# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=598

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 599

---

## [Filebeat error no data coming to kibana](https://discuss.elastic.co/t/filebeat-error-no-data-coming-to-kibana/328034)

<div class="topic-metadata">

**Author:** [@Whazaza](https://discuss.elastic.co/u/Whazaza)\
**Replies:** 13\
**Last updated:** [March 20, 2023, 7:01pm UTC](https://discuss.elastic.co/t/filebeat-error-no-data-coming-to-kibana/328034 "2023-03-20T19:01:04Z")

</div>

Configure filebeat as indicated in the kibana integrations with the following steps: curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-8.6.2-amd64.deb sudo dpkg -i filebeat-8.6.2-amd64.deb (modi…

---

## [RPM signing key is invalid on newer operating systems](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 7:04pm UTC](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476 "2023-03-20T19:04:59Z")

</div>

The signing key used for RPM packages (and I assume other package types) is no longer valid on newer operating systems since the key is SHA1 and these newer operating systems have deprecated SHA1. Specifically, I'm tryi…

---

## [My elasticsearch is not running with error code 128](https://discuss.elastic.co/t/my-elasticsearch-is-not-running-with-error-code-128/327892)

<div class="topic-metadata">

**Author:** [@Terry\_2018](https://discuss.elastic.co/u/Terry_2018)\
**Replies:** 9\
**Last updated:** [March 20, 2023, 6:54pm UTC](https://discuss.elastic.co/t/my-elasticsearch-is-not-running-with-error-code-128/327892 "2023-03-20T18:54:02Z")

</div>

Hi. I'm using Elasticsearch 8.6.2 on Ubuntu 22.04. Since a few days ago, my elastic is not running. Please help me. The system output is below. dev@logserver:~$ sudo systemctl status elasticsearch × elasticsearch.se…

---

## [Allocation Failed](https://discuss.elastic.co/t/allocation-failed/328097)

<div class="topic-metadata">

**Author:** [@fnitz](https://discuss.elastic.co/u/fnitz)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 5:58pm UTC](https://discuss.elastic.co/t/allocation-failed/328097 "2023-03-20T17:58:03Z")

</div>

Hi, I've got many error messages like that: { "index" : "logstash-prod\_operations\_clear-001098", "shard" : 0, "primary" : false, "current\_state" : "unassigned", "unassigned\_info" : { "reason" : "ALLOCATIO…

---

## [How to send aggregation key one by one to webhook action](https://discuss.elastic.co/t/how-to-send-aggregation-key-one-by-one-to-webhook-action/328102)

<div class="topic-metadata">

**Author:** [@sai7276p](https://discuss.elastic.co/u/sai7276p)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 5:20pm UTC](https://discuss.elastic.co/t/how-to-send-aggregation-key-one-by-one-to-webhook-action/328102 "2023-03-20T17:20:20Z")

</div>

Hi I am trying to send an aggregated hosts keys to webhook actions in parameters fields.. When I use single action and this template //{{#ctx.payload.hosts}}{{key}} {{/ctx.payload.hosts}} It perfectly sends an array …

---

## [Does Rally support benchmark the performance about deleting a type of documents?](https://discuss.elastic.co/t/does-rally-support-benchmark-the-performance-about-deleting-a-type-of-documents/328033)

<div class="topic-metadata">

**Author:** [@gloriacs](https://discuss.elastic.co/u/gloriacs)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 4:53pm UTC](https://discuss.elastic.co/t/does-rally-support-benchmark-the-performance-about-deleting-a-type-of-documents/328033 "2023-03-20T16:53:08Z")

</div>

Hi all, I want to use Rally to benchmark the performance of deleting documents instead of deleting an index. Like, delete all documents from that specific day. I know elasticsearch support that by using delete\_by\_query …

---

## [Elastic Agent falling after first enrollment on fleet server](https://discuss.elastic.co/t/elastic-agent-falling-after-first-enrollment-on-fleet-server/327385)

<div class="topic-metadata">

**Author:** [@thiago8martins](https://discuss.elastic.co/u/thiago8martins)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elastic-agent-falling-after-first-enrollment-on-fleet-server/327385 "2023-03-20T16:45:16Z")

</div>

Hello Folks, I'm deploying Elastic Agent and Fleet Server on K8s environment: The Fleet Server I have deployed at the same cluster as the Kibana and ES using ECK. The Elastic Agent i need to deploy in other K8s clust…

---

## [Json parsin](https://discuss.elastic.co/t/json-parsin/326849)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 10\
**Last updated:** [March 20, 2023, 4:34pm UTC](https://discuss.elastic.co/t/json-parsin/326849 "2023-03-20T16:34:54Z")

