# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=502

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 503

---

## [App search filters not working](https://discuss.elastic.co/t/app-search-filters-not-working/336697)

<div class="topic-metadata">

**Author:** [@teoman\_kirac](https://discuss.elastic.co/u/teoman_kirac)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 1:12pm UTC](https://discuss.elastic.co/t/app-search-filters-not-working/336697 "2023-06-22T13:12:57Z")

</div>

Hi All! And thanks in advance for helping me troubleshoot :slight\_smile: I am using app search with a gcp firestore search extension. ANd it automagically cruds according to my collection, but I can't search with a geo\_…

---

## [Frequent shard failures](https://discuss.elastic.co/t/frequent-shard-failures/336358)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 6\
**Last updated:** [June 22, 2023, 1:02pm UTC](https://discuss.elastic.co/t/frequent-shard-failures/336358 "2023-06-22T13:02:19Z")

</div>

Hi, We are running a 3 node Elasticsearch Cluster on Elastic stack version 8.8.1. The nodes are running on 3 identical computers with SSD storage and 16GB RAM. The setup is being used to index Firewall logs. Node 1: es…

---

## [Forcing consistent response when using \_source](https://discuss.elastic.co/t/forcing-consistent-response-when-using-source/336693)

<div class="topic-metadata">

**Author:** [@mikkelduif](https://discuss.elastic.co/u/mikkelduif)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 12:54pm UTC](https://discuss.elastic.co/t/forcing-consistent-response-when-using-source/336693 "2023-06-22T12:54:02Z")

</div>

Hi there, I have a question about using the "\_source" field, where I have noticed that the response is not always consistent with the document, and would like to ask if there is some way to tweak the elasticsearch behav…

---

## [Unexpected character while posting a payload to elastic search via rest client](https://discuss.elastic.co/t/unexpected-character-while-posting-a-payload-to-elastic-search-via-rest-client/335802)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 2\
**Last updated:** [June 22, 2023, 12:53pm UTC](https://discuss.elastic.co/t/unexpected-character-while-posting-a-payload-to-elastic-search-via-rest-client/335802 "2023-06-22T12:53:25Z")

</div>

Hi, Hi, I am using 7.17.3 stack for elastic. Low level Elasticsearch rest client is from 7.15.2 I am trying to send a payload having special characters in it using the below code. Request request = new Request("PUT", …

---

## [High thread count with rest client](https://discuss.elastic.co/t/high-thread-count-with-rest-client/335801)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 13\
**Last updated:** [June 22, 2023, 12:52pm UTC](https://discuss.elastic.co/t/high-thread-count-with-rest-client/335801 "2023-06-22T12:52:08Z")

</div>

Hi, I am using 7.17.3 stack for elastic. Low level Elasticsearch rest client is from 7.15.2 I see very high waiting thread count when I build the client for each request and do that in try block so it gets auto closed…

---

## [Rollover Failure - Unable to auto set lifecycle.rollover\_alias after rollover - Moving to ERROR step](https://discuss.elastic.co/t/rollover-failure-unable-to-auto-set-lifecycle-rollover-alias-after-rollover-moving-to-error-step/336235)

<div class="topic-metadata">

**Author:** [@vedalas21](https://discuss.elastic.co/u/vedalas21)\
**Replies:** 8\
**Last updated:** [June 22, 2023, 12:48pm UTC](https://discuss.elastic.co/t/rollover-failure-unable-to-auto-set-lifecycle-rollover-alias-after-rollover-moving-to-error-step/336235 "2023-06-22T12:48:55Z")

</div>

Getting a "Moving to ERROR step" while rollover from an alias when "max\_age" paramter is met Steps to reproduce Create an Index Template { "name": "temp-test\_idx\_template", "index\_template": { "in…

---

## [Enabling X-Pack Security](https://discuss.elastic.co/t/enabling-x-pack-security/336684)

<div class="topic-metadata">

**Author:** [@tomer\_zamir](https://discuss.elastic.co/u/tomer_zamir)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 12:04pm UTC](https://discuss.elastic.co/t/enabling-x-pack-security/336684 "2023-06-22T12:04:49Z")

</div>

Hi, I just installed Elasticsearch on my ubuntu VM and I'm trying to run it for the first time but encountering errors. I'm doing everything according to this tutorial: digitalocean I added these lines: discovery.typ…

---

## [How injest darktrace SysLog Json to FIlebeat / Elasticseach](https://discuss.elastic.co/t/how-injest-darktrace-syslog-json-to-filebeat-elasticseach/336676)

