# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=569

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 570

---

## [Elastic search docker image - Jar hell error](https://discuss.elastic.co/t/elastic-search-docker-image-jar-hell-error/329767)

<div class="topic-metadata">

**Author:** [@priya\_dhana](https://discuss.elastic.co/u/priya_dhana)\
**Replies:** 11\
**Last updated:** [April 17, 2023, 12:55am UTC](https://discuss.elastic.co/t/elastic-search-docker-image-jar-hell-error/329767 "2023-04-17T00:55:27Z")

</div>

I am using docker.elastic.co/elasticsearch/elasticsearch:5.6.16 as base image and trying to upgrade the jackson packages to resolve Critical CVE. Dockerfile: # https://github.com/elastic/elasticsearch-docker FROM dock…

---

## [BulkIngester: Received \`not\_x\_content\_exception\` when adding json](https://discuss.elastic.co/t/bulkingester-received-not-x-content-exception-when-adding-json/329812)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:34am UTC](https://discuss.elastic.co/t/bulkingester-received-not-x-content-exception-when-adding-json/329812 "2023-04-12T08:34:09Z")

</div>

In the new BulkIngester, how to add json data? I have this json: { "time": "2023-04-13T02:44:16.1782763Z", "user\_id": 1, "user\_name": "admin", "host\_name": "localhost:5567", "type": "PRODUCT\_DELETE", "long\_…

---

## [Initiating a port scan](https://discuss.elastic.co/t/initiating-a-port-scan/329939)

<div class="topic-metadata">

**Author:** [@Infael](https://discuss.elastic.co/u/Infael)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 9:46pm UTC](https://discuss.elastic.co/t/initiating-a-port-scan/329939 "2023-04-17T21:46:23Z")

</div>

I need to scan all ports on my network. I have not been able to figure this out. I am very new to Elastic. Thanks! Michael

---

## [Editing runtime fields for remote index stopped working](https://discuss.elastic.co/t/editing-runtime-fields-for-remote-index-stopped-working/329953)

<div class="topic-metadata">

**Author:** [@erik\_n](https://discuss.elastic.co/u/erik_n)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 9:39pm UTC](https://discuss.elastic.co/t/editing-runtime-fields-for-remote-index-stopped-working/329953 "2023-04-17T21:39:21Z")

</div>

Hello! I had a few runtime fields working with a cluster against data in a remote cluster, and since upgrading both from 7.15 to 8.6 I'm unable to edit them or create new ones. I ran into this when trying to fix usages…

---

## [I am using the Sysmon-\> logstash -\> elasticsearch (ELK) architecture issues](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 11:14pm UTC](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076 "2023-04-15T23:14:36Z")

</div>

Hi, I am trying to use sysmon to logstash to elasticsearch. After advice from others in this forum, I finally came up with a combination of parms and processing that at least shows me data from my laptop IP in kibana. T…

---

## [Kibana not connecting on browser](https://discuss.elastic.co/t/kibana-not-connecting-on-browser/330148)

<div class="topic-metadata">

**Author:** [@Cyberpwc](https://discuss.elastic.co/u/Cyberpwc)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 9:09pm UTC](https://discuss.elastic.co/t/kibana-not-connecting-on-browser/330148 "2023-04-17T21:09:20Z")

</div>

Hi, I'm new to the ELK stack and currently trying to configure Kibana however I am encountering an error regarding some security authentication issue. This is the Kibana log showing the error: Apr 17 16:56:52 CyberELK …

---

## [Error starting watcher](https://discuss.elastic.co/t/error-starting-watcher/330143)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 6:34pm UTC](https://discuss.elastic.co/t/error-starting-watcher/330143 "2023-04-17T18:34:28Z")

</div>

We upgraded to 8.7.0 yesterday, since then none of our watchers have executed. We just keep getting this message in the elastic logs: error starting watcher I tried deleting the extra .watcher-history-\* indices via upda…

