# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=579

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 580

---

## [How to disable add\_cloud\_metadata processor?](https://discuss.elastic.co/t/how-to-disable-add-cloud-metadata-processor/329463)

<div class="topic-metadata">

**Author:** [@Vanav](https://discuss.elastic.co/u/Vanav)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 8:01pm UTC](https://discuss.elastic.co/t/how-to-disable-add-cloud-metadata-processor/329463 "2023-04-05T20:01:05Z")

</div>

I have a standalone Elastic Agent with filestream input. I want to cleanup sent data. How to disable default processors add\_cloud\_metadata and others? I can drop fields, but I prefer to disable processor. In filebeat I …

---

## [Logstash: Ingesting the data from Azure Storage](https://discuss.elastic.co/t/logstash-ingesting-the-data-from-azure-storage/329404)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 7:29pm UTC](https://discuss.elastic.co/t/logstash-ingesting-the-data-from-azure-storage/329404 "2023-04-05T19:29:46Z")

</div>

I know from AWS S3 we can ingest the data into elasticsearch using logstash. Similar way is it possible to ingest the data from Azure Storage as well? I don't see the input plugin in the documentation - Input plugins | …

---

## [Terraform Elastic Provider using the CA fingerprint](https://discuss.elastic.co/t/terraform-elastic-provider-using-the-ca-fingerprint/329115)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 7:25pm UTC](https://discuss.elastic.co/t/terraform-elastic-provider-using-the-ca-fingerprint/329115 "2023-04-05T19:25:56Z")

</div>

Would be great to incorporate the CA fingerprint into the Provider options, any timeline on this ?

---

## [KIbana login giving warning](https://discuss.elastic.co/t/kibana-login-giving-warning/329155)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 7:19pm UTC](https://discuss.elastic.co/t/kibana-login-giving-warning/329155 "2023-04-05T19:19:50Z")

</div>

Hi all, When i try to login to my kibana the below login warning pops up: Configuration recommended In a production environment, it is recommended that you configureserver.publicBaseUrl. \[Learn more.\](https://www.elast…

---

## [Elastic parsing error field type format incorrect](https://discuss.elastic.co/t/elastic-parsing-error-field-type-format-incorrect/329352)

<div class="topic-metadata">

**Author:** [@merlin](https://discuss.elastic.co/u/merlin)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 7:18pm UTC](https://discuss.elastic.co/t/elastic-parsing-error-field-type-format-incorrect/329352 "2023-04-05T19:18:40Z")

</div>

Hello, I am collecting windows event logs via MS windows event log collector and then forwarded to graylog via winlogbeats. I am getting alerts to parsing errors for a winlogbeat field shown below due to the field data b…

---

## [Minimal/optimal hardware setup for one node Elasticsearch stack with daily index 10GB to 20GB](https://discuss.elastic.co/t/minimal-optimal-hardware-setup-for-one-node-elasticsearch-stack-with-daily-index-10gb-to-20gb/328944)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 5:40pm UTC](https://discuss.elastic.co/t/minimal-optimal-hardware-setup-for-one-node-elasticsearch-stack-with-daily-index-10gb-to-20gb/328944 "2023-04-05T17:40:44Z")

</div>

Hello everybody. I'm new here, but very happy to join the community. Is there any official documentation regarding minimal / optimal hardware requirements for Elasticsearch ? Soon I will put in production single node …

---

## [Elasticsearch 8.2.0 doesn't start in centos 8](https://discuss.elastic.co/t/elasticsearch-8-2-0-doesnt-start-in-centos-8/329322)

<div class="topic-metadata">

**Author:** [@dhrchatt](https://discuss.elastic.co/u/dhrchatt)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 3:30pm UTC](https://discuss.elastic.co/t/elasticsearch-8-2-0-doesnt-start-in-centos-8/329322 "2023-04-05T15:30:53Z")

</div>

When I start elasticsearch-8.2.0 version in Linux Centos8, it is giving following error: 0.000s\]\[warning\]\[os,container\] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /scratch/chroot/OL\_7…

---

## ["filter by geometry" button missing for some indexes](https://discuss.elastic.co/t/filter-by-geometry-button-missing-for-some-indexes/329259)

<div class="topic-metadata">

**Author:** [@Donald\_Morton](https://discuss.elastic.co/u/Donald_Morton)\
**Replies:** 4\
**Last updated:** [April 4, 2023, 1:57pm UTC](https://discuss.elastic.co/t/filter-by-geometry-button-missing-for-some-indexes/329259 "2023-04-04T13:57:23Z")

</div>

Kibana: 8.3.2 Hi, i'm trying to use the "filter by geometry" button but it happens to be missing on some indexes. Any idea why it only appears in some?

