# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=645

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 646

---

## [Grokparsefailure in processing a log file](https://discuss.elastic.co/t/grokparsefailure-in-processing-a-log-file/324682)

<div class="topic-metadata">

**Author:** [@Indrajit](https://discuss.elastic.co/u/Indrajit)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 7:54pm UTC](https://discuss.elastic.co/t/grokparsefailure-in-processing-a-log-file/324682 "2023-02-03T19:54:15Z")

</div>

While processing a large log file with logstash, we are getting grokparsefailure & dateparsefailure. We would like to know which line in the log file is causing the failure so that we can look into more details with gro…

---

## [JSON format Decode error](https://discuss.elastic.co/t/json-format-decode-error/324652)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 3\
**Last updated:** [February 3, 2023, 7:51pm UTC](https://discuss.elastic.co/t/json-format-decode-error/324652 "2023-02-03T19:51:49Z")

</div>

I am using : input { file { id =\> "my\_lt\_log" path =\> "/logs/logtransformer.log" type =\> "log" start\_position =\> "beginning" } } filter { if \[type\] == "log" { mutate { …

---

## [One index by dataset?](https://discuss.elastic.co/t/one-index-by-dataset/324684)

<div class="topic-metadata">

**Author:** [@m4rk](https://discuss.elastic.co/u/m4rk)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 7:31pm UTC](https://discuss.elastic.co/t/one-index-by-dataset/324684 "2023-02-03T19:31:22Z")

</div>

I need to store multiple datasets in Elasticsearch, each containing a high number of documents (something between 100,000 and 1,000,000). They have essentially the same structure. Since I use /analyze only one dataset at…

---

## [How make a master node in a 3 node cluster?](https://discuss.elastic.co/t/how-make-a-master-node-in-a-3-node-cluster/324656)

<div class="topic-metadata">

**Author:** [@H\_K7](https://discuss.elastic.co/u/H_K7)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 7:26pm UTC](https://discuss.elastic.co/t/how-make-a-master-node-in-a-3-node-cluster/324656 "2023-02-03T19:26:52Z")

</div>

Current 3 node cluster setup I have setup 3 node cluster { "cluster\_name" : "DEMOCLUSTER", "status" : "green", "timed\_out" : false, "number\_of\_nodes" : 3, "number\_of\_data\_nodes" : 3, "active\_primary\_shards"…

---

## [Python Search on Data Stream](https://discuss.elastic.co/t/python-search-on-data-stream/324680)

<div class="topic-metadata">

**Author:** [@yeppazu](https://discuss.elastic.co/u/yeppazu)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 5:33pm UTC](https://discuss.elastic.co/t/python-search-on-data-stream/324680 "2023-02-03T17:33:49Z")

</div>

Hello, we migrate from an Elasticsearch 7.17 with indeces to Elasticsearch 8.6.0 with data stream. In the past we had develop a python script to search inside indices with pattern "myname-\*". Because now beats use dat…

---

## [Extract part of a log using regex in KQL](https://discuss.elastic.co/t/extract-part-of-a-log-using-regex-in-kql/324677)

<div class="topic-metadata">

**Author:** [@dzlabs](https://discuss.elastic.co/u/dzlabs)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 4:45pm UTC](https://discuss.elastic.co/t/extract-part-of-a-log-using-regex-in-kql/324677 "2023-02-03T16:45:15Z")

</div>

I've log messages that looks like this 07:17:58.211 \[Thread.3;\] INFO Dispatcher - Message from XXX.XXX.XXX.XXX/PORT not dispatched, reason: blah blah, status=xyz I'm trying to query then visualize the different IP add…

---

## [Time shift Kibana vs. Elasticsearch](https://discuss.elastic.co/t/time-shift-kibana-vs-elasticsearch/324653)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [February 3, 2023, 4:22pm UTC](https://discuss.elastic.co/t/time-shift-kibana-vs-elasticsearch/324653 "2023-02-03T16:22:47Z")

</div>

Hi, I have an index in Elasticsearch. When I check - using the search API - the oldest timestamp of my data is 2023-01-13 00:00:00 (I previously applied a filter). However, when generating a Data View in Kibana the olde…

---

## [Elastic Version Moves very fast](https://discuss.elastic.co/t/elastic-version-moves-very-fast/323338)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 12\
**Last updated:** [February 3, 2023, 4:22pm UTC](https://discuss.elastic.co/t/elastic-version-moves-very-fast/323338 "2023-02-03T16:22:19Z")

