# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=521

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 522

---

## [Dynamic data (no code) scenario strategy](https://discuss.elastic.co/t/dynamic-data-no-code-scenario-strategy/334870)

<div class="topic-metadata">

**Author:** [@Zak\_Sesti](https://discuss.elastic.co/u/Zak_Sesti)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 1:38am UTC](https://discuss.elastic.co/t/dynamic-data-no-code-scenario-strategy/334870 "2023-06-06T01:38:52Z")

</div>

I use ES for searching of my basic CRUD constructs. But now we need to expand to help us search, sort, paginate our no-code constructs. These are json documents that have 100% dynamic fields. Some rough numbers: We …

---

## [Can't use ApiKey to update rule](https://discuss.elastic.co/t/cant-use-apikey-to-update-rule/335235)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 2:51pm UTC](https://discuss.elastic.co/t/cant-use-apikey-to-update-rule/335235 "2023-06-05T14:51:33Z")

</div>

I'm trying to update alerting rules in kibana, if I create an apikey, I can see the rules, and I can authenticate, but when trying to update an alerting rule, it gives me this error: {"statusCode":400,"error":"Bad Reque…

---

## [Profile API](https://discuss.elastic.co/t/profile-api/335217)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 1:06am UTC](https://discuss.elastic.co/t/profile-api/335217 "2023-06-06T01:06:58Z")

</div>

I ran the profile API for my query that took 15s to run. I have a very big json as output. I am unable to determine why it is taking 15s. Can someone help me read or what to look for in the output of \_profile?

---

## [JDBC input error when using schedule without last run](https://discuss.elastic.co/t/jdbc-input-error-when-using-schedule-without-last-run/335243)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 10:19pm UTC](https://discuss.elastic.co/t/jdbc-input-error-when-using-schedule-without-last-run/335243 "2023-06-05T22:19:11Z")

</div>

Hi, I need to query a database every 1 minute and get all the results of the query, so I use schedule but no last\_run\_metadata\_path. logstash give an error, but still que the data indexed in ES. logstash look for this…

---

## [ILM not deleting data](https://discuss.elastic.co/t/ilm-not-deleting-data/335204)

<div class="topic-metadata">

**Author:** [@Vitor\_Nilson](https://discuss.elastic.co/u/Vitor_Nilson)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 10:11pm UTC](https://discuss.elastic.co/t/ilm-not-deleting-data/335204 "2023-06-05T22:11:26Z")

</div>

Hello, I'm trying to set a ILM to an index, but it's not deleting old data. This is my ILM: PUT \_ilm/policy/kong\_lifecycle { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { …

---

## [Metricbeat Promethes merging queries](https://discuss.elastic.co/t/metricbeat-promethes-merging-queries/334704)

<div class="topic-metadata">

**Author:** [@evileric77](https://discuss.elastic.co/u/evileric77)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 8:59pm UTC](https://discuss.elastic.co/t/metricbeat-promethes-merging-queries/334704 "2023-06-05T20:59:19Z")

</div>

This has been mentioned before here: But as there is no resolution there I'm posting here and will open an issue on github shortly. With the Prometheus module if you define 2 items that leverage the module, metricbeat …

---

## [ES 8.6.2 - puzzling "Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\]"?](https://discuss.elastic.co/t/es-8-6-2-puzzling-authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/335152)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 8:01pm UTC](https://discuss.elastic.co/t/es-8-6-2-puzzling-authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/335152 "2023-06-05T20:01:41Z")

</div>

I am aware this error has come up before, but please note the version, 8.6.2. Most of the others are about v7. So far I have found the whole configuration of 8.6.2. much more of a challenge (from the security PoV) than v…

---

## [Unable to apply memory lock to deploy elastic 8 on k8s](https://discuss.elastic.co/t/unable-to-apply-memory-lock-to-deploy-elastic-8-on-k8s/334897)

<div class="topic-metadata">

**Author:** [@rsingh\_2023](https://discuss.elastic.co/u/rsingh_2023)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 8:08pm UTC](https://discuss.elastic.co/t/unable-to-apply-memory-lock-to-deploy-elastic-8-on-k8s/334897 "2023-06-05T20:08:51Z")

