# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=647

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 648

---

## [Reingenst CSV to change field names](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219)

<div class="topic-metadata">

**Author:** [@momoaux](https://discuss.elastic.co/u/momoaux)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 11:18am UTC](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219 "2023-02-02T11:18:44Z")

</div>

Hello, I'm new to ELK stack. I have a lot of CSV files which share some common columns. But all have different names for their columns. Example: File 1: Name, Type, Code File 2: TP, NM, CD File 3: Co,Ty,Na My code…

---

## [VEGA developer](https://discuss.elastic.co/t/vega-developer/324525)

<div class="topic-metadata">

**Author:** [@m-cd](https://discuss.elastic.co/u/m-cd)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 10:29am UTC](https://discuss.elastic.co/t/vega-developer/324525 "2023-02-02T10:29:04Z")

</div>

Hello, I'm not totally sure if I can ask help here... So sorry if I'm doing mistakes here. I'm searching for a vega developer to hire for some visualisations (3-4 visualisations) to create using vega scripting. Does …

---

## [Sample data required](https://discuss.elastic.co/t/sample-data-required/324522)

<div class="topic-metadata">

**Author:** [@NS\_Midhun](https://discuss.elastic.co/u/NS_Midhun)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 10:12am UTC](https://discuss.elastic.co/t/sample-data-required/324522 "2023-02-02T10:12:26Z")

</div>

I need sample data (GB's) in json format to upload in opensearch. Please suggest

---

## [Term query not working where type is "text"](https://discuss.elastic.co/t/term-query-not-working-where-type-is-text/324422)

<div class="topic-metadata">

**Author:** [@shebbi](https://discuss.elastic.co/u/shebbi)\
**Replies:** 6\
**Last updated:** [February 2, 2023, 10:05am UTC](https://discuss.elastic.co/t/term-query-not-working-where-type-is-text/324422 "2023-02-02T10:05:08Z")

</div>

Hi Team, We are using ES 7.16.2 version and below is the query which we have generated using Java apis, Please let us know why it is not working or are we doing something wrong? Query: - { "bool" : { "must" : \[ …

---

## [HTTP error 401 in : 401 Unauthorized","service.name":"metricbeat"](https://discuss.elastic.co/t/http-error-401-in-401-unauthorized-service-name-metricbeat/323923)

<div class="topic-metadata">

**Author:** [@bagafoot](https://discuss.elastic.co/u/bagafoot)\
**Replies:** 8\
**Last updated:** [February 2, 2023, 9:59am UTC](https://discuss.elastic.co/t/http-error-401-in-401-unauthorized-service-name-metricbeat/323923 "2023-02-02T09:59:55Z")

</div>

The metric beats service status showing that connection estabilished to elasticsearch but I get this errors metricbeats.yml path: ${path.config}/modules.d/\*.yml reload.enabled: false setup.template.settings: inde…

---

## [Sliced search not returning all hits](https://discuss.elastic.co/t/sliced-search-not-returning-all-hits/324513)

<div class="topic-metadata">

**Author:** [@jkruger](https://discuss.elastic.co/u/jkruger)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 8:30am UTC](https://discuss.elastic.co/t/sliced-search-not-returning-all-hits/324513 "2023-02-02T08:30:38Z")

</div>

Hello, I am a new Elastic user, and I already ran into an issue. I am trying to extract all logs from a certain index. In order to deal with large indices I want to implement pagination using search\_after and PiTs (Poin…

---

## [Data Table limit of values](https://discuss.elastic.co/t/data-table-limit-of-values/324474)

<div class="topic-metadata">

**Author:** [@Brian\_Fernandez](https://discuss.elastic.co/u/Brian_Fernandez)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 7:23am UTC](https://discuss.elastic.co/t/data-table-limit-of-values/324474 "2023-02-02T07:23:02Z")

</div>

Hi guys! I would like to know if there is anything i can do to expand the 100 rows value in a Data Table. Depending on the information you like to show, 100 rows are very few. Can you help me please? v 7.12.0

---

## [How to read logs with permanent \[NULL\]-characters at the end of file?](https://discuss.elastic.co/t/how-to-read-logs-with-permanent-null-characters-at-the-end-of-file/324408)

<div class="topic-metadata">

**Author:** [@Evgenii\_X](https://discuss.elastic.co/u/Evgenii_X)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:46am UTC](https://discuss.elastic.co/t/how-to-read-logs-with-permanent-null-characters-at-the-end-of-file/324408 "2023-02-02T06:46:37Z")

</div>

We need to collect MT4 logs (MetaTrader 4 trading platform). Log-saving "Feature" in MT4 is implemented according to the following algorithm: When creating a log file (or adding new logs to the current one), the platfo…

