# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=662

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 663

---

## [Advanced JSON input](https://discuss.elastic.co/t/advanced-json-input/322366)

<div class="topic-metadata">

**Author:** [@imsudo](https://discuss.elastic.co/u/imsudo)\
**Replies:** 5\
**Last updated:** [January 19, 2023, 2:08am UTC](https://discuss.elastic.co/t/advanced-json-input/322366 "2023-01-19T02:08:05Z")

</div>

I have a data table with data, Metrics, aggregation as count. ( as it shows all the log count) see attached image(if avl) i wish to get only the count of 5xx errors (500-599) in downstreamStatus data field using advanc…

---

## [K8S GKE Deployment - Connect to Internal DNS](https://discuss.elastic.co/t/k8s-gke-deployment-connect-to-internal-dns/323463)

<div class="topic-metadata">

**Author:** [@Jennifer\_Klemisch](https://discuss.elastic.co/u/Jennifer_Klemisch)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 1:41am UTC](https://discuss.elastic.co/t/k8s-gke-deployment-connect-to-internal-dns/323463 "2023-01-19T01:41:25Z")

</div>

I have a Terraform created GKE. Then I use Yaml files to install ES (8.6.0) and Kibana. As part of my terraform IAAS I reserve 2 IPs, and 2 "google\_dns\_record\_set" (es\_dns and kb\_dns) which sit on our company shared VP…

---

## [Pb with format during a CSV import](https://discuss.elastic.co/t/pb-with-format-during-a-csv-import/323267)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 1:33am UTC](https://discuss.elastic.co/t/pb-with-format-during-a-csv-import/323267 "2023-01-19T01:33:58Z")

</div>

Hi all, Sorry in advance for my bad english and my poor knowledge on ELK. I need to import regularly a csv file like this : data\_id iso event\_id\_cnty event\_id\_no\_cnty event\_date year time\_precision event\_type sub\_…

---

## [Elasticsearch high cpu usage](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage/323079)

<div class="topic-metadata">

**Author:** [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 11:29pm UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage/323079 "2023-01-18T23:29:07Z")

</div>

Hi everyone. My Es cluster had high cpu usage at 3:30 am today, below is grafana monitoring: And the kibana monitoring: I don't have a clue, because in my nginx log files, I didn't see any request rise signif…

---

## [Snapshot error](https://discuss.elastic.co/t/snapshot-error/323104)

<div class="topic-metadata">

**Author:** [@Sam\_LE](https://discuss.elastic.co/u/Sam_LE)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 11:28pm UTC](https://discuss.elastic.co/t/snapshot-error/323104 "2023-01-18T23:28:33Z")

</div>

Hello, We have an ES cluster v7.8.1 and we try to create a first snapshot. We used kibana and created a policy. However we got errors on several index. Errors are : """ElasticsearchException\[failed to create blob conta…

---

## [Are there any cron jobs I can perform daily to keep my cluster healthy?](https://discuss.elastic.co/t/are-there-any-cron-jobs-i-can-perform-daily-to-keep-my-cluster-healthy/323150)

<div class="topic-metadata">

**Author:** [@SemperFi](https://discuss.elastic.co/u/SemperFi)\
**Replies:** 3\
**Last updated:** [January 18, 2023, 11:16pm UTC](https://discuss.elastic.co/t/are-there-any-cron-jobs-i-can-perform-daily-to-keep-my-cluster-healthy/323150 "2023-01-18T23:16:18Z")

</div>

I've got a very basic Elasticsearch cluster set up on my server to support search for a Xenforo forum. My technical knowledge is good enough to be dangerous. Lately Elasticsearch is crashing about once a week and I'm w…

---

## [Can not collect logs if I installed beats on local machine or azure vm](https://discuss.elastic.co/t/can-not-collect-logs-if-i-installed-beats-on-local-machine-or-azure-vm/323313)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 0\
**Last updated:** [January 17, 2023, 10:32am UTC](https://discuss.elastic.co/t/can-not-collect-logs-if-i-installed-beats-on-local-machine-or-azure-vm/323313 "2023-01-17T10:32:25Z")

