# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=504

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 505

---

## [How we can calculate only Working days only Monday to Friday and skip Saturday and Sunday](https://discuss.elastic.co/t/how-we-can-calculate-only-working-days-only-monday-to-friday-and-skip-saturday-and-sunday/335731)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 4\
**Last updated:** [June 21, 2023, 5:21am UTC](https://discuss.elastic.co/t/how-we-can-calculate-only-working-days-only-monday-to-friday-and-skip-saturday-and-sunday/335731 "2023-06-21T05:21:21Z")

</div>

How we can calculate only Working days only Monday to Friday and skip Saturday and Sunday

---

## [ELK upgrade to 7.17.10](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 5:11am UTC](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513 "2023-06-21T05:11:10Z")

</div>

Hi , We recentely upgraded the ELK cluster from the 7.15.1 to 7.17.10 in order to fix security vulnerabilities , however after upgrading we are still have the open JDK vulnerability on Elasticsearch servers : OpenJDK…

---

## [What is the FileBeats version that is compatible in Oracle Solaris 11.3?](https://discuss.elastic.co/t/what-is-the-filebeats-version-that-is-compatible-in-oracle-solaris-11-3/336466)

<div class="topic-metadata">

**Author:** [@kam89](https://discuss.elastic.co/u/kam89)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 4:02am UTC](https://discuss.elastic.co/t/what-is-the-filebeats-version-that-is-compatible-in-oracle-solaris-11-3/336466 "2023-06-21T04:02:49Z")

</div>

Hi, Is there any FileBeats version that is compatible in Oracle Solaris 11.3? Thank you and Regards

---

## [Store Old Indices in S3 and load when needed in future?](https://discuss.elastic.co/t/store-old-indices-in-s3-and-load-when-needed-in-future/336503)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 3:59am UTC](https://discuss.elastic.co/t/store-old-indices-in-s3-and-load-when-needed-in-future/336503 "2023-06-21T03:59:01Z")

</div>

We would like to store lots of old indices in S3 for easy storage and the ability to import the indice from S3 back into Elasticsearch when needed. I have installed the repository-s3 plugin, and I have seen how i can do …

---

## [Beats Native Grok Processor](https://discuss.elastic.co/t/beats-native-grok-processor/336521)

<div class="topic-metadata">

**Author:** [@james-mchugh](https://discuss.elastic.co/u/james-mchugh)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 2:32am UTC](https://discuss.elastic.co/t/beats-native-grok-processor/336521 "2023-06-21T02:32:22Z")

</div>

Hello everyone. I am looking into adding a Grok processor to Beats/Filebeat as requested in \[Filebeat\] Add grok Processor as native beat/filebeat processor · Issue #30073 · elastic/beats · GitHub. Our team has already c…

---

## [Aggregate filter の timeout\_timestamp\_field設定時の動作について](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/336283)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 9:48pm UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/336283 "2023-06-20T21:48:19Z")

</div>

Aggregate filter pluginのオプションtimeout\_timestamp\_fieldについて、 機能追加の経緯やドキュメントの記載から設定すると、タイムアウトの判定がシステム時間からログのタイムスタンプに変わると思っていたが、実際に動かしてみると、システム時間で判定されたような挙動をした。 （私と同じ疑問を持った方が過去にいたよう。https://discuss.elastic.co/t/aggregate-fi…

---

## [Metricbeat GCP Billing metricset fails with timeout error](https://discuss.elastic.co/t/metricbeat-gcp-billing-metricset-fails-with-timeout-error/336516)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 11:05pm UTC](https://discuss.elastic.co/t/metricbeat-gcp-billing-metricset-fails-with-timeout-error/336516 "2023-06-20T23:05:32Z")

</div>

I enabled the gcp module for metricbeat and used the billing metricset as: - module: gcp metricsets: - billing period: 24h project\_id: "project" credentials\_file\_path: "/etc/metricbeat/service-account.json" …

---

## [Monthly Index Usage](https://discuss.elastic.co/t/monthly-index-usage/336407)

<div class="topic-metadata">

**Author:** [@IsaacD](https://discuss.elastic.co/u/IsaacD)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 10:40pm UTC](https://discuss.elastic.co/t/monthly-index-usage/336407 "2023-06-20T22:40:14Z")

</div>

We have multiple teams using our elasticsearch stack and need to find out how much usage each team uses. Is there a way to collect the monthly resource usage (CPU, Memory, storage) for a group of indexes without digging…