---

## [Cluster Redundancy](https://discuss.elastic.co/t/cluster-redundancy/329415)

<div class="topic-metadata">

**Author:** [@George\_Smith](https://discuss.elastic.co/u/George_Smith)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 3:00pm UTC](https://discuss.elastic.co/t/cluster-redundancy/329415 "2023-04-05T15:00:46Z")

</div>

Hi all, I have a question regarding network redundancy with an Elasticsearch Cluster. I am attempting to add redundancy to my cluster so that if a network adapter a node is using fails, it can use another network adapt…

---

## [Similar configuration for multiple Filebeat inputs](https://discuss.elastic.co/t/similar-configuration-for-multiple-filebeat-inputs/329443)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:34pm UTC](https://discuss.elastic.co/t/similar-configuration-for-multiple-filebeat-inputs/329443 "2023-04-05T14:34:46Z")

</div>

Hi, I am using Filebeat on about ten servers (almost all under Linux except 2 under Windows). I have edited a filebeat.yml file on each one and approximately 10 inputs inside both. Inputs are only 'filestream' type for t…

---

## [Char\_Filter pattern replace is not behaving correctly](https://discuss.elastic.co/t/char-filter-pattern-replace-is-not-behaving-correctly/329445)

<div class="topic-metadata">

**Author:** [@ahiggins](https://discuss.elastic.co/u/ahiggins)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:44pm UTC](https://discuss.elastic.co/t/char-filter-pattern-replace-is-not-behaving-correctly/329445 "2023-04-05T14:44:42Z")

</div>

Elasticsearch Version 7.178 I am trying to work on a custom analyzer that would fix problematic texts in our database that contain unsearchable texts that are being obscured by existing '\\u200c' characters, or half-spac…

---

## [Either white space or a %{WORD:\_\_\_\_\_}](https://discuss.elastic.co/t/either-white-space-or-a-word/329357)

<div class="topic-metadata">

**Author:** [@Jim\_Thunder](https://discuss.elastic.co/u/Jim_Thunder)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 2:35pm UTC](https://discuss.elastic.co/t/either-white-space-or-a-word/329357 "2023-04-05T14:35:12Z")

</div>

I have two different kinds of messages that are very similar: "Rec": " 10:33:38 +HCXPCTA-E CW83 ISMDAYS ASRA"} "Rec": " 10:31:56 +HCXPCTA-E IS60 RX1 ISMDAYS ASRA"} In the REC field one message has RX1 while …

---

## [Meraki not parsing sport and saddr correctly](https://discuss.elastic.co/t/meraki-not-parsing-sport-and-saddr-correctly/329440)

<div class="topic-metadata">

**Author:** [@pozniako16](https://discuss.elastic.co/u/pozniako16)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:26pm UTC](https://discuss.elastic.co/t/meraki-not-parsing-sport-and-saddr-correctly/329440 "2023-04-05T14:26:17Z")

</div>

Currently in the parsing pipeline for meraki. The sport and saddr are inverted. Address should be in Address:Port format not the opposite.

---

## [Bulk via Python to Kubernetes cluster](https://discuss.elastic.co/t/bulk-via-python-to-kubernetes-cluster/329065)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 1:46pm UTC](https://discuss.elastic.co/t/bulk-via-python-to-kubernetes-cluster/329065 "2023-04-05T13:46:38Z")

</div>

Hi! We are heavily indexing to Elasticsearch 8.6.1 via Python code using bulk API. Our cluster runs on Kubernetes with the elastic operator which creates the following services: my-cluster-es-data my-cluster-es-http m…

---

## [Kibana data](https://discuss.elastic.co/t/kibana-data/329329)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 1:19pm UTC](https://discuss.elastic.co/t/kibana-data/329329 "2023-04-05T13:19:42Z")

</div>

hello i use filebeat to load data from a virtual machine to Elasticsearch and i found it in discover as data stream i just have a question why the number of hits decrease everytime and not still the same thank u

---

## [Prevent filebeat-version-yyyy-mm-dd index from ingesting](https://discuss.elastic.co/t/prevent-filebeat-version-yyyy-mm-dd-index-from-ingesting/329152)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 5\
**Last updated:** [April 5, 2023, 12:37pm UTC](https://discuss.elastic.co/t/prevent-filebeat-version-yyyy-mm-dd-index-from-ingesting/329152 "2023-04-05T12:37:09Z")

