# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=490

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 491

---

## [How to not use Keyword type when importing csv?](https://discuss.elastic.co/t/how-to-not-use-keyword-type-when-importing-csv/337601)

<div class="topic-metadata">

**Author:** [@tavd-projects](https://discuss.elastic.co/u/tavd-projects)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 10:10am UTC](https://discuss.elastic.co/t/how-to-not-use-keyword-type-when-importing-csv/337601 "2023-07-05T10:10:37Z")

</div>

Hello. How to make columns not indexed as Keyword when importing CSV? (I'm using the standard integration, not Logstash). The problem is that I can't seem to change the Keyword to a specific data type in any way. I will …

---

## [When the master node publishes the cluster state, if a certain slave node fails to respond consistently and no timeout is set, does it mean that it will keep waiting and cannot complete?](https://discuss.elastic.co/t/when-the-master-node-publishes-the-cluster-state-if-a-certain-slave-node-fails-to-respond-consistently-and-no-timeout-is-set-does-it-mean-that-it-will-keep-waiting-and-cannot-complete/337595)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 9:47am UTC](https://discuss.elastic.co/t/when-the-master-node-publishes-the-cluster-state-if-a-certain-slave-node-fails-to-respond-consistently-and-no-timeout-is-set-does-it-mean-that-it-will-keep-waiting-and-cannot-complete/337595 "2023-07-05T09:47:35Z")

</div>

I found that when the master node publishes the cluster state, in the second phase, it will wait for all slave nodes to respond (successfully or unsuccessfully) before proceeding with the subsequent process. If a request…

---

## [Change path of data file](https://discuss.elastic.co/t/change-path-of-data-file/337633)

<div class="topic-metadata">

**Author:** [@Hi\_u\_Thu\_n](https://discuss.elastic.co/u/Hi_u_Thu_n)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 9:39am UTC](https://discuss.elastic.co/t/change-path-of-data-file/337633 "2023-07-05T09:39:22Z")

</div>

I change path in file elasticsearch.yml but it not working! # ----------------------------------- Paths ------------------------------------ # # Path to directory where to store the data (separate multiple locations by …

---

## [Can not create update index pipeline without unique identifier in database](https://discuss.elastic.co/t/can-not-create-update-index-pipeline-without-unique-identifier-in-database/337494)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 9:31am UTC](https://discuss.elastic.co/t/can-not-create-update-index-pipeline-without-unique-identifier-in-database/337494 "2023-07-05T09:31:05Z")

</div>

Hi all. I want to create an update index using jdbc input and elasticsearch output. I have a left joined table consists of 4 tables in database. But I do not have a unique identifier in db. Therefore I can not create …

---

## [No node formation by changing bootstrap.password on all node](https://discuss.elastic.co/t/no-node-formation-by-changing-bootstrap-password-on-all-node/337643)

<div class="topic-metadata">

**Author:** [@MALKARAJ\_K](https://discuss.elastic.co/u/MALKARAJ_K)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 9:06am UTC](https://discuss.elastic.co/t/no-node-formation-by-changing-bootstrap-password-on-all-node/337643 "2023-07-05T09:06:30Z")

</div>

Elasticsearch nodes couldn't form the cluster by changing bootstrap.password on each node

---

## [I want to implement automatic user login to a Kibana dashboard from a web application](https://discuss.elastic.co/t/i-want-to-implement-automatic-user-login-to-a-kibana-dashboard-from-a-web-application/337233)

<div class="topic-metadata">

**Author:** [@dilshadpaleri](https://discuss.elastic.co/u/dilshadpaleri)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 9:05am UTC](https://discuss.elastic.co/t/i-want-to-implement-automatic-user-login-to-a-kibana-dashboard-from-a-web-application/337233 "2023-07-05T09:05:55Z")

</div>

I want to implement automatic user login to a Kibana dashboard from a web application. I have successfully enabled x-pack security and attempted to authenticate users through the HTTP header. However, I am facing an issu…

---

## [Parameters in Kibana](https://discuss.elastic.co/t/parameters-in-kibana/337574)

<div class="topic-metadata">

**Author:** [@Olga\_Nalivaiko](https://discuss.elastic.co/u/Olga_Nalivaiko)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 7:43am UTC](https://discuss.elastic.co/t/parameters-in-kibana/337574 "2023-07-05T07:43:07Z")

</div>

Hello! I'm new to Kibana and I have been trying to find such a control feature as parameter. For example, a dropdown with a list of fields so that the user could select one for the chart or a dropdown with numeric value…

