# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=459

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 460

---

## [Noop Query](https://discuss.elastic.co/t/noop-query/340208)

<div class="topic-metadata">

**Author:** [@yonzmeer](https://discuss.elastic.co/u/yonzmeer)\
**Replies:** 0\
**Last updated:** [August 6, 2023, 8:03pm UTC](https://discuss.elastic.co/t/noop-query/340208 "2023-08-06T20:03:11Z")

</div>

Hello, I'm building a some-what generic converter from an object that contains lists of values, to a search requests for elasticsearch, for example: { names: \["john", "bob"\], cities: \["boston", "moscow"\] } tur…

---

## [Did anything change concerning dashboards from version 6.3 to version 7.5?](https://discuss.elastic.co/t/did-anything-change-concerning-dashboards-from-version-6-3-to-version-7-5/338584)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 13\
**Last updated:** [August 6, 2023, 6:54pm UTC](https://discuss.elastic.co/t/did-anything-change-concerning-dashboards-from-version-6-3-to-version-7-5/338584 "2023-08-06T18:54:04Z")

</div>

Hello, Did anything change concerning dashboards from version 6.3 to version 7.5 ? I have a working dashboard in one environment with version 6.3, and the exactly same dashboard doesn't work from version 7.5. The dash…

---

## [Failure to elect master, v7.17](https://discuss.elastic.co/t/failure-to-elect-master-v7-17/340149)

<div class="topic-metadata">

**Author:** [@bobus](https://discuss.elastic.co/u/bobus)\
**Replies:** 19\
**Last updated:** [August 6, 2023, 3:28pm UTC](https://discuss.elastic.co/t/failure-to-elect-master-v7-17/340149 "2023-08-06T15:28:58Z")

</div>

I'm pulling my hair out trying to figure out why my three nodes, running as docker-compose containers on 3 separate Ubuntu 22.04LTS hosts, cannot start. The 3 nodes discover each other but fail to elect a master. When I…

---

## [Security\_exception: unable to authenticate user \[kibana\_system\] for REST request \[/\_nodes?filter\_path=nodes..version%2Cnodes..http.publish\_address%2Cnodes..ip\]](https://discuss.elastic.co/t/security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-nodes-filter-path-nodes-version-2cnodes-http-publish-address-2cnodes-ip/340187)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 7\
**Last updated:** [August 6, 2023, 3:11pm UTC](https://discuss.elastic.co/t/security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-nodes-filter-path-nodes-version-2cnodes-http-publish-address-2cnodes-ip/340187 "2023-08-06T15:11:02Z")

</div>

hello friends, I am getting this error when launching kibana in the browser... below is the cause of the error returned by kibana statuses. Please can you help overcome this situation md/system/kibana.service; enabled…

---

## [How to display a grpah based on commpm value order by timespamp](https://discuss.elastic.co/t/how-to-display-a-grpah-based-on-commpm-value-order-by-timespamp/339264)

<div class="topic-metadata">

**Author:** [@David\_Munsa](https://discuss.elastic.co/u/David_Munsa)\
**Replies:** 2\
**Last updated:** [August 6, 2023, 8:02am UTC](https://discuss.elastic.co/t/how-to-display-a-grpah-based-on-commpm-value-order-by-timespamp/339264 "2023-08-06T08:02:11Z")

</div>

it goes like this : so all my documents have a property called sessionId and has a parent-child connection the purpose: user is searching by sessionId show a graph of all document that shares this Id connect the nod…

---

## [Elasticsearch on a single node docker container after mounting azure storage gives .es\_temp\_file file not found error](https://discuss.elastic.co/t/elasticsearch-on-a-single-node-docker-container-after-mounting-azure-storage-gives-es-temp-file-file-not-found-error/340174)

<div class="topic-metadata">

**Author:** [@sphnix](https://discuss.elastic.co/u/sphnix)\
**Replies:** 1\
**Last updated:** [August 5, 2023, 8:07pm UTC](https://discuss.elastic.co/t/elasticsearch-on-a-single-node-docker-container-after-mounting-azure-storage-gives-es-temp-file-file-not-found-error/340174 "2023-08-05T20:07:44Z")

