# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=575

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 576

---

## [Help with this grok](https://discuss.elastic.co/t/help-with-this-grok/329817)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 9:28am UTC](https://discuss.elastic.co/t/help-with-this-grok/329817 "2023-04-12T09:28:39Z")

</div>

Need a grok filter that parses out the account (the peacesat) from these two types of logs Case 1: Apr 11 14:26:55 mail saslauthd\[15405\]: auth\_zimbra: peacesat@uhtasi.org auth failed: authentication failed for \[peacesa…

---

## [ELK on AWS](https://discuss.elastic.co/t/elk-on-aws/329819)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 9:25am UTC](https://discuss.elastic.co/t/elk-on-aws/329819 "2023-04-12T09:25:14Z")

</div>

Hi Team, We did install elk \[3 elastic nodes and 2 kibana nodes on us-east-1a,us-east-1b\] on AWS. We are trying to access Kibana dashboard via NLB with ACM\[AWS certificate Manager\] ,but somehow when I am starting kiba…

---

## [How elasticsearch distribute the requests from client](https://discuss.elastic.co/t/how-elasticsearch-distribute-the-requests-from-client/329815)

<div class="topic-metadata">

**Author:** [@qksjdhi1212](https://discuss.elastic.co/u/qksjdhi1212)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 8:53am UTC](https://discuss.elastic.co/t/how-elasticsearch-distribute-the-requests-from-client/329815 "2023-04-12T08:53:27Z")

</div>

I want to know the whole process where elasticsearch distribute the request received from client server (logstash, application, fluentd etc.) does the master node in cluster just assign the request to the most stable no…

---

## [Are there any guidelines to estimate how many snapshots can be handled by elasticsearch with specific amount of memory/cpu](https://discuss.elastic.co/t/are-there-any-guidelines-to-estimate-how-many-snapshots-can-be-handled-by-elasticsearch-with-specific-amount-of-memory-cpu/329811)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/are-there-any-guidelines-to-estimate-how-many-snapshots-can-be-handled-by-elasticsearch-with-specific-amount-of-memory-cpu/329811 "2023-04-12T08:29:34Z")

</div>

HI - I am looking for any data or estimates if we can derive about retaining the snapshots based on size of the cluster. E.g. If we have a smaller elastic cluster with 2G of memory allocation, and SLM with each 15 min s…

---

## [Kibana Uptime monitors broken after migrating to another cluster](https://discuss.elastic.co/t/kibana-uptime-monitors-broken-after-migrating-to-another-cluster/329727)

<div class="topic-metadata">

**Author:** [@George\_ML](https://discuss.elastic.co/u/George_ML)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 8:15am UTC](https://discuss.elastic.co/t/kibana-uptime-monitors-broken-after-migrating-to-another-cluster/329727 "2023-04-12T08:15:29Z")

</div>

Hello, I have recently migrated to another cluster, but I have restored the snapshot after the cluster creation. Because of this, I think some encryption keys for the encrypted saved objects have been changed. This cau…

---

## [Logstash plugin install : Error socket closed](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 22\
**Last updated:** [April 12, 2023, 7:50am UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243 "2023-04-12T07:50:09Z")

</div>

Hi , I want to install a Stormshield plugin for Logstash I tried bin/logstash-plugin install --no-verify logstash-filter-SNS I have "ERROR : Something went wrong when installalling bin/logstash-filter-SNS , message s…

---

## [Elasticsearch 8.7, "master\_not\_discovered\_exception" error](https://discuss.elastic.co/t/elasticsearch-8-7-master-not-discovered-exception-error/329495)

<div class="topic-metadata">

**Author:** [@Jyotsna\_Bhati](https://discuss.elastic.co/u/Jyotsna_Bhati)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-master-not-discovered-exception-error/329495 "2023-04-12T06:32:54Z")

</div>

Upgraded elasticsearch from 7.17 to 8.7. Elasticsearch service is running but not able to discover other nodes. Ran: curl -XGET "localhost:9200/\_cluster/state?filter\_path=version,nodes,metadata.cluster\_coordination&p…

---

## [Anonymous access is denied in kibana?](https://discuss.elastic.co/t/anonymous-access-is-denied-in-kibana/329799)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 6:29am UTC](https://discuss.elastic.co/t/anonymous-access-is-denied-in-kibana/329799 "2023-04-12T06:29:09Z")