</div>

Hello, I have a question. We are trying to set up a logging system for a java application running on Jboss. The goal is to be able to filter for certain errors. We've done the following Server.log converted to server.…

---

## [Convert Minutes in to hour in Kibana field "TotalDuration"](https://discuss.elastic.co/t/convert-minutes-in-to-hour-in-kibana-field-totalduration/327413)

<div class="topic-metadata">

**Author:** [@Vivek\_Nigam](https://discuss.elastic.co/u/Vivek_Nigam)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 3:44pm UTC](https://discuss.elastic.co/t/convert-minutes-in-to-hour-in-kibana-field-totalduration/327413 "2023-03-20T15:44:43Z")

</div>

Hi, I calulating sum of TotalDuration field in kibana , TotalDuration field is in Minutes. i want to convert minutes in to Hours while dispalying in kibana visulization . I tried json input : { "script": { "inline…

---

## [Unable to configure curator to archive data from Elasticsearch](https://discuss.elastic.co/t/unable-to-configure-curator-to-archive-data-from-elasticsearch/323354)

<div class="topic-metadata">

**Author:** [@Pendela-BhargavaSai](https://discuss.elastic.co/u/Pendela-BhargavaSai)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/unable-to-configure-curator-to-archive-data-from-elasticsearch/323354 "2023-03-20T15:37:39Z")

</div>

Hi I am a newbie to Elastic search. In my project we are working on archiving data using Curator. I am trying to configure the curator with Elasticsearch but unable to do that. I am facing some connectivity issues for c…

---

## [Kibana Graph - Tree, Tidy of D3.js for create a line trail on my infrastructure with a correlationID](https://discuss.elastic.co/t/kibana-graph-tree-tidy-of-d3-js-for-create-a-line-trail-on-my-infrastructure-with-a-correlationid/328061)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 3:35pm UTC](https://discuss.elastic.co/t/kibana-graph-tree-tidy-of-d3-js-for-create-a-line-trail-on-my-infrastructure-with-a-correlationid/328061 "2023-03-20T15:35:15Z")

</div>

Hey, i want know if the Graph module on Kibana use D3.js ? and if is possible to create a tree graph with only path on dateTime log . I should see a from left to right (oldest to newest) a path on each place where a p…

---

## [Kibana api data view NOT working as expected with namespaces parameter](https://discuss.elastic.co/t/kibana-api-data-view-not-working-as-expected-with-namespaces-parameter/327168)

<div class="topic-metadata">

**Author:** [@Gautier\_Franchini](https://discuss.elastic.co/u/Gautier_Franchini)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 3:29pm UTC](https://discuss.elastic.co/t/kibana-api-data-view-not-working-as-expected-with-namespaces-parameter/327168 "2023-03-20T15:29:11Z")

</div>

Dear All, my goal is to create kibana data\_views using the API; It works fine if I create simple data\_view in the default space. But it's not working if I want to precise the namespace I want to target. Looking in the…

---

## [Kibana Data View update API request doesn't work](https://discuss.elastic.co/t/kibana-data-view-update-api-request-doesnt-work/327435)

<div class="topic-metadata">

**Author:** [@nilaksha](https://discuss.elastic.co/u/nilaksha)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 3:19pm UTC](https://discuss.elastic.co/t/kibana-data-view-update-api-request-doesnt-work/327435 "2023-03-20T15:19:43Z")

</div>

I'm using latest version of 8.6.2 kibana and i need to change the index pattern in kibana Data View to visualize data dynamically. so i have to do it using kibana rest API and found Data View Update API Documentation. bu…

---

## [Prefix and port appear flipped in es-hadoop implementation](https://discuss.elastic.co/t/prefix-and-port-appear-flipped-in-es-hadoop-implementation/328072)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 3:01pm UTC](https://discuss.elastic.co/t/prefix-and-port-appear-flipped-in-es-hadoop-implementation/328072 "2023-03-20T15:01:51Z")

</div>

Attempting to read/write with es-hadoop however I am getting the following error in Databricks EsHadoopInvalidRequest: \[HEAD\] on \[index\_name\] failed; server \[https://serveraddress.com/es:443\] returned \[405|Method Not Al…

---

## [How to write elastic search query for one required parameter and another optional paramater](https://discuss.elastic.co/t/how-to-write-elastic-search-query-for-one-required-parameter-and-another-optional-paramater/328089)

