# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=609

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 610

---

## [Not able to send add logstash output in Elastic Agent setup](https://discuss.elastic.co/t/not-able-to-send-add-logstash-output-in-elastic-agent-setup/326726)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 7\
**Last updated:** [March 9, 2023, 12:46pm UTC](https://discuss.elastic.co/t/not-able-to-send-add-logstash-output-in-elastic-agent-setup/326726 "2023-03-09T12:46:44Z")

</div>

I have created Fleet output as Logstash but while assigning the output to the agent, I'm getting only Elasticsearch output (default). But I want to send the data from Elastic Agent to Logstash. I have followed this link…

---

## [Convert Keyword to object data type](https://discuss.elastic.co/t/convert-keyword-to-object-data-type/327355)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 12:23pm UTC](https://discuss.elastic.co/t/convert-keyword-to-object-data-type/327355 "2023-03-09T12:23:34Z")

</div>

Hi Team I want to convert a keyword data type field to object data type, i know we can do by editing the data stream but as i am using a ingest pipeline which is creating a the field in keyword data type so wanted to kno…

---

## [How to load CSV data to already created and existing Index in Kibana?](https://discuss.elastic.co/t/how-to-load-csv-data-to-already-created-and-existing-index-in-kibana/326979)

<div class="topic-metadata">

**Author:** [@hitnalli\_praveen](https://discuss.elastic.co/u/hitnalli_praveen)\
**Replies:** 8\
**Last updated:** [March 9, 2023, 11:55am UTC](https://discuss.elastic.co/t/how-to-load-csv-data-to-already-created-and-existing-index-in-kibana/326979 "2023-03-09T11:55:07Z")

</div>

I've a unique requirement and trying few new things. My main objective is to display scanned data from Tenable Nessus (showing total count of scanned vulnerabilities - Critical, High and Medium) on to Kibana Dashboard af…

---

## [Filebeat for AWS Cloudwatch does not support timestamps with milliseconds](https://discuss.elastic.co/t/filebeat-for-aws-cloudwatch-does-not-support-timestamps-with-milliseconds/327338)

<div class="topic-metadata">

**Author:** [@Tomas\_Mocek](https://discuss.elastic.co/u/Tomas_Mocek)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:59am UTC](https://discuss.elastic.co/t/filebeat-for-aws-cloudwatch-does-not-support-timestamps-with-milliseconds/327338 "2023-03-09T08:59:08Z")

</div>

Hi, we are using AWS Filebeat CloudWatch input, and everything works as expected, however, the logs are fetched without milliseconds precision. I believe this is caused because of this code, which cuts milliseconds ret…

---

## [Get top 10 data for each group](https://discuss.elastic.co/t/get-top-10-data-for-each-group/327349)

<div class="topic-metadata">

**Author:** [@Shishir\_Kumar2](https://discuss.elastic.co/u/Shishir_Kumar2)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 11:25am UTC](https://discuss.elastic.co/t/get-top-10-data-for-each-group/327349 "2023-03-09T11:25:39Z")

</div>

Requirement is to get top 10 data for each group. I created below index and tried using few combination of aggregation query but it does not get desired result. Index Definition PUT /poc\_agg { "settings": { "numb…

---

## [Vega kibana tooltip](https://discuss.elastic.co/t/vega-kibana-tooltip/327093)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 11:12am UTC](https://discuss.elastic.co/t/vega-kibana-tooltip/327093 "2023-03-09T11:12:05Z")

</div>

Hello everyone, I want to adjust kibana vega tooltip, make it smaller and modify its fontsize, its position, etc Meaning that I want to modify the styling of the vega Kibana tooltip from this to something like this …

---

## [Logstash stopped processing logs after enabling minimal security](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 11:02am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232 "2023-03-09T11:02:25Z")

</div>

I was wondering what should be configured on logstash side after enabling basic on Elasticsearch node? I set x.pack.security.enabled to true on elasticsearch.yml, generated passwords for the cluster users, added the ki…

---

## [Configuration issues - Filebeat for shipping messages from a Kafka topic to Elasticsearch](https://discuss.elastic.co/t/configuration-issues-filebeat-for-shipping-messages-from-a-kafka-topic-to-elasticsearch/327315)

<div class="topic-metadata">

**Author:** [@dvoracek-martin](https://discuss.elastic.co/u/dvoracek-martin)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 1:04am UTC](https://discuss.elastic.co/t/configuration-issues-filebeat-for-shipping-messages-from-a-kafka-topic-to-elasticsearch/327315 "2023-03-09T01:04:01Z")

