# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=509

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 510

---

## [Create visualizatio with filter in field](https://discuss.elastic.co/t/create-visualizatio-with-filter-in-field/336014)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 10:29pm UTC](https://discuss.elastic.co/t/create-visualizatio-with-filter-in-field/336014 "2023-06-15T22:29:03Z")

</div>

How to create a visualization from information contained in a field or with a filter in Kibana. Ex: Group in the graph all processes with the name = joão

---

## [Looking for an index were order matters](https://discuss.elastic.co/t/looking-for-an-index-were-order-matters/334573)

<div class="topic-metadata">

**Author:** [@ron247](https://discuss.elastic.co/u/ron247)\
**Replies:** 3\
**Last updated:** [June 15, 2023, 9:37pm UTC](https://discuss.elastic.co/t/looking-for-an-index-were-order-matters/334573 "2023-06-15T21:37:21Z")

</div>

I am looking for an index that takes into account the order of the search terms. For example, I have the following documents: 1:"bla bla A B bla C bla" 2: "C A bla bla C D" The search string: "bla A" should only retur…

---

## [Nest 7.17 or Elastic.Clients.Elasticsearch 8.1.0 with Server 8.7.1returns a valid JSON but fails to set SearchResponse\<T\>.Documents](https://discuss.elastic.co/t/nest-7-17-or-elastic-clients-elasticsearch-8-1-0-with-server-8-7-1returns-a-valid-json-but-fails-to-set-searchresponse-t-documents/336141)

<div class="topic-metadata">

**Author:** [@Viktor\_Markhelyuk](https://discuss.elastic.co/u/Viktor_Markhelyuk)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 9:01pm UTC](https://discuss.elastic.co/t/nest-7-17-or-elastic-clients-elasticsearch-8-1-0-with-server-8-7-1returns-a-valid-json-but-fails-to-set-searchresponse-t-documents/336141 "2023-06-15T21:01:31Z")

</div>

Nest 5.0.0 with Server 5.6.1 runs correctly: result.DebugInformation shows a valid response JSON and a C# POCO: WX\_ORDER fills in with the response hits.hits.\_source data With Nest 7.17 or Elastic.Clients.Elasticsearc…

---

## [Convert normal logstash output to json output for adx ingestion](https://discuss.elastic.co/t/convert-normal-logstash-output-to-json-output-for-adx-ingestion/336138)

<div class="topic-metadata">

**Author:** [@ashokkrishna99\_Vemur](https://discuss.elastic.co/u/ashokkrishna99_Vemur)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 8:51pm UTC](https://discuss.elastic.co/t/convert-normal-logstash-output-to-json-output-for-adx-ingestion/336138 "2023-06-15T20:51:23Z")

</div>

I have been working on transferring Palo Alto firewall logs(syslog format) to ADX. To achieve this, I developed grok filters and incorporated kv and mutate filters as well. However, I encountered an issue where the outpu…

---

## [Issues with converting standalone instance to cluster](https://discuss.elastic.co/t/issues-with-converting-standalone-instance-to-cluster/336071)

<div class="topic-metadata">

**Author:** [@111407](https://discuss.elastic.co/u/111407)\
**Replies:** 4\
**Last updated:** [June 15, 2023, 7:11pm UTC](https://discuss.elastic.co/t/issues-with-converting-standalone-instance-to-cluster/336071 "2023-06-15T19:11:03Z")

</div>

Hi, I cannot convert my standalone instance to cluster. Initially, I tried just to copy elastic data dir to new nodes, but after some googling I realized it won't work. Then I just brought up elastic daemon on new nod…

---

## [Push & install winlogbeat to 100s of pcs](https://discuss.elastic.co/t/push-install-winlogbeat-to-100s-of-pcs/336134)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 7:02pm UTC](https://discuss.elastic.co/t/push-install-winlogbeat-to-100s-of-pcs/336134 "2023-06-15T19:02:59Z")

</div>

Hi All, I am using elastic stack v8.1 . I am facing a scenario where i have to install winlogbeat and sysmon to more than 300 desktop pcs running on Windows 10. However, installing the beat manually will be time consumi…

---

## [My Filebeat configuration can't listen to my logs inside my Kubernetes pods](https://discuss.elastic.co/t/my-filebeat-configuration-cant-listen-to-my-logs-inside-my-kubernetes-pods/336132)

<div class="topic-metadata">

**Author:** [@Derhoer](https://discuss.elastic.co/u/Derhoer)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 6:57pm UTC](https://discuss.elastic.co/t/my-filebeat-configuration-cant-listen-to-my-logs-inside-my-kubernetes-pods/336132 "2023-06-15T18:57:56Z")

</div>

I have web app service that run in go and produce a log that I stored inside /var/logs/app/app.log. This service is running inside a Kubernetes pods. And I have another pods that running Filebeat to listen to logs produc…

