# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=464

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 465

---

## [Secure traffic via HTTPS - using kafka.output](https://discuss.elastic.co/t/secure-traffic-via-https-using-kafka-output/338779)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 9:26am UTC](https://discuss.elastic.co/t/secure-traffic-via-https-using-kafka-output/338779 "2023-08-01T09:26:31Z")

</div>

I'd like to start using elastic-agent but doing so requires that I setup xpack security. In the docs (here) it gives an example for sending data directly to elasticsearch. We use 'kafka.output'. Is this not supported …

---

## [Winlogbeat/filebeat not sending data to elasticsearch](https://discuss.elastic.co/t/winlogbeat-filebeat-not-sending-data-to-elasticsearch/339135)

<div class="topic-metadata">

**Author:** [@Nirmal](https://discuss.elastic.co/u/Nirmal)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:25am UTC](https://discuss.elastic.co/t/winlogbeat-filebeat-not-sending-data-to-elasticsearch/339135 "2023-08-01T09:25:02Z")

</div>

I am getting error when I run this command for winlogbeat .\\winlogbeat.exe setup -e and for filebeat filebeat setup -e error massage {"log.level":"error","@timestamp":"2023-07-24T22:08:16.309+0100","log.origin":{"fi…

---

## [After upgrading the filebeat 8.8.2 getting the error like publish events: temporary bulk send failure","service.name":"filebeat","ecs.version":"1.6.0"](https://discuss.elastic.co/t/after-upgrading-the-filebeat-8-8-2-getting-the-error-like-publish-events-temporary-bulk-send-failure-service-name-filebeat-ecs-version-1-6-0/339200)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:16am UTC](https://discuss.elastic.co/t/after-upgrading-the-filebeat-8-8-2-getting-the-error-like-publish-events-temporary-bulk-send-failure-service-name-filebeat-ecs-version-1-6-0/339200 "2023-08-01T09:16:08Z")

</div>

Hi, I have upgraded to the filebeat to 8.8.2. Configured it. After started in log I am getting the below error. {"log.level":"error","@timestamp":"2023-07-25T14:38:53.614+0200","log.logger":"publisher\_pipeline\_output",…

---

## [Adding new user in role mapping](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:03am UTC](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755 "2023-08-01T09:03:06Z")

</div>

HI Team, I'm trying to add new user in my existing role mapping and when i perform the action it delete all the existing user from it and create the new user which im parsing. I need to append this in my existing role …

---

## [How to remove a user from role mapping](https://discuss.elastic.co/t/how-to-remove-a-user-from-role-mapping/339688)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 8:59am UTC](https://discuss.elastic.co/t/how-to-remove-a-user-from-role-mapping/339688 "2023-08-01T08:59:17Z")

</div>

HI Team, we are using ELK version 7.17.10 and we have created Roles to manage our indices. my question is if want to remove user from role mapping how do i perform by using Delete command. Looking forward your input. …

---

## [FunctionBeat not able to get CloudWatch Logs](https://discuss.elastic.co/t/functionbeat-not-able-to-get-cloudwatch-logs/339673)

<div class="topic-metadata">

**Author:** [@Vedant14](https://discuss.elastic.co/u/Vedant14)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 8:50am UTC](https://discuss.elastic.co/t/functionbeat-not-able-to-get-cloudwatch-logs/339673 "2023-08-01T08:50:57Z")

</div>

We are trying to fetch the CloudWatch logs in Elastic using FunctionBeat. The function is getting deployed successfully but not able to give the Cloudwatch data in Elastic. We did the configurations for the FunctionBeat …

---

## [Failed to start Filebeat](https://discuss.elastic.co/t/failed-to-start-filebeat/339743)

<div class="topic-metadata">

**Author:** [@rkannan](https://discuss.elastic.co/u/rkannan)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 8:36am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat/339743 "2023-08-01T08:36:49Z")

</div>

Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch , please find the attached screen shot,

---

## [Get all fieldnames of index from](https://discuss.elastic.co/t/get-all-fieldnames-of-index-from/339769)

<div class="topic-metadata">

**Author:** [@aniket\_mandhare](https://discuss.elastic.co/u/aniket_mandhare)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:27am UTC](https://discuss.elastic.co/t/get-all-fieldnames-of-index-from/339769 "2023-08-01T08:27:39Z")

