# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=532

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 533

---

## [I have problem installing elastic agent](https://discuss.elastic.co/t/i-have-problem-installing-elastic-agent/334375)

<div class="topic-metadata">

**Author:** [@daniellopez](https://discuss.elastic.co/u/daniellopez)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 10:55pm UTC](https://discuss.elastic.co/t/i-have-problem-installing-elastic-agent/334375 "2023-05-25T22:55:37Z")

</div>

Actually I am having a problem to install elastic agent. When I run the command that kibana gives me I get the following error 2023-05-25T10:46:57.852-0500 INFO cmd/enroll\_cmd.go:701 Fleet Server - Error - coul…

---

## [Kibana change the "now value" or current time](https://discuss.elastic.co/t/kibana-change-the-now-value-or-current-time/334203)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 9:49pm UTC](https://discuss.elastic.co/t/kibana-change-the-now-value-or-current-time/334203 "2023-05-25T21:49:22Z")

</div>

Kibana "now" value is incorrect and i don't want it to modify the value of my time field. If it's currently 12h05, logstash send the logs from 12h05 but Kibana with this settings : Display the logs from 10h and add 2…

---

## [Tail\_files option for filebeat not working as expected](https://discuss.elastic.co/t/tail-files-option-for-filebeat-not-working-as-expected/334359)

<div class="topic-metadata">

**Author:** [@Puneet\_Singh](https://discuss.elastic.co/u/Puneet_Singh)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 6:53pm UTC](https://discuss.elastic.co/t/tail-files-option-for-filebeat-not-working-as-expected/334359 "2023-05-25T18:53:50Z")

</div>

I have downloaded filebeat 8.8.0 today and it seems that the tail\_files option is not working as expected. When i run filebeat, the filebeat seems to be scanning entire file and scanning everything, instead of shipping …

---

## [ELK version 8.7.0 with mysql using docker compose](https://discuss.elastic.co/t/elk-version-8-7-0-with-mysql-using-docker-compose/333871)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 13\
**Last updated:** [May 25, 2023, 6:36pm UTC](https://discuss.elastic.co/t/elk-version-8-7-0-with-mysql-using-docker-compose/333871 "2023-05-25T18:36:55Z")

</div>

hi every one I want to run elastic and kibana and logstash I use docker compose this is the docker compose file yml : version: '3' services: mysql: container\_name: mysql hostname: mysql image: 'mysql' …

---

## [Scale out logstash server and configure the output in the Fleet UI](https://discuss.elastic.co/t/scale-out-logstash-server-and-configure-the-output-in-the-fleet-ui/333383)

<div class="topic-metadata">

**Author:** [@A113n](https://discuss.elastic.co/u/A113n)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 5:29pm UTC](https://discuss.elastic.co/t/scale-out-logstash-server-and-configure-the-output-in-the-fleet-ui/333383 "2023-05-25T17:29:31Z")

</div>

Hi I have 1 logstash server configured and 1 fleet server. I now want to scale out logstash by 1 more server. The Elastic Agent have client side support for loadbalancing between multiple logstash servers: output.log…

---

## [Filter with winlogbeat](https://discuss.elastic.co/t/filter-with-winlogbeat/324621)

<div class="topic-metadata">

**Author:** [@BeyondRAM](https://discuss.elastic.co/u/BeyondRAM)\
**Replies:** 13\
**Last updated:** [May 25, 2023, 5:10pm UTC](https://discuss.elastic.co/t/filter-with-winlogbeat/324621 "2023-05-25T17:10:40Z")

</div>

Hello I got winlogbeat on my file server which brings up specifics ressources from an file audit, 4663, 4670 and 4659 events, well file activy actually. I got an issue, I want to create a dashboard with the files the mo…

---

## [Searching using query string with variable clauses](https://discuss.elastic.co/t/searching-using-query-string-with-variable-clauses/333756)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 7\
**Last updated:** [May 25, 2023, 4:48pm UTC](https://discuss.elastic.co/t/searching-using-query-string-with-variable-clauses/333756 "2023-05-25T16:48:06Z")

</div>

Hi everyone. I'm trying to make a template wich I can use to search through several fields by one word (using query string). But now I need to add a clause which will get a variable in a query (date). How can I combine …