<div class="topic-metadata">

**Author:** [@yari\_arcopinto](https://discuss.elastic.co/u/yari_arcopinto)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 11:11am UTC](https://discuss.elastic.co/t/how-injest-darktrace-syslog-json-to-filebeat-elasticseach/336676 "2023-06-22T11:11:58Z")

</div>

Hello team, I'm new on ELK Stack System, so i want to apologize if my questions will be stupid. I have installed succeffully the ELK stack system on a my server, and i have installed the agents on all my server. All is…

---

## [Kibana integration with react application without iframe](https://discuss.elastic.co/t/kibana-integration-with-react-application-without-iframe/336680)

<div class="topic-metadata">

**Author:** [@Rajiv\_Ranjan](https://discuss.elastic.co/u/Rajiv_Ranjan)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 11:55am UTC](https://discuss.elastic.co/t/kibana-integration-with-react-application-without-iframe/336680 "2023-06-22T11:55:05Z")

</div>

Hello All, I am trying to integrate Kibana dashboard with React application , Do we have any workaround for integration apart from iframe ?

---

## [Beat-xpack module doesn’t work on localhost 5066 port](https://discuss.elastic.co/t/beat-xpack-module-doesn-t-work-on-localhost-5066-port/334909)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 6\
**Last updated:** [June 22, 2023, 11:41am UTC](https://discuss.elastic.co/t/beat-xpack-module-doesn-t-work-on-localhost-5066-port/334909 "2023-06-22T11:41:11Z")

</div>

Hello, I am trying to use Beat Module for monitoring Metricbeat on Kibana-Stack Monitoring. I am using this in metricbeat.yml - module: beat xpack.enabled: true period: 10s hosts: \[ "http://localhost:5066…

---

## [Logstash conditional statement not working](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657)

<div class="topic-metadata">

**Author:** [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Replies:** 4\
**Last updated:** [June 22, 2023, 11:18am UTC](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657 "2023-06-22T11:18:14Z")

</div>

I want to use a conditional statement in my logstash config, so that syslogs are sent to "syslogindex" and other logs are sent to "testindex". I have tried multiple things, but It just does not work. This is my config: …

---

## [Does not have the remote cluster client role enabled\[Elasticserach, Kibana\]](https://discuss.elastic.co/t/does-not-have-the-remote-cluster-client-role-enabled-elasticserach-kibana/336671)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 10:52am UTC](https://discuss.elastic.co/t/does-not-have-the-remote-cluster-client-role-enabled-elasticserach-kibana/336671 "2023-06-22T10:52:19Z")

</div>

@dylan0911 I'm getting the following error on kibana, you have solved the problem before. what exactly do you do for solution your topic \[ERROR\]\[http\] ResponseError: illegal\_argument\_exception Root causes: …

---

## [Index numbers in strings as numeric and words](https://discuss.elastic.co/t/index-numbers-in-strings-as-numeric-and-words/336666)

<div class="topic-metadata">

**Author:** [@Michael\_Lockwood](https://discuss.elastic.co/u/Michael_Lockwood)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 10:33am UTC](https://discuss.elastic.co/t/index-numbers-in-strings-as-numeric-and-words/336666 "2023-06-22T10:33:45Z")

</div>

Hi, I have a requirement where I want to search for numbers within a string by both the numeric value (e.g. 3) and the string value (e.g. "three"). For example given the following index configuration PUT number-test { …

---

## [Logstash JDBC connection not sending request to Database custom port](https://discuss.elastic.co/t/logstash-jdbc-connection-not-sending-request-to-database-custom-port/336664)

<div class="topic-metadata">

**Author:** [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 10:11am UTC](https://discuss.elastic.co/t/logstash-jdbc-connection-not-sending-request-to-database-custom-port/336664 "2023-06-22T10:11:05Z")

</div>

When I I am trying to retrieve data from a MSSQL database , Logstash JDBC input not connecting to the required custom port 59237. Logstash only trying to connect port 3306. Mentioned the required port 59237 in Connectio…

---

## [Metricbeat get data of eck](https://discuss.elastic.co/t/metricbeat-get-data-of-eck/336663)

<div class="topic-metadata">

**Author:** [@Rick\_Vailer](https://discuss.elastic.co/u/Rick_Vailer)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 10:06am UTC](https://discuss.elastic.co/t/metricbeat-get-data-of-eck/336663 "2023-06-22T10:06:28Z")

</div>

Hello, We are in the process of monitoring an eck elasticsearch. Basically a metricbeat is already configured on the node worker were the eck is running. Is it possible to connect and pull metrics from this eck and ship…

