# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=526

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 527

---

## [Migration to 8.7 kibana](https://discuss.elastic.co/t/migration-to-8-7-kibana/332872)

<div class="topic-metadata">

**Author:** [@Lilia](https://discuss.elastic.co/u/Lilia)\
**Replies:** 4\
**Last updated:** [May 31, 2023, 10:00pm UTC](https://discuss.elastic.co/t/migration-to-8-7-kibana/332872 "2023-05-31T22:00:55Z")

</div>

Hi I'm trying to migrate custom plugin to version 8.7 of kibana, but i receive a Server error and the kibana is not loading, in the logs i have several warnings, could you please help fix it or advice how to clear the wa…

---

## [After a folder is deleted and recreated, file\_integrity events are missing until service restart](https://discuss.elastic.co/t/after-a-folder-is-deleted-and-recreated-file-integrity-events-are-missing-until-service-restart/334873)

<div class="topic-metadata">

**Author:** [@James\_Nelson1](https://discuss.elastic.co/u/James_Nelson1)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 9:30pm UTC](https://discuss.elastic.co/t/after-a-folder-is-deleted-and-recreated-file-integrity-events-are-missing-until-service-restart/334873 "2023-05-31T21:30:05Z")

</div>

We're still on v7.17.x of auditbeat on CentOS, but I think this applies across versions. Say we are using the file\_integrity module for these paths: - /apps - /apps/myapp When the directory /apps/myapp is deleted and r…

---

## [Ingest Pipeline Failure Processor Shard Failures](https://discuss.elastic.co/t/ingest-pipeline-failure-processor-shard-failures/330541)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 4\
**Last updated:** [May 31, 2023, 9:25pm UTC](https://discuss.elastic.co/t/ingest-pipeline-failure-processor-shard-failures/330541 "2023-05-31T21:25:18Z")

</div>

I set up an ingest pipeline in Dev Tools console with this command PUT \_ingest/pipeline/ams-log-pipeline { "processors": \[ { "dissect": { "field": "message", "pattern": "%{@timestamp} %{logLe…

---

## [Log files to Logstash](https://discuss.elastic.co/t/log-files-to-logstash/333063)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 8:43pm UTC](https://discuss.elastic.co/t/log-files-to-logstash/333063 "2023-05-31T20:43:19Z")

</div>

Hi, Good day! I have this scenario where I’m trying to collect log files and ship or ingest it to Logstash. Below is my logstash.conf Below is my input file (my-topics-1.txt) which contains 1-25 as shown below. …

---

## [How to add logging integration for getting filebeat logs in kibana dashboard](https://discuss.elastic.co/t/how-to-add-logging-integration-for-getting-filebeat-logs-in-kibana-dashboard/332553)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 16\
**Last updated:** [May 31, 2023, 8:26pm UTC](https://discuss.elastic.co/t/how-to-add-logging-integration-for-getting-filebeat-logs-in-kibana-dashboard/332553 "2023-05-31T20:26:46Z")

</div>

We are not getting the logs as filebeat is not configured, so please help me in logging integration for kibana dashboard

---

## [Can I still jump from 7.17 to the new 8.8?](https://discuss.elastic.co/t/can-i-still-jump-from-7-17-to-the-new-8-8/334616)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 8\
**Last updated:** [May 31, 2023, 7:16pm UTC](https://discuss.elastic.co/t/can-i-still-jump-from-7-17-to-the-new-8-8/334616 "2023-05-31T19:16:57Z")

</div>

I'm at 7.16 right now. I know I need to update to 7.17 first, but I am wondering if right after that I can go directly to 8.8? I know I could jump to 8.7 from 7.17. Just wondering if it's still the case.

---

## [Take snapshot of a datastream](https://discuss.elastic.co/t/take-snapshot-of-a-datastream/334867)

<div class="topic-metadata">

**Author:** [@Abhilash\_B](https://discuss.elastic.co/u/Abhilash_B)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 7:13pm UTC](https://discuss.elastic.co/t/take-snapshot-of-a-datastream/334867 "2023-05-31T19:13:37Z")

</div>

I have scrambled through a lot of documentation on Snapshot and Restore. I was unable to find a specific example that show how to take a snapshot of a datastream and then restore it. Any help is highly appreciated.

