# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=555

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 556

---

## [Cluster with packetbeat](https://discuss.elastic.co/t/cluster-with-packetbeat/330929)

<div class="topic-metadata">

**Author:** [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)\
**Replies:** 16\
**Last updated:** [May 2, 2023, 10:21am UTC](https://discuss.elastic.co/t/cluster-with-packetbeat/330929 "2023-05-02T10:21:24Z")

</div>

Hello, I'm trying to form a cluster and in this cluster I want to add several nodes and install packtbeat on each node. But when I do that, the data sent from packtbeat is shared across the entire cluster. Is there any w…

---

## [Enabling Exclusion of Specific Text in Elastic Document Searches](https://discuss.elastic.co/t/enabling-exclusion-of-specific-text-in-elastic-document-searches/332179)

<div class="topic-metadata">

**Author:** [@Henkm](https://discuss.elastic.co/u/Henkm)\
**Replies:** 2\
**Last updated:** [May 2, 2023, 10:05am UTC](https://discuss.elastic.co/t/enabling-exclusion-of-specific-text-in-elastic-document-searches/332179 "2023-05-02T10:05:37Z")

</div>

Our platform leverages Elasticsearch technology to enhance search result optimization by analyzing user-uploaded profiles and documents. However, we have identified a data inconsistency issue that is caused by certain in…

---

## [Elastic can not see the lastest log after using ILM](https://discuss.elastic.co/t/elastic-can-not-see-the-lastest-log-after-using-ilm/330822)

<div class="topic-metadata">

**Author:** [@antony.y](https://discuss.elastic.co/u/antony.y)\
**Replies:** 3\
**Last updated:** [May 2, 2023, 9:52am UTC](https://discuss.elastic.co/t/elastic-can-not-see-the-lastest-log-after-using-ilm/330822 "2023-05-02T09:52:22Z")

</div>

My es version is 7.13.4,but after i change the ilm policy, i can not receive any new log from the logstash, even i set the ilm\_enable=false

---

## [Unable to connect to database. Tried 1 times](https://discuss.elastic.co/t/unable-to-connect-to-database-tried-1-times/331547)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 1\
**Last updated:** [May 2, 2023, 9:22am UTC](https://discuss.elastic.co/t/unable-to-connect-to-database-tried-1-times/331547 "2023-05-02T09:22:00Z")

</div>

Hello to All, I am trying to connect with the Database, and I configured the JDBC plugin in case there is a time-out connection. jdbc\_validate\_connection =\> "true" jdbc\_validation\_timeout =\> "60" In the first time-out…

---

## [Importing to an existing index in Elastic doesn't behave as expected](https://discuss.elastic.co/t/importing-to-an-existing-index-in-elastic-doesnt-behave-as-expected/332225)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [May 2, 2023, 9:15am UTC](https://discuss.elastic.co/t/importing-to-an-existing-index-in-elastic-doesnt-behave-as-expected/332225 "2023-05-02T09:15:07Z")

</div>

I am exporting from one ELK stack using logstash. I am writing the output to a json gz file. Then I am importing to another ELK stack also using logstash. There is no connection between the two environments. This expor…

---

## [Elasticsearch looked stopped for a moment](https://discuss.elastic.co/t/elasticsearch-looked-stopped-for-a-moment/332223)

<div class="topic-metadata">

**Author:** [@whoami1](https://discuss.elastic.co/u/whoami1)\
**Replies:** 1\
**Last updated:** [May 2, 2023, 9:09am UTC](https://discuss.elastic.co/t/elasticsearch-looked-stopped-for-a-moment/332223 "2023-05-02T09:09:30Z")

</div>

Hi guys When I looked over ELK overview, I found something on ELK. Every graph has a point to stop for a moment. I don't know the reason. Please help me if someone knows.

---

## [Mapper\_parsing\_exception,reason:object mapping for \[process\] tried to parse field \[process\] as object, but found a concrete value](https://discuss.elastic.co/t/mapper-parsing-exception-reason-object-mapping-for-process-tried-to-parse-field-process-as-object-but-found-a-concrete-value/330979)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 2\
**Last updated:** [May 2, 2023, 9:05am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-reason-object-mapping-for-process-tried-to-parse-field-process-as-object-but-found-a-concrete-value/330979 "2023-05-02T09:05:41Z")

</div>

i am using elasticsearch to store logs and metrics for our applications on kubernetes environment. so now there are two different containers whose logs are collected by fluentd agent and pushed to elasticsearch. one of …

---

## [Master not discovered yet](https://discuss.elastic.co/t/master-not-discovered-yet/330952)

<div class="topic-metadata">

**Author:** [@fnitz](https://discuss.elastic.co/u/fnitz)\
**Replies:** 8\
**Last updated:** [May 2, 2023, 8:22am UTC](https://discuss.elastic.co/t/master-not-discovered-yet/330952 "2023-05-02T08:22:53Z")

