# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=488

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 489

---

## [Counter using geofence](https://discuss.elastic.co/t/counter-using-geofence/337832)

<div class="topic-metadata">

**Author:** [@rafaelrangel](https://discuss.elastic.co/u/rafaelrangel)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 9:20pm UTC](https://discuss.elastic.co/t/counter-using-geofence/337832 "2023-07-06T21:20:31Z")

</div>

Good afternoon people. I'm new here and I have a question. I have two indexes: 1 - Data being indexed through a json that contains mainly location (latitude and londitude) and the name of an asset. 2- A geofence with…

---

## [Socket Hang Up Error with Kibana Login](https://discuss.elastic.co/t/socket-hang-up-error-with-kibana-login/337712)

<div class="topic-metadata">

**Author:** [@josh42](https://discuss.elastic.co/u/josh42)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 8:49pm UTC](https://discuss.elastic.co/t/socket-hang-up-error-with-kibana-login/337712 "2023-07-06T20:49:24Z")

</div>

I've been getting a "Socket Hang Up" error when trying to launch Kibana and could use some help troubleshooting the cause. Some background context: My employer requires their own CA, so I had to setup Kibana manually w…

---

## [Unable to parse grokpattern for below log in opensearch ](https://discuss.elastic.co/t/unable-to-parse-grokpattern-for-below-log-in-opensearch/337839)

<div class="topic-metadata">

**Author:** [@David\_Kumar\_Duggu](https://discuss.elastic.co/u/David_Kumar_Duggu)\
**Replies:** 2\
**Last updated:** [July 6, 2023, 8:13pm UTC](https://discuss.elastic.co/t/unable-to-parse-grokpattern-for-below-log-in-opensearch/337839 "2023-07-06T20:13:34Z")

</div>

I am trying to parse the below log using Grok pattern, Grok pattern is parsing in grokdebugger but it is not able to parse in open search. Please find the log attached {"level":"info","msg":"method:offlineActivate,name:…

---

## [Reverse word order search (with shingles)](https://discuss.elastic.co/t/reverse-word-order-search-with-shingles/336792)

<div class="topic-metadata">

**Author:** [@RS232](https://discuss.elastic.co/u/RS232)\
**Replies:** 4\
**Last updated:** [July 6, 2023, 7:19pm UTC](https://discuss.elastic.co/t/reverse-word-order-search-with-shingles/336792 "2023-07-06T19:19:00Z")

</div>

Hello dear Elasticsearch users, Wanted to ask if anyone has a suggestion how to handle this situation. We have source data with phrases like "mazda 3" And two search scenarios: Customer should be able to find it via…

---

## [Problems with aggregations: Data too large](https://discuss.elastic.co/t/problems-with-aggregations-data-too-large/337591)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 6\
**Last updated:** [July 6, 2023, 7:13pm UTC](https://discuss.elastic.co/t/problems-with-aggregations-data-too-large/337591 "2023-07-06T19:13:42Z")

</div>

Hi, I have problems when trying to get aggregations. I have a cluster with one node, and I'm trying to interact with an index that contains 534,737,088 documents (around 32 GB). Some aggregations work, and Elasticsearch…

---

## [Elastic multy match query with order of words given shoul follow in resulted records](https://discuss.elastic.co/t/elastic-multy-match-query-with-order-of-words-given-shoul-follow-in-resulted-records/337827)

<div class="topic-metadata">

**Author:** [@Lakshmikiran](https://discuss.elastic.co/u/Lakshmikiran)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 6:49pm UTC](https://discuss.elastic.co/t/elastic-multy-match-query-with-order-of-words-given-shoul-follow-in-resulted-records/337827 "2023-07-06T18:49:53Z")

</div>

Using multi match queries in each query different words line word1 word2 word3 respectively. After search results also I'm expecting the words in same order, but in between of the words it could be present or not also. B…

