# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=465

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 466

---

## [Logstash filter mutate problem](https://discuss.elastic.co/t/logstash-filter-mutate-problem/339690)

<div class="topic-metadata">

**Author:** [@pero](https://discuss.elastic.co/u/pero)\
**Replies:** 12\
**Last updated:** [July 31, 2023, 3:01pm UTC](https://discuss.elastic.co/t/logstash-filter-mutate-problem/339690 "2023-07-31T15:01:14Z")

</div>

I have created a filter as shown below filter { if \[application\] == "today" { if field1 { mutate { add\_field =\> { mynewfield =\> "%{\[field1\]}" } …

---

## [Kibana Machine Learning Job Alert](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 7\
**Last updated:** [July 31, 2023, 2:38pm UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151 "2023-07-31T14:38:56Z")

</div>

Hi Team, We have created alert for anomaly detection and we are getting this alert on email. It is showing different timestamp Elastic Stack Machine Learning Alert: - Job IDs: {{context.jobIds}} - Time: {{context.time…

---

## [Where is the certificate authority that signs elastic images using cosign?](https://discuss.elastic.co/t/where-is-the-certificate-authority-that-signs-elastic-images-using-cosign/339699)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 1:45pm UTC](https://discuss.elastic.co/t/where-is-the-certificate-authority-that-signs-elastic-images-using-cosign/339699 "2023-07-31T13:45:05Z")

</div>

Elastic now signs images using cosign to strengthen the supply chain. I'd like to run these images in Kubernetes and use Kyverno to verify the images but i get the error: "certificate signed by unknown authority". Wher…

---

## [Hide black bar in iframe](https://discuss.elastic.co/t/hide-black-bar-in-iframe/339698)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 1:54pm UTC](https://discuss.elastic.co/t/hide-black-bar-in-iframe/339698 "2023-07-31T13:54:29Z")

</div>

I have Python application in which I want render iframe kibana dashboard and want hide black bar in which elastic logo also view. I am attach photo please suggest how can I hide this black bar .

---

## [Searching with runtime, without mapping with runtime](https://discuss.elastic.co/t/searching-with-runtime-without-mapping-with-runtime/339696)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 1:48pm UTC](https://discuss.elastic.co/t/searching-with-runtime-without-mapping-with-runtime/339696 "2023-07-31T13:48:55Z")

</div>

hello , I am trying to learn runtime . it uses in the script the painless language , It wold be nice to I understand this language , that I could test it before mapping . the way to test it before mapping it is search …

---

## [Removing prefix from field names](https://discuss.elastic.co/t/removing-prefix-from-field-names/339674)

<div class="topic-metadata">

**Author:** [@VirusProtect](https://discuss.elastic.co/u/VirusProtect)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 1:39pm UTC](https://discuss.elastic.co/t/removing-prefix-from-field-names/339674 "2023-07-31T13:39:33Z")

</div>

Hi, I have fields in Kibana such as fw.ip, fw.name, fw.test.old, and so on. I am trying to remove the "fw" prefix from all these fields using a Ruby filter in Logstash. Here's the code I'm using: ruby { code =\> " …

---

## [Filebeat to add extra fields for logstash 7.17, it worked previously but not anymore?](https://discuss.elastic.co/t/filebeat-to-add-extra-fields-for-logstash-7-17-it-worked-previously-but-not-anymore/339670)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-to-add-extra-fields-for-logstash-7-17-it-worked-previously-but-not-anymore/339670 "2023-07-31T13:12:14Z")

</div>

I have my dmarc interpreter running here, and noticed that it didn't produce any data to the kibana. It looks like the config is ignored with the 7.17, and back when it was 6.x it worked. Can you tell me what I've done…

---

## [It is possible to set (logstash.conf )output for particular file location in logstash server](https://discuss.elastic.co/t/it-is-possible-to-set-logstash-conf-output-for-particular-file-location-in-logstash-server/339664)

<div class="topic-metadata">

**Author:** [@rkannan](https://discuss.elastic.co/u/rkannan)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 12:47pm UTC](https://discuss.elastic.co/t/it-is-possible-to-set-logstash-conf-output-for-particular-file-location-in-logstash-server/339664 "2023-07-31T12:47:17Z")

</div>

It is possible to set (logstash.conf )output for particular file location in logstash server

