# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=466

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 467

---

## [Elasticsearch Memory Utilization](https://discuss.elastic.co/t/elasticsearch-memory-utilization/338928)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 8\
**Last updated:** [July 31, 2023, 6:31am UTC](https://discuss.elastic.co/t/elasticsearch-memory-utilization/338928 "2023-07-31T06:31:44Z")

</div>

Hi Team, I am new to the Elasticsearch world. I had installed the Elasticsearch in one of my lab VM, where it is showing memory utilization is 8.3 GB when I check "systemctl status elasticsearch" and VM gets hang. Is t…

---

## [Visualization showing both metrics and overall status](https://discuss.elastic.co/t/visualization-showing-both-metrics-and-overall-status/339496)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 3\
**Last updated:** [July 31, 2023, 5:07am UTC](https://discuss.elastic.co/t/visualization-showing-both-metrics-and-overall-status/339496 "2023-07-31T05:07:01Z")

</div>

Is something like below visualization possible in kibana?

---

## [Group By Datetime fields While querying](https://discuss.elastic.co/t/group-by-datetime-fields-while-querying/339639)

<div class="topic-metadata">

**Author:** [@cybercom](https://discuss.elastic.co/u/cybercom)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 4:03am UTC](https://discuss.elastic.co/t/group-by-datetime-fields-while-querying/339639 "2023-07-31T04:03:12Z")

</div>

I need to group by day in my query, so i'm trying to apply group by with datetime field as below: { "\_source": "false", "query": { "match\_all": {} }, "aggs": { "group\_by\_weekday": { …

---

## [Rename nested field in Logstash using Ruby filter](https://discuss.elastic.co/t/rename-nested-field-in-logstash-using-ruby-filter/339637)

<div class="topic-metadata">

**Author:** [@mario\_kazela](https://discuss.elastic.co/u/mario_kazela)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 3:57am UTC](https://discuss.elastic.co/t/rename-nested-field-in-logstash-using-ruby-filter/339637 "2023-07-31T03:57:52Z")

</div>

Hi, I have some issues with rename a nested field in json. Example of nested field: test\_results.result.legacy.entities.user\_mentions.name then i want to rename it to displayname I have try this method, but unfortuna…

---

## [Pipeline Fail, failed to load pipeline. Error: Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"input\\", \\"filter\\", \\"output\\" at line 21](https://discuss.elastic.co/t/pipeline-fail-failed-to-load-pipeline-error-expected-one-of-t-r-n-input-filter-output-at-line-21/339615)

<div class="topic-metadata">

**Author:** [@Youdeep](https://discuss.elastic.co/u/Youdeep)\
**Replies:** 3\
**Last updated:** [July 31, 2023, 12:05am UTC](https://discuss.elastic.co/t/pipeline-fail-failed-to-load-pipeline-error-expected-one-of-t-r-n-input-filter-output-at-line-21/339615 "2023-07-31T00:05:17Z")

</div>

Running a pipeline with two config file: Error after running: logstash -f .\\config\\pipelines.yml Error: \[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_i…

---

## [Issues configuring SSL TCP Syslog Collection - Palo Alto Integration](https://discuss.elastic.co/t/issues-configuring-ssl-tcp-syslog-collection-palo-alto-integration/339572)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 8\
**Last updated:** [July 30, 2023, 6:01pm UTC](https://discuss.elastic.co/t/issues-configuring-ssl-tcp-syslog-collection-palo-alto-integration/339572 "2023-07-30T18:01:35Z")

</div>

I am new to the Elastic ecosystem and looking for assistance...trying to configure tcp SSL collection for palo logs from cortex datalake... this cert worked fine with our previous solution so I know nothing is wrong with…

---

## [Kibana Task Manager (KTM) not reporting accurate observed Kibana instances values](https://discuss.elastic.co/t/kibana-task-manager-ktm-not-reporting-accurate-observed-kibana-instances-values/339624)

<div class="topic-metadata">

**Author:** [@JGreene](https://discuss.elastic.co/u/JGreene)\
**Replies:** 0\
**Last updated:** [July 30, 2023, 4:48pm UTC](https://discuss.elastic.co/t/kibana-task-manager-ktm-not-reporting-accurate-observed-kibana-instances-values/339624 "2023-07-30T16:48:50Z")

</div>

Hello, Looking for guidance on troubleshooting Kibana Task Manager reporting "observed":{"observed\_kibana\_instances":1 when there are 12 instances in total. Other clusters (7.16.X) report their total Kibana instances a…

