# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=650

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 651

---

## [Parse json and non-json logs](https://discuss.elastic.co/t/parse-json-and-non-json-logs/324282)

<div class="topic-metadata">

**Author:** [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 2:52am UTC](https://discuss.elastic.co/t/parse-json-and-non-json-logs/324282 "2023-01-31T02:52:29Z")

</div>

I have multiple Kubernetes clusters sending logs to S3 , then I use logstash to read logs off S3 files. Some logs messages are in JSON , others in structured format. How to dynamically detect and parse JSON , and save n…

---

## [Kibana unreachable: 503 error due to circuit breaking exception](https://discuss.elastic.co/t/kibana-unreachable-503-error-due-to-circuit-breaking-exception/324141)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 12:56am UTC](https://discuss.elastic.co/t/kibana-unreachable-503-error-due-to-circuit-breaking-exception/324141 "2023-01-31T00:56:18Z")

</div>

Hello. I am currently dealing with Kibana being unreachable. The page states "{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}". I don't believe this is an authentication issue as…

---

## [Alternative to FiltersAggregator.KeyedFilter in new Java Client](https://discuss.elastic.co/t/alternative-to-filtersaggregator-keyedfilter-in-new-java-client/323860)

<div class="topic-metadata">

**Author:** [@MrMightyNighty](https://discuss.elastic.co/u/MrMightyNighty)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 4:24pm UTC](https://discuss.elastic.co/t/alternative-to-filtersaggregator-keyedfilter-in-new-java-client/323860 "2023-01-24T16:24:55Z")

</div>

Hello there, currently we are in the process of switching to the new Java API Client since Spring Boot 3 isn't supporting the old client anymore (yes you can just add the old client but we want to do it properly …

---

## [No route to host](https://discuss.elastic.co/t/no-route-to-host/323996)

<div class="topic-metadata">

**Author:** [@MALKARAJ\_K](https://discuss.elastic.co/u/MALKARAJ_K)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 12:37am UTC](https://discuss.elastic.co/t/no-route-to-host/323996 "2023-01-31T00:37:58Z")

</div>

i am trying to connect a node from different machine to the cluster , this node able to find the master node but not able to join it I couldn't able to find any solution for this es 7.5+

---

## [Operation install messages package registry](https://discuss.elastic.co/t/operation-install-messages-package-registry/323928)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:18pm UTC](https://discuss.elastic.co/t/operation-install-messages-package-registry/323928 "2023-01-25T14:18:07Z")

</div>

Following the airgapped documentation attempted to create my own package registery and copied all the files to the repo http server accessible by elasticand kibana. I attempted to upgrade the agetns however I didnt see …

---

## [Type: \_doc why is it still there](https://discuss.elastic.co/t/type-doc-why-is-it-still-there/324033)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 12:35am UTC](https://discuss.elastic.co/t/type-doc-why-is-it-still-there/324033 "2023-01-31T00:35:37Z")

</div>

I thought type = \_doc is deprecated. why is it still here and how do I remove it? This is metricbeat 8.5.3 and elastic also 8.5.3 but it comes with type =\> \_doc ( is this correct ) "@metadata" =\> { "target\_ind…

---

## [OIDC authenticate response documentation shows different response to what I can see](https://discuss.elastic.co/t/oidc-authenticate-response-documentation-shows-different-response-to-what-i-can-see/324013)

<div class="topic-metadata">

**Author:** [@steelydan96](https://discuss.elastic.co/u/steelydan96)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 12:32am UTC](https://discuss.elastic.co/t/oidc-authenticate-response-documentation-shows-different-response-to-what-i-can-see/324013 "2023-01-31T00:32:06Z")

</div>

Hello, I am using version 8.5.2 of elasticsearch, and the documentation states, for an OIDC authenticate response, I should receive: { "access\_token" : "dGhpcyBpcyBub3QgYSByZWFsIHRva2VuIGJ1dCBpdCBpcyBvbmx5IHRlc3QgZGF0…

---

## [Reset password api](https://discuss.elastic.co/t/reset-password-api/324193)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 12:20am UTC](https://discuss.elastic.co/t/reset-password-api/324193 "2023-01-31T00:20:05Z")

</div>

Hi i am installing elk stack using ansible playbook. I am able to set password using elasticsearch-reset-password for all users manually, from command line. How can i do the same using the playbook? if i run this comman…

---

## [How do i know how much data is stored in my Elastic search?](https://discuss.elastic.co/t/how-do-i-know-how-much-data-is-stored-in-my-elastic-search/324279)

<div class="topic-metadata">

**Author:** [@Dishatkr](https://discuss.elastic.co/u/Dishatkr)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 11:56pm UTC](https://discuss.elastic.co/t/how-do-i-know-how-much-data-is-stored-in-my-elastic-search/324279 "2023-01-30T23:56:17Z")

</div>

I want to know how much data is stored in my Elastic search, I m exploring the cluster-stats API. Does "store" -\> size\_in\_bytes , show the size of data stored ?

