# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=511

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 512

---

## [Logstash not applying correct system time to ingestion timestamp](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884)

<div class="topic-metadata">

**Author:** [@Anthony\_Zottola](https://discuss.elastic.co/u/Anthony_Zottola)\
**Replies:** 3\
**Last updated:** [June 14, 2023, 4:53pm UTC](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884 "2023-06-14T16:53:50Z")

</div>

Hello, I live in the NA East timezone so currently we are 4 hours behind UTC, I understand that logstash puts the @timestamp in UTC but it is putting in the wrong time. Logstash parsed a log at 10:30 am in my timezone …

---

## [Kafka plugin with every new group id it is pointing to old offset and not able to consume events](https://discuss.elastic.co/t/kafka-plugin-with-every-new-group-id-it-is-pointing-to-old-offset-and-not-able-to-consume-events/335994)

<div class="topic-metadata">

**Author:** [@Selim\_Hassan](https://discuss.elastic.co/u/Selim_Hassan)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 3:36pm UTC](https://discuss.elastic.co/t/kafka-plugin-with-every-new-group-id-it-is-pointing-to-old-offset-and-not-able-to-consume-events/335994 "2023-06-14T15:36:18Z")

</div>

I have pipeline created as input { kafka { group\_id =\> "3fixed1" client\_id =\> "2fixed1" codec =\> avro{ schema\_uri =\> "C:\\LogStash\\KafkaClient\\topology.avsc" encoding =\> "binary" } bootstrap\_servers =\> "obootstap…

---

## [Expiration date password for kibana users](https://discuss.elastic.co/t/expiration-date-password-for-kibana-users/335989)

<div class="topic-metadata">

**Author:** [@valerio.vigliotta](https://discuss.elastic.co/u/valerio.vigliotta)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 3:34pm UTC](https://discuss.elastic.co/t/expiration-date-password-for-kibana-users/335989 "2023-06-14T15:34:06Z")

</div>

Hi, We have an ELK stack on premise V. 8.5.3 with free licence. We need to be able to set the expiration date to users Kibana password every 6 months. The users that i am referred is those from "Menu"--\>"Stack Managamen…

---

## [Elastic Agent 8.8.0 disk space requirement](https://discuss.elastic.co/t/elastic-agent-8-8-0-disk-space-requirement/334723)

<div class="topic-metadata">

**Author:** [@schapman](https://discuss.elastic.co/u/schapman)\
**Replies:** 6\
**Last updated:** [June 14, 2023, 2:49pm UTC](https://discuss.elastic.co/t/elastic-agent-8-8-0-disk-space-requirement/334723 "2023-06-14T14:49:08Z")

</div>

Just a heads up if installing the latest elastic agent on Linux servers with relatively small free space... It looks like the elastic-agent's requirement for disk space has increased (almost doubled?) over the past year…

---

## [Create ElasticSearch cluster with 2 or 3 nodes](https://discuss.elastic.co/t/create-elasticsearch-cluster-with-2-or-3-nodes/335901)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 4\
**Last updated:** [June 14, 2023, 1:45pm UTC](https://discuss.elastic.co/t/create-elasticsearch-cluster-with-2-or-3-nodes/335901 "2023-06-14T13:45:46Z")

</div>

I need to create an Elasticsearch cluster on Ubuntu machines, but to ensure high availability I would like to have more than one node in case I need to update or upgrade the server. Is there any material that teaches ho…

---

## [Elasticsearch: Terms Aggregation Bucket Order is not skipping the unmapped fields](https://discuss.elastic.co/t/elasticsearch-terms-aggregation-bucket-order-is-not-skipping-the-unmapped-fields/335986)

<div class="topic-metadata">

**Author:** [@crchaulagain1](https://discuss.elastic.co/u/crchaulagain1)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 1:45pm UTC](https://discuss.elastic.co/t/elasticsearch-terms-aggregation-bucket-order-is-not-skipping-the-unmapped-fields/335986 "2023-06-14T13:45:04Z")

</div>

My Elasticsearch alias is pointed to two different indices where the mapping is of a different type. I want the query to execute and get the response from the index where the given filter matches. But the terms aggregati…

---

## [Spike on CPU usage relates to the increase of fielddata memory](https://discuss.elastic.co/t/spike-on-cpu-usage-relates-to-the-increase-of-fielddata-memory/335303)

<div class="topic-metadata">

**Author:** [@GustavoSantos](https://discuss.elastic.co/u/GustavoSantos)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 1:43pm UTC](https://discuss.elastic.co/t/spike-on-cpu-usage-relates-to-the-increase-of-fielddata-memory/335303 "2023-06-14T13:43:41Z")

