# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=616

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 617

---

## [Is it Possible to call a field using uptime tls alerting?](https://discuss.elastic.co/t/is-it-possible-to-call-a-field-using-uptime-tls-alerting/326829)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 8:30am UTC](https://discuss.elastic.co/t/is-it-possible-to-call-a-field-using-uptime-tls-alerting/326829 "2023-03-02T08:30:35Z")

</div>

Hi there, i have made an alert rule like this using elasticsearch query: i set the action to write the alert to kibana.log Here is the message and query: { "query":{ "bool": { "filter": \[ { …

---

## [Blank spaces in Elastic monitoring indicating possible problems?](https://discuss.elastic.co/t/blank-spaces-in-elastic-monitoring-indicating-possible-problems/326828)

<div class="topic-metadata">

**Author:** [@Lay0ut](https://discuss.elastic.co/u/Lay0ut)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 8:13am UTC](https://discuss.elastic.co/t/blank-spaces-in-elastic-monitoring-indicating-possible-problems/326828 "2023-03-02T08:13:40Z")

</div>

Hello everyone, starting this week i noticed that there are occasional gaps in the monitoring graph of my elastic cluster. I wonder if these could indicate a possible problem with the cluster and what could cause these: …

---

## [Ranking in Lens Formula Features Visualization](https://discuss.elastic.co/t/ranking-in-lens-formula-features-visualization/326718)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 7\
**Last updated:** [March 2, 2023, 7:58am UTC](https://discuss.elastic.co/t/ranking-in-lens-formula-features-visualization/326718 "2023-03-02T07:58:12Z")

</div>

Hi, I have problem in ranking my visualization dashboard. I would like to visualize Top 10 Uptime Monitor Availability. I already tried using the TVSB visualization type which is Top N to visualize Top 10 Uptime Monit…

---

## [Use geoip in Painless Script](https://discuss.elastic.co/t/use-geoip-in-painless-script/326550)

<div class="topic-metadata">

**Author:** [@sigizmynd](https://discuss.elastic.co/u/sigizmynd)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 7:49am UTC](https://discuss.elastic.co/t/use-geoip-in-painless-script/326550 "2023-03-02T07:49:00Z")

</div>

hello I want to add geiop to Painless script For example def t4 = "IP\_ADDRESS"; def cntr = t4.geoip;

---

## [Error when searching in a specific field](https://discuss.elastic.co/t/error-when-searching-in-a-specific-field/326734)

<div class="topic-metadata">

**Author:** [@Thoriqul\_Umar](https://discuss.elastic.co/u/Thoriqul_Umar)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 4:14am UTC](https://discuss.elastic.co/t/error-when-searching-in-a-specific-field/326734 "2023-03-02T04:14:51Z")

</div>

hello, I got error "failed to connect to console's backed. please check the kibana server is up and running" when tried to search on field "file\_content". here is my query { "query": { "multi\_match": { "qu…

---

## [Ccs query without log content in Table tab page](https://discuss.elastic.co/t/ccs-query-without-log-content-in-table-tab-page/326816)

<div class="topic-metadata">

**Author:** [@zhangzhuzi](https://discuss.elastic.co/u/zhangzhuzi)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 2:27am UTC](https://discuss.elastic.co/t/ccs-query-without-log-content-in-table-tab-page/326816 "2023-03-02T02:27:53Z")

</div>

Kibana Discover CCS query results do not display log content on the table tab page. Switching to the JSON tab page display the log content, but I can directly query the log content through the command line. What is the r…

---

## [Elasticsearch Indexing Issues](https://discuss.elastic.co/t/elasticsearch-indexing-issues/326768)

<div class="topic-metadata">

**Author:** [@H-Soni](https://discuss.elastic.co/u/H-Soni)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 11:54pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-issues/326768 "2023-03-01T23:54:56Z")

</div>

Hi, We have a 5-node cluster, currently running ES 5.6.11. When there's an increased load in indexing, heap usage reaches 90% in one of the nodes, while some have only 40-50% heap usage. Because of this, elasticsearch t…

