# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=631

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 632

---

## [When i use snmp . why value in key:value is missing](https://discuss.elastic.co/t/when-i-use-snmp-why-value-in-key-value-is-missing/325684)

<div class="topic-metadata">

**Author:** [@sirichai\_phungsuntho](https://discuss.elastic.co/u/sirichai_phungsuntho)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 4:37am UTC](https://discuss.elastic.co/t/when-i-use-snmp-why-value-in-key-value-is-missing/325684 "2023-02-16T04:37:06Z")

</div>

When i use input snmp and selct more than 10 columns in function tables i will receive missing value like this how can i fix it?

---

## [Logstash Kafka consumer count](https://discuss.elastic.co/t/logstash-kafka-consumer-count/325671)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 5:47am UTC](https://discuss.elastic.co/t/logstash-kafka-consumer-count/325671 "2023-02-16T05:47:58Z")

</div>

According to the Logstash guide: "How many partitions should I use per topic?" At least the number of Logstash nodes multiplied by consumer threads per node. Better yet, use a multiple of the above number. Increasing…

---

## [Restart elastic agent from fleet server in kibana](https://discuss.elastic.co/t/restart-elastic-agent-from-fleet-server-in-kibana/325097)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 4:56am UTC](https://discuss.elastic.co/t/restart-elastic-agent-from-fleet-server-in-kibana/325097 "2023-02-16T04:56:11Z")

</div>

Is it possible to restart the elastic agent (which is on the fleet server) from kibana? There is only an option to update, is there a way to restart elastic agents remotely? In case you have so many elastic agents, it …

---

## [Kibana not displaying logs after implementing XPack Security in Elasticsearch 7.16](https://discuss.elastic.co/t/kibana-not-displaying-logs-after-implementing-xpack-security-in-elasticsearch-7-16/325552)

<div class="topic-metadata">

**Author:** [@b2njam1n](https://discuss.elastic.co/u/b2njam1n)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 2:39am UTC](https://discuss.elastic.co/t/kibana-not-displaying-logs-after-implementing-xpack-security-in-elasticsearch-7-16/325552 "2023-02-16T02:39:45Z")

</div>

Hello everyone, I recently set up an Elasticsearch version 7.16 cluster on a RHEL7.9 with Kibana and two Filebeat servers: a Hardware Log Server and an OS Log Server. Everything was working well until I implemented XPac…

---

## [Missing setting option "response.include\_body\_max\_bytes" in "Add Elastic Synthetics integration" UI](https://discuss.elastic.co/t/missing-setting-option-response-include-body-max-bytes-in-add-elastic-synthetics-integration-ui/325444)

<div class="topic-metadata">

**Author:** [@billhong-just](https://discuss.elastic.co/u/billhong-just)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 1:24am UTC](https://discuss.elastic.co/t/missing-setting-option-response-include-body-max-bytes-in-add-elastic-synthetics-integration-ui/325444 "2023-02-16T01:24:03Z")

</div>

Description In Kibana v8.5.3's dashboard, I can't find the setting option response.include\_body\_max\_bytes to control the maximum size of the stored body contents. Is this a bug or is it by design? :thinking: Refer…

---

## [Multiple Logstash Containers](https://discuss.elastic.co/t/multiple-logstash-containers/325319)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Saxena1](https://discuss.elastic.co/u/Vaibhav_Saxena1)\
**Replies:** 0\
**Last updated:** [February 11, 2023, 5:32pm UTC](https://discuss.elastic.co/t/multiple-logstash-containers/325319 "2023-02-11T17:32:58Z")

</div>

Hello, We have following containers setup on our environment: 1- logstash ( Stomp) 2- logstash ( Filebeat) port: 5044 3- Kibana 4- Elasticsearch But by mistake i created the logstash(filebeat) to read only one "lo…

---

## [Filebeat multiline ignores last line](https://discuss.elastic.co/t/filebeat-multiline-ignores-last-line/325654)

<div class="topic-metadata">

**Author:** [@mariana17](https://discuss.elastic.co/u/mariana17)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 9:47pm UTC](https://discuss.elastic.co/t/filebeat-multiline-ignores-last-line/325654 "2023-02-15T21:47:40Z")

</div>

What I want to do is read these records, each of them is inside braces, so I use multilines in filebeat to be able to read them together, however, the last line "\]}" is not read by filebeat, so the record is unfinished a…

---

## [Best practices for internal corporate site search](https://discuss.elastic.co/t/best-practices-for-internal-corporate-site-search/325532)

