# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=644

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 645

---

## [Can I search elastic keys with wildcard or substring](https://discuss.elastic.co/t/can-i-search-elastic-keys-with-wildcard-or-substring/324754)

<div class="topic-metadata">

**Author:** [@sarthik](https://discuss.elastic.co/u/sarthik)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 6:32am UTC](https://discuss.elastic.co/t/can-i-search-elastic-keys-with-wildcard-or-substring/324754 "2023-02-06T06:32:15Z")

</div>

I have the following patterns as keys in my data stored in elk indexes: \* Name \* \_name \* preffered\_name \* first\_name \* last\_name I need to query these keys, but the key names are not fixed, so need to search keys based…

---

## [Getting cluster security error after login](https://discuss.elastic.co/t/getting-cluster-security-error-after-login/324463)

<div class="topic-metadata">

**Author:** [@Kamal\_Khandelwal](https://discuss.elastic.co/u/Kamal_Khandelwal)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 6:05am UTC](https://discuss.elastic.co/t/getting-cluster-security-error-after-login/324463 "2023-02-06T06:05:03Z")

</div>

getting this error whenever i try to login, can someone please help me action \[cluster:monitor/main\] is unauthorized for user \[kamal\] with effective roles (assigned roles \[monitoring,network\] were not found), this a…

---

## [Elasticsearch overview - Indexingexing Latency - no data](https://discuss.elastic.co/t/elasticsearch-overview-indexingexing-latency-no-data/319856)

<div class="topic-metadata">

**Author:** [@Willliam](https://discuss.elastic.co/u/Willliam)\
**Replies:** 3\
**Last updated:** [February 6, 2023, 3:39am UTC](https://discuss.elastic.co/t/elasticsearch-overview-indexingexing-latency-no-data/319856 "2023-02-06T03:39:59Z")

</div>

es version: v8.1.3 kibana version: v8.1.3 monitory tpye: self monitoring Elasticsearch overview - Indexingexing Latency - no data please check the screenshot

---

## [Filebeat stopped working after an hour after the install](https://discuss.elastic.co/t/filebeat-stopped-working-after-an-hour-after-the-install/324538)

<div class="topic-metadata">

**Author:** [@Joshua\_John\_Consulta](https://discuss.elastic.co/u/Joshua_John_Consulta)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 3:08am UTC](https://discuss.elastic.co/t/filebeat-stopped-working-after-an-hour-after-the-install/324538 "2023-02-06T03:08:44Z")

</div>

Here's the error from the terminal: × filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; preset: enabled) Activ…

---

## [Content archival and retrieval app built on ELK](https://discuss.elastic.co/t/content-archival-and-retrieval-app-built-on-elk/324695)

<div class="topic-metadata">

**Author:** [@ryendluri](https://discuss.elastic.co/u/ryendluri)\
**Replies:** 1\
**Last updated:** [February 5, 2023, 11:11pm UTC](https://discuss.elastic.co/t/content-archival-and-retrieval-app-built-on-elk/324695 "2023-02-05T23:11:58Z")

</div>

is there an existing application that supports archiving data and retrieving data in a non-profit context? Thanks

---

## [ElasticSearch Snapshotting using Azure Repository Plugin - Storage Account with Azure DNS Zone](https://discuss.elastic.co/t/elasticsearch-snapshotting-using-azure-repository-plugin-storage-account-with-azure-dns-zone/324421)

<div class="topic-metadata">

**Author:** [@x00m](https://discuss.elastic.co/u/x00m)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 12:17pm UTC](https://discuss.elastic.co/t/elasticsearch-snapshotting-using-azure-repository-plugin-storage-account-with-azure-dns-zone/324421 "2023-02-01T12:17:03Z")

</div>

I'm using the Azure Repository plugin to take snapshot backups. I created a new Storage Account with the "Azure DNS Zone" option in the networking tab as shown :- If we select this option, then snapshot registration…

