# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=536

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 537

---

## [How to hide the search field name menu bar in Kibana Discover](https://discuss.elastic.co/t/how-to-hide-the-search-field-name-menu-bar-in-kibana-discover/333526)

<div class="topic-metadata">

**Author:** [@gopikrish](https://discuss.elastic.co/u/gopikrish)\
**Replies:** 3\
**Last updated:** [May 22, 2023, 8:07am UTC](https://discuss.elastic.co/t/how-to-hide-the-search-field-name-menu-bar-in-kibana-discover/333526 "2023-05-22T08:07:14Z")

</div>

Hi Team, Can anyone please explain to me how to hide or remove the search field name menu bar in Kibana Discover when seeing the logs. For more details, please see the image that I attached above. In that case, I ne…

---

## [How i can convert the given SQl query to dsl query?](https://discuss.elastic.co/t/how-i-can-convert-the-given-sql-query-to-dsl-query/333878)

<div class="topic-metadata">

**Author:** [@babu\_dev](https://discuss.elastic.co/u/babu_dev)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 7:58am UTC](https://discuss.elastic.co/t/how-i-can-convert-the-given-sql-query-to-dsl-query/333878 "2023-05-22T07:58:49Z")

</div>

Sql query SELECT \* FROM USER\_DB WHERE (NAME IN('BABU DEV', 'NIKHIL') OR AGE IN(23,45)) AND COUNTRY = 'INDIA' AND STATE ='DELHI';

---

## [ElasticSearch Version Upgrade in AWS EKS using Helm Charts \[7.17.3 -\> 8.5.1\]](https://discuss.elastic.co/t/elasticsearch-version-upgrade-in-aws-eks-using-helm-charts-7-17-3-8-5-1/333988)

<div class="topic-metadata">

**Author:** [@helloworld466](https://discuss.elastic.co/u/helloworld466)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 7:54am UTC](https://discuss.elastic.co/t/elasticsearch-version-upgrade-in-aws-eks-using-helm-charts-7-17-3-8-5-1/333988 "2023-05-22T07:54:51Z")

</div>

Have deployed Elasticsearch version 7.17.3 in AWS EKS using helm chart GitHub - elastic/helm-charts: You know, for Kubernetes. My goal is to upgrade my ES to the latest version 8.5.1 using helm chart. I followed the ste…

---

## [Filebeat module specific output : why is this a global config?](https://discuss.elastic.co/t/filebeat-module-specific-output-why-is-this-a-global-config/333741)

<div class="topic-metadata">

**Author:** [@sriramb12](https://discuss.elastic.co/u/sriramb12)\
**Replies:** 5\
**Last updated:** [May 22, 2023, 5:10am UTC](https://discuss.elastic.co/t/filebeat-module-specific-output-why-is-this-a-global-config/333741 "2023-05-22T05:10:44Z")

</div>

I have multiple modules active and like to have each module output saved to a distinct location as I choose file ouput (no elastic integration) I see the output configuration as part of filebeat.yml, which is a global c…

---

## [Logstash config](https://discuss.elastic.co/t/logstash-config/333631)

<div class="topic-metadata">

**Author:** [@A1i](https://discuss.elastic.co/u/A1i)\
**Replies:** 9\
**Last updated:** [May 22, 2023, 4:28am UTC](https://discuss.elastic.co/t/logstash-config/333631 "2023-05-22T04:28:57Z")

</div>

how can I config logstash to read two log files from local then pass them into two indies

---

## [I have a ELK Cluster 7.17.3 and I have installed bundled JDK 18+36.. if i need to upgrade JDK to higher version is it compatible with my 7.17.3 version](https://discuss.elastic.co/t/i-have-a-elk-cluster-7-17-3-and-i-have-installed-bundled-jdk-18-36-if-i-need-to-upgrade-jdk-to-higher-version-is-it-compatible-with-my-7-17-3-version/333782)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 1:49am UTC](https://discuss.elastic.co/t/i-have-a-elk-cluster-7-17-3-and-i-have-installed-bundled-jdk-18-36-if-i-need-to-upgrade-jdk-to-higher-version-is-it-compatible-with-my-7-17-3-version/333782 "2023-05-22T01:49:25Z")

</div>

Hi All, I have a ELK Stack 7.17.3 installed on a Windows 2019 server with bundled JDK 18 +36 . Since there is a vulnerability in JDK 18, can i upgrade the jdk to open jdk 18.0.1 will this impact my ELK Stack . Thanks, …

---

## [Reusing certs b/w http & transport xpack security settings](https://discuss.elastic.co/t/reusing-certs-b-w-http-transport-xpack-security-settings/333691)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 1:13am UTC](https://discuss.elastic.co/t/reusing-certs-b-w-http-transport-xpack-security-settings/333691 "2023-05-22T01:13:00Z")

