# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=582

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 583

---

## [How to changes advance setting on my build for ELK setup](https://discuss.elastic.co/t/how-to-changes-advance-setting-on-my-build-for-elk-setup/327716)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 3:52pm UTC](https://discuss.elastic.co/t/how-to-changes-advance-setting-on-my-build-for-elk-setup/327716 "2023-04-03T15:52:41Z")

</div>

Hello Team, Please help to change advance settings on my ELK setup for by build. I have tried with Kibana.yaml, but couldn't succeed. Below are parameters which require changes - Scaled Date Format storeinSessionStor…

---

## [Logstash does not creates nor updates index on elasticsearch](https://discuss.elastic.co/t/logstash-does-not-creates-nor-updates-index-on-elasticsearch/329069)

<div class="topic-metadata">

**Author:** [@Quentin\_Moisy](https://discuss.elastic.co/u/Quentin_Moisy)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 3:41pm UTC](https://discuss.elastic.co/t/logstash-does-not-creates-nor-updates-index-on-elasticsearch/329069 "2023-04-03T15:41:40Z")

</div>

Hello, I new to the ELK flow and I have some issues with Logstash. Sometime my index will be populated sometime not. Furthermore it seems that logstash does not create index on elasticsearch. Can you help on that My .c…

---

## [Read from ES index fails without write permission with HEAD \[405|Method Not Allowed:\]](https://discuss.elastic.co/t/read-from-es-index-fails-without-write-permission-with-head-405-method-not-allowed/328176)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 10\
**Last updated:** [April 3, 2023, 3:03pm UTC](https://discuss.elastic.co/t/read-from-es-index-fails-without-write-permission-with-head-405-method-not-allowed/328176 "2023-04-03T15:03:29Z")

</div>

We're trying to connect to 2 different elastic instances and read data from databricks on indicies where a user has read permissions. For both instances we're seeing the following error EsHadoopInvalidRequest: \[HEAD\] o…

---

## [All AWS WAF event goes to message field even after using correct mapping](https://discuss.elastic.co/t/all-aws-waf-event-goes-to-message-field-even-after-using-correct-mapping/329227)

<div class="topic-metadata">

**Author:** [@SSP1](https://discuss.elastic.co/u/SSP1)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 2:55pm UTC](https://discuss.elastic.co/t/all-aws-waf-event-goes-to-message-field-even-after-using-correct-mapping/329227 "2023-04-03T14:55:22Z")

</div>

HI, I'm using Logstash to ingest AWS WAF Logs from S3 using S3 Input login with SQS and logs are going through to elasticsearch. I can see those in Kibana but all the waf event goes to message filed. I have tried to use …

---

## [Databricks lakehouse delta tables as data source](https://discuss.elastic.co/t/databricks-lakehouse-delta-tables-as-data-source/328591)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 2:44pm UTC](https://discuss.elastic.co/t/databricks-lakehouse-delta-tables-as-data-source/328591 "2023-04-03T14:44:47Z")

</div>

Is it possible to connect to the databricks lakehouse Delta tables to get the data to be indexed into elasticsearch?

---

## [Kibana discover url link click naviagte to custom url](https://discuss.elastic.co/t/kibana-discover-url-link-click-naviagte-to-custom-url/329171)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-discover-url-link-click-naviagte-to-custom-url/329171 "2023-04-03T14:21:46Z")

</div>

Hello All, Above is how my data looks like in old implementation.Now I'm using jdbc plugin in logstash to parse this data and send to elastic index.Now the data in table is simple value. Now I would like to click on …

---

## [Problem with mapping](https://discuss.elastic.co/t/problem-with-mapping/329221)

<div class="topic-metadata">

**Author:** [@matheusgermano](https://discuss.elastic.co/u/matheusgermano)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 1:33pm UTC](https://discuss.elastic.co/t/problem-with-mapping/329221 "2023-04-03T13:33:57Z")

</div>

Hey, folks! How are you? I'm having some troubles with, I believe, mapping. I have a JsonElement field type that is not being saved in my elastic. I'm using C#, working with NEST client. Invalid NEST response built fro…

---

## [Loading BERT Model](https://discuss.elastic.co/t/loading-bert-model/327709)

<div class="topic-metadata">

**Author:** [@Cole\_Crawford](https://discuss.elastic.co/u/Cole_Crawford)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 1:11pm UTC](https://discuss.elastic.co/t/loading-bert-model/327709 "2023-04-03T13:11:18Z")

