# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=550

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 551

---

## ["The processor action grok does not exist" in FileBeat. Why ? (Custom Logs Integration)](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 3\
**Last updated:** [May 8, 2023, 4:00pm UTC](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756 "2023-05-08T16:00:17Z")

</div>

I am a bit confused here. Grok is available in Ingest Processors but not in Filebeat processors May I ask why ? :thinking: I was hoping to do this , but it breaks, as I am getting the following error : \[elastic\_a…

---

## [Elastic Agent excessive cpu / log output in kubernetes](https://discuss.elastic.co/t/elastic-agent-excessive-cpu-log-output-in-kubernetes/330554)

<div class="topic-metadata">

**Author:** [@jlucas](https://discuss.elastic.co/u/jlucas)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 3:24pm UTC](https://discuss.elastic.co/t/elastic-agent-excessive-cpu-log-output-in-kubernetes/330554 "2023-05-08T15:24:23Z")

</div>

Hello, I am noticing some undesirable behavior when using elastic agent within kubernetes on-prem. I have a fleet managed elastic agent running in kubernetes with APM, System, and Kubernetes integrations turned on. I wa…

---

## [Watcher configurtion](https://discuss.elastic.co/t/watcher-configurtion/332827)

<div class="topic-metadata">

**Author:** [@prithvi](https://discuss.elastic.co/u/prithvi)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 2:34pm UTC](https://discuss.elastic.co/t/watcher-configurtion/332827 "2023-05-08T14:34:00Z")

</div>

Hi, Let me explain my architecture here, we have 3 master nodes and 10 data nodes. We need to configure watcher to trigger email alert. challenge here it is very secured environment. anyone pleas ehelp me to configure t…

---

## [Is the dot product score calculation for the vector of byte element\_type correct? I think it is a bug](https://discuss.elastic.co/t/is-the-dot-product-score-calculation-for-the-vector-of-byte-element-type-correct-i-think-it-is-a-bug/331033)

<div class="topic-metadata">

**Author:** [@wangyanbin](https://discuss.elastic.co/u/wangyanbin)\
**Replies:** 6\
**Last updated:** [May 8, 2023, 1:58pm UTC](https://discuss.elastic.co/t/is-the-dot-product-score-calculation-for-the-vector-of-byte-element-type-correct-i-think-it-is-a-bug/331033 "2023-05-08T13:58:10Z")

</div>

I found the dot product score calculation for the vector of byte element\_type is wrong: 0.5 + (dot\_product(query, vector) / (32768 \* dims)) which is same as : 0.5 + (dot\_product(query, vector) / (128\*128\*2\* dims)) ref…

---

## [Active Directory perfmon counter in metricbeat](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 1:42pm UTC](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537 "2023-05-08T13:42:51Z")

</div>

Hi! I have two questions about Active Directory perfmon counters. I´ve created some counters based on this article: And in this article I have seen then that this syntax no longer exists: Now I'm not sure how to …

---

## [Search for an exact Date, ignoring the time\_zone](https://discuss.elastic.co/t/search-for-an-exact-date-ignoring-the-time-zone/332716)

<div class="topic-metadata">

**Author:** [@wil93](https://discuss.elastic.co/u/wil93)\
**Replies:** 5\
**Last updated:** [May 8, 2023, 12:47pm UTC](https://discuss.elastic.co/t/search-for-an-exact-date-ignoring-the-time-zone/332716 "2023-05-08T12:47:16Z")

</div>

Given the following document: PUT /examples/\_doc/1 { "item": "Phone X", "price": 799, "lastUpdateDate" : "2023-05-01T01:00:00+02:00" } No explicit 'Mapping' for index 'examples' is provided (Elasticsearch will t…

---

## [Error when importing my custom dashboard through kibana UI with metricbeat](https://discuss.elastic.co/t/error-when-importing-my-custom-dashboard-through-kibana-ui-with-metricbeat/332421)

<div class="topic-metadata">

**Author:** [@\_Zeyad\_Elshater](https://discuss.elastic.co/u/_Zeyad_Elshater)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 12:45pm UTC](https://discuss.elastic.co/t/error-when-importing-my-custom-dashboard-through-kibana-ui-with-metricbeat/332421 "2023-05-08T12:45:56Z")

</div>

I'm new to ELK , I have custom ndjson file that I imported through the kibana UI , I have some errors like "The field "nuix\_running\_worker" associated with this object no longer exists in the data view. Please use anothe…

---

## [Harvester for file is still running](https://discuss.elastic.co/t/harvester-for-file-is-still-running/332813)

<div class="topic-metadata">

**Author:** [@AndersBolager](https://discuss.elastic.co/u/AndersBolager)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 12:09pm UTC](https://discuss.elastic.co/t/harvester-for-file-is-still-running/332813 "2023-05-08T12:09:13Z")

