# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=654

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 655

---

## [Full-text search is faster if queries are sent constantly](https://discuss.elastic.co/t/full-text-search-is-faster-if-queries-are-sent-constantly/323955)

<div class="topic-metadata">

**Author:** [@athlonIIx2](https://discuss.elastic.co/u/athlonIIx2)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 8:55am UTC](https://discuss.elastic.co/t/full-text-search-is-faster-if-queries-are-sent-constantly/323955 "2023-01-26T08:55:48Z")

</div>

Please help me understand my case, as I am new to Elasticsearch. I use Elasticsearch on a single node to make full-text search queries from a Python API. The problem is that searching time may vary from seconds to tens…

---

## [Is the logstash-plugins artifacts link correct?](https://discuss.elastic.co/t/is-the-logstash-plugins-artifacts-link-correct/323999)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 8:16am UTC](https://discuss.elastic.co/t/is-the-logstash-plugins-artifacts-link-correct/323999 "2023-01-26T08:16:13Z")

</div>

Looking if package named: logstash-output-influxdb exists at https://artifacts.elastic.co/downloads/logstash-plugins/logstash-output-influxdb/logstash-output-influxdb-7.6.2.zip Net::OpenTimeout: execution expired …

---

## [Metricbeat to monitor specific docker containers by name/image](https://discuss.elastic.co/t/metricbeat-to-monitor-specific-docker-containers-by-name-image/323986)

<div class="topic-metadata">

**Author:** [@Yungxin\_Shin](https://discuss.elastic.co/u/Yungxin_Shin)\
**Replies:** 5\
**Last updated:** [January 26, 2023, 8:30am UTC](https://discuss.elastic.co/t/metricbeat-to-monitor-specific-docker-containers-by-name-image/323986 "2023-01-26T08:30:56Z")

</div>

Hello everyone, I am currently using Metricbeat to monitor my Docker containers and it is working well with my current configuration. metricbeat.modules: - module: docker metricsets: - container - cpu…

---

## [\[MAPS\] Activate wheel scroll zoom in maps Kibana 7.14.1](https://discuss.elastic.co/t/maps-activate-wheel-scroll-zoom-in-maps-kibana-7-14-1/323822)

<div class="topic-metadata">

**Author:** [@MADPACISA](https://discuss.elastic.co/u/MADPACISA)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 7:56am UTC](https://discuss.elastic.co/t/maps-activate-wheel-scroll-zoom-in-maps-kibana-7-14-1/323822 "2023-01-26T07:56:41Z")

</div>

Hi, Im trying to activate the wheel scroll zoom in maps, i have kibana 7.14.1, there exist a file where i can activate it or how can i do it?

---

## [Kibana Dashboard](https://discuss.elastic.co/t/kibana-dashboard/323970)

<div class="topic-metadata">

**Author:** [@suj0](https://discuss.elastic.co/u/suj0)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:55am UTC](https://discuss.elastic.co/t/kibana-dashboard/323970 "2023-01-26T07:55:09Z")

</div>

Is there any way I can use the selected date and time range from date picker in the filter KQL

---

## [Visualization link output from watcher alert](https://discuss.elastic.co/t/visualization-link-output-from-watcher-alert/323960)

<div class="topic-metadata">

**Author:** [@Umar\_Farooq1](https://discuss.elastic.co/u/Umar_Farooq1)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:50am UTC](https://discuss.elastic.co/t/visualization-link-output-from-watcher-alert/323960 "2023-01-26T07:50:54Z")

</div>

Hi there, I have many advanced based watchers setup which looks for various queries. when it alerts, we usually get our alerts on slack. I was wondering how can i add a link to it which will show me the specific data po…

---

## [Support of IAM for Elasticsearch Input plugin](https://discuss.elastic.co/t/support-of-iam-for-elasticsearch-input-plugin/323982)

<div class="topic-metadata">

**Author:** [@vijayalakshmi\_chanum](https://discuss.elastic.co/u/vijayalakshmi_chanum)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:49am UTC](https://discuss.elastic.co/t/support-of-iam-for-elasticsearch-input-plugin/323982 "2023-01-26T07:49:04Z")

</div>

Do we have support for passing IAM credentials for logstash using Elasticsearch input plugin?

