# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=627

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 628

---

## [High Vulnerabilities found in Elasticsearch docker image v7.17.9](https://discuss.elastic.co/t/high-vulnerabilities-found-in-elasticsearch-docker-image-v7-17-9/325976)

<div class="topic-metadata">

**Author:** [@hexer338](https://discuss.elastic.co/u/hexer338)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:58pm UTC](https://discuss.elastic.co/t/high-vulnerabilities-found-in-elasticsearch-docker-image-v7-17-9/325976 "2023-02-20T20:58:46Z")

</div>

Hi Elastic Team, We used aquasec's trivy scan(Trivy) to do vuln. scan on elasticsearch docker image: docker.elastic.co/elasticsearch/elasticsearch:7.17.9 We found 4 HIGH severity vulnerabilities below: CVE-2023-0286 …

---

## [Using Arithmetic in pipeline.yml Processor](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725)

<div class="topic-metadata">

**Author:** [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 6:11pm UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725 "2023-02-20T18:11:52Z")

</div>

Hello, I'm appointed to update or rewriting an old ELK project. In the old version we used Logstash and its corresponding 'filebeat.cfg' file. I was rebuilding an IngestPipeline in a 'pipeline.yml'. In Losgtash we had f…

---

## [Elasticsearch data nodes - disk usage optimisation](https://discuss.elastic.co/t/elasticsearch-data-nodes-disk-usage-optimisation/325544)

<div class="topic-metadata">

**Author:** [@chethan\_m](https://discuss.elastic.co/u/chethan_m)\
**Replies:** 5\
**Last updated:** [February 20, 2023, 5:36pm UTC](https://discuss.elastic.co/t/elasticsearch-data-nodes-disk-usage-optimisation/325544 "2023-02-20T17:36:15Z")

</div>

I have an elasticsearch deployed on kubenetes/aws platform. I'm observing that Disk Free Space is not equal in the data nodes. I have 4 data nodes out of which, Two data nodes have around 1 TB free disk space One …

---

## [Matching ip address](https://discuss.elastic.co/t/matching-ip-address/325992)

<div class="topic-metadata">

**Author:** [@Lalii](https://discuss.elastic.co/u/Lalii)\
**Replies:** 4\
**Last updated:** [February 20, 2023, 4:55pm UTC](https://discuss.elastic.co/t/matching-ip-address/325992 "2023-02-20T16:55:01Z")

</div>

Hello everyone, I'm trying to do a condition on IP regex. Trying to match every IPs if \[destination.XXX\] =~ /^\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}$/ { mutate { ... } } I tried the solution from that post but doesnt wor…

---

## [Issues enabling Logstash logs integration for ELK stack](https://discuss.elastic.co/t/issues-enabling-logstash-logs-integration-for-elk-stack/325993)

<div class="topic-metadata">

**Author:** [@Joshua\_Sheathelm](https://discuss.elastic.co/u/Joshua_Sheathelm)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 4:13pm UTC](https://discuss.elastic.co/t/issues-enabling-logstash-logs-integration-for-elk-stack/325993 "2023-02-20T16:13:23Z")

</div>

I am currently configuring an ELK stack with three separate hosts for each service (Elastic search on one host, Logstash on another, and Kibana on the last) I have verified that Elasticsearch and Kibana are accessible fr…

---

## [Visualization of parts of URL](https://discuss.elastic.co/t/visualization-of-parts-of-url/324769)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 4:09pm UTC](https://discuss.elastic.co/t/visualization-of-parts-of-url/324769 "2023-02-20T16:09:57Z")

</div>

I am using ECK. I have created request PATHs visualization in Kibana. One of the URL has the format of /products/product-brand/\<brand\>. How can I create a visualization on parts of the URL like \<brand\>?

---

## [Not an int hash when using Murmur3](https://discuss.elastic.co/t/not-an-int-hash-when-using-murmur3/324902)

<div class="topic-metadata">

**Author:** [@divadpoc](https://discuss.elastic.co/u/divadpoc)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 3:09pm UTC](https://discuss.elastic.co/t/not-an-int-hash-when-using-murmur3/324902 "2023-02-20T15:09:12Z")

</div>

I've tried the Fingerprint filter plugin w/ the MURMUR3 method. If set to MURMUR3 or MURMUR3\_128 the non-cryptographic MurmurHash function (either the 32-bit or 128-bit implementation, respectively) will be used. So …

---

## [Kibana UI Change](https://discuss.elastic.co/t/kibana-ui-change/325938)

<div class="topic-metadata">

**Author:** [@Ajay\_Kotnala](https://discuss.elastic.co/u/Ajay_Kotnala)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 1:00pm UTC](https://discuss.elastic.co/t/kibana-ui-change/325938 "2023-02-20T13:00:54Z")

</div>

Is there a way to remove the option toggle dialog with the details option in Kibana UI. Need to rollback to older layout.

