# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=597

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 598

---

## [Logstash Parse stingyfied json to seperate json fieldsl](https://discuss.elastic.co/t/logstash-parse-stingyfied-json-to-seperate-json-fieldsl/327097)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 3:13pm UTC](https://discuss.elastic.co/t/logstash-parse-stingyfied-json-to-seperate-json-fieldsl/327097 "2023-03-06T15:13:24Z")

</div>

Hello All, I've a column in oracle table PACKAGE\_DATA and it has json like string in it and I would like to get every fileds and its value seperate: PACKAGE\_DATA Column data {"status":"READY\_FOR\_PROCESSING","errorData…

---

## [Logstash filter to process jason array fileds as seperate fileds in elastic indexl](https://discuss.elastic.co/t/logstash-filter-to-process-jason-array-fileds-as-seperate-fileds-in-elastic-indexl/326874)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 9\
**Last updated:** [March 15, 2023, 3:56pm UTC](https://discuss.elastic.co/t/logstash-filter-to-process-jason-array-fileds-as-seperate-fileds-in-elastic-indexl/326874 "2023-03-15T15:56:53Z")

</div>

Hello All, After trying several time,I'm unable to process one column in oracle table that contains json data and I would require every field in that as seperate filed created in elastic index.Could someone guide what a…

---

## [Filtering two different nested fields in the same agg](https://discuss.elastic.co/t/filtering-two-different-nested-fields-in-the-same-agg/328169)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 1:55pm UTC](https://discuss.elastic.co/t/filtering-two-different-nested-fields-in-the-same-agg/328169 "2023-03-21T13:55:39Z")

</div>

I understand how to filter on two nested fields using sub aggregations and get individual doc\_counts out of them, but I want to filter and count one nested field by the value of another nested field. eg: Imagine a docu…

---

## [Request API to obtain active alerts](https://discuss.elastic.co/t/request-api-to-obtain-active-alerts/326461)

<div class="topic-metadata">

**Author:** [@fabien9402](https://discuss.elastic.co/u/fabien9402)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 1:27pm UTC](https://discuss.elastic.co/t/request-api-to-obtain-active-alerts/326461 "2023-03-21T13:27:45Z")

</div>

Hello everyone, On the Kibana interface I have a rule called "No logs from docker", this is a "Log threshold" rule which should tell me when I have not received a log containing the "event.dataset" with value "docker.co…

---

## [Updating an existing field using path data](https://discuss.elastic.co/t/updating-an-existing-field-using-path-data/328110)

<div class="topic-metadata">

**Author:** [@Jeferson\_Schiavinato](https://discuss.elastic.co/u/Jeferson_Schiavinato)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 1:07pm UTC](https://discuss.elastic.co/t/updating-an-existing-field-using-path-data/328110 "2023-03-21T13:07:36Z")

</div>

Hello Guys, I am using a path which is formed by /dir/subdir/filename\_log.gz. I want to extract the filename and update an existent Field called Hostname with this information. I have tried to use this code, but I had…

---

## [Offline plugin needed elf\_elk](https://discuss.elastic.co/t/offline-plugin-needed-elf-elk/328163)

<div class="topic-metadata">

**Author:** [@UsmanNiazi](https://discuss.elastic.co/u/UsmanNiazi)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 12:48pm UTC](https://discuss.elastic.co/t/offline-plugin-needed-elf-elk/328163 "2023-03-21T12:48:39Z")

</div>

Hi I need to install Salesforce Event Log File on ELK Stack. But it is giving error. Can you please provide the offline plugin. I have tried to download the plugin from below but its not working. Giving errors when try …

---

## [Merge 2 Clusters with same name](https://discuss.elastic.co/t/merge-2-clusters-with-same-name/328065)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 12:09pm UTC](https://discuss.elastic.co/t/merge-2-clusters-with-same-name/328065 "2023-03-21T12:09:20Z")

</div>

Hi Team, Is there any way where we can merge 2 clusters with same name to 1. Scenario is... will have an existing cluster with name xyz and have some data. Will create additional cluster in different nodes with same na…

---

## [Kibana Canvas drop-down filter not updating count metric correctly](https://discuss.elastic.co/t/kibana-canvas-drop-down-filter-not-updating-count-metric-correctly/328062)

<div class="topic-metadata">

**Author:** [@cristinan](https://discuss.elastic.co/u/cristinan)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 11:32am UTC](https://discuss.elastic.co/t/kibana-canvas-drop-down-filter-not-updating-count-metric-correctly/328062 "2023-03-21T11:32:55Z")

