# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=548

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 549

---

## [Can I do a sum on the fields that have 'keyword' type](https://discuss.elastic.co/t/can-i-do-a-sum-on-the-fields-that-have-keyword-type/333076)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 11:06am UTC](https://discuss.elastic.co/t/can-i-do-a-sum-on-the-fields-that-have-keyword-type/333076 "2023-05-10T11:06:31Z")

</div>

I have a field that is keyword type. The index looks like this: { "key": 1 }, { "key": 2 }, { "key": 3 }, { "key":"abc" }, { "key":"zyx" } Some values are numeric and some are strings. Is there a way to …

---

## [Gather logs from podman containers](https://discuss.elastic.co/t/gather-logs-from-podman-containers/333073)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 10:44am UTC](https://discuss.elastic.co/t/gather-logs-from-podman-containers/333073 "2023-05-10T10:44:40Z")

</div>

Hi, If I understand the documentation correctly the best practice for shipping logs of docker-container is the following: using container input - type: container stream: stdout paths: - "/var/log/containers/\*.…

---

## [Check performance of cluster](https://discuss.elastic.co/t/check-performance-of-cluster/332996)

<div class="topic-metadata">

**Author:** [@NNI](https://discuss.elastic.co/u/NNI)\
**Replies:** 11\
**Last updated:** [May 10, 2023, 9:56am UTC](https://discuss.elastic.co/t/check-performance-of-cluster/332996 "2023-05-10T09:56:45Z")

</div>

Hi We're facing some performance issue cluster build on 9 nodes 3x ingest 3x master 3x data (on NVMe disks) index\_with\_data 2 r STARTED 10590253 elk\_es\_data-1 index\_with\_data 2 p …

---

## [Install and run Logstash tar file](https://discuss.elastic.co/t/install-and-run-logstash-tar-file/332899)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 9:56am UTC](https://discuss.elastic.co/t/install-and-run-logstash-tar-file/332899 "2023-05-10T09:56:13Z")

</div>

Hi, Good day! Does anyone know how to install and run logstash in a tar format binary? Thank you! Best regards, Hasmine Joyce Roldan

---

## [JDBC plugin - issue getting binary data](https://discuss.elastic.co/t/jdbc-plugin-issue-getting-binary-data/332537)

<div class="topic-metadata">

**Author:** [@vymk](https://discuss.elastic.co/u/vymk)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:25am UTC](https://discuss.elastic.co/t/jdbc-plugin-issue-getting-binary-data/332537 "2023-05-10T09:25:26Z")

</div>

I use the JDBC plugin to get data from a MSSQL database. Generally this is working but my query output includes MD5 hashes saved as binary, and then the output looks something like this in stdout (and even more gibberish…

---

## [LEAD/LAG window function in elasticsearch](https://discuss.elastic.co/t/lead-lag-window-function-in-elasticsearch/332866)

<div class="topic-metadata">

**Author:** [@Sanjana\_Saswade](https://discuss.elastic.co/u/Sanjana_Saswade)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 2:47pm UTC](https://discuss.elastic.co/t/lead-lag-window-function-in-elasticsearch/332866 "2023-05-09T14:47:33Z")

</div>

I need to use LEAD /LAG function in elasticsearch. i tried collapse in ELK but it's not working. How do I fix this? sql query for convert in Elasticsearch query: select name, LAG(salary) OVER(PARTITION BY department …

---

## [Grok debugger works, on logstash not](https://discuss.elastic.co/t/grok-debugger-works-on-logstash-not/332930)

<div class="topic-metadata">

**Author:** [@psyskeletor](https://discuss.elastic.co/u/psyskeletor)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 8:23am UTC](https://discuss.elastic.co/t/grok-debugger-works-on-logstash-not/332930 "2023-05-10T08:23:54Z")

</div>

Hi there. Super new to logstash. I wanted to extract exit code from logs, so i came with this solution using grok debugger filter { grok { match =\> { "message" =\> "(?\<exit\_code\>\\b\[exit code \]\\d+ \\b)" } …

---

## [Aggregating unique (timestamp) values](https://discuss.elastic.co/t/aggregating-unique-timestamp-values/333043)

<div class="topic-metadata">

**Author:** [@idrv](https://discuss.elastic.co/u/idrv)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:13am UTC](https://discuss.elastic.co/t/aggregating-unique-timestamp-values/333043 "2023-05-10T08:13:27Z")

