# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=475

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 476

---

## [Painless script - percentage calculation - returns 0 always due to decimals](https://discuss.elastic.co/t/painless-script-percentage-calculation-returns-0-always-due-to-decimals/338875)

<div class="topic-metadata">

**Author:** [@Jayakrishna\_Manokara](https://discuss.elastic.co/u/Jayakrishna_Manokara)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 12:08pm UTC](https://discuss.elastic.co/t/painless-script-percentage-calculation-returns-0-always-due-to-decimals/338875 "2023-07-20T12:08:50Z")

</div>

Hi, I am trying to calculate percentage. "script": { "source": """ return \[ ctx.payload.first.aggregations.success\_count.doc\_count / (ctx.payload.first.aggregations.success\_count.doc\_count + ctx.payload.first.aggrega…

---

## [ElasticSearch Index Storage Optimization - Firewall Logs](https://discuss.elastic.co/t/elasticsearch-index-storage-optimization-firewall-logs/338410)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 9\
**Last updated:** [July 20, 2023, 11:51am UTC](https://discuss.elastic.co/t/elasticsearch-index-storage-optimization-firewall-logs/338410 "2023-07-20T11:51:59Z")

</div>

We are running a 3 node cluster to index logs from a firewall. The nodes are physical machines (20 Core CPUs, 16GB RAM, SSD Storage). Each days logs are stored in an individual index. The storage utilized per index wor…

---

## [Field loss occurs when making a runtime field](https://discuss.elastic.co/t/field-loss-occurs-when-making-a-runtime-field/338658)

<div class="topic-metadata">

**Author:** [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 10:58am UTC](https://discuss.elastic.co/t/field-loss-occurs-when-making-a-runtime-field/338658 "2023-07-20T10:58:30Z")

</div>

IF agent(original) field exists, the copy field must also exist. However it often happens that there is an agent field but no copy field. Has anyone experienced the same problem?

---

## [Show documents with a last value greater than a number and drop all other documents from the selection](https://discuss.elastic.co/t/show-documents-with-a-last-value-greater-than-a-number-and-drop-all-other-documents-from-the-selection/338783)

<div class="topic-metadata">

**Author:** [@zafire](https://discuss.elastic.co/u/zafire)\
**Replies:** 3\
**Last updated:** [July 20, 2023, 10:42am UTC](https://discuss.elastic.co/t/show-documents-with-a-last-value-greater-than-a-number-and-drop-all-other-documents-from-the-selection/338783 "2023-07-20T10:42:03Z")

</div>

Hi all. First post here, so hope I am doing it right. I have an index of servers and mounted disks (from metricbeat) that has a percent used value, system.filesystem.used.pct and system.filesystem.mount\_point. I want …

---

## [Multi-cluster installation, cluster loss and recovery](https://discuss.elastic.co/t/multi-cluster-installation-cluster-loss-and-recovery/338858)

<div class="topic-metadata">

**Author:** [@Christophe\_DAME](https://discuss.elastic.co/u/Christophe_DAME)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 10:00am UTC](https://discuss.elastic.co/t/multi-cluster-installation-cluster-loss-and-recovery/338858 "2023-07-20T10:00:13Z")

</div>

Hi there, As I'm new, I'll introduce myself quickly : I'm Christophe Dame and I'm working for Camunda. Our solution embarks an Elasticsearch 7.17 and I'm currently experimenting a dual cluster setup. Ideally, my goal w…

---

## [How to check if the index was merged or not](https://discuss.elastic.co/t/how-to-check-if-the-index-was-merged-or-not/338866)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 9:33am UTC](https://discuss.elastic.co/t/how-to-check-if-the-index-was-merged-or-not/338866 "2023-07-20T09:33:27Z")

</div>

Hi there, from this discuss, i know that elastic will check continuously to see if the index needs merging or not. but what parameter i can check, so i can makesure that the index was merged. is that by using this API? …

---

## [What setting is used for filebeat for compression?, like logstash uses:http\_compression =\> true](https://discuss.elastic.co/t/what-setting-is-used-for-filebeat-for-compression-like-logstash-uses-http-compression-true/338854)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 8:29am UTC](https://discuss.elastic.co/t/what-setting-is-used-for-filebeat-for-compression-like-logstash-uses-http-compression-true/338854 "2023-07-20T08:29:37Z")

</div>

Hello All, I'd like to know what settings must be used in filebeat for compression?. In logs i get bulk size issue sometimes.Assuming compression srtting might resolve this like in logstash has http\_compression =\> true…