</div>

Hi. I am running elasticsearch as single node. While starting the container it gives .es\_temp\_file not found error. Tried mounting blobfuse2 but didnot help. {"type": "server", "timestamp": "2023-08-05T08:53:25,540Z", …

---

## [Not able to install elastiKNN plugin in elastic search](https://discuss.elastic.co/t/not-able-to-install-elastiknn-plugin-in-elastic-search/339049)

<div class="topic-metadata">

**Author:** [@Shreeyash\_Pandey](https://discuss.elastic.co/u/Shreeyash_Pandey)\
**Replies:** 2\
**Last updated:** [August 5, 2023, 7:09pm UTC](https://discuss.elastic.co/t/not-able-to-install-elastiknn-plugin-in-elastic-search/339049 "2023-08-05T19:09:37Z")

</div>

I am getting this error during installation of my elsaticKNN plugin. Please let me know the compatible version for my elasticsearch(7.12.0) -\> Installing Release 7.12.0.5 · alexklibisz/elastiknn · GitHub -\> Downloading…

---

## [Vega pie properties error converting github example to Kibana vega using a query with agg](https://discuss.elastic.co/t/vega-pie-properties-error-converting-github-example-to-kibana-vega-using-a-query-with-agg/340181)

<div class="topic-metadata">

**Author:** [@carnealse](https://discuss.elastic.co/u/carnealse)\
**Replies:** 0\
**Last updated:** [August 5, 2023, 5:17pm UTC](https://discuss.elastic.co/t/vega-pie-properties-error-converting-github-example-to-kibana-vega-using-a-query-with-agg/340181 "2023-08-05T17:17:47Z")

</div>

I am getting this error Invalid specification {...} Make sure the specification includes at least one of the following properties: "mark", "layer", "facet", "hconcat", "vconcat", "concat", or "repeat" I was using the p…

---

## [Stored fields getting deleted upon partial update of the document in elastic search](https://discuss.elastic.co/t/stored-fields-getting-deleted-upon-partial-update-of-the-document-in-elastic-search/340011)

<div class="topic-metadata">

**Author:** [@Jagadeesh12](https://discuss.elastic.co/u/Jagadeesh12)\
**Replies:** 4\
**Last updated:** [August 5, 2023, 1:12pm UTC](https://discuss.elastic.co/t/stored-fields-getting-deleted-upon-partial-update-of-the-document-in-elastic-search/340011 "2023-08-05T13:12:32Z")

</div>

Hi. I have an index which have stored fields in the documents. But, upon updating the document with new fields (partially update), the previously existing stored fields are getting deleted. Create the Index PUT itf\_t…

---

## [Issue with metricbeat kibana module when using custom path for Kibana](https://discuss.elastic.co/t/issue-with-metricbeat-kibana-module-when-using-custom-path-for-kibana/338976)

<div class="topic-metadata">

**Author:** [@Pierig\_Le\_Saux](https://discuss.elastic.co/u/Pierig_Le_Saux)\
**Replies:** 4\
**Last updated:** [August 5, 2023, 1:30am UTC](https://discuss.elastic.co/t/issue-with-metricbeat-kibana-module-when-using-custom-path-for-kibana/338976 "2023-08-05T01:30:47Z")

</div>

My kibana setup uses SERVER\_PUBLICBASEURL = http://www.example.com/kibana SERVER\_BASEPATH = /kibana SERVER\_REWRITEBASEPATH = "true" My metricbeat autodiscovery for the kibana module uses: - condition: contains: …

---

## [How to apply filter(s) to all the embedded iframe visuals](https://discuss.elastic.co/t/how-to-apply-filter-s-to-all-the-embedded-iframe-visuals/340071)

<div class="topic-metadata">

**Author:** [@Amphagory](https://discuss.elastic.co/u/Amphagory)\
**Replies:** 8\
**Last updated:** [August 5, 2023, 1:11am UTC](https://discuss.elastic.co/t/how-to-apply-filter-s-to-all-the-embedded-iframe-visuals/340071 "2023-08-05T01:11:26Z")