---

## [Span\_Near and Span\_or query for two multiword match is not giving expected result](https://discuss.elastic.co/t/span-near-and-span-or-query-for-two-multiword-match-is-not-giving-expected-result/334862)

<div class="topic-metadata">

**Author:** [@chetab](https://discuss.elastic.co/u/chetab)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 5:27pm UTC](https://discuss.elastic.co/t/span-near-and-span-or-query-for-two-multiword-match-is-not-giving-expected-result/334862 "2023-05-31T17:27:55Z")

</div>

I need to write the query for below scenario: Ex: The car will be getting close to me but I am unable to stop it. or The car is too close to me but I am unable to stop it. like: Span\_near(span\_or("getting close", "is t…

---

## [Split Value into different document](https://discuss.elastic.co/t/split-value-into-different-document/332799)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 5:12pm UTC](https://discuss.elastic.co/t/split-value-into-different-document/332799 "2023-05-31T17:12:51Z")

</div>

Hi there, if i have data like this \[{...},{...},{...}\] how can i split them into different documents like document 1 =\> {...} document 2 =\> {...} document 3 =\> {...} so in that way, I can use the json filter to spre…

---

## [Upgrade Elastic Stack 7.15.1 to 7.17.10](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/334717)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 4:36pm UTC](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/334717 "2023-05-31T16:36:33Z")

</div>

Hello Team, I need to perform a backup Data KIBANA : tenants-spaces-Index pattern-alias-dashboard -visualisation before upgrade to Elastic version 7.17.10. when i getting issue on upgrade i can restore DATA. how to do…

---

## [Logstash Enrich and translate plugin use](https://discuss.elastic.co/t/logstash-enrich-and-translate-plugin-use/332897)

<div class="topic-metadata">

**Author:** [@gbandasha](https://discuss.elastic.co/u/gbandasha)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 4:08pm UTC](https://discuss.elastic.co/t/logstash-enrich-and-translate-plugin-use/332897 "2023-05-31T16:08:27Z")

</div>

Hello Team, I am trying to enrich the data before it makes its way too elastic, I have tried the below methods but both are currently not working Using the elasticsearch plugin in filter input { kafka { …

---

## [Is it possible to use a runtime field in document based security query](https://discuss.elastic.co/t/is-it-possible-to-use-a-runtime-field-in-document-based-security-query/334730)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 4:06pm UTC](https://discuss.elastic.co/t/is-it-possible-to-use-a-runtime-field-in-document-based-security-query/334730 "2023-05-31T16:06:47Z")

</div>

If I wanted to setup a role that has document based security and uses runtime field in the query, would that be possible? I can use regular, already indexed fields to do that, but I don't know how to do that with a Runti…

---

## [Match query with operator "and", doesn't work when using synonyms analyzer](https://discuss.elastic.co/t/match-query-with-operator-and-doesnt-work-when-using-synonyms-analyzer/334821)

<div class="topic-metadata">

**Author:** [@Bage\_Atanasovska](https://discuss.elastic.co/u/Bage_Atanasovska)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 3:40pm UTC](https://discuss.elastic.co/t/match-query-with-operator-and-doesnt-work-when-using-synonyms-analyzer/334821 "2023-05-31T15:40:02Z")

</div>

I am creating an index using as a search analyzer, an alayzer that has a synonym filter. The query that creates the index is the following: { "settings": { "index": { "analysis": { …

---

## [Pipeline client receives callback 'onFilteredOut'](https://discuss.elastic.co/t/pipeline-client-receives-callback-onfilteredout/334818)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 2:55pm UTC](https://discuss.elastic.co/t/pipeline-client-receives-callback-onfilteredout/334818 "2023-05-31T14:55:43Z")

</div>

Hello, I'm facing an error with my f5\_bigip pipeline. I use the elastic integration module for that, but ,the agent does receive data, but they don't process it : "Pipeline client receives callback 'onFilteredOut' for…