---

## [What ruby gem version should I use with ES 7.17.x](https://discuss.elastic.co/t/what-ruby-gem-version-should-i-use-with-es-7-17-x/324190)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [January 30, 2023, 11:47pm UTC](https://discuss.elastic.co/t/what-ruby-gem-version-should-i-use-with-es-7-17-x/324190 "2023-01-30T23:47:37Z")

</div>

I have just brought up a new linux VM to run an application that talks ES 7 but I can not find any gems for version 7. The latest (8.6.0) says that the server is not running ES : (. Presumably it only works with ES 8.x …

---

## [Elastic image 8.5.3 Vulnerabilities](https://discuss.elastic.co/t/elastic-image-8-5-3-vulnerabilities/324259)

<div class="topic-metadata">

**Author:** [@rajn27](https://discuss.elastic.co/u/rajn27)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 9:35pm UTC](https://discuss.elastic.co/t/elastic-image-8-5-3-vulnerabilities/324259 "2023-01-30T21:35:33Z")

</div>

We are downloading elastic images of docker hub. Elastic image is showing log4j vulnerabilities in 8.5.3 and 8.6 the images released in Dec 2022 and Jan2023. These vulnerabilities were addressed a year ago in dec 2021. C…

---

## [Problems with Scroll and Slice](https://discuss.elastic.co/t/problems-with-scroll-and-slice/324271)

<div class="topic-metadata">

**Author:** [@Olli1](https://discuss.elastic.co/u/Olli1)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 9:17pm UTC](https://discuss.elastic.co/t/problems-with-scroll-and-slice/324271 "2023-01-30T21:17:29Z")

</div>

Hello Com, i have a problem with my Code. When i want to Scroll and Slice about 100.000 data, i get the following Error: # Request: {"scroll":"2m","scroll\_id":"FGluY2x1ZGVfY29udGV4dF91dWlkDnF1ZXJ5VGhlbkZldGNoAhZvNUctQk…

---

## [Problem with restoring old (6.8) indices on ES 8.6.1](https://discuss.elastic.co/t/problem-with-restoring-old-6-8-indices-on-es-8-6-1/324235)

<div class="topic-metadata">

**Author:** [@lno](https://discuss.elastic.co/u/lno)\
**Replies:** 6\
**Last updated:** [January 30, 2023, 8:04pm UTC](https://discuss.elastic.co/t/problem-with-restoring-old-6-8-indices-on-es-8-6-1/324235 "2023-01-30T20:04:17Z")

</div>

Hi, we have some issues with restoring old (6.8.13) indices on the latest 8.6.1 version. Restore fails on some shards with these messages : Caused by: \[users/owINpknoTCmTe2kMmzuRhg\]\[\[users\]\[25\]\] org.elasticsearch.index.…

---

## [NoAliveNodes Elasticsearch-PHP (Ingest-Attachment)](https://discuss.elastic.co/t/noalivenodes-elasticsearch-php-ingest-attachment/324151)

<div class="topic-metadata">

**Author:** [@SplendX](https://discuss.elastic.co/u/SplendX)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 7:21pm UTC](https://discuss.elastic.co/t/noalivenodes-elasticsearch-php-ingest-attachment/324151 "2023-01-30T19:21:12Z")

</div>

Hello, I'm new to programming. when used in php-es code "return $client-\>ingest()-\>putPipeline($params);" outputs an error "NoAliveNodes", but when using for example "return $client-\>index($params);" it works! Plugin Ing…

---

## [Is there a way to show the value instead of percentage in pie/donut chart? - Canvas](https://discuss.elastic.co/t/is-there-a-way-to-show-the-value-instead-of-percentage-in-pie-donut-chart-canvas/324262)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 5\
**Last updated:** [January 30, 2023, 7:19pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-show-the-value-instead-of-percentage-in-pie-donut-chart-canvas/324262 "2023-01-30T19:19:55Z")

</div>

Here is the chart: I need to have the raw values instead of percentage. Is it possible to do it in Canvas? Would be glad if there is anyone who could help with it. Best regards.