</div>

How to get all only fieldnames(key name) and not the values of it from index in Elasticsearch I tried using following request GET /my\_index/\_field\_caps?fields=\*&filter\_path=fields.\* Expected output { fields:{ "fiel…

---

## [Cluster config](https://discuss.elastic.co/t/cluster-config/339767)

<div class="topic-metadata">

**Author:** [@gagidza](https://discuss.elastic.co/u/gagidza)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:21am UTC](https://discuss.elastic.co/t/cluster-config/339767 "2023-08-01T08:21:13Z")

</div>

Hi all. Expert help needed. I have a 1 node cluster with a 7.4 TB hard drive dedicated to it. The server has 32 GB of RAM. Elastic is configured automatically and here are some of its health/stats: health: { "cluster…

---

## [Elasticsearch-java query slowly](https://discuss.elastic.co/t/elasticsearch-java-query-slowly/339382)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 12\
**Last updated:** [August 1, 2023, 8:19am UTC](https://discuss.elastic.co/t/elasticsearch-java-query-slowly/339382 "2023-08-01T08:19:58Z")

</div>

We have an es cluster, a single node, the version is 8.5.3, and then the java program is linked to do the query. The problem now is that the response speed is within 10ms when we directly curl the query on the host where…

---

## [Tuning of index segmentation](https://discuss.elastic.co/t/tuning-of-index-segmentation/339763)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:11am UTC](https://discuss.elastic.co/t/tuning-of-index-segmentation/339763 "2023-08-01T08:11:11Z")

</div>

Hi I am curious if this is recommended or if there are any tips about set parameters for segmentation. In my case the index is refreshed frequently (new data is uploaded and old data is deleted) what values or segment…

---

## [A failure occurred due to an unknown query](https://discuss.elastic.co/t/a-failure-occurred-due-to-an-unknown-query/339591)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 7:04am UTC](https://discuss.elastic.co/t/a-failure-occurred-due-to-an-unknown-query/339591 "2023-08-01T07:04:01Z")

</div>

A query was performed that didn't originate from our team, and this caused a brief breakdown. Do you know where this query originates from? The version is 6.8 and I am using elasticsearch, not opensearch. { "size":…

---

## [Elasticsearch Python Lib](https://discuss.elastic.co/t/elasticsearch-python-lib/339751)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 6:17am UTC](https://discuss.elastic.co/t/elasticsearch-python-lib/339751 "2023-08-01T06:17:58Z")

</div>

Hi, I'm using Elastic Search python lib (8.8.2) to bulk insert data into a index. There are almost 2lakh+ documents I need to insert. I'm using parallel\_bulk api to sync them, but as I track the process RAM usage I see …

---

## [Kibana discover page does not show all documents in list, the timeline does](https://discuss.elastic.co/t/kibana-discover-page-does-not-show-all-documents-in-list-the-timeline-does/339710)

<div class="topic-metadata">

**Author:** [@jori-be](https://discuss.elastic.co/u/jori-be)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 6:13am UTC](https://discuss.elastic.co/t/kibana-discover-page-does-not-show-all-documents-in-list-the-timeline-does/339710 "2023-08-01T06:13:20Z")

</div>

Hi guys, I see strange behavior in Kibana 8.5.3 in the discover page. When I'm filtering on data in discover page, I do not see all the documents that exist in the index-pattern. As you see on the screenshot above,…

---

## [At which step does Bulkresponse occur](https://discuss.elastic.co/t/at-which-step-does-bulkresponse-occur/339740)

<div class="topic-metadata">

**Author:** [@Logan-lxw](https://discuss.elastic.co/u/Logan-lxw)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 3:40am UTC](https://discuss.elastic.co/t/at-which-step-does-bulkresponse-occur/339740 "2023-08-01T03:40:24Z")

</div>

At which stage does the BulkResponse corresponding to BulkRequest occur? Which step does this response specifically refer to before returning? Does it mean that the request was successfully written to the translog and fl…

---

## [Runtime get month()](https://discuss.elastic.co/t/runtime-get-month/339721)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 3:07am UTC](https://discuss.elastic.co/t/runtime-get-month/339721 "2023-08-01T03:07:22Z")

</div>

hello , I have this runtime - GET my-index-000006-test/\_search { "runtime\_mappings": { "day\_of\_week": { "type": "keyword", "script": { "source": "emit(doc\['timestamp'\].value.dayOfWeek…