</div>

Hi Folks, I have 3 node elasticsearch , 2 logstash nodes and 1 kibana node . Do i mention all three elasticsearch nodes in kibana.yml's "elasticsearch.hosts" config line ? . It was working when i had just the master el…

---

## [Cannt find dependency for CommonAnalysisPlugin](https://discuss.elastic.co/t/cannt-find-dependency-for-commonanalysisplugin/329798)

<div class="topic-metadata">

**Author:** [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 6:05am UTC](https://discuss.elastic.co/t/cannt-find-dependency-for-commonanalysisplugin/329798 "2023-04-12T06:05:08Z")

</div>

Hello everyone, I am currently trying to upgrade my Elasticsearch version from 7.8.1 to 7.17.4. However, after the upgrade, I encountered an error in my project: Cannot resolve symbol 'CommonAnalysisPlugin In Elastics…

---

## [Kube State Metrics stop reporting / Potential Leader Election issue](https://discuss.elastic.co/t/kube-state-metrics-stop-reporting-potential-leader-election-issue/329794)

<div class="topic-metadata">

**Author:** [@RichardMatthews](https://discuss.elastic.co/u/RichardMatthews)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 4:00am UTC](https://discuss.elastic.co/t/kube-state-metrics-stop-reporting-potential-leader-election-issue/329794 "2023-04-12T04:00:19Z")

</div>

Hey, I am having an issue with collecting data from kube state metrics where it will randomly stop coming through into Kibana and all that seems to help is restarting the elastic-agents until it starts to come back. I …

---

## [ElasticSearch delete model with force does not work](https://discuss.elastic.co/t/elasticsearch-delete-model-with-force-does-not-work/329781)

<div class="topic-metadata">

**Author:** [@Diogo\_Moura](https://discuss.elastic.co/u/Diogo_Moura)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 10:23pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-model-with-force-does-not-work/329781 "2023-04-11T22:23:17Z")

</div>

According to the documentation here https://www.elastic.co/guide/en/elasticsearch/reference/8.6/delete-trained-models.html#ml-delete-trained-models-query-parms it is possible to use the parameter "force" to force the de…

---

## [How to properly add an ngram tokenizer via Nest](https://discuss.elastic.co/t/how-to-properly-add-an-ngram-tokenizer-via-nest/329777)

<div class="topic-metadata">

**Author:** [@jfavaro](https://discuss.elastic.co/u/jfavaro)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 9:05pm UTC](https://discuss.elastic.co/t/how-to-properly-add-an-ngram-tokenizer-via-nest/329777 "2023-04-11T21:05:22Z")

</div>

We have an existing Elastic version 8.3.3 with a .Net implementation using Nest 7.17.5. I've been trying to add a new field utitlizing an ngram tokenizer but whenever I add the code to my analyzers the existing full\_aut…

---

## [FortiMail logs are being combined in TCP input](https://discuss.elastic.co/t/fortimail-logs-are-being-combined-in-tcp-input/329768)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/fortimail-logs-are-being-combined-in-tcp-input/329768 "2023-04-11T19:12:53Z")

</div>

I have configured a tcp input in logstash to receive FortiMail logs. I believe the logs are losing their new line character in transit because all of the logs come in as a single document. (If I leave the pipeline runnin…

---

## [Kibana Dashboard Filter - Based on Columns](https://discuss.elastic.co/t/kibana-dashboard-filter-based-on-columns/327695)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 6:59pm UTC](https://discuss.elastic.co/t/kibana-dashboard-filter-based-on-columns/327695 "2023-04-11T18:59:35Z")

</div>

Hi, Please advise to achieve the below requirement Data Fields and Sample Values I want to have only one Bar chart which should top 3 person name based upon the selected filter. The Dashboard filter should have the…

---

## [Breakdown metric by formula result](https://discuss.elastic.co/t/breakdown-metric-by-formula-result/328954)

<div class="topic-metadata">

**Author:** [@Nithin\_Ramesh](https://discuss.elastic.co/u/Nithin_Ramesh)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 5:59pm UTC](https://discuss.elastic.co/t/breakdown-metric-by-formula-result/328954 "2023-04-11T17:59:00Z")

