# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=615

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 616

---

## [Is @timestamp in kibana from filebeat or logstash?](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836)

<div class="topic-metadata">

**Author:** [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Replies:** 9\
**Last updated:** [March 3, 2023, 3:11am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836 "2023-03-03T03:11:22Z")

</div>

So the thing is I have filebeat that ship the log file to logstash then to the elasticsearch cluster. And I created the data view the get the messages on the discover page. I wonder where this @timestamp field comes from…

---

## [Add metric and Visualize from Visualize Library to User Experience Dasdboard](https://discuss.elastic.co/t/add-metric-and-visualize-from-visualize-library-to-user-experience-dasdboard/326898)

<div class="topic-metadata">

**Author:** [@hung.lengoc](https://discuss.elastic.co/u/hung.lengoc)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 2:27am UTC](https://discuss.elastic.co/t/add-metric-and-visualize-from-visualize-library-to-user-experience-dasdboard/326898 "2023-03-03T02:27:05Z")

</div>

Hello team, I working with APM and RUM version 5.12.0. Now I want to add "user\_id" or "user\_name" information who is logged in to the app to "User Experience Dashboard". And can I add a "Visualize" from "Visualize Libr…

---

## [Logstash connection error](https://discuss.elastic.co/t/logstash-connection-error/326133)

<div class="topic-metadata">

**Author:** [@peinmercado](https://discuss.elastic.co/u/peinmercado)\
**Replies:** 1\
**Last updated:** [March 3, 2023, 1:27am UTC](https://discuss.elastic.co/t/logstash-connection-error/326133 "2023-03-03T01:27:32Z")

</div>

Hi all, I'm trying to setup log stash for my elasticsearch master region to backup region for our BCP, I will be using the in and out information of logstash however, I got an error \[2023-02-22T07:14:21,226\]\[ERROR\]\[l…

---

## [Getting error when trying o update field value (it is a keyword)](https://discuss.elastic.co/t/getting-error-when-trying-o-update-field-value-it-is-a-keyword/326891)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 10:36pm UTC](https://discuss.elastic.co/t/getting-error-when-trying-o-update-field-value-it-is-a-keyword/326891 "2023-03-02T22:36:06Z")

</div>

Trying to figure out this issue, the pmdata1.pm\_data\_source.hw\_alias is a text field that is also mapped as keyword pmdata1.pm\_data\_source.hw\_alias.key. I tried this query (\_update\_by\_query) using the field it worked (f…

---

## [How to enforce ordering within nested objects?](https://discuss.elastic.co/t/how-to-enforce-ordering-within-nested-objects/326889)

<div class="topic-metadata">

**Author:** [@pure](https://discuss.elastic.co/u/pure)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 9:19pm UTC](https://discuss.elastic.co/t/how-to-enforce-ordering-within-nested-objects/326889 "2023-03-02T21:19:27Z")

</div>

I'm using elasticsearch as a Key-Value store, so that I can guarantee the query always return just 1 document. There is a nested field in the document schema, and I want to make sure multiple values within the nested obj…

---

## [Kubernetes - Inventory showing elastic agents instead of Host names](https://discuss.elastic.co/t/kubernetes-inventory-showing-elastic-agents-instead-of-host-names/323660)

<div class="topic-metadata">

**Author:** [@Pablo\_Halamaj](https://discuss.elastic.co/u/Pablo_Halamaj)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 7:13pm UTC](https://discuss.elastic.co/t/kubernetes-inventory-showing-elastic-agents-instead-of-host-names/323660 "2023-03-02T19:13:07Z")

</div>

Hello, I set up Fleet and a bunch of agents running on a Kubernetes (K8S) cluster with the Kubernetes' integration. So far the log and metrics integration kind of work ( we see them on the DSs, the dashboards and the d…

---

## [Kubernetes Node Condition NetworkUnavailable missing from metricbeat](https://discuss.elastic.co/t/kubernetes-node-condition-networkunavailable-missing-from-metricbeat/326789)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 6:52pm UTC](https://discuss.elastic.co/t/kubernetes-node-condition-networkunavailable-missing-from-metricbeat/326789 "2023-03-02T18:52:05Z")

</div>

The kubernetes Node Condition 'NetworkUnavailable' is missing from metricbeat. Can you please elaborate to why that is? Thank you, Kris

---

## [How to install elastic search fleet server on Kubernetes](https://discuss.elastic.co/t/how-to-install-elastic-search-fleet-server-on-kubernetes/326880)