</div>

Hi - am trying to reuse the same certs for http & transport xpack security settings in elasticsearch.yml. Currently, http settings use company signed, transport xpack settings use elasticsearch signed certs. Tried to use…

---

## [Why Total from the Valid Nest Response is equals 2 and the Documents count equal 1. I'm not sure how that is possible.](https://discuss.elastic.co/t/why-total-from-the-valid-nest-response-is-equals-2-and-the-documents-count-equal-1-im-not-sure-how-that-is-possible/333919)

<div class="topic-metadata">

**Author:** [@Samer\_Abdelwahed](https://discuss.elastic.co/u/Samer_Abdelwahed)\
**Replies:** 3\
**Last updated:** [May 21, 2023, 10:02pm UTC](https://discuss.elastic.co/t/why-total-from-the-valid-nest-response-is-equals-2-and-the-documents-count-equal-1-im-not-sure-how-that-is-possible/333919 "2023-05-21T22:02:35Z")

</div>

Why Total from the Valid Nest Response is equals 2 and the Documents count equal 1. I'm not sure how that is possible. Documents = Count = 1, Total = 2

---

## [Converting timezones in Logstash - HOWTO](https://discuss.elastic.co/t/converting-timezones-in-logstash-howto/333821)

<div class="topic-metadata">

**Author:** [@nbertram](https://discuss.elastic.co/u/nbertram)\
**Replies:** 2\
**Last updated:** [May 21, 2023, 9:12pm UTC](https://discuss.elastic.co/t/converting-timezones-in-logstash-howto/333821 "2023-05-21T21:12:27Z")

</div>

Hi, After trawling a lot of the internet asking how to convert a timestamp from UTC to local time in Logstash I came up blank, and against a whole bunch of answers on here saying "don't - leave that to the presentation …

---

## [Index pattern link is not available at Kibana](https://discuss.elastic.co/t/index-pattern-link-is-not-available-at-kibana/333945)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 2\
**Last updated:** [May 21, 2023, 7:28pm UTC](https://discuss.elastic.co/t/index-pattern-link-is-not-available-at-kibana/333945 "2023-05-21T19:28:20Z")

</div>

I have installed kibana at my Windows 11 WSL. Index pattern is not coming under stack management --\> kibana --\> index pattern Accordingly, when creating an index using logstash or filebeat I cannot find any data at Disc…

---

## [Failed start elasticsearch after install](https://discuss.elastic.co/t/failed-start-elasticsearch-after-install/333959)

<div class="topic-metadata">

**Author:** [@Addr1](https://discuss.elastic.co/u/Addr1)\
**Replies:** 3\
**Last updated:** [May 21, 2023, 6:50pm UTC](https://discuss.elastic.co/t/failed-start-elasticsearch-after-install/333959 "2023-05-21T18:50:25Z")

</div>

Hi, I've an error message after "sudo systemctl start elasticsearch" : Job for elasticsearch.service failed because the control process exited with error code. See "systemctl status elasticsearch.service" and "journalc…

---

## [ELK Indexing Strategy](https://discuss.elastic.co/t/elk-indexing-strategy/333663)

<div class="topic-metadata">

**Author:** [@ARDA\_ASLAN](https://discuss.elastic.co/u/ARDA_ASLAN)\
**Replies:** 11\
**Last updated:** [May 21, 2023, 6:46pm UTC](https://discuss.elastic.co/t/elk-indexing-strategy/333663 "2023-05-21T18:46:30Z")

</div>

Hello Elastic Community, I am quite new in ELK environment so trying to understand the concept and the best practices for a new project that i am responsible. Needing some advices and overview about the indexing strate…

---

## [Creating a table of content for dashboard](https://discuss.elastic.co/t/creating-a-table-of-content-for-dashboard/333908)

<div class="topic-metadata">

**Author:** [@Bav\_Tech](https://discuss.elastic.co/u/Bav_Tech)\
**Replies:** 1\
**Last updated:** [May 21, 2023, 4:41pm UTC](https://discuss.elastic.co/t/creating-a-table-of-content-for-dashboard/333908 "2023-05-21T16:41:13Z")

</div>

hi I have many visualizations in my dashboard and I'd like to make table of contents on the top of dashboard using markdown, so that when i click on one content from the table of content it takes me down to where the vis…

---

## [Elasticsearch cluster replication](https://discuss.elastic.co/t/elasticsearch-cluster-replication/333752)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 4\
**Last updated:** [May 21, 2023, 10:56am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-replication/333752 "2023-05-21T10:56:59Z")

