# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=556

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 557

---

## [How to migrate data from v5.4 to v8.x.x](https://discuss.elastic.co/t/how-to-migrate-data-from-v5-4-to-v8-x-x/329963)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 8:25am UTC](https://discuss.elastic.co/t/how-to-migrate-data-from-v5-4-to-v8-x-x/329963 "2023-05-01T08:25:25Z")

</div>

Hi ES Community, I have few question, i have to migrate ES v5.4 data into latest ES version(v8.x). What would be correct step for this kind data migration? Should i use elasticdump tool to migrate data from old cluster…

---

## [Filebeat kubernetes unable to format json logs into fields](https://discuss.elastic.co/t/filebeat-kubernetes-unable-to-format-json-logs-into-fields/330795)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 2\
**Last updated:** [May 1, 2023, 5:48am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-unable-to-format-json-logs-into-fields/330795 "2023-05-01T05:48:55Z")

</div>

Hello, i want to ingested containers json log data using filebeat deployed on kubernetes, i am able to ingest the logs to but i am unable to format the json logs in to fields following is the logs visible in kibana …

---

## [How to setup username and password in EFK in helm charts](https://discuss.elastic.co/t/how-to-setup-username-and-password-in-efk-in-helm-charts/331038)

<div class="topic-metadata">

**Author:** [@root\_linux](https://discuss.elastic.co/u/root_linux)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 4:18am UTC](https://discuss.elastic.co/t/how-to-setup-username-and-password-in-efk-in-helm-charts/331038 "2023-05-01T04:18:30Z")

</div>

Hi, I have configured EFK using helm charts. But it is not asking for username and password. Could anyone help me how can I configure username and password in EFK using helm charts?

---

## [After upgrading from 7.1 to 8.7, I lost my data](https://discuss.elastic.co/t/after-upgrading-from-7-1-to-8-7-i-lost-my-data/331126)

<div class="topic-metadata">

**Author:** [@toshihisa-nakamura](https://discuss.elastic.co/u/toshihisa-nakamura)\
**Replies:** 2\
**Last updated:** [May 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/after-upgrading-from-7-1-to-8-7-i-lost-my-data/331126 "2023-05-01T04:05:29Z")

</div>

After upgrading from 7.1 to 8.7, I lost my data. With Version 8.7, I want to be able to enter data into Elasticsearch and display graphs in Kibana as before. I've been using it for several years just to send weather da…

---

## [Failed to Parse date](https://discuss.elastic.co/t/failed-to-parse-date/331445)

<div class="topic-metadata">

**Author:** [@valleram](https://discuss.elastic.co/u/valleram)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 2:58am UTC](https://discuss.elastic.co/t/failed-to-parse-date/331445 "2023-05-01T02:58:25Z")

</div>

Hi All, I'm trying to parse dates with format 1/3/2022. I've tried to parse it using following mapping M/d/YYYY but Kibana is showing a completely different result. See example below. Ingested date: Date showed in …

---

## [Remote clusters for basic/platinum , onprem/cloud license](https://discuss.elastic.co/t/remote-clusters-for-basic-platinum-onprem-cloud-license/330668)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 10\
**Last updated:** [May 1, 2023, 12:43am UTC](https://discuss.elastic.co/t/remote-clusters-for-basic-platinum-onprem-cloud-license/330668 "2023-05-01T00:43:55Z")

</div>

Hi, We have several Elastic clusters on-premises and we plan to create a few new ones on Azure cloud. All of them are self-managed version 8.6. The purpose of all Elasticsearch clusters is data analysis in Kibana, so I…

---

## [Elasticsearch G1GC over CMS in resolving the GC overhead](https://discuss.elastic.co/t/elasticsearch-g1gc-over-cms-in-resolving-the-gc-overhead/330744)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 3\
**Last updated:** [April 30, 2023, 11:21pm UTC](https://discuss.elastic.co/t/elasticsearch-g1gc-over-cms-in-resolving-the-gc-overhead/330744 "2023-04-30T23:21:48Z")

</div>

We are using the ES 7.3 with CMS GC and we are preparing for the rolling upgrade to 7.17 which supports G1GC only We are getting the GC overhead curently, \[2023-04-25T02:00:41,085\]\[WARN \]\[o.e.m.j.JvmGcMonitorService\] \[…

---

## [Move ilm based indices to new ILM policy](https://discuss.elastic.co/t/move-ilm-based-indices-to-new-ilm-policy/330793)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:18pm UTC](https://discuss.elastic.co/t/move-ilm-based-indices-to-new-ilm-policy/330793 "2023-04-30T23:18:07Z")