</div>

Hi folks, I have issue for log collecting when I installed the beats on outside of AWS Ec2 instances. My log architecture is beats \>\> kafka (ec2 vm) \>\> logstash (ec2 vm) \>\> elastic cloud I can collect the logs if I i…

---

## [.alerts-security.alerts-default\* indice removed suddenly](https://discuss.elastic.co/t/alerts-security-alerts-default-indice-removed-suddenly/323434)

<div class="topic-metadata">

**Author:** [@raghiboon](https://discuss.elastic.co/u/raghiboon)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 10:03pm UTC](https://discuss.elastic.co/t/alerts-security-alerts-default-indice-removed-suddenly/323434 "2023-01-18T22:03:56Z")

</div>

Hi everybody. i just removed .alerts-security.alerts-default-0000 suddenly after i was working with rules and made my dashboards. is there a way to recreate it? because it gives me this error: Bulk indexing of signals…

---

## [Multipipeline configuration](https://discuss.elastic.co/t/multipipeline-configuration/323272)

<div class="topic-metadata">

**Author:** [@SaM9](https://discuss.elastic.co/u/SaM9)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 9:55pm UTC](https://discuss.elastic.co/t/multipipeline-configuration/323272 "2023-01-18T21:55:31Z")

</div>

How can I create a pipeline configuration in Logstash for two different logs that I'm receiving from syslog, the syslog auditd log and the web server log, and separate them to get different outputs? I have tried using an…

---

## [Limitations for Managed Logstash pipelines](https://discuss.elastic.co/t/limitations-for-managed-logstash-pipelines/323450)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 7:29pm UTC](https://discuss.elastic.co/t/limitations-for-managed-logstash-pipelines/323450 "2023-01-18T19:29:04Z")

</div>

Hello, I want to start using the managed pipelines in the Kibana GUI. From the documentation it is not really clear what the limitations are. As an example if you want to include a Ruby script I presume this script must…

---

## [Has anyone see/solved this kibana error?](https://discuss.elastic.co/t/has-anyone-see-solved-this-kibana-error/323325)

<div class="topic-metadata">

**Author:** [@mwitmer](https://discuss.elastic.co/u/mwitmer)\
**Replies:** 8\
**Last updated:** [January 18, 2023, 6:17pm UTC](https://discuss.elastic.co/t/has-anyone-see-solved-this-kibana-error/323325 "2023-01-18T18:17:34Z")

</div>

{"type":"log","@timestamp":"2023-01-17T13:02:00Z","tags":\["error","elasticsearch","data"\],"pid":818,"message":"\[ResponseError\]: Response Error"} Getting A LOT of these errors and the dashboards are not updating.

---

## [Unable to move the reports from Ansible to logstash](https://discuss.elastic.co/t/unable-to-move-the-reports-from-ansible-to-logstash/322977)

<div class="topic-metadata">

**Author:** [@janaka8](https://discuss.elastic.co/u/janaka8)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 6:03pm UTC](https://discuss.elastic.co/t/unable-to-move-the-reports-from-ansible-to-logstash/322977 "2023-01-18T18:03:46Z")

</div>

Team, We have a ansible setup in our environment and even are using a Kibana Dashboard for resporting purpose. We are getting below attached error while pushing the reports from ansible logs to kibana dashboard. { "co…

---

## [SQL Return Malformed (ignored\_field\_values)](https://discuss.elastic.co/t/sql-return-malformed-ignored-field-values/323418)

<div class="topic-metadata">

**Author:** [@T\_Eckmann](https://discuss.elastic.co/u/T_Eckmann)\
**Replies:** 6\
**Last updated:** [January 18, 2023, 5:29pm UTC](https://discuss.elastic.co/t/sql-return-malformed-ignored-field-values/323418 "2023-01-18T17:29:49Z")

</div>

Hopefully I am not missing anything stupid. But I am working on trying to return some data using the Elasticsearch SQL functions. So far no luck. The data I am trying to get can be found in the raw data as well as when …