---

## [Ask for help](https://discuss.elastic.co/t/ask-for-help/336655)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 9:19am UTC](https://discuss.elastic.co/t/ask-for-help/336655 "2023-06-22T09:19:27Z")

</div>

Good morning, i have a probelm in index elasticsearch elasticsearch.BadRequestError: BadRequestError(400, 'illegal\_argument\_exception', 'mapper \[doc.session\_id\] cannot be changed from type \[text\] to \[long\]') can anyone h…

---

## [Getting JSON data out of message field imported with filebeat](https://discuss.elastic.co/t/getting-json-data-out-of-message-field-imported-with-filebeat/335872)

<div class="topic-metadata">

**Author:** [@Lou003](https://discuss.elastic.co/u/Lou003)\
**Replies:** 3\
**Last updated:** [June 22, 2023, 8:49am UTC](https://discuss.elastic.co/t/getting-json-data-out-of-message-field-imported-with-filebeat/335872 "2023-06-22T08:49:29Z")

</div>

Hi everybody, I have a problem with indexing filebeat output generated from a JSON file. This JSON file has been created by converting a PCAP file and using jq to make it not pretty. After using filebeat this file has b…

---

## [Fetching documents with calendarItems.minNights first value greater than 2 using Elasticsearch DSL](https://discuss.elastic.co/t/fetching-documents-with-calendaritems-minnights-first-value-greater-than-2-using-elasticsearch-dsl/335411)

<div class="topic-metadata">

**Author:** [@Engin\_KARTAL](https://discuss.elastic.co/u/Engin_KARTAL)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 7:51am UTC](https://discuss.elastic.co/t/fetching-documents-with-calendaritems-minnights-first-value-greater-than-2-using-elasticsearch-dsl/335411 "2023-06-22T07:51:24Z")

</div>

Hello, I would like to learn how to fetch documents with the first value of the calendarItems.minNights field greater than 2 using Elasticsearch DSL. The data structure looks like this: In the above data structure, I w…

---

## [Winlogbeat doesn’t work since change of version](https://discuss.elastic.co/t/winlogbeat-doesn-t-work-since-change-of-version/335087)

<div class="topic-metadata">

**Author:** [@blop135](https://discuss.elastic.co/u/blop135)\
**Replies:** 3\
**Last updated:** [June 22, 2023, 7:37am UTC](https://discuss.elastic.co/t/winlogbeat-doesn-t-work-since-change-of-version/335087 "2023-06-22T07:37:14Z")

</div>

Hi everyone, I have a little problem here. I decided to update from the version 6.8.4 to the version 7.17.7. The installation of winlogbeat went well but then it says in the logs that the connexion to Kafka is establish…

---

## [Elasticsearch restoration of a huge dump fails with client connection timeout errors](https://discuss.elastic.co/t/elasticsearch-restoration-of-a-huge-dump-fails-with-client-connection-timeout-errors/336622)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 9\
**Last updated:** [June 22, 2023, 7:21am UTC](https://discuss.elastic.co/t/elasticsearch-restoration-of-a-huge-dump-fails-with-client-connection-timeout-errors/336622 "2023-06-22T07:21:32Z")

</div>

Hi Team, I am trying to restore a 50GB elastic dump file into a new elasticsearch cluster running with 3 elasticsearch replicas on a kubernetes cluster. The elasticsearch is running with a 7.10.2 oss version image and …

---

## [Hashing in ElasticSearch](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 4\
**Last updated:** [June 22, 2023, 5:05am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470 "2023-06-22T05:05:08Z")

</div>

Hello Team, We have a requirement to store an array of 100,000 users in an Elasticsearch field. During search, we need to match if a user exists in that array and return the corresponding document. Is it possible to ac…

---

## [Https://docker-auth.elastic.co not working](https://discuss.elastic.co/t/https-docker-auth-elastic-co-not-working/334665)

<div class="topic-metadata">

**Author:** [@ITMBF](https://discuss.elastic.co/u/ITMBF)\
**Replies:** 6\
**Last updated:** [June 22, 2023, 5:01am UTC](https://discuss.elastic.co/t/https-docker-auth-elastic-co-not-working/334665 "2023-06-22T05:01:38Z")

</div>

Hi guys, I am looking to build a ppc64le version of filebeat and try to get the golang-crossbuild containers. In order to do that I want to obtain them from docker.elastic.co/beats-dev/golang-crossbuild:\[TAG\] When run…

---

## [Random spike in write performance](https://discuss.elastic.co/t/random-spike-in-write-performance/336635)

<div class="topic-metadata">

**Author:** [@dna01](https://discuss.elastic.co/u/dna01)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 2:33am UTC](https://discuss.elastic.co/t/random-spike-in-write-performance/336635 "2023-06-22T02:33:13Z")

