# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=572

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 573

---

## [Elastic forwarder cloudwatch log group wildcard id not working](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987)

<div class="topic-metadata">

**Author:** [@dchocoboo](https://discuss.elastic.co/u/dchocoboo)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:35am UTC](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987 "2023-04-14T09:35:01Z")

</div>

i'm trying to simplify my config.yaml based on this tutorial currently if i put this in my config - type: "cloudwatch-logs" id: "arn:aws:logs:ap-southeast-1:xxxxxxxxxx:log-group:\*:\*" outputs: - type: "el…

---

## [Is it possible to change the logging path for Elastic Agent?](https://discuss.elastic.co/t/is-it-possible-to-change-the-logging-path-for-elastic-agent/329983)

<div class="topic-metadata">

**Author:** [@lengoyvaerts](https://discuss.elastic.co/u/lengoyvaerts)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 8:59am UTC](https://discuss.elastic.co/t/is-it-possible-to-change-the-logging-path-for-elastic-agent/329983 "2023-04-14T08:59:43Z")

</div>

Hi community As per the topic's title, I'm trying to configure the logging path when installing the Elastic Agent. I'm using central fleet management and following the installation guidelines from the Kibana UI as descr…

---

## [Help with Nest Fluent DSL query](https://discuss.elastic.co/t/help-with-nest-fluent-dsl-query/329982)

<div class="topic-metadata">

**Author:** [@vdelcampo](https://discuss.elastic.co/u/vdelcampo)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 8:08am UTC](https://discuss.elastic.co/t/help-with-nest-fluent-dsl-query/329982 "2023-04-14T08:08:07Z")

</div>

Hi! I need help with below query. I´m using .NET Nest library, and I need to convert it to Fluent DSL: GET md-tpmiddle-f5-\*/\_count { "query": { "bool": { "filter": \[ { "bool": { …

---

## [How long does it take to clone an index with 2TB of data?](https://discuss.elastic.co/t/how-long-does-it-take-to-clone-an-index-with-2tb-of-data/329969)

<div class="topic-metadata">

**Author:** [@dilshadpaleri](https://discuss.elastic.co/u/dilshadpaleri)\
**Replies:** 2\
**Last updated:** [April 14, 2023, 7:45am UTC](https://discuss.elastic.co/t/how-long-does-it-take-to-clone-an-index-with-2tb-of-data/329969 "2023-04-14T07:45:41Z")

</div>

Hi, I want to create an identical copy of an existing index with about 2 TB of data, Clone API seems to be the best option here. To clone an index, the index must be marked as read-only, so it will block my application …

---

## [How to use elastic in wiki js](https://discuss.elastic.co/t/how-to-use-elastic-in-wiki-js/329978)

<div class="topic-metadata">

**Author:** [@Kwa](https://discuss.elastic.co/u/Kwa)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 7:13am UTC](https://discuss.elastic.co/t/how-to-use-elastic-in-wiki-js/329978 "2023-04-14T07:13:00Z")

</div>

Hi everyone, i have elasticsearch installed locally in a VM with version 7.17.8. By calling http://localhost:9200 in the browser i get the information like cluster\_name, cluster\_uuid etc. In elasticsearch.yml i have en…

---

## [Elastic 8 not search with hyphen](https://discuss.elastic.co/t/elastic-8-not-search-with-hyphen/327824)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 6\
**Last updated:** [April 14, 2023, 6:50am UTC](https://discuss.elastic.co/t/elastic-8-not-search-with-hyphen/327824 "2023-04-14T06:50:40Z")

</div>

I have documents with id fields {id:domain-837}{id:domain-838} these are automatically stored using mapping with data type keyword. "id": { "type": "text", "fields": { "keyword": { "ignore\_above": 256, "type": "keywor…

---

## [After creating the snapshot, getting snapshot\_missing\_exception and no\_such\_file\_exception](https://discuss.elastic.co/t/after-creating-the-snapshot-getting-snapshot-missing-exception-and-no-such-file-exception/329970)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 6:27am UTC](https://discuss.elastic.co/t/after-creating-the-snapshot-getting-snapshot-missing-exception-and-no-such-file-exception/329970 "2023-04-14T06:27:48Z")

</div>

Hi All, I have created the repository to create snapshot with the following steps in two node (machine) cluster: curl -XPUT "https://:9200$HOSTNAME/\_snapshot/test13?verify=false" -H 'Content-Type: application/json' -…

