# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=595

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 596

---

## [Bug in Cisco FTD Integration's Ingest Pipeline for Message ID's 302013, 302015](https://discuss.elastic.co/t/bug-in-cisco-ftd-integrations-ingest-pipeline-for-message-ids-302013-302015/328292)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 9:42pm UTC](https://discuss.elastic.co/t/bug-in-cisco-ftd-integrations-ingest-pipeline-for-message-ids-302013-302015/328292 "2023-03-22T21:42:06Z")

</div>

We have been getting quite a lot of "Network Traffic to Rare Destination Country" alerts based on the associated ML job, and after looking into each of these detections, the vast majority of them are false-positives for …

---

## [Ingesting Data from an API](https://discuss.elastic.co/t/ingesting-data-from-an-api/328186)

<div class="topic-metadata">

**Author:** [@mrodski](https://discuss.elastic.co/u/mrodski)\
**Replies:** 3\
**Last updated:** [March 22, 2023, 9:32pm UTC](https://discuss.elastic.co/t/ingesting-data-from-an-api/328186 "2023-03-22T21:32:09Z")

</div>

So I am pretty new to Elastic and have it installed on my servers. I do not have Elastic Cloud Services at this point in time. How do you take an API call from one server and have it ingested into Elastic so that I can v…

---

## [Remove Specific Field matching pattern](https://discuss.elastic.co/t/remove-specific-field-matching-pattern/328260)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 8:55pm UTC](https://discuss.elastic.co/t/remove-specific-field-matching-pattern/328260 "2023-03-22T20:55:44Z")

</div>

Hello I am trying to remove specific fields in logstash before it goes to elasticssearch, I tried below config. with drop option. if "\[response\]\[body\]\[entries\]\[values\]" == '^n1D.\*' { drop { } } I have a…

---

## [It is not possible to install Multi-tenancy in kibana](https://discuss.elastic.co/t/it-is-not-possible-to-install-multi-tenancy-in-kibana/328274)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 8:50pm UTC](https://discuss.elastic.co/t/it-is-not-possible-to-install-multi-tenancy-in-kibana/328274 "2023-03-22T20:50:21Z")

</div>

There is no possibility or plugin for the latest version to install Multi-tenancy.

---

## [Speed question between v5 and 7 and 8](https://discuss.elastic.co/t/speed-question-between-v5-and-7-and-8/328291)

<div class="topic-metadata">

**Author:** [@Ahmed\_Alsamarrai](https://discuss.elastic.co/u/Ahmed_Alsamarrai)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:56pm UTC](https://discuss.elastic.co/t/speed-question-between-v5-and-7-and-8/328291 "2023-03-22T19:56:37Z")

</div>

Hi, We are facing a situation which we would like to resolve. We have a server running Elastic version 5.6 (on Docker). We wanted to upgrade and tried 7.17, on the same network, on a machine which is identical and also…

---

## [Unable to PUT \_index\_template which was captured from GET \_index\_template](https://discuss.elastic.co/t/unable-to-put-index-template-which-was-captured-from-get-index-template/328221)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 7:14pm UTC](https://discuss.elastic.co/t/unable-to-put-index-template-which-was-captured-from-get-index-template/328221 "2023-03-22T19:14:32Z")

</div>

I am getting an index template as follows: curl -X GET http://localhost:9200/\_index\_template/filebeat\* \> /var/tmp/filebeat-template.json Now I want to PUT the same template into another elastic instance: curl http://…

---

## [Snapshots and malicious deletion of backups](https://discuss.elastic.co/t/snapshots-and-malicious-deletion-of-backups/328191)

<div class="topic-metadata">

**Author:** [@jgimenez](https://discuss.elastic.co/u/jgimenez)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 7:07pm UTC](https://discuss.elastic.co/t/snapshots-and-malicious-deletion-of-backups/328191 "2023-03-22T19:07:10Z")

</div>

Hi there, I'm evaluating the options to protect against malicious deletion of backups. The recommendation is usually to keep some of the backups in offline storage and give the backup process the minimum permission poss…

---

## [{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/326340)

<div class="topic-metadata">

**Author:** [@nvelumani](https://discuss.elastic.co/u/nvelumani)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 6:43pm UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/326340 "2023-03-22T18:43:59Z")

</div>

Hello Team, I have installed elastic version 8.5.2 on three node cluster, it runs good. when I take down down node 2 (master -2), cluster is up and running with other two nodes. when I take down down node 3 (master -3…