</div>

What is the reason Elastic introduce and release different version at fast pace? it is very hard to keep up with it. And if you fall too much behind version then upgrade process gets harder and harder. for example I w…

---

## [Using Dell ECS s3 for snapshots](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 4:16pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658 "2023-02-03T16:16:18Z")

</div>

I am trying to configure a snapshot repository to use an on-premise s3 compatible solution - Dell ECS. When I issue the command to add the repository with our internal endpoint, ES still is attempting to connect to AWS …

---

## [Quick question about ILM](https://discuss.elastic.co/t/quick-question-about-ilm/324574)

<div class="topic-metadata">

**Author:** [@Monica\_majua](https://discuss.elastic.co/u/Monica_majua)\
**Replies:** 2\
**Last updated:** [February 3, 2023, 3:53pm UTC](https://discuss.elastic.co/t/quick-question-about-ilm/324574 "2023-02-03T15:53:53Z")

</div>

I would like to ask what is an ILM? and is it related to Legacy templates? Is possible to assign an ILM to a Legacy template?

---

## [It is possible to change the bulk\_max\_size and workers on a fleet managed agent?](https://discuss.elastic.co/t/it-is-possible-to-change-the-bulk-max-size-and-workers-on-a-fleet-managed-agent/324380)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 3:50pm UTC](https://discuss.elastic.co/t/it-is-possible-to-change-the-bulk-max-size-and-workers-on-a-fleet-managed-agent/324380 "2023-02-03T15:50:33Z")

</div>

Hello, I'm using Elastic Agent with the AWS Cloudwatch integration to consume some logs, the volume of logs are pretty high and I'm trying to improve the performance of the Elastic Agent. Filebeat per default uses just…

---

## [Autosize Canvas Webpage](https://discuss.elastic.co/t/autosize-canvas-webpage/323741)

<div class="topic-metadata">

**Author:** [@infraendboss](https://discuss.elastic.co/u/infraendboss)\
**Replies:** 1\
**Last updated:** [February 3, 2023, 3:47pm UTC](https://discuss.elastic.co/t/autosize-canvas-webpage/323741 "2023-02-03T15:47:45Z")

</div>

Hello amazing people! I want to share my Canvas page on a website, but the workpad isn't autoscaling when I use a bigger or smaller screen. I want the Canvas page to resize. I've tried tweaking the HTML code, but it has…

---

## [Logstash jdbc input mantain sql row order](https://discuss.elastic.co/t/logstash-jdbc-input-mantain-sql-row-order/324470)

<div class="topic-metadata">

**Author:** [@Ricardo\_Canuto](https://discuss.elastic.co/u/Ricardo_Canuto)\
**Replies:** 8\
**Last updated:** [February 3, 2023, 2:51pm UTC](https://discuss.elastic.co/t/logstash-jdbc-input-mantain-sql-row-order/324470 "2023-02-03T14:51:27Z")

</div>

Hi, I'm new to logstash and I'm trying to check if an sql job (and its steps) runs successfully. The query gets the step 0 (job output) and all the steps that have errors or warnings. I want to gather all the steps…

---

## [Compare data from two different Elasticsearch documents](https://discuss.elastic.co/t/compare-data-from-two-different-elasticsearch-documents/324660)

<div class="topic-metadata">

**Author:** [@slaterar](https://discuss.elastic.co/u/slaterar)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 2:16pm UTC](https://discuss.elastic.co/t/compare-data-from-two-different-elasticsearch-documents/324660 "2023-02-03T14:16:36Z")

</div>

I have two namespaces that I want to compare data from. The first is ab\*:cd.blah1 and second is ab\*:cd.blah2 and each contain a reference ID for a transaction in the same field name. I want to return values in ab\*:cd.bl…

---

## [How to create mapping for special characters and autocomplete search](https://discuss.elastic.co/t/how-to-create-mapping-for-special-characters-and-autocomplete-search/324115)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 2:14pm UTC](https://discuss.elastic.co/t/how-to-create-mapping-for-special-characters-and-autocomplete-search/324115 "2023-02-03T14:14:06Z")

</div>

Hi, In my project, I need to search data with special characters like č,ć,ž,đ, ?, !. What is the best practice for searching special characters in version 8.5? Also, how to create a mapping for autocomplete search? Ho…

