# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=604

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 605

---

## [Do we have lookup similar to Splunk lookup](https://discuss.elastic.co/t/do-we-have-lookup-similar-to-splunk-lookup/327550)

<div class="topic-metadata">

**Author:** [@Saurabhpandey](https://discuss.elastic.co/u/Saurabhpandey)\
**Replies:** 5\
**Last updated:** [March 15, 2023, 2:19pm UTC](https://discuss.elastic.co/t/do-we-have-lookup-similar-to-splunk-lookup/327550 "2023-03-15T14:19:02Z")

</div>

Do we have lookup similar to Splunk lookup

---

## [Best Web crawler to index data to elasticsearch](https://discuss.elastic.co/t/best-web-crawler-to-index-data-to-elasticsearch/327759)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 1:55pm UTC](https://discuss.elastic.co/t/best-web-crawler-to-index-data-to-elasticsearch/327759 "2023-03-15T13:55:05Z")

</div>

Hi Team, As elastic appsearch supports to crawl websites which uses basic auth alone. Any suggestions which web crawler we can use with elasticsearch to crawl the SSO, SAML, NTLM protected websites? Thanks, Disha

---

## [Mapping directly in Logstash Pipeline](https://discuss.elastic.co/t/mapping-directly-in-logstash-pipeline/327757)

<div class="topic-metadata">

**Author:** [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Replies:** 2\
**Last updated:** [March 15, 2023, 1:49pm UTC](https://discuss.elastic.co/t/mapping-directly-in-logstash-pipeline/327757 "2023-03-15T13:49:24Z")

</div>

Hi Guys, since I didn't find anything helpful on the net - I need to ask here: Is it possible to do the Mapping of fields directly in the Logstash Pipeline - either in the Input or in the Filter section? As I do have …

---

## [Actual use of join type field](https://discuss.elastic.co/t/actual-use-of-join-type-field/327627)

<div class="topic-metadata">

**Author:** [@SheetalM](https://discuss.elastic.co/u/SheetalM)\
**Replies:** 5\
**Last updated:** [March 15, 2023, 12:39pm UTC](https://discuss.elastic.co/t/actual-use-of-join-type-field/327627 "2023-03-15T12:39:28Z")

</div>

Hello Experts, We have a use case with a one-to-many relation scenario where number of documents of a child type are huge for one parent type of document. Something similar to a log store where all the events/messages f…

---

## [Logstash ruby filter hash class exception](https://discuss.elastic.co/t/logstash-ruby-filter-hash-class-exception/327747)

<div class="topic-metadata">

**Author:** [@onuruzun](https://discuss.elastic.co/u/onuruzun)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 11:47am UTC](https://discuss.elastic.co/t/logstash-ruby-filter-hash-class-exception/327747 "2023-03-15T11:47:29Z")

</div>

I tried to get the difference between these two JSON objects coming from JDBC in Logstash. example JDBC JSON: before = '{"heroes":\[{"id":1,"name":"pudge"},{"id":2,"name":"slark"},{"id":3,"name":"techies"}\]}' after = '…

---

## [What's the meaning of rally operations when starting a track](https://discuss.elastic.co/t/whats-the-meaning-of-rally-operations-when-starting-a-track/325852)

<div class="topic-metadata">

**Author:** [@marone](https://discuss.elastic.co/u/marone)\
**Replies:** 6\
**Last updated:** [March 15, 2023, 11:39am UTC](https://discuss.elastic.co/t/whats-the-meaning-of-rally-operations-when-starting-a-track/325852 "2023-03-15T11:39:57Z")

</div>

Hello, It's been several times working with rally and every time I feel like it's hard to understand and use. I started an http\_logs track against a cluster, and can't find the meaning of the following operations that r…

---

## [Custom Plugin: EuiToast is being displayed as a section of pagebody rather than](https://discuss.elastic.co/t/custom-plugin-euitoast-is-being-displayed-as-a-section-of-pagebody-rather-than/327744)

<div class="topic-metadata">

**Author:** [@cyrildaniel](https://discuss.elastic.co/u/cyrildaniel)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 10:22am UTC](https://discuss.elastic.co/t/custom-plugin-euitoast-is-being-displayed-as-a-section-of-pagebody-rather-than/327744 "2023-03-15T10:22:29Z")

</div>

When displaying the EuiToast it comes below as a bottom section of the EuiPageBody tag and does not appear as expected. observed output =\> expected output=\>

---

## [Upgrade from 7.x to 8.x requires multi upgrades?](https://discuss.elastic.co/t/upgrade-from-7-x-to-8-x-requires-multi-upgrades/327408)

