# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=545

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 546

---

## [Parse Array of JSON object](https://discuss.elastic.co/t/parse-array-of-json-object/333034)

<div class="topic-metadata">

**Author:** [@Nurm](https://discuss.elastic.co/u/Nurm)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 7:10am UTC](https://discuss.elastic.co/t/parse-array-of-json-object/333034 "2023-05-12T07:10:55Z")

</div>

input { jdbc { jdbc\_connection\_string =\> "jdbc:postgresql://localhost:5432/db" jdbc\_user =\> "user" jdbc\_password =\> "pass" jdbc\_driver\_library =\> "/usr/share/logstash/lib/postgresql-42…

---

## [Index deletion error due to change from Gold to Basic license](https://discuss.elastic.co/t/index-deletion-error-due-to-change-from-gold-to-basic-license/329974)

<div class="topic-metadata">

**Author:** [@kazuo](https://discuss.elastic.co/u/kazuo)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 6:36am UTC](https://discuss.elastic.co/t/index-deletion-error-due-to-change-from-gold-to-basic-license/329974 "2023-05-12T06:36:32Z")

</div>

Hello, I was using a GOLD license, but did not renew my contract and I did not renew the contract and switched to the free version. One week after the switchover I received the following message ERROR Failed to compl…

---

## [I want to split from filed value using logstash](https://discuss.elastic.co/t/i-want-to-split-from-filed-value-using-logstash/333059)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 7\
**Last updated:** [May 12, 2023, 6:12am UTC](https://discuss.elastic.co/t/i-want-to-split-from-filed-value-using-logstash/333059 "2023-05-12T06:12:50Z")

</div>

@warkolm @Badger help me.... Hello Everyone I am trying to split recipient-status feild first 3 digit and want to add in to new feild I tried mutate split and add filed but no luck can any one suggest how I can achiv…

---

## [Bug of /\_nlpcn/sql with subqueries](https://discuss.elastic.co/t/bug-of-nlpcn-sql-with-subqueries/333243)

<div class="topic-metadata">

**Author:** [@liuchsh01](https://discuss.elastic.co/u/liuchsh01)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:51am UTC](https://discuss.elastic.co/t/bug-of-nlpcn-sql-with-subqueries/333243 "2023-05-12T03:51:44Z")

</div>

After using the /\_nlpcn/sql interface to query the sql with subqueries, some subsequent queries will time out. sql sample: SELECT count(\*) FROM a\_index where someCode in (SELECT code FROM b\_index where someType ='ttt') …

---

## [Run elastic in docker](https://discuss.elastic.co/t/run-elastic-in-docker/332720)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 3:48am UTC](https://discuss.elastic.co/t/run-elastic-in-docker/332720 "2023-05-12T03:48:55Z")

</div>

HI i run my elastic in docker but when i tap this command curl --cacert http\_ca.crt -u elastic https://localhost:9200 Enter host password for user 'elastic': i have this problem: curl: (60) schannel: CertGetCertific…

---

## [Abbreviation CST timezone issue when use postgresql filebeat module](https://discuss.elastic.co/t/abbreviation-cst-timezone-issue-when-use-postgresql-filebeat-module/333251)

<div class="topic-metadata">

**Author:** [@yanhj93](https://discuss.elastic.co/u/yanhj93)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:29am UTC](https://discuss.elastic.co/t/abbreviation-cst-timezone-issue-when-use-postgresql-filebeat-module/333251 "2023-05-12T03:29:09Z")

</div>

filebeat.modules: - module: postgresql log: enabled: true var.paths: \["/data/pgdata/pg\_log/\*.log"\] input: tags: "server" processors: - drop\_fields: …

---

## [Change HTTP SSL security without private key of CA](https://discuss.elastic.co/t/change-http-ssl-security-without-private-key-of-ca/331465)

<div class="topic-metadata">

**Author:** [@Alex\_Fan](https://discuss.elastic.co/u/Alex_Fan)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 2:31am UTC](https://discuss.elastic.co/t/change-http-ssl-security-without-private-key-of-ca/331465 "2023-05-12T02:31:28Z")

</div>

We just installed ELK stack v8.5.1 on RHEL linux server and the elasticsearch is using the generated certs and I can generate the enrollment token for my Kibana to connect. However, we want to use our corporate internal …

---

## [Logstash error connecting to ElasticSearch](https://discuss.elastic.co/t/logstash-error-connecting-to-elasticsearch/333168)