---

## [SnapShot Backup and Restore](https://discuss.elastic.co/t/snapshot-backup-and-restore/333943)

<div class="topic-metadata">

**Author:** [@Manjunath\_VS](https://discuss.elastic.co/u/Manjunath_VS)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:28pm UTC](https://discuss.elastic.co/t/snapshot-backup-and-restore/333943 "2023-05-25T16:28:53Z")

</div>

Hi Team, I have deployed Elasticsearch cluster along with Kibana using Bitnami Elasticsearch I am new to Elasticsearch and Kibana We wanted to take a backup from a Kubernetes cluster and restore it to another Kubern…

---

## [Error starting Logstash pipeline after upgrading to Java 17](https://discuss.elastic.co/t/error-starting-logstash-pipeline-after-upgrading-to-java-17/334346)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:19pm UTC](https://discuss.elastic.co/t/error-starting-logstash-pipeline-after-upgrading-to-java-17/334346 "2023-05-25T16:19:21Z")

</div>

I have bundled Logstash within my Java application and launch it using JRuby. It worked fine until upgrading to Java 17. After upgrading, the pipeline fails to start with following exception : java.lang.IllegalAcce…

---

## [How to list non empty field names based on search criteria on elasticsearch](https://discuss.elastic.co/t/how-to-list-non-empty-field-names-based-on-search-criteria-on-elasticsearch/334349)

<div class="topic-metadata">

**Author:** [@ehmd96](https://discuss.elastic.co/u/ehmd96)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:07pm UTC](https://discuss.elastic.co/t/how-to-list-non-empty-field-names-based-on-search-criteria-on-elasticsearch/334349 "2023-05-25T16:07:29Z")

</div>

we are encountering an issue on elasticsearch trying to display fields based on certain search criteria. We have an index with a "payload" field which has multiple properties What we are trying to do is to request t…

---

## [\[Logstash\] How to drop message if field is not a number](https://discuss.elastic.co/t/logstash-how-to-drop-message-if-field-is-not-a-number/333324)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 4\
**Last updated:** [May 25, 2023, 3:59pm UTC](https://discuss.elastic.co/t/logstash-how-to-drop-message-if-field-is-not-a-number/333324 "2023-05-25T15:59:49Z")

</div>

Hi Logstash gurus, I need to drop the messages that contain specific fields that are not a number. The filter I have is: filter { csv { separator =\> "," skip\_header =\> "true" columns =\> \["process-n…

---

## [Set Filter with + on Last Value Aggregation](https://discuss.elastic.co/t/set-filter-with-on-last-value-aggregation/334348)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 3:36pm UTC](https://discuss.elastic.co/t/set-filter-with-on-last-value-aggregation/334348 "2023-05-25T15:36:02Z")

</div>

Hello, if you click the + in a lens table entry from a last value aggregation column of a text field the resulting filter is I assume that happens for all aggregated columns as the expectation is that an aggregate…

---

## [Documents being deleted after BulkRequest indexing](https://discuss.elastic.co/t/documents-being-deleted-after-bulkrequest-indexing/333674)

<div class="topic-metadata">

**Author:** [@vivss](https://discuss.elastic.co/u/vivss)\
**Replies:** 12\
**Last updated:** [May 25, 2023, 3:06pm UTC](https://discuss.elastic.co/t/documents-being-deleted-after-bulkrequest-indexing/333674 "2023-05-25T15:06:35Z")

</div>

Hi all, We are using Elasticsearch 7.17.7 and indexing documents via BulkRequest in Java API Client, and we noticed that many documents are being deleted after indexing. We retrieve the records from a Postgresql databas…

---

## [API Key delete by mistake in stack Management](https://discuss.elastic.co/t/api-key-delete-by-mistake-in-stack-management/334304)

<div class="topic-metadata">

**Author:** [@maniacci](https://discuss.elastic.co/u/maniacci)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 1:04pm UTC](https://discuss.elastic.co/t/api-key-delete-by-mistake-in-stack-management/334304 "2023-05-25T13:04:11Z")

</div>

Hi , I have by mistake deleted API keys (while doing some manipulations following a test to add a Linux server on the SIEM). I would like to know if it is possible to restore his keys? I have Veeam backups . I would …

---

## [Elasticsearch 7.17.10 indexing bottleneck on i3.2xlarge and d3.2xlarge nodes in EKS](https://discuss.elastic.co/t/elasticsearch-7-17-10-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks/333503)

<div class="topic-metadata">

**Author:** [@Chris\_Austin](https://discuss.elastic.co/u/Chris_Austin)\
**Replies:** 52\
**Last updated:** [May 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-10-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks/333503 "2023-05-25T13:03:25Z")

