# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=618

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 619

---

## [Inconsistent AWS Opensearch ingest attachment processor behaviour](https://discuss.elastic.co/t/inconsistent-aws-opensearch-ingest-attachment-processor-behaviour/326602)

<div class="topic-metadata">

**Author:** [@pcvijayvignesh](https://discuss.elastic.co/u/pcvijayvignesh)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 11:26am UTC](https://discuss.elastic.co/t/inconsistent-aws-opensearch-ingest-attachment-processor-behaviour/326602 "2023-02-28T11:26:53Z")

</div>

We are using AWS OpenSearch for one of our application. We have configured ingest attachment processor for extracting text from .docx files. Here is our environment setup details, Note: For DEV/QA, we use same instance…

---

## [Capture Log for Logstash For every successfull pipeline execution](https://discuss.elastic.co/t/capture-log-for-logstash-for-every-successfull-pipeline-execution/326298)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 6\
**Last updated:** [February 28, 2023, 11:23am UTC](https://discuss.elastic.co/t/capture-log-for-logstash-for-every-successfull-pipeline-execution/326298 "2023-02-28T11:23:00Z")

</div>

Hello, I want to capture log for logstash sucessfully fetching the api data from http\_poller plugin and entering it to my elasticDB. My configuration is: input { http\_poller { id =\> "test-plugin" urls =\> { t…

---

## [Kibana filters in Dashboard vs Lens (aggs vs query)](https://discuss.elastic.co/t/kibana-filters-in-dashboard-vs-lens-aggs-vs-query/326414)

<div class="topic-metadata">

**Author:** [@Piotrek](https://discuss.elastic.co/u/Piotrek)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 10:42am UTC](https://discuss.elastic.co/t/kibana-filters-in-dashboard-vs-lens-aggs-vs-query/326414 "2023-02-28T10:42:18Z")

</div>

Dear Community, I'm building kibana Dashboard with Customers names adding controls to my dashboard. When I filter Customer name in the dashboard with let's say 'John' it is not appearing in the particular table I have …

---

## [Vega-Lite, Simple bar-chart won't work](https://discuss.elastic.co/t/vega-lite-simple-bar-chart-wont-work/326617)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 10:29am UTC](https://discuss.elastic.co/t/vega-lite-simple-bar-chart-wont-work/326617 "2023-02-28T10:29:43Z")

</div>

Hi community, I try to work with vega-lite-charts, unfortunatley with no success. Here is my json: { "$schema": "https://vega.github.io/schema/vega-lite/v5.json", "description": "A simple bar chart", "data": {"u…

---

## [How to list out / export all the fields along with data types](https://discuss.elastic.co/t/how-to-list-out-export-all-the-fields-along-with-data-types/325975)

<div class="topic-metadata">

**Author:** [@RajuParipelly](https://discuss.elastic.co/u/RajuParipelly)\
**Replies:** 7\
**Last updated:** [February 28, 2023, 10:20am UTC](https://discuss.elastic.co/t/how-to-list-out-export-all-the-fields-along-with-data-types/325975 "2023-02-28T10:20:19Z")

</div>

I have an index with 25000 fields and wanted to export all the fields into a csv file along with data type? is there any way to do this?

---

## [Prevent setting minimum\_master\_nodes to more than the current node count](https://discuss.elastic.co/t/prevent-setting-minimum-master-nodes-to-more-than-the-current-node-count/326536)

<div class="topic-metadata">

**Author:** [@zhoumengbo](https://discuss.elastic.co/u/zhoumengbo)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 10:10am UTC](https://discuss.elastic.co/t/prevent-setting-minimum-master-nodes-to-more-than-the-current-node-count/326536 "2023-02-28T10:10:38Z")

</div>

Setting zen.discovery.minimum\_master\_nodes to a value higher than the current node count effectively leaves the cluster without a master and unable to process requests. The official website below has fixed this bug. ht…

---

## [Problem with adding node to elastic cluster](https://discuss.elastic.co/t/problem-with-adding-node-to-elastic-cluster/326671)

<div class="topic-metadata">

**Author:** [@reza\_setareh](https://discuss.elastic.co/u/reza_setareh)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 10:05am UTC](https://discuss.elastic.co/t/problem-with-adding-node-to-elastic-cluster/326671 "2023-02-28T10:05:12Z")

</div>

hi every one.i want to add new node to elastic cluster by enrollment token but i got the error below E:\\node-1\\bin\>elasticsearch-create-enrollment-token.bat -s node ERROR: \[xpack.security.enrollment.enabled\] must be se…

