# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=500

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 501

---

## [How to extract string from the log and create a new field and send to elastic search index](https://discuss.elastic.co/t/how-to-extract-string-from-the-log-and-create-a-new-field-and-send-to-elastic-search-index/336797)

<div class="topic-metadata">

**Author:** [@mbsarathchandra](https://discuss.elastic.co/u/mbsarathchandra)\
**Replies:** 2\
**Last updated:** [June 25, 2023, 1:02am UTC](https://discuss.elastic.co/t/how-to-extract-string-from-the-log-and-create-a-new-field-and-send-to-elastic-search-index/336797 "2023-06-25T01:02:46Z")

</div>

Hello Everyone, I am currently using Elastic Search Version 8.8.1 installed on RHEL os. Filebeat Version: 8.6.1 The logs are read from the Application server and pushed to Elasticsearch index using filebeat. Data str…

---

## [The es java client version has been upgraded from 7 to 8, and the syntax has changed significantly](https://discuss.elastic.co/t/the-es-java-client-version-has-been-upgraded-from-7-to-8-and-the-syntax-has-changed-significantly/336809)

<div class="topic-metadata">

**Author:** [@nzb](https://discuss.elastic.co/u/nzb)\
**Replies:** 2\
**Last updated:** [June 25, 2023, 12:57am UTC](https://discuss.elastic.co/t/the-es-java-client-version-has-been-upgraded-from-7-to-8-and-the-syntax-has-changed-significantly/336809 "2023-06-25T00:57:51Z")

</div>

I recently upgraded the es java client version from 7.9.3 to 8.5.3. The syntax has changed significantly. We spent several days modifying the syntax to be compatible, and the regression test took several days. After two …

---

## [Mutate - add\_field - only shows string not the value](https://discuss.elastic.co/t/mutate-add-field-only-shows-string-not-the-value/336816)

<div class="topic-metadata">

**Author:** [@humblemags](https://discuss.elastic.co/u/humblemags)\
**Replies:** 2\
**Last updated:** [June 24, 2023, 8:37pm UTC](https://discuss.elastic.co/t/mutate-add-field-only-shows-string-not-the-value/336816 "2023-06-24T20:37:34Z")

</div>

Hi, I am using Windows 10 with 7.17.6 on localhost install. Filebeat is input being sent to Logstash. Yes, I know the json parser will handle this for me. But I do not understand why "someNewField" does not have the v…

---

## [Include/exclude specific fields](https://discuss.elastic.co/t/include-exclude-specific-fields/336817)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 0\
**Last updated:** [June 24, 2023, 4:28pm UTC](https://discuss.elastic.co/t/include-exclude-specific-fields/336817 "2023-06-24T16:28:39Z")

</div>

My index's documents looks like that: { "sku": "1234567890", "name": "my\_name", "lng:en\_AE:name": "my\_name\_in\_AE", "lng:en\_AE:price": 10.99, "lng:en\_BH:name": "my\_name\_in\_BH", …

---

## [Logstash date timezone](https://discuss.elastic.co/t/logstash-date-timezone/336803)

<div class="topic-metadata">

**Author:** [@Mahdi\_Davoodi](https://discuss.elastic.co/u/Mahdi_Davoodi)\
**Replies:** 6\
**Last updated:** [June 24, 2023, 3:00pm UTC](https://discuss.elastic.co/t/logstash-date-timezone/336803 "2023-06-24T15:00:14Z")

</div>

I want to parse date-time records with logstash date filter. My records have Asia/Tehran time zone. After the recent changes in the time zone in Iran and the removal of DST from it, apparently my date of records does no…

---

## [Multi field match with boosting and fuzziness](https://discuss.elastic.co/t/multi-field-match-with-boosting-and-fuzziness/336806)

<div class="topic-metadata">

**Author:** [@Tim6](https://discuss.elastic.co/u/Tim6)\
**Replies:** 2\
**Last updated:** [June 24, 2023, 2:56pm UTC](https://discuss.elastic.co/t/multi-field-match-with-boosting-and-fuzziness/336806 "2023-06-24T14:56:13Z")

</div>

Hi, Say I have a database of car models containing brand and model Brand Model Foo Bar Foo Baz So if I search for a Foo Bar I want only the first document to match. If I search for just Foo both documents …

---

## [Can we use ElasticSearch of 2.3 version?](https://discuss.elastic.co/t/can-we-use-elasticsearch-of-2-3-version/336556)

<div class="topic-metadata">

**Author:** [@sanjay\_bhati](https://discuss.elastic.co/u/sanjay_bhati)\
**Replies:** 3\
**Last updated:** [June 24, 2023, 1:56pm UTC](https://discuss.elastic.co/t/can-we-use-elasticsearch-of-2-3-version/336556 "2023-06-24T13:56:21Z")

</div>

Hi Team, I need help to understand, In ES plugin we need username and password but my Elasticsearch is old version so not able to get username and passsword so in this case how I can use ES as input plugin ?