</div>

I would like to embed visuals into a webpage. I guess I can use a dashboard to have a filter applied to all the visuals, but I was wondering if I only had a bunch of visuals on a webpage, is it possible to have a filter…

---

## [Elasticsearch search based on term position and fuzzy](https://discuss.elastic.co/t/elasticsearch-search-based-on-term-position-and-fuzzy/340163)

<div class="topic-metadata">

**Author:** [@JohnsM](https://discuss.elastic.co/u/JohnsM)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 10:39pm UTC](https://discuss.elastic.co/t/elasticsearch-search-based-on-term-position-and-fuzzy/340163 "2023-08-04T22:39:30Z")

</div>

I am a beginner in Elasticsearch and I try to combine a query with term position and fuzzy and the results are not what I expected. I tried this query { "query": { "bool": { "must": \[ …

---

## [How to use event.set to get the values of a variable?](https://discuss.elastic.co/t/how-to-use-event-set-to-get-the-values-of-a-variable/340155)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 10:34pm UTC](https://discuss.elastic.co/t/how-to-use-event-set-to-get-the-values-of-a-variable/340155 "2023-08-04T22:34:59Z")

</div>

I'm using Kafka's input plugin within my logstash pipline and I have enabled decorated\_events =\> true If I want to get the kafka topic and partition names I can do this: mutate { add\_field =\> { "\[topic\_na…

---

## [Monitor users (requests, CPU usage, etc.)](https://discuss.elastic.co/t/monitor-users-requests-cpu-usage-etc/340018)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 7:23pm UTC](https://discuss.elastic.co/t/monitor-users-requests-cpu-usage-etc/340018 "2023-08-04T19:23:28Z")

</div>

Hello, I'd like to be able to find out what my users are doing, and more specifically list the users who are consuming CPU, consult the list of "big" requests and the linked user. Basically, I'd like to know if someone…

---

## [Data is redundant in filebeat system module](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096)

<div class="topic-metadata">

**Author:** [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 5:18pm UTC](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096 "2023-08-04T17:18:07Z")

</div>

Hi, i indexed linux secure log via filebeat system module. And the user.name field is duplicated. Most user.name has two versions. The version that start with a blank and the other version that doesn't. There a…

---

## [I want create a kibana table, combining the 2 latest documents grouped by a common field](https://discuss.elastic.co/t/i-want-create-a-kibana-table-combining-the-2-latest-documents-grouped-by-a-common-field/339937)

<div class="topic-metadata">

**Author:** [@MJohansen](https://discuss.elastic.co/u/MJohansen)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 5:05pm UTC](https://discuss.elastic.co/t/i-want-create-a-kibana-table-combining-the-2-latest-documents-grouped-by-a-common-field/339937 "2023-08-04T17:05:00Z")

</div>

Hey guys, I'm fairly new working with Kibana and the ELK stack. I currently have logs being sent roughly every 12 hours, containing packages and their versions. My goal, is to create a table that groups the data by the…

---

## [Wildcard query took 200 seconds with version 8.8 but only a few seconds with 6.3](https://discuss.elastic.co/t/wildcard-query-took-200-seconds-with-version-8-8-but-only-a-few-seconds-with-6-3/340152)

<div class="topic-metadata">

**Author:** [@xluan](https://discuss.elastic.co/u/xluan)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 4:53pm UTC](https://discuss.elastic.co/t/wildcard-query-took-200-seconds-with-version-8-8-but-only-a-few-seconds-with-6-3/340152 "2023-08-04T16:53:49Z")

</div>

We are migrating Elastic from 6.3 to 8,8. But the wildcard queries (in query string) are excessively slow in 8,8 as compared with 6.3. For example, for query "abcddcba\*" that does not actually match anything, it takes 4 …

---

## [How we can remove deduplication event in logstash](https://discuss.elastic.co/t/how-we-can-remove-deduplication-event-in-logstash/340060)