---

## [Logstash - Dateformat yyyyMMdd HHmmss](https://discuss.elastic.co/t/logstash-dateformat-yyyymmdd-hhmmss/324311)

<div class="topic-metadata">

**Author:** [@A.Klos](https://discuss.elastic.co/u/A.Klos)\
**Replies:** 3\
**Last updated:** [February 3, 2023, 2:08pm UTC](https://discuss.elastic.co/t/logstash-dateformat-yyyymmdd-hhmmss/324311 "2023-02-03T14:08:04Z")

</div>

Hi, I have still problem to get right timestamp in elastic. One Row of log looks like: 20210611 111146 SOME Date Field ... I tried: grok { match =\> \[ "message" , "%{DATA:timestamp}" \] } date { …

---

## [Index CSV Timestamp](https://discuss.elastic.co/t/index-csv-timestamp/324579)

<div class="topic-metadata">

**Author:** [@gabrile\_jaime\_gomez](https://discuss.elastic.co/u/gabrile_jaime_gomez)\
**Replies:** 6\
**Last updated:** [February 3, 2023, 1:06pm UTC](https://discuss.elastic.co/t/index-csv-timestamp/324579 "2023-02-03T13:06:11Z")

</div>

hello I want to index some csv files. I want to be indexed with the modification date, not with the date entered in Elastic. Example My file has a modification date of 01/23/2022, that is the date that I would like to…

---

## [Elastic cloud 8.6 read only role](https://discuss.elastic.co/t/elastic-cloud-8-6-read-only-role/324569)

<div class="topic-metadata">

**Author:** [@aneeshks1982](https://discuss.elastic.co/u/aneeshks1982)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 11:20am UTC](https://discuss.elastic.co/t/elastic-cloud-8-6-read-only-role/324569 "2023-02-03T11:20:06Z")

</div>

Hi, Can someone tell me how to create a read-only role in elastic cloud 8.6 version

---

## [Create data view api](https://discuss.elastic.co/t/create-data-view-api/324641)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 10:52am UTC](https://discuss.elastic.co/t/create-data-view-api/324641 "2023-02-03T10:52:23Z")

</div>

Hi I have filebeat installed on one machine. and elasticsearch and kibana on one machine. and logstash on another machine. I am using an ansible playbook which picks logs using filebeat and ships it to logstash. Eevryth…

---

## [Auditbeat : couldn't connect to any of the configured Elasticsearch hosts](https://discuss.elastic.co/t/auditbeat-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/324640)

<div class="topic-metadata">

**Author:** [@rajith\_pathiraja](https://discuss.elastic.co/u/rajith_pathiraja)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 10:46am UTC](https://discuss.elastic.co/t/auditbeat-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts/324640 "2023-02-03T10:46:57Z")

</div>

Im configuring ELK SIEM and im unable to run complete " sudo auditbeat -e setup " as im getting following error Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasti…

---

## [Create multiple index str in filebeat and send logs to them with successfully rolover to next index](https://discuss.elastic.co/t/create-multiple-index-str-in-filebeat-and-send-logs-to-them-with-successfully-rolover-to-next-index/324636)

<div class="topic-metadata">

**Author:** [@Ananya](https://discuss.elastic.co/u/Ananya)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 10:18am UTC](https://discuss.elastic.co/t/create-multiple-index-str-in-filebeat-and-send-logs-to-them-with-successfully-rolover-to-next-index/324636 "2023-02-03T10:18:30Z")

</div>

Hello, I am trying to implement ilm policy. I have multiple index str so I create multiple aliases with their respective bootstrapping index to support them and set is\_write\_index to true. The logs flow to the bootstrap…

---

## [Can't add Integrations to agents](https://discuss.elastic.co/t/cant-add-integrations-to-agents/324512)

<div class="topic-metadata">

**Author:** [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Replies:** 8\
**Last updated:** [February 3, 2023, 10:04am UTC](https://discuss.elastic.co/t/cant-add-integrations-to-agents/324512 "2023-02-03T10:04:02Z")

</div>

Hi , I have a problem with can't add integration with agents. Now sure is it kibana cannot get the integration or other not updated. let see the img as below. Please help Thanks.

