# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=583

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 584

---

## [Help with using Grok to parse these three log formats](https://discuss.elastic.co/t/help-with-using-grok-to-parse-these-three-log-formats/329107)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 8\
**Last updated:** [April 2, 2023, 10:37pm UTC](https://discuss.elastic.co/t/help-with-using-grok-to-parse-these-three-log-formats/329107 "2023-04-02T22:37:55Z")

</div>

Hi I am experienced with Dissect but not Grok. I think I need to use Grok here because the log format varies between the logs, so dissect will only work on one format, not all three: Case 1: 2023-03-31 00:01:24,366 INF…

---

## [Users and Groups export](https://discuss.elastic.co/t/users-and-groups-export/329133)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 0\
**Last updated:** [April 2, 2023, 6:47pm UTC](https://discuss.elastic.co/t/users-and-groups-export/329133 "2023-04-02T18:47:26Z")

</div>

Is it possible to export and import users and groups from Kibana, so that these can be managed in multiple life cycle environments? or the user and role related apis needs to be used?

---

## [Enhanced data table slow response in comparison to kibana discover search?](https://discuss.elastic.co/t/enhanced-data-table-slow-response-in-comparison-to-kibana-discover-search/329047)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [April 2, 2023, 4:49pm UTC](https://discuss.elastic.co/t/enhanced-data-table-slow-response-in-comparison-to-kibana-discover-search/329047 "2023-04-02T16:49:55Z")

</div>

Hello @fbaligand , Can you please let me understand why enhanced table/document table provides data slow or sometime hangs when filtered for huge data. Example 1 month data fetch,document count 20 million(here the data…

---

## [Getting Peak day and corresponding count based on last 30 days data](https://discuss.elastic.co/t/getting-peak-day-and-corresponding-count-based-on-last-30-days-data/329126)

<div class="topic-metadata">

**Author:** [@Yadhav](https://discuss.elastic.co/u/Yadhav)\
**Replies:** 0\
**Last updated:** [April 2, 2023, 3:05pm UTC](https://discuss.elastic.co/t/getting-peak-day-and-corresponding-count-based-on-last-30-days-data/329126 "2023-04-02T15:05:49Z")

</div>

Hi, I have requirement to get max of count value along with its date in last 7 days time frame. Below is my kibana visualization setting. Here I need to get max of count value along with its date. Seeing forward to…

---

## [Upstream prematurely closed connection while connecting to Kibana](https://discuss.elastic.co/t/upstream-prematurely-closed-connection-while-connecting-to-kibana/329056)

<div class="topic-metadata">

**Author:** [@Ravi\_Prakash1](https://discuss.elastic.co/u/Ravi_Prakash1)\
**Replies:** 1\
**Last updated:** [April 2, 2023, 2:26pm UTC](https://discuss.elastic.co/t/upstream-prematurely-closed-connection-while-connecting-to-kibana/329056 "2023-04-02T14:26:03Z")

</div>

Hello , Need some help with issue which we are facing while connecting to Kibana via Nginx using proxy\_pass. We are using ECK operator on Openshift ( Elasticsearch (ECK) Operator 2.6.2 provided by Elastic ) . While d…

---

## [Timestamp search between two fields](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 4\
**Last updated:** [April 2, 2023, 11:32am UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048 "2023-04-02T11:32:53Z")

</div>

In my use case, I created two fields for the values of start\_time and end\_time based on some indicators in the log lines with kibana discover , I want to search for all the log lines that their timestamp is between thes…

---

## [Watchers are not working after elasticsearch migration 7.16.1 to 8.5.1](https://discuss.elastic.co/t/watchers-are-not-working-after-elasticsearch-migration-7-16-1-to-8-5-1/328733)

<div class="topic-metadata">

**Author:** [@mkaymak](https://discuss.elastic.co/u/mkaymak)\
**Replies:** 1\
**Last updated:** [April 2, 2023, 2:57am UTC](https://discuss.elastic.co/t/watchers-are-not-working-after-elasticsearch-migration-7-16-1-to-8-5-1/328733 "2023-04-02T02:57:59Z")

</div>

After migrating Elasticsearch version 7.16.1 to 8.5.1 The watchers which basically find the error logs and send them to our messaging channel started to not working. When I simulate my watcher the error message is: "…

---

## [How to add my network logs of my applications to elastic/observability](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704)

<div class="topic-metadata">

**Author:** [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Replies:** 12\
**Last updated:** [April 2, 2023, 2:12am UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704 "2023-04-02T02:12:34Z")

</div>

I would like to access my logs and create a dashboard in Elasticsearch/observability. Please let me know how to integrate the application logs from the network. I would like to know the steps.

