# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=638

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 639

---

## [Runtime field query performance](https://discuss.elastic.co/t/runtime-field-query-performance/325193)

<div class="topic-metadata">

**Author:** [@vlasami](https://discuss.elastic.co/u/vlasami)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 8:38pm UTC](https://discuss.elastic.co/t/runtime-field-query-performance/325193 "2023-02-09T20:38:27Z")

</div>

Hi, We're evaluating the use runtime fields vs indexed fields (keyword). We have an object field (let's call it X) under which we can have arbitrary amount of fields. Unfortunately we cannot control the sending party, …

---

## [Http filter in Logstash](https://discuss.elastic.co/t/http-filter-in-logstash/325146)

<div class="topic-metadata">

**Author:** [@manikanta](https://discuss.elastic.co/u/manikanta)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 8:28pm UTC](https://discuss.elastic.co/t/http-filter-in-logstash/325146 "2023-02-09T20:28:42Z")

</div>

hey I want to know how to pass a filters output as request body to http filter I am trying to pass output of mutate filter as body to http filter. mutate { remove\_field =\> \[ "@timestamp", "@version"\] } …

---

## [Unable to add multiple hostname while configuring CPU and Memory Alerts](https://discuss.elastic.co/t/unable-to-add-multiple-hostname-while-configuring-cpu-and-memory-alerts/325189)

<div class="topic-metadata">

**Author:** [@soumya201](https://discuss.elastic.co/u/soumya201)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:35pm UTC](https://discuss.elastic.co/t/unable-to-add-multiple-hostname-while-configuring-cpu-and-memory-alerts/325189 "2023-02-09T19:35:05Z")

</div>

---

## [Need to know ways of controlling the write to storage account for event hub access](https://discuss.elastic.co/t/need-to-know-ways-of-controlling-the-write-to-storage-account-for-event-hub-access/325179)

<div class="topic-metadata">

**Author:** [@karthik\_Ravichandran](https://discuss.elastic.co/u/karthik_Ravichandran)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 6:27pm UTC](https://discuss.elastic.co/t/need-to-know-ways-of-controlling-the-write-to-storage-account-for-event-hub-access/325179 "2023-02-09T18:27:56Z")

</div>

since its writing every 5 seconds from azure event hub to storage , its causing more cost utilization , instead we want to make it delay so that we can reduce the cost of ingesting the events , we are not having any iss…

---

## [Unable to connect logstash 8.6.1 to elastic 6.8.23 with SSL](https://discuss.elastic.co/t/unable-to-connect-logstash-8-6-1-to-elastic-6-8-23-with-ssl/324932)

<div class="topic-metadata">

**Author:** [@Patrick\_Lacson](https://discuss.elastic.co/u/Patrick_Lacson)\
**Replies:** 7\
**Last updated:** [February 9, 2023, 6:21pm UTC](https://discuss.elastic.co/t/unable-to-connect-logstash-8-6-1-to-elastic-6-8-23-with-ssl/324932 "2023-02-09T18:21:06Z")

</div>

I'm able to connect to elasticsearch 6.8.23 with logstash 8.6.1 but when I connect to an SSL enabled elasticsearch (using signed CERTS), I get the 503 error unable to connect. My output config looks like this: It works…

---

## [Show dynamic trend values in Dashboard](https://discuss.elastic.co/t/show-dynamic-trend-values-in-dashboard/325182)

<div class="topic-metadata">

**Author:** [@beijo](https://discuss.elastic.co/u/beijo)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 5:28pm UTC](https://discuss.elastic.co/t/show-dynamic-trend-values-in-dashboard/325182 "2023-02-09T17:28:18Z")

</div>

Hi all, I have documents which include a count field (numbers). I want to implement a dashboard, in which based on the selected timerange, the difference of the first document's count value and the last documents count …

---

## [Elastic agent packet beat integration crash windows](https://discuss.elastic.co/t/elastic-agent-packet-beat-integration-crash-windows/325169)

<div class="topic-metadata">

**Author:** [@lordtmk](https://discuss.elastic.co/u/lordtmk)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:02pm UTC](https://discuss.elastic.co/t/elastic-agent-packet-beat-integration-crash-windows/325169 "2023-02-09T16:02:54Z")

</div>

Hello, I tried to add Packet Capture Integration to a Windows Elastic Agent but packetbeat keeps crashing and dont send no logs. I'm in self managed mode with dedicated fleet server. Every other beat or integration wor…

---

## [Update by query with Logstash http output message](https://discuss.elastic.co/t/update-by-query-with-logstash-http-output-message/325180)

