# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=611

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 612

---

## [Configuracion del Node.Roles \[master\]](https://discuss.elastic.co/t/configuracion-del-node-roles-master/327098)

<div class="topic-metadata">

**Author:** [@LeonardoCord](https://discuss.elastic.co/u/LeonardoCord)\
**Replies:** 5\
**Last updated:** [March 7, 2023, 9:33pm UTC](https://discuss.elastic.co/t/configuracion-del-node-roles-master/327098 "2023-03-07T21:33:11Z")

</div>

Buenas Estoy tratando de configurar el Node.Roles \[master\] debido a que es una configuracion obsoleta en la version que tengo 7.17.6 y he configurado mi .YML pero a la hora de correrlo mi elastic no arranca.

---

## [Importing multiple large csv and json files into a single index](https://discuss.elastic.co/t/importing-multiple-large-csv-and-json-files-into-a-single-index/326738)

<div class="topic-metadata">

**Author:** [@mansi\_raval](https://discuss.elastic.co/u/mansi_raval)\
**Replies:** 10\
**Last updated:** [March 7, 2023, 9:29pm UTC](https://discuss.elastic.co/t/importing-multiple-large-csv-and-json-files-into-a-single-index/326738 "2023-03-07T21:29:17Z")

</div>

I have an folder containing data (20 GB) and this folder contains 26 subfolders that are sorted city-wise. Each of these subfolder contain many more subfolders comprising of csv and json files (The data that is stored in…

---

## [Disk size and performance optimization for Elasticsearch cluster](https://discuss.elastic.co/t/disk-size-and-performance-optimization-for-elasticsearch-cluster/327071)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 9:20pm UTC](https://discuss.elastic.co/t/disk-size-and-performance-optimization-for-elasticsearch-cluster/327071 "2023-03-07T21:20:48Z")

</div>

Hi everyone, I'm currently running an Elasticsearch cluster with 6 nodes, and (for every node) the disk usage is around 5.5 TB out of a total disk size of 20 TB. I don't anticipate a significant increase in data storag…

---

## [Elasticsearch monitor with metricbeat](https://discuss.elastic.co/t/elasticsearch-monitor-with-metricbeat/327223)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 7:26pm UTC](https://discuss.elastic.co/t/elasticsearch-monitor-with-metricbeat/327223 "2023-03-07T19:26:47Z")

</div>

I am so crazy confuse on this setup. can't seems to make it work. this is my test setup that I am trying and getting more confuse every min. here is my configuration. monitor cluster:: elkdev11 monitoring cluster: …

---

## [Extracting year in short format from the log file name](https://discuss.elastic.co/t/extracting-year-in-short-format-from-the-log-file-name/327172)

<div class="topic-metadata">

**Author:** [@lupsya](https://discuss.elastic.co/u/lupsya)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 5:38pm UTC](https://discuss.elastic.co/t/extracting-year-in-short-format-from-the-log-file-name/327172 "2023-03-07T17:38:01Z")

</div>

Hello, I am extracting Year, Month, and Day from the following testing log name and converting it to timestamp later. log20230225.log I am using the following grok filter: log%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:d…

---

## [Difference between Timestamp and @timestamp in kibana logs](https://discuss.elastic.co/t/difference-between-timestamp-and-timestamp-in-kibana-logs/327203)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 4:33pm UTC](https://discuss.elastic.co/t/difference-between-timestamp-and-timestamp-in-kibana-logs/327203 "2023-03-07T16:33:17Z")

</div>

Hi everyone, I noticed that there is a difference of time between Timestamp and @timestamp generated with logstash . Is there a way to synchronise the value of @timestamp to be equal to Timestamp on kibana logs? Thank …

---

## [Elasticsearch Cloud API Authentication](https://discuss.elastic.co/t/elasticsearch-cloud-api-authentication/327161)

<div class="topic-metadata">

**Author:** [@Mark\_Rodman](https://discuss.elastic.co/u/Mark_Rodman)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 4:28pm UTC](https://discuss.elastic.co/t/elasticsearch-cloud-api-authentication/327161 "2023-03-07T16:28:31Z")

</div>

Hi, I'm trying to figure how to authenticate REST API use against our Elasticsearch cloud instance. I understand how to use the cloud id etc when using a client library in a language such as Python however in my use ca…

---

## [Issue with RecyclerBytesStreamOutput](https://discuss.elastic.co/t/issue-with-recyclerbytesstreamoutput/325996)

<div class="topic-metadata">

**Author:** [@aurelien.guillaume](https://discuss.elastic.co/u/aurelien.guillaume)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 4:03pm UTC](https://discuss.elastic.co/t/issue-with-recyclerbytesstreamoutput/325996 "2023-03-07T16:03:26Z")