</div>

My 7.17.10 cluster is hosted in AWS EKS and is managed by ECK. It appears to top out at around 90k documents indexed per second (including replicas) per second and I haven't been able to identify the bottleneck. Adding m…

---

## [Filebeat Error and Configuration Issues](https://discuss.elastic.co/t/filebeat-error-and-configuration-issues/334094)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 11:56am UTC](https://discuss.elastic.co/t/filebeat-error-and-configuration-issues/334094 "2023-05-25T11:56:20Z")

</div>

Despite my efforts, I have been unable to resolve the following error messages and configuration challenges. Your expertise and guidance would be greatly appreciated! When checking the status of Filebeat, I encountered …

---

## [System.filesystem.used.pct showing 0.55 want to change it in 55% on Visualization](https://discuss.elastic.co/t/system-filesystem-used-pct-showing-0-55-want-to-change-it-in-55-on-visualization/334020)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/system-filesystem-used-pct-showing-0-55-want-to-change-it-in-55-on-visualization/334020 "2023-05-25T11:54:39Z")

</div>

Hi All, system.filesystem.used.pct showing 0.55 want to change it in 55% on Visualization/Dashboard. How can I change this. Thanks in advance Vaibhav Ubale

---

## [Pass raw search object to \`SearchAsync\` Elastic.Clients.Elasticsearch 8.1.1 .NET](https://discuss.elastic.co/t/pass-raw-search-object-to-searchasync-elastic-clients-elasticsearch-8-1-1-net/334311)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:10am UTC](https://discuss.elastic.co/t/pass-raw-search-object-to-searchasync-elastic-clients-elasticsearch-8-1-1-net/334311 "2023-05-25T11:10:55Z")

</div>

I am trying to implement an API, which allows users to dynamically query an Elasticsearch index. The API should therefore act like a "proxy" between the user and Elasticsearch (the API performs additional operations alon…

---

## [Can U help with optimal search method?](https://discuss.elastic.co/t/can-u-help-with-optimal-search-method/334310)

<div class="topic-metadata">

**Author:** [@Nurm](https://discuss.elastic.co/u/Nurm)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:03am UTC](https://discuss.elastic.co/t/can-u-help-with-optimal-search-method/334310 "2023-05-25T11:03:43Z")

</div>

Can you guys show the best way to find users by first and last name or by full name. Also, when the user enters a name, I want to search for that name in both Cyrillic and Latin. Any links, ideas? Client could enter N…

---

## [Kibana drill down on bar charts](https://discuss.elastic.co/t/kibana-drill-down-on-bar-charts/334208)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 10:35am UTC](https://discuss.elastic.co/t/kibana-drill-down-on-bar-charts/334208 "2023-05-25T10:35:36Z")

</div>

Hi, We are using kibana 7.17. In one of the use cases, it is required to drill down to a dashboard based on the clicked value in a bar chart. Attached the screenshot below. In this case, when the user clicks on a bar …

---

## [Polygon Self-Intersecting when there is minimal wrapping at -180/180 failing](https://discuss.elastic.co/t/polygon-self-intersecting-when-there-is-minimal-wrapping-at-180-180-failing/334065)

<div class="topic-metadata">

**Author:** [@Craig\_Roush](https://discuss.elastic.co/u/Craig_Roush)\
**Replies:** 13\
**Last updated:** [May 25, 2023, 10:05am UTC](https://discuss.elastic.co/t/polygon-self-intersecting-when-there-is-minimal-wrapping-at-180-180-failing/334065 "2023-05-25T10:05:31Z")

</div>

I am receiving a polygon-self intersecting error when I have a polygon that barely wraps across 180 to -180: I have a simple mapping for a index setup as: index\_mapping = { "time": { "type": "da…

---

## [Kibana conflicting field](https://discuss.elastic.co/t/kibana-conflicting-field/334301)

<div class="topic-metadata">

**Author:** [@jfrank](https://discuss.elastic.co/u/jfrank)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 9:57am UTC](https://discuss.elastic.co/t/kibana-conflicting-field/334301 "2023-05-25T09:57:10Z")

</div>

Recently I've changed type of the field from text to long and now I see in documents in Kibana that this field is "conflicting". How Can I solve this? Kibana v 8.1.0