---

## [ElasticSearch Ingress-nginx integration have duplicate entries when elastic agent restart running in k8s](https://discuss.elastic.co/t/elasticsearch-ingress-nginx-integration-have-duplicate-entries-when-elastic-agent-restart-running-in-k8s/326600)

<div class="topic-metadata">

**Author:** [@CisorKnight](https://discuss.elastic.co/u/CisorKnight)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 9:33am UTC](https://discuss.elastic.co/t/elasticsearch-ingress-nginx-integration-have-duplicate-entries-when-elastic-agent-restart-running-in-k8s/326600 "2023-02-28T09:33:12Z")

</div>

I am using Elastic Cloud and "Nginx Ingress Controler Logs" integration to bring back my nginx access-logs to kibana. As mentionned in the tutorial, I created an Agent Policy and since im using a Kubernetes cluster I cr…

---

## [Defining ranges but NOT one at a time](https://discuss.elastic.co/t/defining-ranges-but-not-one-at-a-time/326573)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 5\
**Last updated:** [February 28, 2023, 9:06am UTC](https://discuss.elastic.co/t/defining-ranges-but-not-one-at-a-time/326573 "2023-02-28T09:06:34Z")

</div>

I want to create a bar graph of the time a cellular network was down. The y-axis gives the number of times and the x-axis is a set of ranges, 0-100 seconds, 100-200, seconds, in intervals of 100 seconds up to 100000. Tha…

---

## [Transforming logs into geo\_point to draw them in kibana](https://discuss.elastic.co/t/transforming-logs-into-geo-point-to-draw-them-in-kibana/323053)

<div class="topic-metadata">

**Author:** [@grillo](https://discuss.elastic.co/u/grillo)\
**Replies:** 10\
**Last updated:** [February 28, 2023, 8:29am UTC](https://discuss.elastic.co/t/transforming-logs-into-geo-point-to-draw-them-in-kibana/323053 "2023-02-28T08:29:41Z")

</div>

My goal is to be able to geolocate on a kibana map the connections that interest me. The problem is that the generated indices do not create the correct type of data for kibana to draw. It would be Geopoints. The data …

---

## [Must and should match doesn't return should matches](https://discuss.elastic.co/t/must-and-should-match-doesnt-return-should-matches/326657)

<div class="topic-metadata">

**Author:** [@ksh117](https://discuss.elastic.co/u/ksh117)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 7:58am UTC](https://discuss.elastic.co/t/must-and-should-match-doesnt-return-should-matches/326657 "2023-02-28T07:58:12Z")

</div>

{ "track\_total\_hits": true, "from": 0, "size": 20, "query": { "bool": { "must": \[ { "term": { "item\_id": { "value": "item\_value\_1", "boost": 1 …

---

## [Dashboard creation using Query](https://discuss.elastic.co/t/dashboard-creation-using-query/326647)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 7:49am UTC](https://discuss.elastic.co/t/dashboard-creation-using-query/326647 "2023-02-28T07:49:53Z")

</div>

Hi Team, We use filebeat, logstash, Elasticsearch and kibana for logs. And we have index patterns created and visualisations and then dashboards. Now I got a requirement saying to display the replication status that is…

---

## [Elasticsearch ilm rollover NOT applied as it should on datastreams v8.5.2](https://discuss.elastic.co/t/elasticsearch-ilm-rollover-not-applied-as-it-should-on-datastreams-v8-5-2/326612)

<div class="topic-metadata">

**Author:** [@Gautier\_Franchini](https://discuss.elastic.co/u/Gautier_Franchini)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 7:45am UTC](https://discuss.elastic.co/t/elasticsearch-ilm-rollover-not-applied-as-it-should-on-datastreams-v8-5-2/326612 "2023-02-28T07:45:54Z")

</div>

Dear All, I'm currently using elasticsearch and kibana in 8.5.2 version; I used the stack as a centralized logging platform. Everything works fine, logstash is able to send me tousant of logs through elastic data stream …

---

## [Unable to split the data in message field](https://discuss.elastic.co/t/unable-to-split-the-data-in-message-field/325987)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 10\
**Last updated:** [February 28, 2023, 7:45am UTC](https://discuss.elastic.co/t/unable-to-split-the-data-in-message-field/325987 "2023-02-28T07:45:19Z")

</div>

Hello I am running a python file using exec input plugin, the python file is making multiple api calls and collecting the data in a list(array). I am printing the list and getting the data in message field, but I am un…

---

## [I use auditbeat 8.6.2, can't find no login shell command](https://discuss.elastic.co/t/i-use-auditbeat-8-6-2-cant-find-no-login-shell-command/326659)

