# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=460

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 461

---

## [Elastic Serverless Forwarder for AWS adding reserved \_id field when sending to logstash](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-adding-reserved-id-field-when-sending-to-logstash/340084)

<div class="topic-metadata">

**Author:** [@stabbotco1](https://discuss.elastic.co/u/stabbotco1)\
**Replies:** 3\
**Last updated:** [August 4, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-adding-reserved-id-field-when-sending-to-logstash/340084 "2023-08-04T12:55:27Z")

</div>

Hi All! I am new to ES, so apologies in advance if I mis-state some things. We are looking to use the ES Serverless Forwarder for AWS (Elastic Serverless Forwarder for AWS | Elastic Serverless Forwarder Guide | Elastic)…

---

## [Can Logstash be setup separately after deploying Elasticsearch using AzureRM template?](https://discuss.elastic.co/t/can-logstash-be-setup-separately-after-deploying-elasticsearch-using-azurerm-template/339152)

<div class="topic-metadata">

**Author:** [@Haralambie\_Lungu](https://discuss.elastic.co/u/Haralambie_Lungu)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 11:59am UTC](https://discuss.elastic.co/t/can-logstash-be-setup-separately-after-deploying-elasticsearch-using-azurerm-template/339152 "2023-08-04T11:59:58Z")

</div>

Hi everyone, We have deployed Elasticsearch Self-Managed using the ARM template from Azure Marketplace. We haven't checked Logstash during the setup process, we only created the kibana, master-0,1 and 2 and also the da…

---

## [Sorting help with query](https://discuss.elastic.co/t/sorting-help-with-query/340128)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 11:58am UTC](https://discuss.elastic.co/t/sorting-help-with-query/340128 "2023-08-04T11:58:40Z")

</div>

{ "query": { "bool": { "must": \[ { "term": { "status": { "value": 1 } } } \], "should": \[ { "wildcard": {…

---

## [Elasticsearch not generating certificates and enrollment tokens when started from a DockerFile](https://discuss.elastic.co/t/elasticsearch-not-generating-certificates-and-enrollment-tokens-when-started-from-a-dockerfile/340119)

<div class="topic-metadata">

**Author:** [@Tanmay\_Sharma](https://discuss.elastic.co/u/Tanmay_Sharma)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 9:38am UTC](https://discuss.elastic.co/t/elasticsearch-not-generating-certificates-and-enrollment-tokens-when-started-from-a-dockerfile/340119 "2023-08-04T09:38:22Z")

</div>

Hello everyone, i'm trying to spin up a docker container for elasticsearch using the Dockerfile: FROM elasticsearch:8.8.1 # Set the environment variables for Elasticsearch. ENV discovery.type=single-node ENV xpack.secu…

---

## [Search slowlog in JSON format is truncating the query](https://discuss.elastic.co/t/search-slowlog-in-json-format-is-truncating-the-query/340095)

<div class="topic-metadata">

**Author:** [@gshankar-elastic](https://discuss.elastic.co/u/gshankar-elastic)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 7:53am UTC](https://discuss.elastic.co/t/search-slowlog-in-json-format-is-truncating-the-query/340095 "2023-08-04T07:53:46Z")

</div>

I am on Elasticsearch 7.10.0 and recently I have changed the slowlogs format from plaintext to json anticipating that large query truncation issue will be resolved automatically in the json format. But I am still seeing …

---

## [Help me to query this document](https://discuss.elastic.co/t/help-me-to-query-this-document/340110)

<div class="topic-metadata">

**Author:** [@marcin\_cron](https://discuss.elastic.co/u/marcin_cron)\
**Replies:** 3\
**Last updated:** [August 4, 2023, 9:19am UTC](https://discuss.elastic.co/t/help-me-to-query-this-document/340110 "2023-08-04T09:19:02Z")

</div>

This is my documents: //document 1 { "place": "galaxy", "range": { "area": { "planet": "mars", "country": \[ -----------country 1------------------ …

---

## [Elasticsearch - Attempted to send a bulk request but Elasticsearch appears to be unreachable or down](https://discuss.elastic.co/t/elasticsearch-attempted-to-send-a-bulk-request-but-elasticsearch-appears-to-be-unreachable-or-down/340101)

<div class="topic-metadata">

**Author:** [@aswin\_parakkal](https://discuss.elastic.co/u/aswin_parakkal)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 6:39am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-send-a-bulk-request-but-elasticsearch-appears-to-be-unreachable-or-down/340101 "2023-08-04T06:39:27Z")

</div>

Hyy👋, My Elasticsearch is running properly but sometimes it shows this error . Attempted to send a bulk request but there are no living connections in the pool (perhaps Elasticsearch is unreachable or down?) {:me…