</div>

Hey, I am trying to visualize some data, but I have a feeling that I may be trying to do something that is impossible in Kibana currently. I have data that logs each event in a shipment process that consists of moving 1…

---

## [Is Elasticsearch paid?](https://discuss.elastic.co/t/is-elasticsearch-paid/329759)

<div class="topic-metadata">

**Author:** [@adzik](https://discuss.elastic.co/u/adzik)\
**Replies:** 6\
**Last updated:** [April 11, 2023, 5:52pm UTC](https://discuss.elastic.co/t/is-elasticsearch-paid/329759 "2023-04-11T17:52:54Z")

</div>

Hello, I have an ecommerce app and I would like to utilize Elasticsearch to search my products by customers. Do I need to buy a license in this case? I just want to make sure

---

## [Showing percentage](https://discuss.elastic.co/t/showing-percentage/328604)

<div class="topic-metadata">

**Author:** [@demarco-ion](https://discuss.elastic.co/u/demarco-ion)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 5:43pm UTC](https://discuss.elastic.co/t/showing-percentage/328604 "2023-04-11T17:43:18Z")

</div>

Hi, I am trying to show a percentage value on Kibana, but let me specify better the problem. Basically I have two integer fields in two different indexes which are related to each other, the first one is computed on the…

---

## [Elasicsearch index error: org.elasticsearch.core.Tuple.v2()" is null](https://discuss.elastic.co/t/elasicsearch-index-error-org-elasticsearch-core-tuple-v2-is-null/329763)

<div class="topic-metadata">

**Author:** [@vanwoes](https://discuss.elastic.co/u/vanwoes)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 4:06pm UTC](https://discuss.elastic.co/t/elasicsearch-index-error-org-elasticsearch-core-tuple-v2-is-null/329763 "2023-04-11T16:06:53Z")

</div>

Hi there, We have recently moved from a single node to multi node cluster and I have set up an ILM to move from hot, warm to cold. I keep seeing data moving from cold to warm despite it being marked as complete. I'm co…

---

## [Error: system/socket dataset setup failed](https://discuss.elastic.co/t/error-system-socket-dataset-setup-failed/329761)

<div class="topic-metadata">

**Author:** [@med\_dp](https://discuss.elastic.co/u/med_dp)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 3:33pm UTC](https://discuss.elastic.co/t/error-system-socket-dataset-setup-failed/329761 "2023-04-11T15:33:29Z")

</div>

Hello all I have this issus with auditeat, any help please Apr 11 01:08:47 wnl03 auditbeat\[13640\]: 2023-04-11T01:08:47.574+0200 ERROR instance/beat.go:989 Exiting: 1 error: system/socket dataset se…

---

## [Logstash error](https://discuss.elastic.co/t/logstash-error/329706)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 3:16pm UTC](https://discuss.elastic.co/t/logstash-error/329706 "2023-04-11T15:16:08Z")

</div>

Dear sir ; i want to send a json log file from my local pc to Elasticsearch my sample json file is { "people" : \[ { "firstName": "Joe", "lastName": "Jackson", "gender": "male", "age": 28, "number": "7349282382" …

---

## [Grok filter isn't working but working in kibana grok debugger](https://discuss.elastic.co/t/grok-filter-isnt-working-but-working-in-kibana-grok-debugger/329755)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 2:44pm UTC](https://discuss.elastic.co/t/grok-filter-isnt-working-but-working-in-kibana-grok-debugger/329755 "2023-04-11T14:44:21Z")

</div>

Hi. I have the following logstash configuration: filter { if "platform1" in \[tags\] { grok { match =\> { "message" =\> \['%{TIMESTAMP\_ISO8601:timestamp}? ?\\\[?L?:? ?%{LOGLEVEL:logLevel}?\\\]…

---

## [How to give access to few documents in a field on a role?](https://discuss.elastic.co/t/how-to-give-access-to-few-documents-in-a-field-on-a-role/329534)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/how-to-give-access-to-few-documents-in-a-field-on-a-role/329534 "2023-04-11T13:52:50Z")

</div>

Hi, Lets say I have an index with following documents {"Country": "India", "sample":1 , "Data":"hi" } {"Country": "India", "sample": 2, "Data":"hello" } {"Country": "India", "sample": 3, "Data":"how" } {"Country": "B…

