# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=529

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 530

---

## [Logstash pipeline configuration - extract metrics from message field](https://discuss.elastic.co/t/logstash-pipeline-configuration-extract-metrics-from-message-field/334597)

<div class="topic-metadata">

**Author:** [@Piotr\_Maciejek](https://discuss.elastic.co/u/Piotr_Maciejek)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 2:56pm UTC](https://discuss.elastic.co/t/logstash-pipeline-configuration-extract-metrics-from-message-field/334597 "2023-05-29T14:56:29Z")

</div>

Hi! I want to confgure logstash pipeline. I got many logs in bulk format: ex of one log entry: {"index":{"\_index":"orchestrator-index","\_id":"xxx"}} {"message":"@metrics Exception count: 10","level":"Information","lo…

---

## [Elastic Search - Limit of total fields \[1000\] - How to set in Docker compose file?](https://discuss.elastic.co/t/elastic-search-limit-of-total-fields-1000-how-to-set-in-docker-compose-file/334582)

<div class="topic-metadata">

**Author:** [@Eduardo\_Montes](https://discuss.elastic.co/u/Eduardo_Montes)\
**Replies:** 4\
**Last updated:** [May 30, 2023, 1:04am UTC](https://discuss.elastic.co/t/elastic-search-limit-of-total-fields-1000-how-to-set-in-docker-compose-file/334582 "2023-05-30T01:04:59Z")

</div>

I use ES 6.24 what is running via Docker image configured in docker compose file. After some time I got error Limit of total fields \[1000\] in index my\_index has been exceeded. I tried to use set this limit in environme…

---

## [Send data from packetbeat to kibana space](https://discuss.elastic.co/t/send-data-from-packetbeat-to-kibana-space/334567)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 6\
**Last updated:** [May 30, 2023, 1:00am UTC](https://discuss.elastic.co/t/send-data-from-packetbeat-to-kibana-space/334567 "2023-05-30T01:00:50Z")

</div>

Hello . I have packetbeat installed on one machine and I like to send the logs to a space in a kibana that is on another machine. Can I define the ip of this machine along with the space in the settings file or should I …

---

## [The security settings of 8+ versions is too too complicate](https://discuss.elastic.co/t/the-security-settings-of-8-versions-is-too-too-complicate/334546)

<div class="topic-metadata">

**Author:** [@Ansen\_J](https://discuss.elastic.co/u/Ansen_J)\
**Replies:** 4\
**Last updated:** [May 30, 2023, 12:55am UTC](https://discuss.elastic.co/t/the-security-settings-of-8-versions-is-too-too-complicate/334546 "2023-05-30T00:55:06Z")

</div>

I installed es and kibana through docker , after a period , the kibana cannot connect es , The security settings is too complicate , after weeks of reading docs and search from google, does not know what going wrong. t…

---

## [How do i get this product to integrate with Google Cloud?](https://discuss.elastic.co/t/how-do-i-get-this-product-to-integrate-with-google-cloud/334537)

<div class="topic-metadata">

**Author:** [@ezaidepc](https://discuss.elastic.co/u/ezaidepc)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 11:30pm UTC](https://discuss.elastic.co/t/how-do-i-get-this-product-to-integrate-with-google-cloud/334537 "2023-05-29T23:30:45Z")

</div>

I am trying to add the Elasticsearch Service to my Google Cloud product and it takes me to a page to set up an account but I already have an account, so I can't set up an account, however, there is not an option to simpl…

---

## [How to use Elasticsearch delete\_by\_query API's in watcher webhook. Its failing on Authentication](https://discuss.elastic.co/t/how-to-use-elasticsearch-delete-by-query-apis-in-watcher-webhook-its-failing-on-authentication/334415)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 10:16pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-delete-by-query-apis-in-watcher-webhook-its-failing-on-authentication/334415 "2023-05-29T22:16:41Z")

</div>

Hi Team, I am using delete\_by\_query in elasticsearch watcher action as webhook as below. "actions": { "my\_api": { "webhook": { "scheme": "https", "host": "130.8.1.198", "port": 9200, …

---

## [Kubernetes deployment - 3rd Stateful set replica always fail with java.lang.ClassNotFoundException: com.fasterxml.jackson.core.io.JsonStringEncoder](https://discuss.elastic.co/t/kubernetes-deployment-3rd-stateful-set-replica-always-fail-with-java-lang-classnotfoundexception-com-fasterxml-jackson-core-io-jsonstringencoder/334613)