<div class="topic-metadata">

**Author:** [@Sukhdeob\_95](https://discuss.elastic.co/u/Sukhdeob_95)\
**Replies:** 6\
**Last updated:** [August 4, 2023, 4:53pm UTC](https://discuss.elastic.co/t/how-we-can-remove-deduplication-event-in-logstash/340060 "2023-08-04T16:53:48Z")

</div>

I want to remove the duplicate event based on particular field of my input i wrote logic like following but i got an error aggregate { task\_id =\> "%{\[meta\]\[ingestionHash\]}" code =\> " map\['@metadata'\]\['keep'\] ||= ev…

---

## [Making charts for data like machine learning](https://discuss.elastic.co/t/making-charts-for-data-like-machine-learning/339971)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 2\
**Last updated:** [August 4, 2023, 4:21pm UTC](https://discuss.elastic.co/t/making-charts-for-data-like-machine-learning/339971 "2023-08-04T16:21:16Z")

</div>

Hi I would like to know how can I achieve very likely graph as You have in machine learning module. I have already uploaded data from side car cluster (tensorflow, spark etc) but I need to plot a graph with envelopes an…

---

## [Do we have any possibility to integrate Third-party map (Google Map) with ELK](https://discuss.elastic.co/t/do-we-have-any-possibility-to-integrate-third-party-map-google-map-with-elk/339042)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 4:17pm UTC](https://discuss.elastic.co/t/do-we-have-any-possibility-to-integrate-third-party-map-google-map-with-elk/339042 "2023-08-04T16:17:46Z")

</div>

Hi Team, Can we integrate any third-party map(Google Map) as a plug-in into ELK stack to view the Steet level findings in the Map. Thanks in Advance.

---

## [Session storage for embedded iframes with kibana dashboards and anonymous user](https://discuss.elastic.co/t/session-storage-for-embedded-iframes-with-kibana-dashboards-and-anonymous-user/339960)

<div class="topic-metadata">

**Author:** [@Jordan\_Rutland](https://discuss.elastic.co/u/Jordan_Rutland)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 3:44pm UTC](https://discuss.elastic.co/t/session-storage-for-embedded-iframes-with-kibana-dashboards-and-anonymous-user/339960 "2023-08-04T15:44:42Z")

</div>

Quick questions. My team is using iframes to host embeded dashboards and we want to use anonymous users to avoid having users have to provide their own credentials. The how to for that piece is clear. We however are worr…

---

## [Is there a way to have an aggregation bucket that delivery the sum of other values](https://discuss.elastic.co/t/is-there-a-way-to-have-an-aggregation-bucket-that-delivery-the-sum-of-other-values/340148)

<div class="topic-metadata">

**Author:** [@Fabio\_Batalha](https://discuss.elastic.co/u/Fabio_Batalha)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 3:35pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-have-an-aggregation-bucket-that-delivery-the-sum-of-other-values/340148 "2023-08-04T15:35:26Z")

</div>

I'm doing an aggregation, limiting the buckets size to 6, and I would have a bucket having the sum of the other values. I see Kibana deal with that in a hidden way. At Kibana we can configure an aggregation to delivery …

---

## [Becoming ECS Compliant](https://discuss.elastic.co/t/becoming-ecs-compliant/340080)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 6\
**Last updated:** [August 4, 2023, 3:33pm UTC](https://discuss.elastic.co/t/becoming-ecs-compliant/340080 "2023-08-04T15:33:31Z")

</div>

I've been ingesting datasets from before ECS was a thing that now have an ECS mapping. What would be the most efficient means of ingesting data (moving forward) so that it is ECS compliant? Examples of datasets are For…

---

## [Need to email syslog messages from alert](https://discuss.elastic.co/t/need-to-email-syslog-messages-from-alert/340146)

<div class="topic-metadata">

**Author:** [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 2:55pm UTC](https://discuss.elastic.co/t/need-to-email-syslog-messages-from-alert/340146 "2023-08-04T14:55:54Z")

</div>

I am trying to be alerted whenever a port security issue comes up, however I can only view content on {{context.hits}}. The table for the syslog message contains fields such as @timestamp, @version, host, message I am …

