# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=457

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 458

---

## [ESXI to ELK](https://discuss.elastic.co/t/esxi-to-elk/340366)

<div class="topic-metadata">

**Author:** [@lliadan](https://discuss.elastic.co/u/lliadan)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:06pm UTC](https://discuss.elastic.co/t/esxi-to-elk/340366 "2023-08-08T12:06:04Z")

</div>

Hi ! I'm setting up an ELK server in my company to receive connection logs. My server is ready and operational. I still have one machine to do, but I confess I'm stuck. I need to get the logs from the ESXI server, and…

---

## [Change field name instead of requirement field](https://discuss.elastic.co/t/change-field-name-instead-of-requirement-field/340353)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 10:16am UTC](https://discuss.elastic.co/t/change-field-name-instead-of-requirement-field/340353 "2023-08-08T10:16:23Z")

</div>

i want to change the field name agent.ephemeral\_id instead of ELK\_Id.

---

## [See duplicate transaction with same date and time](https://discuss.elastic.co/t/see-duplicate-transaction-with-same-date-and-time/340340)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 10:04am UTC](https://discuss.elastic.co/t/see-duplicate-transaction-with-same-date-and-time/340340 "2023-08-08T10:04:24Z")

</div>

See duplicate transaction with same date and time .

---

## [How the upsert script will work in elastci search](https://discuss.elastic.co/t/how-the-upsert-script-will-work-in-elastci-search/340352)

<div class="topic-metadata">

**Author:** [@Sukhdeob\_95](https://discuss.elastic.co/u/Sukhdeob_95)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-the-upsert-script-will-work-in-elastci-search/340352 "2023-08-08T09:57:57Z")

</div>

Here is my logstash config file . In the output plugin I have added upsert script it compare the ingestionHash value with old documentation ingestionHash value. If the document\_id doesn't exist (new document ie 1st ti…

---

## [Visualization not working in Canvas, once some other timestamp field is selected in time filter column](https://discuss.elastic.co/t/visualization-not-working-in-canvas-once-some-other-timestamp-field-is-selected-in-time-filter-column/340351)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:55am UTC](https://discuss.elastic.co/t/visualization-not-working-in-canvas-once-some-other-timestamp-field-is-selected-in-time-filter-column/340351 "2023-08-08T09:55:16Z")

</div>

Hi Team, we have index where sorting is done based on modified\_date instead of @timestamp. we have selected the same in time filter as well. now when we are trying to create a visualization in Canvas, its throwing e…

---

## [Perform CRUD Operation on Elasticsearch With REST API](https://discuss.elastic.co/t/perform-crud-operation-on-elasticsearch-with-rest-api/340329)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 5\
**Last updated:** [August 8, 2023, 9:48am UTC](https://discuss.elastic.co/t/perform-crud-operation-on-elasticsearch-with-rest-api/340329 "2023-08-08T09:48:37Z")

</div>

Hi Team, Could anyone share how to perform CRUD operation in Elastic search with REST API. I had tried the below one with the curl command but getting error as "curl: (52) Empty reply from server" . Could you please gui…

---

## [Possible Feature Request: Redis Authentication with Username/Password](https://discuss.elastic.co/t/possible-feature-request-redis-authentication-with-username-password/340349)

<div class="topic-metadata">

**Author:** [@alces](https://discuss.elastic.co/u/alces)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:25am UTC](https://discuss.elastic.co/t/possible-feature-request-redis-authentication-with-username-password/340349 "2023-08-08T09:25:01Z")

</div>

Hi everyone. We are planing to use redis between beats and logstash as a buffer for high utilization timespots. In this setup currently there is only a "password" option for the redis output/input plugin, so every part…

---

## [// "reason": "Arrays (returned by \[ss\]) are not supported"](https://discuss.elastic.co/t/reason-arrays-returned-by-ss-are-not-supported/340136)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 9:21am UTC](https://discuss.elastic.co/t/reason-arrays-returned-by-ss-are-not-supported/340136 "2023-08-08T09:21:00Z")

</div>

Elasticsearch updated version to 8.9, using SQL function, found abnormal collection data reports. Has anyone encountered them?