<div class="topic-metadata">

**Author:** [@Carlitoz](https://discuss.elastic.co/u/Carlitoz)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:56pm UTC](https://discuss.elastic.co/t/update-by-query-with-logstash-http-output-message/325180 "2023-02-09T16:56:04Z")

</div>

I am using Logstash to update by query existing Elasticsearch documents with an additional field that contains aggregate values extracted from Potgresql table. I use elastichsearch output to load one index using document…

---

## [Prefer matching search text in beginning of result using elasticsearch in ElasticSearch Match Query](https://discuss.elastic.co/t/prefer-matching-search-text-in-beginning-of-result-using-elasticsearch-in-elasticsearch-match-query/325178)

<div class="topic-metadata">

**Author:** [@pavel4008](https://discuss.elastic.co/u/pavel4008)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:44pm UTC](https://discuss.elastic.co/t/prefer-matching-search-text-in-beginning-of-result-using-elasticsearch-in-elasticsearch-match-query/325178 "2023-02-09T16:44:22Z")

</div>

I have a query and sometimes I can't get to return the most relevant answer: GET /items2/\_search { "query": { "match": { "description": { "query": "query\_value", "fuzzines…

---

## [How is filter processed in query/fetch phases?](https://discuss.elastic.co/t/how-is-filter-processed-in-query-fetch-phases/325174)

<div class="topic-metadata">

**Author:** [@Robin\_Zimmerman](https://discuss.elastic.co/u/Robin_Zimmerman)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:18pm UTC](https://discuss.elastic.co/t/how-is-filter-processed-in-query-fetch-phases/325174 "2023-02-09T16:18:05Z")

</div>

I'm trying to understand how a filter is processed by the cluster. In particular, I have a metric that gives me the average time queries spend in the "query phase", and using the "took" time I can get an understanding of…

---

## [Query get documents by giving an array of document ids same order of array](https://discuss.elastic.co/t/query-get-documents-by-giving-an-array-of-document-ids-same-order-of-array/325172)

<div class="topic-metadata">

**Author:** [@Guillaume23](https://discuss.elastic.co/u/Guillaume23)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:14pm UTC](https://discuss.elastic.co/t/query-get-documents-by-giving-an-array-of-document-ids-same-order-of-array/325172 "2023-02-09T16:14:42Z")

</div>

Hi, I am a beginner with Elasticsearch and my application is using it for monitoring and search engine.I am currently using ES 5.6.4. I would like to know if it's possible to get documents by giving an array of documen…

---

## [\[bool\] failed to parse field \[filter\]"](https://discuss.elastic.co/t/bool-failed-to-parse-field-filter/325131)

<div class="topic-metadata">

**Author:** [@Test\_Acc](https://discuss.elastic.co/u/Test_Acc)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 3:42pm UTC](https://discuss.elastic.co/t/bool-failed-to-parse-field-filter/325131 "2023-02-09T15:42:37Z")

</div>

Hi i am pretty new to kibana and elastisearch, we upgraded from kibana/elastisearch 7.16.3 to 8.5.2 and since then the dashboard has been less than friendly here is a error that has stumped us ///////////////////////…

---

## [Select all facets](https://discuss.elastic.co/t/select-all-facets/325149)

<div class="topic-metadata">

**Author:** [@athiraaravindan](https://discuss.elastic.co/u/athiraaravindan)\
**Replies:** 4\
**Last updated:** [February 9, 2023, 3:40pm UTC](https://discuss.elastic.co/t/select-all-facets/325149 "2023-02-09T15:40:20Z")

</div>

how can a select all facets values on a page load using the config

---

## [Initializing ELK stack in production environment (AWS EC2)](https://discuss.elastic.co/t/initializing-elk-stack-in-production-environment-aws-ec2/325160)

<div class="topic-metadata">

**Author:** [@st3fus](https://discuss.elastic.co/u/st3fus)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 3:11pm UTC](https://discuss.elastic.co/t/initializing-elk-stack-in-production-environment-aws-ec2/325160 "2023-02-09T15:11:23Z")

</div>

Hey there, just have a general question about initializing ELK stack, I'm launching it with docker, following deviantony/docker-elk guide and his repository. I'm just wondering should i change '0.0.0.0' values for hosts …

---

## [How to completely uninstall ELK?](https://discuss.elastic.co/t/how-to-completely-uninstall-elk/325112)

<div class="topic-metadata">

**Author:** [@usr4](https://discuss.elastic.co/u/usr4)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 2:56pm UTC](https://discuss.elastic.co/t/how-to-completely-uninstall-elk/325112 "2023-02-09T14:56:41Z")

</div>

Hi everyone, I hastily installed ELK and x-pack on a Mac many years ago, the version is 5.6.3. I forgot how it was installed in the first place, now I wanted to uninstall them all clean and install a different version …

