# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=617

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 618

---

## [Interface name](https://discuss.elastic.co/t/interface-name/326736)

<div class="topic-metadata">

**Author:** [@teplyukdimka](https://discuss.elastic.co/u/teplyukdimka)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 8:20am UTC](https://discuss.elastic.co/t/interface-name/326736 "2023-03-01T08:20:49Z")

</div>

Good day. Tell me, please, I collect netflow using filebeat. There are fields '''' "egress\_interface" : 199, "ingress\_interface" : 277, '''' Through SNMP, I found out which network interfaces correspond to these i…

---

## [ELASTICSEARCH\_17 - Could not index '1' records: listener timeout after waiting for \[30000\] ms](https://discuss.elastic.co/t/elasticsearch-17-could-not-index-1-records-listener-timeout-after-waiting-for-30000-ms/326688)

<div class="topic-metadata">

**Author:** [@senix](https://discuss.elastic.co/u/senix)\
**Replies:** 5\
**Last updated:** [March 1, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-17-could-not-index-1-records-listener-timeout-after-waiting-for-30000-ms/326688 "2023-03-01T06:32:05Z")

</div>

We're using streamsets to send messages to Elasticsearch and are consistently getting the following error: ELASTICSEARCH\_17 - Could not index '1' records: listener timeout after waiting for \[30000\] ms We've tried vario…

---

## [Run Logstash manually without interrupting logstash service and logstash Scheduler](https://discuss.elastic.co/t/run-logstash-manually-without-interrupting-logstash-service-and-logstash-scheduler/326036)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 8\
**Last updated:** [March 1, 2023, 6:25am UTC](https://discuss.elastic.co/t/run-logstash-manually-without-interrupting-logstash-service-and-logstash-scheduler/326036 "2023-03-01T06:25:43Z")

</div>

Hello, I have a configuration file with http\_poller plugins, where I have some scheduler which on the given schedule pull the data and enter it into my elastic db. But to manually run lagstash instantly, What I have to…

---

## [Elastic agent: "output not supported" using Logstash output on 8.6](https://discuss.elastic.co/t/elastic-agent-output-not-supported-using-logstash-output-on-8-6/326010)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 10:36pm UTC](https://discuss.elastic.co/t/elastic-agent-output-not-supported-using-logstash-output-on-8-6/326010 "2023-02-28T22:36:31Z")

</div>

Hi all, I have a previously working\* Fleet/Agent config with 8.5.3 and Logstash output configured. \* aside from 8.5.1 agents go unhealthy · Issue #1790 · elastic/elastic-agent · GitHub but I have a workaround for this…

---

## [Filebeat gives an error when it outputs to elasticsearch](https://discuss.elastic.co/t/filebeat-gives-an-error-when-it-outputs-to-elasticsearch/326667)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 8:51am UTC](https://discuss.elastic.co/t/filebeat-gives-an-error-when-it-outputs-to-elasticsearch/326667 "2023-02-28T08:51:01Z")

</div>

My elastic cluster version is 8.6.0 and filebeat version is 8.6.0 The log has been successfully read, but there will be some errors in the log output. Failed to connect to backoff (elasticsearch (http://192.168.3.74:30…

---

## [Check if value is 'null' So it Can Be Used in a Fingerprint and Document \_id](https://discuss.elastic.co/t/check-if-value-is-null-so-it-can-be-used-in-a-fingerprint-and-document-id/326632)

<div class="topic-metadata">

**Author:** [@iFamZ](https://discuss.elastic.co/u/iFamZ)\
**Replies:** 12\
**Last updated:** [March 1, 2023, 2:53am UTC](https://discuss.elastic.co/t/check-if-value-is-null-so-it-can-be-used-in-a-fingerprint-and-document-id/326632 "2023-03-01T02:53:21Z")

</div>

Hello, I am working to setup fingerprint on a field if it is not null. If it is null, I will fingerprint a different field (which is never null). Currently, my filebeat processors look like this: processors: - "de…

---

## [Improving resiliency or changing settings of system indices](https://discuss.elastic.co/t/improving-resiliency-or-changing-settings-of-system-indices/326108)

<div class="topic-metadata">

**Author:** [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Replies:** 3\
**Last updated:** [March 1, 2023, 1:45am UTC](https://discuss.elastic.co/t/improving-resiliency-or-changing-settings-of-system-indices/326108 "2023-03-01T01:45:22Z")

</div>

Hi, I'm trying to improve the resiliency of my elastic stack. I want to make it tolerant to any two node failures, but I can't update system indices to have more than one replica. The setting in question is index.auto…

