# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=535

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 536

---

## [Possability to use ELK-Stack for SNMP Monitoring like PRTG, CheckMK](https://discuss.elastic.co/t/possability-to-use-elk-stack-for-snmp-monitoring-like-prtg-checkmk/334073)

<div class="topic-metadata">

**Author:** [@tweak19](https://discuss.elastic.co/u/tweak19)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 5:49am UTC](https://discuss.elastic.co/t/possability-to-use-elk-stack-for-snmp-monitoring-like-prtg-checkmk/334073 "2023-05-23T05:49:21Z")

</div>

Hi, I would like to ask if there is a way to use ELK stack for SNMP polling of a large number of different devices with different SNMP v3 settings and different OIDs. The idea behind this is that I would have a system …

---

## [Unable to parse "message"](https://discuss.elastic.co/t/unable-to-parse-message/333635)

<div class="topic-metadata">

**Author:** [@bsauvage1](https://discuss.elastic.co/u/bsauvage1)\
**Replies:** 9\
**Last updated:** [May 23, 2023, 3:41am UTC](https://discuss.elastic.co/t/unable-to-parse-message/333635 "2023-05-23T03:41:55Z")

</div>

Hello. New user of logstash here so please bear with me! Sending over TCP from python using logstash\_async, I receive the item in logstash (see bottom of message). How can I parse the "message" into fields? I have tri…

---

## [Discover Top values "Calculated from 5,000 sample records."](https://discuss.elastic.co/t/discover-top-values-calculated-from-5-000-sample-records/334061)

<div class="topic-metadata">

**Author:** [@eorb7569](https://discuss.elastic.co/u/eorb7569)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 2:06am UTC](https://discuss.elastic.co/t/discover-top-values-calculated-from-5-000-sample-records/334061 "2023-05-23T02:06:54Z")

</div>

Hello. I want to solve this problem. "Calculated from 5,000 sample records." I'd like to see Top values using all records instead of 5000.

---

## [Retrieve items sorted by mutual-terms match](https://discuss.elastic.co/t/retrieve-items-sorted-by-mutual-terms-match/333604)

<div class="topic-metadata">

**Author:** [@K\_K2](https://discuss.elastic.co/u/K_K2)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 12:06am UTC](https://discuss.elastic.co/t/retrieve-items-sorted-by-mutual-terms-match/333604 "2023-05-23T00:06:08Z")

</div>

We have index mapping like this: { "mappings": { "\_source": { "includes": \[ "uid" \] }, "properties": { "follow": { "doc\_values": true, …

---

## [8.7.1: Stand Alone Kubernetes Deployment - filestream input with ID '' already exists](https://discuss.elastic.co/t/8-7-1-stand-alone-kubernetes-deployment-filestream-input-with-id-already-exists/333148)

<div class="topic-metadata">

**Author:** [@berg](https://discuss.elastic.co/u/berg)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 11:33pm UTC](https://discuss.elastic.co/t/8-7-1-stand-alone-kubernetes-deployment-filestream-input-with-id-already-exists/333148 "2023-05-22T23:33:29Z")

</div>

I've used the example K8s manifest to deploy Elastic Agent on our AWS EKS cluster. I followed the documentation in the EKS section to comment out modules that are unavailable in AWS EKS. Recently, I upgraded to 8.7.0 an…

---

## [Add day in Add fields](https://discuss.elastic.co/t/add-day-in-add-fields/333164)

<div class="topic-metadata">

**Author:** [@M.Naim](https://discuss.elastic.co/u/M.Naim)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 6:35pm UTC](https://discuss.elastic.co/t/add-day-in-add-fields/333164 "2023-05-22T18:35:03Z")

</div>

Hi All, I am trying to add a derived date field by adding days into exiting date fields using the below query. ZonedDateTime origValue = doc\['body.dates.dispenseDate'\].value; ZonedDateTime newValue = origValue.plusDays…

---

## [Exporting over 10K objects in Kibana](https://discuss.elastic.co/t/exporting-over-10k-objects-in-kibana/332845)

<div class="topic-metadata">

**Author:** [@Francisco\_Yanez](https://discuss.elastic.co/u/Francisco_Yanez)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 6:18pm UTC](https://discuss.elastic.co/t/exporting-over-10k-objects-in-kibana/332845 "2023-05-22T18:18:25Z")

</div>

Hello Everyone, I have to export from saved objects (Stack Management \>\> Saved Objects) over 10,000 objects. So when I tried to export them I get an error message, is there a way to export over 10K? Thanks

---

## [I want to remove nested elements from logs](https://discuss.elastic.co/t/i-want-to-remove-nested-elements-from-logs/333979)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 5:49pm UTC](https://discuss.elastic.co/t/i-want-to-remove-nested-elements-from-logs/333979 "2023-05-22T17:49:11Z")

