# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=656

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 657

---

## [Haproxy + TCP + Provided Grok expressions do not match field value](https://discuss.elastic.co/t/haproxy-tcp-provided-grok-expressions-do-not-match-field-value/323879)

<div class="topic-metadata">

**Author:** [@Dipu\_Haridas](https://discuss.elastic.co/u/Dipu_Haridas)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 4:57am UTC](https://discuss.elastic.co/t/haproxy-tcp-provided-grok-expressions-do-not-match-field-value/323879 "2023-01-25T04:57:56Z")

</div>

Hi, I am new to Filebeat. Sorry if I sound foolish. I have been trying to load the haproxy logs to elasticsearch without much luck for quite some time. Haproxy Version: 1.8.27 Filebeat version: 7.17.8 Elasticsearch v…

---

## [Setting sameSiteCookies to None while kibana being behind a reverse proxy](https://discuss.elastic.co/t/setting-samesitecookies-to-none-while-kibana-being-behind-a-reverse-proxy/323877)

<div class="topic-metadata">

**Author:** [@vangap](https://discuss.elastic.co/u/vangap)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 3:58am UTC](https://discuss.elastic.co/t/setting-samesitecookies-to-none-while-kibana-being-behind-a-reverse-proxy/323877 "2023-01-25T03:58:03Z")

</div>

I have kibana running with SSL disabled and a reverse proxy (nginx) to do the SSL termination. I also have xpack.security.sameSiteCookies: "None" which seems ot be causing issues with below error. Is there a way to tel…

---

## [ElascticsearchClient 8.5.3 (Java) cannot unblock index via client](https://discuss.elastic.co/t/elascticsearchclient-8-5-3-java-cannot-unblock-index-via-client/323812)

<div class="topic-metadata">

**Author:** [@Denko](https://discuss.elastic.co/u/Denko)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 8:42pm UTC](https://discuss.elastic.co/t/elascticsearchclient-8-5-3-java-cannot-unblock-index-via-client/323812 "2023-01-24T20:42:05Z")

</div>

Hi, everyone! I'm trying to create a custom health check for Elasticsearch where its status is Down if an index is blocked (read-only, read-only-allow-delete, write) but I can't cover it with tests. This code doesn't wo…

---

## [\_size field (mapper size plugin)](https://discuss.elastic.co/t/size-field-mapper-size-plugin/323863)

<div class="topic-metadata">

**Author:** [@nikssssss](https://discuss.elastic.co/u/nikssssss)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 6:03pm UTC](https://discuss.elastic.co/t/size-field-mapper-size-plugin/323863 "2023-01-24T18:03:15Z")

</div>

Hi all, as i understand when we enable this feature (mapper size plugin) the \_size meta field is not a new field in the index but a field on kibana index patern, correct? Because i can see the \_size field on kibana disc…

---

## [How to set a value in timestamp](https://discuss.elastic.co/t/how-to-set-a-value-in-timestamp/323762)

<div class="topic-metadata">

**Author:** [@mariana17](https://discuss.elastic.co/u/mariana17)\
**Replies:** 6\
**Last updated:** [January 24, 2023, 5:22pm UTC](https://discuss.elastic.co/t/how-to-set-a-value-in-timestamp/323762 "2023-01-24T17:22:13Z")

</div>

I have two values as my date and hour data and i want them to be my timestamp: "F-MESSAGE-CAB": "20221018","H-MESSAGE-CAB": "601006" "F-MESSAGE-CAB": "20221018","H-MESSAGE-CAB": "1338311" What i'm trying to do is putt…

---

## [Logstash log](https://discuss.elastic.co/t/logstash-log/323775)

<div class="topic-metadata">

**Author:** [@kadamik](https://discuss.elastic.co/u/kadamik)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 5:02pm UTC](https://discuss.elastic.co/t/logstash-log/323775 "2023-01-24T17:02:35Z")

</div>

I have having trouble getting logstash and elasticsearch setup. I have my rsyslog server sending my logs from my Unifi UDM device. I have it setup for the most-part but the problem is how logstash is trasforming the l…

---

## [Methodology for merge data nodes to big one](https://discuss.elastic.co/t/methodology-for-merge-data-nodes-to-big-one/323823)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 3:52pm UTC](https://discuss.elastic.co/t/methodology-for-merge-data-nodes-to-big-one/323823 "2023-01-24T15:52:10Z")

</div>

Hi I need to change architecture of my cluster, thus I need to know Your's idea/approaches to do this. So currently my cluster consist on 3 bare metal server with sdd and hdd disk. But I need to increase memory of the…