</div>

My metric shows okay on dateTime filter, but not on drop down filter. The date time filter uses a column pmt-stsDtTm which is to be found in indices queried to populate drop-down filters. I have uploaded also…

---

## [Is there a way to get less used/searched logs in Elasticsearch](https://discuss.elastic.co/t/is-there-a-way-to-get-less-used-searched-logs-in-elasticsearch/328081)

<div class="topic-metadata">

**Author:** [@Amulya\_Nanda](https://discuss.elastic.co/u/Amulya_Nanda)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 11:24am UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-less-used-searched-logs-in-elasticsearch/328081 "2023-03-21T11:24:07Z")

</div>

Hi Team, We are looking to list out less usage logs in Elasticsearch. For example: we have logs getting ingested from many setups. We wanted to query/ or list out less used logs from setups basis. How can we get the d…

---

## [Display date range](https://discuss.elastic.co/t/display-date-range/328087)

<div class="topic-metadata">

**Author:** [@Igor\_Stankovic](https://discuss.elastic.co/u/Igor_Stankovic)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 10:57am UTC](https://discuss.elastic.co/t/display-date-range/328087 "2023-03-21T10:57:42Z")

</div>

Hi there! I am wondering if there is a possibility to display the selected date range filter in a lens in Kibana. The issue for me is that when in full screen in view mode, the currently selected date range is hidden a…

---

## [Error: failed to perform any bulk index operations: 429 Too Many Requests](https://discuss.elastic.co/t/error-failed-to-perform-any-bulk-index-operations-429-too-many-requests/328074)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 10\
**Last updated:** [March 21, 2023, 10:07am UTC](https://discuss.elastic.co/t/error-failed-to-perform-any-bulk-index-operations-429-too-many-requests/328074 "2023-03-21T10:07:04Z")

</div>

Hello, I know that there is already a lot of post on (github | stackoverflow | here) about this error and how to fix it but despite the reading of all of these ones i was not able to get rid of this error: Here is a sn…

---

## [Ingest logs from S3 bucket](https://discuss.elastic.co/t/ingest-logs-from-s3-bucket/328155)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 10:25am UTC](https://discuss.elastic.co/t/ingest-logs-from-s3-bucket/328155 "2023-03-21T10:25:43Z")

</div>

Currently i am using elk stack to ingest only warning and errors logs to Elasticsearch server. Also i am using elastic beanstalk to rotate logs to S3 bucket. Now as i ingest only warning and error logs sometimes i need …

---

## [Import from Azure Log Analytics Workspace](https://discuss.elastic.co/t/import-from-azure-log-analytics-workspace/328144)

<div class="topic-metadata">

**Author:** [@tigerkungen](https://discuss.elastic.co/u/tigerkungen)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:57am UTC](https://discuss.elastic.co/t/import-from-azure-log-analytics-workspace/328144 "2023-03-21T08:57:41Z")

</div>

What is the recommended design for importing logs from Azure Log Analytics Workspace to Elastic Cloud? Read somewhere that you could export direct to elastic via the advanced menu in Azure Log Analytics workspace. But …

---

## [Overwrite data VS data duplication](https://discuss.elastic.co/t/overwrite-data-vs-data-duplication/328143)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:53am UTC](https://discuss.elastic.co/t/overwrite-data-vs-data-duplication/328143 "2023-03-21T08:53:18Z")

</div>

Hello, every all, What is the goal of handling the data duplication using a fingerprint filter, In my opinion, this is overwritten data, not preventing the duplication. Let's say the overwrite is removing the oldest an…

---

## [My Kibana Dashboard shows 350 percentage or more for CPU utilization for Servers.. i wanted to have the vaules under 100 percentage](https://discuss.elastic.co/t/my-kibana-dashboard-shows-350-percentage-or-more-for-cpu-utilization-for-servers-i-wanted-to-have-the-vaules-under-100-percentage/328141)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:40am UTC](https://discuss.elastic.co/t/my-kibana-dashboard-shows-350-percentage-or-more-for-cpu-utilization-for-servers-i-wanted-to-have-the-vaules-under-100-percentage/328141 "2023-03-21T08:40:55Z")

</div>

ELK 7.17.3 , KIBANA : 7.17.3 I have created Kibana Dashboards - there is a Average CPU Utilization dashboard for Application servers - the graph shows 350 or 250 percentage for cpu . which is quite confusing . I would…

