# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=560

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 561

---

## [Help on using stored filed in side a query](https://discuss.elastic.co/t/help-on-using-stored-filed-in-side-a-query/330825)

<div class="topic-metadata">

**Author:** [@sreekanth\_makam](https://discuss.elastic.co/u/sreekanth_makam)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 11:08am UTC](https://discuss.elastic.co/t/help-on-using-stored-filed-in-side-a-query/330825 "2023-04-26T11:08:44Z")

</div>

I have index1 and index2. Running below query against Index1 where i point to index2. In indexs those fields created with stored option. Please help on this query. POST /Index1/\_search { "query": { "bool": {…

---

## [Map Composite Aggregation Payload in Java using Java Client 8.7](https://discuss.elastic.co/t/map-composite-aggregation-payload-in-java-using-java-client-8-7/330754)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 7:04am UTC](https://discuss.elastic.co/t/map-composite-aggregation-payload-in-java-using-java-client-8-7/330754 "2023-04-26T07:04:41Z")

</div>

{ "buckets": \[ { "key": { "SUBJNAME": "ALL", "ASOFYEARS": 2018 }, "doc\_count": 240, "cnt\_subj": { "value": 25521935824 }, "cnt\_dwnl": { "value": 4…

---

## [Mocking the .net client](https://discuss.elastic.co/t/mocking-the-net-client/330147)

<div class="topic-metadata">

**Author:** [@samlane](https://discuss.elastic.co/u/samlane)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 9:42am UTC](https://discuss.elastic.co/t/mocking-the-net-client/330147 "2023-04-26T09:42:23Z")

</div>

In 8.0 Release notes it mentions: " In order to support user testing scenarios, we have unsealed the ElasticsearchClient type and made its methods virtual. This supports mocking the type directly for unit testing." I h…

---

## [Logstash : Codec multiline problem](https://discuss.elastic.co/t/logstash-codec-multiline-problem/330812)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 9:20am UTC](https://discuss.elastic.co/t/logstash-codec-multiline-problem/330812 "2023-04-26T09:20:11Z")

</div>

Each time logstash try to parse a log like this : 09-Mar-2023 16:45:40.861 SEVERE \[main\] org.apache.catalina.core.StandardContext.listenerStart Exception sending context initialized event to listener instance of class \[…

---

## [Elasticsearch 8.7.0 High Heap Usage](https://discuss.elastic.co/t/elasticsearch-8-7-0-high-heap-usage/330730)

<div class="topic-metadata">

**Author:** [@esi](https://discuss.elastic.co/u/esi)\
**Replies:** 6\
**Last updated:** [April 26, 2023, 9:00am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-0-high-heap-usage/330730 "2023-04-26T09:00:28Z")

</div>

Hello, we have a 3 node cluster one loadbalancer node, one slave node and one master node running with latest Ubuntu 22.04.2 and Elasticsearch with Kibana on version 8.7.0. The master and slave system has 4 CPUs and 64 G…

---

## [Module s3 input does not work error](https://discuss.elastic.co/t/module-s3-input-does-not-work-error/329522)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 8:11am UTC](https://discuss.elastic.co/t/module-s3-input-does-not-work-error/329522 "2023-04-26T08:11:58Z")

</div>

Hi all, ran into this problem. At some point after upgrading from version 7 to 8, my S3 input module stopped working correctly. I see in the logs that the module connects to S3 and that it tries to deduct the content, …

---

## [Response from SQL query does not contain "Rows" (Elastic.Clients.Elasticsearch 8.1.0 .NET)](https://discuss.elastic.co/t/response-from-sql-query-does-not-contain-rows-elastic-clients-elasticsearch-8-1-0-net/330791)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 7:28am UTC](https://discuss.elastic.co/t/response-from-sql-query-does-not-contain-rows-elastic-clients-elasticsearch-8-1-0-net/330791 "2023-04-26T07:28:29Z")

</div>

I have an Elasticsearch cluster, which contains an index called persons. I want to query the documents of the index using the SQL API of Elasticsearch. When using the REST API of Elasticsearch via Kibana everything works…

---

## [Failed to update mapping for index, failure org.elasticsearch.index.mapper.MapperParsingException: Failed to parse mapping: analyzer \[jobtitle\_synonym\_analyzer\] contains filters \[jobtitle\_synonym\_filter\] that are not allowed to run in index time mode](https://discuss.elastic.co/t/failed-to-update-mapping-for-index-failure-org-elasticsearch-index-mapper-mapperparsingexception-failed-to-parse-mapping-analyzer-jobtitle-synonym-analyzer-contains-filters-jobtitle-synonym-filter-that-are-not-allowed-to-run-in-index-time-mode/330785)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 6\
**Last updated:** [April 26, 2023, 5:51am UTC](https://discuss.elastic.co/t/failed-to-update-mapping-for-index-failure-org-elasticsearch-index-mapper-mapperparsingexception-failed-to-parse-mapping-analyzer-jobtitle-synonym-analyzer-contains-filters-jobtitle-synonym-filter-that-are-not-allowed-to-run-in-index-time-mode/330785 "2023-04-26T05:51:19Z")

