# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=495

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 496

---

## [Simple search doesnt work](https://discuss.elastic.co/t/simple-search-doesnt-work/337092)

<div class="topic-metadata">

**Author:** [@Dach](https://discuss.elastic.co/u/Dach)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 11:21am UTC](https://discuss.elastic.co/t/simple-search-doesnt-work/337092 "2023-06-29T11:21:08Z")

</div>

When i do this search, my product is well find : { "query": { "bool": { "must": \[ { "match": { "pickRef": "630203" } }, { "match": { "id": 56139 } }, { "match": { "name.fr": "ENVELOPP…

---

## [NullPointerException when performing a Completion Suggester query with synonym analyzer, v8.5](https://discuss.elastic.co/t/nullpointerexception-when-performing-a-completion-suggester-query-with-synonym-analyzer-v8-5/336674)

<div class="topic-metadata">

**Author:** [@jacoMet](https://discuss.elastic.co/u/jacoMet)\
**Replies:** 3\
**Last updated:** [June 29, 2023, 10:47am UTC](https://discuss.elastic.co/t/nullpointerexception-when-performing-a-completion-suggester-query-with-synonym-analyzer-v8-5/336674 "2023-06-29T10:47:37Z")

</div>

I need to be able to perform Completion Suggest queries that are context dependent. When executing the query below: POST synonym\_file\_test/\_search { "\_source": "suggest", "suggest": { "my-suggest": { "prefix…

---

## [Use aggregate filter of logatash to find dynamic task-id](https://discuss.elastic.co/t/use-aggregate-filter-of-logatash-to-find-dynamic-task-id/337177)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 10:33am UTC](https://discuss.elastic.co/t/use-aggregate-filter-of-logatash-to-find-dynamic-task-id/337177 "2023-06-29T10:33:22Z")

</div>

Hi I want to use aggregate filter to find dynamic task-id https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html Here is the scenario I have log like below need to extract "Send&Receive dura…

---

## [Cannot read properties of undefined (reading 'call') at o (kbn-ui-shared-deps-npm.dll.js:1:388) - when installing plugin in 8.8.1 and 8.5.3](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-call-at-o-kbn-ui-shared-deps-npm-dll-js388-when-installing-plugin-in-8-8-1-and-8-5-3/336894)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 10:01am UTC](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-call-at-o-kbn-ui-shared-deps-npm-dll-js388-when-installing-plugin-in-8-8-1-and-8-5-3/336894 "2023-06-29T10:01:05Z")

</div>

Hi, I am developing a custom plugin using React, in Kibana main branch. I did yarn build for 8.5.3 and 8.8.1 versions of Kibana, and installed the same in the respective versions. But in both the versions, I get the f…

---

## [useNavigate() and useSearchParams() gives Object(...) is not a function error](https://discuss.elastic.co/t/usenavigate-and-usesearchparams-gives-object-is-not-a-function-error/336955)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 9:59am UTC](https://discuss.elastic.co/t/usenavigate-and-usesearchparams-gives-object-is-not-a-function-error/336955 "2023-06-29T09:59:45Z")

</div>

Hi, I am developing a custom plugin using React in Kibana main branch (8.9). When I use useSearchParams() or useNavigate() from react-router v6, I get an error in the browser saying Object(...) is not a function. But w…

---

## [Fleet server configuration file](https://discuss.elastic.co/t/fleet-server-configuration-file/337163)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 9:34am UTC](https://discuss.elastic.co/t/fleet-server-configuration-file/337163 "2023-06-29T09:34:26Z")

</div>

My elastic agents are still sending information to elasticsearch however they are showing as unhealthy or inactive with my fleet server. On the troubleshooting it suggested to run this command; curl -f http://:8220/api…

---

## [Index historical time-series data into a data stream - ILM](https://discuss.elastic.co/t/index-historical-time-series-data-into-a-data-stream-ilm/337167)

<div class="topic-metadata">

**Author:** [@qcha](https://discuss.elastic.co/u/qcha)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 8:51am UTC](https://discuss.elastic.co/t/index-historical-time-series-data-into-a-data-stream-ilm/337167 "2023-06-29T08:51:54Z")

</div>

Hi everyone, My use case is the following : I have continuously produced time-series data + one year history (both outside Elastic). I want to index them into Elastic in such a way that data is deleted after one year (a…

---

## [Mssql server connectivity issue with logstash](https://discuss.elastic.co/t/mssql-server-connectivity-issue-with-logstash/337165)