---

## [Elastic Filter](https://discuss.elastic.co/t/elastic-filter/329104)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 8\
**Last updated:** [April 1, 2023, 4:57pm UTC](https://discuss.elastic.co/t/elastic-filter/329104 "2023-04-01T16:57:52Z")

</div>

I import a csv file via logstash "filter cvs" into Elasticsearch. One of the cells in a table (CVS file) contains several strings example: (categoty, subcategory, sub\_subcategory). I would like to split these strings int…

---

## [Today Avg value vs Moving AVG (14 days) value to trigger an alert based on DSL query](https://discuss.elastic.co/t/today-avg-value-vs-moving-avg-14-days-value-to-trigger-an-alert-based-on-dsl-query/328527)

<div class="topic-metadata">

**Author:** [@cpu](https://discuss.elastic.co/u/cpu)\
**Replies:** 9\
**Last updated:** [April 1, 2023, 9:38am UTC](https://discuss.elastic.co/t/today-avg-value-vs-moving-avg-14-days-value-to-trigger-an-alert-based-on-dsl-query/328527 "2023-04-01T09:38:23Z")

</div>

Hi All, I'm trying to setup an alert (in Stack Management --\> Rules and Connectors -- Rules) to track when the "today" AVG value on a field is lower than the moving AVG (14 days) value for the same field. This check sh…

---

## [Master not discovered yet, this node has not previously joined a bootstrapped](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped/329093)

<div class="topic-metadata">

**Author:** [@williamsun](https://discuss.elastic.co/u/williamsun)\
**Replies:** 1\
**Last updated:** [April 1, 2023, 6:20am UTC](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped/329093 "2023-04-01T06:20:37Z")

</div>

My issue is related to the last post. Master not discovered yet, this node has not previously joined a bootstrapped ====== I installed Elasticsearch 8.7.0 on AWS EKS 1.23 with three master Pods, three Data Pods and tw…

---

## [How can I join or paste array elements as of a one element?](https://discuss.elastic.co/t/how-can-i-join-or-paste-array-elements-as-of-a-one-element/329089)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 2\
**Last updated:** [April 1, 2023, 3:08am UTC](https://discuss.elastic.co/t/how-can-i-join-or-paste-array-elements-as-of-a-one-element/329089 "2023-04-01T03:08:19Z")

</div>

Hi everybody, First of all, thanks for your time. I have a question regarding to Logstash. I would like to join some array elements as of a specific element. The log that I am processing, the first six fields have the …

---

## [Data stream rollover & writing documents at pre-rollover date](https://discuss.elastic.co/t/data-stream-rollover-writing-documents-at-pre-rollover-date/329086)

<div class="topic-metadata">

**Author:** [@nouknouk](https://discuss.elastic.co/u/nouknouk)\
**Replies:** 2\
**Last updated:** [April 1, 2023, 12:14am UTC](https://discuss.elastic.co/t/data-stream-rollover-writing-documents-at-pre-rollover-date/329086 "2023-04-01T00:14:58Z")

</div>

Hi, I brand new to the concept of data streams, and I'm trying to understand the concepts & limits behind them. So sorry in advance if my question is a dumb one. Let's say: I configure a data stream "foo" with rollo…

---

## [How to link to entries triggering a rule](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334)

<div class="topic-metadata">

**Author:** [@blindahl](https://discuss.elastic.co/u/blindahl)\
**Replies:** 6\
**Last updated:** [March 31, 2023, 9:19pm UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334 "2023-03-31T21:19:26Z")

</div>

We have setup some Rules and Alerts that should trigger if we get error in our logs. In the mail that is sent when a rule is triggered it feels natural to include a link to Discover view with some filters setup and with …

---

## [Filebeat MSSQL Module - Log Unreadable](https://discuss.elastic.co/t/filebeat-mssql-module-log-unreadable/329066)

<div class="topic-metadata">

**Author:** [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 9:13pm UTC](https://discuss.elastic.co/t/filebeat-mssql-module-log-unreadable/329066 "2023-03-31T21:13:36Z")