</div>

Hello, actually I've got some problems with my elasticsearch, see below: \[2023-04-27T09:41:23,333\]\[INFO \]\[o.e.c.s.MasterService \] \[kibana-com-2-rz2\] node-join\[{elastic-cold-com-4-rz2}{3jgTzoQdQJSpQaLaQhlMPg}{jk19Bev…

---

## [How to do Metric aggregation inside terms aggregations on nested type](https://discuss.elastic.co/t/how-to-do-metric-aggregation-inside-terms-aggregations-on-nested-type/332217)

<div class="topic-metadata">

**Author:** [@kartikchauhan](https://discuss.elastic.co/u/kartikchauhan)\
**Replies:** 0\
**Last updated:** [May 2, 2023, 8:14am UTC](https://discuss.elastic.co/t/how-to-do-metric-aggregation-inside-terms-aggregations-on-nested-type/332217 "2023-05-02T08:14:27Z")

</div>

I've documents stored in Elastic Search in this way: Doc1: { "owner": "owner\_1", "attributes" : \[ { "name": "dump", "value": "xyz" }, { "name": "weight", "value": "150" } \]…

---

## [JSLT or other tool for Elasticsearch search templates management/generation](https://discuss.elastic.co/t/jslt-or-other-tool-for-elasticsearch-search-templates-management-generation/330212)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 10:09am UTC](https://discuss.elastic.co/t/jslt-or-other-tool-for-elasticsearch-search-templates-management-generation/330212 "2023-04-18T10:09:38Z")

</div>

Hi there, does anybody uses JSLT or anything similar for managing or auto-generating search templates for Elasticsearch? I have 13 search templates for different business purposes for one app., but basically there is a…

---

## [Extremely Weird Search Behaviour on "ing"](https://discuss.elastic.co/t/extremely-weird-search-behaviour-on-ing/330944)

<div class="topic-metadata">

**Author:** [@Ray\_Cannon](https://discuss.elastic.co/u/Ray_Cannon)\
**Replies:** 2\
**Last updated:** [May 2, 2023, 6:25am UTC](https://discuss.elastic.co/t/extremely-weird-search-behaviour-on-ing/330944 "2023-05-02T06:25:07Z")

</div>

I have Elasticsearch 7 installed on a VPS for which I use with my Magento store. After several tests, disabling/removing extensions and using 2 differant Magento Versions (but the same Elasticsearch installation), I can…

---

## [Couldn’t find any Elasticsearch data](https://discuss.elastic.co/t/couldn-t-find-any-elasticsearch-data/330918)

<div class="topic-metadata">

**Author:** [@kparmar](https://discuss.elastic.co/u/kparmar)\
**Replies:** 3\
**Last updated:** [May 2, 2023, 6:13am UTC](https://discuss.elastic.co/t/couldn-t-find-any-elasticsearch-data/330918 "2023-05-02T06:13:56Z")

</div>

Couldn’t find any Elasticsearch data We are trying to redirect our Application log files using EFK but whenever we login into Kibana Management tab we are getting below message You'll need to index some data into Elast…

---

## [How to create Heat Map in kibana 7.17.8?](https://discuss.elastic.co/t/how-to-create-heat-map-in-kibana-7-17-8/331016)

<div class="topic-metadata">

**Author:** [@Chinmay\_Bhusate](https://discuss.elastic.co/u/Chinmay_Bhusate)\
**Replies:** 4\
**Last updated:** [May 2, 2023, 4:43am UTC](https://discuss.elastic.co/t/how-to-create-heat-map-in-kibana-7-17-8/331016 "2023-05-02T04:43:44Z")

</div>

I want to create heat map in kibana version 7.17.8 . But I'm not able to see option of heatmaps like other versions . Attaching the map I'm referring to. Inputs are appreciated .

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[logstash-7.13.3\] does not point to index \[logstash\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-logstash-7-13-3-does-not-point-to-index-logstash/331046)

<div class="topic-metadata">

**Author:** [@Abinsha\_N](https://discuss.elastic.co/u/Abinsha_N)\
**Replies:** 1\
**Last updated:** [May 2, 2023, 3:32am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-logstash-7-13-3-does-not-point-to-index-logstash/331046 "2023-05-02T03:32:27Z")

</div>

roll over is not taking place. Please help. { "policy": "logstash-policy", "phase\_definition": { "min\_age": "0ms", "actions": { "rollover": { "max\_size": "50gb", "max\_age": "30d" …

---

## [Kibana Global variables](https://discuss.elastic.co/t/kibana-global-variables/331055)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [May 2, 2023, 3:31am UTC](https://discuss.elastic.co/t/kibana-global-variables/331055 "2023-05-02T03:31:52Z")

