# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=587

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 588

---

## [Using ES as a back end DB for an APP with high transactions](https://discuss.elastic.co/t/using-es-as-a-back-end-db-for-an-app-with-high-transactions/328755)

<div class="topic-metadata">

**Author:** [@gstlouis](https://discuss.elastic.co/u/gstlouis)\
**Replies:** 5\
**Last updated:** [March 29, 2023, 8:54pm UTC](https://discuss.elastic.co/t/using-es-as-a-back-end-db-for-an-app-with-high-transactions/328755 "2023-03-29T20:54:25Z")

</div>

I am new to ES. I have been installing it and working with its REST API. I like it and I would like to use it in an APP. However, I have started watching some tutorials to understand the full stack, including beats to…

---

## [How can we browse kibana url on https](https://discuss.elastic.co/t/how-can-we-browse-kibana-url-on-https/328712)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 7\
**Last updated:** [March 29, 2023, 8:29pm UTC](https://discuss.elastic.co/t/how-can-we-browse-kibana-url-on-https/328712 "2023-03-29T20:29:45Z")

</div>

I need to browse kibana url on https I have create certificate using command ./bin/elasticsearch-certutil http I got cert file and kibana key I generated both I copied in kibana config folder server.port: 8600 serv…

---

## [Name IPs (source and destination) in packetbeat flows](https://discuss.elastic.co/t/name-ips-source-and-destination-in-packetbeat-flows/327851)

<div class="topic-metadata">

**Author:** [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 7:14pm UTC](https://discuss.elastic.co/t/name-ips-source-and-destination-in-packetbeat-flows/327851 "2023-03-29T19:14:39Z")

</div>

Hello, I'm using packetbeat to monitor internal networks flows. I'd like to know how I can add a name for each known IP (for example 10.10.10.1 is my DHCP server, I want to add field source.name : 'DHCP Server' and dest…

---

## [Certificates](https://discuss.elastic.co/t/certificates/328856)

<div class="topic-metadata">

**Author:** [@branden.heifner](https://discuss.elastic.co/u/branden.heifner)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 6:47pm UTC](https://discuss.elastic.co/t/certificates/328856 "2023-03-29T18:47:04Z")

</div>

Hello everyone, I need to switch the certificates for my elasticsearch nodes, and I was wondering if there is any specific guide or recommendation for switching them out. Currently the servers are using self signed cert…

---

## [Installing Elastic Agent on Kubernetes doesn't come up as healthy - managed by Elastic Fleet](https://discuss.elastic.co/t/installing-elastic-agent-on-kubernetes-doesnt-come-up-as-healthy-managed-by-elastic-fleet/328729)

<div class="topic-metadata">

**Author:** [@Alexios\_Polyzos](https://discuss.elastic.co/u/Alexios_Polyzos)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 6:10pm UTC](https://discuss.elastic.co/t/installing-elastic-agent-on-kubernetes-doesnt-come-up-as-healthy-managed-by-elastic-fleet/328729 "2023-03-29T18:10:00Z")

</div>

So, I'm trying to install the elastic agent on Kubernetes via the daemonset manifest files found here. I'm providing the FLEET\_URL and FLEET\_ENROLLMENT\_TOKEN, and after the first seconds the agents show up as healthy on…

---

## [Tenable.sc integration with Elastic](https://discuss.elastic.co/t/tenable-sc-integration-with-elastic/328724)

<div class="topic-metadata">

**Author:** [@Wenwei](https://discuss.elastic.co/u/Wenwei)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 5:56pm UTC](https://discuss.elastic.co/t/tenable-sc-integration-with-elastic/328724 "2023-03-29T17:56:11Z")

</div>

Hi guys, I am trying Tenable.sc integration with Elasticsearch. I added the integration, configured the URL to be https://private\_ip\_address\_of\_sc also included access key and secret key. Also installed elastic-agent…

---

## [The number of nested documents has exceeded the allowed limit of \[10000\]](https://discuss.elastic.co/t/the-number-of-nested-documents-has-exceeded-the-allowed-limit-of-10000/328852)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 5:02pm UTC](https://discuss.elastic.co/t/the-number-of-nested-documents-has-exceeded-the-allowed-limit-of-10000/328852 "2023-03-29T17:02:00Z")

</div>

Hello! We are reciving the following error: The number of nested documents has exceeded the allowed limit of \[10000\]. This limit can be set by changing the \[index.mapping.nested\_objects.limit\] index level setting. We …

---

## [Fleet Server Agent not listening](https://discuss.elastic.co/t/fleet-server-agent-not-listening/328388)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 4:17pm UTC](https://discuss.elastic.co/t/fleet-server-agent-not-listening/328388 "2023-03-29T16:17:17Z")