---

## [Elasticsearch-reconfigure-node errors and aborts](https://discuss.elastic.co/t/elasticsearch-reconfigure-node-errors-and-aborts/324724)

<div class="topic-metadata">

**Author:** [@H\_K7](https://discuss.elastic.co/u/H_K7)\
**Replies:** 1\
**Last updated:** [February 5, 2023, 10:20pm UTC](https://discuss.elastic.co/t/elasticsearch-reconfigure-node-errors-and-aborts/324724 "2023-02-05T22:20:06Z")

</div>

it errored on the 4th node I ran, previous 3 nodes when I ran reconfigure node with the token it didn't error out. error message ERROR: Aborting enrolling to cluster. Could not communicate with the node on any of the a…

---

## [401 Error : missing authentication credentials : elasticsearch version 7.6.2](https://discuss.elastic.co/t/401-error-missing-authentication-credentials-elasticsearch-version-7-6-2/324618)

<div class="topic-metadata">

**Author:** [@abhay14](https://discuss.elastic.co/u/abhay14)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 10:18pm UTC](https://discuss.elastic.co/t/401-error-missing-authentication-credentials-elasticsearch-version-7-6-2/324618 "2023-02-05T22:18:30Z")

</div>

I have followed the below wiki to enable the basic authentication Elastic verion 7.6 I am not sure how to configure default the username and password so But I am getting the error , curl -s --cacert config/certs/ca/c…

---

## [DEV TOOLS - Group indexes into 1](https://discuss.elastic.co/t/dev-tools-group-indexes-into-1/324666)

<div class="topic-metadata">

**Author:** [@vfeydel](https://discuss.elastic.co/u/vfeydel)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 10:15pm UTC](https://discuss.elastic.co/t/dev-tools-group-indexes-into-1/324666 "2023-02-05T22:15:22Z")

</div>

Hi, I have 66 index with a similar structure ike for example : abc\_1, abc\_2, abc\_3 .... abc\_n. They have a commun field name "identifiant". The id 1 may be in 1 or 2 or n index or only one and the same for the other id.…

---

## [Can't find my index](https://discuss.elastic.co/t/cant-find-my-index/324686)

<div class="topic-metadata">

**Author:** [@Martin\_Sander](https://discuss.elastic.co/u/Martin_Sander)\
**Replies:** 1\
**Last updated:** [February 5, 2023, 10:11pm UTC](https://discuss.elastic.co/t/cant-find-my-index/324686 "2023-02-05T22:11:22Z")

</div>

I have a problem finding my created intex in Kibana/Search App engine. I have an API with a bunch of articles and already created an index with a python script. When I browse 127.0.0.1:9200/articles I do get a response …

---

## [Backward Pagination with Elasticsearch Aggregation with Spring data Elasticsearch](https://discuss.elastic.co/t/backward-pagination-with-elasticsearch-aggregation-with-spring-data-elasticsearch/324607)

<div class="topic-metadata">

**Author:** [@Anuja\_Brahmankar](https://discuss.elastic.co/u/Anuja_Brahmankar)\
**Replies:** 1\
**Last updated:** [February 5, 2023, 4:36pm UTC](https://discuss.elastic.co/t/backward-pagination-with-elasticsearch-aggregation-with-spring-data-elasticsearch/324607 "2023-02-05T16:36:47Z")

</div>

Hi , I have aggregation Query with Composite Aggregation builder with spring data elasticsearch which provides after\_key value,which return last aggregated count with That I am able do forward pagination. Sample Query: …

---

## [Can you get different results from replica and primary if queried at the same time?](https://discuss.elastic.co/t/can-you-get-different-results-from-replica-and-primary-if-queried-at-the-same-time/324732)

<div class="topic-metadata">

**Author:** [@Diya\_Al\_Mahameed](https://discuss.elastic.co/u/Diya_Al_Mahameed)\
**Replies:** 6\
**Last updated:** [February 5, 2023, 4:20pm UTC](https://discuss.elastic.co/t/can-you-get-different-results-from-replica-and-primary-if-queried-at-the-same-time/324732 "2023-02-05T16:20:14Z")

