# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=546

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 547

---

## [Configuración formato metric count](https://discuss.elastic.co/t/configuracion-formato-metric-count/333031)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 12:42pm UTC](https://discuss.elastic.co/t/configuracion-formato-metric-count/333031 "2023-05-11T12:42:23Z")

</div>

Buenos días, Es posible dar formato a una metrica en una visualización tipo tabla? Es decir, cuando creas una tabla y la metrica la configuras como "Sum Bucket" o "count" el número se alinea en la parte de la izquierda…

---

## [Grok regex match after CSV filter: unable to add a new field from grok match in logstash](https://discuss.elastic.co/t/grok-regex-match-after-csv-filter-unable-to-add-a-new-field-from-grok-match-in-logstash/333206)

<div class="topic-metadata">

**Author:** [@rj.elkadmin](https://discuss.elastic.co/u/rj.elkadmin)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 12:24pm UTC](https://discuss.elastic.co/t/grok-regex-match-after-csv-filter-unable-to-add-a-new-field-from-grok-match-in-logstash/333206 "2023-05-11T12:24:26Z")

</div>

Hi team, I am new to here, i apologize for any inconvenient. I am looking for some help on my issue here, kindly assist. My requirement is to process data from csv files located in s3 bucket using Logstash and ingest i…

---

## [How to combine two records into one with logstash and call a filter script before save into Elasticsearch](https://discuss.elastic.co/t/how-to-combine-two-records-into-one-with-logstash-and-call-a-filter-script-before-save-into-elasticsearch/332957)

<div class="topic-metadata">

**Author:** [@liusanyong](https://discuss.elastic.co/u/liusanyong)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 12:23pm UTC](https://discuss.elastic.co/t/how-to-combine-two-records-into-one-with-logstash-and-call-a-filter-script-before-save-into-elasticsearch/332957 "2023-05-11T12:23:38Z")

</div>

Hi, I want to do some aggregation and transformation with logstash for input data stream as following steps: Combine two input metric events for a single transaction coming from transaction server and database into o…

---

## [Adding Processors / Pipelines to an integration attached to a policy breaks running agent (Error creating runner from config: Can only start an input when all related states are finished)](https://discuss.elastic.co/t/adding-processors-pipelines-to-an-integration-attached-to-a-policy-breaks-running-agent-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/332909)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 12:14pm UTC](https://discuss.elastic.co/t/adding-processors-pipelines-to-an-integration-attached-to-a-policy-breaks-running-agent-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/332909 "2023-05-11T12:14:52Z")

</div>

8.7 here, Pretty self explanatory. Steps in the screenshots. Error creating runner from config: Can only start an input when all related states are finished What does related states mean ? there is only that single in…

---

## [Getting error "Could not index event to Elasticsearch" in logstash?](https://discuss.elastic.co/t/getting-error-could-not-index-event-to-elasticsearch-in-logstash/333198)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 11:47am UTC](https://discuss.elastic.co/t/getting-error-could-not-index-event-to-elasticsearch-in-logstash/333198 "2023-05-11T11:47:25Z")

</div>

Using Logstash version 7.4.3 logstash-filter-json plugin. filter { json { source =\> "message" } } logs are:- {"Event":"SparkListenerJobStart","Job ID":1,"Submission Time":1640751467318,"Stage Infos":\[{"Stage ID":…

---

## [I want to get a status based on the date difference ersult](https://discuss.elastic.co/t/i-want-to-get-a-status-based-on-the-date-difference-ersult/333054)

<div class="topic-metadata">

**Author:** [@alig](https://discuss.elastic.co/u/alig)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 11:41am UTC](https://discuss.elastic.co/t/i-want-to-get-a-status-based-on-the-date-difference-ersult/333054 "2023-05-11T11:41:32Z")

</div>

Hi there, This is what I am using in scripted fields def sorDate = new Date().getTime() - doc\['sor\_idate'\].value; if (sorDate \> 5){ return "crtical" }; The field is defined as below and I have an error and cannot f…

---

## [Unable to create new index \[.watches-6-reindexed-for-8\] because it would match composable template \[.watches\]](https://discuss.elastic.co/t/unable-to-create-new-index-watches-6-reindexed-for-8-because-it-would-match-composable-template-watches/333202)

<div class="topic-metadata">

**Author:** [@fmkaiser](https://discuss.elastic.co/u/fmkaiser)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 11:35am UTC](https://discuss.elastic.co/t/unable-to-create-new-index-watches-6-reindexed-for-8-because-it-would-match-composable-template-watches/333202 "2023-05-11T11:35:23Z")

</div>

Hello, when trying to migrate system indices to ES 8.x, I get the following error: unable to create new index \[.watches-6-reindexed-for-8\] because it would match composable template \[.watches\] full output We are cu…

