# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=603

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 604

---

## [Upgrade to Java API Client](https://discuss.elastic.co/t/upgrade-to-java-api-client/327787)

<div class="topic-metadata">

**Author:** [@Michal\_Stefaniuk](https://discuss.elastic.co/u/Michal_Stefaniuk)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 10:11am UTC](https://discuss.elastic.co/t/upgrade-to-java-api-client/327787 "2023-03-16T10:11:52Z")

</div>

Hey guys. We are currently upgrading our ES in production from 7.16.1 to 7.17.7. This is a must for us, client's requirement leaves us no option but to upgrade to this version. Now having moved to 7.17.7 we were wonderi…

---

## [Elastic System watch continous alerts with Firing Status](https://discuss.elastic.co/t/elastic-system-watch-continous-alerts-with-firing-status/327838)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 9:58am UTC](https://discuss.elastic.co/t/elastic-system-watch-continous-alerts-with-firing-status/327838 "2023-03-16T09:58:57Z")

</div>

Hello Team , We are using ELK enterprise license 7.17 with 5 data node and 3 master nodes. We are getting continous alerts from one of the watcher (system watch) Could someone help to resolve this or how can we deact…

---

## [Monitoring index\_pressure](https://discuss.elastic.co/t/monitoring-index-pressure/327835)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 9:12am UTC](https://discuss.elastic.co/t/monitoring-index-pressure/327835 "2023-03-16T09:12:49Z")

</div>

Hi, I want to monitor index\_pressure (indexing\_pressure.memory.current.all\_in\_bytes) in Kibana. How can I add this graph? Thanks

---

## [Duplicate entries in elastic for the same message](https://discuss.elastic.co/t/duplicate-entries-in-elastic-for-the-same-message/327732)

<div class="topic-metadata">

**Author:** [@aks03](https://discuss.elastic.co/u/aks03)\
**Replies:** 3\
**Last updated:** [March 16, 2023, 8:58am UTC](https://discuss.elastic.co/t/duplicate-entries-in-elastic-for-the-same-message/327732 "2023-03-16T08:58:46Z")

</div>

Hey everyone, I have been trying to fix this error of duplicate entries into Elasticsearch through logstash Below is the example of the two entries Entry 1: { "\_index": "test-index", "\_type": "doc", "\_id": "3044350…

---

## [Is it possible to call a python script in logstash?](https://discuss.elastic.co/t/is-it-possible-to-call-a-python-script-in-logstash/327825)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 8:44am UTC](https://discuss.elastic.co/t/is-it-possible-to-call-a-python-script-in-logstash/327825 "2023-03-16T08:44:11Z")

</div>

Is it possible to call a python script in logstash pipeline? or only the RUBY language is supported?

---

## [How to create mass amounts of test data in elasticsearch / Kibana](https://discuss.elastic.co/t/how-to-create-mass-amounts-of-test-data-in-elasticsearch-kibana/327637)

<div class="topic-metadata">

**Author:** [@shelby](https://discuss.elastic.co/u/shelby)\
**Replies:** 5\
**Last updated:** [March 16, 2023, 8:35am UTC](https://discuss.elastic.co/t/how-to-create-mass-amounts-of-test-data-in-elasticsearch-kibana/327637 "2023-03-16T08:35:49Z")

</div>

0 I need to test some logic I have written in Kibana (Vega scripts). For this I require quite a bit of data to generate the graphs. I am currently doing this manually with statements such as: post /metrics-hardware-xx…

---

## [Is it required to always pass http request from public to server and then from server to actual backend api?](https://discuss.elastic.co/t/is-it-required-to-always-pass-http-request-from-public-to-server-and-then-from-server-to-actual-backend-api/327826)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 8:31am UTC](https://discuss.elastic.co/t/is-it-required-to-always-pass-http-request-from-public-to-server-and-then-from-server-to-actual-backend-api/327826 "2023-03-16T08:31:05Z")

</div>

Hi, I am developing a custom external plugin in React. Is it necessary to always call our backend service apis from plugin-server, and then call the plugin-server path from plugin-public? Do I always have to map respo…

---

## [401 after updating API Key role descriptors](https://discuss.elastic.co/t/401-after-updating-api-key-role-descriptors/327756)

<div class="topic-metadata">

**Author:** [@Mateusz\_Migala](https://discuss.elastic.co/u/Mateusz_Migala)\
**Replies:** 8\
**Last updated:** [March 16, 2023, 8:16am UTC](https://discuss.elastic.co/t/401-after-updating-api-key-role-descriptors/327756 "2023-03-16T08:16:40Z")