</div>

in our system we get different responses and I speculate it caused by "Adaptive Replica Selection". the two queries are different but they should fetch the same document . The first query check if the document have bee…

---

## [Query nested array having n matching elements](https://discuss.elastic.co/t/query-nested-array-having-n-matching-elements/324744)

<div class="topic-metadata">

**Author:** [@Frankk](https://discuss.elastic.co/u/Frankk)\
**Replies:** 0\
**Last updated:** [February 5, 2023, 4:00pm UTC](https://discuss.elastic.co/t/query-nested-array-having-n-matching-elements/324744 "2023-02-05T16:00:24Z")

</div>

Is this possible? I am indexing web site user activity focusing on user comments across multiple web sites and databases. I am "fairly" new to ES and am addressing quite a large problem. So basic question... Along wi…

---

## [Invalid FieldReference](https://discuss.elastic.co/t/invalid-fieldreference/324365)

<div class="topic-metadata">

**Author:** [@ztony](https://discuss.elastic.co/u/ztony)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 3:14pm UTC](https://discuss.elastic.co/t/invalid-fieldreference/324365 "2023-02-05T15:14:19Z")

</div>

Does anyone see this "Invalid FieldReference" error? we added some mutations to the pipeline, but new field with the same error came out. see the error log below: An unexpected error occurred! {:error=\>org.logstash.Fiel…

---

## [Http filter Vs elasticsearch ouput](https://discuss.elastic.co/t/http-filter-vs-elasticsearch-ouput/324718)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 8\
**Last updated:** [February 5, 2023, 10:41am UTC](https://discuss.elastic.co/t/http-filter-vs-elasticsearch-ouput/324718 "2023-02-05T10:41:10Z")

</div>

Hello, I want to capture and process failures related to Elasticsearch being down and Elasticsearch output does not offer a way to handle this so, I want to do a POC and experiment with indexing events into Elasticsearc…

---

## [Blocked by: \[TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block\]](https://discuss.elastic.co/t/blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/324725)

<div class="topic-metadata">

**Author:** [@Baygon](https://discuss.elastic.co/u/Baygon)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 5:31am UTC](https://discuss.elastic.co/t/blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/324725 "2023-02-05T05:31:13Z")

</div>

Hi, I reached disk usage of 90%. I increased the disk space and now have 80% usage: /dev/root 562G 445G 118G 80% / I've tried to run the commands to remove the read only blocker: PUT \_cluster/settings { "…

---

## [Logstash crash when starting after messing the queue files](https://discuss.elastic.co/t/logstash-crash-when-starting-after-messing-the-queue-files/324708)

<div class="topic-metadata">

**Author:** [@Baygon](https://discuss.elastic.co/u/Baygon)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 3:34am UTC](https://discuss.elastic.co/t/logstash-crash-when-starting-after-messing-the-queue-files/324708 "2023-02-05T03:34:10Z")

</div>

I've just upgraded Logstash minor version from 7.13 to 7.17.9, but it doesn't restart, erroring about inability to create queues (there was a forced stop of Logstash, so I assume the files are corrupted). I tried to del…

---

## [Average on keyword of a nested object in Kibana Lens?](https://discuss.elastic.co/t/average-on-keyword-of-a-nested-object-in-kibana-lens/324716)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [February 5, 2023, 1:51am UTC](https://discuss.elastic.co/t/average-on-keyword-of-a-nested-object-in-kibana-lens/324716 "2023-02-05T01:51:57Z")

</div>

I'm working with Kibana Lens and I don't understand the results I'm getting. I started by running these commands in Dev Tools on a completely empty index called avg1 POST avg1/\_doc { "order\_items": \[ {"product":…

