# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=524

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 525

---

## [Create Apache Response Code Field](https://discuss.elastic.co/t/create-apache-response-code-field/334913)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:08pm UTC](https://discuss.elastic.co/t/create-apache-response-code-field/334913 "2023-06-01T18:08:14Z")

</div>

Hi Guys, Can anyone help me to do the following configuration to work as expected. I'm trying to create the separate field for apache response code status using grok filter but it print IP address first two octect. Gr…

---

## [Can we have multiple destinations in one jms plugin in logstash cofiguration?](https://discuss.elastic.co/t/can-we-have-multiple-destinations-in-one-jms-plugin-in-logstash-cofiguration/334910)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:02pm UTC](https://discuss.elastic.co/t/can-we-have-multiple-destinations-in-one-jms-plugin-in-logstash-cofiguration/334910 "2023-06-01T18:02:47Z")

</div>

So my requirement is want to insert multiple destination name in one JMS plugin. Writing multiple JMS input plugin for more than 1 destination is bit hectic. So, how can we achieve this with one single jms input plugin. …

---

## [How to Setting single table or specific table output to BigQuery?](https://discuss.elastic.co/t/how-to-setting-single-table-or-specific-table-output-to-bigquery/335022)

<div class="topic-metadata">

**Author:** [@aidensV](https://discuss.elastic.co/u/aidensV)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 5:08pm UTC](https://discuss.elastic.co/t/how-to-setting-single-table-or-specific-table-output-to-bigquery/335022 "2023-06-01T17:08:40Z")

</div>

BigQuery table ID prefix to be used when creating new tables for log data. Table name will be \<table\_prefix\>\<table\_separator\>\<date\>

---

## [Kibana plugin 'yarn dev --watch' fails in Kibana 8.8.0](https://discuss.elastic.co/t/kibana-plugin-yarn-dev-watch-fails-in-kibana-8-8-0/334706)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 4:01pm UTC](https://discuss.elastic.co/t/kibana-plugin-yarn-dev-watch-fails-in-kibana-8-8-0/334706 "2023-06-01T16:01:56Z")

</div>

We have recently upgraded from Kibana 8.6.2 to 8.8.0. We are having issues launching the dev environment which now requires the use of yarn dev --watch as per doc kbujold@yow-kbujold-lx-vm2:wind$ yarn dev --watch yarn r…

---

## [Cross Cluster Replication for existing indexes](https://discuss.elastic.co/t/cross-cluster-replication-for-existing-indexes/334515)

<div class="topic-metadata">

**Author:** [@vvsh](https://discuss.elastic.co/u/vvsh)\
**Replies:** 8\
**Last updated:** [June 1, 2023, 3:58pm UTC](https://discuss.elastic.co/t/cross-cluster-replication-for-existing-indexes/334515 "2023-06-01T15:58:53Z")

</div>

Hello! I am considering CCR as a tool to migrate all the data (including historical data) from a source Elasticsearch single-node cluster to a target Elasticsearch multi-node cluster (both clusters have 7.17.7 version). …

---

## [Mutual tls between fluentd(act as client) and elasticsearch(act as server)](https://discuss.elastic.co/t/mutual-tls-between-fluentd-act-as-client-and-elasticsearch-act-as-server/334816)

<div class="topic-metadata">

**Author:** [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 3:05pm UTC](https://discuss.elastic.co/t/mutual-tls-between-fluentd-act-as-client-and-elasticsearch-act-as-server/334816 "2023-06-01T15:05:33Z")

</div>

Hi I am trying to establish mutual tls between fluentd and elasticsearch. I have followed steps described in https://www.elastic.co/guide/en/elasticsearch/reference/8.7/security-basic-setup.html#generate-certificates …

---

## [My logstash conf file doesn't show me the output I don't what's the problem with that](https://discuss.elastic.co/t/my-logstash-conf-file-doesnt-show-me-the-output-i-dont-whats-the-problem-with-that/334999)

<div class="topic-metadata">

**Author:** [@Viknesh.S](https://discuss.elastic.co/u/Viknesh.S)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 3:19pm UTC](https://discuss.elastic.co/t/my-logstash-conf-file-doesnt-show-me-the-output-i-dont-whats-the-problem-with-that/334999 "2023-06-01T15:19:26Z")

</div>

---

## [Connecting elastic search with microsoft fabric](https://discuss.elastic.co/t/connecting-elastic-search-with-microsoft-fabric/335000)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 3:04pm UTC](https://discuss.elastic.co/t/connecting-elastic-search-with-microsoft-fabric/335000 "2023-06-01T15:04:19Z")

</div>

Microsoft has released fabric for data analysis. It can connect to many types and sources of data How to connect elasticsearch data to microsoft fabric?