</div>

Hi, I'm new in the usage of Elasticsearch (integrated into a security onion appliance) I'm working to get a huge query (2.5M logs), and I'm stuck with this error message { "error": { "root\_cause": \[ { …

---

## [How to Access Kibana time range (timepicker) in a painless script](https://discuss.elastic.co/t/how-to-access-kibana-time-range-timepicker-in-a-painless-script/326871)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 3:50pm UTC](https://discuss.elastic.co/t/how-to-access-kibana-time-range-timepicker-in-a-painless-script/326871 "2023-03-07T15:50:55Z")

</div>

When making a search for documents that have a time stamp the user can specify a time range over which the search will be done. It looks like this in the search request: { "range": { "date"…

---

## [ES query to trigger n no. of email/webhook based on document hits](https://discuss.elastic.co/t/es-query-to-trigger-n-no-of-email-webhook-based-on-document-hits/326910)

<div class="topic-metadata">

**Author:** [@Amulya\_Nanda](https://discuss.elastic.co/u/Amulya_Nanda)\
**Replies:** 12\
**Last updated:** [March 7, 2023, 3:46pm UTC](https://discuss.elastic.co/t/es-query-to-trigger-n-no-of-email-webhook-based-on-document-hits/326910 "2023-03-07T15:46:24Z")

</div>

We are using this below code to trigger email/webhook actions once the threshold is met. But we are getting n no.of hits in one single email. Example our threshold has met with10 documents. So 10 emails/webhook has to …

---

## [Help needed for scripting for runtime fields](https://discuss.elastic.co/t/help-needed-for-scripting-for-runtime-fields/326001)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 26\
**Last updated:** [March 7, 2023, 3:35pm UTC](https://discuss.elastic.co/t/help-needed-for-scripting-for-runtime-fields/326001 "2023-03-07T15:35:29Z")

</div>

Hello everyone, I am completely new to Elastic and scripting in general. I was told to install ElasticStack on our network for monitoring purposes. I now have both Elasticsearch and Kibana installed. I am currently try…

---

## [Markdown link to a secondary dashboard is not time persistent](https://discuss.elastic.co/t/markdown-link-to-a-secondary-dashboard-is-not-time-persistent/326980)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 3:31pm UTC](https://discuss.elastic.co/t/markdown-link-to-a-secondary-dashboard-is-not-time-persistent/326980 "2023-03-07T15:31:00Z")

</div>

Hi Folks, I have a primary dashboard that uses a markdown visualization that links to a secondary dashboard , while the page opens just fine. The time values from the primary dashboard are not carried over to the second…

---

## [Filebeat: failed to parse field \[user\_agent.version\] of type \[date\]](https://discuss.elastic.co/t/filebeat-failed-to-parse-field-user-agent-version-of-type-date/327124)

<div class="topic-metadata">

**Author:** [@mevan](https://discuss.elastic.co/u/mevan)\
**Replies:** 12\
**Last updated:** [March 7, 2023, 2:43pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-field-user-agent-version-of-type-date/327124 "2023-03-07T14:43:29Z")

</div>

This begins as a filebeat issue but I think it's now a matter of elasticsearch index. I'm seeing repeated messages like this in our logging. I can see this is related to the nginx module but I'm unsure how to go about f…

---

## [Timestamp under data stream](https://discuss.elastic.co/t/timestamp-under-data-stream/327192)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 2:32pm UTC](https://discuss.elastic.co/t/timestamp-under-data-stream/327192 "2023-03-07T14:32:57Z")

</div>

Hi I'm facing the case with timestamp under data stream When I put the data do data stream template I can find these data under the different time shifted 1hour ahead. the same data was put to index and looks as e…

---

## [Kibana - one visualization should not be affected by user click on another](https://discuss.elastic.co/t/kibana-one-visualization-should-not-be-affected-by-user-click-on-another/327123)

<div class="topic-metadata">

**Author:** [@richfish](https://discuss.elastic.co/u/richfish)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 2:30pm UTC](https://discuss.elastic.co/t/kibana-one-visualization-should-not-be-affected-by-user-click-on-another/327123 "2023-03-07T14:30:11Z")

</div>

I have a dashboard with 4 pie charts, a data table and a search. When the user clicks on a slice on one of the pies, I want the data table and the search to reflect what they clicked. But I don't want the other 3 pie cha…

---

## [Building beats with oss lisence](https://discuss.elastic.co/t/building-beats-with-oss-lisence/327187)

<div class="topic-metadata">

**Author:** [@Udemy\_Guy](https://discuss.elastic.co/u/Udemy_Guy)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 2:13pm UTC](https://discuss.elastic.co/t/building-beats-with-oss-lisence/327187 "2023-03-07T14:13:09Z")

</div>

We are trying to rebuild beats with oss licensing, anyone can guide? We used "mage build" but looks like it does not build it as oss.

