# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=636

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 637

---

## [Metricbeat: TLS Verification Disabled: certificate signed by unknown authority](https://discuss.elastic.co/t/metricbeat-tls-verification-disabled-certificate-signed-by-unknown-authority/324751)

<div class="topic-metadata">

**Author:** [@Cactus7600](https://discuss.elastic.co/u/Cactus7600)\
**Replies:** 4\
**Last updated:** [February 12, 2023, 4:19pm UTC](https://discuss.elastic.co/t/metricbeat-tls-verification-disabled-certificate-signed-by-unknown-authority/324751 "2023-02-12T16:19:32Z")

</div>

Hi. I disabled certificate validation within Metricbeat, yet it's still throwing untrusted certificate errors when hitting Elasticsearch. I'm using these versions: Elasticsearch: 7.16.2 Metricbeat: 7.16.1 I have the…

---

## [Ingesting Windows events forwarded by Splunk heavy forwarders](https://discuss.elastic.co/t/ingesting-windows-events-forwarded-by-splunk-heavy-forwarders/323460)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 5\
**Last updated:** [February 12, 2023, 2:41pm UTC](https://discuss.elastic.co/t/ingesting-windows-events-forwarded-by-splunk-heavy-forwarders/323460 "2023-02-12T14:41:05Z")

</div>

Hiya We are currently moving our SIEM from Splunk to Elastic. Due to a tight deadline and network/firewall configuration we will be adding the Elastic endpoint to our current Splunk Heavy Forwarders. This approach wor…

---

## [Rollover alias \[xxxx\] can point to multiple indices, found duplicated alias \[\[xxxx\]\] in index template](https://discuss.elastic.co/t/rollover-alias-xxxx-can-point-to-multiple-indices-found-duplicated-alias-xxxx-in-index-template/324802)

<div class="topic-metadata">

**Author:** [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Replies:** 3\
**Last updated:** [February 12, 2023, 10:54am UTC](https://discuss.elastic.co/t/rollover-alias-xxxx-can-point-to-multiple-indices-found-duplicated-alias-xxxx-in-index-template/324802 "2023-02-12T10:54:14Z")

</div>

Hi everyone, I have a problem with rollover. I'm getting an error as described in the title: Rollover alias \[xxxx\] can point to multiple indices, found duplicated alias \[\[xxxx\]\] in index template The indice, for si…

---

## [Failed to parse date field](https://discuss.elastic.co/t/failed-to-parse-date-field/325324)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 5\
**Last updated:** [February 12, 2023, 3:31am UTC](https://discuss.elastic.co/t/failed-to-parse-date-field/325324 "2023-02-12T03:31:45Z")

</div>

I currently have a problem with an error message that is appearing that refers to a date field but is not detecting it as such. \[2023-02-11T15:16:39,111\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index even…

---

## [Kafka input - resync missing items from topic](https://discuss.elastic.co/t/kafka-input-resync-missing-items-from-topic/325294)

<div class="topic-metadata">

**Author:** [@Chris\_Denneen](https://discuss.elastic.co/u/Chris_Denneen)\
**Replies:** 7\
**Last updated:** [February 12, 2023, 2:04am UTC](https://discuss.elastic.co/t/kafka-input-resync-missing-items-from-topic/325294 "2023-02-12T02:04:14Z")

</div>

Ran into issue where we have logstash input reading kafka topics for log events. Last night the ES index rolled over and the write alias was lost (not on the new index... so nothing with is\_write\_index = true) therefore…

---

## [Elasticsearch throwing invalid attributes in log](https://discuss.elastic.co/t/elasticsearch-throwing-invalid-attributes-in-log/323355)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:55am UTC](https://discuss.elastic.co/t/elasticsearch-throwing-invalid-attributes-in-log/323355 "2023-02-12T01:55:50Z")

</div>

Hi, Elasticsearch log is been written as below: 2023-01-16 19:02:31,790 main ERROR Filters contains invalid attributes "onMatch", "onMismatch" In our log4j2.properties, we have included onMatch and onMismatch, what is…

---

## [Import objects from v8.x to v7.x](https://discuss.elastic.co/t/import-objects-from-v8-x-to-v7-x/323801)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:35am UTC](https://discuss.elastic.co/t/import-objects-from-v8-x-to-v7-x/323801 "2023-02-12T01:35:53Z")

</div>

Hi, is it possible to import to kibana v7.16.2 dashboards which were created in kibana version 8.2.3? when i try to import objects i have an error: Best

---

## [Cache mechanism and log when transfer fails](https://discuss.elastic.co/t/cache-mechanism-and-log-when-transfer-fails/325230)

