# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=454

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 455

---

## ["Parse line error: parsing docker timestamp: parsing time \\"\\" as \\"2006-01-02T15:04:05Z07:00\\": cannot parse \\"\\" as \\"2006\\"","service.name":"filebeat","ecs.version":"1.6.0"}](https://discuss.elastic.co/t/parse-line-error-parsing-docker-timestamp-parsing-time-as-2006-01-02t1505z07-00-cannot-parse-as-2006-service-name-filebeat-ecs-version-1-6-0/338920)

<div class="topic-metadata">

**Author:** [@dell2](https://discuss.elastic.co/u/dell2)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 5:09pm UTC](https://discuss.elastic.co/t/parse-line-error-parsing-docker-timestamp-parsing-time-as-2006-01-02t1505z07-00-cannot-parse-as-2006-service-name-filebeat-ecs-version-1-6-0/338920 "2023-08-10T17:09:19Z")

</div>

filebeat.autodiscover: providers: - type: kubernetes hints.enabled: true json.message\_key: message json.timestamp.key: timestamp json.keys\_under\_root: true …

---

## [Daily dashboard with metrics from the last document](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 4:06pm UTC](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963 "2023-08-10T16:06:18Z")

</div>

Hello I'm trying to use Vega as a new tool for me in Kibana. I read some basics tutorials and tried some examples with my editor. It is a powerfull tool ! I already used Kibana lens charts for networks logs with billi…

---

## [Query for an event that happens X times within a given timerange](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550)

<div class="topic-metadata">

**Author:** [@blacklistme](https://discuss.elastic.co/u/blacklistme)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 3:17pm UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550 "2023-08-10T15:17:51Z")

</div>

Hi, as the title already suggests, I am looking for a way in Kibana to generate an Seucurity-Alert, if one event ouccures x times within a given timespan. Example: Five Failed logins on a system within 5 Minutes I´ve …

---

## [Urgent Query: Upgrading Kibana from version 7.9.0 to 8.9.0](https://discuss.elastic.co/t/urgent-query-upgrading-kibana-from-version-7-9-0-to-8-9-0/340561)

<div class="topic-metadata">

**Author:** [@Prathamesh\_S\_Pai](https://discuss.elastic.co/u/Prathamesh_S_Pai)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 2:57pm UTC](https://discuss.elastic.co/t/urgent-query-upgrading-kibana-from-version-7-9-0-to-8-9-0/340561 "2023-08-10T14:57:57Z")

</div>

I have been using Kibana version 7.9.0 for my tasks. I would like to upgrade it to the latest version, 8.9.0, as some features supported by the latest version are urgently required. Could you please let me know if upgra…

---

## [ApiKey for a rule maker viewer](https://discuss.elastic.co/t/apikey-for-a-rule-maker-viewer/340573)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 2:41pm UTC](https://discuss.elastic.co/t/apikey-for-a-rule-maker-viewer/340573 "2023-08-10T14:41:20Z")

</div>

Hi I'm trying to create an apikey that would allow to create/view rules/alerts in kibana. I tried this restrictions but apparently they are not enough: { "kibana\_rulemaker": { "cluster": \[\], "indices": \[\], …

---

## [Logstash JSON Filter Error](https://discuss.elastic.co/t/logstash-json-filter-error/340496)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-json-filter-error/340496 "2023-08-10T14:25:22Z")

</div>

I've pulled data from a SQL database that gets put into a field like below. "assignment": \[ { "assignedto": "1234", "assignedtoname": "John Doe", "assignedgroupid": 1 } \] I'm…

---

## [Bucket Script in Composite Aggregation using Java client 8.8.2](https://discuss.elastic.co/t/bucket-script-in-composite-aggregation-using-java-client-8-8-2/340569)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 2:08pm UTC](https://discuss.elastic.co/t/bucket-script-in-composite-aggregation-using-java-client-8-8-2/340569 "2023-08-10T14:08:39Z")

</div>

Java method should be written for the following ES query and I'm getting an error on script() function. "AVERAGE": { "bucket\_script": { "buckets\_path": { …

---

## [Updating every document to prepare for reindexing](https://discuss.elastic.co/t/updating-every-document-to-prepare-for-reindexing/340568)

<div class="topic-metadata">

**Author:** [@supernat10](https://discuss.elastic.co/u/supernat10)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:53pm UTC](https://discuss.elastic.co/t/updating-every-document-to-prepare-for-reindexing/340568 "2023-08-10T13:53:09Z")