---

## [Create elastic user with more roles](https://discuss.elastic.co/t/create-elastic-user-with-more-roles/324632)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 9:31am UTC](https://discuss.elastic.co/t/create-elastic-user-with-more-roles/324632 "2023-02-03T09:31:12Z")

</div>

As part of bootstrap, Can we create the builtin user "elastic" with providing more roles other than superuser role When elastic user gets created it is assigned with super user role. I need to assign few more privilege…

---

## [Logstash cann not read encrypted key](https://discuss.elastic.co/t/logstash-cann-not-read-encrypted-key/324629)

<div class="topic-metadata">

**Author:** [@AfeefGhannam](https://discuss.elastic.co/u/AfeefGhannam)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-cann-not-read-encrypted-key/324629 "2023-02-03T09:23:26Z")

</div>

Hi, when we create an encrypted and compatible Logstash key, Logstash can not read the key and give the following error in log: message=\>"File does not contain valid private key: /etc/logstash/certs/logstash-pkcs8.key"…

---

## [S3 optimization in elk](https://discuss.elastic.co/t/s3-optimization-in-elk/324298)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 22\
**Last updated:** [February 3, 2023, 9:03am UTC](https://discuss.elastic.co/t/s3-optimization-in-elk/324298 "2023-02-03T09:03:39Z")

</div>

Hi , We have a 8 node cluster in on premise with 3 years data (3 master + 5 data node) one data node out of this being acting as s3 for cold storage. Our s3 is getting space issues and we would like to optimize by mov…

---

## [Elastic Case Insensitive Search](https://discuss.elastic.co/t/elastic-case-insensitive-search/324527)

<div class="topic-metadata">

**Author:** [@Tam2](https://discuss.elastic.co/u/Tam2)\
**Replies:** 12\
**Last updated:** [February 3, 2023, 8:19am UTC](https://discuss.elastic.co/t/elastic-case-insensitive-search/324527 "2023-02-03T08:19:06Z")

</div>

Hi All, I have a schema which uses Keywords to store values an example of a document would be something like this: We aggregate on a number of properties too such as make/model/colour/condition etc { "properties": {…

---

## [Not all primary shards of \[.geoip\_databases\] index are active](https://discuss.elastic.co/t/not-all-primary-shards-of-geoip-databases-index-are-active/324401)

<div class="topic-metadata">

**Author:** [@LiuJintao](https://discuss.elastic.co/u/LiuJintao)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 8:51am UTC](https://discuss.elastic.co/t/not-all-primary-shards-of-geoip-databases-index-are-active/324401 "2023-02-03T08:51:36Z")

</div>

When I start elasticsearch cluster with a single node,it throw an error: \[2023-02-01T15:34:09,249\]\[ERROR\]\[o.e.i.g.GeoIpDownloader \] \[node1\] exception during geoip databases updateorg.elasticsearch.ElasticsearchExceptio…

---

## [Bertopic in Elasticsearch](https://discuss.elastic.co/t/bertopic-in-elasticsearch/324617)

<div class="topic-metadata">

**Author:** [@alvaro\_ing](https://discuss.elastic.co/u/alvaro_ing)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 8:35am UTC](https://discuss.elastic.co/t/bertopic-in-elasticsearch/324617 "2023-02-03T08:35:12Z")

</div>

Hello, I have been training a BERTopic model and I would like to know if there is a way to import it into Elastic. I've seen that some models can be imported with Eland API but I'm not sure if this could be done. Berto…

---

## [Logging in to Kibana 8 without security for LDAP auth ES cluster](https://discuss.elastic.co/t/logging-in-to-kibana-8-without-security-for-ldap-auth-es-cluster/324250)

<div class="topic-metadata">

**Author:** [@Chel](https://discuss.elastic.co/u/Chel)\
**Replies:** 10\
**Last updated:** [February 3, 2023, 7:47am UTC](https://discuss.elastic.co/t/logging-in-to-kibana-8-without-security-for-ldap-auth-es-cluster/324250 "2023-02-03T07:47:07Z")

</div>

Hi, We have 8.5.2 cluster running with LDAP authentication(xpack security) with basic license. Earlier Versions of Kibana in 7.x we use the same username and password of elastic to login to kibana but in 8.x versions lo…

---

## [Copy a remote index using Reindex API](https://discuss.elastic.co/t/copy-a-remote-index-using-reindex-api/324548)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 7:47am UTC](https://discuss.elastic.co/t/copy-a-remote-index-using-reindex-api/324548 "2023-02-03T07:47:00Z")

</div>

Hi, I have a running Elastic node with an index. I'm constantly inserting documents into the index in a process that I can't stop. The whole process is running in a remote server. I need to make a copy of the index into…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=644)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=646)
