# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=553

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 554

---

## [Elasticsearch Query Error](https://discuss.elastic.co/t/elasticsearch-query-error/332501)

<div class="topic-metadata">

**Author:** [@Mohsin\_Ashraf](https://discuss.elastic.co/u/Mohsin_Ashraf)\
**Replies:** 11\
**Last updated:** [May 4, 2023, 10:39am UTC](https://discuss.elastic.co/t/elasticsearch-query-error/332501 "2023-05-04T10:39:38Z")

</div>

Hi, I'm facing this error While querying the data. is there any solution for this? error: query\_shard\_exception Reason failed to create query: field expansion for \[\*\] matches too many fields, limit: 1024, got: 20703 …

---

## [Logstash not sending all data to elasticsearch](https://discuss.elastic.co/t/logstash-not-sending-all-data-to-elasticsearch/330025)

<div class="topic-metadata">

**Author:** [@Koi\_Kin](https://discuss.elastic.co/u/Koi_Kin)\
**Replies:** 7\
**Last updated:** [May 4, 2023, 11:18am UTC](https://discuss.elastic.co/t/logstash-not-sending-all-data-to-elasticsearch/330025 "2023-05-04T11:18:13Z")

</div>

I have a simple jdbc connector without filter to fetch data from database to feed the elasticsearch with. input { jdbc { jdbc\_connection\_string =\> "#connectionstring" jdbc\_user =\> "#username" jdb…

---

## [Error when installing/enrolling Fleet Server](https://discuss.elastic.co/t/error-when-installing-enrolling-fleet-server/332294)

<div class="topic-metadata">

**Author:** [@Miguel\_Azorin](https://discuss.elastic.co/u/Miguel_Azorin)\
**Replies:** 4\
**Last updated:** [May 4, 2023, 9:58am UTC](https://discuss.elastic.co/t/error-when-installing-enrolling-fleet-server/332294 "2023-05-04T09:58:38Z")

</div>

Hi, I've been trying to deploy a Fleet Server (ELK stack 7.17.6), but I'm running into a problem I cannot solve, and the logs don't give enough info for me to figure it out (also, there is nothing about this in the elas…

---

## [Search By Id in Java API Client](https://discuss.elastic.co/t/search-by-id-in-java-api-client/332435)

<div class="topic-metadata">

**Author:** [@DavJane](https://discuss.elastic.co/u/DavJane)\
**Replies:** 2\
**Last updated:** [May 4, 2023, 9:42am UTC](https://discuss.elastic.co/t/search-by-id-in-java-api-client/332435 "2023-05-04T09:42:11Z")

</div>

Hi, I am trying to migrate my existing Elastic Search Rest High Level Client from 6.3.2 to the latest Java Client API. My current code has SearchRequest sr = new SearchRequest(indexName); …

---

## [Incremental data from oracle DB to elastic search using Logstash jdbc plugin](https://discuss.elastic.co/t/incremental-data-from-oracle-db-to-elastic-search-using-logstash-jdbc-plugin/332524)

<div class="topic-metadata">

**Author:** [@Jayasurya](https://discuss.elastic.co/u/Jayasurya)\
**Replies:** 0\
**Last updated:** [May 4, 2023, 9:23am UTC](https://discuss.elastic.co/t/incremental-data-from-oracle-db-to-elastic-search-using-logstash-jdbc-plugin/332524 "2023-05-04T09:23:23Z")

</div>

Hi, I am using Logstash jdbc plugin to ingest my data from oracle Database to Elasticsearch ,so this activity I can able to do. and the problem is while I need to take a incremental data and modified data to Elasticsear…

---

## [Elastic Agent fails to read io.stat file with more than one $MAJ:$MIN device number](https://discuss.elastic.co/t/elastic-agent-fails-to-read-io-stat-file-with-more-than-one-maj-min-device-number/330026)

<div class="topic-metadata">

**Author:** [@vitalyrychkov](https://discuss.elastic.co/u/vitalyrychkov)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 2:46pm UTC](https://discuss.elastic.co/t/elastic-agent-fails-to-read-io-stat-file-with-more-than-one-maj-min-device-number/330026 "2023-04-14T14:46:37Z")