---

## [Logstash:grok:Create a single structure from multiple pattern](https://discuss.elastic.co/t/logstashcreate-a-single-structure-from-multiple-pattern/340098)

<div class="topic-metadata">

**Author:** [@nehag](https://discuss.elastic.co/u/nehag)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 6:15am UTC](https://discuss.elastic.co/t/logstashcreate-a-single-structure-from-multiple-pattern/340098 "2023-08-04T06:15:12Z")

</div>

I have logs coming in the following pattern: ================================================================================================== CHECK 1 : Below are the missing Components in the patch =================…

---

## [Grokparse failure even grok debugger fine](https://discuss.elastic.co/t/grokparse-failure-even-grok-debugger-fine/340023)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 8\
**Last updated:** [August 4, 2023, 4:17am UTC](https://discuss.elastic.co/t/grokparse-failure-even-grok-debugger-fine/340023 "2023-08-04T04:17:25Z")

</div>

Hi All, i am facing the grokparsefailure for my logs even the grok debugger is showing all parsed data but logstash is failing for all fields. below is my filter of logstash filter { grok { …

---

## [Elastic & Kibana Security](https://discuss.elastic.co/t/elastic-kibana-security/339870)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [August 4, 2023, 4:05am UTC](https://discuss.elastic.co/t/elastic-kibana-security/339870 "2023-08-04T04:05:12Z")

</div>

We have successfully embedded the Kibana dashboard into the RTS (Real-Time System) UI Interface. This integration enables our customers to access the powerful analytics feature seamlessly within our platform. To provide…

---

## [Elasticsearch keep migrating shards out of one of my data node](https://discuss.elastic.co/t/elasticsearch-keep-migrating-shards-out-of-one-of-my-data-node/340041)

<div class="topic-metadata">

**Author:** [@Zeeshan\_Alam](https://discuss.elastic.co/u/Zeeshan_Alam)\
**Replies:** 4\
**Last updated:** [August 4, 2023, 3:48am UTC](https://discuss.elastic.co/t/elasticsearch-keep-migrating-shards-out-of-one-of-my-data-node/340041 "2023-08-04T03:48:27Z")

</div>

Elasticsearch keep migrating shards out of one of my data node data-mbesdrtp21. This cluster have mix of plain index and data streams. Around 10-15 shards get allocated to this node and then they are reallocated to othe…

---

## [Rename json nested fields using mutate](https://discuss.elastic.co/t/rename-json-nested-fields-using-mutate/340063)

<div class="topic-metadata">

**Author:** [@mario\_kazela](https://discuss.elastic.co/u/mario_kazela)\
**Replies:** 4\
**Last updated:** [August 4, 2023, 3:32am UTC](https://discuss.elastic.co/t/rename-json-nested-fields-using-mutate/340063 "2023-08-04T03:32:03Z")

</div>

Hi, I have an issue with mutating a nested JSON fields using Logstash. Example of my nested JSON: "test\_results\_result\_legacy\_entities\_hashtags": \[ { "indices": \[ 34, 43 \], "text"…

---

## [Kibana webhook parameter - Host error](https://discuss.elastic.co/t/kibana-webhook-parameter-host-error/340068)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 10:06pm UTC](https://discuss.elastic.co/t/kibana-webhook-parameter-host-error/340068 "2023-08-03T22:06:33Z")

</div>

My question is regarding watcher webhook host. I got 2 logstash VMs where I have loadbalanced to feed data from filebeat. Below is my webhook portion }, "dev\_webhook": { "webhook": { "scheme": "http",…

---

## [Has anyone successfully stood up a multi-node elasticsearch cluster with kibana and logstash through docker images?](https://discuss.elastic.co/t/has-anyone-successfully-stood-up-a-multi-node-elasticsearch-cluster-with-kibana-and-logstash-through-docker-images/340082)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 9:30pm UTC](https://discuss.elastic.co/t/has-anyone-successfully-stood-up-a-multi-node-elasticsearch-cluster-with-kibana-and-logstash-through-docker-images/340082 "2023-08-03T21:30:52Z")

</div>

I've been on this project for while now and I not sure where I'm going wrong. My goal is to setup the ELK stack (elasticsearch, kibana, and logstash) on one host then a second elasticsearch node on a different host usin…

---

## [\`host.name\` and \`host.hostname\`](https://discuss.elastic.co/t/host-name-and-host-hostname/339742)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 9:24pm UTC](https://discuss.elastic.co/t/host-name-and-host-hostname/339742 "2023-08-03T21:24:27Z")

</div>

What kind of values are folks using for host.name and host.hostname? Basically I think ECS is encouraging FQDN in host.name and short name in host.hostname?