---

## [Number precision for 22 digit plus 6 digit decimal](https://discuss.elastic.co/t/number-precision-for-22-digit-plus-6-digit-decimal/334044)

<div class="topic-metadata">

**Author:** [@satyarajpc](https://discuss.elastic.co/u/satyarajpc)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 5:57pm UTC](https://discuss.elastic.co/t/number-precision-for-22-digit-plus-6-digit-decimal/334044 "2023-06-15T17:57:31Z")

</div>

We've a requirement to store and fetch a BigDecimal value (22digits + 6 decimals) in elasticsearch field. While fetching this below field, We're getting value as exponential notation. We would need it as we posted in b…

---

## [Apply grok pattern based on the log file path](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 40\
**Last updated:** [June 15, 2023, 4:29pm UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395 "2023-06-15T16:29:21Z")

</div>

Hi Here is my logstash config file input { beats { port =\> 5044 } } output { elasticsearch { hosts =\> "http://ip:9200" index =\> "%{type}-%{+YYYY.MM.dd}" user =\> "elastic" password =\> "pwd" } …

---

## [Intermitten Connection Failures when Querying Elasticsearch](https://discuss.elastic.co/t/intermitten-connection-failures-when-querying-elasticsearch/336116)

<div class="topic-metadata">

**Author:** [@Adam\_Zucker](https://discuss.elastic.co/u/Adam_Zucker)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 4:09pm UTC](https://discuss.elastic.co/t/intermitten-connection-failures-when-querying-elasticsearch/336116 "2023-06-15T16:09:05Z")

</div>

We have a Rails API that queries Elasticsearch via the elasticsearch-rails gem. At around 10:30 this morning, we started getting a bunch of Faraday::ConnectionFailed errors. They don't happen every time, but they've been…

---

## [How to migrate elasticsearch to another VM](https://discuss.elastic.co/t/how-to-migrate-elasticsearch-to-another-vm/336120)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-migrate-elasticsearch-to-another-vm/336120 "2023-06-15T16:01:12Z")

</div>

Hello, i have 3 virtual machine in ESXI server nodes datahot&kibana , datawarm, logstash with version 7.14.1 how can i migrate this Virtual Machine with data to another ESXI server with new version of Elastic Thanks …

---

## [Can't see all the value of my field in kibana](https://discuss.elastic.co/t/cant-see-all-the-value-of-my-field-in-kibana/335947)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 6\
**Last updated:** [June 15, 2023, 3:03pm UTC](https://discuss.elastic.co/t/cant-see-all-the-value-of-my-field-in-kibana/335947 "2023-06-15T15:03:06Z")

</div>

Hello, I'm currently working with Kibana. I try to filter my data according to a certain field but I notice that it does not display all the values of this field. just the first 10 values. How can I fix this?

---

## [Highlight does not work correctly?](https://discuss.elastic.co/t/highlight-does-not-work-correctly/336109)

<div class="topic-metadata">

**Author:** [@Nurm](https://discuss.elastic.co/u/Nurm)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 2:47pm UTC](https://discuss.elastic.co/t/highlight-does-not-work-correctly/336109 "2023-06-15T14:47:45Z")

</div>

query = 'Ivan Atamanchuk Ivanovich' highlighter is not working correctly when I put text above, it is just highlighting "Ivan Atamanchuk Ivanovich" ignoring last "ovich", I approximately know why it is not highlightin…

---

## [ES cloud - CA certificates](https://discuss.elastic.co/t/es-cloud-ca-certificates/336085)

<div class="topic-metadata">

**Author:** [@leonid\_fayngold](https://discuss.elastic.co/u/leonid_fayngold)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 1:48pm UTC](https://discuss.elastic.co/t/es-cloud-ca-certificates/336085 "2023-06-15T13:48:39Z")

</div>

Hi, Our team is moving from ES on prem to ES on cloud. I have created ES instance in Azure and I want to send some requests to my Elasticsearch endpoint. I have tried to send add user request however the request is re…

---

## [Get request with query yields result in Firefox, but nowhere else](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422)

<div class="topic-metadata">

**Author:** [@Fiothiel](https://discuss.elastic.co/u/Fiothiel)\
**Replies:** 7\
**Last updated:** [June 15, 2023, 2:33pm UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422 "2023-06-15T14:33:32Z")

</div>

Hello, I have a rather strange issue I would love to get some help with. I am running Elastic Search 7.7 locally and I'm trying to implement a very basic search call to it. When I call it without any query parameters i…

---

## [Voting-only node in azure](https://discuss.elastic.co/t/voting-only-node-in-azure/336108)

<div class="topic-metadata">

**Author:** [@Shushan\_Nigoyan](https://discuss.elastic.co/u/Shushan_Nigoyan)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 2:19pm UTC](https://discuss.elastic.co/t/voting-only-node-in-azure/336108 "2023-06-15T14:19:33Z")

</div>

Can I use azure storage account as a voting-only node in my elasticsearch cluster? My Cluster is self managed and has 4 nodes(2 in DC1 and 2 in DC2), fifth will be in azure as witness.

