: "Connection Server\[N\] Started" I can use: "Connection" and "Started" But I wonder if …

---

## [API to create new dashboard in Kibana 8.9.0](https://discuss.elastic.co/t/api-to-create-new-dashboard-in-kibana-8-9-0/341570)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 12:06pm UTC](https://discuss.elastic.co/t/api-to-create-new-dashboard-in-kibana-8-9-0/341570 "2023-08-24T12:06:53Z")

</div>

POST \<kibana host\>:\<port\>/api/kibana/dashboards/import POST \<kibana host\>:\<port\>/s/\<space-id\>/api/kibana/dashboards/import The above apis are deprecated. Could you please help with alternate APIs to create new dashboar…

---

## [Need to setup API Logging tool for our project](https://discuss.elastic.co/t/need-to-setup-api-logging-tool-for-our-project/341573)

<div class="topic-metadata">

**Author:** [@Uttam\_Jagwani](https://discuss.elastic.co/u/Uttam_Jagwani)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 12:05pm UTC](https://discuss.elastic.co/t/need-to-setup-api-logging-tool-for-our-project/341573 "2023-08-24T12:05:40Z")

</div>

Need to set up an API Logging tool for our project on the prod environment. Would like to know the details on the product stack, cluster setup, hardware & software specifications, storage requirements for logging, and a…

---

## [Decode Base64](https://discuss.elastic.co/t/decode-base64/341359)

<div class="topic-metadata">

**Author:** [@Khaled\_Aldughili](https://discuss.elastic.co/u/Khaled_Aldughili)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 11:23am UTC](https://discuss.elastic.co/t/decode-base64/341359 "2023-08-24T11:23:00Z")

</div>

hello , I am a bit new to ELK, I am trying to decode a base64 field to show as a string. I read through some articles that suggest using ingest pipeline, how would i do that exactly? PS: I tried runtime fields, bu…

---

## [Download csv file from dashboard](https://discuss.elastic.co/t/download-csv-file-from-dashboard/341562)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 10:59am UTC](https://discuss.elastic.co/t/download-csv-file-from-dashboard/341562 "2023-08-24T10:59:48Z")

</div>

I am using open source 7.17.7 ELK stack. For 1 Index i have created a Dashboard which contains the details like ERROR count, i am able to download the csv file manually. How ever now i want to automate this like for ever…

---

## [The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510)

<div class="topic-metadata">

**Author:** [@Erdem\_Sekerci](https://discuss.elastic.co/u/Erdem_Sekerci)\
**Replies:** 7\
**Last updated:** [August 24, 2023, 10:51am UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510 "2023-08-24T10:51:22Z")

</div>

Hello. I see that similar issues have been reported before, but I cannot solve my problem using them. I'm using NEST 7.17.5 dotnet core client and with the following configurations. var elasticSettings = new Connectio…

---

## [Terms aggregation on raw field is returning Exception in thread "main" jakarta.json.stream.JsonParsingException: Property name 'doc\_count\_error\_upper\_bound' is not in the 'type#name' format. Make sure the request has 'typed\_keys' set](https://discuss.elastic.co/t/terms-aggregation-on-raw-field-is-returning-exception-in-thread-main-jakarta-json-stream-jsonparsingexception-property-name-doc-count-error-upper-bound-is-not-in-the-type-name-format-make-sure-the-request-has-typed-keys-set/341340)

<div class="topic-metadata">

**Author:** [@hr89](https://discuss.elastic.co/u/hr89)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 10:16am UTC](https://discuss.elastic.co/t/terms-aggregation-on-raw-field-is-returning-exception-in-thread-main-jakarta-json-stream-jsonparsingexception-property-name-doc-count-error-upper-bound-is-not-in-the-type-name-format-make-sure-the-request-has-typed-keys-set/341340 "2023-08-24T10:16:37Z")

</div>

Hi I have a simple index, index1 as below with mappings { "index1": { "mappings": { "properties": { "\_all": { "type": "text", "fields": { …

---

## [Ingest DNS queres from Windows DNS server using Winlogbeat](https://discuss.elastic.co/t/ingest-dns-queres-from-windows-dns-server-using-winlogbeat/341560)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 9:49am UTC](https://discuss.elastic.co/t/ingest-dns-queres-from-windows-dns-server-using-winlogbeat/341560 "2023-08-24T09:49:48Z")

</div>

Hello Community, I want to ingest to elasticsearch all DNS Queries from my MS-DNS-server 2019, How to configure winlogbeat, and that is the EvtLog name. Thanks