---

## [Search all indexes for document's parameter name or retrieve one document p/index](https://discuss.elastic.co/t/search-all-indexes-for-documents-parameter-name-or-retrieve-one-document-p-index/325175)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 5\
**Last updated:** [February 28, 2023, 10:48pm UTC](https://discuss.elastic.co/t/search-all-indexes-for-documents-parameter-name-or-retrieve-one-document-p-index/325175 "2023-02-28T22:48:31Z")

</div>

Hi I am a bit new in elastic and started in a project that has more than 800 indexes and I need to rename some old names to the new ones requested. I already found some indexes that has parameters with values that need …

---

## [Update\_By\_Query in elasticsearch\_dsl matches \<field\> but doesn't match \<object\>.\<field\>](https://discuss.elastic.co/t/update-by-query-in-elasticsearch-dsl-matches-field-but-doesnt-match-object-field/325889)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 10:33pm UTC](https://discuss.elastic.co/t/update-by-query-in-elasticsearch-dsl-matches-field-but-doesnt-match-object-field/325889 "2023-02-28T22:33:56Z")

</div>

I managed to do an update\_by\_query script with elasticsearch\_dsl. response = ubq.script(source="pm\_data\_source.hw\_alias' = params.new\_ap\_name",lang="painless",params={"new\_ap\_name": new\_ap})\\ .query("match", pm\_…

---

## [Filebeat not collecting all logs](https://discuss.elastic.co/t/filebeat-not-collecting-all-logs/326694)

<div class="topic-metadata">

**Author:** [@Norsu296](https://discuss.elastic.co/u/Norsu296)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 4:17pm UTC](https://discuss.elastic.co/t/filebeat-not-collecting-all-logs/326694 "2023-02-28T16:17:13Z")

</div>

I have issue with filebeat. I'm using autodiscover for kubernetes. Filebeat is collecting logs and sending them to elastic and they are visible in kibana. Some logs are not sending and I don't understand why. I see in Ki…

---

## [Logstash Netflow Codec Plugin - "unsupported enterprise" error with IPFIX template](https://discuss.elastic.co/t/logstash-netflow-codec-plugin-unsupported-enterprise-error-with-ipfix-template/326701)

<div class="topic-metadata">

**Author:** [@nosql\_injection](https://discuss.elastic.co/u/nosql_injection)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 6:29pm UTC](https://discuss.elastic.co/t/logstash-netflow-codec-plugin-unsupported-enterprise-error-with-ipfix-template/326701 "2023-02-28T18:29:29Z")

</div>

Hi there, when trying to ingest IPFIX, we get the Can't (yet) decode flowset id 317 from observation domain id 6422528, because no template to decode it with has been received. This message will usually go away after …

---

## [Changing index settings when closed can corrupt an index](https://discuss.elastic.co/t/changing-index-settings-when-closed-can-corrupt-an-index/326705)

<div class="topic-metadata">

**Author:** [@dwilches](https://discuss.elastic.co/u/dwilches)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 8:13pm UTC](https://discuss.elastic.co/t/changing-index-settings-when-closed-can-corrupt-an-index/326705 "2023-02-28T20:13:07Z")

</div>

I found a warning in this documentation page about updating index settings while they are closed: Changing static or dynamic index settings on a closed index could result in incorrect settings that are impossible to re…

---

## [Kibana maps doesn't show clusters/grids](https://discuss.elastic.co/t/kibana-maps-doesnt-show-clusters-grids/326178)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 7\
**Last updated:** [February 28, 2023, 7:59pm UTC](https://discuss.elastic.co/t/kibana-maps-doesnt-show-clusters-grids/326178 "2023-02-28T19:59:35Z")

</div>

Hello, I'm currently experimenting with the maps feature of Kibana, which was easy to set up, but it seems like it is not working correctly. We are currently using the ELK stack version 8.4.1 in an offline environment. …

---

## [Using aggregate to add modsecurity data to previous event](https://discuss.elastic.co/t/using-aggregate-to-add-modsecurity-data-to-previous-event/326423)

<div class="topic-metadata">

**Author:** [@admin\_berlin](https://discuss.elastic.co/u/admin_berlin)\
**Replies:** 3\
**Last updated:** [February 28, 2023, 7:33pm UTC](https://discuss.elastic.co/t/using-aggregate-to-add-modsecurity-data-to-previous-event/326423 "2023-02-28T19:33:13Z")

</div>

Hi, I have a modsec logfile that looks like this: --8afa774c-A-- \[24/Feb/2023:04:34:53 +0100\] Y-WoWiTsAtEsT123 12.139.152.111 14327 10.29.14.193 8080 --8afa774c-B-- POST /its/a/test/dude HTTP/1.1 Host: www.my-site.de Co…

---

## [Fleet API account missing security settings](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 6:32pm UTC](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643 "2023-02-28T18:32:11Z")

