# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=664

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 665

---

## [How to send logs to logstash outside the kubernetes cluster](https://discuss.elastic.co/t/how-to-send-logs-to-logstash-outside-the-kubernetes-cluster/323322)

<div class="topic-metadata">

**Author:** [@sulfred](https://discuss.elastic.co/u/sulfred)\
**Replies:** 0\
**Last updated:** [January 17, 2023, 12:38pm UTC](https://discuss.elastic.co/t/how-to-send-logs-to-logstash-outside-the-kubernetes-cluster/323322 "2023-01-17T12:38:50Z")

</div>

Hi all, I followed this page to set up a logstash with k8s. I can send logs to this logstash within the k8s cluster from other pods. But, I cannot send logs to the logstash outside the cluster. Here is my settings: …

---

## [I am setting elasticsearch 8.5.3 but getting below error](https://discuss.elastic.co/t/i-am-setting-elasticsearch-8-5-3-but-getting-below-error/323216)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 10\
**Last updated:** [January 17, 2023, 12:35pm UTC](https://discuss.elastic.co/t/i-am-setting-elasticsearch-8-5-3-but-getting-below-error/323216 "2023-01-17T12:35:42Z")

</div>

\[2023-01-16T10:41:07,855\]\[ERROR\]\[o.e.i.g.GeoIpDownloader \] \[node-203\] exception during geoip databases update java.net.SocketTimeoutException: Connect timed out at sun.nio.ch.NioSocketImpl.timedFinishConnect(NioSocket…

---

## [Does Elastic env. auto-localize to EFIGS languages based on browser language header?](https://discuss.elastic.co/t/does-elastic-env-auto-localize-to-efigs-languages-based-on-browser-language-header/323072)

<div class="topic-metadata">

**Author:** [@JPT\_Manche](https://discuss.elastic.co/u/JPT_Manche)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 12:04pm UTC](https://discuss.elastic.co/t/does-elastic-env-auto-localize-to-efigs-languages-based-on-browser-language-header/323072 "2023-01-17T12:04:21Z")

</div>

Does Elastic environment auto-localize to EFIGS (English, French, Italian, German and Spanish) languages based on browser language header? I’m super new to elastic and I can’t really find this. I want to know if consol…

---

## [Using Power BI conditional formatting](https://discuss.elastic.co/t/using-power-bi-conditional-formatting/323292)

<div class="topic-metadata">

**Author:** [@Likithsai](https://discuss.elastic.co/u/Likithsai)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 11:39am UTC](https://discuss.elastic.co/t/using-power-bi-conditional-formatting/323292 "2023-01-17T11:39:32Z")

</div>

Problem: When attempting to use conditional formatting on a card, table, etc. I can right click off the measure or column data involved to select conditional formatting. The process starts and the conditional formatting …

---

## [How to create Gantt chart visualization](https://discuss.elastic.co/t/how-to-create-gantt-chart-visualization/322319)

<div class="topic-metadata">

**Author:** [@Kamil\_BdBelfort](https://discuss.elastic.co/u/Kamil_BdBelfort)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 11:37am UTC](https://discuss.elastic.co/t/how-to-create-gantt-chart-visualization/322319 "2023-01-17T11:37:44Z")

</div>

Hi there, I have been looking on previous posts and options in Vega / custom visualization to create Gantt Chart-like visualization for more than a day now. Part of my data are projects, I have start dates, end dates, …

---

## [Can we control file/location where index data is stored in Elasticsearch?](https://discuss.elastic.co/t/can-we-control-file-location-where-index-data-is-stored-in-elasticsearch/322587)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 4\
**Last updated:** [January 17, 2023, 11:04am UTC](https://discuss.elastic.co/t/can-we-control-file-location-where-index-data-is-stored-in-elasticsearch/322587 "2023-01-17T11:04:49Z")

</div>

Hi, Can we control the file or location where the index data of particular index is stored in Elasticsearch? That is, let say, I have multiple indices in my Elasticsearch indices and one of which is called index1 Can …

---

## [Dashboard: increasing the number of entries shown in "options list" filter controls](https://discuss.elastic.co/t/dashboard-increasing-the-number-of-entries-shown-in-options-list-filter-controls/322751)

<div class="topic-metadata">

**Author:** [@hkhalil](https://discuss.elastic.co/u/hkhalil)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 11:00am UTC](https://discuss.elastic.co/t/dashboard-increasing-the-number-of-entries-shown-in-options-list-filter-controls/322751 "2023-01-17T11:00:19Z")

</div>

Hi, We are using filtering controls in our dashboards, specifically "Options List". We've noticed that the max number of entries shown in the dropdown is 10. Is there a way to increase this value ? The following topi…

