# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=655

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 656

---

## [Highlight: Nested search highlights entire phrase instead of matched term](https://discuss.elastic.co/t/highlight-nested-search-highlights-entire-phrase-instead-of-matched-term/323934)

<div class="topic-metadata">

**Author:** [@sandy01](https://discuss.elastic.co/u/sandy01)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:49pm UTC](https://discuss.elastic.co/t/highlight-nested-search-highlights-entire-phrase-instead-of-matched-term/323934 "2023-01-25T14:49:30Z")

</div>

Hello, I have a lot of data of this type: { "timestamp": "2021-01-01T01:22:31" "urls": \[ { "visited": false, "url": "https://drive.google.com", }, { "…

---

## [Cluster red, unassigned shards, no response on writes](https://discuss.elastic.co/t/cluster-red-unassigned-shards-no-response-on-writes/322114)

<div class="topic-metadata">

**Author:** [@decibel83](https://discuss.elastic.co/u/decibel83)\
**Replies:** 16\
**Last updated:** [January 25, 2023, 2:41pm UTC](https://discuss.elastic.co/t/cluster-red-unassigned-shards-no-response-on-writes/322114 "2023-01-25T14:41:58Z")

</div>

Hi everyone, I'm dealing with a problem on Elasticsearch 7.17.5 (I've also tried to upgrade it to version 8 but I'm having the same problem with that version too) which is hanged, red status and unresponsive on any writ…

---

## [Get count based on geo\_distance filter and term search inside an item attribute in ES 7.10](https://discuss.elastic.co/t/get-count-based-on-geo-distance-filter-and-term-search-inside-an-item-attribute-in-es-7-10/323933)

<div class="topic-metadata">

**Author:** [@Coman\_Alexandru](https://discuss.elastic.co/u/Coman_Alexandru)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:35pm UTC](https://discuss.elastic.co/t/get-count-based-on-geo-distance-filter-and-term-search-inside-an-item-attribute-in-es-7-10/323933 "2023-01-25T14:35:48Z")

</div>

I'm running Elasticsearch version: 7.10 with an index and below you have an example for an index item: { "\_index": "wonder-search", "\_type": "\_doc", "\_id": "Bvpam4UBCGd9T\_03g7QP", "\_version": 1, "\_seq\_no": 2000, "…

---

## [Omit indices when searching on multiple indices](https://discuss.elastic.co/t/omit-indices-when-searching-on-multiple-indices/323866)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 1:32pm UTC](https://discuss.elastic.co/t/omit-indices-when-searching-on-multiple-indices/323866 "2023-01-25T13:32:23Z")

</div>

A question and maybe a feature request. We have 100 indices for filebeat with this pattern: filebeat-{CLUSTER\_NAME}-{NAMESPACE}-{DATE} . Documents are: {"@timestamp" : "..." , "cluster" : "prod", "namespace" : "kub…

---

## [Determine if field containing special characters in name is not null in Elasticsearch ingest pipeline](https://discuss.elastic.co/t/determine-if-field-containing-special-characters-in-name-is-not-null-in-elasticsearch-ingest-pipeline/322406)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 2:10pm UTC](https://discuss.elastic.co/t/determine-if-field-containing-special-characters-in-name-is-not-null-in-elasticsearch-ingest-pipeline/322406 "2023-01-25T14:10:47Z")

</div>

I'm monitoring a set of pods using elastic-agent which have labels which resolve to the following format when ingested: kubernetes.labels.foo\_bar/baz: value I need to do something in Elasticsearch ingest pipeline if th…

---

## [Filebeat regex in windows path](https://discuss.elastic.co/t/filebeat-regex-in-windows-path/323927)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-regex-in-windows-path/323927 "2023-01-25T14:06:48Z")

</div>

Hi, I'm trying to collect logs from a windows path with filebeat with filestream as input like so: --- # vim:ft=yaml - type: filestream paths: - 'C:\\Users\\\*\\some\\other\\folders\\\*.json' fields\_under\_root: true …