---

## [ Index not moving to delete phase](https://discuss.elastic.co/t/index-not-moving-to-delete-phase/333026)

<div class="topic-metadata">

**Author:** [@tirelibirefe](https://discuss.elastic.co/u/tirelibirefe)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 11:06am UTC](https://discuss.elastic.co/t/index-not-moving-to-delete-phase/333026 "2023-05-11T11:06:21Z")

</div>

Hello, I have Elasticsearch 8 on K8s. Fluentbit sends logs to ES8. Everyday new indexes are created based on date; likes this: backend-app-2023.05.09 backend-app-2023.05.10 backend-app-2023.05.11 ... I would like e…

---

## [How to disable a plugin in Logstash Configuration file](https://discuss.elastic.co/t/how-to-disable-a-plugin-in-logstash-configuration-file/333197)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 11:00am UTC](https://discuss.elastic.co/t/how-to-disable-a-plugin-in-logstash-configuration-file/333197 "2023-05-11T11:00:52Z")

</div>

Hello, I have a configuration file with multiple plugins. I want to disable all plugin and run 1 plugin for some use cases...How can I do that. My config example- input { http\_poller { urls =\> { api1=\> { …

---

## ["\_cat/nodes" API reports "transport" IP instead of "http" IP](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166)

<div class="topic-metadata">

**Author:** [@Jeremy\_Lecour](https://discuss.elastic.co/u/Jeremy_Lecour)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 10:40am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166 "2023-05-11T10:40:38Z")

</div>

Hi, I have a 2-nodes cluster with this setup for the networking configuration : http.host: \[\_local\_,\_ens192\_\] http.port: 9200 transport.host: \[\_ens161\_\] transport.port: 9300 And here is my network setup : # ip -br a…

---

## [Multiple Elasticsearch instances architecture](https://discuss.elastic.co/t/multiple-elasticsearch-instances-architecture/333187)

<div class="topic-metadata">

**Author:** [@jabulon](https://discuss.elastic.co/u/jabulon)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 10:18am UTC](https://discuss.elastic.co/t/multiple-elasticsearch-instances-architecture/333187 "2023-05-11T10:18:53Z")

</div>

I am designing a solution based on many smaller Elasticsearch engines scattered around the world, and a single instance containing all of the data from all of the instances combined. I do not need the data to be up to da…

---

## [Elasticsearch - get logs from DMZ](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901)

<div class="topic-metadata">

**Author:** [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901 "2023-05-11T09:28:48Z")

</div>

Hi , we have Elasticsearch cluster and now we want to stream logs from DMZ environment to there which isn't allowed by InfoSec purpose. Only allowed method of pull from the DMZ. What's the preferred option in such cas…

---

## [ElasticSearch does not see indices](https://discuss.elastic.co/t/elasticsearch-does-not-see-indices/332960)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 6\
**Last updated:** [May 11, 2023, 9:23am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-see-indices/332960 "2023-05-11T09:23:11Z")

</div>

Hi, I had to reboot EC2 instances that hosts 5-node cluster. The data stored on corresponding EBS volumes. Once I have rebooted the instance and started the Elasticsearch my cluster got into status red. \_cat/indices m…

---

## [My index write api request blocked by status 403 after adding index lifecycle policy](https://discuss.elastic.co/t/my-index-write-api-request-blocked-by-status-403-after-adding-index-lifecycle-policy/333174)

<div class="topic-metadata">

**Author:** [@jeyong.oh](https://discuss.elastic.co/u/jeyong.oh)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 9:01am UTC](https://discuss.elastic.co/t/my-index-write-api-request-blocked-by-status-403-after-adding-index-lifecycle-policy/333174 "2023-05-11T09:01:46Z")

</div>

This is what happened today. I'm using index without life cycle management. The index name is "vehicle-iot-coordinate", it's size is about 280GB and it grow with rate of 1GB/day. I'm adding lifecycle management. (disab…

---

## [Logstash , multiple indexs using same ILM and index template and alias error](https://discuss.elastic.co/t/logstash-multiple-indexs-using-same-ilm-and-index-template-and-alias-error/333092)

<div class="topic-metadata">

**Author:** [@sankrithi43](https://discuss.elastic.co/u/sankrithi43)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 8:38am UTC](https://discuss.elastic.co/t/logstash-multiple-indexs-using-same-ilm-and-index-template-and-alias-error/333092 "2023-05-11T08:38:49Z")

</div>

Hi , below is my task to setup and struggling with ILM issue and looking forward if any help here. i setup and configured filebeat and logstash on kubernetes cluster successfully. since we had multiple application…

