# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=484

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 485

---

## [Provide values to the ctx.vars variables in the Painless file by extracting them from the YAML file](https://discuss.elastic.co/t/provide-values-to-the-ctx-vars-variables-in-the-painless-file-by-extracting-them-from-the-yaml-file/338172)

<div class="topic-metadata">

**Author:** [@Hardik\_Dave](https://discuss.elastic.co/u/Hardik_Dave)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 5:37am UTC](https://discuss.elastic.co/t/provide-values-to-the-ctx-vars-variables-in-the-painless-file-by-extracting-them-from-the-yaml-file/338172 "2023-07-12T05:37:24Z")

</div>

I have a .painless file as mentioned below. As of now, the ctx.vars.var1 have hardcoded values in my original file, which now need to be retrieved from a YAML file. All these files are in same project, so relative path w…

---

## [Filebeat integration with DataDog](https://discuss.elastic.co/t/filebeat-integration-with-datadog/338163)

<div class="topic-metadata">

**Author:** [@KSimon](https://discuss.elastic.co/u/KSimon)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 4:09am UTC](https://discuss.elastic.co/t/filebeat-integration-with-datadog/338163 "2023-07-12T04:09:39Z")

</div>

Hello, we have a use case to use Filebeat as a transporter of logs from one Cloud Source and feed the logs to DataDog and Kafka. There is a documentation for Kafka Output, however, there are no documentations to support…

---

## [Parsing the message field in security event.code 4624](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 11:19pm UTC](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046 "2023-07-11T23:19:14Z")

</div>

The information that I want is located under the first sub-header "Subject" and "Network Information". My basic question is this, how do I pull this information out of the Message field and display it along with the Time…

---

## [Filebeat not sending data to elasticsearch](https://discuss.elastic.co/t/filebeat-not-sending-data-to-elasticsearch/338154)

<div class="topic-metadata">

**Author:** [@gigallo](https://discuss.elastic.co/u/gigallo)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 9:46pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-data-to-elasticsearch/338154 "2023-07-11T21:46:02Z")

</div>

Hi 've installed elasticsearch 8.5 and Kibana 8.5 in my kubernetes cluster simply applying the official helm file in the elastic repo. Now I'm trying to install filebeat with the following conf: filebeat.inputs: - …

---

## [How to convert the Logstash message to fileds](https://discuss.elastic.co/t/how-to-convert-the-logstash-message-to-fileds/337910)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 15\
**Last updated:** [July 11, 2023, 9:17pm UTC](https://discuss.elastic.co/t/how-to-convert-the-logstash-message-to-fileds/337910 "2023-07-11T21:17:00Z")

</div>

Hi, I am using Logstash as a syslog server which sends data to elastic. here is the output. @timestampJul 7, 2023 @ 11:30:12.520@version1 hostname10.11.12.13 message {"proxyname":"test-123-abc","revision":"8","latency…

---

## [Forwarding logs from Sun Solaris to ELK](https://discuss.elastic.co/t/forwarding-logs-from-sun-solaris-to-elk/338147)

<div class="topic-metadata">

**Author:** [@DKalin0789e](https://discuss.elastic.co/u/DKalin0789e)\
**Replies:** 6\
**Last updated:** [July 11, 2023, 9:04pm UTC](https://discuss.elastic.co/t/forwarding-logs-from-sun-solaris-to-elk/338147 "2023-07-11T21:04:29Z")

</div>

We need to find a workaround for forwarding logs from Sun Solaris to ELK. Any ideas - very welcome! No any vendors like Logstash, Filebeat, Vector officially support Log Forwarders on Sun Solaris. Any help? Thank you.

---

## [Cannot use terms aggregation to get the field which is injest by enrich processor](https://discuss.elastic.co/t/cannot-use-terms-aggregation-to-get-the-field-which-is-injest-by-enrich-processor/336554)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 8:23pm UTC](https://discuss.elastic.co/t/cannot-use-terms-aggregation-to-get-the-field-which-is-injest-by-enrich-processor/336554 "2023-07-11T20:23:04Z")

</div>

I am trying to get the db\_tag field which is injested using injestpipeline with enrich processor, but it does not return anything even the field is existed in the doucment.

---

## [Hi Team, Do we have any radio button option in Kibana](https://discuss.elastic.co/t/hi-team-do-we-have-any-radio-button-option-in-kibana/336670)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 7:58pm UTC](https://discuss.elastic.co/t/hi-team-do-we-have-any-radio-button-option-in-kibana/336670 "2023-07-11T19:58:46Z")

</div>

Do we have any radio button option in Kibana.

