# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=559

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 560

---

## [Fatal exception while booting Elasticsearch](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/330887)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 3:41am UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/330887 "2023-04-27T03:41:39Z")

</div>

Hi community My elasticsearch was Up until that i changed all the passwords. After that i tried starting elasticsearch services and it didn't work. When i saw the logs in /var/log/elasticsearch/elasticsearch.log …

---

## [Python -\> ElasticSearch Data Stream.. i'm doing something wrong.. suggestions](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 3:12am UTC](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874 "2023-04-27T03:12:32Z")

</div>

i'm trying to write a pretty basic python script to bulk insert some ip blacklists into an elasticsearch data stream. this is my code, its basic for now: def bulkESSubmit(self): try: count=1 …

---

## [Why does this field exist in my output even though I have removed this?](https://discuss.elastic.co/t/why-does-this-field-exist-in-my-output-even-though-i-have-removed-this/330890)

<div class="topic-metadata">

**Author:** [@CyberGuy](https://discuss.elastic.co/u/CyberGuy)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 11:15pm UTC](https://discuss.elastic.co/t/why-does-this-field-exist-in-my-output-even-though-i-have-removed-this/330890 "2023-04-26T23:15:39Z")

</div>

HI guys, I'm trying to create a logstash pipeline that parses incoming CEF logs, apply some logic and then outputs the log in JSON format to the console. For some reason, a field is generated with the name "Virtual Syst…

---

## [Certain watches never execute when added via the API](https://discuss.elastic.co/t/certain-watches-never-execute-when-added-via-the-api/330883)

<div class="topic-metadata">

**Author:** [@tang214](https://discuss.elastic.co/u/tang214)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 9:23pm UTC](https://discuss.elastic.co/t/certain-watches-never-execute-when-added-via-the-api/330883 "2023-04-26T21:23:21Z")

</div>

I have certain watches that never execute when being added via the API. The exact same watch json will work fine when added via the UI or Dev Tools Console. The watch code does update when pushed to the API but still won…

---

## [Connect to Elastic Cloud using python client](https://discuss.elastic.co/t/connect-to-elastic-cloud-using-python-client/330875)

<div class="topic-metadata">

**Author:** [@Venkatesh\_Guruprasad](https://discuss.elastic.co/u/Venkatesh_Guruprasad)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 7:22pm UTC](https://discuss.elastic.co/t/connect-to-elastic-cloud-using-python-client/330875 "2023-04-26T19:22:14Z")

</div>

I am using python client to connect to Elastic Cloud. I have tried connecting using basic\_auth and api\_keys. In both instances it gives me the following error elasticsearch.AuthorizationException: AuthorizationException…

---

## [Vega-Lite in Kibana visualization problem](https://discuss.elastic.co/t/vega-lite-in-kibana-visualization-problem/330711)

<div class="topic-metadata">

**Author:** [@martinez06](https://discuss.elastic.co/u/martinez06)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 6:12pm UTC](https://discuss.elastic.co/t/vega-lite-in-kibana-visualization-problem/330711 "2023-04-26T18:12:29Z")

</div>

Hi, Im trying to create a custom vizualization using Vega-Lite in Kibana. I have the source data: syslog\_ip\_address, syslog\_url,syslog\_status. For each ip address i check status of three url and i want to visualise it …

---

## [Elastic search 8.5.3 Aggregations query erroring](https://discuss.elastic.co/t/elastic-search-8-5-3-aggregations-query-erroring/330777)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 13\
**Last updated:** [April 26, 2023, 5:51pm UTC](https://discuss.elastic.co/t/elastic-search-8-5-3-aggregations-query-erroring/330777 "2023-04-26T17:51:13Z")

</div>

Elastic search 8.5.3 not at all running aggregation queries , Even for small index ( just 5 documents ) Below Thread information. Same query works perfectly fine in Elastic Search 7.17 100.2% \[cpu=100.2%, other=0.0%…

---

## [Elastic Stack with Chain of certificates](https://discuss.elastic.co/t/elastic-stack-with-chain-of-certificates/330265)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 5:52pm UTC](https://discuss.elastic.co/t/elastic-stack-with-chain-of-certificates/330265 "2023-04-26T17:52:06Z")

</div>

I want to enable Security when using Filebeat and Logstash. I have created a Root CA. This Root Certificate creates an Intermediate CA. The intermediate CA is then used to create and sign my client and sever certificates…