---

## [Limiting Response Data Using URI Based on Value of Search Term](https://discuss.elastic.co/t/limiting-response-data-using-uri-based-on-value-of-search-term/336507)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 7:51pm UTC](https://discuss.elastic.co/t/limiting-response-data-using-uri-based-on-value-of-search-term/336507 "2023-06-20T19:51:14Z")

</div>

I'm looking to filter out data in response objects based on the value of a search term. The request below for instance, filters the data within the objects themselves, excluding a particular field (attribute.betaalmethod…

---

## [Elasticsearch/Kibana - Discover not showing traffic - but logs show no errors Elasticsearch 7.17.10](https://discuss.elastic.co/t/elasticsearch-kibana-discover-not-showing-traffic-but-logs-show-no-errors-elasticsearch-7-17-10/336508)

<div class="topic-metadata">

**Author:** [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 7:56pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-discover-not-showing-traffic-but-logs-show-no-errors-elasticsearch-7-17-10/336508 "2023-06-20T19:56:13Z")

</div>

We use nginx as the front end to move traffic from incoming port 9200 to 9400. This has been working more or less fine. We needed to make a change so port 9200 could accept both http and https traffic. So I made the ch…

---

## [Getting Nginx Logs From docker Container](https://discuss.elastic.co/t/getting-nginx-logs-from-docker-container/336457)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 5:36pm UTC](https://discuss.elastic.co/t/getting-nginx-logs-from-docker-container/336457 "2023-06-20T17:36:40Z")

</div>

Hi All, Usually I used to to read Nginx Logs via the Nginx integration available, but now the nginx app is dockerised within a container. The docker integration available in integrations as i can see will not read the…

---

## [Data View, Canvas, and ESQL](https://discuss.elastic.co/t/data-view-canvas-and-esql/336474)

<div class="topic-metadata">

**Author:** [@witwit](https://discuss.elastic.co/u/witwit)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 5:35pm UTC](https://discuss.elastic.co/t/data-view-canvas-and-esql/336474 "2023-06-20T17:35:48Z")

</div>

Hi, So i have an index which is created from a transform with group by on a field and aggregation using terms. This means that my resulting field is a flattened field of terms. Through this I can create Data View term…

---

## [Force brute vector query](https://discuss.elastic.co/t/force-brute-vector-query/336497)

<div class="topic-metadata">

**Author:** [@Lone\_Eagle](https://discuss.elastic.co/u/Lone_Eagle)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 5:17pm UTC](https://discuss.elastic.co/t/force-brute-vector-query/336497 "2023-06-20T17:17:42Z")

</div>

We are currently having a normal search and want to experiment on vectors. We managed to have a normal knn search but want to create a search query using the brute force of a vector. The query receive a text to search on…

---

## [Publication of cluster state fails - followers check retry count exceeded](https://discuss.elastic.co/t/publication-of-cluster-state-fails-followers-check-retry-count-exceeded/330097)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 49\
**Last updated:** [June 20, 2023, 4:31pm UTC](https://discuss.elastic.co/t/publication-of-cluster-state-fails-followers-check-retry-count-exceeded/330097 "2023-06-20T16:31:34Z")

</div>

Hi everyone, We are running Elasticsearch 8.6.1 (on Kubernetes) with 12 data nodes (pods) and 3 dedicated master pods. We are heavily indexing data (bulks) and we did some configuration tunes to improve indexing: indi…

---

## [How can I index only new documents without updating the older ones?](https://discuss.elastic.co/t/how-can-i-index-only-new-documents-without-updating-the-older-ones/336501)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:23pm UTC](https://discuss.elastic.co/t/how-can-i-index-only-new-documents-without-updating-the-older-ones/336501 "2023-06-20T16:23:15Z")

</div>

I am aware of the create action but when I use it a horrendous WARN log is printed in the logstash screen. The solution of create would fit perfect if it wasn't for it. So I've been wondering if there is another way to a…

---

## [Logstash output s3 prefix with date](https://discuss.elastic.co/t/logstash-output-s3-prefix-with-date/336498)

<div class="topic-metadata">

**Author:** [@kunalmohan](https://discuss.elastic.co/u/kunalmohan)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 3:10pm UTC](https://discuss.elastic.co/t/logstash-output-s3-prefix-with-date/336498 "2023-06-20T15:10:27Z")