---

## [Does fscrawler support opensearch?](https://discuss.elastic.co/t/does-fscrawler-support-opensearch/339613)

<div class="topic-metadata">

**Author:** [@nadiGam](https://discuss.elastic.co/u/nadiGam)\
**Replies:** 2\
**Last updated:** [July 30, 2023, 3:26pm UTC](https://discuss.elastic.co/t/does-fscrawler-support-opensearch/339613 "2023-07-30T15:26:37Z")

</div>

---

## [Kafka Integration Installation Error - "Limit of total dimension fields \[16\] has been exceeded"](https://discuss.elastic.co/t/kafka-integration-installation-error-limit-of-total-dimension-fields-16-has-been-exceeded/339052)

<div class="topic-metadata">

**Author:** [@Moaath](https://discuss.elastic.co/u/Moaath)\
**Replies:** 9\
**Last updated:** [July 30, 2023, 6:46am UTC](https://discuss.elastic.co/t/kafka-integration-installation-error-limit-of-total-dimension-fields-16-has-been-exceeded/339052 "2023-07-30T06:46:29Z")

</div>

Hi Everyone, I am currently trying to install the Kafka integration via the Fleet UI in Kibana, but I've encountered an issue that I hope someone can shed some light on. The error message I'm receiving is as follows: E…

---

## [Split type failure Logstash](https://discuss.elastic.co/t/split-type-failure-logstash/339594)

<div class="topic-metadata">

**Author:** [@Bharat\_Lahori](https://discuss.elastic.co/u/Bharat_Lahori)\
**Replies:** 2\
**Last updated:** [July 29, 2023, 5:58pm UTC](https://discuss.elastic.co/t/split-type-failure-logstash/339594 "2023-07-29T17:58:16Z")

</div>

Dear Team, I have configured below logstash conf file . Trying to give stdin input and getting an error as split type failure. PFB details. We need to create two events based on metricValues. Conf file input { stdi…

---

## [Data storage location for elasticseach on docker](https://discuss.elastic.co/t/data-storage-location-for-elasticseach-on-docker/339602)

<div class="topic-metadata">

**Author:** [@Mataz](https://discuss.elastic.co/u/Mataz)\
**Replies:** 1\
**Last updated:** [July 29, 2023, 5:47pm UTC](https://discuss.elastic.co/t/data-storage-location-for-elasticseach-on-docker/339602 "2023-07-29T17:47:31Z")

</div>

I am trying to install elasticsearch for docker but I got stuck with configuring the data storage location for the logs collected from the log aggregators coming to elasticsearch. Basically I need to store the data on th…

---

## [Add alias to existing indices (and newly created indices) using Kibana UI](https://discuss.elastic.co/t/add-alias-to-existing-indices-and-newly-created-indices-using-kibana-ui/339147)

<div class="topic-metadata">

**Author:** [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Replies:** 3\
**Last updated:** [July 29, 2023, 2:54am UTC](https://discuss.elastic.co/t/add-alias-to-existing-indices-and-newly-created-indices-using-kibana-ui/339147 "2023-07-29T02:54:27Z")

</div>

I've set up an EFK stack on my Kubernetes cluster. I want to automatically delete indices after certain days later (i.e., log retention and rotation), so I've created an index lifecycle policy. The policy's name is dele…

---

## [Simple Anomaly Detection Question](https://discuss.elastic.co/t/simple-anomaly-detection-question/339580)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 29, 2023, 1:01am UTC](https://discuss.elastic.co/t/simple-anomaly-detection-question/339580 "2023-07-29T01:01:04Z")

</div>

Hi all. I'm a newbie at Anomaly Detection. Let's say I have a key, "PET", with two possible values, "CAT" and "DOG". I want to detect when there are an unusual number of CATs in an hour. Is that possible? I thought …

---

## [Logstash Json Parsing Error](https://discuss.elastic.co/t/logstash-json-parsing-error/339515)

<div class="topic-metadata">

**Author:** [@fizem](https://discuss.elastic.co/u/fizem)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 9:03pm UTC](https://discuss.elastic.co/t/logstash-json-parsing-error/339515 "2023-07-28T21:03:46Z")

</div>

Hi, I have setup the following pipeline to consolidate my logs in Elastic Search Cluster : filebeat to gather nginx logs ==\> logstash to parse the log and mutate them if needed ==\> Elasticsearch cluster. I'm facing an…

---

## [How to validate a json value is numeric](https://discuss.elastic.co/t/how-to-validate-a-json-value-is-numeric/339562)

<div class="topic-metadata">

**Author:** [@sc5283](https://discuss.elastic.co/u/sc5283)\
**Replies:** 4\
**Last updated:** [July 28, 2023, 9:01pm UTC](https://discuss.elastic.co/t/how-to-validate-a-json-value-is-numeric/339562 "2023-07-28T21:01:27Z")