---

## [Logstash JDBC Input - Time difference problem](https://discuss.elastic.co/t/logstash-jdbc-input-time-difference-problem/337542)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:20am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-time-difference-problem/337542 "2023-07-05T07:20:45Z")

</div>

Hi, I receive entries from a PostgreSQL database in my Logstash Docker container. I get what I want but I'm facing a problem with the timestamp. When I do a request in pgAdmin, it shows timestamps with the local time (Fr…

---

## [PutComposableIndexTemplateRequest in Custom Plugin](https://discuss.elastic.co/t/putcomposableindextemplaterequest-in-custom-plugin/337625)

<div class="topic-metadata">

**Author:** [@\_murat](https://discuss.elastic.co/u/_murat)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 7:12am UTC](https://discuss.elastic.co/t/putcomposableindextemplaterequest-in-custom-plugin/337625 "2023-07-05T07:12:14Z")

</div>

Hello! I have been working on a custom Elasticsearch plugin that should create an index template and its components when an Elasticsearch instance loads this plugin. The only client that I can access is NodeClient and t…

---

## [MongoDB to Elasticsearch?](https://discuss.elastic.co/t/mongodb-to-elasticsearch/336767)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 6:40am UTC](https://discuss.elastic.co/t/mongodb-to-elasticsearch/336767 "2023-07-05T06:40:52Z")

</div>

Is there a way to index data from mongoDB to elasticsearch? I've searched a bit but I haven't found any mongodb input on logstash i.e. part of the mongoDB collection by making an aggregation query and then storing the r…

---

## [How to use curl command to input data into logstash](https://discuss.elastic.co/t/how-to-use-curl-command-to-input-data-into-logstash/337615)

<div class="topic-metadata">

**Author:** [@vijeibarthi](https://discuss.elastic.co/u/vijeibarthi)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 6:21am UTC](https://discuss.elastic.co/t/how-to-use-curl-command-to-input-data-into-logstash/337615 "2023-07-05T06:21:16Z")

</div>

Hi All, I have a curl command which works fine but I have trouble using that curl command in the json format. Please guide on how to correct this script to output the data. =============================================…

---

## [Regular expressions in kibana filters](https://discuss.elastic.co/t/regular-expressions-in-kibana-filters/337548)

<div class="topic-metadata">

**Author:** [@SajjanKumarPatea](https://discuss.elastic.co/u/SajjanKumarPatea)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 6:11am UTC](https://discuss.elastic.co/t/regular-expressions-in-kibana-filters/337548 "2023-07-05T06:11:55Z")

</div>

Can you tell me how to filter messages in indexes correctly? I am filtering messages by a specific field. And I want to see messages only with this value in the field: id-nmap100-tapic-prod But I also get messages wit…

---

## [TCP input failed with Checkpoint syslog integration](https://discuss.elastic.co/t/tcp-input-failed-with-checkpoint-syslog-integration/337609)

<div class="topic-metadata">

**Author:** [@adub08](https://discuss.elastic.co/u/adub08)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 6:04am UTC](https://discuss.elastic.co/t/tcp-input-failed-with-checkpoint-syslog-integration/337609 "2023-07-05T06:04:50Z")

</div>

Hi I've been unable to setup the Checkpoint Elastic integration due to this error. \[elastic\_agent.filebeat\]\[error\] Input 'tcp' failed with: context canceled Settings: Integration info: logfile: disabled UDP: disa…

---

## [Not eligible for data streams because config contains one or more settings that are not compatible with data streams](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams/337594)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 3:27am UTC](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams/337594 "2023-07-05T03:27:44Z")

</div>

I tried to upload my template using Logstash, but it did not. It says that \[2023-07-05T00:03:53,496\]\[INFO \]\[logstash.outputs.elasticsearch\]\[main\] Not eligible for data streams because config contains one or more settin…

---

## [Can I use "from/size", "timeout", "track\_total\_hits", "format", etc. for free?](https://discuss.elastic.co/t/can-i-use-from-size-timeout-track-total-hits-format-etc-for-free/337523)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 11:46pm UTC](https://discuss.elastic.co/t/can-i-use-from-size-timeout-track-total-hits-format-etc-for-free/337523 "2023-07-04T23:46:30Z")

</div>

hi thank for watching Can I use "from/size", "timeout", "track\_total\_hits", "format", etc. for free? "When I looked it up on the following site, I found that "from/size", "timeout"," "track\_total\_hits" and "format" be…