---

## [Is there a way to remove or hide the black "Elastic" bar with the "Search Elastic" box from Kibana 7.x?](https://discuss.elastic.co/t/is-there-a-way-to-remove-or-hide-the-black-elastic-bar-with-the-search-elastic-box-from-kibana-7-x/327017)

<div class="topic-metadata">

**Author:** [@quan\_w](https://discuss.elastic.co/u/quan_w)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:57pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-remove-or-hide-the-black-elastic-bar-with-the-search-elastic-box-from-kibana-7-x/327017 "2023-03-07T13:57:42Z")

</div>

how to remove or hide the black "Elastic" bar in the header ?

---

## [Data from Filebeat Not Showing in Elastic](https://discuss.elastic.co/t/data-from-filebeat-not-showing-in-elastic/326922)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/data-from-filebeat-not-showing-in-elastic/326922 "2023-03-07T13:41:09Z")

</div>

Hi, Hoping you can help. I am fairly new to Elastic Stack, but the company i work for have a running implementation monitoring Apache logs. I am attempting to add to the functionality by also monitoring the access log …

---

## [Profiling kNN search](https://discuss.elastic.co/t/profiling-knn-search/327065)

<div class="topic-metadata">

**Author:** [@ruslaniv](https://discuss.elastic.co/u/ruslaniv)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/profiling-knn-search/327065 "2023-03-07T13:33:27Z")

</div>

I'm trying to profile slow kNN search as discussed here . So I read the documentation here and set up this query in Postman: { "profile": true, "knn": { "field": "title\_vector", "query\_vector": {{SEARCH\_TEX…

---

## [Table of contents with parameters](https://discuss.elastic.co/t/table-of-contents-with-parameters/326936)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/table-of-contents-with-parameters/326936 "2023-03-07T13:33:18Z")

</div>

Hello, I have a markdown visualization with links to other dashboards. (a table of content) I would like to add a parameter (css combo box, a control visualization) and to pass the value to the links in the markdown vi…

---

## [Parsing multiple JSON entries merged inside 1 "message" of filebeat input Azure Blob Storage](https://discuss.elastic.co/t/parsing-multiple-json-entries-merged-inside-1-message-of-filebeat-input-azure-blob-storage/323153)

<div class="topic-metadata">

**Author:** [@Marquito](https://discuss.elastic.co/u/Marquito)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 12:46pm UTC](https://discuss.elastic.co/t/parsing-multiple-json-entries-merged-inside-1-message-of-filebeat-input-azure-blob-storage/323153 "2023-03-07T12:46:38Z")

</div>

Hello Everyone, I am currently trying to parse a message that contains multiple JSON entries with filebeat input Azure Blob Storage. I have tried using decode\_json\_fields, multiline but it seems like "multiline" only wo…

---

## [Falied to start Elasticsearch to my group volumes](https://discuss.elastic.co/t/falied-to-start-elasticsearch-to-my-group-volumes/325501)

<div class="topic-metadata">

**Author:** [@MonkeyD.J](https://discuss.elastic.co/u/MonkeyD.J)\
**Replies:** 9\
**Last updated:** [March 7, 2023, 12:17pm UTC](https://discuss.elastic.co/t/falied-to-start-elasticsearch-to-my-group-volumes/325501 "2023-03-07T12:17:15Z")

</div>

Hello, Mrs,Mr, I try to start Elasticsearch on my volum group. So I am on a debian 11.3 and I install java jre1.8.0\_121. I Install the version elastick 7.17.6 amd64.deb on my folder with this command dpkg -x /applis…

---

## [502 Bad Gateway Ingress nginx with kibana](https://discuss.elastic.co/t/502-bad-gateway-ingress-nginx-with-kibana/327175)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 12:13pm UTC](https://discuss.elastic.co/t/502-bad-gateway-ingress-nginx-with-kibana/327175 "2023-03-07T12:13:56Z")

</div>

I deployed kibana on a kubernetes cluster the port-forward locally works, I can surf on kibana but when set my ingress configuration, it comes back with a 502 Bad Gateway. Please help! This is my ingress configuration: …