---

## [Elasticsearch high latency](https://discuss.elastic.co/t/elasticsearch-high-latency/328911)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 15\
**Last updated:** [May 11, 2023, 7:49am UTC](https://discuss.elastic.co/t/elasticsearch-high-latency/328911 "2023-05-11T07:49:47Z")

</div>

Hi all, We noticed some high request latency for searches on our elasticsearch cluster(7.17) and while checking the metrics, it was seen that there was spike in search\_fetch\_time for many indices which were configured 1…

---

## [Can we use kibana without ES?](https://discuss.elastic.co/t/can-we-use-kibana-without-es/333151)

<div class="topic-metadata">

**Author:** [@j\_lim](https://discuss.elastic.co/u/j_lim)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 6:53am UTC](https://discuss.elastic.co/t/can-we-use-kibana-without-es/333151 "2023-05-11T06:53:57Z")

</div>

is there any way use Kibana without ES?

---

## [Curriculum Vitae using ES](https://discuss.elastic.co/t/curriculum-vitae-using-es/333108)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 6:15am UTC](https://discuss.elastic.co/t/curriculum-vitae-using-es/333108 "2023-05-11T06:15:57Z")

</div>

Good morning, I would like use elastic to search in CV perfect matchings and I have this question. Is it possible that with the text of CV get a list of tags? Like a tag cloud. My idea is get this tags and simply sav…

---

## [Fetching filtered and unfiltered count in a single request](https://discuss.elastic.co/t/fetching-filtered-and-unfiltered-count-in-a-single-request/333160)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 6:11am UTC](https://discuss.elastic.co/t/fetching-filtered-and-unfiltered-count-in-a-single-request/333160 "2023-05-11T06:11:51Z")

</div>

Hi, I have a use case where a user\_id has multiple records in Elasticsearch. I'm using a bool query on user\_id and additional filters on top of it. I'm able to fetch the count of filtered records using track\_total\_hits…

---

## [Timestamp attribute mapping as text(this existing mapping not working for newly created indices )](https://discuss.elastic.co/t/timestamp-attribute-mapping-as-text-this-existing-mapping-not-working-for-newly-created-indices/333156)

<div class="topic-metadata">

**Author:** [@Dnyaneshwar\_Chavan](https://discuss.elastic.co/u/Dnyaneshwar_Chavan)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 5:46am UTC](https://discuss.elastic.co/t/timestamp-attribute-mapping-as-text-this-existing-mapping-not-working-for-newly-created-indices/333156 "2023-05-11T05:46:36Z")

</div>

I am using dynamic indices creation with template { "base\_index\_dev" : { "order" : 0, "index\_patterns" : \[ "dev\_shipments", "dev\_shipment\_legs\_", "dev\_transport\_orders\_\*" \], "settings" : { "index" : { "default…

---

## [Can we filter multiple values using kibanaAddFilter in Vega](https://discuss.elastic.co/t/can-we-filter-multiple-values-using-kibanaaddfilter-in-vega/332398)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 7\
**Last updated:** [May 11, 2023, 6:05am UTC](https://discuss.elastic.co/t/can-we-filter-multiple-values-using-kibanaaddfilter-in-vega/332398 "2023-05-11T06:05:27Z")

</div>

Hello @everyone, I am using Vega to create my Visualization. I want to put kibanaAddFilter so that on click it filter out a field's multiple selected values. Like a field XYZ contains values( a,b,c,d,e,f,g). The filter…

---

## [Logstash jdbc Illegal instant due to time zone offset transition (daylight savings time 'gap'): 1979-03-21](https://discuss.elastic.co/t/logstash-jdbc-illegal-instant-due-to-time-zone-offset-transition-daylight-savings-time-gap-1979-03-21/332902)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 5:59am UTC](https://discuss.elastic.co/t/logstash-jdbc-illegal-instant-due-to-time-zone-offset-transition-daylight-savings-time-gap-1979-03-21/332902 "2023-05-11T05:59:11Z")

</div>

Hi Here is the logstash jdbc input config: Logstash conf: input { jdbc { jdbc\_driver\_library =\> "/opt/jdbc/ifxjdbc.jar" jdbc\_driver\_class =\> "com.informix.jdbc.IfxDriver" jdbc\_connection\_string =\> "jdbc:…

---

## [ pipeline/output.go:180  failed to publish events: client is not connected](https://discuss.elastic.co/t/pipeline-output-go-180-failed-to-publish-events-client-is-not-connected/333154)

<div class="topic-metadata">

**Author:** [@sandhya\_131](https://discuss.elastic.co/u/sandhya_131)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 5:40am UTC](https://discuss.elastic.co/t/pipeline-output-go-180-failed-to-publish-events-client-is-not-connected/333154 "2023-05-11T05:40:59Z")