---

## [Diferencia valores desde visualice con DevTools](https://discuss.elastic.co/t/diferencia-valores-desde-visualice-con-devtools/339691)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 12:15pm UTC](https://discuss.elastic.co/t/diferencia-valores-desde-visualice-con-devtools/339691 "2023-07-31T12:15:30Z")

</div>

Hola, elasticSearch: 7.17.5 Diferencia de valores cuando el datos se presenta mediante lens tipo tabla con diferentes métricas y query desde DevTools. La métrica que se aplica en un count del filtro que se ejecuta en l…

---

## [Auditbeat logs many warnings](https://discuss.elastic.co/t/auditbeat-logs-many-warnings/339689)

<div class="topic-metadata">

**Author:** [@floriankoenig-work](https://discuss.elastic.co/u/floriankoenig-work)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 12:10pm UTC](https://discuss.elastic.co/t/auditbeat-logs-many-warnings/339689 "2023-07-31T12:10:27Z")

</div>

I've noticed auditbeat spamming (sometimes ~10/sec) the log with following messages: Jul 30 00:04:44 HOSTNAME auditbeat\[2327385\]: {"log.level":"warn","@timestamp":"2023-07-30T00:04:44.668+0200","log.logger":"process","l…

---

## [Filter vector search by similarity value](https://discuss.elastic.co/t/filter-vector-search-by-similarity-value/339654)

<div class="topic-metadata">

**Author:** [@john\_nicolas](https://discuss.elastic.co/u/john_nicolas)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 11:53am UTC](https://discuss.elastic.co/t/filter-vector-search-by-similarity-value/339654 "2023-07-31T11:53:40Z")

</div>

i used in mappings file a dense\_vector for knn "esvector": { "type": "dense\_vector", "dims": 768, "index": true, "similarity": "cosine" }, I want to use a similarity threshold ,…

---

## [Split index into subindexes by dates like 'my-index-yyyy.MM.dd'](https://discuss.elastic.co/t/split-index-into-subindexes-by-dates-like-my-index-yyyy-mm-dd/339330)

<div class="topic-metadata">

**Author:** [@tyro\_plotter](https://discuss.elastic.co/u/tyro_plotter)\
**Replies:** 4\
**Last updated:** [July 31, 2023, 11:49am UTC](https://discuss.elastic.co/t/split-index-into-subindexes-by-dates-like-my-index-yyyy-mm-dd/339330 "2023-07-31T11:49:04Z")

</div>

I am considering two options: Time Series Ingest pipeline (Date index name processor) I am aware that they differ in their intended use, but I am trying to understand what risks there are. As a newbie to the time ser…

---

## [Getting No config files found in path in the cmd](https://discuss.elastic.co/t/getting-no-config-files-found-in-path-in-the-cmd/339684)

<div class="topic-metadata">

**Author:** [@ItsGautam](https://discuss.elastic.co/u/ItsGautam)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 11:23am UTC](https://discuss.elastic.co/t/getting-no-config-files-found-in-path-in-the-cmd/339684 "2023-07-31T11:23:41Z")

</div>

Logstash stopped processing because of an error: (SystemExit) exit in the cmd prompt conf file: input { file { type =\> "logs" path =\> "C:\\elk\\elk-stack" start\_position=\>"beginning" codec =\> multiline { pattern…

---

## [Create a kibana dashboard for user account lockouts](https://discuss.elastic.co/t/create-a-kibana-dashboard-for-user-account-lockouts/339463)

<div class="topic-metadata">

**Author:** [@kibana\_user17](https://discuss.elastic.co/u/kibana_user17)\
**Replies:** 9\
**Last updated:** [July 31, 2023, 11:07am UTC](https://discuss.elastic.co/t/create-a-kibana-dashboard-for-user-account-lockouts/339463 "2023-07-31T11:07:15Z")

</div>

Hi everyone. i'm very new to elasticsearch. Is it possible to create a dashboard in Kibana showing user account lockouts? If so, how? We used winlogbeat and elasticsearch. Appreciate the help..