---

## [Pagerduty connector](https://discuss.elastic.co/t/pagerduty-connector/323244)

<div class="topic-metadata">

**Author:** [@AdityaKhajuria](https://discuss.elastic.co/u/AdityaKhajuria)\
**Replies:** 5\
**Last updated:** [January 25, 2023, 1:19pm UTC](https://discuss.elastic.co/t/pagerduty-connector/323244 "2023-01-25T13:19:57Z")

</div>

Rules & Connectors Hi team, im trying to integrate Pagerduty with Elasticsearch, so far i have created the Elastic-Alerts service in Pagerduty and have used all those credentials right here in Kibana connector, but when…

---

## [Path files Visualizations](https://discuss.elastic.co/t/path-files-visualizations/323899)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 4\
**Last updated:** [January 25, 2023, 12:58pm UTC](https://discuss.elastic.co/t/path-files-visualizations/323899 "2023-01-25T12:58:03Z")

</div>

Hello everyone, I Hobe ta all is very well, I have a Q regarding use path files to visualize them in Kibana. Is it possible to find a way to use Kibana search engine to find specific line in the set of files without s…

---

## [How to use the http.p12, http\_ca.crt and transport.p12 generated by elasticsearch when run as a single node](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913)

<div class="topic-metadata">

**Author:** [@Raja\_Muneer](https://discuss.elastic.co/u/Raja_Muneer)\
**Replies:** 3\
**Last updated:** [January 25, 2023, 12:51pm UTC](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913 "2023-01-25T12:51:25Z")

</div>

I am trying to enable HTTPS on my elk-stack. While I am able to do so using the following link. Configuring ssl,tls and https However, When we run elasticsearch as a single node it generates some default certificates w…

---

## [Error when using autodiscover + hints + templates with filebeat 8.6](https://discuss.elastic.co/t/error-when-using-autodiscover-hints-templates-with-filebeat-8-6/323527)

<div class="topic-metadata">

**Author:** [@Laffs2k5](https://discuss.elastic.co/u/Laffs2k5)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 12:38pm UTC](https://discuss.elastic.co/t/error-when-using-autodiscover-hints-templates-with-filebeat-8-6/323527 "2023-01-25T12:38:11Z")

</div>

Hi, Thought I should check in with the community here before creating a github issue, just in case there's something I'm not understanding correctly; After upgrading our filebeat kubernetes daemonset from 7.17.8 to 8.6…

---

## [Elastic Transforms - continous mode is not detecting changes](https://discuss.elastic.co/t/elastic-transforms-continous-mode-is-not-detecting-changes/323895)

<div class="topic-metadata">

**Author:** [@catrexis](https://discuss.elastic.co/u/catrexis)\
**Replies:** 3\
**Last updated:** [January 25, 2023, 12:32pm UTC](https://discuss.elastic.co/t/elastic-transforms-continous-mode-is-not-detecting-changes/323895 "2023-01-25T12:32:07Z")

</div>

I have a problem with my index transformation and already tried so many different versions but nothing helped: My documents in the source index look like: { "content" : { "creationTime" : "2022-07-25 16:00:49 +02…

---

## [Kubernetes.node.status.\* metrics not available for alerting](https://discuss.elastic.co/t/kubernetes-node-status-metrics-not-available-for-alerting/323901)

<div class="topic-metadata">

**Author:** [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 11:43am UTC](https://discuss.elastic.co/t/kubernetes-node-status-metrics-not-available-for-alerting/323901 "2023-01-25T11:43:52Z")

</div>

Hello, i am using metricbeat in kubernetes with next config - module: kubernetes metricsets: - node - system - pod - container - volume period: 10s host: ${N…

---

## [How can I create custom tags from the data inside a log file using filebeat](https://discuss.elastic.co/t/how-can-i-create-custom-tags-from-the-data-inside-a-log-file-using-filebeat/323657)

