# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=651

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 652

---

## [Incorrect queries in docs?](https://discuss.elastic.co/t/incorrect-queries-in-docs/323917)

<div class="topic-metadata">

**Author:** [@Mohamed\_Khattab](https://discuss.elastic.co/u/Mohamed_Khattab)\
**Replies:** 2\
**Last updated:** [January 30, 2023, 11:18am UTC](https://discuss.elastic.co/t/incorrect-queries-in-docs/323917 "2023-01-30T11:18:31Z")

</div>

I'm copy-pasting a query from this page: Scripted metric aggregation | Elasticsearch Guide \[7.17\] | Elastic the query is { "query": { "match\_all": {} }, "aggs": { "profit": { "scripted\_metric": { …

---

## [How to delete revoked Fleet enrolment tokens](https://discuss.elastic.co/t/how-to-delete-revoked-fleet-enrolment-tokens/324026)

<div class="topic-metadata">

**Author:** [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Replies:** 4\
**Last updated:** [January 30, 2023, 11:11am UTC](https://discuss.elastic.co/t/how-to-delete-revoked-fleet-enrolment-tokens/324026 "2023-01-30T11:11:39Z")

</div>

Hi, Is there a way to delete revoked Fleet enrolment tokens? Thank you

---

## [Collecting logs using docker.container.labels condition with filebeat:8.5.3](https://discuss.elastic.co/t/collecting-logs-using-docker-container-labels-condition-with-filebeat-8-5-3/324158)

<div class="topic-metadata">

**Author:** [@Viktor\_Herman](https://discuss.elastic.co/u/Viktor_Herman)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 10:48am UTC](https://discuss.elastic.co/t/collecting-logs-using-docker-container-labels-condition-with-filebeat-8-5-3/324158 "2023-01-30T10:48:24Z")

</div>

I'm having some problems configuring filebeat to only ingest the logs from the containers that I want. I exhausted all of the resources and documentation doesn't have any examples on this exact issue. Filebeat version is…

---

## [Get just some fields of all elements using curl](https://discuss.elastic.co/t/get-just-some-fields-of-all-elements-using-curl/324184)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 2\
**Last updated:** [January 30, 2023, 9:36am UTC](https://discuss.elastic.co/t/get-just-some-fields-of-all-elements-using-curl/324184 "2023-01-30T09:36:21Z")

</div>

Hi people. I need some help. I'm trying to make a query via curl to get some fields of all elements of a shard. I've tried this command: curl -s -H 'Content-Type: application/json' 'http://localhost:9200/video/\_searc…

---

## [Trouble replacing leading/trailing whitespace in nested json](https://discuss.elastic.co/t/trouble-replacing-leading-trailing-whitespace-in-nested-json/324129)

<div class="topic-metadata">

**Author:** [@mark54g](https://discuss.elastic.co/u/mark54g)\
**Replies:** 4\
**Last updated:** [January 30, 2023, 9:33am UTC](https://discuss.elastic.co/t/trouble-replacing-leading-trailing-whitespace-in-nested-json/324129 "2023-01-30T09:33:59Z")

</div>

Hey, folks Trying to figure out a clean way to solve this problem I have nested json coming in from an SQS queue, and I've been playing with mocking it up with a static file example and filebeat, which I know is not pe…

---

## [Remove extra options from visualisations](https://discuss.elastic.co/t/remove-extra-options-from-visualisations/324084)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 9:25am UTC](https://discuss.elastic.co/t/remove-extra-options-from-visualisations/324084 "2023-01-30T09:25:00Z")

</div>

Is it possible to remove some options that are highlighted ??

