# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=621

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 622

---

## [Logstash.licensechecker.licensereader: elasticsearch: Name or service not known](https://discuss.elastic.co/t/logstash-licensechecker-licensereader-elasticsearch-name-or-service-not-known/326462)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 6:53pm UTC](https://discuss.elastic.co/t/logstash-licensechecker-licensereader-elasticsearch-name-or-service-not-known/326462 "2023-02-24T18:53:33Z")

</div>

Apologies for all of the questions recently and huge thanks to everyone who has responded and helped me get this far. At this point I have logs being passed from a Render web server to a private service running Logstash …

---

## [Logstash is failing with file not found - 'cat JDK\_VERSION' when "LS\_JAVA\_HOME" is set](https://discuss.elastic.co/t/logstash-is-failing-with-file-not-found-cat-jdk-version-when-ls-java-home-is-set/326407)

<div class="topic-metadata">

**Author:** [@skumarp7](https://discuss.elastic.co/u/skumarp7)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 5:23pm UTC](https://discuss.elastic.co/t/logstash-is-failing-with-file-not-found-cat-jdk-version-when-ls-java-home-is-set/326407 "2023-02-24T17:23:47Z")

</div>

Hi, Logstash RPM used: 8.6.1 We have built a docker image with the logstash rpm and running the container in our kubernetes cluster We are exporting LS\_JAVA\_HOME env in the container to the jdk already installed as a …

---

## [Add any 2 Index to form new index which will combined data and should not override any fields values](https://discuss.elastic.co/t/add-any-2-index-to-form-new-index-which-will-combined-data-and-should-not-override-any-fields-values/326173)

<div class="topic-metadata">

**Author:** [@Mangesh\_Mathe](https://discuss.elastic.co/u/Mangesh_Mathe)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 5:09pm UTC](https://discuss.elastic.co/t/add-any-2-index-to-form-new-index-which-will-combined-data-and-should-not-override-any-fields-values/326173 "2023-02-24T17:09:46Z")

</div>

Hello All, I want to merge two Index with same structure , which will create 3rd Index without overriding field values. For example: index\_1: "businessUnits": "FR,JP,IE" index\_2: "businessUnits": "FR,GB,DE" If I m…

---

## [Filebeat still sending logs even if service is stopped](https://discuss.elastic.co/t/filebeat-still-sending-logs-even-if-service-is-stopped/326029)

<div class="topic-metadata">

**Author:** [@Azkiel19](https://discuss.elastic.co/u/Azkiel19)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:43pm UTC](https://discuss.elastic.co/t/filebeat-still-sending-logs-even-if-service-is-stopped/326029 "2023-02-24T16:43:20Z")

</div>

Hi, I'm new to Filebeats and the ELK stack. To provide an overview, our setup uses: Filebeat -\> sends to Logstash -\> sends to Elastic Search I expected that once I turned off / stop the filebeat service from running …

---

## [Kibana server connection to browser multi-domains trusted certificates](https://discuss.elastic.co/t/kibana-server-connection-to-browser-multi-domains-trusted-certificates/326457)

<div class="topic-metadata">

**Author:** [@IamYipi](https://discuss.elastic.co/u/IamYipi)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 4:22pm UTC](https://discuss.elastic.co/t/kibana-server-connection-to-browser-multi-domains-trusted-certificates/326457 "2023-02-24T16:22:53Z")

</div>

Hello, I'm trying to install in my kibana server two different certificates for two different domains where can connect to kibana. Example: Domain 1: example1.com Certificates: example.crt example.key example.ca …

---

## [Bug Report: Alert behaviour after deleting its rule](https://discuss.elastic.co/t/bug-report-alert-behaviour-after-deleting-its-rule/326416)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 4:25pm UTC](https://discuss.elastic.co/t/bug-report-alert-behaviour-after-deleting-its-rule/326416 "2023-02-24T16:25:54Z")

</div>

Hi, would like to report a bug if this is the right place to do so. Environment : Elasticsearch & Kibana 8.6.1 Debian 11 Reproduction steps: Create a new alerting rule in Observability Trigger the alert to be active …

---

## [Logs are not coming for every half n hour](https://discuss.elastic.co/t/logs-are-not-coming-for-every-half-n-hour/326402)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:16pm UTC](https://discuss.elastic.co/t/logs-are-not-coming-for-every-half-n-hour/326402 "2023-02-24T16:16:20Z")

</div>

Hi Team, Since today morning logs in kibana are coming and then going off . This is the third time in a single day. Could anyone please help.