</div>

We have a cluster with multiple VM nodes and a physical node, let's say "PH". The physical node has attached network storage with the multi-path option enabled. When elastic-agent (8.7.0) daemonset is deployed in this cl…

---

## [Field \[ts\] of type \[java.lang.Double\] cannot be cast to \[java.lang.String\]](https://discuss.elastic.co/t/field-ts-of-type-java-lang-double-cannot-be-cast-to-java-lang-string/332257)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 3\
**Last updated:** [May 4, 2023, 8:38am UTC](https://discuss.elastic.co/t/field-ts-of-type-java-lang-double-cannot-be-cast-to-java-lang-string/332257 "2023-05-04T08:38:12Z")

</div>

Hi All, I have few application in kubernetes environment which log timestamp field as "ts" and in unix epoch timestamp (in seconds.milliseconds format). i am referring this post to use ingest pipeline grok processor to …

---

## [Winlogbeat "channel not found error" floods log](https://discuss.elastic.co/t/winlogbeat-channel-not-found-error-floods-log/332304)

<div class="topic-metadata">

**Author:** [@C0FFEEC0FFEE](https://discuss.elastic.co/u/C0FFEEC0FFEE)\
**Replies:** 2\
**Last updated:** [May 4, 2023, 7:58am UTC](https://discuss.elastic.co/t/winlogbeat-channel-not-found-error-floods-log/332304 "2023-05-04T07:58:56Z")

</div>

Since https://github.com/elastic/beats/pull/34605, the winlogbeat logfile is flooded with "channel not found" errors if a non-existent channel is configured in winlogbeat.yml. For each channel which isn't found, this er…

---

## [Ingestion not consistent, data loss](https://discuss.elastic.co/t/ingestion-not-consistent-data-loss/330512)

<div class="topic-metadata">

**Author:** [@Rui\_Goncalves](https://discuss.elastic.co/u/Rui_Goncalves)\
**Replies:** 6\
**Last updated:** [May 4, 2023, 6:44am UTC](https://discuss.elastic.co/t/ingestion-not-consistent-data-loss/330512 "2023-05-04T06:44:06Z")

</div>

Hi, We're ingesting a big amount of data from an oracle database into elastic through logstash. We import some oracle table information into different arrays in elastic. Each table corresponding to an array, and each r…

---

## [How to change the path of Jruby jar files in Logstash](https://discuss.elastic.co/t/how-to-change-the-path-of-jruby-jar-files-in-logstash/330909)

<div class="topic-metadata">

**Author:** [@sriteja\_chebrolu](https://discuss.elastic.co/u/sriteja_chebrolu)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 6:30am UTC](https://discuss.elastic.co/t/how-to-change-the-path-of-jruby-jar-files-in-logstash/330909 "2023-05-04T06:30:32Z")

</div>

Large number of Jruby jar files are generating in Windows temp folder that filling up the C drive space. I want to change the path of those Jruby jar files. Can anyone please help me on this.

---

## [Kibana dashboard is healthy , even filebeat service is stopped](https://discuss.elastic.co/t/kibana-dashboard-is-healthy-even-filebeat-service-is-stopped/332228)

<div class="topic-metadata">

**Author:** [@SalmaShaik](https://discuss.elastic.co/u/SalmaShaik)\
**Replies:** 4\
**Last updated:** [May 4, 2023, 5:53am UTC](https://discuss.elastic.co/t/kibana-dashboard-is-healthy-even-filebeat-service-is-stopped/332228 "2023-05-04T05:53:33Z")

</div>

Hi, Filebeat service is not running. But the kibana Dasboard shows as healthy in Elasticsearch Vm's and their respective nodes. Can anyone help me.