</div>

Hi Team, Few months back we have created one ILM policy for all indices. It was working fine then now our business need to is to create different policy for different indices the idea is to rollover some indices in 3 da…

---

## [Mappings Issue](https://discuss.elastic.co/t/mappings-issue/330797)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:17pm UTC](https://discuss.elastic.co/t/mappings-issue/330797 "2023-04-30T23:17:15Z")

</div>

Hi, I have a field in my index with the mapping and custom analyzer has followed: Mapping: "BookingNo" : { "type" : "text", "fields" : { "lowercase\_keyword" : { "type" : "text", "analyzer" : "lowercase\_keyword\_an…

---

## [How to index audio/video files to kibana](https://discuss.elastic.co/t/how-to-index-audio-video-files-to-kibana/330834)

<div class="topic-metadata">

**Author:** [@AdityaKhajuria](https://discuss.elastic.co/u/AdityaKhajuria)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:15pm UTC](https://discuss.elastic.co/t/how-to-index-audio-video-files-to-kibana/330834 "2023-04-30T23:15:08Z")

</div>

Hi, Im trying to index audio/video files to kibana. I am able to get audio in a field by setting Format-URL and type-Audio in index pattern. But i want my logstash to index my audio/video files to kibana.

---

## [Search template Kibana](https://discuss.elastic.co/t/search-template-kibana/331053)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:02pm UTC](https://discuss.elastic.co/t/search-template-kibana/331053 "2023-04-30T23:02:07Z")

</div>

Is there a way to use search template within kibana page like in discover ? I know we can use elasticsearch search template in devTools , but the output of the result is in json which not very visual I want to display…

---

## [Elasticsearch 8.7.0 Installation issue: elasticsearch.bat cmd automatic closes without installation](https://discuss.elastic.co/t/elasticsearch-8-7-0-installation-issue-elasticsearch-bat-cmd-automatic-closes-without-installation/331156)

<div class="topic-metadata">

**Author:** [@M4MURARI](https://discuss.elastic.co/u/M4MURARI)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 10:58pm UTC](https://discuss.elastic.co/t/elasticsearch-8-7-0-installation-issue-elasticsearch-bat-cmd-automatic-closes-without-installation/331156 "2023-04-30T22:58:55Z")

</div>

After unzipping the elasticsearch-8.7.0-windows-x86\_64.zip when I click on elasticsearch.bat of bin folder, It automatically closes without full installation. One solution I tried was xpack.security.transport.ssl.enable…

---

## [Issue with Elasticsearch indexes](https://discuss.elastic.co/t/issue-with-elasticsearch-indexes/331064)

<div class="topic-metadata">

**Author:** [@milank2](https://discuss.elastic.co/u/milank2)\
**Replies:** 9\
**Last updated:** [April 30, 2023, 10:56pm UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-indexes/331064 "2023-04-30T22:56:38Z")

</div>

Hello everyone, I am new to ELK and the issue I am experiencing is that indexes are after 3 days reduces to 25x bytes and 0 documents. We are viewing index patterns in Kibana but it will display the 3 days only. Nothing…

---

## [No incoming data to Logstash Output from Elastic Agents - Only Elasticsearch ouptut works](https://discuss.elastic.co/t/no-incoming-data-to-logstash-output-from-elastic-agents-only-elasticsearch-ouptut-works/331350)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 5\
**Last updated:** [April 30, 2023, 9:36pm UTC](https://discuss.elastic.co/t/no-incoming-data-to-logstash-output-from-elastic-agents-only-elasticsearch-ouptut-works/331350 "2023-04-30T21:36:01Z")

</div>

8.7 stack here After I setup a logstash output in Fleet, and set a policy to use that logstash ouptut for integrations, no data comes to it basically. When I switch the output for integrations to Elasticsearch instead …

---

## [Log stash behavior when output plug-in not reachable](https://discuss.elastic.co/t/log-stash-behavior-when-output-plug-in-not-reachable/331376)

<div class="topic-metadata">

**Author:** [@eth](https://discuss.elastic.co/u/eth)\
**Replies:** 0\
**Last updated:** [April 30, 2023, 6:14pm UTC](https://discuss.elastic.co/t/log-stash-behavior-when-output-plug-in-not-reachable/331376 "2023-04-30T18:14:03Z")

</div>

I am using logstash 7 with syslog as output plugin. The syslog server is not reachable for a quite a long time and persistent queue is growing as expected to the limit. But the persistent queue data size is growing bey…

---

## [Aggregate field with text type](https://discuss.elastic.co/t/aggregate-field-with-text-type/331119)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 5:37pm UTC](https://discuss.elastic.co/t/aggregate-field-with-text-type/331119 "2023-04-30T17:37:31Z")