</div>

Hi, I am in the process of upgrading to the latest version of Elasticsearch, and during our reindex testing from the old cluster to the new one (as we are jumping from 6.8 to 8.x), we ran into a couple of issues with th…

---

## [ElasticsearchException connection refused](https://discuss.elastic.co/t/elasticsearchexception-connection-refused/340567)

<div class="topic-metadata">

**Author:** [@Hanane1](https://discuss.elastic.co/u/Hanane1)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearchexception-connection-refused/340567 "2023-08-10T13:42:10Z")

</div>

Hello, I have this error when I try to search for something using elasticsearch Caused by: org.springframework.data.elasticsearch.UncategorizedElasticsearchException: java.util.concurrent.ExecutionException: java.net.C…

---

## [Job fails injecting dataframe with variables in index name](https://discuss.elastic.co/t/job-fails-injecting-dataframe-with-variables-in-index-name/340370)

<div class="topic-metadata">

**Author:** [@Joachim\_Rodrigues](https://discuss.elastic.co/u/Joachim_Rodrigues)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 1:08pm UTC](https://discuss.elastic.co/t/job-fails-injecting-dataframe-with-variables-in-index-name/340370 "2023-08-10T13:08:57Z")

</div>

Hello I have this code that injects a dataframe to an elastic cluster 7.9.3 myDataframe.saveToEs("customer-{year}.{month}") But i'm getting this error : User class threw exception: java.lang.Exception: Error(s) durin…

---

## [Please share your wisdom: Passing Elastic key/value pairs instead of log statements?](https://discuss.elastic.co/t/please-share-your-wisdom-passing-elastic-key-value-pairs-instead-of-log-statements/340489)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/please-share-your-wisdom-passing-elastic-key-value-pairs-instead-of-log-statements/340489 "2023-08-10T12:57:38Z")

</div>

Hi all. I'm looking for some very general advice. I know ELK started as a way to make sense of log statements, like: "We shipped 12 yellow rubber duckies to France". It will pick out "yellow", "rubber" and "duckies",…

---

## [Open Search Contexts Not Closed After Expiration](https://discuss.elastic.co/t/open-search-contexts-not-closed-after-expiration/340557)

<div class="topic-metadata">

**Author:** [@Jaeger\_Jochimsen](https://discuss.elastic.co/u/Jaeger_Jochimsen)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 12:25pm UTC](https://discuss.elastic.co/t/open-search-contexts-not-closed-after-expiration/340557 "2023-08-10T12:25:54Z")

</div>

We recently had a sudden surge in open search contexts as a result of initiating many scrolls without iterating on them or closing them explicitly. Even though scroll time to live was set to 2 min we continued to have to…

---

## [WARN messages in elsasticsearch.log CFF/OTF](https://discuss.elastic.co/t/warn-messages-in-elsasticsearch-log-cff-otf/340547)

<div class="topic-metadata">

**Author:** [@shayshy](https://discuss.elastic.co/u/shayshy)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 12:22pm UTC](https://discuss.elastic.co/t/warn-messages-in-elsasticsearch-log-cff-otf/340547 "2023-08-10T12:22:21Z")

</div>

I have lots of WARN Messages in elasticsearch.log org.apache.pdfbox.pdmodel.font.PDCIDFontType2 WARNING: Found CFF/OTF but expected embedded TTF fount Generic3-Regular and also POI does not currently support template…

---

## [AWS target group health check configuration for application load balancer](https://discuss.elastic.co/t/aws-target-group-health-check-configuration-for-application-load-balancer/340553)

<div class="topic-metadata">

**Author:** [@akansha](https://discuss.elastic.co/u/akansha)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 11:35am UTC](https://discuss.elastic.co/t/aws-target-group-health-check-configuration-for-application-load-balancer/340553 "2023-08-10T11:35:34Z")

</div>

I need to expose kibana through application load balancer , i have created one but the problem is health check for target group is failing , what should I do to resolve this?