---

## [Squid Logs Integration (Technical preview) Kibana dashboard](https://discuss.elastic.co/t/squid-logs-integration-technical-preview-kibana-dashboard/336106)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 2:14pm UTC](https://discuss.elastic.co/t/squid-logs-integration-technical-preview-kibana-dashboard/336106 "2023-06-15T14:14:33Z")

</div>

Got Squid Logs working via Elastic Agent, and verified the log entries are ingested. But I haven't yet figured out if a preconfigured dashboard for this integration is available. I have also tried creating dashboards via…

---

## [How can I identify new elements in an array via Logstash/Elasticsearch?](https://discuss.elastic.co/t/how-can-i-identify-new-elements-in-an-array-via-logstash-elasticsearch/336105)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 2:01pm UTC](https://discuss.elastic.co/t/how-can-i-identify-new-elements-in-an-array-via-logstash-elasticsearch/336105 "2023-06-15T14:01:38Z")

</div>

For the context, I have an API request that returns a few devices and the apps installed in them. here is an example of what the result looks like in the elasticsearch: "hits": \[ { "\_index": "devices\_xxxx", "\_…

---

## [How to avoid warning when starting with discovery.type set to single node](https://discuss.elastic.co/t/how-to-avoid-warning-when-starting-with-discovery-type-set-to-single-node/334087)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 4\
**Last updated:** [June 15, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-to-avoid-warning-when-starting-with-discovery-type-set-to-single-node/334087 "2023-06-15T13:55:02Z")

</div>

Hello; I have upgraded a single-node Elasticsearch from version 7.17 to 8.7. When the node starts up it logs this warning: \[WARN \]\[o.e.c.c.ClusterBootstrapService\] \[elasticsearch\] this node is locked into cluster UUID …

---

## [Can't get rid of warning "this node is locked into cluster UUID but \[cluster.initial\_master\_nodes\] is set to \[Z56EEW81\]; remove this setting to avoid possible data loss caused by subsequent cluster bootstrap attempts"](https://discuss.elastic.co/t/cant-get-rid-of-warning-this-node-is-locked-into-cluster-uuid-but-cluster-initial-master-nodes-is-set-to-z56eew81-remove-this-setting-to-avoid-possible-data-loss-caused-by-subsequent-cluster-bootstrap-attempts/335889)

<div class="topic-metadata">

**Author:** [@CodeTradition](https://discuss.elastic.co/u/CodeTradition)\
**Replies:** 4\
**Last updated:** [June 15, 2023, 1:57pm UTC](https://discuss.elastic.co/t/cant-get-rid-of-warning-this-node-is-locked-into-cluster-uuid-but-cluster-initial-master-nodes-is-set-to-z56eew81-remove-this-setting-to-avoid-possible-data-loss-caused-by-subsequent-cluster-bootstrap-attempts/335889 "2023-06-15T13:57:15Z")

</div>

Hello all, I am using Elasticsearch v8.8.0 on a Windows Server 2019. Below is my Elasticsearch configuration file "elasticsearch.yml" : cluster.name: MyCOMPANY-R7 node.name: ${HOSTNAME} node.roles : \[master, data, ing…

---

## [Response time vs took](https://discuss.elastic.co/t/response-time-vs-took/336065)

<div class="topic-metadata">

**Author:** [@Faisal\_Afzal](https://discuss.elastic.co/u/Faisal_Afzal)\
**Replies:** 3\
**Last updated:** [June 15, 2023, 1:50pm UTC](https://discuss.elastic.co/t/response-time-vs-took/336065 "2023-06-15T13:50:46Z")

</div>

Elastic search performing very slow it will almost took 3 seconds to return a response, however when i look to took attribute it's within 100 ms. Not sure why response time is higher? and what does it mean?.

---

## [Problem configuring "Custom configurations" in the "Custom Logs" integration of Elastic Agent](https://discuss.elastic.co/t/problem-configuring-custom-configurations-in-the-custom-logs-integration-of-elastic-agent/336102)

<div class="topic-metadata">

**Author:** [@Emilio\_Bruno](https://discuss.elastic.co/u/Emilio_Bruno)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 1:38pm UTC](https://discuss.elastic.co/t/problem-configuring-custom-configurations-in-the-custom-logs-integration-of-elastic-agent/336102 "2023-06-15T13:38:38Z")

</div>

Hello, we are trying to replace our filebeat configuration using the new elastic agent. We had no problem to ingest the logs (we are using the Custom Logs integration), we have problem when we try to add custom propert…

