# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=493

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 494

---

## [With minimum security level no rights with elasitc user](https://discuss.elastic.co/t/with-minimum-security-level-no-rights-with-elasitc-user/337234)

<div class="topic-metadata">

**Author:** [@enp2s6](https://discuss.elastic.co/u/enp2s6)\
**Replies:** 1\
**Last updated:** [July 1, 2023, 3:45pm UTC](https://discuss.elastic.co/t/with-minimum-security-level-no-rights-with-elasitc-user/337234 "2023-07-01T15:45:46Z")

</div>

Hi, if I enable the minimum security settings; Set up minimal security for Elasticsearch And log in with the "elastic" account, I have no rights and can not see anything. When I try to define a user and rights before…

---

## [Boostrap Elasticsearch Index Template](https://discuss.elastic.co/t/boostrap-elasticsearch-index-template/337377)

<div class="topic-metadata">

**Author:** [@mibeyki](https://discuss.elastic.co/u/mibeyki)\
**Replies:** 2\
**Last updated:** [July 1, 2023, 3:35pm UTC](https://discuss.elastic.co/t/boostrap-elasticsearch-index-template/337377 "2023-07-01T15:35:56Z")

</div>

Hello, I am trying to configure Filebeat to write data to a custom index like my-index-{now/d}-000001 (using filebeat-8.8.1 and Elastcicsearch 8.8.1). I have followed this guide; But when i try to bootstrap the index u…

---

## [Netflow Mikrotik no data in elasticsearch](https://discuss.elastic.co/t/netflow-mikrotik-no-data-in-elasticsearch/335692)

<div class="topic-metadata">

**Author:** [@sana1567](https://discuss.elastic.co/u/sana1567)\
**Replies:** 20\
**Last updated:** [July 1, 2023, 2:29pm UTC](https://discuss.elastic.co/t/netflow-mikrotik-no-data-in-elasticsearch/335692 "2023-07-01T14:29:16Z")

</div>

hello please help, installed elastic 8.8 + kibana filebeat + netflow I don't see data in my Elasticsearch also when checking the netflow module - check data - No data has been received from this module yet /etc/filebe…

---

## [Custom index not showing in Kibana V8.8.0](https://discuss.elastic.co/t/custom-index-not-showing-in-kibana-v8-8-0/336621)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 11\
**Last updated:** [July 1, 2023, 1:16pm UTC](https://discuss.elastic.co/t/custom-index-not-showing-in-kibana-v8-8-0/336621 "2023-07-01T13:16:50Z")

</div>

I have multiple filebeats v 7.17.5 are configured on different remote servers with custom index names. I have recently updated my ELk stack to 8.8.0 and also updating the filebeat version to 8.8.0. I also try to add some…

---

## [Connection Reset to Logstash](https://discuss.elastic.co/t/connection-reset-to-logstash/337242)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 7:23pm UTC](https://discuss.elastic.co/t/connection-reset-to-logstash/337242 "2023-06-30T19:23:01Z")

</div>

Trying to send Metricbeat to Logstash. Metricbeat logs don't throw any errors, but Logstash shows the following: \[2023-06-29T15:30:02,110\]\[INFO \]\[org.logstash.beats.BeatsHandler\] \[local: 192.168.1.78:5045, remote: 192.…

---

## [Create snapshot API not working](https://discuss.elastic.co/t/create-snapshot-api-not-working/337244)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:29pm UTC](https://discuss.elastic.co/t/create-snapshot-api-not-working/337244 "2023-06-30T18:29:42Z")

</div>

We are new to the snapshot-and-restore function of Elasticsearch. Following the example below, we are trying to create a snapshot repository with the Console of Dev Tools. The Elasticsearch server under test runs as a D…

---

## [How to refer to the whole modified event inside http output plugin](https://discuss.elastic.co/t/how-to-refer-to-the-whole-modified-event-inside-http-output-plugin/337232)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:23pm UTC](https://discuss.elastic.co/t/how-to-refer-to-the-whole-modified-event-inside-http-output-plugin/337232 "2023-06-30T18:23:38Z")

</div>

I am trying to map my http payload and put the whole Logstash event inside another json key/field: http { format =\> "json" http\_method =\> "post" url =\> "some url" headers =\> \["some header"\] ma…

---

## [Getting latest data per user\_id in time series data without latest transforms?](https://discuss.elastic.co/t/getting-latest-data-per-user-id-in-time-series-data-without-latest-transforms/337329)