---

## [ES sending multiple API query calls for a single query request for Dashboard](https://discuss.elastic.co/t/es-sending-multiple-api-query-calls-for-a-single-query-request-for-dashboard/336805)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [June 24, 2023, 1:35pm UTC](https://discuss.elastic.co/t/es-sending-multiple-api-query-calls-for-a-single-query-request-for-dashboard/336805 "2023-06-24T13:35:19Z")

</div>

Hi all, I'm using Kibana & ES for building a dashboard. I have allotted 8GB of memory heap space for my ES which I feel is quite enough. One of my data tables has slightly high number of documents i.e 14,000 documents…

---

## [Named query in hybrid queries](https://discuss.elastic.co/t/named-query-in-hybrid-queries/336608)

<div class="topic-metadata">

**Author:** [@Ali\_Nazari](https://discuss.elastic.co/u/Ali_Nazari)\
**Replies:** 4\
**Last updated:** [June 24, 2023, 10:54am UTC](https://discuss.elastic.co/t/named-query-in-hybrid-queries/336608 "2023-06-24T10:54:06Z")

</div>

How can I recognize which of my elasticsearch hits are because of my KNN and which are related to the query part? I don't know where to use a named query in KNN part. GET post-vector/\_search { "query": { "bool": {…

---

## [Use DiscoverGridFlyout of discover-plugin in custom plugin](https://discuss.elastic.co/t/use-discovergridflyout-of-discover-plugin-in-custom-plugin/336807)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [June 24, 2023, 9:47am UTC](https://discuss.elastic.co/t/use-discovergridflyout-of-discover-plugin-in-custom-plugin/336807 "2023-06-24T09:47:51Z")

</div>

Hi, I am developing a custom Kibana plugin in React. I want to use the DiscoverGridFlyout within the Discover plugin inside my plugin. I found this Github feature link for the same (\[Discover\] Extract DiscoverGridFlyou…

---

## [Nodes are offline](https://discuss.elastic.co/t/nodes-are-offline/335716)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 9\
**Last updated:** [June 24, 2023, 8:25am UTC](https://discuss.elastic.co/t/nodes-are-offline/335716 "2023-06-24T08:25:37Z")

</div>

Hi, dears. I deployed a 3-node elastic cluster with default docker-compose in the Elastic document. but expect the master node, other nodes are offline. Are there any additional settings that I have to do? also why m…

---

## [Supporting different calendars, like Jalali (persian) calendar](https://discuss.elastic.co/t/supporting-different-calendars-like-jalali-persian-calendar/336433)

<div class="topic-metadata">

**Author:** [@nevahid](https://discuss.elastic.co/u/nevahid)\
**Replies:** 5\
**Last updated:** [June 24, 2023, 4:40am UTC](https://discuss.elastic.co/t/supporting-different-calendars-like-jalali-persian-calendar/336433 "2023-06-24T04:40:20Z")

</div>

is it possible to filter dates based on different calendar type? i mean instead of Gregorian date, we use Jalali (Shamsi) calendar, where month names and days are different. i would be very grateful if you can help me. …

---

## [Integrations Page in Kibana is too slow and constantly have timeout erros](https://discuss.elastic.co/t/integrations-page-in-kibana-is-too-slow-and-constantly-have-timeout-erros/336785)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [June 24, 2023, 2:41am UTC](https://discuss.elastic.co/t/integrations-page-in-kibana-is-too-slow-and-constantly-have-timeout-erros/336785 "2023-06-24T02:41:04Z")

</div>

Hello, Almost every time I need to use the Integration pages to add a new Integration to the Elastic Agent or update the current ones I have some issues with being too slow or even timing out. I started using Integrati…

---

## [.NET: Using newer NEST high-level client against previous version of Elasticsearch](https://discuss.elastic.co/t/net-using-newer-nest-high-level-client-against-previous-version-of-elasticsearch/336613)

<div class="topic-metadata">

**Author:** [@Thomas\_Doman](https://discuss.elastic.co/u/Thomas_Doman)\
**Replies:** 6\
**Last updated:** [June 23, 2023, 7:43pm UTC](https://discuss.elastic.co/t/net-using-newer-nest-high-level-client-against-previous-version-of-elasticsearch/336613 "2023-06-23T19:43:25Z")

</div>

NEST: 6.8.6 Elasticsearch: 6.8.23 We're looking to upgrade our Elasticsearch clusters now that we're on ECK (hallelujah!). Our .NET code uses NEST and I'd like to try the NEST 7.17.5 NuGet package without upgrading ou…

---

## [How to connect ES8.8 through TCP port & certificate in java?](https://discuss.elastic.co/t/how-to-connect-es8-8-through-tcp-port-certificate-in-java/336793)