---

## [Grok pattern for datadog to get everything between two curly braces {}](https://discuss.elastic.co/t/grok-pattern-for-datadog-to-get-everything-between-two-curly-braces/337665)

<div class="topic-metadata">

**Author:** [@shekhsadiq21](https://discuss.elastic.co/u/shekhsadiq21)\
**Replies:** 8\
**Last updated:** [July 6, 2023, 4:47pm UTC](https://discuss.elastic.co/t/grok-pattern-for-datadog-to-get-everything-between-two-curly-braces/337665 "2023-07-06T16:47:47Z")

</div>

Hi All, Can anyone help to get GROK pattern of logs everthing between two curly braces logsample: { CONNECTION: keep-alive X-ORIGINAL-URL: /Data/RetailItem.js?Log=1&Sync=0 X-FORWARDED-PROTO: https X-FORWARDED-PORT:…

---

## [How to update Kibana Advance Settings via API request](https://discuss.elastic.co/t/how-to-update-kibana-advance-settings-via-api-request/337720)

<div class="topic-metadata">

**Author:** [@Nama\_Chintamani\_Illo](https://discuss.elastic.co/u/Nama_Chintamani_Illo)\
**Replies:** 4\
**Last updated:** [July 6, 2023, 4:08pm UTC](https://discuss.elastic.co/t/how-to-update-kibana-advance-settings-via-api-request/337720 "2023-07-06T16:08:47Z")

</div>

I am trying to update the advance settings of a specific space via an API request. I am attempting to change the "metaFields" setting to include the "\_size" field and would like to send the command via an API without h…

---

## [S3 moving the data from 1 AWS S3 repo to new AWS repo](https://discuss.elastic.co/t/s3-moving-the-data-from-1-aws-s3-repo-to-new-aws-repo/337821)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 4:04pm UTC](https://discuss.elastic.co/t/s3-moving-the-data-from-1-aws-s3-repo-to-new-aws-repo/337821 "2023-07-06T16:04:34Z")

</div>

We have AWS S3 repo1 and we have cold phase data but we are planning to move that data to new AWS S3 repo. What is the best way to do it?

---

## [Bulk insert with Spark causes org.elasticsearch.hadoop.rest.EsHadoopNoNodesLeftException: Connection error (check network and/or proxy settings)- all nodes failed](https://discuss.elastic.co/t/bulk-insert-with-spark-causes-org-elasticsearch-hadoop-rest-eshadoopnonodesleftexception-connection-error-check-network-and-or-proxy-settings-all-nodes-failed/337631)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 6\
**Last updated:** [July 6, 2023, 3:17pm UTC](https://discuss.elastic.co/t/bulk-insert-with-spark-causes-org-elasticsearch-hadoop-rest-eshadoopnonodesleftexception-connection-error-check-network-and-or-proxy-settings-all-nodes-failed/337631 "2023-07-06T15:17:06Z")

</div>

Hi all, I am having trouble with writing to a 5-node Elasticsearch cluster with Spark. Some basic details about the cluster: 5 nodes 6TB of disk 5x28 GB of RAM (half is Heap) 5x6 CPU Allocated 140 shards for the relev…

---

## [Problem in query in logstash](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781)

<div class="topic-metadata">

**Author:** [@Hind\_Alla](https://discuss.elastic.co/u/Hind_Alla)\
**Replies:** 5\
**Last updated:** [July 6, 2023, 2:28pm UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781 "2023-07-06T14:28:23Z")

</div>

input { jdbc { jdbc\_driver\_library =\> "XXXX" jdbc\_driver\_class =\> "Java::oracle.jdbc.driver.OracleDriver" jdbc\_connection\_string =\> "XXXX" jdbc\_user =\> "XXXX" jdbc\_password =\> "XXXX" statement =\> "SELECT \* FROM MO…

---

## [Read an index and count in other index](https://discuss.elastic.co/t/read-an-index-and-count-in-other-index/337803)

<div class="topic-metadata">

**Author:** [@reed](https://discuss.elastic.co/u/reed)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 2:00pm UTC](https://discuss.elastic.co/t/read-an-index-and-count-in-other-index/337803 "2023-07-06T14:00:43Z")