---

## [How can i disable filters in Respective visualizations present in kibana dashboard?](https://discuss.elastic.co/t/how-can-i-disable-filters-in-respective-visualizations-present-in-kibana-dashboard/316751)

<div class="topic-metadata">

**Author:** [@andy4](https://discuss.elastic.co/u/andy4)\
**Replies:** 6\
**Last updated:** [January 30, 2023, 9:18am UTC](https://discuss.elastic.co/t/how-can-i-disable-filters-in-respective-visualizations-present-in-kibana-dashboard/316751 "2023-01-30T09:18:19Z")

</div>

multiple visualizations collectively makes up a dashboard and we have interactive filter application feature available through most of the visualization , Now suppose I want to disable filters to be applied on dashboard …

---

## [Gradle assemble error](https://discuss.elastic.co/t/gradle-assemble-error/324198)

<div class="topic-metadata">

**Author:** [@mkkim](https://discuss.elastic.co/u/mkkim)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 8:18am UTC](https://discuss.elastic.co/t/gradle-assemble-error/324198 "2023-01-30T08:18:16Z")

</div>

\[kor\] 안녕하세요, 저는 한국인입니다. 저는 엘라스틱서치에 사용자 사전을 이용한 노리 플러그인을 이용하고자 합니다. 다음 링크를 참고해서 사용하고 있었습니다. (https://github.com/jimczi/nori/blob/master/how-to-custom-dict.asciidoc) 하지만 elasticsearch를 git pull한 후 gradle assemble을 할 …

---

## [Error while connecting logstash to elasticsearch : Attempted to resurrect connection to dead ES instance, but got an error](https://discuss.elastic.co/t/error-while-connecting-logstash-to-elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/324106)

<div class="topic-metadata">

**Author:** [@abhay14](https://discuss.elastic.co/u/abhay14)\
**Replies:** 8\
**Last updated:** [January 30, 2023, 7:33am UTC](https://discuss.elastic.co/t/error-while-connecting-logstash-to-elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/324106 "2023-01-30T07:33:40Z")

</div>

logstash | \[2023-01-27T11:56:05,943\]\[INFO \]\[logstash.javapipeline \]\[.monitoring-logstash\] Pipeline started {"pipeline.id"=\>".monitoring-logstash"} logstash | \[2023-01-27T11:56:05,956\]\[…

---

## [Monitor SAP on azure](https://discuss.elastic.co/t/monitor-sap-on-azure/324072)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 5:12am UTC](https://discuss.elastic.co/t/monitor-sap-on-azure/324072 "2023-01-30T05:12:37Z")

</div>

It is posible to monitor SAP on azure with beats or extract metrics with logstash? Thanks!

---

## [Is there a slow log (or something similar) for shard refresh durations?](https://discuss.elastic.co/t/is-there-a-slow-log-or-something-similar-for-shard-refresh-durations/324188)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 12:02am UTC](https://discuss.elastic.co/t/is-there-a-slow-log-or-something-similar-for-shard-refresh-durations/324188 "2023-01-30T00:02:07Z")

</div>

Hi All, I'm attempting to debug a somewhat strange issue. Where I have a query which runs every 60 seconds to check a set of logs and if there are no logs for 90 seconds then trigger an alert (this is done via a Kibana …

---

## [Shard lock issue](https://discuss.elastic.co/t/shard-lock-issue/324094)

<div class="topic-metadata">

**Author:** [@akihu](https://discuss.elastic.co/u/akihu)\
**Replies:** 10\
**Last updated:** [January 29, 2023, 10:49pm UTC](https://discuss.elastic.co/t/shard-lock-issue/324094 "2023-01-29T22:49:33Z")

</div>

Dear Community, Would you happen to have any hints what might be wrong (and how to resolve it) with my elasticsearch cluster. I've cluster with three master nodes and two data nodes. Most of the indices are configured …

---

## [On-premise pricing?](https://discuss.elastic.co/t/on-premise-pricing/324183)

<div class="topic-metadata">

**Author:** [@johber](https://discuss.elastic.co/u/johber)\
**Replies:** 6\
**Last updated:** [January 29, 2023, 8:28pm UTC](https://discuss.elastic.co/t/on-premise-pricing/324183 "2023-01-29T20:28:38Z")

</div>

Hello, I'm developing a public e-commerce site. Can it use a self hosted Elasticsearch instance for free, without violating the new license model?