</div>

Hi team, We faced a very weird situation in one of our production clusters. Suddenly the CPU utilization of all nodes got 100% after being consistently under 30% for a long time. Looking at Kibana metrics, the only var…

---

## [How to highlight multifields? Iis there a way to highlight all results with the same multifield (same source, different analyzers) Multi-fields with multiple analyzers](https://discuss.elastic.co/t/how-to-highlight-multifields-iis-there-a-way-to-highlight-all-results-with-the-same-multifield-same-source-different-analyzers-multi-fields-with-multiple-analyzers/335985)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 1:41pm UTC](https://discuss.elastic.co/t/how-to-highlight-multifields-iis-there-a-way-to-highlight-all-results-with-the-same-multifield-same-source-different-analyzers-multi-fields-with-multiple-analyzers/335985 "2023-06-14T13:41:05Z")

</div>

How to highlight multifield? Is there a way to highlight all results with the same multifield (same source, different analyzers)? Multi-fields with multiple analyzers

---

## [Bool Filter doubt / Match\_all](https://discuss.elastic.co/t/bool-filter-doubt-match-all/335982)

<div class="topic-metadata">

**Author:** [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 1:19pm UTC](https://discuss.elastic.co/t/bool-filter-doubt-match-all/335982 "2023-06-14T13:19:32Z")

</div>

Hi everybody. Maybe this is a silly doubt but if someone can answer. I have 3 docs, 1 with status:true field, 1 with status:false field and 1 doc without status field. POST idx\_test/\_bulk {"index":{}} {"name":"xpto 1"…

---

## [After restarting the master node, data and client nodes cannot discover the master](https://discuss.elastic.co/t/after-restarting-the-master-node-data-and-client-nodes-cannot-discover-the-master/334804)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 10\
**Last updated:** [June 14, 2023, 1:11pm UTC](https://discuss.elastic.co/t/after-restarting-the-master-node-data-and-client-nodes-cannot-discover-the-master/334804 "2023-06-14T13:11:53Z")

</div>

Hi, I am using elasticsearch cluster (8.7.0) on Kubernetes, I have 1 master, 1 client and 3 data nodes. After the restart of my master node, the other nodes cannot discover the master again. This is in the log of the d…

---

## [Need help shipping stdout and stderr logs of docker container to different Elasticsearch/kibana](https://discuss.elastic.co/t/need-help-shipping-stdout-and-stderr-logs-of-docker-container-to-different-elasticsearch-kibana/335978)

<div class="topic-metadata">

**Author:** [@Shobana\_Nagarajan](https://discuss.elastic.co/u/Shobana_Nagarajan)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 12:30pm UTC](https://discuss.elastic.co/t/need-help-shipping-stdout-and-stderr-logs-of-docker-container-to-different-elasticsearch-kibana/335978 "2023-06-14T12:30:31Z")

</div>

Hi, I need to separate stdout and stderr streams from my docker container app and ship them to different elasticsearch/kibana hosts. Is it possible? With beats+elasticsearch+kibana, i was not able to get it working. Re…

---

## [Limit a role and API key privledges](https://discuss.elastic.co/t/limit-a-role-and-api-key-privledges/335883)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 12:29pm UTC](https://discuss.elastic.co/t/limit-a-role-and-api-key-privledges/335883 "2023-06-14T12:29:22Z")

</div>

Hello, I have a use case for creating a 'stack maintenance' user that will be called up with Ansible to perform the cluster.routing.allocation.enable action to limit shard allocation before Elasticsearch is stopped and …

---

## [Elastic Augeas Not Working](https://discuss.elastic.co/t/elastic-augeas-not-working/335718)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 4\
**Last updated:** [June 14, 2023, 11:59am UTC](https://discuss.elastic.co/t/elastic-augeas-not-working/335718 "2023-06-14T11:59:40Z")

</div>

SELECT value FROM augeas WHERE path = '/etc/resolv.conf' AND label = 'nameserver'; SELECT \* FROM USERS When I am running this command, it's running successfully, but it's not retrieving the results.

