# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=577

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 578

---

## [Elastic search update document , Java client-8.7](https://discuss.elastic.co/t/elastic-search-update-document-java-client-8-7/329644)

<div class="topic-metadata">

**Author:** [@Adarsh\_R\_K](https://discuss.elastic.co/u/Adarsh_R_K)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 7:25am UTC](https://discuss.elastic.co/t/elastic-search-update-document-java-client-8-7/329644 "2023-04-10T07:25:10Z")

</div>

How to update a document using elasticsearch Java client-8.7 , I could not find any documentation,All the avalilable ones are deprecated.

---

## [Map winlog.event\_data.param\* to text](https://discuss.elastic.co/t/map-winlog-event-data-param-to-text/329642)

<div class="topic-metadata">

**Author:** [@yohanwongso](https://discuss.elastic.co/u/yohanwongso)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 7:17am UTC](https://discuss.elastic.co/t/map-winlog-event-data-param-to-text/329642 "2023-04-10T07:17:24Z")

</div>

By default, Winlogbeat would map the winlog.event\_data.param\* as keyword. How to map the field to multi-fields keyword and text?

---

## [Clarification on cold/frozen state](https://discuss.elastic.co/t/clarification-on-cold-frozen-state/329575)

<div class="topic-metadata">

**Author:** [@QwerFact](https://discuss.elastic.co/u/QwerFact)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 6:58am UTC](https://discuss.elastic.co/t/clarification-on-cold-frozen-state/329575 "2023-04-10T06:58:33Z")

</div>

Hiya, with the changes in version 8, the frozen tier has evolved. I was wondering about the differences between cold, cold fully-mounted and frozen and especially between open source and enterprise/platinum versions. M…

---

## [Logstash pipeline error when processing a csv file](https://discuss.elastic.co/t/logstash-pipeline-error-when-processing-a-csv-file/329612)

<div class="topic-metadata">

**Author:** [@Ashutosh\_Vaidya](https://discuss.elastic.co/u/Ashutosh_Vaidya)\
**Replies:** 6\
**Last updated:** [April 10, 2023, 3:44am UTC](https://discuss.elastic.co/t/logstash-pipeline-error-when-processing-a-csv-file/329612 "2023-04-10T03:44:39Z")

</div>

Hello I am getting the below error when running the pipeline logstash conf file. Kindly let me know way to overcome this error student@elk:/$ sudo /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/csv-read-3.co…

---

## [Difference between KIBANA\_CA and KIBANA\_FLEET\_CA](https://discuss.elastic.co/t/difference-between-kibana-ca-and-kibana-fleet-ca/329634)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 4:06am UTC](https://discuss.elastic.co/t/difference-between-kibana-ca-and-kibana-fleet-ca/329634 "2023-04-10T04:06:15Z")

</div>

Hello everyone. Currently i'm having trouble with applying elastic agent(managed by fleet) to my kubernetes environment. i think one of the related parameter is KIBANA\_CA and KIBANA\_FLEET\_CA. so far, i followed steps …

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/329615)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 2:50am UTC](https://discuss.elastic.co/t/elasticsearch/329615 "2023-04-10T02:50:46Z")

</div>

where is the problem ? curl --cacert http\_ca.crt -u elastic https://localhost:9200 Invoke-WebRequest : Parameter cannot be processed because the parameter name 'u' is ambiguous. Possible matches include: -UseBasicParsi…

---

## [What is the point and purpose of ca\_trusted\_fingerprint?](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 3\
**Last updated:** [April 9, 2023, 5:40pm UTC](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623 "2023-04-09T17:40:38Z")

</div>

What is the point of adding the ca\_trusted\_fingerprint parameter to an logstash-output-elasticsearch section in an output filter? Is it purely to defend against a possible attack on DNS servers? Misconfiguration of the E…

---

## [Unable to perform airthmetic operations in ruby using logstash pipeline](https://discuss.elastic.co/t/unable-to-perform-airthmetic-operations-in-ruby-using-logstash-pipeline/329587)

<div class="topic-metadata">

**Author:** [@Sujith\_Nair](https://discuss.elastic.co/u/Sujith_Nair)\
**Replies:** 10\
**Last updated:** [April 9, 2023, 1:54pm UTC](https://discuss.elastic.co/t/unable-to-perform-airthmetic-operations-in-ruby-using-logstash-pipeline/329587 "2023-04-09T13:54:45Z")

</div>

Hi guys, I am facing an issue where i am trying to perform an airthmetic operation using ruby but in at the field section i am getting the same value not the subtracted value. event.set('\[d\]', (event.get('\[b\]').to\_f) -…