---

## [Descargar CSV con la búsqueda desde un dashboard](https://discuss.elastic.co/t/descargar-csv-con-la-busqueda-desde-un-dashboard/330706)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 5:40pm UTC](https://discuss.elastic.co/t/descargar-csv-con-la-busqueda-desde-un-dashboard/330706 "2023-04-26T17:40:08Z")

</div>

Buenos días, He creado un dashboard añadiendo una visualización con la búsqueda de un discover. He configurado un rol con permisos de lectura al dashboard y aplicado a un usuario. El problema es que cuando hago una bús…

---

## [Pattern Recognition AML ML model](https://discuss.elastic.co/t/pattern-recognition-aml-ml-model/330371)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 5:30pm UTC](https://discuss.elastic.co/t/pattern-recognition-aml-ml-model/330371 "2023-04-26T17:30:08Z")

</div>

Hi is it possible to do some pattern recognition with Elasticsearch ML? I have a dataset with financial data that looks like this: Timestamp,From Bank,Account,To Bank,Account,Amount Received,Receiving Currency,Amount P…

---

## [How do you limit how long a search query will run for or how much resources one query can use?](https://discuss.elastic.co/t/how-do-you-limit-how-long-a-search-query-will-run-for-or-how-much-resources-one-query-can-use/330858)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 5:04pm UTC](https://discuss.elastic.co/t/how-do-you-limit-how-long-a-search-query-will-run-for-or-how-much-resources-one-query-can-use/330858 "2023-04-26T17:04:53Z")

</div>

My Googlefu must not be strong. When using Elasticsearch 8.x, how does one limit how long a query runs or how many resources a query consumes. We're noticing possible denial of service attacks from certain people running…

---

## [Logstash Output](https://discuss.elastic.co/t/logstash-output/330786)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 3:15pm UTC](https://discuss.elastic.co/t/logstash-output/330786 "2023-04-26T15:15:22Z")

</div>

I have a logstash conf file with multiple output configured In both the outputs i'm using multiple if else statements.Is it possible for the data to get entered in the else statement of both output?

---

## [Index external files](https://discuss.elastic.co/t/index-external-files/330771)

<div class="topic-metadata">

**Author:** [@fabian\_barnich](https://discuss.elastic.co/u/fabian_barnich)\
**Replies:** 5\
**Last updated:** [April 26, 2023, 3:11pm UTC](https://discuss.elastic.co/t/index-external-files/330771 "2023-04-26T15:11:21Z")

</div>

Good morning, I installed elasticsearch and kibana on a VM in debian, my documents that I want to index are on another VM. How can I tell Elasticsearch to index them? Thanks in advance

---

## [Markdown only clickable in a small region at the bottom of the image](https://discuss.elastic.co/t/markdown-only-clickable-in-a-small-region-at-the-bottom-of-the-image/330684)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 2:54pm UTC](https://discuss.elastic.co/t/markdown-only-clickable-in-a-small-region-at-the-bottom-of-the-image/330684 "2023-04-26T14:54:00Z")

</div>

I have upgraded to version 8.7, but still experience an issue that should have been fix as follows: \[Dashboard\] Add styling to allow clickable TSVB markdown images by Heenawter · Pull Request #147802 · elastic/kibana · G…

---

## [After migration from Elasticsearch 6.3 to 7.17 the index size on disk doubled](https://discuss.elastic.co/t/after-migration-from-elasticsearch-6-3-to-7-17-the-index-size-on-disk-doubled/330678)

<div class="topic-metadata">

**Author:** [@igor\_sokolov](https://discuss.elastic.co/u/igor_sokolov)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 2:39pm UTC](https://discuss.elastic.co/t/after-migration-from-elasticsearch-6-3-to-7-17-the-index-size-on-disk-doubled/330678 "2023-04-26T14:39:52Z")

</div>

Hello everyone, I've migrated an Elasticsearch 6.3 cluster to the version of 7.17 (by creating a new cluster with the same index mapping/shard structure and reindexing) and the index size on the disk almost doubled. The…

---

## [Filebeat log format](https://discuss.elastic.co/t/filebeat-log-format/330801)

<div class="topic-metadata">

**Author:** [@evanzhang87](https://discuss.elastic.co/u/evanzhang87)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-log-format/330801 "2023-04-26T14:16:18Z")

