# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=453

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 454

---

## [Elasticsearch cluster search performance is bad after upgrade from 7.17 to 8.8](https://discuss.elastic.co/t/elasticsearch-cluster-search-performance-is-bad-after-upgrade-from-7-17-to-8-8/340592)

<div class="topic-metadata">

**Author:** [@chandra123](https://discuss.elastic.co/u/chandra123)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 5:12pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-search-performance-is-bad-after-upgrade-from-7-17-to-8-8/340592 "2023-08-11T17:12:56Z")

</div>

Hello Elasticsearch Community, We recently did in-place upgrade from 7.17 to 8.8 and after which we started to see degraded search performance/latency. We have 150 data nodes and we observed that at most 10 data nodes a…

---

## [How to filter the particular timestamp in KQL field](https://discuss.elastic.co/t/how-to-filter-the-particular-timestamp-in-kql-field/340655)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 4:58pm UTC](https://discuss.elastic.co/t/how-to-filter-the-particular-timestamp-in-kql-field/340655 "2023-08-11T16:58:34Z")

</div>

Hi Can anyone tell me the how to search the particular timestamp in KQL. Am I using the below format in logstash filter. time\_stamp 11/Aug/2023:16:31:44 +0000 So how to use this time\_stamp field and grep the log…

---

## [Is it possible to develop a custom plugin for Filebeat](https://discuss.elastic.co/t/is-it-possible-to-develop-a-custom-plugin-for-filebeat/339952)

<div class="topic-metadata">

**Author:** [@uday22](https://discuss.elastic.co/u/uday22)\
**Replies:** 4\
**Last updated:** [August 11, 2023, 4:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-develop-a-custom-plugin-for-filebeat/339952 "2023-08-11T16:11:03Z")

</div>

Hi, I want to develop a custom plugin for filebeat, where the sensitive information in log files are encrypted. Finding sensitive information can be done by regular expression. I want to know weather the above requireme…

---

## [Terms list might be incomplete because the request is taking too long - Warn message on the dashboard](https://discuss.elastic.co/t/terms-list-might-be-incomplete-because-the-request-is-taking-too-long-warn-message-on-the-dashboard/340644)

<div class="topic-metadata">

**Author:** [@Kumbum](https://discuss.elastic.co/u/Kumbum)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 2:28pm UTC](https://discuss.elastic.co/t/terms-list-might-be-incomplete-because-the-request-is-taking-too-long-warn-message-on-the-dashboard/340644 "2023-08-11T14:28:34Z")

</div>

Hi, I have been seeing the following warn message on the dashboard for the dropdown field. However, the dashboard shows expected results but not sure why has it been showing up there. Terms list might be incomplete bec…

---

## [ELK Stack into AKS](https://discuss.elastic.co/t/elk-stack-into-aks/339086)

<div class="topic-metadata">

**Author:** [@izbant](https://discuss.elastic.co/u/izbant)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 2:30pm UTC](https://discuss.elastic.co/t/elk-stack-into-aks/339086 "2023-08-11T14:30:11Z")

</div>

Hello, I am trying to deploy ELK Stack with basic license into my AKS cluster, but i am unable to secure connection between logstash and elasticsearch. Is there any documentation for deploying ELK Stack into an AKS clu…

---

## [SAML - Migrate to new IDP](https://discuss.elastic.co/t/saml-migrate-to-new-idp/340534)

<div class="topic-metadata">

**Author:** [@heric](https://discuss.elastic.co/u/heric)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 2:29pm UTC](https://discuss.elastic.co/t/saml-migrate-to-new-idp/340534 "2023-08-11T14:29:14Z")

</div>

Hi All, I have 5 nodes cluster of elasticsearch integrated to SAML IDP. i want to migrate to new SAML IDP but i don't have working test environment to integrate to this new IDP. Below scenario that i can think of, do …

---

## [Msearch with PHP](https://discuss.elastic.co/t/msearch-with-php/340585)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 1:56pm UTC](https://discuss.elastic.co/t/msearch-with-php/340585 "2023-08-11T13:56:44Z")

</div>

Hello , I am using msearch like this doc - well it is working in kibana . but when I try to do it , in php . does not work . this is my test code - $this-\>elasticSeacrh-\>msearch(\[ …

---

## [Bin/logstash-plugin not found](https://discuss.elastic.co/t/bin-logstash-plugin-not-found/340574)

<div class="topic-metadata">

**Author:** [@roel82](https://discuss.elastic.co/u/roel82)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 1:03pm UTC](https://discuss.elastic.co/t/bin-logstash-plugin-not-found/340574 "2023-08-11T13:03:21Z")

