# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=505

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 506

---

## [Issue with mapping in elasticsearch](https://discuss.elastic.co/t/issue-with-mapping-in-elasticsearch/336461)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:03pm UTC](https://discuss.elastic.co/t/issue-with-mapping-in-elasticsearch/336461 "2023-06-20T12:03:52Z")

</div>

Hi, I'm trying to index a field in elasticsearch with my index template. Except that my field can either be of type text (ex: No) or it can be of type float ( ex: 8.1). When I set the type to float in my mapping, I get e…

---

## [Can not have the same result](https://discuss.elastic.co/t/can-not-have-the-same-result/336460)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 11:54am UTC](https://discuss.elastic.co/t/can-not-have-the-same-result/336460 "2023-06-20T11:54:33Z")

</div>

Hi, I can't do a song search on an elasticsearch lyrics excerpt, The lyric: "... Na dia mbola zaza Na dia mbola kely ..." if I search for "mbola zaza" it gives me the result but if I type "ola zaza" it gives me no re…

---

## [Not working TCP input with TLS](https://discuss.elastic.co/t/not-working-tcp-input-with-tls/336473)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 11:41am UTC](https://discuss.elastic.co/t/not-working-tcp-input-with-tls/336473 "2023-06-20T11:41:28Z")

</div>

Hi, I want to send syslog events but with tls, unfortunately i have a problem with that. Logstash receive first event and that's all, i don't have any error logs. Here is output config: output { tcp { host =\> …

---

## [TSVB Markdown visualization](https://discuss.elastic.co/t/tsvb-markdown-visualization/335319)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 11:11am UTC](https://discuss.elastic.co/t/tsvb-markdown-visualization/335319 "2023-06-20T11:11:26Z")

</div>

Hello, I am trying to create a table which is displayed like this: ||column\_name ||column\_value|| ||column\_name ||column\_value|| And display information only on a row from an index. in TSVB Markdown visualization. …

---

## [Using "&embed=true" or "&hide-filter-bar=true" to hide KQL doesn't work](https://discuss.elastic.co/t/using-embed-true-or-hide-filter-bar-true-to-hide-kql-doesnt-work/334660)

<div class="topic-metadata">

**Author:** [@cpu](https://discuss.elastic.co/u/cpu)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 10:53am UTC](https://discuss.elastic.co/t/using-embed-true-or-hide-filter-bar-true-to-hide-kql-doesnt-work/334660 "2023-06-20T10:53:29Z")

</div>

Hello, I tried both solutions proposed in the community forum: 1- "Adding !\[kql|410x161\](upload://A1ggJ3BBz6XtO6BbN1Fpt2tVP6p.jpeg) to the URL should remove the filter options." 2- You could add &embed=true a the end…

---

## [Logs related to database (postgres) pods are not moving to elastic](https://discuss.elastic.co/t/logs-related-to-database-postgres-pods-are-not-moving-to-elastic/336459)

<div class="topic-metadata">

**Author:** [@unais](https://discuss.elastic.co/u/unais)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 9:29am UTC](https://discuss.elastic.co/t/logs-related-to-database-postgres-pods-are-not-moving-to-elastic/336459 "2023-06-20T09:29:37Z")

</div>

Hi community, I'm not able to see the logs related postgres even though I have mentioned the name of the pod in filebeat. postgres logs: (on running kubectl logs command) 2023-06-19 07:37:39.591 UTC \[73\] ERROR: "xyz" …

---

## [Vega-Lite problem with the visualization](https://discuss.elastic.co/t/vega-lite-problem-with-the-visualization/334220)

<div class="topic-metadata">

**Author:** [@martinez061](https://discuss.elastic.co/u/martinez061)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 9:56am UTC](https://discuss.elastic.co/t/vega-lite-problem-with-the-visualization/334220 "2023-06-20T09:56:38Z")

</div>

Hi im trying to create something similar to image below. The data, that i want to visualise is syslog\_hostname syslog\_ip\_address syslog\_url syslog\_url\_status For one destination im checking 3 website, and i want…

---

## [LogStash and parsing OPNSenser logs](https://discuss.elastic.co/t/logstash-and-parsing-opnsenser-logs/334234)

<div class="topic-metadata">

**Author:** [@LoggingJennfier](https://discuss.elastic.co/u/LoggingJennfier)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 9:16am UTC](https://discuss.elastic.co/t/logstash-and-parsing-opnsenser-logs/334234 "2023-06-20T09:16:07Z")

