# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=596

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 597

---

## [Kibana rollup for MAX values](https://discuss.elastic.co/t/kibana-rollup-for-max-values/328228)

<div class="topic-metadata">

**Author:** [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:55am UTC](https://discuss.elastic.co/t/kibana-rollup-for-max-values/328228 "2023-03-22T09:55:19Z")

</div>

Hi, i have this problem with Kibana rollups: i have raw data each 5minutes, as you can see the MAX value from 19:00 till 20:00 is 155.775 When i configured rollup job with Interval 60m in the roollup index as MAX v…

---

## [Convert string to ip in painless processor](https://discuss.elastic.co/t/convert-string-to-ip-in-painless-processor/328189)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:39am UTC](https://discuss.elastic.co/t/convert-string-to-ip-in-painless-processor/328189 "2023-03-22T09:39:15Z")

</div>

Hello, Is there a way to convert a string to an ip address in a painless processor? Regards Hans

---

## [How to use user-defined plugin](https://discuss.elastic.co/t/how-to-use-user-defined-plugin/328224)

<div class="topic-metadata">

**Author:** [@wendywong0020](https://discuss.elastic.co/u/wendywong0020)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:24am UTC](https://discuss.elastic.co/t/how-to-use-user-defined-plugin/328224 "2023-03-22T09:24:06Z")

</div>

logstash.conf: input { file { type =\> "\_doc" path =\> "/data/mysql\_\*\_log/slow.log" codec =\> multiline { …

---

## [Mailenable server smtp activity logs using filebeat to elasticsearch](https://discuss.elastic.co/t/mailenable-server-smtp-activity-logs-using-filebeat-to-elasticsearch/327852)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:08am UTC](https://discuss.elastic.co/t/mailenable-server-smtp-activity-logs-using-filebeat-to-elasticsearch/327852 "2023-03-22T09:08:34Z")

</div>

Hello Every one I am using elasticsearch 7.10 and filebeat 7.10 I want to pars following logs using filebeat to direct elasticsearch I have no Idea how I can achive can you please suggest me from my sample logs. 03/15/…

---

## [Detected ambiguous Field Reference warning](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218)

<div class="topic-metadata">

**Author:** [@parosio](https://discuss.elastic.co/u/parosio)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 8:29am UTC](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218 "2023-03-22T08:29:58Z")

</div>

Hello, I've got to ingest (logstash 6.7) documents which are stages of a workflow (queue\_in, start\_work, end\_work, queue\_out, etc.). I need to add various fields with elapsed times (looking for initial times in previou…

---

## [Double values filebeat](https://discuss.elastic.co/t/double-values-filebeat/328217)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 8:09am UTC](https://discuss.elastic.co/t/double-values-filebeat/328217 "2023-03-22T08:09:16Z")

</div>

Hello, I'm trying to read my log server.json into logstash /kibana. Now I have opened a topic for this before, and I was advised to ask further questions in the filebeat forum. For the record. I've already gotten a lit…

---

## [Extract logs from a file that start with a line and end with a known line do this for the whole file using logstash](https://discuss.elastic.co/t/extract-logs-from-a-file-that-start-with-a-line-and-end-with-a-known-line-do-this-for-the-whole-file-using-logstash/328216)

<div class="topic-metadata">

**Author:** [@chikugerson](https://discuss.elastic.co/u/chikugerson)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:58am UTC](https://discuss.elastic.co/t/extract-logs-from-a-file-that-start-with-a-line-and-end-with-a-known-line-do-this-for-the-whole-file-using-logstash/328216 "2023-03-22T07:58:21Z")

</div>

input { file { path =\> "C:/Users/user/Documents/Logstash/mylogs/spa2.log" start\_position =\> "beginning" } } filter { if "SPAHGW:31 32 30 30 :004:: 1200" in \[message\] { …

---

## [Logstash ignores newly created template when importing index](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:40am UTC](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215 "2023-03-22T07:40:43Z")