</div>

Hi! I'd like to have Filebeat set up the way that it would consume messages from Kafka topic and then send them to Elasticsearch. Is there a way, how to set it all up in docker-compose? I could register Logstash as a Kaf…

---

## [Metricbeat not sending data or Elasticsearch not recieving (?)](https://discuss.elastic.co/t/metricbeat-not-sending-data-or-elasticsearch-not-recieving/326863)

<div class="topic-metadata">

**Author:** [@enigmatic](https://discuss.elastic.co/u/enigmatic)\
**Replies:** 12\
**Last updated:** [March 9, 2023, 9:06am UTC](https://discuss.elastic.co/t/metricbeat-not-sending-data-or-elasticsearch-not-recieving/326863 "2023-03-09T09:06:34Z")

</div>

Hi Guys, hope you can help me out in the following. i'm using: Elasticseearch 8.4.3 metricbeat 8.4.3 kubernetes / AWS EKS I've deployed metricbeat in a kubernetes cluster. it gathering all sort of data and i also wa…

---

## [Elasticsearch Setup Custom Index and Write Issue](https://discuss.elastic.co/t/elasticsearch-setup-custom-index-and-write-issue/327332)

<div class="topic-metadata">

**Author:** [@elk-siwm](https://discuss.elastic.co/u/elk-siwm)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:28am UTC](https://discuss.elastic.co/t/elasticsearch-setup-custom-index-and-write-issue/327332 "2023-03-09T08:28:45Z")

</div>

Elasticsearch get logs via filebeats shipper default settings. All custom index settings were configured on /etc/filebeats/filebeats.yml file. This is my configuration file: output.elasticsearch: # Array of hosts to c…

---

## [Sorting by ranges in old (not Lens) visualizations](https://discuss.elastic.co/t/sorting-by-ranges-in-old-not-lens-visualizations/327176)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 8:12am UTC](https://discuss.elastic.co/t/sorting-by-ranges-in-old-not-lens-visualizations/327176 "2023-03-09T08:12:11Z")

</div>

Hi! I have a set of old visualizations in Kibana, built not in Lens but in the Legacy visualization tool. They are donut charts split in slices by some custom defined numerical ranges. The problem is that when I built …

---

## [Request body is required Error encountered while performing reindexing task](https://discuss.elastic.co/t/request-body-is-required-error-encountered-while-performing-reindexing-task/327327)

<div class="topic-metadata">

**Author:** [@Chandan1](https://discuss.elastic.co/u/Chandan1)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 7:58am UTC](https://discuss.elastic.co/t/request-body-is-required-error-encountered-while-performing-reindexing-task/327327 "2023-03-09T07:58:37Z")

</div>

Hello, I am trying to reindex the index with reindex api by providing a proper request body with the Source and Destination Index details and still iam receiving Request body is required Error. Please find below Reques…

---

## [Split a field value in a Visualization](https://discuss.elastic.co/t/split-a-field-value-in-a-visualization/327303)

<div class="topic-metadata">

**Author:** [@Jonathan\_Fernandez](https://discuss.elastic.co/u/Jonathan_Fernandez)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 7:37am UTC](https://discuss.elastic.co/t/split-a-field-value-in-a-visualization/327303 "2023-03-09T07:37:53Z")

</div>

Hi everyone, Currently I am trying to split the value of a field (an email) by the '@' in an "Aggregation Based - Data Table" visualization at Kibana, so the expected output for an email field with value name@domain.com …

---

## [Monitoring Metricbeat On Kibana](https://discuss.elastic.co/t/monitoring-metricbeat-on-kibana/327244)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 5\
**Last updated:** [March 9, 2023, 6:15am UTC](https://discuss.elastic.co/t/monitoring-metricbeat-on-kibana/327244 "2023-03-09T06:15:15Z")

</div>

Hi all, I use windows server 2019 to monitor my laptop's data system, but after I do the .\\metricbeat setup, after Index setup finished. Loading dashboards (Kibana must be running and reachable) Loaded dashboards I chec…

---

## [\[plugin-development\] java.security.AccessControlException](https://discuss.elastic.co/t/plugin-development-java-security-accesscontrolexception/327326)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 7:10am UTC](https://discuss.elastic.co/t/plugin-development-java-security-accesscontrolexception/327326 "2023-03-09T07:10:37Z")

</div>

Vesion: Elasticsearch 8.6.2 (My plugin is working on Elasticsearch7.6.0 ) I am developing a plugin to let ES filter through Redis data. So I import Jedis package in my code. But when ES starts, I get this error. Her…