---

## [Logstash not able to pull multiple beats data (ELK 8.6)](https://discuss.elastic.co/t/logstash-not-able-to-pull-multiple-beats-data-elk-8-6/332424)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 4\
**Last updated:** [May 4, 2023, 3:54am UTC](https://discuss.elastic.co/t/logstash-not-able-to-pull-multiple-beats-data-elk-8-6/332424 "2023-05-04T03:54:44Z")

</div>

Hello all: I am trying to get my filebeat and metricbeat data from another server into logstash . I am using below command line at the logstash bin folder. And I got separate conf file for filebeat and metricbeat on my …

---

## [Elastic 8.7.0 Error in Discover tab](https://discuss.elastic.co/t/elastic-8-7-0-error-in-discover-tab/332329)

<div class="topic-metadata">

**Author:** [@afmiller1](https://discuss.elastic.co/u/afmiller1)\
**Replies:** 3\
**Last updated:** [May 3, 2023, 10:00pm UTC](https://discuss.elastic.co/t/elastic-8-7-0-error-in-discover-tab/332329 "2023-05-03T22:00:03Z")

</div>

Have a single node cluster up and trying to use metricbeats locally and running into this error. I haven't come across it before. What is actually broke? This is when I go into the discover tab under metricbeat and try t…

---

## [How to copy data from old cluster to new cluster](https://discuss.elastic.co/t/how-to-copy-data-from-old-cluster-to-new-cluster/332470)

<div class="topic-metadata">

**Author:** [@Naga\_Prudhvi](https://discuss.elastic.co/u/Naga_Prudhvi)\
**Replies:** 3\
**Last updated:** [May 3, 2023, 8:31pm UTC](https://discuss.elastic.co/t/how-to-copy-data-from-old-cluster-to-new-cluster/332470 "2023-05-03T20:31:17Z")

</div>

Hi I am trying to copy all the index (150) from old cluster to new cluster. Trying reindex api is throwing error, and snapshot and restore is not an option. any other ways to migrate, so that all mapping and data sett…

---

## [Encoded data in message field using filebeat filestream input](https://discuss.elastic.co/t/encoded-data-in-message-field-using-filebeat-filestream-input/330907)

<div class="topic-metadata">

**Author:** [@Ryan\_Clark](https://discuss.elastic.co/u/Ryan_Clark)\
**Replies:** 3\
**Last updated:** [May 3, 2023, 8:16pm UTC](https://discuss.elastic.co/t/encoded-data-in-message-field-using-filebeat-filestream-input/330907 "2023-05-03T20:16:35Z")

</div>

I'm using filebeat to read in a multiline log. I'm able to get the data into elasticsearch with the multiline event stored into the message field. Log Sample: Date: Wed Apr 19 09:57:45 2023 Computer Name: SystemX User…

---

## [How to create a user with only devtools read only access](https://discuss.elastic.co/t/how-to-create-a-user-with-only-devtools-read-only-access/329842)

<div class="topic-metadata">

**Author:** [@Naga\_Prudhvi](https://discuss.elastic.co/u/Naga_Prudhvi)\
**Replies:** 3\
**Last updated:** [May 3, 2023, 8:23pm UTC](https://discuss.elastic.co/t/how-to-create-a-user-with-only-devtools-read-only-access/329842 "2023-05-03T20:23:11Z")

</div>

how can i create a user , when they login directly view devtools and only have read only(GET) access. what are the steps for this, as I can not see any info related to this. Any help on this would be very appreciated

---

## [Filebeat JSON Parsing](https://discuss.elastic.co/t/filebeat-json-parsing/331023)

<div class="topic-metadata">

**Author:** [@Tussingh](https://discuss.elastic.co/u/Tussingh)\
**Replies:** 1\
**Last updated:** [May 3, 2023, 2:43pm UTC](https://discuss.elastic.co/t/filebeat-json-parsing/331023 "2023-05-03T14:43:55Z")

</div>

I am trying to ingest below JSON to elastic through filebeat http json input plugin. \[ { "metricId": 185016812, "metricName": "BTM|Application Diagnostic Data|Base Page:20869077|Synthetic Visually Complete Time (ms)"…

---

## [Best practices for testing against clusters on ECE](https://discuss.elastic.co/t/best-practices-for-testing-against-clusters-on-ece/332321)