<div class="topic-metadata">

**Author:** [@audric\_w](https://discuss.elastic.co/u/audric_w)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 10:29pm UTC](https://discuss.elastic.co/t/logstash-error-connecting-to-elasticsearch/333168 "2023-05-11T22:29:15Z")

</div>

I've tried to created sidecar using beats and logstash on OpenShift. However the logstash always attempted to resurrect connection to dead ES instance (to http://elastisearch:9200), despite configs that I've done. Logst…

---

## [Version conflict, document already exists (current version \[1\])](https://discuss.elastic.co/t/version-conflict-document-already-exists-current-version-1/333107)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 11\
**Last updated:** [May 11, 2023, 8:46pm UTC](https://discuss.elastic.co/t/version-conflict-document-already-exists-current-version-1/333107 "2023-05-11T20:46:01Z")

</div>

I am running metricbeat on few system. sending that data to proxy server. proxy then sends data to two logstash servers logstash then parse this and stores records in Elasticsearch. I am creating my own \_id for each …

---

## [Index Pattern might be treated as substring of other Index Pattern](https://discuss.elastic.co/t/index-pattern-might-be-treated-as-substring-of-other-index-pattern/333220)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 7:51pm UTC](https://discuss.elastic.co/t/index-pattern-might-be-treated-as-substring-of-other-index-pattern/333220 "2023-05-11T19:51:51Z")

</div>

We have 2 servers running Winlogbeat. Server 1 Winlogbeat has this index pattern configured: developer-portal-%{+yyyyMMdd} Server 2 Winlogbeat has this index pattern configured: developer-portal-hydrator-%{+yyyyMMdd} …

---

## [Unable to view docs in dataview (w/timestamp field) after doc update](https://discuss.elastic.co/t/unable-to-view-docs-in-dataview-w-timestamp-field-after-doc-update/333189)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 7:42pm UTC](https://discuss.elastic.co/t/unable-to-view-docs-in-dataview-w-timestamp-field-after-doc-update/333189 "2023-05-11T19:42:06Z")

</div>

I'm inserting docs to an index. There's a created\_at field that I use in the dataview for time filtering. After initial doc inserts I can see all the docs in Kibana in my data view. I'm then needing to update docs so …

---

## [Create new fields in elasticsearch](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 7:19pm UTC](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659 "2023-05-11T19:19:15Z")

</div>

i want to calculate the difference in time between 2 logs different and add the value to a new field i search in google and i find that is possible with painless scripting but i dont know how to do it if there is anyon…

---

## [Change IP of single node instance](https://discuss.elastic.co/t/change-ip-of-single-node-instance/333133)

<div class="topic-metadata">

**Author:** [@Dusty\_Boley](https://discuss.elastic.co/u/Dusty_Boley)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/change-ip-of-single-node-instance/333133 "2023-05-11T19:12:05Z")

</div>

Hello all, if this info is somewhere and my search missed it I apologize. Also, I am an Elasticsearch noob so my apologies if I mix up terminology. I have a simple single node setup running version 8.7 to service a sma…

---

## [Deprecation Log Spam](https://discuss.elastic.co/t/deprecation-log-spam/332851)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 3:43pm UTC](https://discuss.elastic.co/t/deprecation-log-spam/332851 "2023-05-11T15:43:02Z")

</div>

The below line is blowing up my log files. What is it and what do I need to do to get it to stop? \[2023-05-03T22:10:15,259\]\[WARN \]\[o.e.d.c.m.IndexNameExpressionResolver\] \[elastic.contoso.net\] data\_stream.dataset="depre…

---

## [UpdateByQueryRequest.setMaxRetries does not seems available in ElasticSearch version 8 Java Client](https://discuss.elastic.co/t/updatebyqueryrequest-setmaxretries-does-not-seems-available-in-elasticsearch-version-8-java-client/333222)

<div class="topic-metadata">

**Author:** [@csplrj](https://discuss.elastic.co/u/csplrj)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 3:41pm UTC](https://discuss.elastic.co/t/updatebyqueryrequest-setmaxretries-does-not-seems-available-in-elasticsearch-version-8-java-client/333222 "2023-05-11T15:41:42Z")

</div>

Below code is for Elasticsearch Client version 7.17. Can't find equivalent code in Elasticsearch Client version 8.7 Script storedScript = new Script(ScriptType.STORED, null, script.getScriptId(), (Map\<String, Object\>) s…