<div class="topic-metadata">

**Author:** [@Jignesh\_Soni](https://discuss.elastic.co/u/Jignesh_Soni)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 7:40pm UTC](https://discuss.elastic.co/t/how-to-connect-es8-8-through-tcp-port-certificate-in-java/336793 "2023-06-23T19:40:35Z")

</div>

Hi Experts, i am able to connect the ES7.17 through tcp port , but in ES 8.8 library there is no class to connect tcp port. Some code snippet is working in ES 7.17: Client getClient() { Settings settings = Settings.…

---

## [Kibana EVP\_DecryptFinal Error - OpenSSL Version?](https://discuss.elastic.co/t/kibana-evp-decryptfinal-error-openssl-version/336783)

<div class="topic-metadata">

**Author:** [@josh42](https://discuss.elastic.co/u/josh42)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 6:22pm UTC](https://discuss.elastic.co/t/kibana-evp-decryptfinal-error-openssl-version/336783 "2023-06-23T18:22:49Z")

</div>

I'm trying to set up Kibana's server SSL and keep encountering an error related to decrypting the certificate. I created my certs through openssl, and Googling indicates an openssl mismatch might be causing this error. I…

---

## [\[ERROR\]\[logstash.filters.aggregate\]\[main\]Aggregate exception occurred {:error=\>#\<NoMethodError: undefined method \`+' for nil:NilClass\>](https://discuss.elastic.co/t/error-logstash-filters-aggregate-main-aggregate-exception-occurred-error-nomethoderror-undefined-method-for-nil-nilclass/336741)

<div class="topic-metadata">

**Author:** [@Ceyhun\_Quliyev](https://discuss.elastic.co/u/Ceyhun_Quliyev)\
**Replies:** 2\
**Last updated:** [June 23, 2023, 4:25pm UTC](https://discuss.elastic.co/t/error-logstash-filters-aggregate-main-aggregate-exception-occurred-error-nomethoderror-undefined-method-for-nil-nilclass/336741 "2023-06-23T16:25:51Z")

</div>

Dear forum members, We have encountered a problem and cannot solve it. I would be grateful if you could help us with a solution. Below I am providing a link to the configuration file itself and the error logs.

---

## [Access fields from input plugin (cloudwatch\_logs\_importer)](https://discuss.elastic.co/t/access-fields-from-input-plugin-cloudwatch-logs-importer/336585)

<div class="topic-metadata">

**Author:** [@Maarten\_Dekker](https://discuss.elastic.co/u/Maarten_Dekker)\
**Replies:** 19\
**Last updated:** [June 23, 2023, 4:13pm UTC](https://discuss.elastic.co/t/access-fields-from-input-plugin-cloudwatch-logs-importer/336585 "2023-06-23T16:13:27Z")

</div>

Hi, I am using the cloudwatch\_logs\_importer plugin to read and grok logs from cloudwatch. It all works fine, but I am facing issues to access a field which is created by the input module itself: \[cloudwatch\_logs\]\[log\_…

---

## [New node cannot join to the existing cluster](https://discuss.elastic.co/t/new-node-cannot-join-to-the-existing-cluster/336720)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 5\
**Last updated:** [June 23, 2023, 3:28pm UTC](https://discuss.elastic.co/t/new-node-cannot-join-to-the-existing-cluster/336720 "2023-06-23T15:28:39Z")

</div>

I have two servers for elasticsearch. After I installed the elasticsearch on one server, I started the service and ran /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node to generate an environmen…

---

## [Deployment disk usage](https://discuss.elastic.co/t/deployment-disk-usage/336778)

<div class="topic-metadata">

**Author:** [@pavlod](https://discuss.elastic.co/u/pavlod)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 3:16pm UTC](https://discuss.elastic.co/t/deployment-disk-usage/336778 "2023-06-23T15:16:17Z")

</div>

Hello! I'm using Elastic deployment with apps: Elasticsearch, Kibana, APM, Fleet, Enterprise Search. (All these apps located on one disk). So I need to set up an alert of disk space (90%). How and where can I do it? …

---

## [Logstash won't start as deamon](https://discuss.elastic.co/t/logstash-wont-start-as-deamon/336629)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [June 23, 2023, 2:51pm UTC](https://discuss.elastic.co/t/logstash-wont-start-as-deamon/336629 "2023-06-23T14:51:41Z")

</div>

I know I have seen this issue in past and was fixed by using different ls\_temp dir for logstash. but this time it won't work. here is error message. any idea? this dir /s1/log/logstash is wide open stat /s1/log/logst…

---

## [Prebuilt security rule not working with fleet architecture](https://discuss.elastic.co/t/prebuilt-security-rule-not-working-with-fleet-architecture/336779)