<div class="topic-metadata">

**Author:** [@jan.stap](https://discuss.elastic.co/u/jan.stap)\
**Replies:** 2\
**Last updated:** [May 3, 2023, 2:40pm UTC](https://discuss.elastic.co/t/best-practices-for-testing-against-clusters-on-ece/332321 "2023-05-03T14:40:35Z")

</div>

Hello, We intend to test the ingest and query performance of clusters hosted on ECE by using Rally. So far, the elastic/logs track looks interesting. I studied this video and pdf on Rally testing pitfalls by the Rally a…

---

## [Query on array fields with null value](https://discuss.elastic.co/t/query-on-array-fields-with-null-value/332426)

<div class="topic-metadata">

**Author:** [@dhggw](https://discuss.elastic.co/u/dhggw)\
**Replies:** 1\
**Last updated:** [May 3, 2023, 1:54pm UTC](https://discuss.elastic.co/t/query-on-array-fields-with-null-value/332426 "2023-05-03T13:54:24Z")

</div>

Hello all, we have in our index fields with arrays, each containing only one element, which is NULL: "field": \[ null \] I would like to filter on just these records, however I can't find a query that will do this.…

---

## [How to add Azure Service Bus log to elastic](https://discuss.elastic.co/t/how-to-add-azure-service-bus-log-to-elastic/332431)

<div class="topic-metadata">

**Author:** [@abh-remitra](https://discuss.elastic.co/u/abh-remitra)\
**Replies:** 0\
**Last updated:** [May 3, 2023, 1:39pm UTC](https://discuss.elastic.co/t/how-to-add-azure-service-bus-log-to-elastic/332431 "2023-05-03T13:39:32Z")

</div>

We have ECE on-prem (8.5.2) and we have recently added some services running in Azure. Looking for recommendations / advice for the best way to collect and ship Azure Service Bus logs to our ES cluster. Thanks in advan…

---

## [How to add synonym with a forward shash? Error failed to build synonyms](https://discuss.elastic.co/t/how-to-add-synonym-with-a-forward-shash-error-failed-to-build-synonyms/330647)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 3\
**Last updated:** [May 3, 2023, 1:33pm UTC](https://discuss.elastic.co/t/how-to-add-synonym-with-a-forward-shash-error-failed-to-build-synonyms/330647 "2023-05-03T13:33:03Z")

</div>

How to add synonym with a forward shash? Error failed to build synonyms.

---

## [Elastic DSL Query](https://discuss.elastic.co/t/elastic-dsl-query/330656)

<div class="topic-metadata">

**Author:** [@vrviji](https://discuss.elastic.co/u/vrviji)\
**Replies:** 5\
**Last updated:** [May 2, 2023, 8:45pm UTC](https://discuss.elastic.co/t/elastic-dsl-query/330656 "2023-05-02T20:45:41Z")

</div>

Hello All, I would like to do a self join in DSL. Is that possible in Elastic 7.17. Basically i want to search a index for a certain Error message and if the latest status of the order is completed i dont want to includ…

---

## [ElasticSearch 8.6 bat execution error](https://discuss.elastic.co/t/elasticsearch-8-6-bat-execution-error/332305)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 5\
**Last updated:** [May 3, 2023, 12:34pm UTC](https://discuss.elastic.co/t/elasticsearch-8-6-bat-execution-error/332305 "2023-05-03T12:34:41Z")

</div>

Hi all: When I execute elasticsearch.bat from elastic\\bin folder I am getting below error of "Socket connection time out". I have added below elasticsearch.yml as well. Please advise. Thank you. \[2023-05-03T00:51:56,0…

---

## [Logstash file input plugin](https://discuss.elastic.co/t/logstash-file-input-plugin/332259)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [May 3, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-file-input-plugin/332259 "2023-05-03T12:32:48Z")

</div>

Hi, I am trying to use logstash file input plugin. I want to pick files from multiple locations and send them to different indices. Here is my config nput { file { type =\> "TomEE-logs-passport" …

