# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=592

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 593

---

## [Monitor multiple directories in monitors.d using heartbeat](https://discuss.elastic.co/t/monitor-multiple-directories-in-monitors-d-using-heartbeat/328053)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [March 25, 2023, 4:10am UTC](https://discuss.elastic.co/t/monitor-multiple-directories-in-monitors-d-using-heartbeat/328053 "2023-03-25T04:10:47Z")

</div>

Hi All, wanted to know do we able to manager directories in monitors.d directories in heartbeat. I wanted to monitor some service and wanted to manage the yml file in directors i.e. each yml files should be under machin…

---

## [Condicional if with Regex](https://discuss.elastic.co/t/condicional-if-with-regex/328417)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 4\
**Last updated:** [March 25, 2023, 1:21am UTC](https://discuss.elastic.co/t/condicional-if-with-regex/328417 "2023-03-25T01:21:46Z")

</div>

Hi everybody, Does anyone know how can I build a "if" condicional that logstash change de number "1" to string "Worked" ? As example, the input are lines like: hello,ola,1hi,1 1,red1,1,green 1 ... and the output…

---

## [Parsing JSON Array In Event](https://discuss.elastic.co/t/parsing-json-array-in-event/328393)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 9\
**Last updated:** [March 24, 2023, 9:54pm UTC](https://discuss.elastic.co/t/parsing-json-array-in-event/328393 "2023-03-24T21:54:24Z")

</div>

I am using the jdbc\_streaming filter to pull additional data for an event from a database, the result looks like below. Any ideas on how I could have this parsed out so that I don't lose any of the data and keep it all …

---

## [How can I change timefield to have browser timezone using script?](https://discuss.elastic.co/t/how-can-i-change-timefield-to-have-browser-timezone-using-script/328502)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 9:45pm UTC](https://discuss.elastic.co/t/how-can-i-change-timefield-to-have-browser-timezone-using-script/328502 "2023-03-24T21:45:48Z")

</div>

Hello, I'm using version 8.6.0 in elastic cloud. I need to separate a timefield according to the day of the week. The way I'm doing it considers the UTC +00.00, but I would like it to be split according to the browser'…

---

## [Index life cycle policy not deleting the index when reached the defined size](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475)

<div class="topic-metadata">

**Author:** [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Replies:** 7\
**Last updated:** [March 24, 2023, 8:56pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475 "2023-03-24T20:56:08Z")

</div>

Hello I have vector agent running on a k8s. it creates a data stream and indexes. I created ILM with only hot and delete phase. It should keep the index in hot phase until it reaches the defined size \[100MB\] and then r…

---

## [Browse and Navigate functionality](https://discuss.elastic.co/t/browse-and-navigate-functionality/328427)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:46pm UTC](https://discuss.elastic.co/t/browse-and-navigate-functionality/328427 "2023-03-24T20:46:16Z")

</div>

Checking if any of the elastisearch features supports browse and navigate functionality.

---

## [Rollup Job when one of the Terms field is array of objects](https://discuss.elastic.co/t/rollup-job-when-one-of-the-terms-field-is-array-of-objects/328451)

<div class="topic-metadata">

**Author:** [@jiri\_whale](https://discuss.elastic.co/u/jiri_whale)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:30pm UTC](https://discuss.elastic.co/t/rollup-job-when-one-of-the-terms-field-is-array-of-objects/328451 "2023-03-24T20:30:56Z")

</div>

I am trying to create a RollUp job from Kibana. In the Terms field where I have given multiple fields, in which one of the fields is of an array type (actually array of objects). How can I define which item/object of the…

---

## [Graph is showing more traffic for one day](https://discuss.elastic.co/t/graph-is-showing-more-traffic-for-one-day/328478)

<div class="topic-metadata">

**Author:** [@ranganathp08](https://discuss.elastic.co/u/ranganathp08)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:19pm UTC](https://discuss.elastic.co/t/graph-is-showing-more-traffic-for-one-day/328478 "2023-03-24T20:19:55Z")

</div>

Hi team, could you help me on below issue; issue: across 3 months , one day Graph is showing unusual spikes with more traffic . but count is showing accurate . previous days and next days looking good (graph and c…