---

## [How to Access Field that made by Scripted field](https://discuss.elastic.co/t/how-to-access-field-that-made-by-scripted-field/324610)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 8:02am UTC](https://discuss.elastic.co/t/how-to-access-field-that-made-by-scripted-field/324610 "2023-02-03T08:02:43Z")

</div>

Hi everyone, i've been made scripted field like this: From the script, it generates field named expire\_days with number data type and I have also created an alert that points to this index. The problem is if i wan…

---

## [Details of Elasticserver receiving logs](https://discuss.elastic.co/t/details-of-elasticserver-receiving-logs/325969)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 12:45pm UTC](https://discuss.elastic.co/t/details-of-elasticserver-receiving-logs/325969 "2023-02-20T12:45:13Z")

</div>

Hi flocks, We have a fresh ELK stack and now I am trying to create a details dashboard for ES receiving logs daily, weekly and monthly, so we do not have much indexes but default ones. since I am new to this subject is …

---

## [Aliases API : error deleting index](https://discuss.elastic.co/t/aliases-api-error-deleting-index/325265)

<div class="topic-metadata">

**Author:** [@quentin.renoux](https://discuss.elastic.co/u/quentin.renoux)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 12:36pm UTC](https://discuss.elastic.co/t/aliases-api-error-deleting-index/325265 "2023-02-20T12:36:06Z")

</div>

Hi everyone, TL;DR : the \_aliases API throw error trying to remove index saying it doesn't exist but it does. I'm using the aliases API to swap two indices behind an alias in a single atomic operation. I'm following th…

---

## [Interruptions of Metricbeat Metrics in Kibana](https://discuss.elastic.co/t/interruptions-of-metricbeat-metrics-in-kibana/325580)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:56am UTC](https://discuss.elastic.co/t/interruptions-of-metricbeat-metrics-in-kibana/325580 "2023-02-15T09:56:58Z")

</div>

Hi team, i am working for several months on metricbeat in k8s i installed on 3 azure kubernetes cluster metricbeat and i saw it not showing the metrics correctly or with some interruptions each cluster has between 3 …

---

## [Kibana fleet management: failed to decrypt attribute ssl](https://discuss.elastic.co/t/kibana-fleet-management-failed-to-decrypt-attribute-ssl/324881)

<div class="topic-metadata">

**Author:** [@Jesse\_Geens](https://discuss.elastic.co/u/Jesse_Geens)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 10:06am UTC](https://discuss.elastic.co/t/kibana-fleet-management-failed-to-decrypt-attribute-ssl/324881 "2023-02-07T10:06:42Z")

</div>

Hello, I am trying to configure my elastic fleet such that elastic agents connect to a logstash instance, secured with SSL. I set up the SSL for logstash, and was now trying to configure the agents. To make sure that th…

---

## [How to use request.ssl in Filebeat httpjson Input](https://discuss.elastic.co/t/how-to-use-request-ssl-in-filebeat-httpjson-input/325966)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 11:35am UTC](https://discuss.elastic.co/t/how-to-use-request-ssl-in-filebeat-httpjson-input/325966 "2023-02-20T11:35:50Z")

</div>

Hi there, i want to know how using request.ssl in Filebeat input on httpjson type. So, here's an overview of the config I made: filebeat.inputs: - type: httpjson config\_version: 2 request.url: https://192.168.0.217:…

---

## [Kibana UI Not Accessible](https://discuss.elastic.co/t/kibana-ui-not-accessible/325904)

<div class="topic-metadata">

**Author:** [@altif](https://discuss.elastic.co/u/altif)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 11:12am UTC](https://discuss.elastic.co/t/kibana-ui-not-accessible/325904 "2023-02-20T11:12:24Z")

</div>

Greetings, I'm a Kibana novice who recently imported saved-objects via the Kibana UI. However, upon importing the saved-objects JSON file, I encountered an error as illustrated in the attached screenshot. Whenever I…

---

## [Mapper\_parsing\_exception](https://discuss.elastic.co/t/mapper-parsing-exception/325962)

<div class="topic-metadata">

**Author:** [@Roshan\_M\_Thomas](https://discuss.elastic.co/u/Roshan_M_Thomas)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 11:04am UTC](https://discuss.elastic.co/t/mapper-parsing-exception/325962 "2023-02-20T11:04:53Z")