---

## [Logstash SWAP OOM](https://discuss.elastic.co/t/logstash-swap-oom/334675)

<div class="topic-metadata">

**Author:** [@nilsen](https://discuss.elastic.co/u/nilsen)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 2:27pm UTC](https://discuss.elastic.co/t/logstash-swap-oom/334675 "2023-05-31T14:27:39Z")

</div>

We have the past months installed the ELK stack trying to follow the elastic documentation. Currently using logstash to push approx. 15 logs into our elastic indexes. Hoping to push all of our approx. 100 logs into diffe…

---

## [Issue while running FSCrawler on WSL](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620)

<div class="topic-metadata">

**Author:** [@chloesun](https://discuss.elastic.co/u/chloesun)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:05pm UTC](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620 "2023-05-31T14:05:48Z")

</div>

I installed JAVA 11, Elastic Search 7, and Fscrawler2.8 on WSL on my Windows machine. Elastic search has no issue starting, and I already configured JAVA\_HOME in .bashrc export JAVA\_HOME="/usr/lib/jvm/java-11-openjdk-am…

---

## [Akamai integration version 2.7.0 sending wrong values in from and to params](https://discuss.elastic.co/t/akamai-integration-version-2-7-0-sending-wrong-values-in-from-and-to-params/334529)

<div class="topic-metadata">

**Author:** [@abhishek-devops](https://discuss.elastic.co/u/abhishek-devops)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 2:03pm UTC](https://discuss.elastic.co/t/akamai-integration-version-2-7-0-sending-wrong-values-in-from-and-to-params/334529 "2023-05-31T14:03:52Z")

</div>

Hello Team, After upgrading akamai integration the from and to params are getting wrong values ... please refer below logs: "log.level":"debug","@timestamp":"2023-05-28T12:35:53.527Z","message":"HTTP request","transac…

---

## [Mapper\_parsing\_exception error](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:01pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447 "2023-05-31T14:01:26Z")

</div>

Hi all, I create indexes on a daily basis using fluentd in Elasticsearch. I don't do any mapping on elasticsearch side. After a while, the related index could not be created in Elasticsearch and I got the following erro…

---

## [Elastic Search 8.6.2 SSL enabled with 3rd party certificate](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713)

<div class="topic-metadata">

**Author:** [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Replies:** 21\
**Last updated:** [May 31, 2023, 1:50pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713 "2023-05-31T13:50:36Z")

</div>

I have a single instance of Elastic Search 8.6.2 installed on a redhat server. No cloud, No docker and single node, very simple install. We need SSL enabled and configured to use a 3rd party certificate we can't use El…

---

## [How to change the date structure to YYYY:MM:DD](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 5\
**Last updated:** [May 31, 2023, 1:18pm UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789 "2023-05-31T13:18:44Z")

</div>

Hi, I tried multiple way to change the date event into YYYY:MMM:DD as log\_date. below format is actual date event (2023-05-31 10:30:50,244). I tried manual string concatenation even though am getting type as timestamp …

---

## [Ndjson parser doesn't expand keys if target is set](https://discuss.elastic.co/t/ndjson-parser-doesnt-expand-keys-if-target-is-set/334799)

<div class="topic-metadata">

**Author:** [@anon68795679](https://discuss.elastic.co/u/anon68795679)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:13pm UTC](https://discuss.elastic.co/t/ndjson-parser-doesnt-expand-keys-if-target-is-set/334799 "2023-05-31T13:13:05Z")

</div>

Hi, it seems that there is the same issue with the ndjson parser like in the decode\_json\_fields processor some time ago: Expand fields in \`decode\_json\_fields\` if target is set by kvch · Pull Request #32010 · elastic/bea…

---

## [Heartbeat parsing JSON object for HTTP monitor failure](https://discuss.elastic.co/t/heartbeat-parsing-json-object-for-http-monitor-failure/334335)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:05pm UTC](https://discuss.elastic.co/t/heartbeat-parsing-json-object-for-http-monitor-failure/334335 "2023-05-31T13:05:18Z")

</div>

hey there, I am using Heartbeat 8.x and according to I was trying to check the Sendgrid SMTP service using the public url https://status.sendgrid.com/api/v2/components.json Using this code: - type: http id: sendgr…