</div>

Hi. On one of my servers, after working for a few weeks, the following loglines are repeated, and nothing ends up on the elasticstack server: {"log.level":"debug","@timestamp":"2023-05-08T13:53:56.309+0200","log.logger…

---

## [Formatted time string with nanoseconds is not converted to nanosecond timestamp value when sorting on \_search queries](https://discuss.elastic.co/t/formatted-time-string-with-nanoseconds-is-not-converted-to-nanosecond-timestamp-value-when-sorting-on-search-queries/330046)

<div class="topic-metadata">

**Author:** [@jsun-m](https://discuss.elastic.co/u/jsun-m)\
**Replies:** 5\
**Last updated:** [May 8, 2023, 12:04pm UTC](https://discuss.elastic.co/t/formatted-time-string-with-nanoseconds-is-not-converted-to-nanosecond-timestamp-value-when-sorting-on-search-queries/330046 "2023-05-08T12:04:27Z")

</div>

Query: return { "sort": \[ { "time": "desc" }, \], "\_source": \["@timestamp", "message", "time"\], "runtime\_mappings": { "date\_has\_nanos": …

---

## [Elastic Agent Ouput to Logstash](https://discuss.elastic.co/t/elastic-agent-ouput-to-logstash/329809)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 11:56am UTC](https://discuss.elastic.co/t/elastic-agent-ouput-to-logstash/329809 "2023-05-08T11:56:51Z")

</div>

Hi, I'm trying to send the data from fleet to Logstash using agent policy which i configured by following below article. But when choose the output from dropdown, options are greyed out as shown figure. Please be no…

---

## [Elastic-agent to logstash mapper\_parsing\_exception with windows system integration](https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 11:54am UTC](https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300 "2023-05-08T11:54:11Z")

</div>

Hi, I am trying to send windows events via an elastic-agent (8.6.0) (with fleet in 8.6.0) to logstash (8.6.0). the eleastic-agent is configured with an agent policy that has a system integration configured as follows: …

---

## [Elasticsearch upgrade](https://discuss.elastic.co/t/elasticsearch-upgrade/332805)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Dabrowski](https://discuss.elastic.co/u/Krzysztof_Dabrowski)\
**Replies:** 4\
**Last updated:** [May 8, 2023, 11:44am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade/332805 "2023-05-08T11:44:10Z")

</div>

Hey. I wanted to upgrade elasticsearch from 7.16 to 8.7. First I upgraded ES to 7.17 but I didn't restarted the service and immediately upgraded to 8.7. Now Elasticsearch wont start due to error: cannot upgrade a node f…

---

## [Error: invalid connection string: must include a username unless a service token is provided](https://discuss.elastic.co/t/error-invalid-connection-string-must-include-a-username-unless-a-service-token-is-provided/332668)

<div class="topic-metadata">

**Author:** [@osdacita](https://discuss.elastic.co/u/osdacita)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 11:33am UTC](https://discuss.elastic.co/t/error-invalid-connection-string-must-include-a-username-unless-a-service-token-is-provided/332668 "2023-05-08T11:33:58Z")

</div>

I'm trying to enroll a host using the fleet to properly use EndPoint Security, but trying directly causes problems so I resorted to the following commands: .\\elastic-agent enroll --fleet-server-es=https://:443 --flee…

---

## [Elasticsearch 7.10.2 backup](https://discuss.elastic.co/t/elasticsearch-7-10-2-backup/332642)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 20\
**Last updated:** [May 8, 2023, 11:21am UTC](https://discuss.elastic.co/t/elasticsearch-7-10-2-backup/332642 "2023-05-08T11:21:52Z")

</div>

Hi everyone My name is José Manuel and I am trying to make a back from elasticsearch 7.10.2, but show me the next error # curl -X PUT localhost:9200/\_snapshot/my\_backup?pretty -H 'Content-Type: application/json' -d '{…

---

## [Using Dashboard Control to Filter Data Views](https://discuss.elastic.co/t/using-dashboard-control-to-filter-data-views/332771)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 10:36am UTC](https://discuss.elastic.co/t/using-dashboard-control-to-filter-data-views/332771 "2023-05-08T10:36:37Z")

</div>

I am attempting to make a dashboard control that has a list of data views (index patterns). Each of the associated indices contain a different category of computer assets by role. The end goal is that the dashboard user …

---

## [Logstash file input](https://discuss.elastic.co/t/logstash-file-input/332802)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 10:00am UTC](https://discuss.elastic.co/t/logstash-file-input/332802 "2023-05-08T10:00:15Z")

</div>

Hi Team, Need some advice regarding configuration options for file input. If we have multiple patterns for files to watch for, what are pros and cons for below options Configuring each file path pattern as a dedicated…