</div>

On daily basis i am seeing indexes with name filebeat-7.17.7-yyyy-mm-dd are creating. This is eating lot of space i have to delete them manually. I Have seen options like to create entry in ES which will not allow aut…

---

## [What happened to composite runtime fields in Elasticsearch client?](https://discuss.elastic.co/t/what-happened-to-composite-runtime-fields-in-elasticsearch-client/329430)

<div class="topic-metadata">

**Author:** [@MichaelOpitz](https://discuss.elastic.co/u/MichaelOpitz)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 12:33pm UTC](https://discuss.elastic.co/t/what-happened-to-composite-runtime-fields-in-elasticsearch-client/329430 "2023-04-05T12:33:43Z")

</div>

Hi community, We used composite runtime fields in the Elasticsearch java client. But since we moved to the new Elasticsearch client, composite runtime fields are not longer supported. Are these runtime fields deprecate…

---

## [Index and search multiple indices and fields](https://discuss.elastic.co/t/index-and-search-multiple-indices-and-fields/329324)

<div class="topic-metadata">

**Author:** [@Adarsh\_R\_K](https://discuss.elastic.co/u/Adarsh_R_K)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 12:14pm UTC](https://discuss.elastic.co/t/index-and-search-multiple-indices-and-fields/329324 "2023-04-05T12:14:45Z")

</div>

I am new to elasticsearch I am using elasticsearch java-client library to in spring boot application for a global search functionality.I have 5 entity classes with multiple fileds to search for , how can I do that ? I …

---

## [How can I identify the root cause and fix a query in Elasticsearch cluster that never returns a response](https://discuss.elastic.co/t/how-can-i-identify-the-root-cause-and-fix-a-query-in-elasticsearch-cluster-that-never-returns-a-response/329424)

<div class="topic-metadata">

**Author:** [@Sagar\_Gulabani1](https://discuss.elastic.co/u/Sagar_Gulabani1)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 11:35am UTC](https://discuss.elastic.co/t/how-can-i-identify-the-root-cause-and-fix-a-query-in-elasticsearch-cluster-that-never-returns-a-response/329424 "2023-04-05T11:35:11Z")

</div>

How can I identify the root cause and fix a query in Elasticsearch cluster that never returns a response. I have an Elasticsearch cluster with Elasticsearch, Logstash, and Kibana running on the same machine using Docker…

---

## [How to visualize color change depending on the counts on a bar vertical graph?](https://discuss.elastic.co/t/how-to-visualize-color-change-depending-on-the-counts-on-a-bar-vertical-graph/329413)

<div class="topic-metadata">

**Author:** [@OlegG](https://discuss.elastic.co/u/OlegG)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 11:39am UTC](https://discuss.elastic.co/t/how-to-visualize-color-change-depending-on-the-counts-on-a-bar-vertical-graph/329413 "2023-04-05T11:39:43Z")

</div>

The question seems to be clear enough. The picture should look like this.

---

## [How to transfer users from an Elastic Cluster to another one](https://discuss.elastic.co/t/how-to-transfer-users-from-an-elastic-cluster-to-another-one/329366)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 10:54am UTC](https://discuss.elastic.co/t/how-to-transfer-users-from-an-elastic-cluster-to-another-one/329366 "2023-04-05T10:54:54Z")

</div>

Hey everyone! I need to copy the users and roles from an Elastic cluster 7.9 to a new 8.3.2 cluster. Is there a way to do that? Recreating manually is not possible since we have hundreds of users configured and most of…

---

## [Problem with data streams date after rollover](https://discuss.elastic.co/t/problem-with-data-streams-date-after-rollover/329410)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 9:59am UTC](https://discuss.elastic.co/t/problem-with-data-streams-date-after-rollover/329410 "2023-04-05T09:59:27Z")

</div>

Hi. I configured ES to rollover my indexes every day. I noticed that today my index rolled at Current action time 2023-04-05 00:34:31. Despite that, the index name created was .ds-suricata-ids-8.6.2-2023.04.04-000010 w…

---

## [Unable to add empty field with Logstash](https://discuss.elastic.co/t/unable-to-add-empty-field-with-logstash/329306)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 9:34am UTC](https://discuss.elastic.co/t/unable-to-add-empty-field-with-logstash/329306 "2023-04-05T09:34:39Z")

</div>

Hello community! I'm trying to add empty field into Logstash parsers like this: mutate { add\_field =\> {"comments" =\> {} } } this is my mapping in Kibana: { "\_meta": { "documentation": "https://www.elastic.co/gu…