</div>

Hello, I'm trying to limit default privileges of the API key when it's being created. By default it's created by terraform with superuser account which I feel has too much access. We want to use the API\_Key to connect …

---

## [Filebeat - how to monitor inactivity](https://discuss.elastic.co/t/filebeat-how-to-monitor-inactivity/327819)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 7:38am UTC](https://discuss.elastic.co/t/filebeat-how-to-monitor-inactivity/327819 "2023-03-16T07:38:57Z")

</div>

I have an application (windows, 3rd party closed source) which is running as a service. Issue is, it stuck here and there and does nothing although the service is in "running" state. Is there any way how to monitor this…

---

## [我想在聚合汇总后，对聚合的bucket数据进行不响应，只是在响应时丢弃它](https://discuss.elastic.co/t/bucket/327818)

<div class="topic-metadata">

**Author:** [@lujiamingzZ](https://discuss.elastic.co/u/lujiamingzZ)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 7:37am UTC](https://discuss.elastic.co/t/bucket/327818 "2023-03-16T07:37:58Z")

</div>

只想要 sumtotal 结果，不想要bookingIdGroup.buckets结果，但是它对我汇总sumtotal有作用。 GET /booking\_order\_list\_v1/\_search { "from": 0, "size": 1, "aggs": { "bookingIdGroup": { "terms": { "field": "bookingId", …

---

## [Logstash - elapsed plugin](https://discuss.elastic.co/t/logstash-elapsed-plugin/326879)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 7:24am UTC](https://discuss.elastic.co/t/logstash-elapsed-plugin/326879 "2023-03-16T07:24:43Z")

</div>

How to install filter plugin (Elapsed) into Logstash, which is already running as a pod in K8s? If I run Logstash from the image docker.elastic.co/logstash/logstash:8.6.1, I can't use "Elapsed" filter, as it's not insta…

---

## [Elasticsearch Master CPU being used 100% at times](https://discuss.elastic.co/t/elasticsearch-master-cpu-being-used-100-at-times/327801)

<div class="topic-metadata">

**Author:** [@aayush\_kumar](https://discuss.elastic.co/u/aayush_kumar)\
**Replies:** 8\
**Last updated:** [March 16, 2023, 6:54am UTC](https://discuss.elastic.co/t/elasticsearch-master-cpu-being-used-100-at-times/327801 "2023-03-16T06:54:43Z")

</div>

My elasticsearch active master node CPU usage rises to 100% at times and remains the same for few minutes/hours and then comes downs to normal 4-5%. I ran the "hot\_threads" API against the node and found below threads t…

---

## [Possible to have {{#context.hits}}{{.}}{{/context/hits}} as array?](https://discuss.elastic.co/t/possible-to-have-context-hits-context-hits-as-array/327811)

<div class="topic-metadata">

**Author:** [@Maxim\_Afonin](https://discuss.elastic.co/u/Maxim_Afonin)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 6:43am UTC](https://discuss.elastic.co/t/possible-to-have-context-hits-context-hits-as-array/327811 "2023-03-16T06:43:42Z")

</div>

I am preparing payload for the webhook to be sent when alert is generated by the rule. By using the following mustache template I am able to iterate through several documents get values from them: { "content": "{{#co…

---

## [Canvas filters & Visiualisation Library](https://discuss.elastic.co/t/canvas-filters-visiualisation-library/327803)

<div class="topic-metadata">

**Author:** [@Matt\_Daniell](https://discuss.elastic.co/u/Matt_Daniell)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 4:59am UTC](https://discuss.elastic.co/t/canvas-filters-visiualisation-library/327803 "2023-03-16T04:59:53Z")

</div>

Hi there, I've made a bunch of visualizations in the library, and created a Canvas output. There are filters available in Canvas but I am unsure how to link a filter from either dropdown or time, to apply to a visualiza…

---

## [Script based Bulk Update is not parsing the entire document into \_source](https://discuss.elastic.co/t/script-based-bulk-update-is-not-parsing-the-entire-document-into-source/327800)

<div class="topic-metadata">

**Author:** [@AnushaTalluri](https://discuss.elastic.co/u/AnushaTalluri)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 4:52am UTC](https://discuss.elastic.co/t/script-based-bulk-update-is-not-parsing-the-entire-document-into-source/327800 "2023-03-16T04:52:00Z")

</div>

We have an elasticsearch index created in 6.8.23 version, and we used to use script based updates for the documents, which used to be working fine as expected. After upgrading the Elasticsearch version to 7.17, the scrip…