---

## [Queries regarding reindexing](https://discuss.elastic.co/t/queries-regarding-reindexing/340517)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 10:17am UTC](https://discuss.elastic.co/t/queries-regarding-reindexing/340517 "2023-08-10T10:17:11Z")

</div>

Hi there, I want to get some clarity on the reindexing API and how does it work. After talking to an ES developer I understood few points on the high level. But still I am having a doubt with the below question:- If …

---

## [Discovery service as endpoint provider not recognised](https://discuss.elastic.co/t/discovery-service-as-endpoint-provider-not-recognised/340512)

<div class="topic-metadata">

**Author:** [@nealder](https://discuss.elastic.co/u/nealder)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 10:14am UTC](https://discuss.elastic.co/t/discovery-service-as-endpoint-provider-not-recognised/340512 "2023-08-10T10:14:52Z")

</div>

Hi Everyone, I have submitted a bug ticket on github, but I got redirected here. Here is the ticket. In short I found that the 'discovery.zen.ping.unicast.host' could resolve IP addresses of nodes in my cluster via dis…

---

## [The commercial usage of ELK stack in Russia today](https://discuss.elastic.co/t/the-commercial-usage-of-elk-stack-in-russia-today/340545)

<div class="topic-metadata">

**Author:** [@Abbey\_Monk](https://discuss.elastic.co/u/Abbey_Monk)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 10:12am UTC](https://discuss.elastic.co/t/the-commercial-usage-of-elk-stack-in-russia-today/340545 "2023-08-10T10:12:39Z")

</div>

Hi, guys! Could we use ELK for free in Russia for the commercial purposes today? Thank you for your assistance.

---

## [I use elk in docker , i open xpack secuirty ,but when i restart by docker ,there some error log](https://discuss.elastic.co/t/i-use-elk-in-docker-i-open-xpack-secuirty-but-when-i-restart-by-docker-there-some-error-log/340544)

<div class="topic-metadata">

**Author:** [@yichitgo](https://discuss.elastic.co/u/yichitgo)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 10:11am UTC](https://discuss.elastic.co/t/i-use-elk-in-docker-i-open-xpack-secuirty-but-when-i-restart-by-docker-there-some-error-log/340544 "2023-08-10T10:11:45Z")

</div>

aiting for Elasticsearch cluster to respond (1/30) logstash started. Starting Kibana5 \[ OK \] touch: cannot touch '/var/log/elasticsearch/{"error":{"root\_cause":\[{"…

---

## [The issue of data corruption in Logstash's Netflow plugin under high data concurrency](https://discuss.elastic.co/t/the-issue-of-data-corruption-in-logstashs-netflow-plugin-under-high-data-concurrency/340541)

<div class="topic-metadata">

**Author:** [@chenlx594](https://discuss.elastic.co/u/chenlx594)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 10:02am UTC](https://discuss.elastic.co/t/the-issue-of-data-corruption-in-logstashs-netflow-plugin-under-high-data-concurrency/340541 "2023-08-10T10:02:38Z")

</div>

The Logstash Netflow plugin encounters a problem of misinterpreted fields like first\_switched , last\_switched , and bytes under a netflow data copy rate of 0.4 Gbps. How can this issue be resolved?

---

## [Getting 403 denied to elastic.co](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co/339534)

<div class="topic-metadata">

**Author:** [@AlexandrK](https://discuss.elastic.co/u/AlexandrK)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 9:58am UTC](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co/339534 "2023-08-10T09:58:32Z")

</div>

Hello! My company's IP address was blocked by mistake. I wrote in a topic that deals with this problem, but the last unlock activity there was on May 1st. I don't know where to write to get my address unblocked Please …

---

## [Auditbeat authentications log](https://discuss.elastic.co/t/auditbeat-authentications-log/340535)

<div class="topic-metadata">

**Author:** [@lliadan](https://discuss.elastic.co/u/lliadan)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 9:40am UTC](https://discuss.elastic.co/t/auditbeat-authentications-log/340535 "2023-08-10T09:40:34Z")

</div>

Hello ! I'm trying to receive the authentication faillure and success from my devices but i'm having few complications.. From my windows devices, it's ok, i'm able to receive log out / in / failled , with winlogbeat b…

---

## [I get this error in Logstash coming even when the pipeline is working just fine. What could it be?](https://discuss.elastic.co/t/i-get-this-error-in-logstash-coming-even-when-the-pipeline-is-working-just-fine-what-could-it-be/340531)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 9:16am UTC](https://discuss.elastic.co/t/i-get-this-error-in-logstash-coming-even-when-the-pipeline-is-working-just-fine-what-could-it-be/340531 "2023-08-10T09:16:47Z")

</div>

\[2023-08-10T06:10:02,974\]\[ERROR\]\[logstash.licensechecker.licensereader\] Unable to retrieve license information from license server {:message=\>"No Available connections"} \[2023-08-10T06:10:06,662\]\[INFO \]\[logstash.license…