---

## [We can't find products matching the selection](https://discuss.elastic.co/t/we-cant-find-products-matching-the-selection/340075)

<div class="topic-metadata">

**Author:** [@Denis\_Belik](https://discuss.elastic.co/u/Denis_Belik)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 7:33pm UTC](https://discuss.elastic.co/t/we-cant-find-products-matching-the-selection/340075 "2023-08-03T19:33:06Z")

</div>

There is an online store on Magento 2.3.2 When you open a department , a blank page appears without product cards with an error "We can't find products matching the selection.". The hosting technical support said that…

---

## [Making a custom stacked bar chart using nested fields with Vega on Kibana](https://discuss.elastic.co/t/making-a-custom-stacked-bar-chart-using-nested-fields-with-vega-on-kibana/339956)

<div class="topic-metadata">

**Author:** [@Gemma\_S](https://discuss.elastic.co/u/Gemma_S)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 6:07pm UTC](https://discuss.elastic.co/t/making-a-custom-stacked-bar-chart-using-nested-fields-with-vega-on-kibana/339956 "2023-08-03T18:07:14Z")

</div>

I'm trying to make a stacked bar chart in Vega that uses aggregation on nested fields and I've been able to successfully make an inverted version of it (y axis and color the incorrect way round) but can't get it to work …

---

## [Moving preconfigured Elasticsearch and kibana (with custom indexes and dashboards) to another server](https://discuss.elastic.co/t/moving-preconfigured-elasticsearch-and-kibana-with-custom-indexes-and-dashboards-to-another-server/340072)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 5:55pm UTC](https://discuss.elastic.co/t/moving-preconfigured-elasticsearch-and-kibana-with-custom-indexes-and-dashboards-to-another-server/340072 "2023-08-03T17:55:26Z")

</div>

Hello there, I am working on a large ec2 ubuntu instance where I manually downloaded and installed elasticsearch and kibana (I didn't use docker) . I connected my stack with external data sources and made a lot of cust…

---

## [No dashboard is created when adding integrations](https://discuss.elastic.co/t/no-dashboard-is-created-when-adding-integrations/340051)

<div class="topic-metadata">

**Author:** [@hoomant](https://discuss.elastic.co/u/hoomant)\
**Replies:** 5\
**Last updated:** [August 3, 2023, 5:32pm UTC](https://discuss.elastic.co/t/no-dashboard-is-created-when-adding-integrations/340051 "2023-08-03T17:32:52Z")

</div>

Hi I have setup Fleet in my cluster & installed elastic agent on one of my servers & it is sending metrics to elasticsearch & it is showing up in Discover in kibana. The thing is, when I am adding integrations no dashbo…

---

## [Knn as percolator query](https://discuss.elastic.co/t/knn-as-percolator-query/340066)

<div class="topic-metadata">

**Author:** [@Matthew\_Pollard](https://discuss.elastic.co/u/Matthew_Pollard)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 4:37pm UTC](https://discuss.elastic.co/t/knn-as-percolator-query/340066 "2023-08-03T16:37:35Z")

</div>

Hi Just wondering whether it is currently possible to use a knn query as a percolater query - my feeling is that this is currently not possible but just checking? Thanks Matthew

---

## [Error while creating new Fields in Elastic Search](https://discuss.elastic.co/t/error-while-creating-new-fields-in-elastic-search/340064)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 3:35pm UTC](https://discuss.elastic.co/t/error-while-creating-new-fields-in-elastic-search/340064 "2023-08-03T15:35:55Z")

</div>

hello , Can anyone help, I'm new to elasticsearch Kibana but learnt in recent days to understand the usage. I have a Index name "logstash-\*" which receives logs constantly, my task is to filter from all logs in field "…

---

## [Filebeat Index](https://discuss.elastic.co/t/filebeat-index/340008)

<div class="topic-metadata">

**Author:** [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Replies:** 4\
**Last updated:** [August 3, 2023, 2:33pm UTC](https://discuss.elastic.co/t/filebeat-index/340008 "2023-08-03T14:33:38Z")

</div>

Hello, I have installed filebeat and uploaded a CSV to obtain the filebeat configuration for the installation, creating a new index and pipeline. the yml file looks like this: filebeat.inputs: - type: log paths: - C…

---

## [Circuit\_breaking\_exception: \[script\] Too many dynamic script compilations within, max: \[1000/5m\]](https://discuss.elastic.co/t/circuit-breaking-exception-script-too-many-dynamic-script-compilations-within-max-1000-5m/340002)

