# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=561

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 562

---

## [Filebeat Config file](https://discuss.elastic.co/t/filebeat-config-file/330724)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-config-file/330724 "2023-04-25T12:56:57Z")

</div>

I Need a help with the file beat config: I'm trying to read the data from a log file whose size remains the same and its modification time is changed every 30 mins.During these 30 mins interval new logs are added in pla…

---

## [What will happen to my upcoming logs in filebeat IF elasticsearch is Down](https://discuss.elastic.co/t/what-will-happen-to-my-upcoming-logs-in-filebeat-if-elasticsearch-is-down/330734)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/what-will-happen-to-my-upcoming-logs-in-filebeat-if-elasticsearch-is-down/330734 "2023-04-25T11:54:29Z")

</div>

Hi I am forwarding Syslogs from Filebeat to Elasticsearch.If for some reasons my elasticsearch is down for hours or days . What will happen to my upcoming logs will filebeat hold or store locally if yes then how long …

---

## [How to apply ilm policy to index patter tenat-\*](https://discuss.elastic.co/t/how-to-apply-ilm-policy-to-index-patter-tenat/328428)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 10:42am UTC](https://discuss.elastic.co/t/how-to-apply-ilm-policy-to-index-patter-tenat/328428 "2023-04-25T10:42:28Z")

</div>

Hello Expert, I have to apply an ilm policy to my index patter so that the space full issue should not occur. Im able to create the policy but not able to apply to index patter as i need to add manually for index patte…

---

## [Sampling aggregation with a fixed seed producing unstable results](https://discuss.elastic.co/t/sampling-aggregation-with-a-fixed-seed-producing-unstable-results/329849)

<div class="topic-metadata">

**Author:** [@geoffballinger](https://discuss.elastic.co/u/geoffballinger)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 10:10am UTC](https://discuss.elastic.co/t/sampling-aggregation-with-a-fixed-seed-producing-unstable-results/329849 "2023-04-25T10:10:31Z")

</div>

We would like to use sampling aggregations to improve aggregation performance in some dashboards, but the results must be the same each time to avoid confusing customers. We are thus setting the seed since if we do that …

---

## [Handling of null and \[\] (empty list)](https://discuss.elastic.co/t/handling-of-null-and-empty-list/330720)

<div class="topic-metadata">

**Author:** [@nguyen\_huy](https://discuss.elastic.co/u/nguyen_huy)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 9:24am UTC](https://discuss.elastic.co/t/handling-of-null-and-empty-list/330720 "2023-04-25T09:24:01Z")

</div>

Hi everybody, I am very new to Elasticsearch and I have a question regarding the handling of null and \[\] (empty list) values. Specifically, in my dummy index example, I have a document as follows { "hits": \[ …

---

## [Elasticsearchversion 7.17.9 is not starting - Exception in thread "main" java.lang.RuntimeException: starting java](https://discuss.elastic.co/t/elasticsearchversion-7-17-9-is-not-starting-exception-in-thread-main-java-lang-runtimeexception-starting-java/330658)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 5:48am UTC](https://discuss.elastic.co/t/elasticsearchversion-7-17-9-is-not-starting-exception-in-thread-main-java-lang-runtimeexception-starting-java/330658 "2023-04-25T05:48:42Z")

</div>

Elasticsearch 7.8 is upgraded to version 7.17.9, then unable to start the service. And in logs getting following Error: Exception in thread "main" java.lang.RuntimeException: starting java.

---

## [None of the configured nodes are available](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available/330340)

<div class="topic-metadata">

**Author:** [@zz-GuoYF](https://discuss.elastic.co/u/zz-GuoYF)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 8:35am UTC](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available/330340 "2023-04-25T08:35:58Z")

</div>

The version of Elasticsearch I used is 2.4.6 and the deployment mode is single-node es. When I was running a query with a data volume of 7 million, the following error occurred in es： In addition, by adding GC log p…

---

## [Inspect raw JSON source data from Vega/Elasticsearch](https://discuss.elastic.co/t/inspect-raw-json-source-data-from-vega-elasticsearch/330629)

<div class="topic-metadata">

**Author:** [@peppar](https://discuss.elastic.co/u/peppar)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 7:58am UTC](https://discuss.elastic.co/t/inspect-raw-json-source-data-from-vega-elasticsearch/330629 "2023-04-25T07:58:59Z")

