# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=629

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 630

---

## [Certificate issue](https://discuss.elastic.co/t/certificate-issue/325813)

<div class="topic-metadata">

**Author:** [@akhilkv43](https://discuss.elastic.co/u/akhilkv43)\
**Replies:** 1\
**Last updated:** [February 17, 2023, 5:02pm UTC](https://discuss.elastic.co/t/certificate-issue/325813 "2023-02-17T17:02:23Z")

</div>

How can i generate a pem certificate in Elasticsearch I am using 8.5 version

---

## [How to plan and implement shard allocation awareness for the below 3 master 6 data node setup](https://discuss.elastic.co/t/how-to-plan-and-implement-shard-allocation-awareness-for-the-below-3-master-6-data-node-setup/325858)

<div class="topic-metadata">

**Author:** [@H\_K7](https://discuss.elastic.co/u/H_K7)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 3:23pm UTC](https://discuss.elastic.co/t/how-to-plan-and-implement-shard-allocation-awareness-for-the-below-3-master-6-data-node-setup/325858 "2023-02-17T15:23:27Z")

</div>

Current setup hosted in aws ec2, self managed/hosted opensource version of elasticsearch master-1 - us-east-1a master-2 - us-east-1b master-2 - us-east-1c data-1 - us-east-1a data-2 - us-east-1b data-3 - us-east-1c …

---

## [Operators in Ingest Pipeline](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743)

<div class="topic-metadata">

**Author:** [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 3:23pm UTC](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743 "2023-02-17T15:23:59Z")

</div>

Hello, I am trying to parse and compare values through ingest pipeline, but couldn't do it, I was running below code, grok is running fine, but couldn't be able to compare value in set condition. POST \_ingest/pipeline/…

---

## [SSL termination for Elasticsearch cluster](https://discuss.elastic.co/t/ssl-termination-for-elasticsearch-cluster/325613)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 3:21pm UTC](https://discuss.elastic.co/t/ssl-termination-for-elasticsearch-cluster/325613 "2023-02-17T15:21:12Z")

</div>

Hi, I'm trying to add a HAProxy service within the docker-compose.yml outlined here: (Install Elasticsearch with Docker | Elasticsearch Guide \[8.6\] | Elastic). I was wondering if anyone had done the same and could share …

---

## [Custom grok write for my message](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 5\
**Last updated:** [February 17, 2023, 2:37pm UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728 "2023-02-17T14:37:47Z")

</div>

Hello Everyone I am having following example logs I want to extract field using filebeat any one can help ? 0.0.0.0 - - \[16/Feb/2023:09:54:40 +0000\] "POST /api/WebsiteCategory/ProductDesigns HTTP/1.1" 200 95521 "https:…

---

## [How to keep only longest token occupying the same positions](https://discuss.elastic.co/t/how-to-keep-only-longest-token-occupying-the-same-positions/325849)

<div class="topic-metadata">

**Author:** [@Valentin\_Pletzer](https://discuss.elastic.co/u/Valentin_Pletzer)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 2:04pm UTC](https://discuss.elastic.co/t/how-to-keep-only-longest-token-occupying-the-same-positions/325849 "2023-02-17T14:04:09Z")

</div>

Is there a way too keep only the longest token if two or more tokens occupy the same positions? e.g. if I define "fox" and "quick fox" as keep words obviously both would be return when analyzing the sentence "the quick …

---

## [Fielddata on a custom analyzer that is of keyword tokenizer](https://discuss.elastic.co/t/fielddata-on-a-custom-analyzer-that-is-of-keyword-tokenizer/325846)

<div class="topic-metadata">

**Author:** [@drjz](https://discuss.elastic.co/u/drjz)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 1:35pm UTC](https://discuss.elastic.co/t/fielddata-on-a-custom-analyzer-that-is-of-keyword-tokenizer/325846 "2023-02-17T13:35:18Z")

</div>

I created a custom analyzer that does lowercasing. The reason why I did not use a normalizer is because I need to apply stopword filter that the normalizer is not supporting. "lowercase\_analyzer": { …

---

## [Filter working in "Discover" field, but the same filter in Dashboard/lense does not](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395)

<div class="topic-metadata">

**Author:** [@JCW](https://discuss.elastic.co/u/JCW)\
**Replies:** 7\
**Last updated:** [February 17, 2023, 1:33pm UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395 "2023-02-17T13:33:46Z")