---

## ["cluster.routing.allocation.enable": "primaries"](https://discuss.elastic.co/t/cluster-routing-allocation-enable-primaries/338855)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 7:58am UTC](https://discuss.elastic.co/t/cluster-routing-allocation-enable-primaries/338855 "2023-07-20T07:58:33Z")

</div>

Hi Team, "cluster.routing.allocation.enable": "primaries" In reality does it mean which ever primaries Node is unavailable the cluster will turn its related replica to become primary in that same replica node. There is…

---

## [Kibana Control With Static options](https://discuss.elastic.co/t/kibana-control-with-static-options/338824)

<div class="topic-metadata">

**Author:** [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 6:45am UTC](https://discuss.elastic.co/t/kibana-control-with-static-options/338824 "2023-07-20T06:45:35Z")

</div>

Hello! I have a dashboard and would like to add a dropdown field with static options (to make it easier for users to select only what they need). It's possible? If yes, how can I do it? Tks in advance.

---

## [Bypass Login Page](https://discuss.elastic.co/t/bypass-login-page/337047)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 6:39am UTC](https://discuss.elastic.co/t/bypass-login-page/337047 "2023-07-20T06:39:26Z")

</div>

I want to bypass this login page Can i pass username and password through URL

---

## [Remove "Create visualization" Tab from Kibana Dashbord iframe code](https://discuss.elastic.co/t/remove-create-visualization-tab-from-kibana-dashbord-iframe-code/338746)

<div class="topic-metadata">

**Author:** [@Sayed\_Aktar](https://discuss.elastic.co/u/Sayed_Aktar)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 6:11am UTC](https://discuss.elastic.co/t/remove-create-visualization-tab-from-kibana-dashbord-iframe-code/338746 "2023-07-20T06:11:39Z")

</div>

Hello! I have created a kibana dashboard with my custom datasets. Now if I copy the iframe embed code it also contain the "Create visualization", "All types(Dropdown)", "Add from Library" tabs. I want to remove these tab…

---

## [Elasticsearch Cluster Yellow - Index Allocation "No Attempt"](https://discuss.elastic.co/t/elasticsearch-cluster-yellow-index-allocation-no-attempt/338492)

<div class="topic-metadata">

**Author:** [@ChestoOfGlen](https://discuss.elastic.co/u/ChestoOfGlen)\
**Replies:** 5\
**Last updated:** [July 20, 2023, 5:45am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-yellow-index-allocation-no-attempt/338492 "2023-07-20T05:45:49Z")

</div>

We are running several Elasticsearch clusters (v8.8.1) in Kubernetes (AWS EKS on v1.25) via Elastic Cloud on Kubernetes (ECK v2.8). We've had several of the clusters, after a high CPU load event on the K8s workers, not …

---

## [Fluentd doesnt send log to elasticsearch](https://discuss.elastic.co/t/fluentd-doesnt-send-log-to-elasticsearch/337619)

<div class="topic-metadata">

**Author:** [@gurban.suleyman](https://discuss.elastic.co/u/gurban.suleyman)\
**Replies:** 6\
**Last updated:** [July 20, 2023, 5:30am UTC](https://discuss.elastic.co/t/fluentd-doesnt-send-log-to-elasticsearch/337619 "2023-07-20T05:30:48Z")

</div>

Hi I have a problem it is about to send logs to elasticsearch. I had configure the conf file ind the server but in elastic i couldnt see any log even in the Discover menu

---

## [Combining 3 logs into one](https://discuss.elastic.co/t/combining-3-logs-into-one/338832)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:18am UTC](https://discuss.elastic.co/t/combining-3-logs-into-one/338832 "2023-07-20T02:18:15Z")

</div>

I have this 3 events logs that are almost the same. I want to combine the 3 events logs into one log but somehow it won't work. this is my filter aggregate { task\_id =\> "%{\_id}" code =\> " …

---

## [Kibana server is not ready yet kibana.service: Main process exited, code=exited, status=1/FAILURE](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-kibana-service-main-process-exited-code-exited-status-1-failure/338835)

<div class="topic-metadata">

**Author:** [@Tom\_Ferguson](https://discuss.elastic.co/u/Tom_Ferguson)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 1:44am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-kibana-service-main-process-exited-code-exited-status-1-failure/338835 "2023-07-20T01:44:17Z")