</div>

I am using the following pipeline to do an import of an index exported from Elastic: - pipeline.id: import-process pipeline.workers: 4 config.string: | input { file { path =\>…

---

## [Can Filebeat handle same load as Logstash while being a lightweight shipper](https://discuss.elastic.co/t/can-filebeat-handle-same-load-as-logstash-while-being-a-lightweight-shipper/328212)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 6:43am UTC](https://discuss.elastic.co/t/can-filebeat-handle-same-load-as-logstash-while-being-a-lightweight-shipper/328212 "2023-03-22T06:43:09Z")

</div>

if I am using Logstash / Filebeat as a Log server . in term of memory and other things . which tool is better to go with.

---

## [Databricks Spark SQL and Elasticsearch](https://discuss.elastic.co/t/databricks-spark-sql-and-elasticsearch/328028)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 6:19am UTC](https://discuss.elastic.co/t/databricks-spark-sql-and-elasticsearch/328028 "2023-03-22T06:19:45Z")

</div>

Is there any documentation related to Databricks Spark/Spark SQL integration with elasticsearch?

---

## [Query to find all the users with one role](https://discuss.elastic.co/t/query-to-find-all-the-users-with-one-role/328156)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:09am UTC](https://discuss.elastic.co/t/query-to-find-all-the-users-with-one-role/328156 "2023-03-22T04:09:14Z")

</div>

Hi Team, How can I find the user in ELK with one particular role. I can get all the users with following query: GET /\_security/user but when I try to find user with a role GET /\_security/user/ { "query":"select …

---

## [Logstash stop working priodicly!](https://discuss.elastic.co/t/logstash-stop-working-priodicly/328201)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 1:38am UTC](https://discuss.elastic.co/t/logstash-stop-working-priodicly/328201 "2023-03-22T01:38:42Z")

</div>

hi guys. my logstash stopped working several times as you can see in the picture. I have 15 pipelines on one docker logstash node can anyone guess what happened?

---

## [Docker Logs keep getting dropped with tried to parse field \[image\] as object, but found a concrete value error](https://discuss.elastic.co/t/docker-logs-keep-getting-dropped-with-tried-to-parse-field-image-as-object-but-found-a-concrete-value-error/326245)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 49\
**Last updated:** [March 22, 2023, 1:15am UTC](https://discuss.elastic.co/t/docker-logs-keep-getting-dropped-with-tried-to-parse-field-image-as-object-but-found-a-concrete-value-error/326245 "2023-03-22T01:15:41Z")

</div>

When investigating why I couldn't find my docker logs in Elastic, I found that Elastic Agent has been dropping them. It keeps logging stuff like: {"log.level":"warn","@timestamp":"2023-02-22T18:48:50.007-0800","message"…

---

## [Migrating 7.17 to 8.0 (With Frozen Indices and Searchable Snapshots)](https://discuss.elastic.co/t/migrating-7-17-to-8-0-with-frozen-indices-and-searchable-snapshots/328106)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 1:15am UTC](https://discuss.elastic.co/t/migrating-7-17-to-8-0-with-frozen-indices-and-searchable-snapshots/328106 "2023-03-22T01:15:23Z")

</div>

Hello, I'm migrating a cluster from 7.17 to 8.0 and I have frozen indices. I read in the documentation that the frozen action was removed or deprecated in version 8, so I wanted to know I can I safely migrate to version…

---

## [Ingesting syslog from NetApp ONTAP](https://discuss.elastic.co/t/ingesting-syslog-from-netapp-ontap/328170)

<div class="topic-metadata">

**Author:** [@diselkgd7](https://discuss.elastic.co/u/diselkgd7)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:58am UTC](https://discuss.elastic.co/t/ingesting-syslog-from-netapp-ontap/328170 "2023-03-22T00:58:51Z")

</div>

I've configured our storage to send syslog to filebeat but when I examine what's been ingested in kibana - the whole syslog message is crammed in one "message" field while the rest of the 26 fields have values relating t…

---

## [Semantic Search API](https://discuss.elastic.co/t/semantic-search-api/328113)

<div class="topic-metadata">

**Author:** [@rpmansion](https://discuss.elastic.co/u/rpmansion)\
**Replies:** 7\
**Last updated:** [March 21, 2023, 8:52pm UTC](https://discuss.elastic.co/t/semantic-search-api/328113 "2023-03-21T20:52:25Z")

</div>

There is a semantic search API endpoint (/index\_name/\_semantic-search) that was released in the documentation, what is the reason this was removed?