---

## [Can I use grok patterns inside of transform for a watcher?](https://discuss.elastic.co/t/can-i-use-grok-patterns-inside-of-transform-for-a-watcher/325063)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 2:51pm UTC](https://discuss.elastic.co/t/can-i-use-grok-patterns-inside-of-transform-for-a-watcher/325063 "2023-02-09T14:51:36Z")

</div>

I got this transform for a watcher, and it's failing at the "grok" point: "transform": { "script": { "source": """ def finalMessage = "A new workset has been created in a Revit model. \\\\n\\\\n"…

---

## [Index to file (.json)](https://discuss.elastic.co/t/index-to-file-json/324683)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 2:50pm UTC](https://discuss.elastic.co/t/index-to-file-json/324683 "2023-02-09T14:50:53Z")

</div>

Hi, I have a running Elastic node with an index. I'm constantly inserting documents into the index in a process that I can't stop. I need to 'export' the index to a file (e.g., a .json). I've check alternatives to do th…

---

## [Replacing Self-Signed Certificates with Corporate CA Certificates](https://discuss.elastic.co/t/replacing-self-signed-certificates-with-corporate-ca-certificates/324140)

<div class="topic-metadata">

**Author:** [@jceddy](https://discuss.elastic.co/u/jceddy)\
**Replies:** 6\
**Last updated:** [February 9, 2023, 2:23pm UTC](https://discuss.elastic.co/t/replacing-self-signed-certificates-with-corporate-ca-certificates/324140 "2023-02-09T14:23:21Z")

</div>

I am working on changing over the certificates used for communication between elasticsearch nodes, and for communication between other applications and elasticsearch, from self-signed certificates generated by elasticsea…

---

## [How to use boxplot buckets for plotly?](https://discuss.elastic.co/t/how-to-use-boxplot-buckets-for-plotly/325148)

<div class="topic-metadata">

**Author:** [@Emporea](https://discuss.elastic.co/u/Emporea)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 2:16pm UTC](https://discuss.elastic.co/t/how-to-use-boxplot-buckets-for-plotly/325148 "2023-02-09T14:16:02Z")

</div>

I want to create a boxplot graph using plotly.js and elasticsearch. Elasticsearch has an inbuild boxplot aggregation that returns this for each trace: { "aggregations": { "load\_time\_boxplot": { "min": 0.0, …

---

## [All the fields are not imported](https://discuss.elastic.co/t/all-the-fields-are-not-imported/325126)

<div class="topic-metadata">

**Author:** [@sabrine2002](https://discuss.elastic.co/u/sabrine2002)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 10:02am UTC](https://discuss.elastic.co/t/all-the-fields-are-not-imported/325126 "2023-02-09T10:02:35Z")

</div>

Im new to kibana, while creating an index pattern using JSON file, not all fields in my json file are created. this is my json file: \[ { "\_id": "c3d15040-198c-11td-a32c-8562022990ba", "\_type": "index-patte…

---

## [How platinum licensing work with Elasticsearch. Is it node based or cluster based?](https://discuss.elastic.co/t/how-platinum-licensing-work-with-elasticsearch-is-it-node-based-or-cluster-based/325144)

<div class="topic-metadata">

**Author:** [@kommineni24](https://discuss.elastic.co/u/kommineni24)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 1:42pm UTC](https://discuss.elastic.co/t/how-platinum-licensing-work-with-elasticsearch-is-it-node-based-or-cluster-based/325144 "2023-02-09T13:42:11Z")

</div>

Currently, we are a little confused about how platinum licensing work with Elasticsearch. Is it node-based or cluster-based? For example, we have two six nodes clusters(Each Cluster - Three masters with 16 GB RAM each+ …

---

## [Facing issue with kibana and elasticsearch](https://discuss.elastic.co/t/facing-issue-with-kibana-and-elasticsearch/325132)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 1:32pm UTC](https://discuss.elastic.co/t/facing-issue-with-kibana-and-elasticsearch/325132 "2023-02-09T13:32:24Z")

</div>

Hi Team, I have installed the elasticsearch and kibana throgh eck , its working I can able to login If we login first time i'm getting issue like \< elastic did not load properly check the server output for information\> …

---

## [Logstash syslog fields not removed in index](https://discuss.elastic.co/t/logstash-syslog-fields-not-removed-in-index/325060)

<div class="topic-metadata">

**Author:** [@gt2847c](https://discuss.elastic.co/u/gt2847c)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 1:25pm UTC](https://discuss.elastic.co/t/logstash-syslog-fields-not-removed-in-index/325060 "2023-02-09T13:25:39Z")