<div class="topic-metadata">

**Author:** [@atdc12](https://discuss.elastic.co/u/atdc12)\
**Replies:** 5\
**Last updated:** [March 15, 2023, 9:36am UTC](https://discuss.elastic.co/t/upgrade-from-7-x-to-8-x-requires-multi-upgrades/327408 "2023-03-15T09:36:38Z")

</div>

We have a few production sites running ES 7.16 and would like to upgrade to 8.6: upgrade will be done with full cluster restart all indices were created under ES 7.x we have checked Upgrade Assistant on ES 7.16 and con…

---

## [Elasticsearch continuously on yellow Status - Unassigned Shards](https://discuss.elastic.co/t/elasticsearch-continuously-on-yellow-status-unassigned-shards/327742)

<div class="topic-metadata">

**Author:** [@Apostolos\_Koutoulas](https://discuss.elastic.co/u/Apostolos_Koutoulas)\
**Replies:** 1\
**Last updated:** [March 15, 2023, 9:34am UTC](https://discuss.elastic.co/t/elasticsearch-continuously-on-yellow-status-unassigned-shards/327742 "2023-03-15T09:34:13Z")

</div>

Hello all! Hope you are doing well Cluster status in yellow with unassigned replica shards Elasticsearch version 6.8.23 Cluster status: \[root@d38-pan020 ~\]# es\_cluster.sh health { "cluster\_name" : "\_\_pan\_cluster\_\_…

---

## [How can I mark root object as null](https://discuss.elastic.co/t/how-can-i-mark-root-object-as-null/327719)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 11\
**Last updated:** [March 15, 2023, 9:02am UTC](https://discuss.elastic.co/t/how-can-i-mark-root-object-as-null/327719 "2023-03-15T09:02:34Z")

</div>

So my mapping looks like this. My query is I would like to mark the custom\_field property as null as a root \[NULL\_VALUES IN ELASTIC SEARCH\] (null\_value | Elasticsearch Guide \[8.6\] | Elastic) "custom\_field":{ …

---

## [Data not ingested into master node](https://discuss.elastic.co/t/data-not-ingested-into-master-node/327649)

<div class="topic-metadata">

**Author:** [@truekonrads](https://discuss.elastic.co/u/truekonrads)\
**Replies:** 6\
**Last updated:** [March 15, 2023, 7:57am UTC](https://discuss.elastic.co/t/data-not-ingested-into-master-node/327649 "2023-03-15T07:57:19Z")

</div>

Hello, I have a three node cluster set up with no explicitly defined roles for each nodes. I can see by disk usage and index document count that no data was ingested into master node - only non-master nodes have data on…

---

## [Elasticsearch not receiving Metricbeat data completely](https://discuss.elastic.co/t/elasticsearch-not-receiving-metricbeat-data-completely/327723)

<div class="topic-metadata">

**Author:** [@priti](https://discuss.elastic.co/u/priti)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 6:42am UTC](https://discuss.elastic.co/t/elasticsearch-not-receiving-metricbeat-data-completely/327723 "2023-03-15T06:42:04Z")

</div>

After install metricbeat and enable CPU,memory,disk, proccess enable only we are receiving process related data. Please guide how to troubleshoot , why CPU , memory and disk data not coming.

---

## [404 Error installing Filebeat on Debian Linux via apt](https://discuss.elastic.co/t/404-error-installing-filebeat-on-debian-linux-via-apt/327701)

<div class="topic-metadata">

**Author:** [@michael.jarvis](https://discuss.elastic.co/u/michael.jarvis)\
**Replies:** 1\
**Last updated:** [March 15, 2023, 2:36am UTC](https://discuss.elastic.co/t/404-error-installing-filebeat-on-debian-linux-via-apt/327701 "2023-03-15T02:36:35Z")

</div>

Hello, I am trying to install filebeat on some Debian Linux devices, using the instructions from this link. Unfortunately, the URL provided on that page (https://artifacts.elastic.co/packages/8.x/apt) is not working. Am…

---

## [Kibana Audit Log - Alerting Rule Deletion](https://discuss.elastic.co/t/kibana-audit-log-alerting-rule-deletion/327645)

<div class="topic-metadata">

**Author:** [@wanch](https://discuss.elastic.co/u/wanch)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 9:59am UTC](https://discuss.elastic.co/t/kibana-audit-log-alerting-rule-deletion/327645 "2023-03-14T09:59:51Z")

</div>

Hi, I have a question regarding Kibana's audit logging and the deletion of alerting rules. Below is the audit logs I got for deleting an alerting rule in Kibana UI: { "event": { "action": "http\_request", "ca…