---

## [Why does aggregation contain ID's that don't exist in the query results?](https://discuss.elastic.co/t/why-does-aggregation-contain-ids-that-dont-exist-in-the-query-results/326445)

<div class="topic-metadata">

**Author:** [@A\_K3](https://discuss.elastic.co/u/A_K3)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:08pm UTC](https://discuss.elastic.co/t/why-does-aggregation-contain-ids-that-dont-exist-in-the-query-results/326445 "2023-02-24T16:08:10Z")

</div>

To gather data on how many documents have been prepared by some employee in a given time period, I have written this query: { "from": 0, "size": 0, "sort": \[\], "query": { "bool": { "must": \[ { …

---

## [Unable to see trace id or transaction info in logs](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 4:01pm UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375 "2023-02-24T16:01:44Z")

</div>

I currently have a NodeJS server passing logs to a Logstash server with a TCP tunnel using a Winston transport. Logs make it through all the way to my Elastic Cloud hosted Elasticsearch and pretty much everything looks g…

---

## [Different values using date histogram](https://discuss.elastic.co/t/different-values-using-date-histogram/326453)

<div class="topic-metadata">

**Author:** [@bcamboim](https://discuss.elastic.co/u/bcamboim)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 3:15pm UTC](https://discuss.elastic.co/t/different-values-using-date-histogram/326453 "2023-02-24T15:15:26Z")

</div>

Hi everyone. I'am using the package @elastic/elasticsearch (^7.9.1) to do queries in my cluster. I have a dashboard showing the concurrent users using my videos platform. My query is: { query: { bool: { …

---

## [How to get a series aggregation in Lens?](https://discuss.elastic.co/t/how-to-get-a-series-aggregation-in-lens/326438)

<div class="topic-metadata">

**Author:** [@Rick\_V](https://discuss.elastic.co/u/Rick_V)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 1:00pm UTC](https://discuss.elastic.co/t/how-to-get-a-series-aggregation-in-lens/326438 "2023-02-24T13:00:31Z")

</div>

Hi, Currently i am using a TSVB visualization with a series aggregation like described in this post to visualize apm data, it shows the duration of a series of transactions. The aggregation first takes the average of t…

---

## [Migrate backups from S3 to GCP](https://discuss.elastic.co/t/migrate-backups-from-s3-to-gcp/326447)

<div class="topic-metadata">

**Author:** [@Pete1](https://discuss.elastic.co/u/Pete1)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 2:28pm UTC](https://discuss.elastic.co/t/migrate-backups-from-s3-to-gcp/326447 "2023-02-24T14:28:54Z")

</div>

Hello, I want to copy all of my backups that have been made using the s3 plugin to Google Cloud Storage. I tried to copy them just like that, but it seems that this is not the way to do it. Is there a tool or is there so…

---

## [Ingest Pipeline with filebeat not working](https://discuss.elastic.co/t/ingest-pipeline-with-filebeat-not-working/326357)

<div class="topic-metadata">

**Author:** [@heisenberg93](https://discuss.elastic.co/u/heisenberg93)\
**Replies:** 4\
**Last updated:** [February 24, 2023, 2:28pm UTC](https://discuss.elastic.co/t/ingest-pipeline-with-filebeat-not-working/326357 "2023-02-24T14:28:07Z")

</div>

Hi, We have a few Linux hosts which monitor each other with Pacemaker. Here we would like to evaluate the pacemaker.log for this. With Filebeat the log arrives, but the message is not yet analyzable. Therefore I thought…

---

## [Unable to start elasticsearch 7.11.0](https://discuss.elastic.co/t/unable-to-start-elasticsearch-7-11-0/326342)

<div class="topic-metadata">

**Author:** [@anandgavai](https://discuss.elastic.co/u/anandgavai)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 2:27pm UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-7-11-0/326342 "2023-02-24T14:27:10Z")

</div>

Hi there, am getting an ElasticsearchUncaughtExceptionHandler error and not able to start elasticsearch. All I know was there was there was an abrupt shutdown of my server and since then am not able to start the elastic…

---

## [Pyspark-Elasticsearch connectivity and latest version compatibilty](https://discuss.elastic.co/t/pyspark-elasticsearch-connectivity-and-latest-version-compatibilty/325289)

<div class="topic-metadata">

**Author:** [@Bramha](https://discuss.elastic.co/u/Bramha)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 2:24pm UTC](https://discuss.elastic.co/t/pyspark-elasticsearch-connectivity-and-latest-version-compatibilty/325289 "2023-02-24T14:24:12Z")