---

## [Alias creation](https://discuss.elastic.co/t/alias-creation/332273)

<div class="topic-metadata">

**Author:** [@sebinnsebastiann](https://discuss.elastic.co/u/sebinnsebastiann)\
**Replies:** 4\
**Last updated:** [May 8, 2023, 8:55am UTC](https://discuss.elastic.co/t/alias-creation/332273 "2023-05-08T08:55:08Z")

</div>

I deployed efk-8.7.0 using kubernetes. elasticsearch: docker.elastic.co/elasticsearch/elasticsearch:8.7.0 kibana: docker.elastic.co/kibana/kibana:8.7.0 fluentbit: fluent/fluent-bit:2.1.1 Everyday logs are created …

---

## [Extracting unique labels in the field and wordcount](https://discuss.elastic.co/t/extracting-unique-labels-in-the-field-and-wordcount/332567)

<div class="topic-metadata">

**Author:** [@Rama\_Krishna2](https://discuss.elastic.co/u/Rama_Krishna2)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 7:44am UTC](https://discuss.elastic.co/t/extracting-unique-labels-in-the-field-and-wordcount/332567 "2023-05-08T07:44:00Z")

</div>

Hello all, I have some data stored in Elastic Search Kibana 7.17.3 for one year time period, and I want to analyze a specific field to see how many unique labels it has and how many times each label was mentioned on a d…

---

## [Nested document or separate index](https://discuss.elastic.co/t/nested-document-or-separate-index/331011)

<div class="topic-metadata">

**Author:** [@Rishabh\_Jain1](https://discuss.elastic.co/u/Rishabh_Jain1)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 6:23am UTC](https://discuss.elastic.co/t/nested-document-or-separate-index/331011 "2023-05-08T06:23:10Z")

</div>

Hi I want to use elasticsearch in our company. The usage is as following: We have million of influencers and each influencers have 1000s of posts just like instagram. I have 2 use cases: Search among these posts and …

---

## [ES hadoop spark connector having a issue with nested json](https://discuss.elastic.co/t/es-hadoop-spark-connector-having-a-issue-with-nested-json/332551)

<div class="topic-metadata">

**Author:** [@Kuldeep\_Pal](https://discuss.elastic.co/u/Kuldeep_Pal)\
**Replies:** 3\
**Last updated:** [May 4, 2023, 3:52pm UTC](https://discuss.elastic.co/t/es-hadoop-spark-connector-having-a-issue-with-nested-json/332551 "2023-05-04T15:52:26Z")

</div>

org.elasticsearch.hadoop.rest.EsHadoopParsingException: org.elasticsearch.hadoop.EsHadoopIllegalStateException: Position for 'contacts.phone' not found in row; typically this is caused by a mapping inconsistency Not abl…

---

## [Problems connecting to ES from Databricks using spark connector](https://discuss.elastic.co/t/problems-connecting-to-es-from-databricks-using-spark-connector/332411)

<div class="topic-metadata">

**Author:** [@lhfo](https://discuss.elastic.co/u/lhfo)\
**Replies:** 2\
**Last updated:** [May 5, 2023, 8:52am UTC](https://discuss.elastic.co/t/problems-connecting-to-es-from-databricks-using-spark-connector/332411 "2023-05-05T08:52:52Z")

</div>

Hi all, I am trying to connect with ES from our Databricks cluster. I have successfully installed elasticsearch-spark-30\_2.12:8.4.3 on the cluster and confirmed that the elastic version == 8.3.4. I am able to query d…

---

## [How to change the cluster name of an elk cluster with 3 master nodes](https://discuss.elastic.co/t/how-to-change-the-cluster-name-of-an-elk-cluster-with-3-master-nodes/332564)

<div class="topic-metadata">

**Author:** [@coy\_aprieto](https://discuss.elastic.co/u/coy_aprieto)\
**Replies:** 3\
**Last updated:** [May 5, 2023, 9:51am UTC](https://discuss.elastic.co/t/how-to-change-the-cluster-name-of-an-elk-cluster-with-3-master-nodes/332564 "2023-05-05T09:51:33Z")

</div>

Hi, I'm trying to find a way to change the cluster name of my whole elk cluster (7 data nodes, 3 master). If i change the cluster name in config and restart a non-current-master node, it will fail to rejoin cluster aft…

---

## [Convert text field to date in ingest pipeline](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595)

<div class="topic-metadata">

**Author:** [@KentLee](https://discuss.elastic.co/u/KentLee)\
**Replies:** 2\
**Last updated:** [May 5, 2023, 12:59pm UTC](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595 "2023-05-05T12:59:25Z")