<div class="topic-metadata">

**Author:** [@Phoenix1990](https://discuss.elastic.co/u/Phoenix1990)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 2:39pm UTC](https://discuss.elastic.co/t/how-to-write-elastic-search-query-for-one-required-parameter-and-another-optional-paramater/328089 "2023-03-20T14:39:33Z")

</div>

I need to create an Elasticsearch endpoint with two paramater : Session(required field),CallType(Optional) which returns call details bewteen Teacher and student. I can search for specific session with below details. My …

---

## [Transform for change between states](https://discuss.elastic.co/t/transform-for-change-between-states/328082)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 2:06pm UTC](https://discuss.elastic.co/t/transform-for-change-between-states/328082 "2023-03-20T14:06:27Z")

</div>

Hi All I have a large index that is populated using logstash with a Kafka input ~200m documents in it. We are building a pretty conmplex dashboard based on the data from that index I need some guidance on how I can bui…

---

## [We couldn't log you in. Please try again](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again/327950)

<div class="topic-metadata">

**Author:** [@prabakaran23](https://discuss.elastic.co/u/prabakaran23)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 1:55pm UTC](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again/327950 "2023-03-20T13:55:25Z")

</div>

Hi, Unable to login the kibana console today. We are facing following error "We couldn't log you in. Please try again." Kindly help on this..

---

## [\[half\_float\] parsing error](https://discuss.elastic.co/t/half-float-parsing-error/328057)

<div class="topic-metadata">

**Author:** [@Raul\_Uria](https://discuss.elastic.co/u/Raul_Uria)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 1:51pm UTC](https://discuss.elastic.co/t/half-float-parsing-error/328057 "2023-03-20T13:51:00Z")

</div>

Hi, I can´t understand why my data is not parsed. I got this on my logs: status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[MyFIELD-NAME\] of type \[half\_float\] in document with …

---

## [Percent change from variable selections](https://discuss.elastic.co/t/percent-change-from-variable-selections/327864)

<div class="topic-metadata">

**Author:** [@jack-morrison](https://discuss.elastic.co/u/jack-morrison)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 1:39pm UTC](https://discuss.elastic.co/t/percent-change-from-variable-selections/327864 "2023-03-20T13:39:11Z")

</div>

Hi Elastic Community! I've introduced the ELK stack to my organization, and it has been well received with the exception of one requirement I've been so far unable to meet after months of trying - deriving metrics from …

---

## [Not able to sort on Long field and Function score also not working](https://discuss.elastic.co/t/not-able-to-sort-on-long-field-and-function-score-also-not-working/328077)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 1:27pm UTC](https://discuss.elastic.co/t/not-able-to-sort-on-long-field-and-function-score-also-not-working/328077 "2023-03-20T13:27:15Z")

</div>

Hello, I am performing a simple query and sorting on a field (Long Type). It is not sorting. { "from":0, "size": 5000, "query" : { "match\_all" : {} }, "sort":\[ { "sort\_field"…

---

## [Kibana logs for tcp level blocked traffic](https://discuss.elastic.co/t/kibana-logs-for-tcp-level-blocked-traffic/328055)

<div class="topic-metadata">

**Author:** [@Vlada\_Homyakova](https://discuss.elastic.co/u/Vlada_Homyakova)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 1:06pm UTC](https://discuss.elastic.co/t/kibana-logs-for-tcp-level-blocked-traffic/328055 "2023-03-20T13:06:42Z")

</div>

Hi guys! Is it possible to see blocked traffic in tcp level in Kibana logs ? For example load balancer blocked traffic , can I see it somehow in kibana dashboards the blocked requests ?

---

## [How to convert one filed date to string in Logstash](https://discuss.elastic.co/t/how-to-convert-one-filed-date-to-string-in-logstash/328075)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 12:47pm UTC](https://discuss.elastic.co/t/how-to-convert-one-filed-date-to-string-in-logstash/328075 "2023-03-20T12:47:06Z")

</div>

Hi, I have below log pattern, 2023-03-15T11:11:59.341602012Z stdout F \[INFO \] {"logtype":"msg","trackingid":"XXXXXXX","abcid":"XXXXXXX","operation":{"name":"XXXXX","version":"105"} ,"usecase":"ABC","runtimes":{"output…

---

## [Chart-Title from data values](https://discuss.elastic.co/t/chart-title-from-data-values/327998)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 12:32pm UTC](https://discuss.elastic.co/t/chart-title-from-data-values/327998 "2023-03-20T12:32:37Z")

</div>

Hi community, I know this is not necessarily a question for this forum, but I hope someone might be able to help. I want to take the title of my chart directly from the data which are base of the chart. For example the …