</div>

Hello All, I'm trying to use elasticsearch as a source in my poc. I'm using Python-3.10.10, Spark 3.3.0. I'm using Jupyter notebook below is my code: from pyspark import SparkConf, SparkContext conf = SparkConf() c…

---

## [Aggregations: Getting accurate counts for filter panel](https://discuss.elastic.co/t/aggregations-getting-accurate-counts-for-filter-panel/326433)

<div class="topic-metadata">

**Author:** [@MonikaJ](https://discuss.elastic.co/u/MonikaJ)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 11:23am UTC](https://discuss.elastic.co/t/aggregations-getting-accurate-counts-for-filter-panel/326433 "2023-02-24T11:23:09Z")

</div>

Many searches provide a standard filter panel on the left, that allows filtering by OR within a category and AND between categories. The logic the counts that are shown for every filter entry follows the following standa…

---

## [Configure Elasticsearch on Django App](https://discuss.elastic.co/t/configure-elasticsearch-on-django-app/326320)

<div class="topic-metadata">

**Author:** [@ekane3](https://discuss.elastic.co/u/ekane3)\
**Replies:** 8\
**Last updated:** [February 24, 2023, 1:31pm UTC](https://discuss.elastic.co/t/configure-elasticsearch-on-django-app/326320 "2023-02-24T13:31:52Z")

</div>

:wave: Hello everyone, I have been trying for weeks now to configure Elasticsearch/logstash on my Django app. But, all the tutorials i found are dealing with local elasticsearch meanwhile the one i’m dealing with is a…

---

## [Display a simple ratio](https://discuss.elastic.co/t/display-a-simple-ratio/326345)

<div class="topic-metadata">

**Author:** [@lamdba](https://discuss.elastic.co/u/lamdba)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 1:28pm UTC](https://discuss.elastic.co/t/display-a-simple-ratio/326345 "2023-02-24T13:28:38Z")

</div>

Hello there, Driving me crazy, I'm trying to show a small indicator with all the data I've in my dataset. logically, it seems extremely easy to produce, but I can't figure how it can be done in Kibana. { "\_index": "m…

---

## [Records Limits on upload](https://discuss.elastic.co/t/records-limits-on-upload/326442)

<div class="topic-metadata">

**Author:** [@IceF1reX](https://discuss.elastic.co/u/IceF1reX)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 1:26pm UTC](https://discuss.elastic.co/t/records-limits-on-upload/326442 "2023-02-24T13:26:18Z")

</div>

How to increase or remove records limits from simultaneous upload in C# ?? For 300 000 and more

---

## [Not able to connect to Elastic search from logstash](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-search-from-logstash/326267)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 4\
**Last updated:** [February 24, 2023, 1:11pm UTC](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-search-from-logstash/326267 "2023-02-24T13:11:51Z")

</div>

iam getting below error after running logstash pod Using bundled JDK: /usr/share/logstash/jdk Sending Logstash logs to /usr/share/logstash/logs which is now configured via log4j2.properties \[2023-02-23T06:44:35,912\]\[I…

---

## [Logstash plugin had an unrecoverable error. Will restart this plugin](https://discuss.elastic.co/t/logstash-plugin-had-an-unrecoverable-error-will-restart-this-plugin/326220)

<div class="topic-metadata">

**Author:** [@Vinicius\_Carmo](https://discuss.elastic.co/u/Vinicius_Carmo)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logstash-plugin-had-an-unrecoverable-error-will-restart-this-plugin/326220 "2023-02-24T12:39:56Z")

</div>

Hello everyone, I need help I tried using the Microsoft-sentinel plugin output logstash. but I get an error: A plugin had an unrecoverable error. Will restart this plugin Error: address already in use I used two outp…

---

## [SocketException on \_bulk request working in curl but not in restTemplate](https://discuss.elastic.co/t/socketexception-on-bulk-request-working-in-curl-but-not-in-resttemplate/326437)

<div class="topic-metadata">

**Author:** [@D1sturbance](https://discuss.elastic.co/u/D1sturbance)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 12:12pm UTC](https://discuss.elastic.co/t/socketexception-on-bulk-request-working-in-curl-but-not-in-resttemplate/326437 "2023-02-24T12:12:49Z")

</div>

Hello, I have problems with \_bulk request throwing Connection reset by peer: socket write error; nested exception is javax.net.ssl.SSLProtocolException. I've read and know about bulk size and etc... So that's not an is…

---

## [Historic tomcat access logs transform historic timestamp to @timestamp](https://discuss.elastic.co/t/historic-tomcat-access-logs-transform-historic-timestamp-to-timestamp/325862)