</div>

I have deployed LogStash on kubernetes using this image (logstash:8.8.1) and now I would like to install some plugins. I understand that I would need to use the 'logstash-plugin' tool, whis should be located in the bin …

---

## [If condition for null in json field](https://discuss.elastic.co/t/if-condition-for-null-in-json-field/340475)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 12:59pm UTC](https://discuss.elastic.co/t/if-condition-for-null-in-json-field/340475 "2023-08-11T12:59:42Z")

</div>

I'm using the JDBC filter to pull info from a SQL database. If the field is blank, it generates the below: "example": \[ { "contoso": "" } \] I've tried the below to remove the empty field, but i…

---

## [Backup Detection Rules and Exceptions](https://discuss.elastic.co/t/backup-detection-rules-and-exceptions/340639)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 12:48pm UTC](https://discuss.elastic.co/t/backup-detection-rules-and-exceptions/340639 "2023-08-11T12:48:29Z")

</div>

Hello everybody, I want to backup all security detection rules and the exceptions I defined for my Cluster. From the documentation I learned how to access rules via the kibana api but there must also be an elasticsearch…

---

## [Winlogbeat ForwardedEvents channels filtering](https://discuss.elastic.co/t/winlogbeat-forwardedevents-channels-filtering/340626)

<div class="topic-metadata">

**Author:** [@stanley783](https://discuss.elastic.co/u/stanley783)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 12:21pm UTC](https://discuss.elastic.co/t/winlogbeat-forwardedevents-channels-filtering/340626 "2023-08-11T12:21:40Z")

</div>

Hi, we have servers forwarding various log channels (System, Security, Powershell..., Defender..) to WEC server via standard WEF service. Installed Winlogbeat on WEC server to forward those logs to ELK. However, we want…

---

## [Node roles impact on nodes](https://discuss.elastic.co/t/node-roles-impact-on-nodes/340625)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 12:13pm UTC](https://discuss.elastic.co/t/node-roles-impact-on-nodes/340625 "2023-08-11T12:13:10Z")

</div>

Hi, We currently have a really big cluster with 150+ nodes. We are using node attributes to manage the data tiers and our ILM is based on it (node.attr.data). We are currently investigating the impact of migrating to …

---

## [Filters in the url are reset when redirect to Wazuh Dashboard](https://discuss.elastic.co/t/filters-in-the-url-are-reset-when-redirect-to-wazuh-dashboard/340622)

<div class="topic-metadata">

**Author:** [@Aigerim\_Kubanychbeko](https://discuss.elastic.co/u/Aigerim_Kubanychbeko)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 12:00pm UTC](https://discuss.elastic.co/t/filters-in-the-url-are-reset-when-redirect-to-wazuh-dashboard/340622 "2023-08-11T12:00:40Z")

</div>

I have a table in my Opensearch Dashboard. Also, I have Dashboard in Wazuh, integrated in Elastic. Wazuh is like a security application with its built-in dashboards of different categories. I need to create an url for t…

---

## [I have a older version of Logstash 7.16.2 , is there a output plugin for email. i dont see it for 7.16.2 version](https://discuss.elastic.co/t/i-have-a-older-version-of-logstash-7-16-2-is-there-a-output-plugin-for-email-i-dont-see-it-for-7-16-2-version/339705)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 11:06am UTC](https://discuss.elastic.co/t/i-have-a-older-version-of-logstash-7-16-2-is-there-a-output-plugin-for-email-i-dont-see-it-for-7-16-2-version/339705 "2023-08-11T11:06:40Z")

</div>

Hi Team, I have an older version of logstash 7.16.2 and i need install an Email output plugin for it . Is there a plugin available for this version . I see the 7.17.x versions have the output plugins. while i cannot f…

---

## [Poll data ingestion to an index should trigger data ingestion to another index](https://discuss.elastic.co/t/poll-data-ingestion-to-an-index-should-trigger-data-ingestion-to-another-index/340617)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 10:25am UTC](https://discuss.elastic.co/t/poll-data-ingestion-to-an-index-should-trigger-data-ingestion-to-another-index/340617 "2023-08-11T10:25:00Z")

</div>

Hi, Let's say I have to indices, index\_poll and index\_latest. Index\_poll gets metrics data from devices using logstash and beats. When data is ingested into index\_poll, I want this to trigger the data ingestion/updatio…

---

## [How to create dynamic title in Markdown with Handlebars(mustache)?](https://discuss.elastic.co/t/how-to-create-dynamic-title-in-markdown-with-handlebars-mustache/339173)