</div>

i want to remove nested elements from logs "x": { "test": { "rulesetname": "eq", "operation": { "name": "diagnosticresult", "version": "235" }, "device": "string…

---

## [Kubernetes custom pipeline processing](https://discuss.elastic.co/t/kubernetes-custom-pipeline-processing/333946)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 4\
**Last updated:** [May 22, 2023, 5:44pm UTC](https://discuss.elastic.co/t/kubernetes-custom-pipeline-processing/333946 "2023-05-22T17:44:50Z")

</div>

In pod following annotations mentioned but pipeline is not processing. annotations: co.elastic.logs/enabled: 'true' co.elastic.logs/fileset: syslog co.elastic.logs/module: system co…

---

## [Logstash and AWS Cloudtrail](https://discuss.elastic.co/t/logstash-and-aws-cloudtrail/333927)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 3\
**Last updated:** [May 22, 2023, 5:33pm UTC](https://discuss.elastic.co/t/logstash-and-aws-cloudtrail/333927 "2023-05-22T17:33:57Z")

</div>

Help please. It appears that AWS cloudtrail puts multiple log records under one top level field, like this: "Records": \[ { "eventName": "AssumeRole", "requestParameters": { "durationSeconds": 1500, "role…

---

## [Slow ES ingestion using Dataflow template with partialUpdates](https://discuss.elastic.co/t/slow-es-ingestion-using-dataflow-template-with-partialupdates/334039)

<div class="topic-metadata">

**Author:** [@julius11](https://discuss.elastic.co/u/julius11)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 5:14pm UTC](https://discuss.elastic.co/t/slow-es-ingestion-using-dataflow-template-with-partialupdates/334039 "2023-05-22T17:14:23Z")

</div>

We are using this template to ingest data once a day from BigQuery to Elastic Search. It creates a dataflow job using the following relevant parameters: "usePartialUpdate": "true", "batchSizeBytes": "5242880", …

---

## [Synonyms in kibana discover](https://discuss.elastic.co/t/synonyms-in-kibana-discover/333961)

<div class="topic-metadata">

**Author:** [@Bav\_Tech](https://discuss.elastic.co/u/Bav_Tech)\
**Replies:** 3\
**Last updated:** [May 22, 2023, 5:01pm UTC](https://discuss.elastic.co/t/synonyms-in-kibana-discover/333961 "2023-05-22T17:01:55Z")

</div>

i am able to create a synonym analyzer and use it to query and get result using the kibana dev tool. is it possible that i use that same custom synonym analyzer when searching for a text in kibana discover? or bet…

---

## [Unable to start Auditbeat on Proxmox Container](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-proxmox-container/333886)

<div class="topic-metadata">

**Author:** [@tli](https://discuss.elastic.co/u/tli)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 4:36pm UTC](https://discuss.elastic.co/t/unable-to-start-auditbeat-on-proxmox-container/333886 "2023-05-22T16:36:15Z")

</div>

Hi, I tried to install auditbeat on Proxmox Container (Ubuntu) It failed with following msg written to the log 2023-05-19T15:03:04.117-0400 INFO instance/beat.go:309 Setup Beat: auditbeat; Version: 7.15.0 20…

---

## [Elastic Agent logs empty](https://discuss.elastic.co/t/elastic-agent-logs-empty/333681)

<div class="topic-metadata">

**Author:** [@liquidkite](https://discuss.elastic.co/u/liquidkite)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 4:09pm UTC](https://discuss.elastic.co/t/elastic-agent-logs-empty/333681 "2023-05-22T16:09:55Z")

</div>

Hello all, I've been working on installing integrations in elastic-agent. I removed some existing integrations and tried adding them again and the elastic-agent logs are not showing up in Fleet -\> Agents - \>logs. I get …

---

## [How to configure Elastic Agent Policy in Fleet to Handle Long Key Values in JSON Logging](https://discuss.elastic.co/t/how-to-configure-elastic-agent-policy-in-fleet-to-handle-long-key-values-in-json-logging/334033)

<div class="topic-metadata">

**Author:** [@abhidwi27](https://discuss.elastic.co/u/abhidwi27)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 4:02pm UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-policy-in-fleet-to-handle-long-key-values-in-json-logging/334033 "2023-05-22T16:02:07Z")

</div>

Hello, I have successfully set up an Elastic cluster by referring to the documentation provided by Elastic. I have configured the Elastic Stack version 8.7 in a self-managed manner. The following resources were particul…