---

## [Too many fields in an index](https://discuss.elastic.co/t/too-many-fields-in-an-index/339679)

<div class="topic-metadata">

**Author:** [@Jurrien](https://discuss.elastic.co/u/Jurrien)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 10:55am UTC](https://discuss.elastic.co/t/too-many-fields-in-an-index/339679 "2023-07-31T10:55:28Z")

</div>

We have an index with the following structure (see below) So basically, we have our index business\_objects with a link and no. We add objects to this index (doc\_type1, doc\_type2, ....). These objects are linked via no …

---

## [Word count using Logstash Pipeline](https://discuss.elastic.co/t/word-count-using-logstash-pipeline/339678)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 10:53am UTC](https://discuss.elastic.co/t/word-count-using-logstash-pipeline/339678 "2023-07-31T10:53:13Z")

</div>

Hi Team, I am trying to build and design a logstash pipeline where the count of different words tracked against the timestamp. I need to classify every word based on length of texts in three segments, say words with …

---

## [Support hieroglyphs and symbols](https://discuss.elastic.co/t/support-hieroglyphs-and-symbols/339677)

<div class="topic-metadata">

**Author:** [@viachaslau](https://discuss.elastic.co/u/viachaslau)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 10:45am UTC](https://discuss.elastic.co/t/support-hieroglyphs-and-symbols/339677 "2023-07-31T10:45:39Z")

</div>

What analyzer I should use for support hieroglyphs and symbols. I cant use ICU because It remove symbols.

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/339618)

<div class="topic-metadata">

**Author:** [@akhilesh\_teeluck](https://discuss.elastic.co/u/akhilesh_teeluck)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 10:37am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/339618 "2023-07-31T10:37:25Z")

</div>

Dear All, I am using the free version of Elasticsearch and i have installed it on my ubuntu. in the elasticsearch configuration file, i have set the xpack security feature to true. now am having the following error when…

---

## [Getting user id from logstash](https://discuss.elastic.co/t/getting-user-id-from-logstash/339504)

<div class="topic-metadata">

**Author:** [@frh](https://discuss.elastic.co/u/frh)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 10:01am UTC](https://discuss.elastic.co/t/getting-user-id-from-logstash/339504 "2023-07-31T10:01:29Z")

</div>

Hi, I've been trying to get this output in kibana by modifying my logstash, but to no avail. I'm not sure what went wrong. Input: User 'xxxxxx' logged in with concurrent ALM My logstash looks something like this: matc…

---

## [Maximum normal shards open achived](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 6\
**Last updated:** [July 31, 2023, 9:10am UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529 "2023-07-31T09:10:58Z")

</div>

Hello, I have one node ELK, I know that is not the best solution, but I cannot change that. I put logs to ELK, and every day I have new index for example: alerts-2023-07-23. But after few months of working filebeat showe…

---

## [Getting error when trying to run a filebeat](https://discuss.elastic.co/t/getting-error-when-trying-to-run-a-filebeat/339651)

<div class="topic-metadata">

**Author:** [@rkannan](https://discuss.elastic.co/u/rkannan)\
**Replies:** 3\
**Last updated:** [July 31, 2023, 9:00am UTC](https://discuss.elastic.co/t/getting-error-when-trying-to-run-a-filebeat/339651 "2023-07-31T09:00:36Z")

</div>

Exiting: fileset tomcat/error is configured but doesn't exist

---

## [How to add thousand of objects](https://discuss.elastic.co/t/how-to-add-thousand-of-objects/339124)

<div class="topic-metadata">

**Author:** [@senadk](https://discuss.elastic.co/u/senadk)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 8:46am UTC](https://discuss.elastic.co/t/how-to-add-thousand-of-objects/339124 "2023-07-31T08:46:08Z")

</div>

Hi everyone, Im new to Elastic and i can't find a way to add big data (read 150k SQL rows) at once to my index. Im using postman to execute the endpoints like \_bulk. What i would like is to copy my 150k rows from my S…

---

## [How to run Kibana with Ngxinx?](https://discuss.elastic.co/t/how-to-run-kibana-with-ngxinx/339557)

<div class="topic-metadata">

**Author:** [@Filip\_Drzewiecki](https://discuss.elastic.co/u/Filip_Drzewiecki)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 8:44am UTC](https://discuss.elastic.co/t/how-to-run-kibana-with-ngxinx/339557 "2023-07-31T08:44:03Z")