---

## [Count the number of documents that contain two values in one field](https://discuss.elastic.co/t/count-the-number-of-documents-that-contain-two-values-in-one-field/323140)

<div class="topic-metadata">

**Author:** [@steve10](https://discuss.elastic.co/u/steve10)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 2:10pm UTC](https://discuss.elastic.co/t/count-the-number-of-documents-that-contain-two-values-in-one-field/323140 "2023-01-13T14:10:15Z")

</div>

Hi, I have a number of documents like this in Elastic Search database: Document 1: { “Id”: 6000, “customerName”: GT, “customerValue”: 10 } Document 2: { “Id”: 6001, “customerName”: MX, “customerValue”: 10 } Documen…

---

## [Same query convert string to int gives different result for nested fields](https://discuss.elastic.co/t/same-query-convert-string-to-int-gives-different-result-for-nested-fields/322598)

<div class="topic-metadata">

**Author:** [@Kanwardeep\_Singh](https://discuss.elastic.co/u/Kanwardeep_Singh)\
**Replies:** 0\
**Last updated:** [January 6, 2023, 7:13am UTC](https://discuss.elastic.co/t/same-query-convert-string-to-int-gives-different-result-for-nested-fields/322598 "2023-01-06T07:13:54Z")

</div>

I created new index and copy mapping from old index but After elasticdump running same query convert string to int gives different result for nested fields.

---

## [How to get network drop details in packetbeat dashboard?](https://discuss.elastic.co/t/how-to-get-network-drop-details-in-packetbeat-dashboard/323311)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 0\
**Last updated:** [January 17, 2023, 10:09am UTC](https://discuss.elastic.co/t/how-to-get-network-drop-details-in-packetbeat-dashboard/323311 "2023-01-17T10:09:41Z")

</div>

Hi, How to check if the network got failed/dropped in packetbeat dashboard? please help me Thanks jp

---

## [How to restrict search to selected fields when using q param](https://discuss.elastic.co/t/how-to-restrict-search-to-selected-fields-when-using-q-param/323263)

<div class="topic-metadata">

**Author:** [@nn14](https://discuss.elastic.co/u/nn14)\
**Replies:** 3\
**Last updated:** [January 17, 2023, 9:58am UTC](https://discuss.elastic.co/t/how-to-restrict-search-to-selected-fields-when-using-q-param/323263 "2023-01-17T09:58:26Z")

</div>

Hi team, Our users generally use q param to search people. E.g. q="Matthew North" or just q="North". This results in our ES searching across all our 100+ fields defined in the schema and chances are it returns even thos…

---

## [How to optimize elasticsearch query dsl to improve the query performance？](https://discuss.elastic.co/t/how-to-optimize-elasticsearch-query-dsl-to-improve-the-query-performance/323213)

<div class="topic-metadata">

**Author:** [@yeoman](https://discuss.elastic.co/u/yeoman)\
**Replies:** 8\
**Last updated:** [January 17, 2023, 9:53am UTC](https://discuss.elastic.co/t/how-to-optimize-elasticsearch-query-dsl-to-improve-the-query-performance/323213 "2023-01-17T09:53:16Z")

</div>

Dear elasticsearch technology experts,I have a elasticsearch index which size is almost 18Gb,and the amount of documents is about 400000.There are 3 nodes in the elasticserch cluster,and each nodes server is 2Cpu 4Gb mem…

---

## [Elasticsearch kubernetes deployment](https://discuss.elastic.co/t/elasticsearch-kubernetes-deployment/323306)

<div class="topic-metadata">

**Author:** [@Ayyappan](https://discuss.elastic.co/u/Ayyappan)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 9:30am UTC](https://discuss.elastic.co/t/elasticsearch-kubernetes-deployment/323306 "2023-01-17T09:30:56Z")

</div>

is it possible to restore the data from the cache once its cleared/overwritten?

---

## [Logstash conf script language](https://discuss.elastic.co/t/logstash-conf-script-language/323305)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 9:30am UTC](https://discuss.elastic.co/t/logstash-conf-script-language/323305 "2023-01-17T09:30:56Z")

</div>

Hi all, I have installed logstash 8.4.0. with my ES. I have created logstash .conf file to create data pipelines. I use below .conf format input { ... } filter{ .... } output{ ... } I just want to know is above sc…

---

## [Vegalite - Filter Flatten Data](https://discuss.elastic.co/t/vegalite-filter-flatten-data/323123)

<div class="topic-metadata">

**Author:** [@Siva\_Kumar\_Menta](https://discuss.elastic.co/u/Siva_Kumar_Menta)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 9:21am UTC](https://discuss.elastic.co/t/vegalite-filter-flatten-data/323123 "2023-01-17T09:21:09Z")

</div>

Hi All, I have data in Elasticsearch index "testdata" with few fields in array format. While trying to apply filter on flattened data @ line #18 as {"filter":"ms \> 1"} getting error. Syntax wise it looks fine but not su…