---

## [Limiting data in object properties coming to browser from elastic search](https://discuss.elastic.co/t/limiting-data-in-object-properties-coming-to-browser-from-elastic-search/329958)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 6\
**Last updated:** [April 17, 2023, 6:33pm UTC](https://discuss.elastic.co/t/limiting-data-in-object-properties-coming-to-browser-from-elastic-search/329958 "2023-04-17T18:33:07Z")

</div>

Hi, We are currently pulling large amounts of data from Elasticsearch for reporting products in our software. For our larger clients this means sending a large amount of data to the browser which is then loaded into a r…

---

## [Kibana 8.7 expensive queries](https://discuss.elastic.co/t/kibana-8-7-expensive-queries/330120)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 6:32pm UTC](https://discuss.elastic.co/t/kibana-8-7-expensive-queries/330120 "2023-04-17T18:32:35Z")

</div>

Hello, after upgrading Elastic and Kibana to 8.7 i get reports from users that they are seeing this: Combined with missing values in the control. If they type the value they are missing in the search field of the con…

---

## [Kibana 8.7 Control Sort](https://discuss.elastic.co/t/kibana-8-7-control-sort/329758)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 4:30pm UTC](https://discuss.elastic.co/t/kibana-8-7-control-sort/329758 "2023-04-17T16:30:35Z")

</div>

Hello, i just checked out the new sorting functionallity for controls. The default setting is to sort desc by doc count I want asc alphabetically on every control. How can i change that in an easy way? I could not …

---

## [Are runtime multi-fields possible?](https://discuss.elastic.co/t/are-runtime-multi-fields-possible/330153)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 4:44pm UTC](https://discuss.elastic.co/t/are-runtime-multi-fields-possible/330153 "2023-04-17T16:44:48Z")

</div>

Is it possible to have a runtime mapping with a subfield? I mean, so I get fields like "field.keyword" and "field.text" like multi-fields, but at same time this is runtime mapping . I like elasticsearch dynamic mapping,…

---

## [Internal monitoring and log indices have "live forever" ILM policies](https://discuss.elastic.co/t/internal-monitoring-and-log-indices-have-live-forever-ilm-policies/330072)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 4:32pm UTC](https://discuss.elastic.co/t/internal-monitoring-and-log-indices-have-live-forever-ilm-policies/330072 "2023-04-17T16:32:21Z")

</div>

Hi! I was investigating an issue with too much retained data in our ES cloud cluster and realized that a lot of it comes from the internal monitoring and log indices. Specifically, the following indices with correspondi…

---

## [Kibana left side changes on right side's variable click](https://discuss.elastic.co/t/kibana-left-side-changes-on-right-sides-variable-click/329708)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 6:53am UTC](https://discuss.elastic.co/t/kibana-left-side-changes-on-right-sides-variable-click/329708 "2023-04-17T06:53:22Z")

</div>

Hello, I am learning about Kibana and its features so I wanted to know whether Kibana support the feature of having dependent visualization. Something like if I click on a variable or link present in right side then lef…

---

## [Visualize List files from logs](https://discuss.elastic.co/t/visualize-list-files-from-logs/327944)

<div class="topic-metadata">

**Author:** [@Oniriel](https://discuss.elastic.co/u/Oniriel)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 3:38pm UTC](https://discuss.elastic.co/t/visualize-list-files-from-logs/327944 "2023-04-17T15:38:46Z")

</div>

Hi, I have an index that I try to create visualization on for monitoring. Some of the logs have the following structure TEXT - path of a file - TEXT the same file can appear multiple time in the logs I can successful…

---

## [Elasticsearch Transformed index and its dashboard](https://discuss.elastic.co/t/elasticsearch-transformed-index-and-its-dashboard/329827)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 3:33pm UTC](https://discuss.elastic.co/t/elasticsearch-transformed-index-and-its-dashboard/329827 "2023-04-17T15:33:46Z")

</div>

Hi, I am building a Kibana dashboard using an transformed index. What I have observed is for every field change in ES transform, I need to create a new dashboard as object is deleted when deleting the ES transform. C…

---

## [Kafka-Elasticsearch Logstash Configuration Error](https://discuss.elastic.co/t/kafka-elasticsearch-logstash-configuration-error/330130)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 2:52pm UTC](https://discuss.elastic.co/t/kafka-elasticsearch-logstash-configuration-error/330130 "2023-04-17T14:52:20Z")