</div>

I'm trying to create advanced visualizations with Vega, but I'm having the hardest time guessing the dataset names. I'm fetching my data as such: { "$schema": "https://vega.github.io/schema/vega/v4.json", "descripti…

---

## [How to send subject field data from logstash to syslog server](https://discuss.elastic.co/t/how-to-send-subject-field-data-from-logstash-to-syslog-server/330642)

<div class="topic-metadata">

**Author:** [@Thumati](https://discuss.elastic.co/u/Thumati)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-send-subject-field-data-from-logstash-to-syslog-server/330642 "2023-04-25T06:25:52Z")

</div>

I would like to know if is it possible to send subject field to rsyslog server. Eg: subject : " username " should be sent.

---

## [Is Elasticsearch 7.17.9 is compatible withOpenJDK 1.8?](https://discuss.elastic.co/t/is-elasticsearch-7-17-9-is-compatible-withopenjdk-1-8/330654)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 7\
**Last updated:** [April 25, 2023, 5:59am UTC](https://discuss.elastic.co/t/is-elasticsearch-7-17-9-is-compatible-withopenjdk-1-8/330654 "2023-04-25T05:59:59Z")

</div>

Is OpenJDK 1.8 version is compatible with elasticsearch 7.17.9 version? If not Which version of OpenJDK is compatible with elasticsearch 7.17.9?

---

## [Send logs from filebeat to elasticsearch](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elasticsearch/330628)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 7\
**Last updated:** [April 25, 2023, 5:39am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elasticsearch/330628 "2023-04-25T05:39:27Z")

</div>

I am trying to send logs from filebeat to elasticsearch. Here is the filbeat.yml filebeat.inputs: - type: filestream id: my-filestream-id enabled: true paths: - C:\\ProgramData\\sample\_logs\\sample.log - type: lo…

---

## [Analyzer \[full\_chinese\] contains filters \[my\_synonym\] that are not allowed to run in index time mode](https://discuss.elastic.co/t/analyzer-full-chinese-contains-filters-my-synonym-that-are-not-allowed-to-run-in-index-time-mode/330626)

<div class="topic-metadata">

**Author:** [@YKX-Can](https://discuss.elastic.co/u/YKX-Can)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 2:59am UTC](https://discuss.elastic.co/t/analyzer-full-chinese-contains-filters-my-synonym-that-are-not-allowed-to-run-in-index-time-mode/330626 "2023-04-25T02:59:38Z")

</div>

this my setting PUT test { "settings": { "analysis": { "char\_filter": { "my\_tsconvert": { "convert\_type": "t2s", "type": "stconvert" } }, "filter": { "my\_synonym": { "type": "synon…

---

## [Average of sum(value)](https://discuss.elastic.co/t/average-of-sum-value/330685)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 9:09pm UTC](https://discuss.elastic.co/t/average-of-sum-value/330685 "2023-04-24T21:09:50Z")

</div>

I am running a ingestion and records comes every 15 min one of the field is integer #user value might be 1, 2,3 or what ever. what I am trying to do is average of sum ( users) per hour for example rec1 - 10:00am { …

---

## [Runtime Field Convert the Timestamp to Display Month and Year](https://discuss.elastic.co/t/runtime-field-convert-the-timestamp-to-display-month-and-year/330164)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:53pm UTC](https://discuss.elastic.co/t/runtime-field-convert-the-timestamp-to-display-month-and-year/330164 "2023-04-24T19:53:47Z")

</div>

I have a requirement to show only the month and Year from the date on a Dashboard For instance I want to show how number of tickets by month and year - Apr 2023 currently the visualization shows this as below, I want t…

---

## [Send Logs from Filebeat on my local machine to Logstash having a private ip](https://discuss.elastic.co/t/send-logs-from-filebeat-on-my-local-machine-to-logstash-having-a-private-ip/330352)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:13pm UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-on-my-local-machine-to-logstash-having-a-private-ip/330352 "2023-04-24T19:13:10Z")

</div>

Hi i have installed filebeat on my local windows machine. I want to send logs to Logstash which has a private IP only and is in a different VPC. How can i set a connection between these two machines? Is it possible?