---

## [Plugin generator generates a plugin that causes an error](https://discuss.elastic.co/t/plugin-generator-generates-a-plugin-that-causes-an-error/325492)

<div class="topic-metadata">

**Author:** [@przemek\_ironcode](https://discuss.elastic.co/u/przemek_ironcode)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:01pm UTC](https://discuss.elastic.co/t/plugin-generator-generates-a-plugin-that-causes-an-error/325492 "2023-03-24T20:01:36Z")

</div>

Hi, I am trying to create a plugin for the latest version of Kibana \[8.6\]. I have used the plugin generator for this purpose. Unfortunately, after generating the plug-in and starting the server, I see this error: Elas…

---

## [Change Nil values to set default value](https://discuss.elastic.co/t/change-nil-values-to-set-default-value/328369)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 7:29pm UTC](https://discuss.elastic.co/t/change-nil-values-to-set-default-value/328369 "2023-03-24T19:29:14Z")

</div>

Logstash is dropping fields which has "nil" values, but I don't want those fields to be drop, but at least we can set it to default values if the field is nil, else it has it's original value. I tried with this code fou…

---

## [Elasticsearch combining Filter with Bool by a Must](https://discuss.elastic.co/t/elasticsearch-combining-filter-with-bool-by-a-must/327863)

<div class="topic-metadata">

**Author:** [@MonikaJ](https://discuss.elastic.co/u/MonikaJ)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elasticsearch-combining-filter-with-bool-by-a-must/327863 "2023-03-24T16:45:15Z")

</div>

I am trying to combine a "filter" with a "bool"/"should" inside a "must". The following query is automatically generated by an application (hence the nesting). How must the query look like to have an AND condition betwee…

---

## [Logstash Kafka input - converting date to string format](https://discuss.elastic.co/t/logstash-kafka-input-converting-date-to-string-format/327967)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 6\
**Last updated:** [March 24, 2023, 4:20pm UTC](https://discuss.elastic.co/t/logstash-kafka-input-converting-date-to-string-format/327967 "2023-03-24T16:20:27Z")

</div>

Hello, We are using Kafka plugin to get feed into Logstash. One of the fields that come with the message is in date format. I need to convert that date into string format. Please guide. My config file looks as follo…

---

## [What is the ratio between raw data and ingested data that is stored in Elastic cluster](https://discuss.elastic.co/t/what-is-the-ratio-between-raw-data-and-ingested-data-that-is-stored-in-elastic-cluster/327945)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 4:20pm UTC](https://discuss.elastic.co/t/what-is-the-ratio-between-raw-data-and-ingested-data-that-is-stored-in-elastic-cluster/327945 "2023-03-24T16:20:41Z")

</div>

Hi, I want to know what the ratio is between raw data and ingested data that is stored in Elastic cluster. I know raw logs and ingested logs are not same in size. Also is there any way to find the incoming raw log vol…

---

## [High availability with two servers](https://discuss.elastic.co/t/high-availability-with-two-servers/328467)

<div class="topic-metadata">

**Author:** [@amiraliw](https://discuss.elastic.co/u/amiraliw)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 2:43pm UTC](https://discuss.elastic.co/t/high-availability-with-two-servers/328467 "2023-03-24T14:43:53Z")

</div>

I have only two servers, how I should configure elasticsearch nodes to get high availability and avoid split-brain? should I only have one node on each server?

---

## [How variable width histogram with nested aggregations works](https://discuss.elastic.co/t/how-variable-width-histogram-with-nested-aggregations-works/328219)

<div class="topic-metadata">

**Author:** [@rym](https://discuss.elastic.co/u/rym)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-variable-width-histogram-with-nested-aggregations-works/328219 "2023-03-24T13:24:56Z")

</div>

Hi, I want to use the variable\_width\_histogram combined with other aggregations, such as min or max Here is an example of combinated aggregations on a numeric field: "aggs": { "aggregated-items": { …

---

## [Filebeat and Metricbeat get Error 401 Unauthorized](https://discuss.elastic.co/t/filebeat-and-metricbeat-get-error-401-unauthorized/328200)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 7\
**Last updated:** [March 24, 2023, 1:10pm UTC](https://discuss.elastic.co/t/filebeat-and-metricbeat-get-error-401-unauthorized/328200 "2023-03-24T13:10:20Z")