</div>

I installed filebeat 8.7 on my SQL Server and enabled the MSSQL module. Filebeat is normally collecting the logs from the folders I configured, but the original log message is unreadable: 72.\\u0000\\u0000\\u0000\\u0000��…

---

## [Keytool error: java.io.IOException: Invalid keystore format](https://discuss.elastic.co/t/keytool-error-java-io-ioexception-invalid-keystore-format/328939)

<div class="topic-metadata">

**Author:** [@dr01](https://discuss.elastic.co/u/dr01)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 8:40pm UTC](https://discuss.elastic.co/t/keytool-error-java-io-ioexception-invalid-keystore-format/328939 "2023-03-31T20:40:24Z")

</div>

I have Elasticsearch 7.17. Following the generation of new SSL certificates, I have created a new keystore via the command /usr/share/elasticsearch/bin/elasticsearch-keystore create and I'm trying to add the CA cert…

---

## [Update Existing document through logstash](https://discuss.elastic.co/t/update-existing-document-through-logstash/329077)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 8:40pm UTC](https://discuss.elastic.co/t/update-existing-document-through-logstash/329077 "2023-03-31T20:40:21Z")

</div>

logstash pipeline is not updating existing document for the same id, I have couples of fields which got updated frequestly for example Last Modified Date. I have below logstash config. output { elasticsearch { …

---

## [Data stream timestamp in the name of index](https://discuss.elastic.co/t/data-stream-timestamp-in-the-name-of-index/329080)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 8:25pm UTC](https://discuss.elastic.co/t/data-stream-timestamp-in-the-name-of-index/329080 "2023-03-31T20:25:48Z")

</div>

Hi Is it possible to achieve name with timestamp from ingest data to elasticsearch in the index name like .ds-\<data-stream\>-\<yyyy.MM.dd\>-\<generation\> .ds-\<data-stream\>\<mytimestamp\_from\_log\>-\<generation\> I've tried to…

---

## [Kibana not give logs](https://discuss.elastic.co/t/kibana-not-give-logs/328695)

<div class="topic-metadata">

**Author:** [@Prabhath\_samarasingh](https://discuss.elastic.co/u/Prabhath_samarasingh)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 8:13pm UTC](https://discuss.elastic.co/t/kibana-not-give-logs/328695 "2023-03-31T20:13:11Z")

</div>

Configured basic ELK set up.But my kibana interface had no logs. This is the guide I followed. What is the mistake I have done. Installing and Configuring Elasticsearch curl -fsSL https://artifacts.elastic.co/GPG-KEY…

---

## [Reading date format in logstash date filter](https://discuss.elastic.co/t/reading-date-format-in-logstash-date-filter/329070)

<div class="topic-metadata">

**Author:** [@UsmanNiazi](https://discuss.elastic.co/u/UsmanNiazi)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 7:45pm UTC](https://discuss.elastic.co/t/reading-date-format-in-logstash-date-filter/329070 "2023-03-31T19:45:21Z")

</div>

Hi, I am unable to convert this string "03/31/2023 03:15 AM PDT" to date when using logstash date filter. Getting error dateparse failure. I am using below script date { match =\> \[ "start\_time", "mm/dd/yyyy HH:mm Z",…

---

## [Elasticsearch Malformed Query, Expected \[END\_OBJECT\] but found \[Field\_Name\]](https://discuss.elastic.co/t/elasticsearch-malformed-query-expected-end-object-but-found-field-name/329072)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 7:33pm UTC](https://discuss.elastic.co/t/elasticsearch-malformed-query-expected-end-object-but-found-field-name/329072 "2023-03-31T19:33:54Z")

</div>

Hello, I am trying to run reindex with query but getting the error Malformed Query, Expected \[END\_OBJECT\] but found \[Field\_Name\]. { "source": { "index": "index-\*", "\_source" : \[ "@timestamp", "message"\], …

---

## [S3 API Costs are extraordinary expensive for snapshots](https://discuss.elastic.co/t/s3-api-costs-are-extraordinary-expensive-for-snapshots/329071)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 7:04pm UTC](https://discuss.elastic.co/t/s3-api-costs-are-extraordinary-expensive-for-snapshots/329071 "2023-03-31T19:04:45Z")

</div>

To store 5TB of data, we are paying about $1,200 in storage fees per month and $10,000 in API calls Is there a way to fix this? During a snapshot we are seeing upwards of 120k s3 api calls/minute SLM: PUT \_slm/policy/…

---

## [Elastic Search Api with Python](https://discuss.elastic.co/t/elastic-search-api-with-python/329009)

<div class="topic-metadata">

**Author:** [@Sharath\_B.S](https://discuss.elastic.co/u/Sharath_B.S)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 6:45pm UTC](https://discuss.elastic.co/t/elastic-search-api-with-python/329009 "2023-03-31T18:45:31Z")

</div>

Im trying to sort the search results according to the date in ascending order. it would be helpful if i could get to know how to sort the results according to the date.