<div class="topic-metadata">

**Author:** [@Buntu\_Dev](https://discuss.elastic.co/u/Buntu_Dev)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:44pm UTC](https://discuss.elastic.co/t/best-practices-for-internal-corporate-site-search/325532 "2023-02-15T21:44:48Z")

</div>

I'm looking for best practices to tag the existing webpages which consist internal web apps and employee resources (internal forms, static content, policy documents) to help index into ES and make them available for site…

---

## [Couldn't open localhost:9200 for elasticsearch version 8.2.3](https://discuss.elastic.co/t/couldnt-open-localhost-9200-for-elasticsearch-version-8-2-3/325534)

<div class="topic-metadata">

**Author:** [@Sivapriya-Sugumar](https://discuss.elastic.co/u/Sivapriya-Sugumar)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:44pm UTC](https://discuss.elastic.co/t/couldnt-open-localhost-9200-for-elasticsearch-version-8-2-3/325534 "2023-02-15T21:44:15Z")

</div>

This page isn’t working localhost didn’t send any data. ERR\_EMPTY\_RESPONSE getting this batch file is running but couldn't open localhost:9200 in elasticsaerch 8.2.3

---

## [Kibana alerts](https://discuss.elastic.co/t/kibana-alerts/325570)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:41pm UTC](https://discuss.elastic.co/t/kibana-alerts/325570 "2023-02-15T21:41:00Z")

</div>

Hi team, I have installed elastisearch and kibana 8.5.1 throgh helm on cluster, now i tried to configure the alerts on kibana. So inside kibana pod kibana.yaml, In the kibana.yml configuration file, add the xpack.encryp…

---

## [Why data save to master cluster?](https://discuss.elastic.co/t/why-data-save-to-master-cluster/325576)

<div class="topic-metadata">

**Author:** [@fered](https://discuss.elastic.co/u/fered)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:33pm UTC](https://discuss.elastic.co/t/why-data-save-to-master-cluster/325576 "2023-02-15T21:33:24Z")

</div>

I have a cluster that it have 3 master and 4 data node(2 hot , 1 warm , 1 cold). so i configure ILM for this cluster , but I dont know why index(primery & replica) save in master node ?

---

## [Getting 403 code while connecting to elastic](https://discuss.elastic.co/t/getting-403-code-while-connecting-to-elastic/325615)

<div class="topic-metadata">

**Author:** [@fvtarnovskiy](https://discuss.elastic.co/u/fvtarnovskiy)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:32pm UTC](https://discuss.elastic.co/t/getting-403-code-while-connecting-to-elastic/325615 "2023-02-15T21:32:05Z")

</div>

Hello! We are a cloud provider from Uzbekistan pro-data.tech (https://pro-data.tech/). Please help in solving the problem - when trying to access Elastic, we get an error code 403 from all our addresses (95.47.127.0/24…

---

## [Logstash pipeline index question](https://discuss.elastic.co/t/logstash-pipeline-index-question/325273)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 12\
**Last updated:** [February 15, 2023, 9:28pm UTC](https://discuss.elastic.co/t/logstash-pipeline-index-question/325273 "2023-02-15T21:28:45Z")

</div>

AS many of you know and have been following, my syslog collectors keep stopping due to running out of shards. I have made some improvements and they now run for about 3 weeks before I have to "close" the index. Better …

---

## [Kibana does not recognize the @timestamp field as a time filter](https://discuss.elastic.co/t/kibana-does-not-recognize-the-timestamp-field-as-a-time-filter/325404)

<div class="topic-metadata">

**Author:** [@Alvik173](https://discuss.elastic.co/u/Alvik173)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 9:27pm UTC](https://discuss.elastic.co/t/kibana-does-not-recognize-the-timestamp-field-as-a-time-filter/325404 "2023-02-15T21:27:07Z")

</div>

Kibana (7.17.8) does not seem to recognize the @timestamp field in my index as a time field. The symptoms are as follows. In Discover, the "Show dates" box on the top right is missing The time series chart above the D…

---

## [Logstash rename json fields](https://discuss.elastic.co/t/logstash-rename-json-fields/325399)

<div class="topic-metadata">

**Author:** [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Replies:** 6\
**Last updated:** [February 15, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399 "2023-02-15T21:24:05Z")

</div>

Hi community, We have a json log as below { "Timestamp": "2023-02-09T17:41:54.5320239+03:00", "Level": "", "MessageTemplate": "", "Properties": { "responsetime": 4758, "SourceContext": "", "Username…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/325665)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:07pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/325665 "2023-02-15T21:07:06Z")