</div>

hello, if i have 2 nodes standalone elasticsearch working with scenario: node-1 : have elasticsearch and logstash and logstash send logs let's called it "index-1" node-2 : have elasticsearch and logstash and logstash …

---

## [Indexing speed single vs multiple clusters](https://discuss.elastic.co/t/indexing-speed-single-vs-multiple-clusters/333910)

<div class="topic-metadata">

**Author:** [@sliu](https://discuss.elastic.co/u/sliu)\
**Replies:** 3\
**Last updated:** [May 21, 2023, 4:22am UTC](https://discuss.elastic.co/t/indexing-speed-single-vs-multiple-clusters/333910 "2023-05-21T04:22:14Z")

</div>

Here's my simplified use case: three indexes, each has 5 billion documents. No need to hit multiple indexes in search. The length of time to index the data is in concern here. With three server nodes, I can have: (1) si…

---

## [2 conf sending data to the same index](https://discuss.elastic.co/t/2-conf-sending-data-to-the-same-index/333888)

<div class="topic-metadata">

**Author:** [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)\
**Replies:** 7\
**Last updated:** [May 20, 2023, 10:41pm UTC](https://discuss.elastic.co/t/2-conf-sending-data-to-the-same-index/333888 "2023-05-20T22:41:47Z")

</div>

Hello, I have 2 conf files and they are sending data at the same time to the 2 index (when I would like each conf to send the information to the specific index) If you can help me, I can provide more information if nee…

---

## [License - clarification](https://discuss.elastic.co/t/license-clarification/333925)

<div class="topic-metadata">

**Author:** [@A\_Thomas](https://discuss.elastic.co/u/A_Thomas)\
**Replies:** 1\
**Last updated:** [May 20, 2023, 7:57pm UTC](https://discuss.elastic.co/t/license-clarification/333925 "2023-05-20T19:57:03Z")

</div>

We are trying to use ES for a SaaS application and would like to understand the license required in case of below scenario. Probably this is a technical discussion forum, but couldn't find any other place where I can ask…

---

## [Referencing a weight value from array of match under score function](https://discuss.elastic.co/t/referencing-a-weight-value-from-array-of-match-under-score-function/333909)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 3\
**Last updated:** [May 20, 2023, 5:31pm UTC](https://discuss.elastic.co/t/referencing-a-weight-value-from-array-of-match-under-score-function/333909 "2023-05-20T17:31:16Z")

</div>

We have a requirement to override default elastic score mechanism and score two documents equally if they have equal number of matches ignoring tf and idf. Below is my sample index data PUT my\_index/\_doc/5 { "affinit…

---

## [Which beat runs? How do i know it?](https://discuss.elastic.co/t/which-beat-runs-how-do-i-know-it/333286)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 2\
**Last updated:** [May 20, 2023, 8:06am UTC](https://discuss.elastic.co/t/which-beat-runs-how-do-i-know-it/333286 "2023-05-20T08:06:46Z")

</div>

I was trying to make a new beat that collects k6 metrics via rest api and then send them into Elasticsearch. I follow the 7.17 Dev Guide " Creating a Beat based on Metricbeat" documentation. But it's like my beat doesn't…

---

## [Weird Bug, Field name is blocked, cant use the same name of field it in other pipelines](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 5\
**Last updated:** [May 20, 2023, 2:25am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890 "2023-05-20T02:25:50Z")

</div>

Hi, I have a pipeline that stores the fields memory\_memused\_per and memory\_swapused\_per in an index , in another pipeline that stores data in another index I have tried to use the same name but nothing is indexed. after …

---

## [Elastic Agent's elasticsearch integration SSL settings does not work with self-signed cert](https://discuss.elastic.co/t/elastic-agents-elasticsearch-integration-ssl-settings-does-not-work-with-self-signed-cert/333306)

<div class="topic-metadata">

**Author:** [@Kelvin\_Chan](https://discuss.elastic.co/u/Kelvin_Chan)\
**Replies:** 3\
**Last updated:** [May 20, 2023, 12:03am UTC](https://discuss.elastic.co/t/elastic-agents-elasticsearch-integration-ssl-settings-does-not-work-with-self-signed-cert/333306 "2023-05-20T00:03:43Z")

</div>

I uses elastic agent to monitor elasticsearch, kibana, logstash and postgresql. Elastic Agent can send all monitoring data to elasticsearch excluding elasticsearch metrics data. This is my elasticsearch integration metr…

---

## [\_geoip\_lookup\_failure in Logstash pipeline using GeoLite2-City.mmdb](https://discuss.elastic.co/t/geoip-lookup-failure-in-logstash-pipeline-using-geolite2-city-mmdb/333802)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 4\
**Last updated:** [May 19, 2023, 11:51pm UTC](https://discuss.elastic.co/t/geoip-lookup-failure-in-logstash-pipeline-using-geolite2-city-mmdb/333802 "2023-05-19T23:51:35Z")