</div>

Hello, community! I hope my question doesn't double something already asked and answered here. I'm searching for the best way to store aggregated data in a dedicated index. In the best-case scenario, it should include …

---

## [What are the best ways to find near phrases? How to combine them to find near to nearest near? ))](https://discuss.elastic.co/t/what-are-the-best-ways-to-find-near-phrases-how-to-combine-them-to-find-near-to-nearest-near/333042)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:11am UTC](https://discuss.elastic.co/t/what-are-the-best-ways-to-find-near-phrases-how-to-combine-them-to-find-near-to-nearest-near/333042 "2023-05-10T08:11:59Z")

</div>

How to find nearest near. Example: "query" : { "query\_string": { "query": "\\"field korean\\"~10", "fields" : \["message.stemmed"\], "default\_operator": "AND" } It finds all strings that contain …

---

## [Remove all backslash from fields in logstash](https://discuss.elastic.co/t/remove-all-backslash-from-fields-in-logstash/333041)

<div class="topic-metadata">

**Author:** [@SmoZyNS](https://discuss.elastic.co/u/SmoZyNS)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:08am UTC](https://discuss.elastic.co/t/remove-all-backslash-from-fields-in-logstash/333041 "2023-05-10T08:08:08Z")

</div>

Hello, what I am trying to do is to remove backslash as well as double quotes from fields after parsing them with kv. Here is the original input sent to logstash: \<14\>1 2023-05-09T15:06:23+02:00 NAS WinFileService - -…

---

## [Can not access json.orig\_bytes and json.resp\_bytes in filebeat zeek's module](https://discuss.elastic.co/t/can-not-access-json-orig-bytes-and-json-resp-bytes-in-filebeat-zeeks-module/333029)

<div class="topic-metadata">

**Author:** [@pakban3242](https://discuss.elastic.co/u/pakban3242)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 7:05am UTC](https://discuss.elastic.co/t/can-not-access-json-orig-bytes-and-json-resp-bytes-in-filebeat-zeeks-module/333029 "2023-05-10T07:05:00Z")

</div>

Hi , i want to bring zeek logs to Elasticsearch , but this two modules are not included json.orig\_bytes","json.resp\_bytes i have changed this file /usr/share/filebeat/module/zeek/connection/config/connection.yml and …

---

## [Issue with logsatsh](https://discuss.elastic.co/t/issue-with-logsatsh/330227)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 38\
**Last updated:** [May 10, 2023, 6:34am UTC](https://discuss.elastic.co/t/issue-with-logsatsh/330227 "2023-05-10T06:34:23Z")

</div>

Hello, I am currently working on a subject. I am trying to parse my data in JSON format to store it in Elasticsearch, but Logstash is unable to parse my data and is generating errors. Can you help me?

---

## [Conditionally change row colour in EuiInMemoryTable](https://discuss.elastic.co/t/conditionally-change-row-colour-in-euiinmemorytable/332515)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 5:24am UTC](https://discuss.elastic.co/t/conditionally-change-row-colour-in-euiinmemorytable/332515 "2023-05-10T05:24:44Z")

</div>

Hi, How can I conditionally change the row colour in EuiInMemoryTable ? I have a column, say health. I want to change the entire row colour based on the value in the health column (of the corresponding row). Health -\> …

---

## [Mapping conflict between two indexes of different versions of metricbeat](https://discuss.elastic.co/t/mapping-conflict-between-two-indexes-of-different-versions-of-metricbeat/333010)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 7\
**Last updated:** [May 10, 2023, 5:19am UTC](https://discuss.elastic.co/t/mapping-conflict-between-two-indexes-of-different-versions-of-metricbeat/333010 "2023-05-10T05:19:15Z")

</div>

Hi, I have two metricbeats with diferent versions pointing to the same elasticsearch, the difference between their mapping is causing me problems when I try to use the control visualization in kibana. if i choose to u…

---

## [How to change timezone on painless script](https://discuss.elastic.co/t/how-to-change-timezone-on-painless-script/332871)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 3:30am UTC](https://discuss.elastic.co/t/how-to-change-timezone-on-painless-script/332871 "2023-05-10T03:30:59Z")

</div>

Hello everyone, i want to ask something about painless script. so i just made a painless script that look like this: but unfortunately the result of this script is still in utc and i want to change it to another time…

---

## [Trace source of authentication failures from logs](https://discuss.elastic.co/t/trace-source-of-authentication-failures-from-logs/333005)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 12:40am UTC](https://discuss.elastic.co/t/trace-source-of-authentication-failures-from-logs/333005 "2023-05-10T00:40:13Z")