---

## [Elasticsearch update by query](https://discuss.elastic.co/t/elasticsearch-update-by-query/327167)

<div class="topic-metadata">

**Author:** [@v-lixiubo](https://discuss.elastic.co/u/v-lixiubo)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 11:30am UTC](https://discuss.elastic.co/t/elasticsearch-update-by-query/327167 "2023-03-07T11:30:14Z")

</div>

hi , I use the java client updateByQuery to update the data, and the returned result is successful, but the data has not actually changed

---

## [LogStash - Issue with sql\_last\_value and last\_run\_metadata\_path](https://discuss.elastic.co/t/logstash-issue-with-sql-last-value-and-last-run-metadata-path/327087)

<div class="topic-metadata">

**Author:** [@CedMathis](https://discuss.elastic.co/u/CedMathis)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 11:08am UTC](https://discuss.elastic.co/t/logstash-issue-with-sql-last-value-and-last-run-metadata-path/327087 "2023-03-07T11:08:07Z")

</div>

Hello, I'm new to ELK and I'm currently struggling with some setup - maybe I missed a point. I have set up my Logstash to parse my DB (MySql), and I've got 2 cases: "Unforeseen maintenance" -\> In this case, I would…

---

## [Can we add dynamic text to our dashboard?](https://discuss.elastic.co/t/can-we-add-dynamic-text-to-our-dashboard/327064)

<div class="topic-metadata">

**Author:** [@Sugunakar](https://discuss.elastic.co/u/Sugunakar)\
**Replies:** 7\
**Last updated:** [March 7, 2023, 9:56am UTC](https://discuss.elastic.co/t/can-we-add-dynamic-text-to-our-dashboard/327064 "2023-03-07T09:56:59Z")

</div>

Hi, I am new to Kibana reporting. Is there any way to add Dynamic text to Kibana using any API or using Python script. Thanks in advance.

---

## [Unable to select a different output in my agent policy](https://discuss.elastic.co/t/unable-to-select-a-different-output-in-my-agent-policy/326955)

<div class="topic-metadata">

**Author:** [@Lamine](https://discuss.elastic.co/u/Lamine)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 9:42am UTC](https://discuss.elastic.co/t/unable-to-select-a-different-output-in-my-agent-policy/326955 "2023-03-07T09:42:19Z")

</div>

Hello everyone, I am trying to configure two different outputs for my agents, but when i try to create the agent policy, I am unable to select a different output. Does anyone know the reason? Thank you

---

## [Cannot create elastic indexes after removing two nodes from cassandra](https://discuss.elastic.co/t/cannot-create-elastic-indexes-after-removing-two-nodes-from-cassandra/327151)

<div class="topic-metadata">

**Author:** [@Ram5](https://discuss.elastic.co/u/Ram5)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 9:24am UTC](https://discuss.elastic.co/t/cannot-create-elastic-indexes-after-removing-two-nodes-from-cassandra/327151 "2023-03-07T09:24:47Z")

</div>

I cannot create elastic index after removing two nodes from cassandra. We had two nodes earlier, but for some reason they were unable to communicate with each other. So we removed them and changed necessary configuration…

---

## ["Cannot write to a field alias \[...\]" on reindex](https://discuss.elastic.co/t/cannot-write-to-a-field-alias-on-reindex/327162)

<div class="topic-metadata">

**Author:** [@Adrien](https://discuss.elastic.co/u/Adrien)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 9:14am UTC](https://discuss.elastic.co/t/cannot-write-to-a-field-alias-on-reindex/327162 "2023-03-07T09:14:59Z")

</div>

Hi, I'm trying to migrate an Elasticsearch index from 6.8 to 7.10 using the \_reindex route API. Unfortunately during the index migration I get the error Cannot write to a field alias \[gl2\_message\_id\]. The mapping, cop…

---

## [Can't assume role in filebeat cloudwatch input when IAM policy can assume multiple roles](https://discuss.elastic.co/t/cant-assume-role-in-filebeat-cloudwatch-input-when-iam-policy-can-assume-multiple-roles/327159)

<div class="topic-metadata">

**Author:** [@stwang](https://discuss.elastic.co/u/stwang)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 9:10am UTC](https://discuss.elastic.co/t/cant-assume-role-in-filebeat-cloudwatch-input-when-iam-policy-can-assume-multiple-roles/327159 "2023-03-07T09:10:55Z")

</div>

We are using filebeat 7.17.5, and we are using CloudWatch input, we want to retrieve log from another AWS account b and AWS account c. So in filebeat AWS role, we have a policy which allow to assume roles for other two …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=610)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=612)
