# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=498

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 499

---

## [.security-7 can't create replicas in elasticsearch 7.17.10](https://discuss.elastic.co/t/security-7-cant-create-replicas-in-elasticsearch-7-17-10/336936)

<div class="topic-metadata">

**Author:** [@Han2](https://discuss.elastic.co/u/Han2)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 2:06am UTC](https://discuss.elastic.co/t/security-7-cant-create-replicas-in-elasticsearch-7-17-10/336936 "2023-06-27T02:06:59Z")

</div>

My cluster statu is yellow ,When i add new node to my cluster I use this order \_cluster/allocation/explain to exlpian this error and i don't know how to do someone can help me? PLZ

---

## [Performance hit when multiple filebeats are sending to same ES](https://discuss.elastic.co/t/performance-hit-when-multiple-filebeats-are-sending-to-same-es/335493)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 22\
**Last updated:** [June 27, 2023, 1:09am UTC](https://discuss.elastic.co/t/performance-hit-when-multiple-filebeats-are-sending-to-same-es/335493 "2023-06-27T01:09:44Z")

</div>

Hi, I have a total of 5 servers, all sending Netflow data using filebeat to the same server (1 of the 5 servers) running ES. Each server is also running 2 instances of filebeat, so in total, I have 5 x 2 filebeat instan…

---

## [Excluding all fields from object property except for one (4096 byte limit error for large URI)](https://discuss.elastic.co/t/excluding-all-fields-from-object-property-except-for-one-4096-byte-limit-error-for-large-uri/336934)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 4\
**Last updated:** [June 26, 2023, 11:37pm UTC](https://discuss.elastic.co/t/excluding-all-fields-from-object-property-except-for-one-4096-byte-limit-error-for-large-uri/336934 "2023-06-26T23:37:07Z")

</div>

Hi, I'm trying to get ES to return me only currency in the example below in a concise way. The currency field: hits.hits.\_source.attributes.currency For the sake of the example I also have properties like this: hits…

---

## [Enrich vs Transform with 2 source indices](https://discuss.elastic.co/t/enrich-vs-transform-with-2-source-indices/336344)

<div class="topic-metadata">

**Author:** [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 11:17pm UTC](https://discuss.elastic.co/t/enrich-vs-transform-with-2-source-indices/336344 "2023-06-26T23:17:05Z")

</div>

Hi! I am faced with a situation where I am not sure whether an enrich processor or a transform should be used. In my situation, I have sensors sending events in batch to Elastic. Each sensor has a sensor\_key and the eve…

---

## [Filebeat handle multiline](https://discuss.elastic.co/t/filebeat-handle-multiline/334742)

<div class="topic-metadata">

**Author:** [@emily3](https://discuss.elastic.co/u/emily3)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-handle-multiline/334742 "2023-06-26T22:26:54Z")

</div>

we have some logs. most of them are constructed, but for the traceback it was unconstructed and seperated in the log, such as \* 2023-05-30T20:52:15.545314-04:00 ssnode-proxy-1202-f09-2 proxy-server: err STDERR: Tracebac…

---

## [Converting filebeat message with logstash](https://discuss.elastic.co/t/converting-filebeat-message-with-logstash/336931)

<div class="topic-metadata">

**Author:** [@fizem](https://discuss.elastic.co/u/fizem)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 9:32pm UTC](https://discuss.elastic.co/t/converting-filebeat-message-with-logstash/336931 "2023-06-26T21:32:37Z")

</div>

Hi, I have setup filebeat to parse my API logs and send messages to a centralized logstash cluster. filebeat will collect all the logs with a minimum CPU consumption. logstash can transform the data, define multiple …

---

## [ERROR instance/beat.go:1027 Exiting: 1 error: error loading config file: invalid config: yaml: line 85: did not find expected key Exiting: 1 error: error loading config file: invalid config: yaml: line 85: did not find expected key](https://discuss.elastic.co/t/error-instance-beat-go-1027-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key/335171)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 27\
**Last updated:** [June 26, 2023, 8:02pm UTC](https://discuss.elastic.co/t/error-instance-beat-go-1027-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key/335171 "2023-06-26T20:02:08Z")

</div>

I have configured my filebeat.yml as follows : ###################### Filebeat Configuration Example ######################### # This file is an example configuration file highlighting only the most common # options. T…

---

## [Logs does not show in kibana](https://discuss.elastic.co/t/logs-does-not-show-in-kibana/334519)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 13\
**Last updated:** [June 26, 2023, 7:54pm UTC](https://discuss.elastic.co/t/logs-does-not-show-in-kibana/334519 "2023-06-26T19:54:18Z")