---

## [Elasticsearch Composite Aggregation Orderby in Java Client 8.8.2](https://discuss.elastic.co/t/elasticsearch-composite-aggregation-orderby-in-java-client-8-8-2/340514)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 5\
**Last updated:** [August 10, 2023, 9:11am UTC](https://discuss.elastic.co/t/elasticsearch-composite-aggregation-orderby-in-java-client-8-8-2/340514 "2023-08-10T09:11:23Z")

</div>

I'm getting a parse exception when I add order to CompositeAggregationSource. Map\<String, CompositeAggregationSource\> cas = new HashMap\<\>(); List\<NamedValue\<SortOrder\>\> orderby = new ArrayList\<\>(); orderby.add(NamedVal…

---

## [Isolate a node](https://discuss.elastic.co/t/isolate-a-node/340528)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 9:01am UTC](https://discuss.elastic.co/t/isolate-a-node/340528 "2023-08-10T09:01:53Z")

</div>

How can we isolate a node that serves both as a master and data node from a cluster?

---

## [Source missing in filebeat logs](https://discuss.elastic.co/t/source-missing-in-filebeat-logs/340291)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 5\
**Last updated:** [August 10, 2023, 8:51am UTC](https://discuss.elastic.co/t/source-missing-in-filebeat-logs/340291 "2023-08-10T08:51:34Z")

</div>

Hi Team , I have set up the filebeat to send the custom logs to Elasticsearch cluster, But there is "Source" missing on logs when I see them in Filebeat. I am using filebeat-8.7.0-1.x86\_64 for sending the logs. is …

---

## [Chaining queries with rally](https://discuss.elastic.co/t/chaining-queries-with-rally/340525)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 8:22am UTC](https://discuss.elastic.co/t/chaining-queries-with-rally/340525 "2023-08-10T08:22:08Z")

</div>

Hi , What's the best practice to benchmark an application side joins scenario? Meaning running an initial query with "collapse" to group by some id, take all the ids from the response and run a second "terms" query? W…

---

## [Multiterms on multi index](https://discuss.elastic.co/t/multiterms-on-multi-index/340519)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 7:47am UTC](https://discuss.elastic.co/t/multiterms-on-multi-index/340519 "2023-08-10T07:47:46Z")

</div>

Currently I am testing on ES Multi Terms feature. Please find the sample data with indices. PUT multi\_terms\_test1 { "settings": { "number\_of\_shards": 1, "number\_of\_replicas": 0 } } PUT multi\_terms\_test1/\_ma…

---

## [Elasticsearch: 'x\_content\_parse\_exception' \[template\] unknown field \[lifecycle\]](https://discuss.elastic.co/t/elasticsearch-x-content-parse-exception-template-unknown-field-lifecycle/340009)

<div class="topic-metadata">

**Author:** [@anton3](https://discuss.elastic.co/u/anton3)\
**Replies:** 6\
**Last updated:** [August 10, 2023, 7:45am UTC](https://discuss.elastic.co/t/elasticsearch-x-content-parse-exception-template-unknown-field-lifecycle/340009 "2023-08-10T07:45:15Z")

</div>

I have elk stack deployed from deviantony/docker-elk version 8.9 . every component is 8.9 And i'm trying to create lifecycle with retention policy for my datastream as mentioned in official documentetion PUT \_index\_te…

---

## [Overriding timestamp in logstash](https://discuss.elastic.co/t/overriding-timestamp-in-logstash/340515)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 7:26am UTC](https://discuss.elastic.co/t/overriding-timestamp-in-logstash/340515 "2023-08-10T07:26:03Z")

</div>

Hi on logstash need to override timestamp, here is the scenario input file, output as http. here is the string must be send via “http output”: mymeasure,tag=mytag field="myfield" 1689682934 FYI: this part "1689682934…

---

## [Elasticsearch not getting data from filter after index migration](https://discuss.elastic.co/t/elasticsearch-not-getting-data-from-filter-after-index-migration/340467)

<div class="topic-metadata">

**Author:** [@cosskay](https://discuss.elastic.co/u/cosskay)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 6:17am UTC](https://discuss.elastic.co/t/elasticsearch-not-getting-data-from-filter-after-index-migration/340467 "2023-08-10T06:17:23Z")

</div>

after moving an index from one cluster to another, the index does not search for data by filter. The number of Lucene docs is the same in both indexes. All indices Health (green) . Index cloned from VM in openshift . Ela…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=453)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=455)