</div>

I am running into issues with deploying elastic version 8.7 on kubernetes (k8s) I am using this docker image for elastic version 8.7 I have enabled bootstrap memory\_lock as "true" but I see these error logs in my elast…

---

## [Does it use more storage with "fields" mapping?](https://discuss.elastic.co/t/does-it-use-more-storage-with-fields-mapping/334883)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 6:43pm UTC](https://discuss.elastic.co/t/does-it-use-more-storage-with-fields-mapping/334883 "2023-06-05T18:43:22Z")

</div>

"some\_label" : { "type" : "keyword", "fields" : { "keyword" : { "type" : "keyword", "ignore\_above" : 256 } } } Supposed I have a …

---

## [In Kibana's Maps, selecting time range narrows map points, but not vice versa](https://discuss.elastic.co/t/in-kibanas-maps-selecting-time-range-narrows-map-points-but-not-vice-versa/334467)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 9\
**Last updated:** [June 5, 2023, 6:22pm UTC](https://discuss.elastic.co/t/in-kibanas-maps-selecting-time-range-narrows-map-points-but-not-vice-versa/334467 "2023-06-05T18:22:36Z")

</div>

I've been able to successfully query and plot documents with geo\_points in maps in Kibana alongside time series plots of other data in standard fashion. When I select the time range in a time series plot, it correctly na…

---

## [Help optimize my query](https://discuss.elastic.co/t/help-optimize-my-query/335250)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 5:44pm UTC](https://discuss.elastic.co/t/help-optimize-my-query/335250 "2023-06-05T17:44:52Z")

</div>

I have this query: "query": { "bool": { "filter": { "bool": { "must": \[ { "range": { "movies-date": { "gt": "2018", "lt": "2022" } } }, given that this is a must query, does it make sense to move the range …

---

## [When/how often/from where does "filebeat setup -e" need to be run?](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 4:45pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246 "2023-06-05T16:45:31Z")

</div>

I'm trying to wrap my head around "filebeat setup -e". Let's say I've already got filebeat up and running with a couple of modules, and I want to roll out a new module to a bunch of servers. Which of these would make s…

---

## [Cloud Provider - need change](https://discuss.elastic.co/t/cloud-provider-need-change/335113)

<div class="topic-metadata">

**Author:** [@Eduardo\_Maia](https://discuss.elastic.co/u/Eduardo_Maia)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 3:13pm UTC](https://discuss.elastic.co/t/cloud-provider-need-change/335113 "2023-06-05T15:13:49Z")

</div>

Hi, my enterprise use Elasticsearch and your first Provider was Google(GCP) and after change to Azure, when decide to change the cloud provider to Google again, we didn't get. And the problem is appear only Azure, and n…

---

## [Log4j2 vulnerability mitigation](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 6\
**Last updated:** [June 5, 2023, 3:33pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213 "2023-06-05T15:33:18Z")

</div>

Hello all, I was checking the actions needed from our side in the ELK cluster to mitigate the Log4j2 vulnerability found in Dec 2021. we are using 7.9.2 for all ELK components. After investigating and checking the below…

---

## [Considering using L4 or kafka](https://discuss.elastic.co/t/considering-using-l4-or-kafka/335238)

<div class="topic-metadata">

**Author:** [@a01066278824](https://discuss.elastic.co/u/a01066278824)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 3:15pm UTC](https://discuss.elastic.co/t/considering-using-l4-or-kafka/335238 "2023-06-05T15:15:30Z")

</div>

im considering two ways. first, using L4 between Beats and logstash. second, using Kafka between beats and logstahs. which way is more effective one? and im wondering if is it possible Beats - Kafka - L4 - Logstash. …

---

## [iIhave problems Fleet daemonset collect kubernetes container logs](https://discuss.elastic.co/t/iihave-problems-fleet-daemonset-collect-kubernetes-container-logs/335239)

<div class="topic-metadata">

**Author:** [@hanhee](https://discuss.elastic.co/u/hanhee)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 3:10pm UTC](https://discuss.elastic.co/t/iihave-problems-fleet-daemonset-collect-kubernetes-container-logs/335239 "2023-06-05T15:10:11Z")

</div>

hello i have some problems operating elastic-agent with fleet i did the settings elastic-agent usging kubernetes daemonset and kubernetes integration in fleet and that setting works normally without problems but sud…

