# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=643

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 644

---

## [I am trying to add special character in logstash config](https://discuss.elastic.co/t/i-am-trying-to-add-special-character-in-logstash-config/324785)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 6:02pm UTC](https://discuss.elastic.co/t/i-am-trying-to-add-special-character-in-logstash-config/324785 "2023-02-06T18:02:23Z")

</div>

Hi I am sharing log pattern in below. 2023-02-06T10:10:42.075890912Z stdout F 2023-02-06 10:10:42.075 \[DEBUG\] - {"logtype":"INFO","request":{"operation":"XXXXXX","trackingID":"abccc","usecase":"xyz"} I am trying to pu…

---

## [Grok fiels are removed by aggregate section](https://discuss.elastic.co/t/grok-fiels-are-removed-by-aggregate-section/324798)

<div class="topic-metadata">

**Author:** [@Miriam](https://discuss.elastic.co/u/Miriam)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 5:54pm UTC](https://discuss.elastic.co/t/grok-fiels-are-removed-by-aggregate-section/324798 "2023-02-06T17:54:09Z")

</div>

I have follwoing file structure: id, iduser,datetimInit, dateTimeends 0001 0001 2023-02-03 04:45:16.78 2023-02-03 04:46:16.78 0002 0001 2023-02-03 08:45:16.78 2023-02-03 08:46:16.78 0003 0002 2023-02-04 04:45:16.78 2023…

---

## [Heartbeat add fild Source IP](https://discuss.elastic.co/t/heartbeat-add-fild-source-ip/324667)

<div class="topic-metadata">

**Author:** [@brunopsitech](https://discuss.elastic.co/u/brunopsitech)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 5:50pm UTC](https://discuss.elastic.co/t/heartbeat-add-fild-source-ip/324667 "2023-02-06T17:50:22Z")

</div>

Would it be possible to add in the options of the monitors an output parameter for a certain IP when performing the ICMP test? It would be used in firewall environments that have 2 or more WANs, so it could be tested whi…

---

## [Query\_shard\_exception](https://discuss.elastic.co/t/query-shard-exception/324756)

<div class="topic-metadata">

**Author:** [@Tussingh](https://discuss.elastic.co/u/Tussingh)\
**Replies:** 7\
**Last updated:** [February 6, 2023, 5:35pm UTC](https://discuss.elastic.co/t/query-shard-exception/324756 "2023-02-06T17:35:28Z")

</div>

I am getting below error when I am trying to query :slight\_smile : { "error": { "root\_cause": \[ { "type": "query\_shard\_exception", "reason": "failed to create query: \[nested\] failed to find nested object under path…

---

## [Winlogbeat - Crash 7.17.8](https://discuss.elastic.co/t/winlogbeat-crash-7-17-8/324816)

<div class="topic-metadata">

**Author:** [@novaksam](https://discuss.elastic.co/u/novaksam)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 5:14pm UTC](https://discuss.elastic.co/t/winlogbeat-crash-7-17-8/324816 "2023-02-06T17:14:23Z")

</div>

I've been having issues with Winlogbeat for a while now, but I figured I'd finally get someone to look at it. The last working version of Winlogbeat I've used that hasn't shown this issue is 7.17.3, but I wasn't able to …

---

## [Logstash slow processing of events](https://discuss.elastic.co/t/logstash-slow-processing-of-events/324392)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 11\
**Last updated:** [February 6, 2023, 5:02pm UTC](https://discuss.elastic.co/t/logstash-slow-processing-of-events/324392 "2023-02-06T17:02:58Z")

</div>

Hello, I'm trying to process events from logstash and I'm facing issue of slow processing of events.There are around 100k records.In logstash.yml I've enabled log.level debug. So far I can observe in 2 hours around 110…

---

## [Geographic Coordinates and Java API Client in 8.6](https://discuss.elastic.co/t/geographic-coordinates-and-java-api-client-in-8-6/324613)

<div class="topic-metadata">

**Author:** [@BenjaminD](https://discuss.elastic.co/u/BenjaminD)\
**Replies:** 12\
**Last updated:** [February 6, 2023, 4:24pm UTC](https://discuss.elastic.co/t/geographic-coordinates-and-java-api-client-in-8-6/324613 "2023-02-06T16:24:51Z")

</div>

Hello. I'm trying to create documents from a Java app. Those documents includes geographic coordinates (lat and lon in decimal form). Both Elasticsearch and the java client are in 8.6.0. In the beginning, no index exi…

---

## [Kibana sorting in asc/desc order in Discover not working](https://discuss.elastic.co/t/kibana-sorting-in-asc-desc-order-in-discover-not-working/324582)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 3:26pm UTC](https://discuss.elastic.co/t/kibana-sorting-in-asc-desc-order-in-discover-not-working/324582 "2023-02-06T15:26:22Z")