</div>

Hi All, Please am new to Dsiem. I have just clone it from github and running it on ubuntu, below is the error am getting. "Kibana server is not ready yet" see the logs below, can I get help with this please {"type":"…

---

## [【Logstash】The output configuration of logstash cannot connect to the elasticsearch](https://discuss.elastic.co/t/logstash-the-output-configuration-of-logstash-cannot-connect-to-the-elasticsearch/325523)

<div class="topic-metadata">

**Author:** [@Roy176](https://discuss.elastic.co/u/Roy176)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 8:47pm UTC](https://discuss.elastic.co/t/logstash-the-output-configuration-of-logstash-cannot-connect-to-the-elasticsearch/325523 "2023-02-15T20:47:53Z")

</div>

I build a single-node of elasticsearch on GCP and a logstash on the local side. I want to connect the output configuration of logstash to elasticsearch. Info: Elasticsearch、Kibana、Logstash: 8.6.1. I set up an extenal …

---

## [Scoring based on percentage of category](https://discuss.elastic.co/t/scoring-based-on-percentage-of-category/325661)

<div class="topic-metadata">

**Author:** [@sprath](https://discuss.elastic.co/u/sprath)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 8:33pm UTC](https://discuss.elastic.co/t/scoring-based-on-percentage-of-category/325661 "2023-02-15T20:33:59Z")

</div>

I'm not quite sure where to get started with this query. I'm using the opensearch quickstart data to try to explain. The documents have the following fields for example: { ... "customer\_first\_name": …

---

## [Simple aggregation counting distinct values that has turned out to be difficult](https://discuss.elastic.co/t/simple-aggregation-counting-distinct-values-that-has-turned-out-to-be-difficult/325659)

<div class="topic-metadata">

**Author:** [@Adam\_Burr](https://discuss.elastic.co/u/Adam_Burr)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:26pm UTC](https://discuss.elastic.co/t/simple-aggregation-counting-distinct-values-that-has-turned-out-to-be-difficult/325659 "2023-02-15T20:26:30Z")

</div>

I have a very simple index and I am trying to produce what I thought would be a simple aggregation, but I am finding it difficult to get working. I would be very grateful for any help the community can give. My "sales"…

---

## [Computation of total in Reindex API status response](https://discuss.elastic.co/t/computation-of-total-in-reindex-api-status-response/325658)

<div class="topic-metadata">

**Author:** [@fifthist](https://discuss.elastic.co/u/fifthist)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:23pm UTC](https://discuss.elastic.co/t/computation-of-total-in-reindex-api-status-response/325658 "2023-02-15T20:23:53Z")

</div>

I call Reindex API by creating a Task (wait\_for\_completion=false). I then use \_tasks API to get the details of the task once it is completed. Part of the task response is the response of the Reindex API with created, upd…

---

## [Metric to count number of queries per day/month](https://discuss.elastic.co/t/metric-to-count-number-of-queries-per-day-month/325076)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 6:23pm UTC](https://discuss.elastic.co/t/metric-to-count-number-of-queries-per-day-month/325076 "2023-02-15T18:23:00Z")

</div>

Hi, I'm trying to collect the number of queries that users send to Elasticsearch to understand how many queries per day/month are submitted to our clusters. I've tried using the following metrics mentioned in Nodes sta…

---

## [Filebeat : field \[event\] not present as part of path \[event.start\]](https://discuss.elastic.co/t/filebeat-field-event-not-present-as-part-of-path-event-start/325634)

<div class="topic-metadata">

**Author:** [@Youssef\_Mouadden](https://discuss.elastic.co/u/Youssef_Mouadden)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 6:20pm UTC](https://discuss.elastic.co/t/filebeat-field-event-not-present-as-part-of-path-event-start/325634 "2023-02-15T18:20:51Z")

</div>

hello, I'm facing a problem with filebeat pipeline. when I execute the pipeline with a console output, I have no error and I have the right execution, except that when I put an elasticsearch output I receive the followi…

---

## [Term contains a dot (.), nothing is returned](https://discuss.elastic.co/t/term-contains-a-dot-nothing-is-returned/325508)

<div class="topic-metadata">

**Author:** [@thales788](https://discuss.elastic.co/u/thales788)\
**Replies:** 9\
**Last updated:** [February 15, 2023, 5:28pm UTC](https://discuss.elastic.co/t/term-contains-a-dot-nothing-is-returned/325508 "2023-02-15T17:28:45Z")