</div>

I am trying to add ANN semantic search to an Elasticsearch index of scientific documents. To that end, I am trying to set up an NLP pipeline on Elasticsearch to vectorize documents on ingest. I would like to test allenai…

---

## [Find a search Object with part of the name](https://discuss.elastic.co/t/find-a-search-object-with-part-of-the-name/327843)

<div class="topic-metadata">

**Author:** [@KolodzRelyens](https://discuss.elastic.co/u/KolodzRelyens)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 1:07pm UTC](https://discuss.elastic.co/t/find-a-search-object-with-part-of-the-name/327843 "2023-04-03T13:07:05Z")

</div>

Hi, My instance of Elasticsearch start to have a lot of recorded search object, like Batchs\_MyAppA\_MySpecificProcessA Batchs\_MyAppA\_MySpecificProcessB Batchs\_MyAppA\_MySpecificProcessC Batchs\_MyAppB\_MySpecificProcessD B…

---

## [Hybrid Retrieval with approximate KNN](https://discuss.elastic.co/t/hybrid-retrieval-with-approximate-knn/329196)

<div class="topic-metadata">

**Author:** [@jinmingteo](https://discuss.elastic.co/u/jinmingteo)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 12:50pm UTC](https://discuss.elastic.co/t/hybrid-retrieval-with-approximate-knn/329196 "2023-04-03T12:50:49Z")

</div>

Hi, I have read through the following documentation: k-nearest neighbor (kNN) search | Elasticsearch Guide \[master\] | Elastic I have also experimented with a small database and it seems that the results are skewed towa…

---

## [Enrich Processor missing documents](https://discuss.elastic.co/t/enrich-processor-missing-documents/328843)

<div class="topic-metadata">

**Author:** [@FKarraz](https://discuss.elastic.co/u/FKarraz)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 12:24pm UTC](https://discuss.elastic.co/t/enrich-processor-missing-documents/328843 "2023-04-03T12:24:30Z")

</div>

Hi, i have several ingest pipelines that has quite large processor configured in it. Each pipeline for each Data Stream. For example, pipeline "2g\_names" works with "raw\_kpi\_2g\_" (raw\_kpi\_2g\_1) Data Stream, "3g\_names" fo…

---

## [QueryBuilders.nested() in new Java REST Client works not as expected (no "nested" attribute generated), comparing to older (deprecated) HRC](https://discuss.elastic.co/t/querybuilders-nested-in-new-java-rest-client-works-not-as-expected-no-nested-attribute-generated-comparing-to-older-deprecated-hrc/329099)

<div class="topic-metadata">

**Author:** [@Mattteo](https://discuss.elastic.co/u/Mattteo)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 11:31am UTC](https://discuss.elastic.co/t/querybuilders-nested-in-new-java-rest-client-works-not-as-expected-no-nested-attribute-generated-comparing-to-older-deprecated-hrc/329099 "2023-04-03T11:31:51Z")

</div>

The problem: I am trying to upgrade from deprecated HRC (7.13) to new REST Client 8.6 in Java. We use nested queries, but although there is a special NestedQuery.Builder object in the new java client, its not possible t…

---

## [Experience with Large Memory Nodes (1TB, 2TB, and more)](https://discuss.elastic.co/t/experience-with-large-memory-nodes-1tb-2tb-and-more/329124)

<div class="topic-metadata">

**Author:** [@Michael\_Sander](https://discuss.elastic.co/u/Michael_Sander)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 10:53am UTC](https://discuss.elastic.co/t/experience-with-large-memory-nodes-1tb-2tb-and-more/329124 "2023-04-03T10:53:07Z")

</div>

Google Cloud, AWS, and others are now offering nodes with 2TB or more of memory. In the past, the conventional wisdom has been to not provide Elasticsearch with more than 32GB so it uses 32 bit pointers, but I wonder if …

---

## [No Alerts in Winlogbeat](https://discuss.elastic.co/t/no-alerts-in-winlogbeat/328698)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 10:15am UTC](https://discuss.elastic.co/t/no-alerts-in-winlogbeat/328698 "2023-04-03T10:15:06Z")

</div>

Hi there I´m trying to run Winlogbeat. I installed everything but I can´t see any alerts. It seem that it isn´t possible for me to find the problem :frowning: Elasticsearch, Kibana and Winlogbeat are running without …