</div>

I'm trying to add a fleet server agent to my stack so I can get rid of the one living on old hardware. I've re-installed the fleet server agent (after running into Adding a Fleet Server integration to an agent that was …

---

## [Kibana Scripted Fields aggregation](https://discuss.elastic.co/t/kibana-scripted-fields-aggregation/328779)

<div class="topic-metadata">

**Author:** [@sam\_sawant](https://discuss.elastic.co/u/sam_sawant)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 4:11pm UTC](https://discuss.elastic.co/t/kibana-scripted-fields-aggregation/328779 "2023-03-29T16:11:33Z")

</div>

I am new to kibana and trying to create dashboard. I have 4 scripted fields which are calculating dollar savings for specific process due to automation. i am trying to get sum of these 4 scripted fields to show total sav…

---

## [Problem with my logstash file '.conf' for analyse syslog from my switchs](https://discuss.elastic.co/t/problem-with-my-logstash-file-conf-for-analyse-syslog-from-my-switchs/328750)

<div class="topic-metadata">

**Author:** [@Son\_Goku](https://discuss.elastic.co/u/Son_Goku)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 3:29pm UTC](https://discuss.elastic.co/t/problem-with-my-logstash-file-conf-for-analyse-syslog-from-my-switchs/328750 "2023-03-29T15:29:43Z")

</div>

Hello, I have install ELK stack 8.6 with elasticsearch, Logstash, Kibana, Filebeat and Metricbeats; Well ! I tested my server with a Logstash file "syslog.conf" with a beats input, who listen on 5044 port. It works, I …

---

## [Data Table multiple fields](https://discuss.elastic.co/t/data-table-multiple-fields/328710)

<div class="topic-metadata">

**Author:** [@shayme](https://discuss.elastic.co/u/shayme)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 3:19pm UTC](https://discuss.elastic.co/t/data-table-multiple-fields/328710 "2023-03-29T15:19:35Z")

</div>

I have data table with multiple fields. I'm trying to show only unique value of one of my fields. I red a lot about this problem and saw "bucket split" answers but I don't have this feature on my elastic 8.6.2 I w…

---

## [415 error when uploading ndjson to kibana](https://discuss.elastic.co/t/415-error-when-uploading-ndjson-to-kibana/328455)

<div class="topic-metadata">

**Author:** [@amesl](https://discuss.elastic.co/u/amesl)\
**Replies:** 10\
**Last updated:** [March 29, 2023, 3:00pm UTC](https://discuss.elastic.co/t/415-error-when-uploading-ndjson-to-kibana/328455 "2023-03-29T15:00:13Z")

</div>

I need to upload an ndjson dashboard file to the kibana endpoint in Java. The below command is successful with the ndjson files: curl -X POST api/saved\_objects/\_import?overwrite=true -H "kbn-xsrf: true" --form file=@fil…

---

## [Delete documents in Elasticsearch from Logstash](https://discuss.elastic.co/t/delete-documents-in-elasticsearch-from-logstash/328679)

<div class="topic-metadata">

**Author:** [@oo\_eyad](https://discuss.elastic.co/u/oo_eyad)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 2:36pm UTC](https://discuss.elastic.co/t/delete-documents-in-elasticsearch-from-logstash/328679 "2023-03-29T14:36:53Z")

</div>

I have an index in Elasticsearch where the UID is automatically generated, I want to delete documents by query but from Logstash. I am trying different ways like http output plugin, is it the correct option to do so? or …

---

## [I got diffirent result with same filter between unique\_count and list-group-terms in kibana](https://discuss.elastic.co/t/i-got-diffirent-result-with-same-filter-between-unique-count-and-list-group-terms-in-kibana/327721)

<div class="topic-metadata">

**Author:** [@hiteny](https://discuss.elastic.co/u/hiteny)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 2:29pm UTC](https://discuss.elastic.co/t/i-got-diffirent-result-with-same-filter-between-unique-count-and-list-group-terms-in-kibana/327721 "2023-03-29T14:29:57Z")

</div>

In the black rectangle of the picture,I have the TERMS result:461, But,the CARDINALITY result is 460! They both have the same filter,I don't know what makes these result.