<div class="topic-metadata">

**Author:** [@iojas](https://discuss.elastic.co/u/iojas)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 6:03pm UTC](https://discuss.elastic.co/t/how-to-install-elastic-search-fleet-server-on-kubernetes/326880 "2023-03-02T18:03:56Z")

</div>

I think I have been going round and round with the whole setup. I am able to get the fleet connection working when working with ECK on cloud. Since it's a managed instance it comes prebuilt with fleet server installed. w…

---

## [Shift value in CSV condition](https://discuss.elastic.co/t/shift-value-in-csv-condition/326801)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 6\
**Last updated:** [March 2, 2023, 5:05pm UTC](https://discuss.elastic.co/t/shift-value-in-csv-condition/326801 "2023-03-02T17:05:29Z")

</div>

Hi How I can shift some fields with value in "if" condition for example: CLLI, SWREL for the output in one event? expected output: { "NDCFLXDA" =\> "0", "@version" =\> "1", "NDCFLXDC" =\> "0", "STATUS" =\> "K", "NM…

---

## [Kibana 7.x chart label font size](https://discuss.elastic.co/t/kibana-7-x-chart-label-font-size/325262)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 4:38pm UTC](https://discuss.elastic.co/t/kibana-7-x-chart-label-font-size/325262 "2023-03-02T16:38:31Z")

</div>

Hi experts! I'm looking for a way to increase the font size of the labels in a Kibana chart, such as the pie (not into Lens). I found a css file "legacy\_light\_theme.css" in which I've been able to resize some font siz…

---

## [Fleet Server seems to sent plain HTTP to Fleets Logstash Output](https://discuss.elastic.co/t/fleet-server-seems-to-sent-plain-http-to-fleets-logstash-output/324035)

<div class="topic-metadata">

**Author:** [@m-logs](https://discuss.elastic.co/u/m-logs)\
**Replies:** 14\
**Last updated:** [March 2, 2023, 4:13pm UTC](https://discuss.elastic.co/t/fleet-server-seems-to-sent-plain-http-to-fleets-logstash-output/324035 "2023-03-02T16:13:53Z")

</div>

Hello, I am currently trying to configure a logstash output for the fleet server. I followed the instruction from the documentation. First I set up a Elasticsearch output for the fleet server. That worked fine. After t…

---

## [Kubernetes integration does not work on Elasticsearch/Kibana ver. 8.6.2 (SSL issue)](https://discuss.elastic.co/t/kubernetes-integration-does-not-work-on-elasticsearch-kibana-ver-8-6-2-ssl-issue/326306)

<div class="topic-metadata">

**Author:** [@tgolubic](https://discuss.elastic.co/u/tgolubic)\
**Replies:** 15\
**Last updated:** [March 2, 2023, 3:57pm UTC](https://discuss.elastic.co/t/kubernetes-integration-does-not-work-on-elasticsearch-kibana-ver-8-6-2-ssl-issue/326306 "2023-03-02T15:57:47Z")

</div>

Hello team, I have a test environment set up that hosts a 3 node k8s cluster, Elasticsearch and Kibana. ELK is installed on a separate server. ELK works without problems and the integration with Kuberentes was done acco…

---

## [Pipeline on Logstash](https://discuss.elastic.co/t/pipeline-on-logstash/326249)

<div class="topic-metadata">

**Author:** [@psanggabuana](https://discuss.elastic.co/u/psanggabuana)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 3:54pm UTC](https://discuss.elastic.co/t/pipeline-on-logstash/326249 "2023-03-02T15:54:33Z")

</div>

Hi all, I need some suggestions about the pipeline on Logstash. I have running the pipeline on Logstash, and suddenly I have an issue. The pipeline is configured that is automatically changed without restarting the se…

---

## [Custom TF-IDF implementation](https://discuss.elastic.co/t/custom-tf-idf-implementation/326872)

<div class="topic-metadata">

**Author:** [@Karel\_Haerens1](https://discuss.elastic.co/u/Karel_Haerens1)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 3:32pm UTC](https://discuss.elastic.co/t/custom-tf-idf-implementation/326872 "2023-03-02T15:32:29Z")

</div>

I'm trying to implement a custom TF-IDF-like algorithm with scripted similarity, my current approach: The way term frequency is determined is custom, these values are precalculated and stored in the records as lists. as…