</div>

My logs are coming in as follows: \<134\>May 24 14:39:32 edge.internal filterlog\[2535\]: 78,,,ffe6d10d1f27a42fc0edc3abb3a6d333,ovpnc1,match,pass,out,4,0x0,,63,61951,0,DF,6,tcp,60,10.8.0.2,20.44.17.5,44575,443,0,S,149708160…

---

## [Filebeat error for port ERROR: Address already in use](https://discuss.elastic.co/t/filebeat-error-for-port-error-address-already-in-use/336422)

<div class="topic-metadata">

**Author:** [@yogesh.gangwar](https://discuss.elastic.co/u/yogesh.gangwar)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:54am UTC](https://discuss.elastic.co/t/filebeat-error-for-port-error-address-already-in-use/336422 "2023-06-20T08:54:33Z")

</div>

While running the logstash I'm getting an issue of "A plugin had an unrecoverable error. Will restart this plugin." \</ \[2023-06-20T10:37:52,046\]\[INFO \]\[org.logstash.beats.Server\]\[main\]\[f36c0056714d92177d9fb7e027196d5ceb…

---

## [No permissions for user | Security Exception](https://discuss.elastic.co/t/no-permissions-for-user-security-exception/335499)

<div class="topic-metadata">

**Author:** [@Faisal\_Umer](https://discuss.elastic.co/u/Faisal_Umer)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 8:52am UTC](https://discuss.elastic.co/t/no-permissions-for-user-security-exception/335499 "2023-06-20T08:52:58Z")

</div>

I have to delay the shards assignment after a failure and running this command for that PUT \_all/\_settings { "settings": { "index.unassigned.node\_left.delayed\_timeout": "5m" } } Getting the following error whi…

---

## [Elasticerach 8.5.1 version image gives this error curl: (52) Empty reply from server](https://discuss.elastic.co/t/elasticerach-8-5-1-version-image-gives-this-error-curl-52-empty-reply-from-server/336444)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 8:48am UTC](https://discuss.elastic.co/t/elasticerach-8-5-1-version-image-gives-this-error-curl-52-empty-reply-from-server/336444 "2023-06-20T08:48:09Z")

</div>

I used Elasticsearch 8.5.1 image for my Kubernetes cluster. After installing using the helm chart pod is running correctly. but when I tried to check Elasticsearch cluster healthiness. it gave this error. curl 127.0.0.1:…

---

## [Undefined class constant 'MAJOR\_VERSION](https://discuss.elastic.co/t/undefined-class-constant-major-version/336429)

<div class="topic-metadata">

**Author:** [@zaheer8](https://discuss.elastic.co/u/zaheer8)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 8:46am UTC](https://discuss.elastic.co/t/undefined-class-constant-major-version/336429 "2023-06-20T08:46:53Z")

</div>

Hi Geek Elasticsearch component is showing the Undefined class constant 'MAJOR\_VERSION' error in Elasticsearch version 6.x . Can you help why it is showing this error?

---

## [Which visualization should i choose for displaying Host.version](https://discuss.elastic.co/t/which-visualization-should-i-choose-for-displaying-host-version/335927)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 8:46am UTC](https://discuss.elastic.co/t/which-visualization-should-i-choose-for-displaying-host-version/335927 "2023-06-20T08:46:10Z")

</div>

i am want to display host confirmation i dashboard like cpu count, total memory , host.os.version . which visualisation should i choose . as all require aggregate function but . these are not . and more over for my …

---

## [Edit kibana login UI Title](https://discuss.elastic.co/t/edit-kibana-login-ui-title/335962)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 9\
**Last updated:** [June 20, 2023, 8:36am UTC](https://discuss.elastic.co/t/edit-kibana-login-ui-title/335962 "2023-06-20T08:36:23Z")

</div>

how can i edit the title seeing in the loging page of kibana, Where i can find the respective file. how can i add other logos and title texts in it. Change the welcome to elastic into any other title, for that wher…

---

## [Slowness after upgrading ElasticSearch 6.5 to 7.10](https://discuss.elastic.co/t/slowness-after-upgrading-elasticsearch-6-5-to-7-10/336439)

<div class="topic-metadata">

**Author:** [@Thomas\_Kang](https://discuss.elastic.co/u/Thomas_Kang)\
**Replies:** 5\
**Last updated:** [June 20, 2023, 8:26am UTC](https://discuss.elastic.co/t/slowness-after-upgrading-elasticsearch-6-5-to-7-10/336439 "2023-06-20T08:26:35Z")

</div>

Hi folks, I'm experiencing slowness after upgrading Elasticsearch from 6.5.4 to 7.10.2. I can reproduce it in my local (using the official docker images) and also in AWS' managed clusters. Here are the index mappings …