</div>

Hi all When trying to enrich the following pipeline of my Logstash 8.4.3 with GeoIP info: input { file { path =\> "/var/log/apache2/\*.log" start\_position =\> "beginning" } http { } } fi…

---

## [Error wen put pipeline line on conf file (version 8.7)](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887)

<div class="topic-metadata">

**Author:** [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 8:49pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887 "2023-05-19T20:49:55Z")

</div>

Hello, i cant start service, because the logstash bring me this error when i put this lines in conf file. The given configuration is invalid. Reason: Expected one of \[ \\t\\r\\n\], "#", "input", "filter", "output" at line 1…

---

## [Role Template with reference to metadata property from Open ID Realm](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869)

<div class="topic-metadata">

**Author:** [@Artem\_Ruzak](https://discuss.elastic.co/u/Artem_Ruzak)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 7:59pm UTC](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869 "2023-05-19T19:59:13Z")

</div>

Hello, we are having SSO solution implemented based with Keycloak and based on OpenID concept It is working well and we are able to assign roles by username or with reference to realm.name As a next step I want to imp…

---

## [Searching by ngrams](https://discuss.elastic.co/t/searching-by-ngrams/333872)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 9\
**Last updated:** [May 19, 2023, 4:57pm UTC](https://discuss.elastic.co/t/searching-by-ngrams/333872 "2023-05-19T16:57:33Z")

</div>

I use search with query string in index analyzed with ngrams. When I try to search doc with field\_1 = SU0001023277 it's ok. But when I try to use less letters, like SU0001023 the resultset is 0. Why it comes out like th…

---

## [Nested type is removed from the new index while reindexing](https://discuss.elastic.co/t/nested-type-is-removed-from-the-new-index-while-reindexing/333876)

<div class="topic-metadata">

**Author:** [@Maitri](https://discuss.elastic.co/u/Maitri)\
**Replies:** 4\
**Last updated:** [May 19, 2023, 4:14pm UTC](https://discuss.elastic.co/t/nested-type-is-removed-from-the-new-index-while-reindexing/333876 "2023-05-19T16:14:15Z")

</div>

I have an index which a property with nested type. I am reindexing the index into new index. But, in the destination index every mapping are same except the property which was having nested type in the source index. nest…

---

## [When I am trying to open Dev\_tools in Kibana, Why I am getting Black page](https://discuss.elastic.co/t/when-i-am-trying-to-open-dev-tools-in-kibana-why-i-am-getting-black-page/333839)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 3:48pm UTC](https://discuss.elastic.co/t/when-i-am-trying-to-open-dev-tools-in-kibana-why-i-am-getting-black-page/333839 "2023-05-19T15:48:41Z")

</div>

This is how it will shows when I am opening elasticsearch devTools

---

## [Reindex error : "type":"mapper\_parsing\_exception","reason":"failed to parse field \[date\] of type \[date\]](https://discuss.elastic.co/t/reindex-error-type-mapper-parsing-exception-reason-failed-to-parse-field-date-of-type-date/333798)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 3:25pm UTC](https://discuss.elastic.co/t/reindex-error-type-mapper-parsing-exception-reason-failed-to-parse-field-date-of-type-date/333798 "2023-05-19T15:25:12Z")

</div>

Hello, While using the reindexing API, I am running into 4 indices that are giving me errors. It seems like the date in the document matches the template but I guess it is not. I don't really know how to tackle this. …

---

## [Logstash ConfigurationError - Failed to execute action](https://discuss.elastic.co/t/logstash-configurationerror-failed-to-execute-action/333874)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-configurationerror-failed-to-execute-action/333874 "2023-05-19T14:25:51Z")

</div>

I'm getting a configuration error when try to start logstash: at line 13, column 28 (byte 213) after filter {\\n grok {\\n match =\> { \\"message\\" =\> \\"%{COMBINEDAPACHELOG}\\" }\\n }\\n date {\\n match =\> \[ \\"times…

---

## [Disable Kibana Session Timeout](https://discuss.elastic.co/t/disable-kibana-session-timeout/332966)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 3\
**Last updated:** [May 19, 2023, 1:49pm UTC](https://discuss.elastic.co/t/disable-kibana-session-timeout/332966 "2023-05-19T13:49:24Z")

</div>

I have a dashboard displayed on a TV in my office that shows auto-refreshed stats through a Kibana dashboard. I am trying to disable the Kibana Session Timeout so that it never logs out, but the Kibana documentation does…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=535)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=537)