---

## [Occasionally missing data when making both gt + lte queries with a single isoformatted date](https://discuss.elastic.co/t/occasionally-missing-data-when-making-both-gt-lte-queries-with-a-single-isoformatted-date/323284)

<div class="topic-metadata">

**Author:** [@jsun-m](https://discuss.elastic.co/u/jsun-m)\
**Replies:** 9\
**Last updated:** [January 17, 2023, 8:45am UTC](https://discuss.elastic.co/t/occasionally-missing-data-when-making-both-gt-lte-queries-with-a-single-isoformatted-date/323284 "2023-01-17T08:45:34Z")

</div>

Use case: I'm trying to build a realtime logging client that allows the user to search old logs as well as see new logs come in realtime. So far everything mostly functions as expected except when the first queries are …

---

## [Need to know the cost of ELK product without support in all categories](https://discuss.elastic.co/t/need-to-know-the-cost-of-elk-product-without-support-in-all-categories/323302)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 9:02am UTC](https://discuss.elastic.co/t/need-to-know-the-cost-of-elk-product-without-support-in-all-categories/323302 "2023-01-17T09:02:50Z")

</div>

Hi Team, Need to know the cost of ELK product without support.

---

## [Adding new sink to Beats](https://discuss.elastic.co/t/adding-new-sink-to-beats/323295)

<div class="topic-metadata">

**Author:** [@ag-ramachandran](https://discuss.elastic.co/u/ag-ramachandran)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 8:56am UTC](https://discuss.elastic.co/t/adding-new-sink-to-beats/323295 "2023-01-17T08:56:41Z")

</div>

Support for additional datastores: Azure Data Explorer We have requirements for integration of filebeat to a timeseries database called Azure Data Explorer. Roughly ran through the existing modules, this would be along …

---

## [Filestream parsers multiline pattern parse all file in one hit althoutgh I test my pattern in The Go Playground](https://discuss.elastic.co/t/filestream-parsers-multiline-pattern-parse-all-file-in-one-hit-althoutgh-i-test-my-pattern-in-the-go-playground/323179)

<div class="topic-metadata">

**Author:** [@fouadelnahal](https://discuss.elastic.co/u/fouadelnahal)\
**Replies:** 5\
**Last updated:** [January 17, 2023, 8:30am UTC](https://discuss.elastic.co/t/filestream-parsers-multiline-pattern-parse-all-file-in-one-hit-althoutgh-i-test-my-pattern-in-the-go-playground/323179 "2023-01-17T08:30:10Z")

</div>

Here is the parser in filestream input parsers: - multiline: type: pattern pattern: '^DEBUG|INFO|ERROR' negate: true match: after # flush\_pattern: '^\\s\*$' and this is the log…

---

## [How to use elasticsearch 8.x ingest-attachment with Python](https://discuss.elastic.co/t/how-to-use-elasticsearch-8-x-ingest-attachment-with-python/323286)

<div class="topic-metadata">

**Author:** [@garami](https://discuss.elastic.co/u/garami)\
**Replies:** 2\
**Last updated:** [January 17, 2023, 7:45am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-8-x-ingest-attachment-with-python/323286 "2023-01-17T07:45:34Z")

</div>

I am trying to read a pdf from python and send it to elasticsearch. I tried to use ingest-attachment to help with that, but I don't know how. When I followed the official documentation, it worked. However, there doesn…

---

## [TSDS - manual rollover](https://discuss.elastic.co/t/tsds-manual-rollover/323227)

<div class="topic-metadata">

**Author:** [@Sako](https://discuss.elastic.co/u/Sako)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 8:17am UTC](https://discuss.elastic.co/t/tsds-manual-rollover/323227 "2023-01-16T08:17:18Z")

</div>

Hi, I try to use Timeseries Data Streams (TSDS) for telemetry data from network devices to use the new downsampling features later on. I also use ILM to automate the rollover and lifecycle for the TSDS. Under certain c…

---

## [Will this thing work regarding updation of Kibana dashboard through python](https://discuss.elastic.co/t/will-this-thing-work-regarding-updation-of-kibana-dashboard-through-python/323298)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 7:12am UTC](https://discuss.elastic.co/t/will-this-thing-work-regarding-updation-of-kibana-dashboard-through-python/323298 "2023-01-17T07:12:27Z")

</div>

This is a code that I wrote by taking references from many sites: import requests headers = { 'Content-Type': 'application/json', 'kbn-version': '8.4.1' } data = { "options": { "query": { …

---

## [How to set kibana basePath on cloud kibana instance](https://discuss.elastic.co/t/how-to-set-kibana-basepath-on-cloud-kibana-instance/323291)

<div class="topic-metadata">

**Author:** [@dinesh.mandrekar](https://discuss.elastic.co/u/dinesh.mandrekar)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 7:09am UTC](https://discuss.elastic.co/t/how-to-set-kibana-basepath-on-cloud-kibana-instance/323291 "2023-01-17T07:09:55Z")

</div>

kibana instance on cloud elastic does not allow setting basePath in kibana user settings. Is there an alternate solution for this?