---

## [Display best permutation of different fields](https://discuss.elastic.co/t/display-best-permutation-of-different-fields/336055)

<div class="topic-metadata">

**Author:** [@Ravid\_Cohen](https://discuss.elastic.co/u/Ravid_Cohen)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:08am UTC](https://discuss.elastic.co/t/display-best-permutation-of-different-fields/336055 "2023-06-20T08:08:51Z")

</div>

I have a metric (document) that contains three different fields: a, b, and c. The metric can be filtered by time and location. I want to filter all the data points of this metric according to time and location (using Ki…

---

## [Min and Max timestamp difference](https://discuss.elastic.co/t/min-and-max-timestamp-difference/334634)

<div class="topic-metadata">

**Author:** [@SUBIN\_B\_MATHEW](https://discuss.elastic.co/u/SUBIN_B_MATHEW)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:04am UTC](https://discuss.elastic.co/t/min-and-max-timestamp-difference/334634 "2023-06-20T08:04:11Z")

</div>

Aggregated the Min and Max timestamp based on the message id. I wanted to calculate the time difference between min and Max time and show it in a data table on kibana dashboard , could you please help me on this?

---

## [What is the reason for the delay official launch other 8 versions of elastic search helm? Still only has the 8.5.1 version for the helm repo](https://discuss.elastic.co/t/what-is-the-reason-for-the-delay-official-launch-other-8-versions-of-elastic-search-helm-still-only-has-the-8-5-1-version-for-the-helm-repo/336446)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 7:42am UTC](https://discuss.elastic.co/t/what-is-the-reason-for-the-delay-official-launch-other-8-versions-of-elastic-search-helm-still-only-has-the-8-5-1-version-for-the-helm-repo/336446 "2023-06-20T07:42:10Z")

</div>

I need to add Elasticsearch 8.2.3 version for Kubernetes bare metal cluster. But I showed there is no helm release for the 8.2.3 version. what is the reason for it?

---

## [Is there a way to install ES plugins using ENV variables in docker?](https://discuss.elastic.co/t/is-there-a-way-to-install-es-plugins-using-env-variables-in-docker/336445)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 7:30am UTC](https://discuss.elastic.co/t/is-there-a-way-to-install-es-plugins-using-env-variables-in-docker/336445 "2023-06-20T07:30:59Z")

</div>

Hi there, I need to install s3-repository plugin in the ES running using docker. I do not want to edit my elasticsearch.yml file. Is there a way I want install plugins using ENV variables?

---

## [What is the best candidate for the Filestream ID for Autodiscover Kubernetes Provider?](https://discuss.elastic.co/t/what-is-the-best-candidate-for-the-filestream-id-for-autodiscover-kubernetes-provider/336397)

<div class="topic-metadata">

**Author:** [@lprakashv](https://discuss.elastic.co/u/lprakashv)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 7:30am UTC](https://discuss.elastic.co/t/what-is-the-best-candidate-for-the-filestream-id-for-autodiscover-kubernetes-provider/336397 "2023-06-20T07:30:46Z")

</div>

Based on thg logs, it seems that the filestream ID is not unique and this could cause data duplication. However, my rationale towards setting a combination of ${data.kubernetes.pod.name} and ${data.kubernetes.container.i…

---

## [How to get Distinct results using Search API](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336217)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 7:03am UTC](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336217 "2023-06-20T07:03:08Z")

</div>

I have a "customer" index with fields "FirstName" and "LastName". My index contains data as follows: First Name | LastName Richard | Lockwood Richard | Lockwood 2 Richard | Lockwood 3 Richard | Lockwood 4 Richard …

---

## [Facing challange during segregate the data from one index to another index](https://discuss.elastic.co/t/facing-challange-during-segregate-the-data-from-one-index-to-another-index/336349)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 6:37am UTC](https://discuss.elastic.co/t/facing-challange-during-segregate-the-data-from-one-index-to-another-index/336349 "2023-06-20T06:37:27Z")

</div>

Hello Team, We are using Akamai for CDN and WAF. We have configured datastream on akamai and getting those logs on our elasticsaerch. Please refer the below link for same: Stream logs to Elasticsearch As per doc we ha…

---

## [Logstash config for transactions](https://discuss.elastic.co/t/logstash-config-for-transactions/336294)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 5\
**Last updated:** [June 20, 2023, 6:25am UTC](https://discuss.elastic.co/t/logstash-config-for-transactions/336294 "2023-06-20T06:25:36Z")

</div>

Hi need to write logstash config that parse log file from this path: "/tmp/logs/\*" store in elastic. here is the log: 09:54:37:566 R\[SRV1\]L\[477\]T\[0300\]ID\[696119\] 09:54:37:566 S\[SRV2\]L\[477\]T\[0300\]ID\[696119\] 09:54:55:28…

---

## [How to upgrade elk license from trail to community version](https://discuss.elastic.co/t/how-to-upgrade-elk-license-from-trail-to-community-version/336427)

<div class="topic-metadata">

**Author:** [@sraman](https://discuss.elastic.co/u/sraman)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 6:13am UTC](https://discuss.elastic.co/t/how-to-upgrade-elk-license-from-trail-to-community-version/336427 "2023-06-20T06:13:44Z")

</div>

Hi, Currently our elk runs on trial license and it's been expired, is there a way to upgrade to community version?