---

## [Strategy for matching unstructured text to phrases in index](https://discuss.elastic.co/t/strategy-for-matching-unstructured-text-to-phrases-in-index/337583)

<div class="topic-metadata">

**Author:** [@rustunooldu](https://discuss.elastic.co/u/rustunooldu)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 7:39pm UTC](https://discuss.elastic.co/t/strategy-for-matching-unstructured-text-to-phrases-in-index/337583 "2023-07-04T19:39:59Z")

</div>

I'm trying to extract data from product descriptions, and I have the catalog data indexed and categorized. For example, I have a color name index (that contains all possible colors for the product), and I want to be able…

---

## [Replicas shards of Default indexers are in UNASSIGNED State](https://discuss.elastic.co/t/replicas-shards-of-default-indexers-are-in-unassigned-state/336979)

<div class="topic-metadata">

**Author:** [@Sathish22](https://discuss.elastic.co/u/Sathish22)\
**Replies:** 11\
**Last updated:** [July 4, 2023, 5:42pm UTC](https://discuss.elastic.co/t/replicas-shards-of-default-indexers-are-in-unassigned-state/336979 "2023-07-04T17:42:45Z")

</div>

Hi Team, Recently we are facing a issue with replicas shards and all default indexers replica shards are in UNASSIGNED State. due to this cluster is going to yellow and red state. index shard prirep state .ta…

---

## [Bitdefender GravityZone and Logstash Integration](https://discuss.elastic.co/t/bitdefender-gravityzone-and-logstash-integration/337582)

<div class="topic-metadata">

**Author:** [@Paulo\_Martins\_de\_Sen](https://discuss.elastic.co/u/Paulo_Martins_de_Sen)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 5:24pm UTC](https://discuss.elastic.co/t/bitdefender-gravityzone-and-logstash-integration/337582 "2023-07-04T17:24:48Z")

</div>

Hey guys, has anyone done Bitdefender GravityZone and Elastic Security integration? I'm trying to do it through agent elastic, but without success so far.

---

## [How to check if a keyword exists in elastalert](https://discuss.elastic.co/t/how-to-check-if-a-keyword-exists-in-elastalert/337581)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 5:14pm UTC](https://discuss.elastic.co/t/how-to-check-if-a-keyword-exists-in-elastalert/337581 "2023-07-04T17:14:33Z")

</div>

I wanted to send out an alert to our slack channel if a there is an indexing error or the number of events \> 20 for last 10 minutes. Below is my elastalert yaml configuration. influx\_indexing\_error\_slack\_message\_rule: |…

---

## [ilm policy delete action is disable but index is still be deleted](https://discuss.elastic.co/t/ilm-policy-delete-action-is-disable-but-index-is-still-be-deleted/337515)

<div class="topic-metadata">

**Author:** [@frank\_spr](https://discuss.elastic.co/u/frank_spr)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 4:37pm UTC](https://discuss.elastic.co/t/ilm-policy-delete-action-is-disable-but-index-is-still-be-deleted/337515 "2023-07-04T16:37:49Z")

</div>

My Elasticsearch index is managed by IML. Recently, I discovered that my index has been deleted for no reason, so I disabled the delete operation in the IML policy. However, I found that my index will still be deleted 1…

---

## [Log alerting for different applications](https://discuss.elastic.co/t/log-alerting-for-different-applications/337559)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [July 4, 2023, 4:20pm UTC](https://discuss.elastic.co/t/log-alerting-for-different-applications/337559 "2023-07-04T16:20:31Z")

</div>

Hello, i'm a bit confused over the way the alerting works in the elastic stack. I have multiple small applications that generate logs and also have to manage multiple larger applications that generate multiple differen…

---

## [Logstash @timestamp not including milliseconds](https://discuss.elastic.co/t/logstash-timestamp-not-including-milliseconds/337579)

<div class="topic-metadata">

**Author:** [@Anthony\_Zottola](https://discuss.elastic.co/u/Anthony_Zottola)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 4:17pm UTC](https://discuss.elastic.co/t/logstash-timestamp-not-including-milliseconds/337579 "2023-07-04T16:17:08Z")

</div>

All of my logs have this format "@timestamp" =\> 2023-07-04T15:40:19.000Z where the milliseconds are missing, is there any way to make it included the milliseconds. I tried manually adding it but it is read only. My con…

---

## [Heartbeat: Ping TImeout on hosts causes state.duration\_ms to stay at 0?](https://discuss.elastic.co/t/heartbeat-ping-timeout-on-hosts-causes-state-duration-ms-to-stay-at-0/334051)

