# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=449

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 450

---

## [Logstash kafka input plugin not working](https://discuss.elastic.co/t/logstash-kafka-input-plugin-not-working/340956)

<div class="topic-metadata">

**Author:** [@MheniMerz](https://discuss.elastic.co/u/MheniMerz)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 12:14pm UTC](https://discuss.elastic.co/t/logstash-kafka-input-plugin-not-working/340956 "2023-08-17T12:14:49Z")

</div>

Hi, i'm trying to use logstash kafka input plugin to read messages then send them to elasticsearch. my logstash version is 8.6.2 and my kafka version is 3.5.1 root@logstash-02:~# /usr/share/logstash/bin/logstash --ver…

---

## [Bulk API without printing result on terminal](https://discuss.elastic.co/t/bulk-api-without-printing-result-on-terminal/341002)

<div class="topic-metadata">

**Author:** [@cr\_168328](https://discuss.elastic.co/u/cr_168328)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 12:23pm UTC](https://discuss.elastic.co/t/bulk-api-without-printing-result-on-terminal/341002 "2023-08-17T12:23:13Z")

</div>

Is it possible to execute the Bulk API without printing the result on terminal? I am using the following API: curl -X POST "localhost:9200/log/\_bulk?pretty" -H 'Content-Type: application/json' --data-binary @path/log.l…

---

## [Display the consumed energy for every single device in a Trend](https://discuss.elastic.co/t/display-the-consumed-energy-for-every-single-device-in-a-trend/337186)

<div class="topic-metadata">

**Author:** [@deepack86](https://discuss.elastic.co/u/deepack86)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 11:59am UTC](https://discuss.elastic.co/t/display-the-consumed-energy-for-every-single-device-in-a-trend/337186 "2023-08-17T11:59:25Z")

</div>

Hi together, i have a site with three electric devices but only one energy meter. The task is to display the consumed energy for every single device in a Trend. So i get the actual consumed accumulated Energy from the…

---

## [Issue with SSL when importing data but fine in browser](https://discuss.elastic.co/t/issue-with-ssl-when-importing-data-but-fine-in-browser/341008)

<div class="topic-metadata">

**Author:** [@nick\_harper1](https://discuss.elastic.co/u/nick_harper1)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 11:57am UTC](https://discuss.elastic.co/t/issue-with-ssl-when-importing-data-but-fine-in-browser/341008 "2023-08-17T11:57:05Z")

</div>

I have setup an SSL from a local CA which is working fine when I try to view in the browser from the server I am pushing data from but when trying to push data I get the following error on the server: \[2023-08-17T12:40:…

---

## [Disable IPv6 / / AAAA lookups](https://discuss.elastic.co/t/disable-ipv6-aaaa-lookups/341006)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 11:54am UTC](https://discuss.elastic.co/t/disable-ipv6-aaaa-lookups/341006 "2023-08-17T11:54:25Z")

</div>

Hi, I found out that in my GCP stack, my internal DNS setup is costing more than I anticipated. Unfortunately, it seems that there's a lookup cache issue, however, if I could prevent Filebeat using IPv6 / AAAA lookups (…

---

## [Repository-s3 is not compatible with AWS S3 on OUTPOSTS](https://discuss.elastic.co/t/repository-s3-is-not-compatible-with-aws-s3-on-outposts/340999)

<div class="topic-metadata">

**Author:** [@MatiF99](https://discuss.elastic.co/u/MatiF99)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 10:50am UTC](https://discuss.elastic.co/t/repository-s3-is-not-compatible-with-aws-s3-on-outposts/340999 "2023-08-17T10:50:23Z")

</div>

Hello! I am running Elasticsearch cluster on AWS EC2s in version 7.9.1 on AWS Outposts. I wanted to register snapshot repository on s3 bucket which is in this same Outposts, and I was not able to do it. S3 on outposts …

---

## [Kibana TSVB aggregation group by Terms not working correctly?](https://discuss.elastic.co/t/kibana-tsvb-aggregation-group-by-terms-not-working-correctly/340961)