---

## [Filebeat Input X kafka topics](https://discuss.elastic.co/t/filebeat-input-x-kafka-topics/329950)

<div class="topic-metadata">

**Author:** [@luizsouzagarcia](https://discuss.elastic.co/u/luizsouzagarcia)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 9:49pm UTC](https://discuss.elastic.co/t/filebeat-input-x-kafka-topics/329950 "2023-04-13T21:49:21Z")

</div>

Is it possible to consume all topics of a kafka cluster through filebeat input? ex: type: kafka hosts: - ${KAFKA\_BROKERCONNECT} topics: \["\*"\]. --------\> It doesn't work, I've tried several regex =/ group\_id: "kaf…

---

## [From the time to time Elastic's docs.count value is updated by logstash. Is it normal?](https://discuss.elastic.co/t/from-the-time-to-time-elastics-docs-count-value-is-updated-by-logstash-is-it-normal/329875)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 7:42pm UTC](https://discuss.elastic.co/t/from-the-time-to-time-elastics-docs-count-value-is-updated-by-logstash-is-it-normal/329875 "2023-04-13T19:42:41Z")

</div>

Hi everybody, I have a little question about elastic's docs.count as I have noticed that it's not updated constantly. For example: (Don't pay attention to credentials. It's only a lab test). The 3487 docs.count val…

---

## [Same synonyms in different synonym files](https://discuss.elastic.co/t/same-synonyms-in-different-synonym-files/329358)

<div class="topic-metadata">

**Author:** [@antoinelefloch](https://discuss.elastic.co/u/antoinelefloch)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 6:26pm UTC](https://discuss.elastic.co/t/same-synonyms-in-different-synonym-files/329358 "2023-04-13T18:26:19Z")

</div>

Hello, it seems synonyms in 2nd file are not taken into account if already used in 1st file. In 1st file, I have: aaa,bbb In second file, I have: aaa,synaaa bbb,synbbb ccc,synccc When I do the \_analyze { "expl…

---

## [Kibana Visualization modify size](https://discuss.elastic.co/t/kibana-visualization-modify-size/327492)

<div class="topic-metadata">

**Author:** [@chandap](https://discuss.elastic.co/u/chandap)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 6:11pm UTC](https://discuss.elastic.co/t/kibana-visualization-modify-size/327492 "2023-04-13T18:11:50Z")

</div>

When I create visualizations (line graph) in Kibana and try to generate a png to send in an email via a watcher, the image is way too large. Is there any way at all to resize the image or the visualization its self so t…

---

## [Logstash add subfield to elasticsearch index](https://discuss.elastic.co/t/logstash-add-subfield-to-elasticsearch-index/329870)

<div class="topic-metadata">

**Author:** [@Utibeabasi\_Umanah](https://discuss.elastic.co/u/Utibeabasi_Umanah)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 5:59pm UTC](https://discuss.elastic.co/t/logstash-add-subfield-to-elasticsearch-index/329870 "2023-04-13T17:59:00Z")

</div>

Hi, i want to add a sub field called prefix to a text field called title using a logstash filter plugin. how do i go about this? i need this because the sub fields are required in app search. here is my logstash config s…

---

## [How to Reduce the Embedded Dashboard load time inside the angular iframe?](https://discuss.elastic.co/t/how-to-reduce-the-embedded-dashboard-load-time-inside-the-angular-iframe/329840)

<div class="topic-metadata">

**Author:** [@brusque.sowers](https://discuss.elastic.co/u/brusque.sowers)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 5:44pm UTC](https://discuss.elastic.co/t/how-to-reduce-the-embedded-dashboard-load-time-inside-the-angular-iframe/329840 "2023-04-13T17:44:21Z")

</div>

I have embedded Kibana dashboard in a angular app , The dashboard contains around 12 vega-lite visualisations as well as 5 Kibana lens visualizations . The dashboard takes around 25-30 seconds to get completely fetched o…

---

## [How can I check the avaiability of a Heartbeat monitor in Elasticsearch?](https://discuss.elastic.co/t/how-can-i-check-the-avaiability-of-a-heartbeat-monitor-in-elasticsearch/329942)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 4:59pm UTC](https://discuss.elastic.co/t/how-can-i-check-the-avaiability-of-a-heartbeat-monitor-in-elasticsearch/329942 "2023-04-13T16:59:47Z")