</div>

I am seeing this log repeated twice a minute on one of my ES servers: \[2023-05-10T00:11:33,186\]\[WARN \]\[o.e.x.s.a.RealmsAuthenticator\] \[secesprd02\] Authentication to realm default\_native failed - Password authentication …

---

## [Kibana custom plugin](https://discuss.elastic.co/t/kibana-custom-plugin/332603)

<div class="topic-metadata">

**Author:** [@rodrigo\_Ceron](https://discuss.elastic.co/u/rodrigo_Ceron)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 10:35pm UTC](https://discuss.elastic.co/t/kibana-custom-plugin/332603 "2023-05-09T22:35:01Z")

</div>

Hi everyone, I'm developing a customplugin however I have a question. Is it possible to give privileges to a user so they can access only this plugin?

---

## [Restoring snapshot from one cluster to brand new deployment](https://discuss.elastic.co/t/restoring-snapshot-from-one-cluster-to-brand-new-deployment/332844)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 10:29pm UTC](https://discuss.elastic.co/t/restoring-snapshot-from-one-cluster-to-brand-new-deployment/332844 "2023-05-09T22:29:18Z")

</div>

Hello, I am using the Clastic cloud services and I was going through a practice exercise of restoring snapshot from one deployment to brand new deployment in case of any disaster. The GUi is straight forward, but I am …

---

## [Runtime field causes the error "A document doesn't have a field"](https://discuss.elastic.co/t/runtime-field-causes-the-error-a-document-doesnt-have-a-field/332848)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 8:34pm UTC](https://discuss.elastic.co/t/runtime-field-causes-the-error-a-document-doesnt-have-a-field/332848 "2023-05-09T20:34:35Z")

</div>

I'm trying to use a run time field but I keep getting the error: A document doesn't have a value for a field! Use doc\[\<field\>\].size()==0 to check if a document is missing a field! You can reproduce the issue by running…

---

## [Not Able To Install Elastic Agent Onto Windows 10](https://discuss.elastic.co/t/not-able-to-install-elastic-agent-onto-windows-10/332971)

<div class="topic-metadata">

**Author:** [@mx09](https://discuss.elastic.co/u/mx09)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 8:29pm UTC](https://discuss.elastic.co/t/not-able-to-install-elastic-agent-onto-windows-10/332971 "2023-05-09T20:29:52Z")

</div>

Error: unable to perform install command, not executed with Administrator permissions I've tried to add an Agent onto what will be my "Victim Machine" I'm doing this with the Kali Purple instance in a virtual environmen…

---

## [Field in MSSQL as ID and the use of versioning](https://discuss.elastic.co/t/field-in-mssql-as-id-and-the-use-of-versioning/332414)

<div class="topic-metadata">

**Author:** [@Ric1](https://discuss.elastic.co/u/Ric1)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 7:34pm UTC](https://discuss.elastic.co/t/field-in-mssql-as-id-and-the-use-of-versioning/332414 "2023-05-09T19:34:01Z")

</div>

Hello, I hope I've put this in the correct place. My scenario is: I have data accessible via the JDBC input on MSSQL. The JDBC input plugin runs a command to find records that match a certain query. The output is an …

---

## [Form data in body for Logstash HTTP filter](https://discuss.elastic.co/t/form-data-in-body-for-logstash-http-filter/332574)

<div class="topic-metadata">

**Author:** [@analog\_memories](https://discuss.elastic.co/u/analog_memories)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 7:18pm UTC](https://discuss.elastic.co/t/form-data-in-body-for-logstash-http-filter/332574 "2023-05-09T19:18:37Z")

</div>

Hello, I was wondering if anyone has had the syntax for using form data in the body of HTTP filter. I have tried all manor of ways to make it work, and searched the forums, but have not found anything. This post is pr…

---

## [Support for multiple named computed scores in a single search](https://discuss.elastic.co/t/support-for-multiple-named-computed-scores-in-a-single-search/332995)

<div class="topic-metadata">

**Author:** [@Krum\_Bakalsky](https://discuss.elastic.co/u/Krum_Bakalsky)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 7:05pm UTC](https://discuss.elastic.co/t/support-for-multiple-named-computed-scores-in-a-single-search/332995 "2023-05-09T19:05:38Z")

</div>

Hello Elasticsearch community, When serving a given search query, our service is computing and using proximity score for each document in our index relative to the given query. This we currently implement by invoking th…