---

## [Conflict fluent bit and elasticsearch](https://discuss.elastic.co/t/conflict-fluent-bit-and-elasticsearch/328198)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 7:54pm UTC](https://discuss.elastic.co/t/conflict-fluent-bit-and-elasticsearch/328198 "2023-03-21T19:54:54Z")

</div>

Hello everyone, I just migrated my cluster from version 7.9 to 8.5 everything went well but I have problems with fluent. For some reason Fluent is not able to ingest on ELK. Here are some data. \[SERVICE\] Flush …

---

## [Failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/327681)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 7:45pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/327681 "2023-03-21T19:45:08Z")

</div>

Hello everyone. I am trying to modify some parameters of the logs that come from fleet with the "custom logs" integration. I have created the following pipeline: LOG LINE: 2023-02-28 09:04:01,937 ERROR \[org.jboss.rem…

---

## [Handle space in a field](https://discuss.elastic.co/t/handle-space-in-a-field/328190)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 7:43pm UTC](https://discuss.elastic.co/t/handle-space-in-a-field/328190 "2023-03-21T19:43:41Z")

</div>

I am trying to remove a space from a field in logstash but it's not working, because there is space in the field, I can't even rename the field or not able to do replacement is with gsub. Request ID to be renamed to Req…

---

## [Auditbeat Equivalent for Elastic Agent](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 6:08pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171 "2023-03-21T18:08:27Z")

</div>

When will there be an Auditbeat-equivalent Integration for Elastic Agent? We are trying to move exclusively to Elastic Agent, but the same monitoring done by Auditbeat is still not yet available that I can see. Eric

---

## [Query Alert History in Elastic Cloud 8.6.2](https://discuss.elastic.co/t/query-alert-history-in-elastic-cloud-8-6-2/328105)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 3\
**Last updated:** [March 21, 2023, 5:38pm UTC](https://discuss.elastic.co/t/query-alert-history-in-elastic-cloud-8-6-2/328105 "2023-03-21T17:38:00Z")

</div>

As an Elastic Cloud user (v8.6.2), I would like to query my Observability Alert history for reporting purposes, and perhaps even to create a high-level dashboard showing open alerts across multiple workspaces in Elastic …

---

## [Ingest RESTAPI response into Elasticsearch as separate document through Logstash](https://discuss.elastic.co/t/ingest-restapi-response-into-elasticsearch-as-separate-document-through-logstash/328117)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 5:30pm UTC](https://discuss.elastic.co/t/ingest-restapi-response-into-elasticsearch-as-separate-document-through-logstash/328117 "2023-03-21T17:30:28Z")

</div>

I am working http\_poller and using http plugin to ingest RestApi Array response output into Elasticsearch. using Logstash , I need help to split the output and store each as a separate document in Elasticsearch. Below…

---

## [Best approach to implement ILM on a large index and archive old data](https://discuss.elastic.co/t/best-approach-to-implement-ilm-on-a-large-index-and-archive-old-data/328045)

<div class="topic-metadata">

**Author:** [@Baygon](https://discuss.elastic.co/u/Baygon)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 4:43pm UTC](https://discuss.elastic.co/t/best-approach-to-implement-ilm-on-a-large-index-and-archive-old-data/328045 "2023-03-21T16:43:16Z")