---

## [ElasticAgent to multiple locations](https://discuss.elastic.co/t/elasticagent-to-multiple-locations/334989)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 3:01pm UTC](https://discuss.elastic.co/t/elasticagent-to-multiple-locations/334989 "2023-06-01T15:01:18Z")

</div>

I'm using the default elastic agents with windows integrations and some linux ones with linux integrations. Is there a way to send the data from these agents to two locations and two ports? a logstash and elasticsearch …

---

## [Can anyone share the dockercompose yaml file for elasticsearch8 and kibana8 installation with xpack.security](https://discuss.elastic.co/t/can-anyone-share-the-dockercompose-yaml-file-for-elasticsearch8-and-kibana8-installation-with-xpack-security/334979)

<div class="topic-metadata">

**Author:** [@vikranthshetty02413](https://discuss.elastic.co/u/vikranthshetty02413)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 2:14pm UTC](https://discuss.elastic.co/t/can-anyone-share-the-dockercompose-yaml-file-for-elasticsearch8-and-kibana8-installation-with-xpack-security/334979 "2023-06-01T14:14:15Z")

</div>

Can anyone share the dockercompose yaml file for elasticsearch8 and kibana8 installation with xpack.security

---

## [Check the conflict fields](https://discuss.elastic.co/t/check-the-conflict-fields/334754)

<div class="topic-metadata">

**Author:** [@therus000](https://discuss.elastic.co/u/therus000)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 2:00pm UTC](https://discuss.elastic.co/t/check-the-conflict-fields/334754 "2023-06-01T14:00:07Z")

</div>

Good day i wonder if there is another way to check the mapping conflict othere that view data views i see in data view 9 fields conflicted. when i sort the field by type. i found only 3 fields that conflicted how can …

---

## [Elastic - Spark connector failing to read data](https://discuss.elastic.co/t/elastic-spark-connector-failing-to-read-data/334231)

<div class="topic-metadata">

**Author:** [@ljSolaiman](https://discuss.elastic.co/u/ljSolaiman)\
**Replies:** 7\
**Last updated:** [June 1, 2023, 1:57pm UTC](https://discuss.elastic.co/t/elastic-spark-connector-failing-to-read-data/334231 "2023-06-01T13:57:46Z")

</div>

Hi all, I am trying to read data from Elasticsearch to Databricks (Spark) but I'm getting the following error: org.elasticsearch.hadoop.EsHadoopIllegalArgumentException: Cannot detect ES version - typically this happen…

---

## [Auto conect kibana and elastic](https://discuss.elastic.co/t/auto-conect-kibana-and-elastic/334139)

<div class="topic-metadata">

**Author:** [@Ramon\_Moraga](https://discuss.elastic.co/u/Ramon_Moraga)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 1:30pm UTC](https://discuss.elastic.co/t/auto-conect-kibana-and-elastic/334139 "2023-06-01T13:30:56Z")

</div>

How do I make the verification of kibana and elastic be done automatically when lifting the containers?

---

## [Single Sing On](https://discuss.elastic.co/t/single-sing-on/334970)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 1:29pm UTC](https://discuss.elastic.co/t/single-sing-on/334970 "2023-06-01T13:29:39Z")

</div>

I'm loading a Kibana dashboard in an iframe. It asks for username and password to login. How do I bypass this login?

---

## [Error running filebeat](https://discuss.elastic.co/t/error-running-filebeat/334116)

<div class="topic-metadata">

**Author:** [@okasha](https://discuss.elastic.co/u/okasha)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 12:15pm UTC](https://discuss.elastic.co/t/error-running-filebeat/334116 "2023-05-23T12:15:55Z")

</div>

hello guys, I'm getting this error when running this the filebeat 8.7.1 on my local machine (both Elasticsearch and kibana are running) when running .\\filebeat.exe setup -e on power shell i couldn't paste the whole …

---

## [Can not restart Elasticsearch service](https://discuss.elastic.co/t/can-not-restart-elasticsearch-service/334688)

<div class="topic-metadata">

**Author:** [@lcsb-sysadmins](https://discuss.elastic.co/u/lcsb-sysadmins)\
**Replies:** 18\
**Last updated:** [June 1, 2023, 12:57pm UTC](https://discuss.elastic.co/t/can-not-restart-elasticsearch-service/334688 "2023-06-01T12:57:02Z")