---

## [Security Privileges - Auto Expand Replicas](https://discuss.elastic.co/t/security-privileges-auto-expand-replicas/341555)

<div class="topic-metadata">

**Author:** [@tneto](https://discuss.elastic.co/u/tneto)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 9:09am UTC](https://discuss.elastic.co/t/security-privileges-auto-expand-replicas/341555 "2023-08-24T09:09:46Z")

</div>

Hello. I'm running ES version 8.1.3 and I'm facing some issues regarding "auto\_expand\_replicas" This is my command on the console over Dev Tools. PUT /.kibana/\_settings { "index" : { "number\_of\_replicas":0, "aut…

---

## [How can I change an existing node with both "master" and "data" roles to be a "master" role only, without any downtime?](https://discuss.elastic.co/t/how-can-i-change-an-existing-node-with-both-master-and-data-roles-to-be-a-master-role-only-without-any-downtime/340526)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 8:53am UTC](https://discuss.elastic.co/t/how-can-i-change-an-existing-node-with-both-master-and-data-roles-to-be-a-master-role-only-without-any-downtime/340526 "2023-08-24T08:53:16Z")

</div>

I have a cluster with multiple nodes. I intend to dynamically change an existing node that currently serves both the "master" and "data" roles to exclusively perform the "data" role, all without causing any downtime. Wha…

---

## [Extracting texts from Flatten/ Scanned PDF Documents in Kibana](https://discuss.elastic.co/t/extracting-texts-from-flatten-scanned-pdf-documents-in-kibana/341351)

<div class="topic-metadata">

**Author:** [@Anant\_Patankar](https://discuss.elastic.co/u/Anant_Patankar)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 8:50am UTC](https://discuss.elastic.co/t/extracting-texts-from-flatten-scanned-pdf-documents-in-kibana/341351 "2023-08-24T08:50:10Z")

</div>

Hello Everyone, I am trying to read texts from scanned/flattened pdf which are made up of images and texts that are not readable with a pdf reader. How can I read and index texts from flattened or scanned pdf files in …

---

## [How can I pass filters to a dashboard through url](https://discuss.elastic.co/t/how-can-i-pass-filters-to-a-dashboard-through-url/341455)

<div class="topic-metadata">

**Author:** [@kanna](https://discuss.elastic.co/u/kanna)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 8:45am UTC](https://discuss.elastic.co/t/how-can-i-pass-filters-to-a-dashboard-through-url/341455 "2023-08-24T08:45:14Z")

</div>

Hi, I have been trying to pass filters as part of url without success. I followed examples in other threads I would like to add following filters created manually on dashboard as part of url { "query": { "match…

---

## [Audit log issue for Elasticsearch 7.15.2 with trail license](https://discuss.elastic.co/t/audit-log-issue-for-elasticsearch-7-15-2-with-trail-license/341551)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 8:30am UTC](https://discuss.elastic.co/t/audit-log-issue-for-elasticsearch-7-15-2-with-trail-license/341551 "2023-08-24T08:30:24Z")

</div>

Hi Team, I am using Elasticsearch 7.15.2 version with trail license on rpm machine(Red HAT). After enabling the audit log in elasticsearch.yml file , I am not getting audit log for the queries which I had executed. I…

---

## [Help for elk stack](https://discuss.elastic.co/t/help-for-elk-stack/341447)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 5\
**Last updated:** [August 24, 2023, 8:27am UTC](https://discuss.elastic.co/t/help-for-elk-stack/341447 "2023-08-24T08:27:13Z")

</div>

Can I make the datamart from elk stack . and How do I combine 2 index data in elasticsearch do-i-combine-2-index-data-in-elasticsearch/199044 .

---

## [I am using Multiline codec input plugin but the events which are not matching with my PATTERN it also processing those Events](https://discuss.elastic.co/t/i-am-using-multiline-codec-input-plugin-but-the-events-which-are-not-matching-with-my-pattern-it-also-processing-those-events/341425)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 8:13am UTC](https://discuss.elastic.co/t/i-am-using-multiline-codec-input-plugin-but-the-events-which-are-not-matching-with-my-pattern-it-also-processing-those-events/341425 "2023-08-24T08:13:59Z")

</div>

Below is the codec which am using for multiline events. codec =\> multiline { pattern =\> "%{TIMESTAMP\_ISO8601:syslogtime}\\s%{WORD:str}\\s%{WORD:s}\\s%{YEAR:yeaa}-%{MONTHNUM:ooo}-%{MONTHDAY:ppp}\\s%{TIME:trrrs}" #patte…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=441)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=443)