---

## [ECK fleet-server-agent errors after adding "policyID: eck-fleet-server"](https://discuss.elastic.co/t/eck-fleet-server-agent-errors-after-adding-policyid-eck-fleet-server/340347)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:18am UTC](https://discuss.elastic.co/t/eck-fleet-server-agent-errors-after-adding-policyid-eck-fleet-server/340347 "2023-08-08T09:18:04Z")

</div>

Hit the following errors after adding the suggested configuration according to https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-quickstart.html: {"log.level":"error","@timestamp":"2023-08-08T…

---

## [Purge index](https://discuss.elastic.co/t/purge-index/340265)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 13\
**Last updated:** [August 8, 2023, 9:14am UTC](https://discuss.elastic.co/t/purge-index/340265 "2023-08-08T09:14:40Z")

</div>

hello, I would like to purge my data from my indexes in elasticsearch. I'd like to know how to do this without having to delete my index. How can I achieve that?

---

## [Send custom logs to elasticsearch with predefined list of fields](https://discuss.elastic.co/t/send-custom-logs-to-elasticsearch-with-predefined-list-of-fields/338681)

<div class="topic-metadata">

**Author:** [@Johannnnnn](https://discuss.elastic.co/u/Johannnnnn)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 8:43am UTC](https://discuss.elastic.co/t/send-custom-logs-to-elasticsearch-with-predefined-list-of-fields/338681 "2023-08-08T08:43:40Z")

</div>

Disclaimer: I am very confused about filebeat help files. If I need anything more technical than sending a log line to elasticsearch, it does not explain anything. It just states options and leaves me to find out which o…

---

## [Elasticsearch upgrade from 7.17 to 8.x](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-17-to-8-x/340338)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 8:16am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-17-to-8-x/340338 "2023-08-08T08:16:39Z")

</div>

Hi all, We are planning to upgrade our elasticsearch cluster from 7.17.x to 8.X. Apart from general upgrade recommendations from elastic, is there a specific 8.X version that we should be upgrading to?

---

## [Error on lifecycle policy alias](https://discuss.elastic.co/t/error-on-lifecycle-policy-alias/340337)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 8:09am UTC](https://discuss.elastic.co/t/error-on-lifecycle-policy-alias/340337 "2023-08-08T08:09:00Z")

</div>

I wasn't aware of the alias requirement on lifecycle management, so now I have a ton of data imported, on indexes with this pattern based on an index template: dmarc-7.17.4-2023.08 Where the version, year and month var…

---

## [Visualisation based on multiple fields](https://discuss.elastic.co/t/visualisation-based-on-multiple-fields/340333)

<div class="topic-metadata">

**Author:** [@Zuhaib\_Ul\_Zaman](https://discuss.elastic.co/u/Zuhaib_Ul_Zaman)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 7:32am UTC](https://discuss.elastic.co/t/visualisation-based-on-multiple-fields/340333 "2023-08-08T07:32:38Z")

</div>

{ "Name1":{ "total" : 500, "subname1":{ "total":250, "cpu" : 100 }, "subname2" : { "total" : 250, "cpu" : 10000 } }, "Name2":{ "total":25, "subname1" : { "total" : 25, "cpu" : 10 }, …

---

## [Group by id base of sum of range of value](https://discuss.elastic.co/t/group-by-id-base-of-sum-of-range-of-value/340322)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 4\
**Last updated:** [August 8, 2023, 8:05am UTC](https://discuss.elastic.co/t/group-by-id-base-of-sum-of-range-of-value/340322 "2023-08-08T08:05:45Z")

</div>

I had some data as below: \[ { "PAY\_DATE": "2019-10-24", "STATE": "Utah", "id": "1", "SALARY": 6045, "UUID": "a879492b-b402-40bd-8f5d-afc34d66d152" }, { "PAY\_DATE": "2021-01-17", "STATE"…

---

## [Filebeat in docker, permission denied when trying to place registry on the host](https://discuss.elastic.co/t/filebeat-in-docker-permission-denied-when-trying-to-place-registry-on-the-host/339694)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 7:59am UTC](https://discuss.elastic.co/t/filebeat-in-docker-permission-denied-when-trying-to-place-registry-on-the-host/339694 "2023-08-08T07:59:55Z")