---

## [How to pass result of one chained input, into next chained input](https://discuss.elastic.co/t/how-to-pass-result-of-one-chained-input-into-next-chained-input/328069)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 12:07pm UTC](https://discuss.elastic.co/t/how-to-pass-result-of-one-chained-input-into-next-chained-input/328069 "2023-03-20T12:07:03Z")

</div>

I am writing a watcher, to first fetch destination.ip field (using aggregation), and then I have to use 1st input result for terms query value (in 3rd input) POST \_watcher/watch/\_execute { "watch": { "trigger": { …

---

## [Lens formulas count problem](https://discuss.elastic.co/t/lens-formulas-count-problem/328050)

<div class="topic-metadata">

**Author:** [@lize\_su](https://discuss.elastic.co/u/lize_su)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 12:06pm UTC](https://discuss.elastic.co/t/lens-formulas-count-problem/328050 "2023-03-20T12:06:48Z")

</div>

Hi all, I'm pretty new to kibana and trying to use below code to generate dashboard warning count in the last 1 hour: //count(kql='isAlarmTriggered : true')-count(kql='isAlarmTriggered : true',shift='1h') But sometime…

---

## [IBM Cloud Metric Beat Module Contribution to the Beats Community](https://discuss.elastic.co/t/ibm-cloud-metric-beat-module-contribution-to-the-beats-community/327569)

<div class="topic-metadata">

**Author:** [@prashantaruadvi](https://discuss.elastic.co/u/prashantaruadvi)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 12:02pm UTC](https://discuss.elastic.co/t/ibm-cloud-metric-beat-module-contribution-to-the-beats-community/327569 "2023-03-20T12:02:55Z")

</div>

Hi Team, We have built the IBM cloud metric beat module, we would like to contribute back to the community, can you please help us what is right way to contribute, thanks in advance.

---

## [Nested fields are being indexed but are no longer searchable in Discover](https://discuss.elastic.co/t/nested-fields-are-being-indexed-but-are-no-longer-searchable-in-discover/327913)

<div class="topic-metadata">

**Author:** [@Raspberry](https://discuss.elastic.co/u/Raspberry)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 11:51am UTC](https://discuss.elastic.co/t/nested-fields-are-being-indexed-but-are-no-longer-searchable-in-discover/327913 "2023-03-20T11:51:52Z")

</div>

I have the following index mappings that I set up from PHP. "index" =\> "my-index-name", "body" =\> \[ "settings" =\> \[ "number\_of\_replicas" =\> 0, "number\_of\_shards" =\> 1, \], "mappings" =\> \[ …

---

## [Solr to Elasticsearh Migration Size Differance](https://discuss.elastic.co/t/solr-to-elasticsearh-migration-size-differance/327915)

<div class="topic-metadata">

**Author:** [@bilgicsin](https://discuss.elastic.co/u/bilgicsin)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 11:24am UTC](https://discuss.elastic.co/t/solr-to-elasticsearh-migration-size-differance/327915 "2023-03-20T11:24:21Z")

</div>

Hi Everyone, We have Solr and Elasticsearch in our company and we want to do a benchmark test to decide for buying extra license. We tried to transfer 4 gb Solr collection to an elasticsearch indice. We query the whole …

---

## [Unable to Tessellate shape (Polygon)](https://discuss.elastic.co/t/unable-to-tessellate-shape-polygon/327850)

<div class="topic-metadata">

**Author:** [@Shaheryar\_Mahmood](https://discuss.elastic.co/u/Shaheryar_Mahmood)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 11:00am UTC](https://discuss.elastic.co/t/unable-to-tessellate-shape-polygon/327850 "2023-03-20T11:00:06Z")

</div>

I'm having an issue while indexing the polygon below. What's wrong in the shape Elasticsearch version 7.7. {"error":{"root\_cause":\[{"type":"mapper\_parsing\_exception","reason":"failed to parse field \[location\] of type \[g…

---

## [Logstash multiple pipeline Openshift/kubernetes no traffic](https://discuss.elastic.co/t/logstash-multiple-pipeline-openshift-kubernetes-no-traffic/327776)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 10:52am UTC](https://discuss.elastic.co/t/logstash-multiple-pipeline-openshift-kubernetes-no-traffic/327776 "2023-03-20T10:52:59Z")

</div>

EDIT I finally get traffic into the cluster, but I only receive logs that have the string "FMC\_AUDIT\_LOG", nothing else get past. If I receive a syslog message with the string "test", it gets dropped. I want the message…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=597)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=599)