<div class="topic-metadata">

**Author:** [@Hannah\_Zhang](https://discuss.elastic.co/u/Hannah_Zhang)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 4:12am UTC](https://discuss.elastic.co/t/kibana-tsvb-aggregation-group-by-terms-not-working-correctly/340961 "2023-08-17T04:12:29Z")

</div>

It seems when I use TSVB with Aggregation "Average" of Field "cm\_status.upstream\_power", with Group By "Terms" of Field "cm\_status.mac-address.keyword", all mac-addresses show the same value so the multiple lines show id…

---

## [I am using EVENTHUB input Plugin of Logstash for Capturing Azure event hub Audit logs. But there is Data loss](https://discuss.elastic.co/t/i-am-using-eventhub-input-plugin-of-logstash-for-capturing-azure-event-hub-audit-logs-but-there-is-data-loss/340994)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 10:21am UTC](https://discuss.elastic.co/t/i-am-using-eventhub-input-plugin-of-logstash-for-capturing-azure-event-hub-audit-logs-but-there-is-data-loss/340994 "2023-08-17T10:21:17Z")

</div>

Below Configuration We are using: input { azure\_event\_hubs { config\_mode =\> "basic" #Insert primary connection string from shared access policies in event hub namespace from azure portal event\_hub…

---

## [I'm trying to get xewriter to deliver MSSQL logfiles to my elasticsearch](https://discuss.elastic.co/t/im-trying-to-get-xewriter-to-deliver-mssql-logfiles-to-my-elasticsearch/340826)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 4\
**Last updated:** [August 17, 2023, 9:21am UTC](https://discuss.elastic.co/t/im-trying-to-get-xewriter-to-deliver-mssql-logfiles-to-my-elasticsearch/340826 "2023-08-17T09:21:18Z")

</div>

In my logstash I have this to handle different logfiles with different index names: output { elasticsearch { hosts =\> "https://elasticsearch:9200" index =\> "%{\[fields\]\[logtype\]}-%{\[@metadata\]\[version\]}-%{+YY…

---

## [Problems with SCORE on Anomaly Detection JOB](https://discuss.elastic.co/t/problems-with-score-on-anomaly-detection-job/338600)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 10\
**Last updated:** [August 17, 2023, 8:32am UTC](https://discuss.elastic.co/t/problems-with-score-on-anomaly-detection-job/338600 "2023-08-17T08:32:38Z")

</div>

hi! I have this behavior The typical value was 18.3 and the Actual vale was 0. The anomaly score is too low and I should had received an anomaly alert but the score was wrong, so the alert was not fired. I also…

---

## [Simulate index results](https://discuss.elastic.co/t/simulate-index-results/340981)

<div class="topic-metadata">

**Author:** [@franck.valentin](https://discuss.elastic.co/u/franck.valentin)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 8:08am UTC](https://discuss.elastic.co/t/simulate-index-results/340981 "2023-08-17T08:08:24Z")

</div>

Hi, I was testing the Simulate index API on Elasticsearch 7.17 and didn't understand some of the results. The requests below create separate component templates for the mappings and settings and then index templates …

---

## [Example of error response for POST \_aliases API](https://discuss.elastic.co/t/example-of-error-response-for-post-aliases-api/340917)

<div class="topic-metadata">

**Author:** [@Tomas\_Hanus](https://discuss.elastic.co/u/Tomas_Hanus)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 7:41am UTC](https://discuss.elastic.co/t/example-of-error-response-for-post-aliases-api/340917 "2023-08-17T07:41:14Z")

</div>

Hi, we are using 8.x JAVA client to communicate with Elasticsearch. In case of trying to handle unexpected error for updating aliases the documentation is saying nothing - Aliases API | Elasticsearch Guide \[8.11\] | Elas…