</div>

Sorry if this post is repetitive, I did look for this issue and did not see an answer that worked for me. I realize this could turn out to be something fairly simple or even an OSI level 8 error. I can't imaging that I …

---

## [Winlogbeat 8.6 process fields not populated](https://discuss.elastic.co/t/winlogbeat-8-6-process-fields-not-populated/338753)

<div class="topic-metadata">

**Author:** [@stanley783](https://discuss.elastic.co/u/stanley783)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:37am UTC](https://discuss.elastic.co/t/winlogbeat-8-6-process-fields-not-populated/338753 "2023-07-20T01:37:08Z")

</div>

Hi, until now using winlogbeat 7.X, tried winlogbeat 8.6.1 but agent does not parse/populate process.XXX fields anymore, it only uses fields in winlog.event\_data.XXX instead. Is there any easy obvious solution, instead …

---

## [Regarding disk expansion for Elasticsearch Cluster](https://discuss.elastic.co/t/regarding-disk-expansion-for-elasticsearch-cluster/338838)

<div class="topic-metadata">

**Author:** [@klose.foot.baller](https://discuss.elastic.co/u/klose.foot.baller)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 1:30am UTC](https://discuss.elastic.co/t/regarding-disk-expansion-for-elasticsearch-cluster/338838 "2023-07-20T01:30:25Z")

</div>

Hi, We currently have an Elasticsearch (version 6.5) cluster with 3 Azure Virtual Machines. Disk space is getting tight and we would like to improve the situation, but we are wondering what is the best approach to take…

---

## [Output set by field](https://discuss.elastic.co/t/output-set-by-field/338748)

<div class="topic-metadata">

**Author:** [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 1:29am UTC](https://discuss.elastic.co/t/output-set-by-field/338748 "2023-07-20T01:29:02Z")

</div>

Hi Guys, set logstash output influxdb, as title can out by field. output part like output { influxdb\_v2 { host =\> "10.200.101.18" port =\> "8086" org =\> "icep" token =\> "SIRq-QX3d7ddOI33Z9XfmZETHHGAFj…

---

## [Beats release docs for 8.6.2 missing](https://discuss.elastic.co/t/beats-release-docs-for-8-6-2-missing/329335)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 12:31am UTC](https://discuss.elastic.co/t/beats-release-docs-for-8-6-2-missing/329335 "2023-07-20T00:31:50Z")

</div>

After last release 8.7.0 notes for 8.6.2 missing and 8.6.1 present. Can you fix it?

---

## [Size reduction after re-indexing from v7 to v8](https://discuss.elastic.co/t/size-reduction-after-re-indexing-from-v7-to-v8/338833)

<div class="topic-metadata">

**Author:** [@Ian\_Simpson](https://discuss.elastic.co/u/Ian_Simpson)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 12:24am UTC](https://discuss.elastic.co/t/size-reduction-after-re-indexing-from-v7-to-v8/338833 "2023-07-20T00:24:27Z")

</div>

I'm migrating from a v7.17.10 cluster to v8.8.2 using the reindex API. I'm seeing that some indices with data from ingested files (docx, pdf mostly) only take up 5% of the space that they used to. I've done a little spot…

---

## [Role based Control](https://discuss.elastic.co/t/role-based-control/338825)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 10:50pm UTC](https://discuss.elastic.co/t/role-based-control/338825 "2023-07-19T22:50:11Z")

</div>

Hi, I am running a Basic version ELK. I am trying to make a role-based user profile in Kibana. I can see from the subscription page that it is available in the free version as well but when I try to navigate to "Stack M…

---

## [Configurar 3 master nodos sin datos solo maestros? en la version 8.8?](https://discuss.elastic.co/t/configurar-3-master-nodos-sin-datos-solo-maestros-en-la-version-8-8/338829)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 9:36pm UTC](https://discuss.elastic.co/t/configurar-3-master-nodos-sin-datos-solo-maestros-en-la-version-8-8/338829 "2023-07-19T21:36:18Z")

</div>

estoy configurando un cluster con 3 nodos masestros la seguridad ya la tengo cubierta pero cuando inicializo me quedan 3 nodos master con data y 4 nodos de datos necesito que 3 sean dedicados master sin data y todos los…

---

## [Ingest Pipelines - illegal\_argument\_exception reason field not present as part of path](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267)

<div class="topic-metadata">

**Author:** [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Replies:** 3\
**Last updated:** [July 19, 2023, 8:23pm UTC](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267 "2023-07-19T20:23:09Z")