<div class="topic-metadata">

**Author:** [@kfdl](https://discuss.elastic.co/u/kfdl)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 2:16pm UTC](https://discuss.elastic.co/t/prebuilt-security-rule-not-working-with-fleet-architecture/336779 "2023-06-23T14:16:31Z")

</div>

Hello All, first of all thank you for this product, your support and your time. :slight\_smile: I am using the Elastic Stack for a couple month to gather all the logs of my servers and i'm using the fleet server to enro…

---

## [ECS Format and Index Mappings](https://discuss.elastic.co/t/ecs-format-and-index-mappings/336740)

<div class="topic-metadata">

**Author:** [@lxk3](https://discuss.elastic.co/u/lxk3)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 1:59pm UTC](https://discuss.elastic.co/t/ecs-format-and-index-mappings/336740 "2023-06-23T13:59:57Z")

</div>

Hello there, we want to use the ECS log format for our new applications. We already use datastreams with index templates and predefined mappings and I was wondering if we need to write a new mapping for ECS or if there …

---

## [Multiple tables as jdbc input in logstash pipeline](https://discuss.elastic.co/t/multiple-tables-as-jdbc-input-in-logstash-pipeline/336724)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 1:58pm UTC](https://discuss.elastic.co/t/multiple-tables-as-jdbc-input-in-logstash-pipeline/336724 "2023-06-23T13:58:09Z")

</div>

I have 4 tables in oracle database and have a SQL query beginning with CTS (Common Table Expressions) which combines and creates a new single table. I want to create a pipeline using jdbc input and read date once in a …

---

## [How can change the data node to master node?](https://discuss.elastic.co/t/how-can-change-the-data-node-to-master-node/336770)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 7\
**Last updated:** [June 23, 2023, 1:46pm UTC](https://discuss.elastic.co/t/how-can-change-the-data-node-to-master-node/336770 "2023-06-23T13:46:29Z")

</div>

I have 3 data node, so I want to change the one node for master and another two nodes for data nodes.

---

## [Duplicate events user log in winlogbeat using drop event filter](https://discuss.elastic.co/t/duplicate-events-user-log-in-winlogbeat-using-drop-event-filter/336536)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 3\
**Last updated:** [June 23, 2023, 1:43pm UTC](https://discuss.elastic.co/t/duplicate-events-user-log-in-winlogbeat-using-drop-event-filter/336536 "2023-06-23T13:43:45Z")

</div>

Hello all, What I want to achieve is to remove the duplicate events. How should I do that? I am stuck here. Here is the scenario: When I successfully login into my lab computer there is the event ID 4672 that duplica…

---

## [How to pass the value of filter group, in the canvas expression editor](https://discuss.elastic.co/t/how-to-pass-the-value-of-filter-group-in-the-canvas-expression-editor/336773)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 12:43pm UTC](https://discuss.elastic.co/t/how-to-pass-the-value-of-filter-group-in-the-canvas-expression-editor/336773 "2023-06-23T12:43:55Z")

</div>

I have created a dropdown in canvas workpad, having values of company.name field. The name of the filterGroup is customerGroup Lets say the values in the dropdown are: "xyz" and "ABC" I want to show the asset only if t…

---

## [Change index name within filebeats module file](https://discuss.elastic.co/t/change-index-name-within-filebeats-module-file/336772)

<div class="topic-metadata">

**Author:** [@jazzl0ver](https://discuss.elastic.co/u/jazzl0ver)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 12:31pm UTC](https://discuss.elastic.co/t/change-index-name-within-filebeats-module-file/336772 "2023-06-23T12:31:02Z")

</div>

Hi, Filebeat version is 7.10.2 According to Configuring Input Type for Filebeat Module I was trying to do the same for the index: # cat /etc/filebeat/modules.d/haproxy.yml # Module: haproxy # Docs: https://www.elastic…

---

## [How to Remove Gaps between graphs, once hour filter is applied](https://discuss.elastic.co/t/how-to-remove-gaps-between-graphs-once-hour-filter-is-applied/336530)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 9\
**Last updated:** [June 23, 2023, 12:17pm UTC](https://discuss.elastic.co/t/how-to-remove-gaps-between-graphs-once-hour-filter-is-applied/336530 "2023-06-23T12:17:20Z")

</div>

Hello Team, I have been trying to put filter of hour on my graphical dashboard, which I did by putting a scripted field of Hour, and the same I have added as filter on my graphical dashboard However, their are gaps …

---

## [Count arrays as an object](https://discuss.elastic.co/t/count-arrays-as-an-object/336626)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:57am UTC](https://discuss.elastic.co/t/count-arrays-as-an-object/336626 "2023-06-23T11:57:56Z")

</div>

Hi, I am struggling to get an aggregation to work. We have an array with multiple values and what I am trying to do is count (and return the values) how many documents have the exact same set of values in the array. The…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=499)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=501)