---

## [Need Help - with \_update\_by\_query query several indexes for two fields (one is optional)](https://discuss.elastic.co/t/need-help-with-update-by-query-query-several-indexes-for-two-fields-one-is-optional/326786)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 4:37pm UTC](https://discuss.elastic.co/t/need-help-with-update-by-query-query-several-indexes-for-two-fields-one-is-optional/326786 "2023-03-01T16:37:49Z")

</div>

Need help- with \_update\_by\_query to query several indexes for two fields (one is optional, for the indexes where the field exists). I was doing two separate update by query, one when the index' document has a field com…

---

## [Get only the last record of an index in Kibana](https://discuss.elastic.co/t/get-only-the-last-record-of-an-index-in-kibana/326792)

<div class="topic-metadata">

**Author:** [@ismi2002](https://discuss.elastic.co/u/ismi2002)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 10:06pm UTC](https://discuss.elastic.co/t/get-only-the-last-record-of-an-index-in-kibana/326792 "2023-03-01T22:06:28Z")

</div>

Hello everyone, I'm trying to do a visualization of "live events", therefore, I want to see only the last record inserted in an index in Kibana, can you help me with this? Thanks!

---

## [Problema al agregar certificado de empresa en Elasticsearch Centos 7](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-elasticsearch-centos-7/326806)

<div class="topic-metadata">

**Author:** [@DARWIN\_PEREZ](https://discuss.elastic.co/u/DARWIN_PEREZ)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:40pm UTC](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-elasticsearch-centos-7/326806 "2023-03-01T21:40:24Z")

</div>

kibana server is not ready yet

---

## [How to Add custom integration into elastic-agent integration package registry](https://discuss.elastic.co/t/how-to-add-custom-integration-into-elastic-agent-integration-package-registry/326740)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:29pm UTC](https://discuss.elastic.co/t/how-to-add-custom-integration-into-elastic-agent-integration-package-registry/326740 "2023-03-01T21:29:05Z")

</div>

I am Following this guide Build an integration build is successfully done using the command elastic-package build getting error Custom build packages directory found: /opt/elastic-package/build/packages Packages fro…

---

## [Logstash isn't sending data to elastic](https://discuss.elastic.co/t/logstash-isnt-sending-data-to-elastic/326686)

<div class="topic-metadata">

**Author:** [@Uzzi](https://discuss.elastic.co/u/Uzzi)\
**Replies:** 8\
**Last updated:** [March 1, 2023, 6:34pm UTC](https://discuss.elastic.co/t/logstash-isnt-sending-data-to-elastic/326686 "2023-03-01T18:34:18Z")

</div>

Hi, I've 1 vmq for Kibana+elasticsearch and 1 vm for Logstash. Logstash isn't sending data to elastic, this is log: \[DEBUG\]\[logstash.instrument.periodicpoller.cgroup\] One or more required cgroup files or directories no…

---

## [Problem generating Grok from AWS Postgres logs](https://discuss.elastic.co/t/problem-generating-grok-from-aws-postgres-logs/326100)

<div class="topic-metadata">

**Author:** [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 5:13pm UTC](https://discuss.elastic.co/t/problem-generating-grok-from-aws-postgres-logs/326100 "2023-03-01T17:13:11Z")

</div>

Hi, I'm having trouble generating the GROK of AWS logs from the same elasticsearch configuration, as well as from the filebeat.yml file. # ============================== Filebeat inputs =============================== f…

---

## [Ha Proxy integration issues](https://discuss.elastic.co/t/ha-proxy-integration-issues/326785)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 4:37pm UTC](https://discuss.elastic.co/t/ha-proxy-integration-issues/326785 "2023-03-01T16:37:15Z")

</div>

Hey, I'm trying to make the HA Proxy integration working on my ELK stack. I'm able to gather the system metrics as expected, so I tried to add the HA Proxy integration on my hosts with HA proxy servers running. So what…

---

## [I cannot update template](https://discuss.elastic.co/t/i-cannot-update-template/326775)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/i-cannot-update-template/326775 "2023-03-01T16:33:40Z")

</div>

I updated the template of filebeat in the elasticsearch node. It returned me an error: { "error": { "root\_cause": \[ { "type": "mapper\_parsing\_exception", "reason": "Root mapping definition has unsupported …