---

## [Parsing input as JSON: invalid character '\\x00' looking for beginning of value Filebeat](https://discuss.elastic.co/t/parsing-input-as-json-invalid-character-x00-looking-for-beginning-of-value-filebeat/336095)

<div class="topic-metadata">

**Author:** [@Lou003](https://discuss.elastic.co/u/Lou003)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 12:40pm UTC](https://discuss.elastic.co/t/parsing-input-as-json-invalid-character-x00-looking-for-beginning-of-value-filebeat/336095 "2023-06-15T12:40:12Z")

</div>

Hi everybody! I made a configuration where the data is imported in Elastic through a pipeline using filebeat. This gives in Discover the following error: parsing input as JSON: invalid character '\\x00' looking for begin…

---

## [Collecting logs from Azure EH](https://discuss.elastic.co/t/collecting-logs-from-azure-eh/336088)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 12:05pm UTC](https://discuss.elastic.co/t/collecting-logs-from-azure-eh/336088 "2023-06-15T12:05:00Z")

</div>

Hello, My question is, which tool should i use to collect data from Eh, logstash: Azure Event Hubs plugin | Logstash Reference \[8.8\] | Elastic or filebeat: Azure eventhub input | Filebeat Reference \[8.8\] | Elastic ? Whi…

---

## [Master not discovered, even though quorum is fulfilled](https://discuss.elastic.co/t/master-not-discovered-even-though-quorum-is-fulfilled/336079)

<div class="topic-metadata">

**Author:** [@kley](https://discuss.elastic.co/u/kley)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 11:39am UTC](https://discuss.elastic.co/t/master-not-discovered-even-though-quorum-is-fulfilled/336079 "2023-06-15T11:39:13Z")

</div>

Hey! So, I have this 12 node cluster with elastic 7.17.5 running. During the upgrade process to this version the cluster had issues finding the master node: master not discovered or elected yet, an election requires at…

---

## [Squid Logs \[beta\] for Elastic Agent](https://discuss.elastic.co/t/squid-logs-beta-for-elastic-agent/335999)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 10:15am UTC](https://discuss.elastic.co/t/squid-logs-beta-for-elastic-agent/335999 "2023-06-15T10:15:15Z")

</div>

Looking at this document it mentions using a Squid integration for Elastic Agent: Squid Logs | Elastic docs However, In my 8.8.1 Fleet server /app/home#/tutorial/squidLogs only has instructions for Filebeat, which I get…

---

## [OpenSearch 1.3 - Scheduled Action](https://discuss.elastic.co/t/opensearch-1-3-scheduled-action/336072)

<div class="topic-metadata">

**Author:** [@spike83](https://discuss.elastic.co/u/spike83)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 9:57am UTC](https://discuss.elastic.co/t/opensearch-1-3-scheduled-action/336072 "2023-06-15T09:57:27Z")

</div>

Hi, I'm running an AWS OpenSearch cluster and i'm wondering whether there is the possibility to run an action on a schedule that edits an index. I need to remove a field for an index where the index is over 30 days, bu…

---

## [No Login Page to Access Kibana](https://discuss.elastic.co/t/no-login-page-to-access-kibana/336070)

<div class="topic-metadata">

**Author:** [@jact](https://discuss.elastic.co/u/jact)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 9:09am UTC](https://discuss.elastic.co/t/no-login-page-to-access-kibana/336070 "2023-06-15T09:09:51Z")

</div>

Hi, I installed Elastic Logstash and Kibana in 3 diferent server. everything running well. when i access kibana web, directly in the dashboard without a login page. How to add login page in kibana? I have enabled th…

---

## [Benchmarking using ESRally](https://discuss.elastic.co/t/benchmarking-using-esrally/335735)

<div class="topic-metadata">

**Author:** [@Darshan\_J](https://discuss.elastic.co/u/Darshan_J)\
**Replies:** 10\
**Last updated:** [June 15, 2023, 7:17am UTC](https://discuss.elastic.co/t/benchmarking-using-esrally/335735 "2023-06-15T07:17:22Z")

</div>

Hey there, I'm new to ESRally and I would appreciate some assistance in running esrally with ES running on a remote server. The set-up: There is a remote server which I connect to it via ssh.. it has a single elastics…

---

## [APM custom pipeline with enrich processor does not work](https://discuss.elastic.co/t/apm-custom-pipeline-with-enrich-processor-does-not-work/336026)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 5\
**Last updated:** [June 15, 2023, 8:53am UTC](https://discuss.elastic.co/t/apm-custom-pipeline-with-enrich-processor-does-not-work/336026 "2023-06-15T08:53:26Z")

</div>

Hi all, I am trying to use enrich processor in the injest pipeline and apply into apm custom pipeline, but it does not work. Here is my set up, source index: Enrich process policy: Injest pipeline name: limit\_l…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=508)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=510)