---

## [Winlogbeat I am getting error when winlogbeat is 7.5 and elastic is 8.5.3](https://discuss.elastic.co/t/winlogbeat-i-am-getting-error-when-winlogbeat-is-7-5-and-elastic-is-8-5-3/324500)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:02am UTC](https://discuss.elastic.co/t/winlogbeat-i-am-getting-error-when-winlogbeat-is-7-5-and-elastic-is-8-5-3/324500 "2023-02-02T06:02:50Z")

</div>

I am getting error when winlogbeat is 7.5 and elastic is 8.5.3 and kibana is also 8.5.3 if winlogbeat is 7.5 and elastic and kibana also 7.5 it is working fine ERROR pipeline/output.go:100 Failed to connect to backoff(…

---

## [Filebeat still shows old version even if service is a later version](https://discuss.elastic.co/t/filebeat-still-shows-old-version-even-if-service-is-a-later-version/322410)

<div class="topic-metadata">

**Author:** [@Azkiel19](https://discuss.elastic.co/u/Azkiel19)\
**Replies:** 5\
**Last updated:** [February 2, 2023, 5:56am UTC](https://discuss.elastic.co/t/filebeat-still-shows-old-version-even-if-service-is-a-later-version/322410 "2023-02-02T05:56:32Z")

</div>

Hi, Checking into Elastic - the beat version still shows as 5.6.5 even though the service we have running is already at 6.8.13 and confirmed it is still sending logs real time. Already tried restarting the filebeat ser…

---

## [When creating an api key does run-as override the other settings?](https://discuss.elastic.co/t/when-creating-an-api-key-does-run-as-override-the-other-settings/324280)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 3:12am UTC](https://discuss.elastic.co/t/when-creating-an-api-key-does-run-as-override-the-other-settings/324280 "2023-02-02T03:12:29Z")

</div>

I created an API key and left the other settings apart from run-as as default (i.e. wide open) and set run as to a user with a role that has the desired priviliges. Will this key have the restriction of the assigned rol…

---

## [Is number of documents in an Index is proportional to store.size or pri.store.size?](https://discuss.elastic.co/t/is-number-of-documents-in-an-index-is-proportional-to-store-size-or-pri-store-size/324496)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 3:06am UTC](https://discuss.elastic.co/t/is-number-of-documents-in-an-index-is-proportional-to-store-size-or-pri-store-size/324496 "2023-02-02T03:06:12Z")

</div>

GET /\<index\>/\_count gives me the total number of documents in an index. GET /\_cat/indices/\<index\> gives me both total documents, store.size and pri.store.size. Say if I have an index with 1 primary and 1 replica. say …

---

## [Filebeat output logtash - wrong value in "host" field seen in elasticsearch Index](https://discuss.elastic.co/t/filebeat-output-logtash-wrong-value-in-host-field-seen-in-elasticsearch-index/324493)

<div class="topic-metadata">

**Author:** [@madhu\_sudan](https://discuss.elastic.co/u/madhu_sudan)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 2:31am UTC](https://discuss.elastic.co/t/filebeat-output-logtash-wrong-value-in-host-field-seen-in-elasticsearch-index/324493 "2023-02-02T02:31:08Z")

</div>

I see value for "host" field as the container IP, but was expecting the hostname of the docker host. host 192.168.254.4 Also added processors: add\_docker\_metadata: ~

---

## [Latency (No data to display) Stack Monitoring Elasticsearch](https://discuss.elastic.co/t/latency-no-data-to-display-stack-monitoring-elasticsearch/324489)

<div class="topic-metadata">

**Author:** [@jacksparrow414](https://discuss.elastic.co/u/jacksparrow414)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 1:32am UTC](https://discuss.elastic.co/t/latency-no-data-to-display-stack-monitoring-elasticsearch/324489 "2023-02-02T01:32:46Z")

</div>

I use Metricbeat to monitor an Elasticsearch node and send metrics to it. The versions of all components are 8.5.3 The Metricbeat configuration file is as follows ## Metricbeat configuration metricbeat.config: modul…

---

## [Syntax error](https://discuss.elastic.co/t/syntax-error/324471)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 12:32am UTC](https://discuss.elastic.co/t/syntax-error/324471 "2023-02-02T00:32:40Z")

</div>

Hey there, I'm working playing with Logstash and wrote alot of grok patterns. But right now, I have a syntax error in this snippet: if \[message\] =~ "SMTP error from remote mail server after RCPT TO" { grok { …