---

## [After upgrade from 8.2.2 to 8.5.3 elasticsearch.bat works just fine but the elasticsearch-service.bat start fails](https://discuss.elastic.co/t/after-upgrade-from-8-2-2-to-8-5-3-elasticsearch-bat-works-just-fine-but-the-elasticsearch-service-bat-start-fails/322167)

<div class="topic-metadata">

**Author:** [@mbooh](https://discuss.elastic.co/u/mbooh)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 4:59pm UTC](https://discuss.elastic.co/t/after-upgrade-from-8-2-2-to-8-5-3-elasticsearch-bat-works-just-fine-but-the-elasticsearch-service-bat-start-fails/322167 "2023-01-18T16:59:53Z")

</div>

Hi! After upgrade from 8.2.2 to 8.5.3 elasticsearch.bat works just fine but the elasticsearch-service.bat start fails with the following error log: \[2022-12-29 16:51:55\] \[debug\] ( prunsrv.c:1994) \[ 8136\] Apache Commons…

---

## [Trying to recover snapshot](https://discuss.elastic.co/t/trying-to-recover-snapshot/323428)

<div class="topic-metadata">

**Author:** [@Monica\_majua](https://discuss.elastic.co/u/Monica_majua)\
**Replies:** 4\
**Last updated:** [January 18, 2023, 4:35pm UTC](https://discuss.elastic.co/t/trying-to-recover-snapshot/323428 "2023-01-18T16:35:54Z")

</div>

Hello everyone, I'm new to this topic, it's my first time using elastic so I'm a bit lost and confused. I have migrated from ES (elasticsearch 7.17.6) to Opendistro (elasticsearch 7.10.2) but I took a snapshot first. Now…

---

## [Can't create cluster with 2 nodes on elasticsearch version 2.2.2](https://discuss.elastic.co/t/cant-create-cluster-with-2-nodes-on-elasticsearch-version-2-2-2/323350)

<div class="topic-metadata">

**Author:** [@KaZuKi\_Yashiro](https://discuss.elastic.co/u/KaZuKi_Yashiro)\
**Replies:** 3\
**Last updated:** [January 18, 2023, 4:34pm UTC](https://discuss.elastic.co/t/cant-create-cluster-with-2-nodes-on-elasticsearch-version-2-2-2/323350 "2023-01-18T16:34:16Z")

</div>

Hello there! :slight\_smile: We have a single node of Elasticsearch version 2.2.2 and we decided to extend this cluster to two nodes, with replicas and so. But problem is that these two nodes doesn't see each other. =( …

---

## [Error loading Kibana Dashboard](https://discuss.elastic.co/t/error-loading-kibana-dashboard/323413)

<div class="topic-metadata">

**Author:** [@kartheek91](https://discuss.elastic.co/u/kartheek91)\
**Replies:** 3\
**Last updated:** [January 18, 2023, 4:01pm UTC](https://discuss.elastic.co/t/error-loading-kibana-dashboard/323413 "2023-01-18T16:01:56Z")

</div>

{"statusCode":503,"error":"Service Unavailable","message":"License is not available."} I'm getting this error when I'm enabled XPACK Security to true. If it is false it is working like a charm.

---

## [\[Metrics System\] Overview dasboard is empty](https://discuss.elastic.co/t/metrics-system-overview-dasboard-is-empty/322613)

<div class="topic-metadata">

**Author:** [@tsykorii](https://discuss.elastic.co/u/tsykorii)\
**Replies:** 6\
**Last updated:** [January 18, 2023, 3:58pm UTC](https://discuss.elastic.co/t/metrics-system-overview-dasboard-is-empty/322613 "2023-01-18T15:58:34Z")

</div>

Hello! I want to use the \[Metrics System\] Overview stock dashboard from Metricbeat as a source. But it's empty, even when I use metricbeat-\* index pattern as default. How can I change the index for such visualizations…