---

## [Filebeat module ingest pipeline](https://discuss.elastic.co/t/filebeat-module-ingest-pipeline/323270)

<div class="topic-metadata">

**Author:** [@Daniel\_B](https://discuss.elastic.co/u/Daniel_B)\
**Replies:** 5\
**Last updated:** [January 24, 2023, 3:36pm UTC](https://discuss.elastic.co/t/filebeat-module-ingest-pipeline/323270 "2023-01-24T15:36:17Z")

</div>

I'm new to elastic. I'm using filebeat v8.5 and I have enabled some modules example: IIS, Checkpoint and few others which are working great. I also would like to create a new filebeat module for a specific device which …

---

## [Keep data in a rolling window of 3 months](https://discuss.elastic.co/t/keep-data-in-a-rolling-window-of-3-months/323458)

<div class="topic-metadata">

**Author:** [@Harsh0145](https://discuss.elastic.co/u/Harsh0145)\
**Replies:** 7\
**Last updated:** [January 24, 2023, 3:31pm UTC](https://discuss.elastic.co/t/keep-data-in-a-rolling-window-of-3-months/323458 "2023-01-24T15:31:31Z")

</div>

Hi, I am trying to delete or archive documents older than 3 months. Since our use case allows customers to update the data for the last 3 months, so at any moment in time, we should have the last 3 months of data. Accor…

---

## [Unable to install Fleet on 8.6.0](https://discuss.elastic.co/t/unable-to-install-fleet-on-8-6-0/323528)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 3:19pm UTC](https://discuss.elastic.co/t/unable-to-install-fleet-on-8-6-0/323528 "2023-01-24T15:19:49Z")

</div>

Hello I'm unable to install/initiate fleet on our kibana. I get below error message Debug logs for plugin.fleet {"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.4.0"},"@timestamp":"2023-01…

---

## [How to create file that contain tracking\_column date](https://discuss.elastic.co/t/how-to-create-file-that-contain-tracking-column-date/323846)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 3:01pm UTC](https://discuss.elastic.co/t/how-to-create-file-that-contain-tracking-column-date/323846 "2023-01-24T15:01:42Z")

</div>

Hi, please your help, I have a pipeline with input JDBC so I work with tracking\_colum, I have a file .sql\_last\_value\_date with this format: --- !ruby/object:DateTime '2022-07-01 05:00:00.000000000 Z' this the date that …

---

## [\[illegal\_state\_exception\] alias \[x\] has more than one write index \[y,z\]](https://discuss.elastic.co/t/illegal-state-exception-alias-x-has-more-than-one-write-index-y-z/323843)

<div class="topic-metadata">

**Author:** [@lazaro\_mobicare](https://discuss.elastic.co/u/lazaro_mobicare)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 2:34pm UTC](https://discuss.elastic.co/t/illegal-state-exception-alias-x-has-more-than-one-write-index-y-z/323843 "2023-01-24T14:34:38Z")

</div>

Hi! I'm having the following problem when trying to restore an index snapshot: \[illegal\_state\_exception\] alias \[x\] has more than one write index \[y,z\]. I followed the following resolution but I came across another proble…

---

## [500 error on running commands on kibana console](https://discuss.elastic.co/t/500-error-on-running-commands-on-kibana-console/323728)

<div class="topic-metadata">

**Author:** [@pranita.ch](https://discuss.elastic.co/u/pranita.ch)\
**Replies:** 8\
**Last updated:** [January 24, 2023, 2:01pm UTC](https://discuss.elastic.co/t/500-error-on-running-commands-on-kibana-console/323728 "2023-01-24T14:01:33Z")

</div>

Version Elasticsearch 7.10 Service software version R20220928-P2 (latest) on Kibana after running GET \_snapshot/my-snapshot-repo/\_all?pretty its gives 500 error { "error" : { "root\_cause" : \[ { "type" : "repositor…

---

## [Logstash, query not executing inside of the elasticsearch input plugin](https://discuss.elastic.co/t/logstash-query-not-executing-inside-of-the-elasticsearch-input-plugin/323655)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 1:41pm UTC](https://discuss.elastic.co/t/logstash-query-not-executing-inside-of-the-elasticsearch-input-plugin/323655 "2023-01-24T13:41:08Z")

</div>

Hi, I have a logstash pipeline where I'm reading data in from Kafka and then inside of the filter plugin I have a conditional to call the elasticsearch input plugin if a certain condition is met. The condition: If ser…

---

## [Missing Legend Entries](https://discuss.elastic.co/t/missing-legend-entries/322625)

<div class="topic-metadata">

**Author:** [@acbiccy](https://discuss.elastic.co/u/acbiccy)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 12:54pm UTC](https://discuss.elastic.co/t/missing-legend-entries/322625 "2023-01-24T12:54:21Z")