---

## [On-prem Kibana can't join elastic-package-registry (EPR) behind a proxy due to certificate issue - workaround tested](https://discuss.elastic.co/t/on-prem-kibana-cant-join-elastic-package-registry-epr-behind-a-proxy-due-to-certificate-issue-workaround-tested/324486)

<div class="topic-metadata">

**Author:** [@antoine\_duriez](https://discuss.elastic.co/u/antoine_duriez)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 10:20pm UTC](https://discuss.elastic.co/t/on-prem-kibana-cant-join-elastic-package-registry-epr-behind-a-proxy-due-to-certificate-issue-workaround-tested/324486 "2023-02-01T22:20:35Z")

</div>

Hi, I have an on-prem stack 8.5.3 on RHEL 8 with high customer's restriction. Access to internet is done throught a proxy. Access to epr. elastic.co was opened and tested well with the command: nc epr.elastic.co 44…

---

## [Combining records that have the same id with a query](https://discuss.elastic.co/t/combining-records-that-have-the-same-id-with-a-query/324479)

<div class="topic-metadata">

**Author:** [@chachew](https://discuss.elastic.co/u/chachew)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 9:24pm UTC](https://discuss.elastic.co/t/combining-records-that-have-the-same-id-with-a-query/324479 "2023-02-01T21:24:45Z")

</div>

I have records for call logs that i want to query and combine into 1 result per record instead of 2. This is for logging of calls from one person to another. The person that initiates the call has the 'initiator' flag se…

---

## [Make a copy of a running Elastic node](https://discuss.elastic.co/t/make-a-copy-of-a-running-elastic-node/324448)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 8\
**Last updated:** [February 1, 2023, 9:02pm UTC](https://discuss.elastic.co/t/make-a-copy-of-a-running-elastic-node/324448 "2023-02-01T21:02:49Z")

</div>

Hi, I have a running Elastic node with an index. I'm constantly inserting documents into the index in a process that I can't stop. The whole process is running in a remote server. I need to make a copy of the index int…

---

## [Elasticsearch 1.7.0 has authentication at all?](https://discuss.elastic.co/t/elasticsearch-1-7-0-has-authentication-at-all/324394)

<div class="topic-metadata">

**Author:** [@RaZzLe](https://discuss.elastic.co/u/RaZzLe)\
**Replies:** 6\
**Last updated:** [February 1, 2023, 8:23pm UTC](https://discuss.elastic.co/t/elasticsearch-1-7-0-has-authentication-at-all/324394 "2023-02-01T20:23:48Z")

</div>

Hello all, I have received an e-mail from the security department that one of the machines which is under my administration has a basic authentication on Elasticsearch. I have checked the respective Elasticsearch insta…

---

## [Unable to escape special character using Java REST API](https://discuss.elastic.co/t/unable-to-escape-special-character-using-java-rest-api/324456)

<div class="topic-metadata">

**Author:** [@Avi\_Buk](https://discuss.elastic.co/u/Avi_Buk)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 7:33pm UTC](https://discuss.elastic.co/t/unable-to-escape-special-character-using-java-rest-api/324456 "2023-02-01T19:33:54Z")

</div>

Hi, I'm using query\_string which is Lucene-based, and when I'm trying to send a query with "role" field contains the string "INFRA-Server", it cannot find any results because of the "-" sign. I tried to escape it, but …

---

## [OFFSET query \_sql is not recognizing](https://discuss.elastic.co/t/offset-query-sql-is-not-recognizing/324473)

<div class="topic-metadata">

**Author:** [@SergioFF](https://discuss.elastic.co/u/SergioFF)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 7:21pm UTC](https://discuss.elastic.co/t/offset-query-sql-is-not-recognizing/324473 "2023-02-01T19:21:58Z")

</div>

Hello, I have version 8.5.2 of Elasticsearch and I am trying to use the OFFSET clause within a query, but it is not recognizing it, can this clause be used in the version we have? The query I am sending is as follows: G…

---

## [Kibana control limitation](https://discuss.elastic.co/t/kibana-control-limitation/323872)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 5\
**Last updated:** [February 1, 2023, 5:59pm UTC](https://discuss.elastic.co/t/kibana-control-limitation/323872 "2023-02-01T17:59:08Z")

</div>

using Kibana 8.5.3 new control can only show 10 value. How do I change that to see more value? in old control it was working

---

## [Timelion not working at all: "Timelion request error: in cell #1: No such function: es"](https://discuss.elastic.co/t/timelion-not-working-at-all-timelion-request-error-in-cell-1-no-such-function-es/324211)