</div>

noob question I have a JSON as follows: {"attr1":"One", "attr2":"300"} {"attr1":"Two","attr2":45.0} {"attr1":"Three","attr2":"Not Set"} attr2 is a numeric value How do I check if attr2 is numeric, not a string befo…

---

## [.NET client connect to elastic search using SSL](https://discuss.elastic.co/t/net-client-connect-to-elastic-search-using-ssl/339554)

<div class="topic-metadata">

**Author:** [@Nilesh\_Jethwani](https://discuss.elastic.co/u/Nilesh_Jethwani)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 1:43pm UTC](https://discuss.elastic.co/t/net-client-connect-to-elastic-search-using-ssl/339554 "2023-07-28T13:43:53Z")

</div>

We want to connect our .NET application to elasticsearch 8.5.2 single node cluster. We want to use https and ssl communication. We have 3 certificates from our CA. root , intermediate and main along with private key. …

---

## [Phrase suggester giving suggestion on correct terms containing number values](https://discuss.elastic.co/t/phrase-suggester-giving-suggestion-on-correct-terms-containing-number-values/339579)

<div class="topic-metadata">

**Author:** [@Pavithra2014](https://discuss.elastic.co/u/Pavithra2014)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 6:14pm UTC](https://discuss.elastic.co/t/phrase-suggester-giving-suggestion-on-correct-terms-containing-number-values/339579 "2023-07-28T18:14:33Z")

</div>

Team, We are using Phrase suggestion with below configuration. but this is returning suggestion on correct speeled words having numeric values on it. eg: Product 2023 is giving the suggestion Product 2022 . I'm expect…

---

## [I want send a duplicate or clone of my data throught logstash to another kibana/elastic adminitrador](https://discuss.elastic.co/t/i-want-send-a-duplicate-or-clone-of-my-data-throught-logstash-to-another-kibana-elastic-adminitrador/339228)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 3\
**Last updated:** [July 28, 2023, 5:10pm UTC](https://discuss.elastic.co/t/i-want-send-a-duplicate-or-clone-of-my-data-throught-logstash-to-another-kibana-elastic-adminitrador/339228 "2023-07-28T17:10:56Z")

</div>

how could i duplicate the data or send de same data to another elastic, the logstash version is 7.17 while elastic version where i want to receive is 8.8.2, i try with the output configuration but i received this err…

---

## [Is it possible to for winlogbeat to send original raw logs?](https://discuss.elastic.co/t/is-it-possible-to-for-winlogbeat-to-send-original-raw-logs/339559)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 4:37pm UTC](https://discuss.elastic.co/t/is-it-possible-to-for-winlogbeat-to-send-original-raw-logs/339559 "2023-07-28T16:37:54Z")

</div>

For management reasons I need to ask: Is it possible to send the raw windows log (xml or text uncooked) via winlogbeat? Thanks

---

## [Sharing dashboard link publically in an iframe](https://discuss.elastic.co/t/sharing-dashboard-link-publically-in-an-iframe/339570)

<div class="topic-metadata">

**Author:** [@Mitali\_Surwase](https://discuss.elastic.co/u/Mitali_Surwase)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 4:12pm UTC](https://discuss.elastic.co/t/sharing-dashboard-link-publically-in-an-iframe/339570 "2023-07-28T16:12:24Z")

</div>

I want to share the dashboard link to the front end to show the dashboard on the angular ./net application and give the link in the form of iframe. I want the dashboard to be seen to everyone publically without login , s…

---

## [Validate document before sending to elasticsearch](https://discuss.elastic.co/t/validate-document-before-sending-to-elasticsearch/337859)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/validate-document-before-sending-to-elasticsearch/337859 "2023-07-28T15:19:00Z")

</div>

Hi, I have a strict mapping in my ES cluster and send documents via Logstash, sometimes the documents get dropped because they don't conform the strict mapping, is there a way to check if the document conforms or not to…

---

## [Translation does not work in Logged Out Page and Apply Filters in Unified Search](https://discuss.elastic.co/t/translation-does-not-work-in-logged-out-page-and-apply-filters-in-unified-search/338341)

<div class="topic-metadata">

**Author:** [@wsbr](https://discuss.elastic.co/u/wsbr)\
**Replies:** 8\
**Last updated:** [July 28, 2023, 3:12pm UTC](https://discuss.elastic.co/t/translation-does-not-work-in-logged-out-page-and-apply-filters-in-unified-search/338341 "2023-07-28T15:12:11Z")

</div>

Hi, We are using Elasticsearch 8.7.1 and some actions does not be translated. How to solve this problem?