---

## [ILM With Index Sorting](https://discuss.elastic.co/t/ilm-with-index-sorting/338140)

<div class="topic-metadata">

**Author:** [@Ofir\_Sudai](https://discuss.elastic.co/u/Ofir_Sudai)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 4:42pm UTC](https://discuss.elastic.co/t/ilm-with-index-sorting/338140 "2023-07-11T16:42:29Z")

</div>

Hi, We have an index the represents a feed of nft related activities (listing, bid, minted, transfer, sold, etc). The index is used to return realtime feed for users in our system so latency is a priority. The index is…

---

## [Stuck "Cancelled Tasks" In ElasticSearch 8.6.2 causing Cluster failure](https://discuss.elastic.co/t/stuck-cancelled-tasks-in-elasticsearch-8-6-2-causing-cluster-failure/337490)

<div class="topic-metadata">

**Author:** [@Thomas\_Kuisel](https://discuss.elastic.co/u/Thomas_Kuisel)\
**Replies:** 18\
**Last updated:** [July 11, 2023, 4:27pm UTC](https://discuss.elastic.co/t/stuck-cancelled-tasks-in-elasticsearch-8-6-2-causing-cluster-failure/337490 "2023-07-11T16:27:41Z")

</div>

Hi - We are using Elasticsearch 8.6.2 running on Azure AKS and noticed some serious issues lately. As of last week the week of Jun30 2023, we started noticing huge unresolved search transport queues in our cluster. The…

---

## [What if difference between setting node.roles: \["data\_hot"\] vs node.attr.box\_type: hot?](https://discuss.elastic.co/t/what-if-difference-between-setting-node-roles-data-hot-vs-node-attr-box-type-hot/337766)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 3\
**Last updated:** [July 11, 2023, 4:27pm UTC](https://discuss.elastic.co/t/what-if-difference-between-setting-node-roles-data-hot-vs-node-attr-box-type-hot/337766 "2023-07-11T16:27:15Z")

</div>

What is the difference between node.roles:\["data\_hot"\] vs node.attr.box\_type: hot.

---

## [Invalid FieldReference: \`\_Domain\_Labels\[0\]\_ULabel\`](https://discuss.elastic.co/t/invalid-fieldreference-domain-labels-0-ulabel/337016)

<div class="topic-metadata">

**Author:** [@tcapp24](https://discuss.elastic.co/u/tcapp24)\
**Replies:** 5\
**Last updated:** [July 11, 2023, 3:50pm UTC](https://discuss.elastic.co/t/invalid-fieldreference-domain-labels-0-ulabel/337016 "2023-07-11T15:50:13Z")

</div>

Logstash version - 7.17.8 Currently we are seeing invalid FieldReference errors on our Logstash nodes dealing with \_Domain\_Labels\[0\]\_ULabel onf.d/mulesoft/get\_cloudhub\_app\_logs.conf"\], :thread=\>"#\<Thread:0x1475cac0 run\>…

---

## [Metricbeat and Heartbeat 8.x custom index Name should pickup from template ,but creates always bedefault index name](https://discuss.elastic.co/t/metricbeat-and-heartbeat-8-x-custom-index-name-should-pickup-from-template-but-creates-always-bedefault-index-name/337557)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 22\
**Last updated:** [July 11, 2023, 3:40pm UTC](https://discuss.elastic.co/t/metricbeat-and-heartbeat-8-x-custom-index-name-should-pickup-from-template-but-creates-always-bedefault-index-name/337557 "2023-07-11T15:40:37Z")

</div>

Hello All, I'm migrating metricbeat and heartbeat from 7.9.1 to 8.7.1 version and current challenge is I'm unbale to create custom index name defined in my index template and metricbeat.yml. I'm not sure how come every…

---

## [Starting Elasticsearch failed](https://discuss.elastic.co/t/starting-elasticsearch-failed/337616)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 4\
**Last updated:** [July 11, 2023, 2:43pm UTC](https://discuss.elastic.co/t/starting-elasticsearch-failed/337616 "2023-07-11T14:43:07Z")

</div>

Hi, Why does the elasticsearch.service status always give me this every time I start/restart my server? . ● elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled;…

---

## [Using the transform feature for summarizing APM indexes](https://discuss.elastic.co/t/using-the-transform-feature-for-summarizing-apm-indexes/338118)

<div class="topic-metadata">

**Author:** [@Mohammad\_Mousavi](https://discuss.elastic.co/u/Mohammad_Mousavi)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 2:27pm UTC](https://discuss.elastic.co/t/using-the-transform-feature-for-summarizing-apm-indexes/338118 "2023-07-11T14:27:23Z")

</div>

I have elasticsearch version 7.17.1 and our applications are integrated with APM server to send metrics. The problem that we have is it generates heavy indexes, and we want to have old data as well. I thought maybe I ca…