</div>

When I restore the Index with the use of snapshot, It restored successfully but, I am getting an error called all shards are failed. When I search for an Explaination It shows that failed to update mapping for index, fai…

---

## [Kibana dashboard filter doesn't work](https://discuss.elastic.co/t/kibana-dashboard-filter-doesnt-work/330675)

<div class="topic-metadata">

**Author:** [@tonyaw](https://discuss.elastic.co/u/tonyaw)\
**Replies:** 10\
**Last updated:** [April 26, 2023, 5:44am UTC](https://discuss.elastic.co/t/kibana-dashboard-filter-doesnt-work/330675 "2023-04-26T05:44:25Z")

</div>

I created a Kibana dashboard contains a Lens visualization. I'm trying to use filter to get data for "cluster\_id == 77" OR "cluster\_id==80", But what Lens shows is cluster\_id == from 77 to 80. Could you please help to …

---

## [Trying to transform data from one index to another by applying pipeline in transform,But pipeline is executing only first half of it till Android filter](https://discuss.elastic.co/t/trying-to-transform-data-from-one-index-to-another-by-applying-pipeline-in-transform-but-pipeline-is-executing-only-first-half-of-it-till-android-filter/330721)

<div class="topic-metadata">

**Author:** [@Chinmay\_Bhusate](https://discuss.elastic.co/u/Chinmay_Bhusate)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 5:35am UTC](https://discuss.elastic.co/t/trying-to-transform-data-from-one-index-to-another-by-applying-pipeline-in-transform-but-pipeline-is-executing-only-first-half-of-it-till-android-filter/330721 "2023-04-26T05:35:14Z")

</div>

Sharing my transform alongwith Pipeline. Transform POST \_transform/\_preview { "source": { "index": \[ "events.test" \] }, "pivot": { "group\_by": { "session\_id": { "terms": { …

---

## [Use JSON as input for Packetbeat](https://discuss.elastic.co/t/use-json-as-input-for-packetbeat/330763)

<div class="topic-metadata">

**Author:** [@callamby5](https://discuss.elastic.co/u/callamby5)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 4:11am UTC](https://discuss.elastic.co/t/use-json-as-input-for-packetbeat/330763 "2023-04-26T04:11:09Z")

</div>

I am trying to use packetbeat to view a pcap file in Kibana. I have converted my pcap file into json because I know that is the type of file that packetbeat can take in. I used the command: C:\\Program Files\\Packetbeat\>.…

---

## [Change 4000 fields in my index](https://discuss.elastic.co/t/change-4000-fields-in-my-index/330504)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 11:22pm UTC](https://discuss.elastic.co/t/change-4000-fields-in-my-index/330504 "2023-04-25T23:22:03Z")

</div>

I have nested json documents with about 4000 fields. To change the field type, I understand I have to reindex with a new index and updated mapping. But what if i want to change like 2500 fields? is there an alternative w…

---

## [Elasticsearch slow at the beginning of searching , and segment memory is 0](https://discuss.elastic.co/t/elasticsearch-slow-at-the-beginning-of-searching-and-segment-memory-is-0/330638)

<div class="topic-metadata">

**Author:** [@yuhan\_zhang2](https://discuss.elastic.co/u/yuhan_zhang2)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 11:08pm UTC](https://discuss.elastic.co/t/elasticsearch-slow-at-the-beginning-of-searching-and-segment-memory-is-0/330638 "2023-04-25T23:08:14Z")

</div>

When I was testing the performance on 10 millions of docs, I found the performance was really bad at the beginning (~20s) but fast after thousands of search. Then I use \_cat/segments?v=true to check my segments and t…

---

## [Warning Observed after integrating with Active Directory](https://discuss.elastic.co/t/warning-observed-after-integrating-with-active-directory/330631)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 11:03pm UTC](https://discuss.elastic.co/t/warning-observed-after-integrating-with-active-directory/330631 "2023-04-25T23:03:31Z")

</div>

Hi team, We have a cluster running with docker with multiple nodes. The cluster is a licensed cluster and we recently enabled TLS security on the cluster. We have enabled TLS security for node-to-node communication. We …