</div>

I have a logstash pipeline which gets data from kafka and sends it to elasticsearch. However, in elasticsearch, data is not represented correctly. In this data I want it to be just field:value. But it is field:\[value,fi…

---

## [How to display the last date on a grouping set](https://discuss.elastic.co/t/how-to-display-the-last-date-on-a-grouping-set/329854)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 2:45pm UTC](https://discuss.elastic.co/t/how-to-display-the-last-date-on-a-grouping-set/329854 "2023-04-17T14:45:02Z")

</div>

Hello, I am working on a dashboard, and I would like to show the last date on a grouping set. I take the kibana\_sample\_data\_ecommerce as example. Attachedn an example of row part. I would like to group by product\_id…

---

## [Help pattern for multiline logs](https://discuss.elastic.co/t/help-pattern-for-multiline-logs/330134)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 2:41pm UTC](https://discuss.elastic.co/t/help-pattern-for-multiline-logs/330134 "2023-04-17T14:41:54Z")

</div>

What pattern should I use to retrieve correctly multi-lines logs ? Normally I use : file { path =\> "/var/log/appslogs/\*\*/\*.log" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" codec =\> multili…

---

## [Use reciprocal ranking fusion to combine the results of two queries](https://discuss.elastic.co/t/use-reciprocal-ranking-fusion-to-combine-the-results-of-two-queries/329614)

<div class="topic-metadata">

**Author:** [@flando](https://discuss.elastic.co/u/flando)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 2:32pm UTC](https://discuss.elastic.co/t/use-reciprocal-ranking-fusion-to-combine-the-results-of-two-queries/329614 "2023-04-17T14:32:21Z")

</div>

Hi everyone, I'm trying to use reciprocal ranking fusion (RRF) to combine the results of two query performed with the following code: GET /books\_index/\_search { "query": { "bool": { "should": \[ { …

---

## [Trying to update a document but keep getting validation or parse errors](https://discuss.elastic.co/t/trying-to-update-a-document-but-keep-getting-validation-or-parse-errors/330117)

<div class="topic-metadata">

**Author:** [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Replies:** 9\
**Last updated:** [April 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/trying-to-update-a-document-but-keep-getting-validation-or-parse-errors/330117 "2023-04-17T14:25:57Z")

</div>

I have a set of documents created by filebeat -\> logstash pushed to Elasticsearch and they look like this... { "\_index": "sub\_myapp\_prod-filebeat-7.17.7-2023.04", "\_type": "\_doc", "\_id": "IPLahocBBfkGcvN800\_A", …

---

## [Logstash docker cannot log into elasticsearch docker](https://discuss.elastic.co/t/logstash-docker-cannot-log-into-elasticsearch-docker/328336)

<div class="topic-metadata">

**Author:** [@kpankhurst](https://discuss.elastic.co/u/kpankhurst)\
**Replies:** 10\
**Last updated:** [April 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-docker-cannot-log-into-elasticsearch-docker/328336 "2023-04-17T14:25:01Z")

</div>

I have 2 dockers set up as follows: elasticsearch: image: docker.elastic.co/elasticsearch/elasticsearch:8.6.0 volumes: - ./config/elasticsearch/esdata:/usr/share/elasticsearch/data - ./config/elast…

---

## [Perform aggregation on a modified term](https://discuss.elastic.co/t/perform-aggregation-on-a-modified-term/330141)

<div class="topic-metadata">

**Author:** [@manropinxu](https://discuss.elastic.co/u/manropinxu)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 2:11pm UTC](https://discuss.elastic.co/t/perform-aggregation-on-a-modified-term/330141 "2023-04-17T14:11:29Z")

</div>

I'd like to perform an aggregation grouping by a modified version of amessage field. I have lots of messages like invalid x with uuid=1e659cfc-a375-4a8a-88f5-467419fdf87d invalid x with uuid=49c4742e-0368-49a2-aab4-7f…