<div class="topic-metadata">

**Author:** [@flomickl](https://discuss.elastic.co/u/flomickl)\
**Replies:** 6\
**Last updated:** [February 21, 2023, 11:57pm UTC](https://discuss.elastic.co/t/historic-tomcat-access-logs-transform-historic-timestamp-to-timestamp/325862 "2023-02-21T23:57:14Z")

</div>

Hi, I have some historic tomcat log files like 172.x.x.xx - - \[19/Dec/2022:23:59:58 +0100\] "POST /url/text/json HTTP/1.1" 200 348 I have already a Logstash grok pattern but I have a problem with the correct timestamp. …

---

## [Missing client level settings in high level rest client while migrating to transport client](https://discuss.elastic.co/t/missing-client-level-settings-in-high-level-rest-client-while-migrating-to-transport-client/326415)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 10:13am UTC](https://discuss.elastic.co/t/missing-client-level-settings-in-high-level-rest-client-while-migrating-to-transport-client/326415 "2023-02-24T10:13:52Z")

</div>

Hey Team, I am upgrading from transport client to high level rest client and there are some client level settings I could not find in high level rest client. I was able to upgrade almost all the code but was not able t…

---

## [Failed to clean async result](https://discuss.elastic.co/t/failed-to-clean-async-result/326347)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 10:13am UTC](https://discuss.elastic.co/t/failed-to-clean-async-result/326347 "2023-02-24T10:13:23Z")

</div>

Hi I met the case on transport transport\_worker in my workflow ingest node (mem capacity 36GB) received data from source and the next this data should be relocated on data nodes (16GB) Can we control bulk of data betw…

---

## [Control filter in kibana doesnt work properly](https://discuss.elastic.co/t/control-filter-in-kibana-doesnt-work-properly/326160)

<div class="topic-metadata">

**Author:** [@Apoorva\_Shandilya](https://discuss.elastic.co/u/Apoorva_Shandilya)\
**Replies:** 7\
**Last updated:** [February 24, 2023, 9:15am UTC](https://discuss.elastic.co/t/control-filter-in-kibana-doesnt-work-properly/326160 "2023-02-24T09:15:41Z")

</div>

Hi I am a beginner here . Currently, we use Control Filter in Kibana Dashboards, but this filter doesn't work as we expected, so that it can't recommend us what are the available values for each field. which are the o…

---

## [Where to find the generated CSV report](https://discuss.elastic.co/t/where-to-find-the-generated-csv-report/326395)

<div class="topic-metadata">

**Author:** [@ashd](https://discuss.elastic.co/u/ashd)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 9:09am UTC](https://discuss.elastic.co/t/where-to-find-the-generated-csv-report/326395 "2023-02-24T09:09:43Z")

</div>

How can I access the CSV reports that were generated? What are the step to access them?!

---

## [Use Elastic GET script output in Lens (or TSVB) panel](https://discuss.elastic.co/t/use-elastic-get-script-output-in-lens-or-tsvb-panel/326349)

<div class="topic-metadata">

**Author:** [@ivh](https://discuss.elastic.co/u/ivh)\
**Replies:** 5\
**Last updated:** [February 24, 2023, 8:37am UTC](https://discuss.elastic.co/t/use-elastic-get-script-output-in-lens-or-tsvb-panel/326349 "2023-02-24T08:37:50Z")

</div>

Hello! Tried solving this via an Elastic Support case, got nowhere ... hoping the community can help. I have a working GET script that successfully retrieves a single document (from an entire index) that contains the ma…

---

## [\[Filebeat 8.6.1 - httpjson\] invalid memory address or nil pointer dereference](https://discuss.elastic.co/t/filebeat-8-6-1-httpjson-invalid-memory-address-or-nil-pointer-dereference/326365)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 8:19am UTC](https://discuss.elastic.co/t/filebeat-8-6-1-httpjson-invalid-memory-address-or-nil-pointer-dereference/326365 "2023-02-24T08:19:25Z")

</div>

Hello, I try to use httpjson with "chain" and "steps" but I'm stuck on this error "invalid memory address or nil pointer dereference". Here is what I did: a simple httpjson to call an API and get host IDs filebeat.i…

---

## [Use the correct datatype fields](https://discuss.elastic.co/t/use-the-correct-datatype-fields/326290)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 4\
**Last updated:** [February 24, 2023, 7:59am UTC](https://discuss.elastic.co/t/use-the-correct-datatype-fields/326290 "2023-02-24T07:59:01Z")

</div>

Hey there, I would like just to get a suggestion. If I have a field that contains only ip addresses and it is used for standard match query, should be better to map it with the ip datatype or is it not relevant? is the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=620)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=622)