---

## [Primary shard storage bottleneck](https://discuss.elastic.co/t/primary-shard-storage-bottleneck/335197)

<div class="topic-metadata">

**Author:** [@Hoang\_Vu](https://discuss.elastic.co/u/Hoang_Vu)\
**Replies:** 6\
**Last updated:** [June 5, 2023, 3:05pm UTC](https://discuss.elastic.co/t/primary-shard-storage-bottleneck/335197 "2023-06-05T15:05:05Z")

</div>

Hi everyone, I want to ask why the primary shard indexes for 1 day are only stored on 1 Hot3 node. Causing the Hot3 node to get a high CPU boost and denying the bulk request from the Coordination node that controls my fo…

---

## [How to change Data type Runtime and change filter type range slider to dropdown list](https://discuss.elastic.co/t/how-to-change-data-type-runtime-and-change-filter-type-range-slider-to-dropdown-list/335179)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-to-change-data-type-runtime-and-change-filter-type-range-slider-to-dropdown-list/335179 "2023-06-05T14:15:55Z")

</div>

Hi, How to change data type long to String and Range slider to the dropdown list. Please find attached a snap for your reference.

---

## [Exiting: error loading config file: yaml: line 26: did not find expected key](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-26-did-not-find-expected-key/334250)

<div class="topic-metadata">

**Author:** [@FredMir](https://discuss.elastic.co/u/FredMir)\
**Replies:** 8\
**Last updated:** [June 5, 2023, 1:47pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-26-did-not-find-expected-key/334250 "2023-06-05T13:47:56Z")

</div>

I installed filebeat-7.16.3-x86\_64.rpm on a different server and trying to send output logs to logstash but I receive this error when try to run filebeat. Also, when trying to enable modules I get the same error. Would y…

---

## [What's the efficient way to filter and transfer data from Elastic](https://discuss.elastic.co/t/whats-the-efficient-way-to-filter-and-transfer-data-from-elastic/335006)

<div class="topic-metadata">

**Author:** [@Monkey\_D\_Luffy1](https://discuss.elastic.co/u/Monkey_D_Luffy1)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 1:23pm UTC](https://discuss.elastic.co/t/whats-the-efficient-way-to-filter-and-transfer-data-from-elastic/335006 "2023-06-05T13:23:43Z")

</div>

I have an Elastic Index which has 100 million documents inside it and I want to understand whats the efficient way of writing a python script to filter values and then transfer the filtered values to a SQL storage ?

---

## [How to encode the aggregation response and get doc by id response values in Elasticsearch 7.17.x](https://discuss.elastic.co/t/how-to-encode-the-aggregation-response-and-get-doc-by-id-response-values-in-elasticsearch-7-17-x/335220)

<div class="topic-metadata">

**Author:** [@Karunakaran-ti](https://discuss.elastic.co/u/Karunakaran-ti)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 1:05pm UTC](https://discuss.elastic.co/t/how-to-encode-the-aggregation-response-and-get-doc-by-id-response-values-in-elasticsearch-7-17-x/335220 "2023-06-05T13:05:27Z")

</div>

I am writing a custom Elasticsearch plugin. I want to do encode the response values from aggregation response and get doc by id. Using Elasticsearch v7.17.x I want to know what are interface/classes to be used from Ela…

---

## [JWT Realm configuration for Elasticsearch REST APIs authentication](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 11:35am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776 "2023-06-05T11:35:13Z")

</div>

I am new to Elasticsearch JWT Realm configuration. I am using trail version of Elasticsearch 8.7.1. I am configuring JWT Realm as follows in elasticsearch.yml xpack.security.authc.realms.jwt.jwt1: order: 1 token\_type…

---

## [Elasticsearch NEST deserializing issue. (Potential BUG)](https://discuss.elastic.co/t/elasticsearch-nest-deserializing-issue-potential-bug/335200)

<div class="topic-metadata">

**Author:** [@Jacques\_du\_Plessis](https://discuss.elastic.co/u/Jacques_du_Plessis)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 11:09am UTC](https://discuss.elastic.co/t/elasticsearch-nest-deserializing-issue-potential-bug/335200 "2023-06-05T11:09:06Z")

</div>

I am getting the following error while debugging the code. Basically I have an issue where I cant deserialize the response, see this How to run multiple search templates using NEST In frustration i pulled the github cod…