---

## [How to configure Fleet Kubernetes Integration to Push Kubernetes Container Logs to Individual Data Streams Based on Container Name](https://discuss.elastic.co/t/how-to-configure-fleet-kubernetes-integration-to-push-kubernetes-container-logs-to-individual-data-streams-based-on-container-name/334032)

<div class="topic-metadata">

**Author:** [@abhidwi27](https://discuss.elastic.co/u/abhidwi27)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 3:43pm UTC](https://discuss.elastic.co/t/how-to-configure-fleet-kubernetes-integration-to-push-kubernetes-container-logs-to-individual-data-streams-based-on-container-name/334032 "2023-05-22T15:43:41Z")

</div>

Hello, I have successfully set up an Elasticsearch license and started working on a proof-of-concept (POC). Following the documentation provided by Elastic, I have configured the Elastic Stack version 8.7 in a self-mana…

---

## [Change ML instance configuration](https://discuss.elastic.co/t/change-ml-instance-configuration/333773)

<div class="topic-metadata">

**Author:** [@Elijah\_Adeoye](https://discuss.elastic.co/u/Elijah_Adeoye)\
**Replies:** 6\
**Last updated:** [May 22, 2023, 3:18pm UTC](https://discuss.elastic.co/t/change-ml-instance-configuration/333773 "2023-05-22T15:18:43Z")

</div>

Not sure if this can be routed to a more appropriate space but how do we change the ML instance for Elastic Cloud deployments? For my eland experiment, I am currently assigned "aws.es.ml.c5d" (costly) but I'd like to cha…

---

## [I want to sort items by the array of numbers](https://discuss.elastic.co/t/i-want-to-sort-items-by-the-array-of-numbers/333981)

<div class="topic-metadata">

**Author:** [@CookiesPrompt](https://discuss.elastic.co/u/CookiesPrompt)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 3:07pm UTC](https://discuss.elastic.co/t/i-want-to-sort-items-by-the-array-of-numbers/333981 "2023-05-22T15:07:50Z")

</div>

Hello! I am using elasticsearch version 7.11 and I want to sort items by the array of numbers: lucky\_numbers.number\_list A have a lot of elements like below and arrays have a dynamic length, example: \_source { "ga…

---

## [POSTGRESQL 9.6 Y ELASTICSEARCH 8.7.0](https://discuss.elastic.co/t/postgresql-9-6-y-elasticsearch-8-7-0/333711)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 1:54pm UTC](https://discuss.elastic.co/t/postgresql-9-6-y-elasticsearch-8-7-0/333711 "2023-05-22T13:54:15Z")

</div>

Hello everyone, I have a problem with the logs that I receive from postgresql version 9.6 to my elasticseach version 8.7.0. I have configured as instructed but I get the error shown in the image: I have another serv…

---

## [Elasticsearch is not working and gives " all shards not available" using the version 6.4.1](https://discuss.elastic.co/t/elasticsearch-is-not-working-and-gives-all-shards-not-available-using-the-version-6-4-1/334005)

<div class="topic-metadata">

**Author:** [@Shadi\_Almasri](https://discuss.elastic.co/u/Shadi_Almasri)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 1:51pm UTC](https://discuss.elastic.co/t/elasticsearch-is-not-working-and-gives-all-shards-not-available-using-the-version-6-4-1/334005 "2023-05-22T13:51:34Z")

</div>

elasticsearch is not working and gives " all shards not available" using the version 6.4.1

---

## [How do I aggregate/rollup/transform an index that will allow me to see # of daily active users?](https://discuss.elastic.co/t/how-do-i-aggregate-rollup-transform-an-index-that-will-allow-me-to-see-of-daily-active-users/333873)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 1:31pm UTC](https://discuss.elastic.co/t/how-do-i-aggregate-rollup-transform-an-index-that-will-allow-me-to-see-of-daily-active-users/333873 "2023-05-22T13:31:36Z")

</div>

My eventual goal is to graph number of daily active users in Kibana. However, to get there, I think I need an index that aggregates user activity per day. To give a little context - every user activity is logged as a sin…

---

## [Issues regarding the installation of ElasticSearch on a remote server](https://discuss.elastic.co/t/issues-regarding-the-installation-of-elasticsearch-on-a-remote-server/333860)

<div class="topic-metadata">

**Author:** [@Gio\_27](https://discuss.elastic.co/u/Gio_27)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 12:48pm UTC](https://discuss.elastic.co/t/issues-regarding-the-installation-of-elasticsearch-on-a-remote-server/333860 "2023-05-22T12:48:07Z")

</div>

Good morning everyone. First thing first: I am a newbie on topics like servers, unix systems and CLIs. I am working on a Logs monitoring & analysis tool project using the ELK stack. I need to install elasticsearch on …

---

## [Regarding not using data streams for logs](https://discuss.elastic.co/t/regarding-not-using-data-streams-for-logs/334013)