---

## [An index has stayed on the same action longer than expected](https://discuss.elastic.co/t/an-index-has-stayed-on-the-same-action-longer-than-expected/339636)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 1:46am UTC](https://discuss.elastic.co/t/an-index-has-stayed-on-the-same-action-longer-than-expected/339636 "2023-08-01T01:46:06Z")

</div>

I have upgraded my Elastic stack from 8.82 to 8.9 and facing this warning for one of my indices Deployment\_management Automatic index lifecycle and data retention management cannot make progress on one or more indices.…

---

## [Logstash JDBC Input Plugin Connection Pooling](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-connection-pooling/337823)

<div class="topic-metadata">

**Author:** [@alromos](https://discuss.elastic.co/u/alromos)\
**Replies:** 4\
**Last updated:** [July 31, 2023, 11:08pm UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-connection-pooling/337823 "2023-07-31T23:08:35Z")

</div>

Our team is actively using Logstash JDBC Input plugin with MSSQL JDBC driver for reading some data from DB for further processing. Logstash version: 8.5.1 MSSQL JDBC version: 11.2.1.jre17 At the moment we are facing s…

---

## [Fetching substring from a string in kibana](https://discuss.elastic.co/t/fetching-substring-from-a-string-in-kibana/338203)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 8\
**Last updated:** [July 31, 2023, 8:58pm UTC](https://discuss.elastic.co/t/fetching-substring-from-a-string-in-kibana/338203 "2023-07-31T20:58:31Z")

</div>

Hi, I have a field called url in elasticsearch document. The sample value for the field is /3dpassport/login I want to extract only the first string before / that is 3dpassport and store it in a field. I am okay with …

---

## [Question on Vega Circle plot](https://discuss.elastic.co/t/question-on-vega-circle-plot/339734)

<div class="topic-metadata">

**Author:** [@vkon](https://discuss.elastic.co/u/vkon)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 8:29pm UTC](https://discuss.elastic.co/t/question-on-vega-circle-plot/339734 "2023-07-31T20:29:12Z")

</div>

Hi, I'm using Elastic 7.17 version and trying to create Circle visualization using Vega. I have the below sample data; \[ {"stage":"s1","indicator":"i1","score":3,"maxscore":4}, {"stage":"s1","indicator":"i1","score":1…

---

## [Select latest docs for each transactions and apply filters on selections with pagination capability](https://discuss.elastic.co/t/select-latest-docs-for-each-transactions-and-apply-filters-on-selections-with-pagination-capability/339730)

<div class="topic-metadata">

**Author:** [@pramodbhade](https://discuss.elastic.co/u/pramodbhade)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 8:12pm UTC](https://discuss.elastic.co/t/select-latest-docs-for-each-transactions-and-apply-filters-on-selections-with-pagination-capability/339730 "2023-07-31T20:12:31Z")

</div>

I have a situation where I need to load 100 records per page with the latest values and be able to paginate as well. The selected latest records also get filtered for a set of filter values. I'm using aggregation in th…

---

## [Aggregate filter plugin](https://discuss.elastic.co/t/aggregate-filter-plugin/339709)

<div class="topic-metadata">

**Author:** [@pero](https://discuss.elastic.co/u/pero)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 8:06pm UTC](https://discuss.elastic.co/t/aggregate-filter-plugin/339709 "2023-07-31T20:06:22Z")

</div>

I have these two json documents Document 1 is { "\_index": "auditbeat-2023.07.31", "\_type": "\_doc", "\_id": "KhknrIkBBEGDHOFEynSE", "\_version": 1, "\_score": null, "\_source": { "ecs": { "version": "1…

---

## [It is that possible to I return in my Elasticsearch query a new field , that does not exist in the mapping . With a new format from other field?](https://discuss.elastic.co/t/it-is-that-possible-to-i-return-in-my-elasticsearch-query-a-new-field-that-does-not-exist-in-the-mapping-with-a-new-format-from-other-field/339616)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 4\
**Last updated:** [July 31, 2023, 6:46pm UTC](https://discuss.elastic.co/t/it-is-that-possible-to-i-return-in-my-elasticsearch-query-a-new-field-that-does-not-exist-in-the-mapping-with-a-new-format-from-other-field/339616 "2023-07-31T18:46:41Z")

</div>

It is that possible to I return in my Elasticsearch query a new field ( that does not exist in the mapping ), with a new format from other field ? something like that - This is my Mapping - PUT /user-product-2023-06…

---

## [I want to create kibana dashboard with clickable field](https://discuss.elastic.co/t/i-want-to-create-kibana-dashboard-with-clickable-field/339682)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 5:48pm UTC](https://discuss.elastic.co/t/i-want-to-create-kibana-dashboard-with-clickable-field/339682 "2023-07-31T17:48:13Z")

</div>

This is one of my dashboard.I want to create this field(I marked with red colour round) as clickable and open the popup and show details of this number.