</div>

I recently upgraded from ELK Stack 7.9.3 to 7.17.9. Everything is working great except that Filebeat and Metricbeat will not connect to Elasticsearch anymore unless they are installed on the same server. I get errors lik…

---

## [Context suggester with search api](https://discuss.elastic.co/t/context-suggester-with-search-api/328245)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 12:13pm UTC](https://discuss.elastic.co/t/context-suggester-with-search-api/328245 "2023-03-24T12:13:09Z")

</div>

I am using Elasticsearch 7.4 and java client api. I want to use context suggester with search api given in this document Suggesters | Elasticsearch Guide \[8.6\] | Elastic can any one give me any sample documents which e…

---

## [Logstash nested json parsing,getting every nested json as seperate field](https://discuss.elastic.co/t/logstash-nested-json-parsing-getting-every-nested-json-as-seperate-field/327956)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 12\
**Last updated:** [March 24, 2023, 11:51am UTC](https://discuss.elastic.co/t/logstash-nested-json-parsing-getting-every-nested-json-as-seperate-field/327956 "2023-03-24T11:51:44Z")

</div>

Hello, After trying several times I'm unable to parse below json string data coming from oracle column called: package\_data.Kindly assist how to get data in elastic to show data like below from given data. {"status":"R…

---

## [Instantiating elasticsearch processors in custom processor](https://discuss.elastic.co/t/instantiating-elasticsearch-processors-in-custom-processor/328199)

<div class="topic-metadata">

**Author:** [@CaptainAmericaFan2](https://discuss.elastic.co/u/CaptainAmericaFan2)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 11:47am UTC](https://discuss.elastic.co/t/instantiating-elasticsearch-processors-in-custom-processor/328199 "2023-03-24T11:47:50Z")

</div>

Hi! I'm hoping to run language inference over a number of fields as documented in this blog: Multilingual search using language identification in Elasticsearch | Elastic Blog Because I want to run it over a number of fi…

---

## [Tenable.io integration - missing FIXED vulnerabilities](https://discuss.elastic.co/t/tenable-io-integration-missing-fixed-vulnerabilities/328351)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 11:39am UTC](https://discuss.elastic.co/t/tenable-io-integration-missing-fixed-vulnerabilities/328351 "2023-03-24T11:39:42Z")

</div>

Hello, I started to test tenable.io integration (great work BTW) and found a little issue. Vulnerabilities with state FIXED are missing in logs-tenable\_io.vulnerability indexes, I can only find OPEN and REOPENED event…

---

## [Tree Vega - Change the path color based on field condition](https://discuss.elastic.co/t/tree-vega-change-the-path-color-based-on-field-condition/328452)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 11:34am UTC](https://discuss.elastic.co/t/tree-vega-change-the-path-color-based-on-field-condition/328452 "2023-03-24T11:34:08Z")

</div>

Is it possible to alter the path colour of Tree Vega chart depending on a data field where the condition is, flag == 1 imply path should be in red else black in colour, I used the following code for the node and it works…

---

## [Kibana vizualization](https://discuss.elastic.co/t/kibana-vizualization/328440)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 10:38am UTC](https://discuss.elastic.co/t/kibana-vizualization/328440 "2023-03-24T10:38:57Z")

</div>

hello i have a problem in kibana vizualization i can't click on source to vizualize data any help please

---

## [Need to create a bar graph for customers who are having sales less than previous month](https://discuss.elastic.co/t/need-to-create-a-bar-graph-for-customers-who-are-having-sales-less-than-previous-month/328329)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 4\
**Last updated:** [March 24, 2023, 10:04am UTC](https://discuss.elastic.co/t/need-to-create-a-bar-graph-for-customers-who-are-having-sales-less-than-previous-month/328329 "2023-03-24T10:04:46Z")

</div>

Hi Team, Need to create a bar graph for customers who are having sales less than previous month. Here we need departments on X-axis. Thanks.