</div>

Hi Everyone I have a report that has approximately 200 legend entries, however the screen only displays around 25. I have tried moving the legend position but above and below give even less entries. I have tried diffe…

---

## [Elasticserch is refusing connection from my external Java client, but accepting it when they are on the same server](https://discuss.elastic.co/t/elasticserch-is-refusing-connection-from-my-external-java-client-but-accepting-it-when-they-are-on-the-same-server/323816)

<div class="topic-metadata">

**Author:** [@m.jaafar](https://discuss.elastic.co/u/m.jaafar)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 12:06pm UTC](https://discuss.elastic.co/t/elasticserch-is-refusing-connection-from-my-external-java-client-but-accepting-it-when-they-are-on-the-same-server/323816 "2023-01-24T12:06:44Z")

</div>

I have a server that I connect to through \<Server-IP-Address\>:22226, my java client uses port 8099, while elasticsearch is installed on docker on the same server but with port 9200. I got the certificate from elasticsear…

---

## [Kibana Dashboard is not getting updated with latest data](https://discuss.elastic.co/t/kibana-dashboard-is-not-getting-updated-with-latest-data/323303)

<div class="topic-metadata">

**Author:** [@vidvar](https://discuss.elastic.co/u/vidvar)\
**Replies:** 19\
**Last updated:** [January 24, 2023, 12:38pm UTC](https://discuss.elastic.co/t/kibana-dashboard-is-not-getting-updated-with-latest-data/323303 "2023-01-24T12:38:09Z")

</div>

In our Kibana, dashboards are not getting displayed the latest data from Nov 04, 2022 and we could see below logs snippets at kibana.log. Could someone please assist what is missing here. {"type":"log","@timestamp":"20…

---

## [Get random record using must\_not](https://discuss.elastic.co/t/get-random-record-using-must-not/323786)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 12:20pm UTC](https://discuss.elastic.co/t/get-random-record-using-must-not/323786 "2023-01-24T12:20:36Z")

</div>

hello again I need to get a random record excluding some values using must\_not directive. this is the query i've created using some online post. { "index": "articles", "body": { "size": 1, …

---

## [CCR replication paused indices](https://discuss.elastic.co/t/ccr-replication-paused-indices/323817)

<div class="topic-metadata">

**Author:** [@Jairam\_Gauns](https://discuss.elastic.co/u/Jairam_Gauns)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 12:12pm UTC](https://discuss.elastic.co/t/ccr-replication-paused-indices/323817 "2023-01-24T12:12:05Z")

</div>

Hi Guys, I am new to this CCR setup. The CCR setup was working fine when we had fewer and smaller indices, but as of today we have many indices. Monitoring of the ccr was not done for quite sometime. We saw there were …

---

## [\[Logstash OSS\] Invalid UTF-8 start byte issue](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772)

<div class="topic-metadata">

**Author:** [@dstepanov25](https://discuss.elastic.co/u/dstepanov25)\
**Replies:** 7\
**Last updated:** [January 24, 2023, 11:32am UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772 "2023-01-24T11:32:03Z")

</div>

Describe the bug It's not possible to save item with non-ASCII characters into OpenSearch To Reproduce Steps to reproduce the behavior: Run OpenSearch in a Docker container: docker run -d -p 9200:9200 -p 9600:9600…

---

## [Watcher and python client (8.6)](https://discuss.elastic.co/t/watcher-and-python-client-8-6/323811)

<div class="topic-metadata">

**Author:** [@MalfuncEddie](https://discuss.elastic.co/u/MalfuncEddie)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 11:17am UTC](https://discuss.elastic.co/t/watcher-and-python-client-8-6/323811 "2023-01-24T11:17:21Z")

</div>

Hi, I was hoping someone can help me get started using the python client form elastic. Background: I just upgrades to 8.6 and e python script that reads .watches does not work anymore. results = es.search(size = 200,…

---

## [FSCrawler Rest with Elasticsearch](https://discuss.elastic.co/t/fscrawler-rest-with-elasticsearch/323803)

<div class="topic-metadata">

**Author:** [@Johnson\_F](https://discuss.elastic.co/u/Johnson_F)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 11:09am UTC](https://discuss.elastic.co/t/fscrawler-rest-with-elasticsearch/323803 "2023-01-24T11:09:36Z")

</div>

Dear All, I had configured fscrawler 2.10 on ubuntu which works great, got some minor issues: - a. why touch is required? i can understand timestamp has to be new on copied or uploaded files in directory so fscrawler l…