<div class="topic-metadata">

**Author:** [@Raja\_Muneer](https://discuss.elastic.co/u/Raja_Muneer)\
**Replies:** 11\
**Last updated:** [January 25, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-can-i-create-custom-tags-from-the-data-inside-a-log-file-using-filebeat/323657 "2023-01-25T11:21:20Z")

</div>

I am using elk stack for a month now. Lately, I have come across a situation where I need some help from the community to save me some time. I am actually running filebeat and elk stack in docker. I am sending logs from …

---

## [Correct way to get Not Exists or Exists and empty fields Query for multiple level of nested properties](https://discuss.elastic.co/t/correct-way-to-get-not-exists-or-exists-and-empty-fields-query-for-multiple-level-of-nested-properties/323903)

<div class="topic-metadata">

**Author:** [@Denis\_Kostaev](https://discuss.elastic.co/u/Denis_Kostaev)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 9:39am UTC](https://discuss.elastic.co/t/correct-way-to-get-not-exists-or-exists-and-empty-fields-query-for-multiple-level-of-nested-properties/323903 "2023-01-25T09:39:31Z")

</div>

Hello, I have a mapping with the multiple level of nested properties. I'm trying to get Not Exists (not mapped) fields on 3 lvl or Exists and empty (empty string or null values). "mappings": { "properties": { …

---

## [ES 8 Java client: BoolQuery.Builder no longer has hasClauses() method](https://discuss.elastic.co/t/es-8-java-client-boolquery-builder-no-longer-has-hasclauses-method/323894)

<div class="topic-metadata">

**Author:** [@yusufozcan](https://discuss.elastic.co/u/yusufozcan)\
**Replies:** 3\
**Last updated:** [January 25, 2023, 10:33am UTC](https://discuss.elastic.co/t/es-8-java-client-boolquery-builder-no-longer-has-hasclauses-method/323894 "2023-01-25T10:33:00Z")

</div>

Hello. We are upgrading our elastic java client from 6.8.10 to 8.1.3 and it seems BoolQuery.Builder doesn't have hasClauses() method anymore. Is there any workaround which provides the same functionality? Thanks in adv…

---

## [Make virtualization file beat aggregation](https://discuss.elastic.co/t/make-virtualization-file-beat-aggregation/323907)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 10:26am UTC](https://discuss.elastic.co/t/make-virtualization-file-beat-aggregation/323907 "2023-01-25T10:26:00Z")

</div>

"log.file.path": \[ "C:\\ProgramData\\UNO\\SES\\Logs\\user1\\101.log" 10 count "log.file.path": \[ "C:\\ProgramData\\UNO\\SES\\Logs\\user1\\102.log" 20 count "log.file.path": \[ "C:\\ProgramData\\UNO\\SES\\Logs\\user2\\101.log" …

---

## [Showing 'actual' & 'typical' values in ML anomaly detection alert](https://discuss.elastic.co/t/showing-actual-typical-values-in-ml-anomaly-detection-alert/322810)

<div class="topic-metadata">

**Author:** [@nospace](https://discuss.elastic.co/u/nospace)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 9:56am UTC](https://discuss.elastic.co/t/showing-actual-typical-values-in-ml-anomaly-detection-alert/322810 "2023-01-25T09:56:58Z")

</div>

Hey folks, We're running a couple of ML jobs for anomaly detection with mail alerts. For faster detection of false alerts I would like to extend the alert with the values from 'actual' and 'typical'. The documentation …

---

## [Replacement of QueryBuilder(ES 5.6) in ES 8.5](https://discuss.elastic.co/t/replacement-of-querybuilder-es-5-6-in-es-8-5/323856)