---

## [Logstash & JSON array split](https://discuss.elastic.co/t/logstash-json-array-split/324180)

<div class="topic-metadata">

**Author:** [@Jalpesh1689](https://discuss.elastic.co/u/Jalpesh1689)\
**Replies:** 1\
**Last updated:** [January 29, 2023, 6:16pm UTC](https://discuss.elastic.co/t/logstash-json-array-split/324180 "2023-01-29T18:16:56Z")

</div>

Hi Team, We have below array of JSON & want to ingest these JSON into Elasticsearch. We want split this & ingest into 2 rows : \[{ "RequestEventList":\[ { "Instant":"2015-09-28T12:46:50.713Z", "RequestKey":"11bcf87b…

---

## [Monitoring host with example from docs does not work](https://discuss.elastic.co/t/monitoring-host-with-example-from-docs-does-not-work/324161)

<div class="topic-metadata">

**Author:** [@Toaster2-0](https://discuss.elastic.co/u/Toaster2-0)\
**Replies:** 6\
**Last updated:** [January 29, 2023, 4:55pm UTC](https://discuss.elastic.co/t/monitoring-host-with-example-from-docs-does-not-work/324161 "2023-01-29T16:55:03Z")

</div>

Hi, in the Docs is a run command of docker with which you should be able to Monitor the host machine (with the System Module), but It seems to not be working. In a reddit thread nobody seems to be able to give a working…

---

## [Your trial license is expired help](https://discuss.elastic.co/t/your-trial-license-is-expired-help/324173)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 7\
**Last updated:** [January 29, 2023, 4:05pm UTC](https://discuss.elastic.co/t/your-trial-license-is-expired-help/324173 "2023-01-29T16:05:47Z")

</div>

Hi all, Please i use elasticsearch 8.0 version and i have my workspace so yesterday , kibana said Your trial license is expired Please your support i have all my dashbored I am afraid of losing my data and dashboard. …

---

## [Can the size in pixels, vh or other units of a dashboard in an iframe or its visualizations be calculated? How is its size connected with the gridData width and height?](https://discuss.elastic.co/t/can-the-size-in-pixels-vh-or-other-units-of-a-dashboard-in-an-iframe-or-its-visualizations-be-calculated-how-is-its-size-connected-with-the-griddata-width-and-height/322624)

<div class="topic-metadata">

**Author:** [@DMinovski](https://discuss.elastic.co/u/DMinovski)\
**Replies:** 2\
**Last updated:** [January 29, 2023, 2:19pm UTC](https://discuss.elastic.co/t/can-the-size-in-pixels-vh-or-other-units-of-a-dashboard-in-an-iframe-or-its-visualizations-be-calculated-how-is-its-size-connected-with-the-griddata-width-and-height/322624 "2023-01-29T14:19:31Z")

</div>

Is there a way to get a dashboard-in-iframe's height in pixels or other CSS units that can be measured in the browse and its viewport, outside Kibana? Or maybe get the height of individual visualizations based on their g…

---

## [How to add searched value with terms query results](https://discuss.elastic.co/t/how-to-add-searched-value-with-terms-query-results/324174)

<div class="topic-metadata">

**Author:** [@Nowrin\_Hossain](https://discuss.elastic.co/u/Nowrin_Hossain)\
**Replies:** 0\
**Last updated:** [January 29, 2023, 11:23am UTC](https://discuss.elastic.co/t/how-to-add-searched-value-with-terms-query-results/324174 "2023-01-29T11:23:39Z")

</div>

Hello, I want to do search an index with multiple values. I want to also know which search result comes for which searched value. Can I do this in case of terms query. e.g. GET /\_search { "query": { "terms": { …

---

## [How to read logs in subfolder of main folder filebeat](https://discuss.elastic.co/t/how-to-read-logs-in-subfolder-of-main-folder-filebeat/323888)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 13\
**Last updated:** [January 29, 2023, 4:27am UTC](https://discuss.elastic.co/t/how-to-read-logs-in-subfolder-of-main-folder-filebeat/323888 "2023-01-29T04:27:12Z")

</div>

HI, I have one main folder inside this I have 2 folder I am able to read the data of both folder in filebeat but how can be show which log is belong to which subfolder.