---

## [Logstash Mutate Convert Not Working](https://discuss.elastic.co/t/logstash-mutate-convert-not-working/323289)

<div class="topic-metadata">

**Author:** [@Johanes\_Mistrialdo](https://discuss.elastic.co/u/Johanes_Mistrialdo)\
**Replies:** 0\
**Last updated:** [January 17, 2023, 6:18am UTC](https://discuss.elastic.co/t/logstash-mutate-convert-not-working/323289 "2023-01-17T06:18:41Z")

</div>

Hi All, I've created logstash ruby filter like this (ignore my val.each loop, I'm tring to convert all field to string): However, I still cannot convert my field to string (the field is showed as date field): My …

---

## [Can I create a index in the WARM Phase directly with Elastic ILM](https://discuss.elastic.co/t/can-i-create-a-index-in-the-warm-phase-directly-with-elastic-ilm/323224)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 2\
**Last updated:** [January 17, 2023, 5:00am UTC](https://discuss.elastic.co/t/can-i-create-a-index-in-the-warm-phase-directly-with-elastic-ilm/323224 "2023-01-17T05:00:20Z")

</div>

I am indexing my data using ILM Policy and Indexing Template. So, the index moves from one Phase to another(Hot, Warm , Cold and Delete) after the completion of assigned time period for that Phase. Now, I got a requirem…

---

## [Kibana security\_exception Error](https://discuss.elastic.co/t/kibana-security-exception-error/323215)

<div class="topic-metadata">

**Author:** [@vibuverma07](https://discuss.elastic.co/u/vibuverma07)\
**Replies:** 4\
**Last updated:** [January 17, 2023, 4:54am UTC](https://discuss.elastic.co/t/kibana-security-exception-error/323215 "2023-01-17T04:54:27Z")

</div>

Getting this error on Kibana 8.5.2 \[ERROR\]\[http\] ResponseError: security\_exception: \[security\_exception\] Reason: action \[indices:admin/resolve/index\] is unauthorized for user \[temporarykibanasuperuser\] with effective ro…

---

## [E-Commerce Search Engine - Per User Data](https://discuss.elastic.co/t/e-commerce-search-engine-per-user-data/323265)

<div class="topic-metadata">

**Author:** [@panko](https://discuss.elastic.co/u/panko)\
**Replies:** 3\
**Last updated:** [January 17, 2023, 4:15am UTC](https://discuss.elastic.co/t/e-commerce-search-engine-per-user-data/323265 "2023-01-17T04:15:30Z")

</div>

Hello, We do something like a typical e-commerce platform with custom product search based on Elasticsearch (a service which simply send queries to Elasticsearch). Our product search service worked flawlessly, but recen…

---

## [Winlogbeat Alert for certain users in Windows PC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506)

<div class="topic-metadata">

**Author:** [@amis349](https://discuss.elastic.co/u/amis349)\
**Replies:** 4\
**Last updated:** [January 17, 2023, 3:24am UTC](https://discuss.elastic.co/t/winlogbeat-alert-for-certain-users-in-windows-pc/322506 "2023-01-17T03:24:11Z")

</div>

Okay I have looked around and found different iterations of a solution. However I am running into a road block, the winlogbeats (below) are not dropping the events for that targetusername or even the event ID. All logs a…

---

## [How to track the user commands in Kibana?](https://discuss.elastic.co/t/how-to-track-the-user-commands-in-kibana/323092)

<div class="topic-metadata">

**Author:** [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Replies:** 2\
**Last updated:** [January 17, 2023, 1:49am UTC](https://discuss.elastic.co/t/how-to-track-the-user-commands-in-kibana/323092 "2023-01-17T01:49:14Z")

</div>

Hi, We have already installed auditbeat and metricbeat agents (version 7.10.2) on our RHEL / Linux servers and we want to track the "commands" that the user had executed on the server through Kibana dashboards. We do no…

---

## [Importing index field](https://discuss.elastic.co/t/importing-index-field/323155)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 1:22am UTC](https://discuss.elastic.co/t/importing-index-field/323155 "2023-01-17T01:22:17Z")

</div>

Hi folks, I have issues on lacking field on index in elk of beats (filebeat, auditbeat and winlogbeat). current my log flows is log source hosts \>\> kafka \>\> logstash \>\> elastic cloud (elk). according to my understandi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=663)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=665)
