# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=558

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 559

---

## [Elastic metric count to percentage](https://discuss.elastic.co/t/elastic-metric-count-to-percentage/330806)

<div class="topic-metadata">

**Author:** [@Prathamesh\_S\_Pai](https://discuss.elastic.co/u/Prathamesh_S_Pai)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 5:01pm UTC](https://discuss.elastic.co/t/elastic-metric-count-to-percentage/330806 "2023-04-27T17:01:04Z")

</div>

I am using metric visualization type in kibana. In Metric section, I have used 'count' aggregation and in bucket section, i have used 'terms' aggregation with field 'executionStatus.keyword' and clicked on 'update' butt…

---

## [Handling ambiguous field names in search query](https://discuss.elastic.co/t/handling-ambiguous-field-names-in-search-query/329941)

<div class="topic-metadata">

**Author:** [@denvaar](https://discuss.elastic.co/u/denvaar)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:59pm UTC](https://discuss.elastic.co/t/handling-ambiguous-field-names-in-search-query/329941 "2023-04-27T16:59:25Z")

</div>

I have a query that I run against multiple indices. Some of the indices being searched share some common field names, and I'm not sure what the best way to differentiate between them would be. I can get the desired resu…

---

## [Export Users Data Traffic](https://discuss.elastic.co/t/export-users-data-traffic/330937)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:58pm UTC](https://discuss.elastic.co/t/export-users-data-traffic/330937 "2023-04-27T16:58:47Z")

</div>

Hello everyone. I want to export all users' Traffic Data. How can I do ?

---

## [Custom Charting](https://discuss.elastic.co/t/custom-charting/330968)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:57pm UTC](https://discuss.elastic.co/t/custom-charting/330968 "2023-04-27T16:57:55Z")

</div>

Hi, Is it possible to create a chart which shows data for today overlaid against the same data from yesterday in order to compare patterns and volumes? Thx D

---

## [Discovery.seed\_hosts and cluster.initial\_master\_nodes](https://discuss.elastic.co/t/discovery-seed-hosts-and-cluster-initial-master-nodes/330945)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 4:43pm UTC](https://discuss.elastic.co/t/discovery-seed-hosts-and-cluster-initial-master-nodes/330945 "2023-04-27T16:43:40Z")

</div>

I'm struggling to understand the discovery settings now that discovery.zen.minimum\_master\_nodes has gone away. (where current is 8.7) says that discovery.seed\_hosts Provides a list of the addresses of the master-el…

---

## [Kibana Embedding URL](https://discuss.elastic.co/t/kibana-embedding-url/330876)

<div class="topic-metadata">

**Author:** [@Venkatesh\_Guruprasad](https://discuss.elastic.co/u/Venkatesh_Guruprasad)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:25pm UTC](https://discuss.elastic.co/t/kibana-embedding-url/330876 "2023-04-27T16:25:17Z")

</div>

We are using Elastic Cloud currently. We are enabling embedded URL's of Kibana dashboards in our app. We want to just show the filters applied panel in the embedded URL. This is the scenario where users apply a filter on…

---

## [How to color a header in table lens](https://discuss.elastic.co/t/how-to-color-a-header-in-table-lens/330851)

<div class="topic-metadata">

**Author:** [@fatousouleymane.mben](https://discuss.elastic.co/u/fatousouleymane.mben)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 3:36pm UTC](https://discuss.elastic.co/t/how-to-color-a-header-in-table-lens/330851 "2023-04-27T15:36:43Z")

</div>

how to color a header in table lens

---

## [Kibana not updating index in Discover](https://discuss.elastic.co/t/kibana-not-updating-index-in-discover/330885)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 11\
**Last updated:** [April 27, 2023, 3:30pm UTC](https://discuss.elastic.co/t/kibana-not-updating-index-in-discover/330885 "2023-04-27T15:30:19Z")

</div>

Hi All, I see this issue where Kibana is not updating index on the "Discover" page while there is a definite increase in the size of the related index. Also for some reason Discover page shows data with one hour interva…

---

## [Return JSON Array of Arrays from elastic](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 3:23pm UTC](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971 "2023-04-27T15:23:10Z")

</div>

Hi, We've noticed that the overhead of the JSON object structure is creating some performance problems for us. One of the largest parts of this overhead is the repetitiveness of the object properties in each object. We'…