<div class="topic-metadata">

**Author:** [@Aigerim\_Kubanychbeko](https://discuss.elastic.co/u/Aigerim_Kubanychbeko)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 7:50am UTC](https://discuss.elastic.co/t/how-to-create-dynamic-title-in-markdown-with-handlebars-mustache/339173 "2023-08-11T07:50:37Z")

</div>

I wonder if there any way to create dynamic title in the TVSB visualization using Markdown and Handlebars. This visualization is a part of the dashboard. Whenever I filter particular field: title.keyword is ... this tit…

---

## [Auditbeat failed to load rules on aarch64/ARM 64 bits](https://discuss.elastic.co/t/auditbeat-failed-to-load-rules-on-aarch64-arm-64-bits/340612)

<div class="topic-metadata">

**Author:** [@albertchen](https://discuss.elastic.co/u/albertchen)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:47am UTC](https://discuss.elastic.co/t/auditbeat-failed-to-load-rules-on-aarch64-arm-64-bits/340612 "2023-08-11T05:47:56Z")

</div>

Hi sir, When I try to load the following rules on aarch64 platform (ARM 64 bits) -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open\_by\_handle\_at -F exit=-EACCES -k access -a always,exit -F arch=b64…

---

## [Filebeat mssql module multiple drive paths in var.paths config](https://discuss.elastic.co/t/filebeat-mssql-module-multiple-drive-paths-in-var-paths-config/340554)

<div class="topic-metadata">

**Author:** [@Craig\_Sharp](https://discuss.elastic.co/u/Craig_Sharp)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:56am UTC](https://discuss.elastic.co/t/filebeat-mssql-module-multiple-drive-paths-in-var-paths-config/340554 "2023-08-11T06:56:39Z")

</div>

I am ingesting mssql logs from a failover cluster. Due to the nature of the cluster each node has a different mount / drive letter for the log data. The cluster may have M:, N:, O: P:, etc. but only one per node. This ma…

---

## [How to pass variables to filebeat through the Elastic-Agent?](https://discuss.elastic.co/t/how-to-pass-variables-to-filebeat-through-the-elastic-agent/340031)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 6:34am UTC](https://discuss.elastic.co/t/how-to-pass-variables-to-filebeat-through-the-elastic-agent/340031 "2023-08-11T06:34:27Z")

</div>

Hi, We currently use stand-alone filebeat running as a systemd service to shipt cusom application logs to elasticsearch. On each application server, the main application creates/updates a file at boot time and populate …

---

## [Error executing logstash pipeline with jdbc select SQLDataException: ORA-01846: not a valid day of the week](https://discuss.elastic.co/t/error-executing-logstash-pipeline-with-jdbc-select-sqldataexception-ora-01846-not-a-valid-day-of-the-week/340368)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 4\
**Last updated:** [August 11, 2023, 6:23am UTC](https://discuss.elastic.co/t/error-executing-logstash-pipeline-with-jdbc-select-sqldataexception-ora-01846-not-a-valid-day-of-the-week/340368 "2023-08-11T06:23:14Z")

</div>

We have into logstash pipeline the config to search into database and get the data, after the first search we want only select the new data, to do this we use the config of jdbc plugin, my pipeline config. input { jdb…

---

## [Ruby code include?](https://discuss.elastic.co/t/ruby-code-include/340336)

<div class="topic-metadata">

**Author:** [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 5:48am UTC](https://discuss.elastic.co/t/ruby-code-include/340336 "2023-08-11T05:48:03Z")

</div>

Hi All, I have this code that used to be working in ELK 7.12 now that I've upgrade to 8.7.1 it gives a weird error in logstash code =\> " ip\_src = Array.new ip\_…

---

## [Metricbeat](https://discuss.elastic.co/t/metricbeat/340611)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:30am UTC](https://discuss.elastic.co/t/metricbeat/340611 "2023-08-11T05:30:23Z")

</div>

How to get the cpu and memory usage of each users in "CPU Usage \[Metricbeat System\] ECS in ELK" and "Memory Usage \[Metricbeat System\] ECS in ELK". Right now it is showing the metric of 'user' fields which contains all th…

---

## [Parse\_exception, status 400 while reindexing](https://discuss.elastic.co/t/parse-exception-status-400-while-reindexing/340610)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:20am UTC](https://discuss.elastic.co/t/parse-exception-status-400-while-reindexing/340610 "2023-08-11T05:20:00Z")

</div>

We are re-indexing some indices with an updated field mapping. The approach taken is to create a new index with the updated mapping, then copy the existing index into the new index using the Reindex API. Code #create e…