<div class="topic-metadata">

**Author:** [@matej.szabo](https://discuss.elastic.co/u/matej.szabo)\
**Replies:** 7\
**Last updated:** [February 1, 2023, 5:02pm UTC](https://discuss.elastic.co/t/timelion-not-working-at-all-timelion-request-error-in-cell-1-no-such-function-es/324211 "2023-02-01T17:02:50Z")

</div>

Hello everyone, We have just finished building up our ELK stack from the latest pieces of this puzzle (8.6.0): elasticsearch+kibana+filebeat+metricbeat. We are trying to build some timelion visualizations from metricbea…

---

## [Can't Configure or Enable Security Features in Elasticsearch 8.4](https://discuss.elastic.co/t/cant-configure-or-enable-security-features-in-elasticsearch-8-4/323971)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 5\
**Last updated:** [February 1, 2023, 4:15pm UTC](https://discuss.elastic.co/t/cant-configure-or-enable-security-features-in-elasticsearch-8-4/323971 "2023-02-01T16:15:59Z")

</div>

Hello dears, I'm having trouble I'm following the tutorial below, and when I finish the configuration, when starting Kibana I get an error: Toturial: https://www.elastic.co/guide/en/elasticsearch/reference/current/sec…

---

## [Any way to migrate Legacy templates to composable templates?](https://discuss.elastic.co/t/any-way-to-migrate-legacy-templates-to-composable-templates/324454)

<div class="topic-metadata">

**Author:** [@Monica\_majua](https://discuss.elastic.co/u/Monica_majua)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 4:01pm UTC](https://discuss.elastic.co/t/any-way-to-migrate-legacy-templates-to-composable-templates/324454 "2023-02-01T16:01:25Z")

</div>

I have migrated to elasticsearch 7.8, I was reading that some of the changes include the replacement of Legacy index templates to composable index templates and I would like support to find a guide that can help me to mi…

---

## [Move config folder to another location on Window (v8.6.0)](https://discuss.elastic.co/t/move-config-folder-to-another-location-on-window-v8-6-0/324446)

<div class="topic-metadata">

**Author:** [@ykara84](https://discuss.elastic.co/u/ykara84)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 2:53pm UTC](https://discuss.elastic.co/t/move-config-folder-to-another-location-on-window-v8-6-0/324446 "2023-02-01T14:53:03Z")

</div>

Hi, I have ES 8.6.0 on Windows (single-node). I am looking to move the config folder to another location. I have I have added two new environment variables: C:\\Windows\\system32\>echo %ES\_HOME% E:\\elk\\elasticsearch\\8.6.…

---

## [Filebeat log fails to publish events](https://discuss.elastic.co/t/filebeat-log-fails-to-publish-events/324127)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 9\
**Last updated:** [February 1, 2023, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-log-fails-to-publish-events/324127 "2023-02-01T14:23:15Z")

</div>

Hello, Our ELK cluster has been stable for a long time, but recently we have started seeing the following error in the filebeat log: ERROR logstash/async.go:256 Failed to publish events caused by: write tcp xx.xx.x…

---

## [Which certificate do I need for an external Java client linked to a self-hosted docker Elasticsearch 8.x, since the self-signed http\_ca.crt does not function unless the Java client is installed locally on the same server?](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159)

<div class="topic-metadata">

**Author:** [@m.jaafar](https://discuss.elastic.co/u/m.jaafar)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 2:06pm UTC](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159 "2023-02-01T14:06:41Z")

</div>

I understand that when I set up a docker image of elasticsearch version 8.x, the security is automatically activated, and three certificates are produced in the config/certs/ directory, which are: http\_ca.crt: The CA …

---

## [Combining fields into one for performance?](https://discuss.elastic.co/t/combining-fields-into-one-for-performance/324433)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 1:59pm UTC](https://discuss.elastic.co/t/combining-fields-into-one-for-performance/324433 "2023-02-01T13:59:10Z")

</div>

I currently have 140 fields in my Elasticsearch index-based App Search Engine. I realized that 40 of those fields contain data that does not need to be indexed (it's display only data), so I marked them index:false in t…

---

## [Watcher - Actions conditions in foreach](https://discuss.elastic.co/t/watcher-actions-conditions-in-foreach/324349)

<div class="topic-metadata">

**Author:** [@v\_watch](https://discuss.elastic.co/u/v_watch)\
**Replies:** 4\
**Last updated:** [February 1, 2023, 1:56pm UTC](https://discuss.elastic.co/t/watcher-actions-conditions-in-foreach/324349 "2023-02-01T13:56:41Z")

</div>

Hello, I am trying to create a watcher that must send a different slack message depending on the field "state" from each log in the hits.hits The slack message must have: "color" = "good" if the state is finished "col…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=646)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=648)