---

## [Range queries with should clause not working](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 12:58pm UTC](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764 "2023-05-31T12:58:54Z")

</div>

Hi, I'm trying below range query with must and should clause: Product id can range from 1 to 1000. I'm using below query to fetch product\_id between 1 to 99 or product\_id = 100. However I can only see the must clause…

---

## ["The incoming YAML document exceeds the limit: 3145728 code points" in Logstash/ElastiFLOW](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:48pm UTC](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803 "2023-05-31T12:48:41Z")

</div>

Since upgrading to logstash 7.17.10 on Centos 7, I've been seeing the above error when starting. I see some other folks have had similar problems 8.7, and there are similar problems reported in RUBY forums. I had no su…

---

## [Faceting, sorting, paginating within buckets](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:30pm UTC](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801 "2023-05-31T12:30:56Z")

</div>

Hi there, I have a question around Elasticsearch's aggregation functionality. We have a use case where we need to do search with a "search term" and then group results by a field in the document and read documents within…

---

## [Dev-Tools gone](https://discuss.elastic.co/t/dev-tools-gone/334720)

<div class="topic-metadata">

**Author:** [@DavidGreensfelder](https://discuss.elastic.co/u/DavidGreensfelder)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 12:14pm UTC](https://discuss.elastic.co/t/dev-tools-gone/334720 "2023-05-31T12:14:07Z")

</div>

Could someone tell me why my Dev-Tool are gone? What makes them get removed? Are they stored in the cache of my local machine?

---

## [Unable to form an ES cluster](https://discuss.elastic.co/t/unable-to-form-an-es-cluster/334795)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:31am UTC](https://discuss.elastic.co/t/unable-to-form-an-es-cluster/334795 "2023-05-31T11:31:42Z")

</div>

I am having 2 nodes having elasticsearch installed. I am running first node as :- sudo docker run -it --pull=always --net elastic -p 9200:9200 -p 9300:9300 -e discovery.type=multi-node -e cluster.name="my-elasticsearch-…

---

## [Adding Custom Fields to an Elasticsearch Index](https://discuss.elastic.co/t/adding-custom-fields-to-an-elasticsearch-index/334794)

<div class="topic-metadata">

**Author:** [@Abeer\_Islam](https://discuss.elastic.co/u/Abeer_Islam)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:29am UTC](https://discuss.elastic.co/t/adding-custom-fields-to-an-elasticsearch-index/334794 "2023-05-31T11:29:10Z")

</div>

Hi, I want to add custom fields (Year, Yearly Week, Week, Month, Exist (a boolean value)) and their corresponding values into an ES index using API. SInce, I am running the OpenDistro for Elasticsearch version which doe…

---

## [Add query parameter "level" to the IndicesStatsRequest using the 7.17 transport client](https://discuss.elastic.co/t/add-query-parameter-level-to-the-indicesstatsrequest-using-the-7-17-transport-client/334782)

<div class="topic-metadata">

**Author:** [@kley](https://discuss.elastic.co/u/kley)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 11:23am UTC](https://discuss.elastic.co/t/add-query-parameter-level-to-the-indicesstatsrequest-using-the-7-17-transport-client/334782 "2023-05-31T11:23:38Z")

</div>

Hey! We are using Elasticsearch 7.17 + the corresponding transport client. I try to calculate the consumed disk space from Elasticsearch without the cat API and came up with this solution (documentation): curl -H 'Con…

---

## [Elastic-agent failed to enroll due to TLS access denied alert](https://discuss.elastic.co/t/elastic-agent-failed-to-enroll-due-to-tls-access-denied-alert/334699)

<div class="topic-metadata">

**Author:** [@kmahyyg](https://discuss.elastic.co/u/kmahyyg)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 10:18am UTC](https://discuss.elastic.co/t/elastic-agent-failed-to-enroll-due-to-tls-access-denied-alert/334699 "2023-05-31T10:18:09Z")

</div>

This is a really interesting issue. Code related: elastic-agent/client.go at cda5b7e75d080c6be9e9220dfa607c145cf598b4 · elastic/elastic-agent · GitHub I've using self-signed CA to deploy elastic-agent in internal envir…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=525)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=527)