</div>

S3 output plugin | Logstash Reference \[8.8\] | Elastic mentions to use prefix = "%{+YYYY}/%{+MM}/%{+dd}" for creating folders based on event date. This doesn't work for my. It simply creates two nested folders with name /.…

---

## [Creating visualization with timestamp un y axis and not count](https://discuss.elastic.co/t/creating-visualization-with-timestamp-un-y-axis-and-not-count/336430)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 2:54pm UTC](https://discuss.elastic.co/t/creating-visualization-with-timestamp-un-y-axis-and-not-count/336430 "2023-06-20T14:54:27Z")

</div>

Hi All, We have a index which stores the status of job running in controlm platform , like job name ,id ,job start time end time and so on... We want to create a visualization: putting date in y axis (date on which da…

---

## [Alert rules with document link](https://discuss.elastic.co/t/alert-rules-with-document-link/336494)

<div class="topic-metadata">

**Author:** [@pantonis](https://discuss.elastic.co/u/pantonis)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 2:48pm UTC](https://discuss.elastic.co/t/alert-rules-with-document-link/336494 "2023-06-20T14:48:44Z")

</div>

I have created an alert that filters documents based on a condition and for each document that evaluate a condition I send an email based on a mustache expression. Everything works find except I'm missing one thing. Fo…

---

## [Custom JacksonJsonpMapper in RestClientTransport](https://discuss.elastic.co/t/custom-jacksonjsonpmapper-in-restclienttransport/336481)

<div class="topic-metadata">

**Author:** [@JaroslavHolan](https://discuss.elastic.co/u/JaroslavHolan)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 2:24pm UTC](https://discuss.elastic.co/t/custom-jacksonjsonpmapper-in-restclienttransport/336481 "2023-06-20T14:24:42Z")

</div>

Hi, I need to help with how to pass my instance of JacksonJsonpMapper to RestClientTransport in Spring Java/Kotlin project. I have the following exception com.fasterxml.jackson.databind.exc.InvalidDefinitionException:…

---

## [Percolate Query Issues after Upgrading to Elasticsearch 8.6.2 with REST High-Level Client 7.17.9](https://discuss.elastic.co/t/percolate-query-issues-after-upgrading-to-elasticsearch-8-6-2-with-rest-high-level-client-7-17-9/336359)

<div class="topic-metadata">

**Author:** [@ulysse42](https://discuss.elastic.co/u/ulysse42)\
**Replies:** 5\
**Last updated:** [June 20, 2023, 2:16pm UTC](https://discuss.elastic.co/t/percolate-query-issues-after-upgrading-to-elasticsearch-8-6-2-with-rest-high-level-client-7-17-9/336359 "2023-06-20T14:16:35Z")

</div>

Hello Elasticsearch community, I'm currently experiencing an issue with the Percolate Query after upgrading my Elasticsearch version to 8.6.2. I'm still using the REST High-Level Client 7.17.9. Here's the exception I'm…

---

## [Unassigned shards =\> How to set default replica number to 0?](https://discuss.elastic.co/t/unassigned-shards-how-to-set-default-replica-number-to-0/336458)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 1:36pm UTC](https://discuss.elastic.co/t/unassigned-shards-how-to-set-default-replica-number-to-0/336458 "2023-06-20T13:36:37Z")

</div>

Hi, A few days ago, I've just installed a new node to my single node cluster, in order to manage datastreams lifecycle policies between 2 nodes : elk1 is configured in elasticsearch.yml with node.roles: master, data\_…

---

## [Transforms group by on 2 different data fields having same value](https://discuss.elastic.co/t/transforms-group-by-on-2-different-data-fields-having-same-value/336478)

<div class="topic-metadata">

**Author:** [@ashwani\_perf](https://discuss.elastic.co/u/ashwani_perf)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 1:34pm UTC](https://discuss.elastic.co/t/transforms-group-by-on-2-different-data-fields-having-same-value/336478 "2023-06-20T13:34:43Z")

</div>

Hi Team, I am fairly new to Kibana and have run into a problem. I am trying to write a single transform which captures ingress and egress of a single event so that i can aggregate them by timestamp max and min and then …

---

## [Unable to install s3-repository plugin](https://discuss.elastic.co/t/unable-to-install-s3-repository-plugin/336443)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 1:29pm UTC](https://discuss.elastic.co/t/unable-to-install-s3-repository-plugin/336443 "2023-06-20T13:29:26Z")