</div>

I'm using a tags - is - snort filter, on the discover tab it shows 5 hits in the last hour. I have a visualisation, that used the same index pattern etc, with the same filter and timeframe (tags - is - snort) which does…

---

## [Filebeats Threat Intel Module integration with Logstash](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 12:53pm UTC](https://discuss.elastic.co/t/filebeats-threat-intel-module-integration-with-logstash/325735 "2023-02-17T12:53:44Z")

</div>

Hi, I have the following self hosted setup on ELK stack 8.6.1 : Firewall (logs) --\> Filebeat --\> Logstash --\> Elasticsearch Cluster I am trying to integrate FIleBeats Threat Intel Module into this setup so that IOCs i…

---

## [ELK setup on ARO](https://discuss.elastic.co/t/elk-setup-on-aro/325837)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 12:20pm UTC](https://discuss.elastic.co/t/elk-setup-on-aro/325837 "2023-02-17T12:20:38Z")

</div>

i would like to know that is it possible to setup ELK on ARO or no .as per some references ,says its not possible . if yes could you pls let me know how to setup ELK on ARO thanking in advance :slight\_smile:

---

## [I wanted to add comments in Chinese to make it easier to learn and understand. Why did the build fail?](https://discuss.elastic.co/t/i-wanted-to-add-comments-in-chinese-to-make-it-easier-to-learn-and-understand-why-did-the-build-fail/325826)

<div class="topic-metadata">

**Author:** [@xiaodizi](https://discuss.elastic.co/u/xiaodizi)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 9:35am UTC](https://discuss.elastic.co/t/i-wanted-to-add-comments-in-chinese-to-make-it-easier-to-learn-and-understand-why-did-the-build-fail/325826 "2023-02-17T09:35:39Z")

</div>

!\[image|690x183\](upload: //nMdNEBcTf10uHBGKWm5z6abOYth.jpeg) I wanted to add comments in Chinese to make it easier to learn and understand. Why did the build fail?

---

## [Large-scale setup on AWS](https://discuss.elastic.co/t/large-scale-setup-on-aws/325818)

<div class="topic-metadata">

**Author:** [@eof](https://discuss.elastic.co/u/eof)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 7:20am UTC](https://discuss.elastic.co/t/large-scale-setup-on-aws/325818 "2023-02-17T07:20:12Z")

</div>

I'm currently running our infrastructure on ECS Fargate with logs going into CloudWatch. I've been less than happy with CloudWatch as a log tool and have used an ELK stack previously for smaller setups. We have a set of …

---

## [Dashboards not showing in custom kibana space](https://discuss.elastic.co/t/dashboards-not-showing-in-custom-kibana-space/325420)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 4\
**Last updated:** [February 17, 2023, 7:07am UTC](https://discuss.elastic.co/t/dashboards-not-showing-in-custom-kibana-space/325420 "2023-02-17T07:07:40Z")

</div>

I have created a two space in kibana one for production which is default space and second is for staging. on my production space all indexes are showing into it but on my staging space there is only staging index is show…

---

## [Watcher action: multiple actions foreach](https://discuss.elastic.co/t/watcher-action-multiple-actions-foreach/325817)

<div class="topic-metadata">

**Author:** [@mch1307](https://discuss.elastic.co/u/mch1307)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 7:01am UTC](https://discuss.elastic.co/t/watcher-action-multiple-actions-foreach/325817 "2023-02-17T07:01:52Z")

</div>

Hi, I have a watcher with an aggregation query. In the action section, I am trying to execute two actions (transform, then webhook) for each element in the query response. From the logs, it seems the webhook is being ex…

---

## [ELK setup on kubernetes](https://discuss.elastic.co/t/elk-setup-on-kubernetes/325811)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 6:25am UTC](https://discuss.elastic.co/t/elk-setup-on-kubernetes/325811 "2023-02-17T06:25:04Z")

</div>

Iam trying to setup ELK on Azure kubernetes services (AKS) iam finding difficulties as not able to run Elasticsearch,logstash,kibana as a containers kindly help me on this as i don't want to go with ECK let me know if we…

---

## [ELK running on VM, not able to send logs from physical machine](https://discuss.elastic.co/t/elk-running-on-vm-not-able-to-send-logs-from-physical-machine/325720)