</div>

Hi i have two field in kibana "hostname" and "usage", when i add "usage" it will show area chart but when i add "hostname" as breakdown not show. FYI1: hostname type are text and not aggregatable! FYI2: these field cr…

---

## [View In context option is not available(EFK- Elasticsearch Fluentd kibana Stack)](https://discuss.elastic.co/t/view-in-context-option-is-not-available-efk-elasticsearch-fluentd-kibana-stack/331367)

<div class="topic-metadata">

**Author:** [@Srijitha](https://discuss.elastic.co/u/Srijitha)\
**Replies:** 0\
**Last updated:** [April 30, 2023, 4:03pm UTC](https://discuss.elastic.co/t/view-in-context-option-is-not-available-efk-elasticsearch-fluentd-kibana-stack/331367 "2023-04-30T16:03:45Z")

</div>

Hi Team, I am sending log from fluentd to elasticsearch, everything works fine. But I am not able to see "VIEW IN CONTEXT" option in log section of observability, Elasticsearch version: 8.7 and Kibana Version: 8.7. Below…

---

## [How to avoid duplicate values being copied while using copy\_to?](https://discuss.elastic.co/t/how-to-avoid-duplicate-values-being-copied-while-using-copy-to/330905)

<div class="topic-metadata">

**Author:** [@Srikrishna\_Raghupath](https://discuss.elastic.co/u/Srikrishna_Raghupath)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:22am UTC](https://discuss.elastic.co/t/how-to-avoid-duplicate-values-being-copied-while-using-copy-to/330905 "2023-04-30T11:22:10Z")

</div>

My Index definition: PUT /test-index { "mappings": { "properties": { "category":{ "type": "text", "similarity": "boolean", "term\_vector": "with\_positions\_offsets", "fields":{…

---

## [Draw circle or polygons in Kibana Maps](https://discuss.elastic.co/t/draw-circle-or-polygons-in-kibana-maps/331161)

<div class="topic-metadata">

**Author:** [@Ulpcan](https://discuss.elastic.co/u/Ulpcan)\
**Replies:** 2\
**Last updated:** [April 30, 2023, 11:11am UTC](https://discuss.elastic.co/t/draw-circle-or-polygons-in-kibana-maps/331161 "2023-04-30T11:11:19Z")

</div>

Hello, There are 2 different fields in my index: location - geo\_point distance - long (we use as km) In kibana maps I would like to visualize: location field as a center of the circle or polygon distance field is t…

---

## [Run time field generates error when trying tutorial](https://discuss.elastic.co/t/run-time-field-generates-error-when-trying-tutorial/330158)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [April 29, 2023, 9:38pm UTC](https://discuss.elastic.co/t/run-time-field-generates-error-when-trying-tutorial/330158 "2023-04-29T21:38:03Z")

</div>

I'm trying to learn how to create run time fields by following the instructions on this page: I tried my own variation with these queries: PUT rfield POST rfield/\_doc { "Favourite Food": "My fave food is" } GET r…

---

## [Logstash gives OOM & CPU Usage too high when used with S3 Input plugin](https://discuss.elastic.co/t/logstash-gives-oom-cpu-usage-too-high-when-used-with-s3-input-plugin/331121)

<div class="topic-metadata">

**Author:** [@Utpal\_Brahma](https://discuss.elastic.co/u/Utpal_Brahma)\
**Replies:** 3\
**Last updated:** [April 29, 2023, 5:25pm UTC](https://discuss.elastic.co/t/logstash-gives-oom-cpu-usage-too-high-when-used-with-s3-input-plugin/331121 "2023-04-29T17:25:38Z")

</div>

Logstash gives out of Memory when S3 plugin is used for a bucket which has already existing tones of files.

---

## [Can't write data to elasticsearch (cannot be changed from type \[date\] to \[text)](https://discuss.elastic.co/t/cant-write-data-to-elasticsearch-cannot-be-changed-from-type-date-to-text/330062)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 21\
**Last updated:** [April 29, 2023, 2:59pm UTC](https://discuss.elastic.co/t/cant-write-data-to-elasticsearch-cannot-be-changed-from-type-date-to-text/330062 "2023-04-29T14:59:19Z")

</div>

Hi can't write data to elasticsearch vi logstash(http\_poller) here is the scenario: influxdb \> logstash(http\_poller) \> elasticsearch error that I get: "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "…

---

## [Elastic defendで取得するログについて](https://discuss.elastic.co/t/elastic-defend/331118)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 0\
**Last updated:** [April 29, 2023, 8:20am UTC](https://discuss.elastic.co/t/elastic-defend/331118 "2023-04-29T08:20:28Z")