</div>

Hello, I have my KIbana and Elasticsearch upp and running on AKS but I'm not relying on Elastic Operator, I'm just deploying everything as I would did with docker-compose. My services are up and Kibana is running as Lo…

---

## [Multiple JDBC input for different tables and output into separate indexes](https://discuss.elastic.co/t/multiple-jdbc-input-for-different-tables-and-output-into-separate-indexes/339596)

<div class="topic-metadata">

**Author:** [@Youdeep](https://discuss.elastic.co/u/Youdeep)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 7:58am UTC](https://discuss.elastic.co/t/multiple-jdbc-input-for-different-tables-and-output-into-separate-indexes/339596 "2023-07-31T07:58:29Z")

</div>

Hello I'm new to ELK. Question - How do I use different index when importing tables from DB using logstash. I have used multiple JDBC input for different tables and separate output for each table in logstash. Logstash s…

---

## [\[o.e.t.TransportService\] Received response for a request that has timed out](https://discuss.elastic.co/t/o-e-t-transportservice-received-response-for-a-request-that-has-timed-out/339056)

<div class="topic-metadata">

**Author:** [@EVINDX](https://discuss.elastic.co/u/EVINDX)\
**Replies:** 16\
**Last updated:** [July 31, 2023, 7:54am UTC](https://discuss.elastic.co/t/o-e-t-transportservice-received-response-for-a-request-that-has-timed-out/339056 "2023-07-31T07:54:54Z")

</div>

We are receiving the following error {ElasticsearchLogger} \[o.e.t.TransportService\] Received response for a request that has timed out, sent \[21.3s/21361ms\] ago, timed out \[5.6s/5682ms\] ago, action \[indices:monitor/stat…

---

## [How to visualize user login](https://discuss.elastic.co/t/how-to-visualize-user-login/339280)

<div class="topic-metadata">

**Author:** [@frh](https://discuss.elastic.co/u/frh)\
**Replies:** 3\
**Last updated:** [July 31, 2023, 7:50am UTC](https://discuss.elastic.co/t/how-to-visualize-user-login/339280 "2023-07-31T07:50:38Z")

</div>

Hi, I'm trying to figure out the number of user logins in certain instance. The reason being is I want to see how many users have logged in to instance ABC and who are the users logged in to instance ABC. Thank you.

---

## [How to forward ALL logs](https://discuss.elastic.co/t/how-to-forward-all-logs/339653)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 7:20am UTC](https://discuss.elastic.co/t/how-to-forward-all-logs/339653 "2023-07-31T07:20:41Z")

</div>

I have the following logstash configuration file that successfully sends information to a third party location. Effectively what i am asking is, how do i constantly send ALL the data going into elastic to this third par…

---

## [Does ES security settings "xpack.security.transport.filter.allow" conflict with eBPF program?](https://discuss.elastic.co/t/does-es-security-settings-xpack-security-transport-filter-allow-conflict-with-ebpf-program/339652)

<div class="topic-metadata">

**Author:** [@Michael\_K\_Aboagye](https://discuss.elastic.co/u/Michael_K_Aboagye)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 7:17am UTC](https://discuss.elastic.co/t/does-es-security-settings-xpack-security-transport-filter-allow-conflict-with-ebpf-program/339652 "2023-07-31T07:17:23Z")

</div>

ES documentation states that developers/admins can filter IP addresses at the transport layer via this parameter: xpack.security.transport.filter.allow . So let's assume I have configured the parameter xpack.security.t…

---

## [Logstash querying elasticsearch timeout error](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 4\
**Last updated:** [July 31, 2023, 7:09am UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085 "2023-07-31T07:09:33Z")

</div>

Hello, I have the following error; just seeing if anyone knows where i am setting this? i originally put the timeout setting in the testpipeline.conf for logstash. Any help is greatly appreciated \[2023-07-24T11:59:41,3…

---

## [Auto authentication of user in python application](https://discuss.elastic.co/t/auto-authentication-of-user-in-python-application/339648)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 6:50am UTC](https://discuss.elastic.co/t/auto-authentication-of-user-in-python-application/339648 "2023-07-31T06:50:59Z")

</div>

Hi team, I have my django application in which I am rendering iframed Kibana dashboard. If am log in django application at same time log in iframed Kibana dashboard as well, it won't log in again in Kibana dashboard. S…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=464)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=466)