<div class="topic-metadata">

**Author:** [@kolslearningid](https://discuss.elastic.co/u/kolslearningid)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 6:37pm UTC](https://discuss.elastic.co/t/kubernetes-deployment-3rd-stateful-set-replica-always-fail-with-java-lang-classnotfoundexception-com-fasterxml-jackson-core-io-jsonstringencoder/334613 "2023-05-29T18:37:07Z")

</div>

I am trying to build a three replica stateful set Elasticsearch cluster in EKS using helm chart. When I deploy with one or two replicas the PODs are getting created and attached in the cluster mode. When I increase the r…

---

## [MQTT Input - Default qos level?](https://discuss.elastic.co/t/mqtt-input-default-qos-level/334055)

<div class="topic-metadata">

**Author:** [@QuestBevan](https://discuss.elastic.co/u/QuestBevan)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 7:18pm UTC](https://discuss.elastic.co/t/mqtt-input-default-qos-level/334055 "2023-05-29T19:18:36Z")

</div>

Hi All, Could someone please confirm what the default value for the 'qos' setting is, within the MQTT input module. Thanks

---

## [Kafka Connection Failure](https://discuss.elastic.co/t/kafka-connection-failure/334612)

<div class="topic-metadata">

**Author:** [@varunsingla](https://discuss.elastic.co/u/varunsingla)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 6:26pm UTC](https://discuss.elastic.co/t/kafka-connection-failure/334612 "2023-05-29T18:26:37Z")

</div>

I am getting the following error when I am trying to configure output.kafka on my filebeat configuration: "log.logger":"kafka","log.origin":{"file.name":"kafka/client.go","file.line":406},"message":"Kafka publish failed…

---

## [\[ERROR\] \[logstash.agent\] Failed to execute action](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action/334587)

<div class="topic-metadata">

**Author:** [@nml1988](https://discuss.elastic.co/u/nml1988)\
**Replies:** 5\
**Last updated:** [May 29, 2023, 5:33pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action/334587 "2023-05-29T17:33:47Z")

</div>

Hello! I need help from the community! I am having a failure during the execution of the logstash ingest pipes. The service starts normally, but when executing the different pipelines I see this error for which I ca…

---

## [Ignore weekends in timeline visualization in Kibana 7.10.2](https://discuss.elastic.co/t/ignore-weekends-in-timeline-visualization-in-kibana-7-10-2/333638)

<div class="topic-metadata">

**Author:** [@Priyanka\_Rajpal](https://discuss.elastic.co/u/Priyanka_Rajpal)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 5:26pm UTC](https://discuss.elastic.co/t/ignore-weekends-in-timeline-visualization-in-kibana-7-10-2/333638 "2023-05-29T17:26:13Z")

</div>

I have a time series plot on my dashboard, which also includes a mvavg(10) trend line. I want to remove the weekends from the plot and all the calculations(since there is no data available for weekends). I tried creatin…

---

## [Alert for Agent Offline/Server offline](https://discuss.elastic.co/t/alert-for-agent-offline-server-offline/235151)

<div class="topic-metadata">

**Author:** [@spike83](https://discuss.elastic.co/u/spike83)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 5:02pm UTC](https://discuss.elastic.co/t/alert-for-agent-offline-server-offline/235151 "2023-05-29T17:02:22Z")

</div>

Hi, Could someone please help me to work out how to alert on whether an Agent is offline alternatively if a server is restarted or down? Heartbeat is the obvious choice for Offline servers, but that's on the basis for …

---

## [How to group similar log messages and show in bar chart](https://discuss.elastic.co/t/how-to-group-similar-log-messages-and-show-in-bar-chart/333586)

<div class="topic-metadata">

**Author:** [@balaji-khandekar-osv](https://discuss.elastic.co/u/balaji-khandekar-osv)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 4:46pm UTC](https://discuss.elastic.co/t/how-to-group-similar-log-messages-and-show-in-bar-chart/333586 "2023-05-29T16:46:19Z")

</div>

Hello, I wanted to group the similar messages and display them in chart. The message format is not unique, its slightly change every time. below is the sample message: "NO TRANSLATION AVAILABLE From:XYZ Code:ABC To:O…

---

## [Logstash - Creating new field by taking first word from an other field](https://discuss.elastic.co/t/logstash-creating-new-field-by-taking-first-word-from-an-other-field/334536)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 4\
**Last updated:** [May 29, 2023, 4:38pm UTC](https://discuss.elastic.co/t/logstash-creating-new-field-by-taking-first-word-from-an-other-field/334536 "2023-05-29T16:38:32Z")

</div>

Hi all. It must be something plenty of people has answered but I can´t find it :slight\_smile: I've got a pipeline reading a log with the following structure: \[12/May/2022:19:04:50 +0200\] 192.168.0.2 server2 "DROP: Est…