---

## [Search by full name](https://discuss.elastic.co/t/search-by-full-name/335960)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 11:57am UTC](https://discuss.elastic.co/t/search-by-full-name/335960 "2023-06-14T11:57:40Z")

</div>

Hi everyone. I have an index wich consists of 3 fields: sys\_name full\_name man\_id. I want to search by full name wich consists of 3 words: GET managers/\_search { "query": { "match": { "full\_name": "William Garvey J…

---

## [Remove multiple spaces with script](https://discuss.elastic.co/t/remove-multiple-spaces-with-script/335638)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 11:56am UTC](https://discuss.elastic.co/t/remove-multiple-spaces-with-script/335638 "2023-06-14T11:56:26Z")

</div>

Hello, In street fields, the number of spaces has constantly changing values as follows. "street": "YALIM MAH. last/ şajdsj sdkdşfd" I can remove the spaces as follows, bu…

---

## [Elasticsearch snapshots fail everyday](https://discuss.elastic.co/t/elasticsearch-snapshots-fail-everyday/335747)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 11:23am UTC](https://discuss.elastic.co/t/elasticsearch-snapshots-fail-everyday/335747 "2023-06-14T11:23:01Z")

</div>

Hi, I am using elasticsearch 8.7 in out production cluster on Azure kubernetes platform which has 8 data and master nodes and almost 4TB per node disks being used to store our observability data. we have 699 indexes as …

---

## [How can I show the value of a specific field from the most recent document in a time frame](https://discuss.elastic.co/t/how-can-i-show-the-value-of-a-specific-field-from-the-most-recent-document-in-a-time-frame/335964)

<div class="topic-metadata">

**Author:** [@Harold\_Van\_der\_Veken](https://discuss.elastic.co/u/Harold_Van_der_Veken)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 11:22am UTC](https://discuss.elastic.co/t/how-can-i-show-the-value-of-a-specific-field-from-the-most-recent-document-in-a-time-frame/335964 "2023-06-14T11:22:40Z")

</div>

I have an ingest of logs where 1 field gets updated each time. Let say every minute I receive a logline and the count field holds certain value. In Kibana I can select for example the last hour as timeframe. Now I wo…

---

## [Unable to display large text fields in Kibana Markdown visualization](https://discuss.elastic.co/t/unable-to-display-large-text-fields-in-kibana-markdown-visualization/324981)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 9\
**Last updated:** [June 14, 2023, 10:22am UTC](https://discuss.elastic.co/t/unable-to-display-large-text-fields-in-kibana-markdown-visualization/324981 "2023-06-14T10:22:33Z")

</div>

Hello, I have one field store in ES that has a big length, around 35.000 - 40.000 characters. They are stored correctly in ES, I can see them in Discover page, but when I want to use them in a markdown visualization (T…

---

## [Getting HIgh s3 cost on LISTBUCKET OPERATION using logstash s3 pipeline](https://discuss.elastic.co/t/getting-high-s3-cost-on-listbucket-operation-using-logstash-s3-pipeline/335970)

<div class="topic-metadata">

**Author:** [@Dharampal\_Singh](https://discuss.elastic.co/u/Dharampal_Singh)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 9:53am UTC](https://discuss.elastic.co/t/getting-high-s3-cost-on-listbucket-operation-using-logstash-s3-pipeline/335970 "2023-06-14T09:53:45Z")

</div>

Hi elastic Team, We have 3 logstash s3 pipeine from buckets(elb,cloudflare,cloudtrail) .Currently we are getting high s3 list bucket operation cost on these buckets.We want to know is there any way so we can minimize …

---

## [Replacing certificates on the server](https://discuss.elastic.co/t/replacing-certificates-on-the-server/335967)

<div class="topic-metadata">

**Author:** [@lolkerz](https://discuss.elastic.co/u/lolkerz)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 9:42am UTC](https://discuss.elastic.co/t/replacing-certificates-on-the-server/335967 "2023-06-14T09:42:38Z")

</div>

Hello everyone. Previously, I had a certificate on the Logstash server. At the moment I have created a new certificate. Is it enough for me to simply replace it on the server, or does something need to be done beforehand…

---

## [Checking elasticsearch backups](https://discuss.elastic.co/t/checking-elasticsearch-backups/335955)

<div class="topic-metadata">

**Author:** [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 9:37am UTC](https://discuss.elastic.co/t/checking-elasticsearch-backups/335955 "2023-06-14T09:37:30Z")

</div>

i have Elasticsearch on which snapshots are taken daily, there is also a separately Elasticsearch which every day is restored by a script from the last snapshot and after restoration sends to the mail how much space th…

---

## [Unable to execute commands in Logstash pipeline](https://discuss.elastic.co/t/unable-to-execute-commands-in-logstash-pipeline/335199)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 9:25am UTC](https://discuss.elastic.co/t/unable-to-execute-commands-in-logstash-pipeline/335199 "2023-06-14T09:25:28Z")

</div>

I have some pipelines in my logstash. In that pipelines i am executing some commands as per some conditions. After creating the pipeline i used the following command to test the pipeline /usr/share/logstash/bin/lo…