</div>

Hello Everyone, I have ELK setup in kubernetes 1.23 cluster, I have filebeat in one namespace in the cluster as daemonset. For the master nodes we have filebeat deployed on the nodes while building the ami. Earlier we h…

---

## [Custom dotproduct with long type field value](https://discuss.elastic.co/t/custom-dotproduct-with-long-type-field-value/333150)

<div class="topic-metadata">

**Author:** [@Akhilendra](https://discuss.elastic.co/u/Akhilendra)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 5:07am UTC](https://discuss.elastic.co/t/custom-dotproduct-with-long-type-field-value/333150 "2023-05-11T05:07:05Z")

</div>

An array long type field in document geting automatically sorted when calculating dotproduct via custom painless script. Index Mapping PUT /custom\_dot\_product { "settings": { "number\_of\_shards": 1, "number\_o…

---

## [How to apply Kubernetes metrics without adding the Elastic agent to Fleet?](https://discuss.elastic.co/t/how-to-apply-kubernetes-metrics-without-adding-the-elastic-agent-to-fleet/333116)

<div class="topic-metadata">

**Author:** [@dbstjdghks25](https://discuss.elastic.co/u/dbstjdghks25)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-apply-kubernetes-metrics-without-adding-the-elastic-agent-to-fleet/333116 "2023-05-11T04:42:57Z")

</div>

I want to monitor Kubernetes by adding kubernetes-metricbeat to an existing agent, but when I apply the following YAML file, the agent is additionally registered with Fleet. How can I configure the YAML file to avoid thi…

---

## [Split large json file](https://discuss.elastic.co/t/split-large-json-file/333145)

<div class="topic-metadata">

**Author:** [@sree3](https://discuss.elastic.co/u/sree3)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 4:09am UTC](https://discuss.elastic.co/t/split-large-json-file/333145 "2023-05-11T04:09:14Z")

</div>

Hi All, Trying to split a single json file into multiple one's and then to output those single files Could someone please help to get this done Input Data is json file { "Computer": "node2", "ContainerID": "cbcf", …

---

## [Displaying realtime video on Kibana](https://discuss.elastic.co/t/displaying-realtime-video-on-kibana/333055)

<div class="topic-metadata">

**Author:** [@huynv1407](https://discuss.elastic.co/u/huynv1407)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 3:13am UTC](https://discuss.elastic.co/t/displaying-realtime-video-on-kibana/333055 "2023-05-11T03:13:15Z")

</div>

I wants to know if displaying realtime video on kibana is possible or not. How can I do that?.

---

## [Can filebeat recognize .gz log files?](https://discuss.elastic.co/t/can-filebeat-recognize-gz-log-files/332961)

<div class="topic-metadata">

**Author:** [@talka](https://discuss.elastic.co/u/talka)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 2:49am UTC](https://discuss.elastic.co/t/can-filebeat-recognize-gz-log-files/332961 "2023-05-11T02:49:18Z")

</div>

Hi, I'm using filebeat version 8.7.0. /var/log list the following files: -rwxrwxrwx 1 1000 1000 244631 Mar 21 06:30 cron -rwxrwxrwx 1 1000 1000 48940 Feb 26 03:37 cron-20230226.gz -rwxrwxrwx 1 1000 1000 48766 Mar …

---

## [My lifecycle policy is not working](https://discuss.elastic.co/t/my-lifecycle-policy-is-not-working/332856)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 10\
**Last updated:** [May 11, 2023, 2:09am UTC](https://discuss.elastic.co/t/my-lifecycle-policy-is-not-working/332856 "2023-05-11T02:09:47Z")

</div>

I want to automatically delete indexes that are 60 days old and have set up the following lifecycle policy. # curl -XGET '\_ilm/policy/its\_index-policy?pretty' { "its\_index-policy" : { "version" : 1, "modified\_…

---

## [How to extract custom field value from first line and add it into later lines with Filebeat](https://discuss.elastic.co/t/how-to-extract-custom-field-value-from-first-line-and-add-it-into-later-lines-with-filebeat/333140)

<div class="topic-metadata">

**Author:** [@lma\_yb](https://discuss.elastic.co/u/lma_yb)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 1:21am UTC](https://discuss.elastic.co/t/how-to-extract-custom-field-value-from-first-line-and-add-it-into-later-lines-with-filebeat/333140 "2023-05-11T01:21:27Z")

</div>

I am using filebeat to import log file which has some meta data in the first few lines into ELK. The log file format looks like this: Hostname: xxx Created: \<time\> Format: XXX ----Actual logs--- I want to extract the …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=545)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=547)