</div>

Hello, I'm using latest beats, but my log format is json, {"log.level":"info","@timestamp":"2023-04-26T15:59:22.412+0800","log.origin":{"file.name":"instance/beat.go","file.line":779},"message":"Home path: \[/Users/evan/…

---

## [Fuzzy Search Query using KQL or Lucene](https://discuss.elastic.co/t/fuzzy-search-query-using-kql-or-lucene/330575)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 2:14pm UTC](https://discuss.elastic.co/t/fuzzy-search-query-using-kql-or-lucene/330575 "2023-04-26T14:14:22Z")

</div>

I'm trying to find documents where the host.os.platform field has some words similar to host.os.name for example I want to use Kibana discover either Lucene or KQL for that. This is what I came up with : host.os.plat…

---

## [Elastic agent Does not receive traffic, but it reaches the Linux server](https://discuss.elastic.co/t/elastic-agent-does-not-receive-traffic-but-it-reaches-the-linux-server/330100)

<div class="topic-metadata">

**Author:** [@Razovnyik](https://discuss.elastic.co/u/Razovnyik)\
**Replies:** 7\
**Last updated:** [April 26, 2023, 2:09pm UTC](https://discuss.elastic.co/t/elastic-agent-does-not-receive-traffic-but-it-reaches-the-linux-server/330100 "2023-04-26T14:09:40Z")

</div>

Elasticsearch is configured with a Palo Alto Integration a corresponding Agent Policy and Agent. The Agent itself is installed on an Ubuntu Linux machine: The Ubuntu machine itself receives the traffic: But the …

---

## [\_geoip\_database\_unavailable\_GeoLite2-ASN.mmdb](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 22\
**Last updated:** [April 26, 2023, 1:34pm UTC](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772 "2023-04-26T13:34:16Z")

</div>

Hello there, I am running packetbeat-8.4.3-amd64.deb on a node that i want to monitor and I am shiping the metrics to elastcsearch and kibana. I also added geoip data from Enrich events with geoIP information | Packetbea…

---

## [Elasticsearch upgrade from 2.4.6 to 7.x](https://discuss.elastic.co/t/elasticsearch-upgrade-from-2-4-6-to-7-x/330620)

<div class="topic-metadata">

**Author:** [@iarunava](https://discuss.elastic.co/u/iarunava)\
**Replies:** 7\
**Last updated:** [April 26, 2023, 1:12pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-2-4-6-to-7-x/330620 "2023-04-26T13:12:14Z")

</div>

Hi. Arunava here. Im trying to upgrade elasticsearch 2.4.6 to 7.17.x Im new to elasticsearch. I would appreciate some pointers. The 7.17 stack is ready. and there is a task defined which tries to bulk insert the data …

---

## [ELK stack in windows 11](https://discuss.elastic.co/t/elk-stack-in-windows-11/330832)

<div class="topic-metadata">

**Author:** [@Sardor](https://discuss.elastic.co/u/Sardor)\
**Replies:** 15\
**Last updated:** [April 26, 2023, 1:11pm UTC](https://discuss.elastic.co/t/elk-stack-in-windows-11/330832 "2023-04-26T13:11:08Z")

</div>

I tried to install ELK stack, Elasticsearch, Logstash, Kibana. Elasticsearch and Kibana run succesfully, but logstash returned some exceptions. How can I fix it? This is last logs from logstash : \[2023-04-26T16:45:34,3…

---

## [Ha in two node elasticsearch](https://discuss.elastic.co/t/ha-in-two-node-elasticsearch/330819)

<div class="topic-metadata">

**Author:** [@Monish22](https://discuss.elastic.co/u/Monish22)\
**Replies:** 9\
**Last updated:** [April 26, 2023, 12:58pm UTC](https://discuss.elastic.co/t/ha-in-two-node-elasticsearch/330819 "2023-04-26T12:58:07Z")

</div>

Hi, Currently, we setup two node elasticsearch cluster in my lab and configured ha. We set the both the nodes are master and data. but when the elk01 master node is down, the elk02 doesnt take the leader process. ELK02…

---

## [Monitoring data streams](https://discuss.elastic.co/t/monitoring-data-streams/330759)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 4\
**Last updated:** [April 26, 2023, 12:57pm UTC](https://discuss.elastic.co/t/monitoring-data-streams/330759 "2023-04-26T12:57:18Z")