---

## [Can I access data in my 2nd lookup using 1st lookup result using jdbc\_static filter in Logstash for my mariaDB data](https://discuss.elastic.co/t/can-i-access-data-in-my-2nd-lookup-using-1st-lookup-result-using-jdbc-static-filter-in-logstash-for-my-mariadb-data/340977)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 7:32am UTC](https://discuss.elastic.co/t/can-i-access-data-in-my-2nd-lookup-using-1st-lookup-result-using-jdbc-static-filter-in-logstash-for-my-mariadb-data/340977 "2023-08-17T07:32:20Z")

</div>

Hello I am using jdbc\_static filter in Logstash for my mariaDB data . where I have define 2 local\_lookups. Can I access data in my 2nd lookup using 1st lookup result fields ???????????????? local\_lookups =\> \[ { …

---

## [Simulate index API slow](https://discuss.elastic.co/t/simulate-index-api-slow/340973)

<div class="topic-metadata">

**Author:** [@franck.valentin](https://discuss.elastic.co/u/franck.valentin)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 7:02am UTC](https://discuss.elastic.co/t/simulate-index-api-slow/340973 "2023-08-17T07:02:17Z")

</div>

Hi, I experience performance issues when calling the simulate index API on 7.17 (via the Java method SimulateIndexTemplateRequest() or /\_index\_template/\_simulate\_index/). Our ES installation runs on a Kubernetes cluste…

---

## [Index 256 out of bounds for length 256](https://discuss.elastic.co/t/index-256-out-of-bounds-for-length-256/340710)

<div class="topic-metadata">

**Author:** [@1057888035](https://discuss.elastic.co/u/1057888035)\
**Replies:** 7\
**Last updated:** [August 17, 2023, 1:52am UTC](https://discuss.elastic.co/t/index-256-out-of-bounds-for-length-256/340710 "2023-08-17T01:52:57Z")

</div>

Hi Team, I am trying to execute api like this in elasticsearch GET /\_analyze { "tokenizer": "keyword", "char\_filter": \[ { "type": "mapping", "mappings": \["is a test data is a test data is a test da…

---

## [Java Api client documentation example seems to give JacksonParseException](https://discuss.elastic.co/t/java-api-client-documentation-example-seems-to-give-jacksonparseexception/340841)

<div class="topic-metadata">

**Author:** [@Migodden](https://discuss.elastic.co/u/Migodden)\
**Replies:** 5\
**Last updated:** [August 17, 2023, 1:11am UTC](https://discuss.elastic.co/t/java-api-client-documentation-example-seems-to-give-jacksonparseexception/340841 "2023-08-17T01:11:09Z")

</div>

I am attempting to query my elastic cluster using the Elasticsearch Java Api client documentation for my version of elastic, however, I am encountering an error. Is this error because of how I am formulating my query? Co…

---

## [Cluster.initial\_master\_nodes for ElasticSearch on EC2 with Auto Scaling](https://discuss.elastic.co/t/cluster-initial-master-nodes-for-elasticsearch-on-ec2-with-auto-scaling/340784)

<div class="topic-metadata">

**Author:** [@cockroachmondays](https://discuss.elastic.co/u/cockroachmondays)\
**Replies:** 6\
**Last updated:** [August 16, 2023, 10:56pm UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-for-elasticsearch-on-ec2-with-auto-scaling/340784 "2023-08-16T22:56:12Z")

</div>

Trying to upgrade ES from 6.8 to 8.9 for ES running on EC2 AWS instances. The issue is within cluster.initial\_master\_nodes. I see that I set fixed values for node.name. However, the instances are created by Auto Scaling…

---

## [New elasticsearch-client for termsuggest accuracy not available](https://discuss.elastic.co/t/new-elasticsearch-client-for-termsuggest-accuracy-not-available/340954)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 8:22pm UTC](https://discuss.elastic.co/t/new-elasticsearch-client-for-termsuggest-accuracy-not-available/340954 "2023-08-16T20:22:01Z")