---

## [Elasticsearch templates](https://discuss.elastic.co/t/elasticsearch-templates/323984)

<div class="topic-metadata">

**Author:** [@cybersirp](https://discuss.elastic.co/u/cybersirp)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:38am UTC](https://discuss.elastic.co/t/elasticsearch-templates/323984 "2023-01-26T07:38:04Z")

</div>

I notice that starting from elasticsearch 8.x everything has changed in relation to working with templates and I am very confused and I would like a Samaritan to help me solve this problem. curl -s -H "Content-type: app…

---

## [It looks like you have instances that aren't connected to an Elasticsearch cluster](https://discuss.elastic.co/t/it-looks-like-you-have-instances-that-arent-connected-to-an-elasticsearch-cluster/323057)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 7\
**Last updated:** [January 26, 2023, 3:34am UTC](https://discuss.elastic.co/t/it-looks-like-you-have-instances-that-arent-connected-to-an-elasticsearch-cluster/323057 "2023-01-26T03:34:15Z")

</div>

Hello World! per the above screenshot, it appears like there are 2 (two) clusters, in reality there is only 1 (one) the "standalone cluster" is using a separate set of metricbeat vs the "elasticsearch" cluster, and …

---

## [How to Generate UUID from Index Name?](https://discuss.elastic.co/t/how-to-generate-uuid-from-index-name/323979)

<div class="topic-metadata">

**Author:** [@Nebula](https://discuss.elastic.co/u/Nebula)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 3:36am UTC](https://discuss.elastic.co/t/how-to-generate-uuid-from-index-name/323979 "2023-01-26T03:36:16Z")

</div>

Hello everyone, I have some index patterns setup in my Elasticsearch. I see the index name gets encoded as a UUID in the URL (the value for the key “index:” in the URL once an index is selected). How can I go about gen…

---

## [Is logstash-output-influxdb plugin InfluxDB V2 support?](https://discuss.elastic.co/t/is-logstash-output-influxdb-plugin-influxdb-v2-support/323985)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 2:22am UTC](https://discuss.elastic.co/t/is-logstash-output-influxdb-plugin-influxdb-v2-support/323985 "2023-01-26T02:22:00Z")

</div>

Hi guys I notice that it seems no available output plugin for InfluxDB V2. Is logstash-output-influxdb plugin really being maintained? If the plugin isn't maintained actively, who can I contact to request to update th…

---

## [How to add the "hostname" and "environment" variables in the "message body" of the email alert sent from Watcher in Kibana?](https://discuss.elastic.co/t/how-to-add-the-hostname-and-environment-variables-in-the-message-body-of-the-email-alert-sent-from-watcher-in-kibana/323476)

<div class="topic-metadata">

**Author:** [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Replies:** 4\
**Last updated:** [January 25, 2023, 11:03pm UTC](https://discuss.elastic.co/t/how-to-add-the-hostname-and-environment-variables-in-the-message-body-of-the-email-alert-sent-from-watcher-in-kibana/323476 "2023-01-25T23:03:25Z")

</div>

Hi, We had created Watcher and configured alert rules to send the email when a threshold is breached. The email body should contain the "hostname" and the corresponding "environment" when it is triggered. We tried to …

---

## [Upgrade elasticsearch 8.5.0 master not discovered or elected yet and uncaught exception in thread](https://discuss.elastic.co/t/upgrade-elasticsearch-8-5-0-master-not-discovered-or-elected-yet-and-uncaught-exception-in-thread/323974)

<div class="topic-metadata">

**Author:** [@gps88](https://discuss.elastic.co/u/gps88)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 10:13pm UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-8-5-0-master-not-discovered-or-elected-yet-and-uncaught-exception-in-thread/323974 "2023-01-25T22:13:23Z")

</div>

I have 3 elasticsearch nodes, nodes 1 and 2 (Red Hat Enterprise Linux release 8.6 ) are configured as master, I try to start the service and it only starts node 3 which is data only, nodes 1 and 2 show the following in t…

---

## [Elastic Agent elastic-agent-pipeline.conf](https://discuss.elastic.co/t/elastic-agent-elastic-agent-pipeline-conf/323969)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 8:27pm UTC](https://discuss.elastic.co/t/elastic-agent-elastic-agent-pipeline-conf/323969 "2023-01-25T20:27:29Z")

</div>

Where is this file located? I'm testing an integration, created an Agent Policy and then enrolled the Elastic-Agent through Fleet. I need to setup Logstash to accept logs from the Elastic Agent but I need to edit step …

---

## [Dynamic-mapped field changes type after rollover](https://discuss.elastic.co/t/dynamic-mapped-field-changes-type-after-rollover/323968)

<div class="topic-metadata">

**Author:** [@foxy](https://discuss.elastic.co/u/foxy)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 8:04pm UTC](https://discuss.elastic.co/t/dynamic-mapped-field-changes-type-after-rollover/323968 "2023-01-25T20:04:47Z")

</div>

A field in the latest backing index for a data-stream has been mapped to a different type following rollover: Is it possible to re-index the current write index into a new index that would match the index pattern (…