</div>

I created a config file to ingest Cisco syslog output. When I run the config via command line (/usr/share/logstash/bin/logstash -f cisco.conf -r) everything works as expected. The fields I want show up properly in both…

---

## [Fetching, ingesting and merging data from REST API in 2023](https://discuss.elastic.co/t/fetching-ingesting-and-merging-data-from-rest-api-in-2023/325143)

<div class="topic-metadata">

**Author:** [@NiklasHBB](https://discuss.elastic.co/u/NiklasHBB)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 1:07pm UTC](https://discuss.elastic.co/t/fetching-ingesting-and-merging-data-from-rest-api-in-2023/325143 "2023-02-09T13:07:18Z")

</div>

I want to fetch and ingest data from several REST APIs. In previous discussions in 2019 and 2020 it was recommended to use logstash http\_poller input plugin. Is that still the best way to go with fleet and elastic agents…

---

## [Need help with search query](https://discuss.elastic.co/t/need-help-with-search-query/325048)

<div class="topic-metadata">

**Author:** [@PA3mEP](https://discuss.elastic.co/u/PA3mEP)\
**Replies:** 4\
**Last updated:** [February 9, 2023, 1:01pm UTC](https://discuss.elastic.co/t/need-help-with-search-query/325048 "2023-02-09T13:01:10Z")

</div>

Hi, guys. Sorry to interrupt your beautiful, but may be someone can help me with search query I'm trying to figure out. Here goes.. I have an index where filebeat sends logs. For example /var/log/messages. Documents loo…

---

## [Fuzzy query don't working as expected](https://discuss.elastic.co/t/fuzzy-query-dont-working-as-expected/325070)

<div class="topic-metadata">

**Author:** [@pavel4008](https://discuss.elastic.co/u/pavel4008)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 11:29am UTC](https://discuss.elastic.co/t/fuzzy-query-dont-working-as-expected/325070 "2023-02-09T11:29:08Z")

</div>

Hello! Recently I started studying elasticsearch(8.6.1) and got a very incomprehensible behavior. My index: PUT items2/\_settings { "settings": { "analysis": { "filter": { "ru\_stop": { "ty…

---

## [Monitoring Apache Kafka MirrorMaker 2](https://discuss.elastic.co/t/monitoring-apache-kafka-mirrormaker-2/324587)

<div class="topic-metadata">

**Author:** [@perrocontodo](https://discuss.elastic.co/u/perrocontodo)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 10:29am UTC](https://discuss.elastic.co/t/monitoring-apache-kafka-mirrormaker-2/324587 "2023-02-09T10:29:55Z")

</div>

I was wondering if there are any plans to update the Metricbeat module for Kafka, to allow monitoring of MirrorMaker 2. AFAICS there are a few metricsets that make use of JMX to extract information about Kafka. For examp…

---

## [Microsoft SQL Server Password](https://discuss.elastic.co/t/microsoft-sql-server-password/324786)

<div class="topic-metadata">

**Author:** [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 10:18am UTC](https://discuss.elastic.co/t/microsoft-sql-server-password/324786 "2023-02-09T10:18:47Z")

</div>

Hello, We are trying to utilize the Microsoft SQL Server integration in Fleet but having an issue when specifying the password which contains special characters such as }, ?, @ etc. but getting a parsing error: could …

---

## [Turn off “Elasticsearch built-in security features are not enabled” notifications from Python?](https://discuss.elastic.co/t/turn-off-elasticsearch-built-in-security-features-are-not-enabled-notifications-from-python/325034)

<div class="topic-metadata">

**Author:** [@mmoraschini](https://discuss.elastic.co/u/mmoraschini)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 9:43am UTC](https://discuss.elastic.co/t/turn-off-elasticsearch-built-in-security-features-are-not-enabled-notifications-from-python/325034 "2023-02-09T09:43:51Z")

</div>

With respect to this question Which is about silencing the error ElasticsearchWarning: Elasticsearch built-in security features are not enabled. Without authentication, your cluster could be accessible to anyone. See…

---

## [How to disable certificate verification in Kibana webhook](https://discuss.elastic.co/t/how-to-disable-certificate-verification-in-kibana-webhook/325119)

<div class="topic-metadata">

**Author:** [@heric](https://discuss.elastic.co/u/heric)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 9:38am UTC](https://discuss.elastic.co/t/how-to-disable-certificate-verification-in-kibana-webhook/325119 "2023-02-09T09:38:45Z")

</div>

Hi All, I am trying to send a webhook from kibana toward webhook server with self signed certificate, but i am getting below error while testing the webhook connector from kibana. I have tried to add below setting in e…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=637)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=639)