---

## [Filtering with nested query inner\_hits count](https://discuss.elastic.co/t/filtering-with-nested-query-inner-hits-count/335202)

<div class="topic-metadata">

**Author:** [@LaySoft](https://discuss.elastic.co/u/LaySoft)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 10:08am UTC](https://discuss.elastic.co/t/filtering-with-nested-query-inner-hits-count/335202 "2023-06-05T10:08:26Z")

</div>

I have the following query: "query": { "nested": { "path": "cuccok", "inner\_hits": {}, "query": { "bool": { "must": \[ …

---

## [Highlight in the field response](https://discuss.elastic.co/t/highlight-in-the-field-response/334955)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 10:07am UTC](https://discuss.elastic.co/t/highlight-in-the-field-response/334955 "2023-06-05T10:07:24Z")

</div>

Good morning, I have an application that read the results from my query in elasticsearch and I take all the fields of the response and after it, I put it in a windows form for the user. Now I would like remark the part…

---

## [Add\_docker\_metadata is not able to pick container.labels.com\_amazonaws\_ecs\_container-name for a short living containers](https://discuss.elastic.co/t/add-docker-metadata-is-not-able-to-pick-container-labels-com-amazonaws-ecs-container-name-for-a-short-living-containers/335196)

<div class="topic-metadata">

**Author:** [@Maciej\_Piasecki](https://discuss.elastic.co/u/Maciej_Piasecki)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 9:32am UTC](https://discuss.elastic.co/t/add-docker-metadata-is-not-able-to-pick-container-labels-com-amazonaws-ecs-container-name-for-a-short-living-containers/335196 "2023-06-05T09:32:40Z")

</div>

Hi, I am running some short living containers and I noticed that add\_docker\_metadata is not able to access container.labels.com\_amazonaws\_ecs\_container-name at a random frequency. I am using a rename like this: - re…

---

## [C# ElasticClient search - field name upper case issue](https://discuss.elastic.co/t/c-elasticclient-search-field-name-upper-case-issue/334903)

<div class="topic-metadata">

**Author:** [@Yujie\_S](https://discuss.elastic.co/u/Yujie_S)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 9:28am UTC](https://discuss.elastic.co/t/c-elasticclient-search-field-name-upper-case-issue/334903 "2023-06-05T09:28:09Z")

</div>

My record is like this: { "\_index": "cmmtest2", "id": "q3\_WdIgBcz5F0I953TG", "\_score": 1, "\_source": { "characteristic": "150 W8 Prof 0.1 J", "actual": 0.019991, "nominal": 0, "partno": "2022\_7933 S2", "XBAR"…

---

## [Enriching data with ProxyIP database](https://discuss.elastic.co/t/enriching-data-with-proxyip-database/335169)

<div class="topic-metadata">

**Author:** [@Hitz2403](https://discuss.elastic.co/u/Hitz2403)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 8:50am UTC](https://discuss.elastic.co/t/enriching-data-with-proxyip-database/335169 "2023-06-05T08:50:40Z")

</div>

Hi everyone, I need help enriching data with IP Proxy database like geoip plugin, has anyone done this before? Docs or something can help?

---

## [Unable to find valid sertification path to requested target](https://discuss.elastic.co/t/unable-to-find-valid-sertification-path-to-requested-target/334810)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 8:20am UTC](https://discuss.elastic.co/t/unable-to-find-valid-sertification-path-to-requested-target/334810 "2023-06-05T08:20:37Z")

</div>

Hi, I have a watcher with webhook action. And get an error when the watcher is firing "type": "s\_s\_l\_handshake\_exception", "reason": " PKIX path building failed: sun.security.provider.certpath.SunCertPathBuildException…

---

## [Apply ILM to existing index](https://discuss.elastic.co/t/apply-ilm-to-existing-index/334022)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 8\
**Last updated:** [June 5, 2023, 8:05am UTC](https://discuss.elastic.co/t/apply-ilm-to-existing-index/334022 "2023-06-05T08:05:55Z")

</div>

Hello, I use Elastic 7.17. I have created an ILM and applied it to the existing indexes through the Kibana UI (section Index Management). Each day, an index is automaticaly created but has no ILM associated. How can …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=520)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=522)