---

## [Groke parse failure on Haproxy logs while debugger is OK](https://discuss.elastic.co/t/groke-parse-failure-on-haproxy-logs-while-debugger-is-ok/326779)

<div class="topic-metadata">

**Author:** [@Bastien\_Bsc](https://discuss.elastic.co/u/Bastien_Bsc)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 4:29pm UTC](https://discuss.elastic.co/t/groke-parse-failure-on-haproxy-logs-while-debugger-is-ok/326779 "2023-03-01T16:29:42Z")

</div>

Hello, I have a weird situation where the data is correctly parsed, grok debugger doesn't return errors. But logstash still adds a grokeparse\_failure tag. Here is an exemple log (in /var/log/haproxy.log) : Mar 1 15:4…

---

## [Rollover Errors](https://discuss.elastic.co/t/rollover-errors/325272)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 4:23pm UTC](https://discuss.elastic.co/t/rollover-errors/325272 "2023-03-01T16:23:34Z")

</div>

Hello I have been working on some code to be able to rollover my syslogs so that it will continue to populate the Kibana. I am getting the following error in the Dev Tools Illegal argument exception rollover target is…

---

## [Jupyter spark connect to elasticsearch](https://discuss.elastic.co/t/jupyter-spark-connect-to-elasticsearch/326585)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 11\
**Last updated:** [March 1, 2023, 3:14pm UTC](https://discuss.elastic.co/t/jupyter-spark-connect-to-elasticsearch/326585 "2023-03-01T15:14:21Z")

</div>

I'm trying to connect from spark to elasticsearch , so as first I've build docker images from spark3.2.1 for kubernetes then from jupyter notebook I've opened a session to spark a build the context to elasticsearch on t…

---

## [Filestream processing of CSV files](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 2:22pm UTC](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704 "2023-03-01T14:22:23Z")

</div>

Hi all, I'm slowly migrating over to filestream to process some log files and have data coming in and stored into the message field. Here is an example: ec26.515d.ebcf,someUser,GSS-A-1FL-122,SD35 What I would like to …

---

## [Logstash how to mutate string of float array to denseVector](https://discuss.elastic.co/t/logstash-how-to-mutate-string-of-float-array-to-densevector/326750)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 11:03am UTC](https://discuss.elastic.co/t/logstash-how-to-mutate-string-of-float-array-to-densevector/326750 "2023-03-01T11:03:50Z")

</div>

I am using Logstash to transfer data from MySQL to ES, one column in MySQL is \`vec\` text NOT NULL vec has value like \[0.1, 0.2, 0.3\] and is of string type. How to convert string of float array to ES dense\_vector? I tr…

---

## [Subtraction between current date and doc created date](https://discuss.elastic.co/t/subtraction-between-current-date-and-doc-created-date/326405)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 4\
**Last updated:** [March 1, 2023, 10:54am UTC](https://discuss.elastic.co/t/subtraction-between-current-date-and-doc-created-date/326405 "2023-03-01T10:54:44Z")

</div>

Hi, Please see the below code sample. long l1=(new Date().getTime()); //emit(l1); long l= ChronoUnit.SECONDS.between(l1, doc\['timestamp'\].value); if(l\<=100000){ emit('New') } else{emit('Old')} I am getting the b…

---

## [Kibana Dashboard loading Issue](https://discuss.elastic.co/t/kibana-dashboard-loading-issue/326702)

<div class="topic-metadata">

**Author:** [@rohitguptaggg](https://discuss.elastic.co/u/rohitguptaggg)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/kibana-dashboard-loading-issue/326702 "2023-03-01T10:41:31Z")

</div>

Hello, I have created a Kibana dashboard using a filter and query, but it is causing loading issues and the Elasticsearch CPU is going up to 99%, even though there are 3 Elasticsearch nodes. Can someone please help and …

---

## [Autodetect\_column\_names in condition](https://discuss.elastic.co/t/autodetect-column-names-in-condition/326439)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 6\
**Last updated:** [March 1, 2023, 10:36am UTC](https://discuss.elastic.co/t/autodetect-column-names-in-condition/326439 "2023-03-01T10:36:45Z")