<div class="topic-metadata">

**Author:** [@chengzhangzuji](https://discuss.elastic.co/u/chengzhangzuji)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 7:12am UTC](https://discuss.elastic.co/t/i-use-auditbeat-8-6-2-cant-find-no-login-shell-command/326659 "2023-02-28T07:12:36Z")

</div>

1.Enviroment: CentOS7、ELK 8.6、Auditbeat 8.6； Two computers，ELK 8.6 in one，auditbeat in the other； Elasticsearch and Kibana installed by docker, auditbeat 8.6 installed by yum; 2. Use the default configure: \[root@loc…

---

## [Elastic search did not trust this server's certificate, closing connection](https://discuss.elastic.co/t/elastic-search-did-not-trust-this-servers-certificate-closing-connection/326663)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 7:35am UTC](https://discuss.elastic.co/t/elastic-search-did-not-trust-this-servers-certificate-closing-connection/326663 "2023-02-28T07:35:08Z")

</div>

Elasticsearch is running successfully but when iam checking the logs its says "http client did not trust this server's certificate, closing connection" find the log below : WARN", "message":"http client did not trust t…

---

## [Timezone in Ingest Pipeline](https://discuss.elastic.co/t/timezone-in-ingest-pipeline/326592)

<div class="topic-metadata">

**Author:** [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 7:30am UTC](https://discuss.elastic.co/t/timezone-in-ingest-pipeline/326592 "2023-02-28T07:30:16Z")

</div>

I'm using a IngestPipeline to extract fields from my logs. I start with extracting the Timestamp and targeting it into @timestamp s.b. now i'm mostly not provided with any timezone from my log and @Timestamp is using i…

---

## [Logstash log separation per pipeline doesn't work!](https://discuss.elastic.co/t/logstash-log-separation-per-pipeline-doesnt-work/324975)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 8\
**Last updated:** [February 28, 2023, 6:57am UTC](https://discuss.elastic.co/t/logstash-log-separation-per-pipeline-doesnt-work/324975 "2023-02-28T06:57:58Z")

</div>

Hi guys. We use ELK version 8.4.2. on logstash, we have 15 pipelines. Now we need to separate the logs. There is a solution in the elastic document: This document says to insert 2 directives in logstash.yml that aut…

---

## [Is it possible to integrated Elasticsearh with OBM Microfocus?](https://discuss.elastic.co/t/is-it-possible-to-integrated-elasticsearh-with-obm-microfocus/326645)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 6:57am UTC](https://discuss.elastic.co/t/is-it-possible-to-integrated-elasticsearh-with-obm-microfocus/326645 "2023-02-28T06:57:28Z")

</div>

I have question is it possible if elastic APM monitoring results be combined with other monitoring tools such as OBM from Microfocus? same thing as elasticsearch and splunk integration.

---

## [Map multiple fields to same user option in Kibana dashboard](https://discuss.elastic.co/t/map-multiple-fields-to-same-user-option-in-kibana-dashboard/326624)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 6:15am UTC](https://discuss.elastic.co/t/map-multiple-fields-to-same-user-option-in-kibana-dashboard/326624 "2023-02-28T06:15:32Z")

</div>

I am new to Kibana, now trying to develop a dashboard where it has to take the values of 3 or more fields and provide a single option to choose from. For example: Any individual can be contacted by either phone, email,…

---

## [SSL communication issue for Elastic search and logstash](https://discuss.elastic.co/t/ssl-communication-issue-for-elastic-search-and-logstash/326644)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 5:08am UTC](https://discuss.elastic.co/t/ssl-communication-issue-for-elastic-search-and-logstash/326644 "2023-02-28T05:08:31Z")

</div>

Log stash not able comm with Elastic search pls find the below logs for Elasticsearch and Logstash Elastic search: dress=/10.244.0.53:9200, remoteAddress=/10.224.0.5:48848}", "ecs.version": "1.2.0","service.name":"ES\_E…

---

## [Apply new ILM to managed index template FAILED](https://discuss.elastic.co/t/apply-new-ilm-to-managed-index-template-failed/325789)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 7\
**Last updated:** [February 28, 2023, 2:02am UTC](https://discuss.elastic.co/t/apply-new-ilm-to-managed-index-template-failed/325789 "2023-02-28T02:02:45Z")

</div>

I have a time series data stream, it has a managed index template and it was configured to "logs ILM" by default. I want to use another ILM and I changed the index template configure by "Edit" in Index Management and ad…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[log-\*\*-au-uat-buyer-server\] does not point to index \[log-\*\*-au-uat-buyer-server-2022.11\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-log-au-uat-buyer-server-does-not-point-to-index-log-au-uat-buyer-server-2022-11/326636)