---

## [What are logstash-plain-YYYY-MM-DD.log.gz and logstash-deprecation-YYYY-MM-DD.log.gz?](https://discuss.elastic.co/t/what-are-logstash-plain-yyyy-mm-dd-log-gz-and-logstash-deprecation-yyyy-mm-dd-log-gz/328125)

<div class="topic-metadata">

**Author:** [@ohaya](https://discuss.elastic.co/u/ohaya)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 8:21am UTC](https://discuss.elastic.co/t/what-are-logstash-plain-yyyy-mm-dd-log-gz-and-logstash-deprecation-yyyy-mm-dd-log-gz/328125 "2023-03-21T08:21:37Z")

</div>

Hi, I'm fairly new working with logstash (and actually the entire ELK components), but am trying to determine why some logs are not being ingested and indexed. While I was investigating this, I noticed that on the mach…

---

## [Sending data from 2 logstash nodes to an elasticsearch cluster](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 6:29am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128 "2023-03-21T06:29:34Z")

</div>

Hi Folks, I have 2 logstash nodes (version -8.6.2) that i want to send data to 2 elasticsearch nodes (version -8.6.2) ( a third node will be added soon to the cluster) . Do i just mention the elasticsearch nodes' in t…

---

## [Sort on multiple fields Not working](https://discuss.elastic.co/t/sort-on-multiple-fields-not-working/328131)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 6:27am UTC](https://discuss.elastic.co/t/sort-on-multiple-fields-not-working/328131 "2023-03-21T06:27:58Z")

</div>

Hi, I'm trying to sort on multiple fields like - sort on field1 first if there is a tie on field1, sort based on field 2. POST sort\_logic/\_doc { "field1" : 4, "field2" : "4" } POST sort\_logic/\_doc { "field1" : …

---

## [How to specify "bulk\_path" in elasticsearch output on logstash config](https://discuss.elastic.co/t/how-to-specify-bulk-path-in-elasticsearch-output-on-logstash-config/328130)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 5:49am UTC](https://discuss.elastic.co/t/how-to-specify-bulk-path-in-elasticsearch-output-on-logstash-config/328130 "2023-03-21T05:49:19Z")

</div>

Hello, how do i mention "bulk\_path" in the ES output in logstash ? this is how it's currently implemented (testing) , but i wanted to confirm if i'm doing is correct I have 2 elasticsearch nodes ( a 3rd one will be pr…

---

## [Elasticsearch Java Client create query for field with list of values](https://discuss.elastic.co/t/elasticsearch-java-client-create-query-for-field-with-list-of-values/328040)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 1:59pm UTC](https://discuss.elastic.co/t/elasticsearch-java-client-create-query-for-field-with-list-of-values/328040 "2023-03-20T13:59:32Z")

</div>

String searchText = "TEST"; .query(q -\> q.bool(b -\> b .must(c-\> c .match(t -\> t .field("FI…

---

## ["dynamic method \[java.lang.Long, toInstant/0\] not found"](https://discuss.elastic.co/t/dynamic-method-java-lang-long-toinstant-0-not-found/328127)

<div class="topic-metadata">

**Author:** [@saupuran](https://discuss.elastic.co/u/saupuran)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 5:36am UTC](https://discuss.elastic.co/t/dynamic-method-java-lang-long-toinstant-0-not-found/328127 "2023-03-21T05:36:55Z")

</div>

Currently we are using 'LogDate' as scripted field with script doc\['transactiondate'\].value to convert unix time format of 'transactiondate' into human readable date format. When we apply filter with 'LogDate', condition…

---

## [Sort based on absolute value](https://discuss.elastic.co/t/sort-based-on-absolute-value/328078)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 5:36am UTC](https://discuss.elastic.co/t/sort-based-on-absolute-value/328078 "2023-03-21T05:36:07Z")

</div>

Hi, I'm looking to sort documents based on a field of long type by their absolute value. So, the change field has both positive and negative numbers. "change" : { "type" : "long" } I want to sort it in such a way th…

---

## [Index\_failed number is increasing after adding a new node to elasticsearch cluster(previously single node)](https://discuss.elastic.co/t/index-failed-number-is-increasing-after-adding-a-new-node-to-elasticsearch-cluster-previously-single-node/328098)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 5:32am UTC](https://discuss.elastic.co/t/index-failed-number-is-increasing-after-adding-a-new-node-to-elasticsearch-cluster-previously-single-node/328098 "2023-03-21T05:32:45Z")

</div>

Hi Folks, Today i added a new node to a previously single -node elasticsearch cluster and the process was successful . however when i look at the node stats (via the node stats API) it shows the index\_failed numbers to …