</div>

Hi all, I'm on v8.6 of the ELK stack and working on some new custom log parsing. It looks like the configuration is reading our initial test data properly, however it appears the built-in Fleet API account is missing so…

---

## [Got error "The bulk request must be terminated by a newline \[\\\\n\]" when importing data with curl and insomnia](https://discuss.elastic.co/t/got-error-the-bulk-request-must-be-terminated-by-a-newline-n-when-importing-data-with-curl-and-insomnia/326697)

<div class="topic-metadata">

**Author:** [@Kalimink](https://discuss.elastic.co/u/Kalimink)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 5:08pm UTC](https://discuss.elastic.co/t/got-error-the-bulk-request-must-be-terminated-by-a-newline-n-when-importing-data-with-curl-and-insomnia/326697 "2023-02-28T17:08:08Z")

</div>

Hello, after several attempts to integrate my data which are in json form via Curl and even insomnia I always get the same error : "The bulk request must be terminated by a newline \[\\n\]" but even after adding a newlin…

---

## [Elastic Agents fail to upgrade from Fleet, shows "Updating" status for more than a week](https://discuss.elastic.co/t/elastic-agents-fail-to-upgrade-from-fleet-shows-updating-status-for-more-than-a-week/325426)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 13\
**Last updated:** [February 28, 2023, 4:57pm UTC](https://discuss.elastic.co/t/elastic-agents-fail-to-upgrade-from-fleet-shows-updating-status-for-more-than-a-week/325426 "2023-02-28T16:57:37Z")

</div>

I recently upgraded my Elastic Cloud instance to 8.6.1. After upgrading, I triggered an agent upgrade in Fleet to v8.6.1. The agents DID NOT upgrade and were stuck in Updating status for almost a week. If I go into the s…

---

## [Elastic agent transfer via logstahsh with incomplete logs](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 3\
**Last updated:** [February 28, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482 "2023-02-28T16:08:05Z")

</div>

1.elastic agent transfer via logstahsh, endpoint shows healthy but logs are not coming in, what is the reason? Is there any solution for this? The endpoint is viewed locally with the following result? 2.elastic agen…

---

## [Telemetry Devices and Rally 2.7.0](https://discuss.elastic.co/t/telemetry-devices-and-rally-2-7-0/326638)

<div class="topic-metadata">

**Author:** [@Safty](https://discuss.elastic.co/u/Safty)\
**Replies:** 3\
**Last updated:** [February 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/telemetry-devices-and-rally-2-7-0/326638 "2023-02-28T15:57:32Z")

</div>

Hello, fellow elastic/rally kids. Does Rally 2.7.0 support Telemetry Devices? If so is the expectation that all tracks are supported? Meaning you can run any telemetry devices listed under 'esrally list telemetry'. …

---

## [Query not executing in Elasticsearch input plugin for logstash](https://discuss.elastic.co/t/query-not-executing-in-elasticsearch-input-plugin-for-logstash/326362)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 6\
**Last updated:** [February 28, 2023, 3:55pm UTC](https://discuss.elastic.co/t/query-not-executing-in-elasticsearch-input-plugin-for-logstash/326362 "2023-02-28T15:55:15Z")

</div>

I'm new to the stack, and am trying to execute simple queries in logstash via the elasticsearch input plugin. I have worked through some initial errors and now have only a couple of notable warnings, but am not getting a…

---

## [ANN Search: ElasticSearch vs FAISS](https://discuss.elastic.co/t/ann-search-elasticsearch-vs-faiss/326653)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 3:29pm UTC](https://discuss.elastic.co/t/ann-search-elasticsearch-vs-faiss/326653 "2023-02-28T15:29:54Z")

</div>

As i know, Elasticsearch 8.x support for knn search with hnsw index by default, so i try to compare elasticsearch vs faiss (hnsw index), i set both elasticsearch and faiss with same parameter (m=32, efconstruct=128, efs…

---

## [Kibana is going slow](https://discuss.elastic.co/t/kibana-is-going-slow/326172)

<div class="topic-metadata">

**Author:** [@jdbcplusnet](https://discuss.elastic.co/u/jdbcplusnet)\
**Replies:** 11\
**Last updated:** [February 28, 2023, 3:27pm UTC](https://discuss.elastic.co/t/kibana-is-going-slow/326172 "2023-02-28T15:27:27Z")

</div>

Hi all We have some performance issues with Kibana and Elasticsearch. Both Elasticsearch and Kibana are 6.8.7 version. We have Elasticsearch Cluster with 3 nodes, one master and two slaves, 8GB for each node. We have …