---

## [Getting an error while running the logstash email output plugin - Unknown Garbage collector name- "G1 -Concurrent GC"](https://discuss.elastic.co/t/getting-an-error-while-running-the-logstash-email-output-plugin-unknown-garbage-collector-name-g1-concurrent-gc/340133)

<div class="topic-metadata">

**Author:** [@AKCG23](https://discuss.elastic.co/u/AKCG23)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 2:47pm UTC](https://discuss.elastic.co/t/getting-an-error-while-running-the-logstash-email-output-plugin-unknown-garbage-collector-name-g1-concurrent-gc/340133 "2023-08-04T14:47:18Z")

</div>

I Have configured Logstash 7.17.3 and Heart beats 7.17.3. I am trying to send an email alert , if the url returns a code 401 . I have configured the email output plugin. While running the logstash i get this error. \[20…

---

## [Double Quotes being truncated](https://discuss.elastic.co/t/double-quotes-being-truncated/340143)

<div class="topic-metadata">

**Author:** [@tech7857](https://discuss.elastic.co/u/tech7857)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 2:41pm UTC](https://discuss.elastic.co/t/double-quotes-being-truncated/340143 "2023-08-04T14:41:02Z")

</div>

Hi We are shipping all our K8s logs to ELK. We noticed that double quotes are being truncated in ELK. Not sure what is the issue. Can you please guide us K8s logs "{\\r\\n \\"param1\\": true,\\r\\n \\"param2\\":…

---

## [Kibana Input controls old v/s new](https://discuss.elastic.co/t/kibana-input-controls-old-v-s-new/339915)

<div class="topic-metadata">

**Author:** [@VVK](https://discuss.elastic.co/u/VVK)\
**Replies:** 4\
**Last updated:** [August 4, 2023, 1:56pm UTC](https://discuss.elastic.co/t/kibana-input-controls-old-v-s-new/339915 "2023-08-04T13:56:51Z")

</div>

Hi, We are using Kibana/Elasticsearch /eck managed for our dev/production (non customer facing UIs) to analyse many things. Sometime back kibana depricated beta version / non-guaranteed (non production ready) versions …

---

## [MD5 hash of fingerprint processor in ingest pipeline](https://discuss.elastic.co/t/md5-hash-of-fingerprint-processor-in-ingest-pipeline/340135)

<div class="topic-metadata">

**Author:** [@Zaid\_Raza](https://discuss.elastic.co/u/Zaid_Raza)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 1:39pm UTC](https://discuss.elastic.co/t/md5-hash-of-fingerprint-processor-in-ingest-pipeline/340135 "2023-08-04T13:39:48Z")

</div>

Hi, My elastic stack version is 8.5.3. I am using a fingerprint processor in ingest pipeline to create an MD5 hash. By default, it gives a hash in base64. I want a 128-bit MD5 hash. Is there any solution to this issue?

---

## [Logstash / Beats Encryption Error](https://discuss.elastic.co/t/logstash-beats-encryption-error/340140)

<div class="topic-metadata">

**Author:** [@WLhelp](https://discuss.elastic.co/u/WLhelp)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 1:44pm UTC](https://discuss.elastic.co/t/logstash-beats-encryption-error/340140 "2023-08-04T13:44:09Z")

</div>

Hey folks, i have trouble setting up encryption for Beats send to logstash server. Test Config says "ok", test output on the client gives me: logstash: 10.1.7.27:5044... connection... parse host... OK dns lookup...…

---

## [Multipath in the pipeline not working](https://discuss.elastic.co/t/multipath-in-the-pipeline-not-working/339842)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 2\
**Last updated:** [August 4, 2023, 1:09pm UTC](https://discuss.elastic.co/t/multipath-in-the-pipeline-not-working/339842 "2023-08-04T13:09:11Z")

</div>

Hello All, Thanks in advance. We have succesfully sending the data to the Logz.io console via custom application. There was a specific request to add one more path in addition to the existing path. The logs that are p…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=458)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=460)