</div>

I would like to move the registry outside the filebeat folder, to be able to easy kill it. I have this config file: filebeat\_for\_dmarc: image: docker.elastic.co/beats/filebeat:${STACK\_VERSION} container\_name:…

---

## [Unable to create Synthetics projects using the API key](https://discuss.elastic.co/t/unable-to-create-synthetics-projects-using-the-api-key/340335)

<div class="topic-metadata">

**Author:** [@opensourcengineer](https://discuss.elastic.co/u/opensourcengineer)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 7:37am UTC](https://discuss.elastic.co/t/unable-to-create-synthetics-projects-using-the-api-key/340335 "2023-08-08T07:37:00Z")

</div>

I am trying to create project in the monitors using the API key and getting the below error: TypeError: unusable command i used is: npx @elastic/synthetics init projects-itops version 8.4 containerisation deployment

---

## [\[.kibana\_task\_manager\] Action failed with 'Request timed out'](https://discuss.elastic.co/t/kibana-task-manager-action-failed-with-request-timed-out/340325)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:26am UTC](https://discuss.elastic.co/t/kibana-task-manager-action-failed-with-request-timed-out/340325 "2023-08-08T07:26:44Z")

</div>

Hello, I upgraded an Elasticsearch cluster from 7.10 to 7.17.9. ES upgrade is fine, with all the nodes up. However, when upgrading Kibana, I got the error when it attempts to re-index. {"type":"log","@timestamp":"2023-…

---

## [\[version 8.9\] Kibana server is not ready yet](https://discuss.elastic.co/t/version-8-9-kibana-server-is-not-ready-yet/340316)

<div class="topic-metadata">

**Author:** [@SageJustus](https://discuss.elastic.co/u/SageJustus)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 7:21am UTC](https://discuss.elastic.co/t/version-8-9-kibana-server-is-not-ready-yet/340316 "2023-08-08T07:21:31Z")

</div>

Kibana version: 8.9 Elasticsearch version: 8.9 Server OS version: Windows10 Describe the bug: Unable to start kibana. Steps to reproduce: start Elasticsearch, browser access http://localhost:9200/, get the followi…

---

## [Vega lite interactive visual](https://discuss.elastic.co/t/vega-lite-interactive-visual/339669)

<div class="topic-metadata">

**Author:** [@Akarsh\_Shaw](https://discuss.elastic.co/u/Akarsh_Shaw)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:18am UTC](https://discuss.elastic.co/t/vega-lite-interactive-visual/339669 "2023-08-08T07:18:37Z")

</div>

I created a heatmap which is showing the failed transaction in hour bucket, and pie chart showing the error-code contributions. When I select any hour bucket in heatmap then it showing the correct error contribution in p…

---

## [Semantic search and text expansion query with self-deployed model](https://discuss.elastic.co/t/semantic-search-and-text-expansion-query-with-self-deployed-model/339708)

<div class="topic-metadata">

**Author:** [@camoneme](https://discuss.elastic.co/u/camoneme)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:17am UTC](https://discuss.elastic.co/t/semantic-search-and-text-expansion-query-with-self-deployed-model/339708 "2023-08-08T07:17:42Z")

</div>

I'm trying to use the text expansion query to implement semantic search on a rank features field. I've read the ELSER documentation and understand the process. I'm using a local/downloaded elasticsearch on docker (not co…

---

## [Regarding traffic volume in fortinat firewall logs](https://discuss.elastic.co/t/regarding-traffic-volume-in-fortinat-firewall-logs/340327)

<div class="topic-metadata">

**Author:** [@TECHY\_GEEK](https://discuss.elastic.co/u/TECHY_GEEK)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 6:48am UTC](https://discuss.elastic.co/t/regarding-traffic-volume-in-fortinat-firewall-logs/340327 "2023-08-08T06:48:28Z")

</div>

Hi! there, We are monitoring our Fortinet firewalls using Elasticsearch, Filebeat, and Kibana. But the traffic volume shown by the firewall's in-built dashboard is different from the traffic volume aggregated by Elastic…

---

## [Migration from ES V6.8 to V7.17 with an additional node](https://discuss.elastic.co/t/migration-from-es-v6-8-to-v7-17-with-an-additional-node/340252)