<div class="topic-metadata">

**Author:** [@Jay\_Timbadia](https://discuss.elastic.co/u/Jay_Timbadia)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 12:26pm UTC](https://discuss.elastic.co/t/regarding-not-using-data-streams-for-logs/334013 "2023-05-22T12:26:40Z")

</div>

Hi, I am using latest version of Elastic Search. I am trying to Log my application logs to elasticsearch via logstash. It seems that its using data streams by default to create new indexes with weird index hidden name…

---

## [ILM on single-node?](https://discuss.elastic.co/t/ilm-on-single-node/333997)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 6\
**Last updated:** [May 22, 2023, 10:44am UTC](https://discuss.elastic.co/t/ilm-on-single-node/333997 "2023-05-22T10:44:37Z")

</div>

Hello everyone, I am currently on a single-node infrastructure and I would like to know if the implementation of ILM was useful, I assumed that putting an ILM with the different phases would allow me to keep my data lon…

---

## [Kibana url template scripted field](https://discuss.elastic.co/t/kibana-url-template-scripted-field/329050)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [May 22, 2023, 10:29am UTC](https://discuss.elastic.co/t/kibana-url-template-scripted-field/329050 "2023-05-22T10:29:53Z")

</div>

Hello All, I've created a scripted field and would like know how can i configure the url host and port dynamically through some external config for 1 specific index pattern? intention is not to come in kibana and do…

---

## [Equal field values show up as different](https://discuss.elastic.co/t/equal-field-values-show-up-as-different/333436)

<div class="topic-metadata">

**Author:** [@DarkKooky](https://discuss.elastic.co/u/DarkKooky)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 9:42am UTC](https://discuss.elastic.co/t/equal-field-values-show-up-as-different/333436 "2023-05-22T09:42:03Z")

</div>

Why do these values show up as different although equal and how should it be fixed? If this could help: the stack consists of Elasticsearch, Kibana and Filebeat Filebeat's input comes from port 514 the logs are proces…

---

## [How to monitor host machine by using elastic agent docker container](https://discuss.elastic.co/t/how-to-monitor-host-machine-by-using-elastic-agent-docker-container/333938)

<div class="topic-metadata">

**Author:** [@Kelvin\_Chan](https://discuss.elastic.co/u/Kelvin_Chan)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 9:05am UTC](https://discuss.elastic.co/t/how-to-monitor-host-machine-by-using-elastic-agent-docker-container/333938 "2023-05-22T09:05:27Z")

</div>

Container is isolated, which means i do not have enough privilege to access other container. What i did is to mount log files to elastic agent, but it does not solve metricbeat problem that can not access system stats. T…

---

## [Kuromoji\_number and kuromoji\_readingform filter issue](https://discuss.elastic.co/t/kuromoji-number-and-kuromoji-readingform-filter-issue/333999)

<div class="topic-metadata">

**Author:** [@kagnihotri](https://discuss.elastic.co/u/kagnihotri)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 9:02am UTC](https://discuss.elastic.co/t/kuromoji-number-and-kuromoji-readingform-filter-issue/333999 "2023-05-22T09:02:49Z")

</div>

Hi, I have added these two filters - kuromoji\_number, kuromoji\_readingform kuromoji\_readingform is dominating and it is not generating expected tokens from kuromoji\_number filter. Example - { "text": "一〇〇〇", "tok…

---

## [Percentage only available on 1 aggregation in Data Table visualisation](https://discuss.elastic.co/t/percentage-only-available-on-1-aggregation-in-data-table-visualisation/333984)

<div class="topic-metadata">

**Author:** [@Wanching\_Teoh](https://discuss.elastic.co/u/Wanching_Teoh)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 8:29am UTC](https://discuss.elastic.co/t/percentage-only-available-on-1-aggregation-in-data-table-visualisation/333984 "2023-05-22T08:29:20Z")

</div>

Hi, I was trying to add percentage to two columns (4xx and 5xx) which are both an aggregation based on terms. However, from the option list, it only allow me to show percentage on one aggregation. Because I am us…

---

## [Cluster is not established](https://discuss.elastic.co/t/cluster-is-not-established/333671)

<div class="topic-metadata">

**Author:** [@apopap](https://discuss.elastic.co/u/apopap)\
**Replies:** 14\
**Last updated:** [May 22, 2023, 8:16am UTC](https://discuss.elastic.co/t/cluster-is-not-established/333671 "2023-05-22T08:16:28Z")

</div>

I have 2 EC2 instances one on private network 1 AZ1 and other on private network 2 AZ 2 and try to establish a cluster. The configuration is similar on both nodes, node.name changes # Add your configuration lines here …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=534)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=536)