---

## [Elastic Fleet: Alert on Agent Status](https://discuss.elastic.co/t/elastic-fleet-alert-on-agent-status/333502)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 4:11pm UTC](https://discuss.elastic.co/t/elastic-fleet-alert-on-agent-status/333502 "2023-05-29T16:11:00Z")

</div>

As our company's Elastic Administrator, I would like to be notified when Elastic Agents in Fleet go offline. However, I don't see any way to configure this. Is there a way? Is Agent Status saved in an index somewhere tha…

---

## [Date format problem with Kibana ingestion](https://discuss.elastic.co/t/date-format-problem-with-kibana-ingestion/333357)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 3:41pm UTC](https://discuss.elastic.co/t/date-format-problem-with-kibana-ingestion/333357 "2023-05-29T15:41:07Z")

</div>

Hi, I have a CSV file with a field date 5in french) like this : samedi 13 mai 2023 and I don't find any ISO format in Kibana to make this field recognizable as a date field during the ingestion. If you have a solution…

---

## [Elasticsearch Query: Array field length mismatch](https://discuss.elastic.co/t/elasticsearch-query-array-field-length-mismatch/334551)

<div class="topic-metadata">

**Author:** [@kusumakarb](https://discuss.elastic.co/u/kusumakarb)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 2:04pm UTC](https://discuss.elastic.co/t/elasticsearch-query-array-field-length-mismatch/334551 "2023-05-29T14:04:34Z")

</div>

Trying out the following query to get the values of 2 array fields and their corresponding lengths, the array values and the lengths don't match Query: GET my\_index/\_search { "\_source": \["file\_types", "link\_to\_file"\]…

---

## [Showing percentage on the Y axis instead of count](https://discuss.elastic.co/t/showing-percentage-on-the-y-axis-instead-of-count/334428)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 5\
**Last updated:** [May 29, 2023, 1:14pm UTC](https://discuss.elastic.co/t/showing-percentage-on-the-y-axis-instead-of-count/334428 "2023-05-29T13:14:22Z")

</div>

Hi, I want percentage contribution of female gender for the following in the Y axis instead of the count. For e.g., my current week shows 54 count and previous week shows 67 counts for female gender for Angeldale manufa…

---

## [It takes a long time to query the keyword field](https://discuss.elastic.co/t/it-takes-a-long-time-to-query-the-keyword-field/333297)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 3\
**Last updated:** [May 29, 2023, 1:03pm UTC](https://discuss.elastic.co/t/it-takes-a-long-time-to-query-the-keyword-field/333297 "2023-05-29T13:03:26Z")

</div>

Hi, I have a question regarding query performance. What is the difference between querying the normal field and querying the keyword field? I did a test. The data types of the fields I am querying are as follows. …

---

## [Issue in generating PDF of canvas report in 8.7](https://discuss.elastic.co/t/issue-in-generating-pdf-of-canvas-report-in-8-7/334315)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 3\
**Last updated:** [May 29, 2023, 12:31pm UTC](https://discuss.elastic.co/t/issue-in-generating-pdf-of-canvas-report-in-8-7/334315 "2023-05-29T12:31:44Z")

</div>

We have created parameterized canvas reports, wherein we are using group filters, as shown below (in the expression editor) filters group="timeFilter" | embeddable config="eyJ2aWV3TW9kZSI6ImVkaXQiLCJ0aW1lUmFuZ2UiOnsiZnJ…

---

## [Unable to generate export: Either \`type\` or \`objects\` are required](https://discuss.elastic.co/t/unable-to-generate-export-either-type-or-objects-are-required/333138)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 11:59am UTC](https://discuss.elastic.co/t/unable-to-generate-export-either-type-or-objects-are-required/333138 "2023-05-29T11:59:19Z")

</div>

Trying to export ALL objects from the top-right button but hit the error "Unable to generate export: Either type or objects are required." on Kibana 8.7.1

---

## [Unable to authenticate user \[kibana\_system\] for REST request \[/\_xpack\] error](https://discuss.elastic.co/t/unable-to-authenticate-user-kibana-system-for-rest-request-xpack-error/333441)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 6\
**Last updated:** [May 29, 2023, 11:57am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-kibana-system-for-rest-request-xpack-error/333441 "2023-05-29T11:57:18Z")

</div>

I am using EFK stack on Kubernetes, Elastic and Kibana 8.7.0: I changed the passwords for built-in users elastic and kibana\_system with ./bin/elasticsearch-reset-password user --username kibana\_system and ./bin/elastic…

---

## [Can I set log path for connector](https://discuss.elastic.co/t/can-i-set-log-path-for-connector/332311)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 11:45am UTC](https://discuss.elastic.co/t/can-i-set-log-path-for-connector/332311 "2023-05-29T11:45:02Z")