---

## [Cannot use https on elasticsearch server](https://discuss.elastic.co/t/cannot-use-https-on-elasticsearch-server/327148)

<div class="topic-metadata">

**Author:** [@dityudha](https://discuss.elastic.co/u/dityudha)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 6:53am UTC](https://discuss.elastic.co/t/cannot-use-https-on-elasticsearch-server/327148 "2023-03-09T06:53:53Z")

</div>

Hello there, Right now i'm configuring elastic security with https based on article: I'm getting trouble after generate http.p12 certificate. Error like this: elastic server already up, but still not secured el…

---

## [\[esrally\] what cause difference of latency and service time?, what is proper way of custom parameter](https://discuss.elastic.co/t/esrally-what-cause-difference-of-latency-and-service-time-what-is-proper-way-of-custom-parameter/327317)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 6:15am UTC](https://discuss.elastic.co/t/esrally-what-cause-difference-of-latency-and-service-time-what-is-proper-way-of-custom-parameter/327317 "2023-03-09T06:15:47Z")

</div>

Hello. i just saw strange stuff when im trying to do single shard test. here is my metric it's error rate is 0.01% and its service time looks reasonable to service, but latency is really bad. the question is what ca…

---

## [Logstash compliance with RFC5425 and RFC5426](https://discuss.elastic.co/t/logstash-compliance-with-rfc5425-and-rfc5426/327243)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 3:13am UTC](https://discuss.elastic.co/t/logstash-compliance-with-rfc5425-and-rfc5426/327243 "2023-03-09T03:13:49Z")

</div>

From the official logstash docs , the syslog output plugin of logstash supports any of RFC5424, RFC3164 formats only. Syslog output plugin | Logstash Reference \[8.6\] | Elastic Does logstash syslog output plugin comply w…

---

## [Shards Rebalancing Issue Version 7](https://discuss.elastic.co/t/shards-rebalancing-issue-version-7/327107)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 10:57pm UTC](https://discuss.elastic.co/t/shards-rebalancing-issue-version-7/327107 "2023-03-08T22:57:05Z")

</div>

ES version 7, Shards are not equally distributing, one data node has more shards, rest of the two data nodes are less number of shards and low disk used. Replication set to "1" on all indices Please let me know if any …

---

## [Enrollment in Fleet works but agent don't receive its configuration](https://discuss.elastic.co/t/enrollment-in-fleet-works-but-agent-dont-receive-its-configuration/325636)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 9:13pm UTC](https://discuss.elastic.co/t/enrollment-in-fleet-works-but-agent-dont-receive-its-configuration/325636 "2023-03-08T21:13:29Z")

</div>

:frowning: am running a fresh docker based instance of elasticsearch, kibana and fleet-server (all in separate containers). Now I am starting a fresh elastic-agent container which enrolls in fleet just fine but don't re…

---

## [Scripted fields versus scripts in discovery objects](https://discuss.elastic.co/t/scripted-fields-versus-scripts-in-discovery-objects/326802)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 9\
**Last updated:** [March 8, 2023, 7:02pm UTC](https://discuss.elastic.co/t/scripted-fields-versus-scripts-in-discovery-objects/326802 "2023-03-08T19:02:42Z")

</div>

In Kibana I have found two ways to create an additional field based upon what is in the documents. Use scripted fields in the index patterns. Since I want to convert a parameter that is in seconds to hours the script i…

---

## [Getting stuck on load geoip database file while installing Elasticsearch 8.6.2](https://discuss.elastic.co/t/getting-stuck-on-load-geoip-database-file-while-installing-elasticsearch-8-6-2/327289)

<div class="topic-metadata">

**Author:** [@Alfred\_C](https://discuss.elastic.co/u/Alfred_C)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 6:21pm UTC](https://discuss.elastic.co/t/getting-stuck-on-load-geoip-database-file-while-installing-elasticsearch-8-6-2/327289 "2023-03-08T18:21:11Z")

</div>

Hi, I just tried to install Elasticsearch 8.6.2, however it was stuck when run elasticsearch.bat details as show at the screenshot

---

## [Is it possible to sort in a custom grouping manner with unicode collation algorithm in elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-sort-in-a-custom-grouping-manner-with-unicode-collation-algorithm-in-elasticsearch/327294)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 5:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-sort-in-a-custom-grouping-manner-with-unicode-collation-algorithm-in-elasticsearch/327294 "2023-03-08T17:11:35Z")