---

## [Want to use shorten URL functionality of Kibana to generate id of dashboard](https://discuss.elastic.co/t/want-to-use-shorten-url-functionality-of-kibana-to-generate-id-of-dashboard/330648)

<div class="topic-metadata">

**Author:** [@aman\_giri](https://discuss.elastic.co/u/aman_giri)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 11:02pm UTC](https://discuss.elastic.co/t/want-to-use-shorten-url-functionality-of-kibana-to-generate-id-of-dashboard/330648 "2023-04-25T23:02:33Z")

</div>

Hello, everyone I have this public URL that I want to show publicly but it has multiple parameters that can be seen in the URL so I wanted to be short . I was going through Shorten URL | Kibana User Guide \[6.7\] | Elast…

---

## [Changing IP on a running cluster](https://discuss.elastic.co/t/changing-ip-on-a-running-cluster/330673)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 10:58pm UTC](https://discuss.elastic.co/t/changing-ip-on-a-running-cluster/330673 "2023-04-25T22:58:14Z")

</div>

Hello, We have a ELK 7.6.2 stack cluster (3 Master and 5 Data nodes) running in our Production environment. We need to migrate the servers (Cloud VMs) to a more robust ones. This process would result in changing the I…

---

## [Delete indices by date (Elasticsearch 8.7)](https://discuss.elastic.co/t/delete-indices-by-date-elasticsearch-8-7/330750)

<div class="topic-metadata">

**Author:** [@Suren\_Baboyan](https://discuss.elastic.co/u/Suren_Baboyan)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 10:46pm UTC](https://discuss.elastic.co/t/delete-indices-by-date-elasticsearch-8-7/330750 "2023-04-25T22:46:49Z")

</div>

Hello. I created index from logstash (%{\[project\]\[name\]}-%{\[project\]\[service\]}-%{+YYYY.MM.dd}), and I want to keep only last 10 days logs. How can I delete automatically older data?

---

## [Elastic monitoring default retention period](https://discuss.elastic.co/t/elastic-monitoring-default-retention-period/330723)

<div class="topic-metadata">

**Author:** [@Mateusz\_Migala](https://discuss.elastic.co/u/Mateusz_Migala)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 9:57am UTC](https://discuss.elastic.co/t/elastic-monitoring-default-retention-period/330723 "2023-04-25T09:57:54Z")

</div>

Hey, If I ship the metrics and logs to Elastic monitoring cluster using this feature: What is the default retention period for this data and how can I modify it ? I've found some threads in the forum where this ques…

---

## [Elasticsearch Querying a document to grab field using another documents field value](https://discuss.elastic.co/t/elasticsearch-querying-a-document-to-grab-field-using-another-documents-field-value/330411)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 10:32pm UTC](https://discuss.elastic.co/t/elasticsearch-querying-a-document-to-grab-field-using-another-documents-field-value/330411 "2023-04-25T22:32:25Z")

</div>

Hello all, I'm unable to find documentation on the following which I believe might be a niche implementation, but will try to explain the best I can. My inexperience aside, at first glance this seems to probably relate …

---

## [Connecting Filebeat from local machine to existing logstash pipeline](https://discuss.elastic.co/t/connecting-filebeat-from-local-machine-to-existing-logstash-pipeline/330764)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 9:08pm UTC](https://discuss.elastic.co/t/connecting-filebeat-from-local-machine-to-existing-logstash-pipeline/330764 "2023-04-25T21:08:47Z")

</div>

I'm attempting to push logs from my local machine using Filebeats through an existing logstash collector node to an existing elastic index. Here is my filebeat.yml file: filebeat.inputs: - type: log enabled: true pa…

---

## [Metricbeat 8.7.0 mysql 8, performance module, 1400+ event rate/sec, 16gb an hour](https://discuss.elastic.co/t/metricbeat-8-7-0-mysql-8-performance-module-1400-event-rate-sec-16gb-an-hour/330769)

<div class="topic-metadata">

**Author:** [@ensemblebd](https://discuss.elastic.co/u/ensemblebd)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 8:44pm UTC](https://discuss.elastic.co/t/metricbeat-8-7-0-mysql-8-performance-module-1400-event-rate-sec-16gb-an-hour/330769 "2023-04-25T20:44:25Z")

</div>

Topic title really says it all. My database has well over 100 databases, most are wordpress - so that's at least 15 tables per. And the module runs the following query: SELECT object\_schema, object\_name, index\_name, c…

---

## [Sending logs from filebeat(WIndows) to Logstash and Elasticsearch(RHEL)](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-and-elasticsearch-rhel/330499)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 7:52pm UTC](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-and-elasticsearch-rhel/330499 "2023-04-25T19:52:48Z")