<div class="topic-metadata">

**Author:** [@Harsh0145](https://discuss.elastic.co/u/Harsh0145)\
**Replies:** 3\
**Last updated:** [January 25, 2023, 9:49am UTC](https://discuss.elastic.co/t/replacement-of-querybuilder-es-5-6-in-es-8-5/323856 "2023-01-25T09:49:44Z")

</div>

Hi, We have been using the ES 5.6 cluster, but are now migrating to a new ES 8.5 cluster. The Data migration, and indexing queries are all sorted. However, earlier we used to use QueryBuilder in ES 5.6 java app and ther…

---

## [Get List of top occurance for specific condition](https://discuss.elastic.co/t/get-list-of-top-occurance-for-specific-condition/323864)

<div class="topic-metadata">

**Author:** [@nada.nasser](https://discuss.elastic.co/u/nada.nasser)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 9:37am UTC](https://discuss.elastic.co/t/get-list-of-top-occurance-for-specific-condition/323864 "2023-01-25T09:37:05Z")

</div>

I am having an index where data is logged with a success/fail flag for a specific item. I want to get a unique list of items who has fail and never a success. Usually a success is expected after fail from time perspecti…

---

## [Interrupted system call, INTERNAL\_SERVER\_ERROR during Elasticsearch snapshot](https://discuss.elastic.co/t/interrupted-system-call-internal-server-error-during-elasticsearch-snapshot/323900)

<div class="topic-metadata">

**Author:** [@chaitra\_hegde](https://discuss.elastic.co/u/chaitra_hegde)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 9:30am UTC](https://discuss.elastic.co/t/interrupted-system-call-internal-server-error-during-elasticsearch-snapshot/323900 "2023-01-25T09:30:53Z")

</div>

Hi, I am using ES 7.8.0 version and sometimes my snapshot is failing with below errors. What could be the reason for this? "failures\\":\[{\\"index\\":\\"operation-2022.12.23\\",\\"index\_uuid\\":\\"operation-2022.12.23\\",\\"shar…

---

## [Kibana Lens Column Ordering](https://discuss.elastic.co/t/kibana-lens-column-ordering/323666)

<div class="topic-metadata">

**Author:** [@peter.branzi](https://discuss.elastic.co/u/peter.branzi)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 9:08am UTC](https://discuss.elastic.co/t/kibana-lens-column-ordering/323666 "2023-01-25T09:08:48Z")

</div>

hi there I'm using Kibana 8.4.2 and was wondering if anyone knows of a way to reverse the ordering of the columns so that the most recents dates are in front ? Column is an aggregation of events by a timestamp T…

---

## [Create filed with type and format by api](https://discuss.elastic.co/t/create-filed-with-type-and-format-by-api/323853)

<div class="topic-metadata">

**Author:** [@Ased13](https://discuss.elastic.co/u/Ased13)\
**Replies:** 3\
**Last updated:** [January 25, 2023, 8:56am UTC](https://discuss.elastic.co/t/create-filed-with-type-and-format-by-api/323853 "2023-01-25T08:56:11Z")

</div>

hi can create a field with the following request? {"mappings": {"properties": {"address": {"type":"text","format":"url"} } } } If not,How can it be created by request with specifying the forma…

---

## [Filebeat settings](https://discuss.elastic.co/t/filebeat-settings/323845)

<div class="topic-metadata">

**Author:** [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 8:37am UTC](https://discuss.elastic.co/t/filebeat-settings/323845 "2023-01-25T08:37:27Z")

</div>

Hello, I want to clarify if I understood the documentation correctly, bulk\_max\_size - filebeat transmits events (as I understand it, let's say a line in the log file) bundled, default 50, if I set 0, then queue comes i…

---

## [DEPLOY ELK STACK (with eck) using CLONED DISKS](https://discuss.elastic.co/t/deploy-elk-stack-with-eck-using-cloned-disks/323744)