---

## [Recommended configuration](https://discuss.elastic.co/t/recommended-configuration/329120)

<div class="topic-metadata">

**Author:** [@Noam\_Huri](https://discuss.elastic.co/u/Noam_Huri)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 9:48am UTC](https://discuss.elastic.co/t/recommended-configuration/329120 "2023-04-03T09:48:59Z")

</div>

Hi, could someone please help me and guide me on how to calculate the cost or the recommended configuration that would best suit my needs? unfortunately, I'm not an IT guy :slight\_smile: Our data set consists of approx…

---

## [How to Filter Desired Container Logs in Docker Integration in Fleet？](https://discuss.elastic.co/t/how-to-filter-desired-container-logs-in-docker-integration-in-fleet/329030)

<div class="topic-metadata">

**Author:** [@XYYYYY](https://discuss.elastic.co/u/XYYYYY)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 9:20am UTC](https://discuss.elastic.co/t/how-to-filter-desired-container-logs-in-docker-integration-in-fleet/329030 "2023-04-03T09:20:10Z")

</div>

Hello everyone, I am a newcomer using elastic agent. I have tried to collect container logs using Docker integration, but I have a wide variety of container logs. I only want to obtain a few of them. How can I achieve th…

---

## [Embedding iframe dashboards -auto login](https://discuss.elastic.co/t/embedding-iframe-dashboards-auto-login/329159)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 9:03am UTC](https://discuss.elastic.co/t/embedding-iframe-dashboards-auto-login/329159 "2023-04-03T09:03:05Z")

</div>

I want to embed my iframe dashboard links in another application. But when i embed them , it is asking for login. I cannot add login & password in my iframe link. How can i configure auto login for dashboards when it …

---

## [【Please share info】Plugins and OSS for implementing alert functions in kibana (elasticsearch) version 7 series](https://discuss.elastic.co/t/please-share-info-plugins-and-oss-for-implementing-alert-functions-in-kibana-elasticsearch-version-7-series/329182)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 8:51am UTC](https://discuss.elastic.co/t/please-share-info-plugins-and-oss-for-implementing-alert-functions-in-kibana-elasticsearch-version-7-series/329182 "2023-04-03T08:51:53Z")

</div>

Good evening from japan Dear Elastic Engineers, I am always grateful for your help In Elasticsearch/Kibana version 7 series, I would like to create a mechanism to send an alert email when a specific log is received by…

---

## [Fleet-Server Certificate issue](https://discuss.elastic.co/t/fleet-server-certificate-issue/328635)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 6\
**Last updated:** [April 3, 2023, 8:51am UTC](https://discuss.elastic.co/t/fleet-server-certificate-issue/328635 "2023-04-03T08:51:22Z")

</div>

Hi Community, xpack.security.enabled: true xpack.security.enrollment.enabled: true # Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents xpack.security.http.ssl.enabled: true xpack.se…

---

## [Kibana does not work with https on Docker Swarm cluster](https://discuss.elastic.co/t/kibana-does-not-work-with-https-on-docker-swarm-cluster/329179)

<div class="topic-metadata">

**Author:** [@mrkitt](https://discuss.elastic.co/u/mrkitt)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 8:48am UTC](https://discuss.elastic.co/t/kibana-does-not-work-with-https-on-docker-swarm-cluster/329179 "2023-04-03T08:48:11Z")

</div>

I have a Docker Swarm cluster which consists of one manager and two virtual machines inside as workers. I have successfully deployed Elasticsearch with basic security and https and connected it with Kibana. However, I w…

---

## [Elastic Dissect](https://discuss.elastic.co/t/elastic-dissect/329117)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 8:25am UTC](https://discuss.elastic.co/t/elastic-dissect/329117 "2023-04-03T08:25:13Z")

</div>

Hi everyone :slight\_smile: How to split a single cell with a different number of strings in CVS file into separate cells (fields). Assign the names of the fields from the string itself. If I manually write the names of…

---

## [Query template that will append to existing query for further filtering out results](https://discuss.elastic.co/t/query-template-that-will-append-to-existing-query-for-further-filtering-out-results/329151)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 8:23am UTC](https://discuss.elastic.co/t/query-template-that-will-append-to-existing-query-for-further-filtering-out-results/329151 "2023-04-03T08:23:02Z")

</div>

We have an existing "person" index that has "status" field in it. We have several (around 6) existing queries for retrieving person document with different parameters and logic. However, we have a new requirement that o…