---

## [Kibana 8.9.0 Something went wrong :e.replaceAll is not a function](https://discuss.elastic.co/t/kibana-8-9-0-something-went-wrong-e-replaceall-is-not-a-function/340601)

<div class="topic-metadata">

**Author:** [@ss\_s](https://discuss.elastic.co/u/ss_s)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 2:53am UTC](https://discuss.elastic.co/t/kibana-8-9-0-something-went-wrong-e-replaceall-is-not-a-function/340601 "2023-08-11T02:53:27Z")

</div>

Hey Elastic Community team, When I open Kibana on the web after login.This error occurred i try to refreshing the page,but the error continued； Microsoft Edge 84.0.522.52

---

## [We have cluster of 4 nodes, where 2 nodes are master and data and other 2 nodes are data nodes, the configuration was working fine since 2 yrs, today we have to restart the cluster and since then we are getting master not discovered exception](https://discuss.elastic.co/t/we-have-cluster-of-4-nodes-where-2-nodes-are-master-and-data-and-other-2-nodes-are-data-nodes-the-configuration-was-working-fine-since-2-yrs-today-we-have-to-restart-the-cluster-and-since-then-we-are-getting-master-not-discovered-exception/340122)

<div class="topic-metadata">

**Author:** [@vishnu\_ishpujani](https://discuss.elastic.co/u/vishnu_ishpujani)\
**Replies:** 25\
**Last updated:** [August 11, 2023, 2:41am UTC](https://discuss.elastic.co/t/we-have-cluster-of-4-nodes-where-2-nodes-are-master-and-data-and-other-2-nodes-are-data-nodes-the-configuration-was-working-fine-since-2-yrs-today-we-have-to-restart-the-cluster-and-since-then-we-are-getting-master-not-discovered-exception/340122 "2023-08-11T02:41:53Z")

</div>

Please fine attached the logs for master 1 and master 2 \[2023-08-04T20:42:56,086\]\[WARN \]\[r.suppressed \] \[ES-Master-2\] path: /\_license, params: {human=false} org.elasticsearch.discovery.MasterNotDiscoveredExc…

---

## [Documentation for UpdateOperation](https://discuss.elastic.co/t/documentation-for-updateoperation/340566)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 7:02pm UTC](https://discuss.elastic.co/t/documentation-for-updateoperation/340566 "2023-08-10T19:02:48Z")

</div>

Is there any documentation for using UpdateOperation with the new Java API Client. I can't seem to find any. Some examples would be helpful. Thanks.

---

## [Unexpected I/O error while de-serializing auth scheme](https://discuss.elastic.co/t/unexpected-i-o-error-while-de-serializing-auth-scheme/340078)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 7\
**Last updated:** [August 10, 2023, 6:40pm UTC](https://discuss.elastic.co/t/unexpected-i-o-error-while-de-serializing-auth-scheme/340078 "2023-08-10T18:40:14Z")

</div>

I have a simple Java Rest client making an index() call. I am getting warning messages: IndexRequest\<Node\> irequest = IndexRequest.of(i -\> i .index("index-b") .id("123") .document(node) ); …

---

## [Fuzzy search](https://discuss.elastic.co/t/fuzzy-search/340584)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 6:17pm UTC](https://discuss.elastic.co/t/fuzzy-search/340584 "2023-08-10T18:17:37Z")

</div>

Hey there, I take in to a project into elasticsearch. The task is a webshop. Right now the problem is, that its possible to search for foo 40 Liter but its not possible for search for foo 40L. My next step is, to use lo…

---

## [How to calculate number of licenses count for my Elastic cluster](https://discuss.elastic.co/t/how-to-calculate-number-of-licenses-count-for-my-elastic-cluster/340583)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 6:14pm UTC](https://discuss.elastic.co/t/how-to-calculate-number-of-licenses-count-for-my-elastic-cluster/340583 "2023-08-10T18:14:33Z")

</div>

Hi, I want to know what criteria are going to apply, when calculating the number of licenses for my Elastic cluster. Thank you..! Hiruni

---

## [Encryption at rest](https://discuss.elastic.co/t/encryption-at-rest/340580)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 6:02pm UTC](https://discuss.elastic.co/t/encryption-at-rest/340580 "2023-08-10T18:02:55Z")

</div>

Using the docker-compose.yml file found in the official Elastic documents: Install Elasticsearch with Docker | Elasticsearch Guide \[8.9\] | Elastic, is my data encryption at rest? Or do I need to add something to the env…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=452)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=454)