---

## [Parsing logfiles](https://discuss.elastic.co/t/parsing-logfiles/329505)

<div class="topic-metadata">

**Author:** [@SIRAJEDDINE-HAMZA](https://discuss.elastic.co/u/SIRAJEDDINE-HAMZA)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 1:08pm UTC](https://discuss.elastic.co/t/parsing-logfiles/329505 "2023-04-11T13:08:16Z")

</div>

I'm new to using ElasticStack and I'm having trouble parsing a log file using Logstash. Specifically, I want to split the file using the timestamp as a separator and extract data from each block, but I'm not sure how to …

---

## [License in a cluster](https://discuss.elastic.co/t/license-in-a-cluster/329502)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 6\
**Last updated:** [April 11, 2023, 12:33pm UTC](https://discuss.elastic.co/t/license-in-a-cluster/329502 "2023-04-11T12:33:05Z")

</div>

Hello I have a cluster with 5 nodes, one of them (master) is installed on-premises and I have 4 nodes connected to it if I put a license on elasticsearch which is installed on-premises will this license be passed to the…

---

## [Bulk ingester no close at the end](https://discuss.elastic.co/t/bulk-ingester-no-close-at-the-end/329633)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 3\
**Last updated:** [April 11, 2023, 12:11pm UTC](https://discuss.elastic.co/t/bulk-ingester-no-close-at-the-end/329633 "2023-04-11T12:11:49Z")

</div>

I read the documents but it is not clear to me. I have this code: public void indexProduct(Product product) { try (BulkIngester\<String\> bulkIngester = indexingService.createBulkIngester()) { indexingService.bulkI…

---

## [Run direct dsl query using high level client elasticsearch](https://discuss.elastic.co/t/run-direct-dsl-query-using-high-level-client-elasticsearch/329746)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 11:56am UTC](https://discuss.elastic.co/t/run-direct-dsl-query-using-high-level-client-elasticsearch/329746 "2023-04-11T11:56:47Z")

</div>

I am trying run dsl query directly as we do from dev tools. I created java api for that but want provide formatted string. Is there any way to do this? in Elasticsearch

---

## [How to set default value for rank\_feature field type](https://discuss.elastic.co/t/how-to-set-default-value-for-rank-feature-field-type/329694)

<div class="topic-metadata">

**Author:** [@binoiii](https://discuss.elastic.co/u/binoiii)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 1:09am UTC](https://discuss.elastic.co/t/how-to-set-default-value-for-rank-feature-field-type/329694 "2023-04-11T01:09:13Z")

</div>

I'm performing a rank\_feature query and there is a possibility that the fields that I will rank i.e bid field (please below) won't be available. I wonder if there is a way to set a default for bid if the field is not pr…

---

## [How to receive alerts in two elasticsearch](https://discuss.elastic.co/t/how-to-receive-alerts-in-two-elasticsearch/329743)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 11:40am UTC](https://discuss.elastic.co/t/how-to-receive-alerts-in-two-elasticsearch/329743 "2023-04-11T11:40:51Z")

</div>

Hello, I want to know how do I send alerts from one elasticsearch to another. Let's imagine that I have 2 elasticsearch servers in different networks and clusters and on one server I have the fleet installed and several …

---

## [Single page appliaction (SPA) using Elasticsearch REST APIs](https://discuss.elastic.co/t/single-page-appliaction-spa-using-elasticsearch-rest-apis/329735)

<div class="topic-metadata">

**Author:** [@gichhr](https://discuss.elastic.co/u/gichhr)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 10:52am UTC](https://discuss.elastic.co/t/single-page-appliaction-spa-using-elasticsearch-rest-apis/329735 "2023-04-11T10:52:48Z")

</div>

Hello, I'd like to confirm that can be generated a React static Single Page Application (SPA) that use Elasticsearch REST APIs for authentication and role authorization and queering data form indexes. This static SPA ca…

---

## [How to view documents by lucene segment?](https://discuss.elastic.co/t/how-to-view-documents-by-lucene-segment/329512)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 10:16am UTC](https://discuss.elastic.co/t/how-to-view-documents-by-lucene-segment/329512 "2023-04-11T10:16:03Z")

</div>

Hello elasticsearch, I have a tricky question. I accidentally reindexed a bunch of documents into a wrong index. This original index was previously forcemerged to one big segment per shard. Indexing new documents creat…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=574)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=576)