---

## [Protobuf data decode issue](https://discuss.elastic.co/t/protobuf-data-decode-issue/330976)

<div class="topic-metadata">

**Author:** [@Nithingowda](https://discuss.elastic.co/u/Nithingowda)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 3:21pm UTC](https://discuss.elastic.co/t/protobuf-data-decode-issue/330976 "2023-04-27T15:21:12Z")

</div>

Here is the code to read the protobuf data from pubsub and decode in logstash but we are unable to decode the protobuf data. Code: input { google\_pubsub { project\_id =\> "project\_id" topic =\> "topic…

---

## [Can logstash.yml can be reloaded?](https://discuss.elastic.co/t/can-logstash-yml-can-be-reloaded/330942)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 2:42pm UTC](https://discuss.elastic.co/t/can-logstash-yml-can-be-reloaded/330942 "2023-04-27T14:42:34Z")

</div>

We have deployed logstash in kubernetes platform. For one usecase we want to update queue.page\_capacity: 64mb to 1mb. So if we update these changes it can't be reloaded until restart. So is there any way so that this ca…

---

## [Logstash startup error-) Could not load FFI Provider: (NotImplementedError) FFI not available](https://discuss.elastic.co/t/logstash-startup-error-could-not-load-ffi-provider-notimplementederror-ffi-not-available/330904)

<div class="topic-metadata">

**Author:** [@karthic](https://discuss.elastic.co/u/karthic)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 2:40pm UTC](https://discuss.elastic.co/t/logstash-startup-error-could-not-load-ffi-provider-notimplementederror-ffi-not-available/330904 "2023-04-27T14:40:32Z")

</div>

Tried to load logstash in a Centos environment \[INFO \]\[logstash.runner \] JVM bootstrap flags: \[-Xms1g, -Xmx1g, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djruby.compile.invokedynamic=true, -XX:+HeapDumpO…

---

## [Collect logs from multiple machine, what needs to be installed?](https://discuss.elastic.co/t/collect-logs-from-multiple-machine-what-needs-to-be-installed/330833)

<div class="topic-metadata">

**Author:** [@Jay\_Timbadia](https://discuss.elastic.co/u/Jay_Timbadia)\
**Replies:** 5\
**Last updated:** [April 27, 2023, 1:53pm UTC](https://discuss.elastic.co/t/collect-logs-from-multiple-machine-what-needs-to-be-installed/330833 "2023-04-27T13:53:56Z")

</div>

Continuing the discussion from How to collect the logs from multiple machines to my server efficiently?: Hi @jsoriano, really followed the chat. Just one thing, I have logs placed in different machine, so should I insta…

---

## [ESET Protect Cloud logs](https://discuss.elastic.co/t/eset-protect-cloud-logs/330925)

<div class="topic-metadata">

**Author:** [@rodmontgt](https://discuss.elastic.co/u/rodmontgt)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 1:50pm UTC](https://discuss.elastic.co/t/eset-protect-cloud-logs/330925 "2023-04-27T13:50:24Z")

</div>

Hi everyone, I've been playing around with logtash for days but still have not found a solution for this, my ESET console is configured to send syslog/BSD logs but I am getting this odd character set in my logstash inst…

---

## [Failed to start Logstash - S3 output plugin is not working](https://discuss.elastic.co/t/failed-to-start-logstash-s3-output-plugin-is-not-working/330096)

<div class="topic-metadata">

**Author:** [@WonhyeongCho](https://discuss.elastic.co/u/WonhyeongCho)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 1:46pm UTC](https://discuss.elastic.co/t/failed-to-start-logstash-s3-output-plugin-is-not-working/330096 "2023-04-27T13:46:17Z")

</div>

Hi. I'm using Logstash. I recently upgraded Logstash to version 8.7.0, but it's not working. I'm getting an error message. Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:OSQUERY, :excep…

---

## [File input plugin is treating the line as plain string eventhough the input is json](https://discuss.elastic.co/t/file-input-plugin-is-treating-the-line-as-plain-string-eventhough-the-input-is-json/330713)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 10\
**Last updated:** [April 27, 2023, 12:48pm UTC](https://discuss.elastic.co/t/file-input-plugin-is-treating-the-line-as-plain-string-eventhough-the-input-is-json/330713 "2023-04-27T12:48:22Z")

</div>

File input plugin is treating the line as plain string eventhough the input is json. Output in Opensearch is : { "\_index" : "sample-logs-2023.04.24", "\_type" : "\_doc", "\_id" : "ui9PsocBICgSyzdw…