</div>

Hi , getting this error in elastic 7.8.1 and 8.0.0 while inserting mapping using PUT method. Please help us to resolve it. { "error": { "root\_cause": \[ { "type": "mapper\_parsing\_exception", "reason": "Root mapping …

---

## [Elasticsearch creates empty directories in /tmp, can I delete these empty directories](https://discuss.elastic.co/t/elasticsearch-creates-empty-directories-in-tmp-can-i-delete-these-empty-directories/325887)

<div class="topic-metadata">

**Author:** [@eranga\_bandara](https://discuss.elastic.co/u/eranga_bandara)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:59am UTC](https://discuss.elastic.co/t/elasticsearch-creates-empty-directories-in-tmp-can-i-delete-these-empty-directories/325887 "2023-02-20T08:59:47Z")

</div>

Elasticsearch creates directories inside /tmp. These directories used to execute native code by jna and libffi. Most of the time these directories are empty and have the name like elasticsearch.KNoHBn19. more info here. …

---

## [How to store Key value pairs and visualize in Kibana?](https://discuss.elastic.co/t/how-to-store-key-value-pairs-and-visualize-in-kibana/325888)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 10:14am UTC](https://discuss.elastic.co/t/how-to-store-key-value-pairs-and-visualize-in-kibana/325888 "2023-02-20T10:14:12Z")

</div>

Hi, I am trying to store key value pairs into Elasticsearch and visualize in Kibana. I am new to Elastic so sorry if the question is dumb. So here's my data { "mappings": { "properties": { "Topics": {"type…

---

## [How to check the index size on daily basis using python scripts?](https://discuss.elastic.co/t/how-to-check-the-index-size-on-daily-basis-using-python-scripts/325377)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 9:48am UTC](https://discuss.elastic.co/t/how-to-check-the-index-size-on-daily-basis-using-python-scripts/325377 "2023-02-20T09:48:01Z")

</div>

Hi, Does anyone know how to check the index size on daily basis using python scripts?

---

## [Need help to create active directory alerts in Kibana](https://discuss.elastic.co/t/need-help-to-create-active-directory-alerts-in-kibana/325102)

<div class="topic-metadata">

**Author:** [@abhi\_tcs](https://discuss.elastic.co/u/abhi_tcs)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:27am UTC](https://discuss.elastic.co/t/need-help-to-create-active-directory-alerts-in-kibana/325102 "2023-02-09T07:27:11Z")

</div>

Hello All, I am new to ELK stack. I need to create Active Directory related alerts in Kibana for below test cases. Can someone help me. Account lockout Account Disable Regards, AB

---

## [When Downloading CSV, one variable value's is getting in two different column because of comma](https://discuss.elastic.co/t/when-downloading-csv-one-variable-values-is-getting-in-two-different-column-because-of-comma/324984)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 5\
**Last updated:** [February 20, 2023, 9:25am UTC](https://discuss.elastic.co/t/when-downloading-csv-one-variable-values-is-getting-in-two-different-column-because-of-comma/324984 "2023-02-20T09:25:07Z")

</div>

When Downloading CSV from Tabular format, each variable is getting separated with Comma (,). Due to this variable which are numerical values (for e.g., 2,946) are also getting in different columns. As shown in below ima…

---

## [Unable to get real time logs for Elastic-Github Integration](https://discuss.elastic.co/t/unable-to-get-real-time-logs-for-elastic-github-integration/324993)

<div class="topic-metadata">

**Author:** [@Pallavi\_Kshirsagar](https://discuss.elastic.co/u/Pallavi_Kshirsagar)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 10:09am UTC](https://discuss.elastic.co/t/unable-to-get-real-time-logs-for-elastic-github-integration/324993 "2023-02-08T10:09:39Z")

</div>

I've performed Github integration using elastic agent, where I'm running the agent on an EC2 instance. When I go to Discover the logs I see that logs aren't pulled in real time and I get to see too old logs until a certa…

---

## [Two data folder present](https://discuss.elastic.co/t/two-data-folder-present/325834)

<div class="topic-metadata">

**Author:** [@dev\_sab](https://discuss.elastic.co/u/dev_sab)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:59am UTC](https://discuss.elastic.co/t/two-data-folder-present/325834 "2023-02-20T08:59:00Z")

</div>

Hello All, I am having the scenario two data folder present. I have accidently changed the path.data in elasticsearch.yml file. So, Two data folder present, one with old data and another with new data. I need to merge …

---

## [How to find a missing word in elastic search query](https://discuss.elastic.co/t/how-to-find-a-missing-word-in-elastic-search-query/325351)