</div>

Hello, In Discover mode I am not able to sort the duration field in ascending order. It continues to show in descending order. Please guide. We are using 7.6.2 stack Thanks

---

## [How to use conflict.proceed and retry on conflict in elastic search .net](https://discuss.elastic.co/t/how-to-use-conflict-proceed-and-retry-on-conflict-in-elastic-search-net/324806)

<div class="topic-metadata">

**Author:** [@Arvind\_Sharma](https://discuss.elastic.co/u/Arvind_Sharma)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 3:23pm UTC](https://discuss.elastic.co/t/how-to-use-conflict-proceed-and-retry-on-conflict-in-elastic-search-net/324806 "2023-02-06T15:23:59Z")

</div>

Can anyone help me to pass conflict = proceed and retry on conflict params in Bulk and Delete methods of elastic search.net.

---

## [Convert string field to geo\_point field for map visualisation](https://discuss.elastic.co/t/convert-string-field-to-geo-point-field-for-map-visualisation/324397)

<div class="topic-metadata">

**Author:** [@cf4455](https://discuss.elastic.co/u/cf4455)\
**Replies:** 4\
**Last updated:** [February 6, 2023, 2:42pm UTC](https://discuss.elastic.co/t/convert-string-field-to-geo-point-field-for-map-visualisation/324397 "2023-02-06T14:42:59Z")

</div>

Hello, We collect in our logs, among other things, geo-coordinates and their accuracy in 2 "string" fields. Currently there are over 3,200,000 logs since the beginning of 2021. Now we want to display these coordinates o…

---

## [BERTopic en ElasticSearch](https://discuss.elastic.co/t/bertopic-en-elasticsearch/324790)

<div class="topic-metadata">

**Author:** [@alvaro\_ing](https://discuss.elastic.co/u/alvaro_ing)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 12:17pm UTC](https://discuss.elastic.co/t/bertopic-en-elasticsearch/324790 "2023-02-06T12:17:16Z")

</div>

Buenas, Me gustaría poder importar un modelo entrenado con BERTopic dentro de Elasticsearch. Como es de la familia de los BERT entiendo que deberia poder importarse pero no se como una vez tengo el modelo entrenado pued…

---

## [How to sum the values in the column (bytes) and convert it GB?](https://discuss.elastic.co/t/how-to-sum-the-values-in-the-column-bytes-and-convert-it-gb/324563)

<div class="topic-metadata">

**Author:** [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)\
**Replies:** 3\
**Last updated:** [February 6, 2023, 11:19am UTC](https://discuss.elastic.co/t/how-to-sum-the-values-in-the-column-bytes-and-convert-it-gb/324563 "2023-02-06T11:19:12Z")

</div>

Hey Folks, I'm struggling to sum the value in record (bytes) and visualize it in table. Any idea how would i achieve the SUM and converted to GB?

---

## [While Exporting Data from Kibana into CSV file, variables are getting exported as "Part of"](https://discuss.elastic.co/t/while-exporting-data-from-kibana-into-csv-file-variables-are-getting-exported-as-part-of/324772)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 4\
**Last updated:** [February 6, 2023, 11:18am UTC](https://discuss.elastic.co/t/while-exporting-data-from-kibana-into-csv-file-variables-are-getting-exported-as-part-of/324772 "2023-02-06T11:18:20Z")

</div>

While Exporting Data from Kibana into CSV file, variables are getting exported as Part of Variable. For e.g. in below screenshot, "RRC Success" is one of the variable created and available as a complete value However…

---

## [Enable Cross Cluster Search vs Monitoring](https://discuss.elastic.co/t/enable-cross-cluster-search-vs-monitoring/324749)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 11:16am UTC](https://discuss.elastic.co/t/enable-cross-cluster-search-vs-monitoring/324749 "2023-02-06T11:16:24Z")

</div>

Just installed a ES cluster 8.6.1 and a Kibana 8.6.1, trying to enable cluster monitoring, but attempting to access monitoring app from kibana, it just tells me that my cluster has monitoring.ui.ccs.enabled=true. Dunno h…

---

## [Unable to initialize Fleet](https://discuss.elastic.co/t/unable-to-initialize-fleet/324643)

<div class="topic-metadata">

**Author:** [@beth](https://discuss.elastic.co/u/beth)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 10:52am UTC](https://discuss.elastic.co/t/unable-to-initialize-fleet/324643 "2023-02-06T10:52:25Z")

</div>

Hi all, I am getting this error: unable to initialize Fleet search\_phase\_execution\_exception: \[no\_shard\_available\_action\_exception\] Reason: null Deployment Version 8.2.2 Someone please help?