---

## [Metricbeat beats x-pack monitoring + Logstash output not appearing in Kibana monitoring GUI](https://discuss.elastic.co/t/metricbeat-beats-x-pack-monitoring-logstash-output-not-appearing-in-kibana-monitoring-gui/339716)

<div class="topic-metadata">

**Author:** [@novaksam](https://discuss.elastic.co/u/novaksam)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 5:33pm UTC](https://discuss.elastic.co/t/metricbeat-beats-x-pack-monitoring-logstash-output-not-appearing-in-kibana-monitoring-gui/339716 "2023-07-31T17:33:43Z")

</div>

Hey all, As I migrate to Elastic Stack 8 I'm working on migrating all monitoring over to Metricbeat, and because I may have beats installed on more widely accessible locations, I'm wanting to use Logstash output for met…

---

## [Add multiple filters based on geo distance on same index](https://discuss.elastic.co/t/add-multiple-filters-based-on-geo-distance-on-same-index/339623)

<div class="topic-metadata">

**Author:** [@alchemist23](https://discuss.elastic.co/u/alchemist23)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 5:27pm UTC](https://discuss.elastic.co/t/add-multiple-filters-based-on-geo-distance-on-same-index/339623 "2023-07-31T17:27:16Z")

</div>

Hello , I have a single index containing starbucks location data , a data view is based on an index from Elasticsearch I wish to display results on kibana visualization based on the distance with different color coding …

---

## [Cardinality Limitation Work Around](https://discuss.elastic.co/t/cardinality-limitation-work-around/339453)

<div class="topic-metadata">

**Author:** [@edang](https://discuss.elastic.co/u/edang)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 2:44pm UTC](https://discuss.elastic.co/t/cardinality-limitation-work-around/339453 "2023-07-27T14:44:22Z")

</div>

Hi All, With my data set I have seen a mismatch of data between ELK and my DB. For my purpose, I have used the cardinality aggregation to count the unique ids of a field but ran into some issues. The issues comes from t…

---

## [Autocomplete using Completion Suggesters](https://discuss.elastic.co/t/autocomplete-using-completion-suggesters/338823)

<div class="topic-metadata">

**Author:** [@Senchok](https://discuss.elastic.co/u/Senchok)\
**Replies:** 7\
**Last updated:** [July 31, 2023, 5:12pm UTC](https://discuss.elastic.co/t/autocomplete-using-completion-suggesters/338823 "2023-07-31T17:12:04Z")

</div>

Hello, I want to write Autocomplete using Elasticsearch. I use Completion Suggesters and I have problems with it. For example I have fullName and title fields "fullName": "John Smith" "title": "Python Developer" B…

---

## [Error when setting up Alerts in Observability](https://discuss.elastic.co/t/error-when-setting-up-alerts-in-observability/339468)

<div class="topic-metadata">

**Author:** [@elastic12](https://discuss.elastic.co/u/elastic12)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 5:45pm UTC](https://discuss.elastic.co/t/error-when-setting-up-alerts-in-observability/339468 "2023-07-27T17:45:25Z")

</div>

I am setting up an Log Threshold alert using index connector. I followed all the steps shown in the documentation Index connector and action | Kibana Guide \[8.6\] | Elastic and I am getting an error shown below "Rule re…

---

## [Collecting Sophos XG logs using the Sophos integration feature](https://discuss.elastic.co/t/collecting-sophos-xg-logs-using-the-sophos-integration-feature/339565)

<div class="topic-metadata">

**Author:** [@TIT](https://discuss.elastic.co/u/TIT)\
**Replies:** 5\
**Last updated:** [July 31, 2023, 5:10pm UTC](https://discuss.elastic.co/t/collecting-sophos-xg-logs-using-the-sophos-integration-feature/339565 "2023-07-31T17:10:00Z")

</div>

Hello, I'm currently trying to integrate Sophos XG firewall logs into my ELK stack via the Filebeat Sophos module. My setup involves sending logs directly from my Sophos XG device to Elasticsearch, bypassing Logstash. T…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=463)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=465)