</div>

Hi, Elastic Stack Version - 7.17.5 We had an issue with our server (iDRAC is unable to successfully communicate with the device RAID Controller) which caused disruption for our elastic stack. However we solved that is…

---

## [Whole elasticsearh cluster become unresponsive if only one node is saturating](https://discuss.elastic.co/t/whole-elasticsearh-cluster-become-unresponsive-if-only-one-node-is-saturating/334960)

<div class="topic-metadata">

**Author:** [@shahzadkhan](https://discuss.elastic.co/u/shahzadkhan)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 12:14pm UTC](https://discuss.elastic.co/t/whole-elasticsearh-cluster-become-unresponsive-if-only-one-node-is-saturating/334960 "2023-06-01T12:14:53Z")

</div>

Hello All, we have elasticsearch cluster with 12 nodes and all the nodes are configured as master/data. these days we encountring an issue that all the queries are automatically forwarded to a only one node and the thr…

---

## [Giving filebeat admin rights to read from fileshare](https://discuss.elastic.co/t/giving-filebeat-admin-rights-to-read-from-fileshare/334971)

<div class="topic-metadata">

**Author:** [@\_Zeyad\_Elshater](https://discuss.elastic.co/u/_Zeyad_Elshater)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 12:00pm UTC](https://discuss.elastic.co/t/giving-filebeat-admin-rights-to-read-from-fileshare/334971 "2023-06-01T12:00:47Z")

</div>

Hi all, I have filebeat as a windows service, It supposed to read logs from a fileshare on my VM, which must be accessed using the admin account, when I log on the service of filebeat as the admin account it can't access…

---

## [Error in winlogbeat](https://discuss.elastic.co/t/error-in-winlogbeat/334967)

<div class="topic-metadata">

**Author:** [@mariya](https://discuss.elastic.co/u/mariya)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:37am UTC](https://discuss.elastic.co/t/error-in-winlogbeat/334967 "2023-06-01T11:37:47Z")

</div>

I installed winlogbeat and logstash on my pc I made the changes in the configuration file so it can send logs to the server ELK but it gives me this error :

---

## [Why Kibana Dashboard values are different from index query](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813)

<div class="topic-metadata">

**Author:** [@Vitor\_Nilson](https://discuss.elastic.co/u/Vitor_Nilson)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 11:27am UTC](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813 "2023-06-01T11:27:14Z")

</div>

Hello, I have a index called kong (the main index), and a Rollup job in this index grouping every 24h which has a index calld rollup\_job\_kong\_gateway. If we take a look directely in the index Kong and run the following…

---

## [How can I get the global filters in kibana for drilldown](https://discuss.elastic.co/t/how-can-i-get-the-global-filters-in-kibana-for-drilldown/334822)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 11:16am UTC](https://discuss.elastic.co/t/how-can-i-get-the-global-filters-in-kibana-for-drilldown/334822 "2023-06-01T11:16:10Z")

</div>

Hi, I'm trying to create a few drilldown dashboards using Go To URL, I understand that the event.points give me the current context filters, but I would also like to use the global filters of the dashboard to be passed …

---

## [Beats and Composable Templates](https://discuss.elastic.co/t/beats-and-composable-templates/334325)

<div class="topic-metadata">

**Author:** [@johncollaros](https://discuss.elastic.co/u/johncollaros)\
**Replies:** 6\
**Last updated:** [June 1, 2023, 11:15am UTC](https://discuss.elastic.co/t/beats-and-composable-templates/334325 "2023-06-01T11:15:22Z")

</div>

Hi, I am in the process of upgrading our Elastic Stack instance from 7.5 -\> 8, and am going through all of the migration tasks. It looks like migration to component templates is going to be a pain. Currently, I am usi…

---

## [How to give multiple kibana FQDN in rp.redirect\_uri](https://discuss.elastic.co/t/how-to-give-multiple-kibana-fqdn-in-rp-redirect-uri/334961)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:12am UTC](https://discuss.elastic.co/t/how-to-give-multiple-kibana-fqdn-in-rp-redirect-uri/334961 "2023-06-01T11:12:25Z")

</div>

Hi Team, We are running two instance of kibana and we have seperate fqdn for this two kibana instance. We have successfully integrated Azure AD OIDC with Elasticsearch and kibana. During the testing we were testing only…

---

## [Migrating from .net Nest client to v8.\* Elastic.Clients.Elasticsearch .net client](https://discuss.elastic.co/t/migrating-from-net-nest-client-to-v8-elastic-clients-elasticsearch-net-client/334959)