---

## [ERROR: Failed to reset password for the \[elastic\] user](https://discuss.elastic.co/t/error-failed-to-reset-password-for-the-elastic-user/329618)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 1\
**Last updated:** [April 9, 2023, 7:44am UTC](https://discuss.elastic.co/t/error-failed-to-reset-password-for-the-elastic-user/329618 "2023-04-09T07:44:55Z")

</div>

Hi, I installed elasticsearch 8.7 on my windows server but on installing screen I did not get any prompt for my elasticsearch or kibana password, also when I tried to change the password I faced following error: ERROR:…

---

## [Logstash memory consumption and swap memory issues](https://discuss.elastic.co/t/logstash-memory-consumption-and-swap-memory-issues/329456)

<div class="topic-metadata">

**Author:** [@Ofek\_Agmon](https://discuss.elastic.co/u/Ofek_Agmon)\
**Replies:** 12\
**Last updated:** [April 9, 2023, 7:26am UTC](https://discuss.elastic.co/t/logstash-memory-consumption-and-swap-memory-issues/329456 "2023-04-09T07:26:56Z")

</div>

Hi all, I've been using logstash version 7.17.8 in docker, and for a while now trying to minimize its memory usage and swap usage, without much success. I have 2 file inputs and one gelf input, and 2 small filters. I …

---

## [Logstash running code](https://discuss.elastic.co/t/logstash-running-code/329408)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 12:22pm UTC](https://discuss.elastic.co/t/logstash-running-code/329408 "2023-04-05T12:22:26Z")

</div>

Hyy, I am new to Elasticsearch . I am trying to send logfile from logstash to elasticsearch . for checking purspose i am running this config file as below vi logstash-simple.conf input { stdin { } } output { elasti…

---

## [Installing elasticsearch 8.6.2 on a windows server with ealsticserach 7.6.1](https://discuss.elastic.co/t/installing-elasticsearch-8-6-2-on-a-windows-server-with-ealsticserach-7-6-1/329281)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 7\
**Last updated:** [April 9, 2023, 5:01am UTC](https://discuss.elastic.co/t/installing-elasticsearch-8-6-2-on-a-windows-server-with-ealsticserach-7-6-1/329281 "2023-04-09T05:01:58Z")

</div>

In our company we have been using Elasticsearch 7.6.1 for two years, right now we need to update it to version 8.6.2, however, we can not move to version 8.6.2 immediately, we need first run Elasticsearch 8.6.2 beside th…

---

## [Geo\_shape query point in polygon runtime field for pre-indexed docs](https://discuss.elastic.co/t/geo-shape-query-point-in-polygon-runtime-field-for-pre-indexed-docs/329550)

<div class="topic-metadata">

**Author:** [@bchranko](https://discuss.elastic.co/u/bchranko)\
**Replies:** 3\
**Last updated:** [April 9, 2023, 12:48am UTC](https://discuss.elastic.co/t/geo-shape-query-point-in-polygon-runtime-field-for-pre-indexed-docs/329550 "2023-04-09T00:48:35Z")

</div>

I'm trying to create a geo\_shape query that will be used in a runtime field to tag a polygon 'id/name' to a point that it contains. I have two pre-indexed indexes: one for neighborhoods (polygon) and one for car crashe…

---

## [Configuration elasticsearch](https://discuss.elastic.co/t/configuration-elasticsearch/329506)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 10\
**Last updated:** [April 8, 2023, 11:14pm UTC](https://discuss.elastic.co/t/configuration-elasticsearch/329506 "2023-04-08T23:14:51Z")

</div>

hi i want to Start Elasticsearch in Docker by this command : docker run --name es01 --net elastic -p 9200:9200 -it docker.elastic.co/elasticsearch/elasticsearch:8.7.0 but i have this probleme : ERROR: Elasticsearch di…

---

## [Search for a keyword in the field in the title, which can occur simultaneously several matching words from the query](https://discuss.elastic.co/t/search-for-a-keyword-in-the-field-in-the-title-which-can-occur-simultaneously-several-matching-words-from-the-query/329608)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 10:25am UTC](https://discuss.elastic.co/t/search-for-a-keyword-in-the-field-in-the-title-which-can-occur-simultaneously-several-matching-words-from-the-query/329608 "2023-04-08T10:25:38Z")

</div>

I want to find blenders in elastic of a certain name & color and brand. To do this, specify 3 fields for the search, specifying in which field elastic should start the search. Elastic returns products that I have not sea…

---

## [Filebeat can not talk to ELK on AWS EKS](https://discuss.elastic.co/t/filebeat-can-not-talk-to-elk-on-aws-eks/329600)

<div class="topic-metadata">

**Author:** [@williamsun](https://discuss.elastic.co/u/williamsun)\
**Replies:** 2\
**Last updated:** [April 8, 2023, 9:49am UTC](https://discuss.elastic.co/t/filebeat-can-not-talk-to-elk-on-aws-eks/329600 "2023-04-08T09:49:31Z")