</div>

Hi, I started to use data streams in my ELK stack. However, I can't see proper data regarding to the indexing rate. "Elasticsearch overview" shows a 20/s indexing rate, and I can't see the backing indices in the "Indice…

---

## [Number format for mustache](https://discuss.elastic.co/t/number-format-for-mustache/330783)

<div class="topic-metadata">

**Author:** [@phong\_elastic](https://discuss.elastic.co/u/phong_elastic)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 12:54pm UTC](https://discuss.elastic.co/t/number-format-for-mustache/330783 "2023-04-26T12:54:00Z")

</div>

Hello everyone. I'm trying to separate the value of a mustache value in the field to index in Elasticsearch Query Alert by thousands. For example the {{ timeresponse}} has a value of 2500000 but now I want to change it …

---

## [New elasticsearch node does not run enrichments](https://discuss.elastic.co/t/new-elasticsearch-node-does-not-run-enrichments/330523)

<div class="topic-metadata">

**Author:** [@FKarraz](https://discuss.elastic.co/u/FKarraz)\
**Replies:** 9\
**Last updated:** [April 26, 2023, 12:40pm UTC](https://discuss.elastic.co/t/new-elasticsearch-node-does-not-run-enrichments/330523 "2023-04-26T12:40:06Z")

</div>

Hello, as I mentioned in enrich processor missing documents, I am facing some issues in my elasticsearch cluster related to document enrichment. I'm opening a new thread as I suspect they are different problems. As the …

---

## [Logstash "Connection Refused"](https://discuss.elastic.co/t/logstash-connection-refused/330748)

<div class="topic-metadata">

**Author:** [@baba72210](https://discuss.elastic.co/u/baba72210)\
**Replies:** 11\
**Last updated:** [April 26, 2023, 12:02pm UTC](https://discuss.elastic.co/t/logstash-connection-refused/330748 "2023-04-26T12:02:12Z")

</div>

Hello, I'm using a docker-compose to start my whole stack and I have a problem with my logstash. I have two errors on my logstash logs. elasticsearch - Failed to perform request {:message=\>"Connect to localhost:9200 \[l…

---

## [Search query builder and mapping](https://discuss.elastic.co/t/search-query-builder-and-mapping/330715)

<div class="topic-metadata">

**Author:** [@SIMONE2](https://discuss.elastic.co/u/SIMONE2)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 11:55am UTC](https://discuss.elastic.co/t/search-query-builder-and-mapping/330715 "2023-04-26T11:55:11Z")

</div>

Hello everyone, I inherited the mapping of a service (JAVA SPRING BOOT)with Elasticsearch and I'm going crazy for the search. my field is so mapped: "organizationNames":{ "type":"text", "fields":{ …

---

## [Filestream not processing new log messages](https://discuss.elastic.co/t/filestream-not-processing-new-log-messages/330830)

<div class="topic-metadata">

**Author:** [@yohny](https://discuss.elastic.co/u/yohny)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 11:40am UTC](https://discuss.elastic.co/t/filestream-not-processing-new-log-messages/330830 "2023-04-26T11:40:30Z")

</div>

Hi all, I have a filebeat configured to consume log files using filestream and send them to kibana like this: filebeat.inputs: - type: filestream id: my-stream enabled: true paths: - C:\\my-app\\log…

---

## [Elasticsearch 6.8.23 happen OOM](https://discuss.elastic.co/t/elasticsearch-6-8-23-happen-oom/330802)

<div class="topic-metadata">

**Author:** [@yunpeng.jiangyp](https://discuss.elastic.co/u/yunpeng.jiangyp)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 11:37am UTC](https://discuss.elastic.co/t/elasticsearch-6-8-23-happen-oom/330802 "2023-04-26T11:37:05Z")

</div>

Hi, We have a 8core/16GB ( 4 nodes cluster ) for the Elasticsearch and the Elasticsearch process is getting killed. JDK settings -Xms8g -Xmx8g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSI…

---

## [Search templates with nested query](https://discuss.elastic.co/t/search-templates-with-nested-query/330745)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 11:25am UTC](https://discuss.elastic.co/t/search-templates-with-nested-query/330745 "2023-04-26T11:25:41Z")

</div>

Hi everyone. I'm trying to make a search template with bool query. This bool query uses 'should' operator, which searches data throgh 4 fields of index. These results than must be filtered by two fields, so I try to use…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=558)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=560)