---

## [Question about elasticsearch index and logstash ingestion](https://discuss.elastic.co/t/question-about-elasticsearch-index-and-logstash-ingestion/335057)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 20\
**Last updated:** [June 14, 2023, 9:10am UTC](https://discuss.elastic.co/t/question-about-elasticsearch-index-and-logstash-ingestion/335057 "2023-06-14T09:10:27Z")

</div>

Hello everyone I'd like to ask you 2 questions. I receive approximately 270 csv per month, 9 of them per day. Each csv is between 1kB and 3MG in size. All these csv are sent to the same index on elasticsearch with log…

---

## [Info about the free ELK tools](https://discuss.elastic.co/t/info-about-the-free-elk-tools/335044)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 6\
**Last updated:** [June 14, 2023, 8:57am UTC](https://discuss.elastic.co/t/info-about-the-free-elk-tools/335044 "2023-06-14T08:57:36Z")

</div>

Hi Elasticsearch Community, I need some advice, I am creating a New ELK stack where i am going to store oracle log in ES and by using the logstash. I would like get the some information if i use the below the additional…

---

## [Fleet not working after update](https://discuss.elastic.co/t/fleet-not-working-after-update/335950)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 8:33am UTC](https://discuss.elastic.co/t/fleet-not-working-after-update/335950 "2023-06-14T08:33:19Z")

</div>

Hello, Unfortunately, by mistake, one of my elasticsearch hosts updated from version 8.5.3 to 8.8.0, so this caused a lot of problems with my installation. I've already updated the other 2 elasticserver hosts, but now …

---

## [Overwride field "\_time" in splunk](https://discuss.elastic.co/t/overwride-field-time-in-splunk/335944)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 8:12am UTC](https://discuss.elastic.co/t/overwride-field-time-in-splunk/335944 "2023-06-14T08:12:24Z")

</div>

Hi I have logstash config that send logs to Splunk HEC. these data contain field that call "time". Now question is: does it possible to consider "time" as "\_time" on logstash config? FYI: i want to consider this time…

---

## [My xpack license shows valid but monitoring tab is still showing the license got expired](https://discuss.elastic.co/t/my-xpack-license-shows-valid-but-monitoring-tab-is-still-showing-the-license-got-expired/335943)

<div class="topic-metadata">

**Author:** [@Shuvo-Hoque](https://discuss.elastic.co/u/Shuvo-Hoque)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 8:01am UTC](https://discuss.elastic.co/t/my-xpack-license-shows-valid-but-monitoring-tab-is-still-showing-the-license-got-expired/335943 "2023-06-14T08:01:21Z")

</div>

Hi guys! My basic license got expired and I have re-issued and installed the license again using curl -X PUT $HOST/\_xpack/license api . So when I check the license this way : curl -X GET $HOST/\_xpack/license ; It show…

---

## [Shards are going to Intialized state againa and again, like in every 15 mins](https://discuss.elastic.co/t/shards-are-going-to-intialized-state-againa-and-again-like-in-every-15-mins/335902)

<div class="topic-metadata">

**Author:** [@priyankaMS](https://discuss.elastic.co/u/priyankaMS)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 6:59am UTC](https://discuss.elastic.co/t/shards-are-going-to-intialized-state-againa-and-again-like-in-every-15-mins/335902 "2023-06-14T06:59:02Z")

</div>

My Elasticsearch cluster is going to yellow state in about every 15 min, becuase 2 replica shards are going to initialization state. After 5 mins or so, cluster is going back to green state. Error Logs: \[o.e.t.Outbou…

---

## [java.lang.OutOfMemoryError: Java heap space (logstash, http\_poller)](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space-logstash-http-poller/335935)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 6:39am UTC](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space-logstash-http-poller/335935 "2023-06-14T06:39:55Z")

</div>

Hi I run logstash to fetch data from infludb via http\_poller and return below error: java.lang.OutOfMemoryError: Java heap space Here is the jvm.options: -Xms10g -Xmx10g Now question is: data locate on influxdb are …

---

## [Index to red state cluster](https://discuss.elastic.co/t/index-to-red-state-cluster/335763)

<div class="topic-metadata">

**Author:** [@DJ\_Zhu](https://discuss.elastic.co/u/DJ_Zhu)\
**Replies:** 10\
**Last updated:** [June 14, 2023, 6:59am UTC](https://discuss.elastic.co/t/index-to-red-state-cluster/335763 "2023-06-14T06:59:46Z")

</div>

I have a question regarding shard selection during index/bulk operations in Elasticsearch version 6.8.6. In my cluster, I have three data nodes: A, B, and C. The shards (with no replicas) are evenly allocated across the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=510)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=512)