</div>

Hello Everyone, I am using the follow doc to setup the filebeat on EKS. curl -L -O https://raw.githubusercontent.com/elastic/beats/8.7/deploy/kubernetes/filebeat-kubernetes.yaml Default Setting does not work name: …

---

## [Logs in kibana are shown every hour, not during the hour](https://discuss.elastic.co/t/logs-in-kibana-are-shown-every-hour-not-during-the-hour/329607)

<div class="topic-metadata">

**Author:** [@habib\_huseyn](https://discuss.elastic.co/u/habib_huseyn)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 8:33am UTC](https://discuss.elastic.co/t/logs-in-kibana-are-shown-every-hour-not-during-the-hour/329607 "2023-04-08T08:33:44Z")

</div>

I send logs from palo alto to the syslog server using rsyslog. If from the syslog server, I send it to elasticsearch with the agent. but in kibana, the logs are shown in every hour, not during the hour

---

## [Schedule , scroll , size Elasticsearch input plugin Plugin more explanation](https://discuss.elastic.co/t/schedule-scroll-size-elasticsearch-input-plugin-plugin-more-explanation/329606)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 6:11am UTC](https://discuss.elastic.co/t/schedule-scroll-size-elasticsearch-input-plugin-plugin-more-explanation/329606 "2023-04-08T06:11:51Z")

</div>

I am using elasticsearch index as my input in logstash.I read the documentation and don't understand the usage of schedule , scroll , size option.I need more explanation to understand these featues. Thanks

---

## [Design Index & Document](https://discuss.elastic.co/t/design-index-document/329596)

<div class="topic-metadata">

**Author:** [@YB\_Coding](https://discuss.elastic.co/u/YB_Coding)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:47pm UTC](https://discuss.elastic.co/t/design-index-document/329596 "2023-04-07T18:47:45Z")

</div>

Hello everyone I have a hard time designing my documents. I do not know if I need to create multiple indexes, use nested fieds or index multiple times my documents with a field with a "versionning filter". Below my analo…

---

## [Updating @elastic/elasticsearch version on npm](https://discuss.elastic.co/t/updating-elastic-elasticsearch-version-on-npm/329595)

<div class="topic-metadata">

**Author:** [@Chukwuma\_Nwaugha](https://discuss.elastic.co/u/Chukwuma_Nwaugha)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:01pm UTC](https://discuss.elastic.co/t/updating-elastic-elasticsearch-version-on-npm/329595 "2023-04-07T18:01:27Z")

</div>

The latest version of @elastic/elasticsearch is 8.7.0 but the version on npm is still at 8.6.0. When should an update be expected? Thanks and best regards, Chukwuma.

---

## [Creating an indicator match Watcher Alert](https://discuss.elastic.co/t/creating-an-indicator-match-watcher-alert/329590)

<div class="topic-metadata">

**Author:** [@Banderson02](https://discuss.elastic.co/u/Banderson02)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 5:26pm UTC](https://discuss.elastic.co/t/creating-an-indicator-match-watcher-alert/329590 "2023-04-07T17:26:25Z")

</div>

Hello, Has anyone been able to replicate an indicator match alert like what is provided in Kibana security as an Elasticsearch Watcher alert? I have a deployment where we do not have access to Kibana Security, so I nee…

---

## [Can we create dependent inputs in logstash pipeline?](https://discuss.elastic.co/t/can-we-create-dependent-inputs-in-logstash-pipeline/329436)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 2\
**Last updated:** [April 7, 2023, 4:51pm UTC](https://discuss.elastic.co/t/can-we-create-dependent-inputs-in-logstash-pipeline/329436 "2023-04-07T16:51:15Z")

</div>

Hi Team, I have requirement to get the links from rss feed and extract each link and store its XML page source as a document in ES. I am trying to use rss and http\_poller input plugin together, something like below con…

---

## [Enforce Double quotes using csv codec plugin](https://discuss.elastic.co/t/enforce-double-quotes-using-csv-codec-plugin/329585)

<div class="topic-metadata">

**Author:** [@uzair13151](https://discuss.elastic.co/u/uzair13151)\
**Replies:** 1\
**Last updated:** [April 7, 2023, 4:30pm UTC](https://discuss.elastic.co/t/enforce-double-quotes-using-csv-codec-plugin/329585 "2023-04-07T16:30:09Z")

</div>

Hi All, Is it possible to wrap the data in the rows to be encapsulated by double quotes using csv codec plugin. Currently I am getting: Column1|Column2|Column3 Data1|Data2|"" Expectation: "Column1"|"Column2"|"Colum…