</div>

We could not find any option to supply accuracy with term suggest. But Elasticsearch core lib provided that option. https://www.javadoc.io/doc/org.elasticsearch/elasticsearch/latest/org.elasticsearch.server/org/elastics…

---

## [Elastic JSON Processor Error: \`cannot add non-map fields to root of document\`](https://discuss.elastic.co/t/elastic-json-processor-error-cannot-add-non-map-fields-to-root-of-document/340845)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 5\
**Last updated:** [August 16, 2023, 5:39pm UTC](https://discuss.elastic.co/t/elastic-json-processor-error-cannot-add-non-map-fields-to-root-of-document/340845 "2023-08-16T17:39:56Z")

</div>

I am ingesting logs in the ECS format from the Elastic Serverless Forwarder into Elasticsearch. These logs are generated by the ECS Python logging library. Because they are being generated by ESF, I need to expand the nd…

---

## [Kubernetes container labels](https://discuss.elastic.co/t/kubernetes-container-labels/340942)

<div class="topic-metadata">

**Author:** [@Omar\_Al](https://discuss.elastic.co/u/Omar_Al)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 3:59pm UTC](https://discuss.elastic.co/t/kubernetes-container-labels/340942 "2023-08-16T15:59:08Z")

</div>

We are in the process of creating a new instance of filebeat where we switch the container runtime to containerd, and we previously searched for a label in the docker container, but since we switched to containerd, we wo…

---

## [Error when running snapshot using API and console](https://discuss.elastic.co/t/error-when-running-snapshot-using-api-and-console/340937)

<div class="topic-metadata">

**Author:** [@anfel](https://discuss.elastic.co/u/anfel)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 2:45pm UTC](https://discuss.elastic.co/t/error-when-running-snapshot-using-api-and-console/340937 "2023-08-16T14:45:46Z")

</div>

Hi, we are running elastichsearch 7.17 , i have noticed that all the snapshots stored were delated without any indicator . when i tried running a new snapshot using API : PUT \_snapshot/synology/daily\_snapshot-15-08-23 …

---

## [APM java agent dynamic configs not working](https://discuss.elastic.co/t/apm-java-agent-dynamic-configs-not-working/340936)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 2:42pm UTC](https://discuss.elastic.co/t/apm-java-agent-dynamic-configs-not-working/340936 "2023-08-16T14:42:53Z")

</div>

We have elastic stack 8.6.3 with java agent version 1.36.0. Trying to dynamically add few custom traces via trace\_methods config property. Created configuration in UI with changes. I dont see custom trace methods are …

---

## [Filebeat-Container neither sends data to elasticsearch nor writes output to console/file](https://discuss.elastic.co/t/filebeat-container-neither-sends-data-to-elasticsearch-nor-writes-output-to-console-file/340904)

<div class="topic-metadata">

**Author:** [@hmmh-sven-scheil](https://discuss.elastic.co/u/hmmh-sven-scheil)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-container-neither-sends-data-to-elasticsearch-nor-writes-output-to-console-file/340904 "2023-08-16T14:08:31Z")

</div>

Hi there, I'am trying to setup a demo scenario, to demonstrate how to collect Tomcat log data from different containers and send it to an elastic stack for log aggregation and log analysis. I try to describe my setup, …

---

## [Elastic Search - how to create index with mapping](https://discuss.elastic.co/t/elastic-search-how-to-create-index-with-mapping/340925)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 2:08pm UTC](https://discuss.elastic.co/t/elastic-search-how-to-create-index-with-mapping/340925 "2023-08-16T14:08:09Z")

</div>

elasticsearch:8.7.1 I am creating index this way: return new CreateIndexRequest.Builder() .index(name) .aliases(alias, new Alias.Builder().build()) .settings(new Inde…

---

## [Invalid CRI error (Filebeat 7.17 + docker)](https://discuss.elastic.co/t/invalid-cri-error-filebeat-7-17-docker/340930)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 1:57pm UTC](https://discuss.elastic.co/t/invalid-cri-error-filebeat-7-17-docker/340930 "2023-08-16T13:57:17Z")