---

## [How to interpret CPU and memory stats?](https://discuss.elastic.co/t/how-to-interpret-cpu-and-memory-stats/332976)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 3:29pm UTC](https://discuss.elastic.co/t/how-to-interpret-cpu-and-memory-stats/332976 "2023-05-11T15:29:38Z")

</div>

Hi! Filebeat logs metric stats in its log file, I am wondering what CPU and memstat mean. Do these show CPU and memory utilization of the beat on the server? Adding a sample for reference. 2023-05-05T10:26:56.954Z …

---

## [Question logstash | Events received vs Event emitted](https://discuss.elastic.co/t/question-logstash-events-received-vs-event-emitted/333219)

<div class="topic-metadata">

**Author:** [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 3:20pm UTC](https://discuss.elastic.co/t/question-logstash-events-received-vs-event-emitted/333219 "2023-05-11T15:20:04Z")

</div>

Hello, On the monitoring part of my logstash instance, I see that I have 1.3b of events received against 784.7m events emitted. can the fact that I drop certain messages in my pipeline explain this phenomenon or is it r…

---

## [Fastest way to ingest CSV's with logstash to elasticsearch](https://discuss.elastic.co/t/fastest-way-to-ingest-csvs-with-logstash-to-elasticsearch/333118)

<div class="topic-metadata">

**Author:** [@Security\_Check](https://discuss.elastic.co/u/Security_Check)\
**Replies:** 8\
**Last updated:** [May 11, 2023, 3:19pm UTC](https://discuss.elastic.co/t/fastest-way-to-ingest-csvs-with-logstash-to-elasticsearch/333118 "2023-05-11T15:19:24Z")

</div>

I'm currently trying to ingest 100gb of csv files into elasticsearch through logstash. The issue is it's taking forever. I have narrowed down the columns I'm trying to filter for to 8 out of 71 but it still takes a long …

---

## [Multiple matches required](https://discuss.elastic.co/t/multiple-matches-required/333192)

<div class="topic-metadata">

**Author:** [@Jason\_Hall](https://discuss.elastic.co/u/Jason_Hall)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 3:10pm UTC](https://discuss.elastic.co/t/multiple-matches-required/333192 "2023-05-11T15:10:31Z")

</div>

I am currently setting up some filters for my incoming Watchguard Firewall logs. The logs come in various different formats so i have to setup multiple match rules. My current filter is filter { #Watchguard logs filter…

---

## [Ingest data with Node.js on Elastic Search service](https://discuss.elastic.co/t/ingest-data-with-node-js-on-elastic-search-service/333082)

<div class="topic-metadata">

**Author:** [@newbie\_coder](https://discuss.elastic.co/u/newbie_coder)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 2:58pm UTC](https://discuss.elastic.co/t/ingest-data-with-node-js-on-elastic-search-service/333082 "2023-05-11T14:58:03Z")

</div>

I have a simple app and I want to ingest data from my app to Elastic Search sevice. I followed the steps from this tutorial which seem pretty straightforward - get a free trial, create a deployment, then install with np…

---

## [Need to split in form of key & value](https://discuss.elastic.co/t/need-to-split-in-form-of-key-value/333218)

<div class="topic-metadata">

**Author:** [@ZERO\_COOL](https://discuss.elastic.co/u/ZERO_COOL)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 2:40pm UTC](https://discuss.elastic.co/t/need-to-split-in-form-of-key-value/333218 "2023-05-11T14:40:09Z")

</div>

I am getting event as below. "rusage" =\> \[ \[0\] "", \[1\] "\[mem=10000,mem=5000,VCS-BASE-RUNTIME=1\]" \], I want the value of mem as res\_mem higher one among two keys with "mem" as new field. output: { res\_mem = 10000 …

---

## [Joining Two Indexes with common field values](https://discuss.elastic.co/t/joining-two-indexes-with-common-field-values/332861)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 8\
**Last updated:** [May 11, 2023, 2:22pm UTC](https://discuss.elastic.co/t/joining-two-indexes-with-common-field-values/332861 "2023-05-11T14:22:30Z")

</div>

Hi, I am trying to join two indexes with common field values. Can someone please help me. Here is the example: Index\_1 =\> A column\_1 =\> value\_1 Index\_2 =\> B column\_2 =\> value\_1 How can i join both indexes on the…

---

## [Elasticsearch too\_many\_requests disk usage exceeded flood-stage watermark](https://discuss.elastic.co/t/elasticsearch-too-many-requests-disk-usage-exceeded-flood-stage-watermark/333111)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 2:20pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-requests-disk-usage-exceeded-flood-stage-watermark/333111 "2023-05-11T14:20:49Z")