---

## [Getting ENOSPC error when using file output plugin in Logstash](https://discuss.elastic.co/t/getting-enospc-error-when-using-file-output-plugin-in-logstash/332985)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 6:26pm UTC](https://discuss.elastic.co/t/getting-enospc-error-when-using-file-output-plugin-in-logstash/332985 "2023-05-09T18:26:39Z")

</div>

Hi Team, I have the following logstash pipeline config. input { tcp { port =\> "${TCP\_PORT}" codec =\> line } } filter { grok { match =\> {"message" =\> "%{SYSLOGTIMESTAMP:time} %{DATA:s…

---

## [Manage several data stream(s) in the elasitcsearch output with interpolation](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981)

<div class="topic-metadata">

**Author:** [@Pascal\_Nuccio](https://discuss.elastic.co/u/Pascal_Nuccio)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 6:23pm UTC](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981 "2023-05-09T18:23:51Z")

</div>

If you need to manage several data streams for one LOGSTASH instance, you can configure the elasticsearch output like this in your logstash configuration: We must use a filter to configure the data\_stream parameters (ty…

---

## [Using a modal to display Elastic Search-UI results, but there is a weird lag where only part of the original search term is searched](https://discuss.elastic.co/t/using-a-modal-to-display-elastic-search-ui-results-but-there-is-a-weird-lag-where-only-part-of-the-original-search-term-is-searched/332973)

<div class="topic-metadata">

**Author:** [@Jonah\_Cornish\_Packer](https://discuss.elastic.co/u/Jonah_Cornish_Packer)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 5:33pm UTC](https://discuss.elastic.co/t/using-a-modal-to-display-elastic-search-ui-results-but-there-is-a-weird-lag-where-only-part-of-the-original-search-term-is-searched/332973 "2023-05-09T17:33:12Z")

</div>

I have implemented Elastic's Search-UI on my website, where the user can enter their search term on the parent page and when they submit their search the results show up in a modal. The modal displays the search results …

---

## [Error Installing Fleet Server Agent on Centralized Host](https://discuss.elastic.co/t/error-installing-fleet-server-agent-on-centralized-host/332310)

<div class="topic-metadata">

**Author:** [@gmosornoza](https://discuss.elastic.co/u/gmosornoza)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 4:55pm UTC](https://discuss.elastic.co/t/error-installing-fleet-server-agent-on-centralized-host/332310 "2023-05-09T16:55:03Z")

</div>

Hi! I'm facing an issue when installing Fleet Server as centralized host. I' running this command sudo ./elastic-agent install \\ --fleet-server-es=https://XXX.XXX.XXX.XXX:9200 \\ --fleet-server-service-token=my\_tok…

---

## [Use new metric like legacy with Last value function on keyword field](https://discuss.elastic.co/t/use-new-metric-like-legacy-with-last-value-function-on-keyword-field/332927)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 3:31pm UTC](https://discuss.elastic.co/t/use-new-metric-like-legacy-with-last-value-function-on-keyword-field/332927 "2023-05-09T15:31:48Z")

</div>

Hello, i create one index per month, which are grouped in a data view. There is a keyword field in the index which contains a string representation of the month that the index was created like 'May 2023'. Up until now …

---

## [List all runtime fields in index pattern?](https://discuss.elastic.co/t/list-all-runtime-fields-in-index-pattern/332908)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 3:28pm UTC](https://discuss.elastic.co/t/list-all-runtime-fields-in-index-pattern/332908 "2023-05-09T15:28:57Z")

</div>

Hello, sadly it seems Are runtime multi-fields possible? is not possible, so my question for today is: Is it possible to list all runtime fields for an index pattern in Kibana? I know I can dump the mapping for each i…

---

## [Vega: Signal resets to initial value after refreshing the dashboard (revisit)](https://discuss.elastic.co/t/vega-signal-resets-to-initial-value-after-refreshing-the-dashboard-revisit/332963)

<div class="topic-metadata">

**Author:** [@edgarmat1964](https://discuss.elastic.co/u/edgarmat1964)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 3:15pm UTC](https://discuss.elastic.co/t/vega-signal-resets-to-initial-value-after-refreshing-the-dashboard-revisit/332963 "2023-05-09T15:15:36Z")

</div>

LS, when is this https://discuss.elastic.co/t/vega-signal-resets-to-initial-value-after-refreshing-the-dashboard/138263 issue going to be solved? I'm running into this issue. Elasticsearch 7.17.9 Kibana 7.17.9 Rock…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=547)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=549)