---

## [Kibana Alert Index Threshold and Log Threshold Host.ip Fields](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 4\
**Last updated:** [March 16, 2023, 1:47am UTC](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510 "2023-03-16T01:47:40Z")

</div>

Hi Everyone, i have question regarding Kibana's Alerting feature. As we know, we could use 'Group by' to include field into the alert message. But i have trouble to include host.ip field. Any Suggestion or workaround …

---

## [How to Export Specific Server System Data On Kibana?](https://discuss.elastic.co/t/how-to-export-specific-server-system-data-on-kibana/327712)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 2\
**Last updated:** [March 16, 2023, 1:42am UTC](https://discuss.elastic.co/t/how-to-export-specific-server-system-data-on-kibana/327712 "2023-03-16T01:42:05Z")

</div>

I have 2 or more servers in kibana dashboard, and I want to export system data for a specific server. how to export system data for specific server?

---

## [How to check length of an array field in logstash](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 8\
**Last updated:** [March 16, 2023, 1:12am UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625 "2023-03-16T01:12:14Z")

</div>

Hey everyone, can you give me some example about pipeline config to check if an array field is not null? and how i combine it with if else? i already made config like this and i want to create some if statement under…

---

## [Bertopic at Elastic?](https://discuss.elastic.co/t/bertopic-at-elastic/327793)

<div class="topic-metadata">

**Author:** [@Guilherme\_Martins](https://discuss.elastic.co/u/Guilherme_Martins)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 12:37am UTC](https://discuss.elastic.co/t/bertopic-at-elastic/327793 "2023-03-16T00:37:21Z")

</div>

Hello all , last month @alvaro\_ing asked about bertopic at elastic. Any new thoughts about it? @alvaro\_ing Any progress, wanna talk about it?

---

## [Fleet Policy Revision - View revision history](https://discuss.elastic.co/t/fleet-policy-revision-view-revision-history/327791)

<div class="topic-metadata">

**Author:** [@abusiddique](https://discuss.elastic.co/u/abusiddique)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 11:41pm UTC](https://discuss.elastic.co/t/fleet-policy-revision-view-revision-history/327791 "2023-03-15T23:41:20Z")

</div>

Hi I want to check who changed/ modified fleet integration policy, As we can see revision for all changes but am not able to find history for each change Can someone help me how to check revision logs with user and mod…

---

## [How to change the data directory of a node in a cluster?](https://discuss.elastic.co/t/how-to-change-the-data-directory-of-a-node-in-a-cluster/327779)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 2\
**Last updated:** [March 15, 2023, 10:27pm UTC](https://discuss.elastic.co/t/how-to-change-the-data-directory-of-a-node-in-a-cluster/327779 "2023-03-15T22:27:28Z")

</div>

I have a cluster of 8 nodes. This is an "under development but with real data" kind of project (the worst type of project) and I see that I will soon have problems with disk space of the default data store. path: data…

---

## [Elasticsearch 8 Client is giving error The following method did not exist: 'org.elasticsearch.client.RequestOptions$Builder org.elasticsearch.client.RequestOptions$Builder.removeHeader(java.lang.String)'](https://discuss.elastic.co/t/elasticsearch-8-client-is-giving-error-the-following-method-did-not-exist-org-elasticsearch-client-requestoptions-builder-org-elasticsearch-client-requestoptions-builder-removeheader-java-lang-string/327762)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 1\
**Last updated:** [March 15, 2023, 9:50pm UTC](https://discuss.elastic.co/t/elasticsearch-8-client-is-giving-error-the-following-method-did-not-exist-org-elasticsearch-client-requestoptions-builder-org-elasticsearch-client-requestoptions-builder-removeheader-java-lang-string/327762 "2023-03-15T21:50:31Z")

</div>

Elasticsearch 8 is expecting some class RequestOptions which is present in elasticsearch-rest-client-7.6.2.jar. How I can resolve this error done exactly in a way mentioned in elastic8 docs @Bean public ElasticsearchCl…

---

## [Default Sorting Criteria after custom criteria](https://discuss.elastic.co/t/default-sorting-criteria-after-custom-criteria/327207)

<div class="topic-metadata">

**Author:** [@MrIacono](https://discuss.elastic.co/u/MrIacono)\
**Replies:** 3\
**Last updated:** [March 15, 2023, 6:51pm UTC](https://discuss.elastic.co/t/default-sorting-criteria-after-custom-criteria/327207 "2023-03-15T18:51:09Z")

</div>

Hi, If I have these two sorting criteria: "\_score": "desc" "date": "desc" And the query result consists of two documents with same date and same score, What's the third defult criteria? Thank you, Manuel