---

## [Why is data from elasticsearch not being updated?](https://discuss.elastic.co/t/why-is-data-from-elasticsearch-not-being-updated/330810)

<div class="topic-metadata">

**Author:** [@edgarmat1964](https://discuss.elastic.co/u/edgarmat1964)\
**Replies:** 2\
**Last updated:** [May 3, 2023, 11:50am UTC](https://discuss.elastic.co/t/why-is-data-from-elasticsearch-not-being-updated/330810 "2023-05-03T11:50:08Z")

</div>

LS, I have a "simple" vega script to extract data from elasticsearch to "visualize": { "$schema": "https://vega.github.io/schema/vega/v5.json", "width": 400, "height": 70, "padding": 5, "autosize": "none", "b…

---

## [Cross-cluster](https://discuss.elastic.co/t/cross-cluster/332253)

<div class="topic-metadata">

**Author:** [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)\
**Replies:** 1\
**Last updated:** [May 3, 2023, 11:48am UTC](https://discuss.elastic.co/t/cross-cluster/332253 "2023-05-03T11:48:16Z")

</div>

I tried to do the first step in this documentation(Tutorial: Set up cross-cluster replication | Elasticsearch Guide \[8.7\] | Elastic) and I couldn't connect one cluster with another i have port 9300 open on both clusters. …

---

## [Kibana - the most used room - unique id](https://discuss.elastic.co/t/kibana-the-most-used-room-unique-id/330389)

<div class="topic-metadata">

**Author:** [@TheyCallMeTrinity](https://discuss.elastic.co/u/TheyCallMeTrinity)\
**Replies:** 2\
**Last updated:** [May 3, 2023, 11:04am UTC](https://discuss.elastic.co/t/kibana-the-most-used-room-unique-id/330389 "2023-05-03T11:04:06Z")

</div>

Hello, I have a question about visualizations using a table - for booking sw. I have data in Kibana that contains room name, user name, time from and to, event time,.... and id. Every booking, confirmation and change co…

---

## [Control UI format in Kibana dashboard](https://discuss.elastic.co/t/control-ui-format-in-kibana-dashboard/332379)

<div class="topic-metadata">

**Author:** [@rituraj\_B](https://discuss.elastic.co/u/rituraj_B)\
**Replies:** 1\
**Last updated:** [May 3, 2023, 10:49am UTC](https://discuss.elastic.co/t/control-ui-format-in-kibana-dashboard/332379 "2023-05-03T10:49:41Z")

</div>

Hi, is there any way to make the controls on the Kibana dashboard appear one below the other, say on the left hand side of my dashboard, instead of it defaulting to clustering on top of the dashboard?

---

## [Pie chart: Custom color settings and legend font size](https://discuss.elastic.co/t/pie-chart-custom-color-settings-and-legend-font-size/332280)

<div class="topic-metadata">

**Author:** [@Rama\_Krishna2](https://discuss.elastic.co/u/Rama_Krishna2)\
**Replies:** 1\
**Last updated:** [May 3, 2023, 10:42am UTC](https://discuss.elastic.co/t/pie-chart-custom-color-settings-and-legend-font-size/332280 "2023-05-03T10:42:16Z")

</div>

I have recently started working with Kibana version 7.17.3 and have two issues that I need help with. Firstly, I want to create a custom color range for a pie chart. Specifically, I want to use shades of red for each sli…

---

## [Issue to read logs from radsecproxy](https://discuss.elastic.co/t/issue-to-read-logs-from-radsecproxy/332204)

<div class="topic-metadata">

**Author:** [@Ayah](https://discuss.elastic.co/u/Ayah)\
**Replies:** 2\
**Last updated:** [May 3, 2023, 10:21am UTC](https://discuss.elastic.co/t/issue-to-read-logs-from-radsecproxy/332204 "2023-05-03T10:21:31Z")

</div>

Hello, we have implemented ELK to visualize eduroam log from radsecproxy. Our system was developed following this guideline GitHub - REANNZ/etcbd-public: eduroam tools container-based deployment - public tools it was w…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=552)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=554)