---

## [New Filebeat Module - ECS not supports email fields](https://discuss.elastic.co/t/new-filebeat-module-ecs-not-supports-email-fields/329339)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 2:59pm UTC](https://discuss.elastic.co/t/new-filebeat-module-ecs-not-supports-email-fields/329339 "2023-04-04T14:59:46Z")

</div>

Hi I'm trying to contribute several new filebeat modules (Postfix and Exchange) and can't use email fields. Seems filebeat tests use old ECS schema. I've tried to change ecs version to the last one but it's not working. …

---

## [Issue with elasticsearch](https://discuss.elastic.co/t/issue-with-elasticsearch/329333)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 6\
**Last updated:** [April 5, 2023, 9:11am UTC](https://discuss.elastic.co/t/issue-with-elasticsearch/329333 "2023-04-05T09:11:25Z")

</div>

\[logstash.outputs.elasticsearch\]\[main\] Attempted to resurrect connection to dead ES instance, but got an error {:url=\>"http://newadmin:xxxxxx@localhost:9200/", :exception=\>LogStash::Outputs::Elasticsearch::HttpClient::Po…

---

## [Ingest @timestamp](https://discuss.elastic.co/t/ingest-timestamp/329400)

<div class="topic-metadata">

**Author:** [@sta](https://discuss.elastic.co/u/sta)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 8:51am UTC](https://discuss.elastic.co/t/ingest-timestamp/329400 "2023-04-05T08:51:01Z")

</div>

Hello. I have a log file where timestamp is \[2023-04-05 07:42:35\]. I made a ingest pipeline PUT \_ingest/pipeline/fe-logs-json { "processors": \[ { "grok": { "field": "message", "patterns": \[ …

---

## [Latency reporting and rate limitting in logging-indexing-querying track](https://discuss.elastic.co/t/latency-reporting-and-rate-limitting-in-logging-indexing-querying-track/329135)

<div class="topic-metadata">

**Author:** [@Jiri\_Holusa](https://discuss.elastic.co/u/Jiri_Holusa)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 8:48am UTC](https://discuss.elastic.co/t/latency-reporting-and-rate-limitting-in-logging-indexing-querying-track/329135 "2023-04-05T08:48:02Z")

</div>

Hi, we're using rally for performance evaluation. In our case, it's about the effect of a JVM to Elasticsearch's performance (disclaimer: I work for Azul). We would like to use challenge "elastic/logs", track "logging-…

---

## [Is it possible to recover logs that failed to transfer to ElasticSearch?](https://discuss.elastic.co/t/is-it-possible-to-recover-logs-that-failed-to-transfer-to-elasticsearch/329401)

<div class="topic-metadata">

**Author:** [@r.fujii](https://discuss.elastic.co/u/r.fujii)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 8:35am UTC](https://discuss.elastic.co/t/is-it-possible-to-recover-logs-that-failed-to-transfer-to-elasticsearch/329401 "2023-04-05T08:35:20Z")

</div>

The following configuration is used to obtain the server's audit logs and forward them to Elasticsearch. AuditBeat -\> Logstash -\> Elasticsearch However, on Elasticsearch, the number of shards exceeded max\_shards\_per\_no…

---

## [Script Exception on Elasticsearch function score script query](https://discuss.elastic.co/t/script-exception-on-elasticsearch-function-score-script-query/329387)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 8:07am UTC](https://discuss.elastic.co/t/script-exception-on-elasticsearch-function-score-script-query/329387 "2023-04-05T08:07:46Z")

</div>

Hello, I have used function score for a query and my script is: "doc\['Field1\_score'\].value != null && doc\['Field2\_score'\].value !=null ? (doc\['Field1\_score'\].value \* 100000) + (doc\['Field2\_score'\].value \* 100000) : 1", …

---

## [Rally eventdata-track & support for Elastic Stack 8.x](https://discuss.elastic.co/t/rally-eventdata-track-support-for-elastic-stack-8-x/329312)

<div class="topic-metadata">

**Author:** [@jan.stap](https://discuss.elastic.co/u/jan.stap)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 7:53am UTC](https://discuss.elastic.co/t/rally-eventdata-track-support-for-elastic-stack-8-x/329312 "2023-04-05T07:53:44Z")

</div>

Hi, In this post I read that the rally-eventdata-track is not supported for Elasticsearch 8.x, but I find no further info on that. The README.md says it is compatible with the latest development version of Elasticsearch…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=578)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=580)