---

## [Error when starting Elasticsearch single node](https://discuss.elastic.co/t/error-when-starting-elasticsearch-single-node/328207)

<div class="topic-metadata">

**Author:** [@abctha1234](https://discuss.elastic.co/u/abctha1234)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 5:17pm UTC](https://discuss.elastic.co/t/error-when-starting-elasticsearch-single-node/328207 "2023-03-22T17:17:20Z")

</div>

My docker-compose.yaml elasticsearch: container\_name: elasticsearch image: docker.elastic.co/elasticsearch/elasticsearch:8.6.2 volumes: - elasticsearch\_data:/usr/share/elasticsearch/data - cert…

---

## [Elasticsearch endpoint giving http 504 error](https://discuss.elastic.co/t/elasticsearch-endpoint-giving-http-504-error/328276)

<div class="topic-metadata">

**Author:** [@Raman\_Sawhney](https://discuss.elastic.co/u/Raman_Sawhney)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:58pm UTC](https://discuss.elastic.co/t/elasticsearch-endpoint-giving-http-504-error/328276 "2023-03-22T16:58:16Z")

</div>

Hello Team, I am trying to install Elasticsearch on Kubernetes (1.24) version using the Elasticsearch(8.5.1) helm charts. I was able to install the charts and pods are in running status but when i tried to access the e…

---

## [Convert unix timestamp to epoch\_second and assign to @timestamp](https://discuss.elastic.co/t/convert-unix-timestamp-to-epoch-second-and-assign-to-timestamp/328133)

<div class="topic-metadata">

**Author:** [@nika](https://discuss.elastic.co/u/nika)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:54pm UTC](https://discuss.elastic.co/t/convert-unix-timestamp-to-epoch-second-and-assign-to-timestamp/328133 "2023-03-22T16:54:11Z")

</div>

I'm sorry if this is covered elsewhere, but I have been having trouble getting this to work. I have a field in a log being sent to elasticsearch from filebeat. The log is ndjson formatted. The field is called time and…

---

## [DSL query in Kibana Rules does not work the same as from Dev Tools](https://discuss.elastic.co/t/dsl-query-in-kibana-rules-does-not-work-the-same-as-from-dev-tools/327577)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 9\
**Last updated:** [March 22, 2023, 4:30pm UTC](https://discuss.elastic.co/t/dsl-query-in-kibana-rules-does-not-work-the-same-as-from-dev-tools/327577 "2023-03-22T16:30:12Z")

</div>

Hello, I'm using Elastic 7.17.6 and I have an alert rule set up which is using the below DSL query to search for the data: { "size": 0, "query": { "bool": { "must": \[ { "match": { "empty": "true" …

---

## [ES persistent outages](https://discuss.elastic.co/t/es-persistent-outages/327395)

<div class="topic-metadata">

**Author:** [@orthecreedence](https://discuss.elastic.co/u/orthecreedence)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 4:22pm UTC](https://discuss.elastic.co/t/es-persistent-outages/327395 "2023-03-22T16:22:35Z")

</div>

Hello. We recently upgraded to ES 7.17.9 (8.x is on the radar, but we have a lot of reindexing to do before then) and are having a lot of problems. We're using a fairly stock configuration on EC2. Our setup consists of …

---

## [Internal\_networks setting for netflow integration](https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586)

<div class="topic-metadata">

**Author:** [@Andres\_Altamirano](https://discuss.elastic.co/u/Andres_Altamirano)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 9:09am UTC](https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586 "2023-03-22T09:09:36Z")

</div>

Hi, I'm trying to replace filebeat netflow module with elastic integration "netflow" that is deployed on a policy running on a few servers. Flows are indexed properly, but there is no way to set the internal\_networks p…

---

## [Cisco AnyConnect VPN Integration](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942)

<div class="topic-metadata">

**Author:** [@MDimsey](https://discuss.elastic.co/u/MDimsey)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 4:03pm UTC](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942 "2023-03-22T16:03:33Z")

</div>

Hello, My organization is looking to use the Elastic Agent as a replacement for running dedicated winlogbeat.exe agents on hosts. However, through winlogbeat we were able to collect logs from Cisco AnyConnect Security M…

---

## [Why I get after Client.Indices.Create() a second and unassigned index?](https://discuss.elastic.co/t/why-i-get-after-client-indices-create-a-second-and-unassigned-index/328264)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 3:34pm UTC](https://discuss.elastic.co/t/why-i-get-after-client-indices-create-a-second-and-unassigned-index/328264 "2023-03-22T15:34:12Z")