---

## [Kibana too many docvalue\_fields issue](https://discuss.elastic.co/t/kibana-too-many-docvalue-fields-issue/329981)

<div class="topic-metadata">

**Author:** [@Prakash111](https://discuss.elastic.co/u/Prakash111)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 11:36am UTC](https://discuss.elastic.co/t/kibana-too-many-docvalue-fields-issue/329981 "2023-04-27T11:36:05Z")

</div>

I'm getting too many docvalue\_fields error in Kibana. PUT /index\_name\_log-\*/\_settings { "index.max\_docvalue\_fields\_search" : "10000000" } by this way we can increase limit, but can I know which log line causing this…

---

## [Bucket Selector Aggregation to eliminate null buckets](https://discuss.elastic.co/t/bucket-selector-aggregation-to-eliminate-null-buckets/330943)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 10:58am UTC](https://discuss.elastic.co/t/bucket-selector-aggregation-to-eliminate-null-buckets/330943 "2023-04-27T10:58:29Z")

</div>

I'm trying to use the Bucket Selector aggregation to eliminate Null values from other pipeline aggregations without success First Try of null checking: "bucket\_filter": { "bucket\_selector": { "buc…

---

## [ElasticSearch 8.7 initial single node setting fails](https://discuss.elastic.co/t/elasticsearch-8-7-initial-single-node-setting-fails/330870)

<div class="topic-metadata">

**Author:** [@Pfiffikus](https://discuss.elastic.co/u/Pfiffikus)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-initial-single-node-setting-fails/330870 "2023-04-27T07:22:09Z")

</div>

I get elasticsearch-create-enrollment-token -s kibana ERROR: Failed to determine the health of the cluster. Unexpected http status \[401\] for xpack: security: authc: realms: file: file1: …

---

## [Execute a script inside a core application added by a plugin](https://discuss.elastic.co/t/execute-a-script-inside-a-core-application-added-by-a-plugin/330755)

<div class="topic-metadata">

**Author:** [@LucasE](https://discuss.elastic.co/u/LucasE)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 9:58am UTC](https://discuss.elastic.co/t/execute-a-script-inside-a-core-application-added-by-a-plugin/330755 "2023-04-27T09:58:29Z")

</div>

Hello everyone, I'm using Kibana v8.3.3 and i'm trying to modify the DOM of my dashboard. For this I tried to use a chrome extension and it worked but I want to explore another option. I tried creating a SPA and embed…

---

## [Updating Custom HTTP ingestion results in a 504 error](https://discuss.elastic.co/t/updating-custom-http-ingestion-results-in-a-504-error/330879)

<div class="topic-metadata">

**Author:** [@chenderson](https://discuss.elastic.co/u/chenderson)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 9:46am UTC](https://discuss.elastic.co/t/updating-custom-http-ingestion-results-in-a-504-error/330879 "2023-04-27T09:46:27Z")

</div>

I have added an integration to my stack running in Azure Kubernetes using the "Custom HTTP" integration. When I first create the integration everything works as expected and documents are ingested when I send them to th…

---

## [Using Sort API via Elastic.Clients.Elasticsearch 8.1.0 .NET](https://discuss.elastic.co/t/using-sort-api-via-elastic-clients-elasticsearch-8-1-0-net/330908)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 9:37am UTC](https://discuss.elastic.co/t/using-sort-api-via-elastic-clients-elasticsearch-8-1-0-net/330908 "2023-04-27T09:37:32Z")

</div>

I have an Elasticsearch cluster, which contains an index called persons. I want to query and sort the documents of the index using the latest Elasticsearch client for .NET (Elastic.Clients.Elasticsearch 8.1.0 .NET). The …

---

## [Knn to show results for 'Other Locations you may like'](https://discuss.elastic.co/t/knn-to-show-results-for-other-locations-you-may-like/330933)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:29am UTC](https://discuss.elastic.co/t/knn-to-show-results-for-other-locations-you-may-like/330933 "2023-04-27T09:29:40Z")

</div>

I want to create Proximity Search/Reccomendation with Location data. so my search results should have results - 'Other Locations you may like'. My data has Geo ID and Pincode for Location data. I was thinking of creati…

---

## [Best practice for running Elastic Agents in EKS](https://discuss.elastic.co/t/best-practice-for-running-elastic-agents-in-eks/330931)