<div class="topic-metadata">

**Author:** [@MaterializedView](https://discuss.elastic.co/u/MaterializedView)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:21pm UTC](https://discuss.elastic.co/t/getting-latest-data-per-user-id-in-time-series-data-without-latest-transforms/337329 "2023-06-30T18:21:00Z")

</div>

I have a users index. Users have various status "New", "Waiting", "Completed". A status can go from "Completed" to "New" again. So in time series it would look something like user\_id, status, timestamp 1 NEW…

---

## [Change destination datastream with Elasticsearch ingest pipeline](https://discuss.elastic.co/t/change-destination-datastream-with-elasticsearch-ingest-pipeline/336912)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 6:11pm UTC](https://discuss.elastic.co/t/change-destination-datastream-with-elasticsearch-ingest-pipeline/336912 "2023-06-30T18:11:51Z")

</div>

We run Elastic stack in docker containers. The container logs are collected with Elastic Agent, using docker integration and datastreams. This means that the logs of elasticsearch container itself by default end up in l…

---

## [Elasticsearch 8.8 dynamic search request query](https://discuss.elastic.co/t/elasticsearch-8-8-dynamic-search-request-query/336994)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:42pm UTC](https://discuss.elastic.co/t/elasticsearch-8-8-dynamic-search-request-query/336994 "2023-06-30T17:42:55Z")

</div>

SearchResponse\<ObjectNode\> searchResponse = elasticsearchClient.search(req -\> req.index(index) .from((pageNumber - 1) \* pageSize) .size(pageSize) …

---

## [Force Logstash Finish on Error](https://discuss.elastic.co/t/force-logstash-finish-on-error/337331)

<div class="topic-metadata">

**Author:** [@palomasun](https://discuss.elastic.co/u/palomasun)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:03pm UTC](https://discuss.elastic.co/t/force-logstash-finish-on-error/337331 "2023-06-30T17:03:07Z")

</div>

Hi, I use logstash 7.12.1 and I would like to avoid, in case of any error, a ethernal loop: For instance, if my configuration file doesn´t have a certification path it , loops: "unreacheble elastic... " Is there a way…

---

## [Elasticsearch-PHP \[8.8\] - Search for field in date-range, Client Helpers SearchResponseIterator & SearchHitIterator](https://discuss.elastic.co/t/elasticsearch-php-8-8-search-for-field-in-date-range-client-helpers-searchresponseiterator-searchhititerator/337237)

<div class="topic-metadata">

**Author:** [@DavidDPD](https://discuss.elastic.co/u/DavidDPD)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 4:41pm UTC](https://discuss.elastic.co/t/elasticsearch-php-8-8-search-for-field-in-date-range-client-helpers-searchresponseiterator-searchhititerator/337237 "2023-06-30T16:41:08Z")

</div>

The poor documentation of Elasticsearch continues to hamper expanding my usage, and even poorer vagueness in the PHP API documentation. This seems like a simple example. Search for field (it is a tag field, it can have…

---

## [Logstash duplication](https://discuss.elastic.co/t/logstash-duplication/335847)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 3:06pm UTC](https://discuss.elastic.co/t/logstash-duplication/335847 "2023-06-30T15:06:12Z")

</div>

Hello I have created a logstash pipeline via the http\_poller plugin in order to collect information from an API link. In order to manage the duplication of documents, I used the 'fingerprint' plugin in the filter part …

---

## [Filebeat - elasticsearch output without pipeline management](https://discuss.elastic.co/t/filebeat-elasticsearch-output-without-pipeline-management/337322)

<div class="topic-metadata">

**Author:** [@anon68795679](https://discuss.elastic.co/u/anon68795679)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 2:30pm UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-output-without-pipeline-management/337322 "2023-06-30T14:30:32Z")

</div>

Hi, we want to deliver PostgresSQL logs with the filebeat postgres module to an elasticsearch output. But the filebeat shouldn't manage anything in the elasticsearch. ILM, template and ingest pipelines are managed by o…

---

## [SQS Input Plugin retries](https://discuss.elastic.co/t/sqs-input-plugin-retries/337321)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 2:27pm UTC](https://discuss.elastic.co/t/sqs-input-plugin-retries/337321 "2023-06-30T14:27:44Z")

</div>

I have a Logstash pipeline that receives events from an AWS SQS queue via the SQS Input Plugin. If there is a failure during data processing, will SQS retry the event, or do I need a Logstash DLQ to handle intermittent f…

---

## [Strange error with empty delimiter in dissect processor in filebeat](https://discuss.elastic.co/t/strange-error-with-empty-delimiter-in-dissect-processor-in-filebeat/337304)