<div class="topic-metadata">

**Author:** [@Jere](https://discuss.elastic.co/u/Jere)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:04am UTC](https://discuss.elastic.co/t/migrating-from-net-nest-client-to-v8-elastic-clients-elasticsearch-net-client/334959 "2023-06-01T11:04:24Z")

</div>

I’m migrating an API codebase from the .net v7.\* Nest client to the newer v8 .net client The API codebase using the Nest client makes frequent use of QueryDescriptors with logic operators that derive QueryContainer obje…

---

## [Split non-ILM large index](https://discuss.elastic.co/t/split-non-ilm-large-index/334922)

<div class="topic-metadata">

**Author:** [@Anabel](https://discuss.elastic.co/u/Anabel)\
**Replies:** 7\
**Last updated:** [June 1, 2023, 10:55am UTC](https://discuss.elastic.co/t/split-non-ilm-large-index/334922 "2023-06-01T10:55:53Z")

</div>

Hi I have a writable index with 2.1Tb. 1 shards, 1 replica. No ILM (my mistake). named office-project-version (no 000001 in the end) How can I split it into smaller pieces? adding ILM doesn't work, as an alies does…

---

## [Fluentd crashing on startup when trying to connect to Elasticsearch](https://discuss.elastic.co/t/fluentd-crashing-on-startup-when-trying-to-connect-to-elasticsearch/334950)

<div class="topic-metadata">

**Author:** [@xbfh0516](https://discuss.elastic.co/u/xbfh0516)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 10:06am UTC](https://discuss.elastic.co/t/fluentd-crashing-on-startup-when-trying-to-connect-to-elasticsearch/334950 "2023-06-01T10:06:13Z")

</div>

Hi all, Recently installed ECK on Kubernetes (hosted on DigitalOcean). Followed the Deploy ECK in your Kubernetes cluster | Elastic Cloud on Kubernetes \[2.8\] | Elastic tutorial and got Elasticsearch and Kibana up and ru…

---

## [Filebeat 8.8 input configuration - Add Fields](https://discuss.elastic.co/t/filebeat-8-8-input-configuration-add-fields/334949)

<div class="topic-metadata">

**Author:** [@Alessio\_Melis](https://discuss.elastic.co/u/Alessio_Melis)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 10:06am UTC](https://discuss.elastic.co/t/filebeat-8-8-input-configuration-add-fields/334949 "2023-06-01T10:06:01Z")

</div>

Hi, configuration: \[filebeat 8.8\] --\> \[logstash 8.8\] --\> \[elasticsearch 8.8\] I'm trying to add fields in my input configuration but when the data is sent to logstash, the index is created without my field. using the v…

---

## [Query with Text field](https://discuss.elastic.co/t/query-with-text-field/334687)

<div class="topic-metadata">

**Author:** [@Kunjal\_Patel](https://discuss.elastic.co/u/Kunjal_Patel)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 9:44am UTC](https://discuss.elastic.co/t/query-with-text-field/334687 "2023-06-01T09:44:56Z")

</div>

I have index settings and mappings are as below "settings": { "number\_of\_shards": 1, "number\_of\_replicas": 1, "index": {"max\_result\_window": 10000000, "max\_inner\_result\_window": 1000}, "analysis": { "analyzer": { …

---

## [Implement filter aggregation API via elastic .net client 8.1.1](https://discuss.elastic.co/t/implement-filter-aggregation-api-via-elastic-net-client-8-1-1/334940)

<div class="topic-metadata">

**Author:** [@Sagar\_Kayasth2](https://discuss.elastic.co/u/Sagar_Kayasth2)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 9:35am UTC](https://discuss.elastic.co/t/implement-filter-aggregation-api-via-elastic-net-client-8-1-1/334940 "2023-06-01T09:35:57Z")

</div>

Hello I created this json query for searching & aggregation. In aggregation with did filtered specification attributes. How can i implement this query using elastic .net client 8.1.1 sdk through in my .net project? Pl…

---

## [How to run multiple search templates using NEST](https://discuss.elastic.co/t/how-to-run-multiple-search-templates-using-nest/334933)

<div class="topic-metadata">

**Author:** [@Jacques\_du\_Plessis](https://discuss.elastic.co/u/Jacques_du_Plessis)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 9:13am UTC](https://discuss.elastic.co/t/how-to-run-multiple-search-templates-using-nest/334933 "2023-06-01T09:13:20Z")

</div>

I am trying perform a multi-template search using NEST, and then read the reponses, but seems like it always returns null when I try to cast it to the POCO type. The DSL query I run in Kibana looks like this. Just for r…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=523)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=525)