</div>

Hi there! We have a weird problem when Filebeat gets stuck on partial message in Container logs. Parse line error: invalid CRI log format {"level":"error","timestamp":"2023-08-03T11:55:49.674Z","logger":"reader\_docker…

---

## [I am trying to capture audit logs from 2 event hubs but there is data loss or some time not getting the audit logs. I am using below input configuration](https://discuss.elastic.co/t/i-am-trying-to-capture-audit-logs-from-2-event-hubs-but-there-is-data-loss-or-some-time-not-getting-the-audit-logs-i-am-using-below-input-configuration/340924)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 1:21pm UTC](https://discuss.elastic.co/t/i-am-trying-to-capture-audit-logs-from-2-event-hubs-but-there-is-data-loss-or-some-time-not-getting-the-audit-logs-i-am-using-below-input-configuration/340924 "2023-08-16T13:21:40Z")

</div>

input { azure\_event\_hubs { config\_mode =\> "basic" #Insert primary connection string from shared access policies in event hub namespace from azure portal event\_hub\_connections =\> \["\<Shared Acess Pol…

---

## [Registry log.json grows constantly even with filebeat.registry.flush: 60s](https://discuss.elastic.co/t/registry-log-json-grows-constantly-even-with-filebeat-registry-flush-60s/340923)

<div class="topic-metadata">

**Author:** [@pkulenkamp](https://discuss.elastic.co/u/pkulenkamp)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 1:04pm UTC](https://discuss.elastic.co/t/registry-log-json-grows-constantly-even-with-filebeat-registry-flush-60s/340923 "2023-08-16T13:04:24Z")

</div>

Filebeat 7.17.1 I'm looking into decreasing the amount of IO for the filebeat registry in our deployment. I found the filebeat.registry.flush setting after some research and thought that it would do what I wanted. I s…

---

## [Executing multiple .conf files in one instance](https://discuss.elastic.co/t/executing-multiple-conf-files-in-one-instance/340749)

<div class="topic-metadata">

**Author:** [@Tony\_Stark](https://discuss.elastic.co/u/Tony_Stark)\
**Replies:** 9\
**Last updated:** [August 16, 2023, 12:48pm UTC](https://discuss.elastic.co/t/executing-multiple-conf-files-in-one-instance/340749 "2023-08-16T12:48:52Z")

</div>

I am trying to execute multiple .conf files in logstash with logstash -f "path\*.conf" but logstash processes the .conf file the same number of times as the number of .conf files I have , if I have 5 .conf files , I get o…

---

## [Elasticsearch query based on timestamp from kibana (dev tools)](https://discuss.elastic.co/t/elasticsearch-query-based-on-timestamp-from-kibana-dev-tools/340893)

<div class="topic-metadata">

**Author:** [@Mamta\_Bharadwaj](https://discuss.elastic.co/u/Mamta_Bharadwaj)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 12:40pm UTC](https://discuss.elastic.co/t/elasticsearch-query-based-on-timestamp-from-kibana-dev-tools/340893 "2023-08-16T12:40:15Z")

</div>

Hello All, I am using ELK 8.3.3 on Docker. When I am trying to fetch the data with any timestamp range, I am getting the correct output. But when I am trying to fetch the data based on the below, I am getting nothing. P…

---

## [Storage sinze index of a policy](https://discuss.elastic.co/t/storage-sinze-index-of-a-policy/340881)

<div class="topic-metadata">

**Author:** [@agomezgu](https://discuss.elastic.co/u/agomezgu)\
**Replies:** 2\
**Last updated:** [August 16, 2023, 12:36pm UTC](https://discuss.elastic.co/t/storage-sinze-index-of-a-policy/340881 "2023-08-16T12:36:48Z")

</div>

Hi, I'm new to ELKstack and I'm trying to get from an Index Lifecycle Policies "logstash-pro" all the indexes that are in it, and also about this to return me the space occupied by each index. For example, I use the sta…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=448)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=450)