---

## [Logstash date filter truncating milliseconds when they are set to 000](https://discuss.elastic.co/t/logstash-date-filter-truncating-milliseconds-when-they-are-set-to-000/327770)

<div class="topic-metadata">

**Author:** [@Samuel\_Delepiere](https://discuss.elastic.co/u/Samuel_Delepiere)\
**Replies:** 2\
**Last updated:** [March 15, 2023, 6:05pm UTC](https://discuss.elastic.co/t/logstash-date-filter-truncating-milliseconds-when-they-are-set-to-000/327770 "2023-03-15T18:05:44Z")

</div>

We use the following filter date { match =\> \[ "timestampInUtc" , "UNIX\_MS" \] target =\> "timestamp" timezone =\> "UTC" } This works correctly except when the milliseconds are set to 000. In that case, they get trun…

---

## [Metricbeat - unable to retrieve license information from license server no available connection](https://discuss.elastic.co/t/metricbeat-unable-to-retrieve-license-information-from-license-server-no-available-connection/327113)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 5\
**Last updated:** [March 15, 2023, 5:50pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-retrieve-license-information-from-license-server-no-available-connection/327113 "2023-03-15T17:50:05Z")

</div>

This group has always been helpful and hopefully they can help me again. We created a new cluster and installed 8.6 We have a 3 nodes cluster for Elasticsearch, 2 Logstash and 2 Kibana. We completed the configuring in…

---

## [Deploy Fleet server using API](https://discuss.elastic.co/t/deploy-fleet-server-using-api/326951)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 9\
**Last updated:** [March 15, 2023, 3:55pm UTC](https://discuss.elastic.co/t/deploy-fleet-server-using-api/326951 "2023-03-15T15:55:56Z")

</div>

Hi, I am trying to create fully automated script for SIEM deployment. There is one issue. I am not able to install fleet server. I want it to be fully automated no UI interaction. So first i need to create policy using …

---

## [Terraform, Traffic Filters and Kibana](https://discuss.elastic.co/t/terraform-traffic-filters-and-kibana/327767)

<div class="topic-metadata">

**Author:** [@tensor](https://discuss.elastic.co/u/tensor)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 3:48pm UTC](https://discuss.elastic.co/t/terraform-traffic-filters-and-kibana/327767 "2023-03-15T15:48:58Z")

</div>

Hi! We have been successfully using Terraform to set up Elasticcloud instances, and using traffic filtering to allow only access via private link to our own Azure serup - almost too successful, as it turns out, as it me…

---

## [Insert in nodejs is slow](https://discuss.elastic.co/t/insert-in-nodejs-is-slow/327705)

<div class="topic-metadata">

**Author:** [@HF\_Mohammad](https://discuss.elastic.co/u/HF_Mohammad)\
**Replies:** 4\
**Last updated:** [March 15, 2023, 3:19pm UTC](https://discuss.elastic.co/t/insert-in-nodejs-is-slow/327705 "2023-03-15T15:19:45Z")

</div>

This is my code: for (let i = 0; i \< 500; i++) { await client.index({ index: 'user', body: { name: 'mohammad', type: 'mobile' } }) } This code take time about 3 second to fin…

---

## [Ingest pipeline created for filebeat log using grok pattern,but unable to run in dev tools](https://discuss.elastic.co/t/ingest-pipeline-created-for-filebeat-log-using-grok-pattern-but-unable-to-run-in-dev-tools/327660)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [March 15, 2023, 11:43am UTC](https://discuss.elastic.co/t/ingest-pipeline-created-for-filebeat-log-using-grok-pattern-but-unable-to-run-in-dev-tools/327660 "2023-03-15T11:43:12Z")

</div>

Hello All, I'm successfully getting output of my log pattern using grok pattern,but when trying to create log ingest pipeline that can be used in template later,I'm getting exception while running the ingest pipeline in…

---

## [Logs Deprecaction](https://discuss.elastic.co/t/logs-deprecaction/327760)

<div class="topic-metadata">

**Author:** [@LeonardoCord](https://discuss.elastic.co/u/LeonardoCord)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 2:22pm UTC](https://discuss.elastic.co/t/logs-deprecaction/327760 "2023-03-15T14:22:01Z")

</div>

Hola Me esta sacando este error y quisiera saber como podria solucionarlo this request accesses system indices: \[.apm-agent-configuration, .apm-custom-link, .async-search, .fleet-enrollment-api-keys-7, .fleet-policies-…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=602)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=604)