---

## [Elastic Agent show \`Error dialing x509: certificate signed by unknown authority\` but it is healthy in fleet](https://discuss.elastic.co/t/elastic-agent-show-error-dialing-x509-certificate-signed-by-unknown-authority-but-it-is-healthy-in-fleet/329514)

<div class="topic-metadata">

**Author:** [@Kelvin\_Chan](https://discuss.elastic.co/u/Kelvin_Chan)\
**Replies:** 3\
**Last updated:** [April 7, 2023, 5:09am UTC](https://discuss.elastic.co/t/elastic-agent-show-error-dialing-x509-certificate-signed-by-unknown-authority-but-it-is-healthy-in-fleet/329514 "2023-04-07T05:09:06Z")

</div>

I am building elastic stack for testing, which uses self-signed certificate. And i use docker compose to deploy them. Here is part of compose efleet: image: docker.elastic.co/beats/elastic-agent:${STACK\_VERSION} …

---

## [I don't see my index in index management](https://discuss.elastic.co/t/i-dont-see-my-index-in-index-management/329515)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 2\
**Last updated:** [April 7, 2023, 8:59am UTC](https://discuss.elastic.co/t/i-dont-see-my-index-in-index-management/329515 "2023-04-07T08:59:16Z")

</div>

Hello, I'm trying to send data from a CSV file to Elasticsearch using Logstash. I have configured my input, filter, and output, but I cannot find my index in Elasticsearch. I have the impression that Logstash is not proc…

---

## [ES upgrade from 5.6 to 8.7](https://discuss.elastic.co/t/es-upgrade-from-5-6-to-8-7/329568)

<div class="topic-metadata">

**Author:** [@salimtb](https://discuss.elastic.co/u/salimtb)\
**Replies:** 1\
**Last updated:** [April 7, 2023, 4:54am UTC](https://discuss.elastic.co/t/es-upgrade-from-5-6-to-8-7/329568 "2023-04-07T04:54:58Z")

</div>

Hi All, I am planning to upgrade the Elasticsearch from 5.6 to 8.7, I wanted to seek suggestions to see if it is a good idea to go directly from 5.6 to 8.7, or do a roll upgrade, application is built on Django and uses …

---

## [Elastic-operator version upgrade](https://discuss.elastic.co/t/elastic-operator-version-upgrade/329571)

<div class="topic-metadata">

**Author:** [@Satyajeet](https://discuss.elastic.co/u/Satyajeet)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:42am UTC](https://discuss.elastic.co/t/elastic-operator-version-upgrade/329571 "2023-04-07T06:42:33Z")

</div>

These are our existing environment parameters, GKE version 1.21.14-gke.14100 We had installed Elasticsearch with the following version previously, Elasticsearch version 7.9.2 Elastic Operator version 1.2.1 This is o…

---

## [Backfill with previous indexed data](https://discuss.elastic.co/t/backfill-with-previous-indexed-data/329321)

<div class="topic-metadata">

**Author:** [@suminlim](https://discuss.elastic.co/u/suminlim)\
**Replies:** 1\
**Last updated:** [April 7, 2023, 3:02am UTC](https://discuss.elastic.co/t/backfill-with-previous-indexed-data/329321 "2023-04-07T03:02:23Z")

</div>

using logstash, is it available ? input { elasticsearch { hosts =\> "localhost" index =\> "logs" query =\> '{ "sort": \[ "timeinfo" \] }' } } filter { if \[location\] == "" { // how to get previous data …

---

## [Backfill with previous indexed data](https://discuss.elastic.co/t/backfill-with-previous-indexed-data/329278)

<div class="topic-metadata">

**Author:** [@suminlim](https://discuss.elastic.co/u/suminlim)\
**Replies:** 7\
**Last updated:** [April 7, 2023, 3:01am UTC](https://discuss.elastic.co/t/backfill-with-previous-indexed-data/329278 "2023-04-07T03:01:09Z")

</div>

When the document sorted by timestamp, is there any solution that backfill location data into next row with previous row ???

---

## [Ingest pipeline gsub processor back reference not working](https://discuss.elastic.co/t/ingest-pipeline-gsub-processor-back-reference-not-working/329090)

<div class="topic-metadata">

**Author:** [@kmfreder1](https://discuss.elastic.co/u/kmfreder1)\
**Replies:** 8\
**Last updated:** [April 7, 2023, 12:36am UTC](https://discuss.elastic.co/t/ingest-pipeline-gsub-processor-back-reference-not-working/329090 "2023-04-07T00:36:18Z")

</div>

I am having trouble getting a back reference to work using the gsub processor in the elasticsearch ingest node pipeline. I am trying to get just the TLD from a dns.question.name field and using very similar syntax to wh…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=576)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=578)