---

## [How to extract all log sources in ELK?](https://discuss.elastic.co/t/how-to-extract-all-log-sources-in-elk/334188)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 6\
**Last updated:** [May 25, 2023, 9:45am UTC](https://discuss.elastic.co/t/how-to-extract-all-log-sources-in-elk/334188 "2023-05-25T09:45:41Z")

</div>

Hi team, I'm new in elastic stack , please i need a procedure how to extract all the source logs IP and status if possible, for example i have 10 servers linux redhat integrated in elastic with auditbeat and i have 10 w…

---

## [The analyser in mapping is not getting applied to field](https://discuss.elastic.co/t/the-analyser-in-mapping-is-not-getting-applied-to-field/334286)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 9:38am UTC](https://discuss.elastic.co/t/the-analyser-in-mapping-is-not-getting-applied-to-field/334286 "2023-05-25T09:38:44Z")

</div>

This is the mapping and settings { "blogs\_fixed2": { "aliases": {}, "mappings": { "\_meta": { "created\_by": "Sheereen Hamza KV" }, "properties": { "@timestamp": { "t…

---

## [Elastic search Client API](https://discuss.elastic.co/t/elastic-search-client-api/334288)

<div class="topic-metadata">

**Author:** [@Gururaj\_Shivananda](https://discuss.elastic.co/u/Gururaj_Shivananda)\
**Replies:** 7\
**Last updated:** [May 25, 2023, 9:16am UTC](https://discuss.elastic.co/t/elastic-search-client-api/334288 "2023-05-25T09:16:26Z")

</div>

Hi we are using Elastic Search client API to read/write from OpenSearch. This is part of commercial service provided to customer. How would SSPL license Apply here.

---

## [Failing to setup Elasticsearch dual node cluster](https://discuss.elastic.co/t/failing-to-setup-elasticsearch-dual-node-cluster/334298)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 9:15am UTC](https://discuss.elastic.co/t/failing-to-setup-elasticsearch-dual-node-cluster/334298 "2023-05-25T09:15:43Z")

</div>

I am trying to run a 2 node Elasticsearch cluster on different ec2 instances present in different regions. I using the following commands:- Command to run data node:- sudo docker run -it --pull=always --privileged --…

---

## [Taking snapshot of existing data and restore it after some disaster](https://discuss.elastic.co/t/taking-snapshot-of-existing-data-and-restore-it-after-some-disaster/334174)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 8:09am UTC](https://discuss.elastic.co/t/taking-snapshot-of-existing-data-and-restore-it-after-some-disaster/334174 "2023-05-25T08:09:26Z")

</div>

I am running one node which is a master node it receives data/logs from data nodes. This node has some indices that are created when I install this master node on a server. So the logs generated by master node and data …

---

## [Rolover policy for custom Index](https://discuss.elastic.co/t/rolover-policy-for-custom-index/333399)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 6:47am UTC](https://discuss.elastic.co/t/rolover-policy-for-custom-index/333399 "2023-05-25T06:47:08Z")

</div>

I got logs from winlogbeats, and i want to store them in custom indexes. So i need rollover policy for this indexes. here is part of logstash config file (output): output { if \[type\] == "winlogbeat" { elasticsearc…

---

## [Search\_phase\_execution\_exception error with all\_shared failes](https://discuss.elastic.co/t/search-phase-execution-exception-error-with-all-shared-failes/334169)

<div class="topic-metadata">

**Author:** [@Kapildev](https://discuss.elastic.co/u/Kapildev)\
**Replies:** 15\
**Last updated:** [May 25, 2023, 6:18am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-error-with-all-shared-failes/334169 "2023-05-25T06:18:32Z")

</div>

hi team i am facing this search\_phase\_execution\_exception Please find the details. curl -X GET "localhost:9200/\_cluster/health?filter\_path=status,\*\_shards&pretty" { "status" : "red", "active\_primary\_shards" : 0, "…

---

## [elasticsearch build error](https://discuss.elastic.co/t/elasticsearch-build-error/334269)

<div class="topic-metadata">

**Author:** [@sand-hya](https://discuss.elastic.co/u/sand-hya)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 4:56am UTC](https://discuss.elastic.co/t/elasticsearch-build-error/334269 "2023-05-25T04:56:48Z")

</div>

Hello, I was running elasticsearch 7.6.0 version from source, and when I run ./gradlew assemble I am getting this error. Configure project :x-pack:qa:third-party:active-directory Tests for :x-pack:qa:third-party:acti…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=531)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=533)