---

## [How to pass multiple indies to ElasticSearch UI ElasticsearchAPIConnector](https://discuss.elastic.co/t/how-to-pass-multiple-indies-to-elasticsearch-ui-elasticsearchapiconnector/327707)

<div class="topic-metadata">

**Author:** [@Sheng111](https://discuss.elastic.co/u/Sheng111)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 12:08am UTC](https://discuss.elastic.co/t/how-to-pass-multiple-indies-to-elasticsearch-ui-elasticsearchapiconnector/327707 "2023-03-15T00:08:35Z")

</div>

Hi there, I am using Search UI with Elasticsearch, wondering how to pass multiple indies to config? I got requirement is build a global search box, so users can search multiple indies data based on different attribute …

---

## [Runtime field painless script to extract from a field](https://discuss.elastic.co/t/runtime-field-painless-script-to-extract-from-a-field/327696)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 1\
**Last updated:** [March 15, 2023, 12:05am UTC](https://discuss.elastic.co/t/runtime-field-painless-script-to-extract-from-a-field/327696 "2023-03-15T00:05:51Z")

</div>

Hi Have a field named path with content "first\_part/second\_part/third\_part" and what to extract the first\_part with a painless script Thanks

---

## [How to integrate my logs to Elastic Observability](https://discuss.elastic.co/t/how-to-integrate-my-logs-to-elastic-observability/326233)

<div class="topic-metadata">

**Author:** [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 10:01pm UTC](https://discuss.elastic.co/t/how-to-integrate-my-logs-to-elastic-observability/326233 "2023-03-14T22:01:05Z")

</div>

How can I configure my logs from SQL Server on Elastic Search server( is already exists). How can I integrate the logs? Pleas let me know the steps.

---

## [Useragent filter not working as expected after enabling ECS](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662)

<div class="topic-metadata">

**Author:** [@flalar](https://discuss.elastic.co/u/flalar)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 8:13pm UTC](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662 "2023-03-14T20:13:13Z")

</div>

We're having trouble with the useragent filter not adding the data to the document sent to Elasticsearch or stdout. Seems this happend after enabling support for ECS. Upgrading from Logstash 7.17.9 to 8.6.2 did not solv…

---

## [Missing headers even with include\_headers (Csv codec plugin) set to true](https://discuss.elastic.co/t/missing-headers-even-with-include-headers-csv-codec-plugin-set-to-true/327555)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 5\
**Last updated:** [March 14, 2023, 4:34pm UTC](https://discuss.elastic.co/t/missing-headers-even-with-include-headers-csv-codec-plugin-set-to-true/327555 "2023-03-14T16:34:56Z")

</div>

Hello World! per Csv codec plugin | Logstash Reference \[7.17\] | Elastic I'm set include\_headers flag to value true, yet even though headers gets included into output on first run, at later time on re-run schedule of ve…

---

## [Logstash S3 input slow ingestion](https://discuss.elastic.co/t/logstash-s3-input-slow-ingestion/327653)

<div class="topic-metadata">

**Author:** [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Replies:** 5\
**Last updated:** [March 14, 2023, 3:55pm UTC](https://discuss.elastic.co/t/logstash-s3-input-slow-ingestion/327653 "2023-03-14T15:55:12Z")

</div>

I have setup where logstash reads Kubernetes logs from 20 different buckets and send them to ELK. The logs seems to be coming 3-5 minutes late to ELK. The logstash running docker on VM with 31GB Xms/Xmx. I am using one …

---

## [Unable to load data from filebeat using input of AWS S3](https://discuss.elastic.co/t/unable-to-load-data-from-filebeat-using-input-of-aws-s3/327268)

<div class="topic-metadata">

**Author:** [@vivekd](https://discuss.elastic.co/u/vivekd)\
**Replies:** 4\
**Last updated:** [March 14, 2023, 3:40pm UTC](https://discuss.elastic.co/t/unable-to-load-data-from-filebeat-using-input-of-aws-s3/327268 "2023-03-14T15:40:29Z")

</div>

Hi Team, We are unable to load data from filebeat using input of AWS S3. We have followed the below article for setting the filebeat configuration. Post configuration of filebeat, Please let us know on how to create …

---

## [VxLAN packet decription - packetbeat](https://discuss.elastic.co/t/vxlan-packet-decription-packetbeat/327545)

<div class="topic-metadata">

**Author:** [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Replies:** 1\
**Last updated:** [March 14, 2023, 3:01pm UTC](https://discuss.elastic.co/t/vxlan-packet-decription-packetbeat/327545 "2023-03-14T15:01:06Z")