</div>

I am setting up an alert in Kibana. I choose Server log as connector. It goes to /var/log/kibana.log by default. All the server logs are stored in this log file. I want to push the alert messages to the other path /var/l…

---

## [JWT Realms not working using basic license](https://discuss.elastic.co/t/jwt-realms-not-working-using-basic-license/334580)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 11:04am UTC](https://discuss.elastic.co/t/jwt-realms-not-working-using-basic-license/334580 "2023-05-29T11:04:45Z")

</div>

We are using basic license of elasticsearch 8.7.1 and want to implement JWT authentication, but when we add Realm for JWT authentication using token type = access-token getting following warning in log file: \[WARN \]\[o.e…

---

## [Not able to get indices for all services in kibana](https://discuss.elastic.co/t/not-able-to-get-indices-for-all-services-in-kibana/334563)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 9:14am UTC](https://discuss.elastic.co/t/not-able-to-get-indices-for-all-services-in-kibana/334563 "2023-05-29T09:14:50Z")

</div>

I am not getting indices for most of services, but unable to get indices for few services. So I am unable to create index patterns. Please help on this

---

## [The \[dot\_product\] similarity can only be used with unit-length vectors. Preview of invalid vector: \[-1.8447683, 0.20424768, 0.53359556, 1.1610416, 0.905799, ...\]](https://discuss.elastic.co/t/the-dot-product-similarity-can-only-be-used-with-unit-length-vectors-preview-of-invalid-vector-1-8447683-0-20424768-0-53359556-1-1610416-0-905799/334566)

<div class="topic-metadata">

**Author:** [@zheng\_zhiqiang](https://discuss.elastic.co/u/zheng_zhiqiang)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 9:13am UTC](https://discuss.elastic.co/t/the-dot-product-similarity-can-only-be-used-with-unit-length-vectors-preview-of-invalid-vector-1-8447683-0-20424768-0-53359556-1-1610416-0-905799/334566 "2023-05-29T09:13:20Z")

</div>

I create a deployment in elastic cloud with reference ChatGPT and Elasticsearch: OpenAI meets private data. The only difference is that I chose a Chinese model for machine learning. However, I encountered the following …

---

## [Converting epoch time format to datetime format using script](https://discuss.elastic.co/t/converting-epoch-time-format-to-datetime-format-using-script/334560)

<div class="topic-metadata">

**Author:** [@kashimmirza](https://discuss.elastic.co/u/kashimmirza)\
**Replies:** 2\
**Last updated:** [May 29, 2023, 8:33am UTC](https://discuss.elastic.co/t/converting-epoch-time-format-to-datetime-format-using-script/334560 "2023-05-29T08:33:24Z")

</div>

In elastic searach there is a index name personalprofile11 and there is a field named createdDate in epoch format , integer data type. but I want to make it datetime format query Datehistogramaggregation and using that …

---

## [Setting max\_analyzed\_offset permanently for an index](https://discuss.elastic.co/t/setting-max-analyzed-offset-permanently-for-an-index/334470)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [May 29, 2023, 7:48am UTC](https://discuss.elastic.co/t/setting-max-analyzed-offset-permanently-for-an-index/334470 "2023-05-29T07:48:56Z")

</div>

Hi All, We are using ELK stack 7.13.2 I came across an error while displaying an index in dashboard as follows: The length \[2134324\] of field \[additionalInfo\] in doc\[100496\]/index\[370844-2023.05.24\] exceeds the \[index…

---

## [How to make elasticdump faster](https://discuss.elastic.co/t/how-to-make-elasticdump-faster/334380)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 4\
**Last updated:** [May 29, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-make-elasticdump-faster/334380 "2023-05-29T07:24:05Z")

</div>

Hi Elastic Community members, I would like to know, Is there any way to speed up the elastic-dump. I need to migrate data from one elasticsearch to another elasticsearch cluster. I noticed for 1GB of data is taking aro…

---

## [Using Metricbeat to send Filebeat logs to ES](https://discuss.elastic.co/t/using-metricbeat-to-send-filebeat-logs-to-es/333850)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 6\
**Last updated:** [May 29, 2023, 5:43am UTC](https://discuss.elastic.co/t/using-metricbeat-to-send-filebeat-logs-to-es/333850 "2023-05-29T05:43:19Z")

</div>

Hi, I'm running both Filebeat 8.3.3 and Metricbeat 8.3.3 on my RHEL 7.9 server, and sending the logs to another server which is hosting Elasticsearch and Kibana. My filebeat is sending syslog to the ES (I'm simply usin…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=528)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=530)