</div>

I have a few monitors in heartbeat which I am going to plan a few alerts. One of the alerts should be aiming for the avaiability of a monitor in the uptime in a range of a whole period of time (could be a day or a month)…

---

## [Getting started with Logstash JDBC Integration on Windows](https://discuss.elastic.co/t/getting-started-with-logstash-jdbc-integration-on-windows/329784)

<div class="topic-metadata">

**Author:** [@Dale\_ander](https://discuss.elastic.co/u/Dale_ander)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 4:20pm UTC](https://discuss.elastic.co/t/getting-started-with-logstash-jdbc-integration-on-windows/329784 "2023-04-13T16:20:15Z")

</div>

I'm just beginning my learning process on ELK but from what I've seen, I'd like to learn how to index data from an RDB table, I presume using the Logstash JDBC Integration plugin, so I can start trying to create differen…

---

## [Programmatically trigger the search action (React UI)](https://discuss.elastic.co/t/programmatically-trigger-the-search-action-react-ui/329943)

<div class="topic-metadata">

**Author:** [@Olivia\_Xu](https://discuss.elastic.co/u/Olivia_Xu)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 3:52pm UTC](https://discuss.elastic.co/t/programmatically-trigger-the-search-action-react-ui/329943 "2023-04-13T15:52:34Z")

</div>

We hope to programmatically trigger the search action in some cases without the user having to type and click the search button from the front end. We are using React UI components. Is this possible to achieve? We have t…

---

## [Can I make two input and output in the logstash config file?](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933 "2023-04-13T15:26:19Z")

</div>

Hello all. I want to get the two indexes from two input data in the one logstash config file. (One is from tshark file and the other one is filebeat so each data are different.) tshark data is changed to json file for …

---

## [Ls there a processor in filebeat same as a prune filter in logstash?](https://discuss.elastic.co/t/ls-there-a-processor-in-filebeat-same-as-a-prune-filter-in-logstash/329940)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 3:25pm UTC](https://discuss.elastic.co/t/ls-there-a-processor-in-filebeat-same-as-a-prune-filter-in-logstash/329940 "2023-04-13T15:25:05Z")

</div>

Hello. I want to get only specific fields in filebeat data. I know there is a prune filter in logstash config file but which one is same thing in filebeat config file processor? I used include\_fields processor, but it …

---

## [Getting updated documents](https://discuss.elastic.co/t/getting-updated-documents/329910)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 5\
**Last updated:** [April 13, 2023, 3:21pm UTC](https://discuss.elastic.co/t/getting-updated-documents/329910 "2023-04-13T15:21:11Z")

</div>

How to get all documents that have been edited in the last 24 hours and return only the id and attributes that have been changed? Is it possible to do this automatically via Elasticsearch without tracking each attribute?…

---

## [Position Kibana Markdown/shapes with coordinates](https://discuss.elastic.co/t/position-kibana-markdown-shapes-with-coordinates/328821)

<div class="topic-metadata">

**Author:** [@v01d53t](https://discuss.elastic.co/u/v01d53t)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 3:21pm UTC](https://discuss.elastic.co/t/position-kibana-markdown-shapes-with-coordinates/328821 "2023-04-13T15:21:10Z")

</div>

Hello everyone new user here, I am building something in Kibana that visualizes spots in certain places on an avatar image. The circle shape does just well for that. My problem is that I need some way to place the circ…

---

## [FleetServer Policy with Logstash type output failing](https://discuss.elastic.co/t/fleetserver-policy-with-logstash-type-output-failing/329839)

<div class="topic-metadata">

**Author:** [@Bradut\_B](https://discuss.elastic.co/u/Bradut_B)\
**Replies:** 6\
**Last updated:** [April 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/fleetserver-policy-with-logstash-type-output-failing/329839 "2023-04-13T15:02:08Z")

</div>

I have the following scenario that works: FleetServer policy -\> output type Elasticsearch AgentPolicy -\> output type Logstash However if I try to change the output type for the Fleet Server policy, to Logstash I get a…

---

## [Reindexing with a script including hashing](https://discuss.elastic.co/t/reindexing-with-a-script-including-hashing/329937)

<div class="topic-metadata">

**Author:** [@hannesulrich](https://discuss.elastic.co/u/hannesulrich)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 2:30pm UTC](https://discuss.elastic.co/t/reindexing-with-a-script-including-hashing/329937 "2023-04-13T14:30:50Z")