<div class="topic-metadata">

**Author:** [@Nawab\_Zaidi](https://discuss.elastic.co/u/Nawab_Zaidi)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 7:56am UTC](https://discuss.elastic.co/t/mssql-server-connectivity-issue-with-logstash/337165 "2023-06-29T07:56:22Z")

</div>

I am trying to fetch data from MSSQL with the following mssql.conf script in config directory input { jdbc { jdbc\_driver\_class =\> "com.microsoft.sqlserver.jdbc.SQLServerDriver" jdbc\_driver\_library =\> "" jdbc\_connect…

---

## [Calculate total duration](https://discuss.elastic.co/t/calculate-total-duration/337148)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 5:00am UTC](https://discuss.elastic.co/t/calculate-total-duration/337148 "2023-06-29T05:00:19Z")

</div>

Hi How can I calculate duration of below log: 2021-07-15 00:00:01,869 INFO CUS.AbCD-AppService1-1234567 \[AppListener\] Receive Packet\[00\*\]: Kafka\[AppService1.APP1\] 2021-07-15 00:00:01,988 INFO CUS.AbCD-AppService1-1234…

---

## [Calculate transaction duration](https://discuss.elastic.co/t/calculate-transaction-duration/337147)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 4:53am UTC](https://discuss.elastic.co/t/calculate-transaction-duration/337147 "2023-06-29T04:53:54Z")

</div>

Hi i have log file like this: 2021-07-15 00:00:01,869 INFO client.InEE-server1-1234567 \[AppListener\] Receive Message\[A123\]: Q\[p1.APP\], IID\[null\], Cookie\[{"NODE\_SRC":"server0"}\] 2021-07-15 00:00:01,871 INFO client.InEE…

---

## [Find time gaps](https://discuss.elastic.co/t/find-time-gaps/337146)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 4:44am UTC](https://discuss.elastic.co/t/find-time-gaps/337146 "2023-06-29T04:44:33Z")

</div>

Hi i have log like this, need to find where unusuall time gap between "Packet Processed" and "Send Packet" that exist this is normal 001 2021-10-25 08:59:50,725 INFO CUS.AbCD-VW2-1234567890 \[FlowProcessorService\] Packe…

---

## [Find transaction in log](https://discuss.elastic.co/t/find-transaction-in-log/337143)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 4:34am UTC](https://discuss.elastic.co/t/find-transaction-in-log/337143 "2023-06-29T04:34:49Z")

</div>

Hi I have log like below need to extract "Send&Receive duration" and "send that has not respond". this is send 2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567 \[MyService\] Packet Processed: A\[50\] B\[0000211\] t…

---

## [Heartbeat on Kubernetes cluster](https://discuss.elastic.co/t/heartbeat-on-kubernetes-cluster/337140)

<div class="topic-metadata">

**Author:** [@jam\_mahmoudi](https://discuss.elastic.co/u/jam_mahmoudi)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 4:17am UTC](https://discuss.elastic.co/t/heartbeat-on-kubernetes-cluster/337140 "2023-06-29T04:17:24Z")

</div>

Hi guys I have a question How should I define a heartbeat to monitor all pods in a Kubernetes cluster? Do I only need to install and configure Heartbeat on the worker nodes, or do I need to install and configure it on…

---

## [Segments info In Indics Stats](https://discuss.elastic.co/t/segments-info-in-indics-stats/337133)

<div class="topic-metadata">

**Author:** [@Geunmoon\_Oh](https://discuss.elastic.co/u/Geunmoon_Oh)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 11:14pm UTC](https://discuss.elastic.co/t/segments-info-in-indics-stats/337133 "2023-06-28T23:14:37Z")

</div>

I use ES 8.6. I created a lot indexes and added a lot data. but i don't know why segments's memory\_in\_bytes is zero. Can the value be always zero In ES 8.6 ???