---

## [Help receiving logs in Logstash deployed in Heroku](https://discuss.elastic.co/t/help-receiving-logs-in-logstash-deployed-in-heroku/326795)

<div class="topic-metadata">

**Author:** [@lglt](https://discuss.elastic.co/u/lglt)\
**Replies:** 6\
**Last updated:** [March 2, 2023, 2:43pm UTC](https://discuss.elastic.co/t/help-receiving-logs-in-logstash-deployed-in-heroku/326795 "2023-03-02T14:43:22Z")

</div>

Hi! I just deployed my Logstash project in Heroku. My plan is use it to process and send the logs to my Elastic Cloud deploy (Kibana and Elasticsearch). Logstash is running successfully. These are the Logstash logs that…

---

## [WordPress plugin needed](https://discuss.elastic.co/t/wordpress-plugin-needed/326797)

<div class="topic-metadata">

**Author:** [@Peter\_Lipschutz](https://discuss.elastic.co/u/Peter_Lipschutz)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 2:24pm UTC](https://discuss.elastic.co/t/wordpress-plugin-needed/326797 "2023-03-02T14:24:23Z")

</div>

We want to implement an elasticsearch database that we can access through our WordPress site. We want to create a separate db in elasticsearch. It will NOT be used to search the WP MySQL db. I need to figure out what plu…

---

## [How to use actual timestamp or createdtime in Table lens without interval](https://discuss.elastic.co/t/how-to-use-actual-timestamp-or-createdtime-in-table-lens-without-interval/326843)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-use-actual-timestamp-or-createdtime-in-table-lens-without-interval/326843 "2023-03-02T14:02:38Z")

</div>

Hi, How to show actual timestamp or createdTime on table lens which is available in the index. In the below snap highlighted column not showing the actual time which is available in the index, it is showing interval ti…

---

## [Max Number of data nodes per machines](https://discuss.elastic.co/t/max-number-of-data-nodes-per-machines/326788)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 1:41pm UTC](https://discuss.elastic.co/t/max-number-of-data-nodes-per-machines/326788 "2023-03-02T13:41:13Z")

</div>

Hi, I want to install few data nodes on one machines. Each data node will get 32GB RAM. Is there any formula for getting the max number of nodes per machine CPU and RAM? Thanks

---

## [Logstash is processing old events](https://discuss.elastic.co/t/logstash-is-processing-old-events/326336)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 7\
**Last updated:** [March 2, 2023, 1:11pm UTC](https://discuss.elastic.co/t/logstash-is-processing-old-events/326336 "2023-03-02T13:11:57Z")

</div>

Getting continuous errors like below in logstash { "timestamp": "2023-02-10T14:04:33.661-08:00", "severity": "warning", "message": "Could not index event to Elasticsearch. {:status=\>404, :action=\>\['index', {:\_id=\>nil, :…

---

## [Create and Deploy custom ML models for NLP](https://discuss.elastic.co/t/create-and-deploy-custom-ml-models-for-nlp/326777)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 12:57pm UTC](https://discuss.elastic.co/t/create-and-deploy-custom-ml-models-for-nlp/326777 "2023-03-02T12:57:22Z")

</div>

Hello, I've read the documentation on ML and deploying ML models Overview | Machine Learning in the Elastic Stack \[8.6\] | Elastic. Does anyone have examples of how to do the following: Create a custom ML model that f…

---

## [Ruby filter counting error Workers](https://discuss.elastic.co/t/ruby-filter-counting-error-workers/326330)

<div class="topic-metadata">

**Author:** [@puched](https://discuss.elastic.co/u/puched)\
**Replies:** 6\
**Last updated:** [March 2, 2023, 12:51pm UTC](https://discuss.elastic.co/t/ruby-filter-counting-error-workers/326330 "2023-03-02T12:51:42Z")

</div>

I want to store the line number as the document\_id, but i saw that sometimes its not storing in the right way the numbers in order, i guess its because of the multiple workers, the question is Is there a way to store num…

---

## [Error fetching data for metricset http.json](https://discuss.elastic.co/t/error-fetching-data-for-metricset-http-json/326848)

<div class="topic-metadata">

**Author:** [@abdul90082](https://discuss.elastic.co/u/abdul90082)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 12:41pm UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-http-json/326848 "2023-03-02T12:41:03Z")

</div>

{ "log.level": "error", "@timestamp": "2023-03-02T11:40:42.101Z", "message": "Error fetching data for metricset http.json: error making http request: Get \\"http://unix/stats\\": context deadline exceeded (Client.Timeout e…