</div>

Hi, I am trying to install s3-repository plugin but getting the following error:- -\> Installing repository-s3 \[repository-s3\] is no longer a plugin but instead a module packaged with this distribution of Elasticsearch -\>…

---

## [Seeking a developer to help extend Elasticsearch to connect with Web3 API](https://discuss.elastic.co/t/seeking-a-developer-to-help-extend-elasticsearch-to-connect-with-web3-api/336114)

<div class="topic-metadata">

**Author:** [@Jules\_Lai](https://discuss.elastic.co/u/Jules_Lai)\
**Replies:** 6\
**Last updated:** [June 19, 2023, 4:42pm UTC](https://discuss.elastic.co/t/seeking-a-developer-to-help-extend-elasticsearch-to-connect-with-web3-api/336114 "2023-06-19T16:42:34Z")

</div>

Hi, I am looking for a developer who is able to help integrate Web3 into Elasticsearch. I am one of the developers working on the Web3 interface for SIA decentralised storage. I will be mainly using Elasticsearch with…

---

## [Dynamically set s3 bucket name in logstash output](https://discuss.elastic.co/t/dynamically-set-s3-bucket-name-in-logstash-output/336484)

<div class="topic-metadata">

**Author:** [@kunalmohan](https://discuss.elastic.co/u/kunalmohan)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 1:09pm UTC](https://discuss.elastic.co/t/dynamically-set-s3-bucket-name-in-logstash-output/336484 "2023-06-20T13:09:34Z")

</div>

Is there a way I can set s3 bucket name using a @metadata field?

---

## [Most efficient way of accessing long\[\]\[\] data in Painless scripts](https://discuss.elastic.co/t/most-efficient-way-of-accessing-long-data-in-painless-scripts/336437)

<div class="topic-metadata">

**Author:** [@Pyppe](https://discuss.elastic.co/u/Pyppe)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 1:06pm UTC](https://discuss.elastic.co/t/most-efficient-way-of-accessing-long-data-in-painless-scripts/336437 "2023-06-20T13:06:46Z")

</div>

Hi! We have a custom solution for calculating similarities using feature vectors. Each document in Elasticsearch index can have multiple entities. Thus, for each document we have basically long\[\]\[\] formatted data we wou…

---

## [Recursive glob pattern depth](https://discuss.elastic.co/t/recursive-glob-pattern-depth/336471)

<div class="topic-metadata">

**Author:** [@unknotted-evacuee](https://discuss.elastic.co/u/unknotted-evacuee)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 1:04pm UTC](https://discuss.elastic.co/t/recursive-glob-pattern-depth/336471 "2023-06-20T13:04:27Z")

</div>

We are trying to recursively capture logs from a file tree that gets quite deep. According to the documentation here: filestream input | Filebeat Reference \[8.8\] | Elastic This states that: "If enabled it expands a sing…

---

## [Install/ create 6 node elasticsearch 8.7 cluster](https://discuss.elastic.co/t/install-create-6-node-elasticsearch-8-7-cluster/336148)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 1:02pm UTC](https://discuss.elastic.co/t/install-create-6-node-elasticsearch-8-7-cluster/336148 "2023-06-20T13:02:24Z")

</div>

Hi All, I am looking for some info on how to install and create ES 8.7 cluster on RHEL 7 servers using tar.gz. I am not able to find the steps in the documentation. Need to know how to make nodes join a cluster. Need…

---

## [Logstash not listening for second input](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480)

<div class="topic-metadata">

**Author:** [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 1:01pm UTC](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480 "2023-06-20T13:01:21Z")

</div>

I have set up a working ELK stack with input from winlogbeat. Now I want to add a second input for ingesting syslog logs from a switch. I configured my logstash to do so, but it still only listens on port 5044 after rest…

---

## [Issue with mapping in elasticsearch](https://discuss.elastic.co/t/issue-with-mapping-in-elasticsearch/336461)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:03pm UTC](https://discuss.elastic.co/t/issue-with-mapping-in-elasticsearch/336461 "2023-06-20T12:03:52Z")

</div>

Hi, I'm trying to index a field in elasticsearch with my index template. Except that my field can either be of type text (ex: No) or it can be of type float ( ex: 8.1). When I set the type to float in my mapping, I get e…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=503)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=505)