<div class="topic-metadata">

**Author:** [@mikkoc](https://discuss.elastic.co/u/mikkoc)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:16am UTC](https://discuss.elastic.co/t/best-practice-for-running-elastic-agents-in-eks/330931 "2023-04-27T09:16:11Z")

</div>

Hello, We run Elastic Agents via Fleet in our EKS cluster, as DaemonSet, with about 20 nodes. We want to monitor and collect AWS Cloudwatch metrics, in addition to Kubernetes logs on each node. How do we go about inst…

---

## [How to parse API HTTP output data](https://discuss.elastic.co/t/how-to-parse-api-http-output-data/330829)

<div class="topic-metadata">

**Author:** [@sonirajil](https://discuss.elastic.co/u/sonirajil)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 9:00am UTC](https://discuss.elastic.co/t/how-to-parse-api-http-output-data/330829 "2023-04-27T09:00:03Z")

</div>

Hello Team, I am running an API to get servicestatus data which looks like : { "recordcount": 11906, "servicestatus": \[ { "host\_name": "unixteam.abc.com", "service\_description": …

---

## [Retrieve the value of ca\_trusted\_fingerprint](https://discuss.elastic.co/t/retrieve-the-value-of-ca-trusted-fingerprint/330923)

<div class="topic-metadata">

**Author:** [@Jaud](https://discuss.elastic.co/u/Jaud)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 8:43am UTC](https://discuss.elastic.co/t/retrieve-the-value-of-ca-trusted-fingerprint/330923 "2023-04-27T08:43:06Z")

</div>

Hello here. I was trying to configure my kibana and I've deleted the ca\_trusted\_fingerprint value. I searched online for any solution but I founded nothing. Do you know where can I found this value? Thank for reading …

---

## [Elasticsearch.Net.UnexpectedElasticsearchClientException: expected:'{', actual:'\[', at offset:13520](https://discuss.elastic.co/t/elasticsearch-net-unexpectedelasticsearchclientexception-expected-actual-at-offset-13520/330290)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 6\
**Last updated:** [April 27, 2023, 8:23am UTC](https://discuss.elastic.co/t/elasticsearch-net-unexpectedelasticsearchclientexception-expected-actual-at-offset-13520/330290 "2023-04-27T08:23:08Z")

</div>

Hello I am updating a project to a the new NEST version: 7.17 But keep getting this error from the logging: Elasticsearch.Net.UnexpectedElasticsearchClientException: expected:'{', actual:'\[', at offset:13520 ---\> Elas…

---

## [Wrong documents' count after inserting](https://discuss.elastic.co/t/wrong-documents-count-after-inserting/330284)

<div class="topic-metadata">

**Author:** [@Gregory\_Kovalchuk](https://discuss.elastic.co/u/Gregory_Kovalchuk)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 8:07am UTC](https://discuss.elastic.co/t/wrong-documents-count-after-inserting/330284 "2023-04-27T08:07:51Z")

</div>

Hello, please help, I inserted data with spark several times but the count was all the time bigger than expected, how it can be? The version of ES is 8.5.0. The query that I used to check: GET index/\_count.

---

## ["sync" command in Transform API](https://discuss.elastic.co/t/sync-command-in-transform-api/328960)

<div class="topic-metadata">

**Author:** [@SEUNGHYO](https://discuss.elastic.co/u/SEUNGHYO)\
**Replies:** 6\
**Last updated:** [April 27, 2023, 7:52am UTC](https://discuss.elastic.co/t/sync-command-in-transform-api/328960 "2023-04-27T07:52:28Z")

</div>

When a new document is indexed I want to implement a transform instance in which the transform index (dest) is updated every period of "frequency". This is the query I executed. PUT \_transform/test\_transform\_instance …

---

## [Handling Kuberenets Labels Mapping Conflict](https://discuss.elastic.co/t/handling-kuberenets-labels-mapping-conflict/330915)

<div class="topic-metadata">

**Author:** [@Noa](https://discuss.elastic.co/u/Noa)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 7:50am UTC](https://discuss.elastic.co/t/handling-kuberenets-labels-mapping-conflict/330915 "2023-04-27T07:50:35Z")

</div>

I have two kinds of labels which are causing a mapping conflict: app: \* vs. app.kubernetes.io/instance: \* (type text vs. type object) The second label is predefined by Kubernetes and is used to differentiate between d…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=557)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=559)