</div>

Hi, We have a single node cluster where one index unfortunately grew very big (261Gb) as we had no ILM on it. This is a production cluster. We understand that above 50Gb there is performance degradation and I think we …

---

## [Maximum allowed string Issue](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076 "2023-03-21T16:21:11Z")

</div>

I get this error: The content length (732630494) is bigger than the maximum allowed string (536870888) I added to kibana.yml: server.maxPayloadBytes: 888888888 savedObjects.maxImportPayloadBytes: 50485760 I added to…

---

## [How to avoid host.name field in filebeat](https://discuss.elastic.co/t/how-to-avoid-host-name-field-in-filebeat/327578)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 4:06pm UTC](https://discuss.elastic.co/t/how-to-avoid-host-name-field-in-filebeat/327578 "2023-03-21T16:06:24Z")

</div>

Hi Team, I am sending data to elasticsearch using filebeat once the file were harvested I can see field host.name where the value is hostname of the VM { "\_index": "filebeat-7.17.6-2023.03.13-000001", "\_type":…

---

## [Query Elastic APM Data for Custom Dashboard](https://discuss.elastic.co/t/query-elastic-apm-data-for-custom-dashboard/328107)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 4:02pm UTC](https://discuss.elastic.co/t/query-elastic-apm-data-for-custom-dashboard/328107 "2023-03-21T16:02:29Z")

</div>

As our company's Elastic Cloud admin (v8.6.2), I have some users who would EITHER like to include a component from the Obervability-\>APM Overview as part of a custom dashboard OR build a similar visualization from APM da…

---

## [To Know about Legacy Index Template](https://discuss.elastic.co/t/to-know-about-legacy-index-template/327180)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 3\
**Last updated:** [March 21, 2023, 3:25pm UTC](https://discuss.elastic.co/t/to-know-about-legacy-index-template/327180 "2023-03-21T15:25:06Z")

</div>

Hi Team, We changed the ILM of one of the index from 10days to 7days, but we can see the Legacy index templates still showing ILM as 10days. If present ILM of 7days doesn't work, will it consider the older ILM of 10day…

---

## [Metricbeat setup: one-time?](https://discuss.elastic.co/t/metricbeat-setup-one-time/327959)

<div class="topic-metadata">

**Author:** [@NominaSumpta](https://discuss.elastic.co/u/NominaSumpta)\
**Replies:** 11\
**Last updated:** [March 21, 2023, 2:02pm UTC](https://discuss.elastic.co/t/metricbeat-setup-one-time/327959 "2023-03-21T14:02:55Z")

</div>

Is metricbeat setup meant to be run once per cluster? The documentation (Metricbeat quick start: installation and configuration | Metricbeat Reference \[8.6\] | Elastic) does not say. It is implied that this command is m…

---

## [Use Graph inside plugin](https://discuss.elastic.co/t/use-graph-inside-plugin/328129)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 2:25pm UTC](https://discuss.elastic.co/t/use-graph-inside-plugin/328129 "2023-03-21T14:25:38Z")

</div>

Hi, I am developing an external plugin using React. I want to draw graphs inside the same. Is there a library or api using which I can draw custom graphs inside the plugin? Thanks

---

## [Extract from ElasticSearch, into Kafka, continuously add any new ES updates using logstash](https://discuss.elastic.co/t/extract-from-elasticsearch-into-kafka-continuously-add-any-new-es-updates-using-logstash/328172)

<div class="topic-metadata">

**Author:** [@aniketdatir](https://discuss.elastic.co/u/aniketdatir)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 2:21pm UTC](https://discuss.elastic.co/t/extract-from-elasticsearch-into-kafka-continuously-add-any-new-es-updates-using-logstash/328172 "2023-03-21T14:21:20Z")

</div>

Hi Team, My objective is to add latest ES index documents to kafka Below is my logstash conf -\> ''' input { elasticsearch { hosts =\> \["IP"\] index =\> "Index\_name" query =\> '{"query":{"range":{"@timestamp":{"gte": …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=595)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=597)