</div>

I create a index on Elasticsearch with the C# code below. But instead of creating one assigned index I find a second unassigned index with the same name. I don't want and need this second (unassigned) index. My elasticse…

---

## [TSVB "Your query attempted to fetch too much data." when interval is changed](https://discuss.elastic.co/t/tsvb-your-query-attempted-to-fetch-too-much-data-when-interval-is-changed/328195)

<div class="topic-metadata">

**Author:** [@Joshua\_Boyd](https://discuss.elastic.co/u/Joshua_Boyd)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 3:40pm UTC](https://discuss.elastic.co/t/tsvb-your-query-attempted-to-fetch-too-much-data-when-interval-is-changed/328195 "2023-03-22T15:40:09Z")

</div>

Fails with 1m interval For 30day interval or greater it works fine, but i I want to group by month I set the advance setting from 2000 to 10000 based on another thread, but no luck Any ideas?

---

## [Counter rate from log entries](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 6\
**Last updated:** [March 22, 2023, 3:31pm UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148 "2023-03-22T15:31:24Z")

</div>

Hi, I'm trying to cheaply get some numeric data out of our logs. There an event that we log every time it happens and I'd like to see the rate at which it happens. I've added a lens with a filter for that log message an…

---

## [Datastream with upsert](https://discuss.elastic.co/t/datastream-with-upsert/328266)

<div class="topic-metadata">

**Author:** [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 3:28pm UTC](https://discuss.elastic.co/t/datastream-with-upsert/328266 "2023-03-22T15:28:45Z")

</div>

Hello, We are pulling data from MS SQL database into Elastic via Logstash which is working fine however some records get updated and so we want to update the existing entries in Elastic accordingly. The data is stored …

---

## [Data compression and retention](https://discuss.elastic.co/t/data-compression-and-retention/328252)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 3\
**Last updated:** [March 22, 2023, 2:40pm UTC](https://discuss.elastic.co/t/data-compression-and-retention/328252 "2023-03-22T14:40:24Z")

</div>

Hi, I have a task in which i need to store data in elastic cluster. Altogether i have 12TB of disk space available. These are the requirments: 90 days of data retention One replica shard per one primary shard 100GB of…

---

## [Elastic-agent with Misp integration policy no data received while no errors comes up](https://discuss.elastic.co/t/elastic-agent-with-misp-integration-policy-no-data-received-while-no-errors-comes-up/328183)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pellletier](https://discuss.elastic.co/u/Nicolas_Pellletier)\
**Replies:** 8\
**Last updated:** [March 22, 2023, 2:37pm UTC](https://discuss.elastic.co/t/elastic-agent-with-misp-integration-policy-no-data-received-while-no-errors-comes-up/328183 "2023-03-22T14:37:58Z")

</div>

Hello, I've got a standalone elastic-agent deployed on localhost where my MISP instance is running. I'm trying to integrate MISP IOC's to Elastic in order to use the dashboard. I don't understand why i don't receive a…

---

## [Bug: No Misp event data send to Kibana when Threat intel module used](https://discuss.elastic.co/t/bug-no-misp-event-data-send-to-kibana-when-threat-intel-module-used/327979)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 2:24pm UTC](https://discuss.elastic.co/t/bug-no-misp-event-data-send-to-kibana-when-threat-intel-module-used/327979 "2023-03-22T14:24:03Z")

</div>

Hello, I'm trying to integrate IOCs from MISP to Elastic stack (ELK) using the Filebeat Threat intel module. I'm receiving event in Analytics Discover panel of Kibana with filebeat-\* toggle on: (see below image) B…

---

## [Increase doc\_count even if record is same in date\_histogram on Array field](https://discuss.elastic.co/t/increase-doc-count-even-if-record-is-same-in-date-histogram-on-array-field/328257)

<div class="topic-metadata">

**Author:** [@AbhimanyuSharma](https://discuss.elastic.co/u/AbhimanyuSharma)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 2:16pm UTC](https://discuss.elastic.co/t/increase-doc-count-even-if-record-is-same-in-date-histogram-on-array-field/328257 "2023-03-22T14:16:41Z")

</div>

I have an object / array field which contains date-time. This field contains every second of the duration between start and end time of some event. I am doing this because I want to see the running events on each second.…