<div class="topic-metadata">

**Author:** [@YasuhiroOkumura](https://discuss.elastic.co/u/YasuhiroOkumura)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:26am UTC](https://discuss.elastic.co/t/cache-mechanism-and-log-when-transfer-fails/325230 "2023-02-12T01:26:05Z")

</div>

1.When transferring messages from logstash(8.6) to pagerduty using pagerduty output plugin, if the transfer fails, is it possible to cache and resend? 2.When using the pagerduty output plugin to transfer messages from l…

---

## [Help. My filebeat stops working after I installed my wazuh server after 30 minutes](https://discuss.elastic.co/t/help-my-filebeat-stops-working-after-i-installed-my-wazuh-server-after-30-minutes/324536)

<div class="topic-metadata">

**Author:** [@Joshua\_John\_Consulta](https://discuss.elastic.co/u/Joshua_John_Consulta)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:20am UTC](https://discuss.elastic.co/t/help-my-filebeat-stops-working-after-i-installed-my-wazuh-server-after-30-minutes/324536 "2023-02-12T01:20:01Z")

</div>

Here's the error: × filebeat.service - Filebeat sends log files to Logstash or directly to Elasti\> Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; preset: ena\> Active: failed (Result: exit-code) since T…

---

## [Logstash heartbeat input error](https://discuss.elastic.co/t/logstash-heartbeat-input-error/325315)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 2\
**Last updated:** [February 11, 2023, 8:34pm UTC](https://discuss.elastic.co/t/logstash-heartbeat-input-error/325315 "2023-02-11T20:34:40Z")

</div>

Hello All, I am using heartbeat input to perform a specific job periodically. However, on my local windows machine, I occasionally keep getting this error message \[2023-02-09T02:35:37,209\]\[ERROR\]\[logstash.javapipeline…

---

## [Background Update of Millions of Documenrs Using NEST API](https://discuss.elastic.co/t/background-update-of-millions-of-documenrs-using-nest-api/325196)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 11\
**Last updated:** [February 11, 2023, 6:18pm UTC](https://discuss.elastic.co/t/background-update-of-millions-of-documenrs-using-nest-api/325196 "2023-02-11T18:18:24Z")

</div>

What is the most efficient way of updating Millions of documents in the background so that it has little effect on foreground operations such as Autocomplete and user searches. Thanks

---

## [During the backup some indices fails giving me this error](https://discuss.elastic.co/t/during-the-backup-some-indices-fails-giving-me-this-error/325308)

<div class="topic-metadata">

**Author:** [@Amal\_Ranjan\_Misra](https://discuss.elastic.co/u/Amal_Ranjan_Misra)\
**Replies:** 2\
**Last updated:** [February 11, 2023, 10:12am UTC](https://discuss.elastic.co/t/during-the-backup-some-indices-fails-giving-me-this-error/325308 "2023-02-11T10:12:17Z")

</div>

I need help on this "stage" : "FAILURE", "stats" : { "number\_of\_files" : 0, "processed\_files" : 0, "total\_size\_in\_bytes" : 0, "…

---

## [Question about data stream rollover timings](https://discuss.elastic.co/t/question-about-data-stream-rollover-timings/325073)

<div class="topic-metadata">

**Author:** [@xnn](https://discuss.elastic.co/u/xnn)\
**Replies:** 5\
**Last updated:** [February 11, 2023, 3:35am UTC](https://discuss.elastic.co/t/question-about-data-stream-rollover-timings/325073 "2023-02-11T03:35:04Z")

</div>

We're considering moving some large ES clusters from time-based indices to data streams. One concern we have is that with time-based indices we notice a delay between when the first event arrives and when the shards are …

---

## [Configurate ElasticSearch and Kibana with a differente certificate CA](https://discuss.elastic.co/t/configurate-elasticsearch-and-kibana-with-a-differente-certificate-ca/325295)

<div class="topic-metadata">

**Author:** [@Urbina](https://discuss.elastic.co/u/Urbina)\
**Replies:** 3\
**Last updated:** [February 10, 2023, 10:33pm UTC](https://discuss.elastic.co/t/configurate-elasticsearch-and-kibana-with-a-differente-certificate-ca/325295 "2023-02-10T22:33:19Z")

</div>

Hello everyone, I installed elasticksearch and kibana version 8.61 in docker, but I need to cahnge the certificate ca by a differente certificate, can you help me with the steps to take?