</div>

Hi - I am having a little trouble pulling the logs to my Elasticsearch; currently, as I am on the main page, from the Discover menu , nothing shows up. I have Winlogbeat and sysmon installed as a service on my Windows ma…

---

## [Could not validate a connection to the.... No alive nodes found in your cluster](https://discuss.elastic.co/t/could-not-validate-a-connection-to-the-no-alive-nodes-found-in-your-cluster/336928)

<div class="topic-metadata">

**Author:** [@codepan](https://discuss.elastic.co/u/codepan)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 7:39pm UTC](https://discuss.elastic.co/t/could-not-validate-a-connection-to-the-no-alive-nodes-found-in-your-cluster/336928 "2023-06-26T19:39:17Z")

</div>

Estou tendo fazer uma instalação do magento 2.4.6, mas estou recebendo esse erro na instalação. ● elasticsearch.service - Elasticsearch Loaded: loaded (/etc/systemd/system/elasticsearch.service; enabled; vendor preset…

---

## [Elasticsearch query to match all tokens inside a specific field](https://discuss.elastic.co/t/elasticsearch-query-to-match-all-tokens-inside-a-specific-field/336927)

<div class="topic-metadata">

**Author:** [@vsha041](https://discuss.elastic.co/u/vsha041)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 7:17pm UTC](https://discuss.elastic.co/t/elasticsearch-query-to-match-all-tokens-inside-a-specific-field/336927 "2023-06-26T19:17:21Z")

</div>

We have a scenario where for one of the fields of the index should contain all the words in order for that field to be treated as a match. Whereas other fields can contain the rest of search query. Here are few examples.…

---

## [Re-index using a Machine Learning with custom Trained Models](https://discuss.elastic.co/t/re-index-using-a-machine-learning-with-custom-trained-models/336711)

<div class="topic-metadata">

**Author:** [@Lone\_Eagle](https://discuss.elastic.co/u/Lone_Eagle)\
**Replies:** 5\
**Last updated:** [June 26, 2023, 5:14pm UTC](https://discuss.elastic.co/t/re-index-using-a-machine-learning-with-custom-trained-models/336711 "2023-06-26T17:14:19Z")

</div>

We have currently a Production Elasticsearch using Elastic Cloud and want to experiment vectors using a Machine Learning with a custom trained model. Machine Learning Configuration: 32 GB RAM | 16.9 vCPU As a pipeline…

---

## [Filebeat create new index at every x hours](https://discuss.elastic.co/t/filebeat-create-new-index-at-every-x-hours/336924)

<div class="topic-metadata">

**Author:** [@6NMgfDwZ3](https://discuss.elastic.co/u/6NMgfDwZ3)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 5:37pm UTC](https://discuss.elastic.co/t/filebeat-create-new-index-at-every-x-hours/336924 "2023-06-26T17:37:53Z")

</div>

Hi all! The storage under ELK is limited, and can't be increased. So I need to delete indexes very often but deleting one-day indexes would result in the unnecessary loss of a massive amount of documents therefore I nee…

---

## [Date range missing in discover section of kibana](https://discuss.elastic.co/t/date-range-missing-in-discover-section-of-kibana/336913)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 5\
**Last updated:** [June 26, 2023, 5:33pm UTC](https://discuss.elastic.co/t/date-range-missing-in-discover-section-of-kibana/336913 "2023-06-26T17:33:04Z")

</div>

Hi, when I select my index, date range part(near refresh button) gets removed from the display and I only see KQL search field. stack version 7.17.3

---

## [Need to use java jdk 11 on elasticsearch 7](https://discuss.elastic.co/t/need-to-use-java-jdk-11-on-elasticsearch-7/336923)

<div class="topic-metadata">

**Author:** [@adevbrought](https://discuss.elastic.co/u/adevbrought)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 5:31pm UTC](https://discuss.elastic.co/t/need-to-use-java-jdk-11-on-elasticsearch-7/336923 "2023-06-26T17:31:20Z")

</div>

What is the best way to setup install elasticsearch 7 on ec2 with jdk 11 in ansible playbook?