---

## [How to check unmanaged indices in Kibana watcher](https://discuss.elastic.co/t/how-to-check-unmanaged-indices-in-kibana-watcher/326749)

<div class="topic-metadata">

**Author:** [@mr\_sharma](https://discuss.elastic.co/u/mr_sharma)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 12:18pm UTC](https://discuss.elastic.co/t/how-to-check-unmanaged-indices-in-kibana-watcher/326749 "2023-03-02T12:18:17Z")

</div>

I've been trying watcher method in Kibana to get alerts if An index is unmanaged (not following any ILM policy) and it's size is more than 10GB. I'm new to Elastic and it seems so difficult develop the watcher script …

---

## [1 dashboard for multiple nodes](https://discuss.elastic.co/t/1-dashboard-for-multiple-nodes/326761)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 12:10pm UTC](https://discuss.elastic.co/t/1-dashboard-for-multiple-nodes/326761 "2023-03-02T12:10:54Z")

</div>

Hi, How can I combine the multiple nodes graphs to 1 dashboard? Thanks

---

## [How to show percentage column in table lens](https://discuss.elastic.co/t/how-to-show-percentage-column-in-table-lens/326825)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 11:20am UTC](https://discuss.elastic.co/t/how-to-show-percentage-column-in-table-lens/326825 "2023-03-02T11:20:13Z")

</div>

Hi, How we can calculate and add a percentage column in the below snap

---

## [How does Logstash convert a integer value to another integer value](https://discuss.elastic.co/t/how-does-logstash-convert-a-integer-value-to-another-integer-value/326830)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 1\
**Last updated:** [March 2, 2023, 11:02am UTC](https://discuss.elastic.co/t/how-does-logstash-convert-a-integer-value-to-another-integer-value/326830 "2023-03-02T11:02:10Z")

</div>

In the following pipeline, I want to add a shift (1000000) to id column value, id was 1, and I want it to be 1000001. However, with mutate update generates a string "1 + 1000000" instead of making integer shifted. I al…

---

## [How to correctly determine the weight of a node](https://discuss.elastic.co/t/how-to-correctly-determine-the-weight-of-a-node/224871)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 1\
**Last updated:** [March 2, 2023, 9:59am UTC](https://discuss.elastic.co/t/how-to-correctly-determine-the-weight-of-a-node/224871 "2023-03-02T09:59:41Z")

</div>

Hey Team, I'm trying to calculate the weights of each node based on the below two settings taken from shard balancing heuristics: cluster.routing.allocation.balance.shard cluster.routing.allocation.balance.index Let's…

---

## [Difference between Hits and Hits(total)](https://discuss.elastic.co/t/difference-between-hits-and-hits-total/326798)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 9:18am UTC](https://discuss.elastic.co/t/difference-between-hits-and-hits-total/326798 "2023-03-02T09:18:56Z")

</div>

Hi at all, I'm new here and am trying to create a few charts with vega-lite. With some help from here some bars are to be seen. But I have a problem with the amount of records wich are given from the request. Although m…

---

## [What are the strengths of 'Rally' compared to 'JMeter' or 'nGrinder'?](https://discuss.elastic.co/t/what-are-the-strengths-of-rally-compared-to-jmeter-or-ngrinder/326266)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 9:07am UTC](https://discuss.elastic.co/t/what-are-the-strengths-of-rally-compared-to-jmeter-or-ngrinder/326266 "2023-03-02T09:07:12Z")

</div>

What are the strengths of 'Rally' compared to 'JMeter' or 'nGrinder'? I have used 'Rally' before, but have not used 'Apache JMeter' or 'nGrinder'. Are there any relative advantages and disadvantages HAVE A GOOD DAY …

---

## [Cannot collect logs from kubernetes with containerd runtimes](https://discuss.elastic.co/t/cannot-collect-logs-from-kubernetes-with-containerd-runtimes/326678)

<div class="topic-metadata">

**Author:** [@venturieffect](https://discuss.elastic.co/u/venturieffect)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 8:46am UTC](https://discuss.elastic.co/t/cannot-collect-logs-from-kubernetes-with-containerd-runtimes/326678 "2023-03-02T08:46:17Z")

</div>

Hi everyone We deployed elastic agents with kubernetes integrations on newly installed kubernetes clusters 1.24. We noticed some missing logs and investigated the agents logs and status: we have this kind of error for e…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=614)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=616)