</div>

I'm noticing random "slowness" when writing. e.g., while most of the time the write operation completed under 20ms, there are occasional write operation that took \>1s. my setup: 6 data nodes, 24G JVM heap. (there are …

---

## [How to use script in msearch request in Elasticsearch Java client 8](https://discuss.elastic.co/t/how-to-use-script-in-msearch-request-in-elasticsearch-java-client-8/336603)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 3:48pm UTC](https://discuss.elastic.co/t/how-to-use-script-in-msearch-request-in-elasticsearch-java-client-8/336603 "2023-06-21T15:48:29Z")

</div>

my msearch request is like below: {} { "query": { "bool": { "must": { "match\_all": {} }, "filter": { "geo\_distance": { "distance": "3km", "distance\_type": "arc", "latLon": { "lat": 12.9322, "lon": 77.6904 } } } } }, "sc…

---

## [Multiple pipelines utilizing s3 output cause each other to terminate](https://discuss.elastic.co/t/multiple-pipelines-utilizing-s3-output-cause-each-other-to-terminate/336211)

<div class="topic-metadata">

**Author:** [@hughjarse](https://discuss.elastic.co/u/hughjarse)\
**Replies:** 5\
**Last updated:** [June 22, 2023, 12:54am UTC](https://discuss.elastic.co/t/multiple-pipelines-utilizing-s3-output-cause-each-other-to-terminate/336211 "2023-06-22T00:54:51Z")

</div>

In Logstash, I am using the s3 output plugin in multiple pipelines. Each plugin instance stores temporary files to disk and has the restore option set to true. I have problems with the restarting of other pipelines causi…

---

## [Time filter is not applying in the dash board](https://discuss.elastic.co/t/time-filter-is-not-applying-in-the-dash-board/336617)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 5\
**Last updated:** [June 21, 2023, 10:28pm UTC](https://discuss.elastic.co/t/time-filter-is-not-applying-in-the-dash-board/336617 "2023-06-21T22:28:45Z")

</div>

Hi, I have made a dashboard for some KPIs. When I try to filter with Time periods, at that time, some of the visuals are getting updated and some of them are not . I have used TimeStamp in all the dashboards. Attached ar…

---

## [Timelion Expression is not supporting .offset function](https://discuss.elastic.co/t/timelion-expression-is-not-supporting-offset-function/336619)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 9:18pm UTC](https://discuss.elastic.co/t/timelion-expression-is-not-supporting-offset-function/336619 "2023-06-21T21:18:13Z")

</div>

I am trying to visualize the counts of one field for this month and compare it with the count for the next month. I am using the time lion expression with .offset -1m but the same is not working. It gives me an error. My…

---

## [Fleet not sending data after cluster upgrade](https://discuss.elastic.co/t/fleet-not-sending-data-after-cluster-upgrade/336625)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 8:21pm UTC](https://discuss.elastic.co/t/fleet-not-sending-data-after-cluster-upgrade/336625 "2023-06-21T20:21:00Z")

</div>

Hello. Last Thursday I upgraded an Elastic cluster to 7.17.10. Since then, Fleet has not been collecting any data from agents and the Fleet server itself doesn't appear to communicating with the cluster. After restart…

---

## [Parse failure (object mapping for \[trace.detail\] tried to parse field \[null\] as object, but found a concrete value)](https://discuss.elastic.co/t/parse-failure-object-mapping-for-trace-detail-tried-to-parse-field-null-as-object-but-found-a-concrete-value/336551)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 7:20pm UTC](https://discuss.elastic.co/t/parse-failure-object-mapping-for-trace-detail-tried-to-parse-field-null-as-object-but-found-a-concrete-value/336551 "2023-06-21T19:20:17Z")

</div>

Hi Team, I basically use json filter to parse log. But somewhere in json have 2 different type of log that's why I get this error (object mapping for \[trace.detail\] tried to parse field \[null\] as object, but found a conc…

---

## [Some helm charts of the Elasticsearch 8 version are not published yet](https://discuss.elastic.co/t/some-helm-charts-of-the-elasticsearch-8-version-are-not-published-yet/336615)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 6:08pm UTC](https://discuss.elastic.co/t/some-helm-charts-of-the-elasticsearch-8-version-are-not-published-yet/336615 "2023-06-21T18:08:59Z")

</div>

I need to add Elasticsearch 8.2.3 version for Kubernetes bare metal cluster. But I showed there is no helm release for the 8.2.3 version. what is the reason for it?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=501)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=503)