---

## [Inconsistent datastream index rollover](https://discuss.elastic.co/t/inconsistent-datastream-index-rollover/324264)

<div class="topic-metadata">

**Author:** [@Maaayank](https://discuss.elastic.co/u/Maaayank)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 6:40pm UTC](https://discuss.elastic.co/t/inconsistent-datastream-index-rollover/324264 "2023-01-30T18:40:55Z")

</div>

Hello, I'd like to use datastream +ilm policy to roll index on daily basis and delete them after 1 month. It's important for me to roll index on daily basis without fail ( 10-20 mins delay doesn't doesn't affect me). F…

---

## [Kibana advanced settings does not exist](https://discuss.elastic.co/t/kibana-advanced-settings-does-not-exist/324237)

<div class="topic-metadata">

**Author:** [@furkano](https://discuss.elastic.co/u/furkano)\
**Replies:** 11\
**Last updated:** [January 30, 2023, 5:33pm UTC](https://discuss.elastic.co/t/kibana-advanced-settings-does-not-exist/324237 "2023-01-30T17:33:05Z")

</div>

Hi, i want to edit my default size of rows for discover page, default is 500 and i need to increase that, But i can't access to advanced settings page event with my superuser, and i couldn't find any documentary for how…

---

## [Proper way to escape escape characters](https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143)

<div class="topic-metadata">

**Author:** [@hexoffender](https://discuss.elastic.co/u/hexoffender)\
**Replies:** 3\
**Last updated:** [January 30, 2023, 5:31pm UTC](https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143 "2023-01-30T17:31:18Z")

</div>

Hello, I have a weird problem. I'm trying to replace \\x5c with \\ in a mutate. However, the logstash config fails to parse when I do this: input { beats { # The port to listen on for filebeat connections. …

---

## [Logstash Array of JSON](https://discuss.elastic.co/t/logstash-array-of-json/324178)

<div class="topic-metadata">

**Author:** [@creative\_sha](https://discuss.elastic.co/u/creative_sha)\
**Replies:** 4\
**Last updated:** [January 30, 2023, 5:53am UTC](https://discuss.elastic.co/t/logstash-array-of-json/324178 "2023-01-30T05:53:48Z")

</div>

How can I Split Array of JSON into different JSON so that per request we will get 1 row?

---

## [Filter on distinct nested documents](https://discuss.elastic.co/t/filter-on-distinct-nested-documents/324168)

<div class="topic-metadata">

**Author:** [@Sadia\_Mukhtar](https://discuss.elastic.co/u/Sadia_Mukhtar)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 5:09pm UTC](https://discuss.elastic.co/t/filter-on-distinct-nested-documents/324168 "2023-01-30T17:09:26Z")

</div>

I am very new to Elasticsearch and it's data modeling techniques. My dataset is a list of users and locations the users' have been associated with. I am trying to implement a type-ahead search on locations, I need to get…

---

## [Best practice for the creation of an index](https://discuss.elastic.co/t/best-practice-for-the-creation-of-an-index/324246)

<div class="topic-metadata">

**Author:** [@QuentinV](https://discuss.elastic.co/u/QuentinV)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 3:55pm UTC](https://discuss.elastic.co/t/best-practice-for-the-creation-of-an-index/324246 "2023-01-30T15:55:20Z")

</div>

Hello. I'm working on a project with Elastic for my company. I have to export some logs from the test software of our solution to an elastic database. Every night, the test software will create many logs with Java, us…

---

## [Change Log Levels for Standalone Elastic Agent](https://discuss.elastic.co/t/change-log-levels-for-standalone-elastic-agent/324243)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 3:27pm UTC](https://discuss.elastic.co/t/change-log-levels-for-standalone-elastic-agent/324243 "2023-01-30T15:27:23Z")

</div>

I am deploying Elastic Agent to my Kubernetes cluster as a standalone agent. Default log level is info. I would like to change the log level for the agent and ALL beats to warning. I've updated my agent.yml to: agent.lo…

---

## [Missing Integrations from Installed integrations](https://discuss.elastic.co/t/missing-integrations-from-installed-integrations/324181)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 9\
**Last updated:** [January 30, 2023, 3:16pm UTC](https://discuss.elastic.co/t/missing-integrations-from-installed-integrations/324181 "2023-01-30T15:16:54Z")

</div>

Elastic-Stack: 8.6.1 We have encountered an issue where Installed Integrations are missing from the Installed Integration page of Fleet Integrations. As an example, the Windows Integration isn't shown as an installed in…

---

## [Calculating Chronological Contiguous Document Sequences](https://discuss.elastic.co/t/calculating-chronological-contiguous-document-sequences/324240)

<div class="topic-metadata">

**Author:** [@Guy\_Segev](https://discuss.elastic.co/u/Guy_Segev)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 2:57pm UTC](https://discuss.elastic.co/t/calculating-chronological-contiguous-document-sequences/324240 "2023-01-30T14:57:06Z")

</div>

Hi, Would appreciate help with the following conundrum: I have an index with time-series events; here are some document examples: { "timestamp": 1, "status": "running" } { "timestamp": 2, "status": "running" } { "ti…