---

## [Setup\_ssl error](https://discuss.elastic.co/t/setup-ssl-error/336840)

<div class="topic-metadata">

**Author:** [@Lampros](https://discuss.elastic.co/u/Lampros)\
**Replies:** 7\
**Last updated:** [June 26, 2023, 3:41pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840 "2023-06-26T15:41:57Z")

</div>

Hello, I am a little bit lost on this topic. I have a container which is running logstash. What I am trying to do is to use the output syslog module to send logs to a third party application over ssl. But it fails wi…

---

## [NodeJS proxy](https://discuss.elastic.co/t/nodejs-proxy/336921)

<div class="topic-metadata">

**Author:** [@sasheks](https://discuss.elastic.co/u/sasheks)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 4:01pm UTC](https://discuss.elastic.co/t/nodejs-proxy/336921 "2023-06-26T16:01:20Z")

</div>

Hello, hopefully posting this in the correct section. Is there a "recommended" or "best way" to configure a proxy for the agent when using the "elastic-apm-node" package? I couldn't find anything official in the documen…

---

## [Kibana usage statistics / logging](https://discuss.elastic.co/t/kibana-usage-statistics-logging/336788)

<div class="topic-metadata">

**Author:** [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 3:01pm UTC](https://discuss.elastic.co/t/kibana-usage-statistics-logging/336788 "2023-06-26T15:01:05Z")

</div>

Is there anywhere to enable and then view usage statistics / logging in Kibana? I'm wondering how many users are using it, what dashboards they're using, what discover queries, etc.

---

## [Cannot use regex in metrics visualizations](https://discuss.elastic.co/t/cannot-use-regex-in-metrics-visualizations/336616)

<div class="topic-metadata">

**Author:** [@mdcorby](https://discuss.elastic.co/u/mdcorby)\
**Replies:** 4\
**Last updated:** [June 26, 2023, 2:55pm UTC](https://discuss.elastic.co/t/cannot-use-regex-in-metrics-visualizations/336616 "2023-06-26T14:55:40Z")

</div>

Hi, I am trying to set up visualizations by metrics that show a count of unique objects shared between JSON files that are in the same index. I have been able to achieve this by using metrics formulas. My problem persis…

---

## [Index not creating for filebeat](https://discuss.elastic.co/t/index-not-creating-for-filebeat/336908)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 1:28pm UTC](https://discuss.elastic.co/t/index-not-creating-for-filebeat/336908 "2023-06-26T13:28:41Z")

</div>

not able to create index in kibana getting below error {"log.level":"info","@timestamp":"2023-06-26T18:43:27.607+0530","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zer…

---

## [Giving ES big amount of heap space](https://discuss.elastic.co/t/giving-es-big-amount-of-heap-space/336877)

<div class="topic-metadata">

**Author:** [@mzhaqs](https://discuss.elastic.co/u/mzhaqs)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 1:21pm UTC](https://discuss.elastic.co/t/giving-es-big-amount-of-heap-space/336877 "2023-06-26T13:21:31Z")

</div>

We have a pod with ES 5.6.16 container running in Kubernetes cluster. Only one instance running. Can not update the version or horizontally scale. This poor instance needs to deal with significant amount of load. Gave it…

---

## [Discover bar chart not showing](https://discuss.elastic.co/t/discover-bar-chart-not-showing/336900)

<div class="topic-metadata">

**Author:** [@balupad14](https://discuss.elastic.co/u/balupad14)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 1:22pm UTC](https://discuss.elastic.co/t/discover-bar-chart-not-showing/336900 "2023-06-26T13:22:34Z")

</div>

I have an Index called "DemoIndex". I am inserting the below index post /DemoIndex/\_doc { "processCode": "ADPROJ", "processName": "Admin process", "manualDuration": 0, "tableName": "tblProcess", "timestamp": "2023…

---

## [Curl -X GET 'https://localhost:9200'](https://discuss.elastic.co/t/curl-x-get-https-localhost-9200/336624)

<div class="topic-metadata">

**Author:** [@codepan](https://discuss.elastic.co/u/codepan)\
**Replies:** 16\
**Last updated:** [June 26, 2023, 1:07pm UTC](https://discuss.elastic.co/t/curl-x-get-https-localhost-9200/336624 "2023-06-26T13:07:25Z")

</div>

curl -X GET 'https://localhost:9200' curl: (60) Peer's certificate issuer has been marked as not trusted by the user. More details here: http://curl.haxx.se/docs/sslcerts.html curl performs SSL certificate verification…

---

## [Repository\_verification\_exception](https://discuss.elastic.co/t/repository-verification-exception/336859)

<div class="topic-metadata">

**Author:** [@tungnx1](https://discuss.elastic.co/u/tungnx1)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 12:55pm UTC](https://discuss.elastic.co/t/repository-verification-exception/336859 "2023-06-26T12:55:02Z")