---

## [Convert String to Date field](https://discuss.elastic.co/t/convert-string-to-date-field/328752)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 2:11pm UTC](https://discuss.elastic.co/t/convert-string-to-date-field/328752 "2023-03-29T14:11:10Z")

</div>

I tried converting one of the string field to Date field , I can see in the logs that it could changed to date field because it's without quotes . but it's still showing the field is keyword. Logstash Config # "Submit …

---

## [Using stop-words in autocomplete search](https://discuss.elastic.co/t/using-stop-words-in-autocomplete-search/328840)

<div class="topic-metadata">

**Author:** [@Kolobok99](https://discuss.elastic.co/u/Kolobok99)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 2:08pm UTC](https://discuss.elastic.co/t/using-stop-words-in-autocomplete-search/328840 "2023-03-29T14:08:17Z")

</div>

Hi all. On our project, we use elastic to search for products through the autocomplete function using something like this query GET food/\_search { "suggest": { "autocomplete": { "prefix": "apple", "com…

---

## [How to forward index from filebeat to elasticsearch via logstash using http output](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587)

<div class="topic-metadata">

**Author:** [@majan3k](https://discuss.elastic.co/u/majan3k)\
**Replies:** 3\
**Last updated:** [March 29, 2023, 1:54pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587 "2023-03-29T13:54:23Z")

</div>

Hello, Hello, I am starting my journey with elasticsearch and I have a couple of questions. I tried to find answers in documentation but some areas are not clear for me and I am confused. If I understood correct, in o…

---

## [Unable to start elastic search on Ubuntu AWS EC2 Instance](https://discuss.elastic.co/t/unable-to-start-elastic-search-on-ubuntu-aws-ec2-instance/328343)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 1:52pm UTC](https://discuss.elastic.co/t/unable-to-start-elastic-search-on-ubuntu-aws-ec2-instance/328343 "2023-03-29T13:52:35Z")

</div>

Hi, so following the link getting the following error. Here's my elasticsearch.yml config # ======================== Elasticsearch Configuration ========================= # # NOTE: Elasticsearch comes with reasonabl…

---

## [Word\_delimiter\_graph with pattern\_replace](https://discuss.elastic.co/t/word-delimiter-graph-with-pattern-replace/328736)

<div class="topic-metadata">

**Author:** [@Wonder\_Garance](https://discuss.elastic.co/u/Wonder_Garance)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 1:46pm UTC](https://discuss.elastic.co/t/word-delimiter-graph-with-pattern-replace/328736 "2023-03-29T13:46:59Z")

</div>

In the settings I use the filter word\_delimiter\_graph and other filters to uniform some reference numbers, and I want to keep the original. For these references: 01/01234 11-2-3.4.5/67/8 I wish to get the output from c…

---

## [Parsing json inside json](https://discuss.elastic.co/t/parsing-json-inside-json/328496)

<div class="topic-metadata">

**Author:** [@eirik](https://discuss.elastic.co/u/eirik)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 1:42pm UTC](https://discuss.elastic.co/t/parsing-json-inside-json/328496 "2023-03-29T13:42:14Z")

</div>

I'm new to logstash and wanted to test using it reading loglines from IBM Cloud and struggling with parsing this log record using logstash. The log line is a json object, and inside this one of the fields starts with pla…

---

## [Watcher weird error : cannot access method/field \[period\] from a null def reference](https://discuss.elastic.co/t/watcher-weird-error-cannot-access-method-field-period-from-a-null-def-reference/328765)

<div class="topic-metadata">

**Author:** [@Paul\_Chen1](https://discuss.elastic.co/u/Paul_Chen1)\
**Replies:** 3\
**Last updated:** [March 29, 2023, 1:23pm UTC](https://discuss.elastic.co/t/watcher-weird-error-cannot-access-method-field-period-from-a-null-def-reference/328765 "2023-03-29T13:23:43Z")

</div>

My watcher is working normally around 3 years until yesterday, suddenly can't fetch the right number of our doc.count. but weird thing is I think the code should be work, like I paste below int past\_4\_hours\_conversi…

---

## [Does there exist a Helm chart for the Elastic agent for on-prem Elasticsearch?](https://discuss.elastic.co/t/does-there-exist-a-helm-chart-for-the-elastic-agent-for-on-prem-elasticsearch/328675)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 1:22pm UTC](https://discuss.elastic.co/t/does-there-exist-a-helm-chart-for-the-elastic-agent-for-on-prem-elasticsearch/328675 "2023-03-29T13:22:29Z")

</div>

Hello Elastic gurus, I guess the question is in the subject. I am trying to find a helm chart for the Elastic agent, but it's not in the below list: I found the k8s ymls for the Elastic agent here: and converted th…

---

## [Elasticsearch throws a SSLHandshakeException: Client requested protocol TLSv1.2 is not enabled or supported in server context](https://discuss.elastic.co/t/elasticsearch-throws-a-sslhandshakeexception-client-requested-protocol-tlsv1-2-is-not-enabled-or-supported-in-server-context/328294)

<div class="topic-metadata">

**Author:** [@wlktiago70](https://discuss.elastic.co/u/wlktiago70)\
**Replies:** 9\
**Last updated:** [March 29, 2023, 1:09pm UTC](https://discuss.elastic.co/t/elasticsearch-throws-a-sslhandshakeexception-client-requested-protocol-tlsv1-2-is-not-enabled-or-supported-in-server-context/328294 "2023-03-29T13:09:51Z")