</div>

Hey, we are currently looking into reindexing our indices and adding a new field which is the hash fingerprint of a larger field. Our approach is to pass the script to the reindexing api, but it won't work. Our request…

---

## [Versioning in Update API](https://discuss.elastic.co/t/versioning-in-update-api/329934)

<div class="topic-metadata">

**Author:** [@Mykyta\_Piddubskiy](https://discuss.elastic.co/u/Mykyta_Piddubskiy)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 1:53pm UTC](https://discuss.elastic.co/t/versioning-in-update-api/329934 "2023-04-13T13:53:41Z")

</div>

Hello, I need to do version checks when I do some operations in Elastic. Example: I want to use date instance in milliseconds as a version to reject any old doc updates. So I chose \_version as a suitable mechanism fo…

---

## [Find users (IP adresses) which only access one group of servers](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 1:53pm UTC](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714 "2023-04-13T13:53:41Z")

</div>

Hello, I have two groups of forward proxies running Squid (2x 4 servers) Many users are using these proxies. A load balancer sends each new connection on a group or another. Some users are not using the load balancer…

---

## [Restarting logstash cloudwatch plugin](https://discuss.elastic.co/t/restarting-logstash-cloudwatch-plugin/329681)

<div class="topic-metadata">

**Author:** [@mphilip9](https://discuss.elastic.co/u/mphilip9)\
**Replies:** 15\
**Last updated:** [April 13, 2023, 1:42pm UTC](https://discuss.elastic.co/t/restarting-logstash-cloudwatch-plugin/329681 "2023-04-13T13:42:41Z")

</div>

We have an ELK stack app that has been down for over a month due to a credentials issue in the logstash cloudwatch plugin. The plugin is digesting data again now, but what is strange is that it is digesting logs from the…

---

## [Can I save the fields that I only want?](https://discuss.elastic.co/t/can-i-save-the-fields-that-i-only-want/329736)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 1:29pm UTC](https://discuss.elastic.co/t/can-i-save-the-fields-that-i-only-want/329736 "2023-04-13T13:29:34Z")

</div>

Hello all. I collect the network packet data through the 'tshark' and then the packet is filtered through logstash. But there are a lot of fields in packet data so when I see data in the elasticsearch, there are a lot …

---

## [【Please！】How to replace the host name display in kibana with my personal name](https://discuss.elastic.co/t/please-how-to-replace-the-host-name-display-in-kibana-with-my-personal-name/328634)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 1:28pm UTC](https://discuss.elastic.co/t/please-how-to-replace-the-host-name-display-in-kibana-with-my-personal-name/328634 "2023-04-13T13:28:30Z")

</div>

Hello from Japan I have a question for you respected engineers. I am an inexperienced Japanese engineer with Elastic search. I have installed winlogbeat on my Windows PC and have built an environment to send Windows l…

---

## [How to join or merge two document ID data into a single document using a common field value in both Document ID](https://discuss.elastic.co/t/how-to-join-or-merge-two-document-id-data-into-a-single-document-using-a-common-field-value-in-both-document-id/328515)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 1:20pm UTC](https://discuss.elastic.co/t/how-to-join-or-merge-two-document-id-data-into-a-single-document-using-a-common-field-value-in-both-document-id/328515 "2023-04-13T13:20:21Z")

</div>

Hi All, I am using ELK 8.0.0 version and wanted to know can we merge or join the 2 different document ID into a single data with a common field value in both the documents. e.g first document ID has below data emp\_na…

---

## [Unable to start logstash on FreeBSD](https://discuss.elastic.co/t/unable-to-start-logstash-on-freebsd/329874)

<div class="topic-metadata">

**Author:** [@odhiambo](https://discuss.elastic.co/u/odhiambo)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 1:05pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-on-freebsd/329874 "2023-04-13T13:05:45Z")

</div>

I have installed logstash on FreeBSD. For some reason, starting or stopping it prompts for Kerberos authentication. I am not sure where it is getting this from, although it does seem there is some kerberos config somewhe…

---

## [Search using special characters in standard analyzer](https://discuss.elastic.co/t/search-using-special-characters-in-standard-analyzer/329920)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 10:36am UTC](https://discuss.elastic.co/t/search-using-special-characters-in-standard-analyzer/329920 "2023-04-13T10:36:23Z")

</div>

Hi guys, I have a cluster running and I have run into a problem involving including special characters in my search query. Now I did not setup the mapping for the index the mapping is dynamic and the analyzer is also st…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=571)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=573)