</div>

Hi Maybe You have idea why in this case autodetect\_column\_names doesn't work as independent. input: "CLLI","SWREL","RPTDATE","RPTIME","TZ","RPTTYPE","RPTPD","IVALDATE","IVALSTART","IVALEND","NUMENTIDS" "wifi06","EAGL…

---

## [Failure to parce query](https://discuss.elastic.co/t/failure-to-parce-query/326699)

<div class="topic-metadata">

**Author:** [@mikes1962](https://discuss.elastic.co/u/mikes1962)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 10:27am UTC](https://discuss.elastic.co/t/failure-to-parce-query/326699 "2023-03-01T10:27:32Z")

</div>

I'm very new to elasticsearch so please forgive me if this is a stupid question. I'm writing python code to read data from the stack but from time to time I get a message like this: Exception: Invalid Query: \[erm/d-2Cll…

---

## [How to remove restriction from the value of a field in a document such that the field doesn't get marked as \_ignored due to it's long length](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727)

<div class="topic-metadata">

**Author:** [@Deepanshu\_Yadav1](https://discuss.elastic.co/u/Deepanshu_Yadav1)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 10:16am UTC](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727 "2023-03-01T10:16:32Z")

</div>

PROLOGUE: We are using Elastic Fleet and Elastic Agents. Using filebeat and ingest pipeline we are fetching logs from a custom log file kept on an elastic agent. These logs are then indexed in Elastic Search and can b…

---

## [Output stdout does not print to shell when given info log level](https://discuss.elastic.co/t/output-stdout-does-not-print-to-shell-when-given-info-log-level/326392)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:47am UTC](https://discuss.elastic.co/t/output-stdout-does-not-print-to-shell-when-given-info-log-level/326392 "2023-03-01T09:47:19Z")

</div>

The following script reads from mysql through jdbc plugin, and output every item through stdout. However, by running logstash -f mysql2es.conf， it does not print anything. Then I added --debug, I can see entities jdbc re…

---

## [Filebeat problem](https://discuss.elastic.co/t/filebeat-problem/325831)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:38am UTC](https://discuss.elastic.co/t/filebeat-problem/325831 "2023-03-01T09:38:36Z")

</div>

Hello, I am using filebeat v8 that sends data to kafka. On startup, filebeat sends a chunk of data and then NO data is being transferred. I checked filebeat logs no errors are present. Filebeat registry is accessible an…

---

## [How to install custom package of elastic-agent in my kibana](https://discuss.elastic.co/t/how-to-install-custom-package-of-elastic-agent-in-my-kibana/326741)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 3\
**Last updated:** [March 1, 2023, 9:16am UTC](https://discuss.elastic.co/t/how-to-install-custom-package-of-elastic-agent-in-my-kibana/326741 "2023-03-01T09:16:21Z")

</div>

I Followed this link and created custom package for elastic-agent (integration) Build an integration after creating build .zip of the package how i can install this package (integration) into my elasticsearch-kibana ?? …

---

## [Gradual migration from container input to kubernetes autodiscover](https://discuss.elastic.co/t/gradual-migration-from-container-input-to-kubernetes-autodiscover/325979)

<div class="topic-metadata">

**Author:** [@OranShuster](https://discuss.elastic.co/u/OranShuster)\
**Replies:** 3\
**Last updated:** [March 1, 2023, 9:14am UTC](https://discuss.elastic.co/t/gradual-migration-from-container-input-to-kubernetes-autodiscover/325979 "2023-03-01T09:14:11Z")

</div>

We are currently using a filebeat daemon set with the "old" container input, both version 7.17.x we want to start migrating to the newer approach of hint based log collection for this we need the old filebeat daemon se…

---

## [Can I make scripts I run in Kibana tools into Kibana objects](https://discuss.elastic.co/t/can-i-make-scripts-i-run-in-kibana-tools-into-kibana-objects/326471)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 9:04am UTC](https://discuss.elastic.co/t/can-i-make-scripts-i-run-in-kibana-tools-into-kibana-objects/326471 "2023-03-01T09:04:21Z")

</div>

I can write REST, painless, etc. scripts using the Kibana tools (dev Tools) console. At least I can write REST searches. Is it possible to take these searches and make them into a Kibana object? Right now it only seems p…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=615)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=617)