</div>

linuxのサーバにelastic agentを導入し、にelastic defend integrationをあてて、logを収集することを検討しています。 そこで疑問です。 Linuxの場合、File、Network、Processのイベントを取得できるようですが、これらは何処で作成されたログになるのでしょうか。 System integrationや、Auditd log integrationなら、設定にファイルを指定する…

---

## [Limiting data integrity risks from compromised client](https://discuss.elastic.co/t/limiting-data-integrity-risks-from-compromised-client/331086)

<div class="topic-metadata">

**Author:** [@nf4ray](https://discuss.elastic.co/u/nf4ray)\
**Replies:** 3\
**Last updated:** [April 29, 2023, 7:49am UTC](https://discuss.elastic.co/t/limiting-data-integrity-risks-from-compromised-client/331086 "2023-04-29T07:49:16Z")

</div>

Let's say I want to monitor the system logs of a cluster of servers with filebeat. Because using one data stream per host doesn't scale well and the cluster is logically part of the same application, they all write to th…

---

## [When is filebeat 8.7.1 available for download](https://discuss.elastic.co/t/when-is-filebeat-8-7-1-available-for-download/331091)

<div class="topic-metadata">

**Author:** [@pavanrangain](https://discuss.elastic.co/u/pavanrangain)\
**Replies:** 2\
**Last updated:** [April 29, 2023, 7:23am UTC](https://discuss.elastic.co/t/when-is-filebeat-8-7-1-available-for-download/331091 "2023-04-29T07:23:59Z")

</div>

Saw this a few days back - Beats version 8.7.1 | Beats Platform Reference \[8.7\] | Elastic But there is no release artifacts present for downloading. When can we expect them to be available ?

---

## [Accessing Bucket aggregation in watcher condition. unexpected token was expecting one of \[{\<EOF\>, ';'}\]](https://discuss.elastic.co/t/accessing-bucket-aggregation-in-watcher-condition-unexpected-token-was-expecting-one-of-eof/331077)

<div class="topic-metadata">

**Author:** [@rahulkothanath](https://discuss.elastic.co/u/rahulkothanath)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 5:02pm UTC](https://discuss.elastic.co/t/accessing-bucket-aggregation-in-watcher-condition-unexpected-token-was-expecting-one-of-eof/331077 "2023-04-28T17:02:29Z")

</div>

I am executing the below watch and want to compare the values of bucket 1D from the aggregation in the watcher condition. However, I am getting errors while accessing the value. POST \_watcher/watch/\_execute { "watch"…

---

## [Logstash filters for log file which is included some raw data and json data](https://discuss.elastic.co/t/logstash-filters-for-log-file-which-is-included-some-raw-data-and-json-data/330950)

<div class="topic-metadata">

**Author:** [@Harish1](https://discuss.elastic.co/u/Harish1)\
**Replies:** 3\
**Last updated:** [April 28, 2023, 5:24pm UTC](https://discuss.elastic.co/t/logstash-filters-for-log-file-which-is-included-some-raw-data-and-json-data/330950 "2023-04-28T17:24:50Z")

</div>

Hi Elastic team, I'm new to ELK, I'm trying to find out the filters for below log file but I'm not able to find the proper Logstash filter for below data 2023-01-19 15:38:31 INFO VCIPDownstreamController:138 - {"timest…

---

## [Disabled xpack security plugin in Kibana 8](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065)

<div class="topic-metadata">

**Author:** [@pchakour](https://discuss.elastic.co/u/pchakour)\
**Replies:** 5\
**Last updated:** [April 28, 2023, 4:55pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065 "2023-04-28T16:55:00Z")

</div>

Hello ! I want to migrate (from 7.16 to 8.6) my own plugin that manage Kibana security with a custom login page and a custom security strategy. Unfortunately, I notice that the xpack.security.enabled configuration disa…

---

## [Filebeat not harvesting newly added records](https://discuss.elastic.co/t/filebeat-not-harvesting-newly-added-records/330603)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 4:52pm UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-newly-added-records/330603 "2023-04-28T16:52:29Z")

</div>

Hi,I have a filebeat which is running on windows server 2019.The data is actively getting written to that log file but it's timestamp changes every 30 mins.I trying to reading log file,but for some reason the newly added…

---

## [How to improve Kibana initial loading time](https://discuss.elastic.co/t/how-to-improve-kibana-initial-loading-time/330619)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-to-improve-kibana-initial-loading-time/330619 "2023-04-28T16:47:26Z")

</div>

I have a Kibana dashboard which contains 7 Vega-lite visualizations & 2 Kibana lens visualizations. Version used: 8.6.1 The dashboard takes around 13-14 sec to load. Most of the time is spent in initial loading of Kiban…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=555)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=557)