---

## [SSL certificate embedding in winlogbeat or auditbeat - Need example](https://discuss.elastic.co/t/ssl-certificate-embedding-in-winlogbeat-or-auditbeat-need-example/324720)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [February 4, 2023, 11:18pm UTC](https://discuss.elastic.co/t/ssl-certificate-embedding-in-winlogbeat-or-auditbeat-need-example/324720 "2023-02-04T23:18:33Z")

</div>

I'd like to know if someone can present a working example of their Beats config for Beats to Logstash with SSL, but using the embedding the certificate in the beats config as described in Configure SSL | Winlogbeat Refer…

---

## [Possible Bug: Unable to fetch term vectors after applying filter on ingested document](https://discuss.elastic.co/t/possible-bug-unable-to-fetch-term-vectors-after-applying-filter-on-ingested-document/324662)

<div class="topic-metadata">

**Author:** [@Ancel](https://discuss.elastic.co/u/Ancel)\
**Replies:** 1\
**Last updated:** [February 4, 2023, 5:19pm UTC](https://discuss.elastic.co/t/possible-bug-unable-to-fetch-term-vectors-after-applying-filter-on-ingested-document/324662 "2023-02-04T17:19:36Z")

</div>

Hi all. Situation: I am using Elasticsearch 8.4.1. I am ingesting a document, then via applying the apostrophe token filter, I want to remove every character from the apostrophe to the end of the term, apply a couple of…

---

## [FATAL Error: \[config validation of \[elasticsearch\].username\]](https://discuss.elastic.co/t/fatal-error-config-validation-of-elasticsearch-username/324714)

<div class="topic-metadata">

**Author:** [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Replies:** 0\
**Last updated:** [February 4, 2023, 3:06pm UTC](https://discuss.elastic.co/t/fatal-error-config-validation-of-elasticsearch-username/324714 "2023-02-04T15:06:44Z")

</div>

Hello Team, I had Elasticsearch, Logstash and Kibana v7.16.2 with xpack security based login enabled, So today i had upgraded my ELK versions to 8.6.1 using my docker-compose file, but when i start the kibana container …

---

## [ILM: empty indices didn't age-out](https://discuss.elastic.co/t/ilm-empty-indices-didnt-age-out/322980)

<div class="topic-metadata">

**Author:** [@Adam\_Lin](https://discuss.elastic.co/u/Adam_Lin)\
**Replies:** 7\
**Last updated:** [February 4, 2023, 2:40pm UTC](https://discuss.elastic.co/t/ilm-empty-indices-didnt-age-out/322980 "2023-02-04T14:40:29Z")

</div>

Hi, I create an ILM policy and apply it to my index template, everything works fine at first until after a day, there will be an empty index left Here is my ILM policy { "test-policy" : { "version" : 4, "mod…

---

## [Winlogbeat to kafka](https://discuss.elastic.co/t/winlogbeat-to-kafka/324710)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 0\
**Last updated:** [February 4, 2023, 1:00pm UTC](https://discuss.elastic.co/t/winlogbeat-to-kafka/324710 "2023-02-04T13:00:53Z")

</div>

hi everyone, I am trying to send data using wingbeat to Kafka to Logstash to elastic. but the winlogbeat is not shipping any data to kafka topic. when I started the winlogbeat service it created the topic but no data …

---

## [Failed to load SSL configuration](https://discuss.elastic.co/t/failed-to-load-ssl-configuration/324704)

<div class="topic-metadata">

**Author:** [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Replies:** 1\
**Last updated:** [February 4, 2023, 9:59am UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration/324704 "2023-02-04T09:59:50Z")

</div>

Hello Team, I had elasticsearch:7.16.2 version with xpack security based login enabled, So today i had changed elasticsearch and kibna versions to 8.6.1 in my docker-compose file, but it fails with below errors when i s…

---

## [JDBC Plugin - Missing Converter handling for full class name=com.ibm.db2.jcc.am.dc when parsing xml datatype in DB2](https://discuss.elastic.co/t/jdbc-plugin-missing-converter-handling-for-full-class-name-com-ibm-db2-jcc-am-dc-when-parsing-xml-datatype-in-db2/324631)