<div class="topic-metadata">

**Author:** [@mvasuraja](https://discuss.elastic.co/u/mvasuraja)\
**Replies:** 4\
**Last updated:** [February 17, 2023, 5:32am UTC](https://discuss.elastic.co/t/elk-running-on-vm-not-able-to-send-logs-from-physical-machine/325720 "2023-02-17T05:32:00Z")

</div>

I am running Ubuntu 22.04 on my physical machine with IP 10.180.7.188. I am also running a Ubuntu 22.04 Virtual machine with IP 10.180.5.246. I have installed the ELK version 7.6.2 on the VM. I have installed filebeat v…

---

## [Restore all User created Indices, exclude the indices starting with](https://discuss.elastic.co/t/restore-all-user-created-indices-exclude-the-indices-starting-with/324428)

<div class="topic-metadata">

**Author:** [@x00m](https://discuss.elastic.co/u/x00m)\
**Replies:** 6\
**Last updated:** [February 17, 2023, 5:16am UTC](https://discuss.elastic.co/t/restore-all-user-created-indices-exclude-the-indices-starting-with/324428 "2023-02-17T05:16:12Z")

</div>

I am trying to ALL restore user created indices. I don't want to restore the .geoip\_databases, .security, .ds-.logs-deprecation.elasticsearch-default\* and so on. I tried this :- { "indices": "\*", "include\_global\_sta…

---

## [ElasticSearch losing documents](https://discuss.elastic.co/t/elasticsearch-losing-documents/325185)

<div class="topic-metadata">

**Author:** [@apelk](https://discuss.elastic.co/u/apelk)\
**Replies:** 12\
**Last updated:** [February 17, 2023, 4:42am UTC](https://discuss.elastic.co/t/elasticsearch-losing-documents/325185 "2023-02-17T04:42:32Z")

</div>

Using ELK 7.8. We have a Logstash pipeline from JDBC database to Elasticsearch. Using persisted queues and DLQ. We lose about 1% of the documents we send to Elasticsearch. We have enabled TRACE on Elasticsearch and t…

---

## [Logstash to load input file based on time change](https://discuss.elastic.co/t/logstash-to-load-input-file-based-on-time-change/325806)

<div class="topic-metadata">

**Author:** [@dhiyaneshwaran](https://discuss.elastic.co/u/dhiyaneshwaran)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 3:31am UTC](https://discuss.elastic.co/t/logstash-to-load-input-file-based-on-time-change/325806 "2023-02-17T03:31:13Z")

</div>

I'm using Logstash 7.17.0, in that i'm trying to load file using pipeline. It is taking file based on size or checksum changes, but i wanted to pick the file even if the size same but change in file timings. For exampl…

---

## [Vega: Set a text for empty data set](https://discuss.elastic.co/t/vega-set-a-text-for-empty-data-set/325807)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 3:58am UTC](https://discuss.elastic.co/t/vega-set-a-text-for-empty-data-set/325807 "2023-02-17T03:58:21Z")

</div>

Actually my condition same with this thread but when I try, it doesn't work for me. I did the filter transform and when there's no rows that shown after the transform, I want to make a static text to inform that.

---

## [How to get version of the es server using Java Api client](https://discuss.elastic.co/t/how-to-get-version-of-the-es-server-using-java-api-client/325796)

<div class="topic-metadata">

**Author:** [@4color](https://discuss.elastic.co/u/4color)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 3:08am UTC](https://discuss.elastic.co/t/how-to-get-version-of-the-es-server-using-java-api-client/325796 "2023-02-17T03:08:03Z")

</div>

i can't find api in source

---

## [Aggregate Score for Hybrid Search](https://discuss.elastic.co/t/aggregate-score-for-hybrid-search/325205)

<div class="topic-metadata">

**Author:** [@Kok\_Gin\_Xian](https://discuss.elastic.co/u/Kok_Gin_Xian)\
**Replies:** 21\
**Last updated:** [February 17, 2023, 1:12am UTC](https://discuss.elastic.co/t/aggregate-score-for-hybrid-search/325205 "2023-02-17T01:12:37Z")

</div>

Hi, I'm new to Elasticsearch and am trying out the new hybrid search by specifying the "knn" and "query" parameters in my search. I set k=100 in knn, size=k=100 in the search request. For pure vector search (omitting t…

---

## [X-Forwarded-For in Elasticsearch/Kibana Logs](https://discuss.elastic.co/t/x-forwarded-for-in-elasticsearch-kibana-logs/325779)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 11:31pm UTC](https://discuss.elastic.co/t/x-forwarded-for-in-elasticsearch-kibana-logs/325779 "2023-02-16T23:31:11Z")