---

## [Vulnerabilities in docker image elasticsearch/elasticsearch:7.17.8](https://discuss.elastic.co/t/vulnerabilities-in-docker-image-elasticsearch-elasticsearch-7-17-8/323377)

<div class="topic-metadata">

**Author:** [@Jayasree\_N](https://discuss.elastic.co/u/Jayasree_N)\
**Replies:** 5\
**Last updated:** [January 18, 2023, 2:55pm UTC](https://discuss.elastic.co/t/vulnerabilities-in-docker-image-elasticsearch-elasticsearch-7-17-8/323377 "2023-01-18T14:55:48Z")

</div>

Hi, we are using elasticsearch/elasticsearch:7.17.8 docker image. We are getting few CVEs reported as high with the vulnerabilities scanning report. CVE-2021-31684 -- nimbus-jose-jwt and json-smart CVE-2020-36518 -- …

---

## [Elastic search aggregations](https://discuss.elastic.co/t/elastic-search-aggregations/323335)

<div class="topic-metadata">

**Author:** [@Pablo\_Cumpe](https://discuss.elastic.co/u/Pablo_Cumpe)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 2:10pm UTC](https://discuss.elastic.co/t/elastic-search-aggregations/323335 "2023-01-18T14:10:08Z")

</div>

Hi, Im working with Elasticsearch aggregations in an particular index. I have a dought if aggregations do a full scan of the index or only do o partial scan. Does anyone have an idea about this?

---

## [Ingestion of data to Elasticsearch using lostash with incremental data](https://discuss.elastic.co/t/ingestion-of-data-to-elasticsearch-using-lostash-with-incremental-data/323416)

<div class="topic-metadata">

**Author:** [@sriteja\_chebrolu](https://discuss.elastic.co/u/sriteja_chebrolu)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 2:02pm UTC](https://discuss.elastic.co/t/ingestion-of-data-to-elasticsearch-using-lostash-with-incremental-data/323416 "2023-01-18T14:02:52Z")

</div>

Hi All, I am ingesting data from SQL to Elastic cloud If i ingest a SQL table twice it is ingesting two times but I want to ingest only the new data Suppose if a table has 10 records at first ingestion after that 2 re…

---

## [How to set new logging configuration settings as environment variables in Kibana docker container](https://discuss.elastic.co/t/how-to-set-new-logging-configuration-settings-as-environment-variables-in-kibana-docker-container/323412)

<div class="topic-metadata">

**Author:** [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 1:20pm UTC](https://discuss.elastic.co/t/how-to-set-new-logging-configuration-settings-as-environment-variables-in-kibana-docker-container/323412 "2023-01-18T13:20:18Z")

</div>

Hey there, we're running Kibana in a docker container and all configuration is provided via injected environment variables - hence we do not mount a kibana.yml file. As stated in the documentation, the "syntax" for the…

---

## [Keeping anomaly scoring constant](https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 3\
**Last updated:** [January 18, 2023, 1:16pm UTC](https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365 "2023-01-18T13:16:34Z")

</div>

Hi there, I'm currently trying to configure an advanced job that detects low counts or zero counts of documents by using low\_count by field1. I basically want the job to detect any abnormal behavior at all. Some attribu…

---

## [DateTime format in CSV report is not correct. 0's are being appended for nanos](https://discuss.elastic.co/t/datetime-format-in-csv-report-is-not-correct-0s-are-being-appended-for-nanos/322612)

<div class="topic-metadata">

**Author:** [@samee\_alam](https://discuss.elastic.co/u/samee_alam)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 12:17pm UTC](https://discuss.elastic.co/t/datetime-format-in-csv-report-is-not-correct-0s-are-being-appended-for-nanos/322612 "2023-01-18T12:17:48Z")

</div>

ES and kibana version v 7.17.3 When generating CSV report, datetime format is not correct. 0's are being appended for micro and nano seconds, although document holds correct values. Tried playing around with adva…