---

## [2.4.1 groovy script aggregation make high cpu](https://discuss.elastic.co/t/2-4-1-groovy-script-aggregation-make-high-cpu/323107)

<div class="topic-metadata">

**Author:** [@huasheng\_zeng](https://discuss.elastic.co/u/huasheng_zeng)\
**Replies:** 2\
**Last updated:** [January 29, 2023, 4:04am UTC](https://discuss.elastic.co/t/2-4-1-groovy-script-aggregation-make-high-cpu/323107 "2023-01-29T04:04:25Z")

</div>

es version is 2.4.1 query request is {"aggregations":{"0-0":{"aggregations":{"0-1":{"aggregations":{"0-2":{"aggregations":{"1-0":{"aggregations":{"1-1":{"reverse\_nested":{}}},"filters":{"filters":\[{"script":{"script":{…

---

## [Transform not aligning checkpoints with date histogram](https://discuss.elastic.co/t/transform-not-aligning-checkpoints-with-date-histogram/324063)

<div class="topic-metadata">

**Author:** [@ddolcimascolo](https://discuss.elastic.co/u/ddolcimascolo)\
**Replies:** 6\
**Last updated:** [January 27, 2023, 9:41pm UTC](https://discuss.elastic.co/t/transform-not-aligning-checkpoints-with-date-histogram/324063 "2023-01-27T21:41:07Z")

</div>

Hi all. I'm using pivot transforms to group data by a date histogram and a few other terms dimensions. The transforms are running in continuous mode using the ingest timestamp as the sync.time.field but I'm grouping on …

---

## [ElasticSearch-8-5-2 ingest-pipeline issue](https://discuss.elastic.co/t/elasticsearch-8-5-2-ingest-pipeline-issue/324114)

<div class="topic-metadata">

**Author:** [@Pierre\_LANCASTRE](https://discuss.elastic.co/u/Pierre_LANCASTRE)\
**Replies:** 10\
**Last updated:** [January 27, 2023, 5:32pm UTC](https://discuss.elastic.co/t/elasticsearch-8-5-2-ingest-pipeline-issue/324114 "2023-01-27T17:32:26Z")

</div>

Hi all, I recently posted a problem on ingest-pipelines working in testing mode but finally not working. I have the same issue and i m still stuck while I ve tried many tricks (remove special characters from syslog stri…

---

## [Replace one value with another logstash](https://discuss.elastic.co/t/replace-one-value-with-another-logstash/324130)

<div class="topic-metadata">

**Author:** [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 8:44pm UTC](https://discuss.elastic.co/t/replace-one-value-with-another-logstash/324130 "2023-01-27T20:44:05Z")

</div>

Hi, I was trying to convert the value of one field with another, for example: I currently have a field called "priority" and the value of that field is = 1, priority=1. What I want to do is change that value 1 to critic…

---

## [How could i manage types in new versions ? another way?](https://discuss.elastic.co/t/how-could-i-manage-types-in-new-versions-another-way/324134)

<div class="topic-metadata">

**Author:** [@Anibal\_Ardid](https://discuss.elastic.co/u/Anibal_Ardid)\
**Replies:** 5\
**Last updated:** [January 27, 2023, 7:46pm UTC](https://discuss.elastic.co/t/how-could-i-manage-types-in-new-versions-another-way/324134 "2023-01-27T19:46:52Z")