<div class="topic-metadata">

**Author:** [@Maria\_Gabriela\_Perez](https://discuss.elastic.co/u/Maria_Gabriela_Perez)\
**Replies:** 6\
**Last updated:** [January 25, 2023, 7:28am UTC](https://discuss.elastic.co/t/deploy-elk-stack-with-eck-using-cloned-disks/323744 "2023-01-25T07:28:17Z")

</div>

Is it possible to deploy on kubernetes (gke) a new copy of elasticsearch using cloned disks from another elasticsearch deployment in another cluster, without conflicts? Any workarounds ?.. I need to restore logs saved i…

---

## [How to identify if a Windows PC requires a restart?](https://discuss.elastic.co/t/how-to-identify-if-a-windows-pc-requires-a-restart/323887)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 7:08am UTC](https://discuss.elastic.co/t/how-to-identify-if-a-windows-pc-requires-a-restart/323887 "2023-01-25T07:08:20Z")

</div>

Hi, I am using Elastic agent 7.17.4 to monitor the windows machines. Is there any OOB feature to identify if a Windows machine requires a restart after a patch/software update?

---

## [Can Packetbeat just capture the packets without decoding?](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473)

<div class="topic-metadata">

**Author:** [@sarathtv](https://discuss.elastic.co/u/sarathtv)\
**Replies:** 4\
**Last updated:** [January 25, 2023, 4:35am UTC](https://discuss.elastic.co/t/can-packetbeat-just-capture-the-packets-without-decoding/323473 "2023-01-25T04:35:05Z")

</div>

My application uses SIP protocol and I wanted to have a real-time packet analyzer for it. I found that Packetbeat could be the perfect fit, but unfortunately it doesn't support SIP in the listed set of protocols. Is the…

---

## [Is there a beat listing all installed RPMs?](https://discuss.elastic.co/t/is-there-a-beat-listing-all-installed-rpms/323886)

<div class="topic-metadata">

**Author:** [@franknord](https://discuss.elastic.co/u/franknord)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 6:57am UTC](https://discuss.elastic.co/t/is-there-a-beat-listing-all-installed-rpms/323886 "2023-01-25T06:57:02Z")

</div>

In order to get a quick overview of the RPMs installed on my servers, I wrote a simple shell script listing all RPMs and their versions into a CSV and sending this file via Filebeat to Logstash. Everything is working wel…

---

## [Authentication using apikey failed](https://discuss.elastic.co/t/authentication-using-apikey-failed/323875)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 4\
**Last updated:** [January 25, 2023, 6:41am UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed/323875 "2023-01-25T06:41:59Z")

</div>

Suddenly this error appeared. I can't find in the logs what is the cause of this error. Can anyone tell me how to fix this? Please help.. :cry: I am using version of elasticsearch 7.17.8 and kibana 7.17.8 error: Au…

---

## [Filters on lens](https://discuss.elastic.co/t/filters-on-lens/323795)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 5:15am UTC](https://discuss.elastic.co/t/filters-on-lens/323795 "2023-01-25T05:15:16Z")

</div>

Hi, I created a table using the Lens, with the column names as below. Name, Age, city, and occupation. I want to use the filter in the one of the above columns (example age: 27), display all the entries for this table…

---

## [Elastic Search - Error Detail - Only one usage of each socket address (protocol/network address/port) is normally permitted Error](https://discuss.elastic.co/t/elastic-search-error-detail-only-one-usage-of-each-socket-address-protocol-network-address-port-is-normally-permitted-error/323792)

<div class="topic-metadata">

**Author:** [@ankurpatel](https://discuss.elastic.co/u/ankurpatel)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 5:07am UTC](https://discuss.elastic.co/t/elastic-search-error-detail-only-one-usage-of-each-socket-address-protocol-network-address-port-is-normally-permitted-error/323792 "2023-01-25T05:07:31Z")

</div>

We have got below error in API which access data from Elastic Search. Error generated when web site traffic is high. We have configured Elastic Search on Single Node. We developed API(.NET core) by using NEST (7.15.1 lib…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=654)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=656)