<div class="topic-metadata">

**Author:** [@Zephery\_Wen](https://discuss.elastic.co/u/Zephery_Wen)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 2:25pm UTC](https://discuss.elastic.co/t/circuit-breaking-exception-script-too-many-dynamic-script-compilations-within-max-1000-5m/340002 "2023-08-03T14:25:38Z")

</div>

I created a stored script in elasticsearch GET \_scripts/xxx-script { "\_id": "xxx-script", "found": true, "script": { "lang": "painless", "source": "ctx.\_source.a = params.a;ctx.\_source.b = params.b;ctx.\_so…

---

## [Aruba ClearPass Integration with FIlebeat and Elasticsearch](https://discuss.elastic.co/t/aruba-clearpass-integration-with-filebeat-and-elasticsearch/340058)

<div class="topic-metadata">

**Author:** [@kibana\_user17](https://discuss.elastic.co/u/kibana_user17)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 2:15pm UTC](https://discuss.elastic.co/t/aruba-clearpass-integration-with-filebeat-and-elasticsearch/340058 "2023-08-03T14:15:17Z")

</div>

Anyone here have done integration between elasticsearch and aruba clear pass manager?

---

## [Cannot access Flattened field in ElasticSearch Dashboard](https://discuss.elastic.co/t/cannot-access-flattened-field-in-elasticsearch-dashboard/339824)

<div class="topic-metadata">

**Author:** [@Dana\_Pavaday](https://discuss.elastic.co/u/Dana_Pavaday)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 2:14pm UTC](https://discuss.elastic.co/t/cannot-access-flattened-field-in-elasticsearch-dashboard/339824 "2023-08-03T14:14:44Z")

</div>

Hello, I have created a transform where I have grouped by Client, BackupJob and BackupTool and I have put a terms aggregation in BackupStatus. The transform is displaying as expected in Discover. But when I try to creat…

---

## [Vega, Cross reference between 2 indexes](https://discuss.elastic.co/t/vega-cross-reference-between-2-indexes/339391)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 4\
**Last updated:** [August 3, 2023, 2:05pm UTC](https://discuss.elastic.co/t/vega-cross-reference-between-2-indexes/339391 "2023-08-03T14:05:56Z")

</div>

Scenario: -- 2 different indexes -- current\_Id in IndexA and doc\_Id in IndexB I have a use case where i have to display data, when a condition current\_id equals doc\_Id It should retrieve all records for which this co…

---

## [Elasticsearch exited with code 1, docker elk stack](https://discuss.elastic.co/t/elasticsearch-exited-with-code-1-docker-elk-stack/340029)

<div class="topic-metadata">

**Author:** [@donglobal\_B](https://discuss.elastic.co/u/donglobal_B)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch-exited-with-code-1-docker-elk-stack/340029 "2023-08-03T13:41:52Z")

</div>

I am using docker sebp/elk to build my elk environment. normally it runs well, but several days ago, the PC is restarted and when I want to restart the docker, it 99% fail and 1% run successfully. and after inspecting th…

---

## [Access container logs with libbeat / filebeat with non-root user](https://discuss.elastic.co/t/access-container-logs-with-libbeat-filebeat-with-non-root-user/340050)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 1:39pm UTC](https://discuss.elastic.co/t/access-container-logs-with-libbeat-filebeat-with-non-root-user/340050 "2023-08-03T13:39:31Z")

</div>

I have filebeat / libbeat running as non-root user and want to read docker container logs from /var/lib/docker/container . I have mounted the directory within beat pod but the directory has 700 permission by default, i.e…

---

## [Regarding Container Input](https://discuss.elastic.co/t/regarding-container-input/339707)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 14\
**Last updated:** [August 3, 2023, 1:06pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707 "2023-08-03T13:06:17Z")

</div>

Hi, I see that combine\_partial is not a parameter for the container input. Does the input now automatically handle docker's 16kb message limit? Thx D

---

## [Multi match query does not work for nested types](https://discuss.elastic.co/t/multi-match-query-does-not-work-for-nested-types/339936)

<div class="topic-metadata">

**Author:** [@Teqqan](https://discuss.elastic.co/u/Teqqan)\
**Replies:** 4\
**Last updated:** [August 3, 2023, 12:26pm UTC](https://discuss.elastic.co/t/multi-match-query-does-not-work-for-nested-types/339936 "2023-08-03T12:26:30Z")

</div>

Hi, I'm trying to perform a multi match query on some data I have structured as nested types. When I search for something like "gadget plushy" I get no matches for a document with two nested fields "gadget" and "plushy"…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=459)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=461)