</div>

Hi ! I'm new on elasticsearch indexing. And i'm trying to migrate from v5 to v8, i know this is a big change and challenge. I read about types are deprecated now. So , how could i manage my data ? Now I have 1 index…

---

## [Mutate a specific JSON field but not another](https://discuss.elastic.co/t/mutate-a-specific-json-field-but-not-another/324079)

<div class="topic-metadata">

**Author:** [@hexoffender](https://discuss.elastic.co/u/hexoffender)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 8:18pm UTC](https://discuss.elastic.co/t/mutate-a-specific-json-field-but-not-another/324079 "2023-01-27T20:18:40Z")

</div>

Hello, I have data that looks like this. { "remote\_addr": "127.0.0.1", "time\_local": "26/Jan/2023:17:07:18 -0800", "request": "POST /abcd HTTP/1.1", "request\_method": "POST", "status": "200", "us…

---

## [Creating an index with existing index](https://discuss.elastic.co/t/creating-an-index-with-existing-index/323550)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 8:15pm UTC](https://discuss.elastic.co/t/creating-an-index-with-existing-index/323550 "2023-01-27T20:15:28Z")

</div>

Hello, I have many indexes named .ds-traces-apm-default-2022.12.12-000124 .ds-traces-apm-default-2022.12.17-000125 .ds-traces-apm-default-2022.12.20-000126 .ds-traces-apm-default-2022.12.22-000127 .ds-traces-apm-de…

---

## [Elastic search SaveJsontoEs Hadoop Libra dropping documents without throwing error or warning](https://discuss.elastic.co/t/elastic-search-savejsontoes-hadoop-libra-dropping-documents-without-throwing-error-or-warning/323384)

<div class="topic-metadata">

**Author:** [@Bhuvesh\_Seth](https://discuss.elastic.co/u/Bhuvesh_Seth)\
**Replies:** 8\
**Last updated:** [January 27, 2023, 7:51pm UTC](https://discuss.elastic.co/t/elastic-search-savejsontoes-hadoop-libra-dropping-documents-without-throwing-error-or-warning/323384 "2023-01-27T19:51:59Z")

</div>

Hi, we are using Elasticsearch Hadoop library to index the documents from Spark job. We are facing one weird issue where the documents are not getting indexed without throwing any error or exception. Method used: rdd.Sa…

---

## ["upgrade Assistant" is not visible under "management tab"](https://discuss.elastic.co/t/upgrade-assistant-is-not-visible-under-management-tab/324055)

<div class="topic-metadata">

**Author:** [@shahulyousuf](https://discuss.elastic.co/u/shahulyousuf)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 6:18pm UTC](https://discuss.elastic.co/t/upgrade-assistant-is-not-visible-under-management-tab/324055 "2023-01-27T18:18:38Z")

</div>

Hey, I'm new to elasticsearch, I have installed elasticsearch 8.5.2 in single node and configured Kibana. Now I'm trying to upgrade to 8.6.1 through upgrade assistant as elastic user but cant find the upgrade assistant…

---

## [Provided Grok expressions do not match field value](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/324133)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 6:04pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/324133 "2023-01-27T18:04:38Z")

</div>

Hi Team, I installed 7.12.1 filebeat and enabled apache module but I'm getting "error.message Provided Grok expressions do not match field value". I checked apache log format for my website.it seems like below; LogFo…

---

## [How to pass variable to the body section of script in webhook watcher?](https://discuss.elastic.co/t/how-to-pass-variable-to-the-body-section-of-script-in-webhook-watcher/324118)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 5:39pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-to-the-body-section-of-script-in-webhook-watcher/324118 "2023-01-27T17:39:48Z")

</div>

I have the following webhook watcher which creates OTRS ticket when there is a term "Error" in document. However right now the ticket body declared in script is a fixed string for now ( This is only a test). How to pa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=650)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=652)