</div>

Hi, I have installed filebeat on my windows machine. I've enabled the systema nd logstash module. Here is the filebeat.yml - type: filestream # Unique ID among all inputs, an ID is required. id: my-filestream-id …

---

## [Use logstash as a central logging server for log files exported from various devices](https://discuss.elastic.co/t/use-logstash-as-a-central-logging-server-for-log-files-exported-from-various-devices/330689)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 6:21pm UTC](https://discuss.elastic.co/t/use-logstash-as-a-central-logging-server-for-log-files-exported-from-various-devices/330689 "2023-04-25T18:21:55Z")

</div>

Hi All, I want to use logstash as a central logging server for storing log files exported from various devices. The log files can contain structured as well as un-structured data. Also I would like to store binary files…

---

## [Connecting logstash to remote elasticsearch running on https with no port specified](https://discuss.elastic.co/t/connecting-logstash-to-remote-elasticsearch-running-on-https-with-no-port-specified/330587)

<div class="topic-metadata">

**Author:** [@Yahia-M](https://discuss.elastic.co/u/Yahia-M)\
**Replies:** 4\
**Last updated:** [April 25, 2023, 3:31pm UTC](https://discuss.elastic.co/t/connecting-logstash-to-remote-elasticsearch-running-on-https-with-no-port-specified/330587 "2023-04-25T15:31:29Z")

</div>

Hello , i am running Elasticsearch on a website called Cloud IDE gitpod. Once i start the docker image on the gitpod, docker-compose up --build Elasticsearch will start successfully i get a full https public url to ac…

---

## [Bulk upload in Elasticsearch 6.8.19 using python](https://discuss.elastic.co/t/bulk-upload-in-elasticsearch-6-8-19-using-python/330752)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 3:25pm UTC](https://discuss.elastic.co/t/bulk-upload-in-elasticsearch-6-8-19-using-python/330752 "2023-04-25T15:25:47Z")

</div>

Due to some reasons, I need to upload bulk csv data in Elasticsearch 6.8.19. Can someone provide me a piece of code for that. The latest version python code is not working for obvious reasons.

---

## [Kibana connection without enrollment token](https://discuss.elastic.co/t/kibana-connection-without-enrollment-token/330728)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 2:58pm UTC](https://discuss.elastic.co/t/kibana-connection-without-enrollment-token/330728 "2023-04-25T14:58:07Z")

</div>

Can we connect to elasticsearch using Kibana without the enrollment token and username-password? I tried sometime back, then it was not mandatory to provide enrollment token. Even tried setting xpack.security.enrollmen…

---

## [Kibana Table - Cell Text gets truncated](https://discuss.elastic.co/t/kibana-table-cell-text-gets-truncated/330407)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 8\
**Last updated:** [April 25, 2023, 2:12pm UTC](https://discuss.elastic.co/t/kibana-table-cell-text-gets-truncated/330407 "2023-04-25T14:12:09Z")

</div>

Hi Elastic Gurus, I have created a table in Kibana Dashboard and some cells have large amount of text. Is there a text wrap functionality or ability to resize the cell so that we can view the full data without get trim…

---

## [ELK stack lifecycle management](https://discuss.elastic.co/t/elk-stack-lifecycle-management/330663)

<div class="topic-metadata">

**Author:** [@mphilip9](https://discuss.elastic.co/u/mphilip9)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elk-stack-lifecycle-management/330663 "2023-04-25T13:28:27Z")

</div>

I just took over an ELK stack app and I want to set up some proper index lifecycle management policies. From my understanding, I create an index lifecycle policy, and then I add/associate that policy with an index templa…

---

## [Elasticsearch.Net.ElasticsearchClientException](https://discuss.elastic.co/t/elasticsearch-net-elasticsearchclientexception/330735)

<div class="topic-metadata">

**Author:** [@Atilla\_Cokmez](https://discuss.elastic.co/u/Atilla_Cokmez)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 1:00pm UTC](https://discuss.elastic.co/t/elasticsearch-net-elasticsearchclientexception/330735 "2023-04-25T13:00:47Z")

</div>

I Use Elasticsearch 7.16.2 on docker and Nest 7.16.0 I added these codes by collecting them from two different classes. It may look complicated ConnectionSettings conStr = new ConnectionSettings(new Uri("http://localho…

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/330741)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 12:57pm UTC](https://discuss.elastic.co/t/issue-with-logstash/330741 "2023-04-25T12:57:52Z")

</div>

Hello, I am trying to parse this JSON with Logstash. {"creation\_date": "2023/01/04", "vulnerabilities": \[{"count": 1, "score": null, "vuln\_index": 414, "plugin\_name": "WordPad History", "severity": 0, "vpr\_score": null,…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=559)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=561)