<div class="topic-metadata">

**Author:** [@scantron](https://discuss.elastic.co/u/scantron)\
**Replies:** 7\
**Last updated:** [July 4, 2023, 3:46pm UTC](https://discuss.elastic.co/t/heartbeat-ping-timeout-on-hosts-causes-state-duration-ms-to-stay-at-0/334051 "2023-07-04T15:46:49Z")

</div>

We are monitoring a few hosts using ICMP on heartbeat. Heartbeat accurately depicts the uptime using the state.duration\_ms field. However, shutting down a host for testing leads to the error.message field of "ping timeou…

---

## [How to setup a cluster from scratch](https://discuss.elastic.co/t/how-to-setup-a-cluster-from-scratch/337564)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 4\
**Last updated:** [July 4, 2023, 2:31pm UTC](https://discuss.elastic.co/t/how-to-setup-a-cluster-from-scratch/337564 "2023-07-04T14:31:18Z")

</div>

Hi, I have been using elasticsearch for a long time. Our initial cluster was setup in 5.x days (installation procedures have been 'lost') and we have performed rolling upgrade ever since. Currently the cluster is 8.8 wi…

---

## [How to change the username by own instead of elastic?](https://discuss.elastic.co/t/how-to-change-the-username-by-own-instead-of-elastic/337552)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 1\
**Last updated:** [July 4, 2023, 2:09pm UTC](https://discuss.elastic.co/t/how-to-change-the-username-by-own-instead-of-elastic/337552 "2023-07-04T14:09:37Z")

</div>

How to change the username by own instead of elastic in ELK?

---

## [Metricbeat windows module error](https://discuss.elastic.co/t/metricbeat-windows-module-error/337566)

<div class="topic-metadata">

**Author:** [@dchaarifreedomofdev](https://discuss.elastic.co/u/dchaarifreedomofdev)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 1:43pm UTC](https://discuss.elastic.co/t/metricbeat-windows-module-error/337566 "2023-07-04T13:43:14Z")

</div>

I have installed metricbeat 7.17.5 on my windows machine and I enabled the windows module. And I added this configuration : module: windows metricsets: - service enabled: true period: 30s But when I r…

---

## [Documents not editable of index](https://discuss.elastic.co/t/documents-not-editable-of-index/337307)

<div class="topic-metadata">

**Author:** [@Jay\_Desai](https://discuss.elastic.co/u/Jay_Desai)\
**Replies:** 13\
**Last updated:** [July 4, 2023, 12:37pm UTC](https://discuss.elastic.co/t/documents-not-editable-of-index/337307 "2023-07-04T12:37:55Z")

</div>

PUT /your-index/\_settings { "index.blocks.write": true } not working

---

## [Boost score if query contains all tokens in the field](https://discuss.elastic.co/t/boost-score-if-query-contains-all-tokens-in-the-field/337551)

<div class="topic-metadata">

**Author:** [@Siah\_Wei\_Chong](https://discuss.elastic.co/u/Siah_Wei_Chong)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 10:31am UTC](https://discuss.elastic.co/t/boost-score-if-query-contains-all-tokens-in-the-field/337551 "2023-07-04T10:31:17Z")

</div>

I am new to Elasticsearch. I am working off Search for an address My query looks like this GET all\_address/\_search { "explain":true, "query":{ "multi\_match": { "query": "Flat 1, Floor 1, Raymond Court"…

---

## [Elastic Security Detection Rule Management - Update of Duplicates](https://discuss.elastic.co/t/elastic-security-detection-rule-management-update-of-duplicates/337550)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 10:28am UTC](https://discuss.elastic.co/t/elastic-security-detection-rule-management-update-of-duplicates/337550 "2023-07-04T10:28:57Z")

</div>

Hi everyone, does anyone have experience with managing prebuilt detection rules with your own index-patterns and exceptions? Right now I load the prebuilt rules into kibana and then duplicate them in order to add my ow…

---

## [Filebeat restart question](https://discuss.elastic.co/t/filebeat-restart-question/335194)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 4\
**Last updated:** [July 4, 2023, 10:24am UTC](https://discuss.elastic.co/t/filebeat-restart-question/335194 "2023-07-04T10:24:32Z")

</div>

Hi there, Everytime I need to restart Filebeat, my "scripted fields" and customization to some fields are broken. Also the dashboards are reset. Is this normal? Is there any way that I can fix this behaviour to prevent…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=489)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=491)