---

## [How to use the JSON filter correctly?](https://discuss.elastic.co/t/how-to-use-the-json-filter-correctly/339372)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 13\
**Last updated:** [July 28, 2023, 2:27pm UTC](https://discuss.elastic.co/t/how-to-use-the-json-filter-correctly/339372 "2023-07-28T14:27:51Z")

</div>

Application logs is of below JSON format and I'm unsure what should be the source field incase I'm using the JSON filter ? I would like to have all the fields appear on the Kibana output, particularly the message field,…

---

## [Kibana login problem](https://discuss.elastic.co/t/kibana-login-problem/339538)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Replies:** 3\
**Last updated:** [July 28, 2023, 2:20pm UTC](https://discuss.elastic.co/t/kibana-login-problem/339538 "2023-07-28T14:20:36Z")

</div>

Hi all We are experiencing a problem when trying to login kibana 8.8.2, I could't find anythink, does anybody has an idea? thanks

---

## [Pass min\_score to shoudl close](https://discuss.elastic.co/t/pass-min-score-to-shoudl-close/339561)

<div class="topic-metadata">

**Author:** [@john\_nicolas](https://discuss.elastic.co/u/john_nicolas)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 2:16pm UTC](https://discuss.elastic.co/t/pass-min-score-to-shoudl-close/339561 "2023-07-28T14:16:43Z")

</div>

i want to pass a min\_score but for only should clauses, i want filter should clause by min\_score to eliminate docs which have cosinesimilarity poor {'bool': {'filter': {'term': {'hidden': 'false'}}, 'must': \[{'bool': {'…

---

## [Can I reindex using a search template?](https://discuss.elastic.co/t/can-i-reindex-using-a-search-template/339556)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 2:03pm UTC](https://discuss.elastic.co/t/can-i-reindex-using-a-search-template/339556 "2023-07-28T14:03:14Z")

</div>

Would it be possible to use the \_reindex but instead of specifying the query, call a search template stored?

---

## [How to take the fleet server backup](https://discuss.elastic.co/t/how-to-take-the-fleet-server-backup/339068)

<div class="topic-metadata">

**Author:** [@ankitha\_sn](https://discuss.elastic.co/u/ankitha_sn)\
**Replies:** 13\
**Last updated:** [July 28, 2023, 1:51pm UTC](https://discuss.elastic.co/t/how-to-take-the-fleet-server-backup/339068 "2023-07-28T13:51:58Z")

</div>

Hi Team, Can I know how to take the backup of the fleet server? I have looked into the documentation and did not find any useful links. Thanks, Ankitha

---

## [Kibana is using 'anonymus\_access' instead of kibana\_system username](https://discuss.elastic.co/t/kibana-is-using-anonymus-access-instead-of-kibana-system-username/339544)

<div class="topic-metadata">

**Author:** [@Filip\_Drzewiecki](https://discuss.elastic.co/u/Filip_Drzewiecki)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 1:27pm UTC](https://discuss.elastic.co/t/kibana-is-using-anonymus-access-instead-of-kibana-system-username/339544 "2023-07-28T13:27:26Z")

</div>

Hello everyone, First, let me say that I'm quite new to the ELK but I've tried my best to solve that issue myself. I'm trying to migrate my ELK stack from docker-compose to kubernetes (so I'm not using elastic operator…

---

## [Could not push logs to Elasticsearch cluster](https://discuss.elastic.co/t/could-not-push-logs-to-elasticsearch-cluster/339488)

<div class="topic-metadata">

**Author:** [@Vikas1633](https://discuss.elastic.co/u/Vikas1633)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 1:16pm UTC](https://discuss.elastic.co/t/could-not-push-logs-to-elasticsearch-cluster/339488 "2023-07-28T13:16:04Z")

</div>

I am facing issue could not push logs to Elasticsearch cluster but when i change the buffer path and restart elastic it gets solved and every odd day I have to do this, looking for some permanent solution over this. :El…

---

## [Filebeat only sends the first log input](https://discuss.elastic.co/t/filebeat-only-sends-the-first-log-input/339549)

<div class="topic-metadata">

**Author:** [@dcz01](https://discuss.elastic.co/u/dcz01)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-only-sends-the-first-log-input/339549 "2023-07-28T13:09:37Z")

</div>

Hello, I got an filebeat.yml with an filebeat 7.8.0 instance on an server which should send some logs to a central logstash but it only sends the first log input and the others seemd to be ignored or anything else. Can…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=465)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=467)