</div>

Hi I trying apply a ingest pipeline into a datastream. I'm using logstash to send to datastream, this datastream has a mapping: { "template": { "mappings": { "properties": { "@…

---

## [Kibana Visualization Regex Exclusion issue](https://discuss.elastic.co/t/kibana-visualization-regex-exclusion-issue/338695)

<div class="topic-metadata">

**Author:** [@turboz](https://discuss.elastic.co/u/turboz)\
**Replies:** 4\
**Last updated:** [July 19, 2023, 7:14pm UTC](https://discuss.elastic.co/t/kibana-visualization-regex-exclusion-issue/338695 "2023-07-19T19:14:30Z")

</div>

I'm trying to create a table that shows the top 5 source IPs, but only public IPs. I notice there is an advanced section with "Exclude values" I turned on regex and put in the following regex. /(^127\\.)|(^10\\.)|(^172\\.…

---

## ["Watcher" is not showing in Kibana Version 8.6.2](https://discuss.elastic.co/t/watcher-is-not-showing-in-kibana-version-8-6-2/338725)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 6:32pm UTC](https://discuss.elastic.co/t/watcher-is-not-showing-in-kibana-version-8-6-2/338725 "2023-07-19T18:32:37Z")

</div>

Hi, I am using ELK 8.6.2. Till last week, I have the "Watcher" tab in the 'Alerts and Insights' inside the "Stack Management" menu. Can you guide me that how it can be restored back?

---

## [Segregating data sent from Elastic-Agents or Beats to a Specified Index](https://discuss.elastic.co/t/segregating-data-sent-from-elastic-agents-or-beats-to-a-specified-index/338811)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 5:32pm UTC](https://discuss.elastic.co/t/segregating-data-sent-from-elastic-agents-or-beats-to-a-specified-index/338811 "2023-07-19T17:32:47Z")

</div>

Hello, I'm ingesting data from multiple systems and different system owners. I have multi-tenancy set up using Kibana spaces and roles, but all of the data is being sent to a single index. I would like to store my data …

---

## [Query indices on cold node?](https://discuss.elastic.co/t/query-indices-on-cold-node/338810)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 4:49pm UTC](https://discuss.elastic.co/t/query-indices-on-cold-node/338810 "2023-07-19T16:49:06Z")

</div>

I am trying to see if there is a straight forward way to query indices that are located on the "cold" node and to get a list of those indices, is there a straight forward way to do that in Elasticsearch? I presume I can …

---

## [Group data By 5 minutes using sql query in elastic](https://discuss.elastic.co/t/group-data-by-5-minutes-using-sql-query-in-elastic/338754)

<div class="topic-metadata">

**Author:** [@leonid\_fayngold](https://discuss.elastic.co/u/leonid_fayngold)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 4:03pm UTC](https://discuss.elastic.co/t/group-data-by-5-minutes-using-sql-query-in-elastic/338754 "2023-07-19T16:03:48Z")

</div>

how can I group data By 5 minutes using SQL query in elastic

---

## ["The connection is broken and recovery is not possible" after MSSQL reboot](https://discuss.elastic.co/t/the-connection-is-broken-and-recovery-is-not-possible-after-mssql-reboot/338793)

<div class="topic-metadata">

**Author:** [@mr18](https://discuss.elastic.co/u/mr18)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 4:02pm UTC](https://discuss.elastic.co/t/the-connection-is-broken-and-recovery-is-not-possible-after-mssql-reboot/338793 "2023-07-19T16:02:50Z")

</div>

Hi all ! I use a jdbc input plugin to get MS SQL data. Everything works fine, but when my SQL server reboots for maintenance, the queries don't work anymore, and I have the following error: \[ERROR\]\[logstash.inputs.jdb…

---

## [Upgrade Query DSL version 7, a version 8](https://discuss.elastic.co/t/upgrade-query-dsl-version-7-a-version-8/338799)

<div class="topic-metadata">

**Author:** [@Miguel\_Martinez](https://discuss.elastic.co/u/Miguel_Martinez)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 3:58pm UTC](https://discuss.elastic.co/t/upgrade-query-dsl-version-7-a-version-8/338799 "2023-07-19T15:58:38Z")

</div>

Hello, I have several DSL queries in version 7 of elasticsearch but I updated to version 8 but the queries are not working for me, I was looking at a query and in version 7 the eventtime is written like this but in versi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=474)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=476)