---

## [Creation of multiple logstash pipelines using API](https://discuss.elastic.co/t/creation-of-multiple-logstash-pipelines-using-api/330612)

<div class="topic-metadata">

**Author:** [@anjali\_roy](https://discuss.elastic.co/u/anjali_roy)\
**Replies:** 9\
**Last updated:** [April 24, 2023, 7:08pm UTC](https://discuss.elastic.co/t/creation-of-multiple-logstash-pipelines-using-api/330612 "2023-04-24T19:08:11Z")

</div>

I have a use case to create multiple Logstash pipelines inside a running Logstash container, Is it possible to use Logstash APIs as I do not have Elasticsearch and Kibana host. Just a Logstash running inside a cluster. I…

---

## [Elastic search on windows](https://discuss.elastic.co/t/elastic-search-on-windows/330409)

<div class="topic-metadata">

**Author:** [@Preethi\_Manu](https://discuss.elastic.co/u/Preethi_Manu)\
**Replies:** 8\
**Last updated:** [April 24, 2023, 6:34pm UTC](https://discuss.elastic.co/t/elastic-search-on-windows/330409 "2023-04-24T18:34:34Z")

</div>

While installing Elastic search on windows , getting below error like plugin db2jcc4.jar is missing a descriptor properties file. Please help to resolve this

---

## [Kibana Authentification](https://discuss.elastic.co/t/kibana-authentification/330243)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 6:27pm UTC](https://discuss.elastic.co/t/kibana-authentification/330243 "2023-04-24T18:27:00Z")

</div>

Hi, I'have a problem to authentificating Kibana on Elastic . After generating a token on Elastic, Kibana is block on "Server is not ready yet" I have two different IP on each server and they ping each other Changes i…

---

## [Geo\_Point field for mapping](https://discuss.elastic.co/t/geo-point-field-for-mapping/330363)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 5:53pm UTC](https://discuss.elastic.co/t/geo-point-field-for-mapping/330363 "2023-04-24T17:53:27Z")

</div>

hey , im tryin g to create and have and geo\_point field to create a map visualisation , but im finding difficulties , my Lat and Long fields that i extracted previously from Geoip filter on My configuration file are flo…

---

## [100% disk, single node cluster how to fix?](https://discuss.elastic.co/t/100-disk-single-node-cluster-how-to-fix/330588)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 8\
**Last updated:** [April 24, 2023, 5:12pm UTC](https://discuss.elastic.co/t/100-disk-single-node-cluster-how-to-fix/330588 "2023-04-24T17:12:47Z")

</div>

I have a test single node cluster. I know what the problem is but can't seems to figure out how to get out of it and fix without removing everything and star over this node has all index without replica because I exe…

---

## [Using Time Serie DataStream (TSDS) for discrete events with high cardinality](https://discuss.elastic.co/t/using-time-serie-datastream-tsds-for-discrete-events-with-high-cardinality/330679)

<div class="topic-metadata">

**Author:** [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 4:57pm UTC](https://discuss.elastic.co/t/using-time-serie-datastream-tsds-for-discrete-events-with-high-cardinality/330679 "2023-04-24T16:57:04Z")

</div>

Hi there! I'm new to TSDS and time series in general. Let's say I have the following index mapping: { "properties": { "@timestamp": { "type": "date" }, "game\_id": { "…

---

## [Update nested documents via painless](https://discuss.elastic.co/t/update-nested-documents-via-painless/330676)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 4:12pm UTC](https://discuss.elastic.co/t/update-nested-documents-via-painless/330676 "2023-04-24T16:12:47Z")

</div>

Hi, Assuming we have the following mapping "mappings": { "properties": { "id": { "type": "text", }, "messages": { "type": "nested", "dynamic": "strict", "properties": { "id…

---

## [\[NEWBIE\] Increase speed of indexation huge logs](https://discuss.elastic.co/t/newbie-increase-speed-of-indexation-huge-logs/330069)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 25\
**Last updated:** [April 24, 2023, 9:21am UTC](https://discuss.elastic.co/t/newbie-increase-speed-of-indexation-huge-logs/330069 "2023-04-24T09:21:27Z")

</div>

Hi everybody, I'm french and i m a very newbie with elasticsearch. Elasticsearch version imposed by security team : 7.10.2 I create a cluster like this with dedicate nodes: 2 master node 1 master only eligible node 1…