---

## [If there are multiple \`order\`, what is the priority?](https://discuss.elastic.co/t/if-there-are-multiple-order-what-is-the-priority/337045)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 11:51pm UTC](https://discuss.elastic.co/t/if-there-are-multiple-order-what-is-the-priority/337045 "2023-06-28T23:51:25Z")

</div>

Hello, I'm using a translation because I can't speak English, so please teach me gently. Currently, I have something I would like to ask the order, so I am in a community. GET /\_search { "track\_scores": true, "sort" :…

---

## [Problem with data field in logstash](https://discuss.elastic.co/t/problem-with-data-field-in-logstash/336875)

<div class="topic-metadata">

**Author:** [@KarlWolf](https://discuss.elastic.co/u/KarlWolf)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 11:19pm UTC](https://discuss.elastic.co/t/problem-with-data-field-in-logstash/336875 "2023-06-28T23:19:01Z")

</div>

hi, I have a strange case regarding my Logstash process. I'm having a filebeat which sends file-log to Logstash. That file log is updated from old proxy system in the following manner: logs from 15 minutes are gathere…

---

## [Kibana not working// Elasticsearch host](https://discuss.elastic.co/t/kibana-not-working-elasticsearch-host/336929)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 8\
**Last updated:** [June 28, 2023, 11:03pm UTC](https://discuss.elastic.co/t/kibana-not-working-elasticsearch-host/336929 "2023-06-28T23:03:50Z")

</div>

Can anyone help me here, i have been trying to set up Wazuh to work with ELK stack, having Filebeat to send the logs to Kibana for visualization. Just to begin with here\`s my elasticsearch .yml file : network.host: 19…

---

## [Kafka Codec Avro Plugin Polling Frequency](https://discuss.elastic.co/t/kafka-codec-avro-plugin-polling-frequency/337121)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 10:52pm UTC](https://discuss.elastic.co/t/kafka-codec-avro-plugin-polling-frequency/337121 "2023-06-28T22:52:25Z")

</div>

I'm planning on using the Codec Avro Plugin to deserialize incoming events from SQS. However, requests to the Kafka schema registry are rate-limited to 25 queries/second when using an HTTP URI. How frequently does this …

---

## [Linux install of Filebeat under different directory](https://discuss.elastic.co/t/linux-install-of-filebeat-under-different-directory/337130)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 9:56pm UTC](https://discuss.elastic.co/t/linux-install-of-filebeat-under-different-directory/337130 "2023-06-28T21:56:07Z")

</div>

Hi all, In the past I've followed the Filebeat installation instructions for RPM installation on Linux verbatim without issue. But now we have a machine that lacks space under /etc, so we want to install it under /opt …

---

## [Unable to Access Kibana Dashboard](https://discuss.elastic.co/t/unable-to-access-kibana-dashboard/337027)

<div class="topic-metadata">

**Author:** [@vdashora](https://discuss.elastic.co/u/vdashora)\
**Replies:** 4\
**Last updated:** [June 28, 2023, 8:40pm UTC](https://discuss.elastic.co/t/unable-to-access-kibana-dashboard/337027 "2023-06-28T20:40:41Z")

</div>

We are unable to access our Kibana dashboard. The docker daemon was down, but we ssh into our slave and rebooted everything. URL: http://ivtscenarios1.fyre.ibm.com:5601/app/dashboards#/view/d1f9c740-cf59-11ed-b98d-1da6f…

---

## [Elasticsearch Query setting date conditions](https://discuss.elastic.co/t/elasticsearch-query-setting-date-conditions/335554)

<div class="topic-metadata">

**Author:** [@DavidGreensfelder](https://discuss.elastic.co/u/DavidGreensfelder)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 8:13pm UTC](https://discuss.elastic.co/t/elasticsearch-query-setting-date-conditions/335554 "2023-06-28T20:13:57Z")

</div>

I am setting up Alerting Rules under Rules and Connections. My query works great, but I need to not see the alerts during the maintenance window from 9 pm to 5 am. Here is my query: { "query" : { "bool" : { …

---

## [Anyone embed a Kibana chart in a Grafana dash?](https://discuss.elastic.co/t/anyone-embed-a-kibana-chart-in-a-grafana-dash/337127)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 7:24pm UTC](https://discuss.elastic.co/t/anyone-embed-a-kibana-chart-in-a-grafana-dash/337127 "2023-06-28T19:24:11Z")

</div>

We'd love our engineers to be able to see our Grafana-served metrics alongside our Kibana-served logs visualizations. It seems like it should be possible. Has anyone done this?