---

## [Wildcard matches are not highlighted in complex query containing field\_masking\_span](https://discuss.elastic.co/t/wildcard-matches-are-not-highlighted-in-complex-query-containing-field-masking-span/325301)

<div class="topic-metadata">

**Author:** [@claudinoac](https://discuss.elastic.co/u/claudinoac)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 9:42pm UTC](https://discuss.elastic.co/t/wildcard-matches-are-not-highlighted-in-complex-query-containing-field-masking-span/325301 "2023-02-10T21:42:05Z")

</div>

I'm applying the unified highlighter to the query below and the matched terms are being correctly highlighted, except by the ones matched by the wildcard term. That happens only when there is a field\_masking\_span term i…

---

## [Failed to determine the health of the cluster](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/325290)

<div class="topic-metadata">

**Author:** [@goodeejay](https://discuss.elastic.co/u/goodeejay)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 8:56pm UTC](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/325290 "2023-02-10T20:56:57Z")

</div>

Hello, I've been trying to generate enrollment token for kibana with: sudo /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s "kibana" But I'm getting an error, the last line says: ERROR: Failed to …

---

## [How can I get elasticsearch indices, dataviews, documents inside my Kibana plugin?](https://discuss.elastic.co/t/how-can-i-get-elasticsearch-indices-dataviews-documents-inside-my-kibana-plugin/324901)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 7:45pm UTC](https://discuss.elastic.co/t/how-can-i-get-elasticsearch-indices-dataviews-documents-inside-my-kibana-plugin/324901 "2023-02-10T19:45:10Z")

</div>

Hi, I an creating an external plugin in Kibana 8.5.3. How can I get data/docs/indices/dataviews/... from my elasticsearch instance within my plugin? Thanks

---

## [Query response time when search query hits across HOT and WARM phase in ILM](https://discuss.elastic.co/t/query-response-time-when-search-query-hits-across-hot-and-warm-phase-in-ilm/324699)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 12\
**Last updated:** [February 10, 2023, 6:02pm UTC](https://discuss.elastic.co/t/query-response-time-when-search-query-hits-across-hot-and-warm-phase-in-ilm/324699 "2023-02-10T18:02:58Z")

</div>

Hi Team, We have to implement HOT, WARM and COLD phase with ILM implementation as a part of our requirement, wherein the HOT phase Nodes are in SSD and the WARM and COLD are not. Most of the searches will be fired for …

---

## [Error split was expecting field to be an array](https://discuss.elastic.co/t/error-split-was-expecting-field-to-be-an-array/325285)

<div class="topic-metadata">

**Author:** [@fabien9402](https://discuss.elastic.co/u/fabien9402)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 5:09pm UTC](https://discuss.elastic.co/t/error-split-was-expecting-field-to-be-an-array/325285 "2023-02-10T17:09:45Z")

</div>

Hello, We have an error in one of our elastic-agent. This returns the error below: Feb 7, 2023 15:01:20.773 elastic\_agent.filebeat \[elastic\_agent.filebeat\]\[error\] error processing response: split was expecting field t…

---

## [Curl'ing Kibana Dashboards exported into NDJSON](https://discuss.elastic.co/t/curling-kibana-dashboards-exported-into-ndjson/325012)

<div class="topic-metadata">

**Author:** [@plissken](https://discuss.elastic.co/u/plissken)\
**Replies:** 8\
**Last updated:** [February 10, 2023, 4:55pm UTC](https://discuss.elastic.co/t/curling-kibana-dashboards-exported-into-ndjson/325012 "2023-02-10T16:55:49Z")

</div>

I'm having considerable difficulty in understanding the documentation on the Kibana API's. There's so much out of date information on the web that I could literally spend months doing syntax jenga. I have a set of dash…

---

## [Check Forecast accuracy with scripted field](https://discuss.elastic.co/t/check-forecast-accuracy-with-scripted-field/324650)

<div class="topic-metadata">

**Author:** [@CHP93](https://discuss.elastic.co/u/CHP93)\
**Replies:** 3\
**Last updated:** [February 10, 2023, 4:23pm UTC](https://discuss.elastic.co/t/check-forecast-accuracy-with-scripted-field/324650 "2023-02-10T16:23:20Z")

</div>

Hello community, I have a quite challenging task and have not found a solution for my problem, yet. I created a multi-metric anomalies detection machine learning job which is running a forecast as well. My aim is now t…

---

## [Why I am getting two fields (label & metrics) for Prometheus data in Elasticsearch](https://discuss.elastic.co/t/why-i-am-getting-two-fields-label-metrics-for-prometheus-data-in-elasticsearch/325280)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 3:41pm UTC](https://discuss.elastic.co/t/why-i-am-getting-two-fields-label-metrics-for-prometheus-data-in-elasticsearch/325280 "2023-02-10T15:41:00Z")

</div>

I am sending the Prometheus scraped data to Elasticsearch through Metricbeat on 'remote write' option. However I am getting two fields as prometheus.labels.\* and prometheus.metrics.\* for every different fields. Is my con…