---

## [Custom pattern in grok debugger](https://discuss.elastic.co/t/custom-pattern-in-grok-debugger/323805)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 10:49am UTC](https://discuss.elastic.co/t/custom-pattern-in-grok-debugger/323805 "2023-01-24T10:49:08Z")

</div>

Hi I'm trying to set up a grok filter for custom logs, look like this: 2023-01-20 00:00:05.235+0000 \[L: DEBUG\] \[O: S.c.t.d.e.DSLScript\] \[I: \] \[U: Administrator\] \[S: \] \[P: \] \[T: TWEventProcessor-3\] @@@ Property Write Que…

---

## [Cannot access to Security in Kibana due privilege ERROR](https://discuss.elastic.co/t/cannot-access-to-security-in-kibana-due-privilege-error/323804)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 9:40am UTC](https://discuss.elastic.co/t/cannot-access-to-security-in-kibana-due-privilege-error/323804 "2023-01-24T09:40:02Z")

</div>

when i trying to enter Security (Dashboards, Alert, Manage ...) got the message "Failed to retrieve lists privileges" i created spaces and several dashboards and now i want for Each user (spaces) to restrict viewing of…

---

## [Elasticsearch search by part of a word](https://discuss.elastic.co/t/elasticsearch-search-by-part-of-a-word/323748)

<div class="topic-metadata">

**Author:** [@maks1](https://discuss.elastic.co/u/maks1)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 9:37am UTC](https://discuss.elastic.co/t/elasticsearch-search-by-part-of-a-word/323748 "2023-01-24T09:37:38Z")

</div>

Hello. Could you help me? There is an ELK cluster (version 5) and through kibana I execute a query for a part of a word using a wildcard, for example, examp\*, but nothing is found. If I search for the whole word example,…

---

## [Can't see logs in discover](https://discuss.elastic.co/t/cant-see-logs-in-discover/323726)

<div class="topic-metadata">

**Author:** [@mkibani](https://discuss.elastic.co/u/mkibani)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 9:36am UTC](https://discuss.elastic.co/t/cant-see-logs-in-discover/323726 "2023-01-24T09:36:21Z")

</div>

hello, i've just installed elastic stack, then proceeded to install an beat agent for the first time, pushed the template and everything as documented however i can't see anything in the data stream in discover, Down b…

---

## [Query\_string using special character work and dont work without escaping](https://discuss.elastic.co/t/query-string-using-special-character-work-and-dont-work-without-escaping/323794)

<div class="topic-metadata">

**Author:** [@eladonline](https://discuss.elastic.co/u/eladonline)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 8:17am UTC](https://discuss.elastic.co/t/query-string-using-special-character-work-and-dont-work-without-escaping/323794 "2023-01-24T08:17:57Z")

</div>

Hey, what is the diferent that the first works and the others does not? GET /forensics/\_search { "query": { "query\_string": { "fields": \["referer"\], "query": "http://10.26.30.206\*" // but these doe…

---

## [Can not get details of ELK stack monitoring](https://discuss.elastic.co/t/can-not-get-details-of-elk-stack-monitoring/323731)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 8:54am UTC](https://discuss.elastic.co/t/can-not-get-details-of-elk-stack-monitoring/323731 "2023-01-24T08:54:37Z")

</div>

Hi, Suddenly I got this error "Monitoring Request Error Connection error: Check the Elasticsearch Monitoring cluster network connection and refer to the Kibana logs for more information. HTTP 503" What would be the…

---

## [Field type changed results in a conflict - kibana reports an error](https://discuss.elastic.co/t/field-type-changed-results-in-a-conflict-kibana-reports-an-error/322970)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 8:51am UTC](https://discuss.elastic.co/t/field-type-changed-results-in-a-conflict-kibana-reports-an-error/322970 "2023-01-24T08:51:09Z")

</div>

Dear All, from a firewall I send log information to filebeat into a self written module. Within a kibana dashboard I have several lenses to get information of different events and aggregations. This is now running sever…

---

## [Not able to parse logs while parsing mix json objects](https://discuss.elastic.co/t/not-able-to-parse-logs-while-parsing-mix-json-objects/323494)

<div class="topic-metadata">

**Author:** [@abhishek1111](https://discuss.elastic.co/u/abhishek1111)\
**Replies:** 8\
**Last updated:** [January 24, 2023, 8:17am UTC](https://discuss.elastic.co/t/not-able-to-parse-logs-while-parsing-mix-json-objects/323494 "2023-01-24T08:17:08Z")

</div>

Could someone please help me with parsing below mix json logs tried multiple ways of parsing it, but nothing has helped. Logs {"log":"\[GIN\] 2023/01/19 - 08:14:32 | 200 | 5.595393ms | 10.164.30.231 | POST "/api…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=655)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=657)