</div>

I want to do an elasticsearch query, then based on the result of this query, can I store the result of the wanted field in a global variable somewhere and use it as an input to another query ? is there a way to do so wi…

---

## [Datatypes a mess after reindexing](https://discuss.elastic.co/t/datatypes-a-mess-after-reindexing/332055)

<div class="topic-metadata">

**Author:** [@GregoryJC](https://discuss.elastic.co/u/GregoryJC)\
**Replies:** 1\
**Last updated:** [May 2, 2023, 3:18am UTC](https://discuss.elastic.co/t/datatypes-a-mess-after-reindexing/332055 "2023-05-02T03:18:07Z")

</div>

Currently elastic version 7.17.3. We recently reindexed and changed fields to text but we noticed that the field types got all messed up. This is third party data, and we noticed that the field order is not the same in…

---

## [Elasticsearch hosts upgrade - options](https://discuss.elastic.co/t/elasticsearch-hosts-upgrade-options/331071)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 8\
**Last updated:** [May 1, 2023, 11:42pm UTC](https://discuss.elastic.co/t/elasticsearch-hosts-upgrade-options/331071 "2023-05-01T23:42:27Z")

</div>

Hello, We have 3 Master nodes and 5 data nodes in our cluster. The VMs hosting the entire cluster is undergoing an upgrade which will involve downtime (for few hours) and also IP change for the 3 Master nodes and 1 dat…

---

## [Auditbeat btmp file monitoring glitch (saved size or offset illogical)](https://discuss.elastic.co/t/auditbeat-btmp-file-monitoring-glitch-saved-size-or-offset-illogical/332037)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 6:47pm UTC](https://discuss.elastic.co/t/auditbeat-btmp-file-monitoring-glitch-saved-size-or-offset-illogical/332037 "2023-05-01T18:47:55Z")

</div>

Hi, I have auditbeat 7.17.8 installed on an RHEL 7 system. RHEL7 rotates out the BTMP file out at the start of every month. So, starting today I am seeing the following message every few seconds in syslog: May 1 12:…

---

## [How to pass in \`current\_unix\_time\` as a value for elasticsearch query?](https://discuss.elastic.co/t/how-to-pass-in-current-unix-time-as-a-value-for-elasticsearch-query/331385)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 5:33pm UTC](https://discuss.elastic.co/t/how-to-pass-in-current-unix-time-as-a-value-for-elasticsearch-query/331385 "2023-05-01T17:33:54Z")

</div>

My ultimate goal is to create a Kibana visualization that shows "How many days have passed since \[today\]". I was told I might be able to create an elasticsearch query that passes in a current\_unix\_time or (new Date()).…

---

## [FileBeat 7.x ARM32 based Image](https://discuss.elastic.co/t/filebeat-7-x-arm32-based-image/331865)

<div class="topic-metadata">

**Author:** [@Kamesh\_Pratapa](https://discuss.elastic.co/u/Kamesh_Pratapa)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 5:31pm UTC](https://discuss.elastic.co/t/filebeat-7-x-arm32-based-image/331865 "2023-05-01T17:31:20Z")

</div>

Hi, I am unable to locate the filebeat and metric beat ARM 32bit architecture based image in the official download location. Can someone help me to point the location ? Regards, Kamesh.

---

## [How can I generate a CEF output](https://discuss.elastic.co/t/how-can-i-generate-a-cef-output/331867)

<div class="topic-metadata">

**Author:** [@CyberGuy](https://discuss.elastic.co/u/CyberGuy)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 4:53pm UTC](https://discuss.elastic.co/t/how-can-i-generate-a-cef-output/331867 "2023-05-01T16:53:42Z")

</div>

I have created a logstash configuration that successfully parses CEF logs and applies certain logic to it. The filter configuration extracts the CEF with a grok filter and then uses the kv plugin to extract the different…

---

## [Reindex corrupted index into a new copy](https://discuss.elastic.co/t/reindex-corrupted-index-into-a-new-copy/330765)

<div class="topic-metadata">

**Author:** [@rivermigue](https://discuss.elastic.co/u/rivermigue)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 4:47pm UTC](https://discuss.elastic.co/t/reindex-corrupted-index-into-a-new-copy/330765 "2023-05-01T16:47:29Z")

</div>

Hello, Is it possible to reindex a corrupted index into a new copy accepting some data loss? I am trying to reindex a corrupted index with the following call: POST \_reindex { "source": { "index": "index001" }, "…

---

## [Elasticsearch binds to all interfaces even with network.host commented out](https://discuss.elastic.co/t/elasticsearch-binds-to-all-interfaces-even-with-network-host-commented-out/331159)

<div class="topic-metadata">

**Author:** [@alexl9](https://discuss.elastic.co/u/alexl9)\
**Replies:** 4\
**Last updated:** [May 1, 2023, 4:32pm UTC](https://discuss.elastic.co/t/elasticsearch-binds-to-all-interfaces-even-with-network-host-commented-out/331159 "2023-05-01T16:32:08Z")

</div>

I installed the latest Elasticsearch but it binds to all interfaces even with network.host commented out, is that expected behavior?