---

## [How to implement "immutable indices"?](https://discuss.elastic.co/t/how-to-implement-immutable-indices/323297)

<div class="topic-metadata">

**Author:** [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Replies:** 6\
**Last updated:** [January 25, 2023, 7:36pm UTC](https://discuss.elastic.co/t/how-to-implement-immutable-indices/323297 "2023-01-25T19:36:43Z")

</div>

Hi We are using platinum subscription for our "elastic" stack from "elastic.co" and we are informed that they do not support "immutable indices" for our subscription. We are using the elasticsearch version 7.17.5 with o…

---

## [Migration tool for legacy index templates to composable?](https://discuss.elastic.co/t/migration-tool-for-legacy-index-templates-to-composable/323433)

<div class="topic-metadata">

**Author:** [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 7:35pm UTC](https://discuss.elastic.co/t/migration-tool-for-legacy-index-templates-to-composable/323433 "2023-01-25T19:35:55Z")

</div>

We have a large number of legacy index templates. Is there any migration tools to move them to their composable index template version? If not, what is the best way of migrating them?

---

## [Customize Kibana Alerting Rule](https://discuss.elastic.co/t/customize-kibana-alerting-rule/323961)

<div class="topic-metadata">

**Author:** [@lchan](https://discuss.elastic.co/u/lchan)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 7:05pm UTC](https://discuss.elastic.co/t/customize-kibana-alerting-rule/323961 "2023-01-25T19:05:44Z")

</div>

Hello, Is there a way to customize the canned alert rules in Elastic Cloud \> rules? (KQL Query?) Frozen node is using disk cache and always at 90% and I would like to filter the node role. I tried some KQL expression i…

---

## [Bulding nested query with new Java API](https://discuss.elastic.co/t/bulding-nested-query-with-new-java-api/323949)

<div class="topic-metadata">

**Author:** [@schmermeister](https://discuss.elastic.co/u/schmermeister)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 4:55pm UTC](https://discuss.elastic.co/t/bulding-nested-query-with-new-java-api/323949 "2023-01-25T16:55:36Z")

</div>

I try to achieve a query like this: { "query": { "bool": { "must": \[ { "match": { "metaData.cluster": "mobile" } } }, { "bool": …

---

## [Synonyms not being used in search results](https://discuss.elastic.co/t/synonyms-not-being-used-in-search-results/323920)

<div class="topic-metadata">

**Author:** [@appsol](https://discuss.elastic.co/u/appsol)\
**Replies:** 5\
**Last updated:** [January 25, 2023, 4:46pm UTC](https://discuss.elastic.co/t/synonyms-not-being-used-in-search-results/323920 "2023-01-25T16:46:55Z")

</div>

Hello, I have an index for services named 'testing\_services': 'properties' =\> \[ 'id' =\> \['type' =\> 'keyword'\], 'name' =\> \[ 'type' =\> 'text', 'analyzer' =\> 'english…

---

## [Kibana SSL verification Trust Issues](https://discuss.elastic.co/t/kibana-ssl-verification-trust-issues/322836)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 19\
**Last updated:** [January 25, 2023, 4:38pm UTC](https://discuss.elastic.co/t/kibana-ssl-verification-trust-issues/322836 "2023-01-25T16:38:24Z")

</div>

Hi everyone! I'm trying to set up certificate verification in my elk stack version 8.5.3. I'm using self generated certificates using my companys ca for each stack component and my cluster works fine as long as I set e…

---

## [Analyzer conditional token filter with regular expression](https://discuss.elastic.co/t/analyzer-conditional-token-filter-with-regular-expression/323943)

<div class="topic-metadata">

**Author:** [@Wonder\_Garance](https://discuss.elastic.co/u/Wonder_Garance)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 4:29pm UTC](https://discuss.elastic.co/t/analyzer-conditional-token-filter-with-regular-expression/323943 "2023-01-25T16:29:25Z")

</div>

Hello, in an analyzer conditional token filter, I use a painless script with the regular expression. If a token contains only letters et hypens, then the compound word in the token is splitted, otherwise no. But my scri…

---

## [Watcher webhook to create a OTRS ticket](https://discuss.elastic.co/t/watcher-webhook-to-create-a-otrs-ticket/323855)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 5\
**Last updated:** [January 25, 2023, 4:27pm UTC](https://discuss.elastic.co/t/watcher-webhook-to-create-a-otrs-ticket/323855 "2023-01-25T16:27:22Z")

</div>

I can curl and make an OTRS ticket by using the following : curl "http://myotrs.com/otrs/nph-genericinterface.pl/Webservice/GenericTicketConnectorREST/Ticket?UserLogin=username&Password=password" -H "Content-Type: app…

---

## [Is Filebeat suitable for local source-code search?](https://discuss.elastic.co/t/is-filebeat-suitable-for-local-source-code-search/323952)