---

## [Logstash update sql\_last\_value while using paging](https://discuss.elastic.co/t/logstash-update-sql-last-value-while-using-paging/336362)

<div class="topic-metadata">

**Author:** [@zalseryani](https://discuss.elastic.co/u/zalseryani)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 6:00am UTC](https://discuss.elastic.co/t/logstash-update-sql-last-value-while-using-paging/336362 "2023-06-20T06:00:52Z")

</div>

sql\_last\_value update with Paging I am configuring logstash to use jdbc input knowing that I am using jdbc\_paging with the configuration. what I am facing now is that sql\_last\_value is being updated after all record…

---

## [Run a query after grouping and finding max](https://discuss.elastic.co/t/run-a-query-after-grouping-and-finding-max/336414)

<div class="topic-metadata">

**Author:** [@arvidh](https://discuss.elastic.co/u/arvidh)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 5:33am UTC](https://discuss.elastic.co/t/run-a-query-after-grouping-and-finding-max/336414 "2023-06-20T05:33:12Z")

</div>

Here is some test data I have in an index: {"name" : "almara" , "version" : "1" , "groups" : "blueHouse", "data1" : " value1"} {"name" : "almara" , "version" : "2" , "groups" : "blueHouse", "data1" : " Something"} {"nam…

---

## [Indices are not getting deleted](https://discuss.elastic.co/t/indices-are-not-getting-deleted/335590)

<div class="topic-metadata">

**Author:** [@shubham.s](https://discuss.elastic.co/u/shubham.s)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 5:27am UTC](https://discuss.elastic.co/t/indices-are-not-getting-deleted/335590 "2023-06-20T05:27:42Z")

</div>

Hi, I have update policy from kibana GUI to deleted traces after 5days but still indices are not getting deleted GET \_ilm/policy/apm\_test { "apm\_test": { "version": 4, "modified\_date": "2023-06-02T07:15:29.3…

---

## [Elastic agent installation failed on windows](https://discuss.elastic.co/t/elastic-agent-installation-failed-on-windows/336424)

<div class="topic-metadata">

**Author:** [@esijati](https://discuss.elastic.co/u/esijati)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 5:23am UTC](https://discuss.elastic.co/t/elastic-agent-installation-failed-on-windows/336424 "2023-06-20T05:23:40Z")

</div>

Fleet managed Elastic agent installation failed on windows With error Error: fail to enroll: fail to execute request to fleet-server: Proxy Authentication Required. Enroll command failed with exist code: 1 Event view…

---

## [Logstash filling up disk space beyond queue.max\_bytes](https://discuss.elastic.co/t/logstash-filling-up-disk-space-beyond-queue-max-bytes/336388)

<div class="topic-metadata">

**Author:** [@Sindhu\_Bandi](https://discuss.elastic.co/u/Sindhu_Bandi)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 5:19am UTC](https://discuss.elastic.co/t/logstash-filling-up-disk-space-beyond-queue-max-bytes/336388 "2023-06-20T05:19:39Z")

</div>

Logstash persistent volume size is increasing beyond configured queue.max\_bytes Scenario: Logstash : 7.17.3 Env : On Kubernetes cluster Persistence: Enabled logstash.yml: ---- http.host: "0.0.0.0" path.config: /usr/…

---

## [Occasionally NoAliveNodesFound with HAProxy as Loadbalancer](https://discuss.elastic.co/t/occasionally-noalivenodesfound-with-haproxy-as-loadbalancer/335890)

<div class="topic-metadata">

**Author:** [@oliver.hart](https://discuss.elastic.co/u/oliver.hart)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/occasionally-noalivenodesfound-with-haproxy-as-loadbalancer/335890 "2023-06-20T04:30:32Z")

</div>

Hello, we have kind of a special problem, so I try to explain everything in detail. Setup The above diagram shows our current setup (simplified). Our app runs within a Kubernetes / Openshift Cluster. The Deploymen…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=504)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=506)