</div>

Hello. I'm doing a query on the "username" field. The results are correct in most cases. When the given term contains a dot (.), nothing is returned. Ex: "firstname.lastname" = nothing is returned "firstname lastname" …

---

## [Elastic Agent conditions-based autodiscover doesn't pick up newly-scheduled pods/containers](https://discuss.elastic.co/t/elastic-agent-conditions-based-autodiscover-doesnt-pick-up-newly-scheduled-pods-containers/325271)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 5\
**Last updated:** [February 15, 2023, 5:18pm UTC](https://discuss.elastic.co/t/elastic-agent-conditions-based-autodiscover-doesnt-pick-up-newly-scheduled-pods-containers/325271 "2023-02-15T17:18:39Z")

</div>

I am currently using Elastic Cloud, v8.6.1, with Elastic Agent Standalone v8.6.0 deployed to EKS, running Kubernetes v1.22.16 in our non-production cluster and v1.21.14 in our production cluster (to be updated this weeke…

---

## [High search\_fetch\_time for elasticsearch cluster](https://discuss.elastic.co/t/high-search-fetch-time-for-elasticsearch-cluster/325625)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 5:13pm UTC](https://discuss.elastic.co/t/high-search-fetch-time-for-elasticsearch-cluster/325625 "2023-02-15T17:13:03Z")

</div>

We started seeing some high latency with the applications querying elasticsearch(7.17.0) and found that search\_fetch\_time is significantly increasing whenever there is some significant increase in incoming search traffic…

---

## [Filebeat Helm chart run as non root](https://discuss.elastic.co/t/filebeat-helm-chart-run-as-non-root/325649)

<div class="topic-metadata">

**Author:** [@DarthVader](https://discuss.elastic.co/u/DarthVader)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-helm-chart-run-as-non-root/325649 "2023-02-15T16:31:17Z")

</div>

Hello, I have been using Terraform to deploy the filebeat helm chart which currently runs successfully as root. Due to security policies I need to apply the pod security context "fsGroup" or anything similar that will e…

---

## [Master not discovered or elected yet, an election requires at least 2 nodes with ids - ELK Stack - Docker Swarm](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-elk-stack-docker-swarm/325548)

<div class="topic-metadata">

**Author:** [@vdcharter](https://discuss.elastic.co/u/vdcharter)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 4:19pm UTC](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-elk-stack-docker-swarm/325548 "2023-02-15T16:19:09Z")

</div>

Hi, I am trying to setup a elastic cluster with 3 masters, 1 kibana node and 1 data node. This is a common topic but would like to understand what I am doing wrong. Below is portainer error log on master1 WARN master n…

---

## [Connect kibana to Elasticsearch after changes made](https://discuss.elastic.co/t/connect-kibana-to-elasticsearch-after-changes-made/325518)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 16\
**Last updated:** [February 15, 2023, 4:00pm UTC](https://discuss.elastic.co/t/connect-kibana-to-elasticsearch-after-changes-made/325518 "2023-02-15T16:00:15Z")

</div>

Hello! My kibana doesnt talk to Elasticsearch after changes are made in elasticsearch config Some history: installed ELK on one host and filebeat on another one. Started elasticsearch, started kibana, started logsta…

---

## [Elasticsearch sort returns incorrect results?](https://discuss.elastic.co/t/elasticsearch-sort-returns-incorrect-results/325512)

<div class="topic-metadata">

**Author:** [@Fatih\_Erol1](https://discuss.elastic.co/u/Fatih_Erol1)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 3:40pm UTC](https://discuss.elastic.co/t/elasticsearch-sort-returns-incorrect-results/325512 "2023-02-15T15:40:18Z")

</div>

Why elasticsearch sort returns incorrect results? Mappings { "mappings": { "\_doc": { "properties": { "name": { "type": "keyword", "fields": { "sort": { …

---

## [Logstash - Could not connect to a compatible version of Elasticsearch](https://discuss.elastic.co/t/logstash-could-not-connect-to-a-compatible-version-of-elasticsearch/325629)

<div class="topic-metadata">

**Author:** [@hnclientes\_HN](https://discuss.elastic.co/u/hnclientes_HN)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 3:20pm UTC](https://discuss.elastic.co/t/logstash-could-not-connect-to-a-compatible-version-of-elasticsearch/325629 "2023-02-15T15:20:58Z")

</div>

I'm trying to upload a .csv file via logstash to a test version on Cloud V 8.6.1 and I get an error when trying (I'm using logstash version 8.6.1 anyway) and I get the following error: ´\`\`\` \[2023-02-14T23:21:15,274\]\[ER…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=630)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=632)