---

## [Elasticsearch Cluster](https://discuss.elastic.co/t/elasticsearch-cluster/328443)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 10:03am UTC](https://discuss.elastic.co/t/elasticsearch-cluster/328443 "2023-03-24T10:03:07Z")

</div>

Could someone help me to have a cluster with a main machine that has elasticsearch and kibana and other 9 machines with only elasticsearch that are slaves.

---

## [Backfill of data stream](https://discuss.elastic.co/t/backfill-of-data-stream/328446)

<div class="topic-metadata">

**Author:** [@obi134](https://discuss.elastic.co/u/obi134)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 9:57am UTC](https://discuss.elastic.co/t/backfill-of-data-stream/328446 "2023-03-24T09:57:34Z")

</div>

Hi there, Currently we are using "normal" indexes instead of data streams in our application. But in the last days I was faced to ILM and it could be easier to implement with data streams. So I had a look if data stream…

---

## [How to add input fields to Eui Data Grid](https://discuss.elastic.co/t/how-to-add-input-fields-to-eui-data-grid/326567)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 5\
**Last updated:** [March 24, 2023, 8:39am UTC](https://discuss.elastic.co/t/how-to-add-input-fields-to-eui-data-grid/326567 "2023-03-24T08:39:39Z")

</div>

Hi, I want to add input fields to my data grid. Meaning in total I'll have 10 columns After 3 columns data, I need 2 columns as input fields, and the values in the rest of the columns will depend on the values in the …

---

## [Improve elasticsearch aggreation performance](https://discuss.elastic.co/t/improve-elasticsearch-aggreation-performance/328434)

<div class="topic-metadata">

**Author:** [@MonikaJ](https://discuss.elastic.co/u/MonikaJ)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 8:14am UTC](https://discuss.elastic.co/t/improve-elasticsearch-aggreation-performance/328434 "2023-03-24T08:14:42Z")

</div>

I am using elasticsearch aggregations to calculate counts for a faceted search. Therefore I define my general search query (e.g. status.keyword) and exlcude this filter from the status.keyword aggregation itself (the que…

---

## [Fatal error: concurrent map iteration and map write](https://discuss.elastic.co/t/fatal-error-concurrent-map-iteration-and-map-write/328350)

<div class="topic-metadata">

**Author:** [@Z4ck404](https://discuss.elastic.co/u/Z4ck404)\
**Replies:** 5\
**Last updated:** [March 24, 2023, 8:08am UTC](https://discuss.elastic.co/t/fatal-error-concurrent-map-iteration-and-map-write/328350 "2023-03-24T08:08:24Z")

</div>

I am using filebeat with google storage input and elasticsearch as output .. the filebeat starts and throws this error after few seconds : {"log.level":"warn","@timestamp":"2023-03-23T13:46:05.824Z","log.logger":"input…

---

## [.security-6 Reindex (update assistant)](https://discuss.elastic.co/t/security-6-reindex-update-assistant/328422)

<div class="topic-metadata">

**Author:** [@Moe\_Hmaidan](https://discuss.elastic.co/u/Moe_Hmaidan)\
**Replies:** 5\
**Last updated:** [March 24, 2023, 7:33am UTC](https://discuss.elastic.co/t/security-6-reindex-update-assistant/328422 "2023-03-24T07:33:48Z")

</div>

Hello, We have a cluster running elasticsearch 7.17.7, we recently decided to work on upgrading the cluster to 8.x and everything was going well, I was working on creating a snapshot when I noticed that the system indic…

---

## [License Banned Nexus IQ Vulnerability in 7.16.2](https://discuss.elastic.co/t/license-banned-nexus-iq-vulnerability-in-7-16-2/328419)

<div class="topic-metadata">

**Author:** [@PAVK\_PRASAD](https://discuss.elastic.co/u/PAVK_PRASAD)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 6:31am UTC](https://discuss.elastic.co/t/license-banned-nexus-iq-vulnerability-in-7-16-2/328419 "2023-03-24T06:31:39Z")

</div>

Hi Team, We are using 7.16.2 Version of ES and we Observed "License Banned" Nexus IQ Scan issue in 7.16.2 with Elastic Search where as ES 7.10.0 doesn't have this issue. If We want go back to 7.10.0, In that version we…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=591)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=593)