---

## [Dynamic naming of elasticsearch data-streams](https://discuss.elastic.co/t/dynamic-naming-of-elasticsearch-data-streams/325278)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 12\
**Last updated:** [February 28, 2023, 3:22pm UTC](https://discuss.elastic.co/t/dynamic-naming-of-elasticsearch-data-streams/325278 "2023-02-28T15:22:30Z")

</div>

Hi, I'm trying to have some dynamic naming for my data streams based on some syslog fields. Here is my rsyslog conf file for sending datas in JSON format to logstash. # cat logstash-json.conf template(name="json-templ…

---

## [Having trouble running elasticsearch](https://discuss.elastic.co/t/having-trouble-running-elasticsearch/326528)

<div class="topic-metadata">

**Author:** [@bawac](https://discuss.elastic.co/u/bawac)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 2:37pm UTC](https://discuss.elastic.co/t/having-trouble-running-elasticsearch/326528 "2023-02-28T14:37:06Z")

</div>

I am trying to run elasticsearch from my terminal and I'm getting this error: warning: ignoring JAVA\_HOME=/usr/lib/jvm/java-11-openjdk-arm64; using bundled JDK Dynarec for ARM64, with extension: ASIMD AES CRC32 PMULL AT…

---

## [How to integrate user-specified Kibana fields with my data fields](https://discuss.elastic.co/t/how-to-integrate-user-specified-kibana-fields-with-my-data-fields/326684)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 2:03pm UTC](https://discuss.elastic.co/t/how-to-integrate-user-specified-kibana-fields-with-my-data-fields/326684 "2023-02-28T14:03:38Z")

</div>

Here is a basic case I am trying to solve. The data provides events that indicate how long a device lost cellular connectivity. I can use Kibana to get the total amount of downtime. However, the downtime is in seconds an…

---

## [I will reword the issue again](https://discuss.elastic.co/t/i-will-reword-the-issue-again/326675)

<div class="topic-metadata">

**Author:** [@learner75](https://discuss.elastic.co/u/learner75)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 1:50pm UTC](https://discuss.elastic.co/t/i-will-reword-the-issue-again/326675 "2023-02-28T13:50:59Z")

</div>

I will reword the issue again.

---

## [Possible bug with monitoring creating thousands of elasticsearch.index.recovery duplicate docs](https://discuss.elastic.co/t/possible-bug-with-monitoring-creating-thousands-of-elasticsearch-index-recovery-duplicate-docs/324673)

<div class="topic-metadata">

**Author:** [@sparrowt](https://discuss.elastic.co/u/sparrowt)\
**Replies:** 5\
**Last updated:** [February 28, 2023, 1:41pm UTC](https://discuss.elastic.co/t/possible-bug-with-monitoring-creating-thousands-of-elasticsearch-index-recovery-duplicate-docs/324673 "2023-02-28T13:41:19Z")

</div>

Since upgrading to 8.x and (via cloud.elastic.co) enabling Monitoring \> Logs and metrics \> Ship to a deployment, I was surprised at the volume of data arriving into the .monitoring-es-8-mb datastream. On investigation i…

---

## [GET DATA FROM PAYLOAD IN ILM WATCHER](https://discuss.elastic.co/t/get-data-from-payload-in-ilm-watcher/326680)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 11:41am UTC](https://discuss.elastic.co/t/get-data-from-payload-in-ilm-watcher/326680 "2023-02-28T11:41:45Z")

</div>

Hi to all!! I'm trying to get the index with ILM errors, so i created a watcher like this: { "trigger": { "schedule": { "interval": "10m" } }, "input": { "http": { "request": { "scheme": "https", "host": "$host", "port…

---

## [Explain API parsing and displaying tools](https://discuss.elastic.co/t/explain-api-parsing-and-displaying-tools/326677)

<div class="topic-metadata">

**Author:** [@Eylon\_Koren1](https://discuss.elastic.co/u/Eylon_Koren1)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 11:35am UTC](https://discuss.elastic.co/t/explain-api-parsing-and-displaying-tools/326677 "2023-02-28T11:35:18Z")

</div>

Hey ! I'm using the Elasticsearch Explain API in order to understand the ES internal scoring. The explain results is complex json, which i extract the impact of each field on the query overall score. Are there any too…

---

## [Upgradation of elastic version](https://discuss.elastic.co/t/upgradation-of-elastic-version/326679)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 11:28am UTC](https://discuss.elastic.co/t/upgradation-of-elastic-version/326679 "2023-02-28T11:28:18Z")

</div>

Hi all, I'm having ES version 7.10 Now i want to upgrade to 8.6 version. So one way of upgradation, is to take snapshot, delete old version (7.10) and install new version (8.6) and then restore snapshot. Is there a …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=616)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=618)