<div class="topic-metadata">

**Author:** [@Jude\_Jerome](https://discuss.elastic.co/u/Jude_Jerome)\
**Replies:** 7\
**Last updated:** [February 20, 2023, 7:06am UTC](https://discuss.elastic.co/t/how-to-find-a-missing-word-in-elastic-search-query/325351 "2023-02-20T07:06:39Z")

</div>

Hello Team, I have a 100 + applications which sending logs daily. I want to filter out the application which does not have a specific word. For example if a application log does not have success keyword then i need to f…

---

## [Logstash masking logs syntax](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699)

<div class="topic-metadata">

**Author:** [@furkano](https://discuss.elastic.co/u/furkano)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 5:32am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699 "2023-02-20T05:32:58Z")

</div>

Hi, I want to mask some logs in spesific fields, for example if end point ends with api or token i want to remove userKey messages from field ResponseMessage But not whole field that i want to remove or mask, only the …

---

## [Elasticsearch error all shards failed on single node](https://discuss.elastic.co/t/elasticsearch-error-all-shards-failed-on-single-node/325812)

<div class="topic-metadata">

**Author:** [@yc99](https://discuss.elastic.co/u/yc99)\
**Replies:** 6\
**Last updated:** [February 20, 2023, 3:19am UTC](https://discuss.elastic.co/t/elasticsearch-error-all-shards-failed-on-single-node/325812 "2023-02-20T03:19:13Z")

</div>

Caused by: org.elasticsearch.action.NoShardAvailableActionException: \[ip-13-35-23-200.ap-1.compute.internal\]\[13.35.23.200:9300\]\[indices:data/read/search\[phase/query\]\] \[2023-02-17T08:14:15,934\]\[WARN \]\[r.suppressed …

---

## [Beginner’s Crash Course to Elastic Stack - Part 4: Aggregations | Issues with data](https://discuss.elastic.co/t/beginner-s-crash-course-to-elastic-stack-part-4-aggregations-issues-with-data/325902)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 4\
**Last updated:** [February 20, 2023, 3:13am UTC](https://discuss.elastic.co/t/beginner-s-crash-course-to-elastic-stack-part-4-aggregations-issues-with-data/325902 "2023-02-20T03:13:24Z")

</div>

After importing the data.csv file and running the STEP 1: Create a new index(ecommerce\_data) with the following mapping., I am getting an error: { "error": { "root\_cause": \[ { "type": "resource\_already\_exists\_except…

---

## [Watcher search on multiple terms and action depending on conditional result](https://discuss.elastic.co/t/watcher-search-on-multiple-terms-and-action-depending-on-conditional-result/325868)

<div class="topic-metadata">

**Author:** [@mape](https://discuss.elastic.co/u/mape)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 9:11pm UTC](https://discuss.elastic.co/t/watcher-search-on-multiple-terms-and-action-depending-on-conditional-result/325868 "2023-02-17T21:11:03Z")

</div>

Hi. What I am trying to achieve is: Use a search query to find all events where field status code = 400 OR 401 OR 403, AND field servicegroup is one of 6 options AND if the count of events is \> 300 if it occurs on any …

---

## [Elasticsearch data node out of memory](https://discuss.elastic.co/t/elasticsearch-data-node-out-of-memory/325866)

<div class="topic-metadata">

**Author:** [@sssamant](https://discuss.elastic.co/u/sssamant)\
**Replies:** 6\
**Last updated:** [February 20, 2023, 2:26am UTC](https://discuss.elastic.co/t/elasticsearch-data-node-out-of-memory/325866 "2023-02-20T02:26:02Z")

</div>

Hello everyone, We are having out of memory issue for the elasticsearch data nodes? Can you please help me out to find the issue. Here is log from elasticsearch cluster. \[2023-02-17 10:02:47,551\]\[WARN \]\[netty.channel.…

---

## [Parsing Exception when using Bucket\_sort with org.elasticsearch.test.framework:8.6.2](https://discuss.elastic.co/t/parsing-exception-when-using-bucket-sort-with-org-elasticsearch-test-framework-8-6-2/325893)

<div class="topic-metadata">

**Author:** [@Neoministein](https://discuss.elastic.co/u/Neoministein)\
**Replies:** 0\
**Last updated:** [February 18, 2023, 5:00pm UTC](https://discuss.elastic.co/t/parsing-exception-when-using-bucket-sort-with-org-elasticsearch-test-framework-8-6-2/325893 "2023-02-18T17:00:39Z")

</div>

I am using org.elasticsearch.test.framework for Integration testing parts of my codebase. I am currently using the Elasticsearch Java API Client 8.7.0-SNAPSHOT to use the new BulkIngester. I've therefore bumped the ver…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=626)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=628)