</div>

Hi all, I have two index: index\_master name - code m1 - c1 m2 - c2 m3 - c3 index\_details code - other fields c1 - data field c1 - data field c1 - data field c1 - data field c2 - data field c2 - dat…

---

## [Logging from painless script in ingest pipeline](https://discuss.elastic.co/t/logging-from-painless-script-in-ingest-pipeline/337716)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 2:00pm UTC](https://discuss.elastic.co/t/logging-from-painless-script-in-ingest-pipeline/337716 "2023-07-06T14:00:12Z")

</div>

Hi, I have a requirement where I am indexing my raw docs to an index (original\_index). I am creating a rollup job for this index which runs every hour. My rollup index goes through an ingest pipeline which has a script. …

---

## [Migration from OpenSearch2.5 to Elasticsearch8.8.1](https://discuss.elastic.co/t/migration-from-opensearch2-5-to-elasticsearch8-8-1/336491)

<div class="topic-metadata">

**Author:** [@tatsuya](https://discuss.elastic.co/u/tatsuya)\
**Replies:** 8\
**Last updated:** [July 6, 2023, 12:57pm UTC](https://discuss.elastic.co/t/migration-from-opensearch2-5-to-elasticsearch8-8-1/336491 "2023-07-06T12:57:41Z")

</div>

Hello. I'm thinking of migrating from AWS OpenSearch to Elastic Cloud. First, I launched Elasticsearch 8.8.1 locally with docker and checked if the data could be migrated. Data migration experimented with Snapshot & R…

---

## [Hi all i am getting error like Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/hi-all-i-am-getting-error-like-logstash-stopped-processing-because-of-an-error-systemexit-exit/337536)

<div class="topic-metadata">

**Author:** [@maheswari1](https://discuss.elastic.co/u/maheswari1)\
**Replies:** 4\
**Last updated:** [July 6, 2023, 12:07pm UTC](https://discuss.elastic.co/t/hi-all-i-am-getting-error-like-logstash-stopped-processing-because-of-an-error-systemexit-exit/337536 "2023-07-06T12:07:29Z")

</div>

Logstash stopped processing because of an error: (SystemExit) exit

---

## [Combine multiple index and nested in search elasticsearch](https://discuss.elastic.co/t/combine-multiple-index-and-nested-in-search-elasticsearch/337753)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 11:43am UTC](https://discuss.elastic.co/t/combine-multiple-index-and-nested-in-search-elasticsearch/337753 "2023-07-06T11:43:03Z")

</div>

How to search multiple indexes with nested and non-nested fields ? I have an audio index with the results like this : { "\_index" : "audios", "\_type" : "\_doc", "\_id" : "145", "\_score" : 9…

---

## ["ClusterFormationFailureHelper" master not discovered error while master node is run an stable elected](https://discuss.elastic.co/t/clusterformationfailurehelper-master-not-discovered-error-while-master-node-is-run-an-stable-elected/337789)

<div class="topic-metadata">

**Author:** [@Mohammad\_Hossein\_Ela](https://discuss.elastic.co/u/Mohammad_Hossein_Ela)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 11:22am UTC](https://discuss.elastic.co/t/clusterformationfailurehelper-master-not-discovered-error-while-master-node-is-run-an-stable-elected/337789 "2023-07-06T11:22:01Z")

</div>

I have two two nodes. the first node is master. this node is running without any error. but another node cannot discover this node. The full log of second node as below: \[2023-07-06T09:39:30,479\]\[INFO \]\[o.e.n.Node …

---

## [Kibana hangs during search for logs containing base64](https://discuss.elastic.co/t/kibana-hangs-during-search-for-logs-containing-base64/337565)