---

## [Metricbeat timeout](https://discuss.elastic.co/t/metricbeat-timeout/325147)

<div class="topic-metadata">

**Author:** [@imaad](https://discuss.elastic.co/u/imaad)\
**Replies:** 4\
**Last updated:** [February 10, 2023, 3:40pm UTC](https://discuss.elastic.co/t/metricbeat-timeout/325147 "2023-02-10T15:40:56Z")

</div>

Hello all, I have a question about the RabbitMQ module, specially about the queue metricset. My metricbeat send a request every 10s but my rabbitMQ take more than 10s to respond. So, I think that metricbeat continue se…

---

## [Is there a way to get a nested field in not flattened format?](https://discuss.elastic.co/t/is-there-a-way-to-get-a-nested-field-in-not-flattened-format/325276)

<div class="topic-metadata">

**Author:** [@MohammedZia](https://discuss.elastic.co/u/MohammedZia)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 3:00pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-nested-field-in-not-flattened-format/325276 "2023-02-10T15:00:54Z")

</div>

I've a document that contains a field called json\_field. This field contains nested object (a dictionary as complex as it can get, as I can't fix the shape at the moment). When I search for this field using json\_field, I…

---

## [Migration path from embedded 2.x to current](https://discuss.elastic.co/t/migration-path-from-embedded-2-x-to-current/325080)

<div class="topic-metadata">

**Author:** [@Cyntech](https://discuss.elastic.co/u/Cyntech)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 1:41pm UTC](https://discuss.elastic.co/t/migration-path-from-embedded-2-x-to-current/325080 "2023-02-10T13:41:35Z")

</div>

I'm the developer of a Grails web application that had embedded Elastic Search 1.x implemented more around 10 years ago (not by me, I've only been the developer for the last 2 yrs). In the process of upgrading to Grails…

---

## [How to reduce disk usage for metricbeat](https://discuss.elastic.co/t/how-to-reduce-disk-usage-for-metricbeat/325145)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 1:39pm UTC](https://discuss.elastic.co/t/how-to-reduce-disk-usage-for-metricbeat/325145 "2023-02-10T13:39:05Z")

</div>

Hi Team, I am using metricbeat to monitor around 200+ environments, and using system module. But it is comusing lot of disk space daily it use 10 GB of disk space to store the monitor data. Can we do any work to make…

---

## [Remove plain text message in Logstash file input](https://discuss.elastic.co/t/remove-plain-text-message-in-logstash-file-input/325269)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 1:24pm UTC](https://discuss.elastic.co/t/remove-plain-text-message-in-logstash-file-input/325269 "2023-02-10T13:24:17Z")

</div>

I am adding filter to remove a plain text as it causes error while JSON parsing. file { id =\> "my\_lt\_log" path =\> "/logs/logtransformer.log" type =\> "log" start\_position =\> "beginning" …

---

## [Heap memory full? new documents just disappeared!](https://discuss.elastic.co/t/heap-memory-full-new-documents-just-disappeared/325037)

<div class="topic-metadata">

**Author:** [@Pete\_Watcharawit1](https://discuss.elastic.co/u/Pete_Watcharawit1)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 6:07am UTC](https://discuss.elastic.co/t/heap-memory-full-new-documents-just-disappeared/325037 "2023-02-10T06:07:59Z")

</div>

Hello, some of our new batch of documents disappeared lately and I tried checking the heap memory usage of the cluster of 2 nodes by running: curl -XGET 'http://\<address\>:9200/\_nodes/stats/jvm?pretty' Our cluster is usi…

---

## [View cost breakdown of Elasticsearch in Azure](https://discuss.elastic.co/t/view-cost-breakdown-of-elasticsearch-in-azure/325266)

<div class="topic-metadata">

**Author:** [@matthew\_gen](https://discuss.elastic.co/u/matthew_gen)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 1:01pm UTC](https://discuss.elastic.co/t/view-cost-breakdown-of-elasticsearch-in-azure/325266 "2023-02-10T13:01:37Z")

</div>

Is there a way to extract the billing details of Elastic from the Elastic console (https://cloud.elastic.co/billing/usage) to the azure cost management page (Microsoft Azure)? I followed the links from the elastic cloud …

---

## [Logstash + Fortinet + Kibana](https://discuss.elastic.co/t/logstash-fortinet-kibana/323508)

<div class="topic-metadata">

**Author:** [@Cezary](https://discuss.elastic.co/u/Cezary)\
**Replies:** 10\
**Last updated:** [February 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/logstash-fortinet-kibana/323508 "2023-02-10T12:57:21Z")

</div>

Hello to All, I'm trying to create Kibana map using data from Fortinet syslog and Logstash. I was able to load geoip data to kibana, however geo.location field had to be created from Logstash because it was not created…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=635)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=637)