---

## [Intermittent outbound connection issue to elastic cloud from azure app service](https://discuss.elastic.co/t/intermittent-outbound-connection-issue-to-elastic-cloud-from-azure-app-service/328181)

<div class="topic-metadata">

**Author:** [@chiragsharp](https://discuss.elastic.co/u/chiragsharp)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 1:36pm UTC](https://discuss.elastic.co/t/intermittent-outbound-connection-issue-to-elastic-cloud-from-azure-app-service/328181 "2023-03-22T13:36:47Z")

</div>

Hello Folks, I have a Virto Commerce deployed in azure app service. From app service intermittently, I am getting below error for connection to elastic cloud. Invalid NEST response built from a unsuccessful () low leve…

---

## [Elastic shards are not storing data equally](https://discuss.elastic.co/t/elastic-shards-are-not-storing-data-equally/328235)

<div class="topic-metadata">

**Author:** [@Chanaka\_Liyanarachch](https://discuss.elastic.co/u/Chanaka_Liyanarachch)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:39pm UTC](https://discuss.elastic.co/t/elastic-shards-are-not-storing-data-equally/328235 "2023-03-22T12:39:54Z")

</div>

elastic shards are not storing data equally,

---

## [Error al ejecutar docker compose](https://discuss.elastic.co/t/error-al-ejecutar-docker-compose/328239)

<div class="topic-metadata">

**Author:** [@karlosmartos](https://discuss.elastic.co/u/karlosmartos)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:37pm UTC](https://discuss.elastic.co/t/error-al-ejecutar-docker-compose/328239 "2023-03-22T12:37:18Z")

</div>

ERROR: \[1\] bootstrap checks failed. You must address the points described in the following \[1\] lines before starting Elasticsearch.

---

## [Filebeat with multiple log path should direct to different Index and Should follow ILM,ILM policy and rollover already defined in elastic](https://discuss.elastic.co/t/filebeat-with-multiple-log-path-should-direct-to-different-index-and-should-follow-ilm-ilm-policy-and-rollover-already-defined-in-elastic/328236)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 11:17am UTC](https://discuss.elastic.co/t/filebeat-with-multiple-log-path-should-direct-to-different-index-and-should-follow-ilm-ilm-policy-and-rollover-already-defined-in-elastic/328236 "2023-03-22T11:17:03Z")

</div>

Hello All, I've a requirement wherein I would like to have single filebeat.yml and this will have different log paths and will direct the data to respective diffrent index according to path. Now this filebeat.yml would…

---

## [Restore indices on snapshots based on their alias](https://discuss.elastic.co/t/restore-indices-on-snapshots-based-on-their-alias/328237)

<div class="topic-metadata">

**Author:** [@Nuno\_Santos1](https://discuss.elastic.co/u/Nuno_Santos1)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 11:23am UTC](https://discuss.elastic.co/t/restore-indices-on-snapshots-based-on-their-alias/328237 "2023-03-22T11:23:43Z")

</div>

When restoring indices from a snapshot, is there a way to get from the snapshot the aliases associated with an index before starting to restore the index? Through the REST API I can get information about the indices that…

---

## [Too many properties: should we increase the property limit or use a nested approach and increase that limit?](https://discuss.elastic.co/t/too-many-properties-should-we-increase-the-property-limit-or-use-a-nested-approach-and-increase-that-limit/328179)

<div class="topic-metadata">

**Author:** [@obi-wan](https://discuss.elastic.co/u/obi-wan)\
**Replies:** 3\
**Last updated:** [March 22, 2023, 11:19am UTC](https://discuss.elastic.co/t/too-many-properties-should-we-increase-the-property-limit-or-use-a-nested-approach-and-increase-that-limit/328179 "2023-03-22T11:19:59Z")

</div>

Hi there, We have a situation with limits in the mapping, and I am not sure what is the way to go as there are multiple solutions. I will start by describing the use case: there are multiple tenants, which each have …

---

## [UPDATE existing index with reindex and pipeline](https://discuss.elastic.co/t/update-existing-index-with-reindex-and-pipeline/328227)

<div class="topic-metadata">

**Author:** [@hben](https://discuss.elastic.co/u/hben)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:51am UTC](https://discuss.elastic.co/t/update-existing-index-with-reindex-and-pipeline/328227 "2023-03-22T09:51:54Z")

</div>

Hi, I have an index that our application is working with like a Relational table, so we insert and update documents in it. now we want to make a structure change and add 3 fields and add data to those fields from a ta…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=594)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=596)