<div class="topic-metadata">

**Author:** [@khannaja](https://discuss.elastic.co/u/khannaja)\
**Replies:** 2\
**Last updated:** [February 4, 2023, 6:09am UTC](https://discuss.elastic.co/t/jdbc-plugin-missing-converter-handling-for-full-class-name-com-ibm-db2-jcc-am-dc-when-parsing-xml-datatype-in-db2/324631 "2023-02-04T06:09:12Z")

</div>

New to Logstash(ver 8.6.0), need to parse xml data type from db2 database. Keep getting "Missing Converter handling for full class" error. Read through most discussion post on this subject and tried a few things withou…

---

## [How to set maximum degree scale in x-axis](https://discuss.elastic.co/t/how-to-set-maximum-degree-scale-in-x-axis/324390)

<div class="topic-metadata">

**Author:** [@justseeyouagain](https://discuss.elastic.co/u/justseeyouagain)\
**Replies:** 10\
**Last updated:** [February 4, 2023, 3:22am UTC](https://discuss.elastic.co/t/how-to-set-maximum-degree-scale-in-x-axis/324390 "2023-02-04T03:22:00Z")

</div>

Hello, I am using vega-lite to finish my graph, but meet something confusion that how to set maximum degree scale in x-axis, just look at my pic { "$schema": "https://vega.github.io/schema/vega-lite/v2.json", "…

---

## [Can eland (python) filter on datetime64 fields?](https://discuss.elastic.co/t/can-eland-python-filter-on-datetime64-fields/324698)

<div class="topic-metadata">

**Author:** [@mike\_haberman](https://discuss.elastic.co/u/mike_haberman)\
**Replies:** 0\
**Last updated:** [February 4, 2023, 2:07am UTC](https://discuss.elastic.co/t/can-eland-python-filter-on-datetime64-fields/324698 "2023-02-04T02:07:32Z")

</div>

I get a NotImplementedError error for when I try to mask a field that's a datetime field: s\_t = pd.to\_datetime("2023-02-03T23:28:00", utc=True) # UTC t\_m = (df\['start'\] \>= s\_t) File /opt/conda/lib/python3.9/site-packag…

---

## [Create generic BoolQueryDescriptor with a generic type](https://discuss.elastic.co/t/create-generic-boolquerydescriptor-with-a-generic-type/324696)

<div class="topic-metadata">

**Author:** [@chachew](https://discuss.elastic.co/u/chachew)\
**Replies:** 0\
**Last updated:** [February 4, 2023, 12:43am UTC](https://discuss.elastic.co/t/create-generic-boolquerydescriptor-with-a-generic-type/324696 "2023-02-04T00:43:31Z")

</div>

Forgive me im new to Elasticsearch, NEST and dont really code in C# much. Im looking to create a helper class that i can store all my NEST descriptor helper functions in but im getting some errors in the code format. Its…

---

## [Write base64 decoded field from JSON message to a file](https://discuss.elastic.co/t/write-base64-decoded-field-from-json-message-to-a-file/324505)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 10:28pm UTC](https://discuss.elastic.co/t/write-base64-decoded-field-from-json-message-to-a-file/324505 "2023-02-03T22:28:19Z")

</div>

Hi Team, I have the following logstash pipeline configuration. input { tcp { port =\> 5102 codec =\> json } } filter { json { source =\> "message" remove\_field =\> \[ "message" \] } …

---

## [Beats output to logstash using SSL and Cert Errors](https://discuss.elastic.co/t/beats-output-to-logstash-using-ssl-and-cert-errors/324689)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 8:28pm UTC](https://discuss.elastic.co/t/beats-output-to-logstash-using-ssl-and-cert-errors/324689 "2023-02-03T20:28:53Z")

</div>

I am testing SSL from 7.x Beats clients to logstash. Logstash is configured for a wildcard cert to my domain, call it \*.acme.com. Connection works fine if Beats is configured to use a FQDN entry in the output, like log…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=643)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=645)