<div class="topic-metadata">

**Author:** [@deepthi.manam](https://discuss.elastic.co/u/deepthi.manam)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 12:05am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-log-au-uat-buyer-server-does-not-point-to-index-log-au-uat-buyer-server-2022-11/326636 "2023-02-28T00:05:46Z")

</div>

Hi there, I'm getting this exception on some of my indices "illegal\_argument\_exception: index.lifecycle.rollover\_alias \[log--au-uat-buyer-server\] does not point to index \[log--au-uat-buyer-server-2022.11\]. Can you please…

---

## [Is there any problem that set ES heap size to 64G?](https://discuss.elastic.co/t/is-there-any-problem-that-set-es-heap-size-to-64g/326546)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 10:46pm UTC](https://discuss.elastic.co/t/is-there-any-problem-that-set-es-heap-size-to-64g/326546 "2023-02-27T22:46:26Z")

</div>

My machine has 512G memory, and i only need 2 ES nodes( 2 shards is enough for my index). So, is there any problem that set ES heap size to 64G or more bigger?

---

## [Unable to retrieve version information from Elasticsearch nodes. connect ECONNREFUSED 192.168.100.5:9200](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-connect-econnrefused-192-168-100-5-9200/326562)

<div class="topic-metadata">

**Author:** [@flapjack365](https://discuss.elastic.co/u/flapjack365)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 10:45pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-connect-econnrefused-192-168-100-5-9200/326562 "2023-02-27T22:45:50Z")

</div>

Hi All, A few days ago I've successfully setup Elasticsearch and kibana on my local machine. I was reaching out :5601 and I've managed to create a few indices. Today Kibana returns "Kibana server is not ready yet." Wh…

---

## [Configuration to maximize resoration performance](https://discuss.elastic.co/t/configuration-to-maximize-resoration-performance/326610)

<div class="topic-metadata">

**Author:** [@kronx12](https://discuss.elastic.co/u/kronx12)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 3:17pm UTC](https://discuss.elastic.co/t/configuration-to-maximize-resoration-performance/326610 "2023-02-27T15:17:22Z")

</div>

Hi everyone, I have actually setup elasticsearch on an ec2 instance, I currently have 16 cores, 32GB of ram and for the storage I use an gp3 EBS volume of a 1TB but the problem is the next: I need to restore a massive …

---

## [Slow searches after changing daily to weekly indexes](https://discuss.elastic.co/t/slow-searches-after-changing-daily-to-weekly-indexes/326563)

<div class="topic-metadata">

**Author:** [@filipe-m-claudio](https://discuss.elastic.co/u/filipe-m-claudio)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 10:22pm UTC](https://discuss.elastic.co/t/slow-searches-after-changing-daily-to-weekly-indexes/326563 "2023-02-27T22:22:38Z")

</div>

Currently the configuration is set to daily indices in a single-node, so we decided to move to weekly indices in order to reduce the number of shards in the cluster. Most of the time the client wants a 6 month history, …

---

## [Red Cluster Health - Unsure How to Fix](https://discuss.elastic.co/t/red-cluster-health-unsure-how-to-fix/326464)

<div class="topic-metadata">

**Author:** [@bcantrell](https://discuss.elastic.co/u/bcantrell)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 10:08pm UTC](https://discuss.elastic.co/t/red-cluster-health-unsure-how-to-fix/326464 "2023-02-27T22:08:28Z")

</div>

Hi all, I have been trying to figure out a problem where my Kibana is not able to keep connections alive with the Elasticsearch instance, and I think it is because of red cluster/index health. When Kibana is running, I …

---

## [Search as you type for documents with digits, unicode and special characters](https://discuss.elastic.co/t/search-as-you-type-for-documents-with-digits-unicode-and-special-characters/326005)

<div class="topic-metadata">

**Author:** [@zdebyman](https://discuss.elastic.co/u/zdebyman)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 9:46pm UTC](https://discuss.elastic.co/t/search-as-you-type-for-documents-with-digits-unicode-and-special-characters/326005 "2023-02-27T21:46:26Z")

</div>

Hi! Im very new to the ES and while learning and playing around with it, I got stuck with a problem that i'm not sure how to solve. REQUIREMENT I'm trying to build search-as-you-type autocomplete. I have a table with o…

---

## [Query on Logstash S3 input](https://discuss.elastic.co/t/query-on-logstash-s3-input/325964)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 9:13pm UTC](https://discuss.elastic.co/t/query-on-logstash-s3-input/325964 "2023-02-27T21:13:39Z")

</div>

Hi Team, I wanted some clarification on the Logstash S3 input plugin behaviour. There is an option of "sincedb\_path" where as per documentation, it defines where to write the since database (keeps track of the date the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=617)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=619)