</div>

Hello, I've installed elasticsearch and kibana on a virtual Ubuntu Server and I'm pretty sure I do not have enough space on my virtual disk. I'm running on VSphere and I tried to add disk space but it doesn't extend el…

---

## [Using a Terms Query via Elastic.Clients.Elasticsearch 8.1.1 .NET](https://discuss.elastic.co/t/using-a-terms-query-via-elastic-clients-elasticsearch-8-1-1-net/332817)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 2:20pm UTC](https://discuss.elastic.co/t/using-a-terms-query-via-elastic-clients-elasticsearch-8-1-1-net/332817 "2023-05-11T14:20:16Z")

</div>

I am currently trying to write a Terms Query via the Elastic.Clients.Elasticsearch 8.1.1 .NET client. To be more precise, I want to write following query in C#: GET persons/\_search { "query": { "bool": { "mu…

---

## [Kibana showing windows\_eventlog but not sysmon](https://discuss.elastic.co/t/kibana-showing-windows-eventlog-but-not-sysmon/333104)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:57pm UTC](https://discuss.elastic.co/t/kibana-showing-windows-eventlog-but-not-sysmon/333104 "2023-05-11T13:57:01Z")

</div>

Hi, I finally got windows data into security onion. But I dont see sysmon categories? But I do show windows\_events? are windows\_eventlogs the same as sysmon maybe? not sure. thanks for any suggestions or advice

---

## [Filestream id](https://discuss.elastic.co/t/filestream-id/333075)

<div class="topic-metadata">

**Author:** [@haralambop](https://discuss.elastic.co/u/haralambop)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:51pm UTC](https://discuss.elastic.co/t/filestream-id/333075 "2023-05-11T13:51:19Z")

</div>

I have several filestream inputs type: filestream id: filestream1 type: filestream id: filestream2 type: filestream id: filestream3 How can I inserts the Ids ( filestream1,filestream2,filestream3) in the e…

---

## [Elasticsearch in Docker : WARN "this node is locked into cluster UUID" on container restart](https://discuss.elastic.co/t/elasticsearch-in-docker-warn-this-node-is-locked-into-cluster-uuid-on-container-restart/333105)

<div class="topic-metadata">

**Author:** [@Bruno44](https://discuss.elastic.co/u/Bruno44)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch-in-docker-warn-this-node-is-locked-into-cluster-uuid-on-container-restart/333105 "2023-05-11T13:41:05Z")

</div>

Hello, I use Elasticsearch 8.7.1 in an official Docker container. I export the data (/usr/share/elasticsearch/data/) to the host to keep indexing data. If I delete the container (for update for example), when I recrea…

---

## [NEST equivalent code for an ML infer query](https://discuss.elastic.co/t/nest-equivalent-code-for-an-ml-infer-query/333007)

<div class="topic-metadata">

**Author:** [@virtualaidev](https://discuss.elastic.co/u/virtualaidev)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:21pm UTC](https://discuss.elastic.co/t/nest-equivalent-code-for-an-ml-infer-query/333007 "2023-05-11T13:21:55Z")

</div>

Hi there, any NEST library documentation on how to infer query in ML? For instance I want to do the below: POST /\_ml/trained\_models/sentence-transformers\_\_all-minilm-l12-v2/\_infer { "docs": { "text\_field": "simil…

---

## [Filebeat.yml config file permissions owner](https://discuss.elastic.co/t/filebeat-yml-config-file-permissions-owner/333190)

<div class="topic-metadata">

**Author:** [@lmrc](https://discuss.elastic.co/u/lmrc)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:17pm UTC](https://discuss.elastic.co/t/filebeat-yml-config-file-permissions-owner/333190 "2023-05-11T13:17:23Z")

</div>

Hello, I get an error when I start Filebeat about the permissions of the filebeat.yml file error loading config file: config file ("/etc/filebeat/filebeat.yml") can only be writable by the owner but the permissions are…

---

## [If statement performance question](https://discuss.elastic.co/t/if-statement-performance-question/333210)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 12:43pm UTC](https://discuss.elastic.co/t/if-statement-performance-question/333210 "2023-05-11T12:43:59Z")

</div>

Question If I use this IF statement, if ("FTNTFGTpolicyname" in \[message\]) or ("FTNTFGTlogid" in \[message\]) {, the CPU of the logstash server spikes to very high, pretty much forever. If I change it to this, CPU is …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=544)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=546)