---

## [Elasticsearch 8.4.3 - security rules dashboard cannot be accessed - Privileges required](https://discuss.elastic.co/t/elasticsearch-8-4-3-security-rules-dashboard-cannot-be-accessed-privileges-required/329074)

<div class="topic-metadata">

**Author:** [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 6:21pm UTC](https://discuss.elastic.co/t/elasticsearch-8-4-3-security-rules-dashboard-cannot-be-accessed-privileges-required/329074 "2023-03-31T18:21:41Z")

</div>

Hi there, I created a rule in elastic and followed this document for allowing access for a user to all security features including alerts. The role has all indices access including metioned in the above document: …

---

## [In elasticsearch finding documents which meet a specific criteria for the latest for each group](https://discuss.elastic.co/t/in-elasticsearch-finding-documents-which-meet-a-specific-criteria-for-the-latest-for-each-group/329023)

<div class="topic-metadata">

**Author:** [@m.a.tanaka](https://discuss.elastic.co/u/m.a.tanaka)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 5:17pm UTC](https://discuss.elastic.co/t/in-elasticsearch-finding-documents-which-meet-a-specific-criteria-for-the-latest-for-each-group/329023 "2023-03-31T17:17:38Z")

</div>

I am trying to create a query in elasticsearch, which is able to retrieve the documents for each group, which is the latest document within each group and meet a specific criteria. But I have not been able to solve this …

---

## [Elasticsearch backup - S3 repository](https://discuss.elastic.co/t/elasticsearch-backup-s3-repository/328773)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 4:09pm UTC](https://discuss.elastic.co/t/elasticsearch-backup-s3-repository/328773 "2023-03-31T16:09:14Z")

</div>

Hi All, We're backing up the Elasticsearch cluster indices to a S3 bucket (S3 repository by snapshot API), daily backup is around 1TB, and deleting the snapshots older than 30 days. Total size of S3 bucket is more than …

---

## [Java API client : How to reset index settings value](https://discuss.elastic.co/t/java-api-client-how-to-reset-index-settings-value/329059)

<div class="topic-metadata">

**Author:** [@MathieuLacour](https://discuss.elastic.co/u/MathieuLacour)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 3:02pm UTC](https://discuss.elastic.co/t/java-api-client-how-to-reset-index-settings-value/329059 "2023-03-31T15:02:40Z")

</div>

For performance reasons, I need to temporarily disable refresh\_interval at index settings level while bulk loading takes place in the index, and enable it back afterwards. The refresh\_interval value is held by global cl…

---

## [How to apply a filter to a control visualization](https://discuss.elastic.co/t/how-to-apply-a-filter-to-a-control-visualization/328968)

<div class="topic-metadata">

**Author:** [@richfish](https://discuss.elastic.co/u/richfish)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 2:52pm UTC](https://discuss.elastic.co/t/how-to-apply-a-filter-to-a-control-visualization/328968 "2023-03-31T14:52:45Z")

</div>

In Kibana 7.10.1, I have a dashboard with multiple visualizations, each with its own filter based on the same property on the same index. I added a dropdown control that will allow the user to filter by one of those valu…

---

## [Python code in Kibana](https://discuss.elastic.co/t/python-code-in-kibana/329044)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 2:01pm UTC](https://discuss.elastic.co/t/python-code-in-kibana/329044 "2023-03-31T14:01:54Z")

</div>

Can we run python functions in Kibana in order to perform some transformation on the index data?

---

## [Python UDF in Kibana](https://discuss.elastic.co/t/python-udf-in-kibana/328933)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 1:27pm UTC](https://discuss.elastic.co/t/python-udf-in-kibana/328933 "2023-03-31T13:27:26Z")

</div>

Can we build python UDF or any other language's UDF to transform data queried from Kibana dev-tools console?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=582)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=584)