---

## [How to check the default value of \`dynamic\_date\_formats\` and other mapping settings?](https://discuss.elastic.co/t/how-to-check-the-default-value-of-dynamic-date-formats-and-other-mapping-settings/337125)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 6:53pm UTC](https://discuss.elastic.co/t/how-to-check-the-default-value-of-dynamic-date-formats-and-other-mapping-settings/337125 "2023-06-28T18:53:04Z")

</div>

New to Elasticsearch, and I am wondering how to check the current value of dynamic\_date\_formats. The online document, here, provides an example of setting customized value, but I did not find how to check its value. P…

---

## [Cluster shards unbalanced and keep moving shards around after upgrade to 8.8.1](https://discuss.elastic.co/t/cluster-shards-unbalanced-and-keep-moving-shards-around-after-upgrade-to-8-8-1/336573)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 18\
**Last updated:** [June 28, 2023, 3:56pm UTC](https://discuss.elastic.co/t/cluster-shards-unbalanced-and-keep-moving-shards-around-after-upgrade-to-8-8-1/336573 "2023-06-28T15:56:20Z")

</div>

Hello, Yesterday we upgraded our cluster from 8.5.1 to 8.8.1 and now the shards are unbalacend between the nodes and the cluster keeps moving shards around to try to balance it. I have a hot/warm architecture with 4 ho…

---

## [Is it possible to send pfsense syslogs from firewall to elastic agent on windows 11 home to my discover page?](https://discuss.elastic.co/t/is-it-possible-to-send-pfsense-syslogs-from-firewall-to-elastic-agent-on-windows-11-home-to-my-discover-page/337020)

<div class="topic-metadata">

**Author:** [@synthallthetime](https://discuss.elastic.co/u/synthallthetime)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 6:55pm UTC](https://discuss.elastic.co/t/is-it-possible-to-send-pfsense-syslogs-from-firewall-to-elastic-agent-on-windows-11-home-to-my-discover-page/337020 "2023-06-27T18:55:48Z")

</div>

Hi there, I'm looking to see if it's possible to configure pfsense to send its syslogs into the pfsense integrations addin into my elastic agent on my windows 11 home endpoint. I have managed to set up logging for sysm…

---

## [Unable to do match query with new Java API client](https://discuss.elastic.co/t/unable-to-do-match-query-with-new-java-api-client/337065)

<div class="topic-metadata">

**Author:** [@p4charu](https://discuss.elastic.co/u/p4charu)\
**Replies:** 4\
**Last updated:** [June 28, 2023, 2:37pm UTC](https://discuss.elastic.co/t/unable-to-do-match-query-with-new-java-api-client/337065 "2023-06-28T14:37:03Z")

</div>

Hello! I am trying to do a match query similar to one below: "query": { "bool": { "must": \[ { "match": { "detected.tag": "chair" } } \] } } } This query gives me expec…

---

## [Store apm agent log in file](https://discuss.elastic.co/t/store-apm-agent-log-in-file/337099)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 2:33pm UTC](https://discuss.elastic.co/t/store-apm-agent-log-in-file/337099 "2023-06-28T14:33:41Z")

</div>

Hi Normally APM work like this: APMAgent\>APMServer\>Elastic\>kibana 1-Is it possible to store APMAgent log in file after that import in Elastic? Like this APMAgent\>file 2-Then feed log file to APMServer file\>APMServe…

---

## [Missing some machine learning jobs](https://discuss.elastic.co/t/missing-some-machine-learning-jobs/335678)

<div class="topic-metadata">

**Author:** [@queried1](https://discuss.elastic.co/u/queried1)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 2:28pm UTC](https://discuss.elastic.co/t/missing-some-machine-learning-jobs/335678 "2023-06-28T14:28:40Z")

</div>

Hello! Recently I noticed that some ML jobs that start with "v3..." are missing. I can find other jobs that start with "v2..." under Machine Learning \> Anomaly Detection \> Jobs, but not "v3...". Some rules complain tha…

---

## [Docker integration not collecting logs](https://discuss.elastic.co/t/docker-integration-not-collecting-logs/337096)

<div class="topic-metadata">

**Author:** [@glenbot](https://discuss.elastic.co/u/glenbot)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 2:12pm UTC](https://discuss.elastic.co/t/docker-integration-not-collecting-logs/337096 "2023-06-28T14:12:44Z")

</div>

The docker integration is collecting metrics perfectly but not logs. Versions: Agent: 8.7.1 Docker Integration: 2.6.0 I have tried changing the container log path to: /var/lib/docker/containers//-json.log and /var…

---

## [Rsyslog logs stop when any security is enabled](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869)

<div class="topic-metadata">

**Author:** [@Ryan\_Caputo](https://discuss.elastic.co/u/Ryan_Caputo)\
**Replies:** 7\
**Last updated:** [June 28, 2023, 2:04pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869 "2023-06-28T14:04:29Z")

</div>

I have installed ELK 7.17.10 with podman, it works until I turn on security, even minimal security seems to block rsyslog from being received. What am I missing?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=494)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=496)