</div>

Hello there, I am trying to configure Elasticsearch 8.5 to support both TLSv1.3 AND TLSv1.2 communication, but following all documentation available, but it still supports TLSv1.3 only. I did the basic setup following …

---

## [Filestream and sequencing](https://discuss.elastic.co/t/filestream-and-sequencing/328809)

<div class="topic-metadata">

**Author:** [@kakoni](https://discuss.elastic.co/u/kakoni)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 12:47pm UTC](https://discuss.elastic.co/t/filestream-and-sequencing/328809 "2023-03-29T12:47:46Z")

</div>

Hi. Lets say that I've got log directory full of old files; data\_20230301.log data\_20230402.log .. data\_20230329.log and so on. Is it somehow possible to configure filestream input so that these files are read/proc…

---

## [Elasticsearch installation using helm](https://discuss.elastic.co/t/elasticsearch-installation-using-helm/328823)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 12:44pm UTC](https://discuss.elastic.co/t/elasticsearch-installation-using-helm/328823 "2023-03-29T12:44:58Z")

</div>

Hi Team, I have tried to install Elasticsearch using helm k8s package manager by staying inside rancher .. My values.yaml file is antiAffinity: hard antiAffinityTopologyKey: kubernetes.io/hostname clusterHealthCheckP…

---

## [Query Url - Date field not works](https://discuss.elastic.co/t/query-url-date-field-not-works/328816)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 12:12pm UTC](https://discuss.elastic.co/t/query-url-date-field-not-works/328816 "2023-03-29T12:12:03Z")

</div>

Hi guys, I'm trying to create a url query with a date field. Currently in the index I have 2 date fields "@timestamp" and "CALL\_DATE" both correctly recognized as "date". Index mapping: { "cgw\_calls" : { "mappi…

---

## [Probleme dashboard font size in visualization in kibana after migration from 7.10 to 7.17](https://discuss.elastic.co/t/probleme-dashboard-font-size-in-visualization-in-kibana-after-migration-from-7-10-to-7-17/328721)

<div class="topic-metadata">

**Author:** [@elaydi\_elagal](https://discuss.elastic.co/u/elaydi_elagal)\
**Replies:** 9\
**Last updated:** [March 29, 2023, 10:46am UTC](https://discuss.elastic.co/t/probleme-dashboard-font-size-in-visualization-in-kibana-after-migration-from-7-10-to-7-17/328721 "2023-03-29T10:46:23Z")

</div>

How can I change font size of labels in visualization in kibana 7.17 for all dashboard or kept my dashboards format in 7.10 without change in 7.17

---

## [Low level java client not putting messages to elastic search](https://discuss.elastic.co/t/low-level-java-client-not-putting-messages-to-elastic-search/328757)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 8:26am UTC](https://discuss.elastic.co/t/low-level-java-client-not-putting-messages-to-elastic-search/328757 "2023-03-29T08:26:47Z")

</div>

Hi, I am using this version of elastic client. \<dependency\> \<groupId\>org.elasticsearch.client\</groupId\> \<artifactId\>elasticsearch-rest-client\</artifactId\> \<version\>7.17.9\</version\> \<…

---

## [Elastic search fails during restart with unknown setting \[metadata.labels.app\]](https://discuss.elastic.co/t/elastic-search-fails-during-restart-with-unknown-setting-metadata-labels-app/328804)

<div class="topic-metadata">

**Author:** [@sunil\_s](https://discuss.elastic.co/u/sunil_s)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 10:20am UTC](https://discuss.elastic.co/t/elastic-search-fails-during-restart-with-unknown-setting-metadata-labels-app/328804 "2023-03-29T10:20:56Z")

</div>

.plugins.PluginsService","elasticsearch.node.name":"es-cluster-1","elasticsearch.cluster.name":"k8s-logs"} {"@timestamp":"2023-03-29T06:06:49.266Z", "log.level":"ERROR", "message":"fatal exception while booting Elasticse…

---

## [How to change field name in all events in a list of json objects without splitting/with getting again a list of json objects in logstash?](https://discuss.elastic.co/t/how-to-change-field-name-in-all-events-in-a-list-of-json-objects-without-splitting-with-getting-again-a-list-of-json-objects-in-logstash/328807)

<div class="topic-metadata">

**Author:** [@fosota8](https://discuss.elastic.co/u/fosota8)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-to-change-field-name-in-all-events-in-a-list-of-json-objects-without-splitting-with-getting-again-a-list-of-json-objects-in-logstash/328807 "2023-03-29T09:57:00Z")

</div>

For example if i give logstash the following input: \[{"a": 1, "b": 2}, {"a": 14, "b": 65}\] and I want to change all "b" field names to "c", so I will get the following output: \[{"a": 1, "c": 2}, {"a": 14, "c": 65}\] The …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=586)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=588)