<div class="topic-metadata">

**Author:** [@calipee](https://discuss.elastic.co/u/calipee)\
**Replies:** 3\
**Last updated:** [June 30, 2023, 1:57pm UTC](https://discuss.elastic.co/t/strange-error-with-empty-delimiter-in-dissect-processor-in-filebeat/337304 "2023-06-30T13:57:55Z")

</div>

I'm trying to dissect the log message and pattern shown in the following error. I validated my input using an dissect-tester by jorgelbg where it works without any issues. I think its especially strange that the delimi…

---

## [Unable to run a benchmark on a 3 node Elastic-Search Cluster](https://discuss.elastic.co/t/unable-to-run-a-benchmark-on-a-3-node-elastic-search-cluster/337120)

<div class="topic-metadata">

**Author:** [@Kavya2708](https://discuss.elastic.co/u/Kavya2708)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 1:39pm UTC](https://discuss.elastic.co/t/unable-to-run-a-benchmark-on-a-3-node-elastic-search-cluster/337120 "2023-06-30T13:39:59Z")

</div>

When running a race on a 3 node Elasticsearch cluster we are getting the following error. We were able to run a benchmark on a single node cluster. The single node had a document count of 3,556,667 , whereas the 3 node …

---

## [Elasticsearch index migration](https://discuss.elastic.co/t/elasticsearch-index-migration/337314)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [June 30, 2023, 1:23pm UTC](https://discuss.elastic.co/t/elasticsearch-index-migration/337314 "2023-06-30T13:23:28Z")

</div>

Hello. We are in the process of migrating from elasticsearch 7.6.2 to version 8.7.0 In our present set up the indices are stored on local disk of all nodes in the cluster and we do not have a shared storage (NAS). Is t…

---

## [Roles N/A in stack monitoring](https://discuss.elastic.co/t/roles-n-a-in-stack-monitoring/337251)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 7\
**Last updated:** [June 30, 2023, 1:15pm UTC](https://discuss.elastic.co/t/roles-n-a-in-stack-monitoring/337251 "2023-06-30T13:15:38Z")

</div>

Hi team, how can i resolve this problem the roles is showing N/A in stack monitoring i'm alreay specified the node.roles in elasticsearch.yml Thanks in advance

---

## [Reindex data stream](https://discuss.elastic.co/t/reindex-data-stream/337305)

<div class="topic-metadata">

**Author:** [@VirusProtect](https://discuss.elastic.co/u/VirusProtect)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 12:34pm UTC](https://discuss.elastic.co/t/reindex-data-stream/337305 "2023-06-30T12:34:56Z")

</div>

Hello, There is conflicts with fields in the data stream backing indices. I would like to know the correct way to resolve this issue. While reindexing data is possible with regular indexes, I am unsure how to proceed wi…

---

## [Kibana Fleet high CPU Load on Elasticsearch when adding Integrations](https://discuss.elastic.co/t/kibana-fleet-high-cpu-load-on-elasticsearch-when-adding-integrations/336729)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 11:29am UTC](https://discuss.elastic.co/t/kibana-fleet-high-cpu-load-on-elasticsearch-when-adding-integrations/336729 "2023-06-30T11:29:55Z")

</div>

Since Elastic-Stack 8.8.0 we observe an issue that is reproducible when navigating fleet and especially modifying integrations where the Elastic-Stack Cluster stalls out due to high CPU. In the following screenshot I've …

---

## [Cannot upgrade node because incompatible indices created with version \[6.2.3\] exist](https://discuss.elastic.co/t/cannot-upgrade-node-because-incompatible-indices-created-with-version-6-2-3-exist/337293)

<div class="topic-metadata">

**Author:** [@Achyut\_Muley](https://discuss.elastic.co/u/Achyut_Muley)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 10:52am UTC](https://discuss.elastic.co/t/cannot-upgrade-node-because-incompatible-indices-created-with-version-6-2-3-exist/337293 "2023-06-30T10:52:28Z")

</div>

I recently started using 8.5.3 version of Elasticsearch.I have some indices that were created in two earlier versions i.e. 7.17.0 and 6.2.3 Now when i while starting Elasticsearch for the version 8.5.3 i am getting the …

---

## [Elasticsearch query with multiple fuzziness and weights](https://discuss.elastic.co/t/elasticsearch-query-with-multiple-fuzziness-and-weights/336948)