---

## [What mapping or structure should I use for an index that will have very varying fields per document?](https://discuss.elastic.co/t/what-mapping-or-structure-should-i-use-for-an-index-that-will-have-very-varying-fields-per-document/338114)

<div class="topic-metadata">

**Author:** [@Bart\_de\_Man](https://discuss.elastic.co/u/Bart_de_Man)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 2:03pm UTC](https://discuss.elastic.co/t/what-mapping-or-structure-should-i-use-for-an-index-that-will-have-very-varying-fields-per-document/338114 "2023-07-11T14:03:04Z")

</div>

Hi there! As per title; i'd like to have an index which will have very different fields per document. How should I approach this task? What does the mapping look like, if any. Short example of what i'd like to acchieve…

---

## [FluentBit not able to connect to ElasticSearch even with username password given in config](https://discuss.elastic.co/t/fluentbit-not-able-to-connect-to-elasticsearch-even-with-username-password-given-in-config/338104)

<div class="topic-metadata">

**Author:** [@Ganesh\_Kannan\_K\_S1](https://discuss.elastic.co/u/Ganesh_Kannan_K_S1)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 1:58pm UTC](https://discuss.elastic.co/t/fluentbit-not-able-to-connect-to-elasticsearch-even-with-username-password-given-in-config/338104 "2023-07-11T13:58:05Z")

</div>

I am using an AWS EC2 server for running a single-node Elasticsearch instance. I have kibana installed in the same server. I am able to configure 'FluentD' to this node with security enabled, but not 'Fluent-bit'. I am …

---

## [Rename json field from the mongo log with filebeat processor](https://discuss.elastic.co/t/rename-json-field-from-the-mongo-log-with-filebeat-processor/338111)

<div class="topic-metadata">

**Author:** [@slashlinux](https://discuss.elastic.co/u/slashlinux)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/rename-json-field-from-the-mongo-log-with-filebeat-processor/338111 "2023-07-11T13:52:29Z")

</div>

Hi guys, I'm trying to use the official website documentation for filebeat renaming field from the json but doesn't work so I ve decided to post here what i ve done and learn more about my mistake. I want to rename for …

---

## [Documentation on pushing a custom agent to Elastic packages artifactory](https://discuss.elastic.co/t/documentation-on-pushing-a-custom-agent-to-elastic-packages-artifactory/338000)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 6\
**Last updated:** [July 11, 2023, 1:45pm UTC](https://discuss.elastic.co/t/documentation-on-pushing-a-custom-agent-to-elastic-packages-artifactory/338000 "2023-07-11T13:45:21Z")

</div>

I would like to develop an custom agent and push to our own Elastic packages artifactory

---

## [Generating a PDF from a dashboard v7.9](https://discuss.elastic.co/t/generating-a-pdf-from-a-dashboard-v7-9/338094)

<div class="topic-metadata">

**Author:** [@mepec20921](https://discuss.elastic.co/u/mepec20921)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 1:40pm UTC](https://discuss.elastic.co/t/generating-a-pdf-from-a-dashboard-v7-9/338094 "2023-07-11T13:40:30Z")

</div>

Using Elastic v7.9, we have some dashboards set up which we would like to generate a report from every day, and save it to a shared area in Windows. I can see when I am on my dashboard, if I click share and then wither …

---

## [Winlogbeat logs sent through logstash aren't parsed correctly](https://discuss.elastic.co/t/winlogbeat-logs-sent-through-logstash-arent-parsed-correctly/338076)

<div class="topic-metadata">

**Author:** [@dosterberg](https://discuss.elastic.co/u/dosterberg)\
**Replies:** 3\
**Last updated:** [July 11, 2023, 12:51pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-sent-through-logstash-arent-parsed-correctly/338076 "2023-07-11T12:51:00Z")

</div>

Hi everyone! I'm new to ELK and have been enjoying very much working with it so far. I am currently evaluating ELK with Elastic Security as a SIEM in a test environment. I have tried sending both data from filebeat with …

---

## [Disable old alerts](https://discuss.elastic.co/t/disable-old-alerts/337894)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 12:29pm UTC](https://discuss.elastic.co/t/disable-old-alerts/337894 "2023-07-11T12:29:29Z")

</div>

Hello, I have a problem in Kibana Stack Monitoring section. I see historical alerts here. Can it be set to show me, for example, only alerts that are 3 days old? How could I set it up? You can see in the picture that…

---

## [How to archive snapshots](https://discuss.elastic.co/t/how-to-archive-snapshots/337959)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 5\
**Last updated:** [July 11, 2023, 12:27pm UTC](https://discuss.elastic.co/t/how-to-archive-snapshots/337959 "2023-07-11T12:27:59Z")