<div class="topic-metadata">

**Author:** [@Franco901](https://discuss.elastic.co/u/Franco901)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 6:47am UTC](https://discuss.elastic.co/t/migration-from-es-v6-8-to-v7-17-with-an-additional-node/340252 "2023-08-08T06:47:43Z")

</div>

Hi there, I have a V6.8 instance with a ~350 GB index and plan to migrate to ES V7.17. I read that ES can migrate between major versions, so my idea was to setup a new V7.17 node and let him join to the existing V6.8 n…

---

## [Node Up and Down Alert](https://discuss.elastic.co/t/node-up-and-down-alert/340176)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 4:41am UTC](https://discuss.elastic.co/t/node-up-and-down-alert/340176 "2023-08-08T04:41:35Z")

</div>

I am using Elastic Cloud v8.8 and i want to create an alert for node up and down status using kibana alert. Please see the below screenshots. Screenshot-1 Screenshot-2 Screenshot-3 Screenshot-4 I am get…

---

## [Unique count function](https://discuss.elastic.co/t/unique-count-function/340320)

<div class="topic-metadata">

**Author:** [@MeghanaReddy](https://discuss.elastic.co/u/MeghanaReddy)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 4:26am UTC](https://discuss.elastic.co/t/unique-count-function/340320 "2023-08-08T04:26:02Z")

</div>

I have created a table visualisation so on x-axis I have entity data and on y-axis I am having unique count of traceids function but I am getting unique count of traceids for each entity value is more than the count of …

---

## [Is there any performance comparison between the default index codec and best\_compression?](https://discuss.elastic.co/t/is-there-any-performance-comparison-between-the-default-index-codec-and-best-compression/340312)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 3:17am UTC](https://discuss.elastic.co/t/is-there-any-performance-comparison-between-the-default-index-codec-and-best-compression/340312 "2023-08-08T03:17:18Z")

</div>

Hello, I'm looking into ways to optimize the disk usage of my indices on my cluster and before go on the route to remove the \_source field I've decided to try and change the index codec to best\_compression. The documen…

---

## [Combined grok pattern for customized logs](https://discuss.elastic.co/t/combined-grok-pattern-for-customized-logs/338535)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 20\
**Last updated:** [August 8, 2023, 3:09am UTC](https://discuss.elastic.co/t/combined-grok-pattern-for-customized-logs/338535 "2023-08-08T03:09:23Z")

</div>

i am looking some help and guidenace for parsing the customized logs in one file. i have httpd access logs which have two format and i need to prepare the logstash config/filtering the data. so i tried two different pat…

---

## [What's the difference between consumption-based and resource-based pricing?](https://discuss.elastic.co/t/whats-the-difference-between-consumption-based-and-resource-based-pricing/340308)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 2:44am UTC](https://discuss.elastic.co/t/whats-the-difference-between-consumption-based-and-resource-based-pricing/340308 "2023-08-08T02:44:12Z")

</div>

I see two billing models on this page and wondering: does the resource-based model mean I have to pay for ECU of kibana node even if I'm not doing analytics? does the consumption-based model mean I wouldn't need to pay…

---

## [Painless, watcher, alerts](https://discuss.elastic.co/t/painless-watcher-alerts/340305)

<div class="topic-metadata">

**Author:** [@sunny2502](https://discuss.elastic.co/u/sunny2502)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:00am UTC](https://discuss.elastic.co/t/painless-watcher-alerts/340305 "2023-08-08T00:00:46Z")

</div>

Hi I need to maintain key value pair for my output of transform block and send that to action block to send email to particular value its key. my sample code is below, my issue is in action block my payload is not getti…

---

## [Lucene Regex issues](https://discuss.elastic.co/t/lucene-regex-issues/339869)

<div class="topic-metadata">

**Author:** [@turboz](https://discuss.elastic.co/u/turboz)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 10:21pm UTC](https://discuss.elastic.co/t/lucene-regex-issues/339869 "2023-08-07T22:21:06Z")

</div>

I'm trying to use some regex and its becoming frustrating. It appears the syntax is not respected around the Kibana interface. For example, I can exclude via regex with visualizations. However I noticed if you choose to…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=456)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=458)