---

## [Filter search by ids with BM25 score in Python (Elastic 8.7)](https://discuss.elastic.co/t/filter-search-by-ids-with-bm25-score-in-python-elastic-8-7/330625)

<div class="topic-metadata">

**Author:** [@Francisco\_Rocha](https://discuss.elastic.co/u/Francisco_Rocha)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 2:32pm UTC](https://discuss.elastic.co/t/filter-search-by-ids-with-bm25-score-in-python-elastic-8-7/330625 "2023-04-24T14:32:46Z")

</div>

Hi folks, I'm working with Python client and would like to know if it is possible to do a search by target ids with BM25. I have a 500k index and a list of ids that I would like to filter and at the same time obtain BM2…

---

## [Adding syslog priority fields to System integration](https://discuss.elastic.co/t/adding-syslog-priority-fields-to-system-integration/330519)

<div class="topic-metadata">

**Author:** [@sebek](https://discuss.elastic.co/u/sebek)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 2:28pm UTC](https://discuss.elastic.co/t/adding-syslog-priority-fields-to-system-integration/330519 "2023-04-24T14:28:32Z")

</div>

Hi, i'm trying to work out how to add information about syslog priority to my logdata in elasticsearch. I'm testing out a self managed ELK stack, for collecting syslog data from linux(ubuntu) servers and workstations. …

---

## [Elastic Agent kubernetes container logs not shipping from nodes](https://discuss.elastic.co/t/elastic-agent-kubernetes-container-logs-not-shipping-from-nodes/330664)

<div class="topic-metadata">

**Author:** [@Rydzu](https://discuss.elastic.co/u/Rydzu)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-agent-kubernetes-container-logs-not-shipping-from-nodes/330664 "2023-04-24T14:21:01Z")

</div>

I'm quite fresh with elastic stack and I have a problem with elastic agents on k8. Setup: Both Elastic Stack (v8.7) and k8 (v1.25 with cri-o; 1 master, 3 nodes) are deployed on local environment. Elastic Stack deployed…

---

## [Logstash show error "undefined method \`length' for nil:NilClass"](https://discuss.elastic.co/t/logstash-show-error-undefined-method-length-for-nil-nilclass/330373)

<div class="topic-metadata">

**Author:** [@C\_Wesley](https://discuss.elastic.co/u/C_Wesley)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 1:20pm UTC](https://discuss.elastic.co/t/logstash-show-error-undefined-method-length-for-nil-nilclass/330373 "2023-04-24T13:20:09Z")

</div>

Hi there, I have an issue with the title. When I send the JSON log to Filebeat and send it ti my logstash, sometimes it passes the filter, but sometimes it fails. Would you please help me check my configuration to see w…

---

## [Logstash Opensearch Configuration havin codec json](https://discuss.elastic.co/t/logstash-opensearch-configuration-havin-codec-json/330607)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 12:17pm UTC](https://discuss.elastic.co/t/logstash-opensearch-configuration-havin-codec-json/330607 "2023-04-24T12:17:04Z")

</div>

I am using opensearch with logstash, I wanted to use codec =\> json in output section of opensearch configuration. How can I achieve that? opensearch { hosts =\> \["${OPENSEARCH\_HOSTS}"\] index =\> "%{logplan…

---

## [How to know how much resources are being used for machine learning?](https://discuss.elastic.co/t/how-to-know-how-much-resources-are-being-used-for-machine-learning/330606)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 11:49am UTC](https://discuss.elastic.co/t/how-to-know-how-much-resources-are-being-used-for-machine-learning/330606 "2023-04-24T11:49:28Z")

</div>

Hi, we are considering to add a new node exclusively for machine learning, how I can find out how much resources are being used for machine learning for all the jobs runing in real time? the documentation says that ther…

---

## [Different filters for different visualizations inside the same dashboard](https://discuss.elastic.co/t/different-filters-for-different-visualizations-inside-the-same-dashboard/330208)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 6\
**Last updated:** [April 24, 2023, 11:21am UTC](https://discuss.elastic.co/t/different-filters-for-different-visualizations-inside-the-same-dashboard/330208 "2023-04-24T11:21:13Z")

</div>

Hi! I'm building a dashboard that has two visualizations, each of them taking data from different indexes. I want to apply a filter (that can be edited on the dashboard to show different data), but as the data comes fro…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=560)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=562)