---

## [Removing \\ from raw input log data](https://discuss.elastic.co/t/removing-from-raw-input-log-data/329062)

<div class="topic-metadata">

**Author:** [@Merdesz](https://discuss.elastic.co/u/Merdesz)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 8:17am UTC](https://discuss.elastic.co/t/removing-from-raw-input-log-data/329062 "2023-04-03T08:17:59Z")

</div>

I have a device sending in logs which have "" before every string caracter and I would like to remove them or rewrite them to a simple ". So this " --\> " to this. Logs: srcintfrole="undefined" dstip=255.255.255.255 dst…

---

## [Call External API through Kibana](https://discuss.elastic.co/t/call-external-api-through-kibana/329169)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:24am UTC](https://discuss.elastic.co/t/call-external-api-through-kibana/329169 "2023-04-03T07:24:49Z")

</div>

Can we do something like this in Kibana:- Suppose I am querying an index with a particular document whose value is in some other format(let's say jumbled) and what I need to do is to convert it into some other format(m…

---

## [Elasticsearch Watcher Capabilities](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167)

<div class="topic-metadata">

**Author:** [@umityayla](https://discuss.elastic.co/u/umityayla)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:12am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167 "2023-04-03T07:12:32Z")

</div>

Hello, We plan to implement such a watcher that will regex a field in the documents that are found and pass it to the clients. What I mean is; Let's assume there are 2 documents like below; { "\_type": "\_doc", "\_id…

---

## [About Elastalert errors](https://discuss.elastic.co/t/about-elastalert-errors/329138)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 5:57am UTC](https://discuss.elastic.co/t/about-elastalert-errors/329138 "2023-04-03T05:57:31Z")

</div>

We would like to use elasrticsearch and kibana to achieve the ability to email administrators about unusual events. We're using elastalert2 for this purpose but the filter is in error. We have spent a lot of time on th…

---

## [Logstash and mongodb connection error](https://discuss.elastic.co/t/logstash-and-mongodb-connection-error/329153)

<div class="topic-metadata">

**Author:** [@jskang](https://discuss.elastic.co/u/jskang)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 5:50am UTC](https://discuss.elastic.co/t/logstash-and-mongodb-connection-error/329153 "2023-04-03T05:50:34Z")

</div>

input{ jdbc{ jdbc\_driver\_library =\> "/home/admin/lg-862/lgstash-core/lib/jars/mongojdbc4.8.jar" jdbc\_driver\_class =\> "Java::com.wisecoders.dbschema.mongodb.JdbcDriver" jdbc\_connection\_string =\> "mongodb://XXXXXX:XXXX…

---

## [Kibana bar chart aggr query doc\_count](https://discuss.elastic.co/t/kibana-bar-chart-aggr-query-doc-count/329149)

<div class="topic-metadata">

**Author:** [@math1](https://discuss.elastic.co/u/math1)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 5:44am UTC](https://discuss.elastic.co/t/kibana-bar-chart-aggr-query-doc-count/329149 "2023-04-03T05:44:38Z")

</div>

I want to draw the query statement below as a bar chart in Kibana. GET food\_info/\_search { "size": 0, "aggs": { "country": { "terms": { "field": "food.countryCode" }, "aggs": { …

---

## [Can't match string to format date](https://discuss.elastic.co/t/cant-match-string-to-format-date/329132)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 3:30am UTC](https://discuss.elastic.co/t/cant-match-string-to-format-date/329132 "2023-04-03T03:30:23Z")

</div>

Hi everybody, I have a problem while I try to convert a string variable to timestamp. I'm using date module without successful result. Format date is dd/MM/yyyy hh:mm:ss.SSSSSS and originally the variable newDate is: …

---

## [Synthetics monitors are not working on Elastic Agent (Complete)](https://discuss.elastic.co/t/synthetics-monitors-are-not-working-on-elastic-agent-complete/328978)

<div class="topic-metadata">

**Author:** [@chrispangg](https://discuss.elastic.co/u/chrispangg)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 12:31am UTC](https://discuss.elastic.co/t/synthetics-monitors-are-not-working-on-elastic-agent-complete/328978 "2023-04-03T00:31:15Z")

</div>

The Elastic Agent is running within a container, just like the rest of the stack, in my local environment. Tried this across different versions (on 8.7 now) and they all come back with the same error. Elastic Agent - Do…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=581)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=583)