---

## [What the better way, create 400 columns with types keyword, text, float, date and boolean in index or 5 nested fields?](https://discuss.elastic.co/t/what-the-better-way-create-400-columns-with-types-keyword-text-float-date-and-boolean-in-index-or-5-nested-fields/328123)

<div class="topic-metadata">

**Author:** [@Yuri\_Khmelevsky](https://discuss.elastic.co/u/Yuri_Khmelevsky)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 4:02am UTC](https://discuss.elastic.co/t/what-the-better-way-create-400-columns-with-types-keyword-text-float-date-and-boolean-in-index-or-5-nested-fields/328123 "2023-03-21T04:02:18Z")

</div>

What is the better for read and write performance? And in general is this good idea to store 400 columns in index (I know that I can store 1000 columns per index by default). I expect that one documents will have 5-15 t…

---

## [How to enriching events with "dynamic" data from a file](https://discuss.elastic.co/t/how-to-enriching-events-with-dynamic-data-from-a-file/328019)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 9\
**Last updated:** [March 21, 2023, 3:10am UTC](https://discuss.elastic.co/t/how-to-enriching-events-with-dynamic-data-from-a-file/328019 "2023-03-21T03:10:25Z")

</div>

Tinkering with how to enrich filebeat events by tagging/labelling with data picked from a text that might change infrequently but still change (days, weeks, months). We're talking off application version data, so wheneve…

---

## [How to join two indexes or use an index as a lookup](https://discuss.elastic.co/t/how-to-join-two-indexes-or-use-an-index-as-a-lookup/328073)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 1:19am UTC](https://discuss.elastic.co/t/how-to-join-two-indexes-or-use-an-index-as-a-lookup/328073 "2023-03-21T01:19:15Z")

</div>

I have log indexes with 500 million records daily in one index (logs-20230320,logs-20230321,...) And i have malicious IP addresses list ( ~150.000 records) in another index (blacklist-202303) (rebuilt every day) I need…

---

## [Scripted fields in pyspark](https://discuss.elastic.co/t/scripted-fields-in-pyspark/328092)

<div class="topic-metadata">

**Author:** [@nissan15](https://discuss.elastic.co/u/nissan15)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 10:41pm UTC](https://discuss.elastic.co/t/scripted-fields-in-pyspark/328092 "2023-03-20T22:41:12Z")

</div>

Hey, Is it possible to use scripted fields using pyspark? if so how can I use it? and if not - how can I query field and convert the field from float to integer in the query itself? thanks

---

## [Issue with apache Tika Extraction for Tabular Column Data in PDF](https://discuss.elastic.co/t/issue-with-apache-tika-extraction-for-tabular-column-data-in-pdf/328080)

<div class="topic-metadata">

**Author:** [@Sai\_Kiran\_solix](https://discuss.elastic.co/u/Sai_Kiran_solix)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 9:05pm UTC](https://discuss.elastic.co/t/issue-with-apache-tika-extraction-for-tabular-column-data-in-pdf/328080 "2023-03-20T21:05:04Z")

</div>

I extracted a PDF that has tabular column data using apache Tika, in the result the row data from different columns are getting merged Before Extracting | Column A | Column B | | -------- | -------- | | 1 | saikiran | |…

---

## [My Runtime Script is not returning a value](https://discuss.elastic.co/t/my-runtime-script-is-not-returning-a-value/327217)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 8:33pm UTC](https://discuss.elastic.co/t/my-runtime-script-is-not-returning-a-value/327217 "2023-03-20T20:33:10Z")

</div>

Hello, I have created a runtime field named "user". My goal is to extract the username (user=Bob) from a 'event.original' mapping which looks like this: "event.original": \[ "Mar 7 10:17:44 Bob gdm-password\]\[15454…

---

## [Changed password for metricbeat user, now I can't connect to Kibana](https://discuss.elastic.co/t/changed-password-for-metricbeat-user-now-i-cant-connect-to-kibana/327970)

<div class="topic-metadata">

**Author:** [@JacobBaynes](https://discuss.elastic.co/u/JacobBaynes)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 7:41pm UTC](https://discuss.elastic.co/t/changed-password-for-metricbeat-user-now-i-cant-connect-to-kibana/327970 "2023-03-20T19:41:15Z")

</div>

Hello! The employee who set up our instance of elastic is no longer working here and he did not document how he set things up or the passwords that he created for the user that metricbeat uses to connect to the kibana/el…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=596)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=598)