</div>

We have Kibana and Elasticsearch behind AVI (Nginx) load-balancers, and that is unfortunately masking the true client IP addresses that are accessing Kibana/Elasticsearch. We are logging XFF headers on all the LB configs…

---

## [Automatic synonyms generation using ChatGPT or other AI solution?](https://discuss.elastic.co/t/automatic-synonyms-generation-using-chatgpt-or-other-ai-solution/325785)

<div class="topic-metadata">

**Author:** [@Youxu](https://discuss.elastic.co/u/Youxu)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 11:24pm UTC](https://discuss.elastic.co/t/automatic-synonyms-generation-using-chatgpt-or-other-ai-solution/325785 "2023-02-16T23:24:35Z")

</div>

Anyone know if there is out-of-box automatic synonym generation based on index data using AI, like ChatGPT?

---

## [Confused by deprecation message](https://discuss.elastic.co/t/confused-by-deprecation-message/325780)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 10:10pm UTC](https://discuss.elastic.co/t/confused-by-deprecation-message/325780 "2023-02-16T22:10:43Z")

</div>

I am looking at upgrading my 7.17 cluster to version 8, first stop the depreciation logs! I notice that there is both a deprecation.log and a deprecation.json and they have different data. deprecation.log: \[2020-11-16…

---

## [Issue with ingestion pipeline with conditional](https://discuss.elastic.co/t/issue-with-ingestion-pipeline-with-conditional/325747)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 9:51pm UTC](https://discuss.elastic.co/t/issue-with-ingestion-pipeline-with-conditional/325747 "2023-02-16T21:51:34Z")

</div>

Hello, I am trying to parse and compare values through ingest pipeline, but couldn't do it, I was running below code, grok is running fine, but couldn't be able to compare value in set condition. POST \_ingest/pipeline/…

---

## [Update API can't find document](https://discuss.elastic.co/t/update-api-cant-find-document/325777)

<div class="topic-metadata">

**Author:** [@friaca](https://discuss.elastic.co/u/friaca)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 9:37pm UTC](https://discuss.elastic.co/t/update-api-cant-find-document/325777 "2023-02-16T21:37:25Z")

</div>

I'm trying to update a document field but had no success doing it. I can do a GET by ID with ticket-2/ticketelastic/134532 so that clarifies that the ID is valid and the document exists. { "\_index" : "ticket-2", "\_…

---

## [How to get a single field from one beats event and add it to another beats event?](https://discuss.elastic.co/t/how-to-get-a-single-field-from-one-beats-event-and-add-it-to-another-beats-event/325778)

<div class="topic-metadata">

**Author:** [@scantron](https://discuss.elastic.co/u/scantron)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 9:10pm UTC](https://discuss.elastic.co/t/how-to-get-a-single-field-from-one-beats-event-and-add-it-to-another-beats-event/325778 "2023-02-16T21:10:01Z")

</div>

Hello, Essentially, I am looking to monitor when my server is getting full, using metricbeat to log the space left on the filesystem, and also using a filebeat cronjob to monitor more specifically where all of the stora…

---

## [Lens: changing rows in table](https://discuss.elastic.co/t/lens-changing-rows-in-table/324622)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 9:06pm UTC](https://discuss.elastic.co/t/lens-changing-rows-in-table/324622 "2023-02-16T21:06:49Z")

</div>

Hi there, created the following table in Kibana lens: Is it possible to view all metric1 entries where metric2 and vice versa? I tried to put it in a different metrics field,but the result was the same. I remember…

---

## [Kibana error - can't start due to error (problem with ES)](https://discuss.elastic.co/t/kibana-error-cant-start-due-to-error-problem-with-es/325409)

<div class="topic-metadata">

**Author:** [@Blazej\_Makula](https://discuss.elastic.co/u/Blazej_Makula)\
**Replies:** 5\
**Last updated:** [February 16, 2023, 8:47pm UTC](https://discuss.elastic.co/t/kibana-error-cant-start-due-to-error-problem-with-es/325409 "2023-02-16T20:47:58Z")

</div>

Hello, can you please help me with my home lab log collection system. I have two hosts one with logstash + elasticsearch + kibana and the other with logstash + elasticsearch. I want to connect kibana to both ES cluster…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=628)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=630)