</div>

I am working on a phonebook, where if the user does not provide Name but fills only email, I will show the email value in phonebook (as in mac contacts). And the priority is as follows Name (if not present) -\> Email (if…

---

## [How to get logs from jupyter notebook instances generated by jupyterhub](https://discuss.elastic.co/t/how-to-get-logs-from-jupyter-notebook-instances-generated-by-jupyterhub/327290)

<div class="topic-metadata">

**Author:** [@SirReno](https://discuss.elastic.co/u/SirReno)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 4:45pm UTC](https://discuss.elastic.co/t/how-to-get-logs-from-jupyter-notebook-instances-generated-by-jupyterhub/327290 "2023-03-08T16:45:50Z")

</div>

Hello eveyone; We have a jupyterhub (that is being monitored by filebeat) that spawns individual jupyter-notebooks (based on docker image), since it spawns a pod, the filebeat that monitors jupyterhub, cant reach the in…

---

## [Null\_pointer\_exception: Cannot invoke "String.equals(Object)" because the return value of "org.apache.lucene.search.SortField.getField()" is null](https://discuss.elastic.co/t/null-pointer-exception-cannot-invoke-string-equals-object-because-the-return-value-of-org-apache-lucene-search-sortfield-getfield-is-null/327235)

<div class="topic-metadata">

**Author:** [@davidgAID](https://discuss.elastic.co/u/davidgAID)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 4:35pm UTC](https://discuss.elastic.co/t/null-pointer-exception-cannot-invoke-string-equals-object-because-the-return-value-of-org-apache-lucene-search-sortfield-getfield-is-null/327235 "2023-03-08T16:35:29Z")

</div>

This is on Elasticsearch 8.6.2. I have a pretty mundane query that I want to paginate via search\_after. The initial query looks like this: { "\_source": true, "collapse": { "field": "collapse\_col" }, "query…

---

## [Data nodes separation (via attributes) vs. clusters separation](https://discuss.elastic.co/t/data-nodes-separation-via-attributes-vs-clusters-separation/327216)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 4:33pm UTC](https://discuss.elastic.co/t/data-nodes-separation-via-attributes-vs-clusters-separation/327216 "2023-03-08T16:33:45Z")

</div>

Hi, We are B2B that maintain one index per each one of our customers. Every index is being indexed every day from scratch and once it is ready, it replace the previous day index. Once the index is ready, it's in read-…

---

## [Kibana Dashboard is empty with a lot of errors](https://discuss.elastic.co/t/kibana-dashboard-is-empty-with-a-lot-of-errors/327204)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 4:16pm UTC](https://discuss.elastic.co/t/kibana-dashboard-is-empty-with-a-lot-of-errors/327204 "2023-03-08T16:16:19Z")

</div>

I'm new to kibana and Elasticsearch. Could someone tell me what to do here I have everything installed properly I think but I can't see anything in the dashboard. I have siem\_events and siem\_alarm index patterns creat…

---

## [Unable to connect to Elasticsearch client running locally: receiving 'connection refused' on KOTLIN](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-client-running-locally-receiving-connection-refused-on-kotlin/327215)

<div class="topic-metadata">

**Author:** [@GAETANO\_SIMONELLI](https://discuss.elastic.co/u/GAETANO_SIMONELLI)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 4:05pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-client-running-locally-receiving-connection-refused-on-kotlin/327215 "2023-03-08T16:05:49Z")

</div>

I am experiencing connection issues with my Elasticsearch client running locally. Specifically, when I try to connect using localhost in the RestClient.builder, I receive a java.net.connectException: connection refused e…

---

## [Is there a quicker way to import data to Elastic?](https://discuss.elastic.co/t/is-there-a-quicker-way-to-import-data-to-elastic/327275)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 5\
**Last updated:** [March 8, 2023, 3:49pm UTC](https://discuss.elastic.co/t/is-there-a-quicker-way-to-import-data-to-elastic/327275 "2023-03-08T15:49:54Z")

</div>

I have exported elastic indices using logstash with the following logstash configuration: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { …

---

## [Time Filter Canvas](https://discuss.elastic.co/t/time-filter-canvas/327046)

<div class="topic-metadata">

**Author:** [@puched](https://discuss.elastic.co/u/puched)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:48pm UTC](https://discuss.elastic.co/t/time-filter-canvas/327046 "2023-03-08T14:48:28Z")

</div>

Hello, im trying to do a global time filter for my canvas presentation, I dont know what im doing wrong with the filters. Im filtering with logTime variable, I apply the global timefilter but the data is being show…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=608)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=610)