---

## [Elasticsearch boolean term query latency increases with zero match terms](https://discuss.elastic.co/t/elasticsearch-boolean-term-query-latency-increases-with-zero-match-terms/324619)

<div class="topic-metadata">

**Author:** [@vikcher123](https://discuss.elastic.co/u/vikcher123)\
**Replies:** 3\
**Last updated:** [February 6, 2023, 10:41am UTC](https://discuss.elastic.co/t/elasticsearch-boolean-term-query-latency-increases-with-zero-match-terms/324619 "2023-02-06T10:41:56Z")

</div>

I'm observing some interesting behavior with boolean term queries on Elasticsearch that I'd like to understand further. Each document in the index has several terms under the section ev\_tags. I'm issuing queries like b…

---

## [New Java API updateRequest as String](https://discuss.elastic.co/t/new-java-api-updaterequest-as-string/324783)

<div class="topic-metadata">

**Author:** [@schmermeister](https://discuss.elastic.co/u/schmermeister)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 10:38am UTC](https://discuss.elastic.co/t/new-java-api-updaterequest-as-string/324783 "2023-02-06T10:38:10Z")

</div>

Is there a way with the new Java API to update a document as JSON-String? Problem is, i have a Object which i want to update and this contains null value which must be serialized. By default jackson ignores null value t…

---

## [Monitoring several url and setting schedule](https://discuss.elastic.co/t/monitoring-several-url-and-setting-schedule/324104)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 3\
**Last updated:** [February 6, 2023, 10:30am UTC](https://discuss.elastic.co/t/monitoring-several-url-and-setting-schedule/324104 "2023-02-06T10:30:06Z")

</div>

Hello, I use heartbeat module to monitor http responses, with Elastic v7.17.6. I have to monitor several url. Do I have to use this syntax : heartbeat.monitors: - type: http urls: \["http://url1", "http://url2", "ht…

---

## [Macos install elastic agent 8.6.1 unhealthy](https://discuss.elastic.co/t/macos-install-elastic-agent-8-6-1-unhealthy/324782)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/macos-install-elastic-agent-8-6-1-unhealthy/324782 "2023-02-06T10:10:44Z")

</div>

I'm installing elastic agent 8.6.1 and the backend says unhealthy，What can be done about it? Checking the status shows the following error： elastic-agent-8.6.1-darwin-x86\_64 % sudo /Library/Elastic/Agent/elastic-age…

---

## [Logstash and delete of gz files](https://discuss.elastic.co/t/logstash-and-delete-of-gz-files/324514)

<div class="topic-metadata">

**Author:** [@Rhh](https://discuss.elastic.co/u/Rhh)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 10:07am UTC](https://discuss.elastic.co/t/logstash-and-delete-of-gz-files/324514 "2023-02-06T10:07:58Z")

</div>

Hi I have the following my conf file ... input { file { path =\> "C:/TDS.Extra/ConsoleApp13/ConsoleApp13/bin/Debug/test.gz" sincedb\_path =\> "nul" mode =\> "read" file\_completed\_action =\> "delete" codec =\> "json" } …

---

## [【Macos】elastic agent 8.5.2 and 8.5.3 install unhealthy](https://discuss.elastic.co/t/macos-elastic-agent-8-5-2-and-8-5-3-install-unhealthy/324596)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 10:02am UTC](https://discuss.elastic.co/t/macos-elastic-agent-8-5-2-and-8-5-3-install-unhealthy/324596 "2023-02-06T10:02:11Z")

</div>

hello, I am trying to install elastic agent 8.5.2 and 8.5.3 in macos and I get the following error, what can I do to solve it? Status: FAILED Message: app endpoint-security--8.5.3-03e0f317: failed to start connection cr…

---

## [How to go from JSON-based aggregation to UI visualization?](https://discuss.elastic.co/t/how-to-go-from-json-based-aggregation-to-ui-visualization/324774)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 9:56am UTC](https://discuss.elastic.co/t/how-to-go-from-json-based-aggregation-to-ui-visualization/324774 "2023-02-06T09:56:08Z")

</div>

Hi, In the Kibana documentation about aggregations, there is only information about how to write a JSON query and get an aggregated result. However I cannot find any documentation on how to go from there to a UI visual…

---

## [\[URGENT\] Corpora Definiton , no base-url defined || Indexing Local dump.json](https://discuss.elastic.co/t/urgent-corpora-definiton-no-base-url-defined-indexing-local-dump-json/324515)

<div class="topic-metadata">

**Author:** [@Sriram\_Kumar](https://discuss.elastic.co/u/Sriram_Kumar)\
**Replies:** 6\
**Last updated:** [February 6, 2023, 9:32am UTC](https://discuss.elastic.co/t/urgent-corpora-definiton-no-base-url-defined-indexing-local-dump-json/324515 "2023-02-06T09:32:29Z")