</div>

Hi all, We have a requirement to archive snapshots for long term retention. However since the snapshot directories are incremental, we do not want to simply zip it and send to archive storage. Is there a recommended alt…

---

## [Elastic cloud and Elastic Package Registry](https://discuss.elastic.co/t/elastic-cloud-and-elastic-package-registry/336272)

<div class="topic-metadata">

**Author:** [@adrien\_moreau](https://discuss.elastic.co/u/adrien_moreau)\
**Replies:** 3\
**Last updated:** [July 11, 2023, 12:16pm UTC](https://discuss.elastic.co/t/elastic-cloud-and-elastic-package-registry/336272 "2023-07-11T12:16:43Z")

</div>

I have developed a custom integration for Elastic but I don't want to publish this integration to the public EPR repo. I am running Elastic on Elastic Cloud. I would like to know if it is possible to push my custom inte…

---

## [Transferring a writable index from one cluster to another](https://discuss.elastic.co/t/transferring-a-writable-index-from-one-cluster-to-another/337934)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 15\
**Last updated:** [July 11, 2023, 11:35am UTC](https://discuss.elastic.co/t/transferring-a-writable-index-from-one-cluster-to-another/337934 "2023-07-11T11:35:10Z")

</div>

I am trying to migrate writable indices from one cluster to another. I wanted to know what could possibly the best approach for doing this. Currently I am doing it as follows : Phase1 -\> Before taking snapshot of init…

---

## [\[ECONNREFUSED\] connect ECONNREFUSED .. Using elaticsearch connector to connect to theHive fails](https://discuss.elastic.co/t/econnrefused-connect-econnrefused-using-elaticsearch-connector-to-connect-to-thehive-fails/338096)

<div class="topic-metadata">

**Author:** [@Cone](https://discuss.elastic.co/u/Cone)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 11:10am UTC](https://discuss.elastic.co/t/econnrefused-connect-econnrefused-using-elaticsearch-connector-to-connect-to-thehive-fails/338096 "2023-07-11T11:10:43Z")

</div>

When I try to connect the Elasticsearch to TheHive via webhooks i get this error shown in the image . Why is taht happenning, The Hive is up and running on that ip address and port? Thanx in advance My webhook is …

---

## [Trino connector : Elasticsearch exception \[type=search\_phase\_execution\_exception, reason=all shards failed](https://discuss.elastic.co/t/trino-connector-elasticsearch-exception-type-search-phase-execution-exception-reason-all-shards-failed/338092)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 10:39am UTC](https://discuss.elastic.co/t/trino-connector-elasticsearch-exception-type-search-phase-execution-exception-reason-all-shards-failed/338092 "2023-07-11T10:39:09Z")

</div>

Pushing logs via logstash and while retrieving data from two tables query failing with below error Using trino query engine connector.name=elasticsearch and also tried with below config but no luck elasticsearch.da…

---

## [Error : environment is not locked in 3 node Kubernetes Elastic Deployment](https://discuss.elastic.co/t/error-environment-is-not-locked-in-3-node-kubernetes-elastic-deployment/338085)

<div class="topic-metadata">

**Author:** [@brusque.sowers](https://discuss.elastic.co/u/brusque.sowers)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 9:51am UTC](https://discuss.elastic.co/t/error-environment-is-not-locked-in-3-node-kubernetes-elastic-deployment/338085 "2023-07-11T09:51:10Z")

</div>

We have a 3 node Elastic deployment on Kubernetes. We encountered the following error in elastic Logs : elasticsearch.node.id":"LMHIgOg6RrWkCRWFY5QyZQ","elasticsearch.node.name":"elasticsearch-0.es-service","elasticsea…

---

## [Adjusting timezone in Fields in index pattern](https://discuss.elastic.co/t/adjusting-timezone-in-fields-in-index-pattern/337995)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 9:07am UTC](https://discuss.elastic.co/t/adjusting-timezone-in-fields-in-index-pattern/337995 "2023-07-11T09:07:07Z")

</div>

Hi , I'm using Kibana 7.10 One of the time fields i'm using is showing a +5.30 hrs time. i.e showing a future time. I think its a timezone error & I want to clear this error in Kibana index pattern field settings. So …

---

## [Sysdig integration with ELK](https://discuss.elastic.co/t/sysdig-integration-with-elk/338057)

<div class="topic-metadata">

**Author:** [@pennywise01](https://discuss.elastic.co/u/pennywise01)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 6:47am UTC](https://discuss.elastic.co/t/sysdig-integration-with-elk/338057 "2023-07-11T06:47:35Z")

</div>

Hi all, i am trying to intergrate sysdig with ELK stack. I am following a tutorial from a blog. I already configured logstash to put the log into elasticsearch but i got an error. \> Blockquote \[ERROR\] 2023-07-11 05:45:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=483)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=485)