<div class="topic-metadata">

**Author:** [@alex.shmukler](https://discuss.elastic.co/u/alex.shmukler)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 10:22am UTC](https://discuss.elastic.co/t/elasticsearch-query-with-multiple-fuzziness-and-weights/336948 "2023-06-30T10:22:18Z")

</div>

Hey Guys, I need to write query that will combine simple match and fuzziness together on different fields. At the beginning I need to normalize each field to characters and numbers only. Each field will have a differ…

---

## [Embedding Kibana dashboard in a React web app](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-a-react-web-app/336672)

<div class="topic-metadata">

**Author:** [@Radhika\_Praveen](https://discuss.elastic.co/u/Radhika_Praveen)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 10:16am UTC](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-a-react-web-app/336672 "2023-06-30T10:16:59Z")

</div>

Hello, My team has been exploring on the options to embed Kibana dashboard into a React web app. After some exploration we have found the below options: iFrame is one way. But we dont want to use iFrame due to securit…

---

## [Replace Null to 0 if no records found in Visualisation](https://discuss.elastic.co/t/replace-null-to-0-if-no-records-found-in-visualisation/336989)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 8\
**Last updated:** [June 30, 2023, 10:09am UTC](https://discuss.elastic.co/t/replace-null-to-0-if-no-records-found-in-visualisation/336989 "2023-06-30T10:09:28Z")

</div>

We have this visualisation created. We want the CSV download to show the value as 0 not "null" for filters with no records. Is this possible ?

---

## [Auditbeat process.args shortened](https://discuss.elastic.co/t/auditbeat-process-args-shortened/337298)

<div class="topic-metadata">

**Author:** [@radovan](https://discuss.elastic.co/u/radovan)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 10:02am UTC](https://discuss.elastic.co/t/auditbeat-process-args-shortened/337298 "2023-06-30T10:02:49Z")

</div>

Hi, I noticed some time ago, that sometimes process.args get shortened in a way that 3 dots are put there instead of more arguments from the commandline so it looks like this: (this is from socket event.dataset, arg…

---

## [Legacy metric to display unique count of a combination of 3 fields](https://discuss.elastic.co/t/legacy-metric-to-display-unique-count-of-a-combination-of-3-fields/336985)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 9:38am UTC](https://discuss.elastic.co/t/legacy-metric-to-display-unique-count-of-a-combination-of-3-fields/336985 "2023-06-30T09:38:54Z")

</div>

Hi, I am working on a kibana dashboard and using a legacy metric visualization. How can i display a unique count of a combination of three fields in the data view? there is an option of selecting only one field. { "m…

---

## [How to configure the THESPIAN\_BASE\_IPADDR when encounter 'ActorAddr-(T|:1900) is not a valid ActorSystem admin'](https://discuss.elastic.co/t/how-to-configure-the-thespian-base-ipaddr-when-encounter-actoraddr-t-1900-is-not-a-valid-actorsystem-admin/336802)

<div class="topic-metadata">

**Author:** [@tengfei225](https://discuss.elastic.co/u/tengfei225)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 9:10am UTC](https://discuss.elastic.co/t/how-to-configure-the-thespian-base-ipaddr-when-encounter-actoraddr-t-1900-is-not-a-valid-actorsystem-admin/336802 "2023-06-30T09:10:48Z")

</div>

Hi I am a new user of Esrally, currently I have created my custom track in order to benchmark the elastic cloud in azure when I try the below command, the actor system can not be started esrally race --track=percolato…

---

## [Is there a way to dynamically group overlapping events?](https://discuss.elastic.co/t/is-there-a-way-to-dynamically-group-overlapping-events/337290)

<div class="topic-metadata">

**Author:** [@landre](https://discuss.elastic.co/u/landre)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 9:03am UTC](https://discuss.elastic.co/t/is-there-a-way-to-dynamically-group-overlapping-events/337290 "2023-06-30T09:03:29Z")

</div>

I am importing data from MySQL using logstash, that contains events with a start and an end date. However, some of these events overlap and, in some conditions, need to be treated as a single event, starting at the start…

---

## [How to process the performance logs from JMeter to Elastic Kibana](https://discuss.elastic.co/t/how-to-process-the-performance-logs-from-jmeter-to-elastic-kibana/337286)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 9:00am UTC](https://discuss.elastic.co/t/how-to-process-the-performance-logs-from-jmeter-to-elastic-kibana/337286 "2023-06-30T09:00:32Z")

</div>

Hi Team, The Application team is trying to process the live logs from JMeter to Elastic Kibana via API key. Is this possible to see the JMeter performance logs in Kibana ? If yes, please guide us on the steps to be take…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=492)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=494)