---

## [Kafka\_consumer\_lag in Logstash](https://discuss.elastic.co/t/kafka-consumer-lag-in-logstash/324108)

<div class="topic-metadata">

**Author:** [@Ondrej\_S](https://discuss.elastic.co/u/Ondrej_S)\
**Replies:** 2\
**Last updated:** [January 30, 2023, 2:28pm UTC](https://discuss.elastic.co/t/kafka-consumer-lag-in-logstash/324108 "2023-01-30T14:28:23Z")

</div>

Hello, Is it possible to get the value or verify value of “kafka\_consumer\_lag” directly in Logstash 7.17? The idea is to verify: if \[kafka\_consumer\_lag\]\[lag\] == 0 In Logstash Output and if yes run http plugin with u…

---

## [Multiple follower pattern for same primary index](https://discuss.elastic.co/t/multiple-follower-pattern-for-same-primary-index/324232)

<div class="topic-metadata">

**Author:** [@Jairam\_Gauns](https://discuss.elastic.co/u/Jairam_Gauns)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 1:30pm UTC](https://discuss.elastic.co/t/multiple-follower-pattern-for-same-primary-index/324232 "2023-01-30T13:30:27Z")

</div>

Hi Team, We have multiple follower pattern that match the same time series index from primary. In one of the follower we have a prefix and suffix in another follower pattern. Currently the replication of the new inde…

---

## [Embed Kibana dashboards without using iframe](https://discuss.elastic.co/t/embed-kibana-dashboards-without-using-iframe/324185)

<div class="topic-metadata">

**Author:** [@sebastian.nordin](https://discuss.elastic.co/u/sebastian.nordin)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 1:00pm UTC](https://discuss.elastic.co/t/embed-kibana-dashboards-without-using-iframe/324185 "2023-01-30T13:00:34Z")

</div>

Currently we embed Kibana dashboards and visualizations on a Portal overview page in a React app, using the normal share iframe method. We've noticed significant increase in page loading time on portals where more than …

---

## [Upgrade ELK from 7.2.0 to 8.4.3](https://discuss.elastic.co/t/upgrade-elk-from-7-2-0-to-8-4-3/324228)

<div class="topic-metadata">

**Author:** [@rampratap](https://discuss.elastic.co/u/rampratap)\
**Replies:** 2\
**Last updated:** [January 30, 2023, 12:56pm UTC](https://discuss.elastic.co/t/upgrade-elk-from-7-2-0-to-8-4-3/324228 "2023-01-30T12:56:11Z")

</div>

I am trying to upgrade from ELK 7.2.0 to 8.4.3 but getting below error , please help or suggest on the compatible version to upgrade to fatal exception while booting Elasticsearch org.elasticsearch.ElasticsearchExceptio…

---

## [Zeek/Bro to ECS Field Mappings](https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120)

<div class="topic-metadata">

**Author:** [@3weekwhiskers](https://discuss.elastic.co/u/3weekwhiskers)\
**Replies:** 3\
**Last updated:** [January 30, 2023, 12:41pm UTC](https://discuss.elastic.co/t/zeek-bro-to-ecs-field-mappings/324120 "2023-01-30T12:41:47Z")

</div>

Is there a Zeek field to ECS field mapping document? Other than the logtype.yml files which actually do the conversion and renames, I have not been able to find anything. I'm avoiding having to build this mapping from sc…

---

## [Elasticsearch AbstractElasticsearchRepository. e:Request processing failed; nested exception is org.springframework.dao.DataAccessResourceFailureException: Timeout connecting to \[elasticsearch. Timeout connecting to Springboot Application Error](https://discuss.elastic.co/t/elasticsearch-abstractelasticsearchrepository-e-request-processing-failed-nested-exception-is-org-springframework-dao-dataaccessresourcefailureexception-timeout-connecting-to-elasticsearch-timeout-connecting-to-springboot-application-error/323819)

<div class="topic-metadata">

**Author:** [@my\_space](https://discuss.elastic.co/u/my_space)\
**Replies:** 7\
**Last updated:** [January 30, 2023, 11:42am UTC](https://discuss.elastic.co/t/elasticsearch-abstractelasticsearchrepository-e-request-processing-failed-nested-exception-is-org-springframework-dao-dataaccessresourcefailureexception-timeout-connecting-to-elasticsearch-timeout-connecting-to-springboot-application-error/323819 "2023-01-30T11:42:35Z")

</div>

Version Spring Data Elasticsearch: 4.0.0.RELEASE Version Elasticsearch Client in build: 7.6.2 Version Elasticsearch Client used: 7.6.2 e:Request processing failed; nested exception is org.springframework.dao.DataAcces…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=649)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=651)