</div>

Hi, I cannot create repo, before that i made a normal backup and restore. However after reconfiguring elasticsearch.yml: Master nodes: voting only Data 1: master I then try to do it at repo creation but get below e…

---

## [cURL does not download the Elastic Agent, only on one of our sites in Amsterdam (otherwise cURL works fine)](https://discuss.elastic.co/t/curl-does-not-download-the-elastic-agent-only-on-one-of-our-sites-in-amsterdam-otherwise-curl-works-fine/336837)

<div class="topic-metadata">

**Author:** [@SedonD](https://discuss.elastic.co/u/SedonD)\
**Replies:** 9\
**Last updated:** [June 26, 2023, 12:37pm UTC](https://discuss.elastic.co/t/curl-does-not-download-the-elastic-agent-only-on-one-of-our-sites-in-amsterdam-otherwise-curl-works-fine/336837 "2023-06-26T12:37:39Z")

</div>

Hi there, Has anyone ever encountered this issue, if so we would appreciate some guidance? Thanks in advance, Br, SedonD ++++edit: What I have seen so far....(something like this) and/or

---

## [Save timeline in Kibana 8.8.0](https://discuss.elastic.co/t/save-timeline-in-kibana-8-8-0/336381)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 12:34pm UTC](https://discuss.elastic.co/t/save-timeline-in-kibana-8-8-0/336381 "2023-06-26T12:34:14Z")

</div>

Hello everyone, after updating the elastic stack to 8.8.0 it is often not possible to save a timeline. It happens after I have been investigating with an untitled timeline. Once I decide to give it a title to save it j…

---

## [Rename a field](https://discuss.elastic.co/t/rename-a-field/336901)

<div class="topic-metadata">

**Author:** [@Rihab1](https://discuss.elastic.co/u/Rihab1)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 12:24pm UTC](https://discuss.elastic.co/t/rename-a-field/336901 "2023-06-26T12:24:14Z")

</div>

Hello, I want to rename a field which is the result of static filter. it contains many values, I used "Rename" but it didn't work. The field current name is: previous.employeeid

---

## [Elastic Fireall Port 9200](https://discuss.elastic.co/t/elastic-fireall-port-9200/336714)

<div class="topic-metadata">

**Author:** [@codepan](https://discuss.elastic.co/u/codepan)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 11:57am UTC](https://discuss.elastic.co/t/elastic-fireall-port-9200/336714 "2023-06-26T11:57:57Z")

</div>

Como vinculo o Elastic no firewall e a porta 9200? public target: default icmp-block-inversion: no interfaces: sources: services: dhcpv6-client ssh ports: 9200/tcp protocols: masquerade: no forward-por…

---

## [Pull data from Snowflake Database Tables to Elasticsearch using Logstash](https://discuss.elastic.co/t/pull-data-from-snowflake-database-tables-to-elasticsearch-using-logstash/336869)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 11:07am UTC](https://discuss.elastic.co/t/pull-data-from-snowflake-database-tables-to-elasticsearch-using-logstash/336869 "2023-06-26T11:07:46Z")

</div>

Hi Team, Can anyone let know how can we pull data from snowflake tables (Saas based solution) to Elasticsearch onpremise using Logstash Thanks in advance.

---

## [High CPU after updating Filebeat from version 7.12.0 to 8.8.1](https://discuss.elastic.co/t/high-cpu-after-updating-filebeat-from-version-7-12-0-to-8-8-1/336897)

<div class="topic-metadata">

**Author:** [@germain\_nganko](https://discuss.elastic.co/u/germain_nganko)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 10:59am UTC](https://discuss.elastic.co/t/high-cpu-after-updating-filebeat-from-version-7-12-0-to-8-8-1/336897 "2023-06-26T10:59:37Z")

</div>

Description: After updating filebeat from version 7.12.0 to 8.8.1 we started observing high cpu usage. We disabled the cronjob and deployment resources medata on purpose thinking it will help but it didn't really help. A…

---

## [How to prevent a duplcation of collecting logs](https://discuss.elastic.co/t/how-to-prevent-a-duplcation-of-collecting-logs/336881)

<div class="topic-metadata">

**Author:** [@shlee](https://discuss.elastic.co/u/shlee)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 8:42am UTC](https://discuss.elastic.co/t/how-to-prevent-a-duplcation-of-collecting-logs/336881 "2023-06-26T08:42:37Z")

</div>

Hi, everyone I'm using an aws integration on elastic agent to gather logs from aws cloudwatch start position is "beginning"(default value) When a server where an aws integration is installed downs for a while and st…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=497)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=499)