</div>

Hello, I have the same issue like Docker overlay networks I'm using AWS mirroring to send traffic from one Network Interface to another EC2 instance where I have installed ES. AWS is using VXLAN and sends the traffic o…

---

## [Dev console suddenly just a blank canvas](https://discuss.elastic.co/t/dev-console-suddenly-just-a-blank-canvas/327596)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [March 14, 2023, 2:17pm UTC](https://discuss.elastic.co/t/dev-console-suddenly-just-a-blank-canvas/327596 "2023-03-14T14:17:15Z")

</div>

Suddenly one day my Dev Tools Console v.8.6.1 on top of a v.8.6.1 cluster is just a blank canvas, don't why, hints appreciated, TIA! Was a while ago playing with ldap/AD authentication but reverted it again as basic lic…

---

## [Datastream snapshot strategy](https://discuss.elastic.co/t/datastream-snapshot-strategy/327672)

<div class="topic-metadata">

**Author:** [@YP30](https://discuss.elastic.co/u/YP30)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 1:57pm UTC](https://discuss.elastic.co/t/datastream-snapshot-strategy/327672 "2023-03-14T13:57:04Z")

</div>

Hello! We're planning to set up a cluster and use a datastream to ingest our custom logs into elasticsearch. Current setup (spread out over 3 ftServers): 3x master nodes (4vCPU, 12GB RAM) 3x data nodes (4vCPU, 64GB R…

---

## [Building an index for faster search](https://discuss.elastic.co/t/building-an-index-for-faster-search/326301)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 1:49pm UTC](https://discuss.elastic.co/t/building-an-index-for-faster-search/326301 "2023-03-14T13:49:35Z")

</div>

Hi everyone, I have one question. How should I build my index to reduce the time of searching? In my case, using aggregations for distinct search really increases the time of searching.

---

## [X509: certificate signed by unknown authority](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/327572)

<div class="topic-metadata">

**Author:** [@AbbysS](https://discuss.elastic.co/u/AbbysS)\
**Replies:** 8\
**Last updated:** [March 14, 2023, 1:48pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/327572 "2023-03-14T13:48:51Z")

</div>

Hi everyone, I'm new on the forum. I'm little confuse, i try to learn many tutorials on fleet server / agent but i don't know how i can create my own certificate to deploy in production. I try to learn the ELK tutoria…

---

## [Service Metricbeat Suddenly Stop After Loaded Dashboard](https://discuss.elastic.co/t/service-metricbeat-suddenly-stop-after-loaded-dashboard/327622)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 3\
**Last updated:** [March 14, 2023, 1:44pm UTC](https://discuss.elastic.co/t/service-metricbeat-suddenly-stop-after-loaded-dashboard/327622 "2023-03-14T13:44:12Z")

</div>

After i command .\\metricbeat setup my metricbeat service still running, but after loaded to dashboard to kibana, my metricbeat service suddenly stop, i don't know why. my config metricbeat.yml it's okay my output it's …

---

## [Indexing script with parameters into percolation field breaks in 8.5](https://discuss.elastic.co/t/indexing-script-with-parameters-into-percolation-field-breaks-in-8-5/327667)

<div class="topic-metadata">

**Author:** [@cehj](https://discuss.elastic.co/u/cehj)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 1:07pm UTC](https://discuss.elastic.co/t/indexing-script-with-parameters-into-percolation-field-breaks-in-8-5/327667 "2023-03-14T13:07:26Z")

</div>

When indexing into a percolation field on a document, we submit something like: { "bool": { "filter": \[ { "script": { "script": { "sour…

---

## [Filebeat loses first lines when file rotated](https://discuss.elastic.co/t/filebeat-loses-first-lines-when-file-rotated/327655)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 12:28pm UTC](https://discuss.elastic.co/t/filebeat-loses-first-lines-when-file-rotated/327655 "2023-03-14T12:28:58Z")

</div>

We have discovered that filebeat loses first lines when file rotated. For example we use the following config to get auditbeat logs and when file rotated (auditbeat restarted) we see that first lines missing (written in…

---

## [First search Request on Elasticsearch is slow](https://discuss.elastic.co/t/first-search-request-on-elasticsearch-is-slow/327560)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 3\
**Last updated:** [March 14, 2023, 11:41am UTC](https://discuss.elastic.co/t/first-search-request-on-elasticsearch-is-slow/327560 "2023-03-14T11:41:33Z")

</div>

Hello, Having an issue on elasticsearch, my first request to search in elastic is slow. Once any term gets searched then it becomes fast. I have researched about this and get to know the solution is to change the index …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=603)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=605)