---

## [Kibana unable to parse syslog logs](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972)

<div class="topic-metadata">

**Author:** [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Replies:** 9\
**Last updated:** [May 1, 2023, 3:52pm UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972 "2023-05-01T15:52:33Z")

</div>

I have a text file which contains data in the below format (syslog). Oct 9 2019 23:39:37 myrtle sshd\[41925\]: pam\_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.49.202.135 user=…

---

## [Moving all shards in an index to the same node](https://discuss.elastic.co/t/moving-all-shards-in-an-index-to-the-same-node/330956)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 3:43pm UTC](https://discuss.elastic.co/t/moving-all-shards-in-an-index-to-the-same-node/330956 "2023-05-01T15:43:18Z")

</div>

We want to implement the shrink index API on our cluster. A pre-requisite is that all shards in the to-be-shrunk index must reside on the same node. Currently, this is not the case. What is the simplest way to move all …

---

## [Logstash sometimes parsing sometime not, even though sending the Same message](https://discuss.elastic.co/t/logstash-sometimes-parsing-sometime-not-even-though-sending-the-same-message/331870)

<div class="topic-metadata">

**Author:** [@Prakash111](https://discuss.elastic.co/u/Prakash111)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 12:40pm UTC](https://discuss.elastic.co/t/logstash-sometimes-parsing-sometime-not-even-though-sending-the-same-message/331870 "2023-05-01T12:40:01Z")

</div>

Log message 2023-05-01T05:22:20.154Z \[INFO\] "interSample" {"PID": 1, "Service": "XYZService", "Data": \[\]} some times log stash parsing successfully "\_message\_json\_parsed" some times parse failure "\_grokparsefailure" e…

---

## [How to extract the entire value of a complicated field?](https://discuss.elastic.co/t/how-to-extract-the-entire-value-of-a-complicated-field/330891)

<div class="topic-metadata">

**Author:** [@CyberGuy](https://discuss.elastic.co/u/CyberGuy)\
**Replies:** 6\
**Last updated:** [May 1, 2023, 12:34pm UTC](https://discuss.elastic.co/t/how-to-extract-the-entire-value-of-a-complicated-field/330891 "2023-05-01T12:34:29Z")

</div>

HI guys, I'm trying to create a logstash pipeline that parses incoming CEF logs, apply some logic and then outputs the log in JSON format to the console. Some logs are a bit complicated to parse since the key=value pai…

---

## [Extract all data from a composite aggregation in Power BI/Power Query using after\_key](https://discuss.elastic.co/t/extract-all-data-from-a-composite-aggregation-in-power-bi-power-query-using-after-key/331868)

<div class="topic-metadata">

**Author:** [@Felipe\_Moura\_da\_Silv](https://discuss.elastic.co/u/Felipe_Moura_da_Silv)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 12:34pm UTC](https://discuss.elastic.co/t/extract-all-data-from-a-composite-aggregation-in-power-bi-power-query-using-after-key/331868 "2023-05-01T12:34:00Z")

</div>

Hey guys! I'm having a challenge importing data from an elasticsearch query into Power BI. I'm making the call and the results arrive, but only the limit of 16000 results that the API allows due to performance. I need …

---

## [Please tell me about the situation of es hardware resources](https://discuss.elastic.co/t/please-tell-me-about-the-situation-of-es-hardware-resources/330893)

<div class="topic-metadata">

**Author:** [@Astrid\_SRE](https://discuss.elastic.co/u/Astrid_SRE)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 10:18am UTC](https://discuss.elastic.co/t/please-tell-me-about-the-situation-of-es-hardware-resources/330893 "2023-05-01T10:18:13Z")

</div>

hi hello Can you help me analyze it, the current situation of our company is like this 20w logs per second 20T per day What kind of hardware configuration is required What is the configuration of the es cluster, net…

---

## [How to provide own API key in ELK version 8.0.0](https://discuss.elastic.co/t/how-to-provide-own-api-key-in-elk-version-8-0-0/330939)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 6\
**Last updated:** [May 1, 2023, 9:49am UTC](https://discuss.elastic.co/t/how-to-provide-own-api-key-in-elk-version-8-0-0/330939 "2023-05-01T09:49:29Z")

</div>

Hi Team, I want to know how i can provide my own API key in ELK version 8.0.0 I did try - "xpack.security.authc.api\_key.enabled=true" - "xpack.security.authc.api\_key.key=" but no luck getting xpack.security.authc…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=554)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=556)