<div class="topic-metadata">

**Author:** [@avistray](https://discuss.elastic.co/u/avistray)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 4:25pm UTC](https://discuss.elastic.co/t/is-filebeat-suitable-for-local-source-code-search/323952 "2023-01-25T16:25:05Z")

</div>

I have a local folder containing source code and I want to search the files in real time using Elasticsearch. Specifically, I want to use filebeat to monitor files in the folder and send the lines of the files to Elastic…

---

## [Error when creating plugin in Kibana 8.6 - Refused to execute script from 'url/bundles/plugin/dataDemo/1.0.0/dataDemo.plugin.js' because its MIME type ('application/json') is not executable, and strict MIME type checking is enabled](https://discuss.elastic.co/t/error-when-creating-plugin-in-kibana-8-6-refused-to-execute-script-from-url-bundles-plugin-datademo-1-0-0-datademo-plugin-js-because-its-mime-type-application-json-is-not-executable-and-strict-mime-type-checking-is-enabled/323924)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 4:07pm UTC](https://discuss.elastic.co/t/error-when-creating-plugin-in-kibana-8-6-refused-to-execute-script-from-url-bundles-plugin-datademo-1-0-0-datademo-plugin-js-because-its-mime-type-application-json-is-not-executable-and-strict-mime-type-checking-is-enabled/323924 "2023-01-25T16:07:23Z")

</div>

Hi, I just started Kibana in development mode . It works. I then created a plugin using plugin generator. When running kibana after that, it gives an error in the browser Refused to execute script from 'http://ip/bund…

---

## [Mapping conflict 4 fields are defined as several types ----](https://discuss.elastic.co/t/mapping-conflict-4-fields-are-defined-as-several-types/323529)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 6\
**Last updated:** [January 25, 2023, 4:06pm UTC](https://discuss.elastic.co/t/mapping-conflict-4-fields-are-defined-as-several-types/323529 "2023-01-25T16:06:13Z")

</div>

Hello i found this error in Kibana -\> Stack Management Mapping conflict 4 fields are defined as several types (string, integer, etc) across the indices that match this pattern. You may still be able to use these confl…

---

## [Deployment of Elasticsearch to EKS cluster with helm](https://discuss.elastic.co/t/deployment-of-elasticsearch-to-eks-cluster-with-helm/323944)

<div class="topic-metadata">

**Author:** [@Boris\_Tsekinovsky](https://discuss.elastic.co/u/Boris_Tsekinovsky)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 4:00pm UTC](https://discuss.elastic.co/t/deployment-of-elasticsearch-to-eks-cluster-with-helm/323944 "2023-01-25T16:00:53Z")

</div>

Hello elastic community, I'm trying to install ELK stack on AWS EKS cluster. I've created the cluster using CDK and now trying to deploy elasticsearch using helm: helm install elasticsearch elastic/elasticsearch -n mon…

---

## [Issue with running Logstash in docker](https://discuss.elastic.co/t/issue-with-running-logstash-in-docker/323931)

<div class="topic-metadata">

**Author:** [@SimonIv](https://discuss.elastic.co/u/SimonIv)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:34pm UTC](https://discuss.elastic.co/t/issue-with-running-logstash-in-docker/323931 "2023-01-25T14:34:07Z")

</div>

I'm trying to run Logstash in docker with Elasticsearch as output, however there are some warnings and errors like: elasticsearch:9200 failed to respond Unable to retrieve license information from license server {:mess…

---

## [Watcher Email Action with Custom X-Header?](https://discuss.elastic.co/t/watcher-email-action-with-custom-x-header/323938)

<div class="topic-metadata">

**Author:** [@bsherman](https://discuss.elastic.co/u/bsherman)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 3:01pm UTC](https://discuss.elastic.co/t/watcher-email-action-with-custom-x-header/323938 "2023-01-25T15:01:18Z")

</div>

My organization is using the Watcher Email Action and recently we discovered our emails are not reaching their recipient because a custom X-header is expected but we are not populating it. Is there a way to set a custom…

---

## [Logstash $HOME/.logstash\_jdbc\_last\_run not created](https://discuss.elastic.co/t/logstash-home-logstash-jdbc-last-run-not-created/323936)

<div class="topic-metadata">

**Author:** [@duffel](https://discuss.elastic.co/u/duffel)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:56pm UTC](https://discuss.elastic.co/t/logstash-home-logstash-jdbc-last-run-not-created/323936 "2023-01-25T14:56:03Z")

</div>

I am using logstash 7.14 and the jdbc plugin with the following settings jdbc { type =\> "jdbc-audit" id =\> "dev-jdbc-audit" jdbc\_driver\_library =\> "/opt/appl/lib/postgresql-42.5.1.jar" jdbc\_driver\_clas…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=653)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=655)