---

## [Problems Accessing Kibana Lab](https://discuss.elastic.co/t/problems-accessing-kibana-lab/329545)

<div class="topic-metadata">

**Author:** [@ltan](https://discuss.elastic.co/u/ltan)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 1:31pm UTC](https://discuss.elastic.co/t/problems-accessing-kibana-lab/329545 "2023-04-17T13:31:01Z")

</div>

Hi, I am currently enrolled in the Data Analysis with Kibana on-demand course. I have been trying to use the lab environment to use Kibana. But I have been getting multiple issues such as 'kibana server is not ready ye…

---

## [CVE-2022-1471 is not listed in Security Issues site](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/330110)

<div class="topic-metadata">

**Author:** [@Mike\_Joseph](https://discuss.elastic.co/u/Mike_Joseph)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 1:24pm UTC](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/330110 "2023-04-17T13:24:13Z")

</div>

Continuing the discussion from Snakeyaml vulnerability (CVE-2022-1471) on latest ES version: @DavidTurner Forwarded the topic to Security issues but it is still not addressed in the site.

---

## [How to enable CORS for all possible connections?](https://discuss.elastic.co/t/how-to-enable-cors-for-all-possible-connections/330135)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 1:12pm UTC](https://discuss.elastic.co/t/how-to-enable-cors-for-all-possible-connections/330135 "2023-04-17T13:12:12Z")

</div>

How to enable CORS for all possible connections?

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/330061)

<div class="topic-metadata">

**Author:** [@Hugo\_Demont](https://discuss.elastic.co/u/Hugo_Demont)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 1:03pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/330061 "2023-04-17T13:03:10Z")

</div>

Hello ! I'm try to run elasticsearch on my linux computer to download Magento 2 when I try sudo systemctl start elasticsearch I get an error and I dont know how to solve it :confused: Error : \`avril 15 10:34:55 demon…

---

## [Clarification on end of maintenance of elastic search 8.x](https://discuss.elastic.co/t/clarification-on-end-of-maintenance-of-elastic-search-8-x/330129)

<div class="topic-metadata">

**Author:** [@mohammed\_rizwan](https://discuss.elastic.co/u/mohammed_rizwan)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 12:55pm UTC](https://discuss.elastic.co/t/clarification-on-end-of-maintenance-of-elastic-search-8-x/330129 "2023-04-17T12:55:01Z")

</div>

Hi team, From the Elasticsearch link Elastic Product End of Life Dates | Elastic, the Elasticsearch (8.x) end of maintenance is mentioned as "The later of 2024-08-10 or 6 months after the release date of 9.0 (TBD)". Is…

---

## [Can't sort by column/field in Kabana](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 8:31am UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929 "2023-04-17T08:31:29Z")

</div>

Hello, I'm currently implementing ELK on my environment to retrieve the logs and I got a problem. In the discover tab, I can't sort a column. I can only sort by the @Timestamp. I would like to be able to sort by the…

---

## [Connect: connection refused](https://discuss.elastic.co/t/connect-connection-refused/330123)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 11:55am UTC](https://discuss.elastic.co/t/connect-connection-refused/330123 "2023-04-17T11:55:20Z")

</div>

I have a fresh elasticsearch cluster deployed on kubernetes. I have deployed metricbeat 8.7.0 and i get the following error in the logs of each metricbeat pod. Does anyone know how to resolve this issue? {"log.level":…

---

## [Recommended RAM/CPU size for hot data nodes in gcp](https://discuss.elastic.co/t/recommended-ram-cpu-size-for-hot-data-nodes-in-gcp/330119)

<div class="topic-metadata">

**Author:** [@alok.nashikkar](https://discuss.elastic.co/u/alok.nashikkar)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 11:16am UTC](https://discuss.elastic.co/t/recommended-ram-cpu-size-for-hot-data-nodes-in-gcp/330119 "2023-04-17T11:16:30Z")

</div>

Hello, I am exploring recommendations for infra sizing for Elasticsearch hot data nodes in GCP with recommendations for CPU and RAM for probably 3 TB SSD with machine types ex n2d/e2 or some other in similar performance…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=568)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=570)