</div>

Hi I am very new to esRally , I tried finding the similar topic but couldn't . Any help would be really appreciated. So , I have hosted a local es on docker. version : 8.5.2 , single node . I want to do benchmarking us…

---

## [java.security.AccessControlException: access denied (\\"java.net.SocketPermission\\" \\"localhost:0\\" \\"listen,resolve\\")](https://discuss.elastic.co/t/java-security-accesscontrolexception-access-denied-java-net-socketpermission-localhost-0-listen-resolve/324777)

<div class="topic-metadata">

**Author:** [@hitlll](https://discuss.elastic.co/u/hitlll)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 9:08am UTC](https://discuss.elastic.co/t/java-security-accesscontrolexception-access-denied-java-net-socketpermission-localhost-0-listen-resolve/324777 "2023-02-06T09:08:35Z")

</div>

I have configured SocketPermission ("localhost: 0", "listen, resolve"), but this error will still be reported. Please help me solve it. Thanks!

---

## [Audit logs stop on certain nodes in cluster](https://discuss.elastic.co/t/audit-logs-stop-on-certain-nodes-in-cluster/324519)

<div class="topic-metadata">

**Author:** [@ryuujin](https://discuss.elastic.co/u/ryuujin)\
**Replies:** 7\
**Last updated:** [February 6, 2023, 8:19am UTC](https://discuss.elastic.co/t/audit-logs-stop-on-certain-nodes-in-cluster/324519 "2023-02-06T08:19:39Z")

</div>

Hello! I have a production cluster running 20 nodes that I would like to configure audit logs for. Everything seems to be running correctly on 3 nodes, on the rest it stops logging events. When I restart the service on …

---

## [How to Differentiate Elastic Agent with same hostname](https://discuss.elastic.co/t/how-to-differentiate-elastic-agent-with-same-hostname/324763)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 8:01am UTC](https://discuss.elastic.co/t/how-to-differentiate-elastic-agent-with-same-hostname/324763 "2023-02-06T08:01:15Z")

</div>

Hi Everyone, I have multiple CentOS 7 running on VM. What i am trying to do is to monitor processes or services within each host. the problem is that all my host has default hostname. i already placed tags in fleet menu…

---

## [Required Privilege in Microsoft SQL Server to Connect With Elastic Integration and Logstash JDBC Plugin](https://discuss.elastic.co/t/required-privilege-in-microsoft-sql-server-to-connect-with-elastic-integration-and-logstash-jdbc-plugin/324510)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 7:13am UTC](https://discuss.elastic.co/t/required-privilege-in-microsoft-sql-server-to-connect-with-elastic-integration-and-logstash-jdbc-plugin/324510 "2023-02-06T07:13:16Z")

</div>

Hi Everyone, i would like to ask related with Microsoft SQL Integration and JDBC Plugin in logstash. as we know we need username and password to access the database with JDBC or Microsoft SQL Integration. my question wou…

---

## [Snapshot issue when running policy using Alibaba cloud S3](https://discuss.elastic.co/t/snapshot-issue-when-running-policy-using-alibaba-cloud-s3/324731)

<div class="topic-metadata">

**Author:** [@h.allaoui](https://discuss.elastic.co/u/h.allaoui)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 6:41am UTC](https://discuss.elastic.co/t/snapshot-issue-when-running-policy-using-alibaba-cloud-s3/324731 "2023-02-06T06:41:35Z")

</div>

Hi Community, I setup a repo using Alibaba cloud S3 storage and when I run an immediate snapshot it is working but when I run a snapshot policy based on that repo I am getting below error. { "type": "repository\_excep…

---

## [Vega: Set a text for empty data set](https://discuss.elastic.co/t/vega-set-a-text-for-empty-data-set/324758)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 6:38am UTC](https://discuss.elastic.co/t/vega-set-a-text-for-empty-data-set/324758 "2023-02-06T06:38:55Z")

</div>

Actually my condition same with this thread but when I try, it doesn't work for me. I did the filter transform and when there's no rows that shown after the transform, I want to make a static text to inform that.

---

## [Copy only Index Mapping from one cluster to another without the data](https://discuss.elastic.co/t/copy-only-index-mapping-from-one-cluster-to-another-without-the-data/324411)

<div class="topic-metadata">

**Author:** [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 6:37am UTC](https://discuss.elastic.co/t/copy-only-index-mapping-from-one-cluster-to-another-without-the-data/324411 "2023-02-06T06:37:11Z")

</div>

Hi, I have a cluster which has index mappings and data in it. I'm currently creating a new cluster where I have different set of data which need to be ingested with the same mappings like in the previous cluster. So, …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=642)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=644)