<div class="topic-metadata">

**Author:** [@duch](https://discuss.elastic.co/u/duch)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 11:13am UTC](https://discuss.elastic.co/t/kibana-hangs-during-search-for-logs-containing-base64/337565 "2023-07-06T11:13:43Z")

</div>

Hi, we are running into a problem where kibana starts hanging when a search is performed in which logs are returned that contain base64 in a message field. The field encompases an api response with among others 10 mb of…

---

## [Kibana query problem](https://discuss.elastic.co/t/kibana-query-problem/337671)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 7\
**Last updated:** [July 6, 2023, 10:55am UTC](https://discuss.elastic.co/t/kibana-query-problem/337671 "2023-07-06T10:55:52Z")

</div>

Hello, I'm currently working with kibana. Currently I have made a visualization that allows me to count the unique host. I have another plugin \_id field But the problem is that I want to be able to count the unique pl…

---

## [Logstash does not update document](https://discuss.elastic.co/t/logstash-does-not-update-document/337777)

<div class="topic-metadata">

**Author:** [@mehmetalix](https://discuss.elastic.co/u/mehmetalix)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 10:24am UTC](https://discuss.elastic.co/t/logstash-does-not-update-document/337777 "2023-07-06T10:24:23Z")

</div>

Hi, I have a problem with data update in logstash. I need to update specific field in some document according to sql data. My data is looking like this: testid-field1-field2-field3-testtype-time 1-1-1-1-1-2023/05 1…

---

## [Issues with ELK](https://discuss.elastic.co/t/issues-with-elk/337326)

<div class="topic-metadata">

**Author:** [@pero](https://discuss.elastic.co/u/pero)\
**Replies:** 20\
**Last updated:** [July 6, 2023, 10:40am UTC](https://discuss.elastic.co/t/issues-with-elk/337326 "2023-07-06T10:40:38Z")

</div>

Hi All, I have the template siem\_alarm created in my kibana index pattern but i have this error "Error: No indices match pattern "siem\_alarms" at url/bundles/commons.bundle.js:3:1337196" Does anyone know what could be …

---

## [Elastic Curl search index refine](https://discuss.elastic.co/t/elastic-curl-search-index-refine/337776)

<div class="topic-metadata">

**Author:** [@kuthputheen](https://discuss.elastic.co/u/kuthputheen)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 10:21am UTC](https://discuss.elastic.co/t/elastic-curl-search-index-refine/337776 "2023-07-06T10:21:43Z")

</div>

Team, I am using Elastic aggregation to fetch the certain values from the Logstash-database ( Index Name) search and the JSON results generating huge output (currently fetches 30,000 lines output) and bit time consuming…

---

## [Using own SSL certificate doesn't work on stack Elasticsearch + Kibana](https://discuss.elastic.co/t/using-own-ssl-certificate-doesnt-work-on-stack-elasticsearch-kibana/337772)

<div class="topic-metadata">

**Author:** [@vojtech-cerveny](https://discuss.elastic.co/u/vojtech-cerveny)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 9:31am UTC](https://discuss.elastic.co/t/using-own-ssl-certificate-doesnt-work-on-stack-elasticsearch-kibana/337772 "2023-07-06T09:31:34Z")

</div>

Hello! I tried to create production stack kibana + elasticsearch and I am kinda stuck on certificates. Can you help me find the problem in my setting? Situation: We have SSL certificate for \*.example.com and I need …

---

## [Can't enroll new node in current cluster](https://discuss.elastic.co/t/cant-enroll-new-node-in-current-cluster/337764)

<div class="topic-metadata">

**Author:** [@Hi\_u\_Thu\_n](https://discuss.elastic.co/u/Hi_u_Thu_n)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 8:28am UTC](https://discuss.elastic.co/t/cant-enroll-new-node-in-current-cluster/337764 "2023-07-06T08:28:12Z")

</div>

When i try bin\\elasticsearch --enrollment-token MyErrollMent It show an error ERROR: Skipping security auto configuration because it appears that the node is not starting up for the first time. The node might already …