---

## [co.elastic.clients.json.JsonpMappingException: Error deserializing co.elastic.clients.elasticsearch.\_types.mapping.VersionProperty: Unknown field 'index'](https://discuss.elastic.co/t/co-elastic-clients-json-jsonpmappingexception-error-deserializing-co-elastic-clients-elasticsearch-types-mapping-versionproperty-unknown-field-index/323316)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 12:17pm UTC](https://discuss.elastic.co/t/co-elastic-clients-json-jsonpmappingexception-error-deserializing-co-elastic-clients-elasticsearch-types-mapping-versionproperty-unknown-field-index/323316 "2023-01-18T12:17:04Z")

</div>

Hi, When I tried to create an index containing a field of type: "version" or "geo\_point" with 'index' : true/false (sample input below) through the Java API client (7.17.7), I am getting the following exception. Could…

---

## [ES Build failure - resolve all task dependencies](https://discuss.elastic.co/t/es-build-failure-resolve-all-task-dependencies/322823)

<div class="topic-metadata">

**Author:** [@kvmprashanth](https://discuss.elastic.co/u/kvmprashanth)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 11:53am UTC](https://discuss.elastic.co/t/es-build-failure-resolve-all-task-dependencies/322823 "2023-01-18T11:53:56Z")

</div>

I am trying to build Elasticsearch from scratch using ./gradlew localDistro command on one of the latest releases. When I build on master it works. However, when I try to build from one of the tagged (v8.5.3 or even v7.1…

---

## [Joining a New ES search Node to a Bootstrapped Cluster](https://discuss.elastic.co/t/joining-a-new-es-search-node-to-a-bootstrapped-cluster/323378)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 3\
**Last updated:** [January 18, 2023, 10:27am UTC](https://discuss.elastic.co/t/joining-a-new-es-search-node-to-a-bootstrapped-cluster/323378 "2023-01-18T10:27:12Z")

</div>

Hello, Is there a way to join a new ES node to an already existing bootstrapped single node cluster that already contains data? I read on some other blog posts that for this to happen, I'll have to remove the data from …

---

## ["No logs for this cluster"](https://discuss.elastic.co/t/no-logs-for-this-cluster/322932)

<div class="topic-metadata">

**Author:** [@fus80677](https://discuss.elastic.co/u/fus80677)\
**Replies:** 15\
**Last updated:** [January 18, 2023, 8:59am UTC](https://discuss.elastic.co/t/no-logs-for-this-cluster/322932 "2023-01-18T08:59:21Z")

</div>

I've been trying to set up logging for the Stack Monitoring page, but it just won't seem to work: I enabled the elasticsearch module in filebeat with this config: # Module: elasticsearch # Docs: https://www.elastic.c…

---

## [ElasticSearch Dockercompose with plugin not starting up](https://discuss.elastic.co/t/elasticsearch-dockercompose-with-plugin-not-starting-up/322523)

<div class="topic-metadata">

**Author:** [@gjahagir](https://discuss.elastic.co/u/gjahagir)\
**Replies:** 3\
**Last updated:** [January 18, 2023, 8:48am UTC](https://discuss.elastic.co/t/elasticsearch-dockercompose-with-plugin-not-starting-up/322523 "2023-01-18T08:48:40Z")

</div>

Hi, I followed the article here to start a multi node cluster using docker compose. i also installed mapper-size plugin for each node, manually using command - docker exec es02 elasticsearch-plugin install mapper-size…

---

## [How to specify different index name rather than the default?](https://discuss.elastic.co/t/how-to-specify-different-index-name-rather-than-the-default/323391)

<div class="topic-metadata">

**Author:** [@baalchina](https://discuss.elastic.co/u/baalchina)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 8:42am UTC](https://discuss.elastic.co/t/how-to-specify-different-index-name-rather-than-the-default/323391 "2023-01-18T08:42:29Z")

</div>

Hello, guys, I already had a es cluster, and many data in it. Now I want to stor a new nginx's access/error log to my es with filebeat+nginx module. I want the index to be the a new name such as nginx-log-20230118, rath…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=661)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=663)