</div>

Hi, I am creating a ingest pipeline to ingest application log to elastic and I have the log line format as follow: \[2023-05-03 16:12:19,420\] - \[Application Name\] - \[INFO\] - Log details goes here Based on this format I…

---

## [Elasticsearch IndexLifecycleRunner part of source code, log level Setting is not appropriate?](https://discuss.elastic.co/t/elasticsearch-indexlifecyclerunner-part-of-source-code-log-level-setting-is-not-appropriate/332542)

<div class="topic-metadata">

**Author:** [@yujie\_wang](https://discuss.elastic.co/u/yujie_wang)\
**Replies:** 1\
**Last updated:** [May 6, 2023, 2:37am UTC](https://discuss.elastic.co/t/elasticsearch-indexlifecyclerunner-part-of-source-code-log-level-setting-is-not-appropriate/332542 "2023-05-06T02:37:14Z")

</div>

Hi, Recently, I've been reading the source code of the latest version (8.7.1) of Elasticsearch and I have a question about the log level settings that I can't figure out. I noticed that the "current step \[{}\] for index…

---

## [No data received to server](https://discuss.elastic.co/t/no-data-received-to-server/332523)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 4\
**Last updated:** [May 8, 2023, 5:30am UTC](https://discuss.elastic.co/t/no-data-received-to-server/332523 "2023-05-08T05:30:21Z")

</div>

i have one agent with status healthy but didn't send any data to the elastic i got this problem after copying my windows machine \*extra note this agent use the agent before that already register

---

## [ExponentialDate function in new .Net client for v.8](https://discuss.elastic.co/t/exponentialdate-function-in-new-net-client-for-v-8/332704)

<div class="topic-metadata">

**Author:** [@Martin\_Hallonqvist](https://discuss.elastic.co/u/Martin_Hallonqvist)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 5:16am UTC](https://discuss.elastic.co/t/exponentialdate-function-in-new-net-client-for-v-8/332704 "2023-05-08T05:16:01Z")

</div>

I'm trying to migrate older .Net code using the NEST client to adopting the new Elastic.Clients.Elasticsearch .Net client but I'm having problem implementing the ExponentialDate function. In our prior solution, we had a…

---

## [ES agent doesn't feed "host.cpu.usage" metric when CPU loading 100%](https://discuss.elastic.co/t/es-agent-doesnt-feed-host-cpu-usage-metric-when-cpu-loading-100/332231)

<div class="topic-metadata">

**Author:** [@rickywong](https://discuss.elastic.co/u/rickywong)\
**Replies:** 5\
**Last updated:** [May 8, 2023, 4:00am UTC](https://discuss.elastic.co/t/es-agent-doesnt-feed-host-cpu-usage-metric-when-cpu-loading-100/332231 "2023-05-08T04:00:45Z")

</div>

Hi teams, Once my VM CPU loading is up to 100%, ES agent can't feed log to ES cloud. So the detection rules can't work as well. How to solve this problem? Thanks Ricky

---

## [Any logs to monitor ingest pipelines ? (Fleet + Custom Log Integration + Custom configurations)](https://discuss.elastic.co/t/any-logs-to-monitor-ingest-pipelines-fleet-custom-log-integration-custom-configurations/332761)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 3:35am UTC](https://discuss.elastic.co/t/any-logs-to-monitor-ingest-pipelines-fleet-custom-log-integration-custom-configurations/332761 "2023-05-08T03:35:48Z")

</div>

8.7 here I've configured a basic pipeline for fleet and elastic-agent using custom configuration (see below) when the pipeline fails documents are not inserted in the data stream. How to get some logs about how did th…

---

## [Elasticsearch cluster red state](https://discuss.elastic.co/t/elasticsearch-cluster-red-state/332722)

<div class="topic-metadata">

**Author:** [@mark\_twin75](https://discuss.elastic.co/u/mark_twin75)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 3:31am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-red-state/332722 "2023-05-08T03:31:46Z")

</div>

Hello all, I am trying to reset elastic user password , while resting password with bin/elasticsearch-reset-password -u elastic command ,my cluster status changed from yellow state to red state . all master nodes are …

---

## [Example of dot\_product similarity on dense\_vector field index document](https://discuss.elastic.co/t/example-of-dot-product-similarity-on-dense-vector-field-index-document/332396)

<div class="topic-metadata">

**Author:** [@adrian-arapiles](https://discuss.elastic.co/u/adrian-arapiles)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 3:22am UTC](https://discuss.elastic.co/t/example-of-dot-product-similarity-on-dense-vector-field-index-document/332396 "2023-05-08T03:22:32Z")

</div>

Hi, I'm trying to benchmark different possibilities with dense\_vector and knn search. I want to test cosine similarity vs dot\_produce similarity because in documentation says that dot\_product is a optimized way to perf…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=549)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=551)