---

## [Elastic Stack Upgradation](https://discuss.elastic.co/t/elastic-stack-upgradation/337760)

<div class="topic-metadata">

**Author:** [@Akulainelastic](https://discuss.elastic.co/u/Akulainelastic)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 7:57am UTC](https://discuss.elastic.co/t/elastic-stack-upgradation/337760 "2023-07-06T07:57:59Z")

</div>

Hi All, so I want to upgrade the entire elk stack version from 7.2 to 8.4 , could anyone shed some light here upon what all backup and prerequisites I need to take care of. Thanks in advance.

---

## [Issue's in configuring kafka input plugin with TLS](https://discuss.elastic.co/t/issues-in-configuring-kafka-input-plugin-with-tls/337761)

<div class="topic-metadata">

**Author:** [@girish.ms](https://discuss.elastic.co/u/girish.ms)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 7:50am UTC](https://discuss.elastic.co/t/issues-in-configuring-kafka-input-plugin-with-tls/337761 "2023-07-06T07:50:34Z")

</div>

Description of the problem: I'm having trouble integrating Kafka with Logstash, and Kafka is configured with TLS. I am getting the following exceptions when trying to provide PKCS12 format TLS certificates in the Kafka…

---

## [Issue running elastics/security track in esrally offline mode](https://discuss.elastic.co/t/issue-running-elastics-security-track-in-esrally-offline-mode/336609)

<div class="topic-metadata">

**Author:** [@Swathi\_Kakumanu](https://discuss.elastic.co/u/Swathi_Kakumanu)\
**Replies:** 3\
**Last updated:** [July 6, 2023, 4:49am UTC](https://discuss.elastic.co/t/issue-running-elastics-security-track-in-esrally-offline-mode/336609 "2023-07-06T04:49:50Z")

</div>

Hi, I am trying to run esrally in offline mode. I am successful in running the http\_logs or geonames tracks in offline mode. However, I am facing issue when running the elastic/security or elastic/logs tracks in offline…

---

## [Elastic-agent not connecting to fleet server](https://discuss.elastic.co/t/elastic-agent-not-connecting-to-fleet-server/337744)

<div class="topic-metadata">

**Author:** [@pennywise01](https://discuss.elastic.co/u/pennywise01)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 4:30am UTC](https://discuss.elastic.co/t/elastic-agent-not-connecting-to-fleet-server/337744 "2023-07-06T04:30:40Z")

</div>

Hi, I am still new to this elastic-agent stuff. I am trying to connect my elastic agent that i want to install on my vm on GCP to connect to my fleet server on AWS EC2. I have already configured firewall rules to allow c…

---

## [JSON parse error, original data now in message field {:message=\>"Could not set field 'original' on object '' to value '{\\"event\\": \\"\\"}'](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-could-not-set-field-original-on-object-to-value-event/337740)

<div class="topic-metadata">

**Author:** [@cosmosir](https://discuss.elastic.co/u/cosmosir)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 4:09am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-could-not-set-field-original-on-object-to-value-event/337740 "2023-07-06T04:09:53Z")

</div>

logstash8.8.1 JSON parse error, original data now in message field {:message=\>"Could not set field 'original' on object '' to value '{"event": ""}'.This is probably due to trying to set a field like \[foo\]\[bar\] = someVal…

---

## [Elasticsearch restoring got conflicts with the internal system indices](https://discuss.elastic.co/t/elasticsearch-restoring-got-conflicts-with-the-internal-system-indices/337586)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 11:25pm UTC](https://discuss.elastic.co/t/elasticsearch-restoring-got-conflicts-with-the-internal-system-indices/337586 "2023-07-05T23:25:50Z")

</div>

We are trying to restore a snapshot made previously, using the following command: POST /\_snapshot/my\_backup/my\_snapshot\_2023.06.30/\_restore However, the command keeps getting errors saying ... index \[.xxxxxx\] because a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=487)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=489)
